<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-5181500149232975507</id><updated>2011-04-21T15:30:03.545-07:00</updated><category term='unsolicited bounces'/><category term='Googlepages'/><category term='misdirected bounces'/><category term='email backscatter'/><category term='spam reporting'/><category term='vacation programs'/><category term='spam'/><category term='spamcop.net'/><category term='outscatter'/><category term='blogspot'/><category term='auto-responders'/><title type='text'>Victims of Email Backscatter</title><subtitle type='html'>Email backscatter happens when spammers forge an email address in the "From:" field of their spams, and mail servers wrongly reply to that forged address. If it's your address, you'll get tons of "misdirected bounces" (a.k.a. "unsolicited bounce" emails).</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://backscattervictims.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5181500149232975507/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://backscattervictims.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Spam Fighter</name><uri>http://www.blogger.com/profile/10623048310673139240</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-5181500149232975507.post-8997629492332067657</id><published>2008-02-01T06:58:00.000-08:00</published><updated>2008-02-01T09:11:52.986-08:00</updated><title type='text'>Reject spam from zombies</title><content type='html'>&lt;span style="float:right;"&gt;&lt;img src="http://www.webreaders.de/wp-content/uploads/2007/08/zombie-pc.jpg" alt="Image courtesy of www.gdata.de" border="0" /&gt;&lt;br clear="all"/&gt;&lt;br /&gt;&lt;span style="font-size:70%;"&gt;&lt;em&gt;(image courtesy of &lt;a href="http://www.gdata.de/"&gt;www.gdata.de&lt;/a&gt;)&lt;/em&gt;&lt;/span&gt;&lt;/span&gt; The best thing that could happen to reduce email (spam) backscatter (a.k.a. collateral spammage) on the Internet today would be to have all mail servers configured so that they would &lt;span style="font-weight: bold;"&gt;reject &lt;/span&gt;emails from &lt;span style="font-weight: bold;"&gt;zombie PCs&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;So, I have to wonder. Why don't mail server admins use these block lists and reject spam from zombies? &lt;a href="http://spamcop.net/fom-serve/cache/291.html"&gt;All the information about configuring various mail servers to reject mail from IPs on block lists&lt;/a&gt; can be found on the SpamCop FAQ web site.&lt;br /&gt;&lt;br /&gt;Let's break it down in to two parts: 1) Rejecting email and 2) Identifying Zombies&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;Rejecting email&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Rejecting email is not a new thing. It has always been part of the original &lt;a href="http://www.faqs.org/rfcs/rfc821.html"&gt;RFC821&lt;/a&gt; that allowed for email transfers to "fail" during SMTP. The history of why it became fashionable to accept emails first, then validate and possibly bounce them afterward, is probably tied to Microsoft's domination of the Internet with its software. But I'm not enough of an expert to venture an explanation. I can only say that die-hard sendmail users (one of the original mail servers on the Internet) know what rejecting is, and how good it can be with respect to spam fighting.&lt;br /&gt;&lt;br /&gt;But even Microsoft wised up and allows rejecting. Their latest &lt;a href="http://www.microsoft.com/exchange/evaluation/features/default.mspx"&gt;mail server will allow emails to be rejected&lt;/a&gt; (see the bit about Spam Confidence Level) rather than bounced. The administrators only have to make sure they understand why rejecting is better and that they've enabled it.&lt;br /&gt;&lt;br /&gt;Some companies do a disservice to their customers by not informing them of all of the risks of bouncing. For example, Barracuda Networks provide &lt;a href="http://www.barracudanetworks.com/ns/downloads/barracuda_NDR_whitepaper.pdf"&gt;a whitepaper on Email Non Delivery Receipts (bounces)&lt;/a&gt;. Yes, there is useful text explaining the difference between rejecting and bouncing, and the "best practices" for how to draft NDRs. However, Barracuda Networks fails to mention that most spams have &lt;span style="font-weight: bold;"&gt;forged "From:" addresses&lt;/span&gt; and that most of those well written NDRs will go to the users whose email addresses have been forged in the spams that get bounced! All in the spirit of making sure a "false positive" doesn't get mishandled!