been gettings these odd email in my bbs inbox
From: =?utf-8?B?55m96Im+6KeC?= on Sun Nov 5 04:13:36 2017
Subject: =?utf-8?B?MTMgICAgIOa+s+6eluiPm+awuO6eluWIqTMzMjQ5OOeCuUMwTemCgOaCqA==?= =?utf-8?B?5rOo7p6W5YaM6YCBNTjotaI14pKPMOaPkCzkuJPlkZhRMzE4OTcwMzY46aKG?= <p><font color="Black">..............<span style="position: absolute;
not odd... it looks like chinese spam... they are quite common... block the sender and move on ;)
On 2017 Nov 04 16:50:34, you wrote to all:
been gettings these odd email in my bbs inbox
not odd... it looks like chinese spam... they are quite common... block the sender and move on ;)
Re: odd emails
By: Richard Williamson to all on Sat Nov 04 2017 16:50:34
From: =?utf-8?B?55m96Im+6KeC?= on Sun Nov 5 04:13:36 2017
Subject: =?utf-8?B?MTMgICAgIOa+s+6eluiPm+awuO6eluWIqTMzMjQ5OOeCuUMwTemC gOaCqA==?= =?utf-8?B?5rOo7p6W5YaM6YCBNTjotaI14pKPMOaPkCzkuJPlkZhRMzE4OT cwMzY46aKG?= <p><font color="Black">..............<span style="position: absolute;
and they are from *.qq.com??
I'm getting flooded with them too as of 3 days ago, even though DNSBL is rejecting a lot of them, some are still getting through..
not odd... it looks like chinese spam... they are quite common... block the sender and move on ;)
not that easy.. these are listed as coming from *.qq.com. put that in the hostname blocke.. does no good.. different IP addresees.. some getting through the DNSBL also, some how..
it come to a account that I setup it you lost or forgot your pw
" pw@time.synchro.net " ( that goes to my account ) that only show up on the telnet logon screen
ovbiously a bot is crusing the synch bbs list and spamming everything
down the line it possibly can.
not odd... it looks like chinese spam... they are quite common...
block the sender and move on ;)
not that easy.. these are listed as coming from *.qq.com. put that in the hostname blocke.. does no good.. different IP addresees.. some getting through the DNSBL also, some how..
it come to a account that I setup it you lost or forgot your pw "
pw@time.synchro.net " ( that goes to my account ) that only show up
on the telnet logon screen
now that is strange.. I can understand it getting ripped from a
website, but not telnet..
really? not even when the telnet is wrapped in a flash terminal on a web page?? :smh:
The real reason for the leak of this email address can be seen here:
http://synchro.net/sbbslist.html
Because that address was included on the login screen of the BBS, and DM includes a capture of the login screen as text (ANSI -> HTML), the address can easily be read by a run of the mill web scraping bot.
ovbiously a bot is crusing the synch bbs list and spamming
everything down the line it possibly can.
that specific statement is highly doubtful...
responds to their scans... nothing more and nothing less... spamming crud comes from harvested email address lists...
not that easy.. these are listed as coming from *.qq.com. put that
in the hostname blocke.. does no good.. different IP addresees..
some getting through the DNSBL also, some how..
don't look at the email domain... that doesn't mean shite... block the server that sent it to you... better yet, put something like DSPAM in front of your mail server and let it deal with the spam there /before/ it gets to your server... even better would be to do this on a *perimeter firewall* and stop it all long before it gets into your server(s)...
now that is strange.. I can understand it getting ripped from a
website, but not telnet..
really? not even when the telnet is wrapped in a flash terminal on a web page?? :smh:
really? not even when the telnet is wrapped in a flash terminal on a
web page?? :smh:
I would be surprised if any email harvesting web bots bothered with Flash. Even HTML5 based terminals wouldn't be a big risk re: this. Generally the bot would need to know to 'click' a 'Connect' button first, then be able to handle the output (possibly by implementing a Flash runtime or a full browser-like javascript interpreter). It's possible, but far from the low-hanging fruit these things usually go for.
The real reason for the leak of this email address can be seen here:
http://synchro.net/sbbslist.html
really? not even when the telnet is wrapped in a flash terminal on a
web page?? :smh:
I would be surprised if any email harvesting web bots bothered with
Flash. Even HTML5 based terminals wouldn't be a big risk re: this. Generally the bot would need to know to 'click' a 'Connect' button
first, then be able to handle the output (possibly by implementing a
Flash runtime or a full browser-like javascript interpreter). It's possible, but far from the low-hanging fruit these things usually go
for.
The real reason for the leak of this email address can be seen here:
http://synchro.net/sbbslist.html
Because that address was included on the login screen of the BBS, and
DM includes a capture of the login screen as text (ANSI -> HTML), the address can easily be read by a run of the mill web scraping bot.
ovbiously a bot is crusing the synch bbs list and spamming
everything down the line it possibly can.
that specific statement is highly doubtful...
no.. these @qq.com emails and NETMAILS are specifically targeting bbses..
responds to their scans... nothing more and nothing less... spamming
crud comes from harvested email address lists...
harvested emails from the online synchronet bbs list..
what I don't understand is I am using every DNSBL option available,
plus ip.can and host.can and there are still close to 5 emails every couple hours making it through..
to about 20+ emails being denied.. they are abviously coming from many
IP addresses.. the hostnames make no difference.
now that is strange.. I can understand it getting ripped from a
website, but not telnet..
really? not even when the telnet is wrapped in a flash terminal on a
web page?? :smh:
no... even from what you've said, they are dumb bots that are simply harvesting text from a website..
Now you are saying they have become smart enough to know what flash terminal is and how to extract data from that?
You're talking yourself into a circle.. it cannot be both..
If this is what it happening, that would mean someone has specifically written code to target bbs systems..
we're only talking about the initial screen... not actually connecting to the BBS... if bots can OCR captchas, certainly they might also flash things... i definitely remember a problem (elsewhere) with cheating bots in flash games so they had to have been doing flash to do that cheating, right?
omg, really? i thought those were just screenshots... jpgs or such... you are right, though... that is one place where the address could be scrapped from...
We could potentially host those screengrabs as images instead, or not show them at all (a shame, since it looks nice in the list), or people could avoid putting email addresses on their login screens and maybe implement a better/automated password recovery thing.
This reminds me that my own "forgot password" thing sucks. I think I'll give it an overhaul today.
omg, really? i thought those were just screenshots... jpgs or such... you are right, though... that is one place where the address could be scrapped from...
We could potentially host those screengrabs as images instead, or
not show them at all (a shame, since it looks nice in the list), or
people could avoid putting email addresses on their login screens
and maybe implement a better/automated password recovery thing.
Re: odd emails
By: mark lewis to KK4QBN on Sun Nov 05 2017 11:41:20
not that easy.. these are listed as coming from *.qq.com. put that
in the hostname blocke.. does no good.. different IP addresees..
some getting through the DNSBL also, some how..
don't look at the email domain... that doesn't mean shite... block the server that sent it to you... better yet, put something like DSPAM in front of your mail server and let it deal with the spam there /before/ it gets to your server... even better would be to do this on a *perimeter firewall* and stop it all long before it gets into your server(s)...
I realise the doman makes no difference.. this is obviously coming from MANY different IP addresses.. I've never seen such spamming..
Re: odd emails
By: echicken to mark lewis on Sun Nov 05 2017 12:46:01
We could potentially host those screengrabs as images instead, or not show them at all (a shame, since it looks nice in the list), or people could avoid putting email addresses on their login screens and maybe implement a better/automated password recovery thing.
That would be a shame, I've always thought the screengrabs really spice up the bbslist.. I will for sure rip the email addresses off my login screens.
If you have hostname lookups disabled in your mail server, then blocking by hostname won't work anyway.
That would be a shame, I've always thought the screengrabs really
spice up the bbslist.. I will for sure rip the email addresses off my
login screens.
Or you could obfuscate them. e.g. sysop {at} yourbbs {dot} com
Re: odd emails
By: Digital Man to KK4QBN on Sun Nov 05 2017 13:23:11
If you have hostname lookups disabled in your mail server, then blocking by hostname won't work anyway.
I had it disabled for smtp, but then enabled it just for this reason, my terminal window shows the majority of the being blocked.
11/5 20:08:44 mail 0047 SMTP Hostname: mail.spgov.lk
11/5 20:08:44 mail 0047 !SMTP CLIENT IP ADDRESS BLOCKED: 123.231.70.44 (733 total)
11/5 20:08:47 term 0047 Telnet connection accepted from: 58.85.109.204 port 43285
but there are still messages getting through (so far around 30 today) I'm just going to let sbbs run its course, I have all the DNSBL features turned on, hoepfully, like it did with most of the telnet bots it will have everything locked pretty tight in a month or so.
here is one that just went through:
11/5 20:11:58 mail 0056 SMTP Connection accepted on port 25 from: 49.67.164.139 port 59207
11/5 20:11:58 mail 0056 SMTP Hostname: 49.67.164.139
11/5 20:12:01 mail 0056 SMTP Receiving mail message from: <1054610291@qq.com> to 1@kk4qbn.com
hostname will not matter either way here I presume..
here is one that just went through:
11/5 20:11:58 mail 0056 SMTP Connection accepted on port 25 from: 49.67.164.139 port 59207
If you have hostname lookups disabled in your mail server, then blocking by hostname won't work anyway.
I had it disabled for smtp, but then enabled it just for this reason, my terminal window shows the majority of the being blocked.
11/5 20:08:44 mail 0047 SMTP Hostname: mail.spgov.lk
11/5 20:08:44 mail 0047 !SMTP CLIENT IP ADDRESS BLOCKED: 123.231.70.44 (733 total)
11/5 20:08:47 term 0047 Telnet connection accepted from: 58.85.109.204 port 43285
but there are still messages getting through (so far around 30 today) I'm just going to let sbbs run its course, I have all the DNSBL features turned on, hoepfully, like it did with most of the telnet bots it will have everything locked pretty tight in a month or so.
here is one that just went through:
11/5 20:11:58 mail 0056 SMTP Connection accepted on port 25 from: 49.67.164.139 port 59207
11/5 20:11:58 mail 0056 SMTP Hostname: 49.67.164.139
11/5 20:12:01 mail 0056 SMTP Receiving mail message from: <1054610291@qq.com> to 1@kk4qbn.com
hostname will not matter either way here I presume..
No, it wouldn't. But if you add *@qq.com to your text/email.can file, that'd stop that since the MAIL FROM SMTP command includes that address, you can block it easily.
If you have hostname lookups disabled in your mail server, then blocking by hostname won't work anyway.
I had it disabled for smtp, but then enabled it just for this reason, my terminal window shows the majority of the being blocked.
11/5 20:08:44 mail 0047 SMTP Hostname: mail.spgov.lk
11/5 20:08:44 mail 0047 !SMTP CLIENT IP ADDRESS BLOCKED: 123.231.70.44 (733 total)
11/5 20:08:47 term 0047 Telnet connection accepted from: 58.85.109.204 port 43285
but there are still messages getting through (so far around 30 today) I'm just going to let sbbs run its course, I have all the DNSBL features turned on, hoepfully, like it did with most of the telnet bots it will have everything locked pretty tight in a month or so.
here is one that just went through:
11/5 20:11:58 mail 0056 SMTP Connection accepted on port 25 from: 49.67.164.139 port 59207
11/5 20:11:58 mail 0056 SMTP Hostname: 49.67.164.139
11/5 20:12:01 mail 0056 SMTP Receiving mail message from: <1054610291@qq.com> to 1@kk4qbn.com
hostname will not matter either way here I presume..
No, it wouldn't. But if you add *@qq.com to your text/email.can file, that'd stop that since the MAIL FROM SMTP command includes that address, you can block it easily.
did this ~@qq.com didn't help
No, it wouldn't. But if you add *@qq.com to your text/email.can file, that'd stop that since the MAIL FROM SMTP command includes that address, you can block it easily.
that's a chinese IP... do with it what you will...
| Sysop: | Winzlo |
|---|---|
| Location: | Minnesota, USA |
| Users: | 11 |
| Nodes: | 16 (0 / 16) |
| Uptime: | 495938:58:43 |
| Calls: | 82 |
| Files: | 1,070 |
| D/L today: |
27 files (11,920K bytes) |
| Messages: | 286,963 |