Rise in Gmail spam indicates more solved CAPTCHAs

By Jeremy Kirk, IDG News Service |  Security Add a new comment

Spam originating from Google's
Gmail domain doubled last month, indicating that spammers are still defeating
the CAPTCHA, the distorted text used as a security test to thwart mass registration
of e-mail accounts and other Web site abuse.

Gmail spam went from 1.3 percent of all spam e-mail to 2.6 percent in February,
according to data released by e-mail security vendor MessageLabs
on Monday.

The new statistics are another nail in the coffin for CAPTCHA, which stands
for Completely Automated Public Turing test to tell Computers and Humans Apart.

Google is the latest free Web mail provider to be victimized by spammers' efforts
to create software to solve the codes, or at times, also employ people to solve
the codes en masse.

"It's only a matter of time before [CAPTCHAs] are comprehensively defeated,"
said Paul Wood, senior analyst at MessageLabs.

Last month, security vendor Websense
ascertained
that spammers were using two hosts to crack Gmail's CAPTCHAs.
The method appeared to be successful only 20 percent of the time. But if the
procedure is repeated thousands of times, many new accounts can be generated
and used to send spam.

Most of the messages use links and images to advertise adult entertainment
sites, Wood said.

While other spammy domains can simply be blocked by antispam software, businesses
are reluctant to cut off the domains of free Web mail providers because of their
legitimate use, he said. Spam from Web mail providers comprises 4.2 percent
of all spam.

Google's CAPTCHA system is considered hard to crack, but so was Yahoo's, which
is also regularly beaten. MessageLabs said 88.7 percent of the spam from free
Web mail providers comes from Yahoo's domains.

Microsoft's CAPTCHA, used for registering accounts on its Windows Live Mail
service, has also been cracked. Websense believes the same group of spammers
are responsible for breaking both Google and Microsoft's system.

Wood said MessageLabs provides Google as well as other companies with data
that helps fight spam. Google could not be reached for comment.

MessageLabs sells a security service to companies, filtering e-mail before
passing it to their 17,000 customers. Per day, the company snags 2.5 billion
spam messages from a total of more than 3 billion messages.

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    SecurityWhite Papers & Webcasts

    White Paper

    Overcome Top 7 Admin Challenges of Active Directory

    As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

    White Paper

    Insiders Can Ruin Your Company. Take Action.

    Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

    White Paper

    Top Solutions and Tools to Prevent Devastating Malware

    Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

    White Paper

    Streamline Compliance and Increase ROI

    Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

    White Paper

    X-Ray of the PCI Process-4 Proactive Steps

    This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

    See more White Papers | Webcasts

    Ask a question

    Ask a Question