Scammers skirt spam shields with help from Adobe Flash

Look in this specific forum for newly found security threats which may not yet be covered by your usual security software

Moderators: Admin Team, Moderators

User avatar
TeMerc
Site Admin
Site Admin
Posts: 15995
Joined: Fri Jan 28, 2005 5:16 pm
Area Of Expertise: Security
experience: I know the functions, OS settings, registry tweaks and more
PC time: What else is there in life?
Location: PHX, AZ
Contact:

Scammers skirt spam shields with help from Adobe Flash

Postby TeMerc » Thu Sep 04, 2008 12:44 pm

By Dan Goodin in San Francisco
Published Thursday 4th September 2008 18:14 GMT

Online scammers have found a new way to skirt anti-spam filters, this time by making use of Adobe Flash files hosted on free websites.

Spam messages with innocuous-looking content contain links to Flash-based files on ImageShack.com and elsewhere, according to a report from anti-spam service MessageLabs. Then commands embedded in the files redirect the recipient to sites that punt Viagra, work-at-home offers and free software updates.

The technique allows spammers to bypass content filters employed by many anti-spam products, which immediately nix messages that contain links to dodgy sites. Because popular sites such as ImageShack are whitelisted, use of the Flash file allows spammers to bypass the filter but still lure marks to sites that try to bilk them or trick them into installing malware.

"It seems a lot of the free image websites out there will quite happily accept a Flash file and attempt to display it," says Matt Sergeant, senior anti-spam technologist for MessageLabs. "The spammers basically get a free ride to bypass URL blocking."

nwz Continued @ The Register
Image

Return to “EMERGING SECURITY THREATS!”

Who is online

Users browsing this forum: No registered users and 2 guests