Re: Spam sent from compromised (web)hosts vs botnet spam

Paul Smith <[email protected]> Fri, 22 Mar 2013 11:13:02 +0000
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On 22/03/2013 10:21, Alessandro Vesely wrote:
>> Alternatively you could send an ICMP packet back.
> Unusual ICMP packets are more likely to get filtered off, though.
As long as they are filtered at the receiving gateways (not en-route) 
then that should be OK.

AIUI the point was to give hosting companies the ability to see that one 
of their hosts is possibly spamming (either because it's been 
compromised, leased by spammers, or whatever).

If they don't want to check that, they can filter the ICMP. If they do 
want to check it, they can set alerts on the ICMP, or do whatever they 
want. If they are getting the feedback it's up to them what to do with 
it. If they aren't getting the feedback they can't do anything.

Using well defined ICMP packet types should stop them being filtered off 
en-route, I'd have thought.

>> The only way I can come up with at the moment would be to
>> piggy-back on rDNS, which would almost certainly not be allowed.
> Looking up abuse mailboxes in RIR's databases might be an alternative
> to rDNS.  Especially when rdap (http://rdap.org/) will be ready.
>
Yes, if that can be automated.

What I'd see as being really useful is just a way for a receiving MTA to 
automatically send back an alert of some sort - 'I've just got something 
I think is spammy from one of your IP addresses', with no manual 
intervention involved.

The hosting company will probably get zillions of these, but they can 
look at patterns. If they have just leased out a new server, and the 
next day they get 4 billion 'spam alerts' for that IP address, they can 
take a look, but if it gets a few hundred a day it's probably OK (false 
positives).

ISPs could also use this to check for compromised home user PCs, and 
possibly block outgoing port 25 on those.

There's the risk of DDoS attacks (lots of bots sending 'spam alerts' 
about an innocent IP address), but as long as the alerts don't cause 
automatic shutdown of services, then it should be OK.

It just seems to me that an automated system at both ends would work 
better than the manual one we have now. ICMP, UDP, or a standard format 
email, periodic HTTP posted reports or whatever would all be fine, as 
long as it can be automatically generated, and automatically monitored. 
(not to replace abuse@<domain>, but to supplement it).

If it was something with more 'payload' than ICMP (UDP, email, etc), it 
could possibly be extended to other types of abuse alert (port scans, 
login attacks, etc)

I'm coming at this from the angle of a defender, and small hosting 
provider, but the question really is, would enough large hosting 
providers/ISPs find this type of information useful, or would they just 
ignore it.



-

Paul Smith Computer Services
Tel: 01484 855800
Vat No: GB 685 6987 53
-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org