PHPBB3 Captcha is super easy

PHPbb3 Captcha 2

A while back I presented a long-winded algorithm that would crack phpBB3 captchas. However I cracked it a while back and it’s even simpler than I said before. My floodfill routine returns the size of the area it colours in. Soooo… I flood fill background coloured pixels and if it’s a small area we assume it must be part of a letter and keep it. That gives us lots of small segments to join together.

Incidentally we find the background colour by reading the pixels along the top and finding the most regularly occuring colour.

Now we have some small segments we make them touch each other by blurring them and then we force the picture into only two colours. Then using the average density of vertical lines in each letter we rotate them to an approximately correct position. It may throw a few upside down but as long as that letter always comes out that way up the computer doesn’t care.

Now just train Gocr or a neural network or <<insert cunning program here>> to read those letters. Simple. And surprisingly accurate too. We could further improve it with colour checking routines etc but hey, it works.

49 Responses to “PHPBB3 Captcha is super easy”

  1. Joe Splogs Says:

    I have spent today porting your phpBB2 captcha code into my ‘web content creation framework’ ;). The accuracy is excellent and I had never thought of using a dual human and machine approach to captcha cracking. I noticed a lot of phpBB sites are using alternative captchas, so the human side is very useful to get these out of the way.

    One thing I found that was useful to add to your code is something that selects the first option of all select elements (I use a wrapper of the XML DOM and XPath functions to do this). There are quite a lot of mods to phpBB that add extra required fields to the registration form. Using the above solution you can still sign up to these site :)

    Right now I am just getting the registration confirmation text in every language so I can get confirmation. I guess a smart guy would have instantly realised this is probably all in the phpBB distro :|

    Right now I have a few terminal windows ripping up phpBB2 dorks (gotta love those open source programmers) from Yahoo. DB already has 3,589 confirmeed installs :>. Thanks for sharing your phpBB2 code. Is the 3 code going to be made available?

  2. Harry Says:

    I plan to release it eventually in a GTK wrapper as a desktop application.

    Anyway it sounds like you’ve added quite a few things I haven’t thought about. And the whole part of failing a captcha and then showing it to the user idea (At least that what I assume you mean). I didn’t plan it to be used like that :D , but that idea kinda rocks except I bore easily typing in captchas. I did wonder if in Linux you could background run a process that pops the captcha up in some image preview program so that you can still see it from the command line.

    Next thing is to avoid detection.

  3. Kredite ohne Schufa Says:

    Thanks for sharing super easy PHPBB3 Captcha.I think captcha is essential for a blog to protect spam.

  4. nogenius Says:

    Really good stuff - keep up the good work on posting.

    I have to say no one else talks about this kind of material, and it’s refreshing to be able to read about it, think about it, and code it. :)

  5. seo Says:

    Well, I never thought that this can be this easy. Thanks.

  6. reise forum Says:

    Thanks a lot for providing this PHPBB3 Captcha.I will check it.

  7. Jobs in South Yorkshire Says:

    This is really looks easy.I never thought that it is so easy.

  8. Delivery Codes Says:

    I had never thought deeply about this thing.This is really looks easy.Thanks for the post.

  9. Promotional Codes Says:

    I thought this is a tough job.But this time it looks like vey easy.Thanks.

  10. Coupons Says:

    I always thought how they make this things.Thanks for sharing.

  11. Kredite Says:

    thats really easy
    thank you 4 this tip

  12. Liberty Leasing Services Says:

    Good work man… these are the great things you are putting here and helping folk

    thanks

  13. acne Says:

    I havent had ANY yet and all my pages are in google and linked via many sites, I think the capatcha is doing great!

  14. Startlogic Review Says:

    The reason of using a captcha didn’t even work. no matter how hard or easy they are. So I quit thinking about that.

  15. New York Document Scanning Says:

    think captcha is essential for a blog to protect spam.

  16. Testttyq Says:

    Hello

    G’night

  17. Voucher Codes Says:

    I always wondered how they did this

  18. Discount Codes Says:

    That is great info, well written and interesting. Very useful, so thanks. Top man!

  19. Current Voucher Codes Says:

    Interesting information. I’ve always wondered how these things get cracked.

  20. Essay Says:

    I think this captcha is very good to see. but it is very good stuff and easy work. it is a very good concept too.

  21. SA Flights Says:

    Thanks for the great article. very useful

  22. Security Door Says:

    Brilliant

    I’m going to give it a whirl when I’m at home and the doors are locked.

    Keep up the great work

  23. Voucher Codes Says:

    I was looking a similar system to recognise terrain on mapping systems

  24. Cad Conversion Says:

    That’s very clever to blur the words by have the segments touch each other.

  25. Steel Building Today Says:

    No playing around with that phpBB3 captcha.

  26. acne Says:

    That’s definitely very easy to do. Great Catch.

  27. earth4energy Says:

    Really good stuff - keep up the good work on posting.

    I have to say no one else talks about this kind of material, and it’s refreshing to be able to read about it, think about it, and code it.

  28. Nintendo dsi Says:

    Thanks for the article. Really useful info.

  29. ivan Says:

    Thanks for the article.
    I’ve a website which is based on phpBB3. I’m using this captcha to protect website against spam bots.

    Which captcha should I use if phpBB3 captcha is easy to hack, ( reCAPTCHA or something else ) ?

  30. home desktop computers Says:

    thanks for this post.

    It is really good especially in determining if the user is really human or just computer-generated since these are images.

    Great post! Thumbs up for this. I hope to read more informative articles during my next visit. I hope next time you’ll feature home desktop computers.

  31. buy custom essays Says:

    Thanks for this great post, nice info wil help anyone, please keep up this great work

  32. voucher codes Says:

    This is a never ending battle, I have to admit to not knowing where it will stop.

    Josh

  33. Earth 4 Energy Says:

    Just one more thing for forum owners to worry about!?

  34. ekcol Says:

    Heh, poetic justice that this comment thread is full of spam.

  35. wow power leveling Says:

    Well, to soon to say if it’s good, but at least it’s well designed

  36. wow power leveling Says:

    Good article - plenty of food for thought.

  37. Law Says:

    good work

  38. Legal Says:

    excellent stuff

  39. SEO Nottingham Says:

    Get information - keep up the get posting…

  40. bedava sinema izle Says:

    Quite a useful feature you’ve added. Cheers again to the statcounter team.

  41. wow gold Says:

    it is very good!

  42. film izle Says:

    and it will be interesting to follow his progress.

    We are currently making the last changes before releasing the first version

  43. Runescape Money Says:

    MMORPG is now Runescape Gold

  44. Cracker Says:

    Good topic. you can buy any custom essay about PHPBB3 Captcha or buy essay here

  45. yazum Says:

    thank you very much

  46. film izle Says:

    thank you older brother…

  47. dupinghua Says:

    Dream in louboutin shoes

  48. dupinghua Says:

    Most dreams ed hardy caps

  49. wow power leveling Says:

    Great article, again. These informations are especially useful …

Leave a Reply

Enter this code