A secure and covert communication channel for HTTP tar pits to implement dynamic web page blocks to bar spammer's harvesters

Tobias Eggendorfer · 2007

Unsolicited commercial email (UCE, spam), scam and phishing emails make up for more than 90% of all emails sent world-wide. Most anti spam methods known rely on filtering emails. Meanwhile, even web browsers check URLs against blacklists to avoid fraud. However, all those methods are reactive, ergo they are only able to deal with known attack patterns. A preventive approach is to stop spammers from collecting mail addresses with their harvesters. Beside obfuscation of email addresses, HTTP tar pits have proven their efficiency in catching harvesters. This paper presents a method to use HTTP tar pits to identify harvesters and how to use this knowledge to dynamically block their access to regular web pages.

Read the paper · More papers on PaperTik