Guess what I’m in the mood to talk about? You guessed it. Captchas! In fact I feel like dedicating a whole week, maybe more depending on if any downtime occurs. to talking about nothing but captcha breaking. We’ll break every captcha in the book and even by the end of this post the captchas that haven’t been created yet. Furthermore, for this week only I am accepting any and all captcha related guest posts. So if you got a captcha solved or want to discuss techniques to breaking them feel free to write up a guest post and email it to ELI at BLUEHATSEO.COM in html form. You can stay anonymous and not only will I put it up but I’m also willing to put up any ad you’d like. Pick any text or banner ad you’d like to put up with your post and I’ll include it. With as many readers as this place has I’m sure it’ll get clicked. Also be sure to include your paypal address. If I really like your guest post I may even send you a $100 as a thank you. Also, all you bloggers are welcome to repost any of the captcha related posts on this blog. I now declare any captcha related posts on this blog public domain and republishable under full rights. For some odd reason I feel like blowing the captcha breaking industry the fuck up. Like my favorite saying goes, if you’re going to wreck a room you might as well WRECK it. Lets begin by visiting one of my first captcha related posts; the Army Of Captcha Typers.
The Army of Captcha Typers is a great technique because it doesn’t require loads of programming and is 100% adaptable to any captcha. I suggest you go back and reread it, but in interest of keeping this short here’s a quick summary.
You use a service, I used a proxy site as an example, to get the users to type in the captchas for you. It records what the user typed in as the solution to the captcha and you use that to solve it. The more pageviews the service provides per user the more effective it is to breaking captchas. Why pay Indians or tediously code it yourself?
Normally I like to leave most of the code and creative portion out of the written technique in interest of not ruining the technique and to help the methods be more effective through use of spins and unique code. I don’t write this blog to ruin techniques, and those people who claim I do are just insecure and like to claim they already know everything. As common sense as most of the stuff I post is, I haven’t met a person yet who hasn’t in some way learned something from this blog. That truth brags a lot louder than most SEO blogs I’ve seen. But! If we’re going to wreck something lets wreck it. In that spirit I see no reason why every newbie on the planet shouldn’t be able to easily throw up their own web proxy site that solves captchas for them so here’s the script to do it.
This a modified version of CGIPROXY that I mentioned in the post. Basically you install it following the included instructions (README file). Then you setup your web proxy site. Target a niche such as kids behind a school proxy or something similar. There is an extra file included called captcha.cgi. Upload it to the cgi-bin in the same folder as the nph-proxy.cgi and give it 755 chmod permissions. Make a folder one directory below your cgi-bin called captchas. Give it read/write permissions (777 should work all else fails). Then anytime you got a captcha to solve upload it to that directory with a unique filename. This can be done automatically with whatever script you’re using to spam a captcha protected site. On the very next pageview the webproxy will require the person to type in the captcha and disguise it as a human check to prevent abuse. Any captcha works. Once it gets their response it’ll delete the captcha from the folder and write out the solution along with the filename to a new file called solved.txt. Format: characters|image.jpg\n . Remember to make some kind of reminder or code for the filename so you know which image is which when you go to use the solutions. Get enough users to your webproxy (which is very easy) and you can solve any captcha in moments.
Enjoy!
157 Comments
Sorry, the comment form is closed at this time.
“For some odd reason I feel like blowing the captcha breaking industry the fuck up.” ROTFL! I got a pretty good idea what inspired this.
hahaha wreck the room dude!
Eli… what was the deal with the whitehouse redirect earlier this week brother? Course, I didn’t look through a proxy… maybe I was just being cloaked
http://www.wickedfire.com/shooting-shit/25354-eli-working-white-house.html
CAPTCHA is dead!
Take em down eli, all you fuckas had to do is leave eli alone.. hahahhahahah
Take em down.
Eli, Ive watched with great interest what has been happenning to this blog in the past couple of weeks whilst reading the eli working for whitehouse thread at wickedfire. I just want to say that the guy doing the dos attack must be iether a complete ass or very stupid, most probably both..
About the captchas, because i work mainly with php ive been looking at ways at breaking captchas using the gd library and/or image magik, although I havent really had any great results yet im getting there and hopefully i will send you the script to post when i can get it to a decent success rate, im on about 30% at the moment.
still looking forward to your seo empire part two post and dont let these dos attack asswipes grind you down
cheers
ROFLMAO
Mr. Eli
As I understand, you helped software terorists with attacks on the whitehouse.gov site.
Terorist and those people that help them can and will end up in Guantanamo Bay.
You have been warned!
George W. Bush
I don’t believe for a second that those ass hats attacking your site care about captchas.
But I personally find them interesting and I’m glad your back posting again.
Hey Eli, we have at least two more posts about captchas…
Can’t wait that long for the Seo Emp. p2 !!!!
Nice to see you back up Eli. I just hope the guy didn’t have a hard time breaking a captcha and decide “Screw breaking it myself, I’ll DDoS BlueHat and tell them it’s because they shared too many Captcha secrets. Then maybe he’ll get mad and break the captcha for me”. Not at all likely, but that’s the first thing that came to my mind after I read this. Either way, this should be an interesting week.
Stop the terrorists!!
Make Love, Not War, Break Captchas
Bring em out, break the captchas!
CAPTCHA isnt dead, but you guys are going to kill it soon enough. lol!
That’s cool, keep ‘em coming.
=)
This is too funny! I can’t wait to see what comes of this capthca study and experimentation!
I hate those captchas!! I know they are neccessary but i hope there will be another spam safer method in the future!!! Cause this things are ugly for normal users too!!!
Very interestingly!!! Thanks the author.
Useful article! I will necessarily try!
Nice investigation!
Captcha forever…
This I call outsourcing…
Your a maniac lol
hahah is nice. go go
hot
You are crazy
Captcha will dead
Capthca?? Terrorrism? What’s the industry coming to?
I guess i’m just begining to see how this makes any sense.
Captcha has now evolve to recaptcha, doing some social work while surfing the internet.
hahaha CAPTCHA is dead!
ahh, the captcha lol, i always hat having to fill these things out
Meh..I can’t stand those Captcha things. I hope they die.
I cant imagine how other people accept captcha jobs for a very very low cost.
I leave this stuff to the smart guys like Eli
I take my hat off to the guys who crack the code….I am human and can’t read the darn things!
Wow hats off to people who understand captchas! I can barely read the things.
hahaha! same with me! lol!
i freakin hat those, specially the ones that are smused together it like they try so hard for you to not get it right.
http://www.nodatetonight.com
When do we get to see more such stuff?
CAPTCHA is dead! is really easy to breaks now
I would add one small thing to your post.
Don’t delete the captcha until you have 2 people who have typed in the same answer for that captcha. It would require a few more lines of code to do some comparisons in the database but the added accuracy is worth it.
Thank you for taking the time and effort to discuss Captchas, informative article
Very clever. Your site is now in my bookmarks
Genius.
I’ve got some friggin learn to do.
Captcha’s are the vain of all evil on the so called “accessible internet” these days IMHO.
Image CAPTCHA is realy dead. But the ‘answer the question’ Captcha is work, yet.
Hm..it’s very necessary for my HomePage, I hate spamers…
Yeah captchas seem to get harder and harder to read for humans but questions are nice and easy to understand.
I think the captcha questions are ok though.
Bit beyond my skill set at the moment but thought it was very interesting. Makes me want to get back into programming!
It´s clever but not realisable or man on the street. (me for instance!)
Good work Eli! Kapcza DEAD!
Good Work. The Captcha is almost gone!
This is a pretty ingenious solution but it also requires time to code and it isn’t too fast if you intend to automate something on that website. As a developer I think it would be much easier to spend some time to just break the captchas. You don’t need a fancy algorithm. Neural networks is just fine and gives decent results even with a lot of garbage data around. After you have made your first captcha breaker you can reuse code and make a new one a any time. If you don’t know how to but have a noble purpose (aka educational purpose
) pay somebody in India or Eastern Europe to do it. It can be quite cheap in countries where developer wages are measured in hundreds of dollars not thousands
I love the idea of using a website like a proxy to get others to do the manual labor for you….
Just can’t think of any services that I cant use because of a captcha….
Very interestingly! I’ve got some friggin learn to do.
does any have any evil ways that this could be used to exploit?
i cant really think of any sites will catchas that i would like multiple entrys on.
To commenter above: Don’t use this for evil. Easy as that.
