Feeds

ISPs urged to throttle spam zombies

International clean-up campaign

  • alert
  • submit to reddit

Protecting against web application threats using SSL

The US Federal Trade Commission (FTC), along with more than 35 government agencies worldwide, announced an ambitious effort on Tuesday to get ISPs and other organisations to deliver the net from the plague of zombie spam networks. The group is encouraging ISPs to identify and quarantine customers whose PCs may have unwittingly been turned into spam zombies, under the control of hackers.

ISPs are also being encouraged to apply rate-limiting controls for email relays and to block port 25 (a common Internet port used for email) for inappropriate use as part of an educational campaign called Operation Spam Zombies. ISPs are also being urged to educate consumers about net security and to provide tools to disinfect computers under one of the most ambitious net security education initiatives to date.

Trojans such as Phatbot are often used to seize control of Windows PCs, turning them into zombie clients in networks of compromised PCs (botnets). These botnets are used to send spam or as platforms for DDoS attacks, carrying out criminal attacks right under the noses of their rightful owners. The tactic allows hackers to offload the computing effort in sending spam while creating a means to get past basic junk mail filters. According to email security firm MX Logic shows that during April, on average zombie PCs accounted for 44 percent of all spam.

Steve Linford, director of anti-spam organisation Spamhaus, said the FTC's advice was basically common sense even though it was often ignored by ISPs who either didn't know how to apply controls or couldn't be bothered to carry out the work. "This is something we've been advocating for years but the addition of more voices can only help the message get through," he added.

The FTC is leading the publicity drive on Operation Spam Zombies because US ISPs are the main target audience of the campaign. UK groups like Spamhaus and government agencies like the DTI and OFT are also getting behind Operation Spam Zombie which was developed by members of the London Action Plan, an international network combating spam. ®

Related stories

Britain tops zombie PC charts
Rise of the botnets
US tops junk mail list of shame - again
Telenor takes down 'massive' botnet

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
Infosec geniuses hack a Canon PRINTER and install DOOM
Internet of Stuff securo-cockups strike yet again
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.