RE: yahoo.com acknowledges no control over third party email from their mail servers

2008-05-16 Thread James Pratt
> -Original Message-
> From: Michael Scheidell [mailto:[EMAIL PROTECTED]
> Sent: Friday, May 16, 2008 7:46 AM
> To: John Hardin
> Cc: SpamAssassin Users List
> Subject: Re: yahoo.com acknowledges no control over third party email
> from their mail servers
> >
> > How the hell can they disown that? The rDNS is from a domain they
> control!
> >
> Didn't disown it, just said it didn't come from a yahoo.com authorized
> source, ie:  they have open third party relay and just allow random
> spammers
> to use their servers.
> 
> I get that email response from them 75% of the time, which means
> (according
> to yahoo.com) that 75% of the spam coming from yahoo.com DKIM signed
> servers
> is from third partys, not authorized yahoo.com users.
> 

If you get testy with them and mail them back and forth about it, and
include links to the whois/dig output *proving* that they are
lying/hiding/whatever, they will eventually "fess up", and a day or so
later, you should receive the standard "We have taken appropriate action
against the user in   question (yadda-yadda)" email. ...Whether or not
they actually *do* anything is obviously an unknown, however, I agree
that this is just *bad*, so I tend to "call them on it" every time if I
can/have the time. 

IOTW - I'm not exactly on "Elmer's" buddy-list... ;)


Re: yahoo.com acknowledges no control over third party email from their mail servers

2008-05-16 Thread Michael Scheidell
> From: John Hardin <[EMAIL PROTECTED]>
> Date: Thu, 15 May 2008 10:32:29 -0700 (PDT)
> To: Michael Scheidell <[EMAIL PROTECTED]>
> Cc: SpamAssassin Users List 
> Subject: Re: yahoo.com acknowledges no control over third party email from
> their mail servers
> 
> 
> How the hell can they disown that? The rDNS is from a domain they control!
> 
Didn't disown it, just said it didn't come from a yahoo.com authorized
source, ie:  they have open third party relay and just allow random spammers
to use their servers.

I get that email response from them 75% of the time, which means (according
to yahoo.com) that 75% of the spam coming from yahoo.com DKIM signed servers
is from third partys, not authorized yahoo.com users.


-- 
Michael Scheidell, CTO
>|SECNAP Network Security
Winner 2008 Network Products Guide Hot Companies
FreeBSD SpamAssassin Ports maintainer



_
This email has been scanned and certified safe by SpammerTrap(r). 
For Information please see http://www.spammertrap.com
_


Re: yahoo.com acknowledges no control over third party email from their mail servers

2008-05-15 Thread mouss

Michael Scheidell wrote:

John Hardin wrote:

On Thu, 15 May 2008, Michael Scheidell wrote:

I understand your frustration in receiving unsolicited email. While 
we investigate all reported violations against the Yahoo! Terms of 
Service (TOS), in this particular case the message you received was 
not sent through the Yahoo! Mail system.


Received: from web1114.biz.mail.sk1.yahoo.com 
(web1114.biz.mail.sk1.yahoo.com [74.6.114.46])

 by fl.us.spammertrap.net (Postfix) with SMTP id C81DC2E11E
 for <[EMAIL PROTECTED]>; Wed, 14 May 2008 11:00:29 -0400 (EDT)


I assume you trust fl.us.spammertrap.net?


i AM fl.us.spammertrap.net ;-)


hmmm. I've seen almost exactly the same wording (in french) from a 
french ISP. so I would guess that they have a script that failed to 
"qualify" the complaint because there is an "extra hop". try resending 
after removing the first Received header and see if it gets further...





How the hell can they disown that? The rDNS is from a domain they 
control!



DKIM SIGNED NO LESS!


I see no dkim signature.


Re: yahoo.com acknowledges no control over third party email from their mail servers

2008-05-15 Thread SM

At 10:32 15-05-2008, John Hardin wrote:

On Thu, 15 May 2008, Michael Scheidell wrote:

I understand your frustration in receiving unsolicited email. While 
we investigate all reported violations against the Yahoo! Terms of 
Service (TOS), in this particular case the message you received was 
not sent through the Yahoo! Mail system.


Received: from web1114.biz.mail.sk1.yahoo.com 
(web1114.biz.mail.sk1.yahoo.com [74.6.114.46])

by fl.us.spammertrap.net (Postfix) with SMTP id C81DC2E11E
for <[EMAIL PROTECTED]>; Wed, 14 May 2008 11:00:29 -0400 (EDT)


I assume you trust fl.us.spammertrap.net?


I understand your frustration in receiving unsolicited mail from an 
IP address that points to a yahoo.com subdomain and which is directly 
allocated to a Yahoo! company.



How the hell can they disown that? The rDNS is from a domain they control!


Some providers ignore abuse reports for mail originating from 
business customers.


Regards,
-sm 



Re: yahoo.com acknowledges no control over third party email from their mail servers

2008-05-15 Thread Michael Scheidell

John Hardin wrote:

On Thu, 15 May 2008, Michael Scheidell wrote:

I understand your frustration in receiving unsolicited email. While 
we investigate all reported violations against the Yahoo! Terms of 
Service (TOS), in this particular case the message you received was 
not sent through the Yahoo! Mail system.


Received: from web1114.biz.mail.sk1.yahoo.com 
(web1114.biz.mail.sk1.yahoo.com [74.6.114.46])

 by fl.us.spammertrap.net (Postfix) with SMTP id C81DC2E11E
 for <[EMAIL PROTECTED]>; Wed, 14 May 2008 11:00:29 -0400 (EDT)


I assume you trust fl.us.spammertrap.net?


i AM fl.us.spammertrap.net ;-)

How the hell can they disown that? The rDNS is from a domain they 
control!



DKIM SIGNED NO LESS!


--
Michael Scheidell, CTO
Main: 561-999-5000, Office: 561-939-7259
> *| *SECNAP Network Security Corporation
Winner 2008 Technosium hot company award.
www.technosium.com/hotcompanies/ 


_
This email has been scanned and certified safe by SpammerTrap(r). 
For Information please see http://www.spammertrap.com

_


Re: yahoo.com acknowledges no control over third party email from their mail servers

2008-05-15 Thread John Hardin

On Thu, 15 May 2008, Michael Scheidell wrote:

I understand your frustration in receiving unsolicited email. While we 
investigate all reported violations against the Yahoo! Terms of Service 
(TOS), in this particular case the message you received was not sent 
through the Yahoo! Mail system.


Received: from web1114.biz.mail.sk1.yahoo.com (web1114.biz.mail.sk1.yahoo.com 
[74.6.114.46])

 by fl.us.spammertrap.net (Postfix) with SMTP id C81DC2E11E
 for <[EMAIL PROTECTED]>; Wed, 14 May 2008 11:00:29 -0400 (EDT)


I assume you trust fl.us.spammertrap.net?

How the hell can they disown that? The rDNS is from a domain they control!

--
 John Hardin KA7OHZhttp://www.impsec.org/~jhardin/
 [EMAIL PROTECTED]FALaholic #11174 pgpk -a [EMAIL PROTECTED]
 key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
---
 6 days until the 4th anniversary of SpaceshipOne winning the X-prize