A better way than CAPTCHA (because CAPTCHA is a pain in the ass for non fraudulent users) is to use some sort of rate limiting...
Store a session variable that's a hash of submit times... Once the count of the hash is greater than X amount, stop processing the form and give them a warning (or don't and let them spam away but don't process them)...
Rather than punishing the real users with a CAPTCHA :P
__________________
ICQ: 258-202-811 | Email: eric{at}bestxxxporn.com
|