Slashdot Mirror


Comcast Thinks About Stopping Zombies

LehiNephi writes "Comcast has finally admitted that its users are responsible for a large amount of spam, and they are thinking about how to stop it. Apparently they haven't been turning a blind eye to the problem after all. The simple, blanket approach of blocking all traffic on port 25 would have too many side effects, particularly for users running their own mail servers. However, they can block that port on individual cable modems-a sort of surgical strike. As far as I'm concerned, the sooner they implement this, the better!"

40 of 592 comments (clear)

  1. read your usage agreement by lseltzer · · Score: 4, Insightful

    Comcast cable modem customers aren't allowed to run mail servers anyway, so I doubt the side-effects would bother them

    1. Re:read your usage agreement by wo1verin3 · · Score: 4, Insightful

      technically speaking as per the terms of service (usage agreement) you can't even choose to be the host in a two player online game because that is a service.

      However, ComCast also lives in the real world. While on paper they could make an argument, they're trying NOT to upset the technical folks in their customer base.

    2. Re:read your usage agreement by Aaden42 · · Score: 5, Insightful

      There's an aweful lot of people missing the point here. To cause trouble for people running their own mail server, they'd need to block INBOUND traffic coming to port 25. That wouldn't stop any of the zombied machines since they're all trying to make OUTBOUND connections going to port 25.

      If you block outgoing 25 (thus stopping zombies) what you also accomplish is preventing any of your customers from using anyone else's SMTP server as their outgoing SMTP server. My web host supports TLS encryption which I prefer to use so at least my neighbors aren't reading my mail.

      Requiring everyone to use the ISP SMTP server is the wrong solution, and it's a complete pain for laptops. I can take my laptop anywhere, plug it in, and know that I can send mail (using authenticated SMTP) through mail.myhost.com. If everybody starts blocking OUTBOUND 25, then whereever I plugin my laptop, I need to ask, "Hey, what's your SMTP server???" A very poor solution to the problem.

      Block 25 for known zombies or just disconnect them completely. When they call ("My Internet's broken!") let 'em know they've gotta patch their box and get some antivirus software (and stop clicking on those damn attachments!!!) before they get their pr0n0 feed turned back on.

    3. Re:read your usage agreement by PygmySurfer · · Score: 4, Insightful

      Yeah, and pop is 110. My point is still valid, I just have an IMAP server in my situation.

      Uhh, no you don't. POP/IMAP only transfer email between your client and your email provider's mail server. SMTP is used to transfer email between hosts on the internet.

      Parent was talking about configuring his/her own SMTP server on their cable connection, and having issues sending mail to specific domains. In this case it was probably because his cable IP was part of some blacklist which says any dynamic IP must belong to a spammer, as there's obviously no use for someone to be running his/her own SMTP server on a lowly dialup or cable connection.

  2. What about legitimate zombies? by Tourney3p0 · · Score: 5, Funny

    This clearly violates the right to maintain your own SCO-attack zombie.

  3. First! by Anonymous Coward · · Score: 5, Insightful

    I think it's a good idea. But why stop there? Disconnect the zombies until they fix the problem on their computer.

  4. Hmm I think they just started... by Grimster · · Score: 4, Interesting

    Had a user come into our help channel last night, unable to send email through his account with us since that morning (yesterday Sun 05/23) and I confirmed the server was working fine so I had him telnet to port 25 - no luck, had him telnet to port 25 on the server I use for email - no dice, had him use port 2525 - SMTP connection opened up fine.

    He was using comcast for his cable modem. Said it just started that day.

    We accept incoming smtp on port 2525 also since my OWN isp at home blocks port 25 (knology) so I have ot use 2525 to send email through my company email server myself.

    --
    --- www.f-theocean.com
  5. Big difference between zombie and server... by LostCluster · · Score: 5, Interesting

    There's a real easy way to tell the difference between a zombie and somebody running a home mail server...

    The zombie will be sending an insane number of e-mails to an insane number of users constantly. No home mail server should be used to run a listserve with anything more than a hundred people or so. Therefore, bursts of port 25 are okay, camping on port 25 is a sign of trouble.

    1. Re:Big difference between zombie and server... by winkydink · · Score: 4, Interesting
      Uh-oh. I better tell the users of my 800-person list and my 500-person list that it's been a great 8-year run, but we shouldn't be using a home mail server for this.

      Time to move it to the garage, I guess.

      --

      "I'd rather be a lightning rod than a seismometer." -Ken Kesey

  6. Registering mail servers? by mcrbids · · Score: 5, Insightful

    What if they had a *simple* process for registering your mail server with them? 5 minutes, maybe $20 and that's it?

    People who run their own mail servers are control freaks and had better be technically minded enough to call the Admins at Comcast in order to register their mail server.

    Otherwise, who'd notice or care?

    --
    I have no problem with your religion until you decide it's reason to deprive others of the truth.
    1. Re:Registering mail servers? by MalleusEBHC · · Score: 5, Interesting

      It doesn't even have to be that difficult. Just block port 25 by default. If someone calls up and asks for it to be enabled, do it free of charge, no questions asked. Now everyone who wants to run a mailserver can do so painlessly, but the average joe zombie wouldn't be able to spread spam because port 25 would be off for him by default. I bet this would stop 90%+ of all the nasty zombie spam.

  7. *insert anime sweat drop* by Faust7 · · Score: 4, Funny

    "We're the biggest spammer on the Internet," network engineer Sean Lutner said at a meeting of an antispam working group in Washington, D.C., last week.

    Seconds later, bangs, thrashes, and pleads for mercy in a very Lutner-like voice could be heard from outside the conference room.

  8. Screw Comcast! by jchawk · · Score: 4, Interesting

    As a mail admin stop the shit yourself.

    Ban - client.comcast.net, and client2.comcast.net

    Since the spammers can't forge the reverse DNS on the IP you can trust your blocking Comcast's dynamic ranges. Their business customers are not on any of the IP's that reverse to client.comcast.net or client1.comcast.net, and residential customers in the blocked dynamic ranges can relay mail to you through comcast's mail servers like they are supposed to.

    There is absolutely no reason in this day and age of spam to run a legit mail server off of a dynamic IP address. :-)

    1. Re:Screw Comcast! by jchawk · · Score: 4, Insightful

      From the comments so far I've seen "I don't have the money to pay for a static IP address.", I know that it sucks that not everyone can have static IP addresses, but that's something you should take up with your provider. Why should the rest of the Internet Service Providers out there pay for your ability to send email from a dyanmic IP address? You can't begin to imagine how much spam we are able to drop because of those two simple blocks (client.comcast.net and client2.comcast.net)... It's to the point where we would need to add at least another mail server to accept the email coming from those ranges. That's simply not something we are willing to do when 99.9999% of all email from those dynamic ranges are spam.

      You can blame me and the other ISP's out there that refuse to accept mail from dynamic ranges, but you should be blaming the spammers for ruining email as we know it, and you should blame your provider for not allowing you to have a static IP address.

      The ISP I work for only does Static IP addresses (except for dialup customers), all of our DSL customers are allocated a static IP address. This is common if you shop around. From what I understand there are many bigger providers that will allow you to have a static IP address for a few more dollars a month if you can show that you are not using it for commerical purposes, furthermore ISP's like SpeakEasy offer static IP addresses as a part of their typical DSL offerings (no i don't work for them).

      Also, if you're running a server on those dynamic ranges with Comcast you are clearly violating their TOS. Again vote with your wallet and find a provider that is more reasonable with their TOS and IP space. Or get a few friends together and pitch in for a virtual server somewhere. You can find a decent virtual server that will suit all of your needs for less then $50 a month, hell get 5 friends together and it's only $10 a month, surely you can afford that. Plus you can say you have your own server somewhere. :-)

  9. Spammer persistence... by Faust7 · · Score: 5, Funny

    However, they can block that port on individual cable modems-a sort of surgical strike.

    Bit like Whack-A-Mole, then?

  10. Wrong approach? by thedillybar · · Score: 4, Insightful
    However, they can block that port on individual cable modems-a sort of surgical strike.

    Why don't they block it on ALL cable modems and let people unblock it if they wish? The majority of users who go through the trouble to unblock it are going to run secure machines. Even if they don't, it's going to reduce the number of spam bots.

    And they won't have the privacy advocates all over them...

    1. Re:Wrong approach? by LostCluster · · Score: 5, Insightful

      What I would love to see somebody come out with is a provider-side web configurable firewall. Basically, a way to tell my ISP "If you're getting incoming port 80 requests coming my way, don't bother me with it."

      In the default configuration, all ports below 1024 should be blocked, and there should be some explanation to the user that if they want to offer a home-based webserver, they have to visit the designated area on the provider's site to indicate that they want port 80 incoming traffic. That way, ISS-worm-of-the-week traffic will not bother your last mile bandwdith if there's no web server home.

      Outgoing ports can be restricted the same way. Outgoing port 25 should only be allowed to official mail servers, unless the user specifically requests otherwise. That way, if a Spam-bot gets in, most users will already be set to not let it out...

  11. What about the children? by Tourney3p0 · · Score: 5, Funny

    Won't someone please think of the zombie child processes?

  12. Nope. by Anonymous Coward · · Score: 5, Informative

    There is actually an 'official' alternate port for this purpose. See:

    http://www.ietf.org/rfc/rfc2476.txt

  13. Re:why port 25 by Caradoc · · Score: 4, Informative

    If the spammer wants to *send* spam out, they're going to aim at port 25 on the target box.

    If they aim at any other port, they're very likely to see nothing but "Connection denied" messages.

    I've already got most of Comcast simply blocked from my mailservers, simply because I never see anything but spam coming from them: /^.*\.client\.comcast\.net/ 550 comcast direct-to-mx

    If they REALLY want to send me e-mail, they need to send it through a non-client address (for example, through Comcast's own mailservers...)

    It's nice to see that someone at Comcast is waking up, though. I'd been reporting spam coming from a triplet of IP addresses for approximately four months before I simply blackholed the entire /24 there.

    Now, to see if they can actually *do* anything about the problem they just noticed...

    --
    Specialization is for insects. - R.A.H.
  14. People still don't understand the zombie situation by bigberk · · Score: 4, Interesting

    We in the anti-spam community have been yelling this for a while. Since early 2004, most spam is sent through unwitting zombies (compromised Windows hosts) that are remotely controlled spam bots. This is not just an open relay issue. These hosts are hacked in an automated fashion and loaded with spamming software.

    Now obviously, there's a lot an ISP can do about this and it doesn't have to be as drastic as blocking port 25 outright. Users which generate suspicious amounts of TCP port 25 traffic could be reassigned IP addresses from a probation-class pool. That is, hosts within that netblock might not be allowed to make port 25 connections, or might be advertised to the world as block-on-sight.

  15. Re:Port 25 by gnuman99 · · Score: 4, Interesting

    Yeap. This is the only way to stem the traffic. People can still run their own mail servers, but all outbound connections should go though the ISP. Afterall, it is not like it is a privacy issue (they can sniff the packets anyway, so bypassing their SMTP server does not help you!)

  16. Comcast's Agreements by Roguelazer · · Score: 5, Informative
    Anybody here ever read a Comcast Usage & Subscriber Agreement? I have. They're quite... chilling to read. Lots of people have posted about the forbidding of running a server of any kind, so here it is: Acceptable Use Policy

    The area you're referring to is
    (xiv) run programs, equipment, or servers from the Premises that provide network content or any other services to anyone outside of your Premises LAN (Local Area Network), also commonly referred to as public services or servers. Examples of prohibited services and servers include, but are not limited to, e-mail, Web hosting, file sharing, and proxy services and servers;

    For example, take a look at this quote, which makes my browser's caching of Slashdot's GNAA posts illegal:
    (ii) post, store, send, transmit, or disseminate any information or material which a reasonable person could deem to be objectionable, offensive, indecent, pornographic, harassing, threatening, embarrassing, distressing, vulgar, hateful, racially or ethnically offensive, or otherwise inappropriate, regardless of whether this material or its dissemination is unlawful;


    Try reading this one: Subscriber Agreement. This section, in particular, gives Comcast permission to view any information transmitted over the network from or to you:
    Comcast shall have no obligation to monitor postings or transmissions made in connection with the Service. However, you acknowledge and agree that Comcast and its agents shall have the right to monitor any such postings and transmissions, including without limitation e-mail, newsgroups, chat, IP audio and video, and web space content
    Section 9's cool too. It says that you waive the right to sue them in a real court, but instead will have a hearing before a "neutral arbitrator". Anyhow, you should read all that stuff. Some of it's absolutely unique.

    If I don't get modded up for this, I'll be amazed
  17. Port blocking by Openstandards.net · · Score: 5, Interesting
    I don't believe any ISP should block ports. It's a slippery slope. The ISPs should be utilities, like electric companies, providing you an unhindered connection to the Internet.

    I have two primary requirements for an ISP. (1) must not block any ports for any reason. (2) must provide at least one static IP.

    AOL blocks game ports, so they can charge you $5 more per month for opening the ports. They were one of the first to change the role of ISP from utility to controlled collector of optimal revenue. I have for at least 5 years told everyone to get rid of AOL. Unfortunately, today, people have come to accept the idea that it's ok for an ISP to block ports.

    As for the zombies, the ISPs should try:

    • Informing their customers that their machines are infected. Seems obvious, but it's obviously rarely done, as most users don't know they are infected.
    • Provide links to free virus detection and spyware removal software. There is a lot of it out there. If the users don't want to by Norton, they could at least try a free one. I bet most don't know that there are free options available.
    • Offer free Linux CDs.
    1. Re:Port blocking by MBCook · · Score: 5, Interesting
      If I set some large device to store energy and then send it back into the grid wrong (lets say it comes into my house at 220v, 60hz so send it at 1500v 300hz) therby screwing everything up for everyone else on my section of the grid, don't you think the power company would come and cut me off?

      In fact, thanks to safties in the power system, if you tried that you'd probably blow up the transformer outside your house. This would cut off you from the rest of the grid and protect everyone else.

      It's the power company's job to give me good service. Steady power, clean, no problems. My ISP (who actually IS Comcast) should be the same way. Fast, reliable, no problems. Instead ISPs often follow your "we're just the middle man" theory. This leads to my 'net connection getting wasted by downloading tons of spam for every real message that should get through.

      The power company won't let you scew up THEIR network. The phone company doesn't look kindly to people hijacking phone lines and using them for free, and ISPs should be no different. They should FIGHT these zombies.

      After all, zombies cut into the bottom line in traffic that has to be passed (both outgoing spam and incomming spam), storage (storing spam on their e-mail servers), and other such things.

      Knock the zombies off the network. This is no slippery slope, this is climbing back UP the "you can do whatever you want even when it makes the internet worse for 99% of people" hill that a blind eye has slid us down.

      I won't lose sleep, and neither should you.

      --
      Comment forecast: Bits of genius surrounded by a sea of mediocrity.
    2. Re:Port blocking by Hays · · Score: 4, Interesting

      You should not make an analogy between ISPs and traditional utilities like the electric company. Electricity is one way. Internet is two way. No matter what you do with your electricity, it won't destroy the rest of the grid. (barring extreme things for which you WILL receive a visit from the electric company). On the other hand, it's easy for one internet costumer to ruin the experience for many others (by sending thousands of spam a day, for instance).

      A better analogy might be a phone company. They sure as heck don't give you freedom to use your phone however you want.

      But anyway, I agree that ISPs should be unhindered connections to the internet, but only in one direction- to the client.

  18. Re:Port 25 by bigberk · · Score: 4, Insightful
    All they nned to do is to restrict SMTP outbound connections to their own mailservers.
    Ummm.... no, that alone won't do it. They also have to have vigorous spam and virus controls on their mail server. Otherwise the ISP's mail servers will just relay the spam and viruses. SWEN for instance sends itself via the ISP's "proper" relay.

    For example, ISPs that send me plenty of spam and viruses relayed through their main mail servers are: arnet.com.ar, bigpond.com, btinternet.com, libero.it, singnet.com.sg, videotron.ca, wanadoo.fr

    Case in point. Blocking port 25 doesn't stop spam. Booting your spamming customers does.
  19. Zombies: Obligatory by bludstone · · Score: 5, Funny

    "You shot the zombie flanders!"
    "He was a zombie?"

    What did the vegetarian zombie say?
    "Graaiiiinnnnsssss"

    http://www.brains4zombies.com

    Old unix hackers don't die, they just turn into zombie processes.

    I'm sure I'm missing a ton.

    --

    no .sig
  20. Comment removed by account_deleted · · Score: 5, Informative

    Comment removed based on user account deletion

  21. Re:How to tell? by bigberk · · Score: 5, Informative
    Is there an easy way to tell if your own computer is a zombie spambot?
    Yes, there is! If your IP is sending spam, believe me, we will have noticed via our extensive spam traps. Just query your IP at OpenRBL or at dnsstuff to see if you're blocked due to spam received from your IP.

    Note that you can also appear on blocklists for various other reasons. So look into why you're blocked. If you're listed on AHBL, CBL, SpamCop, WPBL for example then your host is probably infected.
  22. Re:An expensive problem. by Caradoc · · Score: 5, Insightful

    They now have a choice - how much is it going to cost them if they do NOT implement some policy that prevents their users from spamming the entire world, and they end up getting all of their e-mail blocked?

    And how much money could have been saved if they'd implemented such a policy when people started telling them it was a problem (it's been several years since people started telling Comcast that their users were a load of USDA Prime Clue-Free Spam Zombies...)

    It's interesting how much money can be saved by paying attention to the small, seemingly innocent details before they add up to be monstrous problems.

    --
    Specialization is for insects. - R.A.H.
  23. Re:Port 25 by Have+Blue · · Score: 4, Insightful

    This story is about compensating for users who are unaware that their computer has been trojaned and is emitting spam. Is getting kicked off your ISP a suitable punishment for that? Comcast is doing the minimum necessary to keep the most people possible happy (except the spammers, and apparently you).

  24. Bot hunting by Enoch+Zembecowicz · · Score: 4, Interesting

    The ISP I work for (name withheld to protect the proactive) has what I consider to be a good policy for handling bots. I think it is good because I came up with it myself. Any host that we get a complaint about is portscanned (all ports are scanned). The output from nmap is then fed into amap for application fingerprinting and mothra to grab banners. We then suspend the customer's internet access until they clean up the computer. On the whole port 25 thing, ever day we find systems that are running SMTP servers on bizarre, very high ports.

    --
    "Who's going to believe a talking head?" - Herbert West
  25. Re:some ISP's already do this by Rick+Zeman · · Score: 4, Insightful

    Speakeasy lets us run whatever the heck we want. Then again, every month or so I see their relay testing in my Postfix logs. It's a strange concept: innocent until found guilty.

  26. What you can't think of is not the issue by frovingslosh · · Score: 4, Insightful
    I can't think of a single good reason why a user needs to run their own outgoing mail server and not relay through the Comcast server.

    Just because you can't think of a reason to not use the Comcast server does not mean there are not good ones. I've recently been put in the same boat by BellSouth, and I assure you there are good reasons for not wanting port 25 blocked.

    First of all, if you, like me, have a notebook and actually move frequently from location to location (home, work, family and friends houses, public sites with wireless access) then you want to be able to configure your mail client so that it will reach a mail server that you can log into and not have to change settings every time you change location. If you have a mail server outside of a "me only" mentality ISP then this is simple and straight forward. But when the ISP blocks port 25 (as well as not letting you use their meil servers whenever you're not originating from their network), it's a royal pain in the ass to reconfigure all the time.

    Also, if you, like me, administer or help maintain a valid mail server off of the Comcast network, you may well find it important to actually send mail through this server. Or you might even have a company policy that states that all business mail must be sent through the compnay mail server. No problem if port 25 isn't blocked and you log into the server you want. Big problem if some short sighted system administrator at your ISP insists that everyone should be expected to use the Internet in exactly the same way.

    And I can't speak about quality of service at Comcast, but at BellSouth the mail server is frequently down. This was not a significant problem if I had to send time critical information out as long as I had port 25 open and could log into one of the other servers I use. Now it's a problem even from my desktop system.

    Fighting spam is great, but fighting stupidity is even more important.

    --
    I'm an American. I love this country and the freedoms that we used to have.
  27. IAAMCCNE by papasui · · Score: 4, Informative

    I am a major cable company network engineer... and while the idea of allowing certain people access to having the ports open is nice in theory, it would be nearly impossible to implement on a large scale operation. With existing infrastructure all restrictions are placed in the access control list on the CMTS router. Without purchasing additional firewall equipment that can service a 1/2 million customers, which would run upwards of hundreds of thousands of dollars. The only way to selectively allow individual ip addresses to be able to use outbond would be to have individual allow statements for each customer who requested it placed on the ACL. Since nobody but the network group is allowed access to these systems we would need individual people dedicated to simply adding ip addresses to the ACL. And of course since each time a packet on port 25 is sent the entire outbound port 25 ACL is processed the load on the routers would be so high that additonal upgrades would be necessary. The entire reason to block all outbound port 25 connections is to stop those with viruses/spam relays from causing the isp's email server from ending up on blacklists from the likes of AOL, earthlink, and other very large isps. So the trade off is you inconvince those customer's who are already violating the acceptable use policy by running a prohibited email server or force them to use your outgoing smtp server. In the end the vast majority of customers are much happier because their email works better, has less spam and garbage and the isp has less work to do by contacting and disabling the service of those customer's spreading viruses or spam via email. If your the type that needs a service that allows servers, static ips, 4 hour service resolutions, higher upload then you can pay extra for those things and get a business class connection. That's really what it boils down to.

