[Gllug] new graphical spam

Tethys sta296 at astradyne.co.uk
Tue Mar 27 21:18:11 UTC 2007


SteveC writes:

>My life was perfect until this new graphical spam started coming a few 
>weeks ago. GIF attachments with text about random stocks with noise or 
>lines on top.

Only a few weeks ago? Lucky you!

>I run spamassassin and procmail on everything. Do people recommend 
>dumping all gif mail (in which case a procmail rule would be appreciated 
>:-) or has anyone tried these spamassassin plugins that does OCR?

So far it hasn't been enough of a problem that I've needed to do
anything about it. Dumping all GIF mail is probably excessive.
You'd probably want to dump GIF mail without any accompanying
text that's from someone not in a whitelist. As for a procmail
rule, just looking for "Content-Type: image/gif" in the body
should do the trick most of the time. Or look for R0lGOD[ld],
which covers base64 encoded GIF87a and GIF89a images.

I don't use spamassasin, but have some experience with OCRing
CAPTCHA images when scraping web sites. It's a bit of a hit and
miss affair. For a specific CAPTCHA, you can tune your image
manipulation to get the best results for that image type. But
for the general case of spam images, you probably don't stand
much of a chance, particularly if they're adding in noise to
the image to thwart OCR.

Tet
-------------- next part --------------
-- 
Gllug mailing list  -  Gllug at gllug.org.uk
http://lists.gllug.org.uk/mailman/listinfo/gllug


More information about the GLLUG mailing list