XPost: news.admin.net-abuse.email
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On Friday, 07 October 2016 16:55 -0000,
in article <
[email protected]>,
Ivan Shmakov <
[email protected]> wrote:
David Ritz <[email protected]> writes:
Ivan Shmakov <[email protected]> wrote:
[Be warned of a few off-topic bits below.]
[ news.admin.net-abuse.email added to cross-post ]
[ alt.spam stripped as group only sees spam, spam, spam and more spam ]
While I understand the evil of sending spam to a high S/N ratio
group, the above seems to suggest there's something wrong with
doing it the other way around. Which is especially strange given
that (a) n.a.n.email's own S/N doesn't seem all that high, and (b)
alt.spam occasionally sees a legitimate message, too (say,
news:[email protected].)
See <news:
[email protected]> (<
http://al.howardknight.net/msgid.cgi?ID=147588564000>).
Per my recollection, that makes two (2) legitimate posts to alt.spam,
within the past four to five years.
(... And also (c) apparently, Aioe blocks crossposts to n.a.n.e;
presumably due to ongoing abuse?)
Paolo has his hands full, in running an open NNTP server, while
attempting to minimize actual net-abuse. Disallowing cross-posts to
certain groups is one option to which he may turn.
[ alt.spam.sightings stripped as bogus (newgrouped by Jamie Baillie) ]
[ <ftp://ftp.isc.org/pub/usenet/control/alt/alt.spam.sightings.gz> ]
FTP is pretty much obsolete. For one thing, requiring two
TCP connections per "session" means trouble passing them through
Tor, NAT, SOCKS, etc. And having three separate transfer modes
(at the least) doesn't help interoperability, either.
That said, the same resource is available via HTTP, too:
http://ftp.isc.org/pub/usenet/control/alt/alt.spam.sightings.gz
Thanks, I've updated lynx_bookmarks.html accordingly.
[ posted and mailed ]
Why?
You're the one posting to (d) a bogus newsgroup
(alt.spam.sightings[*]), which has seen a total of eighty two (82)
posts, since it was created with a bogus cmsg message, from an
habitual network abuser, nearly eight (8) years ago; (e) alt.spam, a
newsgroup in which posters use Usenet as a write only medium, in which
one is lucky to find anything even close to topical more than one a
decade; and (f) comp.mail.misc, which is a group with so little
traffic, I wanted to make sure you at least saw my response. Within
the past year or so, most posts to comp.mail.misc are Italian mission
spam.
To put it short, for about a month, I see a new kind of spam
coming to (strangely) just one of my (many) mailboxes. This one
has DKIM-Signature: (and DomainKey-Signature:) headers in place,
comes from domains with SPF and MX DNS records properly set up,
and, overall, apart from its "unsolicited nature," looks just like
legitimate email. (IPs and MAIL FROM: data shown below.)
Neither SPF nor DKIM say anything about whether mail is unsolicited
and bulk. These are forgery abatement measures. The only things
which might be determined from SPF and DKIM is whether or not mail
originated via a sender allowed host; nothing more, nothing less.
Yes. Still, both somehow get advertised as "counter-spam"
measures.
To the best of my knowledge, both SPF and DKIM counter spam which uses
forged sender information. It has no effect on anything else.
See <
https://wordtothewise.com/?s=SPF>
<
https://wordtothewise.com/?s=DKIM>
<
https://wordtothewise.com/?s=DMARC>
Not that they fail to work that way: my logs have some occurrences
of the SPF check yielding a "negative" result, thus allowing to
reject the incoming message outright. Looks like a must for the
DNS domains not meant to be used for email at all.
That said, being able to confirm that the message indeed comes
from a genuine spam-only domain doesn't seem all that helpful.
That said, being able to confirm that the message comes form IP
addresses which are sending spam, using an unlimited number of domain
names, may be highly useful. That is where DNSbls come into play.
[...]
Of those host I checked, which still resolve, most are listed by the
psbl.org, barracudacentral.org and/or uceprotect.net DNSbls, with a
smattering of SBLCSS (snowshoe) and Spamcop listings. All indicate
the IP addresses you list are spam sources,
ACK, thanks for the pointers.
where SPF and DKIM say that the sending domain is authorized to send
via these spammer controlled, dirty IP addresses.
... For those interested, here's an update for this week.
2016W40 [email protected] [185.58.205.96]
185.58.205.96 sarvtb.ru : psbl.surriel.com : BLOCKED (127.0.0.2)
Listed in PSBL, see
http://psbl.org/listing?ip=185.58.205.96 185.58.205.96 sarvtb.ru : dnsbl-1.uceprotect.net : BLOCKED (127.0.0.2)
IP 185.58.205.96 is UCEPROTECT-Level 1 listed. See
http://www.uceprotect.net/rblcheck.php?ipr=185.58.205.96
[email protected] [194.67.208.8]
194.67.208.8 proteus-spb.ru : psbl.surriel.com : BLOCKED (127.0.0.2)
Listed in PSBL, see
http://psbl.org/listing?ip=194.67.208.8 194.67.208.8 proteus-spb.ru : dnsbl-1.uceprotect.net : BLOCKED
(127.0.0.2)
IP 194.67.208.8 is UCEPROTECT-Level 1 listed. See
http://www.uceprotect.net/rblcheck.php?ipr=194.67.208.8
[email protected] [193.124.176.209]
193.124.176.209 kaminfo.ru : psbl.surriel.com : BLOCKED (127.0.0.2)
Listed in PSBL, see
http://psbl.org/listing?ip=193.124.176.209 193.124.176.209 kaminfo.ru : dnsbl.sorbs.net : BLOCKED (127.0.0.6)
Currently Sending Spam See:
http://www.sorbs.net/lookup.shtml?193.124.176.209
193.124.176.209 kaminfo.ru : dnsbl-1.uceprotect.net : BLOCKED
(127.0.0.2)
IP 193.124.176.209 is UCEPROTECT-Level 1 listed. See
http://www.uceprotect.net/rblcheck.php?ipr=193.124.176.209
[email protected] [185.58.206.163]
185.58.206.163 r-vl.ru : psbl.surriel.com : BLOCKED (127.0.0.2)
Listed in PSBL, see
http://psbl.org/listing?ip=185.58.206.163 185.58.206.163 r-vl.ru : dnsbl-1.uceprotect.net : BLOCKED (127.0.0.2)
IP 185.58.206.163 is UCEPROTECT-Level 1 listed. See
http://www.uceprotect.net/rblcheck.php?ipr=185.58.206.163
[email protected] [193.124.190.134]
193.124.190.134 sab-moskau.ru : psbl.surriel.com : BLOCKED (127.0.0.2)
Listed in PSBL, see
http://psbl.org/listing?ip=193.124.190.134 193.124.190.134 sab-moskau.ru : dnsbl.sorbs.net : BLOCKED (127.0.0.6)
Currently Sending Spam See:
http://www.sorbs.net/lookup.shtml?193.124.190.134
193.124.190.134 sab-moskau.ru : dnsbl-1.uceprotect.net : BLOCKED
(127.0.0.2)
IP 193.124.190.134 is UCEPROTECT-Level 1 listed. See
http://www.uceprotect.net/rblcheck.php?ipr=193.124.190.134
[email protected] [185.58.206.232]
185.58.206.232 taxi-five.ru : zen.spamhaus.org : BLOCKED (127.0.0.3)
https://www.spamhaus.org/sbl/query/SBLCSS
185.58.206.232 taxi-five.ru : dnsbl-1.uceprotect.net : BLOCKED
(127.0.0.2)
IP 185.58.206.232 is UCEPROTECT-Level 1 listed. See
http://www.uceprotect.net/rblcheck.php?ipr=185.58.206.232
