Tracking Spam to the Source

posted more than 12 years ago

Spam 366

cygnusx writes: "MSNBC is carrying a Wall Street Journal article on one reporter's attempts to track the spam she receives to the source. Armed with a few Hotmail and Yahoo accounts, reporter Stacy Forster actually responded to most of the barrage of spam she began to receive after a week or so. Not quite the best investigative jounalism ever seen, but still a good glimpse (or so I thought) at those who send us those unloved missives about "exciting business opportunities" and "millions of $$$ waiting"."

Spamcop in Time (1)

dickens (31040) | more than 12 years ago | (#2980041)

There's a good article on in time this week. They do seem a little slower lately.

All we need is.. (0)

Anonymous Coward | more than 12 years ago | (#2980046)

A beowulf cluster of these reporters to put a stop to all the spam!

Re:All we need is.. (3, Funny)

reemul (1554) | more than 12 years ago | (#2980057)

Bloody hell, is there any way to filter out all posts with the phrase "beowulf cluster of these"? I'd even give up my Jon Katz filter if I could turn off these mindless attempts at humor. "All your base" died months ago, why the hell is this still popular?

Taco, Hemos, anyone, is there some way to stop seeing these damn things?

Re:All we need is.. (1, Funny)

Anonymous Coward | more than 12 years ago | (#2980159)

All your beowulf are belong to us

I know where the Spam is coming from (0)

The_Shadows (255371) | more than 12 years ago | (#2980053)

It's all coming from Monty Python and their Vikings.


Bellsouth = Spam (5, Interesting)

Renraku (518261) | more than 12 years ago | (#2980056)

When I signed up for their ADSL service, I used a very odd username which I haven't used before, nor have I ever seen. I checked my email a day (after the account was made, not after I got DSL) later and guess what? Two email from Bellsouth, one from some porn company. I posted my findings to DSL reports, and got fired from my tech support job at Bellsouth DSL for that.

Re:Bellsouth = Spam (4, Insightful)

Pituritus Ani (247728) | more than 12 years ago | (#2980122)

Did you contact an attorney about suing for wrongful termination? Can you provide a link to your post?

Re:Bellsouth = Spam (2)

Sc00ter (99550) | more than 12 years ago | (#2980136)

Wrongful termination for what? If you're working for a company, and you speak out about them, they have every right to fire you. I've seen it happen before.

Re:Bellsouth = Spam (2)

Sarcasmooo! (267601) | more than 12 years ago | (#2980151)

In the case of unsolicited email maybe a whistleblower's defense would've protected him.

Re:Bellsouth = Spam (2, Insightful)

Pituritus Ani (247728) | more than 12 years ago | (#2980157)

They may technically have a legal right, but they certainly don't have a moral one.

And laws aren't that cut and dried, and various states and localities have laws to protect workers from this and similar kind of capriciousness. In fact, some companies unknowingly tie their own hands with internal policies allowing grievances, etc. An attorney can help exhaust those options--a legal aid attorney can help a wrongly (legally or morally) terminated worker in this kind of situation at least cost their former employer some time and money, and maybe even obtain some severance in return for a promise not to sue. And if that doesn't work, he can always puruse an Office Space type remedy :).

Re:Bellsouth = Spam (1)

BlueUnderwear (73957) | more than 12 years ago | (#2980222)

And if that doesn't work, he can always puruse an Office Space type remedy :).

Please do! You'll be applauded by the zillions of Bellsouth spam victims worldwide. It's burning time!

Re:Bellsouth = Spam (1, Insightful)

Anonymous Coward | more than 12 years ago | (#2980168)

IIRC, whistle-blowers get some protections, but only if the issue is with employee or public safety. This just sounds like a sign that they're a bad place to work with/for. Unfortunatly, it's impossible to NOT deal with BellSouth in some way (even with CLEC phone service: It's still BellSOuth's wirecenter and wires) in the States they service/scam. But at least they TRY to work with CLEC's, unlike Verizon, which just pays the FCC fines for non-compliance every time.

Re:Bellsouth = Spam (2, Interesting)

linzeal (197905) | more than 12 years ago | (#2980156)

Well until the tech workers unionize you are going to get shit on. I contracted for SBC and saw the same thing happen to a guy in project management who finnaly snapped and told a customer on a 700 million dollar deal that we can't get the VPN/DSL installs on time because we have no process or process engineer and no one wants to take responsibility for a 700 million dollar deal gone bad.

Re:Bellsouth = Spam (0)

Anonymous Coward | more than 12 years ago | (#2980195)

My ISP (hint: Eastern Canada, and they claim they can see the future from here) regularly sells the username list to spammers. Either they do officially, or one of their wonderful support folks do it on the side. Either way it doesn't matter, you set up a new email address with as wacky a name as you want, and within a couple of days it's getting spam.

Just use PINE and... (4, Interesting)

Colin Bayer (313849) | more than 12 years ago | (#2980058)

turn on "enable-bounce-cmd" in your prefs. Open the spam, hit "B", tippity-tap out the source e-mail address (or flex your gpm muscles if you're so inclined), and off it goes back to the sender; alternately, do your best to fudge a mailer daemon bounce. When they get the message, 9 times out of 10, they stop sending. Failing that, just redirect known bad domains (I do this with Yahoo and Hotmail because I don't know anybody who uses those accounts) into a spam folder; check it occasionally to make sure the signal-to-noise ratio is non-zero.

It's not worth getting all hot and bothered over some "INCREDIBLE MONEY MAKING OPPORTUNITY" someone felt like telling you about.

On another note, check out somethingawful's pranks section under spam for Lowtax's take on the whole thing. :)

Re:Just use PINE and... (0)

Anonymous Coward | more than 12 years ago | (#2980065)

check it occasionally to make sure the signal-to-noise ratio isn't non-zero.

Oops, my mistake. :)

Re:Just use PINE and... (5, Insightful)

forkboy (8644) | more than 12 years ago | (#2980073)

I bet that works great when the source address is spoofed.

Re:Just use PINE and... (1)

Colin Bayer (313849) | more than 12 years ago | (#2980092)

Heh... should've included a YMMV disclaimer. The server that provides my e-mail is set up not to accept any incoming mail claiming to be from source addresses outside of the source server's domain.

Re:Just use PINE and... (2, Funny)

fatgraham (307614) | more than 12 years ago | (#2980096)

i just close my eyes and hope it goes away.

luckily outlook crashes before i open my eyes again. (karma whoring microsoft bashing there, i find it moderatly stable nowadays)

OS X Mail has this too (2, Informative)

stego (146071) | more than 12 years ago | (#2980180)

Select Message->Bounce to Sender, or Option-Command-B if you do this often...

Ironically, Junkbuster. (3, Interesting)

oregon (554165) | more than 12 years ago | (#2980059)

junkbuster [] blocked 15 images from loading in that one article.

Re:Ironically, Junkbuster. (2)

Suppafly (179830) | more than 12 years ago | (#2980137)

yeh.. that site popped up a "you've won a free toolset from the american homeowners association.." ad..

My favorite part of the article? (2, Insightful)

Stinky Boy (107316) | more than 12 years ago | (#2980060)

The popunder for the "World's Largest Casino." (NOT)

Re:My favorite part of the article? (2, Interesting)

trentfoley (226635) | more than 12 years ago | (#2980201)

The popunder for the "World's Largest Casino." (NOT)

If by (NOT), you mean the popunder did not happen, then disregard this post. Otherwise... I tried loading the msnbc page several times from various boxes and could not get a popunder to appear.

Are you sure you don't have something installed inadvertently that creates these popunders? If you haven't already, give something like AdAware [] a try to see just what is lurking about.

If you are absolutely sure that you are getting popunders from msnbc, then why the hell am I not getting them! I hate feeling left-out.

Recommendation (5, Informative) (184378) | more than 12 years ago | (#2980063)

The article says the FTC recommends that you forward all of your spam to I know I will be doing so from now on...

Re:Recommendation (0)

Anonymous Coward | more than 12 years ago | (#2980072)

I wonder what kind of pipe that is connected to? Anyone want to guess from the traceroute to their mailservers what kind of backbone they have?

Re:Recommendation (0)

Anonymous Coward | more than 12 years ago | (#2980130)

So, I'm taking this to mean that instead of having a nice procmail folder named .spam I should just use procmail to forward all that stuff on to the FTC. Maybe everyone else should do this too.

Re:Recommendation (1, Redundant)

linzeal (197905) | more than 12 years ago | (#2980133)

I wish I could do that for all the IRL junk mail I get as well. If the FTC is in washington that would probably require billions in additional mail radiation devices. Can you bankrupt the FTC, lol?

Re:Recommendation (1)

mmontour (2208) | more than 12 years ago | (#2980200)

I wish I could do that for all the IRL junk mail I get as well.

With junk mail that provides a postage-paid reply envelope, just throw out anything that has your name on it and mail the rest of it back to the sender. They can then re-use that material (saves trees), and it also creates jobs for the post office.

The man behind the curtain... (-1, Funny)

Click on the link to the article.... (1, Interesting)

Atrahasis (556602) | more than 12 years ago | (#2980071)

....and you get a pop-up banner offering you the best casino the net has to offer.


Re:Click on the link to the article.... (1)

attiladehun (469422) | more than 12 years ago | (#2980237)

and Mozilla prefs prevent javascript from opening windows by themselves! Unless you don't like mozilla.

There is, on the other hand, a very interesting trick for staying "in the game" when your tongue is getting tired. Switch from moving your tongue directly, to using your whole jaw to move your tongue, by slightly opening and closing it. If you tire of this, move your entire head, so that it's doing the actual work that makes your tongue move. When even your neck tires, it's on to the final backup-plan, but the one that works the longest; gently rock your entire body back and forth, at the same speed that you were doing each of the other, so that it's your body that's actually doing the work to move your tongue. For someone who hasn't built up the mighty endurance that's useful with a lover who can have hours of orgasms, this is a great trick. Of course it mainly works when you're going simpler, rhythmic the fancy tongue stuff for when your tongue's doing all of the work (you should be able to switch back to tongue-only motion regularly, as it gets rested).

An alternative approach to SPAM filtering (5, Interesting)

chrysalis (50680) | more than 12 years ago | (#2980114)

Instead of using SPAM filters (accept everything by default, deny some mails according to filters), a new and very efficient approach is to do like firewalls :
  • Deny everything by default
  • Only accept mails from known sources.

Software like TMDA [] implements this. When a mail comes from an known source, an automatic confirmation mail is sent by the script. If the sender acknowledges, his address will be added to the 'whitelist'. No more confirmation will be needed.
This is extremely efficient, and it basically reduces the SPAM actually delivered to your mailbox to zero.
Just don't forget to manually add mailing-lists you're subscribed to, to the 'whitelist'.

Re:An alternative approach to SPAM filtering (1, Insightful)

Anonymous Coward | more than 12 years ago | (#2980248)

I like TMDA a lot. The biggest problem I have is that a surprising number of people have trouble understanding they need to send a confirmation for their first message to be delivered.

When a mail comes from an known source, an automatic confirmation mail is sent by the script.
That should have read "from an unknown source"

I want to know HOW they got her address... (5, Interesting)

writermike (57327) | more than 12 years ago | (#2980121)

I want to know about one more part of the story.

She says she signed up a Yahoo account, bought one book from and promptly received spam thereafter.

Sooooo.... if Borders _and_ Yahoo both say they there's no way the e-mail could have been sent out by either of them -- (and if the reporter is completely accurate about her sequence of events) -- how did the company get her e-mail address?

Either someone's lying, is mistaken, or her e-mail address was "created" through some sort of bruteforce e-mail address creation application.



Re:I want to know HOW they got her address... (2, Informative)

oregon (554165) | more than 12 years ago | (#2980148)

Borders and Yahoo just said they didn't sell the address.

The spammer said he used "an e-mail harvesting program called Target 2001 ... [which] ... scans Web sites and databases for addresses ."

So it is possible that neither Borders or Yahoo are lying ... but that there is a security/privacy flaw in one or both of the sites which lets the address be harvested.

from the story.. (2, Informative)

Suppafly (179830) | more than 12 years ago | (#2980123)

The FTC encourages consumers to forward unsolicited commercial spam to

Guess I have someone else than to forward unsolicited spam to now..

I want server configured from client (5, Interesting)

GCP (122438) | more than 12 years ago | (#2980131)

I think we should have a server feature that is configurable from the client. The client would be able to tell the server that if a message has certain characteristics, the server should respond to the sender in the same way it would respond if the address didn't exist at all.

Any message that your client would filter into the trash, your client should be able to tell the server to bounce.

Perhaps we could also use the "plus convention" to allow users to effectively manage their own email address(es). Many servers are set up so that if my assigned email address is, then fred+[anystring] is still sent to fred. Tell your friends to address you as, and then have your client sort the "+friend" messages into a friends folder.

Why not be able to create a list of valid plus extensions in your client, which would then post them to the server? Why not be able to create your own rule for messages that arrive with no extension? You could instruct your client to instruct the server to accept them or to bounce them back to the sender as simply nonexistent addresses.

You could create an extension in your client and specify an expiration date. Your client informs the server. Then you post your email address publicly, a Usenet question perhaps, and your server would accept responses until the date you specify, and then bounce everything thereafter as spam.

With so many addresses expiring quickly and users able to get their servers to hide their non-expiring addresses from mail with certain characteristics, the spammers databases would become much less usable.

Re:I want server configured from client (5, Interesting)

Saeculorum (547931) | more than 12 years ago | (#2980219)

GCP says: Perhaps we could also use the "plus convention" to allow users to effectively manage their own email address(es). Many servers are set up so that if my assigned email address is, then fred+[anystring] is still sent to fred. Tell your friends to address you as, and then have your client sort the "+friend" messages into a friends folder.

I think that's a good idea, but only a short-term solution. If it ever becomes wide-spread, spammers will just use brute force and send emails to It wouldn't even be that hard - most likely, people would somewhere accidentally post their "secret" email address (which happens right now) and a spambot would pick that up. Above that, most people would use common words, "secret", "spam", "free", etc. There would be huge incentive to break the system for the spammer - if they're the first to find out how to bypass the secret system, their spams are able to be read by everyone, while other spams will be filtered out. It'll simply be a race to be the first spammer to be "heard".

The solution must inevitably be, in my mind, to make spam cost something. Not necessarily money, but some sort of tangible resource. Various solutions have been proposed, all of which in my mind are not completely up to the task. However, they're the only effective long-term solution. So long as spam is free, there's no disadvantage to sending 1,000,000 emails to get one responce. I personally like Adam Backs' Hashcash program, which is at> [] . However, the site seems to be down at the moment, so one can use Google's quite convinient cache of it at [] .

Don't you think... (5, Funny)

whipping_post (521700) | more than 12 years ago | (#2980134)

...the reporter could have gotten more info if she didn't keep telling these people that she is a reporter?!?!

How's this for investigative journalism?
1. Locate Spammers
2. Call and explain to spammers that you are a reporter
3. Determine if spammer has hung up
4. If step 3 is yes, call spammer back and leave message
5. Repeat

Re:Don't you think... (1)

Suppafly (179830) | more than 12 years ago | (#2980147)

Yeh she should have borrowed some money from her boss and acted legitimately interested when she called these people.. then she should have got a bunch of info about them and posted that in her story..

Email is becoming worthless (1, Interesting)

Anonymous Coward | more than 12 years ago | (#2980143)

At the current rate of spam increasing everyones mail accounts will be made unusable with in the next 2 year or less.

So people should just bounce all html mail. What ever mail client that you use. As almost all porn mails require to download images from somewhere or try run some Javascript.

Report spam to ISP concerned and ask politely your ISPs to start implement RBL lists.

If people do not stand up a shoud we dont want this junk, email will die.

RIP 2002 Email accounts the world over.

Track down the scum (2, Interesting) (142825) | more than 12 years ago | (#2980149)

Put terms of use on your websites to prohibit email collection. Use a unique email address on the site, so it can be tracke.

Then when the spammer emails to it, track them down, file a large lawsuit for copyright infringment, tresspass to chattel, computer tresspass and fraud.

Bankrupt a few spammers, others may think twice before spamming

Re:Track down the scum (1)

AntDaniel (553730) | more than 12 years ago | (#2980240)

I tried a track down once. Had a nice hotmail account, no numbers!! Eventually the amount of spam outweighed the useful content. So I got active. I don't know what went wrong, either a idiot sysadm got one of my replies or I got targeted by one of the spammers, but hotmail closed my account. They would only tell me that 'sending of unsolicitated email was against their usage policy' then refused to reply to any further emails from me!! Idiot's just didn't understand. Glad I did it from hotmail, I could have lost my ISP account!

She needs a better way to fight spam (1)

jsse (254124) | more than 12 years ago | (#2980152)

say, procmail+spamassassin

"SpamAssassin is a mail filter which attempts to identify spam using text analysis and several internet-based realtime blacklists."

In short, it analysis incoming mails and throw spam away.

Of course, that's not something a layman could setup, even though I found it easy.

Beware spammer dictionary-attack (4, Informative)

Seth Finkelstein (90154) | more than 12 years ago | (#2980154)

Quoth the writer:

In only one of the e-mail accounts, I provided all of the information requested (name, address, demographics, etc.) during the registration process, and I used this e-mail address just one time - to purchase a gift certificate from Less than a week later, the spam started rolling in - jamming the in-box with more spam than the other new accounts I had created.
The writer seems to think spammers couldn't get the address unless they got it from This may be unfair. What spammers sometimes do is to dictionary-attack ISPs, trying lists of usernames (after all, what do they care if the mail bounces - it's not like it's THEIR problem ...). Once they find an address works, (by not having it bounce), they sell it to other spammers as a "verified" address. I saw something similar happen where an account I only used to received a few mailing lists (never send) suddenly received a huge upsurge in spam. The list-maintainers were above reproach, they hadn't sold the user list. What seemed to have happened is that spammer found the address in a dictionary-attack, and then it was all over ... :-(

Sig: What Happened To The Censorware Project ( []

Re:Beware spammer dictionary-attack (3, Interesting)

sqlrob (173498) | more than 12 years ago | (#2980204)

What spammers sometimes do is to dictionary-attack

That's one hell of a dictionary attack. From the article(emphasis mine):
Using my name and a combination of six numbers, I created a few new accounts through free online services such as Microsoft Corp.'s Hotmail and Yahoo Inc.'s YahooMail.

Give those SPAMMERs a taste of their own medicine (2, Interesting)

BillTheKatt (537517) | more than 12 years ago | (#2980160)

I've been sending SPAM to abuse/postmaster/ for months, but most ISPs will just terminate the account if they even bother.
We should be encouraging hackers to point their skills towards a noble goal: shutting down SPAMMER websites. SPAMMER's would take notice when their sites were hacked and redirected to Spamcop. And ISPs would really start to check accounts if their service became a transport for DDOS attacks against a SPAMMER.
Come on hackers it's easy. Create a hotmail account and post just once to USENET. I'm still getting SPAM 4 years after posting 1 message to USENET with a real address. Do something positive to the Internet community for a change. Get to work hacking those jerks' sites!

Re:Give those SPAMMERs a taste of their own medici (0)

Anonymous Coward | more than 12 years ago | (#2980247)

And who's going to complain when a few spammers website are shut down?


It wouldnt be so bad... (0)

Anonymous Coward | more than 12 years ago | (#2980172)

...if only the spam I recieved was actually targetted to me. I dont want or need viagra/work/a degree/porn adverts, they are by default wasted money. If on the other hand I'd get cheap hardware/palmpilot/cool tech toys/gadget adds, I would probably be a little poorer :)

Email harvesters: an answer? (2, Interesting)

FyRE666 (263011) | more than 12 years ago | (#2980189)

I've been thinking about this...


The only way to stop spammers is to make spamming unprofitable.

Their profit depends upon harvesting usable email lists, so there's a chance some idiot will buy something after reading their garbage.


Dilute their mailing lists with so much garbage they'll only actually send out one or two emails to real addresses for every X thousand mails sent to fake addresses.

Method idea:

What if I put together a quick CGI to generate pages with fake text (just paragraphs full of random picks from a dictionary + punctuation) plus randomly created email addresses. Then linked to the chain of 1000's of fake pages from one of the real pages of my sites? What if I allowed anyone to use this tool for their own sites, to generate 1000's more, or made an online tool to generate pages and email them on to people to upload for their websites?

Anyone think this is a good idea? Obviously it's a trivial piece of scripting, but I think if major sites used something like this, it would seriously piss off a lot of these lowlifes...

Re:Email harvesters: an answer? (3, Interesting)

travisd (35242) | more than 12 years ago | (#2980214)

You mean line Wpoison? []

Idea for getting removed from e-mail databases. (5, Interesting)

e_n_d_o (150968) | more than 12 years ago | (#2980193)

This is probably old news, but its just a thought.

What if it were required by law that every company must track WHERE and WHEN they obtained any e-mail address that they send bulk messages to. If you requested to be removed from their list "recursively" the offending company would have to notify its provider. Each company would have to notify any company they bought the address from that you want your information kept PRIVATE. The recursive notification would only go UP the chain. I'd love if it they had to notify everyone they sold it to as well, but this might not be practical. Each provider would send you a message as they removed you from their list. Each company would have to keep your e-mail address on a black list for a period of time you specify (such as "until hell freezes over") and not send you further mesasges until that time elapses.

You would have as evidence the date/time you were removed and would have grounds for damages in the event that someone repurchased your address from a provider or they didn't remove you.

Until then, I'll just continue to give my email address out as
So far, 99% of the spam is coming from, which is about to be automatically filtered and deleted.

We need to pass a law... (0)

Floydian123 (317261) | more than 12 years ago | (#2980196)

We need laws that allow us to sue people if they don't stop spamming us - such as with the "take my off your caller list" idea with telemarketers - since some of my spam has no "remove" at the bottom :/

At least I can dream :D

A (partial) solution... (2, Informative)

Tabercil (158653) | more than 12 years ago | (#2980215)

My dad was complaining bitterly about the volume of spam he was getting as a result of signing up to get a online greeting card (no I don't remember which site) since he's on a dialup account with fixed number of free hours each month. Downloading and deleting the spam effectively ate into his hours. A quick installation of Mailwasher [mailwasher.nett] (which serves to send messages back marking it as undeliverable) served to quiet him afterwards since he now feels like he's doing something to stop it.

What I think I might want to check is to see if it can't also directly forward the original email to that ftc mail address...

