MX Probe Data Base

 

Home | Probe List | Router ACL's | Mailing List | Security Alerts | R.A.P. | Resources | Donations

 

Mail Probing is done by Vigilante organizations and individuals like ORBS and MAPS. They send test emails to try to spoof mail servers into relaying it. Once a mailserver is found that appears to accept and relay mail they list the server and IP in their RBL (Realtime Black List) database. ISP's that subscribe to thier list block all email from these mailservers.

They claim it is helpful by preventing spam and closing spam servers. While we agree with part of this we do not agree with their methods or policy. Their policy prohibts mail services for all but local dial-in users of the mailserver. This is not possible with many ISP's that provide hosting and web services but do not provide dialup accounts. This is also impossible for ISP's that have clients worldwide that may use a local ISP for effective connection to the Internet. Their policy only supports the largest of ISP's and helps build a monopoly by causing smaller ISP's to not be able to service clients worldwide and by blocking email from other domains on the same mailserver that have never sent spam.
 

We feel it is illegal and causes disruption of business by violating law that states "

California Law where MAPS resides: Business and Professions Code, Section 17538.45 (a):

    (4) "Initiation" of an unsolicited electronic mail advertisement refers to the action by the initial sender of the electronic mail advertisement. It does not refer to the actions of any intervening electronic mail service provider that may handle or retransmit the electronic message.

    (5)(d) An electronic mail service provider shall not be required to create a policy prohibiting or restricting the use of its equipment for the initiation or delivery of unsolicited electronic mail advertisements.

    (5)(e) Nothing in this section shall be construed to limit or restrict the rights of an electronic mail service provider under Section 230(c)(1) of Title 47 of the United States Code, or any decision of an electronic mail service provider to permit or to restrict access to or use of its system, or any exercise of its editorial function.

USC Title 47, Section 230(c)(1) referenced in paragraph (5)(e) above reads as follows:
    (1) Treatment of publisher or speaker
    No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider.

According to this, an "open relay" server of a mail service provider is therefore perfectly legal, and the provider's rights are protected under the law! MAPS RSS and the RBL+ combined lists treat the content publisher (spammer) and the provider (relay) the same.

It can further be argued that the MAPS blackhole lists are a form of organized denial of service (DoS) attack on all providers listed, regardless of where they are located, in violation of the amended Section 502 of the California Penal Code:

    (c)(5) Knowingly and without permission disrupts or causes the disruption of computer services or denies or causes the denial of computer services to an authorized user of a computer, computer system, or computer network.

There is also a supporting paragraph in USC Title 18, Sec 1030 (Fraud and related activity in connection with computers):

    (a) Whoever
    (5)(A) knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer;
"

Our solution is to fight fire with fire. We will list known probes and stay alert for new ones to block at the router. We will provide continued support to help you configure your router and mail servers as needed to use our list of known network abusers.
Note: Would probing their security of web servers and networks for vulnerabilities to BackDoor or Virus Infection not be the same? How about confirming the vulnerabilities by unlawfully accessing the networks or servers, via the vulnerabilities, to then use as Zombie and Warez sharing stations and publish the results for everyone to exploit the same until fixed, if possible. Would that not be the same thing they are doing?....They better hope they have Firewalls, Routers, Switches and Networks we do not install and troubleshoot daily....

Want to help us in our fight to eliminate network abuse and probes? Contribute to our campaign with donations or gifts to help us grow and improve.

This site is operated as part of the HoneyPot-Jar Protection Project to eliminate Mail Probes and Network Abuse.
-MXDB.Com