At 22:39 5/07/03 -0500, David B Funk wrote:
On Sat, 5 Jul 2003, Jack Gostl wrote:

>
> > > Over the past several weeks, I've noticed an increasing amount of
> > > spam that is getting through SpamAssassin with scores in the 4.0-4.9
> > > range. This makes me wonder if perhaps some spammers have started to
> > > taylor their spams as follows: run the default version of
> > > SpamAssassin, feed their messages through it, and keep tweaking the
> > > messages until SpamAssassin lets them through.
> >
> > Train bayes.  Everyone has a different bayes db, and they can't
> > work around that centrally.
>
> The problem I'm seeing is that I'm getting messages with a Bayes of 90%
> but it still slips through with 4.5-5.

I'm positive that spammers are tuning spam to get past SpamAssassin.
Last week, while looking at bounce rejects, I came accross two instances
of the same spam (same body, same open-proxy source) which had scores
that differed by more than 10. The difference was that one had
successfully forged headers to triggger the "nice" score for an
exchange server and the other had type-o's that caused it to miss
the "brass ring" (it got forged outlook header points ;).

I've seen several spam crafted to trip the "nice" scores for good MUAs
(USER_AGENT_*).

I've been adjusting down many of the "nice" scores as they're starting
to just reward clever spammers.

What version are you running ? It sounds like you're running 2.53 or earlier, which have some large negative scores. Nearly all the USER_AGENT scores and MSGID_GOOD_EXCHANGE are smaller than -1 since 2.54, so maybe its time you upgraded....


(By the way, just setting a bunch of negative rules to zero or reducing them will skew the scores of ham and spam, since on 2.54 the GA was re-run to readjust all the other scores to compensate for the lesser negative scores)

Regards,
Simon



-------------------------------------------------------
This SF.Net email sponsored by: Free pre-built ASP.NET sites including
Data Reports, E-commerce, Portals, and Forums are available now.
Download today and enter to win an XBOX or Visual Studio .NET.
http://aspnet.click-url.com/go/psa00100006ave/direct;at.asp_061203_01/01
_______________________________________________
Spamassassin-talk mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/spamassassin-talk

Reply via email to