Slashdot Mirror


Porn Rewards Users To Get Past Anti-Spam Captchas

Stalke writes "Spammers are now usings a new technique to circumvent the 'captchas,' the distorted text in graphics, that users must input to receive the free email account. The spammers have cracked the system by displaying the 'captchas' on free porn sites in real time. Since there are always a large number of people signing up for free porn, they do the work of decripting the 'captchas' which is then replayed back into the spammers program to create a new email account. Who thought that porn could be a hacking technique!" Sure sounds plausible, though the link here says only "someone told me."

13 of 420 comments (clear)

  1. Easily countered by Yggdrasil42 · · Score: 4, Interesting

    This can be easily countered if the free e-mail sites configure their servers, so that the 'captchas' can only be loaded into pages that they've served themselves.

    I'm not sure how that works, but I've seen it in action on some sites.

    Maybe someone else knows how it's done?

  2. Countermeasure... by LinuxParanoid · · Score: 3, Interesting

    If the image ...has been inlined from Yahoo or Hotmail... as the article says, couldn't Yahoo/etc have their image generation scripts setup dynamically to check the referrer (or should I say referer? ;-)).

    I seem to recall this approach being used by online comic strips trying to prevent inline linking from elsewhere...

    --LP

  3. Re:Sounds like rubbish by superwiz · · Score: 5, Interesting

    Catchups are constantly designed to be undecodable by OCR. But the porn solution doesn't sound like rubbish at all. It actually sounds quite clever. Here's how it might work: 1.An automated script tries to sign up for public emails (yahoo, hotmail, etc.). 2.At some stage during sign up a page with a catchup is "presented" to the script. 3.The script gets the catchup out of the page and adds it to a pool of catchups to be associated with their perspective words. 4. At some point, shortly after, a visitor to a porn site is presented with a catchup and enters the correct word. THIS IS, BY THE WAY, A PERFECT WAY TO FOIL SPAMMERS AND TO STILL GET YOUR PORN -- since the porn site doesn't, in fact, know what the catchup is supposed to be and is only using you, enter a wrong one. 5. The word entered by the user on the porn site is used to submit a reply to the public email system.

    --
    Any guest worker system is indistinguishable from indentured servitude.
  4. Computer Program by UPAAntilles · · Score: 4, Interesting

    The computer science department at Berkeley has already broken the Yahoo-like Captcha. They use an algorithm to break it. They recommend "Gimpy" as a replacement, which their software has yet to crack. The blog is full of crap, the captcha is generated every session, so you can't make a link to the image like they would like because the session would end.

  5. Re:Nifty by acidtripp101 · · Score: 4, Interesting

    I thought this exact same thing. Every time I see a simple 'sollution' to a 'problem' like this, I always have to give the creator credit due to them... I don't care whether it's for the linux kernel or to send me pills for a larger penis, it's still ingenious.

    --
    Not Free(as in beer). Free(as in "I'm free to beat you over the head for being a dumbass")
  6. Re:good or evil by mlush · · Score: 3, Interesting
    Now if we could only get spammers to use their ingenuity for good rather than evil, we could solve all of the worlds problems.

    I could see this working for some image recognition problems. To get the next page you have to perform some small task. Salt the tasks with 10% control images for which you know the answer and a finders fee where you get a weeks free access if you find X or do Y work units. Could be used in to check survalance video images ...

  7. Re:Spam spam spam spam SPAAM! by Zeinfeld · · Score: 3, Interesting
    What are we going to do?

    I think half of us are going to flame on slashdot and the other half will go off to find the web site where you can get the free porn.

    I hate these C/R schemes, they are OK when they are used for mailing lists or for checking signups to Yahoo! mail or some other forum where the intent is to protect ME. I do not accept that they are at all legitimate when the only purpose is to protect some dweeb who thinks he is really important.

    Worst of all are the systems that send out C/R challenges in response to email that was a reply to something that the challenger sent. I get students asking me some question about a Web spec or something else I did. I spend time writing an answer and then get a C/R challenge. Like some student's time is much more important than mine...

    Worst of all are the C/R systems that don't whitelist after the first challenge. Dan Bernstein is the worst offender here, I answered three of his challenges and still get his robot if I make the mistake of replying to one of his mails to me. So I have his robot blacklisted in my email.

    So on balance I am not at all sad that the nuisance of C/R tests looks like it will be soon ended.

    What is worrying though is that the fact such schemes have worked may well mean that hashcash and other CPU payment schemes are not viable either. The senders could run a java component on the porn viewers machine to generate message authentication ids.

    --
    Looking for an Information Security student project suggestion?
    Try http://dotcrimeManifesto.com/
  8. Countermeasure: URL in Image by G4from128k · · Score: 3, Interesting

    If the captcha contained a background of additional instructions such as "To get your free account, please type in www.free-email.com/username/captchawords", then it would prevent the porn site/ spammer from seeing the results.

    --
    Two wrongs don't make a right, but three lefts do.
  9. Wow by Illserve · · Score: 3, Interesting

    That's genius. Much as I hate spammers, I have to admire this very clever solution.

  10. just added captcha by jqh1 · · Score: 4, Interesting

    We *just* added captcha functionality at spamgourmet but we're using a random number at the end of each quizword, and we use a random filename for each image. The code just went up on sourceforge if you want to take a look.

    --
    who's moderating the meta-moderators?
  11. Re:Sounds like rubbish by Tim+Macinta · · Score: 4, Interesting
    I have been letting people set up free email accounts at kmfms.com for awhile, and there has been an abnormally large surge in new accounts recently (and the sign-up process does use the distorted letters). These have been junk accounts too. I had a huge number of sign-ups just last night and only 1 person actually came through my site first (the email service is provided by everyone.net, so somebody was evidently going straight there without hitting my site first). Once these junk accounts are created, spammers then send email from their own servers, but with the return address of the junk account. I don't know why they are doing this - I seriously doubt they are checking the accounts, and they aren't actually sending anything from the accounts, but they are doing it nonetheless and I have been getting a lot of complaints recently about spam even though all of the headers inidicate that my network and everyone.net's network wasn't involved.

    I have given up that this point and as of today I am switching the email system so that all new users must be paid users. These spammers are like a swarm of locust consuming everything in their path, and now they have destroyed the free service I had been offering for years. I wish they were in the US so I could pursue legal action.

  12. Re:Sounds like rubbish by IthnkImParanoid · · Score: 3, Interesting

    I believe what the grandparent was saying is that when you sign up for porn, the bot starts the email account sign up process. There's a short delay (for you) while the bot grabs the glyph and sends it to be displayed on your page. You enter it, then the bot immediately attempts to complete the email account sign up process. If the word is correct, you're given a success page, and if not the bot gives you another glyph to decipher.

    This process won't add much at all to the time it takes to sign up for an email account, so reducing the expiration time won't solve the problem. It only helps if the bot has already started the email account sign up (a long time) before you start the porn sign up process.

    It's quite clever.

    --
    It's nothing but crumpled porno and Ayn Rand.
  13. Re:Nifty by kramer2718 · · Score: 5, Interesting

    Sure, give credit, but not to spammers. Manuel Blum, who invented CAPTCHA, came to speak at my school. First, he explained CAPTCHA. Then he explained how to beat it. The idea is called 'stealing cycles'. In his version, the CAPTCHA tests would be part of games rather than porn sites, but the concept is the same.