Re: AW: i'm unable to catch these

2008-07-02 Thread Jonas Eckerman
Starckjohann, Ove wrote: Received: from n75.bullet.mail.sp1.yahoo.com ([10.10.10.21]) by EXCHANGE02.norddeutsche.de with Microsoft SMTPSVC(6.0.3790.3959); Mon, 30 Jun 2008 18:58:44 +0200 10.10.10.21 is MY address. It's a smtp-PROXY which passes through the smtp-connection to EXCHANG

Re: AW: i'm unable to catch these

2008-07-02 Thread Arvid Ephraim Picciani
On Wednesday 02 July 2008 16:34:12 SM wrote: > At 05:23 02-07-2008, Starckjohann, Ove wrote: > >10.10.10.21 is MY address. It's a smtp-PROXY which passes through > >the smtp-connection to EXCHANGE02. > > Network tests on the message headers will be ineffective. > that was my worry. With the defaul

Re: AW: i'm unable to catch these

2008-07-02 Thread Matus UHLAR - fantomas
> At 05:23 02-07-2008, Starckjohann, Ove wrote: > >10.10.10.21 is MY address. It's a smtp-PROXY which passes through > >the smtp-connection to EXCHANGE02. On 02.07.08 07:34, SM wrote: > Network tests on the message headers will be ineffective. not if the 10.10.10.21 is in trusted_networks and in

Re: AW: i'm unable to catch these

2008-07-02 Thread SM
At 05:23 02-07-2008, Starckjohann, Ove wrote: 10.10.10.21 is MY address. It's a smtp-PROXY which passes through the smtp-connection to EXCHANGE02. Network tests on the message headers will be ineffective. Regards, -sm

Re: AW: i'm unable to catch these

2008-07-02 Thread Stefan Hornburg
Starckjohann, Ove wrote: nice .-) i added L_UNVERIFIED_YAHOO and GEO_QUERY_STRING to my rules, as i'm still using SA_3.17...so maybe those rules are only embedded into the 3.2x'er SA. But pls tell me: how may CLAMAV score with 10 points ? where is the "virus" ??? This is probably ClamAV wit