cancel
Showing results for 
Search instead for 
Did you mean: 

How did this get through?

Mad_Moggies
Rising Star
Posts: 1,285
Thanks: 43
Registered: ‎01-08-2007

How did this get through?

A very obvious bit of rubbish spam found its way into our catch-all mailbox this morning. I'm wondering how it managed to escape the spam filters as nothing like this has got though in ages. Was Postini only half awake or has someone's pet cat been trying to send a message to our feline mob?  Huh
Headers:
From: ddrljaca@neva.hr
Subject: BGMnXzVcpV
Date: 7 September 2008 09:17:57 BST
To: xxxx@xxxx.plus.com
Return-Path: <ddrljaca@neva.hr>
Envelope-To: xxxx@xxxx.plus.com
Delivery-Date: Sun, 07 Sep 2008 11:05:28 +0100
Received: from exprod5mx243.postini.com ([64.18.0.163] helo=psmtp.com) by pih-sunmxcore13.plus.net with smtp (PlusNet MXCore v2.00) id 1KcH96-0001aB-59  for xxxx@xxxx.plus.com; Sun, 07 Sep 2008 11:05:28 +0100
Received: from source ([68.188.16.119]) by exprod5mx243.postini.com ([64.18.4.10]) with SMTP; Sun, 07 Sep 2008 06:05:26 EDT
Message-Id: <88909.byrd@kip>
User-Agent: Thunderbird 2.0.0.12 (Windows/20080213)
Mime-Version: 1.0
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 7bit
X-Pstn-Neptune: 500/255/0.51/45
X-Pstn-Levels: (S: 2.15098/99.90000 CV:99.9999 )
X-Pstn-Settings: 1 (0.1500:0.1500) cv gt3 gt2 gt1
X-Pstn-Addresses: from <ddrljaca@neva.hr> [309/15]
X-Pn-Pstn: Spam 4
X-Pn-Virus-Filtered: by PlusNet MXCore (v4.00)
X-Pn-Spam-Filtered: by PlusNet MXCore (v4.00)
Message:
fbqBGMnXzVcpVtKHgiQp
Plusnet user since November 2003
Full Fibre since September 2023
Mac OS14 and Firefox user with latest versions of both
9 REPLIES 9
bobpullen
Community Gaffer
Community Gaffer
Posts: 16,887
Thanks: 4,979
Fixes: 316
Registered: ‎04-04-2007

Re: How did this get through?

Quote from: Mad
X-Pstn-Neptune: 500/255/0.51/45
X-Pstn-Levels: (S: 2.15098/99.90000 CV:99.9999 )
X-Pstn-Settings: 1 (0.1500:0.1500) cv gt3 gt2 gt1
X-Pstn-Addresses: from <ddrljaca@neva.hr> [309/15]
X-Pn-Pstn: Spam 4

It was only marked as Spam 4 due to the value highlighted in bold. Increasing the aggressiveness of the filter to 4 would catch this but you'd then run a strionger chance of getting false positives.

Bob Pullen
Plusnet Product Team
If I've been helpful then please give thanks ⤵

Mad_Moggies
Rising Star
Posts: 1,285
Thanks: 43
Registered: ‎01-08-2007

Re: How did this get through?

I understand about the scoring and how that affects the marking as Spam but don't understand why this very obvious rubbish got a better score than some legitimate emails.
Do you think this might be the only one of its sort sent to us for ages too, as well as received? As I said, nothing like it has got right through certainly since Postini has been doing the initial spam filtering, though there have been others similar (blank headers etc rather than random ones) landing in our Spam folders.
I have the Spam filter set to 3 and a list of whitelisted addresses with more to be added, so don't really want to set it any higher.
It's not a big deal but I'm just curious as to why it escaped detection.  Wink
Plusnet user since November 2003
Full Fibre since September 2023
Mac OS14 and Firefox user with latest versions of both
pierre_pierre
Grafter
Posts: 19,757
Thanks: 3
Registered: ‎30-07-2007

Re: How did this get through?

must have been bad luck - or unpredictable Postine
Quote
Return-path: <dcconfn@bewiser.net>
Envelope-to: mr@xxxxxxxxx.idps.co.uk
Delivery-date: Sun, 07 Sep 2008 08:30:36 +0100
Received: from exprod5mx213.postini.com ([64.18.0.72] helo=psmtp.com)
  by pih-sunmxcore15.plus.net with smtp (PlusNet MXCore v2.00) id 1KcEjE-00065o-0p
  for mr@xxxxxxxxxx.idps.co.uk; Sun, 07 Sep 2008 08:30:36 +0100
Received: from source ([217.44.235.5]) by exprod5mx213.postini.com ([64.18.4.13]) with SMTP;
Sun, 07 Sep 2008 00:30:33 PDT
Message-ID: <55844.dominick@borromeo>
Date: Sun, 07 Sep 2008 05:42:59 +0000
From: "addison srimat" <dcconfn@bewiser.net>
User-Agent: Thunderbird 2.0.0.12 (Windows/20080213)
MIME-Version: 1.0
To: "uyYeLLxUKqpiC" <mr@xxxxxxxxx.idps.co.uk>
Content-Type: text/plain;
charset=iso-8859-1
Content-Transfer-Encoding: 7bit
X-pstn-neptune: 500/334/0.67/86
X-pstn-levels:    (S: 1.97852/99.90000 CV:99.9999 )
X-pstn-settings: 1 (0.1500:0.1500) cv gt3 gt2 gt1
X-pstn-addresses: from <dcconfn@bewiser.net> [660/25]
X-pstn-neptune-cave-rslt: qtine
X-pn-pstn: Spam 1
X-PN-Virus-Filtered: by PlusNet MXCore (v4.00)
X-PN-Spam-Filtered: by PlusNet MXCore (v4.00)
Subject: [-SPAM-] CjXYBkIHNcAQOhuy
YBkIHNcAQOhu
pierre_pierre
Grafter
Posts: 19,757
Thanks: 3
Registered: ‎30-07-2007

Re: How did this get through?

definitely dodgy Postini just got this one
Quote
Return-path: <deanna.winfrey@gulfstream.com>
Envelope-to: sue@xxxxxxx.idps.co.uk
Delivery-date: Sun, 07 Sep 2008 10:50:44 +0100
Received: from exprod5mx292.postini.com ([64.18.0.136] helo=psmtp.com)
  by pih-sunmxcore15.plus.net with smtp (PlusNet MXCore v2.00) id 1KcGuq-0005RA-6k
  for sue@xxxxxxxxxx.idps.co.uk; Sun, 07 Sep 2008 10:50:44 +0100
Received: from source ([87.210.51.25]) by exprod5mx292.postini.com ([64.18.4.11]) with SMTP;
Sun, 07 Sep 2008 02:50:41 PDT
Message-ID: <63396.holly@baruch>
Date: Sun, 07 Sep 2008 08:03:18 +0000
From: "derick holly" <deanna.winfrey@gulfstream.com>
User-Agent: Thunderbird 2.0.0.12 (Windows/20080213)
MIME-Version: 1.0
To: "BfYwwn" <sue@xxxxxxx.idps.co.uk>
Content-Type: text/plain;
charset=iso-8859-1
Content-Transfer-Encoding: 7bit
X-pstn-neptune: 500/262/0.52/42
X-pstn-levels:    (S:25.44732/99.90000 CV:99.9999 )
X-pstn-settings: 1 (0.1500:0.1500) cv gt3 gt2 gt1
X-pstn-addresses: from <deanna.winfrey@gulfstream.com> [660/25]
X-PN-Virus-Filtered: by PlusNet MXCore (v4.00)
X-PN-Spam-Filtered: by PlusNet MXCore (v4.00)
Subject: gjGYAyWXljQTK
Mad_Moggies
Rising Star
Posts: 1,285
Thanks: 43
Registered: ‎01-08-2007

Re: How did this get through?

Gracious me, P-P, Postini thought that one ten times more respectable than the one we got this morning!!!  Shocked
Plusnet user since November 2003
Full Fibre since September 2023
Mac OS14 and Firefox user with latest versions of both
pierre_pierre
Grafter
Posts: 19,757
Thanks: 3
Registered: ‎30-07-2007

Re: How did this get through?

well it was sent to my wife Crazy
Mad_Moggies
Rising Star
Posts: 1,285
Thanks: 43
Registered: ‎01-08-2007

Re: How did this get through?

One overnight got well and truly caught in my Spam folder as it should do.  Smiley
To: "zJbbwBAKMk" <xxx@xxxx.plus.com>
Content-Type: text/plain;
    charset=iso-8859-1
Content-Transfer-Encoding: 7bit
X-pstn-neptune: 500/323/0.65/71
X-pstn-levels: (S: 1.28127/99.86050 CV:99.9999 )
X-pstn-settings: 1 (0.1500:0.1500) cv gt3 gt2 gt1
X-pstn-addresses: from <dcripleynn@smart-biggar.ca> [309/15]
X-pstn-neptune-cave-rslt: qtine
X-pn-pstn: Spam 1
X-PN-Virus-Filtered: by PlusNet MXCore (v4.00)
X-PN-Spam-Filtered: by PlusNet MXCore (v4.00)
Subject: GXRQMTejAcTaoAfPxzJ
       
Message was: ejAcTaoAfPxz
Plusnet user since November 2003
Full Fibre since September 2023
Mac OS14 and Firefox user with latest versions of both
Denzil
Grafter
Posts: 1,733
Registered: ‎31-07-2007

Re: How did this get through?

Bear in mind it may be obvious to you or any other reasonably savvy user, but you are an intelligent human who understands the language. Postini is a piece of computer software that doesn't understand anything, because computers are not intelligent. Imagine if you had to look at a piece of text in Chinese (I'm assuming you don't actually speak it!) and had to decide if it was spam. All you can do is look at the symbols and compare the text to examples of spam texts, without any understanding of what it means. That is basically what any spam filter has to do. It will inevitably make mistakes.
Mad_Moggies
Rising Star
Posts: 1,285
Thanks: 43
Registered: ‎01-08-2007

Re: How did this get through?

Not many people write a single word message containing random upper and lower case letters! I think that should count for something. They've all got a Spam rating of some sort anyway, however low, except for the last example pierre-pierre posted about, so Postini is succeeding in recognising them as dodgy most of the time.  Wink
(BTW, you assume correctly; I can just about distinguish between Chinese and Japanese characters but can speak/read neither language.)
Plusnet user since November 2003
Full Fibre since September 2023
Mac OS14 and Firefox user with latest versions of both