internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Norton AntiVirus 2008

Most Popular Software Downloads
Ad-Aware 2008 Free
Windows XP Service Pack 3
Internet Explorer 7
QuickTime for Windows
Adobe Flash Player
AVG Anti-Virus Free
Paint Shop Pro
Windows Live Suite
CCleaner (Crap Cleaner)
Winamp

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Spammers Find New Ways Around Filters
Image Hosting Now Used to Get Around Spam Image Filters
Andy Patrizio

The seemingly endless creativity and intense effort of spammers is as admirable as it is a waste of talent. As soon as spam filter vendors get the hang of blocking image-based spam, the spammers find a new method to completely invalidate it.

Image-based spam exploded last year as a means of getting around the word filters used on client and server e-mail filtering software. Very quickly, image-based spam rose to account for 30 percent of all spam.

Rather than find weird ways to write "Viagra" or "mortgage" or stock symbols for pump and dump schemes, the text would be written in a JPG and the filters couldn't catch it.

So spam filter vendors went to work analyzing embedded images in e-mail files. Just as the products are making it to market, Secure Computing's labs have found that spammers are using image hosting sites and some HTML code to make the image appear in the e-mail.

Secure Computing's Chief Research Scientist, Dmitri Alperovich, said that because the image is hosted rather than embedded, image filters don't examine the file. And since HTML tags are used, the image appears within the e-mail just like am embedded image.

"As a result, they get a couple of benefits from this new technique," he told internetnews.com. "One is they no longer have to generate the image itself in their spam sending software, so they can increase the volume of spam they can send.

"Also, because of filtering technologies, spammers have had to introduce many randomizations and obfuscations into image spam, which reduces the readability. Now they don't need to do that, and they are even including logos of popular brokerage houses inside their image, directing people to these houses to place orders for the stock being promoted," he added.

There is some bit of good news in all of this. While it has been possible to embed actual malicious code into a JPG image, sites like ImageShack parse the image and will find hidden code and reject it. So at least this can't be used as a means to sneak malware (define) onto a computer.

As of now, Secure Computing has only seen one hosting site being used in this manner, called ImageShack. Unlike Yahoo's Flickr, you don't even need an account to upload pictures to ImageShack and then share links to it. But, Alperovich added, it would be a mistake to globally block all e-mails with links to ImageShack.

"These sites are used for legitimate images. People send out links to colleagues. So if you blindly block ImageShack, you may cause a lot of false positives that many individuals may not tolerate," he said.

For the end user, the solution is to set their e-mail client so it does not automatically display images embedded in an e-mail. Microsoft has this defaulted on in Outlook and Outlook Express.

Spammers remain determined to get around whatever roadblocks are throw in front of them because it's still profitable for them to do so, said Alperovich. "They don't need a lot of people to reply to be successful. They can make tens of thousands on pump and dump schemes with just a few hundred people. Getting a few people to fall for it is not very hard," he said.

News courtesy of internetnews.com

April 30, 2007


View All Anti-Spam Software

View All Anti-Malware Software

Contents:
1. Image Hosting Now Used to Get Around Spam Image Filters






JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Microsoft Article: 7.0, Microsoft's Lucky Version?
Microsoft Article: Hyper-V--The Killer Feature in Windows Server 2008
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Windows Server 2008
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES