I then switched the field to a hashed simple time-based value, to which they responded to by just fetching the page to get the value, and posting it back.
The posted content was often in two categories: links with stuffed keywords, or some common framework exploit (generally fetching a remote resource to test for exploitability).
While marginally entertaining in the beginning, it's just a waste of time unless you want to create some form of engagement within a blog..