Re: (no subject)
Laird Breyer <[email protected]> Mon, 15 Mar 2004 11:11:54 +1000
| Newsgroups | gmane.ietf.asrg.filtering |
|---|---|
| Message-ID | <20040315011153.GF3800@ender> |
On Mar 14 2004, Carl Hutzler wrote: > > href=http://www.pornosite.com/ > http://www.pornosite.com/ > ht<htmlcomment>tp://w<comment>ww.po<comment>rnosi<anotherone>te.com > http://rd.yahoo.com/?http://w<comment>ww.po<comment>rnosi<anotherone>te.com > ...and consider using plain text URL with html tables, etc. > > This is the difficult area. Whether it is phone numbers, emails, URLs, > or the attributes of a bayesian filter, the comparison algorithms and > the parser that preprocesses the mail is the gold mine. > I'll second that. Moreover, there are several ways of writing URLs besides the obfuscation methods you noted. One can replace www.pornosite.com with the IP address 123.456.789.123, or replace the dotted quad with one of an infinite supply of equivalent numbers which don't contain dots. One can add any garbage in front of an '@' sign. One of your examples also shows how to set up a redirection script in the yahoo.com domain, so comparing domains is insufficient, one has to parse the directory paths. Overall, the devil is in the details. Now besides just agreeing with your post, I think there's another obvious line of attack for spammers. Why set up their own X domains? All they really need is a web server which displays the product's, shall we say, "attributes" ;-) When they have a network of thousands of spam sending zombie machines, then they can also have thousands of zombie web servers who can serve the ads. So they don't even need their own X domains at all. -- Laird Breyer.