Search
|
Loading
|
Browse by Topic
- Ferris Deliverables
- Topics
- Vendors, Products, Gossip
- Autonomy
- AXS-One
- Blue Coat
- Borderware
- C2C
- CA
- CaseCentral
- Cisco
- Clearswift
- Clearwell
- Code Green
- CommVault
- EMC
- Proofpoint
- GFI
- Global Relay
- H&S
- HP
- IBM
- Iron Mountain
- Kazeon
- LiveOffice
- Marshal836
- McAfee
- MessageOne
- MessageSolution
- Microsoft
- Mimosa
- Open Text
- Oracle
- Quest
- Recommind
- Seagate
- Sherpa Software
- SonicWALL
- Symantec
- Titus Labs
- Trend Micro
- Vericept
- Waterford
- Websense
- ZL Technologies
November, 2006
Late last week, a spammer decided to send a large run of spam messages in my name. We estimate that in the space of 48 hours, the spammer’s botnet spewed 10 million messages that appeared to come from one of my privately owned domains.
A small percentage of those messages bounced, resulting in 25,000 bounces in my email over a 48-hour period. At its peak, I received one misdirected bounce per second. Many of the bounces included images — about half a gigabyte of unwanted, "backscatter" email.
What should we learn from this?
- We were impressed with how well the Symantec Brightmail spam filter that protects these domains worked. It did a near-perfect job of sifting out the bounces from the real email: better than 99% effectiveness, and no false positives — although it’s hard to be sure when there are so many messages to check in the quarantine. (For clarity, Symantec doesn’t protect the ferris.com domain; these forgeries were attacking other, privately owned domains such as richi.co.uk.)
- Many email servers behave badly, to the extent that they bounce unwanted email, instead of rejecting it. Some of this is due to configurations that accept everything at the perimeter and only later decide the mailbox doesn’t exist. Others seem to be due to badly configured perimeter protection — including a surprising number of Barracuda appliances. If you’re responsible for a mail system that creates such backscatter, please fix it.
- Many sites allow their users to auto-reply to email with no regard to whether they’re replying to spam (and hence sending irrelevant junk to a forged sender). Incredibly, some of these sites clearly decided the message was spam — as can be seen from SpamAssassin-like headers or subject tags added to the spam — yet they still kindly let me know that they’re "out of the office" because a spammer falsely used my email address as the spam’s sender. This is another form of backscatter; if you’re responsible for a mail system that does this, please fix it.
Article discussing the IM in the enterprise and how it is replacing email for casual communications. More
SWING Integrator 5 Provides Better Ties between Lotus Notes and OpenOffice
Comment on this... (0 comments) Nov 30, 2006SWING Software released version 5 of SWING Integrator, its Office integration toolkit for Lotus Notes and Domino developers. Adds OpenOffice integration with IBM Lotus Notes applications. Available immediately. More
Azaleos Provides Free Microsoft Exchange Cost Calculator Tool
Comment on this... (0 comments) Nov 30, 2006Azaleos released Exchange TCO, its TCO calculator for Exchange. Analyzes of the costs of running Exchange 2003 and Exchange 2007 incorporating data collected from hundreds of customers to provide assumptions about software, hardware, archiving, management, monitoring, and IT resource costs associated with operating Exchange. Available immediately. More
F-Secure Client Security 7 offers deep proactive protection for the corporate world
Comment on this... (0 comments) Nov 30, 2006F-Secure announced version 7 of F-Secure Client Security, its anti-virus solution. Key enhancements: F-Secure DeepGuard application to provide zero-day protection against previously unknown malware, integrated F-Secure BlackLight rootkit scanning, and new scanning options, among others. Available 1Q2007. More
Accelerate Your Adoption of Application Security Practices
Comment on this... (0 comments) Nov 30, 2006Secure Software will host “Accelerate Your Adoption of Application Security Practices,” it webinar, on December 5, 2006 at 2:00 pm EST. Highlights: application security program needs continue to be driven by compliance demands and the growing number of exploits at the application layer, Yankee Group presentation on current industry perspectives and best practices, and learn [...]
SkillSoft released results for 3Q2007 ended October 31, 2006. Revenue increased 6% to $57.1 million with net income of $7.1 million. More
NaviSite Reports First Quarter Fiscal Year 2007 Results
Comment on this... (0 comments) Nov 29, 2006NaviSite released results for 1Q2007 ended October 31, 2006. Revenue increased 12% to $28.5 million with a net loss of $2.6 million. More
Synchronica released version 1.3 of MobileManager, its mobile device management and synchronization solution. Key enhancements: support for Series 60, 80 and 90 Symbian Smartphones, query devices and display parameters in a web browser for remote diagnosis, and improved management functions, among others. Available immediately. More
CommVault Streamlines Legal Search and Discovery of Enterprise E-mail
Comment on this... (0 comments) Nov 29, 2006CommVault announced Outlook Add-in, its discovery search capability for the Outlook client. Allows cross-mailbox discovery searches in an Exchange environment through an extension to the Outlook client. Available immediately. More
Bynari released version 3.1.1 of Insight Connector, its plug-in that allows native Outlook groupware capabilities without the need for an Exchange server. Key enhancements: grouping support, reminder message when selecting a folder without ACL support enabled, voting button support, among others. Available immediately. More
Finjan’s Award-Winning Vital Security Version 8.4 Sets New Standard for Proactive Web Security
Comment on this... (0 comments) Nov 29, 2006Finjan released version 8.4 of Vital Security, its web security appliances. Key enhancements: security enhancements, improved performance, and enhanced manageability, among others. Available immediately. More
Clearswift simplifies enterprise Web security with MIMEsweeper Web Appliance
Comment on this... (0 comments) Nov 29, 2006Clearswift released MIMEsweeper Web Appliance, its web security appliance. Key features: content security engine, URL blocker and anti-virus and anti-spyware; among others. Available immediately. More
VeriSign announced it has signed a definitive agreement to acquire inCode Wireless, a global business and technology consulting firm specializing in the wireless marketplace, for approximately $52 million. More
OZ announced that it has raised $34 million in its second round of financing from Caisse de dépôt et placement du Québec, VantagePoint Venture Partners, and Fonds de Solidarite. More
Please Wait