Live data from Hacker News

A little trick to spam the spammers (2021)

misc.l3m.in

181–190 of 231 posts

Re: A little trick to spam the spammers (2021)

#181

Earlier quoted context omitted.

I think Log4shell was about the closest we got to this. It’s still crazy to me you could exploit an unknown machine by leaving a string of text somewhere and waiting for a vulnerable client to process it. I imagine many spammers are running a lot of insecure PHP and Perl scripts to support their operation. That was certainly the case back in ~2006, and I imagine most “new entrant” spammers are not using email but rat…

Reminds me of leaving “+++” in bbs posts. This the the AT “hangup” command and would often cause the reader’s modem to disconnect from the internet.

10 year old me hates you :P

Re: A little trick to spam the spammers (2021)

#182

I run marketing email databases. This is cute, but it doesn't actually do anything in most systems - either the employees all already get the marketing emails or there is a system-wide rule to suppress against the email domain. If you actually want to (potentially) break something, try submitting some obscure characters or malformed html into some fields. Blank spaces in emails can particularly be a nuisance. And if…

Would it work if I create a mail alias on my domain that forwards to the CEOs mail? Assuming I only do that for one address per company and they're not all hosting with the same provider, it could take a while until my box ends up on a blacklist.

Re: A little trick to spam the spammers (2021)

#183

Earlier quoted context omitted.

Are you mixing up archive.org (the Internet Archive, a nonprofit company headquartered in San Francisco) with archive.is/archive.ph/archive.today, which ignores robots.txt, and is a for-profit company with unknown owners and an unknown location?

No, I'm talking about archive.org, specifically their "wayback machine".

I had to have content removed from the wayback machine and it was pretty simple and painless all said. Perhaps it's gotten better over time?

Re: A little trick to spam the spammers (2021)

#184
This guy has a different idea of what spam is than I do.

If you examine a website looking for "sign-me-up" buttons, and click them, and submit a subscription form, then you've solicited their newsletter.

Whether you define spam as "Unsolicited Commercial Email" or "Unsolicited Bulk Email", it ain't spam if you asked for it.

Re: A little trick to spam the spammers (2021)

#185
post #51

Earlier quoted context omitted.

I spent hours on bash.org when I found it a few years ago. Thank you for reminding me of it!

Ah hunter7 … great memories. The first time I found bash.org I was in tears of laughter for hours reading through it. Back when web culture was smart .

it was hunter2. I know cause if it was actually hunter7, I would only see **** in your post, but I actually saw ***7.

Re: A little trick to spam the spammers (2021)

#186

Earlier quoted context omitted.

Ah hunter7 … great memories. The first time I found bash.org I was in tears of laughter for hours reading through it. Back when web culture was smart .

it was hunter2. I know cause if it was actually hunter7, I would only see **** in your post, but I actually saw ***7.

Yes! Of course it was ***2, brain fart!

Re: A little trick to spam the spammers (2021)

#187

I wonder if most sites maintain any of the following addresses or not for externally incoming mail: hostmaster@ postmaster@ webmaster@ dns-admin@ info@ contact@ root@ (And if they do, if anyone is actually reading the mail coming to those addresses.) I used to but I got so much spam and 0 actually legit mails to these addresses on my own domains so I stopped accepting externally incoming mails for those names/aliases…

These types of addresses are actually used by corporate anti-spam software and they are called "honeypots". The idea being you setup a inbox with no public email address and report any IP Addresses sending it emails. There is no legitimate reason someone should be emailing these addresses, so it's an obvious flag that someone is being naughty.

Those addresses are role addresses; depending on what services you are providing, you should have have those addresses, and you should read them. They are often aliased to root@. They are not called "honeypots".

A honeypot is an email address that should never get email, typically because the only way a spammer can capture the address is by scraping a web-page. Role addresses don't need to be scraped; they're well-known.

Re: A little trick to spam the spammers (2021)

#188
post #140

Earlier quoted context omitted.

Part of the problem is from admins creating lists and putting users on them without user knowing anything about it. Can you blame users for being confused and seeking to get off a list in the only way they know how? IT Admins bare blame in these incidents. The users just make it fun for everyone but IT, but IT hopefully sees the fun later when they aren't running around putting out the fire

IT Admins bare blame in these incidents. May I amend this to say "IT policies " are to blame? Thinking back to my own days in the IT Department, I would have LOVED to say "No" to the requests to make yet another distribution list for a Senior Manager or Director, full of everyone and their assistants for the very same reason as you (plus a few other reasons), but that was just one of the many things I had a lot of po…

[deleted]

Re: A little trick to spam the spammers (2021)

#189

Earlier quoted context omitted.

I think Log4shell was about the closest we got to this. It’s still crazy to me you could exploit an unknown machine by leaving a string of text somewhere and waiting for a vulnerable client to process it. I imagine many spammers are running a lot of insecure PHP and Perl scripts to support their operation. That was certainly the case back in ~2006, and I imagine most “new entrant” spammers are not using email but rat…

Reminds me of leaving “+++” in bbs posts. This the the AT “hangup” command and would often cause the reader’s modem to disconnect from the internet.

Didn't that just put the modem into "command mode"? I thought you needed +++ATH.

Re: A little trick to spam the spammers (2021)

#190

https://news.ycombinator.com/item?id=12951917 DonHopkins on Nov 14, 2016 | parent | context | favorite | on: The NHS's 1.2M employees are trapped in a 'reply-a... Back in the days of ARPANET mailing lists, there used to be an "educational" mailing list called "please-remove-me", that was for people who asked an entire mailing list to remove them, instead of removing themselves, or sending email to the administrative…

Something similar happened (multiple times?) when I worked at AWS when someone decided to send a mass email to literally the entire company and people inevitably reply-all enough to clog the system and bring it to its knees. Many confused people were replying "UNSUBSCRIBE" (again, to the whole company) as if it would take them off

when you are oncall and people who are not oncall keep replying to the oncall email in response to the not-incident making pager duty go off like a frog in a sock ..stop it.. I say.. but not reply-all.. 'cause then you footgun again
Post reply on HN