Security Wiki
Clear definitions of CAPTCHA, bot protection, online fraud, and web security terms from the CaptchaFox team.
Behavioral analysis distinguishes humans from automation by how a session interacts, from cursor movement to typing rhythm and scrolling, with no user input required.
Read moreBot detection is the process of identifying automated traffic among human visitors by analyzing network, device, and behavioral signals per request.
Read moreBot management is the discipline of detecting, classifying, and responding to automated traffic, allowing good bots while blocking or challenging bad ones.
Read moreBot traffic is any website or API traffic generated by automated software instead of humans, and a large share of it is malicious.
Read moreBots-as-a-Service is the commercial rental of ready-made bot infrastructure: automation, proxies, and evasion tooling sold as a subscription.
Read moreBrowser fingerprinting derives an identifier from a browser's observable traits like versions, fonts, and rendering quirks, without storing anything on the device.
Read moreCanvas fingerprinting derives a device identifier from tiny differences in how a browser renders graphics, with no cookies or stored state required.
Read moreCard cracking is the automated guessing of missing card details like the CVV and expiry date by testing combinations against live payment forms until one succeeds.
Read moreCard-not-present fraud is payment fraud where the physical card is never shown, whether online, by phone, or in-app, so stolen card data alone is enough to pay.
Read moreCarding is the automated testing of stolen credit card data against payment forms to find cards that still work before selling or exploiting them.
Read moreChargeback fraud is the abuse of the card dispute process to reverse legitimate charges, leaving the merchant to lose the goods and the revenue and pay a fee on top.
Read moreClick fraud is the automated or incentivized clicking of paid ads to drain an advertiser's budget or inflate a publisher's revenue, with no buyer ever intending to engage.
Read moreContent theft is the automated bulk copying of a website's articles, listings, or media to republish, resell, or feed a competing product elsewhere.
Read moreCoupon fraud is the systematic abuse of discount codes, referral bonuses, and promotions, often through fake accounts that redeem one-time offers at scale.
Read moreCredential stuffing is an automated attack that tests stolen username-password pairs from data breaches against login forms to take over accounts.
Read moreData minimization is the GDPR principle that personal data must be limited to what a stated purpose actually requires: collect less, keep it shorter.
Read moreData residency is the question of where data is physically stored and processed, and which country's laws and authorities can reach it as a result.
Read moreDenial of inventory is a bot attack that locks products in carts or holds bookings without buying, making stock unavailable to real customers.
Read moreDevice fingerprinting identifies devices by combining technical attributes like browser, OS, and hardware characteristics into a distinctive signature.
Read moreEmail scraping is the automated harvesting of email addresses from websites and public sources to build spam, phishing, and resale lists.
Read moreFight bots and protect your users' data.
Don't give fraudsters and spammers a chance and protect your website with CaptchaFox today.