Re: (no subject)

Laird Breyer <[email protected]> Mon, 15 Mar 2004 11:11:54 +1000
Newsgroups gmane.ietf.asrg.filtering
Message-ID <20040315011153.GF3800@ender>
On Mar 14 2004, Carl Hutzler wrote:

> 
> href=http://www.pornosite.com/
> http://www.pornosite.com/
> ht<htmlcomment>tp://w<comment>ww.po<comment>rnosi<anotherone>te.com
> http://rd.yahoo.com/?http://w<comment>ww.po<comment>rnosi<anotherone>te.com
> ...and consider using plain text URL with html tables, etc.
> 
> This is the difficult area. Whether it is phone numbers, emails, URLs, 
> or the attributes of a bayesian filter, the comparison algorithms and 
> the parser that preprocesses the mail is the gold mine.
> 

I'll second that. Moreover, there are several ways of writing URLs
besides the obfuscation methods you noted. One can replace
www.pornosite.com with the IP address 123.456.789.123, or replace the 
dotted quad with one of an infinite supply of equivalent numbers which
don't contain dots. One can add any garbage in front of an '@' sign.

One of your examples also shows how to set up a redirection script in
the yahoo.com domain, so comparing domains is insufficient, one has
to parse the directory paths.

Overall, the devil is in the details.

Now besides just agreeing with your post, I think there's another
obvious line of attack for spammers. Why set up their own X domains?
All they really need is a web server which displays the product's,
shall we say, "attributes" ;-) When they have a network of thousands
of spam sending zombie machines, then they can also have thousands of 
zombie web servers who can serve the ads. So they don't even need
their own X domains at all. 


-- 
Laird Breyer.