To advertise, contact
Nathalie Akl
+971 4 2108520
nathalie.akl@itp.com
بالعربية
Where am I? Home /


BREAKING NEWS :

Where do Bounce Messages come from?

By Kelly Conley on Wednesday, July 23, 2008


John Doe, sitting at his office, was scrolling through his inbox when he noticed this email:

Subject: Mail delivery failed: returning message to sender

John thought to himself "Message delivery failed? Did my message to Jane get blocked?" Then, he proceeded to open the message and found that it was an online pharmacy spam message he allegedly ‘sent'. John is initially puzzled because he never sent that message himself. Soon, he realizes that the message is NDR spam.

Symantec has observed a wave of Non-Delivery Receipt (NDR) attacks over last month. While this technique is certainly not new, a spike in volume was significant enough for us to take a deeper look. A lot of people are confused about these messages. Where do they come from? What is the purpose?

This spam type is a crafty technique used by some spammers. Rather than inserting the spam victims' email addresses in the ‘To' line of the message, NDR spammers insert the addresses into the ‘From' line. Next, the spammer sends that message to a server with a random inbox as the destination. This message travels to the destination, only to get bounced back to the original ‘sender' because the mailbox does not exist. Because the ‘From' line has been spoofed, the spam victim receives the bounced spam message.
Story continues below
advertisement



Some mail servers are configured to include the entire original message in the bounce. This is the desired result of the NDR spammer as the spam victim will look at the original spam when combing through the bounce message.

The spammer is gambling on the recipient having a higher likelihood of opening this type of message since the subject line is vague enough to not indicate obvious spam. Most people use their emails daily and when they see a bounce message the natural instinct is to open it up and check to see which of the sent messages was not received. Of course if you haven't sent an email recently and you receive a bounce spam in your inbox the chances that it is NDR spam are highly likely as it appears to be the spam type of choice recently for spammers. Do not open bounce messages unless you have recently sent mail.

Kelly Conley is Manager of Anti-Spam Research, Symantec Security Response


User Comments (1 comment)

How does it help the spammers.
Posted by Smita, Dxb, UAE on 12 August 2008 at 08:24 UAE time


Just wanted to know if opening a message can compromise the security of the computer. I was under the impression that only opening infected attachments can do that.
All posts are sent to the administrator for review and are published only after approval. ITP.net reserves the right to remove any comment at any time for any reason. Please keep your responses appropriate and on topic.
Name *
( Remmber Me )
Email *
(Your email address will not be published)
City
Country
Subject *
Comment *
Security Code * Code
 


Please click post only once - your comment will not be published immediately.

Related Comment

Henry Bell discusses ways to stay safe while surfing on coffee shops' wireless networks 

Related Feature

The Spam Report, October 2008

Internet

An overview of the latest spam trends and online threats 

Related Feature

Making space

Networks

As information storage becomes more critical to organisations, IT managers are rising to the complex task with solutions and... 


Competitions

Win an action-packed first-person shooter (FPS)!

Ends On Saturday, 15 November 2008

The latest in Electronic Arts’ pioneering WWII first-person shooter (FPS) franchise sees gamers take the role of a paratrooper in the 82th Airborne Division and drop behind enemy lines in several...


Advertising Features


Latest Products
Nero Burning Rom 8

Software | Applications | September 2008

The latest version of Nero's Burning ROM software is more functional than ever before.

RATING


Acer Aspire 6920g

Hardware | Notebooks | September 2008

Aspires to be a desktop replacement and largely succeeds.

RATING


BenQ DC X800

Hardware | Digital Imaging | September 2008

BenQ's DC X800 has the looks but does this snapper really have the 'X' factor?

RATING


Sony Cybershot DSC-H50

Hardware | Digital Imaging | September 2008

It's got the range for distant shots but do you have the ability to keep still?

RATING


Technology Jobs
Information Technology Manager
Location: Dubai, UAE
Account (Sales) Executive
Location: Dubai, UAE
IT Manager
Location: Dubai, UAE

For editorial enquiries contact
Mark Sutton
mark.sutton
@itp.com
To advertise, contact
Ahmad Bashour
+971 4 210 8549
or ahmad.bashour
@itp.com


Arabian Computer News Channel Middle East Channel Middle East - Arabic Charged CommsMEA Network Middle East Windows Middle East Windows Middle East - Arabic ALL ITP TITLES