CAPTCHA fun
Thursday, March 13. 2008
Websense had a few weeks ago a story on "Google’s CAPTCHA busted in recent spammer tactics". The basic idea is that the attacker automatically signs up for freemail accounts (e.g., Google or live.com) with the help of certain malware. During the registration process, the attacker needs to solve a CAPTCHA. This can be done for example with the help of humans which are paid for this task. Another option is to use humans who want to access a certain service, e.g., a porn website. This is the cheaper option, and presumably also effective. An example of such a CAPTCHA attack is currently available at gift-vip.net. Caution: this is not work-safe and do not open it if you do not want to see adult content. I also created a short movie which illustrates this process. The movie is also available as .mov and .swf file.
Thanks a lot Nick FitzGerald for this tip!
[Update]: Please be careful when opening the actual site since it also contains a malicious iframe.
Thanks a lot Nick FitzGerald for this tip!
[Update]: Please be careful when opening the actual site since it also contains a malicious iframe.


