republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Spam, Scam and Phishbusters » [Spam] Spam, Spam, SPAM!!!
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
[Scam] DROA (Domain Registry of America) »
« Weirdest email to date  
AuthorAll Replies

nevada777

join:2006-01-18
Port Orange, FL

reply to MikelD
Re: [Spam] Spam, Spam, SPAM!!!

Try out this service and simply forward your existing account to the address that you sign up for. I believe that you will find that this cures your problem with junk mail.

»www.cfl.mail-block.com (sign up for the home addition, they have a 30 day trial period)


Angra Mainyu

join:2004-02-13
Spain

nevada777, I have give a look to the Mail-Block service and I have find this statement in their "why it works" page:
quote:
...
2. Mail-Block requires the bulk mailer to verify the e-mail they originally sent you. Highly unlikely!
...
Not good!
As I have said in my previous message to MikelD, most of "From" headers in the spam messages are forged, so, with these "verifications", Mail-Block only will annoy other third people that have none to do with the spam sent (in fact, Mail-Block seems to know that, as they acknowledge that the reply to the "verifications" they sent are "highly unlikely"). You would not be happy at all if the spammer sent 1000000 of their junk with your email address in the "From" header and you start to receive thousands of bounces or these "verifications", from angry clueless people that think that YOU sent the spam, or from Challenge-Response systems (like Mail-Block) that want you to "verify" the spam sent!

The Challenge-Response systems are not so different of the MW "bounces" and only make worse the spam problem. My advice is to stay away from these systems.

nevada777

join:2006-01-18
Port Orange, FL

I have a different perspective on this service and I think for a very good reason. Taking a brief look at a company's website and then believing that this provides you with all the knowlege to make a judgement on the workings of their system seems somewhat flawed.

I on the other hand I have used this system for past 2 years. Never once have I heard or read of a "legitimate" complaint of them sending out "bounced spam" as is suggested.

Bottom Line is that it works for me. Don't really know how or why and really could care less...It Just Works. If someone want to try out this service then check my previous posting linking to this site.


Angra Mainyu

join:2004-02-13
Spain


1 edit
Well, I can be wrong with regard to Mail-Block, but their statements in their web page certainly do intend to provide knowledge -to the future user- about the workings of their system (hey, they call it "Why it Works", not me! ), and I have based my judgement in these statements.

I'm not saying that it don't works for you or others, but that their procedure seems to be based in -or around- a Challenge-Response system. The C/R systems can be of use to some people... at the cost of annoy many more that have had the bad luck of have their emails used as "Froms" by the spammers (this month -and it is being "quiet"- I have received more than 1900 bounces, verifications, and the like).

Well, your mileage may vary and I don't intend to be argumentative about this. I'm sure that in other threads have been discussed the virtues and faults of C/R systems.

NormanS
Premium,MVM
join:2001-02-14
San Jose, CA
·Pacific Bell - SBC

reply to nevada777
said by nevada777 See Profile :

Try out this service and simply forward your existing account to the address that you sign up for. I believe that you will find that this cures your problem with junk mail.
I have been on the receiving end of challenges:
X-Apparently-To: %User_ID%@yahoo.com via 66.218.79.23; 02 Jun 2003 21:20:12 -0700 (PDT)
X-YahooFilteredBulk: 66.227.18.1
Return-Path: <%User_ID%@tannerlaine.com>
Received: from 66.227.18.1 (EHLO texas.businessx.com) (66.227.18.1)
by mta171.mail.scd.yahoo.com with SMTP; 02 Jun 2003 21:20:11 -0700 (PDT)
Received: from 12-230-111-55.client.attbi.com ([12.230.111.55] helo=localhost.com)
by texas.businessx.com with smtp (Exim 3.36 #1)
id 19N3HM-0006JN-00
for %User_ID%@yahoo.com; Mon, 02 Jun 2003 23:20:08 -0500
Subject: Re: Hello!!
to: %User_ID%@yahoo.com
From: %User_ID%@tannerlaine.com
Reply-To: challengereply@mailfrontier.com
X-Mlf-Communication-Key: aibo-eigj-aaab-hobc-akfm-ambk;disposition=internal
Precedence: bulk
Mime-Version: 1.0
Content-Type: multipart/related; boundary="__1054614012.1021.MlfMimeMail__"
Message-Id: <E19N3HM-0006JN-00@texas.businessx.com>
Date: Mon, 02 Jun 2003 23:20:08 -0500
X-PMFLAGS: 570966016 0 1 1F97AC70.CNM

--__1054614012.1021.MlfMimeMail__
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="__1054614012.1020.MlfMimeMail__"

--__1054614012.1020.MlfMimeMail__
Content-Type: text/plain
Mime-Version: 1.0

Thank you for sending me your email with the subject "Hello!!". I really want to receive your email.

In an effort to eliminate junk email, I am using MailFrontier Matador.
Matador has placed your message on hold.

Please click the link below so you will be added to my Allowed people list,
I will receive your email, and we will be able to communicate freely going forward.

<http://c.mailfrontier.net/c/3eae7dd5ad/ed%40tannerlaine.com>

If you can not click on the link above, copy and paste the URL above directly into your browser.

---------------------------------------------------
This mailbox protected from junk email by Matador
from MailFrontier, Inc. http://www.mailfrontier.com

--__1054614012.1020.MlfMimeMail__
Content-Type: text/html
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0

{Redacted.}
This one has long be blocked locally. Earthlink challenges are also blocked. I will check, but I am pretty sure that I have MailBlock blocked.

In the challenge I have posted, that "@yahoo.com" email address is mine; I still use it. However, I never sent any email to that "tannerlaine.com" domain. What happened was that some spammer forged my "@yahoo.com" email address in his spam run, thus:
Received: from punt-1.mail.demon.net by mailstore for %User_ID%@mbsltd.demon.co.uk
id 1055370193:10:14605:122; Wed, 11 Jun 2003 22:23:13 GMT
Received: from [6532140hfc90.tampabay.rr.com] ([65.32.140.90])
by punt-1.mail.demon.net id aa1123730; 11 Jun 2003 22:22 GMT
Message-ID: <1c8c191f78f1$4e0d21bc$5b027e3e@vqtbncsuo.ronm>
From: <%User_ID%@yahoo.com>
To: Webmaster
Subject: Hello !
Date: Thu, 12 Jun 2003 06:54:20 -0600
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_69A_4226_758CB491.6169A072"
X-Priority: 3
X-MimeOLE: Produced By Microsoft MimeOLE V8.0 for Windows US sub 230
X-MSMail-Priority: Normal
X-Mailer: AOL 8.0 for Windows US sub 230
I have never, in my entire life, been either a Road Runner customer, or lived in Florida (though I was, briefly, stationed at Ft. Gordon, Georgia for MP training).

So how would I, a California resident on (at that time) SBC Yahoo! DSL Service, be responsible for sending email from a Florida Road Runner account? Well, in theory, I could have use an open proxy; but I sure as hell would not have used my own email address in the Return-Path:!

My current policy for handling challenges is to:

Not respond, if it was sent back as the result of email I have sent, and report it through SpamCop as abuse.

Respond, if it was sent as the result of a forged Return-Path email address, and report it through SpamCop as abuse.

Those using C/R to filter my email will have to find another way to hear from me, if they think correspondence with me is that important. I don't think it is so important that I want to jump through their hoops.

Those using C/R to filter spammer email will just have to put up with spam in their Inbox, should they annoy me with their stupid challenge.

Either way, C/R is abuse; and, hopefully, SpamCop will get enough complaints to add MailBlock servers to their SCBL.

The same goes for MailWasher bounces:
X-Apparently-To: %User_ID%@yahoo.com via 66.218.79.27; 11 Jun 2003 22:31:25 -0700 (PDT)
X-YahooFilteredBulk: 216.77.233.62
Return-Path: <>
Received: from 216.77.233.62 (HELO bellsouth.net) (216.77.233.62)
by mta124.mail.scd.yahoo.com with SMTP; 11 Jun 2003 22:31:24 -0700 (PDT)
Date: Thu, 12 Jun 2003 01:34:10 -0500
From: Mail Delivery Subsystem <MAILER-DAEMON@bellsouth.net>
Message-Id: <200306120134.LUK8157@mx1.bellsouth.net>
To: <%User_ID%@yahoo.com>
MIME-Version: 1.0
Content-Type: multipart/report; report-type=delivery-status;
boundary="LUK8157.1055376000/mx1.bellsouth.net"
Subject: Returned mail: User unknown
Auto-Submitted: auto-generated (failure)

