Spammers 'tricking ISPs' into sending junk mail

By Dan Ilett, Special to ZDNet
03 February 2005 08:31 AM
Tags: spam, isp, scam, anti, trick
A massive spam spike is predicted, and one expert says that 'it's the beginning of the email meltdown'.

Spam levels are about to skyrocket, according to experts who warned this week that spammers have developed a new way of delivering their wares.

According to SpamHaus -- an anti-spam organisation which compiles blacklists blocking eight billion messages a day -- a new piece of malware has been created that takes over a PC and then uses it to send spam via the mail server of that PC's Internet service provider. This means the spam appears to come from the ISP, making it very hard for an anti-spam blacklist to block it.

Previously, these zombie PCs have been used as mail servers to send spam emails directly to recipients.

"The Trojan is able to order proxies to send spam upstream to the ISP," said Steve Linford, director of SpamHaus.

Linford believes that this Trojan was written by the same people who write spamming software.

Reports suggest that ISPs in the US have already been hit. "We've seen a surge in spam coming from major ISPs. Now all of the ISPs are having large amounts of spam going out from their mail servers," said Linford.

This will cause serious problems for email infrastructures as it is impractical to block domain names from large ISPs. Linford predicts that ISPs will see a growth in the volume of bulk mail they send and receive over the next two months, with spam levels rising from75 percent of all email to around 95 percent within a year.

"The email infrastructure is beginning to fail," Linford warned. "You'll see huge delays in email and servers collapsing. It's the beginning of the email meltdown."

Linford said that ISPs need to act fast to take control of the problem. "They've got to throttle the number of emails coming from ADSL accounts. They are going to have to act quickly to clean incoming viruses. ISPs have so much spam -- they are too understaffed to call people up and tell them they have Trojans on their machines. And no one would know what you're talking about."

ISPs BT and Thus didn't respond to requests for comment on this issue.

Anti-spam company MessageLabs confirmed Linford's findings.

"This ups the ante in the need for filters," said Mark Sunner, chief technology officer for MessageLabs. "It makes it more difficult for people who compile black lists, which is why spammers are doing this. It will put more pressure on ISPs to take greater interest in the traffic they carry and filter at source."

The Information Commissioner's Office, the UK's point of call to report about spam, said it had received no complaints of bulk spam from ISPs. A statement from the ICO said, "As you are aware the ICO's role is to enforce the regulations (the Privacy and Electronic Communications Regulations 2003). If it receives complaints regarding spam, the ICO needs to establish the source of the spam to take action. The ICO then contacts the company concerned."

ZDNet UK's Dan Ilett reported from London. For more coverage from ZDNet UK, click here.

Advertisement

Talkback 2 comments

    You don't issue bulletproof ve ...Anonymous -- 03/02/05

    You don't issue bulletproof vests to the general population to prevent death from a gun-toting killer - you arrest the killer and take away his gun. Why would you filter spam at the RECEIVING end and let the delivery infrastructure become bogged down?

    Time to get serious - bounce the SPAM back at the sender if it fails the filter rules, and let them sort it out. For those that are genuine spammers, they will have to get a little more sneaky, but for the 'inadvertant spammer' that doesn't realise that they have been compromised, they will soon realise that something is amiss...

    Fix the right problem folks!

    Many of the spam toting bandit ...Anonymous -- 03/02/05

    Many of the spam toting bandito's, are not the real culprits. It may be that little old Maude and Mickey of east mid west somewhere in the middle of a wide open prairie, have been duped into thinking they can be the next famous celebrity couple, by making the fortunes from the world wide web of home business opportunities. Your email address has already been sold several thousand times now to such couples. Many of those schemes were set up with legitimate looking facades, by criminal organisations, several years ago. If they didnt collect your email address using a search engine virus, they certainly have the software to generate it anyway.

    The situation may be a little more complex, with major brands fighting to maintain their online image and global market share, and brilliant tracking programs designed to deliver statistics for aggressive online marketing.

    Now who is it we need to arrest, which country, and with whose jurisdiction? Maybe we can rely on the FDA to protect us.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • David Braue Forget the NBN, 100Mbps is already here
    Telstra and TransACT will shortly begin offering 100Mbps broadband to many customers. By moving early, the companies have not only raised the bar for Australia's broadband services, but thrown down a challenge to a government that now faces increased pressure to deliver the NBN as promised.
  • Array IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • Array Can complaints on mobile content be cut?
    On 1 July this year the new Mobile Premium Services Code was introduced. It sounds like it's had a good impact, but is it enough?
  • More blogs »

Tags

Back to top

Featured