Forum Moderators: phranque
We are using a similar technique as Yahoo! to generate captcha, I think if the released program consists of a general image recognition module, then it can be used to break ANY captcha.
From our research, the hacker is hacking at rate of 40-50% of accuracy. We strongly believe that the hacker is using image recognition technique as in the following examples,
sYu52b => syuS2b
sud8k => 5Ud8b
As you can see, they are very similar recognition, and we have a lot of these examples from a UNIQUE IP (serverl K per day).
Any comments?
2. Text captcha is even more easy to crack, if we go for usablility in the future, we might provide voice captcha for example.
Text captcha is even more easy to crack, if we go for usablility in the future, we might provide voice captcha for example.
Me experience has been the exact opposite, you're trying to stop bots. Bots can't answer questions. Keep it simple and keep it unique, for example put a paragraph with some text and underline a word. The underlined word is the answer to the captcha.
This is not an solution for big targets like Yahoo or other large sites because they could just program the bots to defeat it. They'd have to make huge selection of questions for it to be effective.
I used this on my old phpbb2 forum and didn't get a single bot registration in over a year, same goes for e-mail form.