What's with all these spam messages?

C'mon people, List is hurt by a bandalic atack. List need their user
now, do not leave it

Thread name: "what's with all these spam messages?"
Mail number: 1
In reply to: Jerry Davis

···

Date: Sun, Apr 12, 2015

I am getting a lot of spam's in this list?
Is anyone else getting them?

And more importantly, is any moderator working on them?

Jerry

--
Extra Ham Operator: K7AZJ
Registered Linux User: 275424
Raspberry Pi and Arduino developer

*The most exciting phrase to hear in science - the one that heralds new
discoveries - is not "Eureka!" but "That's funny...".*- Isaac. Asimov

*I*
*f you give someone a program, you will frustrate them for a day; if you
teach them how to program, you will frustrate them for a lifetime. *-
Anonymous

*If writing good code requires very little comments, then writing really
excellent code requires no comments at all!*- Ken Thompson

Well, I´d subscribe to learn some ruby, but what is happening?, is there any
problem with the mailing list?, regards.

···

-----Mensaje original-----
De: ruby-talk [mailto:ruby-talk-bounces@ruby-lang.org] En nombre de Lázaro
Armando
Enviado el: lunes, 13 de abril de 2015 17:03
Para: Ruby users
Asunto: Re: what's with all these spam messages?

C'mon people, List is hurt by a bandalic atack. List need their user now, do
not leave it

Thread name: "what's with all these spam messages?"
Mail number: 1
Date: Sun, Apr 12, 2015
In reply to: Jerry Davis

I am getting a lot of spam's in this list?
Is anyone else getting them?

And more importantly, is any moderator working on them?

Jerry

--
Extra Ham Operator: K7AZJ
Registered Linux User: 275424
Raspberry Pi and Arduino developer

*The most exciting phrase to hear in science - the one that heralds
new discoveries - is not "Eureka!" but "That's funny...".*- Isaac.
Asimov

*I*
*f you give someone a program, you will frustrate them for a day; if
you teach them how to program, you will frustrate them for a lifetime.
*- Anonymous

*If writing good code requires very little comments, then writing
really excellent code requires no comments at all!*- Ken Thompson

There was, everythin look fine now..

Thread name: "RE: what's with all these spam messages?"
Mail number: 1
In reply to: Ulises Bretana

···

Date: Mon, Apr 13, 2015

Well, I´d subscribe to learn some ruby, but what is happening?, is there any
problem with the mailing list?, regards.

-----Mensaje original-----
De: ruby-talk [mailto:ruby-talk-bounces@ruby-lang.org] En nombre de Lázaro
Armando
Enviado el: lunes, 13 de abril de 2015 17:03
Para: Ruby users
Asunto: Re: what's with all these spam messages?

C'mon people, List is hurt by a bandalic atack. List need their user now, do
not leave it

Thread name: "what's with all these spam messages?"
Mail number: 1
Date: Sun, Apr 12, 2015
In reply to: Jerry Davis
>
> I am getting a lot of spam's in this list?
> Is anyone else getting them?
>
> And more importantly, is any moderator working on them?
>
> Jerry
>
> --
> Extra Ham Operator: K7AZJ
> Registered Linux User: 275424
> Raspberry Pi and Arduino developer
>
>
> *The most exciting phrase to hear in science - the one that heralds
> new discoveries - is not "Eureka!" but "That's funny...".*- Isaac.
> Asimov
>
> *I*
> *f you give someone a program, you will frustrate them for a day; if
> you teach them how to program, you will frustrate them for a lifetime.
> *- Anonymous
>
>
> *If writing good code requires very little comments, then writing
> really excellent code requires no comments at all!*- Ken Thompson

Yep, that's nice, greetings from cuba...

···

-----Mensaje original-----
De: ruby-talk [mailto:ruby-talk-bounces@ruby-lang.org] En nombre de Lázaro Armando
Enviado el: lunes, 13 de abril de 2015 17:34
Para: Ruby users
Asunto: Re: what's with all these spam messages?

There was, everythin look fine now..

Thread name: "RE: what's with all these spam messages?"
Mail number: 1
Date: Mon, Apr 13, 2015
In reply to: Ulises Bretana

Well, I´d subscribe to learn some ruby, but what is happening?, is
there any problem with the mailing list?, regards.

-----Mensaje original-----
De: ruby-talk [mailto:ruby-talk-bounces@ruby-lang.org] En nombre de
Lázaro Armando Enviado el: lunes, 13 de abril de 2015 17:03
Para: Ruby users
Asunto: Re: what's with all these spam messages?

C'mon people, List is hurt by a bandalic atack. List need their user
now, do not leave it

Thread name: "what's with all these spam messages?"
Mail number: 1
Date: Sun, Apr 12, 2015
In reply to: Jerry Davis
>
> I am getting a lot of spam's in this list?
> Is anyone else getting them?
>
> And more importantly, is any moderator working on them?
>
> Jerry
>
> --
> Extra Ham Operator: K7AZJ
> Registered Linux User: 275424
> Raspberry Pi and Arduino developer
>
>
> *The most exciting phrase to hear in science - the one that heralds
> new discoveries - is not "Eureka!" but "That's funny...".*- Isaac.
> Asimov
>
> *I*
> *f you give someone a program, you will frustrate them for a day; if
> you teach them how to program, you will frustrate them for a lifetime.
> *- Anonymous
>
>
> *If writing good code requires very little comments, then writing
> really excellent code requires no comments at all!*- Ken Thompson

Hello,

I blocked the spammer's IP address yesterday.
I hope it won't happen again....

···

2015-04-14 0:33 GMT+09:00 Lázaro Armando <lazaro@hcg.sld.cu>:

There was, everythin look fine now..

Thread name: "RE: what's with all these spam messages?"
Mail number: 1
Date: Mon, Apr 13, 2015
In reply to: Ulises Bretana

Well, I´d subscribe to learn some ruby, but what is happening?, is there any
problem with the mailing list?, regards.

-----Mensaje original-----
De: ruby-talk [mailto:ruby-talk-bounces@ruby-lang.org] En nombre de Lázaro
Armando
Enviado el: lunes, 13 de abril de 2015 17:03
Para: Ruby users
Asunto: Re: what's with all these spam messages?

C'mon people, List is hurt by a bandalic atack. List need their user now, do
not leave it

Thread name: "what's with all these spam messages?"
Mail number: 1
Date: Sun, Apr 12, 2015
In reply to: Jerry Davis
>
> I am getting a lot of spam's in this list?
> Is anyone else getting them?
>
> And more importantly, is any moderator working on them?
>
> Jerry
>
> --
> Extra Ham Operator: K7AZJ
> Registered Linux User: 275424
> Raspberry Pi and Arduino developer
>
>
> *The most exciting phrase to hear in science - the one that heralds
> new discoveries - is not "Eureka!" but "That's funny...".*- Isaac.
> Asimov
>
> *I*
> *f you give someone a program, you will frustrate them for a day; if
> you teach them how to program, you will frustrate them for a lifetime.
> *- Anonymous
>
>
> *If writing good code requires very little comments, then writing
> really excellent code requires no comments at all!*- Ken Thompson

--
Shugo Maeda

Great!

regards from Italy

···

2015-04-13 11:44 GMT+02:00 Ulises Bretana <ulises@pinarte.cult.cu>:

Yep, that's nice, greetings from cuba...

-----Mensaje original-----
De: ruby-talk [mailto:ruby-talk-bounces@ruby-lang.org] En nombre de
Lázaro Armando
Enviado el: lunes, 13 de abril de 2015 17:34
Para: Ruby users
Asunto: Re: what's with all these spam messages?

There was, everythin look fine now..

Thread name: "RE: what's with all these spam messages?"
Mail number: 1
Date: Mon, Apr 13, 2015
In reply to: Ulises Bretana
>
> Well, I´d subscribe to learn some ruby, but what is happening?, is
> there any problem with the mailing list?, regards.
>
> -----Mensaje original-----
> De: ruby-talk [mailto:ruby-talk-bounces@ruby-lang.org] En nombre de
> Lázaro Armando Enviado el: lunes, 13 de abril de 2015 17:03
> Para: Ruby users
> Asunto: Re: what's with all these spam messages?
>
> C'mon people, List is hurt by a bandalic atack. List need their user
> now, do not leave it
>
>
> Thread name: "what's with all these spam messages?"
> Mail number: 1
> Date: Sun, Apr 12, 2015
> In reply to: Jerry Davis
> >
> > I am getting a lot of spam's in this list?
> > Is anyone else getting them?
> >
> > And more importantly, is any moderator working on them?
> >
> > Jerry
> >
> > --
> > Extra Ham Operator: K7AZJ
> > Registered Linux User: 275424
> > Raspberry Pi and Arduino developer
> >
> >
> > *The most exciting phrase to hear in science - the one that heralds
> > new discoveries - is not "Eureka!" but "That's funny...".*- Isaac.
> > Asimov
> >
> > *I*
> > *f you give someone a program, you will frustrate them for a day; if
> > you teach them how to program, you will frustrate them for a lifetime.
> > *- Anonymous
> >
> >
> > *If writing good code requires very little comments, then writing
> > really excellent code requires no comments at all!*- Ken Thompson

This is a good group. Rubists are the most evolved people on the planet.
The guy was probably drunk. No need to over mod the group.

···

On Tue, Apr 14, 2015 at 7:54 AM, Lázaro Armando <lazaro@hcg.sld.cu> wrote:

look like a simple scriptl just read received headers, with Ruby's rand
method you can make a script like that

#!/usr/bin/ruby

require 'base64'
require 'open-uri'

# from's list
froms=%w[fulano@gmail.com siclano@gmail.com esperanzejo@gmail.com]

# mike mail lib, for write mails
require 'mail'
mail=Mail.new
mail.to='victim@domain.com'
mail.body='hack you'

loop do

  # choose a random from
  mail.from=froms.sample

  # random subject
  mail.subject='THIS LIST IS BEING HACKED'.split.shuffle.join(' ')

  # random body of crap
  mail.body=Base64.encode64(open '
http://en.wikipedia.org/wiki/Special:Random&#39;\)

  # fire!
  mail.deliver

  # take a time
  sleep(rand(3..9))

end

Thread name: "Re: what's with all these spam messages?"
Mail number: 15
Date: Tue, Apr 14, 2015
In reply to: leam hall
>
> It's pretty easy to send to a list and change the "from" address. The
spam
> attack really wasn't that impressive, technology wise.
>
> On Tue, Apr 14, 2015 at 10:36 AM, Jesús Gabriel y Galán < > > jgabrielygalan@gmail.com> wrote:
>
> > On Tue, Apr 14, 2015 at 4:29 PM, Chris Tonkinson <chris@tonkinson.com> > > > wrote:
> > > Problem there is that poor Abinoam IS a trusted user.
> > >
> > > I'm not familiar with the technical details of the attack but either
his
> > > address (and more than a few others) were spoofed, or his (and their)
> > > email accounts were compromised directly.
> >
> > Ah, yes, you are right. Can anybody share how the actual attack
happened?
> >
> > Jesus.
> >
>
>
>
> --
> Mind on a Mission <http://leamhall.blogspot.com/&gt;

Hi Shugo,

And what about to have the list moderated, or at least have a group of
moderators (even if the list is not set to be moderated). So, if we
have such annoying event like this at the future, there's more than
one person to ask help for.

I would suggest at least 10 moderators in different time zones.
You could get the oldest (in Ruby years) people over here, grant some
permissions at the list server and see how it works. People like Ryan
Davis, Xavier Noria, and others could be of great help to keep the
list running.

And, if you really think about setting the list to "moderated" with a
list of at least 10 moderators there'll be not too much delay between
sending the message and it being approved by any of the moderators.

What do you think about it?

And thanks for fixing it.

Best regards,
Abinoam Jr.

···

On Tue, Apr 14, 2015 at 5:09 AM, Shugo Maeda <shugo@ruby-lang.org> wrote:

Hello,

I blocked the spammer's IP address yesterday.
I hope it won't happen again....

2015-04-14 0:33 GMT+09:00 Lázaro Armando <lazaro@hcg.sld.cu>:

There was, everythin look fine now..

Thread name: "RE: what's with all these spam messages?"
Mail number: 1
Date: Mon, Apr 13, 2015
In reply to: Ulises Bretana

Well, I´d subscribe to learn some ruby, but what is happening?, is there any
problem with the mailing list?, regards.

-----Mensaje original-----
De: ruby-talk [mailto:ruby-talk-bounces@ruby-lang.org] En nombre de Lázaro
Armando
Enviado el: lunes, 13 de abril de 2015 17:03
Para: Ruby users
Asunto: Re: what's with all these spam messages?

C'mon people, List is hurt by a bandalic atack. List need their user now, do
not leave it

Thread name: "what's with all these spam messages?"
Mail number: 1
Date: Sun, Apr 12, 2015
In reply to: Jerry Davis
>
> I am getting a lot of spam's in this list?
> Is anyone else getting them?
>
> And more importantly, is any moderator working on them?
>
> Jerry
>
> --
> Extra Ham Operator: K7AZJ
> Registered Linux User: 275424
> Raspberry Pi and Arduino developer
>
>
> *The most exciting phrase to hear in science - the one that heralds
> new discoveries - is not "Eureka!" but "That's funny...".*- Isaac.
> Asimov
>
> *I*
> *f you give someone a program, you will frustrate them for a day; if
> you teach them how to program, you will frustrate them for a lifetime.
> *- Anonymous
>
>
> *If writing good code requires very little comments, then writing
> really excellent code requires no comments at all!*- Ken Thompson

--
Shugo Maeda

I hope too :slight_smile:

have a nice day.

···

2015-04-14 10:09 GMT+02:00 Shugo Maeda <shugo@ruby-lang.org>:

Hello,

I blocked the spammer's IP address yesterday.
I hope it won't happen again....

2015-04-14 0:33 GMT+09:00 Lázaro Armando <lazaro@hcg.sld.cu>:
> There was, everythin look fine now..
>
> Thread name: "RE: what's with all these spam messages?"
> Mail number: 1
> Date: Mon, Apr 13, 2015
> In reply to: Ulises Bretana
>>
>> Well, I´d subscribe to learn some ruby, but what is happening?, is
there any
>> problem with the mailing list?, regards.
>>
>> -----Mensaje original-----
>> De: ruby-talk [mailto:ruby-talk-bounces@ruby-lang.org] En nombre de
Lázaro
>> Armando
>> Enviado el: lunes, 13 de abril de 2015 17:03
>> Para: Ruby users
>> Asunto: Re: what's with all these spam messages?
>>
>> C'mon people, List is hurt by a bandalic atack. List need their user
now, do
>> not leave it
>>
>>
>> Thread name: "what's with all these spam messages?"
>> Mail number: 1
>> Date: Sun, Apr 12, 2015
>> In reply to: Jerry Davis
>> >
>> > I am getting a lot of spam's in this list?
>> > Is anyone else getting them?
>> >
>> > And more importantly, is any moderator working on them?
>> >
>> > Jerry
>> >
>> > --
>> > Extra Ham Operator: K7AZJ
>> > Registered Linux User: 275424
>> > Raspberry Pi and Arduino developer
>> >
>> >
>> > *The most exciting phrase to hear in science - the one that heralds
>> > new discoveries - is not "Eureka!" but "That's funny...".*- Isaac.
>> > Asimov
>> >
>> > *I*
>> > *f you give someone a program, you will frustrate them for a day; if
>> > you teach them how to program, you will frustrate them for a lifetime.
>> > *- Anonymous
>> >
>> >
>> > *If writing good code requires very little comments, then writing
>> > really excellent code requires no comments at all!*- Ken Thompson
>

--
Shugo Maeda

Problem there is that poor Abinoam IS a trusted user.

I'm not familiar with the technical details of the attack but either his
address (and more than a few others) were spoofed, or his (and their)
email accounts were compromised directly.

Chris Tonkinson
http://chris.tonkinson.com/
610.425.7807

  "Lead, follow, or get out of the way."
  -Thomas Paine

···

On 04/14/2015 10:26 AM, Jesús Gabriel y Galán wrote:

On Tue, Apr 14, 2015 at 2:03 PM, Abinoam Jr. <abinoam@gmail.com> wrote:

Hi Shugo,

And what about to have the list moderated, or at least have a group of
moderators (even if the list is not set to be moderated). So, if we
have such annoying event like this at the future, there's more than
one person to ask help for.

I would suggest at least 10 moderators in different time zones.
You could get the oldest (in Ruby years) people over here, grant some
permissions at the list server and see how it works. People like Ryan
Davis, Xavier Noria, and others could be of great help to keep the
list running.

And, if you really think about setting the list to "moderated" with a
list of at least 10 moderators there'll be not too much delay between
sending the message and it being approved by any of the moderators.

What do you think about it?

And thanks for fixing it.

I think moderating all messages is too heavy.
Some lists moderate just the first message of each user, to ensure
it's a real human sending something on-topic.
What about that?

Jesus.

It's pretty easy to send to a list and change the "from" address. The spam
attack really wasn't that impressive, technology wise.

···

On Tue, Apr 14, 2015 at 10:36 AM, Jesús Gabriel y Galán < jgabrielygalan@gmail.com> wrote:

On Tue, Apr 14, 2015 at 4:29 PM, Chris Tonkinson <chris@tonkinson.com> > wrote:
> Problem there is that poor Abinoam IS a trusted user.
>
> I'm not familiar with the technical details of the attack but either his
> address (and more than a few others) were spoofed, or his (and their)
> email accounts were compromised directly.

Ah, yes, you are right. Can anybody share how the actual attack happened?

Jesus.

--
Mind on a Mission <http://leamhall.blogspot.com/&gt;

Moderation in the sense that we have admin access and can turn on mailman's emergency moderation bit on (stop all delivery) until the real admin can deal with something like this. It could have quelled the flood in the first couple hours if we had someone in PST and UTC with mod bits.

···

On Apr 14, 2015, at 09:55, Eric Wong <normalperson@yhbt.net> wrote:

Please no moderation (as others suggested) for ruby-talk,
requiring subscription to post is already bad enough.

Bad idea. Do a little cost/benefit analysis. Such a spam attack is a very
rare event. It's brief. And to stop this we need 10 people, reviewing every
message sent to the list? Too much cost, too little benefit.

t.

···

On Tue, Apr 14, 2015 at 5:03 AM, Abinoam Jr. <abinoam@gmail.com> wrote:

Hi Shugo,

And what about to have the list moderated, or at least have a group of
moderators (even if the list is not set to be moderated). So, if we
have such annoying event like this at the future, there's more than
one person to ask help for.

I would suggest at least 10 moderators in different time zones.
You could get the oldest (in Ruby years) people over here, grant some
permissions at the list server and see how it works. People like Ryan
Davis, Xavier Noria, and others could be of great help to keep the
list running.

And, if you really think about setting the list to "moderated" with a
list of at least 10 moderators there'll be not too much delay between
sending the message and it being approved by any of the moderators.

What do you think about it?

And thanks for fixing it.

Best regards,
Abinoam Jr.

On Tue, Apr 14, 2015 at 5:09 AM, Shugo Maeda <shugo@ruby-lang.org> wrote:
> Hello,
>
> I blocked the spammer's IP address yesterday.
> I hope it won't happen again....
>
> 2015-04-14 0:33 GMT+09:00 Lázaro Armando <lazaro@hcg.sld.cu>:
>> There was, everythin look fine now..
>>
>> Thread name: "RE: what's with all these spam messages?"
>> Mail number: 1
>> Date: Mon, Apr 13, 2015
>> In reply to: Ulises Bretana
>>>
>>> Well, I´d subscribe to learn some ruby, but what is happening?, is
there any
>>> problem with the mailing list?, regards.
>>>
>>> -----Mensaje original-----
>>> De: ruby-talk [mailto:ruby-talk-bounces@ruby-lang.org] En nombre de
Lázaro
>>> Armando
>>> Enviado el: lunes, 13 de abril de 2015 17:03
>>> Para: Ruby users
>>> Asunto: Re: what's with all these spam messages?
>>>
>>> C'mon people, List is hurt by a bandalic atack. List need their user
now, do
>>> not leave it
>>>
>>>
>>> Thread name: "what's with all these spam messages?"
>>> Mail number: 1
>>> Date: Sun, Apr 12, 2015
>>> In reply to: Jerry Davis
>>> >
>>> > I am getting a lot of spam's in this list?
>>> > Is anyone else getting them?
>>> >
>>> > And more importantly, is any moderator working on them?
>>> >
>>> > Jerry
>>> >
>>> > --
>>> > Extra Ham Operator: K7AZJ
>>> > Registered Linux User: 275424
>>> > Raspberry Pi and Arduino developer
>>> >
>>> >
>>> > *The most exciting phrase to hear in science - the one that heralds
>>> > new discoveries - is not "Eureka!" but "That's funny...".*- Isaac.
>>> > Asimov
>>> >
>>> > *I*
>>> > *f you give someone a program, you will frustrate them for a day; if
>>> > you teach them how to program, you will frustrate them for a
lifetime.
>>> > *- Anonymous
>>> >
>>> >
>>> > *If writing good code requires very little comments, then writing
>>> > really excellent code requires no comments at all!*- Ken Thompson
>>
>
>
>
> --
> Shugo Maeda

--
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

My life is full of mistakes. They're like pebbles that make a good road. ~
Ceramic artist Beatrice Wood, who practiced her art until she was 103.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Tom Cloyd, MS MA LMHC (WA)
Psychotherapist (psychological trauma, dissociative disorders)
Spokane, Washington, U.S.A: (435) 272-3332
<< tc@tomcloyd.com >> (email)
<< TomCloyd.com >> (website)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

look like a simple scriptl just read received headers, with Ruby's rand
method you can make a script like that

#!/usr/bin/ruby

require 'base64'
require 'open-uri'

# from's list
froms=%w[fulano@gmail.com siclano@gmail.com esperanzejo@gmail.com]

# mike mail lib, for write mails
require 'mail'
mail=Mail.new
mail.to='victim@domain.com'
mail.body='hack you'

loop do

  # choose a random from
  mail.from=froms.sample

  # random subject
  mail.subject='THIS LIST IS BEING HACKED'.split.shuffle.join(' ')

  # random body of crap
  mail.body=Base64.encode64(open 'http://en.wikipedia.org/wiki/Special:Random&#39;\)

  # fire!
  mail.deliver

  # take a time
  sleep(rand(3..9))
  
end

Thread name: "Re: what's with all these spam messages?"
Mail number: 15
In reply to: leam hall

···

Date: Tue, Apr 14, 2015

It's pretty easy to send to a list and change the "from" address. The spam
attack really wasn't that impressive, technology wise.

On Tue, Apr 14, 2015 at 10:36 AM, Jesús Gabriel y Galán < > jgabrielygalan@gmail.com> wrote:

> On Tue, Apr 14, 2015 at 4:29 PM, Chris Tonkinson <chris@tonkinson.com> > > wrote:
> > Problem there is that poor Abinoam IS a trusted user.
> >
> > I'm not familiar with the technical details of the attack but either his
> > address (and more than a few others) were spoofed, or his (and their)
> > email accounts were compromised directly.
>
> Ah, yes, you are right. Can anybody share how the actual attack happened?
>
> Jesus.
>

--
Mind on a Mission <http://leamhall.blogspot.com/&gt;

That's good news thanks and keep up the good work.

···

On Tue, Apr 14, 2015 at 11:15 AM, Eugeniu T. <eugeniu.rtj@gmail.com> wrote:

I hope too :slight_smile:

have a nice day.

2015-04-14 10:09 GMT+02:00 Shugo Maeda <shugo@ruby-lang.org>:

Hello,

I blocked the spammer's IP address yesterday.
I hope it won't happen again....

2015-04-14 0:33 GMT+09:00 Lázaro Armando <lazaro@hcg.sld.cu>:
> There was, everythin look fine now..
>
> Thread name: "RE: what's with all these spam messages?"
> Mail number: 1
> Date: Mon, Apr 13, 2015
> In reply to: Ulises Bretana
>>
>> Well, I´d subscribe to learn some ruby, but what is happening?, is
there any
>> problem with the mailing list?, regards.
>>
>> -----Mensaje original-----
>> De: ruby-talk [mailto:ruby-talk-bounces@ruby-lang.org] En nombre de
Lázaro
>> Armando
>> Enviado el: lunes, 13 de abril de 2015 17:03
>> Para: Ruby users
>> Asunto: Re: what's with all these spam messages?
>>
>> C'mon people, List is hurt by a bandalic atack. List need their user
now, do
>> not leave it
>>
>>
>> Thread name: "what's with all these spam messages?"
>> Mail number: 1
>> Date: Sun, Apr 12, 2015
>> In reply to: Jerry Davis
>> >
>> > I am getting a lot of spam's in this list?
>> > Is anyone else getting them?
>> >
>> > And more importantly, is any moderator working on them?
>> >
>> > Jerry
>> >
>> > --
>> > Extra Ham Operator: K7AZJ
>> > Registered Linux User: 275424
>> > Raspberry Pi and Arduino developer
>> >
>> >
>> > *The most exciting phrase to hear in science - the one that heralds
>> > new discoveries - is not "Eureka!" but "That's funny...".*- Isaac.
>> > Asimov
>> >
>> > *I*
>> > *f you give someone a program, you will frustrate them for a day; if
>> > you teach them how to program, you will frustrate them for a
lifetime.
>> > *- Anonymous
>> >
>> >
>> > *If writing good code requires very little comments, then writing
>> > really excellent code requires no comments at all!*- Ken Thompson
>

--
Shugo Maeda

Yeah, puberty hits some people hard...

···

On Tue, Apr 14, 2015 at 11:22 AM, Johnny Merrill <ruralhack@gmail.com> wrote:

This is a good group. Rubists are the most evolved people on the planet.
The guy was probably drunk. No need to over mod the group.

--
Mind on a Mission <http://leamhall.blogspot.com/&gt;

I think moderating all messages is too heavy.
Some lists moderate just the first message of each user, to ensure
it's a real human sending something on-topic.
What about that?

Jesus.

···

On Tue, Apr 14, 2015 at 2:03 PM, Abinoam Jr. <abinoam@gmail.com> wrote:

Hi Shugo,

And what about to have the list moderated, or at least have a group of
moderators (even if the list is not set to be moderated). So, if we
have such annoying event like this at the future, there's more than
one person to ask help for.

I would suggest at least 10 moderators in different time zones.
You could get the oldest (in Ruby years) people over here, grant some
permissions at the list server and see how it works. People like Ryan
Davis, Xavier Noria, and others could be of great help to keep the
list running.

And, if you really think about setting the list to "moderated" with a
list of at least 10 moderators there'll be not too much delay between
sending the message and it being approved by any of the moderators.

What do you think about it?

And thanks for fixing it.

Ah, yes, you are right. Can anybody share how the actual attack happened?

Jesus.

···

On Tue, Apr 14, 2015 at 4:29 PM, Chris Tonkinson <chris@tonkinson.com> wrote:

Problem there is that poor Abinoam IS a trusted user.

I'm not familiar with the technical details of the attack but either his
address (and more than a few others) were spoofed, or his (and their)
email accounts were compromised directly.

What kind of spam filtering is done? Should be pretty easy to write
and maintain rules for SpamAssassin and I'd be glad to help.
I basically live and breathe email :slight_smile:

Please no moderation (as others suggested) for ruby-talk,
requiring subscription to post is already bad enough.

···

Shugo Maeda <shugo@ruby-lang.org> wrote:

Hello,

I blocked the spammer's IP address yesterday.
I hope it won't happen again....

Relax guys, its a common problem with any mailing list without premoderation. Some kids just wanted to have fun, block their e-mails and move on.

···

-----Original Message-----
From: "Johnny Merrill" <ruralhack@gmail.com>
Sent: ‎14.‎04.‎2015 18:23
To: "Ruby users" <ruby-talk@ruby-lang.org>
Subject: Re: what's with all these spam messages?

This is a good group. Rubists are the most evolved people on the planet. The guy was probably drunk. No need to over mod the group.

On Tue, Apr 14, 2015 at 7:54 AM, Lázaro Armando <lazaro@hcg.sld.cu> wrote:

look like a simple scriptl just read received headers, with Ruby's rand
method you can make a script like that

#!/usr/bin/ruby

require 'base64'
require 'open-uri'

# from's list
froms=%w[fulano@gmail.com siclano@gmail.com esperanzejo@gmail.com]

# mike mail lib, for write mails
require 'mail'
mail=Mail.new
mail.to='victim@domain.com'
mail.body='hack you'

loop do

  # choose a random from
  mail.from=froms.sample

  # random subject
  mail.subject='THIS LIST IS BEING HACKED'.split.shuffle.join(' ')

  # random body of crap
  mail.body=Base64.encode64(open 'http://en.wikipedia.org/wiki/Special:Random&#39;\)

  # fire!
  mail.deliver

  # take a time
  sleep(rand(3..9))

end

Thread name: "Re: what's with all these spam messages?"
Mail number: 15
Date: Tue, Apr 14, 2015
In reply to: leam hall

It's pretty easy to send to a list and change the "from" address. The spam
attack really wasn't that impressive, technology wise.

On Tue, Apr 14, 2015 at 10:36 AM, Jesús Gabriel y Galán < > jgabrielygalan@gmail.com> wrote:

> On Tue, Apr 14, 2015 at 4:29 PM, Chris Tonkinson <chris@tonkinson.com> > > wrote:
> > Problem there is that poor Abinoam IS a trusted user.
> >
> > I'm not familiar with the technical details of the attack but either his
> > address (and more than a few others) were spoofed, or his (and their)
> > email accounts were compromised directly.
>
> Ah, yes, you are right. Can anybody share how the actual attack happened?
>
> Jesus.
>

--

Mind on a Mission <http://leamhall.blogspot.com/&gt;