[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <43F10E08.8010802@linuxbox.org>
Date: Mon Feb 13 22:55:29 2006
From: ge at linuxbox.org (Gadi Evron)
Subject: defeating voice captchas
One of the newest (now known though) tricks in the Captcha book is using
Voice.
If users cannot understand what the letters are in the now too-complex
Captchas that are forced on us due to spammer counter-measures at
defeating Captchas, he or she can click on an icon and listen to it. :)
Here is the earliest example of it that I know of:
http://www.notonebit.com/projects/killbot/kbaudio.php
That example is a bit amateurish, as the recording is bad and obviously
not done by a girl with a sexy voice. Still, the disturbance from the
bad Microphone can be eliminated or kept entirely. It doesn?t matter.
In this case each letter is played by itself. Further, each letter was
recorded only once.
Therefore, how many times does one have to refresh the page and listen
to the Captcha to be able to simply learn to identify the Captcha by
say, an MD5 hash of the audio for each letter?
Even if it was all set in one audio file, and even if the audio was
played with to be, as an example, in a higher pitch. Or perhaps even if
several different voices would greet us?
Looking at general similarities in the audio file itself would be enough
to break down this Captcha once enough harvesting attempts (not that
many really) were saved.
Auto-generated voice? That sounds easy to beat but I am not an audio
expert so, ?sounds like? will stay as my opinion.
It?s is great to be able to finally understand these new annoying
Captchas, but already we are getting to a point where one can?t
understand the recorded speech either due to counter-measures from the
spammers and the Captchas becoming more and more difficult.
For information on breaking regular text-image Captchas, check:
http://en.wikipedia.org/wiki/Captcha
http://blogs.securiteam.com/index.php/archives/208
For my post on new comment spam problems:
http://blogs.securiteam.com/index.php/archives/285
This text can be found here:
http://blogs.securiteam.com/index.php/archives/287
Gadi.
Powered by blists - more mailing lists