Re: OT: newsgroup SPAM



johnwallace4@xxxxxxxxxxx wrote:

Anyway, do you actually need an email account/address to *send* spam?

You need to know the host name or IP address of an smtp server
accessable from the compromised PC.

I happily admit that I don't fully understand the typical SMTP/email
setup, I'm not sure exactly how spam would get from a compromised PC
to (for example) my email account(s);

The software on the compromised PC can look into the (e.g.) Outlook
profile and read out the smtp server used to send emails from that
particular PC. Then it is simple to send faked emails throught
the same server.

My ISP has reasently changed from plain smtp to using SSL
when sending emails, so it's not that simple now to fake
emails.

something to do with DNS MX
records and all that, iirc, but it's all a bit vague.

But that is far later in the distribution process, way after
the email has left the compromised PC (and not any different
then deleviering any other email to you or anyone else).

Quite why anybody places any trust in or value on an email mechanism
which hasn't really changed since the era of the teletype and has no
pretence of built in authentication or tamper-resistance is a bit
beyond me, but X.400 email (which addresses most of the underlying
problems) doesn't seem fashionable any more (except perhaps within the
military?).
.



Relevant Pages

  • Re: Exchange Hijacked
    ... >Lot's of spammers use domains that either have no inbound SMTP server, ... find the compromised user account ... Thats a lot of spam and a lot of email addresses, ... > Turn off the ability for authenticated users to realy and see what ...
    (microsoft.public.exchange.admin)
  • Re: SMTP not relaying all emails
    ... The emails are flagged due to having the SMTP Server in another domain, ... If it is spam blocked, the receiver can set it so it allows the GoDaddy ... ADODB.Fields oFields; ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: UOL Anti spam is back, again...
    ... smtp server. ... you gain conformity with RFC's by rejecting it whereas ... obviously rejecting when using fetchmail is a pointless option. ... waste a second of time greylisting it, scanning it for attachments, spam ...
    (Fedora)
  • Re: How long does read(2) wait before an EAGAIN is thrown?
    ... The idea being that if the server is known to be a pure spam source, ... It may also delay/block the connection just because the IP address is ... The idea is to slow the sender down a bit, ... I'm connecting to the Exim SMTP server on my local Linux box, ...
    (comp.unix.programmer)
  • Re: UOL Anti spam is back, again...
    ... Not all mail from uol.br.com is spam - I do get genuine mail ... are summarily sent to the giant bit bucket in the sky and the ... The better place is to reject it at the smtp server and thus, ... Since we can't force them to fix it any ...
    (Fedora)