WebApp Sec mailing list archives
Re: CAPTCHA
From: Robin Wood <robin () digininja org>
Date: Tue, 25 Jan 2011 15:37:07 +0000
On 25 January 2011 07:22, Sacks, Cailan C <Cailan.Sacks () standardbank co za> wrote:
Stupid idea. A spammer sees funky implementations of web forms every day, and they patch their bots accordingly. There is no security in obfuscation, just buys you time until someone beats you over the head. Google captcha. They do the work and you reap the benifit. Can't get easier.
Depends on your users. I know loads of people who turn off when they see CAPTCHAs as they have trouble reading them and find them a pain to try to decipher. I know that this method isn't perfect but the way I see it is that if a bot writer wants to modify their spider just to get it to work with my site then they are going to be sending me spam anyway one way or another as they have me as a specific target. Traditional CAPTCHAs have also been cracked, I don't know about Googles but I'd imagine that the bot writers will be putting more effort into improving their systems to get around them than to worry about hitting a few sites. One last thing, why would you call this obfuscation? I see it as just another way to implement a system. Robin
-----Original Message----- From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On Behalf Of Steve Syfuhs Sent: Tuesday, January 25, 2011 3:05 AM To: Robin Wood; Shang Tsung Cc: webappsec () securityfocus com Subject: RE: CAPTCHA This is a brilliant idea. Did you come up with it? If not, got any resources? Sent from my Windows Phone -----Original Message----- From: Robin Wood Sent: Monday, January 24, 2011 7:49 PM To: Shang Tsung Cc: webappsec () securityfocus com Subject: Re: CAPTCHA On 24 January 2011 15:11, Shang Tsung <shangtsung71 () gmail com> wrote:We are planning to use a CAPTCHA in order to stop spam engines from filling our Online Forms. From a quick research I made, I found there are good and there are bad types of CAPTCHA. Does anyone know if there are any standard and secure implementations of CAPTCHA that we can use? Any good articles on the subject?I hate captchas, always have so I use a reverse captcha on sites that I build. You add a field to the form with name and id of email. You then give it a label that says "Please leave blank" and hide them both with CSS. Most people won't see them because the CSS works, even if they do see them they read the message and obey. Spam engines on the other hand spot the email field and happily fill it in. You then silently drop any contact forms with values in the email field. Normal humans aren't affected and you trick most generic bots. Robin This list is sponsored by Cenzic -------------------------------------- Let Us Hack You. Before Hackers Do! It's Finally Here - The Cenzic Website HealthCheck. FREE. Request Yours Now! http://www.cenzic.com/2009HClaunch_Securityfocus -------------------------------------- This list is sponsored by Cenzic -------------------------------------- Let Us Hack You. Before Hackers Do! It's Finally Here - The Cenzic Website HealthCheck. FREE. Request Yours Now! http://www.cenzic.com/2009HClaunch_Securityfocus -------------------------------------- Standard Bank email disclaimer and confidentiality note Please go to http://www.standardbank.co.za/site/homepage/emaildisclaimer.html to read our email disclaimer and confidentiality note. Kindly email disclaimer () standardbank co za (no content or subject line necessary) if you cannot view that page and we will email our email disclaimer and confidentiality note to you.
This list is sponsored by Cenzic -------------------------------------- Let Us Hack You. Before Hackers Do! It's Finally Here - The Cenzic Website HealthCheck. FREE. Request Yours Now! http://www.cenzic.com/2009HClaunch_Securityfocus --------------------------------------
Current thread:
- CAPTCHA Shang Tsung (Jan 24)
- Re: CAPTCHA Robin Wood (Jan 24)
- RE: CAPTCHA Maxim Macovei (Jan 24)
- Re: CAPTCHA Marcel Grabher (sallas) (Jan 24)
- RE: CAPTCHA Sacks, Cailan C (Jan 26)
- <Possible follow-ups>
- RE: CAPTCHA Steve Syfuhs (Jan 24)
- RE: CAPTCHA Sacks, Cailan C (Jan 26)
- Re: CAPTCHA Robin Wood (Jan 26)
- RE: CAPTCHA Sacks, Cailan C (Jan 26)
- RE: CAPTCHA Sacks, Cailan C (Jan 26)
- Re: CAPTCHA Robin Wood (Jan 26)
- RE: CAPTCHA Rod Divilbiss (Jan 26)
- Re: CAPTCHA arvind doraiswamy (Jan 26)
- Re: CAPTCHA Robin Wood (Jan 27)
- The Root Cause of CAPTCHA (was Re: CAPTCHA) elbbit (Jan 29)
- Re: CAPTCHA BlackHawk (Jan 26)