Re: [Asrg] Spammers looking for sites that don't bounce?

"Chris Lewis" <clewis@nortelnetworks.com> Thu, 26 June 2003 21:20 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA22224 for <asrg-archive@odin.ietf.org>; Thu, 26 Jun 2003 17:20:00 -0400 (EDT)
Received: (from exim@localhost) by www1.ietf.org (8.11.6/8.11.6) id h5QLJXN06202 for asrg-archive@odin.ietf.org; Thu, 26 Jun 2003 17:19:33 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19Ve9V-0001bx-OQ for asrg-web-archive@optimus.ietf.org; Thu, 26 Jun 2003 17:19:33 -0400
Received: from optimus.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA22180; Thu, 26 Jun 2003 17:19:29 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19Ve90-0001GU-47; Thu, 26 Jun 2003 17:19:02 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19Ve8a-0001Fg-3k for asrg@optimus.ietf.org; Thu, 26 Jun 2003 17:18:51 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA22143 for <asrg@ietf.org>; Thu, 26 Jun 2003 17:18:17 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19Ve8I-000671-00 for asrg@ietf.org; Thu, 26 Jun 2003 17:18:18 -0400
Received: from zcars04f.nortelnetworks.com ([47.129.242.57]) by ietf-mx with esmtp (Exim 4.12) id 19Ve88-00066c-00 for asrg@ietf.org; Thu, 26 Jun 2003 17:18:08 -0400
Received: from zcard307.ca.nortel.com (americasm07.nt.com [47.129.242.67]) by zcars04f.nortelnetworks.com (Switch-2.2.6/Switch-2.2.0) with ESMTP id h5QLH1d29768 for <asrg@ietf.org>; Thu, 26 Jun 2003 17:17:02 -0400 (EDT)
Received: from zcard031.ca.nortel.com ([47.129.242.121]) by zcard307.ca.nortel.com with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2653.13) id NLV61PF0; Thu, 26 Jun 2003 17:17:02 -0400
Received: from americasm01.nt.com (clewis-2.ca.nortel.com [47.129.150.136]) by zcard031.ca.nortel.com with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2653.13) id NLVG6DLS; Thu, 26 Jun 2003 17:17:02 -0400
Message-ID: <3EFB6395.5050803@americasm01.nt.com>
X-Sybari-Space: 00000000 00000000 00000000
From: Chris Lewis <clewis@nortelnetworks.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.0.2) Gecko/20030208 Netscape/7.02
X-Accept-Language: en-us, en
MIME-Version: 1.0
CC: asrg@ietf.org
Subject: Re: [Asrg] Spammers looking for sites that don't bounce?
References: <p0600170dbb200ed3a08e@[192.168.1.104]> <200306260310.h5Q3AawS027940@calcite.rhyolite.com> <p06001712bb20261c15d5@[192.168.1.104]>
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/pipermail/asrg/>
Date: Thu, 26 Jun 2003 17:20:21 -0400
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

Kee Hinckley wrote:

> I think you misread what I said.  I said that they are specifically 
> looking for NON-rejected messages to fake addresses as a sign that mail 
> is being filtered out without being bounced.

You couldn't prove that by my spamtrap.

It accepts everything, but doesn't forward anything anywhere.

The daily volume is going up very quickly (it's > 2 million/day now).

There are some very stupid dictionary scanners (one day 7+ million 
probes by an IP in singapore.  Next day another few million from another 
IP  in singapore. Rinse, lather and repeat.)


_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg