March 7, 2008 3:26 PM PST

Gmail falls prey to spam bots

Updated 4:25 p.m. PST with additional Google comment.

Spammers have cracked the captcha mechanism Gmail uses to make sure you are a human before you can open an e-mail account, leading to a huge increase in the amount of spam sent from Gmail last month, security firm MessageLabs says.

We've all been subjected to captcha programs when signing up for Web services. They typically consist of a box with some characters, either distorted or displayed against some noisy background, and you have to type the letters and numerals in exactly as you see them before the system will accept your sign-in.

MessageLabs created this graphic that shows how a bot fakes out a captcha and uses the newly created e-mail accounts to send out spam.

(Credit: MessageLabs)

They are designed to catch, or stop, automated programs called bots that are written to create new accounts for spammers to use. Annoying as the captcha systems are, they have been successful in keeping bots out, until recently.

Yahoo Mail and Hotmail captcha mechanisms were broken in July 2007, according to MessageLabs. And now, Gmail has succumbed.

As a result, the proportion of spam sent from Gmail accounts doubled from 1.3 percent in January to 2.6 percent in February, mostly promoting adult-oriented Web sites, MessageLabs says.

A Google representative said she could not confirm or deny that the captcha method used in Gmail had been broken, but did confirm that there had been an increase in spam recently.

The Gmail captcha problem was reported in late February by another security firm, Websense.

Gmail is an attractive target for spammers because a Google account is free and offers access to a wide range of services. Also, Google domains are unlikely to be blacklisted, Websense says.

This screenshot shows network analysis of a bot cracking Gmail's captcha mechanism, a more sophisticated attack than one used to crack Live Mail's captcha technique, Websense says.

(Credit: Websense)
Recent posts from News Blog
Yahoo tries to conceal lawsuit documents
HP to launch fall line of teen PC products
Hooray! Yahoo Mail ditches tagline ads
Conde Nast buys Ars Technica
Sugar Labs will make OLPC interface available for Eee PC, others
Powered by Jive Software
advertisement
  • About News Blog

  • Recent posts on technology, trends, and more.

Add this feed to your online news reader
Google
Yahoo
MSN

Most popular stories

  1. Images: Microsoft telescope puts universe on your desktop

  2. Photos: Cracking open the Atari 2600

  3. This VC forecast scares the pants off of me

  4. End of Intel, AMD duopoly near? Via readies Isaiah chip

  5. Photos: Microsoft previews 2008 Xbox games

Latest tech news headlines

Featured blogs

Beyond Binary by Ina Fried

Coop's Corner by Charles Cooper

Defense in Depth by Robert Vamosi

Geek Gestalt by Daniel Terdiman

Green Tech

One More Thing by Tom Krazit

Outside the Lines by Dan Farber

The Iconoclast by Declan McCullagh

The Social by Caroline McCarthy

Underexposed by Stephen Shankland

advertisement
On MovieTome: See the newest trailer for DARK KNIGHT
Advanced
search
Advanced
search
Visit other CNET Networks sites: