<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://port25.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>SMTPRC</title><link>http://port25.technet.com/archive/2006/06/28/SMTPRC.aspx</link><description>Spam is a well-known problem for many on the Internet. If you have an email account anywhere, chances are you’ve gotten something you didn’t ask for; a “stock tip”, an adult entertainment solicitation, or possibly a plea from an altruistic member of the</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 (Build: 40109.1145)</generator><item><title>re: SMTPRC</title><link>http://port25.technet.com/archive/2006/06/28/SMTPRC.aspx#23158</link><pubDate>Sun, 11 Jan 2009 14:57:59 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:23158</guid><dc:creator>Kendra Taylor</dc:creator><description>&lt;p&gt;hi&lt;/p&gt;
&lt;p&gt;1sroitxx1olpqtub&lt;/p&gt;
&lt;p&gt;good luck&lt;/p&gt;
&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=23158" width="1" height="1"&gt;</description></item><item><title>re: SMTPRC</title><link>http://port25.technet.com/archive/2006/06/28/SMTPRC.aspx#23130</link><pubDate>Sat, 10 Jan 2009 02:22:21 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:23130</guid><dc:creator>Orlando Sandoval</dc:creator><description>&lt;p&gt;hi&lt;/p&gt;
&lt;p&gt;1sroitxx1olpqtub&lt;/p&gt;
&lt;p&gt;good luck&lt;/p&gt;
&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=23130" width="1" height="1"&gt;</description></item><item><title>re: SMTPRC</title><link>http://port25.technet.com/archive/2006/06/28/SMTPRC.aspx#2697</link><pubDate>Fri, 30 Jun 2006 18:58:23 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:2697</guid><dc:creator>fluke</dc:creator><description>anandeep:
&lt;br&gt;Promoting SMTPrc to a novice administrator may end up with a luck rabbits foot effect if it finds nothing it might lead an administrator to believe they are in the clear. &amp;nbsp;
&lt;br&gt;
&lt;br&gt;Before choosing a tool, an administrator should decide what the network policies are. &amp;nbsp;Do your customers/users need to be able to establish SMTP connections directly from their workstation to external SMTP servers. &amp;nbsp;If not, configure the border firewall to block all outbound SMTP connections that don't originate from the established SMTP servers.
&lt;br&gt;
&lt;br&gt;Tools that can be helpful for dealing with administating a large IP space are nessus and snort. &amp;nbsp;One provides active security scanning for machines that might contain exploits. &amp;nbsp;The other is an IDS to do passive scanning for signs of compromised machines.
&lt;br&gt;
&lt;br&gt;I would be happy if you pointed us to a comprehensive set of Windows tools and descriptions on the functionality provided. &amp;nbsp;It would be interesting to see where there are gaps in the FOSS offering that MS solutions could help fill. &amp;nbsp;I would also be interested to know what tools MS would be willing to support running on Wine, Mono, mod_asp, etc. &amp;nbsp;I don't expect all solutions to be FOSS. &amp;nbsp;Nessus v3 isn't even FOSS and there are members of the community that accept that.
&lt;br&gt;
&lt;br&gt;But pointing out tools like SMTPrc and g4u, while both interesting FOSS projects, are not very helpful in the grand scheme of things. &amp;nbsp;Fighting spam with SMTPrc seems like fighting crime with a squirt gun. &amp;nbsp;And g4u as a recovery tools seems to be throwing the baby out with the bath-water.
&lt;br&gt;
&lt;br&gt;There is also already articles available online explaining why RBLs are of limited value in modern day spam fighting.
&lt;br&gt;
&lt;br&gt;I want to discuss how MS current method of handling Sender-ID is in MS best interest in the long run. &amp;nbsp;Should AT&amp;amp;T charged royalities for the transister? &amp;nbsp;Did IBM come out ahead by controlling Microchannel? &amp;nbsp;Could Sony have done something different to make Betamax a widely used standard? &amp;nbsp;Could MS actually come out ahead by providing Sender-ID under less restrictive terms? &amp;nbsp;Is DomainKeys the next EISA or VHS?
&lt;br&gt;
&lt;br&gt;Also, where are we on the road to Cairo? &amp;nbsp;Why can malware (including BotNet) authors hide their start-up from the UI by using Run/RunOnce registry keys? &amp;nbsp;Is the desktop explorer monolithic or can I replace the start button handler object with one that displays the icons referred to in Run/RunOnce in the Startup folder (without also having to also re-write the tray handler, desktop icons, background displayer, etc. objects).
&lt;br&gt;
&lt;br&gt;When someone comes to me with a machine infected with Blackworm and I have a solution but requires BartPE style live CD to work, how can I purchase just the parts of the OS I need for my live CD so I can legally distribute it? &amp;nbsp;(Cairo papers once referred to being able to purchase just the spell checker object from office, is that possible yet?)
&lt;br&gt;
&lt;br&gt;What is stopping the ClamWin anti-virus group from providing a real-time on-access scanner for Windows? &amp;nbsp;Does the Windows DDK/IFS license need to have terms/clauses that most FOSS developers would never agree too? &amp;nbsp;And why is there no FOSS equivalent to *nix's lsof command or SysInternals FileMon/TCPView. &amp;nbsp;Is it because the FOSS community is not interested in writting such tools for Windows or are they locked out from using the example code needed?
&lt;br&gt;
&lt;br&gt;----------
&lt;br&gt;
&lt;br&gt;dogbigair: &amp;nbsp;I just want to point out that smtprc and spamassassin are &amp;nbsp;geared toward two very different functions. &amp;nbsp;One is geared towards fighting outbound spam and the other is geared towards rating inbound spam. &amp;nbsp;However, in addition to including spamassassin, newer distributions also tend to bind the SMTP listener to localhost which also addresses what smtprc is looking for. &amp;nbsp;But since not everyone keeps up with the latest version or configures their software correctly, smtprc does have some limited usefulness.
&lt;br&gt;&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=2697" width="1" height="1"&gt;</description></item><item><title>re: SMTPRC</title><link>http://port25.technet.com/archive/2006/06/28/SMTPRC.aspx#2696</link><pubDate>Fri, 30 Jun 2006 18:18:02 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:2696</guid><dc:creator>hypovex</dc:creator><description>dog: their article was concerning an smtp relay checking utility, you're talking about a mail filtering program. Apples and oranges...&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=2696" width="1" height="1"&gt;</description></item><item><title>re: SMTPRC</title><link>http://port25.technet.com/archive/2006/06/28/SMTPRC.aspx#2694</link><pubDate>Fri, 30 Jun 2006 16:35:59 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:2694</guid><dc:creator>dogbigair</dc:creator><description>I cannot understand why you suggest such an outdated tool. All Linux distributions include SpamAssassin. There is no need to install an inferior product. &lt;img src="http://port25.technet.com/aggbug.aspx?PostID=2694" width="1" height="1"&gt;</description></item><item><title>re: SMTPRC</title><link>http://port25.technet.com/archive/2006/06/28/SMTPRC.aspx#2690</link><pubDate>Fri, 30 Jun 2006 02:35:22 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:2690</guid><dc:creator>anandeep</dc:creator><description>Fluke – thank you very much for your response. &lt;br&gt;&lt;br&gt;As you indicated you wanted in your comment, we at Port 25 ARE listening. &lt;br&gt; &lt;br&gt;&lt;br&gt;This article was obviously not addressed to people like yourself who are deeply knowledgeable about the issues. We have a number of people who are equally knowledgeable in the Windows side, but are dealing with interoperability issues without possessing the familiarity with FOSS that you do. This was intended as a quick and simple tip for them to secure their mail relays with an open source tool. &lt;br&gt;&lt;br&gt; &lt;br&gt;&lt;br&gt;We could have pointed them to a comprehensive set of Windows tools, but I doubt the Port 25 &amp;nbsp;audience would fully appreciate that. Now we find that pointing to open source isn’t satisfactory as well! &lt;br&gt;&lt;br&gt;Your comment will be very valuable to people who click on this blog post, they can use the information you provided to do the investigation to the depth they need.&lt;br&gt;&lt;br&gt;Is there anything specific that you would want Port 25 to address - a discussion of blacklists or of the sender-id? &lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=2690" width="1" height="1"&gt;</description></item><item><title>re: SMTPRC</title><link>http://port25.technet.com/archive/2006/06/28/SMTPRC.aspx#2687</link><pubDate>Thu, 29 Jun 2006 18:44:44 GMT</pubDate><guid isPermaLink="false">af7480c4-26b7-468d-87b0-2acebabb473d:2687</guid><dc:creator>fluke</dc:creator><description>Please tell me this was intended to be a joke instead of a serious attempt on discussing reducing spam in 2006.&lt;br&gt;&lt;br&gt;SMTPrc was an interesting project back in 2002. &amp;nbsp;If you need to monitor multiple IP addresses on the cheap then probably you first step should be contacting SORBS (see &lt;a rel="nofollow" target="_new" href="http://www.us.sorbs.net/"&gt;http://www.us.sorbs.net/&lt;/a&gt;). &amp;nbsp;Unlike SMTPrc, SORBS also takes into account other additional methods of sending spam such as open proxies.&lt;br&gt;&lt;br&gt;But even after checking with SORBS, the biggest source of spam in 2006 seems to be BotNets. &amp;nbsp;The spammer takes advantage of systems that allow for remote execution of arbitary code. &amp;nbsp;For example, MS06-15 at &lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/technet/security/Bulletin/MS06-015.mspx"&gt;http://www.microsoft.com/technet/security/Bulletin/MS06-015.mspx&lt;/a&gt;&lt;br&gt;&lt;br&gt;What makes MS06-15 interesting for someone that wants to issue spam, is that for Windows 98 and Windows ME the OS vendor has already stated they have no intention of addressing the known security issue. &amp;nbsp; (Oddly enough, one of the arguments given against using FOSS is that the roadmap is unclear. &amp;nbsp;But is it truely a clear roadmap that calls for security patches until June 30th while there is also a security bulletin on June 8th that a security patch will *NOT* be provided.)&lt;br&gt;&lt;br&gt;Once a system is exploited to be a member of a BotNet, it will not be detected by SMTPrc since it is a technically not a SMTP relay.&lt;br&gt;&lt;br&gt;Also, several of the subject examples given above (&amp;quot;stock tip&amp;quot;, adult entertainment, etc) tend to also be &amp;quot;Joe Jobs&amp;quot; where the From field is fake. &amp;nbsp;Sender-ID was created as a method to help reduce this type of problem. &amp;nbsp;&lt;br&gt;&lt;br&gt;The Apache Software Foundation (that handles updating the SpamAssassin project) has details as the licensing problems with Sender-ID available:&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://apache.org/foundation/docs/sender-id-position.html"&gt;http://apache.org/foundation/docs/sender-id-position.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;The Debian group has also written a detailed statement as to problems with the Sender-ID license:&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://www.debian.org/News/2004/20040904"&gt;http://www.debian.org/News/2004/20040904&lt;/a&gt;&lt;br&gt;&lt;br&gt;And CircleID which is seprate from both the FOSS groups and Anti-Microsoft groups has an article called &amp;quot;Sender ID: A Tale of Open Standards and Corporate Greed?&amp;quot; which goes into problems adopting Sender ID as an open standard:&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://www.circleid.com/posts/sender_id_a_tale_of_open_standards_and_corporate_greed_part_i/"&gt;http://www.circleid.com/posts/sender_id_a_tale_of_open_standards_and_corporate_greed_part_i/&lt;/a&gt;&lt;br&gt;&lt;br&gt;But thank goodness we have Port 25 to suggest SMTPrc. &amp;nbsp;The FOSS community has given specifics why they can interoperate with Sender-ID and those issues haven't been resolved but at least Port 25 can suggest a GPL solution to finding port 25 open relays. &amp;nbsp;Three cheers for Port 25!&lt;br&gt;&lt;br&gt;And a couple months ago the strangest thing went through my head... &amp;quot;Port 25... cool... the FOSS community has the ear of the largest player in the computer industry... we might be able to make a difference.&amp;quot; &amp;nbsp;But I guess to really make a difference, I should have just stuck to searching SourceForge all along. &amp;nbsp;*sigh* &amp;nbsp;Oh well.&lt;br&gt;&lt;br&gt;Thanks for pointing the FOSS community to the FOSS community. &amp;nbsp;I now know who to go to when I want to interoperate instead of continuing to get crippled rights to &amp;quot;open&amp;quot; standards.&lt;img src="http://port25.technet.com/aggbug.aspx?PostID=2687" width="1" height="1"&gt;</description></item></channel></rss>