Presentation is loading. Please wait.

Presentation is loading. Please wait.

28th March 2003 SPAM Presenter: Matthew Sullivan.

Similar presentations


Presentation on theme: "28th March 2003 SPAM Presenter: Matthew Sullivan."— Presentation transcript:

1 28th March 2003 SPAM Presenter: Matthew Sullivan

2 28th March 2003 What is SPAM...? Spiced Ham UCE (Unsolicited Commercial Email)..? UBE (Unsolicited Bulk Email)..?

3 28th March 2003. Austin, Minnesota, in 1937 Hormel Foods. A spicy ham packaged in a ‘handy dandy’ 12-ounce can. Sixty years later, it's still going strong. More than 5 billion cans have been sold. ‘Spam’ or ‘spam’ is the term that should be used to describe unwanted Internet Email. SPAM is a Registered Trademark of Hormel Foods

4 28th March 2003 So why did bad Email get named after a canned meat product? and the notorious Monty Python Gang The Green Midget Café in Bromley … A bunch of loud Vikings... http://www.oakecommunications.com/GreenMidgetCafe.html

5 28th March 2003 Remember SPAM is pronounced: Thank you “A Trademark of Hormel Foods”

6 28th March 2003 Spam Presenter: Matthew Sullivan Email: matthew@uq.edu.au

7 28th March 2003 UBE, UCE or Spam? UBE (Unsolicited Bulk Email) UCE (Unsolicited Commercial Email) Any Unsolicited Email or Any Unwanted Email…?

8 28th March 2003 What Can be done...? What Should be done...? What can we do as endusers…? What can we do as admins…? What can the law do…?

9 28th March 2003 Filters Content filters Content filters Baysian Filters Baysian Filters Server side Filters Server side Filters Client side Filters Client side Filters The DELETE key The DELETE key

10 28th March 2003 Content Filters False Positives Keyword filtering Detecting False Headers Spamassassin - Spamassassin - http://spamassassin.org/ SpamCop - http://www.spamcop.com

11 28th March 2003 DCC - Distributed Checksum Clearinghouses http:// http://www.rhyolite.com/anti-spam/dcc/ Vipul's Razor - SpamNet http://razor.sourceforge.net/ Content Filters

12 28th March 2003 Bayesian Filters How do they work? Do they really work? Filter projects… http://www.garyarnold.com/projects.php#bayespam http://sourceforge.net/projects/spambayes/ http://www.mozilla.org/

13 28th March 2003 Blocklists Used to Block or Filter...? Access files or DNSbls..? Which DNSbl...? Do you create your own…?

14 28th March 2003 DNSbls SPEWS - Spam Prevention Early Warning System SORBS - Spam and Open Relay Blocking System DSBL - Distributed Server Boycott List ORDB - Open Relay DataBase NJABL - Not Just Another Bogus List MAPS - Mail Abuse Prevention System ROKSO - Register Of Known Spam Operations SBL - Spamhaus Block List

15 28th March 2003 SPEWS Spam Prevention Early Warning System Lists Spammers as they are spotted. Lists Spammers as they are spotted. Lists ISPs who refuse to disconnect Spammers. Lists ISPs who refuse to disconnect Spammers. Good for finding spam history of a Spammer. Good for finding spam history of a Spammer. 3 Levels of blocking.. 3 Levels of blocking.. Level 0 - Spammer gone. Watching… (Not in DNS) Level 0 - Spammer gone. Watching… (Not in DNS) Level 1 - Spammer or blatant spam supporter Level 1 - Spammer or blatant spam supporter Level 2 - All Level 1 plus ‘suspicious’ hosts. Level 2 - All Level 1 plus ‘suspicious’ hosts. http://www.spews.org/

16 28th March 2003 SORBS Spam and Open Relay Blocking System Is Software that automatically blocks incoming connections. Is Software that automatically blocks incoming connections. Lists Open Proxies and Open Relays Lists Open Proxies and Open Relays Lists Hacked Servers Lists Hacked Servers Lists vulnerable scripts (eg. formmail.pl) Lists vulnerable scripts (eg. formmail.pl) Lists Spammers when spam is received. Lists Spammers when spam is received. Lists ISPs after 3 separate spams are received from Lists ISPs after 3 separate spams are received from the spam spammer or ISP. the spam spammer or ISP. More Later on SORBS http://www.dnsbl.sorbs.net/

17 28th March 2003 DSBL Distributed Server Boycott List Lists Open Proxies and Open Relays Lists Open Proxies and Open Relays Lists Hacked Servers Lists Hacked Servers Lists vulnerable scripts (eg. formmail.pl) Lists vulnerable scripts (eg. formmail.pl) Lists Servers sending to ‘listme@listme.dsbl.org’. Lists Servers sending to ‘listme@listme.dsbl.org’. Does not perform any testing Itself. Does not perform any testing Itself. http://www.dsbl.org/

18 28th March 2003 ORDB Open Relay DataBase Lists verified Open Relays Lists verified Open Relays http://www.ordb.org/

19 28th March 2003 NJABL Not Just Another Bogus List Lists Open Proxies and Open Relays Lists Open Proxies and Open Relays Lists Hacked Servers Lists Hacked Servers Lists vulnerable scripts (eg. formmail.pl) Lists vulnerable scripts (eg. formmail.pl) List Dial-Up/Dynamic Netblocks. List Dial-Up/Dynamic Netblocks. Lists spammers as they send spam to NJABL spamtraps Lists spammers as they send spam to NJABL spamtraps http://www.njabl.org/

20 28th March 2003 MAPS Mail Abuse Prevention System RBL List - Real-Time Blackhole RBL List - Real-Time Blackhole DUL List - Dialup User List (Modem pool Address blocks) DUL List - Dialup User List (Modem pool Address blocks) RSS List - Relay Spam Stopper (Spam relaying Servers) RSS List - Relay Spam Stopper (Spam relaying Servers) Subscription required (Educational Rates Available). Subscription required (Educational Rates Available). Attempts to ‘educate’ spammers & ISPs into stopping spam. Attempts to ‘educate’ spammers & ISPs into stopping spam. Have judgements against them NOT to list some networks. Have judgements against them NOT to list some networks. http://www.mail-abuse.org/

21 28th March 2003 ROKSO Register Of Known Spam Operations Lists Spammers. Lists Spammers. Lists Spam Support Services Lists Spam Support Services Lists Spam gangs Lists Spam gangs Criteria for listing is that the spammer has been Criteria for listing is that the spammer has been identified as being ejected from at least 3 ISPs for spamming. http://www.spamhaus.org/rokso/

22 28th March 2003 SBL Spamhaus Block List Lists Spammers. Lists Spammers. Lists Spam Support Services Lists Spam Support Services Lists Spam gangs Lists Spam gangs Lists other spam sources (like proxies) though this is Lists other spam sources (like proxies) though this is activly published. http://www.spamhaus.org/sbl/

23 28th March 2003 Enduser Filters Spam Killer - http://www.spamkiller.com/ Mail Washer - http://www.mailwasher.net/ Spam Eater - http://www.spameaterpro.com/ Microsoft Outlook Express - http://www.microsoft.com/ SpamPal - http://www.spampal.org.uk/ Mozilla - http://www.mozilla.org/

24 28th March 2003 Questions?

25 Thank You Presenter: Matthew Sullivan Email: matthew@uq.edu.au


Download ppt "28th March 2003 SPAM Presenter: Matthew Sullivan."

Similar presentations


Ads by Google