Re: blacklist headaches -> SMTP flaw
Marc Herbert <[email protected]> Fri, 6 Jan 2006 10:32:07 +0100 (CET)
| Newsgroups | gmane.mail.spam.active-spam-killer.general |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 5 Jan 2006, Stephen Byrne wrote: > I do not use Active Spam Killer, but it has caused me much headache. > > Somebody sent a spam to somebody else using my domain in From:. > Active Spam Killer then sent an email to my mail server to an > account that doesn't exist asking for a reply, I presume without > doing any reverse dns checks to see if it would be reasonable to ask > for a reply from my domain. Upon receiving no reply, several ASK > users have added my domian to a blacklist. The spammer keeps sending > mail pretending to be from my domain. ASK, rightly so, does not > deliver it. But at this point, ASK adds to the problem of useless > internet traffic by sending more emails to my mailserver. Each one, > being for an invalid user, prompts my mail server to send an error > back, rightly so. ASK then sends ANOTHER nasty-gram. And my mail > server, rightly so, sends an error because the user is still not a > valid user (surprise!). And ANOTHER nasy-gram comes. Et cetera, et > cetera, et cetera; wasting my resources and the ASK user's > resources, and leaving the spammer to happily send more spam, > unecumbered. - the blacklist "feature" has been _removed_ from recent versions of ASK. Check the archives of this list. - ASK has a limitation scheme to the number of challenges if sends to any given address (I find the default settings for this too low and I have increased them in my install) It should not be so easy to fake the source (return-path) of a message, this is the fundamental flaw of SMTP, what really helps spammers A LOT, and the root cause of the problems you are experiencing. ASK is just a way to demonstrate this ID issue, *among others*. A couple of months ago one spammer decided to use one of my adressses in its From:, so I received tons of "mail undelivered" notices, one for each obsolete address in his spam database. No ASK or similar system was involved here! SPF for instance <http://www.openspf.org/> tries to tackle this; I don't know how far its deployment has gone. The vicious/virtuous circle with all such identification systems is that people have an real incentive to adopt them ONLY once a significant fraction already has. Cheers, Marc. ------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Do you grep through log files for problems? Stop! Download the new AJAX search engine that makes searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! http://ads.osdn.com/?ad_id=7637&alloc_id=16865&op=click