Slashdot Mirror


Deconstructing a Pump-and-Dump Spam Botnet

Behind the Front writes "eWeek has teamed up with Joe Stewart, a senior security researcher at SecureWorks in Atlanta, to show the inner working of a massive botnet that is responsible for the recent surge of 'pump and dump' spam. It's a detailed picture of how these sleazy operations work and why they're so hard to shut down. Sobering numbers: 70,000 infected machines capable of pumping out a billion messages a day, virtually all of them for penis enlargement and stock scams. Excellent graphics, too, including one chart that shows that Windows XP Service Pack 2 is hosting nearly half the attacked machines."

29 of 382 comments (clear)

  1. Filter by insecuritiez · · Score: 4, Insightful

    If more ISPs did egress filtering of email this sort of thing would be harder to do.

    1. Re:Filter by jfengel · · Score: 5, Insightful

      I hear that. It just doesn't seem unreasonable to me to cut off a customer who is sending tens of thousands of email per day. Put the very few with a legitimate reason on a white list (after a phone call) and cut the rest off until they clean up their act.

      As Heinlein said, the answer to any question beginning with "Why don't they..." is "money". Presumably the ISPs figure you'll just take your business and your bot-infested computer elsewhere. But maybe if a few major ISPs got together and agreed to all do it, they'd cut off enough spam to make their customer bases happier, and attract back those customers who gave up in frustration.

    2. Re:Filter by RichMan · · Score: 4, Insightful

      > No, just block port 25 to all servers other than the ISPs for dynamic IP addresses.

      I thought I paid for IP access. Deliberate port blocking by my ISP is blocking services I pay for.

      IP access means IP access, it does mean port 80 web surfing only. Any steps toward that are plain wrong.

      I agree it is a wild world out there but it is a problem of weak clients. The service provider should be blind unless a client is affecting network performance beyond their paid for slice. Then the client should be totally blocked.

    3. Re:Filter by Hognoxious · · Score: 3, Insightful
      If you are not capable of doing either of those things, then you should not have the privilege.
      What if I don't want to go jump through hoops, or pay double for the privelege? What if I want to acess my work mail server from home? Or a clients? Or I just want to access the email that I've been using for years via pop/smtp?

      Are you one of those imbeciles at Belgacom or something? Because they implemented the same cretinous strategy (without any advance warning, I may add) as you're suggesting.
      --
      Confucius say, "Find worm in apple - bad. Find half a worm - worse."
    4. Re:Filter by tha_mink · · Score: 3, Insightful

      I think everyone is missing the point here. The problem really isn't spam. It's the fact that there are botnets out there that are 70,000 strong. Thank god they're only sending enlarge-your-penis emails. Instead of spending energy trying to stop the symptom, let's try and stop the disease. Forget the email, let's figure out a way to stop the infections in the first place. Then there's the issue of cutting off the funding. Why not try and stop the funders of spam. I think that BlueSecurity had it completely right. Piss off the people paying the spammers, and you stop the spam. Nobody's going to send spam for fun, and if they did, maybe we wouldn't mind reading them so much. 1. Stop the infections 2. Stop the funders of spam. 3. Profit! It's a simple as that. I hate how people miss the point on this spam stuff. The spam is only the symptom.

      --
      You'll have that sometimes...
    5. Re:Filter by ZorbaTHut · · Score: 3, Interesting

      My ISP has a web-based configuration utility that allows me to set a server-side firewall to one of several default values. One of their options blocks several commonly-exploitable ports on Windows. I don't use those ports for anything, and I have my own firewall so those ports shouldn't reach my Windows boxes in any way whatsoever, but I set it to block them anyway. (This was the default setting, actually.)

      Something similar would work fine. Block port 25 to SMTP by default and have a web config utility to change it. If you really wanted, you could set it up to email the user if they tried accessing port 25 when it was blocked ("You might be trying to get past this firewall. Or, you might have a virus. Here's how you can find out, and here's how you can disable it if you need . . . ")

      --
      Breaking Into the Industry - A development log about starting a game studio.
    6. Re:Filter by jimicus · · Score: 4, Funny

      Something similar would work fine. Block port 25 to SMTP by default and have a web config utility to change it. If you really wanted, you could set it up to email the user if they tried accessing port 25 when it was blocked ("You might be trying to get past this firewall. Or, you might have a virus. Here's how you can find out, and here's how you can disable it if you need . . . ")

      I like that idea. Virus tries sending out 10,000 emails, user gets 10,000 emails saying "You might have a virus....".

  2. Infection vs Market Share by MrSplog · · Score: 4, Insightful

    The charts would be a lot more interesting if they had them compared to market share. then you've got to consider that people are more likely to target the biggest market share. i mean, how many virus writers are targeting FDOS?

  3. That was a bad picture by Overzeetop · · Score: 5, Funny

    I'm sorry, but the terms "Penis Enlargement" and "Excellent Graphics" were situated a bit too close together in that summary for my liking.

    --
    Is it just my observation, or are there way too many stupid people in the world?
  4. Rebuild the email protocol by Hoi+Polloi · · Score: 5, Insightful

    It is time to rebuild the email protocol. It needs to be redesigned to cope with modern systems and security needs. The pain of the transition would be worth it. It is just too easy to spoof header info now.

    --
    It is by the juice of the coffee bean that thoughts acquire speed, the teeth acquire stains. The stains become a warning
    1. Re:Rebuild the email protocol by LordEd · · Score: 5, Funny

      Your post advocates a

      (x) technical ( ) legislative ( ) market-based ( ) vigilante

      approach to fighting spam. Your idea will not work. Here is why it won't work. (One or more of the following may apply to your particular idea, and it may have other flaws which used to vary from state to state before a bad federal law was passed.)

      ( ) Spammers can easily use it to harvest email addresses
      ( ) Mailing lists and other legitimate email uses would be affected
      ( ) No one will be able to find the guy or collect the money
      ( ) It is defenseless against brute force attacks
      ( ) It will stop spam for two weeks and then we'll be stuck with it
      (x) Users of email will not put up with it
      ( ) Microsoft will not put up with it
      ( ) The police will not put up with it
      ( ) Requires too much cooperation from spammers
      ( ) Requires immediate total cooperation from everybody at once
      ( ) Many email users cannot afford to lose business or alienate potential employers
      ( ) Spammers don't care about invalid addresses in their lists
      ( ) Anyone could anonymously destroy anyone else's career or business

      Specifically, your plan fails to account for

      ( ) Laws expressly prohibiting it
      ( ) Lack of centrally controlling authority for email
      ( ) Open relays in foreign countries
      ( ) Ease of searching tiny alphanumeric address space of all email addresses
      ( ) Asshats
      ( ) Jurisdictional problems
      ( ) Unpopularity of weird new taxes
      ( ) Public reluctance to accept weird new forms of money
      (x) Huge existing software investment in SMTP
      ( ) Susceptibility of protocols other than SMTP to attack
      ( ) Willingness of users to install OS patches received by email
      ( ) Armies of worm riddled broadband-connected Windows boxes
      ( ) Eternal arms race involved in all filtering approaches
      ( ) Extreme profitability of spam
      ( ) Joe jobs and/or identity theft
      ( ) Technically illiterate politicians
      ( ) Extreme stupidity on the part of people who do business with spammers
      ( ) Dishonesty on the part of spammers themselves
      ( ) Bandwidth costs that are unaffected by client filtering
      ( ) Outlook

      and the following philosophical objections may also apply:

      (x) Ideas similar to yours are easy to come up with, yet none have ever
      been shown practical
      ( ) Any scheme based on opt-out is unacceptable
      ( ) SMTP headers should not be the subject of legislation
      ( ) Blacklists suck
      ( ) Whitelists suck
      ( ) We should be able to talk about Viagra without being censored
      ( ) Countermeasures should not involve wire fraud or credit card fraud
      ( ) Countermeasures should not involve sabotage of public networks
      ( ) Countermeasures must work if phased in gradually
      ( ) Sending email should be free
      ( ) Why should we have to trust you and your servers?
      ( ) Incompatiblity with open source or open source licenses
      ( ) Feel-good measures do nothing to solve the problem
      ( ) Temporary/one-time email addresses are cumbersome
      ( ) I don't want the government reading my email
      ( ) Killing them that way is not slow and painful enough

      Furthermore, this is what I think about you:

      (x) Sorry dude, but I don't think it would work.
      ( ) This is a stupid idea, and you're a stupid person for suggesting it.
      ( ) Nice try, assh0le! I'm going to find out where you live and burn your
      house down!

    2. Re:Rebuild the email protocol by Archangel+Michael · · Score: 4, Insightful

      The "we can't change anything because it is too hard waaaaaaa" post.

      Thank you for being a wimp.

      --
      Agent K: A *person* is smart. People are dumb, stupid, panicky animals, and you know it.
    3. Re:Rebuild the email protocol by Anonymous Coward · · Score: 4, Funny

      (x) Yes, I agree
      ( ) Nope, you're wrong

  5. thats okay, but how to detect this infection? by Anonymous Coward · · Score: 4, Insightful

    Perused the article to know how to find out if my computer is infected or not but couldn't find anything. This is such an important news for Windows users, at least tell something abou thow to verify if a particular windows machine is having this problem.

  6. I'm glad I run my own mail server by zitch · · Score: 3, Informative

    And implemented greylisting on it. Cut out almost %100 of the spam I have been receiving (Was up to 50 emails a day, now I think only one has gone through since I installed postgrey on my mail server in 1.5 months!). Unfortunately, this is easy to get around, so it should only be a matter of time till that is worked around and becomes useless in the spam fight. By that time, hopefully another anti-spam method comes up...

  7. eweek confirms it: Linux and Mac are dying! by Trelane · · Score: 5, Funny

    From the graphs, it's obvious that Linux, BSD, and MacOS lumped together are only 0.05 percent of the desktop market!!

    --

    --
    Given enough personal experience, all stereotypes are shallow.
    1. Re:eweek confirms it: Linux and Mac are dying! by mrjb · · Score: 4, Insightful

      Do you really think that 0.05% of all spam comes from Linux, BSD, MacOS, Solaris and OS/2 lumped together? Then I'll have to disappoint you. Look again. Windows 95 is curiously absent from the graph. How big a part of 0.05% do you think it could handle?

      --
      Visit http://ringbreak.dnd.utwente.nl/~mrjb/growingbettersoftware to download your free copy of the book
  8. C'mon by Tarlus · · Score: 3, Insightful

    Well of course Windows is going to be in the majority of affected machines... There is a dramatically higher number of people in the world using Windows than any other OS, so... wouldn't it make sense?

    As a proud user of Kubuntu, I can relate to /.'s tendency to point out everything that appears to be wrong with Windows... but come on, isn't it a little much to explicitly point it out in this case?

    --
    /* No Comment */
    1. Re:C'mon by Mark+Hood · · Score: 3, Insightful

      Actually, the dig was at Windows XP SP2 in particular - not just Windows generally.

      If these bots have control over 'the most secure Windows yet', then that is worthy of note.

      Mark

      PS Yes, I know the link is from 2004 - but they've not released anything since, so it must still be true, right?

      --
      Liked this comment? Why not buy me something nice
  9. I'm just surprised that those spams still ... by Jawood · · Score: 4, Insightful
    work. After all, the folks who are doing the "advertising" must be getting some sort of return.

    Which leads me to wonder about the folks who actually believe that those penis enlargement pills work.

    And as far as the "pump and dump" spam goes, are there folks who beleive those spams? Or are they of the mindset of the "greater sucker"? Meaning, if I buy this stock now, after this spam circulates, there will be others who buy this shit stock and push up the price allowing me to make money.

    Yeah, I know the guy who originates the "buy" recomendation is hoping for everyone to buy the stock, but what makes some of the recipients think they'll make out?

  10. outbound email only on request by davidwr · · Score: 3, Interesting

    If I were running an ISP, I'd have common ports such as IM, file-transfer/ftp/torrent, ssh, 80/443, irc, and many others allowed and all other ports blocked or restricted to certain destinations by default.

    I'd have a web-page for my customers so they can click things such as:

    Outgoing Email:
    [x] web based [turn on port 80/443]
    [x] through remote-login [turn on remote-login ports]
    [x] through us [turn on mail ports, restrict to our servers]
    [ ] through another server: ______ (specify list of outgoing mail servers)
    [ ] through any server
      +-- [x] check here to turn this off after 7 days (recommended)

    x's show defaults.

    Checking the last two would bring up the relevant sections of the AUP/TOS as a reminder of the strict "no spamming" and "we will suspend outgoing mail and charge you cleanup fees if your machine is taken over" clauses.

    --
    Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
  11. Hit the nail right between the eyes. by Rob+T+Firefly · · Score: 4, Insightful

    This is the basic problem with any single antispam measure, or really any single computer security measure.

    1. Someone comes up with a defense mechanism that works well.
    2. It works so well that more people use it.
    3. It becomes popular enough for the bad guys to beat, so they do.
    4. The defense becomes useless, forcing someone to come up with a new defense.
    5. Goto 1.

  12. Hasn't worked for me by Chapter80 · · Score: 3, Funny
    Has anyone had any luck with these stock tips? None of them seem to be panning out for me. I wonder if I am not acting fast enough. I've really taken a beating on some of these.

    Fortunately, I should have significantly more money to invest shortly, as soon as I get a rather large sum from a new online friend and business associate and new friend, Mr. Emmanuel Obi from Africa, of all places.

    1. Re:Hasn't worked for me by Anonymous Coward · · Score: 3, Interesting

      Luck? Did you see www.spamstocktracker.com?

  13. Re:where does it end? by ummit · · Score: 3, Insightful
    I hear you, but: put yourself in the shoes of "Joe Homeowner" for a moment, if you will. You know nothing about chemistry or combustion. You simply purchased your house because you needed a roof over your head. But the law requires you to install smoke detectors (and, in many jurisdictions now, also carbon monoxide detectors). In fact, the reason this is a law is precisely because the average homeowner knows nothing about chemistry or combustion; that's why people need emphatic (enforceable) reminders to install these safety devices.

    So a law that mandated safe computing clearly would not be out of the question, and would not be "blaming" those computer users who did nothing more than purchase a brand new PC in order to use it for its intended purposes.

  14. Windows 95 by Pinky3 · · Score: 3, Funny

    Hackers and Spammers no longer support Windows 95. It's too hard to write worms, bots, and viri that are backward compatible.

  15. Subject by Legion303 · · Score: 3, Insightful

    There's a lot of humor potential in going to a site laced with ads and a list of 30 sponsors to read about spam.

  16. Shorting won't work... by camusflage · · Score: 3, Informative

    No broker will allow you to short a pink sheet stock, which the overwhelming majority of pump and dump spam deals with.

    --
    The truth about Scientology, Xenu, and you: Operation Clambake
  17. Where's law enforcement on this? by Animats · · Score: 3, Interesting

    Those guys shouldn't be that hard to find with enough law enforcement effort. Get a credit card from a cooperating bank. Put a trace on it. Buy some Viagra from a spam. Watch where the money goes, which is probably some bank in a high-crime country. Visit the bank and talk to them. Threaten to have their abilty to process credit cards cut off. Pry the actual payee out of them. Discover that it's another intermediary and start over.

    This is what we pay the FBI for. This is why the FBI has field offices outside the US. This is why the Financial Crimes Information Network exists.

    The FBI's Internet-related criminal enforcement unit has gotten soft. They sit up in Baltimore and send out child pornography, then go after the people they've entrapped. The process is even mostly automated now. That's an easy way to get their stats up, and fits the Bush administration's "regulate sex, not business" mindset, but doesn't solve crimes that have victims. Something to push on after Jan. 20, when the Democrats take Congress and can start asking hard questions of the executive branch.