Re: dsbl.org SERIOUS problem
"John E. Malmberg" <[email protected]>
| Newsgroups | gmane.mail.spam.spamcop.email |
|---|---|
| Message-ID | <[email protected]> |
Christopher Hill wrote: > Thanks to all those who replied, but it seems that dsbl.org have changed > their mind. > > http://dsbl.org/cgi-bin/ezmlm-browse.cgi?list=list/list&cmd=showmsg&msgnum=1553 > >>Bowing to pressure, I've removed the exploit code from every page on the >>website except removal_confirm. Sorry for the hassle. > > > Which is a good thing in my opinion. They have still left all the > IPs that were listed as 'ftp-url' in the system (including me), and > many people aren't going to have a clue how to get themselves back out > again... but at least there aren't more people falling into the trap. When the seven days are up, you can request removal again, but make sure that you use a different browser, or a computer that you can risk getting listed. It was queued for removal once, except that the browser vulnerability caused it to be listed again, so it appears that you or someone can follow the removal procedure. > I personally am not going to use dsbl.org again. What problems is the DSBL.ORG listing causing you? Your listed I.P. address (obtained from the public DSBL archives) is in three of the most popular DYNAMIC pool DNSBLs in use. SORBS, NJABL, and the PDL. It is not yet in the MAPS-DUL, but the first spam report that MAPS-DUL gets from an I.P. address in the same address pool as you are will change that. That listing is only a matter of time. Which means that to reach a large portion of the internet through e-mail, you must go through your ISP's mail servers anyway. If you are not on a DHCP pool, then you need to get your ISP to fix their designation of your I.P. address and then get it removed from the other dynamic pool lists. For most of the postmasters that I know, the dynamic lists are checked second after the local blocking lists, but before the open proxy / open relay lists. MAPS-DUL was just dropped by one because it was missing too many known DHCP pools. According to the statistics from one of my postmasters, dropping the DSBL.ORG confirmed list would result in at least 10 to 15% more spam getting through. Since they also use one or more of the above dynamic pool listings, it would be hard to convince them to drop the DSBL confirmed list just because it is listing insecure browsers that are allowing the execution of scripts against other servers. It looks like there may be other exploits of this issue that the DSBL is not testing for, so I would recommend contacting your browser vendor for a fix or a statement to verify that they are not vulnerable. The DSBL tests are not sufficient to rule out that a browser is vulnerable. -John [email protected] Personal Opinion Only