Collected research
reCAPTCHA bypass via HTTP Parameter Pollution
Applications that build the reCAPTCHA siteverify URL by string concatenation let an attacker smuggle a second secret parameter through the response field. Because the API honoured the first secret, supplying Google's documented always-pass test key made every verification return success, defeating the CAPTCHA entirely.
Record
- Published by
- Andres Riancho
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Andres Riancho, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .