Stories
Slash Boxes
Comments

News for nerds, stuff that matters

BlueSecurity Database Compromised?

Posted by Hemos on Tue May 02, 2006 09:44 AM
from the bad-news dept.
EElyn writes "Numerous users of Blue Security's anti-spam system now report of a new form of aggressive spam. An unknown group of spammers claim to have derived a way to extract the member email addresses of Blue Security group's anti-spam system, called Blue Frog. Blue Frog, a small tool which once installed on the user's computer, enables Blue Security to systematically flood a known spammer's website with opt-out messages; much to the headache of the spammer. Tens of thousands of users have already signed up, so can it really be true that spammers now possess this database? Or is this yet another frail attempt by spammers to intimidate the user?" Another reader sent the text of the letter; read more to see.

Stray1 writes ""You are recieving this email because you are a member of BlueSecurity...." An email from unknown detractors has taken the Bluesecurity anti spam lists and decided to take matters into their own hands. I recieved this Email from an anonymous, and garbled host, which went on to say in not so fantastic english that I, as a Blusecurity member, would recieve this and many more (about 20 -30) spam messages a day until I left the blue security community. Blue Security, (www.bluesecurity.com)a website and community designed to lessen your Spam Email, is down for the moment. Is this what we have come to? Spam,(erm 'high volume email') companys holding your address hostage until you comply? "...We mightve had your email addresses before in our lists, but now, we are targetting YOU, because YOU are a bluesecurity user". I have to say, up until this point, my spam was down by about 70% to 80%."

Related Stories

[+] Spam War Takes Out Blog Services 315 comments
munchola writes "Following on from the story about spammers attacking Blue Security's anti-spam system, CBR is reporting that Six Apart, which runs the popular LiveJournal and TypePad blogging services, has become a collateral victim. Six Apart told its millions of bloggers it had experienced 'intermittent and limited availability for TypePad, LiveJournal, TypeKey, sixapart.com, movabletype.org and movabletype.com', before resolving the issue in the early hours of Wednesday. '[The spammers are] trying to rip apart the internet just to make our community stop fighting back against spam,' Blue Security's chief executive Eran Reshef said, adding that he knows who's behind the attack."
This discussion has been archived. No new comments can be posted.
BlueSecurity Database Compromised? | Log In/Create an Account | Top | 375 comments (Spill at 50!) | Index Only | Search Discussion
Display Options Threshold:
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • Blue? by LCookie (Score:1) Tuesday May 02 2006, @09:46AM
  • Eye for an Eye? by Anonymous Coward (Score:2) Tuesday May 02 2006, @09:48AM
    • A head for an eye? by Anonymous Coward (Score:1) Tuesday May 02 2006, @09:49AM
    • Re:Eye for an Eye? (Score:4, Insightful)

      Blah blah blah.

      'Vigilante' would imply something illegal is going on. This is market forces at work - more effective, generally, than government intervention.
      [ Parent ]
      • Re:Eye for an Eye? (Score:5, Insightful)

        Vigilantism is the act of taking the law into your own hands. It carries an implication of illegal, or more specifically, 'by any means necessary'.

        This is 'a community action to produce a market incentive', which is wholly different from 'vigilantism', at least in a literal sense.

        Sure, sure, it looks like we're locked in this huge digital superhero battle between the evil spammers and the innocent citizenry, but face it: We're making an attempt to prevent high-volume e-mail to our e-mail addresses from being profitable, and that is all. We are consciously generating market pressure to achieve a goal, and we are doing it in an unorthodox, but morally and legally clean way.

        A segment of the population has said, 'High-volume e-mail is annoying enough to be a breach of the peace, as far as I'm concerned. I want none of it, and I will make an effort to prevent my mailbox from recieving them, by filter and by incentive."

        Your use of the term 'vigilante tactics' is an obvious attempt to cast a dim light on the activities of the Blue Security community. It brings a baseless accusation to mind - and this being slashdot, I'm inclined to make it - but I think I'll leave the obvious to the outside observer.

        Frelling trolls.
        [ Parent ]
      • 1 reply beneath your current threshold.
    • Re:Eye for an Eye? by MrHeartbreak (Score:1) Tuesday May 02 2006, @10:09AM
    • Re:Eye for an Eye? (Score:5, Interesting)

      by ScentCone (795499) on Tuesday May 02 2006, @10:09AM (#15245506)
      When will the world learn, violence begets violence and spam begets spam. Lets find a real solution to the problem rahter then a vigalante justice.

      Actually, I've found that things some people think are unfortunate or bad beget shallow, empty platitudes.

      Sometimes, violence simply ends violence, because there is no other way. Sometimes, fighting fire with fire is the best way. Sometimes showing someone what it's like to suffer the consequences of their own actions actually changes their behavior.

      I'm all for as many technical approaches as possible, but finding "a real solution to the problem" that doesn't involve some degree of making this painful/costly for the spammers simply isn't going to work. Even if, through filtering, you can get 99% of the stuff blocked, all they have to do is increase the volume that much more to make that remaining 1% still pay off. Remember, they're not paying for their own overhead most of the time.

      Your "real solution" comment, in the context of "violence only begets violence" is completely tone deaf. You're applying Israeli-Palestinian-conflict-type babble to a completely different situation. The spammers are not oppressed, or the victims of some historical violent wrong... they're a parasitic, bandwidth sucking plague. Any means by which we can stop them is called for. Surely you don't think that you're going to just turn the other Bayesian Filter Cheek, or write a Korea-bound, thought-provoking appeal to integrity and expect the onslaught to stop? Tempting as it is, no one is suggesting actual violence - just a substantial response in kind, only when provoked. It's called self defense, and it's an appropriate measure because it only happens when an illegal spammer causes it to happen.

      How fortunate for you that you've never had anything violent threaten you, requiring you to offer up a physical deterrent to stop it. If you had, you might rethink your metaphors.
      [ Parent ]
    • Re:Eye for an Eye? by suv4x4 (Score:3) Tuesday May 02 2006, @10:10AM
    • Its more than that by Lanoitarus (Score:2) Tuesday May 02 2006, @10:36AM
    • Re:Eye for an Eye? by Anonymous Coward (Score:1) Tuesday May 02 2006, @10:39AM
    • Re:Eye for an Eye? by tonywong (Score:2) Tuesday May 02 2006, @11:34AM
    • Re:Eye for an Eye? by KCMO11 (Score:1) Tuesday May 02 2006, @11:37AM
    • Neville Chamberlain, is that you? by blueZ3 (Score:3) Tuesday May 02 2006, @11:38AM
    • Re:Eye for an Eye? by smokeslikeapoet (Score:2) Tuesday May 02 2006, @12:11PM
    • Re:Eye for an Eye? by jmorris42 (Score:3) Tuesday May 02 2006, @12:24PM
    • Re:Eye for an Eye? by tbannist (Score:3) Tuesday May 02 2006, @02:13PM
    • Re:Eye for an Eye? Response shows effectiveness by darkonc (Score:2) Tuesday May 02 2006, @03:28PM
    • Re:Eye for an Eye? by Alan Jay Weiner (Score:1) Tuesday May 02 2006, @04:19PM
    • Spam attack plan by RedToad (Score:2) Tuesday May 02 2006, @06:05PM
    • Re:Eye for an Eye? by Em Adespoton (Score:2) Tuesday May 02 2006, @12:07PM
    • 2 replies beneath your current threshold.
  • I'd call the bluff (Score:5, Insightful)

    by Anonymous Coward on Tuesday May 02 2006, @09:48AM (#15245262)
    If they're able to do so, what will stop them from *not* spamming you in the future anyway? Their ethics, integrity or your stupidity?
  • Screw the spammers. (Score:4, Interesting)

    by Vengeance (46019) on Tuesday May 02 2006, @09:49AM (#15245263)
    What the hell does 20 or 30 messages mean? Nothing at all to me. I reject anywhere from 20 to 40 THOUSAND emails daily, on a domain with precisely two email users: My wife and me. The vast majority of the crap I get is easily rejected because it's sent to bogus (as in, they never ever existed) email addresses. SpamAssassin catches much of the rest.
  • What must be done (Score:4, Interesting)

    by XxtraLarGe (551297) on Tuesday May 02 2006, @09:49AM (#15245266)
    We really need to take the internet back from these guys. Reply to every spam e-mail by going to their web site, and filling out bogus info. Give them bad information overload. Same thing goes for junk mail and telemarketers. When somebody sends you a credit card offer, send it back to them, writing "Take me off your list". Make sure they have to waste so much time throwing out bad mail that it isn't worth their time. When telemarketers call, ask them to hold on a minute. Then set down the phone and don't pick it up again for 10 minutes. That will dig into their costs.
    • Re:What must be done by Vengeance (Score:1) Tuesday May 02 2006, @09:51AM
    • Re:What must be done (Score:4, Funny)

      by clevershark (130296) on Tuesday May 02 2006, @09:53AM (#15245314)
      (http://www.clevershark.com/)
      Seems like a good approach actually. Perhaps some script could be developed that would do nothing but look at a web form, fill in appropriate bogus info, and just hit the site repeatedly with bogus orders. I'll bet any CC provider would soon get tired of having to constantly do verification on bogus CC numbers and would end up closing the spammer's account.

      Sure, it's a nasty form of attack, but then that's no less than spammers deserve.
      [ Parent ]
      • Re:What must be done (Score:4, Interesting)

        "Perhaps some script could be developed that would do nothing but look at a web form, fill in appropriate bogus info, and just hit the site repeatedly with bogus orders"

        Actually, there's a very nice client written in C++ that does a damn good job. No CC data or anything, but 'please remove me' forms. If you're confused, read the article again; it's mentioned.
        [ Parent ]
        • Re:What must be done (Score:5, Insightful)

          by clevershark (130296) on Tuesday May 02 2006, @10:11AM (#15245524)
          (http://www.clevershark.com/)
          The only thing that most of these "please remove me" BS forms do is confirm that the email address is a valid one, and can be resold to more spammers. If anything filling those out actually causes more harm than good.

          If you're confused, read the article again; it's mentioned.

          Thanks Tips, but all four links in the article seem to be unreachable.
          [ Parent ]
          • Re:What must be done by clevershark (Score:2) Tuesday May 02 2006, @10:13AM
          • Re:What must be done by The Snowman (Score:2) Tuesday May 02 2006, @10:38AM
          • Re:What must be done (Score:5, Interesting)

            by macdaddy (38372) on Tuesday May 02 2006, @11:03AM (#15246107)
            (http://slashdot.org/ | Last Journal: Monday January 31 2005, @05:48PM)
            I used to be a big anti-spammer, back when I had time on my hands. I generated a list of proper-pronouns that was somewhere just over 500k long (I forget the exact #s now). I wrote a number of scripts that used wget and curl (depending on the form) to stuff addresses generated from the pronoun list and about a dozen spam-hole domains I registered into those Remove Me forms. Within hours I was getting tens of thousands of pieces of spam. Within days my Cox cable connection was saturated. I offloaded it onto a co-lo box for another couple of months before I finally changed the MXs to 127.0.0.1 and shut the system down. I had automated scripts for auto-forwarding a copy of the spam to the FTC and to post the messages to NANAS (news.admin.net-abuse.sightings). I also archived the incoming spam and used it to seed my Bayesian filters and DCC system for the ISP I worked for. I can't begin to tell you how effective that was. It was a helluva rig. I wish I still had time to dick around with that kind of stuff.
            [ Parent ]
        • Re:What must be done by HaloZero (Score:1) Tuesday May 02 2006, @10:13AM
      • Re:What must be done by skinfitz (Score:2) Wednesday May 03 2006, @06:39PM
      • Re:What must be done by RedToad (Score:1) Thursday May 04 2006, @04:34AM
      • 2 replies beneath your current threshold.
    • Re:What must be done by haplo21112 (Score:2) Tuesday May 02 2006, @09:55AM
      • Re:What must be done by mpaulsen (Score:3) Tuesday May 02 2006, @10:17AM
      • Re:What must be done by Drathus (Score:2) Tuesday May 02 2006, @10:17AM
      • Re:What must be done by toastyman (Score:3) Tuesday May 02 2006, @10:19AM
        • Re:What must be done (Score:4, Funny)

          by pla (258480) on Tuesday May 02 2006, @10:36AM (#15245801)
          (Last Journal: Monday April 03 2006, @07:23PM)
          That would be awesome, but unfortunately it doesn't work.


          The brick idea, no. But the SD article made a nice suggestion - A rectangular chunk of nice thick sheet metal would fit well inside the return envelope, yet weigh far more than one ounce.


          Also, one point on the SD article:
          of the 161,000 people who wrote to the DMA last year, 116,000 wanted more junk mail. They were sent a booklet entitled "How To Get More Interesting Mail" (as God is my witness, I am not making this up), which tells you various key catalogs that you can send for to guarantee you'll be deluged with stuff.
          I can tell you exactly why people ask for more junk mail...

          They own wood stoves.
          [ Parent ]
      • Re:What must be done by ericspinder (Score:2) Tuesday May 02 2006, @10:37AM
      • Re:What must be done by XxtraLarGe (Score:2) Tuesday May 02 2006, @11:48AM
      • Re:What must be done by SillySlashdotName (Score:2) Wednesday May 03 2006, @11:35AM
      • 2 replies beneath your current threshold.
    • Re:What must be done by Fordiman (Score:2) Tuesday May 02 2006, @09:58AM
    • Re:What must be done by The Snowman (Score:3) Tuesday May 02 2006, @10:35AM
    • Re:What must be done by tidokoro (Score:2) Tuesday May 02 2006, @10:44AM
    • Re:What must be done by Tom (Score:2) Tuesday May 02 2006, @10:52AM
    • Re:What must be done (Score:4, Informative)

      by Pollardito (781263) on Tuesday May 02 2006, @12:17PM (#15246819)
      When somebody sends you a credit card offer, send it back to them, writing "Take me off your list".
      you can get off the prescreened credit mailing lists altogether, just use one of the methods suggested on the FTC website [ftc.gov]
      [ Parent ]
    • Re:What must be done by hazzey (Score:2) Tuesday May 02 2006, @01:28PM
    • Re:What must be done by dbc001 (Score:2) Tuesday May 02 2006, @03:47PM
    • That *is* basically what Bluesecurity does by billstewart (Score:2) Tuesday May 02 2006, @04:57PM
    • Re:What must be done by jonadab (Score:1) Tuesday May 02 2006, @05:28PM
    • 3 replies beneath your current threshold.
  • Unrestricted Warfare (Score:5, Funny)

    by stevesliva (648202) <stevesliva@gmail. c o m> on Tuesday May 02 2006, @09:49AM (#15245273)
    (Last Journal: Thursday February 24 2005, @11:27AM)
    Pretty soon the spammers will be conducting unrestricted submarine attacks on civilian shipping in the North Atlantic.
  • So, is the database compromised? (Score:4, Interesting)

    by Dynamoo (527749) * on Tuesday May 02 2006, @09:50AM (#15245275)
    (http://www.dynamoo.com/)
    A big question here is.. is the database compromised? From the poking around I've done, it does seem that the only people who have received this message are BlueFrog users.. those who don't use it, don't seem to have it. It could simply be that the spammers have used tracking information embedded in the spammy URLs to find out who is using BlueFrog.

    BlueFrog has been criticised for it's so-called "vigilante" approach.. it's not alone in this approach, but perhaps this does go to show a potential downside: spammers are evil - pissed off spammers will simply direct the evil at the people who pissed them off.

  • I had wondered by shadowknot (Score:1) Tuesday May 02 2006, @09:50AM
  • Monty Python (Score:3, Funny)

    So, if I got this right, the spammers that are getting spammed are now spamming the spammers? Sounds like a flying circus to me!
  • So... by yngv (Score:1) Tuesday May 02 2006, @09:51AM
    • Don't Back Down by colonslashslash (Score:3) Tuesday May 02 2006, @10:03AM
    • Re:So... (Score:4, Interesting)

      http://members.bluesecurity.com is still up; I don't know what they did to www., but it seems to be down.

      Meanwhile, stay on, ride it out. Use your spam filter to catch the spams; heuristics will still capture the spams they're sending if they're reported. This guy is desperate - likely going bankrupt - and some of us in the Blue Community would like to see him and his sort become paupers for their asshattery.
      [ Parent ]
      • Re:So... by nystire (Score:1) Tuesday May 02 2006, @11:28AM
      • Re:So... by saleenS281 (Score:2) Tuesday May 02 2006, @01:16PM
        • Re:So... by Anonymous Coward (Score:1) Tuesday May 02 2006, @03:43PM
    • Re:So... by ocbwilg (Score:2) Tuesday May 02 2006, @11:24AM
    • 1 reply beneath your current threshold.
  • ah ha by boredomrisen (Score:1) Tuesday May 02 2006, @09:52AM
    • 1 reply beneath your current threshold.
  • Errr, what? by Otter (Score:1) Tuesday May 02 2006, @09:55AM
    • 1 reply beneath your current threshold.
  • I'm sure that we're all interested in what these people have to sell... also that would probably cause a massive slashdotting.
  • Is anyone really surprised? by wackysootroom (Score:2) Tuesday May 02 2006, @09:57AM
  • So..uh.. by grasshoppa (Score:2) Tuesday May 02 2006, @09:58AM
    • 1 reply beneath your current threshold.
  • Opt Out Message? by LiquidCoooled (Score:1) Tuesday May 02 2006, @10:01AM
  • Email I Received (Score:5, Informative)

    by duerra (684053) * on Tuesday May 02 2006, @10:01AM (#15245413)
    (http://lyrictalk.net/)
    Below is an email that I received, which pretty much confirms that they have been hacked.

    ----

    You are being emailed because you are a user of BlueSecurity's well-known software "BlueFrog." http://www.bluesecurity.com/ [bluesecurity.com]

    Today, the BlueSecurity database became known to the worst spammers worldwide. Within 48 hours, the database will be published on the Internet, and your email address will be open to them all. After this, you will see the spam sent to your mailbox increase 10 - 20 fold.

    BlueSecurity was illegally attacking email marketers, and doing so with your help. Many websites have been targeted and hit, including non-spam sites. BlueSecurity's software has been fully analyzed, and contains an abundance of malicious code. This includes: ability to send mass mail to users; the ability to attack websites with Distributed Denial of Service attack (DDoS); the ability to open hidden doors on any machine on which it is running; and a hidden auto-update code function, which can install anything on your computer and open it up to anyone.

    BlueSecurity lists a USA address as their place of business, whereas their main office is in Tel Aviv. BlueSecurity is run by a few Russian-born Jews, who have previously been spamming themselves. When all is said and done, they will be able to run, hide and change their identities, leaving you to take the fall. YOU CANNOT PARTICIPATE IN ILLEGAL ACTIVITIES and expect to get away with it. This email ensures that you are well aware of the situation. Soon, you will be found guilty of computer crimes such as DDOS attacking of websites, conspiracy, and sending mass unsolicited bulk email messages for everything from viagra to porn, as long as you continue to run BlueFrog.

    They do not take money for downloading their software, they do not take money for removing emails from their lists, and they have no visible revenue stream. What they DO have is 500,000 computers sitting there awaiting their next command. What are they doing now?

    1. Using your computer to send spam ?
    2. Using your computer to attack competitor websites?
    3. Phishing through your files for your identity and banking information?

    If you think you can merely change your email address and be safe while still running BlueFrog, you are in for a big surprise. This is just the beginning...
  • Sent abuse report by ad1c (Score:1) Tuesday May 02 2006, @10:03AM
  • Heh by AugstWest (Score:2) Tuesday May 02 2006, @10:05AM
  • I don't think they've compromised the database by thridur (Score:1) Tuesday May 02 2006, @10:05AM
  • The REST of the story ... (Score:3, Insightful)

    by GISGEOLOGYGEEK (708023) on Tuesday May 02 2006, @10:05AM (#15245458)
    The Gmail spam filter is filtering nearly every one of these spams, only a couple out of 60+ yesturday got into my inbox. .... and every one of that bastard's spams advertising a website went right to bluesecurity to hurt his business. He's just shooting himself in the foot.

    Contrary to what the author wrote, there's closer to 475,000 members, not just a few 10's of thousands, enough that several major spammers have already agreed to not spam members due to the huge financial hits they were taking with the bluefrog choking off their websites.

    What a joke, what dumbass would really believe that the spammers will not spam you if you leave blue security? Who here will admit to believing the criminals? ... I think that about covers the points that were lost when slashdot decided to post this boring version of the story, instead of what I submitted yesturday afternoon :)

  • What I received (Score:5, Interesting)

    by Carny Trash (972308) on Tuesday May 02 2006, @10:06AM (#15245473)
    Here's what I was sent:

    "Hey,
    You are recieving this email because you are a member of BlueSecurity (http://www.bluesecurity.com).

    You signed up because you were expecting to recieve a lesser amount of spam, unfortunately, due to the tactics used by BlueSecurity, you will end up recieving this message, or other nonsensical spams 20-40 times more than you would normally.

    How do you make it stop?

    Simple, in 48 hours, and every 48 hours thereafter, we will run our current list of BlueSecurity subscribers through BlueSecurity's database, if you arent there.. you wont get this again.

    We have devised a method to retrieve your address from their database, so by signing up and remaining a BlueSecurity user not only are you opening yourself up for this, you are also potentially verifying your email address through them to even more spammers, and will end up getting up even more spam as an end-result.

    By signing up for bluesecurity, you are doing the exact opposite of what you want, so delete your account, and you will stop recieving this.

    Why are we doing this?

    Its simple, we dont want to, but BlueSecurity is forcing us. We would much rather not waste our resources and send you these useless mails, but do not believe for one second that we will stop this tirade of emails if you choose to stay with BlueSecurity.

    Just remember one thing when you read this, we didnt do this to you, BlueSecurity did.

    If BlueSecurity decides to play fair, we will do the same.

    We are quite sure you will think this will not continue, that we will not continue wasting our resources doing this, feel free to wait out the first 48, or the second, and see whether these stop, you will be quite suprised.

    If you have another email under the protection of bluesecurity, and have not recieved this there, do not worry, you will soon enough.

    We mightve had your email addresses before in our lists, but now, we are targetting YOU, because YOU are a bluesecurity user.

    You might also notice, that the BlueSecurity site(http://www.bluesecurity.com) is down..

    Just remove yourself from BlueSecurity, and make it easier on you.

    Sal Webber"
  • Rebounding Wave by Phoenix666 (Score:2) Tuesday May 02 2006, @10:12AM
  • Blue security must be working (Score:5, Insightful)

    by paladinwannabe2 (889776) on Tuesday May 02 2006, @10:14AM (#15245556)
    If BlueSecurity wasn't hurting Spammers they would ignore it. If they are fighting back it must mean that BlueSecurity is actually doing damage to them.
  • Probably not compromised by jhernand (Score:2) Tuesday May 02 2006, @10:25AM
  • Sounds like it is effective by SnarfQuest (Score:1) Tuesday May 02 2006, @10:26AM
  • Vigilante by linvir (Score:1) Tuesday May 02 2006, @10:28AM
    • Re:Vigilante by nytes (Score:1) Thursday May 04 2006, @04:45PM
  • I got flooded yesterday by wwphx (Score:1) Tuesday May 02 2006, @10:29AM
  • Blue Security coming back online (Score:3, Interesting)

    by Anonymous Coward on Tuesday May 02 2006, @10:32AM (#15245767)
    From http://www.bluesecurity.com/Announcements/spam.asp [bluesecurity.com]

    As many spammers choose to comply with the Registry (see our recent blog posts here [bluesecurity.com], here [bluesecurity.com] and here [bluesecurity.com]), other spammers may resort to other means in an attempt to avoid compliance.

    A major spammer had started spamming our members with discouraging messages in an attempt to demoralize our community. This spammer is using mailing lists he already owns that may contain addresses of some community members.

    We have also received complaints from users about spam allegedly sent from Blue Security promoting our anti-spam solution and our web site. This is yet another tactic used by some spammers in an attempt to slander us by sending unsolicited email forged to appear as if it was sent from Blue Security. Blue Security is an anti-spam company determined to fight spam and as such never has and never will send unsolicited email.

    Our answer to those criminals should be one - we will not be discouraged; We will continue to exercise our right to opt-out of spam.

    If you are not a member of our community, now is the time to actively fight spam and make spammers leave you alone. For more information click here.

    If you are already a member of our community, make spammers hear you load and clear - report your spam, let Blue Frog fight spammers on your behalf.

    We regret any inconvenience caused by this incident.

    Best Regards,

    Blue Security.

  • BlueSecurity wasn't hacked: Spammer FUD by Nuclear Elephant (Score:2) Tuesday May 02 2006, @10:33AM
  • join by Janek Kozicki (Score:2) Tuesday May 02 2006, @10:35AM
    • Re:join by Janek Kozicki (Score:2) Tuesday May 02 2006, @10:38AM
      • 1 reply beneath your current threshold.
  • Thanks to the message by Too many errors, bai (Score:1) Tuesday May 02 2006, @10:35AM
  • They don't have the database! (Score:5, Informative)

    by drosoph (664471) on Tuesday May 02 2006, @10:37AM (#15245817)
    From what I am seeing, I am now receiving 1,000s of these stupid "Because you are using the BlueSecurity Software ...." emails .... but they are all being directed to Mike, Jan, Cindy, Lucy, Bobby, and Greg@mydomain.com .... They are NOT directed to MY email address. These addresses that they are using were ONCE entered by an ignorant relative of my onto one of those online greeting card sites, (even mispelled) and those are the addresses that are being spammed. Since I ALSO registered my DOMAIN with BlueSecurity, I would ponder to guess that the spammers are using the domain list, matching it up to ANY email they have in their spam database with that domain and spamming the heck out of it. They HAVE NOT, I repeat, HAVE NOT hit ANY of my REGISTERED email addresses with BlueSecurity. They are only hitting random crap email addresses on my domain. They're shooting in the dark, they're angry, and they're running scared ... and I hope that you all keep up the good work!
  • then they laugh at you...

    then they fight you...

    then you win :D

    One thing is safe to know: At least the spammers are now PAYING ATTENTION to us. A year ago they didn't even know we exist. Then they tried to give bad publicity to Blue Security in anti-spam websites (they said bluefrog was a botnet).

    Later, SendSafe [oreilly.com] included an option to use bluefrog's list to NOT send spam to those addresses.

    Finally, they're targeting us directly. You know what that means B-)

    Also, I doubt the database's been compromised. I'm sure they only diffed the original and the filtered e-mail list. This means that only a small percentage of e-mail targets has been truly released.
  • Simple solution? by smbarbour (Score:2) Tuesday May 02 2006, @10:38AM
  • This is going to backfire on spammers by Gat0r30y (Score:1) Tuesday May 02 2006, @10:39AM
  • Anyone even bother to research this? (Score:3, Interesting)

    by Audigy (552883) on Tuesday May 02 2006, @10:39AM (#15245841)
    (http://slashdot.org/~Audigy | Last Journal: Monday February 07 2005, @10:50AM)
    The site hasn't been hacked.

    Hasn't anyone gone to bluesecurity.com to actually see what THEY have to say about this "security breach"?

    I have two other email address that WERE NOT signed up with BlueFrog also getting this spam.

    BlueSecurity's official statement is this: ...which I would be pasting here if I could get to the goddamned site. Thanks a lot, slashdot. I'll be back to post the full text once I can get in the bloody site.

    In short, the spammers are PISSED and they'll do anything to get people to unsubscribe from BlueFrog, including sending spams with lies. Don't fall for it. Keep fighting spam.
  • A thanks to the spammer by phalanx (Score:1) Tuesday May 02 2006, @10:41AM
  • Sounds like fair play to me... by Lord Bitman (Score:1) Tuesday May 02 2006, @10:47AM
  • a la guerre comme a la guerre by mapkinase (Score:1) Tuesday May 02 2006, @10:50AM
  • I know how they did this by Rekolitus (Score:1) Tuesday May 02 2006, @10:51AM
  • DoS and Explanation (Score:4, Informative)

    by cheshire_cqx (175259) on Tuesday May 02 2006, @10:53AM (#15246013)

    According to this article [realtechnews.com] BlueSecurity is the target of a DoS attack.

    Also, here's their explanation of the spammer's countermeasure:


    This sounds scary, but it's not as bad as it sounds. Blue Security's email address registry remains secure contrary to what this spammer would have you believe. The way subscribers' emails were obtained was by checking the spammer's own list of emails against the Do Not Intrude registry. Normally spammers will get the emails of those who subscribe returned to them and will then remove those emails from their spamming lists. This one, however, has taken another approach. Instead of taking those hits off of his spam lists, he is sending them these intimidating emails.

    Makes sense to me, and explains why only BlueSecurity users are getting the emails.

  • So it works? by Tom (Score:2) Tuesday May 02 2006, @10:54AM
  • BlueFrog database has not been compromised ... by slb (Score:1) Tuesday May 02 2006, @10:57AM
  • Ever think it's a phishing attack? by ^Phantom (Score:2) Tuesday May 02 2006, @11:04AM
  • Like they'll take you off. . . by lucidityZ (Score:1) Tuesday May 02 2006, @11:19AM
  • A fundamental change of spam economy by ericald (Score:2) Tuesday May 02 2006, @11:22AM
  • dev.bluesecurity.com still up by Mixel (Score:1) Tuesday May 02 2006, @11:22AM
  • Blue Frog Thunderbird client by spyrochaete (Score:2) Tuesday May 02 2006, @11:30AM
  • Nothing to worry about. by Professr3 (Score:1) Tuesday May 02 2006, @11:35AM
  • Point? by Gattman01 (Score:1) Tuesday May 02 2006, @11:39AM
  • The point is, they're right by ZWithaPGGB (Score:1) Tuesday May 02 2006, @11:41AM
  • Spammers exposed their resources? by VikingThunder (Score:2) Tuesday May 02 2006, @11:49AM
  • If I was a Clever Hacker by XHIIHIIHX (Score:1) Tuesday May 02 2006, @11:49AM
  • Rice Chex and Raisin Toast by IHateAllofYou (Score:1) Tuesday May 02 2006, @11:56AM
  • Coral Cache Link by smokeslikeapoet (Score:2) Tuesday May 02 2006, @12:05PM
  • I got my spams and... by Eric Damron (Score:1) Tuesday May 02 2006, @12:12PM
  • go frog go by coaxeus (Score:1) Tuesday May 02 2006, @12:17PM
  • I never signed up with BlueFrog by Swave An deBwoner (Score:1) Tuesday May 02 2006, @12:27PM
  • I got a different "joe job" mail... by shark72 (Score:2) Tuesday May 02 2006, @12:31PM
  • Diversion tactic #1 by kaufmanmoore (Score:1) Tuesday May 02 2006, @12:40PM
  • Victimized? File a complaint. by smokeslikeapoet (Score:2) Tuesday May 02 2006, @12:50PM
  • Not getting hit here by TheQuietDan (Score:1) Tuesday May 02 2006, @01:46PM
  • I got the following 'recruitement' email. by nblender (Score:2) Tuesday May 02 2006, @02:38PM
  • New attack email text (Score:3, Informative)

    by MrNougat (927651) <ckratsch@nOSpam.gmail.com> on Tuesday May 02 2006, @03:51PM (#15248868)
    I just got the following NDR email (which GMail flagged as spam, but I read anyway). Looks like the pissy spammer is using email addresses from his list in the From field, and generating false spam for BlueSecurity.

    I have deleted contact information at the end, for the sanity of those involved.

    Begin

    Subject: FW:Automaticly send 1000s of DDOS complaints for each spam you recieve

    The trackback URL for this blog entry is:
    http://community.bluesecurity.com/ [bluesecurity.com]

    Bringing spammers to Their Knees:
    Bluesecurity.com hopes you'll join thousands of others in an army capable
    of crippling spammers' Web sites.

    A few thousand spammers have ruined our internet. They've clogged our
    mailboxes with filth. Already, 90% of email traffic is made up of
    spam. Let us no longer blind ourselves to the irrefutable facts:
    current measures have failed to stop spammers. The experience of the
    past several years has proven that passive measures are just not the
    answer.

    Retribution is the only real answer to spam. We must punish spammers
    ourselves to prevent them from taking over cyberspace. We must reclaim
    our territory. We need direct action to eliminate spammers for good.

    The magnitude of the task which lies before us is great. We are fighting
    for the future of the Internet. What we need to do now is get as many
    users as possible into our community. We already have a botnet with
    hundreds of thousands of computers working together to induce commercial
    loss on spammers and their ISPs. We have launched numerous
    Denial-of-Service Attacks on Chinese spam networks with great success,
    and plan many more!

    We have excellent financiers who allow us continued success with our botnet
    growth and Denial-of-Service Attacks. We thank the government agencies
    involved
    for their continued cooperation. We thank our leader, Eran Reshef,
    for continued strategies of DoS attack operations. Also, US-based Rembrandt

    Ventures & Skybox Security for their extensive funding & continued support.
    And a
    very special thanks to Douglas Schrier who has helped our botnet come to
    life.

    If you haven't signed up with the registry and installed a blue frog yet,
    please sign up now.
    If your friends have not yet joined us, we will convince them to do so.

    Let's stop filtering spam and start eliminating spammers.
    Together, we will reclaim the Internet, One ddos at a time.

    Please Contact Us for any questions on signup via the following info:

    address and phone deleted

    Israel HQ: address and phone deleted

    Current and potential investor relations:
    Rembrandt Venture Partners address and phone deleted

    Fight back spam! Join our Botnet today.
    Download our .EXE here: http:/// [http] www.bluesecurity.com/ blue-frog/

  • Another attack on Blue Security: joe job e-mails by owlmon (Score:1) Tuesday May 02 2006, @03:56PM
  • More worried when the spammers didn't care by Oztechreich (Score:1) Tuesday May 02 2006, @04:09PM
  • Nice .... by tinkerghost (Score:1) Tuesday May 02 2006, @04:20PM
  • Honeypot.... by Jerrycan (Score:1) Tuesday May 02 2006, @07:40PM
  • From bluesecurity com. Please spread by mungos (Score:1) Tuesday May 02 2006, @10:32PM
  • the largest legal botnet in the world. by gnuguru (Score:1) Wednesday May 03 2006, @03:21AM
  • Want us to quit BF then do a DDOS? by Nok (Score:1) Wednesday May 03 2006, @08:26PM
  • Bluesecurity DNS entries poisoned! by davygrvy (Score:1) Thursday May 04 2006, @03:17AM
  • The database was not compromised... by krinsh (Score:1) Friday May 05 2006, @10:07AM
  • Re:It is true by Fordiman (Score:2) Tuesday May 02 2006, @12:05PM
  • 10 replies beneath your current threshold.