The Send-Safe Case.
squidefender started as a small program to stop the abusing of one of our hosts
by the Send-Safe Bulkmail program, a program
which scans for open-proxies and use it to send spam. We should note that our
host could not be used to send spam but was put on this list of open-proxies as
a reprisal for shuting down the uplink of a spammer. Putting our host on that
list resulted in a Denial of Service attack on our host.
We want to make clear that we condem all attempts to send spam, with our
without using systems of others. We also want to point out that using the
systems of others to send spam is a criminal act. We strongly believe that
we must do anything within our power to stop those acts, hence we decided to
give away the squidefender program under the GPL.
That squidefender works can be concluded from the discusion below with the
send-safe developers after we send a complaint to them to demand removal of our
host from their list.
The first message
From: "Jasper O Waale ( PriceswaterhouseCoopers Ltd. )"
To: support@send-safe.com; techsupport@send-safe.com;
maillist@send-safe.com; exclaim@send-safe.com
Cc: avd@ogbus.com
Sent: Tuesday, January 14, 2003 7:24 AM
Subject: Please note that your software and you "proxy list" have tried
to our Proxy server as a open relay for bulk e-mail.
Please note that your software and you "proxy list" have tried to use
our Proxy server as a open relay for bulk e-mail.
Scanning for open ports on any system that not legally belong to you or
are under your supervision is a criminal act.
Kindly remove any xxx.xxx.xxx.xxx from your list.
Failure to do so in good time, will result in legal action on behalf of
PricewaterhouseCoopers to compensate for use of resources and time spent
on the matter. This also involves sending any relevant log files to
local law enforcement to start a criminal investigation.
Observe that PricewaterhouseCoopers Ltd, will also, at that point
take action to pursue any private person that might be holder of the
www.send-safe.com www.Winfiles32.com Domains or individual associated
with the hosting of the Domain or selling the send-safe software, and
any ISP that is providing the means to access the Domain or systems that
are used to facilitate any related function on any PwC Mail account or
computer system.
Regards
On behalf of PwC Cambodia
Jasper O Waale
DM,GTS MCPA
[snipped a send-safe proxy list.]
Their initial response
From: support@send-safe.com
To: "Jasper O Waale ( PricewaterhouseCoopers Ltd. Cambodia )"
Sent: Tuesday, January 14, 2003 X:XX PM
Subject: RE: Please note that your software and you "proxy list" have
tried to our Proxy server as a open relay for bulk e-mail.
This is illegal Send-Safe copy.
How did you receive this proxy list?
Any server IP?
From: "Jasper O Waale ( PricewaterhouseCoopers Ltd. Cambodia )"
To: support@send-safe.com
Sent: Tuesday, January 14, 2003 1:46 PM
Subject: RE: Please note that your software and you "proxy list" have
tried to our Proxy server as a open relay for bulk e-mail.
Dear ??????
I am not able to tell you how, or when just that the Proxy list was
obtained in the last 5 days from a IP located in the Canada,
On the matter of misuse of PwC GTS Staff time I still pending any action
from you or your company, may I point out that "good time" in this
matter is 48h,
I like to let you know that we currently hold a list of some 26 server
related IPs that is until we stopped collection and blocked all trafick
from your software and servers.
Regards
GTS indochina
From: support@send-safe.com
To: "Jasper O Waale ( PricewaterhouseCoopers Ltd. Cambodia )"
Sent: Tuesday, January 14, 2003 X:XX PM
Subject: RE: Please note that your software and you "proxy list" have
tried to our Proxy server as a open relay for bulk e-mail.
Our server located in Russia.
You got this list from another server - from illegal Send-Safe copy.
From: "Jasper O Waale ( PricewaterhouseCoopers Ltd. Cambodia )"
To: support@send-safe.com
Sent: Tuesday, January 14, 2003 3:04 PM
Subject: RE: Please note that your software and you "proxy
list" have tried to our Proxy server as a open relay for bulk e-mail.
Dear ????
Regard less of your server location the fact is that your software
generates a proxy list when running as demo, and this list is sent to
your server, and I guess used for selling ?
I guess that a illegal copy of your software works the same way as a
legal and therefore have access to you proxy server list
Let me know if you are willing to remove our proxy server from your
list, it will not work for you anyway, but it takes time and cost money
for us to send the proxy error html page and with the amounts of hits
from you guys 80000 pr. hour pr server it all add up...
Regards
Jasper O Waale
GTS Indochina
And a few months later they contact us.
From: support@send-safe.com
Sent: Thursday, April 24, 2003 22:18
To: Jasper O Waale ( PricewaterhouseCoopers Ltd. Cambodia )
Subject: Re: Please note that your software and you "proxy list" have
tried to our Proxy server as a open relay for bulk e-mail.
Hello
You still abuse our users.
Send me all your networks IP ranges to block it for scanning.
From: "Jasper O Waale ( PricewaterhouseCoopers Ltd. Cambodia )"
To: support@send-safe.com
Subject: RE: Please note that your software and you "proxy list" have
tried to our Proxy server as a open relay for bulk e-mail.
Date: Fri, 25 Apr 2003 08:51:29 +0700
Sorry your software are used by a number Of system to relay Spam, we
have now deployed A safeguard that will not only block you software But
also make sure that the uplink is informed About the activity.
I only see one use for you software and that is To misuse wrongly
configured proxy servers to relay Mail, clearly not in the interest of
any user on the Internet.
You software has the last 3 month been used to attack System that I am
direct or in-direct in control of In 4 dirrent countries, all with
different IP blocks
I will be happy to forward you the some 600 IP that The attacks was made
from, and even more happy Send you the cost of the attack this week on a
server In VN, that put our Indochina operations to a halt For some 6
hours.
Regards
Jasper O Waale
From: Send-Safe [mailto:support@send-safe.com]
Sent: Friday, April 25, 2003 12:06
To: Jasper O Waale ( PricewaterhouseCoopers Ltd. Cambodia )
Subject: Re: Please note that your software and you "proxy list" have
tried to our Proxy server as a open relay for bulk e-mail.
Send me your IPs
From: "Jasper O Waale ( PricewaterhouseCoopers Ltd. Cambodia )"
To: support@send-safe.com
Sent: Friday, April 25, 2003 2:24 PM
Subject: RE: Please note that your software and you "proxy list" have
tried to our Proxy server as a open relay for bulk e-mail.
203.144.0.0
203.162.0.0
203.189.0.0
202.47.0.0
From: send-safe [mailto:support@send-safe.com]
Sent: Friday, April 25, 2003 15:45
To: Jasper O Waale ( PricewaterhouseCoopers Ltd. Cambodia )
Subject: Re: Please note that your software and you "proxy list" have
tried to our Proxy server as a open relay for bulk e-mail.
I removed all proxies from these IP ranges from Send-Safe.
Please write me next time, not to users.
From: "Jasper O Waale ( PricewaterhouseCoopers Ltd. Cambodia )"
To: support@send-safe.com
Subject: RE: Please note that your software and you "proxy list" have
tried to our Proxy server as a open relay for bulk e-mail.
Date: Fri, 25 Apr 2003 16:13:41 +0700
I am sure that I tried some 3 mails before deploying
A anti Send-safe system, its btw Pub. Domain,
http://www.google.com/search?sourceid=navclient&q=Squidefender
I have never send or will send any mail direct to your "users" however I
and PriceswaterhouseCoopers Int. will support any future development of
tools that might be used to stop software designed to use other systems
to relay Spam mail.
You will only by not accessing any of my server be able to Prevent the
system from filing any complains.
I Trust that the matter is done, and do not expect Any future issues
related to Send-Safe or any software Developed by Send-safe, also by
this I void any financial Claims that might be related to you and your
company, However all records are stored, so any future issues Will be
compiled by a total cost related to any matters Found.
Regards
Jasper O Waale
|