Re: Spam sent from compromised (web)hosts vs botnet spam
Chris Lewis <[email protected]> Thu, 21 Mar 2013 21:59:40 -0400
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On 13-03-21 07:55 PM, Dan Oetting wrote: > So you were flooding RFG with spam. You should be glad he didn't send a swat team out to deal with it. :) That would have been hilarious. Swat team vs. multi-building high tech campus with 5000+ employees. It wouldn't have been the first time. I wouldn't have wanted to be RFG afterwards tho... > The abuse packet I was suggesting is an ICMP sent in response to a received packet. Rules for handling ICMP packets are well known, the ruled specifically forbid sending an ICMP in response to an ICMP, the ICMP contains the details of the abusive packet in a format that is well known, you have already opted it to receive ICMP packets by sending the packet which the ICMP Is responding to and unless you specifically look for the ICMP packets you aren't going to see them. We have to be careful about implying shrink-wrap permission based around standards that don't exist yet, when ICMP floods just might trigger IDS and set off IRT. - This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org