Re: dsbl.org SERIOUS problem

"John E. Malmberg" <[email protected]>
Newsgroups gmane.mail.spam.spamcop.email
Message-ID <[email protected]>
Christopher Hill wrote:
> Thanks to all those who replied, but it seems that dsbl.org have changed
> their mind.
> 
> http://dsbl.org/cgi-bin/ezmlm-browse.cgi?list=list/list&cmd=showmsg&msgnum=1553
>  
>>Bowing to pressure, I've removed the exploit code from every page on the
>>website except removal_confirm.  Sorry for the hassle.
> 
> 
> Which is a good thing in my opinion. They have still left all the
> IPs that were listed as 'ftp-url' in the system (including me), and
> many people aren't going to have a clue how to get themselves back out
> again... but at least there aren't more people falling into the trap.

When the seven days are up, you can request removal again, but make sure 
that you use a different browser, or a computer that you can risk 
getting listed.

It was queued for removal once, except that the browser vulnerability 
caused it to be listed again, so it appears that you or someone can 
follow the removal procedure.

> I personally am not going to use dsbl.org again.

What problems is the DSBL.ORG listing causing you?

Your listed I.P. address (obtained from the public DSBL archives) is in 
three of the most popular DYNAMIC pool DNSBLs in use.  SORBS, NJABL, and 
  the PDL.

It is not yet in the MAPS-DUL, but the first spam report that MAPS-DUL 
gets from an I.P. address in the same address pool as you are will 
change that.  That listing is only a matter of time.

Which means that to reach a large portion of the internet through 
e-mail, you must go through your ISP's mail servers anyway.

If you are not on a DHCP pool, then you need to get your ISP to fix 
their designation of your I.P. address and then get it removed from the 
other dynamic pool lists.


For most of the postmasters that I know, the dynamic lists are checked 
second after the local blocking lists, but before the open proxy / open 
relay lists.

MAPS-DUL was just dropped by one because it was missing too many known 
DHCP pools.

According to the statistics from one of my postmasters, dropping the 
DSBL.ORG confirmed list would result in at least 10 to 15% more spam 
getting through.  Since they also use one or more of the above dynamic 
pool listings, it would be hard to convince them to drop the DSBL 
confirmed list just because it is listing insecure browsers that are 
allowing the execution of scripts against other servers.


It looks like there may be other exploits of this issue that the DSBL is 
not testing for, so I would recommend contacting your browser vendor for 
a fix or a statement to verify that they are not vulnerable.  The DSBL 
tests are not sufficient to rule out that a browser is vulnerable.

-John
[email protected]
Personal Opinion Only
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.