Tuesday, June 19, 2007

Product Review: SpamArrest

Does any of this sound familiar? You get so much spam that you have to keep your finger on the delete button whenever you check your email. Then you inevitably erase the one or two important messages that you really needed to see, so you have to sift through all the spam again in your Trash folder to find them.

If you go out of town for a couple of days, your inbox fills up with junk and your important messages start to bounce before you can return to your computer to clean out your inbox and make room.

That was my situation. I have a spam filter at the ISP level, which really does not seem to filter out much. And I tried a couple of other spam filtering solutions, but they delayed my email too much, and I never fully trusted that everything was getting through.

I tried SpamArrest after noticing that a colleague was using it, but my expectations were not terribly high because the other filtering solutions that I had tried just did not work for me.

How Does it Work?

When you sign up for a SpamArrest account, you simply make a few changes to your email program (such as Outlook or Eudora) so that SpamArrest can download your email from your ISP to the Spam Arrest mail server. Then SpamArrest sorts it and filters whatever you do not want. I expected to have a little trouble configuring my email account correctly, but it was no sweat at all. The instructions are very detailed and easy to follow. They definitely cater to the layperson, so there is no jargon. And if you do have trouble, you can get technical support via email.

The basic SpamArrest account allows you to filter up to 5 email accounts. And they have a webmail feature, too, so you can access your mail by logging into your account at the SpamArrest website. It is great if you are traveling and just want to check in.

Once your email accounts are configured, you simply decide whose email you would like to continue to receive. You can preauthorize senders by typing in specific email addresses, by using a special import feature, or by preauthorizing entire domain names.

When someone who is not on your preauthorized list tries to email you, she will receive an email asking her to verify her intent to send you the message. The idea is that a real human being will verify her identity, but a spambot or automated mailing system will not.

One of my favorite parts of the SpamArrest system is that anyone who is on your preauthorized list is never sent a verification email at all. So you can easily set it up such that your friends, relatives, and colleagues never know you are filtering your messages.

Once someone responds to the verification email, she is added to your list of authorized senders. Then her original email (and all subsequent emails she sends you) will get through.

You can always remove people from your list of approved senders, too, so you have total control of whose email gets to your inbox.

If a verification email is not responded to, the email stays in a special "Unverified" folder in your online SpamArrest inbox for a whole week. That way, you can log in and check to see if any important messages were not verified. For example, sometimes I will forget that I signed up for an email newsletter, so I simply authorize the sender by clicking a button on the screen. Then the message, and all subsequent messages from this particular email address, will go right to my inbox and skip the "Unverified" folder altogether.

Right after I opened my SpamArrest account, I checked this Unverified folder every day, but now I find that most of the senders that I want email from are already on the authorized list, so I check in only every few days. It is easy to tell which messages in your Unverified folder are new since your last login, because they stay in bold typeface until you log out.

According to the SpamArrest statistics on my account, a full 63.64 percent of my email to date has been spam. It is such a great relief to know that it never made it to my inbox at all. I save a lot of time each morning, and I enjoy sending and receiving email again.

How Much Does it Cost?

At the time of this writing, SpamArrest subscriptions are $5.95 per month (or you can save by signing up for a year or two at a time: $44.95 for one year and $74.95 for two years.) You can add features for an additional fee, but I have the basic subscription and have never needed anything beyond that.

About the Author:
Susie Cortright
You can get a free 30 day trial of SpamArrest here. And view the latest Coupon Codes here..
Posted: 15-02-2007
Article Source: ArticlesBase.com

Tuesday, June 12, 2007

Spam Fighting Strategies for Webmasters

Battling spam is just like fighting any other activity that is illegal and needs to be fought in many areas. There are some easy steps that you can take to minimize the impact of spam in your email, as discussed in Part I. However, the webmaster of your email service has many more tools they can use to fight spam.

