Security Wiki
Clear definitions of CAPTCHA, bot protection, online fraud, and web security terms from the CaptchaFox team.
EN 301 549 is the European accessibility standard for ICT products and services, the technical spec that laws like the EAA point to for what "accessible" means.
Read moreePrivacy is the EU rule set governing electronic communications and device access, the legal source of the cookie banner, separate from and stricter than GDPR.
Read moreFake account creation is the automated mass registration of accounts under false identities, feeding spam, promo abuse, fake reviews, and downstream fraud.
Read moreForm spam is the automated submission of junk content through website forms, polluting inboxes, CRMs, and comment sections while hiding real leads.
Read moreFullz is underground slang for a complete stolen identity package (name, ID number, financial details), priced and traded as a single fraud-ready bundle.
Read moreIdentity theft is the use of someone else's personal information to commit fraud in their name, the umbrella crime behind account takeover and synthetic identities.
Read moreIP geolocation maps an IP address to a physical region (country, city, sometimes postal area), powering localization, compliance and fraud checks.
Read moreIP reputation is an assessment of how trustworthy traffic from an IP address is, based on its history, network type, and links to proxies or botnets.
Read moreLegitimate interest is a GDPR lawful basis that allows processing personal data without consent, provided a documented balancing test favors the business.
Read moreMFA bypass covers the techniques attackers use to defeat multi-factor authentication: phishing proxies, push fatigue, OTP interception, and token theft.
Read morePayment fraud is any transaction that uses stolen, fabricated, or abused payment credentials, from stolen-card purchases to chargeback and refund abuse.
Read morePII is any information that can identify a specific person, directly or in combination, from names and emails to IP addresses and device identifiers.
Read morePrice scraping is the automated bulk extraction of prices from a competitor's site, fueling undercutting strategies and a constant crawler load.
Read morePrivacy by design is the principle that data protection must be built into systems from the first architecture decision, not added on afterwards.
Read moreProof of work is a cryptographic mechanism that requires solving a computational puzzle before an action is accepted, making abuse expensive at scale.
Read moreProxy rotation is the practice of switching outbound IP addresses continuously so that large volumes of automated requests appear to come from many sources.
Read moreRate limiting caps how many requests a client may send in a given time window, protecting services from overload and slowing down abuse.
Read moreReturn fraud is the abuse of retail return policies, from wardrobing to empty-box refunds, increasingly organized through refund services and networks.
Read moreRisk-based authentication adjusts login friction to the assessed risk of each attempt, invisible for routine sign-ins, stepped up when the evidence turns odd.
Read morerobots.txt is the file where a website declares which crawlers may access which paths, a voluntary protocol that polite bots honor and hostile bots ignore.
Read moreFight bots and protect your users' data.
Don't give fraudsters and spammers a chance and protect your website with CaptchaFox today.