Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

The state of spam 2009, Part 3

New spam vectors
Security Strategies Alert By M. E. Kabay, Network World
April 16, 2009 12:04 AM ET
Sign up for this newsletter now!

Mich Kabay takes a high-level view of security issues and provides resources to help safeguard your corporate and personal security.

  • Share/Email
  • Tweet This
  • Comment
  • Print

More from Jamie de Guerre, CTO of Cloudmark. Today’s column is a continuation of his response to the question of what has changed in the battle against spam in the last year. All of the text below is de Guerre’s own material with minor edits.

Slideshow: Famous last words about spam

* * *
In 2008 spammers increasingly used free content-hosting services as the call to action in their spam e-mail. Again, spammers know that one way antispam vendors block messages is based on the call-to-action URL or domain in the message, so using many pages hosted by a major free provider enables spammers to have different URLs in each message and a domain name that can’t be blocked.

There are several places spammers can go to host their site content: Google (blogspot, googlepages, etc.), Microsoft (live spaces, live), Yahoo (geocities), social networks (Facebook, MySpace), blogs, and basically anywhere that user-generated content is allowed. This practice became increasingly popular in 2008 and I expect we will continue to see it increase in 2009.

Plus, in 2008 we saw a significant increase in spam sent from accounts created or compromised at free Webmail providers. Another way that antispam companies block spam messages is based on the source IP that the messages come from. If the messages come from a major free Webmail provider such as Gmail, Yahoo, Hotmail or AOL then the anti-spam software cannot block it based on its source.

Spammers capitalize on that by creating accounts or gaining access to existing accounts on these large Webmail services as well as on Webmail services provided by telecom and cable operators. Spammers have figured out how to script the Webmail interfaces to send out their messages and create “family” accounts when using a service that allows multiple accounts. This is clearly an advanced technique, but I expect we’ll continue to see this increase as spammers attempt to find new ways to send messages that escape IP based blocks.

Finally, in 2008 the amount of spam targeting new media other than e-mail grew. Social networks such as Facebook and MySpace were major targets for spam and phishing campaigns, using new techniques that don’t involve e-mail but instead use features that the sites themselves provide to propagate content between users.

Many of these attacks have become quite advanced; for example, in one form of attack spammers create accounts on a major social network site, gather a large number of friends and then change their profile to include a link to a site selling their wares. This type of attack changes the spam vector from a push technique, where they are sending out the message with the advertisement, to more of a pull technique, where they’re attracting friends to their page to come see the ad. Defending social networks against spam introduces many additional challenges, as there are improved communication vectors available and more information exposed.

I expect that in 2009 we’ll see spammers' efforts targeted to new media continue to rise, not only targeting social networks but also other media. Personally, I expect to see a rise in mobile spam in 2009 as well, with Short Message System (SMS) spam and phishing messages growing in popularity.

M. E. Kabay, PhD, CISSP-ISSMP, specializes in security and operations management consulting services and teaching. He is Chief Technical Officer of Adaptive Cyber Security Instruments, Inc. and Associate Professor of Information Assurance in the School of Business and Management at Norwich University. Visit his Web site for white papers and course materials.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed