Spammers expose their entire operation through bad backups
csoonline.com
csoonline.com
Overall our current state of (an average user) security can be described as Swiss cheese where anyone with malicious intent can poke a hole and use it without any repercussions.
It's harder than you might expect to do effectively.
E.g. http://blog.talosintelligence.com/2016/09/the-rising-tides-o...
However, the researcher that found it says:
"The search engine at Shodan.io had indexed their IPs as running publicly accessible MongoDB instances"[1]
The screenshot looks like some kind of mongo explorer type UI: http://imgur.com/DzNthuy Probably MongoVue: https://mongopi.files.wordpress.com/2012/11/mongovue.png
So it appears to be the "mongo installed with no password, and open to the internet" thing again.
[1]https://www.reddit.com/r/apple/comments/3wq9fc/massive_data_...
The only way a sender can tell for sure their e-mail was delivered is to have tracking links: images and/or clickable links that include something to uniquely identify which address received the mail.
Most if not all e-mail clients block images, and many even disable links for unknown senders and/or messages that even remotely look like spam (eg: a non-zero spam score that is below the threshold to automatically reject or filter to a junk folder).
If you get tracked by one of these images or links, presumably you move from the "maybe working" e-mail address list to the "reads our messages" or "clicks our links" list, and at the very least means you contribute to making more money for the spammer when they sell that (higher-value) list.
Thats not true. Both spammers and legitimate email delivery services have hundreds if not thousands of accounts at the major email providers that they seed into their lists. As they are delivering email they periodically check their own accounts to see if mail is ending up in the inbox or the spam folder.
You can also request a "Feedback Loop" from major email providers that will forward spam complaints from your network back to you.
Gmail auto preloads (via their servers) all images in emails. You can turn it off though.
(lots of sources on internet about this, http://www.guidingtech.com/13461/gmail-always-display-images... for example)
It's a terrible setting, it should just be 'always ask'. Is there a legitimate use I'm missing? The only thing I can think of is for spammers to track if their spam went through, marketers of 'legit' mail to track the same thing, or a backdoor way to implement the atrocious 'read receipt' feature. None of those is at all beneficial to the user receiving the message.
Sometimes getting on these lists is fairly harmless by itself, but they can end up leaking a large amount of data about some people.
Just knowing that an email address is used and active is a start, but combine that with other information that could be grabbed like rough location data, IP address information, knowledge that the email was associated with that service, active usage dates, and more can end up being much worse.
Better let that one sit in the contemplation folder, as soon as you move to action you'll simply be just another criminal.
Actually, it'd make him/her a vigilante, that while still criminal, aims to serve the public good, whether rightfully so or not. I won't suggest whether that is ethically acceptable, but it'd me more of a conversation than legality.
I think this was the point. DDoS attacks potentially affect innocent people who just want to (say for instance) buy some cheap Viagra and who have nothing to do with the spammer who caused the initial irritation by sending yet another useless email.
Same as anything else: because there are laws forbidding it.
http://resources.infosecinstitute.com/legality-ddos-criminal...
I guarantee you that if you were noticed reliably responding to spam in this way, blackhats would happily direct your bandwidth towards their targets...
A commercial email is legal if it complies with the following:
Unsubscribe compliance
* A visible and operable unsubscribe mechanism is present in all emails.
* Consumer opt-out requests are honored within 10 business days.
* Opt-out lists also known as Suppression lists are only used for compliance purposes.
Content compliance
* Accurate "From" lines (including "friendly froms")
* Relevant subject lines (relative to offer in body content and not deceptive)
* A legitimate physical address of the publisher and/or advertiser is present. PO Box addresses are acceptable in compliance with 16 C.F.R. 316.2(p) and if the email is sent by a third party, the legitimate physical address of the entity, whose products or services are promoted through the email should be visible.
* A label is present if the content is adult.
Sending behavior compliance
* A message cannot be sent through an open relay.
* A message cannot be sent without an unsubscribe option.
* A message cannot be sent to a harvested email address.
* A message cannot contain a false header.
* A message should contain at least one sentence.
* A message cannot be null.
* Unsubscribe option should be below the message.
http://www.businessinsider.com/airbnb-harvested-craigslist-t...
Harvesting emails from Craigslist and spamming people that listed properties.
The Wikipedia intro reads "The software is heavily promoted and has been the subject of a class-action lawsuit for false advertising.".
They are now writing about a data leak of some spammers because these accidently left their repo open while MacKeeper had their own nice similar leak: "In December 2015 security researcher Chris Vickery discovered a publicly accessible database of 21GB of MacKeeper user data on the internet, exposing the usernames, passwords and other information of over 13 million MacKeeper users. According to Kromtech this was the result of a "server misconfiguration""
Attention - Portions of this article may be used for publication if properly referenced and credit is given to MacKeeper Security Researcher, Chris Vickery.
This is what happens to people on a Mac who download minecraft modpacks off of random places on the internet...
I wouldn't even visit their site to be quite frank.
Because that is literally part of the modus operandi of the Windows tech support scammers?
(I'm sorry, couldn't resist)