<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>Jim&#039;s New World &#187; spam</title> <atom:link href="http://www.theczechs.net/blog/tag/spam/feed/" rel="self" type="application/rss+xml" /><link>http://www.theczechs.net/blog</link> <description>Just another place to ramble on about nothing...</description> <lastBuildDate>Tue, 08 Nov 2011 20:26:22 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=</generator> <xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" /> <item><title>Wiki SPAM!!!</title><link>http://www.theczechs.net/blog/ramblings/wiki-spam/</link> <comments>http://www.theczechs.net/blog/ramblings/wiki-spam/#comments</comments> <pubDate>Fri, 24 Dec 2010 23:02:49 +0000</pubDate> <dc:creator>Jim</dc:creator> <category><![CDATA[Ramblings]]></category> <category><![CDATA[Apple]]></category> <category><![CDATA[blog]]></category> <category><![CDATA[OS X]]></category> <category><![CDATA[server]]></category> <category><![CDATA[solution]]></category> <category><![CDATA[spam]]></category> <category><![CDATA[wiki]]></category> <guid
isPermaLink="false">http://www.theczechs.net/blog/?p=1073</guid> <description><![CDATA[I was quite surprised to find my server had been somewhat "compromised" so to speak. I was always focused on fighting spam in email, but overlooked other vulnerabilities.
Occasionally I would happen to notice strange wiki entry references in the logs. I never put two and two together until today. I used group permissions to override the default "unauthenticated user" and only permit those authorized users to post.]]></description> <content:encoded><![CDATA[<p><a
href="http://www.theczechs.net/blog/wp-content/uploads/2010/12/200px-No-spam.svg_.png"><img
src="http://www.theczechs.net/blog/wp-content/uploads/2010/12/200px-No-spam.svg_-150x150.png" alt="" title="No Spam" width="150" height="150" class="alignleft size-thumbnail wp-image-1074" /></a> I was quite surprised to find my server had been somewhat &#8220;compromised&#8221; so to speak. I was always focused on fighting spam in email, but overlooked other vulnerabilities.</p><p>Occasionally I would happen to notice strange wiki entry references in the logs. I never put two and two together until today. Using Google Analytics, I saw where Google had a number of spam appearances attributed to my domain. So I scoured the logs more thoroughly and found the wiki server had been set up to allow &#8220;unauthenticated&#8221; posts. Amazing, and even more so is that this is the default!?! I couldn&#8217;t believe it.</p><p>The &#8220;unauthenticated user&#8221; had created a &#8220;Publications&#8221; entry back in 2008. Again, WTF?!? (And that isn&#8217;t a reference to the CIA&#8217;s &#8220;WikiLeaks Task Force&#8221; either&#8230; ) There were, for the most part some that appeared to be legitimate posts. A lot of the entries had photos that added to the story. There were over 20 pages, each with many posts, going all the way back to 2008. They were posted with somewhat frequent regularity. The latest was posted last night at 02:00 or so.</p><p>A quick Google search really didn&#8217;t reveal a canned, step by step fix. I did see reference to how this configuration is a spam magnet. How true&#8230;</p><p>I decided to dive in to the configuration and see if I could figure it out. I don&#8217;t know if this will work, but since my address has been a regular target, only a day or two will tell if I have been successful.</p><p>In the end, I deleted the offending wiki and blog.  I created a group that has permissions to make / edit a wiki post (and I hope this rolls to the blog entries, too.)  Essentially, since this is a small server and it isn&#8217;t difficult to manage. On a larger scale, an automated configuration should be created.  In essence, I just added authorized users to a group that allows wiki posts.  The next step was to configure the wiki server to only accept posts from that group of users. (It was here in Server Admin that I finally noticed the &#8216;Wiki Allows Posts by Everybody&#8217;.</p><p>Sheesh! For folks like me, I would sure appreciate the default to explicitly reject posts by everyone and require specific permissions.  It make me wonder just how many other compromised installations may be scattered around the Internet.  Even more interesting, it make me think of some of the Google links I have followed&#8230; Some of the posts buried in my wiki / blog server looked suspiciously similar in style and content to ones I have visited.</p><p>Sure the idea is to drive traffic to your server&#8230;  But this is NOT the right method! <img
src="http://www.theczechs.net/blog/wp-content/plugins/yahoo-messenger-emoticons/emoticons/no_talking.gif" style="border:none;background:none;vertical-align:-25%;" alt="no talking" /></p> ]]></content:encoded> <wfw:commentRss>http://www.theczechs.net/blog/ramblings/wiki-spam/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>What would we do without SPAM???</title><link>http://www.theczechs.net/blog/ramblings/what-would-we-do-without-spam/</link> <comments>http://www.theczechs.net/blog/ramblings/what-would-we-do-without-spam/#comments</comments> <pubDate>Sun, 27 Dec 2009 00:02:41 +0000</pubDate> <dc:creator>Jim</dc:creator> <category><![CDATA[Ramblings]]></category> <category><![CDATA[brain surgery]]></category> <category><![CDATA[email]]></category> <category><![CDATA[Gmail]]></category> <category><![CDATA[spam]]></category> <guid
isPermaLink="false">http://www.theczechs.net/blog/?p=868</guid> <description><![CDATA[I wandered through the pages of spam and was cleaning up my Gmail account. It's a good thing I took a look. Over the years, I've only had a few messages that were flagged as spam, but were actually "good" messages. On the other hand, there have been less than a handful of spam that have gotten through. That is more than commendable, and for me anyhow, Gmail has one of the best spam filter systems out there. Until now...]]></description> <content:encoded><![CDATA[<p>I wandered through the pages of spam and was cleaning up my Gmail account.  It&#8217;s a good thing I took a look.  Over the years, I&#8217;ve only had a few messages that were flagged as spam, but were actually &#8220;good&#8221; messages.  On the other hand, there have been less than a handful of spam that have gotten through.  That is more than commendable, and for me anyhow, Gmail has one of the best spam filter systems out there.  Until now&#8230;</p><p>I think there were around 400 messages.  As I was scanning them before deleting (to make sure I didn&#8217;t delete good email) I saw the following:</p><p><a
href="http://www.theczechs.net/blog/wp-content/uploads/2009/12/BrainSurgeryOnSale.inbox_.jpg"><img
class="alignnone size-full wp-image-869" title="BrainSurgeryOnSale.inbox" src="http://www.theczechs.net/blog/wp-content/uploads/2009/12/BrainSurgeryOnSale.inbox_.jpg" alt="Brain Surgery On Sale!" width="726" height="370" /></a></p><p>Wow, I could have almost missed the opportunity!  I saw it was from December 9, so figured it must have been a pre-Christmas sale or promotion.  (It did say this week only, too.)  I wonder if they still have it available at that price?!?!  I know a few people who could take advantage of this&#8230; <img
src='http://www.theczechs.net/blog/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /></p><p><a
href="http://www.theczechs.net/blog/wp-content/uploads/2009/12/BrainSurgeryOnSale_Article_2009-12-09.jpg"><img
class="alignnone size-full wp-image-870" title="BrainSurgeryOnSale_Article_2009-12-09" src="http://www.theczechs.net/blog/wp-content/uploads/2009/12/BrainSurgeryOnSale_Article_2009-12-09.jpg" alt="Brain Surgery On Sale - This week only! - What a deal!!!" width="680" height="157" /></a></p> ]]></content:encoded> <wfw:commentRss>http://www.theczechs.net/blog/ramblings/what-would-we-do-without-spam/feed/</wfw:commentRss> <slash:comments>1</slash:comments> </item> <item><title>Bigfoot, the Stinkfoot, is dead!</title><link>http://www.theczechs.net/blog/ramblings/bigfoot-stinkfoot-dead/</link> <comments>http://www.theczechs.net/blog/ramblings/bigfoot-stinkfoot-dead/#comments</comments> <pubDate>Wed, 08 Jul 2009 18:43:21 +0000</pubDate> <dc:creator>Jim</dc:creator> <category><![CDATA[Ramblings]]></category> <category><![CDATA[Bigfoot]]></category> <category><![CDATA[Bigfoot for Life]]></category> <category><![CDATA[Bigfoot.com]]></category> <category><![CDATA[distribution]]></category> <category><![CDATA[email]]></category> <category><![CDATA[Gmail]]></category> <category><![CDATA[Hotmail]]></category> <category><![CDATA[junk]]></category> <category><![CDATA[redirect]]></category> <category><![CDATA[spam]]></category> <category><![CDATA[stinkfoot]]></category> <category><![CDATA[Yahoo]]></category> <guid
isPermaLink="false">http://www.theczechs.net/blog/?p=316</guid> <description><![CDATA[I've finally terminated the Bigfoot.com email address I've had for years.  I've just had enough of the spam they generated, or passed through, even while paying for their premium services.  Statistics I kept showed far more spam was delivered than was stopped.]]></description> <content:encoded><![CDATA[<p>I finally did it.  I killed Bigfoot.  I threatened many times, especially over the past year, and now I&#8217;ve finally gone and done it.  I finally mustered the courage to put an end to the misery.</p><p>No, I&#8217;m not talking about some big furry man-like creature that lurks in the wilderness.  But this was almost as scary.  