Free Newsletter
Register for our Free Newsletters
Newsletter
Zones
Access Control
LeftNav
Alarms
LeftNav
Biometrics
LeftNav
Detection
LeftNav
Deutsche Zone (German Zone)
LeftNav
Education, Training and Professional Services
LeftNav
Government Programmes
LeftNav
Guarding, Equipment and Enforcement
LeftNav
Industrial Computing Security
LeftNav
IT Security
LeftNav
Physical Security
LeftNav
Surveillance
LeftNav
View All
Other Carouselweb publications
Carousel Web
Defense File
New Materials
Pro Health Zone
Pro Manufacturing Zone
Pro Security Zone
Web Lec
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
 
News

Surge in spam accounts registered on Hotmail and Gmail.

BitDefender UK : 09 August, 2007  (Technical Article)
Yahoo succeeds in blocking spammers from using its accounts but Hotmail and Gmail continue to host vast quantities of spam accounts.
A joint effort between the security teams of BitDefender and Yahoo appears to have stymied attempts by the criminals behind the Trojan.Spammer.HotLan, to generate and use Yahoo accounts to send spam.

However, the malware authors have now switched to generating Hotmail and Gmail accounts to send their spam, apparently having found a way of bypassing the captcha systems of the two webmail providers.

The captchas are supposed to ensure that it is humans, not computers trying to create the account, in an effort to stem exactly this kind of service abuse.

Every active copy of the HotLan trojan tries to create an account, sending off the captcha image in an encrypted form to a spammer-controlled website, wherefrom a solution is sent back to it and entered in the appropriate field. Then, the trojan pulls encrypted spam e-mails from another website, decrypts them and sends them to (presumably valid) addresses taken from yet another website.

'There were 514 thousand Hotmail accounts created as of Friday, as well as about 49 thousand at Google,' commented Viorel Canja, head of BitDefender Antivirus Lab. 'However, it is worth noting that while most of the Hotmail accounts are operational, Gmail accounts get blocked pretty fast, usually about a couple of days after being created.'

BitDefender was the first security company to detect the trojan and add a generic signature, which has been successful in identifying all the versions of the trojan created so far. BitDefender analysts determined that the trojan is not widespread, which might indicate a desire to keep a low profile on the part of its creators.

BitDefender has offered support to the affected parties.

Bookmark and Share
 
Home I Editor's Blog I News by Zone I News by Date I News by Category I Special Reports I Directory I Events I Advertise I Submit Your News I About Us I Guides
 
   © 2012 ProSecurityZone.com
Netgains Logo