Picasa
Picasa is gaining popularity as a spam tool

Picasa and Flash become latest spam tools

Image site helps spammers elude filters

Shaun Nichols in San Francisco

Google's Picasa image hosting service is fast becoming the new tool of choice for spammers to elude email filters.

A recent report from security firm Message Labs said that the service is being used to host the images used in spam messages.

Advertisement

The images can be used for such purposes as pushing fake video files or running text that can elude spam filters.

The use of images in spam is not new. Spammers have long used image files as a way to evade the text-recognition features in spam filters.

The use of specialised imaging services such as Picasa, however, could make it even harder to combat.

Because Picasa is a Google service, the domains are rarely blocked by email filters as they are far more likely to be used to host an image that the user actually wants to receive.

The streamlined nature of the service, designed to make it easier for users to upload and manage their albums, is also appealing to spammers, according to Message Labs.

"The use of these images is very simple," the firm said. "Firstly, a Picasa Web Album is created using the Google account. The album can be marked as private or public, and even with a private album the images can still be used in an email."

The use of photo-sharing sites like Picasa are not the only way spammers are avoiding detection. Message Labs also pointed to Flash files as an emerging threat.

While some exploits have in the past been launched through Flash flaws, Message Labs found that spammers are now using the files to confuse users and redirect them to attack or phishing sites.

"Using this latest technique, spammers are able to bypass many traditional content filters since the link in the message relates to a legitimate website," said the company.

"It is expected to appear in spammed messages posted to comment pages of bl og sites and social networking sites."

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Further reading

spam tins

FBI warns of hit man scam

Threatening emails are designed to get internet users to hand over their money

Virtual world

Virtual worlds becoming money laundries

Criminals are using online currency to cover tracks

Spammers go down to Georgia

New attack exploits war in former Soviet state

Spam around 150bn messages a day

Male enhancement still at large

Related whitepapers

Related jobs

Most watched

Summit: Views From the Valley

V3.co.uk's US office weighs in on the information overload crisis

John Chambers speaks on collaboration

Cisco boss talks up new offerings

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

Summit video: Intel discusses processors designed for data overload (part one of two)

Intel explains how its Xeon processors can handle data-intensive apps

fujitsu logo

Unite calls off Fujitsu strike

Talks between the two sides will extend into the new...

Richard Thomas

Summit: Q&A Richard Thomas, former Information Commissioner

Thomas speaks out on government databases and data privacy

Symantec office

Summit: Symantec makes the case for smarter storage

Company talks up unified approach

Primary Navigation