CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer

A new filter set for MWP users brought to you by Wizcrafts!
Goto page Previous  1, 2, 3, 4, 5, 6, 7, 8, 9  Next
 
Post new topic   Reply to topic       All -> FavForums -> Mailwasher - Troubleshooting / General [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Wizcrafts

Sergeant
Sergeant
Premium Member

Joined: Jun 05, 2003
Posts: 95
Location: Michigan
Premium

PostPosted: Tue Dec 05, 2006 6:04 pm    Post subject:
Reply with quote

I just updated my most effective image spam filter to catch a new variant; jpegs instead of gifs. The rule must be on one continuous line, without spaces after the last character, and no blank lines between rules.

[enabled],"Image Spam type G/J","OE GIF Spam#2b",16711680,AND,Hidden,Delete,Automatic,EntireHeader,contains,"X-Mailer: Microsoft Outlook Express",EntireHeader,contains,"X-MimeOLE: Produced By Microsoft MimeOLE",EntireHeader,contains,"MIME-Version: 1.0",EntireHeader,contains,"Content-Type: multipart/related;",EntireHeader,contains,"type=""multipart/alternative"";",EntireHeader,contains,"boundary=""----=_NextPart_",Body,contains,"src=3D""cid:",Body,contains,"<META content=3D""MSHTML",Body,contains,"<IMG alt=3D""",Body,containsRE,"Content-Type:\ image/(gif|jpeg);"

Place this filter rule before the others, just under the restored from MWP recycle bin rule. It uses only one Regular Expression, thus is faster acting than the ones that rely more on them.


_________________
Submitted by Wiz
Guarding the Castle against spammers and scammers
Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger
Trapper

Trooper
Trooper


Joined: Feb 13, 2004
Posts: 28
Location: UK

PostPosted: Mon Dec 18, 2006 7:53 pm    Post subject:
Reply with quote

I would like to add english words to my own filters, I assume this is okay Question
I wish to auto delete any email containing certain words or varied spelling of words. For example, say I wanted to autodelete an email with 'relica watches' or 'repl1ica watcches' in the subject line how do you serparate the two sets of two words Question or if you have 6 spellings of viagra how do you enter these on one line of a filter rule Question With a comma, or full stop, or what Question Although I have them at present seperated with a comma I still seem to see these words in emails shown.

Back to top
View users profile Send private message
stan_qaz

Premium Member


Joined: Mar 31, 2003
Posts: 10594

Premium

PostPosted: Tue Dec 19, 2006 2:19 am    Post subject:
Reply with quote

There is some good filter help in the wiki, you might want to start there.


_________________
Questions? Try the wiki
http://wiki.castlecops.com/MailWasher_Pro
Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Wed Dec 27, 2006 3:09 pm    Post subject:
Reply with quote

I've been experimenting with the Wizcrafts filter set, and somewhere in the latest version there is a CPU leak I can't seem to find. What it seems to do is send the CPU into a continuous loop on loading Mailwasher, which is strange because I wouldn't think on load that Mailwasher would actually do anything with the filters other than load them. One further strange point on this issue, it works on the first load of Mailwasher just fine, the CPU utilization issue only occurs on the second or later load after installing the filter set. Anyone else have this problem?

One other question, should this thread be set as a sticky?


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
Wizcrafts

Sergeant
Sergeant
Premium Member

Joined: Jun 05, 2003
Posts: 95
Location: Michigan
Premium

PostPosted: Wed Dec 27, 2006 4:24 pm    Post subject:
Reply with quote

PCBruiser;
I don't notice any major problems with MWP loading, but I will try disabling the filters and re-enabling them one at a time, to see which ones are slowing it down the most. I know that regular expressions can slow down the processing time and a lot of my filters use RegExpr's. I have not been using all of the rules in my online filters and I am going to remove the ones that are not effective anymore. This will reduce the size of the filter set and improve loading times and processing. I'll post here when I have reduced the size and eliminated useless old tests for no longer existing spam domains.


_________________
Submitted by Wiz
Guarding the Castle against spammers and scammers
Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Wed Dec 27, 2006 5:03 pm    Post subject:
Reply with quote

One other thing that might give you a hint. The filter set is about 70K in total size. Once I start Mailwasher after replacing my old filter set, it grows to some 100K+ in size and then stays there. If I open the filter set either in Notepad or using Mailwasher's filter tool under Spam Tools, it looks exactly as it should, other than the file size being different. Strange. I wonder of Mailwasher does some kind of pre-processing or some such of the filter set, and that's why I have the problem on the second and later loads only?


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
Ikeb

Special Response Team
Forums Admin

Joined: Apr 20, 2003
Posts: 16506

Forums Admin Moderators MVP Premium SRT Team CC Committee Team F@H

PostPosted: Sun Dec 31, 2006 5:19 am    Post subject:
Reply with quote

PCBruiser wrote:
One other question, should this thread be set as a sticky?

I think that would be useful ... but perhaps some existing stickies should be unstickied? IMO the list of stickied topics shouldn't be too long. Also, perhaps one stickied topic referencing the wiki for lots of goodies might help set folks on the right track. Wink

Back to top
View users profile Send private message
measures

Trooper
Trooper


Joined: May 23, 2004
Posts: 17
Location: Ireland

PostPosted: Mon Jan 01, 2007 1:29 am    Post subject: I second Trapper's request re the 'already blacklisted'
Reply with quote

I agree with Trapper. If MW and I agree that something is already blacklisted, can we both ignore it and move on?
I still want to see the 'proposals for blacklisting' though.
Wink

Back to top
View users profile Send private message
mlrichardson

Captain
Captain
Premium Member

Joined: Jun 16, 2005
Posts: 424
Location: Capitola, California, USA on the shores of the blue - and cold - Pacific
Premium

PostPosted: Tue Jan 02, 2007 8:39 pm    Post subject: A new filter set for MWP users brought to you by Wizcrafts!
Reply with quote

On the subject of blacklisting, one needs to be careful assuming a blacklisted address is really a spammer. If a filter, or the Learning tool sets an address to the blacklist, it could be an address duplicated by a spammer on a one-off. That address might just turn out to be a friend whose address got "appropriated." I'm to the point I don't have any filters or the Learning tool blacklist anything. You just never know. If the email is flagged by the Learning tool as "Possible Spam", it usually is. If a filter flags an email as spam, it usually is, but not just because of the address.

If the blacklist lists flag an address, that's a different story. You can assume anything coming from those addresses is spam - today. But maybe not tomorrow, since valid addresses land on those lists, the owners complain, and they get removed.

Recently all my email to one of my sons was bounced. My IP (a legacy IP in the AT&T system), was being blacklisted by Comcast because too much spam was being sent from the IP. Since the IP has tens of thousands of users, that seems a bit extreme. On a smaller scale, though, that's what can happen with blacklisting.

Useful blacklisting is for the "friend" who sends too many chain letters, forward-forward-forward useless emails, etc; or someone you just don't want to receive email from. Even then I'm not sure I would have an auto-delete on the address.


_________________
Mike Richardson
MS Windows XP, SP2;
Vipre (Beta) Anti-Virus & Anti-Spyware
Firefox 3.0, Thunderbird 2, MWPro 6 (beta), WP Office X3

It is for the superfluous we sweat.
-Seneca (the younger)
Back to top
View users profile Send private message
stan_qaz

Premium Member


Joined: Mar 31, 2003
Posts: 10594

Premium

PostPosted: Tue Jan 02, 2007 9:15 pm    Post subject:
Reply with quote

Don't confuse the two types of blacklisting, by e-mail address and by IP address.

Blocking by the sender's e-mail address is only useful where the sender does not know how to forge an e-mail, or use Google.

The sender's or transferring system's IP address is much more difficult to forge and that is what DNSBL (IP blacklisting aka RBL or Source of Spam) blacklisting is all about.

IP blacklisting IS NOT a tool for proving a message is spam, all it indicates is that one or more of the IP addresses in the mail header is associated with a server that has a history of sending spam or other problems. Therefore it should never be used as a reason to delete mail, only as an indicator that there is a greater chance of the message being spam than a message not so tagged. The rules for inclusion vary by the DNSBL provider and you need to look them over before deciding to bother using one.


_________________
Questions? Try the wiki
http://wiki.castlecops.com/MailWasher_Pro
Back to top
View users profile Send private message
Ikeb

Special Response Team
Forums Admin

Joined: Apr 20, 2003
Posts: 16506

Forums Admin Moderators MVP Premium SRT Team CC Committee Team F@H

PostPosted: Wed Jan 03, 2007 6:21 am    Post subject:
Reply with quote

BTW IP blacklisting is usually called "Blocklisting" ... maybe to signify a contiguous block of IP addresses, that addresses are blocked, ... or both. Smile

Back to top
View users profile Send private message
stan_qaz

Premium Member


Joined: Mar 31, 2003
Posts: 10594

Premium

PostPosted: Wed Jan 03, 2007 2:02 pm    Post subject:
Reply with quote

It really depends on the spammer's setup, some are able to move their spam server arund a block of addresses that are assigned to them, usually a class C network or smaller, so just blocking the whole thing is the easy way to go.

That can be a bit hard on others sharing the same address space but it is up to them to get their net provider to quit hosting spammers or move to a less spammy provider.


_________________
Questions? Try the wiki
http://wiki.castlecops.com/MailWasher_Pro
Back to top
View users profile Send private message
Dragan_Glas

Team CC Chief Host
Team CC Chief Host
Chess Board Host
Chess Board Host

Joined: May 27, 2004
Posts: 2899

Premium RootKit Detection Hosts Rootkit Responders SRT Team CC Committee

PostPosted: Mon Jan 08, 2007 9:50 pm    Post subject:
Reply with quote

Greetings,

Just a FYI...

I notice that when one clicks on the link to Wizcraft's filters, McAfee pops-up a "Exploit-MIME.gen" VirusScan Alert warning.

I assume that this is because it tries to automatically install itself in MW(P)?

Kindest regards,

Dragan Glas


_________________
Quote:
The only secure computer is one that's unplugged, locked in a safe, and buried 20 feet under the ground in a secret location... and I'm not even too sure about that one
Dennis Hughes, FBI
Back to top
View users profile Send private message
stan_qaz

Premium Member


Joined: Mar 31, 2003
Posts: 10594

Premium

PostPosted: Mon Jan 08, 2007 10:38 pm    Post subject:
Reply with quote

Nope, it is just a page full of letters, doesn't try to do anything like that.

I'd guess that your McAfee isn't smart enough to recognize the between filter text and a real attack and is false triggering.

So glad I don't do Windows!


_________________
Questions? Try the wiki
http://wiki.castlecops.com/MailWasher_Pro
Back to top
View users profile Send private message
Dragan_Glas

Team CC Chief Host
Team CC Chief Host
Chess Board Host
Chess Board Host

Joined: May 27, 2004
Posts: 2899

Premium RootKit Detection Hosts Rootkit Responders SRT Team CC Committee

PostPosted: Mon Jan 08, 2007 10:56 pm    Post subject:
Reply with quote

Greetings,

stan_qaz
I don't actually use McAfee at home, I use Avira - this was at work.

I wasn't sure whether that meant that Avira (at home) was missing something or that McAfee (at work), as you say, is reporting a FP.

Kindest regards,

Dragan Glas


_________________
Quote:
The only secure computer is one that's unplugged, locked in a safe, and buried 20 feet under the ground in a secret location... and I'm not even too sure about that one
Dennis Hughes, FBI
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Mailwasher - Troubleshooting / General All times are GMT
Goto page Previous  1, 2, 3, 4, 5, 6, 7, 8, 9  Next
Page 3 of 9

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer