Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Spam, Scam and Phishbusters » Spammers getting around Spam Assassin
Search Topic:
Uniqs:
802
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Pluto Data Credit Card Charge »
« [scam] Yahoo! Lottery Scam  
AuthorAll Replies

Cybertoad

join:2001-11-08
Houston, TX

reply to nightdesigns
Re: Spammers getting around Spam Assassin

quote:
My web provider is using Spam Assassin which for years has worked great, but I see companies have figured out how to get their "score" low enough to get around the filters.
I am not sure who you are hosting with but the hosting provider where I work uses a lot more than just Spamassassin and continuously monitors and updates the spam protection to adapt to all spammer changes on
a daily basis.

quote:
I'm already running a score threshold of 3.
I would be a little leary reducing the score even that
low because it sets up the possibility of trapping HAM
(non-spam) messages by mistake. There are other much
better ways of doing that without reducing the score.
I would leave the spam trigger score higher and adjust
the scoring values on the individual rules themselves.

quote:
I'm hesitatnt to open the spam e-mails to see what the scores are, because it loads the images in the e-mail, and guess what, more spam!

I use Mozilla Thunderbird for my POP3 email client and it
has the ability to block images until you approve that
they be displayed so that you are able to view messages
without anything being reported back to the spammer. It
also isn't vulnerable to a lot of the security problems
that are common to Outlook and Outlook Express. Plus
there is a "Junk" mail feature with Bayes learning built in
that can sort spam out of your inbox immediately upon
checking your mail.

If you are not using Mozilla Thunderbird, you might want
to seriously consider switching over.


madylarian
The curmudgeonly
Premium
join:2002-01-03
Parkville, MD
reply to nightdesigns
I had to drop down to 2 because so many "pump 'n dump" spams were getting through. I'm building up quite a whitelist, but it's worth it.

mady
--
Honi soit qui mal y pense

rmturner

join:2001-10-18
Kennesaw, GA
·Speed Factory
·Comcast

reply to nightdesigns
Are they using 3.0? And do you have access to your user_prefs file? Someone at my webhost suggested adding these rules to your user_prefs, and they are catching everything for me. Almost zero false positives.

score X_MESSAGE_INFO 10
score URIBL_SBL 10
score URIBL_OB_SURBL 10
score URIBL_PH_SURBL 10
score URIBL_WS_SURBL 10
score URIBL_SC_SURBL 10
score URIBL_AB_SURBL 10
score RCVD_IN_XBL 10
score RCVD_IN_SBL 10

You can check out the default scoring for version 3.0 here:
»spamassassin.apache.org/tests_3_0_x.html
and customize your user_prefs accordingly.
--
"No matter how I struggle and strive, I'll never get out of here alive". Hank Williams


nightdesigns
Gone missing, back soon
Premium
join:2002-05-31
AZ
·Cox HSI

My web provider is using Spam Assassin which for years has worked great, but I see companies have figured out how to get their "score" low enough to get around the filters. I'm now getting 10-15 pieces a day under the radar (still blocks 50+/day). Any tips on block these e-mails too? I've tried specific word filtering, etc, which has helped a little, but not much.

I'm already running a score threshold of 3. I'm hesitatnt to open the spam e-mails to see what the scores are, because it loads the images in the e-mail, and guess what, more spam!
--
The _REAL_ OC: Cookie-cutter soccer moms driving their SUVs through the McDonalds drive-through, blowing away their child's college education on their $600/month car payment, $4500/month mortgage payment, and their plastic surgery/boob job/botox bill.
Forums » Up and Running » Security » Spam, Scam and PhishbustersPluto Data Credit Card Charge »
« [scam] Yahoo! Lottery Scam  


Friday, 27-Nov 04:33:46 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [114] Time Warner Cable Fires Broadside At Broadcasters
· [109] New AT&T Ad Campaign Hits Back At Verizon
· [95] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [70] TiVo Sees Record Customer Losses
· [63] In-Flight Internet Headed For Bumpy Landing?
· [56] Thanksgiving Open Thread
· [38] ICANN Slams DNS Redirection
· [36] Senators Want ACTA Made Public
· [35] Despite Billions In USF Fees, U.S. Libraries Lack Bandwidth
Most people now reading
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Bell Response to PIPEDA Request [TekSavvy]
· Newegg Black Friday Sale started [Users Find Hot Deals]
· HOW-TO: QoS and Tomato (fixes "choppy voice") [MagicJack]
· Windows 7 boot manager editing questions [Microsoft Help]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Slow speeds in the evenings [TekSavvy]
· Not strictly "Home" related - but WOW anyways... [Home Repair & Improvement]