Advertisement
Promo

Security threats Toolkit

UK ISPs threaten action over spamming tools

Dan Ilet ZDNet.co.uk

Published: 11 Feb 2005 12:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The London Internet Exchange (LINX) has threatened tough action after MCI, a prominent ISP, was accused of hosting a bulk mailing software application called Send Safe.

Malcolm Hutty, LINX regulation officer, warned on Thursday that the UK ISP community will snub the company responsible for hosting Send Safe, as the tool helps spammers to send massive amounts of mail across the Internet.

"Send Safe's product clearly provides features that are designed to make spamming easier. As such this is exactly the kind of product we are trying to stop," said Malcolm Hutty, regulation officer at LINX.

"ISPs depend on voluntary mutual cooperation for the effective functioning of their core business. ISPs that ignore community standards risk losing the cooperation of their peers, which is more valuable than any one customer could ever be," Hutty added.

LINX's 170 members -- including UUNET, which is part of MCI WorldCom -- use the exchange to swap Internet traffic.

On Monday, anti-spam campaigners at Spamhaus accused MCI of hosting the Send Safe Web site, but MCI denies this charge.

An MCI official told ZDNet UK that the Send Safe Web site was hosted by a company that leased a line from it. MCI also says that it does not censor the content of its customer Web sites.

LINX warns, though, that software designed to assist spamming makes a major and harmful contribution to the prevalence of spam. Its best current practice guide calls on ISPs to prohibit customers from distributing spamming tools and to take action to enforce this, "up to and including terminating the customer's contract".

LINX said that its 170-strong membership in the ISP community, had "collectively decided that condoning this kind of customer abuse is to make [oneself] part of the problem".

Spamhaus believes that tools such as Send Safe are responsible for a huge increase in spam.

"This Send Safe feature instructs its hijacked proxies to send the spam out via the upstream ISP's main mail server (instead of the proxy sending the spam out from the infected machine itself). This means that billions of spam emails now flood the Internet coming from the main mail servers of large ISPs," warned Spamhaus in a recent report.

Security experts at MessageLabs have confirmed that Send Safe was malicious and was able to manipulate any computer that was infected with the Sobig, Sober and MyDoom viruses. It could then force those computers to send spam via an ISP's mail server to avoid being blocked by a blacklist of domain names used by known spammers.

"There's a new version of Send Safe affecting anything with blacklisting capability," said Mark Sunner, chief technology officer for MessageLabs, earlier this week. "Are we going to see more spam because of this? Yes. I don't want to be accused of scaremongering, but we are."

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
57 out of 94 people found this useful


Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters