Security Wiki
Clear definitions of CAPTCHA, bot protection, online fraud, and web security terms from the CaptchaFox team.
Browser fingerprinting derives an identifier from a browser's observable traits — versions, fonts, rendering quirks — without storing anything on the device.
Read moreCanvas fingerprinting derives a device identifier from tiny differences in how a browser renders graphics — no cookies or stored state required.
Read moreCard cracking is the automated guessing of missing card details — CVV, expiry date — by testing combinations against live payment forms until one succeeds.
Read moreCard-not-present fraud is payment fraud where the physical card is never shown — online, by phone, or in-app — making stolen card data alone enough to pay.
Read moreCarding is the automated testing of stolen credit card data against payment forms to find cards that still work before selling or exploiting them.
Read moreChargeback fraud is the abuse of the card dispute process to reverse legitimate charges — the merchant loses the goods, the revenue, and pays a fee on top.
Read moreClick fraud is the automated or incentivized clicking of paid ads to drain an advertiser's budget or inflate a publisher's revenue — no buyer ever intended.
Read moreCoupon fraud is the systematic abuse of discount codes, referral bonuses, and promotions — often through fake accounts that redeem one-time offers at scale.
Read moreCredential stuffing is an automated attack that tests stolen username-password pairs from data breaches against login forms to take over accounts.
Read moreData minimization is the GDPR principle that personal data must be limited to what a stated purpose actually requires — collect less, keep it shorter.
Read moreData residency is the question of where data is physically stored and processed — and which country's laws and authorities can reach it as a result.
Read moreDenial of inventory is a bot attack that locks products in carts or holds bookings without buying, making stock unavailable to real customers.
Read moreDevice fingerprinting identifies devices by combining technical attributes like browser, OS, and hardware characteristics into a distinctive signature.
Read moreEmail scraping is the automated harvesting of email addresses from websites and public sources to build spam, phishing, and resale lists.
Read moreFake account creation is the automated mass registration of accounts under false identities, feeding spam, promo abuse, fake reviews, and downstream fraud.
Read moreForm spam is the automated submission of junk content through website forms — polluting inboxes, CRMs, and comment sections while hiding real leads.
Read moreIP geolocation maps an IP address to a physical region — country, city, sometimes postal area — powering localization, compliance and fraud checks.
Read moreIP reputation is an assessment of how trustworthy traffic from an IP address is, based on its history, network type, and links to proxies or botnets.
Read moreMFA bypass covers the techniques attackers use to defeat multi-factor authentication — phishing proxies, push fatigue, OTP interception, and token theft.
Read morePayment fraud is any transaction that uses stolen, fabricated, or abused payment credentials — from stolen-card purchases to chargeback and refund abuse.
Read moreFight bots and protect your users' data.
Don't give fraudsters and spammers a chance and protect your website with CaptchaFox today.