Firewall Wizards mailing list archives

RE: FWTK and smap/smapd


From: Karl Vogel <karl.vogel () seagha com>
Date: Thu, 18 Jul 2002 10:20:35 +0200

You might want to investigate using Spam Assassin (
http://www.spamassassin.org/ ). This works
really well for identifying & tagging spam.

With EXIM (and probably also sendmail/postfix), you can even have Spam
Assassin check the
message _before_ accepting it. Or you can accept the message at your MTA but
filter it in your
MUA.

It is possible to run SA in a client/server setup, so if you are careful and
setup the server side with
minimal permission, you can make it reasonably secure. For maximum security,
you can setup
the server side on a extra firewalled segment.


-----Original Message-----
From: Dominik Miklaszewski [mailto:dmikey () mac com]
Sent: Thursday, July 18, 2002 01:57
To: Roger Marquis
Cc: firewall-wizards () honor icsalabs com
Subject: Re: [fw-wiz] FWTK and smap/smapd


Guys,
These days spam gets really, annoying (timewise and costwise) 
from a busy admin
standpoint..
I run pair of sendmails with RBL  (ordb.org) feature turned on and two
anti-virus SMTP behind them, it's been catching maybe 20-30% 
of that trash..
They not only use hotmail, msn or yahoo but quite recently, 
while chasing down
another buymycrap.com I found they had used some generic 
Win2000/NT installation
with Exchange on it plugged in via DSL lines and sent them 
with a registered
domain on it. ORDB.org can't check on them as those Win boxes 
can be simply
turned off..  They've been spewing that crap through some 
dictionary generated
generic usernames (8 characters standard) ..I've seen alot of 
that.. anyway
here's the point -> we do not use 8-charaters username 
standard, so everyday I'm
finding some 800-2000 spewage of bounce-offs in the 
postmaster bucket ..I assume
another 800-2000 got back to "the sender" politely informing 
him "no such
user..blablablah".. and that's where RBL can't manage to help 
with. ( I quit
doing strict DNS checkups at sendmail level for obvious reasons)

Here's the idea:
1. create a postmaster account on a Unix box and forward that 
spewage to it.
2. A cronjob would be running on these entities in 
postmaster's bucket parsing
the "Received:" lines
3. Input taken from 2. would be run against MX checking with 
the assumption that
all those "DELIVERY FAILURE 55x:" are spewage.
4. There'll be a black list created from 3. with all those 
IP's and domains that
fail 3. checks.

I'm planning to let this process run and grow that black list 
to see what
percentage of that crap I'd able to nail down..

What do you think?
Would it be easier to do with Exim/Smail/Postfix ?

I'm sorry it's slightly off of that lists mainstream ..but 
since we have so
lively discussion on different MTAs I dared to ask.

thank you
Dominik Miklaszewski

Roger Marquis wrote:

Rick Murphy wrote:
Like? Examples, lots of them (or at least one).

OK.
Much of the spam I used to receive came from forged 
hotmail.com accounts.
Very little spam actually comes from hotmail, so I don't 
want to just block
them since there are some legitimate correspondents of 
mine that use their
mail (heck, I use a hotmail address sometimes when I'm on 
the road..)

Ron Guilmette has patches that do this for Postfix at
<http://www.monkeys.com/anti-spam/filtering/additions.html>.  I
tried them but had too many false positives, even for the commonly
forged domains like hotmail.  They did catch some spam though it
never more than 2 or 3% of the daily filtered total.

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: