Re: [Shutup] [ietf-smtp] Levels of proposals

Chris Lewis <> Fri, 04 December 2015 13:11 UTC

Return-Path: <>
Received: from localhost ( []) by (Postfix) with ESMTP id 564E01B3149; Fri, 4 Dec 2015 05:11:02 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: 3.043
X-Spam-Level: ***
X-Spam-Status: No, score=3.043 tagged_above=-999 required=5 tests=[BAYES_50=0.8, FH_RELAY_NODNS=1.451, RDNS_NONE=0.793, SPF_PASS=-0.001] autolearn=no
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id UIx97EAxfqPz; Fri, 4 Dec 2015 05:11:01 -0800 (PST)
Received: from (unknown []) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 4BEC91B3147; Fri, 4 Dec 2015 05:11:01 -0800 (PST)
Received: from [] ( []) (authenticated bits=0) by (8.14.4/8.14.4/Debian-4.1ubuntu1) with ESMTP id tB4DAw7H020750 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT); Fri, 4 Dec 2015 08:10:59 -0500
References: <> <> <>
From: Chris Lewis <>
X-Enigmail-Draft-Status: N1110
Message-ID: <>
Date: Fri, 4 Dec 2015 08:10:58 -0500
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv: Gecko/20090812 Thunderbird/ Mnenhy/
MIME-Version: 1.0
In-Reply-To: <>
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 7bit
Archived-At: <>
Subject: Re: [Shutup] [ietf-smtp] Levels of proposals
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: SMTP Headers Unhealthy To User Privacy <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Fri, 04 Dec 2015 13:11:02 -0000

On 12/03/2015 09:11 PM, Ted Lemon wrote:

> Can you unpack "AUTH-cracking spambots" for the greenhorns?   I have no idea what this means, and google unfortunately was unable to help.

Primarily botnets that connect to MSAs and use stolen (or potentially 
brute-forced) userid/password credentials in order to use the MSA/MTA 
combo as an open relay.

There's at least one major windows executable botnet that does this in 
very high volumes.  This is a particularly long-standing botnet that has 
many other nasty tricks at its disposal (DDOS, keystroke harvesting, 
account stealing etc).

There are several web server compromises that do the same thing, 
potentially using the same sources for compromised userid/passwords, 
tho, these aren't nearly the volume as the aforementioned botnet.

It's really quite surprising how successful that some spam campaigns are 
in doing this, and I can only imagine that at least part of it is  the 
botnet dredging out an infected user's MSA/userid/password triple from 
their mail reader and propagating it to the rest of the botnet (along 
with harvesting address books), and hence have enormous numbers of 
compromised accounts to exploit.  They may also be using more generic 
userid/password dumps from online site leaks.

We've seen ISPs subject to massive attacks where hundreds or thousands 
(or more) of different IPs do authenticated MSA submissions of 10s or 
100s of thousands of spams in fairly short (hours) intervals, resulting 
in traffic flows 100s of times above normal to the point of overloading 
the ISP's MSAs.  This is even with quite aggressive per-user and per-IP 
rate limiting.

AUTH-cracking to this extent is a relatively recent phenomena, and is 
clearly being used as an attempt to bypass normal direct-2-MX botnet 
blocking and hijack the reputation of the MTA instead of some random 
cracked PC.