ietf-asrg
[Top] [All Lists]

Re: [Asrg] whitelisting server and not users

2003-04-02 14:29:30
On Wed, Apr 02, 2003 at 04:21:37PM -0500, Daniel Feenberg wrote:

On Wed, 2 Apr 2003, Steven F Siirila wrote:

On Wed, Apr 02, 2003 at 04:06:32PM -0500, Kee Hinckley wrote:
At 3:00 PM -0600 4/2/03, Steven F Siirila wrote:
Not a problem here since we also look up the EHLO name.  If that resolves
to the caller's IP address, it counts as good as a PTR record in our book.

But doesn't this open the door for the spammer to just get a throwaway
domain name and authorize his own spam? The advantage of using the RDNS
of the connecting host is that it is fixed by the ISP, who can
be held responsible by RBLs. Since there are a finite number of IP address
blocks, the ISP isn't going to want to repeatedly issue new IP addresses
to the spammer. Without that enforcement tool, there isn't any real
incentive in the system.

You are quite correct.  I realized this after I sent the mail.
It works well for open relays since the spammer cannot control the EHLO name.
However, open proxies and such are another story.



_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg

-- 

Steven F. Siirila                       Office: Lind Hall, Room 130B
Internet Services                       E-mail: sfs(_at_)umn(_dot_)edu
Office of Information Technology        Voice: (612) 626-0244
University of Minnesota
_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg