Re: Spam sent from compromised (web)hosts vs botnet spam

Paul Smith <[email protected]> Fri, 22 Mar 2013 08:45:01 +0000
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On 22/03/2013 03:03, Dan Oetting wrote:
> After all that abuse you inflicted on my server, you have the gall to 
> say that my little ICMP packet is abusing your network

I agree with Dan here.

One 'legal' option is to send a bounce message, or a message back to 
'abuse@<you>' (eg abuse@[1.2.3.4] or something more intelligent). No one 
would complain about those, or say that is abuse, even though that will 
use a lot more bandwidth and server load.

Alternatively you could send an ICMP packet back.

Seems to me that a little ICMP packet would 'abuse' a network much less 
than an email message... It would also be more useful as it can be 
monitored more easily at the gateway level rather that at the host level.

However, it would also make sense to have it be 'opt in', otherwise the 
ICMP packet will be ignored anyway (and does risk someone, somewhere 
taking offense). The problem is that I can't think of a good way to be 
able to 'opt in'. The only way I can come up with at the moment would be 
to piggy-back on rDNS, which would almost certainly not be allowed.



-

Paul Smith Computer Services
Tel: 01484 855800
Vat No: GB 685 6987 53
-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org