The effort would be small if a spammer had to collect email addresses one by one. This is why they take advantage of programming that is automated, such as using a spambot. A spambot is a program that looks through Internet websites for legitimate email addresses. These addresses are then "harvested" and put into huge lists.

The best way to deal with spammers is by raising their cost without putting too much of your own effort into it. Some of the techniques described in Part I can also be used by a webmaster.

CAMOUFLAGE

A spambot will only do what it has been told to do through a program. Many times a spambot will pass you by simply if you've disguised your email address. This is because a spambot is usually programmed to search for character strings that look like this: Jane_email@emailaddressdomain.com. You can fool a spambot by changing the email to Jane_email_at_NOSPAMemailaddressdomain.com.

Should the disguised email address be harvested by a spambot it will still need to "scrubbed" before it can be used. A program for scrubbing can be difficult to write since there are many variations that are possible, such as NO_SPAM and no*spam. Try to be as creative as possible.

There is a disadvantage to the above method: you need to remember to take out the extra letters as well as put in th@ sign.

You can make an email address impossible to harvest by putting it into a graphic instead of plain text or mailto:. Not many spambots are smart enough to translate a graphic and understand the pixel pattern as text that is usable. This is particularly true since graphics can have many shapes. Again, this method can be inconvenient because you won't just be able to reply to this address or copy and paste it.

Another approach is to get rid of the accessbile and visible email address completely. You can use a form for feedback that stores data in areas where a spambot can't search. You can also store the data inside of easy to write code that is difficult to decipher due to encryption. An example of this would be javascript.

BARRIERS

Communication becomes more difficult between trusted sources when visible email addresses are hidden in graphics or banned from visibility. You want to hinder the spammer by putting a block on any spambots that are known.

Many times they will have a signature that is easily seen through an IP address that is well known or a process name (and sometimes both). Other times they can search for User-Agents that are a non-browser form.

Webmasters can easily block IP addresses as well as block any unwanted processes. The webmaster just needs to begin a cron job that will scan the network for the name of a process and then terminate any IDs that are associated with the process.

A more experienced webmaster will have a daemon that will sleep until that time when a process name is noticed. The daemon will then "wake up" and terminate the process before any spam harvesting can occur. Sample programs, which are only a bit harder to implement, can be used and are available online.

You can get traps for spambots that will block any request that is incoming simply based on search patterns and behaviors. This method to fight spam is slightly more difficult to set up and attend to because it needs certain patterns to define it, changing the pattern slightly for different spambots. How-to information and sample perl programs are available online.

RAISE THE PRICE

After time most spammers will tire of trying different variations in programming just to get email addresses, making the reward much less than the effort. This is what you want to do: make the spammer cost much higher than the reward which will make your reward much more than the effort.

A spammer won't give up until there is no profit in the effort. US legislation, such as CAN-SPAM, has only seemed to deter businesses that are legitimate and that were never the guilty ones to begin with.

There are, however, some things being done to reduce the problem of spam to just an annoyance: there are penalties for sending spam, filters for junk mail are becoming smarter, and there are proposals underway that include needing a mailer ID.

This is all bad news for the spammer while at the same time is great for the rest of us computer users.

About the Author:
Paul Wilcox writes about internet security solutions for the Internet Cyber Security website. Sign up for our free newsletter at http://www.internetcybersecurity.com
This article was posted on September 15, 2006
Article Source: articlecity

Wednesday, June 06, 2007

Hall of Shame – The Bad Boys of Email Spam

The majority of Unsolicited Commercial Email (UCE) or “spam” is sent by a relatively small group of dedicated professional spammers. The Register of Known Spam Operations (ROKSO) indicates that 80% of all spam comes from just 200 known spam operations. This data is in line with research completed by CipherTrust research scientists, which indicates that most spam originates from a relatively small group of tightly integrated spam networks. While we’re all very familiar with the spam messages we receive each day, it is interesting to take a look at who these spammers are – to put a “face” to the problem. Following are four of the most notorious and prolific spammers in the world.

Alan Ralsky
Mr. Ralsky is currently one of the most egregious spam senders in the world. His organization, based in Michigan since 1997, uses Chinese, European and US-based servers to host and send spam to millions of email boxes daily. But that’s not enough for Ralsky. Not only does he operate as a spammer, but he also provides hosting services to other spammers.

In 2002, Verizon sued Mr. Ralsky for causing their network to freeze twice. The lawsuit originally sought $37 million, but was settled out of court for an undisclosed amount. Ralsky is no longer allowed to send email over Verizon’s networks, but admits no wrongdoing in the case and has vowed to continue sending bulk email.

Mr. Ralsky was convicted in 1994 for falsifying documents to defraud two banks in Michigan and Ohio and was fined $74,000. In an unrelated case in 1992, Ralsky was sentenced to 50 days in jail and ordered to pay $120,000 in restitution for failing to deliver a contract involving unregistered securities.

While Mr. Ralsky sends millions of unsolicited email messages selling everything from diet pills to online gambling, he claims that his business is legitimate and that his emails are not spam. He also insists that he does not sell pornography. We’re sure he’s an absolutely charming fellow.

Scott Richter
Scott Richter’s Denver-based company, OptinRealBig, is responsible for sending out billions of spam emails. He is one of the most outspoken and notorious spammers in business today. Whereas most spammers attempt to keep a low profile, often denying any involvement in spam, Richter seems to enjoy the spotlight. In fact, Richter even attempted to start up a “Spam King” clothing line before Hormel (the company responsible for bringing delicious canned Spam to dining rooms around the world) put an end to his trademark-infringing idea.

Richter and his partners were named in a lawsuit filed by the New York Attorney General and Microsoft. That suit, filed in 2003, sought millions of dollars in punitive damages, but was settled out of court in mid-2004 with a paltry fine of $50,000. For quite some time, Richter regarded his legal entanglements as excellent advertising for his company which, he claimed, gains value each time he is sued.

Recently he has changed his story somewhat. Faced with prolonged lawsuits led by Microsoft as well as various state and corporate entities, Richter has now declared bankruptcy. As his father (who is also his attorney) said, "It’s the legal fees that are battering the company. OptIn is profitable but for these lawsuits."

Andrew Westmoreland
An apparent accomplice of Scott Richter, Westmoreland’s Texas-based company, Internet Access Group Inc., sends millions of spam messages pushing everything from gas to online diploma mills to auto loans and mortgages. His business also operates under the names Brilliant Marketing, Aphrodite Marketing, OptiGate Networks and Players Exchange Club.

Robert Soloway
Robert Soloway’s Oregon-based company, Newport Internet Marketing Corporation, has sent millions of spam emails and has been the subject of numerous complaints and lawsuits by class action groups and Microsoft.

Soloway’s spam messages often contain get-rich-quick schemes selling (what else?) spam software and “fresh” email addresses. Yes, that’s right folks; you too can send spam to 15 million recipients for just $295. At least that’s what the ad says, but would you want to give your credit card number to someone like this?

Slam the Door on Spam
This is just a small sampling of the questionable characters who insist on clogging your inbox with junk email. While these may be some of the most egregious offenders, there are plenty more waiting in the wings who would like nothing more than to be considered equally offensive. As these new spammers rise through the ranks, we’ll keep you posted on who they are, and what kind of shady business they’re up to.

About the author:
Dr. Paul Judge, CTO, CipherTrust, Inc.
Dr. Paul Judge is a noted scholar and entrepreneur. He is Chief Technology Officer at CipherTrust, the industry's largest provider of enterprise email security. The company’s flagship product, IronMail provides a best of breed enterprise anti spam solution designed to stop spam, phishing attacks and other email-based threats. Learn more by visiting www.ciphertrust.com/products/spam_and_fraud_protection today.
Circulated by Article Emporium