OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: image spam (and selective greylisting)

From: Ralf Hildebrandt (Ralf.Hildebrandtcharite.de)
Date: Sat Sep 02 2006 - 06:40:51 CDT


* Rich Wales <richwrichw.org>:

> > http://www.stahl.bau.tu-bs.de/~hildeb/postfix/postfix_greylisting.shtml
>
> I thought people might be interested in knowing that I was able to use
> this technique to eliminate almost all of the recent wave of image spam
> (the stuff with the presumably bogus stock market tips). I'm now using
> postgrey on incoming mail if (and only if) either the client's DNS name,
> or the name it supplies in the HELO command, has any of the following:
>
> ==> four or more periods
> ==> no periods at all (i.e., unqualified names, including "unknown")
> ==> four numbers in a row separated by periods
> ==> four numbers in a row separated by hyphens

Ah, that's good to hear. I installed the "fuzzyocr" plugin yesterday
to weed out the remaining image spam :)

> Additionally, I'm using the "--lookup-by-host" flag to postgrey, and I've
> also turned off auto-whitelisting (--auto-whitelist-clients=0).

Why would you turn off autowhitelisting?

--
Ralf Hildebrandt (Ralf.Hildebrandtcharite.de) spamtrapcharite.de
Postfix - Einrichtung, Betrieb und Wartung Tel. +49 (0)30-450 570-155
http://www.postfix-buch.com
"Plonk /excl./: The sound a newbie makes as he falls to the bottom of a
kill file." - From the Jargon File.