Ming the Mechanic:
Ingenious email-harvester honeypot

The NewsLog of Flemming Funch
 Ingenious email-harvester honeypot2003-06-19 23:59
1 comment
by Flemming Funch

From BoingBoing:
Merlin Mann outlines an ingenious procedure for identifying spammers' email-harvesters' IP addresses and user-agents:

"In each page I serve, I include a bogus email address, encoded with the date of access as well as the host IP address and embedded in a comment. [Apache's server-side includes are great!] This has allowed me to trace spam back to specific hosts and/or robots.

One of the first I caught with this technique was the robot with the user agent "Mozilla/4.0 efp@gmx.net", which always seems to come from argon.oxeo.com - it's identified it above as simply rude."
Simple and clever. Well, relatively simple for a programmer. Now, if we could coordinate the gathering of a lot of that kind of data. I.e. mapping spam to who mined the address in the first place.


[< Back] [Ming the Mechanic]

Category:  

1 comment

12 Jul 2003 @ 17:49 by maxtobin : Thanks for this link Ming.
The integrity of any system requires the ability to have a transparent way to control what comes in and then goes out. I believe it is very important to develop open robust systems that allow for only integral communications. Hell when I'm already at my best 'fighting weight' I don't need all that spam that promises me I can loose unwanted weight or increase the size of certain parts of my anatomy. Hee hee. I feel like Poo the Bear with these honey pots coming into my world view.  


Other stories in
2014-11-01 17:33: The conversation of work
2007-02-24 14:20: Writing books in HTML/CSS
2007-02-05 15:21: Software is hard
2006-11-19 21:30: Thingamy
2005-12-14 15:15: Ruby on Rails
2005-03-19 16:04: Comment and Refererrer Spam
2005-02-23 21:34: Wikipedia
2005-02-22 17:32: Mail
2005-02-10 16:00: More Google wizardry
2005-02-04 15:14: The Six Laws of the New Software



[< Back] [Ming the Mechanic] [PermaLink]? 


Link to this article as: http://ming.tv/flemming2.php/__show_article/_a000010-000845.htm
Main Page: ming.tv