Feeds

Savvis outed as big-time spam host

Sorry. We won't do it again

  • alert
  • submit to reddit

Top 5 reasons to deploy VMware with Tegile

Savvis, the big US corporate ISP, is to remove spammers from its books following pressure from anti-spam group Spamhaus. The pledge comes after a whistleblower, who had failed to persuade Savvis' management to put its house in order, was fired.

Alif Terranson, an engineer in charge with keeping Savvis's network clean, retaliated by publishing memos which reveal Savvis's attempts to help spammers stay in operation.

He also approached Spamhaus, which had monitored how Savvis had risen to become the second worst "spam-supporting ISP", since its purchase of Cable & Wireless America in March this year.

Previously, Savvis had had a good record, according to Spamhaus, which escalated steps slowly, to encourage the ISP to clean up its act. But the issue of Savvis's spam-friendly practices was brought to a head by the publication of the memos, which showed how Savvis helped penis pill peddlers to dodge blackhole listings by switching their IP addresses and swapping names.

Subversive business methods

These "subversive business methods" were criticised by some on Savvis' management team (such as Kris Kistler, director, infosec and abuse); but objections were ignored. Savvis made up to $2m a month from 148 of the world's most prolific spammers, Terranson told BBC radio. He said the number of spammers had risen since Savvis had acquired Cable & Wireless America, showing it was actively touting for business from spammers.

According to a leaked strategy memo, Savvis would lose between $250,000 to $2m a month in revenues if it booted spammers off its system, depending on where it decided to draw the line. Savvis says its monthly revenues from spammers were around $200,000.

Following publication of the memos, Spamhaus approached Savvis to spell out the consequences if it continued to help notorious spammers such as Eddy Marin stay online. Savvis would risk having its reputation trashed and email sent by clients blacklisted if it failed to mend its ways, it warned.

Steve Linford, a director at Spamhaus, described a three-hour conversation with Savvis chief exec Rob McCormick on Friday as friendly and the outcome positive.

Savvis is to adopt Spamhaus' Register of Know Spam Operations (ROKSO) as a criterion for booting recalcitrant spammers off its network. It reckons it inherited 40 of the world's worst operators when it bought Cable & Wireless America. Spamhaus puts the figure at 56, a discrepancy which might be explained by multiple listings.

Linford welcomes Savvis's change of tack: "We're very pleased to see Savvis has turned things around and pleased to work with them. As soon as an ISP agrees to do the right thing we want to help," he told El Reg. ®

Related stories

Spamming for Dummies
Spam King dodges $20m big stick
US, UK and Australia sign anti-spam act
Junk mail host nations named and shamed

Internet Security Threat Report 2014

More from The Register

next story
'Kim Kardashian snaps naked selfies with a BLACKBERRY'. *Twitterati gasps*
More alleged private, nude celeb pics appear online
Home Depot ignored staff warnings of security fail laundry list
'Just use cash', former security staffer warns friends
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
UK.gov lobs another fistful of change at SME infosec nightmares
Senior Lib Dem in 'trying to be relevant' shocker. It's only taxpayers' money, after all
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Snowden, Dotcom, throw bombs into NZ election campaign
Claim of tapped undersea cable refuted by Kiwi PM as Kim claims extradition plot
Freenode IRC users told to change passwords after securo-breach
Miscreants probably got in, you guys know the drill by now
THREE QUARTERS of Android mobes open to web page spy bug
Metasploit module gobbles KitKat SOP slop
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.