Web Hack List

Collected research

Attacking CAPTCHAs for Fun and Profit

A survey of CAPTCHA implementations on high-traffic sites, sorted into breaches of client-side trust, server-side state flaws and image weaknesses. It names rainbow tables against finite CAPTCHA sets, CAPTCHA fixation, in-session brute-forcing and accumulation. Image attacks combine multiple OCR engines and selective substitution, driven by the author's TesserCap tool.

Record

Researcher
Gursev Singh Kalra
Published by
mcafee.com
Format
Whitepaper
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Gursev Singh Kalra, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .