Spamtrap

Spamtrap

A spamtrap is a honeypot used to collect spam.

Spamtraps are usually e-mail addresses that are created not for communication, but rather to lure spam. In order to prevent legitimate email from being invited, the e-mail address will typically only be published in a location hidden from view such that an automated e-mail address harvester (used by spammers) can find the email address, but no sender would be encouraged to send messages to the email address for any legitimate purpose. Since no e-mail is solicited by the owner of this spamtrap e-mail address, any e-mail messages sent to this address are immediately considered unsolicited.

The term is a compound of the words "spam" and "trap", because a spam analyst will lay out spamtraps to catch wild spam in the same way that a fur trapper lays out traps to catch wild animals. Who originally coined this term is unknown, but several competing anti-spam organizations claim trademark over it [http://www.netliancecorp.com/pdf/spamtrapbrochure.pdf] [http://tess2.uspto.gov/bin/gate.exe?state=gcisui.4.1&f=toc&a_search=&p_s_ALL=SPAMTRAP] .

Industry uses

An untainted spamtrap can continue to collect samples of unsolicited messages that can be acted on by an automated anti-spam system. The automated system could instantly block any further e-mail messages with the same content, arriving for other e-mail addresses, because the messages would then be considered as bulk unsolicited e-mail, the typical definition of spam. Automation is considered "safe" because no legitimate email messages should be arriving to the spamtrap address.

The source IP address of a sender delivering e-mail to the spamtrap could also be added to a blacklist for source address blacklisting of e-mail.

Vulnerabilities

* A spamtrap becomes tainted when a third party discovers what the spamtrap e-mail address is being used for. Once this occurs, the third party could target the spamtrap by maliciously sending email to it giving the third party some control over the automated process of what is being considered bulk unsolicited e-mail by the anti-spam system. They would not however, be able to subscribe a spamtrap address to any legitimate email list since all legitimate lists use a confirmed opt-in procedure.
* Spammers using spamtrap addresses from their mailing lists as sender addresses can cause backscatter when a reply/DSN is sent to the spamtrap address.
* If the spammer put a spamtrap mailbox with many others in the TO or CC line, when any of that other people reply or forward the message, this address will be considered spam too.
* Many spamtrap's addresses are shown in search pages like Google. The mailbox is visible in that page and any can write it without knowing that mail will be caught as spam.

Usenet

A spamtrap can also be a Usenet newsgroup whose sole purpose is to lure cross-posted spam. For example, the alt.sex.cancel newsgroup charter states that any article posted there may be cancelled immediately. Thus, a spammer who cross-posts an article to the entire alt.sex.* hierarchy, including alt.sex.cancel, will find that article is quickly cancelled.

SpamTrap as a Commercial Term

SpamTrap is also used as the product name for several commercial anti-spam systems that are unrelated to the technical term.

ee also

*Project Honey Pot
*Address munging
*Botnets
*E-mail address harvesting
*List poisoning
*Stopping e-mail abuse


Wikimedia Foundation. 2010.

Игры ⚽ Поможем написать курсовую

Look at other dictionaries:

  • Comparison of DNS blacklists — The following table lists technical information for a number of DNS blacklists. Blacklist operator DNS blacklist Informational URL Zone Listing goal Nomination Listing lifetime Notes ARM Research Labs, LLC GBUdb Truncate [1] truncate.gbudb.net… …   Wikipedia

  • Anti-spam techniques — To prevent e mail spam (aka unsolicited bulk email), both end users and administrators of e mail systems use various anti spam techniques. Some of these techniques have been embedded in products, services and software to ease the burden on users… …   Wikipedia

  • Honeypot (computing) — In computer terminology, a honeypot is a trap set to detect, deflect, or in some manner counteract attempts at unauthorized use of information systems. Generally it consists of a computer, data, or a network site that appears to be part of a… …   Wikipedia

  • Anti-spam techniques (e-mail) — To prevent e mail spam, both end users and administrators of e mail systems use various anti spam techniques. Some of these techniques have been embedded in products, services and software to ease the burden on users and administrators. No one… …   Wikipedia

  • E-mail spam — E mail spam, also known as bulk e mail or junk e mail, is a subset of spam that involves nearly identical messages sent to numerous recipients by e mail. A common synonym for spam is unsolicited bulk e mail (UBE). Definitions of spam usually… …   Wikipedia

  • Email spam — An email box folder filled with spam messages. Email spam, also known as junk email or unsolicited bulk email (UBE), is a subset of spam that involves nearly identical messages sent to numerous recipients by email. Definitions of spam usually… …   Wikipedia

  • Botnet — is a jargon term for a collection of software robots, or bots, that run autonomously and automatically. The term is often associated with malicious software but it can also refer to the network of computers using distributed computing… …   Wikipedia

  • Spambot — A spambot is an automated computer program designed to assist in the sending of spam. Email spambotsEmail spambots collect e mail addresses from the Internet in order to build mailing lists for sending unsolicited e mail, also known as spam. Such …   Wikipedia

  • E-mail address harvesting — E mail harvesting is the process of obtaining lists of e mail addresses using various methods for use in bulk e mail or other purposes usually grouped as spam.MethodsThe simplest method involves spammers purchasing or trading lists of e mail… …   Wikipedia

  • SpamCop — is a free spam reporting service, allowing recipients of unsolicited bulk email (UBE) and unsolicited commercial email (UCE) to report offenses to the senders Internet Service Providers (ISPs), and sometimes their web hosts. SpamCop uses these… …   Wikipedia

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”