4 ms·
Since when is a botnet a collection of free email accounts? Since when has a spammers return on investment been low? Since when have spammers only used hijack
by n3rdy 13y ago
Since when is a botnet a collection of free email accounts?
Since when has a spammers return on investment been low?
Since when have spammers only used hijacked "legitimate" business domains instead of just using some wildcard email domain setup?
Its not enough that he posts his strategies online to make it easier for his adversaries to learn from, but this guy doesn't even sound like he grasps the fundamentals of what is supposed to be his profession?
- alexk 13y agoHey, "he" is here :-) To be on the same page in this conversation we are programmatic email service for developers, not for end users. Customers can create their own virtual email server on our page and start sending in a couple of seconds. This concept is pretty similar to cloud servers. > Since when is a botnet a collection of free email accounts? In our terms botnet can be a mix of a free and paid Mailgun accounts. Botnets can include anything from 2-3 to dozens and hundreds of accounts created at different time and using different billing plans. > Since when has a spammers return on investment been low? We are talking about Mailgun service - the time they need to invest in building some solution on top of Mailgun that pays back is just not worth it. Actually I'm surprised why they even bother sending this type of spam through Mailgun. Let's say they were able to send 100K of emails via us (what is pretty hard nowadays btw), in the best case their click rates would be floating around some fractions of a percent. http://www.sitepoint.com/spam-roi-profit-on-1-in-125m-response-rate/ http://www.sitepoint.com/spam-roi-profit-on-1-in-125m-respon... So they wont' get even a couple of clicks from that. On the other hand, phishing attacks are very dangerous and this is our biggest threat - we've noticed that they get very high quality lists with 0 bounces, so it might be real bank users and build pages for every atack. > Since when have spammers only used hijacked "legitimate" business domains instead of just using some wildcard email domain setup? Wildcard MX records are about receiving, I'm talking about subdomains on a free webhosting services (bulk subdomain creation), what is a serious threat. > Its not enough that he posts his strategies online to make it easier for his adversaries to learn from, but this guy doesn't even sound like he grasps the fundamentals of > what is supposed to be his profession? Botnets and targeted phishing attacks are not somewhat new - that's a common practice, it's not that I'm uncovering some unknown secret here.
- n3rdy 13y ago> In our terms botnet can be a mix of a free and paid Mailgun accounts. Botnets can include anything from 2-3 to dozens and hundreds of accounts created at different time and using different billing plans. My criticism is I've never heard of a botnet referred to as a group of accounts. To me, a botnet is a group of host computers that run some sort of proxy server (tens of thousands of hosts). I've never given thought to what someone would call a group of email accounts aimed at exploiting a service, but to me botnet seems like it would be specific to a network of computers, sometimes compromised, sometimes not, running a type of proxy or automated software. > We are talking about Mailgun service - the time they need to invest in building some solution on top of Mailgun that pays back is just not worth it. The problem is when it comes to a service like yours, if it really is that hard to bulk mail, then the guys using your service aren't the guys getting a 1 in 125m response rate. Anyone sending that kind of volume would assume their messages were going to a spam folder, and sending larger volumes to compensate for it. Someone going through the hoops you set in place, are doing it because your service gets inbox. This means they can send bulk email to higher quality lists, and their response rate will be significantly higher than 1 in 125m, more like 1% to 2% response rates. In this case, the people actually sending mail through your service probably don't even bother making those accounts themselves. They likely find people who specialize in circumventing your security measures, and pay a premium of $x to $xx per 1,000 accounts. > On the other hand, phishing attacks are very dangerous and this is our biggest threat - we've noticed that they get very high quality lists with 0 bounces, so it might be real bank users and build pages for every atack. This too, but don't forget about simply cracking passwords for the accounts. Simple math. Take the top 100 most used passwords, assume your users are just as naive as most the internet, and you have x% users you can assume will be compromised at some point in the future.
- alexk 13y ago> The problem is when it comes to a service like yours, if it really is that hard to bulk mail, then the > guys using your service aren't the guys getting a 1 in 125m response rate. So for old school spammers even if they got lucky and got 1% click rate, they'd 1K clicks in their best day in our service. So I'm mostly considering them as people looking for potential holes in the service. The people coming with stolen credit cards who want to steal more are the biggest threat as they are most harmful - they hunt for our ips and domain reputation, so they take time and try pretty hard to break through our filters. > This too, but don't forget about simply cracking passwords for the accounts. Simple math. Take the top > 100 most used passwords, assume your users are just as naive as most the internet, and you have x% > users you can assume will be compromised at some point in the future. Yep, and we watch every account in the system for changes in behavior, but that's happened only once or twice in the last 2 months - so it's not a biggest problem right now.