Jump to content

danmoran

Members
  • Content Count

    15
  • Joined

  • Last visited

Community Reputation

0 Neutral

About danmoran

  • Rank
    Member
  1. danmoran

    SC not parsing URL's

    Once again, the parser is completely ignoring URL's in a submitted spam: http://www.spamcop.net/sc?id=z5429551767z4...054f9ae92a8279z I've seen this before, but very sporadically.
  2. danmoran

    FAQ Entry: The Link Analysis Process

    Spamcop isn't picking up any links in reported spam today.
  3. danmoran

    Reporting problems today?

    As the saying goes: "Fix the problem before you worry about fixing the blame." Good luck guys.
  4. danmoran

    Reporting problems today?

    Still timing out: The proxy server did not receive a timely response from the upstream server. Reference #1.ac971160.1341593853.90894edb
  5. danmoran

    Reporting problems today?

    More of this: got sigalarm, taking too long to process, aborted. Perhaps you can wait a few minutes and reload?
  6. danmoran

    Reporting problems today?

    Still getting this error: got sigalarm, taking too long to process, aborted. Perhaps you can wait a few minutes and reload?
  7. danmoran

    Reporting problems today?

    Same here. The proxy server did not receive a timely response from the upstream server. Reference #1.364d1160.1340977801.1f8f8448
  8. danmoran

    Reporting problems today?

    Actual error message is: got sigalarm, taking too long to process, aborted. Perhaps you can wait a few minutes and reload?
  9. danmoran

    Reporting problems today?

    Several times daily, the system hangs after submitting spam. After letting it timeout, I receive a message about processes taking too long to terminate.
  10. I'm having exactly the same issue. I replied to the notice, but no response so far.
  11. danmoran

    Parsing errors

    So if I no Mailhosts are specified, then the correct source is identified, otherwise SC limits the "source" to one hop?
  12. danmoran

    Parsing errors

    Freenet.de is not one of my mailhosts, but this issue often happens when spam is relayed through freenet.de.
  13. danmoran

    Parsing errors

    Okay, the tracking URL is: http://www.spamcop.net/sc?id=z4908666257zd...fa17b911b273ffz Taking a look at the header: X-Apparently-To: x via 76.13.11.67; Sat, 26 Feb 2011 23:13:00 -0800 Return-Path: <kenjimadoka8[at]aim.com> X-YahooFilteredBulk: 195.4.92.98 Received-SPF: pass (mta1253.mail.mud.yahoo.com: domain of kenjimadoka8[at]aim.com designates 195.4.92.98 as permitted sender) X-YMailISG: G9FM5XccZApSJLD.UqUyRyWHVcpWHK0PE8JqyvGkjLzEp2.v vFHVSrsAkApidHKnZqHDRCMp7MuKWtYkOv2nDmjpDQEzp7RKfutAC._rs2ed Jwm6uWd7WJv_gCCHs_WcmAqJyoap6GsoMmmUtKOce6qTRcY9NcigUe10aqvg 51F3oEB8ly7aCRrDgcKhLFZZuN2n4._43_ZJSh0YXYGxPWmxtKTOy5Lpbk78 baEdNev3hsXZI1CM.laLKlldoerY2xAa2cFCAskTNBVGlvu6VpVqFdYIsl69 R8qyoiuaMf5L1LIL8BoHl_80CaYGoJ9B04xQypfgrGcBnbhP37LAt6djuBsi 3xsaFLPVXRRsqte.aPcWu94NixbrxjClnDzeg24lJSQFmq2P.mZq4ts4MHjv YWK6A4cpNCzpH16xbl76R_2CtpSrHSyUXwmGx.Xox7Ns8rnAFa.7gZ4Mm5H3 r_bTk7dUehlhEGLoD9m890YY9FRmOqucv1btfCKBNu0QaD4LO1RNt._TbBeO A.dOy4pqEFlHV.CKPKXUAIGVD8VvwDd7lonFr4mZp8CJC6Vz8Dczr9oQALP7 7RqfdBYnrVWDHp5Et3xwFfJfSJpHk0iMXmCsvbto0aK75nVIDUhbqQLzCx22 YDSqasUuspMs49ETJ.oSznCc8CbbidDzCwAlMFIdMYh85mNZNSgPm1yBJF_Z 2vQ_pAMrmy1TY4.omLHGqmEEohwqN0ui7T4a7L7SUK5zNSbCfFjdVZkIa_kR hqXLYnm07qZR_EKAAYb2I0SmULae2P5HKRscmMARmslrCg7lxNARgNeSdN30 pcFlzBZ_PfLSyHTXcg9rJw3fYcYLTZ.9vjnVbBpf0siahKKj8zlSL2lrDN8v RsYGrvNBtHcjFYAO5qFYDNk7OWOkWzGWtxqOB65ASx4tUqt_gzOuhikH9rqN C8JIsQ9kkF3N2qAiJox.9_dTtP0ebS1t1m.pOerWeTtF6Hpmr3N2IiiFJAnB rC4eB4W6vJ.JUMWurhRI_mqWrlHTacsZN1kMBamph5WrtN.rIXf.DROg4L95 XvmvR6o3IjFgg5Cuy5WFJQtEZyWXzaJXZL8grZJ5F8SWRpw7KoDWND8_CayP 6hsBCGGapHheEs.zSFditiXT8D_WV_phKAxAo_Ew7Xhq9BnGir00nRy0 X-Originating-IP: [195.4.92.98] Authentication-Results: mta1253.mail.mud.yahoo.com from=aim.com; domainkeys=neutral (no sig); from=aim.com; dkim=neutral (no sig) Received: from 127.0.0.1 (EHLO mout8.freenet.de) (195.4.92.98) by mta1253.mail.mud.yahoo.com with SMTP; Sat, 26 Feb 2011 23:12:54 -0800 Received: from [195.4.92.23] (helo=13.mx.freenet.de) by mout8.freenet.de with esmtpa (ID webmaster[at]donationformulagmbh01.de) (port 25) (Exim 4.72 #3) id 1PtaoF-00047K-6G; Sun, 27 Feb 2011 08:12:51 +0100 Received: from [74.63.125.204] (port=2798 helo=User) by 13.mx.freenet.de with esmtpa (ID webmaster[at]donationformulagmbh01.de) (port 587) (Exim 4.72 #3) id 1PtaoE-0002ZC-LL; Sun, 27 Feb 2011 08:12:51 +0100 Reply-To: <kenjimadoka2[at]yahoo.co.jp> From: "Kenji Madoka"<kenjimadoka8[at]aim.com> Add sender to Contacts Subject: LOST LOTTERY TICKET. Date: Sun, 27 Feb 2011 01:12:36 -0800 MIME-Version: 1.0 X-Content-Type: multipart/mixed; boundary="----=_NextPart_000_00C0_01C2A9A6.65DE4AF6" X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2600.0000 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000 Message-ID: <1Pta________C-LL[at]13.mx.freenet.de> Content-Length: 5217 Content-Type: text/plain X-SpamCop-note: Converted to text/plain by SpamCop (outlook/eudora hack) The source is 74.63.125.204, which is listed in the CBL as running SendSafe malware, which fits in with this 419 spam. But SC: 1: Received: from [195.4.92.23] (helo=13.mx.freenet.de) by mout8.freenet.de with esmtpa (ID webmaster[at]donationformulagmbh01.de) (port 25) (Exim 4.72 #3) id 1PtaoF-00047K-6G; Sun, 27 Feb 2011 08:12:51 +0100 Hostname verified: 13.mx.freenet.de Possible forgery. Supposed receiving system not associated with any of your mailhosts Will not trust anything beyond this header
  14. danmoran

    Parsing errors

    Besides the on-going issue of the spam source going undetected because the parser has erroneously identified it as a forgery, I'm now finding that the abuse-reporting addresses of certain subnets are also being mis-identified. For example, the email address amabusemail4[at]gmail.com, is dismissed and replaced with abuse[at]gmail.com. I'm sorry that I can't provide the actual report, but SC wrongly identified both the source and the reporting address for the spamvertised URL, so I canceled the report.
  15. danmoran

    Reporting Difficulties

    I copy and paste the original format of gmail spam into the SC form, and starting this morning, I'm getting this: Failed to load spam header
×