Security Incidents mailing list archives
Re: Novarg
From: Skip Carter <skip () taygeta com>
Date: Thu, 29 Jan 2004 18:33:39 -0800
I notice someting interesting about the SMTP route that all the Novarg/Mydoom emails are taking to get to my box. I have a personal Linux machine that runs my SMTP server and is MX for wwwdotorg.org. I also have backup MX using DynDNS (www.dyndns.org). I notice that *all* the copies of the Novarg email are coming in via the backup MX, then being forwarded to my box, despite all other emails (spam, virii/worms and real stuff) all going direct to my box...
...
trying to load-balance the multiple records I believe) So, it appears that Novarg actually sorts the DNS responses and sends via the lowest priority MX?
...
So, I guess to stop all the Novarg messages, one could create an extra MX record with a lower priority than anything else, and point it at some bad IP (reserved, localhost, some other IP you own that has no SMTP server...)
I tried this by setting up a honeypot on the lowest priority MX for a domain. I only ran this configuration for a couple of hours, but... not only did it seem to work, but it grabbed lots of 'normal' SPAM as well. Skip -- Dr. Everett (Skip) Carter Phone: 831-641-0645 FAX: 831-641-0647 Taygeta Scientific Inc. INTERNET: skip () taygeta com 1340 Munras Ave., Suite 314 WWW: http://www.taygeta.com Monterey, CA. 93940
Attachment:
_bin
Description:
Current thread:
- RE: Novarg - Stopping .Zip Files, (continued)
- RE: Novarg - Stopping .Zip Files Timmothy Posey (Jan 30)
- Re: Novarg - Stopping .Zip Files Alvin Mills (Jan 30)
- Re: Novarg Dave Laird (Jan 28)
- RE: Novarg Wayne S. Ackley (Jan 28)
- Re: Novarg James Riden (Jan 28)
- RE: Novarg Chris Aguilar (Jan 28)
- RE: Novarg Jeremy Strachan (Jan 28)
- RE: Novarg Stephen Warren (Jan 29)
- Re: Novarg Robin Sheat (Jan 30)
- RE: Novarg steve bernacki (Jan 30)
- Re: Novarg Skip Carter (Jan 30)
- RE: Novarg Duston Sickler (Jan 29)
- RE: Novarg sloppy seconds (Jan 30)
- RE: Novarg Stephen Warren (Jan 29)
- RE: Novarg Robert Morales (Jan 28)
- RE: Novarg Rickert Gerhard (rgerhard) (Jan 29)
- Re: Novarg Ivan Coric (Jan 29)
- RE: Novarg Jeremy Hyland (Jan 30)
- RE: Novarg Ivan Coric (Jan 30)
- Re: Novarg Steve Bremer (Jan 30)