post Category: Code, Internet, MailServer — Chris @ 6:26 pm — post

Currently, there are four major spam attacks postmasters are being faced with. They include, but are not limited to:

  • PDF & FDF: usually a blank e-mail with a PDF attachment.
  • Greeting Card: invitations from an ‘old friend’ to go to a website with a numerical http address, usually containing malware.
  • Image Spam: A gif or png attached to a, usually - though not always, blank e-mail ready to sell the latest software or stock.
  • Obfuscate Words: Lines of text take this format, N o*t o,n-l-y d o-e’s t,h+i s f i+r*m h+a’v_e grea_t fundamenta,ls*,.

I’m going to show you how using the free-software package, SpamAssassin, you can successfully neuter these 4 major spam attacks.

  • Greeting Card: Can be easily defeated using postcards.cf.
  • Image Spam: These quickly become extremely popular, but have now decreased in prevalence after very successful methods were implemented to combat them. For SA, use the module Imageinfo: Imageinfo.pm and Imageinfo.cf supplied by SARE Rules Emporium.
  • PDF & FDF: Can be successfully discarded by using PDFInfo.pm and PDFInfo.cf again supplied by SARE Rules Emporium.
  • Obfuscate Words: These have recently hit, and hit hard. Spammers, seemingly bewildered by their inability to get through current filters using the above popular methods, have now resorted to the old way of securing spam delivery: obfuscation. The good news is that this, again, is easily defeatable. The ruleset(s) originally written by Jennifer Wheeler are mirrored locally by this site.
    1. chickenpox.cf: [words obfuscated by non word characters] Th1s|s a v3ry h4ndy se7 t0 c@tch th!s 50rt 0f (rap.
    2. backhair.cf: [words obfuscated by nonsense html tags] 
      Y<oivugriub>oucou<iuqgheriugv9h>ld rea<y>llyu<owiuer88>se this.

Game on, spammers!

Sorry, no comments yet.

Write Your Comment

Comment Guidelines: Basic XHTML is allowed (a href, strong, em, code). All line breaks and paragraphs will be generated automatically.

You should have a name, right? 
Your email address, I promised I won't tell it to anyone. 
If you have a web site or blog, you can type the URL right here. 
This is where you type your comments. 
Remember my information for the next time I visit.
 

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 4 chars within 0..9 and A..F, and submit the form.

  

Oh no, I cannot read this. Please, generate a