Porn spammers sneak images into Outlook

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

Spammers who send pornographic pictures in the hope of enticing the recipient to signing up to an adult Web site have discovered a way to bypass Outlook 2003's security features, which are designed to stop potentially offensive content being automatically displayed in the preview window.

The latest version of Microsoft's Outlook was built with a relatively sophisticated spam filter, but as the product's first birthday approaches, spammers are finding new ways to ensure that their unsolicited message go undetected.

In order to help fight spam, Microsoft armed Outlook 2003 with a Bayesian filter, which tries to recognise unsolicited messages by examining the words used and, depending on the frequency of certain key words, calculating the probability of that e-mail being spam.

The company also improved on previous versions of Outlook by allowing users to choose if an HTML email should be allowed to access the Internet and download content. This gives the user a chance to prevent the pornography from ever reaching his or her PC.

However, John Cheney, chief executive of email-security firm BlackSpider Technologies, explained that one of the growing trends is for spammers to attach a pornographic image file to their emails and then use HTML code to display the attached image. This means that Outlook doesn't need to access the Internet before displaying the picture.

"Historically, spammers have been able to get the emails through by incorporating a link to the file. This is a change in tactic and we've been seeing a lot more of it recently," Cheney said.

Simon McNally, systems engineer at anti-spam firm Borderware, said the bonus for spammers is that they can now create an image that also displays words or a Web address that would otherwise have been intercepted by the spam filter.

"There are hardly any words in the body of the email because they are in the picture itself. This is very hard to track," said McNally.

But McNally points out that because the spammers now have to send an image file, they use more bandwidth and so the same volume of spam costs more and takes longer.

Another disadvantage for spammers is that they can no longer keep track of how many times their images are being viewed. The ability to track live email addresses is likely to be more of an issue than the bandwidth and time constraints, as the majority of spam is sent from computers that have been hijacked by Trojan horses and viruses.

"The email will be larger because it contains the attachment. But they will find an open relay and send it to as many people as possible," said McNally.

Microsoft could not be reached for comment.

Talkback

What a load of tosh. Outlook 2003 blocks HTML to stop Web Beacons - the bits of HTML code that let spammers track which email addresses are live - NOT to stop pornographic images.

via Facebook 21 June, 2004 18:00
Reply

I am such a sucker. I thought the article was actually about comprimised security. This article is such FUD. Embedding images in email has been around for a long time and not just in Outlook. This is just spammers become more desparate and resorting to sending the images in the email. Soon Outlook will have some sort of Bayesian filter for images and then they will claim that Microsoft "fixed the security hole in Outlook". ZDNet - I am so disappointed.

via Facebook 21 June, 2004 18:25
Reply

Spammers can test their emails using Outlook 2003.

All they have to fo is keep trying out new filter-defeating tactics using their own copy of Outlook 2003 until the email they send themselves gets through!

If Microsoft updates the Bayesian filter algorithms in an Outlook patch then fine - the spammer is quickly able to go through the same process again until a message gets through.

Have I depressed you yet?

via Facebook 22 June, 2004 10:31
Reply

You really need to get your facts right. All HTML capable email clients have the ability to display embedded images in HTML. Embedded images have been around for many years now, and are part of the IETF email standards. So you need to credit the IETF with the “invention” – not the spammers.

Embedded images are inherently safe as they do not require external internet connections in order to render properly. Images that are linked from an email to an external Web site are referred to as “Web Bugs” or “Web Beacons” – and these mechanisms pose both privacy and discovery threats.

I suggest that you retract this silly assertion before Microsoft descends to apply a harsh slap. Their software is doing the right thing (in this case) – and has not been breached as you say.

Most technology journalists seem to think that all legitimate email is generated as plain text, and that HTML emails are generated by spammers. This is simply not true – most person to person email is delivered in HTML format these days, and these legitimate communications often contain branding and other embedded content.

via Facebook 22 June, 2004 11:26
Reply

I think our story makes an interesting and valid point about a new tactic used by spammers - and I don't think all embedded images are inherently safe: people lose their jobs because of porn on their hard drives. However, on reflection do think my headline "Outlook's security compromised by spammers" is too broad, so I've changed it to more accurately reflect the content of the story.

Best,

Michael Parsons
News Editor
ZDNet UK

via Facebook 22 June, 2004 11:59
Reply

Damn! It wasn't an article about a new Easter Egg.

via Facebook 23 June, 2004 11:24
Reply

This article fails to communicate the reason for blocking automatic image loading is primarily one of privacy and not intended to prevent unintended viewing of adult images.

This behavior has been unchanged since the first day that Outlook 2003 was available. Spammers have been keenly aware of this behavior since before the release. So there is no news here.

Thanks for wasting my time. With a catchy headline but nothing to say.

via Facebook 23 June, 2004 15:13
Reply

Bayesian filter in Outlook 2003? I think not.

You can see how the filter thing actually works at

http://www.mapilab.com/articles/outlook_spam_filter.html


I can see no sign of bayesian filtering.

via Facebook 23 June, 2004 17:44
Reply

Hi,
but this whole story is nothing new to be honest. I am rejecting allready for several month evey email with embedded images with NoSPAMProxy (freeware on simtel).
Hardly I get any complaints of sender and then I tell them to zip their images. I know its a hard way - but I use email really just to exchange text. So no problem for me....

via Facebook 28 June, 2004 01:44
Reply

I use Outlook Express 6, and have an excellent way of stopping anything from being shown that shouldn't be: turn the preview pane off, and set Outlook to read all messages in *plain text*. That way, no scripts can be run, as the HTML code and embedded Javascript doesn't get executed.

I know I use OE6, but full Outlook should have the same features - I know the Outlook in Office 97 Pro viewed everything in plain text no matter what (much like Windows Messaging.... I think Outlook 97 was just WM rebadged).

But yeah - turning off the preview pane and setting it to view in plain text will stop anything being executed.

via Facebook 6 July, 2004 14:04
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

9 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

17 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

18 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

19 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

21 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

22 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

24 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

1 day ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

1 day ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

1 day ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

2 days ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

2 days ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

2 days ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint