Technologies that
Bring Peace of Mind
Online
technical Help
and Support
Status live support chat
Live support
Have a question?
Call us Toll-Free at:
1-877-ANTISPY
1-877-2684779
+44-207-099-2078
More contacts


Subscribe to our
RSS feed
Subscribe to our RSS feed
In focus
Gmail, Yahoo and Hotmail´s CAPTCHA Broken
July 3, 2008 13:36

    
It's one thing to start efficiently registering thousands of email accounts at reputable email providers by automatically breaking their CAPTCHA authentication, and entirely another to build a business model on the top of it next to the opportunity to abuse if for your own malicious purposes. Which is exactly what we have here, an underground service that's selling registered accounts at Gmail, Yahoo, Hotmail and the most popular Russian email providers in the thousands. Once the inventory of registered accounts drops due to someone's purchase, it continues registering one to two email accounts per second.

Gmail, Yahoo and Hotmail´s CAPTCHA broken by spammers :

"Breaking Gmail, Yahoo and Hotmail´s CAPTCHAs, has been an urban legend for over two years now, with do-it-yourself CAPTCHA breaking services, and proprietary underground tools assisting spammers, phishers and malware authors into registering hundreds of thousands of bogus accounts for spamming and fraudulent purposes. This post intends to make this official, by covering an underground service offering thousands of already registered Gmail, Yahoo and Hotmail accounts for sale, with new ones registered every second clearly indicating the success rate of their CAPTCHA breaking capabilities at these services."

Text based CAPTCHA is so broken, that if major web sites whose services are getting abused don't at least try to slow down the efficient approach of breaking it, we are going to see an entire spamming infrastructure build on the foundation of legitimate email service providers.

Related posts:
Vladuz's Ebay CAPTCHA Populator
Spammers and Phishers Breaking CAPTCHAs
DIY CAPTCHA Breaking Service
Which CAPTCHA Do You Want to Decode Today?

All news for October 10, 2008
  22:58  Schneier on Security: Friday Squid Blogging: Natural Squid Steganography
  22:45  Martin McKeay: Recording Notice: Security Roundtable - Blogger Ethics
  18:30  Schneier on Security: The More Things Change, the More They Stay the Same
  14:39  Martin McKeay: Brute force attacks against WPA/WPA2 using Nvidia cards
  12:35  Schneier on Security: Data Mining for Terrorists Doesn't Work
  00:02  Martin McKeay: Sequoia´s helping decide the election? God help us!

All news for October 9, 2008
  23:00  MSRC: Update 1: Microsoft Security Advisory 951306
  19:07  Schneier on Security: Nonviolent Activists Are Now Terrorists
  17:51  Martin McKeay: Cisco Ooops: drug runner music on VPN CD
  16:40  MSRC: October 2008 Advanced Notification
  12:44  Schneier on Security: "New Attack" Against Encrypted Images
  12:22  Martin McKeay: Step by step guide to the DNS vulnerability
  09:28  Dancho Danchev: Cybercriminals Abusing Lycos Spain To Serve Malware
  09:00  Dancho Danchev: Commoditization of Anti Debugging Features in RATs - Part Two

All news for October 8, 2008
  14:46  Martin McKeay: NoScript protects from ClickJacking
  14:14  Martin McKeay: Big Surprise: Data mining doesn´t catch terrorists
  12:55  Schneier on Security: Chinese Monitoring Skype Messages
  02:23  Martin McKeay: Network Security Podcast, Episode 123

All news for October 7, 2008
  21:51  Schneier on Security: Do-Not-Call Lists
  18:27  Martin McKeay: Recording notice: NSP 123
  15:54  Dancho Danchev: Summarizing Zero Day's Posts for September
  14:49  Martin McKeay: Now he´s done it! Security Mike sells out
  12:21  Dancho Danchev: A Diverse Portfolio of Fake Security Software - Part Eight
  11:48  Schneier on Security: The Seven Habits of Highly Ineffective Terrorists
  07:42  Dancho Danchev: Web Based Malware Emphasizes on Anti-Debugging Features
  00:01  Dancho Danchev: Fake Windows XP Activation Trojan Wants Your CVV2 Code
Keywords: gmail, yahoo, and, hotmailacutes, captcha, broken

All news for October, 2008


All news for 2008