Best Defense is Offense: Attacking the phishers

| | Comments (3)

Well done Pcal! He's done what I've thought for the longest time is the right way for people to deal with phishing/spamming/etc - phish the phishers. You go!

Idea for V1.1: scrape the address used in the email and "reply" to that address.

Idea for V2: Enlist others to contribute "addresses" and cpu cycles. Maybe this is the future of Grid Computing? I was thinking a lot of the new safepeer plug-in for azareus, and wondering about something similar for blacklisting. hmmm..

Non-idea for V.N: Don't do something on sourceforge, etc. If the algorithms you use are public, people can reverse engineer the defense.

3 Comments

Heh, thanks, Dave. Yeah, I'm actually working on something like what you describe for V2 - stay tuned. :)

V1 is interesting, I didn't think about that. I imagine a lot of them spoof their mail headers to guard against this kind of thing, but it's worth trying.

Neat. I wonder though, if at some point the phishers won't be able to use spam fighting tools to protect against this kind of counterattack, i.e. is fighting SMTP DATA messages with free form text that much different than fighting HTTP POST messages with application/x-www-form-urlencoded text?

Bruce Schneier's solution is the only long-term viable one I've seen yet; http://www.wired.com/news/politics/0,1283,69076,00.html

Leave a comment

About this Entry

This page contains a single entry by Dave Orchard published on October 24, 2005 9:16 AM.

Oh, the irony: music comment spam on a comment spam blog entry after getting tired of the music was the previous entry in this blog.

Devs vs Admin: Cookies, Ajax, SOAP, EPRs, Atom and more is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Categories