Yes, we are aware of it and working to shut it down. It is not easy at
all due to how the system works (as is the case with many redirector URLs).
Feel free to block the URL completely. It is only serving ads for AOL
partners really. Should not be a big problem if you can block URLs in
your antispam SW.
-Carl
david(a)platformnetworks.net wrote:
>==============================================================================
> MAIL SECURITY MESSAGE
>======…
[View More]========================================================================
>
>Mail Security is not 100% sure if the attached message is spam or not and
>needs your help to decide.
>
>
>How to help:
>--------------------------
>If the attached message is not spam, please forward this email to
>notspam(a)mailsecurity.net.au so we can correct our database, which will
>stop future messages of this type from being intercepted.
>
>If the attached message is spam, please delete this message and future
>messages like this will be blocked.
>
>Attached Message Details:
>--------------------------
>From: david(a)platformnetworks.net
>Subject: New Redirector?
>
>Thankyou for your help, your assistance helps us to keep our databases as
>up to date as possible.
>--
>Kind Regards,
>
>Mail Security
>www.mailsecurity.net.au
>
>
>========================================================================
> Pain free spam & virus protection by: www.mailsecurity.net.au
> Forward undetected SPAM to: spam(a)mailsecurity.net.au
>========================================================================
>
>
>
>
> ------------------------------------------------------------------------
>
> Subject:
> New Redirector?
> From:
> "David Hooton" <david(a)platformnetworks.net>
> Date:
> Fri, 7 May 2004 15:38:40 +1000
> To:
> <discuss(a)lists.surbl.org>
>
>
> Hi All,
>
> Just found an AOL redirector being abused in a spam:
>
>http://www.aol.com/ams/clickThruRedirect.adp?1=
>
>073757372,2147618210x2147531923,http://www.freeyouraccounts.com/stressfree/=
>
> Not sure if it’s included in the SURBL/SpamCopURI redirector list yet
> or not – is this published anywhere?
>
> Regards,
>
> David Hooton
>
> Senior Partner
>
> Platform Networks
>
> www.platformnetworks.net
>
--
Carl Hutzler
Director, AntiSpam Operations
America Online Mail Operations
cdhutzler(a)aol.com
703.265.5521 work
703.915.6862 cell
[View Less]
On Friday, May 7, 2004, 3:08:13 PM, ITReading ITReading wrote:
>>>> Jeff Chan <jeffc(a)surbl.org> 05/07/2004 4:45:22 PM >>>
>>I don't see any reports about it to SpamCop. You may want to
>>do that.
> That's interesting. I submit all my "false negatives" to
> Spamcop. I know I've submitted at least a dozen or so ". . .
> bravemouser.com . ." messages.
When I tried processing your message I got the message from
SpamCop saying ~"ISP says …
[View More]problem will cease". So the ISP
is presumably working on it.
Let me know if the spam continues, and I'll add bravemouser.com
to my manual blacklist.
Jeff C.
[View Less]
Hello all,
I continue to receive messages with URIs to "bravemouser.com" in the past few weeks. Should this domain be added to one of the surbl lists? Most of the messages are TV Pay Per View spam.
An example of one of the messages can be found here: http://www.aldridge-borden.com/bravemouser.txt
-Charles Solomon
This is a forwarded message
From: Menno van Bennekom <mvbengro(a)xs4all.nl>
To: spamassassin-users(a)incubator.apache.org
Date: Friday, May 7, 2004, 3:35:37 AM
Subject: URI's not recognized
===8<==============Original message text===============
Hi,
I have problems getting URI's recognized by SpamAssassin 2.63
(postfix/amavisd-new).
At first redirects like this were not recognized:
http://rd.yahoo.com*http://spammer.spam.biz
So I removed ^ from the BIZ expression:
uri BIZ_TLD /(?:…
[View More]https?:\/\/|mailto:)[^\/]+\.biz(?:\/|$)/i
Still the following was not recognized:
<a href=3Dhttp://away.goingabroadd.biz/aps/cms/>
Because of the 3D (and other stuff spammers put there lately).
Only by changing 'uri BIZ_TLD' to 'body BIZ_TLD' it gets recognized.
But I use SpamCopURI and that also doesn't recognize URI's with things in
front of http.
And I can't tell SpamCopURI to use the 'body' check instead or uri..
How can I make the URI subroutine recognize these URI's?
Would using SpamAssassin v3.0 help?
Thanks
Menno
===8<===========End of original message text===========
[View Less]
Hi,
When doing "make test" with 0.15 I get:
t/blacklist........ok
t/dnsrbl...........ok
t/extract_urls.....ok
t/mailto...........ok
t/open_redirect....ok 5/6# Failed test (t/open_redirect.t at line 71)
t/open_redirect....NOK 6# Looks like you failed 1 tests of 6.
t/open_redirect....dubious
Test returned status 1 (wstat 256, 0x100)
DIED. FAILED test 6
Failed 1/6 tests, 83.33% okay
t/spamcopuri.......ok
t/whitelist........ok
Failed Test Stat Wstat Total Fail Failed List of Failed
---------------…
[View More]-------------------------------------------------------------
---
t/open_redirect.t 1 256 6 1 16.67% 6
Failed 1/7 test scripts, 85.71% okay. 1/42 subtests failed, 97.62% okay.
Is a module missing - or need to be updated ??
/Brian
[View Less]
Hi All,
Just found an AOL redirector being abused in one of our spamtraps..
The url is on www.aol.com/ams/clickThruRedirect.adp
If you need an exact copy of it I can provide it.
Not sure if its included in the SURBL/SpamCopURI redirector list yet or not
is this published anywhere?
Regards,
David Hooton
Senior Partner
Platform Networks
www.platformnetworks.net
========================================================================
Pain free spam & …
[View More]virus protection by: www.mailsecurity.net.au
Forward undetected SPAM to: spam(a)mailsecurity.net.au
========================================================================
[View Less]
I have just released SpamCopURI 0.15. I have fixed a few bugs
that were reported and also added some url extraction so open_redirect
resolution isn't need any longer for urls that redirect through
google.com, msn.com, yahoo.com or any site that redirects based
on a url being passed in the query or path portion.
The install *should* be smoother. The Makefile.PL now attempts
to detect …
[View More]where SpamAssassin was installed and place itself in
that directory. See the Changes file for a complete list.
https://sourceforge.net/projects/spamcopuri/
--eric
[View Less]
Justin points out a feature that would be nice to back-port into
SA 2.63....
From: Justin Mason
To: spamassassin-users
Date: Thursday, May 6, 2004, 9:50:17 PM
Subject: svn commit: rev 10552 - in incubator/spamassassin/trunk: lib/Mail/SpamAssassin t t/data/spam
Justin writes:
> Author: jm
> Date: Thu May 6 21:36:42 2004
> New Revision: 10552
>
> Modified:
> incubator/spamassassin/trunk/lib/Mail/SpamAssassin/Util.pm
> incubator/spamassassin/trunk/t/data/spam/009
&…
[View More]gt; incubator/spamassassin/trunk/t/uri.t
> Log:
> spam spotted in wild evading URIBL, so deal with several URI obfuscations: http://0x425c45de/, http://66.92.0x45.221/, http://1113343455/, http://slashdot.org@1113343456/ in get_uri_list
Jeff C et al --
I'm not sure how the SpamAssassin 2.63 code deals with this, but
I'd suspect it'd miss those URLs... I've just checked in a fix
in 3.0.0, so it might be worth porting it over.
- --j.
[View Less]
>-----Original Message-----
>From: Jeff Chan [mailto:jeffc@surbl.org]
>Sent: Wednesday, May 05, 2004 4:52 PM
>To: SURBL Discuss
>Cc: spamassassin-users(a)incubator.apache.org
>Subject: Re: Bug in Spamcop's surbl add-on module
>
>
>On Wednesday, May 5, 2004, 1:03:15 PM, Chris Santerre wrote:
>
>>>From: Jeff Chan [mailto:jeffc@surbl.org]
>>>bigevil.domains:e.1asphost.com
>>>
>>>However we should be taking off the subdomain before …
[View More]it goes into
>>>the SURBL form. I'll need to check with Chris on how we can
>>>handle that.
>
>> It's not a bug, its a feature! Actually, no its a bug :) I
>have been going
>> thru cleaning these sort of things up. However I started at
>the begining of
>> the B.E. list. This is at rule 181, I haven't even got to
>100 yet! This is
>> left over from my alpha phase of B.E. I've had a lot more
>coffee since then.
>
>Hi Chris,
>Would you mind if I added a quick regex to remove and third or
>higher level domains from .com, .biz, .net, .info, etc. from
>domains before they go into be? It wouldn't be perfect but
>it could help some.
>
>In other words trim down e.1asphost.com to 1asphost.com (etc)
>in my own data munging?
>
>Jeff C.
Jeff my friend, nothing would make me happier :) OK, maybe if you sent me
some models bearing beer to ask me. That might be a little better. But
baring that, sure :-)
--Chris
[View Less]
Hi,
I just wanted to report that yesterday I've installed SpamCopURI 0.14
on RedHat 9 with SA 2.63.
On first try, running "perl Makeifle.PL" did not work.
Apparently, it wanted Mail/SpamAssassin to be on perl 5.8.0 but it was deployed on 5.6.1.
After I created a symlink as follows (watch for line breaks):
>>>
lrwxrwxrwx 1 root root 13 May 5 20:00 /usr/lib/perl5/site_perl/5.8.0/Mail -> ../5.6.1/Mail
<<<
I proceeded installing SpamCopURI without a problem.
I thought …
[View More]that other RH users may encounter the same problem.
Regards,
--
Ilan Aisic
Pointer Software Systems, Ltd.
[View Less]