Re[2]: CBL Composite Blocking List problem

Paul Gleave <[email protected]> Tue, 20 Jul 2004 23:00:26 +0100
Newsgroups gmane.mail.spam.active-spam-killer.general
Organization Octonet Limited
Message-ID <[email protected]>
Marc,

Apologies if this is ground that has already been covered. I'm just
trying to work out what is causing my server to appear on the CBL, as
it isn't the result of a compromised PC.

What I am suggesting is that this could be happening in this case:

 1 - ASK intercepts a spam mail that purports to come from a total stranger

 2 - ASK issues the challenge back to the complete stranger, complete
 with a copy of most of the spam message.

 3 - The complete stranger happens to have some sort of Spamcop system
 that recognises the spam message for what it is and automatically
 reports the mail to the CBL system.

This could happen, couldn't it?

Paul




On Tuesday, 20 July 2004, Marc Herbert wrote:

> On Tue, 20 Jul 2004, Paul Gleave wrote:

>> So I'm beginning to wonder if the confirmation messages that ASK
>> sends out are being interpreted by someone somewhere as spam.  If
>> this is the case, then "Houston we have a problem".
>>
>> Anyone else got any thoughts on this?

> This is a frequent issue brought on this list / a frequent argument
> against ASK and other Challenge-Response systems (check the archive).
> Some people argue that, since you can never know for sure who sent the
> message, you should never send an automated reply. Please note that
> this apply not only to Challenge-Response systems like ASK but also to
> any "vacation" program, (stupid) virus warning, failed delivery error
> messages, etc. Consider the worst case (I guess it happened to many of
> us). Some spammer repeatedly forges its "From:" with your personal
> address. The forged address will then receive tons of "failed
> delivery" error messages, to be compared to at most 1-2 confirmation
> requests from ASK or similar...

> Yes there is something bad here, but I really think that ASK is the
> wrong target in this case. The real fix is to fix SMTP so that you can
> have some more or less trusted source address. Some people are working
> hard towards this: http://spf.pobox.com/ (I strongly suggest anyone
> interested by antispam efforts to check this URL).

> Back to ASK and you being blacklisted: if some guy received a couple
> of ASK confirmation requests, he surely had received at least 100
> spams and 30 "failed delivery" at the same time. Complaining only
> about ASK confirmation requests is a demonstration of bad faith... as
> said above: wrong target. Some people are irrationally angry at C-R
> systems, trying to fight what it's easy to fight instead of fighting
> the bulk.
> http://kmself.home.netcom.com/Rants/challenge-response.html


> Any decent blacklist system should publish the justification for every
> blacklisted domain. Could you find the one for your server ?


>> Also: Marco - the SBL seems like quite a good idea (as long as it
>> only traps the baddies) and it can be freely downloaded - have you
>> thought of integrating it into ASK?

> I don't think any other spam filter should be "integrated" into ASK. A
> more flexible and generally speaking better design IMHO is to "pipe"
> multiple filters, in the order the user wants.





-------------------------------------------------------
This SF.Net email is sponsored by BEA Weblogic Workshop
FREE Java Enterprise J2EE developer tools!
Get your free copy of BEA WebLogic Workshop 8.1 today.
http://ads.osdn.com/?ad_id=4721&alloc_id=10040&op=click