Re: [Asrg] Re: Bots

Gadi Evron <ge@linuxbox.org> Wed, 18 January 2006 00:15 UTC

Received: from localhost.cnri.reston.va.us ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1Ez0yx-0001ay-MP; Tue, 17 Jan 2006 19:15:23 -0500
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1Ez0yw-0001Zm-Pe for asrg@megatron.ietf.org; Tue, 17 Jan 2006 19:15:22 -0500
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id TAA12964 for <asrg@ietf.org>; Tue, 17 Jan 2006 19:13:57 -0500 (EST)
Received: from linuxbox.org ([24.155.83.21] ident=root) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1Ez179-0000Fc-BY for asrg@ietf.org; Tue, 17 Jan 2006 19:23:52 -0500
Received: from [192.115.22.106] (prometheus.solaris.org.il [192.115.22.106]) (authenticated bits=0) by linuxbox.org (8.13.4/8.13.4/Debian-3) with ESMTP id k0I0F9ZP009824; Tue, 17 Jan 2006 18:15:13 -0600
Message-ID: <43CD8856.7010309@linuxbox.org>
Date: Wed, 18 Jan 2006 02:14:14 +0200
From: Gadi Evron <ge@linuxbox.org>
User-Agent: Mozilla Thunderbird 1.0.2 (Windows/20050317)
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: Larry Seltzer <larry@larryseltzer.com>
Subject: Re: [Asrg] Re: Bots
References: <049001c61bc1$3deb0b90$0d00005a@moregarlic.com>
In-Reply-To: <049001c61bc1$3deb0b90$0d00005a@moregarlic.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Greylist: Sender succeded SMTP AUTH authentication, not delayed by milter-greylist-1.7.5 (linuxbox.org [24.155.83.21]); Tue, 17 Jan 2006 18:15:14 -0600 (CST)
X-Spam-Status: No, score=-2.6 required=5.0 tests=AWL,BAYES_00 autolearn=ham version=3.0.3
X-Spam-Checker-Version: SpamAssassin 3.0.3 (2005-04-27) on linuxbox.org
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 69a74e02bbee44ab4f8eafdbcedd94a1
Content-Transfer-Encoding: 7bit
Cc: asrg@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/asrg>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
Sender: asrg-bounces@ietf.org
Errors-To: asrg-bounces@ietf.org

Larry Seltzer wrote:
>>>A zombie can do everything it's former owner can do.  Hijack

I think not many people understand what a Zombie is.. I think I will 
write on this soon.

<snip>

> Out of this list only two are really mail spamming activities. Port 587 is
> inherently authenticated, so a bot that uses it will be quickly shut down.
> It's just not much of a substitute for the freedom port 25 presents. "Create
> Web mail accounts in the name of its former owner and spam" - why would you
> need a bot to do this? What value does a bot add? In any event, it's still
> not a reason to keep port 25 open. 
> 
> Basically, you're right that there's a lot that bots can do besides spam on
> port 25, but blocking port 25 would make it much, much harder for bots to be
> a significant source of spam. Consequently the value of botnets would
> decrease substantially.

Larry, I can honestly say I couldn't have put it better myself.

This is a never-ending game of cat and mouse. Once we block one route, 
the mouse opens another which we hurry to try and block, and so on and 
so forth to the end of time.

That doesn't mean we shouldn't block, or more to the point, kill the 
mouse or cut off one of its legs.. or even better, prevent it from 
creating new lil mices.

Port 25 blocking is advancing spam in the direction we want it to take, 
which I believe will be more manageable, rather than letting the 
scUmmers lead us on their own evolutionary ride, reacting to our 
reactions and getting better while they're at it.

[Nothing personal, der Mouse. :) ]

	Gadi.

_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg