[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: SPAM on the debian lists...



I've never tried them, but I've attached two posts from my Suncoast LUG list http://www.suncoastlug.org HTH! Mario

X-POP3-Rcpt: mario@alienscience.com
Date: Mon, 14 Jan 2002 22:48:35 -0500 (EST)
From: R P Herrold <herrold@owlriver.com>
To: Slug List <slug@nks.net>
Subject: Re: [SLUG] SPAM blackhole lists?
Sender: slug@lists.nks.net
Reply-To: slug@nks.net

On Mon, 14 Jan 2002, Bill Triplett wrote:

 I was wondering if anyone is using any of those anti-spam relay
 blacklist features[1] to block spam. If so, which one and what kind of
 results are you seeing? Are there alot of false positives?

I use several and am very active with orbz -- I may be reached
through herrold@orbz.org, for example -- one of three working
'real' email addresses in that domain, I believe, as the time
I was afforded that cortesy by the Admin at ORBZ.
That mailing list is quite good -- Russel Nelson (of Cynwer
drivers fame) fought it out there over the weekend.  Hard core
spammers try to convert the RBL'ser there as well.

I offered a extended technical proposal for greatly speeding
RBL filtering with checking on ALL hops, rather than just the
LAST hop, over the weekend as well:

    http://www.orbz.org/list.cgi?mss:1100:200201:mnbjgdfcfolejabghgff

Orbz has ZERO false positives -- ZERO -- for every listing is
backed up with a piece from the ORBZ tester.

As to your question, see:
    http://www.orbz.org/list.cgi?mss:1120:200201:killgealghdpcjljpcgf

which states in part, answering a similar question:

... I run automated processes which harvest and submit to ORBZ
and another testing blocklist the IP of every mailserver which
has had a piece of mail pass through it which is eventually
offered to any of 7 primary, geographically [diverse]
mailserver clusters I admin, handling a couple 100k pieces a
day, in aggregate.

... and submit _every_ IP to orbz.
The more people who use orbz or a competitive RBL, the more
likely the owner of an open relay will have a customeer's mail
bounced.  The more bounces in the hand of end customers, the
less the admin of the open relay can stay in denial.

The only way to stay off the OR blocklists -- is to not run an
open relay.

-----------------snippet ends ----------------------

 If you aren't using one, and there is a specific reason or bad
 experience with them, I'd really like to hear about that.

Between 20% and 40% of my mailload transits through Open
relay's -- and most of that is spam.  Pure and simple.  A
correspondent can clean up their act, find a new ISP, or I'll
do without corresponding with them.  ... but some may consider
my unreasonable.

 We're moving our company mail server from Eudora Internet Mail Server
 (on a Mac) to linux, and I'd like to take advantage of some of the
 features that this move opens up.

My sendmail.mc is somewhat complex, but it is amazingly good. I maintain a tools page at:

   ftp://ftp.owlriver.com at  /pub/local/ORC/rblcheck/

which includes a command line tool   rblcheck  to permit
one-off testing of IP's.

-- Russ Herrold

X-POP3-Rcpt: mario@alienscience.com
Date: Tue, 15 Jan 2002 07:43:15 -0500
From: Bill Triplett <btt@nethouse.com>
To: slug@nks.net
Subject: Re: [SLUG] SPAM blackhole lists?
Sender: slug@lists.nks.net
Reply-To: slug@nks.net

On Mon, Jan 14, 2002 at 10:48:35PM -0500, R P Herrold wrote:
 On Mon, 14 Jan 2002, Bill Triplett wrote:

 > I was wondering if anyone is using any of those anti-spam relay
 > blacklist features[1] to block spam. If so, which one and what kind of
 > results are you seeing? Are there alot of false positives?

 I use several and am very active with orbz -- I may be reached
 through herrold@orbz.org, for example -- one of three working
 'real' email addresses in that domain, I believe, as the time
I was afforded that cortesy by the Admin at ORBZ.

Thanks for the info. Last night before I left I turned on
inputs.orbz.org and hit about 5 spams overnight. One of them notorious
around the office for being particularly offensive.

I think we'll keep it up for a while, maybe add one or two more RBLs
if this works out. There is one that tracks any source of spam,
whether it be an open relay or not:

    http://spamcop.net/bl.shtml

Cheers,
Bill




Being as they are "subsciption only" lists, why do I see SPAM on them?

Bob
--
<>  ><>  ><>  ><>  ><>  ><>  ><>  ><>  ><>  ><>  ><>  ><>  ><>
Bob Van Cleef, Systems Administrator             (408) 734-8100
MicroUnity, Inc.                             FAX (408) 734-8136
376 Martin Ave., Santa Clara, CA 95050  vancleef@microunity.com

---------- Forwarded message ----------
Received: from metis.microunity.com (metis.microunity.com [192.86.7.23])
	by gaea.microunity.com (8.8.8/8.8.8) with ESMTP id MAA05965
	for <vancleef@microunity.com>; Wed, 16 Jan 2002 12:47:58 -0800 (PST)
Received: from murphy.debian.org (murphy.debian.org [216.234.231.6])
	by metis.microunity.com (8.8.8/8.8.8) with SMTP id MAA10676
	for <vancleef@microunity.com>; Wed, 16 Jan 2002 12:47:57 -0800 (PST)
Resent-Date: Wed, 16 Jan 2002 12:47:57 -0800 (PST)
Received: (qmail 19254 invoked by uid 38); 16 Jan 2002 20:37:40 -0000
X-Envelope-Sender: maildeliverysystem@lycos.com
Received: (qmail 18520 invoked from network); 16 Jan 2002 20:37:26 -0000
Received: from smarthost-2.mail.telinco.net (212.1.128.91)
  by murphy.debian.org with SMTP; 16 Jan 2002 20:37:26 -0000
Received: from ppp-3-56.cvx4.telinco.net ([212.1.150.56] helo=lycos.com)
	by smarthost-2.mail.telinco.net with smtp (Exim 3.22 #1)
	id 16QwoA-000Eeh-00; Wed, 16 Jan 2002 20:37:19 +0000
From: "Mobile Fun (4 UK mobiles)" <maildeliverysystem@lycos.com>
To: <debian-perl@lists.debian.org>
Subject: Mobi-Cam - Strip-O-Text - SMS Party Pack: brand new, lot`s of FUN!
Sender: "Mobile Fun (4 UK mobiles)" <maildeliverysystem@lycos.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="ISO-8859-1"
Date: Wed, 16 Jan 2002 20:40:23 -0000
Reply-To: "Mobile Fun (4 UK mobiles)" <maildeliverysystem@excite.com>
Content-Transfer-Encoding: 8bit
Message-Id: <E16QwoA-000Eeh-00@smarthost-2.mail.telinco.net>
Resent-Message-ID: <V9OTmD.A.eqE.SSeR8@murphy>
Resent-From: debian-sparc@lists.debian.org
X-Mailing-List: <debian-sparc@lists.debian.org> archive/latest/8164
X-Loop: debian-sparc@lists.debian.org
Precedence: list
Resent-Sender: debian-sparc-request@lists.debian.org

To find out what on earth is going on follow this link:

http://ukmaildeliverysubsystem.com/viewreturnedmail.html


--
To UNSUBSCRIBE, email to debian-sparc-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org


--
To UNSUBSCRIBE, email to debian-sparc-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org



Reply to: