Advertisement
Promo

Security threats Toolkit

Spammers 'using bugs' to find active email addresses

Graeme Wearden ZDNet.co.uk

Published: 14 Apr 2004 17:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Many spammers are including illicit code in their unsolicited mail to help them detect active email addresses, a security firm warned on Tuesday.

MX Logic claimed that nearly 50 percent of spam sent over the last 12 months included a 'spam beacon' -- a piece of HTML code embedded in the email that detects when an email is opened, or even just previewed.

This information is then relayed back to the spammer, telling them that certain email addresses are in use. Similar techniques are also used by marketing companies to track behaviour and detect the response rate to targeted emails.

Web users have long been advised to ignore spam, rather than replying to it, so as not to attract more attention from spammers. According to MX Logic, though, just looking at the junk mail is all it takes.

"Millions of users are unaware that spammers have the ability to track when they view and open their email," said Scott Chasin, MX Logic's chief technology officer.

"While Web bugs are not a new phenomenon to the Internet, this new data shows that nearly one out of two spam messages now contain these beacons. This reinforces the fact that spammers are using increasingly deceptive tools to invade end users' privacy and harvest valid email addresses."

Back in February 2003, UK law firm Masons warned that spammers were breaking the law by including these secret tracking codes in their messages.

MX Logic's spam filtering technology has been watching out for such bugs since March 2003.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
60 out of 142 people found this useful


Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters