Re: How Did I Get This Mail?

From: N. Miller (anonymous_at_discussions.microsoft.com)
Date: 10/23/03


Date: Thu, 23 Oct 2003 12:23:23 -0700

In article <3F97BB58.76D09C5A@earthlink.net>, mtnviews@earthlink.net says...
> It's very unlikely that any communication with those 10 people in the5 days since I
> revealed to them my new e-mail address have resulted in bcc's, or cc's.

O.K., but I had to ask because that is one source of email address
discovery.

> My new address is 13 characters long. It only differs by an s (no longer plural) from
> the previous one. It seems like a very unlikely address that anyone would really want
> to use. It is possible I suppose since I just dropped the s from the old address that
> some one reproduced it without an s.

That is a very easy test for a spammer to try; with 's', and without 's'.
Another interesting variation on the theme is the 'grepping' out of address
components. I created an account with the username 'antispam'; on a local
domain that I own, so I don't have to deal with provider rules prohibiting
that name. So many people 'munge' their email addresses with some variation
of 'spam', or 'nospam', that the spammers automatically search and remove
such obvious munges.

In my case, however, I wasn't trying to over think a solution to a problem,
I just wanted a unique address at my domain to deal with spam. I figured I
could filter/block, if necessary, and a spammer would have to have something
akin to a deathwish to spam an antispam account. So what did one spammer try
to do? Unmunge the address by removing the spam from the account name; I got
a few logged rejects where my server sent; "550 Address
<anti@mydomain.invalid> not known"!

> I think I'm going to do a little experiment. I'm going to create something of a funky
> address, and not let anyone know what it is. I will then troll my usual web sites and
> see how long it is before I start getting Swen msgs or any spam.

Anywhere from hours to weeks. If you reveal it in locations where the
harvesters can grab it. Try it with "1337" spelling tricks, and make two
addresses that look like they are identical, but change which characters are
used. Say, si1ly8il1y" and "5il1ybi1ly". Note that the first case uses the
numeral '1' in the first place of 'silly', and the second place of 'billy',
while the second case reverses that order. Use one prolifically, but don't
even use the other; ever. See how long that second one lasts. I have one
such at Hotmail which is over a year old, now, and has yet to receive even a
single spam. {Gotta check it every 28 days, or so, so it won't go
'inactive', though.}

-- 
Norman
~Win dain a lotica, En vai tu ri, Si lo ta
~Fin dein a loluca, En dragu a sei lain
~Vi fa-ru les shutai am, En riga-lint


Relevant Pages

  • Re: SPAM
    ... Munge your e-mail address. ... That way, the spammer's mail server can't even begin to send their crap because there will be no receiving mail host by that name to which they can connect. ... There are some NSPs that require you use the same e-mail address as is recorded in your registration to use their service, so you're screwed with those NSPs that are forcing you to deliberately divulge a valid e-mail address (and why you might try using an alias or disposable account to register with that NSP). ... You would define a filter that looks for a special string (or passcode) in the Subject of any e-mail delivered to that account: if that string is *not* in the Subject header then the e-mail gets deleted. ...
    (microsoft.public.outlook)
  • Re: THIS IS MOHAMMED 12
    ... You can't report the spam you don't see; ... You don't have to have a Google account to use it (but to have ... becomes boring and costly for the spammer at some point. ... evangelism: XHTML 1.0 Strict ...
    (comp.lang.javascript)
  • Re: block_ssh_guessers
    ... zombies on wide bandwidth hookups - such as windoze boxes on ... titled "A day in the life of a spammer" (don't know if it's still at ... indicating that was a main mechanism for _mail_ delivery of spam. ... means following the registrations of the sites being advertised. ...
    (comp.os.linux.security)
  • Re: recommendations of natural anti inflammatories please
    ... there isn't any misunderstanding, you are spamming here, and in the ... never said you were chris - i showed who the owners of the spam ... spammer by any name is still a spammer... ... I am part of the sales and support staff of the Emu Farm and our ...
    (alt.support.arthritis)
  • Re: FA: Vintage stuff up for auction UK - loads more next week
    ... (Berlin Uni) ... So, some lazy, clueless buffoon puts up a simplified definition ... and you see that as a license to spam. ... odd years military service but none ever mentioned spammer. ...
    (sci.electronics.components)