Automated Form Fillers

0 views
Skip to first unread message

Tashiro

unread,
May 21, 2006, 3:01:07 AM5/21/06
to okopipi-discuss
Blue Frog had, as part of their system, the ability to fill out forms
on the spamvertisement sites, with the request that they scrub their
lists. (Causing, as a result, the sellers to have to go through
500,000 'we don't want your crap!' sales slips, to find the legitimate
sales). Will Okopipi do the same, or will it simply send the 'do not
want!' requests (which was the first option with the 10-day leeway
before the latter hammer-hit)?

Hal9000

unread,
May 21, 2006, 7:04:04 AM5/21/06
to okopipi-discuss
Speaking for myself (and others I hope), I am hoping that Okopipi will
emulate the sucess of BS/BF in the way it would poison the spamvertised
website with the same number of requests as reported spam messages
received by Okopipi members.

BUT this only occured if the spamvertised site did not respond to an
initial request from BS for them to download their list scrubber app
and clean out their lists.

This then throws a warning and the onus to the spamvertiser to delete
Okopipi subscribed members.

As a separate function BS would report obvious frauds or illegal
operations to the appropriate authorities (to what success, who
knows?). Such frauds included pump and dump stocks, perscription only
medicines, pirated software and so on.

Kamikazi

unread,
May 21, 2006, 8:39:12 AM5/21/06
to okopipi-discuss
Hal9000 wrote:
> Speaking for myself (and others I hope), I am hoping that Okopipi will
> emulate the sucess of BS/BF in the way it would poison the spamvertised
> website with the same number of requests as reported spam messages
> received by Okopipi members.

The automated form fillers for the spamvertized sites is the only thing
that gave the frog teeth - or poison if you like... This being the
achilles heel of the spamvertized sites, I wonder how easily spammers
could protect these sites from people who are demanding to opt-out, vs.
the few idiots who might actually be trying to order something from
them?
One method seems obvious - simply don't save/process form data that
does not contain a valid CC number. I'm not so sure that a LOT of
spamvertized sites don't do this already, and if the few who don't use
this filtering mechanism started to get bombarded with out-outs, I
don't think it would take long before they figured it out.
Anyone know how BS dealth with this? Perhaps they DIDN'T - perhaps they
only sent opt-out requests to sites where forms appeared to save some
data before actually asking for and processing credit card info.
Finding a way to get our opt-out requests beyond any filtering
mechanisms would seem to be an enormous challenge. Even if the valid
credit card issue could be overcome, it would seem that there would be
many other ways that complaints could be automatically distinguished
from real orders and complaints simply tossed in the bit-bucket.
Am I missing something here?

Hal9000

unread,
May 21, 2006, 9:12:55 AM5/21/06
to okopipi-discuss
If not the order form then the contact us form.

Failing that then may be an email address as a very last resort.

And if we really want to play dirty (not to mention illegal) there are
plenty of CC number generators out there. But hey I am not suggesting
we actually do this.

The other thing is this is a tit for tat scenario. One visit from the
client for each reported instance of spam in a members mailbox. As
mentioned this visit is to either the order form or the contact us form
or an email to a listed, and proven, email address.

Spoofing HTTP client details is a no brainer! No not a problem.

larry Vagina

unread,
May 21, 2006, 11:26:54 AM5/21/06
to okopipi-discuss
What about adding spammers to spam "opt out" sites:
http://www.vrooomvrooom.com/OptOut.asp?RefId=11111

Although spammers probably get more spam than anyone else, and this
won't do anything but piss them off:
http://it.slashdot.org/article.pl?sid=03/07/07/1130226

psychoRebel

unread,
May 21, 2006, 5:50:46 PM5/21/06
to okopipi-discuss
Every suggestion I've heard in this forum, no matter how extreme, or
even illegal, should be at our disposal. The spamertizers don't seem to
worry about ethics or legalities (as proven by the actions of one
"PharmaMaster") so why should we. At root, what spammers are doing is
an invasion of privacy, at the least, and fraud. Whatever it takes to
take them down, I say, is fair. Specially since there are no
"authorities" doing any thing at all. Also, what about targeting the
big corporations that receive some profit and advertising by the
spammers, namely Walmart, Target, etc., whose names are used by
spammers with their tacit approval. Why aren't they doing something to
stop the illegal use of their trademarks in the spammers scams. Either
they are happy to receive the free advertizing, or somewhere way up the
chain they are responsible for some of it. Walmart Gift Cards, Target
Gift Cards, Win a FREE Dell Notebook, Free iPod, Viagra, etc.!

larry Vagina

unread,
May 21, 2006, 9:19:02 PM5/21/06
to okopipi-discuss
I've heard some crazy stuff, but aren't we a higher life form than the
spammers?

Or will we have to be like that line from mississippi burning:
"these people came up out of the gutter, we've got to go down in their
to get to them", or something like that. It's a great line.

gershon

unread,
May 22, 2006, 3:08:00 AM5/22/06
to okopipi-discuss
Actually, there's a real easy way for spammers to protect themselves
against automatic form-filling: they should put one of those
Turing-test graphics on the sites.

This can practically kill any automated form-filling application. In
fact, if the Okopipi network is impossible to bring down, I expect this
is exactly what will happen. It will rended the clients useless, and
will leave us nothing to do except DDoS these sites.

Kamikazi

unread,
May 22, 2006, 7:27:08 AM5/22/06
to okopipi-discuss
That's exactly what I'm afraid of. If okopipi doesn't play within the
bounds of CAN-SPAM, I will definitely think twice before supporting it.
Blue Frog claimed to play by the rules. Even though Blue Frog
supposedly stayed within the law, much of the media still accused them
of illegal DDoSing - because they simply didn't take the time to read
exactly how it worked.
Now if okopipi does resort to real DDoS attacks, it is going to come
under heavy fire by a lot more people - because it WILL be using
illegal tactics. I'm not interested in debating if these tactics are
justified or not. Maybe they are, maybe they aren't.

As for sending opt-outs via 'contact us forms' or email - good luck.
I've looked at a fair number of spamvertized sites to see how
complaints might be entered and found that very few of them have
mechanisms for contacting them. They are only interested in your name
and credit card number. There is typically no doorway to ask questions,
chit-chat, or complain.

reinma...@gmail.com

unread,
May 23, 2006, 11:30:20 AM5/23/06
to okopipi-discuss
I really don't think they can do this. Most spammers rely on stupid
people or people who are ignorant of how the internet works.
Throw something like that in their order forms they wouldn't get any
customers.

Spy der Mann

unread,
May 24, 2006, 1:05:29 AM5/24/06
to okopipi-discuss
You got a point. Users who clicked on an e-mail saying "Enlarge your
manhood by 10 inches and surprise your wife!" can't be expected to fill
complicated Turin tests.

Um, the implications of this statement are either hilarious or
depressing. You choose :P

Alcator

unread,
May 24, 2006, 5:33:09 AM5/24/06
to okopipi-discuss
In another thread, someone said "We don't have to be afraid to use
"illegal tactics", because spammers aren't going to "complain".

However, that's underestimation: Don't forget there are many
influential people around the globe who for some reason or another keep
talking about things that perhaps are of no real impact upon them,
simply because they have some Messiah complex or whatever.

Newsreporters keep publishing articles about human rights violation in
China and other countries, so we have to accept the fact that someone
somewhere WILL talk about Okopipi (btw, in my native language, OKO =
Eye, Pipi is a childish adress to a hen :-) , and if we try to use
something even slightly illegal, they might hold us responsible and
liable. (Hope I'm using the right words, I'm not English and these
words can get confusing...)

So, my vote: We cannot use anything that cannot be successfully
defended at the court as "absolutely legal". Otherwise we would put our
own people at risk that one of them, someone who joined just to help
internet, would be caught and used as "the Example" of how badly you
might end if you mess up with law. There are still ways how to salt
someone's life and still being perfectly legal.

stahlsau

unread,
May 24, 2006, 5:58:29 AM5/24/06
to okopipi...@googlegroups.com
>
> So, my vote: We cannot use anything that cannot be successfully
> defended at the court as "absolutely legal". Otherwise we would put our
> own people at risk that one of them, someone who joined just to help
> internet, would be caught and used as "the Example" of how badly you
> might end if you mess up with law. There are still ways how to salt
> someone's life and still being perfectly legal.
>
>
>

Than, at first we have to define the term "legal". Legal in which state?
Only US? That wouldn't be neither fair nor right, since this is an
international project. Europe? At least we don't have to fear the RIAA
or something ;)
Every country? Impossible. I bet there is always a country with a law
against this or that feature...for example in China it is completely
forbidden to visit some special "capitalistic" websites, afaik.

Second, which country should hunt us down for these lawbreaks? All of
them? This won't work. And what if, like the author of the quoted text
wrote, some journalists from a "foreign" state write about okopipi being
illegal in their country?

The best choice would be to make it legal for some state in Africa or
s/t, where they don't have any laws against internet-crimes ;)

just my 2 Cents
cu
stahlsau

Arancaytar Ilyaran

unread,
May 24, 2006, 6:16:23 AM5/24/06
to okopipi...@googlegroups.com
On 5/24/06, stahlsau <stah...@gmail.com> wrote:

> The best choice would be to make it legal for some state in Africa or
> s/t, where they don't have any laws against internet-crimes ;)

That's what the spammers do... "fighting fire with fire" is an
enticing concept, but something is to be said for "not stooping to
their level", too.

cadGweep

unread,
May 24, 2006, 12:50:54 PM5/24/06
to okopipi-discuss
If I remember correctly, the issue of Turing-test graphics was the
subject of much discussion on one of the BS forums. The answer to this
problem is that BS would identify multiple field entries to target at
any given site. And unless the spammers were willing to guard each and
every field entry with a turing-test, the frog would get its' message
through. I don't know if I completely understand or buy that argument,
but that was the basically the concept.

Alcator

unread,
May 24, 2006, 2:19:40 PM5/24/06
to okopipi-discuss
I believe they were talking about each and every FORM, not FIELD.

A form consists of several fields. The original discussion concerned
the spammers protecting "complaint-forms" with CAPTCHA, and BS
responded that opt-out request can be easily filled into "order-forms"
(I believe I saw an example where the script filled something like
this:

Name: You are sending unsolicited
Surname: bulk e-mail to adresses of the Blue Community
Adress: Please download the cleaning...
Order item 1: ...
...
...

of course, there is always the problem that the spammer could simply do


" delete from orders where name like 'You are %' "

(which would purge the DB of all such complaints)

bryant...@gmail.com

unread,
May 24, 2006, 6:39:48 PM5/24/06
to okopipi-discuss
couldn't we just get a client to display the turing test graphic and
volunteers could fill them out as they come? it would take time, but I
would be willing.

bryant...@gmail.com

unread,
May 24, 2006, 6:42:43 PM5/24/06
to okopipi-discuss
we could always vary the text into a number of categories, just like
they do with spam. fight fire with fire.

Spy der Mann

unread,
May 24, 2006, 6:49:09 PM5/24/06
to okopipi-discuss
THAT could be an option.

Don Z (TFG)

unread,
May 24, 2006, 6:49:40 PM5/24/06
to okopipi...@googlegroups.com
"couldn't we just get a client to display the turing test graphic and
volunteers could fill them out as they come? it would take time, but I
would be willing."

I, too, would be willing to devote some time to this.

Alcator

unread,
May 25, 2006, 8:30:45 AM5/25/06
to okopipi-discuss
Oh, this topic is running in several threads.

No, we couldn't. With 200 spams per day, no sane person will ever fill
200 CAPTCHA tests. But as I wrote in "I don't think it will work"
thread, OCR/ICR (Optical Character recognition and Intelligent
Character Recognition, the latter being use for hand-writing and
otherwise damaged or slanted letters) should work very well on this,
because spammers cannot employ the harder types of CAPTCHA, otherwise
their customers wouldn't be able to fill them correctly and thus
wouldn't buy anything.

Kamikazi

unread,
May 26, 2006, 6:12:27 PM5/26/06
to okopipi-discuss
Forget Turing tests and Captcha's - spamvertizers aren't going to annoy
their customers with stuff like that...

Still haven't heard a good explanation on how you can get past a
requirement to enter a valid credit card number... If a valid card
number is not entered, then ALL of the data (our opt-outs) can get
tossed in the bit-bucket. I'm sure that the credit card companies don't
like getting flooded with bogus CC numbers, and that could leave us in
a very questionable legal position. SO... will Okopipi opt-out scripts
use valid CC numbers - and valid CC owner names? (I don't think so)

This concerns me because it means that our opt-out requests would
likely NOT be saved... Why would they save them? I'm sure they don't
want to be bothered reading through order-form data that contained no
valid payment for their crap!

Filling out forms with opt-out requests that never get saved or read
may create a traffic bottleneck - especially if many are done at the
same time. But, it's NOT going to be hassle for anyone or anything
aside from loading down their servers.

So, if we are trying to opt-out, but their forms won't let us, what do
we do?

Spy der Mann

unread,
May 27, 2006, 10:08:45 AM5/27/06
to okopipi-discuss
We'll just assume they're purposedly ignoring our request. Gradually
we'll let more of our users submit opt-out until all the people they've
spammed complain.

Sooner or later, they'll have to find out that SOMEONE is sending them
valuable information. Their traffic logs will reveal the cause. I think
that's the only thing we can do.

UNLESS....

Remember Bart Simpson? He would give names to Moe and Moe would repeat
them aloud, and everybody would laugh at him.

So... here's the idea (muahahahaha *insert evil smirk here* )...

Name: Dawn. L'ad Dunot Intrudleest (sounds: Download donot intrude
list)
Address: Le Poisson Phrog Ave R. #33617
City: Okopippe town
State: Ma
Country: US
CC Number: (Insert valid but fake CC number here)

Here's others:

Ayem Anuyed Baijurs Pam (Sounds: I am annoyed by your spam)
P. Lisa S. Tapson Dingar Badge. (Sounds: Please stop sending garbage)
Jaur Cladding Aureen Pox. (Sounds: You're clodding our inbox)
Ree Movmee Fromm Eurleest (Sounds: Remove me from your list)

I think we can get imaginative enough to come up with one or two
hundred names, then we can use them. Notice that I used *REAL* names
and surnames in here (or at least words that have a meaning in at least
one language). Ayem... Lisa... Tapson, Dingar, Badge... Aureen, Fromm,
so they sound credible enough.

Why will it work: There aren't phonetic filters in spam. If the
spammers decided to filter the words, they might be losing potential
customers. Note that not only the names could be given the message,
also the street. So, we could have common names (John Doe) and adresses
like:

Unsoly zeted Lettars #25 (Unsolicited letters)
Donsenz paam #13 (Don't send spam)
Kleenup JoorLizts #140 (Clean up your lists)
Plis topmae linus #874 (Please stop mailing us)

Here we don't need as much imagination. Just mixing up the vowels and
consonants with equivalents. A program to do that is very easy to do.

Or we can even send blantantly fake names with the above streets, but
different numbers:

John F. Kennedy
Elizabeth Hurley
Reed Richards
Stan Lee
Nelson Mandela
Mahatma Gandhi
Indiana Jones
Lara Croft

But we should use diversity. Like, a percentage of users would use
phony names with the messages, other users would use the phonics
addresses, a minor percentage would use famous but fake names... and
another percentage which MUST be present would use the typical message
"Your are receiving this because".

This guarantees that at least some of the messages will pass thru the
filters.

bryant...@gmail.com

unread,
Jun 1, 2006, 1:31:09 PM6/1/06
to okopipi-discuss
using the source code from the refi relatiator and the refi retaliator
2 could provide a good database for fake information. we could also
think about including something like that in the app, so that it would
flood the mortgage and other spammers with useless data and information
that looks credible enough that it would have to be verified before it
is used.

also, i have seen many spam order pages using captcha, so we will have
to get around it somehow. alcator is right, no one is going to fill in
200 captcha tests a day, but i think a lot would fill in 10-20 a day,
which would take only a few minutes. they could come in Que from the
network and people could fill in others forms when they have time. I'm
not sure how this would work, as i am not extremely technical.

jaantispam

unread,
Jun 2, 2006, 3:36:39 PM6/2/06
to okopipi-discuss
> also, i have seen many spam order pages using captcha, so we will have
> to get around it somehow. alcator is right, no one is going to fill in
> 200 captcha tests a day, but i think a lot would fill in 10-20 a day,

I would consider doing this. Like you I've seen captcha used on some
sites. I think there maybe enough volunteers to help in this way.

hedwards

unread,
Jun 2, 2006, 9:04:48 PM6/2/06
to okopipi-discuss

bryant...@gmail.com wrote:
> also, i have seen many spam order pages using captcha, so we will have
> to get around it somehow. alcator is right, no one is going to fill in
> 200 captcha tests a day, but i think a lot would fill in 10-20 a day,
> which would take only a few minutes. they could come in Que from the
> network and people could fill in others forms when they have time. I'm
> not sure how this would work, as i am not extremely technical.

Technically, I doubt that this would be hard. But each person would be
able to fill in information for 1 email each time he compteted a
captcha.

Still, if we could on average do 5 per person, that would make a
difference. But if we are going to make things that labor intensive and
actually make people go to the site, we have already conceded to the
spammer what he wanted in the first place.

jaantispam

unread,
Jun 3, 2006, 12:19:19 AM6/3/06
to okopipi-discuss
> Still, if we could on average do 5 per person, that would make a
> difference. But if we are going to make things that labor intensive and
> actually make people go to the site, we have already conceded to the
> spammer what he wanted in the first place.

True.

The people working on this project are doing it for free. Spammers on
the other hand make a profit for what they do. You could say they get
paid for it, LOL, no matter how wrong it is. Anything we do here hurts
their livelihood. They will fight back. As we saw what happened to BS
(Blue Security).

I have no idea of what BS was doing but whatever it was, it was
working. For the first few months I didn't notice much at all, but
after that I saw a significant decease in spam I was getting. In one
email account the spam dropped next to nil. I can only guess why that
is (another topic) but whatever they did worked. Spammers fought back
and BS lost.

People here have decided to pick up where BS left off, from scratch,
the best I can tell. In the beginning when I signed into this group
- truth be told - I didn't take them seriously. Later I come to
realize they really are serious. They decided to take a bite out of a
very huge pie. They decided to fight back against the spammers.

If OKOPIPI is going to have any chance of winning this war, they will
need our support. You can't win a battle if you don't fight.

hedwards

unread,
Jun 3, 2006, 11:47:34 PM6/3/06
to okopipi-discuss
The idea here is to make it less desirable to use captchas. The more
people that routinely go past the captchas to opt out anyway, the less
likely that the spammers will bother.

As has been said many times before, if you can keep the spammers from
cashing in on the spam; the spam will go away on its own.

Kind of like drugged up lab mice; always pressing the button for the
drugs, even in preference to food pellets.+

bryant...@gmail.com

unread,
Jun 6, 2006, 4:32:28 PM6/6/06
to okopipi-discuss
I think the goal should be to make spam as unprofitable as possible,
and forcing them to install captchas on all contact forms will help do
that. we want to do whatever is possible to make it hard for people to
buy from spamvertised websites.

Reply all
Reply to author
Forward
0 new messages