Slashdot Mirror


How Image Spam Works

Esther Schindler writes "CSO Magazine has an article about "The Scourge of Image Spam," with an explanation of its effect (a year ago, fewer than five out of 100 e-mails were image spam; today, up to 40 percent are in that category, and image spam is the reason spam traffic overall doubled in 2006). You might already know about that, ho-hum. But what's even cooler is a interactive graphic page which demonstrates the various methods used by image spammers and how it works."

18 of 278 comments (clear)

  1. Here's how it works from another perspective by Richard+McBeef · · Score: 5, Insightful

    It works because some rat fuckers out there buy the shit that's being advertised.

    1. Re:Here's how it works from another perspective by Qoroite · · Score: 4, Insightful

      You know, I've always wondered how true that really is.

      What sort of a brain-dead moron would actually fall for spam? There can't be many people that dumb surely?(I hope....)

    2. Re:Here's how it works from another perspective by jfengel · · Score: 4, Insightful

      You know that the IQ bell curve has two tails. Somebody's got to be in the left tail. And since spam is nearly free, you only need to find a few idiots.

      Then again, they've got to be coming to the intersection point between "Dumb enough to buy v1@gra from a spammer" and "Too freaking stupid to use a computer or have any money".

    3. Re:Here's how it works from another perspective by Anonymous Coward · · Score: 5, Funny

      There wouldn't be anyone in the left tail if we took the warning labels off everything.

      /just sayin'

    4. Re:Here's how it works from another perspective by plover · · Score: 5, Insightful
      You have to look at the business of spam to understand why it hasn't gone away yet.

      There are actually three parties involved in spamming: the merchant, the spammer, and the victims/recipients. The merchant is the trailer trash dude who fished a case of expired viagra out of some pharmacy's dumpster. He wants to sell it online and make a fortune. So he hires a spammer who agrees to send out 10,000 emails for $60.00.

      Whether or not the merchant makes a single sale has no effect on the spammer. The spammer made his money just by sending the crap emails out. And the supply of idiots with get-rich-quick schemes is virtually infinite, guaranteeing the spammers a never-ending stream of fools willing to hand them $60.00 apiece.

      This means we'll probably be fighting spam until the world runs out of greedy idiots.

      --
      John
    5. Re:Here's how it works from another perspective by MarkGriz · · Score: 4, Funny

      "It works because some rat fuckers out there buy the shit that's being advertised"

      So that's why they are buying penis enlarging pills

      --
      Beauty is in the eye of the beerholder.
    6. Re:Here's how it works from another perspective by Mr+Z · · Score: 4, Insightful

      I once made a calculation that if every person on the Internet responded positively to precisely one spam, that would be enough to make spam wildly profitable. Granted, that was a few years ago, but bandwidth (and therefore spam) has only gotten cheaper and bot nets more prevalent (making spam cheaper still).

      You don't have to go too far down the left tail of the bell curve to make up for the folks on the right half. After all, in terms of positive response, the best the folks in the right half can do is respond positively to zero spams. The further you go into the left tail, the more likely you are to run into people who respond positively to spam on a somewhat regular basis. The cut-over line for "responds to spam" vs "does not respond to spam" can be pretty far into the left tail and still have spam be profitable.

      Making matters worse, negative responses to spam rarely do anything to the spammer. Instead, they just annoy IT departments into implementing ever heavier spam filters. Every so often somebody gets sued, but it's hardly enough to make a real dent in things.

  2. For me it's not image spam, it's botnet traffic... by garcia · · Score: 5, Informative

    For me the spam e-mails are minimal to my machine. I do see a couple of them come in through GMail on the account that I have posted publicly on my website for people to contact me but for the most part they are the standard stock pump and dumps or phishing schemes.

    What has been killing me recently were the fucking botnet "attacks" sucking my DSL's bandwidth with those douchebags hitting me with a GET and an immediate POST for tons of URLs all over my site. Their referrer was http://www.google.com/ and for a few hours I couldn't figure out how to stop that w/o stopping Google search referrals too.

    Some nice guy in #apache helped me out with:

    SetEnvIfNoCase Referer "^http://www.google.com/?$" BadReferrer=1

    SetEnvIfNoCase Referer "^http://www.google.com/?$" BadReferrer
    order deny,allow
    deny from env=BadReferrer

    That has been returning 403s to the botnet which apparently stop such frequent attempts when they receive the error. I was getting hit with their shit every 4 to 5 seconds all day yesterday and now they are "pinging" me with attempts every hour or so. I don't know if it's a different botnet or the same one trying to get back in but that was the most effectual way to drop the huge spam traffic I was receiving but couldn't ban due to the wide range of IPs.

    Botnets fucking suck :(

  3. A Key Point by eldavojohn · · Score: 5, Interesting

    This is a great article describing how it is formed, why it looks like that, what that is designed to trick, etc.

    The key point they're missing is that it works under the assumption that a very small part of the populace doesn't recognize this as spam. These people then think that an investment firm decided to tip everyone off and they mistakenly buy the stock so that it goes up a nickel only to watch it drop shortly after the spammer drops the stock.

    What's ironic is that I'll bet there's people out there with money that know this scam but buy the stock to also cash in on people who think this is a real tip. It might even be that the initial assumption is wrong and that the only people scamming each other are scammers trying to take advantage of another scammer's scam. Scam. Oh, the irony if that's the case. Either way, the article mentions the SEC removing stocks that went up that were junk stocks in spam mailings!

    It's a scam. Stay away and alert your loved ones if you think they may fall into the initial category of the small part of the populace. The safest way to stop spam is to alert people and teach them how to identify it.

    You don't buy stock that an angry fruit salad told you was hot just like you don't sleep with the girl who leaves dead spots of grass where she sits on the corner. Awareness is a valuable key to our solution against spam.

    --
    My work here is dung.
  4. Re:Ideas? by Applekid · · Score: 4, Funny

    For starters, there's always hiring someone else to screen your emails for you. I wouldn't be surprised if there was already a service that you could join today and get your emails pre-screened.

    Spam filters are going to have to get to be as good as an informed human being before they can stop all spam regardless of what tricks they use.

    I just hope AI gets to that point before it goes all sentient... you know:
    "DESTROY ALL SPAM"
    ...computing...
    "SPAM COMES FROM HUMANS"
    ...computing...
    "DESTROY ALL HUMANS"

    --
    More Twoson than Cupertino
  5. Re:Spam? by u-bend · · Score: 5, Interesting

    Anyone with a Gmail account ever notice that your targeted advertising links are all about spam recipes (i.e. Spam Meat Loaf) when you're in your spam folder? I've always loved that, and figured that it may have started out as a bug, but one that the Gmail team sort of fell in love with.

    --
    u-bend
  6. Re:For me it's not image spam, it's botnet traffic by WTBF · · Score: 5, Interesting

    Every 4 to 5 seconds is not bad, I was hit by a similar attack.

    I run a webserver on my home connection, all it hosts is MythWeb, and it is password protected. I am the only person who should have to access it, and am on a dynamic IP address (not a problem I thought when setting it up, and have been very successfully using DynDNS.) About a year ago my IP address was changed to a new one, as it happens. My internet was going as slow as molasses about 10 minutes later, although I just thought it was a temporary thing with my connection. The next day it is even slower, and so I begin to investigate - I perform a speedtest and get very good results for download (but not perfect), but almost no upload. I thought this was odd and checked with my ISP to make sure there were no known issues with the connections in my area - there were not. So I then plugged my modem directly into my computer and it was still happening (which made me think it was something with my ISP, as it affected my router and my computer), and so I then clicked on my bandwidth monitor to see what speeds I could get, and before doing anything there was a constant stream of about 100kb-150kb of downstream traffic. And so I plugged the internet back through the router (I was running a software firewall by the way, so I considered bypassing the router safe).

    I then looked at my webserver logs, and it took forever to load. So instead I did a "tail -f" on the error log. I must have been receiving hundreds of requests per second for websites that were nothing to do with me. It was scrolling so quickly I could not read entries as they went past. Examining it more closely I realized what happened: the owner of the IP address before me had been running an open proxy on port 80, and when the IP address changed all their requests were redirected to me, killing my much slower connection (from all the 404 responses apache was sending). So I closed port 80 for a week, and my connection returned to a somewhat normal state. However, I was still receiving about 20 requests a second, despite being offline (seemed mainly to be people trying to do dos attacks through a proxy). After a month this was down to only 1 or 2 a second, and it has remained like that till today.

    Because of your post I checked my webserver logs, and at 1:27:18am I received my last request for a website, and looking into it my IP address changed to a new one (only took a year), and so some other unfortunate person is now receiving a few requests a second to be a proxy server.

  7. Where is Chris Hansen on this? by oni · · Score: 5, Insightful

    What sort of a brain-dead moron would actually fall for spam?

    I wish that somebody would do a TV show like "To Catch a Predator" except that they would go after the people who buy spam. Embaras them a little.

    "Hi, I'm Chris Hansen from NBC. Why don't you have a seat there. Why are you here sir?"
    "uh well I, I'm here to see a friend."
    "You're here to have your penis enlarged aren't you?"
    "no, no, I'm just here to hang out."
    "Sir this is an email that we sent to you advertising penis enlargement. You clicked on this email."
    "omg, is this on TV??"

  8. pump-n-dump by Penguinshit · · Score: 4, Funny

    describes the multitude of summer camp romances in my youth...

  9. Re:Spam? by LiquidCoooled · · Score: 4, Informative

    The spam recipe bar is an offshoot from the WebClips feature of your inbox.
    The inbox can be configured to have a single item selected at random from one of a number of RSS feeds, I have mine configured to show Routers oddly enough and slash.

    The area marked for webclips is a custom feed from www.recipesource.com

    If you look on your trash folder, you also get tips about recycling.

    The other folders give standard syndication adverts.

    More info here

    --
    liqbase :: faster than paper
  10. Re:tutorial? by cayenne8 · · Score: 4, Insightful
    See? I used to bitch years ago that email should be TEXT ONLY, but, no...we all want html mail and purty graphics.

    If we'd stuck with text only email....no problem with images.

    Oh well....back to trying to install Win 95 on an abacus.....

    --
    Light travels faster than sound. This is why some people appear bright until you hear them speak.........
  11. GIF SPAM by geekmansworld · · Score: 5, Interesting

    It seems that a lot of image spammers have tried to circumvent newer spam-blocking technology by using animated GIFs: the first frame of which is blank, and the second of which contains the ad.

    For months, we had consistent problems with clients e-mails (using a major ISP I won't mention here) not reaching our server. Curiously, it would happen most often with replies to our original e-mails.

    After months of anguish and highly accusatory phonecalls to the ISP's tech support, we discovered the problem. Our company e-mail signature contains GIF images. When a client replied to us, quoting the original e-mail, the ISP would scan the e-mail, detect the inline GIF, and block the e-mail.

    Since we changed the format of our signature to use JPEGs instead of GIFs, we've had no problems with the ISP blocking client replies.

    So once again I assert: the biggest problem with spam isn't even the spammers, it's the n00b sysadmins who implement agressing spam-blocking rules before thinking about the consequences. I'd rather get more spam that have legitimate e-mails blocked by false positives.

    "The first thing we'll do is kill all the spammers..."

  12. So what? by SanityInAnarchy · · Score: 4, Interesting

    I've almost deliberately exposed my email address all over the place, without the ridiculous antispam obfuscations (no "ninja AT slaphack DOT com" here), because I prefer not to use CAPTCHAS where I can help it, and that's just a poor-man's CAPTCHA.

    The reason? Simple:

    Statistical spamfiltering of any kind -- bogofilter, in this case -- is creepily accurate.

    Recently, I lost my bogofilter database (due to my own stupidity). It took one day for it to get back to 95% accuracy, and another day to get up to 99%, with one false positive -- the first I had seen in about six months.

    --
    Don't thank God, thank a doctor!