Re: .co.at

2014-11-22 Thread Reindl Harald
Am 23.11.2014 um 03:22 schrieb Igor Chudov: I have a special perl script, that I wrote, that scans emails, makes a WHOIS query via a perl WHOIS module, and looks at the creation date. It then flags all messages that are emailed from domains less than a week old. The reason for this is that spam

Re: Facebook subdomain spamming started today

2014-11-22 Thread Reindl Harald
Am 22.11.2014 um 23:49 schrieb Benny Pedersen: No more info in public from me so why make noise at all by saying nothing? signature.asc Description: OpenPGP digital signature

Re: Emails with extremely long URLs

2014-11-22 Thread John Hardin
On Sat, 22 Nov 2014, Igor Chudov wrote: I receive spam emails that contain extremely long URLs, about 2,400 characters. I wanted to know if spamassassin has a rule that I can turn on to flag such URLs. I do not think that I ever receive legitimate emails with URLs that long. I don't think ther

Emails with extremely long URLs

2014-11-22 Thread Igor Chudov
I receive spam emails that contain extremely long URLs, about 2,400 characters. I wanted to know if spamassassin has a rule that I can turn on to flag such URLs. I do not think that I ever receive legitimate emails with URLs that long. i

Re: .co.at

2014-11-22 Thread Igor Chudov
I have a special perl script, that I wrote, that scans emails, makes a WHOIS query via a perl WHOIS module, and looks at the creation date. It then flags all messages that are emailed from domains less than a week old. The reason for this is that spammers register throwaway domains, spam from the

Facebook subdomain spamming started today

2014-11-22 Thread Benny Pedersen
No more info in public from me

Re: Honeypot email addresses

2014-11-22 Thread Dave Funk
Another way to seed spamtrap addresses is to make up some and then feed them into "unsubscribe" links in spam sent to regular users. I've got some of those I started that way 15 years ago and they're still going strong. On Sat, 22 Nov 2014, Ted Mittelstaedt wrote: That's a lot of work, there's

Re: Honeypot email addresses

2014-11-22 Thread Ted Mittelstaedt
That's a lot of work, there's a much easier way Just search your /var/log/maillog for user unknown messages, and create email addresses for the unknown users which are showing up multiple times over multiple days. It's a great trick because it gets spammers who already have email addresses in t

IPv6 mail (was Re: Honeypot email addresses)

2014-11-22 Thread David F. Skoll
On Sat, 22 Nov 2014 13:15:29 +0100 Aban Dokht wrote: > We also have honeypots with enabled IPv6 MX, but SPAM over IPv6 is > very, very seldom. We keep reputation reports from a large number of mailboxes and they break down roughly as follows: IPv4 mail: about 475 million reports of which 166 mi

Re: Honeypot email addresses

2014-11-22 Thread Aban Dokht
On 21.11.2014 18:17, Matthias Leisi wrote: We are about to simplify the reporting we previously had, and want to push this especially to detect spam coming in over IPv6. We also have honeypots with enabled IPv6 MX, but SPAM over IPv6 is very, very seldom. But pushing IPv6 anti spam is a good