<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: How Spam Works</title>
	<link>http://ask.metafilter.com/6917/How-Spam-Works/</link>
	<description>Comments on Ask MetaFilter post How Spam Works</description>
	<pubDate>Fri, 30 Apr 2004 14:15:53 -0800</pubDate>
	<lastBuildDate>Fri, 30 Apr 2004 14:15:53 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: How Spam Works</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works</link>	
		<description>A question about &lt;b&gt;SPAM.&lt;/b&gt; It&apos;s a new trick and I&apos;m wondering how they do it.  (more inside.) &lt;br /&gt;&lt;br /&gt; I use MS Outlook 2000 with autopreview enabled.  Lately I&apos;ve been finding spam email in my box that autopreviews certain random sentences -- obviously an attempt to get past my spam filters.  But interestingly, the text that appears in autopreview appears absolutely nowhere in the body of the email itself, which usually has entirely DIFFERENT random sentences.  Am I being clear?  I&apos;ll post an example in a moment to illustrate.  &lt;br&gt;
&lt;br&gt;
My question is, how are they doing this?  Where is the autopreview data being stored, if it doesn&apos;t show up in the body?  And why would they want to spoof to this level anyway?&lt;br&gt;
&lt;br&gt;
(As an interesting aside, sometimes the anti-filter quotations are intriguing enough that I actually open the email to read the rest of the quotations.  Now if that isn&apos;t mind-blowing, I don&apos;t know what is... spam that is interesting enought that I actually care to open it.)</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2004:site.6917</guid>
		<pubDate>Fri, 30 Apr 2004 14:03:39 -0800</pubDate>
		<dc:creator>Jonasio</dc:creator>
		
			<category>spam</category>
		
			<category>outlook</category>
		
			<category>spamfilter</category>
		
	</item> <item>
		<title>By: crunchland</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139422</link>	
		<description>It&apos;s hard to say without seeing the email, but one way I can think to do that is by embedding javascript into an html document and having it spit out random things. You can look at the html code of an email by right clicking on the email, choosing Properties, Details, and then Message Source.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139422</guid>
		<pubDate>Fri, 30 Apr 2004 14:15:53 -0800</pubDate>
		<dc:creator>crunchland</dc:creator>
	</item><item>
		<title>By: Jonasio</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139426</link>	
		<description>Here&apos;s a screenshot of an example.  Note that I&apos;ve checked the source of the email and it the mystery sentences don&apos;t appear.  Thanks for answering my curiosity!&lt;br&gt;
&lt;br&gt;
&lt;a href=&quot;http://jonasmiller.com/spamquestion.jpg&quot;&gt;the example&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139426</guid>
		<pubDate>Fri, 30 Apr 2004 14:23:51 -0800</pubDate>
		<dc:creator>Jonasio</dc:creator>
	</item><item>
		<title>By: humuhumu</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139428</link>	
		<description>Just quickly glancing at the screenshot, I&apos;d guess that they have put the words you see in hidden text at the top of the email - either by making them so small as to be unreadable and the same colour as the background, or by putting them in comment tags or [noscript] tags. You see the same tricks on web pages sometimes...</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139428</guid>
		<pubDate>Fri, 30 Apr 2004 14:27:28 -0800</pubDate>
		<dc:creator>humuhumu</dc:creator>
	</item><item>
		<title>By: Jonasio</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139429</link>	
		<description>humuhumu, I&apos;ve seen that many times, but not in the case of these mystery emails.  Thanks, though.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139429</guid>
		<pubDate>Fri, 30 Apr 2004 14:28:27 -0800</pubDate>
		<dc:creator>Jonasio</dc:creator>
	</item><item>
		<title>By: zsazsa</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139430</link>	
		<description>It could be that the plain text portion is showing up in the autopreview, and the HTML part shows up when it displays the actual message. (or what humuhumu said)</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139430</guid>
		<pubDate>Fri, 30 Apr 2004 14:29:14 -0800</pubDate>
		<dc:creator>zsazsa</dc:creator>
	</item><item>
		<title>By: Jonasio</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139431</link>	
		<description>For further clarification, here&apos;s a screenshot of the source for this particular spam.  No javascript.  No indication of the sentences that appear in the autopreview.  Weird, huh?&lt;br&gt;
&lt;br&gt;
&lt;a href=&quot;http://www.jonasmiller.com/spamquestion2.jpg&quot;&gt;the source&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139431</guid>
		<pubDate>Fri, 30 Apr 2004 14:34:12 -0800</pubDate>
		<dc:creator>Jonasio</dc:creator>
	</item><item>
		<title>By: Sangre Azul</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139438</link>	
		<description>frames, maybe?</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139438</guid>
		<pubDate>Fri, 30 Apr 2004 14:52:05 -0800</pubDate>
		<dc:creator>Sangre Azul</dc:creator>
	</item><item>
		<title>By: zsazsa</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139439</link>	
		<description>That&apos;s the source of the email&apos;s HTML part, not the entire email.  My money&apos;s on the mystery text being in the plain text portion.  I don&apos;t really know much about Outlook, so I&apos;m not sure how you can get.&lt;br&gt;
&lt;br&gt;
(If anyone doesn&apos;t know, email is sent with the MIME standard, which allows multiple parts in varying formats, and also allows for attachments.  If there&apos;s an HTML part, most mailers will display that first; otherwise it displays the plain text part.)</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139439</guid>
		<pubDate>Fri, 30 Apr 2004 14:53:43 -0800</pubDate>
		<dc:creator>zsazsa</dc:creator>
	</item><item>
		<title>By: zsazsa</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139440</link>	
		<description>Er, sorry, I meant: I don&apos;t really know much about Outlook, so I&apos;m not sure how you can get to the plain text part.  I know there&apos;s a way to view message headers, but I don&apos;t know of a way to display the entire raw contents of an email, including not-displayed MIME parts)</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139440</guid>
		<pubDate>Fri, 30 Apr 2004 14:55:05 -0800</pubDate>
		<dc:creator>zsazsa</dc:creator>
	</item><item>
		<title>By: ph00dz</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139444</link>	
		<description>That&apos;s funny... I get that same spam email, which has proved incredibly resistant to Mozilla&apos;s filters.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139444</guid>
		<pubDate>Fri, 30 Apr 2004 15:10:05 -0800</pubDate>
		<dc:creator>ph00dz</dc:creator>
	</item><item>
		<title>By: Jonasio</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139455</link>	
		<description>Extra thanks to Andrew Cooke and Richard Parker, who attempted to answer this question off-thread by email.  Richard does not have a mefi account, but answered anyway.  His answer seems like a probable solution to this mystery: &lt;br&gt;
&lt;br&gt;
&lt;em&gt;Avoiding assumptions of correct behavior on the part of third-parties, particularly those who might be malicious, is an important part of defensive programming.  I suspect what is occurring is an example of Outlook placing too much trust in the validity of e-mail headers, in particular I think that you have received more that one piece of spam e-mail that have the same &quot;Message-ID:&quot; header.&lt;br&gt;
&lt;br&gt;
The value of the &quot;Message-ID:&quot; header is supposed to be unique to each e-mail, but perhaps the spammer has sent you several with identical IDs.  This might confuse an e-mail program if the programmers relied on this value being unique.  For example, the Microsoft engineers who wrote Outlook might have decided to improve performance by looking up pre-computed previews in a database using the message ID as a key instead of, perhaps, computing the preview on-the-fly as necessary.  If they did, and there were multiple previews stored with the same ID, you might end up seeing a preview computed for an earlier message rather the correct one.  You could verify this by looking for an earlier spam message that contains the garbage text that you see in the preview and checking if the two e-mails have the same message ID.&lt;/em&gt;&lt;br&gt;
&lt;br&gt;
Unfortunately, I recently deleted my old spam, so I have no way to search for an identical spam like Richard mentions.  But at the moment I&apos;m pretty sure that this is a correct answer.&lt;br&gt;
&lt;br&gt;
Thanks again, Richard.  Somebody get this man a mefi account!</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139455</guid>
		<pubDate>Fri, 30 Apr 2004 15:30:14 -0800</pubDate>
		<dc:creator>Jonasio</dc:creator>
	</item><item>
		<title>By: andrew cooke</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139456</link>	
		<description>i agree with zsazsa - i asked jonas to forward me the email (which he kindly did), but outlook isn&apos;t forwarding the whole email, so it&apos;s difficult to tell (it seems that &quot;forward&quot; in outlook is just like &quot;reply&quot;, but with a different address, rather than bundling up the email as an attachment, so i get nothing more than a quoted chunk from the original below a message from jonas...)&lt;br&gt;
&lt;br&gt;
[on preview - neat idea.  could be.]</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139456</guid>
		<pubDate>Fri, 30 Apr 2004 15:32:27 -0800</pubDate>
		<dc:creator>andrew cooke</dc:creator>
	</item><item>
		<title>By: Jonasio</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139466</link>	
		<description>Question posted: 4:03 pm local time.&lt;br&gt;
Email received: 5:04 pm local time.&lt;br&gt;
&lt;br&gt;
MeFi came through in 61 minutes.  &lt;br&gt;
&lt;br&gt;
Thanks.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139466</guid>
		<pubDate>Fri, 30 Apr 2004 15:48:20 -0800</pubDate>
		<dc:creator>Jonasio</dc:creator>
	</item><item>
		<title>By: falconred</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139478</link>	
		<description>FYI: using auto-Preview in Outlook 2000 has been known to be a security risk, you should leave it off if possible.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139478</guid>
		<pubDate>Fri, 30 Apr 2004 16:06:52 -0800</pubDate>
		<dc:creator>falconred</dc:creator>
	</item><item>
		<title>By: fvw</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139508</link>	
		<description>I don&apos;t buy the mixed up message ID thing. I doubt outlook uses message IDs for anything apart from threading, and more significantly, the random word strings in the text part of a multipart/alternative spam are very common these days. I&apos;m going to go with zsazsa&apos;s theory that it uses the plaintext version for preview.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139508</guid>
		<pubDate>Fri, 30 Apr 2004 18:45:51 -0800</pubDate>
		<dc:creator>fvw</dc:creator>
	</item><item>
		<title>By: Jonasio</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139510</link>	
		<description>Here&apos;s a way to test the theory:  the message ID for this email is&lt;br&gt;
&lt;br&gt;
Message-ID: D2CA6B6871448D6@endoderm&lt;br&gt;
&lt;br&gt;
ph00dz, or anybody else that has received this particular spam, if you&apos;d kindly check your spam&apos;s ID against this one, we&apos;ll know if the spammer is recycling the same ID or not.  &lt;br&gt;
&lt;br&gt;
Worth a shot, anyway.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139510</guid>
		<pubDate>Fri, 30 Apr 2004 18:57:13 -0800</pubDate>
		<dc:creator>Jonasio</dc:creator>
	</item><item>
		<title>By: ph00dz</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139557</link>	
		<description>Sorry for the self link, but my heywood@jablome.com experiment captured the spam &lt;a href=&quot;http://jablome.com/index.php?msgID=215&amp;pageNum=1&amp;searchTerm=xanax&quot;  jablome&gt;here&lt;/a&gt;. &lt;br&gt;
&lt;br&gt;
I got the headers &apos;n&apos; everything if you want to check it out.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139557</guid>
		<pubDate>Sat, 01 May 2004 01:35:51 -0800</pubDate>
		<dc:creator>ph00dz</dc:creator>
	</item><item>
		<title>By: andrew cooke</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139569</link>	
		<description>it has the strcuture zsazsa predicted, while the message id is different, which doesn&apos;t support richard&apos;s idea.  but that&apos;s not conclusive - someone needs to view the same email in outlook.  if the preview shows the text visible directly in the link above, but viewing the iterm shows the &quot;html page&quot; then zsazsa has it.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139569</guid>
		<pubDate>Sat, 01 May 2004 04:48:47 -0800</pubDate>
		<dc:creator>andrew cooke</dc:creator>
	</item><item>
		<title>By: andrew cooke</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139570</link>	
		<description>ps the site&apos;s a nice idea (thought i&apos;d seen this discussed somewhere - was it on /. or ntk?)</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139570</guid>
		<pubDate>Sat, 01 May 2004 04:49:47 -0800</pubDate>
		<dc:creator>andrew cooke</dc:creator>
	</item><item>
		<title>By: bingo</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139574</link>	
		<description>&lt;em&gt;As an interesting aside, sometimes the anti-filter quotations are intriguing enough that I actually open the email to read the rest of the quotations. Now if that isn&apos;t mind-blowing, I don&apos;t know what is... spam that is interesting enought that I actually care to open it.&lt;/em&gt;&lt;br&gt;
&lt;br&gt;
In other news, some people are so intrigued by an ad that they buy the associated product.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139574</guid>
		<pubDate>Sat, 01 May 2004 05:25:18 -0800</pubDate>
		<dc:creator>bingo</dc:creator>
	</item><item>
		<title>By: Pericles</title>
		<link>http://ask.metafilter.com/6917/How-Spam-Works#139595</link>	
		<description>I&apos;m with Jonasio. I&apos;ve never bought generic viagra or whatever they&apos;re selling, but I can&apos;t resist the Finnegans-Wakesque poetry of &quot;grand piano living with corporation brainwash polar bear from salad dressing&quot; when it pops up after a message from my boss talking about &quot;leveraging synergies&quot; and similar management bullshit ...</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.6917-139595</guid>
		<pubDate>Sat, 01 May 2004 09:01:08 -0800</pubDate>
		<dc:creator>Pericles</dc:creator>
	</item>
	</channel>
</rss>
