Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

C is quirky, flawed, and an enormous success -- Dennis M. Ritchie


computers / news.admin.net-abuse.usenet / Current Usenet anti-spam measures

SubjectAuthor
* Current Usenet anti-spam measuresRayner Lucas
+* Current Usenet anti-spam measuresIvo Gandolfo
|+- Current Usenet anti-spam measuresyamo'
|`- Current Usenet anti-spam measuresRayner Lucas
+* Current Usenet anti-spam measuresMarc SCHAEFER
|`- Current Usenet anti-spam measuresRayner Lucas
+- Current Usenet anti-spam measuresSn!pe
`- Current Usenet anti-spam measuresRayner Lucas

1
Current Usenet anti-spam measures

<MPG.3f404d70284a94c79896be@news.eternal-september.org>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=1714&group=news.admin.net-abuse.usenet#1714

  copy link   Newsgroups: news.admin.net-abuse.usenet
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: usenet202101@magic-cookie.co.ukNOSPAMPLEASE (Rayner Lucas)
Newsgroups: news.admin.net-abuse.usenet
Subject: Current Usenet anti-spam measures
Date: Fri, 11 Aug 2023 14:52:21 +0100
Organization: The Lumber Cartel (TINLC)
Lines: 22
Message-ID: <MPG.3f404d70284a94c79896be@news.eternal-september.org>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Injection-Info: dont-email.me; posting-host="5f24bda655649ee9f9a19cb2d29677f5";
logging-data="923391"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18RKIOc5rizNZEiUHfwKt8s"
User-Agent: MicroPlanet-Gravity/3.0.4
Cancel-Lock: sha1:dWpZ43oumIesaD6X3mSmTqyZfzk=
 by: Rayner Lucas - Fri, 11 Aug 2023 13:52 UTC

Hi folks,

I'm trying to get an overview of what de-spamming measures are currently
in use on Usenet.

Would I be right in thinking most newsadmins are using Cleanfeed as
their main spam-control measure?

Are there any current efforts to identify and reject spam at a level
beyond the individual provider or server admin? The Cleanfeed docs
mention a "bad_hosts_central" file that is meant to be a centrally-
maintained list of servers to reject messages from. However, the link to
it (http://www.mixmin.net/cleanfeed/bad_hosts_central) gives an error
403.

Is anyone still issuing cancels for spam? Is anyone still acting on
them?

What other methods, if any, are people using nowadays?

Regards,
Rayner

Re: Current Usenet anti-spam measures

<ub5f6b$1orvh$1@paganini.bofh.team>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=1715&group=news.admin.net-abuse.usenet#1715

  copy link   Newsgroups: news.admin.net-abuse.usenet
Path: i2pn2.org!i2pn.org!paganini.bofh.team!not-for-mail
From: usenet@bofh.team (Ivo Gandolfo)
Newsgroups: news.admin.net-abuse.usenet
Subject: Re: Current Usenet anti-spam measures
Date: Fri, 11 Aug 2023 16:05:00 +0200
Organization: To protect and to server
Message-ID: <ub5f6b$1orvh$1@paganini.bofh.team>
References: <MPG.3f404d70284a94c79896be@news.eternal-september.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Fri, 11 Aug 2023 14:04:59 -0000 (UTC)
Injection-Info: paganini.bofh.team; logging-data="1863665"; posting-host="QFOwQB3J/Oe3xd8vsWzMiA.user.paganini.bofh.team"; mail-complaints-to="usenet@bofh.team"; posting-account="NnMoDEm3qkIJGKBtBYRUeg";
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.14.0
Cancel-Lock: sha256:qHqCtH6SVsJgzAvmgCgWzv1Mf7KyjdRZe+V7l6puWQc=
X-Notice: Filtered by postfilter v. 0.9.3
Content-Language: en-US
 by: Ivo Gandolfo - Fri, 11 Aug 2023 14:05 UTC

On 11/08/2023 15:52, Rayner Lucas wrote:
> Hi folks,
>
> I'm trying to get an overview of what de-spamming measures are currently
> in use on Usenet.
[cut]
>
> Regards,
> Rayner

Hi Rayner,

right now Usenet is left in a lot of disarray, so individual
administrators must necessarily rely on their own strength to keep SPAM
(in all its genres and forms) away.

In addition to the aforementioned CleanFeed, there are other ways to
keep spam away. For example NoCem-On-Spool. There are several bots that
are currently at work deleting unwanted messages, in some cases
automatically or "manually", and it is the bot operators who ensure
correct functioning and possibly few (or no) false positives.
Another way is to write your own filter, which using spamassassin or
other (like I do on my server which has an "open-server" policy, so
everyone can read and write with certain limits) eliminates or doesn't
accept all the unwanted.

Sincerely

--
Ivo Gandolfo
Newsmaster

Re: Current Usenet anti-spam measures

<ub5kt4$jgm$2@shakotay.alphanet.ch>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=1716&group=news.admin.net-abuse.usenet#1716

  copy link   Newsgroups: news.admin.net-abuse.usenet
Path: i2pn2.org!i2pn.org!news.alphanet.ch!alphanet.ch!.POSTED!not-for-mail
From: schaefer@alphanet.ch (Marc SCHAEFER)
Newsgroups: news.admin.net-abuse.usenet
Subject: Re: Current Usenet anti-spam measures
Supersedes: <ub5krd$jgm$1@shakotay.alphanet.ch>
Date: Fri, 11 Aug 2023 15:42:28 -0000 (UTC)
Organization: Posted through news.alphanet.ch
Message-ID: <ub5kt4$jgm$2@shakotay.alphanet.ch>
References: <MPG.3f404d70284a94c79896be@news.eternal-september.org>
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
Injection-Date: Fri, 11 Aug 2023 15:42:28 -0000 (UTC)
Injection-Info: shakotay.alphanet.ch; posting-account="schaefer";
logging-data="19990"; mail-complaints-to="usenet@alphanet.ch"; posting-host="634ce6c9682d817d72f6177875e2bb4f.nnrp.alphanet.ch"
User-Agent: tin/2.4.3-20181224 ("Glen Mhor") (UNIX) (Linux/4.19.0-25-amd64 (x86_64))
Cancel-Key: sha256:y267OfR/tvrSbo/vFLt3GsqdHGSJ55pKONh03W9v/s4=
Cancel-Lock: sha256:/K7bve39S712QklvwIPVSSHZsw2vlcvAGYRt+4SxeV0= sha256:tlkLtsiXaB+ykZzqn4DXJC3LIu0gSUNcHGbQ80SWIkM=
 by: Marc SCHAEFER - Fri, 11 Aug 2023 15:42 UTC

On Fri, 11 Aug 2023 15:52:21, Rayner Lucas <usenet202101@magic-cookie.co.uknospamplease> wrote:
> Would I be right in thinking most newsadmins are using Cleanfeed as
> their main spam-control measure?

We use it here, but in a special way: we use a NNTP/NNRP proxy which can
allow user to choose what category they want to hide.

We use this for NoCeMs, most of cleanfeed (we still cancel binaries
locally, e.g.), etc.

As it's not really easy to see how our scheme work without a NNTP/NNRP
account, here is a quick web (not NNTP/NNRP) demo.

Look at this newsgroup:

https://nnrp.alphanet.ch/newsgroup-nothreads/news.admin.net-abuse.usenet

now, click on the Config link at the bottom of the page, select
"désactiver tout" at the bottom and then Submit query.

You now have access to news.admin.net-abuse.usenet with a lot of
spam.

Feel free to go back to https://nnrp.alphanet.ch/config and select what
filters you want.

> Is anyone still issuing cancels for spam? Is anyone still acting on
> them?

There are still some bots that send classic cyberspam cancels: bleachbot
and miakibot (fr hierarchy only).

However, a lot of servers only accept Cancel-Key, or sometimes some
NoCeMs.

> What other methods, if any, are people using nowadays?

NoCeM, site admin Cancel-Key.

Typically we use spamassassin to detect spam in the big8, post the
announces to news.lists.filters. Of course it needs configuration on
your part.

Re: Current Usenet anti-spam measures

<1qfb64f.n5e6a715vv679N%snipeco.2@gmail.com>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=1717&group=news.admin.net-abuse.usenet#1717

  copy link   Newsgroups: news.admin.net-abuse.usenet
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!snipe.eternal-september.org!.POSTED!not-for-mail
From: snipeco.2@gmail.com (Sn!pe)
Newsgroups: news.admin.net-abuse.usenet
Subject: Re: Current Usenet anti-spam measures
Date: Fri, 11 Aug 2023 17:11:06 +0100
Organization: Sn!peCo World Wide Wading Birds
Lines: 47
Message-ID: <1qfb64f.n5e6a715vv679N%snipeco.2@gmail.com>
References: <MPG.3f404d70284a94c79896be@news.eternal-september.org> <ub5eo2$1nng$2@gallifrey.nk.ca>
Reply-To: snipeco.1@gmail.com (Sn!pe)
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Info: snipe.eternal-september.org; posting-host="cc46c56c97f696ec0e8e0b8b1d74a039";
logging-data="962833"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+mHrawqNlm/n/HJpz71OgS"
User-Agent: MacSOUP/2.8.6b1 (ed136d9b90) (Mac OS 10.13.6)
Cancel-Lock: sha1:Bebi5jj7C90xznde6KI/wJiVHSA=
X-Validate: All genuine Sn!peCo articles contain the header:
"Injection-Info: snipe.eternal-september.org;" my registered FQDN.
X-Clacks-Overhead: GNU Terry Pratchett; WonK; Large Enid; Peter Green; Jeff Beck
X-Face: 5<x+vv{"AHN,F~/dhf,X*~1zNv[TF/WUe(Uw.*ZOw\P'Ju]C6].T~7Z5cVjV\xTO6&)1#VQ
iZ4vFDG
X-Copyright: Copyright (c) 2023 Sn!peCo WWWB, All Rights Reserved.
This article may be reproduced for the purposes of propagation and
personal use only, no commercial use without express permission.
X-Tongue-In-Cheek: Always
X-Disclaimer: Any advice that I may give is worth only what I paid for it.
This article comprises only my personal opinions unless otherwise stated.
May contain traces of nuts.
 by: Sn!pe - Fri, 11 Aug 2023 16:11 UTC

The Doctor <doctor@doctor.nl2k.ab.ca> wrote:

> In article <MPG.3f404d70284a94c79896be@news.eternal-september.org>,
> Rayner Lucas <usenet202101@magic-cookie.co.ukNOSPAMPLEASE> wrote:
> >Hi folks,
> >
> >I'm trying to get an overview of what de-spamming measures are currently
> >in use on Usenet.
> >
> >Would I be right in thinking most newsadmins are using Cleanfeed as
> >their main spam-control measure?
> >
> >Are there any current efforts to identify and reject spam at a level
> >beyond the individual provider or server admin? The Cleanfeed docs
> >mention a "bad_hosts_central" file that is meant to be a centrally-
> >maintained list of servers to reject messages from. However, the link to
> >it (http://www.mixmin.net/cleanfeed/bad_hosts_central) gives an error
> >403.
> >
> >Is anyone still issuing cancels for spam? Is anyone still acting on
> >them?
> >
> >What other methods, if any, are people using nowadays?
> >
> >Regards,
> >Rayner
> >
>
> Mixmin has been spamjacked.
>

In what way is that relevant to this query?



> Better to ask news.software.nntp .
>
> Which NNTP server are you using?
>

Is there some reason why you do not believe
his article's eternal-september headers?

--
^Ï^. – Sn!pe – <https://youtu.be/_kqytf31a8E>

My pet rock Gordon just is.

Re: Current Usenet anti-spam measures

<ub7uas$j2e$1@rasp.pasdenom.info>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=1718&group=news.admin.net-abuse.usenet#1718

  copy link   Newsgroups: news.admin.net-abuse.usenet
Path: i2pn2.org!i2pn.org!paganini.bofh.team!pasdenom.info!.POSTED.newsportal.pasdenom.info!newsportal
From: news@pasdenom.info (yamo')
Newsgroups: news.admin.net-abuse.usenet
Subject: Re: Current Usenet anti-spam measures
Date: Sat, 12 Aug 2023 12:35:40 -0000 (UTC)
Organization: <https://pasdenom.info/news.html>
Message-ID: <ub7uas$j2e$1@rasp.pasdenom.info>
References: <MPG.3f404d70284a94c79896be@news.eternal-september.org>
<ub5f6b$1orvh$1@paganini.bofh.team>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Sat, 12 Aug 2023 12:35:40 -0000 (UTC)
Injection-Info: newsportal.pasdenom.info; posting-account="stephane@usenet";
posting-host="37.169.115.218" logging-data="http";
mail-complaints-to="abuse@pasdenom.info"
User-Agent: NewsPortal/0.52.a8
( https://gitlab.com/yamo-nntp/newsportal )
Cancel-Lock: sha256:pOzfHj2qGcQlhrGtFjtrDt9WACXaiquuFhTojKMYEko=
Http-User-Agent: Mozilla/5.0 (Linux; Android 11) AppleWebKit/537.36 (KHTML,
like Gecko) Version/4.0 Chrome/115.0.5790.166 Mobile DuckDuckGo/5
Safari/537.36
 by: yamo' - Sat, 12 Aug 2023 12:35 UTC

Hi,

Ivo Gandolfo a écrit :

> In addition to the aforementioned CleanFeed, there are other ways to
> keep spam away. For example NoCem-On-Spool. There are several bots that
> are currently at work deleting unwanted messages, in some cases
> automatically or "manually", and it is the bot operators who ensure
> correct functioning and possibly few (or no) false positives.

Yes, I saw that my bot mark as spam the posts of an user on your server
maybe he wrote often the same words?
Often the notices "spam" from nono are really goods, I will look at that in
august...

I cannot see if there is false positive on alphanet nocem notices but it is
also based on spamassassin.

> Another way is to write your own filter, which using spamassassin or
> other (like I do on my server which has an "open-server" policy, so
> everyone can read and write with certain limits) eliminates or doesn't
> accept all the unwanted.

It is possible, I can send by mail my config (on cleanfeed.local) which drop
a lot of spam :
<https://pasdenom.info/usenet/news-notice.2023.08.11-06.15.02.html#innd_perl>

--
Stéphane
Sorry for my bad English

Re: Current Usenet anti-spam measures

<MPG.3f45c0e536eb75289896bf@news.eternal-september.org>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=1720&group=news.admin.net-abuse.usenet#1720

  copy link   Newsgroups: news.admin.net-abuse.usenet
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: usenet202101@magic-cookie.co.ukNOSPAMPLEASE (Rayner Lucas)
Newsgroups: news.admin.net-abuse.usenet
Subject: Re: Current Usenet anti-spam measures
Date: Tue, 15 Aug 2023 18:06:22 +0100
Organization: The Lumber Cartel (TINLC)
Lines: 31
Message-ID: <MPG.3f45c0e536eb75289896bf@news.eternal-september.org>
References: <MPG.3f404d70284a94c79896be@news.eternal-september.org> <ub5eo2$1nng$2@gallifrey.nk.ca>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Injection-Info: dont-email.me; posting-host="736dbc0729578ca689565ecfcfe962db";
logging-data="3063619"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/X22+n0FJbKm2V6zAika+7"
User-Agent: MicroPlanet-Gravity/3.0.4
Cancel-Lock: sha1:o+NbA4Ch8N1VMh+RR2Lw3DtjxjM=
 by: Rayner Lucas - Tue, 15 Aug 2023 17:06 UTC

In article <ub5eo2$1nng$2@gallifrey.nk.ca>, doctor@doctor.nl2k.ab.ca
says...
>
> In article <MPG.3f404d70284a94c79896be@news.eternal-september.org>,
> Rayner Lucas <usenet202101@magic-cookie.co.ukNOSPAMPLEASE> wrote:
> >
> >Are there any current efforts to identify and reject spam at a level
> >beyond the individual provider or server admin? The Cleanfeed docs
> >mention a "bad_hosts_central" file that is meant to be a centrally-
> >maintained list of servers to reject messages from. However, the link to
> >it (http://www.mixmin.net/cleanfeed/bad_hosts_central) gives an error
> >403.
>
> Mixmin has been spamjacked.
>
> Better to ask news.software.nntp .
>
> Which NNTP server are you using?

Hmm, I'm out of the loop with whatever's been happening at Mixmin. The
Cleanfeed web pages still seem to be there, but not sure how up to date
anything is.

I'm currently posting via Eternal September, but have been planning to
set up INN (with some degree of spam filtering) for testing and/or
personal use. Mostly I wanted to make sure I was up-to-date and informed
about what people are currently doing to keep Usenet running smoothly.

Thanks for the reply!

Rayner

Re: Current Usenet anti-spam measures

<MPG.3f45c12f799694229896c0@news.eternal-september.org>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=1721&group=news.admin.net-abuse.usenet#1721

  copy link   Newsgroups: news.admin.net-abuse.usenet
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: usenet202101@magic-cookie.co.ukNOSPAMPLEASE (Rayner Lucas)
Newsgroups: news.admin.net-abuse.usenet
Subject: Re: Current Usenet anti-spam measures
Date: Tue, 15 Aug 2023 18:07:33 +0100
Organization: The Lumber Cartel (TINLC)
Lines: 30
Message-ID: <MPG.3f45c12f799694229896c0@news.eternal-september.org>
References: <MPG.3f404d70284a94c79896be@news.eternal-september.org> <ub5f6b$1orvh$1@paganini.bofh.team>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Injection-Info: dont-email.me; posting-host="736dbc0729578ca689565ecfcfe962db";
logging-data="3063619"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX187+6svSY6MnQjiSLFpfqSa"
User-Agent: MicroPlanet-Gravity/3.0.4
Cancel-Lock: sha1:iB57i6G/qS3v5Jybbd23Zr1zTqE=
 by: Rayner Lucas - Tue, 15 Aug 2023 17:07 UTC

In article <ub5f6b$1orvh$1@paganini.bofh.team>, usenet@bofh.team says...
>
> Hi Rayner,
>
> right now Usenet is left in a lot of disarray, so individual
> administrators must necessarily rely on their own strength to keep SPAM
> (in all its genres and forms) away.
>
> In addition to the aforementioned CleanFeed, there are other ways to
> keep spam away. For example NoCem-On-Spool. There are several bots that
> are currently at work deleting unwanted messages, in some cases
> automatically or "manually", and it is the bot operators who ensure
> correct functioning and possibly few (or no) false positives.
> Another way is to write your own filter, which using spamassassin or
> other (like I do on my server which has an "open-server" policy, so
> everyone can read and write with certain limits) eliminates or doesn't
> accept all the unwanted.

Hi Ivo,

Thank you for this. It looks like the NoCeM Registry is still actively
updated and even gets new participants, which is great to see.

I had the impression that (as you say) news admins were mostly relying
on their own efforts to keep spam off their servers. But it is
encouraging to know that there is still co-ordination happening at a
higher level.

Best regards,
Rayner

Re: Current Usenet anti-spam measures

<MPG.3f45c222a1d8a3bc9896c1@news.eternal-september.org>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=1722&group=news.admin.net-abuse.usenet#1722

  copy link   Newsgroups: news.admin.net-abuse.usenet
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: usenet202101@magic-cookie.co.ukNOSPAMPLEASE (Rayner Lucas)
Newsgroups: news.admin.net-abuse.usenet
Subject: Re: Current Usenet anti-spam measures
Date: Tue, 15 Aug 2023 18:11:34 +0100
Organization: The Lumber Cartel (TINLC)
Lines: 33
Message-ID: <MPG.3f45c222a1d8a3bc9896c1@news.eternal-september.org>
References: <MPG.3f404d70284a94c79896be@news.eternal-september.org> <ub5kt4$jgm$2@shakotay.alphanet.ch>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Injection-Info: dont-email.me; posting-host="736dbc0729578ca689565ecfcfe962db";
logging-data="3063619"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+eMtbADOwQmTv3pjWf6CRt"
User-Agent: MicroPlanet-Gravity/3.0.4
Cancel-Lock: sha1:IIXLzUnOodB6mTgZCheksMFjOgA=
 by: Rayner Lucas - Tue, 15 Aug 2023 17:11 UTC

In article <ub5kt4$jgm$2@shakotay.alphanet.ch>, schaefer@alphanet.ch
says...
>
> On Fri, 11 Aug 2023 15:52:21, Rayner Lucas
> <usenet202101@magic-cookie.co.uknospamplease> wrote:
> > Would I be right in thinking most newsadmins are using Cleanfeed as
> > their main spam-control measure?
>
> We use it here, but in a special way: we use a NNTP/NNRP proxy which can
> allow user to choose what category they want to hide.
>
> We use this for NoCeMs, most of cleanfeed (we still cancel binaries
> locally, e.g.), etc.
>
[snip explanations]
>
> Typically we use spamassassin to detect spam in the big8, post the
> announces to news.lists.filters. Of course it needs configuration on
> your part.

Thank you for such a detailed reply with a demo of your spam-filtering
measures.

I did not know that any sites were configured to allow users to choose
which categories of spam-filtering to use. That is an ingenious way of
implementing it, very nice!

I appreciate all the other pointers too, particularly the explanation of
how you're using news.lists.filters. Thank you for the education, I now
feel like I have a much better idea of what's possible.

Thanks and regards,
Rayner

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor