Re: Blue Frog calls it quits?

"Vanguard" <[email protected]> Wed, 17 May 2006 22:25:00 -0500
Newsgroups gmane.mail.spam.spamcop.user
Organization SpamCop
Message-ID <[email protected]>
"Jesse Hathaway" <holy_saiyan1@2+2=5.REMOVE.MATH.EQUATION.hotmail.com> 
wrote in message news:[email protected]...
> Inaccurate, but a common misconception.  The ratio of number of 
> opt-out messages posted on the spamvertised website to the number of 
> received spam messages spamvertising said website was STRICTLY 1:1.


Sounds super great as they were claiming to provide an automated opt-out 
process (because the BS users were too damn lazy to do the opt-outs 
themselves) and maybe they really only did sent at a 1:1 ratio but WHEN 
they sent was at issue.  They didn't send all those reports from BS 
users at the time the BS users reported the spam.  They stored them up 
so they could slam the targeted site all at once.  After all, if 
opt-outs had worked before then BS wouldn't even be needed - but it 
didn't work.  The site getting opt-outs from individual users when they 
got the spam mail didn't hurt those sites (or cause any collateral 
damage).  However, BS stored up all the reports so their volume would 
accrue to a threshold that became sufficient to become a DOS attack.  Of 
course, it wasn't just a DOS attack.  It was a DDOS attack by BS using 
all their users to distribute the attack from the zombied hosts so the 
attack would hide that BS initiated it.  BS was *not* providing an 
automated opt-out service as they claimed.

They were pending up all those reports until they had enough to slam a 
site and they used the distributed DOS method by using their zombied 
users' hosts.  Yes, BS might have been sending one opt-out from one 
report from a BS user but BS did not send those opt-outs at the same 
rate that they received the reports.  A creek doesn't damage the 
surrounding residential properties but damming it up so a huge reservoir 
builds up and then suddenly releasing it becomes a flood that will harm 
the targeted property (along with other properties).  Trickling out the 
opt-outs at the same rate that the spam reports came in would have no 
more effect than the users themselves submitting the opt-out requests.

The rate of opt-outs sent by individual users receiving spam has not 
worked in the past.  Then BS came out with a "tool" to help users send 
those opt-outs but if the opt-outs impinged the targeted site at the 
same rate as before then BS would be an ineffective solution.  The 
trickle of opt-outs hasn't worked before and trickling them out through 
BS won't work any better.  Pending up the trickle to then blast it out 
all at once would be the only way that the opt-out flood could 
effectively DDoS the targeted site.

Amazing how many BS users bought into the scheme to have their hosts 
running as zombies in a DDOS attack.  Most users expend effort using 
anti-virus and anti-malware products to prevent their hosts from 
becoming zombie slave hosts.