Email servers strain under doubled spam load

, posted: 1-NOV-2006 14:30

If you have noticed a big increase in spam lately, you're not alone. My mail server is getting hammered by spammers, and half of Ihug's customers experienced a day-long delay in receiving email.

Much of the spam comes as images - that is, spammers make pictures, with the "sales pitch" text in them. Just about all the image spam I've seen is for illegal pump-n-dump penny stock scams, and they're getting through the spam filters.

I just got a press release from Secure Computing, which included the below chart that says image spam volumes have doubled lately:

Secure Computing

This is vendor supplied information, and should be treated with as such, but everything I've seen so far points to Secure Computing being right. Other sources such as McAfee reckon image spam makes up for around forty per cent of the total spam volume now.

Stopping this kind of spam is difficult, especially since some images are rendered dynamically according the text in them and thus vary in size. I've found some useful rules for Spam Assassin at Wonko.com but have yet to install FuzzyOCR, an optical character recognition plug in for SA. Having to use resource intensive OCR doesn't seem like the right way to go. I'm going to see if I can make use of pf's ability to fingerprint connections from specific operating systems, and firewall off say Windows desktop ones.

Have also heard that "greylisting", which temporarily defers reception of email, is effective here.

Image spam takes up more bandwidth than text-based stuff, which in turn may be one reason the Internet seems to be in go-slow mode at the moment. Haven't had any confirmation about this yet though, so pure speculation on my part.

Where does the spam come from then? Well, it could be your Windows box, compromised using for instance the recent SpamThru trojan horse. The recent spam-flood has been accompanied by many more trojans being emailed out to users as well, I note. Clearly, the spammers are seeking more recruits to their bot armies.








Other related posts:
Flickr targetted in new-style social phish/trojan attack


 





Comment by Matt Beechey, on 1-NOV-2006 21:04

I've installed FuzzyOCR recently but also installed Imageinfo - FuzzOCR only kicks in if all other rules are exhausted and its still below the spam score and it's rarely running for me since updating to newer spamassassin and installing "imageinfo". Theres little documentation on this plugin yet but it analyzes the image sizes (dimensions) etc to determine if it could be image spam - I've had FAR less missed spam emails (around 1 every 2 days) and we get around 100 spam a day AFTER our server has kicked invalid recipients at the door using LDAP lookups. Our spam gateway is only a p3-733 with 256mb ram but it is dedicated for the task and it seems to process the OCR VERY quickly.


Comment by Troy, on 2-NOV-2006 03:05

Here's a link to the Secure Computing page which explains Image Spam and includes a link to a White Paper and Press Release on the subject.


Author's note by juha, on 2-NOV-2006 07:33

Yeah, I'm thinking about putting in the OCR plug in - using Exim with SA-Exim from the FreeBSD port collection and would it to be be tied up with that, for ease of maintenance.


Author's note by juha, on 2-NOV-2006 07:34

Thanks Troy. Inserted the link in the main entry as well.


Comment by Matt Beechey, on 3-NOV-2006 07:11

Just had a case yesterday of a clients email to me leaving their server to callplus at 12:43 in the afternoon - then being forwarded to my server at 11:38pm - thats 11 hours sitting inside callplus/Slingshot's network!!!!!

I accept their servers are getting bogged down with spam etc but thats ridiculous!


Comment by waiotahi, on 3-NOV-2006 20:03

still can't send out on Ihug!!! - how long is this going to last - its been a few days!


Add a comment

Please note: comments that are inappropriate or promotional in nature will be deleted. E-mail addresses are not displayed, but you must enter a valid e-mail address to confirm your comments.

Are you a registered Geekzone user? Login to have the fields below automatically filled in for you and to enable links in comments. If you have (or qualify to have) a Geekzone Blog then your comment will be automatically confirmed and shown in this blog post.

Your name:

Your e-mail:

Your webpage:





Links to stories I've written:

Google News search for me
PC World New Zealand
Computerworld NZ
PC World and Computerworld Australia
PC World US
Computerworld US
Infoworld
NZ Herald
Virus Bulletin
PC World NZ Blog

Content copyright © Juha Saarinen. If you wish to use the content of my blog on your site, please contact me for details. I'm usually happy to share my stuff, as long as it's not for spamblogs and what have you. Attribution with a link back to the blog is always appreciated. If you wish to advertise on my blog, please drop me an email to discuss the details.

Comments policy
All comments posted on this blog are the copyright and responsibility of the submitters in question. Comments commercial and promotional in nature are not allowed. Please ensure that your comments are on topic and refrain from making personal remarks.




    follow me on Twitter





    Add to Netvibes



    Latest comments

    Miki Szikszai on Pacific Fibre cable a bold initiative that the gov: There's more than one pocket the government can take from. And some PPP funds ex...

    sbiddle on ComCom: Don’t forget mobile roaming rates: Traveller as the default option would be horrible - it would mean significantly ...

    Paul Brislen on ComCom: Don’t forget mobile roaming rates: Roaming is set up before customers leave but some customers are still on the old...

    juha on ComCom: Don’t forget mobile roaming rates: @Paul: why not set Traveller as the default roaming option?And "roaming" is a st...

    Paul Brislen on ComCom: Don’t forget mobile roaming rates: If you're signed up with Vodafone Traveller for roaming you get the same rates f...

    gtxboyracer on ComCom: Don’t forget mobile roaming rates: I dont know your sources for that last snippet about roaming in Australia at nat...

    Rory on Hands on with Google Nexus One – briefly: Thats one speedy processor installed in it. Seems like it will browse the net qu...

    Rory on Twitter.com DNS hijacked?: Wow...I hope this one will serve as a warning to the public that sharing too muc...

    lchiu7 on Hands on with Google Nexus One – briefly: I have been using the N1 since the day after it was released since I was in the ...

    juha on Hands on with Google Nexus One – briefly: @Dan C: Quick Google finds this: http://www.becextech.com.au/catalog/product_inf...



    Top Ten Techsplodings

    Telecom New Zealand's local lo...
    (28-APR-2006 17:32, 179468 views)
    Join New Zealand Internet blac...
    (16-FEB-2009 09:26, 133914 views)
    iTunes 7 bugs: doesn't Apple t...
    (14-SEP-2006 12:34, 92903 views)
    Working BIOS driver crack for ...
    (13-MAR-2007 16:14, 51665 views)
    The spoofed Telecom commercial...
    (19-MAY-2006 15:59, 45563 views)
    What did Materazzi say to Zida...
    (11-JUL-2006 08:20, 39748 views)
    Windows Vista problem solving ...
    (24-FEB-2007 18:16, 37878 views)
    Firefox 2.0 and Windows Vista ...
    (3-DEC-2006 12:23, 34113 views)
    Gutmann Reloaded and My Vista ...
    (26-JAN-2007 15:35, 32901 views)
    Apple iPhone GPRS/EDGE only...
    (10-JAN-2007 08:05, 31789 views)




    Subscribe to RSS headline updates from: http://feeds.feedburner.com/Technozone
    Powered by FeedBurner



    Click here to add this RSS feed to AvantGo Click here to add this RSS feed to Feedster Add to Google Click here to add this RSS feed to My MSN Subscribe in NewsGator Online Click here to add this RSS feed to My Yahoo!

    Linkorama

    Bad Science
    Centre for Citizen Media
    Copyblogger
    Daniel McKenzie
    Darren Rowse - Problogger
    Dion Hinchcliffe
    Frankarr
    Fraser Talk
    Griffin's Gadgets
    InternetNZ blog (Colin Jackson)
    KhooSuyinKhoo
    Leaf Salon
    Modern Drunkard Magazine
    Neil Sanderson's blog
    Object Dart
    Off the record
    Rawiri Blundell
    ReadWriteWeb
    Spareroom
    The Assimilated Negro
    The Hivelogic Narrative
    The Opinionated Diner
    The Raw Feed
    Tim Haines
    Wanda Harland
    Kiwi Herald
    Mauricio Freitas
    Hard News
    The Geekzoner
    Mr Cokemaster
    Commercial Archive
    Kiwiblog
    Chiefie's blog
    Generation X Y
    Jama
    Loosewire (Jeremy Wagstaff of WSJ)
    Nic often Wise
    Not the South China Morning Post
    SunnyO
    BlackMagic NZ Film Blog
    Nigel Parker's MSDN blog