elfs: (Default)
[personal profile] elfs
Dear Pendorwright User:

We have recieved complaints that your account was being used to send unsolicited commercial email. Your email service has been suspended. Please contact us here and enter your username and password to re-enable your email service.

Sincerely, The Pendorwright Support Team
I've elided the link URL. I received this the day after I had completed a security survey and had a third party independently confirm that there was no external evidence of virtualization of the Pendorwright machine (i.e. nobody else was seeing any unusual traffic on the wire).

Sorry, this was just too amusing. Have these people no brains at all?

Date: 2007-03-13 04:51 pm (UTC)
From: [identity profile] pixel39.livejournal.com
I got a bunch of those a while back from "The Hundred Acre Wood Support Team". Never mind that the domain right is only an mx record and the "team" is me. I laughed.

Yes, they have no brains.

Date: 2007-03-13 04:51 pm (UTC)
From: [identity profile] pixel39.livejournal.com
"the domain right *now*..."

Date: 2007-03-13 04:55 pm (UTC)
kengr: (Default)
From: [personal profile] kengr
Oh, *that* sort of stupidity. I thought Elf was referring to a *real* message from support.

Yeah, I've been getting that sort of thing too. nd since I'm all but two of the users on my domain, it gets kinda obvious, y'know.

Date: 2007-03-13 04:53 pm (UTC)
kengr: (Default)
From: [personal profile] kengr
Ah, but they've received *complaints*.

I recently received almost 6000 bounced messages that purported to come from an account in my domain and to have been sent via the mail server on the box that hosts my domain.

Of course, examining the Receieved lines showed that the "first" one was a forgery.

Probably more trouble than the idiots you are dealing with felt like going to.

Date: 2007-03-13 05:05 pm (UTC)
From: [identity profile] sirfox.livejournal.com
if you think that *these* folks are brainless, you should meet the folks who fall for it.

No, actually, you shouldn't. Nobody should. it hurts too much.

Probably due to changing ISP requirements

Date: 2007-03-13 05:33 pm (UTC)
From: (Anonymous)
They may not have brains, but they had hope. And volume. Lots and LOTS of volume. (From The Smoking Gun: "spammer" (http://www.thesmokinggun.com/archive/years/2007/0312071clifford2.html))

I have to figure it's due to the fact that many ISPs now require authentication for SMTP. We end up moving with some regularity, and I've noticed that the default config has changed over the past... oh, about a year and a half. Every one of them (3 in my completely invalid statistical sample) has required you have an email account with them and use its credentials to authorize outgoing mail. Once that requirement is met, they don't give a hoot what the return address is. I guess wi-fi has changed things to the point where "if you're using us to connect, you can use our mail server" doesn't apply any more.

As I read your comment I couldn't help but start trying to figure the math to describe something like this... for the set of (x) attempts, there is the subset of (n) successful phishing attacks. Of those (n) accounts another subset (d) will be relatively quickly disabled, but (s) will be used -- to great volume -- to send spam through mail servers that people are going to be more hesitant to blacklist. Here's hoping (s) is a very small number (sadly, it won't be) and the ratio of (n)/(x) is skewed to indicate greater human intelligence and suspicion (again, I don't see it happening). The relationship of (x-n) to (d) to (n-d) to (s) shows the relative sizes of the population that are (1) paying attention, (2) too trusting but still paying some attention, (3) gullible and (4) oblivious.

Eeep... I think I'm gonna go hide now. I don't like how those numbers are going to come out, especially where I'm living now.

Bryan.

Date: 2007-03-13 11:26 pm (UTC)
From: [identity profile] srmalloy.livejournal.com
It's probably too much trouble to set up, but it would be entertaining to feed them a bogus username and password, and have a modded login that would automatically block hosts that attempt to connect with that username...

Profile

elfs: (Default)
Elf Sternberg

May 2025

S M T W T F S
    123
45678910
111213141516 17
18192021222324
25262728293031

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jun. 14th, 2025 01:13 pm
Powered by Dreamwidth Studios