internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It


  About Us l Contact Us l Privacy
Home News Business Software Hardware Online Marketing Web Management The Basics
Product Watch Buyer's Guide Small Business Essentials Online Forums Glossary Images Events

Search SBC

Search internet.com


Small Business Computing Product of the Year Awards
Winners Announced!


internet.commerce
Be a Commerce Partner
Baby Photo Contest
Best Price
Promotional Gifts
Computer Hardware
GPS
Web Hosting Directory
Home Improvement
Prepaid Phone Card
Logo Design
Domain registration
Compare Prices
KVM Switch over IP
Find Software
Data Center Solutions

Free Newsletters
Small Business Computing

Ecommerce Guide Daily

Webopedia

E-mail Offers

Newsletter Address Changes
Webopedia Glossary
Enter a Term:

internet.com
IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

Get Started with Oracle on Windows DVD
Learn how Oracle gives you the power to grow by providing a scalable, easy-to-use platform for running your business at a price you can afford. Request your free copy of this DVD, containing Oracle Database 11g software, whitepapers, tutorials, etc. Register now! ;
Guide to Oracle 11g and Database Migration
Oracle Database 11g includes more features for self-management and automation, which makes it easier for customers to cost-effectively manage their data. Download this Internet.com eBook for an overview of some of the new features in 11g and for an overview of the issues you need to consider as you prepare for a database migration. ;
Innovate Faster with Oracle Database 11g
Read this in-depth analysis of 56 customers, which shows significant differences between the value software vendors Oracle and SAP deliver to midsize companies. ;
Oracle Business Intelligence Standard Edition One
Find out how Newport Beach, CA-based Mobilitie is shaking up the telecom industry by leveraging technology to provide an entirely different financial model for deploying, upgrading, and owning wireless and wireline network assets. ;
Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
Quickly implementing an ERP software solution can be of tremendous benefit; however, companies often struggle to balance the benefits of reducing implementation time and cost with the risks of an accelerated deployment. Read this white paper to learn about easy-to-follow best practices for achieving a successful accelerated implementation. ;
Making the Case for Oracle Database on Windows
Users benefit as vendors reduce enterprise complexity and deliver integration. ;



Hot Topics
Driving Business from Bloggers
Demystifying Search Engine Optimization: Part 2
Last Call: Vote Today!


Small Business Essentials
Networking Fundamentals
Be it wired or wireless, building a network can take your small business to new heights in Internet communications, real-time collaboration, webhosting and e-commerce — or simply be setup to connect a series of workstations with a shared printer. Learn how to leverage today's networking technologies at your small business.
[ more ]


Visit ServerWatch for summaries of server and development tool updates, the latest on server news and trends, and more.
Online Marketing
Spoofing: Identity Crisis
May 22, 2002

By Rebecca Lieb

Who steals my purse steals trash... / But he that filches from me my good name / Robs me of that which not enriches him / And makes me poor indeed. --William Shakespeare

Imagine this scenario: Hundreds of thousands of spam emails appear to come from... your company. The ensuing flood of bounces and complaints from recipients crash your server. Outraged addressees clog your phone lines. Business grinds to a halt. Days and dollars are spent salvaging your technology, soothing complaints, and doing damage control for your brand. It's called spoofing - and it could happen to you.

Spoof email forges the sender's identity to trick the recipient into opening it (or to trick a spam filter into delivering it). When recipients click on a link or attachment, they're off on a little trip to well-known circles in Internet Hell: Scam, Porn Site, Disinformation Campaign, or Virus.

Real-Life Spoofs
flowers.com (now 1-800-FLOWERS.COM). A student used the company's address in spam selling information on "free cash grants." Bounces and return-to-sender hate mail swamped flowers.com 's network and crashed its system.

Sony. A message "from" Sony's president threatening a hostile takeover of Apple Computer at an inflated per-share price landed at tech and finance companies from Silicon Valley to Wall Street.

Herbert Smith (law firm). An icily worded message "from" management informed employees a colleague had been brutally murdered, naming her replacement. Shocked staff forwarded the message to friends outside the company's London and Hong Kong offices. A viral global smear campaign rapidly unfurled. Microsoft. An attachment in a message "from" Microsoft was purported to be a software update. Those who clicked succumbed to the virus the "update" really was.

PayPal. A message, apparently from an AOL account, told recipients they had been paid $200. It linked to a fake PayPal page that collected their financial information. (Similarly, email "from" the American Red Cross following the September 11 disaster sent recipients to fake Web sites where people used credit cards to make "donations.") Warner Bros. A message "from" "warnerbros.au" linked to a porn site. (Computerworld magazine and many other media companies suffered similar fates.)

The FBI. "From" a bureau employee: "Your application is approved. Please fill out this form to confirm your identity." Requested were name, address, and credit card number with expiration date.

Juno. Back when dinosaurs walked the earth (in 1997), ISP Juno filed suit against five companies and 10 groups spamming with fake Juno addresses. The claim sought millions in "damages to Juno's reputation."

Making a Federal Case out of Spoof
Anti-spam activist and Web pioneer Rodney Joffe successfully filed suit against a spoofer who, in his estimate, cost his business $20,000 cash, employee work hours, and attorney's fees. "Almost none of these people are caught because few are prepared to invest what I invested," he said. "The odds are with the spammer because there's no real federal law that covers this, and this was a federal case."

Here's how the spoof unfolded: Joffe's system was suddenly overwhelmed with bounces (undeliverable messages). Recipients of the spoofed message, believing it to have come from his company, complained, which added to the email deluge. Some were so outraged that they phoned company executives to vent. It took a couple of hours to figure out what was happening and to formulate an email response template for complaints. These then had to be manually sent to tens of thousands of complainants.

The problem is real and getting worse, Joffe says. "One reason is blackhole lists, like MAPS, are being fragmented. Companies are installing their own spam filters. Spammers craft spam to get through. If you can put anything in [a return address line], you might as well put in things that will be received. .edus and .govs are very popular, so is .mil."

The How and Why of Spoof
Spam software can randomize the "from" line, so 1 million messages would not appear to come from a single source. Randomize enough names, and the software will occasionally spit out a real one, belonging to a real company - maybe yours.

There's some division of opinion on why spoofers choose the addresses they do. Margie Arbon, MAPS director of operations, says .edu addresses are used because universities often have open relays, so by cloaking yourself as a .edu you can get messages through them as if you were a legitimate user.

Then there are those spoofers who appropriate a real email address. "Phishers" will mock up an ISP's site and email you, telling you that a new ID needs to be entered, with a link to the fake page provided. Once they have your password, they hack your account and send email as you.

Coalition Against Unsolicited Commercial Email (CAUCE) board member and author John R. Levine says spoofing is technically no harder than "forging a return address on paper mail."

"I get a lot of bounces from mail I never sent," he told me, "but it's easy to explain to people I'm not a spammer. Customers are not that technically sophisticated. Spoofing is rarely done well - it doesn't look professional or sophisticated. But people say, 'Oh, how nice.' Click. Boom."

As time goes on, Levine predicts, marketers are going to get more upset about spoofing, for which he says Windows security flaws are largely to blame. "Customers' perception is: If you get spam, it's fraudulent. I didn't know this company is a bunch of crooks," Levine said.

Spoofers use company names because, as Levine puts it, "most individuals don't have an identity worth defaming. You could send rude things to someone's coworkers or mother. It's well known political spam has been sent by the opposition. People do fake press releases all the time. People are a long way from understanding the way email works."

Spoofers can be anyone. Spammers earn money sending massive volumes of email. They can be competitors trying to cripple your business or disgruntled employees or irate customers out to "teach you a lesson." Attacks can be personally motivated or just random.

Fighting Spoof
What precautions should you, as marketers, take against spoofing? What if your next bounced email is from you and you never sent the message? Levine, Joffe, and Arbon gave me some suggestions:

Be aware spoofing is possible and can happen to you (most executives have never heard of the practice).

Be on the lookout. Tell your IT staff to look for bounces of mail not sent by your company and to keep an eye out for complaints. An early-warning system is critical. After the first complaint or two, you're bombarded and it's too late.

Have an auto-reply form letter ready explaining what happened and that it's faked. That way, you won't have to write one in the middle of a crisis situation. Have a plan of action. Remember that, in the event of a spoof attack, marketing and PR are the front lines of defense.

Make it known you'll prosecute. Have a dedicated email address posted on your site for reports: abuse@ or piracy@. (Software companies who have set up a reporting structure for pirated software have seen declines in the practice.)

Don't keep quiet - whatever you do. Your company needs to acknowledge the problem, explain it to the aggrieved parties, and mop up external damage (even if internally you've taken a big hit).

Spoofers create the problem. It's up to you to provide a solution for your business - and your brand.

Rebecca Lieb is executive editor of internet.com's eCommerce/marketing channel. She has held executive marketing and communications positions at strategic e-services consultancies, including Siegelgale. She worked in the same capacity for global entertainment and media companies including Universal Television & Networks Group (formerly USA Networks International) and Bertelsmann's German network, RTL Television. As a journalist, Rebecca has written on media for numerous publications, including The New York Times and The Wall Street Journal, and spent five years as Variety's German/Eastern European bureau chief.

Tools:
Add smallbusinesscomputing.com to your favorites
Add smallbusinesscomputing.com to your browser search box
IE 7 | Firefox 2.0 | Firefox 1.5.x
Receive news via our XML/RSS feed

eBook: Evaluating Software as a Service for Your Business. Sponsored by Webroot
Whitepaper: Maximizing Site Visitor Trust Using Extended Validation SSL
Learn Tools & Techniques to Justify and Fund Your IT Investments. Download Complimentary Report Now!
HP eBook: Using Business Service Management (BSM) to Manage Your Business Applications
IT in 2018: Download Free eBook By The Author Of "Does IT Matter?" Simple Registration Is Required.



JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: HyperV-The Killer Feature in WinServer ‘08
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Win Server ‘08
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES