Advertisement
Promo

Security threats Toolkit

MCI accused of harbouring spammers

Dan Ilet ZDNet.co.uk

Published: 07 Feb 2005 18:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Anti-spam campaigner Spamhaus has accused US-based Internet service provider MCI of hosting a Web site that distributes malware used by spammers.

In an article published on its Web site last Friday, Spamhaus alleged that the telecoms giant's servers are home to the Web site of a 'bulk-mailing' programme called Send-Safe.

Spamhaus said that Send-Safe takes remote control of broadband computers. This enables spammers to use these compromised computers, or zombies, as proxy servers to send masses of emails without the owners' knowledge. As reported last week, this can let a spammer evade spam blacklists.

"This for Spamhaus is the crux of the spam problem," the report said. "Because MCI WorldCom not only know they are hosting the Send-Safe spam operation, MCI's executives know send-safe.com uses the MCI network to sell and distribute the illegal Send-Safe proxy hijacking bulk mailer, yet MCI has been providing service to send-safe.com for more than a year."

Later in the report, Spamhaus wrote that MCI executives have refused to stop providing services to spam gangs.

"For over two years Spamhaus has repeatedly informed the same MCI executives that the distribution of 'stealth' anonymous spamware is also illegal in the State of Virginia where MCI UUNet is based," said Spamhaus.

"In other words, we do not simply see MCI's knowingly servicing known spam gangs as highly unethical activity for an ISP to be involved in, we also see it as being illegal in MCI UUNet's home state."

However, MCI has denied that it hosts the Send-Safe Web site, saying that it was hosted by another company that leased a line from it.

"I'm familiar with the allegations," Timothy Vogel, director of MCI's technology and network legal team, told ZDNet UK. "Every Internet provider has spammers on its network. If they send spam, that's a violation of policy and we would take action to take them down.

"At this moment we have no complaints of Send-Safe sending spam. Send-Safe certainly could be used for illegal purposes. But if someone used a crowbar to burgle a house, you don't arrest the hardware store. We take the allegations very seriously."

Spamhaus refuted Vogel's claims, insisting that it had found the Web site to be linked to the telecoms company's network.

Security experts at MessageLabs confirmed that the Send-Safe program was malicious. According to MessageLabs, Send-Safe was behind a recent spate of spam attacks on Internet service provider mail servers. It added that the program was able to manipulate any computer that was infected with versions of the SoBig, Sober and MyDoom viruses, using them to send spam via an ISP's mail server to avoid being blocked by a blacklist of domain names used by known spammers.

"There's a new version of Send-Safe affecting anything with blacklisting capability," said Mark Sunner, chief technology officer for MessageLabs. "Are we going to see more spam because of this? Yes. I don't want to be accused of scaremongering, but we are."

"Here we have a brilliant example of how spammers have found a way of getting around filtering. You can bet your life that service providers are seeing a big increase in traffic on their mail servers."

Spamhaus said that new versions of Send-Safe were being released on the same time frame as new SoBig virus variants, suggesting a link between the program and the virus.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
56 out of 104 people found this useful



Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

DNA details of innocent will be kept f...

The government has announced that it plans to keep innocent people's DNA details for up to six years. In response to a consultation it launched last December, the government said... More

3 comments

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters