From mailscanner at ecs.soton.ac.uk Wed Feb 1 09:03:42 2006 From: mailscanner at ecs.soton.ac.uk (Julian Field) Date: Wed Feb 1 09:08:23 2006 Subject: MailScanner ANNOUNCE: Version 4.50 released Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Morning all, A major new release this month, with around 40 new features and improvements. The major highlights are: - - Great speed improvements. Many sites are seeing 40% speed improvement. - - Auto-detection of installed virus scanners. - - Zero-configuration required on sendmail systems. You no longer need to set configuration options in MailScanner.conf, it will auto-detect the presence of SpamAssassin and your virus scanning engines. - - New UU-decoder to allow filename and filetype traps in UU-encoded files inside attachments. - - Many command-line options added to the "MailScanner" command so you can test your configuration, evaluate rulesets and debug your installation without have to set the debug options in MailScanner.conf. Type "MailScanner --help" for more information. "MailScanner --lint" is particularly useful. Download this major update from www.mailscanner.info ** Please note you will need to run the installation script ./ install.sh as several new modules have been added to it to support the new features. The whole Change Log is this: (as you can see, it has been a busy month :-) - - Speed increased significantly! Caches SpamAssassin results. Note you need to run my install.sh script to get the new modules required. - - If "Virus Scanners = auto" (ie. the installed default value) then it searches for and uses every available installed virus scanner. - - Added SpamAssassin cache analyser (analyse_SpamAssassin_cache) to the distributions. 99% written by Steve Freegard of MailWatch fame. - - Upgraded ClamAV+SA bundle to ClamAV 0.88. - - Added default headers that Thunderbird 1.5 will use to automatically identify spam based on SpamAssassin's spam headers. - - Added UU-decoder to automatically extract files from attachments that were stored in uu-encoded form. This behaves similarly to the zip and rar decoders. The virus scanners should check inside these files for themselves anyway, but this assists them when they do not. It also allows for filename and filetype checking of files stored in uu-encoded attachments. - - Added configuration option "Find UU-Encoded Files" to set whether uu-encoded files are decoded or not. These files are very rarely used, and the overhead of finding them is fairly large as it involves reading all existing attachments looking for the signature of them. So the default is to not look for them. A ruleset can be used to protect particularly vulnerable recipients or senders. - - You can now start up MailScanner without changing MailScanner.conf at all. It will auto-detect SpamAssassin and all available virus scanners. - - Changed default setting to "Use SpamAssassin = yes" and now auto- detect installation of SpamAssassin, logging installation instructions if it is not already installed and working. - - Added DBI and DBD::SQLite Perl modules. Please use my install.sh scripts when you upgrade or install this version. - - Added American spelling of "analyze_SpamAssassin_cache" as well as English spelling of "analyse_SpamAssassin_cache". - - DBI installation is forced in RPM distributions. - - Improved RPM installer to handle DBI module dependencies better. It now installs cleanly on the systems I have tested it on. These include Fedora Core 3, Fedora Core 4, SuSE 9.3, SuSE 10, RedHat Enterprise 4. - - Made log warnings more obvious when DBI/DBD::SQLite/Digest::MD5 are not all installed properly. - - Improved comments about "Allow Filenames" and "Allow Filetypes" in MailScanner.conf. - - Improvement to F-Prot output parser to handle new strings. - - Changed filename/type traps to account for new vulnerability in TNEF files. - - Adapted trend-autoupdate for 2006 onwards. - - --help implemented so you can see how to use it now. - - --debug now written. Works just like "Debug = yes" in MailScanner.conf. - - --debug-sa now written. Works just like "Debug SpamAssassin = yes". - - --check ruleset-checker now written. Takes max 1 from address, multiple to addresses, client IP address and virus name. - - Added a new command-line parameter "--lint" to verify the config file. - - --lint now prints what virus scanners you have chosen to use, and what - - --lint now checks SpamAssassin configuration too. scanners it can find installed. - - Added hi-res timing so the batch speed timings are now displayed to micro- second accuracy. - - Added Time::HiRes to the list of required modules. You must use ./ install.sh to upgrade to, or install, this version in order to get the new module. Time taken to process the entire batch is logged, and time taken to do "Always Looked Up Last" is logged separately if it is being used at all. - - Added check that MailScanner.conf has at least been customised to set the organisation name, long name and web site. - - Added "SpamAssassin Cache Timings" configuration option for the few people who need to adjust these settings. Do *not* change it unless you really know what you are doing, the default settings will work nicely. - - Updated important perl modules. - - Removed duplicate logging of warnings about infected messages. - - Added detection of no virus scanners being installed, giving the user advice about how to install ClamAV using my easy-installation package. - - Improved ClamAV+SA easy-installation package so that it automatically enables the updates by commenting out the "Example" lines. - - Changed default Lock Type for sendmail to "posix" instead of "flock" as new Linux systems (the most popular platform by far) run sendmail 8.13 or later, which requires this to be "posix". - - Upgraded Sys::Hostname::Long and HTML::Parser in ClamAV+SA package. - - Disabled movie format "deny" rules in filetype.rules.conf and have enabled filetype checking by default. - - Updated man pages. - - Updated AVG parser to handle latest version 7.1. - - Added "Always Looked Up Last After Batch" which is looked up after the "Always Looked Up Last" option. The 2nd of those is looked up once for each message, the "...After Batch" value is looked up once for the entire batch. It is only intended for use with a Custom Function, its value is ignored. * Fixes * - - Improved reliability of Bayes rebuilds a lot. - - Force installation of DBI as previous versions cause problems. - - Removed broken patch I was given, which was temporarily in 4.50. - - Packaging bug in 4.50.9-1 fixed. MailTools version typo. - - Fixed bug where temporary files were not cleaned up properly. - - Fixed missing HTML-Parser 3.48 package. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ+B5cPw32o+k+q+hAQGSRAgAk+ufLJo6cBuy6ZANssZ5GpjUWcPLMqkU GuRYKj36B6nklbEmhlmyJeib8J/zqseo9Yk03Ppi5P+z8uKsc2bVrVhArPeLB8j2 YkMF/jADsoB85Z8CSRxJBR3LBo+/uZuZRr9q23DFl7YeQQKfPe01I8vqX1MRHLnR P2XB5JM2yQ+yR3Ae+wVqdEn7llN1SS/VVkH5ytJUBcFOWsr4MajyShxXqnrQ4Wut xy9cKSA61uZeW3r2OCvygxrIBzxeH+5rxoZnZUAL4CVOUpVgswj0fn0g6GQohZGR NtIW6Er646I83XIuuuPPTNiAnBne8AlXUJnDieCLnTiNtiygxxWUvA== =sGbd -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Wed Feb 1 15:54:12 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Feb 1 15:54:38 2006 Subject: MailScanner ANNOUNCE: Thunderbird 1.5 support Message-ID: <6BA4D37A-055B-44DB-A21A-EDA100164C49@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Thunderbird 1.5 has the ability to trust the spam headers generated by SpamAssassin. It uses these headers to automatically put all identified spam into the user's "Junk" mailbox, so the users don't have to write any filters or anything like that. All new installations of MailScanner generate the correct headers for this. If you want to add support for this to your existing MailScanner setup, simply use the "header" Spam Action to generate them for you. Put these into your MailScanner.conf file: Spam Actions = deliver header "X-Spam-Status: Yes" High Scoring Spam Actions = deliver header "X-Spam-Status: Yes" Non Spam Actions = deliver header "X-Spam-Status: No" - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ+DZp/w32o+k+q+hAQE2Sgf/alqO2uPYCdbG2U7B+ZdAoyNsiiWrV55s nJj4t0qhEM05ujTRn1AwHDsD14X8RBKc2opM8vv6Dd5I5lVk3z2+VOLCE/bnwRxX ICQ1NQ/vGjIrtj7VwPAroCoZJjbxXqUaJSf0L2ePhPQ50s/Wu+GJbdxSWO44Xa5m EHPbC4o7SU/E0VTynj7Wjy0UKEpTJJBVZ1imw70FFgldlwY31coF7g3qqFwW8XDp M3Za8swbe63oEzuegntsCwj2/hSlW1Pm97sxSildD4Jg/VGGBFwLCHDTlCuyVr0w hXLXiiT83XlxGNq484XSuYQpLVSyUYfiB3PFrnm1lq7y9MU/VPh/oQ== =tl+A -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean.