OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [dns-operations] negative caching of throwaway spam domains

From: Michael Monnerie (michael.monnerieit-management.at)
Date: Fri Jun 23 2006 - 17:34:07 CDT


On Freitag, 23. Juni 2006 21:29 Noel Jones wrote:
> I don't expect this to catch much.  As you and others have
> said, fresh domains seem more likely to be used as links
> within the spam payload and postfix can't check for them
> there.  But this will be an interesting experiment anyway.

I put it in now, and report back if there's something that jumps in my
eyes. I'm still not sure how valid the RBL list data is, as I don't
know the source.

> rbl_reply_maps should contain the entire rbl reply
> string.  RBL's not listed in this map will get the default
> response.

Thank you for clarification.

> # main.cf
> rbl_reply_maps hash:/path/to/rbl_reply_maps

There's the "=" missing between key and value ;-)

> # rbl_reply_maps
> dob.sibl.support-intelligence.net  454 4.7.1 Service
> unavailable; $rbl_class [$rbl_what] blocked using
> $rbl_domain${rbl_reason?; $rbl_reason}

I wrote "Service unavailable - domain must be older than 5 days" to make
the response clear. And I'm not sure if a 4xx or a 5xx would be better
here. Chances are that a 4xx will pass later, if the domain becomes
older than 5 days. Also, the sending server will fill up with retries,
possibly waking an admin of a cracked server. 5xx would make everything
straight from the beginning...

mfg zmi
--
// Michael Monnerie, Ing.BSc ----- http://it-management.at
// Tel: 0660/4156531 .network.your.ideas.
// PGP Key: "curl -s http://zmi.at/zmi3.asc | gpg --import"
// Fingerprint: 44A3 C1EC B71E C71A B4C2 9AA6 C818 847C 55CB A4EE
// Keyserver: www.keyserver.net Key-ID: 0x55CBA4EE

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQBEnGxhyBiEfFXLpO4RAuMlAJ9JOgxgXIoR7myjOsf0ZBWzFTx3TgCeNTwp
M6sejUrm8FNiP5EToZ37CFU=
=BjHN
-----END PGP SIGNATURE-----