Newsletter:

Skip Navigation LinksHome > News > Security > Picasa and Flash become latest spam tools

Picasa and Flash become latest spam tools

By Shaun Nichols
8 September 2008 06:33AM
Tags: picasa | flash | become | latest | spam | tools

Google's Picasa image hosting service is fast becoming the new tool of choice for spammers to elude email filters.

A recent report from security firm Message Labs said that the service is being used to host the images used in spam messages.

The images can be used for such purposes as pushing fake video files or running text that can elude spam filters.

The use of images in spam is not new. Spammers have long as a way to evade the text-recognition features in spam filters.

The use of specialised imaging services such as Picasa, however, could make it even harder to combat.

Because Picasa is a Google service, the domains are rarely blocked by email filters as they are far more likely to be used to host an image that the user actually wants to receive.

The streamlined nature of the service, designed to make it easier for users to upload and manage their albums, is also appealing to spammers, according to Message Labs.

"The use of these images is very simple," the firm said. "Firstly, a Picasa Web Album is created using the Google account. The album can be marked as private or public, and even with a private album the images can still be used in an email."

The use of photo-sharing sites like Picasa are not the only way spammers are avoiding detection. Message Labs also pointed to Flash files as an emerging threat.

While have in the past been launched through Flash flaws, Message Labs found that spammers are now using the files to confuse users and redirect them to attack or phishing sites.

"Using this latest technique, spammers are able to bypass many traditional content filters since the link in the message relates to a legitimate website," said the company.

"It is expected to appear in spammed messages posted to comment pages of bl og sites and social networking sites."

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch





Product Reviews

Star Rating
The AdventNet Manage-Engine Password Manager Pro provides a complete system for password management in one...
Star Rating
The Cyber-Ark Enterprise Password Vault, or EPV, is a high-end password management powerhouse.
Star Rating
The Hitachi ID-Archive sets its focus on password randomisation.
Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Unified Communications Podcast Centre

TopTopics
(5700) -  broadband
(5588) -  telstra
(5546) -  nbn
(4357) -  internet
(4013) -  iinet
(3983) -  copyright
(3983) -  afact
(3678) -  servers
(3678) -  mipi
(3077) -  network
(2890) -  internode
(2259) -  microsoft
(2112) -  linux
(1634) -  data
(1529) -  software