Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: Is predictable spam filtering a vulnerability?
From: Jon Fiedler <jmf9 () cwru edu>
Date: Fri, 18 Jun 2004 19:49:29 -0500

David F. Skoll wrote:

On Wed, 16 Jun 2004, R Armiento wrote:

However, 'C':s spam filter silently drops the email.

In my opinion, any spam filter that silently drops e-mail is broken, and
is indeed a security risk.  A spam filter MUST respond with a 500 SMTP
failure code if it rejects a message.

Regards,

David.
This ignores client side spam filters, and doesn't really change the attack. The 500 message would be sent back to A, but not B, so B is still in the dark about C not receiving the emails.

jon


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]