WebApp Sec mailing list archives

RE: Defeating CAPTCHA


From: "Derick Anderson" <danderson () vikus com>
Date: Mon, 29 Aug 2005 08:03:14 -0400

I'm sure there is a significant number of valid credit card numbers
floating around in the open, but it is not without bound. An open, free
system (which I am not against, by the way) allows spammers to create as
many accounts as they wish. Once they have to pay for it, even with
stolen credit cards, the availability of accounts drops into a much
smaller finite number. Besides, if I have your credit card number, why
bother using it to create a spamming account? I've already got free
money. =)

Derick Anderson

-----Original Message-----
From: Devdas Bhagat [mailto:devdas () dvb homelinux org] 
Sent: Sunday, August 28, 2005 2:35 AM
To: webappsec () securityfocus com
Subject: Re: Defeating CAPTCHA

On 26/08/05 12:45 -0400, Derick Anderson wrote:
<snip>
1. Charge money. Spammers aren't going to shell out cash en masse.

But they are perfectly willing to use _your_ credit card for 
that. There are a lot of phishing attacks and broken CC# 
storage and transport systems that some spammers will have 
access to that data.

Devdas Bhagat



Current thread: