Porn Rewards Users To Get Past Anti-Spam Captchas
Stalke writes "Spammers are now usings a new technique to circumvent the 'captchas,' the distorted text in graphics, that users must input to receive the free email account. The spammers have cracked the system by displaying the 'captchas' on free porn sites in real time. Since there are always a large number of people signing up for free porn, they do the work of decripting the 'captchas' which is then replayed back into the spammers program to create a new email account. Who thought that porn could be a hacking technique!" Sure sounds plausible, though the link here says only "someone told me."
I'm hacking ..... now go away, what I'm doing in here is private.
you're all figments of my deranged imagination
Porn, the foundation of the internet. It will never go away or die. It has more uses then we can even imagine.
Evolution or ID?
I'm not for spamming... But if I were a spammer... I would pat myself on my back... Pretty nifty... Bastards!
Proof once again that porn (and it's usually associated activities... ahem) will NOT make you go blind!
What is everyone in the Slashdot crowd gonna do? On one hand you dont want to get spammed, but on the other hand you NEED your pr0n. However, i think this will take care of itself because eventually people will be too busy deleting spam to look at pr0n online, reducing the amount of spam....Ok, i'm half kidding, but i really do think this is an ingenius way of spammers getting around certain barriers. Say what you will, but spammers have shown/proven that they can overcome many obstacles to continue their spamming.
Two reasons this sounds like rubbish: The catchups are generated on a per session basis for the person trying to sign up for the email address . Surely if they then try and get a third party to do the decoding the session will be expired. Also The article points out that Optical Character recognition is more than adequate to break this so I can not see a situation that spammers would do this elaborate probably unworkable method over OCR. No facts and a friend of a friend source makes this sound like total BS.
The internet makes me stupid.
This can be easily countered if the free e-mail sites configure their servers, so that the 'captchas' can only be loaded into pages that they've served themselves.
I'm not sure how that works, but I've seen it in action on some sites.
Maybe someone else knows how it's done?
For your captcha, use a picture of a really ugly old woman with "click here to see more" written across it, and no one visiting a porn site will help with the decryption.
Sheesh, evil *and* a jerk. -- Jade
Is it just me or are people becoming less critical about what a valid news sources is?
'Someone told me...' on a 'blog'?
That doesn't carry quite the weight of the BBC and Reuters to me, but I suppose there's a good chance no-one was threatened by a 'democratic' government during the production of the article, so maybe it's less biased than some.
"Those who cast the votes decide nothing; those who count the votes decide everything." (attrib. Joseph Stalin)
A million new Slashdot accounts were added today.
Sheesh, evil *and* a jerk. -- Jade
If the image ...has been inlined from Yahoo or Hotmail... as the article says, couldn't Yahoo/etc have their image generation scripts setup dynamically to check the referrer (or should I say referer? ;-)).
I seem to recall this approach being used by online comic strips trying to prevent inline linking from elsewhere...
--LP
That method is already in use by several sites that get paid by the number of ad-clicks. To make *dead sure* that the patrons click the banners you have to fill in a missing word in a sentence collected from the banner-site or the 3rd word etc to get into the site.
It's pretty lame, and I guess most ad-agencies frown upon it as the clickers aren't really producing any business..
Someone told me once that most technologies that have become successful are those technologies that assist in the dissemination of porn and/or voyeurism. Thinking about it, that's very true. Radio gave way quickly to television, which gave way to cable, and BAM! You get porn. Radio also gave way to the telephone, which gave way to party lines, and BAM! Advances in optics have brought us photography (BAM!), telescopes (BAM!), and eyeglasses (the... the porn is so CLEAR now!), to name a few. Look at the primary achievement of the 90s. The commercialization of the Internet. That's essentially a porn revolution!
So porn is being used to break encryption. Personally, I feel there can be no other way. Porn will lead us to the greatest achievements of our day, and conversely, all roads lead to porn.
It's our past, our present, and our future. Embrace it, or be left behind.
"Every jumbled pile of person has a thinking part that wonders what the part that isn't thinking isn't thinking of"-TMBG
The computer science department at Berkeley has already broken the Yahoo-like Captcha. They use an algorithm to break it. They recommend "Gimpy" as a replacement, which their software has yet to crack. The blog is full of crap, the captcha is generated every session, so you can't make a link to the image like they would like because the session would end.
