Re: RFC 6471 and "listing the Internet" as a punishment

Steve Atkins <[email protected]>
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On Jan 24, 2012, at 10:59 AM, David Romerstein wrote:

> On 1/24/12 1:50 PM, John R. Levine wrote:
>>> Listing the world for folks overloading your system is unlikely to have
>>> the effect that you want, and is most likely going to impact folks who
>>> have no say in the configuration of the receiving mail server.
>> 
>> You may be right, but I have to have some sympathy for BL operators who
>> are getting bombed by clueless misconfigurations.
> 
> I do not, in any way, disagree with this.
> 
> I'm just wondering if there's a middle ground that can stop BL operators from being abused by (willfully or unwillfully) clueless folks without severely impacting innocent users. Something more than "just sit back and take all those stupid queries" and less than "return a response code that could indicate a listing for every one of those stupid queries".

The innocent users are the people who are abusing the blacklist and those who send email to them. And most of them are using blacklist data for scoring, not for blocking. Listing the world doesn't usually affect them much at all.

There really isn't much of a middle ground. If you have non-broken software querying the blacklist then there aren't any problems - it'll shut down gracefully when the blacklist goes away. But if the software querying the blacklist doesn't do that (and almost everything deployed is broken in that way) then you really only have three options as a blacklist operator:

1. List nothing
2. List everything
3. List things at random

(1) leads to no change, you get to keep fielding bogus DNS requests until the end of time.
(2) causes immediate change at abusers who are using the blacklist to block email, and maximises the chance of someone using the data as part of a scoring based system noticing
(3) is worse than either, as it will potentially cause some mail to be lost but is much less likely to cause people to stop using the list

This isn't a trivial problem, nor a trivial amount of traffic. In the past, I've had service overages of >$2000/mo due to massive DNSBL traffic to cbl.abuseat.com (which isn't a DNSBL, so returns "not listed" for every query).

I'm currently eating quite amazing amounts of misconfigured CBL lookup traffic (hundreds of different ways to misspell cbl.abuseat.org) - and configuring my zones to list everything still doesn't stop the traffic. I've played with long TTL delegations to non-routable addresses and suchlike, and it doesn't have much effect either. At some point I'll probably start running a "stunt" server rather than powerdns for that zone, and be more creative with how I handle the abusive queries.

Cheers,
  Steve
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.