Help! DOS attack

  • Thread starter Thread starter MacWildstar
  • Start date Start date
M

MacWildstar

Is there anyway to prevent a denial of service, "dos attack",? Some jackass
is bombarding one of my email boxes with the w.32.swen.a.mm virus, via
messages like, "deamon mailer" and "microsoft update", and "microsoft
patch".. The anti-virus stuff is catching it so far, but its gone from 3
messages to over 20 per day..
 
Quoth the raven named MacWildstar:
Is there anyway to prevent a denial of service, "dos attack",? Some
jackass is bombarding one of my email boxes with the w.32.swen.a.mm
virus, via messages like, "deamon mailer" and "microsoft update",
and "microsoft patch".. The anti-virus stuff is catching it so far,
but its gone from 3 messages to over 20 per day..

Assuming that macwildstar at charter.net is your correct address, you
will continue to get Swens. It harvests addresses from newsgroups,
y'know. <g> It also reads from victims' local files, looking for
addresses.

Mung your address to something like:
(e-mail address removed)
 
Is there anyway to prevent a denial of service, "dos attack",? Some jackass
is bombarding one of my email boxes with the w.32.swen.a.mm virus, via
messages like, "deamon mailer" and "microsoft update", and "microsoft
patch".. The anti-virus stuff is catching it so far, but its gone from 3
messages to over 20 per day..

Get mailwasher Pro http://www.firetrust.com/home/
You will catch them and delete them from the server without loading
them on your computer.

Franchon
 
MacWildstar said:
Is there anyway to prevent a denial of service, "dos attack",? Some jackass
is bombarding one of my email boxes with the w.32.swen.a.mm virus, via
messages like, "deamon mailer" and "microsoft update", and "microsoft
patch".. The anti-virus stuff is catching it so far, but its gone from 3
messages to over 20 per day..

It's not a DOS attack. And stop posting your real address to newsgroups, it
might help.
I
 
Is there anyway to prevent a denial of service, "dos attack",? Some
jackass is bombarding one of my email boxes with the w.32.swen.a.mm
virus, via messages like, "deamon mailer" and "microsoft update", and
"microsoft patch".. The anti-virus stuff is catching it so far, but
its gone from 3 messages to over 20 per day..

A DOS attack is a flood of Internet traffic sent to your machine to over
load the machine as it tries to respond to the request of sending back
acknowledgement that it's there. The attack is looking to crash the O/S on
the machine as it overwhelms the machine.

Duane :)
 
A DOS attack is a flood of Internet traffic sent to your machine to over
load the machine as it tries to respond to the request of sending back
acknowledgement that it's there. The attack is looking to crash the O/S on
the machine as it overwhelms the machine.

Bollocks are per usual.

You describe a syn flood which is but a subsection of DOS attacks.

You need to be able to grasp that if something denies you service then
it is a denial of service. Surely even you can get that one.


Jim.
 
Bart Bailey said:
I have posted a small (243bytes) filter ruleset to use in Mailwasher Pro
that's very effective against Swen and other spam too.
I must have missed it. Can you post it again or email me? You have my
addresse(s)?
 
Bollocks are per usual.

You describe a syn flood which is but a subsection of DOS attacks.

You need to be able to grasp that if something denies you service then
it is a denial of service. Surely even you can get that one.


Jim.

What the heck are you talking about? Oh, I get 20 emails in my InBox is
some kind of DOS attack. Yeah, right! I get that two to three times a
week and I am not having no DOS attack.

No I cannot grasp that, because it's too rediculous.

And were not going to get started, because you're hitting the killfile. I
don't need this.

Duane
 
Duane said:
What the heck are you talking about?

he's talking about the imprecision of your definition of a DoS...
Oh, I get 20 emails in my InBox is
some kind of DOS attack. Yeah, right! I get that two to three times a
week and I am not having no DOS attack.

No I cannot grasp that, because it's too rediculous.

if 20 is enough to fill your inbox past capacity then 20 is a DoS...
denial of service is a very generic term and it covers a great many
things, including denial of email service due to a full inbox...

it may or may not constitute a DoS *attack* - that part is really quite
dependant on the circumstances (and intent) surrounding a particular
DoS situation...
 
In Message-ID:<baDqb.93857$mZ5.611534@attbi_s54> posted on Fri, 07 Nov
I must have missed it. Can you post it again or email me? You have my
addresse(s)?

---begin---
[enabled],Attachment,Filtered,0,OR,Delete,EntireHeader,contains,multipart,EntireHeader,contains,base64
[enabled],HTML,Filtered,0,OR,Delete,Body,contains,html,EntireHeader,contains,html
[enabled],HTTP,Filtered,0,OR,Delete,Body,contains,http
---end---
(if it wraps, make sure [enabled] is at the beginning of each line)
Call it [filters.txt] and put it in your MWP program folder.
I recently added the transfer type base64, because some spam was using
that to get around the multipart header label requirements of RFC822

These filters use a comma delimited format;
1 - The bracketed [enabled] places a check in the activate box
2 - The name of the rule
3 - "filtered" indicates how the hits are marked
4 - The 0 (zero) is the code for black text, you can change as you like
5 - The OR is boolean for "any" of the conditions being met
6 - "Delete" is how the hits are marked
7 - The part of the message evaluated
8 - indicates criteria for a hit "does or does not contain the keywords"
9 - repeats #8 as often as there are conditions to eval

Note - A pure text spam like the Nigerian 419s will pass these, but they
are so obvious, and varied that they would exceed the point of
diminishing returns to try and accommodate all of their incarnations.
<g>
 
he's talking about the imprecision of your definition of a DoS...


if 20 is enough to fill your inbox past capacity then 20 is a DoS...
denial of service is a very generic term and it covers a great many
things, including denial of email service due to a full inbox...

it may or may not constitute a DoS *attack* - that part is really quite
dependant on the circumstances (and intent) surrounding a particular
DoS situation...

Before you people get started, the whole thread is being killed. Not
because I am running I think you know better than that. I just don't want
to hear it.

Duane
 
Bart said:
In Message-ID:<baDqb.93857$mZ5.611534@attbi_s54> posted on Fri, 07 Nov
Mailwasher Pro >> that's very effective against Swen and other spam
too.
I must have missed it. Can you post it again or email me? You have
my addresse(s)?

---begin---
[enabled],Attachment,Filtered,0,OR,Delete,EntireHeader,contains,multip
art,EntireHeader,contains,base64
[enabled],HTML,Filtered,0,OR,Delete,Body,contains,html,EntireHeader,co
ntains,html [enabled],HTTP,Filtered,0,OR,Delete,Body,contains,http
---end--- (if it wraps, make sure [enabled] is at the beginning of
each line) Call it [filters.txt] and put it in your MWP program
folder. I recently added the transfer type base64, because some spam
was using that to get around the multipart header label requirements
of RFC822

These filters use a comma delimited format;
1 - The bracketed [enabled] places a check in the activate box
2 - The name of the rule
3 - "filtered" indicates how the hits are marked
4 - The 0 (zero) is the code for black text, you can change as you
like 5 - The OR is boolean for "any" of the conditions being met
6 - "Delete" is how the hits are marked
7 - The part of the message evaluated
8 - indicates criteria for a hit "does or does not contain the
keywords" 9 - repeats #8 as often as there are conditions to eval

Note - A pure text spam like the Nigerian 419s will pass these, but
they are so obvious, and varied that they would exceed the point of
diminishing returns to try and accommodate all of their incarnations.
<g>

Hi Bart

I'm new to Mailwasher, can you tell me how to use your filter - I'm
still getting 200+ of the fake "Microsoft patch" emails every day.

TIA
 
In Message-ID:<[email protected]> posted on 7
Bart said:
In Message-ID:<baDqb.93857$mZ5.611534@attbi_s54> posted on Fri, 07 Nov
I have posted a small (243bytes) filter ruleset to use in
Mailwasher Pro >> that's very effective against Swen and other spam
too.
I must have missed it. Can you post it again or email me? You have
my addresse(s)?

---begin---
[enabled],Attachment,Filtered,0,OR,Delete,EntireHeader,contains,multip
art,EntireHeader,contains,base64
[enabled],HTML,Filtered,0,OR,Delete,Body,contains,html,EntireHeader,co
ntains,html [enabled],HTTP,Filtered,0,OR,Delete,Body,contains,http
---end--- (if it wraps, make sure [enabled] is at the beginning of
each line) Call it [filters.txt] and put it in your MWP program
folder. I recently added the transfer type base64, because some spam
was using that to get around the multipart header label requirements
of RFC822

These filters use a comma delimited format;
1 - The bracketed [enabled] places a check in the activate box
2 - The name of the rule
3 - "filtered" indicates how the hits are marked
4 - The 0 (zero) is the code for black text, you can change as you
like 5 - The OR is boolean for "any" of the conditions being met
6 - "Delete" is how the hits are marked
7 - The part of the message evaluated
8 - indicates criteria for a hit "does or does not contain the
keywords" 9 - repeats #8 as often as there are conditions to eval

Note - A pure text spam like the Nigerian 419s will pass these, but
they are so obvious, and varied that they would exceed the point of
diminishing returns to try and accommodate all of their incarnations.
<g>

Hi Bart

I'm new to Mailwasher, can you tell me how to use your filter - I'm
still getting 200+ of the fake "Microsoft patch" emails every day.

TIA

If I may assume you already have MWP configured to access your email
accounts, hit "C" to clear the queue, then close it down. Open notepad,
or whatever text editor you use, and copy and paste the lines between
the begin and end. Save this as filters.txt. Copy it into the program
folder for Mailwasher Pro, if you're asked to replace a file of the same
name, click yes. Now open Mailwasher, hit [ctrl+F7]. On the right tab
"Filters" you'll see three entries, these are the ones you just put
there. you can close that panel with the "X". Go ahead and hit F5 to
check for new mail and give a glance to be sure one of your friends
didn't get tagged, then F6 to see all the swen go away.
 
In Message-ID:<[email protected]>
Before you people get started, the whole thread is being killed. Not
because I am running I think you know better than that. I just don't want
to hear it.

I'm sure that wee bit of breaking news
brings as much sadness to everyone else
as it does to me. <g>
 
Bart said:
In Message-ID:<[email protected]> posted on
Bart said:
In Message-ID:<baDqb.93857$mZ5.611534@attbi_s54> posted on Fri, 07
I have posted a small (243bytes) filter ruleset to use in
Mailwasher Pro >> that's very effective against Swen and other spam
too.

I must have missed it. Can you post it again or email me? You have >> > my addresse(s)?


---begin---
[enabled],Attachment,Filtered,0,OR,Delete,EntireHeader,contains,multip
art,EntireHeader,contains,base64 >> [enabled],HTML,Filtered,0,OR,Delete,Body,contains,html,EntireHeader,co
ntains,html [enabled],HTTP,Filtered,0,OR,Delete,Body,contains,http
---end--- (if it wraps, make sure [enabled] is at the beginning of
each line) Call it [filters.txt] and put it in your MWP program >> folder. I recently added the transfer type base64, because some spam
was using that to get around the multipart header label requirements >> of RFC822 >>
These filters use a comma delimited format;
1 - The bracketed [enabled] places a check in the activate box
2 - The name of the rule
3 - "filtered" indicates how the hits are marked
4 - The 0 (zero) is the code for black text, you can change as you
like 5 - The OR is boolean for "any" of the conditions being met
6 - "Delete" is how the hits are marked
7 - The part of the message evaluated
8 - indicates criteria for a hit "does or does not contain the
keywords" 9 - repeats #8 as often as there are conditions to eval

Note - A pure text spam like the Nigerian 419s will pass these, but
they are so obvious, and varied that they would exceed the point of
diminishing returns to try and accommodate all of their
incarnations. >> said:
Hi Bart

I'm new to Mailwasher, can you tell me how to use your filter - I'm
still getting 200+ of the fake "Microsoft patch" emails every day.

TIA

If I may assume you already have MWP configured to access your email
accounts, hit "C" to clear the queue, then close it down. Open
notepad, or whatever text editor you use, and copy and paste the
lines between the begin and end. Save this as filters.txt. Copy it
into the program folder for Mailwasher Pro, if you're asked to
replace a file of the same name, click yes. Now open Mailwasher, hit
[ctrl+F7]. On the right tab "Filters" you'll see three entries, these
are the ones you just put there. you can close that panel with the
"X". Go ahead and hit F5 to check for new mail and give a glance to
be sure one of your friends didn't get tagged, then F6 to see all the
swen go away.

Thanks, Bart. Works a treat (although in my case I had to paste
"filters.txt" into the "root\documents and settings\<user>\Application
Data\Mailwasher Pro" folder.

Once again, many thanks.
 
Is there anyway to prevent a denial of service, "dos attack",? Some jackass
is bombarding one of my email boxes with the w.32.swen.a.mm virus, via
messages like, "deamon mailer" and "microsoft update", and "microsoft
patch".. The anti-virus stuff is catching it so far, but its gone from 3
messages to over 20 per day..
That's not a DOS attack. It's a mailbomb/flood. 20 per day isn't alot.
 
Duane said:
@news20.bellglobal.com: [snip]
Before you people get started, the whole thread is being killed. Not
because I am running I think you know better than that. I just don't want
to hear it.

well, before us people get offended by being referred to as "you
people", it's worthwhile to note that folks who ignore feedback are in
an emperor's league... and that emperor has new clothes...
 
Back
Top