| Subcribe via RSS

Yahoo CAPTCHA Cracked By Russians

February 1st, 2008 | Comments Off | Posted in Technology

CAPTCHA (Completely Automated Turing Test To Tell Computers and Humans Apart), is a program that protects websites against bots by generating and grading tests that humans can pass but current computer programs cannot. For example, humans can read distorted text as the one shown below, but current computer programs can’t:

yahoocaptcha.jpg

The Yahoo! CAPTCHA being the most difficult CAPTCHA to crack found itself vulnerable to a team of Russian hackers who found a way to read the CAPTCHA with 35% accuracy. Yahoo! Captcha utilizes bended alpha numeric characters and other features that one might expect from a strong CAPTCHA, but is still recognizable by humans.

This is what the hackers said about Yahoo! CAPTCHA:

The CAPTCHA has a vulnerability we’ll discuss later. It’s not necessary to achieve high degree of accuracy when designing automated recognition software. The accuracy of 15% is enough when attacker is able to run 100.000 tries per day, taking into the consideration the price of not automated recognition – one cent per one CAPTCHA.

This is an alarming issue for everybody. This kind of vulnerability will allow more emails to be registered automatically and can be used for phishing spam and fraud. This will clearly have a great negative impact on the online community and businesses. They must find new ways to improve CAPTCHA. Maybe we’ll be seeing some form of evolution in CAPTCHA, what are those billion dollar companies paying their programmers and developers for anyway. If this is not resolved quickly, we can expect automated online businesses, blogs, and any site that utilizes CAPTCHA to take extra effort in making sure that they are safe from spam by checking their comments and transactions manually.

Source: geeksaresexy

Tags: , , , ,

WordPress Important Update (2.3.2)

December 30th, 2007 | 3 Comments | Posted in Blog Tips

wordpress.jpgWordPress just released an update that fixes a bug that could expose your draft posts. The update also suppresses some error messages that can give away information about your database table structure and limits and stops some information leaks in the XML-RPC and APP implementations. I have seen these error messages from orangeinks and some other blogs. The codes are there for everyone to see. I you’re using WordPress as a hosted blog platform, it is strongly suggested that you upgrade now to protect your blog from the said disclosures.

WordPress also added a little bonus of allowing you to define a custom DB error page.

Place your custom template at wp-content/db-error.php. If WP has a problem connecting to your database, this page will displayed rather than the default error message.

To help you with the upgrade, just follow the instructions posted here. And remember guys, backup your files.

Tags: , , , ,

Subscribe FaceBook Follow Orangeinks Follow Orangeinks on FriendFeed del.icio.us


Enter your email address:

Delivered by FeedBurner