[Esd-l] Spam Filtering

John D. Hardin jhardin at impsec.org
Wed Jul 31 06:56:01 PDT 2002

On Wed, 31 Jul 2002, Peter Hanecak wrote:

> 	# some SPAM hase "To" filed set to addresses like
> 	# Undisclosed.Recipients at our.gateway.com so I know for 
> 	# sure that this is some "To" faking in progress and 
> 	# message is SPAM, scum or something along that line

Another 100% rule is a blank or missing To: header.

> 4) notorious junk senders are placed in sendmail's access file
> with "ERROR:550 Spammers are banned from our site" and (if that
> control is effective) messages from then are not delivered to me
> (and colegues) anymore

I've been thinking about this for a while: there are open relay lists
(ORBS), does anybody do a similar known-bulk-mailer-ipaddress service?
SPABS maybe?

 John Hardin KA7OHZ    ICQ#15735746    http://www.impsec.org/~jhardin/
 jhardin at impsec.org                        pgpk -a jhardin at impsec.org
  768: 0x41EA94F5 - A3 0C 5B C2 EF 0D 2C E5  E9 BF C8 33 A7 A9 CE 76 
 1024: 0xB8732E79 - 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
  ...the Fates notice those who buy chainsaws...
                                              -- www.darwinawards.com
   296 days until The Matrix Reloaded

More information about the esd-l mailing list