August 30, 2013

SPEWS Memorial Day

Every August 30th the APEWS.org website changes it's home page to show the following;

 **************************************

Today our website and our mail-servers are not available, because it is 30 August - SPEWS MEMORIAL DAY

Our beloved SPEWS operator got hit by a truck and died 30 August 2006. One of his dreams was to make the world a spam free place.
As long as spam exists we therefore recommend all of you to shutdown all mail-servers at every 30. August for 24 hours.
Be creative to make today a black day for all spammers and spam supporters and a day without mail and spam.
It is just one day in the year so it will not hurt you nor your company, but it will set a widely visible sign if enough people do so.
Our blacklists are online, but we will not display reasons for listings nor do any removals by today.
We will be back by tomorrow. APEWS - Anonymous Postmasters Early Warning System.

 **************************************

The man behind the former blacklist known as SPEWS was visionary in that he recognized that playing with dynamic listings was mot a solution, just prolonging the problem and in fact permitting both spammers and anti-spammers to continue to profit from the problem at the expenses of the general public internet users.

Instead he designed a fixed listing system that prevented the internet service providers (ISP) from recycling their IP space for profit, listing them as having a bad reputation. The SPEWS blacklist database was known to be fairly aggressive with the ISPs that ignored the spam problem whilst making money from it.

From what we know, the founder of SPEWS was not only an experienced driver but had additional training possibly as a driving instructor. He also liked to drive one of the safest cars manufactured yet, despite this, whilst driving his usual cross-country route between home and office, a truck appeared and there was a crash that left the SPEWS founder dead. That was August 30th 2006. Was there foul play?

We think that if the SPEWS founder was still alive today, he would be pleased with the progress that APEWS.org has made using his ideology and advancing it further to cover all ISPs and IPv4 space.

August 28, 2013

L2.APEWS.ORG False Positive #23

Another reported false positive, few and far between as you have seen. This is the full header munged where appropriate;

Wed 2013-08-28 01:14:38: [6404:8081] Accepting SMTP connection from [98.130.1.134]
Wed 2013-08-28 01:14:38: [6404:8081] Looking up PTR record for 98.130.1.134 (134.1.130.98.IN-ADDR.ARPA)
Wed 2013-08-28 01:14:39: [6404:8081] D=134.1.130.98.IN-ADDR.ARPA TTL=(1440) PTR=[mail404.opentransfer.com]
Wed 2013-08-28 01:14:39: [6404:8081] Gathering A-records for PTR hosts
Wed 2013-08-28 01:14:39: [6404:8081] D=mail404.opentransfer.com TTL=(1440) A=[98.130.1.134]
Wed 2013-08-28 01:14:39: [6404:8081] --> 220 xxx.xxx.xxx ESMTP MDaemon 6.7.8; Wed, 28 Aug 2013 01:14:39 -0400
Wed 2013-08-28 01:14:39: [6404:8081] <-- HELO mail404.opentransfer.com
Wed 2013-08-28 01:14:39: [6404:8081] Performing reverse lookup on mail404.opentransfer.com (looking for 98.130.1.134)
Wed 2013-08-28 01:14:39: [6404:8081] D=mail404.opentransfer.com TTL=(1439) A=[98.130.1.134]
Wed 2013-08-28 01:14:39: [6404:8081] --> 250 xxx.xxx.xxx Hello mail404.opentransfer.com, pleased to meet you
Wed 2013-08-28 01:14:39: [6404:8081] <-- MAIL FROM:<xxx@xxx.xxx>
Wed 2013-08-28 01:14:39: [6404:8081] Performing reverse lookup on xxx.xxx (looking for 98.130.1.134)
Wed 2013-08-28 01:14:40: [6404:8081] D=xxx.xxx TTL=(360) A=[98.130.139.194]
Wed 2013-08-28 01:14:40: [6404:8081] P=010 D=xxx.xxx TTL=(359) MX=[mail404.ixwebhosting.com] {76.162.254.110}
Wed 2013-08-28 01:14:40: [6404:8081] Spam Blocker A-record resolution of [134.1.130.98.L2.APEWS.ORG] in progress (DNS Server: 192.168.1.2)...
Wed 2013-08-28 01:14:40: [6404:8081] Spam Blocker D=134.1.130.98.L2.APEWS.ORG TTL=(35) A=[127.0.0.2]
Wed 2013-08-28 01:14:40: [6404:8081] L2.APEWS.ORG LISTED
Wed 2013-08-28 01:14:40: [6404:8081] Message will be accepted and X-RBL-Warning: header will be inserted.
Wed 2013-08-28 01:14:40: [6404:8081] --> 250 <xxx@xxx.xxx>, Sender ok
Wed 2013-08-28 01:14:40: [6404:8081] <-- RCPT TO:<xxx@xxx.xxx>
Wed 2013-08-28 01:14:40: [6404:8081] --> 250 <xxx@xxx.xxx>, Recipient ok
Wed 2013-08-28 01:14:40: [6404:8081] <-- DATA
Wed 2013-08-28 01:14:40: [6404:8081] --> 354 Enter mail, end with <CRLF>.<CRLF>
Wed 2013-08-28 01:14:41: [6404:8081] --> 250 Ok, message saved <Message-ID: !&!AAzWLFEsxmkTAAA==@xxx.xxx>
Wed 2013-08-28 01:14:41: [6404:8081] <-- QUIT
Wed 2013-08-28 01:14:41: [6404:8081] --> 221 See ya in cyberspace
Wed 2013-08-28 01:14:41: [6404:8081] SMTP session successful, 1273 bytes transferred.
Wed 2013-08-28 01:14:41: [6404:8081] Shuffling message(s) into proper queue(s)
Wed 2013-08-28 01:14:41: [6404:8081] Message received from mail404.opentransfer.com [98.130.1.134] <xxx@xxx.xxx> with SMTP for <xxx@xxx.xxx> [Size 1260] {j:\localq\000330.msg}