As far as Lycos is concerned, I'm not a fan of vigilantism of this type, and it is often illegal to employ such tactics. If you would just imagine how many spam bots are out there under the control of these guys you would quickly see why you would not want their attention drawn to you. They can take down any site they want, and even just about any router on the Internet, which in turn can shut down millions of users. This has happened, and if you remember back in 2001, it was a teenager that shut down Yahoo, Amazon and Buy.com, and he had no financial interest in his dirty work. The Internet is just that delicate.
Proper enforcement can take down not just individual sites, it can take down million of messages a day sent by a single individual or group. I'm quite certain that about 90% of the spam is created by under 250 individuals or groups. If you think about the billions that are being spent now on anti-spam measures, one could easily conclude that it would be much less expensive to spend a few million and deputize some of us to hunt down and prosecute the offenders.
Another thing that is often overlooked is the importance of mail servers supporting AUTH-only connections on port 587. Once this is in wide use, broadband providers can shut off port 25 outgoing connections from their networks without interfering with legitimate mail traffic, and spam couldn't be sent on port 587 AUTH-only connections. SPF has gotten a great deal of attention in the past year, but it is only a drop in the bucket compared to the effectiveness of something as simple as port 587 AUTH-only. This would cure the vast majority of the zombie issue, and the only downfall would be that these spammers would in turn resort to focusing on hacking Internet servers instead, but the numbers would be far fewer and therefore easier to track.
Matt
Bill Foresman wrote:
I just think that the courts take too long with everything they do. Implementing the death penalty takes 15 years so how would a spammer even hit the radar screen.
I think the only justice we will have is what we do for ourselves. I'm disappointed that the Lycos SCR didn't take off because I don't think anything else will have an impact on them.
Matt wrote:
Bill,
I guess that I don't feel so distraught because I now do this as a business and I feel that it is also quite redeeming work. I do understand that most administrators aren't in the same boat and it does in fact take a good deal of work and understanding to do a decent job. Nevertheless, there are so many resources out there that people share for all to use which makes it not nearly as difficult as truly going it alone.
My primary blacklist is built to tag spammers that own their own IP space. Unfortunately Congress legalized the practice early this year, and there is no filtering mechanism that can tell a good advertisement from a bad one without some form of human intervention. Despite the labor involved with identifying such sources, once tagged, they are useless to spammers, at least for those that use one of these blacklists.
It's the zombie spammers and the tactics that they use with their armies of 10,000+ bots that worries me. Although this type of spam only accounts for maybe 20% of what gets through my system despite being sent in larger numbers, their tactics are dangerous and in the last two weeks, we have seen the zombie spam increase by 50% from 'dictionary attacks' (really they are just haphazardly sending to hundreds of thousands of non-existent addresses). These people are breaking the law, yet the government hasn't done one thing to enforce the law.
This type of tactic does require new capabilities. For instance, the sheer volume when paired with a spam and virus scanning system can prematurely overwhelm a system by a factor of 2 or more. To combat this, one needs for their gateway to do proper address resolution, and on IMail, one must remove all of the nobody aliases. If you gateway domains with IMail, you must add another layer to your system prior to IMail in order to handle this for those domains. These spammers have also done great harm to the NDR. Although we have managed to filter out the vast majority of the Joe-Job NDR's that are sent to our users, many NDR's don't contain the original content and one can't determine what is real or not with just computer logic. Unfortunately I don't know quite what to do here, especially since one spammer recently stopped playing nice (in a relative sense) and is hammering real addresses with Joe-Job NDR's for a week at a time, creating frustration among the users that are targeted by this tactic.
Personally, I feel that it is best for most administrators to hand the keys to their spam and virus blocking over to a service that achieves +99% block rates on spam (at present this excludes every large player in the business unfortunately). You can't expect that but a few percent can do this on their own, and it will cost everyone who does it at minimum a great deal of time, and often a fair deal of money. That's why I got into the business at least.
There are no magic bullets on the horizon, and the most effective means of stopping spam from being sent would be to start to enforce the law, and clearly that wouldn't stop but a portion of it. One only needs to look at what has happened with viruses to figure out the realities here. I'm afraid that this is the reality of the E-mail world now and everyone needs to come to grips with it.
Matt
Bill Foresman wrote:
We appreciate your work and all the other blacklists out there but we better come up with some new plays because we're losing this game. The fact that we have to setup and maintain all this is ridiculous and we spend more and more time on it as this goes on. I think targeting the spammer customers was the right idea and apparently they were worried as well.
Matt wrote:
I'm afraid to say that this person is in fact in danger of being blacklisted. I run a private blacklist with 6 return codes and over 1 million IP's that were manually collected (in blocks), and will frequently tag all space related to a particular spammer. So if I looked up one block in ARIN and then found the others by association, I would generally research those as well. Chances are that this situation would confuse me and there's no telling how I might list such a thing since I can't say that I can recall ever finding such a block that I was aware of. I'm sure that several other blacklists do this as well, and most with much less care in terms of research.
There are also other blacklists that will do collateral damage to spam hosting companies. Everyone should know that SPEWS does this, but Spamhaus will also do this on some occasions. I don't participate in any collateral damage, especially since it would be quite ineffective with only a few systems using the zones that I maintain.
It is very wise for everyone to make sure that ARIN no longer lists the company's information with old blocks of IP's that are no longer delegated to you. Contacting the IP provider and having them change it (demanding) is the proper course of action.
Matt
R. Scott Perry wrote:
About ten years ago we changed our ISP and got a new block of IPs to use. Our domain name stayed the same. The old ISP never cleaned out the contact information on the old block of IPS.
Apparently someone is now spamming through our old block of IPs. Anyone doing a whois on the old block would find our domain info. I've contacted the ISP and they've corrected the info on that block, but I'm wondering...
Would I have been in danger of being blacklisted?
No.
Very, very few blacklists work on domains instead of IPs. Those that do must be careful not to blacklist any innocent domains, as domains can *always* be forged by spammers
.
Of course, there are some exceptions (for example, lists of spammer URLs often aren't checked), but those shouldn't apply. Anyone smart enough to find your contact info will know that it could be faked (or old, in this case).
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000.
Declude Virus: Ultra reliable virus detection and the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.
----
This outgoing message is guaranteed to be authentic by Message Level users.
Guarantee the authenticity of your email @ http://www.messagelevel.com.
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
-- ===================================================== MailPure custom filters for Declude JunkMail Pro. http://www.mailpure.com/software/ =====================================================
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