I&#8217;m talking about the Bigfoot, &#8220;email address for life&#8221; service.  Well, it was alive until I killed it, anyway&#8230;</p><p>For the past couple of years, the spam received at my &#8220;Bigfoot for life&#8221; address was on the rise.  The spam that got through far out numbered the &#8220;good&#8221; mail that was received.  I spent hours tracking, logging, and charting the spam versus good.  What was worse, and far more frustrating, was that I had upgraded my account to &#8220;premium&#8221; membership.  This entitled me to increased spam protection.  Yea, right!  I think I overlooked the fine print that must have said &#8216;I pay for the privilege to receive all the spam I can handle, and then some.&#8217;</p><p>I threatened to delete the service, but was drawn in by that &#8220;email address for life.&#8221;  A few months ago, I did finally cancel my premium membership.  The spam protection was virtually non-existent, and I only had been using the address to receive a few mailing list emails a day.  I quit giving out the address long ago, when the spam started to become unbearable.</p><p>All of the other free email services, including Hotmail, Yahoo, and particularly Gmail, have far better spam protection.  I would forward the Bigfoot email to one of these services and literally less than a few spam messages *ever* made it through to the inbox.  That is saying a lot, since Hotmail was always notorious for spam.</p><p>The proverbial straw was when I received what (to me, anyway) appears to be a valid email from my Bigfoot account, to my business account.  Of course, it was spam.  I looked at the headers, since I just assume the &#8216;from&#8217; was spoofed.  From my limited expertise however, this came from my Bigfoot account!</p><p>I tried to log on, and found I couldn&#8217;t remember my password, or it had been changed.  I was able to find a &#8216;contact us&#8217; web form, but I&#8217;ve gone that route for issues in the past.  I think it goes off into a black hole.  I asked for my account to be disabled / deleted immediately.  That was yesterday, and still nothing today.  In the meantime, I did locate my password and was able to log in.  I didn&#8217;t even look through the webmail (which in hindsight was dumb) but immediately deleted the account.  Bigfoot is dead&#8230;</p><p>In the beginning, it was a good concept and actually worked well.  However, I think they got in to the business of selling their email addresses or something, as a source of revenue.  One interesting note, which makes me believe this, was a sign-on notice.  It said I had a &#8220;free&#8221; account, and would have to accept some terms of service, which allowed third-party mailings.  What a rip-off!  I think that borders on criminal.</p><p>But it&#8217;s all behind me now.  I know there are other redirections / forwarding services.  But with the proliferation of Gmail and others, why do you really need them now?</p><p>Bigfoot, RIP&#8230;</p><pre>Diagnostic-Code: smtp;550 This account is not allowed...jczech@bigfoot.com</pre><div
id="_mcePaste" style="position: absolute; left: -10000px; top: 591px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Reporting-MTA: dns;blu0-omc2-s25.blu0.hotmail.com</div><div
id="_mcePaste" style="position: absolute; left: -10000px; top: 591px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Received-From-MTA: dns;BLU148-W19</div><div
id="_mcePaste" style="position: absolute; left: -10000px; top: 591px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Arrival-Date: Tue, 7 Jul 2009 13:18:48 -0700</div><div
id="_mcePaste" style="position: absolute; left: -10000px; top: 591px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Final-Recipient: rfc822;jczech@bigfoot.com</div><div
id="_mcePaste" style="position: absolute; left: -10000px; top: 591px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Action: failed</div><div
id="_mcePaste" style="position: absolute; left: -10000px; top: 591px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Status: 5.5.0</div><div
id="_mcePaste" style="position: absolute; left: -10000px; top: 591px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Diagnostic-Code: smtp;550 This account is not allowed&#8230;jczech@bigfoot.com</div><div
id="attachment_317" class="wp-caption alignleft" style="width: 585px"><img
class="size-full wp-image-317" title="bigfoot.is.dead" src="http://www.theczechs.net/blog/wp-content/uploads/2009/07/bigfoot.is.dead.jpg" alt="A test message to ensure Bigfoot is really dead." width="575" height="620" /><p
class="wp-caption-text">A test message to ensure Bigfoot is really dead.</p></div> ]]></content:encoded> <wfw:commentRss>http://www.theczechs.net/blog/ramblings/bigfoot-stinkfoot-dead/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
