Slashdot Mirror


My Short Life As An Unintentional Porn Spammer

Freerange writes "Mike Masnick wrote up his experience getting slammed by a somewhat new kind of spam attack that doesn't get much hype (yet?). A spammer spoofed his personal email address as the 'reply-to' for a batch of spam, with interesting results for Mike: "I can now answer the questions 'who replies to spam?' and (should anyone ever wonder) 'what are the hundreds of variations on bounced messages?'" From Politech."

145 of 557 comments (clear)

  1. Reverse spam really isn't that new... by Anonymous Coward · · Score: 5, Insightful

    Spammers have been spoofing legit addresses for a while. I know a lot of times they'll simply use webmaster@somelegitdomain.com and basically cause that person a bunch of grief and headaches. Most users are too clueless to realize it's really not coming from that address.

    1. Re:Reverse spam really isn't that new... by The_K4 · · Score: 5, Interesting

      The new one i've run into recently is they use some kinda script so that the reply-to address in my address....which makes fintering really easy becuase how often do I send mail from my account TO the same account. However I could see some stuipd user getting very confused. :)

    2. Re:Reverse spam really isn't that new... by entrylevel · · Score: 3, Insightful

      What is even less interesting about this is that the Reply-To header can be set to anything you want by most e-mail clients and processors. There are plenty of legitimate reasons for doing this, such as wanting all incoming mail to go to one account, or making people have to think about whether they want to reply to a mailing list or just the default of the original poster. The From header is the one that requires a tiny bit of knowledge to "forge".

      This sounds to me sort of like referring to someone who discovers an unpublished URL by trial and error as a "hacker". Of course, I didn't RTFA, but I will once it is un-slashdotted.

      --
      Karma: Incomprehensible (Mostly affected by posting at +5, reading at -1, and metamoderating everything unfair.)
    3. Re:Reverse spam really isn't that new... by Anonymous Coward · · Score: 2, Informative

      how often do I send mail from my account TO the same account.

      I used to do it all the time - general reminders / memos to self.

    4. Re: Reverse spam really isn't that new... by Black+Parrot · · Score: 5, Funny


      > The new one i've run into recently is they use some kinda script so that the reply-to address in my address....which makes fintering really easy becuase how often do I send mail from my account TO the same account. However I could see some stuipd user getting very confused.

      ...and replying to himself in outrage.

      --
      Sheesh, evil *and* a jerk. -- Jade
    5. Re:Reverse spam really isn't that new... by Greg+Hewgill · · Score: 5, Funny

      That reminds me of when it was cool to tell lusers that there was this huge ftp site at 127.0.0.1, just log in with your existing account...

    6. Re:Reverse spam really isn't that new... by Target+Drone · · Score: 2, Interesting
      It's been happening to me for the last month or two now. I get about 10 or 20 bounced emails a week on an email account that is only used as the contact for my domain name. The fact that I only get a few a week makes me think that the spammer is sending out a thousand or so emails for every contact in the whois database.

      Have any other people that manage a domain run into this problem?

    7. Re:Reverse spam really isn't that new... by WIAKywbfatw · · Score: 3, Interesting

      Ditto.

      The easiest way of me getting data (Word docs, code, etc) to and from a place of business where I'm freelancing and my home is by emailing the files from one web-based email address to that same email address.

      Because the data is being sent from and to the same server, there's no chance that the email won't be delivered. So, you know that (barring a major server or internet breakdown) your data will be there waiting for you at the other end - no need to carry around any media at all.

      It can even be made practically secure - just zip up your files and attach a password to the transmitted zip file.

      Also, should you get side-tracked and not make it home (eg, if you get lucky and score, despite being a geek) then you don't have to worry about carting around a floppy disk or CD-R all day, or worry about losing it (leaving it at her place).

      Temporary online storage like this works wonders.

      --

      "Accept that some days you are the pigeon, and some days you are the statue." - David Brent, Wernham Hogg
    8. Re:Reverse spam really isn't that new... by Zeinfeld · · Score: 4, Interesting
      The new one i've run into recently is they use some kinda script so that the reply-to address in my address....which makes fintering really easy becuase how often do I send mail from my account TO the same account

      More often than you might think. This is how a lot of mail systems support people like me who like to keep a copy of everything they have sent.

      I do wish that more of the spam filtering people would take notice of these tactics however. Quite a few of the more clueless ones have all sorts of hack-back features that can end up slamming innocent people.

      The only unusual thing in this case is that it was porn. The porn senders tend to be rather more discrete than most since they know that if there is an FBI type investigation they are sure to make examples of porno senders first. This tactic tends to be more common amongst the con-artists that the FBI are completely uninterested in prosecuting.

      One of the big problems is that there is no agency that has an analogous operation to the mail-inspectors role in the post office. In theory this is wire fraud but the wire fraud investigators tend to be busy dealing with cases with a few really big transactions. They are much less interested in a case where the amounts are $30 or so, even though the totals might be millions.

      --
      Looking for an Information Security student project suggestion?
      Try http://dotcrimeManifesto.com/
    9. Re:Reverse spam really isn't that new... by dead+sun · · Score: 4, Interesting
      I've actually had spam being forged from my yahoo account a couple times. They didn't do just the reply-to trick either, but instead forged the whole thing so the send from is my email address. Though it's only happened a couple times and I've only ever gotten one irate reply, I know it's happened several times by the mail server bounce back that I get with the original message, along with the huge alphabetical list of addresses it couldn't be delivered to.

      But that isn't the most disgusting part about it. All the bounced addresses were coming from one particular domain, which happens to be the domain my parents are on so I really don't want my email address blacklisted from their servers. Nor do I want my account closed by Yahoo, as I've had the account for a long time. Since I don't want this, and I hate spam as much as the next guy, I decided that I should send that domain owner's operators, which happen to be an ISP, an email message explaining what was going on and that if they could retrieve the headers from my message they'd have another relay they should add to their list to block.

      On to the disgusting part. I get a message back telling me that I have a virus. A virus of all things, sending spam, to alphabetical lists of people on a single domain. Right. I try again, explaining the situation in detail so they can see what's going on. I include the bounce message, etc. They tell me they'll take care of it in that sort of message you know means they'll delete any correspondence we've had to this point and ignore it. Luckily enough I haven't gotten any more such signs that my email address is being forged, but I'm still put out that the people who should care, because it's their bandwidth and customers, first insulted me and then told me in so many words to bugger off.

      --
      If not now, when?
    10. Re:Reverse spam really isn't that new... by BlueUnderwear · · Score: 2, Funny
      ...and others insist that we have to stop whoever is doing it immediatly...

      Hard to do... Easy solution: just block the bounces at your mailserver, at least then the lusers won't notice the problem any longer...

      --
      Say no to software patents.
    11. Re:Reverse spam really isn't that new... by evilviper · · Score: 4, Funny
      just zip up your files and attach a password to the transmitted zip file.


      should you get side-tracked and not make it home (eg, if you get lucky and score


      What kind of a geek ARE you??? Not only do you talk about zip rather than gzip/bzip, then call zip passwording "secure", but you also talk about getting sidetracked by scoring, rather than some more sci-fi reason, like being shot at by storm troopers, attacked by some creature from LOTR, etc. Come on, get it together man! This IS slashdot afterall.
      --
      Slashdot gets worse every day... Pipedot: News for nerds, without the corporate slant
    12. Re:Reverse spam really isn't that new... by jovlinger · · Score: 3, Funny

      many years ago, at this site, i believe, it was reported that someone registered warez.blackdown.net as 127.0.0.1 Could have been SA too.

      The chat logs as people came in fuming and it slowly dawned on people that they had been had were priceless

    13. Re:Reverse spam really isn't that new... by David+Gould · · Score: 4, Funny


      That reminds me of when it was cool to tell lusers that there was this huge ftp site at 127.0.0.1, just log in with your existing account...

      No, it's "Dude, I hate to be the bearer of bad news, but I'm afraid you've been hacked -- the FTP server at 127.0.0.1 has all your personal files. See for yourself; just log in with your normal id..."

      Thing is, it only worked when a sufficiently naive person would still be likely to be using a Unix system and be familiar with FTP, whereas now, even having heard of those things is something like a guarantee of knowing too much to fall for it.

      Speaking of falling for it, though -- didn't I read here a while back that this particular troll had been used on the Scientologists, with spectacular success? Like, they were in court taking a deposition and their lawyer was shouting at the guy "Tell us who runs the FTP server at 127.0.0.1!"

      --
      David Gould
      main(i){putchar(340056100>>(i-1)*5&31|!!(i<6)<< 6)&&main(++i);}
    14. Re:Reverse spam really isn't that new... by AndroidCat · · Score: 5, Interesting

      Keith Henson, during a deposition. It's all over the place, but definitely here

      --
      One line blog. I hear that they're called Twitters now.
    15. Re:Reverse spam really isn't that new... by AndroidCat · · Score: 2, Funny
      You're welcome. I can hear Keith saying that. Heh.

      Jerking the chain of $cientology is always fun. I had one alt.religion.scientology handler threaten me with legal action unless I immediately took down my site .. hisname.isgay.com, ah my! Another time, I contacted a number of critics by email and we started the rumour of a phantom web site called Umbra Xenu, home of the ARSCC [wdne]. (The joke is that I do have a phantom web site with a dynamic IP and weird ports. I'll have to scan my logs some day.)

      --
      One line blog. I hear that they're called Twitters now.
    16. Re: Reverse spam really isn't that new... by Have+Blue · · Score: 4, Funny

      ...And replying to himself in outrage.
      ...And replying to himself in outrage.
      ...And replying to himself in outrage.
      ...And replying to himself in outrage.
      ...And replying to himself in outrage.

      It's "How do you keep an idiot busy for hours?" for the new millenium!

    17. Re:Reverse spam really isn't that new... by AndroidCat · · Score: 2, Insightful
      but instead forged the whole thing so the send from is my email address

      Including the Received lines? Learning how to read those, backstepping from the last (trusted) one takes a bit of practice, but will get you to the spammer or the open proxy that he's hijacking.

      The main thing to track is the web site that most spammers have as the "payload" of their spam. Disposable accounts to send the spam are easy to replace, but getting the web site killed hurts the spammer. (Alas, too many ISPs are wearing the Enormous Foam Helm of Stupidity about spam-support web sites.)

      --
      One line blog. I hear that they're called Twitters now.
  2. What to do with all that spam you get... by insanecarbonbasedlif · · Score: 2, Funny

    It makes good eating, even if it's a little strange

    I tried the first one, and the paper doesn't mix too well, but once the eggs soak through, it cooks up well... not too flavorful. It's more of a filler like Tofu.

    --
    Just because I doubt myself does not mean I find your position compelling.
  3. What the Internet needs: by unterderbrucke · · Score: 5, Funny

    A proprietary mail protocol by a major power (MS?) to eliminate IP address/e-mail address spoofing.

    1. Re:What the Internet needs: by zaqattack911 · · Score: 3, Interesting

      It's funny people are modding you down cuz you mentioned MS.

      I agree with you, and these morons are missing the point. The email protocol is fucked, millions could be saved if we moved to something new. And it is no secret that MS and a few other major companies could have the power to do it.

      Anyways, I gave you a few extra points. The question should be how. And, how on earth can we enforce the destruction of today's email protocol while introducing another? How can we even stop spam with a new one?

    2. Re:What the Internet needs: by pomakis · · Score: 2, Funny
      It's funny people are modding you down cuz you mentioned MS. [...] Anyways, I gave you a few extra points.
      Waaaiiit a minute... that shouldn't be possible! You can't mod something and then reply to it! And what do you mean "a few extra points"? Cheater!

  4. Not New @ All by devaldez · · Score: 5, Interesting

    I experienced this five years ago and a group of sysadmins helped me track the guy back to his ISP and we turned the info over to the FBI as identity theft. We were told that my experience did not meet the threshold for them to investigate further ($5000 in damages). Worse, the ISP didn't have a code of conduct prohibiting this type of thing...

    Sucks when it happens, but isn't new.

    Probably the same idiot in Minnesota:(

    --
    "... but you can love completely without complete understanding." - Norman Maclean, "A River Runs Through It"
    1. Re:Not New @ All by jo_ham · · Score: 4, Funny

      That's what baseball bats are for.

      If the FBI won't take it further, you could always beat seven shades of shit out of him, then when the police arrest you, assume his identity.

  5. Skynet by OwlofCreamCheese · · Score: 5, Funny

    its not going to be military computers that come alive and kill us all, its going to be the spam filters! I mean, its going to take some serious adaptive AI to filter out spam at this rate...

    and the conformforting thought:

    when spamfilters come alive... their prime directive will be "eliminate anything that is worthless"

    --
    -You're wasting your time. Alfador only likes me.
    1. Re:Skynet by Feztaa · · Score: 2, Funny

      when spamfilters come alive... their prime directive will be "eliminate anything that is worthless"

      It wouldn't be all bad; at least we'd be rid of Microsoft once and for all.

  6. I hear ya! by spammeister · · Score: 2, Interesting

    a couple of months ago Rogers cut off a friend of mine in Toronto, and he was without cable for 3 days...When his father was eventually contacted/got a hold of them, they said that my friend was spamming people. If I was there I would have liked to see proof, but I know my friend doesn't spam people and this is pretty groundless. But it just goes to show how gullible ISP's are (at least Roger's) at cracking down on this sort of thing. Basically I lost 3 days of downloading warez to his box (since I live in SlowNet land meh!

    --
    I tried to think of a good sig, and this wasn't it.
    1. Re:I hear ya! by davmct · · Score: 2, Funny

      are you sure it wasn't YOU that were spamming on his account by leaving a worm virus on his machine? what kind of a name is spammeister anyway?

    2. Re:I hear ya! by spammeister · · Score: 2, Interesting

      SPAMMEISTER is the name I use...Mr. DAVMCT????

      at least my nic is thought provoking (unless that isn't your sort of thing :))

      --
      I tried to think of a good sig, and this wasn't it.
  7. Yeah, us too by YodaToad · · Score: 3, Interesting

    The place I work (Productive Data Corporation) gets tons of bounced spams and replies to spams every day. Our domain is productive.com so any email to whatever (at) productive.com comes back to the admin email accounts. As you can probably guess there's quite a few spammers that use productive.com as reply-to. We have to constantly update our spam blockers to weed out all the real emails from the spam =/

    1. Re:Yeah, us too by FuzzyBad-Mofo · · Score: 2, Funny

      So I guess you could say spam lowered your productivity? :rimshot:

  8. For those that have experienced this... by HeelToe · · Score: 2, Interesting

    So what did you do? Change your address? Or wade through it all until eventually the maelstrom died down?

    I'd be pretty upset if this happened to me.

  9. Why? by BurntHombre · · Score: 4, Interesting
    Why intentionally spoof someone's legitimate email address in the reply-to field?

    Why not just put some bogus made-up address there?

    Are the spammers just trying to cause as much chaos and unpleasantness for as many peoples as is humanly possible?

    1. Re:Why? by stratjakt · · Score: 4, Informative

      >> Are the spammers just trying to cause as much chaos and unpleasantness for as many peoples as is humanly possible?

      Perhaps some, but it's also a way to get past some spam filtering app, or to make you think its a legit e-mail. I remember there was a big whoopty-doo a year or so ago about spammers using someone@linux.org as the reply to.

      Which goes into the trashbin first, hotsex69@sexparty.ru or ltrovalds@linux.org?

      --
      I don't need no instructions to know how to rock!!!!
    2. Re:Why? by Black+Parrot · · Score: 2, Interesting


      > Why intentionally spoof someone's legitimate email address in the reply-to field?

      Who knows? Once in a while I get spam faked to look like I sent it to myself.

      Spammers are the only "businesses" in the world who think it's best to be as offensive as possible to potential customers. The mentality is astonishing.

      --
      Sheesh, evil *and* a jerk. -- Jade
    3. Re:Why? by Neon+Spiral+Injector · · Score: 5, Informative

      Hanging out on some anti-spam news groups I've seen this happen to people who go after spammers. In this case the spammer quite intentionally selects the FROM: address to make the bounces and irrate replies cause trouble for someone who has been causing trouble for the spammer. This is called a "Joe-job".

    4. Re:Why? by Fluffy+the+Cat · · Score: 5, Informative

      In general, it's not a good idea to accept mail unless you think you can correctly generate a bounce message if you fail to deliver it. As a result, many mail servers will refuse to accept mail if the

      MAIL FROM:

      section of the SMTP exchange doesn't include a domain that exists. Some will go further and do some checks to see if the localpart exists, too. If the spammers want to get to as many addresses as possible, they have to use a real address rather than a made up one. In some cases, they'll pick the address of someone who's irritated them (anti-spammers, for instance).

    5. Re:Why? by schon · · Score: 4, Interesting

      Why intentionally spoof someone's legitimate email address in the reply-to field?

      Revenge.

      I've had several spammers disconnected by reporting them to their ISP. One of the ISPs I reported to was stupid enough to send the report (along with my email address) to the spammer (before they disconnected them.)

      Next thing I know, I'm getting tons of bounce messages for spam I didn't send.

      It stopped after a week or so.

    6. Re:Why? by evilviper · · Score: 2, Funny
      Which goes into the trashbin first, hotsex69@sexparty.ru or ltrovalds@linux.org?

      Well, if Linus can't spell his own last-name...
      --
      Slashdot gets worse every day... Pipedot: News for nerds, without the corporate slant
  10. It's nothing new by Anonymous Coward · · Score: 5, Informative
    It's referred to as a "Joe Job" or that you've been "joe jobbed"

    an article about it

  11. No way to contact spammer by $$$$$exyGal · · Score: 5, Funny
    I am repeatedly surprised by the amount of spam out there that does not contain any way to contact the spammer. How do they expect to make money if there is no way to contact them?

    --sex

    --
    Very popular slashdot journal for adul
    1. Re:No way to contact spammer by nomadic · · Score: 5, Funny

      Volume!

    2. Re:No way to contact spammer by Sheetrock · · Score: 3, Interesting
      A lot of that in my case is simply 'stock advice' that amounts to setting up a pump-and-dump scheme for the stockholder sending or contracting someone to send the spam. Obviously in such a situation all the stockholder has to do is wait for the price of the stock to be artificially inflated by all the buyers then sell off everything he's got.

      I don't know if this actually works for anybody trying the spam technique, as I'd hope most people getting these messages would either be too smart to fall for it or too afraid of the stock market to set up and manage their own account.

      --

      Try not. Do or do not, there is no try.
      -- Dr. Spock, stardate 2822-3.




    3. Re:No way to contact spammer by TheLink · · Score: 2, Interesting

      Could be like typical brand advertising. I'm sure many of you remember those Enlarge your Penis campaigns, or cheap Norton antivirus, or etc.

      Or perhaps it's a counter strategy by antispammers - they send spam to make people hate spam.

      Or maybe that's a counter counter strategy by spammers, erm nevermind. ;)

      --
    4. Re:No way to contact spammer by wobblie · · Score: 5, Informative

      Some spams are purely for confirmation that your email address works. I repeatedly see spams which have 1x1 pixel gif's that link to a script to call the image and pass your email address off to that script. Biggest reason not to use HTML mail.

    5. Re:No way to contact spammer by Drakonian · · Score: 3, Insightful

      Can I turn off HTML email in Outlook? Sorry for the stupid question that Google would probably answer for me.

      --
      Random is the New Order.
    6. Re:No way to contact spammer by camusflage · · Score: 3, Informative

      Just ask Rodona Garst or her "customer" who paid for the pump and dump, Mark Rice for what their take on this scheme is. Details of their pump and dump can be found here.

      And since everyone loves to see spammers get theirs, go visit Behind Enemy Lines. Be sure to visit the Lets Get Brutal section to see what spammers look like in various states of undress!

      --
      The truth about Scientology, Xenu, and you: Operation Clambake
    7. Re:No way to contact spammer by camusflage · · Score: 4, Informative

      Try this.

      --
      The truth about Scientology, Xenu, and you: Operation Clambake
    8. Re:No way to contact spammer by SoCalChris · · Score: 3, Informative

      Can I turn off HTML email in Outlook?

      As far as I know, there is no way built into Outlook to do this.

      I spent some time searching on how to do this a while ago, and the only way I know of is to use a COM add in. It doesn't work through the rules wizard, you have to go into your advanced email settings and register the DLL before it will work. Search Google, and you'll find the answer. A word of warning though... The one I found a while ago made Outlook painfully slow, so I ended up uninstalling it.

      It is a huge pain the way Outlook has it set up. You can't set up a rule that strips the HTML, you can't set your email to automatically convert HTML mail to plain text, and you can't even use the VBA scripting language built in to automatically strip the HTML. What a pain...

    9. Re:No way to contact spammer by blackbear · · Score: 3, Informative

      Can I turn off HTML email in Outlook?

      You don't need to turn off HTML e-mail to protect yourself. Though it is a good idea if you can stand it.

      All you need to do is tell your mailer not to automatically download images. This will result in readable text with no images, and no indication that you read the mail. You should also turn off auto return reciept (less widely, but more correctly known as DSN notification,) and javascript in e-mail as those can be used against you as well.

      I don't know how to do these things in Outlook, since I use evolution where the default setting is not to download automatically.

    10. Re:No way to contact spammer by ColdForged · · Score: 4, Funny
      I am repeatedly surprised by the amount of spam out there that does not contain any way to contact the spammer. How do they expect to make money if there is no way to contact them?
      Are you really gonna leave that hanging up there like a big, juicy grapefruit?
      1. Sling a kajillion spam messages with no contact information whatsoever.
      2. ???
      3. Profit!

      "We apologize for the previously displayed shenanigans. Those responsible for that ordered list have been sacked."
      --

      -"I seem to be having tremendous difficulty with my lifestyle." - Arthur Dent

    11. Re:No way to contact spammer by ewhac · · Score: 2, Funny

      Can I turn off HTML email in Outlook?

      Um, uh... No! Yeah, there's no way to turn off HTML mail in Outlook. Yeah. Outlook has no provisions for safe email reading.

      To be completely safe, you should... Uh... delete Outlook entirely. Mmm, yeah, delete it. Outlook gone. Perfectly safe. Yeah, that's it...

      Then you can safely install a safe email program, like... Er... Mozilla! Yeah! Or Evolution! Yeah, Evolution. I use it. And so does my wife... Morgan Fairchild...

      Schwab

  12. Not happy... by Space_Nerd · · Score: 5, Funny

    ...with all the spam replies and such he got, he now decides to take it a step further and slashdot his server!

    Way to go!

    --
    Everybody has a purpose in life, maybe mine is to lurk in slashdot.
  13. Happened to Me, Too by Lucas+Membrane · · Score: 4, Interesting

    I'm in the Northwest US. The spam sent with my name came from Bermuda, according to the headers. I got complaints and a reply that seemed to be a death threat. The death threat came from Russia. Email to its return address came back as undeliverable. Talking to my ISP, they said that there is really not much that can be done about this unless I wanted to change my email address. I do business there, so I can't.

  14. Happened to Me 3 Times by snarfer · · Score: 2, Interesting

    This has happened to me three times. Two at one domain my business owned and once at my personal domain.

    First you get millions of bounces. Then you get hundreds of angry replies. "TAKE ME OFF THIS LIST!" (Which only ensures that they get put ON more lists because it proves that it is a valid e-mail and that they OPEN AND READ their e-mail!)

    AND you get the orders! You don't get that many, compared to how many e-mails were sent, but since the RECEIVER pays to receive the stuff, who cares?

    1. Re: Happened to Me 3 Times by Black+Parrot · · Score: 2, Funny


      > First you get millions of bounces. Then you get hundreds of angry replies. "TAKE ME OFF THIS LIST!"

      What I hate is when the spam includes all the victims' e-dresses in the header, and a bunch of people reply/all demanding to be taken off the list. Then a bunch more people reply/all saying "you're an idiot", and then a bunch more reply/all saying "so are you, idiot". You could probably bring down the internet if you included enough e-dresses in the header.

      --
      Sheesh, evil *and* a jerk. -- Jade
  15. Fix it with PGP. by bartman · · Score: 4, Interesting

    Really, the only way to combat this kind of identiy fraud is with PGP. It would be ideal if every mail-program out there supported PGP.

    --
    -- bartman
    1. Re:Fix it with PGP. by Enry · · Score: 4, Informative

      There was a discussion on my local lug.

      PGP/GPG only ensures that you did send it, not that you did not. Since you can send e-mails without being signed, unsigned e-mails don't prove a thing.

      Those that know you (or have your key) would know
      enough about you that any non-PGP e-mails would be
      suspect, but that's what, .000001% of the internet?

  16. Spam needs a technical solution. by Sheetrock · · Score: 5, Insightful
    This adds more weight to my assessment of spam as being a technical problem with a need for a technical solution. Why are address spoofing and open mail relays still a problem after over a decade of spam-related problems?

    Obviously, legislation isn't catching up and as evidenced by the junk fax law is useless when it does. Technical minds built the Internet, and I have little doubt that a solution could be found once we quit looking for the quick fix.

    --

    Try not. Do or do not, there is no try.
    -- Dr. Spock, stardate 2822-3.




    1. Re:Spam needs a technical solution. by sean23007 · · Score: 2, Funny

      Yeah, so let's stop looking for that quick fix, so we can finally get this fixed quick!

      --

      Lack of eloquence does not denote lack of intelligence, though they often coincide.
    2. Re:Spam needs a technical solution. by IamTheRealMike · · Score: 5, Interesting
      About a year ago I designed a new email system. It was pretty kickass.

      It was kind of a cross between usenet and standard email. When you "sent" an email, it was in reality uploaded to your message store (the idea of the inbox was removed). Then notifications were sent to each person that a message was in the To field. That meant that for instance you could edit messages after they were sent, you could bring people in on threaded conversations half way through preserving the threading and so on. It also meant the attachment limit was decided by the senders account, not the receivers. Want to send a 200mb video to your hotmail using friend? No problem.

      One of the features of this system was that key signing was built in from the start. That meant, you could opt to trust certain "roots", probably international ISPs. If you wanted to setup a newMail server, you'd have to get your hosting ISP to sign it for you, probably requiring a contract to be signed saying you'd shut down any abusive accounts etc.

      Mailing lists were dealt with specially, I've never been happy with the way they currently work.

      Combined with send limits (how often do you email >100 people?), that meant that spam could be cut down quite significantly. In particular, because it could be shut off at the source, if a spammer did somehow manage to spam lots of people at once, all it'd take is one report and the email would magically disappear from peoples message stores, before they'd even seen it in some cases. If the spammers were running their own servers, revoking their certs would do a similar trick.

      It wouldn't eliminate spam of course, that's not possible. Smart enough people will figure out ways around it. However, having accountability built in from the start would help curb the situation a lot.

      Originally I was going to write the client as a commercial app, but make the protocols open (with a non-commercial free license available). However, I ended up working on autopackage instead, so I never got around to it. If somebody thinks it'd be cool, contact me and I'll fill you in.

    3. Re:Spam needs a technical solution. by _ph1ux_ · · Score: 2, Interesting

      the other scary feature is when someone figures out how to spoof the recall and auto-delete feature.

      it would require that a hash be made based on the content of the message and that checksum be the message ID. so you could only fuck with messages that you know the explicit content of....

  17. incase of slashdotting by adamruck · · Score: 3, Informative

    the site seemed to be going pretty slow for me.. so Ill put the info here if it gets slashdotted

    My Short Life As An Unintentional Spammer
    by Mike Masnick

    Ever wonder what sorts of emails end up in a spammer's email database? Want to know who actually responds to spam and what they say? Want to know the myriads of formats (and languages) a bounced email message can take? I can now tell you all of this. Without my knowledge, I recently became an accidental porn spammer.

    When I got home one evening a few weeks ago, I noticed that I had more than the expected amount of email waiting for me. A quick glance through the inbox showed about fifty "bounced" emails - saying that email addresses of people I had emailed did not exist. The problem with this, of course, was that I hadn't actually emailed anyone.

    It did not take long to figure out what happened. While some bounces simply told me that the recipient didn't exist, others included the original text of the email I had supposedly sent. It claimed to be from someone named "Chris" or "Ali" and was a reply to an alleged message from an online dating site. Chris and Ali apologized for taking so long to reply, and nervously suggested that the recipient find out more information about them by going to a website. Clearly, this was porn spam. Out of principal I won't visit the websites that were in the spam messages.

    The problem was, I hadn't sent these messages at all. I'm not Chris or Ali. I don't use dating sites. I don't have a porn website. I don't send spam.

    One of the popular "tricks" among spammers nowadays is to set the "reply-to" address as the same as the recipient's email address. That cuts out on the problems of bounce mails, and also has a psychological effect on recipients who are curious what email they've sent themselves. Most spam filters have figured out ways to still capture these spam messages (though, I'm now hearing stories of legitimate emails that people send to themselves being classified as spam). I've received plenty of these types of spam, and most are filtered away, never to be bothered with.

    It seems that this particular spammer took things one step further, and made the "reply-to" address for all of his spam message set to my personal email address. If anyone looked at the headers, it was clear that I had nothing to do with the email whatsoever. However, most mail servers aren't so smart.

    With any spam list, there's a certain percentage of "bad" or outdated email addresses. Generally speaking, a server that receives an email for someone they don't have an account for will "bounce" the message. Those bounces go to the person who sent the message - normally found in the "reply-to" line. Since my email address was in the reply-to line, all those bounces started coming my way, regrettably informing me that my pornographic spam emails had not found their intended recipient.

    After dealing with the rapidly growing desire to reach through the internet and strangle whatever lower-than-life scum did this to my email address, I resigned myself to looking at this from an anthropological perspective. Suddenly, I was in a position to offer information on things that few others would (hopefully) ever willingly have access to.

    Should anyone want it for research purposes, I now have a fairly large collection of bounce messages. It appears there is no standard format for a bounce message (which, by the way, makes them painfully difficult to filter). They have infinitely different subject lines. They say different things in the body of the message, sometimes nicely, sometimes rudely. They show up in different languages with different explanations. Some admit that the account has been closed due to too much spam. Others simply don't exist any more (if they ever did at all). Some bounces quote the original message; some don't. Some include full headers; some don't. Who knew there was such variety in how mail servers bounce their email?

    Beyond the bounce messages were all sorts of auto-responders. It seems that some of the email addresses in the spammer's database were emails people used to send responses to those who "request more info". Suddenly I was receiving huge files of information that I really had no use for whatsoever. I also found out about a number of people who were on vacation that week, or who had recently switched jobs. One even had an auto-responder saying "this is closed...I am tired of the internet... all internet access for me is closing". Some of the addresses were to subscribe to various mailing lists. Many bounced back confirmation emails, asking to prove that I really wanted to subscribe, while others just subscribed me automatically (which will now force me to manually unsubscribe).

    While most of the "information" was fairly useless, I suddenly had the opportunity to peek into the lives of people I had no association with whatsoever - connected only by spammer. I felt like reaching out and commiserating with those who were sick of the spam and wondered if I should congratulate those with new jobs. However, there was no time for that, I had more erroneous spam fallout to deal with.

    Next, came the responses. I, like many people, often wonder what sorts of people actually respond to spam emails. For years, it has been beaten into my head that you never, under any circumstance, respond to a spam email. It just shows that you're a live human being, making your email address more valuable. I'm still shocked when I come across people who haven't heard this. However, they are out there, and they come in all different shapes and sizes. I have their emails to prove it.

    There are the confused, but polite people. One woman wrote me a nice message saying that a "horrible" mistake had been made, and that she had not replied to my online dating ad. She did warn me, however, that there are "plenty of strange people out there" and that I should be careful. How nice. Another woman couldn't remember what she had said in her reply to my non-existent online dating profile and wanted to be reminded. A few others just asked who I was.

    Then there are the unsubscribers, who are under the unfortunate delusion that asking spammers to take them off their list will help. They send simple messages saying simply "unsubscribe" or "unsubscribe, please", as if that will ever get to the actual spammer, or that they would actually pay any attention to it.

    Lastly, are the angry, but clueless. I feel their pain, but they need to find a better outlet. I received emails telling me things I never knew (and find unlikely) about my lineage and suggesting I go places I have no interest in going, using all sorts of language you wouldn't use in polite company. I also received a threatening letter saying that I would be hearing from some company's corporate lawyer.

    None of these people stopped to think that it was odd that my email address includes, pretty clearly, my name - which is neither Chris nor Ali. With the number of spam messages that go out every day, I wonder if these people reply to them all. I guess, for some people with anger management problems, this is a kind of outlet. All day, every day, respond angrily to spam messages, and maybe it will have a calming effect on your life.

    What's scary is that, for the most, part, I only saw the bounced messages. They continued for approximately 36 hours, and then stopped abruptly. In the end, about 500 email messages bounced back to me, so I can only guess at how many thousands of poor, unsuspecting email boxes are currently dealing with spam sent with my email address as the reply-to. I apologize to all of you, even if I had nothing to do with it. I don't want to date you, and please, feel no compulsion to look at the web page in the email.

    Most people agree that spam is evil. It's a waste of time and a general nuisance. I can argue against spam from a variety of levels. It's bad for the internet. It's bad for users. It's bad for business. It's just bad. Luckily, there's a rapidly growing industry of companies (and simply concerned individuals) creating software solutions to help stop the spam menace. While there are debates over how well any of these systems work, it is possible to at least reduce your spam intake. Personally, I use a spam filter that is pretty effective in reducing my spam load to a mostly manageable level.

    However, with something like this, there simply is no effective preventative measure in place. The spammers spoof the reply-to, making it whatever they want - so it never even touches my mail server at all. My inbox gets bombarded because there's no simple way to filter out the bounced messages since they are all so different. It's difficult to track down a spammer normally - and more so when the spam isn't even sent to you. Despite the fact that my address was the reply-to, it seems the spammer never sent me the message directly. I found a bounce message that showed the full headers and tracked it back. The email came from a mail server in the Philippines, and pointed to a website hosted in China, owned by a company in London. Tracking down the actual spammer would likely be close to impossible. Assuming they could be found, suing them would be nearly impossible as well, not to mention costly.

    One potential solution to this would be to require every outgoing email to have a verified identifier of some sort, so that any email can automatically be traced back to the original sender. This (as does every solution) brings up other problems. There are benefits to anonymous email, and we wouldn't want to take that away (though, perhaps you could limit the number of emails that could be sent anonymously to prevent bulkmailers from abusing the system).

    In the end, though, this sort of stunt has killed off the tiniest amount of support I had for spammers. These spammers stand behind their First Amendment rights to speak their minds (which is an argument that can be shot full of holes in a second). In this case, though, the spammer made no use of any First Amendment rights. What they did was just mean and nasty and a complete waste of my time.

    --
    Selling software wont make you money, selling a service will.
  18. Who replies to spam by WIAKywbfatw · · Score: 4, Funny
    I can think of a few. People looking for:
    • Penis emlargements;
    • Viagra;
    • Boob jobs;
    • Sex;
    • Porn;
    • Rebuilt credit;
    • Credit cards;
    • Cheap mortgages;
    • Cheap health insurance;
    • Cheap dental insurance;
    • An easy way to make millions from home with little effort!;
    • University Diplomas;
    • Free anything; and, of course
    • Spam lists.
    Spammers try to sell (gullible) people what they might buy, never what they won't. I've yet to see a spammer selling flights to Mars - although I do predict it will be a growth area for spammers in 20 years time.
    --

    "Accept that some days you are the pigeon, and some days you are the statue." - David Brent, Wernham Hogg
  19. Doesn't protect the ISP or end user by Mustang+Matt · · Score: 2, Insightful

    Sure you can filter it, but you haven't stopped the bandwidth that you paid for from being sucked up.

    --
    The man who trades freedom for security does not deserve nor will he ever receive either. - Benjamin Franklin
  20. Am I missing something? by why-is-it · · Score: 2, Interesting

    Why do we just not modify the mailer daemons to do a forward and reverse DNS lookup whenever another host attempts to send it mail. If the domain the mail originates from does not resolve, or the source IP address of the sender is not registered to the same domain that the mail originates from, the message is considered SPAM and the connection dropped.

    Why wouldn't that work to vastly reduce the amount of SPAM?

    --
    *** Where are we going? And what's with this handbasket?
    1. Re:Am I missing something? by Entrope · · Score: 4, Informative

      That would vastly reduce the amount of USEFUL EMAIL as well. You would not believe what a large fraction of the Internet is configured to fail that kind of test -- or else you would not seriously contemplate that solution. Sometimes there are good reasons to configure a mail server that way.

      DNS is not a terribly useful authentication mechanism for this kind of thing. Much more useful is origin-authenticated SMTP: the originator (either user or mail server) calculates a signed hash of the message, and attaches that when sending it. The receiver can verify that the signature is valid for the person (or mail server) that claimed to originate the message.

      Obviously things lose in the transition period before every sender does that. You also get a huge fight over which algorithms to use, how to distribute and verify the public keys, and so forth. Welcome to Internet politics.

    2. Re:Am I missing something? by robbo · · Score: 2, Insightful

      or the source IP address of the sender is not registered to the same domain that the mail originates from

      Do you mean that the server should ensure the source IP isn't masqueraded, or that the originating domain in the From: header should match the domain of the IP address? In the latter case, refusing mail from mismatched domains would prevent me from using my email address at school when I send mail from home via my ISP. That's an important convenience I wouldn't want to give up, and I suspect that many more people use this feature.

      I do agree with the rev DNS lookups and I think most well-configured SMTP servers already do that.

      --
      So long, and thanks for all the Phish
  21. Everyone call your State Rep! by Mustang+Matt · · Score: 5, Insightful

    I gave Testimony to the Missouri House of Reps on Jan. 29th.

    It's easy to get things in motion, everyone is too lazy to try though.

    --
    The man who trades freedom for security does not deserve nor will he ever receive either. - Benjamin Franklin
    1. Re:Everyone call your State Rep! by scottm52 · · Score: 3, Insightful

      Read your stuff... pretty good, actually. However, your assumption that a "do not call" type list would be unusable is slightly off target.

      It can be done....

      From my post of last Friday Evening...

      "I'm from Missouri "And this version of the proposed law sucks big-time. How about they put a million bucks in a pool, open up 50 or 60 tracking bank accounts, and buy whatever it is the spam is selling.... Thus creating a $$$ trail that can be followed, and a judge can just take and put back into the state coffers. Him em where it hurts... in the pocket!

      Think about this now....

      1) Recieve Spam
      2) Report Spam (forward to spam-abuse somewhere official)
      3) More than X number received complaints, State goes into action.
      4) State dude/dudette actually buys whatever the spam is selling...
      5) state office then traces the $$$, get's a judge to freeze the $$$, apply an ADMINISTRATIVE FINE and keep the spammers frozen $$$ til the fine is paid.
      6) spammer learns to not screw with Missouri if they can help it (tough, but doable).

      Is this easy? No.. Can it be done? Yes, absolutly... If they're gonna write a law, write one that works...
      And yes, I'm chatting with several MO Reps and State Senators about it too.

  22. This is old news for me by jfaughnan · · Score: 4, Interesting
    It's been about two years since I started receiving spam from "myself", or rather some spammer spoofing me. I still get several a day, but mostly they get hung up in my postini filters. I also get several bounce messages a day. For some reason the spammers often use an ancient address in one of my domains that is no longer used.

    Curiously, I almost never get anyone writing to me complaining about the spam. That used to happen, but I think most folks have figured out not to reply. I also don't seem to have been blacklisted anywhere (faughnan.com); the blacklist maintainers are apparently smart enough not to be fooled by spoofed fields.

    Why did they pick me? I think they like to take addresses that are present in the registrar databases. Or maybe they picked me because I complained about spam and write about ways to stop it (not that hard really, we just need to authenticate the sending service rather than the harder task of authenticating the sender).

    In any event, sadly this is old news. Good to know it's starting to make its way into the public consciousness though.

    --
    John Faughnan
    jfaughnan@spamcop.net
  23. Internet growth halted protocol refinement? by robslimo · · Score: 4, Interesting

    Has the rapid growth of the Internet of the last few years caused it to reach the status of an immovable object?

    IPv6, which includes security, ummm, mechanisms that could be utilized to curtail spoofing, some forms of DDOS and net abuses in general, but rolling it out seems too be gracial.

    New RFC's could be authored that extend, modify or replace those upon which our present mail server's are based, but would... could anyone get them pushed through? Or is the Internet infrastructure so massive that any major advances in concept run smack into the issue of interoperability?

  24. and in other news by mark_lybarger · · Score: 3, Insightful

    it's now illegal to provide any false information while using oral communication. specifically related to, but not limited to, false information regarding the name of the communicator.

    spam spam spam. if spam should be illegal, so should any form of unsolicited communication. that includes conversing to persons without their permission at the local pub.

    i'm personally in favor of a more liberated
    government system, but if we want our legislatures to make rules, let's make it a level playing field , not just fix the annoying problem we have of spam (that is created because of a technical deficiency in the overall system of itself).

    1. Re:and in other news by Entrope · · Score: 2, Informative

      Yes .. obviously, being able to talk to millions upon millions of people (at least potentially) is a deficiency in the Internet. The lack of strong cryptographic authentication in a 20 year old protocol is a deficiency in the late Jon Postel's design abilities. Finally, the not-so-commonness of common courtesy is a deficiency in the human species.

      SMTP and email format are both essentially 20 year old protocols. There are two reasons they are still used. First, it is expensive to replace that much software (and sometimes hardware). Second, it basically works. Can you imagine how much less productive the world would be without email being so ubiquitous?

      If you want a level playing field, apply the common rules of postal service to email: The sender must accurately identify themselves. The origin must be labelled (you know, the postmark). Sending huge volumes of mail to harass someone is against the law. Sending huge volumes of mail costs the sender considerably more than the receivers.

      Do not claim that email is exempt from being legislated in ways specific to its new capabilities. It is different than what came before, and deserves to be treated as such.

    2. Re:and in other news by Fluffy+the+Cat · · Score: 4, Insightful

      spam spam spam. if spam should be illegal, so should any form of unsolicited communication. that includes conversing to persons without their permission at the local pub.

      Spam is grossly different to most other forms of unsolicited communication in one simple respect - the total cost to the recipiants is hugely larger than the total cost to the sender. This isn't true of (say) unsolicited email from an individual directly to you, unsolicted junk mail, unsolicited telephone calls or unsolicited personal conversation.

    3. Re:and in other news by FuzzyBad-Mofo · · Score: 2, Insightful

      if spam should be illegal, so should any form of unsolicited communication

      This is not insightful. In the US, you have the right to freedom of speech. You do not have the right to force anyone to listen. Spammers try to force people to listen to them by faking headers, ect.

      To use your pub analogy, you have the right to strike up conversation with anyone you choose. However, persisting when the conversation is clearly not desired by the other party, and going as far as masquerading as someone else to get their attention would be harassment, and possibly stalking.

    4. Re:and in other news by FuzzyBad-Mofo · · Score: 2, Informative

      I think you misunderstood. I just stated how the law currently is, at least in the USA. People have the right to privacy. As stated in the recent NYT article, "Tangled Up in Spam" by James Gleick:

      "Many people who hate spam believe, honorably enough, that it's protected as free speech. It is not. The Supreme Court has made clear that individuals may preserve a threshold of privacy. ''Nothing in the Constitution compels us to listen to or view any unwanted communication, whatever its merit,'' wrote Chief Justice Warren Burger in a 1970 decision. ''We therefore categorically reject the argument that a vendor has a right under the Constitution or otherwise to send unwanted material into the home of another.''"

  25. Re:Report them to the FBI by Anonymous Coward · · Score: 2, Funny

    Yeah, the FBI has nothing better to do than make sure your free Hotmail address is safe. Mulder and Scully will be right over.

  26. Mirror. by vidnet · · Score: 2
  27. Coming next... by Bazman · · Score: 2, Funny

    My Short Life as A Slashdotted Person

    "So I got this story posted on slashdot after that time gigabytes of bandwidth got used up by that fake porn spam address, and so the site got slashdotted and that used up even more bandwidth until my ISP decided to limit my access, so I got another story posted under 'YRO' on slashdot about that and...."

  28. It happened to my wife! by mjh · · Score: 5, Interesting
    This exact same thing happened to my wife. At the time, she had an email address "@iname.com". Someone posted something to alt.bestiality.something or another with the From and reply-to set to her email address. The actual email was talking about what Julia and her little sister liked to do, and encouraged suitors to respond in email.

    Holy crap the email she got! Emails came from people all over the world. An incredibly rare number of them included clothing and were simply introductions. Most of them included an attached nude picture of (I assume) themself (either that or there is a cast of nude pictures of incredibly ugly people floating around somewhere). Some of them demonstrated their sexual experiences with animals. But every single one of them seriously pursuing some sort of sexual relationship with someone that

    1. they had never met
    2. wasn't actually my wife

    This whole experience turned my wife off of the internet for a long time.

    I was able to track down the original post to alt.bestiality.whatever it was, and tracked it to a posting through deja news. (This was about 5 years ago). But ironically, there was nothing in that post that included "go to this website" or anything like that. The only contact information in it was my wife's email address. At the time, I assumed that the person who did this wanted us to change email addresses so he/she could have the one that we had (which was simply my wife's first name@iname.com).

    After tracking it down I sent deja the information and asked them to pursue it. And I changed my wife's email address. We have our own domain now. BUT I still, occasionally login to the iname.com account and empty it. I want that account to stay active forever so that whoever tried this doesn't win.

    What would you do if this happened to you? What are the defenses for this kind of thing? The email that came in wasn't spam. It was real email from real people who had real mailboxes. How do you prevent this kind of thing? So most of the antispam techniques that I know of wouldn't have worked. Additionally, we occasionally get emails w/attachments from friends who want to show us pictures of their kids. So blocking all attachments won't work. What should be done?

    --
    Key to financial independence: Spend less than you earn. Save and invest the difference. Do it for a long time.
    1. Re:It happened to my wife! by Anonymous Coward · · Score: 3, Funny

      That was *your* wife?

      Sorry man. I didn't know.

      You have to admit though, I bet you never expected to see a picture of a guy doing that to to a chicken.

    2. Re:It happened to my wife! by sireasoning · · Score: 3, Informative

      For a situation like this, the best bet may be something like Tagged Message Delivery Agent (TMDA). In essence, it blocks all incoming email first. It has a whitelist (for email from people you know), a blacklist, and a reply form for the unknown.

      In your case, a bestiality enthusiast would reply to your email. Instead of ending up in your email box, the sender would get an email from you confirming that they intended to send you an email (this blocks most unsolicited email since this email would end up at the forged email address), and you could put in an additional warning along the lines that any person replying to a forged post to bestiality.whatever will be turned over to the proper authorities.

      You should then be unencumbered by any other such annoyance.

      TMDA can be found at http://tmda.net/

      --
      The significant problems we face cannot be solved by the same level of thinking that created them. -Albert Einstein
  29. Do Spammers use bounces to prune their databases? by Argyle · · Score: 2, Insightful

    If so, perhaps spamware like SpamAssassin could be modified to intentionally bounce mail?

    --
    nuclear iraq bioweapon encryption cocaine korea terrorist
  30. Flowers.com by The+Turd+Report · · Score: 3, Insightful

    This domain was used by a spammer, they sued and won. http://www.mids.org/mn/803/spamset.html

  31. Most ISPs do though... by Mustang+Matt · · Score: 2, Insightful

    I pay every penny of my T1 cost and we're already looking at jumping to T3 for more bandwidth.

    So just to put things into perspective... Every piece of spam comes through:
    1. Eats a little bandwidth
    2. Eats up a little CPU doing filtering.
    3. Eats up a little bit of CPU doing virus filtering.
    4. Eats up a little bit of disk space.

    Now you say most americans don't pay by the bandwidth, this is true, but they do pay FOR the bandwidth. For instance, all of my customers pay for the shared resources on my server. If one customer gets 50 million pieces of spam in an hour my server has come to a crawl and all of the customers who paid for hosting service are interrupted.

    --
    The man who trades freedom for security does not deserve nor will he ever receive either. - Benjamin Franklin
  32. Replying can help stop spam... by Phoenix · · Score: 4, Interesting

    ...if it's a legit company who has someone who has a person actually reading the replies.

    This is a letter I sent off to a company who offered me ways to enlarge my breasts. Being male and having no desire for hooters I felt obliged to reply.

    ----------

    Do you people simply not bother to see to whom this message is going to? Do you not bother to do market research to see if I'm even going to be able to use the product? I am a man. I have a penis and not breasts. I am a guy, a bloke packing a "willie", a "johnson", "meat and two veg", a "one-eyed trouser snake", a "little fellow", a thingie, the "outy" parts to match up with the "inny" bits of the people to whom you should be sending this spam to and not me and my "Collection of dangly bits".

    To put it simply people..."A DICK"

    I have no interest in your product for the enlargement of breasts and request that you remove me from your list.

    Thank You,
    [name removed]
    BTW: I'm also happy with the size of my naughty bits and request that you not send me information on that product should you offer that as well.

    ----------

    To which I actually got this as a response:

    ----------
    ROFL

    Sir we are deeply sorry that you have recieved this advertisment and we are taking you off our contact list. We thank you for your polite and amusing letter.

    Again sorry for the inconvience
    ----------

    That was in August and to this day I have not seen any messages offering to give me "Huge...tracts of Land" since that date.

    Sometimes it pays to answer a spam

    Phoenix

    --
    -- Wiccan Army, 13th Airborne Division "We will not fly silently into the night"
    1. Re:Replying can help stop spam... by isorox · · Score: 3, Funny

      Do you people simply not bother to see to whom this message is going to? Do you not bother to do market research to see if I'm even going to be able to use the product? I am a man. I have a penis and not breasts. I am a guy, a bloke packing a "willie", a "johnson", "meat and two veg", a "one-eyed trouser snake", a "little fellow", a thingie, the "outy" parts to match up with the "inny" bits of the people to whom you should be sending this spam to and not me and my "Collection of dangly bits".

      To put it simply people..."A DICK"


      You've got balls man...

  33. Happened to my wife by overunderunderdone · · Score: 3, Interesting

    This happened to my wife recently - She was suprised (to say the least) to be getting hundreds of bounces back from a spam.

    If it had been porn I would have looked into the possiblity of filing a defamation of character lawsuit. It was in your case and if it was written in the first person singular ( "come see me nekkid...") and had *you* as the reply-to I'd imagine you'd have an excellent chance of winning such a case - it would certainly be worth talking to a lawyer about.

  34. A novel approach to killing spam. by aglewack · · Score: 2, Interesting

    Here's a possibly novel spam solution.

    Instead of putting the effort of defining spam on the user, put the effort to defining non-spam.
    This could be be done quite easily, maybe in a method that would be "expensive" to spamitize.

    Create an algorithm, similar to sha1, but that can be calculated with any given number of calculations. Perhaps make it easier to decompute than compute.

    So, when sending a mail, attach a CPU cost of lets say 20 seconds. (X number of calculations)

    When your friend receives the mail, he spends 2 seconds checking the calculation (or maybe 20, does it matter?) And then accepts it is probably not spam.

    Thus, a spammer, in order to spam, would need a reallly fast computer! This would cost money, etc. I'm guessing that spammers probably have cheap equipment anyway, so calculating their message tag would be much more time-consuming than an average joe?

    -- What do you think?

  35. You have no right to complain /. by MagicMerlin · · Score: 2, Interesting
    I have an interesting anecdote that is related to this. I am being spammed from the most amazing site: sourceforge (sister site to slashdot). I was running a project on sourceforge and was fiddling around with setting up a mailing list. Somehow, the mailing list software malfunctioned (and continues to malfunction) and does not allow me to log in with administrator rights. Shortly after, that web casino site (you know who it it is) requested access to be able to post to the list.

    Since that time, sourceforge has been spamming me EVERY DAY, asking me to deal with the mailing list request. I am unable to log in and deny the request, even using the mailing list admin password that I am spammed with once a month. Does anybody else see the irony here?

    Merlin

    1. Re:You have no right to complain /. by Carlos+Laviola · · Score: 2, Insightful

      You could actually do something, like filing a request for support at Sourceforge. Their support guys are extremely responsive. You should've done so as soon as you had noticed the problem instead of blaming "sourceforge" as a whole for some technical glitch that was correctable.

  36. Spam Addresses by David_Bloom · · Score: 3, Funny

    Someone needs to register a domain name and make anything@foo.bar automatically forward to UCE@FTC.GOV . That way, when we sign up for sites and such that filter out users who use UCE@FTC.GOV as their email, there will still be a way to prevent junk mail. Also, sites that list randomly generated fake emails to slow down spambots could be made more effective.

    --

    Karma: Excellent (fuck, even in the future moderation doesn't work!)
  37. It's called a "Joe Job" by Rathian · · Score: 5, Interesting

    Sometimes spammers do this just by putting whatever domain in. Other times this is done deliberately as a means of attacking someone.

    The term Joe-Job got it's name originally from Joes.com when a spammer decided to get revenge in this fashion. Information can be found here:

    Spam Attack!

    I can say from having had this done to me, it absolutely sucks. It creates a huge mess that takes weeks to clean up, plus the joy of dealing with people who decide to attack you for something you didn't/would never do. If I were to ever get my hands on those responsible....

    Unfortunately, the problem with tracking down those responsible for this dispicable act is the same one with tracking spammers down in general. It is time consuming, costly and may not yield a desireable result.

    If you want to see more on this, just Google Search for "Joe-Job"

    It is good to bust/report spammers, but when you do, look at the spam and the site being spamvertized. You might have received a joe-job email and by reporting them, you're playing into the spammer's hands.

    If you ever get joe-jobbed, I would say one defense on the web is to change your page to one similar to the "Spam Attack" page I reference above.

  38. Bounces by kooganani · · Score: 2, Informative

    36 hours is about right for receiving bounces. Many messages bounce immediately, mainly the 'user unknown' or 'mailbox full' variety. For errors like 'connection refused' or 'server timed out', the sending mail server will attempts to deliver the message periodically over the course of 36 hours. This period of time is generally configurable can change from mail server to mail server.

    The specifications for bounce messages are extremely loose, and while many mailservers adhere to the definitions, many do not. Most bounces are sent to the 'envelope from' address listed in the header as the 'Return Path:' address, but some go to the header 'To:' or the 'Reply-To:'.

  39. Better than Disneyland? by harlows_monkeys · · Score: 4, Funny
    Q: You've had your email address forged on spam, subjecting your mail server to many many many bounce messages and complaints. What are you going to do now?

    A: I'm going to slashdot my web server!

  40. Killed or Hurt Spammers by PerlPunk · · Score: 3, Funny

    Have there ever been any cases of an e-mail equivalent of "road rage", where someone (or a group) has actually went out and either physically harmed a spammer or killed him?

  41. 3 little words by Proc6 · · Score: 3, Informative
    POP
    BEFORE
    SEND

    Seriously, if your mail server has that, turn it on. It means no one can relay mail through your server, unless their IP has made a successful mail-check. Some mail servers let you "authenticate" by checking to see that the reply-to address is valid on the local server, that, as you can see, does nothing and can be spoofed easily. Pop-before-send is quite a bit stronger and doesnt really require the clients to do anything. No, its not perfect, Im not saying it is, but it will help 99% of the time.

    --

    I'm Rick James with mod points biatch!

    1. Re:3 little words by ahrenritter · · Score: 4, Insightful

      Um.. those are three very pretty all caps words... but they don't have a lot to do with this article. They aren't talking about open-relay abuse here.. During the course of an SMTP transaction, there are two important identifying lines:
      HELO
      and
      MAIL FROM:

      Many SMTP servers will do some sort of verification on the HELO line, but very little can be done about the FROM line. You can't easily kill addresses that don't match the HELO domain because legitimate mail relays would be unable to forward your mail on then.

      I can send you a piece of mail that will display bob.hope@whitehouse.gov as the from address. If Bob had that address, and people replied to the forged address, he'd be getting the blame for my spam.

      It sucks.

      --

      All I wanted was a rock to wind a piece of string around, and I ended up with the biggest ball of twine in Minnesota
    2. Re:3 little words by Fluffy+the+Cat · · Score: 4, Informative

      POP before send is a hack to get around the poor level of authenticated SMTP support in most clients. A correctly configured SMTP sever will only relay for clients with IP addresses in the local network - authenticated SMTP or POP before send allow people who aren't on the local network to relay mail through the SMTP server. This has very little to do with spam - POP before send just allows you to do something that wouldn't otherwise be possible without running an open relay. How on earth would it prevent someone from forging somebody else's email address? There's no way to pass that authentication information to remote machines, and POP before send generally allows you to use arbitrary email addresses once you've authenticated.

  42. This happened to me... Here's what I did... by cjustus · · Score: 4, Interesting
    This doesn't sound so bad to someone, until it really happens... I began receiving a couple hundred bounced messages an hour, and a few "please don't spam me any more" messages... Just what I wanted - to be known as a porn spammer...

    I tried to find where they were coming from, some of the bounces were more informative than others... The originating IP ended up being someone(intentionally or unintentionally) running an SMTP proxy server... And the IP was out in the middle of nowhere... (Came back to a B-class set of addresses... Not much help in tracking down a network admin...)

    Some of the bounces had the actual message... Which were linking people to a site which in turn asked them to buy something (saying that their order page was secure when it wasn't)... I tracked down who had registered the domain (the admin and billing contacts...) addresses ended up being in China (domain was cnmailads.com)... Sent email, no response... I set up procmail to redirect the hundreds of bounces to them, plus I had some simple spam filters, and redirected all of my spam to them as well...

    The order page contained a form that had an email address for where the orders were really going... I made my own personal copy of the form, and began sending megs of data through... Entering bogus info to corrupt any real entries (who would order this crap over the Net from a website in China??? Who knows...) Email address was a yahoo account, which it didn't take long for me to fill it up... All added the yahoo address to my procmail redirector as well...

    I went to a couple of spammy sites (cooldeals.com or something like that)... Signed them up to receive all sorts of valuable emails... Signed them up for some mailing lists too... Easy to sign up, and pain to get off of...

    It had been going on for about a week before I started this, and stopped after about 2 days... Checked back to the link that was sent and the site was gone... Probably moving on to the next sucker email address and site...

  43. What the Internet REALLY DOESN'T needs by Anonymous Coward · · Score: 2, Informative

    >What the Internet needs: A proprietary mail protocol by a major power (MS?) to eliminate IP address/e-mail address spoofing.

    Yeah right. The last thing I want is to need a Microsoft client to read my email just because "somehow" their new proprietary protocol isn't compatible with their own specifications...

    I'd rather keep on deleting that useless spam for now (if ONLY spam was targeted... Give me MP3 players offers, web hosting offers, etc... I can find my pr0n myself, thank you).

  44. One result: more SPAM. (Can you say "DOS"?) by frostfreek · · Score: 3, Informative

    I had this happen to me. It was "www securedrugs net" I thought for a while of using some recent attack as revenge, such as the anonymous UDP Gamespy DOS attack, to take down the perp's website for a few weeks. However, I don't really have the time or experience for this sort of thing. If anyone else feels like it, Go right ahead! Now that this has happened, my inbox has seen a doubling of spam. From a Yahoo account, it is not so easy to filter this stuff. Soon I may very well have to pay for Yahoo mail, to get better filtering. Perhaps some of these recipients have signed me up for more? J

  45. For those who cannt access the site by Neophytus · · Score: 4, Informative

    I mirrored it. Read away.

  46. er, get a better email client by DrSkwid · · Score: 3, Informative

    Even Outlook Express sets any From: you want

    --
    There are places where the networks are not touching,and there are places where they are-Boeing's Lori Gunter
    1. Re:er, get a better email client by zcat_NZ · · Score: 2, Interesting

      The mail client has no idea what From (envelope address) or From: (Header address) are supposed to be until someone configures it. Changing it to something else is utterly trivial.

      Almost the only thing you can't change is the Recieved-By: headers. All the ones from your own mailer to the open relay (usually just two hops) will be correct, and even when spammers add their own fake ones it's trivial to follow the chain back to where it 'breaks'.. The spammer's real IP address is usually the first (from the bottom) IP in the chain that doesn't answer an SMTP connection, and usually it's also the first one where the hostname and IP don't match.

      --
      455fe10422ca29c4933f95052b792ab2
  47. This is a result of broken mail servers by Gunzour · · Score: 3, Informative

    If an email bounces, the bounce is supposed to go back to the sender, not to the Reply-to: address. (I believe this is in RFC 2821) It's amazing how many commercial mail servers out there use Reply-to: to send postmaster notifications.

  48. Have you read Peter Watts book Starfish? by hpulley · · Score: 2, Informative

    In Starfish by Peter Watts, some of the book is centered around genetically programmed pseudo-AIs used to patrol the net for spam, virii, worms, etc. I won't say more as it might spoil the book for you but read it and I'm sure you'll enjoy it! What you said in your message has something to do with it ;-)

    --
    $#!^ happens, but why does it always have to happen to me???
  49. More and more of this stuff: by rerunn · · Score: 3, Informative

    Spammers have been resorting to guessing email addys now. This isnt new but I've just started seeing more and more of this shit lately:

    Feb 12 13:39:27 warthog sendmail[21909]: h1CIdQK21909: <dclark@mydomain.com>... User unknown
    Feb 12 13:39:27 warthog sendmail[21909]: h1CIdQK21909: <paladin@mydomain.com>... User unknown
    Feb 12 13:39:27 warthog sendmail[21909]: h1CIdQK21909: <mbrown@mydomain.com>... User unknown
    Feb 12 13:39:27 warthog sendmail[21909]: h1CIdQK21909: <viper@mydomain.com>... User unknown
    Feb 12 13:39:27 warthog sendmail[21909]: h1CIdQK21909: <kelley@mydomain.com>... User unknown
    Feb 12 13:39:27 warthog sendmail[21909]: h1CIdQK21909: <rbrown@mydomain.com>... User unknown
    Feb 12 13:39:28 warthog sendmail[21909]: h1CIdQK21909: from=<joe@nowhere.com>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA, relay=[200.162.240.168]

    I tried to post all 65 attempts in this batch but the damn lameness filter said:
    "Your comment violated the "postercomment" compression filter. Try less whitespace and/or less repetition. Comment aborted"

    Nonetheless you get the picture.

  50. New Mail System by macboy2k3 · · Score: 3, Informative

    It seems to me that as long as we have no authentication method for sending e-mail and verifying where it is coming from we will continue to have problems with SPAM. Most mail servers will believe whatever you tell them; this has got to stop. The Reply-To and From fields need to be set on the mail server. Users should also log in to send mail from their smtp server and you should be able to use the same smtp server from anywhere instead of just within its domain. There are other details involved in verifying the smtp server when receiving mail to prevent people from using their own sendmail in an inapropriate manner. This can be solved techinically; especially if there was one global e-mail database but we all know how much everyone wants a global database of anything; let alone e-mail to ID.

  51. Most users too clueless... by ackthpt · · Score: 3, Funny
    Most users are too clueless to realize it's really not coming from that address.

    I've given up on most of it. The best way to figure out where junk is coming from is to just view the contents as ASCII, which The Bat does very nicely. (Show kludges shows headers) Most of the time there's a phone number or website and doing a whois on many will reveal the villain.

    There are urls which are use just the IP address and those which look like HTTP://434328432849, the number being an IP address, not in the form 127.0.0.1, but the sum of 1+0*2^8+0*2^16+127*2^24, a neat way of masking sites.

    Other news... I was just checkin a website I've had for 4+ years and never checked the mailbox that came with it. It filled up Mar 23, 2002 and has 1,669 pieces of mail, mostly spam. Looks like I'll be cleaning it out on Saturday. It would be an interesting project to archive it all and see how many violate California's anti-spam law and see if I can Make $$$$ At Home!

    --

    A feeling of having made the same mistake before: Deja Foobar
    1. Re:Most users too clueless... by dead+sun · · Score: 3, Interesting

      Fun reply to your last bit, I've got an Earthlink DSL account, which comes with an email address that I've had for about 2.5 years now. I've never used the thing to send mail ever. I had to log in to it to get something from Earthlink a while back, to find about 8 MB of spam on an account that has never been posted anywhere, never been used to send email, never known by anybody but Earthlink and myself, and my username isn't so common that people should be just guessing to send email there, at least not 8 MB of spam much.

      I figure it isn't my space so I'll let Earthlink deal with it. They're probably the ones who sold me out in the first place.

      --
      If not now, when?
    2. Re:Most users too clueless... by soulcutter · · Score: 2

      Just a thought, but if you use the same username for an email address on a different domain (like if you have gyurbhhr44ty@earthlink.net and gyurbhhr44ty@yahoo.com), and have posted THAT email address anywhere (in this case the yahoo one), then many spammers are clever enough to send email to that same username on as many domains as they can think of with the theory that people tend to reuse usernames.

      Just one possible (and plausible) explanation *shrug*. I find that far more likely than your ISP sharing your email address without regard to your wishes, but then I'm constantly surprised by how shady businesses can be sometimes. Mostly I would like to assume that spam is a nuisance to ISPs just as much as customers, though, since it's such a gigantic waste of bandwidth and storage space.

      On a side note, gyurbhhr44ty will probably be recieving spam now (heh!).

      -Sou|cuttr

      --
      Old programmers don't die, they're just cast into a void
  52. No, not Skynet; Nomad by karlandtanya · · Score: 2, Insightful

    Now, all we have to do is get the super spamfilter to think that all the reply-to addresses are JacksonRoyKirk@ufp.mil

    --
    "Reality is that which, when you stop believing in it, doesn't go away." - Philip K. Dick
  53. Operate an 'ANTI' website and see what happens by Slaveway · · Score: 3, Interesting

    I have had to deal with this same problem off and on.
    Someone who does not like the idea of my operation of a website critical
    of our company forges e-mails with my E-mail Address.
    Instead of porn or spam this person includes Virus files.
    Same said person also sends me 2 or 3 Klez infected e-mails everyday.

    --

    http://www.Slaveway.com
  54. since they have a threshold by commodoresloat · · Score: 4, Funny

    only break $5000 worth of his bones. then you won't be worth investigating either.

  55. You Don't Like The Mail Admin, Do You? by Myriad · · Score: 4, Funny
    Our domain is productive.com so any email to whatever (at) productive.com comes back to the admin email accounts. As you can probably guess there's quite a few spammers that use productive.com as reply-to.

    Given that you just entered the domain name not once, but twice, and your post is likely to be seen my thousands, spidered, and google-cached, I take it that you don't like your mail admin very much, do you?

    --
    "They do not preach that their god will rouse them, a little before the Nuts work loose." Kipling, 'The Sons of Martha'
  56. not just the internet.... by commodoresloat · · Score: 2, Funny
    This whole experience turned my wife off of the internet for a long time.

    I bet she wasn't much into sex with animals for a while after that too.

  57. State laws? by MacAndrew · · Score: 2, Insightful

    The FBI routinely sets a high threshold before it will get involved, and it sounds unfair until you consider they are *tiny* compared to local law enforcement. Similarly, the entire federal judiciary has fewer judges than California.

    Did you look at state law remedies, call the attorney general, that sort of thing? I'm not faulting you if you didn't, I'm just ignornant of whether there a meaningful alternatives.

    You could have sued the guy personally in small claims, although the dollar value was low. But there's nothing wrong with a little spite. :)

  58. Depends on Which Version of Outlook by Carnage4Life · · Score: 4, Informative

    Service Pack 1 of Office XP (which contains Outlook 2002) adds a feature for disabling HTML mail which is described in Microsoft KB Article # 307594 . Users of previous versions of Outlook can use the macros provided here

  59. IQ Test by nuggz · · Score: 3, Funny

    Press CTRL-ALT-DEL now for an IQ test.

    1. Re:IQ Test by shepd · · Score: 5, Funny

      Which button is it???~!?//!?11

      LOCK WORKSTATION, logout, shutDown, _Change Password, TaSK L1st, or Cncel?

      I MUST KNWO! Give me answer! Pleez! NOW! Right NOW! PLEAEEHZ! PLEEZ!

      --
      If you could be told what you can see or read, then it follows that you could be told what to say or think - BoC
    2. Re:IQ Test by Anonymous Coward · · Score: 5, Funny

      Duh. It's a trick question.

      The *real* IQ test button is hidden on the back of your computer near the power cord.

    3. Re:IQ Test by schon · · Score: 5, Funny

      Press CTRL-ALT-DEL now for an IQ test.

      Reminds me of my days as a BBS sysop..

      My board forced registration before you could post anything - in the registration sign-up (before it asked for any information) I had it say "Press any key to begin. If you don't know which key is the 'any key, it's the large one on the front of your computer labeled 'reset'

      Over the course of the 3 years I had it running, the logs showed two people drop carrier immediately after reading that.

    4. Re:IQ Test by gidds · · Score: 4, Insightful
      LOL!

      I've never understood why people don't put "Press a key" instead. The intelligence-challenged can search out the `a' key, which will work, and the rest of us will know that all the others'll work too. Plus it's two characters shorter -- benefits all round!

      --

      Ceterum censeo subscriptionem esse delendam.

    5. Re:IQ Test by Bastian · · Score: 2, Insightful

      There's a huge difference between can and should.

      Anyone can use a computer.

      Some people shouldn't.

    6. Re:IQ Test by rwise2112 · · Score: 2, Funny

      Check out this User Friendly RE: any key.

      This one cracked me up.

      --

      "For every expert, there is an equal and opposite expert"
    7. Re:IQ Test by nytes · · Score: 2, Funny

      Simple - the first thing you'd get is a bunch of calls to tech support complaining "I pressed the 'B' key and the program went ahead and did it anyway!"

      --
      -- I have monkeys in my pants.
  60. Re:Doing this in procmail by greed · · Score: 3, Informative
    Any idea how to reject messages that have bogus domains in the Received: headers?

    You're going to have trouble with any mail that passes through non-routable hosts inside a firewall. All my mail will have something like "Received: ... by gateway.localdomain (10.0.0.1)".

    It will be even worse for mail that travels though something other than SMTP for a bit.

  61. My personal experience with the "joe job" tactic by mojotooth · · Score: 3, Insightful

    I was the target of a joe-job since last April. A spammer advertising a Human Growth Hormone website based in China was sending out tens of thousands of spams over a long period, with my long-held email addy in the From: address.

    The vast majority of the mails you get back are administrative emails saying that "the user does not exist." There is also a small amount that you get that are ill-informed, ignorant, and often very inflamed responses from people who respond.

    At the peak of the attack, I got over 14,000 emails in a single day. It almost caused me to have to give up my email address, which I had held for almost seven years at the time. I didn't want to give it up so easily.

    My solution was to install and use the Tagged Message Delivery Agent (http://www.tmda.net), which is a whitelisting service. It has my admiration for rejecting 100% of the unwanted emails for two reasons. First administrative accounts don't reply to their whitelisting requests, and second, ignorant angry users don't bother to reply to get whitelisted anyways.

    As for the question of why someone would do this, I have thought of three reasons:

    - To make their spam look more legitimate.
    - Just to cause general havoc
    - Because I have, in the past, not hesitated to complain to service providers about spam. This was probably retribution.

    I did attempt to bring some form of legal action into the fray. I talked informally to Scott Frewing, a US attorney (one of the prime players in the Skylarov case), about the attack. He referred me to the FBI's online fraud folks, but couldn't really give me much encouragement on the chance of the success, since the spammer's website was located in the China Telecom domain, although the company it claimed to represent was in New Jersey. In fact, he told me I would probably be better off pursuing the case strictly on the basis of fraud and possible identity theft (the use of my email address) rather than as a spam case.

    I stopped pursuing it after talking to Frewing.

    In any event, I have won the battle in the sense that I will never see the unwanted mails. But I have lost the war in the sense that I can't really make the F*CKER stop doing it, and it does consume resources on my linux box.

    --
    -- Mojo Tooth : exploring our world as only an idiot can.
  62. Spam or DDOS? by Xenna · · Score: 2, Insightful

    I had a different but similarly disturbing experience recently. A domain I host has the same name as a fairly large ISP in a neighbouring country (just the tld is different). A spammer started sending floods of messages with made up rcpt (aaa@domain, aab@domain, etc) addresses to it.

    The sender address was a similar auto-generated hotmail address. When I found out what was going on (on a sunday night) because the sysload went up, my mailqueue contained over 50000 undeliverable messages.

    I blocked the sending address with an ip table rule and mailed the Irish ISP. The next morning the connection attempts were still bouncing of my firewall and the ISP never replied.

    These guys are beginning to do more and more damage...

    Xenna

  63. Happened to my Sweetie Two Weeks Ago by ewhac · · Score: 3, Interesting

    My sweetie got Joe-Jobbed a couple of weeks ago. 20K bounces over the course of the day. Thankfully, the payload of the spam was only two lines of text, containing a URL to a (non-existent) pr0n site. So the bounce messages were comparatively short. A cursory look at the headers in the bounces suggested that the attacker -- 'spammer' is too genteel a term for this -- was using a constellation of open relays to spread the stuff.

    She came into my office, saying, "Make it stop!" Sadly, there turns out to be little one can do to stop it. The emails were coming from thousands of different legitimate sites, all serving a legitimate bounce to an illegitimate spam. It was very distressing for her. Fortunately, the attack stopped, and things settled down after about 24 hours.

    I wrote up the experience on Kuro5hin. Feel free to have a look.

    Schwab

  64. Happened to me by joncombe · · Score: 3, Interesting

    I had the UK national radio station Classic FM hijack my domain and use it to send a Valentines day spam message (this was last year). Again, the only way I found out was when all the spam came bouncing back to me. I wrote to the MD of the station, and did get a personal reply, apologising and claiming their web developer had made a "mistake". I asked for compensation and didn't get it though. I also got plenty of out of office auto replies, plenty with name, addresses and telephone numbers. The biggest number of bouncing emails came from Hotmail, Yahoo and Lycos. The thing I found most upsetting was the possibility of having my email blocked by companies or people that got this spam or having my net connection closed because of spam reports.

  65. Unfortunately, posting to /. can generate spam.... by droopus · · Score: 5, Interesting

    Two stories, one related to /.

    I submitted an article to /. last weekend about the Simpsons cast on Bravo. To my utter shock, it was accepted and posted. I stupidly put my very private email (the one that didn't ever get spam) in the Email field. I know, I know...

    Less than two hours later, I started getting weird email, complete with .zip.pir attachments, and a few with blatant Trojans. Luckily, I'm OSX so they had no effect, but I was amazed how quickly the email hoovering app grabbed that email addy. They seemed more malicious than sales oriented.

    I haven't received any today at that address but I'm still kicking myself. Moral: spammers hoover slashdot, so don't post your email here, ever.

    Story two: For almost five years I had the email bruce@altavista.net. In November, I got mail from Mail.com stating that the Altavista.net domain was being closed down and they were replacing my long-used address to something like bruce@way-cool-dude.com. Um, no thanks I said, I use this account for business and that doesn't work for me.

    Ok, they said, how about we reactivate bruce@mail.com and you can have that? "Hmm, neat addy, easy to remember," so I agreed. They activated it on a Monday night.

    Tuesday morning I woke up to more than 400 mails. Maybe 20% were typical Hotmail "make your penis so big you need a hose reel" spams but a full 80% were Joe jobs: spammers who had used that address as a reply-to. I knew I was going to shut it down but I watched it for three days just to see.

    Total Joe job spams, almost four thousand (in three days) before I had them cut the damn thing off. Said fuck it, and bought a domain for business mail, and ended that adventure.

    Someone oughta make a law.....

    --
    "The pie shall be cut in half and each man shall receive.....death. I'll eat the pie."
  66. It's about ADVERTISING by rdmiller3 · · Score: 2, Interesting
    The author of the article appears to have missed the point. His address was used as a return address because the spammer did not care about any e-mailed responses. The spammer never expected (and probably didn't want) to receive any response in the normal "reply" sense.

    The message almost certainly contained some sort of serial-numbered link to the spammer's web site. That way if your serial number shows up in their web server's log, they know that you've opened their message.

    Doesn't sound like a big win for them... until you know that advertising is big business. By proving that you opened the message, they can claim that their spam will make one more "impression". Initially, they'll want to do a little profiling because audiences "targeted" by interest areas can be sold for higher rates, something like [US]$10 per 1000 impressions in general and up around [US]$20 or more for 1000 targeted impressions.

    Once you've opened one of those dumb spams with a mail client that will load images from HTML IMG tags, you become part of the "audience" which that spammer can sell to advertising clients.

    And by the way... five hundred e-mails is nothing compared to the number of hits the spammer probably got back.

  67. New Mail RFC by Ayanami+Rei · · Score: 5, Informative

    You mean like this?

    RFC 2487: SMTP Service Extension for Secure SMTP over TLS.

    SMTP [RFC-821] servers and clients normally communicate in the clear over the Internet.... Further, there is often a desire for two SMTP agents to be able to authenticate each others' identities. For example, a secure SMTP server might only allow communications from other SMTP agents it knows, or it might act differently for messages received from an agent it knows than from one it doesn't know.

    --
    THIS THING CAN TURN ON A DIME, MACROSSZERO STYLE ALSO FUCK BETA, ~NYORON
  68. My 2 cents. by dasMeanYogurt · · Score: 2, Interesting
    I'm surprised no one has mentioned RFC 2505: Anti-Spam Recommendations for SMTP MTAs: http://www.faqs.org/rfcs/rfc2505.html

    ISPs and mail providers following these recommendations can prevent most illegitimate spam(forged headers, open relays), and completely prevent what happened here. Unfortunately, large providers cannot follow these recommendations, due to the large volume of legitimate mail that gets blocked from systems with ignorant admins. The former ISP I worked for decided to implement some of the measures in RFC 2505 and began verifying PTR records (reverse DNS)....I never had to take so many calls from pissed customers not recieving their mail. I was threatened by an admin US Department of Education, who, in a most impolite fashion told me to fix our problem(we don't need no stinkin PTR records).....not to mention the University of Texas, Texaco, and so on. Soon the ISP relented, the spam came flooding back in and we were back where we started. I don't see the need for a new system.....just better admins.

    --
    --Gentoo Baby!
  69. It happened to me too, but I got a little revenge. by antigone · · Score: 3, Funny

    in the last 4 days my yahoo account (which i've had for years and don't want to have to change) has used its' 6mb quota up 17 times because of all of the undeliverables i'm getting back from this spam I didn't send. I volunteer for a Forensics K9 Search group and I get emergency call-outs sent to this address, so my mailbox filling up and bouncing messages is a very very very bad thing. (side note: this week NASA contacted us saying that if they needed to call in groups from outside CA and TX we were next on the list to be brought in!) This morning was the last straw..i got over 1000 bounces again and I decided to take a closer look at the SPAMMERs site. It turns out they have a crappy verisign shopping cart that does not, in fact, verify credit card numbers beforehand. So i submitted the form about 1000 times before i got sick of it. If you'd like to have a laugh, or to help me get revenge, then click the link below to see a screenshot of their website with the info i filled in the form, as well as the URL to the SPAMMER's page...

    This is NOT the spammer's page, just a link to a screenshot of their page with the URL included

    --
    "Leave no authority existing which does not answer to the people" --Thomas Jefferson
  70. next attack by Trailer+Trash · · Score: 2, Funny

    Mike Masnick wrote up his experience getting slammed by a somewhat new kind of spam attack that doesn't get much hype

    Now he gets to write about a somewhat old type of DOS attack known as "getting slashdotted". Actually, his site seems to be holding up well.

    MDC

  71. Spam Radio by seekohler · · Score: 2, Funny

    He could always bounce some of the more humorus replies to Spam Radio for everyone to enjoy.

  72. How to easily avoid this kind of problems by SysKoll · · Score: 2, Informative
    Sending a spam with a fake return address is called a Joe Job in anti-spam circles (see the posts above). This is why you should never, ever reply to a spam. A reply will either enrich the database of the spammer (if the Reply-To address is genuine) or will annoy an innocent user. Spammers don't read replies.

    The only effective countermeasure I found was to use SpamGourmet. It's a web site that allows you to define disposable addresses forwarded to your real (secret) address. The disposable addresses can be disabled. They automatically shutdown after 20 messages from unknown senders (not in your whitelist). So, a Joe Job would generate, at most, 20 replies into your forwarded mailbox. After that, you'd have to re-enable the disposable email, although you'd rather leave it disabled because it WILL be spammed again.

    -- SysKoll
    --

    --
    Mad science! Robots! Underwear! Cute girls! Full comic online! http://www.girlgeniusonline.com/

  73. This happens too frequently by Necronomicant · · Score: 2, Informative

    In the course of day to day work (I do helpdesk work at a company that contracts out to multiple ISPs) I've frequently run across this situation in the past two or three months. It's not terribly common *yet* but it seems to be happening with much more frequency. One individual that I spoke with was receiving about 50 emails an hour, and, whilst out of town for 3 days, received 350 - 400 emails. All of these were bounced.

    My solution has always been to renamed the account and cancel the forwarding from the old name to the new one. Seems to do the trick. I wonder what happens to the bounced emails then.. :)

  74. Reverse spam by gomoX · · Score: 2, Interesting

    I send email to myself to check how GPG works on different MUA's, if they can check signs etc
    By now i got the conclusion that Sylpheed and Evolution dont sign the same way.
    Whatever, its useful

    --
    My english is sow-sow. Sowhat?
  75. This happened to my girlfriend too by forkboy · · Score: 4, Interesting

    My girlfriend started getting a ton of bounced emails and not being a techie type person, asked me what the hell was going on...turns out the same thing happened to her as happened to the writer of that article: A spammer was mass mailing, in this case, penis enlargement pills, and setting her address as the reply-to.

    Instead of writing a witty retort on a website though, I took care of it the way everyone else should from now on: (READ THIS) I looked up the registration info on the website that was being advertised in the spam....luckily it was a US registrant.

    I then immediately called the technical contact listed for that company. After a few tries, I managed to get him to answer the phone. I told him politely but firmly that whomever he had hired to advertise his website/product was using questionably legal and certainly unethical tactics to do so and was making a lot more enemies than customers. He seemed genuinely upset that this was going on and gladly gave up the name, address, email address, and telephone number of the spam-mercenary he had hired. I called the spammer and left a voice mail telling him I hope he didn't really enjoy his email address or phone number a whole lot and proceeded to sign up for any and every mass marketing, porn, magazine subscription, and telemarketing form I could find.

    Sometimes the operator of the website is the one doing the spamming, and if this were the case I would have chewed him a new one when I talked to him. Either way, you'll get a pretty good idea of where the spam is coming from if you just call the webmaster for the advertised site. I've been saying for years that this is how they need to enforce spam legislation....bring charges against the website operator rather than trying to track down the spammer. No customers to spam for, the spammers will dry up and blow away. Legally, it makes sense...if you hire someone to kill a person for you, you're legally culpable...so hiring someone to spam for you should get you into trouble as well. Make the first offense a "warning" in case they hired a marketing company and didn't know they were spammers. A slap on the wrist and warnings of heavy fines for future infractions will most certainly make them choose more wisely when picking a marketing company.

    --
    This message brought to you by the Council of People Who Are Sick of Seeing More People.