D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Linux - viruses etc

 

On Wed, 6 Feb 2013, Simon Avery wrote:

I used to do that - then gave up.

Tut, no staying power, you youngsters. :)

Hm. I think getting the computer to do the work for you is more efficient..

Up-front is NoListing.

Do you find this useful? When I researched it, much ratware was only
sending to the secondary MX on the logic that it was likely to be less
well defended.

Every little helps and it's free, zero effort.

Next is an RBL check. Sadly I feel that total blocking based on the various
RBL lists out there is not a good thing to do these days, so if an incoming
connection fails the RBLs I check against, then it's plan B.

I score based on RBLs as part of a fairly comprehensive set of rules.
I disagree on some RBL policies, but there are enough around to allow
me to avoid those.

Plan B is Greylisting.

I've done that too, then discarded it. The delay it added was
frustrating and eventually unacceptable. Some wouldn't retry for 5-30
minutes, by which time you've forgotten why you asked for that
password reset was resent and moved onto something else. I like fast
email.

You've cut too much out, so it makes my post miselading, so I'll re-iterate: I don't block email based on RBL, but use it as a means to feed messages into the Greylisting. This means I get instant email from well maintained sites - e.g. password checkers, etc. and suspicious sites get fed through the Greylister.

Mimedefang just flags the message as 'spammy' at that point, then it's up to
my MUA to filter the message into the spam folder. I don't use my MUA's own
filters, but I use procmail. This also filters messages from mailing lists,
etc. into their own folder rather than cluttering up my inbox.

Not used mimedefang. I found procmail too much effort to maintain over time.

The procmail rules are simple - the spam rule:

# Spam
:0:
* ^X-Spam-Score.*
spam


The DCLUG rule:

:0:
* ^Subject:.*\[LUG\]
lug

and so on.

There are also some sendmail rules too which I forgot to mention. Rate limiting and early rejction (is a sending site sends before the first 200 is sent the connection is closed)

After all, what's the alternative?

Skypee

I'm currently working with some people half a world away and they prefer skype typey thing (not voice) to email. I hate it. Really really loathe it. I have to watch for 5 minutes while they type badly formatted text, mis-spelt and just wrong text to me when I could be getting on with something else.

And they call this progress.

Gordon

--
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq