Re: Spam

From: Moe Trin (ibuprofin_at_painkiller.example.tld)
Date: 11/23/04


Date: Tue, 23 Nov 2004 13:12:47 -0600

In article <JGyod.448657$D%.235864@attbi_s51>, Robert Folkerts wrote:

>JC wrote:
>> My firewall logs indicate that a site in China is sending me spam packets
>> on port 1027

[snip]

>However, that doesn't mean that you can't mount a defense that makes
>attacking you expensive. If you are willing to install OpenBSD as a
>firewall, you can use their spamd. See http://www.openbsd.org/spamd/
>for a description.

Not impressed. I really would have expected something better out of
OpenBSD. You also seem to have missed the fact that the original
poster is complaining about 'messenger spam' (windoze pop-up ads
delivered via UDP to port 1027) not email.

>The basic idea is to 1)get a list of known spammers and route the
>traffic to spamd. Spamd has been written to return (perhaps slowly) a
>450 or 550 reutrn code. The 450 return code results in the email being
>returned to the sender's queue. If the spammer's account starts to get
>lots of returned emails, their ISP will be faced with extra traffic and
>storage.

The concept is wrong. You (or the program author) are assuming that the
spammer actually cares about return codes. First, most spam is delivered
from zombie PCs that are running a spam daemon, NOT A MAIL TRANSPORT AGENT
and are just shoveling sh1t out to your mail server. A 4xx or 5xx code
merely causes the spam daemon to move on to the next address. Delays in
returning the code have little effect on the spammer - hell, he's often
not even in the same country as the system trying to deliver the spam,
so he won't know OR CARE about delays. Have you ever seen one of the
"Millions" CDs (literally a CD with several million "valid" email
addresses - cost about $30 to $150, depending on how much the source
thinks they can rip off)? Despite claims of high numbers of "valid"
addresses, a lot of them are bad. Do you _really_ think a spammer is
waiting for result codes when upwards of HALF of the names are returning
a 550 (user unknown)? Hey, he's got a spam run of 5 to 10 million to
get out - he doesn't have that kind of time to waste.

As far as returning the spam to the sender's queue, please give an
indication of how often you have ever seen a 450 return code (4xx being
a transient condition - telling the remote mailer to try again later)
result in later retries? One of my ISP's recently had a fire, which
knocked the domain completely off the world for 12 hours. Looking at
the 'spam count' for that day showed about half the historical average
for that day - while ordinary mail (sent from real mail servers) ran
about normal.

        Old guy



Relevant Pages

  • Re: content filtering
    ... opinion on experience that's limited to dealing with domestic US ... Considering that the large majority of spam originates from the US, ... Now all you need is some method of identifying the sender. ... 550 code would come to the attention of the mail server admin who could ...
    (microsoft.public.exchange.admin)
  • Re: anti spam sw?
    ... It only tags suspect mail as spam. ... Bayesian filtering should ALWAYS be the *last* mechanism used to detect spam since it is a guessing scheme based on word weigthing over a historical sample set experienced by just one particular user. ... I also use the MXblocking plug-in because I don't want mails sent from dynamically IP addressed hosts. ... If someone wants to operate their own mail server then let them get a static IP address. ...
    (alt.computer.security)
  • Re: Massive Drug and Porn E-mail
    ... There are two main places to block spam: ... Does your company have an IT department, and its own mail server? ... spammer, and you're still downloading the spam. ... A lot of spam uses stupid tricks to try to fool simple filters. ...
    (microsoft.public.outlook.general)
  • Re: Outlook Express Undeliverable
    ... If your client is not getting an NDR message back from ... his mail server (which means his sending mail server got rejected during the ... Maybe you have server-side spam filtering enabled and his mails ... sender is infected so his mails could also be infected. ...
    (microsoft.public.internet.mail)
  • Re: How does Cron send email?
    ... Spam is invariably sent from somebody else's computer ... or through a mail server configured as an open ... Windows machine that uses your ISP e-mail server to connect to. ... have much problems with supporting the SPAM from machines they service ...
    (Debian-User)