lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <002201c3533a$c2efa640$0300a8c0@bzdrnja>
From: Bojan.Zdrnja at LSS.hr (Bojan Zdrnja)
Subject: Advances in Spamming Techniques


> -----Original Message-----
> From: full-disclosure-admin@...ts.netsys.com 
> [mailto:full-disclosure-admin@...ts.netsys.com] On Behalf Of 
> David Maxwell
> Sent: Saturday, 26 July 2003 4:30 p.m.
> To: Paul Schmehl
> Cc: security snot; full-disclosure@...ts.netsys.com
> Subject: Re: [Full-Disclosure] Advances in Spamming Techniques
> 
> 
> However, a related technique which I've seen lately is that of appending
> a couple of paragraphs of non-spam text, in an attempt to out-weigh the
> spamminess of the other content.

Yep, this is a known technique they try to use to defeat anti-spam measures.

In most cases they make HTML e-mails (is one solution to completely ban HTML
e-mails?) with for example white background then put their spam text at the
beginning and then anti-spam paragraphs at the bottom of the e-mail, but in
white color.

On the screen you won't see those paragraphs at all as they are white on
white, but that doesn't make any difference to anti-spam tool.

Also, a lot of spam e-mails I've been getting lately just have an img src
pointer in HTML which actually shows complete spam as one picture. This can
be defeated by denying outbound HTTP connections to MUA.

Regards,

Bojan Zdrnja


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