Yahoo Captcha Cracked By Russians, and Hard Deciscions
|
| |
![]() | |
To All Complainers, this has been mentioned enough places(including Slashdot) by now that I see little harm in mentioning it. Don’t complain at me.
So for those of you who haven’t heard(this news has 772 inbound links already, so I assume the news is getting out there), the yahoo captcha has been cracked. Open source style.
So I’m asking if any of yall have actually run it yet?
I have 2 rules for software. I don’t download odd binaries from Blackhats, and I don’t download anything from russians. Especially russian security experts who operate under pseudonyms.
So has anyone run this yet? Gotten spam complaints about their connection/had CPU burst into flames? Or is it legit? C/C++ are not my ace languages by a long shot, so I can’t really examine the code myself.
- XMCP
PS: Everyone notice we now have a piqq invitation feed. Updates every hour.





















February 16th, 2008 at 4:56 pm
you can run it, its basically open source c++ code and the main functions are precompiled into a .dll. it needs some weird runtime-dll’s tho.
February 16th, 2008 at 5:46 pm
Yeah I got as far as seeing the source and all…but I feel it to be pretty dangerous to run the dll file…this kinda stuff is not released for free often, and I have trouble believing there’s no real motive..
February 16th, 2008 at 7:01 pm
I took a look at it as well. I’m not going to be messing with it until it gets ported over to php so I can tell what’s going on.
February 16th, 2008 at 7:50 pm
Well, smart not to run it. But does anyone thing CAPTCHA is more than a temporary fix? My five year old can decode them - computers can’t be that far behind.
-OT
February 16th, 2008 at 11:01 pm
Yeah, Russian’s + the internet = scare me. I wouldn’t be that surprised if this was just another front to get more drones for their DDoS attacks.
Best bet is to just wait a few days and let somebody else pour over the code, I’m not in a huge hurry to break any Captcha’s anyway.
February 17th, 2008 at 1:55 am
I know nothing about cracking captchas but looking at the given example you just need to ignore lines longer than a certain length on a (closer to) horizontal axis.
Easier said than done Im sure!
February 18th, 2008 at 4:02 am
Want to be secure? Use a throw away virtual machine with windows installed on it. VMware even offers a free server or player for that…
February 19th, 2008 at 12:48 pm
[…] by Slightly Shady SEO: Russian crackers found a way to crack Yahoo CAPTCHA. Although he mentioned it, he does not want to […]