- Related Stories
-
Feds call for global spam fight
April 20, 2006 -
On sentry duty in your in-box
April 18, 2006 -
Feds shut down spam ring for good
April 7, 2006 -
China plans spam crackdown
February 22, 2006
What's more, a spammer is attempting to intimidate the Blue Security customers by sending them threatening messages, according to the Israeli company, which launched its spam-fighting service in July last year.
"It had to happen. We're amazed it's taken so long," said Richi Jennings, an analyst at Ferris Research.
The Do Not Intrude Registry is a list of e-mail addresses that should not be spammed. It's encrypted, so spammers can't extract the actual addresses. Blue Security fights spammers by crippling their Web sites, in the name of its users, with a flood of complaints. About 500,000 people have signed up for the service, Blue Security said.
But it was simple for spammers to get hold of at least some of the e-mail addresses in Blue Security's registry, Jennings said. "A spammer has taken his list and 'cleaned' it against the Blue Security list. He then compared the original list with the cleaned list to figure out which addresses were removed."
It appears spammers are passing around this list of names that purports to be the Blue Security do-not-spam list. "Levels of spam received by members of the Blue Security list have roughly doubled since May 1," Jennings wrote.
The spam troubles are evidence that the Blue Security approach to fighting spam works, company CEO Eran Reshef said in the statement. "This is just proof that the Blue Community is an effective deterrent to spammers that are using unethical and illegal tactics to promote their products and services."
The affected Blue Security users were already getting spam, since the spammers had them on a list in the first place. Now they may just be getting a little more. "This isn't a disaster for Blue Security," Jennings said.
"Spammers are feeling the pressure," Reshef said. "This incident is only a futile attempt by a degenerate spammer to fight back through intimidation and extortion."
See more CNET content tagged:
spammer, anti-spam, security, e-mail address, e-mail




Does this spammer think that, quite possibly, spamming the people on the list will only increase exponentially his servers flooding? Do you think that occurred to him?
So the ampunt of spam in a "protected" account went down. And what about the amount of legitimate mail?
Does this spammer think that, quite possibly, spamming the people on the list will only increase exponentially his servers flooding? Do you think that occurred to him?
So the ampunt of spam in a "protected" account went down. And what about the amount of legitimate mail?
But Blue Security wasn't honest with its users either. They never informed users that they were engaged in counter-spamming, instead characterizing their activities as sending reports to the appropriate government agencies.
Perhaps the spammers and Blue Security truly are cut from the same cloth.
have always been straight forward, honest, and
open about the intent and the execution of the
communities resources. AND we have been hoping for
a day like this. The asshat SPAMMERS pain is so
sweet. Contrary to a misguided news report that
went all over the place. NO THEY ARE NOT SPAMMING
THE Do Not Intrude Registry. The peoples accounts
that always got spam are getting a little more.
But the accounts that never got any STILL Don't.
They can't maintain this attack. Most of the links
in the Spam this afternoon went to sights that
are YOINKED for Spamming Activity. And just wait
till this lets up and we act on all the spam that's been piling up. So Smooth Move SPAM Dummies
Thanks for all this Free Public Awareness.
We will Multiply in Numbers.
Extra Thanks for Proving that OUR efforts work.
....FROG ON...OH YEAH....
Delivered-To: xxxxxxxxxxxx
Received: by xxxxxxxxxxxxx with SMTP id xxxxxxxxxxxxxxxxxxxxxxxxx;
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Received: by xxxxxxxxxxxxxx with SMTP id xxxxxxxxxxxxxxxxxxxxxxxxxx;
Mon, 01 May 2006 05:50:09 -0700 (PDT)
Return-Path: <thabto@esplanade.com>
Received: from 3CF5918 ([http://218.23.108.114|http://218.23.108.114])
by mx.gmail.com with SMTP id a1si5179001ugf.2006.05.01.05.49.58;
Mon, 01 May 2006 05:50:09 -0700 (PDT)
Received-SPF: neutral (gmail.com: 218.23.108.114 is neither permitted nor denied by best guess record for domain of thabto@esplanade.com)
Received: from 250.0.102.32 by 218.23.108.114; Mon, 01 May 2006 16:44:55 +0300
Message-ID: <UYOHTRYWBIILJYTMXVZOQYOKM@erg.it>
From: "BARTHOLOMEW Julius" <thabto@esplanade.com>
Reply-To: "BARTHOLOMEW Julius" <thabto@esplanade.com>
To: xxxxxxxxxxx@gmail.com
Cc: xxxxxxxxxxxxxxx@gmail.com, xxxxxxxxxxxxxxxxxxxgmail.com, xxxxxxxxxxxx@gmail.com, xxxxxxxxxxxxxxxxxxx@gmail.com, xxxxxxxxxxxxxxxx@gmail.com
Subject: re:Don't pay attention to this email!
Date: Mon, 01 May 2006 14:40:55 +0100
X-Mailer: Microsoft Outlook, Build 10.0.2627
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="--xxxxxxxxxxxxxxxxxxxxx"
X-Priority: 3
X-MSMail-Priority: Normal
----8335755536655359
Content-Type: text/plain;
Content-Transfer-Encoding: 7Bit
You are being emailed because you are a user of BlueSecurity's well-known software "BlueFrog." http://www.bluesecurity.com/
Today, the BlueSecurity database became known to the worst spammers worldwide. Within 48 hours, the database will be published on the Internet, and your email address will be open to them all. After this, you will see the spam sent to your mailbox increase 10 - 20 fold.
BlueSecurity was illegally attacking email marketers, and doing so with your help. Many websites have been targeted and hit, including non-spam sites. BlueSecurity's software has been fully analyzed, and contains an abundance of malicious code. This includes: ability to send mass mail to users; the ability to attack websites with Distributed Denial of Service attack (DDoS); the ability to open hidden doors on any machine on which it is running; and a hidden auto-update code function, which can install anything on your computer and open it up to anyone.
BlueSecurity lists a USA address as their place of business, whereas their main office is in Tel Aviv. BlueSecurity is run by a few Russian-born Jews, who have previously been spamming themselves. When all is said and done, they will be able to run, hide and change their identities, leaving you to take the fall. YOU CANNOT PARTICIPATE IN ILLEGAL ACTIVITIES and expect to get away with it. This email ensures that you are well aware of the situation. Soon, you will be found guilty of computer crimes such as DDOS attacking of websites, conspiracy, and sending mass unsolicited bulk email messages for everything from viagra to porn, as long as you continue to run BlueFrog.
They do not take money for downloading their software, they do not take money for removing emails from their lists, and they have no visible revenue stream. What they DO have is 500,000 computers sitting there awaiting their next command. What are they doing now?
1. Using your computer to send spam ?
2. Using your computer to attack competitor websites?
3. Phishing through your files for your identity and banking information?
If you think you can merely change your email address and be safe while still running BlueFrog, you are in for a big surprise. This is just the beginning...
----xxxxxxxxxxxxxxxx--
But Blue Security wasn't honest with its users either. They never informed users that they were engaged in counter-spamming, instead characterizing their activities as sending reports to the appropriate government agencies.
Perhaps the spammers and Blue Security truly are cut from the same cloth.
have always been straight forward, honest, and
open about the intent and the execution of the
communities resources. AND we have been hoping for
a day like this. The asshat SPAMMERS pain is so
sweet. Contrary to a misguided news report that
went all over the place. NO THEY ARE NOT SPAMMING
THE Do Not Intrude Registry. The peoples accounts
that always got spam are getting a little more.
But the accounts that never got any STILL Don't.
They can't maintain this attack. Most of the links
in the Spam this afternoon went to sights that
are YOINKED for Spamming Activity. And just wait
till this lets up and we act on all the spam that's been piling up. So Smooth Move SPAM Dummies
Thanks for all this Free Public Awareness.
We will Multiply in Numbers.
Extra Thanks for Proving that OUR efforts work.
....FROG ON...OH YEAH....
Delivered-To: xxxxxxxxxxxx
Received: by xxxxxxxxxxxxx with SMTP id xxxxxxxxxxxxxxxxxxxxxxxxx;
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Received: by xxxxxxxxxxxxxx with SMTP id xxxxxxxxxxxxxxxxxxxxxxxxxx;
Mon, 01 May 2006 05:50:09 -0700 (PDT)
Return-Path: <thabto@esplanade.com>
Received: from 3CF5918 ([http://218.23.108.114|http://218.23.108.114])
by mx.gmail.com with SMTP id a1si5179001ugf.2006.05.01.05.49.58;
Mon, 01 May 2006 05:50:09 -0700 (PDT)
Received-SPF: neutral (gmail.com: 218.23.108.114 is neither permitted nor denied by best guess record for domain of thabto@esplanade.com)
Received: from 250.0.102.32 by 218.23.108.114; Mon, 01 May 2006 16:44:55 +0300
Message-ID: <UYOHTRYWBIILJYTMXVZOQYOKM@erg.it>
From: "BARTHOLOMEW Julius" <thabto@esplanade.com>
Reply-To: "BARTHOLOMEW Julius" <thabto@esplanade.com>
To: xxxxxxxxxxx@gmail.com
Cc: xxxxxxxxxxxxxxx@gmail.com, xxxxxxxxxxxxxxxxxxxgmail.com, xxxxxxxxxxxx@gmail.com, xxxxxxxxxxxxxxxxxxx@gmail.com, xxxxxxxxxxxxxxxx@gmail.com
Subject: re:Don't pay attention to this email!
Date: Mon, 01 May 2006 14:40:55 +0100
X-Mailer: Microsoft Outlook, Build 10.0.2627
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="--xxxxxxxxxxxxxxxxxxxxx"
X-Priority: 3
X-MSMail-Priority: Normal
----8335755536655359
Content-Type: text/plain;
Content-Transfer-Encoding: 7Bit
You are being emailed because you are a user of BlueSecurity's well-known software "BlueFrog." http://www.bluesecurity.com/
Today, the BlueSecurity database became known to the worst spammers worldwide. Within 48 hours, the database will be published on the Internet, and your email address will be open to them all. After this, you will see the spam sent to your mailbox increase 10 - 20 fold.
BlueSecurity was illegally attacking email marketers, and doing so with your help. Many websites have been targeted and hit, including non-spam sites. BlueSecurity's software has been fully analyzed, and contains an abundance of malicious code. This includes: ability to send mass mail to users; the ability to attack websites with Distributed Denial of Service attack (DDoS); the ability to open hidden doors on any machine on which it is running; and a hidden auto-update code function, which can install anything on your computer and open it up to anyone.
BlueSecurity lists a USA address as their place of business, whereas their main office is in Tel Aviv. BlueSecurity is run by a few Russian-born Jews, who have previously been spamming themselves. When all is said and done, they will be able to run, hide and change their identities, leaving you to take the fall. YOU CANNOT PARTICIPATE IN ILLEGAL ACTIVITIES and expect to get away with it. This email ensures that you are well aware of the situation. Soon, you will be found guilty of computer crimes such as DDOS attacking of websites, conspiracy, and sending mass unsolicited bulk email messages for everything from viagra to porn, as long as you continue to run BlueFrog.
They do not take money for downloading their software, they do not take money for removing emails from their lists, and they have no visible revenue stream. What they DO have is 500,000 computers sitting there awaiting their next command. What are they doing now?
1. Using your computer to send spam ?
2. Using your computer to attack competitor websites?
3. Phishing through your files for your identity and banking information?
If you think you can merely change your email address and be safe while still running BlueFrog, you are in for a big surprise. This is just the beginning...
----xxxxxxxxxxxxxxxx--
On the other hand, the thought that spammers cannot escape "being spammed" is quite retarted: They forge headers. They send from hijacked machines. They change their websites often with hosting and domains they obtain using stolen credit card data. And if they are attacked from a limited number of sources they can quite easily locate the sources and block them.
It's easier to change an email address than to "protect" it or take down a spammer, and it's trivial to stay quite spam free if you plan in advance how to use your email addresses.
By posting an FUD comment without knowing the facts, it looks like you are supporting the spammers...
ones who are hurting. In a desparate attempt to
discourage users from fighting back, they have
resorted to their old tricks.
If spammers do succeed in shutting down Blue
Security permanently, then I will write my own
spam complaint tool. This tool will use a
cryptographically signed instruction file that
will be spread via peer to peer protocols. When
distributed via peer to peer, spammers will have
no centralized target to attack. Since there
are no centralized email servers used in
spamming, this is the reason it is no longer
effective to shutdown spam spewing machines.
However the places where spammers collect their
money (websites) are still centralized. These
are attacked by Blue Frog programs.
Spammers are in business to make money. People
who are fed up with spam enough to sign up for
Blue Security are not the ones who buy from
spammers. The lists of Blue Frog email
addresses is valuable to spammers in the fact
that the list will identify those who are likely
to cause problems rather than profit.
A bully that is allowed to punch someone with
near impunity has no real reason to stop.
However, if the bully's victim tries to punch
back and recruits other victims to puch back at
the same time, the bully is going to get his
nose bloodied. Having an angry mob of bullied
victims kicking the living sh** out of the bully
is not what he wants. He wants a victim who
will do nothing more than cover his face and
body when being beat up.
I too have put together a spammer fighting tool.
This one should be used by web page authors to
punish spammers who spam the author's email
address.
visit http://www.plaza1.net/SpammerSlapper/
On the other hand, the thought that spammers cannot escape "being spammed" is quite retarted: They forge headers. They send from hijacked machines. They change their websites often with hosting and domains they obtain using stolen credit card data. And if they are attacked from a limited number of sources they can quite easily locate the sources and block them.
It's easier to change an email address than to "protect" it or take down a spammer, and it's trivial to stay quite spam free if you plan in advance how to use your email addresses.
By posting an FUD comment without knowing the facts, it looks like you are supporting the spammers...
ones who are hurting. In a desparate attempt to
discourage users from fighting back, they have
resorted to their old tricks.
If spammers do succeed in shutting down Blue
Security permanently, then I will write my own
spam complaint tool. This tool will use a
cryptographically signed instruction file that
will be spread via peer to peer protocols. When
distributed via peer to peer, spammers will have
no centralized target to attack. Since there
are no centralized email servers used in
spamming, this is the reason it is no longer
effective to shutdown spam spewing machines.
However the places where spammers collect their
money (websites) are still centralized. These
are attacked by Blue Frog programs.
Spammers are in business to make money. People
who are fed up with spam enough to sign up for
Blue Security are not the ones who buy from
spammers. The lists of Blue Frog email
addresses is valuable to spammers in the fact
that the list will identify those who are likely
to cause problems rather than profit.
A bully that is allowed to punch someone with
near impunity has no real reason to stop.
However, if the bully's victim tries to punch
back and recruits other victims to puch back at
the same time, the bully is going to get his
nose bloodied. Having an angry mob of bullied
victims kicking the living sh** out of the bully
is not what he wants. He wants a victim who
will do nothing more than cover his face and
body when being beat up.
I too have put together a spammer fighting tool.
This one should be used by web page authors to
punish spammers who spam the author's email
address.
visit http://www.plaza1.net/SpammerSlapper/
Yet the spam continues. Why?
;)
(BTW Frog User for 3 months - Go Frog - The fight has just begun)
Yet the spam continues. Why?
;)
(BTW Frog User for 3 months - Go Frog - The fight has just begun)
Martin
Martin
I get a nice warm fuzzy feeling in side knowing that the spammers are getting spammed for spamming me. I love it.
Though I suspect that this is like an arms race and it just leeds to escalation instead of an actual end to the problem. But, still I love the fuzzy feeling.
Robert
I get a nice warm fuzzy feeling in side knowing that the spammers are getting spammed for spamming me. I love it.
Though I suspect that this is like an arms race and it just leeds to escalation instead of an actual end to the problem. But, still I love the fuzzy feeling.
Robert
The deathpenalty has never reallybeen a deterntbecuse we hide the"humane"("pain -free")executions. I twould become a powerful deterent if we killed tha bastards as painfullyas possible.IE though of English style hanging: high andshort, by slow strangulation.Not painful eough: let'stry burning at the stake and make it slow televise it in everynews segment: see thecrimes, spam included plummet. Inhumane , says you but so is therapeand mutilation of innocent young girls.I brelieve in reciprocity: Do unto you whatyou do orpropose to do to me' Prettyfair is it not?
The deathpenalty has never reallybeen a deterntbecuse we hide the"humane"("pain -free")executions. I twould become a powerful deterent if we killed tha bastards as painfullyas possible.IE though of English style hanging: high andshort, by slow strangulation.Not painful eough: let'stry burning at the stake and make it slow televise it in everynews segment: see thecrimes, spam included plummet. Inhumane , says you but so is therapeand mutilation of innocent young girls.I brelieve in reciprocity: Do unto you whatyou do orpropose to do to me' Prettyfair is it not?
The deathpenalty has never reallybeen a deterntbecuse we hide the"humane"("pain -free")executions. I twould become a powerful deterent if we killed tha bastards as painfullyas possible.IE though of English style hanging: high andshort, by slow strangulation.Not painful eough: let'stry burning at the stake and make it slow televise it in everynews segment: see thecrimes, spam included plummet. Inhumane , says you but so is therapeand mutilation of innocent young girls.I brelieve in reciprocity: Do unto you whatyou do orpropose to do to me' Prettyfair is it not?
The deathpenalty has never reallybeen a deterntbecuse we hide the"humane"("pain -free")executions. I twould become a powerful deterent if we killed tha bastards as painfullyas possible.IE though of English style hanging: high andshort, by slow strangulation.Not painful eough: let'stry burning at the stake and make it slow televise it in everynews segment: see thecrimes, spam included plummet. Inhumane , says you but so is therapeand mutilation of innocent young girls.I brelieve in reciprocity: Do unto you whatyou do orpropose to do to me' Prettyfair is it not?
I don't at all like the wishful thinking Blue Security exuded, where everything ends up somehow proving that they're winning. They're not winning. I seriously doubt they will even be online again. Who would want to assume the risk of hosting them?
I am uninstalling Blue Security. People who can't admit their mistakes are dangerous, those who proclaim that all is well when they suffer a setback.
- This is confirmation that it works
- by ppentz May 4, 2006 2:04 PM PDT
- I have Blue Frog loaded on one PC, and was never all that sure it was working. Now, thanks to the confirmation from the spammers themselves, I KNOW it works and will install the Blue Frog on several more PCs. Thanks, spammers!
- Reply to this comment
-
-
- It's not working now
- by srdiamond May 4, 2006 2:57 PM PDT
- Blue Security is offline, and any mail you try to report does not get reported. I would call this a spammer victory, and poor planning by Blue Security for this contingency.
- View reply
Processing -
Showing 1 of 2 pages (66 Comments)I don't at all like the wishful thinking Blue Security exuded, where everything ends up somehow proving that they're winning. They're not winning. I seriously doubt they will even be online again. Who would want to assume the risk of hosting them?
I am uninstalling Blue Security. People who can't admit their mistakes are dangerous, those who proclaim that all is well when they suffer a setback.