UK and Europe · Public discussion

Security Warning

Started by Cliff · · Last activity · 41 posts · 937 views

This thread is locked and is currently read-only.

Thread navigation

Jump through the discussion

Go to the original post, the replies on this page, or the latest preserved contribution.

Thread details

What we know about this thread

Original section
UK and Europe
Published
4 October 2005
Last activity
11 October 2005
Original author
Cliff
Posts
41
Discussion status
Public discussion
Total views
937
Views / 30 days
0

The navigation and discussion metadata provide context. Posts remain in their original chronological order.

Showing posts 21–40 of 41
Posts remain in their original chronological order.

Text size
  1. On 05 Oct 2005 19:50:29 GMT, Andy Leighton <[email hidden]>

    Quoted message said:
    Quoted message said:
    Quoted message said:

    "11) The customer must not send email or post articles with headers
    modified in such a way as to disguise the true source of such mail or
    article. It is the customer's responsibilty to ensure that a real
    email address is present and obvious to a human. "

    To comply with the TOS I have set up a genuine Yahoo! email address
    which I will not monitor. The address is obvious to a human by
    looking at the reply address.

    But unfortunately it isn't a real email address.

    It depends how you interpret the ToS. The real address is obvious to
    a human. If the AUP team contact me and ask me to amend I will. The
    fact that they use the clause *obvious to a human* suggests that
    munged addresses are acceptable, otherwise the clause would have been
    omitted..

  2. Nick Kew said:

    Latest news: you can use Apache to receive mail, and hook spamassassin
    right in to the server. Not that I'd recommend it quite yet for a
    production system - just running locally on a test machine here.

    1.3 or 2.0 only?
    --
    ------------------------------------------------------------------
    - Stuart Millington ALL HTML e-mail rejected -
    - [email hidden] http://w3.z-add.co.uk/ -

  3. On Wed, 05 Oct 2005 21:18:59 +0100,

    Bertie Wiggins said:

    On 05 Oct 2005 19:50:29 GMT, Andy Leighton <[email hidden]>

    Quoted message said:
    Quoted message said:

    >"11) The customer must not send email or post articles with headers
    >modified in such a way as to disguise the true source of such mail or
    >article. It is the customer's responsibilty to ensure that a real
    >email address is present and obvious to a human. "

    To comply with the TOS I have set up a genuine Yahoo! email address
    which I will not monitor. The address is obvious to a human by
    looking at the reply address.

    But unfortunately it isn't a real email address.

    It depends how you interpret the ToS. The real address is obvious to
    a human.

    But it clearly says a real email address is present AND obvious to a human.
    Whilst your Reply-To can be decoded by a human it most definitely isn't a
    real email address on a number of counts. Even after removing the remove
    bits, removing the underscores and changing the dot to a . it still isn't
    a real address.

    Quoted message said:

    If the AUP team contact me

    AUP team, don't make me laugh. Most ISPs don't have a AUP team as such,
    they will just take action on complaints.

    --
    Andy Leighton => [email hidden]
    "The Lord is my shepherd, but we still lost the sheep dog trials"
    - Robert Rankin, _They Came And Ate Us_

  4. On 05 Oct 2005 20:36:11 GMT, Andy Leighton <[email hidden]>

    Quoted message said:

    AUP team, don't make me laugh. Most ISPs don't have a AUP team as such,
    they will just take action on complaints.

    Most ISP's have an "abuse" team and Clara's do take action on valid
    complaints[1].

    [1] Except when it was Clara issuing .net addresses to customers in
    violation of RFC's (A long time ago...) :-(

    --
    ------------------------------------------------------------------
    - Stuart Millington ALL HTML e-mail rejected -
    - [email hidden] http://w3.z-add.co.uk/ -

  5. On 05 Oct 2005 20:36:11 GMT, Andy Leighton <[email hidden]>

    Quoted message said:

    But it clearly says a real email address is present AND obvious to a human.
    Whilst your Reply-To can be decoded by a human it most definitely isn't a
    real email address on a number of counts. Even after removing the remove
    bits, removing the underscores and changing the dot to a . it still isn't
    a real address.

    ->cycling_remove_bertie @ yahoo_remove_dot_co.uk

    The spaces need removing too.

    *cyclingbertie* is the name, *yahoo.co.uk* the domain.

    Two years ago one of my jobs as IT co-ordinator in a primary school
    was the mail admin. God help the hapless children!!!

  6. Stuart Millington <[email hidden]>typed

    Quoted message said:

    On Wed, 05 Oct 2005 18:44:22 +0100, Danny Colyer
    <[email hidden]> wrote:

    Quoted message said:
    Quoted message said:

    I set up my news account to provide a genuine reply address, one that I
    have never given to anyone for any other reason. According to Google,
    I've posted about 40 messages to 2 groups (urc and rec.sport.unicycling)
    using this address. Surprisingly (to me), the account has so far
    remained spam free.

    I don't get much spam. My address and sig are fairly transparent.
    Zetnet's fairly good at keeping it out. My KF filters help too.

    --
    Helen D. Vecht: [email hidden]
    Edgware.

  7. Bertie Wiggins said:

    The spaces need removing too.

    But you stated that the address was "which I will not monitor"...

    Quoted message said:

    Two years ago one of my jobs as IT co-ordinator in a primary school
    was the mail admin. God help the hapless children!!!

    Indeed... and the staff & parents :-(

    --
    ------------------------------------------------------------------
    - Stuart Millington ALL HTML e-mail rejected -
    - [email hidden] http://w3.z-add.co.uk/ -

  8. Helen Deborah Vecht said:

    I don't get much spam. My address and sig are fairly transparent.
    Zetnet's fairly good at keeping it out. My KF filters help too.

    ;-)

    --
    ------------------------------------------------------------------
    - Stuart Millington ALL HTML e-mail rejected -
    - [email hidden] http://w3.z-add.co.uk/ -

  9. Stuart Millington said:
    Nick Kew said:

    Latest news: you can use Apache to receive mail, and hook spamassassin
    right in to the server. Not that I'd recommend it quite yet for a
    production system - just running locally on a test machine here.

    1.3 or 2.0 only?

    2.1+ (though shoehorning onto 2.0 shouldn't be too hard).

    This project has been a twinkle in some of our eyes for some time.
    We used the google "summer of code" to get some manpower to kick
    off the project. Since mod_smtpd was a new project with no
    existing users to worry about, back-compatibility with 2.0 was
    never a concern. mod_smtpd won't be ready for prime-time
    before 2.2 (due in december).

    As for 1.3, that's been obsolete for three and a half years.

    --
    Nick Kew

  10. Danny Colyer said:

    I set up my news account to provide a genuine reply address, one that I
    have never given to anyone for any other reason. According to Google,
    I've posted about 40 messages to 2 groups (urc and rec.sport.unicycling)
    using this address. Surprisingly (to me), the account has so far
    remained spam free.

    I have been posting with this valid from address for about 3 years. It
    is picking up a little spam, but far less than any of (a) an address I
    sent to a job agency 3 years ago, (b) the address I use for Yahoo
    groups, (c) an address that appears on a website lightly munged with #
    for @, and (d) the address I use for personal emails.

    I think I'll go on using a valid address.

    Colin McKenzie

  11. Danny Colyer said:


    I set up my news account to provide a genuine reply address, one that I
    have never given to anyone for any other reason. According to Google,
    I've posted about 40 messages to 2 groups (urc and rec.sport.unicycling)
    using this address. Surprisingly (to me), the account has so far
    remained spam free.

    I have a working, but disposable, posting address. I intended to change
    it every month or so when the spam got irritating. But 90% of my spam
    is sent to other addresses that have never been used on Usenet. Some
    haven't ever been used anywhere : I presume they were found with
    dictionary attacks.

    I'm also running Spamassassin merely to mark suspected spam, but since
    NTL's spam trap was started it doesn't really catch anything - the few
    bits that make it through aren't detected by Spamassassin either.

    -adrian

  12. Stuart Millington said:
    Quoted message said:

    Two years ago one of my jobs as IT co-ordinator in a primary school
    was the mail admin. God help the hapless children!!!

    Indeed... and the staff & parents :-(

    The staff, perhaps, but no direct impact on the parents.

  13. Danny Colyer said:
    Cliff said:

    Anyone is using there proper address for replies on this newsgroup, I would
    expect you are getting a load of Spam e-mails selling medicines, computer
    software, phoney degrees and male enhancing drugs.

    A few weeks ago, after reading a post by Simon Brooke claiming not to
    have a spam problem despite posting to usenet using a genuine reply
    address, I decided to try an experiment.

    I set up my news account to provide a genuine reply address, one that I
    have never given to anyone for any other reason. According to Google,
    I've posted about 40 messages to 2 groups (urc and rec.sport.unicycling)
    using this address. Surprisingly (to me), the account has so far
    remained spam free.

    I've been using the same unmunged email address on Usenet for at least
    five years now. I use the same address for Yahoo groups and another
    linked one on our company website.

    The two combined get about 90 spam messages a day. most of which are
    caught by SpamSieve. I have to trawl through them in case a genuine
    business enquiry gets binned by mistake, but on the whole it's not a
    major annoyance.

    --
    Carol
    "This might as well say "bing tiddle tiddle bong".
    It's complete gibberish!" - Rodney McKay, Stargate Atlantis

  14. Nick Kew said:
    Stuart Millington said:
    Nick Kew said:

    Latest news: you can use Apache to receive mail, and hook spamassassin
    right in to the server. Not that I'd recommend it quite yet for a
    production system - just running locally on a test machine here.

    1.3 or 2.0 only?

    2.1+ (though shoehorning onto 2.0 shouldn't be too hard).

    :-(

    Quoted message said:

    As for 1.3, that's been obsolete for three and a half years.

    Unfortunately, that's what we're stuck with at DSVR for the
    foreseeable future :-(

    --
    ------------------------------------------------------------------
    - Stuart Millington ALL HTML e-mail rejected -
    - [email hidden] http://w3.z-add.co.uk/ -

  15. Cliff said:

    A word of warning.

    My disguised reply address has been appearing in Spam e-mail address lines
    and this is the only place I use it.

    I suspect it has been collected by Harvester Software.

    Anyone is using there proper address for replies on this newsgroup, I would
    expect you are getting a load of Spam e-mails selling medicines, computer
    software, phoney degrees and male enhancing drugs.

    My advice would be to disguise your address

    Great, more newbies trying to ruin Usenet with bad advice and crappy
    behaviour.

    If it's not your email address, don't use it. It doesn't belong to you.

    Daniele

  16. "Cliff" <[email hidden]> sd / msg
    <[email hidden]> dtd Tue, 4 Oct 2005
    23:15:37 +0100:

    Quoted message said:

    My disguised reply address has been appearing in Spam e-mail address lines
    and this is the only place I use it.

    Mine (in the reply-to field) has not. I do hope, though, that they
    have been making full and free use of the from address I use :-)

    Guy
    --
    http://www.chapmancentral.co.uk

    "To every complex problem there is a solution which is
    simple, neat and wrong" - HL Mencken

  17. Stuart Millington <[email hidden]> sd / msg
    <[email hidden]> dtd Wed, 05 Oct 2005
    19:18:02 +0100:

    Quoted message said:

    It is mostly, 99% of the time, the From: address that is harvested
    from Usenet (as it tends to be in the XOVER results). The Reply-To:
    address does not, generally, get harvested (as it is not in the XOVER
    results).

    That is what I have found (empirically).

    Quoted message said:

    Hence, my From: address gets a 550 whilst the Reply-To: is valid and
    is used by all working software for valid, human generated, replies.

    And my From: address is [email hidden] - the owner of that address
    actively solicits the forwarding of spam email to it, so I feel no
    compunction in using it, especially since my reply-to is valid and
    does arrive in my inbox.

    Interestingly I have started getting a very small amount of spam (all
    of which is filtered out by SpamCop) to the address on my home page,
    which is obscured from web crawlers by use of encoding. Evidently
    they are onto that wheeze now.

    In my view the punishment for spamming should be death by drowning in
    a vat of taurean diarrhoea.

    Guy
    --
    http://www.chapmancentral.co.uk

    "To every complex problem there is a solution which is
    simple, neat and wrong" - HL Mencken

  18. "Just zis Guy, you know?" <[email hidden]> whizzed past me shouting

    Quoted message said:


    And my From: address is [email hidden] - the owner of that address
    actively solicits the forwarding of spam email to it, so I feel no
    compunction in using it, especially since my reply-to is valid and
    does arrive in my inbox.

    Would they like me to use it too? I get lots of spam, I could even send
    them some of the better examples. Do they like 419s?

    --
    Sue ];(🙂

    Sometimes a public spirited citizen...

  19. Simon Brooke <[email hidden]> whizzed past me shouting

    Quoted message said:


    You are /required/ to provide a 'From' header, and the content of the
    'From' header is required to be your email address. End of story.

    I'd understood that the top-level domain .invalid (see headers)
    is provided expressly for munging addresses.

    I've never had any complaints about my munging both addresses. Of course
    I'd stop doing it if my ISP objected, but I think they're too busy
    battling zombies and open relays.

    This does mean there's no excuse for using a valid address that isn't
    yours.

    --
    Sue ]🙁🙂

  20. Sue White <[email hidden]> sd / msg
    <[email hidden]> dtd Sun, 9 Oct 2005 22:31:48
    +0100:

    Quoted message said:
    Quoted message said:

    And my From: address is [email hidden] - the owner of that address
    actively solicits the forwarding of spam email to it, so I feel no
    compunction in using it, especially since my reply-to is valid and
    does arrive in my inbox.

    Quoted message said:

    Would they like me to use it too? I get lots of spam, I could even send
    them some of the better examples. Do they like 419s?

    The more the merrier, Sue :-)

    Guy
    --
    http://www.chapmancentral.co.uk

    "To every complex problem there is a solution which is
    simple, neat and wrong" - HL Mencken

Active in the last 60 minutes

Active in this thread

0 users · 0 guests ·0 bots ·0 total

No signed-in users are active right now.

No known search crawlers active right now.