Re: Spam sent from compromised (web)hosts vs botnet spam
Paul Smith <[email protected]> Fri, 22 Mar 2013 11:13:02 +0000
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On 22/03/2013 10:21, Alessandro Vesely wrote: >> Alternatively you could send an ICMP packet back. > Unusual ICMP packets are more likely to get filtered off, though. As long as they are filtered at the receiving gateways (not en-route) then that should be OK. AIUI the point was to give hosting companies the ability to see that one of their hosts is possibly spamming (either because it's been compromised, leased by spammers, or whatever). If they don't want to check that, they can filter the ICMP. If they do want to check it, they can set alerts on the ICMP, or do whatever they want. If they are getting the feedback it's up to them what to do with it. If they aren't getting the feedback they can't do anything. Using well defined ICMP packet types should stop them being filtered off en-route, I'd have thought. >> The only way I can come up with at the moment would be to >> piggy-back on rDNS, which would almost certainly not be allowed. > Looking up abuse mailboxes in RIR's databases might be an alternative > to rDNS. Especially when rdap (http://rdap.org/) will be ready. > Yes, if that can be automated. What I'd see as being really useful is just a way for a receiving MTA to automatically send back an alert of some sort - 'I've just got something I think is spammy from one of your IP addresses', with no manual intervention involved. The hosting company will probably get zillions of these, but they can look at patterns. If they have just leased out a new server, and the next day they get 4 billion 'spam alerts' for that IP address, they can take a look, but if it gets a few hundred a day it's probably OK (false positives). ISPs could also use this to check for compromised home user PCs, and possibly block outgoing port 25 on those. There's the risk of DDoS attacks (lots of bots sending 'spam alerts' about an innocent IP address), but as long as the alerts don't cause automatic shutdown of services, then it should be OK. It just seems to me that an automated system at both ends would work better than the manual one we have now. ICMP, UDP, or a standard format email, periodic HTTP posted reports or whatever would all be fine, as long as it can be automatically generated, and automatically monitored. (not to replace abuse@<domain>, but to supplement it). If it was something with more 'payload' than ICMP (UDP, email, etc), it could possibly be extended to other types of abuse alert (port scans, login attacks, etc) I'm coming at this from the angle of a defender, and small hosting provider, but the question really is, would enough large hosting providers/ISPs find this type of information useful, or would they just ignore it. - Paul Smith Computer Services Tel: 01484 855800 Vat No: GB 685 6987 53 - This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org