[Mimedefang] SNARE spam detection

Leonard Mills lenm at ops.corpnet.sel.sony.com
Wed Jul 29 17:16:53 EDT 2009



On Wed, 29 Jul 2009, Kenneth Porter wrote:

> If I understand it correctly, there are two methods they use to identify a 
> spamming host:
>... 
> 2) They look at how many open ports are on the sender. (Few ports indicates 
> a bot-controlled zombie spammer.)

Ouch.  I hope this approach only becomes popular for vanity domains.  Our
outbounds all have precisely zero inbound ports open to the Internet in
general.

Len





More information about the MIMEDefang mailing list