I have been finding spam with a first received header like this:
Received: (from tomcat@localhost)
by 171.157.180.109 (8.12.8/8.12.8/Submit) id j1CHmn0V898482 for me@myhost; Sat, 8 Nov 2008 20:14:50 -0100With a week's worth of filtering on "tomcat@localhost" I have found 1000 or so spams like that with exactly zero false positives. I also can't be sure that the header isn't totally forged. But. . . It's sure finding spam.
tomcat seems to be a new - at least to me - part of the apache web server. Can the above tomcat@localhost be a part of apache perhaps running on a zombie computer? Can someone point me to a succinct URL that talks about it?
-- --> A fair tax is one that you pay but I don't <-- --------------------------------------------------------------------- The official User-To-User support forum of the Apache HTTP Server Project. See <URL:http://httpd.apache.org/userslist.html> for more info. To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx " from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx