Deconstructing a Pump-and-Dump Spam Botnet
Behind the Front writes "eWeek has teamed up with Joe Stewart, a senior security researcher at SecureWorks in Atlanta, to show the inner working of a massive botnet that is responsible for the recent surge of 'pump and dump' spam. It's a detailed picture of how these sleazy operations work and why they're so hard to shut down. Sobering numbers: 70,000 infected machines capable of pumping out a billion messages a day, virtually all of them for penis enlargement and stock scams. Excellent graphics, too, including one chart that shows that Windows XP Service Pack 2 is hosting nearly half the attacked machines."
If more ISPs did egress filtering of email this sort of thing would be harder to do.
The charts would be a lot more interesting if they had them compared to market share. then you've got to consider that people are more likely to target the biggest market share. i mean, how many virus writers are targeting FDOS?
I'm sorry, but the terms "Penis Enlargement" and "Excellent Graphics" were situated a bit too close together in that summary for my liking.
Is it just my observation, or are there way too many stupid people in the world?
It is time to rebuild the email protocol. It needs to be redesigned to cope with modern systems and security needs. The pain of the transition would be worth it. It is just too easy to spoof header info now.
It is by the juice of the coffee bean that thoughts acquire speed, the teeth acquire stains. The stains become a warning
Perused the article to know how to find out if my computer is infected or not but couldn't find anything. This is such an important news for Windows users, at least tell something abou thow to verify if a particular windows machine is having this problem.
And implemented greylisting on it. Cut out almost %100 of the spam I have been receiving (Was up to 50 emails a day, now I think only one has gone through since I installed postgrey on my mail server in 1.5 months!). Unfortunately, this is easy to get around, so it should only be a matter of time till that is worked around and becomes useless in the spam fight. By that time, hopefully another anti-spam method comes up...
From the graphs, it's obvious that Linux, BSD, and MacOS lumped together are only 0.05 percent of the desktop market!!
--
Given enough personal experience, all stereotypes are shallow.
Well of course Windows is going to be in the majority of affected machines... There is a dramatically higher number of people in the world using Windows than any other OS, so... wouldn't it make sense?
/.'s tendency to point out everything that appears to be wrong with Windows... but come on, isn't it a little much to explicitly point it out in this case?
As a proud user of Kubuntu, I can relate to
/* No Comment */
Which leads me to wonder about the folks who actually believe that those penis enlargement pills work.
And as far as the "pump and dump" spam goes, are there folks who beleive those spams? Or are they of the mindset of the "greater sucker"? Meaning, if I buy this stock now, after this spam circulates, there will be others who buy this shit stock and push up the price allowing me to make money.
Yeah, I know the guy who originates the "buy" recomendation is hoping for everyone to buy the stock, but what makes some of the recipients think they'll make out?
If I were running an ISP, I'd have common ports such as IM, file-transfer/ftp/torrent, ssh, 80/443, irc, and many others allowed and all other ports blocked or restricted to certain destinations by default.
I'd have a web-page for my customers so they can click things such as:
Outgoing Email:
[x] web based [turn on port 80/443]
[x] through remote-login [turn on remote-login ports]
[x] through us [turn on mail ports, restrict to our servers]
[ ] through another server: ______ (specify list of outgoing mail servers)
[ ] through any server
+-- [x] check here to turn this off after 7 days (recommended)
x's show defaults.
Checking the last two would bring up the relevant sections of the AUP/TOS as a reminder of the strict "no spamming" and "we will suspend outgoing mail and charge you cleanup fees if your machine is taken over" clauses.
Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
This is the basic problem with any single antispam measure, or really any single computer security measure.
1. Someone comes up with a defense mechanism that works well.
2. It works so well that more people use it.
3. It becomes popular enough for the bad guys to beat, so they do.
4. The defense becomes useless, forcing someone to come up with a new defense.
5. Goto 1.
Slashdot Burying Stories About Slashdot Media Owned
Fortunately, I should have significantly more money to invest shortly, as soon as I get a rather large sum from a new online friend and business associate and new friend, Mr. Emmanuel Obi from Africa, of all places.
So a law that mandated safe computing clearly would not be out of the question, and would not be "blaming" those computer users who did nothing more than purchase a brand new PC in order to use it for its intended purposes.
Hackers and Spammers no longer support Windows 95. It's too hard to write worms, bots, and viri that are backward compatible.
There's a lot of humor potential in going to a site laced with ads and a list of 30 sponsors to read about spam.
No broker will allow you to short a pink sheet stock, which the overwhelming majority of pump and dump spam deals with.
The truth about Scientology, Xenu, and you: Operation Clambake
Those guys shouldn't be that hard to find with enough law enforcement effort. Get a credit card from a cooperating bank. Put a trace on it. Buy some Viagra from a spam. Watch where the money goes, which is probably some bank in a high-crime country. Visit the bank and talk to them. Threaten to have their abilty to process credit cards cut off. Pry the actual payee out of them. Discover that it's another intermediary and start over.
This is what we pay the FBI for. This is why the FBI has field offices outside the US. This is why the Financial Crimes Information Network exists.
The FBI's Internet-related criminal enforcement unit has gotten soft. They sit up in Baltimore and send out child pornography, then go after the people they've entrapped. The process is even mostly automated now. That's an easy way to get their stats up, and fits the Bush administration's "regulate sex, not business" mindset, but doesn't solve crimes that have victims. Something to push on after Jan. 20, when the Democrats take Congress and can start asking hard questions of the executive branch.