General fitness, health and nutrition · Public discussion

spammers?

Started by Guy · · Last activity · 80 posts · 2,185 views

Thread navigation

Jump through the discussion

Go to the original post, the replies on this page, or the latest preserved contribution.

Thread details

What we know about this thread

Original section
General fitness, health and nutrition
Published
1 February 2004
Last activity
11 February 2004
Original author
Guy
Posts
80
Discussion status
Public discussion
Total views
2,185
Views / 30 days
0

The navigation and discussion metadata provide context. Posts remain in their original chronological order.

Showing posts 1–20 of 80
Posts remain in their original chronological order.

Text size
  1. It seems some spammers lack a conscience and probably lack a soul. They worship the buck. If you are
    smart you will ignore them. Let them waste their time. They think they are very smart and you are
    stupid. Just be positive and you will take the bait.

    They have no concern for diabetics or any other sick person. The internet is a no cost
    advertising media.

    I remember a Nazi spokesman that was reported to have said---if you tell a lie often enough people
    will finally believe it.

  2. Guy <[email hidden]> wrote in misc.health.diabetes:

    Quoted message said:

    They think they are very smart and you are stupid.

    We are. And that's the problem. On average one out of every 1,000,000 spam mails gives them
    a positive

    out of 6 spam mails.

    As long as there are twits responding to spam mail, it's here to stay.

    Quoted message said:

    Just be positive and you will take the bait.

    Prevent them from sending it to you. I find it staggering - given the knowledge that spambots
    harvest both the web and Usenet 24/7 for e-mail addresses or domain names- people here _still_ use
    their full e-mail addresses without any restriction or precaution. With that knowledge it's by now
    close to _solliciting_ for spam.

    Insertions like NOSPAM and the likes aren't much use anymore. Spammers are not resting on their bums
    waiting for the money to come in.

    Get a free anonymous webmail account you can easily discard after it's spammed to the bottom, or use
    a non-existent address.

    Get a virusscanner and update it regularly, and get a firewall program to prevent spammers to hack
    your PC and spread their filth that way.

    --
    CeeBee

    "I am not a crook"

  3. CeeBee said:

    Prevent them from sending it to you. I find it staggering - given the knowledge that spambots
    harvest both the web and Usenet 24/7 for e-mail addresses or domain names- people here still use
    their full e-mail addresses without any restriction or precaution. With that knowledge it's by now
    close to solliciting for spam.

    Hi CB,

    I have Earthlink challenge-response on my j-dumas account. Nothing gets through since I started
    using it last June. I get a report daily of challenged emails and none seem to come from this
    no.SPAM!, (the !bang hoses up sendmail big-time and it nevers gets on the net to waste bandwidth),
    mangled address I use here. The challenged emails are the ones that get through Norton AV on
    Earthlink, then they must get through BrightMail spam filters and _then_ they are challenged for a
    human response. So if no ticket, no laundry, and it gets deleted after 14 days.

    Also note that text filters spammers use can never know if no.mindspring.com is a bad email address.
    So these filters can never have the smarts to say no. is not a legal addition to the address. They
    can find the SPAM and maybe the bang !, but they'll need a human to decide if no. is bad. This is
    too much work for them and they can't get through without more hassles from the challenge-response
    afterwards. So spam is dead for me.

    In any case, Earthlink has an effective despamming system,
    --
    Jim Dumas T1 4/86, background retinopathy, rarely hypoglycemic: <1/mo. lispro+R+U+NPH daily,
    moderate exercise, typically <6% HbA1c

  4. I have many safeguards and monitoring equipment. I have one e-mail account that has never been used
    My equipment stopped 30 spams to it saturday. I am glad they are costing providers and software
    manufacturer money. Some steps will be taken. I lock out most interrogations. My open account fares
    as well as the hidden ones.

    Spammer that come here are the ones I do not like. Lazy bums are looking for hits on people that
    have diabetes and are easy marks.

    I have good blocks on outgoing mail but I am getting "returns" that someone is faking my address. I
    am not sending e-mails now and I see none going out except responses to a legit items.. Guy

    Jim Dumas !mindspring.com said:
    CeeBee said:

    Prevent them from sending it to you. I find it staggering - given the knowledge that spambots
    harvest both the web and Usenet 24/7 for e-mail addresses or domain names- people here still use
    their full e-mail addresses without any restriction or precaution. With that knowledge it's by
    now close to solliciting for spam.

    Hi CB,

    I have Earthlink challenge-response on my j-dumas account. Nothing gets through since I started
    using it last June. I get a report daily of challenged emails and none seem to come from this
    no.SPAM!, (the !bang hoses up sendmail big-time and it nevers gets on the net to waste bandwidth),
    mangled address I use here. The challenged emails are the ones that get through Norton AV on
    Earthlink, then they must get through BrightMail spam filters and _then_ they are challenged for a
    human response. So if no ticket, no laundry, and it gets deleted after 14 days.

    Also note that text filters spammers use can never know if no.mindspring.com is a bad email
    address. So these filters can never have the smarts to say no. is not a legal addition to the
    address. They can find the SPAM and maybe the bang !, but they'll need a human to decide if no. is
    bad. This is too much work for them and they can't get through without more hassles from the challenge-
    response afterwards. So spam is dead for me.

    In any case, Earthlink has an effective despamming system,

  5. Guy said:

    I have many safeguards and monitoring equipment. I have one e-mail account that has never been
    used My equipment stopped 30 spams to it saturday. I am glad they are costing providers and
    software manufacturer money. Some steps will be taken. I lock out most interrogations. My open
    account fares as well as the hidden ones.

    The Earthlink method of using Earthlink computers to check for worms/viruses, then check for known
    spam with BrightMail, has the advantage of keeping most of the garbage off my equipment from the get-
    go. (So if I'm on the road with 56k modem, this [censored] never wastes my download time.)

    But when you first set up an Earthlink account, all tools are turned off. So you have to go online
    to your email accounts and turn on Norton AV for each one. Then turn on the BrightMail first layer
    of known spam filters. The next tier of challenge-response requires an online addressbook of good
    email and domain name (company name) addresses. This requires some work to set up. But once done it
    is easy to maintain and is almost 100% effective at preventing spam. (None have gotten through yet
    for me on 7 email addresses.)

    I also get large amounts of bounced emails on my dumas accounts, (earthlink and mindspring). But I
    didn't sent them of course. So I have a special spam filter I wrote in Perl to pull these from the
    server before my email client downloads the good emails. Then I take a quick look to see which
    spammer sent them and then delete the log file. So it's a minor problem.

    Next, I think it's important to post with my mangled real email address, as a good faith gesture of
    honesty. I'm not looking for trouble by using an alias to flame-war-harden my identity. If anybody
    wants to email me, they can with some effort to get through the challenge-response test.
    Surprisingly, nobody has harassed me with the exception of some vitamin spammer that got my address
    before I mangled it 2-3 years ago. This one gets caught in the challenge-response and to date this
    spammer has never responded to the challenge. So this spammer's [censored] is all automated and gets none
    of my attention. I could also put it in an online block list. But haven't to date, as I want to see
    if I do get a response from the challenge.

    Finally, I post to news groups with my dumas at earthlink.net account. So people like Dr Jay, that
    have access to news group trace data, can look this address up. But this email address is
    deliberately set to bounce all incoming. The mailbox is full by design. The previous owner already
    burned this address, so I decided to use it constructively with: "Sorry. You got the wrong number.
    Try again when Hell freezes over."

