<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>(b)logophile &#187; spam</title>
	<atom:link href="http://www.logophile.org/blog/tags/spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.logophile.org/blog</link>
	<description>blog of a logophile (not "logos", but "λόγος")</description>
	<lastBuildDate>Fri, 20 Aug 2010 10:21:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=128</generator>
		<item>
		<title>Subtle</title>
		<link>http://www.logophile.org/blog/2008/05/15/subtle/</link>
		<comments>http://www.logophile.org/blog/2008/05/15/subtle/#comments</comments>
		<pubDate>Thu, 15 May 2008 10:31:58 +0000</pubDate>
		<dc:creator>tikitu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[amusement]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.logophile.org/blog/?p=389</guid>
		<description><![CDATA[In my inbox this morning: Office of the Honourable Minister Of Information Federal Republic Of Nigeria Tel: 234 703 440 0879 REF/PAYMENTS CODE:06654 This is to inform you that we have verified your payment, Nigerian 419 scam practiotioners where Arested,your name has been shortlisted and approved for this payment as one of the 419 scam [...]]]></description>
			<content:encoded><![CDATA[<p>In my inbox this morning:</p>

<p><pre>
Office of the 
Honourable Minister Of Information 
Federal Republic Of Nigeria 
Tel: 234 703 440 0879</p>

<p>REF/PAYMENTS CODE:06654</p>

<p>This is to inform you that we have verified your payment,
Nigerian 419 scam practiotioners where Arested,your name 
has been shortlisted and approved for this payment as one 
of the 419 scam victims,get back to me immedately for more 
details.</p>

<p>Waiting to receive your reply.</p>

<p>Yours faithfully, 
Chief John Odeh 
Honourable Minister Of Information 
Federal Republic Of Nigeria
</pre></p>
]]></content:encoded>
			<wfw:commentRss>http://www.logophile.org/blog/2008/05/15/subtle/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Fine print (a scam? a shame?)</title>
		<link>http://www.logophile.org/blog/2006/12/14/fine-print-a-scam-a-shame/</link>
		<comments>http://www.logophile.org/blog/2006/12/14/fine-print-a-scam-a-shame/#comments</comments>
		<pubDate>Thu, 14 Dec 2006 19:56:55 +0000</pubDate>
		<dc:creator>tikitu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[irritation]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://www.logophile.org/blog/?p=235</guid>
		<description><![CDATA[PayPal just sent me an email (which you can see for yourself): Dear Tikitu De jager, Christmas is approaching! Still need to find some gifts for your loved ones? We show you how to find unique gifts on eBay. Also, find out how you can send money home with PayPal and stay in touch for [...]]]></description>
			<content:encoded><![CDATA[<p>PayPal just sent me an email (which you can <a href="http://www.logophile.org/blog/wp-content/uploads/2008/06/paypal.html">see for yourself</a>):</p>

<blockquote> Dear Tikitu De jager,

Christmas is approaching! Still need to find some gifts for your loved
ones? We show you how to find unique gifts on eBay. Also, find out how you
can send money home with PayPal and stay in touch for free with Skype!

Seasons greetings!  
PayPal  
</blockquote>

<p>The funny thing is, I could have sworn I asked them not to spam me. But&#8230;</p>

<blockquote> This PayPal notification was sent to [ my address ] because
you chose to receive All Policy Change Notices.  </blockquote>

<p>Oh. Fair enough. I suppose the policy that&#8217;s changed is that &#8220;Policy Change Notices&#8221; no longer contain notification of changed policies.</p>

<p>I still can&#8217;t make up my mind if this is <a href="http://en.wikipedia.org/wiki/Phishing">phishing</a> or corporate stupidity.</p>

<h3>Case for phishing</h3>

<ul>
<li>They misspell (mis-capitalise) my surname (&#8220;De jager&#8221;) while it shows correctly when I log in to paypal.com.</li>
<li>Can anyone really be so soulless as to take &#8220;please send me all Policy Change Notices&#8221; as an invitation for Christmas spam?!</li>
<li>The links in the newsletter go to <code>email1.paypal.nl</code>, which is not <code>www.paypal.com</code> which is where I log in. (Ok, <code>paypal.nl</code> is legit. But a DNS lookup site tells me <a href="http://www.dnsstuff.com/tools/lookup.ch?name=mail1.paypal.nl&amp;type=ALL">that subdomain doesn&#8217;t exist</a>.)</li>
<li>Said links include a session identifier, which would suffice to identify me for the phisher site.</li>
</ul>

<h3>Case against phishing</h3>

<ul>
<li>The got the correct name and email address for my PayPal account. That&#8217;s not as easy as it sounds, it&#8217;s not the name you&#8217;re looking at. (It&#8217;s not so very difficult either, though, and the email address is an easy guess.)</li>
<li>They don&#8217;t ask for any information or even that I go somewhere to &#8220;confirm&#8221; anything. The links are apparently continuations of the articles, or things like &#8220;Get Skype&#8221;. They all go to that <code>email1.paypal.nl</code> though.</li>
<li>And if <code>email1.paypal.nl</code> doesn&#8217;t exist, how are they getting any information at all, let alone useful information?!</li>
</ul>

<h3>Result&#8230;</h3>

<p>I&#8217;m confused. Anyone know anything about this? Legit and <em>really bloody irritating</em>, not to mention <em>braindead stupid</em>? Dodgy and <em>diabolically clever</em>? It&#8217;s got me puzzled.</p>

<h3>Update</h3>

<p>The PayPal spoofline says it&#8217;s fake. But I&#8217;m not sure I believe them &#8212; the email is clearly a form letter, and it looks to me like it just ripped out the urls from the email and checked whether they were registered to PayPal. Which they apparently aren&#8217;t, but I still can&#8217;t get past one question: how does it help a scammer to direct me to a non-existant website? (Hm. How does it help PayPal? Good question. No answer.)</p>

<blockquote>
Thank you for bringing this suspicious email to our attention. We can
confirm that the email you received was not sent to you by PayPal. The
website linked to this email is not a registered URL authorized or used by
PayPal. We are currently investigating this incident fully. Please do not
enter any personal or financial information into this website.
</blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.logophile.org/blog/2006/12/14/fine-print-a-scam-a-shame/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>This morning&#8217;s spam harvest</title>
		<link>http://www.logophile.org/blog/2006/03/22/this-mornings-spam-harvest/</link>
		<comments>http://www.logophile.org/blog/2006/03/22/this-mornings-spam-harvest/#comments</comments>
		<pubDate>Wed, 22 Mar 2006 10:26:12 +0000</pubDate>
		<dc:creator>tikitu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[bemusement]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.logophile.org/blog/?p=144</guid>
		<description><![CDATA[A couple of spams got past Gmail today. It seems they&#8217;re putting the spam pitch in an image, and padding out the message with random text. But the randomisation is getting cleverer, or else they&#8217;re scraping from some very strange sites&#8230; &#8220;When we last saw pesticide it wasn&#8217;t diebold. Then after messieurs or runt got [...]]]></description>
			<content:encoded><![CDATA[<p>A couple of spams got past Gmail today. It seems they&#8217;re putting the spam pitch in an image, and padding out the message with random text. But the randomisation is getting cleverer, or else they&#8217;re scraping from some very strange sites&#8230; &#8220;When we last saw pesticide it wasn&#8217;t diebold. Then after messieurs or runt got to the seminole it was like plead.&#8221; Sadly it loses it thereafter: &#8220;drumlin we opaque that penal come with his lance.&#8221; That sentence isn&#8217;t even capitalised!</p>

<p>Why was I even looking inside? Well, the subject line was intriguing: &#8220;<a href="http://en.wikipedia.org/wiki/Anhydrous">anhydrous</a> <a href="http://www.comp.leeds.ac.uk/people/staff/rens.jpg">Rens</a>&#8220;. (The chappy on the right is Rens Bod, one of our ILLC characters. Only his homepage here is all boring text, and I really needed a photo to show how anhydrous he is.)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.logophile.org/blog/2006/03/22/this-mornings-spam-harvest/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Invited speaker! (almost)</title>
		<link>http://www.logophile.org/blog/2005/12/19/invited-speaker-almost/</link>
		<comments>http://www.logophile.org/blog/2005/12/19/invited-speaker-almost/#comments</comments>
		<pubDate>Mon, 19 Dec 2005 19:33:44 +0000</pubDate>
		<dc:creator>tikitu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[bemusement]]></category>
		<category><![CDATA[events]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://www.logophile.org/blog/?p=113</guid>
		<description><![CDATA[I just received not one but two invitations to present at an upcoming conference, or even to organise a special session, should I so desire. The catch? It&#8217;s the 2006 edition of the scam conference that accepted a randomly-generated paper in 2005. So I guess maybe the personal opening and &#8220;We are emphasizing the area [...]]]></description>
			<content:encoded><![CDATA[<p>I just received not one but <em>two</em> invitations to present at an upcoming conference, or even to organise a special session, should I so desire. The catch? It&#8217;s the 2006 edition of the <a href="http://www.iiisci.org/wmsci2006/">scam conference</a> that <a href="http://pdos.csail.mit.edu/scigen/">accepted a randomly-generated paper</a> in 2005.</p>

