Jump to content

Virtual sweatshops defeat anti-spam tests


Recommended Posts


An army of low paid workers has been deployed to beat yet another security tool.

The abundance of these low-skilled, low-paying jobs is coming from firms that specialise in the shadowy market of mass-solving CAPTCHAs, those blurry and squiggly words that some websites force you to retype. One big player in this industry is KolotiBablo.com, a service that appeals to spammers and exploits low cost labor in China, India, Pakistan, and Vietnam.

KolotiBablo, which means "earn money" in transliterated Russian, helps clients automate the solving of puzzles designed to prevent automated activity by bots, such as leaving spammy comments or mass-registering accounts at webmail providers and social networking sites. The service offers an application programming interface (API) that allows clients to feed kolotibablo.com CAPTCHAs served in real time by various sites, which are then solved by KolotiBablo workers and fed back to the client's system.

Paying clients interface with the service at antigate.com, a site hosted on the same server as kolotibablo.com. Antigate charges clients 70 US cents to US$1 for each batch of 1000 CAPTCHAs solved, with the price influenced heavily by volume. KolotiBablo says employees can expect to earn between US$0.35 to US$1 for every thousand CAPTCHAs they solve.

The twin operations say they do not condone the use of their services to promote spam, or "all those related things that generate butthurt for the 'big guys,'" mostly likely a reference to big free webmail providers like Google and Microsoft. Still, both services can be found heavily advertised and recommended in several underground forums that cater to spammers and scam artists.

Registered antigate.com users can read more about why customers typically purchase the service, and how KolotiBablo is run. From the description:

"All CAPTCHAs in our service are completely solved by real humans, there are usually 500-1000 (and growing) workers online from all the world. That's why we can process any CAPTCHAs at any volume for a fixed price $1 per 1000 CAPTCHAs.

"You may probably think that using human resource inappropriate or inhumane. However, keep in mind that we pay the most of collected money to our workers who sit in the poorest corners of our planet and this work gives them a stable ability to buy food, clothes for themselves and their families. Most of our staff is from China, India, Pakistan and Vietnam."

To get started as a CAPTCHA-solving worker at Kolotibabo.com, workers need to provide a working account at WebMoney, a virtual currency. After that, the system will start feeding them live CAPTCHAs to solve, prefacing each with a notice about the rate that the client has agreed to pay per batch.

Depending on the demands that clients place on the service, there may be a brief delay between CAPTCHAs, but generally only a few seconds pass between the time a solved puzzle is submitted and when a new one is offered. Each new puzzle is preceded by an audible "beep," and workers are expected to solve and type each of the CAPTCHAs in less than 10 seconds. During downtime, the system displays workers' average puzzle solving times, as well as actual and projected weekly earnings.

If it sounds like easy money, take a moment to work out the math. Assuming that one can solve a six CAPTCHAs per minute and work eight hours straight, they'd be able to solve about 2880 puzzles each day. Even at the highest CAPTCHA solving rate, they'd only make US$2.88 daily; at the lowest rate, they'd make just over a dollar a day.

No, the real earnings only come when workers assemble an army of workers to solve CAPTCHAs for their WebMoney account, as described by the FAQ at KolotiBablo.com.

Update: the KolotiBablo website appeared to be down following the publication of this article with only the worker login page still online at present.

As long as there is low-cost human labor willing to do this kind of work for pennies per day, CAPTCHAs will continue to be an ineffective way to prevent automated account creation and spammy websites comments. But at least experts are working on making CAPTCHAs less annoying: Some firms are starting to pitch more user-friendly alternatives to the hard-to-read squiggly CAPTCHAs.

If you'd like to learn more about CAPTCHAs and the semi-automated systems being built to defeat them, I'd suggest reading this paper (PDF) on CAPTCHA-solving services, from researchers at University of California, San Diego. Also, in November 2010, I wrote about CAPTCHABot, another puzzle-solving service with similar rates and practices.

someone burn these spammer companies down to the ground... or come up with the next big thing to fight spam.

Link to comment
Share on other sites

  • Views 946
  • Created
  • Last Reply


This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Create New...