Re: email spam

From: Hairy One Kenobi (abuse_at_[127.0.0.1)
Date: 12/03/03

  • Next message: Hairy One Kenobi: "Re: Private Address Spaces"
    Date: Wed, 3 Dec 2003 07:50:03 -0000
    
    

    "Ant" <not@home.today> wrote in message
    news:bqjfrh$co1$1@news6.svr.pol.co.uk...
    > "Hairy One Kenobi" <abuse@[127.0.0.1]> wrote...
    > > "diespammer" <diesp@ammer.net> wrote in message
    > > news:3FCD1512.C60972C6@ammer.net...
    > >> if someone got pissed off and sent me a spam email with only several
    > >> pictures that you usually see when the pics have broken links and the
    > >> link to all the pics reads...
    >
    > [snip long url]
    >
    > >> what would they be trying to do ?
    > >
    > > They have encoded the URL, in an effort to get it through a scanner.
    >
    > [snip explanation]
    >
    > > The site decodes to www.only-best-things.com
    >
    > Also, the part before the @ symbol could be an identifier. If this URL
    > is part of an 'img src' it will try and fetch the graphic if you open
    > or preview the email in something like Outbreak Excess. This 'user ID'
    > is sent with the http request and could confirm to the spammer that you
    > opened the email, and thus your address is valid.

    Correct. (I didn't bother to translate the whole URL). The bit on the left
    is a username or username/password combination n the format:

    http://username:password@www.domain/path/page.html

    Unless you've a very good reason, it's a good rule of thumb to avoid
    anything that has a username or password and uses http instead of https - a
    "genuine" site probably wouldn't want to spray a password all over the 'net
    ;o)

    H1K


  • Next message: Hairy One Kenobi: "Re: Private Address Spaces"

    Relevant Pages

    • Re: Secure access to RPC over HTTPs
      ... >1) We would like some kind of additional authentication beside username + ... >to successfully configure RPC over HTTP + the require user certificate option ... I understand a setup with RSA Secure ID is out of the ... Is it possible to force the ISA ...
      (microsoft.public.exchange.admin)
    • Re: Help with HTTP please
      ... There is still a hard limit to the number of concurrent connection allowed. ... Also another suggestion is to use HTTP keep-alive. ... When I send data from the scanner to the pc, I run a small Http server on ...
      (microsoft.public.pocketpc.activesync)
    • Re: Anti-virus section for FAQ
      ... > I'd add a disclaimer to check licensing on the scanners. ... > It's only really viable http option IMO. ... > source http scanner I've seen. ... > http://www.openantivirus.org needs mentioning in all sections. ...
      (FreeBSD-Security)
    • Re: Can I do this with a firewall? nat with Password!
      ... Thanks, and yes the current system is username and password protected, the ... defence. ... this easily done in a firewall or should I put a NAT router behind it? ... home page as http but have a link or a redirection to https. ...
      (comp.security.firewalls)
    • Re: Automate screen scraping: How to programmically "push" a Login button on another web page?
      ... You'll have to use HttpWebRequest to do a HTTP POST passing values for the IDs of the username and password fields. ... I'd suggest downloading Fiddler to see the HTTP traffic and it'll make what's being passed over the HTTP protocol seem so much more clear. ...
      (microsoft.public.dotnet.framework)

  • Quantcast