<p>So I guess maybe the personal opening and &#8220;We are emphasizing the area of Mathematical Methods and Optimization in Problem Solving Systems which is related to your specific area&#8221; doesn&#8217;t really mean I&#8217;m an invited speaker (funnily enough, the second invitation was emphasising a different area: Computing Technologies, which certainly <em>sounds</em> worth emphasising). Also notable is that this particular invitation comes via my old Otago student address, which dates back to the days when I didn&#8217;t <em>have</em> a &#8220;specific area&#8221;.</p>

<p>Problem is, now I&#8217;m afraid to mark it as spam &#8212; not knowing how gmail is working its magic, I&#8217;m worried about punishing other more legitimate calls for submissions. Instead, here&#8217;s a little link love: <a href="http://anthony.liekens.net/index.php/Misc/FakeConferences/">Anthony Lieken  describes</a> this <a href="http://www.iiisci.org/wmsci2006/">WMSCI as a &#8220;fake conference&#8221;</a>, the <a href="http://pdos.csail.mit.edu/scigen/blog/">authors of the paper generator software call </a> it <a href="http://www.iiisci.org/wmsci2006/">(WMSCI) a &#8220;spamference&#8221;</a>. You&#8217;re welcome to make up your own minds, although this <a href="http://homepage.mac.com/redbird/iblog/G-Squared/C1322884510/E6227103/">blog posting</a> might dissuade you: the poster &#8211;then an undergraduate, if I read his later stuff correctly&#8211; paid $400 registration after having his paper accepted by &#8220;a huge conference having something to do with computing&#8221;. Wonder if it was worth it?</p>

<p>(Excuse the ugly phrasing in the links, I&#8217;m going for a particular <a href="http://www.google.com/search?q=%22president+of+the+internet%22">poetic effect</a>. I heartily encourage all seven readers of this blog to emulate me.)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.logophile.org/blog/2005/12/19/invited-speaker-almost/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Magic word comment spamtrap</title>
		<link>http://www.logophile.org/blog/2005/06/28/magic-word-comment-spamtrap/</link>
		<comments>http://www.logophile.org/blog/2005/06/28/magic-word-comment-spamtrap/#comments</comments>
		<pubDate>Tue, 28 Jun 2005 13:53:47 +0000</pubDate>
		<dc:creator>tikitu</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[ideas]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[technical]]></category>

		<guid isPermaLink="false">http://www.logophile.org/blog/?p=60</guid>
		<description><![CDATA[A couple of thoughts about trapping comment spam: my first idea was, add a textfield requiring a significant word from the blog entry in question. Simple for a person to produce, and in practise you just need to check if the word occurred in the entry at all, skipping a list of obvious stop words [...]]]></description>
			<content:encoded><![CDATA[<p>A couple of thoughts about trapping comment spam: my first idea was, add a textfield requiring a significant word from the blog entry in question. Simple for a person to produce, and in practise you just need to check if the word occurred in the entry at all, skipping a list of obvious stop words (&#8220;in&#8221;, &#8220;the&#8221;, etc.).</p>

<p>But of course a clever robot spider from hell can deal with that: the same technique <em>generates</em> magic words as tests for them.</p>

<p>So my second idea was a textfield already <em>containing</em> a word, with a note saying &#8220;If you submit this form without clearing this textfield, I&#8217;ll know you&#8217;re a robot spider from hell.&#8221; Better still, &#8220;Change this word to the one following it in the article above, to prove you&#8217;re not &#8230;&#8221; You get the idea.</p>

<p>For added fun, rotate these methods (and the simpler &#8220;Don&#8217;t fill in this textfield unless you&#8217;re a RSfH&#8221; on eg. the URL field) at random. If I didn&#8217;t have a thesis to write, I&#8217;d put together a wordpress plugin.</p>

<p>(Why am I thinking about this, given the obvious lack of comment spam on my blog? Because (a) I still occasionally moderate down posts advertising the-card-game-whose-name-we-do-not-speak, and (b) I&#8217;m terrified that one of the extremely infrequent genuine comments of my friends is going to get blitzed. It&#8217;s not that I don&#8217;t trust <a href="http://unknowngenius.com/blog/wordpress/spam-karma/dev/">Spam Karma</a>, it&#8217;s simply that I don&#8217;t understand it.)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.logophile.org/blog/2005/06/28/magic-word-comment-spamtrap/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
