OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: rbl.shub-inter.net is hosed?
From: Greg A. Woods (woodsweird.com)
Date: Thu Aug 10 2000 - 11:15:30 CDT


[ On Thursday, August 10, 2000 at 14:53:46 (+0200), Brad Knowles wrote: ]
> Subject: Re: rbl.shub-inter.net is hosed?
>
> At 1:41 PM +0100 2000/8/10, Chris Horry wrote:
>
> > This service shut down a VERY long time ago, a couple of years at least.
>
> In it's original function, yes. However, many people configure
> things like what black lists they use, and then never go back to them
> again.

Yeah, but their domain name was "obtained" by the current owners
sometime in May. I had done exactly as you said and forgotten about
them, but SCCS notes that I fixed my configs on May 26 of this year
after discovering some mail being blocked, and the WHOIS record shows
the domain was last updated 24-May-2000.

I don't know if Postfix was blocking any e-mail because at the time my
only system running postfix was not receiving much public traffic -- the
problem was similar for my smail machines though....

> If anyone on this list has done this, and is using
> rbl.shub-inter.net, then they're likely to start refusing all mail
> from all sources, if I'm correct about the wildcard DNS issue.

Since late May even!

> Furthermore, it's also important to get postfix modified so that
> it's a bit more intelligent about validating the returned IP address,
> and can't be snookered by a mis-placed wildcard DNS record.

This would be good. The problem is though that you'd probably want a
fairly flexible mechanism since although most peoplue use the MAPS-style
127.0.0.* addresses, there's nothing independent specifying this as even
a best common practice. Perhaps an optional list of IP/MASK pairs
against which the result could be verified. Then again even the record
type is rather arbitrary....

It would be good if the MAPS folks proposed a standard in an RFC....

-- 
							Greg A. Woods

+1 416 218-0098 VE3TCP <gwoodsacm.org> <robohack!woods> Planix, Inc. <woodsplanix.com>; Secrets of the Weird <woodsweird.com>