Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » MCI Boots Send-Safe » Public pressure works against prominent companies
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
« So what's this got to do with Vint Cerf?  
AuthorAll Replies

robscullion
Premium
join:2001-12-07
Philadelphia, PA
·Speakeasy

reply to Mr Pilkington
Re: Public pressure works against prominent compan

Just for the sake of argument, I think you'd have to also block any direct outbound DNS queries from the zombies (client PCs) to outside DNS servers in order to make this at all feasible. Otherwise, the zombies could just skip the local DNS server and do an end-run around the whole system by querying the remote DNS servers directly.

But isn't the point here that the referenced spam software is sending via the zombie ISP's SMTP server? In that case, there's no MX DNS query involved. I don't even see how you can really differentiate the zombie software from the legitimate user. The zombie just sends to the ISPs SMTP server and that server takes care of all the forwarding for it.

Maybe if all ISPs forced authentication for sending even from within their own network it would put a dent in Send Safe type systems. Does this Send Safe stuff steal auth info from the user's local legit email software? If so, I guess that'd be a dead end as well. Otherwise, going to a system that requires authentication over a secure channel for sending email might at least curb the effectiveness of this particular method.


pcscdma
Chocobo Chocobo Random Battle
Premium
join:2004-01-14
Winterset, IA
clubs:
reply to Mr Pilkington
said by Mr Pilkington:

... and hoping others will do the same in return.
That's the hard part.



Mr Pilkington

@ip.alltel

reply to TKJunkMail
Ha ha ha - I don't think it's even near the final solution against spam. I do think it's one that hasn't been tried yet.

Matchstick - You *do* allow your mail server to look up outside MXs. You just don't allow any other IP range(s) to do the same. And, your DNS server would allow anyone to request its own records. For example, if you are bob.com, anyone can pull the bob.com MX records. However, if a bob.com user's IP wants joe.com's MX address, the request is denied. If bob.com's email server wants joe.com's MX, it's allowed.

pcscdma - Your description is correct. However, the spambots do that entire process on your machine; they're their own mail server. That's why they shouldn't have access to MX records in the first place.

pog - There would be no true "whitelist" to manage and actually not much "management" at all. Simply block MX records from all except a few subnets or IP ranges.

I don't think anyone is thinking far enough into it before instantly deeming it useless. You're not blocking *your* MX records from ouside sources. You're preventing your users' PCs from obtaining ouside MX's and hoping others will do the same in return.
Forums » MCI Boots Send-Safe« So what's this got to do with Vint Cerf?  


Tuesday, 01-Dec 20:41:58 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [124] Comcast Releasing Promised Usage Meter
· [67] Baltimore To Ban Lazy Cable Installs
· [55] Broadband Killed The Game Console
· [46] Rogers Unveils The ISP Dream Model
· [39] Rural Carriers Quickly Embracing Fiber
· [35] Charter Exits Chapter 11
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [30] ACTA: Global Three Strikes
· [30] Latest Consumer Reports Survey Not Kind To AT&T
· [24] Midcontinent Socked With Easement Lawsuit
Most people now reading
· [Internet] Gaming problem for "Heroes of Newerth" ( New bell Upd [Bell Canada]
· [Phish] email from CDC "personal vaccination profile" [Spam, Scam and Phishbusters]
· Am I the only one that loves to work in IT? [No, I Will Not Fix Your #@$!! Computer]
· Why Criminals (Hackers) Must Not Be Rewarded [Security]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Windows 7 boot manager editing questions [Microsoft Help]
· Considering Leaving Vonage, who should I Consider? [VOIP Tech Chat]
· Need a better layout.. [Home Repair & Improvement]
· [Newsgroups] Newzleech down? [Filesharing Software]
· persistent connection to qw-in-f113.1e100.net on boot [Security]