Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Full Disclosure: Re: Spam sent via spambots?

Re: Spam sent via spambots?

From: J.A. Terranson <measl_at_mfn.org>
Date: Sun, 31 Oct 2004 18:22:36 -0600 (CST)

On Mon, 1 Nov 2004, Nick FitzGerald wrote:

> In another thread Hugo van der Kooij wrote:
>
> > Securing every machine on the internet would be a good start. 95% of all
> > spam messages I have seen lately gets send from DSL or Cable IP addresses.
> > These are machine which run spamware without the user knowing (s)he is
> > sending out spam by the buckets untill their ISP shuts them down.
>
> Really?
>
> 95%?
>
> Does anyone have sound statistics on how much spam comes from DSL/Cable
> IP-space?

We see at minimum, several thousand a day, and while I can't give you a
statistic, I can state with great confidence that the vast majority,
likely a lot higher than 95%, comes from zombied machines, almost all on
DSL/Cable space.

> And further, does anyone have any idea how to pick apart how much of
> that is simply relaying type activity vs.dedicated spam-bot activity?

Does it matter?

-- 
Yours,
J.A. Terranson
sysadmin_at_mfn.org
0xBD4A95BF
	"An ill wind is stalking
	while evil stars whir
	and all the gold apples
	go bad to the core"
	S. Plath, Temper of Time
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
Received on Nov 01 2004
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]