Attacking Email Abusers
Unsolicited and unwanted email is a fact of life, and there’s precious little that can be done to stop it. This has not gone unnoticed by the denizens of the washington cesspool. There is a way to give these semi official Pooh-Bahs a taste of their own trash, and it’s outlined here as a public service.
The biggest lobbyists in the nation’s capital are well run organizations, and as demonstrated during the last national election, know how to maximize technology by using sophisticated tools and systems. Some of these include what appear to be separate organizations that do some of the automated dirty work, like sending massive numbers of emails to get even more clout at the federal trough. These allow the main group to claim purity of driven snow.
It’s easy to get email addresses, and hard to recognize these email abusers with the usual filters, spam detectors and firewalls and such. Even the origination addresses in their email storms are fake and always changing, done using the sophistication mentioned earlier.
Their latest email scam is to include an ‘opt-out’ link in their emails, that when clicked go instead to a subscription form. These emails also claim that the recipient opted-in, which is nothing short of a bald faced lie, something the denizens of Washington cesspool know how to do quite well.
Complaining doesn’t do any good, even when taken to an ‘official’ level, with all the facts and figures on exhibit, like trace routes and such. Confronting these denizens with their deeds is also a waste of time, having to do with their claims of the purity of snow mentioned above.
There is something that can be done, with very little effort for someone who knows how to program HttpRequests objects, using (for example) PHP. It consists of sending the originators their own trash. Here’s how to do it.
1. Get the email addresses of the organization’s officers and senior staffs. This is surprisingly easy to do. The more and deeper, the better.
2. Get the organization’s subscription form (the one that should have been an unsubscribe page) HTML and isolate the form’s fields.
3. Write a program that programmatically submits the form data, using the names and email addresses found is step 1 as the form’s requestors, and any other information required using the organization’s information (mailing address, phone numbers, etc.). Adding some SQL injection would be a good stress test for their sophisticated systems. Change the requests headers to those of the offending emails from the organization.
4. Finally, programmatically flood their servers with these optin requests, or as many as can be done in one session.
Will it make a difference? The only way anything really makes a difference is for the perpetrators to experience, first hand, what they’ve unleashed on those outside of the Washington cesspool.
© Copyright 2009 Chuck Brooks for FutureWare SCG
A Word From Our Sponser
Finally, a fast way to fix
html scripts without having to rebuild them!
Tags: email abuse, k-street bandits, lobbyists, pigs at the trough, public service announcement, washington cesspool
