Re: Spam sent from compromised (web)hosts vs botnet spam
Chris Lewis <[email protected]> Thu, 21 Mar 2013 13:03:28 -0400
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On 13-03-21 04:51 AM, Emanuele Balla (aka Skull) wrote: > On 3/20/13 10:32 PM, Chris Lewis wrote: > >> There's another class that's died down considerably by now. It's a >> "kit" dropped on hosting environments that contains a full spam suite - >> real MTA etc. This is real MTAS. Up until about 5-6 months ago it was >> the largest spam emitter by far. We class this as snowshoe, because the >> hosting is leased by the spammers. > > There's a side-case of this (actually from the same people): purchased > unix boxes in colocation providers, used to create a GRE tunnel with the > spammer's "real location". All IPs delegated to the unix box (except the > one used for the tunnel endpoint) are re-routed through the tunnel, and > used by the spammer to pump out directly from his big pipes, using > asymmetric routing. I think we're talking about exactly the same thing, you're just giving more detail ;-) - This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org