计算机工程 ›› 2006, Vol. 32 ›› Issue (20): 170-172.doi: 10.3969/j.issn.1000-3428.2006.20.062

• 安全技术 • 上一篇    下一篇

基于验证码破解的HTTP攻击原理与防范

吉治钢   

  1. (网易互动娱乐有限公司,广州 510665)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2006-10-20 发布日期:2006-10-20

Principles and Prevention of HTTP Attacks Based on Identifying Code Recogniztion

JI Zhigang   

  1. (Netease Interactive Entertainment Co., Ltd., Guangzhou 510665)
  • Received:1900-01-01 Revised:1900-01-01 Online:2006-10-20 Published:2006-10-20

摘要: 为防止基于表单自动提交的HTTP攻击,验证码技术得到了广泛应用。论文对常见的几种验证码形式作了简要介绍,讨论了验证码的破解原理,实验表明,互联网上相当多的验证码都不具有可靠的安全性。最后结合OCR技术探讨了一些防范方法。

关键词: 验证码, HTTP攻击, Internet安全

Abstract: To avoid HTTP attacks using automatic form-committing, the identifying code technique is widely used. A brief introduction of the types of identifying code techniques and its application is given. The principles of recognizing and attacking are discussed. Primary experiments suggest that quite a lot of identifying codes are not secure enough. Finally, some methods and schedules with OCR techniques for prevention are proposed.

Key words: Identifying code, HTTP attacks, Internet security