Hosting generously provided by
www.mv.com





Pick Your Language


Spammers crack Gmail Captcha
Posted 2/25/08 by Robert from the cracking google department

"Captcha (Completely Automated Public Turing test to tell Computers and Humans Apart) challenge-response systems, which are used to prevent accounts being created until a user correctly identifies letters in an image, are designed to ensure requests are made by a human rather than an automated program. The technique has been used to defeat automatic sign-ups to email accounts by services including Yahoo! Mail and Gmail for years, and hackers are increasingly successful in defeating the approach. For example, the HotLan Trojan has created more than 500,000 spam email accounts with Hotmail, Yahoo! and Gmail since its arrival back in July 2007.

Websense reckons the latest Gmail Captcha hack is the most sophisticated it has seen to date. Unlike Live Mail Captcha breaking, which involved just one zombie host doing the entire job, the Gmail breaking process involves two compromised hosts. Each of the two compromised hosts applies a slightly different technique to analysing Captcha, as explained in a posting by Websense.

Even using the two techniques, only one in every five Captcha-breaking requests are successful. It's a fairly low percentage, but one that's still more than workable in the case of automated attacks."

Article Link: http://www.theregister.co.uk/2008/02/25/gmail_captcha_crack/
Link to this Story: Spammers crack Gmail Captcha
Link: Have a Site Suggestion, Material Request, or News? Submit it!
News RSS Feed: Web Security news RSS Feed
Discuss this article    Find Related Stories



External Links:
Copyright 2000-2007 Cgisecurity.com.
Providing Web Security news since 2000.
Information contained on this website may not be copied without explicit permission.
Best Viewed with Netscape.
Website Security Web Application Security solid state drives ssd ebay ebay topdeals . buy macbook air not work safe software security


Popular Links By Subject

Sponsored Link (Advertise)


Subscribe to CGISecurity.com


The Web Security Mailing List
  • Re: [WEB SECURITY] Fake Captcha Protection
  • Re: [WEB SECURITY] Fake Captcha Protection
  • [WEB SECURITY] Re: Odd XSS Exploit
  • Re: [WEB SECURITY] Fake Captcha Protection
  • Re: [WEB SECURITY] Fake Captcha Protection
  • Re: [WEB SECURITY] webapp security curse
  • Re: [WEB SECURITY] Fake Captcha Protection
  • Re: [WEB SECURITY] Fake Captcha Protection
  • Re: [WEB SECURITY] Fake Captcha Protection
  • Re: [WEB SECURITY] webapp security curse

  • Contact us
    Post News, get linkage!

    Name

    Email or Homepage:

    Subject

    Finish the word below: deadb33f

    Body