Announcement

Collapse
No announcement yet.

Deluged by spam

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    #61
    I got mine from Network Solutions. It's a domain validation certificate, so the common name on it is just rileyz.net. To avoid name mismatch errors, I don't use any www or smtp or imap prefixes -- everything simply points to the domain name.

    Comment


      #62
      Looks like I'll have to re-organise Apache; my PTR record and mail server already use plain samhobbs.co.uk.

      Don't say you told me so
      samhobbs.co.uk

      Comment


        #63
        Any good reason I shouldn't buy through a reseller like ssls.com (namecheap)?
        samhobbs.co.uk

        Comment


          #64
          Originally posted by Feathers McGraw View Post
          Don't say you told me so
          If one looks carefully, one will observe a KFN administrator, quietly and unobtrusively observing his minions as they toil to and fro. Yes, quietly and unobtrusively.

          Comment


            #65
            Originally posted by Feathers McGraw View Post
            Any good reason I shouldn't buy through a reseller like ssls.com (namecheap)?
            For reasons I cannot fathom or rationally explain, buying an identity from a reseller makes me squeamish.

            Comment


              #66
              Originally posted by SteveRiley View Post
              If one looks carefully, one will observe a KFN administrator, quietly and unobtrusively observing his minions as they toil to and fro. Yes, quietly and unobtrusively.
              That would be Snowhog, surely?

              samhobbs.co.uk

              Comment


                #67
                Originally posted by SteveRiley View Post
                For reasons I cannot fathom or rationally explain, buying an identity from a reseller makes me squeamish.
                I thought it might. I read somewhere that some people don't like it but I couldn't put my finger on why. If the signing process required them to see your private key that would make sense (because 2 parties seeing/storing it is worse than one) but it doesn't, so I'll probably use a reseller and save some cash.
                samhobbs.co.uk

                Comment


                  #68
                  Here's something you might find interesting...I got two emails today imitating fail2ban, sent by an external email server.

                  Here's the source for the email:

                  Code:
                  Return-Path: <fail2ban at samhobs.co.uk>
                  Delivered-To: <sam at samhobbs.co.uk>
                  Received: from samhobbs.co.uk
                  	by samhobbs (Dovecot) with LMTP id kZTaOIdcSlRQZwAA+i6E6g
                  	for <sam at samhobbs.co.uk>; Fri, 24 Oct 2014 15:04:55 +0100
                  Received: by samhobbs.co.uk (Postfix, from userid 119)
                  	id E5FD2140EDB; Fri, 24 Oct 2014 15:04:55 +0100 (BST)
                  X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on samhobbs
                  X-Spam-Level: *
                  X-Spam-Status: No, score=1.3 required=5.0 tests=RDNS_NONE autolearn=no
                  	autolearn_force=no version=3.4.0
                  Received: from marinescus.ro (unknown [92.86.115.232])
                  	by samhobbs.co.uk (Postfix) with ESMTP id 9EC3E1403CD
                  	for <root at samhobbs.co.uk>; Fri, 24 Oct 2014 15:04:55 +0100 (BST)
                  Received: by marinescus.ro (Postfix, from userid 0)
                  	id 15DD5C11A4; Fri, 24 Oct 2014 17:01:02 +0300 (EEST)
                  Subject: [Fail2Ban] Apache-301-DoS: started
                  Date: Fri, 24 Oct 2014 14:01:01 +0000
                  From: Fail2Ban <fail2ban at samhobs.co.uk>
                  To: root at samhobbs.co.uk
                  Message-Id: <20141024140444.15DD5C11A4@marinescus.ro>
                  
                  Hi,
                  
                  The jail Apache-301-DoS has been started successfully.
                  
                  Regards,
                  
                  Fail2Ban
                  This had me puzzled for a while before I realised what had happened. First thing I noticed/checked is that fail2ban hadn't actually restarted.

                  Then I noticed the incorrect spelling of my domain name "samhobs.co.uk" - this is an error in the action definition for a custom Fail2ban jail I wrote (specifically, the error was in "sender" for the sendmail-whois action, but the destination was spelled correctly). The error must have been copied and pasted from my tutorial into this person's configuration, they didn't change the details so that they are relevant to their domain, and now they send emails to my root user when they restart the jail.

                  It occurs to me that if you wanted to mess with someone this might be a good way to go about it, at a glance the email looked plausible.
                  samhobbs.co.uk

                  Comment


                    #69
                    Yeah, that's interesting. I'd recommend changing your tutorial to use a generic domain. example.com | .net | .org are reserved for this purpose. See RFC 2606.

                    Comment


                      #70
                      Yep, I think I'll do that. To date, I think I've done it about half of the time, apparently it's not uncommon to just copy and paste stuff straight over.
                      samhobbs.co.uk

                      Comment


                        #71
                        Originally posted by Feathers McGraw View Post
                        apparently it's not uncommon to just copy and paste stuff straight over.
                        Laziness is not uncommon, alas.

                        Comment


                          #72
                          Sorry to resurrect an old thread but I have just this moment received a spam e-mail from some "barrister" in Malaysia.
                          Code:
                          Return-Path: chamber_lewfirm@yahoo.com.my
                          Received: from nm19-vm6.bullet.mail.sg3.yahoo.com ([106.10.149.117]) by
                           mx-ha.gmx.net (mxgmxus003) with ESMTPS (Nemesis) id 0MOfTs-1YLNX22C86-00641k
                           for <davidharrison45@gmx.com>; Sat, 31 Jan 2015 14:07:47 +0100
                          DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com.my; s=s2048; t=1422709663; bh=EBzqNontsKdsiNC7hKYkXpZst6ZZ2wP95DoII9jxOO0=; h=Date:From:Reply-To:To:Subject:From:Subject; b=IHKi42GRbkQtFAK1fqllgLwu8XAtIC8n/4umSa30Dbkp3nLG2d5Bs5k+n2RAKLQTGnt4D45hneOlf2mla0WlGLNCM3AiMB03GYTYivAtgpTyg5cRytGJZ1Eqka4CSaFSljTh2hj4m5b65JWnyvugYYtxUvtk0he6fUxxm19Wz+riru3r/wxojSyoc15lF9Fy+QTWbFWkBqLjhUFGPkZHy/J9MS39hxYyiM2dQpbVY654oVdLvmSw647vHTw32WBWxQUKsTKR4VA55jeOLgy3p5Rc+0C5L4tYV25Wbcm7gj+cqJUn6XduPkSmICDDoEqwQkHyxPlocrh6prRiZ4H8Bg==
                          Received: from [106.10.166.127] by nm19.bullet.mail.sg3.yahoo.com with NNFMP; 31 Jan 2015 13:07:43 -0000
                          Received: from [106.10.150.23] by tm16.bullet.mail.sg3.yahoo.com with NNFMP; 31 Jan 2015 13:07:43 -0000
                          Received: from [127.0.0.1] by omp1024.mail.sg3.yahoo.com with NNFMP; 31 Jan 2015 13:07:43 -0000
                          X-Yahoo-Newman-Property: ymail-3
                          X-Yahoo-Newman-Id: 376792.92675.bm@omp1024.mail.sg3.yahoo.com
                          X-YMail-OSG: M3F7G.sVM1nqWX_8OARRbxYAP9IEe7r7JdlCaINhPvh7TIZg4wf_BWOJ2svf1eD
                           wpRFUusSyFvp3auA9sAxGbG_AUEYBtPra5nfVvXAXm3TDqwpU4Fsqy5bry6cFcijdQrtYBg9HvgG
                           Vyhlk8qRwmKlcRvsDzwGpSrmtyAVHWsRNcAkE1jL.nB.MSfXtUf.DIebVK.BZhgDR523qA_GpN1A
                           H8CjGVVAwBae_3foZX9GJSyP.1QkQv2anWOf86.Qv8F_UJufLWdx9tKzBzhalyZiYiXdYsuBn7H3
                           n70PYTivqpmfFwfffcWfYJ1_2I2C.o.7xpVqP_._XvWBqu47v6RDwbvIsqmu0TWLGmr2eYZ0mPPw
                           lS2QAETHPc60J6o.9jaOm8vkBR8vEDr8FEgwiO2g.KD4hqH81RDp3ZyR_Azkv1tEbh13Q1zzspoo
                           O7u95xqcmzeyuY2Md9b1n5Z6foZ.u5CjHhDiaDwlN6xlzawM.jF5mzSaQCiOW2nA1aS4-
                          Received: by 106.10.196.94; Sat, 31 Jan 2015 13:07:42 +0000 
                          Date: Sat, 31 Jan 2015 13:07:42 +0000 (UTC)
                          From: Barrister Zarinah Binti Ghazali <chamber_lewfirm@yahoo.com.my>
                          Reply-To: 
                          	Barrister Zarinah Binti Ghazali <barristerzarinah.ghazali@yandex.com>
                          To: "davidharrison45@gmx.com" <davidharrison45@gmx.com>
                          Message-ID: <59076231.142009.1422709662539.JavaMail.yahoo@mail.yahoo.com>
                          Subject: Attention.......David Harrison
                          MIME-Version: 1.0
                          Content-Type: multipart/alternative; 
                          	boundary="----=_Part_142008_810138120.1422709662536"
                          Content-Length: 5510
                          Envelope-To: <davidharrison45@gmx.com>
                          X-GMX-Antispam: 0 (Mail was not recognized as spam); Detail=V3;
                          X-GMX-Antivirus: 0 (no virus found)
                          X-UI-Filterresults: notjunk:1;V01:K0:C0/RuU652HE=:1vSpJNdC8dilnZTKb5/EvMFiXm
                           Hvdg7EuVgfCZpJADKXkfx2XkXYKMUU7EjekOpMcsxTmQmYiCX+pLIKQKy0ezeCmf8gAs7xYic
                           eukdR/x3monltTZ1WRsMTPWJRyoGxWlOume1cLoPTWAZd8OBnrrNq6qcr0nBYlLh/DeOy8eAu
                           lEIbKJRB/CF6VsBS5AXkOdUnqbqm4N+tZfpU6UJZKX6a9EQt0G8aXH+M8bBbtKgJ3dUOOu3WZ
                           j1BsPNSbq5C85muA2CeLHSrY7P5N9EoJ948Kw8rUYplu1CURL0xquj29uv5cJp6xpOrtYbVMI
                           XvXqPpv9Fa1K84CgcvNWdneFYEsnMGvms+3BBJExxpHo6lplcXjodPAtsvO8vP2Gc3hFhvK3m
                           wPKLd7gQGcsLd7jUYKhXgFnjwf/o4/S5z5SlBN3jHBuGCALgEwp35avZYN4wXFO4xcgflzEav
                           foRT3Iv6yFHXE36vXRjKpTw2Y3dvigLctx0xj4OnMONU8QltUEEj+dyf5faOYDWPinWq96K4A
                           2x6eafzFekz+8jeJbm62lC7dNniAu/DpcpsmmL1JMPJPyhiZgfzFFO9dRL40teWv1LWR0qvOh
                           efb3wxv1aq5TQUUbYSnEPuatVhCa8Os1mULrdCNlFN9gSQjnPv1XhB6zqkIBVKyqEjOFw9A5W
                           4ixjoKslztt2Dcw8BRpivMpesBlfvRbmrOMzBOcS5cQPNLiCE2Wo0gI3AKTCHPArULY2ggS+s
                           ChUl55sHeF2toCitc0EXXOIDSj0zquOuYSHGp1O2BWLCR/WU4s2aIl1i5N5EbvrWlFZgsrkXb
                           M4WmrDHhjT/vLQDhdYJI+PrqBN54e2BfbbwNj8L8QDYYYscz4Pb22X6LEV3xfZf4ctK+zvgK8
                           ZnIQCeZj9hucDLM3iYtDPaEt+TRx753u6Gca9Ju1omHZtIcDzdPKKBs57FN59OyZzL17On1fL
                           aq2WH0HNmAoF8MtOD3ApCmwcLR04/h3Ih7fAcSYEsjcF/ItiCRlZnJ19rORGyUwqtahAK/24J
                           9oAKCkhW4iT4FQJard4ncNxYcasH3ohxt/lQ7E3AY41mOF6UMp43t7MvuD55xvdLQhejxozYF
                           4Et/ZL8IsylLCSLyLSbz/U3TjvOKx5OOa2+YHkdkh0yE0R+8TOAE6dMcCLMabs0BwWnPSz+So
                           kJsXhaal+3IeuwUeSMuvgkCB0o8/Tqfeqqq9GpXWSHr/6nGQpadri8uRaHGln3zydFZNnidRa
                           ilcyjaZ6YdBJf3izPNpyrflMR1PfLWzvN2lkHSO+j7gRYv5dhEcqLGqQu0wPxU7xeS+ECGbFS
                           e3LiE21bgLGIVRqcIJJytwqrsw==
                          
                          ------=_Part_142008_810138120.1422709662536
                          Content-Type: text/plain; charset=UTF-8
                          Content-Transfer-Encoding: quoted-printable
                          Content of the e-mail is
                          Code:
                           
                          No. 3 (1st Floor) Jalan
                          Kemajuan Batu Gajah Seremban
                          Kuala Lumpur Malaysia.
                          
                          
                          Dear David Harrison.
                          
                          My name is Mrs. Zarinah Binti Ghazali, a legal practitioner with Bh Koh, Soong, Zarin & Partners. No. 3 1st Floor Jalan Kemajuan Batu Gajah Seremban Kuala Lumpur Malaysia.
                          
                          I saw your contact and profile and decided that you could cooperate with me in this proposition.
                          
                          I have a client by Name Mr. Abdul Albert Harrison, who was deceased in November, 2012, in Kuala Lumpur, Malaysia. I am contacting you because you have the same surname as my deceased client and I felt that you could help me in the distribution of funding that were left in my deceased client's bank account. This funding is closed to be declared UN-serviceable by the bank as there were no indicated next of kin or next of beneficiary of the funding in the bank account.
                          
                          The total amount of cash in the bank account of my deceased client is US$ 12.5 Million (Say, Twelve Million, Five Hundred Thousand United States dollars) The bank had issued to me a notification to contact the next of kin of my deceased client for either to re-activate the bank account or to make claim of beneficiary of the funding in the bank account, with a month surcharge of 6% to be deducted as an Escrow safe keeping fee of the bank account, so as to avoid the indefinite closure of the bank account. My proposition to you is to seek your consent, and to present your kind self as the next-of-kin and beneficiary of my deceased client since you have the same last name with him.
                          
                          This means that the proceeds of his bank account would be paid to you as his next of kin or the legitimate beneficiary. When the proceeds in his bank account are paid to you, we would share the proceeds on a mutually agreed-upon percentage of 55% to me and 45% to your kind self. All the legal documents to back up your claim as my client's next-of-kin would be provided from high court of Selangor Malaysia. The most important thing I would need is your honest co-operation in this proposition. This would be done under a legitimate arrangement that would protect you from any breach of the law.
                          
                          Contact me at once if you are interested, reply through my Personal email (barristerzarinah.ghazali@yandex.com)
                          
                          Regards,
                          Barrister Zarinah Binti Ghazali.
                          Even if it is genuine, which it isn't, then this "law professional" is trying to encourage me to break the law by fraudulently claiming that I am the next of kin.

                          The sad fact is though that some people will be gullible enough to fall for this type of scam.

                          Comment


                            #73
                            What? Dude, you're gonna be RICH!

                            Woohoo - new 'puters for everyone!

                            Please Read Me

                            Comment


                              #74
                              I've been getting some interesting ones recently, including "how to get pregnant just by reading this email", which would be quite impressive really.
                              samhobbs.co.uk

                              Comment


                                #75
                                Originally posted by oshunluvr View Post
                                What? Dude, you're gonna be RICH!

                                Woohoo - new 'puters for everyone!
                                Oh I wish!

                                Comment

                                Working...
                                X