Results 1 to 5 of 5
  1. #1
    slotplayer is offline Private Member
    Join Date
    September 2006
    Posts
    1,044
    Thanks
    198
    Thanked 322 Times in 252 Posts

    Default Spam is out of Control

    I've been using a couple Yahoo emails for many years, one I just give out and another I use for my retail sites, the one for the retail sites has always been amazingly spam free until recently.

    Now I'm plagued with it. Thanks marissa mayer.

  2. #2
    lowrisk is offline Private Member
    Join Date
    June 2011
    Posts
    801
    Thanks
    80
    Thanked 180 Times in 132 Posts

    Default

    I wonder, if we signed up a test registration with a certain casino, with a completely new clean email address. I'd be interested to monitor aid email address for any spam for other brands. Thus confirming that said brand are trying to cut the affiliate out of the loop, or data is being sold on.

  3. #3
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,893
    Thanks
    4,519
    Thanked 9,274 Times in 5,964 Posts

    Default

    Spam is CLEARLY out of control and I have been battling it forever, but it has increased a great deal the last few months.

    Most of us know how bad it is to put email addresses in plain text on websites, but today I discovered a practice I had no idea was going on. I found that some websites publish their mail server logs, and in so doing are publishing thousands (and in some cases) hundreds of thousands of email addresses in plain text on website pages that ARE most certainly being spidered.

    I guaranteee they are linked and spidered since I stumbled on the pages from a google search researching a spamming domain or ip or something.

    xxhttp://ns4.appservhosting.com/mailreport/general/2013/11/13.html
    xxhttps://rznet.com/mailreport/general/2013/6/9.html

    The pages are created by Ender UNIX Isolog. Now this is clearly not the software developer's fault, and in fact they recommend not publishing them, but some idiot hosts think this is ok, even though they do NOT have permission to publish these private email addresses (thousands upon thousands of them) and it has got to rate right up there on my list of the 10 most boneheaded things a web host that doesn't have a clue is doing.

    Now, if these pages were published behind ssl or at least protected pages for hosting clients only I could understand, but let's look at an example. Appserverhosting logs for 2013 show a total of 1246437 emails, so that is an easy potential of a half million unique email addresses sitting there in those publish log files.

    That means that if, whatif, you have ever sent them an email? If so your email address is sitting there somewhere in those logs.

    What an extremely foolish thing to do. And worse, how many opther hosts do such stupid things as that?

    Some of these spammers think they are sooooo slick, and I have studied them closely in recent months. They really think that instead of hitting every ip in a /27 or /28 they will instead avoid detection by hitting every other ip will work out so much better. Or they will hit wit .16 and .31 today, .17 and .30 tomorrow, .18 and .29 the next day.

    Or, they will use 40 different subnets and hit 10 ip's out of each one over the course of a 2 week period, and funny emaough all 40 of the subnets will be from the same host or upstream provider.

    We won't even talk about the adult spammer I have managed to catch that has a few thousand domain names that all have their mx records pointed at a rather well know company, ok one of the biggest companies out there. In fact when I proved to them that unscrupulous mailers were using said company's ip address fraudulently, and that over 6000 domains were pointed at the ip, they thanked me for all the proof, suggested no one can do anything about it, suggested I block the ip, and stated emphatically unless I could prove the traffic was coming FROM the ip there was nothing that could be done.

    Well this adult spammer happens to send their spam using bot networks and it is the return emails going back to them that goes to the mx record in question. Blocking the ip only means that the server logs contain a number of mx failures, since if the mail filter catches and denies the mail, by defult the bounce message is sent to the sender.

    If anyone ever needs any help blocking subnets, or recommendations on mxlookup tools, subnet calculators or otherwise, let me know and we can discuss it.

    Rick
    Universal4

  4. #4
    edgarf76's Avatar
    edgarf76 is offline Private Member
    Join Date
    March 2013
    Location
    Montreal
    Posts
    2,196
    Thanks
    804
    Thanked 582 Times in 429 Posts

    Default

    Rick is there a website that teaches the basics of what you wrote about?


    Sent from my iPad using Tapatalk
    Visit Play Slots 4 Real Money and Casino Slots Money for trusted recommendations and tips on the best casinos.

  5. #5
    universal4's Avatar
    universal4 is offline Forum Administrator
    Join Date
    July 2003
    Location
    Courage is being scared to death...and saddling up anyway. John Wayne
    Posts
    33,893
    Thanks
    4,519
    Thanked 9,274 Times in 5,964 Posts

    Default

    Nope, sorry edgar.

    I would be happy to answer any questions if I am able to though. There are a LOT of very knowledgeable folks here where we can all turn for answers to questions, so don't be afraid to ask.

    As an example, I honestly hate figuring out subnets and refuse to do so in binary, but I happen to know a pretty well laid out subnet calculator online that allows me to put in a start address, and I can just tell it to show me what the subnet is for say 32,768 ips is (half a class b) and it will tell me where it has to start and end and what the cidr is as well as the subnet mask. (great for ipsec rules)

    As far as courses for learning or understanding, my guess is you could find cbt's for just about any subject in networking, security or whatever.

    Finding those pages that published the emails was just dumb luck to be honest.

    Figuring out what the spammers were doing in Buffalo, Scranton, Miami and California came from studying the mail server logs for months and months and months and I have a fairly analytical mind.....(some that know me will just say I am anal)....LOL

    I am not saying there aren't spammers from other geographic areas, I would rather not be more specific since it would appear that I was then targeting certain countries in general terms.

    I will honestly say I have a few areas that when I see spam from them I will perform a lookup on the ip, and try and make the subnet as large as I can for blocking purposes so i can block the most with the fewest entries.

    Also, spam blocking is a touchy subject and you need to be even more careful if mail is on the same server as webs. In my case, mail is a sepearate server so any blocking on mail still allows web traffic.

    I will be happy to send every single spammer in the world to a casino using my links, or that of my clients, just stop sending me your drug spam.

    One tip I will put out there, if your mail server has an option that you can reject with the EHLO response, block "EHLO ylmf-pc". You just have to trust me on that one, just google ylmf attack. Very few mail servers support blocking by EHLO response, and some only do so after authentication, which is like only closing the gate AFTER the cattle leave the ranch.

    And if you happen to look through your logs and see a single ip hitting yoiu 500 or 1000 times in an hour, block them without question since they might come back.

    You might be surprised how many ip's that will try to hack one day end up being used by honest hard working affiliates or other innocent users the next day due to isp's handing out fresh new (very dirty) ip's to different users every day because they are too lazy to user a reservation system in their dhcp servers making spam and hacker blocking 10 times harder in a handful of countires.

    Once enough of those ips and subnets get blocked in the really big lists like sorbs, spamhaus, rbl etc, that will change when enough clients have enough trouble sending mail to Yahoo, Outlook, GMail, AOL, the banks, the utility companies, as well as their own isp's. For now for those folks all they usually have to do is reboot and they will get another ip and hope it isn't blocked.

    That will continue to work for a while, but based upon what I am seeing in my logs, and the various rbl lists I see, more and more ips are added every day. Almost all decent mail server software allows as admin to assign lookups in some of those lists and automatically reject mail if the sending ip is on those lists.

    Rick
    Universal4

  6. The Following 2 Users Say Thank You to universal4 For This Useful Post:

    Doolally (21 April 2014), edgarf76 (20 April 2014)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •