i360 Support wrote:
Attached is the filter that I use to kill this stuff. Last I checked, there were two different spammers that were cracking AUTH to get this stuff through, and their patterns don't seem to have changed, although they probably will and/or more will come. Matt -- ===================================================== MailPure custom filters for Declude JunkMail Pro. http://www.mailpure.com/software/ ===================================================== |
# HACKEDEARTHLINK v1.1.0 REVDNS END NOTCONTAINS .earthlink.net MAILFROM END CONTAINS earthlink MAILFROM END CONTAINS mindspring REMOTEIP 2 CONTAINS . SUBJECT 10 CONTAINS =?windows-1251?b? HEADERS 15 CONTAINS User-Agent: aol TESTSFAILED 2 CONTAINS SNIFFER- TESTSFAILED 1 CONTAINS FOREIGN TESTSFAILED 1 CONTAINS BADHEADERS TESTSFAILED 2 CONTAINS (ALL) TESTSFAILED -2 CONTAINS (LAST) TESTSFAILED 2 CONTAINS SPAMCOP(ALL) TESTSFAILED 2 CONTAINS XBL(ALL) TESTSFAILED 1 CONTAINS DSBL(ALL)
