Re: dsbl.org SERIOUS problem

"Christopher Hill" <[email protected]>
Newsgroups gmane.mail.spam.spamcop.email
Organization SpamCop
Message-ID <[email protected]>
>> So I went and had a look at the dsbl.org listing for the IP and saw a 
>> range of requests to block my IP address
>> http://dsbl.org/listing?81.103.11.204
>
> I think what you are seeing is dsbl.org blocking you from accessing their 
> site because your computer has been used in a DDoS campaign against their 
> site.  81.103.11.204 was tested by them and proven to be an open proxy. 
> Further, the computer on that IP was part of a zombie army used in a 
> personal DDoS attack against them in an attempt to knock them off the air.
>
> dsbl's response was to block access to their site from that IP.  It is a 
> defensive move taken by many sites to fend of attacks.
>
> What you need to do is find the backdoor on your computer and secure it so 
> it can't be used by spammers and in future attacks on Internet sites.

It's not because of any DDoS campaign on my behalf (although dsbl.org does 
seem to be down...?) - it's because I'm running fully-patched IE...

Here is the latest response and reply to dsbl.org for those who are 
interested:

Fred Smith <mailto:[email protected]> wrote:
> On Fri, 2004-12-24 at 12:06 +0000, Christopher Hill wrote:
>> OK, so what you've done is set up a policy where anyone that goes to
>> your website using ANY version of Internet Explorer (mine is patched
>> with the latest available patches), is going to start having
>> problems sending emails to certain servers.
>
> Yes, just like people who are running mdaemon software are going to be
> listed because that software is impossible to secure.  You'll need to
> pressure your vendor for a patch (you did *pay* for that browser,
> since it came with your paid OS), or switch to a different piece of
> software. If you don't, you'll need to understand that people may be
> using your system to send unsolicited email without your consent, and
> that many people don't want to receive email from your system as a
> result of it.
> The exploit we're testing has been known publicly for 6 months now,
> and Microsoft hasn't patched it.

OK, yes, I understand the reasoning behind it. I run insecure software, you 
block me. What I'm saying is that while mail administrators should be 
expected to have a 'clue' and patch their software - after all, it is their 
job - home users in general don't.

In principle, I can see where you're coming from. My system may be used to 
send unsolicited mail. However, at the moment I would guess that this 
exploit isn't being used to send spam because it's just not practical - 
realistically you're going to be sending perhaps one or two emails with this 
command, and any mass spammer is going to have to write some sort of script 
to get people who visit his site to automatically send loads and loads of 
emails, with the page getting refreshed and so on. I think that with the 
number of open-relay SMTP daemons around and other ways of sending spam, 
they're not going to bother.

>> That is, you have made it so that 95% of the people who are browsing
>> the World Wide Web are going to have problems sending emails,
>
> under 90% these days, actually.  Mozilla Firefox is used by an ever
> growing percentage of Internet users, for reasons much like this one.

OK, yes, but it's not ready for some deployments. I've considered deploying 
it at the school where I work (I am the ICT technician there) but it's just 
not quite ready yet. I could go in depth into the reasons for you if you 
wanted. And besides, whether it's 90% or 95%... isn't that still quite a 
large percentage?

>> How dare these people try to use the
>> Internet without a clue? How dare they think it can be as helpful
>> and useful and troublefree as switching on a TV or driving their car?
>
> I'm not sure how it works in your country, but in the US, people who
> do not know how to drive are not given drivers licenses and are not
> allowed on the road.

You can kill people if you don't drive properly. Sending an unsolicited 
email isn't quite on the same level.

>> (By the way, yes it will cause problems for those people, even if
>> they use their ISP's SMTP server to send email. I *used* to use
>> dsbl.org for blocking on my SpamCop account, and that means that
>> *every* IP address in the Received: headers has to be clear of *all*
>> the blocking lists.
>
> That's a significant bug in spamcop's filtering system, then. You
> cannot trust any header appended by anything but your mail server.
> Mail filtering systems should never make decisions like that based on
> untrustable and easily spoofed data.

They have software that automatically detects which headers can be trusted 
and which can't when you *report* spam. And as for receiving spam, who is 
going to *deliberately* put an IP address into a header that they *know* is 
on a DNS block list?

>> ALL responsible blocklists should ONLY punish people who have been
>> negligent - either in configuring their mail server, or in not
>> updating their software
>
> Thank you for making our point for us.  People running Internet
> explorer in this day and age are negligent.

Every piece of software has security holes. FireFox doubtless has some (for 
example, opening certain mangled HTML files can cause problems that don't 
occur in IE - see http://www.internetnews.com/ent-news/article.php/3425631)

Yes, Internet Explorer has serious problems in its actual architecture. Yes, 
Microsoft in general take longer than most vendors to release patches, and 
sometimes ignore holes completely. And someone needs to take them to task 
over that.

But I don't think that blocking people who use Internet Explorer because 
they don't even think of switching to anything else, or they can't (some 
sites still don't work in FireFox - see http://www.launch.com/ among 
others), or because they just expect their computers to work, is a very good 
attitude to have. It's preventing the flow of information. I haven't got a 
problem with that as such (otherwise I wouldn't use lists like dsbl.org 
myself) but I think that you have overstepped the mark in this case, because 
the solution that you require to the problem (everyone moves to FireFox or 
another browser) is too radical to ever actually happen. Or if it does 
happen, it probably won't be for another 5 to 10 years, and your action will 
not speed that process up significantly.

So I hope you see that I think your principles are correct (insecure 
software should be blocked) but your application of them *in this case* is 
flawed (the consequences of your actions will create more problems than they 
solve, and will not be easily reversed).

>> When people hear about this I think they will stop using dsbl.org,
>> unless you reverse your policy on this pretty quickly, and unblock
>> the IPs that have already been listed in this way. As far as I can
>> see, there's not even any mention on your website that you've
>> adopted this policy.
>
> It's not a policy change.  These listings are perfectly legitimate,
> and work under our existing policy.

I can't see your website at the moment (is it down?) but I thought the 
policy was that you did not undergo active testing of sites, but you let 
other people do your testing for you. Isn't attempting to exploit a flaw in 
a piece of software when people visit your site active testing?

Even if you don't consider this to be a change in policy, I still think you 
should advertise this fact on your site. When people are finding out whether 
to use your DNS list or not, they want to know the source of your data. When 
I read your site trying to find out why I was listed, I did not find 
anything that might suggest that it was because I was using Internet 
Explorer to access your site. The site is almost entirely geared towards 
checking for open relays and buggy daemons. There should at the very least 
be an entry in your FAQ that says 'I've been blocked since visiting your 
website with Internet Explorer. Why?' to answer questions like these and 
make clear what you are doing. IMHO there should also be an entry on the 
main page of your site telling existing dsbl.org users that you are now 
blocking those who visit your site with buggy (ie all current) versions of 
Internet Explorer, and why. If this is something that people who currently 
use your list want (as you seem to think it is) then why not be upfront 
about it? Doubtless there *will* be some people who like this new policy. 
But as an existing user, I do *not* like it, and need to be informed as well 
so that I can choose to stop using your DNS blacklist. I hope that you do 
agree that while this may not be a change of policy in your opinion, yet it 
is a significant change to the way that the blocklist is compiled, and 
something that some (if not many) people will want to know about.

I disagree with your policy, but putting that aside, you should make it 100% 
clear on your website, so that each user can make an informed decision.

>> 'Therefore, if anyone is in Christ, he is a new creation;
>> the old has gone, the new has come!' - 2 Corinthians 5v17
>
> Ah, that explains it.  Get a clue.

I don't think you're helping anything by insulting my faith. This has 
nothing to do with the discussion and I am saddened that you should bring 
that into it.

Regards,

Chris Hill
--

'Therefore, if anyone is in Christ, he is a new creation;
the old has gone, the new has come!' - 2 Corinthians 5v17
[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.