hcaptcha-challenger icon indicating copy to clipboard operation
hcaptcha-challenger copied to clipboard

Hcaptcha on Cloudflare websites

Open Peskedor opened this issue 3 years ago • 7 comments

It seems like there is an issue with hcaptcha captchas with cloudflare sitekeys, the response of the token starts with W0 instead of P0 - if you try to submit that token its invalid and it wont proceed. Example sitekey: f9630567-8bfa-4fc9-8ee5-9c91c6276dff

Peskedor avatar Sep 21 '22 22:09 Peskedor

I don't understand what you said. Can you provide more information?

QIN2DIM avatar Sep 22 '22 03:09 QIN2DIM

I don't understand what you said. Can you provide more information?

Ok let me try to clearify it. When i submit the sitekey f9630567-8bfa-4fc9-8ee5-9c91c6276dff to the program and then check for the hcaptcha response with ctx.execute_script("return hcaptcha.getResponse()") it will return a response that starts with W0_xxxx instead of P0_xxxx . If i try to submit the W0_xxxx response that you currently get when you provide the sitekey i wrote above it wont count is as valid and asks for another one. Issue seems to exist with all cloudflare hcaptcha responses, no matter what site

Peskedor avatar Sep 22 '22 05:09 Peskedor

Did you load Cloudflare's challenge on the demo site? I think you need to replicate it in a specific business context. Can you provide a site?

I think the submitted form was missing some fields, so it must have failed because the challenge was loaded at the demo site and Cloudflare used an extra iframe to submit these additional fields.

QIN2DIM avatar Sep 22 '22 06:09 QIN2DIM

Did you load Cloudflare's challenge on the demo site? I think you need to replicate it in a specific business context. Can you provide a site?

I think the submitted form was missing some fields, so it must have failed because the challenge was loaded at the demo site and Cloudflare used an extra iframe to submit these additional fields.

* https://docs.hcaptcha.com/#integration-testing-test-keys

Example website that shows a captcha (not always, if you cant see it reload the website in a private tab) gydrus.net - the site key is also for that website.

Peskedor avatar Sep 22 '22 06:09 Peskedor

+1. I have this problem with cloudflare sitekeys too. Here's another example: https://accounts.hcaptcha.com/demo?sitekey=33f96e6a-38cd-421b-bb68-7806e1764460

It only partially passes the hcaptcha with horses and never passes the hcaptcha with lions. My assumption is that the noise, or rather the spirals in the picture, make it difficult to recognize what is in the picture.

cheasea avatar Sep 24 '22 12:09 cheasea

watermark is a good thing

QIN2DIM avatar Sep 24 '22 12:09 QIN2DIM

watermark is a good thing

What do you mean?

cheasea avatar Sep 24 '22 15:09 cheasea