RE: CBV

"Seth Goodman" <[email protected]>
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
> From: Tony Finch
> Sent: Monday, May 10, 2004 4:06 PM
>
>
> On Fri, 7 May 2004, Seth Goodman wrote:
> >
> > Nobody wants this, but there is a vulnerability to replay
> > attacks.  Maybe
> > we've given it too much airtime, since the vulnerability only
> > really exists
> > for promiscuous sales type accounts that send mail to anyone who asks.
>
> IME, using only an unpublished sender address (not signed, not changing,
> valid as a recipient address) I'm very well protected from the hundreds
> of virus bounces etc. I get each day.

Thank you for this observation.  This at least provides anecdotal support
for the idea that private bounce addresses can be used for typical email and
forum participation without being discovered.  Though the final gateway MTA
is supposed to put MAIL FROM: into the Return-Path: header, mailing lists
and other public services that are not broken don't do this.

Unless you have the bad luck to send a message to a broken service or
someone gives a spam complaint to a spammer without obfuscating your
address, your bounce address will likely remain unknown to spammers.  How
long have you been using the same unpublished bounce address without having
it harvested?

--

Seth Goodman
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.