Altru Web Form Security

We had an incident recently and my IT director is wondering if anyone else using Altru web forms has experienced something similar.  We had our donation web form used by a robot for card testing.  The issue started with a  $1 donation that showed up in Altru.  Then over 15,000 "card testing" transactions hit our credit card processor in about 15 minutes.  The card processor caught it quickly and took action.  We followed Blackbaud's recommendation to adjust our gateway account settings and Blackbaud blocked "some" of the urls that were being used.  

I noticed in researching other Blackbaud products that some do use a captcha challenge, however support confirmed this is not an option in Altru web forms.  Has anyone experienced something similar with Altru web forms?

Comments

  • Adding a basic rate limiter with Altru at the firewall level would dramatically improve the security of the webforms. 


    Simple and straight forward solution Blackbaud could add. 

Categories