Watermarking should do something now

Julian Field MailScanner at ecs.soton.ac.uk
Fri Jul 13 22:26:42 IST 2007


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1



Chris Yuzik wrote:
> Julian Field wrote:
>> -----BEGIN PGP SIGNED MESSAGE-----
>> Hash: SHA1
>>
>> I have hopefully fixed the watermarking setup so it should do 
>> something now :-)
>> You'll need to upgrade_MailScanner_conf to pick up the new options 
>> and their docs.
>>
>> Release 4.62.3-2.
>
> Jules,
>
> Did the upgrade to latest beta. Made changes to MailScanner.conf. 
> Restarted MailScanner.
>
> Did same test as this morning.
>
> 1. Sent message from user "a" to user "b"
> 2. User "b" replied to user "a" message with gtube.
> 3. MailScanner tagged message as spam with a score of 997.40 and 
> quarantined it.
>
> I can run further tests if you like, but I'm not really sure what to 
> test.
The watermarking only applies to messages with received with a null 
sender (ie delivery error notifications). The idea is that by spotting a 
valid watermark, you can see that a message delivery error came from a 
delivery you attempted, and that it is not a joe-job attack (where vast 
quantities of spam are sent out claiming to come from you, so that you 
get all the delivery error messages. This can be used as a DoS attack on 
your site, by overwhelming you with delivery error messages. And it's a 
right pain too).

Jules

- -- 
Julian Field MEng CITP
www.MailScanner.info
Buy the MailScanner book at www.MailScanner.info/store

MailScanner customisation, or any advanced system administration help?
Contact me at Jules at Jules.FM

PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654
For all your IT requirements visit www.transtec.co.uk


-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.6.2 (Build 2014)
Charset: ISO-8859-1

wj8DBQFGl+4UEfZZRxQVtlQRAgCoAJ9FD28TCxSbaM1mw72nVnSi1ez7BwCgwViu
tfXnolBvdwITw/xXTy0dUY8=
=e/5o
-----END PGP SIGNATURE-----

-- 
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.
For all your IT requirements visit www.transtec.co.uk



More information about the MailScanner mailing list