RE: ISP outbound SMTP filtering

"Kevin Kargel" <kkargel-BvA0c2rBOuxWk0Htik3J/[email protected]>
Newsgroups gmane.org.operators.internet-access
Message-ID <70DE64CEFD6E9A4EB7FAF3A063141066706F85@mail>
I beg to differ, there are a lot of young experimenters out there who
take great joy in running their own mail servers.  There are many people
who have their own domains who prefer to run their own mail and web
servers instead of paying an ISP for the service.  I have many customers
running mail, web and gaming servers on static IP's at their DSL.  

I have not needed to turn on SMTP auth on my network.  I do not have a
network full of spam zombies as you sould like to suggest.  Forcing
zombies through your mail server as a detection method is just silly,
sort of like checking to see if your gun is loaded by shooting yourself
in the foot..  if you like working to get your network delisted over and
over again feel free, I would rather avoid the disruption..





 

> -----Original Message-----
> From: [email protected] 
> [mailto:[email protected]] On Behalf Of JC Dill
> Sent: Monday, June 04, 2007 10:24 AM
> To: [email protected]
> Subject: Re: ISP outbound SMTP filtering
> 
> Kevin Kargel wrote:
> > Analysis of network traffic is always good to let you know what is 
> > going on, but doing any analysis to the point of being able to 
> > differentiate between legitimate traffic and zombies would 
> be extremely difficult.
> 
> Huh?  Very few non-business ISP customers run SMTP servers.  
> So very few of them have any reason to be making multiple 
> port 25 connections from their computer to numerous other 
> computers on the internet.  Some users will have legitimate 
> reasons to connect to port 25 to other servers (sending mail 
> thru other networks where they have an account, such as the 
> work server, or their webhost server, or their alternate email
> provider) but most of those connections are over port 587 
> today.  Any computer (especially one on a dynamic IP) that is 
> making multiple outbound port 25 connections to other 
> computers should be suspected of being part of a spam-spewing botnet.
> 
> > It
> > is pretty much a given that if you do not have defenses in 
> place you 
> > will have zombie traffic.
> 
> Very true.  So put in the defenses!
> 
> > Redirection to your mail server is also risky if your mail server 
> > allows relay by IP.  This would be a pretty sure way to get 
> your mail 
> > server on the blacklists.  Forcing zombie traffic to your 
> mail server 
> > will make your mail server appear spam friendly to the world.
> 
> And what is the problem with that?  Said network IS 
> spam-friendly when you let your customer's zombies run 
> unfettered!  If you force those zombies thru your mail 
> server, then YOU will notice them, then YOU will get them off 
> the 'net.  Those zombies are YOUR responsibility!
> 
> > If you do silly router tricks to redirect port 25 traffic 
> to your mail 
> > server I would suggest implementing SMTP auth to limit the zombie 
> > activity.  This carries it's own frustrations, as you will need to 
> > reconfigure/educate all of your SMTP users.
> 
> Haven't we heard this tired old song ("It's too hard") many 
> times before as network "best practices" change over time?  
> (e.g. closing open
> relays)  Yes, you will have to educate your SMTP users.  The 
> alternative is continuing to spew spam.  Let's see, on one 
> hand we have zombies on the network spewing spam, and on the 
> other hand we have educated customers using SMTP auth and not 
> spewing spam... think, think, think. 
> Which one is better for the network, better for the internet???
> 
> jc
> 
> 
> 
> _______________________________________________
> "Eat sushi frequently". - Avi
> [email protected] is the human contact address.
> [email protected] is the list posting address.
> See below URL for subscribe/unsubscribe and list options:
> http://inet-access.net/mailman/listinfo/list
> 
_______________________________________________
"Eat sushi frequently". - Avi
[email protected] is the human contact address.
[email protected] is the list posting address.
See below URL for subscribe/unsubscribe and list options:
http://inet-access.net/mailman/listinfo/list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.