giza: Giza White Mage (Default)
[personal profile] giza
As some of you know, I had some concerns with Bluesecurity for a while, because I was concerned that they were essentially performing DoS attacks on spammers. However, since their site is back up, I found these awesome papers that do a really good job of explaining exactly how their technology works, and what safeguards they have in place:

http://www.bluesecurity.com/blue-frog/wp/solution_overview_wp.pdf
http://www.bluesecurity.com/blue-frog/wp/blue-security-overview-mjr.pdf

The stuff explained therein puts to rest a lot of the concerns that I had. For one thing, it's not a DDoS at all. A user's system sends a complaint to the spammer if and only if they receive any more spam /after/ the spammer has been given a 10 day "grace period" since Bluesecurity initially contacts them. Also, the total number of complaints sent is less than or equal to the number of spams that are sent after the grace period.

They also made a very important point about "remove lists" which is that they have not worked in the past because there is no enforcement mechanism. Now there is.

I'm gonna download their plugin and give it a try.

(no subject)

Date: 2006-05-06 12:53 am (UTC)
From: [identity profile] taral.livejournal.com
I can't even get the site to load. :(

(no subject)

Date: 2006-05-06 12:54 am (UTC)
From: [identity profile] giza.livejournal.com

I've been hitting the site fine for the last 5 minutes. Do you have stale DNS?

(no subject)

Date: 2006-05-06 01:01 am (UTC)
From: [identity profile] taral.livejournal.com
Not me...

dragon-% dig +short www.bluesecurity.com
72.52.9.7
72.52.8.7
dragon-% dig +short @24.93.41.125 www.bluesecurity.com
127.0.0.1

(no subject)

Date: 2006-05-06 01:04 am (UTC)
From: [identity profile] giza.livejournal.com
What's that IP?

"dig ns bluesecurity.com" gives bsec[1-3].prolexic.net as he nameservers, all of which are in 204.74.66.0/24.

(no subject)

Date: 2006-05-06 01:09 am (UTC)
From: [identity profile] taral.livejournal.com
My ISP's nameserver.

(no subject)

Date: 2006-05-06 01:14 am (UTC)
From: [identity profile] giza.livejournal.com

What's the TTL/expiration?

When I hit their nameservers directly, I see it's 300s. If it's anything greater than that, you probably have old data.

(no subject)

Date: 2006-05-06 01:18 am (UTC)
From: [identity profile] taral.livejournal.com
300... hm. Must be an override by the ISP to stop zombies.

(no subject)

Date: 2006-05-06 01:20 am (UTC)
From: [identity profile] taral.livejournal.com
Okay, now it's being weird:

dragon-% dig +norec @24.93.41.125 www.bluesecurity.com
...
bluesecurity.com. 55178 IN NS ns2.domainthenet.net.
bluesecurity.com. 55178 IN NS ns1.domainthenet.net.

Those aren't right.

(no subject)

Date: 2006-05-06 01:22 am (UTC)
From: [identity profile] giza.livejournal.com

That TTL is less than a day. It's possible that those are old nameservers. Maybe they moved to a new host with more bandwidth. :-)

(no subject)

Date: 2006-05-06 01:34 am (UTC)
From: [identity profile] taral.livejournal.com
Looks like it. Another site has:

bluesecurity.com. 172785 IN NS gdc.prolexic.org.
bluesecurity.com. 172785 IN NS gdc.prolexic.net.

but if you query www.bluesecurity.com's A record, you get:

bluesecurity.com. 300 IN NS bsec2.prolexic.net.
bluesecurity.com. 300 IN NS bsec3.prolexic.net.
bluesecurity.com. 300 IN NS bsec1.prolexic.net.

TTL 300 on nameservers seems awfully temporary.

(no subject)

Date: 2006-05-06 12:59 am (UTC)
From: [identity profile] taral.livejournal.com
Hm. Windows thinks bluesecurity.com -> 127.0.0.1 -- must be a bit of anti-DDOS that's still in the DNS.

(no subject)

Date: 2006-05-06 04:21 am (UTC)
From: [identity profile] thraxarious.livejournal.com
That whole thing where they would send you evil "Because you chose to be a bluefrog member" spam attacks is done and over?

(no subject)

Date: 2006-05-06 03:10 pm (UTC)
From: [identity profile] giza.livejournal.com

Unknown.

Profile

giza: Giza White Mage (Default)
Douglas Muth

April 2012

S M T W T F S
1234567
891011121314
15161718192021
22232425262728
2930     

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags