{"id":220,"date":"2009-04-20T18:54:43","date_gmt":"2009-04-20T10:54:43","guid":{"rendered":"http:\/\/www.computersolutions.cn\/blog\/?p=220"},"modified":"2009-04-20T18:54:43","modified_gmt":"2009-04-20T10:54:43","slug":"spam-from-livecom","status":"publish","type":"post","link":"https:\/\/www.computersolutions.cn\/blog\/2009\/04\/spam-from-livecom\/","title":{"rendered":"Spam from Live.com"},"content":{"rendered":"<p>We&#8217;re seeing a huge recurrence of spam thats been getting through our spam filters., all coming from @live.com addresses.<br \/>\nI hadn&#8217;t seen any personally until one of our clients brought up the fact that she was receiving 20-30 sex related spam a day, all coming from Random name @live.com addresses.<\/p>\n<p>A check of the logs showed that we&#8217;ve received at least 100,000 of these spam mails over the last month that have gotten through to our users.<br \/>\nThis is something I&#8217;d obviously like to remedy.\u00a0 Not receiving, processing, or storing that much spam free&#8217;s up the servers for other things.<\/p>\n<p>As the number of valid addresses using @live.com accounts appears to be minimal (I could only see a handful of legitimate users sending from that domain), I have taken the decision to block any email from the @live.com domain until Microsoft can resolve their spam issues.<\/p>\n<p>If you do have clients using @live.com addresses, you will be able to send email to them, but not receive from them.<br \/>\nWe apologize for the inconvenience, but unfortunately there is no other solution that easily mitigates the issue, other than completely blocking them.<\/p>\n<p>For a more technical explanation of whats happening, read below:<br \/>\n<!--more--><br \/>\nThis is a header from a sample spam email from a live.com address.<br \/>\nAs you can see below, the header shows that it passes an SPF check &#8211; meaning that the sending email server was verified to be a microsoft one.<br \/>\nThat means that the sender also passes our greylist and SPF checks, as Hotmail is a valid sender (for most of the time!).<\/p>\n<blockquote><p>Return-Path: &lt;lourdesuxanbirr1980@live.com&gt;<br \/>\nDelivered-To: XXXX<br \/>\nReceived: (qmail 3070 invoked from network); 20 Apr 2009 11:53:37 +0800<br \/>\nDomainKey-Status: no signature<br \/>\nReceived: from blu0-omc2-s16.blu0.hotmail.com (65.55.111.91)<br \/>\nby mail.computersolutions.cn with SMTP; 20 Apr 2009 11:53:37 +0800<br \/>\nReceived-SPF: pass (mail.computersolutions.cn: SPF record at spf-a.hotmail.com designates 65.55.111.91 as permitted sender)<br \/>\nReceived: from BLU128-W5 ([65.55.111.72]) by blu0-omc2-s16.blu0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959);<br \/>\nSun, 19 Apr 2009 20:54:11 -0700<br \/>\nMessage-ID: &lt;BLU128-W51B2E2DECCF46C5980E74DC760@phx.gbl&gt;<br \/>\nReturn-Path: lourdesuxanbirr1980@live.com<br \/>\nX-Originating-IP: [201.150.66.6]<br \/>\nFrom: Lourdes Browne &lt;Lourdesuxanbirr1980@live.com&gt;<br \/>\nSender: &lt;lourdesuxanbirr1980@live.com&gt;<br \/>\nTo: XXXXX<br \/>\nSubject: Hi! This is Muriel. Young girls in action with animals.<br \/>\nDate: Mon, 20 Apr 2009 03:54:11 +0000<br \/>\nImportance: Normal<br \/>\nContent-Type: text\/plain; charset=&#8221;iso-8859-1&#8243;<br \/>\nContent-Transfer-Encoding: quoted-printable<br \/>\nMIME-Version: 1.0<br \/>\nX-OriginalArrivalTime: 20 Apr 2009 03:54:11.0766 (UTC) FILETIME=[AA2F5560:01C9C16B]<\/p><\/blockquote>\n<p>As the sender is a legitimate hotmail \/ live account &#8220;lourdesuxanbirr1980@live.com&#8221; (albeit a garbage generated name), its probable that the sender is generated from a script.<\/p>\n<p>A check on google reveals that the live.com captcha system has been cracked, and is being abused by botnets to send spam.<\/p>\n<p><a href=\"http:\/\/arstechnica.com\/security\/news\/2008\/04\/gone-in-60-seconds-spambot-cracks-livehotmail-captcha.ars\">http:\/\/arstechnica.com\/security\/news\/2008\/04\/gone-in-60-seconds-spambot-cracks-livehotmail-captcha.ars<\/a><\/p>\n<p>This probably explains the sudden flood of spam coming from @live.com addresses, although its a bit strange that we didn&#8217;t see this sooner!<br \/>\nHopefully they&#8217;ll resolve it soon, so we can unblock them.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We&#8217;re seeing a huge recurrence of spam thats been getting through our spam filters., all coming from @live.com addresses. I hadn&#8217;t seen any personally until one of our clients brought up the fact that she was receiving 20-30 sex related spam a day, all coming from Random name @live.com addresses. A check of the logs [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[73,48,25],"tags":[96,94,95,76],"class_list":["post-220","post","type-post","status-publish","format-standard","hentry","category-email","category-exploits","category-technical-mumbo-jumbo","tag-botnet","tag-live","tag-microsoft","tag-spam"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.computersolutions.cn\/blog\/wp-json\/wp\/v2\/posts\/220","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.computersolutions.cn\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.computersolutions.cn\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.computersolutions.cn\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.computersolutions.cn\/blog\/wp-json\/wp\/v2\/comments?post=220"}],"version-history":[{"count":1,"href":"https:\/\/www.computersolutions.cn\/blog\/wp-json\/wp\/v2\/posts\/220\/revisions"}],"predecessor-version":[{"id":221,"href":"https:\/\/www.computersolutions.cn\/blog\/wp-json\/wp\/v2\/posts\/220\/revisions\/221"}],"wp:attachment":[{"href":"https:\/\/www.computersolutions.cn\/blog\/wp-json\/wp\/v2\/media?parent=220"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.computersolutions.cn\/blog\/wp-json\/wp\/v2\/categories?post=220"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.computersolutions.cn\/blog\/wp-json\/wp\/v2\/tags?post=220"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}