I've been using TMDA for three years now (since around version 0.42 as I recall). In that time I am happy to report that I have received almost no SPAM as a result. However, just in the last three weeks I have started to receive two to five SPAM a day. Each and every one has authenticated by replying to the challenge message and the originating email address has been added to my whitelist (which I have been removing manually).
I have seen this on occasion also, but not that frequently yet.
This is disturbing, as it would seem to indicate that some spammers must be automating responses to the challenge messages TMDA generates.
This could also be the case of a mis-configured MTA and a joe-jobed account. All of my "spammer-released" email has been released in this way:
1- Spammer sends email to me, forging the envelope too be from [EMAIL PROTECTED]
2- TMDA challenges the spam and sends the challenge to [EMAIL PROTECTED]
3- The server at 'jobs.com' is misconfigured and sends a bounce "No such user joe" to my Reply-To address (where the confirmation cookie is) instead of my Envelope like it should (which would then be ignored by me and not release the email
Is there a web-based challenge option being developed for TMDA, such as I've seen one some commercial services similar to TMDA?
Indeed:
http://tmda.net/tmda-cgi/ http://tmda.net/tmda-cgi/confirm.html
-- Jim Ramsay "Me fail English? That's unpossible!"
_____________________________________________ tmda-users mailing list ([EMAIL PROTECTED]) http://tmda.net/lists/listinfo/tmda-users
