You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@spamassassin.apache.org by bu...@bugzilla.spamassassin.org on 2012/12/08 02:39:25 UTC

[Bug 6873] New: Please blacklist exodusrobot@yahoo.com from your spam list

https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6873

            Bug ID: 6873
           Summary: Please blacklist exodusrobot@yahoo.com from your spam
                    list
           Product: Spamassassin
           Version: SVN Trunk (Latest Devel Version)
          Hardware: All
                OS: All
            Status: NEW
          Severity: blocker
          Priority: P2
         Component: spamassassin
          Assignee: dev@spamassassin.apache.org
          Reporter: exodusrobot@yahoo.com
    Classification: Unclassified

I'm the maintainer of Parted Magic and I've been using exodusrobot@yahoo.com
for 10+ years as my primary e-mail. When people sign-up for my forum or have
anything to do with spamassassin the official e-mail address for everything
Parted Magic is marked as spam. This is the only known software that blocks a
major OSS project from conducting simple tasks. Please fix it. To say the least
it's irritating. This reminds me of some of the virus scanners out there that
mark everything compressed with upx as a virus.

Do you know why this pisses me off? Over the years I could have lost 1,000s of
bug reports because a few assholes marked my e-mail as spam. By looking at your
software, that's all it takes. I could mark anybody's e-mail as spam and your
program will do the same thing.

I have reported this several times over the past 6 years and it still isn't
resolved. FIX IT!!!11!

P.S. Your bug tracker took this same "spam" address without issue and allowed
me to sign up.

-- 
You are receiving this mail because:
You are the assignee for the bug.

[Bug 6873] Please blacklist exodusrobot@yahoo.com from your spam list

Posted by bu...@bugzilla.spamassassin.org.
https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6873

--- Comment #4 from John Hardin <jh...@impsec.org> ---
(In reply to comment #3)
> perhaps "apache@partedmagic.com" as is being used for the HELO

Oops. That should be "as is being used for the envelope from".

-- 
You are receiving this mail because:
You are the assignee for the bug.

[Bug 6873] Please blacklist exodusrobot@yahoo.com from your spam list

Posted by bu...@bugzilla.spamassassin.org.
https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6873

Patrick Verner <ex...@yahoo.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|NEW                         |RESOLVED
                 CC|                            |exodusrobot@yahoo.com
         Resolution|---                         |WONTFIX

--- Comment #2 from Patrick Verner <ex...@yahoo.com> ---
That's pretty much the response I expected. I'll make a note that Spamassassin
tosses my e-mail in the garbage when anybody uses Spamassassin and signs up for
the forum.

-- 
You are receiving this mail because:
You are the assignee for the bug.

[Bug 6873] Please blacklist exodusrobot@yahoo.com from your spam list

Posted by bu...@bugzilla.spamassassin.org.
https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6873

Darxus <Da...@ChaosReigns.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |Darxus@ChaosReigns.com

--- Comment #5 from Darxus <Da...@ChaosReigns.com> ---
Nice John.  Although I wonder if adding that to your ham corpus is a good idea
when the problem seems pretty fixable on Patrick's end.  Do you really want to
drop the score of those rules for this case?

-- 
You are receiving this mail because:
You are the assignee for the bug.

[Bug 6873] Please blacklist exodusrobot@yahoo.com from your spam list

Posted by bu...@bugzilla.spamassassin.org.
https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6873

--- Comment #6 from John Hardin <jh...@impsec.org> ---
(In reply to comment #5)
> Nice John.  Although I wonder if adding that to your ham corpus is a good
> idea when the problem seems pretty fixable on Patrick's end.  Do you really
> want to drop the score of those rules for this case?

I'd be suprised if *one ham* has much effect.

-- 
You are receiving this mail because:
You are the assignee for the bug.

[Bug 6873] Please blacklist exodusrobot@yahoo.com from your spam list

Posted by bu...@bugzilla.spamassassin.org.
https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6873

--- Comment #7 from John Hardin <jh...@impsec.org> ---
In consideration that this _is_ a FP, how about: if FORGED_YAHOO_RCVD hits and
a reply-to header is present and that address is in the yahoo.com domain,
subtract back a point?

-- 
You are receiving this mail because:
You are the assignee for the bug.

[Bug 6873] Please blacklist exodusrobot@yahoo.com from your spam list

Posted by bu...@bugzilla.spamassassin.org.
https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6873

John Hardin <jh...@impsec.org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |jhardin@impsec.org

--- Comment #3 from John Hardin <jh...@impsec.org> ---
If you won't provide any details about what happens when it misbehaves how are
we supposed to fix it?

Please note, there are no specific-email-address blacklists provided in the
base SpamAssassin install. If your specific email address is being rejected,
then it's likely due to local explicit blacklists created by individual admins,
about which we can do nothing.

Otherwise, and most likely, it's some set of rules that are consistently
hitting on those emails.

In either case *provide us examples*, because we genuinely do want to minimize
SA's propensity for false positives. If you have the post-processing headers
from an email of yours that was rejected because SA scored it as spammy, please
provide those headers in an email to the SA users list so that we have some
chance of figuring out the cause. A bounce from an SMTP-time reject is likely
not useful because it likely doesn't include any of the specific rules that
hit.

For forum messages being rejected, it may be something that your forum software
is doing to the email messages it sends that makes them look spammy. You did
not tell us *what* forum this is; I'm going to *guess* you're referring to
http://forums.partedmagic.com and I am going to register so that maybe I can
see what is happening. If I've guessed wrong please tell us *which* forum you
are referring to.

Throwing a snit may make you feel better but it won't get the problem solved,
and it reflects much more on _your_ professionalism than on ours.

Also: "I have reported this several times over the past 6 years" - where?
Neither your name nor your email address nor "parted" in this context appear
anywhere in the mailing list archives or the SA bugzilla. As far as I can tell
this is the first report of this problem.

...time passes...

Okay, the forum confirmation mail just came through. Here are the only two rule
hits that add anything to the score:

        *  2.4 FORGED_YAHOO_RCVD 'From' yahoo.com does not match 'Received'
headers
        *  2.6 RDNS_DYNAMIC Delivered to internal network by host with
        *      dynamic-looking rDNS

Both of these are due to questionable practices on your part, and that you can
probably fix very easily.

(1) The email from the forum does NOT pass through Yahoo's mail servers at any
point. Since you already set Reply-To and Sender headers, I suggest that you
change the From: to something that is not in the Yahoo domain - perhaps
"apache@partedmagic.com" as is being used for the HELO, or
"forum@partedmagic.com".

(2) The rDNS for your server looks suspicious (from a spam point of view):

Received: from partedmagic.com (client-208-92-232-31.sevenl.net [208.92.232.31]
(may be forged))
    by ga.impsec.org (8.13.7/8.13.7) with ESMTP id qB8KSxSD016553
    (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO)
    for <jh...@impsec.org>; Sat, 8 Dec 2012 12:29:03 -0800

If you're truly sending this from a dynamic IP there's little we can do about
it, that's going to score some spamminess points. If it's a static IP, contact
your ISP and see if they can get the rDNS set to something that doesn't look
dynamic; ideally forward and reverse DNS should match, and would be something
from the partedmagic.com domain to match the HELO and (changed) From address.

Basically, you've configured your forum to look like a spambot.

I have added the confirmation email to my ham corpus, perhaps it will cause the
rescorer to reduce the points assigned to those rules. No guarantees, though,
unless perhaps other masscheck contributors also do what I have just done.

-- 
You are receiving this mail because:
You are the assignee for the bug.

[Bug 6873] Please blacklist exodusrobot@yahoo.com from your spam list

Posted by bu...@bugzilla.spamassassin.org.
https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6873

RW <rw...@googlemail.com> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |rwmaillists@googlemail.com

--- Comment #1 from RW <rw...@googlemail.com> ---
If someone came to your bug tracker and reported a bug that read "Parted Magic
no work - FIX IT", how much time would you devote to that?

Please take this to the user list and provide some actual evidence.
Spamassassin doesn't work like a virus scanner and it doesn't target recipient
addresses.

-- 
You are receiving this mail because:
You are the assignee for the bug.