Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

MXroute Black Friday Deals - Bring Your Own Domain Email Service!

191012141519

Comments

  • jarjar Patron Provider, Top Host, Veteran

    Let me tell you a story of why you want to be on the front lines with MXroute.

    So there's this phishing campaign (I'm using phishing loosely here, just go with it) going around that actually uses PayPal to make money requests, and for some reason they use Office 365 accounts (stolen or disposable, could be both) and set up forwarders to you, then send themselves a PayPal request that gets forwarded to you. No idea why they do it this way, like people are going to block PayPal but not O365? Anyway, not as important.

    Blocking these has been difficult because one can neither block legitimate PayPal emails, nor can one block email forwarders from Office 365. However, we were able to block these without any consequences, without hitting any desirable email. After doing that, I discovered what appeared (to me) to be the person managing these phishing attacks on our platform, using us as kind of a base of operations for these. Upon kindly asking the user to explain, telling them what it looked an awful lot like to me, their response was one that heavily implied they knew they were about to be terminated and really didn't care what I thought about it. So, of course, user terminated.

    After that, some interesting things happened:

    1. A user uploaded child porn to files.freesocial.co (no longer active) and reported it to Hetzner.
    2. The phishing campaign changed techniques, started breaking through again.

    So I deployed a new rule that totally blocked the new campaign, once again with no casualties other than that which was intended. Minutes later, someone ramped up a spam registration/password reset campaign to DDOS my inbox. I mentioned casually in our Discord that this was pretty funny, something I deal with often, and that I have a script which just handles it for me in the background so I really don't care. Minutes later, far earlier than any of these attacks ever had before, the inbound email flood halted. Shortly after that, the PayPal phishing campaigns stopped hitting our servers.

    Now we're not the only ones noticing the PayPal/O365 phishing thing, not by a long shot. But from where I sit it looks to me like the threat actor involved with it takes great interest in MXroute and her customers.

    So why would that interest you? Because MXroute is on the front lines of pissing off the people who are trying to ruin email every day. It's us vs them, and they don't like that we're getting better at it every day. I'm not asking you to buy me a new house, I don't want to be rich. I just want all of us together as an unstoppable force against the worst of the internet. Join me?

  • kevindskevinds Member, LIR
    edited December 2024

    @jar said:
    Let me tell you a story of why you want to be on the front lines with MXroute.

    Sometimes I really wonder why some people do many of the things they do....

    Does sound like they are/were watching your Discord channels though. ;)

    Thanked by 1jar
  • @jar said:

    I just want all of us together as an unstoppable force against the worst of the internet. Join me?

    Hard to resist a pleading like that...

    Thanked by 1jar
  • kevindskevinds Member, LIR

    This isn't worth opening a ticket for.. But how does a user 'report spam'?

    Is there an address to forward the spam, attachments, and headers to?

    We would like the "flame thrower engaged" more often than it is..

    Thanked by 1jar
  • jarjar Patron Provider, Top Host, Veteran

    @kevinds said:
    This isn't worth opening a ticket for.. But how does a user 'report spam'?

    Is there an address to forward the spam, attachments, and headers to?

    We would like the "flame thrower engaged" more often than it is..

    There’s not a way. All open source learning algorithms I’ve declared incompatible with current trends, and I spend so much time gathering spam from logs that I usually don’t require individual reports. But if there’s a strong trend you see that you feel like I’m overlooking, which can and does happen, a ticket with enough information to just point me at it like you’re throwing a steak at a dog will work. Casual mentions in Discord about spam trends I’m missing also get me riled up.

  • kevindskevinds Member, LIR
    edited December 2024

    @jar said:
    But if there’s a strong trend you see that you feel like I’m overlooking, which can and does happen, a ticket with enough information to just point me at it like you’re throwing a steak at a dog will work. Casual mentions in Discord about spam trends I’m missing also get me riled up.

    Alright, wasn't sure if a spam report ticket would make it to you.

    Begrudgingly, I'll join Discord when needed.

    Thank you.

    Thanked by 1jar
  • jarjar Patron Provider, Top Host, Veteran

    Don’t expect that I’d restock some of the Small plans and they’d still be stocked, but here’s a reminder to anyone who was asking me for it.

    Thanked by 1Riz
  • jar is email B)

    Thanked by 1jar
  • @jar said:
    Don’t expect that I’d restock some of the Small plans and they’d still be stocked, but here’s a reminder to anyone who was asking me for it.

    i bought the medium plan while the small plan oos.

    but then you restock the small plan lol. :D

    Thanked by 1jar
  • @jar said:
    Let me tell you a story of why you want to be on the front lines with MXroute.

    So there's this phishing campaign (I'm using phishing loosely here, just go with it) going around that actually uses PayPal to make money requests, and for some reason they use Office 365 accounts (stolen or disposable, could be both) and set up forwarders to you, then send themselves a PayPal request that gets forwarded to you. No idea why they do it this way, like people are going to block PayPal but not O365? Anyway, not as important.

    Blocking these has been difficult because one can neither block legitimate PayPal emails, nor can one block email forwarders from Office 365. However, we were able to block these without any consequences, without hitting any desirable email. After doing that, I discovered what appeared (to me) to be the person managing these phishing attacks on our platform, using us as kind of a base of operations for these. Upon kindly asking the user to explain, telling them what it looked an awful lot like to me, their response was one that heavily implied they knew they were about to be terminated and really didn't care what I thought about it. So, of course, user terminated.

    After that, some interesting things happened:

    1. A user uploaded child porn to files.freesocial.co (no longer active) and reported it to Hetzner.
    2. The phishing campaign changed techniques, started breaking through again.

    So I deployed a new rule that totally blocked the new campaign, once again with no casualties other than that which was intended. Minutes later, someone ramped up a spam registration/password reset campaign to DDOS my inbox. I mentioned casually in our Discord that this was pretty funny, something I deal with often, and that I have a script which just handles it for me in the background so I really don't care. Minutes later, far earlier than any of these attacks ever had before, the inbound email flood halted. Shortly after that, the PayPal phishing campaigns stopped hitting our servers.

    Now we're not the only ones noticing the PayPal/O365 phishing thing, not by a long shot. But from where I sit it looks to me like the threat actor involved with it takes great interest in MXroute and her customers.

    So why would that interest you? Because MXroute is on the front lines of pissing off the people who are trying to ruin email every day. It's us vs them, and they don't like that we're getting better at it every day. I'm not asking you to buy me a new house, I don't want to be rich. I just want all of us together as an unstoppable force against the worst of the internet. Join me?

    Name and shame. They're committing crimes, they receive no protection.

    Thanked by 1jar
  • jarjar Patron Provider, Top Host, Veteran

    @TimboJones said:

    @jar said:
    Let me tell you a story of why you want to be on the front lines with MXroute.

    So there's this phishing campaign (I'm using phishing loosely here, just go with it) going around that actually uses PayPal to make money requests, and for some reason they use Office 365 accounts (stolen or disposable, could be both) and set up forwarders to you, then send themselves a PayPal request that gets forwarded to you. No idea why they do it this way, like people are going to block PayPal but not O365? Anyway, not as important.

    Blocking these has been difficult because one can neither block legitimate PayPal emails, nor can one block email forwarders from Office 365. However, we were able to block these without any consequences, without hitting any desirable email. After doing that, I discovered what appeared (to me) to be the person managing these phishing attacks on our platform, using us as kind of a base of operations for these. Upon kindly asking the user to explain, telling them what it looked an awful lot like to me, their response was one that heavily implied they knew they were about to be terminated and really didn't care what I thought about it. So, of course, user terminated.

    After that, some interesting things happened:

    1. A user uploaded child porn to files.freesocial.co (no longer active) and reported it to Hetzner.
    2. The phishing campaign changed techniques, started breaking through again.

    So I deployed a new rule that totally blocked the new campaign, once again with no casualties other than that which was intended. Minutes later, someone ramped up a spam registration/password reset campaign to DDOS my inbox. I mentioned casually in our Discord that this was pretty funny, something I deal with often, and that I have a script which just handles it for me in the background so I really don't care. Minutes later, far earlier than any of these attacks ever had before, the inbound email flood halted. Shortly after that, the PayPal phishing campaigns stopped hitting our servers.

    Now we're not the only ones noticing the PayPal/O365 phishing thing, not by a long shot. But from where I sit it looks to me like the threat actor involved with it takes great interest in MXroute and her customers.

    So why would that interest you? Because MXroute is on the front lines of pissing off the people who are trying to ruin email every day. It's us vs them, and they don't like that we're getting better at it every day. I'm not asking you to buy me a new house, I don't want to be rich. I just want all of us together as an unstoppable force against the worst of the internet. Join me?

    Name and shame. They're committing crimes, they receive no protection.

    I wish but I’m positive it was just a convincing fake identity that they don’t appear to use elsewhere.

  • This is why Jar is the best <3

    Thanked by 2jar exe
  • @jar said:
    Let me tell you a story of why you want to be on the front lines with MXroute.

    So there's this phishing campaign (I'm using phishing loosely here, just go with it) going around that actually uses PayPal to make money requests, and for some reason they use Office 365 accounts (stolen or disposable, could be both) and set up forwarders to you, then send themselves a PayPal request that gets forwarded to you. No idea why they do it this way, like people are going to block PayPal but not O365? Anyway, not as important.

    Blocking these has been difficult because one can neither block legitimate PayPal emails, nor can one block email forwarders from Office 365. However, we were able to block these without any consequences, without hitting any desirable email. After doing that, I discovered what appeared (to me) to be the person managing these phishing attacks on our platform, using us as kind of a base of operations for these. Upon kindly asking the user to explain, telling them what it looked an awful lot like to me, their response was one that heavily implied they knew they were about to be terminated and really didn't care what I thought about it. So, of course, user terminated.

    After that, some interesting things happened:

    1. A user uploaded child porn to files.freesocial.co (no longer active) and reported it to Hetzner.
    2. The phishing campaign changed techniques, started breaking through again.

    So I deployed a new rule that totally blocked the new campaign, once again with no casualties other than that which was intended. Minutes later, someone ramped up a spam registration/password reset campaign to DDOS my inbox. I mentioned casually in our Discord that this was pretty funny, something I deal with often, and that I have a script which just handles it for me in the background so I really don't care. Minutes later, far earlier than any of these attacks ever had before, the inbound email flood halted. Shortly after that, the PayPal phishing campaigns stopped hitting our servers.

    Now we're not the only ones noticing the PayPal/O365 phishing thing, not by a long shot. But from where I sit it looks to me like the threat actor involved with it takes great interest in MXroute and her customers.

    So why would that interest you? Because MXroute is on the front lines of pissing off the people who are trying to ruin email every day. It's us vs them, and they don't like that we're getting better at it every day. I'm not asking you to buy me a new house, I don't want to be rich. I just want all of us together as an unstoppable force against the worst of the internet. Join me?

    That's why I love MXRoute.

    Thanked by 1jar
  • Why sending email take a really long time that it affects the load time of my websites?

  • brueggusbrueggus Member, IPv6 Advocate

    @didtav said:
    Why sending email take a really long time that it affects the load time of my websites?

    Because you don't send emails asynchronously.

  • jarjar Patron Provider, Top Host, Veteran
    edited December 2024

    @didtav said:
    Why sending email take a really long time that it affects the load time of my websites?

    That can be a large range of causes. Code overhead, simultaneous database lookups, DNS lookup latency, packet loss, just off the top of my head.

  • kevindskevinds Member, LIR

    @didtav said:
    Why sending email take a really long time that it affects the load time of my websites?

    How does an email being delayed affect the load time of your website??

  • jarjar Patron Provider, Top Host, Veteran

    @kevinds said:

    @didtav said:
    Why sending email take a really long time that it affects the load time of my websites?

    How does an email being delayed affect the load time of your website??

    If it’s execution is a precondition of page load.

    Thanked by 1kevinds
  • @jar said:

    @didtav said:
    Why sending email take a really long time that it affects the load time of my websites?

    That can be a large range of causes. Code overhead, simultaneous database lookups, DNS lookup latency, packet loss, just off the top of my head.

    is ~20s normal?
    I tried using other provider and it loads faster (almost immediately)
    The website is hosted in SG so it could be latency issue,
    or some kind of firewall, maybe? receiving email is fast but sending email is slow.
    sending email using Thunderbird also takes about 20s, so I don't think it's code related issue

    @brueggus said:

    @didtav said:
    Why sending email take a really long time that it affects the load time of my websites?

    Because you don't send emails asynchronously.

    That would makes it faster but the email will be send 5 minutes later

  • jarjar Patron Provider, Top Host, Veteran
    edited December 2024

    @didtav said: is ~20s normal?

    I would say 20 seconds isn't what I consider normal. I could whitelist the IP from any checks and we could test if that reduced it any. Singapore latency like that isn't entirely unexpected, but if you yourself are not in Singapore and Thunderbird is doing the same then it's probably not. Ping me in a ticket and mention that I wanted to test this with you, or hit me up on Discord.

  • These are great deals, thank you @jar!

    Thanked by 1jar
  • jarjar Patron Provider, Top Host, Veteran

    @jar said:
    Just so people visiting the thread don't have to go back a page, and before posting the same thing twice would be inappropriate thread bumping:

    Early Cyber Monday promo VERY LIMITED QUANTITY:

    First, 80% off of our large storage plans with promo code ETTU2024. That brings it to these prices:

    100GB: $20.00/year
    200GB: $30.00/year
    300GB: $40.00/year
    400GB: $50.00/year
    500GB: $60.00/year
    600GB: $70.00/year
    700GB: $80.00/year
    800GB: $90.00/year
    900GB: $100.00/year
    1TB: $110.00/year

    Order: https://accounts.mxroute.com/index.php?/cart/mxroute-large-storage/

    Second, for those who miss that, 70% off our large storage plans with promo code BENEDICT23. That brings them to:

    100GB: $30.00/year
    200GB: $45.00/year
    300GB: $60.00/year
    400GB: $75.00/year
    500GB: $90.00/year
    600GB: $105.00/year
    700GB: $120.00/year
    800GB: $135.00/year (Cut here as the rest exceed the applicable rule agreed upon for offer limits)

    Order: https://accounts.mxroute.com/index.php?/cart/mxroute-large-storage/

    We'll have a more "normal" offering on Cyber Monday itself. Grab these while they're hot, I'm not likely to do this again.

    Still have some of these left if anyone wants them.

  • @jar said:

    @jar said:
    Just so people visiting the thread don't have to go back a page, and before posting the same thing twice would be inappropriate thread bumping:

    Early Cyber Monday promo VERY LIMITED QUANTITY:

    First, 80% off of our large storage plans with promo code ETTU2024. That brings it to these prices:

    100GB: $20.00/year
    200GB: $30.00/year
    300GB: $40.00/year
    400GB: $50.00/year
    500GB: $60.00/year
    600GB: $70.00/year
    700GB: $80.00/year
    800GB: $90.00/year
    900GB: $100.00/year
    1TB: $110.00/year

    Order: https://accounts.mxroute.com/index.php?/cart/mxroute-large-storage/

    Second, for those who miss that, 70% off our large storage plans with promo code BENEDICT23. That brings them to:

    100GB: $30.00/year
    200GB: $45.00/year
    300GB: $60.00/year
    400GB: $75.00/year
    500GB: $90.00/year
    600GB: $105.00/year
    700GB: $120.00/year
    800GB: $135.00/year (Cut here as the rest exceed the applicable rule agreed upon for offer limits)

    Order: https://accounts.mxroute.com/index.php?/cart/mxroute-large-storage/

    We'll have a more "normal" offering on Cyber Monday itself. Grab these while they're hot, I'm not likely to do this again.

    Still have some of these left if anyone wants them.

    That are very nice deals! Keep up the good work!

    Thanked by 1jar
  • jarjar Patron Provider, Top Host, Veteran

    Big day for inbound spam filtering improvements. More good stuff coming!

    Thanked by 2brueggus Wolf
  • brueggusbrueggus Member, IPv6 Advocate

    After idling my MXroute plan for several years, I've finally made the move away from Gmail. I am pretty happy so far.
    It's obvious that Google's spam filtering works differently (I won't say it's better) and I get more spam in my inbox than I got with Google. But I'm optimistic that I can iron that out by tweaking Spamassassin.

    Thanked by 2jar tentor
  • jarjar Patron Provider, Top Host, Veteran

    @brueggus said: I get more spam in my inbox than I got with Google

    Might feel differently as soon as today <3

    Thanked by 1brueggus
  • How would I migrate my old package to this new package ? Migration is manual process, yeah?

  • kevindskevinds Member, LIR
    edited December 2024

    @Liso said: How would I migrate my old package to this new package ? Migration is manual process, yeah?

    DIY transfer the accounts and then transfer the data.

    @brueggus said:
    I get more spam in my inbox than I got with Google. But I'm optimistic that I can iron that out by tweaking Spamassassin.

    I'm seeing the opposite problem, important emails being marked as junk.

  • jarjar Patron Provider, Top Host, Veteran

    @kevinds said:

    @Liso said: How would I migrate my old package to this new package ? Migration is manual process, yeah?

    DIY transfer the accounts and then transfer the data.

    @brueggus said:
    I get more spam in my inbox than I got with Google. But I'm optimistic that I can iron that out by tweaking Spamassassin.

    I'm seeing the opposite problem, important emails being marked as junk.

    What SA score are you running with? I tune for 15.

This discussion has been closed.