Web Hack List

Top 10 winner

CAPTCHA Re-Riding Attack

Kalra shows that many CAPTCHA implementations store the solution in the HTTP session but never clear it during verification. Because the CAPTCHA image endpoint is not called again, a single solved CAPTCHA stays valid for the session's life. Replaying the recorded submission, refreshing the session id where it rotates, yields unlimited successful form submissions.

Record

Researcher
Gursev Singh Kalra
Published by
gursevkalra.blogspot.com
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Gursev Singh Kalra, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .