mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* Re: Horiffic SPAM
@ 2003-09-24 15:08 John Bradford
  2003-09-24 16:21 ` David Lang
  0 siblings, 1 reply; 11+ messages in thread
From: John Bradford @ 2003-09-24 15:08 UTC (permalink / raw)
  To: rjohnson; +Cc: andrea, linux-kernel

> They are persistant, gang up, and will not give up until they are
> able to deliver the mail! When I firewall them, my network traffic
> ends up being continuous SYN floods

The ISP who supply this DSL connection have been rejecting connects to
their inbound SMTP server from unlisted IPs for ten minutes after the
initial connection attempt.  Retries after ten minutes are accepted,
and future connections are allowed immediately, unless the IP doesn't
make any connections for more than a week.

Apparently, it has reduced the volume of junk mail considerably, as
the 'virus' SMTP engines often don't bother to retry after getting a
4xx error code :-).  Obviously it delays genuine traffic coming
through that server slightly.

This may be a good solution to the problem for anyone who has control
of their own SMTP servers.

(Before anybody says that such greylisting by an ISP is irresponsible,
it's not in this case - unlike most DSL providers, they provide a real
static IP address block, (both v4 and v6), and fully configurable and
delegatable reverse DNS.  This means that there is no need to use
their SMTP server at all.  The most obvious setup is to run your own
primary SMTP server(s), and use theirs as a secondary.)

One theoretical solution to the whole junk mail problem that occurs to
me, would be for everybody to run a spoof open mail relay on port 25
of every IP under their control.  By that I mean a script that accepts
mail and claims that it will be delivered, but never delivers it.
Since the IPs running these spoof SMTP servers would never be listed
against an MX record anywhere, no genuine mail would go to them, only
junk.

Anybody sending junk mail via open relays they'd discovered via port
scanning would probably see a >99% reduction in the mails that
actually got through.  Presumably the companies who pay for the bulk
mail delivery would learn that their mails were not getting through,
and the business would cease to be profitable.

The only junk mail left would be from identifyable sources which is
_much_ easier to deal with.

Of course IPv6 will bring some of these benefits as hopefully ISPs
will assign static IP allocations, rather than dynamic ones.

John.

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Horiffic SPAM
  2003-09-24 15:08 Horiffic SPAM John Bradford
@ 2003-09-24 16:21 ` David Lang
  2003-09-24 16:35   ` Wakko Warner
  0 siblings, 1 reply; 11+ messages in thread
From: David Lang @ 2003-09-24 16:21 UTC (permalink / raw)
  To: John Bradford; +Cc: rjohnson, andrea, linux-kernel

if you want to block mail you need to have your MTA return a 500 series
error code when it gets a connection from that IP address, otherwise the
sending MTA will just retry later, resulting in the problem described.

David Lang

 On Wed, 24 Sep 2003, John Bradford wrote:

> Date: Wed, 24 Sep 2003 16:08:18 +0100
> From: John Bradford <john@grabjohn.com>
> To: rjohnson@analogic.com
> Cc: andrea@suse.de, linux-kernel@vger.kernel.org
> Subject: Re: Horiffic SPAM
>
> > They are persistant, gang up, and will not give up until they are
> > able to deliver the mail! When I firewall them, my network traffic
> > ends up being continuous SYN floods
>
> The ISP who supply this DSL connection have been rejecting connects to
> their inbound SMTP server from unlisted IPs for ten minutes after the
> initial connection attempt.  Retries after ten minutes are accepted,
> and future connections are allowed immediately, unless the IP doesn't
> make any connections for more than a week.
>
> Apparently, it has reduced the volume of junk mail considerably, as
> the 'virus' SMTP engines often don't bother to retry after getting a
> 4xx error code :-).  Obviously it delays genuine traffic coming
> through that server slightly.
>
> This may be a good solution to the problem for anyone who has control
> of their own SMTP servers.
>
> (Before anybody says that such greylisting by an ISP is irresponsible,
> it's not in this case - unlike most DSL providers, they provide a real
> static IP address block, (both v4 and v6), and fully configurable and
> delegatable reverse DNS.  This means that there is no need to use
> their SMTP server at all.  The most obvious setup is to run your own
> primary SMTP server(s), and use theirs as a secondary.)
>
> One theoretical solution to the whole junk mail problem that occurs to
> me, would be for everybody to run a spoof open mail relay on port 25
> of every IP under their control.  By that I mean a script that accepts
> mail and claims that it will be delivered, but never delivers it.
> Since the IPs running these spoof SMTP servers would never be listed
> against an MX record anywhere, no genuine mail would go to them, only
> junk.
>
> Anybody sending junk mail via open relays they'd discovered via port
> scanning would probably see a >99% reduction in the mails that
> actually got through.  Presumably the companies who pay for the bulk
> mail delivery would learn that their mails were not getting through,
> and the business would cease to be profitable.
>
> The only junk mail left would be from identifyable sources which is
> _much_ easier to deal with.
>
> Of course IPv6 will bring some of these benefits as hopefully ISPs
> will assign static IP allocations, rather than dynamic ones.
>
> John.
> -
> To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
> Please read the FAQ at  http://www.tux.org/lkml/
>

-- 
"Debugging is twice as hard as writing the code in the first place.
Therefore, if you write the code as cleverly as possible, you are,
by definition, not smart enough to debug it." - Brian W. Kernighan

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Horiffic SPAM
  2003-09-24 16:21 ` David Lang
@ 2003-09-24 16:35   ` Wakko Warner
  0 siblings, 0 replies; 11+ messages in thread
From: Wakko Warner @ 2003-09-24 16:35 UTC (permalink / raw)
  To: David Lang; +Cc: John Bradford, rjohnson, andrea, linux-kernel

> if you want to block mail you need to have your MTA return a 500 series
> error code when it gets a connection from that IP address, otherwise the
> sending MTA will just retry later, resulting in the problem described.

Adendum: 5xx error code for each RCPT command.  Otherwise, some MTAs will
treat 5xx as 4xx.

I've been hit enough with this virus that I've blocked everyone except lkml
and exim lists (by IP) from this server (my backup will accept however and is
on a quicker line)

-- 
 Lab tests show that use of micro$oft causes cancer in lab animals

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Horiffic SPAM
  2003-09-24 16:45 John Bradford
  2003-09-24 17:22 ` David Lang
@ 2003-09-24 17:40 ` James Stevenson
  1 sibling, 0 replies; 11+ messages in thread
From: James Stevenson @ 2003-09-24 17:40 UTC (permalink / raw)
  To: John Bradford; +Cc: david.lang, andrea, linux-kernel, rjohnson

> 
> A lot of the simple SMTP engines embedded in viruses _don't_ retry on
> 4xx error codes.  Real SMTP engines do.
> 
> That flaw is what we are taking advantage of, to filter out the junk.
> 
> I.E. we tell everybody 'come back later'.  Genuine mail does, whilst
> junk mail often doesn't bother.

This also seems to work with most spammer systems.
But its hard to tell which connections to refuse and
which to accept.

I have had a situation where the connection to the
internet has failed on either the mail server or
its backup relay and amount of spam that day for all users
is greatly reduced.

	James


^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Horiffic SPAM
  2003-09-24 16:45 John Bradford
@ 2003-09-24 17:22 ` David Lang
  2003-09-24 17:40 ` James Stevenson
  1 sibling, 0 replies; 11+ messages in thread
From: David Lang @ 2003-09-24 17:22 UTC (permalink / raw)
  To: John Bradford; +Cc: andrea, linux-kernel, rjohnson

correct, but the origional poster attempted to solve the problem at the
network layer, not at the SMTP layer, also while some of the virus engines
will not retry in the face of 400 series errors, if you have a backup MX
configured that accepts it and relays it to you that machine will retry.

my point (and I think part of yours as well) is that you need to block
this at the application layer, not the network layer

David Lang

 On Wed, 24 Sep 2003, John
Bradford wrote:

> Date: Wed, 24 Sep 2003 17:45:28 +0100
> From: John Bradford <john@grabjohn.com>
> To: david.lang@digitalinsight.com, john@grabjohn.com
> Cc: andrea@suse.de, linux-kernel@vger.kernel.org, rjohnson@analogic.com
> Subject: Re: Horiffic SPAM
>
> > if you want to block mail you need to have your MTA return a 500 series
> > error code when it gets a connection from that IP address, otherwise the
> > sending MTA will just retry later, resulting in the problem described.
>
> Read my post again.
>
> A lot of the simple SMTP engines embedded in viruses _don't_ retry on
> 4xx error codes.  Real SMTP engines do.
>
> That flaw is what we are taking advantage of, to filter out the junk.
>
> I.E. we tell everybody 'come back later'.  Genuine mail does, whilst
> junk mail often doesn't bother.
>
> John.
>

-- 
"Debugging is twice as hard as writing the code in the first place.
Therefore, if you write the code as cleverly as possible, you are,
by definition, not smart enough to debug it." - Brian W. Kernighan

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Horiffic SPAM
@ 2003-09-24 16:45 John Bradford
  2003-09-24 17:22 ` David Lang
  2003-09-24 17:40 ` James Stevenson
  0 siblings, 2 replies; 11+ messages in thread
From: John Bradford @ 2003-09-24 16:45 UTC (permalink / raw)
  To: david.lang, john; +Cc: andrea, linux-kernel, rjohnson

> if you want to block mail you need to have your MTA return a 500 series
> error code when it gets a connection from that IP address, otherwise the
> sending MTA will just retry later, resulting in the problem described.

Read my post again.

A lot of the simple SMTP engines embedded in viruses _don't_ retry on
4xx error codes.  Real SMTP engines do.

That flaw is what we are taking advantage of, to filter out the junk.

I.E. we tell everybody 'come back later'.  Genuine mail does, whilst
junk mail often doesn't bother.

John.

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Horiffic SPAM
  2003-09-23 18:36 ` Andrea Arcangeli
  2003-09-23 18:53   ` Matt Heler
@ 2003-09-24 14:18   ` Richard B. Johnson
  1 sibling, 0 replies; 11+ messages in thread
From: Richard B. Johnson @ 2003-09-24 14:18 UTC (permalink / raw)
  To: Andrea Arcangeli; +Cc: Johnson, Richard, linux-kernel

On Tue, 23 Sep 2003, Andrea Arcangeli wrote:

> On Tue, Sep 23, 2003 at 02:11:59PM -0400, Richard B. Johnson wrote:
> > Hello all,
> >
> > I took root@chaos.analogic.com off the linux-kernel list
> > for a few days so I can trap the spammers and write their
> > addresses to `ipchains`. I have been getting approximately
> > 12,000 email messages per day on that system, making it
> > impossible to use. It's all about the servers spreading
> > the M$ email virus with the phony message to update to the
>
> the baesyan algorithm learnt about them pretty quickly, so they don't
> hurt me anymore (besides some wasted bandwidth).
>
> I doubt answerning those messages will do any good besides generating
> more traffic, but I don't know the detail of the virus so I could be
> wrong.
>

Well it seems that fire-walling the SPAM servers is *not* a good idea.
They are persistant, gang up, and will not give up until they are
able to deliver the mail! When I firewall them, my network traffic
ends up being continuous SYN floods as every spam-server in the
country tries to connect. It doesn't do any good to set `ipchains` to
REJECT instead of DENY. They just keep on banging on the door.

This morning, there was too much traffic on our T3 link to use
a Web crawler, so I had to un-firewall my machine to get about
100,000 (maybe more) mail messages delivered and thrown away.
Procmail is throwing away everything as fast as it can. The
hard-disk LEDs are on continuously, and it takes about 20
seconds to log in. The machine has been eating SPAM mail since
7:00 this morning and it's now 10:15. Maybe, eventually, I
will be able to use my machine again.

To give you a hint of the size of the problem, my /var/log/messages
which logs sendmail activity is about 12 Gb in length. I truncated
it to zero this morning.

Richard B. Johnson
Project Engineer
Analogic Corporation
Penguin : Linux version 2.2.20 on an i586 machine (330.14 BogoMips).

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Horiffic SPAM
  2003-09-23 18:53   ` Matt Heler
@ 2003-09-24  6:28     ` Paul Dickson
  0 siblings, 0 replies; 11+ messages in thread
From: Paul Dickson @ 2003-09-24  6:28 UTC (permalink / raw)
  To: Matt Heler; +Cc: linux-kernel

On Tue, 23 Sep 2003 11:53:04 -0700, Matt Heler wrote:

> Ive been living in a mail hole theese past few years.. Where does one get this 
> baesyan algorithm ?? 

Go to google.com and search "bayesian spam filter".  The first two hits
are Paul Graham's articles that started it all.  There are at least two
sourceforge.net projects in the first tens hits.

	-Paul


^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Horiffic SPAM
  2003-09-23 18:36 ` Andrea Arcangeli
@ 2003-09-23 18:53   ` Matt Heler
  2003-09-24  6:28     ` Paul Dickson
  2003-09-24 14:18   ` Richard B. Johnson
  1 sibling, 1 reply; 11+ messages in thread
From: Matt Heler @ 2003-09-23 18:53 UTC (permalink / raw)
  To: Andrea Arcangeli, Johnson, Richard; +Cc: linux-kernel

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Ive been living in a mail hole theese past few years.. Where does one get this 
baesyan algorithm ?? 

Matt H.

On Tuesday 23 September 2003 11:36 am, Andrea Arcangeli wrote:
> On Tue, Sep 23, 2003 at 02:11:59PM -0400, Richard B. Johnson wrote:
> > Hello all,
> >
> > I took root@chaos.analogic.com off the linux-kernel list
> > for a few days so I can trap the spammers and write their
> > addresses to `ipchains`. I have been getting approximately
> > 12,000 email messages per day on that system, making it
> > impossible to use. It's all about the servers spreading
> > the M$ email virus with the phony message to update to the
>
> the baesyan algorithm learnt about them pretty quickly, so they don't
> hurt me anymore (besides some wasted bandwidth).
>
> I doubt answerning those messages will do any good besides generating
> more traffic, but I don't know the detail of the virus so I could be
> wrong.
>
> Andrea - If you prefer relying on open source software, check these links:
> 	    rsync.kernel.org::pub/scm/linux/kernel/bkcvs/linux-2.[45]/
> 	    http://www.cobite.com/cvsps/
> 	    svn://svn.kernel.org/linux-2.[46]/trunk
> -
> To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
> Please read the FAQ at  http://www.tux.org/lkml/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iD8DBQE/cJaTleY/n9G/oZ8RAoPjAKCHtX9SsUNSjI+MsXlKwVbxRP5+SwCeIIHB
SdEfk80hkuGGV1tj3bnU5ns=
=+yr7
-----END PGP SIGNATURE-----

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: Horiffic SPAM
  2003-09-23 18:11 Richard B. Johnson
@ 2003-09-23 18:36 ` Andrea Arcangeli
  2003-09-23 18:53   ` Matt Heler
  2003-09-24 14:18   ` Richard B. Johnson
  0 siblings, 2 replies; 11+ messages in thread
From: Andrea Arcangeli @ 2003-09-23 18:36 UTC (permalink / raw)
  To: Johnson, Richard; +Cc: linux-kernel

On Tue, Sep 23, 2003 at 02:11:59PM -0400, Richard B. Johnson wrote:
> Hello all,
> 
> I took root@chaos.analogic.com off the linux-kernel list
> for a few days so I can trap the spammers and write their
> addresses to `ipchains`. I have been getting approximately
> 12,000 email messages per day on that system, making it
> impossible to use. It's all about the servers spreading
> the M$ email virus with the phony message to update to the

the baesyan algorithm learnt about them pretty quickly, so they don't
hurt me anymore (besides some wasted bandwidth).

I doubt answerning those messages will do any good besides generating
more traffic, but I don't know the detail of the virus so I could be
wrong.

Andrea - If you prefer relying on open source software, check these links:
	    rsync.kernel.org::pub/scm/linux/kernel/bkcvs/linux-2.[45]/
	    http://www.cobite.com/cvsps/
	    svn://svn.kernel.org/linux-2.[46]/trunk

^ permalink raw reply	[flat|nested] 11+ messages in thread

* Horiffic SPAM
@ 2003-09-23 18:11 Richard B. Johnson
  2003-09-23 18:36 ` Andrea Arcangeli
  0 siblings, 1 reply; 11+ messages in thread
From: Richard B. Johnson @ 2003-09-23 18:11 UTC (permalink / raw)
  To: linux-kernel

[-- Attachment #1: Type: TEXT/PLAIN, Size: 846 bytes --]

Hello all,

I took root@chaos.analogic.com off the linux-kernel list
for a few days so I can trap the spammers and write their
addresses to `ipchains`. I have been getting approximately
12,000 email messages per day on that system, making it
impossible to use. It's all about the servers spreading
the M$ email virus with the phony message to update to the
latest security patches, plus a few hundred "penis-patch" spam
messages per hour.

Anyway, I am trying to fight back. I have attached a
tar-file which contains the source-code I use to create
anti-spam entries for `ipchains`. It also automatically
ties up the spammers and sends them an email message
asking them to stop, plus it logs the connections.

Cheers,

Richard B. Johnson
Project Engineer
Analogic Corporation
Penguin : Linux version 2.2.15 on an i586 machine (330.14 BogoMips).


[-- Attachment #2: Type: APPLICATION/x-gzip, Size: 17572 bytes --]

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2003-09-24 17:38 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2003-09-24 15:08 Horiffic SPAM John Bradford
2003-09-24 16:21 ` David Lang
2003-09-24 16:35   ` Wakko Warner
  -- strict thread matches above, loose matches on Subject: below --
2003-09-24 16:45 John Bradford
2003-09-24 17:22 ` David Lang
2003-09-24 17:40 ` James Stevenson
2003-09-23 18:11 Richard B. Johnson
2003-09-23 18:36 ` Andrea Arcangeli
2003-09-23 18:53   ` Matt Heler
2003-09-24  6:28     ` Paul Dickson
2003-09-24 14:18   ` Richard B. Johnson

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®