    It also gives the spammers something to do,
    --
    Jim Dumas T1 4/86, background retinopathy, rarely hypoglycemic: <1/mo. lispro+R+U+NPH daily,
    moderate exercise, typically <6% HbA1c

  6. On Sun, 01 Feb 2004 06:18:00 GMT, Jim Dumas

    !mindspring.com said:
    Guy said:

    I have many safeguards and monitoring equipment. I have one e-mail account that has never been
    used My equipment stopped 30 spams to it saturday. I am glad they are costing providers and
    software manufacturer money. Some steps will be taken. I lock out most interrogations. My open
    account fares as well as the hidden ones.

    The Earthlink method of using Earthlink computers to check for worms/viruses, then check for known
    spam with BrightMail, has the advantage of keeping most of the garbage off my equipment from the
    get-go. (So if I'm on the road with 56k modem, this [censored] never wastes my download time.)

    But when you first set up an Earthlink account, all tools are turned off. So you have to go online
    to your email accounts and turn on Norton AV for each one. Then turn on the BrightMail first layer
    of known spam filters. The next tier of challenge-response requires an online addressbook of good
    email and domain name (company name) addresses. This requires some work to set up. But once done it
    is easy to maintain and is almost 100% effective at preventing spam. (None have gotten through yet
    for me on 7 email addresses.)

    I also get large amounts of bounced emails on my dumas accounts, (earthlink and mindspring). But I
    didn't sent them of course. So I have a special spam filter I wrote in Perl to pull these from the
    server before my email client downloads the good emails. Then I take a quick look to see which
    spammer sent them and then delete the log file. So it's a minor problem.

    Next, I think it's important to post with my mangled real email address, as a good faith gesture of
    honesty. I'm not looking for trouble by using an alias to flame-war-harden my identity. If anybody
    wants to email me, they can with some effort to get through the challenge-response test.
    Surprisingly, nobody has harassed me with the exception of some vitamin spammer that got my address
    before I mangled it 2-3 years ago. This one gets caught in the challenge-response and to date this
    spammer has never responded to the challenge. So this spammer's [censored] is all automated and gets none
    of my attention. I could also put it in an online block list. But haven't to date, as I want to see
    if I do get a response from the challenge.

    Finally, I post to news groups with my dumas at earthlink.net account. So people like Dr Jay, that
    have access to news group trace data, can look this address up. But this email address is
    deliberately set to bounce all incoming. The mailbox is full by design. The previous owner already
    burned this address, so I decided to use it constructively with: "Sorry. You got the wrong number.
    Try again when Hell freezes over."

    It also gives the spammers something to do,

    Jim, some time back when thing got hot and heavy here I had attempted hacks for a week or two.
    I have some protection I prefer not to identify. Hacker are learning to get past some well
    known software.

    I only get a tally on spam and virus inputs. However very recently they have penetrated a system
    external to my computer Looks like they are scanning possibilities and setting headers to bypass
    some spam software.

    In any case I have provisions to cleanup in a few minutes. I do not use a business system to come to
    the groups or for e-mail. Too risky unless you encode everything.

    Actually commercial operations are the biggest problem when they slow a system down gathering data.

    Using less well known software may be better if you have the energy to set it up. Guy

  7. Guy said:

    I only get a tally on spam and virus inputs. However very recently they have penetrated a system
    external to my computer Looks like they are scanning possibilities and setting headers to bypass
    some spam software.

    In any case I have provisions to cleanup in a few minutes. I do not use a business system to come
    to the groups or for e-mail. Too risky unless you encode everything.

    In the old MSDOS days, there was a virus checker called "InVircible" written in Israel. It created
    CRCs (Cyclic Redundancy Checks used for error tests) for all executable files on the system. Then
    checked these executables for changes each time the system was booted. Any new files were
    indentified with a prompt asking if they were OK to add to the CRC lists. If some trojan horse like
    MyDOOM left an exec file, it would be found quickly and deleted.

    Linux has finally got a similar tool called AIDE, Advanced Intrusion Detection Environment. It uses
    MD5 and others then cross-checks all error tests just in case the hacker has modified a trojan to
    keep the same MD5 signature. All this data is saved in an mySQL database and moved to a CDROM rescue
    system so you can check using a known good database copy. It sends GPG encrypted emails to system
    administrators when a problem is found. Pretty slick and free, of course. I'm just starting to work
    with it. But it was set up for a Debian Linux system and I'm having trouble getting it to work on my
    Red Hat 8.0 system (cryptography problem on this laptop). So have to dig into it deeper. But it is
    impressive. Last November, crackers broke into the Debian servers (with snooped passwords) and were
    found within two days with AIDE. So they had done little damage before going offline for repairs.

    I have mag tape backup and can recover (bare metal restore) in two hours. So I can recover
    quickly too.

    In any case, the anti-cracker tools are getting better,
    --
    Jim Dumas T1 4/86, background retinopathy, rarely hypoglycemic: <1/mo. lispro+R+U+NPH daily,
    moderate exercise, typically <6% HbA1c

  8. 1-800-new-and-improved-preferred-special-offers abound

    "Guy" <[email hidden]> wrote in message "]news:[email hidden]...

    Quoted message said:


    It seems some spammers lack a conscience and probably lack a soul. They worship the buck. If you
    are smart you will ignore them. Let them waste their time. They think they are very smart and you
    are stupid. Just be positive and you will take the bait.

    They have no concern for diabetics or any other sick person. The internet is a no cost
    advertising media.

    I remember a Nazi spokesman that was reported to have said---if you tell a lie often enough people
    will finally believe it.

  9. CeeBee said:

    Insertions like NOSPAM and the likes aren't much use anymore. Spammers are not resting on their
    bums waiting for the money to come in.

    But how stupid can they be to expect a sale by working that hard to get their [censored] to someone who
    worked that hard to avoid it?

    I no longer depend on munging--I set up my own filters on the server, and have one at this end for
    the ones that slip past.

  10. Jim Dumas said:

    I have Earthlink challenge-response on my j-dumas account. Nothing gets

    Problem with challenge-response is that it magnifies the abuse of the network. Spam and virus loads
    down the wires. Response queries either dump on the poor guy whose address was picked by the virus,
    or generate a load of bounce messages when a spammer has used a non-existent address.

    Far better to use methods that discard the stuff.

    Be assured that there are plenty of people with enough free time and spam-hatred to track down where
    the stuff is really coming from and get accounts closed.

  11. Guy said:

    protection I prefer not to identify. Hacker are learning to get past some well known software.

    I only get a tally on spam and virus inputs. However very recently they have penetrated a system
    external to my computer Looks like they are scanning possibilities and setting headers to bypass
    some spam software.

    I use a Bayesian classifier called spamprobe. It's not the best of that type, but it was easy to set
    up. Once in a while, I look at a spam. It surprises me the lengths the spammers go to attempt to
    fool this kind of tool. For example, a lot of them put in hundreds of lines of random words from the
    dictionary. Suppose a potential victim reads the sales pitch. Is the spammer really stupid enough to
    think that four pages of gibberish will make him look like an honest merchant? One guy tried to get
    in by appending three unrelated Bible verses. Neither technique has ever fooled the classifier.

  12. Wes Groleau <[email hidden]> wrote in misc.health.diabetes:

    Quoted message said:

    But how stupid can they be to expect a sale by working that hard to get their [censored] to someone who
    worked that hard to avoid it?

    As I said already up this thread:

    Quoted message said:

    CeeBee <[email hidden]> wrote in misc.health.diabetes:

    Quoted message said:

    On average one out of every 1,000,000 spam mails gives them a

    Quoted message said:
    Quoted message said:

    rate of 1 out of 6 spam mails.

    You mistakenly assume the spam was sent to _you_. It isn't. It is sent to _as many as possible_.

    --
    CeeBee

    "I am not a crook"

  13. CeeBee said:

    You mistakenly assume the spam was sent to _you_. It isn't. It is sent to _as many as possible_.

    You mistakenly assume I'm as stupid as the spammer.

    If the spammer sends an ordinary message to a million addresses, a large number of addresses are
    bogus, leaving a large number. Of those, a large number are filtered, leaving a large number of
    potential victims. A few of those will fall for it, so maybe the jerk makes a thousand dollars.

    Now suppose he puts in a lot of time tweaking his message to get past the filters. His yield
    probably goes down.

    The guys with the filters are not going to reward him.

    And some of the marks are going to be alerted by the weirdness of the message.

    Of course, this is speculation on my part. Anyone want to do a controlled study?

  14. Wes Groleau said:
    CeeBee said:

    You mistakenly assume the spam was sent to _you_. It isn't. It is sent to _as many as possible_.

    You mistakenly assume I'm as stupid as the spammer.

    If the spammer sends an ordinary message to a million addresses, a large number of addresses are
    bogus, leaving a large number. Of those, a large number are filtered, leaving a large number of
    potential victims. A few of those will fall for it, so maybe the jerk makes a thousand dollars.

    Now suppose he puts in a lot of time tweaking his message to get past the filters. His yield
    probably goes down.

    The guys with the filters are not going to reward him.

    And some of the marks are going to be alerted by the weirdness of the message.

    Of course, this is speculation on my part. Anyone want to do a controlled study?

    WTF for?

    Diagnosed 20/03/03 Type II D&E + Metformin + Gliclazide
    + Asprin 210lbs at Dx to BMI 166lbs achieved. To mail: aspen at freeuk.com

  15. Wes Groleau said:

    Problem with challenge-response is that it magnifies the abuse of the network. Spam and virus
    loads down the wires. Response queries either dump on the poor guy whose address was picked by the
    virus, or generate a load of bounce messages when a spammer has used a non-existent address.

    Far better to use methods that discard the stuff.

    Only if you know it's 100% spam.

    The Earthlink BrightMail filter removes known spam first. Then new contacts are given a chance to
    start a two way dialogue by the challenge post. This is exactly what we do in life, try to start a
    two way conversation.

    If the challenge goes unanswered, then nobody is home and it must be spam. The challenge is less
    than 1 KB and is just one network packet. This is peanuts relative to DVD/CDROM/music downloads
    going on all the time. So it's the price of starting a conversation with an unknown person. It has
    to be done to make 100% sure it's not spam.

    I thought it was wasteful of bandwidth when I first started to use it last June. But I've changed my
    mind, as it's very effective at testing for a human at the sending end. The response is a necessary
    requirement to start a two way dialogue. So let's automate it.

    It works and it's simple. And I get my share of bandwidth as well,
    --
    Jim Dumas T1 4/86, background retinopathy, rarely hypoglycemic: <1/mo. lispro+R+U+NPH daily,
    moderate exercise, typically <6% HbA1c

  16. In article <[email hidden]>,

    Jim Dumas !mindspring.com said:
    Wes Groleau said:

    Problem with challenge-response is that it magnifies the abuse of the network. Spam and virus
    loads down the wires. Response queries either dump on the poor guy whose address was picked by
    the virus, or generate a load of bounce messages when a spammer has used a non-existent address.

    Far better to use methods that discard the stuff.

    Only if you know it's 100% spam.

    The Earthlink BrightMail filter removes known spam first. Then new contacts are given a chance to
    start a two way dialogue by the challenge post. This is exactly what we do in life, try to start a
    two way conversation.

    If the challenge goes unanswered, then nobody is home and it must be spam.

    Your assumption here is that ordinary human beings would be willing or able to comply with
    the challenge. For willing, I can't imagine circumstances in which I would comply with an
    earthlink-style challenge. For able, I can easily imagine that my mother or someone like her
    would be befuddled by the challenge and think that *it* was spam, and, as a result, she
    wouldn't reply either.

    --
    AF

  17. Wes Groleau <[email hidden]> wrote in misc.health.diabetes:

    Quoted message said:

    You mistakenly assume I'm as stupid as the spammer.

    I assume nothing. You assume that they are too dumb to understand that your countermeasures indicate
    that they should stop sending _you_.

    Quoted message said:

    Anyone want to do a controlled study?

    The fact that we're all still spammed to death no matter all your ingenious schemes and thoughts
    might make that study very superfluous.

    --
    CeeBee

    "I am not a crook"

  18. Alice Faber said:

    Your assumption here is that ordinary human beings would be willing or able to comply with
    the challenge. For willing, I can't imagine circumstances in which I would comply with an
    earthlink-style challenge. For able, I can easily imagine that my mother or someone like her
    would be befuddled by the challenge and think that it was spam, and, as a result, she
    wouldn't reply either.

    Hi Alice,

    When the challenge gets a response, I'm asked if I want to add the sender to my online
    addressbook. I usually say yes and then they never get challenged again. So it's a one time test
    for a human sender.

    Usually, cold contacts want some information from me, and are willing to post a short subject line
    in the response email. So it's relatively painless.

    But those that don't jump the hoop, don't care to begin with. The net effect is they don't bother me
    and it's no skin off my nose, as it looks like spam in a daily report. One poster here recently,
    didn't take the time to respond. But I saw the spam report and it caught my attention. So I went
    online and added her (a lurker) to the addressbook. Then responded.

    The challenge-response works well. It's a small price to pay,
    --
    Jim Dumas T1 4/86, background retinopathy, rarely hypoglycemic: <1/mo. lispro+R+U+NPH daily,
    moderate exercise, typically <6% HbA1c

  19. In article <[email hidden]>,

    Jim Dumas !mindspring.com said:
    Alice Faber said:

    Your assumption here is that ordinary human beings would be willing or able to comply with the
    challenge. For willing, I can't imagine circumstances in which I would comply with an earthlink-
    style challenge. For able, I can easily imagine that my mother or someone like her would be
    befuddled by the challenge and think that it was spam, and, as a result, she wouldn't reply
    either.

    Hi Alice,

    When the challenge gets a response, I'm asked if I want to add the sender to my online
    addressbook. I usually say yes and then they never get challenged again. So it's a one time test
    for a human sender.

    Usually, cold contacts want some information from me, and are willing to post a short subject line
    in the response email. So it's relatively painless.

    But those that don't jump the hoop, don't care to begin with.

    I'd flip it around and say that you care less about corresponding with folks than about not
    getting spam.

    Mind you, I have a whole set of procmail filters on my mail server, as well as SpamAssassin, and the
    Junk filters in Eudora. I also have a set of files I check for false positives, mostly caused by
    folks who send email in HTML format. I'm accepting the burden of making my email usable, not
    foisting it off on others.

    --
    AF

  20. Alice Faber said:

    I'd flip it around and say that you care less about corresponding with folks than about not
    getting spam.

    True. "Don't bother me unless you're serious." That's the net effect.

    And that's life in a spam-burdened world.

    Quoted message said:

    Mind you, I have a whole set of procmail filters on my mail server, as well as SpamAssassin, and
    the Junk filters in Eudora. I also have a set of files I check for false positives, mostly caused
    by folks who send email in HTML format. I'm accepting the burden of making my email usable, not
    foisting it off on others.

    I decided I was wasting too much of my time looking at spam email headers and writing rules to
    catch this moving target. Earthlink has simplified my life with challenge-response. As spam
    continues to grow, it will consume your free time with all the maintenance your layered filters
    require. But if this is an educational exercise, then that's wonderful. But I've concluded that
    until some change is made in email header tracability, (verified originator ID for example), then
    it's useless to chase spammers.

    Just force the sender to make a second attempt in good faith.

    It works,
    --
    Jim Dumas T1 4/86, background retinopathy, rarely hypoglycemic: <1/mo. lispro+R+U+NPH daily,
    moderate exercise, typically <6% HbA1c

Active in the last 60 minutes

Active in this thread

0 users · 0 guests ·0 bots ·0 total

No signed-in users are active right now.

No known search crawlers active right now.