Re: TCPIP Services for OpenVMS V5.4 ECO1 anti spam feature

From: John E. Malmberg (wb8tyw_at_qsl.network)
Date: 05/29/04


Date: Sat, 29 May 2004 00:12:23 -0400

Jonathan Boswell wrote:
>
> Oh rats. That explains why it's not working. So by "client", HP really
> means "last relay". This is useless in my present circumstance since I have
> never seen the outblaze.com spammers use the same relay twice.

Outblaze is known for prompt nuking of spammers or blocking of any spam
sources, but they are are a very large ISP for their geographical area.

 From every anti-spam forum on the Internet that I monitor, Outblaze is
well known to terminate spammers on their networks as fast as possible.

Much faster than many other ISPs.

You can not trust the I.P. address that a relay that delivers spam to
you claims it got it from, unless you control the relay.

Spammers routinely inject spam through a compromised machine with fake
headers to make it look like it came from another network.

Essentially they are expecting that if the mail server accepted the
spam, then the any user content filter would then check the fake headers
that the spammer inserted, and send the abuse report there.

If you get a spamcop.net account (free and paid versions available) you
can use the parser showing technical details to see where the parser is
detecting the spam coming from. This is good for a postmortem to
improve your spam defenses.

[Care is needed when reporting spam through spamcop.net. while usually
accurate, it can by mistake allow you to report your own mailserver as
the source of the spam]

As a mail message passes through each relay, a line is added by each to
indicate the path.

The spamcop.net parser checks each line from the mail servers from the
last one to see if every thing matches, and also checks several public
reports to see if the alleged mail server is listed as a DHCP host, open
proxy, or open relay.

If the spamcop.net parser finds a mis-match in what the relay claims to
be it's name and the names that it's DNS servers give for it, or if it
finds that an open relay, open proxy, or apparent DHCP address, it stops
the parse and does not trust it further.

It is a more sophisticated test than most spam filters, and while not
perfect, it is pretty accurate. It does make the occasional error,
either due to software bugs, misconfigured DNS servers, or general
internet errors that can give incorrect DNS information.

-John
wb8tyw@qsl.network
Personal Opinion Only



Relevant Pages

  • Re: [Full-Disclosure] Im calling for LycosEU heads and team to resign or be sacked
    ... To go back to a previous message; in attacking spammers, ... I run a small mail server that services about 10 domains. ... I have approximately 500MB of spam stored on my server. ... bandwidth fees to upload disk images to a remote server. ...
    (Full-Disclosure)
  • Re: [Full-Disclosure] Im calling for LycosEU heads and team to resign or be sacked
    ... I woud recommend a nice email detailing the real damage and spiritual damage caused by spam, aned what they might do to find a better way to make a living.. ... Lots of spammers are simply trying to make a living, and don't feel they have other options. ... How will we pay for damages, ... I run a small mail server that services about 10 domains. ...
    (Full-Disclosure)
  • Re: Bad case of Spam Fatigue, Can anyone help
    ... When spammers start testing a new domain they often configure such programs to send spam to randomly made up user names. ... When the spammer sells the lists, and the list gets resold over and over this activity can quickly grow exponentially to a point where it can overload a small mail server. ... SPF is a protocol that lets you publish via a DNS record what your outgoing mail servers are so that when another server receives an email with your domain name in the from header, it can check your SPF policy to see if the IP is allowed by you or not. ...
    (comp.mail.misc)
  • Re: TMDA and other challenge-response systems considered harmful
    ... > They are also a pain in the neck when you get a CR sent to a ... > months on my own mail server and found that I was severely defeated ... > system to whitelist their spam into my server. ... what nice spammers you meet: ...
    (Debian-User)
  • Re: Sendmail queue warning rewrite
    ... up because one email got delayed while sending to aol because aol ... blocked our relay before I setup their loopback system because someone ... sent spam to our mail servers which then sent a NDR back to ... better without any need to change behavior users may expect. ...
    (comp.mail.sendmail)