Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: Distributed spam-based DoS in progress

From: Hugo van der Kooij <hvdkooij(at)vanderkooij.org>
Date: Wed Feb 19 2003 - 01:49:55 EST


On Tue, 18 Feb 2003, Dave Hart wrote:

> > From: Hugo van der Kooij [mailto:hvdkooij@vanderkooij.org]

>From 4.5.5.:

   Implementors of automated email processors should be careful to make    sure that the various kinds of messages with null reverse-path are    handled correctly, in particular such systems SHOULD NOT reply to    messages with null reverse-path.

But the problem arises before that. If your server is set to accept message for non existing accounts you have a server that can be easily brought down.

If you do not accept these messages you do not have to send bounce messages. It will the task of the system that tried to hand them to you.

If you find yourself with a server with lots of waiting bounces your are likely (ab)used as relay and you have other fish to fry.

And from 6.1:

Do you need help?X

   When the receiver-SMTP accepts a piece of mail (by sending a "250 OK"    message in response to DATA), it is accepting responsibility for    delivering or relaying the message. It must take this responsibility    seriously. It MUST NOT lose the message for frivolous reasons, such    as because the host later crashes or because of a predictable    resource shortage.

Which seems to indicate you have to make sure your mailserver is up to the task.

Hugo.

-- 
 All email sent to me is bound to the rules described on my homepage.
    
hvdkooij(at)vanderkooij.org		
http://hvdkooij.xs4all.nl/
	    Don't meddle in the affairs of sysadmins,
	    for they are subtle and quick to anger.


----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: 
http://aris.securityfocus.com
Received on Wed Feb 19 14:48:23 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:58 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library