Please support our Tech Talk advertiser:
Feb 28th, 2008, 6:03 pm
McAfee Avert Labs has warned that the number of spammers which use the 'out of office' functionality of web-based email systems to distribute junk mail is on the increase. The particular technique in question, which involves spammers setting up web-based email accounts which are configured to auto-respond with spam instead of a genuine 'sorry but I am away from the office right now' message, is reaching new heights of popularity.
One spammer seen using this technique is advertising an adult Web site. The auto-responder spam does not look like a typical out of office reply. The message subject does always contain "Re:" because that's added by the Web mail service, but the spammer controls the rest of the subject line and the message body text. Indeed, pretty much the only way to determine the auto-responder nature of the mail is to carefully inspect the headers.
"In recent weeks we have seen an increasing number of spam apparently sent by legitimate Web-based e-mail systems," said Jeremy Gilliat, an Aylesbury, UK-based anti-spam engineer at McAfee. "Interestingly we see spam from a number of accounts being abused in this way. I suspect the spammer has a program that automatically creates accounts and sets the responder text, all with no manual work required. This gives the spammer the capability to have lots of Web-mail accounts, all used to spam lots of people."
From the perspective of the spammer it makes plenty of sense, because it is yet another method of circumventing many anti-spam filtering systems. After all, an automatic reply from any of the usual suspects when it comes to web-based email systems will look pretty legitimate to most such tools. Botnets tend not to have a legit sender nor do they come replete with correct signatures such as DKIM, DomainKey or Sender ID for example. McAfee, of course, claims its own filters are not so easily fooled and use a combination of header and message content checks to block such auto-responder spamming.
One spammer seen using this technique is advertising an adult Web site. The auto-responder spam does not look like a typical out of office reply. The message subject does always contain "Re:" because that's added by the Web mail service, but the spammer controls the rest of the subject line and the message body text. Indeed, pretty much the only way to determine the auto-responder nature of the mail is to carefully inspect the headers.
"In recent weeks we have seen an increasing number of spam apparently sent by legitimate Web-based e-mail systems," said Jeremy Gilliat, an Aylesbury, UK-based anti-spam engineer at McAfee. "Interestingly we see spam from a number of accounts being abused in this way. I suspect the spammer has a program that automatically creates accounts and sets the responder text, all with no manual work required. This gives the spammer the capability to have lots of Web-mail accounts, all used to spam lots of people."
From the perspective of the spammer it makes plenty of sense, because it is yet another method of circumventing many anti-spam filtering systems. After all, an automatic reply from any of the usual suspects when it comes to web-based email systems will look pretty legitimate to most such tools. Botnets tend not to have a legit sender nor do they come replete with correct signatures such as DKIM, DomainKey or Sender ID for example. McAfee, of course, claims its own filters are not so easily fooled and use a combination of header and message content checks to block such auto-responder spamming.
This blog entry was written by Bill Andad, staff writer aka newsguy. It has received 1,251 views, 0 comments, and 12 linkbacks. 3 voters have rated this entry an average of 5 out of 5 stars. It was promoted to featured status Feb 28th, 2008.
•
•
•
•
advertising apple browser business crime data development email environment europe facebook firefox forensic gaming google hacking hardware help ibm internet iphone ipod it law legal linux malware marketing microsoft mobile mozilla news phishing privacy research search security social networking software spam survey technology trojan video virus vista web windows yahoo youtube
All Recent Tags Post Comment
•
•
•
•
Only community members can start a blog or comment on blog entries. You must register or log in to contribute.
•
•
•
•
•
•
•
•
DaniWeb Tech Talk Marketplace
Related Blog Entries
- Viacom defends itself over YouTube data log disclosure (23 Hours Ago)
- Apple slow to patch iPhone security holes (1 Day Ago)
- Microsoft 'Equipt' to Battle Free Software (1 Day Ago)
- Need an online dictionary? Just ask Ask. (2 Days Ago)
- 12,000 laptops lost in US airports EVERY WEEK (2 Days Ago)
- Judge hands YouTube video viewing data to Viacom (3 Days Ago)
- Ballmer Again Chomping At The Bit for Yahoo (3 Days Ago)
- Apple iPhone 3G creates shortage of flash memory chips (3 Days Ago)
- Microsoft announces host of new Internet Explorer 8 security features (3 Days Ago)
- Seeing double, twice, with Matrox M-Series QuadHead GPU (4 Days Ago)
Related Forum Threads
- What's going on here? (PHP)
- Is this a virus or not?! (Viruses, Spyware and other Nasties)
- Has anyone heard of Global Domains International? (Advertising Sales Strategies)
Featured Entry