Great Circle Associates List-Managers
(March 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: massive list subscription bombs (was Possible spam?)
From: edmonds @ cs . ubc . ca (Brian Edmonds)
Date: 22 Mar 1997 22:50:37 -0800
Cc: recipient.list.not.shown:;
>received: from mornir.gweep.bc.ca by edmonds.home.cs.ubc.ca (Sendmail 8.7.5)with SMTP id WAA08623; Sat, 22 Mar 1997 22:50:43 -0800
In-reply-to: Chuq Von Rospach's message of Fri, 21 Mar 1997 22:44:36 -0800
Newsgroups: news.admin.net-abuse.email

I'm copying this up to nana.email, as it appears to be a concerted
attack via email, rather than an isolated incident.  As I discuss below,
it may also related to news, but seems primarily a mail problem.

Chuq Von Rospach <chuqui@plaidworks.com> writes:
> Oh, yeah. There's a lot of spam going down, and a lot of users,
> including many AOL users, being forged onto list.

For the past week I've been noticing a sharp increase in zubscribe
activity on my lists, including a number of people zubscribing to an
unusual spectrum of lists.  Most of the latter I've manually removed
proactively.

This attack has been somewhat unusual in that the lists that are being
attacked are not the digest lists, which the server advertises, but the
regular versions.  These are widely advertised in the PAML and such, but
most obvious attacks I've dealt with before this have been vectored via
the server's lists command, and thus the digests.

> I'm still looking for a clean way to put a procmail filter in front of
> my server and trap this until I can get majordomo up and upgrade all
> my stuff.

Sorry, can't help with the procmail, but I highly recommend majordomo
1.94 (and up).  Last night I finally got tired of all the people who
were obviously being indirectly mailbombed through my lists, bit the
bullet, and upgraded my majordomo from 1.93 to 1.94.1.  Presto chango,
no more wild subscription sprees.

I did get one interesting bounce of a confirm message today from a bad
address someone tried to subscribe.  It was one of those .REMOVE
anti-spam doctored addresses a number of people use for news postings.
This leads me to believe someone is either randomly harvesting people to
attack from news postings, or is running an active campaign against the
posters on particular news groups.

Brian.


Indexed By Date Previous: Current Spam sources...
From: Chuq Von Rospach <chuqui@plaidworks.com>
Next: Re: Current Spam sources...
From: "Gess Shankar" <gess@earthchannel.com>
Indexed By Thread Previous: Re: A list-abuse mailing list?
From: "John Buckman" <jbuckman@shelby.com>
Next: New spam sources...
From: Chuq Von Rospach <chuqui@plaidworks.com>

Google
 
Search Internet Search www.greatcircle.com