Jan 27 2005 @ 14:08:21

The War Against Spam Bots

(5)
0
-Use the "Cached" link in Google to view this story if you can't access the site-Spam bots are searching the pages of the net, thinking they can get their referrers published on blogs.

They're easy to point out in the list. They usually have referrers like:
http://star-poker.tecrep-inc.net/,
http://cialis.tecrep-inc.net/,
http://poker-tournaments.tecrep-inc.net/,
http://student-loan.tecrep-inc.net/,
http://mortgage-company.tecrep-inc.net/,
http://poker-tables.tecrep-inc.net/,
http://poker-rooms.tecrep-inc.net/,
http://mortgage-broker.tecrep-inc.net/,
http://internet-poker.tecrep-inc.net/,
http://home-mortgage-loan.tecrep-inc.net/,
http://casino-poker.tecrep-inc.net/,
http://poker-hands.tecrep-inc.net/,
http://texas-mortgage-loans.tecrep-inc.net/,
http://free-online-poker.tecrep-inc.net/,
and various other subdomains of "tecrep-inc.net".

so, after blocking referrers that contain "tecrep-inc.net", they show up again...using an IP as a referrer:
http://12.163.72.13/. Now the IP is included in the referrer block list.

Just looking at where these requests are coming from, i'd say they're computers that are infected with a Trojan. An army of drones that browse the net looking for more computers to infect and collect email addresses on the net to send spam to, and while they do so advertise websites that collect more email addresses.

If this isn't orgenized crime, I don't know what it.

The registrant of these domains is a "Jane Phill" (fake name), 61 Street, NYC (fake address). Other domains have also been registered with that name to be used in the same manner.

I used the term "orgenized crime" above. Let me show you why.
Spamming is a multimillion dollar "business" that script kiddies and criminals use, to make large sums of "easy" money. The business model is roughly as follows:

Let's say you make money by selling placebo wrapped in Viagra packaging.
You need people to sell your products to. To be more precise, you need idiots that are new to the internet to sell your products to. You need advertising. You need a target audience that is stupid enough to read your messages and buy your products.

What you need is a way of directly advertising your products to as many people as possible. And since you're selling fake viagra, you aren't exactly worries about the legality of spamming. All you know is that you need idiots (your target audience) that read spam with the same joy they read christmas cards.

Who? Me?
So you want to send out spam, but you don't want to get caught. You hire someone to send the spam out for you. You hire Self.Propelled.Advertising.Mailers Inc, a script kiddie group that sends out your spam for you. But the good people at S.P.A.M Inc don't want to get caught either. Here's where the same idiots that buy your products come in.

"Why the hell is my computer so slow?"
Enter "Joe". Joe has just bought a brand new computer. He's 50 years old and never used a computer before, but he's pretty sure he knows what he's doing. He also got himself an internet connection.

Joe thinks he's pretty good with computers, so he reads the manuals and sets up his internet connection all by himself and after only 30 minutes, Joe is enjoying his first porn site.

After clicking around for 10 minutes on links and images he has never seen before, his computer crashes. He thinks nothing of it since he was told that computers crash often. "Oh, well..." And so, he restarts his computer.

Joe's computer was online without a firewall. Joe's computer is fucked. Joe doesn't know he has a Trojan on his computer. he didn't know that after only 2 minutes of being only, his computer was infected with a number of Trojans. He doesn't even know what a Trojan is.

One of the Trojan that out buddy Joe has on his computer was written by our good friends at S.P.A.M Inc.

The people at S.P.A.M Inc now have full control over Joe's computer like thousands of other computers infected with their Trojan. They can now use the infected computers to send out the spam mails of their clients (like our Viagra selling buddy) without being caught, since it's computers like Joe's that are sending out the actual spam.

You get the spam mails, some of you fall for it and buy stuff advertised in those emails, or click on the links inside them to either confirm that your email address is real or to download a Trojan of your own. Meanwhile the people at S.P.A.M Inc get paid hundreds of thousands of dollars for their "services" as advertisers.

For more info on referrer spammers or abusive advertisers read this blog.

UPDATE: New domain added to block list (from the same idiots): learnhowtoplay.com and a few IPs to go with them (194.241.45.5 and 82.194.62.16)

PS: Spam this email address: [email]acyon@acyon.com" title="[/email] , the makers of the ref-spam software. A bunch of assholes if you ask me.

Also see "htaccess rules that leave referrer spammers feeling left out"
Jun 16 2005 @ 10:39:41
njkhg wrote:

Your comment has been screened, and was found to be spam. I wish you and your family a slow and painful death.

Feb 1 2005 @ 14:01:22
TCorp wrote:

Re: The War Against Spam Bots

Almost every country if you consider this a DoS attack on your site. One of the bots has even tried brute forcing the admin password to one of my sites. If only I knew where these people live and who exactly they are...Boy, it would be fun reporting them to their local legal authorities.
Jan 28 2005 @ 23:28:07
Ann Elisabeth wrote:

Re: The War Against Spam Bots

Ann Elisabeth - iconI've tried to explain this problem to non-bloggers, journalists and sys admins. They don't get it at all.

So the question is, what countries have laws that cover this problem?
Jan 28 2005 @ 15:48:00
TCorp wrote:

Re: The War Against Spam Bots

I've seem both cases on this site, the "tecrep-inc.net" ones being the most recent. Some of the IPs are dial-up and, yes, you're right, a public proxy or unconfigured open proxy port is all that is needed to "attack" a website in this way. I see both types of this abuse as being part of the same problem.

Anonymous public proxies are also a part of this problem. What do people have to hide anyway? Unlike most public proxies, anonymous ones don't add your IP at the end of every request (GET or POST), creating an environment where people can do whatever they want without anyone ever finding out where the request came from. It's like a highway filled with cars with no license plates. Every hit is actually a hit and run.

Frankly i'm getting tired of setting up new block rules on my systems. I believe that agencies like InterPol should get much more active on computer abuse related issues, like spamming and identity falsification, be it fraud through identity theft or fake domain information at registrants.

They should investigate who's behind the abuse and publish their home addresses somewhere and let the consequences of their actions take their course. Or at least put their pictures on huge billboards with texts like "A WANTED SPAMMER" and put rewards on their heads.

Imagine a real world situation, of a group of people going around the world using fake IDs, stealing money, conducting fraud, and vandelizing anything they can get their hands on, causing damage to homes and businesses in the millions. The monitary damage done "online" through abuse goes beyond millions.

I've had only one good experience when it comes to reporting abuse to an ISP myself. The "attacking" website in that case was using a major ISP and they shut the site down within hours, and I got a reply for them confirming it.
Jan 28 2005 @ 13:16:47
Ann Elisabeth wrote:

Re: The War Against Spam Bots

Ann Elisabeth - iconThe machines misused by this particular group of spammers are actually normally not trojaned home machienes. I have seen spammers use an army of those, but these spammers do not do that. They use open proxies. Those may occasionally be home machines, but they're normally servers.

I've talked to a number of the owners of these servers, so I know this is what's happening.

All sorts of operating systems, from linux, windows, mac to proprietary os. All that's needed is an open proxy port.

Comment on this