[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Massive increase of spam on debian-*@l.d.o



on Wed, May 05, 2004 at 09:51:44AM +0000, Adam Funk (a24061@yahoo.com) wrote:
> On Wednesday 05 May 2004 09:20, Paul Johnson wrote:
> 
> > William Ballard <40414.nospam@comcast.net> writes:
> > 
> >> What steps are being taken to mitigate the significant increase in
> >> spam getting through to the lists?
> > 
> > I'm reporting the spam.  What are you doing to help, or are you
> > content to only bitch instead of take action?
> 
> What reporting system do you use?  (I use SpamCop.)
> Do you think it really makes a difference?  (I don't know)

I wrote my own.

It's fairly simple minded.  You can shoot yourself in the foot.  It
needs to be configured to your site.  SPECIFIC MAILING LIST DOMAINS MUST
BE ADDED TO PREVENT ANNOYING LIST ADMINS.  There are known bugs.  It
should probably be rewritten in a Real Programming Language (or at least
a Real Scripting Language).  It's currently bash with some other stuff
thrown in.

It reports spam to the usual suspects.  Starting with postmaster/abuse
addresses, if known.  Then IP / domain WHOIS contacts, abuse.net
contacts, and the like.  You can create a list of undeliverable contacts
not to try (I post same to news.admin.net-abuse.email, aka NANAE).  It
posts a notice with information on the offending IP to
news.admin.net-abuse.sightings, which may be of use to various parties.

    http://linuxmafia.com/~karsten/Download/SpamTools.tar.gz

...there are a few other goodies thrown in there which help in
researching spam as well.

Aside for the LARTing capabilities, I use it to gather stats on where
spam is originating, which I find to be somewhat interesting.


It beats manual reporting, and that was the design intent.  Run it on a
mailbox (Maildir format) of known spam.  Takes about 20-40 seconds to
generate and send a LART (mostly in DNS/remote lookups).

John Draper (aka Captain Crunch of phreaker fame) is working on a system
which kicks out several LARTs a second, though his system isn't publicly
available.  Discussed on NANAE as well recently.


Peace.

-- 
Karsten M. Self <kmself@ix.netcom.com>        http://kmself.home.netcom.com/
 What Part of "Gestalt" don't you understand?
    I've been waiting for the right woman to get confused.
    - On not being married.

Attachment: signature.asc
Description: Digital signature


Reply to: