Introduction About Site Map

XML
RSS 2 Feed RSS 2 Feed
Navigation

Main Page | Blog Index

Archive for the ‘Security’ Category

Challenge/Response Gets Blacklisted

Junk mail

LAST night, Brad Templeton pointed out that mail servers which run autoresponders or challenge/response filters could get blacklisted by spamcop.net. This is a database-driven Web site, which various spam filters rely on as a knowledgebase-type service. It also banned our LUG‘s mailing list earlier today.

I have been aware of the problems with such anti-spam tactics for quite some time, but never thought it could lead to this. As some commenters pointed out, other services may indirectly abolish anti-spam practices such as challenge/response, as well lead to banishment from people’s inboxes. Put in Brad’s words:

I learned a couple of days ago my mail server got blacklisted by spamcop.net. They don’t reveal the reason for it, but it’s likely that I was blacklisted for running an autoresponder, in this case my own custom challenge/response spam filter which is the oldest operating one I know of.

My personal solution, as posted in reply to the article, is to use a spam filter ‘on top’ of the challenge/response component. The intent: lowering the amount of challenges. One can reduce the likelihood of banishment in this way, as well as become less of a nuisance to the Net. In other words, it is possible to rule out cases when messsages are rather obviously spam. It leads to lower volume of messages being dispatched, which in turn can avoid blacklisting.

I use SpamAssasin, which is active at a layer higher than challenge/response (in this case Apache with BoxTrapper). Whatever gets scored as spam will be put aside in a mail folder which is reserved for spam. Only messages not marked as spam (and not in the whitelist either) will have a challenge delivered. This cuts down the number challenges by about 70% in my case. It never entails any false positive because I set the thresholds rather high.

Windows Users, Be Alert

Shark attacks

HERE I am to report about yet another critical Windows bug, which many others have blogged about already. This DLL-based exploit has floated about for quite a while. It has now grown tremendously in terms of its scale though.

The victimised user can be infected merely by opening an E-mail message with a graphics files embedded. Older versions of Outlook, for example, have no protection against that. A short visit to a Web site can lead to a malicious program installed on Windows workstations. This flaw was described can be ‘severe’ and it comes at a rather sensitive time of the year. This whole situation relates to a post of mine from yesterday.

As Matt Cutts put it:

…new exploit of the Windows WMF graphics rendering engine that applies to Windows versions from 98 to XP. This is a pretty nasty exploit… You’ll lose some thumbnail previews and such, but if you want to be safe until a patch is available, click Start->Run and then type “regsvr32 /u shimgvw.dll” to disable the vulnerable DLL.

Older related items:

Auction of Excel Vulnerability Intercepted by eBay

Skype and eBay
As information is offered for sale, negotiation
by telephone can seal such transactions

FROM ZDNet comes as item that speaks of yet another odd item ‘on sale’. The article states: “An online auction of a “brand new vulnerability” in Microsoft Excel had reached about $60 when eBay pulled the item late Thursday. A seller using the name “fearwall” started the auction Wednesday evening at 1 cent. It was up to $56 on Thursday afternoon with 21 bids placed, and eBay quashed the auction soon after that.”

Other strange items which I can recall eBay boasting: chewing gums that have been sput out by celebrities, fake love letters, and potato chips.

Funny Data Loss Disasters

Data Recovery - presentation
A single slide from my talk on data recovery (XHTML)

Below is a snippet from an amusing BBC article.

One incident involved a dog that used a USB flash drive as a chew toy and almost ate all its owner’s data.

[...]

But top of the list is an old laptop containing key company data that was found filled with cockroach corpses.

It seems as though computer disasters and Darwin awards are becoming a golden source of joy to the computer literate. This could leverage tentions. People should never be humiliated for being unfamiliar with technology, but then again, this is a blog…

Similar items:

Microsoft Come Under Pressure

Small clock
The clock ticks for Microsoft while their competition evolves

MAKERS of Windows are expected to ship its next version in line with their promises. Release dates get postponed time after time while immature products develop and skip the conventional testing cycle. Having had to re-build Windows Vista from scratch, this becomes worrisome. More worrisome if the fact that a million users migrated from Windows to Apple Mac last year alone. With a flow of critical, and yet unpatched flaws, one wonders: why has Microsoft not fixed them all?

Almost 4 years after the launch of Trustworthy Computing, I found myself wondering why am I staying up till 4:00 AM to deliver an emergency set of instructions (Home and Enterprise) to my readers because Microsoft felt it unnecessary to patch a flaw six months ago that was originally low risk but mutated in to something extremely dangerous.

Timely link: Novell: Vista to Drive User to Linux

Retrieval statistics: 21 queries taking a total of 0.082 seconds • Please report low bandwidth using the feedback form
Original styles created by Ian Main (all acknowledgements) • PHP scripts and styles later modified by Roy Schestowitz • Help yourself to a GPL'd copy
|— Proudly powered by W o r d P r e s s — based on a heavily-hacked version 1.2.1 (Mingus) installation —|