CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 930
Comments: 25
block bottom
spacer spacer

A new filter set for MWP users brought to you by Wizcrafts!
Goto page Previous  1, 2, 3, 4, 5, 6, 7, 8, 9  Next
 
Post new topic   Reply to topic       All -> FavForums -> Mailwasher - Troubleshooting / General [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Wizcrafts

Sergeant
Sergeant
Premium Member

Joined: Jun 05, 2003
Posts: 95
Location: Michigan
Premium

PostPosted: Fri Jun 15, 2007 10:12 pm    Post subject: MWP Custom Filter Rules Have Been Updated
Reply with quote

Hi guys and gals. It's been a while since I dropped by this thread, named after my filter rules for MailWasher Pro. I wanted to let you know that I have been updating the rules on my website and have split them into two groups; full and abbreviated. I use the abbreviated rules myself and recommend them to most users. Both sets are now available on this page:

http://www.wizcrafts.net/mwp-filters.html

The Image Spam filters are the most frequently applied rules, since the majority of the spam I get is image spam for junk stocks and silly drugs. I have also created special rules to deal with the HopOne hosted .info spammers who inundate our Inboxes with their junk.

Since I have to live with these filters myself I try to keep the processing time to an acceptable level, considering the complexity of some of my rules. Make no mistake, the image spam rules will slow delivery of any email containing images, as it searches for regular expressions matches. If you find them to be too slow for you try disabling some of the images spam filters, wait for them to "take," then check you email again. You may find that you can live without some of my rules, based on the type of spam you are personally getting, or not getting.

Later guys...


_________________
Submitted by Wiz
Guarding the Castle against spammers and scammers
Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger
Wizcrafts

Sergeant
Sergeant
Premium Member

Joined: Jun 05, 2003
Posts: 95
Location: Michigan
Premium

PostPosted: Fri Jul 06, 2007 9:10 pm    Post subject: Wizcrafts' MailWasher Filter Rules Updated for PDF and Spam
Reply with quote

Hey Y'all, I wanted to let you know that I have been updating my MailWasher Pro filter rules to block the new PDF attachment spam for pump-n-dump stocks, or illicit pills, and also to block the latest round of greeting postcard scams that have links to ecard Trojan Horse programs hosted on zombie home or business computers that are infected with the Yodi Worm, or similar threats. You can download, or copy/paste the new rules on my MailWasher Filters page.


_________________
Submitted by Wiz
Guarding the Castle against spammers and scammers
Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger
Dragan_Glas

Team CC Chief Host
Team CC Chief Host
Chess Board Host
Chess Board Host

Joined: May 27, 2004
Posts: 2894

Premium RootKit Detection Hosts Rootkit Responders SRT Team CC Committee

PostPosted: Thu Jul 12, 2007 10:15 am    Post subject:
Reply with quote

Greetings,

Wizcrafts
I've been using your filters for some years now with MWP (and as a Beta Tester) and have found them extremely useful. Thumbs Up

I was just wondering how exactly your PDF filter works...

Quote:
[enabled],"PDF Spam","PDF Spam",16711680,AND,Blacklist,Delete,Automatic,Subject,contains,.pdf,Body,contains,"Content-Type: application/pdf;",Body,contains,"Content-Disposition: inline;",Body,contains,"Content-Transfer-Encoding: base64",EntireHeader,contains,"User-Agent: Thunderbird"


Does it simply filter all emails with PDF attachments or just those whose PDF attachments meet certain criteria? And if the latter, what are these criteria - I'm not quite au fait with what the rest of the above filter means. Embarassed

Kindest regards,

James


_________________
Quote:
The only secure computer is one that's unplugged, locked in a safe, and buried 20 feet under the ground in a secret location... and I'm not even too sure about that one
Dennis Hughes, FBI
Back to top
View users profile Send private message
Wizcrafts

Sergeant
Sergeant
Premium Member

Joined: Jun 05, 2003
Posts: 95
Location: Michigan
Premium

PostPosted: Thu Jul 12, 2007 5:17 pm    Post subject:
Reply with quote

Dragan_Glas wrote:
Greetings,

Wizcrafts
I've been using your filters for some years now with MWP (and as a Beta Tester) and have found them extremely useful. Thumbs Up


Thanks!

Quote:

I was just wondering how exactly your PDF filter works...

Quote:
[enabled],"PDF Spam","PDF Spam",16711680,AND,Blacklist,Delete,Automatic,Subject,contains,.pdf,Body,contains,"Content-Type: application/pdf;",Body,contains,"Content-Disposition: inline;",Body,contains,"Content-Transfer-Encoding: base64",EntireHeader,contains,"User-Agent: Thunderbird"


Does it simply filter all emails with PDF attachments or just those whose PDF attachments meet certain criteria? And if the latter, what are these criteria - I'm not quite au fait with what the rest of the above filter means. Embarassed

Kindest regards,

James

James;
This filter works by matching ALL of the conditions listed above, which include the subject, the headers, the body and the user agent. Even though these rules don't override your friends list I strongly advise everybody to keep all desired contacts in the MWP whitelist, to avoid having any one of my rules accidentally delete a legit email. However, these pdf spam messages are all basically the same and meet all of my rules. If and when the spammer changes to details I will catch it in my honeypot and update my filters to match and catch, which is usually within a few hours of the release of a new spam run.

BTW: You may want to remove "Blacklist," from the actions and just delete automatically. This will keep the blacklist from growing out of proportion if you get a lot of these useless pieces of garbage email.

PS: If I explain the exact details all of the World will know what I know, including the bad guys.


_________________
Submitted by Wiz
Guarding the Castle against spammers and scammers
Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger
Dragan_Glas

Team CC Chief Host
Team CC Chief Host
Chess Board Host
Chess Board Host

Joined: May 27, 2004
Posts: 2894

Premium RootKit Detection Hosts Rootkit Responders SRT Team CC Committee

PostPosted: Fri Jul 13, 2007 9:56 am    Post subject:
Reply with quote

Greetings,

Wizcrafts
Thank you for the explanation! Thumbs Up

As regards your concerns about revealing too much in a publicly-accessible topic - and bearing in mind your other posts where you mentioned the spammers may be/are watching - I wonder would it be an idea to have a "Private" forum for you and staff members to discuss the finer points of and share suggestions for your filters?

The current public topic could then just be used for announcements of new/updated filters.

Public forums could allow discussion of general ideas/advice to everyone for filtering and/or "rolling your own" filter-sets.

Just a thought! Very Happy

Kindest regards,

James


_________________
Quote:
The only secure computer is one that's unplugged, locked in a safe, and buried 20 feet under the ground in a secret location... and I'm not even too sure about that one
Dennis Hughes, FBI
Back to top
View users profile Send private message
Wizcrafts

Sergeant
Sergeant
Premium Member

Joined: Jun 05, 2003
Posts: 95
Location: Michigan
Premium

PostPosted: Fri Jul 13, 2007 4:52 pm    Post subject:
Reply with quote

Dragan_Glas wrote:
Greetings,

Wizcrafts
Thank you for the explanation! Thumbs Up

As regards your concerns about revealing too much in a publicly-accessible topic - and bearing in mind your other posts where you mentioned the spammers may be/are watching - I wonder would it be an idea to have a "Private" forum for you and staff members to discuss the finer points of and share suggestions for your filters?

The current public topic could then just be used for announcements of new/updated filters.

Public forums could allow discussion of general ideas/advice to everyone for filtering and/or "rolling your own" filter-sets.

Just a thought! Very Happy

Kindest regards,

James

James;
I think that is a good idea. I have some posts on WebmasterWorld that are only available to members, concerning security issues and I believe it would be useful to discuss some filtering techniques off the public forum, but with CastleCops members, particularly Firetrust personel and deputies. If we can create the forum you described I'll post about it here.


_________________
Submitted by Wiz
Guarding the Castle against spammers and scammers
Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger
Wizcrafts

Sergeant
Sergeant
Premium Member

Joined: Jun 05, 2003
Posts: 95
Location: Michigan
Premium

PostPosted: Thu Jul 19, 2007 2:01 am    Post subject: Wizcrafts' PDF Spam filter has been updated on July 18, 2007
Reply with quote

This is a quick note for MailWasher Pro users that my PDF Spam filter has been updated on July 18, 2007. Also, the replica watches filter was updated today. Grab your copy at www.wizcrafts.net/mwp-filters.html . Both the long and short versions of my filter rules are available for copying or downloading.

With the PDF filter rule it is important that you white-list your friends and contacts, in case they send you a legitimate email containing an attached PDF document. Otherwise this filter will hide emails containing an attached PDF file, then delete them from the mail server when you click on the Process button.

PS: Don't neglect the Process button. Using it not only deletes hidden spam messages, or other mail you want to delete, but it also frees up memory consumed by the program itself and the filters. It is a good idea to hit the Process button every couple of hours


_________________
Submitted by Wiz
Guarding the Castle against spammers and scammers
Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger
Wizcrafts

Sergeant
Sergeant
Premium Member

Joined: Jun 05, 2003
Posts: 95
Location: Michigan
Premium

PostPosted: Thu Jul 19, 2007 3:19 am    Post subject:
Reply with quote

I just updated the "Pharmaceutical Spam" filter to respond to a new spam run.


_________________
Submitted by Wiz
Guarding the Castle against spammers and scammers
Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger
Wizcrafts

Sergeant
Sergeant
Premium Member

Joined: Jun 05, 2003
Posts: 95
Location: Michigan
Premium

PostPosted: Sat Jul 21, 2007 7:50 pm    Post subject:
Reply with quote

I updated these MailWasher Pro filters today:

PDF Spam
Watches Spam
Pharmaceutical Spam
Pills Spam (new)
Juviotravel Spammer (new)

The changes are in response to new spam techinques and phrases.


_________________
Submitted by Wiz
Guarding the Castle against spammers and scammers
Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger
Wizcrafts

Sergeant
Sergeant
Premium Member

Joined: Jun 05, 2003
Posts: 95
Location: Michigan
Premium

PostPosted: Sun Jul 22, 2007 7:51 pm    Post subject:
Reply with quote

I just updated these MWP filters:

eBay Phishing Scams (2 filters - 1 new, 1 updated)
HTML Tricks (fixed RegExpr to eliminate false positives)


_________________
Submitted by Wiz
Guarding the Castle against spammers and scammers
Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger
Wizcrafts

Sergeant
Sergeant
Premium Member

Joined: Jun 05, 2003
Posts: 95
Location: Michigan
Premium

PostPosted: Sun Jul 29, 2007 8:16 pm    Post subject:
Reply with quote

I forgot to mention earlier that my filters automatically detect and delete the ecard greeting postcard spams that are sent by Storm Worm infected computers. These spam messages are generated by scripts installed on zombie computers which are being used to host a web page that contains a JavaScript redirect to a hostile script that installs a Trojan Horse on your PC, unless your defenses are A1.

I have modified several filters to remove Blacklisting. I did this because most of the current breed of postcard, RX and image spams are sent from zombies and have forged return and from addresses that are probably never repeated.

Wizcrafts' MailWasher Pro Filters


_________________
Submitted by Wiz
Guarding the Castle against spammers and scammers
Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger
Wizcrafts

Sergeant
Sergeant
Premium Member

Joined: Jun 05, 2003
Posts: 95
Location: Michigan
Premium

PostPosted: Tue Jul 31, 2007 12:00 am    Post subject:
Reply with quote

I have updated my MailWasher Pro filters tonight to detect and delete the newly discovered "Beautiful Screensaver" Trojan attachment spam messages, and I fine-tuned the Image Spam #1 rules to catch a new modification of an older spam technique.

I have not fine-tuned the screensaver rule yet, so expect some tweaking after I see a few more samples.


_________________
Submitted by Wiz
Guarding the Castle against spammers and scammers
Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger
Wizcrafts

Sergeant
Sergeant
Premium Member

Joined: Jun 05, 2003
Posts: 95
Location: Michigan
Premium

PostPosted: Tue Jul 31, 2007 1:50 am    Post subject:
Reply with quote

I have just made two adjustments to my MWP filters. I moved the "Beautiful Screensaver" rule down the list (to let other more common rules work first and faster) and added two more rules to the Watches spam filter.

Let me know what types of spam you are seeing the most of. It may be time to trim the list again to improve filter processing time. The main types of spam I have seen over the last two weeks are as follows:

1: Postcards that link to numeric IPs on BotNetted PCs
2: PDF or other Image spam
3: Replica Watches junk
4: RX and performance enhancement illicit drugs

These are based on the Statistics page on MailWasher Pro, showing the filter classifications of messages ID'd and deleted as spam.


_________________
Submitted by Wiz
Guarding the Castle against spammers and scammers
Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger
Wizcrafts

Sergeant
Sergeant
Premium Member

Joined: Jun 05, 2003
Posts: 95
Location: Michigan
Premium

PostPosted: Wed Aug 01, 2007 5:27 pm    Post subject:
Reply with quote

Today (so far) I have updated the following filters to speed up processing time, or catch new variants of old tricks:

1: ZipFile Spam
2: Screensaver Trojan
3: Misspelled Drugs
4: HTML Tricks

I have added this new filter:

> Russia (IP filter, still a work in progress)

Only use this filter if you do not receive legitimate email from the Russia Federation.

All of my filters are subject to change at any time and are sometimes updated more than once per day. If you experience slowdowns in email checking times you should reduce the number of incoming lines scanned, in your MWP options. Mine is currently set at 250 lines and I find this acceptable. My MailWasher Pro Filters are here.


_________________
Submitted by Wiz
Guarding the Castle against spammers and scammers
Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger
Wizcrafts

Sergeant
Sergeant
Premium Member

Joined: Jun 05, 2003
Posts: 95
Location: Michigan
Premium

PostPosted: Mon Aug 06, 2007 8:41 pm    Post subject:
Reply with quote

Today (so far) I have updated the PDF Spam filter by adding a second filter to detect and delete a brand new variant of this attachment type of spam. Accordingly, I have renamed the original rule as PDF Spam #1 and the new one is PDF Spam #2. Both are in the online filters available on my website on the MailWasher Pro Filters page.

Yesterday I rearranged the order of some of the filters in the master filters.txt list and removed a lot of blacklist options from many of the rules. I spend a fair amount of time working on these items, both to capture spam and to improve processing time and cpu load.

I wanted to let you know that I am also posting a lot of technical information on my blog that deals with MailWasher filters, blog and log spammers, server exploits, and denying access to online scammers in various countries, as is accomplished by my Nigerian blocklist.


_________________
Submitted by Wiz
Guarding the Castle against spammers and scammers
Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Mailwasher - Troubleshooting / General All times are GMT
Goto page Previous  1, 2, 3, 4, 5, 6, 7, 8, 9  Next
Page 4 of 9

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer