What is word verification:
Word verification is term called for verification of a word displayed in a image (most commonly). Users are asked to type the string displayed in image and server checks whether input is correct.
Why word verification:
Used to disallow hacker (Only till we come up with algorithm to identify word in the image) to write automation code to create a bulk of accounts, task which can cause server to be overloaded or out of account. A common practice used across many site.
Screen shot asking for word verification:
data:image/s3,"s3://crabby-images/9f54b/9f54b7c62387ab572e2bf6b6d1f9c2a9fcb183e3" alt=""
What's wrong with this one:
This site ask for word verification, and to reduce the server traffic (I guess), it also send the correct string in the same packet. When I saw that yesterday, you can view the correct string in the page source code.
Code is displayed in page source:
data:image/s3,"s3://crabby-images/1ca70/1ca70e07e8a070b7e6b6877d83bdd3d2c3e289ac" alt=""
data:image/s3,"s3://crabby-images/1af23/1af234857f8e547515a5fd7a13d97c2eaeae92cc" alt=""
Old saying: "Security of whole setup is equal to weakest link in it!"