I have seen a CAPTCHA with “count the number of ninjas in the image”. I love that. Anyone knows where to get that from?
which is better, captcha with counting number or captcha with image?
Agree that captchas are a thing of the past.
This is pretty genius, I must say.
Captchas are my personal interest too and I have to admit there’s no way I’d thought of that myself.
Andy
If captchas go, some thing else will come and replace it. And then that will be cracked and on and on and on!
i hate captcha, my readers hate it too … , they become lazy to leave comments
Let’s wait till recaptcha is hacked.
I have never heard of a captcha til right now, i am really lost still..haha.
There are captcha services that help you bypass captchas like http://www.beatcaptchas.com
I really don’t know alot about captcha, so I tried to read your post - and guess what, I still don’t understand anything about it. All I know is that thousands of people from the Philippines or India or other countries make a meager dollar to type in 10000 (am I right?). What’s that for?
And oh, is an audio version of a captcha called captcha too? Haha.
Excellent. I found blue hat through someone that wasa using the technique very successfully… I’m a true follower of the method
this site says everything we should have already known. I fell stupid but wow I’ll be back for more!
i felt that captchas is so useful.
and i think it is still effective
Without captchas so much could be possible. Thanks for the post.
Very interesting post.Thanks for the sharing……
CAPTCHA is dead!
I need something that can automatically solve LylaCaptcha. If you point me in the right direction it would be greatly appreciated.
james
Great Post.
But Capcha is many blogs not dead.
I ask you all if this worth the effort. If the site makes money as well as solves captcha then I guess that’s cool, but otherwise it’s a lot of work on a long shot.
Captchas can only do so much. It helps though.
Speaking of George W. Bush:
George W. Bush committed hate crimes of epic proportions and with the stench of terrorism (indicated in my blog).
George W. Bush did in fact commit innumerable hate crimes.
And I do solemnly swear by Almighty God that George W. Bush committed other hate crimes of epic proportions and with the stench of terrorism which I am not at liberty to mention.
Many people know what Bush did.
And many people will know what Bush did—even to the end of the world.
Bush was absolute evil.
Bush is now like a fugitive from justice.
Bush is a psychological prisoner.
Bush has a lot to worry about.
Bush can technically be prosecuted for hate crimes at any time.
In any case, Bush will go down in history in infamy.
Submitted by Andrew Yu-Jen Wang
B.S., Summa Cum Laude, 1996
Messiah College, Grantham, PA
Lower Merion High School, Ardmore, PA, 1993
“GEORGE W. BUSH IS THE WORST PRESIDENT IN U.S. HISTORY” BLOG OF ANDREW YU-JEN WANG
______________________
I am not sure where I had read it before, but anyway, it is a linguistically excellent statement, and it goes kind of like this: “If only it were possible to ban invention that bottled up memory so it never got stale and faded.” Oh wait—off the top of my head—I think the quotation came from my Lower Merion High School yearbook.
Captchas are good but they don’t work all the time.
Some occasion, Capthcas are annoying but it’s still important to protect spam
There are captcha services that help you bypass captchas like Decaptcher.
The price is $2 for 1000 CAPTCHAs.
You pay for correctly recognized CAPTCHAs only.
It’s almost standard for all blogs to have captchas.
There are too many choices. Which one should I use?
sometimes I use recaptchas plugin and it’s okay in my blog.
Very useful tool, I gave it a look especially to code source. Good.
I hope new post will come sooner. This is a complete and fashionable blog. Cool
Thank you
I tried the web proxy idea. Wow. Traffic is easy to get, after advertising a few places tons of eastern europeans were on it. Yeesh
They don’t really work well these days.
Yes, unfortunately captcha creators don’t lose time - now it really doesn’t work.. maybe more ideas?
It’s amazing how anything that can be created … can be destroyed.
I usually hate captchas those lame ones with the letters you can’t read, but yours in comments is at least readable.
I agree! Sometimes I will put in a captcha like 6 times before it is finally accepted! I do agree with the need for them but they should be made to at least be readable!!
I hate these blasted things, nice post and funny!
You’ve got captcha - you’ve got non automated spam.
hey how can its possible to catch them terrorist
that’s great articles i like the topic
Captcha is really important to block spammers
I think the captcha should be strong or it would be read by spam-bots.
good call
good call on cap
Accidentaly I hae to say that I fail those maths captchas then those where you need to decipher a pic.
