Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
digimetrica
New Contributor

How to block fake linkedin spam

there is a serious warning about fake linkedin spam. http://www.pcworld.com/article/206372/warning_fake_linkedin_spam_can_steal_your_bank_passwords.html For some reason fortiguard is not blocking those kind of fake emails contaning fake urls within. I don' t want to block the whole domain or by content (the mail looks fine), it' s just the uri embedded is wrong.
14 REPLIES 14
cmberry
New Contributor

I am getting slammed with these emails, hundreds per day. Because of Bug ID 0131322, I currently have my email filter off, which I think is making the problem worse. I would also be interested in a custom sig if someone here comes up with one to block these.
laf
New Contributor II

Where are you guys from?

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.
digimetrica
New Contributor

Italy. I am using fortiguard service on a fortimail and on several fortigate but those emails keeps passing and our clients are really getting angry. I am submitting those emails to our bayesan but still they keep passing. I can' t put the whole domain in blacklist cause the real linkedin (sadly) is used :\
abelio
Valued Contributor

Do you' re using SURBL in your AS incoming profile? Many URL included in those linkedin spam are already listed in surbl.org BTW, to enable ' Forged IP' AS feature should be also helpful, because true Linkedin communications has correct reverse records for its mailservers regards

regards




/ Abel

regards / Abel
cmberry
New Contributor

Do you' re using SURBL in your AS incoming profile? Many URL included in those linkedin spam are already listed in surbl.org BTW, to enable ' Forged IP' AS feature should be also helpful, because true Linkedin communications has correct reverse records for its mailservers
Can SURBL and Forged IP be set on a fortigate like the 200B running 4.2, or are these only available on FortiMail? I dont see any settings in my webconfig along those lines....
abelio
Valued Contributor

Can SURBL and Forged IP be set on a fortigate like the 200B running 4.2, or are these only available on FortiMail? I dont see any settings in my webconfig along those lines....
only for FortiMail, former poster of this thread talked about fortimail.

regards




/ Abel

regards / Abel
Not applicable

Bug ID 0131322
cmberry, or perhaps someone else, could you explain what but 0131322 is?
ede_pfau
Esteemed Contributor III

I am working on a regex that can be used to trigger on false links. It recognizes a web link and compares the description to the link with the link target address. Goal is to trigger if the link text looks like an URL but the principal domain doesn' t match the link target domain. This could be useful for linkedin, facebook, your_bank_URL_here... As today is Friday and I' m already out of office I' ll report on Monday.

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
cmberry
New Contributor

cmberry, or perhaps someone else, could you explain what bug 0131322 is?
This is a bug, recently found, that causes issue when AV scanning POP3 email, which shows itself by failed downloads and " page not found" errors in browser due to proxy worker crash (as I understand it). Nothing to do with the Linkedin emails in this thread, except that in order to bypass BUG ID 0131322 you need to turn email filtering off in UTM, so emails dont get AV scanned. (some smart people here have suggested ways that I could seperate email scanning, therefore keep email filter on, and not have interruptions in internet traffic, but I have not tried yet). So even if Fortinet normally recognizes these emails and blocks them, I am getting the full brunt of the attack since I am not using email filter until they fix the bug.
Where are you guys from?
Portland, Maine, USA.
Labels
Top Kudoed Authors