Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« More Anti-Spyware Authority to the Federal Trade Commission | Main | Extended Validation SSL Certificates and Phishing »

Stripping for Spam

Spammers have come up with an innovative way to get around those scrambled letters used to prevent automated registrations. They've turned the tables on using humans using computers to computers using human to solve a problem. Spammers get humans to write the scrambled letters and the human gets to see a character named Melissa undress.


Many computer criminals have been trying to crack these systems to get at the net-based resources, such as e-mail accounts or blogging tools, they are designed to protect.

"The free e-mail services, so far, have been extremely successful at using Captchas [Completely Automated Public Turing test to tell Computers and Humans Apart] to recognise a human being or an automatic program," said Raimund Genes, chief technology officer at Trend Micro.

The novel system for getting round Captchas uses images of a woman called "melissa" who invites victims to decipher the scrambled text. Entering the correct text produces another image and another chunk of scrambled text.

This is a great example of a problem that is too difficult for current AI methods and depends on "real" intelligence to solve. Humans are plugged into the workflow to solve the problem just as you'd add another service to a pipeline. The innovative spirit is alive and well with spammers.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/501

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net