Re [2]: Whimper. Anybody notice huge spam jump??

From: Aron Roberts <aron_at_socrates.berkeley.edu>
Date: Tue, 14 Nov 2006 15:49:03 -0800 (PST)

  A quick follow-up on the previous post:

Marilyn Saarni wrote:
>>>>I have a favorite, easy-to-use javascript for email addresses on
>>>>websites that I have used for years without issue. I happen to use
>>>>it not only on the campus website that I manage, but also on a
>>>>non-profit's website. That particular website's emails are
>>>>actually aliases, so I get different information when that
>>>>website's emails are forwarded.
>>>>
>>>>Well, the spambots seem to be breaking through my javascript, and
>>>>forwarding garbage into these aliases--and in turn into my own
>>>>mailbox.

  The key point here is that, at this juncture, one can't tell by what
means the spammers obtained your 'alias' email addresses. While it's
possible they harvested them from the JavaScript on your web pages,
whatever happened has already occurred and so you don't have a
controlled experiment.

  By putting up and protecting new 'test' email addresses on your pages,
you can see if those start getting spammed as well. (By the way, if you
use disposable addresses as test email addresses, make sure that their
non-domain portions are truly unique and obscure: something like
"dfksiwerlfs7d9ka.something_at_yourdisposableaddresshost.com", for
instance.)

Aron Roberts
Information Systems and Technology

>>>>
>>>>I suspect that this is probably true for the campus website
>>>>javascript mailto: bits too, though I can't tell since there is no
>>>>forwarding involved. I'm guessing that the "mailto:" code probably
>>>>triggers the spambot software to run more sophisticated analysis of
>>>>the javascript to pull out the email address (the javascript breaks
>>>>up the email address into pieces in plain text, and then
>>>>reassembles it for display).
>>>>
>>>>There has been news already about the 20% worldwide increase of
>>>>spam over the last month due to these new spambots.
>>>>
>>>>Is anyone else having this problem? Any javascript mailto code
>>>>others are using without increased spam?
>>>>
>>>>- Marilyn
>>>>
>>>>-----------------------------------------------------------------------
>>>>The following was automatically added to this message by the list
>>>> server:
>>>>
>>>>Webnet information is available at http://webnet.berkeley.edu.
>>>>Email sent to this list is archived at
>>>>http://ls.berkeley.edu/mail/webnet/ . This archive is open to the
>>>>general public and browsable by search engine spiders,
>>>>email-address harvesting robots, your bosses, etc.
>>>
>>>
>>>--
>>>Aileen 'Ellie' Paterson
>>>Fellowships and Publications Coordinator
>>>Doreen B. Townsend Center for the Humanities
>>>510/643-7236
>>
>> -----------------------------------------------------------------------
>> The following was automatically added to this message by the list
>> server:
>>
>> Webnet information is available at http://webnet.berkeley.edu. Email
>> sent
>> to this list is archived at http://ls.berkeley.edu/mail/webnet/ . This
>> archive is open to the general public and browsable by search engine
>> spiders, email-address harvesting robots, your bosses, etc.
>>
>
>

-----------------------------------------------------------------------
The following was automatically added to this message by the list server:

Webnet information is available at http://webnet.berkeley.edu. Email sent to this list is archived at http://ls.berkeley.edu/mail/webnet/ . This archive is open to the general public and browsable by search engine spiders, email-address harvesting robots, your bosses, etc.
Received on Tue Nov 14 2006 - 15:53:21 PST

This archive was generated by hypermail 2.2.0 : Tue Nov 14 2006 - 15:53:21 PST