Re: Filter envelope sender not from address to prevent new spam attack
Russell Robinson <[email protected]> Mon, 4 May 2009 07:49:54 +1000
| Newsgroups | gmane.mail.spam.tmda.user |
|---|---|
| Organization | Root Software |
| Message-ID | <[email protected]> |
Hi, On Thu, 30 Apr 2009 01:40:11 pm David Grimberg wrote: > This just illustrates why it's a best practice to have your black list > rules early on in your filter so that they get matched before your white > list rules. No, this problem has nothing to do with blacklisting. This is a pure challenge-response issue and it seems to be a new type of attack that the spammers have come up with. Here is what they are doing: Find two addresses in the same domain that are probably valid addresses. Say, "user1" and "user2". Assume that "user1" has "user2" whitelisted. Use a valid sender (return path) outside the domain in question (so that the MTA doesn't reject the message). Set the From address to "user2" and send To "user1". In the case of TMDA (and possibly other C-R systems) only one of From, Reply-To, and Sender has to be whitelisted to allow the spam through. The logic in TMDA that will fix this is (I think): Check only Sender (return path) for whitelisting. This logic is not sufficient. It assumes that your MTA will not accept a forged Sender. But, the MTA can (and usually does) do this by verifying that a message from a Sender within your domain has been sent from one of your own servers. -- Russell Robinson ([email protected]) Author of Tectite FormMail and FormMailEncoder/Decoder Root Software (www.tectite.com) ------------------------------------------------------------------------------ Register Now & Save for Velocity, the Web Performance & Operations Conference from O'Reilly Media. Velocity features a full day of expert-led, hands-on workshops and two days of sessions from industry leaders in dedicated Performance & Operations tracks. Use code vel09scf and Save an extra 15% before 5/3. http://p.sf.net/sfu/velocityconf _______________________________________________ tmda-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/tmda-users