Statue Forum 





Go Back   Statue Forum > Other Stuff > Books, Literature & News

Reply
 
Thread Tools
Old 02-08-2008, 04:09 PM   #1
hawkeyethearcher
Yeah, I spend WAY too much time here!
 
hawkeyethearcher's Avatar
 
Join Date: Feb 2006
Location: o'side baby
Posts: 12,629
impressive spammers

Spammers are using a sophisticated piece of software that can create thousands of Windows Live email addresses by cracking the protections designed to prevent the large-scale creation of fraudulent accounts.

According to security firm Websense, the bot is surreptitiously installed on the PCs of end users. It then establishes a connection to the registration page of the Microsoft-owned mail service. About a third of the time, the software is able to bypass the Captcha requirement through a process that researchers have yet to precisely figure out.

The executable software,has already led to a surge of spam being sent from the Microsoft-owned service, said Dan Hubbard, vice president of security research at Websense. Its discovery comes a few weeks after the release of proof-of-concept code that defeats a similar Captcha used by Yahoo! Mail.

Free email services from Microsoft, Yahoo! and Google are rarely blocked by anti-spam products, making accounts on those services highly prized by spammers. In the past week or so, Websense antispam filters have gone from blocking fewer than 100 Windows Live accounts per day to a number that's in the thousands.

"Some customers were actually flagging the mail as legitimate because it was coming from Microsoft Live," said Hubbard. "Clearly, (spammers) are using the fact that (the services) are legitimate."

Short for "completely automated public Turing test to tell computers and humans apart," Captchas have emerged as a key barrier hindering scammers who want to create large numbers of fake online accounts. In some cases, Captcha-cracking has involved software that transmits the graphic to third-party website that promises a visitor free porn in exchange for typing in the characters. Other times, programs using highly specialized heuristics algorithms try to guess the characters, based on the arrangement of the pixels.

"Captcha breaking has been one of the largest targets of malware operators for some time, even to the point that they will go and farm out the job to human beings," said Adam O'Donnell, a research scientist at antispam company Cloudmark. "It's that profitable."

For years now, the forces of good and evil have been engaged in an arms race of sorts, in which new Captcha cracks beget stronger Captcha images, which in turn lead to more advanced cracks.

Hubbard said a Websense honeynet recently caught malware. When researchers installed it on a lab machine, they discovered that in addition to sending spam, it attempted to create the Windows Live accounts. The software cuts Microsoft's Captcha image and sends it to a server controlled by the scammers. The server then sends the text contained in the image back to the infected PC. The answer is correct as much as 35 per cent of the time.

"We don't know what the process is," said Hubbard. One possibility is that there are human being on the other end, but Hubbard is leaning away from that theory because it would require hundreds of people to make it work. It's also possible the spammers have found a new type of Captcha-cracking software.

Besides being rarely blocked by spam filters, accounts with big email services are valuable to spammers for other reasons. For one, they're free. And for another, the millions of other accounts held by legitimate users makes it hard for the services to pinpoint mass mailers.

Don't count on this cat-and-mouse match ending anytime soon
hawkeyethearcher is offline   Reply With Quote
Old 02-08-2008, 04:16 PM   #2
Alex655321
Yeah, I spend WAY too much time here!
 
Alex655321's Avatar
 
Join Date: May 2005
Location: LI New York
Posts: 143,157
Alex655321 is offline   Reply With Quote
Old 02-08-2008, 04:17 PM   #3
Ink
My Better Is Better Than Your Better
 
Ink's Avatar
 
Join Date: Jan 2006
Location: O-H-I-O!!
Posts: 5,546
there's always tons on my yahoo email, and they're all .yahoo adresses
Ink is offline   Reply With Quote
Old 02-08-2008, 04:28 PM   #4
Vince-Vell
Cosmic Painter
PainterModerator
 
Vince-Vell's Avatar
 
Join Date: Mar 2006
Location: In Da Studio!
Posts: 15,780
This is why i LOVE my Apple .Mac account. I get no spam at all, maybe 1 or 2 junk/spam emails a month. Eeverything else is stuff i have allowed or get regularly from people.

All tho i have a hotmail email for my junk email, which i use to sign up to places or for when places ask for a email address.
Vince-Vell is offline   Reply With Quote
Old 02-08-2008, 05:12 PM   #5
P1X4R
...
Producer
 
Join Date: Aug 2004
Location: .
Posts: 11,209
i avoid free, public email accounts. our company uses ironport software that catches a lot of spam from our inboxes.
P1X4R is offline   Reply With Quote
Old 02-08-2008, 08:34 PM   #6
armitage
Kindly Asked To Leave
 
Join Date: Oct 2004
Posts: 9,163
Microsoft blows!
armitage is offline   Reply With Quote
Old 02-09-2008, 01:05 AM   #7
riderV3
ROT Minister of Scientific Emergency Management
 
riderV3's Avatar
 
Join Date: Mar 2006
Location: Where the best steaks are served.
Posts: 7,472
Quote:
Originally Posted by armitage View Post
Microsoft blows!
WORD!
riderV3 is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Powered by vBadvanced CMPS

All times are GMT -4. The time now is 12:29 AM.



Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright StatueForum.com