[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [WEB SECURITY] Brute Force authentication attack
- From: skarvin <skarvin@xxxxxxxxx>
- Subject: Re: [WEB SECURITY] Brute Force authentication attack
- Date: Sat, 1 Jul 2006 09:38:56 +0200
------=_Part_57647_13575918.1151739536045
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Hi,
If you use a very simple captcha, maybe you'll be vulnerable to brute force
attacks by OCR techniques.
On 6/30/06, Chris Weber <chris@lookout.net> wrote:
> True is that. Also "Human Interactive Proof" or HIP, CAPTCHA being more
> common, I think.
>
> -----Original Message-----
> From: Jeremiah Grossman [mailto:jeremiah@whitehatsec.com]
> Sent: Friday, June 30, 2006 1:33 PM
> To: Web Security
> Subject: Re: [WEB SECURITY] Brute Force authentication attack
>
> We all get those from time to time. :)
>
> CAPTCHA
> "completely automated public Turing test to tell computers and humans
apart"
>
> On Jun 30, 2006, at 10:41 AM, Schmidt, Albert E wrote:
>
> > I am definitely having a senior moment. Can anybody please tell me
> > what it is called when you have to enter a code displayed in a picture
> > when authenticating? I know this is a control against brute force
> > hacking, but for the life of me I cannot remember what it is called.
> >
> > ----------------------------------------------------------------------
> > ------
> > The Web Security Mailing List:
> > http://www.webappsec.org/lists/websecurity/
> >
> > The Web Security Mailing List Archives:
> > http://www.webappsec.org/lists/websecurity/archive/
> > http://www.webappsec.org/rss/websecurity.rss [RSS Feed]
> >
>
>
>
----------------------------------------------------------------------------
> The Web Security Mailing List:
> http://www.webappsec.org/lists/websecurity/
>
> The Web Security Mailing List Archives:
> http://www.webappsec.org/lists/websecurity/archive/
> http://www.webappsec.org/rss/websecurity.rss [RSS Feed]
>
>
>
----------------------------------------------------------------------------
> The Web Security Mailing List:
> http://www.webappsec.org/lists/websecurity/
>
> The Web Security Mailing List Archives:
> http://www.webappsec.org/lists/websecurity/archive/
> http://www.webappsec.org/rss/websecurity.rss [RSS Feed]
>
>
--
Un saludo,
skarvin
skarvin.blogspot <http://skarvin.blogspot.com>.com<http://skarvin.blogspot.com>
------=_Part_57647_13575918.1151739536045
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Hi,<br><br>If you use a very simple captcha, maybe you'll be vulnerable to brute force attacks by OCR techniques.<br><br><br>On 6/30/06, Chris Weber <<a href="mailto:chris@lookout.net";>chris@lookout.net</a>> wrote:<br>
> True is that. Also "Human Interactive Proof" or HIP, CAPTCHA being more<br>> common, I think.<br>> <br>> -----Original Message-----<br>> From: Jeremiah Grossman [mailto:<a href="mailto:jeremiah@whitehatsec.com";>
jeremiah@whitehatsec.com</a>]<br>> Sent: Friday, June 30, 2006 1:33 PM<br>> To: Web Security<br>> Subject: Re: [WEB SECURITY] Brute Force authentication attack<br>> <br>> We all get those from time to time. :)
<br>> <br>> CAPTCHA<br>> "completely automated public Turing test to tell computers and humans apart"<br>> <br>> On Jun 30, 2006, at 10:41 AM, Schmidt, Albert E wrote:<br>> <br>> > I am definitely having a senior moment. Can anybody please tell me
<br>> > what it is called when you have to enter a code displayed in a picture<br>> > when authenticating? I know this is a control against brute force<br>> > hacking, but for the life of me I cannot remember what it is called.
<br>> ><br>> > ----------------------------------------------------------------------<br>> > ------<br>> > The Web Security Mailing List:<br>> > <a href="http://www.webappsec.org/lists/websecurity/";>
http://www.webappsec.org/lists/websecurity/</a><br>> ><br>> > The Web Security Mailing List Archives:<br>> > <a href="http://www.webappsec.org/lists/websecurity/archive/";>http://www.webappsec.org/lists/websecurity/archive/
</a><br>> > <a href="http://www.webappsec.org/rss/websecurity.rss";>http://www.webappsec.org/rss/websecurity.rss</a> [RSS Feed]<br>> ><br>> <br>> <br>> ----------------------------------------------------------------------------
<br>> The Web Security Mailing List:<br>> <a href="http://www.webappsec.org/lists/websecurity/";>http://www.webappsec.org/lists/websecurity/</a><br>> <br>> The Web Security Mailing List Archives:<br>> <a href="http://www.webappsec.org/lists/websecurity/archive/";>
http://www.webappsec.org/lists/websecurity/archive/</a><br>> <a href="http://www.webappsec.org/rss/websecurity.rss";>http://www.webappsec.org/rss/websecurity.rss</a> [RSS Feed]<br>> <br>> <br>> ----------------------------------------------------------------------------
<br>> The Web Security Mailing List:<br>> <a href="http://www.webappsec.org/lists/websecurity/";>http://www.webappsec.org/lists/websecurity/</a><br>> <br>> The Web Security Mailing List Archives:<br>> <a href="http://www.webappsec.org/lists/websecurity/archive/";>
http://www.webappsec.org/lists/websecurity/archive/</a><br>> <a href="http://www.webappsec.org/rss/websecurity.rss";>http://www.webappsec.org/rss/websecurity.rss</a> [RSS Feed]<br>> <br>> <br><br><br><br>-- <br>Un saludo,
<br><br><span style="font-weight: bold;">skarvin</span><br><a href="http://skarvin.blogspot.com";>skarvin.blogspot</a><a href="http://skarvin.blogspot.com";>.com</a>
------=_Part_57647_13575918.1151739536045--
Brought to you by http://www.webappsec.org
Search this site
|