Hello,
They are literally using * in the headers for to and from.
It could be a response to our bouncing of their Spam.
Thanks for the rule!
Frederic Tarasevicius
- Original Message -
From: "Matt Kettler" <[EMAIL PROTECTED]>
To: "Fred I-IS.COM" <[EMAIL PROTECTED]>;
<[EMAIL PROTECTED]>
Se
This doesn't seem to be the problem in exchange 5.5
I know what you mean by not being able to ditch exchange. :::Sigh:: ONE
DAY!!
-Original Message-
From: Covington, Chris [mailto:[EMAIL PROTECTED]
Sent: Monday, August 04, 2003 3:45 PM
To: [EMAIL PROTECTED]
Hi all,
RH 9, amavisd-new
Simon Byrnand writes:
>>BTW the AWL helps.
>
>I've mainly stayed away from AWL because a few people have suggested that
>sitewide enabling of AWL is a bad idea. Is that the case ?
>
>By default will it try to use one common AWL database, or will each user
>have their own AWL database ? If both o
At 8/4/2003 02:17 PM -0700, Mark H wrote:
>What I CAN'T do is send an email to SA for training. Since I don't use shell mail at
>all, there is really no way that I know to send email back from my home PC to SA,
>with an indication that its spam, and the filters should be trained to recognize it
At 17:00 4/08/2003 -0700, Justin Mason wrote:
Simon Byrnand writes:
>Whitelisting this list in spamassassin doesn't help prevent it from being
>autolearnt - because the whitelist scores don't contribute to deciding if a
>message triggers the autolearn thresholds or not
>
>Having said that, I h
Larry Gilson writes:
> However, if one tries to automate this then thresholds need to be attained
> automatically. So even if Bayes learns the time, a filtration engine needs
> to be able to analyze the spam/ham over time. A time minimum time interval
> needs to be met before thresholds can be a
I wrote a quick eval function that work as a proof-of-concept only. It
doesn't look at the headers at all... it uses the current system time and
*assumes* that the email is being scanned within a few minutes of being
received by the local server. I am aware that this is a weak assumption
in many
Matt Kettler writes:
>At 03:49 PM 8/4/2003 -0400, Fred I-IS.COM wrote:
>>Hello,
>>I noticed an issue with 2.55 and the test for FORGED_JUNO_RCVD,
>>The reverse dns for juno customers is: untd.com
>>This causes a false positive for juno customers.
>>Thanks,
>
>Theoretically Theo Van Dinter fixed
Simon Byrnand writes:
>Whitelisting this list in spamassassin doesn't help prevent it from being
>autolearnt - because the whitelist scores don't contribute to deciding if a
>message triggers the autolearn thresholds or not
>
>Having said that, I havn't personally seen a problem with autolea
- Original Message -
From: "Chris Santerre" <[EMAIL PROTECTED]>
To: "'Mark'" <[EMAIL PROTECTED]>; "Gary Funck" <[EMAIL PROTECTED]>;
"Spamassassin List" <[EMAIL PROTECTED]>
Sent: Monday, August 04, 2003 7:41 PM
Subject: RE: [SAtalk] those pesky small v*agra ads
> Wow I take one day off an
At 13:59 4/08/2003 -0400, Matt Kettler wrote:
At 01:02 PM 8/4/2003 -0400, Matthew Moldvan wrote:
Hey there Andrea,
Looks like this was caught by mine (and probably most people's) spam filters
... can you repost the question with the spam attached instead of in the
body? That should help ...
Matth
At 8/4/03 02:20 PM , Erick Calder wrote:
> Instead, I'd probably write an eval function
where do I find docs on how to do that?
The Camel Book? Seriously, you should learn Perl if you want to write an
eval function; it's not as simple as a one-line rule. If you do understand
Perl, then looking a
Hi all,
RH 9, amavisd-new 06162003, Postfix 2.0.13, SA 2.55.
I've been using the wonderful script from:
http://marc.theaimsgroup.com/?l=spamassassin-talk&m=105622875610715&w=2
I instruct users to move undetected SPAM to Public Folders.
But I've noticed that Exchange 2000 Public Folders in IMAP
At 08:23 4/08/2003 -0400, Michael W. Cocke wrote:
First of all, I apologize for the multi-post - it took me a while to
realize that messages from this list were being bounced, so when I
didn't see my message come back in, I assumed that something had gone
wrong with the send.
Second, I took DCC b
At 03:49 PM 8/4/2003 -0400, Fred I-IS.COM wrote:
Hello,
I noticed an issue with 2.55 and the test for FORGED_JUNO_RCVD,
The reverse dns for juno customers is: untd.com
This causes a false positive for juno customers.
Thanks,
Theoretically Theo Van Dinter fixed this a long time ago in this bug:
On Mon, 4 Aug 2003, Florian Effenberger wrote:
> Is there an option within procmail to filter out headers? So I could do
> it via procmail instead of modifying the code...
:0 fhw
| formail -I X-Spam-Checker-Version:
---
This SF.Net email spon
On Mon, Aug 04, 2003 at 11:57:31PM +0200, Florian Effenberger wrote:
> thanks for the quick reply! Is there an option within procmail to filter out
> headers? So I could do it via procmail instead of modifying the code...
not via procmail, but you could use formail.
I wouldn't suggest removing it
Hi Theo,
thanks for the quick reply! Is there an option within procmail to filter out
headers? So I could do it via procmail instead of modifying the code...
Thanks!
Florian
- Original Message -
From: "Theo Van Dinter" <[EMAIL PROTECTED]>
To: "Florian Effenberger" <[EMAIL PROTECTED]>
Cc
The -D output gave me the answer. I had not correctly set bayes_path.
I set it to the directory only and needed to add '/bayes'. When I saw
the output I re-checked the Conf manpage and there it was in black and
white. I guess I saw the option and did not read the text. My hubris
cost me
> Instead, I'd probably write an eval function
where do I find docs on how to do that?
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] Behalf Of Kai
MacTane
Sent: Monday, August 04, 2003 2:00 PM
To: [EMAIL PROTECTED]
Subject: RE: [SAtalk] [RD] Creating rule for time a
On Mon, Aug 04, 2003 at 11:38:46PM +0200, Florian Effenberger wrote:
> is there any possibility of removing the
>
> X-Spam-Checker-Version
>
> header line from messages? I was unable to do so :(
not without modifying the code. that's the only header required to be in there.
from the as-yet unr
Fred I-IS.COM writes:
> Hello,
> I noticed an issue with 2.55 and the test for FORGED_JUNO_RCVD,
> The reverse dns for juno customers is: untd.com
> This causes a false positive for juno customers.
Yeah, I think we have that fixed in 2.60.
--j.
Hello,
is there any possibility of removing the
X-Spam-Checker-Version
header line from messages? I was unable to do so :(
Thanks
Florian
---
This SF.Net email sponsored by: Free pre-built ASP.NET sites including
Data Reports, E-commerce, P
> -Original Message-
> From: Kai MacTane [mailto:[EMAIL PROTECTED]
> Sent: Monday, August 04, 2003 5:00 PM
> To: [EMAIL PROTECTED]
> Subject: RE: [SAtalk] [RD] Creating rule for time accepted
>
>
> At 8/4/03 12:49 PM , Chris Santerre wrote:
>
> >Well you could make a header rule to loo
I have some feature suggestions, for what I feel might be the "typical"
user - like me, for example.
Am I typical - well, maybe not. You decide...
I use a POP client (in my case, Eudora). SA runs on my ISPs mail server.
Mail is marked, and I filter out the spam on my PC.
Its complex and diffic
Hello,
I noticed a few messages using
[EMAIL PROTECTED] in the headers. (To, From, CC).
The domain part is random, sometimes I see juno.com or
hotmail.com or china.com but I have many others.
Can someone help me create a custom rule to trap
this?
Thank you,
Frederic TaraseviciusInternet I
Title: Advice on gateway config?
I'm building a small gateway that will sit in front of an Exchange system - sending 'ham' through to the user and redirecting 'spam' to another email address - which will be a 'public' folder probably.
Scott L Henderson's guide to using Amavis and Postfix t
> -Original Message-
> From: Covington, Chris [mailto:[EMAIL PROTECTED]
> Sent: Friday, August 01, 2003 10:20 AM
> To: [EMAIL PROTECTED]
> Subject: [SAtalk] sa-learn and exchange
>
>
> Hi all,
>
> Has anyone thought of/found an automated solution to removing messages
> from an Exchange
I added the following, is that
correct?
whitelist_from_rcvd
[EMAIL PROTECTED] sourceforge.net
--Harri Pesonen
I used to file high scoring spam into /dev/null with no ill-effect, but went
to keeping it all in a spam folder, to be saved for future Bayes scoring and
regression runs.
> -Original Message-
> From: Kai MacTane
> Sent: Monday, August 04, 2003 11:23 AM
>
[...]
> >A good day is when no s
At 8/4/03 12:49 PM , Chris Santerre wrote:
Well you could make a header rule to look for a time in the date field
between 20-24 or 0-6 and give them some points. But I would score it small
and see how it pans out. I might try it for kicks this week.
I wouldn't use the Date: field; that can easily
Now can you tell me why mine refuses to do mysql lookups? ;-)
> -Original Message-
> From: Greg Nowicki [mailto:[EMAIL PROTECTED]
> Sent: Monday, August 04, 2003 3:52 PM
> To: Rob Hutton
> Cc: [EMAIL PROTECTED]
> Subject: Re: [SAtalk] Bayes not working
>
>
> The -D output gave me th
Hello,
I noticed an issue with 2.55 and the test for
FORGED_JUNO_RCVD,
The reverse dns for juno customers is: untd.com
This causes a false positive for juno customers.
Thanks,
Frederic TaraseviciusInternet Information Services, Inc.http://www.i-is.com/
> -Original Message-
> From: Mark Emerle [mailto:[EMAIL PROTECTED]
> Sent: Thursday, July 31, 2003 5:29 PM
> To: [EMAIL PROTECTED]
> Subject: [SAtalk] [RD] Creating rule for time accepted
>
>
> Hi-
>
> Someone in our office presented this to me. Is there a
> way to create a rule
I have installed Spamassassin 2.55 on HPUX 11.0, with perl 5.8.0 and
integrated it with iPlanet Messaging server. All email going through
the spamassassin process takes 23 to 25 seconds. I have set the
timelog_path to get times for events, but nothing really shows up
there. I see only 1.000s for
At Mon Aug 4 19:28:18 2003, Andrew Clarke wrote:
>
> I've been using SpamAssassin for a couple weeks now, so I'm still pretty
> new to it. I have use_bayes 1 and auto_learn 1 in my
> .spamassassin/user_prefs file so shouldn't that mean that it autolearns
> from my email?
Yes. But it won't auto
> -Original Message-
> From: Kai MacTane [mailto:[EMAIL PROTECTED]
> Sent: Monday, August 04, 2003 2:23 PM
> To: [EMAIL PROTECTED]
> Subject: RE: [SAtalk] Wired Article
>
>
> At 8/4/03 10:36 AM , Gary Funck wrote:
>
> >Nice article. Rather than looking for higher scores, I like
> writ
Carey Jung writes:
> Could somebody explain to me why the BAYES_80 score for local-with-bayes
> (5th column, 5.300) is higher than the BAYES_90 and BAYES_99 scores? This
> seems counter-intuitive.
This should be a FAQ, if it isn't already.
Basically, the GA looks at the overall success rate --
I am trying to setup a mail sever to use
spamassasin form spam scanning and it works just fine. but only for locally
delivered emails and ones originating from the server. my current setup is
this
sendmail 8.11.6
procmail as the mta
redhat linux
I have a few domains that I want to scan th
Ok, makes sense ... I never thought about whitelisting the list for the
simple fact that I never had a problem with the messages being marked as
spam.
I'll check into the bayes poisoning you mentioned; thanks for the tip!
Regards,
Matt.
-Original Message-
From: Matt Kettler [mailto:[EMAI
Thanks for the tip. I'm new to SpamAssassin and this list.
So if I just move my procmail rule for this list above my call to spamc,
that will work, right? Then email from this list will be moved out of
my mailbox and into another one before spamassassin is run on my inbox.
Thanks,
- Andrew.
--
I've been using SpamAssassin for a couple weeks now, so I'm still pretty
new to it. I have use_bayes 1 and auto_learn 1 in my
.spamassassin/user_prefs file so shouldn't that mean that it autolearns
from my email?
If I run "sa-learn --ham --mbox some_folder", it learns from the
contents of the fol
I'm running SA 2.55. It uses the following Bayes scores out of the box:
score BAYES_00 0 0 -5.300 -5.200
score BAYES_01 0 0 -5.400 -5.400
score BAYES_10 0 0 -5.300 -4.701
score BAYES_20 0 0 -4.701 -2.601
score BAYES_30 0 0 -1.070 -0.927
score BAYES_40 0.0
score BAYES_44 0.0
score BAYES_50 0.0
sco
At 8/4/03 10:36 AM , Gary Funck wrote:
Nice article. Rather than looking for higher scores, I like writing new
rules that stomp out the latest vermin that sneak under the radar screen.
A good day is when no spams show up in my inbox.
Same here. I redirect anything scoring over about 7 points stra
At 01:02 PM 8/4/2003 -0400, Matthew Moldvan wrote:
Hey there Andrea,
Looks like this was caught by mine (and probably most people's) spam filters
... can you repost the question with the spam attached instead of in the
body? That should help ...
Matthew, if you're running this list through SA wit
> -Original Message-
> From: Mark [mailto:[EMAIL PROTECTED]
> Sent: Friday, August 01, 2003 5:24 PM
> To: Gary Funck; Spamassassin List
> Subject: Re: [SAtalk] those pesky small v*agra ads
>
>
> - Original Message -
> From: "Gary Funck" <[EMAIL PROTECTED]>
> To: "Spamassassin L
Nice article. Rather than looking for higher scores, I like writing new
rules
that stomp out the latest vermin that sneak under the radar screen. A good
day
is when no spams show up in my inbox.
> -Original Message-
> From: Tim
> Sent: Monday, August 04, 2003 9:19 AM
> To: [EMAIL PROTECTE
Hey there Andrea,
Looks like this was caught by mine (and probably most people's) spam filters
... can you repost the question with the spam attached instead of in the
body? That should help ...
Regards,
Matt.
-Original Message-
From: Andrea Riela [mailto:[EMAIL PROTECTED]
Sent: Saturda
Interestingly, 2.60(cvs dated 6/30) and Bayes did a pretty good job on this
(I'm using the default cut off of 5, but the result is well over that).
Content analysis details: (11.5 points, 5.0 required)
0.3 NO_REAL_NAME From: does not include a real name
1.6 SUBJ_HAS_SPACESSu
Hi Guys,
Thought you might enjoy this article on Wired:
http://www.wired.com/news/culture/0,1284,59859,00.html
I enjoy wading through each morning's batch of spam looking for high
scores too.
Later--
Tim
--
Timothy J. Schutte | AIM: TimSchutte | ICQ: 57061028
[EMAIL PROTECTED] | Yah
> -Original Message-
> From: Chris Santerre
> Sent: Monday, August 04, 2003 8:53 AM
[...]
> >
> >
>
> I'm a little behind in reading and writing today :)
>
> You could try the NOT function, that's what I call it :)
>
> /rem[^o]ve/i would give you everything BUT remove with an 'o'.
> But
Rob,
Not directly related, but setting ERRORCODE=67, which will return "no such
user"
back to the sender, isn't very useful on spam, because spammers fake their
from
addresses, and most of the time those from addresses point to non-existent
users.
It probably will only serve to confuse your friend
> -Original Message-
> From: Gary Funck [mailto:[EMAIL PROTECTED]
> Sent: Saturday, August 02, 2003 4:30 PM
> To: Spamassassin List
> Subject: [SAtalk] How to detect *only* obfuscated strings?
>
>
>
>
> Simple example:
>
> body REMOVE_OBFUSCATE
> /(Rem(o|0)ve|Delete).{0,10}y(o|0)ur.{
> Personaly, based on their policies, I'm bewildered why anyone
> would ever use DCC in the first place on a "general purpose" type mail
> account. I could see it being pretty useful on an account that
subscribes to no
> mailing lists (commercial or conversational). That said, I'm
> certainly n
> I tried to create it with a mkdir in the users mail folder, but I can
not acces it through things like squirrelmail.
because you need to subscribe the folder as well. here is part of my
maildrop filter i use to do it automagically
`test -d $VHOME/Maildir/.Spam`
if ( $RETURNCODE == 1 )
{
`/u
Do I need to create the spam folder first?
Also, is this what you are adding to each users .procmailrc file?
Rob
- Original Message -
From: "Thomas Cameron" <[EMAIL PROTECTED]>
To: "Rob Freeman" <[EMAIL PROTECTED]>;
<[EMAIL PROTECTED]>
Sent: Monday, August 04, 2003 9:58 AM
Subject: Re:
I am also using RH9 and sendmail. Here's what ours look like:
LOGFILE=$HOME/.log.procmail
DROPPRIVS=yes
:0
* ^^rom[ ]
{
LOG="*** Dropped F off From_ header! Fixing up. "
:0 fhw
| sed -e '1s/^/F/'
}
:0:
* ^X-Spam-Status: Yes
mail/spam
It might not be the best way, but it works just as yo
(BHello Alan,
(B
(B> -Original Message-
(B> From: alan premselaar
(B> Sent: Sunday, August 03, 2003 11:52 PM
(B>
(B> On 8/4/03 3:20 PM, "Gary Funck" <[EMAIL PROTECTED]> wrote:
(B>
(B> [...]
(B> >
(B> > The problem is that I saw things like,
(B> >
(B> > X-Spam-Checker-Version:
How do I get spam found with spamassasin to go to a
users folder called spam? I am running redhat 9 with sendmail. I now
get the spam in the users inbox. I tried this, but I do not have a spam
folder:
Procmail preferences
1: MAILDIR=$HOME/mail2: 3: :0 H4: *
^X-Spam-Status:.*Yes5:
I did up a real quick and dirty on Friday to keep them out of our
network. We block high scores, so this made sure no one (else) got it in
their inbox. I set the score to 150 to overcome any white lists.
header YOURACCOUNTH Subject =~ /^your account /
describe YOURACCOUNTH Possible virus
Simon Byrnand wrote:
At 21:06 3/08/2003 -0600, Bob Proulx wrote:
Simon Byrnand wrote:
> Why would anyone submit the SA list to DCC ? The only people
receiving the
> SA list should be people who subscribed to it, and would have no
reason to
> go submitting it to DCC, so I don't follow your reason
At 05:02 PM 8/4/03 +1200, you wrote:
I think you're missing my point. I never said DCC wasn't about bulk mail.
However I question your premise that anyone would *knowingly* submit a
mailing list that they *deliberately* subscribed to, to a bulk detector
like DCC. If they did, they're just being
Hi,
Anyone have anything as far as a rule for blocking the latest microsoft
worm that comes as a mail from and admin of your domain and (so far the
header is X-Mailer: The Bat!(v1.61))
Claims that your account is about to expire with a message.zip attached.
Rules?
-Matt Chapman
--
Matt Chapman
N
On Sun, 3 Aug 2003, Matt Kettler wrote:
> In theory you should feed your bayes engine a fairly balanced
> diet of spam and nonspam, without consideration of wether or
> not SA caught it.
I send anything scoring 10 or greater directly to /dev/null, so
these highly spammy messages are not includ
Hey Justin,
Fuzzy Fox suggested a similar route. The Bayes token is a great
possibility. The tokens in this case would be time rather than words.
One way to accomplish this task is to just give local.cf assignments that
would score during a specific time interval. This would allow the
administ
> On Sun, 3 Aug 2003 23:48:44 -0400 Daniel Carrera <[EMAIL PROTECTED]>
> wrote:
>
>> How do I find out which one my system has? This is a UNIX network.
>
> You'd have to look at the SA docs or in the score sets; I'm not sure
> which ones SA uses out-of-the-box. I prefer the open proxy lists, dialu
* Cahya Wirawan <[EMAIL PROTECTED]>:
> > > but our domain I get daily around 20 000 return messages to user that
> > > dont exist
> >
> > Why do you accept mail to non-existing users at your site?
> >
>
> If you use incoming email gateway and all emails will be sent again to
> another mail se
On Mon, Aug 04, 2003 at 11:24:18AM +0200, Ralf Hildebrandt wrote:
>
> > but our domain I get daily around 20 000 return messages to user that
> > dont exist
>
> Why do you accept mail to non-existing users at your site?
>
If you use incoming email gateway and all emails will be sent again to
On Mon, 04 Aug 2003 13:21:23 +1200, you wrote:
>At 11:57 3/08/2003 -0600, Bob Proulx wrote:
>>Please, one posting of the same message is enough.
>>
>>Michael W. Cocke wrote:
>> > Has anyone who uses DCC had problems with it stopping this mailing
>> > list?
>>
>>DCC does not stop any mail. It only
> swapna ghosh <[EMAIL PROTECTED]> wrote:
>>
>> But i am getting information from our clients that they are getting
>> spam mails - that means few mails are not being filtered by
>> spamc/spamd.
>
> The correct response here is to tell your clients that there is no such
> thing as a 100% spam detec
* Michal Gubik <[EMAIL PROTECTED]>:
> okey the problem is that someone spamed using some non existing username
Oh my.
> but our domain I get daily around 20 000 return messages to user that
> dont exist
Why do you accept mail to non-existing users at your site?
> and they bounce to postmaste
okey the problem is that someone spamed using some non existing username
but our domain I get daily around 20 000 return messages to user that
dont exist and they bounce to postmaster that is set to my username all
of them had one thing in common and that was null from but I got it now
I filter
On 8/4/03 3:20 PM, "Gary Funck" <[EMAIL PROTECTED]> wrote:
(B
(B[...]
(B>
(B> The problem is that I saw things like,
(B>
(B> X-Spam-Checker-Version: SpamAssassin 2.60-cvs (1.195-2003-06-30-exp) on
(B> screamerX-Spam-Level: ***
(B> X-Spam-Status: No, hits=3.0 required=5.0 tests=BAYES_99 a
> -Original Message-
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] Behalf Of Fuzzy
> Fox
> Sent: Sunday, August 03, 2003 10:13 PM
> To: Spamassassin List
> Subject: [SAtalk] Re: SA cv6 2.60 - Bayes auto learn set by default?
>
>
> Gary Funck <[EMAIL PROTECTED]> wrote:
> >
> > Is t
74 matches
Mail list logo