Search 
You are here: ArticlesIn Focus   
ArticlesMinimize
IN FOCUS: Spammers Adopt New Tactics
Posted by SteveT on Saturday, November 17, 2007 :: Last Updated on Sunday, January 20, 2008:: Views 2318

   

by Mark Joseph Edwards, News Editor, mark at ntsecurity / net

Got spam? Of course you do. For the life of me, I cannot understand the minds of spammers. They're simply not mentally healthy individuals, as evidenced by their escalating intrusions into our inboxes and Web browsers.

So how bad is the problem now? According to statistics published by Distributed Checksum Clearinghouse (at the URL below), the volume of spam has nearly doubled since November 2006 and has at least tripled since November 2005. I'm sure other entities that track such statistics have data that indicates the same trend.

http://list.windowsitpro.com/t?ctl=6DE77:E0792EBBCDE7A61AA63286175C8EF58F

Recently, spammers have taken on new tactics to bypass various spam filters used by Web sites and for email processing. A recent item on Symantec's Security Response blog says that spammers are using Google to redirect people to spammer Web sites. When I first heard the report, it seemed surprising that Google could be taken advantage of by spammers. But there's a simple explanation of how it can happen.

Due to certain parameters that can be passed as part of a URL, spammers can mask the URL of a spam or malware Web site in an email message (rendering URL blacklists useless!). The technique involves first crafting a Google query that returns only the single page that spammers hope someone will visit. The spammer then adds a variable to the end of the Google query URL that causes Google to instantly redirect the browser to the spammmer's Web page.

Fortunately, you can create a custom filter to catch the trick, assuming of course that your spam filter system allows you to write custom rules. Simply look for "google.com" and "&btnl=" in any URL string. You can read more about the trick and the block at the URL below.

http://list.windowsitpro.com/t?ctl=6DE6A:E0792EBBCDE7A61AA63286175C8EF58F

A recent item on McAfee's Avert Labs blog (at the URL below) tells how Web spammers are using a distributed method of solving CAPTCHAs--those images with numbers and letters that you have to read and then type into a form field before submitting the form.

http://list.windowsitpro.com/t?ctl=6DE6C:E0792EBBCDE7A61AA63286175C8EF58F

In a nutshell, spammers are now capturing legitimate Web sites' CAPTCHA images in real time and inserting them into their own Web pages that
offer some type of enticing free content. Visitors that want to gain access to that free content must enter the CAPTCHA solution. What they don't know is that the CAPTCHA came from another site. When the visitor enters the solution, the spammer sends the solution to the originating site thereby getting past the CAPTCHA spam filter.

Fortunately there's a way to defeat this type of spamming too: Don't use images for CAPTCHAs. Instead, use a lengthy set of text-based questions and answers, and randomize the HTML that wraps the questions so that they can't be easily parsed by spammers' code.

On a semi-related note, if you're using DNS blacklists, you might be interested in an entry I read at Al Iverson's DNSBL Resource blog. Iverson set up a spam trap to determine which DNS blacklists are most accurate. Based on his tests so far, Spamcop and Spamhaus operate the best blacklists. Neither site mistakenly tagged any legitimate email as spam. On the other hand, Iverson found that SORBS tagged about 10 percent of his legitimate email as spam. I'll add to Iverson's findings that, based on my experience, SORBS blacklists entire class C networks due to the violations of a few servers within those networks. You can read Iverson's article at the URL below, wherein you'll find a link to his statistics, which will give you a good idea of which blacklists to consider using.

http://list.windowsitpro.com/t?ctl=6DE6E:E0792EBBCDE7A61AA63286175C8EF58F

Previous Page | Next Page

COMMENTS


DonationsMinimize

Find our site useful? Make a donation to show your support

Donate

logo_ccMC.giflogo_ccVisa.giflogo_ccDiscover.giflogo_ccAmex.gif

ArGoStuff Supporters

 


News from ArGoSoftMinimize
1 2 3 4 5 6


Mail Server v1.0.8.3
  • Added support of STARTTLS (STLS) command for SMTP, POP3, IMAP, and SMTP relay and delivery, which will allow secure, fully encrypted connections, when possible;
11/6/2011 1:10:34 PM
Mail Server v1.0.8.2
  • Optimized delivery speed. In earlier versions each "tick" which was checking whether messages were in the outbox queue, was picking up only one message at a time. Now it will attempt to pick MaximumAllowedThreads-ActiveDelivery threads messages, which should considerably increase deliver speed;
  • Optimized SEARCH and STATUS IMAP commands. They appear to be used very extensively by Android, and (not that extensively, but still) by iPhone. Now users who use mobile phones to access their IMAP accounts will see considerable improvement;
  • Optimized STORE IMAP command. Before storing of IMAP flags was occuring one message at a time, which seemed to be fine with SQL server, but proved to be slow for SQLite... Now it happens with single SQL call.
10/8/2011 7:59:35 PM
ArGoSoft Mail Server v1.0.8.1
  • Fixed a bug: when using IMAP via Firefox with "When I delete a message, move it to Trash folder" option, marking messages in the trash folder was causing high CPU usage, and was taking some time, making the server pretty much non-responsive. The problem was happening only when using SQLite.
6/6/2011 9:33:36 PM
ArGoSoft Mail Server v1.0.8.0
  • Fixed a problem with web interface - was showing only first page of messages, and would not switch to other pages; In order to fix the web interface, mail server itself has to be updated;
  • When installint initially, was still using SQLite, even when SQL was requested;
  • There was a problem with switching from SQLite database engine to SQL server database engine: the SQL database was not being created;
5/23/2011 5:53:55 PM
ArGoSoft Mail Server .NET v1.0.7.9
  • The server no longer requires Microsoft SQL Server. If SQL server is not found, it will use SQLite engine, which does not require separate installation. If SQL server is found, then user will be prompted whether he wants to use it;
  • Made other improvements, such as, now mailbox rebuild indexes orphaned records, rather then deleting them, also added an opotion to increment UIDL validity of folder (both on the Mailbox viewer box);
  • Made minor improvements on web interface;
4/26/2011 9:47:25 PM


1 2 3 4 5 6

Protect Your Computer today withGet AVG Today


Home:ArGoStuff:Forums:Articles:Cyber Security Tips:FAQ:Downloads:Links
Copyright 2006-2011 by ArGoStuff Terms Of UsePrivacy Statement