Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: Distributed spam-based DoS in progress

From: Dave Hart <davehart(at)davehart.com>
Date: Wed Feb 19 2003 - 02:26:37 EST


Hugo van der Kooij quotes two different sections of current SMTP RFC in response to my challenge to cite where in the RFC the behavior he described is documented. He does not in fact find any such citation, and instead changes the subject by claiming the _real_ problem is that no incoming MX server should ever accept mail that will eventually bounce. There are many reasons why such configurations are useful. Examples:

  1. Backup MX servers provided by third parties routinely accept all mail for domains they service for inbound relay. Backup MX is not really interesting until there are brief outages for the primary MX, so in practice the backup servers are not going to have enough information to bounce invalid recipients.
  2. SMTP-based inbound antivirus scanners and spam scanners such as SpamAssassin in front (SMTP-wise) of a Microsoft Exchange server. Here because the front-end scanner is backend receiving mailer-neutral it is often unaware of which recipient addresses are valid.
  3. Prevention of trivial probing for valid email addresses. Spammers have a practice of hitting a mailserver with "war-dialed" random recipient addresses using RCPT without ever actually sending mail. This scanning stays below the radar of many administrators, who often do not log a RCPT with no successful DATA/BDAT to complete the transaction.

Getting back to the original message of this thread, there is nothing "broken" about the SMTP server behavior observed by the presumptive DoS victim. I welcome evidence from relevant RFCs that contradict me on this point.

Regards,
Dave Hart



This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com Received on Wed Feb 19 14:51:31 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:01:58 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library