Re: [poppler] Encrypted malicious PDFs fails

2017-09-13 Thread Alex
Hi, On Wed, Sep 13, 2017 at 7:04 PM, Ross Moore wrote: > Hello Alex, > > On Sep 14, 2017, at 8:20 AM, Alex wrote: > > Hi, > > I have a malicious PDF that fails to be detected properly apparently > because it's encrypted in some way: > > > Yes. It uses PDF password protection. > You can do this

Lashback RBL testing

2017-09-13 Thread David Jones
I have been working with Michael from Lashback RBL to improve the false positive hits from major mail providers. I would like to ask for others to help test and provide some feedback by saving this file in the same location as the local.cf (usually /etc/mail/spamassassin): https://pastebin.co

Re: new campaign: bitly & appengine.google

2017-09-13 Thread Kevin A. McGrail
On 9/13/2017 3:22 PM, Benny Pedersen wrote: last i tryed using kam.cf it was for me atleast to big to continue to keep, but i can begin using it again now since i have more memory to spare, would you mind split the cf file into more smaller cf files all begining with kam_foo.cf kam_bar.cf ? G

Re: new campaign: bitly & appengine.google

2017-09-13 Thread Benny Pedersen
Kevin A. McGrail skrev den 2017-09-13 20:45: Thanks.  I like to create low FP rules using metas that create higher levels of hurdles to definitively score things. i enlist us tld, and enlist non spaming us tld domains that are not spamming, so this way i get rid of random new domain spaming t

Re: new campaign: bitly & appengine.google

2017-09-13 Thread Kevin A. McGrail
On 9/13/2017 1:36 PM, Chip M. wrote: I took a look at your rules, and like your scoring.:) Over my years, I've seen enough BBB scare campaigns which use shorteners, that perhaps it would make sense to add "KAM_SHORT" to your additive list of metas (I forget what that's called). Thanks.  I like

Re: new campaign: bitly & appengine.google

2017-09-13 Thread Benny Pedersen
Chip M. skrev den 2017-09-13 19:36: bit.ly/2sLdd2P http://programmingkeeda.club/ https://github.com/smfreegard/DecodeShortURLs add bit.ly to this plugin then real url is considered in sa i will check in my return what happens here

Re: new campaign: bitly & appengine.google

2017-09-13 Thread Chip M.
KAM, thanks! I took a look at your rules, and like your scoring. :) Over my years, I've seen enough BBB scare campaigns which use shorteners, that perhaps it would make sense to add "KAM_SHORT" to your additive list of metas (I forget what that's called). To all the other repliers: Thanks for your