RE: [Full-Disclosure] E-mail spoofing countermeasures (Was: Backdoor not recognized by Kaspersky)

From: Bill Royds (full-disclosure_at_royds.net)
Date: 03/04/04

  • Next message: Nick FitzGerald: "RE: [Full-Disclosure] Backdoor not recognized by Kaspersky"
    To: <full-disclosure@lists.netsys.com>
    Date: Thu, 4 Mar 2004 07:31:10 -0500
    
    

     Having a MS record would not eliminate spam coming from users validated on
    the sending server, but it would identify the server that it comes from as
    "knowing" the sender name. Compromised client boxes would need to use the
    ISP mail server to send mail, rather than spewing it directly, since the
    servers allowed on the MS entry for that domain would not include the client
    host.
      Either the ISP owing the server blocks spam spew or that ISP gets a
    blackhole block that would be very effective.
       Yesterday I inspected the spam I had in my spam bucket for kinds of
    actual senders (last sender on Received header for my ISP). Of 11 spam
    messages in the last hour, 9 were from compromised machines sending
    directly. If they had to send this stuff through their ISP (comcast,
    telstra, swbell etc.), they would be blocked fairly quickly. The envelope
    from address was often Yahoo, so the ISP would block on this as well.
      Requiring MS entries would not block spam or viruses immediately but would
    help make RBL lists more effective and prosecution of spammers easier
    (easier to trace a registered user of an ISP).

    -----Original Message-----
    From: full-disclosure-admin@lists.netsys.com
    [mailto:full-disclosure-admin@lists.netsys.com] On Behalf Of Nick FitzGerald
    Sent: March 4, 2004 3:00 AM
    To: full-disclosure@lists.netsys.com
    Subject: RE: [Full-Disclosure] E-mail spoofing countermeasures (Was:
    Backdoor not recognized by Kaspersky)

    "Bill Royds" <broyds@rogers.com> wrote:

    <<snippage>>
    > Using authenticated SMTP, this would still allow a different return
    > address in headers since envelope from would be user who authenticated to
    > SMTP server. But it would prevent spoofed email (although spam would
    still
    > arrive, it could be tied to actual sender, allowing things like CAN-SPAM
    to
    > work).

    Wrong. It would, at best, identify the sending _machine_, not the
    "actual sender".

    There is far too much prior art in the Windows malware armory to not be
    aware of how easily an agent program on a "compromised" Windows box can
    steal whatever configuration and authentication data it may need to
    "properly" send mail "just like" the user's preferred MUA. Just
    because, of late, spam and mass-mailing viruses have used randomized
    From: and SMTP envelope FROM addresses does not mean thay have to
    continue to do so, nor that not doing so will necessarily be less
    effective for them...

    These are important considerations to not overlook despite the fact
    that the SPF, etc pushers make a habit of ignoring such. Further,
    several IRC bot-nets in tens-of-thousands of active bots size range
    have already been found and there are probably several million such
    compromised mnachiens out there waiting for the fateful order to "wake
    up" and answer the call of their "master".

    SMTP "sender authentication" is a far less trivial problem to solve
    that the SPF, aller-ID, etc folk would have you believe (and, of
    course, they don't like us pointing out that their preferred
    "solutions" are already doomed to failure).

    -- 
    Nick FitzGerald
    Computer Virus Consulting Ltd.
    Ph/FAX: +64 3 3529854
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Nick FitzGerald: "RE: [Full-Disclosure] Backdoor not recognized by Kaspersky"

    Relevant Pages

    • Re: [opensuse] Martin =?UTF-8?B?R2zDtnR6bC1Lb2NoIFNUT1AgQk9VTkNJ?= =?UTF-8?B?TkcgTElTVCBNQUl
      ... what I'm bothered is receiving email from my ISP boxes with false ... On my private server here at home I very seldom see any spam at all, ... On our company mailserver I have a completely different situation. ...
      (SuSE)
    • RE: POP & SMTP Server Question
      ... > control on the spam I can reject. ... Whenj my ISP gets it, they don't filter, ... I also use spamassassin, and that's coming ... less than 1% via my own server. ...
      (Fedora)
    • Re: Hotmail
      ... it is returned to the sender (assuming there is ... over quota - the recipient's server mail box has reached its limit ... message rejected - messages from the sender or the sender's ISP are ... I have no problem sending to the ...
      (microsoft.public.internet.mail)
    • Re: Help! Need to sell my company on Exchange!
      ... the SBS 2003 server would help you on a lot of the issues. ... forwarding messages to the Exchange Server. ... this) that it can be done since my ISP claims they can do it??? ... filter Spam messages. ...
      (microsoft.public.windows.server.sbs)
    • Re: 4.4.7 non-delivery reports
      ... It sounds strange that many ISPs are causing a timeout error as a way to ... I know everything points to a problem at the receiving server but I ... hidden in PDF spam. ... We suspect that a particular item of ISP based anti-spam software is ...
      (microsoft.public.exchange.admin)

    Loading