<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-17725307</id><updated>2011-04-21T21:29:40.218-07:00</updated><title type='text'>Dario La - Email Obfuscation Tools</title><subtitle type='html'>This is the project blog for the Dario La email obfuscation project at university of edinburgh</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://dariola.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://dariola.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>daVe =p</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>9</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-17725307.post-113405539801935101</id><published>2005-12-08T07:22:00.000-08:00</published><updated>2005-12-08T07:23:18.033-08:00</updated><title type='text'>[eBook] Spam-Proof Your E-Mail Address by Brian Livingston</title><content type='html'>https://windowssecrets.com/spamproof/buy.php&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/17725307-113405539801935101?l=dariola.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dariola.blogspot.com/feeds/113405539801935101/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=17725307&amp;postID=113405539801935101' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default/113405539801935101'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default/113405539801935101'/><link rel='alternate' type='text/html' href='http://dariola.blogspot.com/2005/12/ebook-spam-proof-your-e-mail-address.html' title='[eBook] Spam-Proof Your E-Mail Address by Brian Livingston'/><author><name>daVe =p</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-17725307.post-113405384688781413</id><published>2005-12-08T06:54:00.000-08:00</published><updated>2005-12-08T06:57:26.886-08:00</updated><title type='text'>projecthoneypot.org Finally found!</title><content type='html'>The original spam email harvesting project. http://www.projecthoneypot.org/&lt;br /&gt;&lt;br /&gt;Personal note:&lt;br /&gt;&lt;br /&gt;Yes, I've finally found the home of Project Honeypot today! I've been looking for this for this for the past two months and all google seems to return are links to articles. Visiting unspam.com did not provide any links the first few times I visited it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/17725307-113405384688781413?l=dariola.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dariola.blogspot.com/feeds/113405384688781413/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=17725307&amp;postID=113405384688781413' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default/113405384688781413'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default/113405384688781413'/><link rel='alternate' type='text/html' href='http://dariola.blogspot.com/2005/12/projecthoneypotorg-finally-found.html' title='projecthoneypot.org Finally found!'/><author><name>daVe =p</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-17725307.post-113405132148932707</id><published>2005-12-08T06:04:00.000-08:00</published><updated>2005-12-08T06:15:21.503-08:00</updated><title type='text'>Neumann@SRI RISK digest</title><content type='html'>Found an interesting mailing list quite a while back just before I got my RSI and lost my ability to type. Here's a link to &lt;a href="http://www.csl.sri.com/users/neumann/illustrative.html#31"&gt;index to articles on SPAM&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;There's also another &lt;a href="http://www.csl.sri.com/users/neumann/insiderisks04.html#163"&gt;article&lt;/a&gt; by &lt;b&gt;Marcus Ranum&lt;/b&gt; about the Security Myth that security has to be inconvenient. His comments that security often fails because:&lt;br /&gt;&lt;ol&gt;   &lt;li&gt;Security measure does not try to solve the problem - the &lt;span style="font-style: italic;"&gt;just work harder approach,&lt;/span&gt; that ignores the fundamental problems.&lt;br /&gt;  &lt;/li&gt;   &lt;li&gt;Security measures ignore human factors - users refuse or fail to use measures that they don't understand or require lots of effort.&lt;br /&gt;  &lt;/li&gt; &lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/17725307-113405132148932707?l=dariola.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dariola.blogspot.com/feeds/113405132148932707/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=17725307&amp;postID=113405132148932707' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default/113405132148932707'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default/113405132148932707'/><link rel='alternate' type='text/html' href='http://dariola.blogspot.com/2005/12/neumannsri-risk-digest.html' title='Neumann@SRI RISK digest'/><author><name>daVe =p</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-17725307.post-113224646261455813</id><published>2005-11-17T08:54:00.000-08:00</published><updated>2005-11-17T08:54:22.620-08:00</updated><title type='text'>Arable Labs II Honeypot</title><content type='html'>&lt;div style="float: right; margin-left: 10px; margin-bottom: 10px;"&gt; &lt;a href="http://www.flickr.com/photos/daveynet/64226365/" title="photo sharing"&gt;&lt;img src="http://static.flickr.com/32/64226365_4c1eb3990e_m.jpg" alt="" style="border: solid 2px #000000;" /&gt;&lt;/a&gt; &lt;br /&gt; &lt;span style="font-size: 0.9em; margin-top: 0px;"&gt;  &lt;a href="http://www.flickr.com/photos/daveynet/64226365/"&gt;Flickr_Screenshot&lt;/a&gt;  &lt;br /&gt;  Originally uploaded by &lt;a href="http://www.flickr.com/people/daveynet/"&gt;davey =P&lt;/a&gt;. &lt;/span&gt;&lt;/div&gt;The second version of the project's email harvesting honeypot was launched at arablelaboratories.com. &lt;br /&gt;&lt;br /&gt;So far we've had Google and Yahoo crawl through the site. Still waiting for those evil spambots to visit us! Hope they come soon.&lt;br clear="all" /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/17725307-113224646261455813?l=dariola.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dariola.blogspot.com/feeds/113224646261455813/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=17725307&amp;postID=113224646261455813' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default/113224646261455813'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default/113224646261455813'/><link rel='alternate' type='text/html' href='http://dariola.blogspot.com/2005/11/arable-labs-ii-honeypot.html' title='Arable Labs II Honeypot'/><author><name>daVe =p</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-17725307.post-112929935361036649</id><published>2005-10-14T07:03:00.000-07:00</published><updated>2005-10-14T07:15:53.616-07:00</updated><title type='text'>Waiting Time and User Tolerance Limit</title><content type='html'>Must identify a useability limit and upper bound on how long a user is willing to wait before getting an email address. How "frustrating the expectation is".&lt;br /&gt;&lt;br /&gt;In a discussion with Jon Oberlander today after lectures he suggested:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;1. What is the aim of the user when browsing the site? &lt;/span&gt;&lt;br /&gt;&lt;ul&gt;   &lt;li&gt;Users with specific aim of getting an email address and general browsers have different aims. Their user experience expectations will adjust according to their desired goals.&lt;br /&gt;  &lt;/li&gt;   &lt;li&gt;E.g. when viewing an academics homepage, most users would be interested in finding out what research areas are, what papers are etc., not in trying to achieve commuinication with the page owner. As such, a browser will probably tolerate, not be bothered about any delays. However, when a user has specific intention to get email address(or contact site owner), they will want get information fast. They can be similar to a "spambot".&lt;br /&gt;  &lt;/li&gt;   &lt;li&gt;Explaining why and how long user must wait for information may increase their tolerance for waiting. Incorporating something like "this is an anti-spam measure ... it will take XXX seconds for the email address to appear" this into the design may increase useability.&lt;/li&gt; &lt;/ul&gt; &lt;span style="font-weight: bold;"&gt;2. Imperical research: how long is a user willing to wait before their expectations are frustated:&lt;/span&gt; &lt;ul&gt;   &lt;li&gt;check Nelson's usit column. Although may not have publish figures, may hint to sources of primary research that's uncited!&lt;/li&gt;   &lt;li&gt;Google keywords: &lt;span style="font-weight: bold;"&gt;latencies&lt;/span&gt;, &lt;span style="font-weight: bold;"&gt;user tolerance&lt;/span&gt;&lt;br /&gt;  &lt;/li&gt; &lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/17725307-112929935361036649?l=dariola.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dariola.blogspot.com/feeds/112929935361036649/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=17725307&amp;postID=112929935361036649' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default/112929935361036649'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default/112929935361036649'/><link rel='alternate' type='text/html' href='http://dariola.blogspot.com/2005/10/waiting-time-and-user-tolerance-limit.html' title='Waiting Time and User Tolerance Limit'/><author><name>daVe =p</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-17725307.post-112925069545889708</id><published>2005-10-13T17:44:00.000-07:00</published><updated>2005-10-13T17:44:55.503-07:00</updated><title type='text'>Lecture Notes 13 Oct</title><content type='html'>&lt;strong&gt;University Email Anti-Spam Fact Finding&lt;/strong&gt;&lt;br/&gt;&lt;br/&gt;Had a meeting with both the informatics support team and the EUCS Science and Engineering computing support team. They referred me to resources providing more information on measures to deal with Spam within the university.&lt;br/&gt;&lt;br/&gt;It seems the university has a hierarchy of measures in place to deal with spam. Furthermore, it maybe a possible security risk and computing regulation issues regarding the use of university email resources for the spambot honeypot.&lt;br/&gt;&lt;br/&gt;&lt;em&gt;Discussion is left offline for obvious security reasons.&lt;/em&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/17725307-112925069545889708?l=dariola.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dariola.blogspot.com/feeds/112925069545889708/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=17725307&amp;postID=112925069545889708' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default/112925069545889708'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default/112925069545889708'/><link rel='alternate' type='text/html' href='http://dariola.blogspot.com/2005/10/lecture-notes-13-oct_13.html' title='Lecture Notes 13 Oct'/><author><name>daVe =p</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-17725307.post-112924401851963954</id><published>2005-10-13T15:53:00.000-07:00</published><updated>2005-10-13T15:53:38.563-07:00</updated><title type='text'>Lecture Notes 13 Oct</title><content type='html'>Project Musings: 13 Oct 2005&lt;br/&gt;&lt;br/&gt;&lt;strong&gt;Honeypot&lt;/strong&gt;&lt;br/&gt;&lt;br/&gt;Started reading Honeypots by Lance Spitzner (Addison-Wesley, 2003) to gather ideas on how to improve on the existing spam honeypot.&lt;br/&gt;&lt;br/&gt;&lt;strong&gt;Establishing Upper Resource Bounds on Spammer’s machine&lt;/strong&gt;&lt;br/&gt;&lt;ul&gt;&lt;li&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br/&gt;&lt;strong&gt;NP Complete Problem for Spammer&lt;/strong&gt;&lt;br/&gt;&lt;ul&gt;&lt;li&gt;Mine Sweeper is NP complete (wikipedia)&lt;/li&gt;&lt;br/&gt;&lt;li&gt;Problem must not be easy to solve&lt;/li&gt;&lt;br/&gt;&lt;li&gt;Must deter spammer to try use site&lt;/li&gt;&lt;br/&gt;&lt;li&gt;Can limit attacker machine’s – CPU, Memory or Bandwidth&lt;/li&gt;&lt;br/&gt;&lt;li&gt;Must identify way to set/measure reasonable bounds on these?&lt;/li&gt;&lt;br/&gt;&lt;li&gt;Whilst may not be able to know these bounds, as we do not know attackers modus operandi, an estimated bounds maybe useful in identifying a suitable NP complete problem &lt;/li&gt;&lt;/ul&gt;&lt;br/&gt;&lt;strong&gt;JavaScript must have these characteristics to deter the attacker&lt;/strong&gt;&lt;br/&gt;&lt;ul&gt;&lt;li&gt;Problem must be NP complete – must be no shortcuts to solving the problem i.e. attacker must successfully complete execution before they can derive result&lt;/li&gt;&lt;br/&gt;&lt;li&gt;The source code function must be such that&lt;/li&gt;&lt;/ul&gt;&lt;br/&gt;&lt;strong&gt;## JavaScript Idea (Email address stored in an incomplete private-key) ##&lt;/strong&gt;&lt;br/&gt;&lt;ol&gt;&lt;li&gt;Encrypt email address using trapdoor function/public-key algorithm&lt;/li&gt;&lt;br/&gt;&lt;li&gt;To gain email address need private key&lt;/li&gt;&lt;br/&gt;&lt;li&gt;Use certain bits in private-key to generate a minesweeper grid&lt;/li&gt;&lt;br/&gt;&lt;li&gt;Human user must play the minesweeper game and discover where all the mines are to recover the full private key to de-crypt the email address&lt;/li&gt;&lt;/ol&gt;&lt;br/&gt;# with this method, we may not need code obfuscation, although code obfuscation may make it harder for attacker to understand the underlying algorithm&lt;br/&gt;&lt;br/&gt;# Obfuscation may be important to prevent automated processing of the script. If attacker does not know how JavaScript runs cannot run it, must require human user to run code. Becomes a new form of captcha (reverse turing test)&lt;br/&gt;&lt;br/&gt;&lt;strong&gt;Cons of this approach: &lt;/strong&gt;&lt;br/&gt;&lt;ul&gt;&lt;li&gt;user must interact (and win minesweeper) to gain private key.&lt;/li&gt;&lt;br/&gt;&lt;li&gt;Client-side code cannot be relied to set up minesweeper grid&lt;/li&gt;&lt;br/&gt;&lt;li&gt;Must random minesweeper grids, therefore server side code is required&lt;/li&gt;&lt;br/&gt;&lt;li&gt;May not appeal to diabled users&lt;/li&gt;&lt;br/&gt;&lt;li&gt;May not be suitable for micro browsers&lt;/li&gt;&lt;/ul&gt;&lt;br/&gt;But it maybe a fun way to demonstrate how it works! Hiding your email address in games. It maybe simple for you to solve the puzzle, but not for a computer.