CAPTCHAs were created in response to bots (software agents) that automatically fill in Web forms as if they were individual users. Bots are used to overload opinion polls, steal passwords (see dictionary attack) and, most popular, to register thousands of free e-mail accounts to be used for sending spam. CAPTCHAs were designed to circumvent non-humans from performing such transactions.
The Battle of the Bots and CAPTCHAs
After CAPTCHAs were deployed in 2001, the felonious bots were updated to analyze the distorted text, enter the correct text and thereby render many CAPTCHA styles ineffective. In an on-going battle between the bots and the CAPTCHAs, the CAPTCHA text is increasingly more distorted and camouflaged, often making it difficult for humans to decode. Non-text approaches have been added; for example, displaying several images and asking what object is common in all of them, such as a tree or dog. See reCAPTCHA, dictionary attack and Turing test.
Type the Word You See
In this early CAPTCHA example from Carnegie Mellon, a random word is camouflaged, and users are asked to type what they see. (Image courtesy of Carnegie Mellon School of Computer Science, www.captcha.net)
More Obtuse, More Random
CAPTCHAs are increasingly more distorted in order to fool the bots, and real words have given way to random letters and digits. However, just like virus writers, who learn to code their programs more effectively, so do the bot writers... a fun-loving, creative bunch.
![]() | Reproduced with permission from Computer Desktop Encyclopedia. Copyright (c) 1981-2009 The Computer Language Company Inc. All rights reserved. |
Additional Resources
- Phishing experiment sneaks through all anti-spam filters
- A recently conducted ethical phishing New study details the dynamics of successful phishing experiment impersonating LinkedIn by mailing invitations coming from Bill Gates, has achieved a 100% success rate in bypassing the anti-spam filters it was tested against. The experiment emphasizes on how small-scale spear phishing campaigns...
- Blog posts 2009-10-29
- Spooky Halloween - scareware or crimeware?
- With all the "spooky" cybercrime trends taking place on a monthly basis, such as the death of CAPTCHA, the suspicious idleness of the Conficker botnet, the clear presence of government-tolerated and upcoming government-sponsored botnets, the inevitable migration from using malicious infrastructure to entirely relying on legitimate one, followed by the...
- Blog posts 2009-10-29
- New Koobface campaign spoofs Adobe's Flash updater
- Earlier this week, the botnet masters behind the most efficient social engineering driven botnet, Koobface, launched a new campaign currently spreading across Facebook with a new template spoofing Adobe's Flash updater embedded within a fake Youtube page. The malware campaign is relying on compromised legitimate web sites,...
- Blog posts 2009-10-14
- Weak passwords dominate statistics for Hotmail's phishing scheme leak
- The recently leaked accounting data of thousands of Hotmail users -- Gmail has also been affected -- obtained through what appears to be a badly executed phishing campaign, once again puts the spotlight on the how bad password management practices remain an inseparable part of the user-friendly ecosystem. ...
- Blog posts 2009-10-06
- ASP.NET CAPTCHA Control,Component 2.0 (Windows)
- The AspXtremeCaptcha .NET web control & compoment that creates and validates image and sound CAPTCHAs Completely Automated Public Turing test to tell Computers and Humans Apart, which can easily be used from ASP.NET application with just drag & drop from the Visual Studio Toolbox, no need to modify the .config...
- Software downloads 2009-09-29
- LSN Password Safe 3.0.0.0 (Windows)
- High security password manager + AntiKeyLogger + virtual keyboard + CAPTCHA. Easy to use and free. You can create as many fields per entry as you need. Portable version. File protection and data theft prevention. The synchronization of files on multiple drives for data loss protect.
- Software downloads 2009-09-27
- Scareware scammers hijack Twitter trending topics
- Researchers from F-Secure and Sophos are reporting on an ongoing scareware serving campaign abusing the popular micro-blogging service Twitter. Hundreds of tweets using four different URL shortening services are currently spammed through the automatically registered Twitter accounts, relying on a pseudo-random text generation using Twitter's trending topics....
- Blog posts 2009-09-23
- Google reCAPTCHA could raise bar in anti-bot, anti-spam battle
- Well what are other options?I'm not knocking your concern because it is a valid point. But does that mean we just leave everything open to bots and spammers? What could be done for the disabled? I thought reCAPTCHA had some ways of handling this.What about for the deaf-blind?Implement CAPTCHA or...
- Discussion threads 2009-09-16
- Google buys reCAPTCHA: Digitize old books and fight spam
- Too Bad ..."They try to distinguish humans from robots when entering form data."Too bad they can't discriminate humans from 3rd World wage slaves decoding them for the spammers :(RE: Google buys reCAPTCHA: Digitize old books and fight spamCool from a machine learning standpoint but does this freak you out since...
- Discussion threads 2009-09-16
- Google scores a 2-for-1 with reCAPTCHA acquisition
- Google said today that it has acquired reCAPTCHA, a company that provides CAPTCHAs, those squiggly words in a box that you have to type to verify that you are a real person and not a computer bot. The technology is widely used - more than 100,000 Web...
- Blog posts 2009-09-16
- Google buys reCAPTCHA: Digitize old books and fight spam
- Captcha's are annoying, but necessary. They try to distinguish humans from robots when entering form data. One of the most terrifying problems with hosting your own content on the web is spam. These trolls will do anything to get you to click...
- Blog posts 2009-09-16
- Internet Captcha 1.2 (Windows)
- Internet Captcha is designed to protect your HTML forms, where users send information to others users or databases. An information robot can automatically send a lot of information saturating your system or can send you spam continuously to publish. With this captcha only human can complete the security code and...
- Software downloads 2009-09-15
- The ultimate guide to scareware protection
- Throughout the last two years, scareware fake security software, quickly emerged as the single most profitable monetization strategy for cybercriminals to take advantage of. Due to the aggressive advertising practices applied by the cybercrime gangs, thousands of users fall victim to the scam on a daily...
- Blog posts 2009-09-13
- Cute Autoposter 1.0.0.6 (Windows)
- Program Features: Create powerful rich professional HTML ads; - Edit/Delete/Rename ads; - View ad submission history; - Ad Title Rotations; - Automatically rewrite ads to appear unique to Craigslist; - Submit ads to as many Categories and Cities simultaneously; - No need to confirm CL emails to make ads go...
- Software downloads 2009-08-09
- Cute Backpage Poster 1.0 (Windows)
- Program Features: - Create powerful rich professional HTML ads - Edit/Delete/Rename ads - View ad submission history - Ad Title Rotations - Insert variables to make ad unique Backpage - Submit ads to as many Categories and Cities simultaneously - No need to confirm CL emails to make ads go...
- Software downloads 2009-07-25
- BotDetect ASP.NET CAPTCHA 2.0.13 (Windows)
- BotDetect ASP.NET CAPTCHA is a website security component designed to protect your registration, comment, poll, guestbook, content submission, and other online forms from automated spam submissions. It generates CAPTCHA images with textual code rendered in them that are easily decipherable to humans -- but not to spam bots. In essence,...
- Software downloads 2009-07-08
- Koobface worm joins the Twittersphere
- Cybercriminals are experimenting with a new feature introduced in one of the latest Koobface variants - the ability of the worm to hijack the Twitter accounts of infected users and post tweets in an attempt to infect their followers. According to researchers from TrendMicro, once the infected...
- Blog posts 2009-07-07
- Michael Jackson's death themed malware campaigns spreading
- The sudden death of Michael Jackson quickly opened a window of opportunity for cybercriminals to capitalize on. With a malicious spam campaign, blackhat SEO search results poisoning which is serving scareware within the first 100 search results for Michael Jackson's death, and an opportunistic participant in Zango...
- Blog posts 2009-06-26
- Jiffy Gmail Email Creator 2.1 (Windows)
- Introducing the Jiffy Gmail Email Creator. Our Gmail Email Creator software features: setup an auto-Responder automatically; setup forwarding automatically; use random or custom names; enable POP3 automatically; proxy support: HTTP/SOCKS4/SOCKS5; multiple exporting options; automatic self-updating software; Lifetime Updates for free.Version 2.1 fixes a few minor bugs in captcha and proxy...
- Software downloads 2009-06-09
- Email service provider: 'Hack into our CEO's email, win $10k'
- A newly launched startup called StrongWebMail is aiming to add a new layer of secure authentication for its customers - phone verification prior to logging in and alert services for potential email compromises. The company is in fact so confident in its approach that it's currently offering...
- Blog posts 2009-06-02
Neighboring Terms
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
Meet Doc
-
Here to help you with your Document Management Needs
- Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
- To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
-
Produced by
ZDNet and




