March 19, 2003

Study answers: 'Why all this spam?'

Primary source for spammer lists are e-mail addresses on public sites

It's easy to fool e-mail harvesting software, even though the primary source for spammers' e-mail lists are e-mail addresses listed on public Web sites, according to a six-month experiment from the Center for Democracy and Technology (CDT).

The center set up about 250 dummy e-mail addresses, and during the six-month test those addresses received a combined 8,842 e-mail messages that center researchers classified as unsolicited e-mail, which is commonly known as spam. But about 97 percent of that spam -- 8,609 e-mail messages -- were received by six e-mail addresses listed at three Web sites: GetNetWise.org, ConsumerPrivacyGuide.org, and CDT.org.

USENET newsgroup postings were the second-largest source of spam, but e-mail addresses registered at e-commerce sites, posted to online discussions on Web sites, or listed as the contact for domains in the WHOIS database generated little spam, according to the study released Wednesday, titled "Why am I getting all this spam?"

Addresses on those three sites disguised by simply replacing the @ system with "at" or coding the addresses in HTML instead of in regular text received no spam at all during the six months. And the spam fell off significantly on three addresses that were removed from public view two weeks into the center's test. For example, an e-mail address listed on GetNetWise.org for the full six months received 6,035 pieces of spam, but an address removed after two weeks received only 894 pieces of spam during the length of the study.

"The shelf life of an e-mail address when it's pulled off the Web is fairly short," noted Rob Courtney, a policy analyst with CDT.

To test spam from USENET, CDT used dummy addresses to post to 13 newsgroups, ranging from alt.sex.erotica to alt.kids-talk, and 85 percent of those addresses received spam. But those addresses only received 110 pieces of spam over six months, and disguised e-mail addresses received no spam.

One piece of good news was that CDT received little spam from 31 top-trafficked e-commerce Web sites, Courtney said. In every case in which CDT registered at a Web site and asked not to receive commercial e-mail, its wishes were respected.

"We certainly found that for the most part, when Web sites did offer privacy policies and choices, that meant something," Courtney said.

CDT also used other dummy addresses to opt in to commercial e-mail and later opt out. At five sites, CDT continued to receive commercial e-mail -- a total of 82 pieces -- after a two-week grace period it gave Web site operators a two-week grace period to shut off the e-mail spigot.

Twenty-six of those 82 spam messages came from Priceline.com, but a spokesman there said the Web site uses a third-party, "off-the-shelf" opt-out solution that several other companies use. "If it happened to us, it'd strike me that a lot of other companies would have the same problem," the spokesman said.

The spokesman said Priceline.com would examine the CDT study further to understand what happened. "The last thing we want to do is spam people," he said. "Our policy is if somebody wants to opt out, we let them opt out."

CDT received only 15 pieces of spam from posting to discussion forums at 10 Web sites, including Monster.com, eBay.com, and Amazon.com. All 15 came from an e-mail address that posted to InteliHealth.com. CDT received just one piece of spam from e-mail addresses entered in the WHOIS database.

Close

On Twitter now

Applications

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Applications Resource Alerts

Subscribe to the Applications Newsletter

Stay informed of the latest news and technologies around application, project and performance management.

White paper

Turn Your IT Department into a Lean Machine

Like any valuable resource, IT is a terrible thing to waste. But by applying the same lean techniques that have been used to streamline manufacturing processes, IT departments can reduce costs, improve performance and better manage resources.

Download now! »

Podcast

Economy Makes Automation a Must-Have Tech for 2009

Stephen Elliot, vice president of strategy for CA's Infrastructure Management and Data Center Automation business unit, explains why difficult economic times drive the need for simplified management capabilities and advanced automation tools.

Listen now! »

White paper

What You Need to Know About Virtual Infrastructure Management - Now

According to a recent study CA conducted with 300 CIOs and top IT executives, 64 percent of respondents say they've already invested in virtualization, and the other 36 percent reported that they plan to invest in virtualization.

Download now! »

Webcast

Leveraging Virtualization and Process Automation

In this video learn about process automation in a virtualized world. How CA and VMware are enabling enterprise datacenter automation.

View now! »
©1994-2009 Infoworld, Inc.