Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » What's Behind the Penny Stock Spam Surge » Uhm..
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
Users are the problem »
« Vontage?  
AuthorAll Replies


sporkme
drop the crantini and move it, sister
Premium,MVM
join:2000-07-01
Morristown, NJ
·Optimum Online

reply to nixen
Re: Uhm..

said by nixen See Profile :

They post a message that's about 80% "real" text, and then the stock pump is a single JPEG or GIF image in the message. So, most of the Bayesian filters just give it a pass. If it weren't for all of the MS mail users, I'd simply reject HTML email altogether.
SpamAssassin is getting pretty good at catching the quirks that seperate these messages from real mail.

One thing that really helps is automating "sa-update" to grab the latest rules from the SpamAss folks. I didn't even no about that until a few weeks ago - previously they released new rules with each version of spamass, but now the rules are continuously updated.

I would imagine if you greylist and use spamass, you don't see too much of this crap.

I wonder how long it will be until they have botnet clients that are compliant enough to make their way through greylisting (ie: include a queue)? I mean if they can generate a unique image for each email, queueing sounds pretty darn simple in comparison.


nixen
Rockin' the Boxen
Premium
join:2002-10-04
Alexandria, VA
·Cox HSI
·Speakeasy

said by sporkme See Profile :

SpamAssassin is getting pretty good at catching the quirks that seperate these messages from real mail.

One thing that really helps is automating "sa-update" to grab the latest rules from the SpamAss folks. I didn't even no about that until a few weeks ago - previously they released new rules with each version of spamass, but now the rules are continuously updated.
Hmm... perhaps it would be helpful if I read the Release Notes to see these new tools? Just ran it in debug mode. Nifty tool. I got it croned now.

said by sporkme See Profile :

I would imagine if you greylist and use spamass, you don't see too much of this crap.
Yeah, I use a greylist daemon. However, the bot-nets are getting a bit more sophisticated. They aren't just attempting single delivery any more.

-tom
--
"Experience should teach us to be most on our guard to protect liberty when the government's purposes are beneficial. The greatest dangers to liberty lurk in insidious encroachment by men of zeal, well meaning but without understanding." -Louis D Brandeis
Forums » What's Behind the Penny Stock Spam SurgeUsers are the problem »
« Vontage?  


Thursday, 03-Dec 00:53:03 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [162] Comcast Releasing Promised Usage Meter
· [95] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [79] Latest Consumer Reports Survey Not Kind To AT&T
· [70] Baltimore To Ban Lazy Cable Installs
· [62] Broadband Killed The Game Console
· [55] Rogers Unveils The ISP Dream Model
· [46] ACTA: Global Three Strikes
· [44] Avast Antivirus Has Gone Mad
· [41] Rural Carriers Quickly Embracing Fiber
· [39] AT&T, Verizon Drop 3G Ad Dispute
Most people now reading
· False positive in Avast! or is it real? [Security]
· ToC 4th boss - Preliminary Strategy for Twin Valkyr [World of Warcraft]
· Poll: Have you ever been charged an overage fee since ... [TekSavvy]
· Grammar Question [General Questions]
· Windows 7 boot manager editing questions [Microsoft Help]
· Options if ACTA is ratified [TekSavvy]
· [Config] cisco asa 5505 with multiple outside IP addresses [Cisco]
· Maximizing Rogue DPS for 3.1 [World of Warcraft]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Error registering Magnet link handler [Need Site Help?]