Re: shouldn't SA treat certain web-script headers as X-Spam-Relays-External?

2012-01-05 Thread Henrik K
On Fri, Jan 06, 2012 at 06:06:35PM +1300, Jason Haar wrote: > Hi there > > I just had the following phishing attacks get through with scores in the 2s. > > http://pastebin.com/4Yyc0m7j > http://pastebin.com/R0XMM9Je > > Both are generated by different hacked websites - both from 41.184.112.222 >

shouldn't SA treat certain web-script headers as X-Spam-Relays-External?

2012-01-05 Thread Jason Haar
Hi there I just had the following phishing attacks get through with scores in the 2s. http://pastebin.com/4Yyc0m7j http://pastebin.com/R0XMM9Je Both are generated by different hacked websites - both from 41.184.112.222 Could X-EN-OrigIP: and X-PHP-Script: be added to X-Spam-Relays-External so a

Re: sa-update / perl error again

2012-01-05 Thread Dave Pooser
>Wow, really? Then why wouldn't RedHat or CentOS have a fixed updated >version in their repo? That seems egregious if what you say is indeed the >case. RedHat (and CentOS, since their whole mission is to match RHEL feature-for-feature and bug-for-bug) believes that their Enterprise Linux custome

Re: sa-update / perl error again

2012-01-05 Thread email builder
>>>       What is the Net::DNS version, are you pure ipv6 > and are you >> >>>   64-bit? >> >>       perl-Net-DNS-0.63-1.el5.rf >> > >     You are in no man's land there - the distro uses   perl-Net-DNS-0.59-3.el5 >     and the latest rpmforge package i

Re: sa-update / perl error again

2012-01-05 Thread email builder
>> /usr/lib/perl5/5.8.8/Exporter.pm line 65.  at >> /usr/lib/perl5/vendor_perl/5.8.8/i386-linux-thread-multi/Net/DNS/Resolver/Base.pm >> >> line 66 [  OK  ] >> >> With my spamassassin, perl-Net-DNS and per-IO-Socket-INET6 >> packages all being from CentOS repo, I'm unsure why this would hap

Re: SPF tests and authenticated SMTP

2012-01-05 Thread nsayer
David B Funk wrote: > > > I'm not familiar with the FreeBSD ports tree, but if its > spamass-milter-0.3.2 is the same as the one from > http://www.freshports.org/mail/spamass-milter/ then it does -not- > add the auth tokens to its internally synthesized "Received" header. > Thus your problem

Re: SPF tests and authenticated SMTP

2012-01-05 Thread David B Funk
On Thu, 5 Jan 2012, nsayer wrote: David B Funk wrote: Noel, I assume that you're saying he has a sendmail config problem because his SA isn't 'seeing' the auth tokens. That might not be the case, it may be his milter that is at fault. SA depends upon the auth tokens that your MTA adds to its

Re: sa-update / perl error again

2012-01-05 Thread Axb
On 2012-01-05 21:28, email builder wrote: What is the Net::DNS version, are you pure ipv6 and are you 64-bit? perl-Net-DNS-0.63-1.el5.rf You are in no man's land there - the distro uses perl-Net-DNS-0.59-3.el5 and the latest rpmforge package is perl-Net-DNS-0.66-1.el

Re: sa-update / perl error again

2012-01-05 Thread Kevin A. McGrail
Starting spamd: Subroutine Net::DNS::Resolver::Base::AF_INET6 redefined at /usr/lib/perl5/5.8.8/Exporter.pm line 65. at /usr/lib/perl5/vendor_perl/5.8.8/i386-linux-thread-multi/Net/DNS/Resolver/Base.pm line 66 [ OK ] With my spamassassin, perl-Net-DNS and per-IO-Socket-INET6 packages all bei

Re: sa-update / perl error again

2012-01-05 Thread email builder
>   What is the Net::DNS version, are you pure ipv6 and are you > 64-bit?   perl-Net-DNS-0.63-1.el5.rf >>> >>>   You are in no man's land there - the distro uses >> perl-Net-DNS-0.59-3.el5 >>>   and the latest rpmforge package is perl-Net-DNS-0.66-1.el5.rfx. >>> >

Re: SPF tests and authenticated SMTP

2012-01-05 Thread nsayer
Noel Butler wrote: > > Ack, you have far bigger problems then you realise given below... > Question, you are smtp-auth'ing via port 587 aren't you? > > Yes. If you are, > then your sendmail is incorrectly configured and I suggest you load the > news group comp.mail.sendmail and ask there (

Re: SPF tests and authenticated SMTP

2012-01-05 Thread nsayer
David B Funk wrote: > > Noel, > I assume that you're saying he has a sendmail config problem because his > SA isn't 'seeing' the auth tokens. That might not be the case, it may be > his milter that is at fault. > > SA depends upon the auth tokens that your MTA adds to its "Received:" > head

Re: sa-update / perl error again

2012-01-05 Thread email builder
>   What is the Net::DNS version, are you pure ipv6 and are you > 64-bit?   perl-Net-DNS-0.63-1.el5.rf >>> >>> You are in no man's land there - the distro uses >>> perl-Net-DNS-0.59-3.el5 >>> and the latest rpmforge package is perl-Net-DNS-0.66-1.el5.rfx. >>> >>>

Re: razor2 and cloudmark?

2012-01-05 Thread AJ Weber
OK, fair-enough, and your theory seems very valid. I wish they (Cloudmark) made a SA plugin for us SOHO users that can't afford (and don't need) a full Cloudmark Authority server/setup. I'd pay a license fee if it were reasonable and it performed anywhere near as accurately as their windows desk

Re: razor2 and cloudmark?

2012-01-05 Thread Kevin A. McGrail
On 1/5/2012 8:49 AM, AJ Weber wrote: Yes, I still have other rules enabled. I have found the Cloudmark product to be extremely accurate, and really my question is specific to whether "razor == cloudmark" or to what extent they are related and how, so I can better understand the results I'm seein

Re: razor2 and cloudmark?

2012-01-05 Thread AJ Weber
Yes, I still have other rules enabled. I have found the Cloudmark product to be extremely accurate, and really my question is specific to whether "razor == cloudmark" or to what extent they are related and how, so I can better understand the results I'm seeing. Thanks for the reply, AJ Martin

Re: SPF tests and authenticated SMTP

2012-01-05 Thread Dave Funk
Noel, I assume that you're saying he has a sendmail config problem because his SA isn't 'seeing' the auth tokens. That might not be the case, it may be his milter that is at fault. SA depends upon the auth tokens that your MTA adds to its "Received:" header to recognize properly authed messag