UK and Europe · Public discussion

Security Warning

Started by Cliff · · Last activity · 41 posts · 937 views

This thread is locked and is currently read-only.

Thread navigation

Jump through the discussion

Go to the original post, the replies on this page, or the latest preserved contribution.

Thread details

What we know about this thread

Original section
UK and Europe
Published
4 October 2005
Last activity
11 October 2005
Original author
Cliff
Posts
41
Discussion status
Public discussion
Total views
937
Views / 30 days
0

The navigation and discussion metadata provide context. Posts remain in their original chronological order.

Showing posts 1–20 of 41
Posts remain in their original chronological order.

Text size
  1. A word of warning.

    My disguised reply address has been appearing in Spam e-mail address lines
    and this is the only place I use it.

    I suspect it has been collected by Harvester Software.

    Anyone is using there proper address for replies on this newsgroup, I would
    expect you are getting a load of Spam e-mails selling medicines, computer
    software, phoney degrees and male enhancing drugs.

    My advice would be to disguise your address

    Good Luck

    Cliff
    --
    Remove my Bra to reply

  2. in message <[email hidden]>, Cliff

    (') said:

    A word of warning.

    My disguised reply address has been appearing in Spam e-mail address
    lines and this is the only place I use it.

    I suspect it has been collected by Harvester Software.

    Anyone is using there proper address for replies on this newsgroup, I
    would expect you are getting a load of Spam e-mails selling medicines,
    computer software, phoney degrees and male enhancing drugs.

    My advice would be to disguise your address

    Oh, please, no. The 'but they behaved badly first' excuse is no excuse.
    You are /required/ to provide a valid from address for Usenet postings.
    Yes, your address will get harvested by the spammer scum; and, frankly,
    for me, even worse than that they will send you junk, they will send
    junk (and worse) purportedly coming form you. But the answer to the
    incoming UCE problem is a decent filter such as spamassassin. Don't mung
    your email address, that just makes life harder for everyone.

    Seriously, I've been using my real address to post to Usenet for twenty
    years. I use spamassassin. I don't have a problem.

    --
    [email hidden] (Simon Brooke) http://www.jasmine.org.uk/~simon/

    Tony Blair's epitaph, #1: Tony Blair lies here.
    Tony Blair's epitaph, #2: Trust me.

  3. "Simon Brooke" <[email hidden]> wrote in message
    news:[email hidden]...

    Quoted message said:

    in message <[email hidden]>, Cliff

    (') said:

    A word of warning.

    My disguised reply address has been appearing in Spam e-mail address
    lines and this is the only place I use it.

    I suspect it has been collected by Harvester Software.

    Anyone is using there proper address for replies on this newsgroup, I
    would expect you are getting a load of Spam e-mails selling medicines,
    computer software, phoney degrees and male enhancing drugs.

    My advice would be to disguise your address

    Oh, please, no. The 'but they behaved badly first' excuse is no excuse.
    You are /required/ to provide a valid from address for Usenet postings.
    Yes, your address will get harvested by the spammer scum; and, frankly,
    for me, even worse than that they will send you junk, they will send
    junk (and worse) purportedly coming form you. But the answer to the
    incoming UCE problem is a decent filter such as spamassassin. Don't mung
    your email address, that just makes life harder for everyone.

    Seriously, I've been using my real address to post to Usenet for twenty
    years. I use spamassassin. I don't have a problem.

    It may not be fashionable to praise NTL, but they recently started spam
    killing on my mail server. the volume of daily spam has gone from a hundred
    to a handful. It's actually feels quite spooky to check your mail and find
    there's nothing in the last hour.

    --

    Duncan Gray

    The Mountaineering Council of Scotland
    www.mountaineering-scotland.org.uk

  4. "Duncan Gray" <[email hidden]> wrote in message
    news:[email hidden]...

    Quoted message said:

    It may not be fashionable to praise NTL, but they recently started spam
    killing on my mail server. the volume of daily spam has gone from a


    hundred

    Quoted message said:

    to a handful. It's actually feels quite spooky to check your mail and find
    there's nothing in the last hour.

    Likewise BT-Yahoo. I get 2 or 3 spams per week to my inbox and many hundreds
    to my junk mail box.
    Occasionally a bona-fide mail will end up in the spam trap but it's no big
    deal.
    --
    Pete
    http:[email hidden]/P

  5. Simon Brooke said:

    in message <[email hidden]>, Cliff

    (') said:

    A word of warning.

    My disguised reply address has been appearing in Spam e-mail address
    lines and this is the only place I use it.

    I suspect it has been collected by Harvester Software.

    Anyone is using there proper address for replies on this newsgroup, I
    would expect you are getting a load of Spam e-mails selling medicines,
    computer software, phoney degrees and male enhancing drugs.

    My advice would be to disguise your address

    Oh, please, no. The 'but they behaved badly first' excuse is no excuse.
    You are /required/ to provide a valid from address for Usenet postings.
    Yes, your address will get harvested by the spammer scum; and, frankly,
    for me, even worse than that they will send you junk, they will send
    junk (and worse) purportedly coming form you. But the answer to the
    incoming UCE problem is a decent filter such as spamassassin. Don't mung
    your email address, that just makes life harder for everyone.

    Seriously, I've been using my real address to post to Usenet for twenty
    years. I use spamassassin. I don't have a problem.

    I use a totally fictional nom de net, and a totally fictional reply
    address.

    Apart from a tiny trickle of spam from Amazon and a tiny trickle of
    spam from Expedia, both of whom I have used on occasion, my inbox is a
    spam free zone without the need for filters.

    If anyone wants to email me they can ask for my address.

  6. Simon Brooke said:

    in message <[email hidden]>, Cliff
    ([email hidden]'😉 wrote:


    <snipped>

    Quoted message said:


    Seriously, I've been using my real address to post to Usenet for twenty
    years. I use spamassassin. I don't have a problem.


    That's great, but why should you have to download the stuff to pass it
    through spamassassin? Much better to blow the spam away on the mail server
    with a server side delete.

  7. Cliff said:

    Anyone is using there proper address for replies on this newsgroup, I would
    expect you are getting a load of Spam e-mails selling medicines, computer
    software, phoney degrees and male enhancing drugs.

    A few weeks ago, after reading a post by Simon Brooke claiming not to
    have a spam problem despite posting to usenet using a genuine reply
    address, I decided to try an experiment.

    I set up my news account to provide a genuine reply address, one that I
    have never given to anyone for any other reason. According to Google,
    I've posted about 40 messages to 2 groups (urc and rec.sport.unicycling)
    using this address. Surprisingly (to me), the account has so far
    remained spam free.

    --
    Danny Colyer (my reply address is valid but checked infrequently)
    <URL:http://www.colyer.plus.com/danny/>
    "He who dares not offend cannot be honest." - Thomas Paine

  8. Danny Colyer said:

    I set up my news account to provide a genuine reply address, one that I
    have never given to anyone for any other reason. According to Google,
    I've posted about 40 messages to 2 groups (urc and rec.sport.unicycling)
    using this address. Surprisingly (to me), the account has so far
    remained spam free.

    It is mostly, 99% of the time, the From: address that is harvested
    from Usenet (as it tends to be in the XOVER results). The Reply-To:
    address does not, generally, get harvested (as it is not in the XOVER
    results).

    Hence, my From: address gets a 550 whilst the Reply-To: is valid and
    is used by all working software for valid, human generated, replies.

    The later only got onto spam lists due to historic use and a couple of
    misconfigurations when it appeared in the From: header :-( Even so,
    the vast majority of the spam I get is to the From: address - looking
    at all the 550's in the MTA logs is nice ;-)
    --
    ------------------------------------------------------------------
    - Stuart Millington ALL HTML e-mail rejected -
    - [email hidden] http://w3.z-add.co.uk/ -

  9. Simon Brooke said:

    You are /required/ to provide a valid from address for Usenet postings.

    There is /zero/ problem with a From: address that gives 550 when used
    with a working Reply-To: address - as long as the From: address is
    syntactically valid and you have permission to use it.
    --
    ------------------------------------------------------------------
    - Stuart Millington ALL HTML e-mail rejected -
    - [email hidden] http://w3.z-add.co.uk/ -

  10. Bertie Wiggins said:

    I use a totally fictional nom de net, and a totally fictional reply
    address.

    http://www.uk.clara.net/support/aup.php
    "11) The customer must not send email or post articles with headers
    modified in such a way as to disguise the true source of such mail or
    article. It is the customer's responsibilty to ensure that a real
    email address is present and obvious to a human. "

    How likely they are to enforce it is another matter...
    --
    ------------------------------------------------------------------
    - Stuart Millington ALL HTML e-mail rejected -
    - [email hidden] http://w3.z-add.co.uk/ -

  11. Scrumpy Joe said:

    That's great, but why should you have to download the stuff to pass it
    through spamassassin? Much better to blow the spam away on the mail server
    with a server side delete.

    SpamAssassin /is/ server-side ;-) (I run it on my Exim MTA.)
    --
    ------------------------------------------------------------------
    - Stuart Millington ALL HTML e-mail rejected -
    - [email hidden] http://w3.z-add.co.uk/ -

  12. Simon Brooke said:

    in message <[email hidden]>, Cliff

    (') said:

    A word of warning.

    My disguised reply address has been appearing in Spam e-mail address
    lines and this is the only place I use it.

    I suspect it has been collected by Harvester Software.

    Anyone is using there proper address for replies on this newsgroup, I
    would expect you are getting a load of Spam e-mails selling medicines,
    computer software, phoney degrees and male enhancing drugs.

    My advice would be to disguise your address

    Oh, please, no. The 'but they behaved badly first' excuse is no excuse.
    You are /required/ to provide a valid from address for Usenet postings.
    Yes, your address will get harvested by the spammer scum; and, frankly,
    for me, even worse than that they will send you junk, they will send
    junk (and worse) purportedly coming form you. But the answer to the
    incoming UCE problem is a decent filter such as spamassassin. Don't mung
    your email address, that just makes life harder for everyone.

    Seriously, I've been using my real address to post to Usenet for twenty
    years. I use spamassassin. I don't have a problem.

    And you and me and everybody else is paying more so that the ISP's
    can buy enough servers and bandwidth to cope with the spam traffic
    that finally gets dropped only on your very desk.

    You can enjoy your righteous sense of doing the right thing by
    some standard or RFC that's two or more decades out of date if you
    want but personally, I'd prefer not to add to the problem.

  13. Stuart Millington said:
    Scrumpy Joe said:

    That's great, but why should you have to download the stuff to pass it
    through spamassassin? Much better to blow the spam away on the mail
    server with a server side delete.

    SpamAssassin /is/ server-side ;-) (I run it on my Exim MTA.)

    I sit corrected then. I had had a brief play around with it under kmail and
    the setup left me with the impression that it was downloading the emails
    and then tagging them as spam.

  14. Stuart Millington said:

    "11) The customer must not send email or post articles with headers
    modified in such a way as to disguise the true source of such mail or
    article. It is the customer's responsibilty to ensure that a real
    email address is present and obvious to a human. "

    To comply with the TOS I have set up a genuine Yahoo! email address
    which I will not monitor. The address is obvious to a human by
    looking at the reply address.

  15. Scrumpy Joe said:
    Quoted message said:

    SpamAssassin /is/ server-side ;-) (I run it on my Exim MTA.)

    I sit corrected then. I had had a brief play around with it under kmail and
    the setup left me with the impression that it was downloading the emails
    and then tagging them as spam.

    It probably was. It can run at any point in the chain - the
    earlier the better.

    Latest news: you can use Apache to receive mail, and hook spamassassin
    right in to the server. Not that I'd recommend it quite yet for a
    production system - just running locally on a test machine here.

    --
    Nick Kew

  16. On Wed, 05 Oct 2005 19:58:09 +0100,

    Bertie Wiggins said:
    Stuart Millington said:

    "11) The customer must not send email or post articles with headers
    modified in such a way as to disguise the true source of such mail or
    article. It is the customer's responsibilty to ensure that a real
    email address is present and obvious to a human. "

    To comply with the TOS I have set up a genuine Yahoo! email address
    which I will not monitor. The address is obvious to a human by
    looking at the reply address.

    But unfortunately it isn't a real email address.

    --
    Andy Leighton => [email hidden]
    "The Lord is my shepherd, but we still lost the sheep dog trials"
    - Robert Rankin, _They Came And Ate Us_

  17. Bertie Wiggins said:
    Stuart Millington said:

    "11) The customer must not send email or post articles with headers
    modified in such a way as to disguise the true source of such mail or
    article. It is the customer's responsibilty to ensure that a real
    email address is present and obvious to a human. "

    To comply with the TOS I have set up a genuine Yahoo! email address
    which I will not monitor. The address is obvious to a human by
    looking at the reply address.

    <AOL>

    Hotmail in my case. I'm very proud of mine (see header) and even go and
    have a look at what it has caught every 30 days to keep it open.

    </AOL>

    Julesh

  18. Bertie Wiggins said:
    Stuart Millington said:

    "11) The customer must not send email or post articles with headers
    modified in such a way as to disguise the true source of such mail or
    article. It is the customer's responsibilty to ensure that a real
    email address is present and obvious to a human. "

    To comply with the TOS I have set up a genuine Yahoo! email address
    which I will not monitor. The address is obvious to a human by
    looking at the reply address.

    The "please ask" does not, IMO, comply with Clara's AUP. (However,
    this thread does seem to have gone OTT based on some dodgy advice in
    certain articles.)

    Your From: address in particular is bad as it is invalid in precisely
    the wrong way :-(

    If you really want to block the From: address either use an address at
    a domain that you own or something like "[email hidden]".

    The Reply-To: must work, subject to a human's ability to remove the
    "remove this" bits, per Clara's AUP. But, as long as you are not
    forging someone else's domain - or a made up one that you don't have
    specific permission to use - they are unlikely to revoke your account
    unless you send spam, etc.
    --
    ------------------------------------------------------------------
    - Stuart Millington ALL HTML e-mail rejected -
    - [email hidden] http://w3.z-add.co.uk/ -

  19. Scrumpy Joe said:

    Stuart Millington wrote:

    Quoted message said:
    Quoted message said:

    SpamAssassin /is/ server-side ;-) (I run it on my Exim MTA.)

    I sit corrected then. I had had a brief play around with it under kmail and
    the setup left me with the impression that it was downloading the emails
    and then tagging them as spam.

    AIUI there are client-side programmes that use SpamAssasin
    (http://spamassassin.apache.org/), but the original version is/was
    designed for server-side processing. I used [1] it as part of Exim's
    primary accept/reject filtering.

    [1] Used, until the HD died on my MTA recently :-(
    --
    ------------------------------------------------------------------
    - Stuart Millington ALL HTML e-mail rejected -
    - [email hidden] http://w3.z-add.co.uk/ -

  20. On Wed, 05 Oct 2005 19:28:08 +0100, [email hidden]

    Quoted message said:

    And you and me and everybody else is paying more so that the ISP's
    can buy enough servers and bandwidth to cope with the spam traffic
    that finally gets dropped only on your very desk.

    This is going way OTT, but it appears that you are just sending your
    spam to Yahoo and getting them to pay for the bandwidth of e-mail sent
    to, possibly, invalid addresses... That would be hypocritical, unless
    I'm wrong and that address - including the ".cutitout" bit - is valid
    and read by you?
    --
    ------------------------------------------------------------------
    - Stuart Millington ALL HTML e-mail rejected -
    - [email hidden] http://w3.z-add.co.uk/ -

Active in the last 60 minutes

Active in this thread

0 users · 0 guests ·0 bots ·0 total

No signed-in users are active right now.

No known search crawlers active right now.