Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« MPAA Runs Into Its Own Copyright Infrigement Problems | Main | Cyber-insurance and Emerging Market Pressures for Security »

Tracing Ron Paul Spam

SecureWorks has taken the time to investigate the October round of spam supporting Republican presidential candidate Ron Paul. Thanks to their work (with the help of myNetWatchman, IronPort and Spamhaus), we have a good case study in just how easy it is to send millions of spam for little cost.

They undertook the investigation to cut through the conjecture and accusations about who sent the spam:

On the weekend of October 27, 2007, the Internet was suddenly bombarded with a rash of spam emails promoting U.S. presidential candidate Ron Paul. The spam run continued until Tuesday, October 30, when it stopped as suddenly as it began. At the same time, political blogs began to light up, accusing the campaign (or at least its ardent supporters) of running a criminal botnet for political purposes. We decided to cut through the spin and take a closer look at this botnet to determine its origins and shine some light on who might be responsible.

The investigators traced the source as far back as a small affiliate spammer who was probably running other spam jobs in addition to the Ron Paul spam.

With the facts above, we are left asking the question, “who paid to have the Ron Paul spam sent and how did they connect with the spammer, “nenastnyj?” The evidence shows that despite being capable of sending upwards of 200 million messages a day, nenastnyj is not one of the major spammers of the world, and seems to focus on spamming as an affiliate for larger “kingpin” operations. The Ron Paul spam was very much a “one-off” job among the other tasks in the Reactor interface. It almost seems as though there may have been some pre-established relationship between the sponsor of the spam and nenastnyj.

The report includes details on how the investigators traced the spam and includes a discussion and screen shots of a template driven spam management system. Sending spam with that system is as easy as online banking.

Will spam, a YouTube video or some other Internet based ploy be the Swift Boaters of 2008? Clearly candidates can't control what supporters do and the 2004 election showed how effective unauthorized activities can be. It will be an interesting year.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/551

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net