Spammers 'tricking ISPs' into sending junk mail

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

Topics

Spam, ISP, Spamhaus, linford

NEWS
Spam levels are about to skyrocket, according to experts who warned this week that spammers have developed a new way of delivering their wares.

According to SpamHaus -- an anti-spam organisation which compiles blacklists blocking eight billion messages a day -- a new piece of malware has been created that takes over a PC and then uses it to send spam via the mail server of that PC's Internet service provider. This means the spam appears to come from the ISP, making it very hard for an anti-spam blacklist to block it.

Previously, these zombie PCs have been used as mail servers to send spam emails directly to recipients.

"The Trojan is able to order proxies to send spam upstream to the ISP," said Steve Linford, director of SpamHaus.

Linford believes that this Trojan was written by the same people who write spamming software.

Reports suggest that ISPs in the US have already been hit. "We've seen a surge in spam coming from major ISPs. Now all of the ISPs are having large amounts of spam going out from their mail servers," said Linford.

This will cause serious problems for email infrastructures as it is impractical to block domain names from large ISPs. Linford predicts that ISPs will see a growth in the volume of bulk mail they send and receive over the next two months, with spam levels rising from75 percent of all email to around 95 percent within a year.

"The email infrastructure is beginning to fail," Linford warned. "You'll see huge delays in email and servers collapsing. It's the beginning of the email meltdown."

Linford said that ISPs need to act fast to take control of the problem. "They've got to throttle the number of emails coming from ADSL accounts. They are going to have to act quickly to clean incoming viruses. ISPs have so much spam -- they are too understaffed to call people up and tell them they have Trojans on their machines. And no one would know what you're talking about."

ISPs BT and Thus didn't respond to requests for comment on this issue.

Anti-spam company MessageLabs confirmed Linford's findings.

"This ups the ante in the need for filters," said Mark Sunner, chief technology officer for MessageLabs. "It makes it more difficult for people who compile black lists, which is why spammers are doing this. It will put more pressure on ISPs to take greater interest in the traffic they carry and filter at source."

The Information Commissioner's Office, the UK's point of call to report about spam, said it had received no complaints of bulk spam from ISPs. A statement from the ICO said, "As you are aware the ICO's role is to enforce the regulations (the Privacy and Electronic Communications (EC Directive) Regulations 2003. If it receives complaints regarding spam, the ICO needs to establish the source of the spam to take action. The ICO then contacts the company concerned."

Talkback

Hmm. Well I'd be surprised if most ISPs didn't already have software to detect suspicious email activity from a user, so I can't see this technique working particularly well. Seems like someone's massively overhyping this situation. "Email meltdown" indeed?!

via Facebook 3 February, 2005 14:14
Reply

Shouldn't ISPs suggest software (avg, spybot, etc) to their customers to prevent this?

via Facebook 3 February, 2005 14:50
Reply

I noted Steve's comment - but it seems to me that the article is trying to say is that the infected PC starts acting exactly like the ISP mail server. If this is true, then how will the difference between real and phoney servers be determined? In other words will the ISP be able to determine the source?

via Facebook 3 February, 2005 16:32
Reply

There's only one way to stop these people - toughen up and send them to jail.
Up the ante and start imposing fixed custodial sentences to anyone convicted of unsolicited emailing.
Its intrusive and costs all of us in the long run in increased access charges.
ISP's pay by the megabyte and the more they pay the more we pay for access, if they are paying for a vast amount of traffic from a tiny minority of spammers then we are the ones that suffer. Lock the spammers up I say.

via Facebook 4 February, 2005 13:31
Reply

To curb some of the backlash of spam, I would see if my ISP had a setting to only allow email from those in your address book.

via Facebook 26 February, 2005 13:16
Reply

Hi!

i'm currently in charge of setting up ISP MX's and Filters.
But, i don't agree to Dan Ilett's article. Indeed, spam from customer accounts IS a problem, but not this big, to proclamate the beginning end of SMTP.
Yes, it's an ongoing 'fight' against spammers and even if the filters are getting better (at provider-level: refer to SPF and equivalents) spammers will use techniques against them.
Essentially, i believe the whole spam problem cannot be solved on a technical base, well, today you're able to seal systems nearly perfect, but regular users won't deal with certificates and keys, they expect easy use.
I believe, the spam problem has to be solved at an political and legal level. As long as it is possible to sell products advertised via spam only, we're fighting against windmills.

Only my two cents :)

Stephan

via Facebook 9 March, 2005 16:54
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

2 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

7 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

9 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

9 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

11 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

12 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

12 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

13 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

13 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

14 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

14 hours ago by ramwellian on Cloud computing security: no more oxymoron?
BugStalker

"Interesting thought ... If you installed Win7 as a dual boot on a machine that previously only had Linux, and it wrecked your Linux installation,...

14 hours ago by BugStalker on Windows 7 Declares War on GRUB
whs001

This is an excellent summary of Ubuntu and Mint and the interface differences between them. Most such articles take a very partisan position for...

14 hours ago by whs001 on A tale of two distros: Ubuntu and Linux Mint
Moley

@ewallace. Not so clear. Anyone can obtain the text, for example from here http://www.ustr.gov/webfm_send/2379. I support ACTA so long as it and...

15 hours ago by Moley on ACTA: Facts, misconceptions and questions
45283

I think WinRT is fantastic. I just wish it was an option for people that didn't want to go through Microsoft's App Store with its attendant...

18 hours ago by 45283 on Why Windows 8 needs architectural hygiene for WOA
Burn-IT

Nine people? £30m? Who's back pocket is that lot going in? And IF they say it is for new buildings, what about all the ones the government has...

19 hours ago by Burn-IT on Police set to launch three £30m e-crime hubs
ewallace

Just to be clear, nobody knows what is in the text of ACTA, here is a photograph of the text of ACTA http://twitpic.com/8h9iju as submitted to the...

19 hours ago by ewallace on ACTA: Facts, misconceptions and questions
fgvrg56

Unfortunately main issue is that ASUS is refusing to accept that they make some mistake on this version of asus Transformer prime. 1 - GPS sensor...

20 hours ago by fgvrg56 on Asus Eee Pad Transformer Prime Wi-Fi & GPS problems?
Ben Woods

@Marcus A fair question. Just talked with Archos which said it was working on an announcement for next week....

21 hours ago by Ben Woods on Archos confirms G9 Ice Cream Sandwich update schedule
Marcus Karlsson

Any update on this, considering the claimed "first week of February"?

22 hours ago by Marcus Karlsson via Facebook on Archos confirms G9 Ice Cream Sandwich update schedule