spam from jabber jabservice@jabbim.com jabservise@xmpp.jp quickcoin@linuxlovers.at quick_coin@exploit.im quick_coin19@jabber.sk Prof: https://telegra.ph/Flud-servis-04-10
Ge0rG
jabbim admins won't delete spammer accounts.
404.city
Ge0rG, This is likely to be sufficient equipment to include jabbim .com in the ban list
Ge0rG
404.city: step 2: escalate to ISP
Ge0rG
-ETIME
Ge0rG
Alright, yax.im is going down for a short maintenance. BRB
mightyBroccoli
404.city: the blacklist Readme gives a nice overview of the overall workflow of this group.
Bakuninhas left
Bakuninhas joined
Ge0rGhas left
Ge0rGhas joined
guyhas joined
guyhas left
guyhas joined
guyhas left
guyhas joined
jayteeukhas left
jayteeukhas joined
raspbeguyhas left
raspbeguyhas joined
guyhas left
guyhas joined
jayteeukhas left
jayteeukhas joined
guyhas left
guyhas joined
guyhas left
guyhas joined
Licaon_Kterhas left
perflysthas joined
perflysthas left
guyhas left
404.city
The worst thing is that blocking such servers causes negative feedback from users. At the same time, these same servers sell contact databases to spammers.
When adding a contact from a similar server, a person automatically enters the spam mailing list. Then people wonder how spammers know their XMPP ID.
raspbeguyhas left
raspbeguyhas joined
Martinhas left
Bakuninhas left
Bakuninhas joined
Martinhas joined
404.cityhas left
Licaon_Kterhas joined
raspbeguyhas left
raspbeguyhas joined
paulhas left
paulhas joined
Martin
Do you have proof that those servers collect addresses and are not just abused from spammers for their dirty work?
Martin
Actually I only get spam to not existing jids. I don't know why, but I still report them as they might also have real users from other servers in their list.
raspbeguyhas left
raspbeguyhas joined
paulhas left
paulhas joined
raspbeguyhas left
raspbeguyhas joined
raspbeguyhas left
raspbeguyhas joined
404.cityhas joined
paulhas left
paulhas joined
404.cityhas left
Bakuninhas left
jayteeukhas left
jayteeukhas joined
Bakuninhas joined
raspbeguyhas left
raspbeguyhas joined
paulhas left
paulhas joined
paulhas left
paulhas joined
paulhas left
paulhas joined
jayteeukhas left
jayteeukhas joined
jayteeukhas left
jayteeukhas joined
Jonnyhas left
jayteeukhas left
jayteeukhas joined
Ge0rG
404.city [10:52]:
> At the same time, these same servers sell contact databases to spammers.
This is a very strong accusation. I hope you have proof of that.
Martinhas left
Martinhas joined
Jonnyhas joined
sonnyhas left
sonnyhas joined
404.cityhas joined
Bakuninhas left
Bakuninhas joined
404.city
Ge0rG, Spammers wrote to me. They offered money to protect a spam account. They also offered money for the XMPP IDs contact database. They also offered spam protection. They said that they would not send spam to 404.city and from 404.city in exchange for protecting the spammer's account. I declined the offer of spammers, but some servers may be bribed by spammers.
Ge0rG
404.city: that's very interesting indeed. It puts a response I've received recently into a new light. Do you know of servers that accepted the deal?
404.city
Ge0rG, >This is a very strong accusation. I hope you have proof of that.
I have no evidence of this, but if the server protects spammers, the spammer probably bribed the owner of the server.
Ge0rG
Also what's the value in your user database if they promise not to spam you?
anhas joined
MattJ
Sell it to other spammers who will spam you :P
pep.
:D
paulhas left
paulhas joined
paulhas left
paulhas joined
404.city
>Also what's the value in your user database if they promise not to spam you?
In the router, the contacts of other servers. They buy contacts of interlocutors. This explains why XMPP IDs that are not publicly placed get into the spam database.
ibikkhas left
pep.
Wat
pep.
And you buy into this?
404.city
>Sell it to other spammers who will spam you :P
Spammers conflict with each other spamers. There is information that they order flood attacks against competing spammers.
ibikkhas joined
404.city
> pep.: And you buy into this?
I refused to sell the any database to these spammers.
pep.
k
pep.
("Buy into" here was meant as "believe", not literally buying)
404.city
I will explain the structure of the work of spammers.
404.city
The spammers are located in Russia. This makes it impossible for them to be arrested by European intelligence services.
404.city
I think the intelligence services already have enough information about them.
Ge0rG
What if we write a bot that registers random account names at different IBR servers and tracks incoming spam.
jayteeukhas left
jayteeukhas joined
Holger
'honeybot'
Ge0rG
Holger: awesome name
Ge0rG
Holger: do it!
pep.
The distribution of spam is not the same among accounts
pep.
Even on the same server
sonnyhas left
anhas left
anhas joined
paulhas left
paulhas joined
anhas left
anhas joined
jayteeukhas left
jayteeukhas joined
Martin
> 'honeybot'
🥰
Bakuninhas left
Bakuninhas joined
sonnyhas joined
jayteeukhas left
jayteeukhas joined
Chobbeshas joined
Licaon_Kter
> I think the intelligence services already have enough information about them.
Since when is SPAM a matter for "intelligence agencies" pffft ?
Ge0rG
Licaon_Kter: they infiltrate the spammers to obtain lists of jabber users, to be used as input for the enemy of the state blacklists
Chobbeshas left
Chobbeshas joined
Licaon_Kter
Ge0rG: cool story bro
Ge0rG
jonas’: how many outgoing c2s connections can aioxmpp handle?
jonas’
Ge0rG, it depends
jonas’
there is no technical limit
jonas’
the only limit will be your resources
Ge0rG
jonas’: how hard would it be to hack something together that does IBR on a list of servers and stays logged in with a non-negative presence?
Martinhas left
Martinhas joined
jayteeukhas left
jayteeukhas joined
Jonnyhas left
Chobbeshas left
Chobbeshas joined
Jonnyhas joined
Licaon_Kter
Ge0rG: that sounds like what a spammer would love, bypass captcha too? :))
Ge0rG
Licaon_Kter: you'd be surprised how many servers offer IBR with no captcha
Jonnyhas left
Licaon_Kter
Ge0rG: user friendly for clients that can't, eg. CS
Ge0rG
There also used to be a promo video of a spam software showing off their parallel-connection tool
Ge0rG
Licaon_Kter: IBR captchas have been circumvented in the past