1. Advertising
    y u no do it?

    Advertising (learn more)

    Advertise virtually anything here, with CPM banner ads, CPM email ads and CPC contextual links. You can target relevant areas of the site and show ads based on geographical location of the user if you wish.

    Starts at just $1 per CPM or $0.10 per CPC.

Email spam explosion?

Discussion in 'General Chat' started by Owlcroft, May 28, 2004.

  1. #1
    I thought I had a bad situation when my overnight email totals--almost all spam--were between 500 and 1000. But just lately, say the last week or two, there seems to have been a virtual explosion in spam emails, to the point that now, being stuck (owing to being in a really rural area) with a 28.8K dialup, I can barely download email spam as fast as it arrives at the server. An overnight load (say 8 to 10 hours offline) is about 3,500 emails. By the time those are downloaded, there's another 800 or 900 waiting, and so it goes. We don't get "caught up" till late at night, when the incoming pace seems to slow materially.

    I wonder two things. One, have others seen such an explosion over the past, say 10 to 15 days? Or am I just lucky?

    Two, what can be done? My ISP offers an email filtering program, which I have in place set to the most stringent level available. (I shudder to think what volume I might see otherwise.) But custom filtering is really fairly simple. On my email software, I have filters set up such that very little of the scum (at least as a percentage) actually surfaces in any box but TRASH, and none of those filters is terribly sophisticated.

    My problem is that I don't know offhand how to filter without first downloading the emails in question, which is what takes all the time, and apparently the software at the ISP's end is not custom configurable.

    Any ideas?
     
    Owlcroft, May 28, 2004 IP
  2. candysmith

    candysmith trying not to be evil

    Messages:
    227
    Likes Received:
    13
    Best Answers:
    0
    Trophy Points:
    88
    #2
    I'm having the same problem and I'm in a differenct country. I was getting about 300 a day now its up to about 500. I really feel for you with 3,500 coming in, what a monumental waste of your time.
    Its the flippin drug sites, and there seems to be no way to unsubscribe from these things.
     
    candysmith, May 28, 2004 IP
  3. hexed

    hexed Peon

    Messages:
    333
    Likes Received:
    11
    Best Answers:
    0
    Trophy Points:
    0
    #3
    I used to get no spam emails until about 1 week ago. Now I get 10 a day and it's annoying the hell out of me.

    Go check out Inboxer or Mailwasher. Both are very good spam divertors.

    Also - A lot of these spammers are using what we call "alphabetical spamming". They spam hotmail or yahoo, rogers, etc, with every combination of username available. Even if 1 out of every 1000 hits, they still win.

    There's no way to unsuscribe even though they have a link to unsuscribe. If you put your email in there, the emails will get worse because you are in effect, telling them your email address is valid.


    hexed
     
    hexed, May 28, 2004 IP
  4. ViciousSummer

    ViciousSummer Ayn Rand for President! Staff

    Messages:
    3,210
    Likes Received:
    526
    Best Answers:
    0
    Trophy Points:
    308
    #4
    WOW! 10 a day? I wish! I'm up to about 300-500 a day. I can't use spam filters because my customer's emails occasionally get caught up in them. I honestly don't think there is much we can do to fight it at this point. Although, if I ever need Viagra or penis enlargement pills, I know where to go :rolleyes: !!
     
    ViciousSummer, May 28, 2004 IP
  5. digitalpoint

    digitalpoint Overlord of no one Staff

    Messages:
    38,334
    Likes Received:
    2,613
    Best Answers:
    462
    Trophy Points:
    710
    Digital Goods:
    29
    #5
    Well not only do I get the normal spam, I have some ass monkey using random emails within digitalpoint.com as the return address of his spam.

    The last 3 seconds of mail logs from my mail server:

    May 28 01:22:00 blink sendmail[4793]: i4S8Lxf04793: <Georgiaev@digitalpoint.com>... No such user here
    May 28 01:22:00 blink sendmail[4790]: i4S8Lxf04790: from=<MAILER-DAEMON@mail.feldkirch.net>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA, relay=194-208-067-012.TELE.NET [194.208.67.12]
    May 28 01:22:00 blink sendmail[4793]: i4S8Lxf04793: from=<>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA, relay=194-208-067-012.TELE.NET [194.208.67.12]
    May 28 01:22:00 blink sendmail[4794]: i4S8M0f04794: <Adrianafh@digitalpoint.com>... No such user here
    May 28 01:22:00 blink sendmail[4796]: i4S8M0f04796: <Adrianafh@digitalpoint.com>... No such user here
    May 28 01:22:00 blink sendmail[4795]: i4S8M0f04795: <Adrianafh@digitalpoint.com>... No such user here
    May 28 01:22:00 blink sendmail[4797]: i4S8M0f04797: <Adrianafh@digitalpoint.com>... No such user here
    May 28 01:22:00 blink sendmail[4794]: i4S8M0f04794: lost input channel from imail01.samsung.co.kr [203.254.197.71] to MTA after rcpt
    May 28 01:22:00 blink sendmail[4794]: i4S8M0f04794: from=<>, size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=imail01.samsung.co.kr [203.254.197.71]
    May 28 01:22:00 blink sendmail[4796]: i4S8M0f04796: lost input channel from imail01.samsung.co.kr [203.254.197.71] to MTA after rcpt
    May 28 01:22:00 blink sendmail[4796]: i4S8M0f04796: from=<>, size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=imail01.samsung.co.kr [203.254.197.71]
    May 28 01:22:00 blink sendmail[4795]: i4S8M0f04795: lost input channel from imail01.samsung.co.kr [203.254.197.71] to MTA after rcpt
    May 28 01:22:00 blink sendmail[4795]: i4S8M0f04795: from=<>, size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=imail01.samsung.co.kr [203.254.197.71]
    May 28 01:22:00 blink sendmail[4797]: i4S8M0f04797: lost input channel from imail01.samsung.co.kr [203.254.197.71] to MTA after rcpt
    May 28 01:22:00 blink sendmail[4797]: i4S8M0f04797: from=<>, size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=imail01.samsung.co.kr [203.254.197.71]
    May 28 01:22:00 blink sendmail[4798]: i4S8M0f04798: <Robinao@digitalpoint.com>... No such user here
    May 28 01:22:00 blink sendmail[4798]: i4S8M0f04798: from=<>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA, relay=194-208-067-012.TELE.NET [194.208.67.12]
    May 28 01:22:00 blink sendmail[4800]: i4S8M0f04800: <Juliettelku@digitalpoint.com>... No such user here
    May 28 01:22:00 blink sendmail[4800]: i4S8M0f04800: from=<>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA, relay=sc021pub.verizon.net [206.46.170.104]
    May 28 01:22:01 blink sendmail[4801]: i4S8M0f04801: <Juliettelku@digitalpoint.com>... No such user here
    May 28 01:22:01 blink sendmail[4801]: i4S8M0f04801: lost input channel from sc021pub.verizon.net [206.46.170.104] to MTA after rcpt
    May 28 01:22:01 blink sendmail[4801]: i4S8M0f04801: from=<antispam575868@west.verizon.net>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA, relay=sc021pub.verizon.net [206.46.170.104]
    May 28 01:22:01 blink sendmail[4804]: i4S8M1f04804: <RHASI@digitalpoint.com>... No such user here
    May 28 01:22:01 blink sendmail[4805]: i4S8M1f04805: <Alissarfn@digitalpoint.com>... No such user here
    May 28 01:22:01 blink sendmail[4805]: i4S8M1f04805: from=<>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA, relay=sc021pub.verizon.net [206.46.170.104]
    May 28 01:22:01 blink sendmail[4804]: i4S8M1f04804: from=<>, size=2205, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=204.60.171.28.ded.snet.net [204.60.171.28]
    May 28 01:22:01 blink sendmail[4807]: i4S8M1f04807: <Alissarfn@digitalpoint.com>... No such user here
    May 28 01:22:01 blink sendmail[4807]: i4S8M1f04807: lost input channel from sc021pub.verizon.net [206.46.170.104] to MTA after rcpt
    May 28 01:22:01 blink sendmail[4807]: i4S8M1f04807: from=<antispam575875@west.verizon.net>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA, relay=sc021pub.verizon.net [206.46.170.104]
    May 28 01:22:02 blink sendmail[4810]: i4S8M2f04810: <zvfmjijiuvj@digitalpoint.com>... No such user here
    May 28 01:22:02 blink sendmail[4810]: i4S8M2f04810: from=<>, size=4072, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=omr-m14.mx.aol.com [64.12.136.12]
    May 28 01:22:02 blink sendmail[4813]: i4S8M2f04813: <Georgiaev@digitalpoint.com>... No such user here
    May 28 01:22:02 blink sendmail[4816]: i4S8M2f04816: <Denaqn@digitalpoint.com>... No such user here
    May 28 01:22:02 blink sendmail[4816]: i4S8M2f04816: from=<>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA, relay=sc021pub.verizon.net [206.46.170.104]
    May 28 01:22:02 blink sendmail[4817]: i4S8M2f04817: <Denaqn@digitalpoint.com>... No such user here
    May 28 01:22:02 blink sendmail[4818]: i4S8M2f04818: <Elliottulr@digitalpoint.com>... No such user here
    May 28 01:22:02 blink sendmail[4813]: i4S8M2f04813: from=<>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA, relay=194-208-067-012.TELE.NET [194.208.67.12]
    May 28 01:22:02 blink sendmail[4817]: i4S8M2f04817: lost input channel from sc021pub.verizon.net [206.46.170.104] to MTA after rcpt
    May 28 01:22:02 blink sendmail[4817]: i4S8M2f04817: from=<antispam575879@west.verizon.net>, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA, relay=sc021pub.verizon.net [206.46.170.104]
    May 28 01:22:02 blink sendmail[4818]: i4S8M2f04818: from=<>, size=2896, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=Debian-exim@mail.supremeserver10.com [209.25.134.111]


    Just the bounces coming to my server. Been going on for 48 hours now. What a waste of bandwidth.
     
    digitalpoint, May 28, 2004 IP
  6. T0PS3O

    T0PS3O Feel Good PLC

    Messages:
    13,219
    Likes Received:
    777
    Best Answers:
    0
    Trophy Points:
    0
    #6
    I spent a whole day once opting out of each of these spam mails where they offered it. It actually worked as in I went down from approx 300 a day to literally just sub 10. Unfortunately, now after a few months it's rising rapidly again, now at about 50 a day. They seem to be triggered all mid day US time because we get them here in the UK all between 4 and 7 PM.
     
    T0PS3O, May 28, 2004 IP
  7. dkalweit

    dkalweit Well-Known Member

    Messages:
    520
    Likes Received:
    35
    Best Answers:
    0
    Trophy Points:
    150
    #7
    I have that happen all the time. Usually spamming russian addresses in my case...

    I personally use SpamBayes with Outlook, which filters out 700-800 junk mails each day. It rarely marks anything legitimate as spam, but I do regularly skim the subjects in the junk folder-- I usually just find things like Network Solutions confirmations in there(that are very much like the fake spam ones).


    --
    Derek
     
    dkalweit, May 28, 2004 IP
  8. Bernard

    Bernard Well-Known Member

    Messages:
    1,608
    Likes Received:
    107
    Best Answers:
    0
    Trophy Points:
    185
    #8
    I've been using G-Lock's SpamCombat to filter and purge spam on the server. Owlcroft, you might like to take a look as it will definitely decrease the amount of information you need to transfer in order to eliminate spam from your e-mail.

    You can custom configure white lists and black lists with text strings and regular expressions. It also has a Bayesian filter that learns what you consider spam as you use it.
     
    Bernard, May 28, 2004 IP
  9. debunked

    debunked Prominent Member

    Messages:
    7,298
    Likes Received:
    416
    Best Answers:
    0
    Trophy Points:
    310
    #9
    I love the spam program we have on our server, it puts most spam into a spam box and I can check it. So far the only thing that I wouldn't have wanted in their was a Findwhat.com newsletter, but I never get anything out of it anyways.

    Here is a copy of what I see when I look up SPAM in my spam box

    Spam detection software, running on the system "********.com", has
    identified this incoming email as possible spam. The original message
    has been attached to this so you can view it (if it isn't spam) or block
    similar future email. If you have any questions, see
    the administrator of that system for details.

    Content preview: Silver World respects your privacy. If you no longer
    wish to receive our 0ffers, please see the rem0val instructions below.
    Advertisement [...]

    Content analysis details: (5.1 points, 5.0 required)

    pts rule name description
    ---- ---------------------- --------------------------------------------------
    0.2 EXCUSE_14 BODY: Tells you how to stop further spam
    0.3 LOTS_OF_STUFF BODY: Thousands or millions of pics/movies/etc
    0.2 BAD_CREDIT BODY: Eliminate Bad Credit
    0.5 HTML_IMAGE_RATIO_10 BODY: HTML has a low ratio of text to image area
    0.1 HTML_TAG_EXISTS_TBODY BODY: HTML has "tbody" tag
    0.1 HTML_FONT_BIG BODY: HTML has a big font
    0.4 HTML_FONT_INVISIBLE BODY: HTML font color is same as background
    0.4 HTML_TAG_BALANCE_HTML BODY: HTML has unbalanced "html" tags
    0.0 HTML_MESSAGE BODY: HTML included in message
    0.1 HTML_FONTCOLOR_UNKNOWN BODY: HTML font color is unknown to us
    0.3 HTML_TAG_BALANCE_BODY BODY: HTML has unbalanced "body" tags
    0.1 HTML_60_70 BODY: Message is 60% to 70% HTML
    1.1 MAILTO_TO_SPAM_ADDR URI: Includes a link to a likely spammer email
    0.2 NORMAL_HTTP_TO_IP URI: Uses a dotted-decimal IP address in URL
    1.3 RCVD_IN_SBL RBL: Received via a relay in Spamhaus Block List
    [<http://www.********.org/SBL/sbl.lasso?query=SBL14875>]
    0.0 CLICK_BELOW Asks you to click below

    The original message was not completely plain text, and may be unsafe to
    open with some email clients; in particular, it may contain a virus,
    or confirm that your address can receive spam. If you wish to view
    it, it may be safer to save it to a file and open it with an editor.
     
    debunked, May 28, 2004 IP
  10. schlottke

    schlottke Peon

    Messages:
    2,185
    Likes Received:
    63
    Best Answers:
    0
    Trophy Points:
    0
    #10
    I redirect everything to my yahoo account from my website account and then back to another website account.

    Yahoo really does a great job of filtering the spam out.
     
    schlottke, May 28, 2004 IP
  11. Bernard

    Bernard Well-Known Member

    Messages:
    1,608
    Likes Received:
    107
    Best Answers:
    0
    Trophy Points:
    185
    #11
    schlottke, you must be kidding me. Yahoo appears to have gotten worse at filtering spam IMO. Did you pay for the upgraded service? The free service has been allowing more and more obvious spam into my inbox than ever before.
     
    Bernard, May 28, 2004 IP
  12. steve sardell

    steve sardell Peon

    Messages:
    19
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #12
    This morning I read that Postini reports 85% of the mail coming thru its system is spam. Also the NY spammer is getting a little time in the *big house* .The time is for ID theft not the fact he had sent millions of spam emails, but it is a stepin the right direction.
     
    steve sardell, May 28, 2004 IP
  13. T0PS3O

    T0PS3O Feel Good PLC

    Messages:
    13,219
    Likes Received:
    777
    Best Answers:
    0
    Trophy Points:
    0
    #13
    Just read this article by IMRG here: Spam Article 26th May
    indicating 70% of emails are spam and rising to 80% halfway 2004!

    I always wondered... Is sending millions of e-mails out really that lucrative? Are there still people reading it and buying the stuff they offer?
     
    T0PS3O, May 28, 2004 IP
  14. respree

    respree Peon

    Messages:
    33
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #14
    I got so sick of dealing with the spam that I recently dumped all my e-mail accounts. Even with good client spam filters, it wasted so much of my day.

    So I set up new ones and life is good again (at least for now). I know you're probably attached to the account you have now, but one needs to weight that attachment to the time that gets wasted everyday dealing with the spam. Anyway, that solution worked for me.
     
    respree, May 28, 2004 IP
  15. digitalpoint

    digitalpoint Overlord of no one Staff

    Messages:
    38,334
    Likes Received:
    2,613
    Best Answers:
    462
    Trophy Points:
    710
    Digital Goods:
    29
    #15
    Well, I got so sick of those suckers using fake digitalpoint.com addresses as their reply-to address, and my mail servers getting 20 bounces per second for the last 72 hours, that I decided I will take some of their bandwidth from them too. So I wrote a multi-threaded script for them (which is filling out their online form request for a mortgage quote at the rate of about 100 times per second). Letting them know it will continue as long as they use digitalpoint.com addresses in their spam. :)
     
    digitalpoint, May 28, 2004 IP
    T0PS3O likes this.
  16. Such Great Heights

    Such Great Heights Peon

    Messages:
    715
    Likes Received:
    19
    Best Answers:
    0
    Trophy Points:
    0
    #16
    NICE! :D

    Computer Nerds get digital revenge.â„¢

    Reminds me a little of the movie Hackers, where they make their enemy deceased, no credit, and all that. hehe. :cool:

    ---
    oh and keep us updated on what happens.
     
    Such Great Heights, May 28, 2004 IP
  17. Bernard

    Bernard Well-Known Member

    Messages:
    1,608
    Likes Received:
    107
    Best Answers:
    0
    Trophy Points:
    185
    #17
    Anyone can use the Hammer
     
    Bernard, May 28, 2004 IP
  18. digitalpoint

    digitalpoint Overlord of no one Staff

    Messages:
    38,334
    Likes Received:
    2,613
    Best Answers:
    462
    Trophy Points:
    710
    Digital Goods:
    29
    #18
    Didn't know about that... but mine is a pretty simple script. Needed to be able to do a POST rather than a GET, so not sure if it would work.

    Also, it spawns it's threads into independent processes (across multiple machines if I wanted to).

    I think these guys must be spamming 200M+ emails with bad digitalpoint.com emails as the reply to address, because I've received in excess of 1 million bounces coming to my mail server so far.
     
    digitalpoint, May 28, 2004 IP
  19. Owlcroft

    Owlcroft Peon

    Messages:
    645
    Likes Received:
    34
    Best Answers:
    0
    Trophy Points:
    0
    #19
    Ah, but their site front page contains the Five Deadly Words: "Works on all Windows platforms." This shop was, is, and for long will be 100% OS/2.

    Moreover, the irony is that I don't need advanced or sophisticated filtering, Bayesian or other. At my receiving end, a few elementary checks of simple header data--notably "To" and "Subject"--eliminate the vast majority of the scum. It's not being able to apply those simple checks before downloading that's the nut.

    I reckon that if I understood the email interface, I could write a little php script to periodically read my email's headers and delete the ofenders. I think pretty soon it's going to be email study time . . . .
     
    Owlcroft, May 28, 2004 IP
  20. dazzlindonna

    dazzlindonna Peon

    Messages:
    553
    Likes Received:
    21
    Best Answers:
    0
    Trophy Points:
    0
    #20
    wow, i didn't even realize os/2 still existed!
     
    dazzlindonna, May 28, 2004 IP