Re: Spam sent from compromised (web)hosts vs botnet spam
Chris Lewis <[email protected]> Wed, 20 Mar 2013 17:32:13 -0400
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On 13-03-20 01:46 PM, Paul Smith wrote: > On 20/03/2013 16:59, Martijn Grooten wrote: >> Here someone looked at CBL's stats and found that the ten worst >> senders of spam are all hosting companies: >> >> http://www.mailchannels.com/blog/2013/03/worlds-largest-spam-sources-are-all-hosting-companies/ >> >> >> I think this isn't just an interesting statistic about spam (like >> reports listing the ten worst spam-sending countries), but it may >> indicate a problem. > > I've noticed this as well. I'm not convinced they're all 'compromised > webhosts'. The ones I've noticed noticing are in big blocks of hosting > company address space (eg aaa.bbb.ccc.130-254), and they all had valid > SPF entries, and reverse-DNS names which don't look legitimate at all, > but match the sender domain. The ones that mailchannels is talking about are truly infected webhosts with direct-to-MX spam engines (usually written in PHP or Perl) that have gotten onto the webhosts by compromised user credentials (hosted website's owner's PeeCee got compromised) or an outright hole in a unpatched version of Joomla, wordpress, Cpanel, Plesk or some other similar thing. I have copies of these spam tools. They aren't real MTAs sending the spam. They don't _have_ to be web servers either. I have encountered a number that are *ix machines with a remotely controlled perl script with _no_ web server. The perl scripts are encrypted inside of executable binaries and includes a proxy, a downloader, and a spam engine, and don't need a web server. The above spam engine can push in excess of 60 emails/second over wimpy house-grade G wireless from a dual Atom laptop. How do I know? Because I run it occasionally to see what it's sending ;-) There's another class that's died down considerably by now. It's a "kit" dropped on hosting environments that contains a full spam suite - real MTA etc. This is real MTAS. Up until about 5-6 months ago it was the largest spam emitter by far. We class this as snowshoe, because the hosting is leased by the spammers. But the former, compromised *IX, usually web servers, are about 50% of all spam now. - This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org