CAPTCHAs Baffle Bots
Bots (software agents) have been developed to automatically perform illegitimate transactions over the Web, including overloading online opinion polls, performing dictionary attacks to find names and passwords as well as grabbing thousands of free e-mail accounts for sending spam. CAPTCHAS can be used to prevent such transactions as they ensure that a real person made the transaction.
CAPTCHAs Get Tougher
After CAPTCHAS were deployed in 2001, bots were created to circumvent them by analyzing the distorted images, requiring even more sophisticated CAPTCHA techniques. Instead of using real words from a list, made-up words are used with more distortion in the background. Non-text approaches have also been added; for example, showing a series of images and asking the user to type in what is common in all of them, perhaps an apple or some other object. See reCAPTCHA, dictionary attack and Turing test.
The CAPTCHA Concept
Random words or letters are displayed as in the above examples, and users are asked to type in what they see. The text is camouflaged so that only humans can decipher it. (Images courtesy of Carnegie Mellon School of Computer Science, www.captcha.net)
![]() | Reproduced with permission from Computer Desktop Encyclopedia. Copyright (c) 1981-2008 The Computer Language Company Inc. All rights reserved. |
Additional Resources
- Cybercriminals syndicating Google Trends keywords to serve malware
- Cybercriminals syndicating Google Trends keywords to serve malwareLarge networks are increasingly...being used to comprimise the Internet. These commercial networks are too large to be managed by hands-on real people and are being managed by technology. Things are only going to get worse. If these networks can't be properly managed they...
- Discussion threads 2008-10-03
- Spammers attacking Microsoft's CAPTCHA -- again
- Spammers attacking Microsoft's CAPTCHA -- againI'm all for shutting down...mail servers that are spamming. No matter how big they are. If my server started spamming, my ISP would give me one shot to clean it up. If I didn't or couldn't it would be blocked. Just because it's Microsoft doesn't...
- Discussion threads 2008-10-01
- News to know: Economy watch; Google trades; RealDVD; Apple's showdown; Pandora
- Here are today's notable headlines. You can get News To Know via email alert and RSS daily: Reuters: Senate agrees to vote on bailout, stocks rally Michael Krigsman: Economic meltdown: The insanity of disagreement Larry Dignan: Analyst: Intel will weather the storm ...
- Blog posts 2008-10-01
- Spammers attacking Microsoft's CAPTCHA -- again
- Never let a human do a malware infected host's CAPTCHA recognition job. On their way to abuse the DomainKeys verified server reputation in order increase the probability of their spam emails reaching the receipts, spammers and malware authors are once again attempting to break Microsoft's "revisited" CAPTCHA, and are able...
- Blog posts 2008-09-30
- Spamming vendor launches managed spamming service
- Spamming vendor launches managed spamming serviceGo into a little more detail on MX and Ptr...records being defined. There will have to be a domain registered pointing to a start of authority. DNS servers query for the SOA. Then proceed to the SOA to get the DNS records you are referring...
- Discussion threads 2008-09-14
- News to know: Google Chrome; CAPTCHA breaking; StatusHQ
- Here are today's notable headlines. You can get News To Know via email alert and RSS daily: Larry Dignan: Google to launch browser to target IE; Is Firefox a target or tag-team partner? Adrian Kingsley-Hughes: Is Google Chrome an IE/Firefox/Opera/Safari killer? Ryan Naraine: Google Chrome, the security...
- Blog posts 2008-09-02
- Inside India's CAPTCHA solving economy
- Inside India's CAPTCHA solving economyEconomic TerrorismThe purpose of the CAPTCHA is to ensure fair access to internet services in a manner that is consistent with the license agreements of those offering the services.Employing humans to purposely solve CAPTCHA should be considered economic terrorism because it has no other purpose than...
- Discussion threads 2008-08-29
- Inside India's CAPTCHA solving economy
- No CAPTCHA can survive a human that's receiving financial incentives for solving it, and with an army of low-waged human CAPTCHA solvers officially in the business of "data processing" while earning a mere $2 for solving a thousand CAPTCHA's, I'm already starting to see evidence of consolidation between India's major...
- Blog posts 2008-08-29
- Twitter's "me too" anti-spam strategy
- With Twitter's continuing growth, its popularity is logically starting to attract the attention of malicious parties, like spammers, phishers, and malware authors who wouldn't mind the fact that nobody is following them when they're actively updating several hundred users with their latest propositions. Last' week's Twitter announcement...
- Blog posts 2008-08-25
- Fortune 500 companies use of email spoofing countermeasures declining
- Here's a paradox - a technology originally meant to verify the sender of an email message for the sake of preventing spoofed messages from reaching the network, still hasn't been embraced by the world's biggest companies despite being around for years, but is actively used by adaptive spammers increasingly abusing...
- Blog posts 2008-08-19
- Facebook's (futile) malware exorcism - can social networks fight back?
- Facebook's futile malware exorcism - can social networks fight back?Banks have this problemUser gets phished or malwared and then goes onto Internet banking and gets ripped off... then who's fault is it? The user? Probably, but that is just driving them away from the online banking. So...
- Discussion threads 2008-08-08
- Spam coming from free email providers increasing
- After analyzing three weeks of spam data between June 13 to July 3, 2008, Roaring Penguin Software Inc. found evidence that spam originating from the top three free email providers (Gmail, Yahoo Mail and Hotmail) is increasing, with spammers in favor of abusing Gmail's privacy preserving feature of not including...
- Blog posts 2008-07-18
- Google Group Genius (exe)
- GoogleGroups Automated Submission Software. This Powerful New Software Quickly Enables you to post your ads on virtually unlimited GoogleGroupsTM Pages Quickly and Easily. 100% fully automated, with the exception of captcha verification image codes but we have even made that part super fast and easy. This version is the first...
- Software downloads 2008-07-16
- YouTube Genius (exe)
- YouTube Automated Submission Software. This new software quickly enables you to post your ads on unlimited YouTubeTM Video Pages quickly and easily. This New Software will enable you to cut the time ad posting takes to mere seconds. 100% fully automated, with the exception of captcha verification image codes (but...
- Software downloads 2008-07-16
- Demographics forging a new Net market: It's not your kids' Web
- It's easy and fashionable to talk about "digital natives" that have grown up online, but the demographics of the United States are shifting radically to the grey and Web services developers should heed that news and make changes in their products and plans as a result. Old coots, like me,...
- Blog posts 2008-07-07
- News to know: Open Office; Google; Security metrics; IT jobs
- Notable headlines: Dana Blankenhorn: What could Open Office do with a business model? Adrian Kingsley-Hughes: First look at Ubuntu 8.10 - Intrepid Ibex. Gallery right Paul Murphy: Internet abuse and Cloud Computing An IT productivity horror story ...
- Blog posts 2008-07-07
- Gmail, Yahoo and Hotmail's CAPTCHA broken by spammers
- Gmail, Yahoo and Hotmail's CAPTCHA broken by spammersIt is impossible to manage...networks the size of Google with technology alone. It takes a real live person. Now we can expect more spam coming from these networks. Spam that will be harder to filter. If these companies can't manage their networks in...
- Discussion threads 2008-07-03
- Gmail, Yahoo and Hotmail's CAPTCHA broken by spammers
- Breaking Gmail, Yahoo and Hotmail's CAPTCHAs, has been an urban legend for over two years now, with do-it-yourself CAPTCHA breaking services, and proprietary underground tools assisting spammers, phishers and malware authors into registering hundreds of thousands of bogus accounts for spamming and fraudulent purposes. ...
- Blog posts 2008-07-03
- Craigslist Genius (exe)
- Craigslist Auto Posting and Submission Software. This new software quickly enables you to post your ads to craigslist quickly and easily. This Cutting-Edge Explosive New Software will enable you to cut the time ad posting takes to mere seconds! 100% fully automated, with the exception of captcha verification image codes...
- Software downloads 2008-07-03
- Blizzard introducing two-factor authentication for WoW gamers
- Password stealing malware targeting popular MMORPGs such as World of Warcraft for instance, has become so prevalent, that video game developers are taking their authentication model a step further, by introducing two-factor authentication into play. And while marketable, is the new authentication layer actually useful in a real life situation?...
- Blog posts 2008-07-02
Neighboring Terms
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- ZDNet News Videos
-
Tech news covering the latest in products, conferences and blog commentary, from ZDNet video.
- Watch the latest video >>
- See how Intel Xeon processors provide data traffic optimization
-
With key platform innovations built-in, the Intel Xeon processor 7400 series offers more headroom, reliability, and the highest expandability for large-scale server consolidation.
- Watch the Flash demo to learn about the Intel® Xeon® processor 7400 series >>
- Printers
- 'Green' Font Cuts Costs and Saves Trees (BNET)
- Three Ways to Save Paper (BNET)
- CNET Reviews printer buying guide (CNET)
- View all printers-tagged content on ZDNet
- Plan B from Brother
- It's the smarter way to work in color Our professional color ink-jet all-in-ones give you more choices, more features, and more value. Make the Smarter Choice. Learn More »



