Re: Spam sent from compromised (web)hosts vs botnet spam

"Emanuele Balla (aka Skull)" <[email protected]> Thu, 21 Mar 2013 09:51:02 +0100
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On 3/20/13 10:32 PM, Chris Lewis wrote:

> There's another class that's died down considerably by now.  It's a
> "kit" dropped on hosting environments that contains a full spam suite -
> real MTA etc.  This is real MTAS.  Up until about 5-6 months ago it was
> the largest spam emitter by far.  We class this as snowshoe, because the
> hosting is leased by the spammers.

There's a side-case of this (actually from the same people): purchased
unix boxes in colocation providers, used to create a GRE tunnel with the
spammer's "real location". All IPs delegated to the unix box (except the
one used for the tunnel endpoint) are re-routed through the tunnel, and
used by the spammer to pump out directly from his big pipes, using
asymmetric routing.

The side effect is the colo doesn't see any significant traffic, as the
only traffic going in and out the machine they host is return traffic
(non-tunneled going IN, tunneled going OUT). So, unless you (as colo)
know what to look at, there's nothing triggering your alarms...

-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org