Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: [WEB SECURITY] Defeating CAPTCHA |
|---|---|
| Date: | Thu, 25 Aug 2005 15:30:06 +0100 (BST) |
Hi all! I suppose if the user had to select each letter and/or numeric digit from a captcha seperately, and enter these using a randomly generated input sequence by the server, that would block any programs from reading the CAPTCHA and feeding it directly to the form input field. After several failed attempts the server could generate another CAPTCHA, and make the user (or robot) start over again. Eg. CAPTCHA: ZXCVBNM Please enter the above CAPTCHA in the following sequence: 3rd letter: [ C ] 6th letter: [ N ] 5th letter: [ B ] 2nd letter: [ X ] 7th letter: [ M ] 4th letter: [ V ] 1st letter: [ Z ] Or via several drop down selection boxes, one for each CAPTCHA character. HTH - KR
There already exists few interesting projects around on circumventing CAPTCHA ( http://www.captcha.net/ ). There are various alogorithms being written to defeat simplests to the complex CAPTCHAs but only few CAPTCHAs have survived such tests. A project devoted to breaking CAPTCHA systems can be found here: http://sam.zoy.org/projects/pwntcha/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: [WEB SECURITY] Defeating CAPTCHA, Debasis Mohanty |
|---|---|
| Next by Date: | looking for stats, Robin Wood |
| Previous by Thread: | RE: [WEB SECURITY] Defeating CAPTCHA, Debasis Mohanty |
| Next by Thread: | RE: [WEB SECURITY] Defeating CAPTCHA, Michal Zalewski |
| Indexes: | [Date] [Thread] [Top] [All Lists] |