• Welcome to the LegalBeagles Consumer and Legal Forum.
    Please Register to get the most out of the forum. Registration is free and only needs a username and email address.
    REGISTER
    Please do not post your full name, reference numbers or any identifiable details on the forum.

Microsoft Windows Live Mail’s CAPTCHA defense falls to spam bots

Collapse
Loading...
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • Microsoft Windows Live Mail’s CAPTCHA defense falls to spam bots

    Microsoft’s Windows Live Mail is being targeted by spammers adept at eluding CAPTCHA protection, according to Websense.

    According to Websense, spammers have created bots that are capable of creating random Live Mail accounts and then using them to launch attacks. In other words, the CAPTCHA defense doesn’t work. A CAPTCHA is a program that protects websites against bots by generating tests that humans can pass but current computer allegedly programs can’t.



    In its blog, Websense says the whole bot-as-email-account process is automated. For instance, Jay’s email account to the right was created by a bot. Websense added:
    Websense believes that there are three main advantages to this approach for the spammers. First, the Microsoft domain is unlikely to be blacklisted. Second, they are free to sign up. And third, it may be hard to keep track of them as there are millions of users worldwide using the service.
    Here’s how the bot works:
    1. The bot goes to the Live Mail registration page and fills out the form fields (just as you would do) with random data;
    2. When the CAPTCHA verification comes up, the bot sends the image to its breaking service.
    3. The bot gets the answer and plugs it in.
    4. Now spammers add a few gazillion accounts for malicious endeavors.
    5. The spam barrage ensues. Here’s an image courtesy of Websense, which features a lot more on its blog.


    Websense estimates that about 30 percent to 35 percent of these CAPTCHA killing attempts works. Websense has the screen shot walk through. It’s a fascinating–and totally evil–bot. Websense also reckons that these attacks could extend to other Live services including Messenger and online storage.

    Larry Dignan

  • #2
    Re: Microsoft Windows Live Mail’s CAPTCHA defense falls to spam bots

    Pkea,

    Any chance something like this could be the origin of our DOS attack?

    More in particular this one

    http://by131w.bay131.mail.live.com/mail/Applicatio
    [actual clickable link removed,please do not copy to your browser just in case]
    Any opinions I give are my own. Any advice I give is without liability. If you are unsure, please seek qualified legal advice.

    IF WE HAVE HELPED YOU PLEASE CONSIDER UPGRADING TO VIP - click here

    Comment


    • #3
      Re: Microsoft Windows Live Mail’s CAPTCHA defense falls to spam bots

      I dont think this would be the origin of the attack, as this program is designed to bypass the image text verification on registration screens.

      ie the type the text in the image thing.

      The main purpose of this program is to collect multiple email addresses to enable email spamming.

      Do you want to pm or mail thst link to me and I will have a look at it

      PKea

      Comment


      • #4
        Re: Microsoft Windows Live Mail’s CAPTCHA defense falls to spam bots

        Cheers Pk ,

        Have added a few more suspect ones too
        Any opinions I give are my own. Any advice I give is without liability. If you are unsure, please seek qualified legal advice.

        IF WE HAVE HELPED YOU PLEASE CONSIDER UPGRADING TO VIP - click here

        Comment

        View our Terms and Conditions

        LegalBeagles Group uses cookies to enhance your browsing experience and to create a secure and effective website. By using this website, you are consenting to such use.To find out more and learn how to manage cookies please read our Cookie and Privacy Policy.

        If you would like to opt in, or out, of receiving news and marketing from LegalBeagles Group Ltd you can amend your settings at any time here.


        If you would like to cancel your registration please Contact Us. We will delete your user details on request, however, any previously posted user content will remain on the site with your username removed and 'Guest' inserted.
        Working...
        X