On CNET: Keep your software up-to-date
BNET Business Network:
BNET
TechRepublic
ZDNet

February 7th, 2008

Microsoft Windows Live Mail's CAPTCHA defense falls to spam bots

Posted by Larry Dignan @ 4:46 am

Categories: Botnets, Microsoft, Spam and Phishing, Vulnerability research

Tags: CAPTCHA, Microsoft Windows Live Mail, Websense Inc., Microsoft Windows Live, Microsoft Windows, Microsoft Corp., Bot, Larry Dignan

Microsoft’s Windows Live Mail is being targeted by spammers adept at eluding CAPTCHA protection, according to Websense.

According to Websense, spammers have created bots that are capable of creating random Live Mail accounts and then using them to launch attacks. In other words, the CAPTCHA defense doesn’t work. A CAPTCHA is a program that protects websites against bots by generating tests that humans can pass but current computer allegedly programs can’t.

wbsn1.pngIn its blog, Websense says the whole bot-as-email-account process is automated. For instance, Jay’s email account to the right was created by a bot. Websense added:

Websense believes that there are three main advantages to this approach for the spammers. First, the Microsoft domain is unlikely to be blacklisted. Second, they are free to sign up. And third, it may be hard to keep track of them as there are millions of users worldwide using the service.

Here’s how the bot works:

1. The bot goes to the Live Mail registration page and fills out the form fields (just as you would do) with random data;

2. When the CAPTCHA verification comes up, the bot sends the image to its breaking service.

3. The bot gets the answer and plugs it in.

4. Now spammers add a few gazillion accounts for malicious endeavors.

5. The spam barrage ensues. Here’s an image courtesy of Websense, which features a lot more on its blog.

wbsn.png

Websense estimates that about 30 percent to 35 percent of these CAPTCHA killing attempts works. Websense has the screen shot walk through. It’s a fascinating–and totally evil–bot. Websense also reckons that these attacks could extend to other Live services including Messenger and online storage.

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 17 Talkback(s)
By THAT logic, Dick Cheney is a better human being than Al Gore
Guess which one won the Nobel Prize, and which one has an impeachment groundswell building around him....... (Read the rest)
Posted by: drprod@... Posted on: 02/08/08 You are currently: a Guest | | Terms of Use
I'll second that...  Taz_z | 02/07/08
One of two possibilities  CobraA1 | 02/07/08
RE: Microsoft Windows Live Mail's CAPTCHA defense falls to spam bots  Rick_R | 02/07/08
You knew it was only a matter of time  Confused by religion | 02/07/08
RE: Microsoft Windows Live Mail's CAPTCHA defense falls to spam bots  dhindublin | 02/07/08
Microsoft sucks! (NT)  nomoremicrosoft | 02/07/08
Re: "Microsoft sucks! (NT)"  IT_Guy_z | 02/07/08
Really?  wez@... | 02/07/08
By THAT logic, Dick Cheney is a better human being than Al Gore  drprod@... | 02/08/08
BUWAHAHAAHAH!!!  itanalyst | 02/07/08
How soon we forget!  kd5auq | 02/07/08
I don't think that too many new virus are being made  BALTHOR | 02/07/08
RE: Microsoft Windows Live Mail's CAPTCHA defense falls to spam bots  karen.bosso@... | 02/07/08
Normally, I'd agree  WebWatcher | 02/08/08
Windows Live???  LonnieRM | 02/08/08
It was only a matter of time before someone put OCR in  Been_Done_Before | 02/08/08
RE: Microsoft Windows Live Mail's CAPTCHA defense falls to spam bots  atari8bit@... | 02/08/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Meet Doc