Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Slashdot Log In

Log In

Create Account  |  Retrieve Password

Where Has All My Spam Gone?

Posted by kdawson on Fri Aug 15, 2008 09:10 AM
from the yesterday-upon-the-stair dept.
An anonymous reader writes "I have my own domain, which has its own email server, where I receive all my personal email. I've been getting about 800 emails a day, of which perhaps 20 are real. Suddenly, Sunday or Monday evening, the spam pretty much stopped. My volume of mail has plummeted to less than 100 a day, and as far as I can tell, I'm not missing any real mail — I'm still getting the email list subscriptions I'm expecting, and every time I ask someone to send me a test message, it gets through. My domain host insists that it doesn't do any spam filtering before mail gets to my inbox, and that they've changed nothing about their configuration. I run SpamAssassin on my server to mark, but not delete, spam, and download the whole mess to my home client, and I'm still seeing the occasional message tagged by SpamAssassin. But it's virtually all gone. And I haven't changed anything about my own mail configuration, or the harvestability of my site (my personal email has been harvestable for almost a decade). So what's going on? I can't believe that several major botnets would have vanished overnight. Any ideas?"
+ -
story

Related Stories

This discussion has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
  • Hmm (Score:5, Informative)

    by geminidomino (614729) * on Friday August 15 2008, @09:10AM (#24614491) Homepage Journal

    *Checks mail logs*

    Yeh, you need to ask the ISP again. No sign of slowing here.

    • Re:Hmm (Score:5, Informative)

      by urbanriot (924981) on Friday August 15 2008, @09:13AM (#24614547)
      Agreed. No changes in spam over here, my domain is still receiving the daily average of about 100 per day.
      • Re:Hmm (Score:5, Informative)

        by Southpaw018 (793465) * on Friday August 15 2008, @09:27AM (#24614891) Journal
        Thirded over here. Solid 7000/day for months (small business).
        • Re:Hmm (Score:5, Funny)

          by VenomPhallus (904463) on Friday August 15 2008, @09:45AM (#24615231)

          Yup, and here; still getting 250 a day+ or so.

          Maybe they finally clicked that you've already got a huge penis and legendary bedroom performance?

          • Re:Hmm (Score:5, Funny)

            by tha_mink (518151) on Friday August 15 2008, @09:50AM (#24615341)
            Perhaps the botnets are busy fighting amongst themselves, vis a vis the Georgia v. Russia conflict.
            • Re:Hmm (Score:5, Funny)

              by Like2Byte (542992) <Like2Byte.yahoo@com> on Friday August 15 2008, @10:22AM (#24615897) Homepage

              Perhaps the botnets are busy fighting amongst themselves, vis a vis the Georgia v. Russia conflict.

              Ok, Agent Mulder, settle down.

            • Re:Hmm (Score:5, Funny)

              by Anonymous Coward on Friday August 15 2008, @10:33AM (#24616037)
              The Russian spammers can't get bandwidth because the military is busy using it against Georgia.
            • Re:Hmm (Score:5, Interesting)

              by swb (14022) <mobocracy@gmail.com> on Friday August 15 2008, @10:46AM (#24616303)

              There's something to that, even if the original poster's claim of not having spam anymore is local to him through unknown upstream changes.

              Its long been suspected that the Russian government and Russian organized crime have cooperative links, if not outright overlapping "membership" (Putin is FSA/KGB, and its well known that ex-KGB members have been deeply involved in the Russian Mafia).

              With this in mind, its not hard to speculate that if botnets controlled by Russian organized crime were put use against pro-Georgian assets, the ensuing defenses, publicity and exposure at the political/military level could possible cause these botnets to be far more vulnerable than they otherwise would be in the course of normal criminal activity.

              This higher level exposure might lead to weakening them and reduce their effectiveness at normal tasks like spam.

              Its also possible they may also be overutilized and prioritized for cyberwarfare and not for spam.

      • Re:Hmm (Score:5, Informative)

        by y86 (111726) on Friday August 15 2008, @09:56AM (#24615447)

        Agreed. No changes in spam over here, my domain is still receiving the daily average of about 100 per day.

        You should REALLY consider trying postgrey.

        http://postgrey.schweikert.ch/ [schweikert.ch]

        Postgrey on non whitelisted servers rejects the first mail attempt with a fail. The sending email server will retry X times, but the 2nd time it accepts it and adds the server to the whitelist.

        Postgrey will add a 5 minute lag to an email that's sending server has never sent an email to you. It's worth it to screw the spammers zombies over IMHO.

        Also, I would check your postfix/whatever you are using for a mail servers policy. I get 0 spam emails now and my address is posted all over the web.

        I do have spamassassin running as well with sieve filtering to put what is marked as spam in a junk folder but the junk folder is empty, every now and then I'll see something -- but very rarely. Like once every 2 months.

        Here's my spam prevention system :-)

        smtpd_recipient_restrictions =
            permit_mynetworks,
            permit_sasl_authenticated,
            reject_unauth_destination,
            reject_non_fqdn_sender,
            reject_unknown_sender_domain,
            reject_non_fqdn_recipient,
            reject_unknown_recipient_domain,
            reject_unauth_destination,
            reject_rbl_client zen.spamhaus.org,
            reject_rbl_client bl.spamcop.net,
            check_policy_service inet:127.0.0.1:60000

        • Re:Hmm (Score:5, Informative)

          by j-cloth (862412) on Friday August 15 2008, @10:35AM (#24616069)
          A huge second to PostGrey. It kills 90% of my incoming spam before it even touches spamassassin. However, I have noticed a few people who receive failure messages from their mail systems telling them that they've been greylisted before the mail goes through. Then uppy-ups whine to me.
    • Re:Hmm (Score:5, Funny)

      by ElizabethGreene (1185405) on Friday August 15 2008, @09:25AM (#24614837)
      A group of the original SpamAssassin developers got together with a group of mercenaries and created SpammerAssassin. It's in alpha, and looks good except it seems to have started a teeny-tiny war in the eastern bloc. Oops. They have an open bug ticket on it.

      :D
      • Re:Hmm (Score:5, Funny)

        by oldspewey (1303305) on Friday August 15 2008, @09:34AM (#24615029)
        Seriously though ... if spammers started turning up dead where would the police even begin their investigation? There's only a pool of what, half a billion suspects?
    • by r_cerq (650776) on Friday August 15 2008, @10:21AM (#24615881)

      I've just checked my work's logs (an ISP). The number of hits in the spam taggers fell from 12/sec to 3/sec earlier this week.

      So either we're identifying less spam, or there is in fact less of it.

  • by digitrev (989335) <digitrev@hotmail.com> on Friday August 15 2008, @09:11AM (#24614497) Homepage
    My spam has tripled over the past few days. So I'm not getting all of it, but I'm getting a chunk of it.
      • Re:I'm getting it (Score:5, Interesting)

        by ShadowBlasko (597519) on Friday August 15 2008, @09:34AM (#24615015) Homepage
        Heh, we've got a virus running around the site lately that is titled "CNN Gold Medal tracker".

        Sneaky ...
      • Re:I'm getting it (Score:5, Interesting)

        by SatanicPuppy (611928) * <<Satanicpuppy> <at> <gmail.com>> on Friday August 15 2008, @09:40AM (#24615145) Journal

        We've been getting a lot of "reverse spam"...The organizational emails are necessarily public, so some enterprising Russian has harvested the entire set and is using them as "REPLY-TO" addresses, so we get all the bounce messages from their damn spamming.

        It's all the fun of having an exploited mail server without actually having an exploited mail server. The mail doesn't actually come from us so we're not having any blacklist problems, but the floods of bounce messages zip right through the spam filters and piss off the users.

        • Re:I'm getting it (Score:5, Insightful)

          by nabsltd (1313397) on Friday August 15 2008, @10:03AM (#24615581)

          Don't you hate it that you have to deal with this sort of thing because some other mail server isn't configured correctly?

          If all mail servers instituted the policy of "reject...don't accept then bounce", then there wouldn't be any blowback spam. Unfortunately, there is some MTA software that can't do the right thing without non-standard add-ons (qmail, I'm looking at you).

      • Re:I'm getting it (Score:5, Insightful)

        by KillerBob (217953) on Friday August 15 2008, @09:52AM (#24615363)

        I've seen a huge increase in both spam and particularly spam that makes it past my spam filter.

        It's an arms race. They come out with a new message that tricks the filters into thinking it's real. The filters update and adapt. They rethink things and come out with a new junk message which sometimes succeeds, sometimes doesn't. When they find one that works, I start getting spam again until the filters adapt. Ad nauseum.

        I've got my SpamAssassin filters set to update on a daily cron job, and it's always the same... Every week or two, I get a handful of spam messages getting past the filters. They're all basically the same. And it lasts for about a day before I stop getting spam again. So it comes in bursts for me, every time the spammers rethink the message they send out.

        I've had my domain, and the same e-mail address for half a decade. My IP address did recently change when I moved into a new colo, but all of the DNS has updated already, so the spammers still know who I am. It's annoying. But it is manageable.

  • by bugeaterr (836984) on Friday August 15 2008, @09:13AM (#24614525)

    Did you install Skynet 1.0?

    Hey, what's that siren going off for....

  • Because... (Score:5, Funny)

    by Capt James McCarthy (860294) on Friday August 15 2008, @09:13AM (#24614549) Journal

    When spammers took over your box, they didn't want to flood it with their own mail.

  • One down (Score:5, Informative)

    by canderley (1234622) on Friday August 15 2008, @09:14AM (#24614553)
    Per Ars, a 100,000 machine bot net was shut down recently. http://arstechnica.com/news.ars/post/20080814-police-nab-shadow-creators-force-botnet-to-commit-suicide.html [arstechnica.com]
  • Oops... (Score:5, Funny)

    by bhamlin (986048) on Friday August 15 2008, @09:14AM (#24614557) Homepage

    Sorry, we've been down for maintenance and it's taking a lot longer than we originally planned. You can expect normal service to resume by next monday.

  • by Seakip18 (1106315) on Friday August 15 2008, @09:14AM (#24614581) Journal

    Spam Assassin is actually assassinating spam.

    On another note, has anyone heard from cousin who is a Nigerian prince? He hasn't called in days and we're beginning to get worried.....

  • by Anonymous Coward on Friday August 15 2008, @09:16AM (#24614621)
    ... to save the health of the athletes.
  • by NMBob (772954) on Friday August 15 2008, @09:16AM (#24614623)
    ...and the Chinese are busy watching 13-year olds win gold metals. Bob
  • We Can Test (Score:5, Funny)

    by awitod (453754) on Friday August 15 2008, @09:16AM (#24614625)

    We're happy to help you solve this mystery.
    What is your email address?

  • by Bogtha (906264) on Friday August 15 2008, @09:16AM (#24614627)

    Okay, here's the thing: nobody but you ever got spam. We all just thought it would be funny to fool you into thinking there was some kind of worldwide scamming epidemic. You don't seriously think people would be stupid enough to buy pills off strangers who email them out of the blue, do you? I thought we'd gone a bit too far and stretched the limits of credibility when we came up with the idea for the Nigerian scams, but I was wrong, you even fell for that! Nobody is stupid enough to send all their money to a "Nigerian prince".

    Anyway, enough's enough. The joke's stale now, so we decided to stop sending it all to you.

  • by Toe, The (545098) on Friday August 15 2008, @09:16AM (#24614637)

    A large chunk of spam comes from a very small group of spammers. It may just be that you are only targeted by one of them, and he took a break recently.

    Hang in there... he'll come back from vacation soon, and you'll be able to mortgage your penis to Nigeria again.

  • by suso (153703) * on Friday August 15 2008, @09:17AM (#24614659) Homepage Journal

    I run a web hosting company and over the past couple weeks I've had a few customers report that the amount of spam has dropped. Of course, they thought that this was something wrong, but I couldn't find any evidence of increased failures, it was just that there was slightly less mail coming in.