&lt;br/&gt;&lt;br/&gt;Disability factor can be addressed by a guest book form input function.&lt;br/&gt;&lt;br/&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/17725307-112924401851963954?l=dariola.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dariola.blogspot.com/feeds/112924401851963954/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=17725307&amp;postID=112924401851963954' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default/112924401851963954'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default/112924401851963954'/><link rel='alternate' type='text/html' href='http://dariola.blogspot.com/2005/10/lecture-notes-13-oct.html' title='Lecture Notes 13 Oct'/><author><name>daVe =p</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-17725307.post-112906677793614308</id><published>2005-10-11T14:29:00.000-07:00</published><updated>2005-10-11T14:54:21.103-07:00</updated><title type='text'>Group Project Meeting</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Project Description:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Unsolicited email, spam, is a well known issue facing internet users. Currently popular methods are typically based around identifying and filtering out spam. Such reactionary solutions that can only deal with spam after an unwanted message is sent out onto the network are at best sub-optimal. They do not prevent spam from consuming network bandwidth.&lt;br /&gt;&lt;br /&gt;Before a spam message can be sent out onto the network, a spammer must first gain hold of a valid destination email address. Spammers are known to use web crawlers, spambots, which search through public web pages looking for valid email targets.&lt;br /&gt;&lt;br /&gt;This project aims to investigate and identify techniques that can be used to obfuscate email address and prevent spambots from harvesting email address from public websites.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Project Goals:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;   &lt;li&gt;Analyze spambot email harvesting techniques&lt;/li&gt;   &lt;li&gt;Identify anti-email harvesting techniques&lt;/li&gt;   &lt;li&gt;Develop email obfuscation tools&lt;/li&gt;   &lt;li&gt;Promote awareness of email harvesting and email obfuscation &lt;/li&gt; &lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Plan of Attack:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Stage I: Basic Milestones&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;1. Email obfuscation toolkit for static web pages&lt;br /&gt;&lt;br /&gt;        a. Simple client-side JavaScript obfuscators&lt;br /&gt;        b. Image translation tool&lt;br /&gt;&lt;br /&gt;Emphasis is to build a ease to use toolkit based on known existing techniques.&lt;br /&gt;&lt;br /&gt;2. Email Harvesting Honeypot&lt;br /&gt;&lt;br /&gt;Deploy a decoy honeypot web site with email addresses present in different formats to attract spambots and track which techniques are most vulnerable to email harvesting and spam.&lt;br /&gt;&lt;ul&gt;   &lt;li&gt;Control case 1 – mailto tag in clear&lt;/li&gt;   &lt;li&gt;Control case 2 – email address in clear&lt;/li&gt;   &lt;li&gt;Simple JavaScript Obfuscation&lt;/li&gt;   &lt;li&gt;Email address in GIF image&lt;/li&gt;   &lt;li&gt;Email address embedded in a PDF document&lt;/li&gt;   &lt;li&gt;Simple key word substitution and separation – AT DOT DOT technique &lt;/li&gt; &lt;/ul&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Stage II: Intermediate Milestones&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;3. Awareness &amp; promotion website (social engineering)&lt;br /&gt;4. AJAX/Captcha based JavaScript obfuscator&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Stage III: Advanced Milestones&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;5. Website Threat Assessment Diagnostic Tool (greyhat web crawler)&lt;br /&gt;6. PDF email obfuscation&lt;br /&gt;7. Applying Code Obfuscation Techniques to JavaScript&lt;br /&gt;8. Client-side scripting (JavaScript) server based alternatives&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Action Items&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;   &lt;li&gt;Setup a website visitor counter to monitor the number of visits to the honeypot&lt;br /&gt;&lt;/li&gt;   &lt;li&gt;Use tables to divide up the email address&lt;br /&gt;&lt;/li&gt;   &lt;li&gt;Investigate CSS.none attribute, can be used to prevent the display of nonsense html tags&lt;/li&gt;   &lt;li&gt;RSS feed to notify users of new email obfuscation techniques published at the site&lt;br /&gt;&lt;/li&gt; &lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/17725307-112906677793614308?l=dariola.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dariola.blogspot.com/feeds/112906677793614308/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=17725307&amp;postID=112906677793614308' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default/112906677793614308'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default/112906677793614308'/><link rel='alternate' type='text/html' href='http://dariola.blogspot.com/2005/10/group-project-meeting.html' title='Group Project Meeting'/><author><name>daVe =p</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-17725307.post-112906612352762104</id><published>2005-10-03T16:10:00.000-07:00</published><updated>2005-10-11T14:54:04.760-07:00</updated><title type='text'>Plan of Attack</title><content type='html'>&lt;pre style="font-family: times new roman;"&gt;Plan of attack for Honours Project.&lt;br /&gt;&lt;br /&gt;TRY TO DO SIMPLE VERSION OF 1 OR 2 IN TIME FOR PROJECT MEETING&lt;br /&gt;&lt;br /&gt;1.  Build a simple obfuscation tool based on user choice of techniques.&lt;br /&gt;Suitable for users that only have static pages.&lt;br /&gt;a.  simple Javascript - executing Javascript on client computes mailto tag&lt;br /&gt;b.  translate e-mail name into an image&lt;br /&gt;Emphasis here is on stitching existing tools together for easy use&lt;br /&gt;&lt;br /&gt;[DO THIS FIRST]&lt;br /&gt;&lt;br /&gt;2.  Experiment&lt;br /&gt;Generate fresh e-mail names via different techniques and see which&lt;br /&gt;generate spam.&lt;br /&gt;a.  Control case - name in clear&lt;br /&gt;b.  simple Javascript (as with 1a)&lt;br /&gt;c.  image (as with 1b)&lt;br /&gt;d.  in clear in pdf document&lt;br /&gt;e.  current Informatics technique (name @ inf.ed.ac.uk) (purpose of this&lt;br /&gt;is to check how effective current technique is)&lt;br /&gt;&lt;br /&gt;[DO THIS SECOND -- SO AS TO MAXIMIZE TIME TO ACCUMULATE DATA]&lt;br /&gt;&lt;br /&gt;3.  PDF e-mail obfuscation tool&lt;br /&gt;&lt;br /&gt;[TECHNOLOGICALLY STRAIGHTFORWARD, BUT PERSONALLY, PHIL COULD MAKE USE OF&lt;br /&gt;THIS]&lt;br /&gt;&lt;br /&gt;4.  Diagnostic tool -- at users request, crawl their website and report&lt;br /&gt;vulnerabilities [DO NOT RELEASE AS OPEN SOURCE]&lt;br /&gt;&lt;br /&gt;[TECHNOLOGICALLY STRAIGHTFORWARD, PERSONALLY PHIL IS LESS INTERESTED IN&lt;br /&gt;THIS]&lt;br /&gt;&lt;br /&gt;5.  Study obfuscated code techniques and apply them to generate a more&lt;br /&gt;sophisticated Javascript obfuscator&lt;br /&gt;&lt;br /&gt;[THIS HAS MOST ACADEMIC CONTENT]&lt;br /&gt;&lt;br /&gt;6.  Consider alternative to Javascript (e.g., challenge-response running&lt;br /&gt;on server) for clients that do not have Javascript -- this probably&lt;br /&gt;requires that user have CGI capability.&lt;br /&gt;&lt;br /&gt;[TECHNOLOGICALLY STRAIGHTFORWARD]&lt;br /&gt;&lt;br /&gt;7. User-engineer a site distributing these tools in order to make it&lt;br /&gt;popular.  Count downloads to measure success.&lt;br /&gt;&lt;br /&gt;[RELEVANT TO INFORMATICS, BUT USES DIFFERENT MUSCLES]&lt;br /&gt;&lt;br /&gt;8. Apply AJAX techniques, possibly using Captcha and/or using self&lt;br /&gt;modifyng code.&lt;br /&gt;&lt;br /&gt;[PERSONALLY INTERESTING TO PHIL, MAY BE PRETTY CHALLENGING]&lt;br /&gt;&lt;br /&gt;9. Build well-engineered tool&lt;br /&gt;&lt;br /&gt;10.  Study which techniques are effective -- what sort of things will&lt;br /&gt;spambots easily do (e.g., perhaps, execute Javascript) and not easily do&lt;br /&gt;(e.g., if Javascript is expensive when will they stop)?&lt;br /&gt;&lt;br /&gt;Overall plan:&lt;br /&gt;&lt;br /&gt;Start with something simple, so you have a definite result under your&lt;br /&gt;belt: 1, 2, 9, start 7.&lt;br /&gt;&lt;br /&gt;Then spend bulk of time on something intellectually challenging, such as&lt;br /&gt;5 or perhaps 8.&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/17725307-112906612352762104?l=dariola.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://dariola.blogspot.com/feeds/112906612352762104/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=17725307&amp;postID=112906612352762104' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default/112906612352762104'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/17725307/posts/default/112906612352762104'/><link rel='alternate' type='text/html' href='http://dariola.blogspot.com/2005/10/plan-of-attack.html' title='Plan of Attack'/><author><name>daVe =p</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
