{"id":22528,"date":"2023-05-30T14:26:09","date_gmt":"2023-05-30T14:26:09","guid":{"rendered":"https:\/\/news24feed.com\/?p=22528"},"modified":"2023-05-30T14:26:09","modified_gmt":"2023-05-30T14:26:09","slug":"captcha-cracking-services-with-human-solvers-that-help-cybercriminals-defeat-security","status":"publish","type":"post","link":"https:\/\/news24feed.com\/?p=22528","title":{"rendered":"CAPTCHA cracking services with human solvers that help cybercriminals defeat security"},"content":{"rendered":"<p><\/p>\n<p><span class=\"p-author\">\ue802<span class=\"author\">May 30, 2023<\/span>I<span class=\"author\">Ravie Lakshmanan<\/span><\/span><\/p>\n<p>Cybersecurity researchers are warning about CAPTCHA cracking services offered for sale to bypass systems designed to distinguish legitimate users from bot traffic.<\/p>\n<p>&#8220;Since cybercriminals are interested in cracking CAPTCHAs with precision, several services have been created that primarily target this market demand,&#8221; Trend Micro. <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/e\/abusing-web-services-using-automated-captcha-breaking-services-and-residential-proxies.html\" rel=\"noopener\" target=\"_blank\">said<\/a> in a report published last week.<\/p>\n<p>&#8220;These CAPTCHA solving services are not used [optical character recognition] advanced machine learning techniques or methods;  instead, they break CAPTCHAs by assigning CAPTCHA-breaking tasks to real human solvers.&#8221;<\/p>\n<p><a href=\"https:\/\/support.google.com\/a\/answer\/1217728\" rel=\"noopener\" target=\"_blank\">CAPTCHA<\/a> &#8211; short for Fully Automated Public Turing Test to Distinguish Computers from Humans &#8211; is a tool to differentiate real human users from automated users with the aim of combating spam and restricting the creation of fake accounts.<\/p>\n<p>While CAPTCHA mechanisms can be a <a href=\"https:\/\/blog.cloudflare.com\/end-cloudflare-captcha\/\" rel=\"noopener\" target=\"_blank\">disruptive user experience<\/a>they are seen as an effective means of countering attacks from web traffic originating from bots.<\/p>\n<p>Illicit CAPTCHA solving services work by funneling requests submitted by clients and delegating them to their human solvers, who work out the solution and send the results to users.<\/p>\n<p>This, in turn, is accomplished by calling an API to submit the CAPTCHA and invoking a second API to retrieve the results.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/thehackernews.com\/new-images\/img\/b\/R29vZ2xl\/AVvXsEikkPctWhi-9hjBBQnpiTONztPcVUFUQ1TBCSm-lb3Clb2Rl9HF9GgCoE15ag979TxB_SMM6odR-dqCPZ9XWij1wx-fH2zSV_6qzBM1lF3LjxunWNalygi3WRPflw4EFY2xe7qhkC6k1EUoBBiFX2nbnNEZsK886g-_upoLNu_K8e7kdL-z5NsfMjVf\/s728-e3650\/domain.jpg\" alt=\"CAPTCHA\" border=\"0\" data-original-height=\"331\" data-original-width=\"728\" title=\"CAPTCHA\"\/><\/p>\n<p>&#8220;This makes it easier for customers of CAPTCHA cracking services to develop automated tools against online web services,&#8221; said security researcher Joey Costoya.  &#8220;And since real humans are solving CAPTCHAs, the purpose of filtering automated bot traffic through these tests is rendered ineffective.&#8221;<\/p>\n<p>That&#8217;s not all.  Threat actors have been observed purchasing CAPTCHA cracking services and combining them with proxyware offerings to hide the source IP address and evade anti-bot barriers.<\/p>\n<p> <span class=\"ad-label\">UPCOMING WEBINAR<\/span> <\/p>\n<p>Zero Trust + Deception &#8211; Learn to Outsmart Attackers!<\/p>\n<p class=\"ad-description\">Learn how Deception can detect advanced threats, stop lateral movement, and improve your Zero Trust strategy.  Join our in-depth webinar!<\/p>\n<p> <a href=\"https:\/\/thn.news\/z-inside-2\" rel=\"noopener\" target=\"_blank\" class=\"ad-button\">Save my seat!<\/a><\/p>\n<p><a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/23\/b\/hijacking-your-bandwidth-how-proxyware-apps-open-you-up-to-risk.html\" rel=\"noopener\" target=\"_blank\">Middleware<\/a>while it&#8217;s marketed as a utility for sharing a user&#8217;s unused Internet bandwidth with other parties in exchange for &#8220;passive income,&#8221; it essentially turns the devices running them into residential proxies.<\/p>\n<p>In one instance of a CAPTCHA cracking service aimed at the popular social commerce marketplace Poshmark, task requests emanating from a bot are routed through a middleware network.<\/p>\n<p>&#8220;CAPTCHAs are common tools used to prevent spam and bot abuse, but the increasing use of CAPTCHA cracking services has made CAPTCHAs less effective,&#8221; Costoya said.  &#8220;While online web services can block abusers&#8217; source IPs, the increased adoption of proxyware makes this method as toothless as CAPTCHAs.&#8221;<\/p>\n<p>To mitigate these risks, it is recommended that online web services supplement CAPTCHAs and the IP blocklist with other anti-abuse tools.<\/p>\n<p><\/p>\n<p>Did you find this article interesting?  Follow us at <a href=\"https:\/\/twitter.com\/thehackersnews\" rel=\"noopener\" target=\"_blank\">Twitter \uf099<\/a> i <a href=\"https:\/\/www.linkedin.com\/company\/thehackernews\/\" rel=\"noopener\" target=\"_blank\">LinkedIn<\/a> to read more exclusive content we publish.<br \/>\n<script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/>[ad_2]<br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2023\/05\/captcha-breaking-services-with-human.html\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\ue802May 30, 2023IRavie Lakshmanan Cybersecurity researchers are warning about CAPTCHA cracking services offered for sale to bypass systems designed to distinguish legitimate users from bot traffic. &#8220;Since cybercriminals are interested in cracking CAPTCHAs with precision, several services have been created that primarily target this market demand,&#8221; Trend Micro. said in a report published last week. &#8220;These CAPTCHA solving services are not used [optical character recognition] advanced machine learning techniques or methods; instead, they break CAPTCHAs by assigning CAPTCHA-breaking tasks to real human solvers.&#8221; CAPTCHA &#8211; short for Fully Automated Public Turing Test to Distinguish Computers from Humans &#8211; is a&#8230; <\/p>\n","protected":false},"author":8,"featured_media":22529,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-22528","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-videos"],"_links":{"self":[{"href":"https:\/\/news24feed.com\/index.php?rest_route=\/wp\/v2\/posts\/22528","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/news24feed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news24feed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news24feed.com\/index.php?rest_route=\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/news24feed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=22528"}],"version-history":[{"count":1,"href":"https:\/\/news24feed.com\/index.php?rest_route=\/wp\/v2\/posts\/22528\/revisions"}],"predecessor-version":[{"id":22530,"href":"https:\/\/news24feed.com\/index.php?rest_route=\/wp\/v2\/posts\/22528\/revisions\/22530"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news24feed.com\/index.php?rest_route=\/wp\/v2\/media\/22529"}],"wp:attachment":[{"href":"https:\/\/news24feed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=22528"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news24feed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=22528"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news24feed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=22528"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}