Tuesday, February 4, 2014

Backscatter

Backscatter (also known as outscatter, misdirected bounces, blowback or collateral spam) is incorrect automated bounce messages sent by mail servers, typically as a side effect of incoming spam.

Recipients of such messages see them as a form of unsolicited bulk email or spam since they were not solicited by the recipients, are substantially similar to each other and are delivered in bulk quantities. Systems that generate email backscatter can end up being listed on various DNSBLs and be in violation of internet service providers' Terms of Service. Backscatter occurs because worms and spam messages often forge their sender address, and mailservers configured by naive administrators send a bounce message to this address.

Measures to reduce the problem include avoiding the need for bounce message by doing most rejections at the initial SMTP connection stage; and sending bounce messages only to addresses which can be reliably judged to have not been forged.

Contents

1 Cause
2 Reducing the problem
2.1 Preventing email address collection
2.2 Connection-stage rejection
2.3 Checking bounce recipients
2.4 Filtering backscatter
3 See also
4 References
5 External links

Cause

Authors of spam and viruses wish to make their messages appear to originate from a legitimate source to fool recipients into opening the message so they often use web-crawling software to scan usenet postings, message boards, and web pages for legitimate email addresses.
Due to the design of SMTP mail, recipient mail servers receiving these forged messages have no simple standard way to determine the authenticity of the sender. If they accept the email during the connection phases then, after further checking refuse it - for example because they believe it to be spam they will use the (potentially forged) sender's address to attempt a good-faith effort to report the problem to the apparent sender.

Mail servers can handle undeliverable messages in three fundamentally different ways:

Reject. A receiving server can reject the incoming email during the connection stage while the sending server is still connected. If a message is rejected at connect time with a 5xx error code then the sending server can report the problem to the real sender cleanly.

Drop. A receiving server can initially accept the full message, but then determine that it is spam, and quarantine it - delivering to "Junk" or "Spam" folders from where it will eventually be deleted automatically. This is common behaviour, even though RFC 5321 says: "...silent dropping of messages should be considered only in those cases where there is very high confidence that the messages are seriously fraudulent or otherwise inappropriate..."

Bounce. A receiving server can initially accept the full message, but then determine that it is spam or to a non-existent recipient, and generate a bounce message back to the supposed sender indicating that message delivery failed.
Backscatter occurs when the "bounce" method is used, and the sender information on the incoming email was that of an unrelated third party.

Reducing the problem

Every step to control worms and spam messages helps reduce backscatter, but other common approaches such as those in this section also reduce the same problem.

Preventing email address collection

It is common to attempt to obscure email addresses in a manner that is not easily machine-readable. Several methods are available, such as simply not using a standard text format (john (at) example.com) or using a bitmap image of the address rather than raw text. More complex address obscuration methods are available, such as encoding the addresses using a substitution cipher, embedded as program code within a tiny javascript or Adobe Flash program for each address, which when clicked, opens a temporary window and sends the decoded mailto: address to the local email client, but all such obscuration methods can potentially be attacked by spammers in the same manner as CAPTCHAs.

Connection-stage rejection

During the initial SMTP connection mailservers can do a range of checks, and often reject email with a 5xx error code while the sending server is still connected. Rejecting a message at the connection-stage in this way will usually cause the sending MTA to generate a local bounce message or Non-Delivery Notification (NDN) to a local, authenticated user.
Reasons for rejection include:

- Recipient validation
- Anti-forgery checks such as SPF, DKIM or Sender ID
- Servers that do not have a forward-confirmed reverse DNS entry
- Senders on block lists.
- Temporary rejection via greylisting methods

Mail transfer agents (MTAs) which forward mail can avoid generating backscatter by using a transparent SMTP proxy.

Checking bounce recipients

Mail servers sending email bounce messages can use a range of measures to judge whether a return address has been forged.

Filtering backscatter

While preventing backscatter is desirable, it is also possible to reduce its impact by filtering for it, and many spam filtering systems now include the option to attempt to detect and reject backscatter emails as spam. In addition, systems using schemes such as Bounce Address Tag Validation "tag" their outgoing email in a way that allows them to reliably detect incoming bogus bounce messages.

© Wikipedia, the free encyclopedia

Song Chun

How is life with you over there?

Please considering the fact that I sourced your email from the peoples search database on the web during my discrete search for a foreign partner whom can assist..My name is Mr. Song chun; I am the Head of Operations at Dah Sing Bank, Hong Kong. My business proposal for you is to assist me transfer US$12.8 million from my bank in Hong Kong to a foreign bank if willing. After the successful transfer,our sharing ratio will be 40% for you and 60% for me.

This money was deposited by my client Mr. Yoshi Yuu, who lost his life along with his family in the massive Earthquake and Tsunami disaster that destroyed avast area of Japan on the date 11th March 2011. According to the law in my Country, after nine months the Hong Kong Government would come for the funds if nobody applies to claim the money. Should you be interested, please respond immediately to my private email:(song_chun78@accountant.com) with the following information for documentation purpose by the attorney:

Your Complete Name:
Current Residential Address:
Mobile/cell Number:
Your Occupation:
Your Age and Sex:

I look forward to hearing from you.

Best Regards,
Mr. Song Chun

Mr Adnan Khashoggi - Charity/Investment Project

My name is Mr Adnan Khashoggi, a merchant in Saudi Arabian . I have recently been diagnosed with Esophageal cancer, which has defiled all medical treatment. Expert diagnosis has shown that I have few months to live.

The intention of this email is to employ the expertise of a business entrepreneur, who can identify a viable investment and guarantee reasonable returns on my wealth. I cannot rely on his closest relatives any more, as they did not show responsible behaviour two years ago when I entrusted half of my wealth to them to invest on his behalf. They thought I wouldn't survive the operation and then used the money for their personal needs.

The last of my money which no one knows of is the huge cash deposit of USD$75 Million dollars. I will want you to help me collect this deposit,I have set aside 10% for your time and effort.

To prevent any more mishaps, my attorney will act as a check, monitoring every aspect of the investment. Funds should be split in half and distributed to charity organisation and the other half, as investment for my son.

If this interests you, please reach me on this email address: adnan.khashoggi@aim.com to discuss terms and compensation.

Kind regard

Mr.Adnan Khashoggi.

From Microsoft NI - re: claim

Winner No. 009,

It is obvious that this notification will come to you as a surprise but please find time to read it carefully as we congratulate you over your success in the following official publication of results of the E-mail electronic online Sweepstakes organized by Microsoft Corporation, in conjunction with the foundation for the promotion of software products, (F.P.S.) held in Amsterdam- The Netherlands. A Payment of 815.810.00 Euros ( Eight hundred and fifteen Thousand, Eight Hundred and Ten Euros only ) will be paid in your name.

It is important to note that your award was released with the following particulars attached to it.

(1) File Number: MS1267-2014
(2) Grant Number: MIWT/11846563459/266
(3) Ref. Code: KB23/857/MCL5 /CO

Forward The above Information as Listed to Microsoft Agency NL.

Microsoft Group Agency NL:
Director: Dr.David Bengal
Contact Email: msoftagency@aol.com
Tel: +31 659 216 095

Soon as the Above Information is received through E-mail to: msoftagency@aol.com , your payment will be processed and paid to you.

Sincerely,
Mrs. Angela Banks

Director Of National Warehouse - From The Desk Of : Dr. Paul Hanson

Hello Sir / Madam!!!

Firstly, I wish to introduce myself as a sympathizer of your situation. I am the Controller of Fund Movement Terminal and Director of national warehouse where abandoned fund/valuables consignments are dumped.

This is to inform you that fresh arrangement was made by me to conclude the shipment of your consignment of funds to your country. I choose to do it and make sure it has left the shores of Ghana already before contacting you. I found out that this consignment has been lying here because of lack of contact and none payment of delivery cost This is why I decided to use my connections as the Delivery/Shipment officer in charge of the National Security warehouse. (This is where all the abandoned consignments in Ghana are kept at the orders of the Government of Ghana for seizure or destruction.

Therefore, this letter is highly confidential and top secret. For this reason,you must not inform anybody about this letter or my contact with you. You must keep my relationship with you to be topped secret and highly confidential because as I have arranged your consignment to the Diplomatic Security Company in Ghana where the delivery will come from to your house, so no one must know so that the fund will not raise an eye brow.

CONDITIONS OF THIS DELIVERY

1. You must keep my relationship with you highly secret/confidential.
2. You must not expose all the above information to anybody.
3. You must be willing to act fast on any information, directives and advice from me and the Diplomatic Security Company in Ghana.

Note: I know the content of the Box because I could see the amount you are being owned by the Federal Government of Ghana as an inheritance. This is why I decided to get involved. You must also know that this arrangement do not concern all the people that you have had contact with in Ghana before today as this consignment/Payment has been surrendered to the Government, Hence my involvement.

As soon as I receive your response, I will give you more details on the way of such arrangements and I will also give you the full contact information of the Diplomatic Security Company in Ghana as soon as you have contacted me.

Therefore, further details will be furnished to you as soon as I receive your reply.

Yours Sincerely
Dr. Paul Hanson
Director Of National Warehouse

PAYMENT VIA ATM MASTERCARD WITH PROOF OF OWNERSHIP

ATM MasterCard Department, Zenith Bank Plc

Attn: Beneficiary

Due to your over-due fund which you have been finding it difficult to receive through a Bank Draft, Bank to Bank Wire Transfer and Western Union Installment Payment arrangements. A meeting was held last weekend as to the problem surrounding the Remittance of your fund, and after all deliberation, the Panel Agreement was to load your fund into a worldwide accessible ATM MasterCard from zenith Bank Plc to you.

The Panel has approved to send you an International Swift (ATM MasterCard) total sum of $2,500.000.00. (Two Million, Five hundred Thousand United State Dollars) Which you are to use in accessing your funds in any ATM Machine location Worldwide with a limit withdraw of $5.000.00 until you complete the total amount loaded.

Be inform that your ATM MasterCard an its papers has been sealed and handed over to our ATM Admin director, Mr Anthony Morrison. He will attache the Proof of Ownership Certificate and the Approval Letter of your funds Via ATM MasterCard with Zenith Bank Plc. Before processing your shipment for usage.Also, according to the shipping arrangement with the Fedex courier service,the director on behalf of zenith bank estimated $250.00 for the shipping security papers an all vital requirement needed to execute this delivery to you for pick up.

Reconfirm the bellow information to start processing your shipment with immediate effect

(1) Your Full Name :
(2) Full Residential Address : (P.O.BOX NOT ALLOWED)
(3) Direct and Current Phone :
(4) Present Country :
(5) passport identification:

Once your details is been received by the Swift zenith ATM Card Center, Mr Anthony Morrison will attache your vital document and further instructions to secure your card and its tracking number from the courier service to your door step. Please endevour to see the vital papers in your name from zenith bank first,before remitting the courier shipping fee for pick up.

Please be regular with your email so we can use 1week to confirm your payment ATM MasterCard with you so you can start usage immediately

Thanks for your co-operation.
Tel-Number: +234-809-227-3438