Re: dsbl.org SERIOUS problem

"John E. Malmberg" <[email protected]>
Newsgroups gmane.mail.spam.spamcop.email
Message-ID <[email protected]>
Larry Kilgallen wrote:
> In article <[email protected]>, "Christopher Hill" <[email protected]> writes:
> 
>>OK, this sucks. Turns out that dsbl.org now blocks people for using Internet 
>>Explorer to visit their site.
>>
>>Let me qualify that. It blocks people for using any version of IE that has a 
>>particular vulnerability. Trouble is, there's no patch for that 
>>vulnerability yet. So you visit dsbl.org with IE and images enabled, even if 
>>you're totally patched up - you get your email blocked.
>>
>>Does that sound really really stupid to anyone else?

As soon as the vulnerability gets more widely published, a worm or 
spamware will be written to take advantage of it.  In the 30 seconds 
that someone might be waiting for images to load, a lot of spam can be 
queued up on an SMTP server for relaying.

> To use a browser with a known vulnerability ?  Yes, that sounds stupid.

It appears that this is a new vulnerability, and that the number of 
browsers that are affected have not been mapped, but may not be 
restricted to IE.

If your browser will not allow you to connect to ftp://localhost:25, 
then it is likely that you will pass the dsbl.org test.  That does not 
mean that your browser is totally free of the exploit.


According to postings on the archives of the dsbl.org mailing lists, the 
systems with browsers that they get to relay mail are going on the 
"multihop" list, not the main one.

Absolute blocking on the multihop list is a bad idea as it is almost 
impossible for most major commercial ISPs to stay off of it all of the time.

So even before this action by the dsbl, using the multihop list for 
blocking was likely to cause real e-mail to be blocked.

DSBL has always recommended that the mutihop list only be used for scoring.

This test by the DSBL actually is helping to find sources of potential 
direct to MX viruses, most of which lately morph into spam zombies.

If a company requires all e-mail to be sent through a designated SMTP 
gateway, even if they have a vulnerable browser, they will currently 
pass the dsbl test unless they are using vulnerable browser on their 
outgoing mail server.

Also if your ISP is blocking port 25 except to it's designated SMTP 
servers, then you will pass the DSBL test, even if you have an insecure 
browser.

It might have been more useful if DSBL would create a new zone for this 
exploit.  Of course then it would be more likely that this zone would be 
used for directly blocking mail, since as pointed out earlier, the 
multihop list is already too aggressive for that.

-John
[email protected]
Personal Opinion Only
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.