Re: CBV

Meng Weng Wong <[email protected]>
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
On Thu, Apr 29, 2004 at 05:15:07PM -0500, Seth Goodman wrote:
| This would be true for normal (non-DSN) spam, but for SRS, a spammer would
| abuse a harvested address is by sending the spam as a DSN.  Since a DSN has
| a null-sender, SPF checks based on the HELO name.  If I understand SRS
| correctly (and perhaps I don't), if you can obtain a valid SRS-rewritten
| address, you can send a DSN to that address from any machine whose HELO name
| and SPF record will allow it to pass an SPF check.  That's not much of a
| hurdle.  If what I've said is true, harvesting an SRS or an SES address
| makes you equally vulnerable to spam, though through different mechanism.
| 

If a spammer can get his hands on the return-path, SRS makes the sender
vulnerable to spam directed to that return-path, yes.

But SES makes the sender vulnerable to spoofing --- a spammer could send
mail *as* that SES address to a bazillion recipients.  You'd have to
dynamically invalidate the SES address and hope enough people do CBV.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.