<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Public pressure works against prominent companies in </title>
<link>http://www.dslreports.com/forum/r12799689</link>
<description></description>
<language>en</language>
<pubDate>Sat, 28 Nov 2009 09:10:01 EDT</pubDate>
<lastBuildDate>Sat, 28 Nov 2009 09:10:01 EDT</lastBuildDate>

<item>
<title>Re: Public pressure works against prominent compan</title>
<link>http://www.dslreports.com/forum/remark,12810522</link>
<description><![CDATA[<A HREF="/useremail/u/533476"><b>robscullion</b></A> : That rhyolite link is great! I agree...it should definitely be required reading.<br><br>I'd say lurking in NANAE (&raquo;<A HREF="http://groups-beta.google.com/group/news.admin.net-abuse.email" >groups-beta.google.com/group/new&middot;&middot;&middot;se.email</A>) for a month should be considered required as well, but that'd fall into the category of "cruel and unusual punishment".]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12810522</guid>
<pubDate>Wed, 02 Mar 2005 12:17:41 EDT</pubDate>
</item>

<item>
<title>Re: Public pressure works against prominent compan</title>
<link>http://www.dslreports.com/forum/remark,12810401</link>
<description><![CDATA[<A HREF="/useremail/u/533476"><b>robscullion</b></A> : Just for the sake of argument, I think you'd have to also block any direct outbound DNS queries from the zombies (client PCs) to outside DNS servers in order to make this at all feasible. Otherwise, the zombies could just skip the local DNS server and do an end-run around the whole system by querying the remote DNS servers directly.<br><br>But isn't the point here that the referenced spam software is sending via the zombie ISP's SMTP server? In that case, there's no MX DNS query involved. I don't even see how you can really differentiate the zombie software from the legitimate user. The zombie just sends to the ISPs SMTP server and that server takes care of all the forwarding for it.<br><br>Maybe if all ISPs forced authentication for sending even from within their own network it would put a dent in Send Safe type systems. Does this Send Safe stuff steal auth info from the user's local legit email software? If so, I guess that'd be a dead end as well. Otherwise, going to a system that requires authentication over a secure channel for sending email might at least curb the effectiveness of this particular method.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12810401</guid>
<pubDate>Wed, 02 Mar 2005 12:02:17 EDT</pubDate>
</item>

<item>
<title>Re: Public pressure works against prominent compan</title>
<link>http://www.dslreports.com/forum/remark,12810001</link>
<description><![CDATA[<A HREF="/useremail/u/932022"><b>pcscdma</b></A> : <div class="bquote"><SMALL>said by Mr Pilkington:</SMALL><br><br>... and hoping others will do the same in return.<br> </DIV>That's the hard part.<br><br>:p]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12810001</guid>
<pubDate>Wed, 02 Mar 2005 10:57:51 EDT</pubDate>
</item>

<item>
<title>Re: Public pressure works against prominent compan</title>
<link>http://www.dslreports.com/forum/remark,12808076</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Ha ha ha - I don't think it's even near the final solution against spam.  I do think it's one that hasn't been tried yet.<br><br>Matchstick - You *do* allow your mail server to look up outside MXs.  You just don't allow any other IP range(s) to do the same.  And, your DNS server would allow anyone to request its own records.  For example, if you are bob.com, anyone can pull the bob.com MX records.  However, if a bob.com user's IP wants joe.com's MX address, the request is denied.  If bob.com's email server wants joe.com's MX, it's allowed.<br><br>pcscdma - Your description is correct.  However, the spambots do that entire process on your machine;  they're their own mail server.  That's why they shouldn't have access to MX records in the first place.<br><br>pog - There would be no true "whitelist" to manage and actually not much "management" at all.  Simply block MX records from all except a few subnets or IP ranges. <br><br>I don't think anyone is thinking far enough into it before instantly deeming it useless.  You're not blocking *your* MX records from ouside sources.  You're preventing your users' PCs from obtaining ouside MX's and hoping others will do the same in return.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12808076</guid>
<pubDate>Wed, 02 Mar 2005 01:24:25 EDT</pubDate>
</item>

<item>
<title>Re: Public pressure works against prominent compan</title>
<link>http://www.dslreports.com/forum/remark,12802856</link>
<description><![CDATA[<A HREF="/useremail/u/1018019"><b>pog</b></A> : a) compiling and maintaining the required whitelist is not some trivial task.  I'd think it's cumbersome/tedious/problematic enough that that alone would deter anyone from going for it.<br><br>b) what about the case where an ISP's caching DNS server is used by more than one class of user (ie residential, business users, their own mail servers, etc).  How will you decide which request you will honor and which you won't?  Perhaps you're thinking to force each mail server into running their own local DNS?<br><br>c) this doesn't seem much different than existing firewalling/blocklisting <B>except</B> that your protection is indirect... it wouldn't take much for an attacker to learn the IP address of the intended victim and then feed it manually to the zombies and then... what?  The path is clear?<br><br>So... <B>no</B>... your approach would be far more ineffective, restrictive and inconvenient than an outbound/off-net block of port 25 traffic which does a better job of destroying a zombie's SMTP abilities.  Of course, we don't need to rehash the pros/cons of port 25 blocking here... that's another topic altogether.<br><br>Perhaps, the following should be required reading :)<br>&raquo;<A HREF="http://www.rhyolite.com/anti-spam/you-might-be.html" >www.rhyolite.com/anti-spam/you-might-be.html</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12802856</guid>
<pubDate>Tue, 01 Mar 2005 15:51:36 EDT</pubDate>
</item>

<item>
<title>Re: Public pressure works against prominent compan</title>
<link>http://www.dslreports.com/forum/remark,12801426</link>
<description><![CDATA[<A HREF="/useremail/u/932022"><b>pcscdma</b></A> : I thought that MX records were for telling SMTP servers where to send the mail.<br><br>I'll send a mail to someone at dslreports.com using my ISP<br>My email client is configured to send stuff to mail.mchsi.com<br>My email client looks up mail.mchsi.com using my ISP's DNS lookup servers 204.127.202.4 or 216.148.227.68<br>It either finds it in the cache or tells me to go the dns server for that domain or does it itself (confused on how this part works)<br>My email client connects to 204.127.203.151 and sends the message<br>mail.mchsi.com (204.127.203.151) sees that I'm sending something to dslreports.com<br>mail.mchsi.com (204.127.203.151) looks up the DNS server of dslreports.com or finds it in cache using it's DNS server (probably the same as mine)<br>It looks to see if there is an MX record and if it finds one it uses it and looks up the IP address of them using DNS because the addresses are URLs<br>It tries the lowest priority number and goes up until it connects to one<br>If it doesn't find an MX record it just uses the web server (209.123.109.175)<br>It connects using one of the methods above and sends it on it's way<br><br>This is at least how I understand it.<br><SMALL>--<br>"The bad news is that we are told that Michael Powell, one of Washington's better bureaucrats, is calling it quits today after four years at the helm of the Federal Communications Commission." - WSJ 2005/01/21</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12801426</guid>
<pubDate>Tue, 01 Mar 2005 13:05:37 EDT</pubDate>
</item>

<item>
<title>Re: Public pressure works against prominent compan</title>
<link>http://www.dslreports.com/forum/remark,12800731</link>
<description><![CDATA[<A HREF="/useremail/u/471549"><b>Matchstick</b></A> : Errrm I'm no DNS expert but AIUI, if a SMTP server asks a DNS server for an MX record for which it is non-authoritative, the only way for the DNS server to find the MX record is to request it from a DNS server which *is* authoritative for the domain.<br><br>So if this is correct, you HAVE to continue to allow DNS requests for MX records from outside a small ACL of IPs.<br><br>And then how can the authoritative DNS server easily tell the difference between a legitimate request from a non-authoritative DNS server and a request direct from a zombied PC ?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12800731</guid>
<pubDate>Tue, 01 Mar 2005 11:43:34 EDT</pubDate>
</item>

<item>
<title>Re: Public pressure works against prominent compan</title>
<link>http://www.dslreports.com/forum/remark,12800558</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Again, allow me to point out that the "zombie networks" would be completely ineffective if a DNS server refused all local MX record requests except from its own mail servers.  Regular users have no need for MX lookups except for serving spam.<br><br>MX requests from "the world" would be answered only for domains for which the server is authoritative.  The only machines that could request any MX record would be those IPs listed in a conf file -- like your mail and web servers for example.<br><br>Think about it - it's much less restricting and inconvienent than a blanket filter on port 25.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12800558</guid>
<pubDate>Tue, 01 Mar 2005 11:22:15 EDT</pubDate>
</item>

<item>
<title>Re: Public pressure works against prominent compan</title>
<link>http://www.dslreports.com/forum/remark,12799724</link>
<description><![CDATA[<A HREF="/useremail/u/732594"><b>ronpin</b></A> : :><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap WIDTH=33%><A HREF="/speak/slideshow/12799724?c=783267&ret=L2ZvcnVtL3IxMjc5OTY4OS54bWw%3D"><IMG TITLE="6446 bytes" BORDER=0 WIDTH=175 HEIGHT=131 SRC="/r0/download/783267~a2327f6b1c7614314df40001ce26382e/Bernie.jpg"></A><br>Meet my new Board of Directors, capishe?</TD><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=2 WIDTH=66%><A HREF="/speak/slideshow/12799724?c=783268&ret=L2ZvcnVtL3IxMjc5OTY4OS54bWw%3D"><IMG TITLE="27375 bytes" BORDER=0 WIDTH=350 HEIGHT=230 SRC="/r0/download/783268~2e932e05fab7c234a228d055876cb81a/tony.jpg"></A><br>Spam? -- I dun see no spam here eh Tony?</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12799724</guid>
<pubDate>Tue, 01 Mar 2005 09:21:15 EDT</pubDate>
</item>

<item>
<title>Re: Public pressure works against prominent companies</title>
<link>http://www.dslreports.com/forum/remark,12799697</link>
<description><![CDATA[<A HREF="/useremail/u/141383"><b>Karl Bode</b></A> : Only when it's blatantly obvious to even the dimmest that what they're doing is wrong.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12799697</guid>
<pubDate>Tue, 01 Mar 2005 09:16:55 EDT</pubDate>
</item>

<item>
<title>Re: Public pressure works against prominent companies</title>
<link>http://www.dslreports.com/forum/remark,12799689</link>
<description><![CDATA[<A HREF="/useremail/u/610550"><b>RR Conductor</b></A> : Sometimes.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12799689</guid>
<pubDate>Tue, 01 Mar 2005 09:15:57 EDT</pubDate>
</item>

<item>
<title>Public pressure works against prominent companies</title>
<link>http://www.dslreports.com/forum/remark,12799684</link>
<description><![CDATA[<A HREF="/useremail/u/594412"><b>TKJunkMail</b></A> : Public pressure often works against prominent companies. Secondary income sources that are kind of sleazy can often be squashed because a company like MCI fears losing their more lucrative primary business.<br><br><A HREF="http://tinyurl.com/4zmr3"><B>My Web Page</B></A><BR><A HREF="http://spaces.msn.com/members/tkjunkmail/"><B>My Blog</B></A><BR><A HREF="http://tinyurl.com/5eurx"><B>Join Red Room Forum</B></A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,12799684</guid>
<pubDate>Tue, 01 Mar 2005 09:15:11 EDT</pubDate>
</item>

</channel>
</rss>
