• 1 Post
  • 122 Comments
Joined 2 years ago
cake
Cake day: December 28th, 2023

help-circle




  • You’re given the challenge to solve by the server, yes. But just because the challenge is provided to you, that doesn’t mean you can fake your way through it.

    You still have to calculate the answer before you can get any farther. You can’t bullshit/spoof your way through the math problem to bypass it, because your correct answer is required to proceed.

    There is no way around this, is there?

    Unless the server gives you a well-known problem you have the answer to/is easily calculated, or you find a vulnerability in something like Anubis to make it accept a wrong answer, not really. You’re stuck at the interstitial page with a math prompt until you solve it.

    Unless I’m misunderstanding your position, I’m not sure what the disconnect is. The original question was about spoofing the challenge client side, but you can’t really spoof the answer to a complicated math problem unless there’s an issue with the server side validation.



  • it’s a real shame MS see security architecture as a nuisance rather than a core responsibility of their business.

    I’m pretty sure the reason behind this is that they treat backwards compatibility as a higher priority in a lot of cases. There are so many odd choices I see in my day to day that I can only explain away by backwards compatibility. It’s part of the reason you see them take forever to depreciate old and insecure protocols until they get an encouragement from a vuln hitting the news.