BigPond floodgate wide open to spammers

A flaw in at least one BigPond email server allows spammers to hijack the infrastructure to send bulk emails, resulting in the Telstra server being blacklisted and innocent outgoing emails bouncing back to users, according to comments posted on a broadband users' forum.

The problem is due to the incorrect configuration of at least one Telstra email server, according to an announcement on www.whirlpool.net.au This server is categorised as an "open relay" because it allows anybody to relay outgoing emails through the server without being a BigPond user - an open invitation to spammers who send thousands of unsolicited emails, leaving Telstra (and its end users) to cop the cost.

Online organisations, such as Relay Spam Stopper (RSS), test servers and publish information of those that are insecure - providing administrators with the means to block their servers to incoming emails from open relay servers. These emails bounce back to the sender.

-We've started noticing a large number of our emails bouncing back," Whirlpool's Dan Warne told ZDNet Australia. "Telstra really should have this basic security issue sorted out by now."

Warne claims that protecting a mail server form relay access is "extremely simple" to do and that BigPond users will have -ongoing issues" until the telco heavyweight patches the hole.

"It points to a business problem at their [Telstra's] end - they haven't audited the security of servers adequately," Warne said.

Telstra said it was aware of the problem and was investigating whether it was one of its own servers or that of a customer that was wrongly configured.

The RSS Web site has a database of -spam on file" which is purportedly sent from BigPond servers.

-A well-configured mail server should not relay third-party email, otherwise the server is subject to attack and hijack by Internet vandals and spammers," an RSS message says.

Advertisement

Talkback 3 comments

    Telstra's ADSL email servers are open spammers. I have had numerous emails bounced trying to communicate with my friends whose ISP's actively check for this type of behavour. When I wish to email my friends, I have to use another email provider. ie;webmaiKeith Styles -- 27/08/01

    Telstra's ADSL email servers are open spammers. I have had numerous emails bounced trying to communicate with my friends whose ISP's actively check for this type of behavour. When I wish to email my friends, I have to use another email provider. ie;webmail such as yahoo.

    Telstra have ignored my complaints totally. Why should I be surprised. Their ABUSE section is just as bad.

    my billingmelvin rama -- 30/11/06 (in reply to #120005330)

    sir can you explain why my billing is very big my first billing is $318 dollar what charge they have on this amount. My choose 49 every month why 318 my bill now im start oct 23,2006 can you explain me why like this sir so that i dont understand why is very big my bill

    thank you sir please reply me in my email address

    best regard

    melvin rama

    Hi, Yes, I use the bigfoot "universal email address for life" as my email address and anyone who sends me an email with thier return address as username@bigpond.com gets rejected by bigfoot because of the SPAMING problem bigpond has. TPhillip Stephenson -- 04/09/01

    Hi,
    Yes, I use the bigfoot "universal email address for life" as my email address and anyone who sends me an email with thier return address as username@bigpond.com gets rejected by bigfoot because of the SPAMING problem bigpond has.
    The moment this happened I emailed bigpond with the information and it has been 8 weeks now and I still have received a reply from them.
    It is interesting to note, however, if some sends me an email from the telstra.com site it makes it through fine. This is because their return address come up as username@telstra.com instead of bigpond.com!

Add your opinion


Latest Videos

Blogs

  • Chris Duckett PayPal launches Aussie developer program
    PayPal announced the opening of its certification program for Australian developers today, making Australia the first country outside of the US to offer certification.
  • Array Cash cow in a BigTinCan?
    Around one third of Australia's telcos have shut their doors over time, but that isn't stopping new ventures hoping to chip away at carriers' mobile call bonanza. By fighting carriers at the smartphone rather than the home phone, could the latest two contenders be onto something big?
  • Array A third of the way to a zettabyte
    This week on Twisted Wire we look at how internet usage is changing in Australia and around the world. How are we meeting this demand and how is the cost structure changing for the service provider?
  • More blogs »

Tags

Back to top

Featured