Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Rise of the Spam Zombies
Kevin Poulsen, SecurityFocus 2003-04-25

Pressed by increasingly effective anti-spam efforts, senders of unsolicited commercial e-mail are resorting to outright criminality in their efforts to conceal the source of their ill-sent missives, using Trojan horses to turn the computers of innocent netizens into secret spam zombies.

Comments Mode:
Rise of the Spam Zombies 2003-04-26
minas-beede
Beautiful. To decieve the spammer just send him a similar message with your IP and your port number. Set up first to receive the email on the specified port and then .............................

nothing. Don't deliver it, that's for sure.

Caution: You may injure yourself ROFL if large qua...

[ more ]  [ reply ]
A good way to spot it 2003-04-27
Alan (2 replies)
Any users with NAV2003 on it will have all their outgoing email scanned. If you see the popup in the bottom right going crazy scanning mail, be VERY suspicious. I saw some poor guy in an IRC help channel that said this happening, I guessed this was what was happening, now I've read this article its ...

[ more ]  [ reply ]
Qualification 2003-04-28
Anonymous (2 replies)
"If you use Microsoft operating systems..."...

[ more ]  [ reply ]
Qualification 2003-04-28
Ryan Lambert
If you use Microsoft Operating Systems, what?

Properly configured AV/Personal firewall along with decent net-smarts should eliminate this threat. Don't blame this one on Microsoft. And let's not forget the recent problems suffered by the Open Source Community.

Need I refresh your memory for th...

[ more ]  [ reply ]
Qualification 2003-05-02
Daniel Basse
Sendmail anyone?

I've patched Sendmail, BIND, and SSL more than my M$ boxes this year......

[ more ]  [ reply ]
A good way to spot it 2003-04-30
Herr Mouse
Hey! tell a house wife or mom of 4 kids that she needs to seek for "rouge processes" on her machine.. :> the problem is not the high-tech education, nor the spammers ... it's more and more USER FRIENDLY products incl. operating systems that are designed to be sold and handled even by a total illiter...

[ more ]  [ reply ]
Rise of the Spam Zombies 2003-04-27
Anonymous (1 replies)
sigh... well I guess we'll just have to convince the govt that spammers are terrorists, please bomb them. ...

[ more ]  [ reply ]
Rise of the Spam Zombies 2003-05-01
GG
Re. convincing the govt' that spammers are terrorists: The going joke here is that after we wrap up in Iraq we should ask our best military minds to develop a precision micro-munition that can seek out & destroy spam servers while leaving innocent machines nearby undamaged. Seriously though, spam ...

[ more ]  [ reply ]
Rise of the Spam Zombies 2003-04-28
Michael
Alan mentions the e-mail scanning function of Norton Anti-Virus as a detection mechanism. A better, preventive, solution would be the full Norton Internet Security suite or any other personal firewall product.

Not only would it block the incoming "random" port, but even if that failed, the Appli...

[ more ]  [ reply ]
Rise of the Spam Zombies 2003-04-28
WarpKat at NoIntegrity.Org (2 replies)
A better way would be to educate users on the follies of their actions and not to trust any attachment that comes to them from unfamiliar people and to even be wary of those that do.

Of course, the ultimate would be to get everyone off of Windows because of the BS that you purchase along with it ...

[ more ]  [ reply ]
Rise of the Spam Zombies 2003-04-29
Anonymous
Rise of the Spam Zombies 2003-04-30
Jim (3 replies)
I always cringe when I see comments like this:

"Of course, the ultimate would be to get everyone off of Windows because of the BS that you purchase along with it and throw them on Linux, BSD or anything else that can't be easily thwarted. "

Where on EARTH did you get the idea that Linux is mor...

[ more ]  [ reply ]
Rise of the Spam Zombies 2003-04-30
Anonymous
Thank you - the voice of (un)common sense. I cringe to think of the support calls I would get if my software expected the users to think. Even my managers have a difficult time using Outlook for anything other than email. "It does meetings, tasks, and calendaring? Wow!"...

[ more ]  [ reply ]
Rise of the Spam Zombies 2003-04-30
Anonymous
1./ If you look only to CERT for your advisories, you know nothing about internet/network/computer security. Check Security Focus, and others first.

2./ Windows is and always has been a pile of poorly coded, poorly implemented tripe. And yes, Virginia, it is less secure than other OSes, most no...

[ more ]  [ reply ]
Rise of the Spam Zombies 2003-05-02
Anonymous
Okay, let's look at the security models of Unix & Netware vs. Microsoft.

Unix & Netware:

By default deny all access

Microsfot:

By default allow all access

Over simplified, but I think the point is clear. Look at the starting point of each of these systems.

Now I wouldn't necessarily a...

[ more ]  [ reply ]
Rise of the Spam Zombies 2003-04-29
Bill Kennard
I noticed this trend last week after much filtering and blocking. Most of our spam now comes from users on broadband isps.

Convince people that Outlook sucks, use Web, Groupwise, Evolution, IMAP.(Rave)...

[ more ]  [ reply ]
Rise of the Spam Zombies 2003-04-30
Mark Gruber
Just want to say that coining an expression like "e-mail laundering" is a pure stroke of genius, from a linguist point of view :) ...

[ more ]  [ reply ]
Take the spammers down 2003-05-01
Crypt0 tronic <crypt0tronic (at) hotmail (dot) com [email concealed]>
I beleive that we should have the right to defend ourselves. I beleive it should be legal for us to take the spammers down. It's not ethical for someone to spam, and if you're ignorant enogh to allow a spammer to use your server to send spam then you should learn a lesson. I think it's even better t...

[ more ]  [ reply ]
Rise of the Spam Zombies 2003-05-01
Anonymous (1 replies)
Intrestingly, my work was attacked recently and the server admin password was changed. Last summer I'd got a new PC and there was no personal firewall installed by IT on it. After the server was attacked, finally personal firewalls were installed on the PC's.

I'd had an incident where the compu...

[ more ]  [ reply ]
Rise of the Spam Zombies 2003-05-02
Anonymous
If you, or any other readers, ever gets their hands on an actual SPAM zombie, I'd very much appreciate a copy, emailed as an attachment to me at helpdesk (at) pestpatrol (dot) com. [email concealed] PestPatrol _should_ catch this stuff and contribute to a solution to this problem.

- David Stang

PestPatrol Research, Developm...

[ more ]  [ reply ]
Rise of the Spam Zombies 2003-05-02
morning_wood
Correct me if im wrong but i think a trojan can be configured for simply "mail" and use the hosts ISP mail. Generally instructions on trojan / RAT say to enter a server but testing i find "mail" is generally sufficent. ...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus