Re: A request to all mail admins

From: Tim Haynes (usenet-20030828_at_stirfried.vegetable.org.uk)
Date: 08/28/03


Date: Thu, 28 Aug 2003 10:21:55 +0100

Jem Berkes <jb@users.pc9.org> writes:

> A request to mail system admins: if you have virus scanners or some sort of
> worm/attachment blocking mechanism, please configure it to NOT send notices
> back to the sender that they sent a virus.
>
> These modern windows worms all forge the sender anyway. There are people
> like me who, unfortunately, have their addresses on too many windows
> users' address books and my inbox is flooded with "you sent a virus"
> notices. The notices just add to network congestion, and these are an
> avoidable bounce.

Agreed, with a couple other thoughts:

a) if you're going to bounce a viral mail, damn' well leave the attachment
in place so I can reject it.

b) bouncing virus mails is just as stupid as replying to any other kind of
UBE - it's automation of generating replies (new mails with different
envelopes), and is similarly moronic.

c) If you reject at the SMTP stage (ie the last state message after reading
in all the DATA is `550 Bog Off') then while you are giving the real sender
a message, and you're not generating the bounce yourself, you do risk
causing bounces from clueless smarthosts. I still maintain that this is a
misconfiguration error, for which the masses of innocent victims of
backscatter should mail postmaster@[smarthost's domain] to complain.

d) It would be nice if there were more of a way to tie in checks that "is
the bounce likely to go back where it came from?" at SMTP stage; we already
have the ability to do MX lookups on the Sender/Return-Path/mail-from
domain, and to connect into those MXes to see if they accept mail for the
user from <>; it should be possible to devise an algorithm where the
closeness of IP# for the MX of the return-path-to-be-used-in-a-bounce is
measured relative to the incoming connection - that way, relayed mail can
be detected, and you can influence your do-I-bounce-this-virus? decision
accordingly as well.

~Tim

-- 
And it's true we are immune.                |piglet@stirfried.vegetable.org.uk
When fact is fiction and                    |http://spodzone.org.uk/
T.V. is reality,                            |


Relevant Pages

  • Re: Beware of ISP spam filtering
    ... They receive the mail and tell the sender that they've got it correctly. ... Then they open a new connection to the destination server to pass the ... OTOH, if the destination server says no, maybe because the spam or virus ... it can send a bounce to let the supposed sender ...
    (uk.telecom.broadband)
  • Re: OE6 rejects some messages
    ... What does the bounce message say? ... it is returned to the sender (assuming there is ... message rejected - messages from the sender or the sender's ISP are ... than the ISP they are currently dialed into (an incorrect setting in the mail program). ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: SMTP: stop sending "no such user" messages
    ... which will notify a legitimate sender right away without ... VMS having to send a bounce after accepting the message. ... since the sender at the other end was bogus ...
    (comp.os.vms)
  • Re: spammed by my own email address?
    ... > email address as the sender. ... If it is forged by a virus, ... address forged by a spammer. ... I was getting bounce for three months; ...
    (microsoft.public.security)
  • Re: Linux virus or forged address?
    ... >>I recently received the following bounce message for a message I never ... virus scan on the fly and drop the connection if one is found. ... with bounces since you know darned well the sender is invalid. ... buggy, security-hole-ridden Outlook/OE/Exchange clients. ...
    (Fedora)