Spam War Takes Out Blog Services
munchola writes "Following on from the story about spammers attacking Blue Security's anti-spam system, CBR is reporting that Six Apart, which runs the popular LiveJournal and TypePad blogging services, has become a collateral victim. Six Apart told its millions of bloggers it had experienced 'intermittent and limited availability for TypePad, LiveJournal, TypeKey, sixapart.com, movabletype.org and movabletype.com', before resolving the issue in the early hours of Wednesday. '[The spammers are] trying to rip apart the internet just to make our community stop fighting back against spam,' Blue Security's chief executive Eran Reshef said, adding that he knows who's behind the attack."
fta:
The spammer also launched a conventional bandwidth-consumption DDoS attack against bluesecurity.com. It was around this time that the company opened its new blog, which meant TypePad got whacked.
This blue security article has been running for a few days now and the site hasn't been responding any time I've tried recently.
Isn't it just another DDOS blame fest when in reality its just the news spreading around the world and all the collective users of all the collective news sites are clicking the links to try to read the story?
A total slashdotting/digging/farking and general newsing all at once.
It was the same when word spread about google going down.
"OMG have you heard, google is dead?"
*CLICK* "Yer, its not working here either" *CLICK* *CLICK* *CLICK*
*CLICK* "Hey, its loaded here." *CLICK* "Oh crap, its broken again now.."
We are all guilty of assisting this DDOS attack. shame on us.
It will ease up once something else comes and takes our attention away from it.
liqbase
I don't think spam will stop, or even slow down, until a spammer is seriously hurt or killed. Right now, they know there is no consequence to their actions. I'm not saying I personally advocate killing spammers, but it certainly wouldn't make me feel bad to hear about it being done. Spamming would be a lot riskier if there were an element of harm attached for the spammer.
Taking out spammers and bloggers?
I can't see any down side to this, honestly.
He tried to kill me with a forklift!
The best way to eradicate spammers would simply be to go after their clients.
That hasn't worked yet. If you have some idea how that could be accomplished and effective against spam and spammers, please feel free to elaborate.
Blue security seems to be causing pain to spammers, enough to get a rise out of them at least. Aren't they actually reflecting the spam back to the source? I think that was their tactic.
If they are effective, that's a net positive in the spam fight.
.
isn't that counter to what you have in your signature?
-- "Freedom is the right of all sentient beings" -Optimus Prime
But have they got any better suggestions. The federal government is a *Joke* about bringing any kind of justice down on this filth, and so the masses remained *outraged* and *victimized*. To me a (A computer tech) I see people's computers every day that have been turned into Zombies. Some so bad that they have to be reformated. They are bringing in their computers to me, and paying hard cash for me to fix it and prevent it from happening again. That's real money, real damages everyone is having to pay every day. I guess you could spin it in a positive light and say it's good for the tech industry, but not if people start becoming afraid to even get on the internet because of what might happen to their computer. This is theft, this is vandilism and the governements of the world are practically standing by and watching it happen.
So, do you have any better suggestions, if not then I kindly ask you to ommit your views until you can add something to the cause.
Go ahead and call me unreliable; reliable is just a synonym for predictable.
All blue frog does is requesting to be opted out. One form send per spam received. No more, no less.
4 of the 10 major spammers had already excluded the blue security list from their mass mailings, and their problem was solved. But this particular spammer, instead of complying, shut down Blue Security.
Just because Blue Frog causes A SIDE EFFECT of disminishing the bandwidth of the spammer's website, is not Blue Security's fault. (It is our LEGAL RIGHT to request for opt-out, and to keep requesting it UNTIL IT IS FULFILLED).
To say opting out is abuse, is nothing but legitimizing illegal (non CAN-SPAM complying) spam.
Also, the spam reports that are sent out are sent from a proxy type email address. My normal address wouldn't show up, but username@reports.bluesecurity.com is where it would come from.
Personally, I see nothing wrong with sending 1 unsubscribe request per piece of spam I get. BlueSecurity has just automated this method so I don't have to take the time, and they also handle escalation to the proper authorities if the situation isn't resolved.
If the spammer perceives getting 1 unsubscribe request per spam he sends a DDOS attack then I would think the best course of action would be not to send to those people. Heck, we are the ones who wouldn't buy anything from them anyway.
Also, based on what I have read in the blog itself (when it was still accessible) it was a user in the comments that suggested redirecting the site and error pages to the blog so users would at least have some clue what was going on. It's likely they took the advice without contemplating the potential outcome.
I am Homer of Borg. Resistance is Fut.. Mmmmmmmm, Donuts!
Agreed! I've got my pitchfork and torch right here... I dunno about you but I'm up for some mob rule and a lynching to take care of this mess.
Help Brendan pay off his student loans
Even if that's not the case here, it's certainly possible for someone malicious to subvert Blue Security's agent in such a manner.
It seems blue security has been compromised by the spammers.
I can't see why blue security should be blamed- except for their security problem.
The problem is spam and spammers, and it is ludicrous to think otherwise.
I have been working on the spam problem for >10 years.
The problem is lax ISPs and network operators who don't pay attention to their mail. Who don't jump on the trojaned machines on their network that are causing >90% of the spam problem in the world.
I have had the same trojaned machine sending me the same spam every 15 minutes, from a school district. It took me days to finally get a shitty response out of the network operators there to get that machine shut down until it could be cleaned. They didn't seem concerned at all, it was like I was "bothering them" to ask them to stop that machine from spamming.
I bet it was sending 150,000 messages between the ones I received. Obviously a major problem. They couldn't care less.
Now THEY should have been DOS'd.
Ya know, several years ago I asked one of the principles of Akamai to get involved, to provide some of the bandwidth and hosting in a fault tolerant fashion, which they reportedly are in a unique position to provide on their monitored distributed network. Practically cannot be effectivedly DOS'd. They thought my proposal "interesting" but didn't want to get involved for the good of the internet, because they didn't want to attract attention from the bad guys.
It wasn't 5 or 6 months before they were DOS'd and extorted.
EVERYONE is involved now. We are all being extorted by the spammers. If you cross them they will attack you, even if you just ask them to please stop spamming you.
The only possible answer is responsibility. Networks being responsible for what goes on over their network. Shut down spammers. Don't rent them servers. Don't sell them bandwidth. Jump on problems, even on weekends and holidays, and you have to do it FAST.
Nothing is going to stop spam completely, we can only increase the cost to spammers, and increase the costs for networks to sell to spammers. Make it uneconomical to have spammers as customers.
When the cheapest T-1 a spammer can find is $250,000 a month, spam will stop.
.
Guys, I'm growing tired of the high moral argument that "it's not right to fight abuse with abuse" or "eye for an eye still leaves you blind".
War and drama asside: I keep waiting for someone to make this point but I'm not seeing it yet.
Spam is a solicitation to contact the advertised party in the hopes that you will give them money. Otherwise known as an advertisement. THEY CONTACT US. It's called the free market. In turn we all have the right to use the communication path they supply to request that they leave us alone.
Is it illegal to contact some company you see on a billboard or in a TV commercial? What absurdity! What is this world coming to where everyone gets sucked into DDoS drama at every chance? Blue Froggers are just doing business within the realm of the law. No stretching the rules. No sensationalism.
The only reason spammer servers crash is because they aren't prepared and are poorly designed. They have two options:
1. Seriously upgrade their infrastructure to handle whatever degree of responses their advertisements generate & hire more staff to process the hits their ad generates.
=or=
2. Seriously decrease their advertisements to be in line with their capacity to manage their generated trafic.
It's just economics and common sense. This DDoS talk is a waste of time - the Blue Frog client is much nicer to the spammers than they are to us. And this huge amount of anger directed at Blue Frog is proof that it bites into their freedom to be irresponsible.
They can keep their pill pushing sites - I don't care if there are suckers out there dumb enough to give them money. I just want them to stop bothering ME. They will never get one red hot cent from me. They WILL get endless trouble from me as long as they continue to disrespect my privacy.
All the best folks!
B.