convincing spam from CNN
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- Broadband
- :
- convincing spam from CNN
Re: new convincing spam from CNN
05-08-2008 9:44 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
See headers below, 1st is from a message delivered to my PN account, 2nd is a message blocked by postini on my corporate account.
Return-path: <vaavaava_1956@3dfa.com>
Envelope-to: XXX@YYY.COM
Delivery-date: Tue, 05 Aug 2008 15:06:38 +0100
Received: from exprod5mx253.postini.com ([64.18.0.48] helo=psmtp.com)
by pih-sunmxcore19.plus.net with smtp (PlusNet MXCore v2.00) id 1KQNBM-0000AZ-3B
for XXX@YYY.COM; Tue, 05 Aug 2008 15:06:36 +0100
Received: from source ([68.163.225.52]) by exprod5mx253.postini.com ([64.18.4.14]) with SMTP;
Tue, 05 Aug 2008 09:06:33 CDT
X-mailed-to: XXX@YYY.COM
X-To: cnn-dailytop10#*#XXX@YYY.COM
X-job: 20080801155902.cnn-dailytop10.5299
Message-Id: <20080801155902.cnn-dailytop10@mail.cnn.com>
From: "Daily Top 10" <vaavaava_1956@3dfa.com>
To: XXX@YYY.COM
Date: Tue, 5 Aug 2008 10:06:27 -0400
Content-type: multipart/alternative; boundary="053vmiiwg741"
MIME-version: 1.0
X-pstn-neptune: 233/226/0.97/86
X-pstn-levels: (S:79.83032/99.90000 CV:99.0000 R:95.9108 P:95.9108 M:97.0282 C:98.6951 )
X-pstn-settings: 1 (0.1500:0.1500) cv gt3 gt2 gt1 r p m c
X-pstn-addresses: from <vaavaava_1956@3dfa.com> [255/11]
X-pstn-xfilter: y
X-PN-Virus-Filtered: by PlusNet MXCore (v4.00)
X-PN-Spam-Filtered: by PlusNet MXCore (v4.00)
Subject: CNN.com Daily Top 10
Received: from source ([200.100.91.137]) by exprod6mx229.postini.com ([64.18.5.11]) with SMTP;
Tue, 05 Aug 2008 14:39:31 EDT
X-mailed-to: AAA@BBB.COM
X-To: cnn-dailytop10#*#AAA@BBB.COM
X-job: 20080801155902.cnn-dailytop10.6504
Message-Id: <20080801155902.cnn-dailytop10@mail.cnn.com>
From: "Daily Top 10" <Dmitri-giretnel@mediateca2000.it>
To: AAA@BBB.COM
Date: Tue, 5 Aug 2008 15:39:42 -0300
Subject: CNN.com Daily Top 10
Content-type: multipart/alternative; boundary="043jkuuex633"
MIME-version: 1.0
X-pstn-neptune: 500/494/0.99/86
X-pstn-levels: (S:85.91170/99.90000 CV:99.0000 R:95.9108 P:95.9108 M:97.0282 C:98.6951 )
X-pstn-settings: 4 (1.5000:1.5000) s cv gt3 gt2 gt1 r p m c
X-pstn-addresses: from <Dmitri-giretnel@mediateca2000.it> [341/15]
X-pstn-xfilter: y
X-pstn-disposition: quarantine
Answers anyone?
SW.
3Mb FTTC
https://portal.plus.net/my.html?action=data_transfer_speed
Re: new convincing spam from CNN
05-08-2008 11:02 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: new convincing spam from CNN
05-08-2008 11:19 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Postini unconditionally designate any message with that header as spam and quarantine it. Currently the Plusnet tagging rules do not.
If Plusnet change their rules there is a risk that genuine messages could get incorrectly tagged as spam. I have one example where that header is included in a genuine message, 3 with it that are spam (2 being the CNN Top 10 spoof).
Does anyone else have *genuine* messages where that header is incorrectly included?
David
Re: new convincing spam from CNN
05-08-2008 11:58 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I've just received another one, so clearly, even if Postini have been informed, they haven't done anything.
Re: new convincing spam from CNN
06-08-2008 12:00 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: new convincing spam from CNN
06-08-2008 12:06 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Rgds
Chris
Re: new convincing spam from CNN
06-08-2008 1:05 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Users of Outlook (not Outlook Express) and (I think) Thunderbird could also help by setting up a mail filter rule to move messages containing the X-pstn-xfilter: header to a specially created folder. The rule could be run retrospectively on existing Inbox contents to check past history.
Unfortunately I don't think Outlook Express allows mail filters to be based on the presence of a specific header.
David
Re: new convincing spam from CNN
06-08-2008 1:05 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
But zero from CNN.
"In The Beginning Was The Word, And The Word Was Aardvark."
Re: new convincing spam from CNN
06-08-2008 1:11 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: new convincing spam from CNN
06-08-2008 8:47 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I'll try the filter thing with my Mac's Mail program, which can filter on headers. I'll pick up the ones sent to me and to our joint address and anything else that gets marked in the same way (just continuing monitoring and deleting those in webmail for my husband's address and the catch-all).
Full Fibre since September 2023
Mac OS14 and Firefox user with latest versions of both
Re: new convincing spam from CNN
06-08-2008 9:49 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: new convincing spam from CNN
06-08-2008 9:51 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Unfortunately, it's using a Global Pattern Match rule to flag it, which the Plusnet system's aren't (yet) matching Spam on
This means it's slipping through the PN mail servers at this end.
B.
Re: new convincing spam from CNN
06-08-2008 9:59 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: new convincing spam from CNN
06-08-2008 10:16 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Postini use a couple of different methods of flagging the spam, and the Plusnet mail servers haven't been configured to act on all of those. Particularly the X-pstn-filter: header which is used to handle exactly this situation.
There is current discussion ongoing about the best way to handle items that are flagged using the X-pstn-filter header.
B.
Re: new convincing spam from CNN
06-08-2008 10:27 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page