Re: [Asrg] Is there anything good enough? - Spoofing stats

David Walker <antispam@grax.com> Wed, 07 May 2003 16:00 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA06634 for <asrg-archive@odin.ietf.org>; Wed, 7 May 2003 12:00:21 -0400 (EDT)
Received: (from mailnull@localhost) by www1.ietf.org (8.11.6/8.11.6) id h47G9Nj30381 for asrg-archive@odin.ietf.org; Wed, 7 May 2003 12:09:23 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h47G9N830378 for <asrg-web-archive@optimus.ietf.org>; Wed, 7 May 2003 12:09:23 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA06600; Wed, 7 May 2003 11:59:51 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19DRMg-0002aG-00; Wed, 07 May 2003 12:01:54 -0400
Received: from ietf.org ([132.151.1.19] helo=www1.ietf.org) by ietf-mx with esmtp (Exim 4.12) id 19DRMg-0002aD-00; Wed, 07 May 2003 12:01:54 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h47G74829401; Wed, 7 May 2003 12:07:04 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h47G65829113 for <asrg@optimus.ietf.org>; Wed, 7 May 2003 12:06:05 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA06513 for <asrg@ietf.org>; Wed, 7 May 2003 11:56:33 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19DRJU-0002Y8-00 for asrg@ietf.org; Wed, 07 May 2003 11:58:36 -0400
Received: from c.vorteon.com ([12.144.144.54] helo=maillist.grax.com) by ietf-mx with esmtp (Exim 4.12) id 19DRJU-0002Xy-00 for asrg@ietf.org; Wed, 07 May 2003 11:58:36 -0400
Received: from localhost (grax_web1 [127.0.0.1]) by maillist.grax.com (Postfix) with ESMTP id 492AF2CB0C; Wed, 7 May 2003 10:58:58 -0500 (CDT)
From: David Walker <antispam@grax.com>
Reply-To: asrg@ietf.org
Organization: Vorteon, LLC
To: Barry Shein <bzs@world.std.com>, Alan DeKok <aland@freeradius.org>
Subject: Re: [Asrg] Is there anything good enough? - Spoofing stats
User-Agent: KMail/1.5
Cc: asrg@ietf.org
References: <19744716058.20030506103859@brandenburg.com> <E19D7LU-00078n-00@mail.nitros9.org> <16056.13955.271718.59630@world.std.com>
In-Reply-To: <16056.13955.271718.59630@world.std.com>
X-Hockey: Colorado Avalanche
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Message-Id: <200305071058.57835@grx>
Content-Transfer-Encoding: 7bit
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/pipermail/asrg/>
Date: Wed, 07 May 2003 10:58:57 -0500
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

With regards to spoofing being a minor problem.
Out of 3130 denied messages 
(to accounts I had to stop because they were receiving 100% spam)
 @juno.com                                        |    36
 @netscape.com                                    |    38
 @email.com                                       |    40
 @excite.com                                      |    50
 @lycos.com                                       |    50
 @earthlink.net                                   |    71
 @msn.com                                         |    72
 @yemenmail.com                                   |    93
 @hotmail.com                                     |   241
 @aol.com                                         |   298
 @yahoo.com                                       |   311
Total | 1300

1300 out of 3130 = 41% of all my denies are very high likelyhood spoofs from 
the popular domains
1050 out of 3130 = 34% are guaranteed spoofs (The helo name is not remotely 
associated with the spoofed domain) from the popular domains.
(These numbers do not represent all spoofing I receive but rather just the 
spoofing to popular domains)

So it doesn't look like a minor problem to me.  Sure it is easy to avoid by
1. switching to domains that have not implemented RMX yet
2. by setting up your own domains
but in the first case the DNS admin would have a tool to fight them (he can 
configure his RMX records) and with the second there is a cost involved.

Assuming just the 11 domains and I implement RMX it becomes useful as I could 
receive messages from my friends and family that use those services.

On Tuesday 06 May 2003 05:26 pm, Barry Shein wrote:
> No, the problem is that this spoofing is a minor problem and any
> solution is easily evaded by spammers.

_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg