BigPond floodgate wide open to spammers

A flaw in at least one BigPond email server allows spammers to hijack the infrastructure to send bulk emails, resulting in the Telstra server being blacklisted and innocent outgoing emails bouncing back to users, according to comments posted on a broadband users' forum.

The problem is due to the incorrect configuration of at least one Telstra email server, according to an announcement on www.whirlpool.net.au This server is categorised as an "open relay" because it allows anybody to relay outgoing emails through the server without being a BigPond user - an open invitation to spammers who send thousands of unsolicited emails, leaving Telstra (and its end users) to cop the cost.

Online organisations, such as Relay Spam Stopper (RSS), test servers and publish information of those that are insecure - providing administrators with the means to block their servers to incoming emails from open relay servers. These emails bounce back to the sender.

-We've started noticing a large number of our emails bouncing back," Whirlpool's Dan Warne told ZDNet Australia. "Telstra really should have this basic security issue sorted out by now."

Warne claims that protecting a mail server form relay access is "extremely simple" to do and that BigPond users will have -ongoing issues" until the telco heavyweight patches the hole.

"It points to a business problem at their [Telstra's] end - they haven't audited the security of servers adequately," Warne said.

Telstra said it was aware of the problem and was investigating whether it was one of its own servers or that of a customer that was wrongly configured.

The RSS Web site has a database of -spam on file" which is purportedly sent from BigPond servers.

-A well-configured mail server should not relay third-party email, otherwise the server is subject to attack and hijack by Internet vandals and spammers," an RSS message says.

Like this article? Click below to send it to your mobile for free!

Talkback 3 comments

  1. Telstra's ADSL email servers are open spammers. I have had numerous emails bounced trying to communicate with my friends whose ISP's actively check for this type of behavour. When I wish to email my friends, I have to use another email provider. ie;webmai Keith Styles -- 27/08/01

    Telstra's ADSL email servers are open spammers. I have had numerous emails bounced trying to communicate with my friends whose ISP's actively check for this type of behavour. When I wish to email my friends, I have to use another email provider. ie;webmail such as yahoo.

    Telstra have ignored my complaints totally. Why should I be surprised. Their ABUSE section is just as bad.

    1. my billing melvin rama -- 30/11/06

      sir can you explain why my billing is very big my first billing is $318 dollar what charge they have on this amount. My choose 49 every month why 318 my bill now im start oct 23,2006 can you explain me why like this sir so that i dont understand why is very big my bill

      thank you sir please reply me in my email address

      best regard

      melvin rama

  2. Hi, Yes, I use the bigfoot "universal email address for life" as my email address and anyone who sends me an email with thier return address as username@bigpond.com gets rejected by bigfoot because of the SPAMING problem bigpond has. T Phillip Stephenson -- 04/09/01

    Hi,
    Yes, I use the bigfoot "universal email address for life" as my email address and anyone who sends me an email with thier return address as username@bigpond.com gets rejected by bigfoot because of the SPAMING problem bigpond has.
    The moment this happened I emailed bigpond with the information and it has been 8 weeks now and I still have received a reply from them.
    It is interesting to note, however, if some sends me an email from the telstra.com site it makes it through fine. This is because their return address come up as username@telstra.com instead of bigpond.com!

Add your opinion


Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Alex Serpo Will the NSW Govt put Linux in schools?
    The NSW Government's release this week of an expressions of interest tender to give low-cost laptops to every senior public school student in NSW is a big step, but will these systems be Windows or Linux?
  • Array Naked Mac versus protected PC: What wins?
    What's easier to manage — 200 Mac OS X systems without antivirus or 200 Windows systems running a leading antivirus package?
  • Array Dear Telstra: pack up your toys, go home
    Rejecting Telstra's proposal, after all, is the only conclusion Conroy can reach: as someone whose entire philosophy is built around transparency and process, he simply cannot keep Telstra as part of the NBN bidding process anymore.
  • More blogs »

Tags

Back to top

Featured