Vcoderz Community
We create websites that have it all, beauty & brains
Lebanon Web Design & Development - Coddict
 

Go Back   Vcoderz Community > Computer Zone > Computers & Information Technologies

Notices

Computers & Information Technologies « Everything related to computers and internet. »

Reply
 
Share Thread Tools Search this Thread
Old 10-20-2009   #91
xcoder
Ma ghayro
 
xcoder's Avatar
 
Last Online: 04-19-2018
Join Date: Dec 2005
Posts: 5,592
Thanks: 1,765
Thanked 4,201 Times in 2,361 Posts
Groans: 12
Groaned at 18 Times in 11 Posts
Default

Don't worry they will remove it soon =)


__________________
http://twitter.com/danymoussa
xcoder is offline   Reply With Quote
Old 10-20-2009   #92
Google

 
Google's Avatar
 
Last Online: 05-30-2013
Join Date: Jan 2008
Posts: 1,788
Thanks: 10,018
Thanked 1,100 Times in 651 Posts
Groans: 1
Groaned at 6 Times in 6 Posts
Default

Quote:
Originally Posted by xcoder View Post
Don't worry they will remove it soon =)
I thought that they might remove it. But at the end. I don't really care.
And are you saying this based on some feelings, thoughts or insights?


I'm being very busy for the moment. I will try to solve that problem as soon as I can. But let's face it. How would I manage to solve this problem?
I have 4 solutions in mind and I don't mind this time publishing them in public. Let it be.

1- Code an OCR (optical character detection) function and add it to the bot.
2- Make the CAPTCHA image load in the bot form (Exactly like Alfa did).
3- Implement my CAPTCHA exploit in the bot.
4- Other_unknown_method (Maybe a private exploit ).


Solution 1 is perfect theoretically speaking but not practically. Cause OCR methods have a certain accuracy. When coding some spam bots, this accuracy doesn't really matter since for example if the bot didn't make it with the 20% false positives to register to a certain website, it will make it with the other 80%, so for example 800 users will be created from 1000 attempts (Which is very good!). While this is acceptable when dealing with spam bots, it is not acceptable in our case. Cause suppose the accuracy of my OCR algorithm is 95%, means that there are still 5% of false positives. These 5% can occur at any time, so we won't take the risk and use a program that drops 5% of the sent messages without the user knowing. So the solution 1 can't be a real solution in our case because there is not ideal OCR algorithm with 100% accuracy.


Solution 2 is a mimic state for the current one on Alfa website. This will surely solve this problem, but I don't like it. I don't like the CAPTCHA thing at all. It is not because I'm the bot author, it is because... listen carefully...
Do you know what is the purpose of CAPTCHA tests? Alfa didn't really implement CAPTCHA in the right place. Not at all! CAPTCHA is used to avoid spam. Now in our case, the user only has 5 tiny messages to send. So putting a CAPTCHA there and forcing the user to analyze it and write it each time he/she wants to send a message is not really a good decision made by Alfa. I wonder who's the person behind this decision.

Solution 3 is based on an exploit found in the code of the CAPTCHA used by Alfa. You can find the code of the CAPTCHA used on CodeProject.Com. Actually the exploiting part is easy, ready and applicable (I'm not going to mention now any details about the exploit). But the hardest part of the whole process is to implement this exploit in the bot. I'm sure no one understands what I'm talking about because I didn't clarify the exploit and explain it. But it needs a human side to function within the bot. This cause a little dilemma here because the bot is meant to work by itself. Anyways, this exploit is under study (for the possibility to neglect the tiny human intervention in the process), not just for Alfa SMS bot but for other purposes also.

Solution 4 is not known for the time being because I haven't yet find the time to manage to solve this issue. Maybe I'll find other alternatives for the 3 solutions presented before.

At the end, I would like to thank Alfa for promoting the "security through obscurity" slogan. All I can say is that the CAPTCHA validation was a bad decision. I'll end up with this picture (edited by me). It expresses the whole scene.


__________________

Google is offline   Reply With Quote
The Following 2 Users Say Thank You to Google For This Useful Post:
Kingroudy (10-20-2009), SysTaMatIcS (10-21-2009)
Reply

  Vcoderz Community > Computer Zone > Computers & Information Technologies

Tags
alfa, alfa or mtc, bot, sms, v10



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 06:33 AM.


Lebanon web design and development
Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2026, Jelsoft Enterprises Ltd.
Ad Management plugin by RedTyger
Share