You are here: silicon.com > Software > Malware

Malware

Worry over MSN blogs aiding spam

And various malware

Tags: msn blogs, surfcontrol, malware

By Munir Kotadia

Published: 26 August 2005 08:10 BST

Spammers have started using Microsoft's MSN blogging service to host malicious content used during spam and virus onslaughts, internet security firm SurfControl has said.

MSN Spaces, which was launched at the end of last year, is a free content sharing and hosting service. Users are required to register for a Hotmail account, after which they can publish a blog and share files.

However, a relatively simple registration system means that spammers are exploiting the service by creating accounts used to deliver often illegal messages and malicious files to unsuspecting users, said Charles Heunemann, managing director of SurfControl.

According to Heunemann, Yahoo!'s web hosting service Geocities has been targeted by spammers for some time but MSN's validation system is making the service very popular. SurfControl claims that 10 per cent of all spam on the internet is now linked to Microsoft's blog network.

"About three weeks ago 30 percent of the spam on the internet was directing victims to Geocities sites advertising pharmaceuticals. Spammers have moved their content to [MSN Spaces] and from what we gather, the volume of spam attacking MSN sites is about 10 per cent - but we think it will grow," said Heunemann.

However, Tim Hartman, senior systems engineer at Symantec, said that even if Microsoft improved the validation system, spammers would soon find a way around it.

"This isn't Microsoft's fault. Any introduction of new technology is at risk of being exploited or used for inappropriate purposes. Microsoft is not the only target. This is simply a method of keeping the content of the spam email to an absolute minimum - giving anti-spam companies very little to go on," said Hartman.

Hartman said the problem is a prime example of why simple blacklists are no longer effective: "Mail administrators should be aware that simple blacklists are no longer an appropriate countermeasure against spam - companies need to dig deep into the content of the email's body to make a call on whether something is spam or not."

Last month, internet security firm Websense reported an "alarming" increase in the use of free web space services for distributing malware. Dan Hubbard, Websense senior director of security and technology research, said that more malware was found on free hosting services during the first two weeks of July than in May and June combined.

Adam Biviano, senior systems engineer at Trend Micro Australia and New Zealand, said that although free web hosting is becoming a popular tool for spammers and virus writers, it is still second choice to a zombie network - a group of computers infected by a virus [which remain under the control of virus authors].

"Botnets are always going to be a more lucrative avenue for [spammers and virus authors] - you are not going to get that mass control you get with a botnet," said Biviano, who argued that improved design could help reduce the exploitation of such services.

"There are definitely safety controls that can be put into place if you design the system accordingly," said Biviano.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Senior QA (Quality Assurance) Officer, Biopharmaceutical Company

Other responsibilities include: + performing routine audits of the manufacturing facilities and operations, and the companys Quality Systems + ...

McAffee Anti-Virus Rollout Engineer (Field Based)

My West Midlands based client has a requirement for 2 Engineers to rollout McAfee Anti-Virus on to 600+ desktops at multiple sites throughout the ...

Systems engineer South Verification/Validation 50-60K

Systems engineer South Verification/Validation 50-60K I am looking for 2 Senior Systems engineers to join a project based around Air Traffic ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: