WebApp Sec mailing list archives
RE: Defeating CAPTCHA
From: "Derick Anderson" <danderson () vikus com>
Date: Mon, 29 Aug 2005 08:03:14 -0400
I'm sure there is a significant number of valid credit card numbers floating around in the open, but it is not without bound. An open, free system (which I am not against, by the way) allows spammers to create as many accounts as they wish. Once they have to pay for it, even with stolen credit cards, the availability of accounts drops into a much smaller finite number. Besides, if I have your credit card number, why bother using it to create a spamming account? I've already got free money. =) Derick Anderson
-----Original Message----- From: Devdas Bhagat [mailto:devdas () dvb homelinux org] Sent: Sunday, August 28, 2005 2:35 AM To: webappsec () securityfocus com Subject: Re: Defeating CAPTCHA On 26/08/05 12:45 -0400, Derick Anderson wrote: <snip>1. Charge money. Spammers aren't going to shell out cash en masse.But they are perfectly willing to use _your_ credit card for that. There are a lot of phishing attacks and broken CC# storage and transport systems that some spammers will have access to that data. Devdas Bhagat
Current thread:
- Re: Defeating CAPTCHA, (continued)
- Re: Defeating CAPTCHA Stephen de Vries (Aug 25)
- RE: Defeating CAPTCHA Glenn Euloth (Aug 26)
- Re: Defeating CAPTCHA Christopher Kunz (Aug 31)
- Re: Defeating CAPTCHA Stephen de Vries (Aug 25)
- Re: Defeating CAPTCHA Subs (Aug 26)
- Re: Defeating CAPTCHA Michal Zalewski (Aug 26)
- Re: Defeating CAPTCHA Paul M. (Aug 26)
- Re: Defeating CAPTCHA victor (Aug 29)
- RE: [WEB SECURITY] Re: Defeating CAPTCHA Marian Ion (Aug 29)
- RE: Defeating CAPTCHA Derick Anderson (Aug 26)
- Re: Defeating CAPTCHA Devdas Bhagat (Aug 28)
- RE: Defeating CAPTCHA Derick Anderson (Aug 29)
- RE: Defeating CAPTCHA wilsonc (Aug 29)
- Re: Defeating CAPTCHA Devdas Bhagat (Sep 05)
- RE: Defeating CAPTCHA Derick Anderson (Sep 06)