Bot breaks Hotmail's CAPTCHA in 6 seconds
Spammer's bot beats Microsoft's registration test in no time
Computerworld - A new bot can crack defenses erected by Microsoft Corp. to keep spammers from creating large numbers of accounts on its Live Hotmail service within seconds, a security researcher said today.
Dan Hubbard, vice president of security research at Websense Inc., said the bot broke Live Hotmail's CAPTCHA (Completely Automated Public Turing Test to Tell Computers and Humans Apart) within six seconds, on average. CAPTCHA is the name given to the distorted, scrambled characters that many Web services require users to decipher and type in to create a new account. The tests are meant to block automated account registration by spammers and malware authors.
The bot, Hubbard acknowledged, is similar to one Websense uncovered in February.
"In the past, though, it was kind of questionable whether the CAPTCHA breaking was automated," Hubbard said today, noting that there had been some evidence that spammers were paying people to decode and type in the CAPTCHA characters. "But the bot's breaking [CAPTCHA] in six seconds, so it's definitely automated."
In a long post to the Websense blog yesterday, Sumeet Prasad -- "our CAPTCHA expert," said Hubbard -- provided technical details of how the bot automatically registers Live Hotmail accounts and then immediately begins using those accounts to spew spam.
The bot's total response time -- how long it takes the program to grab a CAPTCHA image, analyze it and return with the correct code -- is considerably shorter than that of earlier such bots, said Prasad in the blog.
One in every eight to 10 attempts to create a Live Hotmail account is successful, added Prasad, so the success rate is 10% to 15%. However, the rate is actually meaningless, said Hubbard, since the bot will continue to try to create accounts using a predetermined list of account names until they're all registered.
Copies of the bot are seeded on unsuspecting users' PCs, said Websense, making it less likely that Microsoft will detect and stop the automated account registrations.
Free Web-based e-mail services such as Live Hotmail, Yahoo Mail and Gmail are favorite targets for spammers because the services' domains can't be blocked by blacklisting antispam tools, Hubbard said. "When Google, Microsoft and Yahoo [domains] are in the top 10 or top 20 spam domains, it's hard to use reputation tools," said Hubbard.
"You're not going to block those [domains]," he said.
Related Blog
Read more about Security in Computerworld's Security Topic Center.
- 10 Hot Big Data Startups to Watch
- 11 Unique Uses for Google Glass, Demonstrated by Celebs
- How to Export Your Google Reader Account
- How to Better Engage Millennials (and Why They Aren't Really so Different)
- Telltale signs of ATM skimming
- 20 security and privacy apps for Androids and iPhones
- Big screen con artists: 7 great movies about social engineering
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- An Interactive eGuide: DDoS Attacks In today's world, Distributed Denial of Service (DDoS) attacks on organizations are becoming more prevalent. The number of attacks are increasingly annually with...
- Cloud Impacts and Outcomes for Business Leaders Learn More
- Wanted: A Trusted Provider for Public Cloud Services Learn how Dell's cloud strategy, built on the highest level of VMware integration and security, is enabling enterprises to get out of the...
- Firewall and IPS Deployment Guide Discover how to quickly deploy a full-service business network that is next-generation threat-ready. This comprehensive guide is based on best-practice design principles that...
- HIPAA Hiccup Solved Data protection priorities rapidly changed after a patient data leak that caused one healthcare provider unexpected expenses, potential reputational risk and possible HIPAA...
- Dell Software This overview of Dell SonicWALL next-generation firewalls showcases how you can increase network security by scanning every packet without any compromises in network... All Security White Papers | Webcasts