Re: Web host spam vs spam filters

Chris Lewis <[email protected]> Thu, 20 Jun 2013 16:22:22 -0400
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On 06/20/2013 01:07 PM, Martijn Grooten wrote:
>> One obvious difference between a botnet compromised windows desktop
>> and a botnet compromised unix webserver would seem to be that the
>> webserver probably has a perfectly functional MTA, meaning that it'd be less
>> likely to have some of the obvious giveaways (protocol and headers) that the
>> mail from compromised desktops often has.
>
> Yes - though I've been told that most of the scripts used to send botnet spam aren't very different than what's used on Windows boxes. At least they don't seem to use the local MTA.

Right.  All of the ones I've seen are written in PHP or Perl, and do 
direct-to-MX.

The operators of these machines tend to be at least somewhat more 
technically astute than the canonial "grandma on DSL", and real MTA logs 
are too much of a dead giveaway as to the presence and ultimate 
eradication of the malware.

-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org