Slashdot Mirror


SpamSlayer - should we DDOS spammers?

pointbeing writes "Just read this article about a company called Blue Security that essentially floods a spammer's website with requests to unsubscribe members - we're talking thousands of requests per day - the company's CEO says that fighting back by "inducing loss" against spammers is the only way to eventually stop them. Although I hate spam as much as the next guy, is participating in a DDOS attack the way to bring spammers to their knees? If it's okay in this instance, it it okay to DDOS the next guy who does something we don't like? "

32 of 587 comments (clear)

  1. Sophistry at its finest... by TripMaster+Monkey · · Score: 5, Insightful

    From TFA:
    The influx of tens of thousands of requests exactly at the same time floods the spammers' Web site, causing it to become inoperable.
    Sounds a lot like a DDOS attack...in fact, it sounds exactly like a DDOS attack. But aren't they illegal?

    Also from TFA:
    Launching a distributed denial of service attack is illegal in the U.S. and in most European countries.
    That's what I thought...what does Blue Security have to say in their defense?

    Again from TFA:
    Blue Security's Reshef bristles at the notion that his firm is involved with any type of DDoS attack. "We aren't trying to shut down any Web sites. We are just trying to slow these sites down so much the spammers can't earn money"
    Sorry, Reshef, but what you are describing is a textbook example of a DDOS attack. Whether the site in question is actully shut down, or merely incapacitated, is beside the point.

    This whole caper is a non-starter, especially so since a precedent for this sort of thing has already been established by Lycos Europe.
    --
    ____

    ~ |rip/\/\aster /\/\onkey

    1. Re:Sophistry at its finest... by turrican · · Score: 2, Insightful

      Also from TFA:
      Launching a distributed denial of service attack is illegal in the U.S. and in most European countries.

      That's what I thought...what does Blue Security have to say in their defense?

      ...maybe they'll have to start using the same offshore ISPs as the spammers?

    2. Re:Sophistry at its finest... by Gherald · · Score: 3, Insightful

      This seems like a form of vigilanteism to me.

      If spammers are sending unsolicited emails to others, I have no moral problem with a system that sends coordinated unsolicited requests to their sites in response.

      The legal issues are quite another matter.

    3. Re:Sophistry at its finest... by Tinik · · Score: 5, Insightful

      Vigilatism may seem like a good idea at the time, but always leads to problems in the long run. It's better to work through proper channels to resolve these problems. If the proper channels can't resolve the problem, then work to fix them.

      Doing things properly results in a more permanent fix. Vigilantism just gets innocent bystanders hurt and only works until the next guy comes along.

    4. Re:Sophistry at its finest... by Technician · · Score: 5, Insightful

      Sounds a lot like a DDOS attack...in fact, it sounds exactly like a DDOS attack. But aren't they illegal?



      Rule #1 Spammers lie
      Rule #2 see rule #1

      If an e-mail has false headers, what makes you think the reply-to or un-suscribe belong to the spammer. A DDOS against a third party (Joe Job) is not the way to shut down a spammer. You may be helping him shut down his legit competition. An obfuscated URL may point to amazon.com for example.

      I liked the other aproach of repeatedly reloading the page used to buy the spammer's product. That's a way to have them melt or have the hosting company become less friendly to hosting spam product order websites.

      --
      The truth shall set you free!
    5. Re:Sophistry at its finest... by ArsenneLupin · · Score: 5, Insightful

      Personnally, I prefer to submit only one single unsubscribe request. My email address just happend to be ...:
      'or'test@yahoo.com'like'%
      If the spammer uses sequel sewer or access rather than a real database, this will wipe their address list squeaky clean!

    6. Re:Sophistry at its finest... by chromaphobic · · Score: 4, Insightful

      While it's certainly true that DDoS attacks are illegal, and that there is a precedence that sets these types of things firmly in the illegal category, I personally think that we should reexamine them. Set a statute that allows DDoS attacks against known spam hosts and the like.

      That's one knot that I think would be best left untied. It may start out as an anti-spam tool, but it'll only be a matter of time before all manner of other uses are okayed. How long before the RIAA gets permission to DDoS file-sharers, or entire P2P networks? How long before Microsoft gets permission to DDoS servers hosting cracks for their software?

      Legalized DDoS attacks as a tool for fighting spam just reeks of a Pandora's Box solution to the problem. Once we make it an acceptable method for netcrime fighting in one instance, it's only a matter of time before all manner of major corporations and organizations tug the leash they have around US lawmaker's necks and get the right to DDoS anything they don't like.

    7. Re:Sophistry at its finest... by YomikoReadman · · Score: 1, Insightful

      So by saying that DDoSing warez servers is a bad thing? Or are you saying that they should be proteced and allowed to carry out illegal activities?

      I'm not saying that I like the idea of DDoS attacks; at the same time I'm not going to allow my personal dislike of them to keep from saying that it may or may not be a good thing for bringing down servers.

      Ultimately, any manner of dealing with spam can be seen as a gateway for heavy handed squashing other things that major corporations don't like and carry enough influence to accomplish their own ends. If you're willing to dismiss one of them, you might as well give up on fighting netcrime in all its' forms.

      --
      I have no regrets, this is the only path.
      My whole life has been "UNLIMITED BLADE WORKS"
    8. Re:Sophistry at its finest... by ZorinLynx · · Score: 2, Insightful

      It's either one. Batman has been referred to as both "The Batman" and just plain "Batman" in different comics and television shows/movies.

      So I suppose it depends on which story/continuity you're discussing.

      -Z

    9. Re:Sophistry at its finest... by farnz · · Score: 2, Insightful

      Who gets to define warez? I've just been in an argument with a BSA employee who claimed that any software that's not been purchased (i.e. obtained without payment) is warez. By this definition, http://www.debian.org/ is a warez server.

    10. Re:Sophistry at its finest... by interiot · · Score: 3, Insightful

      See, a large part of the definition of "DOS" involves intent. People can try to sue Slashdot, but it's extremely unlikely the person would win (baring actual malicious intent from Slashdot operators, of course).

    11. Re:Sophistry at its finest... by chromaphobic · · Score: 2, Insightful

      So by saying that DDoSing warez servers is a bad thing? Or are you saying that they should be proteced and allowed to carry out illegal activities?

      It could be. Say you own a small net-based business, small enough that you can only afford shared hosting. Now say one of those warez sites is on the same shared server as you. Microsoft (or Adobe, or Apple, or whomever) lays a DDoS attack on the server, now your site is down until the attack is over and you can no longer conduct business. Even worse, a particularly potent DDoS could take the entire host down, affecting all the sites they host.

      Perhaps the warez site is hosted off of some kid's home PC through his cable modem. The DDoS attack could take down everyone's internet access around him. Do you want your internet connection killed for a day (or days) because the kid next door hosted a warez server? I know I don't.

      There are already laws, albeit sometimes ineffective, on the books to deal with those kinds of situations. Opening the floodgates on DDoS-ing every server that commits anything even percieved as illegal is using a sledgehammer to swat a mosquito, and there's too much risk of collateral damage, IMHO.

  2. Hell yes! by base3 · · Score: 2, Insightful
    I think a few GB of traffic in an hour is just the ticket for spamvertized sites, and I always do my part for any one I come across.

    For those who complain that ISPs end up footing the bill because the spammers don't pay, well, I guess they'll need to be more careful about vetting their customers next time. As if there are any really "innocent" ISPs hosting Internet "pharmacies" or "Rolex" dealers.

    --
    One CPU cycle wasted on digital restrictions management is ONE TOO MANY.
  3. No, no no no no... by gmknobl · · Score: 5, Insightful

    I'm sorry, acting just like a criminal for revenge purposes, no matter how satisfying, is wrong. It just brings you down to their level.

  4. I don't think so ... by Living+WTF · · Score: 3, Insightful

    What if only once a bad guy manages to blame someone innocent who get's DDoSed? Should we hazard the consequences?

    --
    I don't suffer from insanity, I enjoy every minute of it.
  5. Different purposes, different results by Overzeetop · · Score: 1, Insightful

    If you shoot me and take my wallet, you are a murderer and a thief.

    If I shoot you before you do so, being reasonably certain that you intend to shoot me and take my wallet, I have acted in self defense, and there is no crime.

    Not really a one-for-one analogy, but it does illustrate that shooting someone does have different consequences depending on the situation and purpose.

    --
    Is it just my observation, or are there way too many stupid people in the world?
  6. Two wrongs don't make a right by Zane+Hopkins · · Score: 2, Insightful

    Why are they doing this, when they could put their energy into tracking the spammers so they can be prosecuted.

    Only sending spammers to jail AND taking away ALL their assets (cash/cars/houses) is going to deter them.

  7. Or the opposite? by Anonymous Coward · · Score: 1, Insightful

    Instead of unsubscribing thousands of emails, how about subscribing thousands of fake emails ... which in turn would lower their return ratio and might even result in fail delivery messages, using up more resources.

    -Rick

  8. Hate to break it to you, but by MatD · · Score: 2, Insightful

    Spam wouldn't be a problem if people didn't actually click on the links. I've seen studies somewhere about the return rate on spam. While it is quite low, it's still high enough to make it worth their while.

    Maybe we should establish a site that lists all the companies that support spam, and then boycott them. We could even have a plugin in firefox that would warn or block a site that was known to have used spam.

    --
    Since when did operating systems become a religion?
  9. Menace to the Internet by dfn5 · · Score: 4, Insightful
    This is just another form of spamming. Anyone who generates unnecessary network traffic is a menace to the Internet.

    --
    -- Thou hast strayed far from the path of the Avatar.
    1. Re:Menace to the Internet by njfuzzy · · Score: 2, Insightful

      Without unnecessary traffic, would there even be an Internet?

      --
      My Photography - http://ian-x.com
      The Deathlings (comic) - http://thedeathlings.com
  10. DDoSing spammers by farnz · · Score: 5, Insightful
    If you're sending an unsubscribe request to a spammer in response to a spam you've received, that's not intended as a DDoS; the spammer invited you to contact them and unsubscribe, and should have taken care to limit their list to avoid accidentally DDoSing their servers. In the same vein, I see nothing wrong with browsing a site advertised to you in a spam, despite intending to merely use up bandwidth, rather than make a purchase; again, if the spammer isn't happy, they shouldn't invite you to browse their site (in other words, they shouldn't send spam if they don't want to be visited).

    When you start trusting someone else to tell you who's spamming and who isn't, you invite them to abuse that power; what guarantees do you have that Blue Security will never go to a legitimate site owner, and threaten to tell SpamSlayer users that the legitimate site is spamvertised unless Blue Security receive enough money?

  11. DDoS attacks affect more than just the target... by Afecks · · Score: 2, Insightful

    Something everyone should remember is that unless you are directly connected to the spammer's LAN, you aren't sending packets to him directly. Every packet you send out travels many hops. Your ISP and everyone in between have to use resources to forward that packet.

    I don't know about everyone else but I don't want my cable connection bogged down just because my neighbor feels like being an activist. Let's let the legal system do its job and use distributed computing for protein folding or other more worthy causes.

  12. Re:I remember when this debate started by Have+Blue · · Score: 4, Insightful

    And when the "necessary evil" is more than half the email traffic on the net and starting to drown out the things we are supposed to be gaining by putting up with this necessary evil? The moral of the tragedy of the commons is that nobody wins.

  13. What shall we do? by erroneus · · Score: 3, Insightful

    Two wrongs not making a right and all that... we know the drill. But it is undeniably wrong that spammers do what spammers do. With that in mind, we can either (a) wait until they see the error of their ways, (b) wait until sufficient legislation is enabled that will actually work or (c) do something about it ourselves.

    A and B aren't working. C, at present, is the only answer we have available to us.

    I want to say for the "record" (whatever that means) that marketing through email is okay with me so long as people WANT to recieve it. If someone out there WANTS to buy some descrete penis pills or any other "plain brown wrapper" item that's fine with me. And let there be a means for them to subscribe to the stuff. The key is Opt-in explicitly and without any tricks or gimicks and more significantly, an "instant off" function that will not require 4-6 weeks to update their databases (which is utter horse shit). Okay I said it... now let's move on.

    We do everything we can to block these people. They do everything they can to avoid being blocked. Their attempts at evasion is proof positive that they know they are pissing off the world for profit. How many other business models work at public expense for personal gain? In effort to prevent at-large vigilante-ism, where should the line be drawn? As much as I'd like to pull over and beat the crap out of people with ridiculously loud stereos playing in their cars, it's wrong (and dangerous) to do.

    I'm at a loss for what we should do about the problem. These people are essentially polluting the internet and it needs to stop. But how?

  14. No, Protector of the Internet by fmaxwell · · Score: 2, Insightful

    This is just another form of spamming. Anyone who generates unnecessary network traffic is a menace to the Internet.

    Policing the Internet and making it an unwelcoming place for spammers is not "unnecessary." It's necessary if e-mail is to remain a viable, cost-effective means of communication.

    Spammers love the kind of prissy-assed, holier-than-thou, arguments about ethics that people like you put up every time someone actually tries to combat spam. Bullsh*t. Enough is enough. If two or three months of attacks on a spammer's servers could get him to stop pissing off a million or more people a day, then let the attacks begin! If it makes a Chinese ISP stop writing web hosting contracts for spammers, then let's get going. If you don't have a viable plan to combat the ever-increasing volume of spam, then get out of the way and let those who do take action.

  15. Wasted bandwidth by ZorinLynx · · Score: 2, Insightful

    If I were a carrier/backbone level provider, I certainly wouldn't want all this extra garbage traffic on my network.

    I'm sure the rest of the network doesn't appreciate the potential increase in latency and packet loss these attacks can result in, either.

    DDoS attacks are never a solution to a problem. They may hurt the target, but at the cost of wasted bandwidth for everyone else using the paths to that target.

    Let's not start down this path. Please.

    -Z

  16. Spam from BlueSecurity.Com by DavidD_CA · · Score: 2, Insightful

    OMG i just got spammed from bluesecurity.com! We better rush out and DDOS them.

    Seriously, what's to stop a spammer from sending spam on behalf of a competitor, and laughing while BlueSecurity shuts down their website?

    And who decides what is spam? BlueSecurity employees? A poll of users? A 13 yr old who scripts a bunch of canned messages to "BS" and says Microsoft spammed him?

    Spam is Evil, but so is fighting spam *with* Evil.

    --
    -David
  17. The danger of vigilantism by ezraekman · · Score: 4, Insightful

    There's another name for this sort of activity: "Lynching" There's a good reason why one isn't supposed to take the law into one's own hands. It's because, however noble your intentions, there are no checks or balances on your actions; no safeties or limits.

    I HATE spammers. When I'm bored, I shut them down by tracking relevant data about them, and reporting them to their hosts and domain registrars. But who decides who the next "spammer" is? When I get spammed, even that isn't strong enough evidence for me. My next step is to ensure that it isn't an isolated incident, and so I go search the web to see if they've been added to a database/blacklist, or are on any of a number of spammer watchlists. Once I've got enough evidence to be able to convince a host/registrar, as well as myself, THEN I take action. But... how many vigilantes would take these extra steps? How many would simply go along with the crowd? "Hey! It's a spammer! GET HIM!!!"

    As much as I hate what spammers do, I simply can't condone this kind of action, without some kind of safety net for false positives. We're seeing something of a double standard here. What if, instead of discussing actions against "spammers", we were discussing actions against "terrorists"? Biometric tracking? Millimeter wave scanners? RealID? We've all seen how many people get strip-searched, end up on no-fly lists, get arrested for not having the right paperwork or IDs, and have any number of other civil rights violated. We're constantly demanding that we have some sort of guarantee that we're not going to end up flagging the wrong individuals. I agree wholeheartedly; we'd damn well better ensure we're flagging the right people, or the system is pointless, and the "terrorists" will end up laughing all the way back to the compound. So... where's our safety net here, folks?

    If we could legitimately do something like this, there wouldn't be a need for it, because it would mean the authorities would already be doing so. What happens on the day someone decides that Bob's Direct Mail service is "close enough" to spam, and we should start targeting them? How about Bob's Direct Mail Order? Bob's Direct Shipping? Bob's Joint? Who decides the next target? What if it's just a personal vendetta, and isn't even accurate? What happens when 20,000 people take that person's word for it, without doing any of their own research?

    Yes, something needs to be done about the spammers, but this sets a dangerous precident. What's the solution? Hell if I know, though I suspect it's a combination of legislation and education. I just know that this has enough problems to have been condemned by almost everyone here, if it had come from the opposite direction.

  18. Is spam email a DDOS? by gorehog · · Score: 3, Insightful

    Is going to the DMV and waiting on line a DDOS? no, it is following the procedure as it has been recommended by the provider.

    Before you can ask if using the function is a denial of service answser this question: Is sending spam a denial of service attack? I have had to cancel email accounts because of all the spam. Did the spammers attack me? Did they deny me access to my email by raising the noise to signal ratio to the point that I could not use it anymore? I certainly feel that they did.

    Now, the only reason that the spammers would have a technical issue is if they were not prepared for all the cancellation requests that come through. In that sense it is like a slashdotting. When a site gets slashdotted we laugh and say the site should have been on a better server, with more bandwidth, etc, etc. So...if the spammer cannot handle the cancellation requests maybe it's his fault. Maybe he should have vetted his mailing list and not sent emails to uninterested parties. Maybe 10 year old boys dont need viagra, cheap diabetic supplies, and hot lesbian horse action. Some discretion and discipline in advertising practices could help alleviate this problem.

    Fact of the matter is that each spam email out is supposed to offer a chance to cancel the mailings and get off the list. If the spammer cant do that he is in violation of the law. I dont care if he has too many cancellation requests. I dont care if everyone who recieves it cancels.

    If they dont want attention then they should not advertise.

  19. This is an embarassment to law enforcement by mabu · · Score: 2, Insightful

    The fact that so many people are seriously considering vigilante-oriented solutions to these problems calls attention to the woefully inadequate enforcement resources we have.

    I am still dumbfounded as to why ANY of the ~200 (or less) spam-gangs (as documented by Spamhaus) who are responsible for 80% of all spam haven't been taken down? I don't buy the jurisdictional problem excuse -- most of them are in the states and all of us know they can be easily traced. Almost every one of these spammers are engaging in multiple criminal activities, including computer tampering, fraud, copyright infringement, RICO violations, identity theft, ponzi schemes, and more.

    The biggest casualty of spam is the theft of bandwidth and network resources. DDOS'ing the spammers, while effective in that it may increase their cost of doing business, compounds the problem.

    However, at this point, since the feds seem incapable of doing anything about this, I'm unwilling to write off any approach that might wake them up and get them into action. Our country does have a history demonstrating that civil disobedience can be an effective catalyst when the status quo is ambivalent. With that being said, I wouldn't personally endorse anything of questionable legality, but at the same time, I can't help but respect the role of such tactics in history.

    Still, it just boggles me that a few FBI agents haven't done something as simple as toss up a few PCs on a cable connection with a packet sniffer, and begun documenting the propagation of worms and how the spammers are operating. It would take no more than a week to build a solid case against so many of these operations, you could pick-and-choose which perpetrator would be the easiest to prosecute. So why hasn't this been done?

  20. What do you really know about the West? by kaladorn · · Score: 2, Insightful

    The situation you are likening things to probably doesn't work as you suspect.

    Do you think the West was tamed by vigilante gangs, citizen lynchings, and the like? Do you believe this is what civilized the West?

    Or rather, was it the coming of the railroad, the influx of honest people, the extension of the hands of law enforcement, the implementation of new laws and their enforcement, etc.

    I submit that the Wild West was a place of murderers, vigilante gangs (murderers), hired guns (ditto), the precursor of the corporate army (likewise sometimes), and citizens who were sometimes willing to backshoot a dangerous stranger or lynch him without due process.

    Now, all I'm getting at is reverting to the same type of action as the spammers is sort of like admitting you can't come up with anything better, more civilized, or more effective. That smacks of giving up, of throwing up your hands and saying "we can't beat 'em, better join 'em".

    There are any number of existent laws and if the agencies that enforced them were a bit better funded and there was better international cooperation, we'd see a fairly marked decrease in some of this sort of traffic. Fighting spam is as much an international diplomatic/legal/bureaucratic issue as it is a technical one.

    I mean, think of it in another way. You've got a dark room and you have a door onto it. You know the dark room has some nasty critters in it, and one might wander into your lighted door and try to eat you. I don't think the solution is releasing alternate strains of nasty critter. That's just magnifying the problem. Instead, you'd put a door on with a peep hole, you'd install a mantrap or two, and you might find out which other room is popping monsters out and send a group of people to that room to speak with them about it.

    I figure we can win this war another way, we just have to decide to spend the money and put it as a priority for our law makers, law enforcers, and budget allocators for same. And of course, arm-twist some offshore havens into rethinking their policies.

    --
    -- Mal: "Well they tell you: never hit a man with a closed fist. But it is, on occasion, hilarious."