Hello Bugtraq! I want to warn you about security vulnerabilities in CaptchaSecurityImages. It's captcha script which is using at many web sites and engines. ----------------------------- Advisory: Vulnerabilities in CaptchaSecurityImages ----------------------------- URL: http://websecurity.com.ua/4043/ ----------------------------- Timeline: 06.10.2007 - found Insufficient Anti-automation vulnerability, during conducting of my project Month of Bugs in Captchas (http://websecurity.com.ua/category/mobic/). 17.09.2009 - found Denial of Service vulnerability. 17.03.2010 - disclosed at my site. 18.03.2010 - informed developers. ----------------------------- Details: These are Insufficient Anti-automation and Denial of Service vulnerabilities. Insufficient Anti-automation: Parameters characters, width and height fall under manipulation in the captcha. They can be set in such way, that will allow easy bypass of the captcha via half-automated or automated (with using of OCR) methods. And in some systems (http://websecurity.com.ua/4046/) it's also possible to use session reusing with constant captcha bypass method. http://site/CaptchaSecurityImages.php?width=150&height=100&characters=2 In that way it's possible to set two characters and increase the size of the captcha. DoS: http://site/CaptchaSecurityImages.php?width=1000&height=9000 With setting of large values of width and height it's possible to create large load at the server. Best wishes & regards, MustLive Administrator of Websecurity web site http://websecurity.com.ua