<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.7" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Curious mailbomb</title>
	<link>http://spamhuntress.com/2007/10/25/curious-mailbomb/</link>
	<description>Just another WordPress weblog</description>
	<pubDate>Fri, 29 Aug 2008 23:21:25 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.7</generator>

	<item>
		<title>by: David Clarke</title>
		<link>http://spamhuntress.com/2007/10/25/curious-mailbomb/#comment-271728</link>
		<pubDate>Mon, 29 Oct 2007 15:25:43 +0000</pubDate>
		<guid>http://spamhuntress.com/2007/10/25/curious-mailbomb/#comment-271728</guid>
					<description>To me, the issue is not just what the spammer is trying to achieve; they may just be testing the forms and security before sending out the payload, or possibly, if you were the sole target, some form of DOS on your mail server.

More interestingly, I find it hard to understand that the owners of the servers with vulnerable forms don't notice anything in their logs - even if it's just a spike in the bandwidth being used.

I have to admit that I've had dealings with an organisation that should know better, and informed them of their vulnerability, shown them a demo of how it can be abused and then had them tell me that it'll never happen to them - or words to that effect.

Do you know of any way to successfully persuade vulnerable hosts to tighten their security?</description>
		<content:encoded><![CDATA[<p>To me, the issue is not just what the spammer is trying to achieve; they may just be testing the forms and security before sending out the payload, or possibly, if you were the sole target, some form of DOS on your mail server.</p>
<p>More interestingly, I find it hard to understand that the owners of the servers with vulnerable forms don&#8217;t notice anything in their logs - even if it&#8217;s just a spike in the bandwidth being used.</p>
<p>I have to admit that I&#8217;ve had dealings with an organisation that should know better, and informed them of their vulnerability, shown them a demo of how it can be abused and then had them tell me that it&#8217;ll never happen to them - or words to that effect.</p>
<p>Do you know of any way to successfully persuade vulnerable hosts to tighten their security?
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
