Social networking - Facebook Attackers May Have Cracked CAPTCHA - eWeek Security Watch

Facebook Attackers May Have Cracked CAPTCHA

Written By
Brian Prince
Brian Prince
Oct 2, 2009
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Researchers at AVG Technologies may have uncovered a scheme by attackers to circumvent the CAPTCHA protections on Facebook to create fraudulent accounts.

According to Roger Thompson, chief of research at AVG, the firm discovered a number of Facebook pages whose creation appears to have been automated by attackers. The bogus pages were being used to spam out links leading to sites pushing rogue antivirus.

“The rogues are being created by some central group…and then being re-sold via an affiliate model,” he said. “Once it’s installed…at a minimum, they get your credit card when you register the software.”

If attackers have indeed cracked the CAPTCHA on Facebook, it will hardly be the first such defense to fall. Black hats have made mincemeat of CAPTCHA technologies on Yahoo Mail and other Web mail services in the past. However, officials at Facebook aren’t sure that’s what happened.

“Based on our investigation and the relatively small number of accounts created, we’re almost certain that they were created manually, rather than by a bot,” Facebook spokesman Simon Axten said. “We think this actually validates the captchas we use, as well as the various other automated security systems we’ve implemented, which severely limited the scope of this attack and enabled us to get all evidence of it off the site before people were actually harmed.”

Thornton conceded it was possible the accounts were created manually, but he doubted it.

“They might be setting them up manually, but the numbers of accounts seem to be too high for that, and the accounts look automated,” he said. “There’s no extra data, for example. It’s the same each time, and only the name changes.”

Either way, Axten said Facebook is working to identify any fake accounts that have been created and disable them. In the meantime, Facebook users are advised to use caution when receiving unsolicited links or messages from people they don’t know.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.