ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Hotlan Trojan defeats captcha

Matt Loney ZDNet.co.uk

Published: 06 Jul 2007 12:14 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new Trojan horse that sends spam through Hotmail and Yahoo email accounts has antivirus companies worried that the commonly used "captcha" system, used to prove new members are real people, may have been compromised.

Captcha systems typically use a selection of alphanumeric characters that have been distorted and presented in a graphic with other elements designed to confuse character-recognition software. The idea is that, as only a person can read it and type in the correct sequence, spam bots and other malware can be stopped from automatically setting up accounts.

The new threat was highlighted on Thursday by BitDefender Labs, which has dubbed it Trojan.Spammer.HotLan.A.

"The Trojan uses automatically generated accounts, suggesting that spammers have found a way to bypass the captcha systems," the company said in a statement.

Every active copy of the Trojan accesses an account, then pulls encrypted spam emails from a website, decrypts them and sends them to (presumably valid) addresses taken from yet another website, BitDefender continued.

Viorel Canja, head of BitDefender's antivirus labs, said there are "only" about 500 or so new accounts being created in this attack every hour, and 15,000-plus Hotmail accounts had already been used.

Yahoo could not be immediately contacted for comment.

The spam email currently being distributed is trying to lead users to a site that advertises pharmacy products. Common spammer techniques are used in the email body, added BitDefender.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
45 out of 49 people found this useful



Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Website / Web Developer Required - Wiltshire - New Media 25 - 30k

Huxley Associates are looking for a talented Web Developer to work for our exclusive client based in Wiltshire to work for our well known client. You ...

Website Developer - ASP.Net, C#, SQL Server in Bristol

An international company in Bristol requires an experienced web developer to join their IT team. You will be working in .Net on 7 websites for UK ...

Webmaster / Website administrator

My exciting client requires a Webmaster. This exciting 3 month + contract based in the Thames Valley, requires experience of Intelligent Content ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment