Re: SPAM from Usenet



Le 6 juin 2009 à 07:24, Eric Hodel a écrit :

On Jun 5, 2009, at 18:49, James Gray <james@xxxxxxxxxxxxxxxxxxx> wrote:

On Jun 5, 2009, at 7:21 PM, Joshua Collins wrote:

Yes, there is a bit of spam getting through, but it is not enough
to annoy me. I just hit 'report spam' in my Gmail account and I do
not get any more mail from that user.

Please never do this!

Gateway messages come from a address I setup for the purpose. You
are not reporting the spammer. Instead you are reporting me. Our
host has already threatened to shut the gateway down once due to
these complaints. If the complaint volume increases, we will be
forcefully terminated.

Is it possible to include the usenet Received headers in gateway
messages? They don't seem to be there now. (maybe I'm mis-remembering
Usenet.)

There's a path header instead, and a bunch of relevant headers, notably
for the web-news gateways (i.e. google groups) ; here's a sample of the
headers usenet-side for one of the last spams :

| Path: talisker.lacave.net!lacave.net!feeder.erje.net!news2.arglkargh.de!news.glorb.com!news2.glorb.com!postnews.google.com!g20g2000vba.googlegroups.com!not-for-mail
| From: "khan.babardk@xxxxxxxxx" <khan.babardk@xxxxxxxxx>
| Newsgroups: comp.lang.ruby
| Subject: http://kh-luxuriescar.blogspot.com
| Date: Fri, 5 Jun 2009 12:30:27 -0700 (PDT)
| Organization: http://groups.google.com
| Lines: 4
| Message-ID: <0f56e7b8-caa1-43b2-9369-0379637ac1e9@xxxxxxxxxxxxxxxxxxxxxxxxxxxx>
| NNTP-Posting-Host: 116.71.7.204
| Mime-Version: 1.0
| Content-Type: text/plain; charset=ISO-8859-1
| Content-Transfer-Encoding: 7bit
| X-Trace: posting.google.com 1244230227 25805 127.0.0.1 (5 Jun 2009 19:30:27 GMT)
| X-Complaints-To: groups-abuse@xxxxxxxxxx
| NNTP-Posting-Date: Fri, 5 Jun 2009 19:30:27 +0000 (UTC)
| Complaints-To: groups-abuse@xxxxxxxxxx
| Injection-Info: g20g2000vba.googlegroups.com; posting-host=116.71.7.204; posting-account=rqGG2woAAABMByqenh5rRwTgLM5dCy-7
| User-Agent: G2/1.0
| X-HTTP-Via: 1.1 STAR
| X-HTTP-UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/525.19 (KHTML, like Gecko) Chrome/1.0.154.53 Safari/525.19,gzip(gfe),gzip(gfe)
| Xref: talisker.lacave.net comp.lang.ruby:242475

This might help my spam filter block these messages for me.

Note that, recently, I thought that it would be a good idea to include
the _mail_ received headers Usenet side, quite for the same reasons...
:)

Fred
--
I remember when everybody posted to Usenet with their real, deliverable
e-mail address. Of all the sins committed by the spammers, destroying
the viability of the open Internet was the worst.
(Shmuel (Seymour J.) Metz in NANAE)
.



Relevant Pages