Re: (no subject)

Carl Hutzler <[email protected]> Sun, 14 Mar 2004 21:09:08 -0500
Newsgroups gmane.ietf.asrg.filtering
Message-ID <[email protected]>
Ahhh, your last point is very true. But for some reason they don't yet 
seem to use "reverse" proxy-bots that way, that much. I mean I have seen 
the proxies used in the reverse manner, but for some reason it is 
currently unattractive.

I think the reason is that it costs $5-10 or so to register and host a 
domain.  So if the spammer advertises http://www.pornopills.com/ and I 
block that efficiently, the spammer has to get another. And if I block 
that, another.

Now to make this an issue for the spammer, you have to be quick. But not 
that quick...just quick enough to prevent your members from being able 
to get there :-) And you also have to keep pace to keep it expensive. 
Expensive can mean eliminating a lot of click throughs combined with 
taking new domains off the air at a rate of about 100 a day ($1000 a day 
in domain registrations).

So you really need a fairly quick method to automatically determine a 
spammer URL from a legit one (that may both be being sent in high volume).

This simply is a way to detect behavior (high volume similar 
emails)...tying a spammers url to his identity...making his url his 
identity. But you have to have one or two checks against legit high 
volume URLs like the video for Janet Jackson's costume "malfunction".

-Carl


[email protected] wrote:

>On Mar 14 2004, Carl Hutzler wrote:
>
>  
>
>>href=http://www.pornosite.com/
>>http://www.pornosite.com/
>>ht<htmlcomment>tp://w<comment>ww.po<comment>rnosi<anotherone>te.com
>>http://rd.yahoo.com/?http://w<comment>ww.po<comment>rnosi<anotherone>te.com
>>...and consider using plain text URL with html tables, etc.
>>
>>This is the difficult area. Whether it is phone numbers, emails, URLs, 
>>or the attributes of a bayesian filter, the comparison algorithms and 
>>the parser that preprocesses the mail is the gold mine.
>>
>>    
>>
>
>I'll second that. Moreover, there are several ways of writing URLs
>besides the obfuscation methods you noted. One can replace
>www.pornosite.com with the IP address 123.456.789.123, or replace the 
>dotted quad with one of an infinite supply of equivalent numbers which
>don't contain dots. One can add any garbage in front of an '@' sign.
>
>One of your examples also shows how to set up a redirection script in
>the yahoo.com domain, so comparing domains is insufficient, one has
>to parse the directory paths.
>
>Overall, the devil is in the details.
>
>Now besides just agreeing with your post, I think there's another
>obvious line of attack for spammers. Why set up their own X domains?
>All they really need is a web server which displays the product's,
>shall we say, "attributes" ;-) When they have a network of thousands
>of spam sending zombie machines, then they can also have thousands of 
>zombie web servers who can serve the ads. So they don't even need
>their own X domains at all. 
>
>
>  
>

-- 
Carl Hutzler
Director, AntiSpam Operations
America Online Mail Operations
[email protected]
703.265.5521 work
703.915.6862 cell