Re: Web host spam vs spam filters

Barry Shein <[email protected]> Wed, 19 Jun 2013 15:53:31 -0400
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
I notice a similar pattern, informally, here. That "informally"
includes not my mail box per se but the mail system here for our
customers at this ISP and the constant, daily effort to add cases to
the global spam filters. Our filter list includes around 170,000
specific cases which include ip ranges, body and subject text
patterns, etc. developed over the years one at a time from customer
complaints and attack forensics.

But I think definitionally it's a hard row to hoe.

My impression is spammers find web sites on web hosting services using
web software either with known holes and/or holes they can easily scan
for.

It's really just a massive extension of the open relay problem.

Where we used to be able to say that a site running, say, sendmail
with a particular rule set could be exploited by a spammer today it
could be any of zillions of e-commerce or other packages either known
or home-brewed or a little of both (code added to some package out
there which was ill-conceived security-wise) which can be used as an
open relay.

I also assume spammers just set up on these hosting services and put
their own relay code onto their site.

I guess all I'm trying to say is: Yes, but a big, big problem, the new
botnets, not that the old ones have gone away.

-- 
        -Barry Shein

The World              | [email protected]           | http://www.TheWorld.com
Purveyors to the Trade | Voice: 800-THE-WRLD        | Dial-Up: US, PR, Canada
Software Tool & Die    | Public Access Internet     | SINCE 1989     *oo*
-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org