McColo Information & McColo Links at HealthHaven.com
advertise
add site
services
publishers
database
health videos
Bookmark and Share

search wiki for    ?
web dir firms image gallery news pdf wiki shop video 
about
toolbar
stats
live show
health store
more stuff
JOIN/LOGIN
Effect of McColo takedown on spam volumes, from SpamCop.

McColo was a San Jose-based web hosting service provider.[1] In late 2008, the company was shut down by the two upstream providers, Global Crossing and Hurricane Electric, due to the fact that a significant amount of malware and botnets had been trafficking from the McColo servers.[1]

[edit] Malware traffic

At the time of termination of its upstream service on November 11, 2008, it was estimated that McColo customers were responsible for a substantial proportion of all email spam then flowing[2] and subsequent reports claim a two-thirds or greater reduction in global spam volume.[3] This reduction had been sustained for some period after the takedown.[4] McColo was one of the leading players in the so-called "bulletproof hosting" market — ISPs that will allow servers to remain online regardless of complaints.

According to Ars Technica and other sources, upstream ISPs Global Crossing and Hurricane Electric terminated service when contacted by Brian Krebs and The Washington Post’s Security Fix blog,[5][6] but multiple reports had been published by organisations including SecureWorks, FireEye and ThreatExpert, all naming McColo as the host for much of the world's botnet traffic.[7][8][9][10] According to Joe Stewart, director of malware research for SecureWorks, the Mega-D, Srizbi, Pushdo, Rustock and Warezov botnets all hosted their master servers at McColo; numerous complaints had been made but McColo simply moved offending servers and sites to different subnets. Spamhaus.org reportedly finds roughly 1.5 million computers infected with either Srizbi or Rustock sending spam in an average week.

Following the shutdown, details began to emerge of the ISP's other clients, which included distributors and vendors of child pornography and other criminal enterprises, including the notorious Russian Business Network.[11]

McColo gained reconnection briefly on 19 November 2008 via a backup connection agreement common in the industry, but was rapidly shut down again.[12]

The McColo takedown especially affected Srizbi, the world's largest botnet, with around 500,000 infected nodes as of November 2008.[13] The botnet is reported to be capable of sending around 60 billion spam messages a day, which is more than half of the global total of 100 billion.[14]

Symantec's monthly state of spam report for April 2009, stated that spamming was now back to what it was before McColo was taken offline. Thanks to botnets being created and old ones being brought back online, it estimated that about 85 percent of all email traffic is spam. [15][16]

[edit] External links

[edit] References




Product Results (view all...)

search wiki for    ?
web dir firms image gallery news pdf wiki shop video 



↑ top of page ↑about thumbshots