  • by Wrath0fb0b (302444) on Friday August 15 2008, @09:18AM (#24614695)

    http://it.slashdot.org/article.pl?sid=08/08/12/191255&from=rss [slashdot.org]
    http://bits.blogs.nytimes.com/2008/08/11/georgia-takes-a-beating-in-the-cyberwar-with-russia/ [nytimes.com]

    When the crisis abates, I expect the botnets will be returned to their regularly scheduled duties. Quite a versatile tool those botnets -- pimping V!agr4, collapsing government sites, enhancing the male doodad, distributing pr0n, bullying your neighbors (http://news.bbc.co.uk/2/hi/europe/6665145.stm [bbc.co.uk]). For the cost of one M1A1 tank tread, Putin bought himself a whole lot of firepower.

    Advantage: Putin.

  • headless botnets (Score:5, Interesting)

    by Lord Ender (156273) on Friday August 15 2008, @09:20AM (#24614731) Homepage

    We've been seeing botnets changing desktop background to an image alerting people that they are infected with a virus. Obviously a real spam botnet operator would not alert people like that.

    My theory is that some grayhat wrested control of a major botnet, and is shutting it down from the source (and alerting the victims in the process).

  • by Sloppy (14984) on Friday August 15 2008, @09:22AM (#24614757) Homepage Journal
    Dear Sir,
    We humbly apologize for the interruption in service. Please reply with your email address and our technical staff will get back to you.
  • by IceCreamGuy (904648) on Friday August 15 2008, @09:40AM (#24615129) Homepage
    Maybe you could forward some spam from, say, a gmail account to your address in question. If it doesn't make it through to your server then you have a definitive record to confront your ISP with. Or, if they do get through, maybe you should buy a lottery ticket because your the luckiest admin on slashdot!
  • Black Hat (Score:5, Funny)

    by machine321 (458769) on Friday August 15 2008, @09:45AM (#24615229)

    They all just got back from Black Hat / Defcon, and they're still hung over.

  • by Kirys (662749) on Friday August 15 2008, @09:59AM (#24615517) Homepage
    Most spam is sent by bot-nets, mostly composed by infected pc of workplaces, school and private homes. In many countries during the second and third week of August many schools and workplaces are closed so their pc are just turned off, this mean that the bot-nets have less active nodes and so are less effective. I do receive less spam too but I think that it will be back to the sad old amount at the end of the summer :(
    • Re:Okay (Score:5, Insightful)

      by kinzillah (662884) <douglas,price&mail,rit,edu> on Friday August 15 2008, @09:14AM (#24614563)
      Perhaps he'd like to leave it to systems he controls? I, for one, would rather a third party weren't silently dropping mail that could be false positives.
    • Re:Okay (Score:5, Insightful)

      by qortra (591818) on Friday August 15 2008, @09:16AM (#24614629) Homepage
      He isn't complaining. It isn't wrong to ask questions when things unexpectedly go well.
          • Re:Okay (Score:5, Funny)

            by Hektor_Troy (262592) on Friday August 15 2008, @10:12AM (#24615731)

            Mace? Screw maze.

            Flurescent green spray paint [choiceful.com] is much better. Not only will you keep your assailant off of you, but you will also make it REALLY easy to pick him out of a line-up later.

            Police: "Can you identify the guy who jumped you?"
            Victim: "He's the green faced guy, crying on the corner about being blind."

    • Re:Okay (Score:5, Funny)

      by camperdave (969942) on Friday August 15 2008, @09:34AM (#24615027) Journal
      And you're complaining because .... ?

      Without having the spam to process, the server doesn't run as hot as it's "supposed to". This causes a power imbalance, sending more current to the other servers and tripping breakers. Also, because of the lack of that heat, the server room is too cold. The UPS batteries are not storing enough of a charge as they are less efficient when they're cold. If a power sag, brownout, or blackout happens during one of these spam free moments, well, the results could be catastrophic.