Re: CBV
Meng Weng Wong <[email protected]>
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Apr 29, 2004 at 05:15:07PM -0500, Seth Goodman wrote: | This would be true for normal (non-DSN) spam, but for SRS, a spammer would | abuse a harvested address is by sending the spam as a DSN. Since a DSN has | a null-sender, SPF checks based on the HELO name. If I understand SRS | correctly (and perhaps I don't), if you can obtain a valid SRS-rewritten | address, you can send a DSN to that address from any machine whose HELO name | and SPF record will allow it to pass an SPF check. That's not much of a | hurdle. If what I've said is true, harvesting an SRS or an SES address | makes you equally vulnerable to spam, though through different mechanism. | If a spammer can get his hands on the return-path, SRS makes the sender vulnerable to spam directed to that return-path, yes. But SES makes the sender vulnerable to spoofing --- a spammer could send mail *as* that SES address to a bazillion recipients. You'd have to dynamically invalidate the SES address and hope enough people do CBV.