Jump to content

Google reCAPTCHA Cracked in New Automated Attack


Batu69

Recommended Posts

Facebook's CAPTCHA system too, over 70% accuracy achieved

google_recaptcha_cracked_in_new_automate

   Google's reCAPTCHA system cracked in new attack

A trio of security researchers have devised a new automated attack that can break the CAPTCHA systems employed by Google and Facebook.

The researchers utilized a large number of factors in putting together their attack, leveraging tricks to bypass CAPTCHA security measures (cookies, tokens) and machine learning to "guess" the correct (image) CAPTCHA answer with a higher degree of accuracy than previous studies.

Experiment achieves very high accuracy

The results of this new attack were better than they expected. On Google's reCAPTCHA system, researchers recorded a 70.78 percent success rate over 2,235 CAPTCHAs. Average CAPTCHA solving time was 19.2 seconds.

They achieved a better success rate on Facebook's system, where they had a success rate of 83.5 percent on over 200 CAPTCHAs.

The better accuracy for solving Facebook CAPTCHAS stems from the fact that the social network uses images with a higher resolution, and also depicts objects from distinct categories. Google, on the other hand, uses low-quality photos, always related to each other, which makes automatic image classification much harder.

Taking into account that attackers can rent CAPTCHA-breaking systems that use human operators to solve CAPTCHAs, the researchers also analyzed the economics needed to plan and run their attack.

New automated attack is also economically viable

If crooks ever wanted to start their own CAPTCHA-busting business, the whole attack would cost only $110 (€96) a day, per IP address, and would allow them to crack around 63,000 CAPTCHAs in 24 hours from one IP address without being detected and getting banned.

"Our completely offline captcha-breaking system is comparable to a professional solving service in both accuracy and attack duration, with the added benefit of not incurring any cost on the attacker," researchers explained.

Before going public with their research, Google and Facebook were contacted with the study's findings. Researchers said that Google took some steps to harden reCAPTCHA, but Facebook has not replied with any changes they've made to their CAPTCHA system.

Suphannee Sivakorn, Jason Polakis, and Angelos D. Keromytis are the three experts behind this research. Their paper called I Am Robot: (Deep) Learning to Break Semantic Image CAPTCHAs, is available Columbia University's Department of Computer Science website. Another copy is also available via the Black Hat Asia 2016 website, where the researcher presented their work last week.

Article source

Link to comment
Share on other sites


  • Replies 6
  • Views 1.1k
  • Created
  • Last Reply

Not surprising.  Anything coded by man can be broken by man.  The only thing that cannot be hacked is death, when your time comes you die. Period.

Link to comment
Share on other sites


viettungvuong

Thing that human created can be also broken by human

Link to comment
Share on other sites


5 hours ago, viettungvuong said:

Thing that human created can be also broken by human

off topic, but how about nuclear meltdown.

Link to comment
Share on other sites


viettungvuong
2 hours ago, player said:

off topic, but how about nuclear meltdown.

Nuclear is not completely made by human, so my statement is not true about the nuclear meltdown

Link to comment
Share on other sites


Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...