[BUGS] Forged-sender bounce spam: how to avoid/mitigate?

Peter Jeremy peterjeremy at optushome.com.au
Thu Sep 25 18:47:30 EST 2008


On 2008-Sep-25 13:39:40 +1000, Andrew Reilly <areilly at bigpond.net.au> wrote:
>Aargh!  I don't know what, if anything, I'm doing wrong, but
>I'm attracting an awful lot of forged-sender bounce mail at the
>moment:

I saw a lot starting a few weeks ago but nothing like the volume you
are getting and it seems to have tapered off.

> of the 4500 or so messages in my freebsd mailing list
>incoming folder, 3300 or so were this sort of spam.

Assuming your mail distribution is working, that means that the
mails are actually bouncing through the FreeBSD mailing lists -
I don't think I'm seeing any via that path.  What mailing list(s)
are you seeing them on.

>  They seem
>to get past my bayesian spam filter (bogofilter) quite easily.

Keep in mind that the filter needs something to learn from,
though 3300 should be sufficient to stop them continuing.

>  Anyone have any
>effective strategies for mitigation?

An effective spam mitigation strategy would make you an instant
millionaire or better.

>[Most of it seems to be to/from Russian or Korean addresses.

Likewise.

-- 
Peter Jeremy
Please excuse any delays as the result of my ISP's inability to implement
an MTA that is either RFC2821-compliant or matches their claimed behaviour.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 195 bytes
Desc: not available
Url : http://mailman.barnet.com.au/pipermail/bugs/attachments/20080925/3ca8cf99/attachment.bin 


More information about the BUGS mailing list