[SpamCop.net - protecting the internet through technology]

[SpamCop-List] Re: rsp

J G anon at coks.net
Tue Aug 2 11:10:47 EDT 2005


On 8/2/2005 9:59 AM Mike Easter scribbled:

> I don't know what kind of experiment you are trying to do with the
> forgery of changing pr1ority.com to www.pr1ority.com to see what
> happens.
> 

w/o the www., which is what the original msg. was and reported as such,
SC didn't see the URL at all.  I just added www. to see if that made the
program see it, and it did but could not resolve it, which my utility
did.  I was curious as to why SC didn't resolve to 194.126.188.4 /after/
picking up the URL.

> A simpler experiment would be to just put the naked 'URL' into the
> parser and see if it can resolve -- because when you fool around with
> trial and error of forgeries for that particular spam you are dealing
> with the additional layer of how the spam is 'misconstructed'. 
> It is using some kind of crude or simplistic RTF rich text format and
> calling it text/html.

I didn't know that was possible - thought one needed headers and such...

> The simpler experiment shows that the naked url/s [with and without www]
> in the parser aren't resolved by SC.
> 


More information about the SpamCop-List mailing list