Time to check the rate limits on your mail servers

Jason Frisvold xenophage0 at gmail.com
Thu Feb 3 19:02:51 UTC 2005


On Thu, 03 Feb 2005 12:26:55 -0500, Valdis.Kletnieks at vt.edu
<Valdis.Kletnieks at vt.edu> wrote:
> On Thu, 03 Feb 2005 12:16:41 EST, Jason Frisvold said:
> 
> > Agreed.  And depending on your service, there are different ports
> > worth blocking.  For residential users, I can't see a reason to not
> > block something like Netbios.  And blocking port 25 effectively
> > prevents zombies from spamming.  Unfortunately, it also blocks
> > legitimate users from being able to use SMTP AUTH on a remote server..
> 
> There's a *reason* why RFC2476 specifies port 587....

I assume you're referring to the ability to block port 25 if 587 is
used for submission.  This is great in theory, but if this were the
case, then the Trojan authors would merely alter their Trojan to use
port 587.  Unfortunately, I don't think there's an easy answer to the
spam problem.  Sure, we can educate and block.  But at the end of the
day, the spammers will just find another way to worm those messages
into the network.  Some of these guys are making boatloads of money,
and I hardly think they're willing to throw in the towel if they hit a
bump in the road...  On the flipside, those of us working as admins
and trying to stop the flow of spam are making next to nothing..

*sigh*

-- 
Jason 'XenoPhage' Frisvold
XenoPhage0 at gmail.com



More information about the NANOG mailing list