Re: [PHP] captcha WAS Please visit my php program

This is a discussion on Re: [PHP] captcha WAS Please visit my php program within the PHP General forums, part of the PHP Programming Forums category; --- "Chris W. Parker" <cparker@swatgear.com> wrote: > Exactly what is the purpose of this? Let ...


Go Back   Usenet Forums > PHP Programming Forums > PHP General

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 09-29-2003
Chris Shiflett
 
Posts: n/a
Default Re: [PHP] captcha WAS Please visit my php program

--- "Chris W. Parker" <cparker@swatgear.com> wrote:
> Exactly what is the purpose of this? Let me clarify. I know that
> it's supposed to prevent computers from submitting forms
> automatically because they cannot read the graphic, but what I
> don't understand is in what cases this is useful?


You have a page that collects credit card information for payment. An attacker
finds a database full of credit card numbers but wants to verify which ones are
still valid (it might be a very old database). So, after noticing your page,
this attacker writes a quick little script in PHP that loops through the list
of credit card numbers, submitting them to your site, and compares the output
to distinguish success from failure.

You end up with so many chargebacks that you lose your merchant account, and
your company loses so much money that you lose your job.

How's that? :-)

Chris

=====
HTTP Developer's Handbook
http://shiflett.org/books/http-developers-handbook
My Blog
http://shiflett.org/
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 03:12 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0