> I  know  more email admins repulsed by RBLs than I know spammers, so
> I'm open to many possibilities.

As  an honest guy, you wouldn't be expected to know more spammers than
legit  admins,  so  that's not statistically valid! Are the admins you
know sufficiently criminally minded, confident, connected, and skilled
to  mount  a DDoS attack? Note that the DNS-based blacklists that have
been  taken  down of late weren't exactly cutting-edge: MONKEYS wasn't
the  enemy  of  a legit-hearted and technically skilled sysadmin; with
the  exception of the cross-posted OSSRC (which could hardly have been
the main target, since it carried as much harm for the people who used
it  exclusively  as  for those listed), OsiruSoft wasn't a champion of
collateral damage. No, I think you're taking a grand leap of logic.

Spammers,  whose  income  is proportional to their ability to get spam
delivered  (and  thus  acted  upon), are far more direly threatened by
public  blacklists than full-time sysadmins of legit servers. But it's
not  just  a qualitative question of how deeply one's ox is gored, but
also  a binary one: who's going to go over to the other side vs. who's
already   *on*  the  other  side?  So  your  server  was  accidentally
blacklisted for false positives, and you're justly fit to be tied, but
mounting  a  DDoS?  You didn't have a PTR, so you're going to commit a
criminal  act?  Your  employer  is  using a provider that derives huge
revenue from spammers, and is therefore blacklisted by association, so
you  decide  to mount an attack that could land you in jail instead of
getting  another  provider? Your legit webmail business is going under
because  you  didn't  actively police your traffic as the spam problem
grew, so you're going to spend your last dime and time taking this out
on  the blacklists, rather than realizing that your business model was
not sustainable?

Look,  I've  gone on record against collateral blacklisting, as I know
there  can  be  substantial  business  impact  that  will be blamed on
techies,  but--maybe  this is just hopeful me--I can't believe there's
*yet*  been  enough  outright  loss  of  income or position to explain
attacks   like   this   being  conducted  by  formerly  legitimate  IT
professionals.  I think you're dealing with contract hackers, probably
non-US  in  origin,  hired  by  a consortium of spammers. You could be
right, but I'd bet against you.

> And NEVER underestimate a kid in his basement.

I'd  hope  there  aren't  many  kiddies who find room in the "hacker's
creed"  for  DDoSing  anti-spam  blacklists. If there are, they're not
growing them like they used to. :) And a kiddy who's directly employed
by spammers is no longer an experimenting white hat.

-Sandy


------------------------------------
Sanford Whiteman, Chief Technologist
Broadleaf Systems, a division of
Cypress Integrated Systems, Inc.
e-mail: [EMAIL PROTECTED]
------------------------------------


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to