iTnews

Hackers blamed for MessageLabs spam

By Brett Winterford on Nov 12, 2010 11:16AM
Hackers blamed for MessageLabs spam

Antispam company insists it can keep customers in check.

Managed email provider MessageLabs has blamed a security breach on one of its customer's networks for a bout of spam detected from its IP address range.

The incident saw the vendor - which incidentally is paid to protect customers from inbound spam - included in block lists by other anti-spam services.

As detailed exclusively in iTnews, MessageLabs customers found that some of their outbound mail bounced last week after the service providers' IP address was included in the SORBS antispam block list.

MessageLabs has since investigated the incident and concluded that its addresses were blocked due to a security incident affecting one of its customers.

"From time to time," said MessageLabs engineer Paul Woods, one of the company's 30,000 clients "will send mail that it is considered to be spam by us or one of the block list providers.

"In the instance it appears that a customer's webmail service had been compromised by a spammer and used to send spam emails," he said.

Woods said that MessageLabs' systems can detect abnormal numbers of emails being sent from a client account and delay the customer's ability to send email.

But in this case, these processes kicked in after "a small number of spam emails were sent, which resulted in one of our IP addresses being listed on the SORBS block list for a short period."

MessageLabs was unwilling to disclose what industry the affected customer operated in, nor its country of origin. "But we can say that the most common form of abuse of legitimate email accounts is often caused by insecure passwords on corporate webmail systems," Woods said.

MessageLabs was also able to re-route email from a blocked cluster to another cluster in order to ensure its other clients are not affected.

The company has toned down its past criticism of the SORBS model.

"Some of the block list providers have very aggressive rules and may occasionally add a block based on a single email that is deemed spam-like," Woods said.

"We work very closely with block list providers like SORBS and Spamhaus who generally play a very positive role in the fight against spam."

Woods said MessageLabs did not pay SORBS a fee to remove its IP addresses from the block list.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
antispam block hackers list messagelabs security sorbs spam

Partner Content

Setting a path to self-funded mainframe-to-cloud modernisation with Micro Focus
Promoted Content Setting a path to self-funded mainframe-to-cloud modernisation with Micro Focus
Beat the DDoS blackmails in 2021
Promoted Content Beat the DDoS blackmails in 2021
Tackling cybersecurity in 2021
Partner Content Tackling cybersecurity in 2021
What is zero trust cybersecurity?
Partner Content What is zero trust cybersecurity?

Sponsored Whitepapers

DevSecOps: A framework for digital innovation
DevSecOps: A framework for digital innovation
Encryption: Protect your most critical data
Encryption: Protect your most critical data
Overcoming data security challenges in a hybrid, multicloud world
Overcoming data security challenges in a hybrid, multicloud world
Move beyond passwords
Move beyond passwords
The top 5 tech trends to deliver business outcomes
The top 5 tech trends to deliver business outcomes

Events

  • On-Demand Webinar: How Poly and Microsoft are Embracing Future Work Environments
By Brett Winterford
Nov 12 2010
11:16AM
0 Comments

Related Articles

  • MinterEllison makes its IT security 'interventions' easier to understand
  • SolarWinds hackers accessed Microsoft source code
  • Tyro agrees to independent review after sending 150,000 spam messages
  • Apple could block apps that don't comply with new privacy feature
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

CBA becomes first 'Big 4' data recipient under CDR

CBA becomes first 'Big 4' data recipient under CDR

NSW Police green-lights Mark43 for $1bn COPS overhaul

NSW Police green-lights Mark43 for $1bn COPS overhaul

Urgent patches out for exploited Exchange Server zero-days

Urgent patches out for exploited Exchange Server zero-days

NBN Co to start consulting on gigabit speeds for FTTC

NBN Co to start consulting on gigabit speeds for FTTC

You must be a registered member of iTnews to post a comment.
Log In | Register
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.