Insufficient Anti-automation

Insufficient Anti-automation is when a web site permits an attacker to automate a process that should only be performed manually. Certain web site functionalities should be protected against automated attacks.s

Left unchecked, automated robots (programs) or attackers could repeatedly exercise web site functionality attempting to exploit or defraud the system. An automated robot could potentially execute thousands of requests a minute, causing potential loss of performance or service.

For example, an automated robot should not be able to sign up ten thousand new accounts in a few minutes. Similarly, automated robots should not be able to annoy other users with repeated message board postings. These operations should be limited only to human usage.


Telling Humans Apart (Automatically)

"Ravaged by Robots!", By Randal L. Schwartz

".Net Components Make Visual Verification Easier", By JingDong (Jordan) Zhang

"Vorras Antibot"

"Inaccessibility of Visually-Oriented Anti-Robot Tests"

