Re: Using spamassassin to thwart sharepoint phishing attacks

2021-04-12 Thread John Hardin
On Mon, 12 Apr 2021, jwmi...@gmail.com wrote: John Hardin writes: > From: John Hardin > Date: Mon, 12 Apr 2021 07:29:03 -0700 (PDT) > > On Sun, 11 Apr 2021, Loren Wilton wrote: > > >> 3.5 BAYES_99 BODY: Bayes spam probability is 99 to 100% > >> [score:

Re: Using spamassassin to thwart sharepoint phishing attacks

2021-04-12 Thread jwmincy
John Hardin writes: > From: John Hardin > Date: Mon, 12 Apr 2021 07:29:03 -0700 (PDT) > > On Sun, 11 Apr 2021, Loren Wilton wrote: > > >> 3.5 BAYES_99 BODY: Bayes spam probability is 99 to 100% > >> [score: 1.] > >> 0.5 BAYES_999

Re: Using spamassassin to thwart sharepoint phishing attacks

2021-04-12 Thread Benny Pedersen
On 2021-04-12 16:29, John Hardin wrote: On Sun, 11 Apr 2021, Loren Wilton wrote: 3.5 BAYES_99 BODY: Bayes spam probability is 99 to 100% [score: 1.] 0.5 BAYES_999 BODY: Bayes spam probability is 99.9 to 100%

Re: Using spamassassin to thwart sharepoint phishing attacks

2021-04-12 Thread John Hardin
On Sun, 11 Apr 2021, Loren Wilton wrote: 3.5 BAYES_99 BODY: Bayes spam probability is 99 to 100% [score: 1.] 0.5 BAYES_999 BODY: Bayes spam probability is 99.9 to 100% [score: 1.] I have 5.0 BAYES_99

Re: Using spamassassin to thwart sharepoint phishing attacks

2021-04-12 Thread Matus UHLAR - fantomas
However, in 50_scores.cf, this line is commented out: #score RCVD_IN_SORBS_SPAM 0 0.5 0 0.5 Maybe that's the problem? no, there are other SORBS lists used: score RCVD_IN_SORBS_DUL 0 0.001 0 0.001 # n=0 n=2 score RCVD_IN_SORBS_HTTP 0 2.499 0 0.001 # n=0 n=2 score RCVD_IN_SORBS_MISC 0 # n=0 n=1

Re: Using spamassassin to thwart sharepoint phishing attacks

2021-04-12 Thread Steve Dondley
However, in 50_scores.cf, this line is commented out: #score RCVD_IN_SORBS_SPAM 0 0.5 0 0.5 Maybe that's the problem? no, there are other SORBS lists used: score RCVD_IN_SORBS_DUL 0 0.001 0 0.001 # n=0 n=2 score RCVD_IN_SORBS_HTTP 0 2.499 0 0.001 # n=0 n=2 score RCVD_IN_SORBS_MISC 0 # n=0

Re: Using spamassassin to thwart sharepoint phishing attacks

2021-04-12 Thread Matus UHLAR - fantomas
sorbs dnsbl missing, have you denied sorbs.net results ?, or is spamassassin not testing sorbs.net anymore ? On 11.04.21 18:22, Steve Dondley wrote: Best I can tell, my SA config should be testing for sorbs. I've got this line in /etc/spamassassin/v3220.pre: loadplugin Mail::SpamAssassin::Plu

Re: Using spamassassin to thwart sharepoint phishing attacks

2021-04-11 Thread Kevin A. McGrail
If you have spamples for sharepoint phishes that evade kam ruleset, shoot me an email off-list to discuss getting me the spamples. On Sun, Apr 11, 2021, 16:43 Steve Dondley wrote: > On 2021-04-11 04:19 PM, Benny Pedersen wrote: > > On 2021-04-11 22:09, Steve Dondley wrote: > > > >> Content analy

Re: Using spamassassin to thwart sharepoint phishing attacks

2021-04-11 Thread Loren Wilton
3.5 BAYES_99 BODY: Bayes spam probability is 99 to 100% [score: 1.] 0.5 BAYES_999 BODY: Bayes spam probability is 99.9 to 100% [score: 1.] I have 5.0 BAYES_99 BODY: Bayes spam probabilit

Re: Using spamassassin to thwart sharepoint phishing attacks

2021-04-11 Thread Steve Dondley
sorbs dnsbl missing, have you denied sorbs.net results ?, or is spamassassin not testing sorbs.net anymore ? Best I can tell, my SA config should be testing for sorbs. I've got this line in /etc/spamassassin/v3220.pre: loadplugin Mail::SpamAssassin::Plugin::DNSEval And in /usr/share/spama

Re: Using spamassassin to thwart sharepoint phishing attacks

2021-04-11 Thread Steve Dondley
Also, I've heard of sorbs over the years but I'm not sure exactly what it is. Is this the same block list run by Cisco? OK, I was getting SORBS confused with SenderBase Reputation Score (SBRS). That's the one run by Cisco, I believe. I actually have an account on the SORBS website that I s

Re: Using spamassassin to thwart sharepoint phishing attacks

2021-04-11 Thread Steve Dondley
sorbs dnsbl missing, have you denied sorbs.net results ?, or is spamassassin not testing sorbs.net anymore ? How would I check if it's turned on? I tried grepping in /etc/spamassassin on "sorb" (case insensitive) and found nothing. So I guess it's not in my default config. I see many men

Re: Using spamassassin to thwart sharepoint phishing attacks

2021-04-11 Thread Benny Pedersen
On 2021-04-11 22:43, Steve Dondley wrote: On 2021-04-11 04:19 PM, Benny Pedersen wrote: On 2021-04-11 22:09, Steve Dondley wrote: Content analysis details: (4.4 points, 5.0 required) pts rule name description -- ---

Re: Using spamassassin to thwart sharepoint phishing attacks

2021-04-11 Thread Steve Dondley
On 2021-04-11 04:19 PM, Benny Pedersen wrote: On 2021-04-11 22:09, Steve Dondley wrote: Content analysis details: (4.4 points, 5.0 required) pts rule name description -- -- 3.5 BAYES_99 BO

Re: Using spamassassin to thwart sharepoint phishing attacks

2021-04-11 Thread Benny Pedersen
On 2021-04-11 22:09, Steve Dondley wrote: Content analysis details: (4.4 points, 5.0 required) pts rule name description -- -- 3.5 BAYES_99 BODY: Bayes spam probability is 99 to 100%

Using spamassassin to thwart sharepoint phishing attacks

2021-04-11 Thread Steve Dondley
I've received about a dozen phishing attack emails from Microsoft's sharepoint service within the last couple of weeks. Only one of them was identified by SA as spam. After running the emails through sa-learn, they still only score a 4 to 4.5. But I could see that it would be easy for these ema