Empresas
Empleos
  • Sobre nosotros
  • Soluciones
    • Publicación de vacantes
      Publica tu vacante y recibe candidatos calificados en 48h.
    • Evaluación de candidatos
      500+ pruebas técnicas y psicológicas, más anti-fraude.
    • Headhunting
      Búsqueda ejecutiva a la medida de principio a fin.
    • Nómina + EOR
      Dispersión de nómina y EOR en más de 15 países de LATAM.
  • Precios
  • Empleos

0

179
Vistas
Security Risks of Using a Captcha Solving Provider such as 2captcha, deathbycaptcha, anticaptcha, azcaptcha, captcha.io

My question pertains to the general security of using a captcha solving provider.

First to explain using a captcha provider the required steps are:

  1. send out a get or post http request to the service provider with the data-sitekey, url, and your api key (that comes from the service provider to know whose account to charge and that you are a valid user)
GET https://2captcha.com/in.php?key=YOUR_API_KEY&method=userrecaptcha&googlekey=6LeIxboZAAAAAFQy7d8GPzgRZu2bV0GwKS8ue_cH&pageurl=http://2captcha.com/demo/recaptcha-v2
  1. send out a get or post http request to get the solution. Resend until the captcha is solved or has failed to solve (not always a %100 percent solve rate). Can take up to a minute some times to solve.
GET https://2captcha.com/res.php?key=YOUR_API_KEY&action=get&id=2122988149
  1. Get a solution token response
OK|03AHJ_Vuve5Asa4koK3KSMyUkCq0vUFCR5Im4CwB7PzO3dCxIo11i53epEraq-uBO5mVm2XRikL8iKOWr0aG50sCuej9bXx5qcviUGSm4iK4NC_Q88flavWhaTXSh0VxoihBwBjXxwXuJZ-WGN5Sy4dtUl2wbpMqAj8Zwup1vyCaQJWFvRjYGWJ_TQBKTXNB5CCOgncqLetmJ6B6Cos7qoQyaB8ZzBOTGf5KSP6e-K9niYs772f53Oof6aJeSUDNjiKG9gN3FTrdwKwdnAwEYX-F37sI_vLB1Zs8NQo0PObHYy0b0sf7WSLkzzcIgW9GR0FwcCCm1P8lB-50GQHPEBJUHNnhJyDzwRoRAkVzrf7UkV8wKCdTwrrWqiYDgbrzURfHc2ESsp020MicJTasSiXmNRgryt-gf50q5BMkiRH7osm4DoUgsjc_XyQiEmQmxl5sqZP7aKsaE-EM00x59XsPzD3m3YI6SRCFRUevSyumBd7KmXE8VuzIO9lgnnbka4-eZynZa6vbB9cO3QjLH0xSG3-egcplD1uLGh79wC34RF49Ui3eHwua4S9XHpH6YBe7gXzz6_mv-o-fxrOuphwfrtwvvi2FGfpTexWvxhqWICMFTTjFBCEGEgj7_IFWEKirXW2RTZCVF0Gid7EtIsoEeZkPbrcUISGmgtiJkJ_KojuKwImF0G0CsTlxYTOU2sPsd5o1JDt65wGniQR2IZufnPbbK76Yh_KI2DY4cUxMfcb2fAXcFMc9dcpHg6f9wBXhUtFYTu6pi5LhhGuhpkiGcv6vWYNxMrpWJW_pV7q8mPilwkAP-zw5MJxkgijl2wDMpM-UUQ_k37FVtf-ndbQAIPG7S469doZMmb5IZYgvcB4ojqCW3Vz6Q
  1. Inject the solution into the hidden text area in the site you are solving the captcha for. Methods are either to use Inspector and Developers Console to see the code of the website. Or to send a javascript callback that finds the element and injects it.
function injectToken() { document.getElementsByName("g-recaptcha-response").innerHTML=token}
injectToken()

My question is rather broad, and I apologize in advance for that, but there is no searchs or information I could find that could address this.

What is the security risks in sending out such requests to Captcha Solving Service Provider? None of their websites have any information pertaining to the security of their service? Tickets I have opened with them are still pending.

Would this allow for people to steal data, get access in anyway, execute code, or track the user?

How would you convince someone it is a secure service? None of the providers seem to care about providing the basic information on why there service does not introduction any security risks.

Also does it make a difference that some services use human workers that could also potentially have access to the site-key and url information from the request?

Excuse my ignorance. Hopefully your answers will bring me into the know. Thank you.

I have opened support tickets with various vendors. Searched on many forums and search engines with no avail.

about 4 years ago · Juan Pablo Isaza
Responde la pregunta
Encuentra empleos remotos

¡Descubre la nueva forma de encontrar empleo!

Top de empleos
Top categorías de empleo
Empresas
Publicar vacante Precios Comercial
Legal
Términos y condiciones Política de privacidad
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Recomiéndame algunas ofertas
Necesito ayuda