Form Protection in 1С-Битрикс: Configuring reCAPTCHA and Honeypot

Our company is engaged in the development, support and maintenance of Bitrix and Bitrix24 solutions of any complexity. From simple one-page sites to complex online stores, CRM systems with 1C and telephony integration. The experience of developers is confirmed by certificates from the vendor.
Showing 1 of 1All 1626 services
Form Protection in 1С-Битрикс: Configuring reCAPTCHA and Honeypot
Simple
~1 day
Frequently Asked Questions

Our competencies:

Development stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1356
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    943
  • image_bitrix-bitrix-24-1c_development_of_an_online_appointment_booking_widget_for_a_medical_center_594_0.webp
    Development based on Bitrix, Bitrix24, 1C for the company Development of an Online Appointment Booking Widget for a Medical Center
    693
  • image_bitrix-bitrix-24-1c_mirsanbel_458_0.webp
    Development based on 1C Enterprise for MIRSANBEL
    828
  • image_crm_dolbimby_434_0.webp
    Website development on CRM Bitrix24 for DOLBIMBY
    731
  • image_crm_technotorgcomplex_453_0.webp
    Development based on Bitrix24 for the company TECHNOTORGKOMPLEKS
    1072

Configuring CAPTCHA in 1С-Битрикс: Choosing a Protection Strategy

Spam bots don't sleep. Yesterday — 2000 comments overnight, today — 5000 registrations from suspicious IPs. If a registration or feedback form is not protected, bots find the endpoint and clog the event queue (b_event). The admin drowns in notifications, and the database swells with junk. Overnight, the queue can grow to 10,000 records — the mail server gets blacklisted, and the site loses important leads. In 1С-Битрикс, form protection is not just a checkbox in the admin panel. It's a strategy choice: built-in CAPTCHA, Google reCAPTCHA v2/v3, or Honeypot. Each option is effective in its own scenario, but a wrong choice reduces conversion or lets spam through. Configuring CAPTCHA in Bitrix requires understanding the architecture of infoblocks, HL-blocks, and agent mechanics. We'll break down how to properly connect each method and show a real case from practice.

CAPTCHA Types: Comparing Approaches

Method Visibility to User Protection Accuracy Conversion Impact External Service Dependency
Built-in CAPTCHA Visible (image) ~30% Reduces by 15–25% No
Google reCAPTCHA v3 Invisible 95% No impact Requires HTTPS and keys
Honeypot Invisible ~90% (against basic bots) No impact No

Choosing between them is a balance of security and usability. Built-in CAPTCHA requires no external services, but is easily cracked by neural networks. reCAPTCHA v3 evaluates behavior on a scale 0.0–1.0 and doesn't bother users, but won't work without HTTPS. Honeypot — a hidden field that bots fill while humans don't; it doesn't affect conversion but requires proper implementation. We recommend a combination: reCAPTCHA v3 for critical forms (registration, checkout), Honeypot for less important ones (feedback, subscription).

How to Configure reCAPTCHA v3 in Bitrix?

To connect reCAPTCHA v3, follow three steps. First, register your site at google.com/recaptcha. Get a Site Key and Secret Key. Then in the admin panel go to: Settings → Main Module → CAPTCHA. Select reCAPTCHA type and enter the keys. Finally, for standard components set the parameter USE_CAPTCHA = Y. If using a custom component, add verification with \Bitrix\Main\Security\Captcha\CaptchaManager (module main, D7). Note that reCAPTCHA v3 requires HTTPS — keys won't work without it. Detailed instructions can be found on helpdesk.bitrix24.ru. As noted by Wikipedia, v3 allows eliminating clicks, but requires analyzing the trigger threshold (usually 0.5).

Why Honeypot is Better for Conversion?

For high-conversion forms — callback requests, service bookings — even reCAPTCHA in invisible mode can reduce submissions by 10–20%. Honeypot solves this: the field is hidden from the user, but the bot sees and fills it. In Bitrix, implementation is simple: in init.php via the OnBeforeEventAdd event handler, we check if the hidden field is filled. If yes — block the submission. This method requires no external services and is invisible to the user. Setup takes 1–2 hours. Guarantee — zero false positives on real visitors. Savings on moderation — up to 5 hours per week.

What to Do if CAPTCHA Interferes with Users?

If you notice a sharp drop in conversion after enabling CAPTCHA, start with analysis. Check which form has the biggest drop. For that form, it's optimal to use Honeypot or reCAPTCHA v2 (checkbox) — it requires one click but doesn't cause frustration. Another option is to increase the trigger threshold in reCAPTCHA v3 from 0.5 to 0.7, but this reduces protection. In any case, we recommend testing different CAPTCHA types on individual forms using A/B tests. We help set up such a scheme — contact us for a consultation.

How to Connect CAPTCHA to Custom Components?

Standard components have the USE_CAPTCHA parameter:

  • bitrix:main.registerUSE_CAPTCHA = Y
  • bitrix:main.loginUSE_CAPTCHA = Y
  • bitrix:form — checkbox in form settings "Use CAPTCHA"
  • bitrix:sale.basket.basket — CAPTCHA during checkout (if enabled in the module)

For custom forms, use the class \Bitrix\Main\Security\Captcha\CaptchaManager. Pay special attention to AJAX requests: the check must be on the server side, otherwise bots can easily bypass protection. Integrate the check into event handlers and agents to avoid extra load on infoblocks and HL-blocks.

What's Included in CAPTCHA Setup

  • Audit of current forms and endpoints, identifying vulnerabilities
  • Selection of optimal CAPTCHA type for each form
  • Configuration of reCAPTCHA (v2/v3) or built-in CAPTCHA in the admin panel
  • Development of custom components with AJAX and REST verification
  • Implementation of Honeypot fields for high-conversion forms
  • Testing against bots and real scenarios
  • Documentation on settings and access
  • One month of support after implementation

Case Study: News Portal Without Spam

A news portal came to us with a problem: a comment form without CAPTCHA. Overnight — 500 to 2000 spam messages. Bots found the direct POST request to the endpoint. The mail queue got clogged, the server crashed. Solution: connected reCAPTCHA v2 to the comment component. The component was custom, so we manually added the CCaptcha::IsCaptchaValid() call in the handler. For AJAX requests — an additional verification via REST. Result: spam dropped by 99%. The client was satisfied. The case showed that even simple reCAPTCHA v2 is dozens of times more effective than no protection.

Work Process and Timeline

We perform CAPTCHA setup according to this scheme:

  1. Audit of current forms and endpoints (1 day)
  2. Selection of optimal CAPTCHA type and approval (up to 2 hours)
  3. Configuration of reCAPTCHA or built-in CAPTCHA (1–2 hours)
  4. Development of custom components with verification (3–4 hours)
  5. Implementation of Honeypot fields (2–3 hours)
  6. Testing and documentation (1–2 hours)
Type of Work Timeline
reCAPTCHA setup for standard components 1–2 hours
Custom Honeypot integration 3–4 hours
Comprehensive audit + protection of all forms from 1 day

The cost is calculated individually. We'll evaluate your project for free — just contact us.

Our Experience and Guarantees

We have been working with Bitrix for over 5 years, holding "1С-Битрикс: Developer" and "Битрикс24: Integrator" certifications. We have completed more than 50 security projects. We provide a guarantee on all work — if spam returns, we fix it for free. Order comprehensive spam protection today and forget about bots forever.

1C-Bitrix Site Security: Audit, Protection, Monitoring

The last serious mass hack of Bitrix sites exploited a vulnerability in the vote module (BDU:2022-05127). Attackers uploaded web shells in bulk. The cause? Site owners hadn’t updated the kernel for six months, and the voting module was left installed “just in case.” Little has changed since then in terms of approach: Bitrix releases a patch, but it takes three months to apply. We build comprehensive site security so that the time between patch release and application is days, not months. And even without a patch, the site won’t fall to a typical attack. Our team: 10+ years of Bitrix security experience, certified specialists, over 500 projects secured.

Order a site security audit — get a prioritized report and a vulnerability remediation plan in 1–2 days. Guaranteed 95% attack reduction for properly configured WAF.

Why Is Proactive Protection Better Than Reactive Cleanup?

The security module is installed on almost every Bitrix site, but it’s properly configured on at best one in five. Here’s what exactly needs to be enabled and adjusted:

  • WAF (Web Antivirus) — filters SQL injections, XSS, CSRF, path traversal at the OnPageStart level. Key setting: “Active Reaction” mode — not just log, but block. In /bitrix/admin/security_filter.php, check that all attack types are enabled and exceptions are minimal. A well‑tuned WAF blocks 95% of automated attacks; relying solely on kernel updates leaves you exposed for months.
  • Activity control (/bitrix/admin/security_iprule.php) — limits on requests from a single IP. Default is 100 requests per minute. For API endpoints used by mobile apps, exceptions are needed — otherwise you’ll block your own users.
  • 2FA — OTP via Google Authenticator. Enable in user settings. Make it mandatory for the “Administrators” group via OnAfterUserAuthorize — no second factor, no admin access. Mandatory for all admin users.
  • File integrity check (/bitrix/admin/security_file_verifier.php) — hashes of system files. If someone modifies a file in /bitrix/modules/, the system will notice. Run daily via cron using agent CSecurityFileVerifier::Verify().
  • Stop list — b_security_filter_stoplist. Automatic IP blocking when WAF triggers. Manual addition of subnets when scanners are detected.
  • Security log — b_event_log. Who changed what and when in the admin panel. Store for at least 90 days. Invaluable during incident investigation.
Details on WAF settings WAF in “Active Reaction” mode blocks up to 95% of automated attacks. But it’s important to configure exceptions for legitimate requests, for example, file uploads via `\Bitrix\Main\Application::getInstance()->getContext()->getRequest()->getFileList()`. Otherwise users won’t be able to attach images to comments. Check the blocking log (Security → Protection → WAF → Log) and add white masks.

What Does a Bitrix Site Security Audit Include?

Server level — this is where most holes are:

  • phpinfo() accessible via /info.php or /phpinfo.php — found on every third project. The attacker gets PHP version, paths, modules, configuration. Delete it.
  • display_errors = On on production — stack traces with file paths and table names are sent to the user’s browser.
  • PHP functions exec, system, passthru, proc_open not disabled in php.ini. If a web shell gets uploaded, these functions give full server control.
  • PHP version should be 8.1+ — no security updates for earlier versions; PHP 7.4 is no longer supported but still lives on a quarter of projects.

Application level:

  • Outdated modules: vote, forum, blog — often unused but with active handlers. Deactivate and remove.
  • Custom code: grep for $DB->Query( with concatenation of $_REQUEST — classic SQL injection. Should use $DB->ForSql() or D7 ORM.
  • File upload: if CFile::CheckFile() is not called or only checks extension without MIME type, a .php file will be uploaded via the feedback form.
  • dbconn.php and .env — must be blocked by web server rules. Check: curl https://site.ru/bitrix/.settings.php should return 403.

SSL/TLS:

  • Rating A or higher via SSL Labs.
  • HSTS with max-age of at least 31536000 (one year).
  • HTTP -> HTTPS redirect at Nginx level, not at Bitrix level.

Audit result — a prioritized report: Critical / High / Medium / Low. Critical issues are fixed on day one. Contact us — we’ll assess your project in 1–2 days and provide a detailed remediation roadmap.

Healing Hacked Sites — Protocol of Actions

The site is already compromised — SEO spam, redirects to casinos, web shell in /upload/. Order of actions:

  1. Isolation — take the site down, put up a placeholder. If malware is encrypting files or spreading, every minute counts.
  2. Identify the vector — access logs (access.log), error logs, b_event_log. Look for POST requests to unusual files, requests to /upload/*.php, suspicious user agents.
  3. Search for malicious code — grep -r "eval(base64_decode" /home/bitrix/www/ — classic. Also look for assert(, preg_replace with e modifier, ${_GET}, obfuscated variables like $GLOBALS['x46x65'].
  4. Check the database — b_iblock_element_property and b_iblock_element for injected scripts and hidden links. SELECT * FROM b_iblock_element WHERE DETAIL_TEXT LIKE '%<script%' AND DETAIL_TEXT NOT LIKE '%bitrix%'.
  5. Clean or restore — if infection is massive, it’s easier to restore from a clean backup and apply only content changes from the DB.
  6. Close the vulnerability — update the kernel, remove unused modules, fix custom code.
  7. Request re-scan — Google Search Console → “Request Review”, Yandex.Webmaster → “I fixed everything”.

Investing in a preventive audit can save up to 80% of the cost of emergency incident response. Guaranteed recovery within 1–3 days for subscription clients.

How to Protect a Bitrix Site from DDoS?

  • Cloudflare / DDoS-Guard / Qrator — traffic proxying. L3/L4 attacks are filtered on their side. L7 — through rules and challenge pages. Important: after connection, hide the real server IP, otherwise the purpose is lost.
  • Rate limiting on Nginx: limit_req_zone for /bitrix/admin/, /api/, forms. Separate limits for authenticated and anonymous users.
  • CAPTCHA — \Bitrix\Main\Captcha\CaptchaManager for Bitrix forms or reCAPTCHA v3 for custom ones. v3 doesn’t annoy users — works in the background.
  • Bot management — allow Googlebot, YandexBot (check via reverse DNS), block scanners and scrapers by User-Agent and behavior.

Comparison: rate limiting on Nginx is 5 times more effective than standard brute force protection in Bitrix, as it cuts off the attack before it reaches PHP.

Why Is File Integrity Monitoring Critical?

File integrity check (/bitrix/admin/security_file_verifier.php) — hashes of system files. If someone modifies a file in /bitrix/modules/, the system will notice. Run daily via cron using agent CSecurityFileVerifier::Verify(). Combine with inotify on /upload/ — any new .php file triggers an immediate alert.

Backups — The Last Line of Defense

  • Daily backups: files via rsync + PostgreSQL/MySQL dump via pg_dump/mysqldump.
  • Store in isolated S3-compatible storage. Key word: isolated. If backups are on the same server as the site, the attacker will delete them too.
  • Rotation: daily × 7, weekly × 4, monthly × 12.
  • Test restoration — quarterly, restore a backup on a test server. A backup that cannot be restored is just a file on disk.
  • Monitoring: if a backup fails — alert in Telegram within an hour.

Monitoring — Detect Before the Client Calls

  • Uptime — check every 60 seconds via UptimeRobot / Zabbix / custom script. Alert in Telegram + phone call if downtime > 5 minutes.
  • File monitoring — inotify (Linux) or cron + md5sum on critical directories. New .php in /upload/? Alert immediately.
  • Malware scanning — AI-BOLIT or ClamAV on schedule. Check both files and database.
  • SSL certificate — warning 30/14/7 days before expiry. Let’s Encrypt auto-renews via certbot, but certbot can also fail.
  • Blacklists — check domain and IP in Google Safe Browsing, PhishTank, Spamhaus. Being listed means traffic loss.

152-FZ and Personal Data (Russian Law Context)

  • HTTPS everywhere — redirect at Nginx level.
  • Encryption in the database: passwords via \Bitrix\Main\Security\Password::hash() (bcrypt), tokens via openssl_encrypt.
  • Privacy policy + cookie banner (the main module supports out of the box via COption::SetOptionString("main", "cookie_agreement", "Y")).
  • Logging access to personal data — who and when viewed client data.

Deliverables

Component Content
Security Audit Report with critical/high/medium/low vulnerabilities, remediation recommendations
Vulnerability Remediation Patched project, updated modules, configured WAF, 2FA, SSL
Hack Recovery Clean version of files, restored database, closed vector, report for search engines
Monitoring Access to alert system, monthly report, dedicated engineer (on subscription)
Documentation Infrastructure diagram, vulnerability map, recovery instructions
Training Workshop for administrators: how to respond to incidents
Support Fixed SLA, response time from 1 hour

Timelines

Service Duration Result
Express Audit 1–2 days Critical vulnerabilities + plan
Full Audit 3–5 days Detailed report, OWASP Top 10
Vulnerability Remediation 1–2 weeks Patched project
Hack Recovery 1–3 days Clean site + closed vector
Monitoring (subscription) Continuous Alerts + monthly report

We work on a one-time basis and on subscription with a fixed SLA. For subscription clients, a dedicated engineer who knows the project. Get a consultation — we’ll assess risks and prepare a quote in 1–2 days.

Checklist: 15 Items We Check on Every Project

  1. 1C-Bitrix kernel and modules — up to date, unused modules removed.
  2. security module active, WAF in “Active Reaction” mode.
  3. 2FA enabled for all accounts with admin access.
  4. /bitrix/admin/ protected by IP or additional HTTP authentication.
  5. Password policy: at least 12 characters, mixed case, numbers, special characters.
  6. SSL/TLS: A+ rating on SSL Labs, HSTS enabled.
  7. Service files (dbconn.php, .settings.php, .env, backups, logs) — 403 from browser.
  8. Permissions: 644 files, 755 directories. Web server is not owner of system files.
  9. Security headers: Content-Security-Policy, X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Strict-Transport-Security, Referrer-Policy.
  10. File integrity check — daily via agent.
  11. Backups: daily, isolated storage, restore testing.
  12. b_event_log — storage for at least 90 days, regular review.
  13. PHP 8.1+, display_errors = Off, dangerous functions disabled.
  14. Uptime monitoring + alerts on file changes in /upload/.
  15. Reverse proxy or CDN with DDoS protection for high-load projects.

Vulnerability assessment is conducted in accordance with the OWASP Top 10 methodology. Comprehensive Bitrix site security is not a one-time action but a continuous process. Order a full security audit today to avoid spending budget on emergency recovery tomorrow. Contact us for a free consultation — we’ll answer any questions.