public inbox for overseers@sourceware.org
 help / color / mirror / Atom feed
* [SlashZot <dj@delorie.com>] Spambot Poisoner
  2000-12-30  6:08 [SlashZot <dj@delorie.com>] Spambot Poisoner Tom Tromey
@ 2000-11-23 10:57 ` Tom Tromey
  2000-12-30  6:08 ` Jason Molenda
  2000-12-30  6:08 ` Andrew Cagney
  2 siblings, 0 replies; 6+ messages in thread
From: Tom Tromey @ 2000-11-23 10:57 UTC (permalink / raw)
  To: Overseers List

Anybody see this?
The site was down when I tried to connect.

I wonder if it would be easier to simply reject spambots.  It seems
like if this program is to work it would have to be able to detect
them.

Tom
------- Start of forwarded message -------
Date: Thu, 23 Nov 2000 13:00:10 -0500
Message-Id: <200011231800.NAA25687@delorie.com>
To: slashzot@delorie.com
From: SlashZot <dj@delorie.com>
Subject: Spambot Poisoner
Reply-To: slashzot@delorie.com
Content-Type: text

Spambot Poisoner

[1]halfelven writes: "[2]Sugarplum, the anti-spambot fighting
machine, is out! Quoting from their website: Sugarplum is an
automated spam-poisoner. Its purpose is to feed realistic and
enticing, but totally useless data to wandering spam-bots
such as EmailSiphon, Cherry Picker, etc. The idea is to so
contaminate spammers' databases as to require that they be
discarded, or at least that all data retrieved from your site
(including actual email addresses) be removed." I've seen
this sort of thing before, but I just figured it's a fun
thing to chat about on a holiday. It would be cool to put
this on Slashdot some time: I bet I'm not the only Slashdot
reader whose email address has been slurped.

    <URL: http://slashdot.org/article.pl?sid=00/11/23/162232 >
[1] <REF: mailto:florin@linuxstart.com >
[2] <REF: http://www.devin.com/sugarplum/ >


This is an automated posting to slashzot@delorie.com
See http://www.delorie.com/listserv/ to be removed.

------- End of forwarded message -------

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [SlashZot <dj@delorie.com>] Spambot Poisoner
  2000-12-30  6:08 ` Jason Molenda
@ 2000-11-23 11:03   ` Jason Molenda
  0 siblings, 0 replies; 6+ messages in thread
From: Jason Molenda @ 2000-11-23 11:03 UTC (permalink / raw)
  To: Tom Tromey; +Cc: Overseers List

On Thu, Nov 23, 2000 at 12:05:54PM -0700, Tom Tromey wrote:

> I wonder if it would be easier to simply reject spambots.  It seems
> like if this program is to work it would have to be able to detect
> them.


I have some stuff in the /www/conf/httpd.conf to attempt this.  There
is documentation about where I got the regexps.

Most tarpit style things work by having a link at the bottom of a
page to the cgi-bin script; the cgi-bin script (masquerading as
static content) serves up endless series of invalid e-mail addresses.

Unless great advances have been made, detecting a spambot is pretty
tough.  All you've got to work with are the user-agent headers provided
by the web client, and it's trivial for a spambot author to copy an
IE user-agent header and send that to the server.


But hey, who knows, maybe they're doing something even more clever.



J

PS- I thought the link on slashdot to the scanned in gutenberg
bible was far more interesting. :-)

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [SlashZot <dj@delorie.com>] Spambot Poisoner
  2000-12-30  6:08 ` Andrew Cagney
@ 2000-11-23 17:10   ` Andrew Cagney
  0 siblings, 0 replies; 6+ messages in thread
From: Andrew Cagney @ 2000-11-23 17:10 UTC (permalink / raw)
  To: tromey; +Cc: Overseers List

On http://sources.redhat.com/psim/ go to the bottom of the page and
click on the ``:'' in ``Mailing lists :''.

Hopefully you'll find your way back out by Monday :-)

	Andrew

^ permalink raw reply	[flat|nested] 6+ messages in thread

* [SlashZot <dj@delorie.com>] Spambot Poisoner
@ 2000-12-30  6:08 Tom Tromey
  2000-11-23 10:57 ` Tom Tromey
                   ` (2 more replies)
  0 siblings, 3 replies; 6+ messages in thread
From: Tom Tromey @ 2000-12-30  6:08 UTC (permalink / raw)
  To: Overseers List

Anybody see this?
The site was down when I tried to connect.

I wonder if it would be easier to simply reject spambots.  It seems
like if this program is to work it would have to be able to detect
them.

Tom
------- Start of forwarded message -------
Date: Thu, 23 Nov 2000 13:00:10 -0500
Message-Id: <200011231800.NAA25687@delorie.com>
To: slashzot@delorie.com
From: SlashZot <dj@delorie.com>
Subject: Spambot Poisoner
Reply-To: slashzot@delorie.com
Content-Type: text

Spambot Poisoner

[1]halfelven writes: "[2]Sugarplum, the anti-spambot fighting
machine, is out! Quoting from their website: Sugarplum is an
automated spam-poisoner. Its purpose is to feed realistic and
enticing, but totally useless data to wandering spam-bots
such as EmailSiphon, Cherry Picker, etc. The idea is to so
contaminate spammers' databases as to require that they be
discarded, or at least that all data retrieved from your site
(including actual email addresses) be removed." I've seen
this sort of thing before, but I just figured it's a fun
thing to chat about on a holiday. It would be cool to put
this on Slashdot some time: I bet I'm not the only Slashdot
reader whose email address has been slurped.

    <URL: http://slashdot.org/article.pl?sid=00/11/23/162232 >
[1] <REF: mailto:florin@linuxstart.com >
[2] <REF: http://www.devin.com/sugarplum/ >


This is an automated posting to slashzot@delorie.com
See http://www.delorie.com/listserv/ to be removed.

------- End of forwarded message -------

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [SlashZot <dj@delorie.com>] Spambot Poisoner
  2000-12-30  6:08 [SlashZot <dj@delorie.com>] Spambot Poisoner Tom Tromey
  2000-11-23 10:57 ` Tom Tromey
@ 2000-12-30  6:08 ` Jason Molenda
  2000-11-23 11:03   ` Jason Molenda
  2000-12-30  6:08 ` Andrew Cagney
  2 siblings, 1 reply; 6+ messages in thread
From: Jason Molenda @ 2000-12-30  6:08 UTC (permalink / raw)
  To: Tom Tromey; +Cc: Overseers List

On Thu, Nov 23, 2000 at 12:05:54PM -0700, Tom Tromey wrote:

> I wonder if it would be easier to simply reject spambots.  It seems
> like if this program is to work it would have to be able to detect
> them.


I have some stuff in the /www/conf/httpd.conf to attempt this.  There
is documentation about where I got the regexps.

Most tarpit style things work by having a link at the bottom of a
page to the cgi-bin script; the cgi-bin script (masquerading as
static content) serves up endless series of invalid e-mail addresses.

Unless great advances have been made, detecting a spambot is pretty
tough.  All you've got to work with are the user-agent headers provided
by the web client, and it's trivial for a spambot author to copy an
IE user-agent header and send that to the server.


But hey, who knows, maybe they're doing something even more clever.



J

PS- I thought the link on slashdot to the scanned in gutenberg
bible was far more interesting. :-)

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [SlashZot <dj@delorie.com>] Spambot Poisoner
  2000-12-30  6:08 [SlashZot <dj@delorie.com>] Spambot Poisoner Tom Tromey
  2000-11-23 10:57 ` Tom Tromey
  2000-12-30  6:08 ` Jason Molenda
@ 2000-12-30  6:08 ` Andrew Cagney
  2000-11-23 17:10   ` Andrew Cagney
  2 siblings, 1 reply; 6+ messages in thread
From: Andrew Cagney @ 2000-12-30  6:08 UTC (permalink / raw)
  To: tromey; +Cc: Overseers List

On http://sources.redhat.com/psim/ go to the bottom of the page and
click on the ``:'' in ``Mailing lists :''.

Hopefully you'll find your way back out by Monday :-)

	Andrew

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2000-12-30  6:08 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2000-12-30  6:08 [SlashZot <dj@delorie.com>] Spambot Poisoner Tom Tromey
2000-11-23 10:57 ` Tom Tromey
2000-12-30  6:08 ` Jason Molenda
2000-11-23 11:03   ` Jason Molenda
2000-12-30  6:08 ` Andrew Cagney
2000-11-23 17:10   ` Andrew Cagney

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).