Thursday, April 27, 2006

How spammers are beating CAPTCHA.

(Ok this is not exactly SEO, but then I know you would be interested in this).
Just in case you donot know CAPTCHA is Completely Automated Public Turing test to tell Computers and Humans Apart.

Captcha are the pictures containing words you have to spell before you can post a comment in blogs, write something on digg or make a free mail account.
Now spammers need a lot of free email account. They want to comment spam your blog. For this they need to beat the captcha.
Spammers are beating captcha in two ways. Unless the image is very blurred/grainy iage processing software can be used to get the words in them. The guy at http://www.mperfect.net/aiCaptcha/
gives an example of how captcha can be beaten using software. But there is an even better way. Social Engineering.
What is the internet most used for? I donot have the statistics, but I am willing to bet that PORN is right there at the top. And what is even better than porn? Free porn, obviously.
When Mr. BigSpammer needs to break a million captchas he makes a tie up with BigFreePornSite.com. His software gets the captcha images and sends them to BigFreePornSite.com. When Joe TeenHighOnSex visits BigFreePornSite.com he asked to post the text in captcha image which is sent to Mr. BigSpammer's servers. Lo, the captcha is broken. Now Mr. Big Spammer can comment spam, digg spam, yahoo spam.

2 comments:

Sarah said...

If you have the traffic, and the porn industry would, I can so see that system working.

But does it work, has it been tested, and is the porn industry doing it.

Well, I guess they are now :)

shabda said...

Yes it is working, there is just too much money in it for it to not work.
How much programming does it require to parse the captcha image out of the page and get it to your server and ask an unsuspecting Joe TeenHighOnSex to decode it.
The porn industry has low clicktroughs as it is, so it is a novel way to get so fast money.