Monday, May 11, 2009

 

Hotmail stupidity protects spammers

Apparently Hotmail (Microsoft Corporation) is now selling private label email service, and some of its customers offer that service "free" to the Nigerian identity theft syndicate.

A typical fraud email offers the usual box of money stranded somehow in Nigeria, and to reclaim it I must email the gov't of Nigeria at atm.cardremmitance@hotellos.nl. (Yes, people actually fall for this. Mostly it's wanna-be con artists who think they're gonna con the Nigerians.) I got three copies. The MX records for hotellos.nl are
hotellos.nl. 86024 IN MX 0 1023266581.pamx1.hotmail.com.
hotellos.nl. 86024 IN MX 10 1023266581.pamx1.hotmail.com.
That is, Hotmail hosts this Nigerian identity theft mailbox account.

The only address that seems to work at all for Hotmail is report_spam@hotmail.com. Abuse@ and Postmaster@ don't work. I sent a complete, simple spam report. Hotmail said:

Unfortunately, in order to process your request, Hotmail Support needs a valid MSN/Hotmail hosted account.

The response came within a couple of minutes. Nobody told the abuse deaprtment about these new private-labeled domains. An automatic filter is throwing away reports of hotmail hosted spam. Until this is fixed, spammer accounts on Hotmail are pretty much bullet proof.

Apr1l 2010 update.  I think I'll list the problem domains here.
8u8.tw, admin.it.th, banat.ps, discuz.org, hotellos.nl, hotmail.com.tw, info.al, live.co.uk, mycin.net, nba2k.com.cn, qatar.io, ufo.tc, w.cn, ws.tc

Labels: , ,


This page is powered by Blogger. Isn't yours?