Sign In
Terry Zink's Cyber Security Blog
Discussing Internet security in (mostly) plain English
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Common Tasks
Blog Home
Email Blog Author
About
OK
RSS for comments
RSS for posts
Atom
Search
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tags
Authentication
Backscatter
Botnets
Economics
Education
Entertainment
Facebook
Foreign language
Hacking
Legal
Malware
Miscellaneous
Net Neutrality
Outbound
Pages
Privacy
Reputation
Security
Social Networking
Spam
Stories
Monthly Archives
Archives
February 2012
(7)
January 2012
(21)
December 2011
(6)
November 2011
(12)
October 2011
(13)
September 2011
(12)
August 2011
(15)
July 2011
(14)
June 2011
(11)
May 2011
(11)
April 2011
(11)
March 2011
(11)
February 2011
(9)
January 2011
(1)
December 2010
(19)
November 2010
(16)
October 2010
(18)
September 2010
(16)
August 2010
(16)
July 2010
(16)
June 2010
(16)
May 2010
(16)
April 2010
(21)
March 2010
(25)
February 2010
(17)
January 2010
(13)
December 2009
(13)
November 2009
(17)
October 2009
(18)
September 2009
(13)
August 2009
(12)
July 2009
(15)
June 2009
(12)
May 2009
(13)
April 2009
(10)
March 2009
(9)
February 2009
(9)
January 2009
(16)
December 2008
(15)
November 2008
(16)
October 2008
(13)
September 2008
(19)
August 2008
(16)
July 2008
(16)
June 2008
(15)
May 2008
(14)
April 2008
(15)
March 2008
(17)
February 2008
(15)
January 2008
(14)
December 2007
(16)
November 2007
(12)
October 2007
(16)
September 2007
(16)
August 2007
(8)
July 2007
(15)
June 2007
(16)
May 2007
(15)
April 2007
(11)
March 2007
(10)
February 2007
(9)
January 2007
(20)
December 2006
(14)
November 2006
(8)
October 2006
(14)
September 2006
(13)
August 2006
(22)
July 2006
(12)
October, 2009
MSDN Blogs
>
Terry Zink's Cyber Security Blog
>
October, 2009
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Terry Zink's Cyber Security Blog
Live Free or Die Hard
Posted
over 3 years ago
by
tzink
3
Comments
Spoiler alert. This past weekend, I got a chance to watch the 4th installment in the Die Hard series, Live Free or Die Hard . I hadn’t seen the whole thing end-to-end before, only parts of it. It was nice to finally get a chance to see the...
Terry Zink's Cyber Security Blog
The evolving MAAWG
Posted
over 3 years ago
by
tzink
1
Comments
MAAWG is an organization that started up in response to the spam problem. Its official name is the Messaging Anti-Abuse Working Group, and they are meeting this week in Philadelphia to discuss all things abusive. I didn’t go this time around...
Terry Zink's Cyber Security Blog
What’s waledac up to these days?
Posted
over 3 years ago
by
tzink
0
Comments
Just for the fun of it, I decided to check some statistics on the waledac botnet. I got the total number of distinct IPs sending us spam and broke them out by how much spam they were sending us, by country, for Oct 22, 2009. Below are the...
Terry Zink's Cyber Security Blog
Things we can learn from Animaniacs
Posted
over 3 years ago
by
tzink
3
Comments
Does anyone remember that cartoon from the 1990’s, Animaniacs? It was a pretty good cartoon for its short run. One of the segments that they aired was called “Good Idea, Bad Idea”. It was a short clip segment. It would go something like...
Terry Zink's Cyber Security Blog
Keeping track of botnets
Posted
over 3 years ago
by
tzink
0
Comments
A couple of months ago, I posted a one-day snapshot of how much spam we see from individual botnets. I’ve been keeping track since July 29 on the biggest ones that have names, and only for IPs that get past our RBLs. At the time of my first...
Terry Zink's Cyber Security Blog
I don’t know what it is…
Posted
over 3 years ago
by
tzink
0
Comments
I don’t know what it is, but whenever I hear the name of the waledac botnet, I always think of Wario from the Super Mario Bros. series. Something about both starting with the letters Wa, both being three syllables, both being bad guys, both using...
Terry Zink's Cyber Security Blog
Fooled today… almost
Posted
over 3 years ago
by
tzink
0
Comments
Today, I got a spam in my junk mail folder that nearly fooled me. Below are the headers with some information removed to protect trade secrets: Received: from VA3EHSMHS008.bigfish.com (unknown [10.7.14.235]) by mail29-va3.bigfish.com (Postfix) with...
Terry Zink's Cyber Security Blog
Best practices for sending outbound mail
Posted
over 3 years ago
by
tzink
0
Comments
One of the questions that I am frequently asked is if we get a sudden burst of outbound mail from a customer using us to send outbound, will we throttle their mail? Throttling is the process of slowing down outbound mail such that a sending organization...
Terry Zink's Cyber Security Blog
How to reclaim your sender reputation, part 10 - Results
Posted
over 3 years ago
by
tzink
0
Comments
Results Forefront Online (ie, us) has come a long way in reclaiming its outbound reputation. The question now is this – has it worked? I will report on some anecdotal evidence. The Good To determine whether or not we have gotten better, I prefer to check...
Terry Zink's Cyber Security Blog
How to reclaim your sender reputation, part 9 – disabling offenders
Posted
over 3 years ago
by
tzink
0
Comments
Continuing on in my 9 part series , the process of mitigating an outbound spam problem occurs in a two-fold manner. Usually they are mutually exclusive, but one can lead to the other. Cutting off mail only for the offending email address This is the default...
Terry Zink's Cyber Security Blog
Are we seeing more spam from Gmail, Hotmail and Yahoo?
Posted
over 3 years ago
by
tzink
0
Comments
Last week, I commented on the the Gmail/Hotmail/Yahoo username and password leak. The question we now ask is whether or not we are seeing an increased amount of spam from those services. The folks from All Spammed Up recently posted that various...
Terry Zink's Cyber Security Blog
How to reclaim your sender reputation, part 8 – More pattern analysis
Posted
over 3 years ago
by
tzink
0
Comments
Islands Islands are named that way because their appearance looks like an island – a time zone infraction in which the middle sticks out above the others. Another term for this pattern is the head-and-shoulders pattern. Islands are the most ambiguous...
Terry Zink's Cyber Security Blog
Yahoo, Gmail, Hotmail compromised
Posted
over 3 years ago
by
tzink
0
Comments
I wasn’t going to comment on this until later, but the story is spreading; there’s a link off the Yahoo Canada homepage. 10,000 usernames and passwords were posted this past week, victims of a phishing scam. From Computerworld : If (technology...
Terry Zink's Cyber Security Blog
How to reclaim your sender reputation, part 7 – Pattern analysis
Posted
over 3 years ago
by
tzink
0
Comments
Mountains A mountain pattern is when each subsequent monitoring of an outbound spam problem is worse than the previous time. It looks like you are climbing a mountain. Once a threshold is crossed, an alert is generated. Mountains generate the most obvious...
Terry Zink's Cyber Security Blog
The multinational nature of spam
Posted
over 3 years ago
by
tzink
0
Comments
I received a spam message the other day that went to my Junk Mail Folder. I decided to take a look at it and dissect it piece by piece. It really is amazing to see how spam crosses so many international borders and exploits so many different...
Terry Zink's Cyber Security Blog
How to reclaim your sender reputation, part 6 – Noise reduction
Posted
over 3 years ago
by
tzink
0
Comments
Pattern Detection and Noise Reduction The amount of noise inherent in outbound spam detection is high. End users will routinely mark messages as spam that aren’t actually spam. An example of this would be company billing reports; these are not spam but...
Terry Zink's Cyber Security Blog
How to reclaim your sender reputation, part 5 - Monitoring
Posted
over 3 years ago
by
tzink
0
Comments
Monitoring FOSE has implemented a lot of different mechanisms to mitigate the spam problem. These include, but are not limited to, the following: Routing all mail from non-customer domains that is marked as spam through the NDR pool. Changing (1) and...
Terry Zink's Cyber Security Blog
How to reclaim your sender reputation, part 4 – More options
Posted
over 3 years ago
by
tzink
0
Comments
Option 3 - Keep track of the mail disposition and cut off the entire organization This was one of the original ideas proposed to solving the outbound spam problem. The idea is to filter the mail and write the disposition (spam vs non-spam) to an...
Page 1 of 1 (18 items)