Slashdot Mirror


Following the Spam Trail

An anonymous reader writes "MSNBC's Bob Sullivan doggedly follows a spam trail from Alabama to Argentina to find out who actually benefits from spam. The beneficiaries aren't necessarily the pasty faced, high school drop out industrial spammers we have gotten to know, but well known companies."

13 of 232 comments (clear)

  1. Pick up the phone. by pontifier · · Score: 5, Informative

    If you can nail down a domain that seems to profit, use the whois information and call them on the phone. I usually dont get spam after I have complained to a person. If the phone number is bogus you can report them at http://reports.internic.net/cgi/rpt_whois/rpt.cgi

    --
    -John Fenley
    1. Re:Pick up the phone. by Yanna · · Score: 4, Informative

      Notice how the guy that spams is in Argentina. First, I do not think that your calls will bother him more than they will cost you. Second, this guy is a real mercenary. This is his way of life.

      I ran a little query and found that he actually registers his domains under the following address:

      Entidad Registrante: Zonda Sistemas S.A.
      Direccion: Callao 1253
      Ciudad: Buenos Aires
      Codigo Postal: 1024
      Pais: Argentina
      Telefono: 4803-3824
      Fax: 4803-3824
      Actividad Principal: Sistemas

      Persona Responsable: Alberto Roberto Meyer
      Direccion: Callao 1253
      Ciudad: Buenos Aires
      Codigo Postal: 1024
      Pais: Argentina
      Telefono: 4803-3824
      Horarios Contacto: 10-18

      Fecha de registracion: 20/01/2003
      Entidad Administradora: Zonda Sistemas S.A.
      Direccion: Callao 1253
      Ciudad: Buenos Aires
      Codigo Postal: 1024
      Pais: Argentina
      Telefono: 4803-3824
      Fax: 4803-3824
      Actividad Principal: Sistemas

      Contacto Tecnico: Alberto Roberto Meyer
      Direccion: Callao 1253
      Ciudad: Buenos Aires
      Codigo Postal: 1024
      Pais: Argentina
      Telefono: 4803-3824
      Horario Contacto: 10-18
      Fax: 4803-3824

      Servidores de Nombre de Dominio
      Servidor de Nombres Primario:
      Nombre: ns.super-zonda.com
      Direccion ip:

      Servidor de Nombres Secundario:
      Nombre: ns1.super-zonda.com
      Direccion ip:

      Tercer Servidor de Nombres:
      Nombre: ns2.super-zonda.com
      Direccion ip:

      Cuarto Servidor de Nombres:
      Nombre: ns3.super-zonda.com
      Direccion ip:

      Sorry that it is in Spanish, but the only way to find this guy is by running queries in nic.ar. Were you in a position where you could actually phone this criminals, you need to add +54 11 to the listed telephone numbers (54 being the country code for Argentina and 11 the city code for Buenos Aires).

      Good luck!

    2. Re:Pick up the phone. by notfancy · · Score: 5, Informative

      Don't bother calling. The number is disconnected. I just called (I'm in BA, so it's local) and the earnest recorded-message lady informed me of the fact.

      I pity the poor soul that gets assigned that number.

  2. From a related link. by spumoni_fettuccini · · Score: 3, Informative
    The spam damSpam isn't that big a problem. A noisy, wired minority, the report said, has overexaggerated the spam jam-up. In fact, only 15 percent of workers surveyed say they have to deal with more than 50 e-mails a day. And nearly three-quarters said "only a little" of their work e-mail is spam.

    How many Sysadmins are running spam filters to catch that crap so the end user never sees it?

    --
    -- Some days you're the dog; some days you're the hydrant.
  3. ISP connections by abhisarda · · Score: 2, Informative
    "ISPS MAKE MONEY, TOO
    An entirely separate set of companies also benefits from the spam economy -- Internet service providers who carry their traffic... In exchange, the ISP agrees to suffer more than normal complaint rates. In PSINet's contract, revealed on News.com, the firm received an upfront payment of $27,000 from Cajunnet, a marketing firm based in Slidell, La. In exchange, PSINet agreed to permit Cajunnet to send unsolicited email "in mass quantity" through PSINet's lines."

    Maybe this might drum some sense into somethingawful.com's heads.

    I made a comment 2 days earlier about this. If you do business with ISP's that work hand in glove with spammers, don't go around whining that SPEWS is the one to blame.
  4. No spam no spam by Brian+Kendig · · Score: 4, Informative

    I don't see what the problem is. I don't get spam any more.

    Now, granted, I run my own mail server: Exim, attached to SpamAssassin via SA-Exim. And this combination is highly effective. I have it set up to be more aggressive than most people would want their spam filter to be; if an incoming message even *smells* like spam, my server refuses to accept it and instead gives a failure message with an alternate non-filtered address to use if the email wasn't actually spam. In a year of running it, it's rejected 100 spams per day on average, with only one known false positive in the entire year (it was someone forwarding a spam to me). And if a spam is sent to one of the addresses which I haven't used for years, then I perform the added courtesy of tarpitting the spammer.

    But there are a lot of tactics that an ISP's mail server can use to cut down on a huge amount of spam without risking false positives. Check the mail against Razor and the other services which keep track of mass-mailings which have been reported as spam, for example. Refuse mail from a server which pipelines its SMTP commands then drops its connection without waiting for a response. Verify that the sending mail server's address actually can be resolved.

    ISP's could go a long way towards making spam much less of an annoyance if they'd just use software to filter out the obvious spams. Hook the mail server up to SpamAssassin, set the threshold high enough to avoid false positives.

    1. Re:No spam no spam by big-magic · · Score: 2, Informative

      Most service providers that have anti-spam software will allow you to turn it off.

      But I think the real advance will come when service providers give individualized Bayesian filter to each customer. That way, each customer can decide what is spam to them. Of course, that's a lot of data to keep track of when you have a lot of customers. But I think it is doable. The downside is that during the training process, the customer would need to use a web based client rather than your IMAP/POP client in order to mark messages as spam. But once they are satisfied with the training, they could use their regular mail client.

      And when a customer is happy with their filter setup and "turn it on" so that the system will delete spam directed at them, the inbound mail server could do the spam check in real time and refuse to accept such spam. I know it sounds like a lot of processing, but I think it's possible.

  5. Re:fighting back by rediguana · · Score: 4, Informative

    Ah that will pale into insignificance when compared to the aging of the customer data already in the db. I did a Certificate in Direct Marketing (never used it in the end) 4-5 years ago, it was quite interesting. One of the points we were taught by our national DMA was that in a given year, approximately 25% of the customer records in a database will become outdated - I'm sure it is even higher in Internet time. The relevance to spammers is that they must continually be creating new databases to guard against obselete customer data.

  6. Re:SPEWS and SomethingAwful by LordKaT · · Score: 2, Informative
    Hasn't this been played TO DEATH on fark?

    Oh well, I'll bite.

    1. SPEWS doesn't block anyone. The ISP's do.
    2. SPEWS only adds one IP. When the spam-friendly ISP/Host changes the spammers IP, the block of IPs gets larger.
    3. SomethingAwefuls visitors are not exactly the ... brightest ... people on the planet. You're not going to get into a debate so much as an argument.
    4. SA and it's members often encourage one another to flood the mentioned websites with crap, pages of text, and a general amount of spamming.
    5. While I do sense a bit of sarcasam and a bit of "we're never really going to win this fight" in the article, SA has two options: either get a new host, or get a seperate IP address for their mail server.
    6. The article goes on and on into what seems to be perpetual whining. If he had at least attempted to talk with his host about the situation, rather than bitch and moan, and encourage the readers to flood the newsgroup.
    7. 4 TB a month? I call bullshit.
    8. If they're not making enough money to get on a different host, then they really need to review their course of action.

    I don't agree with using SPEWS, as I think it's too drastic, but SPEWS has a right to exist. I should also point out that there is no case of slander/libel as SPEWS keeps evidence. As for staying totally anonymous, they don't want to be spammed, theatened, or be litigated into oblivion. Also, Seeing as how it's the ISP's bandwidth, the ISP's have the right to use, opr ignore SPEWS. Yes, places like SA get caught in the middle, but, honestly, if it's just places like SA, I really don't want them. They're, quite frankly, just childish.

    Also, this is a case of consumer ignorance. If a customer does not know they their ISP uses SPEWS, then it's their own damn fault.

    When all else fails, use Hotmail, or setup your own mail server.

    --LordKaT

  7. Re: Sort of by justMichael · · Score: 2, Informative

    You see, most of that stuff stuff is made in sunny Southern California... Swedish Erotica (A.K.A. Cal Exotics) is in Chino CA.

  8. Incredible Market Efficiency by tabdelgawad · · Score: 3, Informative

    "Four days later, four companies sent us an e-mail indicating they knew we were looking for a new mortgage". Four days!! With the myriad layers of 'affiliates', 'lead generators', and 'spammers' operating in legally grey areas and distributed all over the world, it's amazing that it takes only this long to get a response. I mean, sometimes it takes longer to get a response from legitimate online tech support!

    The article opens by saying "There wouldn't be spam if there wasn't money in spam". Truer words were never uttered. And there wouldn't be money in spam if consumer demand didn't exist. All 'solutions' to the spam problem that fail to take this 'demand' problem into account are, IMO, doomed to failure.

    --
    Imposing Libertarian views on everyone online since 1992.
  9. Sneakemail.com by KevinMS · · Score: 5, Informative

    This is why Sneakemail was created over 3 years ago. You can easily bust whoever benefits from your stolen/sold email address no matter how far down the chain it goes. For those who don't know Sneakemail was the first disposable email address service which was designed both for keeping your address clean and tracking those selling your address. Sneakemail got a mention in this months MIT Technology review magazine.

    --
    Sneakemail is to spam filters what an ounce of prevention is to a pound of cure.
  10. Re:SPAM will end when... by gujo-odori · · Score: 2, Informative

    Would you like to make spam drop off tremendously overnight?

    The technology is there right now. All ISPs have to do is is block outbound port 25 TCP and the problem will almost vanish.

    What makes it that easy is the economics of spam. Spammers are generally not paying for the resources they use, which is how they can make a profit even at their incredibly small success rates.

    Consider the case of a spammer who uses a DSL or cable line to send spam. Assume a relatively expensive plan offering high bandwidth costing $125/month and how many referrals does a spammer need to generate to cover that cost? At $20/referral, the sixth one moves the spammer into the black. If the spammer pumps out 1,000,000 spams per month and gets a 0.1% hit rate, that's 1000 per month. If the spammer gets paid for them all, that's $20,000. Even if only 10% of those hits turn out to be legit leads and the spammer gets paid for only those, that's still $2,000. Put another way, it pays for the spammer's PC and DSL hookup costs in the first month, with profit left over.

    But let's assume this spammer knows a friendly ISP and is paying $1000 for a T-1, including local loop (you can go cheaper than that in many areas). If the spammer gets the same $2000 in referrals, that covers the cost of the T-1 and the PC. The next month covers the cost of the T-1 and leaves $1000 left over.

    Major spammers send many millions of mails each month, and even the small-scale ones probably do over a million, so these numbers are pretty conservative.

    What the spammers must do, however, that doesn't appear in the above numbers, is find some SMTP host(s) to carry their mail, since sending it from their own netblocks gets them quickly locked out by a great many MXes, invites DDOS attacks, results in people calling their upstream to get them shut down, etc.

    Enter the open relay. Open relay mail servers are (sadly), not uncommon even today. A pox on all the clueless mail admins who run these things. Spammers need to send outbound traffic on port 25 to get to the open relays. If all ISPs closed off outbound port 25 traffic in their consumer dial, cable, and DSL pools, the spam problem would shrink tremendously. I worked for an ISP that followed this practice, and we almost never had spammers (just a few times a year), and those we did get disappeared in a *hurry* because we would know they were there in short order because they couldn't exploit any open relay; they had to use *our* outbound SMTP hosts because we closed port 25. That mean that if someone started a spam run, their account wouldn't survive the day. By the time the first complaint arrived, we could write back and say "This account has already been terminated."

    That still leaves the problem of open proxies, of which there are also many, but those have to be dealt with via RBLs. That notwishtstanding, if all ISPs closed outbound 25 and required their dial, cable, and DSL customers to smarthost through their outbound SMTP hosts, it would take a huge bite out of spam, so to speak :-)