>-----Original Message-----
>From: Daniel Quinlan [mailto:quinlan@pathname.com]
>Sent: Monday, June 07, 2004 10:22 PM
>To: spamassassin-dev(a)incubator.apache.org
>Cc: discuss(a)lists.surbl.org
>Subject: SURBL works well on envelope sender
>
*snip*
>
>How's the multi roll-out going? It would definitely be handy for this
>test (the code to support it already exists).
The simple answer is, "Its begining to look a lot like christmas." :)
We are finally making some …
[View More]good headway. Bill has a nice system up. More
_trusted_ people able to make submissions. A little more testing needed, and
some scripts added.
BigEvil.cf will be retiring from its current form soon, and be changing over
to being created off of WS. I can't tell you how happy that makes me!! (And
how much time it saves me!)
Possibility of another SURBL taking the place of BE. 6dos.surbl.org? Still
in discussion.
Those stats should go thru the roof when we change over.
--Chris (The tired one.)
[View Less]
I forgot, DO I add these into the SURBL, or do I keep IPs out for now and
add to my BigEvil dynamic version?
Chris Santerre
System Admin and SARE Ninja
http://www.rulesemporium.com
'It is not the strongest of the species that survives,
not the most intelligent, but the one most responsive to change.'
Charles Darwin
This is a forwarded message
From: Menno van Bennekom <mvbengro(a)xs4all.nl>
To: spamassassin-users(a)incubator.apache.org
Date: Monday, June 7, 2004, 5:00:50 AM
Subject: URI with one slash not recognised by SA/SPAMCOP_URI?
===8<==============Original message text===============
Hi,
I get spam with a different URL, the redirect has only one '/':
<a
href="http://rd.yahoo.com/oashoscy/*http:/hjktccbz.woodwheel.info/mn/num17">
This is not recognised by BIZ_TLD (in this example my …
[View More]copy, INFO_TLD).
I can change that in the regular expression.
But I don't think SPAMCOP_URI_RBL recognizes it too because woodwheel is
in the database but SA gives no hit.
If you click on the link above it works, so it seems the one slash is
possible.
Can anyone confirm that one slash is not recognized?
Regards
Menno van Bennekom
===8<===========End of original message text===========
[View Less]
Not sure if this is a new type of spam or not:
http://www.surbl.org/fitch7826drug.us.4jun04.txt
This example I just received had many real or joe job URIs
with no text in the anchor like:
<a href=3D"http://www.elysian-MUNGED.com"></a>
Perhaps it's trying to run out some counters, but the real
target domain is visible as the last "removal" URI:
<a href=3D"http://=
www.ozone.fitch7826drug-MUNGED.us/d.ddd">here.</a>
> Name: fitch7826drug.us
> Address: …
[View More] 61.250.93.214
Where this IP is in sbl.spamhaus.org of course.
The "ordering" link just before it was broken (no dot, at
least in my MUA, The Bat!):
<a href=3D"http://fitch7826drug=
us/b94">Click
Interestingly SpamCop did parse the message correctly in terms
of ignoring the blank anchors and finding only the clickable
ones.
That said, if urirhsbl or SpamCopURI limit the number of
URIs checked, these could sneak through. A useful behavior
might be to ignore any non-clickable anchors, if we're not
already doing that.
Jeff C.
--
Jeff Chan
mailto:jeffc@surbl.org
http://www.surbl.org/
[View Less]
Hallo und guten Morgen Jeff,
danke für die Email vom 04.06.2004 um 00:43
Jeff Chan schrieb - wrote:
> On Thursday, June 3, 2004, 7:25:06 AM, Chris Santerre wrote:
>> LOL, guess they don't like being added to BigEvil! watchsound.com is Joe
>> Jobbing me now. Poor little pron spammer hosted in China. (61.152.133.68).
>> Feel free to add this to the other SURBL servers, firewall blocks, Host file
>> blocks, squid blocks, ect.....
> FWIW This domain is currently in …
[View More]sc.surbl.org and ws.surbl.org..
> (But not be.surbl.org? That doesn't seem right...)
warum schickst Du mir das? Hab ich damit etwas zu tun?
why do you send that to me? Have done I with that something?
--
Viele Grüße, Kind regards,
Jim Knuth
jk(a)jkart.de
ICQ #277289867
----------
Zufalls-Zitat
----------
Frauen würden sich leichter damit abfinden, dass ihr Mann später
nach Hause kommt, wenn sie sich wirklich darauf verlassen
könnten, dass er nicht früher da ist. [Sidonie-Gabrielle Colette]
----------
Dieser Text hat nichts mit dem Empfänger der Mail zu tun
----------
virengeprüft mit NOD32 Version 1.780 Update 03.06.2004
[View Less]
LOL, guess they don't like being added to BigEvil! watchsound.com is Joe
Jobbing me now. Poor little pron spammer hosted in China. (61.152.133.68).
Feel free to add this to the other SURBL servers, firewall blocks, Host file
blocks, squid blocks, ect.....
Thankfully a LOT of people have wised up to Joe Jobs and seem to be checking
the sending IP vs. the From. So I don't get many complaints.
I guess I should be flatered?
Chris Santerre
System Admin and SARE Ninja
http://www.rulesemporium.…
[View More]com
'It is not the strongest of the species that survives,
not the most intelligent, but the one most responsive to change.'
Charles Darwin
[View Less]
They *seem* to be white. But have spammers signup and run one time spam
runs. They aren't in the URL links, but are the senders. Just something to
look out for.
However, surpluscomputers.com can be blacklisted to the stoneage! ALong with
softwareandstuff.com !
Chris Santerre
System Admin and SARE Ninja
http://www.rulesemporium.com
'It is not the strongest of the species that survives,
not the most intelligent, but the one most responsive to change.'
Charles Darwin
>-----Original Message-----
>From: Kris Deugau [mailto:kdeugau@vianet.ca]
>Sent: Thursday, June 03, 2004 12:47 PM
>To: SURBL Discussion list
>Subject: Re: [SURBL-Discuss] Whitelist sparklist.com
>
>
>Chris Santerre wrote:
>> However, surpluscomputers.com can be blacklisted to the stoneage!
>> ALong with softwareandstuff.com !
>
>Why? Their list management seems... dubious at times, but they're a
>legit business and I for one specifically signed up …
[View More]for their
>newsletter- which, IIRC, was properly confirmed opt-in. (Both domains
>are for the same company; they've been trying to change their name and
>domain.)
>
>-kgd
Because they sent a SPAM to me, to an email that was setup specifically to
be used by at another site. I make alias emails for everything I sign up
for. So I can track when this happens. They used this email address, which
they somehow got from a competitor of theirs. It was obviously not signed up
for use with them, because I would have made a new one.
So not only did they spam, but they got the address thru ill means. I am
working with the original site to find how they got it. They are NOT
affiliates or partners.
--Chris
[View Less]