<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
	<channel>
		<title>www.ritlabs.com [Topic: spam problem]</title>
		<link>http://www.ritlabs.com</link>
		<description>New posts in spam problem of  forum at www.ritlabs.com [www.ritlabs.com]</description>
		<language>en</language>
		<docs>http://backend.userland.com/rss2</docs>
		<lastBuildDateTag>Tue, 07 Nov 2006 23:16:13 +0200</lastBuildDateTag>		<item>
			<title>spam problem</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic3754/message14578/">spam problem</a></b> <i>being spammed by thebat user</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			Highlighting the message and pressin F9 gets the headers which it looks like that's what you did<br /><br />Then from the message body start reading upward until you come to an IP address<br /><br />Received: from 216.15.179.130 (HELO gold.internet-media.net) <br /><br />...and that IP does belong to intermedia.net - many spammers will try to hide it but the IP tells unless you have someone REALLY good with DNS that can spoof where it is coming from (be nice when you contact - they may be being abused also) THis is not the full story of how to follow headers. Your best bet might be to copy the message from the f9 screen and paste it into the "report spam" area at Spamcop<br /><noindex><a href="http://www.spamcop.net/" target="_blank" rel="nofollow">http://www.spamcop.net/</a></noindex><br /><br /><br /> <br />
			<i>07 November 2006 23:16:13, <a href="http://www.ritlabs.com/en/forums/">Rick G</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic3754/message14578/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic3754/message14578/</guid>
			<pubDate>Tue, 07 Nov 2006 23:16:13 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>spam problem</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic3754/message14563/">spam problem</a></b> <i>being spammed by thebat user</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			Got the message, and it was not my intention to cast thebat in an ill-light.<br /><br />So, the Received: headers are where to look? I didn't show those? I'll see if I can find that, possibly with MailWasher, and figure it out, possibly with the help of DiamondCS Port Explorer, and check into that, and I'll stop posting to this thread.<br /><br />Thank you. <br />
			<i>05 November 2006 05:50:31, <a href="http://www.ritlabs.com/en/forums/">ritlabsnut</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic3754/message14563/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic3754/message14563/</guid>
			<pubDate>Sun, 05 Nov 2006 05:50:31 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>spam problem</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic3754/message14561/">spam problem</a></b> <i>being spammed by thebat user</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			<br />====quote====<br />Date: Thu, 2 Dec 2006 09:41:12 -0060 <br />From: "Rachel Newell" &lt;akstcaustraliamnsdgs@australia.edu&gt; <br />X-Mailer: The Bat! (v2.00.9) Educational <br />X-Priority: 3 (Normal) <br />Message-ID: &lt;481698102.91985773155631@thebat.net&gt; <br /><br />=============<br /><br />I see that you'd like a reaction.<br />The headers of the first spam message are faked, it's clearly no TB message-id. TB's message-ids are built like this: randomnumber.yyyymmddmmss@domain (with the first double m being the month and the second double m being the minutes of the timedate of message creation), as you can see the message-id doesn't match that pattern so you can assume that the message is created by something else then TB.<br />In case you're interested, yes there are spam tools that create messages with faked message headers, not only the from address can be faked, but a lot of the other headers can be faked too.<br /><br />Blaming Ritlabs or TB for the first message is as useless as blaming Microsoft and OE for the second, my guess is that OE isn't used either for the second message as it's not very suited for the real spam, nor do I think it very likely that AVG and avast are using the same custom header in the same message. <br /><br />The only remotely useful headers for tracking a message to it's source are the Receved: headers and you neglected to mention those.<br /><br />Apart from that, this whole subject is rather off topic here as this forum is intended for user to user support for <B><U>configuring</U></B> The Bat!<br /> <br />