[email protected] [185.117.155.168]
185.117.155.168 uralgsm.ru : dnsbl-1.uceprotect.net : BLOCKED
(127.0.0.2)
IP 185.117.155.168 is UCEPROTECT-Level 1 listed. See
http://www.uceprotect.net/rblcheck.php?ipr=185.117.155.168
[email protected] [193.124.181.229]
193.124.181.229 nordmor.ru : zen.spamhaus.org : BLOCKED (127.0.0.3)
https://www.spamhaus.org/sbl/query/SBLCSS
193.124.181.229 nordmor.ru : psbl.surriel.com : BLOCKED (127.0.0.2)
Listed in PSBL, see
http://psbl.org/listing?ip=193.124.181.229 193.124.181.229 nordmor.ru : dnsbl.sorbs.net : BLOCKED (127.0.0.6)
Currently Sending Spam See:
http://www.sorbs.net/lookup.shtml?193.124.181.229
193.124.181.229 nordmor.ru : dnsbl-1.uceprotect.net : BLOCKED
(127.0.0.2)
IP 193.124.181.229 is UCEPROTECT-Level 1 listed. See
http://www.uceprotect.net/rblcheck.php?ipr=193.124.181.229
[email protected] [193.124.184.229]
193.124.184.229 whdent.ru : zen.spamhaus.org : BLOCKED (127.0.0.3)
https://www.spamhaus.org/sbl/query/SBLCSS
193.124.184.229 whdent.ru : psbl.surriel.com : BLOCKED (127.0.0.2)
Listed in PSBL, see
http://psbl.org/listing?ip=193.124.184.229 193.124.184.229 whdent.ru : ix.dnsbl.manitu.net : BLOCKED (127.0.0.2)
Your e-mail service was detected by mail.ixlab.de (NiX Spam) as
spamming at Fri, 07 Oct 2016 23:39:23 +0200. Your admin
should visit
http://www.dnsbl.manitu.net/lookup.php?value=193.124.184.229 193.124.184.229 whdent.ru : dnsbl.sorbs.net : BLOCKED (127.0.0.6)
Currently Sending Spam See:
http://www.sorbs.net/lookup.shtml?193.124.184.229
193.124.184.229 whdent.ru : dnsbl-1.uceprotect.net : BLOCKED
(127.0.0.2)
IP 193.124.184.229 is UCEPROTECT-Level 1 listed. See
http://www.uceprotect.net/rblcheck.php?ipr=193.124.184.229
[email protected] [193.124.184.229]
193.124.184.229 whdent.ru : zen.spamhaus.org : BLOCKED (127.0.0.3)
https://www.spamhaus.org/sbl/query/SBLCSS
193.124.184.229 whdent.ru : psbl.surriel.com : BLOCKED (127.0.0.2)
Listed in PSBL, see
http://psbl.org/listing?ip=193.124.184.229 193.124.184.229 whdent.ru : ix.dnsbl.manitu.net : BLOCKED (127.0.0.2)
Your e-mail service was detected by mail.ixlab.de (NiX Spam) as
spamming at Fri, 07 Oct 2016 23:39:23 +0200. Your admin
should visit
http://www.dnsbl.manitu.net/lookup.php?value=193.124.184.229 193.124.184.229 whdent.ru : dnsbl.sorbs.net : BLOCKED (127.0.0.6)
Currently Sending Spam See:
http://www.sorbs.net/lookup.shtml?193.124.184.229
193.124.184.229 whdent.ru : dnsbl-1.uceprotect.net : BLOCKED
(127.0.0.2)
IP 193.124.184.229 is UCEPROTECT-Level 1 listed. See
http://www.uceprotect.net/rblcheck.php?ipr=193.124.184.229
[email protected] [185.87.49.127]
185.87.49.127 02info.ru : zen.spamhaus.org : BLOCKED (127.0.0.3)
https://www.spamhaus.org/sbl/query/SBLCSS
185.87.49.127 02info.ru : bl.spamcop.net : BLOCKED (127.0.0.2)
Blocked - see
http://www.spamcop.net/bl.shtml?185.87.49.127
185.87.49.127 02info.ru : psbl.surriel.com : BLOCKED (127.0.0.2)
Listed in PSBL, see
http://psbl.org/listing?ip=185.87.49.127
185.87.49.127 02info.ru : ix.dnsbl.manitu.net : BLOCKED (127.0.0.2)
Your e-mail service was detected by test.port25.me (NiX Spam) as
spamming at Fri, 07 Oct 2016 20:25:53 +0200. Your admin
should visit
http://www.dnsbl.manitu.net/lookup.php?value=185.87.49.127 185.87.49.127 02info.ru : dnsbl.sorbs.net : BLOCKED (127.0.0.6)
Currently Sending Spam See:
http://www.sorbs.net/lookup.shtml?185.87.49.127
185.87.49.127 02info.ru : dnsbl-1.uceprotect.net : BLOCKED (127.0.0.2)
IP 185.87.49.127 is UCEPROTECT-Level 1 listed. See
http://www.uceprotect.net/rblcheck.php?ipr=185.87.49.127
[email protected] [193.124.183.150]
193.124.183.150 agcher.ru : zen.spamhaus.org : BLOCKED (127.0.0.3)
https://www.spamhaus.org/sbl/query/SBLCSS
193.124.183.150 agcher.ru : psbl.surriel.com : BLOCKED (127.0.0.2)
Listed in PSBL, see
http://psbl.org/listing?ip=193.124.183.150 193.124.183.150 agcher.ru : dnsbl.sorbs.net : BLOCKED (127.0.0.6)
Currently Sending Spam See:
http://www.sorbs.net/lookup.shtml?193.124.183.150
193.124.183.150 agcher.ru : dnsbl-1.uceprotect.net : BLOCKED (127.0.0.2)
IP 193.124.183.150 is UCEPROTECT-Level 1 listed. See
http://www.uceprotect.net/rblcheck.php?ipr=193.124.183.150
[email protected] [193.124.181.9]
193.124.181.9 fanabe.ru : zen.spamhaus.org : BLOCKED (127.0.0.3)
https://www.spamhaus.org/sbl/query/SBLCSS
193.124.181.9 fanabe.ru : bl.spamcop.net : BLOCKED (127.0.0.2)
Blocked - see
http://www.spamcop.net/bl.shtml?193.124.181.9
193.124.181.9 fanabe.ru : psbl.surriel.com : BLOCKED (127.0.0.2)
Listed in PSBL, see
http://psbl.org/listing?ip=193.124.181.9
193.124.181.9 fanabe.ru : dnsbl.sorbs.net : BLOCKED (127.0.0.6)
Currently Sending Spam See:
http://www.sorbs.net/lookup.shtml?193.124.181.9
193.124.181.9 fanabe.ru : dnsbl-1.uceprotect.net : BLOCKED (127.0.0.2)
IP 193.124.181.9 is UCEPROTECT-Level 1 listed. See
http://www.uceprotect.net/rblcheck.php?ipr=193.124.181.9
FWIW, I hope that whatever software they use to distribute spam
is /not/ parallelized. That way, the failure of my MTA to
produce any TCP response whatsoever (thanks to the plain -j DROP
in the iptables' INPUT chain) would result in at least some 30 s
delay (that is: their TCP connection timeout) before the next
address in the list is tried.
HTH.
[*] alt.spam.sighting is not on the active lists of four out of the
six NNTP service to which I subscribe, suggesting that it appears only
on servers running largely on autopilot.
- --
David Ritz <
[email protected]>
Be kind to animals; kiss a shark.
-----BEGIN PGP SIGNATURE-----
iEYEARECAAYFAlf4S+oACgkQUrwpmRoS3uu9MwCgtw6pEYgdgQLRnsQ2TtRhIawJ a6MAmwbFVCqdzzCNrFIeok/W2MWyOBqa
=nzKg
-----END PGP SIGNATURE-----
--- SoupGate-Win32 v1.05
* Origin: fsxNet Usenet Gateway (21:1/5)