Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Spam, Scam and Phishbusters » SORBS got my buddy
Search Topic:
Uniqs:
922
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[Spam] [Scam] Shinobia.com software »
« (topic move) AOL Warns that the Internet can be a bad place  
page: 1 · 2 · 3 · 4 · 5
AuthorAll Replies


sweintz
Premium
join:2002-03-01
Hamden, CT

reply to NormanS
Re: SORBS got my buddy

Norman-

Your points are correct, but do not address the issue I mentioned, which seems to be responsible for most of the backscatter I see the servers at $dayjob getting hit with - virus infected machines sending via their ISP's mail server with forged from and return path. The ISP's own user is the one sending the mail (although inadvertently). The forged address is one of the users in oir domain. The ISP's server get's a 550 when it tries to deliver the mail, and then sends the bounce to our server.

Very bad, IMO. When I get these, I complain to the ISP. MOST ISP's do not want to acknowledge this is a problem at all.

When I get a "it's not our problem" response, I gladly post the offending backscatter on news.admin.net-abuse.sightings, and also report it to SpamCop. If they get blacklisted because of this, well... that's not MY problem...

NormanS
Premium,MVM
join:2001-02-14
San Jose, CA
·Pacific Bell - SBC

Viral backscatter is a completely different issue from NDRs. Because no contemporary virus identifies the sending computer accurately, no server AV scanner should be sending notifies of viral infections. It is entirely possible to configure the MTA so that it sends NDRs to an authorized Return-Path address, but bins viral messages without sending notifies.
--
Norman
~Oh Lord, why have you come
~To Konnyu, with the Lion and the Drum


sweintz
Premium
join:2002-03-01
Hamden, CT


ER... No.

What I am talking about is not exactly viral backscatter.

What you mention is bad, and is a problem, but not as bad I what I am talking about.

What I am whining about is this:

ISP customer has a virus infected machine that tries to send a virus out via the ISP's mail server. The virus mail gets 550'ed on the receiving end (for whatever reason the receiving MTA refuses it -- perhaps it has a virus scanner that runs after the data command is issued but before the mail is queued, or perhaps a blocklist is used, or perhaps some other filtering - doesn't matter why, point is it gets a 550 error). ISP mail server sees the 550, and since it now knows it cannot deliver the email, it sends a NDR to the sender. Problem is the virus forges the sender envelope and header, so the NDR goes to some innocent 3rd party.


NormanS
Premium,MVM
join:2001-02-14
San Jose, CA
·Pacific Bell - SBC

I haven't seen a lot of evidence of that happening. That could be mitigated by requiring message submissions to be authenticated. It would force the virus to use the user's mail client instead of its own SMTP relaying client.
--
Norman
~Oh Lord, why have you come
~To Konnyu, with the Lion and the Drum
Forums » Up and Running » Security » Spam, Scam and Phishbusters[Spam] [Scam] Shinobia.com software »
« (topic move) AOL Warns that the Internet can be a bad place  
page: 1 · 2 · 3 · 4 · 5


Tuesday, 08-Dec 20:45:11 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [193] Sprint Sued For Distracted Driving Death
· [81] 3G Network Test Says AT&T Is Tops
· [71] Mediacom Unveils 105 Mbps Pricing
· [57] Sprint Poised For A Turnaround?
· [50] The Future Of Wi-Fi Is Bright
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [46] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [44] Microwaving Your Innards Is Not 'Extreme'
· [39] Verizon LTE: 5-12 Mbps Downstream
· [18] Verizon Settles With NJ Over Misleading FiOS Marketing
Most people now reading
· Servers UP!!! [World of Warcraft]
· CRTC Response to ME: You will be Band F FOREVER!!! [TekSavvy]
· Google chief: Only miscreants worry about net privacy [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· Account Hacked With Authenticator [World of Warcraft]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Comcast Customers: Would You Prefer Metered Billing? [Comcast HSI]
· World of Warcraft Client Patch 3.3 (12-8-2009) [World of Warcraft]
· SB6120 Firmware update [Comcast HSI]
· Man Downloads Child Porn "Accidentally," Faces 20 Years [Security]