Saturday, November 01, 2003


Security Hole - Spam. I use a spam checker that uses various strategies to identify spam email. One of them is that it will send an email back to a suspected spammer asking to prove that they are a real person (by identifying an image) - known as a Challenge message. Clever idea, no?

Here's the problem: the very act of sending that email reveals my primary email address to the spammer! I've carefully protected my primary email address and kept it off lists, and I believe this hole has now cracked that open. Luckily almost all spammers seem to have fake From: addresses so they aren't reading the challenge. I've turned the feature off!


7:22:52 AM  >  trackback []   comment []