interesting spammer tricks

David Relson relson at osagesoftware.com
Wed Sep 24 05:25:12 CEST 2003


Tom,

I'm not sure exactly how good a foiler your message is.  The scoring
results using _my_ wordlists are given below.  Of interest is that using
my min_dev, robs, robx, etc the message parses with 11 hammish tokens
and 16 spammish tokens, which puts the message squarely in the "Unsure"
category (at 0.500000).  After using this message for spam training (and
then rescoring it), the score goes to Spam 1.01e-5 (which means the
score is 1.000000 - 1.01e-5, which is 0.999995 or so).

Once again, a spam trick that works the first time.  After training on
the trick, bogofilter will nail it to the wall!!!

Time for a new, different spammer trick!

David


--- use '-vv' to display histogram ---

[relson at osage src]$ bogofilter -vvF -c bogofilter.cf <
../../people/TomAnderson/spammer_trick 
X-Bogosity: Unsure, tests=bogofilter, spamicity=0.500000,
version=0.15.4.cvs.0923.1950

#  int  cnt   prob  spamicity histogram
# 0.00   11 0.017039 0.007584 ###########
# 0.10    0 0.000000 0.007584 
# 0.20    0 0.000000 0.007584 
# 0.30    0 0.000000 0.007584 
# 0.40    0 0.000000 0.007584 
# 0.50    0 0.000000 0.007584 
# 0.60    0 0.000000 0.007584 
# 0.70    0 0.000000 0.007584 
# 0.80    0 0.000000 0.007584 
# 0.90   16 0.980788 0.504404 ################

--- use '-vvv' and grep to see tokens used in scoring ---

[relson at osage src]$ bogofilter -vvvF -c bogofilter.cf <
../../people/TomAnderson/spammer_trick | grep "+$"
"head:In-Reply-To"                 187  0.001146  0.000000  0.000019 +
"head:References"                  183  0.001121  0.000000  0.000019 +
"definetly"                         15  0.000092  0.000000  0.000233 +
"scgi.ebay.com"                      9  0.000055  0.000000  0.000388 +
"to:oac-design.com"                  6  0.000037  0.000000  0.000582 +
"to:tanderso"                        6  0.000037  0.000000  0.000582 +
"subj:users"                       222  0.001342  0.000032  0.023190 +
"I'd"                            10480  0.063173  0.001793  0.027603 +
"url:24"                         47033  0.281854  0.010919  0.037294 +
"It'll"                            378  0.002261  0.000095  0.040538 +
"head:Sender"                      267  0.001581  0.000095  0.056984 +
"href"                           91477  0.046232  0.890581  0.950649 +
"color"                          63780  0.031522  0.622168  0.951778 +
"border"                         70958  0.029329  0.702132  0.959904 +
"width"                          70662  0.029151  0.699299  0.959982 +
"head:quoted-printable"           1163  0.000441  0.011576  0.963288 +
"height"                         69900  0.025781  0.697049  0.964333 +
"head:multipart"                  1343  0.000331  0.013677  0.976378 +
"head:html"                       1501  0.000221  0.015545  0.986006 +
"head:attachment"                  529  0.000031  0.005560  0.994508 +
"head:base64"                     1030  0.000043  0.010855  0.996058 +
"head:image"                       496  0.000012  0.005242  0.997655 +
"FFFFF4"                             3  0.000000  0.000032  0.997841 +
"vtz"                                3  0.000000  0.000032  0.997841 +
"head:Content-ID"                  467  0.000006  0.004945  0.998749 +
"head:gif"                         495  0.000006  0.005242  0.998819 +
"head:related"                     495  0.000006  0.005242  0.998819 +

--- train on new message (as spam) ---

[relson at osage src]$ bogofilter -vvF -c bogofilter.cf -s <
../../people/TomAnderson/spammer_trick
# 118 words, 1 message
bogofilter: list word - 94244 spam, 163219 good

--- recalc score of message ---

[relson at osage src]$ bogofilter -vvF -c bogofilter.cf <
../../people/TomAnderson/spammer_trick
X-Bogosity: Spam, tests=bogofilter, spamicity=1.01e-05,
version=0.15.4.cvs.0923.1950

#  int  cnt   prob  spamicity histogram
# 0.00    7 0.031730 0.011178 #######
# 0.10    0 0.000000 0.011178 
# 0.20    0 0.000000 0.011178 
# 0.30    0 0.000000 0.011178 
# 0.40    0 0.000000 0.011178 
# 0.50    0 0.000000 0.011178 
# 0.60    0 0.000000 0.011178 
# 0.70    0 0.000000 0.011178 
# 0.80    0 0.000000 0.011178 
# 0.90   43 0.988837 0.708172
###########################################
[relson at osage src]$ 




More information about the Bogofilter mailing list