The part I just do not understand is this; Ask any average e-mail user if they have ever bought something from a spam message and I am sure you will get a NO from 99 percent of them. In fact, mot people will NOT do business with a company that uses spam to send their flyers. You seen what happened when one of those political people got caught doing it, they were all over his butt.
The only thing that I can think of is that someone is offered a deal that sounds so good. Like 1 million e-mailings over a 6 month period. I am sure the spammers have their software in place to mail it out with just a click or two of the mouse. I have no ideal what it costs to have a company spam for you, but just grabbing a random number like 500 bucks for 1 million mailings over a 6 month period. The company can now just spend 500 bucks for advertising that he can of course wipe out. I am sure there sales pitch to the poor company says, if you just get 1 percent of everyone we mail to come to your business and you sell to 1/2 of them; that is 5000 sales for you. All for a measly 500 bucks! This has to sounds very inviting for the poor proprietor. Little does he know that a very small percentage of that million will even receive the mail, since spam filters are spreading around to the mail servers and to the end user's computer. Even when the government starts slapping the wrists of spammers, they will head over to other countries that will allow them to spam all they want. Will this ever end? Larry Anderson -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Len Conrad Sent: Saturday, September 13, 2003 10:10 PM To: [EMAIL PROTECTED] Subject: [IMail Forum] example: analysis of traffic from charter.com subscriber networks Many Imail admins don't have the tools nor the IMail log data to do such an analysis, so I post this here to support my position that all subscriber networks merit blanket blocking. For maillog of yesterday, Friday. I chose a "business" day when there would be fighting chance of seeing legitimate traffic from a subscriber network. :)) I chose charter.com because, well, because all subscriber networks stink. What are the total connects from IPs with PTR charter.com: # zegrep -ic " connect from.*\.charter\.com" /postfix/log/maillog.1.gz 1200 What are total rejects for charter.com PTRs: # zegrep -ic "reject:.*\.charter\.com" /postfix/log/maillog.1.gz 1767 So we are doing an average of 1.5 rejects from every connect session from a charter PTR. At the top level, it already sounds bad. What could those charter customers possibly be up to?? For all the charter.com connect sessions, how many sessions did we hang up on because charter hit our limit of 3 each 5xx rejects per session: # zegrep -ic "too many.*\.charter\.com" /postfix/log/maillog.1.gz 745 So it seems like charter users are very insistent on sending us SMTP commands that we repeatedly respond to with 5xx within the same SMTP session. Tisk tisk, sounds very naughty indeed. To give you some perspective, for the msgs that we accepted from all domains, here's the distribution of "number of recipients", nrcpt, per msg: 22665 nrcpt=1 338 nrcpt=2 98 nrcpt=3 32 nrcpt=4 25 nrcpt=5 11 nrcpt=6 3 nrcpt=9 3 nrcpt=7 3 nrcpt=25 3 nrcpt=17 2 nrcpt=8 2 nrcpt=14 2 nrcpt=12 1 nrcpt=26 1 nrcpt=19 1 nrcpt=18 1 nrcpt=15 1 nrcpt=11 1 nrcpt=10 22665 / (22665 + 530) = 98% of all msgs through this MX are for one recipient. But for charter, 63% of all their sessions are generating 3 5xx errors, as if charter clients were attempting to send at least 3 RCPT TO's per session (at which point we hang up), which would have placed them under 2%, not at 63%. This looks very, very bad, charter. Total rejects due to unknown users: # zegrep -ic "reject:.*recipient table.*\.charter\.com" /postfix/log/maillog.1.gz 1100 Wow, those charter customers really have a LOT of bad recipients for our domains. Probably just a bunch of typo's, right? Let's disregard the above "unknown user" traffic since that's obviously illegit. No need to look at it further, it's traffic not for our users anyway. Let's see what the traffic looks like to our "known users" from charter.com, since, if there are any candidates for the dreaded false positives, they would be in the msgs to our known users. The following is the MAIL FROM: and HELO fields sent to our known users from IPs with charter.com PTRs. But let's break this longish list into two groups: 1) when the helo hostname contains charter.com, and 2) when it doesn't. For HELO containing charter.com to our known users, what do the FROM fields look like, sorted by sender@: from=<[EMAIL PROTECTED]> helo=<4476d0252.knnwck.wa.charter.com> from=<[EMAIL PROTECTED]> helo=<c66.169.176.92.ts46v-08.otn-c2.ftwrth.tx.charter.com> from=<[EMAIL PROTECTED]> helo=<24-240-224-119.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-68-116-161-138.ma.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-68-187-233-216.vt.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-24-151-130-250.ma.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-68-118-229-107.ma.charter.com> from=<[EMAIL PROTECTED]> helo=<66-168-65-97.wb.wi.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-68-118-180-136.ma.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-24-196-206-123.hkry.nc.charter.com> from=<[EMAIL PROTECTED]> helo=<24-196-150-99.mazo.wi.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-68-115-215-099.spa.sc.charter.com> from=<[EMAIL PROTECTED]> helo=<24-240-143-9.charter.com> from=<[EMAIL PROTECTED]> helo=<jennifer.cpe.mvllo.al.charter.com> from=<[EMAIL PROTECTED]> helo=<66-188-103-25.mad.wi.charter.com> from=<[EMAIL PROTECTED]> helo=<c68.113.212.39.ts46v-09.otn-d1.ftwrth.tx.charter.com> from=<[EMAIL PROTECTED]> helo=<dell1.cpe.mvllo.al.charter.com> from=<[EMAIL PROTECTED]> helo=<c68.113.212.197.ts46v-09.otn-d1.ftwrth.tx.charter.com> from=<[EMAIL PROTECTED]> helo=<c66.169.165.73.ts46v-12.otn-e2.ftwrth.tx.charter.com> from=<[EMAIL PROTECTED]> helo=<4476d614.wlawla.wa.charter.com> from=<[EMAIL PROTECTED]> helo=<66-191-38-134.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-24-107-234-98.ma.charter.com> from=<[EMAIL PROTECTED]> helo=<c24.197.242.97.spt.wi.charter.com> from=<[EMAIL PROTECTED]> helo=<24-216-100-33.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-68-118-229-107.ma.charter.com> from=<[EMAIL PROTECTED]> helo=<c24.197.242.97.spt.wi.charter.com> from=<[EMAIL PROTECTED]> helo=<cable-24-158-216-175.sli.la.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-24-107-234-98.ma.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-24-159-170-136.spa.sc.charter.com> from=<[EMAIL PROTECTED]> helo=<dell1.cpe.mvllo.al.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-68-116-161-138.ma.charter.com> from=<[EMAIL PROTECTED]> helo=<c24.197.242.97.spt.wi.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-68-119-223-243.hkry.nc.charter.com> from=<[EMAIL PROTECTED]> helo=<charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-66-189-24-115.ma.charter.com> from=<[EMAIL PROTECTED]> helo=<66-191-125-181.mad.wi.charter.com> from=<[EMAIL PROTECTED]> helo=<24-159-232-84.jvl.wi.charter.com> from=<[EMAIL PROTECTED]> helo=<c68.117.105.87.ash.wi.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-66-189-24-115.ma.charter.com> from=<[EMAIL PROTECTED]> helo=<c68.113.212.197.ts46v-09.otn-d1.ftwrth.tx.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-24-197-103-076.spa.sc.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-66-189-11-213.ma.charter.com> from=<[EMAIL PROTECTED]> helo=<c66.169.114.7.ts46v-04.otn-a2.ftwrth.tx.charter.com> from=<[EMAIL PROTECTED]> helo=<c68.117.53.235.rose.mn.charter.com> from=<[EMAIL PROTECTED]> helo=<66-188-111-60.mad.wi.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-24-197-117-106.spa.sc.charter.com> from=<[EMAIL PROTECTED]> helo=<c68.114.218.86.jvl.wi.charter.com> from=<[EMAIL PROTECTED]> helo=<24-196-127-39.fdl.wi.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-68-115-215-099.spa.sc.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-24-151-130-250.ma.charter.com> from=<[EMAIL PROTECTED]> helo=<c68.113.212.39.ts46v-09.otn-d1.ftwrth.tx.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-66-169-53-183.spa.sc.charter.com> from=<[EMAIL PROTECTED]> helo=<c68.116.218.74.ts46v-01.conroe.tx.charter.com> from=<[EMAIL PROTECTED]> helo=<cable-24-158-216-175.sli.la.charter.com> from=<[EMAIL PROTECTED]> helo=<c68.117.105.87.ash.wi.charter.com> from=<[EMAIL PROTECTED]> helo=<c68.116.220.75.ts46v-01.conroe.tx.charter.com> from=<[EMAIL PROTECTED]> helo=<c66.169.176.92.ts46v-08.otn-c2.ftwrth.tx.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-24-196-206-123.hkry.nc.charter.com> from=<[EMAIL PROTECTED]> helo=<66-188-111-60.mad.wi.charter.com> from=<[EMAIL PROTECTED]> helo=<c68.112.169.110.dul.mn.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-66-189-11-213.ma.charter.com> from=<[EMAIL PROTECTED]> helo=<66-188-208-141.roc.mn.charter.com> from=<[EMAIL PROTECTED]> helo=<c68.114.233.197.fdl.wi.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-24-197-117-106.spa.sc.charter.com> from=<[EMAIL PROTECTED]> helo=<cpe-24-197-103-076.spa.sc.charter.com> from=<[EMAIL PROTECTED]> helo=<c24.197.242.97.spt.wi.charter.com> What a delightful relief!! Every one of those MAIL FROM: to our users looks perfectly legitimate!! :)) The other group below is the mail addressed to our known users from charter where the HELO does NOT contain charter.com. That is, these endearing, earnest charter customers had the initiative and/or smarts to change the HELO name to represent their "legitimate business domain". As you go through this list, you will probably have to remind yourself that these are from charter.com IPs: from=<[EMAIL PROTECTED]> helo=<24.159.170.136> from=<[EMAIL PROTECTED]> helo=<pldi.net> from=<[EMAIL PROTECTED]> helo=<wild-college-party-videos.com> from=<[EMAIL PROTECTED]> helo=<girls-4-me.us> from=<[EMAIL PROTECTED]> helo=<drumandbass.de> from=<[EMAIL PROTECTED]> helo=<juergen-steckenreiter.de> from=<[EMAIL PROTECTED]> helo=<localhost> from=<[EMAIL PROTECTED]> helo=<localhost> from=<[EMAIL PROTECTED]> helo=<localhost> from=<[EMAIL PROTECTED]> helo=<localhost> from=<[EMAIL PROTECTED]> helo=<localhost> from=<[EMAIL PROTECTED]> helo=<localhost> from=<[EMAIL PROTECTED]> helo=<localhost> from=<[EMAIL PROTECTED]> helo=<localhost> from=<[EMAIL PROTECTED]> helo=<localhost> from=<[EMAIL PROTECTED]> helo=<localhost> from=<[EMAIL PROTECTED]> helo=<localhost> from=<[EMAIL PROTECTED]> helo=<localhost> from=<[EMAIL PROTECTED]> helo=<localhost> from=<[EMAIL PROTECTED]> helo=<localhost> from=<[EMAIL PROTECTED]> helo=<ozestock.com.au> from=<[EMAIL PROTECTED]> helo=<eudoramail.com> from=<[EMAIL PROTECTED]> helo=<80.232.219.81> from=<[EMAIL PROTECTED]> helo=<oberon.aif.msk.su> from=<[EMAIL PROTECTED]> helo=<pldi.net> from=<[EMAIL PROTECTED]> helo=<onlinehome.de> from=<[EMAIL PROTECTED]> helo=<margaret.mollerus.org> from=<[EMAIL PROTECTED]> helo=<margaret.mollerus.org> from=<[EMAIL PROTECTED]> helo=<alex-koenen.de> from=<[EMAIL PROTECTED]> helo=<modern-home.co.uk> from=<[EMAIL PROTECTED]> helo=<mailbox.as> from=<[EMAIL PROTECTED]> helo=<pldi.net> from=<[EMAIL PROTECTED]> helo=<gjr.paknet.com.pk> from=<[EMAIL PROTECTED]> helo=<orbit.de> from=<[EMAIL PROTECTED]> helo=<bldrbobs> from=<[EMAIL PROTECTED]> helo=<bldrbobs> from=<[EMAIL PROTECTED]> helo=<bormann.ws> from=<[EMAIL PROTECTED]> helo=<oricom.ca> from=<[EMAIL PROTECTED]> helo=<24.196.244.111> from=<[EMAIL PROTECTED]> helo=<onlinehome.de> from=<[EMAIL PROTECTED]> helo=<gjr.paknet.com.pk> from=<[EMAIL PROTECTED]> helo=<lycos.com> from=<[EMAIL PROTECTED]> helo=<lycos.com> from=<[EMAIL PROTECTED]> helo=<your-ink-place.com> from=<[EMAIL PROTECTED]> helo=<the-inkers-spot.com> from=<[EMAIL PROTECTED]> helo=<64.157.4.78> from=<[EMAIL PROTECTED]> helo=<microsoft.com> from=<[EMAIL PROTECTED]> helo=<isabell-berens.de> from=<[EMAIL PROTECTED]> helo=<sender1188> from=<[EMAIL PROTECTED]> helo=<sender1488> from=<[EMAIL PROTECTED]> helo=<worldcom.ch> from=<[EMAIL PROTECTED]> helo=<sto-helit.de> from=<[EMAIL PROTECTED]> helo=<yahoo.com> from=<[EMAIL PROTECTED]> helo=<mailer.com> from=<[EMAIL PROTECTED]> helo=<monty> from=<[EMAIL PROTECTED]> helo=<monty> from=<[EMAIL PROTECTED]> helo=<compuserve.com> from=<[EMAIL PROTECTED]> helo=<derpi.tuwien.ac.at> from=<[EMAIL PROTECTED]> helo=<bleau.de> from=<[EMAIL PROTECTED]> helo=<lycos.ne.jp> from=<[EMAIL PROTECTED]> helo=<mdi-ger.de> from=<[EMAIL PROTECTED]> helo=<24.196.14.173> from=<[EMAIL PROTECTED]> helo=<dplanet.ch> from=<[EMAIL PROTECTED]> helo=<tiscali.co.uk> from=<[EMAIL PROTECTED]> helo=<arti.vub.ac.be> from=<[EMAIL PROTECTED]> helo=<rons-house.de> from=<[EMAIL PROTECTED]> helo=<67.161.71.65> from=<[EMAIL PROTECTED]> helo=<tenbit.pl> ... did you forget? The above MAIL FROM + HELO fields are from __CHARTER__ IPs. Conclusion: absolute total crap from charter.com subscriber networks to our known users. ( and remember, we have earlier already rejected 1100 msgs to unknown users from charter.com. All in day's work over at charter.com! ). So, in conclusion, the "single criteria" of a PTR hostname being in a charter.com subscriber subdomain is reliably indicative of mail abuse. There is no need to accept the DATA command, scan the headers, scan the body, screw around with multiple criteria. The envelope info is sufficient, reject. I have run the same analysis on subscriber network traffic from comcast.com and hsia.telus.com ("High Speed Internet Access" up in Canada), and the results are the same. Total crap. So, it is a perfectly justifiable, defensible policy, based on hard, repeatable data such as the above, to define all subscriber PTR domains to be illegitimate, (which means it is, by definition, impossible to have false positives). There may be some vanishingly tiny number of legitimate mailers on subscriber networks dribbling out a few legit messages/day, but they are illegitimate _by definition_ since they are on subscriber networks. What can you expect to find as users and machines on subscriber networks?: * amateur and semi-pro home spammers * machines with no firewall, so have been compromised. * machines infected with mailer-worms, DDoS agents, and whatever else * machines running as open relays being raped by spammers * machines running as open proxies driven by hard-core proxy abusers And that's just the situation today. In the future, blanket blocking of subscriber networks will be even more defensible and effective due to much higher volumes of subscriber network IPs and their volumes of abusive traffic, because cable/DSL access, still deploying widely in North Amreica, is now within reach of mass markets in Europe, South America, Asia. (I suppose the only continent with no subscriber network abuse is the continent that has essentially no subscriber networks, Africa). You ain't seen nothing, yet. Len _____________________________________________________________________ http://MenAndMice.com/DNS-training: San Jose; Wash DC; Dallas; Atlanta IMGate.MEIway.com: anti-spam gateway, effective on 1000's of sites, free To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
