Porn Rewards Users To Get Past Anti-Spam Captchas
Stalke writes "Spammers are now usings a new technique to circumvent the 'captchas,' the distorted text in graphics, that users must input to receive the free email account. The spammers have cracked the system by displaying the 'captchas' on free porn sites in real time. Since there are always a large number of people signing up for free porn, they do the work of decripting the 'captchas' which is then replayed back into the spammers program to create a new email account. Who thought that porn could be a hacking technique!" Sure sounds plausible, though the link here says only "someone told me."
This can be easily countered if the free e-mail sites configure their servers, so that the 'captchas' can only be loaded into pages that they've served themselves.
I'm not sure how that works, but I've seen it in action on some sites.
Maybe someone else knows how it's done?
If the image ...has been inlined from Yahoo or Hotmail... as the article says, couldn't Yahoo/etc have their image generation scripts setup dynamically to check the referrer (or should I say referer? ;-)).
I seem to recall this approach being used by online comic strips trying to prevent inline linking from elsewhere...
--LP
Catchups are constantly designed to be undecodable by OCR. But the porn solution doesn't sound like rubbish at all. It actually sounds quite clever. Here's how it might work: 1.An automated script tries to sign up for public emails (yahoo, hotmail, etc.). 2.At some stage during sign up a page with a catchup is "presented" to the script. 3.The script gets the catchup out of the page and adds it to a pool of catchups to be associated with their perspective words. 4. At some point, shortly after, a visitor to a porn site is presented with a catchup and enters the correct word. THIS IS, BY THE WAY, A PERFECT WAY TO FOIL SPAMMERS AND TO STILL GET YOUR PORN -- since the porn site doesn't, in fact, know what the catchup is supposed to be and is only using you, enter a wrong one. 5. The word entered by the user on the porn site is used to submit a reply to the public email system.
Any guest worker system is indistinguishable from indentured servitude.
The computer science department at Berkeley has already broken the Yahoo-like Captcha. They use an algorithm to break it. They recommend "Gimpy" as a replacement, which their software has yet to crack. The blog is full of crap, the captcha is generated every session, so you can't make a link to the image like they would like because the session would end.
I thought this exact same thing. Every time I see a simple 'sollution' to a 'problem' like this, I always have to give the creator credit due to them... I don't care whether it's for the linux kernel or to send me pills for a larger penis, it's still ingenious.
Not Free(as in beer). Free(as in "I'm free to beat you over the head for being a dumbass")
I could see this working for some image recognition problems. To get the next page you have to perform some small task. Salt the tasks with 10% control images for which you know the answer and a finders fee where you get a weeks free access if you find X or do Y work units. Could be used in to check survalance video images ...
I think half of us are going to flame on slashdot and the other half will go off to find the web site where you can get the free porn.
I hate these C/R schemes, they are OK when they are used for mailing lists or for checking signups to Yahoo! mail or some other forum where the intent is to protect ME. I do not accept that they are at all legitimate when the only purpose is to protect some dweeb who thinks he is really important.
Worst of all are the systems that send out C/R challenges in response to email that was a reply to something that the challenger sent. I get students asking me some question about a Web spec or something else I did. I spend time writing an answer and then get a C/R challenge. Like some student's time is much more important than mine...
Worst of all are the C/R systems that don't whitelist after the first challenge. Dan Bernstein is the worst offender here, I answered three of his challenges and still get his robot if I make the mistake of replying to one of his mails to me. So I have his robot blacklisted in my email.
So on balance I am not at all sad that the nuisance of C/R tests looks like it will be soon ended.
What is worrying though is that the fact such schemes have worked may well mean that hashcash and other CPU payment schemes are not viable either. The senders could run a java component on the porn viewers machine to generate message authentication ids.
Looking for an Information Security student project suggestion?
Try http://dotcrimeManifesto.com/
If the captcha contained a background of additional instructions such as "To get your free account, please type in www.free-email.com/username/captchawords", then it would prevent the porn site/ spammer from seeing the results.
Two wrongs don't make a right, but three lefts do.
That's genius. Much as I hate spammers, I have to admire this very clever solution.
We *just* added captcha functionality at spamgourmet but we're using a random number at the end of each quizword, and we use a random filename for each image. The code just went up on sourceforge if you want to take a look.
who's moderating the meta-moderators?
I have given up that this point and as of today I am switching the email system so that all new users must be paid users. These spammers are like a swarm of locust consuming everything in their path, and now they have destroyed the free service I had been offering for years. I wish they were in the US so I could pursue legal action.
-----
Free P2P Backup, Windows & Linux
I believe what the grandparent was saying is that when you sign up for porn, the bot starts the email account sign up process. There's a short delay (for you) while the bot grabs the glyph and sends it to be displayed on your page. You enter it, then the bot immediately attempts to complete the email account sign up process. If the word is correct, you're given a success page, and if not the bot gives you another glyph to decipher.
This process won't add much at all to the time it takes to sign up for an email account, so reducing the expiration time won't solve the problem. It only helps if the bot has already started the email account sign up (a long time) before you start the porn sign up process.
It's quite clever.
It's nothing but crumpled porno and Ayn Rand.
Sure, give credit, but not to spammers. Manuel Blum, who invented CAPTCHA, came to speak at my school. First, he explained CAPTCHA. Then he explained how to beat it. The idea is called 'stealing cycles'. In his version, the CAPTCHA tests would be part of games rather than porn sites, but the concept is the same.
http://yetanotherpoliticalrant.blogspot.com