This has been going on for some time now, there was discussion on this list regarding the topic, we ended up putting a policy in our platforms just to deal with this issue. "Reject messages from senders forging bounce messages".


On 16-04-29 06:25 AM, Benoit Panizzon wrote:
Hi Renaud

I am seeing in my logs some bounces messages (empty sender) from
various outbound.protection.outlook.com servers. All those bounce
messages are directed towards one specific email address which is
probably used as an envelope field in a spam run.

Now my question is: if it comes from outbound servers for outlook.com,
shouldn't the mails also pass through some kind of inbound servers at
outlook.com? If that's the case, how comes that those messages which
surely have a wrong DMARC, SPF and DKIM pass through the incoming
gateways?

We have exactly the same problem. We sometimes observe that some of our
customers get DOSed by large volumes of outbound.protection.outlook.com
bounces.

The 'Attacker' apparently is a botnet (aka many different ip
addresses) that fakes the sender@our-domain and sends very small emails
to various non existing recipients hosted on
outbound.protection.outlook.com servers.

Our domains are protected by SPF.

In the first place, the outlook.com services should not accept emails
to non existent recipients and then send 'late' bounces to the fake
sender, resulting in some kind of amplificator attack.

Secondly if the sender domains is protected by SPF with -all that email
should be rejected my Microsoft right away during SMTP handshake.

None of both is done.

I documented the case and how to reproduce.

I did try to open a trouble ticket with the Microsoft Security. It was
impossible, because we, as an ISP do not use any outlook.com services.
I did try to explain the microsoft security agent for long time, that
his handling of the issue was completely wrong and that it was not a
question what M$ product we use, but he did not want to connect me to
his supervisor as we are no M$ customer and therefore there is no way
to open an abuse/security trouble ticket. WTF!

I contacted [email protected] several times about the issue, without
reply.

I even went so far to notify the Heise Journal security team with the
hint that kind of an mail traffic amplificator attack was possible via
outlook.com, to try to increase the pressure on Microsoft to look into
the issue, but they unfortunately considered this not serious enough.

We cannot block the IP Addresses of the outbound.protection.outlook.com
as this would also affect a lot of legitimate email.

So I have no solution here and don't know how I can make Microsoft take
my reports seriously.

Kind regards

-BenoƮt Panizzon-



_______________________________________________
mailop mailing list
[email protected]
https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop




--
"Catch the Magic of Linux..."
------------------------------------------------------------------------
Michael Peddemors, President/CEO LinuxMagic Inc.
Visit us at http://www.linuxmagic.com @linuxmagic
------------------------------------------------------------------------
A Wizard IT Company - For More Info http://www.wizard.ca
"LinuxMagic" a Registered TradeMark of Wizard Tower TechnoServices Ltd.
------------------------------------------------------------------------
604-682-0300 Beautiful British Columbia, Canada

This email and any electronic data contained are confidential and intended
solely for the use of the individual or entity to which they are addressed.
Please note that any views or opinions presented in this email are solely
those of the author and are not intended to represent those of the company.

_______________________________________________
mailop mailing list
[email protected]
https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop

Reply via email to