CAPTCHA phishing: a practical attack on human interaction proofing

  • Authors:
  • Le Kang;Ji Xiang

  • Affiliations:
  • State Key Laboratory of Information Security, Chinese Academy of Science, Beijing, China;State Key Laboratory of Information Security, Chinese Academy of Science, Beijing, China

  • Venue:
  • Inscrypt'09 Proceedings of the 5th international conference on Information security and cryptology
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

CAPTCHAs are widespread security measures on the World Wide Web that prevent automated programs from massive access. To overcome this obstacle attackers generally utilize artificial intelligence technology, which is not only complicated but also not adaptive enough. This paper addresses on the issue of how to defeat complex CAPTCHAs with a social engineering method named CAPTCHA Phishing instead of AI techniques. We investigated each step of this attack in detail and proposed the most effective way to attack. Then we did experiment with real Internet web sites and obtained a positive results. The countermeasures to prevent this attack are also discussed.