Smart Crooks using scam to break CAPTCHA challenges

These crooks have found a way to use unsuspecting humans under the influence of testosterone poisioning to break online security systems. While this is funny, it is also a serious reminder of the ingenuity people can use to break into whatever security protections we, as programmers, can come up with.

--wck

SAN JOSE, Calif. —  In a new online striptease, the buxom, beautiful blonde who promises to remove her slinky scraps of lingerie doesn't want your money. She's interested in your brain. Really.

2_61_melissa_captcha_virus.jpgThe creation of online scammers, she's trying to trick unsuspecting Internet users into helping the scammers break the online barriers that banks and e-mail services set up to thwart crooks.

The striptease is the latest attempt to defeat so-called CAPTCHA systems, which is short for Completely Automated Public Turing test to tell Computers and Humans Apart.

Those safeguards require users to prove they are human by reading wavy, oddly shaped jumbles of letters and numbers that appear in an image and typing them out.

• Click here to visit FOXNews.com's Cybersecurity Center.

In the new scam, an icon of an alluring woman suddenly appears on a Windows computer infected by a virus.

After clicking on the icon, the user sees a photo of an attractive woman who vows to take off an article of clothing each time the jumble of figures next to her is entered.

 

But the woman never fully undresses, and after several passwords are entered the program restarts, possibly enticing unsuspecting users into trying again.

Trend Micro researchers say the scam appears to be isolated for now to spammers trying to register bogus e-mail addresses and flood chat rooms with unwanted pitches.

But they worry schemes to infiltrate financial institutions could soon appear.

Paul Ferguson, network architect at Trend Micro, speculated that spammers might be using the results to write a program to automatically bypass CAPTCHA systems.

"I have to hand it to them," Ferguson said, laughing. "The social engineering aspect here is pretty clever."

 

 

What did you think of this article?




Trackbacks
  • No trackbacks exist for this entry.
Comments

  • 3/10/2008 2:48 PM test wrote:
    Why don't the comments work?
    Reply to this
    1. 3/10/2008 3:40 PM Wkiraly wrote:
      Comments work fine but I must approve comments because of the spammers trying to get in and post garbage or porn links on our site. Any legitimate comment, even if we don't agree with it, will be approved. I'm just not interested in turning our blog into a bazaar for online pharmaceuticals.

      Reply to this
Leave a comment

Submitted comments will be subject to moderation before being displayed.

 Enter the above security code (required)

 Name

 Email (will not be published)

 Website

Your comment is 0 characters limited to 3000 characters.