New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 24)
· Marcia's (CO8)
· Bill G's (CO12)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 1170
Comments: 21
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin   Your Favorite ForumsFavForums 

How to filter body that's all image...

 
Post new topic   Reply to topic       Computer Cops Forum Index -> Mailwasher - Troubleshooting / General
View previous topic :: View next topic  
Author Message
Eisenson

Corporal
Corporal
Premium Member
Premium Member


Joined: May 22, 2004
Posts: 59
Location: USA

PostPosted: Sun Jun 06, 2004 11:39 am    Post subject: How to filter body that's all image...
Reply with quote

My MWP setup is better than 99% effective now, thanks to help from the experts here. But two all-image spamgrams slipped through today, and I wonder if there's an effective way to treat them.

The subjects were misleading and could not be used as filter criteria. FirstAlert, DNS Blacklist, Bayesian, and existing filters all passed them.

Even when I examined the raw data, content was all image except for a one-line "to be removed" at the bottom. Problem is that the same one-liner appears on some emails that I want to see. I couldn't even use the domain of that address because it's nothing special.

So... is there a way?
Back to top
View users profile Send private message
rogerw

Major
Major
Premium Member
Premium Member


Joined: May 11, 2003
Posts: 858
Location: USA

PostPosted: Sun Jun 06, 2004 1:16 pm    Post subject:
Reply with quote

Look as the raw source of the email in the preview window.

Emails with images that are embedded have a multipart format and one of the parts will have a Content-Type: of image, gif, jpeg, etc.

Many emails just have html links to images out on web sites. Those will have Html tags for "img src = ".

You need to build filters that recognize these tricks.

Gary's filters might give a leg-up on writing such a filter (but I don't know for sure, as I've not looked at them in ages). They also haven't been actively updated/corrected in over a year. I know you know of them and where to find them, but for the benefit of others, Gary's sample filters are here: http://www.w5hq.com/MailWasher/
Back to top
View users profile Send private message
Eisenson

Corporal
Corporal
Premium Member
Premium Member


Joined: May 22, 2004
Posts: 59
Location: USA

PostPosted: Sun Jun 06, 2004 1:46 pm    Post subject:
Reply with quote

If DNS blacklist or FirstAlert don't catch it, I think these are just doomed to trickle in. There doesn't seem to be a way to differentiate between a legit and illegitimate "img src ="

MWP's smart, but probably can't be told how to tell whether an image is a requested product sheet or a porn-o-gram.

_________________
Perfection is sometimes sufficient...
Back to top
View users profile Send private message
rogerw

Major
Major
Premium Member
Premium Member


Joined: May 11, 2003
Posts: 858
Location: USA

PostPosted: Sun Jun 06, 2004 1:55 pm    Post subject:
Reply with quote

Well, that's why the cascade of various tools (in the specific order) are provided.

Friends list trumps all, so images from friends are OK. If you then construct a filter to trap all other images, then once you build your friends list up - any "img src ="'s you get probably aren't in a 'good' email.

You'll note, too, that many web references in spam are pretty bizarre. There're often not "http://www.server.com/...." - but more like "http://eats_your_lunch.hubba_hubba.biz/...". You could trap on any web references that don't begin as "http://www" to get a feel for how that'll help.
Back to top
View users profile Send private message
AlphaCentauri

Captain
Captain



Joined: Nov 20, 2003
Posts: 302
Location: USA

PostPosted: Tue Jun 08, 2004 12:28 pm    Post subject:
Reply with quote

Lots of firms get URL's that don't include the www nowadays. It's considered a "premium" web address.

My very last filter is for emails that only have an image source and an href. It isn't very specific, and it's a different color because I do have to look at the subject lines, but unfortunately there are lots of spams that don't trigger anything else.


[enabled],image,image,16777088,AND,Body,containsRE,"img src|<IMG src=|<IMG id=",Body,contains,"a href"
Back to top
View users profile Send private message
Ikeb

General
General
Premium Member
Premium Member


Joined: Apr 20, 2003
Posts: 3555
Location: Canada

PostPosted: Tue Jun 08, 2004 1:57 pm    Post subject:
Reply with quote

But your filter doesn't distinguish between a single image / link reference and multiple image / link references. Trouble is that many legit emails use image references as well as link references (but USUALLY not a single one, and certainly not with anything but the image). Building a filter to look for a msg with only a single image, and nothing but the image is somewhat more challenging I'm sure.
_________________
I like SPAM ... on my sandwich!
Back to top
View users profile Send private message Send email
AlphaCentauri

Captain
Captain



Joined: Nov 20, 2003
Posts: 302
Location: USA

PostPosted: Tue Jun 08, 2004 2:13 pm    Post subject:
Reply with quote

That's why it's my lowest priority filter. Most individuals include the photo instead of linking to it. Otherwise it's pretty broad and will trigger on most commercial emails.
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       Computer Cops Forum Index -> Mailwasher - Troubleshooting / General All times are GMT - 5 Hours
Page 1 of 1

 
 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops