The University of Southampton
University of Southampton Institutional Repository

A simple generic attack on text Captchas

A simple generic attack on text Captchas
A simple generic attack on text Captchas

Text-based Captchas have been widely deployed across the Internet to defend against undesirable or malicious bot programs. Many attacks have been proposed; these fine prior art advanced the scientific understanding of Captcha robustness, but most of them have a limited applicability. In this paper, we report a simple, low-cost but powerful attack that effectively breaks a wide range of text Captchas with distinct design features, including those deployed by Google, Microsoft, Yahoo!, Amazon and other Internet giants. For all the schemes, our attack achieved a success rate ranging from 5% to 77%, and achieved an average speed of solving a puzzle in less than 15 seconds on a standard desktop computer (with a 3.3GHz Intel Core i3 CPU and 2 GB RAM). This is to date the simplest generic attack on text Captchas. Our attack is based on Log-Gabor filters; a famed application of Gabor filters in computer security is John Daugman’s iris recognition algorithm. Our work is the first to apply Gabor filters for breaking Captchas.

The Internet Society
Gao, Haichang
ca792d28-9307-46a6-ae7e-29b439d200cc
Yan, Jeff
a2c03187-3722-46c8-b73b-439eb9d1a10e
Cao, Fang
e6af6430-7ab4-4d19-ba36-1f1e0ec5aa71
Zhang, Zhengya
d5f6c486-ff50-4d9c-bddc-9ea4a3eb5f18
Lei, Lei
72192a6f-a439-4fd4-8010-d389b5ae3bf8
Tang, Mengyun
000e1359-083b-4bb0-b90b-0c16ef6c064d
Zhang, Ping
2def4374-679d-41d1-bf3a-483028a73275
Zhou, Xin
0de7851a-aa2c-41a3-915a-fb149c23d9cb
Wang, Xuqin
c30e2c7f-0873-417c-b4b7-dc9299cebd96
Li, Jiawei
74fa0a87-c34d-4ac8-bd64-23fcb4a60a61
Gao, Haichang
ca792d28-9307-46a6-ae7e-29b439d200cc
Yan, Jeff
a2c03187-3722-46c8-b73b-439eb9d1a10e
Cao, Fang
e6af6430-7ab4-4d19-ba36-1f1e0ec5aa71
Zhang, Zhengya
d5f6c486-ff50-4d9c-bddc-9ea4a3eb5f18
Lei, Lei
72192a6f-a439-4fd4-8010-d389b5ae3bf8
Tang, Mengyun
000e1359-083b-4bb0-b90b-0c16ef6c064d
Zhang, Ping
2def4374-679d-41d1-bf3a-483028a73275
Zhou, Xin
0de7851a-aa2c-41a3-915a-fb149c23d9cb
Wang, Xuqin
c30e2c7f-0873-417c-b4b7-dc9299cebd96
Li, Jiawei
74fa0a87-c34d-4ac8-bd64-23fcb4a60a61

Gao, Haichang, Yan, Jeff, Cao, Fang, Zhang, Zhengya, Lei, Lei, Tang, Mengyun, Zhang, Ping, Zhou, Xin, Wang, Xuqin and Li, Jiawei (2016) A simple generic attack on text Captchas. In 23rd Annual Network and Distributed System Security Symposium, NDSS 2016. The Internet Society. 14 pp . (doi:10.14722/ndss.2016.23154).

Record type: Conference or Workshop Item (Paper)

Abstract

Text-based Captchas have been widely deployed across the Internet to defend against undesirable or malicious bot programs. Many attacks have been proposed; these fine prior art advanced the scientific understanding of Captcha robustness, but most of them have a limited applicability. In this paper, we report a simple, low-cost but powerful attack that effectively breaks a wide range of text Captchas with distinct design features, including those deployed by Google, Microsoft, Yahoo!, Amazon and other Internet giants. For all the schemes, our attack achieved a success rate ranging from 5% to 77%, and achieved an average speed of solving a puzzle in less than 15 seconds on a standard desktop computer (with a 3.3GHz Intel Core i3 CPU and 2 GB RAM). This is to date the simplest generic attack on text Captchas. Our attack is based on Log-Gabor filters; a famed application of Gabor filters in computer security is John Daugman’s iris recognition algorithm. Our work is the first to apply Gabor filters for breaking Captchas.

Text
simple-generic-attack-text-captchas - Version of Record
Available under License Other.
Download (830kB)

More information

Published date: 2016
Venue - Dates: 23rd Annual Network and Distributed System Security Symposium, NDSS 2016, , San Diego, United States, 2016-02-21 - 2016-02-24

Identifiers

Local EPrints ID: 508335
URI: http://eprints.soton.ac.uk/id/eprint/508335
PURE UUID: d122d858-32c5-4fed-a699-7fdf045f4222

Catalogue record

Date deposited: 19 Jan 2026 17:35
Last modified: 19 Jan 2026 17:35

Export record

Altmetrics

Contributors

Author: Haichang Gao
Author: Jeff Yan
Author: Fang Cao
Author: Zhengya Zhang
Author: Lei Lei
Author: Mengyun Tang
Author: Ping Zhang
Author: Xin Zhou
Author: Xuqin Wang
Author: Jiawei Li

Download statistics

Downloads from ePrints over the past year. Other digital versions may also be available to download e.g. from the publisher's website.

View more statistics

Atom RSS 1.0 RSS 2.0

Contact ePrints Soton: eprints@soton.ac.uk

ePrints Soton supports OAI 2.0 with a base URL of http://eprints.soton.ac.uk/cgi/oai2

This repository has been built using EPrints software, developed at the University of Southampton, but available to everyone to use.

We use cookies to ensure that we give you the best experience on our website. If you continue without changing your settings, we will assume that you are happy to receive cookies on the University of Southampton website.

×