Re: dsbl.org SERIOUS problem
"John E. Malmberg" <[email protected]>
| Newsgroups | gmane.mail.spam.spamcop.email |
|---|---|
| Message-ID | <[email protected]> |
Larry Kilgallen wrote: > In article <[email protected]>, "Christopher Hill" <[email protected]> writes: > >>OK, this sucks. Turns out that dsbl.org now blocks people for using Internet >>Explorer to visit their site. >> >>Let me qualify that. It blocks people for using any version of IE that has a >>particular vulnerability. Trouble is, there's no patch for that >>vulnerability yet. So you visit dsbl.org with IE and images enabled, even if >>you're totally patched up - you get your email blocked. >> >>Does that sound really really stupid to anyone else? As soon as the vulnerability gets more widely published, a worm or spamware will be written to take advantage of it. In the 30 seconds that someone might be waiting for images to load, a lot of spam can be queued up on an SMTP server for relaying. > To use a browser with a known vulnerability ? Yes, that sounds stupid. It appears that this is a new vulnerability, and that the number of browsers that are affected have not been mapped, but may not be restricted to IE. If your browser will not allow you to connect to ftp://localhost:25, then it is likely that you will pass the dsbl.org test. That does not mean that your browser is totally free of the exploit. According to postings on the archives of the dsbl.org mailing lists, the systems with browsers that they get to relay mail are going on the "multihop" list, not the main one. Absolute blocking on the multihop list is a bad idea as it is almost impossible for most major commercial ISPs to stay off of it all of the time. So even before this action by the dsbl, using the multihop list for blocking was likely to cause real e-mail to be blocked. DSBL has always recommended that the mutihop list only be used for scoring. This test by the DSBL actually is helping to find sources of potential direct to MX viruses, most of which lately morph into spam zombies. If a company requires all e-mail to be sent through a designated SMTP gateway, even if they have a vulnerable browser, they will currently pass the dsbl test unless they are using vulnerable browser on their outgoing mail server. Also if your ISP is blocking port 25 except to it's designated SMTP servers, then you will pass the DSBL test, even if you have an insecure browser. It might have been more useful if DSBL would create a new zone for this exploit. Of course then it would be more likely that this zone would be used for directly blocking mail, since as pointed out earlier, the multihop list is already too aggressive for that. -John [email protected] Personal Opinion Only