Re: Spam sent from compromised (web)hosts vs botnet spam

Dan Oetting <[email protected]> Fri, 22 Mar 2013 10:15:02 -0600
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On Mar 22, 2013, at 9:59, Steve Atkins <[email protected]> wrote:

> 
> On Mar 22, 2013, at 8:55 AM, "John Levine" <[email protected]> wrote:
> 
>>> AIUI the point was to give hosting companies the ability to see that one 
>>> of their hosts is possibly spamming (either because it's been 
>>> compromised, leased by spammers, or whatever).
>> 
>> Sounds like we're reinventing feedback loops.  They work pretty well
>> where they exist, with the hardest part being to figure out where to
>> send the report for a random IP or signature.
> 
> And even that's not too difficult for opt-in FBLs, though the management
> can be tedious.
> 
> . o O (Still not "research")

But we're getting close. I floated the idea of using ICMP as a feedback mechanism and I intend to follow up on that. The next step is to start documenting the concept on the wiki (does everyone know about the wiki?). Then the default behavior of existing systems to these packets needs to be documented to identify if there are any potential damaging side effects. For this step I could definitely use some help from the group as the variety of systems I have access to is limited. I think we could call this "research" if data is actually collected and documented.

-- Dan Oetting
 -
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org