Honeypot Problem |
Post Reply |
Author | |
kspare
Senior Member Joined: 26 January 2005 Location: Canada Status: Offline Points: 334 |
Post Options
Thanks(0)
Posted: 24 June 2005 at 1:03am |
Is anything going to be done about the problem Marco and I were having with the honeypot and trusted ip's??? I have narrowed it down to that if the honeypot was applied after tagged subject lines it would resolve my problem. or just being able to add in trusted ips in the honey pot..... Roberto? |
|
LogSat
Admin Group Joined: 25 January 2005 Location: United States Status: Offline Points: 4104 |
Post Options
Thanks(0)
|
Kevin,
We were originally staying with the response given at http://logsat.com/spamfilter/forums/forum_posts.asp?TID=5217 #6068, however we've revisited that... We prepared a new beta that may solve your issues. Build 461 has the following release notes: // New to VersionNumber = '2.5.2.461'; {TODO -cNew : Added RealtimeDiskLogging option in SpamFilter.ini file to have log being flushed to disk with every entry} {TODO -cNew : Added DoNotAddIPToHoneypot option to SpamFilter.ini file to prevent certain trusted IPs from being blacklisted by the honeypot filter} {TODO -cNew : Changed the logging on screen performance to increase reliability and have a smoother scroll} We have not released it yet in the pre-release area of the website as it's an on-going work to add a per-domain filtering options (you'll see a non-working preview on the settings tab. It is however otherwise fully functional and should be very stable. If you wish to try it to see if it will solve your problem, I'm sending you and Marco a download link by private message in this forum. |
|
Marco
Senior Member Joined: 07 June 2005 Location: Netherlands Status: Offline Points: 137 |
Post Options
Thanks(0)
|
thanks a lot Roberto, having a working honeypot for those that are behind a relay server or use some other sort of mail forwarding server can be sure the relay won't get blacklisted when that is implemented. Regards, Marco |
|
Anyone who is capable of getting himself made president, should on no account be allowed to do the job. D.Adams
|
|
kspare
Senior Member Joined: 26 January 2005 Location: Canada Status: Offline Points: 334 |
Post Options
Thanks(0)
|
Works great for me too! Thanks Roberto!!
|
|
WebGuyz
Senior Member Joined: 09 May 2005 Location: United States Status: Offline Points: 348 |
Post Options
Thanks(0)
|
One big problem I see with Honeypots is this. Now that most ISP's are blocking port 25, spammers are starting to use the Zombie PC's default outgoing ISP to send the spam. Before too long you end up blocking comcast.net, rr.com, and all major ISP's. Without a way to bypass this issue by a DO NOT BLOCK list like the one that being talked about, the honeypot will die a slow death I believe. I tried doing something like this a while back and created my own RBL of IP's that had sent me spam and that my then current spam filter detected. I ended up having to scrap it because it was adding so many big ISP's ip numbers that my customers revolted and I had to remove it.
|
|
http://www.webguyz.net
|
|
kspare
Senior Member Joined: 26 January 2005 Location: Canada Status: Offline Points: 334 |
Post Options
Thanks(0)
|
Most ISP's are getting smart and are only allowing authenticated users or only ip's from their own network to use their smtp server. If anything it will force lazy isp's to smarten up....The honeypot works great! |
|
Marco
Senior Member Joined: 07 June 2005 Location: Netherlands Status: Offline Points: 137 |
Post Options
Thanks(0)
|
Roberto, Multiple trusted ip's are accepted too? DoNotddIPToHoneypot=xxx.xxx.xxx.xxx,xxx.xxx.xxx.xxx works? Regards, Marco |
|
Anyone who is capable of getting himself made president, should on no account be allowed to do the job. D.Adams
|
|
LogSat
Admin Group Joined: 25 January 2005 Location: United States Status: Offline Points: 4104 |
Post Options
Thanks(0)
|
Once we add new features, we try to make them as useful as possible! Yes, multiple IPs are allowed, spearate them with commas or semicolons (without spaces) as you correctly guessed.
|
|
Simone
Groupie Joined: 06 July 2005 Status: Offline Points: 42 |
Post Options
Thanks(0)
|
The honeypot is a great feature, but i think that it should be not a definitely ip ban. The ip list should be clean every X days, or better, the ip older than X days should be deleted from honeypot ip ban list. This feature could help the virus infected PC that has been cleaned to come up and working. Don't you think that a days limited ban wuold be better? Simone |
|
WebGuyz
Senior Member Joined: 09 May 2005 Location: United States Status: Offline Points: 348 |
Post Options
Thanks(0)
|
Just as I knew would happen. Got an email from earthlink asking why I had blacklisted one of their smtp servers. Here is the actual letter: Hello, Bottom line, this is bound to happen will with every major ISP. I now remember why I stopped my earlier home brew attempts at this (ip blocking on spam hits) and alas will have to stop using the honeypot as well. I think it will eventually hit everyone who is an ISP or does a lot of mail that honeypot is impossible to do without pissing off a lot of people. Anyone else ran into this yet?
|
|
http://www.webguyz.net
|
|
lead
Newbie Joined: 08 March 2005 Status: Offline Points: 18 |
Post Options
Thanks(0)
|
If I put in a scheduled task every 30mins to delete the honeypot IP
black list, would this have any adverse effect on spamfilter?
I guess I am asking if spamfilter would recreate the blacklist file? If there is a spam zombie sending through the ISPs SMTP this should cover it for a short period. Another question, I take it the rejection message is the Local IP blacklist message? |
|
LogSat
Admin Group Joined: 25 January 2005 Location: United States Status: Offline Points: 4104 |
Post Options
Thanks(0)
|
lead,
SpamFilter will import any black/white list files that are changed by an external application. The files are checked every 60 seconds to see if they are modified. The same applies to the honeypot IP list, but there is a catch. If an email arrives from an email address in your honeypot email list, that IP will be immediately added to the honeypot IP blacklist file. This means that if you empty the file (you should not delete the whole file, just clear its contents...) and an IP is added by SpamFilter *before* the 60 seconds interval, SpamFilter will re-save the entire IP list to file before it is reloaded. If an IP is added every few minutes, chances are the file will clear successfully. But if IPs are added every few seconds, this will be less likely to succeed every time. |
|
sgeorge
Senior Member Joined: 23 August 2005 Status: Offline Points: 178 |
Post Options
Thanks(0)
|
Webguyz, I ran into the same type of problem last week with my SpamFilter honeypot. It has been working great, reducing a large amount of spam. But just recently, my honeypot blocked an smtp server that sends my mail server a substantial number of valid emails. It just happened to be that someone who harvested one of the honeypot emails that I hid on my web site had sent my server mail, using the a smtp server that I often receive good email from. This seems like an impossible thing to ask, but how does one work around a situation where they receive some good email from a smtp server that has been blocked by the honeypot? I don’t believe that I have any solid white list criteria that I could add to safeguard the good email that comes in from some of these partially-bad smtp server. My only solution to this point has been to disable my honeypot. Below is a snippet from my logs, in which one such smtp server was blocked - adamant.xo.com. After this, a number of good emails were getting blocked.
11/13/05 01:02:35:960 -- (5012) Connection from: 207.155.248.114 - Originating country : United States 11/13/05 01:02:36:304 -- (5012) Resolving 207.155.248.114 - adamant.xo.com 11/13/05 01:02:36:304 -- (5012) - EMail To is in honeypot emails - 11/13/05 01:02:36:335 -- (5012) - Added 207.155.248.114 to honeypot blacklist 11/13/05 01:02:36:335 -- (5012) 207.155.248.114 - Mail from: TaraFarber@benker-vermietung.com To: honeypie@***********.*** will be rejected 11/13/05 01:02:37:117 -- (5012) EMail from TaraFarber@benker-vermietung.com to hypot1@msandyou.org was received and quarantined. Size: 20 KB, 20480 bytes 11/13/05 01:02:37:179 -- (7180) Time to add Msg to Bayes corpus:0 11/13/05 01:02:37:195 -- (5012) Disconnect I appreciate any suggestions, thanks. Edited by sgeorge |
|
WebGuyz
Senior Member Joined: 09 May 2005 Location: United States Status: Offline Points: 348 |
Post Options
Thanks(0)
|
I had to stop using honeypot because it was blocking emails from AOL, gmail, and others causing a false positive headache. The biggest thing we do to cut down on false positives is a script that parses our outbound mail server log (using MS Logparser) every 10 minutes get all the FROM:/TO: pairs, and if they are a valid user and the entry is not a dupe, add the FROM|TO pair into AutoWhitelistDelivery.txt file. That file is currently at 2.3 meg but doesn't seem to slow down SF (so far ;-). Get much fewer calls about mail getting 'stuck' |
|
http://www.webguyz.net
|
|
Web123
Guest Group |
Post Options
Thanks(0)
|
Every time a message is released from quarantien(that has been blocked as spam) it is checked against the blacklist, if found it removes the blacklisted IP! This way if HoneyPot has blocked a "valid" senderIP, it will be removed by the first release from quarantine. (have blacklistedIPs in a DB that I sync with SF every 15min) |
|
Post Reply | |
Tweet
|
Forum Jump | Forum Permissions You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |
This page was generated in 0.305 seconds.