U.S. gov't e-mail server turns into spam cannon

October 4, 2007, 09:03 AM —  IDG News Service — 

Subscribers to a U.S. Department of Homeland Security daily e-mail bulletin were inundated with dozens of e-mails on Wednesday due to a glitch with the mailing list.

The gaffe started after one man, Alex Greene, a manager at GKN Freight Services Inc., sent a reply to the Daily Open Source Infrastructure Report, a round-up of security-related news reports, to change his subscription information.

The e-mail server sent Greene's reply to everyone on the DHS's subscriber list, which sent off a torrent of responses from recipients -- some humorous, some irritable -- which in turn were fired out again to all subscribers, according to the SANS Institute, a computer security monitoring organization. The cause of the problem was likely an erroneous change in the e-mail server's settings.

The error could cause big trouble if a hacker sent a bad e-mail attachment with a zero-day security vulnerability "to nail a few dozen gullible security professionals," Marcus Sachs wrote in the SANS diary, which documents security incidents.

"If you maintain a broadcast mailing list, make sure that the address will not reflect e-mail from sources other than the owner of the list," Sachs wrote. "Otherwise, you will become a training example for SANS."

Excerpts of some of the e-mails were published by The New York Times.

"Dear Mr. Alex Greene (the guy who started this mess). May the fleas of a thousand camels infest your armpits and may a yak in heat make love to your shin," wrote Michael B. Smith.

Others were more lighthearted and opportunistic about the mistake. "Well as long as we have a free for all going here, I'm job hunting," wrote Lt. Col. Mary Brown, a U.S. Air Force Reserve officer. "Anybody have anything open out there?

IDG News Service

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Free stuff

Win an Amazon Kindle!
This month's giveaway gadget - Amazon's Kindle - will keep you entertained on the long trip home to visit family and friends over the holidays. Enter the drawing now!

Applied Security Visualization
By Raffael Marty
Published by Addison-Wesley Professional
Learn more!

 

IT Manager's Handbook
By Bill Holtsnider and Brian D. Jaffe
Published by Morgan Kaufmann
Learn more!

 

Windows Vista Resource Kit
By Mitch Tulloch, Tony Northrup, and Jerry Honeycutt
Published by Microsoft Press
Learn more!

Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

More Resources