How to spot a spammer

jes

MyBroadband Alumnus
Joined
Nov 11, 2009
Messages
11,992
Reaction score
123
How to spot a spammer

New initiative, called ZA Spam Spotters, aims to name and shame spammers on social media networks
 
Last edited:
Hoe to spot a spammer

Spammer found!

hoe.jpg
 
Thanks guys! The day's off to a good start :D
 
First gate: You write to me in English, you go into the 'possible' folder.
Second gate: Message in poor English, proceed to 'very possible' folder
 
plastering spammers names al over the place is like a reward to them..
 
Please correct me if I am wrong, but there are no South African IP black lists. Our mail server allows us to enter custom blacklist providers. Why does ISPA and SpamSpotters not create a webservice of some sort and blacklist these spammer scums using a SA spam blacklist?

Also, how come the ISP industry is not able to stop these bank spam emails? SURELY they are capable of getting the 3 or 4 South African banks email IP addresses (there really can't be that many) and white list those, anything that has FNB or ABSA in the subject/contents that does not originate from these collected IP's and just dumb the email?

Personally, I don't think naming and shamming helps. Give me the IP's and I'll block them. surely that will have a bigger impact than namming and shamming?
 
I agree, name and shame is a joke. SA needs to do more to permanently block these spammers.
 
Please correct me if I am wrong, but there are no South African IP black lists. Our mail server allows us to enter custom blacklist providers. Why does ISPA and SpamSpotters not create a webservice of some sort and blacklist these spammer scums using a SA spam blacklist?

Also, how come the ISP industry is not able to stop these bank spam emails? SURELY they are capable of getting the 3 or 4 South African banks email IP addresses (there really can't be that many) and white list those, anything that has FNB or ABSA in the subject/contents that does not originate from these collected IP's and just dumb the email?

Personally, I don't think naming and shamming helps. Give me the IP's and I'll block them. surely that will have a bigger impact than namming and shamming?

from the ISPA side bear in mind that even with the limited information available on the public hall of shame ISPA has been referred to the competition authorities and sued in the High Court (judgement pending)...there are some nasty issues at play which are not helped by the weak anti-spam legislation currently in place

re the bank phishing mails - problem is not the traditional ISPs who know IP and how to run an abuse desk...most of this is coming through the mobile networks
 
Each South African ISP makes use of their own set of filtering rules. This then allows the spammer to bounce from one provider to another.

The providers need to come together, forget all about their politics and share their current filters with each other. We are currently working on a South African RBL (based on criteria) that we will make public. It is then up to each mail server admin out there to decide whether they would like to make use of it, with their current anti-spam rules.

As for blocking IPs - we have found spammers to set the TTLs as low as possible in order to change a blocked IP and move on to the next one. So you end up with an outdated list within days for a specific domain.

The bigger problem really comes to how easy it is to register a domain for spam purposes only.

For instance, all of the domains mentioned below are registered (but not paid for) by the same registrant and ready for suspension as per COZA schedule.

2a. Registrant: Expertmail

- carcoversa.co.za
- get-carcover.co.za
- get-hospitalcover.co.za
- hospitalcovernow.co.za
- insurance-cover-options.co.za
- sa-life.co.za
- sa-lifeinsure.co.za
- sa-life-insure.co.za

Their MX and WWW record all points to international ISPs. There are various other domains that we have picked up using the exact same ammo. (http://co.za/cgi-bin/whois.sh?Domain=sa-life-insure.co.za&Enter=Enter)

Now it would definitely help if Uniform comes to the party as the registrar and remove these domains from the COZA zone and quite possibly ban the registrant from registering any additional domains:

2a. registrant : ExpertmaiL
2b. registrantpostaladdress: Po Box 210, CPT,-, , ,
2c. registrantstreetaddress: Po Box 210, CPT
2j. registrantphone : +27.218582244
2k. registrantfax : +27.218582244
2l. registrantemail : [email protected]


The process seems to be

a) register a domain
b) spam
c) COZA suspension & deletion for non-payment
d) register a new domain and repeat

We are aware that they are changing the registration process to only allow delegation into the COZA zone after payment received, but given the low cost for a domain, we are not sure it would help curb this particular problem.


We are not just about name & shaming; we need to be proactive as well since nobody else seems to be taking the lead. ISPA been doing great things, and let’s not forget TrustFabric as national opt-in/opt-out register (hopefully).

We need to start somewhere. Work with us. We are open to suggestions and any other constructive feedback.


#ZASS
 
I really agree the solution should be largely technical - and SA can be proud of innovative prowess.

When I set the saci domain as spam on my mailbox, I would like a signal to go out to a common server which monitors trends and picks up that a minimum threshold of other people are doing the same. That would trigger an update to the spamfilters at the ISP level to block the email address and possibly even the domain. I am sure that's what Google and Hotmail do anyway - making use of their larger base.

Granted, there needs to check for false positives, but that's a detail. The main point is the use of the collective information.
 
Spam buster • 3 hours ago
ZA spam spotters need to take time to understand the difference between spammy senders and ESPs. We are all for anti-spam practices but they should first get their facts right and not take the cowboy approach.

You have a very valid point.

We are not taking the cowboy approach with this initiative. We have spent a lot of hours studying & discussing amongst ourselves and with other industry experts. This is the current way forward for us.

We are a group of people that are currently employed in the IT industry and specialises in various fields. Some of us run and maintain large mail clusters, work at Internet Service Providers, DBA, web development, engineers; one is with big red mobile provider and so forth. A lot of years of experience in this group and we want to use it, in order to not only combat this particular virus, but also educate at the same time.

We should just point out, that this is not an all-boys club though, and had a good chuckle at the Mybroadband staff writer referring to a “he”.

We understand the challenges, we understand the differences as pointed out by you, and we are trying out a new approach. It is of course very easy to stand on the side lines and shout, but we invite you, to come and help.

We will not only name & shame, but will be engaging/notifying the people of such listings and that is a slight difference between us and ISPA’s Hall of Shame. Every quarter or so, an updated version of the list comes out and surprise people. We are not taking away the hard work that has gone into the Hall of Shame, hours and hours of working through spam submissions, keeping track of data and everything else that goes with it.

ISPA took the initial step in taking on spammers and of course, it is up to us all, to decide whether we want to use that list on our mail servers. They are certainly not forcing it down anybody’s throat. Let’s not forget about the current legal issue between them and Ketler Presentations. The outcome will be ground-breaking for the South African community. Either we will be moving forward and have the law behind us, or set us back years & years.

We are also busy developing a functional website linked to the Spammer database, which will include statistics, RBL, whitelistings, search functionality on domain, IPs etc in order to see why they are listed, when they were listed, when last a complaint lodged against them. We are not going to hide the complaints. If you spammed, we will have that spam in the database, and anybody can look at it. The recipients will be removed to avoid future harvesting.

We are busy liaising with Project Honeypot and being proactive by notifying South African ISP to clean up their act, make sure their IPs are reputable. Have a look for instance at http://www.projecthoneypot.org/list_of_ips.php?t=h&ctry=ZA&rf=131674 . Do ISPs actually care about their reputation out there?

We want to engage with the community here and work together. As mentioned earlier, why can ISPs not work with each other and stop a spammer from moving ISPs. Why can Uniform, the current COZA registrar, not do something about domains registered purely for spam?

Sure, we are open to some abuse, one reader of MyBroadband pointed out that giving out our email address is not clever and he knows people that will be bombarding us; we are going to make some mistakes, but we will own up, and learn from it and be better at it.

We welcome all suggestions, all support, and anybody can email us for assistance, to complain or whatever the case might be. Catch us on Facebook/Twitter. We all have full time job, so responding might be delayed from time to time, but we will respond.

This is our start. Help us, to help you.

#ZASS
 
Last edited:
@zaspamspotters - do you rely on feedback from spamhaus, spamcop etc?

We are focusing on South African spam only. While we are certainly engaging with other anti spam entities, we unfortunately have to focus on a battle we should be able to win :)

We will be using data from various dns rbls; for instance to look at ZA IP space's reputation and hopefully be able to clean it up with those ISPs willing to do so. We are also looking at making use of various spam-trap addresses asking people to donate a mailbox on their domains in order to do stats etc.

Every bit helps.
 
Also, how come the ISP industry is not able to stop these bank spam emails? SURELY they are capable of getting the 3 or 4 South African banks email IP addresses (there really can't be that many) and white list those, anything that has FNB or ABSA in the subject/contents that does not originate from these collected IP's and just dumb the email?
http://wl.org.za/ has been running for a few years now but only a small number of providers use it.
 
Last edited:
Top
Sign up to the MyBroadband newsletter
X