主動攻擊 --- 這是 SpammerSkewer 的哲學!!
SpammerSkewer 的作者認為只有耗盡發垃圾郵件的資源才可以使他們停手。所以提議攻擊 Spammer 的網站,在網站的表格內填上你們對垃圾郵件的投訴。這軟件的進一步方法就是用 P2P 的技術,每個參與的 peer互相通知大家新的 spammer 網站和攻擊指令。
Spammer 用 botnets 技術寄垃圾郵件,antispamming 今天也用類似技術反擊。
問題是: SpammerSkewer 的作者選擇不公開自己的身份 (恐怕比 spammer 報復 ??) ,大家憑甚麼相信他派的攻擊指令一定是 spammer 網站呢?? 再者這類攻擊是否合法還要法律界人仕澄清。
2007年1月27日 星期六
帝國反擊戰
2007年1月26日 星期五
造市

一直很奇怪為何關於股票的垃圾郵件為何特別多的 (據統計,垃圾郵件中有 15% 是關於股票的)。此類郵件一般會推薦一或幾隻所謂「仙股」,用 pump and dump (aka pump'n'dump) spam email 方式發送出去,今日看到一篇文章講此類 spam email 對股價變化的分析先知道「造市」是那麼容易,利潤也不錯。這也解釋為何這類垃圾郵件的發送技術是最新和最有創意的。
標籤: News, pump and dump
2007年1月23日 星期二
Nolisting -- Poor Man's Greylisting
今天從 Slashdot 看到這篇文章介紹一個 anitspam solution 叫 Nolisting。簡單來說就是:
1. Primary MX 故意地不接 SMTP connection , 而根據 RFC 2821 規定,Client connection 會
2. 轉接到 Secondary MX,而這才是真正的 Email server。
3. 根據作者所說,Spammer 用的軟件大部份是 non-RFC compliance ,所以當 primary MX 不接時就不會再寄垃圾郵件到此地址。
但我自己的實際觀察是:
1. Secondary MX 也有垃圾郵件的。這可以由 headers 中看到!! 有Spammer 反而是故意攻擊 secondary mx --- 因為認為這些 secondary mx 的保護一般會較差。
2. Slashdot 內的評論也說某些正常 SMTP 也是 non-RFC compliance。這些 smtp server 便永遠不能寄信給你了。
2007年1月22日 星期一
已所不欲,勿施於人
上一篇談到 backscatter 問題的文章提到有些 antispam gateway 是 catch all 的,判斷電郵地址正確與否交了給下層的 delivery agent ,這種做法是不正確的。大家看了 Richi Jennings 的兩篇文章,便知道這麼做的嚴重性。如果你不能在 SMTP 層面 reject unknown user ,而要等到 delivery 層面時才 rebound message 的話,最大可能是 rebound 到一些無辜的第三者身上。
我前幾個星期替一個客戶安裝 email server,他不需要我安裝 anitspam 和 firewall function,因為他用上了一間香港「著名」的 antispam 公司的產品 (據講還得了獎)。
當天大家上 datacenter ,分別完成了各自的安裝工作,我奇怪的問那公司的工程人員為何從不問我電郵戶口的資料,他說不需要了,所有 incoming 來信 antispam gateway 都會接收,判斷是否有問題 (virus 或 spam),無問題的就交給你的 email server ,由我的機器是否需要 rebound。
我跟着解釋這方法的問題所在,他才勉強的接受我 export 一個 text based account list ,好讓他能在 smtp 層面擋 dictionary attack。
2007年1月20日 星期六
發放垃圾郵件坐 101 年監??
這是美國第一宗針對發放垃圾郵件的案件:
Source
LA-area man first in nation convicted under anti-spam law
Associated Press
LOS ANGELES - A man faces a sentence of up to 101 years in federal prison after being the first person in the U.S. convicted under a federal anti-spam law, authorities said.
Jeffrey Brett Goodin, 45, of Azusa, was found guilty Friday of running a "phishing" scheme that tricked people into believing they were giving personal information to a legitimate business. Prosecutors said Goodin then used the information to go on a spending spree.
Goodin is the first person in the nation convicted under the 2003 CAN-SPAM Act, the U.S. attorney's office said. The law forbids e-mail marketers from sending false or misleading messages and requires them to provide recipients with a way to opt out of receiving future mailings.
During trial, prosecutors presented evidence that Goodin used several compromised Internet accounts to send e-mails to America Online users. The e-mails appeared to be from the company's billing department and told customers to update their billing information or lose service.
The e-mails referred people to one of several Web pages controlled by Goodin where they could enter their personal information, prosecutors said.
In addition to the anti-spam conviction, Goodin was convicted of 10 other counts, including wire fraud, misuse of the AOL trademark and attempted witness harassment.
Goodin is scheduled to be sentenced June 11.
我已在 google calender 記下 6月11日這天,就看看到時判多少刑期。
2007年1月18日 星期四
ORDB 結束營業
ORDB 結束營業已經不是新消息了,這是我開始寫這 blog 之前的新聞。但到昨天才感受到它帶來的影響:
昨天一個舊客打比我說收不到電郵。他的 server 已經是兩年前安裝的,當時他堅持要安裝 qmail (這是一個我最不熟悉的 MTA ,我對 qmal 的評語一向都是「安裝容易,管理、除錯麻煩」的東東)。老實說,自此之後我從沒有再安裝過 qmail。
他打電話來時我也考慮過幫不幫他呢? 我心想,收錢都未必解決到問題喎,我對 qmail 的認識只是到了安裝階段,兩年都無問題真的要感恩了。聽他說得那麼緊急,即管上去看看吧。他公司電郵伺服器病徵是:
telnet mail.emailserver.com 25 後的 220 greeting response 要很久才有回應 (要等足足三分鐘!!)。一般來說這一定是 DNS 問題 (nameserver set 錯了),但為何同一部機的 pop3 就無問題!! 跟了足足一個鐘頭仍然毫無頭緒,正常告訴客人有錢也賺不到,準備離開時忽然醒覺這個 qmail 是有做 MTA level 的 DNSBL (RBL) blocking 的,立即找找它用的 RBL ---- 其中一個是 relay.ordb.org!!
我的天啊,難道真的是這一個。刪除了這一個 RBL,restart qmail。Bingo!!! 一切回復正常。
我回來後再看看資料,ordb 的 server 應該是 06年12月31日 shutdown 了,但為何我的客戶說他到前天才有問題呢?? 難道 31日後仍然運作了一段時間??
還有的是立即看看我其他客戶的電郵 server 有沒有相同問題..........