Researcher Discover “A logic vulnerability” dubbed ReBreakCaptcha to bypassing Google’s reCAPTCHA fields which is using for prevent from robots and abusive scripts to access sites by using google’s Speech Recognition API.
According to the Security Researcher , a bypass Technique called ReBreakCaptcha which is used for bypass Google’s ReCaptcha v2 anywhere on the web.
The proof-of-concept code the researcher released allows attackers to automate the process of bypassing reCAPTCHA fields, currently used on millions of sites to keep out spam bots.
Researcher explained in East-Ee Security , ReBreakCaptcha works in three stages ,
As per the Explantion give by the East-Ee Security , 3 Types of ReBreakCaptcha challenges has bee performed in this task .
The challenge contains a description and an image which consists of 9 sub-images. The user is requested to select those sub-images that best match the given description.
The challenge contains an audio recording, The user is requested to enter the digits that are heard.
Now we have the audio challenge Recognition file and are ready to send it to Google Speech Recognition. How can this be done? Using their API.
The challenge contains a category and 5 candidate phrases. The user is requested to select those phrases which best match the given category.
The [verification] stage is fairly short.
East-EE has named this assault ReBreakCaptcha, and he says he found this weakness in 2016. Today, when he opened up to the Public about his research, he said the vulnerability was still unpatched .
Researcher released allows attackers to automate the process of bypassing reCAPTCHA fields, currently used on millions of sites to keep out spam bots by proof-of-concept code which is written by python and available in Github .
Also Read :
Google’s March 2025 Android Security Bulletin has unveiled two critical vulnerabilities—CVE-2024-43093 and CVE-2024-50302—currently under limited,…
A critical vulnerability in BigAntSoft's enterprise chat server software has exposed ~50 internet-facing systems to…
With the growing importance of security compliance for startups, more companies are seeking to achieve…
Two critical security flaws in IBM Storage Virtualize products could enable attackers to bypass authentication…
A newly disclosed path traversal vulnerability (CVE-2024-4885) in Progress Software’s WhatsUp Gold network monitoring solution…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent warning on March 3,…
View Comments