The part I just do not understand is this;

Ask any average e-mail user if they have ever bought something from a
spam message and I am sure you will get a NO from 99 percent of them. In
fact, mot people will NOT do business with a company that uses spam to
send their flyers. You seen what happened when one of those political
people got caught doing it, they were all over his butt.

The only thing that I can think of is that someone is offered a deal
that sounds so good. Like 1 million e-mailings over a 6 month period. I
am sure the spammers have their software in place to mail it out with
just a click or two of the mouse. I have no ideal what it costs to have
a company spam for you, but just grabbing a random number like 500 bucks
for 1 million mailings over a 6 month period. The company can now just
spend 500 bucks for advertising that he can of course wipe out. I am
sure there sales pitch to the poor company says, if you just get 1
percent of everyone we mail to come to your business and you sell to 1/2
of them; that is 5000 sales for you. All for a measly 500 bucks!

This has to sounds very inviting for the poor proprietor. Little does he
know that a very small percentage of that million will even receive the
mail, since spam filters are spreading around to the mail servers and to
the end user's computer.

Even when the government starts slapping the wrists of spammers, they
will head over to other countries that will allow them to spam all they
want.

Will this ever end?

Larry Anderson


-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Len Conrad
Sent: Saturday, September 13, 2003 10:10 PM
To: [EMAIL PROTECTED]
Subject: [IMail Forum] example: analysis of traffic from charter.com
subscriber networks


Many Imail admins don't have the tools nor the IMail log data to do such
an 
analysis, so I post this here to support my position that all subscriber

networks merit blanket blocking.

For maillog of yesterday, Friday. I chose a "business" day when there
would 
be fighting chance of seeing legitimate traffic from a subscriber 
network.  :))

I chose charter.com because, well, because all subscriber networks
stink.

What are the total connects from IPs with PTR charter.com:

# zegrep -ic " connect from.*\.charter\.com" /postfix/log/maillog.1.gz
1200

What are total rejects for charter.com PTRs:

# zegrep -ic "reject:.*\.charter\.com" /postfix/log/maillog.1.gz
1767

So we are doing an average of 1.5 rejects from every connect session
from a 
charter PTR.  At the top level, it already sounds bad.  What could those

charter customers possibly be up to??

For all the charter.com connect sessions, how many sessions did we hang
up 
on because charter hit our limit of 3 each 5xx rejects per session:

# zegrep -ic "too many.*\.charter\.com" /postfix/log/maillog.1.gz
745

So it seems like charter users are very insistent on sending us SMTP 
commands that we repeatedly respond to with 5xx within the same SMTP 
session.  Tisk tisk, sounds very naughty indeed.

To give you some perspective, for the msgs that we accepted from all 
domains, here's the distribution of "number of recipients", nrcpt, per
msg:

   22665 nrcpt=1
     338 nrcpt=2
      98 nrcpt=3
      32 nrcpt=4
      25 nrcpt=5
      11 nrcpt=6
       3 nrcpt=9
       3 nrcpt=7
       3 nrcpt=25
       3 nrcpt=17
       2 nrcpt=8
       2 nrcpt=14
       2 nrcpt=12
       1 nrcpt=26
       1 nrcpt=19
       1 nrcpt=18
       1 nrcpt=15
       1 nrcpt=11
       1 nrcpt=10

22665 / (22665 + 530) = 98% of all msgs through this MX are for one
recipient.

But for charter, 63% of all their sessions are generating 3 5xx errors,
as 
if charter clients were attempting to send at least 3 RCPT TO's per
session 
(at which point we hang up), which would have placed them under 2%, not
at 
63%.  This looks very, very bad, charter.

Total rejects due to unknown users:

# zegrep -ic "reject:.*recipient table.*\.charter\.com" 
/postfix/log/maillog.1.gz
1100

Wow, those charter customers really have a LOT of bad recipients for our

domains.  Probably just a bunch of typo's, right?

Let's disregard the above "unknown user" traffic since that's obviously 
illegit. No need to look at it further, it's traffic not for our users
anyway.

Let's see what the traffic looks like to our "known users" from 
charter.com, since, if there are any candidates for the dreaded false 
positives, they would be in the msgs to our known users.

The following is the MAIL FROM: and HELO fields sent to our known users 
from IPs with charter.com PTRs.

But let's break this longish list into two groups:

1) when the helo hostname contains charter.com, and

2) when it doesn't.

For HELO containing charter.com to our known users, what do the FROM
fields 
look like, sorted by sender@:

from=<[EMAIL PROTECTED]>
helo=<4476d0252.knnwck.wa.charter.com>
from=<[EMAIL PROTECTED]> 
helo=<c66.169.176.92.ts46v-08.otn-c2.ftwrth.tx.charter.com>
from=<[EMAIL PROTECTED]>  helo=<24-240-224-119.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-68-116-161-138.ma.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-68-187-233-216.vt.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-24-151-130-250.ma.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-68-118-229-107.ma.charter.com>
from=<[EMAIL PROTECTED]>
helo=<66-168-65-97.wb.wi.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-68-118-180-136.ma.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-24-196-206-123.hkry.nc.charter.com>
from=<[EMAIL PROTECTED]>
helo=<24-196-150-99.mazo.wi.charter.com>
from=<[EMAIL PROTECTED]>
helo=<cpe-68-115-215-099.spa.sc.charter.com>
from=<[EMAIL PROTECTED]>  helo=<24-240-143-9.charter.com>
from=<[EMAIL PROTECTED]>  helo=<jennifer.cpe.mvllo.al.charter.com>
from=<[EMAIL PROTECTED]>  helo=<66-188-103-25.mad.wi.charter.com>
from=<[EMAIL PROTECTED]> 
helo=<c68.113.212.39.ts46v-09.otn-d1.ftwrth.tx.charter.com>
from=<[EMAIL PROTECTED]>  helo=<dell1.cpe.mvllo.al.charter.com>
from=<[EMAIL PROTECTED]> 
helo=<c68.113.212.197.ts46v-09.otn-d1.ftwrth.tx.charter.com>
from=<[EMAIL PROTECTED]> 
helo=<c66.169.165.73.ts46v-12.otn-e2.ftwrth.tx.charter.com>
from=<[EMAIL PROTECTED]>  helo=<4476d614.wlawla.wa.charter.com>
from=<[EMAIL PROTECTED]>  helo=<66-191-38-134.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-24-107-234-98.ma.charter.com>
from=<[EMAIL PROTECTED]>  helo=<c24.197.242.97.spt.wi.charter.com>
from=<[EMAIL PROTECTED]>  helo=<24-216-100-33.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-68-118-229-107.ma.charter.com>
from=<[EMAIL PROTECTED]>  helo=<c24.197.242.97.spt.wi.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cable-24-158-216-175.sli.la.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-24-107-234-98.ma.charter.com>
from=<[EMAIL PROTECTED]> 
helo=<cpe-24-159-170-136.spa.sc.charter.com>
from=<[EMAIL PROTECTED]>
helo=<dell1.cpe.mvllo.al.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-68-116-161-138.ma.charter.com>
from=<[EMAIL PROTECTED]>
helo=<c24.197.242.97.spt.wi.charter.com>
from=<[EMAIL PROTECTED]>
helo=<cpe-68-119-223-243.hkry.nc.charter.com>
from=<[EMAIL PROTECTED]>  helo=<charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-66-189-24-115.ma.charter.com>
from=<[EMAIL PROTECTED]>  helo=<66-191-125-181.mad.wi.charter.com>
from=<[EMAIL PROTECTED]>  helo=<24-159-232-84.jvl.wi.charter.com>
from=<[EMAIL PROTECTED]>  helo=<c68.117.105.87.ash.wi.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-66-189-24-115.ma.charter.com>
from=<[EMAIL PROTECTED]> 
helo=<c68.113.212.197.ts46v-09.otn-d1.ftwrth.tx.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-24-197-103-076.spa.sc.charter.com>
from=<[EMAIL PROTECTED]>
helo=<cpe-66-189-11-213.ma.charter.com>
from=<[EMAIL PROTECTED]> 
helo=<c66.169.114.7.ts46v-04.otn-a2.ftwrth.tx.charter.com>
from=<[EMAIL PROTECTED]>  helo=<c68.117.53.235.rose.mn.charter.com>
from=<[EMAIL PROTECTED]>  helo=<66-188-111-60.mad.wi.charter.com>
from=<[EMAIL PROTECTED]>
helo=<cpe-24-197-117-106.spa.sc.charter.com>
from=<[EMAIL PROTECTED]>
helo=<c68.114.218.86.jvl.wi.charter.com>
from=<[EMAIL PROTECTED]>  helo=<24-196-127-39.fdl.wi.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-68-115-215-099.spa.sc.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-24-151-130-250.ma.charter.com>
from=<[EMAIL PROTECTED]> 
helo=<c68.113.212.39.ts46v-09.otn-d1.ftwrth.tx.charter.com>
from=<[EMAIL PROTECTED]>
helo=<cpe-66-169-53-183.spa.sc.charter.com>
from=<[EMAIL PROTECTED]> 
helo=<c68.116.218.74.ts46v-01.conroe.tx.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cable-24-158-216-175.sli.la.charter.com>
from=<[EMAIL PROTECTED]>  helo=<c68.117.105.87.ash.wi.charter.com>
from=<[EMAIL PROTECTED]>
helo=<c68.116.220.75.ts46v-01.conroe.tx.charter.com>
from=<[EMAIL PROTECTED]> 
helo=<c66.169.176.92.ts46v-08.otn-c2.ftwrth.tx.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-24-196-206-123.hkry.nc.charter.com>
from=<[EMAIL PROTECTED]>  helo=<66-188-111-60.mad.wi.charter.com>
from=<[EMAIL PROTECTED]>
helo=<c68.112.169.110.dul.mn.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-66-189-11-213.ma.charter.com>
from=<[EMAIL PROTECTED]>  helo=<66-188-208-141.roc.mn.charter.com>
from=<[EMAIL PROTECTED]>  helo=<c68.114.233.197.fdl.wi.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-24-197-117-106.spa.sc.charter.com>
from=<[EMAIL PROTECTED]>  helo=<cpe-24-197-103-076.spa.sc.charter.com>
from=<[EMAIL PROTECTED]>  helo=<c24.197.242.97.spt.wi.charter.com>

What a delightful relief!!  Every one of those MAIL FROM: to our users 
looks perfectly legitimate!! :))

The other group below is the mail addressed to our known users from
charter 
where the HELO does NOT contain charter.com.  That is, these endearing, 
earnest charter customers had the initiative and/or smarts to change the

HELO name to represent their "legitimate business domain".

As you go through this list, you will probably have to remind yourself
that 
these are from charter.com IPs:

from=<[EMAIL PROTECTED]>  helo=<24.159.170.136>
from=<[EMAIL PROTECTED]>  helo=<pldi.net>
from=<[EMAIL PROTECTED]> 
helo=<wild-college-party-videos.com>
from=<[EMAIL PROTECTED]>  helo=<girls-4-me.us>
from=<[EMAIL PROTECTED]>  helo=<drumandbass.de>
from=<[EMAIL PROTECTED]>  helo=<juergen-steckenreiter.de>
from=<[EMAIL PROTECTED]>  helo=<localhost>
from=<[EMAIL PROTECTED]>  helo=<localhost>
from=<[EMAIL PROTECTED]>  helo=<localhost>
from=<[EMAIL PROTECTED]>  helo=<localhost>
from=<[EMAIL PROTECTED]>  helo=<localhost>
from=<[EMAIL PROTECTED]>  helo=<localhost>
from=<[EMAIL PROTECTED]>  helo=<localhost>
from=<[EMAIL PROTECTED]>  helo=<localhost>
from=<[EMAIL PROTECTED]>  helo=<localhost>
from=<[EMAIL PROTECTED]>  helo=<localhost>
from=<[EMAIL PROTECTED]>  helo=<localhost>
from=<[EMAIL PROTECTED]>  helo=<localhost>
from=<[EMAIL PROTECTED]>  helo=<localhost>
from=<[EMAIL PROTECTED]>  helo=<localhost>
from=<[EMAIL PROTECTED]>  helo=<ozestock.com.au>
from=<[EMAIL PROTECTED]>  helo=<eudoramail.com>
from=<[EMAIL PROTECTED]>  helo=<80.232.219.81>
from=<[EMAIL PROTECTED]>  helo=<oberon.aif.msk.su>
from=<[EMAIL PROTECTED]>  helo=<pldi.net>
from=<[EMAIL PROTECTED]>  helo=<onlinehome.de>
from=<[EMAIL PROTECTED]>  helo=<margaret.mollerus.org>
from=<[EMAIL PROTECTED]>  helo=<margaret.mollerus.org>
from=<[EMAIL PROTECTED]>  helo=<alex-koenen.de>
from=<[EMAIL PROTECTED]>  helo=<modern-home.co.uk>
from=<[EMAIL PROTECTED]>  helo=<mailbox.as>
from=<[EMAIL PROTECTED]>  helo=<pldi.net>
from=<[EMAIL PROTECTED]>  helo=<gjr.paknet.com.pk>
from=<[EMAIL PROTECTED]>  helo=<orbit.de>
from=<[EMAIL PROTECTED]>  helo=<bldrbobs>
from=<[EMAIL PROTECTED]>  helo=<bldrbobs>
from=<[EMAIL PROTECTED]>  helo=<bormann.ws>
from=<[EMAIL PROTECTED]>  helo=<oricom.ca>
from=<[EMAIL PROTECTED]>  helo=<24.196.244.111>
from=<[EMAIL PROTECTED]>  helo=<onlinehome.de>
from=<[EMAIL PROTECTED]>  helo=<gjr.paknet.com.pk>
from=<[EMAIL PROTECTED]>  helo=<lycos.com>
from=<[EMAIL PROTECTED]>  helo=<lycos.com>
from=<[EMAIL PROTECTED]>  helo=<your-ink-place.com>
from=<[EMAIL PROTECTED]>  helo=<the-inkers-spot.com>
from=<[EMAIL PROTECTED]>  helo=<64.157.4.78>
from=<[EMAIL PROTECTED]>  helo=<microsoft.com>
from=<[EMAIL PROTECTED]>  helo=<isabell-berens.de>
from=<[EMAIL PROTECTED]>  helo=<sender1188>
from=<[EMAIL PROTECTED]>  helo=<sender1488>
from=<[EMAIL PROTECTED]>  helo=<worldcom.ch>
from=<[EMAIL PROTECTED]>  helo=<sto-helit.de>
from=<[EMAIL PROTECTED]>  helo=<yahoo.com>
from=<[EMAIL PROTECTED]>  helo=<mailer.com>
from=<[EMAIL PROTECTED]>  helo=<monty>
from=<[EMAIL PROTECTED]>  helo=<monty>
from=<[EMAIL PROTECTED]>  helo=<compuserve.com>
from=<[EMAIL PROTECTED]>  helo=<derpi.tuwien.ac.at>
from=<[EMAIL PROTECTED]>  helo=<bleau.de>
from=<[EMAIL PROTECTED]>  helo=<lycos.ne.jp>
from=<[EMAIL PROTECTED]>  helo=<mdi-ger.de>
from=<[EMAIL PROTECTED]>  helo=<24.196.14.173>
from=<[EMAIL PROTECTED]>  helo=<dplanet.ch>
from=<[EMAIL PROTECTED]>  helo=<tiscali.co.uk>
from=<[EMAIL PROTECTED]>  helo=<arti.vub.ac.be>
from=<[EMAIL PROTECTED]>  helo=<rons-house.de>
from=<[EMAIL PROTECTED]>  helo=<67.161.71.65>
from=<[EMAIL PROTECTED]>  helo=<tenbit.pl>

... did you forget? The above MAIL FROM + HELO fields are from
__CHARTER__ IPs.

Conclusion: absolute total crap from charter.com subscriber networks to
our 
known users.

( and remember, we have earlier already rejected 1100 msgs to unknown
users 
from charter.com. All in day's work over at charter.com! ).

So, in conclusion, the "single criteria" of a PTR hostname being in a 
charter.com subscriber subdomain is reliably indicative of mail 
abuse.  There is no need to accept the DATA command, scan the headers,
scan 
the body, screw around with multiple criteria.  The envelope info is 
sufficient, reject.

I have run the same analysis on subscriber network traffic from
comcast.com 
and hsia.telus.com ("High Speed Internet Access" up in Canada), and the 
results are the same.  Total crap.

So, it is a perfectly justifiable, defensible policy, based on hard, 
repeatable data such as the above, to define all subscriber PTR domains
to 
be illegitimate, (which means it is, by definition, impossible to have 
false positives).

There may be some vanishingly tiny number of legitimate mailers on 
subscriber networks dribbling out a few legit messages/day, but they are

illegitimate _by definition_ since they are on subscriber networks.

What can you expect to find as users and machines on subscriber
networks?:

* amateur and semi-pro home spammers

* machines with no firewall, so have been compromised.

* machines infected with mailer-worms, DDoS agents, and whatever else

* machines running as open relays being raped by spammers

* machines running as open proxies driven by hard-core proxy abusers

And that's just the situation today.

In the future, blanket blocking of subscriber networks will be even more

defensible and effective due to much higher volumes of subscriber
network 
IPs and their volumes of abusive traffic, because cable/DSL access,
still 
deploying widely in North Amreica, is now within reach of mass markets
in 
Europe, South America, Asia.

(I suppose the only continent with no subscriber network abuse is the 
continent that has essentially no subscriber networks, Africa).

You ain't seen nothing, yet.

Len


_____________________________________________________________________
http://MenAndMice.com/DNS-training: San Jose; Wash DC; Dallas; Atlanta
IMGate.MEIway.com: anti-spam gateway, effective on 1000's of sites, free


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to