Spam vigilante spat knocks out blog services

04.05.2006
A dispute between a mysterious Russian spammer and an Israeli antispam firm spilled over to the rest of the Internet on Wednesday, when denial of service attacks aimed at the Israeli firm's Web site knocked out servers that host millions of blogs.

Blogging company Six Apart suffered a sophisticated denial of service attack Tuesday afternoon, Pacific Time, which caused service outages at all of Six Apart's Web sites, including LiveJournal and TypePad. The denial of service attack stems from an ongoing feud between Blue Security and an unnamed spammer disgruntled over that company's antispam crusade, according to Blue Security CEO Eran Reshef.

Blue Security, based in Haifa, Israel, operates the "Do Not Intrude" list. The company allows individuals to register an e-mail address on the list, and then tracks spam messages to those accounts with desktop client software, known as "Blue Frog."

When spam e-mail is sent to a Do Not Intrude Member, Blue Security traces the message to its origin, and then bombards the Web site behind the campaign (known as the "sponsor") with requests to remove the e-mail message from their distribution lists. Millions of e-mail messages translate into millions of "opt out" requests from Blue Security members, which bog down the spammers' servers.

In recent days, e-mail users who had registered with the Do Not Intrude list have instead been the target of a concerted spam campaign and received extortion e-mail messages threatening to continue the campaigns unless the users remove their name from the Do Not Intrude registry.

The individual behind the attack, who uses the moniker "pharmamaster" and who is believed to reside in Russia, also cut off traffic to Blue Security's Web site, allegedly by manipulating routing configurations at a large Internet backbone provider to prevent traffic from outside Israel from reaching Blue Security's servers.