Hidden Characters

Spammers face an interesting challenge in that they must make their message obscure to spam filtering systems without making it unintelligible to their target audience.

One approach to this problem is to present the message in such a way that what a human sees is completely different from what a computer filtering system sees. Their hope is that by sending a message that says “VIAGRA” to a human reader but “VsuIpAuGuRapA” to the filter they can avoid having their message caught and can then sell more Viagra (or something resembling Viagra, or just collect money and not deliver anything).

Looking at the image below you might think that the spammer did a pretty bad job of designing the email, but you can definitely discern their intent: They want to sell you some drugs.

hidden characters hidden

On the other hand, if you look at the same message with all of the text selected and displayed, the email looks completely different:

hidden characters showing

The spammer’s trick here is to use HTML to set the color of the text they don’t want the human recipient to see to be the same color as the background, in this case black.  The result is that humans see the first email above, sloppy but readable.

On the other hand, computer filtering systems see all of the text as displayed in the second example, and read “VsuIpAuGuRapA” instead of “VIAGRA”.

With this tactic, what would be obvious spam to a human becomes an unrecognizable string of characters to a computer.

So what are we to do?

Fortunately for us in the spam wars there’s more to sending spam than just scrambling characters. Most spam messages contain many subtle clues as to their illicit nature which, when added together, provide a much stronger case against the messages delivery than just the name of an any specific ED medication.

- -

OnlyMyEmail is an award winning hosted spam filtering service and business email hosting provider. Our enterprise cloud computing anti-spam solution, the MX-Defender, has the highest capture rate of any spam filter ever tested in the VBSpam Challenge, blocking a record setting 99.9993% of all malicious and junk email.

Our Personal spam filtering system is also a Software as a Service (SaaS) solution and has won both the PC World "World Class Award" and also the PC Magazine "Editor's Choice Award."

OME-Kids is a webmail solution that protects children from spam and other harmful emails. OME-Kids offers unique Parental Controls that allow you to choose the level of security and oversight that's right for your child.

Related posts:

  1. Spammers Use Word-Joiner Characters to Encode URLs

Tags:

Comments are closed.