, , ,

“Normal” websites are being hijacked to overload victims with spam

Hackers have found a creative new way to distribute spam by abusing the infrastructure of legitimate websites. Since the crooks don’t technically take over the website, and it continues to operate as intended, spam filters are having a hard time blocking these emails. As a result, the campaigns are more successful in reaching people’s inboxes.

The good news is that the emails are blatant spam, and unless the recipients click on the links without even reading the contents of the email, they should be able to spot the fraud immediately.

The new campaign was spotted by cybersecurity researchers from Cisco Talos, who explained in a technical write-up how the trick is in abusing sign-up and registration services. Many websites allow users to register a new account, and once that happens, the website will send an email to the address associated with the newly generated account.

No validation

The attack works by overloading the name field with text and a link. Since the site does not validate, or sanitize, this content in any way, it returns to the victim in the post-registration email, unfiltered. The worst part is – there’s no defending against it:

“Unfortunately for defenders, there is very little we can do to defend against such spam messages,” Cisco Talos said. “Most of the emails sent by these contact forms are legitimate, so the malicious email blends in with the otherwise legitimate traffic.”

But the good news is that the emails sent like this are easy to spot. They still look, and read, like your usual post-signup email, albeit with somewhat modified content. That should make it clear to any recipient that the site is being abused and that the email should be deleted on the spot.

More from TechRadar Pro

https://www.techradar.com/pro/security/normal-websites-are-being-hijacked-to-overload-victims-with-spam


Leave a Reply

Your email address will not be published. Required fields are marked *

Featured Posts

September 2024
M T W T F S S
 1
2345678
9101112131415
16171819202122
23242526272829
30  

About Us

Welcome to encircle News! We are a cutting-edge technology news company that is dedicated to bringing you the latest and greatest in everything tech. From automobiles to drones, software to hardware, we’ve got you covered.

At encircle News, we believe that technology is more than just a tool, it’s a way of life. And we’re here to help you stay on top of all the latest trends and developments in this ever-evolving field. We know that technology is constantly changing, and that can be overwhelming, but we’re here to make it easy for you to keep up.

We’re a team of tech enthusiasts who are passionate about everything tech and love to share our knowledge with others. We believe that technology should be accessible to everyone, and we’re here to make sure it is. Our mission is to provide you with fun, engaging, and informative content that helps you to understand and embrace the latest technologies.

From the newest cars on the road to the latest drones taking to the skies, we’ve got you covered. We also dive deep into the world of software and hardware, bringing you the latest updates on everything from operating systems to processors.

So whether you’re a tech enthusiast, a business professional, or just someone who wants to stay up-to-date on the latest advancements in technology, encircle News is the place for you. Join us on this exciting journey and be a part of shaping the future.

Podcasts

TWiT 999: Bananas and Browsers – CA AI Bill Veto, Meta's Orion, FTC Vs. Fake Reviews This Week in Tech (Audio)

CA AI Bill Veto, Meta's Orion, FTC Vs. Fake Reviews Sam Altman's AI Manifesto News from Meta Connect Gavin Newsom vetoes sweeping AI safety bill, siding with Silicon Valley The Panel discusses CoPilot The Panel debates AGI James Cameron Joins Board of Stability AI in Coup for Tech Firm SAG-AFTRA Calls Strike Against 'League of Legends' Rabbit says only 5,000 people use the R1 daily Orion: True AR Glasses Have Arrived AI smackdown: How a new FTC ruling just protected the free press DoNotPay has to pay $193K for falsely touting untested AI lawyer, FTC says Firefox Review Checker – Ensure review authenticity in your online shopping New California law requires one-click subscription cancellations The DOJ sues Visa for locking out rival payment platforms NIST proposes barring some of the most nonsensical password rules Some Mad Genius Put ChatGPT on a TI-84 Graphing Calculator 23andMe troubles, company recently settled data insecurity suit for $30 mil Host: Leo Laporte Guests: Denise Howell, Parmy Olson, Daniel Rubino, and Henry Laporte Download or subscribe to this show at https://twit.tv/shows/this-week-in-tech Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: lookout.com 1password.com/twit shopify.com/twit veeam.com flashpoint.io
  1. TWiT 999: Bananas and Browsers – CA AI Bill Veto, Meta's Orion, FTC Vs. Fake Reviews
  2. TWiT 998: Artisanal Locally-Sourced Dopamine – Amazon Returns to Office, CA AI Bill, Elon Backs Down
  3. TWiT 997: Put an OLED on it – iPhone Event 2024, $700 PS5, AI in AU
  4. TWiT 996: The Quiet Office Crackdown – Starlink Backtracks, AI Royalty Heist
  5. TWiT 995: The Story of Us – AnandTech Shuts Down, Brazil Bans X, Alexa Revamp