"Lighthouse Afghan" fools Outlook spam filter

Spammers using hidden words to slip through Bayesian filter…

NEWS Spammers are inserting hidden words into their email messages to fool Microsoft Outlook's built-in anti-spam technology.

As spam-filtering technologies become more common, spammers have altered the construction of their messages to avoid detection. Although spam is very simple for a human to spot, the artificial intelligence systems used by junk filters rely on spotting obvious keywords, applying statistical theories to messages, and using rule-based systems to try and differentiate between wanted and unwanted emails.

The latest version of Microsoft Outlook is armed with a Bayesian filter, which tries to recognise spam by looking at the words used in an email and, depending on the frequency of certain key words, calculating the probability of that email being spam.

John Cheney, CEO of email security firm BlackSpider Technologies, said to get past the Bayesian methods, spammers have started hiding words that are not usually associated with spam at the bottom their emails: "At the bottom of the message they have included a whole load of keywords that are used to fool the Bayesian filters - they are in a tiny font and in the same colour as the background," he said.

"These messages are designed to fool the Outlook 2003 filters because there are a lot of words in there that don't look spam-like and they would weight the email as a normal email rather than a spam email," he said.

Another trick used by spammers to bypass junk-email filters is to write their messages using accented characters in their messages to makes obvious spam keywords, such as Viagra, look like a legitimate word written in a foreign language.

Some of the most recent examples of anti-junk-mail combine accented characters to make messages written in English look like they are written in a foreign language. Because the majority of Spam originates in the US, most spam is written in English, so many email filters ignore non-English spam. For example, if a spam keyword was "enhancer" and the spam included the word "ènháncer", the message would be allowed to pass.

Alun Davies, European VP of marketing at internet software firm Rockliffe, said his company's products will soon be updated to filter out this relatively recent development: "A large percentage of our MailSite email server customers do not use English as their main language, so for some time we have been aware of the need for spam filtering technology that can recognise accented characters and non Latin characters," he said.

Blackspider's Cheney said that yet another relatively successful spamming technique hides the spammers message by inserting HTML code between the words. Because most mail clients automatically render HTML messages, users don't see the tags, just the message: "HTML tags are typically used to make words bold or red or something like that, but these are general tags that don't actually affect the appearance of the message but they do confuse the lexical analysers," he said.

Munir Kotadia writes for ZDNet UK

Comments

There are 3 comments. Join the discussion

  1. 1. John Graham-Cumming

    This technique is hardly new, I talked about it at the MIT Spam Conference in January 2003. The fact that Microsoft's spam filter is fooled by it is surprising because it is a well known technique.

    I've been keeping track of as many spammer tricks as possible in The Spammers Compendium and there are more that are much more complex than this article talks about.

    Good spam filters (e.g. POPFile and others) can handle these tricks with ease.

    John.

    • 6 April 2004 13:42
    • Add comment
  2. 2. Bob Parker

    Sooner or later the internet industry is going to be forced to accept that the current methods of generating and transmitting e-mail cannot continue into the future.
    Spam is going to destroy e-mail as a communications medium unless everyone stops trying to apply band-aid solutions and agrees on a completely new standard which makes high-volume anonymous e-mail transmission technically impossible because it's been built that way from the ground up.
    Spam is now resulting in e-mail becoming close to useless for me. All the spam filtering is causing messages to vanish in transit in both directions.
    When they come up with a whole new standard, remember that you read it here first. Well maybe not. :)

    • 6 April 2004 17:47
    • Add comment
  3. 3. Moraru

    Spam filter - Spam Bully for Outlook and Outlook Express, use rendering Html.

    • 11 June 2004 14:56
    • Add comment

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your silicon.com account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ

Get silicon.com's daily newsletter

  • Register on silicon.com

    Enter your email to register

Keep in touch with silicon.com

silicon.com newsletters