ietf-asrg
[Top] [All Lists]

Re: [Asrg] Random thought

2003-03-12 14:06:44
wayne wrote:

If you silently accept email with invalid recipients, you may well end
up in the same position as Alan DeKok.  (see
http://www.striker.ottawa.on.ca/ and his several million spams per
day)  Spammers often have more bandwidth than you do, and often care
less about wasting it (since it is often stolen bandwidth.)  Trying to
get spammers to waste their bandwidth by consuming yours doesn't sound
like a good idea to me.

Slight correction. Striker never did that AFAIK. Striker always rejected, via either outright denial of connection or inline rejects rather than bouncing or accepting. The unproven supposition is that his problem is because of one or two malfunctioning dictionary runs. There's on the order of 1500 or so unique destinations in the load.

To an example more to the point and closer to my heart: our spamtraps didn't even have MXes for two years. Spam load before the MXes was removed was on the order of 50,000/day. Spam load after the MXes was restored is on the close order of 800,000/day and growing slowly day-by-day. There's about 10,000 unique addresses in the spam load.

Note: _our_ spamtrap accepts _any_ address (our spamtrap has a hardcoded "yes" to every question). Your supposition would suggest that it'd grow far faster than it is.

I think comparing our numbers with AOL and/or MSN would suggest that "late bouncing" isn't anywhere near the influence as you may think.

Remember, Millions CDs are write-only.

Similarly, I'm not sure that disabling the VRFY SMTP command is a good
idea.  Yes, the VRFY command can be easily used by spammers to do a
dictionary attack on your server, but if you don't let them do it the
"easy" way, they will likely do it the "hard" way by sending spam to
every possible email address.

Multiple "RCPT TO" then "QUIT" is the same as VRFY.

We don't see a lot of that on our spamtrap actually. What we see _vastly_ more of is "HELO/MAIL FROM/QUIT" same "MAIL FROM" all the time. God knows why they're doing that.

_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg



<Prev in Thread] Current Thread [Next in Thread>