Re: Spam sent from compromised (web)hosts vs botnet spam

Dave Warren <[email protected]> Fri, 22 Mar 2013 01:46:40 -0700
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On 2013-03-21 18:32, Chris Lewis wrote:
> On 13-03-21 04:41 PM, Dave Warren wrote
>> If we wanted to get serious about this type of implementation, an SMTP
>> extension could do the trick.
> What do you think the odds are that spammers will implement anything
> like that in their bot cannons?
>
> IOW: the SMTP tools establishing the SMTP connection to the recipient's
> MTAs are owned and implemented by the spammers in probably more than 90%
> of all spam.
>
> They have no incentive to provide you with a workable complaint channel.
>
> If you wanted to announce it, you'd have to announce in a way that was
> keyed off IP address/allocations, _not_ something inband with the spam.
>
> Kinda like rDNS ;-)

Agreed.

I guess I wasn't thinking about direct-to-MX botnet spam, but rather, 
compromised webhosts where the script being abused is not under the 
control of the spammer directly, but instead is a contact-me or 
forward-this-article script with a bug that the spammer can exploit.

In this situation, my outbound SMTP is still involved, and I'd 
appreciate the abuse reports. For direct-to-MX, then something out of 
band is obviously a better solution.

-- 
Dave Warren
http://www.hireahit.com/
http://ca.linkedin.com/in/davejwarren

-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org