No consensus
By Robert Lemos
Published: 30 June 2003 07:55 GMT
Junk emailers are spreading viruses that let them send spam anonymously through home computers, according to an email security firm.
The company, MessageLabs, operates servers that block spam and viruses for its clients. Its analysis of data shows that mass distributions of junk email are increasingly coming from the internet addresses of computers that have in the past sent out viruses as email attachments.
"There is a high correlation," said Matt Sergeant, senior anti-spam technologist for the UK company. "About 30,000 machines have both open-proxy software and are responsible for sending viruses."
Open proxies, also known as open relays, are computers that can resend email or other network data, erasing the original address information that could identify the source of the traffic. The 30,000 computers represent about 14 per cent of the total open relays from which MessageLabs has registered bulk unsolicited email, otherwise known as spam.
If true, the finding could add momentum to the backlash against spammers. Earlier this month, the Federal Trade Commission (FTC) asked Congress for greater power to pursue and penalise those who send unsolicited bulk email.
In mid-May, the FTC and enforcement agencies from other nations sent warning letters to the operators of 1,000 email servers, urging them to close their relays.
Estimates for the percentage of email traffic due to spam run from 30 per cent to as much as 75 per cent. Nearly 70 per cent of spam messages appear to come from servers classified as open relays, according to MessageLabs.
But the connection between open relays and viruses seems tenuous, said Craig Schmugar, senior anti-virus engineer for Network Associates, a security software firm.
"It is interesting data, to be able to correlate spam relays and virus relays, if you can call them that," he said. "However, it's tough to make the case that these machines are infected."
There are other explanations for the connection, Schmugar said. Computers vulnerable to viruses could be more likely to download a program that turns the system into an open relay, for instance. Schmugar also stressed that a 14 per cent correlation isn't conclusive.
MessageLabs maintained that the latest outbreaks of computer viruses may have been deliberately caused by spammers. The company has already pinpointed the recent Sobig virus, and previous variants as probable spammer creations. The programs are likely to have been specifically designed to use home computers as a large pool of open relays for spammers, said MessageLabs' Sergeant.
The company's analysis suggests the virus opens a range of 'ports', communication channels through which software applications route data from the network. The latest Sobig.E variant opens a series of five ports through which the virus downloads additional software to turn the infected computer into an open relay. The mechanism could also download other kinds of programs, such as remote control software and backdoor Trojans.
Sergeant also pointed to the time limit, the fact that each variant of the virus spread only for about three weeks, as another indication that the programs were created with a purpose. Sobig.E, for example, will stop spreading on 14 July.
Network Associates' Schmugar confirmed the existence of the series of five ports but said the company hadn't yet confirmed the software update mechanism.
However, another email security firm, likely the only kind of internet company that could correlate virus attacks and spam floods, hasn't been able to confirm the correlation seen by MessageLabs.
Postini, a MessageLabs competitor, sifted through 1.8 billion email transactions logged in the past 40 days and didn't find a significant correlation.
"We haven't seen a smoking gun," said Scott Petry, chief technology officer for the Redwood City, California-based company.
Still, Petry said Postini's data may not go back far enough. Much of MessageLabs' evidence stems from the original Sobig infection that started in January.
Robert Lemos writes for CNET News.com.
Back to The Spam Report Special Report
Virtual worlds under siege from cyber crime
A hiding place for scams, spam and phishing…
Spammers switching on to YouTube?
Video spam and PowerPoint slides next on the menu, warns MessageLabs...
Spam surge emanating from the Far East
Made in China...
US court upholds anti-spam law
Junks convicted spammer's appeal...
Spammers dust off their botnet passports
Targeting pastures new...
Stories from around the web...
Beware: You have mail Times Online
The economies of spam Global Politician
Special report: Fighting spam and cyberscams CNET News.com
Spam ain't dead yet PC Magazine
Slaying Spam-Spewing Zombie PCs PC World
Make your voice heard
silicon.com and the Bathwick Group have created an opportunity for business and IT executives to share their experience with each other and thus enhance their knowledge of the IT marketplace.
Join our research panel, and you'll be asked to participate in short surveys - and then will be privy to the answers of all your colleagues, as we send you tailored versions of the results.
Extras include complementary passes to silicon.com events and survey prizes such as iPods. Plus, there are the obvious networking opportunities with your fellow panellists.
For more about the Research Panel and how to join, click here
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page