Nov 8, 2009
Pages: 1, 2, 3

Stop Spam Harvesters - add a Honey Pot to your site

free web hosting

Read Latest Entries..: (Post #21) by vizskywalker on Aug 31 2005, 02:45 AM.
Already a memebr and a proud donater of an MX entry. Already had one bot caught one with that MX entry. As soon as my website goes public it will have a honeypot page. For business websites, this is better than a ToS or Privacy Statement for convincing viewers that their email addresses are safe with you and you won't spam them. If you are stopping spammers, it almost guarantees you aren't one .~Viz...
read more.
Read the FIRST post of this Topic. - Express your Opinion! Contribute Knowledge :-).

Open Discussion & Free Web Hosting > Computers & Tech > How-To's and Tutorials > Internet > Emails

Stop Spam Harvesters - add a Honey Pot to your site

NilsC
A way to stop spam are identifying the top spam harvesters, and shut them down before they reach your mailbox. The time you get spam at a new email address can vary. If you never give out the address on the Internet and the address are not just a first or a last name you may not see spam for years. If you create a website and put your email address anywhere on the page, eventually it will be harvested by a spam bot.

Munging the address may help, same if you use ASCII characters that will prevent harvesting for a while.

A lot of the block lists used by email providers come from users reporting spam and email hitting spam traps. Project Honey Pot are going one step further by identifying the spam harvesters and bot / spiders they use to crawl over your web-space using your bandwidth stealing your email addresses.

This is achieved by handing out a unique email address to every hit on your spam-trap. If a bot follows the link to the honey pot and harvests the address it will be logged. When an email hits that particular email box a spam harvester are identified.

It’s a few different ways we can help stop the harvesters and help reduce spam. You can host a honey pot on your website or if that is impossible (like it is for me at the present time) you can put a link to the Project Honey Pots website and help educate others. The last way to help is donating MX addresses to the project. The more MX addresses they have the more variety of spam-traps can be created. If you have a domain name that you are not using donate up to 5 MX records for each domain name.

To learn more about the project go to . Stop Spam Harvesters, Join Project Honey Pot

I’m using the button on company web pages and will add a honey pot as soon as an “.asp” script are ready. I have an average of 5000 to 10000 spam per day hitting a email server with less than 200 users. The 50 to 250 that slip through the filters and spam assassin I report.

Nils

 

 

 


Comment/Reply (w/o sign-up)

Darren
QUOTE (NilsC @ Dec 25 2004, 03:09 PM)
A way to stop spam are identifying the top spam harvesters, and shut them down before they reach your mailbox. The time you get spam at a new email address can vary. If you never give out the address on the Internet and the address are not just a first or a last name you may not see spam for years. If you create a website and put your email address anywhere on the page, eventually it will be harvested by a spam bot.

Munging the address may help, same if you use ASCII characters that will prevent harvesting for a while.

A lot of the block lists used by email providers come from users reporting spam and email hitting spam traps. Project Honey Pot are going one step further by identifying the spam harvesters and bot / spiders they use to crawl over your web-space using your bandwidth stealing your email addresses.

This is achieved by handing out a unique email address to every hit on your spam-trap. If a bot follows the link to the honey pot and harvests the address it will be logged. When an email hits that particular email box a spam harvester are identified.

It’s a few different ways we can help stop the harvesters and help reduce spam. You can host a honey pot on your website or if that is impossible (like it is for me at the present time) you can put a link to the Project Honey Pots website and help educate others. The last way to help is donating MX addresses to the project. The more MX addresses they have the more variety of spam-traps can be created.  If you have a domain name that you are not using donate up to 5 MX records for each domain name.

To learn more about the project go to .        Stop Spam Harvesters, Join Project Honey Pot

I’m using the button on company web pages and will add a honey pot as soon as an “.asp” script are ready. I have an average of 5000 to 10000 spam per day hitting a email server with less than 200 users. The 50 to 250 that slip through the filters and spam assassin I report.

Nils
*


I think that this project is a great idea and as soon as I get a website running I will sign up for it. I will try almost anything to help stop or at least lower the amount of spamming that goes on. Thanks for the link smile.gif .

 

 

 


Comment/Reply (w/o sign-up)

daniel15
ah cool this is great! finally some people trying to stop spambots. I'm gonna donate some MX records to Project Homey Pot, since i've got a .INFO domain i'm not using...

