This is a forwarded message
From: Menno van Bennekom <mvbengro(a)xs4all.nl>
To: spamassassin-users(a)incubator.apache.org
Date: Monday, June 7, 2004, 5:00:50 AM
Subject: URI with one slash not recognised by SA/SPAMCOP_URI?
===8<==============Original message text===============
Hi,
I get spam with a different URL, the redirect has only one '/':
<a
href="http://rd.yahoo.com/oashoscy/*http:/hjktccbz.woodwheel.info/mn/num17">
This is not recognised by BIZ_TLD (in this example my …
[View More]copy, INFO_TLD).
I can change that in the regular expression.
But I don't think SPAMCOP_URI_RBL recognizes it too because woodwheel is
in the database but SA gives no hit.
If you click on the link above it works, so it seems the one slash is
possible.
Can anyone confirm that one slash is not recognized?
Regards
Menno van Bennekom
===8<===========End of original message text===========
[View Less]
Not sure if this is a new type of spam or not:
http://www.surbl.org/fitch7826drug.us.4jun04.txt
This example I just received had many real or joe job URIs
with no text in the anchor like:
<a href=3D"http://www.elysian-MUNGED.com"></a>
Perhaps it's trying to run out some counters, but the real
target domain is visible as the last "removal" URI:
<a href=3D"http://=
www.ozone.fitch7826drug-MUNGED.us/d.ddd">here.</a>
> Name: fitch7826drug.us
> Address: …
[View More] 61.250.93.214
Where this IP is in sbl.spamhaus.org of course.
The "ordering" link just before it was broken (no dot, at
least in my MUA, The Bat!):
<a href=3D"http://fitch7826drug=
us/b94">Click
Interestingly SpamCop did parse the message correctly in terms
of ignoring the blank anchors and finding only the clickable
ones.
That said, if urirhsbl or SpamCopURI limit the number of
URIs checked, these could sneak through. A useful behavior
might be to ignore any non-clickable anchors, if we're not
already doing that.
Jeff C.
--
Jeff Chan
mailto:jeffc@surbl.org
http://www.surbl.org/
[View Less]
Hallo und guten Morgen Jeff,
danke für die Email vom 04.06.2004 um 00:43
Jeff Chan schrieb - wrote:
> On Thursday, June 3, 2004, 7:25:06 AM, Chris Santerre wrote:
>> LOL, guess they don't like being added to BigEvil! watchsound.com is Joe
>> Jobbing me now. Poor little pron spammer hosted in China. (61.152.133.68).
>> Feel free to add this to the other SURBL servers, firewall blocks, Host file
>> blocks, squid blocks, ect.....
> FWIW This domain is currently in …
[View More]sc.surbl.org and ws.surbl.org..
> (But not be.surbl.org? That doesn't seem right...)
warum schickst Du mir das? Hab ich damit etwas zu tun?
why do you send that to me? Have done I with that something?
--
Viele Grüße, Kind regards,
Jim Knuth
jk(a)jkart.de
ICQ #277289867
----------
Zufalls-Zitat
----------
Frauen würden sich leichter damit abfinden, dass ihr Mann später
nach Hause kommt, wenn sie sich wirklich darauf verlassen
könnten, dass er nicht früher da ist. [Sidonie-Gabrielle Colette]
----------
Dieser Text hat nichts mit dem Empfänger der Mail zu tun
----------
virengeprüft mit NOD32 Version 1.780 Update 03.06.2004
[View Less]
LOL, guess they don't like being added to BigEvil! watchsound.com is Joe
Jobbing me now. Poor little pron spammer hosted in China. (61.152.133.68).
Feel free to add this to the other SURBL servers, firewall blocks, Host file
blocks, squid blocks, ect.....
Thankfully a LOT of people have wised up to Joe Jobs and seem to be checking
the sending IP vs. the From. So I don't get many complaints.
I guess I should be flatered?
Chris Santerre
System Admin and SARE Ninja
http://www.rulesemporium.…
[View More]com
'It is not the strongest of the species that survives,
not the most intelligent, but the one most responsive to change.'
Charles Darwin
[View Less]
They *seem* to be white. But have spammers signup and run one time spam
runs. They aren't in the URL links, but are the senders. Just something to
look out for.
However, surpluscomputers.com can be blacklisted to the stoneage! ALong with
softwareandstuff.com !
Chris Santerre
System Admin and SARE Ninja
http://www.rulesemporium.com
'It is not the strongest of the species that survives,
not the most intelligent, but the one most responsive to change.'
Charles Darwin
>-----Original Message-----
>From: Kris Deugau [mailto:kdeugau@vianet.ca]
>Sent: Thursday, June 03, 2004 12:47 PM
>To: SURBL Discussion list
>Subject: Re: [SURBL-Discuss] Whitelist sparklist.com
>
>
>Chris Santerre wrote:
>> However, surpluscomputers.com can be blacklisted to the stoneage!
>> ALong with softwareandstuff.com !
>
>Why? Their list management seems... dubious at times, but they're a
>legit business and I for one specifically signed up …
[View More]for their
>newsletter- which, IIRC, was properly confirmed opt-in. (Both domains
>are for the same company; they've been trying to change their name and
>domain.)
>
>-kgd
Because they sent a SPAM to me, to an email that was setup specifically to
be used by at another site. I make alias emails for everything I sign up
for. So I can track when this happens. They used this email address, which
they somehow got from a competitor of theirs. It was obviously not signed up
for use with them, because I would have made a new one.
So not only did they spam, but they got the address thru ill means. I am
working with the original site to find how they got it. They are NOT
affiliates or partners.
--Chris
[View Less]
Hi!
> On Wednesday, June 2, 2004, 9:00:52 AM, Ricardo Ricardo wrote:
>>We are trying to setup a local rbldnsd with rsynced data to answer the
>>DNS queries, but the rbldnsd is not responding.
[...]
>>If I test our cached DNS system:
>>% nslookup adulteroticfiction-MUNGED.com.sc.surbl.org 127.0.0.1
>>*** Can't find server name for address 127.0.0.1: Query refused
>>*** Default servers are not available
Thanks for the tips! I saw that I was not doing the …
[View More]right test... This
one worked:
dig test.surbl.org-MUNGED.sc.surbl.org @127.0.0.1
BTW, I (think I) understand how the whole thing works, but... isn't it
possible to change SpamCopURI to resolve the names at a specific machine
ip/port, instead of changing the DNS setup? Wouldn't this be easier and
safer?
[]s!
--
... Hofstadter's Law: The time and effort required to complete a project
are always more than you expect, even when you take into account
Hofstadter's Law.
[View Less]
>-----Original Message-----
>From: John Andersen [mailto:jsa@pen.homeip.net]
>Sent: Wednesday, June 02, 2004 10:47 PM
>To: discuss(a)lists.surbl.org
>Subject: Re: [SURBL-Discuss] Need assistance in Installing SpamCopURI
>
>
>On Wednesday 02 June 2004 07:05, Raymond Dijkxhoorn wrote:
>> Hi!
>>
>> > You could also try install SpamCopURI through CPAN:
>> >
>> > perl -MCPAN -e shell
>> > install Mail::SpamAssassin::…
[View More]SpamCopURI
>> >
>> >
>> > And the dependencies should be taken care of.
>>
>> Hey, cool, didnt know it was in CPAN yet, great!
>
>That is cool!
>I wish more people would use CPAN for perl things.
>I don't understand why people want to use RPMs for this,
>I've always done Spamassassin this way and its So easy.
>
Hey I didn't know it was on CPAN either! Now that is cool! Very nice guys,
great work!
--Chris
[View Less]