Tim Anderson
Tim Anderson

Port 25 needs policing

Worms would be severely curtailed if all ISPs followed AOL's mail server policy

Written by Tim Anderson

Most viruses and worms spread by email, hitching a ride along with all the spam. It's a particularly effective route for malware and often exploits our psychology. From "I love you" to "Bin Laden captured", the virus-mongers know what makes us click.

So how are these emails sent? In days gone by they would hook into the user's email client, but email clients are better defended now and few successful worms will bother. Instead, they install their own SMTP engine and cut out the middle-man. Once safely installed, a worm like this can churn out a huge volume of messages on a broadband-connected PC, for example.

I had an unpleasant reminder of this recently, when one such machine started sending thousands of messages with my email address as the faked sender. Spam filters can wrongly identify genuine messages, so I glanced through all my email. I was getting about 2,000 viral messages an hour. The headers identified the source of the problem, a machine on the network of a large and highly reputable UK ISP.

I emailed the complaints department, to be told that though the user would be advised, no action would be taken for 24 hours.

In the event the problem was resolved sooner, although I will never know whether my indignant protests speeded things along. This incident highlights a question: to what extent is the ISP, rather than the end-user, responsible for this kind of abuse? After all, most users have no need for outgoing traffic on port 25, other than to the ISP's own mail server. Similarly, on an internal network, responsible administrators disable outgoing traffic on port 25 from machines other than mail servers. It is not possible to enforce best practice on every individual user, but if the major ISPs took action to restrict their customers' use of this port, there would be an immediate drop in malware traffic.

In fact, some ISPs already have such a policy. AOL's Jonathan Lambeth told me that "all traffic on port 25 is redirected through our mail servers, monitored and blocked if viral". Where customers have a legitimate need for outgoing port 25, they are whitelisted on request. It strikes me that AOL has the right policy in this instance.

On the client side, many Windows XP users are looking forward to the final release of Service Pack 2, which is laden with new security features. Will it prevent worms from spewing out emails? Unfortunately not. Contrary to rumour, SP2 does not block outgoing traffic at all. The reason for the misunderstanding is that SP2 maintains an application whitelist, which makes it look as if it monitors outgoing connections. However, this whitelist restricts the applications that can listen for incoming connections, not those that can initiate outgoing connections. This is a valuable security, but it is a shame Microsoft hasn't gone further by blocking outbound traffic.

On the other hand, once a worm is installed, all bets are off whichever personal firewall you use, especially with so many Windows users running with local administrative permissions. Security has to be enforced elsewhere.

Tags:

reader comments

related articles

Windows XP SP2

XP SP2: the business angle

What IT managers need to know about XP SP2 15 Sep 2004

 

Latest Bagle variant bites back

Experts increase risk assessment on Bagle.aq as worm spreads rapidly 10 Aug 2004

Data tsar seeks anti-spam powers

The information commissioner wants new powers to more rapidly halt UK-based spammers 19 Jul 2004

Worried firms consider email boycott

Security concerns threaten future of 'everyone's favourite killer app' 16 Jul 2004

related whitepapers

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation