{"id":3582,"date":"2015-06-10T15:36:20","date_gmt":"2015-06-10T15:36:20","guid":{"rendered":"https:\/\/www.inmotionhosting.com\/support\/2015\/06\/10\/sweetcaptcha-service-security-alert\/"},"modified":"2015-06-10T15:36:20","modified_gmt":"2015-06-10T15:36:20","slug":"sweetcaptcha-service-security-alert","status":"publish","type":"post","link":"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/","title":{"rendered":"sweetCAPTCHA Service Security Alert"},"content":{"rendered":"<p class=\"alert alert-danger\">Who is affected? Websites that use the sweetCAPTCHA service<\/p>\n<p class=\"alert alert-success\">Solution:  <b>Remove sweetCAPTCHA<\/b> from website.  If you are a website viewer, ignore links or popups that may appear after using the sweetCAPTCHA service.  Do not download anything from the links and ignore the pop-up messages.<\/p>\n<p><b>SweetCATPCHA<\/b> is a service that uses images instead of distorted characters to make sure that someone is a person instead of robot. SweetCAPTCHA is found on many website platforms including thousands of WordPress installations.  However, there have been recent reports of this graphic appearing where sweetCAPTCHA has been in use:<\/p>\n<p> <a href=\"\/support\/images\/stories\/sweet-captcha-alert\/pop-up-alert.jpg\" rel=\"lightbox-0\"><img decoding=\"async\" alt=\"False image alert\" class=\"std_ss\" src=\"\/support\/images\/stories\/sweet-captcha-alert\/pop-up-alert.jpg\" width=\"400\"><\/a><\/p>\n<div style=\"clear:both;\"><\/div>\n<p>The resulting investigation showed that the sweetCAPTCHA code included Javascript that loaded the banner.  Unfortunately, this code was <b>not<\/b> added maliciously, but with intent from the developers of sweetCAPTCHA.  The addition of this code is covered in their Terms of Use<\/p>\n<blockquote>\n<p><i>5.2 You acknowledge that within the sweetCAPTCHA service and\/or sweetCAPTCHA API, There might be included 3rd party content which will be displayed for the purpose of user interaction. This content might include but will not be limited to ads, banners, links, search engine input fields and etc.<\/i><\/p>\n<\/blockquote>\n<h2>Malicious clktag in JavaScript<\/h2>\n<p>Recent investigation of the sweetCAPTCHA code has found the use of clktags which lead to popups, and several links that could install malware and viruses onto your computer.  If you do see those links, make sure to ignore and never download anything from them. <\/p>\n<h2>Other Malicious Scripts<\/h2>\n<p>If you do use other services like sweetCAPTCHA, make sure to closely read through their Terms of Use, and review the operation of the service over a period of a time.  There are definitely other malicious scripts in services both intentional and unintentional. Common services like extensions, add-ons and plugins include sliders, site meters, etc. that can contain scripts. If you select a product, make sure to check the community to see if other users have reported any problems and always keep a close eye on your website to make sure that nothing unexpected is occurring.<\/p>\n<p>This issue is not restricted to website owners, it\u2019s also a problem for website viewers.  Malicious scripts can be hidden in advertising in websites.  Always make sure to practice safe web browsing habits.  If you use reputable malware scanners, make sure to keep them up-to-date.<\/p>\n<h2>What do I do for the sweetCAPTCHA issue?<\/h2>\n<ul>\n<li>Remove sweetCAPTCHA \u2013 at least until they remove the services and amend their Terms of Use <\/li>\n<li>Be wary of any service you purchase and use for your website<\/li>\n<li>If you\u2019re adding code that\u2019s not yours, make sure to review the terms of use <\/li>\n<\/ul>\n<p> <i>For more information, please see <a href=\"https:\/\/blog.sucuri.net\/2015\/06\/sweetcaptcha-service-used-to-distribute-adware.html\" target=\"_blank\">this SucuriBlog post<\/a><\/i>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Who is affected? Websites that use the sweetCAPTCHA service Solution: Remove sweetCAPTCHA from website. If you are a website viewer, ignore links or popups that may appear after using the sweetCAPTCHA service. Do not download anything from the links and ignore the pop-up messages. SweetCATPCHA is a service that uses images instead of distorted characters<a class=\"moretag\" href=\"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/\"> Read More ><\/a><\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[4299],"tags":[],"class_list":["post-3582","post","type-post","status-publish","format-standard","hentry","category-security"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>sweetCAPTCHA Service Security Alert | InMotion Hosting<\/title>\n<meta name=\"description\" content=\"sweetCAPTCHA is a CAPTCHA service that uses images instead of distorted characters. Unfortunately, it has been recently found to be a source of malware due to javascript within its code. The following article advises on the issue and actions to take.