From: James S. <jl...@ma...> - 2008-10-06 02:25:46
|
Hi, Be a good idea if the person in charge of this list reviewed its configuration to prevent the spam that is now flowing. James > -----Original Message----- > From: <cut> > Sent: Monday, 6 October 2008 1:25 p.m. > To: oorexx-announce > Subject: [SPAM] [SPAM] XZWIW绁WZ > > > _______________________________________________ > Oorexx-announce mailing list > Oor...@li... > https://lists.sourceforge.net/lists/listinfo/oorexx-announce > |
From: Bill T. W. <wb...@ar...> - 2008-10-06 16:04:48
|
James, I'm not receiving any SPAM from the list. In fact the only message I received today "tagged" as spam was the title of your message. /s/ Bill Turner, wb4alm |
From: David A. <dav...@gm...> - 2008-10-06 16:21:40
|
Bill Turner, WB4ALM wrote: > James, I'm not receiving any SPAM from the list. > > In fact the only message I received today "tagged" as spam was the title > of your message. > /s/ Bill Turner, wb4alm > > > ------------------------------------------------------------------------- > This SF.Net email is sponsored by the Moblin Your Move Developer's challenge > Build the coolest Linux based applications with Moblin SDK & win great prizes > Grand prize is a trip for two to an Open Source event anywhere in the world > http://moblin-contest.org/redirect.php?banner_id=100&url=/ > _______________________________________________ > Oorexx-announce mailing list > Oor...@li... > https://lists.sourceforge.net/lists/listinfo/oorexx-announce > > The list is generating some spam. I have altered the list to try an eliminate the spam but at this point I am not sure if I have succeeded or not. W. David Ashley ooRexx Team |
From: Klaus A. S. <kse...@gm...> - 2008-10-06 17:06:33
|
David Ashley wrote: > The list is generating some spam. I have altered the list to try an > eliminate the spam but at this point I am not sure if I have succeeded > or not. Make the list read-only for non-subscribers, and kick any subscriber that spams the list. Cheers, -- Klaus Alexander Seistrup http://klaus.seistrup.dk/ |
From: Chip D. <ch...@av...> - 2008-10-07 21:11:29
|
On 10/6/08 17:03 Klaus Alexander Seistrup said: > David Ashley wrote: > >> The list is generating some spam. I have altered the list to try an >> eliminate the spam but at this point I am not sure if I have succeeded >> or not. > > Make the list read-only for non-subscribers, and kick any subscriber > that spams the list. Well, I got four copies of Klaus' email, so I hope you set a high threshold for spamming... ;-) I have been on "announce" for a long time and am not receiving any spam from there. I suspect that the problem is the work of a bot harvesting email addresses and subject lines from selected subscribers. The spam uses the "announce" subject line to make it appear as if it is from a legitimate source in order to slip through your filters. It's a common exploit that I have experienced on lists which I know have not been compromised. -Chip- |
From: Rick M. <obj...@gm...> - 2008-10-07 21:19:43
|
Except in this case, the spam emails really were posted to the announce list. They originals are still in the archives. I suspect if you didn't see the original spam, your ISPs spam filters probably screened them out. Rick On Mon, Oct 6, 2008 at 4:02 PM, Chip Davis <ch...@av...> wrote: > On 10/6/08 17:03 Klaus Alexander Seistrup said: >> David Ashley wrote: >> >>> The list is generating some spam. I have altered the list to try an >>> eliminate the spam but at this point I am not sure if I have succeeded >>> or not. >> >> Make the list read-only for non-subscribers, and kick any subscriber >> that spams the list. > > Well, I got four copies of Klaus' email, so I hope you set a high threshold for > spamming... ;-) > > I have been on "announce" for a long time and am not receiving any spam from > there. I suspect that the problem is the work of a bot harvesting email > addresses and subject lines from selected subscribers. > > The spam uses the "announce" subject line to make it appear as if it is from a > legitimate source in order to slip through your filters. It's a common exploit > that I have experienced on lists which I know have not been compromised. > > -Chip- > > > > ------------------------------------------------------------------------- > This SF.Net email is sponsored by the Moblin Your Move Developer's challenge > Build the coolest Linux based applications with Moblin SDK & win great prizes > Grand prize is a trip for two to an Open Source event anywhere in the world > http://moblin-contest.org/redirect.php?banner_id=100&url=/ > _______________________________________________ > Oorexx-announce mailing list > Oor...@li... > https://lists.sourceforge.net/lists/listinfo/oorexx-announce > |
From: James S. <jl...@ma...> - 2008-10-07 22:50:33
|
Chip, > I have been on "announce" for a long time and am not > receiving any spam from > there. I suspect that the problem is the work of a bot > harvesting email > addresses and subject lines from selected subscribers. > > The spam uses the "announce" subject line to make it appear > as if it is from a > legitimate source in order to slip through your filters. > It's a common exploit > that I have experienced on lists which I know have not been > compromised. > The mail I received came from the sourceforge list server. My mail service uses SPF to detect and refuse mail from unauthorised senders on the basis of the IP address of the machine sending the mail. See the relevant header lines below. Received-SPF: pass (landry.iserve.net.nz: domain of lists.sourceforge.net designates 216.34.181.88 as permitted sender) client-ip=216.34.181.88; envelope-from=oor...@li...; helo=lists.sourceforge.net; Received: from lists.sourceforge.net (lists.sourceforge.net [216.34.181.88]) by landry.iserve.net.nz (Postfix) with ESMTP id 342B780BB for <jl...@ma...>; Sat, 4 Oct 2008 19:55:43 +1300 (NZDT) This means that the mail was sent to me via the machine at IP address 216.34.181.88 (which is the Sourceforge list server). The following header was the first "Received" line of one of the spam messages, which should be the source of the message, but all we can know is that the machine on 58.63.116.135 delivered it to Sourceforge. It may have come from elsewhere before that. Received: from [58.63.116.135] (helo=WWW-99FE8E40F3B) by 1b2kzd1.ch3.sourceforge.com with esmtp (Exim 4.69) id 1Km0xH-0001L1-6S for oor...@li...; Sat, 04 Oct 2008 06:55:32 +0000 From: =?GB2312?B?s8LQob3j?= <454944@AYUPAN.net> Another spam message I received came from Yahoo, which seems genuine in this case (see below) Received: from [194.187.138.131] (helo=smtp.yahoo.com) by 1b2kzd1.ch3.sourceforge.com with smtp (Exim 4.69) id 1KkL2q-0006MW-Ah for oor...@li...; Mon, 29 Sep 2008 15:52:25 +0000 Message-ID: <200...@ya...> From: "cornel" <cornel1208@yahoo> Regards, James |
From: James S. <jl...@ma...> - 2008-10-06 20:49:41
|
Thanks for the replies. I have forwarded the headers (from some recent spam received) to David Ashley, who may be able to use the details to improve the ability of the list to block spam. Regards, James |