Well, as I can see, the Captchas images have some id so that we can use to find it´s typed text? I´ll check it out…
fantastic article, really helpful information, I didnt know there was SO much to captchas!
I hate captchas. They’re everywhere these days and too often they don’t even work.
Captchas are the best way to prevent website from the spammer.
it protect from ordinary spammer. but in real life it is 98% . so works perfect
Your alternative to a captcha is terrible! Sorry but it really is. It usually takes me at least 2 tries to post a comment because I’m always told that i didn’t pass math!
What gives? 0 plus 9 is 9, why does it tell me it’s not?!
arrrghhh
I love simple captchas like yours. I can add a couple of numbes together. Half the time the slippery little letters that are stuck together I cannot figure out.
Guy
If CAPTCHA is dead, what’s next. It sounds like the arms race to me.
Captchas can be real trouble when your trying to get things done in a hurry. Thanks for these tips.
They’re still ok. I can’t remain complain as they’re still doing their job.
I like your non capta. Just the use of p,lain old simple addition problems. What happenes when the user cvant perform the simple arithmitic? lol
They do, do their job but can be a little annoying at times.
No More Captcha =))
Your article is an excellent example of why I keep comming back to read your excellent quality content that is forever updated. Thank you
Thanks for that awesome tool mate
CAPTCHAS is dead, long live CAPTCHAS
That’s really cool how you broke that down. Captchas are becoming more useless.
No matter what they do to shore up CAPTCHAs there will always be some people who rise to the challenge and figure them out.
Drop it like Pro…
Great post, Captchas wind me up soooo much.
a wonderful and detailed article again where I have learned something, hope it will find many other readers here, thanks to first, but still fun
Really a great Post.
I’m not sure I understand this CAPTCHA crack. How would this work on a dynamically generated CAPTCHA image?
Really cool how you handle that. I think captchas will be more and more useless.
Well Captcha is not really bad. I protected my customer service email with captcha. But Captcha can be so annoyed if too hard to read.
Thanks for good stuff
Thanks for good stuff.
Keep posting!
thanks for the great info on captchas and keep up the good work
Thanks for posting the info.
class information, which makes it nice still sites that are fully informed. again many thanks and keep it up
captcha is so usefull against guestbook spammer tools, thanks for the article.
Very usefull infomation, thank you.
Immer das mit den Captchas
good infornation!thanks for you
captcha is useful gainst spaming but the fact is that spammers have many ways to break it so s ome new technique is required to protect against spammers
We dont like them too
very nice your post and interesting…
Yeah, Captcha is very useful because no spambot can surpass it’s checks even if it’s adding numbers like here. Some black hat softwares won’t work when captcha is involved because they cannot pick it up. It’s a good way to fight spam. I like your offer but I don’t have any much knowledge about Captchas hehe.
Useful article! I dont like captcha too
Captchas are good , they help preventing the spamming.
Will this method work with “salve this problem” type authentication?
the capthcas are really good for the users whcih are preventing from spamming.
Capcha is the magic portion to eliminate web proxy.
As far as my opinion is concerned I would simply like to say that it is fantastic.
According to me it is the best post in every way ………… Thanks
i think the guys who make SBD have come up with some capture reading software… not sure if its actually released yet though. nor have i tried it would be interesting to see if it works though.
im not so sure about this either.. having lots of high pr traget links might make a difference such as .edu and.gov but its not going to be easy!
the sbd guys have come up with or are developing some captcha reading software or so i hear… would be interesting to see if it works!
Captchas are good thing against spamming but some times these are the headache for users when they continuously ask to the users.
Eli, you talked and discuss with detail about captchas, its really like a dreadful disease, especially when i cannot read it or the format is too weird to read it and user have to put the words again n again getting a same page asking to reenter the words. Ahhhh
Very useful article! I dont like captcha too but i think they are useful in Blogs to protect for too much spam.
In my opinion Captchas are really good for bloggers to prevent from spamming.
Yes but not all the very captchas dont stop spam boots
the most captchas stops spamming but not really all. you must try it
Interesting blog post. I love reading your information and utilizing it on my websites. Thank You!
good information, however not all captha can stop spamming..
I actually don’t use captchas any longer. Proxy detection and blacklisting is far more reliable.