Testing mail list

Lists: pgsql-hackers
From: Gregory Stark <stark(at)enterprisedb(dot)com>
To: pgsql-hackers list <pgsql-hackers(at)postgresql(dot)org>
Subject: Testing mail list
Date: 2007-12-19 11:25:36
Message-ID: 87wsrblydr.fsf@oxford.xeocode.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-hackers


I'm receiving bogus bounce messages like this (which are malformed even, the
Subject isn't properly encoded). I'm not sure what list is generating them or
what address but if we can figure out who could we drop whoever it is from the
list please?


From: Andrew Dunstan <andrew(at)dunslane(dot)net>
To: Gregory Stark <stark(at)enterprisedb(dot)com>
Cc: pgsql-hackers list <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: Testing mail list
Date: 2007-12-19 12:28:19
Message-ID: 47690E63.7010309@dunslane.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-hackers

Gregory Stark wrote:
> I'm receiving bogus bounce messages like this (which are malformed even, the
> Subject isn't properly encoded). I'm not sure what list is generating them or
> what address but if we can figure out who could we drop whoever it is from the
> list please?
>
>
> ------------------------------------------------------------------------
>
> Subject:
> Confirmação de envio / Sending confirmation (captchaid:1324333124c3)
> From:
> <postmaster(at)infotecnica(dot)com(dot)br>
>
>
>
> The email message sent to dev(at)archonet(dot)com requires a confirmation to
> be delivered. Please, answer this email informing the characters that
> you see in the image below
>
>
>

Receipt of messages like this is guaranteed an immediate entry in my
junk filter. Use of this braindead software is bad enough, but being so
clueless as not to whitelist a technical mailing list you subscribe to
is truly horrible.

cheers

andrew


From: Gregory Stark <stark(at)enterprisedb(dot)com>
To: "Andrew Dunstan" <andrew(at)dunslane(dot)net>
Cc: "pgsql-hackers list" <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: Testing mail list
Date: 2007-12-19 13:09:39
Message-ID: 87bq8mn84s.fsf@oxford.xeocode.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-hackers

"Andrew Dunstan" <andrew(at)dunslane(dot)net> writes:

> Receipt of messages like this is guaranteed an immediate entry in my junk
> filter. Use of this braindead software is bad enough, but being so clueless as
> not to whitelist a technical mailing list you subscribe to is truly horrible.

It's worse than that in this case. This is an *impressively* broken
configuration. What appears to be happening is that the mail server at this
university is looking at the To and From headers and treating it as a personal
email between those two addresses. It sends this captcha to the From header
claiming that the person in the To header is insisting on the captcha being
filled out. The first such bounce I looked at actually claimed it was on Tom's
behalf!

If I were the list maintainer here I would ban infotecnica.com.br addresses
from subscribing to any of our lists. Ideally with a message saying "as a
result of misconfigured mail software addreses from infotecnica.com.br are
banned from pgsql mailing lists. Please contact your postmaster to request
they fix the problems"

--
Gregory Stark
EnterpriseDB http://www.enterprisedb.com
Ask me about EnterpriseDB's Slony Replication support!


From: Alvaro Herrera <alvherre(at)alvh(dot)no-ip(dot)org>
To: Gregory Stark <stark(at)enterprisedb(dot)com>
Cc: Andrew Dunstan <andrew(at)dunslane(dot)net>, pgsql-hackers list <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: Testing mail list
Date: 2007-12-19 13:20:03
Message-ID: 20071219132003.GA9937@alvh.no-ip.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-hackers

On Wed, Dec 19, 2007 at 01:09:39PM +0000, Gregory Stark wrote:

> If I were the list maintainer here I would ban infotecnica.com.br addresses
> from subscribing to any of our lists. Ideally with a message saying "as a
> result of misconfigured mail software addreses from infotecnica.com.br are
> banned from pgsql mailing lists. Please contact your postmaster to request
> they fix the problems"

Right. Problem is, I checked and I found no infotecnica.com.br
addresses subscribed to pgsql-hackers.

Are you sure it was mail from -hackers that caused the problem? I have
seen the bounce myself but never made much of it (even though I agreed
it was quite broken).

--
Alvaro Herrera http://www.amazon.com/gp/registry/DXLWNGRJD34J
La web junta la gente porque no importa que clase de mutante sexual seas,
tienes millones de posibles parejas. Pon "buscar gente que tengan sexo con
ciervos incendiándose", y el computador dirá "especifique el tipo de ciervo"
(Jason Alexander)


From: Andrew Dunstan <andrew(at)dunslane(dot)net>
To: Alvaro Herrera <alvherre(at)alvh(dot)no-ip(dot)org>
Cc: Gregory Stark <stark(at)enterprisedb(dot)com>, pgsql-hackers list <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: Testing mail list
Date: 2007-12-19 13:36:14
Message-ID: 47691E4E.8080506@dunslane.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-hackers

Alvaro Herrera wrote:
> On Wed, Dec 19, 2007 at 01:09:39PM +0000, Gregory Stark wrote:
>
>
>> If I were the list maintainer here I would ban infotecnica.com.br addresses
>> from subscribing to any of our lists. Ideally with a message saying "as a
>> result of misconfigured mail software addreses from infotecnica.com.br are
>> banned from pgsql mailing lists. Please contact your postmaster to request
>> they fix the problems"
>>
>
> Right. Problem is, I checked and I found no infotecnica.com.br
> addresses subscribed to pgsql-hackers.
>
> Are you sure it was mail from -hackers that caused the problem? I have
> seen the bounce myself but never made much of it (even though I agreed
> it was quite broken).
>
>

It could be via some mail <-> news or list <-> list gateway.

cheers

andrew


From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Gregory Stark <stark(at)enterprisedb(dot)com>
Cc: "Andrew Dunstan" <andrew(at)dunslane(dot)net>, "pgsql-hackers list" <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: Testing mail list
Date: 2007-12-19 16:15:37
Message-ID: 23554.1198080937@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-hackers

Gregory Stark <stark(at)enterprisedb(dot)com> writes:
> It's worse than that in this case. This is an *impressively* broken
> configuration.

Understatement of the week. The mail includes absolutely no evidence
about what message is allegedly being filtered. Are you sure that
this is really a filtering engine at all, and not just random spam
hoping to draw responses from careless people? I've heard of web
comment-spammers who try to get other people to decode captchas
for them this way.

Adding to my suspicion is that I don't recall having seen one of these
personally, and if it were really tied to posting on any of the PG
lists, I shoulda seen a lot ;-)

regards, tom lane


From: Alvaro Herrera <alvherre(at)commandprompt(dot)com>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: Gregory Stark <stark(at)enterprisedb(dot)com>, Andrew Dunstan <andrew(at)dunslane(dot)net>, pgsql-hackers list <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: Testing mail list
Date: 2007-12-19 16:24:25
Message-ID: 20071219162425.GH9937@alvh.no-ip.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-hackers

Tom Lane wrote:
> Gregory Stark <stark(at)enterprisedb(dot)com> writes:
> > It's worse than that in this case. This is an *impressively* broken
> > configuration.
>
> Understatement of the week. The mail includes absolutely no evidence
> about what message is allegedly being filtered. Are you sure that
> this is really a filtering engine at all, and not just random spam
> hoping to draw responses from careless people? I've heard of web
> comment-spammers who try to get other people to decode captchas
> for them this way.
>
> Adding to my suspicion is that I don't recall having seen one of these
> personally, and if it were really tied to posting on any of the PG
> lists, I shoulda seen a lot ;-)

Yeah, I think it comes from pgsql-performance. I just got one
mentioning an address to which I had responded some minutes before.

--
Alvaro Herrera http://www.CommandPrompt.com/
The PostgreSQL Company - Command Prompt, Inc.


From: Andrew Sullivan <ajs(at)crankycanuck(dot)ca>
To: pgsql-hackers(at)postgresql(dot)org
Subject: Re: Testing mail list
Date: 2007-12-19 16:33:42
Message-ID: 20071219163342.GB32137@crankycanuck.ca
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-hackers

On Wed, Dec 19, 2007 at 11:15:37AM -0500, Tom Lane wrote:
> hoping to draw responses from careless people? I've heard of web
> comment-spammers who try to get other people to decode captchas
> for them this way.

Yes. This is the latest spammer trick. They get people all over the globe
to decode the captchas. It's way easier than programming to decode the
captchas (which itself isn't that hard -- there are plenty of toolkits out
there that will decode such things for you).

A


From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Gregory Stark <stark(at)enterprisedb(dot)com>, "Andrew Dunstan" <andrew(at)dunslane(dot)net>, "pgsql-hackers list" <pgsql-hackers(at)postgresql(dot)org>
Subject: Re: Testing mail list
Date: 2007-12-19 16:45:12
Message-ID: 23979.1198082712@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Lists: pgsql-hackers

I wrote:
> Adding to my suspicion is that I don't recall having seen one of these
> personally,

I take that back --- some digging in my mail logs shows that I have
gotten a few of these, but they went straight to /dev/null because
my spam filters thought they were a virus. Have you checked whether
that "gif" is really an image, rather than a bit of malware?

The mail-log trace of the last such attempt is pretty interesting too:

Dec 16 13:05:16 sss2 sm-mta[27362]: lBGI5G1g027362: infotecnica.com.br [201.35.247.5] did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA
Dec 16 13:05:16 sss2 sm-mta[27363]: lBGI5GFn027363: infotecnica.com.br [201.35.247.5] did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA
Dec 16 13:05:17 sss2 sm-mta[27365]: lBGI5HIe027365: infotecnica.com.br [201.35.247.5] did not issue MAIL/EXPN/VRFY/ETRN during connection to MTA
Dec 16 13:05:52 sss2 sm-mta[27368]: lBGI5n2G027368: from=<root(at)infotecnica(dot)com(dot)br>, size=27892, class=0, nrcpts=1, msgid=<200712161805(dot)lBGI59uu016307(at)infotecnica(dot)com(dot)b
r>, bodytype=8BITMIME, proto=ESMTP, daemon=MTA, relay=infotecnica.com.br [201.35.247.5]
Dec 16 13:05:52 sss2 sm-mta[27369]: lBGI5n2G027368: to="|/usr/local/bin/procmail -tYf- || exit 75 #tgl", ctladdr=<tgl(at)sss(dot)pgh(dot)pa(dot)us> (301/20), delay=00:00:02, xdelay=0
0:00:00, mailer=prog, pri=58095, dsn=2.0.0, stat=Sent

Since 11 December there are consistently three no-op connections before
anything actually happens, which adds a whole new layer of incompetence
that could be charged against whoever is running this, if it actually is
a mail server --- which I grow increasingly dubious of. I also see a
whole lot of connection attempts in the preceding months in which
nothing was *ever* sent, just "did not issue MAIL" reports in bursts of
three.

Looks like spamhaus.org was blocking them for portions of last month,
too, so other people have been unhappy about this as well.

Whoever these people are, I've seen enough; I'm off to add this IP
address to my local permanent blacklist.

regards, tom lane