Re: Web host spam vs spam filters
Chris Lewis <[email protected]> Thu, 20 Jun 2013 16:22:22 -0400
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On 06/20/2013 01:07 PM, Martijn Grooten wrote: >> One obvious difference between a botnet compromised windows desktop >> and a botnet compromised unix webserver would seem to be that the >> webserver probably has a perfectly functional MTA, meaning that it'd be less >> likely to have some of the obvious giveaways (protocol and headers) that the >> mail from compromised desktops often has. > > Yes - though I've been told that most of the scripts used to send botnet spam aren't very different than what's used on Windows boxes. At least they don't seem to use the local MTA. Right. All of the ones I've seen are written in PHP or Perl, and do direct-to-MX. The operators of these machines tend to be at least somewhat more technically astute than the canonial "grandma on DSL", and real MTA logs are too much of a dead giveaway as to the presence and ultimate eradication of the malware. - This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org