PDA

View Full Version : Spam


mjc
05-07-2003, 04:52 AM
OK, so what is spam and why is it so bad?

Spam is the common name for unsolicited commercial (bulk) email. It is the junk mail of the internet.

Other than the most obvious reason for being bad, that it is annoying, spam clogs email servers, wastes time (for end users and system administrators), in some cases is illegal, and very often consumes resources that the recipient of being used.

Spam can clog email servers either while being sent or, as in the case of the major "free" email providers, when being received. Imagine your "snail mail" mailbox being forced to handle 100 items at once, multiply that by the number of mailboxes your post office services, then you have an idea of what a small ISP goes through, daily. Another way it can clog servers is when the inevitable bounces occur. These bounces can either be legitimate from non-existent addresses or from users of various programs with this feature.

The problem is that purposefully bouncing does not work. Spammers forge the headers. The headers are like the return address, they detail the path a particular piece of email traveled to get to the end mailbox. Spammers forge headers so that the mail is difficult to trace to its real origination point, to cover their tracks.

Spam wastes time and resources of both end-users and admins, when they have to wade through the morass of junk to find wanted legitimate messages. Also, most often, it uses a significant portion of the users bandwidth in order to download it (or view it on the web)...definitely uses major chunks of bandwidth for ISPs and sys admins to deal with it for all the machines they service.

Spam is usually sent by Co-opting some email servers...many times these are known as open relays. Some ISP are complicit in the sending of spam (mostly Asian...Chinese to be more specific). Plus there is a new technique on the rise, where a spammer actually uses a trojan to infect unsuspecting recipients and then turn their machines into spam sending zombies.

Spam is very cheap compared to other forms of advertising. It takes a very small number of positive response to make a particular campaign a success. The number of major spam operations is fairly small (there are many small time operators who may last for a couple of runs, but the bulk of it is this core group of hard-core slime-balls). These people make quite a large amount of money peddling useless, disgusting and possibly illegal wares (some porn spam and most investment spam is blatantly illegal).

There are two things that the end-user should never do with spam...

1. Never, under any circumstances, buy a product or service that is advertised by means of spam. It doesn't matter if this particular product is something you really need. You are financing somewhere between 10,000 and 100,000 more useless messages.

2. Never use the un-subscribe link in a spam...if you did not sign up for an email item, do not un-subscribe from it by any link provided. Most often all that link does is confirm a valid address.

A couple other important things to consider...

1. Disable the ability of your email client to display html email. There are methods of confirming your address with it enabled.

2. Disable the ability for your email client to run scripts...there are more ways to confirm your address, and now there is even an exploit that allows the reading of forwarded emails by third parties (using a script to read anything appended to the message)

Budfred
05-07-2003, 04:04 PM
mjc,

For your last 2 points, if you are using MailWasher or a similar program to delete SPAM before it is downloaded from the ISP server, do these 2 items still apply. I am thinking that the SPAMmer can't do anything with it if you don't download it, is this true???

mjc
05-07-2003, 09:17 PM
If it is viewed in text mode or deleted from the server then, no there is nothing the spammer can do, but if you use webmail and view it ...

rahulkothari
05-08-2003, 04:31 AM
Can spam exploit my yahoo-hotmail-etc address book contacts ? i mean, is it possible for the spammer to send mailz using my name if i use ONLY WEBMAIL ?

TIA.

mjc
05-08-2003, 10:54 AM
Yes, because most often the spammer does not actually attack your addressbook, but just plops your name into the From: field from his list of email addresses.

These lists are hot commodities in the spammer community. They come from harvestbots that grab email addresses from places like these forums, Usenet, and just about every other webpage around, from trading of email addresses by sites with shady privacy policies or no concern whatsoever about privacy, from scam sites specifically set up to harvest addresses and many more ways.

So if you are receiving spam, chances are that sometime you can become the "sender" of a mass mailing.

rahulkothari
05-09-2003, 12:59 AM
Say, i receive a virus named "mjc" :p in outlook express, and this virus accesses my windows/outlook add book (.wab), meaning it can "see" all my contacts.

Now, if i receive the same virus in my webmail (yahoo), THEN, can it also "see" all my contacts stored online, i.e. on yahoo's server ?

is there any virus which can access WEBMAIL ADD BOOK also ?

mjc
05-09-2003, 01:57 AM
Most webmail does AV scans, and runs in a *nix environment so it is actually immune to Win32 viruses.

So there are some ways webmail is safer than POP mail.

rahulkothari
05-10-2003, 01:47 PM
ok. :)

stefanus
05-19-2003, 11:29 AM
Wish that I would have checked this thread earlier it would have solved my self induced problem! MJC How does one per your last two notes disable the ability etc??......

ONE DAY PERHAPS I CAN ANSWER QUESTIONS AND SPELL CORRECTLY

stefanus
05-28-2003, 01:21 PM
MJC, very interesting. Would it be incovenient for you to e-mail your original thread to me. Have tried to print it, unsucssesful.
Thank you in advance.

Stefanus

Budfred
05-28-2003, 03:36 PM
stefanus,

I am assuming you are talking about mjc's first post in this thread?? If so, just highlight it, copy it and paste it into Notepad. You can print it from there....

david eaton
05-28-2003, 05:50 PM
Well, I never!! Just received this E-mail: -

Subject: Spam detective
From: Lourdes Rodgers

Date: Wed, 28 May 2003 15:24:53



Download Your Anti-Spam Software Here!
Spam Remedy
3 Benefits To Blocking Spam for GOOD

1 - Spam Remedy checks your email boxes and filters unwanted, dangerous, or offensive email messages.
2 - Spam Remedy helps you save time & get ONLY the emails you want!
3 - Spam Remedy automatically cleans spam messages out before you even receive or read them. Get Yours Today!

The Hands-Down
Most Powerful, Effective & Intelligent
Anti-Spam Tool!

Download Your Anti-Spam Software Here!
(links removed)


Fancy that! A spam removal tool. Advertised by - yep - SPAM!

Am I alone in thinking this would be funny if it wasn't so pathetic?


David

Budfred
05-28-2003, 06:26 PM
Not only is it SPAM, it will probably also happily distribute your email address all over SPAMdom if you use it and it probably won't provide any protection. That said, I imagine they will distribute thousands of copies....

stefanus
05-29-2003, 09:21 AM
Budfred, Thank you. I tried and succeeded. (Siabonga)

Budfred
05-29-2003, 11:01 AM
"I tried and succeeded"

To do what???:confused:

stefanus
05-29-2003, 11:12 AM
BUDFRED, your suggestion to Highlight it, copy and paste onto Notepad! again Thanx.
Stefanus

pentachris
06-10-2003, 04:10 PM
Mageek presents Email Tracker (http://www.theinquirer.net/email_tracker.htm).