{"id":10593,"date":"2023-08-07T11:18:13","date_gmt":"2023-08-06T23:18:13","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=10593"},"modified":"2023-08-07T11:18:13","modified_gmt":"2023-08-06T23:18:13","slug":"avoiding-subscription-bombs","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=10593","title":{"rendered":"Avoiding Subscription Bombs"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row column_structure=&#8221;1_3,2_3&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;1_3&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_image src=&#8221;http:\/\/kinetics.co.nz\/wp-content\/uploads\/2023\/07\/SubscriptionBomb.jpg&#8221; title_text=&#8221;SubscriptionBomb&#8221; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][\/et_pb_image][\/et_pb_column][et_pb_column type=&#8221;2_3&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<h4>If 10,000 emails suddenly flooded your inbox, what would you do?<\/h4>\n<p>Suddenly any real messages will be lost in the blitz of spam that&#8217;s overloading your screen.\u00a0 It is hard enough to delete all those messages, let alone filter out the genuine ones from the flood.<\/p>\n<h2>This situation is called &#8220;subscription bombing&#8221;<\/h2>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.4&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.22.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p>We saw it for the first time a few weeks ago. It is a very targeted form of &#8220;DOS&#8221; (Denial of Service) attack.<\/p>\n<p>The perpetrator sets up a bunch of bots to sign their victim up to every mailing list on the internet!\u00a0 That means a tonne of &#8220;thank you for subscribing&#8221; emails, or &#8220;confirm your subscription&#8221; are unleashed.<\/p>\n<p>Often this means that poor person is overwhelmed, and the bad actor can take advantage of this to undertake another, more malicious attack while the victim is distracted.<\/p>\n<h4><strong style=\"font-size: 14px;\">How do you manage a bomb?<\/strong><\/h4>\n<p>Firstly, be less worried about the emails, and look for what else they are doing.\u00a0 Make sure it isn&#8217;t a distraction from a more severe attack.<strong><\/strong><\/p>\n<p>Turn up your spam filter, even at the cost of missing some genuine emails &#8211; an autoreply can help you manage the fallout of genuine senders.<\/p>\n<p>Use the Outlook mail filter options, which fortunately get smarter all the time, albeit they are not infallible.<\/p>\n<h4>Protect your own mailing list from being abused.<\/h4>\n<p class=\"text-base font-normal text-gray-800 leading-[24px] pt-[9px] pb-[2px]\" dir=\"ltr\"><span>One of the most effective approaches is to implement CAPTCHA on your signup forms. CAPTCHA, an acronym for &#8216;Completely Automated Public Turing test to tell Computers and Humans Apart&#8217;, is a feature that helps distinguish a human user from a computer, thus preventing automated subscription attacks.<\/span><\/p>\n<p class=\"text-base font-normal text-gray-800 leading-[24px] pt-[9px] pb-[2px]\" dir=\"ltr\"><span>Another approach involves using double opt-in for your email subscriptions. This means that after a user signs up for your service, they must confirm their subscription through an email sent to their address. This extra step effectively deters bots from successfully subscribing.<\/span><\/p>\n<h4 class=\"font-semibold text-gray-800 text-2xl leading-[36px] pt-[21px] pb-[2px] [&amp;_a]:underline-offset-[6px] [&amp;_.underline]:underline-offset-[6px]\" dir=\"ltr\"><span>Be Careful What You Click <\/span><\/h4>\n<p class=\"text-base font-normal text-gray-800 leading-[24px] pt-[9px] pb-[2px]\" dir=\"ltr\"><span>When you see an email asking you to confirm your subscription, be sure to check the source of the email and make sure that it&#8217;s coming from a legitimate source. Never click on suspicious links or attachments within emails, as they could contain malicious scripts that are used for subscription bombing attacks. <\/span><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If 10,000 emails suddenly flooded your inbox, what would you do? Suddenly any real messages will be lost in the blitz of spam that&#8217;s overloading your screen.\u00a0 It is hard enough to delete all those messages, let alone filter out the genuine ones from the flood. This situation is called &#8220;subscription bombing&#8221; &nbsp; &nbsp;We saw [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":10594,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4,5],"tags":[],"class_list":["post-10593","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-security"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/10593","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10593"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/10593\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10593"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10593"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10593"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}