Re: IM2000 RNASP -- identifying message stores to recipients

James Craig Burley <[email protected]> 11 Mar 2004 23:12:14 -0000
Newsgroups gmane.mail.im2000
Message-ID <[email protected]>
>Bruno Wolff III <[email protected]> wrote:
>> 
>> This would still invalid notifications previously sent out with the old
>> IP address. So they need to steal some more resources to send a new round
>> of notifications,
>
>... which are designed to be lightweight, and which don't involve a monetary
>cost, unlike registering a new domain.

But they still need to get ahold of a new IP address that isn't
already blacklisted.  Hijacking zombie machines is one way to do that
that is inexpensive to the spammer, even compared to buying a new
domain name.  It is *not*, however, inexpensive to the upstream
"owner" of that address, who will end up with a lower-value IP address
by virtue of having leased it out to a spammer (via an insecure
machine).

And...see below...

>> I don't think the innocent parties is a big problem as long as the block lists
>> get aged over something like weeks. Generally they either got hacked or
>> they are using dynamic IP addresses which shouldn't be used for a message
>> store. Occasionally spammers will get a static IP revoked and it will get
>> handed out to a new customer. Aging blocked IPs will take care of this
>> case.
>
>Too bad it doesn't work out this way.  In my experience, many of the DNSBLs
>add addresses to their lists and never remove them.  I've been bitten perhaps
>a hundred times in this fashion, where I can't send mail because my current
>address was added to some DNSBL years before I got it.

Do you think these IP addresses were added because spam was being sent
from spammer@[1.2.3.4], or because they were the source, *after*
domain name resolution for [email protected], of detected
spam?  I'm pretty sure it was the latter.

See, it probably doesn't matter whether IM2000 allows IP addresses in
place of domain names in message-store references.  And it probably
doesn't matter whether it *recommends* blacklisting based on domain
names...

...because people will do what they think is "best", and if they're
obnoxious enough to impose a *lifetime* ban on an IP address simply
because it was once a source of spam...

...then they'll *surely* choose to blacklist (post-resolution) IP
addresses instead of domain names, on the theory that any number of
domain names could point to the same IP address, *all* of which are
therefore a source of spam.  They'll do this even if the message-store
references consist only of domain names.

As I said in an earlier post: the IPv4 (and even IPv6) address space
is much, much smaller than the domain-name space (which is effectively
infinite).  So, despite the fact that domain names are typically
purchased *separately*, they are, on average, less expensive than IPv4
addresses, because the cost of the latter is bundled into Internet
access in the first place.

-- 
James Craig Burley
Software Craftsperson
<http://www.jcb-sc.com>