ietf-asrg
[Top] [All Lists]

RE: [Asrg] Whitelisting on Message-ID (Was Turing Test ...) honyp ot plug

2003-04-07 07:31:47
From: "Sauer, Damon" <Damon(_dot_)Sauer(_at_)bellsouth(_dot_)com>

...
 Here is a very interesting experiment for you... Add an IP to DNS and have
it mail enabled. 

What do you mean by "add an IP to DNS and have it mail enabled"? 
I assume you mean create an A RR for a new third level domain name,
set a new SMTP server to listening on the IP address in the new A RR,
and possibly create an MX RR for the name.

                 I saw this happen first hand as I was bringing a whole load
of new equipment online. The *moment* I added the a new record to DNS,
spammers and spam researchers were hammering my boxes.
 I believe they watch every addition to DNS. It was amazing to watch these
spammers come online and try to hammer systems that were not even in
production yet.  ...

How do you figure that spammers are able to do that?  Don't the
gTLD namesevers for .com, .net, and .org contain several GBytes of
data?  Wouldn't keeping track of the A and MX RRs in only the third
level of .com, .net, and .org require keeping and watching for
changes in TBytes of data?  How many spammers have the bandwidth
or servers to do such things?

How were you able to reject the obvious and far more plausible
alternative explanations?


Vernon Schryver    vjs(_at_)rhyolite(_dot_)com
_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg