Ask a Question related to Debian, Design and Development.
-
Johann Koenig #1
Discussion of Challenge/Response
Because this topic is getting somewhat out of hand, and is being discussed in various threads, I thought I would try and consolidate it, if only to make it easier for the regulars who aren't interested to ignore one thread, instead of several.
Brief summary:
There are several ways of dealing with spam, including, but not limited to, Spamassassin, Mr. Conner's C-R scripts, and several proprietary ones. This particular discussing deals mostly with Mr. Conner's Mailbox Sentry Program (MSP)
In the fight against spam, there are several solutions that try to balance false positives/negatives, ease of use and ease of maintenance.
/Brief summary
Picking up from where I left off elsewhere:
Reading through Mr. Conner's page [1], I found an interesting concession to the fact that C-R systems could still be abused:
"on rare occassions, you may find yourself being harassed by someone with the patience to send a second mail with a password, or even write a program that automates the process."
This suggests that it would be possible for people sending out Unsolicited Mass Mail (UMM) could set up a system to send out a message, get a challenge, and send back a response, getting themselves whitelisted. Mr. Conner even alludes that such a program already exists:
Alan Connor <alanconnor@earthlink.net> wrote:However, it seems to be that the challenge message is user-defined to a certain degree. Therefore, I suppose one could put the pass in a non-standard place, and fool UMMers.> I have just persuaded a large non-profit organization to install the
> simple server-side software that will allow them to transparently deal
> with people using C-R programs.
Another issue that is not addressed is forged From: headers. Mr. Conner insists that these can not be forged, or at least Received headers can not be:
However, there is no indication the MSP even looks at Received: headers. Truthfully, email is one of the most insecure forms of communication, as far as verifying the sender. PGP seeks to solve that, but that is another topic altogether. The very basis of email, smtp, has no method for verifying a sender.>Mail from debian.org to me must COME from debian.org...
>Don't tell me you have never heard of Received: headers? (etc.)
I hope we can keep this exchange civil, and confined to this new thread, for the benefit of all those reading linux.debian.user.
[1]
[url]http://home.earthlink.net/~alanconnor/msp/msp.html[/url]
--
-johann koenig
now playing: Gass Huffer - Rotten Egg
Today is Prickle-Prickle, the 68th day of Confusion in the YOLD 3169
My public pgp key: [url]http://mental-graffiti.com/pgp/johannkoenig.pgp[/url]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.2 (GNU/Linux)
iD8DBQE/LCmsFk4duwOzQpURAqKfAJ9ulKv/ZNu4ygoV8kh0Wtlmez79NwCePePf
lgspUyN1Y7nULZyHeu8pVU0=
=b+9B
-----END PGP SIGNATURE-----
Johann Koenig Guest
-
OT NT challenge response
I am pretty sure I know the answer to this, but I wanted to ask just to make sure. Our server is Windows 2003 IIS6 with CFMX 7.0 All desktops run... -
NT Challenge response without popup
Hi, I have one page visible to the public which is my loginform. The username and password entered here I check against my LDAP server if they... -
AW7 vs. DirectorMX for psychology experiment using response times AND response answers
Hello, I'm very new to application design, but need to develop a web based application to use at multiple schools as part of an experimental... -
Challenge-response mail filters considered harmful
> From dfokkema@ileos.nl Sun Aug 3 12:04:08 2003 Any decent CR program auto-matically passlists anyone that they send a message to. -
Challenge-response mail filters considered harmful (by spammers)
There is SO much misunderstanding (and disinformation) about CR systems here. Let's say I was going to mail a business. Here's what would...



Reply With Quote

