[55951] in cryptography@c2.net mail archive
Spammer using Graphical Steganography
daemon@ATHENA.MIT.EDU (Bill Stewart)
Wed Oct 25 13:39:32 2006
X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Mon, 23 Oct 2006 15:46:38 -0700
To: cryptography@metzdowd.com
From: Bill Stewart <bill.stewart@pobox.com>
Spammers have been including images in their email to evade anti-spammers.
Anti-spammers have been using OCR to identify spammy words in images.
Spammers have recently come up with tricks to work around OCRs,
by doing steganography with animated GIF images.
One approach they're taking is to build the real image progressively,
first drawing a background, then drawing parts of the image
(one spammer uses transparent pixels to do parts of it, showing dark parts=
=20
of background),
then waiting a long time and drawing a blank page in case anything's=20
checking the final image.
http://www.networkworld.com/community/?q=3Dnode/8977
Spammers dodging OCR with .gif 'cut-and-paste'
By Paul McNamara on Fri, 10/20/2006 - 2:11pm
Spammers have begun slipping their junk past optical character recognition=
=20
(OCR) software through a variety of animated .gif "cut-and-paste"=20
techniques, says John Graham-Cumming, an anti-spam activist who maintains=20
The Spammers' Compendium and also founded Electric Cloud.
On blog posts this week -- here and here
http://www.jgc.org/blog/2006/10/why-ocring-spam-images-is-useless.html
http://www.jgc.org/blog/2006/10/spam-image-that-slowly-builds-to.html
-- Graham-Cumming explains two of the OCR-evading methods that were brought=
=20
to his attention by Nick FitzGerald, a New Zealand anti-spam consultant and=
=20
regular contributor to The Spammers' Compendium. (It being 3 a.m. in New=20
Zealand, I'm relying on Graham-Cumming's account here.) ... (Update:=20
FitzGerald explains his advantage.)
"I don't know how widespread it is," Graham-Cumming told me this afternoon.=
=20
"(The second spam message) was targeted for this Wednesday, so I think it's=
=20
probably pretty new."
The second of the two techniques takes animated .gif spam "to a new level,"=
=20
he said on his blog.
From the blog post: "The first image is the .gifs background and is=20
displayed for 10ms then the second image is layered on top with a=20
transparent background so that the two images merge together and the image=
=20
the spammer wants you to see appears. That image remains on screen for=20
100,000 ms (or 1 minute 40 seconds). After that the image is completely=20
blanked out by the third frame.
"My favorite touch is that it's not the entire image that's transparent,=20
not even the white background, but just those pixels necessary to make the=
=20
black pixels underneath show through. If you look carefully above you can=20
see that some of the pixels appear yellow (which is the background color of=
=20
this site) indicating where the transparency is."
In our interview, Graham-Cumming belied more than begrudging admiration for=
=20
what this spammer has achieved.
"What's really neat about what this guy has done is that he takes a piece=20
of text and he randomly kills pixels in it so that each frame of this thing=
=20
is unreadable," he told me. "But when you merge them together, you get a=20
readable piece of text. It is immensely clever. He's used animation with=20
transparency in .gif so what happens is that although this is actually=20
animated you don't see the animation because the two frames which have got=
=20
the pixels killed on them are animated together so fast =85 that it looks=20
like a static image."
Despite the fact that Graham-Cumming headlined his blog item "Why OCRing=20
spam images is useless," he tempered that assessment in our talk.
"Saying OCR is useless is an overstatement, of course," he said. "There=20
will be some value in OCRing because the history of spam shows that there=20
are bleeding-edge spammers who fight to get through every filter and=20
there's a large pool of spammers who use out of date software, essentially,=
=20
so it's always worth going with techniques that worked a few months ago. =85=
=20
The problem with OCR is that it's very expensive to do in terms of CPU and=
=20
so that's why it hasn't been rolled out widely. It's pretty clear that=20
spammers are thinking about this. That (animated .gif) technique and the=20
previous one I showed in the previous blog entry both make OCRing=
difficult."
Coincidentally, the two anti-spammers involved here had recently been=20
discussing the possibility of such techniques emerging.
"What's amazing about this one is that (FitzGerald) and I had gone back and=
=20
forth in a conversation about -- 'You know what spammers could do, is=20
something like this.' We had anticipated that something like this was going=
=20
to happen; the particular technique is very close to what we had been=20
discussing and (FitzGerald) actually sent me an e-mail today saying, 'Look=
=20
at this one, maybe they're reading our mail.' "
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com