ietf-asrg
[Top] [All Lists]

Re: [Asrg] A CAPTCHA that automatically detects and neutralizes attacks.

2005-06-01 01:12:48

On Tue, 31 May 2005, Seth Breidbart wrote:

If your computer is infected, wouldn't it be easier to have the
malware drop the spam (not SPAM, that's Hormel's product) directly
into your inbox without worrying about any filters (such as your
ISP's)?  For that matter, why bother with mail at all; why not just
show it to you via popups?

Oh, some malware does that already.

Admittedly, your address book is a list of victims who likely have
_you_ whitelisted; but again, having the malware send directly from
your computer works even better, because then the spam's headers all
match the real mail you send.

If all malware messages were sent only from people on which computer
the malware is installed to the people on their whitelist, this would
greatly improve the odds that such malware would be noticed and removed reasonably fast since people who enjoy letting rats run wild in their
house for long rarely have friends they can communicate with and invite
to their home [i.e. their friends would remove the address from their whitelist as they would no longer wish to communicate with such person] and would also face problems with pest-control agency [i.e. some global blocklist] and would get ticketed [warning from ISP] and ultimately house is condemned [i.e. account disconnected by ISP].

--
William Leibzon
Elan Networks
william(_at_)elan(_dot_)net

_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg



<Prev in Thread] Current Thread [Next in Thread>