9fans - fans of the OS Plan 9 from Bell Labs
 help / color / mirror / Atom feed
* [9fans] wierd spam
@ 2007-11-26 22:08 erik quanstrom
  2007-11-26 22:14 ` William Josephson
  2007-11-28  3:18 ` sqweek
  0 siblings, 2 replies; 5+ messages in thread
From: erik quanstrom @ 2007-11-26 22:08 UTC (permalink / raw)
  To: 9fans

i noticed some bizarre spam sent to these addresses

rb2 Nov 26 16:58:02 Disallowed mx.coraid.com!postmaster (mx.coraid.com/65.14.39.130) to blocked name coraid.com!060008d17dc9d5acc8afc6045f4e68fc
rb2 Nov 26 16:58:23 ehlo from 65.14.39.130 as barracuda.coraid.com
rb2 Nov 26 16:58:23 Disallowed mx.coraid.com!postmaster (mx.coraid.com/65.14.39.130) to blocked name coraid.com!09f65e2191201eb38304af55f15ad810

a quick google of them shows 060008d17dc9d5acc8afc6045f4e68fc and
09f65e2191201eb38304af55f15ad810 to be message ids from email i sent
to the list in july.

does anyone know what the exploit here is?
some sort of outlook thing?

- erik


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [9fans] wierd spam
  2007-11-26 22:08 [9fans] wierd spam erik quanstrom
@ 2007-11-26 22:14 ` William Josephson
  2007-11-26 22:24   ` erik quanstrom
  2007-11-26 23:24   ` Lyndon Nerenberg
  2007-11-28  3:18 ` sqweek
  1 sibling, 2 replies; 5+ messages in thread
From: William Josephson @ 2007-11-26 22:14 UTC (permalink / raw)
  To: Fans of the OS Plan 9 from Bell Labs

On Mon, Nov 26, 2007 at 05:08:55PM -0500, erik quanstrom wrote:
> does anyone know what the exploit here is?
> some sort of outlook thing?

Probably some spammer mistaking message IDs like
<5a07215f3e7e896f4b528a1838e78757@quanstro.net>
for addresses.


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [9fans] wierd spam
  2007-11-26 22:14 ` William Josephson
@ 2007-11-26 22:24   ` erik quanstrom
  2007-11-26 23:24   ` Lyndon Nerenberg
  1 sibling, 0 replies; 5+ messages in thread
From: erik quanstrom @ 2007-11-26 22:24 UTC (permalink / raw)
  To: 9fans

now that you mention it, it's pretty obvious.
for some reason i was hung up on the fact that
one would think Message-ID: would be a clue that
this is not an email address.

- erik

On Mon Nov 26 17:20:31 EST 2007, jkw@eecs.harvard.edu wrote:
> On Mon, Nov 26, 2007 at 05:08:55PM -0500, erik quanstrom wrote:
> > does anyone know what the exploit here is?
> > some sort of outlook thing?
> 
> Probably some spammer mistaking message IDs like
> <5a07215f3e7e896f4b528a1838e78757@quanstro.net>
> for addresses.


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [9fans] wierd spam
  2007-11-26 22:14 ` William Josephson
  2007-11-26 22:24   ` erik quanstrom
@ 2007-11-26 23:24   ` Lyndon Nerenberg
  1 sibling, 0 replies; 5+ messages in thread
From: Lyndon Nerenberg @ 2007-11-26 23:24 UTC (permalink / raw)
  To: Fans of the OS Plan 9 from Bell Labs

On 2007-Nov-26, at 14:14 , William Josephson wrote:

> Probably some spammer mistaking message IDs like
> <5a07215f3e7e896f4b528a1838e78757@quanstro.net>
> for addresses.

Makes sense.  The address harvesters are pretty stupid.  E.g., I use  
plus-detail addresses on my internet draft submissions, and regularly  
see spam sent to rfc-crammd5@orthanc.ca as a result of harvesters not  
parsing lyndon+rfc-crammd5@orthanc.ca correctly.

I'm slowly moving my mailing list subscriptions over to lyndon+@orthanc.ca 
, to take advantage of the spammers lack of RE-fu :-)  Sadly, there is  
still quite a bit of list management software that also doesn't grok  
full RFC[2]822 address syntax.

While the '+' hack helps circumvent the harvesting, bayesian filters  
are your only practical defense.

--lyndon


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [9fans] wierd spam
  2007-11-26 22:08 [9fans] wierd spam erik quanstrom
  2007-11-26 22:14 ` William Josephson
@ 2007-11-28  3:18 ` sqweek
  1 sibling, 0 replies; 5+ messages in thread
From: sqweek @ 2007-11-28  3:18 UTC (permalink / raw)
  To: Fans of the OS Plan 9 from Bell Labs

On Nov 27, 2007 7:08 AM, erik quanstrom <quanstro@quanstro.net> wrote:
> i noticed some bizarre spam sent to these addresses

 Speaking of weird email:
http://9fans.net/archive/2007/11/803
http://9fans.net/archive/2007/11/804
http://9fans.net/archive/2007/11/847
-sqweek


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2007-11-28  3:18 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2007-11-26 22:08 [9fans] wierd spam erik quanstrom
2007-11-26 22:14 ` William Josephson
2007-11-26 22:24   ` erik quanstrom
2007-11-26 23:24   ` Lyndon Nerenberg
2007-11-28  3:18 ` sqweek

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).