[Be warned; this E-mail mentions one of our programs several 
times.  However, if you have your server properly locked down, you can be 
safe from these attacks without running our software.]

After developing our Declude Hijack program (which is designed to allow 
legitimate E-mail through without having to lock down your server with SMTP 
AUTH or IP address restrictions), we waited almost 2 months for a spammer 
to try to hijack our server.  Although there were a number of spammers that 
"sniffed" our server (sent out a few E-mails to make sure that they could 
relay, and to see what headers were used), they must have all noticed the 
Declude headers and looked for an easier target.

Anyways, this weekend, there were 6 different (but related) attacks on our 
server (which fortunately Declude Hijack caught; not a single spam went out)!

These attacks were unusual in that they averaged only about 600 E-mails at 
a time, which is very low for a spammer.  Usually, they find one server and 
send out 50,000 to 100,000's of E-mails (or more).  It appears that some 
spammers are now sending out smaller amounts of mail through larger numbers 
of servers, to minimize the chances of them getting caught.  In fact, this 
attempted hijacking would have gone unnoticed if we hadn't been running our 
new program.

All of the E-mails were addressed to AOL users.  AOL has effective spam 
controls, so it may be that this spammer is trying to bypass some of the 
AOL spam controls by having their E-mails sent from a larger set of IP 
addresses.

#1:  HTML E-mail for a viagra alternative, 315 E-mails attempted.
#2:  text E-mail for bodybuilding pills; 1,680 E-mails attempted.
#3:  text E-mail for gambling web site; 357 E-mails attempted.
#4:  HTML E-mail for Internet Investigations (personal); 294 E-mails attempted.
#5:  HTML E-mail for female viagra; 420 E-mails attempted.
#6:  HTML E-mail for Internet Investigations (business); 63 E-mails attempted.

These came from 6 different E-mail addresses.  We believe they all came 
from the same spamming company (likely a "spammer for hire" sending E-mails 
for others), because all 6 E-mails had random text at the very end that 
appears to be designed to bypass spam filtering (making it look like a 
legitimate E-mail).

None of the 6 IP addresses that sent these E-mails has a reverse DNS 
entry.  None of them sent any "Received:" headers (a dead giveaway that the 
E-mail is spam).  They all had different headers, but each one had headers 
that aren't normally found in spam (such as "Replyto" headers).

It appears that some spammers are now being very creative in ways of 
avoiding spam detection, as well as avoiding getting noticed by the servers 
they are leeching off of.
                                                 -Scott


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to