Re: How to detect this spam..

2006-10-19 Thread Daryl C. W. O'Shea
Jonas Eckerman wrote: *If* the system is set up to use the SPF plugin *and* enable/allow user rules, it should still be possible for an end user to "whitelist_from_spf". You don't need to enable user rules for whitelist_from_spf, or any other whitelist method, to work. Daryl

Re: How to detect this spam..

2006-10-19 Thread John D. Hardin
On Thu, 19 Oct 2006, Jonas Eckerman wrote: > Come to think of it, it *might* be a good idea for the official ruleset to > include: > > ifplugin Mail::SpamAssassin::Plugin::SPF > whitelist_from_spf [EMAIL PROTECTED] > endif +1 -- John Hardin KA7OHZICQ#15735746http://www.impsec.org/~jha

Re: How to detect this spam..

2006-10-19 Thread Jonas Eckerman
Jo Rhett wrote: You can only exclude the mailing list if you're running SA from procmail or .forward or something like that. No. You can exclude it in other situations as well. I was referring to the knobs available for tweaking by an end user. Ah. Yes, that limits the possibilities. I

Re: How to detect this spam..

2006-10-19 Thread Jo Rhett
Jonas Eckerman wrote: Jo Rhett wrote: You can only exclude the mailing list if you're running SA from procmail or .forward or something like that. No. You can exclude it in other situations as well. Usually it's running on the MX hosts. We're using SA on our MX host, daemonized in MIMEDef

Re: How to detect this spam..

2006-10-19 Thread Jonas Eckerman
Jo Rhett wrote: You can only exclude the mailing list if you're running SA from procmail or .forward or something like that. No. You can exclude it in other situations as well. Usually it's running on the MX hosts. We're using SA on our MX host, daemonized in MIMEDefang (a milter). We're e

Re: How to detect this spam..

2006-10-18 Thread Bob McClure Jr
On Tue, Oct 17, 2006 at 09:56:13PM -0700, Jo Rhett wrote: > On Oct 17, 2006, at 6:53 PM, John D. Hardin wrote: > >Anyone who runs the SA mailing list through SA deserves what they > >get... :) > > You can only exclude the mailing list if you're running SA from > procmail or .forward or something

Re: How to detect this spam..

2006-10-17 Thread Jo Rhett
On Oct 17, 2006, at 6:53 PM, John D. Hardin wrote: Anyone who runs the SA mailing list through SA deserves what they get... :) You can only exclude the mailing list if you're running SA from procmail or .forward or something like that. I haven't seen a company (or individual actually) who

RE: How to detect this spam..

2006-10-17 Thread John D. Hardin
On Wed, 18 Oct 2006, Christopher Martin wrote: > Also, be careful about putting samples out of spam in your mails. > Sometimes people might actually pick you up as the spam, and, > potentially worse, train their Bayesian filters to exclude you, > automatically. Anyone who runs the SA mailing list

RE: How to detect this spam..

2006-10-17 Thread Christopher Martin
The regex would be: [a-zA-Z]\s[a-zA-Z]\s[a-zA-z]\s So, (IIRC) the rule could be: body LOCAL_GAPPY_WORDS/[a-zA-Z]\s[a-zA-Z]\s[a-zA-z]\s/ score LOCAL_GAPPY_WORDS2 Try it with a low score to start with. I use the LOCAL_ prefix for any rules I put into local.cf. But, I a

Re: How to detect this spam..

2006-10-17 Thread Matt Kettler
Monty Ree wrote: > Hello.. > > I have received lots of spam mails like below... > > S B N S.P K IS BLOWING UP ON HEAVY PR CAMPAIGNS! > WATCH S B N S.P K TRADE ON TUESDAY OCTOBER 17! > > So I would like to make a rule to detect spam which use blank for each > characters(over 3 characters) like below