Many Imail admins don't have the tools nor the IMail log data to do such an analysis, so I post this here to support my position that all subscriber networks merit blanket blocking.


For maillog of yesterday, Friday. I chose a "business" day when there would be fighting chance of seeing legitimate traffic from a subscriber network. :))

I chose charter.com because, well, because all subscriber networks stink.

What are the total connects from IPs with PTR charter.com:

# zegrep -ic " connect from.*\.charter\.com" /postfix/log/maillog.1.gz
1200

What are total rejects for charter.com PTRs:

# zegrep -ic "reject:.*\.charter\.com" /postfix/log/maillog.1.gz
1767

So we are doing an average of 1.5 rejects from every connect session from a charter PTR. At the top level, it already sounds bad. What could those charter customers possibly be up to??

For all the charter.com connect sessions, how many sessions did we hang up on because charter hit our limit of 3 each 5xx rejects per session:

# zegrep -ic "too many.*\.charter\.com" /postfix/log/maillog.1.gz
745

So it seems like charter users are very insistent on sending us SMTP commands that we repeatedly respond to with 5xx within the same SMTP session. Tisk tisk, sounds very naughty indeed.

To give you some perspective, for the msgs that we accepted from all domains, here's the distribution of "number of recipients", nrcpt, per msg:

  22665 nrcpt=1
    338 nrcpt=2
     98 nrcpt=3
     32 nrcpt=4
     25 nrcpt=5
     11 nrcpt=6
      3 nrcpt=9
      3 nrcpt=7
      3 nrcpt=25
      3 nrcpt=17
      2 nrcpt=8
      2 nrcpt=14
      2 nrcpt=12
      1 nrcpt=26
      1 nrcpt=19
      1 nrcpt=18
      1 nrcpt=15
      1 nrcpt=11
      1 nrcpt=10

22665 / (22665 + 530) = 98% of all msgs through this MX are for one recipient.

But for charter, 63% of all their sessions are generating 3 5xx errors, as if charter clients were attempting to send at least 3 RCPT TO's per session (at which point we hang up), which would have placed them under 2%, not at 63%. This looks very, very bad, charter.

Total rejects due to unknown users:

# zegrep -ic "reject:.*recipient table.*\.charter\.com" /postfix/log/maillog.1.gz
1100


Wow, those charter customers really have a LOT of bad recipients for our domains. Probably just a bunch of typo's, right?

Let's disregard the above "unknown user" traffic since that's obviously illegit. No need to look at it further, it's traffic not for our users anyway.

Let's see what the traffic looks like to our "known users" from charter.com, since, if there are any candidates for the dreaded false positives, they would be in the msgs to our known users.

The following is the MAIL FROM: and HELO fields sent to our known users from IPs with charter.com PTRs.

But let's break this longish list into two groups:

1) when the helo hostname contains charter.com, and

2) when it doesn't.

For HELO containing charter.com to our known users, what do the FROM fields look like, sorted by sender@:

from=<[EMAIL PROTECTED]> helo=<4476d0252.knnwck.wa.charter.com>
from=<[EMAIL PROTECTED]> helo=<c66.169.176.92.ts46v-08.otn-c2.ftwrth.tx.charter.com>
from=<[EMAIL PROTECTED]> helo=<24-240-224-119.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-68-116-161-138.ma.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-68-187-233-216.vt.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-24-151-130-250.ma.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-68-118-229-107.ma.charter.com>
from=<[EMAIL PROTECTED]> helo=<66-168-65-97.wb.wi.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-68-118-180-136.ma.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-24-196-206-123.hkry.nc.charter.com>
from=<[EMAIL PROTECTED]> helo=<24-196-150-99.mazo.wi.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-68-115-215-099.spa.sc.charter.com>
from=<[EMAIL PROTECTED]> helo=<24-240-143-9.charter.com>
from=<[EMAIL PROTECTED]> helo=<jennifer.cpe.mvllo.al.charter.com>
from=<[EMAIL PROTECTED]> helo=<66-188-103-25.mad.wi.charter.com>
from=<[EMAIL PROTECTED]> helo=<c68.113.212.39.ts46v-09.otn-d1.ftwrth.tx.charter.com>
from=<[EMAIL PROTECTED]> helo=<dell1.cpe.mvllo.al.charter.com>
from=<[EMAIL PROTECTED]> helo=<c68.113.212.197.ts46v-09.otn-d1.ftwrth.tx.charter.com>
from=<[EMAIL PROTECTED]> helo=<c66.169.165.73.ts46v-12.otn-e2.ftwrth.tx.charter.com>
from=<[EMAIL PROTECTED]> helo=<4476d614.wlawla.wa.charter.com>
from=<[EMAIL PROTECTED]> helo=<66-191-38-134.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-24-107-234-98.ma.charter.com>
from=<[EMAIL PROTECTED]> helo=<c24.197.242.97.spt.wi.charter.com>
from=<[EMAIL PROTECTED]> helo=<24-216-100-33.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-68-118-229-107.ma.charter.com>
from=<[EMAIL PROTECTED]> helo=<c24.197.242.97.spt.wi.charter.com>
from=<[EMAIL PROTECTED]> helo=<cable-24-158-216-175.sli.la.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-24-107-234-98.ma.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-24-159-170-136.spa.sc.charter.com>
from=<[EMAIL PROTECTED]> helo=<dell1.cpe.mvllo.al.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-68-116-161-138.ma.charter.com>
from=<[EMAIL PROTECTED]> helo=<c24.197.242.97.spt.wi.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-68-119-223-243.hkry.nc.charter.com>
from=<[EMAIL PROTECTED]> helo=<charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-66-189-24-115.ma.charter.com>
from=<[EMAIL PROTECTED]> helo=<66-191-125-181.mad.wi.charter.com>
from=<[EMAIL PROTECTED]> helo=<24-159-232-84.jvl.wi.charter.com>
from=<[EMAIL PROTECTED]> helo=<c68.117.105.87.ash.wi.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-66-189-24-115.ma.charter.com>
from=<[EMAIL PROTECTED]> helo=<c68.113.212.197.ts46v-09.otn-d1.ftwrth.tx.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-24-197-103-076.spa.sc.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-66-189-11-213.ma.charter.com>
from=<[EMAIL PROTECTED]> helo=<c66.169.114.7.ts46v-04.otn-a2.ftwrth.tx.charter.com>
from=<[EMAIL PROTECTED]> helo=<c68.117.53.235.rose.mn.charter.com>
from=<[EMAIL PROTECTED]> helo=<66-188-111-60.mad.wi.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-24-197-117-106.spa.sc.charter.com>
from=<[EMAIL PROTECTED]> helo=<c68.114.218.86.jvl.wi.charter.com>
from=<[EMAIL PROTECTED]> helo=<24-196-127-39.fdl.wi.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-68-115-215-099.spa.sc.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-24-151-130-250.ma.charter.com>
from=<[EMAIL PROTECTED]> helo=<c68.113.212.39.ts46v-09.otn-d1.ftwrth.tx.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-66-169-53-183.spa.sc.charter.com>
from=<[EMAIL PROTECTED]> helo=<c68.116.218.74.ts46v-01.conroe.tx.charter.com>
from=<[EMAIL PROTECTED]> helo=<cable-24-158-216-175.sli.la.charter.com>
from=<[EMAIL PROTECTED]> helo=<c68.117.105.87.ash.wi.charter.com>
from=<[EMAIL PROTECTED]> helo=<c68.116.220.75.ts46v-01.conroe.tx.charter.com>
from=<[EMAIL PROTECTED]> helo=<c66.169.176.92.ts46v-08.otn-c2.ftwrth.tx.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-24-196-206-123.hkry.nc.charter.com>
from=<[EMAIL PROTECTED]> helo=<66-188-111-60.mad.wi.charter.com>
from=<[EMAIL PROTECTED]> helo=<c68.112.169.110.dul.mn.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-66-189-11-213.ma.charter.com>
from=<[EMAIL PROTECTED]> helo=<66-188-208-141.roc.mn.charter.com>
from=<[EMAIL PROTECTED]> helo=<c68.114.233.197.fdl.wi.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-24-197-117-106.spa.sc.charter.com>
from=<[EMAIL PROTECTED]> helo=<cpe-24-197-103-076.spa.sc.charter.com>
from=<[EMAIL PROTECTED]> helo=<c24.197.242.97.spt.wi.charter.com>


