OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: Question about "standards" WRT BATV and SAV

From: Arne Hoffmann (arnefish.in-berlin.de)
Date: Fri May 09 2008 - 03:11:52 CDT


Robert Fournerat wrote:
> Unlike Ralf, regardless of what address_verify_sender value I use, the
> SAV's fail.

Showing some logs is always a good idea. If some implementation of BATV
isn't working, other people might be interested too.

> So BATV offuscates the FROM: address. This seems like a TERRIBLE idea to
> me. Isn't the BATV methodology making an email look MORE suspicious by
> forging a FROM: address?

BATV doesn't 'forge' or 'obfuscate' the envelope sender. When using the
simple private signature (prvs) the local-part can easily be detagged by
skipping the first 12 characters.

> I know that some belive that SAV is evil because it enables the
> possibility of being abused in a DOS attach against some- one else.

Well, at least the people at backscatterer.org think so. That's probably why
they blacklistet you (assuming netin.com is the domain you are talking
about).

arnenell [~]$ dig 14.160.109.216.ips.backscatterer.org +short
127.0.0.2
arnenell [~]$