  28. Offer a /dev/null machine address too by IBitOBear · · Score: 4, Interesting

    I would dearly love it if Comcast (nee any and every ISP) offered a spesific /dev/null address that I could use with icmp-redirect like clarity.

    When I see a bunch of bogus packets slam into my box that have no reason to exist, I would like to be able to automagically do the IP equivalent of call blocking.

    Sending an ICMP-REDIRECT-like message out in response to a bogus packet should be snuffled up by the ISP equipment and taken as a "call block" request against a particular peer address.

    So if I rig up my firewall to icmp-redirect to some magic address (say 0.0.0.0, which is never legal in a redirect), the upstream router should process it as, say, a 24 hour ban of packets from that address to my address.

    Were such a thing to become common, the ISP could forward that ban on to the next upstream peer and so on until the "well behaved" router closest to the miscreant would be keeping the wastage off of the backbones entirely.

    Since it is a poit-to-point ban it would be rather effective without letting malicious third parties do too much damage unless they could get common-segment with one of the parties.

    Talk about killing a DDOS at the diverse roots.

    Anyway, it would need a little refinement to keep the haxors next door from pretending to be me and cutting all of the sites they sniff me using, you know, check mac addresses or require me to use an activation squib from my firewall from time to time....

    But it should be easy and safe enough once the nearest "Real" router got the do-not-call packet.

    --
    Innocent people shouldn't be forced to pay for inferior software development.
    --"Code Complete" Microsoft Press
  29. Re:How to tell? by ShaunC · · Score: 4, Interesting
    Your modem activity light is, I suppose, the most foolproof method.
    Back when I had my old Motorola CybrSurfr cable modem, this was a decent way of judging network activity. That modem had a "Send" LED and a "Receive" LED, and while the "Receive" light was typically flashing most of the time, the "Send" light was only blinking if someone on the network was doing something. Unfortunately, when Nimda struck, this method became totally unreliable and has stayed so ever since. The "Send" light was on solid, as my machine dealt with the flood of incoming traffic in one manner or another.

    My Motorola Surfboard's orange "Activity" light (this model doesn't have separate LEDs for TX/RX) is almost always solid, even when I'm not doing anything at all. As if the constant flood of ARP traffic over the cable system wasn't enough, the constant hammering of any number of worms brings the traffic to a steady buzz. I still get Nimda and Code Red attempts on a daily basis, and lots of hits to 3306, which I presume are Slammer. In fact, here's the most recent attempt,
    24.[..].224.119 - - [24/May/2004:23:07:43 -0500] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 65 "-" "-"
    About 8 minutes ago. From a worm that came out in, what, 2001?

    tcpdump or Ethereal are probably the best ways to determine if you've been turned into a zombie. tcpdump | grep smtp, or leave Ethereal running for awhile and scan the output for connections to port 25. If either comes up with a shitload of outbound SMTP traffic, you've probably got a trojanned box.
    --
    Thanks to the War on Drugs, it's easier to buy meth than it is to buy cold medicine!
  30. One solution by japa · · Score: 4, Insightful
    I work at a Finnish ISP and we have an automated system that monitors user traffic. Not the content, but the amount. There are lots of rulesets, which may trigger the action. For example scanning X amount of ports in second (like some viruses do). When users computer is determined to be infected/owned by the system, all outbound http connections are directed to a page telling their system is infected and general information on what to do next. All outbound smtp connections are replied by similar kind of error message (and 500 series reply). Besides getting those replies, the customer is basically disconnected from the net. (s)he can't connect anywhere and can't be connected to.

    The system lets the user out of isolation 30 minutes after the reason for isolation has disappeared. Though there are some users who get into isolation, out of it, back again all day long. One has to wonder what the users is doing with the computer? Just having it on, warming the house? Cause they can't surf the net, they can't send email...

    This system has reduced outbound spam drastically! And the best part is, we don't have to find out who is infected (dynamic IPs) and then try to contact the end user (many times not the one who pays..).

    here's the manufacturer's slide show (don't slashdot him to death..)

  31. Re:proxy everything until asked by Chatterton · · Score: 4, Insightful

    Them: "How may we help you?"
    Me: "Please unblock TCP port 25, both ways"
    Them: "OK"
    , we could do it for 5$ a month

    After all, why should millions of people have not to pay for ten of thousands of needed ports ?