Re: Crisis on the Russian Front! Endless Cyrillic Spam...

From: Barry Wainwright (barry_at_mvps.org.INVALID)
Date: 06/30/04


Date: Wed, 30 Jun 2004 15:31:42 +0100

On 30/6/04 12:08 pm, in article
bunnyslippers-6A19FE.07082130062004@news.newsguy.com, "Sammy"
<bunnyslippers@flophouse.edu> wrote:

> In article <BD074A6F.1B452%barry@mvps.org.INVALID>,
> Barry Wainwright <barry@mvps.org.INVALID> wrote:
>
>> On 29/6/04 3:38 pm, in article
>> bunnyslippers-0BD3E6.10380829062004@news.newsguy.com, "Sammy"
>> <bunnyslippers@flophouse.edu> wrote:
>>
>>> I'm still having difficulties here. Perhaps I'm not working the Rules
>>> correctly - it seemed so easy in Apple's Mail program.
>>>
>>> The bulk of what I'm getting comes from seznam.cz . I've made
>>> several different variants of that seznam.cz> , @seznam.cz , and had
>>> the instruction read "If From seznam.cz, change status to junk email".
>>>
>>> Is there anything glaringly obvious that I should be doing?
>>>
>>> Thanks,
>>>
>>> Sammy
>>
>> 1. I presume that reads if 'from' <contains> 'seznam.cz', not if 'from <is>
>> 'seznam.cz'?
>>
>> 2. Post the headers of one of the messages here and we may be able to give
>> you some pointers.
>
>
> Thanks for your patience, Barry.
>
> Here's the header of one of the ceznam emails I got today:
>
> Received: from mail1.panix.com (mail1.panix.com [166.84.1.72])
> by echonyc.com (8.12.11/8.12.11) with ESMTP id i5UAQopn016355
> for <jaze@echonyc.com>; Wed, 30 Jun 2004 06:26:50 -0400 (EDT)
> Received: from 218.191.73.150 (unknown [218.191.73.150])
> by mail1.panix.com (Postfix) with SMTP id 32CDC4872A
> for <jaze@echonyc.com>; Wed, 30 Jun 2004 06:26:46 -0400 (EDT)
> Date: Wed, 30 Jun 2004 10:23:58 +0000
> From: huasheng <jiseong@seznam.cz>
> To: jaze@echonyc.com
> Subject: =?Windows-1251?B?5O7s4Pjt6OUg6+Xq4PDo?=
> MIME-Version: 1.0
> Content-Type: multipart/related;
> boundary="----------B50202D1701B4C18296099906"
> Message-Id: <20040630102646.32CDC4872A@mail1.panix.com>
> Content-Length: 5571
> Status:
>
>
> Any suggestions?
>
> THANKS!

OK, 1 step further...

I see that the subject is encoded in windows-1251, which is either Russian
or Macedonian character set.

I'm not sure there is any way to test the encoding of the subject line - you
could try 'subject contains "windows-1251", but I think that's an outside
chance.

The message itself is labelled as 'multi-part/related', indicating that
there is likely to be an HTML part and an alternative plain text part.
Unfortunately, your headers didn't post the content type header for either
of these parts! They are likely to be 1251 as well, but could, in theory, be
different.

Look at those headers for the encoding set, and then set up a filter to look
for 'any header' contains 'windows-1251' (or whatever the relevant encoding
scheme is).

-- 
Barry Wainwright
Microsoft MVP (see http://mvp.support.microsoft.com for details)
Seen the All-New Entourage Help Pages? - Check them out:
        <http://www.entourage.mvps.org/>


Relevant Pages

  • Re: HTTP Request, character encoding and fsockopen
    ... You could try using HTTP/1.0 or simply leaving off the HTTP version. ... which is the encoding you're seeing. ... send a regular GET header without any specific HTTP headers regarding ... alphanumeric characters, ...
    (comp.lang.php)
  • Re: Corrupted Subject and From header in Amazon.co.uk mail
    ... It looks as if they're encoding the subject text (or rather, ... only US-ASCII characters and so there was no need to encode it. ... and I wasn't aware that headers like Subject and From ... you and I can't exactly see how to achieve a security compromise, ...
    (comp.mail.pine)
  • Re: The word "rasismi" in Finnish (was Re: unnatural languages)
    ... as the default encoding for this ng, but perhaps that was a mistake. ... everyone using UTF-8 has an appropriate line in their headers, ... explicit encoding header line if I am in a default mode. ... usually change the View/Encoding to Unicode ...
    (sci.lang)
  • Re: problems with messages FROM GroupWise users
    ... The issue is in the encoding, not the decoding (Groupwise) ... with all the internet headers in the body of the message and the ... My users are running Outlook 2003, and we have Exchange 2003. ... patch breaking some of the base64 encoding on the Exchange side. ...
    (microsoft.public.outlook)
  • Re: [Gravity] Send 8 bit chars doesnt work *anymore*
    ... Sending posts is not critical since I don't use any specific ... Sending (encoding) and reading are two different things. ... Reading should be based on the headers of the post you are reading, ... If there are no headers I assume gravity maps the characters to the ...
    (news.software.readers)