I took a look into the possible defenses versus clickjacking, and to me it looks like it might be a good idea for the recaptcha admin page (http://bit.ly/16b600a) to check the HTTP header for the X-Frame-Options line to give security recommendations to the web developer. That way if their site isn't configured to prevent clickjacking then they could be warned ahead of time. I would imagine that most high volume sites targeted by attackers would probably already use this option to prevent accounts from being stolen through clickjacking. I was looking into how hard it would be to detect an attack so statistics could be collected. This might work: (http://bit.ly/1zUFYaH), but the attackers could use the same anti-frame-busting techniques involving XSS filters to disable it. If it just used AJAX to log the referrer domain rather than trying to break out of the frame, an attacker might not even notice it. On Thursday, December 11, 2014 8:48:29 AM UTC-6, James Turner wrote: Browsers can defeat this, but only if the server providing the original captcha supplies a valid X-Frame-Options header. That being said, not a lot of servers supply the X-Frame-Options header. http://mzl.la/16b600e What you're talking about is essentially a form of clickjacking. On Wednesday, 3 December 2014 21:23:53 UTC, Allen Webb wrote: I was impressed by the new developments to reCAPCHA which use the entire user experience as input for the detection process. As a grad student working on security research I wonder how this impacts the known attacks to CAPCHAs specifically attacks which involve tricking users into solving a CAPCHA on behalf of an attacker through a third party service. There may already be measures in place against this kind of attack since it was published in 2004 (http://bit.ly/1uoQz95). I think it would be an interesting problem to solve because regardless of how good a CAPTCHA is at detecting bots the loophole of attackers tricking or motivating people to solve CAPTCHAs on their behalf may be significant. Along these lines I have the following questions: Are measures already in place for defeating this kind of attack? (I don't want to spend too much time looking into a problem that is already solved) Are there any measurements / estimates to how much this kind of attack has already been used? (It might not be worth looking into this problem yet if there isn't enough abuse of the loophole to justify the effort) -- You received this message because you are subscribed to the Google Groups "reCAPTCHA" group. To unsubscribe from this group and stop receiving emails from it, send an email to recaptcha+unsubscribe@googlegroups.com. To post to this group, send email to recaptcha@googlegroups.com. Visit this group at http://bit.ly/1dkFnYd. For more options, visit http://bit.ly/P65DvS.
Send Voicemail | EnAcCiOn
Contact me using vCita | EnAcCiOn
Contact Form & Online Scheduling by vCita
Contact me using vCita | EnAcCiOn
Meeting Scheduler Powered by vCita
Suscribirse a:
Enviar comentarios (Atom)
EnAcCiOn
Contador Web | EnAcCiOn
EnAcCiOn
-
shows de baile de la colombiana laura en el kilombo (huacho) | EnAcCiOn.Tk ░░░░░░░░░░░░▄▄░░░░░░░░█░█░█░░█░█▀▀░▀█▀░█▀▀ ░░░░░░░░░░░█░░█░░░░...
-
C-C-C CIUCCIA CAZZI DI CAVALLO PAOLO BARRAI DI WMO E BSI ITALIA SRL, UNA VOLTA CACCIATO (E FATTO CONDANNARE A GALERA) DA CITIBANK, PRIMA DI ...
-
Hello, My code works fine a few days ago, but no, I have this problem. Code Example: $(function(){ widgetnu = grecaptcha.render('c...
-
Hi,I have resized it by transform:scale and all seems good until I get the pop-up bubble with pictures (napr.: "choose all cakes" ...
-
Any thoughts on this would be really helpful. Same issue posted in StackOverflow doesn't seem to get a response: I am trying to get Goog...
-
░░░░░░░░░░░░▄▄░░░░░░░░█░█░█░░█░█▀▀░▀█▀░█▀▀ ░░░░░░░░░░░█░░█░░░░░░░█░█░██░█░█▀░░░█░░█▀░ ░░░░░░░░░░░█░░█░░░░░░░▀▄▀░█░▀█░█▄▄░░█░░█▄▄ ░░░░░░░...
-
EL PAÃS compartió una publicación. VÃdeo | Aunque en las pelÃculas no da resultado, se ve que los mensajes en la arena funcionan en la ...
-
Diario El Comercio compartió una publicación. #YouTube Descubren a pedófilo en experimento de niña perdida [#VIDEO] ►http://bit.ly/1h8Up Pe...
EnAcCiOn
EnAcCiOn
Blog Archive | EnAcCiOn
-
►
2013
(1429)
- ► septiembre (156)
-
▼
2014
(1220)
- ► septiembre (43)
-
▼
diciembre
(206)
-
▼
dic 11
(18)
- Re: Problem with new reCAPTCHA in a single-page An...
- Re: Problem with new reCAPTCHA in a single-page An...
- no hay manera de entender los malditos rechapta es...
- Blogger maisdoquevcimagina
- Re: Still seeing the OLD ReCAPTCHA, not the new one
- Re: Hardening CAPTCHA against attacks - actual peo...
- New recaptcha width
- Re: Problem with new reCAPTCHA in a single-page An...
- Centering the NoCAPTCHA ReCAPTCHA
- Re: Centering the NoCAPTCHA ReCAPTCHA
- Re: Hardening CAPTCHA against attacks - actual peo...
- Any details/further documentation available e.g. o...
- Re: Anyone implimented the new recaptcha in 'ole C...
- Re: Still seeing the OLD ReCAPTCHA, not the new one
- Re: Async issues
- Delivery Status Notification (Delay)
- Text field on ReCAPTCHA popup window becomes non e...
- help
-
▼
dic 11
(18)
No hay comentarios:
Publicar un comentario