Snort mailing list archives

Re: Subliminal html in spam?


From: John Sage <jsage () finchhaven com>
Date: Sat, 6 Apr 2002 16:24:21 -0800

umm..

I'm not sure whether I should <blush>blush</blush>, or ask you to take
your tongue out of your cheek..

On Fri, Apr 05, 2002 at 12:03:51AM -0600, J. Craig Woods wrote:
John Sage wrote:

All embedded within comment tags, within the body text.

WTF?

You do realize what you have discovered here, yes? This is espionage in
its most diabolical expression. You are to be lauded on your
investigations. I do hope you have notified the appropriate authorities.
I certainly did. The first thing I did after reading your post, just in
case secure communication was needed, was to get out my seldom used Dick
Tracy wristwatch. The serious nature of this sedition, as I am sure you
would agree, might necessitate bringing James Bond into this matter too.

Do get back to us...  

Your friend (or is it fiend)


Actually, as I have discussed with several people off-list(s), it
would be trivially easy to write an html parser that strips out
comment tags, and then run the remainder of the email body through
whatever parsing engine your spam killer of choice might employ..

Hell, there's about 98% of what you'd need on pp.716-718 of "Perl
Cookbook"...

Still, I wonder if this "cloaking" is being touted as a new *feature*
by some spam software dealers...


- John
-- 
In those days, you could not buy a $2000 200MHz Pentium server.

_______________________________________________
Snort-users mailing list
Snort-users () lists sourceforge net
Go to this URL to change user options or unsubscribe:
https://lists.sourceforge.net/lists/listinfo/snort-users
Snort-users list archive:
http://www.geocrawler.com/redir-sf.php3?list=snort-users


Current thread: