Forums  Register  Login  My Profile  Inbox  Address Book  My Subscription  My Forums 

Member List  Search  FAQ  Ticket List  Log Out

 

PDF Spam updates

 
Logged in as: Guest
Users viewing this topic: none
  Printable Version
All Forums >> [Web & Mail Security] >> GFI MailEssentials >> PDF Spam updates Page: [1]
Login
Message << Older Topic   Newer Topic >>
PDF Spam updates - 20.Jul.2007 10:42:49 AM   
Nicks

 

Posts: 2772
Joined: 17.Mar.2003
Status: offline
This thread will contain information on the updates released for GFI MailEssentials which target the evolving PDF spam attacks.

So as to keep the posts in this thread concise, the thread will be locked. Kindly use the active post on the topic to post your feedback and comments - http://forums.gfi.com/PDF_Spam/m_900750394/tm.htm.

_____________________________

Nicholas Sciberras
GFI Software
Blog-Twitter-YouTube-Facebook
Post #: 1
RE: PDF Spam updates - 20.Jul.2007 10:47:30 AM   
Nicks

 

Posts: 2772
Joined: 17.Mar.2003
Status: offline
A new build of GFI MailEssentials 12 (build 20070707) has been released. This build targets the first variants of the pdf spam emails. Information on the new build can be found at http://kbase.gfi.com/showarticle.asp?id=KBID003114

_____________________________

Nicholas Sciberras
GFI Software
Blog-Twitter-YouTube-Facebook

(in reply to Nicks)
Post #: 2
RE: PDF Spam updates - 20.Jul.2007 10:48:52 AM   
Nicks

 

Posts: 2772
Joined: 17.Mar.2003
Status: offline
A new update in the form of a patch has been released. This update patch targets the most recent type of pdf spam.

This patch should be applied to installations of the following builds of GFI MailEssentials 12:

- 20070707

Issues fixed:

  1. The Header Checking > "Check if e-mail contains PDF spam" check has been updated to cater for the evolving PDF spam attacks.
  2. A check has been implemented so that a PDF smaller than 30kb will be blocked.

    The default value can be changed by adding a DWORD registry value called 'minpdfsize' in [HKLM\SOFTWARE\GFI\ME12\Config\]. The registry value is in bytes. To disable this check, create the registry key and set the value to 0.

The patch can be downloaded from ftp://ftp.gfisoftware.com/support/ME12_PATCH_20070718_01.zip
Installation instructions can be found in readme.txt included in the zip.

_____________________________

Nicholas Sciberras
GFI Software
Blog-Twitter-YouTube-Facebook

(in reply to Nicks)
Post #: 3
RE: PDF Spam updates - 9.Aug.2007 4:12:05 AM   
Nicks

 

Posts: 2772
Joined: 17.Mar.2003
Status: offline
We're seeing quite a rapid evolution of spamming techniques lately.
We've seen pdf spam containing text, pdf spam containing images, excel files containing text, and zip files containing excel files among others. The underlying trend is the use of container formats so as to obfuscate the underlying text or image spam from anti-spam filters. We expect to see the continued introduction of new container file formats as the spammers continue to develop the use of this technique. The viability of this technique to spammers is based upon the container file format being supported by the end user system and the likelihood of the end user clicking through the layers of containers.

We are currently working on a new build of GFI MailEssentials 12 in which the current PDF spam check will be evolved so as to target these new trends in spam focusing on the presence of a small attachment in combination with limited or no body text and/or subject line. The tentative release date for this update is mid-August.

We are also looking at means of applying other more generic capabilities against this type of spamming technique. At this moment in time, Bayesian works successfully against top level text and image spam. We have some interesting lines of research about how to include attachments in our Bayesian analysis; however it will take us a couple of weeks to determine its ultimate effectiveness in a production environment.

_____________________________

Nicholas Sciberras
GFI Software
Blog-Twitter-YouTube-Facebook

(in reply to Nicks)
Post #: 4
Attachment Spam updates - 20.Aug.2007 8:15:09 AM   
Nicks

 

Posts: 2772
Joined: 17.Mar.2003
Status: offline
A new build of GFI MailEssentials 12 (build 20070810) has been released. This build targets Attachment Spam. Information on the new build can be found at http://kbase.gfi.com/showarticle.asp?id=KBID003143

_____________________________

Nicholas Sciberras
GFI Software
Blog-Twitter-YouTube-Facebook

(in reply to Nicks)
Post #: 5
Page:   [1]
All Forums >> [Web & Mail Security] >> GFI MailEssentials >> PDF Spam updates Page: [1]
Jump to:





New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts