[Tfug] Odd new spam relay method

Adrian choprboy at dakotacom.net
Fri Nov 28 11:40:45 MST 2014


Can't find any info on this method being seen before... this is definitely a new 
one on me. I just ran across a compromised Untangle firewall/filter being used 
to send out spam. Expect the compromised host is not sending the spam 
directly. Instead it is spooling the spam message and sending out a quarantine 
message for the recipient to pickup the message via URL. The actual third-
party recipient box resides on the compromised host. Anyone seen this before?


Adrian




More information about the tfug mailing list