Re: IM2000 RNASP -- identifying message stores to recipients
James Craig Burley <[email protected]> 11 Mar 2004 23:12:14 -0000
| Newsgroups | gmane.mail.im2000 |
|---|---|
| Message-ID | <[email protected]> |
>Bruno Wolff III <[email protected]> wrote: >> >> This would still invalid notifications previously sent out with the old >> IP address. So they need to steal some more resources to send a new round >> of notifications, > >... which are designed to be lightweight, and which don't involve a monetary >cost, unlike registering a new domain. But they still need to get ahold of a new IP address that isn't already blacklisted. Hijacking zombie machines is one way to do that that is inexpensive to the spammer, even compared to buying a new domain name. It is *not*, however, inexpensive to the upstream "owner" of that address, who will end up with a lower-value IP address by virtue of having leased it out to a spammer (via an insecure machine). And...see below... >> I don't think the innocent parties is a big problem as long as the block lists >> get aged over something like weeks. Generally they either got hacked or >> they are using dynamic IP addresses which shouldn't be used for a message >> store. Occasionally spammers will get a static IP revoked and it will get >> handed out to a new customer. Aging blocked IPs will take care of this >> case. > >Too bad it doesn't work out this way. In my experience, many of the DNSBLs >add addresses to their lists and never remove them. I've been bitten perhaps >a hundred times in this fashion, where I can't send mail because my current >address was added to some DNSBL years before I got it. Do you think these IP addresses were added because spam was being sent from spammer@[1.2.3.4], or because they were the source, *after* domain name resolution for [email protected], of detected spam? I'm pretty sure it was the latter. See, it probably doesn't matter whether IM2000 allows IP addresses in place of domain names in message-store references. And it probably doesn't matter whether it *recommends* blacklisting based on domain names... ...because people will do what they think is "best", and if they're obnoxious enough to impose a *lifetime* ban on an IP address simply because it was once a source of spam... ...then they'll *surely* choose to blacklist (post-resolution) IP addresses instead of domain names, on the theory that any number of domain names could point to the same IP address, *all* of which are therefore a source of spam. They'll do this even if the message-store references consist only of domain names. As I said in an earlier post: the IPv4 (and even IPv6) address space is much, much smaller than the domain-name space (which is effectively infinite). So, despite the fact that domain names are typically purchased *separately*, they are, on average, less expensive than IPv4 addresses, because the cost of the latter is bundled into Internet access in the first place. -- James Craig Burley Software Craftsperson <http://www.jcb-sc.com>