OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: (OT) Paul Hoffman, Director Internet Mail Consortium wants number s

From: Peter H. Coffin (hellsopninehells.com)
Date: Wed Sep 17 2003 - 18:33:54 CDT


On Wed, Sep 17, 2003 at 12:58:56PM -0400, Wietse Venema wrote:
> I already see spam coming at my system with a sender that resolves
> to the Verisign wild-card address.
>
> Some has a non-existent sender domain, and some has a non-existent
> MX hostname for the sender domain.

$ grep -c 64.94.110.11 /var/log/maillog
59

It's a small system, dealing with about 1500 connections per day, of
which 60-65% of which are spam and rejected. The log is a week old.

I think the question of whether or not the spam was accepted or
otherwise blocked later is irrelevant to the quantative results: every
time that IP address is in the log, it's evidence of wasted resources.
Nothing should be coming from that IP. Nothing should be looked up to
that IP. Anything blocked after testing for the existence of the domain
was blocked by a MORE EXPENSIVE lookup, not a simpler one. If it came
in, it was spam. If it was blocked, it was blocked by the expensive
(though effective) sender verification.

--
26. No matter how attractive certain members of the rebellion are, there is
    probably someone just as attractive who is not desperate to kill me.
    Therefore, I will think twice before ordering a prisoner sent to my
    bedchamber. --Peter Anspach's list of things to do as an Evil Overlord