- Payload marker - Every piece of useful spam has a payload. This could be a URL, a domain name, a Stock Symbol, or and email address.
- Payoff domain - the website, or websites, that take your money that was followed as part of a spam
- Phishbait - the actual email used to fool the addressee into a nefarious act. In practice, the bait contains legitimate and contrived components to appear legitimate.
- Phishing - the act of using unsolicted email for nefarious acts where by the addressee unwillingly or unknowinly participates in another nefarious act
- Spammer - person or entity that engages in the transmission of spam.
- Spam - unsolicted email with the purpose of engaing the recipent with a solicitous transaction or fraudulent activity.
- Added 2008-12-03
- Domain dumping - whereby incoming spam (plural) is using more than one (1) domain per spam (singular) email. In some cases, the domains in question are not seen together again. In some cases, the domains are not seen in the same 48 hour period again. This may be caused by a programming glitch.
- IP dumping - from time to time spammers will use IP numbers instead of domain names when sending spam. The appearance is that they might be moving those hosts, therefore any open use of their IP numbers is unimportant.
- Added 2009-03-16
- Idle spam time - that being the time when spammer are apparently not actively sending spam, but letting the bots do the work. (Next added 2010-07-30) Weekends and long holiday weeks are the most common.
- Added 2009-04-27
- Free web shill - Any domain that hosts a website for free. In some cases, they will use the provided domains names, but in most cases they will provide a secondary domain name - much like blogs do. For that matter, many blogs are serving the same use for spammers, but we might call them Free blog shills. (In this case we want the old english meaning, as in to cover up the true purpose or meaning. It is a shill because most people do not understand subdomains, hence to the unknowing it appears a primary domain.)
- Added 2009-08-08
- URL wrapping - Using HTML encoded in the message, usually a plain text and an HTML encoded in the same message, the payload is hidden as the HREF. The URL then is made sufficently long such that the URL needs to wrap on a second line, usually by quoted-printable.
- Added 2010-07-30
- Reverse Captcha - When spammers are trying to find the real humans with images, the reverse of finding bots with images.
- Added 2010-09-22
- Double Blind Encoding - an HTML document encoded in base64 with a snippet of javascript encode it hexidecimal. This requires a three (3) step decoding. 1) decode the base64 2) decode the javascript 3) decode the HTML
- URL bounce - By in large, the payload sends the user to a URL that bounces them to the payoff. The URL could be a single webpage, or a domain, or script that replies with an HTTP (protocol) "Location", or an HTML link.
- JavaScript Jump - This a method or technique of URL Bouncing. The psuedo-javascript code (usually the payload or payoff) goes in the "HEAD" and the javascript is loaded in the "BODY" - usually from a legitimate domain.
Thursday, March 27, 2008
Glossary - What are we talking about
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment