ietf-asrg
[Top] [All Lists]

RE: [Asrg] C/R - What people say

2003-05-13 17:53:11
From: "Eric Dean" <eric(_at_)purespeed(_dot_)com>

Well, I use a CR system and am subscribed to various mailing lists.  We use
the Sender header to exempt challenges.
...

How does that operate?  What Sender values garner exceptions, and why
won't more spammers use them if there are any?  Or by "exception,"
do you mean that the mail is immediately discarded unchallenged?

About 5% of the last 29,319 spam caught in my traps have Sender headers.
Some of the streams of spam follow all of the forms that I know of
for a mailing list.  Here is a sample from a stream that you should
recognize, since it's from the hard working entity that sometimes
calls itself "Drew Lanzetta":

    From: Spec Sheet <ssha(_at_)all(_dot_)at>
    To: vj(_at_)calcite(_dot_)rhyolite(_dot_)com
    Subject: Stockgroup Signs Licensing Agreement with Time Warner
    Date: Mon, 12 May 2003 13:56:33 -0700
    MIME-Version: 1.0
    Content-Type: text/html
    List-Unsubscribe: 
<mailto:leave-specsheet-html-a-634245P(_at_)financepages(_dot_)com>
    List-Subscribe: 
<mailto:subscribe-specsheet-html-a(_at_)financepages(_dot_)com>
    List-Owner: <mailto:owner-specsheet-html-a(_at_)financepages(_dot_)com>
    X-List-Host: Main site
    Reply-To: ssha(_at_)all(_dot_)at
    Sender: bounce-specsheet-html-a-634245(_at_)financepages(_dot_)com
    Message-Id: 
<LYRIS-634245-31612-2003(_dot_)05(_dot_)12-13(_dot_)56(_dot_)34--vj#calcite(_dot_)rhyolite(_dot_)com(_at_)fin
    ancepages.com>
    MIME-Version: 1.0
    Content-Type: text/html

Note that those headers are exactly as they appeared on the wire before
my MTA did anything to them, including adding a Received: header.

Well, "Drew Lanzetta" doesn't include List-ID header, and I don't see
any recent spam in my traps that does.  
However, there is plenty in NANAS.  See
http://groups.google.com/groups?q=+%22list-id%22+group%3A*abuse.sightings


Vernon Schryver    vjs(_at_)rhyolite(_dot_)com
_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg



<Prev in Thread] Current Thread [Next in Thread>