CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Defeating the ...............

 
Post new topic   Reply to topic       All -> FavForums -> Mailwasher - Troubleshooting / General [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Bob

Guest
IP: 205.184.*.*






PostPosted: Sat Aug 02, 2003 4:05 am    Post subject: Defeating the ...............
Reply with quote

I have filter rules set to:

"The Body" "contains" "Viagra" and have "any rule below is satisfied" checked but still get messages in my box that are not removed as they should be.

Now I was confused at first, but when I took a look at the whole header, the bastards are encoding the file in html and inserting comment fields randomly interspersed throughtout the message, obviously to defeat spam blockers.

Does the iinsanity ever end!?!? Any way to defear this?[/quote]

Back to top
Sam

Guest
IP: 24.92.*.*






PostPosted: Sat Aug 02, 2003 5:28 am    Post subject:
Reply with quote

Yes , we need to find them and line them up and break there hands and fingers with a nice Louieville Slugger. Laughing

Back to top
dav4is

Guest
IP: 129.44.*.*






PostPosted: Sat Aug 02, 2003 8:54 am    Post subject:
Reply with quote

Yes, I've been seeing more of this lately.

Idea This tactic would be easily defeated if WW had an option in the filter to apply the BODY check to the HTML rendered text -- i.e. with all the markup removed.

-R.

Back to top
rusticdog

Site Moderator
Premium Member

Joined: Aug 12, 2002
Posts: 5850
Location: New_Zealand
Blue Security Firetrust Moderators Premium

PostPosted: Mon Aug 04, 2003 8:29 am    Post subject:
Reply with quote

Filtering for these tags is easiest.

Following is a filter another user has written to detect these, which with Mailwaher closed you can just copy/paste into your filters.txt file

[enabled],"[2] HTML Spam Tricks (B)","[2] HTML Spam Tricks (B)",16711680,OR,Blacklist,Delete,Body,containsRE,"font size=""?0""?",Body,containsRE,"((<![\w\s,\.\-]+>)+([\w\s,\.\-]){1,20}){3}",Body,containsRE,"(</\w>)[\w\s,\.\-]{1,20}(\1([\w\s,\.\-]){1,20}){2}"

For the full filter list this user has published, check out http://www.w5hq.com/MailWasher/MailWasherFilters.txt

Back to top
View users profile Send private message Send email Visit posters website Yahoo Messenger MSN Messenger
TimeGhost

Major
Major


Joined: Apr 11, 2003
Posts: 750
Location: USA
Team F@H

PostPosted: Mon Aug 04, 2003 3:28 pm    Post subject:
Reply with quote

Another exploit is one in which invalid html tags are inserted into spam keywords. For example, via<duh>gra would appear as viagra, but not get caught by Gary's filter.

Please read this thread for more information. HTH

Back to top
View users profile Send private message
jjmarsi

Guest
IP: 68.186.*.*






PostPosted: Mon Aug 04, 2003 7:34 pm    Post subject: Gary's filters are a godsend!
Reply with quote

I just wanted to give Gary some props here for his awesome filter list. I was getting bombarded with spam and was not really up to the task of building them myself. I copied them in, and the next time I ran MW, it caught a bunch of stuff it wouldn't have caught before!
Thanks again!

John
Very Happy

Back to top
IP: 80.62.*.*

Guest






PostPosted: Wed Aug 06, 2003 4:48 pm    Post subject:
Reply with quote

Sam wrote:
Yes , we need to find them and line them up and break there hands and fingers with a nice Louieville Slugger. Laughing


One day someone will "make an example of ..... "
and do something to one af them
that will scare the shit out of the rest !!! Evil or Very Mad Evil or Very Mad Evil or Very Mad

Back to top
directory

Guest
IP: 68.38.*.*






PostPosted: Tue Sep 02, 2003 11:46 am    Post subject:
Reply with quote

The file filters.txt is found, in, my gosh:
C:\Documents and Settings\sandy.USER-ZBYWXSO0KS\Application Data\MailWasher

I don't want the file in this crazy directory!
I want it in the same directory as MailWasher.exe.

How do I fix this?

Back to top
TimeGhost

Major
Major


Joined: Apr 11, 2003
Posts: 750
Location: USA
Team F@H

PostPosted: Tue Sep 02, 2003 1:54 pm    Post subject:
Reply with quote

You could use a shared list and put it in the MWP directory. But the automated features such as GUI edits and additions won't take effect on that shared file.

The current location makes sense in a multi-user environment. That way, each user can have his/her own lists of goodies and baddies.

Back to top
View users profile Send private message
!Wilbur

Cadet
Cadet


Joined: Aug 31, 2003
Posts: 7


PostPosted: Tue Sep 02, 2003 10:53 pm    Post subject: Re: Gary's filters are a godsend!
Reply with quote

jjmarsi wrote:
I just wanted to give Gary some props here for his awesome filter list. I was getting bombarded with spam and was not really up to the task of building them myself. I copied them in, and the next time I ran MW, it caught a bunch of stuff it wouldn't have caught before!
Thanks again!

John
Very Happy



Where can I get this list?

Back to top
View users profile Send private message
rusticdog

Site Moderator
Premium Member

Joined: Aug 12, 2002
Posts: 5850
Location: New_Zealand
Blue Security Firetrust Moderators Premium

PostPosted: Wed Sep 03, 2003 4:35 am    Post subject:
Reply with quote

Check out
http://www.w5hq.com/MailWasher/MailWasherFilters.txt

Back to top
View users profile Send private message Send email Visit posters website Yahoo Messenger MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Mailwasher - Troubleshooting / General All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer