Quantcast
PCWorld.com is upgrading some back-end systems. Some site features, such as user registration, may be temporarily unavailable.

Blogs

    Consumer Watch

  • Contributing Editor Anne Kandra helps you avoid the gotchas and pitfalls of buying and using technology products.
  • Subscribe to this blog

Consumer Watch: Are You Helping a Spammer?

Anne Kandra

Proxy Danger

Proxies are most often found in academic networks or in a home or small-office system with a broadband connection. Proxy software allows PCs within a network to share an Internet connection and be recognized with the same IP address. Open proxies, though, will accept and process requests from users outside the network they serve--putting out the welcome mat for spammers who want to hide their true IP address.

If you use Windows Internet Connection Sharing, or if you share your broadband connection via a standard gateway from a company such as D-Link or Netgear, you probably have no cause for concern. Open proxies generally result from having a proxy application, such as AnalogX Proxy, that has not been properly configured. Unless you are an experienced network administrator, it isn't always clear how to secure such software so that it will allow connections only from local network users.

Spammers don't need to be particularly savvy to find open relays and proxies: Plenty of readily available scanners and automated applications do nothing but scour the Web looking for openings. These tools enable a spammer to effortlessly get all the information necessary to infiltrate someone's machine.

As if that were not enough, however, some spammers now gain access to PCs by duping users into installing virus-laden applications through peer-to-peer file-sharing sites such as Kazaa. These viruses can install open proxies on otherwise secure systems and set up e-mail generators that surreptitiously exploit the victim's resources to foist a steady stream of spam on other people.

Most users learn that their systems have been invaded only if their ISP traces the spam back to their computer and notifies them. EarthLink's Arnold says most hijack victims are surprised to hear that they've been targeted, but readily cooperate to close security holes.

In an effort to tighten security, some ISPs, such as the broadband provider Road Runner, routinely do probes of subscribers' connections, attempting to identify network holes and vulnerabilities. While you probably don't need to fret about Road Runner techies getting access to your personal information via a probe, there's something unnerving about the idea of your ISP actively trying to find a way into your hard drive--even in the name of keeping the troublemakers out.

Probes, whether they're from the good guys or the bad guys, won't be a problem if you make certain your system is secure. Suppose you have a home office with DSL or cable modem broadband access and a wireless network. You use spam filters, regularly update your virus protection software, and even have a firewall to protect your network. Does that mean you're safe from spammers and their nefarious deeds? Not necessarily, according to Arnold. "Home network security is like a sieve, and there are a lot of infected computers out there. Spammers are constantly disguising their tools and rotating locations. In this Internet climate, you should always be vigilant."

Stay current with all available vendor security patches, especially for your operating system and browser; security experts say that you can avoid most network intrusions by installing updates when they become available. (For news on the latest security holes and patches, read Bugs and Fixes each month.)

As always, be extremely discerning about opening e-mail file attachments. If you use a file sharing application, you're playing with fire--be extra cautious when downloading files, and limit the directories you share. (See this month's Privacy Watch for tips on sharing files safely.)

And finally, if you're serving as your own network administrator and aren't sure about whether your security settings are sufficient, consult an expert. Web sites such as Mail Abuse Prevention System have tools to test your system for security glitches and offer advice on how to beef up your settings.

To learn more about controlling spam and protecting yourself against hijackers, visit the Coalition Against Unsolicited Commercial Email, Junkbusters, or spam.abuse.net. You'll be helping yourself--and maybe just about everyone else who has an e-mail in-box.

Anne Kandra is a contributing editor for PC World. E-mail her at consumerwatch@pcworld.com. Click here to view past Consumer Watch columns.
  • Recommend this story?
  • 0 Yes
    0 No
  • Great year-end deals for small business!
  • Get 24/7 live remote AT&T Tech Support 360* service along with select Lenovo* PCs (with Intel® Core™ 2 Duo processors and save up to 200!

    Learn more

  • HP EliteBook* 6930p Notebook with Intel® vPro™ technology and a free HP Basic Docking Station - $641 instant savings!

    Learn more

Learn more about the Windows Phone PCWorld Gift Guide

Focus on Personal Productivitysponsored by Microsoft

  • Personal Finance 2.0 These free and fee-based Web services not only aggregate data from your online bank accounts, they give you tools for managing your money.
  • High-Tech Travel Tips Plenty of stories provide advice for elite mobile professionals. But what about you, the unproductive traveler?

People who read this also read:

Consumer Watch

All PC World Blogs

  • 15 Minutes to a Secure Business Get the Secure in 15 toolkit starting with the "15 Minutes Month-at-a-Glance" calendar. McAfee will send you additional tools and tricks to stay protected around the clock.
  • A Buyer's Guide to Data Protection Implementing data protection products and processes can be daunting. Make the right decisions by exploring what is available and what makes sense for your organization. Use this simple guide to evaluate different vendor offerings.

Sponsored Links