Title :
A Case Study of Text-Based CAPTCHA Attacks
Author :
Ling-Zi, Xiao ; Yi-Chun, Zhang
Author_Institution :
Dept. of Digital Media Technol., Commun. Univ. of China, Beijing, China
Abstract :
CAPTCHA (Completely Automated Public Turing Test to tell Computers and Human Apart) is widely used than before, which becomes the common part of current website login system. However, the CAPTCHA implementation is tricky and risky without deliberate design. In this paper, we give a study case of the vulnerabilities in current login website using text-based CAPTCHA. Our target is a website of mainstream bank of china. We show that with some specialized methods, the CAPTCHA scheme in its website can be easily cracked. Finally, we give some advices for CAPTCHA designers to revise our CAPTCHA implementation security in the future.
Keywords :
Web sites; character recognition; image segmentation; security of data; text analysis; CAPTCHA implementation security; Web site login system; completely automated public turing test to tell computers and human apart; image segmentation; text-based CAPTCHA attacks; Biological neural networks; Computers; Filtering; Humans; Image segmentation; Security; Training; CAPTCHA (Completely Automated Public Turing Test to tell Computers and Human Apart); CAPTCHA attacks; Image segmentation; security;
Conference_Titel :
Cyber-Enabled Distributed Computing and Knowledge Discovery (CyberC), 2012 International Conference on
Conference_Location :
Sanya
Print_ISBN :
978-1-4673-2624-7
DOI :
10.1109/CyberC.2012.28