[Full-disclosure] Google reCAPTCHA Validation Bypass
Harry Strongburg
harry at harry.lu
Tue Aug 3 04:57:06 BST 2010
Google's reCAPTCHA is currently broken. At the moment, you may follow these steps to complete a CAPTCHA without user-input:
1) Click the "Play Sound" button (javascript:Recaptcha.switch_type('audio');)
2) Enter any sentence comprising of 10 words ("google google google google google google google google google google", as an example).
3) "Answer Correct!"
http://www.google.com/recaptcha/learnmore
Full-Disclosure is hosted and sponsored by Secunia.