Testing for Captcha (OWASP-AT-012)

This article is part of the new OWASP Testing Guide v4.
WARNING: CAPTCHA is considered to be an ineffective security mechanism - most current CAPTCHAs in these days can be cracked in a fully automated way!

Brief Summary

CAPTCHA ("Completely Automated Public Turing test to tell Computers and Humans Apart") is a type of challenge-response test used by many web applications to ensure that the response is not generated by a computer.


