On CBS.com: You a Race Fan?Play Amazing Race Fantasy
BNET Business Network:
BNET
TechRepublic
ZDNet

December 10th, 2008

Gmail, Yahoo and Hotmail systematically abused by spammers

Posted by Dancho Danchev @ 12:07 pm

Categories: Botnets, Google, Hackers, Malware, Microsoft, Passwords, Phishing, Spam and Phishing, Web 2.0

Tags: Security, CAPTCHA, Gmail, Yahoo Mail, Hotmail, Dancho Danchev

MessageLabs CAPTCHA Email Providers SpamWith the industry’s eyes constantly monitoring the usual suspects’ use of phony hosting providers, another market segment within the underground marketplace has been developing beneath the radar, aiming to build a malicious infrastructure (Spammers targeting Bebo, generate thousands of bogus accounts; Malware and spam attacks exploiting Picasa and ImageShack) through efficient CAPTCHA recognition.

The latest MessageLabs Intelligence annual report for 2008 indicates that on average, 12 percent of the spam volume that they were monitoring in 2008 came from legitimate email providers such as Gmail, Yahoo Mail and Hotmail, followed by its September’s peak of 25%. Earlier this year, more vendors emphasized on this ongoing development, citing machine learning CAPTCHA breaking techniques as the cause of it. In reality though, the very same humans that CAPTCHA was meant to identify continue undermining it as an anti-bot registration measure.

Researching the market segment throughout the year (Microsoft’s CAPTCHA successfully broken; Gmail, Yahoo and Hotmail’s CAPTCHA broken by spammers; Spam coming from free email providers increasing; Spammers attacking Microsoft’s CAPTCHA — again; Inside India’s CAPTCHA solving economy) it’s time to assess the current situation and speculate on the upcoming efficiency model.

“In 2008, spammers developed an affinity for spamming from large, reputable web-based email and application services by defeating CAPTCHA (Completely Automated Public Turing Test to tell Computers and Humans Apart) techniques to generate massive numbers of personal accounts from these services. In January, 6.5 percent of spam originated from these hosted webmail accounts, peaking in September when 25 percent of spam originated from these sources, averaging about 12 percent for the remainder of the year.”

ReputationAuthority GmailThree of the most popular free email providers continue being systematically abused by cybercriminals so efficiently, that they often top the charts (Gmail; Yahoo; Microsoft) of major anti-spam organizations such as Spamhaus. Despite that the affected companies are aware of this ongoing abuse, some of their mail servers have such a bad reputation due to the outgoing spam that it would be hard not to assume that sent email may not be reaching its destination. Moreover, BorderWare’s ReputationAuthority.org also comes handy when assessing the reputation of Gmail, Yahoo Mail and Hotmail. Who’s got the worst reputation varies, but for the time being, Microsoft’s web properties appear to be ahead of Gmail and Yahoo’s.

Is the supply of pre-registered accounts at these services driving the market, or is the customer’s demand that’s actually driving it? Whatever the case, supply is pretty efficient for the time being. For instance, I’m currently monitoring several web based bogus account registration services, with an average price for a thousand accounts at any of these email providers of $10. That’s right, for $10 a spammer could get his hands on a thousand pre-registered email accounts if we are to exclude the discounts offered for a bulk purchase. And whereas I still haven’t been able to establish a relationship between these services and Indian CAPTCHA breakers, theoretically, the supply of bogus accounts offered by a Russian service could be in fact outsourced as registration process to human CAPTCHA breakers, and the service itself acting as an intermediary. Whether it’s the use of malware infected hosts, or through human CAPTCHA solvers, the hundreds of thousands of accounts offered for sale remain there.

Gmail Yahoo Hotmail CAPTCHALet’s talk about efficiency. A research paper entitled “Exploiting the Trust Hierarchy among Email Systems” released earlier this year, and surprisingly receiving zero media attention, shows a proof of concept allowing the researchers to not only bypass Gmail’s messages limit for bulk messages, but also, abuse Gmail’s email forwarding function in order to successfully deliver emails classified as spam by relaying them through white listed Gmail servers — now DomainKeys empowered :

“The presented vulnerability enables an attacker to bypass blacklist/whitelist based email filters and freely forge all fields in an email message by having Google’s SMTP servers tricked into behaving like open SMTP relays. We were able to confirm that this vulnerability is indeed exploitable by assembling a proof of concept (PoC) attack that allowed us to use one single Gmail account to send bulk messages to more than 4,000 email targets (which surpasses Gmail’s 500 messages limit for bulk messages). Although we have limited the number of messages in our example to 4,000+, no counter measures took place that would have prevented us from sending more messages, and for that matter sending an unlimited number of messages.”

What this means is that the potential spamming speed achieved through a single automatically registered Gmail account could be greatly increased. From another perspective, a bogus account wasn’t worth as much as it is worth today, since it allows automatic access to all of the company’s web properties allowing spammers and cybercriminals (Cybercriminals syndicating Google Trends keywords to serve malware) to abuse them even further. CAPTCHA is dead, humans that were supposed to recognize it killed it by starting to recognize it efficiently and monetizing the process.

The bottom line, ask yourself the following - how many incoming anti-spam solutions can you think of right now, and how many outgoing anti-spam solutions are you aware of? Before spam comes it has to go out first.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 77 Talkback(s)
I need captcha entry work
Dear sir
Take my salam
we 7 years experience in this field. we have 30 pc 90 worker & we have 24/7 nonstop support worker. If you have posible pls send me your captcha work, our contact number... (Read the rest)
Posted by: sumon234 Posted on: 01/09/09 You are currently: a Guest | | Terms of Use
I could have told them that for free.  James T. Kirk | 12/10/08
"Atmosphere important to life on Earth"  cwallen19803@... | 12/11/08
And they would have ignored you  mejohnsn | 12/12/08
That's the same as saying  AzuMao | 12/15/08
Like I keep saying...  bjbrock | 12/10/08
These companies are Microsoft and Google  CobraA1 | 12/11/08
Mandate change to MIME/SMTP  no_zd_user_name | 12/10/08
PGP is all very well Dietrich  a foot in both camps | 12/11/08
It can theoretically be implemented in a user friendly way  CobraA1 | 12/11/08
Establish a Mandate 'with incentives'  no_zd_user_name | 12/11/08
Agreed.  CobraA1 | 12/11/08
Impunity  no_zd_user_name | 12/11/08
Very close to what Ive been saying for years  LegendsOfBatman | 12/11/08
#3 especially  CobraA1 | 12/11/08
Definitely  LegendsOfBatman | 12/13/08
Known sender  Ashtonian | 12/11/08
Government Does Not Want Mandate!  dmksage@... | 12/14/08
Govt can and does routinely intercept and crack encrypted emails...  no_zd_user_name | 12/14/08
huge fines  Mectron | 12/10/08
Speaking Of Huge  itanalyst2@... | 12/11/08
I have few more creative ideas on what to do to them!...nt  USTechHead | 12/11/08
Cannon?  fionncreagh@... | 12/13/08
That explains it  jhughs | 12/11/08
CAPTCHA and Child-proofing  w_c_mead | 12/11/08
Child proof caps  jhughs | 12/11/08
security vs usability  narxym | 12/15/08
Require a physical ID, such as credit card?  CobraA1 | 12/11/08
I dont think they need to go that far  Stan57 | 12/11/08
Not a solution.  CobraA1 | 12/11/08
Right. I use a Gmail address b/c  Telexer | 12/11/08
I Use It Too  catlovver | 12/11/08
Not a solution  Stan57 | 12/12/08
On the "porn farm" issue  Telexer | 12/11/08
RE: Gmail, Yahoo and Hotmail systematically abused by spammers  clarnT | 12/11/08
RE: Gmail, Yahoo and Hotmail systematically abused by spammers  wrenchmonkey | 12/11/08
Genius!  aureolin@... | 12/11/08
Not that easy...  JCitizen | 12/11/08
RE: Gmail, Yahoo and Hotmail systematically abused by spammers  rwhaller42 | 12/11/08
The NSA, FBI, CIA, KGB and  arminw | 12/11/08
Clandestine?  redbeard74 | 12/17/08
But the government isn't that stupid  AzuMao | 12/18/08
Remember "Blue Frog"?  public@... | 12/11/08
Peer to Peer Blue Frog  cyberscan | 12/11/08
RE: Gmail, Yahoo and Hotmail systematically abused by spammers  w_c_mead | 12/11/08
Usable seat belts are available - widespread usage is the challenge  lareynolds | 12/11/08
RE: Gmail, Yahoo and Hotmail systematically abused by spammers  lareynolds | 12/11/08
A CAPTCHA successor...  arminw | 12/11/08
A CAPTCHA successor???  ambercromby | 12/11/08
Trivia questions are just another form of CAPTCHA  lareynolds | 12/11/08
hummm . . .  CobraA1 | 12/11/08
It's about criminals, not computers  lareynolds | 12/11/08
Yup, we need to be identifying criminals.  CobraA1 | 12/11/08
Credit Card Companies Really DON'T Care  IBKrusty | 12/11/08
Nobody is in the business of losing customers.  CobraA1 | 12/12/08
. . . and a note about Form Armor  CobraA1 | 12/11/08
Not a Client-Side App  lareynolds | 12/12/08
Never confuse obscurity with security.  CobraA1 | 12/12/08
RE: Gmail, Yahoo and Hotmail systematically abused by spammers  rocketman67 | 12/11/08
Hotmail, maybe one a day for me...  JCitizen | 12/11/08
Whatever.  bbneo | 12/11/08
RE: Gmail, Yahoo and Hotmail systematically abused by spammers  WATKINS12@... | 12/11/08
Writer Needs to Learn How To Write  ken.bld@... | 12/12/08
Wrong  mejohnsn | 12/12/08
Perhaps one of you could enlighten the rest of us  ttrtilley@... | 12/16/08
Wrong, but for the oppisite reason.  AzuMao | 12/17/08
RE: Gmail, Yahoo and Hotmail systematically abused by spammers  twaynesdomain | 12/12/08
RE: Gmail, Yahoo and Hotmail systematically abused by spammers  cgenrich | 12/12/08
RE: Gmail, Yahoo and Hotmail systematically abused by spammers  gabrielbear@... | 12/12/08
My dormant gmail account  twirth5@... | 12/12/08
Using Credit Card Numbers  satovey@... | 12/12/08
RE: Gmail, Yahoo and Hotmail systematically abused by spammers  emenau | 12/13/08
RE: Gmail, Yahoo and Hotmail systematically abused by spammers  larrytucker5650 | 12/13/08
RE: Gmail, Yahoo and Hotmail systematically abused by spammers  CapitolValley | 12/15/08
RE: Gmail, Yahoo and Hotmail systematically abused by spammers  vilppuu@... | 12/16/08
RE: Gmail, Yahoo and Hotmail systematically abused by spammers  dadogg2 | 12/17/08
RE: Gmail, Yahoo and Hotmail systematically abused by spammers  redbeard74 | 12/17/08
I need captcha entry work  sumon234 | 01/09/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here