Re: Spam sent from compromised (web)hosts vs botnet spam
Dave Warren <[email protected]> Fri, 22 Mar 2013 01:46:40 -0700
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On 2013-03-21 18:32, Chris Lewis wrote: > On 13-03-21 04:41 PM, Dave Warren wrote >> If we wanted to get serious about this type of implementation, an SMTP >> extension could do the trick. > What do you think the odds are that spammers will implement anything > like that in their bot cannons? > > IOW: the SMTP tools establishing the SMTP connection to the recipient's > MTAs are owned and implemented by the spammers in probably more than 90% > of all spam. > > They have no incentive to provide you with a workable complaint channel. > > If you wanted to announce it, you'd have to announce in a way that was > keyed off IP address/allocations, _not_ something inband with the spam. > > Kinda like rDNS ;-) Agreed. I guess I wasn't thinking about direct-to-MX botnet spam, but rather, compromised webhosts where the script being abused is not under the control of the spammer directly, but instead is a contact-me or forward-this-article script with a bug that the spammer can exploit. In this situation, my outbound SMTP is still involved, and I'd appreciate the abuse reports. For direct-to-MX, then something out of band is obviously a better solution. -- Dave Warren http://www.hireahit.com/ http://ca.linkedin.com/in/davejwarren - This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org