RE: CBV

"Seth Goodman" <[email protected]>
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
> From: Meng Weng Wong
> Sent: Thursday, April 29, 2004 3:07 PM
>
>

<...>

> I should be clear --- when I say "replay attack" I mean a spammer gets
> his hands on an SRS/SES address and sends mail *using it* as the return
> path.  That attack works for SES, doesn't work so well for SRS/SPF.
>
> An SRS address would (presumably) have SPF protection so a replay attack
> wouldn't work.  If SES addresses refuse SPF protection (and if they
> decline SRS, they refuse SPF protection) then replay attacks do work.
>
> The vulnerability Shevek responded to was where the spammer uses an SRS
> address as the *recipient address* to send spam to the original sender.
> In this situation, under both SES and SRS the original sender gets the
> spam, but this case is of limited interest outside the 5-player SRS1
> game which Shevek has already solved by adding the "never shortcut"
> subclass.

This would be true for normal (non-DSN) spam, but for SRS, a spammer would
abuse a harvested address is by sending the spam as a DSN.  Since a DSN has
a null-sender, SPF checks based on the HELO name.  If I understand SRS
correctly (and perhaps I don't), if you can obtain a valid SRS-rewritten
address, you can send a DSN to that address from any machine whose HELO name
and SPF record will allow it to pass an SPF check.  That's not much of a
hurdle.  If what I've said is true, harvesting an SRS or an SES address
makes you equally vulnerable to spam, though through different mechanism.

--

Seth Goodman
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.