<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="http://syndication.webwiz.co.uk/rss_namespace/">
 <channel>
  <title>Spam Filter ISP Forums : another h&#111;ney pot thought</title>
  <link>https://www.logsat.com/spamfilter/forums/</link>
  <description><![CDATA[This is an XML content feed of; Spam Filter ISP Forums : Spam Filter ISP Support : another h&#111;ney pot thought]]></description>
  <pubDate>Sat, 08 Aug 2026 09:03:05 +0000</pubDate>
  <lastBuildDate>Thu, 11 Aug 2005 11:47:05 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 11.04</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://www.logsat.com/spamfilter/forums/RSS_post_feed.asp?TID=5157</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Spam Filter ISP Forums]]></title>
   <url>https://www.logsat.com/spamfilter/forums/forum_images/web_wiz_forums.png</url>
   <link>https://www.logsat.com/spamfilter/forums/</link>
  </image>
  <item>
   <title><![CDATA[another h&#111;ney pot thought : How about adding a checkbox to...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6387&amp;title=another-honey-pot-thought#6387</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=99">Alan</a><br /><strong>Subject:</strong> 5157<br /><strong>Posted:</strong> 11 August 2005 at 11:47am<br /><br />How about adding a checkbox to add IP's to the honeypot block list whoexceed the "maximum concurrent connections from same IP"&nbsp;]]>
   </description>
   <pubDate>Thu, 11 Aug 2005 11:47:05 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6387&amp;title=another-honey-pot-thought#6387</guid>
  </item> 
  <item>
   <title><![CDATA[another h&#111;ney pot thought : ahh, that is exactly what i was...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6383&amp;title=another-honey-pot-thought#6383</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=118">Marco</a><br /><strong>Subject:</strong> 5157<br /><strong>Posted:</strong> 11 August 2005 at 3:47am<br /><br /><P>ahh, that is exactly what i was referring to, and i see how it happened.</P><P>The problem is that an 'unknown' sender is mailing us spam to legit mail adresses. adding those adresses to honeypot list is not an option.</P><P>Since the senders don't use honeypot adresses, and some of the incoming mails are relayed throuygh to our primary mailsystem, the possibility that the relay's ip gets trapped is high. This is what happened, and i agree, the honeypot is working fine, but the donotaddiptohoneypot setting needs to be applied to the content tagging system also.</P><P>So maybe the tag 'honeypot' is a bit out of place in the keyword filter, perhaps a tag called '::blacklistIP' (or something) would be better.</P><P>Regardless, a system that blacklists senders ip's on the basis of mail or subject content could proove invaluable. But caution has to be applied not to blacklist legit ip's.</P><P>Another wish that might proove useful if possible is extending the 'automatic blacklisting' when the sender's mail is matched in MAPS and/or&nbsp;surbl search.&nbsp; Also 'FROM' domain names /attachment filter perhaps.</P><P>Thank you for taking the effort in looking into this 'issue' i would gladly help test the new prerelease.</P><P>&nbsp;</P><P>Regards,</P><P>Marco</P><span style="font-size:10px"><br /><br />Edited by Marco</span>]]>
   </description>
   <pubDate>Thu, 11 Aug 2005 03:47:13 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6383&amp;title=another-honey-pot-thought#6383</guid>
  </item> 
  <item>
   <title><![CDATA[another h&#111;ney pot thought : Marco,  I&amp;#039;m not sure if...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6382&amp;title=another-honey-pot-thought#6382</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 5157<br /><strong>Posted:</strong> 10 August 2005 at 10:14pm<br /><br />Marco,<br><br>I'm not sure if you refer to your comment below or not:<br><br>==============================<br>I think the order of filters needs to be looked at again, so that DoNotAddIPToHoneypot has preference again.<br>==============================<br><br>If it's not this comment, but another "hidden bugreport", then it'shidden really good since I have no idea of where it is... Can yourepost it?<br><br>If instead it was the above comment, it looked like a "wish" not a bugreport. Looking over the behavior again, we noticed that theDoNotAddIPToHoneypot optionis doing exactly what it was asked anddesigned to do. That is, if an email comes in from an <span style="font-style: italic;">email address </span>that is in the honeypot email list, the IP won't be added if it's listed in the DoNotAddIPToHoneypot list. <br><br>When we started adding extra tags to add sender's IP to the honeypotblacklist if they triggered other filters, that process ignored theDoNotAddIPToHoneypot. It's technically not a bug... but you're correct,it would be more appropriate if that "whitelist" would be expanded toall other filters as well.<br><br>We're pre-testing a build with this ability internally right now. We'llmake it available in a few days, but if you wish to test it please letus know and we'll make it available to you.<br>]]>
   </description>
   <pubDate>Wed, 10 Aug 2005 22:14:58 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6382&amp;title=another-honey-pot-thought#6382</guid>
  </item> 
  <item>
   <title><![CDATA[another h&#111;ney pot thought : Maybe you missed the hidden bugreport...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6374&amp;title=another-honey-pot-thought#6374</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=118">Marco</a><br /><strong>Subject:</strong> 5157<br /><strong>Posted:</strong> 09 August 2005 at 3:16am<br /><br /><P>Maybe you missed the hidden bugreport i mentioned in my earlier post Roberto, just making sure.</P><P>The DoNotAddIPToHoneypot ini entry is beeing ignored in build 476</P><P>Regards,</P><P>&nbsp;</P><P>Marco</P>]]>
   </description>
   <pubDate>Tue, 09 Aug 2005 03:16:25 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6374&amp;title=another-honey-pot-thought#6374</guid>
  </item> 
  <item>
   <title><![CDATA[another h&#111;ney pot thought : Alan,  We honestly don&amp;#039;t...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6362&amp;title=another-honey-pot-thought#6362</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 5157<br /><strong>Posted:</strong> 07 August 2005 at 6:57pm<br /><br />Alan,<br><br>We honestly don't see expirations on filters to be available any time soon. <br><br>What we do have next on the list however is a "timed cache" on sourceIPs. If an IP has sent more that "n" number of spams in the last "x"number of minutes, it will be immediately disconnected even before itsends any data for "y" number of minutes. This will save a considerableamount of bandwidth and will prevent filling user's quarantine withmassive amounts of spam to sort thru. We're trying to make theseoptions available for each type of filter, so that for example thetimer is active on the "virus" filter but not on the "reverse DNS"filter.<br>]]>
   </description>
   <pubDate>Sun, 07 Aug 2005 18:57:03 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6362&amp;title=another-honey-pot-thought#6362</guid>
  </item> 
  <item>
   <title><![CDATA[another h&#111;ney pot thought : Thank you Roberto for getting...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6356&amp;title=another-honey-pot-thought#6356</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=99">Alan</a><br /><strong>Subject:</strong> 5157<br /><strong>Posted:</strong> 05 August 2005 at 5:06pm<br /><br />Thank you Roberto for getting such a jump on that one.&nbsp; It reallyhas made a noticable difference already in my testing.&nbsp; And I donot see any performance hit either.&nbsp; I am still very impressed athow quickly you have been able to encorporate new ideas and userrequests over the years of using SF.<br><br>Seems like some of the old requests from years ago are starting to getincluded in the product now.&nbsp; So how about some way to set a timelimit on filters?&nbsp; Maybe something like "::NULL/08102005" to havea filter that will no longer be effective as of a certain expirationdate (08/10/2005 in this case).&nbsp; Of course it would be either upto the admin to clean up or you can have the app auto-remove expiredfilters.&nbsp; This would be good for outbreaks or spambot attackswhere certain is suddenly a big problem but will probably not be in thefuture.<br><br>And another thought, a way to also scan within attached text files suchas spoofed bounces resulting from joe-job instances.&nbsp; <br><br>Oh and finally, how about that darned mailing list for registered usersso we can be notified immediately of new official and betaversions?&nbsp; That seems like a no-brainer and another reason forpeople to pony up for a fine product.<br>]]>
   </description>
   <pubDate>Fri, 05 Aug 2005 17:06:34 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6356&amp;title=another-honey-pot-thought#6356</guid>
  </item> 
  <item>
   <title><![CDATA[another h&#111;ney pot thought : ok, one of them badasses sent...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6350&amp;title=another-honey-pot-thought#6350</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=118">Marco</a><br /><strong>Subject:</strong> 5157<br /><strong>Posted:</strong> 05 August 2005 at 8:21am<br /><br /><P>ok, one of them badasses sent us one... and it seems to work.. but you guessed it: the ISP's relay server got blocked :)))</P><P>I think the order of filters needs to be looked at again, so that DoNotAddIPToHoneypot has preference again.</P><P>Other than that it works great! This is gonna give the spammers some serious headaches. How to try and sell something if the text needed to sell it will cause you an ipblock? muhahaha (sorry, was beeing myself for a sec there) :)</P><P>regards,</P><P>Marco</P><span style="font-size:10px"><br /><br />Edited by Marco</span>]]>
   </description>
   <pubDate>Fri, 05 Aug 2005 08:21:04 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6350&amp;title=another-honey-pot-thought#6350</guid>
  </item> 
  <item>
   <title><![CDATA[another h&#111;ney pot thought : Fantastic! great work roberto....]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6346&amp;title=another-honey-pot-thought#6346</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=118">Marco</a><br /><strong>Subject:</strong> 5157<br /><strong>Posted:</strong> 05 August 2005 at 3:05am<br /><br /><P>Fantastic! great work roberto. </P><P>&nbsp;</P><P>just to make sure, the following lines are correct?</P><P>subject:challenged on live tv::honeypot<BR>subject:software,at,incredibly,low,price::honeypot<BR></P><span style="font-size:10px"><br /><br />Edited by Marco</span>]]>
   </description>
   <pubDate>Fri, 05 Aug 2005 03:05:44 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6346&amp;title=another-honey-pot-thought#6346</guid>
  </item> 
  <item>
   <title><![CDATA[another h&#111;ney pot thought : Marco, Alan, keizersozay, everyone,  We...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6342&amp;title=another-honey-pot-thought#6342</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 5157<br /><strong>Posted:</strong> 04 August 2005 at 11:49pm<br /><br />Marco, Alan, keizersozay, everyone,<br><br>We now have a pre-release build that does include support for extratags in the keyword filter as well. This was done with practically noperformance loss. The build is still being tested, but is available inthe registered user area as build 2.6.3.476.<br><br>The syntax for the extra tag had to be slightly different. In this listyou MUST use a double colon rather than a single one to separate thetag from the keyword entries. The updated help file for that sectionisas follows:<br><br><font face="verdana,arial,helvetica"><b><a name="Keywords "><font size="2">Keywords        Filter</font></a><font size="2"> - </font></b><font size="2">You can        check email content and subject header for specific keyword and/or        phrases. If found, the email is rejected. You can also use <a href="#Bayesian%20Statistical%20Filtering" target="_blank">Regular        Expressions</a> (RegEx).&nbsp;If the keyword file does not exist it will        be created. The file is reloaded every minute. The contents of the file        will be loaded in the memo box, allowing you to make changes to the        file. This list supports the ::NULL option to send emails in a black hole. If an entry is in the form <em><strong>keyword::NULL</strong></em> it will cause all		emails to be accepted and then sent to NULL right away. Such		emails will not cause NDRs, they will not be quarantined, they will not be seen by the users.</font></font><font face="verdana,arial,helvetica" size="2">If an entry	is in the form <em><strong>keyword::NoNDR</strong></em> such	emails will not cause NDRs as in the DoNotSendNDROnQuarantine parameter in the ini file. This list supports the <strong>::Honeypot</strong> option, which will cause the sender's IP address to be automatically blacklisted in the future.</font><font face="verdana,arial,helvetica" size="2">&nbsp;Please note that unlike in other cases, with the keyword list you must enter the ":" symbol <i>twice</i> to specify the extra tag.<br>&nbsp;</font><br>]]>
   </description>
   <pubDate>Thu, 04 Aug 2005 23:49:25 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6342&amp;title=another-honey-pot-thought#6342</guid>
  </item> 
  <item>
   <title><![CDATA[another h&#111;ney pot thought : I was going to suggest the exact...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6338&amp;title=another-honey-pot-thought#6338</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=118">Marco</a><br /><strong>Subject:</strong> 5157<br /><strong>Posted:</strong> 04 August 2005 at 10:47am<br /><br /><P>I was going to suggest the exact same (topic), from then on anyone with 'case of fine wine' 'improved cialis without prescription' (to name some) in the subject would get blocked into oblivian.</P><P>&nbsp;</P><P>This feature would only need to be active for a limited time, and would catch quite a few of the badasses that got hold of our domain name and are swamping it with spam.</P><P>Any users that forward such spam and dont change at least the titles are deserving of a block :-&gt;</P><P>But i would also like to see a limited timeblock, say - a day- with notification to the sender, so that they are warned not to do it again.</P><P>&nbsp;</P><P>Just my 2 cents</P><P>&nbsp;</P>]]>
   </description>
   <pubDate>Thu, 04 Aug 2005 10:47:37 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5157&amp;PID=6338&amp;title=another-honey-pot-thought#6338</guid>
  </item> 
 </channel>
</rss>