On Fri, 29 Jan 2010 06:43:02 -0800
Bill Landry wrote:
> Mark Martinec wrote:
> > On Thursday 28 January 2010 14:40:56 Graham Murray wrote:
> >> Since upgrading to SA 3.3.0, botnet (version 0.8) is showing a
> >> false positive on every email I receive via IPv6.
> >
> > Has anyone contacted the a
Mark Martinec wrote:
> On Thursday 28 January 2010 14:40:56 Graham Murray wrote:
>> Since upgrading to SA 3.3.0, botnet (version 0.8) is showing a false
>> positive on every email I receive via IPv6.
>
> Has anyone contacted the author?
As most here on the list know: "Good luck with that". From
On Thursday 28 January 2010 14:40:56 Graham Murray wrote:
> Since upgrading to SA 3.3.0, botnet (version 0.8) is showing a false
> positive on every email I receive via IPv6.
Has anyone contacted the author?
A sample header field:
Received: from mx2.freebsd.org (mx2.freebsd.org [IPv6:2001:4f8:f
Since upgrading to SA 3.3.0, botnet (version 0.8) is showing a false
positive on every email I receive via IPv6.
On Thu, 1 Feb 2007, Bob McClure Jr wrote:
> > host 66.251.54.6
> > 6.54.251.66.in-addr.arpa domain name pointer outbox2.onceanddone.com.
> >
> > host outbox2.onceanddone.com
> > outbox2.onceanddone.com has address 66.251.51.6
> >
> > host 66.251.51.6
> > Host 6.51.251.66.in-addr.arpa not found: 3(
On Thu, Feb 01, 2007 at 05:21:08PM +0100, Jonas Eckerman wrote:
> > [botnet0.7,ip=66.251.54.6,hostname=outbox2.onceanddone.com,maildomain=onceanddone.com,baddns]
>
> host 66.251.54.6
> 6.54.251.66.in-addr.arpa domain name pointer outbox2.onceanddone.com.
>
> host outbox2.onceanddone.com
> outbox2
> [botnet0.7,ip=66.251.54.6,hostname=outbox2.onceanddone.com,maildomain=onceanddone.com,baddns]
host 66.251.54.6
6.54.251.66.in-addr.arpa domain name pointer outbox2.onceanddone.com.
host outbox2.onceanddone.com
outbox2.onceanddone.com has address 66.251.51.6
host 66.251.51.6
Host 6.51.251.66.in
I'm running SA v3.1.7, under Perl v5.8.5 on a RedHat ES4 box. I call
spamc from each user's ~/.procmailrc.
I recently started using Botnet (v0.7) on several servers, and find
it's terrific. But today, I saw my first false positive. Here is the
report and the mail header:
Content analysis detai