[Top] [All Lists]

Re: No good spamming bastards are using new tricks to get by the filters

2003-01-20 11:09:10
On Mon, 20 Jan 2003 04:46:30 -0500 (EST), dman(_at_)nomotek(_dot_)com wrote:
=> Has anyone yet found a base-64-encoded *non-multipart*
=> message that wasn't spam? 
=>  :0:  # 021109 () base-64-encoded html head is shrouding more than charset
=>   * ^Content-Type:(.*\<)?text/(html|plain)
=>   * ^Content-Transfer-Encoding:(.*\<)?base64
=>   spammy
=> regularly grabs 20% of my spam and has not yet (in three months) 

        Unfortunately I have, but just one.  It's from an
ex-vendor (manufacturer) to one of my clients.  IMO, the vendor
technical staff have been intentionally ignorant of *all* email
related issues in the several years I had to handle their
incoming flow - very frustrating.

        This email was mailing list generated to a *registered*
user of theirs - I've *never* known them to spam, so please don't
misread this - this email was legal and legitimate.  Here's the
[edited] headers:

Received: from (HELO ( by
EDITED-OUT-SERVER with SMTP; 15 Jan 2003 18:14:02 -0000
Date: Wed, 15 Jan 2003 12:28:09 -0500
X-Priority: 1 (High)
Importance: High
From: EXAMPLE_Registered_Owner_Automailer(_at_)EXAMPLE(_dot_)com
Subject: Test Drive EXAMPLE, and You Could Win a Free EXAMPLE
X-MIMETrack: Serialize by Router on
DPS-US-MAIL/DigitalProcessingSystems(Release 6.0|September
    26, 2002) at 01/15/2003 01:14:02 PM
MIME-Version: 1.0
Content-type: text/plain; charset=UTF-8
Content-transfer-encoding: base64

        It hit my spam can.  Next time it comes thru, it will do
so again.  My base-64 text/plai filters are still in place.

        If someone can point me to a good URL explaining why
these folks shouldn't do this (you know a *third-party*
arms-length explanation), I'll pass it along.


        - Don

procmail mailing list