Quote:
Originally Posted by Alexander Turcic
One of the most popular spam tools is XRumer. From what's been said elsewhere and from what we've seen, CAPTCHAs like ReCaptcha can be cracked, either automatically (through OCR/averaging) or semi-automatically (through third parties who offer the solving of captures within seconds through APIs). Text-captchas, too, are easily cracked. From what we've seen, users of said spam tools were given credits for any solved text-captcha that is then stored in a global database. Easy permutation (simple math problems changing digits) is also solved by the tool.
|
Very interesting! I just had my own
custom-written capcha cracked a few days ago, and this explains the motivation and method of the crackers. i've got ideas for improvements, but it will be cat and mouse. It's sad that people resort to this. Anything for a buck. Thank you, Alex!
[Edit 15 Aug 2013: Turns out my capcha was not cracked. I had a "hole" in my entry form so that it could be submitted without the capcha and still be accepted. I've patched it.]