Web lists-archives.com

Re: Your Password Reset Link from CorrLinks




On Thu, Feb 21, 2019 at 10:55:44AM +0300, Reco wrote:
> 	Hi.
> 
> On Thu, Feb 21, 2019 at 02:30:48AM -0500, Gene Heskett wrote:
> > On Thursday 21 February 2019 01:14:03 Web@xxxxxxxxxxxxx wrote:
> > 
> > > To reset your password, please click the link below.  This link will
> > > expire in 24 hours.
> > >
> > > <dumb spammer link was here>
> > 
> > Whats worse is that my isp is rightfully rejecting some of this bs as 
> > spam, but I get the threatening msgs from the debian server, threatening 
> > to unsuscribe me for the bounces.
> 
> You do not bounce to the list - [1]. Yes, even if it's spam.
> They will excommunicate you if you insist on bouncing to the list.

+10 (duh, as an "antisocial network" hater, I never thought I'd be
doing this). You shouldn't /bounce/ spam anyway: where are you going
to bounce it to? To a most probably spoofed address, i.e. to a
totally innocent victim? Thus generating reflected spam, aka Joe
Jobs?

If your mail provider is doing this, he is incompetent and you
should bounce HIM. The only fair game these days is to reject the
message while it's being delivered.

> If you want to notify listmaster team about spam, you should bounce to [2].

I'm using [3]. What do folks think is the Right Thing To Do?

> > debian shoulda rejected it in the first place.
> 
> And you can help this by reporting an offending e-mail as spam, see [1].

Exactly. "debian" is "all of us". We ain't Big Blue or Microsoft
or something (that's at least why /I/ am here).

FWIW, the list spam checker wasn't way off the mark:

  X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on bendel.debian.org
  X-Spam-Level: **
  X-Spam-Status: No, score=2.7 required=4.0 tests=DIGITS_LETTERS,DKIM_SIGNED,
    [...]

Interestingly, the mail itself seems genuine, coming from corrlinks [4],
some kind of state-backed jail inmate exploitation schema. Shudder. Just
their web "masters" seem to have enabled a spam hub in their infinite
wisdom.

Cheers

[1] https://wiki.debian.org/Teams/ListMaster/FAQ
[2] mailto:listmaster@xxxxxxxxxxxxxxxx
[3] mailto:report-listspam@xxxxxxxxxxxxxxxx
-- tomás

Attachment: signature.asc
Description: Digital signature