Hi all,
recently, I have been getting trouble posting replies, because my IP address is blocked by spamhaus. Funnily enough just retrying a few times has so far worked every time. They do list an IPv4 address as being blocked, and I wonder if sending on IPv6 (which my ISP thankfully also carries) remedies it.
Anyway, this is clearly a false positive. Can anyone do anything about it?
Ciao,
Markus
Spamhaus blocks me sometimes
Spamhaus blocks me sometimes
Carpe diem!
Re: Spamhaus blocks me sometimes
If you are talking about posts here, it appears that you already access the site via an IPv6 address. The only people who can get Spamhaus blocks removed are the owners of the IP address or domain being blocked; ordinary mortals like you or I can't do it.
Blocks can be applied to whole domains, or IP ranges if a significant amount of spam is being sent from addresses in those ranges, not just a particular address. Unfortunately, the facts of life are that many domains in Eastern European countries, and Russia are used for spam (I don't know if this covers your situation). You can only contact your ISP to see if they can do anything. I'm assuming that you are not using a VPN - addresses associated with VPNs are often covered by the various blacklists. It's rare for Spamhaus to generate false positives within the parameters listed. If your address is in a banned block I appreciate that it's a false positive to you but Spamhaus is just, normally accurately, saying that because of general misuse you can't trust any address in this whole range of addresses.
I guess this site must use Spamhaus to filter out potential spammers. I'm more used to using it on mail servers, but I'm a long time out of active participation in the industry.
Blocks can be applied to whole domains, or IP ranges if a significant amount of spam is being sent from addresses in those ranges, not just a particular address. Unfortunately, the facts of life are that many domains in Eastern European countries, and Russia are used for spam (I don't know if this covers your situation). You can only contact your ISP to see if they can do anything. I'm assuming that you are not using a VPN - addresses associated with VPNs are often covered by the various blacklists. It's rare for Spamhaus to generate false positives within the parameters listed. If your address is in a banned block I appreciate that it's a false positive to you but Spamhaus is just, normally accurately, saying that because of general misuse you can't trust any address in this whole range of addresses.
I guess this site must use Spamhaus to filter out potential spammers. I'm more used to using it on mail servers, but I'm a long time out of active participation in the industry.
Re: Spamhaus blocks me sometimes
I am only now realizing that I never specified that, and somebody who never got a Spamhaus block message wouldn't know it. But yes, I am talking about replies on this site. Just before sending this OP, I had some trouble replying to the other topic I was in.
Dual stack, as I said. Which one gets used is up to the whims of Firefox, or more likely, whatever address getaddrinfo() returns first.
IP based geolocation services reliably place me in my native Germany. An IPv4 based one was uncomfortably close to home, but an IPv6 based one placed me in Gaildorf, which is an hour's train ride away. Mind you, I do not own the IPv4 address, and it is conceivable a company as big as Vodafone (my ISP) had a bad actor in their network.
In the age of DHCP, address based block lists are only as up to date as the address assignments.
I just got the message again, and it contains a link to more info. It seems someone using the IP address a couple of hours ago was infected with a spam-sending worm.
Carpe diem!
Re: Spamhaus blocks me sometimes
Interesting. All of your entries in the moderator log seem to show an IPv6 address.
That’s why Spamhaus will lock ranges of addresses - they know there are sufficient bad actors in the range, enough to justify a block, but can’t rely on the addresses in that range staying the same. Spammers will use DHCP to try to avoid being blocked.In the age of DHCP, address based block lists are only as up to date as the address assignments.
Re: Spamhaus blocks me sometimes
I just got blocked for most of 2 weeks. Here's what I found out, and what apparently resolved it.
Spamhaus maintain multiple blacklists. The PBL blanket-covers domestic ISPs with exceptions by request. Any address on the PBL found to be making outgoing connections on port 25 (SMTP) gets put on the XBL -- the eXploits BlockList. There's no reason for domestic machines to be sending mail on port 25, they normally make a secure connection to their mail server. (Port 587 or 465.) The XBL blacklists individual IP addresses for a year. It's possible to contact Spamhaus to be removed from it.
This forum blocks posting from any IP address on the XBL, but Spamhaus's explanation of the XBL mentions only email, and only on port 25. It has nothing to do with forums or other services, nor does it affect sending mail on ports 587 or 465 in any way. I'm not sure it's appropriate for the forum to be blocking posters on the XBL.
My trouble started last month when I cancelled my landline and started using only mobile data. (I guess the landline ISP simply blocked outgoing connections on port 25. The mobile ISP apparently doesn't.) An Android tablet is the gateway and serves as a regular tablet with apps and games. 2 Win10 computers access the gateway via wifi. The mobile data connection gets a new IPv4 address every so often, (likely when I go out and return,) which has allowed me to try different things.
So, in chronological order, I started using mobile data only, and I was blocked when I tried to post here. I clicked the link which took me to Spamhaus, I read up on it as best I could. Spamhaus shows the time and nature of the 'offense' which resulted in getting on the XBL. In this instance, it was a SMTP "HELO" on port 25 at a very recent date and time; quite possibly the time my tablet switched over to the cell tower covering my home. 2 days later, I checked my IP address was different, and tried posting again. Results were identical; on the XBL for the same offense, and the time was again plausibly when I came in range of the cell tower.
I blocked connections to port 25 on both my Win10 computers, and bemoaned the fact that my tablet would have been firewalled already if Samsung hadn't made it so hard to root it. A few days later, I tried to post again from a 3rd IP address with the same results. It looked like the problem was on my tablet. Having seen some evidence that certain versions of PySol contain malware, I removed the Android PySol app from my tablet and waited about a week before trying again with a 4th IP address. This time, the post was successful. Checking with Spamhaus shows this IP address is not on the XBL.
Now posting this from a 5th IP address which Spamhaus tells me was on the CSS list earlier this month, with no mention of the XBL. (I didn't read up on what the CSS is.) -- Well I guess it worked.
Spamhaus maintain multiple blacklists. The PBL blanket-covers domestic ISPs with exceptions by request. Any address on the PBL found to be making outgoing connections on port 25 (SMTP) gets put on the XBL -- the eXploits BlockList. There's no reason for domestic machines to be sending mail on port 25, they normally make a secure connection to their mail server. (Port 587 or 465.) The XBL blacklists individual IP addresses for a year. It's possible to contact Spamhaus to be removed from it.
This forum blocks posting from any IP address on the XBL, but Spamhaus's explanation of the XBL mentions only email, and only on port 25. It has nothing to do with forums or other services, nor does it affect sending mail on ports 587 or 465 in any way. I'm not sure it's appropriate for the forum to be blocking posters on the XBL.
My trouble started last month when I cancelled my landline and started using only mobile data. (I guess the landline ISP simply blocked outgoing connections on port 25. The mobile ISP apparently doesn't.) An Android tablet is the gateway and serves as a regular tablet with apps and games. 2 Win10 computers access the gateway via wifi. The mobile data connection gets a new IPv4 address every so often, (likely when I go out and return,) which has allowed me to try different things.
So, in chronological order, I started using mobile data only, and I was blocked when I tried to post here. I clicked the link which took me to Spamhaus, I read up on it as best I could. Spamhaus shows the time and nature of the 'offense' which resulted in getting on the XBL. In this instance, it was a SMTP "HELO" on port 25 at a very recent date and time; quite possibly the time my tablet switched over to the cell tower covering my home. 2 days later, I checked my IP address was different, and tried posting again. Results were identical; on the XBL for the same offense, and the time was again plausibly when I came in range of the cell tower.
I blocked connections to port 25 on both my Win10 computers, and bemoaned the fact that my tablet would have been firewalled already if Samsung hadn't made it so hard to root it. A few days later, I tried to post again from a 3rd IP address with the same results. It looked like the problem was on my tablet. Having seen some evidence that certain versions of PySol contain malware, I removed the Android PySol app from my tablet and waited about a week before trying again with a 4th IP address. This time, the post was successful. Checking with Spamhaus shows this IP address is not on the XBL.
Now posting this from a 5th IP address which Spamhaus tells me was on the CSS list earlier this month, with no mention of the XBL. (I didn't read up on what the CSS is.) -- Well I guess it worked.
Kaph — a modular OS intended to be easy and fun to administer and code for.
"May wisdom, fun, and the greater good shine forth in all your work." — Leo Brodie
"May wisdom, fun, and the greater good shine forth in all your work." — Leo Brodie

