<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/movabletype/spammers-hack-captcha-to-post-blog-spam-comments.asp" />
  <link rel="self" type="application/atom+xml" href="http://blog.tmcnet.com/blog/tom-keating/atom.xml" />
  <id>tag:blog.tmcnet.com,2014:/blog/tom-keating//4/tag:blog.tmcnet.com,2006:/blog/tom-keating//4.22424-</id>
  <updated>2014-03-28T22:23:06Z</updated>
  <title>Comments for Spammers hack captcha to post blog spam comments?</title>
  <subtitle>VoIP &amp; Gadgets blog - Latest news in VoIP &amp; gadgets, wireless, mobile phones, reviews, &amp; opinions</subtitle>
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.38</generator>
  <entry>
    <id>tag:blog.tmcnet.com,2006:/blog/tom-keating//4.22424</id>
    <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/movabletype/spammers-hack-captcha-to-post-blog-spam-comments.asp" />
    <link rel="service.edit" type="application/atom+xml" href="http://blog.tmcnet.com/mt/mt-atom.cgi/weblog/blog_id=4/entry_id=22424" title="Spammers hack captcha to post blog spam comments?" />
    <published>2006-01-20T14:31:24Z</published>
    <updated>2008-04-10T21:35:21Z</updated>
    <title>Spammers hack captcha to post blog spam comments?</title>
    <summary>Either the spammers are either very stupid or they have figured out a way to hack the visual captcha plugin (created by James Seng) I installed in my Movable Type blog (sample image to right). The reason I say this...</summary>
    <author>
      <name>Tom Keating</name>
      <uri>http://blog.tmcnet.com/blog/tom-keating/</uri>
    </author>
    
    <category term="MovableType" />
    
    <content type="html" xml:lang="en" xml:base="http://blog.tmcnet.com/blog/tom-keating/">
      <![CDATA[<p><img vspace="5" hspace="5" border="0" align="right" src="http://blog.tmcnet.com/blog/tom-keating/images/captcha.png" />Either the spammers are either very stupid or they have figured out a way to hack the visual captcha plugin (<a href="http://james.seng.cc/archives/000145.html">created by James Seng</a>) I installed in my Movable Type blog (sample image to right). The reason I say this is that my blog has been receiving spam comments over the past several months that are the <span style="font-style: italic;">exact same text</span> and I've seen this exact text on other blogs as well.<br /><br />The spam text reads:<br /><span style="font-weight: bold;">I totally agree with what you're saying. I wish more people felt this way and took the time to express themselves. Keep up the great work.</span><br style="font-weight: bold;" /><br style="font-weight: bold;" /><span style="font-weight: bold;">&lt;name&gt;</span><br style="font-weight: bold;" /><span style="font-weight: bold;">&lt;website&gt;</span><br /><br />The spam text is &quot;generic&quot; enough and even complimentary to the blogger that a naïve blogger that hasn't some across this spam may let the comment stay on the blog. In any case, it's always this exact text, but the IP address varies (could be open proxies) and the website is always different which indicates multiple spammers using the same script &amp; text template. It could be one spammer with hundreds of domains, but it seems to me that this comment spam text is so common that there must be some sort of script out there that can get around the captcha. James Seng's captcha is pretty popular, so perhaps a hacker/spammer has devised an OCR (optical character recognition) algorithm to detect the numbers and created a script to automate this?<br /><br /><a href="http://www.google.com/search?q=%22I+totally+agree+with+what+you%27re+saying.%22+I+wish+more+people+felt+this+way+and+took+the+time+to+express+themselves.+Keep+up+the+great+work.&btnG=Search&hl=en&lr=&rls=GGGL%2CGGGL%3A2005-09%2CGGGL%3Aen">I Googled this spammy text </a>with a portion of it in quotes (exact match) and found at least 114 results. A slightly less strict search reveals <a href="http://www.google.com/search?q=%22I+totally+agree+with+what+you%27re+saying.%22++great+work&btnG=Search&hl=en&lr=&rls=GGGL%2CGGGL%3A2005-09%2CGGGL%3Aen">765 Google results</a>. Now granted, the spammers could be simply copy/pasting their script into the Comments body and then manually entering the random numeric captcha code. But if they are going to go through the effort of copy/pasting to dozens of blogs in hopes of raising their Google Page Rank, why not come up with 10 text templates instead of just 1 text template? (<span style="font-style: italic;">not that I should be giving them any ideas</span>) Eventually, even the naïve blogger is going to catch onto this spam text and delete it. So why waste the effort? You'd think a spammer smart enough to hack the captcha code would modify his/her text template. Then again, if a script does exist to hack the captcha, it's probably script kiddies borrowing the hacker's original script and so damn lazy they don't even change the text.<br /><br />Actually, I've also seen some slight variants on this spam such as these:<br /><span style="font-weight: bold;">Hello! You have very interesting blog! I enjoy reading you blog... keep it up guys! Respect you. Good luck you!</span><br /><br />This one is interesting, <a href="http://www.google.com/search?hl=en&lr=&rls=GGGL%2CGGGL%3A2005-09%2CGGGL%3Aen&q=%22Thanks+for+this+great+post.%22+You%27ve+got+some+really+good+info+in+your+blog.+If+you+get+a+chance%2C+you+can+check+out+my+blog&btnG=Search">because if you Google it by clicking here</a>, you will see the &quot;variants&quot; of the exact text with the only text changed being the part in RED. Could be one spammer with hundreds of domains, who knows?<br /><br style="font-weight: bold;" /><span style="font-weight: bold;">Thanks for this great post. You've got some really good info in your blog. If you get a chance, you can check out my blog on {</span><span style="color: rgb(255, 0, 0); font-weight: bold;">copiers</span><span style="font-weight: bold;">} at http://www.</span><span style="color: rgb(255, 0, 0); font-weight: bold;">XYZ</span><span style="font-weight: bold;">.com.</span><br /><br />Some of the &quot;red&quot; keywords include: free credit reports, inkjet printer ink, mortgage brokers, donate, and more.<br /><br />You gotta love the poor grammar they use by the way. I actually find it<br />
amusing to read such tortured English. Though I hope this isn't<br />
Americans using such poor grammar. After all, isn't the controversial <a href="http://www.ed.gov/nclb/landing.jhtml?src=pb">No Child Left Behind</a> supposed to help with that? :D And yes, I know I used the word &quot;gotta&quot;.<br /><br />We have two possibilities here.<br />1) spammers are using a script that can visually see the numbers in the captcha code and the script automatically posts a comment using the same text template.<br />2) spammers aren't &quot;hacking&quot; the captcha but rather they are manually entering their crap on people's blogs and manually entering the captcha code (if installed) and using the same damn text template. My only question is &quot;Is this one annoying spammer or dozens doing this?&quot;<br /><br />Either option makes these spammers (spammer?) look like the dumbest spammers that ever walked God's green Earth. Thankfully, spammers tend to be the bottom of the genetic gene pool and are more &quot;lucky&quot; than &quot;smart&quot; when it comes to making money on the Internet. Their &quot;shotgun&quot; approach to spamming the entire Internet as opposed to using a more refined &quot;sniper rifle&quot; attack just might be a blessing. Just imagine if they actually had some intelligence in their spamming methods. Might make spam filters irrelevant, which would really suck since I spend at least 30 minutes a day going through spam on my blog and email accounts.<br /><br />That reminds me - you know those stats that tell you you spend X number of years sleeping, X number of years in a car, X number of years eating, etc.? I wonder how many years the average person loses dealing with spam. :@ I loathe spammers. Ok, I'll end my Friday morning rant against spammers.<br /></p>]]>
      
    </content>
  </entry>

  <entry>
    <id>tag:blog.tmcnet.com,2006:/blog/tom-keating//4.22424-comment:5030</id>
    <thr:in-reply-to ref="tag:blog.tmcnet.com,2006:/blog/tom-keating//4.22424" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/movabletype/spammers-hack-captcha-to-post-blog-spam-comments.asp"/>
    <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/movabletype/spammers-hack-captcha-to-post-blog-spam-comments.asp#c5030" />
    <title>Comment from Zoli Erdos on 2006-01-22</title>
    <author>
        <name>Zoli Erdos</name>
        <uri>http://www.zoliblog.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.zoliblog.com">
        <![CDATA[<p>Spam Blogs are <strong>Splogs</strong>, Comment Spam is&nbsp;<strong>Spomment, </strong>how about trackback spam?&nbsp;&nbsp;<strong>Spamback</strong> or <strong>Trackspam</strong>?&nbsp;&nbsp;&nbsp;Please vote&nbsp;<a href="http://www.zoliblog.com/blog/_archives/2006/1/22/1718858.html">here</a>.</p>]]>
    </content>
    <published>2006-01-22T23:42:04Z</published>
  </entry>

  <entry>
    <id>tag:blog.tmcnet.com,2006:/blog/tom-keating//4.22424-comment:17077</id>
    <thr:in-reply-to ref="tag:blog.tmcnet.com,2006:/blog/tom-keating//4.22424" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/movabletype/spammers-hack-captcha-to-post-blog-spam-comments.asp"/>
    <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/movabletype/spammers-hack-captcha-to-post-blog-spam-comments.asp#c17077" />
    <title>Comment from John Shield on 2006-07-13</title>
    <author>
        <name>John Shield</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p><br />
Come on... automated visual (and even audio) captcha decoding has been implemented by spammers for years. Check out <a href="http://sam.zoy.org/pwntcha/">http://sam.zoy.org/pwntcha/</a> for the most complete decoder probably in use by every spammer today.</p>

<p>For an excellent Audio Captcha decoder, look at <a href="http://vorm.net/captchas/,">http://vorm.net/captchas/,</a> in my tests, I could break MSN audio captcha's 100% of the time.</p>

<p>(I'm not a spammer incidently, I'm into VoIP and needed a way to do speaker recognition for voice dialing (instead of DTMF dialing))</p>

<p>Keep up the good work, I'll leave off my url :)</p>]]>
    </content>
    <published>2006-07-13T12:43:02Z</published>
  </entry>

  <entry>
    <id>tag:blog.tmcnet.com,2006:/blog/tom-keating//4.22424-comment:17078</id>
    <thr:in-reply-to ref="tag:blog.tmcnet.com,2006:/blog/tom-keating//4.22424" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/movabletype/spammers-hack-captcha-to-post-blog-spam-comments.asp"/>
    <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/movabletype/spammers-hack-captcha-to-post-blog-spam-comments.asp#c17078" />
    <title>Comment from Tom Keating on 2006-07-13</title>
    <author>
        <name>Tom Keating</name>
        <uri>http://blog.tmcnet.com/blog/tom-keating/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://blog.tmcnet.com/blog/tom-keating/">
        <![CDATA[<p>John,<br />
Yeah, I was aware that hacking captcha was do-able using OCR. However, I've used regular OCR software to scan documents and they are generally inaccurate. I guess I figured OCRing a captcha wouldn't be worth the trouble or wouldn't be that accurate. You'd have to keep hammering my MT blog entry, OCRing the captcha until the comment finally posted.</p>

<p>I suppose Scode (what I use) is a fairly common captcha, so once the script is written, it can hammer all Movable Type blogs that use it. Of course Scode uses very basic fonts + layout, so I figured this captcha was fairly simply to break. Thanks for the link that states 100% accuracy in breaking Scode. Wonderful. Time to move to a new captcha perhaps. LOL!</p>]]>
    </content>
    <published>2006-07-13T13:43:30Z</published>
  </entry>

  <entry>
    <id>tag:blog.tmcnet.com,2006:/blog/tom-keating//4.22424-comment:24543</id>
    <thr:in-reply-to ref="tag:blog.tmcnet.com,2006:/blog/tom-keating//4.22424" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/movabletype/spammers-hack-captcha-to-post-blog-spam-comments.asp"/>
    <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/movabletype/spammers-hack-captcha-to-post-blog-spam-comments.asp#c24543" />
    <title>Comment from csharpp on 2007-03-27</title>
    <author>
        <name>csharpp</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>what about <a href="http://www.captchasolver.com">http://www.captchasolver.com</a> ? it's an automated captcha solving web service.</p>]]>
    </content>
    <published>2007-03-27T18:57:46Z</published>
  </entry>

