Bot breaks Hotmail's CAPTCHA in 6 seconds
- 14 April, 2008 08:26
- Comments
A new bot can crack defenses erected by Microsoft to keep spammers from creating large numbers of accounts on its Live Hotmail service within seconds, a security researcher said Friday.
Dan Hubbard, vice president of security research at Websense, said the bot broke Live Hotmail's CAPTCHA (Completely Automated Public Turing Test to Tell Computers and Humans Apart) within six seconds, on average. CAPTCHA is the name given to the distorted, scrambled characters that many Web services require users to decipher and type in to create a new account; the tests are meant to block automated account registration by spammers and malware authors.
The bot, Hubbard acknowledged, is similar to one Websense uncovered in February.
"In the past, though, it was kind of questionable whether the CAPTCHA breaking was automated," Hubbard said Friday, noting that there had been some evidence that spammers were paying people to decode and type in the CAPTCHA characters. "But the bot's breaking [CAPTCHA] in six seconds, so it's definitely automated."
In a long post to the Websense blog Thursday, Sumeet Prasad -- "our CAPTCHA expert," said Hubbard -- provided technical details of how the bot automatically registers Live Hotmail accounts and then immediately begins using those accounts to spew spam.
The bot's total response time -- how long it takes the program to grab a CAPTCHA image, analyze it and return with the correct code -- is considerably shorter than that of earlier such bots, said Prasad in the blog.
One in every eight to 10 attempts to create a Live Hotmail account is successful, added Prasad, meaning that the success rate is 10 per cent to 15 per cent. However, the rate is actually meaningless, said Hubbard, since the bot will continue to try to create accounts using a predetermined list of account names until they're all registered.
Copies of the bot are seeded on unsuspecting users' PCs, said Websense, making it less likely that Microsoft will detect and stop the automated account registrations.
Free Web-based e-mail services such as Live Hotmail, Yahoo Mail and Gmail are favorite targets for spammers because the services' domains can't be blocked by blacklisting antispam tools, Hubbard said. "When Google, Microsoft and Yahoo [domains] are in the top 10 or top 20 spam domains, it's hard to use reputation tools," said Hubbard.
"You're not going to block those [domains]."
- Bookmark this page
- Share this article
- Got more on this story? Email TechWorld
- Follow TechWorld on twitter
- Virtual Certainty - Best Practices for Gaining Monitoring Clarity in VMware Environments
- Delivering Tomorrow's Backup and Recovery Infrastructure
- Data Center Physical Infrastructure: Optimising Business Value
- Security Threat Report 2012
- Blurring boundaries: The disappearing gap between work and home life
-
Coalition NBN better or worse?
-
CSIRO develops hands-free technology for mining repairs
-
Broadband Forum to improve IPTV performance with new spec
-
Amazon Web Services moves backups to cloud with new appliance
-
Callforfree.net.au offers free calls to 70 countries
-
Teach Yourself Visually Windows 7
-
Windows 7 for Dummies®
-
Office 2007 All-In-One Desk Reference for Dummies
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Microsoft Office
-
MYOB Software for Dummies 6E Australian Edition
-
Computers for Seniors for Dummies, 2nd Edition
-
Windows 7 for Dummies® Dvd+book Bundle
-
Windows 7 for Seniors for Dummies®








Comments
Post new comment