Hello
I have joined this discussion forum today to ask if there is anything wrong with the multi.surbl.org list? We had been using this list successfully for almost 3 years now. Beginning about 3/15/08, we are no longer getting the same number of hits as we had before. Before 3/15 we routinely saw 6000 - 8000 SuRBL hits per day. Between 3/15 and today we were seeing less then 500 hits per day.
This morning I switched our GWAVA to use black.uribl.com and am now seeing thousands of SuRBL …
[View More]hits. For test purposes I switched back to the multi.surbl.org but in 5 minutes didn't have any hits.
Does anyone else have this problem?
Thank you for any information.
Peter Garcia
[View Less]
SURBL was great when it was running. It made me wonder if I should
even run any other RBL's at all?
This is off topic already but what is generally thought to have less overhead?
It would seem to be that RBLs would but their effectiveness have
really dropped with the use of massive botnets.
Anyhow regarding my topic...
something has changed in the usage of the lists and so my false
positives has jumped.
This is doug swallows plugin for Icewarp MerakMail. (the author has
long since dropped …
[View More]support for this project)
http://clip.drlinky.com/149606
I have altered the scope to not include the header (from the surblg
list I was told to) and also to not scan the ip addresses but to no
avail.
I was getting false positives for test invites I was sending myself
from linked in.
I believe it is the way counting is performed that is messing things
up a bit. From the looks of it a count of 1 is rejected, but 1 is
added to everything anyway surbl_multi_count += 1
Appreciate any information
Thank you
KieranMullen
[View Less]
Are there any plans in the future to move the email based discussion
list to a forum based system with e-mail subscription per topics?
Thank you
KieranMullen
Judging by recent spamassassin-users mailing list messages, Verizon is
hijacking DNS responses that seem to be invalid and replacing them
with their own responses (in oder to drive traffic to their search
sites). Naturally this breaks SURBL lookups. If you are using
Verizon's nameservers and are getting false positives, you may want to
check into this.
Here's one reference:
http://www.freedom-to-tinker.com/?p=1227
Jeff C.
Does anyone have any comments on adding the malware domains at:
http://www.malwaredomains.com/
to the SURBL phising list, with significant filtering to exclude
possible false positives? The actual list would be the third field
of:
http://www.malwaredomains.com/files/domains.txt
The data includes malware and phishing sites.
Cheers,
Jeff C.
AUTOMATED REPLY
------------------------------
NCISP has taken over all support related to previous Aginet ISP services. Please contact them directly at support(a)ncisp.net if you are looking for support.
Scott Wolf
Question for admins
Is it ok if I run a list of 45k IP's I am researching, against SURBL list please ? I didn't want to do it without permission in case you suddenly thought I have become a MUCH larger company !!
Many thanks
Phil
_____________________________________________
Website Hosting from only £5.00 per month.
www.medwayhosting.com - +44 (0)1634 856965
_____________________________________________
Digital & Traditional Printing, and much more
www.medwayprint.com - +44 (0)1634 281199
_____________________________________________
As we know, the storm malware is responsible for a large number of compromised
computers in botnets, for DDOS, for e-card, PDF, and stock spams, etc. A large
number of storm e-card-advertised URI IP addresses are available from the XS
data source but are not currently being listed on XS. (Those IPs, of course
are all or mostly bot-hosted web sites with malware loaders to further spread
storm by compromising more computers and growing the botnets by infecting
anyone who visits the sites.)
…
[View More]Shall we:
1. Blacklist those on XS
2. Add XS into multi.surbl.org as the 128th bit
In principle #1 and #2 could be separate issues, but to get maximum benefit if
#1 is done then #2 should probably be done also.
XS will have likely have much other data added to it in future, including
non-storm domain names and other URI hosts. This would only be a first step.
It's also worth noting that we don't intend XS to be a malware list; we're
still focussed on unsolicited messages and that is the aspect that arguably
makes the storm IPs appropriate for inclusion: their appearance in huge amounts
of bot-sent unsolicited messages. It just happens that the messages are
primarily meant to propagate storm, but they're still unsolicited, bulk, etc.
Also, regarding storm URI IPs, some are currently being added to SC and WS.
Some are probably going onto JP and PH also. But the XS collection would
probably be more comprehensive than the others for now.
Comments?
Jeff C.
[View Less]
http://lists.surbl.org/ seems to be down for me, can anyone else reach it?
--
Kindest regards
Paul Freeman,
NOC4 Limited
+44(0)1844 318 083 (Direct)
+44(0)1844 318 104 (Fax)
------------------------------------------------------------------------
*Confidential Information.*
This e-mail and any attachments (“the message”) contains information
from noc4, which may be privileged and/or confidential. The message is
intended for use only by the organisation(s) or individual(s) named
above (…
[View More]“the recipient”). If you are not the intended recipient, please
be aware that any form of disclosure, copying, distribution or use of
the contents of the message is strictly prohibited. If you have received
the message in error, please notify us by telephone or e-mail as
detailed at the bottom of this message immediately. Activity and use of
the noc4 e-mail system is monitored and recorded to secure its effective
operation and for other lawful business purposes.
The opinions and beliefs expressed in this email may not necessarily be
those of NOC4 Limited.
NOC4 Limited
2 Manor Farm Cottages, Rycote Lane, Thame, OX9 2HF
Registered in England and Wales, Company No. 05356870
VAT Registration No. GB 807 9233 20
*T* +44(0)1844 318 084
*F* +44(0)1844 318 104
*E* * * *sales(a)noc4.net <mailto:sales@noc4.net>*
*support(a)noc4.net <mailto:support@noc4.net>*
*accounts(a)noc4.net <mailto:accounts@noc4.net>*
* *
[View Less]