<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>TV Science Associates.</title>
    <link rel="alternate" type="text/html" href="http://www.tvscience.uk/" />
    <link rel="self" type="application/atom+xml" href="http://www.tvscience.uk/atom.xml" />
    <id>tag:www.tvscience.uk,2013-05-19://3</id>
    <updated>2017-12-20T11:55:34Z</updated>
    <subtitle>tvScience Hosting - Specialist hosting Provider.</subtitle>
    <generator uri="http://www.sixapart.com/movabletype/">Movable Type 5.2.13</generator>

<entry>
    <title>550 Empty envelope senders not allowed - The tvScience Blog</title>
    <link rel="alternate" type="text/html" href="http://www.www.tvscience.uk/blog/2017/12/550-empty-envelope-senders-not-allowed.html" />
    <id>tag:www.tvscience.uk,2017:/blog//4.106</id>

    <published>2017-12-19T10:15:04Z</published>
    <updated>2017-12-20T11:55:34Z</updated>

    <summary><![CDATA[The refusal by an ISP to accept a bounce message (one with an empty envelope sender) is increasingly rare these days, but occasionally we do see it. This is always a bad idea: H=mx01.csx1.net [38.103.192.105] &hellip; SMTP error from remote...]]></summary>
    <author>
        <name>The Postmaster</name>
        
    </author>
    
        <category term="Incoming E-mail" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="arseelbow" label="arse &amp; elbow" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://www.www.tvscience.uk/blog/">
        <![CDATA[<p>The refusal by an
<abbr title="Internet Service Provider">ISP</abbr>
to accept a bounce message (one with an empty envelope sender) is increasingly rare these days, but occasionally we do see it.
<p>This is always a bad idea:
<blockquote>
<kbd>
H=mx01.csx1.net [38.103.192.105] &hellip; SMTP error from remote mail server after pipelined DATA: 550 Empty envelope senders not allowed
</kbd>
</blockquote>
<p>The sender of the message (<em>their</em> client remember) will never
find out that the email has not been delivered. In this case the mail was being forwarded, so it&apos;s impossible for us to do any better than accept the mail and then test the
recipient address by trying a delivery. We had to delete the bounce message &mdash; there was nowhere to send it.
]]>
        <![CDATA[<p>Bounce messages are sent with an empty envelope sender to eliminate mail loops.
For more information see:
<a href=https://tools.ietf.org/html/rfc5321#section-4.5.5>RFC 5321</a>.
<p>Did I mention that we would <em>never</em> contemplate such a foolish policy?]]>
    </content>
</entry>

<entry>
    <title>This is NOT How You Use a Spamhaus Blocklist - The tvScience Blog</title>
    <link rel="alternate" type="text/html" href="http://www.www.tvscience.uk/blog/2017/07/this-is-not-how-you-use-a-spamhaus-blocklist.html" />
    <id>tag:www.tvscience.uk,2017:/blog//4.105</id>

    <published>2017-07-12T10:32:44Z</published>
    <updated>2017-07-12T14:50:24Z</updated>

    <summary><![CDATA[TFL are rejecting authenticated mail relayed through our servers due to one of the SMTP Received: headers containing an IP address listed at Spamhaus. In this case, it&apos;s the mistaken &amp; inadvertent use of the Spamhaus PBL where the error...]]></summary>
    <author>
        <name>The Postmaster</name>
        
    </author>
    
        <category term="Outgoing E-mail" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="arseelbow" label="arse &amp; elbow" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="spamhaus" label="Spamhaus" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://www.www.tvscience.uk/blog/">
        <![CDATA[<p><a  href=https://tfl.gov.uk/><abbr title="Transport for London">TFL</abbr></a>
are rejecting authenticated mail <em>relayed through our servers</em>
due to one of the SMTP <b>Received:</b> headers containing an IP address listed at
<a  href=https://www.spamhaus.org/>Spamhaus</a>.
<p>In this case, it&apos;s the mistaken &amp; inadvertent use of the
<a  href=https://www.spamhaus.org/pbl/>Spamhaus PBL</a> where the error lies. 
A majority of e-mail sent from a home broadband connection will contain an IP listed in the PBL.
TFL (or is it
<a  href=https://www.capita.com/>Capita</a>?)
are wrongly using the 
<a  href=https://www.spamhaus.org/zen/>Spamhaus ZEN</a>
blocklist which is an aggregate of <em>all</em> the lists maintained by Spamhaus. This includes the PBL.
<style>
strong.a { color:green }
</style>
<p> Here's the rejection message:
<blockquote><pre>
  REDACTED@tflcc.co.uk
    host smtp.tflcc.co.uk [80.82.130.162]
    SMTP error from remote mail server after end of data:
    550 5.7.1 <strong class=a>92.40.249.10</strong> listed at zen.spamhaus.org
</pre></blockquote>
The IP address TFL take an exception to is [<strong class=a>92.40.249.10</strong>] which is indeed listed in the PBL. The crucial thing is that this IP
has not connected to TFL&apos;s servers at all. Instead it has been plucked from the trace headers included in the message.]]>
        <![CDATA[<p>Here are the SMTP <b>Received:</b> headers from the outgoing message rejected by TFL:
<blockquote><SAMP><pre>
Received: from [<strong class=a>92.40.249.10</strong>] (helo=dsklinux.lan)
	by smtp2.tvscience.co.uk with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
	(Exim 4.89)
	(envelope-from &lt;REDACTED@tv-science.co.uk&gt;)
	id 1dVEdi-0004i8-Wd
	for REDACTED@tflcc.co.uk; Wed, 12 Jul 2017 10:13:02 +0000
Received: from localhost ([127.0.0.1]:59230 helo=dsklinux.lan)
	by dsklinux.lan with esmtp (Exim 4.88)
	(envelope-from &lt;REDACTED@tv-science.co.uk&gt;)
	id 1dVEdh-0004QW-Bd
	for REDACTED@tflcc.co.uk; Wed, 12 Jul 2017 11:13:01 +0100
</pre></SAMP></blockquote>

<p>The IP of our SMTP relay server smtp2.tvscience.co.uk is [185.208.170.37] &mdash;
not listed in 
<em>any</em>
blocklist.

<p>Mail administrators from TFL/Capita would do well to read and inwardly digest
<a  title="What zone should my server or spam filter query?" href=https://www.spamhaus.org/faq/section/Spamhaus%2520PBL#185>this Spamhaus <abbr title="Frequently asked questions">FAQ</abbr> entry</a>;
noting particularly the <i>"&#x26a0;WARNING!"</i> section.

<p>For information on the <em>correct</em> and <em>appropriate</em> use of Spamhaus&apos;s blocklists see
<a  href=https://www.spamhaus.org/faq/>this
<abbr title="Frequently asked questions">FAQ</abbr></a>.

<p>For more information on SMTP trace headers, including the <b>Received:</b> header see:
<a  href=https://tools.ietf.org/html/rfc2822#section-3.6.7>RFC 2822</a>.]]>
    </content>
</entry>

<entry>
    <title>POP3 SSL Access in Beta Test - The tvScience Blog</title>
    <link rel="alternate" type="text/html" href="http://www.www.tvscience.uk/blog/2015/12/pop3-ssl-access-in-beta-test.html" />
    <id>tag:www.tvscience.uk,2015:/blog//4.94</id>

    <published>2015-12-08T11:36:04Z</published>
    <updated>2015-12-08T12:15:48Z</updated>

    <summary><![CDATA[All our POP3 servers now support access via encrypted connections for e&hyphen;mail retrieval. Your secure connection can use port 995 for SSL access or stick with port 110 and enable STARTTLS. You will need to accept the SSL certificate presented...]]></summary>
    <author>
        <name>The Postmaster</name>
        
    </author>
    
    
    <content type="html" xml:lang="en-us" xml:base="http://www.www.tvscience.uk/blog/">
        <![CDATA[<P>All our
<abbr title="Post Office Protocol">POP</abbr>3
servers now support access via encrypted connections for e&hyphen;mail retrieval.
<P>Your secure connection can use port 995 for
<abbr title="Secure Sockets Layer">SSL</abbr>
access or stick with port 110 and enable START<abbr title="Transport Layer Security">TLS</abbr>.
<p>You will need to accept the SSL certificate presented in order to proceed with your first e&hyphen;mail check.
Use the "Accept all certificates" option where available.]]>
        <![CDATA[<p><strong>Remember</strong>,
this does not make your e-mails much more secure at all. Just your username and password now become fully protected from snooping.
Only an end&hyphen;to&hyphen;end encryption scheme such as
<abbr title="Pretty Good Privacy"><a  href="https://en.wikipedia.org/wiki/Pretty_Good_Privacy">PGP</a></abbr>
or
<abbr title="GNU Privacy Guard"><a  href="https://en.wikipedia.org/wiki/GNU_Privacy_Guard">GPG</a></abbr>
can
<em>guarantee</em>
e&hyphen;mail security.
]]>
    </content>
</entry>

<entry>
    <title>Byte Quotas for SMTP (e-mail) Posting Increased Again!  - The tvScience Blog</title>
    <link rel="alternate" type="text/html" href="http://www.www.tvscience.uk/blog/2015/11/smtp-e-mail-posting.html" />
    <id>tag:www.tvscience.uk,2015:/blog//4.93</id>

    <published>2015-11-30T11:33:10Z</published>
    <updated>2015-11-30T11:45:36Z</updated>

    <summary>We have just doubled the byte quota for our base SMTP (e-mail) posting package. You now get 350 recipients/128MiB per month for a measly GBP20+VAT per year....</summary>
    <author>
        <name>The Hostmaster</name>
        
    </author>
    
        <category term="Outgoing E-mail" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en-us" xml:base="http://www.www.tvscience.uk/blog/">
        <![CDATA[<p>We have just
<em>doubled</em>
the byte quota for our base
<abbr title="Simple mail transfer protocol">SMTP</abbr>
(e-mail) posting package.
<p>You now get 350 recipients/128<abbr title="Mebibytes">MiB</abbr> per month for a measly GBP20+VAT per year.
]]>
        <![CDATA[<P>Any unused quota, both bytes
<em>and</em>
recipients, roll over for a second month.
<p>Optionally we offer
<abbr title="Domain keys identified mail"><a  href="http://www.dkim.org/">DKIM</a></abbr>
signing at no extra cost.]]>
    </content>
</entry>

<entry>
    <title>Remember - No Mail from Dynamic IP Addresses - The tvScience Blog</title>
    <link rel="alternate" type="text/html" href="http://www.www.tvscience.uk/blog/2015/07/remember-no-mail-from-dynamic-ip-addresses.html" />
    <id>tag:www.tvscience.uk,2015:/blog//4.88</id>

    <published>2015-07-25T08:54:49Z</published>
    <updated>2015-10-14T11:18:10Z</updated>

    <summary><![CDATA[E&hyphen;mail from dynamic IP addresses has long been refused by the wise postmaster, including ourselves. The reason is that both whitelisting &amp; blacklisting are ineffective in this case &mdash; two tools that are essential for the world&apos;s mail administrators. Remember...]]></summary>
    <author>
        <name>The Postmaster</name>
        
    </author>
    
        <category term="Incoming E-mail" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en-us" xml:base="http://www.www.tvscience.uk/blog/">
        <![CDATA[<p>E&hyphen;mail from dynamic IP addresses has long been refused by the wise postmaster, including ourselves.
The reason is that both whitelisting &amp; blacklisting are ineffective in this case &mdash;
two tools that are essential for the world&apos;s mail administrators.
<p>Remember also that cloud services use dynamically allocated
<abbr title="Internet Protocol">IP</abbr>
addresses in many cases and are thus also unsuitable for relaying mail for
the same reasons given above. Currently we do not block such computing services from sending mail to our servers;
they <em>are</em> regarded with additional suspicion by our filters however.]]>
        
    </content>
</entry>

<entry>
    <title>Upgrade Your Movable Type Installation - The tvScience Blog</title>
    <link rel="alternate" type="text/html" href="http://www.www.tvscience.uk/blog/2015/04/upgrade-your-movable-type-installation-1.html" />
    <id>tag:www.tvscience.uk,2015:/blog//4.86</id>

    <published>2015-04-15T05:50:09Z</published>
    <updated>2015-04-15T05:53:08Z</updated>

    <summary>The latest stable version of Movable Type Open Source is MTOS-5.2.13. You should upgrade your installations....</summary>
    <author>
        <name>The Hostmaster</name>
        
    </author>
    
    
    <content type="html" xml:lang="en-us" xml:base="http://www.www.tvscience.uk/blog/">
        <![CDATA[<p>The latest stable version of
<a 
href="https://movabletype.org/">Movable Type Open Source</a>
is
<a 
href="https://movabletype.org/downloads/stable/MTOS-5.2.13.zip">MTOS-5.2.13</a>. You should upgrade your installations.]]>
        
    </content>
</entry>

<entry>
    <title>Server Outage n6.tvscience.co.uk - The tvScience Blog</title>
    <link rel="alternate" type="text/html" href="http://www.www.tvscience.uk/blog/2015/02/server-outage-n6.html" />
    <id>tag:www.tvscience.uk,2015:/blog//4.84</id>

    <published>2015-02-17T11:39:35Z</published>
    <updated>2015-02-18T17:13:54Z</updated>

    <summary>The server known as n6.tvscience.co.uk is currently down due to a power outage in the datacentre....</summary>
    <author>
        <name>The Hostmaster</name>
        
    </author>
    
        <category term="Incoming E-mail" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="serviceoutage" label="Service Outage" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://www.www.tvscience.uk/blog/">
        <![CDATA[<p>The server known as
<a href="http://n6.tvscience.co.uk/">n6.tvscience.co.uk</a>
is currently down due to a power outage in the datacentre.
]]>
        <![CDATA[Incoming mail is being handled by the backup server and will be delivered to clients once services are restored.
Websites are being handled by the mirror server and are thus unaffected. Outgoing e-mail is also unaffected.
<p>We will publish an update when there is further news.
<p><strong>UPDATE:</strong> The server came back online at 1915UTC and services were reinstated shortly afterwards.]]>
    </content>
</entry>

<entry>
    <title>Upgrade Your Movable Type Installation - The tvScience Blog</title>
    <link rel="alternate" type="text/html" href="http://www.www.tvscience.uk/blog/2015/02/upgrade-your-movable-type-to-5-2-12.html" />
    <id>tag:www.tvscience.uk,2015:/blog//4.82</id>

    <published>2015-02-12T11:51:14Z</published>
    <updated>2015-02-12T11:54:35Z</updated>

    <summary>The latest stable version of Movable Type Open Source is MTOS-5.2.12. You should upgrade your installations....</summary>
    <author>
        <name>Martin</name>
        
    </author>
    
        <category term="Movable Type" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en-us" xml:base="http://www.www.tvscience.uk/blog/">
        <![CDATA[<p>The latest stable version of
<a 
href="https://movabletype.org/">Movable Type Open Source</a>
is
<a 
href="https://movabletype.org/downloads/stable/MTOS-5.2.12.zip">MTOS-5.2.12</a>. You should upgrade your installations.]]>
        
    </content>
</entry>

<entry>
    <title>Upgrade Your Movable Type Installation - The tvScience Blog</title>
    <link rel="alternate" type="text/html" href="http://www.www.tvscience.uk/blog/2015/01/upgrade-your-movable-type-to-5-2-11.html" />
    <id>tag:www.tvscience.uk,2015:/blog//4.79</id>

    <published>2015-01-11T16:37:57Z</published>
    <updated>2015-01-11T16:39:36Z</updated>

    <summary>The latest stable version of Movable Type Open Source is MTOS-5.2.11. You should upgrade your installations....</summary>
    <author>
        <name>Martin</name>
        
    </author>
    
        <category term="Movable Type" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en-us" xml:base="http://www.www.tvscience.uk/blog/">
        <![CDATA[<p>The latest stable version of
<a 
href="http://movabletype.org/">Movable Type Open Source</a>
is
<a 
href="http://www.movabletype.jp/downloads/stable/MTOS-5.2.11.zip">MTOS-5.2.11</a>. You should upgrade your installations.]]>
        
    </content>
</entry>

<entry>
    <title>Malware Now Being Pushed in &quot;.arj&quot; Files - The tvScience Blog</title>
    <link rel="alternate" type="text/html" href="http://www.www.tvscience.uk/blog/2014/09/malware-now-being-pushed-in-arj-files.html" />
    <id>tag:www.tvscience.uk,2014:/blog//4.75</id>

    <published>2014-09-02T14:30:41Z</published>
    <updated>2014-09-02T20:13:09Z</updated>

    <summary>Most file compression formats are ripe for exploitation these days. We&apos;ve seen our first .arj files today: Thank you for using our services! Your order #37311131537 will be shipped on 05-09-2014. Date: September 02, 2014. 03:09pm Price: Â£191.50 Payment method:...</summary>
    <author>
        <name>The Postmaster</name>
        
    </author>
    
        <category term="Incoming E-mail" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="malware" label="malware" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="spam" label="spam" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://www.www.tvscience.uk/blog/">
        <![CDATA[<p>Most file compression formats are ripe for exploitation these days. We've seen our first
<code>.arj</code>
files today:
<blockquote>
<samp>
Thank you for using our services!<br>
Your order #37311131537 will be shipped on 05-09-2014.<br>
<br>
Date: September 02, 2014. 03:09pm<br>
Price: Â£191.50<br>
Payment method: Wire transfer<br>
Transaction number: 0466142997148E<br>
<br>
Please find the detailed information on your purchase in the attached file (sale_2014-09-02_14-20-08_37311131537.arj)<br>
<br>
Best regards,<br>
Sales Department<br>
Evelina Example<br>
+07775 xxx xxx<br>
</samp>
</blockquote>
]]>
        <![CDATA[<p>The payload is a Windows&trade; executable as one might expect.]]>
    </content>
</entry>

<entry>
    <title>Upgrade Your Movable Type Installation - The tvScience Blog</title>
    <link rel="alternate" type="text/html" href="http://www.www.tvscience.uk/blog/2014/08/upgrade-your-movable-type-installation.html" />
    <id>tag:blog.tv-science.co.uk,2014://4.65</id>

    <published>2014-08-21T11:52:00Z</published>
    <updated>2014-09-02T20:42:40Z</updated>

    <summary>The latest stable version of Movable Type Open Source is MTOS-5.2.10. You should upgrade your installations....</summary>
    <author>
        <name>The Postmaster</name>
        
    </author>
    
        <category term="Movable Type" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en-us" xml:base="http://www.www.tvscience.uk/blog/">
        <![CDATA[<p>The latest stable version of
<a 
href="http://movabletype.org/">Movable Type Open Source</a>
is
<a 
href="http://www.movabletype.jp/downloads/stable/MTOS-5.2.10.zip">MTOS-5.2.10</a>. You should upgrade your installations.]]>
        <![CDATA[<p>Note: Version 5.2.9 of
<a 
href="http://movabletype.org/">Movable Type Open Source</a>
closes a
<a 
href="https://movabletype.org/news/2013/11/movable_type_601_529_and_5161_released_to_close_security_vul.html">security vulnerability</a>.]]>
    </content>
</entry>

<entry>
    <title>Outlook Test Messages Not SMTP Compliant - The tvScience Blog</title>
    <link rel="alternate" type="text/html" href="http://www.www.tvscience.uk/blog/2014/03/outlook-test-messages-not-smtp-compliant.html" />
    <id>tag:blog.tv-science.co.uk,2014://4.68</id>

    <published>2014-03-20T12:27:40Z</published>
    <updated>2014-10-15T11:44:28Z</updated>

    <summary><![CDATA[There are versions of MS Outlook out there which don't send messages compliant with SMTP (RFC 5322 - Section-3.6), in as much as the mandatory &ldquo;Date:&rdquo; header is missing. Quite naturally this makes them useless as a method for testing...]]></summary>
    <author>
        <name>The Postmaster</name>
        
    </author>
    
        <category term="Incoming E-mail" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Outgoing E-mail" scheme="http://www.sixapart.com/ns/types#category" />
    
    
    <content type="html" xml:lang="en-us" xml:base="http://www.www.tvscience.uk/blog/">
        <![CDATA[<P>There are versions of 
<a  href="http://office.microsoft.com/en-gb/outlook/"><abbr title="Microsoft&trade;">MS</abbr> Outlook</a>
out there which don't send messages compliant with
<abbr title="Simple Mail Transfer Protocol">SMTP</abbr><br>
(<a  href="http://tools.ietf.org/html/rfc5322#section-3.6">RFC 5322 - Section-3.6</a>),
in as much as the mandatory <em>&ldquo;Date:&rdquo;</em> header is missing.
Quite naturally this makes them useless as a method for testing your SMTP mail system. See
<a 
href="http://answers.microsoft.com/en-us/office/forum/office_2010-outlook/554-message-is-not-rfc-compliantmissing-date/577fc121-8240-40ab-a5fe-136353b5d86b">this discussion</a> for more information.

<p><b>WORKAROUND:</b> If you encounter this when testing SMTP delivery, compose your own test message and send
<em>that</em>
one to yourself.

]]>
        <![CDATA[
<p>Only two headers are compulsory in an SMTP e-mail:
the <em>&ldquo;Date:&rdquo;</em> header &amp;
the <em>&ldquo;From:&rdquo;</em> header.
Our servers refuse messages where either of these two are absent.
The error message returned by our servers is, helpfully we think:
<blockquote><samp>
550-Mandatory header absent,<br>
550 see: http://tools.ietf.org/html/rfc5322#section-3.6
</samp></blockquote>

<p>Note: Some mailservers will return an imcomplete version of the above message &mdash; returning only 
part of it.

<p>All tvScience customers using our SMTP posting accounts will have a <em>&ldquo;Date:&rdquo;</em>
header added automatically should buggy software fail to add one itself.]]>
    </content>
</entry>

<entry>
    <title>Spam to Your PayPal E-mail Address - The tvScience Blog</title>
    <link rel="alternate" type="text/html" href="http://www.www.tvscience.uk/blog/2014/03/paypal-spam.html" />
    <id>tag:blog.tv-science.co.uk,2014://4.67</id>

    <published>2014-03-16T17:00:24Z</published>
    <updated>2014-09-02T20:15:45Z</updated>

    <summary>As PayPal give your name and e-mail address away to its merchants (i.e: they effectively make it public) - we recommend our clients to use a throw-away or time-limited address for paypal accounts. The spam will be sent to your...</summary>
    <author>
        <name>The Postmaster</name>
        
    </author>
    
        <category term="Incoming E-mail" scheme="http://www.sixapart.com/ns/types#category" />
    
        <category term="Outgoing E-mail" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="spam" label="spam" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://www.www.tvscience.uk/blog/">
        <![CDATA[<p>As
<a href="https://www.paypal.com/" >PayPal</a>
give your name and e-mail address away to its merchants
(i.e: they effectively make it public) -
we recommend our clients to use a throw-away or time-limited address for paypal accounts.
The spam will be sent to your address using your full name so:
<blockquote>
<samp>
To: "Anthony Other" &lt;another@example.com&gt;
</samp>
</blockquote>

<p>Currently the spam is promoting a fake goods site with the connivance of an
<abbr title="Internet Service Provider">ISP</abbr>
based in Hong Kong. 
]]>
        <![CDATA[<p>All customers with SMTP posting accounts can request throw-away and time-limited addresses.
A throw-away address is preferable in this case as a time-limited address must be promptly
updated before it expires. An expired address can cause you to be temporarily
locked out of your PayPal account, requiring a telephone call to PayPal customer services.]]>
    </content>
</entry>

<entry>
    <title>Phishing From Microsoft Messaging - The tvScience Blog</title>
    <link rel="alternate" type="text/html" href="http://www.www.tvscience.uk/blog/2014/01/phishing-from-microsoft-messaging.html" />
    <id>tag:blog.tv-science.co.uk,2014://4.64</id>

    <published>2014-01-08T11:57:58Z</published>
    <updated>2017-07-12T11:14:52Z</updated>

    <summary><![CDATA[Here&rsquo;s a phish, sent by: mail14-co9on0066.outbound.messaging.microsoft.com [157.56.211.66] seconds ago: From: Barclays Bank PLC Subject: Important Information From Barclays! You have not used the telephone banking service for some time now and this could lead to a temporary de-activation of your...]]></summary>
    <author>
        <name>Martin</name>
        
    </author>
    
        <category term="Incoming E-mail" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="arseelbow" label="arse &amp; elbow" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="hotmail" label="Hotmail" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="spam" label="spam" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://www.www.tvscience.uk/blog/">
        <![CDATA[<p>Here&rsquo;s a phish, sent by: mail14-co9on0066.outbound.messaging.microsoft.com [157.56.211.66] seconds ago:
<blockquote><samp>
From: Barclays Bank PLC <notice@barclays.com><br>
Subject: Important Information From Barclays!<br>
<br>
You have not used the telephone banking service for some
time now and this could lead to a temporary de-activation
of your access to this service.
In order to ensure your continued usage of the service and
other services such as the internet banking, please follow
the steps below :<br>
Click here to begin<br>
&copy; 2014 Barclays Bank.<br>
All Rights Reserved
</samp></blockquote>
]]>
        <![CDATA[<p>Unlike
<a href="http://blog.tv-science.co.uk/2013/08/gmail-spewing-malware.html">Gmail</a>,
they are happy to accept a report back although this particular mail does not contain an executable payload.

<p>Unfortunately little gets done. Parts of their network,
<a  href="http://www.uceprotect.net/en/rblcheck.php?asn=8075">AS8075</a>
in particular, is currently listed by
<a  href="http://www.uceprotect.net/en/">UCEPROTECT</a> at level 2.
]]>
    </content>
</entry>

<entry>
    <title>Gmail Spewing Malware - The tvScience Blog</title>
    <link rel="alternate" type="text/html" href="http://www.www.tvscience.uk/blog/2013/08/gmail-spewing-malware.html" />
    <id>tag:blog.tv-science.co.uk,2013://4.59</id>

    <published>2013-08-08T07:14:24Z</published>
    <updated>2014-01-16T11:47:57Z</updated>

    <summary>We&apos;ve trapped a couple of mails from gmail containing malware. Malware in the form of an attachment called &quot;Payment.rar&quot;, &quot;document.rar&quot; or &quot;INVOICES.rar&quot;; within that file is a windows &quot;.scr&quot; or &quot;.exe&quot; executable. The text is like this (sic): Dear Sir/MaPlease...</summary>
    <author>
        <name>The Postmaster</name>
        
    </author>
    
        <category term="Incoming E-mail" scheme="http://www.sixapart.com/ns/types#category" />
    
    <category term="arseelbow" label="arse &amp; elbow" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="gmail" label="Gmail" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="malware" label="malware" scheme="http://www.sixapart.com/ns/types#tag" />
    <category term="spam" label="spam" scheme="http://www.sixapart.com/ns/types#tag" />
    
    <content type="html" xml:lang="en-us" xml:base="http://www.www.tvscience.uk/blog/">
        <![CDATA[<p>We've trapped a couple of mails from gmail containing malware. Malware in the form of an attachment called
"Payment.rar", "document.rar" or "INVOICES.rar";
within that file is a windows ".scr" or ".exe" executable.

<p>The text is like this (<em><abbr title="sic erat scriptum">sic</abbr></em>):
<blockquote><samp>
Dear Sir/Ma<br>Please check attachment for the confirmation of the part payment into your account. Thanks for your patient and we sincerely apologize for the delay. Please find swift message for the payment made via attachment and confirm back.<br>
--<br>
Thanks &amp; Regard,<br>
Rohitashwa K. Mishra,<br>
Senior Journalist,<br>
Dainik Bhaskar Group.
</samp></blockquote>

<p>Or perhaps like this, received from
mail-vc0-f194.google.com [209.85.220.194]
on Tue, 29 Oct 2013 06:12:01
(<em><abbr title="sic erat scriptum">sic</abbr></em>):
<blockquote><samp>
Dear sir ,<br>
 Regarding to the previous order i made in your company , the goods shipped<br>
to me are not exactly what i purchased,  the attachments are the slip of<br>
the payment i made and sample of the products i need if you have them give<br>
me feedback and the new account so that i`ll make the next payment as you<br>
told me .<br>
thanks.
</samp></blockquote>
]]>
        <![CDATA[<p>Reporting this to Google's abuse address results in this message:
<blockquote><samp><code><small>
SMTP error from remote mail server after end of data: host aspmx.l.google.com [74.125.136.27]:<br>
552-5.7.0 This message was blocked because its content presents a potential<br>
552-5.7.0 security issue. Please visit http://support.google.com/mail/bin/answe<br>
552-5.7.0 r.py?answer=6590 to review our message content and attachment content<br>
552 5.7.0 guidelines. t9si5817581eeo.35 - gsmtp
</small></code></samp></blockquote>

<p>They're right, there is a potential security issue - pity they don't want to have it reported to them.
Also a pity they don't enforce such guidelines on their own
<del cite="http://www.metafilter.com/95152/Userdriven-discontent#3256046">product</del>
<ins cite="http://www.metafilter.com/95152/Userdriven-discontent#3256046">users</ins>.

<p>tvScience clients are shielded from the risk as all executable attachments from unknown senders are held in quarrantine. We report the message where possible to the sending organisation; in the above case the mails now have to be deleted.

<p>UPDATE: They're still at it as of 2014/01/16.
<p>Onthis occasion text is:
<blockquote><samp>
Hello dear,<br>
I am sorry for getting back to you very late, I was on leave and only<br>
came back to the office today.<br><br>
As a matter of fact, we have evaluated your PI you sent to us previously.<br><br>
kindly see the attached Revised Invoice and check if you can supplier me<br>
the engines, spear spear parts, oils and cooler this January 2014, as we<br>
have many demanding.<br><br>
Hope to hear from you soonest.<br><br>
Mr. Toney Adem (CEO)<br>
Toney Adem Holdings Ltd.
</samp></blockquote>

<p>The file is called "copy1.rar" and was sent by "mail-lb0-f194.google.com" ["209.85.217.194"].
]]>
    </content>
</entry>

</feed>
