Hotmail CAPTCHA: cracked in 20 seconds
By Davey Winder in Editorial
Posted in Data Protection, Spam, Security, Microsoft on
Although many people would like you to believe otherwise, the Completely Automated Public Turing test to tell Computers and Humans Apart (better known as CAPTCHA) is not foolproof. Yahoo! knows this, Google knows this, and now it would look like Microsoft knows it as well.
According to security researcher Sumeet Prasad at Websense the Microsoft Live Hotmail service CAPTCHA system has been busted wide open.
This is made all the more embarrassing for Microsoft courtesy of one small detail: just a few short months ago Microsoft had redesigned the CAPTCHA authentication it uses in order to prevent automated bot registration.
According to Websense “As the latest attack shows, those efforts have failed.” Its research suggests that the kind of anti-CAPTCHA attacks Microsoft is feeling are part of a strategy of escalation on the part of the spammer gangs in order to ensure that they can continue to exploit Microsoft branding and trust in order to sell their wares.
Worryingly, it appears that this latest attack is not the usual automated bot account creation system using command and control templates, but instead a much more sophisticated effort involving automated but encrypted communications between the spammer bots and compromised machines in order to secure the cracking attempts. Well, I say attempts but I mean successes. According to Prasad the success rate in converting a CAPTCHA cracking attempt into a fully active Live Hotmail account is as high as 20 percent. That’s one in every five attempts being successful.
If that were not frightening enough, it takes just 20 seconds from start to finish to do the cracking.
A full step by step expose of the technology and techniques employed can be found here.
Comment by - March 19, 2009 on 10:09 am
Whythey have changed the CAPTCHA system… what’s the reason… how to crack hotmail CAPTCHA…
Comment by - March 19, 2009 on 10:10 am
Why they have changed the CAPTCHA system… what’s the reason… how to crack hotmail CAPTCHA…
Pingback by - October 5, 2009 on 11:56 pm
[…] fell victim to spammer gang hacking attention earlier in the year. I wrote a piece on IT Pro called Hotmail CAPTCHA: cracked in 20 seconds at the […]
Comment by buy anabol tablets - April 2, 2011 on 5:26 pm
Sounds good, I like to read your blog, just added to my favorites ![]()
Comment by forex automoney reviews - April 8, 2011 on 8:40 pm
As a Newbie, I am always searching online for articles that can help me. Thank you Wow! Thank you! I always wanted to write in my site something like that. Can I take part of your post to my blog?
Make a comment
Tag cloud
Archives
- June 2010
- May 2010
- April 2010
- March 2010
- February 2010
- January 2010
- December 2009
- November 2009
- October 2009
- September 2009
- August 2009
- July 2009
- June 2009
- May 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- October 2007
- September 2007
- August 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
- February 2007
- January 2007
- December 2006
- November 2006
- October 2006
- September 2006
- August 2006
Most commented posts
- 80 percent of viruses love Windows 7
165 comments
- Has Microsoft gone mental?
- Has the US Army declared war on Windows 7?
- Cuil frozen out: market share drops to next to nothing
- Xbox 360 FAIL
- The 24GB RAM Desktop is born
- Use old version of Windows instead of Linux, says teacher
- Microsoft reveals time-based licensing model
- How Marblecake Hacked Time
- Nexus Two - The Next Generation
Highest Rated Blog Posts
- Why ecommerce fails (100%)
- Google Chrome stands alone at PWN2OWN (100%)
- Betting on Hubdub technology (100%)
- Has Google gone insane as GMail goes back to beta? (100%)
- Chinese whispers as government implicated in UK hack attacks (100%)
- Crimeware toolkit targets 10,000 trusted sites (100%)
- Black Hat risk to migrating VMs (100%)
- Tough on cyber crime, tough on the causes of cyber crime (100%)
- Firefox 3, Beta 4, Enhancements 900, Tested 5 (100%)
- Has the US Army declared war on Windows 7? (100%)

