This captcha has been broken before and exploit code is available here:
http://www.securityfocus.com/archive/1/471641 . The fix was to add a
randomly generated static.
I was able to write code to decipher the audio file using a Fuzzy Logic
comparison http://en.wikipedia.org/wiki/Fuzzy_logic . The comparison is the
Hamming Distance http://en.wikipedia.org/wiki/Hamming_distance between the
original audio file and the damaged one generated by the Captcha.
peace
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Maksymilian Arciemowicz discovered a Integer Overflow
vulnerability in the libc library "strfmon()" function.A vulnerability could allow an attacker who successfully exploits this vulnerability to take control of the affected *BSD systems.