[00:00.000 --> 00:05.900] My name is Doc, and today John Draper will be speaking, but first we have a couple of announcements you may find interesting. [00:06.840 --> 00:13.840] The lock picking session, hands on, in area 8 of the second floor will be running from 2 to 5. [00:13.960 --> 00:15.060] Today there are going to be two tracks. [00:15.300 --> 00:21.280] One's going to be for beginners, the other one will be for the more advanced techniques, and you are welcome and encouraged to bring your own locks. [00:22.660 --> 00:26.240] The second announcement is Kevin Mitnick will be having a book signing at 1 p.m. in the area just outside of room A. [00:28.540 --> 00:31.780] So if you have seen the table set up there, he will be right next to it. [00:31.960 --> 00:36.000] He will be signing copies of his new book, which just walked out of the room. [00:38.680 --> 00:39.380] There it is. [00:42.550 --> 00:44.010] A hand for our lovely model, please. [00:48.800 --> 00:53.000] Alright, our speaker today needs no introduction, but does need access to the mic. [00:53.540 --> 00:57.110] So, I will just talk while we do this. [00:57.610 --> 01:00.780] This is John Draper, known to most people as Captain Crunch. [01:00.780 --> 01:03.220] He is the 13th employee of Apple computers. [01:03.640 --> 01:04.880] He created the modem for apples. [01:05.540 --> 01:09.420] He's the one that discovered if you plug up a hole in a Captain Crunch whistle, it makes an interesting noise. [01:12.620 --> 01:15.360] And he's been at this forever. [01:18.080 --> 01:22.180] If you want to read more about his exploits, I recommend the 1971 issue of Esquire magazine. [01:22.860 --> 01:23.660] It's kind of hard to find. [01:23.740 --> 01:25.300] It seems to get stolen from libraries a lot. [01:29.640 --> 01:35.960] And in other news, Congress just moved to block certain provisions. [01:37.400 --> 01:40.240] Well, you'll have to go to the elevator and see the CNN feed for that. [01:44.480 --> 01:44.960] Alright, the topic for today is where did all that spam come from. [01:59.530 --> 02:00.210] Hi, everybody. [02:00.530 --> 02:01.110] Okay, I'm ready. [02:01.970 --> 02:03.270] Just had to get everything hooked up here. [02:05.350 --> 02:07.250] I don't give you too much time between sessions. [02:08.490 --> 02:09.930] Where did all that spam come from? [02:10.110 --> 02:12.030] Well, I'm going to talk a little bit about all this stuff. [02:12.310 --> 02:14.590] How many of you really get a lot of spam? [02:16.310 --> 02:21.930] How many here would like to see spammers drawn and quartered and hung up on the Tower of London for 30 days and 30 nights? [02:22.890 --> 02:23.330] Okay. [02:23.830 --> 02:33.950] Well, you might be happy to know that over the last month, maybe year, year and a half, I've been one of the leading persons in the war against spam and spammers. [02:35.110 --> 02:40.730] And it all got started about two and a half years ago when I had my own web hosting company, Web Crunchers. [02:40.730 --> 02:46.470] And I basically offered email services and also web hosting services. [02:46.950 --> 02:52.170] And over the past two years, spammers found out about my server. [02:52.470 --> 02:58.850] And at the time I was running Mac OS 9 with the EIMS mail server from Eudora. [02:59.450 --> 03:02.690] And that's not a very secure mail server, let me tell you. [03:03.310 --> 03:10.390] So spammers found out about it and of course they spammed through my network and I wound up on just about every black hole list you can imagine. [03:11.310 --> 03:14.770] So I pretty much gave up on using Shop IP for mail anymore. [03:15.270 --> 03:20.450] And a lot of my customers bailed off of Shop IP like rats leaving a sinking ship. [03:22.650 --> 03:34.490] So, in lieu of the fact that I've had Web Crunchers up for 15 years and I've had about 150 emails in existence for 15 years, they've been collecting a lot of spam. [03:34.790 --> 03:38.670] They wound up on many, many CD-ROMs that spammers were selling. [03:39.290 --> 03:42.490] And of course my users never started using them anymore. [03:42.790 --> 03:48.910] So about a month ago I took out that Apple and put it in an OpenBSD box. [03:49.670 --> 03:52.950] And a really robust server on a really fat pipe. [03:53.510 --> 03:58.430] And now I'm able to offer much better mail services. [03:58.430 --> 04:02.730] And one of the things that I've been doing is I've been basically studying spam. [04:03.830 --> 04:08.350] One of the things I wanted to talk about is the early origin of spam. [04:09.250 --> 04:13.190] Back in the old days were open gateways, lots of them, before 1995. [04:14.630 --> 04:19.090] And ISPs in spammer friendly countries, China, Russia, Costa Rica, and Brazil. [04:19.490 --> 04:26.990] And then of course we've got spam proxies, which are of course not too often used. [04:26.990 --> 04:32.630] And the current origin of spam now is still offshore mail gateways, mostly in China. [04:33.030 --> 04:36.290] But 80% of it comes from infected hosts. [04:36.830 --> 04:37.690] That's right. [04:37.870 --> 04:41.110] People who do real stupid things like opening up attachments. [04:41.790 --> 04:46.090] And they're getting themselves infected with a virus or a proxy. [04:46.790 --> 04:50.570] And that virus goes out there and phones home to a secret server. [04:50.570 --> 04:54.570] The secret server downloads a Trojan into the machine. [04:55.830 --> 05:04.950] And currently right now, in the best estimate, I believe there's approximately 500,000 to 750,000 infected hosts out there on the Internet. [05:05.670 --> 05:15.370] Well, these infected hosts, of course, are being controlled by a small group of people, mostly spam gangs operating out of Eastern Europe. [05:16.010 --> 05:18.070] I've tracked down quite a few myself. [05:19.110 --> 05:27.570] And through a number of, you might say, spam spies, I've been able to infiltrate into their system and learn a lot about how they all work. [05:29.250 --> 05:33.210] The favorite choice of spammers is what we call deferred hacking. [05:33.210 --> 05:41.350] Basically, this means writing an IRC bot, which can be executed from anybody joining a channel. [05:41.870 --> 05:49.150] And it basically tells a... it connects to another server, which is a master controller server. [05:49.490 --> 05:56.610] That master control server then communicates to a number of previously selected infected hosts. [05:56.950 --> 05:59.630] They don't like to use these infected hosts all at once. [05:59.630 --> 06:03.630] They use them a little at a time in the hopes that they won't be discovered. [06:03.910 --> 06:05.410] So they're usually turned off. [06:05.950 --> 06:15.790] A lot of the more sophisticated spammers and hackers who use these infected hosts use a rather interesting way of hiding the fact that the machine is infected. [06:16.170 --> 06:19.190] And this is done through what they call the knock-knock principle. [06:19.610 --> 06:23.450] The way this works is, normally the listener is turned off. [06:23.450 --> 06:25.550] So when you do a port scan, they don't show up. [06:25.930 --> 06:27.270] It's totally invisible. [06:27.270 --> 06:35.750] However, if you send it a series of specially crafted pings with special port numbers in a certain sequence, well, guess what? [06:35.970 --> 06:40.330] You open up a port, the listener activates, and you now can control that proxy. [06:40.850 --> 06:43.210] That then becomes a master controller proxy. [06:43.450 --> 06:44.850] It then controls all the rest. [06:45.310 --> 06:50.810] So it's almost virtually impossible to catch this kind of level of spamming and hacking. [06:50.810 --> 06:53.610] And these are how all the DDoS attacks have happened as well. [06:56.030 --> 06:57.290] Does anybody have a question? [06:57.830 --> 06:58.230] Oh, okay. [06:59.250 --> 07:00.690] So let's talk a little bit... yeah? [07:00.970 --> 07:04.570] Does this affect only people who have high-speed Internet or any machine? [07:05.950 --> 07:09.470] Mostly high-speed Internet users are mostly the ones that are prone. [07:09.630 --> 07:11.110] People leave their machines on all the time. [07:11.110 --> 07:15.730] And they have DSL or cable modem and they do really dumb things. [07:15.850 --> 07:18.790] They leave their machine on and they don't patch their machine. [07:19.010 --> 07:28.010] And then there's this new recent virus problem with the IE Internet Explorer where you visit a website and you're infected just by visiting a website. [07:28.310 --> 07:31.830] So, I mean, there's lots and lots of ways these things can be infected. [07:32.490 --> 07:34.930] Let's talk a little bit about spamming in general. [07:35.650 --> 07:37.610] First thing is the chain of responsibility. [07:37.950 --> 07:39.130] Let me kind of explain that. [07:39.450 --> 07:41.030] A company has a product to sell. [07:41.290 --> 07:44.730] The company contacts some type of mass marketing company. [07:45.050 --> 07:51.570] The mass marketing company basically outsources their work to smaller companies or resellers. [07:52.190 --> 07:54.590] And they maintain and monitor their own list. [07:54.610 --> 07:59.490] Or they can also get a list from the actual company if that company has a website. [07:59.950 --> 08:09.210] And if they have a website that has a website that basically asks for people for information, for product information. [08:09.430 --> 08:12.570] They say, well, if you want product information, fill out this form and we'll send you something. [08:13.270 --> 08:19.990] And they'll often think that if somebody's interested in a product, that, yeah, they'll go ahead and add that person to the mailing list. [08:20.090 --> 08:21.670] These are clean mailing lists, by the way. [08:21.870 --> 08:23.750] And these are people that are already opted in. [08:24.130 --> 08:31.390] And then, of course, they pass this on to the mass marketing company, which outsources it to other people who then actually do the spamming. [08:31.670 --> 08:34.130] And the marketing company can be anywhere. [08:34.350 --> 08:37.350] In most cases it's in China, sometimes in Eastern Europe. [08:39.190 --> 08:45.890] And so basically the selling company is already two levels removed from the spammer, making it really difficult to nail the spammer. [08:46.350 --> 08:51.810] And the best way is to go after the spammortized website owners and the beneficiary of the spam. [08:53.910 --> 08:55.990] The mail trail pretty much is a dead end. [08:55.990 --> 09:01.730] To trace the mail headers and find out where the spam comes from, you can pretty much guess it's going to come from some infected host. [09:02.010 --> 09:03.750] And that's about as far as you're going to get. [09:04.450 --> 09:09.290] And of course the ISPs are not going to tell you who that is because they've got privacy policies they have to respect. [09:11.470 --> 09:14.150] Spammortized websites also have no contact information. [09:14.230 --> 09:22.530] But they have, often have 800 numbers or forms page for sucking in suckers that want to buy whatever they're going to hawk out and sell. [09:23.770 --> 09:26.710] Registered domain contact info is often false and bogus. [09:27.310 --> 09:32.650] So you can't really use domain ownership and the who is to find the location of a spammer. [09:32.910 --> 09:38.150] Most of the domains that end in .biz are often in Costa Rica. [09:38.830 --> 09:46.230] And often these registrars that register these domain names don't really give a hoot about whether the information is accurate or not. [09:46.230 --> 09:48.490] So that's really not a good way to track it down. [09:48.690 --> 09:51.150] But the best way is follow the money trail. [09:51.870 --> 09:54.370] Yes, go out and buy one of these things that they sell. [09:54.770 --> 09:56.550] Look at your bank statement afterwards. [09:56.810 --> 09:57.890] Find out what the bank is. [09:58.670 --> 09:59.690] Contact the bank. [09:59.870 --> 10:00.670] Claim fraud. [10:01.110 --> 10:03.190] Do whatever you have to do to get the information. [10:03.870 --> 10:05.450] And pass it on to the authorities. [10:06.150 --> 10:09.050] And you can pretty much get really close to the spammer that way. [10:09.710 --> 10:12.830] And if they ship something to you, you can also follow the shipping trail. [10:12.830 --> 10:14.430] Look at the shipping label on your package. [10:14.710 --> 10:16.090] Find out where it was shipped from. [10:17.570 --> 10:19.050] Okay, spam gangs. [10:19.670 --> 10:21.130] Yeah, I run into these guys. [10:21.470 --> 10:23.730] Spam gangs are an interesting lot. [10:24.290 --> 10:30.530] To give you an idea, let me see if I can show you a sample mail here [10:34.410 --> 10:37.370] in my spam to investigate folder. [10:39.470 --> 10:48.330] And while that's doing its thing, I'm going to go back over here to my presentation and go back to that later. [10:55.810 --> 10:56.690] Spam gangs. [10:56.930 --> 11:03.370] Well, I found spam gangs basically by accident. [11:03.750 --> 11:10.470] One of the interesting things that I worked on is when I send out an email to anybody that I know. [11:10.690 --> 11:13.090] I have a hash code built into the email. [11:13.450 --> 11:21.090] Like instead of my email being crunch at shopip.com, my email really is crunch9364 at shopip.com. [11:21.330 --> 11:27.590] That 9364 is a random unique number that's assigned when I compose a new message to somebody. [11:27.810 --> 11:33.950] So if I send a message to somebody for the very first time, they get assigned a number that uniquely identifies them. [11:33.950 --> 11:37.110] So when they send a mail back to me, I know where it came from. [11:37.330 --> 11:46.810] If he goes off and tattletales and tells somebody else what my email address is, and that person starts using my email, I can trace it back to the original person that I gave the email to. [11:47.330 --> 11:52.490] If a spammer finds out where my email address is, well, I know exactly who gave that email address out. [11:52.550 --> 11:55.190] And I could go after the person and say, shame on you for doing that. [11:55.430 --> 11:56.910] Well, here's something else that I've done. [11:57.710 --> 12:01.850] For a while, I've been opting out of spam just to see how effective it is. [12:02.810 --> 12:06.230] And, well, I found out some really interesting things. [12:06.630 --> 12:10.530] I found out that, yes indeed, sometimes opting out does work. [12:10.910 --> 12:21.950] And on other times when I opt out, all of a sudden, when I opt out, I take that hash code that's built into my email address and I log it into a database. [12:22.530 --> 12:27.370] So now when I get email from a spammer, let's see if it's ready. [12:33.700 --> 12:36.100] I think my email is kind of messed up for some reason. [12:37.560 --> 12:39.260] Yeah, I won't worry about it right now. [12:41.320 --> 12:49.840] So when I actually send it to a spammer, the spammer goes ahead and gives out that email address with that funny-looking code on it. [12:49.880 --> 12:57.280] And I was going to actually show you some sample emails from some spammers that I've gotten with this number on it. [12:57.520 --> 13:00.400] And it's not just one, it's 20 or 30. [13:00.860 --> 13:06.120] So I proved beyond a reasonable doubt that, yes indeedy, spammers do sell your email address out. [13:06.580 --> 13:08.000] I can prove that. [13:09.580 --> 13:11.200] So, reporting spam. [13:11.480 --> 13:11.640] Yeah? [13:12.380 --> 13:13.900] I said shock, surprise. [13:14.220 --> 13:16.860] Yeah, well, we've all known that anyway, but I went out and proved it. [13:18.120 --> 13:18.960] Spam gangs. [13:19.220 --> 13:20.880] Okay, spam gangs are well-funded. [13:20.880 --> 13:25.820] Mostly in Eastern Europe, and they mostly are the ones that are cranking out the viruses and exploits. [13:25.860 --> 13:42.900] For instance, the Sobig virus was probably developed by a Russian hacker somewhere that was paid pretty high dollar from the Russian mafia, which often is used to fund spam operation mostly for their porn sales. [13:42.900 --> 13:48.380] And what they do is they offer what they call bulletproof hosting. [13:48.760 --> 13:53.420] How many of you have gotten an email message touting and claiming bulletproof hosting? [13:53.880 --> 13:56.280] Well, guess who's hosting your server? [13:56.780 --> 13:58.540] It won't be a regular server. [13:58.660 --> 14:01.980] It won't be sitting in some box on some co-location facility. [14:01.980 --> 14:03.020] I can assure you that. [14:03.320 --> 14:10.720] It'll probably be Aunt Jemima's computer that she happens to like to leave on with a screensaver, and it's her computer that's hosting all that spam mail. [14:10.940 --> 14:13.320] Or it could be the church group leader for all they know. [14:13.660 --> 14:16.580] But that's who's hosting most of the spam. [14:16.780 --> 14:22.380] I did this by actually tracing through one particular one. [14:22.480 --> 14:32.580] It's called gordontower.com forward slash something, colon, and then it's 3116 or something like that. [14:32.580 --> 14:35.760] That's the port number that you specify. [14:36.060 --> 14:37.340] So it doesn't use port 80. [14:37.640 --> 14:39.660] It doesn't use any of these other ports. [14:39.800 --> 14:41.160] It uses an odd port number. [14:41.660 --> 14:46.280] And they've got a little web server running on their machine that they don't even know about. [14:46.460 --> 14:49.200] Along with all the porn on their machine as well. [14:49.620 --> 14:56.000] And this was done through the use of infected hosts. [14:56.980 --> 15:06.700] And with the current job situation like in this country, with all the outsourcing going on and all these programmers out of work, somebody comes up to you and offers you $35,000 to provide a virus. [15:06.900 --> 15:09.560] And you're about four months overdue in your rent or car payments. [15:09.620 --> 15:10.780] What are you going to do? [15:11.760 --> 15:12.240] Yes. [15:12.600 --> 15:15.340] Well, there are people, of course, that do have desperate needs. [15:15.720 --> 15:21.120] And no doubt, they were often recruited to do these kinds of things. [15:22.560 --> 15:26.220] So we've done a lot of infiltration into these mailing lists. [15:26.380 --> 15:28.740] I have a lot of people in Russia that I know. [15:29.380 --> 15:31.880] I'm very familiar with Eastern Europe and Europe myself. [15:32.080 --> 15:33.140] I've traveled there many times. [15:33.280 --> 15:37.320] I know a lot of friends in Yugoslavia, Bulgaria, and Romania. [15:38.080 --> 15:39.600] And as well as Russia. [15:40.140 --> 15:41.580] And also Ukraine. [15:42.180 --> 15:44.300] And, of course, lots of German people, too. [15:44.500 --> 15:46.260] So I'm very familiar with these people. [15:46.440 --> 15:48.660] And I can even read Russian. [15:48.660 --> 15:53.740] So I have no problem going into the Russian websites to learn what they do and what they're saying. [15:54.620 --> 15:56.940] And so this is sort of one of the things that I've done. [15:58.760 --> 15:59.540] Reporting spam. [15:59.760 --> 16:01.640] I highly encourage you to report spam. [16:01.940 --> 16:05.000] The only problem with reporting spam is it's very time consuming. [16:05.460 --> 16:06.780] There are several ways you can do it. [16:06.860 --> 16:07.860] You can do it the easy way. [16:07.940 --> 16:10.300] So signing up for a spam cop. [16:11.140 --> 16:12.440] It's a good way to do this. [16:12.580 --> 16:16.300] But again, it takes a lot of time to set that up and to report it. [16:16.300 --> 16:18.320] And you can get free reporting. [16:18.840 --> 16:20.980] Or you can pay for the reporting. [16:21.180 --> 16:24.740] And it's about a dollar a megabyte of spam. [16:24.940 --> 16:28.580] So if you want to report 15 megabytes of spam, it's going to cost you 15 bucks. [16:29.480 --> 16:32.360] So that's roughly what the spam cop's prices are. [16:32.420 --> 16:34.780] The advantage of paying versus not paying is pretty simple. [16:35.080 --> 16:38.460] If you're not paying, spam cop puts this thing called a nag screen up there. [16:38.640 --> 16:40.980] It's a built-in 15, 20 second delay. [16:40.980 --> 16:45.060] So it makes it very inconvenient when you really want to report a lot of spam. [16:45.300 --> 16:46.480] It takes very time consuming. [16:48.800 --> 16:54.140] The next thing, of course, is what you want to do reporting. [16:54.680 --> 16:59.480] And the reason why you want to do reporting is the fact that you can point out where these infected hosts are. [16:59.800 --> 17:01.580] They're actually telling you where they are. [17:01.720 --> 17:06.340] If you have a lot of spam sources, you can go and get exactly all these infected hosts. [17:06.340 --> 17:07.960] And, of course, this is kind of neat. [17:09.580 --> 17:11.700] And if you don't have much to report, no problem. [17:11.880 --> 17:13.280] You just go into spam clenching. [17:13.700 --> 17:17.700] What we've done is we've been working on a very aggressive spam reporting. [17:18.080 --> 17:22.240] I have a patented system right now that takes an IP address of a mail. [17:22.660 --> 17:28.700] And it returns back an email of the ISP where that mail came from. [17:28.700 --> 17:44.820] So, in other words, if this mail came from Comcast.net or Comcast.com or whatever they're called, I take this IP and I have a way of taking that IP and converting it into an email address. [17:45.440 --> 17:52.000] And what I do is I have a very, very large collection of spam in an inbox format. [17:52.680 --> 17:54.240] I'll show you some in just a minute. [17:54.740 --> 18:02.480] And this inbox formatted spam will then allow you to send this to the spam reporter. [18:02.840 --> 18:04.840] The spam reporter does two things. [18:05.060 --> 18:07.340] It takes it and breaks it up into two different sections. [18:07.800 --> 18:13.660] The first section is spam that it can find the email address of from the IP address. [18:13.920 --> 18:17.880] And, of course, there's always going to be some spam that you can't find the IP address of. [18:18.380 --> 18:21.160] So, it breaks it up into bad spam and good spam. [18:21.520 --> 18:24.720] The bad spam generates a list of IP addresses. [18:25.100 --> 18:28.280] This list of IP addresses is then fed into another program. [18:28.520 --> 18:33.000] It goes out there and does a who is on the database for that IP address. [18:33.480 --> 18:37.120] And it generates a file not unlike this file right here. [18:37.400 --> 18:38.460] I thought I'd bring it up real quick. [18:39.500 --> 18:40.220] Let's see. [18:41.180 --> 18:42.420] You go to my database. [18:44.200 --> 18:45.900] And it would look something like this. [18:46.780 --> 18:54.260] This particular file here has an IP block followed with the appropriate email address where to send the spam from. [18:55.400 --> 18:57.820] And this is generated in a very cool way. [18:58.000 --> 18:59.460] It's automatically generated, of course. [18:59.980 --> 19:00.920] It does a who is. [19:01.140 --> 19:05.120] It determines the IP block by reading the objects out of the who is record. [19:05.760 --> 19:09.660] It does a really good job of trying to guess whether there's an abuse contact or not. [19:09.660 --> 19:12.680] If there isn't abuse contact, it assumes there's one. [19:12.840 --> 19:16.100] It goes out and actually tries to make an email connection to abuse. [19:16.380 --> 19:17.940] And it sends a little probe message. [19:18.280 --> 19:20.340] The probe message is something to this effect. [19:20.740 --> 19:21.140] Hi. [19:21.720 --> 19:23.420] We're getting spam from your network. [19:23.600 --> 19:26.440] We would like to know if this is the right place to send it. [19:26.980 --> 19:28.440] And they'll come back with a report. [19:28.440 --> 19:31.520] And if they come back with a report, they might know that this is a good email. [19:32.040 --> 19:34.700] Very often, of course, I get bogus email addresses. [19:34.980 --> 19:43.360] Because if we go in with Aaron, APNIC, and the likes of these other registry systems, you'll find that the information in there is often outdated and old. [19:43.580 --> 19:49.460] So what the spam reporter does, it actually will send a report to the thing. [19:49.460 --> 19:51.680] So let me, for instance, go through here. [19:52.480 --> 19:56.180] And I'll find, let's say, APNIC. [20:00.460 --> 20:01.500] Here's one down here. [20:01.700 --> 20:06.500] This one, 061.066, info at APNIC.net. [20:06.720 --> 20:10.800] That right there, that IP address has got bogus who is information. [20:11.060 --> 20:19.780] But when I say info at APNIC.net, what it does, it sends a bogus who is report to the APNIC.net and requests a tracking number. [20:19.780 --> 20:22.140] So it automatically does this. [20:22.700 --> 20:26.220] So whenever there's a spam, it can't determine what the IP address is. [20:26.340 --> 20:26.880] It does that. [20:27.320 --> 20:35.100] Now, if it's a big IP block, I can also go through the Looking Glass server and extract information on the upstream provider. [20:35.340 --> 20:37.520] And I could hassle them if I really want to. [20:37.900 --> 20:42.920] So this is sort of what the database sort of looks like in one form or another. [20:43.760 --> 20:45.340] Okay, going back to my slides. [20:52.770 --> 20:54.510] Very aggressive spam reporting. [20:55.010 --> 21:01.690] Well, the very aggressive spam reporting, in order to really do it right, you need a database of IP blocks versus abuse report emails, which I've just shown you. [21:02.230 --> 21:06.950] I can report up to 8,000 spams a day from our users with our service. [21:07.090 --> 21:12.450] It's the service that I offer for us, for our people on my network, and I automatically report spam. [21:12.450 --> 21:13.890] I run the report twice a day. [21:14.130 --> 21:17.330] So I do it in two blocks of about 4,000 spams each. [21:18.170 --> 21:22.610] It's resulted in the shutdown of approximately 150,000 infected hosts per month. [21:22.870 --> 21:23.810] Not too bad. [21:24.070 --> 21:27.630] So we are causing... we are being a real thorn in this side of spammers. [21:28.130 --> 21:31.810] Because it's causing them very severe headaches, and they're running out of these hosts very fast. [21:31.950 --> 21:32.770] How do I know this? [21:32.770 --> 21:39.490] I know this because I'm actually spying on the spammers network by going into their chat channels and hearing what they have to say about it. [21:40.390 --> 21:42.930] The reports are sent within minutes of getting them. [21:43.590 --> 21:47.530] Our newer system, when we get it implemented, is going to be through an incoming filter. [21:47.530 --> 22:00.990] The way that works is, when spam comes in, if it's filtered to be spam, if the filter actually detects if it's indeed spam, and what it does, it immediately sends the report back within 30 seconds of getting the mail. [22:01.130 --> 22:05.570] So the ISP can get, in real time, an indication that this spammer is active. [22:06.230 --> 22:11.170] And ISPs that subscribe to our service can then shut down the infected host almost immediately. [22:11.170 --> 22:17.130] So we're getting, we're getting almost real-time spam shutdowns of the system now. [22:18.430 --> 22:21.810] And, uh, so here's some nasty things you can do with the spammers. [22:22.090 --> 22:22.310] Okay. [22:22.710 --> 22:26.290] Let's say you have a, uh, a mortgage spammer. [22:26.410 --> 22:31.410] And he sends you a, uh, uh, an email address, and it's got a website. [22:31.750 --> 22:36.450] And you go to the website, and usually these mortgage spammers are the best ones to really pick on. [22:36.930 --> 22:43.670] They've got a forms page that requires you to send in your address, phone number, your email, and all that stuff. [22:43.930 --> 22:47.510] So you fill out the forms page, some fields are required, others aren't. [22:47.670 --> 22:54.210] What I do is I take that forms page, the HTML of that forms page, and I copy that to my own server. [22:54.710 --> 23:04.070] Well, the action tag in a forms page contains the CGI calls, which get called when you fill out that forms page. [23:04.270 --> 23:11.550] Instead of me putting in their CGI action form, I put my own CGI action form, and I add two buttons to the web page. [23:12.030 --> 23:19.310] One button is mass, uh, I can, I can call it like multiple submissions or whatever it is. [23:19.630 --> 23:24.650] And then another button is just, you know, uh, I forget what the other button was, what I used it for. [23:24.870 --> 23:31.350] But, uh, when you click on that button, what happens is, uh, it doesn't go to their CGI, it goes to my CGI. [23:31.810 --> 23:39.430] My CGI then goes to the forms page, submits the forms page, but instead of me, instead of it going to... [23:39.990 --> 23:45.350] So what I do is I take the, the action tag, and then I send the action tag through my server. [23:45.570 --> 23:51.150] So it makes it look like as if I'm actually going in, filling in that forms page, but this one does it automatically. [23:51.150 --> 23:57.050] And I've got a huge database of bogus email addresses and, and bogus, uh, uh, addresses. [23:57.290 --> 24:00.990] And I could just swamp their server with thousands and thousands of reports per minute. [24:01.170 --> 24:04.430] And it, and it can, you know, and of course you've got to be careful. [24:04.530 --> 24:07.110] You don't want to do anything illegal, so you wouldn't want to do it too often. [24:07.270 --> 24:08.870] So I put a little delay in there. [24:09.290 --> 24:10.970] You know, maybe one or two seconds. [24:14.970 --> 24:17.770] Well, suffice it to say that really got their attention. [24:17.770 --> 24:20.730] The next day, I got back an email message. [24:21.090 --> 24:24.830] Because what I did was, I actually was using my honeypot of email addresses. [24:25.270 --> 24:29.950] The crunch, 8263 at whatever, those email addresses were like my throwaway ones. [24:30.130 --> 24:33.550] So they were sending me back email addresses on these things saying, why are you doing this? [24:35.570 --> 24:37.330] And I said, why are you spamming me? [24:39.530 --> 24:41.530] So this works most of the time. [24:41.690 --> 24:44.210] However, it depends on how they've implemented their pages. [24:44.450 --> 24:45.970] Now they're getting a little wiser. [24:45.970 --> 24:48.070] And they're preventing you from doing that. [24:48.230 --> 24:49.890] Because what they do is they check the referrer. [24:49.970 --> 24:56.530] And if the referrer isn't the same as your original page submission, then they could probably block you. [24:56.730 --> 25:00.210] It depends on how they wrote the PHP code that did their web page. [25:01.070 --> 25:02.030] And so... [25:02.030 --> 25:07.250] And also what I do is I flood the mailing list with bogus email addresses and poison their list. [25:08.270 --> 25:10.110] And that's one of my favorite ones too. [25:10.110 --> 25:17.330] And I just do as much as I can to just give them as many email addresses that are perfectly valid email addresses. [25:17.550 --> 25:18.750] Oh, they won't bounce. [25:19.110 --> 25:22.790] When they send an email, it'll show that it's indeed truly an email. [25:23.490 --> 25:28.030] I have a little auto-replier on there that kind of sends something back saying, hi, how are you? [25:30.190 --> 25:31.050] Something like that. [25:31.050 --> 25:36.390] And by the way, go out and find the Woz tomorrow if you see him around there and get some prank ideas from him. [25:38.170 --> 25:39.230] Trojans and viruses. [25:39.950 --> 25:40.470] Okay. [25:40.870 --> 25:45.070] These are the main tools that spammers and hackers use to send spam to you. [25:45.490 --> 25:48.190] Like I said earlier, they're virtually impossible to trace. [25:49.270 --> 25:51.670] They use deferred hacking, IRC bots. [25:52.230 --> 25:54.730] The knock-knock protocols, of course. [25:54.970 --> 25:57.970] And we've got good success in stopping them in real time. [25:57.970 --> 26:00.750] But only effective at a large ISP level. [26:01.430 --> 26:03.090] Here's how I do it. [26:03.650 --> 26:06.870] I take a honeypot. [26:08.150 --> 26:10.270] And it's on an isolated network. [26:10.590 --> 26:19.230] I have some friends up in Twainheart, which is in the mother load, which has given me a beautiful, fantastic IP block that I can use for whatever I want to use it for. [26:19.470 --> 26:23.470] So what I have is I've got a Windows machine running VMware. [26:23.790 --> 26:26.210] It runs several operating systems on it at the same time. [26:27.330 --> 26:29.550] And one of them is Windows XP. [26:29.710 --> 26:31.070] Another one is Windows 2K. [26:31.690 --> 26:39.270] And then I have another box, which is an OpenBSD box running all kinds of sniffers, port scanners, and hacker tools, and everything on it. [26:39.410 --> 26:41.930] And it's designed primarily to analyze the network. [26:42.070 --> 26:44.270] It's got protocol analyzers and stuff on it as well. [26:44.270 --> 26:48.570] So what we do is we take a Windows machine. [26:48.630 --> 26:50.690] We establish what is called a baseline. [26:51.050 --> 26:56.450] A baseline is an analysis of the machine before anything happens is ever attached to it. [26:56.590 --> 27:00.950] It's just an indication of all of the registries that are on it currently. [27:00.950 --> 27:02.030] It's a clean machine. [27:02.470 --> 27:08.850] It's just been created from a VMware original install of a Windows machine. [27:09.450 --> 27:15.370] And then we monitor the traffic on that without the actual virus running. [27:15.570 --> 27:18.070] And we get an idea of what kind of network traffic it generates. [27:18.170 --> 27:20.610] And it generates a little bit of network traffic, but not very much. [27:21.390 --> 27:26.110] After we've determined the baseline, we then take one of the infected PCs. [27:26.510 --> 27:28.890] I take one of my viruses, and I've got a whole bunch of them. [27:29.490 --> 27:31.630] And I infect the machine with the virus. [27:31.830 --> 27:34.490] I run the sniffer, and I see what happens. [27:34.790 --> 27:36.010] And I log everything. [27:36.210 --> 27:38.830] I take every bit of traffic and just completely log it. [27:39.210 --> 27:41.850] It's in PCAP format, like most of the sniffers are. [27:42.110 --> 27:46.310] And then I have another program that goes through and analyzes this PCAP stuff. [27:46.310 --> 27:50.390] And analyzes it and determines what protocol it uses. [27:50.950 --> 27:51.910] Extracts the protocol. [27:52.330 --> 27:56.030] And then after that, it then generates a Snort rule for it. [27:56.410 --> 28:01.290] And then I test the Snort rule for it by taking that PCAP data, feeding it back into the Snort. [28:01.490 --> 28:03.150] And verify that I can detect it. [28:03.890 --> 28:06.030] And it can even detect the knock-knock protocol. [28:06.370 --> 28:08.590] Because all we need to do is detect it. [28:08.650 --> 28:09.910] Who cares whether it's encrypted? [28:10.090 --> 28:10.930] We don't care about that. [28:11.030 --> 28:12.730] All I care about is, can I detect it? [28:12.810 --> 28:13.130] Yes or no? [28:13.210 --> 28:13.750] Is it there? [28:13.930 --> 28:14.690] Is it not there? [28:14.690 --> 28:15.870] That's all I care about. [28:16.050 --> 28:20.790] If it's there, the IDS sends a command to the firewall to block the port in real time. [28:21.070 --> 28:22.610] Stopping the virus right in its tracks. [28:23.150 --> 28:24.890] The crunch box is really good for that, by the way. [28:25.610 --> 28:28.930] So a complete spam fighting toolkit includes a UNIX box. [28:29.390 --> 28:32.070] A wind blows box, which is our sacrificial lamb. [28:32.310 --> 28:35.030] And the ability to read capture data and write Snort rules for them. [28:36.430 --> 28:41.050] And with this, you can go out there and analyze viruses and all kinds of neat things. [28:41.590 --> 28:50.010] And the production network, this is a network that you're going to be using for your web server, your services, whatever you're going to use, your company's network. [28:50.410 --> 28:52.070] You'll need an IDS Snort. [28:52.250 --> 28:54.670] You'll need the Snort output coupled to a firewall. [28:55.030 --> 28:57.010] Again, the crunch box does all that for you. [28:57.010 --> 29:02.390] But it's not very hard to write a script that'll take a Snort output and control the firewall. [29:02.590 --> 29:03.370] You've got to be careful, though. [29:03.490 --> 29:05.330] You only want to do this on certain ports. [29:05.610 --> 29:13.050] You don't want to just be switching off, turning on your firewall for things that aren't necessary, of course. [29:13.990 --> 29:19.870] And then at that point, it just simply drops packets going to and from the infected host using the port numbers used by the virus. [29:20.630 --> 29:22.250] Detects the knock-knock protocol as well. [29:22.250 --> 29:24.690] And the machine owner is not even aware this is happening. [29:25.170 --> 29:30.250] And the beauty of it is, the owner of the machine, it doesn't violate their privacy at all. [29:30.410 --> 29:31.850] It doesn't interfere with their service. [29:32.130 --> 29:33.610] It doesn't cut off their service. [29:33.790 --> 29:36.990] It just disables the virus in real time, which is really important. [29:37.150 --> 29:39.050] And that stops the worm in its tracks. [29:39.250 --> 29:41.370] We've had very good success with this technique. [29:42.270 --> 29:46.190] And one more last bit of thing I want to talk about is avoid being spammed. [29:47.950 --> 29:51.670] The thing you want to really have is you really want to have two email addresses. [29:52.170 --> 30:01.150] One, your private email address is used for your close friends, associates, your business people, the people you work with in your work or whatever you're doing. [30:01.430 --> 30:03.310] And then have another email address. [30:03.530 --> 30:07.350] And it's not uncommon that you just have like a Hotmail email address or something like that. [30:07.450 --> 30:08.950] This is a throwaway email address. [30:08.950 --> 30:18.910] And you would use this for doing things like posting the USENET, going up on mailing lists, filling out web forms pages, website contacts, and stuff like that. [30:19.230 --> 30:21.570] So use your private email, of course, for close friends. [30:21.690 --> 30:23.570] And never give out your email to those you don't trust. [30:23.810 --> 30:24.950] It's another important thing. [30:25.490 --> 30:27.750] Okay, and I'll finish off with my contact information. [30:27.750 --> 30:29.290] This is how you can contact me. [30:29.690 --> 30:37.610] And if I'm running a little early on this, I can probably see if I can get this mail thing working and show you some real cool things. [30:37.610 --> 30:40.630] I just need some time to just get this thing restarted. [30:40.950 --> 30:44.090] And in the meantime, I can answer any questions at this point. [30:44.230 --> 30:46.330] So if you have any questions, this is a good time to answer them. [30:46.750 --> 30:47.430] Or ask them. [30:52.560 --> 30:57.420] If I were a spammer and I were to send you a web form or something, why write it in PHP? [30:57.860 --> 30:59.540] Well, I'm just using that as an example. [30:59.680 --> 31:01.320] You could write it into whatever language you want. [31:01.440 --> 31:01.820] It doesn't matter. [31:02.080 --> 31:05.480] Well, if I were a spammer, I would do it in ASP.NET. [31:05.480 --> 31:09.800] So, and I'll just get that so that it could easily be the source code to be not tagged. [31:10.260 --> 31:12.940] And so, and to prevent myself from getting... [31:12.940 --> 31:15.400] Well, I'm sure some people do that, you know. [31:15.620 --> 31:16.760] But a lot of people don't. [31:17.120 --> 31:19.380] And it's those people don't that I can really have fun with. [31:27.480 --> 31:28.100] What's that? [31:31.450 --> 31:32.230] What were you saying? [31:32.610 --> 31:33.370] Yeah, go ahead. [31:34.210 --> 31:35.190] You in the middle there. [31:39.730 --> 31:40.170] Exactly. [31:40.590 --> 31:42.830] I don't report them to the authorities. [31:44.610 --> 31:46.970] Reporting spam to the authorities is a waste of time. [31:47.110 --> 31:56.050] I mean, for one thing, okay, even though my server had been attacked, I could easily substantiate more than $5,000 or $6,000 in losses. [31:56.350 --> 31:58.390] I have tried to report it to the authorities. [31:58.390 --> 31:59.890] But guess what? [32:00.050 --> 32:03.310] There's not equal justice for all anymore in this country. [32:03.310 --> 32:04.270] Unless you're Microsoft. [32:04.510 --> 32:07.670] If I was Microsoft, I could probably get the attention of the FBI. [32:08.090 --> 32:11.790] But I have tried many times to file reports and I have not been able to do it. [32:11.910 --> 32:11.930] Yeah? [32:12.950 --> 32:17.820] Have you thought about the potential for abuse of this sort of thing? [32:18.320 --> 32:18.640] Absolutely. [32:18.980 --> 32:20.320] And this is one of the reasons why I'm not... [32:20.320 --> 32:22.900] I've taken down my thumb over the grudge who just forged a spam cop. [32:23.100 --> 32:23.420] Absolutely. [32:24.180 --> 32:25.580] And I had to hear from my upstream. [32:26.280 --> 32:26.600] Absolutely. [32:26.980 --> 32:30.000] And I have very, very formal thoughts on that. [32:30.100 --> 32:31.900] Let me tell you how I'm going to be dealing with that. [32:33.100 --> 32:36.720] Number one is I'm not going to be releasing this to the public, number one. [32:37.420 --> 32:40.980] Only because it does have a lot of potential for abuse. [32:41.200 --> 32:51.320] If your girlfriend's email is in that spam pot ready to send out spam, you can best bet your tweet dippy that her email address will be hosed by the Internet service provider. [32:51.320 --> 32:57.740] I have, in early testing, have overlooked some email messages that should not have been in there. [32:57.960 --> 33:01.180] Yes, indeedy, I have had people's Internet services interrupted. [33:01.520 --> 33:03.120] And it has caused some problems. [33:03.260 --> 33:04.640] Yes, that is a problem. [33:04.880 --> 33:10.060] However, I have a way around to make it as easy as possible for somebody to do that. [33:10.060 --> 33:26.640] If and when I get around to putting a web-based interface on this and making it available to my web crunchers users, I'm going to have a system set up so that when I view, I'm going to have what is called a viewing system that can view 50 messages at a time on one screen full. [33:26.640 --> 33:32.420] And you can just very quickly glance down through, page 50 at a time, 50 at a time. [33:32.620 --> 33:36.820] It's pretty easy to visually spot HTML code because most of this stuff is HTML. [33:37.300 --> 33:41.820] So it's not too hard for me to just click on the check box of the ones I don't want to send. [33:42.320 --> 33:49.180] And only when I page through every single page of the spam pot that I'm going to send will it let the reporter actually do the reporting. [33:49.640 --> 33:53.580] So yeah, there is a definite means of abuse. [33:53.740 --> 33:53.780] Yeah? [33:53.780 --> 33:54.760] Two things. [33:54.980 --> 34:00.900] When you say turn off your DSL, if I have DSL, do you think I should just turn off the DSL modem? [34:00.980 --> 34:04.420] I mean, I turn off my computer, but just turn off the DSL modem? [34:04.480 --> 34:05.020] Is that what you're saying? [34:05.120 --> 34:05.680] Oh, absolutely. [34:05.680 --> 34:08.440] If you're not using your DSL modem, why leave it on, you know? [34:08.680 --> 34:14.780] A lot of people just don't bother because they know that they can be on forever and not have to pay any extra. [34:15.100 --> 34:16.840] They don't bother to turn their machine off. [34:16.940 --> 34:17.640] They just leave it on. [34:17.640 --> 34:25.320] Or if you have like a Netgear router and you hook it up to your DSL, you know, unless you turn your router off, you know? [34:25.880 --> 34:27.440] Normally you just leave it on all the time. [34:27.560 --> 34:29.020] You have your little subnet inside your house. [34:29.120 --> 34:30.360] More than one person can use it. [34:30.840 --> 34:32.380] I mean, that's pretty common. [34:33.940 --> 34:35.840] Let's see if I can get this mail started again. [34:36.620 --> 34:40.500] For some reason or another, my mail program has not really been functioning correctly. [34:40.500 --> 34:42.460] It's been going really weird. [34:44.320 --> 34:56.600] Any thoughts on the popular use of services like Spam Gourmet and Mailinator and also on mail filters or, you know, spam filters as a defense against spam? [34:56.860 --> 34:57.840] Yeah, yeah, yeah. [34:57.960 --> 34:59.260] We work with spam filters. [34:59.480 --> 35:00.700] I mean, we have a Bayesian filter. [35:00.980 --> 35:04.280] Plus one of my partners is working on a really, really good filter. [35:04.280 --> 35:08.640] But the only problem is this good filter is extremely slow. [35:09.000 --> 35:10.400] I mean, it's infinitely slow. [35:11.060 --> 35:17.140] So it's... I'm not really sure how accurate it is, but I can tell you this. [35:17.400 --> 35:22.340] That after filtering 250,000 messages, not one message was ham. [35:22.720 --> 35:25.780] And ham is my definition of something that's not spam. [35:26.380 --> 35:29.100] So it's very, very good, actually. [35:31.340 --> 35:31.820] Yeah. [35:32.120 --> 35:34.960] I have a question about the opposite of what you've been talking about. [35:35.640 --> 35:42.700] I get barrages of bounce messages from spam that's being sent out using some of my domain names. [35:42.780 --> 35:43.040] Right. [35:43.300 --> 35:46.700] They're using your... they're hijacking your email address is what they're doing. [35:46.900 --> 35:48.180] And I don't know what to do about that. [35:48.380 --> 35:48.620] Yeah. [35:48.880 --> 35:51.220] That's often referred to as a Joe job. [35:51.780 --> 35:54.680] And this happens... this happens a lot. [35:55.120 --> 36:02.540] And there's not really much you can do about it except identify where the mail comes from and shut the host off that's sending you that bounce. [36:03.000 --> 36:05.320] That's probably the best thing you can do at this point. [36:09.570 --> 36:10.020] Question. [36:10.420 --> 36:10.660] Mm-hmm. [36:11.520 --> 36:11.820] Hold on. [36:12.740 --> 36:13.050] Okay. [36:13.340 --> 36:16.460] I've been having a lot of problems with comment spam on my website. [36:16.460 --> 36:19.050] And I'm wondering if you can talk about the mechanisms behind that. [36:19.050 --> 36:24.000] And then they generally... there's generally an ISP or an IP address which goes along with. [36:24.100 --> 36:25.480] And I'm wondering if those are generally of any use. [36:25.570 --> 36:28.340] I notice they tend to be... the first couple of digits are generally the same. [36:28.620 --> 36:28.780] What? [36:28.960 --> 36:29.620] Comment spam? [36:29.740 --> 36:30.880] Comment spam on my blog. [36:31.050 --> 36:32.380] Like, they'll come... they'll post to my website. [36:32.400 --> 36:33.620] It's like, you have a great site. [36:33.740 --> 36:34.550] My name is Fentermine. [36:34.660 --> 36:35.420] Please visit my site. [36:35.550 --> 36:36.070] You know, so... [36:36.070 --> 36:36.880] Yeah, yeah. [36:36.920 --> 36:37.800] I get a lot of that too. [36:39.120 --> 36:41.900] And I'm just wondering if you know, like, how are they... how are they finding my site? [36:42.000 --> 36:43.660] And is there any way to sort of block them from getting there? [36:44.340 --> 36:44.840] What's that? [36:46.070 --> 36:47.420] I'm not exactly sure. [36:48.940 --> 36:50.380] What you can do about that. [36:52.680 --> 36:53.240] What's that? [36:54.340 --> 36:55.800] Well, there's several ways around it. [36:55.900 --> 37:07.260] I mean, you know, you can... if it's coming in from a... if it's coming in from a single source, a single IP block, you can just simply, you know, block an email coming from that IP block. [37:08.000 --> 37:09.940] You know, just block it by IP address. [37:10.120 --> 37:10.240] Yeah. [37:10.460 --> 37:10.820] Yes, hi. [37:10.940 --> 37:11.540] I have a question. [37:12.200 --> 37:16.070] Two months ago, I came across one of those websites that generate fake email addresses. [37:16.070 --> 37:18.640] And every time you hit refresh, they look legitimate. [37:18.820 --> 37:20.280] Could you comment if you think those are effective? [37:20.640 --> 37:21.460] Fake email addresses. [37:21.460 --> 37:26.420] Yeah, just, you know, it was like a random generator at so-and-so, dot com, dot net, dot org. [37:26.520 --> 37:27.660] They got their uses. [37:28.260 --> 37:32.840] I would use that, for instance, if I were to, like, fill out a forms page. [37:33.570 --> 37:37.570] And if I was interested in something, but I really didn't want these guys to spam me. [37:37.960 --> 37:41.440] I would also use it if I were, let's say, want to post something to use net. [37:42.020 --> 37:43.640] I would use something like that. [37:43.820 --> 37:48.600] If I can read in... if I can read mail from that, that would be what you would use these things for. [37:48.940 --> 37:52.220] It's the same thing as getting yourself a Hotmail account. [37:55.560 --> 37:56.380] Anybody else? [37:56.380 --> 37:56.820] Yeah. [37:58.480 --> 37:59.060] You. [37:59.380 --> 37:59.680] Yeah. [38:00.320 --> 38:09.360] Do you believe that perhaps a new protocol could be developed for sending mail that would prevent spam from happening? [38:09.440 --> 38:10.640] Well, that would be really nice. [38:12.240 --> 38:13.560] That would be real nice. [38:13.680 --> 38:15.740] But let's try to keep Microsoft out of it, shall we? [38:17.980 --> 38:18.560] Yeah. [38:18.560 --> 38:22.280] And you mentioned that it doesn't seem to be worthwhile reporting of the spam. [38:22.440 --> 38:26.520] Would that include even forwarding it to UCE at FTC.gov? [38:26.640 --> 38:29.800] Or does that help them compile statistics to see... [38:29.800 --> 38:31.860] That's basically what it does, the latter. [38:32.000 --> 38:33.900] It helps them compile statistics. [38:34.200 --> 38:38.260] In fact, I gave a talk at the Nexpo Security Conference back in... [38:38.260 --> 38:42.480] Back last month, toward the end of the last month. [38:42.780 --> 38:53.100] And I was on a panel with the FTC, and I met this person, Jonathan, and got all the inside scoop on how they do that. [38:53.780 --> 38:59.200] The best of my recollection, they're getting 350,000 spam submissions a day. [38:59.940 --> 39:23.480] What they do is they have an automatic system that tabulates this information and categorizes it in various different forms and ways, and collects all that information up and statistically analyzes it, and what they do is they pick just one or two of the really good likely ones that are easy for them to track down. [39:24.240 --> 39:26.800] They're not going to go after the ones that are hard to track down. [39:26.920 --> 39:31.720] They're not going to go after the ones that are sending their spam through infected hosts. [39:31.840 --> 39:38.440] They are going to go through ones that are sending spam through perhaps proxies that they can somehow get contact information for. [39:38.440 --> 39:46.580] Or if it's a spamvertised website, they can probably get information from the domain name, and that's possible, too. [39:47.560 --> 39:48.680] What's the deal with that? [39:49.040 --> 39:53.060] Well, again, they're coming from infected hosts, so I don't bother to trace them. [39:53.340 --> 39:58.080] What they're trying to do is they don't care whether or not they're advertising anything. [39:58.360 --> 40:02.020] What they're trying to do is they're trying to throw off the spam filters. [40:02.780 --> 40:10.600] See, they'll send out a bunch of gibberish, knowing that it's not really going to do any good, except for one thing. [40:10.760 --> 40:12.020] It throws off the filters. [40:12.260 --> 40:20.260] So it's going to open up the filters to let more spam through when they send subsequent spams down through their system. [40:20.600 --> 40:24.020] So it just kind of opens up their system a little bit better. [40:25.060 --> 40:27.060] I have it... yeah? [40:27.060 --> 40:31.020] Wouldn't it help to report it to the Internet Fraud Division of the FBI? [40:31.200 --> 40:35.120] I once got rid of a spammer by doing that, instead of that other government agency... [40:35.120 --> 40:35.360] Well, that's all fine. [40:35.700 --> 40:38.000] That's real fine if you can do that, you know. [40:38.960 --> 40:40.040] That's really cool. [40:41.340 --> 40:43.780] Have you ever tried reporting it to them? [40:43.780 --> 40:44.340] Yes, I did. [40:44.500 --> 40:52.620] I've got quite a few submissions already pending, and they've just been ignoring me. [40:53.840 --> 40:56.100] Remember that I am John T. [40:56.240 --> 40:56.480] Draper. [40:56.740 --> 40:57.700] I'm not very rich. [40:58.060 --> 41:02.280] I'm running a very small web crunchers, web hosting, and email service. [41:02.780 --> 41:06.240] And I'm barely making a couple hundred bucks a month off of it, if that. [41:07.100 --> 41:12.880] However, if I'm Microsoft, making millions and millions of dollars, then... [41:12.880 --> 41:19.100] And I complain to the FBI, the FBI is going to listen to me, because I'm a big corporation. [41:20.100 --> 41:23.940] Like I said, there's not much equal justice for all anymore in this country, yeah. [41:24.520 --> 41:26.900] Yeah, but how are you going to just get rid of... [41:27.360 --> 41:30.800] Nobody can just get rid of all the spam in the whole Internet system. [41:31.040 --> 41:34.740] I mean, the Internet system is so big, it's just... [41:34.740 --> 41:36.660] You just can't really get rid of it all. [41:36.940 --> 41:46.960] The best thing you can do is use technical means to make it as expensive and as hard as possible for spammers to spam, in the hopes of discouraging them. [41:47.140 --> 41:53.100] And I seem to be doing a reasonably good job of that, actually, according to the reports I've been getting from my spam spies. [41:53.520 --> 41:53.580] Yeah. [41:54.300 --> 41:56.060] You had a question about following the money trail. [41:56.200 --> 42:06.900] Obviously, you can't really do anything with the authorities to these companies, since they're completely outside of their jurisdiction, out of this country in the Middle East, in Eastern Europe, where you can't really touch them. [42:07.060 --> 42:11.840] Is there anything being done to boycott the companies that patronized them? [42:11.840 --> 42:15.620] I mean, you have companies that use these marketing services that end up spamming. [42:15.800 --> 42:25.700] Is there any kind of boycott list of all these URLs where people could find out if somebody was either knowingly or unknowingly patronizing a spammer so that you could avoid doing business with them? [42:26.200 --> 42:27.680] Not to my recollection. [42:27.740 --> 42:34.780] However, that would be a good little project that somebody could take on, is to do that, you know? [42:34.900 --> 42:36.200] You'd have to have a credit card. [42:36.340 --> 42:39.360] You'd have to have a little bit of disposable cash at hand to try to buy these things. [42:39.360 --> 42:43.160] But buying these things could also serve another bit... [42:43.160 --> 42:45.780] Well, it could serve a bad purpose and it can serve a good purpose. [42:46.040 --> 42:48.920] The bad purpose is, you're buying from a spammer. [42:49.540 --> 42:51.140] And that encourages spamming. [42:51.600 --> 43:03.440] We want to try to discourage people from buying from spammers altogether, because then once spammers realize that, hey, they're not making any more money, they're not selling anything because nobody's buying anything, maybe they'll stop. [43:03.700 --> 43:05.120] Well, that's not going to be likely. [43:06.060 --> 43:14.380] On the other hand, if you have disposable cash on hand and really want to go after these people, that's the best way to do it. [43:14.500 --> 43:23.780] Because, number one, you're going to get a statement from your financial institution, your credit card company, on just exactly who processed that credit card. [43:24.020 --> 43:27.100] You can contact your bank and that information is public. [43:27.340 --> 43:32.920] Once you've contacted the bank, then you can contact that bank and say, hey, this is a fraudulent transaction. [43:32.920 --> 43:41.120] And I know because I've had an e-commerce account with Shop IP back in just before the .bomb days took me out. [43:41.320 --> 43:46.800] And what happened was, they're very, very sensitive about what they call chargebacks. [43:47.440 --> 43:52.040] You know, they'll hit you really hard with fees up the wazoo if you charge something back. [43:52.300 --> 43:56.580] A chargeback means you have to return an item that they're not satisfied with. [43:56.580 --> 44:01.580] And if you let that bank know and know in certain terms that, hey, these people are fraudulent. [44:01.700 --> 44:03.200] Yeah, they're going to do something about it. [44:03.300 --> 44:07.180] And to me, that's the best approach that I can suggest people to take. [44:07.400 --> 44:11.140] But again, it takes somebody with disposable cash to do that. [44:11.320 --> 44:12.920] I'm not one of those persons. [44:13.460 --> 44:13.900] Yeah. [44:17.040 --> 44:17.710] Yeah. [44:26.660 --> 44:27.340] Right. [44:29.640 --> 44:40.840] Well, what I do, what I do is, I take a message and I evaluate each of the words in the message. [44:40.840 --> 44:45.480] How many of these words are in the dictionary and are English language words? [44:46.540 --> 44:54.440] The less number of words that's in the English dictionary that's in the dictionary, the more likely it's going to be a spam. [44:55.040 --> 44:57.440] And my threshold is very, very low. [44:57.640 --> 45:03.980] So if there's just one or two words in there that are not in the English dictionary, it's considered spam. [45:04.140 --> 45:05.800] And so it automatically gets classified. [45:05.920 --> 45:07.040] It doesn't go through any other filters. [45:07.200 --> 45:09.060] I've got a three-filter system. [45:09.060 --> 45:16.940] The first filter, what it does, is it takes and UU-encodes, takes a UU-decodes the message into English. [45:17.500 --> 45:17.880] Okay? [45:18.100 --> 45:23.660] The next thing it does, it strips out the HTML tags that are often used to confuse the filters. [45:24.040 --> 45:30.600] You know, it puts in these BRs and all these HTML angle bracket tags in the middle of a word. [45:30.840 --> 45:37.060] So if it says VI and then there's an angle bracket, SP angle bracket A, another angle bracket. [45:37.060 --> 45:40.320] You know, and these things are embedded in the message. [45:40.500 --> 45:45.060] What I do is I take all that out and I turn it into a more of an Englishy type of a word. [45:45.260 --> 45:47.500] Then I feed that to the Bayesian filters. [45:47.620 --> 45:50.060] And I'm getting about 96 to 98% filtering. [45:50.920 --> 45:51.500] Really good. [45:51.840 --> 45:56.780] And spammers can't get past that anymore because I just filter that out before I do that. [45:56.780 --> 45:59.860] This is called pre-filtering and I highly recommend that you do that. [46:00.740 --> 46:07.360] And all it takes is just writing a little routine that goes in there and analyzes the body of the message and looks for things like HTML tags. [46:07.480 --> 46:09.980] If it's an HTML tag, it's probably going to be spam. [46:10.240 --> 46:13.520] And all I have to do is tell my friends, never send me mail in HTML. [46:13.920 --> 46:15.340] And you're going to be just fine. [46:15.340 --> 46:23.240] So let me find now an email address here of some... let me go by date and go better. [46:23.900 --> 46:32.520] I'm going to try to pick one here that's got a... that's got a... one of those email addresses. [46:34.240 --> 46:36.360] Let's see here... nope, that's not one. [46:37.720 --> 46:40.820] Let's... I got enough of them here that I can certainly find. [46:42.440 --> 46:44.360] Just kind of pecking at random here. [46:45.400 --> 46:49.140] What I'm trying... what I'm actually looking for is I'm actually looking for a... [46:50.380 --> 46:56.200] looking for a message with the... with that... with that hash code that I've got. [46:56.200 --> 47:01.580] Unfortunately, Max iMail is so slow and so... such a pig. [47:02.340 --> 47:03.540] I never did like it. [47:04.280 --> 47:05.480] How are we doing time-wise? [47:05.840 --> 47:06.500] One minute. [47:06.800 --> 47:07.000] Okay. [47:07.200 --> 47:09.320] Let me take one or two more questions and I'll end it. [47:09.600 --> 47:10.100] Yeah, go ahead. [47:10.280 --> 47:13.120] I was wondering what server you're using on BSD now. [47:13.300 --> 47:15.060] And have you tried anything like spam assassin? [47:15.940 --> 47:19.560] Actually, I'm using the... the spam base... Bayesian filtering. [47:19.740 --> 47:20.640] I'm writing my own code. [47:21.020 --> 47:24.400] And the servers I use is most often OpenBSD. [47:25.380 --> 47:27.860] That's my server of choice because of its security. [47:28.100 --> 47:28.160] What? [47:29.340 --> 47:30.220] Like Sendmail? [47:30.520 --> 47:31.680] Yeah, I use Sendmail. [47:32.380 --> 47:33.620] Mostly I just use Sendmail. [47:33.740 --> 47:36.280] I don't... I don't bother too much with... with actually mail coming in. [47:36.420 --> 47:40.760] But when I get my new system built in, I'm going to be implementing my own MTA. [47:41.540 --> 47:43.440] And I've already got parts of it implemented. [47:43.580 --> 47:45.780] I'm actually going to be developing that in Twisted Python. [47:46.440 --> 47:48.260] My... my language of choice is Python. [47:48.720 --> 47:53.340] And... and Twisted Python's got a very, very wonderful way of handling these things. [47:53.340 --> 47:56.980] And I have absolute total control over how mail comes in using Twisted Python. [47:57.300 --> 47:58.680] And it's very fast. [47:58.860 --> 48:02.720] And it's also designed for multiple mails coming in at the same time. [48:03.080 --> 48:05.260] Totally asynchronous and all that. [48:05.380 --> 48:07.040] I think I'm about out of time, folks. [48:07.040 --> 48:08.760] I want to thank you very much for attending. [48:08.760 --> 48:09.020] And then...