On Fri, 2003-06-20 at 03:51, Benjamin A. Shelton wrote:
> >
> >
> >I can't believe a spamware writer would be smart enough to create
> >proxy-raping spamware and yet dumb enough to not send himself a test
> >message with it to see if it works. 
> >
> If he's dumb enough to spam in the first place, does this *really* 
> surprise you? :-)

It does. When someone makes something, it is natural instinct for them
to want to test it, see if it works.

Raping proxies is hardly rocket science, irc skript kiddies have been
abusing socks proxies for as long as i can remember, but it would still
require some skill to program. The use of html comments to try and
obfuscate the message displays some knowledge of the issues at hand, the
author is looking at someone's antispam filter and trying to get around
it. 

I'm not saying he's the brightest bulb in the pack, but spamware writer
is displaying some intelligence. Maybe he just doesnt care about the
rest of the world, but he's not totally stupid or he wouldn't be able to
get his spam thru a socks proxy. The contrast between being intelligent
enough to rape proxies and being dumband unnatural enough to not check
your output seems, well, ridiculous to me.

The more I think about it, the more I think that spam renders in
something, I'm sure it does. It works just like the author meant for it
to work. Either it renders in oe (can't test here, this is a
microsoft-free zone) or it is specifically made to spam a web-oriented
mail service (yahoo or aol or something) that blindly strips anything
outside a limited subset of html (which would be a reasonable security
measure for a webmail service to take) and the truly stupid spammer
end-user fed it the wrong address list.

I think I'm going to keep an eye on this one, maybe send a few
comment-obfuscated links to a free beer to friends on various webmail
services and see if any of them get it intact :))

-- 
Yorkshire Dave


-------------------------------------------------------
This SF.Net email is sponsored by: INetU
Attention Web Developers & Consultants: Become An INetU Hosting Partner.
Refer Dedicated Servers. We Manage Them. You Get 10% Monthly Commission!
INetU Dedicated Managed Hosting http://www.inetu.net/partner/index.php
_______________________________________________
Spamassassin-talk mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/spamassassin-talk

Reply via email to