The Spamhaus Project is a volunteer effort founded by Steve Linford in 1998 that aims to track e-mail spammers and spam-related activity. Steve Linford is a British anti-spam campaigner best known for founding The Spamhaus Project. Year 1998 ( MCMXCVIII) was a Common year starting on Thursday (link will display full 1998 Gregorian calendar) E-mail spam, also known as "bulk e-mail" or "junk e-mail" is a subset of spam that involves nearly identical messages sent to numerous recipients by It is named for the anti-spam jargon term coined by Linford, spamhaus, a pseudo-German expression for an ISP or other firm which spams or willingly provides service to spammers. The German language (de ''Deutsch'') is a West Germanic language and one of the world's major languages. An Internet service provider ( ISP, also called Internet access provider or IAP) is a company which primarily offers their customers access to the Internet
Contents |
Spamhaus is responsible for three widely used anti-spam DNS Blocklists (DNSBLs) — the Spamhaus Block List (SBL), the Exploits Block List (XBL), and the Policy Block List (PBL). A DNS Blacklist, or DNSBL ( definition below) is a means by which an Internet site may publish a list of IP addresses that some people may want to avoid Many internet service providers and other Internet sites use these free services to reduce the amount of spam they take on. An Internet service provider ( ISP, also called Internet access provider or IAP) is a company which primarily offers their customers access to the Internet The SBL, XBL and PBL collectively protect over 500 million e-mail users, according to Spamhaus' web page (December 2006). Like most DNSBLs, their use is controversial. A DNS Blacklist, or DNSBL ( definition below) is a means by which an Internet site may publish a list of IP addresses that some people may want to avoid
The Spamhaus Block List (SBL)[1] targets "verified spam sources (including spammers, spam gangs and spam support services). " Its goal is to list IP addresses belonging to known spammers, spam operations, and spam-support services[2]. The SBL's listings are partially based on the ROKSO index of "spam gangs", for which see below.
The Exploits Block List (XBL)[3] targets "illegal 3rd party exploits, including open proxies, worms/viruses with built-in spam engines, and other types of trojan-horse exploits. An open proxy is a Proxy server which is accessible by any Internet user " That is to say, like several other DNSBLs it is a list of known open proxies and exploited computers being used to send spam and viruses. The XBL includes listings gathered by Spamhaus as well as by two contributing DNSBL operations — the Composite Blocking List (CBL) and the Not Just Another Bogus List (NJABL) lists. In computer networking the Composite Blocking List (CBL is a DNS-based Blackhole List of suspected E-mail spam senders In computer networking the Composite Blocking List (CBL is a DNS-based Blackhole List of suspected E-mail spam senders Not Just Another Bogus List, or NJABL is a DNS blacklist. NJABL maintains a list of known and potential spam sources ( Open mail relays, Open proxies Not Just Another Bogus List, or NJABL is a DNS blacklist. NJABL maintains a list of known and potential spam sources ( Open mail relays, Open proxies
The Policy Block List (PBL)[4] is a list that serves many of the same functions of a Dialup Users List, but really it is not a DUL. A Dynamic Users List (DUL is a type of DNSBL which contains the IP addresses an ISP assigns to its customer on a temporary basis often using DHCP The PBL lists not only dynamic and DHCP type IP address space designated as 'not allowed to make direct SMTP connections', but static assignments that shouldn't be sending email without prior arrangement. Examples of such are an ISP's core routers, corporate users required by policy to send via their internal mail server, and unassigned IP addresses. Much of the data is provided to Spamhaus by the owners (ISPs) of the IP address space.
Spamhaus's DNSBLs are offered as a free public service to low-volume mail server operators on the Internet. [5] Spam filtering services and other large sites doing large numbers of queries must instead sign-up for an rsync-based feed of these DNSBLs, which Spamhaus calls its Data Feed[6], at a moderate fee as long as they are not in Spamhaus's top ten worst spam service ISPs list[7], and they must also pass a background check to make sure they do not knowingly or intentionally provide services to spammers. rsync is a Software application for Unix systems which synchronizes files and directories from one location to another while minimizing
Spamhaus also provides two combined DNSBLs. One is the SBL+XBL[8], which allows users to query sbl-xbl. spamhaus. org once and get return codes from both lists. A newer combination is called ZEN[9] (named after founder Linford's dog), which allows users to query zen. spamhaus. org once and get return codes from the SBL+XBL and the newer PBL.
The Spamhaus Register of Known Spam Operations (ROKSO)[10] is a database of "hard-core spam gangs" -- spammers and spam operations who have been terminated from three or more ISPs due to spamming. The ROKSO list is not a DNSBL; it is, rather, a directory of publicly-sourced information about these persons and their business and at times criminal activities.
As Spamhaus operates in the United Kingdom, it is subject to the Data Protection Act which restricts its ability to publish private information legally. The United Kingdom of Great Britain and Northern Ireland, commonly known as the United Kingdom, the UK or Britain,is a Sovereign state located The Data Protection Act ( DPA) is a United Kingdom Act of Parliament. For this reason, ROKSO publishes only information gathered from public sources such as newspapers, court records, incorporation filings, and other public records. Spamhaus also keeps additional information on spammers for disclosure only to law enforcement agencies.
The Spamhaus Don't Route Or Peer (DROP) List[11] is a text file delineating so-called "zombie" (stolen) CIDR blocks and netblocks which are "totally controlled by spammers or 100% spam hosting operations", as shown by SBL listings, with the numbers of the underlying listings as comments. Classless Inter-Domain Routing ( CIDR, pronounced "cider" is a method of categorizing Internet Protocol (IP addresses for the purpose of allocating It is intended not to include netblocks registered to ISPs and sublet to spammers, but only those blocks wholly used by spammers. It is intended to be incorporated in firewalls and routing equipment to block network traffic from and to those blocks.
In September 2006 an American spammer named David Linhardt, operating as "e360 Insight LLC", filed suit in an Illinois state court against Spamhaus for blacklisting his website. Spamhaus initially succeeded in moving the case from state to federal court, but then stopped defending itself against the lawsuit, because it is based in the United Kingdom and outside the jurisdiction of United States courts. The United Kingdom of Great Britain and Northern Ireland, commonly known as the United Kingdom, the UK or Britain,is a Sovereign state located In Law, jurisdiction (from the Latin ius iuris meaning "law" and dicere meaning "to speak" is the practical Authority The United States of America —commonly referred to as the [12][13] The American court had no choice but to award e360 a default judgment totaling $11,715,000 in damages. Spamhaus subsequently announced that it would ignore the judgment. [14][15]
e360 filed a motion in Federal court to force ICANN to remove the domain records of Spamhaus until the default judgment had been satisfied. ICANN (aɪkæn eye-can is the Internet Corporation for Assigned Names and Numbers. [16] This raised issues regarding ICANN's unusual position as an American organization with worldwide responsibility for domain names,[17][18] and ICANN protested[19] that they had neither the ability, nor the authority, to remove the domain records of Spamhaus, which is a UK-based not-for-profit organization.
On 2006-10-20, U. Year 2006 ( MMVI) was a Common year starting on Sunday of the Gregorian calendar. Events 1740 - Maria Theresa takes the throne of Austria. France, Prussia, Bavaria and Saxony S. Federal District Court Judge Charles Kocoras, for the Northern District of Illinois, issued a ruling denying e360's motion, stating in his opinion, that "there has been no indication that ICANN [is] not [an] independent entit[y] [from Spamhaus], thus preventing a conclusion that [it] is acting in concert" with Spamhaus and that the court had no authority over ICANN in this matter. In the United States the title of federal judge usually refers to a Judge appointed by the President of the United States and confirmed by the United States ICANN (aɪkæn eye-can is the Internet Corporation for Assigned Names and Numbers. The court further ruled that removing Spamhaus's domain name registration was a remedy that was "too broad to be warranted in this case," because it would "cut off all lawful online activities of Spamhaus via its existing domain name, not just those that are in contravention" of the default judgment. Kocoras concluded, "[w]hile we will not condone or tolerate noncompliance with a valid order of this court [i. e. Spamhaus' refusal to satisfy the default judgment] neither will we impose a sanction that does not correspond to the gravity of the offending conduct. "[20][21]
In June 2007 Spamhaus requested the national registry of Austria nic.at to unregister a number of domains because of their use for phishing purposes [22]. A domain name registry, also called Network Information Centre (NIC is part of the Domain Name System (DNS of the Internet which converts Domain Austria (Österreich ( officially the Republic of Austria (Republik Österreich In the field of computer security phishing is the Criminally Fraudulent process of attempting to acquire sensitive information such as usernames Passwords The registry nic. at rejected that request and argued that they would break Austrian law when doing so. Further nic. at argued that the respective DNS-providers should remove the domain.
To put more pressure on the Austrian registry Spamhaus put the mail server of nic. at on their spam blacklist for several days which caused interference of mail traffic. [23]. For some time Spamhaus had a pointer entry (SBL55483) for the single IP address 192. 174. 68. 0/32 to highlight how nic. at supports phishing. This listing did not block any email, since this address is unused. This entry has since been removed. Most of the phishing domains have since been deleted/suspended by the respective DNS-providers.
Spamhaus has been given the blessing of Hormel, to trademark the name Spamhaus in the European Union. Hormel Foods Corporation ( is a food company based in southeastern Minnesota ( Mower County) perhaps best known as the producer of SPAM luncheon meat [24]