Re: Trying to catch spoofed ToCc

2006-12-07 Thread hamann . w
Hi, I am doing exactly that for my personal mailbox, and it took me a few months to define all my exceptions (mostly mailing list and forum related). Are you sure you want to do this for hundreds of domains Wolfgang Hamann >> This is a multi-part message in MIME format. >> >> --_=_NextP

Re: Rule update over DNS?

2006-12-07 Thread Daryl C. W. O'Shea
Duncan Findlay wrote: Anyways... maybe I should get back to doing something useful like studying for tomorrow's exam... Boo exams... road trip! I hear the 401 is fun at this time of year. ;)

Re: rules_du_jour not working confusion?

2006-12-07 Thread Matt Kettler
Daryl C. W. O'Shea wrote: > > [EMAIL PROTECTED] dos]$ grep " CF_URLS\[" rules_du_jour | grep -v > RULESEMPORIUM > > CF_URLS[7]="http://mywebpages.comcast.net/mkettler/sa/antidrug.cf"; > > > antidrug.cf isn't being updated ever again and it's not for use with > SA 3.x or later (which excludes it's

Re: Rule update over DNS?

2006-12-07 Thread Duncan Findlay
On Thu, Dec 07, 2006 at 08:56:45PM +1300, Jason Haar wrote: > If all SA users set sa-update to run hourly - then when an update comes > out, you will have *all* SA users contacting the same sites > simultaneously for the downloads. Och... That's a good point. Those of us packaging SpamAssassin

Re: spam

2006-12-07 Thread Duncan Findlay
On Thu, Dec 07, 2006 at 10:47:01AM -0500, Fred T wrote: > > Considering headers are not part of the body, I'd say that if body rules > > match against the subject, then either the documentation in the wiki is > > misleading and needs to be changed, or there's a problem with the body > > rules behav

Re: Rule update over DNS?

2006-12-07 Thread Duncan Findlay
On Thu, Dec 07, 2006 at 01:38:54PM -0500, Jim Maul wrote: > >>I dont think anyone is using spamd to call SpamAssassin. > oh? Care to explain how spamd would call spamassassin? That would be a neat > trick ;) Alright... I'm being pedantic, but you're confusing "spamassassin" and "SpamAssassin".

Re: Google open relay?

2006-12-07 Thread David B Funk
On Thu, 7 Dec 2006, Steven Stern wrote: > David B Funk wrote: > > If you buy into the spamcop premium service one of the things that > > you gain is the ability to modify their report and add such notices. > > Best to send it directly to Google's abuse address. > Spamcop sent a report to both sha

RE: blacklist messagID ?

2006-12-07 Thread John D. Hardin
On Thu, 7 Dec 2006, Jean-Paul Natola wrote: > > > Can I blacklist a message without blacklisting the sender? > > > > Sure. Write a rule for that message-ID header and give it a score of > > 1000 or so (adding insult to injury). > > > > I'm not exactly well versed, scratch that , I DO NOT KNOW how

Re: Botnet 0.6 plugin for Spam Assassin availabile

2006-12-07 Thread John Rudd
Michael Schaap wrote: John Rudd wrote: It would be great if Botnet could do something similar, like: 2.0 BOTNET The submitting mail server looks like part of a Botnet [ip=12.34.56.789 rdns=dhcp12.34.example.org] Any tips on how to do that? :-}

Re: spam

2006-12-07 Thread Chris
On Tuesday 05 December 2006 3:31 pm, Rosenbaum, Larry M. wrote: > Has anybody come up with a rule for these yet? I tried the following: > > body ORNL_B0RKEN1 /^\d{3,5}\n{1,3}$/s > describe ORNL_B0RKEN1 B0rken spamware, message just contains a short > number > scoreORNL_B0RKEN1 1 > I believ

Re: Botnet 0.6 plugin for Spam Assassin availabile

2006-12-07 Thread Michael Schaap
John Rudd wrote: It would be great if Botnet could do something similar, like: 2.0 BOTNET The submitting mail server looks like part of a Botnet [ip=12.34.56.789 rdns=dhcp12.34.example.org] Any tips on how to do that? :-} Well, I had a look,

RE: blacklist messagID ?

2006-12-07 Thread Jean-Paul Natola
On Thu, 7 Dec 2006, Jean-Paul Natola wrote: > > Apparently a remote server is having issues- > > It keeps sending this message here- > > > > [EMAIL PROTECTED] > > > > Can I blacklist a message without blacklisting the sender? > > Sure. Write a rule for that mess

Re: Botnet 0.6 plugin for Spam Assassin availabile

2006-12-07 Thread John Rudd
Michael Schaap wrote: John Rudd wrote: The next version of the Botnet plugin for Spam Assassin is ready. The install instructions are in the Botnet.txt file, and in the INSTALL file. Great work! To Do before 1.0: (...) There's another thing that would be really nice to have. You k

Re: Google open relay?

2006-12-07 Thread Steven Stern
David B Funk wrote: > On Thu, 7 Dec 2006, Steven Stern wrote: > >> John D. Hardin wrote: >>> On Thu, 7 Dec 2006, Steven Stern wrote: >>> I've been getting lots of these "get out of debt" messages. It looks like the last stop before getting here is a gmail server. Could they have an

Re: Score=x+5

2006-12-07 Thread Mark Martinec
On Thursday December 7 2006 18:21, Fred T wrote: > > -0.0 P0F_UNIX OS fingerprint BSD/Solaris/HP-UX/Tru64 > I'm curious about P0F_UNIX could you share this rule with me? And any > similar fingerprint rules? Thanks! The rules are quite straightforward (see below) - just matching on

Re: Trying to catch spoofed ToCc

2006-12-07 Thread Mike Pepe
Loren Wilton wrote: Nasty to do without using a plugin or eval rule, but it can be done. The following is off the top of my head, and I almost guarantee it won't work correctly without testing and some minor tweak somewhere. But you can try it and/or fool with it if you like. header __SENT_T

Re: Botnet 0.6 plugin for Spam Assassin availabile

2006-12-07 Thread Michael Schaap
John Rudd wrote: The next version of the Botnet plugin for Spam Assassin is ready. The install instructions are in the Botnet.txt file, and in the INSTALL file. Great work! To Do before 1.0: (...) There's another thing that would be really nice to have. You know how the DNS rules'

Re: Trying to catch spoofed ToCc

2006-12-07 Thread Loren Wilton
Trying to catch spoofed ToCcNasty to do without using a plugin or eval rule, but it can be done. The following is off the top of my head, and I almost guarantee it won't work correctly without testing and some minor tweak somewhere. But you can try it and/or fool with it if you like. header __

Re: forwarding email

2006-12-07 Thread aubreyL
Jonas Eckerman wrote: This really would be more on topic on the MIMEDefang list, but here goes... You have a small but significant typo in your code: if ($hits >= req) { You forgot the "$" in "$req". The effect of the above comparison is that all mail that scores above 0

Re: Google open relay?

2006-12-07 Thread David B Funk
On Thu, 7 Dec 2006, Steven Stern wrote: > John D. Hardin wrote: > > On Thu, 7 Dec 2006, Steven Stern wrote: > > > >> I've been getting lots of these "get out of debt" messages. It > >> looks like the last stop before getting here is a gmail server. > >> Could they have an open relay? > > > > Have

Re: Spamassassin doesn't ding sender for saying "HELO i-am-you"

2006-12-07 Thread Loren Wilton
Having it set up automagically is a great idea. But it is worth considering as a config option IMO. After all, it is already necessary in many cases to config trusted_networks and internal_networks. So it isn't like SA will always run optimally without some local user input. I'd simply sugg

Trying to catch spoofed ToCc

2006-12-07 Thread Jason Oriente
> In my mail setup, it is gospel that (ignoring BCC and mailing lists) > the full email address in the Delivered-To will match an email address > in the ToCc. > Example below. > > Return-Path: <[EMAIL PROTECTED]> > Delivered-To: [EMAIL PROTECTED] > Received: from mx01.domain.ext (unknown [172.1

Re: Help with understanding a rule

2006-12-07 Thread Loren Wilton
Yes, you are probably right. But: there must be a reason why the rule no_real_name exists? Yes. It successfully HELPS to detect spam. It is not, on its own, a good method to detect spam. That is why it normally has a low score. And if there is a rule (written or not) that From: headers s

Re: Google open relay?

2006-12-07 Thread Evan Platt
At 02:52 PM 12/7/2006, you wrote: Have you notified <[EMAIL PROTECTED]>? You're kidding right? I've given up on e-mailing google about blogspot pages, or anything else. They could care less.

Re: Google open relay?

2006-12-07 Thread Steven Stern
John D. Hardin wrote: On Thu, 7 Dec 2006, Steven Stern wrote: I've been getting lots of these "get out of debt" messages. It looks like the last stop before getting here is a gmail server. Could they have an open relay? Have you notified <[EMAIL PROTECTED]>? You betcha! And al

How do I know if DCC is running and working?

2006-12-07 Thread Vernon Webb
Subject says it all. How can I tell if DDC is running and working on my system? Thanks

Re: Google open relay?

2006-12-07 Thread John D. Hardin
On Thu, 7 Dec 2006, Steven Stern wrote: > I've been getting lots of these "get out of debt" messages. It > looks like the last stop before getting here is a gmail server. > Could they have an open relay? Have you notified <[EMAIL PROTECTED]>? -- John Hardin KA7OHZhttp://ww

RE: How can I learn a mail which how many score it got from each my rules?

2006-12-07 Thread Larry Rosenman
Halid Faith wrote: > I use spamassassin3.1.7 > > I go through some mails. > I see a mail in /var/log/spamd.log as below Wed Dec 6 13:33:49 2006 > [4484] info: spamd: result: Y 15 - > EXTRA_MPART_TYPE,FRONTPAGE,HTML_MESSAGE,INVALID_DATE,MIME_BOUND_NEXTPART > ,MIME_QP_LONG_LINE,MSGID_MULTIPLE_AT,SA

Re: How can I learn a mail which how many score it got from each my rules?

2006-12-07 Thread John D. Hardin
On Fri, 8 Dec 2006, Halid Faith wrote: > I go through some mails. > I see a mail in /var/log/spamd.log as below > Wed Dec 6 13:33:49 2006 [4484] info: spamd: result: Y 15 - > EXTRA_MPART_TYPE,FRONTPAGE,HTML_MESSAGE,INVALID_DATE,MIME_BOUND_NEXTPART > ,MIME_QP_LONG_LINE,MSGID_MULTIPLE_AT,SARE_GIF_A

How can I learn a mail which how many score it got from each my rules?

2006-12-07 Thread Halid Faith
I use spamassassin3.1.7 I go through some mails. I see a mail in /var/log/spamd.log as below Wed Dec 6 13:33:49 2006 [4484] info: spamd: result: Y 15 - EXTRA_MPART_TYPE,FRONTPAGE,HTML_MESSAGE,INVALID_DATE,MIME_BOUND_NEXTPART ,MIME_QP_LONG_LINE,MSGID_MULTIPLE_AT,SARE_GIF_ATTACH,SARE_OBFUGIRLS,SUBJ

Google open relay?

2006-12-07 Thread Steven Stern
I've been getting lots of these "get out of debt" messages. It looks like the last stop before getting here is a gmail server. Could they have an open relay? Received: from ccim-mx2.cciminstitute.com ([10.0.2.10]) by ccim-exchange.cciminstitute.com with Microsoft SMTPSVC(6.0.3790.1830);

RE: blacklist messagID ?

2006-12-07 Thread John D. Hardin
On Thu, 7 Dec 2006, Jean-Paul Natola wrote: > > Apparently a remote server is having issues- > > It keeps sending this message here- > > > > [EMAIL PROTECTED] > > > > Can I blacklist a message without blacklisting the sender? > > Sure. Write a rule for that message-ID header and give it a score

RE: blacklist messagID ?

2006-12-07 Thread Jean-Paul Natola
> Apparently a remote server is having issues- > It keeps sending this message here- > > [EMAIL PROTECTED] > > Can I blacklist a message without blacklisting the sender? Sure. Write a rule for that message-ID header and give it a score of 1000 or so (adding insult to injury). I'm not exactly

Re: blacklist messagID ?

2006-12-07 Thread John D. Hardin
On Thu, 7 Dec 2006, Jean-Paul Natola wrote: > Apparently a remote server is having issues- > It keeps sending this message here- > > [EMAIL PROTECTED] > > Can I blacklist a message without blacklisting the sender? Sure. Write a rule for that message-ID header and give it a score of 1000 or so (

Re: What is the correct way of whitelisting local mail?

2006-12-07 Thread John D. Hardin
On Fri, 8 Dec 2006, Robert S wrote: > > Determine what is passing messages to SA and tell it to not do that > > with locally-sources messages. If you use procmail to launch spamc > > this is pretty easy to do. > > I use procmail. I could do this in /etc/procmailrc: > > :0fw: spamassassin.lock >

RE: blacklist messagID ?

2006-12-07 Thread Jean-Paul Natola
Subject: Re: blacklist messagID ? On Thu, 2006-12-07 at 16:00 -0500, Jean-Paul Natola wrote: > Apparently a remote server is having issues- > It keeps sending this message here- > > [EMAIL PROTECTED] > > Can I blacklist a message without blacklisting the sender? Is the sending host someone tha

Re: blacklist messagID ?

2006-12-07 Thread Adam Lanier
On Thu, 2006-12-07 at 16:00 -0500, Jean-Paul Natola wrote: > Apparently a remote server is having issues- > It keeps sending this message here- > > [EMAIL PROTECTED] > > Can I blacklist a message without blacklisting the sender? Is the sending host someone that you care about receiving messages

blacklist messagID ?

2006-12-07 Thread Jean-Paul Natola
Apparently a remote server is having issues- It keeps sending this message here- [EMAIL PROTECTED] Can I blacklist a message without blacklisting the sender? Jean-Paul Natola Network Administrator Information Technology Family Care International 588 Broadway Suite 503 New York, NY 10012

Re: Recognizing Sendmail's authentication -- patch included (WAS: How is LOCAL_AUTH_RCVD used?)

2006-12-07 Thread Jo Rhett
On Dec 5, 2006, at 4:17 PM, Daryl C. W. O'Shea wrote: Jo Rhett wrote: While you are fixing bugs related to authentication, any chance you'll fix the SPF plugin to skip checks on authenticated delivery? Or have an option to enable this behavior? Or do you want a patch from me? It'll take me

RE: Spam: New to Spamassassin

2006-12-07 Thread Darren Cockburn
Absolutely! All you have to do is set up your spamassassin email server as a smarthost (gateway) email server then forward all scanned email to your exchange or groupwise server. - Darren. From: Development [mailto:[EMAIL PROTECTED] Sent: Thursday, Dec

Re: What is the correct way of whitelisting local mail?

2006-12-07 Thread Robert S
Determine what is passing messages to SA and tell it to not do that with locally-sources messages. If you use procmail to launch spamc this is pretty easy to do. I use procmail. I could do this in /etc/procmailrc: :0fw: spamassassin.lock * < 256000 * ! From: .*mydomain.com | /usr/bin/spamc ..

Re: Rule update over DNS?

2006-12-07 Thread Daryl C. W. O'Shea
Jim Maul wrote: oh? Care to explain how spamd would call spamassassin? That would be a neat trick ;) Neat, but really simple with the plugin interface. :)

RE: our latest award!

2006-12-07 Thread Sietse van Zanen
Nah, that's overdone. The "linux-based' is waaay too much said... :-) -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Sent: Thursday, December 07, 2006 7:43 PM To: users@spamassassin.apache.org Subject: our latest award! I think I noted this honour on the dev list a

Re: ***SPAM*** SpamAssassin dns timeouts... why?!

2006-12-07 Thread Richard D Alloway
On Thu, 7 Dec 2006, Jeff Chan wrote: On Wednesday, December 6, 2006, 2:19:11 PM, Richard Alloway wrote: Any idea what could be wrong? I'm rapidly running out of ways to try to increase performance here. Net::DNS uses the first server in your resolv.conf . Make sure that server works, is loc

Re: Spamassassin doesn't ding sender for saying "HELO i-am-you"

2006-12-07 Thread Ben O'Hara
On 12/7/06, Kelly Jones <[EMAIL PROTECTED]> wrote: Spamassassin has lots of tests for fake HELOs. If someone says "HELO hotmail.com", but aren't connecting from a Hotmail IP address, they get dinged (spam score is increased). Recently, someone connected our server, call it mx.xyz.com, and said "

Re: New to Spamassassin

2006-12-07 Thread Rick Macdougall
Development wrote: I would like to know if it is possible to use spamassassin on one server to filter mail and then deliver it to a seperate mail server on the network running exchange, groupwise, etc? Hi, Easiest way is to setup a Unix based MTA (I prefer the Qmail/Simscan setup, but what e

Re: Rule update over DNS?

2006-12-07 Thread Justin Mason
Jim Maul writes: > Justin Mason wrote: > > Jim Maul writes: > >> Kelson wrote: > >>> Jason Haar wrote: > May I propose that sa-update should become merged into spamd? (or > daemonized) > >>> Merging would be bad. There are plenty of us using methods other than > >>> spamd to call SpamAs

Re: Spamassassin doesn't ding sender for saying "HELO i-am-you"

2006-12-07 Thread John D. Hardin
On 7 Dec 2006 [EMAIL PROTECTED] wrote: > >> > >> On Wed, 6 Dec 2006, Kelly Jones wrote: > >> > >> > Recently, someone connected our server, call it mx.xyz.com, and said > >> > "HELO mx.xyz.com". Spamassassin didn't ding it for doing this. > >> > >> IMHO this is worthy of a 500 reject at the MTA

RE: New to Spamassassin

2006-12-07 Thread Jean-Paul Natola
I would like to know if it is possible to use spamassassin on one server to filter mail and then deliver it to a seperate mail server on the network running exchange, groupwise, etc? YES I use it to filter my mail - then pass it to exchange- But the server that has SA must have an MTA and sinc

our latest award!

2006-12-07 Thread Justin Mason
I think I noted this honour on the dev list a week or two ago -- but the _physical_ award for 'Best Linux-based Anti-spam Solution' from the Linux New Media Awards 2006 just turned up, and that warrants another post ;) Take a look: http://taint.org/2006/12/07/140259a.html w00t, --j.

Re: Rule update over DNS?

2006-12-07 Thread Jim Maul
Justin Mason wrote: Jim Maul writes: Kelson wrote: Jason Haar wrote: May I propose that sa-update should become merged into spamd? (or daemonized) Merging would be bad. There are plenty of us using methods other than spamd to call SpamAssassin. I dont think anyone is using spamd to call Spam

deny messageID

2006-12-07 Thread Jean-Paul Natola
I know this may sound weird but, I have this message ( a valid one) that keeps coming in The senders machine is off so I'm not really sure whats going on Its been happening for about 36 hours now- its odd that this message is in both the mainlog AND the rejectlog- My thought is if I deny that

Botnet 0.6 plugin for Spam Assassin availabile

2006-12-07 Thread John Rudd
(I had a bout of insomnia last night, and got more done than I had pre-announced yesterday...) The next version of the Botnet plugin for Spam Assassin is ready. The install instructions are in the Botnet.txt file, and in the INSTALL file. For those who don't know what Botnet is, it's a pl

Re: Rule update over DNS?

2006-12-07 Thread Justin Mason
Jim Maul writes: > Kelson wrote: > > Jason Haar wrote: > >> May I propose that sa-update should become merged into spamd? (or > >> daemonized) > > > > Merging would be bad. There are plenty of us using methods other than > > spamd to call SpamAssassin. > > I dont think anyone is using spamd to

New to Spamassassin

2006-12-07 Thread Development
I would like to know if it is possible to use spamassassin on one server to filter mail and then deliver it to a seperate mail server on the network running exchange, groupwise, etc?

Re: Rule update over DNS?

2006-12-07 Thread Jim Maul
Kelson wrote: Jason Haar wrote: May I propose that sa-update should become merged into spamd? (or daemonized) Merging would be bad. There are plenty of us using methods other than spamd to call SpamAssassin. I dont think anyone is using spamd to call SpamAssassin.

Re: forwarding email

2006-12-07 Thread Jonas Eckerman
This really would be more on topic on the MIMEDefang list, but here goes... You have a small but significant typo in your code: > if ($hits >= req) { You forgot the "$" in "$req". The effect of the above comparison is that all mail that scores above 0 (zero) are considered spam. R

Re: Spamassassin doesn't ding sender for saying "HELO i-am-you"

2006-12-07 Thread hamann . w
>> >> On Wed, 6 Dec 2006, Kelly Jones wrote: >> >> > Recently, someone connected our server, call it mx.xyz.com, and said >> > "HELO mx.xyz.com". Spamassassin didn't ding it for doing this. >> >> IMHO this is worthy of a 500 reject at the MTA level. There is NO >> legitimate reason for J. Random

RE: Spamassassin doesn't ding sender for saying "HELO i-am-you"

2006-12-07 Thread Larry Rosenman
John D. Hardin wrote: > On Wed, 6 Dec 2006, Kelly Jones wrote: > >> Recently, someone connected our server, call it mx.xyz.com, and said >> "HELO mx.xyz.com". Spamassassin didn't ding it for doing this. > > IMHO this is worthy of a 500 reject at the MTA level. There is NO > legitimate reason for

Re: local.cf

2006-12-07 Thread Steven Stern
Andrea Bencini wrote: I am looking for local.cf documentation to understand which are the variables to set in this file. Can you help me? Thank Andrea man Mail::SpamAssassin::Conf

Re: What is the correct way of whitelisting local mail?

2006-12-07 Thread John D. Hardin
On Thu, 7 Dec 2006, Robert S wrote: > I'm trying to stop SA from incorrectly labeling local messages as > spam. The most common target is a weekly script that notifies the > user of quarantined spams. The subject lines of each message fire off > a false positive. Determine what is passing messa

Re: Rule update over DNS?

2006-12-07 Thread Kelson
Jason Haar wrote: May I propose that sa-update should become merged into spamd? (or daemonized) Merging would be bad. There are plenty of us using methods other than spamd to call SpamAssassin. -- Kelson Vibber SpeedGate Communications

Re: Spamassassin doesn't ding sender for saying "HELO i-am-you"

2006-12-07 Thread John D. Hardin
On Wed, 6 Dec 2006, Kelly Jones wrote: > Recently, someone connected our server, call it mx.xyz.com, and said > "HELO mx.xyz.com". Spamassassin didn't ding it for doing this. IMHO this is worthy of a 500 reject at the MTA level. There is NO legitimate reason for J. Random User out on the internet

local.cf

2006-12-07 Thread Andrea Bencini
I am looking for local.cf documentation to understand which are the variables to set in this file. Can you help me? Thank Andrea

Re: Score=x+5

2006-12-07 Thread Fred T
Hello Alan, Wednesday, November 29, 2006, 8:23:14 PM, you wrote: > -0.0 P0F_UNIX OS fingerprint BSD/Solaris/HP-UX/Tru64 I'm curious about P0F_UNIX could you share this rule with me? And any similar fingerprint rules? Thanks! -- Best regards, Fredma

Re: Synchronizing two Bayes database

2006-12-07 Thread Emmanuel Lesouef
Yes, I was thinking about this solution. But isn't it network ressource hungry ? And if I would like to keep a files based bayes db, what should be the good manner to migrate one to another server ? Thanks Sietse for the advice. Sietse van Zanen a écrit : > Sure, use MySQL for bayes storage and

Re: What is the correct way of whitelisting local mail?

2006-12-07 Thread Nels Lindquist
Robert S wrote: I'm trying to stop SA from incorrectly labeling local messages as spam. The most common target is a weekly script that notifies the user of quarantined spams. The subject lines of each message fire off a false positive. What is the correct way of whitelisting local mail? The

Re: Percentage of email that is spam after filtering?

2006-12-07 Thread aubreyL
Fred T wrote: Hello Kelly, Friday, November 24, 2006, 8:28:38 PM, you wrote: I know that most (90%+) email sent now is spam, but what are the numbers for people who use spam filtering? Well, I run a small ISP with about 3,000 mailboxes, we receive about 50k messages per day. Of that

Re: SV: Help with understanding a rule

2006-12-07 Thread Michael Scheidell
[EMAIL PROTECTED] wrote: >> The list managers are the first ones who have to change. >> >> > > Yes, you are probably right. But: there must be a reason why the > rule no_real_name exists? And if there is a rule (written or not) > that From: headers should contain a real name, I want to follow

Re: Percentage of email that is spam after filtering?

2006-12-07 Thread Fred T
Hello Kelly, Friday, November 24, 2006, 8:28:38 PM, you wrote: > I know that most (90%+) email sent now is spam, but what are the > numbers for people who use spam filtering? Well, I run a small ISP with about 3,000 mailboxes, we receive about 50k messages per day. Of that, on average 39-44k ar

RE: false positives

2006-12-07 Thread Sietse van Zanen
off-topic) spamcop =?windows-1251?B?4vrv8O7x6A==?= Was that really your subject, did you type that? I think the =?windows-1251?B?4vrv8O7x6A==?= is the double encoded part. Your problem might be the result of some incompatibility between slavic - european character sets. But I'm not suchh an smt

forwarding email

2006-12-07 Thread aubreyL
OS - slackware 11.0 MDA - sendmail 8.13.8 mimedefang version 2.58 SpamAssassin version 3.1.7 running on Perl version 5.8.8 I have one user that has to get email forwarded from an old account to the server that I administer. I have spam going to a spamdrop via MiMEDefang. So I added this lit

Re: false positives

2006-12-07 Thread Kamen TOMOV
On четвъртък, Декември 07 2006, Sietse van Zanen wrote: > They contain too little information. All right - here is more information. I sent a message to a group and I got it classified as spam. Here is the report: * 1.7 SUBJECT_ENCODED_TWICE Subject: MIME encoded twice Here is how the subject

Re: rules_du_jour not working confusion?

2006-12-07 Thread Daryl C. W. O'Shea
Alan Munday wrote: Daryl C. W. O'Shea wrote the following on 06/12/2006 17:31: Is a migration document really necessary? Stop using the rule files you got via RDJ that you now want to get with sa-update. Start using sa-update for those rule files. Have some lunch. Agreed - I do like to l

RE: Synchronizing two Bayes database

2006-12-07 Thread Sietse van Zanen
Sure, use MySQL for bayes storage and have both servers use that DB. Then you could be fairly sure, both use the same bayes. I think it should even be possible to dump both databases and migrate into one SQL db. But I don't use MySQL myself, so I would not know how. -Sietse From: Emmanuel L

Re: ***SPAM*** SpamAssassin dns timeouts... why?!

2006-12-07 Thread Jeff Chan
On Wednesday, December 6, 2006, 2:19:11 PM, Richard Alloway wrote: > Any idea what could be wrong? I'm rapidly running out of ways to try to > increase performance here. Net::DNS uses the first server in your resolv.conf . Make sure that server works, is local, etc. Jeff C. -- Jeff Chan mailto

RE: Re[4]: spam

2006-12-07 Thread Coffey, Neal
Fred T wrote: > 100% sure of this, I've been writing rules for over 2 years, not that > big by some standards, but I've come to know for a very long time this > is how it is. > > [...] > > I know it's been this way, there's probably a really old bugzilla > ticket someone can dig up, but it's been

Synchronizing two Bayes database

2006-12-07 Thread Emmanuel Lesouef
Dear List, This is sort of a repost of a previous email I sent to this list. I have two mailserver acting as mail proxies for ou main mailserver. These two servers have the same sitewide configuration for Spamassassin and they use site-wide bayes databases. For a reason I don't really know, the

RE: No Nework tests?!

2006-12-07 Thread Bowie Bailey
leemansvg wrote: > I'm running spamassasint --lint and it comes up saying that its only > doing local tests. I've enabled dns and I am connected to the > internet. I've also enabled razor, dcc, and pyzor in the > spam.assassin.perfs files. Does anyone have an idea where I might > have a mis-configu

Re[2]: Spamassassin doesn't ding sender for saying "HELO i-am-you"

2006-12-07 Thread Fred T
Hello Justin, Thursday, December 7, 2006, 10:11:45 AM, you wrote: > yeah -- there are any number of ways to do this, if requiring admin > configuration is OK -- I'm asking for ways we can automatically > figure it out from SpamAssassin code, without help. ;) As someone else pointed out, the best

No Nework tests?!

2006-12-07 Thread leemansvg
I'm running spamassasint --lint and it comes up saying that its only doing local tests. I've enabled dns and I am connected to the internet. I've also enabled razor, dcc, and pyzor in the spam.assassin.perfs files. Does anyone have an idea where I might have a mis-configuration. Here's snap in fro

Re[4]: spam

2006-12-07 Thread Fred T
Hello Neal, Wednesday, December 6, 2006, 11:08:27 AM, you wrote: >> Except for the problem that body tests include the subject, so there >> will be non-alpha characters in the body due to the subject inclusion. > Are you sure about that? I find nothing in the documentation that > indicates this

Re: Spamassassin doesn't ding sender for saying "HELO i-am-you"

2006-12-07 Thread Duncan Hill
On Thursday 07 December 2006 15:11, Justin Mason wrote: > yeah -- there are any number of ways to do this, if requiring admin > configuration is OK -- I'm asking for ways we can automatically > figure it out from SpamAssassin code, without help. ;) Really and truly, it belongs at the MTA level, n

Re: SpamAssassin dns timeouts... why?!

2006-12-07 Thread Richard D Alloway
On Thu, 7 Dec 2006, Matthias Häker wrote: Richard D Alloway schrieb: Hi! I have been having loads of problems with spamassassin timing out during DNS lookups... If I use /usr/bin/spamassassin -D < /tmp/spamemail.txt I see the correct IP used for the nameserver: [16018] dbg: dns: name se

Re: Spamassassin doesn't ding sender for saying "HELO i-am-you"

2006-12-07 Thread Justin Mason
Jack L. Stone writes: > On 7 Dec 2006 at 13:21, Justin Mason wrote: > > Kelly Jones writes: > > > Spamassassin has lots of tests for fake HELOs. If someone says > > > "HELO hotmail.com", but aren't connecting from a Hotmail IP > > > address, they get dinged (spam score is increased). > > > > > >

Re: Spamassassin doesn't ding sender for saying "HELO i-am-you"

2006-12-07 Thread Jack L. Stone
On 7 Dec 2006 at 13:21, Justin Mason wrote: > > Kelly Jones writes: > > Spamassassin has lots of tests for fake HELOs. If someone says > > "HELO hotmail.com", but aren't connecting from a Hotmail IP > > address, they get dinged (spam score is increased). > > > > Recently, someone connected our s

RE: SV: Help with understanding a rule

2006-12-07 Thread Sietse van Zanen
Think of this anology: If somebody calls me on my home phone, I immediately see his nr. (If I don't see a nr. I don't pick up my phone at all). Now, the first thing I'd expect someone to say when I pick up is his name. If people start talking to me without stating who they are, it is commercia

Re: Rule update over DNS?

2006-12-07 Thread Theo Van Dinter
On Thu, Dec 07, 2006 at 09:31:36AM +, Justin Mason wrote: > > and got freshclam to run as a daemon - so it > > could randomly sleep between lookups - and thus spread the load. > > I can think of a useful modification -- change sa-update so that, if it's > run non-interactively, it sleeps for a

Re: Spamassassin doesn't ding sender for saying "HELO i-am-you"

2006-12-07 Thread Alan Munday
Justin Mason wrote the following on 07/12/2006 13:21: This is a great spam-sign alright, but I don't know of a way to detect what the local site's HELO is, bar each site writing their own rules to do so. Bayes does a good job of figuring this out, btw. Any suggestions? A script that telnets

Re: SV: Help with understanding a rule

2006-12-07 Thread Chris Lear
* [EMAIL PROTECTED] wrote (07/12/06 12:03): The list managers are the first ones who have to change. Yes, you are probably right. But: there must be a reason why the rule no_real_name exists? And if there is a rule (written or not) that From: headers should contain a real name, I want to follo

RE: false positives

2006-12-07 Thread Sietse van Zanen
They contain too little information. -Sietse From: Kamen TOMOV Sent: Thu 07-Dec-06 14:34 To: users@spamassassin.apache.org Subject: false positives Hi, I constantly have problems with spamcop these days. Could you tell me what's wrong with my messages so that I can fix it? Thanks, -- Камен

false positives

2006-12-07 Thread Kamen TOMOV
Hi, I constantly have problems with spamcop these days. Could you tell me what's wrong with my messages so that I can fix it? Thanks, -- Камен

Re: SA not firing on every email

2006-12-07 Thread guenther
On Thu, 2006-12-07 at 03:12 -0700, Jason Marshall wrote: > > Perhaps SA was too busy and those messages timed out and weren't scanned ? > > Maybe those messages were greater than 250K (default max scan size) ? > > I have the same sort of problem, though it's on linux rather than windows. > Sever

Re: Spamassassin doesn't ding sender for saying "HELO i-am-you"

2006-12-07 Thread Justin Mason
Kelly Jones writes: > Spamassassin has lots of tests for fake HELOs. If someone says "HELO > hotmail.com", but aren't connecting from a Hotmail IP address, they > get dinged (spam score is increased). > > Recently, someone connected our server, call it mx.xyz.com, and said > "HELO mx.xyz.com". Sp

Re: SA not firing on every email

2006-12-07 Thread Craig
Thanks for your reply Its not that the server is to busy-I can put any one of those emails in the receive directory when no other emails are in the que-and being scanned and it still gets passed through. Size is not an issue, the emails are 26k. More details- I have spamassassin intigrated

RE: Help with understanding a rule

2006-12-07 Thread Sietse van Zanen
I want the IT staff to change this, but they require some "proof" that the full name should be there(!). >That is definite proof of an incompetent IT staff..

SV: Help with understanding a rule

2006-12-07 Thread Magnus.Ekhall
>The list managers are the first ones who have to change. > Yes, you are probably right. But: there must be a reason why the rule no_real_name exists? And if there is a rule (written or not) that From: headers should contain a real name, I want to follow it. And to follow it I need to convince my

What is the correct way of whitelisting local mail?

2006-12-07 Thread Robert S
I'm trying to stop SA from incorrectly labeling local messages as spam. The most common target is a weekly script that notifies the user of quarantined spams. The subject lines of each message fire off a false positive. What is the correct way of whitelisting local mail? trusted_networks 192.1

RE: Help with understanding a rule

2006-12-07 Thread Michael Scheidell
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] > Sent: Thursday, December 07, 2006 5:54 AM > To: users@spamassassin.apache.org > Subject: Help with understanding a rule > > " > Content analysis details: (3.0 points, 3.0 required) > > pts rule name

Re: trouble calling spamc from within postfix

2006-12-07 Thread Mathias Homann
Noel Jones schrieb: > * NEVER * use "sendmail -t" to reinject mail coming from the network. > Doing so will send mail to everyone listed in the To: header, which > doesn't have anything to do with who should receive the mail. > > As the guide said, use "sendmail -oi -f ${sender} -- ${recipient}".

  1   2   >