Phishers on sdl mailing list?

I received this email today claiming to be sent from
sdl-request at lists.libsdl.org.

I did not send any messages to the list on 21-Apr-2014 as the message claims.
The password given is not my password (although I x’d it out in case it might
be someones).

Has anyone else received messages like this?

Jeff

Message text:------------------

Your membership in the mailing list SDL has been disabled due to
excessive bounces The last bounce received from you was dated
21-Apr-2014. You will not get any more messages from this list until
you re-enable your membership. You will receive 3 more reminders like
this before your membership in the list is deleted.

To re-enable your membership, you can simply respond to this message
(leaving the Subject: line intact), or visit the confirmation page at

http://lists.libsdl.org/confirm.cgi/sdl-

libsdl.org/9dbd8b626e909c393753411f744528b323d4e877

You can also visit your membership page at

http://lists.libsdl.org/options.cgi/sdl-libsdl.org/j_post%40pacbell.net

On your membership page, you can change various delivery options such
as your email address and whether you get digests or not. As a
reminder, your membership password is

xxxxxxxx

If you have any questions or problems, you can contact the list owner
at

sdl-owner at lists.libsdl.org

This looks like a legit message, although I’m not sure why the data looks
incorrect. The links also go to libsdl.org… ?On Mon, Apr 21, 2014 at 10:58 AM, j_post <j_post at pacbell.net> wrote:

I received this email today claiming to be sent from
sdl-request at lists.libsdl.org.

I did not send any messages to the list on 21-Apr-2014 as the message
claims.
The password given is not my password (although I x’d it out in case it
might
be someones).

Has anyone else received messages like this?

Jeff

Message text:

Your membership in the mailing list SDL has been disabled due to
excessive bounces The last bounce received from you was dated
21-Apr-2014. You will not get any more messages from this list until
you re-enable your membership. You will receive 3 more reminders like
this before your membership in the list is deleted.

To re-enable your membership, you can simply respond to this message
(leaving the Subject: line intact), or visit the confirmation page at

http://lists.libsdl.org/confirm.cgi/sdl-

libsdl.org/9dbd8b626e909c393753411f744528b323d4e877

You can also visit your membership page at

http://lists.libsdl.org/options.cgi/sdl-libsdl.org/j_post%40pacbell.net

On your membership page, you can change various delivery options such
as your email address and whether you get digests or not. As a
reminder, your membership password is

xxxxxxxx

If you have any questions or problems, you can contact the list owner
at

sdl-owner at lists.libsdl.org

SDL mailing list
SDL at lists.libsdl.org
http://lists.libsdl.org/listinfo.cgi/sdl-libsdl.org

I did not send any messages to the list on 21-Apr-2014 as the
message claims.

[…snip…]
Your membership in the mailing list SDL has been disabled due to
excessive bounces The last bounce received from you was dated
21-Apr-2014.

This is probably a legit email.

It means Mailman tried to send you mailing list traffic on the 21st (and
other dates), and pacbell.net bounced it for whatever reason. It’s mail
coming to you, not mail you sent. If your mail provider keeps bouncing
traffic from the list, the mailing list manager takes you off the list,
assuming the account is no longer viable.

Often times this means your mailbox is overfull, etc, but it can also
mean that pacbell.net (temporarily) had problems or (temporarily?)
thought the mailing list traffic was spam.

Also, very few people set up Mailman passwords, instead using the random
default that Mailman generates (which is good, because the stupid things
are stored unencrypted and mailed in plaintext to you once a month,
stupid stupid stupid)…are you sure that wasn’t really your password?

–ryan.

I’ve received messages like that too, more than once over the past month.? And I’m on Yahoo Mail, and it receives SDL messages just fine.? Not sure what the problem is, but I don’t think it’s on the receiving end.

MasonOn Monday, April 21, 2014 1:24 PM, Ryan C. Gordon wrote:

? ? I did not send any messages to the list on 21-Apr-2014 as the
? ? message claims.
[…snip…]
? ? Your membership in the mailing list SDL has been disabled due to
? ? excessive bounces The last bounce received from you was dated
? ? 21-Apr-2014.

This is probably a legit email.

It means Mailman tried to send you mailing list traffic on the 21st (and
other dates), and pacbell.net bounced it for whatever reason. It’s mail
coming to you, not mail you sent. If your mail provider keeps bouncing
traffic from the list, the mailing list manager takes you off the list,
assuming the account is no longer viable.

Often times this means your mailbox is overfull, etc, but it can also
mean that pacbell.net (temporarily) had problems or (temporarily?)
thought the mailing list traffic was spam.

Also, very few people set up Mailman passwords, instead using the random
default that Mailman generates (which is good, because the stupid things
are stored unencrypted and mailed in plaintext to you once a month,
stupid stupid stupid)…are you sure that wasn’t really your password?

–ryan.


SDL mailing list
SDL at lists.libsdl.org
http://lists.libsdl.org/listinfo.cgi/sdl-libsdl.org

On another issue relevant to the subject, I’m getting some, nothing special
or suspicious [SDL List] mail filtered as spam, daily or weekly.On Mon, May 5, 2014 at 4:53 AM, Mason Wheeler wrote:

I’ve received messages like that too, more than once over the past month.
And I’m on Yahoo Mail, and it receives SDL messages just fine. Not sure
what the problem is, but I don’t think it’s on the receiving end.

Mason

On Monday, April 21, 2014 1:24 PM, Ryan C. Gordon wrote:

I did not send any messages to the list on 21-Apr-2014 as the
message claims.
[…snip…]
Your membership in the mailing list SDL has been disabled due to
excessive bounces The last bounce received from you was dated
21-Apr-2014.

This is probably a legit email.

It means Mailman tried to send you mailing list traffic on the 21st (and
other dates), and pacbell.net bounced it for whatever reason. It’s mail
coming to you, not mail you sent. If your mail provider keeps bouncing
traffic from the list, the mailing list manager takes you off the list,
assuming the account is no longer viable.

Often times this means your mailbox is overfull, etc, but it can also
mean that pacbell.net (temporarily) had problems or (temporarily?)
thought the mailing list traffic was spam.

Also, very few people set up Mailman passwords, instead using the random
default that Mailman generates (which is good, because the stupid things
are stored unencrypted and mailed in plaintext to you once a month,
stupid stupid stupid)…are you sure that wasn’t really your password?

–ryan.


SDL mailing list
SDL at lists.libsdl.org
http://lists.libsdl.org/listinfo.cgi/sdl-libsdl.org


SDL mailing list
SDL at lists.libsdl.org
http://lists.libsdl.org/listinfo.cgi/sdl-libsdl.org

I also get this. gmail puts quite a few SDL emails in the spam
folder… including this thread and your email.

Not sure what can be done about this.On Tue, May 6, 2014 at 1:52 AM, Juan Manuel Borges Ca?o wrote:

On another issue relevant to the subject, I’m getting some, nothing special
or suspicious [SDL List] mail filtered as spam, daily or weekly.

On Mon, May 5, 2014 at 4:53 AM, Mason Wheeler wrote:

I’ve received messages like that too, more than once over the past month.
And I’m on Yahoo Mail, and it receives SDL messages just fine. Not sure
what the problem is, but I don’t think it’s on the receiving end.

Mason

On Monday, April 21, 2014 1:24 PM, Ryan C. Gordon wrote:

I did not send any messages to the list on 21-Apr-2014 as the
message claims.
[…snip…]
Your membership in the mailing list SDL has been disabled due to
excessive bounces The last bounce received from you was dated
21-Apr-2014.

This is probably a legit email.

It means Mailman tried to send you mailing list traffic on the 21st (and
other dates), and pacbell.net bounced it for whatever reason. It’s mail
coming to you, not mail you sent. If your mail provider keeps bouncing
traffic from the list, the mailing list manager takes you off the list,
assuming the account is no longer viable.

Often times this means your mailbox is overfull, etc, but it can also
mean that pacbell.net (temporarily) had problems or (temporarily?)
thought the mailing list traffic was spam.

Also, very few people set up Mailman passwords, instead using the random
default that Mailman generates (which is good, because the stupid things
are stored unencrypted and mailed in plaintext to you once a month,
stupid stupid stupid)…are you sure that wasn’t really your password?

–ryan.


SDL mailing list
SDL at lists.libsdl.org
http://lists.libsdl.org/listinfo.cgi/sdl-libsdl.org


SDL mailing list
SDL at lists.libsdl.org
http://lists.libsdl.org/listinfo.cgi/sdl-libsdl.org


SDL mailing list
SDL at lists.libsdl.org
http://lists.libsdl.org/listinfo.cgi/sdl-libsdl.org

Me too, Gmail seems to put all messages from Mason Wheeler and Nathanial
J Fries in SPAM, even though I report them as “not spam” every time.
The reason being: “Be careful with this message. Our systems couldn’t
verify that this message was really sent by yahoo.com. You might want to
avoid clicking links or replying with personal information.”
(Yeah, both are using @yahoo.com addresses).
I have no idea what makes google/Gmail think that the messages are not
from yahoo.com.

Cheers,
DanielAm 05.05.2014 15:52, schrieb Juan Manuel Borges Ca?o:

On another issue relevant to the subject, I’m getting some, nothing
special or suspicious [SDL List] mail filtered as spam, daily or weekly.

On Mon, May 5, 2014 at 4:53 AM, Mason Wheeler <masonwheeler at yahoo.com <mailto:masonwheeler at yahoo.com>> wrote:

I've received messages like that too, more than once over the past
month.  And I'm on Yahoo Mail, and it receives SDL messages just
fine.  Not sure what the problem is, but I don't think it's on the
receiving end.

Mason


On Monday, April 21, 2014 1:24 PM, Ryan C. Gordon <icculus at icculus.org <mailto:icculus at icculus.org>> wrote:
 >    I did not send any messages to the list on 21-Apr-2014 as the
 >    message claims.
 > [...snip...]
 >    Your membership in the mailing list SDL has been disabled due to
 >    excessive bounces The last bounce received from you was dated
 >    21-Apr-2014.

This is probably a legit email.

It means Mailman tried to send you mailing list traffic on the 21st
(and
other dates), and pacbell.net <http://pacbell.net> bounced it for
whatever reason. It's mail
coming to you, not mail you sent. If your mail provider keeps bouncing
traffic from the list, the mailing list manager takes you off the list,
assuming the account is no longer viable.

Often times this means your mailbox is overfull, etc, but it can also
mean that pacbell.net <http://pacbell.net> (temporarily) had
problems or (temporarily?)
thought the mailing list traffic was spam.

Also, very few people set up Mailman passwords, instead using the
random
default that Mailman generates (which is good, because the stupid
things
are stored unencrypted and mailed in plaintext to you once a month,
stupid stupid stupid)...are you sure that wasn't really your password?

--ryan.


_______________________________________________
SDL mailing list
SDL at lists.libsdl.org <mailto:SDL at lists.libsdl.org>
http://lists.libsdl.org/listinfo.cgi/sdl-libsdl.org



_______________________________________________
SDL mailing list
SDL at lists.libsdl.org <mailto:SDL at lists.libsdl.org>
http://lists.libsdl.org/listinfo.cgi/sdl-libsdl.org

SDL mailing list
SDL at lists.libsdl.org
http://lists.libsdl.org/listinfo.cgi/sdl-libsdl.org

I found some more information on this, basically Yahoo is screwing up
and you shouldn’t use Yahoo Mail to post to any mailing list:
http://www.ietf.org/mail-archive/web/ietf/current/msg87153.html

Cheers,
DanielAm 06.05.2014 01:19, schrieb Daniel Gibson:

Me too, Gmail seems to put all messages from Mason Wheeler and Nathanial
J Fries in SPAM, even though I report them as “not spam” every time.
The reason being: “Be careful with this message. Our systems couldn’t
verify that this message was really sent by yahoo.com. You might want to
avoid clicking links or replying with personal information.”
(Yeah, both are using @yahoo.com addresses).
I have no idea what makes google/Gmail think that the messages are not
from yahoo.com.

Cheers,
Daniel

Am 05.05.2014 15:52, schrieb Juan Manuel Borges Ca?o:

On another issue relevant to the subject, I’m getting some, nothing
special or suspicious [SDL List] mail filtered as spam, daily or weekly.

On Mon, May 5, 2014 at 4:53 AM, Mason Wheeler <masonwheeler at yahoo.com <mailto:masonwheeler at yahoo.com>> wrote:

I've received messages like that too, more than once over the past
month.  And I'm on Yahoo Mail, and it receives SDL messages just
fine.  Not sure what the problem is, but I don't think it's on the
receiving end.

Mason


On Monday, April 21, 2014 1:24 PM, Ryan C. Gordon <icculus at icculus.org <mailto:icculus at icculus.org>> wrote:
 >    I did not send any messages to the list on 21-Apr-2014 as the
 >    message claims.
 > [...snip...]
 >    Your membership in the mailing list SDL has been disabled

due to
> excessive bounces The last bounce received from you was dated
> 21-Apr-2014.

This is probably a legit email.

It means Mailman tried to send you mailing list traffic on the 21st
(and
other dates), and pacbell.net <http://pacbell.net> bounced it for
whatever reason. It's mail
coming to you, not mail you sent. If your mail provider keeps

bouncing
traffic from the list, the mailing list manager takes you off the
list,
assuming the account is no longer viable.

Often times this means your mailbox is overfull, etc, but it can also
mean that pacbell.net <http://pacbell.net> (temporarily) had
problems or (temporarily?)
thought the mailing list traffic was spam.

Also, very few people set up Mailman passwords, instead using the
random
default that Mailman generates (which is good, because the stupid
things
are stored unencrypted and mailed in plaintext to you once a month,
stupid stupid stupid)...are you sure that wasn't really your

password?

--ryan.


_______________________________________________
SDL mailing list
SDL at lists.libsdl.org <mailto:SDL at lists.libsdl.org>
http://lists.libsdl.org/listinfo.cgi/sdl-libsdl.org



_______________________________________________
SDL mailing list
SDL at lists.libsdl.org <mailto:SDL at lists.libsdl.org>
http://lists.libsdl.org/listinfo.cgi/sdl-libsdl.org

SDL mailing list
SDL at lists.libsdl.org
http://lists.libsdl.org/listinfo.cgi/sdl-libsdl.org

Message-ID: <53681C70.2060605 at gmail.com>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed

Me too, Gmail seems to put all messages from Mason Wheeler and Nathanial
J Fries in SPAM, even though I report them as “not spam” every time.
The reason being: “Be careful with this message. Our systems couldn’t
verify that this message was really sent by yahoo.com. You might want to
avoid clicking links or replying with personal information.”
(Yeah, both are using @yahoo.com addresses).
I have no idea what makes google/Gmail think that the messages are not
from yahoo.com.

Probably some random mailing protocol extension that Yahoo isn’t
reliably using, which itself could come from e.g. sending a response
query back to Yahoo before something had been entered into a database.
If it was happening with other mail services then I’d tend to suspect
the list mailer of implementing redirection wrong.> Date: Tue, 06 May 2014 01:19:12 +0200

From: Daniel Gibson
To: SDL Development List
Subject: Re: [SDL] phishers on sdl mailing list?

Just informing I’ve been receiving a few of these bounce notifications
on April and May. Not a lot of them, but they have arrived, nevertheless.

In case anybody is wondering, I’ve sent just a couple of messages to the
list during April 29th (none on May before this message). Furthermore,
an outlook.com account is currently in use (this is really a part of the
list account name, not hotmail.com or any other different domain).

It is surely important to ensure the links in such a bounce notification
are legitimate. As expected, though, if it is the case then you probably
need to follow the instructions, since you probably won’t get any SDL
mailing list message otherwise (ignoring more such bounce notifications).