<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>blog.iloaf.com &#187; Spam</title>
	<atom:link href="http://blog.iloaf.com/category/spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.iloaf.com</link>
	<description>Reflective Reality 3</description>
	<pubDate>Fri, 19 Sep 2008 14:46:58 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
	<language>en</language>
			<item>
		<title>Mailchannels TrafficControl update</title>
		<link>http://blog.iloaf.com/2008/06/02/mailchannels-trafficcontrolupdate/</link>
		<comments>http://blog.iloaf.com/2008/06/02/mailchannels-trafficcontrolupdate/#comments</comments>
		<pubDate>Mon, 02 Jun 2008 20:02:59 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
		
		<category><![CDATA[Spam]]></category>

		<category><![CDATA[email]]></category>

		<category><![CDATA[mailchannels]]></category>

		<category><![CDATA[smtp]]></category>

		<category><![CDATA[traffic shaping]]></category>

		<guid isPermaLink="false">http://blog.iloaf.com/?p=107</guid>
		<description><![CDATA[	Having spent an interesting evening chatting with Dave from MailChannels, I&#8217;ve now spent well over a week traffic shaping SMTP for some 200k connections and it&#8217;s time for a few observations:

	The installer is very Solaris-a-like. I&#8217;m not a fan. I do remember a few far worse, but only a few  
Upgrades are somewhat clunky, [...]]]></description>
			<content:encoded><![CDATA[	<p>Having spent an interesting evening chatting with Dave from MailChannels, I&#8217;ve now spent well over a week traffic shaping <span class="caps">SMTP</span> for some 200k connections and it&#8217;s time for a few observations:<br />
<ol></p>
	<p><li>The installer is very Solaris-a-like. I&#8217;m not a fan. I do remember a few far worse, but only a few <img src='http://blog.iloaf.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </li><br />
<li>Upgrades are somewhat clunky, since the installer A) takes settings saved in ~/.something rather than the running config (weird) &#038; B) buggers about with your config file removing all those logical line breaks you put in to define sections once you enabled some of the disabled features.</li><br />
<li>I did wonder why the hell it wasn&#8217;t a direct replacement smtpd for postfix at one point. <span class="caps">XCLIENT</span> functionality might cut the mustard though.</li><br />
<li>FP&#8217;d disastrously on a finance site I use quite a bit. I had to whitelist it</li><br />
<li>It annoyed my kids by FP&#8217;ing on a very popular music site they use a lot</li><br />
<li>>90% of rejections were <span class="caps">RBL</span> related.</li><br />
<li>I&#8217;ve a suggestion list a few pages long, but raised enough bugs already. I&#8217;m not really a grumpy-old-man <img src='http://blog.iloaf.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </li><br />
<li>It appears not to like the popular catalog shops, this isn&#8217;t so much of a problem because I can&#8217;t afford the wifes shopping habits at the moment.</li><br />
<li>There is a setting to turn off the feedback &#038; Ken made a change to the license to exclude addressing info but my preference is to opt out on my personal box</li><br />
<li>It appears to be catching less (or I&#8217;ve been noticing a lot more) and I&#8217;m relying on SpamAssassin more since the upgrade</li><br />
</ol></p>
	<p>I&#8217;ve a hunch that most of these issues come down to <span style="text-decoration: line-through;">bulkers</span> postmasters setting short timeouts and increasing parallelism to get the greatest bang-for-the-buck-come-instant-gratification from their listservs in the zero hour. Postfix and qmail come with excellent defaults that cope with sods like me greylisitng or traffic shaping spammers connections &#8211; don&#8217;t fuck with them eh?</p>

	<p>This is after all my personal mailhost, it runs a few small spamtraps and a bunch of mailboxes but not scientific empirical datasets. My mailbox has been hard to manage this week and I&#8217;m not aware of anything out of the ordinary happening. My public self seeding site is getting more english junk: <a href="http://test.iloaf.com/Week-of-Mon-20080526/thread.html">This week</a> then the <a href="http://test.iloaf.com/Week-of-Mon-20080428/thread.html">same week last month</a>. Pure observation but interesting none the less.</p>

	<p>If I had to sum it up: At the moment, I&#8217;m sorry to say it&#8217;s not as effective as the decent greylisting implementation I was running, it appears to be FP&#8217;ing more but nevertheless it has far fewer drawbacks in normal use since the delays appear more usual than the arbitrary 3<sup>rd</sup> party retry timeouts greylisting causes. It could be excellent. (<strong>Edit:</strong> added the dot. <a href="http://blogsearch.google.co.uk/blogsearch?um=1&#038;ie=UTF-8&#038;q=mailchannels+free+beer&#038;scoring=d">Is anyone else trying it</a>? )</p>

	<p>The Granddaddy of rejections was very interesting though natwest.co(m|.uk) <span class="caps">WTF</span> is going on with all that phish?</p>
 <div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fblog.iloaf.com%2F2008%2F06%2F02%2Fmailchannels-trafficcontrolupdate%2F&amp;title=Mailchannels+TrafficControl+update', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="http://s3.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.iloaf.com/2008/06/02/mailchannels-trafficcontrolupdate/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Mailchannels first impressions &#038; its feedback loop</title>
		<link>http://blog.iloaf.com/2008/05/25/mailchannels-first-impressions-its-feedback-loop/</link>
		<comments>http://blog.iloaf.com/2008/05/25/mailchannels-first-impressions-its-feedback-loop/#comments</comments>
		<pubDate>Sun, 25 May 2008 22:09:22 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
		
		<category><![CDATA[Knee Jerk]]></category>

		<category><![CDATA[Spam]]></category>

		<category><![CDATA[feedback]]></category>

		<category><![CDATA[mailbox]]></category>

		<category><![CDATA[mailchannels]]></category>

		<category><![CDATA[smtp proxy]]></category>

		<category><![CDATA[spy]]></category>

		<guid isPermaLink="false">http://blog.iloaf.com/?p=104</guid>
		<description><![CDATA[	I love the idea of abusing the fact that spammers are in a hurry. Traffic Control checks all the geeky check-boxes of a SMTP proxy I should take a closer look at.
So the first thing I do once I can netcat to the proxy and check it&#8217;s running is fire up a &#8220;tcpflow -c -i [...]]]></description>
			<content:encoded><![CDATA[	<p>I love the idea of abusing the fact that spammers are in a hurry. Traffic Control checks all the geeky check-boxes of a <span class="caps">SMTP</span> proxy I should take a closer look at.<br />
So the first thing I do once I can netcat to the proxy and check it&#8217;s running is fire up a &#8220;tcpflow -c -i eth0 not port 22&#8221; to watch it in action.  I could immediately see how it slows connections (sweet), and then the instant phone home traffic or feedback mechanism.<br />
I&#8217;m not so sure I like the feedback mechanism. The main issue is &#8220;but not be limited to&#8221; statement in the license as usual not the fact that they aggregate logs, over http on port 25.</p>

	<p>Exhibit #1 &#8211; License snippet :<br />
<blockquote>17.Feedback. The Software may periodically submit statistics about its<br />
operation to servers operated by MailChannels and other parties<br />
authorized by MailChannels (the &#8220;Feedback&#8221;). The Feedback shall<br />
include <strong>but not be limited to</strong> the IP addresses of email senders,<br />
server memory usage, server <span class="caps">CPU</span> usage, and various attributes of<br />
email sending hosts such as operating system type.</blockquote><br />
Exhibit #2 &#8211; Stream capture : feedback.mailchannels.com port 25 gets sent a log line per email as a http post.<br />
<blockquote>rd.42946-feedback.mailchannels.com.00025: <span class="caps">POST </span>/et/capture <span class="caps">HTTP</span>/1.1<br />
Host: feedback.mailchannels.com<br />
Content-Length: 402<br />
Connection: keep-alive</p>

	<p>[2008-05-25 16:58:53 +0100] [22019] i=78.149.112.169:52371 h= o=N u= a= t= p=0 d=0<br />
x=&#8221;ClientACL t=0,0|EarlyTalker t=0|RBL action=reject;cbl.abuseat.org=no_data;hul.habeas.com=no_data; query.bondedsender.org=no_data;sbl-xbl.spamhaus.org=no_data; t=0.11,0.17,0.04,0.28,0.17;zen.spamhaus.org=127.0.0.11.reject&#8221;<br />
l=ACCEPT c=550 z=&#8221;Found on zen spamhaus&#8221; e=&#8221;[550,Found on zen spamhaus]&#8221;<br />
q= n=1/0/1 b=0/0/0/1 v=</blockquote><br />
<sup>CR&#8217;s added for readability</sup></p>

	<p>I completely understand why they want the spy-in-the-box (having worked with Justin I know the possibilities are endless) but that license is a bit too lax for me. It&#8217;s just a niggle but I&#8217;d feel more comfortable if it was defined explicitly, and explained in full and have the option to disable it on privacy grounds.</p>

	<p>You need to disable <span class="caps">SPF</span> in your mailserver too, since the postfix sees the proxy ip, spf hard fails result in a reject &#8230; I should have thought of that <img src='http://blog.iloaf.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> Maybe thats where my license file has gone <img src='http://blog.iloaf.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> Woops.</p>

	<p>Just in case Ken reads this..<br />
<ul></p>
	<p><li>Kudos for the non commercial licensing</li><br />
<li>I&#8217;ve mailed free-beer and am still waiting for a key.</li><br />
</ul></p>
	<p>Being a typical old school QA guy I&#8217;ve a heap of suggestions, but for the time being this image of my mailbox shows the performance in the first hour or two with the default config.<br />
<a href="/wp-content/mailbox.png"><img class="aligncenter" src="/wp-content/mailbox.png" alt="mailbox" width="70%" height="70%" /> </a><br />
...eww, but you should see what happens without it.<br />
In fact if you look at the graph below you can see the effect is that the server is relaying more mail and rejecting less.</p>

	<p><sup> E&#038;OE plus the fact I&#8217;m in a rotten mood, I&#8217;m blaming the prescription(s) <img src='http://blog.iloaf.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </sup></p>
 <div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fblog.iloaf.com%2F2008%2F05%2F25%2Fmailchannels-first-impressions-its-feedback-loop%2F&amp;title=Mailchannels+first+impressions+%26%23038%3B+its+feedback+loop', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="http://s3.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.iloaf.com/2008/05/25/mailchannels-first-impressions-its-feedback-loop/feed/</wfw:commentRss>
		</item>
		<item>
		<title>MailChannels &#8220;Free Beer&#8221; edition</title>
		<link>http://blog.iloaf.com/2008/05/20/mailchannels-free-beer-edition/</link>
		<comments>http://blog.iloaf.com/2008/05/20/mailchannels-free-beer-edition/#comments</comments>
		<pubDate>Tue, 20 May 2008 07:58:59 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
		
		<category><![CDATA[Spam]]></category>

		<category><![CDATA[free beer]]></category>

		<category><![CDATA[mailchannels]]></category>

		<category><![CDATA[smto proxy]]></category>

		<guid isPermaLink="false">http://blog.iloaf.com/?p=100</guid>
		<description><![CDATA[	I looked at the MailChannels &#8220;free beer&#8221; edition yesterday and decided that 10k/day is not enough for my personal mailhost.

	$ grep -c  connect /var/log/mail.log.1
28652

	...and yesterday wasn&#8217;t a busy day either.

	

	IMHO it&#8217;d have much better adoption if it had been free for non-commercial use like MT Etc. since it has wide appeal to the hobbyist [...]]]></description>
			<content:encoded><![CDATA[	<p>I looked at the MailChannels &#8220;free beer&#8221; edition yesterday and decided that 10k/day is not enough for my personal mailhost.</p>

	<p><code>$ grep -c  connect /var/log/mail.log.1<br />
28652</code></p>

	<p>...and yesterday wasn&#8217;t a busy day either.</p>

	<p><img src="http://iloaf.com/mailgraph-day" alt="graph" /></p>

	<p><span class="caps">IMHO</span> it&#8217;d have much better adoption if it had been free for non-commercial use like <span class="caps">MT </span>Etc. since it has wide appeal to the hobbyist lower middle class sysadmin type. Tried it at home and bought it for work isn&#8217;t a bad sales model after all for geeks.</p>

	<p>I wonder if they cope with PayPals&#8217; silly/borked <span class="caps">SPF</span> records? <img src='http://blog.iloaf.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  .. I wonder if they process <span class="caps">SPF</span> at all for that matter.</p>
 <div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fblog.iloaf.com%2F2008%2F05%2F20%2Fmailchannels-free-beer-edition%2F&amp;title=MailChannels+%26%238220%3BFree+Beer%26%238221%3B+edition', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="http://s3.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.iloaf.com/2008/05/20/mailchannels-free-beer-edition/feed/</wfw:commentRss>
		</item>
		<item>
		<title>New spam graphing</title>
		<link>http://blog.iloaf.com/2007/08/18/new-spam-graphing/</link>
		<comments>http://blog.iloaf.com/2007/08/18/new-spam-graphing/#comments</comments>
		<pubDate>Sat, 18 Aug 2007 09:47:16 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
		
		<category><![CDATA[Spam]]></category>

		<category><![CDATA[~/]]></category>

		<guid isPermaLink="false">http://blog.iloaf.com/2007/08/18/new-spam-graphing/</guid>
		<description><![CDATA[	Here is a sneak peek at the next tool in the rrd-client suite. A daemon that monitors your MTA&#8217;s logs real-time and feeds stats into rrd-server.

Plenty of TODO&#8217;s still to be completed but it&#8217;s dead neat so far.

	Not sending all that mail through spamassassin is really helping my CPU usage too. This is really going [...]]]></description>
			<content:encoded><![CDATA[	<p>Here is a sneak peek at the next tool in the <a href="http://rrd.me.uk/cgi-bin/rrd-browse.cgi">rrd-client</a> suite. A daemon that monitors your <span class="caps">MTA</span>&#8217;s logs real-time and feeds stats into rrd-server.<br />
<img src="http://iloaf.com/mailgraph-day" alt="Graph" /><br />
Plenty of <span class="caps">TODO</span>&#8217;s still to be completed but it&#8217;s dead neat so far.</p>

	<p>Not sending all that mail through spamassassin is really helping my <span class="caps">CPU</span> usage too. This is really going to help when I get my colo box next week.<br />
<img src="http://iloaf.com/cpugraph-day" alt="Graph2" /></p>
 <div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fblog.iloaf.com%2F2007%2F08%2F18%2Fnew-spam-graphing%2F&amp;title=New+spam+graphing', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="http://s3.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.iloaf.com/2007/08/18/new-spam-graphing/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Jobbed again</title>
		<link>http://blog.iloaf.com/2007/08/04/jobbed-again/</link>
		<comments>http://blog.iloaf.com/2007/08/04/jobbed-again/#comments</comments>
		<pubDate>Sat, 04 Aug 2007 11:06:55 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
		
		<category><![CDATA[Spam]]></category>

		<category><![CDATA[~/]]></category>

		<guid isPermaLink="false">http://blog.iloaf.com/2007/08/04/jobbed-again/</guid>
		<description><![CDATA[	It would appear that some 3-4 hours of spam was cluelessly sent with a fake from address aimed at me, but this time there was no grief with it unlike the last big last time. This attack was about half the size of the awesome flood a year ago.

	

	So this gave me an excellent opportunity [...]]]></description>
			<content:encoded><![CDATA[	<p>It would appear that some 3-4 hours of spam was cluelessly sent with a fake from address aimed at me, but this time there was no grief with it <a href="/2006/11/27/wtf-my-mailbox-exploded/">unlike the last big last time</a>. This attack was about half the size of the awesome flood a year ago.</p>

	<p><a href='http://blog.iloaf.com/wp-content/uploads/2007/08/cpu_loadavg-daily.png' title='Load Average Last night'><img src='http://blog.iloaf.com/wp-content/uploads/2007/08/cpu_loadavg-daily.thumbnail.png' alt='Load Average Last night' /></a></p>

	<p>So this gave me an excellent opportunity to test out many mail servers sending me &#8216;ham&#8217; via the greylist service (set to accept after 40 seconds).  So here is a small random selection:</p>

	<p>X-Greylist: delayed 1107 seconds (postfix)<br />
X-Greylist: delayed 95 seconds (sendmail)<br />
X-Greylist: delayed 169 seconds (sendmail)<br />
X-Greylist: delayed 1295 seconds (postfix)<br />
X-Greylist: delayed 400 seconds (qmail)<br />
X-Greylist: delayed 1208 seconds (nplex)<br />
X-Greylist: delayed 1307 seconds (postfix)<br />
X-Greylist: delayed 400 seconds (qmail)<br />
X-Greylist: delayed 400 seconds (qmail &#8211; hmmm a pattern)<br />
X-Greylist: delayed 318 seconds (sendmail)<br />
X-Greylist: delayed 63 seconds (microsoft )<br />
X-Greylist: delayed 400 seconds (qmail)<br />
X-Greylist: delayed 62 seconds (unknown &#8211; suspect MS p0f gave &#8220;Windows 2000 <span class="caps">SP4</span>, XP <span class="caps">SP1</span>&#8221;)<br />
X-Greylist: delayed 400 seconds (qmail)<br />
X-Greylist: delayed 64 seconds (microsoft)<br />
X-Greylist: delayed 840 seconds (sendmail)<br />
X-Greylist: delayed 65 seconds (microsoft)<br />
X-Greylist: delayed 2353 second (postfix)<br />
X-Greylist: delayed 970 seconds (symantec)<br />
X-Greylist: delayed 2616 seconds (sendmail)<br />
X-Greylist: delayed 400 seconds (qmail)<br />
X-Greylist: delayed 162 seconds (unknown &#8211; Linux)<br />
X-Greylist: delayed 917 seconds (sendmail)<br />
X-Greylist: delayed 64 seconds (microsoft)<br />
X-Greylist: delayed 399 seconds (qmail)<br />
X-Greylist: delayed 363 seconds (postfix)<br />
X-Greylist: delayed 69 seconds (microsoft)<br />
X-Greylist: delayed 69 seconds (microsoft)<br />
X-Greylist: delayed 915 seconds (MS <span class="caps">IMS</span>)<br />
X-Greylist: delayed 395 seconds (qmail)<br />
X-Greylist: delayed 445 seconds (sendmail)</p>

	<p>So a revisit time of 580-620 seconds might be worth a spamassassin point or two.</p>

	<p>One observation that also caught my eye is that yahoo are sending a lot of user-unknown messages out of the <span class="caps">SMTP</span> session. Yahoo are whitelisted on postgrey and hence have no greylist header added (though I wish it would with the reasoning) so I caught a lot of their blow-back for user unknown errors. Thats just wrong Y! guys!</p>

 <div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fblog.iloaf.com%2F2007%2F08%2F04%2Fjobbed-again%2F&amp;title=Jobbed+again', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="http://s3.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.iloaf.com/2007/08/04/jobbed-again/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Botspam vs. Greylisting  -  1 : 0</title>
		<link>http://blog.iloaf.com/2007/07/15/botspam-vs-greylisting-1-0/</link>
		<comments>http://blog.iloaf.com/2007/07/15/botspam-vs-greylisting-1-0/#comments</comments>
		<pubDate>Sun, 15 Jul 2007 13:38:13 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
		
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://blog.iloaf.com/2007/07/15/botspam-vs-greylisting-1-0/</guid>
		<description><![CDATA[	With nothing better to do on a dull/hungover Sunday morning I thought I&#8217;d investigate a rumor I&#8217;d heard in the week regarding greylisting.
Now don&#8217;t get me wrong, I&#8217;m no fan of delaying email. I just want to see if what I&#8217;d heard was true&#8230;

I&#8217;m a bit of a tree-hugging Debian/postfix junkie so getting everything going [...]]]></description>
			<content:encoded><![CDATA[	<p>With nothing better to do on a dull/hungover Sunday morning I thought I&#8217;d investigate a rumor I&#8217;d heard in the week regarding <a href="http://projects.puremagic.com/greylisting/">greylisting</a>.<br />
Now don&#8217;t get me wrong, I&#8217;m no fan of delaying email. I just want to see if what I&#8217;d heard was true&#8230;</p>

I&#8217;m a bit of a tree-hugging Debian/postfix junkie so getting everything going was literally childs-play.
<a href="http://postgrey.schweikert.ch/">Postgrey</a> being the implementation of choice this time round and I had it running and tested in under 2 minutes.<pre>sudo apt-get install postgrey
</pre> Then a quick edit of postfix&#8217;s main.cf.

	<p>At this time I also reduced the timeout from 5 minutes to 40 seconds since all I&#8217;m interested in is if they come back at all.</p>

	<p>At the same time I deliberately turned off all rbl&#8217;s so that I&#8217;d get a big &#38; fair dataset on the trap server. Then all I had to do is sit and watch.</p>

	<p>Now of course this let through all the spam being sent via <span class="caps">ISP</span>&#8217;s relays but looking for direct sending bots running on <span class="caps">DSL</span>&#8217;s is pretty easy because they don&#8217;t have Wanadoo/Orange or Tiscali in the headers <img src='http://blog.iloaf.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> (only kidding).</p>

So after a quick cuppa I had the results I was expecting. Here are the log highlights:
<pre>X-Greylist: delayed 651 seconds by postgrey;  &lt;image /knob pills
X-Greylist: delayed 602 seconds by postgrey;  &lt;PDF
X-Greylist: delayed 602 seconds by postgrey;  &lt;Ecard
X-Greylist: delayed 605 seconds by postgrey;  &lt;Image/knob pills
X-Greylist: delayed 608 seconds by postgrey;  &lt;PDF
X-Greylist: delayed 604 seconds by postgrey;  &lt;Stock
X-Greylist: delayed 685 seconds by postgrey;  &lt;Ecard
X-Greylist: delayed 603 seconds by postgrey;  &lt;Stock
</pre>
These were all definitely dialup/dsl pools. The interesting thing is how long they all took to come back but nevertheless it shows that at least some bots are well wise to greylisting.
</image></pre>
 <div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fblog.iloaf.com%2F2007%2F07%2F15%2Fbotspam-vs-greylisting-1-0%2F&amp;title=Botspam+vs.+Greylisting++-++1+%3A+0', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="http://s3.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.iloaf.com/2007/07/15/botspam-vs-greylisting-1-0/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The worst place for spam?..Your bug tracker</title>
		<link>http://blog.iloaf.com/2007/05/04/the-worst-place-for-spamyour-bug-tracker/</link>
		<comments>http://blog.iloaf.com/2007/05/04/the-worst-place-for-spamyour-bug-tracker/#comments</comments>
		<pubDate>Fri, 04 May 2007 21:25:16 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
		
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://blog.iloaf.com/2007/05/04/the-worst-place-for-spamyour-bug-tracker/</guid>
		<description><![CDATA[	I was taking a look at lighthouse just now as a lightweight task tracker. Functional, attractive and tight email integration all looked good until I stumbled upon their spam problem.  Gah, that almost put me off.
 ]]></description>
			<content:encoded><![CDATA[	<p>I was taking a look at lighthouse just now as a lightweight task tracker. Functional, attractive and tight email integration all looked good until I stumbled upon their <a href="http://ar-code.lighthouseapp.com/projects/34/tickets/2-tag-help-for-designers-using-liquid#ticket-2-156">spam problem</a>.  Gah, that almost put me off.</p>
 <div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fblog.iloaf.com%2F2007%2F05%2F04%2Fthe-worst-place-for-spamyour-bug-tracker%2F&amp;title=The+worst+place+for+spam%3F..Your+bug+tracker', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="http://s3.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.iloaf.com/2007/05/04/the-worst-place-for-spamyour-bug-tracker/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Prank or scam?</title>
		<link>http://blog.iloaf.com/2007/03/09/prank-or-scam/</link>
		<comments>http://blog.iloaf.com/2007/03/09/prank-or-scam/#comments</comments>
		<pubDate>Fri, 09 Mar 2007 13:56:24 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
		
		<category><![CDATA[Spam]]></category>

		<category><![CDATA[~/]]></category>

		<guid isPermaLink="false">http://blog.iloaf.com/2007/03/09/prank-or-scam/</guid>
		<description><![CDATA[	&#8220;You&#8217;ve been spotted using your mobile phone whilst driving and you have been traced through your car registration&#8221;
The number to call is 07666000###. At the end of the call ~5minutes the message ends:
&#8220;You&#8217;ve been had, HA HA!!&#8221;

	Sounds like the usual prank calls but they usually involve a premium rate number, and that&#8217;s what got me [...]]]></description>
			<content:encoded><![CDATA[	<p>&#8220;You&#8217;ve been spotted using your mobile phone whilst driving and you have been traced through your car registration&#8221;<br />
The number to call is 07666000###. At the end of the call ~5minutes the message ends:<br />
&#8220;You&#8217;ve been had, <span class="caps">HA HA</span>!!&#8221;</p>

	<p>Sounds like the usual prank calls but they usually involve a premium rate number, and that&#8217;s what got me wondering, could this be the start of mobile <a href="http://www.didx.net/mobile/"><span class="caps">DID</span></a> scams?</p>
 <div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fblog.iloaf.com%2F2007%2F03%2F09%2Fprank-or-scam%2F&amp;title=Prank+or+scam%3F', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="http://s3.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.iloaf.com/2007/03/09/prank-or-scam/feed/</wfw:commentRss>
		</item>
		<item>
		<title>SPAM FREE or die!</title>
		<link>http://blog.iloaf.com/2007/02/07/spam-free-or-die/</link>
		<comments>http://blog.iloaf.com/2007/02/07/spam-free-or-die/#comments</comments>
		<pubDate>Wed, 07 Feb 2007 09:32:38 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
		
		<category><![CDATA[Spam]]></category>

		<category><![CDATA[~/]]></category>

		<guid isPermaLink="false">http://blog.iloaf.com/2007/02/07/spam-free-or-die/</guid>
		<description><![CDATA[	I know it&#8217;s old but I can&#8217;t resist a reminder of the Anti-Spam anthem. Enjoy!

 ]]></description>
			<content:encoded><![CDATA[	<p>I know it&#8217;s old but I can&#8217;t resist a reminder of the Anti-Spam anthem. Enjoy!<br />
<object width="425" height="350"><param name="movie" value="http://www.youtube.com/v/EnH1djvoaUE"></param><param name="wmode" value="transparent"></param><embed src="http://www.youtube.com/v/EnH1djvoaUE" type="application/x-shockwave-flash" wmode="transparent" width="425" height="350"></embed></object></p>
 <div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fblog.iloaf.com%2F2007%2F02%2F07%2Fspam-free-or-die%2F&amp;title=SPAM+FREE+or+die%21', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="http://s3.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.iloaf.com/2007/02/07/spam-free-or-die/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Fscked domain rule</title>
		<link>http://blog.iloaf.com/2007/01/25/fscked-domain-rule/</link>
		<comments>http://blog.iloaf.com/2007/01/25/fscked-domain-rule/#comments</comments>
		<pubDate>Thu, 25 Jan 2007 23:20:34 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
		
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://blog.iloaf.com/2007/01/25/fscked-domain-rule/</guid>
		<description><![CDATA[	So I&#8217;ve just read this bug (way too late I know..) and wondered why I think about these things a bit differently. Maybe it&#8217;s a good thing, maybe it&#8217;s bad but this has been killing the badsite*foo.tld spam since day 1 one for me, about 5 days now IIRC. The idea is that is spots [...]]]></description>
			<content:encoded><![CDATA[	<p>So I&#8217;ve just read <a href="http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5302" target="_new">this bug</a> (way too late I know..) and wondered why I think about these things a bit differently. Maybe it&#8217;s a good thing, maybe it&#8217;s bad but this has been killing the badsite*foo.tld spam since day 1 one for me, about 5 days now <span class="caps">IIRC</span>. The idea is that is spots any weirdness in a <span class="caps">URL</span> before the domain name terminator (or end of the string if one is not present).</p>

	<p><a href="/dump07/20_c_uri.cf" target="_new">Rule File</a>.</p>

	<p>Adjust your score as you see fit. It will FP on IDNs and such.</p>

	<p>Feel free to drop me your masses results for it in a comment.</p>
 <div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fblog.iloaf.com%2F2007%2F01%2F25%2Ffscked-domain-rule%2F&amp;title=Fscked+domain+rule', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="http://s3.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.iloaf.com/2007/01/25/fscked-domain-rule/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
