ietf-asrg
[Top] [All Lists]

Re: [Asrg] How to defeat spam that uses encryption?

2003-03-31 20:40:58
At 10:49 AM 3/31/2003 -0500, you wrote:
If I were a spammer (I am not) I'd start encrypting messages to throw off
content filtering. Public keys are easily obtainable and are readily
associated with good email addresses.

Well, I recently started getting a pot-load of spam that does this. (I think it is coming in from a newsgroup I moderate. I just delete it and so I am not sure about this.)

Anyway, what they do is misspell words.  They use < and > to make "se><"
for example, 1's for l's 0's (zeros) for o's, etc. It is of course harder to read but the message is still quite understandable. What is more, it makes it virtually impossible for a filtering mechanism to catch it unless the various tricks such as this were programmed into it directly.

Of course, the other thing that has been happening more lately is simply a chunk of innocuous text in a HTML mail that won't trip up a filter but the HTML mail also has an image embedded in it that has the contents of the actual spam.

I suspect that Baysian and other similar techniques will have only a limited life span as techniques such as this become more prevalent.

-Art
--
Art Pollard
http://www.lextek.com/
Suppliers of High Performance Text Retrieval Engines.

_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg



<Prev in Thread] Current Thread [Next in Thread>