Re: KOREAN SPAM: HOWTO deal with it???

From:
Date: 09/13/02


Date: Fri, 13 Sep 2002 18:27:11 +0100

no-KOREAN-spam <nospam@NOSPAM-from.KOREA> writes:

> Koreans are not only the world's leading consumers of SPAM
> (the edible kind), but also the world's leading SOURCE of electronic
> SPAM. They are obstinate, persistent, and incessant, and simply ignore
> all politely worded complaints.

Is there some REASON you're SHOUTING half the time?

> Only Brazil and China come anywhere _NEAR_ creating the
> amoung to SPAM and UCE that they generate each day.

You don't mean spam or UCE. You mean UBE; that's what the problem is. All
UBE is theft, and it encompasses UCE and more. (And `spam' is a usenet-only
term, not applicable to email, and subject to too-many people's rather
vague and woolly "definition"s.)

[snip]
> QUESTION: Could someone kindly direct a newbie on how to deal with
> this problem?

I'd start with taking a deep breath and a cold shower, if I were you.

> Constant complaints to the webmasters do nothing. This poster is
> considering the following action(s): to set up the system so that any
> emails which are in Korean, or originate from Korea, are bounced back to
> the originators,

Naff idea. All you'll do is at least double the network bandwidth consumed,
probably treble it:
     a) incoming mail gets all the way in, that's 1 unit of processing;
     b) mail goes back out again, that's another unit (especially so if
        it subsequently bounces, as it will because the return-path is
        faked);
     c) mail goes on to abuse@, that's a 3rd unit;
     d) mail goes to a valid innocent user whose name was impersonated
        in the spam, well, you've got a lawsuit on your hands.

I'd say you're probably best-off filtering out
     1) mails with invalid syntax - use `headers_check_syntax' in exim;
     2) Korean IP#s - dig through APNIC to see what IP blocks the country
        has, and ban them from connecting to your mail-server.

Also, get a proper spam filter such as _ifile_, _spamprobe_ and
_spamassassin_ (pick one of the first two and definitely the latter), fold
up your probably-spam folder so you only read it once a week, check your
rejectlog for relay attempts and dump the perps into the IP#-block
periodically, see what happens.

~Tim

-- 
They did a dance called America             |piglet@stirfried.vegetable.org.uk
They danced it round                        |http://spodzone.org.uk/
And waited at the turns                     |



Relevant Pages

  • Re: anti-spamming, anti-spyware
    ... known as spam, then one way to combat UCE is to stop supporting ISPs ... Your ISP seems ... On your home computer, install Linux, then use the SpamBouncer, ...
    (comp.security.misc)
  • Re: Where is the charter for comp.unix.solaris?
    ... Junk mail is UCE although the ... UCE is referred to as spam. ... > postings that have gone before and therefore hits the Briedbart ... The difference being, no time range documentation needed, ...
    (comp.unix.solaris)
  • Re: FOUND A NEW PID "KIT"
    ... UCE is spam by definition. ... Spam is messages spewed across multiple newsgroups. ... There is no big picture. ...
    (alt.coffee)
  • Re: Sprungziel bei Abbildungen und Tabellen
    ... E-Mail copies of replies to this posting are welcome. ... Spam (UCE) is not ...
    (de.comp.text.tex)
  • Re: KOREAN SPAM: HOWTO deal with it???
    ... >> Koreans are not only the world's leading consumers of SPAM ... >> amoung to SPAM and UCE that they generate each day. ... You mean UBE; ... >> emails which are in Korean, or originate from Korea, are bounced back to ...
    (comp.os.linux.security)

Loading