comp.lang.ada
 help / color / mirror / Atom feed
From: Preben Randhol <randhol+abuse@pvv.org>
Subject: Re: Current "Swen" worm attack - a tip
Date: Tue, 23 Sep 2003 07:33:49 +0000 (UTC)
Date: 2003-09-23T07:33:49+00:00	[thread overview]
Message-ID: <slrnbmvtqt.gu.randhol+abuse@kiuk0152.chembio.ntnu.no> (raw)
In-Reply-To: Uc2cnZUs_-UVXPKiU-KYjA@gbronline.com

On 2003-09-23, Wes Groleau <groleau@freeshell.org> wrote:
> Stephane Richard wrote:
>> in my case (100 of them per hour)....all ranging from "undeliverable
>> message", to "Security updates", to whatever else there could be...."Report
>> from Admin", "Letter", you name it...all different Fromline to Subject
>> linesit put my regular email over quota quite fast ... which is why I posted
>
> I did detect a simple pattern: in the subject header,
> the word SUBJECT is like that--all caps.

No, but the exe files incuded are mainly the same. I think there are 3
different exe files so just take one line from the base64 encoding and
delete any mail containing it. Of course there is a slight slight risk
that another e-mail could have an attachment that could give the same
line, but it is not very likely.

> Once I noticed that it was a simple matter to filter
> them out.

I have found that the baysian filtering is very good when you have
taught it what is spam and what is not. It takes a bit effort in the
beginning, but now I get about 40-50 spams a day and I have some 5-7
mailinglists and it filters all for me into correct folders. Sometimes a
spam ends in the wrong place, but then it is simply (for me) to press a
key and it is relearnt as spam and moved into that folder.

I have heard talk that the naive baysian statisical methods used could
be improved and other statistical methods might do better, however there
has not been an implementation yet. So if anybody here knows statistics
it is a nice chance to make a killer spam filter :-)

Preben



  reply	other threads:[~2003-09-23  7:33 UTC|newest]

Thread overview: 31+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-09-22  3:05 Current "Swen" worm attack Alexander Kopilovitch
2003-09-22 10:27 ` Stephane Richard
2003-09-22 11:45   ` chris
2003-09-23  3:49     ` Wes Groleau
2003-09-22 11:49   ` Preben Randhol
2003-09-22 21:42     ` Randy Brukardt
2003-09-23  7:10       ` Preben Randhol
2003-09-23  7:35       ` Vinzent Hoefler
2003-09-23  0:39     ` Alexander Kopilovitch
2003-09-23  4:11       ` David Marceau
2003-09-23 11:08         ` Jeff C,
2003-09-23 15:41           ` Ludovic Brenta
2003-09-24  1:14             ` Jeff C,
2003-09-24  8:20             ` Martin Krischik
2003-09-25 10:10               ` Ludovic Brenta
2003-09-25 11:01                 ` Martin Krischik
2003-09-25 11:32                 ` Preben Randhol
2003-09-25 12:07                   ` Ludovic Brenta
2003-09-25 13:47                 ` Stephen Leake
2003-09-23 18:47         ` Randy Brukardt
2003-09-23 20:56         ` Berend de Boer
     [not found]       ` <3F6FA78D.3070708@myob.com>
2003-10-03 13:41         ` sk
2003-10-03 14:17           ` Preben Randhol
2003-09-23  3:44   ` Current "Swen" worm attack - a tip Wes Groleau
2003-09-23  7:33     ` Preben Randhol [this message]
2003-09-23 17:44       ` Jeffrey Carter
2003-09-23 18:00         ` Brian Catlin
2003-09-23 19:14           ` tmoran
2003-09-23 20:55         ` Berend de Boer
2003-09-24 10:08         ` Dmitry A. Kazakov
2003-09-24 21:50           ` Wes Groleau
replies disabled

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox