Re: help with phishing email?

2017-12-08 Thread Colony.three
> first: before you call me again a fascist just because i don't agree > with your opinions backed by 10 years professional mailadmin better > don't give half thought advises! > > Am 09.12.2017 um 03:50 schrieb Colony.three: > >> Also in /etc/postfix/main.cf add to smtpd_recipient_restrictions = >>

Re: help with phishing email?

2017-12-08 Thread Jari Fredriksson
> Tom Hendrikx kirjoitti 9.12.2017 kello 0.34: > > On 08-12-17 19:09, AJ Weber wrote: >> I'm trying to decide the best way to detect something like this. >> >> https://pastebin.com/hCX9MWNg >> >> Looking at the raw headers and body it's pretty easy to tell this is a >> spoof, but when it show

Re: help with phishing email?

2017-12-08 Thread Jari Fredriksson
> Tom Hendrikx kirjoitti 9.12.2017 kello 0.34: > > On 08-12-17 19:09, AJ Weber wrote: >> I'm trying to decide the best way to detect something like this. >> >> https://pastebin.com/hCX9MWNg >> >> Looking at the raw headers and body it's pretty easy to tell this is a >> spoof, but when it show

Re: help with phishing email?

2017-12-08 Thread Colony.three
> I'm trying to decide the best way to detect something like this. > > https://pastebin.com/hCX9MWNg > > Looking at the raw headers and body it's pretty easy to tell this is a > spoof, but when it shows-up in an inbox, it looks pretty good. > > Something specific to Amazon (where this is purported

Re: help with phishing email?

2017-12-08 Thread David B Funk
On Fri, 8 Dec 2017, John Hardin wrote: On Fri, 8 Dec 2017, AJ Weber wrote: I'm trying to decide the best way to detect something like this. https://pastebin.com/hCX9MWNg That appears to be corrupt. I downloaded it and ran it through my testbed and it wouldn't decode the body. Don't know

Re: help with phishing email?

2017-12-08 Thread John Hardin
On Fri, 8 Dec 2017, AJ Weber wrote: I'm trying to decide the best way to detect something like this. https://pastebin.com/hCX9MWNg That appears to be corrupt. I downloaded it and ran it through my testbed and it wouldn't decode the body. -- John Hardin KA7OHZhttp://ww

Re: help with phishing email?

2017-12-08 Thread Tom Hendrikx
On 08-12-17 19:09, AJ Weber wrote: > I'm trying to decide the best way to detect something like this. > > https://pastebin.com/hCX9MWNg > > Looking at the raw headers and body it's pretty easy to tell this is a > spoof, but when it shows-up in an inbox, it looks pretty good. > > Something specif

Re: help with phishing email?

2017-12-08 Thread Pedro David Marco
AJ, i cannot see anything with sense... is the pastebin correct?  -PedroD

help with phishing email?

2017-12-08 Thread AJ Weber
I'm trying to decide the best way to detect something like this. https://pastebin.com/hCX9MWNg Looking at the raw headers and body it's pretty easy to tell this is a spoof, but when it shows-up in an inbox, it looks pretty good. Something specific to Amazon (where this is purported to come fr

Re: Mailsploit and RFC1342 and spoofed From

2017-12-08 Thread David Jones
On 12/07/2017 06:47 PM, Kevin A. McGrail wrote: On 12/7/2017 7:02 PM, Giovanni Bechis wrote: On 12/08/17 00:59, Kevin A. McGrail wrote: On 12/7/2017 6:39 PM, Giovanni Bechis wrote: unfortunately I cannot use KAM.cf out of the box because some scores are completely wrong in my environment (work

Re: Mailsploit and RFC1342 and spoofed From

2017-12-08 Thread Kevin A. McGrail
On 12/8/2017 3:25 AM, Giovanni Bechis wrote: Unfortunately I cannot know how new added rules will affect my enviroment, there are also some idn rules that breaks my Puppet instance but that's another story. Agreed.  But how would you know if they are added to sa-update natively? Rules that co

Re: Mailsploit and RFC1342 and spoofed From

2017-12-08 Thread Giovanni Bechis
Il 8 dicembre 2017 01:47:47 CET, "Kevin A. McGrail" ha scritto: >On 12/7/2017 7:02 PM, Giovanni Bechis wrote: >> On 12/08/17 00:59, Kevin A. McGrail wrote: >>> On 12/7/2017 6:39 PM, Giovanni Bechis wrote: unfortunately I cannot use KAM.cf out of the box because some >scores are completely wr