They've harnessed the power of horniness, but for evil. If only that unlimited power could be harnessed for good -- it would be like having controlable fusion and all of the heavy water we'd ever need.
Amazingly clever, those evil spamming bastards.
Why are you letting these clowns ruin our country?
You're right. But. A) you're repeating what the editor already said, and B) you are overstating your case a bit for the following reasons:
In fairness, the poster on the blog was Cory Doctorow, who is a long time, well-known net-citizen and isn't exactly some random guy, although you may not know him. For a sample of his work, see this piece in Salon which mentions that he won the John W. Campbell Award for best new science fiction writer at the 2000 Hugo Awards. He's not a journalist, he's a blogger, but it's an interesting tidbit nonetheless...
And even if he was a random blogger, his credentials are much less important than the core concept he's disclosing: that someone seeking to generate email accounts (or open bank accounts or whatever) could have porn-seeking humans workaround the turing-ish test security measures. The story is less that someone is doing it, than that someone could be doing it. At least to me.
Plus this is a hacker-type story... I wouldn't expect Reuters, etc. to carry it first.
I actually was glad to see the Slashdot editor point out the "someone told me" caveat... it's a sign to me that the editors here are getting better. They're warning us about the weaknesses in the story, not just slapping stuff up here without a care.
--LP
Well I don't have an example of the page, but I do happen to have one of the captcha tests they were using... :)
Click here to decode pr0n captcha
-JT
I could see this working for some image recognition problems. To get the next page you have to perform some small task. Salt the tasks with 10% control images for which you know the answer and a finders fee where you get a weeks free access if you find X or do Y work units. Could be used in to check survalance video images ...
If the captcha contained a background of additional instructions such as "To get your free account, please type in www.free-email.com/username/captchawords", then it would prevent the porn site/ spammer from seeing the results.
Two wrongs don't make a right, but three lefts do.
Rather than guess a single image, how about a feature on the page at random? For example Yahoo Mail can ask "What is the menu to the immediate right of Addresses. (which according to my Yahoo Mail screen would be "Calendar"), Or even "What company is the banner ad up top advertising" which serves 2 purposes 1) Captcha Test and 2) Ensuring the advertising is looked at :-)
Unless a Spammer plans on building a porno site exactly like Yahoo (and incur the wrath of a zillion lawyers consequently), this would be a difficult one to counter attack (unless someone here could prove otherwise). Thoughts?
...in bed
That's genius. Much as I hate spammers, I have to admire this very clever solution.
"Hey, I'm only seeing ugly people having sex!, guess I have to step up the quality of my work"
The grass is only greener, if you don't take care of your own lawn.
We *just* added captcha functionality at spamgourmet but we're using a random number at the end of each quizword, and we use a random filename for each image. The code just went up on sourceforge if you want to take a look.
who's moderating the meta-moderators?
This is ancient news, it has been mentioned by me on the ASRG list in November and on my blog. The original new article was published by the Post Gazette, and found by Matt McCay in his blog. Liudvikas Bukys mentioned it in his blog also. You might also want to take a look at the W3C draft on why these visual tests do not work for disabled people. And to end this off, the basic premise of C/R is that the return address is valid. Even if spammers break these visual tests, in order to do that, they must have a valid return address - ergo, making them traceable.
I thought that'w why there's something called ethics, which tells you when an ingenious thing may be good or bad.
IMHO, you can't applaud unethical uses of ingenuity.
I expect that soon all porn viewing jobs will be outsourced to India.
It's a clever idea (even if nobody has actually done it yet) but I think Captchas will always be ahead in the arms race.
.sig
Cut and paste my Captchas? Ok, I'll embed it in a java program.
Screen capture? I'll make it dependant on the web-site you're visiting.
(which of these objects starts with the same letter as the third letter of my website?)
In the end though, the best a captchas can do is prove there's a human somewhere in the loop.
A spammer (or anyone else for that matter) could hire real people to answer them.
Automate the non-captcha part of the signup, and you could generate several hundred accounts per hour.
-- this is not a