Re: Spam sent from compromised (web)hosts vs botnet spam
Paul Smith <[email protected]> Wed, 20 Mar 2013 17:46:38 +0000
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On 20/03/2013 16:59, Martijn Grooten wrote: > So, research. > > A few people (Chris a.o.) have mentioned the large volume of spam sent from compromised webhosts. > > Here someone looked at CBL's stats and found that the ten worst senders of spam are all hosting companies: > > http://www.mailchannels.com/blog/2013/03/worlds-largest-spam-sources-are-all-hosting-companies/ > > I think this isn't just an interesting statistic about spam (like reports listing the ten worst spam-sending countries), but it may indicate a problem. I've noticed this as well. I'm not convinced they're all 'compromised webhosts'. The ones I've noticed noticing are in big blocks of hosting company address space (eg aaa.bbb.ccc.130-254), and they all had valid SPF entries, and reverse-DNS names which don't look legitimate at all, but match the sender domain. (If you get spam which has good SPF entries, it's sometimes worth investigating further) Eg, on our internal 'DNSBL' we have 46.20.116.1-46.20.116.155 as a 'bad range' from last year. These didn't seem to be running anything on port 80 or port 25 at the time, but were pumping out spam at a huge rate. The IP range is owned by Peer 1 Hosting (http://en.wikipedia.org/wiki/Peer_1) who are quite big. So, AFAICS either: - someone hacked a big bank of servers (or a server with lots of IP addresses), and managed to set up reverse DNS for the addresses so that they could have good SPF results - Peer 1 hosting gave lots of servers and/or lots of IP addresses to someone who paid for them with stolen card details, without doing adequate checks, or - Peer 1 are colluding (I'm not picking on Peer 1 here, that's just the example I came across first. We have also got big blacklisted ranges from Network Operations Centre, Inc (nocinc.com), SInglehop, DevilDogs Hosting and many other hosting companies) My suspicion is that spammers are using stolen card details, setting up server(s) in a hosting company running them for a few days (with HUGE bandwidth) and then abandoning them when they get discovered The sad thing is that the hosting companies don't seem to learn. I have lots of ranges from nocinc.com which have been used for spamming over many months. So, it looks as if the spammers just go back again and again with new stolen card details. I've tried contacting several of these companies when I notice spam pouring in from their servers, but tend to get ignored (or at least, they never bother responding). When we have requests for hosting on our own servers, we always take a look at the details. If we're suspicious we ask for more information (amazing how many people want to buy a commercial mail service, but only have a yahoo.fr email address with a postal address in New Zealand or somewhere). When we start checking up they tend to go away and we just refund the payment, but it looks as if the big hosting companies don't put as much effort in and bear the hit. - Paul Smith Computer Services Tel: 01484 855800 Vat No: GB 685 6987 53 - This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org