So the upshot of this is we need to
1. Figure out a way to enforce strong passwords for
mail users
and
2. Monitor traffic for individual user accounts on
an intra-day basis, perhaps even have a means of detecting sharp increases in
traffic from a particular account and alerting an admin to investigate. We
do review a daily report the following morning of traffic by domain, but
don't have anything in place to monitor by account, or to alert on an intra-day
basis.
Something to look into...
Darin. ----- Original Message -----
From: Matt
Sent: Wednesday, November 16, 2005 6:18 PM
Subject: Re: [Declude.JunkMail] OT: another SOBERing
though Subject: Re: [Declude.JunkMail] SPF Success While this is certainly a bit of me patting myself on my back, it is also a reminder to all that the worst is yet to come and for the most part people are totally unprepared for this sort of thing. So what's next? Maybe Geocities spam sent through hacked Yahoo accounts??? Oh wait, that's already happening. Matt Colbeck, Andrew wrote: So, we've seen the recent SOBER variants used their own SMTP engine to propagate as well as a predefined list of usernames and passwords at ISPs to send themselves. We've also seen that keeping viruses and spam out of our mailboxes is easier when we can identify the sender as a zombie, and that it is harder when the junk is coming from a valid ISP and/or user at an ISP. http://www.viruslist.com/en/weblog?done=vlpolls_resp155596558 Well, Kaspersky is reporting that the latest SOBER is also stealing (at least) Outlook usernames and passwords from infectees. Therefore, we can reasonably expect more junk coming from AUTH'ed senders. Andrew. --- This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.JunkMail". The archives can be found at http://www.mail-archive.com. |
- Re: [Declude.JunkMail] OT: another SOBERing t... Nick Hayer
- RE: [Declude.JunkMail] OT: another SOBER... Colbeck, Andrew
- Re: [Declude.JunkMail] OT: another S... Nick Hayer
- RE: [Declude.JunkMail] OT: another S... John T \(Lists\)
- Re: [Declude.JunkMail] OT: another SOBER... Darin Cox
- Re: [Declude.JunkMail] OT: another S... Matt
- Re: [Declude.JunkMail] OT: anoth... Darin Cox
- RE: [Declude.JunkMail] OT: another S... Markus Gufler
- Re[2]: [Declude.JunkMail] OT: an... Sanford Whiteman
- Re: [Declude.JunkMail] OT: anoth... Darin Cox
- RE: [Declude.JunkMail] OT: another SOBER... Colbeck, Andrew
- Re: [Declude.JunkMail] OT: another S... Darrell \([EMAIL PROTECTED])
- RE: [Declude.JunkMail] OT: another SOBER... Colbeck, Andrew
- RE: [Declude.JunkMail] OT: another S... Markus Gufler