RE: email address "spoofed"

From: Aditya, ALD [Aditya Lalit Deshmukh] (aditya.deshmukh_at_online.gateway.technolabs.net)
Date: 03/13/04

  • Next message: chumma chumma: "Which one have more vulnerability history, SSH or OpenSSH ?"
    To: <gillettdavid@fhda.edu>, <ald2003@users.sourceforge.net>, <hometeam@goeaston.net>, "'security-basics'" <security-basics@securityfocus.com>
    Date: Sat, 13 Mar 2004 10:25:19 +0530
    
    

    >
    > A great many ISPs who hand out addresses via DHCP maintain a
    > set of generic reverse-DNS entries for their scopes. On the one
    > hand, this greatly diminishes the value of this lookup as an
    > anti-spam measure; on the other hand, it avoids the particular
    > problem you describe.

    the problem is that my address when forward resolved is different from reverse resolution.

    > A more effective measure employed by several ISPs is to block
    > outbound SMTP at their borders, except for their own officially
    > sanctioned email server(s). This cuts the propagation of viruses
    > with their own SMTP engine, and use of spam-sending packages with
    > their own, to virtually nil, and if they don't turn on the reverse
    > check, they can probably (*safely*) avoid setting up reverse
    > records for their DHCP scopes.

    this would work only if the isp allowed any and every email from any domain to pass through, that is why i run myy own mail server with the A and MX recored pointing to my smtp server address

    > If your ISP allows arbitrary port 25 traffic to the world, but
    > won't set up reverse ranges on its DNS servers, maybe you should
    > evaluate some of their competitors....
    >

    ther competitors are worse, atleast this one has a very responcive help desk and good people at the phone and not some script monkeys, one call is what it takes to resolve any complicated matter.

    -aditya

    ________________________________________________________________________
    Delivered using the Free Personal Edition of Mailtraq (www.mailtraq.com)

    ---------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off
    any course! All of our class sizes are guaranteed to be 10 students or less
    to facilitate one-on-one interaction with one of our expert instructors.
    Attend a course taught by an expert instructor with years of in-the-field
    pen testing experience in our state of the art hacking lab. Master the skills
    of an Ethical Hacker to better assess the security of your organization.
    Visit us at:
    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    ----------------------------------------------------------------------------


  • Next message: chumma chumma: "Which one have more vulnerability history, SSH or OpenSSH ?"

    Relevant Pages

    • Re: Yet another multisite VPN DNS question!
      ... router to tell it where to forward DHCP requests to. ... Reverse lookups are used mainly by management software to make log files ... DHCP to do the registration for you, as it will have the rights to delete ... find an authoritative name server, ...
      (microsoft.public.windows.server.dns)
    • Re: Sites that block dynamic/dialups
      ... > If the receiving MTA could connect to the sending MX, ... domain name registered in the DNS that isn't a sub-zone of the ISP (even if the ... "undetected" fixed address blocks hiding inside the dynamic blocks of some ISPs, ... "dummy" hostname that contains the IP address (I've seen dotted-quads, reverse ...
      (comp.os.linux.networking)
    • RE: email address "spoofed"
      ... A more effective measure employed by several ISPs is to block ... their own, to virtually nil, and if they don't turn on the reverse ... won't set up reverse ranges on its DNS servers, ... > this is the case of the server on which the openssl mailing ...
      (Security-Basics)
    • RE: W2K to W2K3 Upgrade
      ... updating the forward record but not the reverse record. ... lookup zones had not been created and configured for dynamic update. ... I have DHCP and DNS running on the remaining W2K DC. ...
      (microsoft.public.win2000.dns)
    • Re: [opensuse] postfix and helo/ehlo
      ... Many ISPs will simply NOT allow you to specify a reverse. ... your provider is on good speaking terms with the provider of address space ... it ist not neccessary for the client itself to have the option to define the reverse dns name. ...
      (SuSE)

  • Quantcast