Re: Defeating audio captcha systems

To: Jos?e M. Palazon Romero <>
Subject: Re: Defeating audio captcha systems

Dear Jos?e M. Palazon Romero,

This   approach   is   not   new,   it   was   demonstrated  by  ShAnKaR
<shankar_(at)> against Simple Machines Forum 1.1.2 in June,

See: (in Russian) (Exploit code)

--Tuesday, January 15, 2008, 9:01:03 AM, you wrote to

JeMPR> Hi all,

JeMPR> Some days ago I wrote an advisory which demonstrates how the
JeMPR> Math Antispam Spinoff plugin for wordpress
JeMPR> ( can be defeated by its
audio file.

JeMPR> It's hard to summarize, you better read the advisory, but in a
JeMPR> small nutshell, the flaw its about not using any kind of
distortion on
JeMPR> the audio clip, which makes it easily identificable by a script.

JeMPR> Here is the link:


JeMPR> I'm sure you will find the advisory inspirational, as the
approach is
JeMPR> applicable to many other capthas, and anti-script methods.

JeMPR> Regards

JeMPR> Jose

  ...       . ()

Copyright © 1995-2020 All rights reserved.