Re: Captcha testing
James Green <[email protected]>
| Newsgroups | gmane.comp.security.websecurity,gmane.comp.security.basics,gmane.comp.security.web-applications |
|---|---|
| Message-ID | <[email protected]> |
You might also want to go through the paper mentioned in the post. http://www.schneier.com/blog/archives/2010/10/analyzing_captc.html - jg On Wed, Oct 6, 2010 at 5:09 AM, Marco M. Morana <[email protected]>wrote: > I suggest using the testing of CAPTCHA using the test case of the OWASP > testing guide (AT 08) > > Regards > Marco > > Sent from my iPhone > > On Oct 2, 2010, at 1:21 AM, rajat swarup <[email protected]> wrote: > > > On Fri, Oct 1, 2010 at 12:25 PM, Kiran Kumar <[email protected]> > wrote: > >> > >> I required to test captcha feature. Is there any standards to test this > >> feature? please suggest me any materials & tools. > >> > > Typically CAPTCHAs are implemented mostly as an afterthought. One of > > the things that I've seen is simply submitting the form by removing > > the CAPTCHA parameters and the "captcha required flag" altogether and > > the forms still seem to work. It's a very basic test but seems to > > work a lot. > > > > Also, sometimes replay might work. So as long as you have one right > > CAPTCHA you can replay the form multiple times with that same CAPTCHA > > and things do work. > > > > Hope it helps! > > -- > > Rajat Swarup > > www.rajatswarup.com > > > > ------------------------------------------------------------------------ > > Securing Apache Web Server with thawte Digital Certificate > > In this guide we examine the importance of Apache-SSL and who needs an > SSL certificate. We look at how SSL works, how it benefits your company and > how your customers can tell if a site is secure. You will find out how to > test, purchase, install and use a thawte Digital Certificate on your Apache > web server. Throughout, best practices for set-up are highlighted to help > you ensure efficient ongoing management of your encryption keys and digital > certificates. > > > > > http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 > > ------------------------------------------------------------------------ > > > > > > This list is sponsored by Cenzic > -------------------------------------- > Let Us Hack You. Before Hackers Do! > It's Finally Here - The Cenzic Website HealthCheck. FREE. > Request Yours Now! > http://www.cenzic.com/2009HClaunch_Securityfocus > -------------------------------------- > >