Search
Browse by Topic
- Ferris Deliverables
- Topics
- Vendors and Products
- Attenex
- Autonomy/Zantaz
- AXS-One
- Blue Coat
- Borderware
- C2C
- CA/Ilumin
- CaseCentral
- Cetaphora
- Cisco/Ironport
- Clearswift
- Clearwell
- Code Green
- CommVault
- EMC
- Fortiva
- GFI
- Global Relay
- Google/Postini
- H&S
- HP/IAP
- IBM CommonStore
- IBM Notes/Domino
- IBM Quickplace
- Iron Mountain/Stratify
- Kazeon
- LiveOffice
- Marshal
- McAfee
- MessageLabs
- MessageOne
- Microsoft Exchange/Outlook
- Mimosa Systems
- Open Text/Hummingbird
- Oracle/Stellent
- Orchestria
- Other Products
- Permessa
- Proofpoint
- Quest
- Reconnex
- RPost
- Seagate/EVault/MetaLINCS
- Sherpa Software
- SonicWALL
- Symantec/Vault/Veritas/Vontu
- Tablus
- Titus Labs
- Trend Micro
- Vericept
- Waterford
- Websense/Port Authority/SurfControl
- ZL Technologies
Archives
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- October 2007
- September 2007
- August 2007
- July 2007
- June 2007
- May 2007
- April 2007
- March 2007
- February 2007
- January 2007
- December 2006
- November 2006
- October 2006
- September 2006
- August 2006
- July 2006
- June 2006
- May 2006
- April 2006
- March 2006
- February 2006
- January 2006
- December 2005
- November 2005
- October 2005
- September 2005
- August 2005
- July 2005
- June 2005
- May 2005
- April 2005
- March 2005
- February 2005
- January 2005
- December 2004
- November 2004
- October 2004
- September 2004
- August 2004
- July 2004
- June 2004
- May 2004
- April 2004
- March 2004
- February 2004
- January 2004
- December 2003
- November 2003
- October 2003
- September 2003
- August 2003
- July 2003
- June 2003
- May 2003
- April 2003
- March 2003
- February 2003
- January 2003
- December 2002
- November 2002
- October 2002
- September 2002
- August 2002
- July 2002
- June 2002
- May 2002
- April 2002
- March 2002
- February 2002
- January 2002
- December 2001
- October 2001
- September 2001
- August 2001
- July 2001
- June 2001
- May 2001
- April 2001
- March 2001
- December 2000
- October 2000
- September 2000
- August 2000
- July 2000
- June 2000
- May 2000
- April 2000
- March 2000
- February 2000
- January 2000
- December 1999
- November 1999
- October 1999
- September 1999
- July 1999
- June 1999
- April 1999
- March 1999
- February 1999
- January 1999
November, 2006
Late last week, a spammer decided to send a large run of spam messages in my name. We estimate that in the space of 48 hours, the spammer’s botnet spewed 10 million messages that appeared to come from one of my privately owned domains.
A small percentage of those messages bounced, resulting in 25,000 bounces in my email over a 48-hour period. At its peak, I received one misdirected bounce per second. Many of the bounces included images — about half a gigabyte of unwanted, "backscatter" email.
What should we learn from this?
- We were impressed with how well the Symantec Brightmail spam filter that protects these domains worked. It did a near-perfect job of sifting out the bounces from the real email: better than 99% effectiveness, and no false positives — although it’s hard to be sure when there are so many messages to check in the quarantine. (For clarity, Symantec doesn’t protect the ferris.com domain; these forgeries were attacking other, privately owned domains such as richi.co.uk.)
- Many email servers behave badly, to the extent that they bounce unwanted email, instead of rejecting it. Some of this is due to configurations that accept everything at the perimeter and only later decide the mailbox doesn’t exist. Others seem to be due to badly configured perimeter protection — including a surprising number of Barracuda appliances. If you’re responsible for a mail system that creates such backscatter, please fix it.
- Many sites allow their users to auto-reply to email with no regard to whether they’re replying to spam (and hence sending irrelevant junk to a forged sender). Incredibly, some of these sites clearly decided the message was spam — as can be seen from SpamAssassin-like headers or subject tags added to the spam — yet they still kindly let me know that they’re "out of the office" because a spammer falsely used my email address as the spam’s sender. This is another form of backscatter; if you’re responsible for a mail system that does this, please fix it.
SWING Integrator 5 Provides Better Ties between Lotus Notes and OpenOffice
Comment on this... (0 comments) Nov 30, 2006Azaleos Provides Free Microsoft Exchange Cost Calculator Tool
Comment on this... (0 comments) Nov 30, 2006F-Secure Client Security 7 offers deep proactive protection for the corporate world
Comment on this... (0 comments) Nov 30, 2006Accelerate Your Adoption of Application Security Practices
Comment on this... (0 comments) Nov 30, 2006Has phishing become so prevalent that banks cannot use email to contact their customers?
In a recent incident, Citibank Australia sent email to its online banking customers that was confused as a phishing attack. The issue was that Citibank’s email requested that recipients browse to a Web site, authenticate using their card number, account number, and PIN number, and then create their user ID and password — very similar to a standard phishing attack.
This email was met by a backlash from the industry, many pointing out that Citibank contravened its own privacy policy. Security experts issued conflicting statements about the use of email by banks. Some actually urged banks to stop sending email to their customers; others opined that email was still a valid communication medium but consistent messaging and proper security were imperative.
While Citibank believes that its customers are used to receiving email from the bank, and that the email didn’t contain active URLs (except to the bank’s privacy policy), it certainly contained enough "phishy" material for it to be considered suspicious.
In a way, the issue is about the email content. A message regarding new services available or a new borrowing vehicle shouldn’t really set off alarm bells. The above incident requested almost the same action of the recipient as a standard phishing attack. Organizations — not just banks — should avoid sending email to customers that confuse this issue. Unfortunately, phishing attacks are prevalent, so any request for personal information in email should be considered suspicious, no matter what the source.
Please Wait