Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: SpamAssassin: users

Trusting TLS for spamfighting purposes?

 

 

SpamAssassin users RSS feed   Index | Next | Previous | View Threaded


kelly.terry.jones at gmail

Oct 6, 2008, 12:27 PM

Post #1 of 3 (193 views)
Permalink
Trusting TLS for spamfighting purposes?

Can SpamAssassin negative score emails that are sent using TLS?

I realize anyone (even spammers) can use TLS, but I tend to trust
encrypting mail servers more than I do non-encrypting ones.

However, I'm guessing all evidence of TLS usage has disappeared by the
time SpamAssassin gets the message?

--
We're just a Bunch Of Regular Guys, a collective group that's trying
to understand and assimilate technology. We feel that resistance to
new ideas and technology is unwise and ultimately futile.


scheidell at secnap

Oct 6, 2008, 12:38 PM

Post #2 of 3 (176 views)
Permalink
Re: Trusting TLS for spamfighting purposes? [In reply to]

> Can SpamAssassin negative score emails that are sent using TLS?
>
> I realize anyone (even spammers) can use TLS, but I tend to trust
> encrypting mail servers more than I do non-encrypting ones.
>
> However, I'm guessing all evidence of TLS usage has disappeared by the
> time SpamAssassin gets the message?

I looked at this a while back.. Lots of spam with TLS from servers.
(too easy to set up in linux/ms)

As to how to check fingerprints:

Depends on your MTA.

Postfix, add this to main.cf:
smtpd_tls_received_header = yes
See this in emails:
Received: from fl.us.spammertrap.net (fl.us.spammertrap.net
[204.89.241.173])
(using TLSv1 with cipher ADH-AES256-SHA (256/256 bits))
(No client certificate requested)
by mail.secnap.net (Postfix) with ESMTPS id 34B33164838
for <scheidell[at]secnap.net>; Sat, 4 Oct 2008 10:29:49 -04

Regardless, I don't see any relationship between TLS and !spam.
In fact, most 'spam' that got through today had tls 'fingerprints' from our
MTA.

Only thing TLS MIGHT help with is zombies (I doubt that the infected bot on
the xp workstation would use TLS encryption). So, using it with p0f, MAYBE,
as in:
If you think p0f or other 'dialup' things this is a workstation, and it has
TLS fingerprints, maybe not trigger the p0f / dialup/dynamic rules.


--
Michael Scheidell, CTO
>|SECNAP Network Security
Winner 2008 Network Products Guide Hot Companies
FreeBSD SpamAssassin Ports maintainer


_________________________________________________________________________
This email has been scanned and certified safe by SpammerTrap(r).
For Information please see http://www.spammertrap.com
_________________________________________________________________________


anfi at onet

Oct 6, 2008, 1:04 PM

Post #3 of 3 (175 views)
Permalink
Re: Trusting TLS for spamfighting purposes? [In reply to]

"Kelly Jones" <kelly.terry.jones[at]gmail.com> wrote:

> Can SpamAssassin negative score emails that are sent using TLS?
>
> I realize anyone (even spammers) can use TLS, but I tend to trust
> encrypting mail servers more than I do non-encrypting ones.
>
> However, I'm guessing all evidence of TLS usage has disappeared by the
> time SpamAssassin gets the message?

1) It may be present in topmost "Received:" header.
2) You may consider deploying SA via milter in SMTP session.
* Milters are supported by sendmail and postfix
* You may try tweaking MIMEDefang.org milter

--
[pl>en: Andrew] Andrzej Adam Filip : anfi[at]onet.eu : anfi[at]xl.wp.pl
You're always thinking you're gonna be the one that makes 'em act different.
-- Woody Allen, "Manhattan"

SpamAssassin users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact lists@gossamer-threads.com
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.