You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@spamassassin.apache.org by "Ramdas P. Prabhu" <cy...@vsnl.com> on 2006/11/10 18:11:50 UTC

Spam assasin query

Dear All,

I have a small query, and shall be highly obliged if you could solve it.

Some time back, I had enabled some option in spam assasin whereby anyone who
sent me a mail received an automated message to click on a link in order to
verify whether he was real or a spam source. Somehow that option is not
available to me now. Can you please let me know how this option can be
activated in spam assasin. Below is an excerpt of the same feature which I
have mentioned above.

> "
> Subject: Your email requires
> verificationverify#EdsAtW8RAHzEKlx83QUQtDhQLl6DnCF9
>
>
> The message you sent requires that you verify that you
> are a real live human being and not a spam source.
>
> To complete this verification, simply reply to this message and leave
> the subject line intact.
>
> The headers of the message sent from your address are show below:
>
> >>From cygan@vsnl.com Wed Jan 18 01:19:06 2006
> Received: from wwwparm by gains.house4domains.com with local-bsmtp (Exim
> 4.52)
>  id 1Ez7ax-0001Bz-FM
>  for sunil@parmanandindia.com; Wed, 18 Jan 2006 01:19:05 -0600
> X-Spam-Checker-Version: SpamAssassin 3.1.0 (2005-09-13) on
> 	gains.house4domains.com
> X-Spam-Level:
> X-Spam-Status: No, score=-1.4 required=5.0 tests=ALL_TRUSTED
> 	autolearn=unavailable version=3.1.0
> Received: from [59.182.37.119] (helo=rpp)
> 	by gains.house4domains.com with esmtpa (Exim 4.52)
> 	id 1Ez7av-0001BG-82
>
> "



 I shall be highly obliged if you could let me know how the same can be
 enabled again.


 Thanx & Rgds.,

 Ramdas P. Prabhu


Re: Spam assasin query

Posted by Jim Maul <jm...@elih.org>.
Ramdas P. Prabhu wrote:
> Dear All,
> 
> I have a small query, and shall be highly obliged if you could solve it.
> 
> Some time back, I had enabled some option in spam assasin whereby anyone who
> sent me a mail received an automated message to click on a link in order to
> verify whether he was real or a spam source. Somehow that option is not
> available to me now. Can you please let me know how this option can be
> activated in spam assasin. Below is an excerpt of the same feature which I
> have mentioned above.
> 
>> "
>> Subject: Your email requires
>> verificationverify#EdsAtW8RAHzEKlx83QUQtDhQLl6DnCF9
>>
>>
>> The message you sent requires that you verify that you
>> are a real live human being and not a spam source.
>>
>> To complete this verification, simply reply to this message and leave
>> the subject line intact.
>>
>> The headers of the message sent from your address are show below:
>>
>>> >From cygan@vsnl.com Wed Jan 18 01:19:06 2006
>> Received: from wwwparm by gains.house4domains.com with local-bsmtp (Exim
>> 4.52)
>>  id 1Ez7ax-0001Bz-FM
>>  for sunil@parmanandindia.com; Wed, 18 Jan 2006 01:19:05 -0600
>> X-Spam-Checker-Version: SpamAssassin 3.1.0 (2005-09-13) on
>> 	gains.house4domains.com
>> X-Spam-Level:
>> X-Spam-Status: No, score=-1.4 required=5.0 tests=ALL_TRUSTED
>> 	autolearn=unavailable version=3.1.0
>> Received: from [59.182.37.119] (helo=rpp)
>> 	by gains.house4domains.com with esmtpa (Exim 4.52)
>> 	id 1Ez7av-0001BG-82
>>
>> "
> 
> 
> 
>  I shall be highly obliged if you could let me know how the same can be
>  enabled again.
> 
> 

Spamassassin might have scanned this message, but it in no way produced 
the output you are referring to.  This has to have been some C/R system 
which SA does not use.

-Jim

Re: Spam assasin query

Posted by "John D. Hardin" <jh...@impsec.org>.
On Fri, 10 Nov 2006, Ramdas P. Prabhu wrote:

> Some time back, I had enabled some option in spam assasin whereby
> anyone who sent me a mail received an automated message to click
> on a link in order to verify whether he was real or a spam source.

PLEASE do not do this. This will help mailbomb anyone whose name is
forged as the sender address on a spam that you receive. Do you really
want to be a DDoS multiplier?

Also, many people will say "if it's that hard to talk to you, why
bother?" I know *I* do.

Also, you are training people to click on links received in email.
Given the vulnerability of the most-widely-used end-user platform to
exploits via malicious websites, this is *not* something you want to
encourage.

If your SA installation is running properly a challenge/response
mechanism like this is not needed.

--
 John Hardin KA7OHZ                    http://www.impsec.org/~jhardin/
 jhardin@impsec.org    FALaholic #11174     pgpk -a jhardin@impsec.org
 key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
-----------------------------------------------------------------------
  It is not the business of government to make men virtuous or
  religious, or to preserve the fool from the consequences of his own
  folly.                                              -- Henry George
-----------------------------------------------------------------------
 Tomorrow: Veterans Day