CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image Malware: AOL Tests New Spam-Blockers image
America Online
AOL Tests New Spam-Blockers
If widely adopted, protocol could identify, halt e-mail using spoofed addresses.
Paul Roberts,
IDG News Service

With its subscribers deluged by unsolicited commercial e-mail, Internet service provider America Online is trying new technology to crack down on one common spammer tool: forged sender addresses, which spammers and virus-writers use to bypass blacklists and trick recipients.

AOL is testing a new e-mail protocol called Sender Permitted From across its entire user base of 33 million subscribers. SPF is designed to eliminate e-mail forgeries by enabling organizations to specify which servers can send mail on behalf of their Internet domain, according to Nicholas Graham, an AOL spokesperson.



How It Works
SPF stops e-mail address spoofing by modifying the Domain Name System to declare which servers can send mail from a particular Internet domain. AOL is using SPF to publish the IP addresses of the servers it uses for outgoing e-mail. DNS is the system that translates numeric IP addresses into readable Internet domain names.

Once widely deployed, SPF records could be consulted by Mail Transfer Agents stationed around the Internet when routing e-mail messages. The agents could then check records for particular domains to determine whether an e-mail message's source is legitimate or spoofed, according to Graham.

AOL briefly tested the protocol two weeks ago, before shutting it off to make technical changes based on feedback from other ISPs, says Graham, who declines to describe the changes.

The program is still experimental and for now AOL is not using SPF to filter mail from other Internet domains, Graham says.



Growing Problem
SPF is just getting off the ground, Graham says. AOL is interested in putting the proposal out there and getting feedback from stakeholders. Those stakeholders include other major ISPs such as Microsoft's MSN, Yahoo, and Earthlink, as well as other major domain owners processing bulk e-mail, Graham says.

The trial is a major test of SPF, which is one of a number of new technologies designed to thwart spammers, according to John Levine, co-chairman of the Anti-Spam Research Group.

SPF patches a hole in Simple Mail Transfer Protocol, which is used to route e-mail messages among in-boxes. Developed in the early 1980s, SMTP was designed to provide a reliable and efficient way to relay messages between host systems running different computer hardware and operating systems.

In recent years, spammers and viruses such as Sobig-F and the recent Beagle/Bagel worm have exploited SMTP's flexibility, easily transposing the actual source of messages with legitimate e-mail addresses from lists that are traded online or harvested from infected computers' hard drives.



Other Attempts
The long-term benefit of SPF is that, when the technology is widely deployed, e-mail providers will be able to associate reputations with Internet domains rather than with IP addresses, which are harder to track, according to Eric Raymond, president of the Open Source Initiative, who gave a presentation on SPF during January's Spam Conference 2004 at the Massachusetts Institute of Technology in Cambridge.

SPF itself will not stop spam, but it will help other antispam technologies like spam traps, by enabling ISPs to track spam back to specific domains and forcing spammers to move to new domains more frequently, Raymond said. The combination of technologies can be likened to a drug cocktail that, taken together, may stop spam, he said.

However, the protocol still has problems, including incompatibility with some e-mail forwarding services and Web sites that use mail forwarding features, Levine says. For example, online greeting card services and news Web sites use forwarding to allow readers to send e-mail cards and articles to friends, Levine notes.

SPF also causes performance problems under certain circumstances and has features that spammers could exploit to slow down and derail the system, he said. I would be surprised if SPF survived in its current form, but something like it might survive, Levine said.

Levine is more optimistic about a technology called domain keys, which Yahoo champions. It uses public key encryption technology at the domain level to verify an e-mail message's sender.


Gathering Data..................................
More at PCWorld
Posted on Friday, 23 January 2004 @ 19:13:53 UTC by phoenix22 (1786 reads)
[ Trackback ]
image

"Malware: AOL Tests New Spam-Blockers" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Microsoft
· OpenSource
· HotScripts
· Babelfish Translator
· W3 Consortium
· Spam Cop
· America Online
· America Online
· More about America Online
· News by phoenix22


Most read story about America Online:
Aluria and WhenU... How do they fit with AOL?

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer