Title: What is Spam
1SPAM Presenter Matthew Sullivan
2What is SPAM...?
UBE (Unsolicited Bulk Email)..?
UCE (Unsolicited Commercial Email)..?
Spiced Ham
3.
Austin, Minnesota, in 1937 Hormel Foods. A
spicy ham packaged in a handy dandy 12-ounce
can. Sixty years later, it's still going
strong. More than 5 billion cans have been sold.
SPAM is a Registered Trademark of Hormel Foods
Spam or spam is the term that should be used
to describe unwanted Internet Email.
4So why did bad Email get named after a canned
meat product?
The Green Midget Café in Bromley
A bunch of loud Vikings ...
and the notorious Monty Python Gang
http//www.oakecommunications.com/GreenMidgetCafe.
html
5Remember SPAM is pronounced
6Spam Presenter Matthew Sullivan Email
matthew_at_uq.edu.au
7UBE, UCE or Spam?
UBE (Unsolicited Bulk Email) UCE (Unsolicited
Commercial Email) Any Unsolicited Email or Any
Unwanted Email?
8What Can be done...? What Should be done...? What
can we do as endusers? What can we do as
admins? What can the law do?
9Filters
- Content filters
- Baysian Filters
- Server side Filters
- Client side Filters
- The DELETE key
10Content Filters
False Positives Keyword filtering Detecting False
Headers Spamassassin - http//spamassassin.org/ Sp
amCop - http//www.spamcop.com
11Content Filters
DCC - Distributed Checksum Clearinghouses http//w
ww.rhyolite.com/anti-spam/dcc/ Vipul's Razor -
SpamNet http//razor.sourceforge.net/
12Bayesian Filters
How do they work? Do they really work? Filter
projects http//www.garyarnold.com/projects.phpb
ayespam http//sourceforge.net/projects/spambayes/
http//www.mozilla.org/
13Blocklists
Used to Block or Filter...? Access files or
DNSbls..? Which DNSbl...? Do you create your
own?
14DNSbls
SPEWS - Spam Prevention Early Warning
System SORBS - Spam and Open Relay Blocking
System DSBL - Distributed Server Boycott
List ORDB - Open Relay DataBase NJABL - Not Just
Another Bogus List MAPS - Mail Abuse Prevention
System ROKSO - Register Of Known Spam
Operations SBL - Spamhaus Block List
15SPEWS
Spam Prevention Early Warning System
- Lists Spammers as they are spotted.
- Lists ISPs who refuse to disconnect Spammers.
- Good for finding spam history of a Spammer.
- 3 Levels of blocking..
- Level 0 - Spammer gone. Watching (Not in DNS)
- Level 1 - Spammer or blatant spam supporter
- Level 2 - All Level 1 plus suspicious hosts.
http//www.spews.org/
16SORBS
Spam and Open Relay Blocking System
- Is Software that automatically blocks incoming
connections. - Lists Open Proxies and Open Relays
- Lists Hacked Servers
- Lists vulnerable scripts (eg. formmail.pl)
- Lists Spammers when spam is received.
- Lists ISPs after 3 separate spams are received
from - the spam spammer or ISP.
More Later on SORBS
http//www.dnsbl.sorbs.net/
17DSBL
Distributed Server Boycott List
- Lists Open Proxies and Open Relays
- Lists Hacked Servers
- Lists vulnerable scripts (eg. formmail.pl)
- Lists Servers sending to listme_at_listme.dsbl.org
. - Does not perform any testing Itself.
http//www.dsbl.org/
18ORDB
Open Relay DataBase
- Lists verified Open Relays
http//www.ordb.org/
19NJABL
Not Just Another Bogus List
- Lists Open Proxies and Open Relays
- Lists Hacked Servers
- Lists vulnerable scripts (eg. formmail.pl)
- List Dial-Up/Dynamic Netblocks.
- Lists spammers as they send spam to NJABL
spamtraps
http//www.njabl.org/
20MAPS
Mail Abuse Prevention System
- RBL List - Real-Time Blackhole
- DUL List - Dialup User List (Modem pool Address
blocks) - RSS List - Relay Spam Stopper (Spam relaying
Servers) - Subscription required (Educational Rates
Available). - Attempts to educate spammers ISPs into
stopping spam. - Have judgements against them NOT to list some
networks.
http//www.mail-abuse.org/
21ROKSO
Register Of Known Spam Operations
- Lists Spammers.
- Lists Spam Support Services
- Lists Spam gangs
- Criteria for listing is that the spammer has
been - identified as being ejected from at least 3 ISPs
- for spamming.
http//www.spamhaus.org/rokso/
22SBL
Spamhaus Block List
- Lists Spammers.
- Lists Spam Support Services
- Lists Spam gangs
- Lists other spam sources (like proxies) though
this is - activly published.
http//www.spamhaus.org/sbl/
23Enduser Filters
Spam Killer - http//www.spamkiller.com/ Mail
Washer - http//www.mailwasher.net/ Spam Eater -
http//www.spameaterpro.com/ Microsoft Outlook
Express - http//www.microsoft.com/ SpamPal -
http//www.spampal.org.uk/ Mozilla -
http//www.mozilla.org/
24Questions?
25Thank You
Presenter Matthew Sullivan Email
matthew_at_uq.edu.au