...
This is the overall list of IPs blocked; with breakdowns by date in the comments:
Jira Legacy | ||||||
---|---|---|---|---|---|---|
|
...
How to Block IPs reported in the List Bombing email:
Open the List Bombing email
Look over the data provided for any red flags (see criteria below) and note any potential problem IPs
Click through all of the CleanTalk, StopForumSpam, and Project Honeypot links provided (even if the email says "Not blacklisted," it's possible the IP has been listed in the time between the alert and your response)
Make a list of all of the IPs that have been reported as spam or other malicious behavior on any of the three sites - these IPs must all be blocked and documented
Verify whether any of the potential problem IPs from Step 2 need to be added to the block list by confirming spam report status or suspicious data
Use Postman to block each IP address from adding new addresses to SignupApp2 (SUA2)
You will need access to the SUA2 environment, if you don't have correct permissions submit a ticket to IT
use SUA Endpoints > Exclusions > Add blacklisted IP code
Paste the IP address into the bar where highlighted
Click "Send"
Verify 200 OK response
You should see this:
If you see this, the IP has already been blocked (you probably duplicated it in your list by accident, eg noted the IP at first and copied again where it was blacklisted)
Repeat these steps for all IPs
Document the IPs you've blocked. *Note, for the time being that process is being handled on this DLV ticket:
Jira Legacy server agora publishing serverId af0addc4-7667-3733-8fe3-a9af723b162a key DLV-3174 Paste the list of blocked IPs into a comment, so there's a timestamp for those IPs
Paste the list of blocked IPs into the master blocklist in the body of the ticket
...
Criteria for blocking an IP address:
Blacklisted on any of the blacklists in the "Possible IP List Bombing" email; OR
A combination of the following:
High spam rate on Cleantalk – anything above 2-3% should raise a red flag.
IP is located in problematic regions (ie, SE Asia, China, Russia, Eastern Europe)
High discrepancy between unique email addresses and unique signups/attempts
Apparent but unmarked bulk uploads in SUA2 (eg, dozens of signups within a second, patterns in uploads, etc)
The following addresses have been positively ID'd as legit sources of signups (to be whitelisted):
54.224.244.168 - vendor
161.47.117.248 - vendor
104.196.168.51 - FTM / Australia
35.189.61.7 - PPP / Australia
34.206.153.163 - investmentu
162.242.156.206 - zapier / agora financial
144.202.62.164 - oxf + mmp vendor
144.202.56.90 - mmp vendor
54.241.34.25 - AF vendor Unbounce
50.19.99.184 - AF vendor Unbounce
...
3.220.115.188 - Zapier
3.220.22.251 - Zapier
52.1.205.184 - Zapier
52.6.229.193 - Zapier
52.6.82.82 - Zapier
54.85.112.125 - Zapier
...
Further reading on List Bombing:
Word to the Wise: Subscription Bombing, ESPs, and Spamhaus:
https://wordtothewise.com/2016/08/subscription-bombing-esps-spamhaus/Subscription Bombing: COI, CAPTCHA, and the Next Generation of Mail Bombs:
https://www.spamhaus.org/news/article/734/Mailing Lists -vs- Spam Lists:
https://www.spamhaus.org/whitepapers/mailinglists/Confirmed Opt In - A Rose by Any Name:
https://www.spamhaus.org/news/article/635Spamhaus Marketing FAQ:
https://www.spamhaus.org/faq/section/Marketing%20FAQs
...
...
Tip |
---|
Wrap upYou should now know how to block IPs reported for list-bombing. |
...