			<i>05 November 2006 03:29:29, <a href="http://www.ritlabs.com/en/forums/">Roelof Otten</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic3754/message14561/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic3754/message14561/</guid>
			<pubDate>Sun, 05 Nov 2006 03:29:29 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>spam problem</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic3754/message14560/">spam problem</a></b> <i>being spammed by thebat user</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			Hi again everyone,<br /><br />I see there've been a few hits on this post. Active stalking is always an interesting subject. There seems to be no 'thebat' line in this one, but I thought people might like to see the apparent results of my post here, because for the first time in months of daily or bi-daily spam/stalker emails to me, this is the first time the sender has ever shown any open animosity. I would survise that it was somehow brought to the attention of the sender that I posted here, possibly by someone at 'thebat' tracing him by the info I posted here, and cutting off his 'thebat' account. Just a guess. Anyways, I've put the usual [DELETED] in my actual home email line, and I will add the sender has also for the first time indicated that he actually knows I subscribe to musician literature, that I am older, and that I am retired, and has added a thinly veiled threat with the words 'you, an aging amateur musician drawn from retirement to risk his life' (meaning me). Oh, now I am 'risking my life' am I? Apparently, the stalker did not like having his 'thebat' account header info posted here and possibly cut off. Getting a little creepy here.<br /><br />Notice also his wierd, offensive use of a misspelled 'viagra' reference, possibly not spelled right to get past spam filters.<br /><br />I thank the admin for letting me post this here, as the best treatment for this kind of wierdness seems to be a good public airing.<br /><br />Regards to all,<br /><br />'thebatnut'<br /><br />Full email header and spam/stalker mssg follows:<br /><br />Subject:<br />Re: tip 328<br />From:<br />"Jaswinder Pettiford" &lt;besseylumusi@agsprint.com&gt;<br />Date: Sat, 4 Nov 2006 03:04:46 -0800<br />To: DELETED@ruraltel.net<br />Return-path: &lt;besseylumusi@agsprint.com&gt;<br />Envelope-to: DELETED@ruraltel.net<br />Received: from mail2.ruraltel.net ([24.225.0.35]) by atmail with smtp (Exim 4.60) (envelope-from &lt;besseylumusi@agsprint.com&gt;) id 1GgJKy-0007UA-Nw for DELETED@ruraltel.net; Sat, 04 Nov 2006 05:05:20 -0600<br />X-Spam-Score:<br />3.9<br />X-Spam-Flag:<br />NO<br />X-Spam-Level:<br />***<br />X-Spam-Status:<br />No, hits=3.9 required=4.0<br />X-Spam-Processed-By:<br />spamd2.ruraltel.net<br />X-Spam-Report:<br />3.9 points, 4.0 required * 1.6 URIBL_SBL Contains an URL listed in the SBL blocklist * [URIs: kasedunhyuietionde.com] * 2.2 DCC_CHECK Listed in DCC (<noindex><a href="http://rhyolite.com/anti-spam/dcc/" target="_blank" rel="nofollow">http://rhyolite.com/anti-spam/dcc/</a></noindex>) * 0.1 FORGED_RCVD_HELO Received: contains a forged HELO * 0.0 HTML_MESSAGE BODY: HTML included in message * 0.0 BAYES_50 BODY: Bayesian spam probability is 40 to 60% * [score: 0.4880] * 0.0 HTML_70_80 BODY: Message is 70% to 80% HTML<br />Received:<br />from amontpellier-156-1-90-187.w83-205.abo.wanadoo.fr (HELO agsprint.com) (83.205.209.187) by mail2.ruraltel.net with SMTP; 4 Nov 2006 11:05:19 -0000<br />Received-SPF:<br />none (mail2.ruraltel.net: domain at agsprint.com does not designate permitted sender hosts)<br />Message-ID:<br />&lt;000001c70001$09b4a730$6b9ea8c0@zwifand&gt;<br />Reply-To:<br />"Jaswinder Pettiford" &lt;besseylumusi@agsprint.com&gt;<br />X-Priority:<br />3<br />X-MSMail-Priority:<br />Normal<br />X-Mailer:<br />Microsoft Outlook Express 6.00.2800.1106<br />X-MimeOLE:<br />Produced By Microsoft MimeOLE V6.00.2800.1106<br />X-Antivirus:<br />avast! (VPS 0645-4, 03/11/2006), Outbound message<br />X-Antivirus-Status:<br />Clean<br />X-Antivirus:<br />AVG for E-mail 7.1.409 [268.13.27/517]<br />MIME-Version:<br />1.0<br />Content-Type:<br />multipart/mixed; boundary="=======AVGMAIL-454CB0F66FA0======="<br /><br />Hi,<br />VljlAGRA $ 3, 35 <noindex><a href="http://www.kasedunhyuietionde.com" target="_blank" rel="nofollow">http://www.kasedunhyuietionde.com</a></noindex><br /> <br /><br />you, an aging amateur musician drawn from retirement to risk his life<br /><br /><br /><br />No virus found in this incoming message.<br />Checked by AVG Free Edition.<br />Version: 7.1.409 / Virus Database: 268.13.27/517 - Release Date: 11/3/2006 <br />
			<i>05 November 2006 02:18:20, <a href="http://www.ritlabs.com/en/forums/">ritlabsnut</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic3754/message14560/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic3754/message14560/</guid>
			<pubDate>Sun, 05 Nov 2006 02:18:20 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
		<item>
			<title>spam problem</title>
			<description><![CDATA[<b><a href="http://www.ritlabs.com/en/forums/forum4/topic3754/message14532/">spam problem</a></b> <i>being spammed by thebat user</i> in forum <a href="http://www.ritlabs.com/en/forums/forum4/">The Bat! - Configuring the E-mail Client</a>. <br />
			My apologies to all for bothering anyone, but I've been getting wierd, vulgar gibberish spam messages for months, and forwarding each one to my ISP tech dept to block, but they keep coming. I finally used MailWasher to check full header plus the typically broken mssg on what seems to be another one today, and it is as follows (I replaced my actual email address prefix by [DELETED] for privacy);<br /><br />Return-path: &lt;akstcaustraliamnsdgs@australia.edu&gt;<br />Envelope-to: DELETED@ruraltel.net<br />Received: from mail3.ruraltel.net ([24.225.0.36])<br />	by atmail with smtp (Exim 4.60)<br />	(envelope-from &lt;akstcaustraliamnsdgs@australia.edu&gt;)<br />	id 1GfZ4S-0007tV-G1<br />	for DELETED@ruraltel.net; Thu, 02 Nov 2006 03:41:12 -0600<br />X-Spam-Score: 2.4<br />X-Spam-Flag: NO<br />X-Spam-Level: **<br />X-Spam-Status: No, hits=2.4 required=4.0<br />X-Spam-Processed-By: spamd3.ruraltel.net<br />X-Spam-Report: 2.4 points, 4.0 required<br />	* &nbsp;2.4 DATE_IN_FUTURE_96_XX Date: is 96 hours or more after Received: date<br />	* &nbsp;0.0 BAYES_50 BODY: Bayesian spam probability is 40 to 60%<br />	* &nbsp; &nbsp; &nbsp;[score: 0.4555]<br />Received: from amazonas-4642.adsl.datanet.hu (HELO Krissz) (91.120.114.70)<br /> &nbsp;by mail3.ruraltel.net with SMTP; 2 Nov 2006 09:41:11 -0000<br />Received-SPF: none (mail3.ruraltel.net: domain at australia.edu does not designate permitted sender hosts)<br />Received: from 216.15.179.130 (HELO gold.internet-media.net)<br /> &nbsp; &nbsp; by ruraltel.net with esmtp (S113MYCUH3A BIN2O)<br /> &nbsp; &nbsp; id 9NBUHG-216973-B2<br /> &nbsp; &nbsp; for svferg@ruraltel.net; Thu, 2 Dec 2006 09:41:12 -0060<br />Date:	Thu, 2 Dec 2006 09:41:12 -0060<br />From:	"Rachel Newell" &lt;akstcaustraliamnsdgs@australia.edu&gt;<br />X-Mailer: The Bat! (v2.00.9) Educational<br />X-Priority: 3 (Normal)<br />Message-ID: &lt;481698102.91985773155631@thebat.net&gt;<br />To: svferg@ruraltel.net<br />Subject: nose-leafed mosaic binding<br />MIME-Version: 1.0<br />Content-Type: text/plain;<br /> &nbsp;charset=iso-8859-1<br />Content-Transfer-Encoding: quoted-printable<br />X-Spam: Not detected<br /><br />elizabeth almost stared at her. "can this be mr. darcy?" thought=20=<br />she."that is to say, you had given your permission. i guessed as much."=20=<br />and though he exclaimed at<br /><br />END QUOTE.<br /><br />Please notice it contains a line that starts;<br />X-Mailer: The Bat!<br /><br />which is what brought me here. I've heard of viruses that can hijack innocent users' machines to do stuff like this, even substituting false headers for real ones somehow. I'm seeking responses from anyone who thinks they can help figure out what is going on here. Perhaps someone just needs to be informed their pc has been hijacked? If I get any more, I will see if they also contain a thebat line.<br /><br />My personal email contact for this forum is through SNEAKEMAIL, which is a legitimate paid anti-spam virtual email service, but the spammer seems to be targeting my actual home email address.<br /><br />Regards,<br /><br />'thebatnut'<br /> <br />
			<i>02 November 2006 15:41:51, <a href="http://www.ritlabs.com/en/forums/">ritlabsnut</a>.</i>]]></description>
			<link>http://www.ritlabs.com/en/forums/forum4/topic3754/message14532/</link>
			<guid>http://www.ritlabs.com/en/forums/forum4/topic3754/message14532/</guid>
			<pubDate>Thu, 02 Nov 2006 15:41:51 +0200</pubDate>
			<category>The Bat! - Configuring the E-mail Client</category>
		</item>
	</channel>
</rss>
