Web Hack List

Collected research

Bypassing NoCAPTHCA

Egor Homakov: The No CAPTCHA problem

Google's No CAPTCHA reCAPTCHA is really a cookie-based whitelist: trusted users get a token, everyone else still solves the old OCR-breakable challenge. The widget can be loaded with another site's sitekey, its referrer check defeated by a meta referrer tag, so an attacker can clickjack trusted visitors into minting tokens to spend on the victim.

Record

Document
Egor Homakov: The No CAPTCHA problem
Researcher
Egor Homakov
Published by
homakov.blogspot.com
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Egor Homakov, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .