[Mimedefang] SNARE spam detection

Leonard Mills lenm at ops.corpnet.sel.sony.com
Wed Jul 29 17:16:53 EDT 2009

On Wed, 29 Jul 2009, Kenneth Porter wrote:

> If I understand it correctly, there are two methods they use to identify a 
> spamming host:
> 2) They look at how many open ports are on the sender. (Few ports indicates 
> a bot-controlled zombie spammer.)

Ouch.  I hope this approach only becomes popular for vanity domains.  Our
outbounds all have precisely zero inbound ports open to the Internet in


