PDA

View Full Version : email worm again?


JBoze3131
9-30-03, 09:54 PM
im starting to get tons of undeliverable mail messages again like i was a month or so ago when the worm hit. is this something new? i didnt see another topic on this, so i apologize if someone already mentioned it.

20 or so e mails in 10 mins so far. i swear id like ten mins with the idiots that create and spread these things!

stevel
9-30-03, 10:25 PM
There are a couple of worms still going around, the latest one, Swen aka Gibe.F, seems to be the one causing the most annoyance lately, with a steady stream of "Latest Internet Pack" and variant e-mails.

JBoze3131
9-30-03, 10:52 PM
man oh man. someone tell these virus writers to get a life! its not too annoying until you leave for the day and come back and there are so many e mails that your acct has been shut off until you delete some of them. i use hotmail for all my e mail (and transfer my domain name mail there too), so it easily goes over the limit with 20 returned mails every 10 mins.

Croc Hunter
10-1-03, 12:28 AM
I hate hotmail. There are sites dedicated to hacking those accounts. "Hack hotmail in 10 easy steps" :rolleyes: If you use mailwasher to check your mail first you can set it to always bounce certain emails back to sender. Then only d/l the stuff you want. Comes in handy when your 'friends' send those stupid chain mails - bounce!!

stevel
10-1-03, 08:58 AM
Please DON'T bounce - the sender is almost always forged in spam and viruses. All bouncing does is add to network traffic and annoy innocent users.

Croc Hunter
10-1-03, 11:09 PM
Then maybe powweb should intercept known spam and viral mail.
My ISP provides this protection as an option. Using a list similar to SpamCops as mailwasher does. Do we have to clog servers with this stuff before something is done? It seems as long as its the end user copping the brunt of these attacks powweb is reluctant to do anything about it.

Anyway bouncing mail with mailwasher removes it from powwebs server before its downloaded and sends it back to the mail server it came from with an "undeliverable" message. It is not open relay, You set it up to bounce using powweb SMTP outgoing before recieving with hotmail etc. Irresponsible server owners who allow this obvious repeater mail to go out in the first place deserve to get clogged.

RocketJeff
10-1-03, 11:25 PM
Originally posted by Croc Hunter
Anyway bouncing mail with mailwasher removes it from powwebs server before its downloaded and sends it back to the mail server it came from with an "undeliverable" message.
No, mailwasher doesn't bounce it back to the sending mail server - it bounces it back to the mail server/email address in the From: line. This is almost always forged anymore and just fills innocent people's mailboxs.

The only way to send it back to the true sender with a real standards-based 'undeliverable' message is from the reciving SMTP server at the time the mail is received. Since mailwasher (and similar programs) don't work with the SMTP server (they look at the mailbox after the mail is received), they can't know the true mail server - that information isn't kept with the email.

If you want to read more about this, see Why (some) anti-virus companies are to blame for the recent (http://www.f-prot.com/news/gen_news/open_letter_10sept2003.html). While it's addressing virus email, the same holds true for all other spam.

Croc Hunter
10-2-03, 06:30 AM
Originally posted by RocketJeff The only way to send it back to the true sender with a real standards-based 'undeliverable' message is from the reciving SMTP server at the time the mail is received. Since mailwasher (and similar programs) don't work with the SMTP server (they look at the mailbox after the mail is received), they can't know the true mail server - that information isn't kept with the email.
Thanks for your concise reply RocketJeff. Do you know of a "real standards-based" email program I can use to truly reject mail at SMTP server level?, I don't mind paying big $$. Or is this up to powweb to execute?.

RocketJeff
10-2-03, 09:10 AM
Originally posted by Croc Hunter
Thanks for your concise reply RocketJeff. Do you know of a "real standards-based" email program I can use to truly reject mail at SMTP server level?, I don't mind paying big $$. Or is this up to powweb to execute?.
It has to be done as the mail's being received by the SMTP server - it would require Powweb to make any changes.

Your only other option would be to run your own mail server and have your DNS MX record redirected to it.

Croc Hunter
10-2-03, 09:24 AM
Thanks again RocketJeff. That's what I thought, and believe me I've considered running my own mail servers but my air-con bill alone is killing me. lol.

C'arn powweb shell out the peas. :cool:

stevel
10-2-03, 11:56 AM
PowWeb already blocks spam at the server based on the Spamhaus RBL. However, this is for mail delivered to the PowWeb server only, not for mail forwarded elsewhere. Uses have no control over this - blocked mail has delivery rejected - no separate bounce is sent.

For my own use, I forward mail to SpamCop (http://www.spamcop.net/) which offers both spam and virus filtering. The spam filtering is configurable and spam is diverted into a "Held Mail" folder for review. Highly recommended.