Beefy Boxes and Bandwidth Generously Provided by pair Networks
laziness, impatience, and hubris
 
PerlMonks  

Re: howto: Perl CGI, image with random scewed text for account creations

by Phaysis (Pilgrim)
on Mar 16, 2007 at 07:06 UTC ( [id://605108]=note: print w/replies, xml ) Need Help??


in reply to howto: Perl CGI, image with random scewed text for account creations

There's no doubting it; captchas are ultimately hackable and as such are not much of a defense against the determined. The spammer's workaround scenario (which is in practice as we speak) goes like so:
  1. An unscrupulous spammer finds a board or guestbook (the victim) that has been protected by a captcha.
  2. He trains a spambot to the victim's form.
  3. Somewhere on another site (the bait, also run by the spammer), some user (an unknowing agent) manually clicks for a form to post something to that site.
  4. The bait site calls the spambot which grabs a form from the victim site, fills it with spam, pulls the URL of the captcha image served with the victim form, and feeds that captcha URL in the bait's form.
  5. The unknowing agent fills the bait form, decodes the captcha (which appears to come from the bait site), and submits.
  6. The bait site passes the captcha code to the spambot and then goes about its business.
  7. The spambot then adds the final captcha piece to the puzzle and submits the spam-filled form to the victim site
You folks are correct to say it is an arms race. There are several tacts one could take to forego any nefariousness, but rest assured that if the stakes are high enough the forgoing will be foregone.

Never take your eye off the smart bully.

(Ph) Phaysis (Shawn)
If idle hands are the tools of the devil, are idol tools the hands of god?

  • Comment on Re: howto: Perl CGI, image with random scewed text for account creations

Log In?
Username:
Password:

What's my password?
Create A New User
Domain Nodelet?
Node Status?
node history
Node Type: note [id://605108]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this?Last hourOther CB clients
Other Users?
Others taking refuge in the Monastery: (3)
As of 2025-06-16 03:36 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?

    No recent polls found

    Notices?
    erzuuliAnonymous Monks are no longer allowed to use Super Search, due to an excessive use of this resource by robots.