Home Operation and Maintenance Safety How to easily bypass human-machine authentication Captcha

How to easily bypass human-machine authentication Captcha

May 11, 2023 pm 05:55 PM
captcha

The Writeup shared today is a simple human-computer authentication (Captcha) bypass method discovered by the author during the target website vulnerability test. The Chrome developer tools were used to create simple elements on the target website login page. The editor has implemented Captcha bypass.

Human-computer authentication (Captcha) usually appears on the registration, login and password reset pages of the website. The following is the Captcha mechanism arranged by the target website in the login page.

How to easily bypass human-machine authentication Captcha

As you can see from the picture above, the user can only click the login button (Sign-IN) after checking "I'm not a robot" of the Captcha verification mechanism. Display will be enabled for users to click on. Therefore, based on this, I right-clicked the Sign-In button, and then used the "Inspect Element" function of Chrome Developer Tools to view the underlying elements of the Sign-In button. At this time, I found that it was in the " After the "Submit" action, the "Disable" attribute is defined. Well, then I will change it to "Enable" and give it a try.

How to easily bypass human-machine authentication Captcha

With this change, the login button (Sign-IN) is displayed and clickable. Well, I am indeed not a robot. Human-machine authentication (Captcha) is here It became a decoration.

How to easily bypass human-machine authentication Captcha

I was curious about the server-side verification method, so I used BurpSuite to capture packets in the above process. I found that the server did not verify the Captcha operation submitted by the user at the beginning, so , even if I delete the submitted Captcha session content, I can still jump to the login page without triggering the "Enable" attribute.

How to easily bypass human-machine authentication Captcha

The above is the detailed content of How to easily bypass human-machine authentication Captcha. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

AI Hentai Generator

AI Hentai Generator

Generate AI Hentai for free.

Hot Article

R.E.P.O. Energy Crystals Explained and What They Do (Yellow Crystal)
4 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
R.E.P.O. Best Graphic Settings
4 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
R.E.P.O. How to Fix Audio if You Can't Hear Anyone
4 weeks ago By 尊渡假赌尊渡假赌尊渡假赌
WWE 2K25: How To Unlock Everything In MyRise
1 months ago By 尊渡假赌尊渡假赌尊渡假赌

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)