  <entry>
    <id>tag:blog.tmcnet.com,2006:/blog/tom-keating//4.22424-comment:34435</id>
    <thr:in-reply-to ref="tag:blog.tmcnet.com,2006:/blog/tom-keating//4.22424" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/movabletype/spammers-hack-captcha-to-post-blog-spam-comments.asp"/>
    <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/movabletype/spammers-hack-captcha-to-post-blog-spam-comments.asp#c34435" />
    <title>Comment from Moshe Cohen on 2008-03-08</title>
    <author>
        <name>Moshe Cohen</name>
        <uri>http://j2ee-now.blogspot.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://j2ee-now.blogspot.com">
        <![CDATA[<p>Nice article, In my opinion each not-hackable system can be hacked in one way or another, same is true for the Captcha system.</p>

<p>For example this article describe how to hack simple Captcha words: <br />
<a href="http://j2ee-now.blogspot.com/2008/03/captcha-hack-part-1.html">http://j2ee-now.blogspot.com/2008/03/captcha-hack-part-1.html</a></p>]]>
    </content>
    <published>2008-03-08T15:57:57Z</published>
  </entry>

  <entry>
    <id>tag:blog.tmcnet.com,2006:/blog/tom-keating//4.22424-comment:38779</id>
    <thr:in-reply-to ref="tag:blog.tmcnet.com,2006:/blog/tom-keating//4.22424" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/movabletype/spammers-hack-captcha-to-post-blog-spam-comments.asp"/>
    <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/movabletype/spammers-hack-captcha-to-post-blog-spam-comments.asp#c38779" />
    <title>Comment from shemer on 2008-08-11</title>
    <author>
        <name>shemer</name>
        <uri>http://yourfreeitouch.blogspot.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://yourfreeitouch.blogspot.com">
        <![CDATA[<p>If you dont like those spam comments I suggest and I currently use spamwow, which stops those pesty spammers, It is by far the best one out there!</p>]]>
    </content>
    <published>2008-08-11T14:55:11Z</published>
  </entry>

  <entry>
    <id>tag:blog.tmcnet.com,2006:/blog/tom-keating//4.22424-comment:41266</id>
    <thr:in-reply-to ref="tag:blog.tmcnet.com,2006:/blog/tom-keating//4.22424" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/movabletype/spammers-hack-captcha-to-post-blog-spam-comments.asp"/>
    <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/movabletype/spammers-hack-captcha-to-post-blog-spam-comments.asp#c41266" />
    <title>Comment from mohan on 2008-12-12</title>
    <author>
        <name>mohan</name>
        <uri>http://www.gurusonline.in</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.gurusonline.in">
        <![CDATA[<p>Nice post....Good discussion going here......</p>]]>
    </content>
    <published>2008-12-13T00:23:54Z</published>
  </entry>

  <entry>
    <id>tag:blog.tmcnet.com,2006:/blog/tom-keating//4.22424-comment:47916</id>
    <thr:in-reply-to ref="tag:blog.tmcnet.com,2006:/blog/tom-keating//4.22424" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/movabletype/spammers-hack-captcha-to-post-blog-spam-comments.asp"/>
    <link rel="alternate" type="text/html" href="http://blog.tmcnet.com/blog/tom-keating/movabletype/spammers-hack-captcha-to-post-blog-spam-comments.asp#c47916" />
    <title>Comment from ram on 2009-09-29</title>
    <author>
        <name>ram</name>
        <uri>http://www.zoombits.fr/ram</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.zoombits.fr/ram">
        <![CDATA[<p>Hi,<br />
The easiest way to get rid of those spam contents is to use a software which detect spammers or you have to check it manually.</p>]]>
    </content>
    <published>2009-09-29T13:08:19Z</published>
  </entry>

</feed>
