Slashdot Mirror


Porn Rewards Users To Get Past Anti-Spam Captchas

Stalke writes "Spammers are now usings a new technique to circumvent the 'captchas,' the distorted text in graphics, that users must input to receive the free email account. The spammers have cracked the system by displaying the 'captchas' on free porn sites in real time. Since there are always a large number of people signing up for free porn, they do the work of decripting the 'captchas' which is then replayed back into the spammers program to create a new email account. Who thought that porn could be a hacking technique!" Sure sounds plausible, though the link here says only "someone told me."

17 of 420 comments (clear)

  1. I am not looking at porn by hetairoi · · Score: 5, Funny

    I'm hacking ..... now go away, what I'm doing in here is private.

    --
    you're all figments of my deranged imagination
  2. Nifty by turbofisk · · Score: 5, Funny

    I'm not for spamming... But if I were a spammer... I would pat myself on my back... Pretty nifty... Bastards!

    1. Re:Nifty by kramer2718 · · Score: 5, Interesting

      Sure, give credit, but not to spammers. Manuel Blum, who invented CAPTCHA, came to speak at my school. First, he explained CAPTCHA. Then he explained how to beat it. The idea is called 'stealing cycles'. In his version, the CAPTCHA tests would be part of games rather than porn sites, but the concept is the same.

  3. Proof! by RiscIt · · Score: 5, Funny


    Proof once again that porn (and it's usually associated activities... ahem) will NOT make you go blind!

  4. Re:Foundation by krumms · · Score: 5, Funny

    It has more uses then we can even imagine.

    And several uses that we just don't WANT to imagine :P

  5. In related news... by Black+Parrot · · Score: 5, Funny


    A million new Slashdot accounts were added today.

    --
    Sheesh, evil *and* a jerk. -- Jade
  6. Re:Easily countered by Violet+Null · · Score: 5, Informative

    Wouldn't matter.

    Automated spam script goes to sign up new email address, gets presented captcha. Downloads captcha -- as the server would expect any normal web browser to do.

    Captcha is copied to some location. Filename probably contains information that can identify the specific script that's running, since there'll undoubtedly be many going simultaneously.

    From that point, there's about 20 minutes, give or take, for the porn site to display the copy of the captcha and ask for the user's input. On a site seeing any amount of traffic at all, that should be more than enough.

    Once a user has given input, the spam script is notified, and sends the input back to the captcha server. The captcha server never sees the IP address of the human -- it only deals with the spam script -- so it'll never know anything's up.

  7. It really is true by The+Night+Watchman · · Score: 5, Funny

    Someone told me once that most technologies that have become successful are those technologies that assist in the dissemination of porn and/or voyeurism. Thinking about it, that's very true. Radio gave way quickly to television, which gave way to cable, and BAM! You get porn. Radio also gave way to the telephone, which gave way to party lines, and BAM! Advances in optics have brought us photography (BAM!), telescopes (BAM!), and eyeglasses (the... the porn is so CLEAR now!), to name a few. Look at the primary achievement of the 90s. The commercialization of the Internet. That's essentially a porn revolution!

    So porn is being used to break encryption. Personally, I feel there can be no other way. Porn will lead us to the greatest achievements of our day, and conversely, all roads lead to porn.

    It's our past, our present, and our future. Embrace it, or be left behind.

    --
    "Every jumbled pile of person has a thinking part that wonders what the part that isn't thinking isn't thinking of"-TMBG
  8. Re:Spam spam spam spam SPAAM! by thedillybar · · Score: 5, Insightful
    What are we going to do?

    How about type something other than what's in the box? I seriously doubt you have to sit there waiting while it verifies that what you entered is actually correct. They're probably just assuming most people will type it correctly.

  9. Re:Sounds like rubbish by superwiz · · Score: 5, Interesting

    Catchups are constantly designed to be undecodable by OCR. But the porn solution doesn't sound like rubbish at all. It actually sounds quite clever. Here's how it might work: 1.An automated script tries to sign up for public emails (yahoo, hotmail, etc.). 2.At some stage during sign up a page with a catchup is "presented" to the script. 3.The script gets the catchup out of the page and adds it to a pool of catchups to be associated with their perspective words. 4. At some point, shortly after, a visitor to a porn site is presented with a catchup and enters the correct word. THIS IS, BY THE WAY, A PERFECT WAY TO FOIL SPAMMERS AND TO STILL GET YOUR PORN -- since the porn site doesn't, in fact, know what the catchup is supposed to be and is only using you, enter a wrong one. 5. The word entered by the user on the porn site is used to submit a reply to the public email system.

    --
    Any guest worker system is indistinguishable from indentured servitude.
  10. Re:Sounds like rubbish by Z-MaxX · · Score: 5, Informative
    Two reasons this sounds like rubbish: The catchups are generated on a per session basis for the person trying to sign up for the email address . Surely if they then try and get a third party to do the decoding the session will be expired.
    Not neccesarily. From the writeup:
    by displaying the 'captchas' on free porn sites in real time.
    If you have thousands of visitors every hour, then you only have to wait a few seconds on average to have your image shown to a user and a few more seconds for the user to respond.
    --
    Dr Superlove 300ml. I use my powers for awesome
  11. Holy crap by osgeek · · Score: 5, Funny

    They've harnessed the power of horniness, but for evil. If only that unlimited power could be harnessed for good -- it would be like having controlable fusion and all of the heavy water we'd ever need.

    Amazingly clever, those evil spamming bastards.

  12. Re:Spam spam spam spam SPAAM! by Anonymous Coward · · Score: 5, Insightful

    Why sign up for porn? Damn, isn't there enough available without signing up? It's bad enough that they can match your IP address; why give them registration info too? It's hysterical that a bunch of geeks who won't sign up to read the New York Times will gladly give name, rank, and serial number for porn.

  13. Re:Foundation by chaoticset · · Score: 5, Funny
    "Porn...is there anything it can't do?"

    Sorry.

    --

    -----------------------
    You are what you think.
  14. Old news and incorrect data by shaftek · · Score: 5, Informative

    This is ancient news, it has been mentioned by me on the ASRG list in November and on my blog. The original new article was published by the Post Gazette, and found by Matt McCay in his blog. Liudvikas Bukys mentioned it in his blog also. You might also want to take a look at the W3C draft on why these visual tests do not work for disabled people. And to end this off, the basic premise of C/R is that the return address is valid. Even if spammers break these visual tests, in order to do that, they must have a valid return address - ergo, making them traceable.

  15. I'm afraid I disagree by fejikso · · Score: 5, Insightful

    I thought that'w why there's something called ethics, which tells you when an ingenious thing may be good or bad.

    IMHO, you can't applaud unethical uses of ingenuity.

  16. Re:Foundation by Dyolf+Knip · · Score: 5, Funny
    It surrounds us, penetrates us, and binds the galaxy together.

    Well, one out of three ain't bad.

    --
    Dyolf Knip