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"sweetCAPTCHA Service Security Alert | InMotion Hosting\" \/>\n<meta property=\"og:description\" content=\"sweetCAPTCHA is a CAPTCHA service that uses images instead of distorted characters. Unfortunately, it has been recently found to be a source of malware due to javascript within its code. The following article advises on the issue and actions to take.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/\" \/>\n<meta property=\"og:site_name\" content=\"InMotion Hosting Support Center\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/inmotionhosting\/\" \/>\n<meta property=\"article:published_time\" content=\"2015-06-10T15:36:20+00:00\" \/>\n<meta name=\"author\" content=\"InMotion Hosting Contributor\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@https:\/\/twitter.com\/InMotionHosting\" \/>\n<meta name=\"twitter:site\" content=\"@InMotionHosting\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"InMotion Hosting Contributor\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/\"},\"author\":{\"name\":\"InMotion Hosting Contributor\",\"@id\":\"https:\/\/www.inmotionhosting.com\/support\/#\/schema\/person\/8d626175dd3b70ee90a172bdb09a460b\"},\"headline\":\"sweetCAPTCHA Service Security Alert\",\"datePublished\":\"2015-06-10T15:36:20+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/\"},\"wordCount\":440,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.inmotionhosting.com\/support\/#organization\"},\"articleSection\":[\"Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/\",\"url\":\"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/\",\"name\":\"sweetCAPTCHA Service Security Alert | InMotion Hosting\",\"isPartOf\":{\"@id\":\"https:\/\/www.inmotionhosting.com\/support\/#website\"},\"datePublished\":\"2015-06-10T15:36:20+00:00\",\"description\":\"sweetCAPTCHA is a CAPTCHA service that uses images instead of distorted characters. Unfortunately, it has been recently found to be a source of malware due to javascript within its code. The following article advises on the issue and actions to take.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.inmotionhosting.com\/support\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"sweetCAPTCHA Service Security Alert\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.inmotionhosting.com\/support\/#website\",\"url\":\"https:\/\/www.inmotionhosting.com\/support\/\",\"name\":\"InMotion Hosting Support Center\",\"description\":\"Web Hosting Support &amp; Tutorials\",\"publisher\":{\"@id\":\"https:\/\/www.inmotionhosting.com\/support\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.inmotionhosting.com\/support\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.inmotionhosting.com\/support\/#organization\",\"name\":\"InMotion Hosting\",\"url\":\"https:\/\/www.inmotionhosting.com\/support\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.inmotionhosting.com\/support\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.inmotionhosting.com\/support\/wp-content\/uploads\/2023\/02\/inmotion-hosting-logo-yoast.jpg\",\"contentUrl\":\"https:\/\/www.inmotionhosting.com\/support\/wp-content\/uploads\/2023\/02\/inmotion-hosting-logo-yoast.jpg\",\"width\":696,\"height\":696,\"caption\":\"InMotion Hosting\"},\"image\":{\"@id\":\"https:\/\/www.inmotionhosting.com\/support\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/inmotionhosting\/\",\"https:\/\/x.com\/InMotionHosting\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.inmotionhosting.com\/support\/#\/schema\/person\/8d626175dd3b70ee90a172bdb09a460b\",\"name\":\"InMotion Hosting Contributor\",\"description\":\"InMotion Hosting contributors are highly knowledgeable individuals who create relevant content on new trends and troubleshooting techniques to help you achieve your online goals!\",\"sameAs\":[\"https:\/\/www.linkedin.com\/company\/inmotion-hosting\/\",\"https:\/\/x.com\/https:\/\/twitter.com\/InMotionHosting\"],\"url\":\"https:\/\/www.inmotionhosting.com\/support\/author\/arn\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"sweetCAPTCHA Service Security Alert | InMotion Hosting","description":"sweetCAPTCHA is a CAPTCHA service that uses images instead of distorted characters. Unfortunately, it has been recently found to be a source of malware due to javascript within its code. The following article advises on the issue and actions to take.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/","og_locale":"en_US","og_type":"article","og_title":"sweetCAPTCHA Service Security Alert | InMotion Hosting","og_description":"sweetCAPTCHA is a CAPTCHA service that uses images instead of distorted characters. Unfortunately, it has been recently found to be a source of malware due to javascript within its code. The following article advises on the issue and actions to take.","og_url":"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/","og_site_name":"InMotion Hosting Support Center","article_publisher":"https:\/\/www.facebook.com\/inmotionhosting\/","article_published_time":"2015-06-10T15:36:20+00:00","author":"InMotion Hosting Contributor","twitter_card":"summary_large_image","twitter_creator":"@https:\/\/twitter.com\/InMotionHosting","twitter_site":"@InMotionHosting","twitter_misc":{"Written by":"InMotion Hosting Contributor","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/#article","isPartOf":{"@id":"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/"},"author":{"name":"InMotion Hosting Contributor","@id":"https:\/\/www.inmotionhosting.com\/support\/#\/schema\/person\/8d626175dd3b70ee90a172bdb09a460b"},"headline":"sweetCAPTCHA Service Security Alert","datePublished":"2015-06-10T15:36:20+00:00","mainEntityOfPage":{"@id":"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/"},"wordCount":440,"commentCount":0,"publisher":{"@id":"https:\/\/www.inmotionhosting.com\/support\/#organization"},"articleSection":["Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/","url":"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/","name":"sweetCAPTCHA Service Security Alert | InMotion Hosting","isPartOf":{"@id":"https:\/\/www.inmotionhosting.com\/support\/#website"},"datePublished":"2015-06-10T15:36:20+00:00","description":"sweetCAPTCHA is a CAPTCHA service that uses images instead of distorted characters. Unfortunately, it has been recently found to be a source of malware due to javascript within its code. The following article advises on the issue and actions to take.","breadcrumb":{"@id":"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.inmotionhosting.com\/support\/security\/sweetcaptcha-service-security-alert\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.inmotionhosting.com\/support\/"},{"@type":"ListItem","position":2,"name":"sweetCAPTCHA Service Security Alert"}]},{"@type":"WebSite","@id":"https:\/\/www.inmotionhosting.com\/support\/#website","url":"https:\/\/www.inmotionhosting.com\/support\/","name":"InMotion Hosting Support Center","description":"Web Hosting Support &amp; Tutorials","publisher":{"@id":"https:\/\/www.inmotionhosting.com\/support\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.inmotionhosting.com\/support\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.inmotionhosting.com\/support\/#organization","name":"InMotion Hosting","url":"https:\/\/www.inmotionhosting.com\/support\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.inmotionhosting.com\/support\/#\/schema\/logo\/image\/","url":"https:\/\/www.inmotionhosting.com\/support\/wp-content\/uploads\/2023\/02\/inmotion-hosting-logo-yoast.jpg","contentUrl":"https:\/\/www.inmotionhosting.com\/support\/wp-content\/uploads\/2023\/02\/inmotion-hosting-logo-yoast.jpg","width":696,"height":696,"caption":"InMotion Hosting"},"image":{"@id":"https:\/\/www.inmotionhosting.com\/support\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/inmotionhosting\/","https:\/\/x.com\/InMotionHosting"]},{"@type":"Person","@id":"https:\/\/www.inmotionhosting.com\/support\/#\/schema\/person\/8d626175dd3b70ee90a172bdb09a460b","name":"InMotion Hosting Contributor","description":"InMotion Hosting contributors are highly knowledgeable individuals who create relevant content on new trends and troubleshooting techniques to help you achieve your online goals!","sameAs":["https:\/\/www.linkedin.com\/company\/inmotion-hosting\/","https:\/\/x.com\/https:\/\/twitter.com\/InMotionHosting"],"url":"https:\/\/www.inmotionhosting.com\/support\/author\/arn\/"}]}},"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"primary_category":null,"_links":{"self":[{"href":"https:\/\/www.inmotionhosting.com\/support\/wp-json\/wp\/v2\/posts\/3582","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.inmotionhosting.com\/support\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.inmotionhosting.com\/support\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.inmotionhosting.com\/support\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.inmotionhosting.com\/support\/wp-json\/wp\/v2\/comments?post=3582"}],"version-history":[{"count":0,"href":"https:\/\/www.inmotionhosting.com\/support\/wp-json\/wp\/v2\/posts\/3582\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.inmotionhosting.com\/support\/wp-json\/wp\/v2\/media?parent=3582"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.inmotionhosting.com\/support\/wp-json\/wp\/v2\/categories?post=3582"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.inmotionhosting.com\/support\/wp-json\/wp\/v2\/tags?post=3582"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}