Re: Academic interested in interviewing you for research paper.

2012-08-17 Thread Michael Scheidell
in a country where we might be looking for work!) -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 * Official port maintainer for FreeBSD port of SpamAssassin http://www.freebsd.org/cgi/ports.cgi?query=scheidell&stype=maintainer <http://www.freebsd.org/cgi/ports.cgi?query=scheidel

Re: SpamAssassin scores and 12-letter domains

2012-08-05 Thread Michael Scheidell
oints should be suspect. http://spamassassin.1065346.n5.nabble.com/FROM-12LTRDOM-high-scored-remove-td100710.html this is the url that hits hex -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011

Re: Spamhaus and others check at MTA level: how disable in Spamassassin?

2012-08-04 Thread Michael Scheidell
meta rules. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security Product * Certified SNO

Re: Advice

2012-07-03 Thread Michael Scheidell
this means that a large multiple of that number has manually blacklisted you and your network :-( oh, and you can't get past AOL's rate limiting unless you do sign up. So, it works exactly as AOL designed it. ESP's who listwash and don't want to disable spamming clients can&

Re: Can't locate object method "get_tag"

2012-06-28 Thread Michael Scheidell
(HTML::TokeParse?) just googled for 'perl+get_tag' what version of perl? something somewhat modern? 5.10+? install all the missing modules and restart spamd/mia --Richard -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation *

Re: Is this a new typoe of URI obfuscation?

2012-06-12 Thread Michael Scheidell
ITIONAL SECTION: ns1.webme.com.287INA62.116.130.62 ns2.webme.com.287INA62.116.162.62 and it is a valid tld: <http://en.wikipedia.org/wiki/.gg> -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Bes

Re: What to tell senders of these messages

2012-06-09 Thread Michael Scheidell
On 6/9/12 8:24 AM, haman...@t-online.de wrote: Michael Scheidell wrote: HS_INDEX_PARAM: tell them not to use web bugs in their marketing emails Hi Michael, since we are sending out newsletters (to people who really subscribed:) and I got the role to be my own "email marketing compan

Re: What to tell senders of these messages

2012-06-09 Thread Michael Scheidell
ught as spam) just unsubscribe from their marketing newsletter, that is the best way to tell the spammer/sender to find a more RFC compliant, more reliable email marketing company or program. of, just whitelist that person -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *

Re: Large image spam

2012-05-29 Thread Michael Scheidell
file? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security Product * Certified SNORT In

Re: Solved! Re: claims "no rules found" but I have run sa-update

2012-04-26 Thread Michael Scheidell
also added critical patches backported from 3.4. have you ever done a slave port? even a local one? (look at japanese/p5-Mail-SpamAssassin for example of slave port) -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Pr

Re: New versions of Perl are slower

2012-04-11 Thread Michael Scheidell
s any performance impact? - Julian don't know, we always used WITH_PERL_MALLOC so I never tested it without. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Pro

Re: New versions of Perl are slower

2012-04-10 Thread Michael Scheidell
p5-Mail-SpamAssassin-3.3.2_6. -- Michael Scheidell, CTO >|SECNAP Network Security -Original message- From: Julian Yap To: Michael Scheidell Cc: "users@spamassassin.apache.org" Sent: Wed, Apr 11, 2012 00:35:04 GMT+00:00 Subject: Re: New versions of Perl are slower O

Re: New versions of Perl are slower

2012-04-10 Thread Michael Scheidell
-Mail-SpamAssassin-devel out. visit here and ping them: <https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6689> -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prev

Re: FreeBSD ports users: Q: Value in SA 3.4?

2012-04-04 Thread Michael Scheidell
On 4/4/12 10:01 AM, Michael Scheidell wrote: so, anyone want to follow the FreeBSD ports/p5-Mail-SpamAssassin-devel? ok, so I am an idiot. I can't find Mail-SpamAssassin-3.4.0.tar.gz, and the nightly build link on http://spamassassin.apache.org/downloads.cgi points no

FreeBSD ports users: Q: Value in SA 3.4?

2012-04-04 Thread Michael Scheidell
e you are working on. so, anyone want to follow the FreeBSD ports/p5-Mail-SpamAssassin-devel? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company

Re: Request to change rule RCVD_IN_RP_CERTIFIED

2012-04-02 Thread Michael Scheidell
some time now. correct, both of you. previously, you needed to sign up, accept their TOS. (which allows them to spam you), all OT subjects aside, my issue is the 'sfh' (spam for hire) credits in SA. and the autolearn tflags. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 &

Re: Missed SPAM

2012-03-31 Thread Michael Scheidell
one at all. What information is important might not be apparent to you. If it was, you might have solved the problem yourself. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intru

Re: Request to change rule RCVD_IN_RP_CERTIFIED

2012-03-30 Thread Michael Scheidell
ils and decide which ones you wanted or not. I am talking about the whole RP/IADB group of rules in general. Some human being decided on the -3.0 score. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of

Re: Request to change rule RCVD_IN_RP_CERTIFIED

2012-03-30 Thread Michael Scheidell
ble email passed through, but Bayesian keys are added as if they are 'clean' email. So, email like this sent from other sources will eventually come in as 'clean', due to Bayesian credits. I would like to consider tflags for all 'spam for hire' scores be changed

Request to change rule RCVD_IN_RP_CERTIFIED

2012-03-29 Thread Michael Scheidell
ese, and all I get is the runaround. if this rule is truly CERTIFIED not to spam, then they had better review us federal laws, and make this company conform. <http://pastebin.com/K0r29v6F> (even pastebin thought this was spam and made me type in chars to prove I wasn't a robot/zombot)

Re: My Mad Plan's Achillies heel?

2012-03-28 Thread Michael Scheidell
earned, by now, as I have submitted close to a dozen via spamassassin -r< text.file -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Fin

Re: Want help to create a rule for filtering mails with empty message body and attachments

2012-03-24 Thread Michael Scheidell
Sorry for bothering you guys. Found answer to my question: Cool.. this should be part of the stock SA rules -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Prod

Re: having trouble running spamassassin from command line to test rules.

2012-03-22 Thread Michael Scheidell
u don't have two copies of spamassassin installed. third, since you are running amavisd-new, you should run as the amavisd user su - vscan -c 'spamassassin -L -t -c dumptext < spammail ' > /dev/null ? forth, amavisd-new adds,subtracts points, so this won't really be a valid test.

Re: SPF_FAIL

2012-03-22 Thread Michael Scheidell
ck of competence of most Microsoft Exchange admins, though. :) like ip/dns that is not 'round trip' consistent :-) host colo3.roaringpenguin.com colo3.roaringpenguin.com has address 70.38.112.54 host 70.38.112.54 54.112.38.70.in-addr.arpa domain name pointer roaringpenguin.com -- Michael

Re: SPF_FAIL

2012-03-21 Thread Michael Scheidell
ublish an SPF Record score SPF_NONE1 score of zero? or 1? regards, kAM -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finali

Re: Allowing IMAP users to train spam/ham

2012-03-21 Thread Michael Scheidell
that someone else has one of those silly anti-malware plugins that surfs to every url in any inbound email? (or some forwarder recipient decides to click on of the links) -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobi

Re: OT how to bypass public nameservers as bind forwarders?

2012-03-21 Thread Michael Scheidell
ueries per day, just use bind and root zones. if you want information on how to fix bind, then you need the bind faq/man page/news group. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * B

Re: Allowing IMAP users to train spam/ham

2012-03-21 Thread Michael Scheidell
mangle the headers, and the body, even changing the actual encoding. so, what would you manually learn? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product

Re: sa-update doesn't work anymore after upgrade to spamassassin-3.3.2-4.el4.rfx

2012-03-18 Thread Michael Scheidell
204.159.20 b.auth-ns.sonic.net.37091INA184.173.92.18 c.auth-ns.sonic.net.37091INA69.9.186.104 ;; Query time: 117 msec ;; SERVER: 10.70.1.2#53(10.70.1.2) ;; WHEN: Sun Mar 18 09:54:41 2012 ;; MSG SIZE rcvd: 208 -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 &

