lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <191a9b6f0802081557r3e4a97fby79716dfbd7298a1f@mail.gmail.com> Date: Fri, 8 Feb 2008 18:57:23 -0500 From: Camilo <camilo.uribe@...il.com> To: full-disclosure@...ts.grok.org.uk Subject: Break Captcha to send sms at Movistar Colombia, Movistar Ecuador and Comcel Colombia The captcha of the Movistar Colombia cellphone company web page[1] is too simple I get in contact with them but don't fix it so I made a poc to break it[2] Movistar ecuador[3] has the same problem but it's "captcha" don't even use an image but 4 numbers in plain text. Comcel of Colombia don't even use captcha. In the three cases the person who get the sms has to pay for it. [1] http://www.movistar.com.co/portaldecontenidos/ [2] http://rapidshare.com/files/90269321/movistar.zip.html [3] http://movistar.com.ec/contenidos/ [4] http://www.comcel.com.co/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/