Feeds

Savvis outed as big-time spam host

Sorry. We won't do it again

  • alert
  • submit to reddit

Internet Security Threat Report 2014

Savvis, the big US corporate ISP, is to remove spammers from its books following pressure from anti-spam group Spamhaus. The pledge comes after a whistleblower, who had failed to persuade Savvis' management to put its house in order, was fired.

Alif Terranson, an engineer in charge with keeping Savvis's network clean, retaliated by publishing memos which reveal Savvis's attempts to help spammers stay in operation.

He also approached Spamhaus, which had monitored how Savvis had risen to become the second worst "spam-supporting ISP", since its purchase of Cable & Wireless America in March this year.

Previously, Savvis had had a good record, according to Spamhaus, which escalated steps slowly, to encourage the ISP to clean up its act. But the issue of Savvis's spam-friendly practices was brought to a head by the publication of the memos, which showed how Savvis helped penis pill peddlers to dodge blackhole listings by switching their IP addresses and swapping names.

Subversive business methods

These "subversive business methods" were criticised by some on Savvis' management team (such as Kris Kistler, director, infosec and abuse); but objections were ignored. Savvis made up to $2m a month from 148 of the world's most prolific spammers, Terranson told BBC radio. He said the number of spammers had risen since Savvis had acquired Cable & Wireless America, showing it was actively touting for business from spammers.

According to a leaked strategy memo, Savvis would lose between $250,000 to $2m a month in revenues if it booted spammers off its system, depending on where it decided to draw the line. Savvis says its monthly revenues from spammers were around $200,000.

Following publication of the memos, Spamhaus approached Savvis to spell out the consequences if it continued to help notorious spammers such as Eddy Marin stay online. Savvis would risk having its reputation trashed and email sent by clients blacklisted if it failed to mend its ways, it warned.

Steve Linford, a director at Spamhaus, described a three-hour conversation with Savvis chief exec Rob McCormick on Friday as friendly and the outcome positive.

Savvis is to adopt Spamhaus' Register of Know Spam Operations (ROKSO) as a criterion for booting recalcitrant spammers off its network. It reckons it inherited 40 of the world's worst operators when it bought Cable & Wireless America. Spamhaus puts the figure at 56, a discrepancy which might be explained by multiple listings.

Linford welcomes Savvis's change of tack: "We're very pleased to see Savvis has turned things around and pleased to work with them. As soon as an ISP agrees to do the right thing we want to help," he told El Reg. ®

Related stories

Spamming for Dummies
Spam King dodges $20m big stick
US, UK and Australia sign anti-spam act
Junk mail host nations named and shamed

Internet Security Threat Report 2014

More from The Register

next story
George Clooney, WikiLeaks' lawyer wife hand out burner phones to wedding guests
Day 4: 'News'-papers STILL rammed with Clooney nuptials
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
PEAK IPV4? Global IPv6 traffic is growing, DDoS dying, says Akamai
First time the cache network has seen drop in use of 32-bit-wide IP addresses
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
Stunned by Shellshock Bash bug? Patch all you can – or be punished
UK data watchdog rolls up its sleeves, polishes truncheon
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.