<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Outbound Email Spam is teh suck</title>
	<atom:link href="http://blogs.iphouse.net/mike/2009/07/outbound-email-spam-is-teh-suck/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.iphouse.net/mike/2009/07/outbound-email-spam-is-teh-suck/</link>
	<description>Spewing from the heart</description>
	<lastBuildDate>Wed, 18 Jan 2012 21:05:41 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: mike</title>
		<link>http://blogs.iphouse.net/mike/2009/07/outbound-email-spam-is-teh-suck/comment-page-1/#comment-26</link>
		<dc:creator>mike</dc:creator>
		<pubDate>Tue, 27 Oct 2009 23:13:15 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.iphouse.net/mike/?p=223#comment-26</guid>
		<description>&lt;a href=&quot;#comment-25&quot; rel=&quot;nofollow&quot;&gt;@dannyclyde&lt;/a&gt; Hey there!

Implemented parts of policyd (cluebringer or cbpolicyd).  (hate when kiddies decide to name things)

Set it up for a sliding 1 hour window and set metrics, and allow customers to go over by contacting us and putting them into a different bucket.

Has worked well so far.  Since we only allow SASL authenticated relay - I set the authentication key to be their SASL username - what IP they come from doesn&#039;t matter, so even if an account is breached and abuse is coming from multiple IP addresses - it is caught.

Best of luck!

Mike</description>
		<content:encoded><![CDATA[<p><a href="#comment-25" rel="nofollow">@dannyclyde</a> Hey there!</p>
<p>Implemented parts of policyd (cluebringer or cbpolicyd).  (hate when kiddies decide to name things)</p>
<p>Set it up for a sliding 1 hour window and set metrics, and allow customers to go over by contacting us and putting them into a different bucket.</p>
<p>Has worked well so far.  Since we only allow SASL authenticated relay &#8211; I set the authentication key to be their SASL username &#8211; what IP they come from doesn&#8217;t matter, so even if an account is breached and abuse is coming from multiple IP addresses &#8211; it is caught.</p>
<p>Best of luck!</p>
<p>Mike</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dannyclyde</title>
		<link>http://blogs.iphouse.net/mike/2009/07/outbound-email-spam-is-teh-suck/comment-page-1/#comment-25</link>
		<dc:creator>dannyclyde</dc:creator>
		<pubDate>Tue, 27 Oct 2009 22:54:31 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.iphouse.net/mike/?p=223#comment-25</guid>
		<description>Hey Mike, 

We have a serious new Postfix system, and we had the same exact Nigerian nightmare as you write about here.

Yeah, it&#039;s teh suck all rights!! 

Nigerians were using stolen credit cards to sign up for accounts, and so far our newb-scribers have smartened up and aren&#039;t sending their id&#039;s/ps&#039;s to them anymore. So far this month anywaze. We stopped the online sign-upability, but we still want to impose limits for the next inevitable phishing incident.

&gt; On Wednesday, I implemented software that implements per user limits of number of 
&gt; authentications per hour.

So what change did you made? We&#039;re looking to do exactly the same thing. I&#039;m trying to find the specifics for my linux guy.

We&#039;re also looking at running this milter, that counts outbound failures:
http://www.snertsoft.com/sendmail/milter-error/ 

Thanks!

Danny
Cyber Mesa Telecom
www.cybermesa.com</description>
		<content:encoded><![CDATA[<p>Hey Mike, </p>
<p>We have a serious new Postfix system, and we had the same exact Nigerian nightmare as you write about here.</p>
<p>Yeah, it&#8217;s teh suck all rights!! </p>
<p>Nigerians were using stolen credit cards to sign up for accounts, and so far our newb-scribers have smartened up and aren&#8217;t sending their id&#8217;s/ps&#8217;s to them anymore. So far this month anywaze. We stopped the online sign-upability, but we still want to impose limits for the next inevitable phishing incident.</p>
<p>&gt; On Wednesday, I implemented software that implements per user limits of number of<br />
&gt; authentications per hour.</p>
<p>So what change did you made? We&#8217;re looking to do exactly the same thing. I&#8217;m trying to find the specifics for my linux guy.</p>
<p>We&#8217;re also looking at running this milter, that counts outbound failures:<br />
<a href="http://www.snertsoft.com/sendmail/milter-error/" rel="nofollow">http://www.snertsoft.com/sendmail/milter-error/</a> </p>
<p>Thanks!</p>
<p>Danny<br />
Cyber Mesa Telecom<br />
<a href="http://www.cybermesa.com" rel="nofollow">http://www.cybermesa.com</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using memcached
Page Caching using memcached
Database Caching using memcached
Object Caching 234/238 objects using memcached

Served from: blogs.iphouse.net @ 2012-02-07 07:37:03 -->
