<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.0.5" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Brett Sheffield . com</title>
	<link>http://www.brettsheffield.com</link>
	<description>Open Source for Business Blog</description>
	<pubDate>Mon, 12 Nov 2007 16:22:35 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.5</generator>
	<language>en</language>
			<item>
		<title>Georbl: Individual Country DNSBL Zones</title>
		<link>http://www.brettsheffield.com/email/georbl-individual-country-dnsbl-zones/</link>
		<comments>http://www.brettsheffield.com/email/georbl-individual-country-dnsbl-zones/#comments</comments>
		<pubDate>Mon, 12 Nov 2007 16:22:35 +0000</pubDate>
		<dc:creator>brett</dc:creator>
		
		<category>email</category>

		<category>spam</category>

		<category>Georbl</category>

		<guid isPermaLink="false">http://www.brettsheffield.com/email/georbl-individual-country-dnsbl-zones/</guid>
		<description><![CDATA[I&#8217;ve added individual country zones to georbl.info.  If you&#8217;re only interested in one zone, or are using it with something that doesn&#8217;t support TXT lookups (postfix without patching?) you can perform lookups with less hassle.
If anyone has some config examples for other MTA&#8217;s, or knows if postfix will support TXT lookups, please let me [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve added <a href="http://georbl.info/blog/individual-country-zones-now-available/">individual country zones</a> to georbl.info.  If you&#8217;re only interested in one zone, or are using it with something that doesn&#8217;t support TXT lookups (postfix without patching?) you can perform lookups with less hassle.</p>
<p>If anyone has some config examples for other MTA&#8217;s, or knows if postfix will support TXT lookups, please let me know.  Otherwise, I&#8217;ll write something up later myself.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.brettsheffield.com/email/georbl-individual-country-dnsbl-zones/feed/</wfw:commentRss>
		</item>
		<item>
		<title>georbl.info</title>
		<link>http://www.brettsheffield.com/email/georblinfo/</link>
		<comments>http://www.brettsheffield.com/email/georblinfo/#comments</comments>
		<pubDate>Sun, 11 Nov 2007 14:57:02 +0000</pubDate>
		<dc:creator>brett</dc:creator>
		
		<category>email</category>

		<category>Gladserv</category>

		<category>spam</category>

		<category>Georbl</category>

		<guid isPermaLink="false">http://www.brettsheffield.com/email/georblinfo/</guid>
		<description><![CDATA[We&#8217;ve had a couple of customers who want to be aggressive on spam, *but* don&#8217;t want to risk losing any business emails, however broken the mailserver that it originates from.
The oil industry seem to be particularly bad, and having two marketing companies using our service and a chain of casinos also make for fun times [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve had a couple of customers who want to be aggressive on spam, *but* don&#8217;t want to risk losing any <a href="http://www.gladserv.com/pages/email-for-business.php">business emails</a>, however broken the mailserver that it originates from.</p>
<p>The oil industry seem to be particularly bad, and having two marketing companies using our service and a chain of casinos also make for fun times when using various filters.</p>
<p>A couple of months ago I implemented some tighter spam controls.  Basically, enforcing the <a href="http://www.imc.org/rfcs.html">RFCs</a> a bit more tightly because we know spammers take short-cuts. Most of these controls are still in place, but I&#8217;ve had to exempt several of our customers due to complaints that email wasn&#8217;t getting through.  It seems it&#8217;s not just spammers that take short-cuts - there are a lot of amateur mail admins out there, and we&#8217;re not just talking cowboys who&#8217;ve thrown an M$ Exchange server in without taking it out of its cellophane.  We&#8217;re talking BIG companies (lots in the oil industry), technical companies, all sorts.</p>
<p>You&#8217;d think being strict with enforcing RFCs would be reasonably safe, but I&#8217;ve lost count of the number of mailservers that don&#8217;t have a postmaster address set up, that send from invalid addresses, don&#8217;t have reverse IP resolution set up etc. etc. etc.  These are really good ways to catch out spammers at smtp time, but from time to time it catches a real email and I&#8217;m tired of explaining to customers that it&#8217;s the other guy&#8217;s mailserver that&#8217;s broken.</p>
<p>Many email RFCs have been broken, bent and ignored for so long that suddenly enforcing them breaks things.</p>
<p>Rejecting mail at SMTP time is the &#8220;right&#8221; way to do things.  It reduces bandwidth, memory, cpu and disk usage and eliminates <a href="http://www.brettsheffield.com/email/backscatter-spam/">backscatter</a>.  In a large ISP the two main costs are power and bandwidth, and so there are real cost savings to be made by enforcing RFCs at SMTP time.  It&#8217;s even good for the environment.  By ruthlessly checking for a postmaster address I know that while I sit at my keyboard here, I&#8217;m doing my bit for the <a href="http://animals.nationalgeographic.com/animals/enlarge/emperor-penguins_image.html">polar ice caps</a>.</p>
<p>By fortunate coincidence, the most problematic of our clients *only* receive email from UK companies + a couple of known addresses that we can whitelist individually.  So, if we could whitelist *everything* from the UK as well, we&#8217;d be pretty sure of not missing and valuable emails.</p>
<p>I&#8217;ve taken an old script of Dan Shearer&#8217;s (thanks <a href="http://shearer.org/">Dan</a>) for grabbing the IP ranges from RIPE, APNIC, AFRINIC, ARIN &#038; LACNIC, updated it and hacked it around so it spits out zone files suitable for use with <a href="http://www.corpit.ru/mjt/rbldnsd.html">rbldnsd</a>.  If anyone else wants to make use of it, feel free.  <a href="http://georbl.info/">http://georbl.info/</a>
</p>
]]></content:encoded>
			<wfw:commentRss>http://www.brettsheffield.com/email/georblinfo/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Scottish Open Source Awards Launched</title>
		<link>http://www.brettsheffield.com/open-source/scottish-open-source-awards-launched/</link>
		<comments>http://www.brettsheffield.com/open-source/scottish-open-source-awards-launched/#comments</comments>
		<pubDate>Wed, 01 Aug 2007 16:50:22 +0000</pubDate>
		<dc:creator>brett</dc:creator>
		
		<category>open source software</category>

		<category>OSS for Business</category>

		<guid isPermaLink="false">http://www.brettsheffield.com/open-source/scottish-open-source-awards-launched/</guid>
		<description><![CDATA[
The Scottish Open Source Awards opened today, 1st August 2007 at 9AM, for nominations and entries. The awards are open to business, government, education, not-for-profit, charities and students, who contribute to or use Open Source Software or services.

Press Release
Scottish Open Source Awards website.

]]></description>
			<content:encoded><![CDATA[<blockquote><p>
The Scottish Open Source Awards opened today, 1st August 2007 at 9AM, for nominations and entries. The awards are open to business, government, education, not-for-profit, charities and students, who contribute to or use Open Source Software or services.
</p></blockquote>
<p><a href="http://www.openpr.com/news/25083/Launch-of-Scottish-Open-Source-Awards-2007.html">Press Release</a></p>
<p><a href="http://www.scottishopensourceawards.co.uk/">Scottish Open Source Awards</a> website.
</p>
]]></content:encoded>
			<wfw:commentRss>http://www.brettsheffield.com/open-source/scottish-open-source-awards-launched/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Exim: Previous (cached) callout verification failure</title>
		<link>http://www.brettsheffield.com/email/exim-previous-cached-callout-verification-failure/</link>
		<comments>http://www.brettsheffield.com/email/exim-previous-cached-callout-verification-failure/#comments</comments>
		<pubDate>Wed, 25 Apr 2007 11:37:17 +0000</pubDate>
		<dc:creator>brett</dc:creator>
		
