Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    February 2012
    S M T W T F S
    « Jan    
     1234
    567891011
    12131415161718
    19202122232425
    26272829  
  • About Us
    Malware Blog > CAPTCHA Wish Your Girlfriend Was Hot Like Me?

    A nifty little program that Trend Micro detects as TROJ_CAPTCHAR.A disguises itself as a strip-tease game, wherein a scantily clad “Melissa” agrees to take off a little bit of her clothing. However, for her to strut her stuff, users must identify the letters hidden within a CAPTCHA. Input the letters correctly, press “go,” and “Melissa” reveals more of herself.

    Screenshots below:

    TROJ_CAPTCHAR.A screenshot

    TROJ_CAPTCHAR.A screenshot

    However, the “answers” are then sent to a remote server, where a malicious user eagerly awaits them. The strip-tease game is actually a ploy by ingenious malware authors to identify and match ambiguous CAPTCHA images from legitimate sites, using the unsuspecting user as the decoder of the said image.

    Interesting enough, the CAPTCHAs in the example above were taken from the Yahoo! Web site, possible proof that someone may be building a huge base of Yahoo! accounts. For spam-related reasons perhaps? Although various methods of OCR (Optical Character Recognition) are already used to circumvent the CAPTCHA, this social engineering technique is new in that it uses people to unsuspectingly aid a malicious user.

    The CAPTCHA, short for Completely Automated Public Turing test to tell Computers and Humans Apart, was born when bots started spreading over the Internet scene a few years ago. The system was aimed at preventing automated submissions/registrations of bots by prompting the user to validate himself as a human, usually requiring the user to input a sequence of alphanumeric characters contained in an image supposedly “unreadable” by a machine.

    However, some people are really hooked up on defeating the CAPTCHA, and they are literally asking for public help, in a rather discreet—and, um, provocative—manner.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    34 Responses to “CAPTCHA Wish Your Girlfriend Was Hot Like Me?”

    Trackbacks

    1. mein betrunkenes Gestotter » Verteiltes Rechnen
    2. Dennis Stolze : Blog
    3. Tom Smith's the OTHER blog
    4. Security Tips » Melissa Strips For Captcha Translations
    5. The Guerilla CISO » Blog Archive » Be a Slave to Nakedness and CAPTCHAs
    6. flyingpenguin » Blog Archives » CAPTCHA Strippers
    7. Business News Research » Cybercriminal Bets Users Will Trade Security For Sex — Security
    8. Alanat News » Cybercriminal Bets Users Will Trade Security For Sex
    9. CAPTCHAs: SPAMMERs as Social Engineers at thinkbeta.com
    10. Blogger News Network / One of the oldest social engineering techniques (sex) still seems to work!
    11. Would you like to know more? » Blog Archive » Ingenious Spam
    12. Lifestyle business » Blog Archive » СтрипCAPTCHA
    13. Hacking al alcance motivacional de las masas « Enciso’s Blog
    14. Hacking al alcance motivacional de las masas « PaQueSepas
    15. links for 2007-11-03 « Netweb
    16. Cómo los spammers descifran los CAPTCHAs «
    17. chmod007.com » Troca justa?
    18. Virtual Strippers to Boost Productivity ? | PuTech Naman! | Yet Another Technology Blog…
    19.   Batiburrillo links IV by Tecnorantes
    20. Jack Of All Blogs → Blog Archive » CAPTCHA and Social Engineering
    21. matthewgruman.com » Fooling the CAPTCHAS
    22. Melissa Strip Captcha Breaker Trojan… un troyano que parece que muchos no van a poder resistirse :
    23. V0lTr4n Bl0G » Blog Archive » Melissa Strip Captcha Breaker Trojan… un troyano que parece que muchos no van a poder resistirse
    24. Melissa Strip Captcha Breaker Trojan at BTT | Blog The Tech
    25. Cybercriminal Bets Users Will Trade Security For Sex
    26. XKOD | El troyano irresistible: Melissa Strip Captcha Breaker
    27. Rauschkinda.at blog
    28. Daemon Life » Blog Archive » Alan Turing e lo Spam
    29. Troyano Melissa Strip Captcha Breaker al ataque » El blog de KnxDT
    30. CAPTCHA-Hacking « Maikls Notizbuch
    31. greybrimstone (Adriel Desautels)
    32. greybrimstone (Adriel Desautels)
    33. greybrimstone (Adriel Desautels)
    34. Spineless Twit » CounterMeasures


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice