<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0" 
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
    xmlns:admin="http://webns.net/mvcb/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:content="http://purl.org/rss/1.0/modules/content/">

  <channel>
    <title>Gadgetopia: Spam</title>
    <link>http://www.gadgetopia.com/Categories/Spam.html</link>
    <description>This is a sub-feed of the main Gadgetopia RSS feed. This feed displays entries from the "Spam" category.  The main Gadgetopia feed is available at http://www.gadgetopia.com/index.xml.</description>
    <dc:language>en-us</dc:language>
    <dc:creator>deane@deanebarker.net</dc:creator>
    <dc:rights>Copyright 2008</dc:rights>
    <dc:date>2008-07-16T05:58:01-06:00</dc:date>
    <admin:generatorAgent rdf:resource="http://www.movabletype.org/?v=3.35" />
    <admin:errorReportsTo rdf:resource="mailto:deane@deanebarker.net"/>
    <sy:updatePeriod>hourly</sy:updatePeriod>
    <sy:updateFrequency>1</sy:updateFrequency>
    <sy:updateBase>2000-01-01T12:00+00:00</sy:updateBase>

    <item>
      <title>Craigslist Phone Verification</title>
      <link>http://gadgetopia.com/post/6473</link>
      <description><![CDATA[<p><a title="Craigslist phone verification system - Black Hat Forum" href="http://www.blackhatworld.com/blackhat-seo/craigslist-other-classified-ads-sites/13487-craigslist-phone-verification-system.html">Craigslist phone verification system</a>: Craigslist has implemented perhaps the absolute killer app in terms of anti-spam solutions:</p>

<blockquote>
  <p>[&#8230;] Craigs*list has implemented a phone verification system in certain categories to reduce SPAM content. When you attempt to make a post, it asks for you to verify yourself by typing in a viable phone number. It automatically calls it and repeats a verification code which you must then enter for your post to go live. If your post gets flagged, the phone number you verified with will be blacklisted. </p>
</blockquote>

<p>So while email address are cheap and disposable, phone numbers are not, and every spam post is bound to blacklist a phone number.</p>

<p>The link goes to a forum newsgroup thread where a bunch of spammers talk about it and conclude that they&#8217;re more-or-less screwed.  There&#8217;s a lot of talk about getting cheap VOIP numbers, but the closest workable idea they found was to go to public places and use pay phones.</p>

<p>This presumably has the added benefit of binding a set of spam postings to the same phone number.  So, if one of them gets flagged as spam, you could find everything else verified from that number and pull them down at the same time.</p>

<p>Via <a href="http://reddit/">Reddit</a></p>
]]></description>
      <guid isPermaLink="false">6473@http://gadgetopia.com/</guid>
      <content:encoded><![CDATA[<p><a title="Craigslist phone verification system - Black Hat Forum" href="http://www.blackhatworld.com/blackhat-seo/craigslist-other-classified-ads-sites/13487-craigslist-phone-verification-system.html">Craigslist phone verification system</a>: Craigslist has implemented perhaps the absolute killer app in terms of anti-spam solutions:</p>

<blockquote>
  <p>[&#8230;] Craigs*list has implemented a phone verification system in certain categories to reduce SPAM content. When you attempt to make a post, it asks for you to verify yourself by typing in a viable phone number. It automatically calls it and repeats a verification code which you must then enter for your post to go live. If your post gets flagged, the phone number you verified with will be blacklisted. </p>
</blockquote>

<p>So while email address are cheap and disposable, phone numbers are not, and every spam post is bound to blacklist a phone number.</p>

<p>The link goes to a forum newsgroup thread where a bunch of spammers talk about it and conclude that they&#8217;re more-or-less screwed.  There&#8217;s a lot of talk about getting cheap VOIP numbers, but the closest workable idea they found was to go to public places and use pay phones.</p>

<p>This presumably has the added benefit of binding a set of spam postings to the same phone number.  So, if one of them gets flagged as spam, you could find everything else verified from that number and pull them down at the same time.</p>

<p>Via <a href="http://reddit/">Reddit</a></p>
]]></content:encoded>
      <dc:subject>Spam</dc:subject>
      <dc:date>2008-07-16T05:58:01-06:00</dc:date>
    </item>
    <item>
      <title>Richard can help your comment spam problem...</title>
      <link>http://gadgetopia.com/post/6129</link>
      <description><![CDATA[<p>I found this comment on one of my client&#8217;s blogs today.</p>

<blockquote>
  <p>hello , my name is Richard and I know you get a lot of spammy comments ,  I can help you with this problem . I know a lot of spammers and I will ask them not to post on your site. It will reduce the volume of spam by 30-50% .In return Id like to ask you to put a link to my site on the index page of your site.</p>
</blockquote>

<p>Did you hear that?  <em>He&#8217;ll tell the spammers to stop.</em>  What a gift.</p>
]]></description>
      <guid isPermaLink="false">6129@http://gadgetopia.com/</guid>
      <content:encoded><![CDATA[<p>I found this comment on one of my client&#8217;s blogs today.</p>

<blockquote>
  <p>hello , my name is Richard and I know you get a lot of spammy comments ,  I can help you with this problem . I know a lot of spammers and I will ask them not to post on your site. It will reduce the volume of spam by 30-50% .In return Id like to ask you to put a link to my site on the index page of your site.</p>
</blockquote>

<p>Did you hear that?  <em>He&#8217;ll tell the spammers to stop.</em>  What a gift.</p>
]]></content:encoded>
      <dc:subject>Spam</dc:subject>
      <dc:date>2007-10-22T15:11:12-06:00</dc:date>
    </item>
    <item>
      <title>Big Medium and Comment Spam</title>
      <link>http://gadgetopia.com/post/5830</link>
      <description><![CDATA[<p><a title="Seven Habits of Highly Effective Spambot Hunters (Global Moxie)" href="http://beta.bigmedium.com/blog/stop-comment-spam-spambots.shtml">Seven Habits of Highly Effective Spambot Hunters</a>: <a href="http://www.gadgetopia.com/post/3606">Josh Clark</a> is doing some crazy fun stuff to counter comment spammers on <a href="http://www.globalmoxie.com/moxie/bigmedium/index.shtml">Big Medium</a>.  I love it.</p>

<blockquote>
  <p>Big Medium counters this by covering its tracks, never using the same field names twice. Every time you visit the page, all of the field names change. The field names are MD5 hashes of the page's slug name, its database creation date and a server secret. A semi-obfuscated timestamp is mashed with this field name, creating a 50-digit field name that changes every second.</p>
  
  <p>If the correct combination of field names are not received, the form submission is discarded.</p>
</blockquote>
]]></description>
      <guid isPermaLink="false">5830@http://gadgetopia.com/</guid>
      <content:encoded><![CDATA[<p><a title="Seven Habits of Highly Effective Spambot Hunters (Global Moxie)" href="http://beta.bigmedium.com/blog/stop-comment-spam-spambots.shtml">Seven Habits of Highly Effective Spambot Hunters</a>: <a href="http://www.gadgetopia.com/post/3606">Josh Clark</a> is doing some crazy fun stuff to counter comment spammers on <a href="http://www.globalmoxie.com/moxie/bigmedium/index.shtml">Big Medium</a>.  I love it.</p>

<blockquote>
  <p>Big Medium counters this by covering its tracks, never using the same field names twice. Every time you visit the page, all of the field names change. The field names are MD5 hashes of the page's slug name, its database creation date and a server secret. A semi-obfuscated timestamp is mashed with this field name, creating a 50-digit field name that changes every second.</p>
  
  <p>If the correct combination of field names are not received, the form submission is discarded.</p>
</blockquote>
]]></content:encoded>
      <dc:subject>Spam</dc:subject>
      <dc:date>2007-03-30T14:07:03-06:00</dc:date>
    </item>
    <item>
      <title>The Fight Over the Word &quot;Spam&quot;</title>
      <link>http://gadgetopia.com/post/5576</link>
      <description><![CDATA[<p><a title="EU Rejects Spam Maker's Trademark Bid - International Business Times -" href="http://www.ibtimes.com/articles/20061011/techbits-spam.htm">EU Rejects Spam Maker's Trademark Bid</a>: This phenomenon is interesting.  The company that makes Spam has essentially lost their name -- it was stolen by the rest of the world and there's nothing they can do about it.  Even if they claim a legal victory, it's not going to help them.  They're never getting the word back in any meaningful sense.</p>

<blockquote>
  <p>The producer of the canned pork product Spam has lost a bid to claim the word as a trademark for unsolicited e-mails. EU trademark officials rejected Hormel Foods Corp.'s appeal, dealing the company another setback in its struggle to prevent software companies from using the word "spam" in their products, a practice it argued was diluting its brand name.</p>
</blockquote>
]]></description>
      <guid isPermaLink="false">5576@http://gadgetopia.com/</guid>
      <content:encoded><![CDATA[<p><a title="EU Rejects Spam Maker's Trademark Bid - International Business Times -" href="http://www.ibtimes.com/articles/20061011/techbits-spam.htm">EU Rejects Spam Maker's Trademark Bid</a>: This phenomenon is interesting.  The company that makes Spam has essentially lost their name -- it was stolen by the rest of the world and there's nothing they can do about it.  Even if they claim a legal victory, it's not going to help them.  They're never getting the word back in any meaningful sense.</p>

<blockquote>
  <p>The producer of the canned pork product Spam has lost a bid to claim the word as a trademark for unsolicited e-mails. EU trademark officials rejected Hormel Foods Corp.'s appeal, dealing the company another setback in its struggle to prevent software companies from using the word "spam" in their products, a practice it argued was diluting its brand name.</p>
</blockquote>
]]></content:encoded>
      <dc:subject>Spam</dc:subject>
      <dc:date>2006-10-12T12:14:08-06:00</dc:date>
    </item>
    <item>
      <title>Subliminal Spam</title>
      <link>http://gadgetopia.com/post/5513</link>
      <description><![CDATA[<p><a title="John Graham-Cumming: Subliminal advertising in spam?" href="http://www.jgc.org/blog/2006/09/subliminal-advertising-in-spam.html?rf=23m">Subliminal advertising in spam?</a>: I followed this link, and I think I bought 100 shares.</p>

<blockquote>
  <p>The spam contains an animated GIF with four frames. One of the frames (which contains the actual spam message) remains visible for 17 seconds. The other three frames are displayed for 10ms or 40ms, and each of those contains a little random noise and the word BUY in random positions.</p>
</blockquote>
]]></description>
      <guid isPermaLink="false">5513@http://gadgetopia.com/</guid>
      <content:encoded><![CDATA[<p><a title="John Graham-Cumming: Subliminal advertising in spam?" href="http://www.jgc.org/blog/2006/09/subliminal-advertising-in-spam.html?rf=23m">Subliminal advertising in spam?</a>: I followed this link, and I think I bought 100 shares.</p>

<blockquote>
  <p>The spam contains an animated GIF with four frames. One of the frames (which contains the actual spam message) remains visible for 17 seconds. The other three frames are displayed for 10ms or 40ms, and each of those contains a little random noise and the word BUY in random positions.</p>
</blockquote>
]]></content:encoded>
      <dc:subject>Spam</dc:subject>
      <dc:date>2006-09-06T07:18:21-06:00</dc:date>
    </item>
    <item>
      <title>Comment Spam Theories</title>
      <link>http://gadgetopia.com/post/5318</link>
      <description><![CDATA[<p><a title="Boing Boing: Reader feedback on bizarre no-link spam" href="http://www.boingboing.net/2006/05/30/reader_feedback_on_b.html">Reader feedback on bizarre no-link spam</a>: A while back, Mark over at Boing Boing <a href="http://www.boingboing.net/2006/05/23/wtf_is_going_on_with.html">posted about</a> some odd spam comments he'd seen that had no URL.  If there's no URL, why post the spam?  In the last week, several readers have approached him with theories.  Some of them are interesting.</p>

<blockquote>
  <p>I've found that many times innocuous-looking comments with no url are used to sneak past sophisticated blog-spamfilters [...]. Many of these filters give a 'karmic boost' to commenters who already have one approved comment. By not posting any links at all, they have a better chance of getting their foot in the door [...]</p>
  
  <p>[...] If the spammer [...] can attribute these numbers to a particular blog or email address, they can see which sites are 'hot ones'.</p>
  
  <p>I've long suspected that spam is (or could be) used by spies or (more likely) terrorist cells. There is so much NOISE in email, it's the perfect place to hide SIGNAL. </p>
</blockquote>

<p>Thanks to <a href="http://www.gadgetopia.com/post/5238">Akismet</a> we're almost spam-free these days.</p>
]]></description>
      <guid isPermaLink="false">5318@http://gadgetopia.com/</guid>
      <content:encoded><![CDATA[<p><a title="Boing Boing: Reader feedback on bizarre no-link spam" href="http://www.boingboing.net/2006/05/30/reader_feedback_on_b.html">Reader feedback on bizarre no-link spam</a>: A while back, Mark over at Boing Boing <a href="http://www.boingboing.net/2006/05/23/wtf_is_going_on_with.html">posted about</a> some odd spam comments he'd seen that had no URL.  If there's no URL, why post the spam?  In the last week, several readers have approached him with theories.  Some of them are interesting.</p>

<blockquote>
  <p>I've found that many times innocuous-looking comments with no url are used to sneak past sophisticated blog-spamfilters [...]. Many of these filters give a 'karmic boost' to commenters who already have one approved comment. By not posting any links at all, they have a better chance of getting their foot in the door [...]</p>
  
  <p>[...] If the spammer [...] can attribute these numbers to a particular blog or email address, they can see which sites are 'hot ones'.</p>
  
  <p>I've long suspected that spam is (or could be) used by spies or (more likely) terrorist cells. There is so much NOISE in email, it's the perfect place to hide SIGNAL. </p>
</blockquote>

<p>Thanks to <a href="http://www.gadgetopia.com/post/5238">Akismet</a> we're almost spam-free these days.</p>
]]></content:encoded>
      <dc:subject>Spam</dc:subject>
      <dc:date>2006-05-30T23:11:00-06:00</dc:date>
    </item>
    <item>
      <title>Darn Spammers Anyways</title>
      <link>http://gadgetopia.com/post/5251</link>
      <description><![CDATA[<p>So, a few of us here at work got a spam today with this as part of the body:</p>

<blockquote>
  <p>Your credit doesn't matter to us</p>
</blockquote>

<p>We believe this should have been caught by our spam filter.  However, if you copy the text and paste it into notepad, it come out like this:</p>

<blockquote>
  <p>Your cr y ed y it doesn't matter to us</p>
</blockquote>

<p>How the heck are they doing that?  How am I or any other software supposed to stop that?  We are using Mailsweeper and it isn't doing a very good job.  What is everybody here using for their corporate spam filter solution?  And yes, we are running Exchange.</p>
]]></description>
      <guid isPermaLink="false">5251@http://gadgetopia.com/</guid>
      <content:encoded><![CDATA[<p>So, a few of us here at work got a spam today with this as part of the body:</p>

<blockquote>
  <p>Your credit doesn't matter to us</p>
</blockquote>

<p>We believe this should have been caught by our spam filter.  However, if you copy the text and paste it into notepad, it come out like this:</p>

<blockquote>
  <p>Your cr y ed y it doesn't matter to us</p>
</blockquote>

<p>How the heck are they doing that?  How am I or any other software supposed to stop that?  We are using Mailsweeper and it isn't doing a very good job.  What is everybody here using for their corporate spam filter solution?  And yes, we are running Exchange.</p>
]]></content:encoded>
      <dc:subject>Spam</dc:subject>
      <dc:date>2006-04-26T10:09:24-06:00</dc:date>
    </item>
    <item>
      <title>Akismet</title>
      <link>http://gadgetopia.com/post/5238</link>
      <description><![CDATA[<p>Once again, <a href="http://www.swoofware.com">Matt Smith</a> has come and rescued me from spammers.  A couple of weeks ago, I was at <a href="http://www.gadgetopia.com/post/5177">my wit's end</a>.  Some commentors recommended <a href="http://akismet.com/">Akismet</a>, but I thought it was WordPress-only.  Then Matt emailed me to tell me there was a <a href="http://akismet.com/blog/2006/04/for-mt/">Movable Type port</a>.  Given <a href="http://www.gadgetopia.com/post/4465">Matt's track record</a> of helping me banish spam, I decided to try it.</p>

<p>It's not perfect, but it's very, very, very good.  Spams that get through to the site have dropped 97%.  I'll get maybe one per day now.</p>

<p>I don't even know how Akismet works.  I think it's a Web service of some kind, but -- to be honest -- I don't much care.  I just dropped the directory into my plugins, applied for and received a <a href="http://www.wordpres.com">wordpress.com</a> key, and spam went bye-bye.</p>

<p>They ask that if you make over $500 a month from your blog (we do), then you should pay $5 a month for the API key.  Worth every penny.</p>

<p>So, thanks Matt.  And thanks to <a href="http://matt.wordpress.com/">the other Matt</a> that created Akismet in the first place.  Thanks to them, the <a href="http://www.gadgetopia.com/comments.xml">Gadgetopia comments feed</a> isn't such a bad place to hang out anymore.</p>
]]></description>
      <guid isPermaLink="false">5238@http://gadgetopia.com/</guid>
      <content:encoded><![CDATA[<p>Once again, <a href="http://www.swoofware.com">Matt Smith</a> has come and rescued me from spammers.  A couple of weeks ago, I was at <a href="http://www.gadgetopia.com/post/5177">my wit's end</a>.  Some commentors recommended <a href="http://akismet.com/">Akismet</a>, but I thought it was WordPress-only.  Then Matt emailed me to tell me there was a <a href="http://akismet.com/blog/2006/04/for-mt/">Movable Type port</a>.  Given <a href="http://www.gadgetopia.com/post/4465">Matt's track record</a> of helping me banish spam, I decided to try it.</p>

<p>It's not perfect, but it's very, very, very good.  Spams that get through to the site have dropped 97%.  I'll get maybe one per day now.</p>

<p>I don't even know how Akismet works.  I think it's a Web service of some kind, but -- to be honest -- I don't much care.  I just dropped the directory into my plugins, applied for and received a <a href="http://www.wordpres.com">wordpress.com</a> key, and spam went bye-bye.</p>

<p>They ask that if you make over $500 a month from your blog (we do), then you should pay $5 a month for the API key.  Worth every penny.</p>

<p>So, thanks Matt.  And thanks to <a href="http://matt.wordpress.com/">the other Matt</a> that created Akismet in the first place.  Thanks to them, the <a href="http://www.gadgetopia.com/comments.xml">Gadgetopia comments feed</a> isn't such a bad place to hang out anymore.</p>
]]></content:encoded>
      <dc:subject>Spam</dc:subject>
      <dc:date>2006-04-20T23:44:36-06:00</dc:date>
    </item>
    <item>
      <title>My Planned Comment Spam Solution</title>
      <link>http://gadgetopia.com/post/5177</link>
      <description><![CDATA[<p>Well, comment spam has finally done me in.</p>

<p>A big new wave launched about a week ago, and we're getting spammed about once every 2 minutes, 24 hours a day.  I have to manually delete over 100 comment spams a day in three or four "shifts" at the MT interface.</p>

<p>For every one that gets on the site, nine or ten are caught, but the bastards still manage to get dozens on the site throughout the day, where they sit for hours.  The fact that these idiots are getting some value, however small, is just pissing me off.</p>

<p>I'm going to install <a href="http://projects.heavymeta.org/HMPassphrase/wiki/Description">HMPassphrase</a> over the weekend.  This is the Movable Type version of <a href="http://www.meyerweb.com/eric/tools/wordpress/wp-gatekeeper.html">WP Gatekeeper</a>, which <a href="http://www.gadgetopia.com/post/3908">I posted about last year</a> after encountering it on <a href="http://joseph.randomnetworks.com/">Joseph Scott's site</a>.  It asks you a simple question, to which you must provide the correct answer before it will accept your comment ("What color is the sky?", "What color is an orange?", "What shape is a wheel?", etc.)</p>

<p>I hate to do this, but I'm just sick of it.</p>
]]></description>
      <guid isPermaLink="false">5177@http://gadgetopia.com/</guid>
      <content:encoded><![CDATA[<p>Well, comment spam has finally done me in.</p>

<p>A big new wave launched about a week ago, and we're getting spammed about once every 2 minutes, 24 hours a day.  I have to manually delete over 100 comment spams a day in three or four "shifts" at the MT interface.</p>

<p>For every one that gets on the site, nine or ten are caught, but the bastards still manage to get dozens on the site throughout the day, where they sit for hours.  The fact that these idiots are getting some value, however small, is just pissing me off.</p>

<p>I'm going to install <a href="http://projects.heavymeta.org/HMPassphrase/wiki/Description">HMPassphrase</a> over the weekend.  This is the Movable Type version of <a href="http://www.meyerweb.com/eric/tools/wordpress/wp-gatekeeper.html">WP Gatekeeper</a>, which <a href="http://www.gadgetopia.com/post/3908">I posted about last year</a> after encountering it on <a href="http://joseph.randomnetworks.com/">Joseph Scott's site</a>.  It asks you a simple question, to which you must provide the correct answer before it will accept your comment ("What color is the sky?", "What color is an orange?", "What shape is a wheel?", etc.)</p>

<p>I hate to do this, but I'm just sick of it.</p>
]]></content:encoded>
      <dc:subject>Spam</dc:subject>
      <dc:date>2006-03-31T06:47:48-06:00</dc:date>
    </item>
    <item>
      <title>Comment Spam</title>
      <link>http://gadgetopia.com/post/4999</link>
      <description><![CDATA[<p>If it's not obvious by now, I've tightened up the spam filtering.  We're getting hammered by comment spam this last week or so -- some big new round of scripts is going off.</p>

<p>I'm sorry if your comment is delayed, but it's either that or <a href="http://www.sixapart.com/typekey/">TypeKey</a>, which I don't really want to do either.  This sucks.  I have to find a solution of some kind -- I'm open to suggestions.</p>
]]></description>
      <guid isPermaLink="false">4999@http://gadgetopia.com/</guid>
      <content:encoded><![CDATA[<p>If it's not obvious by now, I've tightened up the spam filtering.  We're getting hammered by comment spam this last week or so -- some big new round of scripts is going off.</p>

<p>I'm sorry if your comment is delayed, but it's either that or <a href="http://www.sixapart.com/typekey/">TypeKey</a>, which I don't really want to do either.  This sucks.  I have to find a solution of some kind -- I'm open to suggestions.</p>
]]></content:encoded>
      <dc:subject>Spam</dc:subject>
      <dc:date>2006-02-10T17:27:21-06:00</dc:date>
    </item>
    <item>
      <title>AOL&apos;s Spam Bribery Campaign</title>
      <link>http://gadgetopia.com/post/4985</link>
      <description><![CDATA[<p><a title="USATODAY.com - AOL to charge fee as way to cut spam" href="http://www.usatoday.com/tech/news/computersecurity/2006-02-05-aol-yahoo-email_x.htm">AOL to charge fee as way to cut spam</a>: Marketers can now pay America Online to ensure their messages are delivered and not flagged as spam.  How is this not bribery?</p>

<blockquote>
  <p>The certified e-mail system would require advertisers to pay $2 to $3 per 1,000 messages. The plan is optional, though AOL and its tech partner, Goodmail Systems, cannot guarantee that all non-certified e-mail with Web links and images will be delivered.</p>
</blockquote>

<p><em>Nothing</em> has changed except:</p>

<ol>
<li>AOL is making money hand over fist.</li>
<li>Marketers have a nice, handy way around spam filters at AOL.</li>
</ol>

<p>This will do <em>nothing</em> to dissaude hardcore spammers.  Zero.  Nada. Zilch.  They're no worse off than they were before, so why should they change?  The  economics of spam are the same for them.  This just means there's a new class of spammer: those that have paid AOL for the right to bypass the filters.</p>

<p>This is crap.</p>
]]></description>
      <guid isPermaLink="false">4985@http://gadgetopia.com/</guid>
      <content:encoded><![CDATA[<p><a title="USATODAY.com - AOL to charge fee as way to cut spam" href="http://www.usatoday.com/tech/news/computersecurity/2006-02-05-aol-yahoo-email_x.htm">AOL to charge fee as way to cut spam</a>: Marketers can now pay America Online to ensure their messages are delivered and not flagged as spam.  How is this not bribery?</p>

<blockquote>
  <p>The certified e-mail system would require advertisers to pay $2 to $3 per 1,000 messages. The plan is optional, though AOL and its tech partner, Goodmail Systems, cannot guarantee that all non-certified e-mail with Web links and images will be delivered.</p>
</blockquote>

<p><em>Nothing</em> has changed except:</p>

<ol>
<li>AOL is making money hand over fist.</li>
<li>Marketers have a nice, handy way around spam filters at AOL.</li>
</ol>

<p>This will do <em>nothing</em> to dissaude hardcore spammers.  Zero.  Nada. Zilch.  They're no worse off than they were before, so why should they change?  The  economics of spam are the same for them.  This just means there's a new class of spammer: those that have paid AOL for the right to bypass the filters.</p>

<p>This is crap.</p>
]]></content:encoded>
      <dc:subject>Spam</dc:subject>
      <dc:date>2006-02-06T15:36:32-06:00</dc:date>
    </item>
    <item>
      <title>Yahoo Calendar Spamming</title>
      <link>http://gadgetopia.com/post/4875</link>
      <description><![CDATA[<p>Get this for a new spam angle --</p>

<p>I had shared my Yahoo Calendar with my wife, so she could add events.  Somehow I must have hosed it up, because some idiot has managed to add events to my calendar so that I'm amply remind that I need to join his Party Poker site <em>every single day</em>.</p>

<p>These aren't on my calendar -- I have the bonehead's username and I've turned it into Yahoo.  But I checked my settings again, and I only allowed "Trusted Friends" to view and add events to my calendar.</p>

<p>No idea how it happened, but it just proves that spammers are bleeping weasels.</p>
]]></description>
      <guid isPermaLink="false">4875@http://gadgetopia.com/</guid>
      <content:encoded><![CDATA[<p>Get this for a new spam angle --</p>

<p>I had shared my Yahoo Calendar with my wife, so she could add events.  Somehow I must have hosed it up, because some idiot has managed to add events to my calendar so that I'm amply remind that I need to join his Party Poker site <em>every single day</em>.</p>

<p>These aren't on my calendar -- I have the bonehead's username and I've turned it into Yahoo.  But I checked my settings again, and I only allowed "Trusted Friends" to view and add events to my calendar.</p>

<p>No idea how it happened, but it just proves that spammers are bleeping weasels.</p>
]]></content:encoded>
      <dc:subject>Spam</dc:subject>
      <dc:date>2006-01-10T09:35:16-06:00</dc:date>
    </item>
    <item>
      <title>Random Subject...Or Not</title>
      <link>http://gadgetopia.com/post/4476</link>
      <description><![CDATA[<p>I found this subject line in my spam trap this morning:</p>

<blockquote>
  <p>Get your site seen by 100K+ now-%RND_SUBJ</p>
</blockquote>

<p>Apparently he screwed up the "random subject" parameter in his spam generator.</p>
]]></description>
      <guid isPermaLink="false">4476@http://gadgetopia.com/</guid>
      <content:encoded><![CDATA[<p>I found this subject line in my spam trap this morning:</p>

<blockquote>
  <p>Get your site seen by 100K+ now-%RND_SUBJ</p>
</blockquote>

<p>Apparently he screwed up the "random subject" parameter in his spam generator.</p>
]]></content:encoded>
      <dc:subject>Spam</dc:subject>
      <dc:date>2005-10-13T09:45:22-06:00</dc:date>
    </item>
    <item>
      <title>SpamStopsHere</title>
      <link>http://gadgetopia.com/post/4465</link>
      <description><![CDATA[<p>Last week, I posted about <a href="http://www.gadgetopia.com/post/4440">installing SpamAssassin for Exchange</a>.  It was a simple install, and it worked pretty well.  I was getting a 50% filter rate right out of the box, and I was confident  I could get it up to 70% or so by cranking down the threshold.</p>

<p>In a comment to that post, <a href="http://www.swoofware.com/">Matt Smith</a> turned me on to <a href="http://www.spamstopshere.com">SpamStopsHere</a>, which is a filtering service.  I'm currently in the middle of a 30-day trial, but there's no going back: they have essentially turned off the spam faucet -- <em>completely</em>.</p>

<p>SpamStopsHere (SSHere) is the "nuclear option" for spam filtering.  You actually change all your MX records in DNS to send all inbound email to them first.  They filter it on their servers and only forward what's left over. (I shudder to think what kind of big iron they have running over there to process all that mail...)</p>

<p>SSHere gives you the five or six IP addresses from which they will connect to your server so you can lock it down to only accept email from those addresses.</p>

<p>(This is necessary because when some crafty spammers query DNS for your domain and find nothing but SSHere domain names, they try to get around it by just blindly sending the email to "mail.yourdomain.com" (Cowards!  Face the filters like men!).  Several hundred spams a day were getting around the system by doing this.  But by locking down my SMTP servers to accept only connections from SSHere addresses, there's effectively <em>no way</em> to get email into my network that hasn't been filtered.)</p>

<p>What this all means is that you never even see the spam -- your server only fields messages that have gotten through the SSHere filters.  And that ain't much, believe me.</p>

<p>They have six levels of filtering.  The first three catch the really easy stuff -- I just toss anything that pops on one of these filters.  I don't even send an NDR -- the email just disappears into the ether.</p>

<p>The second three filters are more fine-tuned.  For example, one of them simply filters out email from the 11 countries from which 90% of spam originates (China, Nigeria, etc. -- though you can allow certain countries to pass, if you have people there that send you legitimate email; or you could just whitelist one or two people).  For these three filters, I have the email forwarded to a special mailbox on my network, just in case there's a false positive (there hasn't been so far).</p>

<p>They have whitelists, blacklists, and custom filters.  Plus, you can filter out email with selected attachment extensions (.vbs, .exe, .scr, .bat, etc.).  On top of all that, you can pay extra and get anti-virus screening on all the email that passes through the system.</p>

<p>The result?  A <em>99% filter rate</em>, and not one complaint about a false positive.  (I count as "filtered" email that pops on the second group of filters and gets forwarded to my sandboxed email address.)</p>

<p>(Yes, 99% -- we get spammed like crazy over here.  I have three brokers who have had the same email addresses for eight years now -- and at least five of those years had the addresses in unencoded "mailto" links on a well-spidered Web site.)</p>

<p>What's great about having this done off-site is that my email server has hardly anything to do now.  It's fielding 1/20th of the email it was before (why not 1/100th? Because  it still receives emails flagged and sent to the sandboxed account.), and it doesn't even have to run them through SpamAssassin anymore.  It's almost idle.  Additionally, spam is a Bad Thing.  And anything that keeps Bad Things off my network is, by definition, a Good Thing.</p>

