Possible 'bug' on "Spamvertising"


This is the conversation I just had to engage with my ISP in order to get my server back online due SpamCop being too "smart" on Spamvertising and perhaps my ISP being too 'fast' on suspeding accounts. Please, fixing this issue would make SpamCop a better product. Thank you!!!!


*** Please note the following: ***

The offender email body message contains an URL (www.pipoclub.com) that resolved to the box we got suspended, and we assume that this was done automatically by SpamCop and your abuse interface of some sort.

We have concluded that SOMEBODY *not* in our company just re-utilized an HTML file from our website to generate an HTML body message that became the offending spam message. We realize both points because of the following:

1) After analyzing the full body message, you can see how our URL appears inside a <BASE HREF> tag, inside the <HEAD> block of the HTML code that is used by Dreamweaver. Our URL does NOT appear anymore in the code, even you can see that our URL is NOT being shown nor really linked for users to click in, if you look into the code and search matches for "pipoclub.com" (our suspended box). You can check our URL and see the html code similitudes, JUST in the <HEAD> section. But our website is for childrens and parents (educational software), not Cars nor Markets as the spammer mail is.

2) We are from Spain, not Argentina. The abuse email seems to come from there. Bad to see that our fellows latin-americans are so good spammers.

Thank you very much for your support on the issue.



> ----- Original Message ----- From: "Abuse Administrator" <abuse[at]xxxxxxx.com>

> To: <xxxxx[at]xxxxxx.es>

> Cc: <abuse[at]xxx.com>

> Sent: Monday, March 21, 2005 4:37 PM

> Subject: [***spam*** Score/Req: 15.80/04.00] FINAL Notice of AUP Violation - 63.x.x.x



> You are being contacted because Sago Networks has received complaints

> regarding:


> [ SpamCop V1.417 ]

> This message is brief for your comfort. Please use links below for details.


> Spamvertised web site: http://www.pipoclub.com/espanol/pipo7/home.htm

> http://www.spamcop.net/w3m?i=z1385631560zc...5f91fcf06682bbz

> http://www.pipoclub.com/espanol/pipo7/home.htm is 63.x.x.x; Sun, 20 Mar

> 2005 23:55:46 GMT


> [ Offending message ]

> Received: from avas-mx03.fibertel.com.ar ([]) by

> mail.fibertel.com.ar (Fibertel S.A. - Argentina) with ESMTP id

> <0IDN009S615RYBF5[at]mta4.fibertel.com.ar>; Sun, 20 Mar 2005 05:46:41 -0300

> (ART)

> Received: from 201-254-35-112.speedy.com.ar

> ([]:34064 "HELO amor-eterno") by avas-mx03.fibertel.com.ar

> with

> SMTP id S327774AbVCTIqf; Sun, 20 Mar 2005 05:46:35 -0300

> Date: Sun, 20 Mar 2005 05:46:22 -0300


> Subject: {spam!!} GUIA YPF 2005 Y CD ACA INTELIGENTE !!! IMPERDIBLE !!!


> To: unlisted-recipients: ; (no To-header on input)


> Message-id:

> <S327______________________________2923[at]avas-mx03.fibertel.com.ar>

> MIME-version: 1.0

> X-MIMEOLE: Produced By Microsoft MimeOLE V5.50.4522.1200

> X-Mailer: Microsoft Outlook Express 5.50.4522.1200

> Content-type: text/html; charset=iso-8859-1

> Content-transfer-encoding: 8BIT

> X-Priority: 3

> X-MSMail-priority: Normal

> X-Fib-Al-Info: Al

> X-Fib-Al-MXId: ffb674e2ef356e16e5a5888a506db5e3

> X-Fib-Al: noav

> X-Fib-Al-SA: spam, Al-SA-3.02 (punt=16.691, req 8, autolearn=disabled,


> 0.80,




> 0.23,


> 0.00,



> TRACKER_ID 1.06)


> X-Fib-Al-From: mipoison[at]uolsinectis.com.ar


This is the conversation I just had to engage with my ISP in order to get my server back online due SpamCop being too "smart" on Spamvertising and perhaps my ISP being too 'fast' on suspeding accounts. Please, fixing this issue would make SpamCop a better product. Thank you!!!!

Why do you think that spamcop's parser is "too smart"?

It simply looks for links within any messages reported as spam by it's users and the user decides to send the report. Spamvertized web sites do NOT count toward any blocklists and the message received is only a warning to your ISP that your URL was seen in a piece of spam.

Your ISP should have contacted you and together you could have determined what the problem was and your ISP could have marked you as an Innocent Bystander and receive no further messages.


I don't think one can call your site "spamvertized" by that spam or call that spam "on your behalf" if there is no easy way for the typical recipient to get from the spam to your site and the spam does not display any images from your site. Sago Networks should re-examine its determination that the spam violated their policies - I don't think it did.

In fact, it looks like the Argentinian spammer has stolen your copyrighted work from one of your webpages, but I don't know what you can do about that.


Thanks for the replies guys. I'm glad you see the same fact, Jeff.

Steven, the "too smart" thing was just ironic, I just wanted to point out that SpamCop could improve parsing HTML body messages and avoid these type of things from happening.

Any malicious user could begin to use this method to generate false warnings and causing trouble to honest companies.



Steven, the "too smart" thing was just ironic, I just wanted to point out that SpamCop could improve parsing HTML body messages and avoid these type of things from happening.


How would you have a piece of software select which links are real and which are not? If the reporter checking the links notices this, I would expect them to uncheck the box, but the primary responsibility for having proof and investigating before shutting down a domain or site should still be in the hands of the provider. Again, the spamcop report is ONLY a notice that the URL was seen in a spam message.

In fact, if you follow the link spamcop presented, the options are:

Please select one..

This message advertised the site without permission.

This website has been disabled.

This issue is under investigation.

I am not the right person to contact about this.

This message is not spam.

Add a note to this issue.

The ISP should have investigates and probably selected the first item in this case.

Any malicious user could begin to use this method to generate false warnings and causing trouble to honest companies.




The only trouble caused is when the ISP does not investigate to find out what really happened. The only trouble is caused when ISP's over-react to a spamvertized site report. Perhaps spamcop should modify their spamvertized site report to more directly say that it is only a notice and that no further action is taken by spamcop. This is a case of learning what evidence has been presented.

The same thing can happen with malformed email submissions on email programs that add a signature to the message. If I submit from work by pasting the spam into a new message (not the correct way to do it, btw, but it works) and forget to remove my signature, spamcop wants to send a spamvertize report to my admin address. Because of the way it was submitted, it looks to the software that it is part of the same message. By forwarding an attachment of the body, spamcop ignores the signature. This is a case of learning how to use the tool.


Your comments make sense Steven :) Thank you. I suppose I over-reacted too about SpamCop just as my ISP in this particular case.




