Re: really 'evi'l ipfw rules

From:
Date: 09/26/02


Date: Thu, 26 Sep 2002 04:37:59 GMT

Hi Doug -

On Wed, 25 Sep 2002 21:48:17 GMT, "Doug Young" <dougy@brizzie.org>
wrote:

>Is anyone aware of a way to write ipfw rules that automagically return SPAM
>to whence it came & clone a few million copies to accompany it ?? Would
>also need some safeguard to prevent problems resulting from the typical
>asian spammer belong non-functional reply address. I realize there are
>possibly other more conventional means of doing something like this, however
>I've been finding firewall rules somewhat more effective than anything else,
>particularly with korean / chinese junk

This reply includes references to other messages in this thread ...

1. As has already been pointed out, what you are requesting above is
not a firewall kind of thing.

2. 99.99% of spam has from, sender, and reply addresses that are
totally bogus or are valid email addresses but not connected with the
spammer in any way. Would you really want to dump your load in the
mailbox of some innocent person?

3. After all of these messages hit your ISP's SMTP server to go out,
your ISP would have some very pointed things to say to you.

4. All of those messages would be clogging up internet bandwidth,
slowing people down.

5. If your email got through to the spammer, you would be confirming
your email address, thereby making your email address more valuable to
spammers.

6. Sending remove requests to spammers, regardless of their location,
is just confirming your email address. Report the spam to the ISP
that the spammer is using to connect to the internet and/or the ISP of
the SMTP server being used, as is appropriate. (If there is a local
connection to an SMTP server, there is no connecting ISP. If they are
connecting directly to your ISP's server, there is no point
complaining to your ISP, but in this case they will have a connecting
ISP.)

7. Using a firewall DENY rule only works if the spammer is connecting
directly to your system to drop the mail in a local SMTP server. If
you connect out to a server to pick up your mail a firewall rule won't
work.

8. I use filter rules in my email software. When I get spam, I look
up the valid IP address(es) in the headers at ARIN. If I find that
the associated class A network belongs to APNIC, I add a filter rule
to trash all messages with an IP address from that class A network
anyplace in the headers. If I were to need to receive email from
someone who uses APNIC connections and/or servers, I would create an
appropriate filter rule and put it higher on the list.

Ken



Relevant Pages

  • RE: [PHP] PHP Mailer and SMTP = SPAM?
    ... report back to some of the lists marking you as a spammer. ... So even that I send from thedomain.com SMTP server I should to set the FROM ... www.lauri.se - personal website ...
    (php.general)
  • Re: Cant send email
    ... I have the correct incoming and outgoing settings. ... Message could not be sent because connecting to SMTP server ... Second, if you're *certain* that your email client is configured with your correct email address and corresponding password, the most likely reason for this message is that you are attempting to use the SMTP server from your ISP but you are connected to the Internet using a different ISP. ...
    (microsoft.public.windowsxp.general)
  • Mail-Internet problem
    ... This is a Red Hat Linux box connecting to the internet over ... I am using my ISP's SMTP server. ... my ISPs spam filter. ... The following script, when executed, appears to do nothing at all; ...
    (perl.beginners)
  • Re: Email Filter at router? [K9 help?]
    ... POP3 settings as changed by K9, then your SMTP server doesn't recognize the ... POP3 settings for K9 in the email client are parsed by K9 before connecting to ... that order in response to prompts from the server as parsed by K9 to username; ...
    (comp.security.firewalls)
  • RE: smtp error 550
    ... are connected to their network you cannot send to any other SMTP server. ... Instead of using Earthlink's SMTP server you should use your ISPs SMTP Smart ... > as connecting from an EarthLink connection. ...
    (microsoft.public.exchange.admin)