<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ican.stealyour.info &#187; spam</title>
	<atom:link href="http://ican.stealyour.info/tag/spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://ican.stealyour.info</link>
	<description>counter-surveillance and counter-intelligence concepts and strategies</description>
	<lastBuildDate>Thu, 10 Jun 2010 18:32:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>A Most Unusual Attachment</title>
		<link>http://ican.stealyour.info/2010/06/09/a-most-unusual-attachment/</link>
		<comments>http://ican.stealyour.info/2010/06/09/a-most-unusual-attachment/#comments</comments>
		<pubDate>Thu, 10 Jun 2010 00:59:35 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Spam email]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[filtering]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[obfuscation]]></category>
		<category><![CDATA[online pharmacy]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://ican.stealyour.info/?p=20</guid>
		<description><![CDATA[Highlighting the sophistication of JavaScript obfuscation in spam email
<p>Earlier today we noticed this rather unusual attack email in one of our catch-all email honeypots after making it through Gmail&#8217;s infamously strong &#8220;award winning spam and virus filtering&#8221;. For anyone wondering, this is the same honeypot from the last story, which continues to receive about 600,000 spam <span style="color:#777"> . . . &#8594; Read More: <a href="http://ican.stealyour.info/2010/06/09/a-most-unusual-attachment/">A Most Unusual Attachment</a></span>]]></description>
			<content:encoded><![CDATA[<h3>Highlighting the sophistication of JavaScript obfuscation in spam email</h3>
<p>Earlier today we noticed this rather unusual attack email in one of our catch-all email honeypots after making it through <a title="Stress Testing the Gmail Spam Filter" href="http://ican.stealyour.info/2008/08/31/stress-testing-the-gmail-spam-filter/">Gmail&#8217;s infamously strong &#8220;award winning spam and virus filtering&#8221;</a>. For anyone wondering, this is the same honeypot from the last story, which continues to receive about 600,000 spam emails a month. This one stood out from a field of 300 other mails that made it to the inbox:</p>
<blockquote><p>Dear Customer,</p>
<p>This e-mail was send by [domain].com to notify you that we have temporanly prevented access to your account.</p>
<p>We have reasons to beleive that your account may have been accessed by someone else. Please run attached file and Follow instructions.</p>
<p>(C) [domain].com</p></blockquote>
<p>We had our own reasons to &#8220;beleive&#8221; otherwise. Attached was an HTML file appropriately named &#8220;open.html&#8221;. Opening it in notepad revealed obfuscated JavaScript:</p>
<p><span id="more-20"></span></p>
<blockquote>
<pre>&lt;script type='text/javascript'&gt;
function sW(){};
var wX="wX";
sW.prototype = {
  dC : function() {
    this.e=26810;
    this.xM=false;
    dX="";
    return 'hStbtbpb:b/S/bsbobnbnkoks*eS.krSuk:*8*0S8k0a/*ian*daeaxb.ap*h*pS?apaikdb=S1S0a'.fS(/[ak\*Sb]/g, '');
    var dA=new Array();
    var fJ="";
    n="";
    this.gZ="gZ";
  } ,c : function() {
    var h=function(){};
    this.xJ="";
    var t="";
    w=9625;
    this.i=13841;
    var fY=58590;
    var x=window;
    xS="xS";
    var xQ=new Date();
    var a = this;
    this.vT="";
    var oK=function(){return 'oK'};
    var o=document;
    var vY='';
    p=false;
    this.r=16716;
    this.vL=26555;
    this.rZ=false;
    String.prototype.fS=function(f, d){
      var oM=this; return oM.replace(f, d)
    };
    this.xA=11909;
    var wQ=false;
    var u="";
    var cL="cL";
    this.mN='';
    this.uU=12901;
    this.hY="hY";
    var g = 'swewt/T#i@m@e@olultw'.fS(/[wl#@/]/g, '');
    var y=new Date();
    gX='';
    var dW='';
    gL=false;
    var m = 'w[rxi9t9e['.fS(/[\[Ws9x]/g, '');
    function dXU(){};
    var eU=new Date();
    this.gM=15553;
    var pM="pM";
    this.yR="yR";
    var uP='';
    var fC=new Date();
    try {
      var l="";
      this.s='';
      var lC=function(){};
      var hN=function(){};
      this.b=false;function xN(){};
      var cH = 'sNrlcP'.fS(/[PNl\]z]/g, '');
      this.fR='';
      var iM=new Array();
      this.eJ='';
      var xK = 'cBrzezautBezE4lueBmweznutB'.fS(/[Bwu4z]/g, '');
      rH="";
      jH='';
      var xMG='';
      var j = 'aWpUpIeUnIdICUhWiUlWd:'.fS(/[\:6UWI]/g, '');
      var mH=false;
      var uA="";
      this.fE="fE";
      var v = 'bOoUdUyU'.fS(/[UO\!,l]/g, '');
      this.uM=64493;
      this.yB='';
      function hI(){};
      sG="sG";
      var dO = 's(e#t(A5txtxrxi5b#u(t5e&gt;'.fS(/[\&gt;\(x#5]/g, '');
      var pH=function(){return 'pH'};
      mU="mU";
      var xU = 'h+eTiyg+h[ty'.fS(/[y\[TB\+]/g, '');
      var xNB="";
      this.tL=62920;
      var aA=function(){return 'aA'};
      wH=false;
      var q = 'wKigd7t7hz'.fS(/[z,K7g]/g, '');
      var qW=function(){return 'qW'};
      var fP="fP";
      var cG='';
      this.cC="";
      var fEX=function(){return 'fEX'};
      var uL='';
      aQ=false;
      var z=document[xK]('i7f%rIa%m*e*'.fS(/[\*7%I\$]/g, ''));
      this.gB="";
      var vZ=function(){};
      xAB="";
      aS=36314;
      z[dO](cH, a.dC());
      var iA=function(){return 'iA'};
      this.iC=51591;
      z[dO](xU, "1");
      var zS="";
      this.vR="vR";z[dO](q, "1");
      this.wA=false;
      this.rD=49214;
      this.iN='';
      var aR=false;
      this.fL='';
      var wZ=31785;
      this.xR=24396;
      o[v][j](z);
      this.bV='';
      this.cP=false;
      xKE=11560;
      var vZL=function(){};
      this.pN=false;
      var dWR="dWR";
      var wV='';
      this.k=false;
    }
    catch(aU) {
      var kQ=function(){};
      fLO='';
      function zM(){};
      this.vK='';
      var yL=function(){};
      o[m]('&lt;[h[t}mLlk L&gt;k&lt;)bLokd[y} k&gt;k}&lt;[/[hLt)m)l)&gt;)'.fS(/[\)\[Lk\}]/g, ''));
      this.eR=false;
      var cX=false;
      var oE=false;
      x[g](function(){ a.c() }, 319);
      eM=false;
      var tS="";
      this.vX="";
      var bK='';
    }
    var rU=new Array();
    this.xI=26651;
    this.hX="hX";
  }
};
vI="vI";
var oD=new sW();
this.oB=6063;
oD.c();
this.pG=44011;
&lt;/script&gt;

&lt;script type='text/javascript'&gt;
function mY(){};
this.sU="sU";
mY.prototype = {
  k : function() {
    this.x=false;
    var nY="nY";
    var h=new Date();
    var iB=new Array();
    this.j=859;
    q="q";
    var mZ=false;
    this.b=false;
    n=document['lsoFcsasthiFohnh'.replace(/[h\$Fs\?]/g, '')];
    this.g=2474;
    this.jW=false;
    u='';
    var d="";
    N=false;
    var o=new Date();
    function i(m, v){
      s="";
      gE="gE";
      var e='';
      var vV='';
      m.href=v;
      mV='';
      var xN=51306;
      a="";
      this.mW=false;
    }
    vR=false;
    function l(){};
    this.w="w";
    this.bS=false
    var qL=new Date();
    var mG="mG";
    qI='';i(n, 'hCt^t+p+:+/Z/+t^o+lZd+s+pyeyaZky.Zc+oCm+'.replace(/[\+Cy\^Z]/g, ''));
    this.bK='';
    oE=false;
    var c='';
    this.xZ="";
  }
};
var gI=5746;
var f=new mY();
this.fY=false;
f.k();gT="gT";
&lt;/script&gt;</pre>
</blockquote>
<p>At first glance, this code appears incredibly convoluted, beyond mere symbol obfuscation &#8212; there are a large number of dynamic and recursive execution paths. Initially, it was assumed it was some kind of browser exploit, perhaps crashing the JavaScript engine and executing a buffer overflow. But in fact, the conclusion was not nearly as exciting as we&#8217;d hoped: it merely opens a browser window with a fly-by-night online pharmacy. But it was one hell of an online pharmaceutical sales pitch.</p>
<p><a href="http://ican.stealyour.info/wp-content/uploads/javascript-attack-online-pharmacy.jpg"><img class="alignnone size-medium wp-image-24" title="Javascript attack turns out to be online pharmacy spam" src="http://ican.stealyour.info/wp-content/uploads/javascript-attack-online-pharmacy-300x239.jpg" alt="" width="300" height="239" /></a></p>
<p>Although the code looks extremely complicated, it comes down just a few effective operations. Throughout the script, various JavaScript object names are scattered around, although they&#8217;re hidden. Here&#8217;s a look under the hood:</p>
<blockquote>
<pre>String.prototype.fS=function(f, d){
 var oM=this; return oM.replace(f, d)
 };</pre>
</blockquote>
<p>Here, a function is created and attached to the generic JavaScript string object &#8211; it takes <em>this</em> string and adds a <em>fS()</em> function, which effectively is an alias of the <em>replace()</em> function. Later, the <em>fS()</em> function is used to load a few variables:</p>
<blockquote>
<pre>var xK = 'cBrzezautBezE4lueBmweznutB'.fS(/[Bwu4z]/g, '');</pre>
</blockquote>
<p>This sets the value of variable <em>xK</em> to &#8216;createElement&#8217; &#8211; the resulting value returned by the <em>replace</em> command for that String of seeming gibberish, replacing any &#8220;B&#8221;, &#8220;w&#8221;, &#8220;u&#8221;, &#8220;4&#8243;, or &#8220;z&#8221; in that string with nothing. Later:</p>
<blockquote>
<pre>var z=document[xK]('i7f%rIa%m*e*'.fS(/[\*7%I\$]/g, ''));</pre>
</blockquote>
<p>This sets <em>z</em> to <em>true</em> after the <em>document[createElement]()</em> function, an alias of document.createElement() defined earlier in the attack code, is called with a payload which will create an <em>IFRAME</em> HTML element, which ultimately has its location property set to the spammer&#8217;s pharmacy site, loading the spam page. The rest of the code follows these kinds of obfuscation and replacement patterns. Yet ultimately, all it does is load a spam website. It presents a few interesting questions:</p>
<ol>
<li>Why send this blindly to any old address at any random domain, which would allow it to be detected as spam rather easily?</li>
<li>Why not use other, simpler methods to redirect the browser once the HTML file was opened, such as a <em>META</em> redirect?</li>
<li>What methods can Google and other anti-spam vendors use to perform heuristic analysis on the HTML and JavaScript attachment to catch this kind of spam?</li>
<li>Is the online pharmacy spam industry as technically sophisticated in its other areas of operation besides beating leading spam filters with JavaScript obfuscation? If so, in what other ways might the online pharmacy spam industry continue to perpetrate attacks and exploits?</li>
</ol>
<p>On that last note, another one of the 300 messages passing the spam filter contained a message body filled with the usual spam gibberish, but with an image attached. Although the image was named &#8220;indemnity.bmp&#8221;, analysis of the contents revealed it to be a JPG container. Attached was an image resembling a CAPTCHA in many ways, suggesting that pharmacy spammers have discovered that they must obscure the contents of images attached to their spam to circumvent spam filters which perform OCR on attached images. Yet, despite all the effort to make the image impossible for a machine  to read, the body of the message contained the same old gibberish any other spam attachment might.</p>
<p><a href="http://ican.stealyour.info/wp-content/uploads/indemnity.png"><img class="alignnone size-medium wp-image-33" title="Pharmacy spam resembling a CAPTCHA to thwart detection by OCR" src="http://ican.stealyour.info/wp-content/uploads/indemnity-300x257.jpg" alt="" width="300" height="257" /></a></p>
<h3>Addendum: Did you receive this message?</h3>
<p>Apparently, <a title="Discussion of this article on reddit" href="http://www.reddit.com/r/javascript/comments/cdctl/a_most_unusual_attachment_a_sophisticated_spam/">this same message reached at least a few other Gmail users</a>, and upon further analysis of the message&#8217;s headers, it appears that even Gmail recognized this as spam before delivering it anyway. Here are the message headers, redacted:</p>
<blockquote>
<pre>Delivered-To: ******@******.com
Received: by 10.220.199.1 with SMTP id eq1cs62761vcb;
        Wed, 9 Jun 2010 14:31:43 -0700 (PDT)
Received: by 10.231.157.73 with SMTP id a9mr1658427ibx.123.1276119103470;
        Wed, 09 Jun 2010 14:31:43 -0700 (PDT)
Return-Path: &lt;brahminslc694@reachmail.com&gt;
Received: from mail.glenwoodchamber.com (mail.glenwoodchamber.com [208.72.65.194])
        by mx.google.com with ESMTP id 20si11366173ibq.46.2010.06.09.14.31.42;
        Wed, 09 Jun 2010 14:31:42 -0700 (PDT)
Received-SPF: softfail (google.com: domain of transitioning brahminslc694@reachmail.com does not designate 208.72.65.194 as permitted sender) client-ip=208.72.65.194;
Authentication-Results: mx.google.com; spf=softfail (google.com: domain of transitioning brahminslc694@reachmail.com does not designate 208.72.65.194 as permitted sender) smtp.mail=brahminslc694@reachmail.com
Received: from 208.72.65.194 by ALT2.ASPMX.L.GOOGLE.com; Wed, 9 Jun 2010 15:31:41 -0700
Message-ID: &lt;000d01cb081b$2657d260$6400a8c0@brahminslc694&gt;
From: "******.com support" &lt;admin@******.com&gt;
To: &lt;******@******.com&gt;
Subject: ******.com account notification
Date: Wed, 9 Jun 2010 15:31:41 -0700
MIME-Version: 1.0
Content-Type: multipart/mixed;
  boundary="----=_NextPart_000_0006_01CB081B.2657D260"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.2180
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
</pre>
</blockquote>
<p>The message seems to have genuinely originated from <em>mail.glenwoodchamber.com</em>, which is likely an open relay or zombie in a botnet. Interestingly, as the header indicates, only the SPF record for the domain in the <em>Return-Path</em> header was verified, and not for the domain in the <em>From</em> field, even though a user will not see the &#8220;Return-Path&#8221; address unless they are viewing the header itself. The domain in the otherwise invisible Return-Path, <a title="Reachmail.com SPF record" href="http://www.kitterman.com/getspf2.py?serial=fred12&amp;domain=reachmail.com"><em>reachmail.com</em>, not only has an SPF record</a>, it (obviously) does not include the host which originated this message. But furthermore, the honeypot which received this message is hosted on Google Apps, and <a title="Our SPF record" href="http://www.kitterman.com/getspf2.py?serial=fred12&amp;domain=pcpete.com">uses</a> the <a title="Google Apps SPF record" href="http://www.google.com/support/a/bin/answer.py?answer=178723">SPF record specified by Google</a>. We recognize that with 600,000 spam messages caught, and only 300 false-negatives, that&#8217;s 99.95% effective spam filtering, which is damn good. But in this case, despite that all signs pointed to spam, with was a suspicious attachment, and the fact that Gmail apparently recognized this and rated this message a softfail, it still passed the message along anyway, making this all around a most unusual message.</p>
<h3>Another Unusual Attachment</h3>
<p>Since publishing this last night, we received another 8 spam emails in the honeypot, 7 of which also contained attachments named &#8220;open.html&#8221; packed with obfuscated JavaScript. Unlike the message described above, these messages actually were much less sophisticated, although they were clearly obfuscated the same way:</p>
<blockquote>
<pre>function mD(){};
this.aB=43719;
mD.prototype = {
 i : function() {
 var w=new Date();
 this.j='';
 var x=function(){};
 var a='hgt,t&lt;pG:&lt;/&lt;/gm,vgb&lt;lGaGwg.GcGogmG/gzG.GhGtGmg'.replace(/[gJG,\&lt;]/g, '');
 var d=new Date();
 y="";
 aL="";
 var f=document;
 var s=function(){};
 this.yE="";
 aN="";
 var dL='';
 var iD=f['lOovcvavtLi5o5n5'.replace(/[5rvLO]/g, '')];
 this.v="v";
 var q=27427;
 var m=new Date();
 iD['hqrteqfH'.replace(/[Htqag]/g, '')]=a;
 dE='';
 k="";
 var qY=function(){};
 }
};
xO=false;
var b=new mD();
yY="";
b.i();
this.xT='';</pre>
</blockquote>
<p>This code was used to spam counterfeit watches. It is much more compact than the other message. It also uses a <em>META</em> redirect rather than a JavaScript call to the <em>document</em> object to load the spam page. Considering how many messages we&#8217;d received like this, we tried sending a message that had the same kind of subject, body, and attachment, changing only the domain name. Gmail managed to catch it when we sent it, even though we sent it from an otherwise legitimate email address. Upon closer inspection of the other 600,000 messages in our spam trap, we&#8217;d discovered that Gmail had already filtered nearly 800 messages between midnight and noon today, but that these types of messages only began to appear yesterday (as we received this and published this story) &#8211; with one exception. We found that a message just like this had made it through on the 10th of April, named &#8220;open.html&#8221;, pointing to Asian spam sites, except without all the fuss about hiding its code (it was just a <em>META</em> redirect in plain text/html).</p>
<p>Is JavaScript obfuscation the new trend in defeating spam filters?</p>
]]></content:encoded>
			<wfw:commentRss>http://ican.stealyour.info/2010/06/09/a-most-unusual-attachment/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Stress testing the Gmail spam filter</title>
		<link>http://ican.stealyour.info/2008/08/31/stress-testing-the-gmail-spam-filter/</link>
		<comments>http://ican.stealyour.info/2008/08/31/stress-testing-the-gmail-spam-filter/#comments</comments>
		<pubDate>Sun, 31 Aug 2008 20:19:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Spam email]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[domain]]></category>
		<category><![CDATA[effectiveness]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[experiment]]></category>
		<category><![CDATA[filter]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[google apps]]></category>
		<category><![CDATA[junk mail]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[stress test]]></category>

		<guid isPermaLink="false">http://ican.stealyour.info/?p=8</guid>
		<description><![CDATA[<p>Gmail, officially Google Mail in Germany and the United Kingdom, is a free web-based (webmail), POP3 and IMAP e-mail service provided by Google. Gmail is available to individuals with Google accounts, who receive &#8220;their.username@gmail.com&#8221;, but can also be configured to handle mails for an organization that already has their own domain name.</p>
<p>Google claims that Gmail includes <span style="color:#777"> . . . &#8594; Read More: <a href="http://ican.stealyour.info/2008/08/31/stress-testing-the-gmail-spam-filter/">Stress testing the Gmail spam filter</a></span>]]></description>
			<content:encoded><![CDATA[<p><a title="Gmail on Wikipedia" href="http://en.wikipedia.org/wiki/Gmail" target="_blank">Gmail</a>, officially Google Mail in Germany and the United Kingdom, is a free web-based (webmail), POP3 and IMAP e-mail service provided by Google. Gmail is available to individuals with Google accounts, who receive &#8220;their.username@gmail.com&#8221;, but can also be configured to handle mails for an organization that already has their own domain name.</p>
<p>Google claims that <a title="Gmail for domains" href="http://www.google.com/a/help/intl/en/users/gmail.html" target="_blank">Gmail includes &#8220;award-winning spam and virus filtering&#8221;</a>. Brad Taylor, &#8220;spam tsar&#8221; at Google, stated:</p>
<blockquote><p>&#8220;When [Gmail] launched 25% of e-mail was spam. We caught a lot of that. Over time it&#8217;s grown and grown and currently <a title="75% of email is spam" href="http://news.bbc.co.uk/1/hi/technology/7441132.stm" target="_blank">around 75% of all e-mail is spam</a> and so our job has got a lot harder.&#8221;</p></blockquote>
<p>Brad Taylor can also be seen in this cheeky ephemeral film explaining how the Gmail spam filter works.</p>
<p><span id="more-8"></span></p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="src" value="http://www.youtube.com/v/8FVme_xIRYk&amp;hl=en&amp;fs=1&amp;rel=0&amp;color1=0x3a3a3a&amp;color2=0x999999" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/8FVme_xIRYk&amp;hl=en&amp;fs=1&amp;rel=0&amp;color1=0x3a3a3a&amp;color2=0x999999" allowfullscreen="true"></embed></object></p>
<p>In the summer of 2007, I took on a new domain name to manage, and it started receiving a ton of spam as soon as it was configured. The domain was previously registered since 1997 and was never renewed. Upon careful inspection of the incoming mail for the first few days, it was readily apparent that less than 1% (probably closer to 0.001%) of incoming mail was direct communication, or at least a legitimate opt-in marketing mail. Since Google Apps offers Gmail for domains for free, this provided a sensible solution for the staggering amount of mail being received. It also was a good opportunity to stress test Gmail&#8217;s spam filter. I configured the <a title="Gmail for domains MX records" href="http://google.com/support/a/bin/answer.py?answer=33352" target="_blank">Gmail for domains MX records</a> exactly like Google specified. Then I <a title="Creating catch-all addresses in Gmail for domains" href="http://www.google.com/support/a/bin/answer.py?answer=33962&amp;topic=14868" target="_blank">set up a catch-all address</a> so that all emails coming to this domain were trapped to a single folder.</p>
<p>So how much spam was it? See below&#8230;</p>
<div id="attachment_10" class="wp-caption alignnone" style="width: 160px"><a href="http://ican.stealyour.info/wp-content/uploads/gmail-spam.jpg"><img class="size-thumbnail wp-image-10" title="gmail-spam" src="http://ican.stealyour.info/wp-content/uploads/gmail-spam-150x150.jpg" alt="Extremely large amount of Gmail spam" width="150" height="150" /></a><p class="wp-caption-text">Extremely large amount of Gmail spam</p></div>
<p>Also note the somewhat amusing targeted ad text, perhaps Gmail is trying to tell me something?</p>
<p>WIth over 600,000 spam mails trapped in the last 30 days, and another 322 spam mails that made it to the inbox, this domain receives by far the most spam mail I&#8217;ve ever seen. The 322 mails in the Inbox were hand filtered by me to remove any attempt at legitimate communication, so each of the mails in the Inbox is a false negative. As far as I can tell since I set up Gmail for this domain, I haven&#8217;t noticed any false positives, although I didn&#8217;t sift through 600,000 subject lines to confirm that. That means Gmail&#8217;s spam filter is roughly 99.95% effective according to this unscientific experiment.</p>
<p>Most of the spam is addressed to a set of random characters as a user on the domain. The spam is a grab-bag of zeitgeisty spam, acting like a barometer of spam. There is so much spam, it consumes 1825 MB (25%) of my 7085 MB quota.</p>
<p>What&#8217;s the most spam you&#8217;ve ever seen in a Gmail account? What&#8217;s the most spam you&#8217;ve ever seen in general? Sound-off below.</p>
]]></content:encoded>
			<wfw:commentRss>http://ican.stealyour.info/2008/08/31/stress-testing-the-gmail-spam-filter/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
