Archive for the 'Quarantine' Category

The spammers are using Linux man pages in the spam to bypass bayesian

Hello,

Today, while we are testing quarantine webmail feature in our labs, I got a mail marked as a certainly spam in my SurGATE quarantine mailbox.

The funny part  is here, the  spammer puts the full bash man page to bypass or poison Bayesian database in html div area like below.

But he could not delivery the spam to our mailbox. It was matched by our spam signature database based on url and some other unique patterns in the mail.

</p><p align=”center”><em>YoshiBlade</em> is located at P.O Box 600991 San Diego, CA 92160.<br>
To be Removed from future YoshiBlade mailings, please Click Here!

<img src=”http://SPAMURL/images/a9a4f56d217106465337951325968172954699.gif” border=”0″>
</body>
</html>
<div style=”color:white; font-size:1%; line-height:1px”>

WeNeedYourConfirmationFor1500Deposit
WeNeedYourConfirmationFor1500Deposit
WeNeedYourConfirmationFor1500Deposit

Search

Linux
HomeComputing & TechnologyLinux

SharePrint
LinuxGet StartedExplore LinuxBecome a Guru
Filed In:Linux
Linux / Unix Command: bash

Command Library
NAME

bash – GNU Bourne-Again SHell
SYNOPSIS

….

</p><p align=”center”><em>YoshiBlade</em> is located at P.O Box 600991 San Diego, CA 92160.<br>
To be Removed from future YoshiBlade mailings, please Click Here!

<img src=”http://ihi219.just212011.info/images/a9a4f56d217106465337951325968172954699.gif” border=”0″>
</body>
</html>
<div style=”color:white; font-size:1%; line-height:1px”>

WeNeedYourConfirmationFor1500Deposit
WeNeedYourConfirmationFor1500Deposit
WeNeedYourConfirmationFor1500Deposit

Search

Linux
HomeComputing & TechnologyLinux

SharePrint
LinuxGet StartedExplore LinuxBecome a Guru
Filed In:Linux
Linux / Unix Command: bash

Command Library
NAME

bash – GNU Bourne-Again SHell
SYNOPSIS

Initial version of quarantine webmail feature committed on SurGATE trunk

Hello,

Today, I am happy to announce that we completed initial version of quarantine webmail on SurGATE development branch.

We developed self account creation to access quarantine webmail by the users.  If the user domain is managed by SurGATE, we sent an  account activation URL to user’s email address. After the user click on the activation link, he can set his own password.

Then, he can access the his quarantine mailbox with this password. Here is the draft  welcome page. We will improve this page usability before the release!