{"id":183,"date":"2008-03-02T23:33:41","date_gmt":"2008-03-03T07:33:41","guid":{"rendered":"http:\/\/cubist.cs.washington.edu\/Security\/2008\/03\/02\/spammers-find-a-way-to-abuse-out-of-office-replies\/"},"modified":"2008-03-02T23:33:41","modified_gmt":"2008-03-03T07:33:41","slug":"spammers-find-a-way-to-abuse-out-of-office-replies","status":"publish","type":"post","link":"https:\/\/secblog.cs.washington.edu\/Security\/2008\/03\/02\/spammers-find-a-way-to-abuse-out-of-office-replies\/","title":{"rendered":"Spammers find a way to abuse out-of-office replies"},"content":{"rendered":"<p>We&#8217;ve all recieved those helpful out-of-office replies when someone is not going to respond to your email for a while.\u00a0 At work, I always like recieving these because then I know I shouldn&#8217;t hold my breath waiting for a response for whatever problem I am facing.\u00a0 I would have never thought these could be harmful, but, of course, spammers have found a way to abuse them.<\/p>\n<p><!--more--><\/p>\n<p>An <a href=\"http:\/\/www.securitypronews.com\/news\/securitynews\/spn-45-20080225SpammersFindWayToAbuseAutoResponders.html\">article<\/a> posted on securitypronews.com describes how a spammer can take advantage of auto-responders.\u00a0 The trick is that the spammer needs to get around security measures that prevent spam.\u00a0 First, the adversary sets up a valid account at a normally-trusted provider.\u00a0 Then they turn on their auto-responder with an out-of-office message that is really their spam.\u00a0 They then send email with a spoofed &#8216;from&#8217; field ito their newly created account.\u00a0 The auto-responder dutifully replies to the victim&#8217;s email message with a spam-filled auto-reply.\u00a0 Since the email came from a legit sender, everything checks out and the email is not filtered out.<\/p>\n<p>In the article,\u00a0a McAfee spokesperson noted that since the replies come from a legitimate sender, with various safe signatures like DKIM, DomainKey or Sender ID in place, they may breeze past typical spam filtering technology.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>We&#8217;ve all recieved those helpful out-of-office replies when someone is not going to respond to your email for a while.\u00a0 At work, I always like recieving these because then I know I shouldn&#8217;t hold my breath waiting for a response &hellip; <a href=\"https:\/\/secblog.cs.washington.edu\/Security\/2008\/03\/02\/spammers-find-a-way-to-abuse-out-of-office-replies\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":43,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[120,121,119,122,118],"class_list":["post-183","post","type-post","status-publish","format-standard","hentry","category-current-events","tag-auto-reply","tag-auto-respond","tag-mcafee","tag-out-of-office","tag-spam"],"_links":{"self":[{"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/posts\/183","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/users\/43"}],"replies":[{"embeddable":true,"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/comments?post=183"}],"version-history":[{"count":0,"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/posts\/183\/revisions"}],"wp:attachment":[{"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/media?parent=183"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/categories?post=183"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/secblog.cs.washington.edu\/Security\/wp-json\/wp\/v2\/tags?post=183"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}