Musings Home

The world through my looking glass.


  

Tuesday, April 26, 2005

abuse@comcast.net Is Run By Idiots

I noted today that I was receiving SPAM (again) in my mailbox. This wasn't the usual "We have a loan for you" or "I'm from another country and need you to" SPAM. This one was specifically selling Rolexes. Okay, so I was curious to see where it came from. I looked at the email header and found the following.

From RickieShafferohuds@city-codes.com Tue Apr 26 03:03:41 2005
Received: from sccrmxc15.comcast.net ([63.240.76.61])
by urth.org with esmtp (Exim 4.50)
id 1DQL2j-0002o5-Fx
for avinsen@urth.org; Tue, 26 Apr 2005 03:03:41 -0500
Received: from c-24-91-218-230.hsd1.ma.comcast.net ([24.91.218.230])
by sccrmxc15.comcast.net (sccrmxc15) with SMTP
id <20050426080308s15004nupfe>; Tue, 26 Apr 2005 08:03:09 +0000
X-Originating-IP: [24.91.218.230]
Received: from [96.164.32.96] by 24.91.218.230; Tue, 26 Apr 2005 03:51:54 -0500
Message-ID: <329042619033.512301875599811545887@sacramento>
From: "Olin Houston" <RickieShafferohuds@city-codes.com>
To: Kieth <ronbake@comcast.net>
Date: Tue, 26 Apr 2005 03:51:54 -0500
Subject: Re: fvhhg, It's time for the BIG one!
MIME-Version: 1.0
Content-Type: text/plain
Content-Transfer-Encoding: 7bit
Status: R

Specifically, the address c-24-91-218-230.hsd1.ma.comcast.net indicates that this email was sent from a Comcast customer's machine in Massachusetts.

So, "what's the big deal?" you may ask.

Well, having come from an ISP (4 years at Winternet), I know that this could easily be someone's compromised machine. This doesn't affect me that much, but if I was the admin at the ISP, I'd like to know about it, and I would have contacted the customer to let them know that they may have had a security breach of their PC.

I quickly composed an email to abuse@comcast.net and sent it via their webform to alert them to this.

The response I got was the following:

Dear Yuk Lau,

Thank you for your message.

I understand you have been receiving some unwanted e-mail messages, or spam. We do automatically filter out spam with the BrightMail product, however we cannot combat all spam. This feature is automatically activated upon the creation of your e-mail account. If you do not want any of the e-mail that is sent to you filtered, you can turn off the e-mail filtering by accessing the Service Center at www.comcast.net, or by clicking on the following link:

http://www.comcast.net/memberservices/index.jsp

If you are using the Comcast Mail Center and would like to report missed spam, place a check in front of the e-mail you want to report as spam and click the Report Checked As Spam button. If you are using a mail client like Outlook Express, you can follow the link I included below for instructions on how to forward the spam as an attachment to missed-spam@comcast.net

Yada yada yada.

In essence, this is a form email for people complaining about SPAM. I goes on to tell me how to setup mail filtering on various mail clients. It seems Comcast isn't interested.

So I sent a second email explaining what I was trying to do.

You misunderstand my meaning.

First, if you look at the header information I sent, you will note that the SPAM came from a Comcast IP address. This means that either a customer is sending SPAM, or their computer has been compromised and used by another party to send SPAM.

While I understand that Comcast is not responsible for everyone keeping their systems secure, I do know that it is within Comcast's interests to stem any breach of security where SPAM is originating from within your network.

Note, the email arrived at my personal email address outside of the Comcast network. This means that this issue is affecting your customers and the internet as a whole.

Hopefully you now understand the issue at hand and will take the approrpriate actions.

Their response:

To ensure your issue is handled correctly, please report any e-mail abuse activity by sending a detailed e-mail message to our Abuse Department at abuse@comcast.net. The Abuse Department will research this issue for you and take the necessary steps to ensure your safety. Include a copy of the e-mail itself and the header information in the body of the e-mail. Do not forward the e-mail to Abuse and send only one e-mail per issue, please.

At this point I realize (finally) that they don't really care. In fact, they don't really want to hear from me. If they did, they'd have taken the information I'd sent them (specifically the email headers) and would have done something with it. Instead, they have sent me form mail after form mail.

Well, I'm tired of their bad service, and I hope Minneapolis and St. Paul both start up their wireless internet connections soon.

Enough of me.

0 Comments:

Post a Comment

<< Home