&lt;br /&gt;&lt;br /&gt;Those backscatter victims (like me and possibly you if you found this blog) will not be happy to get a well written NDR that says a message we sent (that we didn't send!) was blocked by the Barracuda Spam Firewall. If anything, it implies that Barracuda are foolish enough to be tricked by the forged sender address. On the one hand, they are experts who deal with spam filtering. On the other hand, they "ignore" that spammers forge the "From:" address. Smells like marketing... Anyway, that's what a whitepaper is.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;Identifying Zombies&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Here's a fact: 100% of the backscatter I get today results from bounced spam sent originally from zombie PCs. How do I know this? The backscatter messages often contain the RFC822 "Received:" headers of the spam that had my email address forged in the "From:" field. From these headers, I can see that the injection point of the spam was a zombie.&lt;br /&gt;&lt;br /&gt;How do I know it's a zombie? That's easy. The IP address of the "from" host on the last "Received:" line is on a DNSBL, such as bl.spamcop.net, cbl.abuseat.org or zen.spamhaus.org. The first two DNSBL are for "known" spam-sending IPs (they are dynamically updated), and the last one is for IP address that are located on ISPs that have a policy that no email should be sent by such IPs. That's right - a "home PC" should not be acting like a mail server (Mail Transfer Agent) outside of the local network.&lt;br /&gt;&lt;br /&gt;You'll notice that I don't need any high-powered Bayesian filtering or keywords or TCP/IP probes to decide if it's a zombie is sending me spam. It's just basic common sense. Has the IP shown up as a known spam-sender (open relay) or does the IP have no business sending SMTP traffic? If the answer is yes (i.e., it's on one of those block lists), I conclude it's a zombie and reject the email (spam) it wants to send me.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;Rejecting spam from zombies&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Here's an example of a missed opportunity that makes backscatter victims suffer. Barracuda, who definitely can use block lists to reject spam from zombies, could have stressed in their whitepaper about NDRs that &lt;span style="font-weight: bold;"&gt;rejecting&lt;/span&gt; email is a good compromise with respect to false positives and backscatter. That is, when a message gets rejected (rather than bounced), there are two possibilities:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;It's a spam message: the rejection causes the spammer's mail server (usually a zombie) to have to deal with the bounce. This means that the zombie does nothing and moves onto the next spam to send. No collateral spamage (damage?).&lt;/li&gt;&lt;li&gt;It's a legitimate message (false positive): the rejection causes the legitimate sender's mail server to generate an NDR with the reason for the rejection in the message. This NDR will likely be written in the language of the legitimate sender.&lt;/li&gt;&lt;/ol&gt;To conclude, if you're an administrator of a mail server (or Barracuda Spam Firewall), make the Internet a better place and reject mail from zombies! Please don't generate NDRs to forged sender email addresses like mine!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5181500149232975507-8997629492332067657?l=backscattervictims.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://backscattervictims.blogspot.com/feeds/8997629492332067657/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5181500149232975507&amp;postID=8997629492332067657' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5181500149232975507/posts/default/8997629492332067657'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5181500149232975507/posts/default/8997629492332067657'/><link rel='alternate' type='text/html' href='http://backscattervictims.blogspot.com/2008/02/reject-spam-from-zombies.html' title='Reject spam from zombies'/><author><name>Spam Fighter</name><uri>http://www.blogger.com/profile/10623048310673139240</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5181500149232975507.post-6152967822888062567</id><published>2007-12-27T12:48:00.000-08:00</published><updated>2008-12-08T15:51:56.128-08:00</updated><title type='text'>Barracuda Networks and their customers could to do more to stop the backscatter</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_WOjBpRSCReA/R4axxLZwb6I/AAAAAAAAAB0/U4HSjpf9oNU/s1600-h/MCj00911230000%5B1%5D.gif"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://1.bp.blogspot.com/_WOjBpRSCReA/R4axxLZwb6I/AAAAAAAAAB0/U4HSjpf9oNU/s400/MCj00911230000%5B1%5D.gif" alt="" id="BLOGGER_PHOTO_ID_5154002282004639650" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Here's my latest tally of backscatter received from Barracuda firewalls since 2007-09-16:&lt;br /&gt;&lt;blockquote&gt;1940 messages&lt;/blockquote&gt;According to the &lt;a href="http://www.businesswire.com/portal/site/google/index.jsp?ndmViewId=news_view&amp;amp;newsId=20071212005158&amp;amp;newsLang=en"&gt;press releases&lt;/a&gt;, Barracuda says 95% of email being sent is spam. According to most people's experiences, 100% of spams have forged "from" addresses. The success of their firewall product, and the continual increase in spam are probably the reasons for an increase in &lt;a href="http://en.wikipedia.org/wiki/Backscatter#Backscatter_of_email_spam"&gt;email backscatter&lt;/a&gt;. Sadly, too many Barracuda Spam Firewall customers still enable auto-replies for spams that get blocked.&lt;br /&gt;&lt;br /&gt;When I get such backscatter, it's easy to fight back with an auto-reply of my own (thanks to Thunderbird's filters). Several Barracuda Spam Firewall customers have replied to me when I (automatically) contacted them about their firewalls creating backscatter.&lt;br /&gt;&lt;br /&gt;Here are a few of those relatively rare, yet encouraging replies. I have left out the names of the individuals involved for privacy reasons:&lt;br /&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;span style="font-style: italic;"&gt;date: Dec 21, 2007 6:02 AM&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;subject: RE: Please configure your spam firewall to stop bouncing spams to me&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;First of all, sorry for the inconvenience and we thank you your advice.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;We have changed the wrong configuration parameter.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Please, let us know if you receive still bouncing spams in the next days.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Date: Dec 3, 2007 8:17 AM&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Subject: RE: Please configure your spam firewall to stop bouncing spams to me (was: **Message you sent blocked by our bulk email filter**)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Sir –&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Thank you for the information.  I would have never known about this problem without your email.  I have made the recommend changes on my Barracuda filter.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;date: Nov 28, 2007 12:11 AM&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;subject: RE: Please configure your spam firewall&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;The suggested changes have been made.  Thanks for the heads up.&lt;br /&gt;&lt;br /&gt;date: Oct 31, 2007 1:48 PM&lt;br /&gt;subject: RE: Please configure your spam firewall to stop bouncing spams to me (was: **Message you sent blocked by our bulk email filter**)&lt;br /&gt;&lt;br /&gt;Sorry for the inconvenience, I disabled the feature&lt;br /&gt;&lt;br /&gt;Thanks, there is enough crap going around, no use having it bounce around on top of that&lt;br /&gt;&lt;br /&gt;date: Oct 29, 2007 7:22 PM&lt;br /&gt;subject: RE: Please configure your spam firewall to stop bouncing spams to me (was: **Message you sent blocked by our bulk email filter**)&lt;br /&gt;&lt;br /&gt;Please accept our apologies for any trouble caused by backscatter originating from our Barracuda. We have disabled the notifications that were causing the messages to be sent.&lt;br /&gt;&lt;br /&gt;Thanks!&lt;br /&gt;&lt;/span&gt;&lt;/blockquote&gt;Next is an example of a depressing response, which shows an administrator who is clueless about the damage she is causing the rest of the users on the internet. Her suggestion is that I just block her bounces...&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;date    Dec 7, 2007 7:31 AM&lt;br /&gt;subject    RE: Please configure your spam firewall to stop bouncing spams to me (was: **Message you sent blocked by our bulk email filter**)&lt;br /&gt;&lt;br /&gt;Thanks for your email.  We understand your frustration with receiving notifications of spoofed emails forged with your address.  However, the notifications serve a purpose to alert you that: 1) someone is using your address to  send spam; 2) alert you that you might be infected and are sending potentially infected emails.&lt;br /&gt;&lt;br /&gt;If you feel that you are receiving too many false positives from our Barracuda, please feel free to add our domain to your blocking list.&lt;br /&gt;&lt;/blockquote&gt;Don't you like how she turned it around as doing us all a service! My response to this nonsense got escalated to the VP of IT in her company, who wrote me a message that was very defensive, to which I replied below:&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-style: italic;"&gt;Hello,&lt;br /&gt;&lt;br /&gt;On Dec 7, 2007 9:20 AM, (Anonymized) wrote:&lt;br /&gt;&lt;blockquote&gt;&lt;span style="color: rgb(51, 51, 255);"&gt;    The next time you want to criticize someone, slap some credentials behind your name.&lt;/span&gt;&lt;br /&gt;&lt;/blockquote&gt;Who says credentials are necessary to say that your Barracuda is spamming me?!&lt;br /&gt;&lt;br /&gt;I'm complaining about the spam your Barracuda is sending to me because you've enabled the feature that most people recognize as abusive. Just Google it! I won't be the only person who is upset about this. If you want credentials to back up what I'm saying, you're just being ignorant and not listening. Again, if you don't trust me, try Google:&lt;br /&gt;&lt;br /&gt;http://www.google.ca/search?hl=en&amp;amp;q=barracuda+backscatter&amp;amp;btnG=Google+Search&amp;amp;meta=&lt;br /&gt;&lt;br /&gt;I have sent many, many, many complaints to Barracuda owners about this problem. When I get a response, it's one of the following:&lt;br /&gt;&lt;br /&gt;1) Thank you for pointing this out to us, we are correcting the problem.&lt;br /&gt;2) Backscatter isn't my fault. Too bad for you.&lt;br /&gt;3) postmaster does not exist.&lt;br /&gt;&lt;br /&gt;Since you're a VP, I trust you know which one is the more professional and customer-oriented. Yes, I'm holding you to your credentials!&lt;br /&gt;&lt;blockquote style="color: rgb(51, 51, 255);"&gt;    I assure you we have better things to do with our time than pick on someone like yourself, and send them bogus emails telling them that they might be infected.  Gmail supports an outlook interface which is a commonly targeted service for spammers, have you considered the fact that someone, yes someone malicious may have in fact cracked your password and might be using your account.&lt;/blockquote&gt;This is a possible explanation, but there are no facts to support my Gmail has been hacked.&lt;br /&gt;&lt;br /&gt;I have already more than 30,000 backscatter emails, and &lt;a href="http://profs.logti.etsmtl.ca/cfuhrman/backscatter/"&gt;I found out how it works&lt;/a&gt;. I am not the only one who's a victim of this kind of spamming problem. If you check your Barracuda logs, I'm willing to bet you'll find it's bouncing spams to other people.&lt;br /&gt;&lt;/span&gt;&lt;/blockquote&gt;Funny, this "VP" never wrote back. Perhaps he's still trying to figure out how to turn off the auto-reply feature of their Barracuda Spam Firewall - maybe he's asking his underlings what a log file is?...&lt;br /&gt;&lt;br /&gt;Finally, here's the most common response I get when I reply to Barracuda backscatter (the&lt;span style="font-style: italic;"&gt; &lt;/span&gt;domain &lt;span style="font-style: italic;"&gt;example.com&lt;/span&gt; is used below, but it will be something else depending on the Barracuda box that sends it out):&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-style: italic;"&gt;This is an automatically generated Delivery Status Notification&lt;br /&gt;&lt;br /&gt;Delivery to the following recipient failed permanently:&lt;br /&gt;&lt;br /&gt;postmaster@example.com&lt;br /&gt;&lt;br /&gt;Technical details of permanent failure:&lt;br /&gt;PERM_FAILURE: SMTP Error (state 13): 550 &amp;lt;postmaster@example.com&amp;gt;: Recipient address rejected: No such user (postmaster@example.com)&lt;/span&gt;&lt;/blockquote&gt;This shows that Barracuda Networks are not doing a great job at having customers set up their boxes properly. Pert near all of these domains end up getting a listing for being &lt;a href="http://www.rfc-ignorant.org/policy-postmaster.php"&gt;RFC-ignorant with respect to postmaster&lt;/a&gt;. I don't have a count yet, but it's got to be over 100 domains that I've reported there, "thanks" to the Barracuda backscatter from their poorly configured appliances.&lt;br /&gt;&lt;br /&gt;p.s. A more rare event is that sometimes a Barracuda Spam Firewall actually blocks my automated response to its backscatter, claiming my request for them to stop bouncing spams to me is itself a spam! Although telling me that my request was blocked isn't backscatter, it will get them listed as being RFC-ignorant. They're blocking requests to the postmaster address.&lt;blockquote&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5181500149232975507-6152967822888062567?l=backscattervictims.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://backscattervictims.blogspot.com/feeds/6152967822888062567/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5181500149232975507&amp;postID=6152967822888062567' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5181500149232975507/posts/default/6152967822888062567'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5181500149232975507/posts/default/6152967822888062567'/><link rel='alternate' type='text/html' href='http://backscattervictims.blogspot.com/2007/12/barracuda-networks-could-to-do-more-to.html' title='Barracuda Networks and their customers could to do more to stop the backscatter'/><author><name>Spam Fighter</name><uri>http://www.blogger.com/profile/10623048310673139240</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_WOjBpRSCReA/R4axxLZwb6I/AAAAAAAAAB0/U4HSjpf9oNU/s72-c/MCj00911230000%5B1%5D.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5181500149232975507.post-2310346297183760355</id><published>2007-12-11T06:56:00.000-08:00</published><updated>2008-12-08T15:51:56.303-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Googlepages'/><category scheme='http://www.blogger.com/atom/ns#' term='spam reporting'/><category scheme='http://www.blogger.com/atom/ns#' term='spam'/><category scheme='http://www.blogger.com/atom/ns#' term='blogspot'/><category scheme='http://www.blogger.com/atom/ns#' term='spamcop.net'/><title type='text'>Why I stopped reporting (Googlepages, Blogspot) spams to Google</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_WOjBpRSCReA/R17StlRhkRI/AAAAAAAAABs/JmcVagISKAE/s1600-h/Picture1.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://4.bp.blogspot.com/_WOjBpRSCReA/R17StlRhkRI/AAAAAAAAABs/JmcVagISKAE/s400/Picture1.png" alt="" id="BLOGGER_PHOTO_ID_5142779505045246226" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;I've been a Spam Fighter for 7+ years, and Google has got me frustrated. I'm quite happy about the &lt;a href="http://gmailblog.blogspot.com/2007/10/how-our-spam-filter-works.html"&gt;little spam I get on my Gmail account&lt;/a&gt;. But they are doing &lt;a href="http://news.yahoo.com/s/pcworld/20071210/tc_pcworld/140432;_ylt=AnXBeFisUYTQWeSw1wo7e3EE1vAI"&gt;a bad job of controlling spam on their systems&lt;/a&gt;. Worst of all, they don't accept automated reports, but instead want users to spend time reporting spams and abuse on Google systems manually.&lt;br /&gt;&lt;br /&gt;Every other ISP or web service accepts &lt;span style="font-weight: bold;"&gt;automated &lt;/span&gt;spam reports via systems like SpamCop.net. Google requires us to report spams with on-line web forms. A good example is this web form to report an &lt;a href="http://help.blogger.com/?page=troubleshooter.cs&amp;amp;problem=&amp;amp;ItemType=adult_image&amp;amp;contact_type=adult_image&amp;amp;Submit=Continue"&gt;adult-content blogspot.com page&lt;/a&gt;. I can't tell you how many spams I have got with blogspot.com links that redirect to porn sites in China somewhere. I have reported them &lt;span style="font-style: italic;"&gt;all&lt;/span&gt; to Google using that stupid form. Guess what? The links are all still up, sometimes weeks after I report them. There is never any closure or follow up, despite when I include my email address.&lt;br /&gt;&lt;br /&gt;So, I'm resorting to ranting about this poor quality of service in a blog. You can see some of the other rants about this subject in this discussion in the &lt;a href="http://groups.google.com/group/blogger-help-troubleshoot/browse_thread/thread/11cdd6040f93ee62/c05434fa166be17b#c05434fa166be17b"&gt;Google Group for Blogspot&lt;/a&gt;. Try some of the links (if you're not afraid of seeing porn) to see if they're still up. Google knows about these but is not taking quick action.&lt;br /&gt;&lt;br /&gt;Google has some of the sharpest, most creative people working for them. Yet they require us to submit spam reports about Gmail abuse using &lt;a href="http://mail.google.com/support/bin/request.py?contact_type=abuse_spoofing"&gt;archaic web forms that cannot parse emails&lt;/a&gt; or &lt;a href="http://www.google.com/support/pages/bin/request.py?contact_type=abuse_spam&amp;amp;extra.IssueType=abuse_spam"&gt;require us to submit Googlepages abuse emails one link at a time&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Google refuses SpamCop.net automated reports about spams that contain links to Googlepages.com or blogspot.com pages. Here's an example of what happens when you put a spam into SpamCop that contains a Googlepages.com link:&lt;br /&gt;&lt;blockquote&gt;&lt;p&gt;&lt;strong&gt;Re:&lt;/strong&gt; http://burtsmithwx.googlepages.com/index.html (Administrator of network hosting website referenced in spam)&lt;br /&gt;&lt;strong&gt;To:&lt;/strong&gt; abuse@google.com  (refuses to accept this type of report) &lt;input name="send2" value="" type="hidden"&gt;&lt;br /&gt;&lt;input name="type2" value="www" type="hidden"&gt; &lt;input name="master2" value="abuse@google.com" type="hidden"&gt; &lt;input name="info2" value="http%3A%2F%2Fburtsmithwx.googlepages.com%2Findex.html" type="hidden"&gt; &lt;input name="send3" checked="checked" type="checkbox"&gt; &lt;input name="type3" value="www" type="hidden"&gt; &lt;input name="master3" value="abuse#google.com@devnull.spamcop.net" type="hidden"&gt; &lt;input name="info3" value="http%3A%2F%2Fburtsmithwx.googlepages.com%2Findex.html" type="hidden"&gt;&lt;strong&gt;To:&lt;/strong&gt; &lt;a href="mailto:abuse#google.com@devnull.spamcop.net"&gt;abuse#google.com@devnull.spamcop.net&lt;/a&gt; &lt;a href="javascript:showcomment('comment3');"&gt;(Notes)&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;strong&gt;Re:&lt;/strong&gt; http://yodatrinidadt.googlepages.com/index.html (Administrator of network hosting website referenced in spam)&lt;br /&gt;&lt;strong&gt;To:&lt;/strong&gt; abuse@google.com  (refuses to accept this type of report) &lt;input name="send4" value="" type="hidden"&gt;&lt;br /&gt;&lt;input name="type4" value="www" type="hidden"&gt; &lt;input name="master4" value="abuse@google.com" type="hidden"&gt; &lt;input name="info4" value="http%3A%2F%2Fyodatrinidadt.googlepages.com%2Findex.html" type="hidden"&gt; &lt;input name="send5" checked="checked" type="checkbox"&gt; &lt;input name="type5" value="www" type="hidden"&gt; &lt;input name="master5" value="abuse#google.com@devnull.spamcop.net" type="hidden"&gt; &lt;input name="info5" value="http%3A%2F%2Fyodatrinidadt.googlepages.com%2Findex.html" type="hidden"&gt;&lt;strong&gt;To:&lt;/strong&gt; &lt;a href="mailto:abuse#google.com@devnull.spamcop.net"&gt;abuse#google.com@devnull.spamcop.net&lt;/a&gt; &lt;a href="javascript:showcomment('comment5');"&gt;(Notes)&lt;/a&gt;&lt;/blockquote&gt;Accepting automated SpamCop reports would be the most intelligent way for Google to fight the spam on their systems.&lt;br /&gt;&lt;br /&gt;Finally, let's not forget that spammers use software to create the spams, the Googlepages.com and Blogspot.com pages. So why shouldn't Google use software to detect and delete them!? Perhaps it doesn't affect the Google bottom line, and so they haven't put any resources on it.&lt;br /&gt;&lt;br /&gt;As of today, I'm no longer reporting any more spam to Google with their archaic methods. They need to modernize on this aspect and start accepting automated reports from SpamCop.net.&lt;br /&gt;&lt;br /&gt;Finally, stop exploiting the volunteer spam reporters! We have better things to do!&lt;br /&gt;&lt;br /&gt;Interesting links: &lt;a href="http://www.ceas.cc/2007/papers/paper-85.pdf"&gt;Blog Spam: A review&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.ceas.cc/2007/papers/paper-85.pdf"&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5181500149232975507-2310346297183760355?l=backscattervictims.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://backscattervictims.blogspot.com/feeds/2310346297183760355/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5181500149232975507&amp;postID=2310346297183760355' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5181500149232975507/posts/default/2310346297183760355'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5181500149232975507/posts/default/2310346297183760355'/><link rel='alternate' type='text/html' href='http://backscattervictims.blogspot.com/2007/12/why-i-stopped-reporting-googlepages.html' title='Why I stopped reporting (Googlepages, Blogspot) spams to Google'/><author><name>Spam Fighter</name><uri>http://www.blogger.com/profile/10623048310673139240</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_WOjBpRSCReA/R17StlRhkRI/AAAAAAAAABs/JmcVagISKAE/s72-c/Picture1.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-5181500149232975507.post-8387540434597224307</id><published>2007-10-27T10:35:00.000-07:00</published><updated>2008-12-08T15:51:56.466-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vacation programs'/><category scheme='http://www.blogger.com/atom/ns#' term='email backscatter'/><category scheme='http://www.blogger.com/atom/ns#' term='auto-responders'/><category scheme='http://www.blogger.com/atom/ns#' term='misdirected bounces'/><category scheme='http://www.blogger.com/atom/ns#' term='unsolicited bounces'/><category scheme='http://www.blogger.com/atom/ns#' term='outscatter'/><title type='text'>Victims of email backscatter unite!</title><content type='html'>&lt;p&gt;Currently I receive close to 500 backscattered messages per day at one of my email addresses. Some spammers must be really pissed off at me, or maybe my alias is a good one to use because it's on a common email alias provider. Anyway, I decided it's time to do something about it, if possible.&lt;/p&gt;&lt;p&gt;First, you may be asking what's a backscattered message? It's a "bounce" email that arrives in your in-box, that usually has a subject of "Delivery notification: delivery has failed", "Deliver status notification", "failure notice", etc. The messages typically originate from "Mailer daemon", "postmaster", or "Mail delivery subsystem". Backscatter are messages that tell you about &lt;span style="font-weight: bold;"&gt;problems with messages you did not send&lt;span style="font-weight: bold;"&gt;. &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Huh? This is weird... What's up with that? Well, you get backscattered messages because of two problems:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;a spammer &lt;span style="font-weight: bold;"&gt;has forged your email address&lt;/span&gt; in the "From:" field of the spam she sent;&lt;/li&gt;&lt;li&gt;some email server has received that spam, and for some reason decided to &lt;span style="font-weight: bold;"&gt;reply to the forged email address (yours)&lt;/span&gt;, probably to tell you:&lt;/li&gt;&lt;ul&gt;&lt;li&gt;it couldn't be delivered because the destination address was not valid, the user's mailbox was full, etc.;&lt;/li&gt;&lt;li&gt;the user is on vacation (vacation auto-responder);&lt;/li&gt;&lt;li&gt;the message contained a virus and was blocked;&lt;/li&gt;&lt;li&gt;the message was detected as spam and blocked.&lt;/li&gt;&lt;/ul&gt;&lt;/ol&gt;&lt;p&gt;The last two reasons are particularly incredible. If the mail server is smart enough to determine a message was a virus or spam, then it should know darn well that replying to its "From:" address makes no sense because -- guess what --  spammers/viruses nearly &lt;span style="font-weight: bold;"&gt;always forge the "From:" address&lt;/span&gt;!&lt;/p&gt;&lt;p&gt;The following image shows the anatomy of email backscatter. Click on it to see a bigger version.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_WOjBpRSCReA/RyTxYTVZTaI/AAAAAAAAAAo/myk3euPPf9M/s1600-h/email+backscatter.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; cursor: pointer;" src="http://1.bp.blogspot.com/_WOjBpRSCReA/RyTxYTVZTaI/AAAAAAAAAAo/myk3euPPf9M/s400/email+backscatter.png" alt="Anatomy of email backscatter" id="BLOGGER_PHOTO_ID_5126487675663633826" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;The bad news is, you won't be able to stop spammers from forging your email address (problem #1 above). But there is some good news -- you &lt;span style="font-style: italic;"&gt;may&lt;/span&gt; be able to do something about the servers that bounce messages (they create the backscatter messages, problem #2). Did you know that AOL, Hotmail, Yahoo, Gmail, etc. are examples of email services that do NOT create backscatter? This is because they are well administered and their email servers are correctly configured.&lt;/p&gt;&lt;p&gt;Sadly, there are too many email servers on the Internet today that create backscatter. See the links about backscatter on the side menu of this blog for information about the technical details. One of the worst offenders is the &lt;span style="font-style: italic;"&gt;Barracuda Spam Firewall&lt;/span&gt;. I get sometimes 15 of their bounces per day, telling me the "Message you sent was blocked by our bulk email filter". Their software accuse me of sending spams, because the designer of the software made a mistake in thinking it was a good thing to reply to spams that have forged emails. That is irresponsible, and &lt;a href="http://larting.you.googlepages.com/readthisbeforeyoubuyabarracudaspamfirewa"&gt;Barracuda should fix their product&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;All ranting aside, if you're willing to work a little, I suspect there is a &lt;span style="font-style: italic;"&gt;huge potential&lt;/span&gt; to fight spam if one is a victim of backscatter. Here are a couple of thoughts about useful information that could be exploited, provide there was some way to process it:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Email bounces arrive practically in "real time" from spam runs. As soon as the spammer starts hitting mail servers with her spam, the bounces of failed messages come in to the victim of the forged "From:" address.&lt;/li&gt;&lt;li&gt;Some of the bounces themselves contain full headers of the spam email. Most often, one can trace back the IP address to a spam-sending zombie. &lt;/li&gt;&lt;li&gt;A spam run will typically have the same subject of spam, or even the same "spamvertised" URL to a web page.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;(if you have concrete ideas or resources about how to use this information, send me an &lt;a href="mailto:larting.you@gmail.com"&gt;email &lt;/a&gt;or post your ideas here in response) &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;There is a block-list for backscattering hosts at &lt;a href="http://www.backscatterer.org/"&gt;www.backscatterer.org&lt;/a&gt;. I have already contacted them, &lt;span style="text-decoration: underline;"&gt;&lt;/span&gt;but they are only interested in my backscatter if I host an MX on UCEProtect.net's system. Apparently their backscatter-reporting is hard-coded from that system. Sadly, I would lose the backscatter if I were to move my email there, as it's coming into an email alias, which forwards to my Gmail system. By the way, Gmail does a great job of classifying spam, including backscattered messages.&lt;/p&gt;&lt;p&gt;You can report backscatter to &lt;a href="http://spamcop.net/"&gt;Spamcop.net&lt;/a&gt;, and, in principle, the administrators of offending sites will get a SpamCop report. However, the &lt;a href="http://www.spamcop.net/fom-serve/cache/329.html"&gt;link that SpamCop sends to them&lt;/a&gt; does a poor job of explaining the problem and the solution, and I don't think it has much affect. Sadly, a backscattering host will only get put on the SpamCop block-list if enough different people report it. So, if you're a victim of backscatter, you &lt;span style="font-style: italic;"&gt;can&lt;/span&gt; make a difference by reporting it to SpamCop!&lt;/p&gt;&lt;p&gt;I report all backscatter (and other spams) to SpamCop fairly easily using a combination of Gmail, FreePOPs, Thunderbird and &lt;a href="http://forum.spamcop.net/forums/index.php?showtopic=88"&gt;SpamCop's quick-report feature&lt;/a&gt; (which is free). See &lt;a href="http://forum.spamcop.net/forums/index.php?showtopic=4668&amp;amp;pid=55344&amp;amp;mode=threaded&amp;amp;show=&amp;amp;st=0&amp;amp;#entry55344"&gt;how to setup FreePOPs to download spam from your Gmail spam folder&lt;/a&gt;. In the interest of getting more people to report their backscatter, I would be happy to help you set up your system to do it easily. Please post your requests here, but don't identify your emails on this blog. If you want me to know specific info, you can &lt;a href="mailto:larting.you@gmail.com"&gt;email me at my Gmail address&lt;/a&gt; if you choose.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5181500149232975507-8387540434597224307?l=backscattervictims.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://backscattervictims.blogspot.com/feeds/8387540434597224307/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=5181500149232975507&amp;postID=8387540434597224307' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/5181500149232975507/posts/default/8387540434597224307'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/5181500149232975507/posts/default/8387540434597224307'/><link rel='alternate' type='text/html' href='http://backscattervictims.blogspot.com/2007/10/email-backscatter-victims-unite.html' title='Victims of email backscatter unite!'/><author><name>Spam Fighter</name><uri>http://www.blogger.com/profile/10623048310673139240</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_WOjBpRSCReA/RyTxYTVZTaI/AAAAAAAAAAo/myk3euPPf9M/s72-c/email+backscatter.png' height='72' width='72'/><thr:total>6</thr:total></entry></feed>
