ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Spammers use free porn to bypass Hotmail protection

Munir Kotadia ZDNet.co.uk

Published: 06 May 2004 18:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Spammers are bypassing a security protection that is designed to stop automated bots from automatically opening Web mail accounts, by offering humans access to free porn.

Free Web mail services such as Hotmail and Yahoo are often used by spammers to send unsolicited emails. But because of the sheer quantity of emails that are sent, spammers require thousands of accounts and employ Web bots to automate the account-opening process.

In order to combat this automation, Web mail companies started using the Captcha test (Completely Automated Public Turing test to tell Computers and Humans Apart), which creates a graphically distorted representation of a simple word that can easily be read by a human but not by a machine. The word is often written in an unusual font and presented on a patterned background to further confuse the bots.

To open an email account, the applicant is asked to read the word contained in the Captcha graphic and then type that word into an application form. Because the disguised word is virtually impossible for a computer to read, spammers need a human to intervene, which ruins their automation process.

However, as first noted in the BoingBoing blog earlier this year, some spammers have found an ingenious way to bypass the Captcha protection.

Firstly, the spammers open and advertise a Web site containing pornography. Visitors to the porn site are asked to enter the word contained in a Captcha graphic before they are granted access. In the background, spammers have already used scripts to automate the Web mail account opening process to the point where they need a human to "read" the Captcha graphic. The Captcha graphic from the Web mail site is transferred to the porn site, where the porn consumer interprets the Captcha word. As soon as they enter the correct word, the script can complete its application process and the visitor is rewarded with free porn.

Simon Perry, vice president of security at Computer Associates, said that security is always a "moving target" and as soon as a company like MSN uses a new technology to secure a product or service, it is only a matter of time before it will be bypassed.

"Each little improvement makes it a little bit more difficult for the spammers. This is an exercise in continually moving up the bar," he said.

According to Perry, the only way to make a real difference is to combine technology with legislation and enforce that legislation. However, he said that even though spammers may have found a way past the Captcha, it is still slowing them down.

"Before the Captcha those bots could open a million Hotmail accounts a day, but now, if they can attract 10,000 people to their free porn site, they can set up 10,000 accounts, which is a lot, but still an order of magnitude less," said Perry.

A Microsoft spokesperson said that the fight between Hotmail and the spammers is a game of "cat and mouse" in which spammers are continually innovating and creating more sophisticated methods to escape detection.

"We must continue to invest in R&D to advance anti-spam technologies and not only stay ahead of the curve, but eventually turn their incentives upside down and make it no longer profitable to send spam," the spokesperson said.

Yahoo would not comment on the issue.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
133 out of 212 people found this useful



Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

QA Test Analyst - QTP AUTOMATION expert - LONDON

QA QTP Automation Test Analyst - My growing Telecomms client are urgently looking to recruit a QA Automation Test Engineer to join their QA team in ...

Account Director - Media Agency - W London - 50,000 - 70,000

Key Responsibilities - Prioritising and defining account developments approaches - Generate and implement practical plans to develop accounts - ...

Automation Test Analyst QTP - FINANCE/BANKING

A fantastic automation test analyst position has become available with one of the leading financial institutions in london. Working in a ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation