[Full-Disclosure] Spam Solution

From: Alavan (alavan_at_pangeatech.com)
Date: 06/18/04

  • Next message: Poof: "RE: [Full-Disclosure] MS Anti Virus?"
    To: full-disclosure@lists.netsys.com
    Date: Thu, 17 Jun 2004 15:53:25 -0700
    
    

    Please correct me if I'm missing something here:

      Microsoft and POBOX.com support Caller ID and SPF to help thwart phishing
    and SPAM.

    I can see it helping phishing (kind of) as the phishers won't be able to
    forge the FROM address. But, that won't stop naive users from entering
    their personal information onto the fake site even with some rogue FROM
    address. Also, the phishers can just claim to be from a hired consulting
    agency and send the SPAM from a hijacked PC on a domain that sounds
    somewhat technical (or something like that).

    Also, if spammers can't forge, so what? They'll just grab the domain name
    from the PC they've hijacked and send away or go back to using the e-mail
    client on the machine. Once the spammers change their methodology (which
    they do all the time to counter anti-spam efforts), these measures will
    have little to no effect.

    Plus, many people use a FROM address from one of their other POP accounts
    on other domains. For instance, let's say I'm sending an e-mail from home
    just before I leave to a business contact and I want them to see my
    corporate e-mail address instead. In order to accomplish this after Caller
    ID and SPF, all admins will have to get their users to switch to POP before
    SMTP to their corporate mail servers to avoid these returned e-mails (when
    the FROM address is intentionally forged).

     From what I've seen, most of the SPAM comes from hijacked machines - even
    the SPAM from other countries. So, port 25 blocking is good, but not the
    be-all end-all as some "users" will want to host their own mail.

    It seems to me that if we make all MTA's register somehow (both SMTP and
    POST), this would eliminate the hijacked machine as spambot phenomenon. We
    already have MX records for SMTP, but a lot of providers use different
    machines to receive (via SMTP) and send mail (POST). So, maybe a new DNS
    record is introduced for POST. Your machine(s) could do both or not. When
    your server goes to accept a message, it looks to see if the IP of the
    sending machine is listed in this new DNS record. If not, return a 5XX error.

    Didn't I read something somewhere about the possibility of this?

    Thanks,

    Alavan

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Poof: "RE: [Full-Disclosure] MS Anti Virus?"

    Relevant Pages

    • Re: increase in spam and what to do about it
      ... One-to-one agreements aren't scalable with the modern internet unless you ... paid to wade through the garbage (a kind of wetware spam filter :-). ... Usenet News is not a one-to-one agreement between your organisation ... Just use SMTP but set your mail system up so that it just accepts mail from the ...
      (comp.os.vms)
    • Re: increase in spam and what to do about it
      ... One-to-one agreements aren't scalable with the modern internet unless you ... paid to wade through the garbage (a kind of wetware spam filter :-). ... Usenet News is not a one-to-one agreement between your organisation ... Just use SMTP but set your mail system up so that it just accepts mail from the ...
      (comp.os.vms)
    • Re: A flood of spams - another virus on the way?
      ... You would need to totally redesign TCPIP and SMTP with security in mind. ... You can block viruses at the mailhub level the problem is what you then do. ... Spam is a worse problem. ... >number of emails they will be sending out in any one day. ...
      (comp.os.vms)
    • Re: Anti AV/Spam solution
      ... I am not going to get in the discussion which filter is better or worst. ... Be aware that filters integrating with the SMTP protocol do have access ... An SMTP reject is much more light weight than an NDR. ... > features like creating JunkMail folders and moving spam there. ...
      (microsoft.public.exchange2000.admin)
    • Re: anti-spam web page and email reply
      ... mail currently is spam with forged but functional sender addresses, ... them, including rejecting them in SMTP before accepting them, accepting ... manage by pushing the 'challenge' down into SMTP. ...
      (comp.mail.sendmail)

  • Quantcast