Re: dsbl.org SERIOUS problem
"Christopher Hill" <[email protected]>
| Newsgroups | gmane.mail.spam.spamcop.email |
|---|---|
| Organization | SpamCop |
| Message-ID | <[email protected]> |
>> So I went and had a look at the dsbl.org listing for the IP and saw a >> range of requests to block my IP address >> http://dsbl.org/listing?81.103.11.204 > > I think what you are seeing is dsbl.org blocking you from accessing their > site because your computer has been used in a DDoS campaign against their > site. 81.103.11.204 was tested by them and proven to be an open proxy. > Further, the computer on that IP was part of a zombie army used in a > personal DDoS attack against them in an attempt to knock them off the air. > > dsbl's response was to block access to their site from that IP. It is a > defensive move taken by many sites to fend of attacks. > > What you need to do is find the backdoor on your computer and secure it so > it can't be used by spammers and in future attacks on Internet sites. It's not because of any DDoS campaign on my behalf (although dsbl.org does seem to be down...?) - it's because I'm running fully-patched IE... Here is the latest response and reply to dsbl.org for those who are interested: Fred Smith <mailto:[email protected]> wrote: > On Fri, 2004-12-24 at 12:06 +0000, Christopher Hill wrote: >> OK, so what you've done is set up a policy where anyone that goes to >> your website using ANY version of Internet Explorer (mine is patched >> with the latest available patches), is going to start having >> problems sending emails to certain servers. > > Yes, just like people who are running mdaemon software are going to be > listed because that software is impossible to secure. You'll need to > pressure your vendor for a patch (you did *pay* for that browser, > since it came with your paid OS), or switch to a different piece of > software. If you don't, you'll need to understand that people may be > using your system to send unsolicited email without your consent, and > that many people don't want to receive email from your system as a > result of it. > The exploit we're testing has been known publicly for 6 months now, > and Microsoft hasn't patched it. OK, yes, I understand the reasoning behind it. I run insecure software, you block me. What I'm saying is that while mail administrators should be expected to have a 'clue' and patch their software - after all, it is their job - home users in general don't. In principle, I can see where you're coming from. My system may be used to send unsolicited mail. However, at the moment I would guess that this exploit isn't being used to send spam because it's just not practical - realistically you're going to be sending perhaps one or two emails with this command, and any mass spammer is going to have to write some sort of script to get people who visit his site to automatically send loads and loads of emails, with the page getting refreshed and so on. I think that with the number of open-relay SMTP daemons around and other ways of sending spam, they're not going to bother. >> That is, you have made it so that 95% of the people who are browsing >> the World Wide Web are going to have problems sending emails, > > under 90% these days, actually. Mozilla Firefox is used by an ever > growing percentage of Internet users, for reasons much like this one. OK, yes, but it's not ready for some deployments. I've considered deploying it at the school where I work (I am the ICT technician there) but it's just not quite ready yet. I could go in depth into the reasons for you if you wanted. And besides, whether it's 90% or 95%... isn't that still quite a large percentage? >> How dare these people try to use the >> Internet without a clue? How dare they think it can be as helpful >> and useful and troublefree as switching on a TV or driving their car? > > I'm not sure how it works in your country, but in the US, people who > do not know how to drive are not given drivers licenses and are not > allowed on the road. You can kill people if you don't drive properly. Sending an unsolicited email isn't quite on the same level. >> (By the way, yes it will cause problems for those people, even if >> they use their ISP's SMTP server to send email. I *used* to use >> dsbl.org for blocking on my SpamCop account, and that means that >> *every* IP address in the Received: headers has to be clear of *all* >> the blocking lists. > > That's a significant bug in spamcop's filtering system, then. You > cannot trust any header appended by anything but your mail server. > Mail filtering systems should never make decisions like that based on > untrustable and easily spoofed data. They have software that automatically detects which headers can be trusted and which can't when you *report* spam. And as for receiving spam, who is going to *deliberately* put an IP address into a header that they *know* is on a DNS block list? >> ALL responsible blocklists should ONLY punish people who have been >> negligent - either in configuring their mail server, or in not >> updating their software > > Thank you for making our point for us. People running Internet > explorer in this day and age are negligent. Every piece of software has security holes. FireFox doubtless has some (for example, opening certain mangled HTML files can cause problems that don't occur in IE - see http://www.internetnews.com/ent-news/article.php/3425631) Yes, Internet Explorer has serious problems in its actual architecture. Yes, Microsoft in general take longer than most vendors to release patches, and sometimes ignore holes completely. And someone needs to take them to task over that. But I don't think that blocking people who use Internet Explorer because they don't even think of switching to anything else, or they can't (some sites still don't work in FireFox - see http://www.launch.com/ among others), or because they just expect their computers to work, is a very good attitude to have. It's preventing the flow of information. I haven't got a problem with that as such (otherwise I wouldn't use lists like dsbl.org myself) but I think that you have overstepped the mark in this case, because the solution that you require to the problem (everyone moves to FireFox or another browser) is too radical to ever actually happen. Or if it does happen, it probably won't be for another 5 to 10 years, and your action will not speed that process up significantly. So I hope you see that I think your principles are correct (insecure software should be blocked) but your application of them *in this case* is flawed (the consequences of your actions will create more problems than they solve, and will not be easily reversed). >> When people hear about this I think they will stop using dsbl.org, >> unless you reverse your policy on this pretty quickly, and unblock >> the IPs that have already been listed in this way. As far as I can >> see, there's not even any mention on your website that you've >> adopted this policy. > > It's not a policy change. These listings are perfectly legitimate, > and work under our existing policy. I can't see your website at the moment (is it down?) but I thought the policy was that you did not undergo active testing of sites, but you let other people do your testing for you. Isn't attempting to exploit a flaw in a piece of software when people visit your site active testing? Even if you don't consider this to be a change in policy, I still think you should advertise this fact on your site. When people are finding out whether to use your DNS list or not, they want to know the source of your data. When I read your site trying to find out why I was listed, I did not find anything that might suggest that it was because I was using Internet Explorer to access your site. The site is almost entirely geared towards checking for open relays and buggy daemons. There should at the very least be an entry in your FAQ that says 'I've been blocked since visiting your website with Internet Explorer. Why?' to answer questions like these and make clear what you are doing. IMHO there should also be an entry on the main page of your site telling existing dsbl.org users that you are now blocking those who visit your site with buggy (ie all current) versions of Internet Explorer, and why. If this is something that people who currently use your list want (as you seem to think it is) then why not be upfront about it? Doubtless there *will* be some people who like this new policy. But as an existing user, I do *not* like it, and need to be informed as well so that I can choose to stop using your DNS blacklist. I hope that you do agree that while this may not be a change of policy in your opinion, yet it is a significant change to the way that the blocklist is compiled, and something that some (if not many) people will want to know about. I disagree with your policy, but putting that aside, you should make it 100% clear on your website, so that each user can make an informed decision. >> 'Therefore, if anyone is in Christ, he is a new creation; >> the old has gone, the new has come!' - 2 Corinthians 5v17 > > Ah, that explains it. Get a clue. I don't think you're helping anything by insulting my faith. This has nothing to do with the discussion and I am saddened that you should bring that into it. Regards, Chris Hill -- 'Therefore, if anyone is in Christ, he is a new creation; the old has gone, the new has come!' - 2 Corinthians 5v17 [email protected]