<p>Pricing is good: I'm paying $26 a month for one domain and 15 email addresses.  Worth every penny.</p>

<p>Another thing I appreciate: SSHere's Web site is full of great technical and support information.  This solution isn't for the faint of heart or people with a single email address, so they assume you know something about email when you come to check them out.  They discuss all <a href="http://www.spamstopshere.com/antispam_techdetails.aspx">the gory details of the DNS-based solution</a>, and <a href="http://www.spamstopshere.com/antispam_howitworks.aspx?RC=147994471">explain all their filters in graphic detail</a> so you have complete confidence in what they're proposing before you pull the trigger.</p>

<p>Ironically, this whole situation has made me a little...sad, really.  I'm obviously happy with the service, and I'll keep using it, but there's no gee-whiz factor to it.  I mean, there's no sense of accomplishment like when you set up your own spam filter and thwart the bad guys single-handedly.  I just changed a few DNS records, locked down an SMTP server, and that was it -- spam go bye bye.  Where's the sport?  The challenge?  The thrill of victory?</p>

<p>But [sigh], that's another post entirely...</p>

<p>(Note: SSHere has a referral program. But if you decide to use them, give them <a href="http://www.swoofware.com">Matt's name</a>, not mine.  He's responsible for bringing them to my attention, and I don't want anyone to think I'm shilling for something just to get free stuff.)</p>
]]></description>
      <guid isPermaLink="false">4465@http://gadgetopia.com/</guid>
      <content:encoded><![CDATA[<p>Last week, I posted about <a href="http://www.gadgetopia.com/post/4440">installing SpamAssassin for Exchange</a>.  It was a simple install, and it worked pretty well.  I was getting a 50% filter rate right out of the box, and I was confident  I could get it up to 70% or so by cranking down the threshold.</p>

<p>In a comment to that post, <a href="http://www.swoofware.com/">Matt Smith</a> turned me on to <a href="http://www.spamstopshere.com">SpamStopsHere</a>, which is a filtering service.  I'm currently in the middle of a 30-day trial, but there's no going back: they have essentially turned off the spam faucet -- <em>completely</em>.</p>

<p>SpamStopsHere (SSHere) is the "nuclear option" for spam filtering.  You actually change all your MX records in DNS to send all inbound email to them first.  They filter it on their servers and only forward what's left over. (I shudder to think what kind of big iron they have running over there to process all that mail...)</p>

<p>SSHere gives you the five or six IP addresses from which they will connect to your server so you can lock it down to only accept email from those addresses.</p>

<p>(This is necessary because when some crafty spammers query DNS for your domain and find nothing but SSHere domain names, they try to get around it by just blindly sending the email to "mail.yourdomain.com" (Cowards!  Face the filters like men!).  Several hundred spams a day were getting around the system by doing this.  But by locking down my SMTP servers to accept only connections from SSHere addresses, there's effectively <em>no way</em> to get email into my network that hasn't been filtered.)</p>

<p>What this all means is that you never even see the spam -- your server only fields messages that have gotten through the SSHere filters.  And that ain't much, believe me.</p>

<p>They have six levels of filtering.  The first three catch the really easy stuff -- I just toss anything that pops on one of these filters.  I don't even send an NDR -- the email just disappears into the ether.</p>

<p>The second three filters are more fine-tuned.  For example, one of them simply filters out email from the 11 countries from which 90% of spam originates (China, Nigeria, etc. -- though you can allow certain countries to pass, if you have people there that send you legitimate email; or you could just whitelist one or two people).  For these three filters, I have the email forwarded to a special mailbox on my network, just in case there's a false positive (there hasn't been so far).</p>

<p>They have whitelists, blacklists, and custom filters.  Plus, you can filter out email with selected attachment extensions (.vbs, .exe, .scr, .bat, etc.).  On top of all that, you can pay extra and get anti-virus screening on all the email that passes through the system.</p>

<p>The result?  A <em>99% filter rate</em>, and not one complaint about a false positive.  (I count as "filtered" email that pops on the second group of filters and gets forwarded to my sandboxed email address.)</p>

<p>(Yes, 99% -- we get spammed like crazy over here.  I have three brokers who have had the same email addresses for eight years now -- and at least five of those years had the addresses in unencoded "mailto" links on a well-spidered Web site.)</p>

<p>What's great about having this done off-site is that my email server has hardly anything to do now.  It's fielding 1/20th of the email it was before (why not 1/100th? Because  it still receives emails flagged and sent to the sandboxed account.), and it doesn't even have to run them through SpamAssassin anymore.  It's almost idle.  Additionally, spam is a Bad Thing.  And anything that keeps Bad Things off my network is, by definition, a Good Thing.</p>

<p>Pricing is good: I'm paying $26 a month for one domain and 15 email addresses.  Worth every penny.</p>

<p>Another thing I appreciate: SSHere's Web site is full of great technical and support information.  This solution isn't for the faint of heart or people with a single email address, so they assume you know something about email when you come to check them out.  They discuss all <a href="http://www.spamstopshere.com/antispam_techdetails.aspx">the gory details of the DNS-based solution</a>, and <a href="http://www.spamstopshere.com/antispam_howitworks.aspx?RC=147994471">explain all their filters in graphic detail</a> so you have complete confidence in what they're proposing before you pull the trigger.</p>

<p>Ironically, this whole situation has made me a little...sad, really.  I'm obviously happy with the service, and I'll keep using it, but there's no gee-whiz factor to it.  I mean, there's no sense of accomplishment like when you set up your own spam filter and thwart the bad guys single-handedly.  I just changed a few DNS records, locked down an SMTP server, and that was it -- spam go bye bye.  Where's the sport?  The challenge?  The thrill of victory?</p>

<p>But [sigh], that's another post entirely...</p>

<p>(Note: SSHere has a referral program. But if you decide to use them, give them <a href="http://www.swoofware.com">Matt's name</a>, not mine.  He's responsible for bringing them to my attention, and I don't want anyone to think I'm shilling for something just to get free stuff.)</p>
]]></content:encoded>
      <dc:subject>Spam</dc:subject>
      <dc:date>2005-10-11T22:09:42-06:00</dc:date>
    </item>
    <item>
      <title>SpamAssassin for Exchange</title>
      <link>http://gadgetopia.com/post/4440</link>
      <description><![CDATA[<p>I was looking for a spam filter for my Exchange server.  I had great luck with <a href="http://spamassassin.apache.org/">SpamAssassin</a> on another box (just regular SMTP), and luckily I found two great resources today:</p>

<ol>
<li><p><a title="How To Use SpamAssassin on Win32" href="http://www.openhandhome.com/howtosa300.html">How To Use SpamAssassin on Win32</a>: This is a fantastic example of someone documenting something they know how to do, and documenting it well.</p>

<p>It's a fantastic body of information, written by someone who has been doing it for a long time.  Everything is covered, including odd permutations, bugs, warnings, dependencies, etc.</p></li>
<li><p><a href="http://www.christopherlewis.com/ExchangeSpamAssassin.htm">Exchange SpamAssassin Sink</a>: This event sink fires on every inbound message, writes it to a file, sics SpamAssassin on it, and parses the result.  It can just add headers to the message (allowing client filtering), or it can toss it altogether.</p></li>
</ol>

<p>I installed this whole solution in about two hours this afternoon, including tuning and fiddling. It's currently filtering away like crazy -- 50% of inbound email is spam right now, and I know I can turn down the threshold quite a bit yet.  </p>

<p>On a well-powered Windows Server 2003 machine, it's taking one second  to filter each email.  (It's probably less, but the logs don't list micro-seconds.  Suffice it to say that no email has taken more than one second to process.)  Remember, however, that none of the network tests (Razor, Pyzor, etc.) work on Windows, and they're what tended to add all the processing time.</p>

<p>What's nice about this setup  is that it saves all email in "Ham" and "Spam" folders.  While this is a bit of a privacy risk, obviously, it also allows you to save up thousands of good and bad emails then train SpamAsassin's Bayesian filter on them (it even inclues a BAT file to do that in one click).  My understanding is that SpamAssassin gets scary-good when you have a well-trained Bayesian database behind it.</p>
]]></description>
      <guid isPermaLink="false">4440@http://gadgetopia.com/</guid>
      <content:encoded><![CDATA[<p>I was looking for a spam filter for my Exchange server.  I had great luck with <a href="http://spamassassin.apache.org/">SpamAssassin</a> on another box (just regular SMTP), and luckily I found two great resources today:</p>

<ol>
<li><p><a title="How To Use SpamAssassin on Win32" href="http://www.openhandhome.com/howtosa300.html">How To Use SpamAssassin on Win32</a>: This is a fantastic example of someone documenting something they know how to do, and documenting it well.</p>

<p>It's a fantastic body of information, written by someone who has been doing it for a long time.  Everything is covered, including odd permutations, bugs, warnings, dependencies, etc.</p></li>
<li><p><a href="http://www.christopherlewis.com/ExchangeSpamAssassin.htm">Exchange SpamAssassin Sink</a>: This event sink fires on every inbound message, writes it to a file, sics SpamAssassin on it, and parses the result.  It can just add headers to the message (allowing client filtering), or it can toss it altogether.</p></li>
</ol>

<p>I installed this whole solution in about two hours this afternoon, including tuning and fiddling. It's currently filtering away like crazy -- 50% of inbound email is spam right now, and I know I can turn down the threshold quite a bit yet.  </p>

<p>On a well-powered Windows Server 2003 machine, it's taking one second  to filter each email.  (It's probably less, but the logs don't list micro-seconds.  Suffice it to say that no email has taken more than one second to process.)  Remember, however, that none of the network tests (Razor, Pyzor, etc.) work on Windows, and they're what tended to add all the processing time.</p>

<p>What's nice about this setup  is that it saves all email in "Ham" and "Spam" folders.  While this is a bit of a privacy risk, obviously, it also allows you to save up thousands of good and bad emails then train SpamAsassin's Bayesian filter on them (it even inclues a BAT file to do that in one click).  My understanding is that SpamAssassin gets scary-good when you have a well-trained Bayesian database behind it.</p>
]]></content:encoded>
      <dc:subject>Spam</dc:subject>
      <dc:date>2005-10-05T16:55:34-06:00</dc:date>
    </item>


  </channel>
</rss>