[xmail] Re: virus database

2004-06-14 Thread Goesta Smekal
On [Fri, 11.06. 08:56], Tracy wrote: At 03:09 6/11/2004, Goesta Smekal wrote: I do a similar thing for two months : Every mail reportet to be infected gets a second treatment: * look for originating IP (of SMTP envelope, _not_ headers) * resolve its domain * get the MX for that domain *

[xmail] Re: virus database

2004-06-11 Thread Goesta Smekal
On [Thu, 03.06. 14:43], alex wrote: Tracy wrote: At 08:22 6/3/2004, you wrote: This is a CRAZY idea ! In a few time you have banned 50% or more of internet traffic ! alex wrote: It's actually not a crazy idea, because a very large percentage of the virus traffic on the

[xmail] Re: virus database

2004-06-11 Thread Goesta Smekal
On [Mon, 07.06. 08:05], alex wrote: On Jun 7, 2004, at 12:24 AM, Wim Verveen wrote: I am actually trying this out. It doesn't catch a lot until now. Maybe the database needs to grow or more 'points of measurement' are needed? I think they need more points of measurement, the database

[xmail] Re: virus database

2004-06-11 Thread Liron Newman
Goesta Smekal wrote: I do a similar thing for two months : Every mail reportet to be infected gets a second treatment: * look for originating IP (of SMTP envelope, _not_ headers) * resolve its domain * get the MX for that domain * if the IPs are not equal, block the host, since it is an

[xmail] Re: virus database

2004-06-11 Thread Wim Verveen
Smekal Verzonden: vrijdag 11 juni 2004 9:25 Aan: [EMAIL PROTECTED] Onderwerp: [xmail] Re: virus database =20 On [Mon, 07.06. 08:05], alex wrote: =20 On Jun 7, 2004, at 12:24 AM, Wim Verveen wrote: =20 I am actually trying this out. It doesn't catch a lot until now.=20 Maybe the database

[xmail] Re: virus database

2004-06-11 Thread Tracy
At 03:09 6/11/2004, Goesta Smekal wrote: I do a similar thing for two months : Every mail reportet to be infected gets a second treatment: * look for originating IP (of SMTP envelope, _not_ headers) * resolve its domain * get the MX for that domain * if the IPs are not equal, block the host,

[xmail] Re: virus database

2004-06-11 Thread Davide Libenzi
On Fri, 11 Jun 2004, Liron Newman wrote: Goesta Smekal wrote: I do a similar thing for two months : Every mail reportet to be infected gets a second treatment: * look for originating IP (of SMTP envelope, _not_ headers) * resolve its domain * get the MX for that domain * if the IPs

[xmail] Re: virus database

2004-06-07 Thread alex
On Jun 7, 2004, at 12:24 AM, Wim Verveen wrote: I am actually trying this out. It doesn't catch a lot until now. Maybe the database needs to grow or more 'points of measurement' are needed? I think they need more points of measurement, the database doesnt really grow because they are only

[xmail] Re: virus database

2004-06-07 Thread Wim Verveen
: [xmail] Re: virus database On Jun 7, 2004, at 12:24 AM, Wim Verveen wrote: I am actually trying this out. It doesn't catch a lot until now. Maybe the database needs to grow or more 'points of measurement' are needed? I think they need more points of measurement, the database doesnt=20 really

[xmail] Re: virus database

2004-06-06 Thread Wim Verveen
I am actually trying this out. It doesn't catch a lot until now. Maybe the database needs to grow or more 'points of measurement' are needed? Wim=20 -Oorspronkelijk bericht- Van: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Namens alex Verzonden: donderdag 3 juni 2004 14:11 Aan:

[xmail] Re: virus database

2004-06-03 Thread Servitel srl - Roberto Pavesi
This is a CRAZY idea ! In a few time you have banned 50% or more of internet traffic ! alex wrote: more info: http://virbl.bit.nl/ -- --- SMS ad alta velocità via web: http://www.gatewaysms.it

[xmail] Re: virus database

2004-06-03 Thread Tracy
At 08:22 6/3/2004, you wrote: This is a CRAZY idea ! In a few time you have banned 50% or more of internet traffic ! alex wrote: It's actually not a crazy idea, because a very large percentage of the virus traffic on the Internet originates from end-user boxes (machines that were never

[xmail] Re: virus database

2004-06-03 Thread alex
Servitel srl - Roberto Pavesi wrote: This is a CRAZY idea ! In a few time you have banned 50% or more of internet traffic ! alex wrote: more info: http://virbl.bit.nl/ the internettraffic you're talking about are home pc's sending viruses not mailservers. isp mailserver are whitelisted

[xmail] Re: virus database

2004-06-03 Thread alex
Tracy wrote: At 08:22 6/3/2004, you wrote: This is a CRAZY idea ! In a few time you have banned 50% or more of internet traffic ! alex wrote: It's actually not a crazy idea, because a very large percentage of the virus traffic on the Internet originates from end-user boxes (machines

[xmail] Re: virus database

2004-06-03 Thread Tracy
At 08:43 6/3/2004, you wrote: as adsl-99-25-74-211.dsl.blvloh.ameritech.net). Since these kinds of machines are 1) not intended to deliver mail, and 2) prohibited by their ISP's Terms Of Service or Acceptable Use Policies from running mail servers, there is no reason not to block them. And

[xmail] Re: virus database

2004-06-03 Thread chabral
they can also be pc's on a corporate network going out to the internet by a server o firewall doing nat/pat, so it will be blocking some corporations too. chabral alex [EMAIL PROTECTED] wrote: Servitel srl - Roberto Pavesi wrote: This is a CRAZY idea ! In a few time you have banned 50% or

[xmail] Re: virus database

2004-06-03 Thread Toby Reiter
To bring this to the realm of spam rather than viruses, I have some of the RDNS blocking set up through SpamAssassin. I've noticed that this sometimes creates false positives for mail that originated on a dynamic DSL address, and then was relayed through that users ISP. Would this same problem

[xmail] Re: virus database

2004-06-03 Thread Tracy
At 09:36 6/3/2004, you wrote: To bring this to the realm of spam rather than viruses, I have some of the RDNS blocking set up through SpamAssassin. I've noticed that this sometimes creates false positives for mail that originated on a dynamic DSL address, and then was relayed through that users

[xmail] Re: virus database

2004-06-03 Thread Wim Verveen
Actually some ISP's like xs4all in the Netherlands will block a company network because of that -Oorspronkelijk bericht- Van: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Namens chabral Verzonden: donderdag 3 juni 2004 14:58 Aan: [EMAIL PROTECTED] Onderwerp: [xmail] Re: virus database

[xmail] Re: virus database

2004-06-03 Thread Leonardo Cabral
] Namens chabral Verzonden: donderdag 3 juni 2004 14:58 Aan: [EMAIL PROTECTED] Onderwerp: [xmail] Re: virus database they can also be pc's on a corporate network going out to the internet by a server o firewall doing nat/pat, so it will be blocking some corporations too. chabral

[xmail] Re: virus database

2004-06-03 Thread Wim Verveen
juni 2004 16:50 Aan: [EMAIL PROTECTED] Onderwerp: [xmail] Re: virus database we have a big world with millions of internet users, no? well, here in argentina thats very common. The isp gives an internet access and each company uses it as it likes, for example, giving his lan internet access via