public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-dev] Recent lists mail loss
@ 2010-02-01 20:40 Robin H. Johnson
  2010-02-02  7:02 ` ALIP BUDIANTO
  2010-02-03 22:53 ` Hanno Böck
  0 siblings, 2 replies; 4+ messages in thread
From: Robin H. Johnson @ 2010-02-01 20:40 UTC (permalink / raw
  To: gentoo-dev; +Cc: gentoo-announce

[-- Attachment #1: Type: text/plain, Size: 830 bytes --]

As the listadmin, I'd like to apologize for some recent lists mail loss.

A spammer managed to get a subscription confirmation email send to a
spamtrap address, that promptly caused the lists server to be listed on
a blacklist for 12-14 hours.

During that time, approximately 2000 list deliveries were rejected due
to the RBL. First recorded rejection was around Feb 1 00:20 UTC, last
recorded was Feb 1 13:35 UTC.

I've included full log details in a blogpost:
http://robbat2.livejournal.com/236942.html

If you know anybody that runs similar spamtraps, please ask them to
ensure list confirmation requests are NOT treated as spam.

-- 
Robin Hugh Johnson
Gentoo Linux: Developer, Trustee & Infrastructure Lead
E-Mail     : robbat2@gentoo.org
GnuPG FP   : 11AC BA4F 4778 E3F6 E4ED  F38E B27B 944E 3488 4E85

[-- Attachment #2: Type: application/pgp-signature, Size: 330 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [gentoo-dev] Recent lists mail loss
  2010-02-01 20:40 [gentoo-dev] Recent lists mail loss Robin H. Johnson
@ 2010-02-02  7:02 ` ALIP BUDIANTO
  2010-02-03 22:53 ` Hanno Böck
  1 sibling, 0 replies; 4+ messages in thread
From: ALIP BUDIANTO @ 2010-02-02  7:02 UTC (permalink / raw
  To: gentoo-dev

[-- Attachment #1: Type: text/plain, Size: 1057 bytes --]

On Mon, Feb 1, 2010 at 11:40 AM, Robin H. Johnson <robbat2@gentoo.org>wrote:

> As the listadmin, I'd like to apologize for some recent lists mail loss.
>
> A spammer managed to get a subscription confirmation email send to a
> spamtrap address, that promptly caused the lists server to be listed on
> a blacklist for 12-14 hours.
>
> During that time, approximately 2000 list deliveries were rejected due
> to the RBL. First recorded rejection was around Feb 1 00:20 UTC, last
> recorded was Feb 1 13:35 UTC.
>
> I've included full log details in a blogpost:
> http://robbat2.livejournal.com/236942.html
>
> If you know anybody that runs similar spamtraps, please ask them to
> ensure list confirmation requests are NOT treated as spam.
>
> --
> Robin Hugh Johnson
> Gentoo Linux: Developer, Trustee & Infrastructure Lead
> E-Mail     : robbat2@gentoo.org
> GnuPG FP   : 11AC BA4F 4778 E3F6 E4ED  F38E B27B 944E 3488 4E85
>
Woah so thats why I had to move the subscribe messages to the Inbox in
gmail. THey may be CONNECTED TO THAT SPAM LIST!!!!!!!!!!!!!!

[-- Attachment #2: Type: text/html, Size: 1539 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [gentoo-dev] Recent lists mail loss
  2010-02-01 20:40 [gentoo-dev] Recent lists mail loss Robin H. Johnson
  2010-02-02  7:02 ` ALIP BUDIANTO
@ 2010-02-03 22:53 ` Hanno Böck
  2010-02-03 23:09   ` Robin H. Johnson
  1 sibling, 1 reply; 4+ messages in thread
From: Hanno Böck @ 2010-02-03 22:53 UTC (permalink / raw
  To: gentoo-dev

[-- Attachment #1: Type: Text/Plain, Size: 882 bytes --]

There's a german statement from the Nix Spam RBL.

http://www.heise.de/ix/foren/S-Re-Mailinglisten-Bestaetigungs-Email-an-
Spamtrap-legt-Gentoos-Mailinglisten-
lahm/forum-48292/msg-18035095/read/showthread-1/

As many here probably can't read german, the important points are:
- RFC 3834 defines headers for automatically sent mails, seems our mailing 
list software doesn't do that - but robbat2 commented in his blog is already 
in contact with upstream about that.
- they claim that nobody contacted them directly and their automatic delisting 
method was not used.

I'm personally using the mentioned RBL on my servers and I read some articles 
and heared some talks from their operators and generally think they are doing 
good work, so I wanted to share that.

cu,
-- 
Hanno Böck		Blog:		http://www.hboeck.de/
GPG: 3DBD3B20		Jabber/Mail:	hanno@hboeck.de

[-- Attachment #2: This is a digitally signed message part. --]
[-- Type: application/pgp-signature, Size: 198 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [gentoo-dev] Recent lists mail loss
  2010-02-03 22:53 ` Hanno Böck
@ 2010-02-03 23:09   ` Robin H. Johnson
  0 siblings, 0 replies; 4+ messages in thread
From: Robin H. Johnson @ 2010-02-03 23:09 UTC (permalink / raw
  To: gentoo-dev

On Wed, Feb 03, 2010 at 11:53:08PM +0100, Hanno Böck wrote:
> There's a german statement from the Nix Spam RBL.
> 
> http://www.heise.de/ix/foren/S-Re-Mailinglisten-Bestaetigungs-Email-an-
> Spamtrap-legt-Gentoos-Mailinglisten-
> lahm/forum-48292/msg-18035095/read/showthread-1/
> 
> As many here probably can't read german, the important points are:
> - RFC 3834 defines headers for automatically sent mails, seems our mailing 
> list software doesn't do that - but robbat2 commented in his blog is already 
> in contact with upstream about that.
> - they claim that nobody contacted them directly and their automatic delisting 
> method was not used.
I only noted it after the 12 hour period was up, and it had expired from
their listing.

mlmmj is sending RF3834 headers on some mails, but not all of them.

-- 
Robin Hugh Johnson
Gentoo Linux: Developer, Trustee & Infrastructure Lead
E-Mail     : robbat2@gentoo.org
GnuPG FP   : 11AC BA4F 4778 E3F6 E4ED  F38E B27B 944E 3488 4E85



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2010-02-03 23:09 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-02-01 20:40 [gentoo-dev] Recent lists mail loss Robin H. Johnson
2010-02-02  7:02 ` ALIP BUDIANTO
2010-02-03 22:53 ` Hanno Böck
2010-02-03 23:09   ` Robin H. Johnson

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox