Re: Spam sent from compromised (web)hosts vs botnet spam

Dan Oetting <[email protected]> Thu, 21 Mar 2013 21:03:53 -0600
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On Mar 21, 2013, at 19:59, Chris Lewis <[email protected]> wrote:

> On 13-03-21 07:55 PM, Dan Oetting wrote:
> 
>> The abuse packet I was suggesting is an ICMP sent in response to a received packet. Rules for handling ICMP packets are well known, the ruled specifically forbid sending an ICMP in response to an ICMP, the ICMP contains the details of the abusive packet in a format that is well known, you have already opted it to receive ICMP packets by sending the packet which the ICMP Is responding to and unless you specifically look for the ICMP packets you aren't going to see them.
> 
> We have to be careful about implying shrink-wrap permission based around
> standards that don't exist yet, when ICMP floods just might trigger IDS
> and set off IRT.

Sorry, I wasn't aware that RFC 792 didn't exist yet.

When you send a packet out into the Internet, you have to expect any number of errors can cause an ICMP packet to return. That's what you signed up for when you installed the IP stack. To claim that this is going to cause your network to go into meltdown is simply rediculous.

If you are flooding the Internet with spam, you might get a flood of ICMP packets back if EVERYBODY adopted this protocol. More likely you would get only a very small trickle.

Let's examine the worst case under the scenario I started with: You have initiated an SMTP connection to my server, you go through the hello phase, you negotiate options, you send a mail from and then start sending rcpt to's At some point after all that, I decide that you are spammy and I don't want your junk. Furthermore, I want to pin a note on you and send you back home where your mommy who if she is a good mommy will see the note when you come in through the front door. 

After all that abuse you inflicted on my server, you have the gall to say that my little ICMP packet is abusing your network.

-- Dan Oetting


-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org