RE: CBV
"Seth Goodman" <[email protected]>
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
> From: Meng Weng Wong > Sent: Thursday, April 29, 2004 3:07 PM > > <...> > I should be clear --- when I say "replay attack" I mean a spammer gets > his hands on an SRS/SES address and sends mail *using it* as the return > path. That attack works for SES, doesn't work so well for SRS/SPF. > > An SRS address would (presumably) have SPF protection so a replay attack > wouldn't work. If SES addresses refuse SPF protection (and if they > decline SRS, they refuse SPF protection) then replay attacks do work. > > The vulnerability Shevek responded to was where the spammer uses an SRS > address as the *recipient address* to send spam to the original sender. > In this situation, under both SES and SRS the original sender gets the > spam, but this case is of limited interest outside the 5-player SRS1 > game which Shevek has already solved by adding the "never shortcut" > subclass. This would be true for normal (non-DSN) spam, but for SRS, a spammer would abuse a harvested address is by sending the spam as a DSN. Since a DSN has a null-sender, SPF checks based on the HELO name. If I understand SRS correctly (and perhaps I don't), if you can obtain a valid SRS-rewritten address, you can send a DSN to that address from any machine whose HELO name and SPF record will allow it to pass an SPF check. That's not much of a hurdle. If what I've said is true, harvesting an SRS or an SES address makes you equally vulnerable to spam, though through different mechanism. -- Seth Goodman