Re: ISP outbound SMTP filtering

JC Dill <[email protected]>
Newsgroups gmane.org.operators.internet-access
Message-ID <[email protected]>
Kevin Kargel wrote:
> Analysis of network traffic is always good to let you know what is going
> on, but doing any analysis to the point of being able to differentiate
> between legitimate traffic and zombies would be extremely difficult. 

Huh?  Very few non-business ISP customers run SMTP servers.  So very few 
of them have any reason to be making multiple port 25 connections from 
their computer to numerous other computers on the internet.  Some users 
will have legitimate reasons to connect to port 25 to other servers 
(sending mail thru other networks where they have an account, such as 
the work server, or their webhost server, or their alternate email 
provider) but most of those connections are over port 587 today.  Any 
computer (especially one on a dynamic IP) that is making multiple 
outbound port 25 connections to other computers should be suspected of 
being part of a spam-spewing botnet.

> It
> is pretty much a given that if you do not have defenses in place you
> will have zombie traffic.  

Very true.  So put in the defenses!

> Redirection to your mail server is also risky if your mail server allows
> relay by IP.  This would be a pretty sure way to get your mail server on
> the blacklists.  Forcing zombie traffic to your mail server will make
> your mail server appear spam friendly to the world.

And what is the problem with that?  Said network IS spam-friendly when 
you let your customer's zombies run unfettered!  If you force those 
zombies thru your mail server, then YOU will notice them, then YOU will 
get them off the 'net.  Those zombies are YOUR responsibility!

> If you do silly router tricks to redirect port 25 traffic to your mail
> server I would suggest implementing SMTP auth to limit the zombie
> activity.  This carries it's own frustrations, as you will need to
> reconfigure/educate all of your SMTP users.

Haven't we heard this tired old song ("It's too hard") many times before 
as network "best practices" change over time?  (e.g. closing open 
relays)  Yes, you will have to educate your SMTP users.  The alternative 
is continuing to spew spam.  Let's see, on one hand we have zombies on 
the network spewing spam, and on the other hand we have educated 
customers using SMTP auth and not spewing spam... think, think, think. 
Which one is better for the network, better for the internet???

jc



_______________________________________________
"Eat sushi frequently". - Avi
[email protected] is the human contact address.
[email protected] is the list posting address.
See below URL for subscribe/unsubscribe and list options:
http://inet-access.net/mailman/listinfo/list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.