OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: being mailbombed..or something

From: Terry Carmen (terrycnysupport.com)
Date: Tue Jan 01 2008 - 21:54:30 CST


Matthias Schmidt wrote:
>> Bots are pretty easy to kill. You can refuse to talk to them by matching
>> their reverse DNS against a regular expression.
>>
>> This has also been a huge help.
>>
> with these rules you might also reject legal eMails from servers running
> via dyndns, or?
>
Dyndns never enters into it. It's looking up the *reverse* DNS, which
would return the ISP's DN, not the home user.

In any case, I'm more than willing to take a chance on temporarily
rejecting a few legitimate emails from dynamic IPs in exchange for
eliminating millions of zombie spams.

If you look at the regexp, you'll note that it contains a reject
message, which in the case of the companies I manage mail servers for,
includes a contact phone number for the IT department, so they can be
white-listed. They generally average maybe a couple of calls a week for
whitelisting, in contrast to millions of rejects.

Businesses are more than happy to make that trade-off, especially since
it lowers their risk of infection, spam and scams.

Dynamic users should be routing their mail through their ISPs mail
servers. If they don't want to, that's fine, but I don't have to talk to
them.

Terry