Re: Spam sent from compromised (web)hosts vs botnet spam

Martijn Grooten <[email protected]> Wed, 20 Mar 2013 20:57:45 +0000
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
> I've heard that a lot of them are sites running versions of blog or cms
> software with known security holes that allow bad guys to upload scripts and
> run them.  Since the number of popular blog and cms packages is small, the
> scanning and upload is automated.

That's my understanding too. WordPress, Joomla, phpBB all need to send the occasional email, so if you buy a web hosting package on a shared host you can send emails from it too. Vulnerabilities in these packages (usually in older versions of these packages - a lot of the compromised websites have long been abandoned) allow for crooks to upload files, including PHP and .htaccess. The latter can be used to redirect people to spam sites (so the domains seen in spam are quite often legitimate - that's another problem), while the former allows the crooks to send spam.

I'll do some initial research to see if a significant number of spam sending IPs is listening on port 80. If there is, I'll look at the correlation between catch rates and listening on port 80. I'm making the assumption here that, for IP addresses that send spam, there is significant overlap between 'listening on port 80' and 'being a compromised webhost'.

Distinguishing other kind of hosts may be more difficult, but I'll see if I can automate some of that.

Martijn.


________________________________

Virus Bulletin Ltd, The Pentagon, Abingdon, OX14 3YP, England.
Company Reg No: 2388295. VAT Reg No: GB 532 5598 33.
-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org