Microsoft Engineer Discovers Android Spam Botnet, Google Denies Claim
An anonymous reader writes "Microsoft engineer Terry Zink has discovered Android devices are being used to send spam. He has identified an international Android botnet and outlined the details on his MSDN blog. A closer look at the e-mails' header information shows all the messages come from compromised Yahoo accounts. Furthermore, they are also stamped with the 'Sent from Yahoo! Mail on Android' signature. Google has denied the allegations. 'The evidence does not support the Android botnet claim,' a Google spokesperson said in a statement. 'Our analysis suggests that spammers are using infected computers and a fake mobile signature to try to bypass anti-spam mechanisms in the email platform they're using.'"
Would it kill you to link to MSDN - where the blog entry actually resides? I get the anti-MS sentiment (although jeez, quit living in the 90s), but making readers jump to ZDNet first (or sending them back to /.) is just being passive aggressive.
There is a follow-up blog post where Zink backtracks a bit and admits the headers could be forged.
"In comments of various blogs a lot of people have suggested that these headers are spoofed, or there was a botnet connecting to Yahoo Mail from a Windows PC and sent mail that way. Yes, it’s entirely possible that bot on a compromised PC connected to Yahoo Mail, inserted the the message-ID thus overriding Yahoo’s own Message-IDs and added the “Yahoo Mail for Android” tagline at the bottom of the message all in an elaborate deception to make it look like the spam was coming from Android devices."
"We make our world significant by the courage of our questions and by the depth of our answers." Carl Sagan
(most users just click yes to anything)
On Android, you have to. Your only options are accept everything or you don't get the app.
I believe him.
Sent from my Cray Supercomputer. BillGates@Microsoft.com
Waiting for an amusing sig.
And if anyone knows how to take what should be a simple, straightforward, technical discussion and turn it into a MS vs Google flame war, it will be Slashdot commenters.
I see emails from compromised accounts. The one thing that appears to be common is that it is always from Yahoo accounts. After one of my friends had her Yahoo account compromised, I throughly scanned her PC -- nothing showed up. I scanned the hard drive while connected to a known clean PC, so it wasn't just a well hidden malware.
I am beginning to wonder if there is a vulnerability in Yahoo's security that is being used to compromise accounts.
The real "Libtards" are the Libertarians!
To be clear, Cyanogenmod 7 contains permission management. This feature was dropped in Cyanogenmod 9.