A little trick to spam the spammers (2021)
misc.l3m.in
misc.l3m.in
DonHopkins on Nov 14, 2016 | parent | context | favorite | on: The NHS's 1.2M employees are trapped in a 'reply-a...
Back in the days of ARPANET mailing lists, there used to be an "educational" mailing list called "please-remove-me", that was for people who asked an entire mailing list to remove them, instead of removing themselves, or sending email to the administrative "-request" address.
So when somebody asked an entire mailing list to remove them, somebody else would add them to the "please-remove-me" mailing list, and they would start getting hundreds of "please remove me" requests from other people, so they could discuss the topic of being removed from mailing lists with people with similar interests, without bothering people on mailing lists whose topics weren't about being removed from mailing lists.
It worked so well that it was a victim of its own success: Eventually the "please-remove-me" mailing list was so popular that it got too big and had to be shut down...
...Then there was Jordan Hubbard's infamous "rwall incident" in 1987:
https://techcommunity.microsoft.com/t5/exchange-team-blog/me...
lol
May I amend this to say "IT policies" are to blame?
Thinking back to my own days in the IT Department, I would have LOVED to say "No" to the requests to make yet another distribution list for a Senior Manager or Director, full of everyone and their assistants for the very same reason as you (plus a few other reasons), but that was just one of the many things I had a lot of power to execute but next to no power to actually influence-at least if I had any expectation of keeping my job and not getting chewed out for balking at such requests.
Memory goes back to the two worst IT Admin positions I held, both were in high volume calling environments, both involved people constantly moving between teams, managers renaming teams, trading personnel, moving people between groups, hot desking--all of which involved the constant creation and distruction of distribution groups, ring groups, hunt groups etcetera in ADUC, hot phones, not to mention the nesting of groups within groups within groups, and no amount of "showing my work" to the Director or IT Management to show how nothing was getting done except beating our Exchange Server into a bloody mess got any movement from anyone in leadership
So I quit trying, and eventually just quit.
Once upon a time that was the accepted albeit snarky way to inform senders they were misusing the to field and that the recipient was not interested in the message
I would definitely still use it for that, albeit wouldn't use it within a reply all.
The ultimate thing that helped immediately: reply-all to hundred recipients. (Also got my account blocked from sending emails for a while. Fun)
A fun aside is the article on wikipedia [1] begins with Jordan Hubbard and ends with Epic:
[0] https://linustechtips.com/topic/1435395-epic-games-github-em...
Not as large, but reminds me of a new freshman when I was a senior in college back in 1993 that got the great idea to "cd /home; mail *" on the main undergrad machine. Complaints to us admins were flooding in for days.
If someone sends an email with most of the words just being "unsubscribe" or "remove me" then at the least you don't send it on. Added points for auto-replying unsubscribe instructions or even just do it.
Fairly basic for a mailing list program.
Pure genius.
If you actually want to (potentially) break something, try submitting some obscure characters or malformed html into some fields. Blank spaces in emails can particularly be a nuisance.
And if you want some real fun, some systems only enforce validation rules via client-side javascript. If you block them, you might be able to submit some real chaotic entries.
We will often take your name and insert them into emails (for some dumb reasons around personalization supposedly increasing opens). But an email being stuffed full of spam words is a good way to get it flagged by anti-spam software and potentially hurt our sender reputation score.
You would probably have to do it en masse and use real inboxes. A couple other names you could use would be "free", "lovers", "singles", or any sort of mid word character substitution.
We were not allowed to send emails with “pussy bow” blouses as they were getting caught by corporate spam filters
One of my favorites was in Leather Goddesses of Phobos. Something like:
LGOP: ... there is a painting of a cat.
> LOOK PAINTING
LGOP: It's a very nice painting of a pussy, but is it art?
That said, the real guilty spammers are the companies doing it under the flag of a sales tool. RIP your email if you put it in a git commit.
not my fault you haphazardly inserted <whatever I crafted> into an HTML field in some browser at some point in the future.
DNS records, facebook statuses, titles of apps on the playstore, Wifi SSIDs, BIO's on obscure forums, names of children, recipe ingredients, your TV's network nick name...anything that can hold the input of a user, that a scraper or content mechanism will eventually naively come across...
eventually it will get added to the DOM of some unknownst messenger, and I will receive a ping, letting me know that someone, somewhere, somewhen, sniffed my digital fart.
Good way to put it, and I'm going to share this.
ITT people are using Spam to cover all sorts of junk email, but in my mind there is a difference between companies engaging in annoying methods to get your consent and organizations engaging in bad faith breaches of CAN-SPAM.
If my email is public because it’s in a Git commit or a Gravatar or even an intentionally public “email” field in my profile, that is not consent to send me unsolicited, automated messages followed by a multi-day campaign of emails guilt-tripping me for not responding to the first one. Maybe they have an unsubscribe link at the bottom. I don’t know, because I don’t open unsolicited emails that may contain malicious zero-days targeting my device. But if they do include the unsubscribe link, it doesn’t make me think any better of them and it doesn’t absolve them of any moral wrong-doing.
