<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">

<channel>
	<title>pebkac thoughts &#187; spam</title>
	<atom:link href="http://pebkac.homelinux.net/category/spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://pebkac.homelinux.net</link>
	<description>ID=10T ERROR (tagline not found)</description>
	<lastBuildDate>Tue, 17 Nov 2009 17:47:39 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9-beta-1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/us/</creativeCommons:license>		<item>
		<title>email from the lord</title>
		<link>http://pebkac.homelinux.net/2008/06/14/email-from-the-lord/</link>
		<comments>http://pebkac.homelinux.net/2008/06/14/email-from-the-lord/#comments</comments>
		<pubDate>Sun, 15 Jun 2008 02:50:39 +0000</pubDate>
		<dc:creator>tarheelcoxn</dc:creator>
				<category><![CDATA[flickr]]></category>
		<category><![CDATA[ibiblio]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://pebkac.homelinux.net/2008/06/14/email-from-the-lord/</guid>
		<description><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=email+from+the+lord&amp;rft.aulast=Palmer&amp;rft.aufirst=Crist%C3%B3bal&amp;rft.subject=flickr&amp;rft.subject=ibiblio&amp;rft.subject=spam&amp;rft.source=pebkac+thoughts&amp;rft.date=2008-06-14&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://pebkac.homelinux.net/2008/06/14/email-from-the-lord/&amp;rft.language=English"></span>

The only autoreply from the joe-job of mirror@ibiblio that I found entertaining.
]]></description>
			<content:encoded><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=email+from+the+lord&amp;rft.aulast=Palmer&amp;rft.aufirst=Crist%C3%B3bal&amp;rft.subject=flickr&amp;rft.subject=ibiblio&amp;rft.subject=spam&amp;rft.source=pebkac+thoughts&amp;rft.date=2008-06-14&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://pebkac.homelinux.net/2008/06/14/email-from-the-lord/&amp;rft.language=English"></span>
<p><a href="http://www.flickr.com/photos/tarheelcoxn/2579555552/" title="email from the lord by tarheelcoxn, on Flickr"><img src="http://farm4.static.flickr.com/3271/2579555552_606dc2a8d2_o.png" width="537" height="259" alt="email from the lord" /></a></p>
<p>The only autoreply from the joe-job of mirror@ibiblio that I found entertaining.</p>
]]></content:encoded>
			<wfw:commentRss>http://pebkac.homelinux.net/2008/06/14/email-from-the-lord/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>stuck</title>
		<link>http://pebkac.homelinux.net/2008/04/29/stuck/</link>
		<comments>http://pebkac.homelinux.net/2008/04/29/stuck/#comments</comments>
		<pubDate>Tue, 29 Apr 2008 15:00:02 +0000</pubDate>
		<dc:creator>tarheelcoxn</dc:creator>
				<category><![CDATA[spam]]></category>
		<category><![CDATA[work/web]]></category>

		<guid isPermaLink="false">http://pebkac.homelinux.net/2008/04/29/stuck/</guid>
		<description><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=stuck&amp;rft.aulast=Palmer&amp;rft.aufirst=Crist%C3%B3bal&amp;rft.subject=spam&amp;rft.subject=work%2Fweb&amp;rft.source=pebkac+thoughts&amp;rft.date=2008-04-29&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://pebkac.homelinux.net/2008/04/29/stuck/&amp;rft.language=English"></span>
I&#8217;m stuck and I don&#8217;t have a good way out. I&#8217;ll paint the picture for you: I&#8217;m responsible for a mail server that handles mail for about 50 domains. We get joe jobbed pretty much constantly, and recently spammers have started picking on not-so-tech-savvy individuals who do their mail with us. Eg. &#8220;Poor User&#8221;&#60;p.user@example.net&#62; gets [...]]]></description>
			<content:encoded><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=stuck&amp;rft.aulast=Palmer&amp;rft.aufirst=Crist%C3%B3bal&amp;rft.subject=spam&amp;rft.subject=work%2Fweb&amp;rft.source=pebkac+thoughts&amp;rft.date=2008-04-29&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://pebkac.homelinux.net/2008/04/29/stuck/&amp;rft.language=English"></span>
<p>I&#8217;m stuck and I don&#8217;t have a good way out. I&#8217;ll paint the picture for you: I&#8217;m responsible for a mail server that handles mail for about 50 domains. We get <a href="http://en.wikipedia.org/wiki/Joe_job" title="wikipedia on Joe Job">joe jobbed</a> pretty much constantly, and recently spammers have started picking on not-so-tech-savvy individuals who do their mail with us. Eg. &#8220;Poor User&#8221;&lt;p.user@example.net&gt; gets inundated with bounces. Why?</p>
<ol>
<li>Spammer forges From: &#8220;Poor User&#8221; &lt;p.user@example.net&gt;</li>
<li>Spammer sends mail to a misconfigured MTA (not us).</li>
<li>misconfigured MTA accepts the forged mail, realizes the final To: address is invalid.</li>
<li>misconfigured MTA generates a <a href="http://en.wikipedia.org/wiki/Bounce_message" title="Delivery Status Notification">DSN</a> (Delivery Status Notification).</li>
<li>DSN goes to&#8221;Poor User&#8221; &lt;p.user@example.net&gt;.</li>
<li>Poor User files a ticket with me.</li>
</ol>
<p>Now, there are circumstances when the original recipient MTA of the spam is not &#8220;misconfigured&#8221; when it sends the DSN. Example: somebody has set up a mail alias, say joe.user@example.org (note .ORG instead of .NET here), that points to TriLUG mail address, but joe does something silly and kills the TriLUG address without notifying the example.org mail admin. Over the weekend, spam sent to the example.org address will generate bounces.</p>
<p>Anyway, part of the solution would seem to be deploying something like <a href="http://www.openspf.org/" title="Sender Policy Framework">SPF</a> or <a href="http://www.dkim.org/" title="DomainKeys Identified Mail">DKIM</a>. This would cut down on the number of servers that accept mail that claims to be from us but isn&#8217;t. Great! Let&#8217;s delpoy one of them! But&#8230;.</p>
<ol></ol>
<ul>
<li>Suddenly we&#8217;re forcing all our (hundreds of) active users to reconfigure their mail clients to use <em>us</em> when sending mail outbound with a From: that claims to be from our domain. That&#8217;s a big flood of tickets, given the number of MUAs that aren&#8217;t configured that way by default.</li>
<li>We don&#8217;t do DNS in-house. We&#8217;re dependent on $UNIVERSITY for DNS, and they&#8217;ve told me flatly they won&#8217;t do SPF or DKIM until they&#8217;ve finishd migrating to a new IPAM. Oh, and I&#8217;m the first person ever to have asked them about either.</li>
</ul>
<p>So I&#8217;m stuck. I&#8217;d welcome any suggestions that will help mitigate the problem. This is a bit of a pickle.</p>
]]></content:encoded>
			<wfw:commentRss>http://pebkac.homelinux.net/2008/04/29/stuck/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>aaaarrgh</title>
		<link>http://pebkac.homelinux.net/2008/04/22/aaaarrgh/</link>
		<comments>http://pebkac.homelinux.net/2008/04/22/aaaarrgh/#comments</comments>
		<pubDate>Wed, 23 Apr 2008 01:52:53 +0000</pubDate>
		<dc:creator>tarheelcoxn</dc:creator>
				<category><![CDATA[flickr]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://pebkac.homelinux.net/2008/04/22/aaaarrgh/</guid>
		<description><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=aaaarrgh&amp;rft.aulast=Palmer&amp;rft.aufirst=Crist%C3%B3bal&amp;rft.subject=flickr&amp;rft.subject=spam&amp;rft.source=pebkac+thoughts&amp;rft.date=2008-04-22&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://pebkac.homelinux.net/2008/04/22/aaaarrgh/&amp;rft.language=English"></span>

]]></description>
			<content:encoded><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=aaaarrgh&amp;rft.aulast=Palmer&amp;rft.aufirst=Crist%C3%B3bal&amp;rft.subject=flickr&amp;rft.subject=spam&amp;rft.source=pebkac+thoughts&amp;rft.date=2008-04-22&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://pebkac.homelinux.net/2008/04/22/aaaarrgh/&amp;rft.language=English"></span>
<p><a href="http://www.flickr.com/photos/tarheelcoxn/2435613908/" title="bad day by tarheelcoxn, on Flickr"><img src="http://farm3.static.flickr.com/2379/2435613908_709b5c52c0.jpg" alt="bad day" width="342" height="500" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://pebkac.homelinux.net/2008/04/22/aaaarrgh/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>when mail servers get angry</title>
		<link>http://pebkac.homelinux.net/2008/04/02/when-mail-servers-get-angry/</link>
		<comments>http://pebkac.homelinux.net/2008/04/02/when-mail-servers-get-angry/#comments</comments>
		<pubDate>Wed, 02 Apr 2008 05:04:13 +0000</pubDate>
		<dc:creator>tarheelcoxn</dc:creator>
				<category><![CDATA[ibiblio]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://pebkac.homelinux.net/2008/04/02/when-mail-servers-get-angry/</guid>
		<description><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=when+mail+servers+get+angry&amp;rft.aulast=Palmer&amp;rft.aufirst=Crist%C3%B3bal&amp;rft.subject=ibiblio&amp;rft.subject=spam&amp;rft.source=pebkac+thoughts&amp;rft.date=2008-04-02&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://pebkac.homelinux.net/2008/04/02/when-mail-servers-get-angry/&amp;rft.language=English"></span>
I had 403 messages in my inbox as of Tue,  1 Apr 2008 21:23:15 -0400 (EDT). I now have 3295. /var filled up and postfix got a bit unhappy about that. I had it fixed by 22:54, so theoretically we haven&#8217;t lost any legitimate mail, but boy did the floodgates open&#8230;. h8 spammers. We got [...]]]></description>
			<content:encoded><![CDATA[	
	<span class="Z3988" title="ctx_ver=Z39.88-2004&amp;rft_val_fmt=info%3Aofi%2Ffmt%3Akev%3Amtx%3Adc&amp;rfr_id=info%3Asid%2Focoins.info%3Agenerator&amp;rft.title=when+mail+servers+get+angry&amp;rft.aulast=Palmer&amp;rft.aufirst=Crist%C3%B3bal&amp;rft.subject=ibiblio&amp;rft.subject=spam&amp;rft.source=pebkac+thoughts&amp;rft.date=2008-04-02&amp;rft.type=blogPost&amp;rft.format=text&amp;rft.identifier=http://pebkac.homelinux.net/2008/04/02/when-mail-servers-get-angry/&amp;rft.language=English"></span>
<p>I had 403 messages in my inbox as of Tue,  1 Apr 2008 21:23:15 -0400 (EDT). I now have 3295. /var filled up and postfix got a bit unhappy about that. I had it fixed by 22:54, so theoretically we haven&#8217;t lost any legitimate mail, but boy did the floodgates open&#8230;. <a href="http://www.ibiblio.org/sysblog/?p=8" title="entry in ibiblio systems blog">h8 spammers</a>. We got absolutely hammered today. The mail log is already 235M again.</p>
]]></content:encoded>
			<wfw:commentRss>http://pebkac.homelinux.net/2008/04/02/when-mail-servers-get-angry/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