What a delightful relief!! Every one of those MAIL FROM: to our users looks perfectly legitimate!! :))

The other group below is the mail addressed to our known users from charter where the HELO does NOT contain charter.com. That is, these endearing, earnest charter customers had the initiative and/or smarts to change the HELO name to represent their "legitimate business domain".

As you go through this list, you will probably have to remind yourself that these are from charter.com IPs:

from=<[EMAIL PROTECTED]> helo=<24.159.170.136>
from=<[EMAIL PROTECTED]> helo=<pldi.net>
from=<[EMAIL PROTECTED]> helo=<wild-college-party-videos.com>
from=<[EMAIL PROTECTED]> helo=<girls-4-me.us>
from=<[EMAIL PROTECTED]> helo=<drumandbass.de>
from=<[EMAIL PROTECTED]> helo=<juergen-steckenreiter.de>
from=<[EMAIL PROTECTED]> helo=<localhost>
from=<[EMAIL PROTECTED]> helo=<localhost>
from=<[EMAIL PROTECTED]> helo=<localhost>
from=<[EMAIL PROTECTED]> helo=<localhost>
from=<[EMAIL PROTECTED]> helo=<localhost>
from=<[EMAIL PROTECTED]> helo=<localhost>
from=<[EMAIL PROTECTED]> helo=<localhost>
from=<[EMAIL PROTECTED]> helo=<localhost>
from=<[EMAIL PROTECTED]> helo=<localhost>
from=<[EMAIL PROTECTED]> helo=<localhost>
from=<[EMAIL PROTECTED]> helo=<localhost>
from=<[EMAIL PROTECTED]> helo=<localhost>
from=<[EMAIL PROTECTED]> helo=<localhost>
from=<[EMAIL PROTECTED]> helo=<localhost>
from=<[EMAIL PROTECTED]> helo=<ozestock.com.au>
from=<[EMAIL PROTECTED]> helo=<eudoramail.com>
from=<[EMAIL PROTECTED]> helo=<80.232.219.81>
from=<[EMAIL PROTECTED]> helo=<oberon.aif.msk.su>
from=<[EMAIL PROTECTED]> helo=<pldi.net>
from=<[EMAIL PROTECTED]> helo=<onlinehome.de>
from=<[EMAIL PROTECTED]> helo=<margaret.mollerus.org>
from=<[EMAIL PROTECTED]> helo=<margaret.mollerus.org>
from=<[EMAIL PROTECTED]> helo=<alex-koenen.de>
from=<[EMAIL PROTECTED]> helo=<modern-home.co.uk>
from=<[EMAIL PROTECTED]> helo=<mailbox.as>
from=<[EMAIL PROTECTED]> helo=<pldi.net>
from=<[EMAIL PROTECTED]> helo=<gjr.paknet.com.pk>
from=<[EMAIL PROTECTED]> helo=<orbit.de>
from=<[EMAIL PROTECTED]> helo=<bldrbobs>
from=<[EMAIL PROTECTED]> helo=<bldrbobs>
from=<[EMAIL PROTECTED]> helo=<bormann.ws>
from=<[EMAIL PROTECTED]> helo=<oricom.ca>
from=<[EMAIL PROTECTED]> helo=<24.196.244.111>
from=<[EMAIL PROTECTED]> helo=<onlinehome.de>
from=<[EMAIL PROTECTED]> helo=<gjr.paknet.com.pk>
from=<[EMAIL PROTECTED]> helo=<lycos.com>
from=<[EMAIL PROTECTED]> helo=<lycos.com>
from=<[EMAIL PROTECTED]> helo=<your-ink-place.com>
from=<[EMAIL PROTECTED]> helo=<the-inkers-spot.com>
from=<[EMAIL PROTECTED]> helo=<64.157.4.78>
from=<[EMAIL PROTECTED]> helo=<microsoft.com>
from=<[EMAIL PROTECTED]> helo=<isabell-berens.de>
from=<[EMAIL PROTECTED]> helo=<sender1188>
from=<[EMAIL PROTECTED]> helo=<sender1488>
from=<[EMAIL PROTECTED]> helo=<worldcom.ch>
from=<[EMAIL PROTECTED]> helo=<sto-helit.de>
from=<[EMAIL PROTECTED]> helo=<yahoo.com>
from=<[EMAIL PROTECTED]> helo=<mailer.com>
from=<[EMAIL PROTECTED]> helo=<monty>
from=<[EMAIL PROTECTED]> helo=<monty>
from=<[EMAIL PROTECTED]> helo=<compuserve.com>
from=<[EMAIL PROTECTED]> helo=<derpi.tuwien.ac.at>
from=<[EMAIL PROTECTED]> helo=<bleau.de>
from=<[EMAIL PROTECTED]> helo=<lycos.ne.jp>
from=<[EMAIL PROTECTED]> helo=<mdi-ger.de>
from=<[EMAIL PROTECTED]> helo=<24.196.14.173>
from=<[EMAIL PROTECTED]> helo=<dplanet.ch>
from=<[EMAIL PROTECTED]> helo=<tiscali.co.uk>
from=<[EMAIL PROTECTED]> helo=<arti.vub.ac.be>
from=<[EMAIL PROTECTED]> helo=<rons-house.de>
from=<[EMAIL PROTECTED]> helo=<67.161.71.65>
from=<[EMAIL PROTECTED]> helo=<tenbit.pl>


... did you forget? The above MAIL FROM + HELO fields are from __CHARTER__ IPs.

Conclusion: absolute total crap from charter.com subscriber networks to our known users.

( and remember, we have earlier already rejected 1100 msgs to unknown users from charter.com. All in day's work over at charter.com! ).

So, in conclusion, the "single criteria" of a PTR hostname being in a charter.com subscriber subdomain is reliably indicative of mail abuse. There is no need to accept the DATA command, scan the headers, scan the body, screw around with multiple criteria. The envelope info is sufficient, reject.

I have run the same analysis on subscriber network traffic from comcast.com and hsia.telus.com ("High Speed Internet Access" up in Canada), and the results are the same. Total crap.

So, it is a perfectly justifiable, defensible policy, based on hard, repeatable data such as the above, to define all subscriber PTR domains to be illegitimate, (which means it is, by definition, impossible to have false positives).

There may be some vanishingly tiny number of legitimate mailers on subscriber networks dribbling out a few legit messages/day, but they are illegitimate _by definition_ since they are on subscriber networks.

What can you expect to find as users and machines on subscriber networks?:

* amateur and semi-pro home spammers

* machines with no firewall, so have been compromised.

* machines infected with mailer-worms, DDoS agents, and whatever else

* machines running as open relays being raped by spammers

* machines running as open proxies driven by hard-core proxy abusers

And that's just the situation today.

In the future, blanket blocking of subscriber networks will be even more defensible and effective due to much higher volumes of subscriber network IPs and their volumes of abusive traffic, because cable/DSL access, still deploying widely in North Amreica, is now within reach of mass markets in Europe, South America, Asia.

(I suppose the only continent with no subscriber network abuse is the continent that has essentially no subscriber networks, Africa).

You ain't seen nothing, yet.

Len


_____________________________________________________________________ http://MenAndMice.com/DNS-training: San Jose; Wash DC; Dallas; Atlanta IMGate.MEIway.com: anti-spam gateway, effective on 1000's of sites, free


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to