Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - email spam

 
Thread Tools Search this Thread
Old 12-02-2003, 10:42 PM   #1
Default email spam


if someone got ****ed off and sent me a spam email with only several
pictures that you usually see when the pics have broken links and the
link to all the pics reads...
http://7%75%69%7a%445%6f%79%6b%66%74...2e%68%74%6d%6c

what would they be trying to do ?



diespammer
  Reply With Quote
Old 12-03-2003, 12:07 AM   #2
Hairy One Kenobi
 
Posts: n/a
Default Re: email spam
"diespammer" <> wrote in message
news:...
> if someone got ****ed off and sent me a spam email with only several
> pictures that you usually see when the pics have broken links and the
> link to all the pics reads...
>

http://7%75%69%7a%445%6f%79%6b%66%74...2e%68%74%6d%6c
>
> what would they be trying to do ?


They have encoded the URL, in an effort to get it through a scanner.

You'll occasionally se legitimate use of this encoding (e.g. "Fred
Flintstone" would encode to Fred%20Flintstone, because 20 in hexadecimal
[base 16, what most people use these days for binary stuff] is equal to 32
in decimal [computers don't have fingers!]. ASCII 32 is " " (space)

The site decodes to www.only-best-things.com

--

Hairy One Kenobi

Disclaimer: the opinions expressed in this opinion do not necessarily
reflect the opinions of the highly-opinionated person expressing the opinion
in the first place. So there!




Hairy One Kenobi
  Reply With Quote
Old 12-03-2003, 01:55 AM   #3
Ant
 
Posts: n/a
Default Re: email spam
"Hairy One Kenobi" <abuse@[127.0.0.1]> wrote...
> "diespammer" <> wrote in message
> news:...
>> if someone got ****ed off and sent me a spam email with only several
>> pictures that you usually see when the pics have broken links and the
>> link to all the pics reads...


[snip long url]

>> what would they be trying to do ?

>
> They have encoded the URL, in an effort to get it through a scanner.


[snip explanation]

> The site decodes to www.only-best-things.com


Also, the part before the @ symbol could be an identifier. If this URL
is part of an 'img src' it will try and fetch the graphic if you open
or preview the email in something like Outbreak Excess. This 'user ID'
is sent with the http request and could confirm to the spammer that you
opened the email, and thus your address is valid.




Ant
  Reply With Quote
Old 12-03-2003, 05:54 AM   #4
Snake-Eyes
 
Posts: n/a
Default Re: email spam
On Tue, 2 Dec 2003 16:42:33 -0600, diespammer wrote
(in message <>):

> if someone got ****ed off and sent me a spam email with only several
> pictures that you usually see when the pics have broken links and the
> link to all the pics reads...
> http://7%75%69%7a%445%6f%79%6b%66%74...%491%71%79%50%
> 62%61%50%4c%68%6a6%51%59%63%68%77%78%780%6d%6f1%74 7%65%6e%49%4f%61%52%7a%63%6
> a72%76%68%54%74%7a%64%6e%71%63%42%49%498%67%49%77% 47%4a%5a%4d%5a%6d%77%4f%79%
> 6f%6e@%77%77%77%2e%6f%6e%6c%79%2d%62%65%73%74%2d%7 4%68%69%6e%67%73%2e%63%6f%6
> d/%6c%65%61%64%73/%69%6e%64%65%78%2e%68%74%6d%6c
>
> what would they be trying to do ?
>


The best thing you can do to fight SPAM is to do some research. One of
the most complete collection of pages I have found on "email SPAM" is:

http://email.about.com/cs/spamfightingtips/

--
Snake-Eyes
(nickname) AT mchsi DOT com




Snake-Eyes
  Reply With Quote
Old 12-03-2003, 07:50 AM   #5
Hairy One Kenobi
 
Posts: n/a
Default Re: email spam
"Ant" <> wrote in message
news:bqjfrh$co1$...
> "Hairy One Kenobi" <abuse@[127.0.0.1]> wrote...
> > "diespammer" <> wrote in message
> > news:...
> >> if someone got ****ed off and sent me a spam email with only several
> >> pictures that you usually see when the pics have broken links and the
> >> link to all the pics reads...

>
> [snip long url]
>
> >> what would they be trying to do ?

> >
> > They have encoded the URL, in an effort to get it through a scanner.

>
> [snip explanation]
>
> > The site decodes to www.only-best-things.com

>
> Also, the part before the @ symbol could be an identifier. If this URL
> is part of an 'img src' it will try and fetch the graphic if you open
> or preview the email in something like Outbreak Excess. This 'user ID'
> is sent with the http request and could confirm to the spammer that you
> opened the email, and thus your address is valid.


Correct. (I didn't bother to translate the whole URL). The bit on the left
is a username or username/password combination n the format:

http://username/path/page.html

Unless you've a very good reason, it's a good rule of thumb to avoid
anything that has a username or password and uses http instead of https - a
"genuine" site probably wouldn't want to spray a password all over the 'net
;o)

H1K




Hairy One Kenobi
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
I have become rich in 30 days lemony-snicket A+ Certification 2 09-07-2009 03:01 PM
How to turn $6 to $16000 in few days of web crawling please@dontreply.net DVD Video 0 02-02-2007 07:25 AM
This is incredible! jc_ice DVD Video 1 08-13-2006 10:47 AM
Increase Your Wealth From Home misteek DVD Video 1 08-13-2006 10:47 AM
TURN $5 INTO $15,000 IN ONLY 30 DAYS...HERES HOW! mosquitonose@hotmail.com DVD Video 0 01-18-2006 10:32 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46