Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Web-App-Sec
[Top] [All Lists]

Re: Script Based Attacks & Form Hacks

Subject: Re: Script Based Attacks & Form Hacks
Date: Fri, 22 Jul 2005 18:23:16 +1000
CAPTCHA implementations need to be aware of their accessibility requirements. I strongly recommend against CAPTCHAs as they prevent disabled users from accessing your site. There are many legal cases, including against the Olympics organizers SOCOG in 2000, which prove that you may not disregard your obligations to disabled access.

It may be enough to provide an e-mail link or alternative accessible mechanism for disabled users to use as an alternative path ... as long as that path ends up with full access to your site, which was the fundamental reasoning behind the SOCOG fines and remediation order.

Lastly, one of the most effective anti-CAPTCHA tactics I've seen regularly used is "free day passes" to adult web sites. The time to crack CAPTCHAs is less than 30 seconds for groups with extensive numbers of sites or affiliates. Plus, from the attacker's point of view, a human does the OCR step. This is a complete defeat of the CAPTCHA system for sites which have something of value to attackers (link spam, etc).

thanks,
Andrew

On 22/07/2005, at 5:46 PM, Vicente Aguilera wrote:

Hi,

CAPTCHA is a good solution to prevent automatic form submissions, but:

<Prev in Thread] Current Thread [Next in Thread>