Showing posts with label spam. Show all posts
Showing posts with label spam. Show all posts

20070712

Google Evades Google

I received a spam on a gmail account today that didn't end up in the spam bucket automatically. Ordinarily, gmail does a really good job of filtering SPAM, but this account, then used Picasa's built-in invitation features to send an invite to me to lone used a different vector.

The spammer used an Italian free webmail account as the source address. (Maybe something like Nduja is making it in the wild already?) But rather than use the freemail account directly to send the spam, they created a Picasa ook at the Picasa gallery. The invitation mechanism allows you to put whatever text you want in the body of the invitation, which is where they put the invitation for me to send them my personal information.

There were no links in the body of the email itself, except back to Picasa. But what was really interesting about it is that it evaded the Spam filters by using a Google service. It even had the DKIM headers intact. So since Google verified the authenticity of the sender using DKIM, the email must be trusted, right?

Now, I don't know that Google is using DKIM or SPF to actually reject email yet - they might just be measuring at this point. But there's one way that they won't necessarily be 100% effective.

20070520

Evading Spam Filters with Spam?

In order to evade Bayesian filters, spammers add lorem to their mails so that they look legitimate. This is in addition to the odd punctuation or misspellings of words that will ordinarily show up in the Bayesian filter's vocabulary blacklists.

Do you think the spam will ever get to a point of maturity that we have to add spam vocabulary to our legitimate emails just to get them through the spam filters? Meaning, will the spammers ever stop making it so obvious the type of product they're advertising that those words get removed from the filters, meaning legitimate emails would need to have enough of those just to get by the filters?

Man I wish more people would adopt and pay attention to S/MIME or PGP signatures. Obviously, spammers can use those signatures as well, but at least then I can have my email client check who the signature is from for me. Rats! There are always trojans to send the emails out and fill in the passphrase boxes, too.