[antispam-f] Re: What have they got against Deborah anyway?

  • From: Jeremy C B Nicoll <Jeremy@xxxxxxxxxxxxxxxx>
  • To: antispam@xxxxxxxxxxxxx
  • Date: Sat, 25 Nov 2006 22:12:09 +0000 (GMT)

In article <4e8b70cf52Steve@xxxxxxxxxxxxxxxxxx>,
   Steve Joyce <Steve@xxxxxxxxxxxxxxxxxx> wrote:
> In article <745e678b4e.stuart@xxxxxxxxxxxxxxxxxxxxxx>,
>    Stuart Painting <stuart@xxxxxxxxxxxxxxxxxx> wrote:

> > 3. Faulty address harvesting - one of the "address swiping"
> >    routines used by spammers accidentally(?) prepends the surname
> >    in the victim's address book to the email address.

> >    delete to: = *paintingstuart@zedtoo*

> I've been using my equivalent, i.e.

>         delete to: = *joycesteve*

Don't you mean joycessteve     ie two Ses in the middle?

> and one of today's mails was not stopped, despite containing
> 'joycesteve'. After much examination, there was no 'To' header, just
> 'Received for' containing 'joycesteve'. A new rule examining the
> 'Received' header works in the trial window, but I think I'll try
> making the mailbox more specific. That should dump all the ones
> containing random strings as suggected by Jeremy C B Nicoll.

I've no desire to download the headers for them to make that decision.

I get rid of the bulk of those separately using a cut-down version of
AS that runs through the main addresses, logs into each such 'mailbox'
and deletes everything it finds.  I've thought of making that program
available, but a drawback (for other people) is that I wrote it to
generate stats on which of these addresses attract the most spam, and
there's a back-end program that regenerates the config for the cut-down
version of AS which isn't very portable to other peoples' situations.
My own version of AS also generates stats for this process.

I have been considering dumping my version of AS and starting to use
Frank's version.  However it'll be ages before I've decided if I'm
going to, and how to add the features I like from my version into his,
especially if I try to find a way to do that without making direct
source code changes to his version (so that there's some chance that I
can then update use updated copies of his version as time goes on).

-- 
Jeremy C B Nicoll, Edinburgh, Scotland - my opinions are my own.

Other related posts: