Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

April 14th, 2008, 14:14 GMT · By Bogdan Popa

Microsoft Live Hotmail CAPTCHA - Hacked in 6 Seconds

SHARE:

Adjust text size:


Hotmail's CAPTCHA - hacked in 6 seconds..
Enlarge picture
The folks at Websense have managed to prove, once again, that an experienced spammer who attempts to create a large number of Microsoft Live Hotmail accounts
to send spam messages doesn't need more than six seconds in order to bypass the CAPTCHAs. The reports comes after only a few days since several sources confirmed that hackers around the world are willing to hire and pay human workforce in order to enter the visual CAPTCHAs and help them create accounts on several services.

Getting back to the Microsoft Live Hotmail CAPTCHA, Websense's experts estimated that 6 seconds should be enough if a spammer who uses advanced techniques attempts to register multiple accounts on this mail service. Just like previous attacks, a bot starts the browser (usually Internet Explorer), connects to the service, uses a pre-defined list of account names and attempts to bypass the CAPTCHAs. The process may take no longer than six minutes, Websense explains.

"It is observed that unlike Live Mail Anti-CAPTCHA and Gmail Anti-CAPTCHA operations in the past, the current attack is aggressive and instantaneous in terms of CAPTCHA breaking host turn-around time. In the current attack, the response time of CAPTCHA breaking host after grabbing a CAPTCHA image from a victims' machine, analyzing it, and responding back to victims' machine with corresponding CAPTCHA code is relatively lower when compared to previous attacks," the people of Websense explained.

What's worse is that a Windows Live Hotmail may also be used for several purposes, other than sending spam email messages. For instance, the same accounts registered through the method described by Websense, can also be used for connecting to Windows Live Messenger, which means another spamming campaign could be started on the instant messaging application, millions of connected users being vulnerable to such an attack.

TELL US WHAT YOU THINK:

3,759 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Spammers Need Human Workforce to Solve CAPTCHAs

The Secrets of Guestbooks

Google: The Return of the Grieving Widow Strikes Back

How Easy Could A CAPTCHA Be Broken ?

Gmail Cracked!

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM