Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 4 of 4
  1. #1
    PbG
    PbG is offline
    Member PbG's Avatar
    Join Date
    Mar 2003
    Posts
    238

    Default 3 pointer for the Spammers

    Spammers have a new weapon against our SPAM controls. A script embedded in the header outputs an undesireable/filterable string eg: 1/2 price Viagr*a.

    I discovered this when I tested the message against the filter expecting it to fail on "Viag" in the subject. When it did not I doublechecked the subject in the header and realized they differ and/or produce different results depending on how it is being viewed.

    In the inbox it shows up as:

    1/2 price Viagr*a

    Viewing the header (see below) returns:

    Subject: =?ISO-8859-1?b?MS8yIHByaWNlIFZpYWdyKmE=?=

    Gotta admire the tenacity of the bastards . . .

    ========== Begin Forwarded Message ========
    Return-path: <gus@studiog39mw.uncensored-hosting.com>
    Envelope-to: gus@studiog39mw.uncensored-hosting.com
    Delivery-date: Thu, 15 Apr 2004 12:24:17 -0700
    Received: from gus by studiog39mw.uncensored-hosting.com with local-bsmtp (Exim 4.24)
    id 1BECT9-0000Fl-Uk
    for gus@studiog39mw.uncensored-hosting.com; Thu, 15 Apr 2004 12:24:17 -0700
    Received: from [217.88.218.169] (helo=tenbit.pl)
    by studiog39mw.uncensored-hosting.com with smtp (Exim 4.24)
    id 1BECT9-0000Ff-61
    for gus@photographybygus.com; Thu, 15 Apr 2004 12:24:15 -0700
    Subject: =?ISO-8859-1?b?MS8yIHByaWNlIFZpYWdyKmE=?=
    To: gus@photographybygus.com
    From: "Florine A. Hathaway" <florine.hathawaypc@xcelco.on.ca>
    Message-ID: <e66401c4231f$2e4c44c0$badb78ac@g8vvls3>
    Date: Thu, 15 Apr 2004 19:22:56 +0000
    MIME-Version: 1.0
    Content-Type: text/html
    Content-Transfer-Encoding: 8bit
    X-Spam-Checker-Version: SpamAssassin 2.63 (2004-01-11) on
    studiog39mw.uncensored-hosting.com
    X-Spam-Level: ******
    X-Spam-Status: No, hits=6.4 required=7.0 tests=HTML_60_70,HTML_IMAGE_ONLY_02,
    HTML_MESSAGE,MIME_HTML_NO_CHARSET,MIME_HTML_ONLY,RCVD_IN_DYNABLOCK,
    RCVD_IN_NJABL,RCVD_IN_NJABL_DIALUP,RCVD_IN_SORBS autolearn=no
    version=2.63


    ======== End Forwarded Message =========

  2. #2
    Member
    Join Date
    Oct 2003
    Posts
    1,020

    Default Re: 3 pointer for the Spammers

    Originally posted by PbG
    Gotta admire the tenacity of the bastards . . .
    heh

    Thanks for sharing.

  3. #3
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Well, it's nothing really new.

    If you are using spamassassin with MailScanner with bayes learning enabled, they rarely get through. Especially if you "learn" them manually.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  4. #4
    Staff Member Spearow's Avatar
    Join Date
    Mar 2004
    Location
    Sunnyvale, CA
    Posts
    15

    Default

    that's not a script embedded in anything, just a standard subject line in iso-8859-1...
    Es ist nicht leicht ein Gott zu sein.
    mike@cpanel.net

Similar Threads & Tags
Similar threads

  1. Apache 2.2.14 mod_isapi Dangling Pointer
    By javamorg in forum Security
    Replies: 1
    Last Post: 03-10-2010, 04:18 AM
  2. Pointer
    By jackal in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 02-12-2003, 06:16 PM
  3. Pointer email
    By sparek-3 in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 01-14-2003, 01:13 PM
  4. Pointer domains and email
    By sparek-3 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 12-17-2002, 11:13 AM
  5. Domain Pointer in Cpanel ? from where
    By aitn in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 03-28-2002, 07:35 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube