They Make Apps' slider-based alternative to CAPTCHA
lukew.com
lukew.com
A slider? Really? Yeah, there's no way a script could fake changing the value of a slider.
http://www.nextthing.org/archives/2005/07/16/a-few-upgrades
My own has worked fairly well for me since then.
The thing is, for big sites like Google or Yahoo that won't work. If Google implemented the slider I'd bet a month's salary that it would be flooded with spammers overnight. The CAPTCHA's they use have been put through the ringer and are proven to work against spammers who are focused and resourceful. By lining the two up like that, the post tries to equivocate big site CAPTCHAs with user-friendly client-side-only validation, but the latter is not even in the same league, much less an alternative. It works for the same reasons "Enter the sum of 3 and 5: ____" would work.
The CAPTCHA's they use have been put through the ringer
and are proven to work against spammers who are focused
and resourceful.
Not really:- http://securitylabs.websense.com/content/Blogs/2919.aspx
- http://www.cs.sfu.ca/~mori/research/gimpy/
- http://www.zdnet.co.uk/news/security-management/2004/05/06/s...
- http://caca.zoy.org/wiki/PWNtcha
etc. Most of those articles are from several years ago. The state of the art has improved since then.
My point was more to the fact that the slider solution wouldn't retain anywhere near the same stats if it were put up against the same level of effort and sophistication spent towards breaking it. It would get solved and then bypassed completely.
You could use something like Eggplant, though. Or you could decompile the Flash file and fake the communications it sends to the server. The latter is probably the easiest and most scalable method.
In it he mentions the site below which is a some Chinese hacker's page that breaks down a number of common CAPTCHAs and puts a price on them: http://www.lafdc.com/captcha/
javascript:updateSlider1(4);
As far as I know, different CAPTCHAs have different degrees of effectiveness. Google's is among one of the best.
"Although a checkbox "check here if you are not a bot" might serve to distinguish between humans and computers, it is not a CAPTCHA because it relies on the fact that an attacker has not spent effort to break that specific form. (Such 'check here' methods are very easy to defeat.) Instead, CAPTCHAs rely on difficult problems in artificial intelligence. In the short term, this has the benefit of distinguishing humans from computers. In the long term, it creates an incentive to advance the state of AI, which the originators of the term view as a benefit in its own right."
(from wikipedia)
I haven't tried circumventing their form, and maybe they didn't do this, but the basic idea is to store the submission URL in javascript, and assign it to the form only on the slider event.
hell, a regular firefox browser with images disabled (for speed) and the selenium plugin installed could probably accomplish a high rate of automated spamming.