Welcome, Guest. Please login or register.

Author Topic: AREXX fake  (Read 2410 times)

Description:

0 Members and 1 Guest are viewing this topic.

Offline CassTopic starter

  • Hero Member
  • *****
  • Join Date: Apr 2003
  • Posts: 826
  • Country: 00
    • Show only replies by Cass
AREXX fake
« on: April 15, 2004, 09:58:21 PM »
Is there any good AREXX script that fakes a returned mail to the spammer? Some kind of:
Quote

 ----- The following addresses had permanent fatal errors -----

    (reason: User unknown)


This is already part of a *nix mailer (I don't recall its name), and it would be nice to have something similar in Amiga, especially now that the SPAM rages all over the net.
________
Upskirt Car
« Last Edit: March 18, 2011, 10:20:11 PM by Cass »
"If we don't got it, you don't want it!"
 

Offline Piru

  • \' union select name,pwd--
  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 6946
    • Show only replies by Piru
    • http://www.iki.fi/sintonen/
Re: AREXX fake "Returned mail" for SPAM ?
« Reply #1 on: April 15, 2004, 11:36:06 PM »
You don't want to run such script.

The problem is that the faking is too easy to spot. It's trivial to tell that the reply was sent from real address or if it was real "user unknown" reply the mail server.

From this a competent spammer will know that there is a real recipiant at the other end. The only effective way to not get more spam is to delete the spam without any response (can be automated with for example spamassassin).

Responding with "user unknown" will only work if rigged at receiving mail server (that would send such messages normally, too).
 

Offline Doobrey

  • Hero Member
  • *****
  • Join Date: Oct 2002
  • Posts: 1876
    • Show only replies by Doobrey
    • http://www.doobreynet.co.uk
Re: AREXX fake "Returned mail" for SPAM ?
« Reply #2 on: April 16, 2004, 12:03:18 AM »
Never ever reply to spam.

 The from: and reply to: are often faked, so all you`ll end up doing is wasting your own bandwidth.
 Worse still,if the forged address is a real address belonging to an innocent user, you`ll end up wasting their  bandwidth too, and they might end up reporting you for sending spam..

 Just delete it from the server and forget about it.
On schedule, and suing
 

Offline CassTopic starter

  • Hero Member
  • *****
  • Join Date: Apr 2003
  • Posts: 826
  • Country: 00
    • Show only replies by Cass
Re: AREXX fake
« Reply #3 on: April 16, 2004, 12:13:55 AM »
I know Piru, and I really don't want to give them feedback, afterall this is what they're looking for.

But sending a mail to my POP server at an non-existant user, I get a "user unknown" notice, with all the needed info in the headers.
I thought that using this mail responce as a template and exchanging string variables (as the date, the sender's domain/address etc.) might do the work.
________
Xs750
« Last Edit: March 18, 2011, 10:20:32 PM by Cass »
"If we don't got it, you don't want it!"
 

Offline cecilia

  • Amiga Snob
  • Hero Member
  • *****
  • Join Date: Mar 2002
  • Posts: 4875
  • Country: 00
    • Show only replies by cecilia
    • http://cecilia.sawneybean.com/
Re: AREXX fake "Returned mail" for SPAM ?
« Reply #4 on: April 16, 2004, 12:59:44 AM »
spam the spammers

I place this link on one of my web pages of any site I happen to be making. this is so whatever spam robots are wandering the web looking for email will go there and find all sorts of fake emails which will bounce back to the spammers.

tee hee.
 :lol:
the no CARB diet- no Cheney, Ashcroft, Rumsfeld or Bush.
IFX CD Tutorial
 

Offline Piru

  • \' union select name,pwd--
  • Hero Member
  • *****
  • Join Date: Aug 2002
  • Posts: 6946
    • Show only replies by Piru
    • http://www.iki.fi/sintonen/
Re: AREXX fake "Returned mail" for SPAM ?
« Reply #5 on: April 16, 2004, 01:03:24 AM »
Quote
I thought that using this mail responce as a template and exchanging string variables (as the date, the sender's domain/address etc.) might do the work.

The idea is good (well if you ignore the fact that it generates even more useless&expensive traffic), but normal user can't do it. You need to control the mail server to generate authentic responses. If you run your own, you can do this, of course.
 

Offline dcr8520

  • Full Member
  • ***
  • Join Date: Mar 2002
  • Posts: 107
    • Show only replies by dcr8520
    • http://Amiga.SourceForge.net
Re: AREXX fake "Returned mail" for SPAM ?
« Reply #6 on: April 16, 2004, 05:33:09 AM »
I wrote such a script years ago, he does his job, creating a full faked msg
(mta + original msg + delivery status), and then connects to the same smtp
server the spamer used (if possible) to be a bit more faked... ;)

I used it for months, but finally I got frustrated due almost all spamers are
using inexistent email addresses.

I can send it to you, or if there are any interest I cna upload it somewhre,
I wrote it when I was learning arexx so do not expect something pro....

anyway, doing this is not recomended, aside if he is effective or no, you can
get very large spams and what you can obtain only is waste your bandwidth.



I recommend you to do a script like the follow (this is what Im using todays,
since the servers where I have accounts had some kind of spam filter):

that script should connect to all your pop3 servers to check all your emails
addresses, using STAT check if you have new emails,if any: loop through all msg
numbers using "TOP <#> 0", then the email headers are returned, now reading
line by line check if a "X-Spam" string match in a line and if so delete it.

something like:

Code: [Select]

....

do i=0 TO msgs
   
   send(&quot;TOP &quot;x&quot; 0&quot;);
   
   do until eof(smtp)
   
    ln = readln(smtp); quelofollen = 0;
   
    if pos(&quot;X-Spam-Flag: YES&quot;,ln)>0 | pos(&quot;X-Spam-Level: ****&quot;,ln)>0 then quelofollen = 1;
    else if word(ln,1)==&quot;X-Spam-Score:&quot; then do
   
     if left(strip(word(ln,2)),1)>2 then quelofollen = 1;
    end
    else if word(ln,1)==&quot;X-Spam-Warning:&quot; then do
   
     if strip(word(ln, words(ln)-1))>20 then quelofollen = 1;
    end
   
    if quelofollen == 1 then do
     
     send(&quot;DELE &quot;x); LEAVE;
     
    end
   
   end

end

.......



I think this is a good way to avoid spams, and you do not lost bandwidth
downloading the entire spam, also my script uses the amigados command 'say'
to let me know how many emails I have and how many spams was deleted on
intervals of 20 minutes, saving the subjects to a log in ram: in case
something goes wrong..

btw, I've not tested but seems YAM can do this.


regards.
 

Offline CassTopic starter

  • Hero Member
  • *****
  • Join Date: Apr 2003
  • Posts: 826
  • Country: 00
    • Show only replies by Cass
Re: AREXX fake
« Reply #7 on: April 16, 2004, 07:32:53 PM »
Nice job cecilia!!

For the time being I'm stuck with a plain local filter that deletes the "X-Spam-Flag YES" mails...

________
DRUG TEST
« Last Edit: March 18, 2011, 10:20:53 PM by Cass »
"If we don't got it, you don't want it!"
 

Offline cecilia

  • Amiga Snob
  • Hero Member
  • *****
  • Join Date: Mar 2002
  • Posts: 4875
  • Country: 00
    • Show only replies by cecilia
    • http://cecilia.sawneybean.com/
Re: AREXX fake "Returned mail" for SPAM ?
« Reply #8 on: April 16, 2004, 07:38:39 PM »
Quote

Cass wrote:
Nice job cecilia!!

For the time being I'm stuck with a plain local filter that deletes the "X-Spam-Flag YES" mails...
well, if you go on that site there seems to be various strategies one can use.
One I use for sites is to use a certain code to display email so robots can't decode it and use it.

I get little spam, so it seems to be working. If i find a page showing this code I'll post it. (i downloaded it so i don't have the link).
the no CARB diet- no Cheney, Ashcroft, Rumsfeld or Bush.
IFX CD Tutorial