A Case Study of Text-Based CAPTCHA Attacks

Xiao Ling-Zi, Zhang Yi-Chun · 2012

CAPTCHA (Completely Automated Public Turing Test to tell Computers and Human Apart) is widely used than before, which becomes the common part of current website login system. However, the CAPTCHA implementation is tricky and risky without deliberate design. In this paper, we give a study case of the vulnerabilities in current login website using text-based CAPTCHA. Our target is a website of mainstream bank of china. We show that with some specialized methods, the CAPTCHA scheme in its website can be easily cracked. Finally, we give some advices for CAPTCHA designers to revise our CAPTCHA implementation security in the future.

Read the paper · More papers on PaperTik