Home PCs hijacked to spread spam
Posted: Fri Oct 08, 2004 7:10 am
Home PCs hijacked to spread spam
By Mark Ward
BBC News Online technology correspondent
There is a good chance that your home computer has been hijacked by spammers if you have a broadband net link, but are not using a firewall or anti-virus software to protect your PC.
Even if you use anti-virus software but do not keep it up to date, there is every possibility that you are helping to keep spam alive and spreading.
You could also be helping if you are one of those people that open up attachments on e-mail messages that turn out to contain viruses, rather than the pictures you were promised in a subject line.
Spammers are actively seeking out and hijacking home PCs to act as remotely controlled relays, or zombies, that pass on their unwanted messages.
Viruses such as MSBlaster, Agobot, MyDoom and Sobig were all written with the aim of converting home PCs to the spammers cause.
And they have succeeded in huge numbers.
So much so that law enforcement agencies report that zombie nets can now be hired by the hour to pass on spam or other unwanted messages.
Huge army
Technology firm Sandvine estimates that 1% of all the active hosts on the net could be compromised.
That means potentially millions of computers waiting to act on the instructions of their spam-sending masters.
"85% of e-mail leaving broadband residential networks is likely to be spam," said Tom Donnelly, founder of Sandvine.
It reached this estimate by analysing traffic from customers for the tell-take signs of spam sent by infected machines.
It is easy to check the scale of infection on many broadband networks thanks to sites such as SenderBase.
This site shows the number of messages flowing through particular net addresses.
Type in the name of almost any broadband net service firm and you will find that many of the PCs used by subscribers are sending out as many, and sometimes more, messages as that company's designated e-mail servers.
Given that many broadband net firms have millions of customers that adds up to a lot of spam.
Net firms are keen to stamp out the problem because of the bandwidth costs they incur passing on huge amounts of traffic and because net addresses used for spam are typically blocked by everyone else in the internet world.
SenderBase measures e-mail output by magnitude, just like earthquakes, and a search for the names of British high-speed net firms shows that many addresses are spewing out as many as a million messages per day.
Network trouble
"It's a big problem," said Mike Galvin, head of internet operations at BT. "Spammers do this because if they used their own machine they would be banned from the net."
BT contacts customers directly when it discovers that a PC has been compromised and offers advice about how to clean up their computer and stop it happening again.
"A lot of people genuinely do not know it could happen to them," said Mr Galvin.
A spokeswoman for NTL said that it had seen an increase in attempts to create zombie computers over the last few months.
It said it regularly contacts customers to help them sort out their PC and stop it being used by the spammers.
A spokeswoman for Telewest said that currently it was tackling about 8-10 cases per week of compromised computers.
"We're cracking down quite heavily on open relays and have been for a few months now," she said.
It too talks subscribers through cleaning up a PC, installing anti-virus software and setting up a firewall.
"We have gone through early adopters. Now we're getting into the people who maybe do not completely understand that there are a few security implications when using broadband," she said.
Sandvine's Mr Donnelly agreed saying that late adopters of broadband do not see what they are getting as a technology. Instead, he said, they see it as a utility that they simply plug in and use.
Unfortunately without care they could find themselves helping the spammers, he said.
"Most people see themselves as victims of spam," said Mr Donnelly, "rather than potentially participants in its distribution."
[url=\"http://news.bbc.co.uk/1/hi/technology/3528810.stm\"]source[/url]
By Mark Ward
BBC News Online technology correspondent
There is a good chance that your home computer has been hijacked by spammers if you have a broadband net link, but are not using a firewall or anti-virus software to protect your PC.
Even if you use anti-virus software but do not keep it up to date, there is every possibility that you are helping to keep spam alive and spreading.
You could also be helping if you are one of those people that open up attachments on e-mail messages that turn out to contain viruses, rather than the pictures you were promised in a subject line.
Spammers are actively seeking out and hijacking home PCs to act as remotely controlled relays, or zombies, that pass on their unwanted messages.
Viruses such as MSBlaster, Agobot, MyDoom and Sobig were all written with the aim of converting home PCs to the spammers cause.
And they have succeeded in huge numbers.
So much so that law enforcement agencies report that zombie nets can now be hired by the hour to pass on spam or other unwanted messages.
Huge army
Technology firm Sandvine estimates that 1% of all the active hosts on the net could be compromised.
That means potentially millions of computers waiting to act on the instructions of their spam-sending masters.
"85% of e-mail leaving broadband residential networks is likely to be spam," said Tom Donnelly, founder of Sandvine.
It reached this estimate by analysing traffic from customers for the tell-take signs of spam sent by infected machines.
It is easy to check the scale of infection on many broadband networks thanks to sites such as SenderBase.
This site shows the number of messages flowing through particular net addresses.
Type in the name of almost any broadband net service firm and you will find that many of the PCs used by subscribers are sending out as many, and sometimes more, messages as that company's designated e-mail servers.
Given that many broadband net firms have millions of customers that adds up to a lot of spam.
Net firms are keen to stamp out the problem because of the bandwidth costs they incur passing on huge amounts of traffic and because net addresses used for spam are typically blocked by everyone else in the internet world.
SenderBase measures e-mail output by magnitude, just like earthquakes, and a search for the names of British high-speed net firms shows that many addresses are spewing out as many as a million messages per day.
Network trouble
"It's a big problem," said Mike Galvin, head of internet operations at BT. "Spammers do this because if they used their own machine they would be banned from the net."
BT contacts customers directly when it discovers that a PC has been compromised and offers advice about how to clean up their computer and stop it happening again.
"A lot of people genuinely do not know it could happen to them," said Mr Galvin.
A spokeswoman for NTL said that it had seen an increase in attempts to create zombie computers over the last few months.
It said it regularly contacts customers to help them sort out their PC and stop it being used by the spammers.
A spokeswoman for Telewest said that currently it was tackling about 8-10 cases per week of compromised computers.
"We're cracking down quite heavily on open relays and have been for a few months now," she said.
It too talks subscribers through cleaning up a PC, installing anti-virus software and setting up a firewall.
"We have gone through early adopters. Now we're getting into the people who maybe do not completely understand that there are a few security implications when using broadband," she said.
Sandvine's Mr Donnelly agreed saying that late adopters of broadband do not see what they are getting as a technology. Instead, he said, they see it as a utility that they simply plug in and use.
Unfortunately without care they could find themselves helping the spammers, he said.
"Most people see themselves as victims of spam," said Mr Donnelly, "rather than potentially participants in its distribution."
[url=\"http://news.bbc.co.uk/1/hi/technology/3528810.stm\"]source[/url]