SURBL list,
Has anyone seen any emails with hundreds of URIs - meant to overload
filtering servers and the SURBL DNS servers, not poison them...?
Matthew Wilson, MCSE (2003), MCSA-Messaging
Network Administrator
matthew(a)boomer.com
Boomer Consulting, Inc.
610 Humboldt
Manhattan, KS 66502
http://www.boomer.com
1-888-266-6375 x 17
I just got a spam that hit 2 SURBL domains. Advert for "Send your kids an
email from santa!" How nice of spammers to not only tkae your $10, but
harvest your children's email account and name as well. I'll be drafting up
a warning to my users shortly. Others may want to do the same. Spread the
love :)
Content preview: Commercial Announcement
======================================= Get a Letter From Santa! Go
here to get started:
http://kelepouri113.com/ssnbpsq.php?oioWAHTwnlp94ooMSG_bcfchahj.3284859ioWAH
Twnlp94oo22SJWMerchantsOverseas.comioWAHTwnlp94oo1027163931&f=493&i=1908
[...]
Content analysis details: (5.2 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
0.7 EXCUSE_6 BODY: Claims you can be removed from the list
0.8 HTML_IMAGE_ONLY_20 BODY: HTML: images with 1600-2000 bytes of words
0.0 HTML_MESSAGE BODY: HTML included in message
0.2 HTML_90_100 BODY: Message is 90% to 100% HTML
0.6 MY_ALT RAW: Empty ALT uri
0.5 MY_NO_QU RAW: Q without a U
0.4 MY_OBFU_LONG RAW: One long word!
2.0 URIBL_WS_SURBL Contains an URL listed in the WS SURBL blocklist
[URIs: kelepouri113.comequalispecialvecto.com]
--Chris (Santa don't need this crap right now!)
>-----Original Message-----
>From: Jeff Chan [mailto:jeffc@surbl.org]
>Sent: Monday, November 15, 2004 10:06 PM
>To: Chris Santerre
>Cc: SURBL Discussion list (E-mail)
>Subject: Re: [SURBL-Discuss] Should we list ratware?
>
>
>On Monday, November 15, 2004, 8:13:18 AM, Chris Santerre wrote:
>> MailinglistMaster.com
>
>Q: "Should we list ratware?"
>
>A: Only if the domain appears exclusively in spams.
>
A2: Or if the domain is responsible for one of the major tools for
delivering spams.
I sure the heck don't want anyone in my company getting an email with a link
to their site. I'm guessing ISPs and colleges would feel the same.
--Chris
>-----Original Message-----
>From: Jeff Chan [mailto:jeffc@surbl.org]
>Sent: Monday, November 15, 2004 10:33 PM
>To: SURBL Discussion list
>Subject: Re: [SURBL-Discuss] FW: SURBL+ Checker Submission
>
>
>On Monday, November 15, 2004, 3:54:18 PM, David Funk wrote:
>> On Mon, 15 Nov 2004, Chris Santerre wrote:
>
>>> Both domains in this submission are Whitelisted. Let me guess.....
>>>
>>> sina.com and 6to23.com appear in ham :/
>>>
>>> --Chris
>
>> Not to dissapoint you Chris but sina.com is the Chinese equivalent
>> of yahoo/geocities, big ISP (webmail, hosting, etc).
>> Clearly whitelisting material.
>
>Yes, sina.com one of the globally most visited web sites according
>to Alexa:
>
> http://www.alexa.com/site/ds/top_sites?ts_mode=global&lang=none
>
>6to23.com is also on the Alexa Global 500.
>
>Both have legitimate uses, so we don't list them.
>
LOL....Show offs! ;)
I didn't know Dave could read Chinese :-)
Well then they better clean up their act now, just like yahoo :/
--Chris
>-----Original Message-----
>From: Jeff Chan [mailto:jeffc@surbl.org]
>Sent: Monday, November 15, 2004 11:59 PM
>To: Chris Santerre
>Cc: SURBL Discussion list (E-mail)
>Subject: Re: [SURBL-Discuss] domain check dealsforrecruiters.net
>
>
>On Monday, November 15, 2004, 12:47:43 PM, Chris Santerre wrote:
>> I've got numerous reports on these guys. But I can't make up
>my mind. But I
>> have at least 6 spammy looking submitted mails.
>
>> so anyone got an opinion on dealsforrecruiters.net?
>
>FWIW It shows up on no RBLs.
>
>The real question is whether it has legitimate uses. Can
>we tell from their web site? Their web site seems to offer
>"Targeted-mail marketing" and it also seems to have a
>subscription form. I did not try the subscription but
>if it's open, perhaps vigilantes are signing up anti-spam
>addresses to try to get these guys listed? If so that
>would be highly annoying and a counterproductive waste of
>our time, and I wish they would stop.
>
Agreed. I'm putting them on my watch closely list. They will go
unlisted.....for now.
--Chris
Hi,
I've keep getting the same spam every now and then. I think i have
reported this spam atleast 4 times on the submission form at
rulesemporium.com.
How come it won't be listed?
The domain in the spam is http://www.pinksheetsMUNGED.com and the spam
is about stocks. I get this spam reported almost every day from
different users in our organization.
This is 100% spam!
When will this be added to multi? I can send the message in original if
you want, just let me know.
Thank you
/ Martin
>-----Original Message-----
>From: Jose Marcio Martins da Cruz [mailto:Jose-Marcio.Martins@ensmp.fr]
>Sent: Monday, November 15, 2004 3:27 PM
>To: SM
>Cc: Chris Santerre; Jeff Chan
>Subject: Re: [SURBL-Discuss] Re: [SURBL-Announce] SURBL stats: list hit
>ra tes measured in DNS
>
>
>SM wrote:
>
>>> > http://j-chkmail.ensmp.fr/urlbl/urlbl.txt
>>
>Wrong link...
>
>http://j-chkmail.ensmp.fr/jeff/urlbl/urlbl.txt
>
>Jose-Marcio
Thanks, but.....
These stats are pretty useless:
STATS BY URL BL
=================================================
* ab.surbl 139803 38226
* j-chkmail 207945 54310
* multi.surbl 175657 54486
* ob.surbl 990 260
* sc.surbl 220 180
* ws.surbl 354 246
Because you said it goes by alphabet and stops at first hit. Mutli.surbl
contains everything in SC and WS. So everything after mutli is of no use.
Your other stats are cool though ;)
--Chris
I've got numerous reports on these guys. But I can't make up my mind. But I
have at least 6 spammy looking submitted mails.
so anyone got an opinion on dealsforrecruiters.net?
--Chris
MailinglistMaster.com
They produce StealthMail Master 5.0, rateware.
"The anonymous bulk email software you need to protect your connection from
being shut down when you send out bulk email. With this new technology your
ISP will not have a problem with your bulk e-mail operation. It uses special
proxies for anonymity. Reliable proxy service comes with the software.
Proxies are updated daily. We update our proxies several times a day. The
program gets its speed from up to 300 concurrent connections to different
proxy servers. We carefully select the proxies we add to our
database.Instant and very accurate delivery rate is assessed by the program.
This is the most reliable proxy mailer out there. It is sold on a membership
basis. You can purchase either a monthly or a lifetime membership."
--Chris