Re: RE: [SPAM] - Re: [DSBL-Contact] Website link for 24.249.105.34 - Found word(s) to be removed list error remove list in the Text body
"Alexey Lobanov (dsbl)" <[email protected]> Fri, 08 Dec 2006 19:49:03 +0300
| Newsgroups | gmane.mail.spam.dsbl.admin |
|---|---|
| Organization | DSBL volunteer |
| Message-ID | <[email protected]> |
Hello. On 08/12/06 19:19, Andrew Bustraan wrote: > Thanks for the prompt reply. > > Ironically, my "buggy filtering logic" allowed your email to reach me > even though it found the same words in the email you sent back to me. So, this logis is non-deterministic a bit. Or we (both you and me) do not know the rules in details. I myself like non-deterministic computer behavior in shooters but definitely do not want to see it in any regular business applications. > > Very true that my postmaster and abuse accounts aren't end-users, my > postmaster and abuse email accounts are additional SMTP proxy addresses > in my user account. They are not users at all. Yes. Same configuration is used in vast majority of Internet mail systems: "postmaster" is a role alias routed sometimes to one or more real mailboxes, sometimes to a shared folder. In ISP systems this shared folder may be read-only: all mail for Postmaster is stored for a long time, nothing can be deleted manually by Postmaster team members. > > As per Microsoft To my knowledge, noone (except MS marketing team) says that Microsoft makes good Internet mail servers. Yes, they really do a very powerful corporate collaboration suite. > > To designate a specific user's mailbox as the postmaster mailbox for any > local SMTP domain that is created, you can manually add the proxy > postmaster@localdomainname to the user's list of SMTP proxy addresses. I wonder if this logic is the _only_ possible? Modern computer systems are flexible enough, and same task can be normally done by many methods. I.e., in my corporate mail system I can define "postmaster" in global /etc/aliases to route it to a specific path at the very first stage of processing, or create "mailAlternateAddress" attributes for arbitrary users in LDAP to catch this address at final stage (same as you do). > > I had several people from outside of our domain send me test messages to > both the postmaster, and abuse email addresses and was able to receive > those email, which I did before my second removal request on December > 6th. It seems to be a yet another illustration of "asymmetry" in bug hunting. A single failed test proves the presence of a bug, even many tests do not prove the absence until you know the program internals and can audit it. Unfortunately, you knew (or had to know) about the illogical filtering policy inside of your system, but you have ignored this knowledge - as far as we can see. Alexey > > Thanks again for the prompt reply. > > Andrew Bustraan > Network Coordinator > Law/Kingdon, Inc. > 345 Riverview Suite 200 > Wichita, KS 67203 > PH: 316-268-0230 > FX: 316-268-0205 > > > -----Original Message----- > From: Alexey Lobanov (dsbl) [mailto:[email protected]] > Sent: Friday, December 08, 2006 9:45 AM > To: Andrew Bustraan > Cc: [email protected] > Subject: [SPAM] - Re: [DSBL-Contact] Website link for 24.249.105.34 - > Found word(s) to be removed list error remove list in the Text body > > Hello. > > On 08/12/06 18:18, Andrew Bustraan wrote: > >> Thank you for your reply. >> >> There is nothing accountable for trying to alleviate my end users of > the >> barrage of spam inundating the Internet daily. > > For sure. But DSBL does not test access to your end-users, and > Postmaster is not an end-user. > >> Because my Spam filtering >> program doesn't have a provision to circumvent filtering for a >> particular address or addresses > > I'm afraid, it is your problem. > >> is not justification to be hampered by >> anyone's list. > > It is a real logical bug in the software choosen by you. Or, better say, > the absence of vital control function. If you prefer to use handicapped > software, you should be responsible for all adverse effects (IMHO). > >> As far as recipients needing to add us to their white lists, yes they >> can do that, but since we deal with a number of new people every day >> that is not only impractical but unnecessary since our server is no >> longer an open relay and should not be on "any" restrictive lists. > > The problem is that now we do not know if your server is an open relay > or not. Security is an asymmetric game: one simple test is enough to > prove the PRESENCE of a hole, but extensive internal audit is necessary > to prove the ABSENCE. We trust your words; all you need is to prove that > you are able to perform such audit when you receive spam or abuse > complaints to a standard role address. Instead, you are proving > effectively that you are unable to receive real spam complaints, just > because your uncontrolled filtering system will predictably kill them as > "spam". Yes, spam and virus complaints may and should contain the > evidences inside. > > So, the only practical proposal is to fix your buggy filtering logic. > Your system should not check contents of any mail for > <[email protected]> and <[email protected]>, because you > must be able to receive real evidences of spam and malware activity > related to your system. > > Alexey > > >> Thanks again for your response, and insight. >> >> Andrew Bustraan >> Network Coordinator >> Law/Kingdon, Inc. >> 345 Riverview Suite 200 >> Wichita, KS 67203 >> PH: 316-268-0230 >> FX: 316-268-0205 >> >> -----Original Message----- >> From: Alexey Lobanov (dsbl) [mailto:[email protected]] >> Sent: Friday, December 08, 2006 9:00 AM >> To: Andrew Bustraan >> Cc: [email protected] >> Subject: [SPAM] - Re: [DSBL-Contact] Website link for 24.249.105.34 - >> Found word(s) to be removed list error remove list in the Text body >> >> Hello. >> >> On 07/12/06 17:38, Andrew Bustraan wrote: >> >>> In a continued effort to be removed from this black list, I was able >>> to determine that the email address that should be added to >>> everyone's whitelist process is [email protected]. I managed to find >>> the following entry in my spam filtering log under keywords: >>> >>> >>> >>> "11/29/06 15:48:50","Anti-Spam Keyword >>> Checking","[email protected]","[email protected]","Removal >>> Confirmation for 24.249.105.34","Deleted","Found word(s) remove list >>> in the Text body" >>> >>> >>> >>> I however could not find an entry for my resubmission yesterday. >>> >>> >>> >>> Nor could I find the email in any other logs, or mailboxes, spam >>> folders, or even when checking a mail monitoring program checking the >>> email at the door to see if it's being returned for bad address or >>> because of a relay attempt. >>> >>> >>> >>> Please help me get off your list. I have fixed my problems, and I am >>> not considered an open relay by any other blacklist services besides >>> yours. >> DSBL does not say that your host is an open relay now. >> >> Instead, DSBL says that your host is still unaccountable now, because >> you are unable to receive reports and alerts related to your server >> activity in Internet. And you are explaining above how you are making >> your system unaccountable. Intentionally, as far as I understand this >> evidence: >> >>> "11/29/06 15:48:50","Anti-Spam Keyword >>> Checking","[email protected]","[email protected]","Removal >>> Confirmation for 24.249.105.34","Deleted","Found word(s) remove list >>> in the Text body" >> All this is enough for DSBL users to deny mail from your >> "send-only" system which operates out of proper human control. >> >>> Yours is hampering my companies' ability to conduct business. >> Please address this issue to your business partners who agree DSBL >> criteria and do not want to receive mail from your system. It is quite >> possible that they will whitelist your system as a legitimate mail >> source. >> >> Alexey >> DSBL volunteer >> >> >>> >>> Andrew Bustraan >>> >>> Network Coordinator >>> >>> Law/Kingdon, Inc. >>> >>> 345 Riverview Suite 200 >>> >>> Wichita, KS 67203 >>> >>> PH: 316-268-0230 >>> >>> FX: 316-268-0205 >>> >>> >>> >>> >>> This email is confidential and may contain privileged information >>> intended only for the person(s) or entity to whom it is addressed. If >>> the reader of this message is not the intended recipient, you are >>> hereby notified that you have received this message in error and that >>> any review, dissemination, use, distribution, copying and/or >>> disclosure in parts or whole of this email and/or the attachments in >>> any form by any means is strictly prohibited. If you have received >>> this email in error, please notify Andrew Bustraan by a reply email >>> or call (316) 268 0230 and remove this email and all related material >>> from your digital infra structure. >>> >>> >