home.social

#spamtraps — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #spamtraps, aggregated by home.social.

fetched live
  1. I added a few more translations of the phrase "The rest is trash" to the spamtraps at nxdomain.no/~peter/traplist.sh (see nxdomain.no/~peter/the_rest_is or bsdly.blogspot.com/2026/02/the).

    If you want further translations added, please let me know (with translation in your message).

    #spamtraps #greytrapping #spamd #openbsd #freebsd #antispam #imaginaryfriends #localization #cybercrime

    The list without wrapper text is available as bsdly.net/~peter/sortlist.txt (BIG! -- 22975800 entries as of right now, will increase)

  2. I added a few more translations of the phrase "The rest is trash" to the spamtraps at nxdomain.no/~peter/traplist.sh (see nxdomain.no/~peter/the_rest_is or bsdly.blogspot.com/2026/02/the).

    If you want further translations added, please let me know (with translation in your message).

    #spamtraps #greytrapping #spamd #openbsd #freebsd #antispam #imaginaryfriends #localization #cybercrime

    The list without wrapper text is available as bsdly.net/~peter/sortlist.txt (BIG! -- 22975800 entries as of right now, will increase)

  3. I find it quite chuckleworthy that the pop3 gropers are eagerly trying even the /dev/random sourced local parts of spamtraps (mentioned in passing in nxdomain.no/~peter/eighteen_ye). But is it worth writing a fresh article about that?
    #openbsd #spamtraps #pop3gropers #cybercrime

  4. I find it quite chuckleworthy that the pop3 gropers are eagerly trying even the /dev/random sourced local parts of spamtraps (mentioned in passing in nxdomain.no/~peter/eighteen_ye). But is it worth writing a fresh article about that?
    #openbsd #spamtraps #pop3gropers #cybercrime

  5. Hm. log entries like

    Sep 30 00:54:41 skapet spamd[83364]: (GREY) 171.4.7.241: <[email protected]> -> <[email protected]>
    Sep 30 00:54:41 skapet spamd[83004]: new entry 171.4.7.241 from <[email protected]> to <[email protected]>, helo ns3000605.ip-37-59-46.eu

    have me suspect they are actually reading my stuff such as nxdomain.no/~peter/eighteen_ye #spamtraps #greytrapping #antispam #cybercrime #spamd #openbsd

  6. Hm. log entries like

    Sep 30 00:54:41 skapet spamd[83364]: (GREY) 171.4.7.241: <[email protected]> -> <[email protected]>
    Sep 30 00:54:41 skapet spamd[83004]: new entry 171.4.7.241 from <[email protected]> to <[email protected]>, helo ns3000605.ip-37-59-46.eu

    have me suspect they are actually reading my stuff such as nxdomain.no/~peter/eighteen_ye #spamtraps #greytrapping #antispam #cybercrime #spamd #openbsd

  7. In 2013 I wrote up "Maintaining A Publicly Available Blacklist - Mechanisms And Principles" (also bsdly.blogspot.com/2013/04/mai) . TL;DR: blocklisting is a kind of public shaming, be sure your process is verifiable and transparent.

    Minor edits today, links to resources and #eurobsdcon inside. #blocklists #spamtraps #antispam #smtp #spamd #openbsd #freebsd #security #cybercrime

  8. In 2013 I wrote up "Maintaining A Publicly Available Blacklist - Mechanisms And Principles" (also bsdly.blogspot.com/2013/04/mai) . TL;DR: blocklisting is a kind of public shaming, be sure your process is verifiable and transparent.

    Minor edits today, links to resources and #eurobsdcon inside. #blocklists #spamtraps #antispam #smtp #spamd #openbsd #freebsd #security #cybercrime

  9. September 7, 2022 the 300,000th spamtrap was added to our list of imaginary friends, see "The Things Spammers Believe - A Tale of 300,000 Imaginary Friends" nxdomain.no/~peter/spammers_be.

    Today, the number at at nxdomain.no/~peter/traplist.sh rolled past 5,000,000 (yes, five million). #spam #spamtraps #spamd #openbsd #cybercrime #scams #malware

  10. September 7, 2022 the 300,000th spamtrap was added to our list of imaginary friends, see "The Things Spammers Believe - A Tale of 300,000 Imaginary Friends" nxdomain.no/~peter/spammers_be.

    Today, the number at at nxdomain.no/~peter/traplist.sh rolled past 5,000,000 (yes, five million). #spam #spamtraps #spamd #openbsd #cybercrime #scams #malware

  11. The symptoms of what I take to have been a #phishing campaign aimed at users in #japan are no longer that visible in the backscatter.

    But they will be visible as new #imaginaryfriends in the published #spamtraps list we user for our our #openbsd #spamd #graytrapping, see nxdomain.no/~peter/traplist.sh and nxdomain.no/~peter/spammers_be (with the total now inching in the direction of the 5 million mark)

  12. The symptoms of what I take to have been a #phishing campaign aimed at users in #japan are no longer that visible in the backscatter.

    But they will be visible as new #imaginaryfriends in the published #spamtraps list we user for our our #openbsd #spamd #graytrapping, see nxdomain.no/~peter/traplist.sh and nxdomain.no/~peter/spammers_be (with the total now inching in the direction of the 5 million mark)

  13. Laura at WttW on "What Spamtraps Tell Us"

    "Just to be clear, spamtraps are NOT the problem; they’re a signal. Spamtraps tell us that there are problems with something about our data. No one really cares if email addresses that don’t belong to people get mail. But what they do care about is the fact that if your list processes allow spamtraps on the list, it’s likely you’re also sending mail to actual people who don’t want it."

    #spamtraps #emaildeliverability

    wordtothewise.com/2025/03/what

  14. Laura at WttW on "What Spamtraps Tell Us"

    "Just to be clear, spamtraps are NOT the problem; they’re a signal. Spamtraps tell us that there are problems with something about our data. No one really cares if email addresses that don’t belong to people get mail. But what they do care about is the fact that if your list processes allow spamtraps on the list, it’s likely you’re also sending mail to actual people who don’t want it."

    #spamtraps #emaildeliverability

    wordtothewise.com/2025/03/what

  15. The other horribly nonsensical thing I saw during the last 24 hours was the error messages GNU Emacs emits when it is faced with a file of a size that exceeds its expected per-buffer memory allocation.

    Fortunately a sane solution was found for that particular problem (split that big hand generated log into smaller pieces) - search for "this log directory" in nxdomain.no/~peter/traplist.sh #spamtraps #greyptrapping #spamd #antispam #cybercrime #imaginaryfriends

  16. The other horribly nonsensical thing I saw during the last 24 hours was the error messages GNU Emacs emits when it is faced with a file of a size that exceeds its expected per-buffer memory allocation.

    Fortunately a sane solution was found for that particular problem (split that big hand generated log into smaller pieces) - search for "this log directory" in nxdomain.no/~peter/traplist.sh #spamtraps #greyptrapping #spamd #antispam #cybercrime #imaginaryfriends

  17. Despite our efforts (such as those described in nxdomain.no/~peter/spammers_be btw that number rolled past 3 million some time back), *some* #spam will occasionally make it all the way through to an inbox and to be read by a person.

    Today I offer a prime sample: nxdomain.no/~peter/blogpix/202 #spamtraps #cybercrime #mail #email #smtp #scams #greytrapping

  18. Despite our efforts (such as those described in nxdomain.no/~peter/spammers_be btw that number rolled past 3 million some time back), *some* #spam will occasionally make it all the way through to an inbox and to be read by a person.

    Today I offer a prime sample: nxdomain.no/~peter/blogpix/202 #spamtraps #cybercrime #mail #email #smtp #scams #greytrapping

  19. Already somewhat blasé from life in the honeypots, yours truly registers an even more bizarre level of events after a some routine logs spelunking

    Read on in "A Suitably Bizarre Start of the Year 2025" nxdomain.no/~peter/suitably_bi (or bsdly.blogspot.com/2025/01/a-s)

    #OpenBSD #spamd #spam #spamtraps #greytrapping #SMTP #relaying, #antispam #network #security #cybercrime #2025 #yearofcrazy

    A *new* byproduct of the silliness: Spamtraps added per year (growth since records started): nxdomain.no/~peter/spamtraps-p

  20. Already somewhat blasé from life in the honeypots, yours truly registers an even more bizarre level of events after a some routine logs spelunking

    Read on in "A Suitably Bizarre Start of the Year 2025" nxdomain.no/~peter/suitably_bi (or bsdly.blogspot.com/2025/01/a-s)

    #OpenBSD #spamd #spam #spamtraps #greytrapping #SMTP #relaying, #antispam #network #security #cybercrime #2025 #yearofcrazy

    A *new* byproduct of the silliness: Spamtraps added per year (growth since records started): nxdomain.no/~peter/spamtraps-p

  21. A Suitably Bizarre Start of the Year 2025 nxdomain.no/~peter/suitably_bi (also bsdly.blogspot.com/2025/01/a-s)

    Already somewhat blasé from life in the honeypots, yours truly registers an even more bizarre level of events after a some routine logs spelunking

    #OpenBSD #spamd #spam #spamtraps #greytrapping #SMTP #relaying, #antispam #network #security #cybercrime #2025 #yearofcrazy

    *Bonus EDIT* for CET morning crowd: Spamtraps added per year (growth since records started): nxdomain.no/~peter/spamtraps-p

  22. A Suitably Bizarre Start of the Year 2025 nxdomain.no/~peter/suitably_bi (also bsdly.blogspot.com/2025/01/a-s)

    Already somewhat blasé from life in the honeypots, yours truly registers an even more bizarre level of events after a some routine logs spelunking

    #OpenBSD #spamd #spam #spamtraps #greytrapping #SMTP #relaying, #antispam #network #security #cybercrime #2025 #yearofcrazy

    *Bonus EDIT* for CET morning crowd: Spamtraps added per year (growth since records started): nxdomain.no/~peter/spamtraps-p

  23. Friday night follies included several attemtpts from [email protected] to deliver spam to one of the imaginary friends at nxdomain.no/~peter/traplist.sh as well as somebot attempting to ssh in as user <space>, which for #shell reasons will not be able to join the 500k+ #spamtraps

    All while you were sleeping. #spamd #cybercrime #antispam #sshgropers #passwordguessing

  24. Friday night follies included several attemtpts from [email protected] to deliver spam to one of the imaginary friends at nxdomain.no/~peter/traplist.sh as well as somebot attempting to ssh in as user <space>, which for #shell reasons will not be able to join the 500k+ #spamtraps

    All while you were sleeping. #spamd #cybercrime #antispam #sshgropers #passwordguessing

  25. My favorite among the imaginary friends[1] - now numbering more than half a million and counting by the way - for now would be [email protected], added today.

    [1] nxdomain.no/~peter/traplist.sh also nxdomain.no/~peter/spammers_be, same sentiments, but larger numbers.

    #spamtraps #antispam #spamd #openbsd #smtp #email #cybercrime

  26. My favorite among the imaginary friends[1] - now numbering more than half a million and counting by the way - for now would be [email protected], added today.

    [1] nxdomain.no/~peter/traplist.sh also nxdomain.no/~peter/spammers_be, same sentiments, but larger numbers.

    #spamtraps #antispam #spamd #openbsd #smtp #email #cybercrime

  27. I can report that it actually rolled past 400,000 this Tuesday.

    Fun or interesting in its own way, but not quite blogworthy. The sentiments expressed in the article about the 300,000 mark are still valid, though.

    See nxdomain.no/~peter/traplist.sh for latest updates. 408357 and counting.

    #spam #spamtraps #spamd #greytrapping #traplist #cybercrime

  28. I can report that it actually rolled past 400,000 this Tuesday.

    Fun or interesting in its own way, but not quite blogworthy. The sentiments expressed in the article about the 300,000 mark are still valid, though.

    See nxdomain.no/~peter/traplist.sh for latest updates. 408357 and counting.

    #spam #spamtraps #spamd #greytrapping #traplist #cybercrime

  29. @tab2space @paul_ipv6 @briankrebs heh, yes, the effort to make the spamto: databases as useless as possible has been progressing for years, and seems to have some effect.

    The traplist home page nxdomain.no/~peter/traplist.sh has links to various useful material. Perhaps nxdomain.no/~peter/badness_enu is worth mentioning too (also prettified, tracked at bsdly.blogspot.com/2018/08/bad) #spamtraps #antispam #cybercrime #feedback

  30. @tab2space @paul_ipv6 @briankrebs heh, yes, the effort to make the spamto: databases as useless as possible has been progressing for years, and seems to have some effect.

    The traplist home page nxdomain.no/~peter/traplist.sh has links to various useful material. Perhaps nxdomain.no/~peter/badness_enu is worth mentioning too (also prettified, tracked at bsdly.blogspot.com/2018/08/bad) #spamtraps #antispam #cybercrime #feedback

  31. For some reason I just looked up my now just over 2 year old piece "The Things Spammers Believe - A Tale of 300,000 Imaginary Friends" nxdomain.no/~peter/spammers_be (prettified, tracked bsdly.blogspot.com/2022/09/the) and realized that number will soon roll past the next big round marker. #spamtraps #traplist #spam #antispam #openbsd #pf #spamd #cybercrime #bottomfeeders #imaginaryfriends

  32. For some reason I just looked up my now just over 2 year old piece "The Things Spammers Believe - A Tale of 300,000 Imaginary Friends" nxdomain.no/~peter/spammers_be (prettified, tracked bsdly.blogspot.com/2022/09/the) and realized that number will soon roll past the next big round marker. #spamtraps #traplist #spam #antispam #openbsd #pf #spamd #cybercrime #bottomfeeders #imaginaryfriends

  33. Another one for the #ssh #password #groper #blooper reel:

    Nov 4 15:24:12 portal sshd-session[16361]: Failed password for invalid user user1!2@3#4$ from 185.11.61.88 port 40254 ssh2

    #sshgropers #passwordguessing #cybercrime

    (also to be added posthaste, with a domain appended, to the list of imaginary friends at nxdomain.no/~peter/traplist.sh) #spamtraps

  34. Another one for the #ssh #password #groper #blooper reel:

    Nov 4 15:24:12 portal sshd-session[16361]: Failed password for invalid user user1!2@3#4$ from 185.11.61.88 port 40254 ssh2

    #sshgropers #passwordguessing #cybercrime

    (also to be added posthaste, with a domain appended, to the list of imaginary friends at nxdomain.no/~peter/traplist.sh) #spamtraps

  35. This morning had me notice a new episode of the type described in "The Despicable, No Good, Blackmail Campaign Targeting ... Imaginary Friends?" nxdomain.no/~peter/despicable_ (or prettified, tracked bsdly.blogspot.com/2022/12/the), the first in quite a while, I might add.

    Data so far to be perused at nxdomain.no/~peter/wankstortio (now refreshed & gzipped).

    #spam #scams #wankstortion #sextortion #cybercrime #imaginaryfriends #spamtraps

  36. This morning had me notice a new episode of the type described in "The Despicable, No Good, Blackmail Campaign Targeting ... Imaginary Friends?" nxdomain.no/~peter/despicable_ (or prettified, tracked bsdly.blogspot.com/2022/12/the), the first in quite a while, I might add.

    Data so far to be perused at nxdomain.no/~peter/wankstortio (now refreshed & gzipped).

    #spam #scams #wankstortion #sextortion #cybercrime #imaginaryfriends #spamtraps

  37. Novel new #scam: a #spam email in French claiming to be from Interpol & stating that the recipient (one of our #spamtraps) has been "found guilty" of sexual crimes against minors & will be arrested (isn’t it usually the other way around?)

    Payload is a long official-looking JPEG enumerating the supposed crimes & requiring the recipient to contact a “law firm" at their Gmail address.

    It's a basic 'frightener scam’, but with no immediate mention of payment: that will presumably come later.

  38. Novel new #scam: a #spam email in French claiming to be from Interpol & stating that the recipient (one of our #spamtraps) has been "found guilty" of sexual crimes against minors & will be arrested (isn’t it usually the other way around?)

    Payload is a long official-looking JPEG enumerating the supposed crimes & requiring the recipient to contact a “law firm" at their Gmail address.

    It's a basic 'frightener scam’, but with no immediate mention of payment: that will presumably come later.

  39. The joys of running your own #mail system: Seeing that mailer-daemon@ and root@ for specific hosts along with postmaster@ and even hostmaster@ for all domains now included in bottom-feeders' spamto: lists #smtp #spam (and of course seeing that for a brief time, the number of #spamtraps collected for #greytrapping was a palindromic number, nxdomain.no/~peter/traplist.sh)

  40. The joys of running your own #mail system: Seeing that mailer-daemon@ and root@ for specific hosts along with postmaster@ and even hostmaster@ for all domains now included in bottom-feeders' spamto: lists #smtp #spam (and of course seeing that for a brief time, the number of #spamtraps collected for #greytrapping was a palindromic number, nxdomain.no/~peter/traplist.sh)

  41. A post in my linkedin feed reminded me that when I first wrote about #wankstortion (aka #sextortion) spam back in 2019, it was a well-known and well-explored problem and we had quickly concluded that the only thing those jokers had was a list of mail addresses. And of course that list had a goodly chunk of my #spamtraps in it.

    For some reason, these campaigns keep turning up. My 2022 piece nxdomain.no/~peter/despicable_ (or with trackers bsdly.blogspot.com/2022/12/the) has links to the older story too.

  42. A post in my linkedin feed reminded me that when I first wrote about #wankstortion (aka #sextortion) spam back in 2019, it was a well-known and well-explored problem and we had quickly concluded that the only thing those jokers had was a list of mail addresses. And of course that list had a goodly chunk of my #spamtraps in it.

    For some reason, these campaigns keep turning up. My 2022 piece nxdomain.no/~peter/despicable_ (or with trackers bsdly.blogspot.com/2022/12/the) has links to the older story too.