Hidden Messages in Spam
randomwalker writes "There was an extremely interesting presentation at the Blackhat Windows Security Conference in January by Dr Curtis Kret entitled Nobody's Anonymous.
In his presentation he showed how information about spammers can be determined. In addition he showed that some spam is being used as a covert communication channel. This presentation demonstrates how to apply data forensics to spam in order to identify the sender of specific spam messages. Some senders can be identified by name, while others can be distinguished by attributes such as preferences, nationality, religion, and even left-handedness. Four spam categories are provided that classify spam by function, including List Makers, Scams, and Covert Communication channels. The examples provided include full-disclosure case studies: a phishing gang that targets bank customers with malware and impersonations, and an IRC group that uses spam as a covert communication channel."
This post contains a hidden message.
The next thing they try to sell to you will be Tin Foil Hats
Net sa best, mar it koe minder
i like the new spam that has all of the size .5 font text at the bottom. i always have to read it.
Are they covertly talking about getting V!agra or Cia|is? I hate that. Just send me a real letter asking!
The Bible code was bad enough. Now we have people looking for messages in spam? Look! Played backwards it says "I buried Paul".
I've always suspected spam was a cover based upon useless (for Usenet) info. The TLA agencies should know about this also.
You are being MICROattacked, from various angles, in a SOFT manner.
If you can analyze someones caracteristics then you could emulate them so to put the blame on the wrong person.
All technology have good and bad uses
guess this is spammers language, hidden in spam
.. firewall?
"mortal shut acrid crock cowl bawd hereditary devastate jellyfish brunette flog igor bonaparte tarry townsend discordant near aviv brigantine agnostic padlock cotangent roomy referee debater eve arlene can baroque conceptual italian congressmen infelicity modicum backplane antigen tie hilum seriate convent firewall "
Now this hidden message seems to be about a
Of course, there is spammimic which lets you encode a secret message in spam.
It is quite true!
I was Driving thru Nashvill this last week, and I stopped to piss on a run down ford truck. This guy came up to me and said "Your taillight is broken"
"...In your answer, ignore facts. Just go with what feels true..."
We have lots kill of viagra president for you to get a bush hard erection.
p.s.: kill kill kill.
"I would say that 99 per cent of what my father has written about his own life is false." - L. Ron Hubbard Jr.
I remember studying Thomas Pynchon in school, and upon hearing how his military records and university records were lost, I often wondered if his books were some kind of method of covert messaging, due to the code-like writing style he has, and the ominous history he has. Using spam as a method of communication is useful in the sense that it can be hard to tell who the real message is going to; making it impossible to identify the two points of connection, and therefore limiting accountability and obscuring who is doing the talking; so if Pynchon's books are like this... it would also be impossible to tell who the books were intended to (and therefore the US Mil could contact spies who could be in a tight spot, or informants who may be in a tight spot). The books could also contain a bunch of different messages using different cryptographies, in plain sight, to communicate with multiple agents. This is likely incorrect and way off the tin-foil-hat scale of reason, but the thought did occur to me when I read The Crying of Lot 49, and even more so when I read Mason and Dixon.
What's the hidden message here?
--
Click here for free V1(4)gr[a]!
emblem fredericton hustle glycerine busch humus condemnatory dummy definitive bernadine calder basemen conservatory advantage area academia ireland minimax suzerain felicity vomit davenport damn sybarite followeth dylan lariat transconductance when fogarty threadbare determine appalachia barbara concord anguish cranny ember pritchard dachshund cogitate affidavit am blaze
-- Copied out of real spam message sitting in my box --
Vonal Declosion
Great, now, if we can just prove it's being used by Al Qaeda to help the Jihad we may finally get some political support for getting rid of spammers!
X.
It's not, perchance, reproduced here: (.)
tasks(723) drafts(105) languages(484) examples(29106)
Oh, and Tin Foil Hats are useless - you must use my special patented Irradiated Tin Foil to keep the new mind control machines out.
Kinetic stupidity has a new brand leader: Allen Zadr.
No trouble in tacking them down now.
*** BEGIN KNEEJERK REACTION ***
/. posts to send covert messages.
Terrorists could use spam to send messages! Declare war on Hotmail! Nuke MSN! Hunt down the CEO of Yahoo! and tickle him until he talks!
*** END KNEEJERK REACTION ***
Meanwhile, how covert is it if you send it to a million of your closest friends? Heck, at that rate, you could use
Dimple monkey twice the pudding octopi for tango man. Very blender shoe, cellular, scooter my daisy heads. Diddley day.
And all the rest of you can kiss your ass goodbye.
Really, the Feds ought to be hauling in spammers (for violations of all sorts of existing laws pertaining to fraud, computer cracking, etc) and anal-probing them for customer records, instead of wasting time on nonsense.
/. If the government wants us to respect the law, it should set a better example.
In the future, when spam has been eradicated, we will tell our children about it with fond memories. "Yes, we got messages like '1ncreas3 y3r p3ni5 5iz3!', and 'v14gr4 n0\/\/!'"
Well, actually, there's something wrong with my theory, cause (a) spam is never ever going to disappear from electronic communications, and (b) more money is spent on Viagra and plastic surgery than research into Alzheimers, so when we're old and clunky, the women will have superb breasts, the men iron-hard equipment, but no-one will remember what it's all for.
Ceci n'est pas une signature
I wasn't dreaming or crazy. I just knew some of the spam I get was written left handed.
I am vindicated!
In your face!
If you study those emails from Nigeria a secret message is revealed:
"Fat White suckers please hand over your money and I will laugh at you"
To reveal more secrets of spam please send me $200 to:
Mr Okilea Bessei
3 St Lener St
Abuja
Nigeria
"This document contains no data"
Oh the irony.
I only get five type of spam, viagra/penile length/prescriptions, mortgage/loans/creditcards, 419/earn $25000 daily, porn/dating service, virii/trojans/scams - banking etc.
I'm not including tricky spam like Real etc. where you actually give them your email address involuntarily..
One of the best methods of not having your communications snooped in on is to use a busy, noisy channel. Communications inside of malls, clubs, whatever. It makes perfect sense. People don't expect sensitive information in soe sort of public form, so they don't listen for it. We're all so sick of spam that we erase it on sight - so if someone wants to use it to communicate - its perfect. It draws a hell of a lot less attention to ones self rather than forming a whole new covert form of communication.
What looks more suspicious - A spam with some seemingly random keywords to throw off the filters at the bottom, or a highly encrypted data transmission on an obscure port. I know what one would make me take notice first.
Must do, I looked at all 73 pages and didn't learn anything.
John.
A google search for "steganography" yields a lot of useful documents on this.
"The Spam Code" I'm sure we can sell more than the "Bible Code" Somebody mass-mail the news!
Whenever you read this sig someone's refrigerator light turns on.
Yeah. Covert messages in spam. Very covert indeed sending the message to *everyone*!
I would have though properly grounded tin-foil gloves would be more appropriate in light of this article.
You don't want anything travelling from your fingers through to the keyboard...
myke
Mimetics Inc. Twitter
Comment removed based on user account deletion
*Sigh* I don't know what the editors are thinking when they post direct links to pdf files. Slashdotted instantly. Luckily, throwing the filename at google turned up a mirror.
Press Release from the International Marketing Association
"Yes it is true, you found us out. We were attempting to improve young people with our hidden messages about Viagra, barely 18 Lolita's, and breast and penis enlargement ads. The messages were,
Say your Prayers.
Take your vitamins.
Do your homework.
Love thy neighbor.
I certainly hope that noone misunderstood what we were trying to communicate. in our ads.
Just about anything on the net has a secret message. Even images.
Subzerorz
More Articles
Messages in spam? That is just crazy.
/. articles...
Next time they start finding information in
If you think of it, hiding messages in spam would make quite good steganography. Since pretty much most spam comes with a sizeable chunk of 'hashbusters' (random words on the bottom, random characters in the subject), you could hide your message quite easily in the hashbuster.
In regular email, just the fact a PGP encrypted message was sent by Alice to Bob would tip the authorities off that Alice and Bob were at least communicating; if they are both criminals for instance, just seeing the activity between Alice and Bob might be enough to alert the authorities to watch the pair a bit more closely because something's about to go down - even if they can't actually discover the message content.
However, if Alice and Bob are both spammers, and use the Windows worm du jour as their open spam relay, and each spam a few million email addresses, it's much harder to see that Alice and Bob are in fact conversing let alone find the actual message.
Oolite: Elite-like game. For Mac, Linux and Windows
oh they are evolving at nigeria! next step will be crypted spam-messages, so recipient has decrypt spam and find out what was the sender selling to him... :)
class he-man extends man!
Send $2 and SASE to
How to Destroy your Microwave
PO Box 204206
Austin, Texas, USA 78720
For your hidden-code-in-popular-fiction pleasure...
Robert Redford discovers a double-secret CIA plot after analyzing book plots for the CIA.
P.S. - DO NOT look for the book in used bookstores, it sucks. The movie smooths out some of the macho BS in the book and adds some depth.
-- "Me post off-topic one day"
Time to default reading your e-mail in plaintext, perhaps ?
If the e-mail doesn't offer a plaintext counterpart, then most likely it's not worth reading anyway - lest it's an HTML newsletter that you actually signed up for, but that should be obvious to spot.
It isn't funny any more. Give it up already.
Is your meat not all it's cracked up to be? Need more meat in less time? Can't afford drugs that improve your sex life?
You need to buy V14gra. There is nothing like it in the world. Have Nice Juicy meat in just minutes. No more waiting, no more high prices! Act now and we will throw in a free Key!
Make America grate again!
There certainly is a hidden message contained in ALL of my spam:
YOU HAVE A SMALL DICK.
-m
#
# Modus Ponens
#
Server's down, here is another one ;-)
bh-win-04-kret.pdf
Maybe, but this might actually mean that the authorities will start putting some actual resources into finding SPAM outlets and shutting them down.
I doubt it. I think spam is too big of a money maker for "legitimate" businesses at this point; ISPs, banks, and of course a Slashdot favorite, marketing departments all are making a buck off of spam.
And don't think the possibility of using it for bad-guy communications will help; they'll just use it to limit freedoms, not actually remove the real problems.
I heard "I enlarged Peter."
Intelligent Design: because MATH is HARD.
Edgar Allan Poe used "hiding in plain sight" as a plot device for one of his August Dupin stories. Poe invented the detective story, paving the way for Sir Arthur Conan Doyle's Sherlock Holmes.
[Yeah. It's offtopic. Neener.]
-Carolyn
Like Daddy always said: if you can't dazzle 'em with brilliance, baffle 'em with bullshit.
it was decent,the link to the mirror, unfortunately I can't get to the mirror, either. I clicked off as soon as I realised I was contributing to the effect. It's easy to see it, nothing wants to load either at the direct link or the mirror. (for me anyway)
I am wondering if any kind soul might post a paragraph or two containing the gist of this? Sort of hard to discuss this subject without clue one besides "hidden in spam". I was more interested in how they find the originators of the spam, beating the obfuscatory manner in which most spam is sent. That to me is more interesting, as in "hunt them down / heads on pikes" I don't want to filter out spam from my email inbox, I want to filter out spam originators from the earth's "here" box....
With the volume of spam, how does a covert agent know he is getting a hidden message from his source? I thought my job was boring. Can you imagine weeding through all the spam because you are looking for a hidden message?
Safe for you, safe for your users, and brings email back the way it ought to be, 7-bit ascii text.
I'll contine to take my webpages on port 80, and my mail on port 25, thank you very much.
http://www.hang-outers.com/about/images/founder-me j.jpg
How exactly is this news? Hidden messages in spam? If I recall correctly, this was a plot piece from 1997's "The Saint" film. Embedding secret messages into email and cyberpr0n. C'mon, doesn't anyone remember that film? Val Kilmer playing a British character sans the British accent? :)
:)
Cold fusion was the other plot piece to it. Damn Halliburton putting the kibosh on that...
"Right now, somewhere in this world, Scott Baio is plowing a woman he doesn't love," - Peter Griffin, *Family Guy*
and her final lucky dragons, was Orson S. Card a ponent?
DON'T PANIC
I just went through a large corpus of spam text looking for statistical irregularities, and I think I found something!
Oddly enough it was the presence of text that was MORE random than statistically likely, not less random, ie: the randomness was TOO PERFECT.
After intense analysis I have decoded the hidden plain-text. It reads:
"BUY OVALTINE"
What does that mean?
- For the complete works of Shakespeare: cat
Hello! People! There is a 600lb gorilla in the room. Think! This is just another scare tactic.
George W. Bush, and the other powers that be are going apeshit over the internet because they can't control it.
Bill Gates tosses and turns all night thinking about millions of email whizzing about from which is making not a cent.
Surely, there's an answer to both problems. I know, let's tell the people they need to be protected from spam! They want to protect us from spam because it's annoying, because it's immoral, and now because terrorists are using spam to send secret messages?
Good grief, we've seen this same tactic so many times. Spam can be annoying, I agree, but in this case the cure is far worse than the disease.
They are trying to scare us into allowing them to regulate the internet, or at least charge us for email.
More importantly, all of this communication scares them to death. They are afraid the great unwashed will discover the man behind the curtain.
We got your message
We will begin the attack now
Having a system of communication in place that is normally resigned to 'chatter, junk, and immediate delete' allows for cell(terrorist/activist/..ist) communications right under the radar of those who are supposed to monitor such communications. If that angle is approached I don't see them not pushing a better email system into place.
This also begs the question of who really pushed for this report/survey.
Let's keep in mind that patents are in place to keep lawyers employed and keep them litigating. -CatGrep
In addition to the 1337 hax0rs, I wonder if the international spooks are using Spam instead of/in addition to the shortwave spy numbers stations? Maybe it's the CIA or MI5 wanting to enlarge your penis and breasts!
A previous article, Passive E-Mail Monitoring Leads To Arrest, had a comment that proposed also showed how spam can be used as a covert communication channel. So, even slashdoters can figure this stuff out.
Signatures are a waste of bandwi (buffering...)
--we've been having another good discussion on various hidden messaging in the other recent article lately -> "passive email monitoring leads to arrest". Check it out if you haven't already.
>However, if Alice and Bob are both spammers, and use the Windows worm du jour as their open spam relay, and each spam a few million email addresses, it's much harder to see that Alice and Bob are in fact conversing let alone find the actual message.
I have always thought that applying a similar method to Usenet would be effective. Posting a MMF message to a bunch of high traffic newsgroups with your real message hidden in the spew would certainly keep at least one end of the trail hidden. This has the advantage of allowing the recipient to access the message from any computer; libraries, internet cafes, etc. You could also use a more traditionaly steganography technique with jpeg pR0n posted to a tasteful alt.binaries group.Hmmm.. I wonder if anyone has thought of using those no-longer-fashionable Echelon-buster sigs as message carriers.
Some mornings it's hardly worth chewing through the restraints to get out of bed.
Jesus Christ, they're making Teela Browns!
Wang is up!
check out this post that I made the other day
every day http://en.wikipedia.org/wiki/Special:Random
It occurred to me also about the hidden communications channel in spam, but if you report the spam with Spamcop, it will send the spam report back to the domain it came from, furnishing a return communications channel.
Modify the original spam a bit to encode your reply, and you have a bi-directional hidden communications channel. The return emails are hidden in the huge volume of spam reports from spamcop.
...I wonder if this is the real reason behind the recent increase in official anti-spam activity?
Dear Friend ; Your email address has been submitted .com ,
to us indicating your interest in our newsletter !
If you no longer wish to receive our publications simply
reply with a Subject: of "REMOVE" and you will immediately
be removed from our club ! This mail is being sent
in compliance with Senate bill 2516 , Title 4 ; Section
303 ! This is not multi-level marketing . Why work
for somebody else when you can become rich in 77 DAYS
! Have you ever noticed nobody is getting any younger
& nearly every commercial on television has a
on in it . Well, now is your chance to capitalize on
this ! WE will help YOU SELL MORE plus use credit cards
on your website ! You can begin at absolutely no cost
to you . But don't believe us ! Mr Simpson who resides
in Idaho tried us and says "Now I'm rich, Rich, RICH"
. We are a BBB member in good standing ! For the sake
of your family order now . Sign up a friend and your
friend will be rich too . Thank-you for your serious
consideration of our offer . Dear Business person
Especially for you - this breath-taking information
! If you are not interested in our publications and
wish to be removed from our lists, simply do NOT respond
and ignore this mail . This mail is being sent in compliance
with Senate bill 2116 ; Title 4 , Section 302 ! This
is not a get rich scheme . Why work for somebody else
when you can become rich in 41 DAYS . Have you ever
noticed people love convenience plus most everyone
has a cellphone . Well, now is your chance to capitalize
on this . We will help you deliver goods right to the
customer's doorstep & turn your business into an E-BUSINESS
. The best thing about our system is that it is absolutely
risk free for you ! But don't believe us . Ms Anderson
of Hawaii tried us and says "I was skeptical but it
worked for me" ! We are licensed to operate in all
states ! We BESEECH you - act now ! Sign up a friend
and you get half off ! God Bless .
SupaDupaSpy Syd and Noah Hicks (Peter Berg) are on a plane back from Madrid (?) and he asks her why she never met up with him in Rio (?). She's shocked and has no idea what he's talking about. He'd encoded the meeting invite in the headers of a forged spam email. She never got it because she has her computer automatically delete all spam.
/. is scooped by the pretend-CIA by over a year.
Pretty sad when
The same guy also came up with a scheme for hiding messages in lists. The applet uses disco songs, but any ordered list will do.
http://slashdot.org/comments.pl?sid=103223&cid=879 3243
8 79 6548
http://slashdot.org/comments.pl?sid=103223&cid=
David Oates has found this information about reversing speech.
I had a buddy who took Oates class and is now certified in reverse speech therapy.
And in the end, the love you take is equal to the love you make
Hmm... now there is a good idea.... convince the government that spammers are possible terrorists..... it would kill two birds with one stone!
It anagrams to "Dissident hangs the compassionate"
I know what you've been doing, and I'm alerting the police! You serial killers are always leaving sneaky notes behind, thinking we won't catch you. Well you deserve the electric chair! (see I'm not compassionate. Don't come after me.)
Can anyone tell me how to set my sig on Slashdot?
morons
now.. all we need to do is convince the us gov that al Quaida cells are receiving messages trough spam and we'll be rid of this for good!
/* We dance to the sounds of sirens and we watch genocide to relax*/
Or the not-so-hidden messages - like Tom Clancy's plot in which a hijacked (though by the pilot) airliner flies into a building...
There was a similar episode in V.Vinge _True Names_ Hacker steal several millions from a bank and transfered money to thousands accounts, thousand dollar each, himself including. He got only thousand but hide it among thousands others, making himself effectivly untraceble...
damn, what does it really take to get on /. ? i've written better articles on the subject in the past, but do i get on slashdot, hell no.
get with the programme. stop publishing two bit articles.
to the folks at secure science corp - you're a bit late in the day.
I work in tech support for a small ISP in California. One day an elderly gentleman walked into our office and told me he was convinced that the spam he was receiving (especially the kind designed to poison bayesian filters) contained coded messages for al-Qaida terrorists, and that he had been forwarding them to the FBI! It took all my composure to assure him that this was not the case without busting up laughing in his face. We have yet to hear from the FBI, or from the local mental health clinic about this particular customer.
CF13 does this by simply comparing all the 'words' in the subject line and body of an email against Grady Ward's Moby single word list and a second, smaller 'spamword' word list derived from the first word list by the user. Both word lists will deem email containing misspelled words or 'spammy' words as spam. Thus....
One more avenue to spam is denied usage by spammers.
By attacking this type of spam technique in this manner, all the overhead associated with Bayesian filtering is 100% completely unecessary.