dnssec / dane

2014-08-14 Thread Robert Schetterer
Question: Would it make sense to have rules based on dnssec / dane records exist for a maildomain ? Best Regards MfG Robert Schetterer -- [*] sys4 AG http://sys4.de, +49 (89) 30 90 46 64 Franziskanerstraße 15, 81669 München Sitz der Gesellschaft: München, Amtsgericht München: HRB 199263 Vorsta

Re: Opinions needed on what to consider spam

2014-08-14 Thread hamann . w
>> >> All of this doesn't translate to the end-user, though. There's no way I >> could ever set up a set of rules, in the form of an end-user doc, that >> could be used to describe when to unsubscribe and when not to, and under >> what conditions an email can be trusted and when it shouldn't (beyo

Re: Hotfix/phishing spam

2014-08-14 Thread David B Funk
On Thu, 14 Aug 2014, John Hardin wrote: On Thu, 14 Aug 2014, Alex wrote: Microsoft outsourcing their tech-support that badly? I don't think so. Right, that was my point. The sender is not one of my trusted users, yet the link in the body seems legit. So what's the point of this spam? Just a

Re: Hotfix/phishing spam

2014-08-14 Thread Alex
Hi, Microsoft outsourcing their tech-support that badly? I don't think so. >>> >> >> Right, that was my point. The sender is not one of my trusted users, yet >> the link in the body seems legit. >> >> So what's the point of this spam? Just a misconfigured machine somehow? >> > > That's a really g

Re: Hotfix/phishing spam

2014-08-14 Thread John Hardin
On Thu, 14 Aug 2014, Alex wrote: Hi, But when they do I doubt that they do it via Yahoo from somebody in Bangladesh. Looking at the headers in that pastbin example, the originating IP is 114.31.4.36 which looks like it's from a cyber-cafe in Bangladesh. Microsoft outsourcing their tech-supp

Re: Hotfix/phishing spam

2014-08-14 Thread Alex
Hi, > But when they do I doubt that they do it via Yahoo from somebody in Bangladesh. > Looking at the headers in that pastbin example, the originating IP is > 114.31.4.36 which looks like it's from a cyber-cafe in Bangladesh. > > Microsoft outsourcing their tech-support that badly? I don't think

RE: Hotfix/phishing spam

2014-08-14 Thread David B Funk
But when they do I doubt that they do it via Yahoo from somebody in Bangladesh. Looking at the headers in that pastbin example, the originating IP is 114.31.4.36 which looks like it's from a cyber-cafe in Bangladesh. Microsoft outsourcing their tech-support that badly? I don't think so. On Thu,

AXB_X_FF_SEZ_S not fired

2014-08-14 Thread Alex
Hi, AXB_X_FF_SEZ_S is a rule that fires when the X-Forefront-Antispam-Report header is found. I have a sample which has this header, yet the rule doesn't fire, and wondered if someone could help me figure out why: http://pastebin.com/vRQXxgJH I'm using spamassassin-3.4, and I tested it on anothe

Re: Opinions needed on what to consider spam

2014-08-14 Thread Alex
Hi, >> For the Nigerian 419 spam, the last thing you want to do is reply to it :) > > unsubscribe doesn't mean "reply" > > where I sit, if you can't unsubscribe with ONE click, they get the hard block All of this doesn't translate to the end-user, though. There's no way I could ever set up a set

RE: Hotfix/phishing spam

2014-08-14 Thread John Traweek CCNA, Sec+
Usually an end user has to request the hotfix and fill out a form on the MS site and then MS will send out an email with the URI. So to answer your question, yes, MS does send out emails with hotfixes, but only when an end user requests it, at least in my experience… If the end user did not

Re: Dealing with suspicious unicode in domains

2014-08-14 Thread Mark Martinec
Alex writes: Just came across this article about measures Google is taking to block domains using suspicious unicode characters: http://threatpost.com/google-tweaks-gmail-to-help-limit-spam/107732 Does SA yet have similar measures? I seem to recall some discussion about this probably a year a

Hotfix/phishing spam

2014-08-14 Thread Alex
Hi, We had users reporting receiving an email that appears to be from Microsoft regarding a hotfix, but it appears to actually contain Microsoft hotfix info with a URI to download an executable. The executable is a zip that contains a MSU (Windows6.1-KB977307-x64.msu). Does MS send such email? ht

Dealing with suspicious unicode in domains

2014-08-14 Thread Alex
Hi guys, Just came across this article about measures Google is taking to block domains using suspicious unicode characters: http://threatpost.com/google-tweaks-gmail-to-help-limit-spam/107732 Does SA yet have similar measures? I seem to recall some discussion about this probably a year ago. Wha

Re: Opinions needed on what to consider spam

2014-08-14 Thread Matus UHLAR - fantomas
On 2014-08-13 07:14, Matus UHLAR - fantomas wrote: call an unsubscribe-hook _and_ train as spam. Should be viable for both solicided an unsolicited mail. Or, does anyone think that unsubscribing spam is counter-productive still? On 13.08.14 11:06, Dave Warren wrote: In short, yes, it is unpro