Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


November 28, 2004

More About Blacklists and Passphrases


RSS
View this exclusive article with VIP access -- click here to join |
See More Security Articles Here | Reprints | Or sign up for our VIP Monthly Pass!

Over the past month, I've written about how passphrases can improve security and how blacklists can help better determine whether some email messages might actually be unwanted junk mail. This week, I'll discuss a little bit more about both of those topics, beginning with blacklists.

After last week's edition of this newsletter, a few more readers wrote to offer additional insight regarding the use of blacklists. Charles Oriez pointed out that when you have trouble with a given blacklist service because it has inadvertently blocked your network while trying to block some spammer, it's more effective to get your ISP involved. A blacklist provider might not be willing to listen to you or, if it does listen, it might not take any action to help you. However, your ISP might be able to work things out with the blacklist provider. So get your ISP involved.

Another reader expressed another concern related to ISPs. Sometimes an ISP is to blame when its network addresses are put on blacklists. If what this reader and other people are telling me is correct, some large ISPs are problematic when it comes to spammers using the ISPs' networks. The problems might be related to the ISPs' acceptable use policies, downstream ISPs who resell the large ISPs' services, or other factors I'm not aware of. But in any case, Internet users suffer.

Other readers have suggested that you check out an ISP as thoroughly as possible before you decide to do business with it, and the same holds true for blacklist services. One way to start that process is to use search engines to check the Internet for complaints. But also keep in mind that some people have the mindset of a reckless vigilante. If they receive even one piece of junk mail, they blow a fuse and go into overdrive to do anything they can to get the involved networks blacklisted. And they hurt innocent people in the process. By the same token, there are people with an equally aggressive mindset who run blacklist services. So choose the ISP you use wisely.

We have a nonscientific Instant Poll question on our Web site (which will be removed in a few days) that asks whether you use blacklist services and if you do, how? Please take a minute to see how others are voting and offer your answer.

http://www.windowsitpro.com/windowssecurity#poll

If you use Microsoft Exchange Server as your email solution, you might be interested in reading the recent Web chat, "Fighting Spam in the Exchange 2003 Environment," which was hosted by Microsoft. The chat (at the first URL below) offers some insight into the Intelligent Mail Filter (IMF--at the second URL below), which can help reduce unwanted email.

http://www.microsoft.com/technet/community/chats/trans/exchange/exchange_111004.mspx

http://www.microsoft.com/exchange/downloads/2003/imf/default.asp

Ron Bradley wrote to offer a tip for Exchange administrators. He said that you should consider taking a look at Vamsoft's Open Relay Filter (ORF) add-on for Exchange. ORF uses multiple filtering methods, including DNS blacklists, reverse DNS lookup testing, and whitelisting, as well as keyword, attachment, and recipient filtering, to help reduce unwanted email. For less than $100 per server, it might be an inexpensive way to improve your mail filtering.

http://www.vamsoft.com/orf/orfee_prodspec.asp

Now back to the issue of passphrases, which I discussed in In Focus on October 27 (at the first URL below) and November 3 (at the second URL below). As you recall, I wrote about how using longer passphrases instead of shorter passwords can increase security. We ran a poll during that time that asked, "What password length do you enforce on your network?" Eighty-two percent of respondents said that they use short passwords of 14 characters or less, 10 percent said they use 15 to 24 characters, and 8 percent said they use 35 characters or more. The poll is closed, but you can view the results on our Web site at the third URL below.

http://www.windowsitpro.com/Article/ArticleID/44338/44338.html

http://www.windowsitpro.com/Article/ArticleID/44389/44389.html

http://www.windowsitpro.com/Poll/Index.cfm?Action=PollResults&Q_ID=1668

In my editorials about passphrases, I mentioned Jesper Johansson's article series "The Great Debates: Pass Phrases vs. Passwords." The third and final part of the series was published recently. In it, Johansson discusses the need to make passphrases stronger by using nonalphanumeric characters, how to enforce password policies, and interestingly enough, why setting an account lockout threshold is a bad idea.

http://www.microsoft.com/technet/security/secnews/articles/itproviewpoint110104.mspx

It's long been common knowledge that using an account lockout policy for bad password attempts can lead to Denial of Service (DoS) on a machine if an intruder (or a user who simply forgets his or her password) repeatedly tries to guess a given logon password. Johansson also says that the average cost for a company to reset a locked account is $70! That's a lot more than I would have guessed.

Another issue covered in the article is the use of a custom password-filtering DLL. If you're a developer interested in creating one that fits your needs, see the article for numerous links to helpful information.

Until next time, have a great week.

End of Article



Reader Comments
I agree. A while back when we were on Exchnage 5.5 I needed a cheap spam filter. All the ones for 5.5 were expensive. So I set up one of our 2K servers with SMTP and had it be the gateway with ORF. Worked very well. One feature that it has that is invaluable is the "Allow blocking of Delivery Status Nofications" which is very handy if your mail servers is being flodded with DSN's. We migrated to Exchange 2003 and now use IMF in combination with ORF. It works very well. ORF (ORF has many customizable options) handles blacklist and AD address checks, and IMF handles SPAM at the confidence level. The 2 programs have cut our spam load by 90%. The best part is ORF is 99.00 for a single licence and IMF is free for those who run Exchange 2003. ORF + IMF = The best SPAM solution out on the market today for Microsoft technologies.

Richnep November 30, 2004 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

WinInfo Short Takes: Week of November 24, 2008

An often irreverent look at some of the week's other news, including a Vista Capable dismissal request, Zune price reductions, Morrow musings, Novell and Microsoft sitting in a tree ... two years later, Yahoo!, IE 6 on Windows Mobile, and so much more ...

Have New Features Made Exchange Server Backups Unnecessary?

Cluster continuous replication and Volume Shadow Copy Service might have made backups unnecessary in Exchange 2007, but will admins feel comfortable without a dedicated backup solution in place? ...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events Top 10 Email Security Challenges and Solutions

Introduction to Identity Lifecycle Manager "2"

SQL Server Security: How to Secure, Monitor & Audit Your Databases

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing