Re: Spam sent from compromised (web)hosts vs botnet spam
Alessandro Vesely <[email protected]> Fri, 22 Mar 2013 11:21:36 +0100
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On Fri 22/Mar/2013 09:45:01 +0100 Paul Smith wrote: > On 22/03/2013 03:03, Dan Oetting wrote: >> After all that abuse you inflicted on my server, you have the gall >> to say that my little ICMP packet is abusing your network > > I agree with Dan here. > > One 'legal' option is to send a bounce message, or a message back to > 'abuse@<you>' (eg abuse@[1.2.3.4] or something more intelligent). No > one would complain about those, or say that is abuse, even though that > will use a lot more bandwidth and server load. That's well described in RFC 6650. (I'm trying to implement it --at bradypus pace, since nobody else seems to be interested: A web-based complaint shop to be outlined in the human-readable part of unsolicited ARF messages.) There are reporting alternatives which don't require bounce messages, e.g. using IODEF. Since there is the need to convey some trust in the data being reported, I wouldn't expect such processes to be surprisingly lightweight anyway. > Alternatively you could send an ICMP packet back. Unusual ICMP packets are more likely to get filtered off, though. > The only way I can come up with at the moment would be to > piggy-back on rDNS, which would almost certainly not be allowed. Looking up abuse mailboxes in RIR's databases might be an alternative to rDNS. Especially when rdap (http://rdap.org/) will be ready. - This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org