Threat Level: green Handler on Duty: Bojan Zdrnja

SANS ISC: SANS Daily Network Security Podcast (Stormcast) for Thursday, December 4th 2014 - SANS Internet Storm Center SANS Daily Network Security Podcast (Stormcast) for Thursday, December 4th 2014


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Apple Updates Safari; Paypal fixes interesting CSRF; Decoding F5 Cookies; CAPTCHAS are dead and rebo

SANS Daily Network Security Podcast (Stormcast) for Thursday, December 4th 2014
00:00

My Next Class

Intrusion Detection In-DepthMadridMar 25th - Mar 30th 2019
Defending Web Applications Security EssentialsSan DiegoMay 9th - May 14th 2019

… more classes

Apple Updates Safari; Paypal fixes interesting CSRF; Decoding F5 Cookies; CAPTCHAS are dead and reborn

Safari (OS X) Update
http://lists.apple.com/archives/security-announce/2014/Dec/msg00000.html

PayPal Vulnerable CSRF Implementation
http://yasserali.com/hacking-paypal-accounts-with-one-click/

Abusing F5 Load Balancer Cookies
http://blog.ptsecurity.com/2014/12/ddos-attack-over-load-balancer-secure.html

Google rolls outnew CAPTCHA
http://googleonlinesecurity.blogspot.com.es/2014/12/are-you-robot-introducing-no-captcha.html Get a free ISC sticker (login required):
https://isc.sans.edu/sticker.html
Spotify spotify logo

Discussion

There is problem.

In just 4 minutes, manually, I was able to use Windows Snipping tool on each picture, import those pictures into Google's own image search, and use a Word Map, to discover single most common noun for each photo, then could easily correlate with the most common noun of the subject image.

This is a bit slower than simply running a captcha image through an advanced OCR... but fairly easy to write a script to take cropped screenshots of each image and run through Google's image search and then do a word correlation.

Google could try to lock down their Image Search API, limiting the number of searches per second to catch spammers, but that is easy to get around. They could try removing these images from their index, but that is make it hard to use good recognizable images.

Any attempt to obfuscate the images will result in pain for the user to recognize on mobile devices, just like captchas are getting harder.

My suggestion, is to overlap, blend, and blur borders of the images together, and analyze user input (press) coordinates on the server to determine the closest, most likely choice of the user. You have to eliminate a clean "cropping" of the image, while preserving human recognizability.
Posted by Joeviocoe on Thu Dec 04 2014, 02:49

New Discussions closed for all Podcasts older than two(2) weeks
Please send your comments to our Contact Form

Intrusion Detection In-DepthMadridMar 25th - Mar 30th 2019
Defending Web Applications Security EssentialsSan DiegoMay 9th - May 14th 2019
Intrusion Detection In-DepthSan AntonioMay 28th - Jun 2nd 2019
Defending Web Applications Security EssentialsMunichJul 1st - Jul 6th 2019
Intrusion Detection In-DepthLondonJul 8th - Jul 13th 2019
Intrusion Detection In-DepthBostonJul 29th - Aug 3rd 2019
Defending Web Applications Security EssentialsSan JoseAug 12th - Aug 17th 2019
Defending Web Applications Security EssentialsArlingtonAug 14th - Aug 19th 2019
Defending Web Applications Security EssentialsBrusselsSep 2nd - Sep 7th 2019
Intrusion Detection In-DepthLondonSep 23rd - Sep 28th 2019