Comment/Reply (w/o sign-up)

NilsC
QUOTE (daniel15 @ Dec 25 2004, 06:46 AM)
ah cool this is great! finally some people trying to stop spambots. I'm gonna donate some MX records to Project Homey Pot, since i've got a .INFO domain i'm not using...
*


Daniel,

I'm using MX records for domains I own and use. I have different mx record for my real email and donated mx records for the honey pot.
This are the real mx records that point to my email server:
  • mail.exampledomain.com
  • pop3.exampledomain.com
  • smtp.exampledomain.com
This are the donated MX records pointing to Honey Pots servers:
  • nopop3.exampledomain.com
  • nomail.exampledomain.com
  • nosmtp.exampledomain.com
Since it's ilegal harvesting email addresses in the US, the records will be used to help lawenforcement officers shut down spam harversters.

If you look at the top 20 list you can see that a lot of the spam bots are collecting the addresses from the same computer that they are sending the spam from (or from the same 0/24 range). The computer may be compromized but if we shudown compromized computers we shut down the spam.

Nils

Comment/Reply (w/o sign-up)

ouachiski
Glad to see that someone is finaly taking action afainst these pests. They do nothing but eat up bandwith and waist valuble time.

Comment/Reply (w/o sign-up)

pbolduc
Thanks for the link. This is a serious problem on the internet. Assinine individuals who would invade your privacy with spyware and harvesters ought to be lined up and shot.

wink.gif

Comment/Reply (w/o sign-up)

NilsC
QUOTE (ouachiski @ Dec 28 2004, 02:44 PM)
Glad to see that someone is finaly taking action afainst these pests.  They do nothing but eat up bandwith and waist valuble time.
*

[RANT]
spam is a pet peeve of mine... I hate it. I'm an active spam reporter. smile.gif I use spam-traps with some of my posts. I have not done it on this site yet but there are places I put a email address in my sigfile with text color the same as the background color. Only time that address get email is after a spam bot have harvested a forum or newsgroup. smile.gif
[/RANT]
QUOTE (pbolduc @ Dec 28 2004, 03:33 PM)
Thanks for the link.  This is a serious problem on the Internet.  Asinine individuals who would invade your privacy with spyware and harvesters ought to be lined up and shot.

wink.gif
*

[RANT]
If you read into the concept it will not stop spam but it will help identify spam harvesters and their IP address, a lot of times the spam bot are operated on zombie hosts without the knowledge of the user/owner. Some of the larger ISP's are ignorant when it comes to spam bot and don't shut them down when a complaint is filed. One of the excuses are "This is a dynamic IP range and it could have been anyone". (Translation, I'm working the abuse desk and I don't feel like checking the log to see who was assigned that IP address at the time of the complaint!) Or you get an auto-response that don't make sense or has anything to do with the problem you reported. I have reported open proxies and got an email back with the statement that this is not one of our email servers so we are not responsible for the spam, please report it to the proper ... bla bla bla.[/RANT] rolleyes.gif

When they get a notice from the authorities the response seems to be a lot faster. smile.gif
Thanks for the interest, be an active spamreporter. It's like hunting Osama Bin .... cool.gif
Nils

Comment/Reply (w/o sign-up)

r3d
i've heard once that most of this spams is made by email provider and spam assassins. you can also have some bux by just spamming. therefore spamming is business not a bad habit. and in my point of view this project honey pot is another good business smile.gif

Comment/Reply (w/o sign-up)

NilsC
QUOTE (r3d @ Dec 28 2004, 09:01 PM)
i've heard once that most of this spams is made by email provider and spam assassins. you can also have some bux by just spamming. therefore spamming is business not a bad habit. and in my point of view this project honey pot is another good business smile.gif
*

I'm still online even thou I should have gone to bed smile.gif

The Honeypot project are like astahost.com a free service by a company that are working to make money. smile.gif

CODE
Parent company in 'code' to keep link from non click able :) http://www.unspam.com/
is the parent company and they have to be in the business of making money.

The inherent problem with things you hear are "they are not first hand knowledge". Most of the income to spammers go to the big spam operations that are sending millions of spam a day. As a added side business they sell email addresses to spammer wannabies<sp> that buy a cd rom and think they can make money.

What spammers do are stealing from all of us, everyone on the internet that pay for the connection are paying the cost. spammers steal bandwidth, who pays for that, your ISP and in the end you pay for it.

The other issue are slow internet connection, if you are on a 56k dialup line and your pop3 email box are downloading 200 spam because you didn't go online for a couple of days. Are you going to be happy that you couldn't surf the net for 1/2hr because the spam downloaded? You can stop the transmission but then you may miss an important email.
What if your rich uncles email telling you to come and pick up a million $ bounced because your email box on the server was over the limit and your ISP bouncesd it.

Is it OK to steal a million $ from 1 person. If you answer no, then is it OK to steal $1.00 from a million people? the sum is the same and they are both wrong.

Nils signing off from Mars.

Comment/Reply (w/o sign-up)

Hercco
Very interesting project. I joined and am now scattering the links all over my site.

The idea is great and it's really easy to participate and it doesn't take webspace nor bandwidth much.

Comment/Reply (w/o sign-up)

Latest Entries

vizskywalker
Already a memebr and a proud donater of an MX entry. Already had one bot caught one with that MX entry. As soon as my website goes public it will have a honeypot page. For business websites, this is better than a ToS or Privacy Statement for convincing viewers that their email addresses are safe with you and you won't spam them. If you are stopping spammers, it almost guarantees you aren't one smile.gif.

~Viz

Comment/Reply (w/o sign-up)

Sarah81
Oh, how I love it when I hear about new ways to deal with spammers and their insipid little bots!

I hate spam. Yahoo! does a pretty good job of keeping it out of my inbox, but I still resent the fact that the spam even exists - and I DOUBLY resent the fact that it's such a huge, massive deal now. (Some people get THOUSANDS of junk mails every DAY.)

One of the best things that I've found to do is 1. don't fall for that stupid "click here to remove from mailing list" link ... and 2. cheer loudly when national news headlines are made because a bunch of idiots at UT-Austin were caught participating in one heck of a huge spamming organizations.

Comment/Reply (w/o sign-up)

mckenneth
hhmp.. great idea... once I've got my domain set up... I'll sign up to this program! laugh.gif

Comment/Reply (w/o sign-up)

lesmizzie
QUOTE (NilsC @ Dec 25 2004, 12:09 AM)
A way to stop spam are identifying the top spam harvesters, and shut them down before they reach your mailbox. The time you get spam at a new email address can vary. If you never give out the address on the Internet and the address are not just a first or a last name you may not see spam for years. If you create a website and put your email address anywhere on the page, eventually it will be harvested by a spam bot.

Munging the address may help, same if you use ASCII characters that will prevent harvesting for a while.

A lot of the block lists used by email providers come from users reporting spam and email hitting spam traps. Project Honey Pot are going one step further by identifying the spam harvesters and bot / spiders they use to crawl over your web-space using your bandwidth stealing your email addresses.

This is achieved by handing out a unique email address to every hit on your spam-trap. If a bot follows the link to the honey pot and harvests the address it will be logged. When an email hits that particular email box a spam harvester are identified.

It’s a few different ways we can help stop the harvesters and help reduce spam. You can host a honey pot on your website or if that is impossible (like it is for me at the present time) you can put a link to the Project Honey Pots website and help educate others. The last way to help is donating MX addresses to the project. The more MX addresses they have the more variety of spam-traps can be created.  If you have a domain name that you are not using donate up to 5 MX records for each domain name.

To learn more about the project go to .        Stop Spam Harvesters, Join Project Honey Pot

I’m using the button on company web pages and will add a honey pot as soon as an “.asp” script are ready. I have an average of 5000 to 10000 spam per day hitting a email server with less than 200 users. The 50 to 250 that slip through the filters and spam assassin I report.

Nils
*



To those confused, I think this is what the system does:

There are programs that go to random websites and pick out email addresses.

The honeybot code apparently gets the address of the company that is trying to snag email addresses in order to spam unsuspecting people.

The honeybot reports these addresses in order to stop the companies from doing this.

I hate spam. I get at least twenty spam messages every few hours, and it is very annoying and it slows down production.

I think that this is an ingenious way to fight spam!

Comment/Reply (w/o sign-up)

NilsC
They create a php page for you that you add to your website. It's not visible to humans and it have warnings in cleartex in case a user uses page source to get to the page, that is where all the legalese is that makes it legal smile.gif

On this page there is a email address that changes everytime a spider / bot collects it. The IP and other data are recorded in a database and if the email is used there will be a record of where and when it was collected. Since it's illegal to collect email addresses in a lot of places you can use
CODE
<meta name="no-email-collection" value="[link to your terms]" />
the no collect meta tag and link to your TOS, place it on all your webpages that way good bot's stay away from the pages.

A php script is created for you and you just have to upload it onto the server and place links to it on your webpages. Instructions come with it.

The honeypot does the rest, you will have email addresses that are automaticly updated and tracked by the projects servers.

Here is a link to the example honeypot http://www.projecthoneypot.org/honey_pot_example.php

Nils

Comment/Reply (w/o sign-up)


Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

This textarea will convert to Rich-Text automatically (IE, Firefox, Chrome)

Pages: 1, 2, 3
Similar Topics

Keywords : Spam Harvesters Honey Pot Site


    Looking for stop, spam, harvesters, add, honey, pot, site

See Also,

*SIMILAR VIDEOS*
Searching Video's for stop, spam, harvesters, add, honey, pot, site
advertisement



Stop Spam Harvesters - add a Honey Pot to your site

Affordable Web Hosting, Low cost Web Hosting - ComputingHost.com