Out of Office SPAM MethodBest Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
TIPS NEWS TOOLS DOWNLOADS MALWARE FORUM BOOKS FREE MAGAZINES FREE WEBCASTS & VIDEOS
GFI LANguard - New Version 9 Out Now - Dld 30-day trial!   $100 Free Sweep   Bookmark and Share 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
2009/12/24 0:00:00
2009/7/3 22:52:05
2009/7/3 22:52:05
2009/7/3 21:32:02
2009/7/3 17:46:40
Our Partners
Downloads
Security Incidents : Out of Office SPAM Method
Posted by Max on 2008/2/26 14:22:13 (1056 reads)
Security Incidents

Spammers are increasingly using 'out of office' features in web-based email to relay junk messages, security experts warned today. McAfee Avert Labs reported several instances where spammers set up web-based email accounts and configured auto responders with spam messages.

The scammers then send email with fake 'from' addresses to their newly created web mail accounts. The 'from' addresses subsequently receive the spam 'out of office' notices.

McAfee noted that, while this may sound like a convoluted way to send spam, it allows the fraudsters to trick spam filters.

An automatic reply from a well-known web-based email service will look legitimate to many spam filtering tools.

In addition, unlike spam sent by botnets, the auto reply spam will have a legitimate sender and will be signed with the correct signatures used to sign email messages, such as DKI or Sender ID.

The auto-responder spam does not look like a typical out of office reply. The message subject always contains 'Re:' because it is added by the web mail service, but the spammer controls the rest of the subject line and the message body text.

"In recent weeks we have seen an increasing amount of spam apparently sent by legitimate web-based email systems," said Jeremy Gilliat, an anti-spam engineer at McAfee.

"I suspect the spammer has a program that automatically creates accounts and sets the responder text, all with no manual work required. This gives the spammer lots of web-mail accounts, all used to spam lots of people."




Other articles
2009/7/1 13:22:13 - Ultimate Firewall : Location Aware WLAN Firewall by Trapeze Networks
2009/6/28 16:04:09 - New Panda 2010 Ultra-Ligh Security Products
2009/6/24 17:08:30 - Red Condor's Spam Trip Wire Detects a New Computer Virus
2009/6/22 4:32:25 - Finjan's Research Unveils Botnet Trading Platform for Hacked PCs
2009/6/22 4:23:14 - Panda GateDefender Integra Delivers 'Plug and Protect' UTM Security Appliance
2009/6/16 15:42:26 - SanDisk Cruzer Enterprise Wins 2009 Product Innovation Award
2009/6/9 9:02:20 - Weekly $100 Sweepstake Launched By BestSecurityTips.com
2009/6/8 11:29:49 - Paretologic Released a New Free Online Malware Scan
2009/6/8 11:13:17 - New Release of Djigzo Open Source Email Encryption Gateway
2009/5/31 17:27:39 - New BitDefender Online Scanner Released

The comments are owned by the poster. We aren't responsible for their content.