Responding to complaints that the Microsoft Network is allowing spammers to relay junk e-mail through MSN servers, the Mail Abuse Prevention System (MAPS) has
added several MSN systems to its notorious anti-spam blacklist. The action
could potentially disrupt emails from thousands of legitimate MSN
subscribers.
SecuritySpace:: MSN Criticized For Open Spam Relays. Story from InternetNewscom, Nov 16 2000 PSINet AT&T caught serving up spam. Story from Info World, Nov 8 2000 http://www.securityspace.com/de/secnews/showmonth.html?month=200011HOME |
MAPS is the controversial California non-profit that maintains databases of
known junk e-mailers. The lists are used by many Internet service providers
to protect their users from unsolicited commercial e-mail. Spokesperson
Kelly Thompson Wednesday confirmed that the organization has placed six MSN
servers on its MAPS Relay Spam Stopper or RSS list, which contains more than
50,000 entries and is used by thousands of ISPs.
"Those MSN relays are a spammer's dream. They are big and high capacity, and
they can send a lot of e-mail fast. You can bounce 10,000 messages off the
relay without them noticing," said Thompson.
Relaying is a tactic used by spammers to conceal the true origin of their
junk email. By exploiting misconfigured SMTP servers,
spammers can avoid being traced and prevent their messages from being
filtered by some anti-spam software. Properly configured SMTP servers do not
allow connections from users who do not have valid accounts on those
systems.
MAPS placed the IP address of the first MSN server on the RSS list November
2, after receiving complaints from Internet users who received spam relayed
through open MSN mail servers. MAPS tested the servers and confirmed the
reports, according to Thompson. Additional MSN server IPs were placed on the
list on November 12 and 13.
Slashdot | Pay-per-email and the "Market Myth":: Hotmail: http://postmaster.msn.com/snds/ [msn.com] . work around open relay-originating spam without having to block legitimate email from open relays, http://it.slashdot.org/article.pl?sid=06/03/29/1411221HOME | almisbar.com directory:: MSN Criticized For Open Spam Relays, Responding to complaints that the Microsoft Network is allowing spammers to relay junk e-mail through MSN servers, http://dir.almisbar.com:99/dir.asp?node=Top/Computers/Internet/Abuse/Spam/News%20and%20Media/2000&bar=HOME |
The RSS list is separate from the MAPS Realtime Black Hole List, which
consists of over 4,000 systems which have been known to harbor junk
e-mailers. More than 20,000 organizations subscribe to the RBL, according to
Thompson.
As a result of the action by MAPS, many legitimate MSN subscribers have had
their outgoing messages blocked by the ISPs who use the RSS. Thompson
reports that MAPS has received over 100 inquiries from affected MSN users
over the past week, an unusually high number. Thompson says MSN support
staff were directing subscribers to take their complaints to MAPS.
SAI Security News Archives 2004:: The guidelines have been criticized for being "vendor-driven." 9 March 2004 - Comcast Cracking Down on Zombie Spam Relays http://www.securityawareness.com/news2004.htmHOME | Proposal on referrer spam: Background and blacklists - jotsheet:: Previously on this site, I have criticized MT-Blacklist. IP against the blacklist maintained at DSBL (a service that keeps a list of open relays). http://underscorebleach.net/jotsheet/2005/01/referrer-spam-proposalHOME |
MSN representatives were not available by newstime for comment, but Thompson
claims the company acknowledged that some of its systems were open relays.
"They said, 'They're easily spoofed, we know it, and we don't know when it
will be fixed.' It doesn't sound like it's not a terribly urgent priority
for them," said Thompson, who estimates that MSN operates dozens of mail
servers, most of which are not vulnerable to relaying.
Ironically, MSN's Hotmail service is a subscriber to the MAPS RBL, and MSN
was recently sued for using the list to block e-mail messages sent by Harris
Interactive, the online polling firm, to Hotmail users.
According to John Levine, operator of Network
Abuse Clearinghouse, MSN has had a spotty record of battling spam.
"This is a longstanding problem. Their mail servers have been a mess for a
long time. And I think there's a good deal of internal tension at Microsoft
between people who say 'This is a mess we need to fix it' and people who say
'No, we need to keep it limping along,'" said Levine.
Brian McWilliams is the host of InternetNews Radio.
SoftQuad Snags XML Content Transformation Firm
W3C Gives Thumbs-Up to DOM Level 2
|