Global Journal of Computer Science and Technology (D) Volume XIII Issue III Version I | Year 2013

CAPTCHA: Attacks and Weaknesses against
OCR Technology

Silky Azad α & Kiran Jain σ

Abstract - The basic challenge in designing these obfuscating CAPTCHAs is to make them easy enough that users are not dissuaded from attempting a solution, yet still too difficult to solve using available computer vision algorithms. As Modern technology grows this gap however becomes thinner and thinner. It is possible to enhance the security of an existing text CAPTCHA by system-apically adding noise and distortion, and arranging characters more tightly. These measures, however, would also make the characters harder for humans to recognize, resulting in a higher error rates and higher Network load. This paper presents few of most active attacks on text CAPTCHAs existing today.

Keywords: CAPCHA, human interactive proofs, recaptcha, optical character recog-nition, tessaract, security.
I. Introduction

CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart)[1], also known as Human Interactive Proof (HIP), is an automated Turing test in which both generation of challenges and grading of responses are performed by computer programs. CAPTCHAs are based on Artificial Intelligence (AI) problems that cannot be solved by current computer programs or bots, but are easily solvable by humans.

Distorted visual text CAPTCHA from Hotmail
Figure 1 : CAPTCHAs from Internet Source Hotmail.com

The term “CAPTCHA” was first introduced in 2000 by Von an et al., [1] describing a test that can differentiate humans from computers. Under common dentitions, the test must be

  1. Easily solved by humans
  2. Easily generated and evaluated,
  3. But, Not easily solved by computer

Over the past decade, a number of different techniques for generating CAPTCHAs have been developed, each satisfying the properties described above to varying degrees. The most commonly found

Author α : Department of Computer Science, Doon Valley Institute of Engineering. E-mail: silkyzd15@gmail.com
Author σ : Department of Computer Science, Doon Valley Institute of Engineering. Kurukshetra University, Kurukshetra.

CAPTCHAs are visual challenges that require the user to identify alphanumeric characters present in an image Obfuscated by some combination of noise and distortion. Figure 1 shows examples of such visual CAPTCHAs.

Another example of an excellent CAPTCHA service is re CAPTCHA[2], re CAPTCHA is a user-dialogue system originally developed by Luis von An, Ben Maurer, Colin McMillan, David Abraham and Manuel Blum at Carnegie Mellon University's main Pittsburgh campus.

reCAPTCHA system interface showing words 'island nwaswdn'

It uses the CAPTCHA interface, of asking users to enter words seen in distorted text images onscreen, to help digitize the text of books, while protecting websites from bots attempting to access restricted areas. [1]

a) Applications of CAPTCHAs

CAPTCHAs are used in attempts to prevent automated software from performing actions which degrade the quality of service of a given system. CAPTCHAs are also used to minimize automated postings to various sites.

  • Preventing Comment Spam in Blogs.
  • Protecting Website Registration.
  • Protecting Email Addresses.
  • Prevention from Scrapers.
  • Online Polls. IP addresses of voters are recorded in order to prevent single users from voting more than once.
  • Preventing Dictionary Attacks. CAPTCHAs can also be used to prevent dictionary attacks in password systems.
  • Search Engine Bots. It is sometimes desirable to keep WebPages un-indexed to prevent others from finding them easily.
  • Preventing Worms and Spam. CAPTCHAs also offer a plausible solution against email worms and spam.
II. Related Work

Marti Motoyama, et al [2] The Authors describes the reverse Turing tests, or CAPTCHAs, have become a