ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    Spammers beat new Microsoft CAPTCHA defences

Compromised Microsoft accounts are very valuable to spammers, which means that they’ll constantly try and break in using new techniques.

By Asavin Wattanajantra, 16 Feb 2009 at 15:54

Security firm Websense has claimed that new CAPTCHA techniques reworked by Microsoft at the end of last year have already been busted by spammers.

CAPTCHA (Completely Automated Public Turing Test to tell Computers & Humans Apart) was developed in 2000 to stop spam robots. Websense said that recent Microsoft efforts to rework it and achieve a balance between security and usability had failed.

The problem was that every time Microsoft tried to implement CAPTCHA changes to prevent spammers from breaking in and getting control of accounts, the criminals managed to adapt and beat them.

Some of the changes which Microsoft made to CAPTCHA involved disguising individual letters to prevent character recognition technology from working.

Carl Leonard, threat researcher at Websense, said that the firm wasn’t totally sure of what systems the scammers were employing to break into the CAPTCHA, but suspected that it was automated due to the success the spammers were having and the duration it was took to sign up an account.

“This particular attack is using encryption between the compromised machine and the bot server. They are aiming to go for the CAPTCHA for the same reasons as previously, piggy backing on the reputation of Live.com email accounts," he said.

“They can then use other Microsoft services such as Live Spaces to host malicious firewalls as well.”

Leonard said that Microsoft were reacting to the problem, but said compromised accounts were so valuable to spammers that they would always try and get around any new defences. As Microsoft property, security vendors could not blacklist the accounts.

Leonard said: “It’s a very difficult one. There are experiments with other types of CAPTCHA systems that don’t really just on letters.

“Perhaps using visual images, humans would be able to recognise what these were. It could be another layer to the CAPTCHA is required.”

Microsoft has not responded to a request for comment by time of writing.

Email to a friend

Print this page

< Previous   Security : News Next >

Be the first to comment on this article

You need to Login or Register to comment.

    You may also like...

 Sponsored Links

advertisement

    You may also like...

advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement