extending the MAPS search |
Post Reply ![]() |
Author | |
StevenJohns ![]() Senior Member ![]() Joined: 03 August 2006 Status: Offline Points: 119 |
![]() ![]() ![]() ![]() ![]() Posted: 06 September 2006 at 9:51am |
Roberto, I have been getting hammered by a hacker who seems to be sending an email apparently from an insurance company which is 800kb in size. So far we have got over 4000 of these !!!! It appears that this user is connecting to BT (here in the UK) and using their server to relay his email. Now, BT's server isn't blacklisted in any of the usual lists, but the IP of the hackers machine is !!! Now, as I understand it, the maps checker will only check on the IP that connected to SF. But what if that IP is ok, but the IP of the origional sender is listed.....but they used a relay that was good (at the moment). Can you extend the maps checker to check not just the IP that connected to SF, but also include all of the IP's in the chain right back to the origional senders server?? Below is a section of the offending headers. Received: from 194.73.73.210 by mail.protected-mail.co.uk (LogSat Software SMTP Server); Wed, 6 Sep 2006 11:16:14 +0100
As you can see, we received the email from 194.73.73.210 (one of BT's servers) that is not blacklisted, however, this was an relayed email from 217.43.193.123 (the hacker's dial-up address) which is listed in dnsbl.sorbs.net, yet SF let the email through.
|
|
![]() |
|
LogSat ![]() Admin Group ![]() ![]() Joined: 25 January 2005 Location: United States Status: Offline Points: 4104 |
![]() ![]() ![]() ![]() ![]() |
Sorry... SpamFilter can and will only act upon the IP address that connects to it, as using any information contained in the headers can lead to false positives. All headers can be faked by the sender, and spammers could use them to inject invalid data that could cause unwanted side-effects.
...however. In the SpamFilter.ini file there is the following option: ;if ScanReceivedHeaders is set to 1 SpamFilter will add the "Received:" headers to the text examined for keywords and statistical Bayesian searches. ScanReceivedHeaders=1 You could enable it, and then add a keyword in your blacklist to block the IP address mentioned in the headers. |
|
![]() |
|
StevenJohns ![]() Senior Member ![]() Joined: 03 August 2006 Status: Offline Points: 119 |
![]() ![]() ![]() ![]() ![]() |
excellent...that'll do nicely !
|
|
![]() |
Post Reply ![]() |
|
Tweet
|
Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |
This page was generated in 0.223 seconds.