Hi, On the Spanish mail list, I added a header check. All mail which have user-agent=HyperKitty on https://lists.opensuse.org/ are now moderated. Reason is that the list has got recently (September) a dozen or more English language spam, all coming via that interface, from "non members" apparently. Somehow spammers found a hole and they are exploiting it. Interesting thing is, the first hit provoked a reply from the spammer, sent to users-es-owner@lists.opensuse.org. It is possible that they interpret the rejection post as a "reply to our spam" that triggers a "reply to customer" automatically. If that is so, I may eventually have to silently reject or delete all email from hiperkitty. It would then be preferable to simply close the page, in order to not confuse possible good faith posters. Curio: https://lists.opensuse.org/manage/lists/users-es.lists.opensuse.org/members/... has 9491 entries including this last attempt. -- Cheers / Saludos, Carlos E. R. (from openSUSE 15.5 (Laicolasse))
On Do, Sep 14 2023 at 07:58:53 -0400, Carlos E. R. <carlos.e.r@opensuse.org> wrote:
Hi,
On the Spanish mail list, I added a header check. All mail which have user-agent=HyperKitty on https://lists.opensuse.org/ are now moderated.
Reason is that the list has got recently (September) a dozen or more English language spam, all coming via that interface, from "non members" apparently. Somehow spammers found a hole and they are exploiting it.
Would you be able to compile a list of addresses of the spammers? I would like to see if maybe removing some login provider would let us avoid this situation. The last attempt I can see came from google login and a gmail address, which are well known for being simple for spammers to set up. That being said, it's not like SUSE Community Accounts are any harder to set up anyway.
Interesting thing is, the first hit provoked a reply from the spammer, sent to users-es-owner@lists.opensuse.org. It is possible that they interpret the rejection post as a "reply to our spam" that triggers a "reply to customer" automatically.
If that is so, I may eventually have to silently reject or delete all email from hiperkitty. It would then be preferable to simply close the page, in order to not confuse possible good faith posters.
Feel free to suggest that as a feature to hyperkitty upstream, we don't really have a way to do that right now. LCP [Jake] https://lcp.world/
On 2023-09-14 08:09, Jacob Michalskie wrote:
On Do, Sep 14 2023 at 07:58:53 -0400, Carlos E. R. <carlos.e.r@opensuse.org> wrote:
Hi,
On the Spanish mail list, I added a header check. All mail which have user-agent=HyperKitty on https://lists.opensuse.org/ are now moderated.
Reason is that the list has got recently (September) a dozen or more English language spam, all coming via that interface, from "non members" apparently. Somehow spammers found a hole and they are exploiting it.
Would you be able to compile a list of addresses of the spammers? I would like to see if maybe removing some login provider would let us avoid this situation. The last attempt I can see came from google login and a gmail address, which are well known for being simple for spammers to set up. That being said, it's not like SUSE Community Accounts are any harder to set up anyway.
I will look at it later, yes. Maybe this evening. (huh, "members" above I understand means list subscribers) I suspect that such a list could be grepped from the mail archive looking for the user-agent string, though. I will instead search my spam folder.
Interesting thing is, the first hit provoked a reply from the spammer, sent to users-es-owner@lists.opensuse.org. It is possible that they interpret the rejection post as a "reply to our spam" that triggers a "reply to customer" automatically.
If that is so, I may eventually have to silently reject or delete all email from hiperkitty. It would then be preferable to simply close the page, in order to not confuse possible good faith posters.
Feel free to suggest that as a feature to hyperkitty upstream, we don't really have a way to do that right now.
Ah, ok. -- Cheers / Saludos, Carlos E. R. (from openSUSE 15.5 (Laicolasse))
On 2023-09-14 09:04, Carlos E. R. wrote:
On 2023-09-14 08:09, Jacob Michalskie wrote:
On Do, Sep 14 2023 at 07:58:53 -0400, Carlos E. R. <carlos.e.r@opensuse.org> wrote:
Hi,
On the Spanish mail list, I added a header check. All mail which have user-agent=HyperKitty on https://lists.opensuse.org/ are now moderated.
Reason is that the list has got recently (September) a dozen or more English language spam, all coming via that interface, from "non members" apparently. Somehow spammers found a hole and they are exploiting it.
Would you be able to compile a list of addresses of the spammers? I would like to see if maybe removing some login provider would let us avoid this situation. The last attempt I can see came from google login and a gmail address, which are well known for being simple for spammers to set up. That being said, it's not like SUSE Community Accounts are any harder to set up anyway.
I forgot about login providers! So that's how they can gain access.
I will look at it later, yes. Maybe this evening.
Currently held messages: Currently held Messages: Sender: drewroy0031@gmail.com Subject: mrhealthfitness Sender: adomosalvis@gmail.com Subject: diggblog Sender: adomosalvis@gmail.com Subject: diggblog Day before: esha noor <eshanoorjasi@gmail.com> Previous (on my spam folder): These come in pairs, seconds appart, so maybe not a human at the web interface: Subject: webinfoblog From: "Alice Roy" <aliceroy0031@gmail.com> To: users-es@lists.opensuse.org Date: Wed, 13 Sep 2023 09:45:01 -0000 Message-ID: <169459830154.17179.8234291790551071992@mailman3.infra.opensuse.org> Subject: webinfoblog From: "Alice Roy" <aliceroy0031@gmail.com> To: users-es@lists.opensuse.org Date: Wed, 13 Sep 2023 09:45:24 -0000 Message-ID: <169459832452.17179.11884282474120388540@mailman3.infra.opensuse.org> User-Agent: HyperKitty on https://lists.opensuse.org/ Message-ID-Hash: 3SNWGGRMRDFWG4V2QDBG6VGR6NMZ627L X-Message-ID-Hash: 3SNWGGRMRDFWG4V2QDBG6VGR6NMZ627L ... X-Mailman-Version: 3.3.8 Precedence: list List-Id: Spanish speaking openSUSE users <users-es.lists.opensuse.org> Archived-At: <https://lists.opensuse.org/archives/list/users-es@lists.opensuse.org/message/4I7MPWJ7IEERJDXIQL3YS4WHZUDPH6WU/> .. X-TnetIn-SenderInfo: IP: 195.135.221.145 | Country: DE | SPF: pass X-VADETIN-SPAMSTATE: clean X-VADETIN-SPAMSCORE: 50 X-VADETIN-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgedviedrudeikedgudelucetufdoteggodetrfdotffvucfrrhhofhhilhgvmecuteevgffpufdquedvveenuceurghilhhouhhtmecufedttdenucgovfgvgihtqfhnlhihqddqteefjeefqddtgeculdehtddmnecujfgurheptggggffuhffvfffkfghpjeegfedvuddtjfesthejtddttderjeenucfhrhhomhepfdetlhhitggvucftohihfdcuoegrlhhitggvrhhohidttdefudesghhmrghilhdrtghomheqnecuggftrfgrthhtvghrnheptdettdduteduieekfeetueffteehleeuteejgfetleehleekueeuieduudeftddvnecuffhomhgrihhnpeifvggsihhnfhhosghlohhgrdgtohhmnecukfhppeduleehrddufeehrddvvddurddugeehnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehinhgvthepudelhedrudefhedrvddvuddrudeghedphhgvlhhopegrnhhnrgdrohhpvghnshhushgvrdhorhhgpdhmrghilhhfrhhomhepuhhsvghrshdqvghsqdgsohhunhgtvghssehlihhsthhsrdhophgvnhhsuhhsvgdrohhrghdpnhgspghrtghpthhtohepvddprhgtphhtthhopegvrdhsrghluggrnhgrsehtvghlvghfohhnihgtrgdrnhgvthdprhgtphhtthhopehrohgsihhnrdhlihhsthgrshesthgvlhgvfhhonhhitggrrdhnvght Subject: How To Take Business To Next Level With Your Android TV App From: "Patrick Pierre" <patrickpierree2023@gmail.com> To: users-es@lists.opensuse.org Date: Wed, 13 Sep 2023 08:06:45 -0000 Message-ID: <169459240576.9035.1754004484928630963@mailman3.infra.opensuse.org> User-Agent: HyperKitty on https://lists.opensuse.org/ Message-ID-Hash: EDPVK3EVCK46R3YOUF5EGACQKWCVTAJK Subject: IoT Product Development From: "billy roberts" <billyroberts1@protonmail.com> To: users-es@lists.opensuse.org Date: Tue, 12 Sep 2023 11:19:28 -0000 Message-ID: <169451756812.4696.16957248448138260458@mailman3.infra.opensuse.org> User-Agent: HyperKitty on https://lists.opensuse.org/ Message-ID-Hash: A6VBUAIOBAITT7NDBGSMH2YM7KFV2RCF X-Message-ID-Hash: A6VBUAIOBAITT7NDBGSMH2YM7KFV2RCF X-MailFrom: billyroberts1@protonmail.com Subject: bigtechweb From: "Steven Roy" <stevenroy0014@gmail.com> To: users-es@lists.opensuse.org Date: Tue, 12 Sep 2023 09:17:11 -0000 Message-ID: <169451023184.24044.5323562309596860087@mailman3.infra.opensuse.org> User-Agent: HyperKitty on https://lists.opensuse.org/ Message-ID-Hash: VH7IRCTP6OYP5X432QX65GYDQK3YNT57 Subject: bigtechweb From: "Steven Roy" <stevenroy0014@gmail.com> To: users-es@lists.opensuse.org Date: Tue, 12 Sep 2023 09:16:40 -0000 Message-ID: <169451020040.22533.1694205484245828738@mailman3.infra.opensuse.org> User-Agent: HyperKitty on https://lists.opensuse.org/ Message-ID-Hash: 7X2MREFWSUX2WKIKYHTUEB35TZ5GNPHZ Subject: gobusinesstips From: "Adomos Alvis" <adomosalvis@gmail.com> To: users-es@lists.opensuse.org Date: Tue, 12 Sep 2023 07:41:36 -0000 Message-ID: <169450449615.13890.11465070597350415577@mailman3.infra.opensuse.org> User-Agent: HyperKitty on https://lists.opensuse.org/ Message-ID-Hash: EI4M2UXGWQD4OV3A4AHJNIVHUUHCK2XG X-Message-ID-Hash: EI4M2UXGWQD4OV3A4AHJNIVHUUHCK2XG X-MailFrom: adomosalvis@gmail.com From: "Kiera roy" <kieraroy0031@gmail.com> To: users-es@lists.opensuse.org Date: Mon, 11 Sep 2023 10:53:14 -0000 Message-ID: <169442959434.11379.14649624320458435402@mailman3.infra.opensuse.org> User-Agent: HyperKitty on https://lists.opensuse.org/ Message-ID-Hash: FQ7YUNM65XFNI7QOSI5DB5I4URFPYLW6 X-Message-ID-Hash: FQ7YUNM65XFNI7QOSI5DB5I4URFPYLW6 X-MailFrom: kieraroy0031@gmail.com Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Subject: techgadgetsblog From: "Kiera roy" <kieraroy0031@gmail.com> To: users-es@lists.opensuse.org Date: Mon, 11 Sep 2023 10:52:53 -0000 Message-ID: <169442957320.9976.11252842357939421899@mailman3.infra.opensuse.org> User-Agent: HyperKitty on https://lists.opensuse.org/ Message-ID-Hash: E7J3EW3WPK7SNNUZEV32UZX2SYCFEMQN X-Message-ID-Hash: E7J3EW3WPK7SNNUZEV32UZX2SYCFEMQN X-MailFrom: kieraroy0031@gmail.com Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Subject: emarketerblog From: "Monica Roy" <monicaroy0031@gmail.com> To: users-es@lists.opensuse.org Date: Fri, 08 Sep 2023 18:34:27 -0000 Message-ID: <169419806750.4157.14701785648656923632@mailman3.infra.opensuse.org> User-Agent: HyperKitty on https://lists.opensuse.org/ Message-ID-Hash: LA4AFT77TOZBMBHLII5EIPCU24KI4PYB X-Message-ID-Hash: LA4AFT77TOZBMBHLII5EIPCU24KI4PYB X-MailFrom: monicaroy0031@gmail.com Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Subject: emarketerblog From: "Monica Roy" <monicaroy0031@gmail.com> To: users-es@lists.opensuse.org Date: Fri, 08 Sep 2023 18:34:03 -0000 Message-ID: <169419804352.3738.14449516641909173412@mailman3.infra.opensuse.org> User-Agent: HyperKitty on https://lists.opensuse.org/ Message-ID-Hash: 3U24R6GUMR3UFJ7JEL5DJ7Y2OIJIKYLZ X-Message-ID-Hash: 3U24R6GUMR3UFJ7JEL5DJ7Y2OIJIKYLZ X-MailFrom: monicaroy0031@gmail.com Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Subject: technologyic From: "Blake Roy" <blakeroy0031@gmail.com> To: users-es@lists.opensuse.org Date: Thu, 07 Sep 2023 10:11:41 -0000 Message-ID: <169408150158.24929.15005688544672406987@mailman3.infra.opensuse.org> User-Agent: HyperKitty on https://lists.opensuse.org/ Message-ID-Hash: RCHQFUGFS4W47XDGF3JUIIYCMB3QOPNW X-Message-ID-Hash: RCHQFUGFS4W47XDGF3JUIIYCMB3QOPNW Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Subject: foxconnblog From: "max roy" <maxroy0031@gmail.com> To: users-es@lists.opensuse.org Date: Wed, 06 Sep 2023 10:38:51 -0000 Message-ID: <169399673150.2833.12422614847268842002@mailman3.infra.opensuse.org> User-Agent: HyperKitty on https://lists.opensuse.org/ Message-ID-Hash: 7EHFS4ZVIDLCISLLYN6TMHFIAEGFVY4P X-Message-ID-Hash: 7EHFS4ZVIDLCISLLYN6TMHFIAEGFVY4P X-MailFrom: maxroy0031@gmail.com Previous attempts are not in my spam folder, and they happened months before. Searching on my IMAP Inbox: Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Subject: gobusinesstips From: "Adomos Alvis" <adomosalvis@gmail.com> To: users-es@lists.opensuse.org Date: Thu, 10 Aug 2023 10:09:46 -0000 Message-ID: <169166218667.24054.15881678497040547939@mailman3.infra.opensuse.org> User-Agent: HyperKitty on https://lists.opensuse.org/ Message-ID-Hash: 4PTLZ4PNPITGMONB2W3R52ULPNNOJMYC X-Message-ID-Hash: 4PTLZ4PNPITGMONB2W3R52ULPNNOJMYC X-MailFrom: adomosalvis@gmail.com Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Subject: JetBlue Last Minute Deals From: "Adam Stack" <adamstack01@gmail.com> To: users-es@lists.opensuse.org Date: Tue, 13 Jun 2023 06:42:08 -0000 Message-ID: <168663852873.8769.7604992388513792175@mailman3.infra.opensuse.org> User-Agent: HyperKitty on https://lists.opensuse.org/ Message-ID-Hash: VZRPVKNYZNV3H6V3KEZSYXU6YBGVXKSG X-Message-ID-Hash: VZRPVKNYZNV3H6V3KEZSYXU6YBGVXKSG X-MailFrom: adamstack01@gmail.com Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Subject: What is QuickBooks Error Code 6069? From: "amelia smith" <smithameliasmith20@gmail.com> To: users-es@lists.opensuse.org Date: Thu, 16 Mar 2023 06:27:04 -0000 Message-ID: <167894802427.16872.5836132109597530018@mailman3.infra.opensuse.org> User-Agent: HyperKitty on https://lists.opensuse.org/ Message-ID-Hash: XWCDT3IWN5WRFNYVVOSVM7M3WWSAS45P X-Message-ID-Hash: XWCDT3IWN5WRFNYVVOSVM7M3WWSAS45P X-MailFrom: smithameliasmith20@gmail.com Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Subject: What is QuickBooks Error Code 6069? From: "amelia smith" <smithameliasmith20@gmail.com> To: users-es@lists.opensuse.org Date: Thu, 16 Mar 2023 06:25:50 -0000 Message-ID: <167894795006.19733.10975436522859416190@mailman3.infra.opensuse.org> User-Agent: HyperKitty on https://lists.opensuse.org/ Message-ID-Hash: 42MFV4QX6JX342LUQ5CKY4DD6W5MEG2V X-Message-ID-Hash: 42MFV4QX6JX342LUQ5CKY4DD6W5MEG2V X-MailFrom: smithameliasmith20@gmail.com Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Subject: How to Fix QuickBooks Error Code 9584? From: "Levin Smith" <levinsmith0444@gmail.com> To: users-es@lists.opensuse.org Date: Mon, 13 Mar 2023 07:44:05 -0000 Message-ID: <167869344596.26011.14108178361467054955@mailman3.infra.opensuse.org> User-Agent: HyperKitty on https://lists.opensuse.org/ Message-ID-Hash: EPOE5XFEL5TN526NBZGUO7IONQHLUHET X-Message-ID-Hash: EPOE5XFEL5TN526NBZGUO7IONQHLUHET X-MailFrom: levinsmith0444@gmail.com So, yes, mostly from gmail, but there is one from protonmail. There was a bunch of spam about QuickBooks, so there is a rule in place for that subject since then. Is the Spanish mail list the only one affected? The spam itself is in English. -- Cheers / Saludos, Carlos E. R. (from openSUSE 15.5 (Laicolasse))
On Fr, Sep 15 2023 at 08:25:51 -0400, Carlos E. R. <carlos.e.r@opensuse.org> wrote:
So, yes, mostly from gmail, but there is one from protonmail.
There was a bunch of spam about QuickBooks, so there is a rule in place for that subject since then.
Is the Spanish mail list the only one affected? The spam itself is in English.
Yeah, it seems like the spanish ml is the most affected one. Thanks for compiling that, I will have a look at this later LCP [Jake] https://lcp.world/
On 2023-09-14 15:04, Carlos E. R. wrote:
On 2023-09-14 08:09, Jacob Michalskie wrote:
On Do, Sep 14 2023 at 07:58:53 -0400, Carlos E. R. <carlos.e.r@opensuse.org> wrote:
Hi,
On the Spanish mail list, I added a header check. All mail which have user-agent=HyperKitty on https://lists.opensuse.org/ are now moderated.
Reason is that the list has got recently (September) a dozen or more English language spam, all coming via that interface, from "non members" apparently. Somehow spammers found a hole and they are exploiting it.
Just to mention that we get one or two hits daily. Someone must have a script for this hole. Not a problem, I just have to click "discard", just makes life a bit more entertaining ;-) Still curious why only the Spanish list is hit. -- Cheers / Saludos, Carlos E. R. (from openSUSE 15.5 (Laicolasse))
On Mi, Sep 27 2023 at 12:36:02 +02:00:00, Carlos E. R. <robin.listas@telefonica.net> wrote:
Just to mention that we get one or two hits daily. Someone must have a script for this hole.
Not a problem, I just have to click "discard", just makes life a bit more entertaining ;-)
Still curious why only the Spanish list is hit.
I temporarily removed the ability to log in with google, let's see if we get any more of the spam and reports of genuine users trying to log in. LCP [Jake] https://lcp.world/
On 2023-09-27 12:39, Jacob Michalskie wrote:
On Mi, Sep 27 2023 at 12:36:02 +02:00:00, Carlos E. R. <robin.listas@telefonica.net> wrote:
Just to mention that we get one or two hits daily. Someone must have a script for this hole.
Not a problem, I just have to click "discard", just makes life a bit more entertaining ;-)
Still curious why only the Spanish list is hit.
I temporarily removed the ability to log in with google, let's see if we get any more of the spam and reports of genuine users trying to log in.
LCP [Jake] https://lcp.world/
Ah! Interesting. We'll see. Last hit was this morning at 12:06 CEST. -- Cheers / Saludos, Carlos E. R. (from openSUSE 15.5 (Laicolasse))
participants (3)
-
Carlos E. R.
-
Carlos E. R.
-
Jacob Michalskie