IWETHEY v. 0.3.0 | TODO
1,095 registered users | 0 active users | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New Ideas of handling backscatter spam, please?
For those unaware what "backscatter spam" is, it's when a spammer uses your email address as the From: address in a spam email to an address that doesn't exist. The mail server it's sent to unfortunately accepts it before checking the mailbox name, then has to generate a bounce message and only has the forged From address.

I've been getting backscatter spam for a couple of weeks. All of them originate from a server hiding in business.telecomitalia.it who hasn't responded to my emails. I'm tempted to put a filter rule in place to reject any email that mentions that domain. But what I really want to do is get telecomitalia.it blacklisted on the various spam lists. Instructions for doing this seems to be impossible to find. Anyone know how to achieve that?

I guess I could locate their upstream providers and bother them. Or contact RIPE, since that's where I got the email address for telecomitalia.it. (Address registries *really* don't like people who list addresses in IP records and then don't respond to them.)

Thoughts? Ideas? Comments?

Wade.
Just Add Story http://justaddstory.wordpress.com/
New Block the IP Address.
Its drastic... but hey it works.
New That's not going to work.
Because I would be blocking IP addresses of numerous ISPs including Yahoo.

I'm getting the bounces from email sent to others using my email address as the From address. I'm getting last-chain backscatter spam. I'm pretty sure I said this in the initial post.

Wade.
Just Add Story http://justaddstory.wordpress.com/
New Didn't crazy do a lot of work on stuff like this??
New No, I only send it
New Ha!
New Misread your post...
Sorry, I thought you were getting it only from the one machine/ISP
New Spamcop.net?




New It's a start.
Their FAQ doesn't mention backscatter spam, so I'll look in the forums just to see.

Wade.
Just Add Story http://justaddstory.wordpress.com/
New Reject the domain
but don't reject it... just drop it silently.
New Ah. Someone else who didn't read it all.
business.telecomitalia.it never emails me directly. I'm getting the rejected messages from the people they are spamming.

Wade.
Just Add Story http://justaddstory.wordpress.com/
New That's why I said reject the domain
not the host. If you can create blacklists, put "*@*.telecomitalia.it" in it. I'm assuming you can specify To:, From:, and the SMTP envelope entries as well. Depends on the capabilities of your server to a certain extent.
New Ah. I see.
I was going to look into something like that, but the filter has to look through the whole message. I'm not sure it can do that.

Wade.
Just Add Story http://justaddstory.wordpress.com/
New backscatterer.org?
We have not had to deal with this for quite some time, so this is only the result of a Google search, but backscatterer.org seems to provide the means you are looking for.
New Doesn't even resolve for me.
I think I found this linked to earlier.

Wade.
Just Add Story http://justaddstory.wordpress.com/
New Strange... It resolves across the pond.
New You sure you used it?
With the final 2 "er" in it?
New http://www.backscatterer.org/
http://www.backscatterer.org/
New Pretty sure I did.
Copy'n'paste, doncha'know.

Resolves at work, though, so I clearly need to kick my home resolver...

Wade.
Just Add Story http://justaddstory.wordpress.com/
New Just making sure
I typod (not c&p) when I 1st tried.
New Huh. It works now. Thanks all!
Just Add Story http://justaddstory.wordpress.com/
     Ideas of handling backscatter spam, please? - (static) - (20)
         Block the IP Address. - (folkert) - (5)
             That's not going to work. - (static) - (4)
                 Didn't crazy do a lot of work on stuff like this?? -NT - (Another Scott) - (2)
                     No, I only send it -NT - (crazy) - (1)
                         Ha! -NT - (mmoffitt)
                 Misread your post... - (folkert)
         Spamcop.net? - (pwhysall) - (1)
             It's a start. - (static)
         Reject the domain - (jake123) - (3)
             Ah. Someone else who didn't read it all. - (static) - (2)
                 That's why I said reject the domain - (jake123) - (1)
                     Ah. I see. - (static)
         backscatterer.org? - (scoenye) - (7)
             Doesn't even resolve for me. - (static) - (6)
                 Strange... It resolves across the pond. -NT - (scoenye)
                 You sure you used it? - (crazy) - (4)
                     http://www.backscatterer.org/ - (folkert)
                     Pretty sure I did. - (static) - (2)
                         Just making sure - (crazy) - (1)
                             Huh. It works now. Thanks all! -NT - (static)

Tasty little nuggets of alien technology...
158 ms