Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Bugtraq: Bugtraq

Defeating audio captcha systems

 

 

Bugtraq bugtraq RSS feed   Index | Next | Previous | View Threaded


josem.palazon at gmail

Jan 14, 2008, 10:01 PM

Post #1 of 2 (630 views)
Permalink
Defeating audio captcha systems

Hi all,

Some days ago I wrote an advisory which demonstrates how the Peter's
Math Antispam Spinoff plugin for wordpress
(http://www.theblog.ca/math-anti-spam) can be defeated by its audio file.

It's hard to summarize, you better read the advisory, but in a very
small nutshell, the flaw its about not using any kind of distortion on
the audio clip, which makes it easily identificable by a script.

Here is the link:

http://docs.google.com/View?docid=df36cd52_19xzmkwqcg

I'm sure you will find the advisory inspirational, as the approach is
applicable to many other capthas, and anti-script methods.

Regards

Jose


3APA3A at SECURITY

Jan 15, 2008, 2:33 PM

Post #2 of 2 (589 views)
Permalink
Re: Defeating audio captcha systems [In reply to]

Dear Jos?e M. Palazon Romero,

This approach is not new, it was demonstrated by ShAnKaR
<shankar_(at)_shankar.name> against Simple Machines Forum 1.1.2 in June,
2007.

See:
http://securityvulns.ru/Rdocument271.html (in Russian)
http://securityvulns.ru/files/capcha.pl (Exploit code)
http://www.securityfocus.com/archive/1/archive/1/471641/100/0/threaded

--Tuesday, January 15, 2008, 9:01:03 AM, you wrote to bugtraq [at] securityfocus:


JeMPR> Hi all,

JeMPR> Some days ago I wrote an advisory which demonstrates how the
Peter's
JeMPR> Math Antispam Spinoff plugin for wordpress
JeMPR> (http://www.theblog.ca/math-anti-spam) can be defeated by its
audio file.

JeMPR> It's hard to summarize, you better read the advisory, but in a
very
JeMPR> small nutshell, the flaw its about not using any kind of
distortion on
JeMPR> the audio clip, which makes it easily identificable by a script.

JeMPR> Here is the link:

JeMPR> http://docs.google.com/View?docid=df36cd52_19xzmkwqcg

JeMPR> I'm sure you will find the advisory inspirational, as the
approach is
JeMPR> applicable to many other capthas, and anti-script methods.

JeMPR> Regards

JeMPR> Jose



--
~/ZARAZA http://securityvulns.com/
Человек это тайна... я занимаюсь этой тайной чтобы быть человеком. (Достоевский)

Bugtraq bugtraq RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.