		<category>email</category>

		<category>Exim</category>

		<category>errors</category>

		<guid isPermaLink="false">http://www.brettsheffield.com/email/exim-previous-cached-callout-verification-failure/</guid>
		<description><![CDATA[When testing routing behavior in Exim, remember to flush the callout cache.  If an address callout has failed, that failure will be cached to speed up routing should another email arrive for that address.   This is normally a good thing, but a pain if you&#8217;re testing configs because you&#8217;ll keep getting the [...]]]></description>
			<content:encoded><![CDATA[<p>When testing routing behavior in Exim, remember to flush the callout cache.  If an address callout has failed, that failure will be cached to speed up routing should another email arrive for that address.   This is normally a good thing, but a pain if you&#8217;re testing configs because you&#8217;ll keep getting the address rejected even if you&#8217;ve fixed the routing problem.  </p>
<pre><code>rejected RCPT &lt;joe@bloggs.com&gt;: Previous (cached) callout verification failure</code></pre>
<p>There are two solutions.</p>
<p>The first is to turn off callout caching using the <code>no_cache</code> option in <code>exim.conf</code>.  eg:</p>
<pre><code>verify = recipient/callout=no_cache</code></pre>
<p>or you can flush the callout cache.  Simply -HUPing or restarting exim won&#8217;t do.  You need to delete the cache manually:</p>
<pre><code>
cd /var/spool/exim/db
mv callout callout.deleted  # or just delete it
</code></pre>
]]></content:encoded>
			<wfw:commentRss>http://www.brettsheffield.com/email/exim-previous-cached-callout-verification-failure/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Debian Etch Released - Changes to /etc/apt/sources.list</title>
		<link>http://www.brettsheffield.com/linux/debian-etch-released-changes-to-etcaptsourceslist/</link>
		<comments>http://www.brettsheffield.com/linux/debian-etch-released-changes-to-etcaptsourceslist/#comments</comments>
		<pubDate>Mon, 09 Apr 2007 14:01:47 +0000</pubDate>
		<dc:creator>brett</dc:creator>
		
		<category>Linux</category>

		<category>Debian</category>

		<guid isPermaLink="false">http://www.brettsheffield.com/linux/debian-etch-released-changes-to-etcaptsourceslist/</guid>
		<description><![CDATA[When my grandfather was a boy, back in the days when everything was black and white, he waited up all night so he could witness the release of Debian Sarge.  Now I, too, can say I&#8217;ve witnessed the release of that Halley&#8217;s Comet of distros, a new Debian Stable&#8230;
Debian 4.0 (Etch) became the stable [...]]]></description>
			<content:encoded><![CDATA[<p>When my grandfather was a boy, back in the days when everything was black and white, he waited up all night so he could witness the release of Debian Sarge.  Now I, too, can say I&#8217;ve witnessed the release of that Halley&#8217;s Comet of distros, a new Debian Stable&#8230;</p>
<p>Debian 4.0 (Etch) became the stable version of Debian yesterday.  If you&#8217;ve been using Etch prior to this, you will need to add security updates to your <code>sources.list</code>:</p>
<pre><code>
#
#  /etc/apt/sources.list
#

#
# etch
#
deb     http://ftp.uk.debian.org/debian/     etch main contrib non-free
deb-src http://ftp.uk.debian.org/debian/     etch main contrib non-free

#
#  Security updates
#
deb     http://security.debian.org/ etch/updates  main contrib non-free
deb-src http://security.debian.org/ etch/updates  main contrib non-free

</code></pre>
<p>Running <code>apt-get update</code> you may run into these errors:</p>
<pre><code>
W: Conflicting distribution: http://security.debian.org stable/updates Release
     (expected stable but got etch)
W: You may want to run apt-get update to correct these problems
</code></pre>
<p>Check your <code>sources.list</code> file again, and explicity use &#8220;etch&#8221; instead of stable as on some mirrors they don&#8217;t seem to be the same thing, yet.  Then re-run <code>apt-get update</code>.</p>
<p>Welcome to Debian 4.0!</p>
<p><a href="http://wiki.debian.org/NewInEtch">What&#8217;s New</a><br />
<a href="http://www.uk.debian.org/releases/etch/i386/release-notes/index.en.html">Release Notes</a><br />
<a href="http://www.debianadmin.com/upgrade-sarge-to-etch.html">Upgrading from Sarge to Etch</a>
</p>
]]></content:encoded>
			<wfw:commentRss>http://www.brettsheffield.com/linux/debian-etch-released-changes-to-etcaptsourceslist/feed/</wfw:commentRss>
		</item>
		<item>
		<title>UK WEEE Regulations - Registration Deadline</title>
		<link>http://www.brettsheffield.com/news/uk-weee-regulations-registration-deadline/</link>
		<comments>http://www.brettsheffield.com/news/uk-weee-regulations-registration-deadline/#comments</comments>
		<pubDate>Thu, 15 Mar 2007 17:17:37 +0000</pubDate>
		<dc:creator>brett</dc:creator>
		
		<category>news</category>

		<guid isPermaLink="false">http://www.brettsheffield.com/news/uk-weee-regulations-registration-deadline/</guid>
		<description><![CDATA[The deadline for registration as a system builder under the WEEE(EEY) legislation is today.  ie. If you&#8217;re building and selling your own systems or rebranded hardware, you&#8217;re meant to join a scheme and then pay wodges of cash to ensure environmentally friendly disposal of your systems when they end of life.  This doesn&#8217;t [...]]]></description>
			<content:encoded><![CDATA[<p>The deadline for registration as a system builder under the WEEE(EEY) legislation is today.  ie. If you&#8217;re building and selling your own systems or rebranded hardware, you&#8217;re meant to join a scheme and then pay wodges of cash to ensure environmentally friendly disposal of your systems when they end of life.  This doesn&#8217;t apply if you&#8217;re reselling someone else&#8217;s branded systems.</p>
<p>The legal stuff:<br />
<a href="http://www.dti.gov.uk/files/file35992.pdf">http://www.dti.gov.uk/files/file35992.pdf</a></p>
<p><a href="http://www.dti.gov.uk/innovation/sustainability/weee/page30269.html">http://www.dti.gov.uk/innovation/sustainability/weee/page30269.html</a></p>
<p>Now our <a href="http://www.linux.org/info/penguin.html">penguins</a> are safe.</p>
<p>Anyone looking for amusement should head to their nearest computer shop and ask if they&#8217;ve &#8220;registered for WEEE&#8221;.  Photos of the resultant facial expressions should be sent to me.  Prizes awarded.
</p>
]]></content:encoded>
			<wfw:commentRss>http://www.brettsheffield.com/news/uk-weee-regulations-registration-deadline/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Freeserve/Wanadoo/Orange spam</title>
		<link>http://www.brettsheffield.com/email/freeservewanadooorange-spam/</link>
		<comments>http://www.brettsheffield.com/email/freeservewanadooorange-spam/#comments</comments>
		<pubDate>Thu, 08 Mar 2007 19:51:14 +0000</pubDate>
		<dc:creator>brett</dc:creator>
		
		<category>email</category>

		<category>spam</category>

		<guid isPermaLink="false">http://www.brettsheffield.com/spam/freeservewanadooorange-spam/</guid>
		<description><![CDATA[Google &#8220;freeserve spam&#8221; or &#8220;wanadoo spam&#8221; and you&#8217;ll see these guys get themselves blacklisted frequently by dns blacklists for backscatter spam and for spammers using their network.  Spamhaus, Spamcop and Sorbs all pick up some of their servers regularly.  Their mails get bounced by any email provider using dns blacklists.  Unfortunately, people [...]]]></description>
			<content:encoded><![CDATA[<p>Google <a href="http://www.google.com/search?q=freeserve+spam">&#8220;freeserve spam&#8221;</a> or <a href="http://www.google.com/search?q=wanadoo+spam">&#8220;wanadoo spam&#8221;</a> and you&#8217;ll see these guys get themselves blacklisted frequently by dns blacklists for backscatter spam and for spammers using their network.  Spamhaus, Spamcop and Sorbs all pick up some of their servers regularly.  Their mails get bounced by any email provider using dns blacklists.  Unfortunately, people keep using them.  Why?</p>
<p>I&#8217;d write more on this, but so many have already.</p>
<p>If you&#8217;re attached to your Freeserve/Wanadoo/Orange account, but are sick of having your emails bounced, I suggest reading Andrew West&#8217;s <a href="http://wongablog.co.uk/2007/02/13/gmail-workaround-for-orangefreeservewanadoo-customers-with-email-problems/">Gmail workaround for Orange/Freeserve/Wanadoo customers with email problems</a>.
</p>
]]></content:encoded>
			<wfw:commentRss>http://www.brettsheffield.com/email/freeservewanadooorange-spam/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Backscatter Spam</title>
		<link>http://www.brettsheffield.com/email/backscatter-spam/</link>
		<comments>http://www.brettsheffield.com/email/backscatter-spam/#comments</comments>
		<pubDate>Mon, 26 Feb 2007 22:52:49 +0000</pubDate>
		<dc:creator>brett</dc:creator>
		
		<category>email</category>

		<category>spam</category>

		<guid isPermaLink="false">http://www.brettsheffield.com/email/backscatter-spam/</guid>
		<description><![CDATA[One of the domains I host has recently attracted a lot of backscatter spam.  What is backscatter?  Let me explain.
If a spammer fakes an email address on someone else&#8217;s domain, some incorrectly configured mailservers receiving the spam will bounce the message back to the (apparent) sender.  Meaning whichever poor schmuck has had [...]]]></description>
			<content:encoded><![CDATA[<p>One of the domains I host has recently attracted a lot of <a href="http://en.wikipedia.org/wiki/Backscatter#Backscatter_of_email_spam">backscatter</a> spam.  What is backscatter?  Let me explain.</p>
<p>If a spammer fakes an email address on someone else&#8217;s domain, some incorrectly configured mailservers receiving the spam will bounce the message back to the (apparent) sender.  Meaning whichever poor schmuck has had their domain faked will get a huge pile of bounce messages.  Thousands.  Some misguided email administrators will even ban email from the domain and/or mailserver that appears to send the message.</p>
<p>Despite the abundance of information available on backscatter spam, there are still loads of mail servers that will happily <a href="http://www.sput.nl/spam/bad-bounce.html">bounce mail</a> in this manner.  <a href="http://exim.org/">Exim</a>, <a href="http://postfix.org/">Postfix</a> and <a href="http://sendmail.org/">Sendmail</a>, configured correctly, are all capable of dealing with this problem.  If you&#8217;re looking for a reason to avoid using qmail, <a href="http://lwn.net/Articles/197662/">backscatter spam</a> would be a good place to start.</p>
<p>The only time a mailserver should reject a message is at SMTP time.  ie. when it is still connected to the sending machine.  Once a mailserver has accepted an email for delivery it has made a commitment to deliver the email.  Therefore a mailserver should never accept email that it isn&#8217;t able to deliver.   Bounce messages should only be sent to local clients to indicate that their message did not get through.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.brettsheffield.com/email/backscatter-spam/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Madeira</title>
		<link>http://www.brettsheffield.com/travel/madeira/</link>
		<comments>http://www.brettsheffield.com/travel/madeira/#comments</comments>
		<pubDate>Mon, 19 Feb 2007 21:21:59 +0000</pubDate>
		<dc:creator>brett</dc:creator>
		
		<category>travel</category>

		<guid isPermaLink="false">http://www.brettsheffield.com/travel/madeira/</guid>
		<description><![CDATA[I&#8217;m back and refreshed from a week in Madeira.  Lots of pictures (including some fabulous shots of my knees) and a comprehensive write-up of our adventures can by found on my on the my girlfriend&#8217;s above-linked blog.  That was actually a couple of weeks ago, but I&#8217;ve had my head in a machine [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m back and refreshed from a week in <a href="http://shandydann.livejournal.com/163944.html">Madeira</a>.  Lots of pictures (including some fabulous shots of my knees) and a comprehensive write-up of our adventures can by found on my on the my girlfriend&#8217;s above-linked blog.  That was actually a couple of weeks ago, but I&#8217;ve had my head in a machine since then.  Amazing what a difference a holiday makes.</p>
<p>I was very amused to find from my Google Webmaster Tools that I currently rank number 3 when searching for &#8220;alcohol unpacking software&#8221;.  I suppose it&#8217;s only fair really - alcohol and computers make up such a large part of my life.
</p>
]]></content:encoded>
			<wfw:commentRss>http://www.brettsheffield.com/travel/madeira/feed/</wfw:commentRss>
		</item>
		<item>
		<title>/proc/sys/net/huh?</title>
		<link>http://www.brettsheffield.com/linux/procsysnethuh/</link>
		<comments>http://www.brettsheffield.com/linux/procsysnethuh/#comments</comments>
		<pubDate>Sat, 13 Jan 2007 23:59:05 +0000</pubDate>
		<dc:creator>brett</dc:creator>
		
		<category>Linux</category>

		<category>networking</category>

		<guid isPermaLink="false">http://www.brettsheffield.com/linux/procsysnethuh/</guid>
		<description><![CDATA[You&#8217;ll often come across docs and how-tos that say things like &#8220;to enable forwarding issue the following command&#8221;:
echo 1 > /proc/sys/net/ipv4/ip_forward
Ever wondered what all that stuff in /proc/sys/net actually does?  Ok, a lot of it is pretty logical, but sometimes it&#8217;s nice to actually know with a bit more certainty.  Today I broke [...]]]></description>
			<content:encoded><![CDATA[<p>You&#8217;ll often come across docs and how-tos that say things like &#8220;to enable forwarding issue the following command&#8221;:</p>
<pre><code>echo 1 > /proc/sys/net/ipv4/ip_forward</code></pre>
<p>Ever wondered what all that stuff in /proc/sys/net actually does?  Ok, a lot of it is pretty logical, but sometimes it&#8217;s nice to actually know with a bit more certainty.  Today I broke something on a server because I assumed, instead of looking it up.  Oops.</p>
<p>There&#8217;s a lot of documentation in the kernel sources which is surprisingly accessible to the non kernel hackers among us.  First, get yourself a copy of the kernel source if you don&#8217;t have one.  Take a look in /usr/src.  If you don&#8217;t see a directory called something like linux-2.6.18, you probably don&#8217;t have the kernel source available.  If you&#8217;re on a debian, ubuntu or other apt-based distro, you can apt-get the source for your kernel:</p>
<pre><code>cd /usr/src
apt-get source linux-image-2.6.18-3-k7</code></pre>
<p>Once your kernel source has downloaded and unpacked, cd into the source directory. You&#8217;ll find a directory called Documentation, and inside that a subdirectory called networking.  The document we&#8217;re looking for in this case is ip-sysctl.txt.  Open it in your favorite text editor.</p>
<pre>
  <code>
/proc/sys/net/ipv4/* Variables:

ip_forward - BOOLEAN
        0 - disabled (default)
        not 0 - enabled

        Forward Packets between interfaces.

        This variable is special, its change resets all configuration
        parameters to their default state (RFC1122 for hosts, RFC1812
        for routers)

  </code>
</pre>
<p>Have a browse around - there&#8217;s quite a bit of other doco.  There&#8217;s an index file, 00-INDEX that lists what&#8217;s what.
</p>
]]></content:encoded>
			<wfw:commentRss>http://www.brettsheffield.com/linux/procsysnethuh/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