If you’re a founder or employee of a company that revolves around sending automated emails to non-customers, just be aware that your target market is a group of self-anointed “hustlers” who send unsolicited email messages to people who slowly grow to rightfully despise them. If your “marketing database” is a scraped list of emails, you should delete it and shut down the company. In the future, consider using your skills to work on problems that have a positive impact on the world.
However, you've unwittingly touched on one of the philosophical divisions that exist in most organizations between Marketing and Sales: Sales departments in general have a much more "liberal" idea of who is email-able. The idea being, "what's the rule against me just emailing someone about something"?
Well, you give a mouse a cookie and before you know it Sales has an entire email automation system to themselves. So if you look at an expensive sales tool like Outreach or Salesloft and ask, "what's the difference between this and a normal email automation tool" the answer is a lot of money and a lot of looking the other way.
So to give you a window into the politics of a GTM organization, most companies keep kind of a curtain of plausible deniability between their "inbound"/optin-based marketing and their outbound sales systems.
So I will say I have witnessed some amount of "grey market" lists (Tech Target, Experts Exchange, etc). But in my professional opinion, all these seem to do is generate garbage leads and unsubscribes.
>S: (n) spam, junk e-mail (unwanted e-mail (usually of a commercial nature sent out in bulk))
http://wordnetweb.princeton.edu/perl/webwn?s=spam&sub=Search...
There's a product we use called SiftRock that automatically sorts through noisy inboxes and detects real human responses so we know which ones a service person actually needs to respond to.
Most of the other 10% goes to spam anyway and I never see it. Apart from the obvious spam that I never see anyway, I very rarely get emails that I didn't intend to receive.
Terrible! It's as good as no validation. Client side validation should simply save the convenience of a wasted HTTPs request.
Surely better to send known honeypot email addresses if looking to poison an email list.
My wife got pissed at their lack of response. She took our two boys to their office, sat down, and instructed them to feel free to touch and play with everything (tile, wood samples, etc.) Salesperson notices and approaches “can I help you?” She explained the situation and the salesperson said no problem we will send someone next week.
Unsatisfied with this answer- we had already experienced many weeks of “soon” - she said ok no problem, we will just sit here until someone shows up at our house to finish the job.
Sure enough a worker showed up later that day and installed the three punch list items we had identified. Worked like a charm!
Eventually, he got what he wanted to get : some 30k€ of construction work that weren’t estimated up front and that they tried to make him pay once back to the wall. And as a plus, the company’s boss took directly the management of the project.
My writeup about this "project": https://blog.healthchecks.io/2020/09/about-tracking-cookies-...
https://github.com/cl-test-grid/cl-test-grid/blob/873b2fa978...
I don't know if this snippet is really effective, can be improved a little, especially that I noticed a couple of new crawlers that ignore `User-agent: * Disallow: /path` in robots.txt, and do not fix that even after reported.
archive.org is the worst offender for me; not only do they ignore robots.txt, there is absolutely no way to get something removed once they archived it (despite the data including accidentally leaked PII for example - which can cause actual harm to someone).
If you examine a website looking for "sign-me-up" buttons, and click them, and submit a subscription form, then you've solicited their newsletter.
Whether you define spam as "Unsolicited Commercial Email" or "Unsolicited Bulk Email", it ain't spam if you asked for it.
There is no dark pattern that will persuade me that typing in my email address isn't going to result in commercial email. If doing that is a condition for receiving service, then I have to decide how much I want the service. If I go ahead and sign up, I certainly can't complain that the resulting newsletter is spam.
Online shops often require an email address when I order. They send it an order confirmation/invoice or whatever. Is that manipulation or briberousness?
This phrase "technically solicited": I suppose if some company gets my email so they can send me an invoice, and then proceeds to send me newsletters daily, with no means to unsubscribe, well, I solicited the order-confirmation, not the newsletters. That's not technically solicited; it's unsolicited (and it's a shop I won't be using again).
I live in Europe where we have a few minor rights and such so I guess I just have higher standards for online interactions ¯\_(ツ)_/¯
If I find something interesting I will contact the owner of the website or share what I find (using https://links.l3m.in/ :P), but I don't want to receive an email per day/week.
The real problem here is my internet connection ; my top upload speed seems to be something like 100-200ko/s, which isn't very much when there's a lot of people loading various parts of my self-hosted websites :(
Keep refreshing like anyone (I guess), my server is at 1.5% of load average, you should be able to access this txt file, if my slow connection is allowing you to reach my server :/
HTTP/1.1 200/OK
Link: <https://l3m.in/>; rel="home"
Link: <https://misc.l3m.in/txt/>; rel="up"
Link: <https://misc.l3m.in/txt/js_ratio.txt>; rel="prev"
[1]: https://datatracker.ietf.org/doc/html/rfc8288#section-3.5[2]: https://www.iana.org/assignments/link-relations/link-relatio...
I guess it would be nice for bots to get the set of links in a header.
At least that's what a friend told me. ;)
I do occasionally wonder if it would still work, but most business reply mail type spam has been supplanted by email nowadays.
Back when web culture was smart.
Edible Arrangements is the most recent place this happened. The store wouldn't sell anything to me without an address and phone number, even though I was paying cash. The manager said the POS wouldn't even let him start a transaction without collecting the information.
So Edible Arrangements' marketing department is now spamming my local Edible Arrangements store.
I gave up trying to explain why I prefer not to have that info, so I just give them obviously bogus info that I can remember. Most people don't even realize what you're telling them. They just robotically enter the numbers. They just want to get on with their day as much as you do, and really don't want to hear your diatribe about big brother tracking blah blah, can you hurry up the line is backing up.
Phone (local area code) 867-5309 Name: Jenny Blues.
hostmaster@<domain>
postmaster@<domain>
webmaster@<domain>
dns-admin@<domain>
info@<domain>
contact@<domain>
root@<domain>
(And if they do, if anyone is actually reading the mail coming to those addresses.)I used to but I got so much spam and 0 actually legit mails to these addresses on my own domains so I stopped accepting externally incoming mails for those names/aliases.
It's actually a bit more complicated than that. Our expensive GDPR lawyers have made it clear there is still some amount of risk.
The example was of a German citizen booking American hotels for their vacation. Under the wording of the GDPR law, if their data was breached, the hotel could be held liable under a German court.
Now, the realisticness of this actually going to court or there being any meaningful penalty has not really been tested, but it's our corporate policy not to be the first ones to do so. So even for signup forms targeting Americans for American events, legal has asked us to specify to always collect country information (so we know what GDPR rules to process this person under) or include a dumb disclaimer that people from certain countries should not sign up.
Just works.
> Denial of service attacks (flooding a mailbox with junk) will be easier after this document becomes a standard, since more systems will support the same set of mailbox names.
The spam we got was often useful for abuse handling and spam filtering too. It was a good thing!
Every network should have an abuse@ address. Web forms are pretty popular these days too, but every extra hoop you force reporters to jump through can cut down on the reports you get of problems on your network. It's worth dealing with the spam to make sure you're getting notified as quickly as possible.
A honeypot is an email address that should never get email, typically because the only way a spammer can capture the address is by scraping a web-page. Role addresses don't need to be scraped; they're well-known.
The text on his contact page literally start with "warning: if you want to pay me to put something on my site your email address will be leaked on this page". Funny how many people won't read any content of a website but still want to pay in order to put content on them :P
So I set up my .forward to bounce spam from that company right back to any email addresses I can find for them and their ISP. Every spam I get, I add another copy to the list. The folks at xertog.com currently get 8 copies each to their noc@, sales@ etc for every spam they send me.
I couldn’t get them to stop calling me or cancel the account.
So I changed my phone number to their support line number. Never got another call.
15 years later I wonder if they still call themselves.
On the other hand, if you do want a one-time piece of email, but don't want to be subscribed to a mailing list, check out sharklasers.com. It's a free temporary email service that works pretty well
You cant just remove yourself with replying either, you have to go to a website and remove them, either 1 at a time or if lucky a unsubscribe all.
But its ironic the government email lists are being abused to such an extent to annoy people.
I had users get caught in such an attack, but easily enough to just spam their domains. Hammer solution, but quick fix.
If I were to do this, the email wouldn't be fake!
I have hundreds of email aliases on my (main) domain, and the list keeps on growing.
The best part of running Postfix was I could add domains and addresses to a denylist and it would bounce the email and the senders server would often put a REJECTED message in their inbox. The email equivalent of slamming the door.
I have seen this done before where we were forced to use technology that would support both Mac and Windows because the CTO had a Mac (and that was the only reason). So Silverlight it was :-/. Yes you can guess the year probably!
> published: 26/07/21 (dd/mm/yy) > updated: not yet
> A little trick to spam the spammers.
> When I find a "get X free" button on a website that then asks for my email address, I like to search for the email of the company behind the website (sometimes it's on the legal page, or the privacy policy page) and I submit their email. I also make sure to check the "sign me up for the newsletter" box, to make sure the spammers get at least one of their messages.
> I don't really know why I do this, it seemed funny a few months ago when I started and now I do it out of habit.
> I now keep a list of emails from these spam sites, and subscribe them all to the various newsletters I find if I have 5 minutes.
all@domain.com allstaff@domain.com support@domain.com legal@domain.com careers@domain.com refunds@domain.com
If you really don't like them keep adding those addresses to other subscriptions.
If all goes well they'll end up on black lists really quickly.
It was a huge pain in the butt. Nowadays we would probably barely notice.
And of course, as others suggested, you can also subscribe sales, hiring, website staff, abuse@ and other departments.
"What kind of chip you got in there, a Dorito?"
Keep refreshing, maybe you will find a way to this txt file :P
Or state-level intelligence addresses / TLAs of various stripes.