- 1
- 2
- 3
- < previous
- next >
According to Nagle, waxing sarcastic, "Several commercial products are now available to overcome those little obstacles to bulk posting. A tool called CL Auto Posting Tool is one such product. It not only posts to Craigslist automatically, it has built-in strategies to overcome each Craigslist anti-spam mechanism." It's not the only one. There are, he added, "other desktop software products [such as] AdBomber and Ad Master. For spammers preferring a service-oriented approach, there's ItsYourPost." The result? "The defenses of Craigslist have been overrun. Some categories on Craigslist have become over 90 per cent spam. The personals sections were the first to go, then the services categories, and more recently, the job postings."
Of course, you don't have to pay anything. There are now free CAPTCHA crackers available online.
Craigslist is fighting back. The organization is now using phone verification for some ads. Crackers, in return, are working on a way to break Craigslist's phone defenses. With combat costs mounting, it's hard to see how Craigslist, which has always been a free service, can continue to survive with its no-visible-means-of-revenue model.
It's not, as the Craigslist situation shows, that malicious e-mail is the only problem coming from broken CAPTCHA security. Paul Wood, senior analyst at MessageLabs, a UK-based e-mail security company, says, "MessageLabs have already begun to see examples of spammers exploiting other techniques once they have bypassed the CAPTCHA of Google and Hotmail -- for example, using Google Docs to create spam content and including the link in the spam e-mail messages, evading traditional antispam techniques that rely on identifying known spam domains in URLs."
Social network users are also vulnerable to attack from CAPTCHA-compromised sites, says Stephan Chenette, manager of security research at Websense Security Labs.
"The newer generation doesn't use e-mail to communicate," Chenette explains. "Instead, they use social networks, and they're not too concerned about revealing their personal information on social networks or blogs where they post instead of sending e-mail. What happens is that an attacker creates a public blog of his own or sets up an account; he can then use these to publish malicious links. By exploiting the trust of the people on that community, he uses them to spread botnets and the like."
Because social networks offer such an "enormous attack surface" and "their users don't think of themselves as being vulnerable in the same way experienced e-mail or IM users are," they're especially easy to exploit, says Chenette.
Another new attack vector is coming from CAPTCHA's collapse: the quick creation of fake Web sites. According to Chenette, these sites get their content from legitimate Web sites by copying and pasting to maximize their search engine optimization and reputation to quickly gain an audience.
"Reputation is all the rage for malicious attackers. From a search engine perspective, the content is what matters. Malicious attackers will pull sites' contents and embed it in their site, and that gives them a high search-engine ranking, which gives them a higher reputation," says Chenette. "We've been seeing that quite a lot recently. Of course, search engine poisoning is quite old, but now reputation sites [such as Digg] that use CAPTCHA are being targeted."
- 1
- 2
- 3
- < previous
- next >
Read up on the latest ideas and technologies from companies that sell hardware, software and services. RFS6000 | Wireless switch
Everything you need to know about email and web security (but were afraid to ask)
The Case for an Untethered Enterprise
AP-7131 | The industry’s first 802.11n access point with tri-radio design
Wi-Fi Attitudes Shift
Motorola point-to-point 500 series | Wireless Ethernet Bridges
Opening the door to endless possibilities and bringing surveillance into the wireless age
Case Study: International airport seeks an infrastructure upgrade that meets the EC standards
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Mitel Launches Simpler Unified Communications 2008-11-19 17:40:00+11
Symantec Security Products Shine in In-Depth Protection Reviews 2008-11-19 13:01:00+11
Digital Sense opens first stage of the world’s largest data centre complex in Brisbane 2008-11-19 13:00:00+11
RightNow Technologies Delivers RightNow November ’08 Plus New On Demand Enterprise Contact Centre Package 2008-11-19 12:00:00+11
Valorem uniquely deploys RSA SecurID for remote workforce management 2008-11-19 10:16:00+11
Best Practice in Building an Integrated Information Management Strategy
Discover the business value that creating an integrated information platform can bring. Learn how to provide consistent, accurate information to all stakeholders within your business network. Integrate vital data from disparate sources and deliver a trusted information foundation. Read on to uncover the stepping-stones to your new information management strategy.