This is a MIME-encapsulated message

--LUK8157.1055376000/mx1.bellsouth.net

The original message was received at Thu, 12 Jun 2003 01:34:10 -0500
from ilovejesus.com

----- The following addresses had permanent fatal errors -----
<%User_ID%@bellsouth.net>
(expanded from: <%User_ID%@bellsouth.net>)

----- Transcript of session follows -----
mail.local: unknown name: jlads
550 <%User_ID%@bellsouth.net>... User unknown
Since when does <MAILER-DAEMON@bellsouth.net> come from a residential DSL connection? Should be from a Bellsouth SMTP server. This is a blatant violation of the Bellsouth TOS, as well as most other ISPs: Impersonating an official of the ISP. Why was I bothered with this notice? Some idiot Bellsouth customer used their MailWasher application to forge bounce this spam:
Return-Path: <%User_ID%@yahoo.com>
Received: from ilovejesus.com ([140.239.119.97]) by imf35bis.bellsouth.net
(InterMail vM.5.01.04.25 201-253-122-122-125-20020815) with ESMTP
id <20030612000232.VGJF18695.imf35bis.bellsouth.net@ilovejesus.com>
for <%User_ID%@bellsouth.net>; Wed, 11 Jun 2003 20:02:32 -0400
Received: from yahoo.com (na-200-38-238-114.na.avantel.net.mx [200.38.238.114] (may be forged))
by ilovejesus.com (8.12.8/8.12.8) with SMTP id h5BNxUJT014641;
Wed, 11 Jun 2003 19:59:31 -0400 (EDT)
Message-ID: <80e7fba9f3d2$47f7e478$01f9ee5d@mywhwsfxcxdg.deck>
From: <%User_ID%@yahoo.com>
To: AOL.Users@ilovejesus.com
Subject: Hello!!
Date: Wed, 11 Jun 2003 18:46:48 +0800
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_116_FF5F_90036E50.97E94994"
X-Priority: 3
User-Agent: Microsoft Outlook Express 5.50.4133.2400
------=_NextPart_116_FF5F_90036E50.97E94994
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
I have never been a customer of "ilovejesus", nor used their mail service. So why should I receive a Delivery Failure Notice about email I have never sent?

I received so many DFNs on the first day of the forgery that my Yahoo! Mail account was threatened with becoming useless; I was on the edge of bouncing email that I wanted because my mailbox was too full. I had to set filters to delete DFNs as fast as they came in. For a month and a half, that Yahoo! Mail account was nearly useless because of misguided idiots bouncing email to me which I never sent.

Do not use a C/R system to filter your spam.
Do not use the "bounce" feature of MailWasher, or any similar application.

Do not think that the Return-Path email address correctly identifies the spammer; it does not.

--
Norman
~Oh Lord, why have you come
~To Konnyu, with the Lion and the Drum
Forums » Up and Running » Security » Spam, Scam and Phishbusters[Scam] DROA (Domain Registry of America) »
« Weirdest email to date  


Wednesday, 25-Nov 11:36:44 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [104] New AT&T Ad Campaign Hits Back At Verizon
· [89] Apple Joins AT&T Verizon Snark Fest
· [85] New Bill Takes Aim At Higher Verizon ETFs
· [41] In-Flight Internet Headed For Bumpy Landing?
· [32] Senators Want ACTA Made Public
· [32] TiVo Sees Record Customer Losses
· [30] Earthlink Suffers From Major E-mail Outage
· [30] AT&T Offers New Prepaid Wireless plans
· [28] Frontier Increases Modem Rental Fee
· [24] Despite Billions In USF Fees, U.S. Libraries Lack Bandwidth
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· Mysterious $800 Cash Deposit? [General Questions]
· Climate Change Scandal Erupts After Email Hack. [Security]
· How do people get virut infection [Security]
· IPComms Free DIDs now with sip registration maybe?? [VOIP Tech Chat]
· [Rant] Damn Sermons through my speakers! [Rants, Raves, and Praise]
· christmas music already, Christ! [Rants, Raves, and Praise]
· RG Firmware update to VDSL2 this morning [AT&T U-verse]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]