This is topic What kind of spam is this??? in forum Film-Yak at Film-Tech Forum ARCHIVE.


To visit this topic, use this URL:
https://ft-forum.com/ft/cgi-bin/ubb/ultimatebb.cgi?ubb=get_topic;f=8;t=004937

Posted by Ken Lackner (Member # 1002) on 01-17-2007, 06:42 AM:
 
Over the last six months or so I have been getting an increasing rash of spam to all of my email addresses, incuding work. I'll get 3 or 4 EVERY DAY at work. (How they hell do they get that address???) This spam is not like your typical spam used to be. The messages do not make any sense, and they all follow the same format: A random name and strange address in the From line, a random subject line that often makes no sense, an image at the top of the body, and anywhere from a couple lines to a couple paragraphs of text that makes ABSOLUTELY NO SENSE WHATSOEVER. What the hell is this crap, and what does someone get out of sending it? Here is a partial screen capture of one of these messages. I'm sure I'm not the only one getting this junk. Anyone else care to share thoughts?

 -
 
Posted by Mark Lensenmayer (Member # 134) on 01-17-2007, 06:52 AM:
 
It's a stock pumping ad. They put in the random text to get passed SPAM filters, then put the information they want you to pay attention to in a graphic, which the filters don't see. Most are sent by "bot" computers controlled by spyware or viruses.

These promote a small stock, which the spammers have already bought. They send out these things, wait for a rush on the stock to move the price up, then sell at a profit. Most of the time, the companies aren't even aware of what is going on.

I also understand that this is a legal activity. There is nothing illegal about suggesting that the reader buy something.

They must get enough hits on these things to make it worthwhile...I also get quite a few every day, usually with odd titles from people I have never heard of.

I've gotten some recently with fake weather warnings: "TWELVE INCHES OF SNOW EXPECTED - WARNINGS POSTED"
 
Posted by Stephen Furley (Member # 1277) on 01-17-2007, 07:16 AM:
 
You're lucky if you're only getting three or four a day.

The latest thing I've been getting for the past month or so have a subject that's a random collection of biblical sounding words; like these examples from my 'Deleted items' folder:

And said, unto my sword, of Israel that forsake said: if the God

unto my name, of his own sake O Lord, in righteousness

From Hamath; is like a kid of Nathan the spirit drieth the gold

I really can't see the point in sending this stuff; it's obviously junk, so it gets deleted, without even looking at it. I'm sure most people would do the same. If they want people to open it why not use a subject line that at least makes some sense, rather than just random words? Something like 'I've found some lost property which I belive belongs to you.' might persuade more people to open it. Even then you still have the problem (from the point of view of the spammer) that they will still know that it's junk as soon as they open it and see the contents.
 
Posted by John Walsh (Member # 168) on 01-17-2007, 07:36 AM:
 
Yeah, it's a trick to get past spam filters. The message they want you to see is a jpg picture, which spam filters can't 'see.' The text is random, but does have sentences and puncation, so the filters see what they think is a real message (notice they would never put the word 'viagra' or 'penis' in the text part, since it would be rejected.)

Last year, there was a news story about how filter were winning the war against spam, but that completly turned around this year.
 
Posted by Ken Lackner (Member # 1002) on 01-17-2007, 08:07 AM:
 
Um...okay....how the crap am I supposed to know what to do with the information contained in the picture? (Not that I want to, I'm just thinking from the point of view of the spammer.)

quote: Mark Lensenmayer
These promote a small stock, which the spammers have already bought. They send out these things, wait for a rush on the stock to move the price up, then sell at a profit. Most of the time, the companies aren't even aware of what is going on.
Which companies?

quote: Stephen Furley
I really can't see the point in sending this stuff; it's obviously junk, so it gets deleted, without even looking at it. I'm sure most people would do the same. If they want people to open it why not use a subject line that at least makes some sense, rather than just random words? Something like 'I've found some lost property which I belive belongs to you.' might persuade more people to open it. Even then you still have the problem (from the point of view of the spammer) that they will still know that it's junk as soon as they open it and see the contents.
I completely agree. Of course smart Internet users, like most of us are, will delete it anyway. But to others, a subject line that at least makes sense would make the message more likely to be opened. I just don't understand why all this random nonsense!

Where are these people getting the email addresses from? I can udnerstand my Yahoo! address because I use that everywhere, but my work address???

Why the random text in the body? Why not just the picture if that's what they want you to see?

Yahoo!'s filter is pretty good at catching these, but the ones that slip by are caught by McCaffee when the messages are downloaded to Outook on my computer at home. Very few, if any, make it to my Outlook inbox.
 
Posted by Randy Stankey (Member # 64) on 01-17-2007, 09:31 AM:
 
Dump Outlook Express/Entorage and get Thunderbird instead.

Set T-Bird NOT to display remote images in incoming messages and to truncate all messages over 100 KB in length.

After about a week's worth of e-mail the built-in spam filter will be trained well enough to block 90% of this crap. The remaining 10% won't matter because they will either have images or will be larger than 100 KB.

You can set T-Bird's spam/message filters to whitelist any names in your address book if you want to.

Almost every single person I have gotten to switch to Thunderbird instead of Microsoft has seen their spam problem greatly diminish if not disappear all together.
 
Posted by Jeffry L. Johnson (Member # 453) on 01-17-2007, 09:31 AM:
 
Why Am I Getting All This Spam?
FTC Spam
Coalition Against Unsolicited Commercial Email
Anti-Phishing Working Group
TrustedSource
Abuse.net
 
Posted by Mark Lensenmayer (Member # 134) on 01-17-2007, 01:45 PM:
 
Many of the viruses the past few years have harvested Outlook address books. If your address is in that book, and that computer is infected, the spammers have your address.

I got spam on a Gmail account that had never been used! I think sometimes they just put together likely combinations of letters and send them out...doesn't cost them anything to have things bounce.
 
Posted by Carl Martin (Member # 1146) on 01-17-2007, 02:36 PM:
 
let's post our favorite subject lines from these emails. i've got

potty astronomer
peacock-feathered omnibus driver
with this, she can use your cock as huge toothbrush!
Bizarrely, the movie gives their dispute a gay subtext.
 
Posted by David Stambaugh (Member # 1102) on 01-17-2007, 02:54 PM:
 

 
Posted by Wayne Keyser (Member # 2420) on 01-17-2007, 04:28 PM:
 
Question 1 - Why you even open or read a message with a nonsense subject line? Lord only knows what opening some malicious emails will do (without even opening any attachments)

Question 2 - "how the crap am I supposed to know what to do with the information contained in the picture?" - Might be that the only thing they really want is to know who downloaded the image in the email - the sender can log who downloaded it (that's why IE7 has a setting to block images in emails unless you agree to download them) - then they would know yours was a valid email address and you'll be flooded with spam cause you'll be on the newest, freshest compendium of "send spam to these guys" addresses.

3 - Maybe I'm wrong about you. Maybe you're interested in v1a-gra or C1a-l1s, maybe you're receptive to emails with subjects like "Hey impress your girlfriend why so short?", or emails from "Jessica" subject "Want a date tonight?". I understand - personally, I only open ones titled "hottest young girls."
 
Posted by Ken Lackner (Member # 1002) on 01-17-2007, 06:16 PM:
 
I don't use Outlook Express. I use Outlook. I know people have complaints about it, but I love it. I don't like Thuderbird. (Although I use Firefox and love it.) I have McAfee (sorry, spelled it wrong in my last post) Internet Security Suite, and it filters all these messages to a spam folder.

I don't open messages about v1a-gra or C1a-l1s, or any messages of that nature. These are not those. Mabye I'm asking for trouble, but the sheer randomness of these messages makes me curious. Nowadays I don't open anything in my spam folder unless I recognize it and it's not supposed to be there, but before I had McAfee, I would get these in my Inbox and sometimes I would see them. I wanted to open one today to take a screen shot for this thread. I usually just delete them.
 
Posted by Joe Redifer (Member # 3) on 01-17-2007, 06:27 PM:
 
How the hell can a spammer tell if you looked at an image? Does the e-mail program send them confirmation that the image has been downloaded?

Also, when I got spam I opened all of it, downloaded every attached program and double clicked them many times. Lots of them were .pif files, whatever those are. Nothing ever happened. I never got a single virus. That could be because I have a Mac. And Macs are absolute shit on a stick! They can't even run .pif files! I need to get a better computer, one that will run .pif files. Yeah!

Also, Ken, you really need to take that plastic thing off of the xenon bulb. A bare bulb being held, or preferably waved around with one hand would be much better.
 
Posted by Ken Lackner (Member # 1002) on 01-17-2007, 07:33 PM:
 
LOL! Unfortunately it doesn't look like anyone who has recently uploaded a new pic of themsleves has had their member picture changed, so I haven't bothered to do that yet. Brad, what's up with that?
 
Posted by Chad Souder (Member # 343) on 01-18-2007, 11:29 AM:
 
Will Thunderbird work with hotmail or other html based email servers?
 
Posted by Jeffry L. Johnson (Member # 453) on 01-18-2007, 01:29 PM:
 
Jimmy Malone responds to a Nigerian scam
 
Posted by Scott Jentsch (Member # 1681) on 01-18-2007, 03:24 PM:
 
Thunderbird uses Bayesian filtering in addition to a white list to filter spam messages from its inbox. The whitelist allows all messages from anyone currently in your Address Book. The Bayesian filter trains itself to recognize the spam that you receive by also looking at the non-spam that you receive.

Bayesian filters are exactly what much of the spam these days is trying to circumvent by using embedded graphics, common words and phrases, and even text from weather sites.

By default, Outlook 2003 uses a profiling system that depends on regular updates from Microsoft to update the profiles used. If a message matches this profile, it gets acted upon.

Even though I use Outlook 2003, I don't use the built-in filter. Rather, I use a free add-on called SpamBayes, which is a Bayesian filter that scans incoming messages for spam as Outlook is retrieving them. It's quite effective.

It's very flexible in how it can be configured, as you can adjust its sensitivity and what it does when messages reach certain thresholds. For example, all messages that score 90 or more get tossed into a Junk E-Mail folder I never look at and auto-purge every two weeks (just in case someone says they sent me something and it got pitched by mistake). This folder currently has 4,504 messages in it, to give you an idea of how much spam I receive in two weeks.

I've never had a message land in the Junk E-Mail folder that didn't belong there. All messages which score more than 15 get moved into a "suspects" folder which I review and then tag as "Spam" or "Not Spam".

I used my existing spam-free E-Mail messages as training material for SpamBayes, so it has something to start with. If you have a folder of known spam, it will also use that to know what kind of spam you've been getting, too.

The nice thing about Bayesian filtering is that it applies to the messages that you receive. No corporate entity is being relied upon to come up with profiles, and with solutions that depend on a community of users submitting spam reports, you run the chance of people using the spam button for a delete button. I like being in control of things, even if it meant that it took a while to train, and I have to review some messages that are suspected spam.

SpamBayes will also show me what it's doing. I can see how many good messages it's using as a reference (775) and how many spam messages (21,454) as well. It will also display the clues for any message in my inbox, so that I can see why a particular message might have been tagged as spam (or not).

Long story short. You don't have to use Thunderbird to get Bayesian filtering. While it may be a great program, it's not for everyone. I haven't used Microsoft's built-in filter for 18 months, so I don't know how effective it now is.

All I know is that I'm very happy with the spam filtering I've got going on, even if I'm not happy with the fact that spam exists in the first place.
 
Posted by Tristan Lane (Member # 1169) on 01-18-2007, 10:06 PM:
 
Gmail does a wonderful job of stuffing this type of crap into my spam folder.

For a HTTP/POP based e-mail, it doesn't get any better for free.
 
Posted by Dave Macaulay (Member # 813) on 01-25-2007, 12:52 PM:
 
No, tbird is an email client. Hotmail (and hopefully others too!) does a lot of filtering for you, and virus check attachments as well.
The biggest problem with outlook & outlook express is the preview pane in email folder listing. This opens the email when you highlight it, any "virus" is immediately activated (actually this is a fairly unusual event) but the biggest problem is that HTML email will open the images or whatever from the remote site and in doing so tell the spammers that your email address is valid. To generate address lists they do just make up random names and send the mail off - the shotgun approach. Problem is that once your address is vailidated as active (by you opening the HTML stuff) suddenly it's valuable. Spammers sell and buy lists of valid emails... so suddenly you get 1000% more spam.
 
Posted by Ken Lackner (Member # 1002) on 01-25-2007, 03:47 PM:
 
quote: Joe Redifer
How the hell can a spammer tell if you looked at an image? Does the e-mail program send them confirmation that the image has been downloaded?
My thoughts exactly! I never thought they could tell when a message was read or downloaded. How are they able to tell this?

For anyone out there who uses Outlook or Outlook Express and doesn't already know, the Preview Pane can be turned off so that you have to double click a message to open it.
 
Posted by Phil Hill (Member # 371) on 01-25-2007, 04:04 PM:
 
Yup, they can tell. Those pics contain a "Tattletale" pixel or 2 that is transparent or so small it's not noticed. But it contains code that notifies the spammer that you opened the spam and therefore a legit email address. Oh, and are a sucker for a shitload of more spam. Then YOU are worth $$$ to sell to other spammers.
 
Posted by Joe Redifer (Member # 3) on 01-25-2007, 05:26 PM:
 
The thing is that when I open a spam e-mail, I've never seen my network indicate any activity as I was doing it. I would like to know how to make one of these tattle-tale pixels. Then we should make every pixel here on Film-Tech one of those pixels so we can see exactly who is accessing what page at what time, and then stalk them.
 
Posted by Ken Lackner (Member # 1002) on 01-26-2007, 06:28 AM:
 
I would have thought the act of downloading the message would do more harm than just reading it. What if you are not connected to the Internet when you open the message?
 
Posted by Wayne Keyser (Member # 2420) on 01-26-2007, 07:01 AM:
 
Scott:

About "whitelisting" - so how do you ever get email from someone not on your already-permitted list?

This must leave you open to a certain amount of "sorry, Dr. Jones, I forgot to whitelist you so I didn't see your email telling me I had seven days to live that you sent - uh, let me see - 6 days ago."

Okay, I'm using humor, but don't you miss some communications you wish you hadn't?
 
Posted by Frank Angel (Member # 248) on 01-26-2007, 10:15 AM:
 
I am looking into using a proxy. There are free ones out there that claim to be a buffer between you and the spammer. Spammers never see your real addy.

On the other hand, what I REALLY want to do is to find a way to send a virus BACK to the sender. And I don't mean some wippy virus or worm that just locks up his spamming suckass computer - I am talking about a REAL Robocop virus...one that BLOWS his damn computer the F up. AND shorts his entire power grid. I want it to zap ten thousand volts of static electricity at his gonads as he sits at his keyboard sending out spam to me about my peanut size penis that needs viagra that he can send to me for only $1.80 a pill. I want his prick burst into flames and his sperm boil in is scrotum.

Now THAT's the kind of virus I want to send out.
 
Posted by Dave Macaulay (Member # 813) on 01-26-2007, 01:34 PM:
 
"I would have thought the act of downloading the message would do more harm than just reading it. What if you are not connected to the Internet when you open the message?"

Downloading doesn't cause any problem. The way the internet works, unless your computer or your ISP sends a return email type message to the sender there is no way for the sender to know what happened to the message.
If you send an email to a nonexistent address you'll usually get a return mail telling you you've screwed up; that doesn't work too well for spammers because most spam uses false "from" and "return to" addresses so even if you send a "no such address" message the sender (real sender) won't get it.
Even if you download an email with a dangerous virus attached, you won't be infected until you open the message or attachment. This is why Outlook's preview pane is dangerous: if you start at the top of your mail list and delete the top item, the next one is highlighted and opens in the preview pane. The top item in the list will always open by default. The preview panes can be disabled.
Next problem is HTML/RTF email formats. Outlook can not be convinced to ignore this encoding, it will always open and display an HTML/RTF email as a formatted image. That's a choice MS made long ago and is obviously unwilling to change.
Most add-on email clients allow you to open messages as text only, this eliminates the "pixel bug" or image download that says "yay this is a valid email I can sell now!" sent to your spammer.
Pixel bugs are just oddly named very small image tags embedded in an HTML page. The name of the image identifies YOU. Your computer sends a GET message to the spammer's server asking for the image file, his server notes the image name (and tags your email address as good) and sends you a default image. This will also work with any image in an HTML page/message but that's a bit harder to keep track of at the server end so people get the correct images.
Disconnecting from the internet does make HTML pixel bugs fail. It's just a pain to bother with and sometimes impractical. Better to just never open suspect/unknown messages. Seriously, the viagra is fake, the hot babes don't exist, messages with bayesian evading nonsense subjects are pretty easy to avoid, and the stock being pumped will go down like the Titanic.
 
Posted by Patrick de Groot (Member # 858) on 01-26-2007, 04:44 PM:
 
Spammers or marketing companies can track openened mail by including a small (or big) picture of for example 1*1 pixels that is put on a webserver somewhere. By openening the e-mail you are in fact downloading the picture from a website. The webserver can track your ip and date/time. So they can see if the e-mail is openend.
Most modern e-mail client do block linked images these days (including Firebird, Outlook Express and Outlook 2003).
However, this won't help with the inline type of images that image spam uses. This is an embedded image (encoded into the message itself). They can't track you, but the message will show up. It is however very funny to see the stupid images they are sending to circurvent OCR (optical character recognition) spam filtering... If only there weren't so many of them. I can't see anyone taking these messages serious.
 
Posted by Scott Jentsch (Member # 1681) on 01-30-2007, 05:14 PM:
 
quote: Dave Macaulay
The biggest problem with outlook & outlook express is the preview pane in email folder listing. This opens the email when you highlight it, any "virus" is immediately activated (actually this is a fairly unusual event) but the biggest problem is that HTML email will open the images or whatever from the remote site and in doing so tell the spammers that your email address is valid.
Outlook 2003 does not view remote images by default, you have to enable that feature globally or on a "by sender" basis. (You can mark certain senders as "safe.")

Outlook 2003 also blocks links in HTML E-Mails by default, and you can set all messages to be viewed in a restricted zone so that Javascript and other garbage is not automatically run. I believe this behavior is by default and would have to be overridden on purpose. I cannot speak for previous versions of Outlook or for Outlook Express, as I've never used them.

quote: Wayne Keyser
About "whitelisting" - so how do you ever get email from someone not on your already-permitted list?

This must leave you open to a certain amount of "sorry, Dr. Jones, I forgot to whitelist you so I didn't see your email telling me I had seven days to live that you sent - uh, let me see - 6 days ago."

Okay, I'm using humor, but don't you miss some communications you wish you hadn't?

My spam solution doesn't use whitelists. My mention of them was in the context of how Thunderbird uses whitelists to identify good messages. The whitelists aren't used to block messages from people that aren't on the list (as far as I can tell from their web site), but rather to allow all messages that do come from someone on the whitelist.

Blocking exclusively by using a whitelist is too restrictive, and I would never use that method except in very specific situations. I get messages from people's whitelist blockers that want me to go to some web site and answer a question in order to get unblocked. I don't have the time to chase white rabbits, so I just leave the challenge unanswered.

To answer your question, I've never known of an E-Mail that was mistakenly sent to my Spam folder that should not have been. That's from over three and a half years of receiving E-Mail, which amounts to hundreds of thousands of messages.

Some good messages do land in my "Spam Suspects" folder, but that's what that folder is there for. It gives the Bayesian filter a chance to learn by telling it whether a questionable E-Mail is spam or not. It's quite effective, and one of the first questions I posed to the Microsoft presenter at today's launch of Office 2007. Unfortunately, they didn't know whether the built-in spam filter was now using Bayesian filtering in addition to profile-based filtering.
 




Powered by Infopop Corporation
UBB.classicTM 6.3.1.2