SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

Image spammers try PDFs on for size

Image spammers try PDFs on for size

By:  Kathleen Lau  On: 17 Jul 2007 For: ComputerWorld Canada Creator

Messaging security vendors notice a spike in the use of Adobe's portable document format to convey malicious content. What IT managers can do to prepare

Spam filter reports from a couple of months ago suggested the usual barrage of image spam had eased up, but the reality is those images had merely assumed a new identity: Portable Document Format (PDF).

Most vendors of messaging security systems have incorporated some sort of defense against image spam, which has only led spam creators to find novel modes of entry, specifically through what has become the "de facto standard" for sending documents between organizations, said Andrew Graydon, chief technology officer of Mississauga, Ont.-based messaging security vendor BorderWare Technologies Inc.

This latest spam tactic works because most messaging security tools detect images in the form of JPEG, JIF and PNG, for example, but not those in PDF.

"Spammers will always find the vulnerability, and push the limits to find where the majority of vendors are not solving the problem," said Graydon. And it's surprising, he added, how few messaging security systems scan the contents of PDF documents – making the tactic successful across 80 per cent of security solutions on the market.

Currently, he said PDF spam accounts for about 50 per cent of image spam, a marked increase from the initial three per cent when spammers were still testing the waters a couple of months ago before finally opening the floodgates.

PDF spam is just another invasion technique designed to bypass "reasonably effective" defenses against basic image spam, said Larry Karnis, president of Toronto, Ont.-based messaging security provider XPM Software Inc.

"They can put the same image in a PDF document and the PDF document wrapper allows the image to travel through the spam filter undetected," said Karnis.

But as with all forms of malware, PDF spam – currently a simple format of identical images for content – will soon take on different appearances as it morphs to avoid detection, said Graydon. "We're going to start seeing some of the exploits happening on the PDF where they're going to start changing the size of the PDF, and the size of the image inside."

But Karnis believes PDF spam will be a short-term threat because they are relatively easy for vendors to block: companies using an anti-spam tool and are under a maintenance agreement with the product vendor should see the problem going away fairly quickly.

Besides, he added, the impact thus far has been nowhere near as severe as the initial image spam attacks that hit last year. And the tactic is hardly economical from the spammer's point of view, given PDF attachments tend to inflate message size thereby reducing the number of outgoing attacks from a botnet.

Spammers at this point are probably trying to work out the economics of PDF spam given the limited number attacks that can be launched, said Bradley Anstis, director of product management for Basingstoke, U.K.-based Marshal Ltd., a provider of e-mail and internet management solutions.


Sign up for our Newsletters












Print |  Views: 710   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Kathleen Lau Kathleen Lau was a senior writer with ITWorldCanada.com and ComputerWorld Canada from December 2006 to August 2011.In her role as senior writer, she covered broadly technology news and issues r... more

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.