dsbl.org SERIOUS problem
"Christopher Hill" <[email protected]>
| Newsgroups | gmane.mail.spam.spamcop.email |
|---|---|
| Organization | SpamCop |
| Message-ID | <[email protected]> |
BEWARE OF VISITING THE DSBL.ORG SITE. Don't follow the links to dsbl.org in this email until you've read the whole thing and understand the potential consequences! I noticed this morning that my cable modem's IP address was being blocked on dsbl.org. So I went and had a look at the dsbl.org listing for the IP and saw a range of requests to block my IP address http://dsbl.org/listing?81.103.11.204 For those who don't know, dsbl.org works by people sending a special message through any open proxies to [email protected]. Any IP addresses that send an email to this address are automatically added to the block list. So I was wondering why my IP address would have sent such an email to their account, as I am a fairly savvy user - no mail server, no web proxy, no spyware, and behind a hardware NAT firewall anyway. As I was investigating it, I noticed something very interesting. The list was getting longer as I was looking at the dsbl.org site - in real time. I realised that whatever or whoever was causing the listings was causing it *right now*. So I looked harder at the listings. Here is the first one: [quote] IP: 81.103.11.204 Input IP: 213.107.224.10 Transport: ftp-url Input Port: 80 Message Received: 2004/12/23 17:48:48 UTC Message Sent By: ian Extended Information for Transport: dsbl.org website hit Full Message: Subject: DSBL Submission To: [email protected] [endquote] The IP address is mine alright, and 213.107.224.10 is the address of ntlworld's transparent proxy servers (which I have to use for all port 80 traffic, as they're transparent). What confused me was the 'transport' which is ftp-url and the 'extended information' - dsbl.org website hit. So I fiddled around a bit more... but then I started to look at the date and time of each of the requests... ... and realised that they coincided *exactly* with *every* time I visited *any* part of the dsbl.org site. Oh dear. I tested this further and yes, indeed, every time I loaded a page from dsbl.org into Internet Explorer, a new request to block my IP address was added. At this point I started to get very, very slightly annoyed with the maintainers of dsbl.org. And yes, that is good old British understatement. I think someone has *seriously* goofed up here. Maybe they're testing something new on their web server, but if they are, they've seriously messed it up, and it seems that every request I make to their web site is resulting in the originating IP address being added to their list. I can confirm this because if you look at the listing, you'll see that there's one request for yesterday, and lots for today. Guess what I was doing yesterday at about 17:48:48 UTC? I happened to visit just the home page of the dsbl.org site. I hope people are beginning to understand how stupid and dangerous this behaviour is. Can anyone else confirm that it happens to them, or is it just me? If they can, I think there is a very serious case for removing dsbl.org from being used on SpamCop, and discouraging *anyone* else from using them again, *ever*. I don't know whether it's administrator incompetence or a hack attack, but whatever it is, if they're not competent enough to keep their systems secure or (even worse) to not let this sort of thing happen when they make changes, I for one don't trust them to block spam emails any more. Let us know how you get on. Regards, Chris -- 'Therefore, if anyone is in Christ, he is a new creation; the old has gone, the new has come!' - 2 Corinthians 5v17 [email protected]