Bienvenido! - Willkommen! - Welcome!

Bitácora Técnica de Tux&Cía., Santa Cruz de la Sierra, BO
Bitácora Central: Tux&Cía.
Bitácora de Información Avanzada: Tux&Cía.-Información
May the source be with you!
Showing posts with label SPAM. Show all posts
Showing posts with label SPAM. Show all posts

Tuesday, June 19, 2012

spamina.com

Source

Cloud Email Firewall
Es una solución que protege de forma 100% eficaz las cuentas de correo electrónico de las empresas de manera eficiente y a la vez permite administrarlas, controlarlas y gestionarlas.

Ofrece una disponibilidad máxima del correo y protección contra las amenazas existentes.

El correo electrónico es una herramienta estratégica para las organizaciones que debe ser protegida. El 95% de los correos que reciben las empresas a diario es Spam o Malware, esta situación hace que disminuya la productividad. El firewall de correo permite reducir el impacto económico provocado por la recepción del Spam y otro Malware, ya que permite optimizar el uso de las infraestructuras tecnológicas relacionadas con el correo electrónico. La constante evolución de las técnicas usadas por los hackers, spammers, etc. requiere del uso de un firewall de correo que utilice tecnologías de filtrado avanzadas y constantemente actualizadas.

The World's Worst ISPs

Source

The networks listed on this page knowingly provide service to criminal spam gangs and ignore spam reports from anti-spam systems and Internet users. These networks are defacto Spam Havens from where spammers operate freely and with the full knowledge of the network administrators and the executives. In the name of profits, these ten networks turn a blind eye to criminal spam gangs on their networks.

Spam continues to plague the Internet because a small number of large Internet Service Providers sell service knowingly to professional spammers for profit, or do nothing to prevent spammers operating from their networks.

Although all networks claim to be anti-spam, some network executives factor revenue made from hosting known spam gangs into corporate policy decisions to continue to sell services to spam operations. Others simply decide that closing the holes in their end-user broadband systems that allow spammers access would be too costly to their bottom lines.

The majority of the world's service providers succeed in keeping spammers off their networks and work to maintain a positive anti-spam reputation, but their work is undermined daily by the few networks such as these who, out of corporate greed or mismanagement, choose to be part of the problem.

The World's Worst Spam Support ISPs
As of 19 June 2012 the ISPs with the worst Abuse Departments and consequently the worst reputations for knowingly hosting illegal spam operations are:
1
unicom-cnNumber of Current Known Spam Issues: 109

2
chinanet-fjNumber of Current Known Spam Issues: 69

3
dacom.co.krNumber of Current Known Spam Issues: 64

4
chinanet-gdNumber of Current Known Spam Issues: 62

5
gvt.net.brNumber of Current Known Spam Issues: 60

6
telefonica.com.arNumber of Current Known Spam Issues: 54

7
hinet.netNumber of Current Known Spam Issues: 54

8
iliad.frNumber of Current Known Spam Issues: 51

9
ttnet.net.trNumber of Current Known Spam Issues: 50

10
dreamhost.comNumber of Current Known Spam Issues: 48

spamcop.net

www.spamcop.net
SpamCop is the premier service for reporting spam. SpamCop determines the origin of unwanted email and reports it to the relevant Internet service providers. By reporting spam, you have a positive impact on the problem. Reporting unsolicited email also helps feed spam filtering systems, including, but not limited to, SpamCop's own service.

GET SPAM-FREE EMAIL

Professional-grade SpamCop email accounts feature spam reporting, customizable spam and virus filtering and simultaneous Webmail, POP and IMAP access.
Learn More

USE FREE BLOCKING LIST

Use the SpamCop DNS-based Blocking List with your own mailserver and get safe and effective spam filtering for free:

SpamCop Blocking List
Am I listed?: You can check the status of any server by entering its address:
 
SpamCop Blocking List Details
The SpamCop Blocking List (SCBL) lists IP addresses which have transmitted reported email to SpamCop users. SpamCop, service providers and individual users then use the SCBL to block and filter unwanted email. The SCBL is a fast and automatic list of sites sending reported mail, fueled by a number of sources, including automated reports and SpamCop user submissions. The SCBL is time-based, resulting in quick and automatic delisting of these sites when reports stop.
Received a Report from SpamCop?
Start by following the link(s) in the email report you received from SpamCop. These links provide details about the reported email and SpamCop's procedures. These links provide access to advanced options for analyzing and responding to reported spam.
Implement the SCBL to Filter Spam
The SCBL aims to stop most spam while not blocking wanted email. This is a difficult task. It is not possible for any blocking tool to avoid blocking wanted mail entirely. Given the power of the SCBL, SpamCop encourages use of the SCBL in concert with an actively maintained whitelist of wanted email senders. SpamCop encourages SCBL users to tag and divert email, rather than block it outright. Most SCBL users consider the amount of unwanted email successfully filtered to make the risks and additional efforts worthwhile.
The SCBL is aggressive and often errs on the side of blocking mail. When implementing the SCBL, provide users with the information about how the SCBL and your mail system filter their email. Ideally, they should have a choice of filtering options. Many mailservers operate with blacklists in a "tag only" mode, which is preferable in many situations.
There is no warranty associated with using this system. It is provided as is.

The Spamhaus Project

(Excerpt)
The Spamhaus Project is an international organisation (founded by Steve Linford in 1998) to track e-mail spammers and spam-related activity. It is named for the anti-spam jargon term coined by Linford, spamhaus, a pseudo-German expression for an ISP or other firm which spams or willingly provides service to spammers.


® Registered Trademark of The Spamhaus Project Ltd. Used under permission from Spamhaus Press Area.

Contents

  [hide

Spamhaus DNSBLs and DNSWLs

Spamhaus is responsible for a number of very widely used anti-spam DNS-based Blocklists (DNSBLs) and Whitelists (DNSWLs). Many internet service providers and Internet networks use these services to reduce the amount of spam they take on. The Spamhaus lists collectively protect over 1.4 billion e-mail users, according to Spamhaus' web page (June 2008) and are estimated to block 80 billion spam emails per day globally on the internet (almost 1 million spams per second). Like all DNSBLs, their use is considered controversial by some.
The Spamhaus Block List (SBL)[1] targets "verified spam sources (including spammers, spam gangs and spam support services)." Its goal is to list IP addresses belonging to known spammers, spam operations, and spam-support services[2] The SBL's listings are partially based on the ROKSO index of "spam gangs", for which see below.
The Exploits Block List (XBL)[3] targets "illegal 3rd party exploits, including open proxies, worms/viruses with built-in spam engines, and other types of trojan-horse exploits." That is to say, like several other DNSBLs it is a list of known open proxies and exploited computers being used to send spam and viruses. The XBL includes listings gathered by Spamhaus as well as by two contributing DNSBL operations — the Composite Blocking List(CBL) and the Not Just Another Bogus List (NJABL) lists.
The Policy Block List (PBL)[4] is a list that serves many of the same functions of a Dialup Users List, but really it is not a DUL. The PBL lists not only dynamic and DHCP type IP address space designated as 'not allowed to make direct SMTP connections', but static assignments that shouldn't be sending email without prior arrangement. Examples of such are an ISP's core routers, corporate users required by policy to send via their internal mail server, and unassigned IP addresses. Much of the data is provided to Spamhaus by the organizers (ISPs) of the IP address space.
The Domain Block List (DBL)[5] was released in March 2010 and is a list of domain names, which is both a domain URI Blocklist and RHSBL. It lists spam domains including spam payload URLs, spam sources and senders ("right-hand side"), known spammers and spam gangs, and phish, virus and malware-related sites.
The Spamhaus White List (SWL)[6] was released in October 2010 and is a whitelist of IPv4 and IPv6 addresses. The SWL is intended to allow mail servers to separate incoming email traffic into 3 categories: Good, Bad and Unknown. Only verified legitimate senders with clean reputations are approved for whitelisting and there are strict terms to keeping a Spamhaus Whitelist account.
The Domain White List (DWL)[6] was released in October 2010 and is a whitelist of domain names. The DWL enables automatic certification of domains with DKIM signatures. Only verified legitimate senders with clean reputations are approved for whitelisting and there are strict terms to keeping a whitelist account.
Spamhaus's DNSBLs and DNSWLs are offered as a free public service to low-volume mail server operators on the Internet.[7] Commercial spam filtering services and other large sites doing large numbers of queries must instead sign up for an rsync-based feed of these DNSBLs, which Spamhaus calls its Datafeed Service,[8] at a moderate fee as long as they are not in Spamhaus's top ten worst spam service ISPs list.[9]
Spamhaus also provides two combined DNSBLs. One is the SBL+XBL[10] which allows users to query sbl-xbl.spamhaus.org once and get return codes from both lists. A newer combination is called ZEN[11] (named after founder Linford's dog), which allows users to query zen.spamhaus.org once and get return codes from the SBL+XBL and the newer PBL.
Spamhaus outlines the way its DNSBL technology works in a document called Understanding DNSBL Filtering.[12]

Register of Known Spam Operations

The Spamhaus Register of Known Spam Operations (ROKSO)[13] is a database of "hard-core spam gangs" -- spammers and spam operations who have been terminated from three or more ISPs due to spamming. The ROKSO list is not a DNSBL; it is, rather, a directory of publicly-sourced information about these persons and their business and at times criminal activities.
The ROKSO database is nowadays part of the signup checking procedure of many of the major ISPs, ensuring that ROKSO-listed spammers find it difficult to get hosting. A listing on ROKSO also means that all IP addresses associated with the spammer (his other domains, sites, servers, etc.) get listed on the Spamhaus SBL as "under the control of a ROKSO-listed spammer" whether there is spam coming from them or not (as a preventative measure).
There is a special version of ROKSO available to Law Enforcement Agencies (for which LEAs need to apply for access) which gives access to data on hundreds of spam gangs, with evidence, logs and information on illegal activities of these gangs, too sensitive to publish in the public part of ROKSO.

Don't Route Or Peer List

The Spamhaus Don't Route Or Peer (DROP) List[14] is a text file delineating so-called "zombie" (stolen) CIDR blocks and netblocks which are "totally controlled by spammers or 100% spam hosting operations", as shown by SBL listings, with the numbers of the underlying listings as comments. It is intended not to include netblocks registered to ISPs and sublet to spammers, but only those blocks wholly used by spammers. It is intended to be incorporated in firewalls and routing equipment to block network traffic from and to those blocks.

Spamhaus Companies

The Spamhaus 'Group' (although there is no group identity) consists of a number of independent companies which focus on different aspects of Spamhaus anti-spam technology or provide services based around it. At the core is The Spamhaus Project Ltd., a UK-registered non-profit which tracks spam sources and publishes free DNSBLs. Further 'Spamhaus' companies include Spamhaus Logistics Corp.,[15] a Seychelles-registered corporation which owns the large server infrastructure used by Spamhaus and employs engineering staff to maintain it. Spamhaus Technology Ltd.,[16] a UK-registered commercial 'data delivery' company which "manages data distribution and synchronization services". Spamhaus Research Corp., a company which "develops anti-spam technologies". The Spamhaus Whitelist Co. Ltd.,[17] a Jersey-registered company which manages the Spamhaus Whitelist. Also there are several references on the Spamhaus website to The Spamhaus Foundation,[18] a private interest foundation (believed to be a Liechtenstein Foundation) whose charter is "to assure the long-term security of The Spamhaus Project and its work".

Awards

Saturday, October 29, 2011

Saturday, February 20, 2010

Listado gris

greylisting.org
Greylisting is a new weapon to use against spam in this great war being waged upon it. With this new shielding method, by which you may block out huge amounts of spam, you are sure to please your email clients!
In name, as well as operation, greylisting is related to whitelisting and blacklisting. What happen is that each time a given mailbox receives an email from an unknown contact (ip), that mail is rejected with a "try again later"-message (This happens at the SMTP layer and is transparent to the end user). This, in the short run, means that all mail gets delayed at least until the sender tries again - but this is where spam loses out! Most spam is not sent out using RFC compliant MTAs; the spamming software will not try again later.
But.. spammers adapt!?
Yes they do. But that does not really make greylisting useless. This delay in new sender contacts also gives you a lot of extra power. This may be an hour, but in this hour there is a large chance that the mass mailer/spammer has been identified by the more conventional anti-spam software. Thus, when he retries it, is likely that we will know him for what he really is!
What if my email was rejected and greylisting was mentioned as the cause?
This can happen for various reasons:
  • The MTA (mail transfer agent) / email ISP that you use to send email is not RFC 821 compliant. Contact your ISP.
  • The MTA is in some way misconfigured to not automatically retry email messages that gets rejected with the "try later"-message. Maybe it's timing is off and it retries immediately (which it shouldn't). Contact your ISP.
  • The recipient email server has got greylisting misconfigured, ie. an implementation that just doesn't let mails through even on later retries. Or maybe their error message is actually wrong: greylisting was NOT the reason your mail bounced - but something else.
Introduction
In 2003 Evan Harris announced a notion he called greylisting. Greylisting does not absolutely reject mail, but requires mail from unfamiliar senders to be retransmitted by their ISPs' SMTP clients. Mail from familiar senders is passed immediately.
The idea is to delay mail from unfamiliar senders for half an hour, but immediately deliver mail from regular correspondents. It is based on the observation that large amounts of spam is sent via open proxies, botnets, and other mechanisms that do not involve proper mail transfer agents (MTAs). A proper sending MTA will repeat a transmission after a temporary 4yz rejection. RFC 2821 says that the sending MTA should retransmit 30 minutes or later after a failure, but spam sent through an open proxy as well as some viruses and worms are not retransmitted.
Greylisting is extremely effective against spam that is not otherwise detected by DCC clients. If you cannot use greylisting, consider body URL blacklisting by adding something like -Bsbl-xbl.spamhaus.org,any to DCCM_ARGS or DCCIFD_ARGS in /var/dcc/dcc_conf.
In the DCC implementation of greylisting the sendmail milter interface, dccm, or the general MTA interface, dccifd, sends a request to a modified version of the DCC server, greylist dccd. The requests contains the simple DCC body checksum of the message as well as an MD5 checksum of the MD5 checksums of IP address of the SMTP client sending the mail message, the envelope sender or Mail From value of the message, and the recipient or envelope Rcpt To value of the message. If the combination IP address, sender, and recipient is familiar, the DCC client tells the MTA to accept the message. Otherwise the DCC client tells the MTA to embargo or temporarily reject the message.
If the sending MTA persists and retransmits the message after the embargo but within the wait time, the triple (sender, IP address, addressee) is added to the database.

Friday, February 12, 2010

Internet crawler

Source
Once i created new email account, and left it for one day without telling anyone about it. The next time i log in, my inbox already fill with spam and junk mail.
Its not only happened to me. Almost every one i assumed experience it. Some people even accused yahoo, hotmail and other provider of selling their user list to the spammers. Well actually it doesn't have to be that way.
As you know online search engine like yahoo, google, etc. Used a software application that they called crawler or meta-bot, to crawl through the internet page by page. For each page they try to find a relevant information of how this page will be index. For example a page about planting flower maybe indexed by flower, planting, or gardening. So this page will be added to the crawler database by the relevant information. So when next time a user type "flower" in the search category of the search engine. This page will be showed as one of the page that has relevant information about flower.
And with the fast pacing growth of online search engine. Finding a crawler application is simple enough as inserting "internet crawler" in google. You will be given a list of option, from free to propietary appliaction.
So as the spammer, all you have have to do is get a crawler, create a sub crawler for specific criteria - Crawler that only index email address they found. And abracadabra the spammer database will fill with email address ready to be spam.
Damn it how can you fight this? No matter how you try to protect your email address. One day there will be a page that will show your email address. Damn, they out smart us again!
HS-Crawler
Email marketing is the ideal way to promote your business. HS-Crawler is a software designed to extract email addresses from web sites, search engines and Newsgroups.
Name : EncodedMailLink
Description : Component that encodes email addresses into javascript so as to attempt to avoid detection by spambots.

Tuesday, April 7, 2009

The Nigerian Spam Scam Exposed

Source
Ever wondered what would happen if you ever responded to one of the many Nigerian spam scams? Zone-H have done just that and have chronicled every step in this paper, from the first email exchange to the final phone call where they agreed to meet the scammers in Nigeria.
Click Here to download this article

Monday, April 6, 2009

SPAM: Vacation responder hack

A hacked account in gmail.com allows mechanisms to send a lot of spam to your contacts:
Hey friend,
How are you doing recently? I'd like to introduce you a very good
foreign trading online company and the website is www.ui-mall.com
It can offer you so many kinds of electronic products which you may be
in need,such as laptops...
...
Email: uimall@188.com
Hoping you can enjoy your shopping from that company !
Regards
Tux&Cia. Solution:
Set a stronger password in you account and disable the vacation responder

Settings in gmail.com

Vacation responder:
TURN IT OFF!
(sends an automated reply to incoming messages. If a contact sends you several messages, this automated reply will be sent at most once every 4 days)
Learn more