Re: Understanding AXB_X_AOL_SEZ_S

2012-03-15 Thread Michael Scheidell
IRRORED.BY) grep AXB_X_AOL_SEZ_S * -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security Product * Ce

Re: Updated: 90_axb_fraud.cf

2012-03-15 Thread Michael Scheidell
, restart spamd, amavisd new, reload amavisd. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security Prod

Re: Updated: 90_axb_fraud.cf

2012-03-15 Thread Michael Scheidell
idn't know anything about 9_axb_fraud.cf what kind of data do you need? enjoy... -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Final

Re: someone hijacked spamassassin.org whois record?

2012-03-11 Thread Michael Scheidell
On 3/11/12 2:52 PM, João Gouveia wrote: - Original Message - From: "Michael Scheidell" To: "SpamAssassin Users List" Sent: Sunday, March 11, 2012 6:25:52 PM Subject: someone hijacked spamassassin.org whois record? hacked dns servers records? Not likely. It do

someone hijacked spamassassin.org whois record?

2012-03-11 Thread Michael Scheidell
...@apache.org Name Server:NS2.SURFNET.NL Name Server:NS3.NO-IP.COM Name Server:NS2.NO-IP.COM Name Server:NS1.NO-IP.COM Name Server:NS4.NO-IP.COM -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * B

Re: uribl lastminute.com listed in uribl whte and is now used for nordea phisting mails

2012-03-02 Thread Michael Scheidell
On 3/2/12 11:36 AM, Benny Pedersen wrote: just a note to whom it might concern :) phisting? OUCH. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product *

Re: Bayes now changed to autolearn=unavailable.

2012-02-27 Thread Michael Scheidell
together score below -1 and do NOT have noautolearn flags. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Secur

Re: Yet another thread about AWL

2012-02-22 Thread Michael Scheidell
On 2/22/12 8:17 AM, Antonio Gutiérrez Mayoral wrote: Oh, thank you! I though that restarting spamd was sufficient. you don't run spamd at all with amavisd-new. just wasting ram/cpu/swap. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Cor

Re: Yet another thread about AWL

2012-02-22 Thread Michael Scheidell
On 2/22/12 7:36 AM, Antonio Gutiérrez Mayoral wrote: I have checked with spamassassin --lint the config and restart spamd. I am still seeing AWL triggered on the amavis log: and, you don't use spamd with amavisd-new. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*|

Re: Yet another thread about AWL

2012-02-22 Thread Michael Scheidell
ddress, use 'random' ip addresses on zombot networks. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Ema

Re: Yet another thread about AWL

2012-02-21 Thread Michael Scheidell
://wiki.apache.org/spamassassin/AutoWhitelist "Previous version implementation In 3.3, the plugin is not loaded by default." -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Preve

Re: Yet another thread about AWL

2012-02-21 Thread Michael Scheidell
score, would you have marked those emails as spam? if answer is yes, disable AWL. also, since you are using amavisd-new, you might want to ask specific (non AWL) questions on their mailing list about backscatter. they have a solution that might work better than AWL. -- Michael Scheidell, CTO

Re: Spam messages with no payload

2012-02-20 Thread Michael Scheidell
totally lose your shipment anyway. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security P

Re: how do I fix my spamassassin setup? I can't use Bayes anymore -- won't open the files...

2012-02-11 Thread Michael Scheidell
scratch. if you have a busy system, use the mysql dbi, with innodb engine. less likely to corrupt. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product

Re: Getting high spam score for email server hosted on AWS instance

2012-02-08 Thread Michael Scheidell
ist (I am just guessing: Received: from G9W0725.americas.hpqcorp.net ([169.254.8.28]) by You have a microsoft cluster, where microsoft thought it would be a good idea to use 169.254.0.0/16 ip addresses?) Bring this up with microsoft, have them 'fix' this. -- Michael Scheidell, C

Re: ACL vs. TRANSPORT styles

2012-02-03 Thread Michael Scheidell
yle.. it is the MIB style (no, not snmp, MIB, MIKE IN a BOX). -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best

Re: SA 3.0.2 buggie? -- message that DB file doesn't exist -- but systrace shows successful lock and open!

2012-01-16 Thread Michael Scheidell
On 1/16/12 9:36 AM, Linda Walsh wrote: This is not permission problem -- Message I get: have you tried to upgrade to the released version? 3.3.2? 3.0.2 was obsolete 6 years ago. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * B

FreeBSD port ja-p5-Mail-SpamAssassin needs adoption

2012-01-14 Thread Michael Scheidell
use email address reference: scheid...@freebsd.org) -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Sec

Re: sa-update channel list

2012-01-12 Thread Michael Scheidell
On 1/11/12 10:09 PM, jida...@jidanni.org wrote: "MS" == Michael Scheidell writes: All I know is I'm using Jan 12 11:07:09.394 [21138] dbg: generic: SpamAssassin version 3.4.0-r1102360 which is obviously newer than 3.3.2. they whoever built that unreleased development versio

Re: sa-update channel list

2012-01-11 Thread Michael Scheidell
if you don't have the current version of spamassassin then your sa-update channel will be older. (case in point) -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Pr

Re: sa-update channel list

2012-01-09 Thread Michael Scheidell
t, maintainer of the FreeBSD version of sa, and running one of the mirrors: We use stock sa-update channel, and (local) custom rules, lots of meta rules. #1 priority: keep your version of sa updated, because new(er) rules and tests are only added, or are added first to current/stable ver

Re: sa-update / perl error again

2012-01-09 Thread Michael Scheidell
On 1/9/12 6:25 AM, Michael Scheidell wrote: On 1/8/12 9:52 PM, email builder wrote: rpm -e --nodeps perl-IO-Socket-INET6 By the way, is there a way to grep for the errant code? My feeble attempt didn't turn up much: as in one of my previous emails: 'locate IO-Socket-INET6'

Re: sa-update / perl error again

2012-01-09 Thread Michael Scheidell
On 1/8/12 9:52 PM, email builder wrote: rpm -e --nodeps perl-IO-Socket-INET6 By the way, is there a way to grep for the errant code? My feeble attempt didn't turn up much: as in one of my previous emails: 'locate IO-Socket-INET6' -- Michael Scheidell, CTO o: 561-999-5000

Re: sa-update / perl error again

2012-01-08 Thread Michael Scheidell
nstall INET6 pm unless the system was compiled with INET6 in the kernel. ymmv, Did I mention that we were not able to reproduce this in the lab? and up till then, no other client had a problem? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation

Re: sa-update / perl error again

2012-01-01 Thread Michael Scheidell
s at 5.14.* something now, but don't update it, it might now help. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best

Re: installation problem

2011-12-31 Thread Michael Scheidell
here I ran the installation, and also under usr/pkg/share, and they are both populated with files which look relevant. I tweaked the script so as not to require rules, and it ran and produced output. utweak. you need rules. NetBSD 4.01, working as root. What is amiss? -- Michael Scheidell,

Fwd: cvs commit: ports/mail/p5-Mail-SpamAssassin Makefile pkg-plist ports/mail/p5-Mail-SpamAssassin/files patch-bug6698

2011-12-26 Thread Michael Scheidell
patch-bug6698 Date: Mon, 26 Dec 2011 18:14:37 + From: Michael Scheidell To: , , scheidell2011-12-26 18:14:37 UTC FreeBSD ports repository Modified files: mail/p5-Mail-SpamAssassin Makefile pkg-plist mail/p5-Mail-SpamAssassin/files patch-bug6698 Log: - private

Re: dccproc/dccifd error

2011-12-23 Thread Michael Scheidell
I am going to update the original bug with patch. Ill have mark look at it first. -- Michael Scheidell, CTO SECNAP Network Security -Original message- From: "dar...@chaosreigns.com" To: Michael Scheidell Cc: "users@spamassassin.apache.org" Sent: Fri, Dec 23, 201

Re: dccproc/dccifd error

2011-12-23 Thread Michael Scheidell
A BUGzilla soon. (so, yes, this would be a bug in 3.4 if released, but only shows up under one certain condition) -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Produc

Re: solicitations via netsuite.com

2011-12-13 Thread Michael Scheidell
orce would be relayed through our servers, not theirs), but it would raise our cost by 65%. so, who really cares about netsuite.com them selves.. they are just a CRM. send complaints to abuse@ and see what happens. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Net

Re: DNSWL will be disabled by default as of tomorrow

2011-12-13 Thread Michael Scheidell
. returning FP on HIGH won't ever get google's attention, will it? and you still get the bandwidth and cpu cycles from the largest abusers. Regards, KAM -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solution

Re: score based on a list of domains

2011-12-13 Thread Michael Scheidell
spam blocking. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security Product * Certified SNORT Integra

Re: error on SA learning.

2011-12-11 Thread Michael Scheidell
already been included netset: cannot include 0:0:0:0:0:0:0:1/128 as it has already been included* it means that the ipv6 localhost address has already been included. Ignore this, these are not the droids you are looking for. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SEC

Re: Mark all invites as spam

2011-12-09 Thread Michael Scheidell
On 12/9/11 7:58 AM, Ram wrote: If I want to mark *all* invite mails as spam linkedin, WAYN , facebook , google+ or anything else. Is there a global way of doing this copy the rule that marks all phishing emails as spam, and change 'phishing' to 'invites' -- Mich

Re: Bayes database in mysql on multiple servers

2011-12-01 Thread Michael Scheidell
On 12/1/11 10:06 AM, Benny Pedersen wrote: does not make sense so hire a unix programmer to help you understand. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevent

Re: Bayes database in mysql on multiple servers

2011-11-30 Thread Michael Scheidell
On Wed, 30 Nov 2011 08:23:59 -0500, Michael Scheidell wrote: sed -i '' -e '/INSERT INTO bayes_seen/s/INTO/IGNORE INTO/' MySQL.pm (hey SA folks.. any reason not to just put that into 3.4.0? won't hurt anything, will it?) or simply just ALTER TABLE `bayes_seen` E

Re: Bayes database in mysql on multiple servers

2011-11-30 Thread Michael Scheidell
folks.. any reason not to just put that into 3.4.0? won't hurt anything, will it?) -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Fin

Re: Rules for opt-in mailing list

2011-11-30 Thread Michael Scheidell
just email. SA will most likely score as spam that joke your brother in law sent. is that SPAM? it is sure bulk, and has lots of 'cruft' in it, by the time he has gotten it forwarded to him by 20 people. did you want it? no. is it COMMERCIAL? no. is it SPAM? heck yes, I didn'

Freebsd Users: Mail-SpamAssassin update available

2011-11-29 Thread Michael Scheidell
Freebsd SA port. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security Product * Certifie

Re: new paradigm

2011-11-24 Thread Michael Scheidell
On 11/24/11 3:30 PM, Martin Hepworth wrote Rfc 5321 says I can discard if I have high confidence it's rubbish ! -- Martin I wonder what the rfc's say about helo line not matching dns: Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) -- Michael Scheidell,

Re: new paradigm

2011-11-24 Thread Michael Scheidell
again, sounds like amavisd-new penpals. what about if your message was stored in a folder of your correspondent, his machine is infected by a virus, and this virus sends fake replies using your message id ? I've seen cases like that in the past. you can't whitelist a virus in

Re: new paradigm

2011-11-24 Thread Michael Scheidell
addresses that you haven't replied to for, say, a month but that is about all you can delete. sounds like amavisd-new 'penpals'. (sliding credit score starting at -100, counting down to 0 for your time period..). -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >

Re: One-line URI body spam

2011-10-18 Thread Michael Scheidell
mples of hack's, you must prevent google from indexing those pages. you might need to have the reader sign up, log in to view them. if google sees them, they will blacklist you. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best

Re: Spam email many have RCVD_IN_DNSWL_MED

2011-10-11 Thread Michael Scheidell
On 10/11/11 1:47 PM, John Hardin wrote: Yahoo is in RCVD_IN_DNSWL_HI ?!?! YGBFKM! there goes the neighborhood. I am removing RCVD_IN_DNSWL_HI checks on our servers right now. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mob

Re: Spam email many have RCVD_IN_DNSWL_MED

2011-10-11 Thread Michael Scheidell
And I have my own IP reputation project that could use your data: http://www.chaosreigns.com/iprep/ -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot

Re: Spam email many have RCVD_IN_DNSWL_MED

2011-10-11 Thread Michael Scheidell
cal.cf and restart spamd/ tflags RCVD_IN_DNSWL_HI nice net noautolearn tflags RCVD_IN_DNSWL_HI net nice noautolearn tflags RCVD_IN_DNSWL_MED net nice noautolearn tflags RCVD_IN_DNSWL_LOW net nice noautolearn -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security C

Re: Increasing score based on membership to commercial whitelist

2011-10-11 Thread Michael Scheidell
d in, all they needed, to keep me from complaining, was a link like twitter had: 'report this as abuse', AND, 'I never want to hear from linked in about anything, ever again', and for US CAN-SPAM compliance, the full, physical address of the spammer. -- Michael Scheidell, CT

Re: Blacklisting based on SPF

2011-10-05 Thread Michael Scheidell
fwds (incorrectly), OR, dns doesn't answer in time, you lose email. best to write a metarule. put your def_ whitelist from (7 points), and set up some metarules. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile

Re: Rule updates

2011-10-04 Thread Michael Scheidell
26 23:32 1162027.tar.gz <-- 3.3.2 -rw-r--r-- 1 rsync rsync 236957 Aug 25 23:23 1161446.tar.gz -rw-r--r-- 1 rsync rsync 236980 Aug 24 23:22 1161015.tar.gz -rw-r--r-- 1 rsync rsync 236920 Aug 23 23:18 1160585.tar.gz -rwxr--r-- 1 rsync rsync 237167 Aug 22 23:17 1160145.tar.gz -- Michael Scheid

Re: critsend (/gridsend?)... what's the(ir) trick?

2011-09-12 Thread Michael Scheidell
mavisd-new. if that didn't help by adding more status lines, then ask in amavisd-new group. again, this is most likely an amavisd.conf issue, so start your question in the amavisd-new users group. don't assume they read spamassassin group. some do, some don't. -- Mich

Re: Plugin for Spanish Spams?

2011-09-09 Thread Michael Scheidell
char sets that you expect? block spanish charset in MTA? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best

Re: critsend (/gridsend?)... what's the(ir) trick?

2011-09-08 Thread Michael Scheidell
. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security Product * Certified SNORT Integra

Re: Anybody else getting hit by WannaBeBig forum notifications?

2011-09-07 Thread Michael Scheidell
looking like a legit forum. I don't see anything in our larger installations, guess you just must be blessed :-) -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prev

Re: spamd takes forever to start

2011-09-03 Thread Michael Scheidell
les. sares rules? depricated, private rules? take them out for now. perl versions? update modules? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product

Re: Curious phenomenon with 9-repetitions of each spam...

2011-09-02 Thread Michael Scheidell
this already? I think postfix has some policy services to do this. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Em

OT Re: sa users list down due to irene?

2011-08-30 Thread Michael Scheidell
be. same with RFC compliance. (which I think still says that you should send an NDR if you can't deliver the spam :-) getting OT here, just ranting this am. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutio

Re: sa users list down due to irene?

2011-08-29 Thread Michael Scheidell
; with the rest of the world. (ok, I don't care if it plays nice with aol/hotmail/etc, you get free email? you get what you pay for). -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best In

Re: sa users list down due to irene?

2011-08-29 Thread Michael Scheidell
area, but 10 years and counting, its never made it into the official build. causes a lot of anger, back and forth when this patch is discussed. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011

sa users list down due to irene?

2011-08-29 Thread Michael Scheidell
ate as well. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security Product * Certified SN

Re: sa-update bug: TMPDIR full?

2011-08-26 Thread Michael Scheidell
On 8/26/11 4:59 PM, Michael Scheidell wrote: found a bug in sa-update bigger bug.. bug is in ../Util.pm. it will TRY to create a tmpfile on a nonexistant or read only dir, and anything that trys to use that dir will fail and not know why. patch to fix included. -- Michael Scheidell

sa-update bug: TMPDIR full?

2011-08-26 Thread Michael Scheidell
uot;generic: update tmp directory $UPDTmp"); } elsif (!clean_update_dir($UPDTmp)) { die "channel: attempt to clean update dir failed, aborting"; } -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Soluti

Re: Mirror daryl.dostech.ca down forever?

2011-08-25 Thread Michael Scheidell
now. either delete MIRRORED.BY or run sa-update --refreshmirrors now. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011

Re: Please format you mail so people can read it. WAS: updates mirror is down

2011-08-25 Thread Michael Scheidell
ml part has correct to that any modern mail reader can read it. oh, ps, ms outlook CAN allow you to bottom post. you just have to move the mouse down below before you post. (or so I have been told) -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corpo

Re: Mirror daryl.dostech.ca down forever?

2011-08-25 Thread Michael Scheidell
be patient.. it takes a little time to set up, test, QA and make sure any new mirror is up and running before adding it to the rotation. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Be

Re: updates mirror is down

2011-08-24 Thread Michael Scheidell
On 8/24/11 10:46 AM, Michael Cronenworth wrote: http://www.sa-update.pccc.com/ weight=5 question is... why didn't it pull from pccc.com? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011

Re: updates mirror is down

2011-08-24 Thread Michael Scheidell
On 8/24/11 10:37 AM, Michael Cronenworth wrote: Michael Scheidell wrote: if you are trying to update this by hand, you are on your own. just use sa-update (-D to watch) it will delete MIRRORED.BY for you, pull a new one, and use it. I *am* using sa-update. sa-update is continuously failing

Re: updates mirror is down

2011-08-24 Thread Michael Scheidell
elete MIRRORED.BY for you, pull a new one, and use it. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security

Re: updates mirror is down

2011-08-24 Thread Michael Scheidell
On 8/24/11 10:26 AM, Michael Cronenworth wrote: Michael Scheidell wrote: pccm mirror is back up again. Huh? $ wget daryl.dostech.ca --2011-08-24 09:25:17-- http://daryl.dostech.ca/ Resolving daryl.dostech.ca... 71.164.246.108 Connecting to daryl.dostech.ca|71.164.246.108|:80... (hangs

Re: updates mirror is down

2011-08-24 Thread Michael Scheidell
mirror is back up again. Thanks, Michael -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security Prod

Re: 500 Can't connect to daryl.dostech.ca:80 (connect: timeout):

2011-08-23 Thread Michael Scheidell
On 8/23/11 11:50 AM, dar...@chaosreigns.com wrote: On 08/23, Michael Scheidell wrote: since at least 3am http: GET http://daryl.dostech.ca/sa-update/asf/1160145.tar.gz request failed, retrying: 500 Can't connect to daryl.dostech.ca:80 (connect: timeout): 500 Can't connect to daryl.

500 Can't connect to daryl.dostech.ca:80 (connect: timeout):

2011-08-23 Thread Michael Scheidell
since at least 3am http: GET http://daryl.dostech.ca/sa-update/asf/1160145.tar.gz request failed, retrying: 500 Can't connect to daryl.dostech.ca:80 (connect: timeout): 500 Can't connect to daryl.dostech.ca:80 (connect: timeout) -- Michael Scheidell, CTO o: 561-999-5000 d: 56

  1   2   3   4   5   6   7   8   9   10   >