Re: flood/spammer's new tactics



On 2007-08-16, Robert M. Riches Jr. <spamtrap42@xxxxxxxxxxx> wrote:

The flood/spammer has adapted (just like the Borg). From
what I can see, the common denominator of about half of
today's round is:

X-Complaints-To: abuse@xxxxxxxxxxx

That is easy enough to filter out without much collateral
damage. However, most of the other half appear to have the
following:

NNTP-Posting-Host: 24.174.213.62
X-Complaints-To: abuse@xxxxxx

Unfortunately, when I tried filtering in slrn on the NNTP
posting host, it didn't work--none of the postings got
marked green. A quick grep of my archived "good" historical
postings show the rr.com line for many good postings.

I'm hoping the current bozo will go away in a couple of
days, reducing the urgency to install and set up leafnode,
at least in the short term.

Does anyone else have good leads in filtering out this new
round of junk?

Try escaping the "." like this:

NNTP-Posting-Host: 24\.174\.213\.62

Works here with slrn, but the spewer changes things often enough that
I've needed a lot of new rules anyway.

--

John (john@xxxxxxxxxxx)
.



Relevant Pages

  • flood/spammers new tactics
    ... today's round is: ... when I tried filtering in slrn on the NNTP ... postings show the rr.com line for many good postings. ...
    (comp.os.linux.misc)
  • Re: flood/spammers new tactics
    ... today's round is: ... when I tried filtering in slrn on the NNTP ... postings show the rr.com line for many good postings. ... This catches all the junk so far for me, ...
    (comp.os.linux.misc)
  • Re: [Full-Disclosure] Shortcut...... may cause 100% cpu use!!!
    ... filtering out annoying peoples' postings ... on mailing lists. ... For purposes of example, ...
    (Full-Disclosure)
  • Re: flood/spammers new tactics
    ... today's round is: ... postings show the rr.com line for many good postings. ... the HEAD NNTP command is used to get all headers. ...
    (comp.os.linux.misc)
  • Re: [SI] The Final (again) Fate of the Shoot-In
    ... You could count me back in if you really aren't filtering Gmail email. ... followup you said that only applied to news postings. ... *as long as* someoneare willing to administer them. ...
    (rec.photo.equipment.35mm)