From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:14:07 2006 Subject: No subject Message-ID: Virus Scanner = mcafee Sweep = /usr/local/bin/mcafeewrapper When the setting is uning sophos, i.e. Virus Scanner = sophos and Sweep = /usr/local/bin/sophoswrapper, it works ok. Please see the floowing for detail. Thanks, Bruce The log: Nov 19 08:54:10 hudson.geog.utoronto.ca sm-mta[14733]: fAJDs9GT014733: from=, size=202672, class=0, nrcpts=1, msgid=, bodytype=8BITMIME, proto=ESMTP, daemon=MTA, relay=credit.erin.utoronto.ca [142.150.1.1] Nov 19 08:54:10 hudson.geog.utoronto.ca sm-mta[14733]: fAJDs9GT014733: to=, delay=00:00:00, mailer=esmtp, pri=240797, stat=queued Nov 19 08:54:33 hudson.geog.utoronto.ca mailscanner[13342]: Using flock() to lock /var/spool/mqueue.in/qffAJDs9GT014733 Nov 19 08:54:33 hudson.geog.utoronto.ca mailscanner[13342]: Using flock() to lock >/var/spool/MailScanner/incoming/fAJDs9GT014733.header Nov 19 08:54:34 hudson.geog.utoronto.ca mailscanner[13342]: >>> Virus 'W32/Sircam-A' found in file ./fAJDs9GT014733/National Diploma in Forestry.doc.com Nov 19 08:54:34 hudson.geog.utoronto.ca mailscanner[13342]: Found 2 viruses in messages fAJDs9GT014733 Nov 19 08:54:34 hudson.geog.utoronto.ca mailscanner[13342]: Saved infections to /var/spool/MailScanner/quarantine/20011119/fAJDs9GT014733 Nov 19 08:54:34 hudson.geog.utoronto.ca mailscanner[13342]: Using flock() to lock >/var/spool/mqueue/dffAJDs9GT014733 Nov 19 08:54:34 hudson.geog.utoronto.ca mailscanner[13342]: Using flock() to lock >/var/spool/mqueue/tffAJDs9GT014733 Nov 19 08:54:38 hudson.geog.utoronto.ca mailscanner[13342]: >>> Virus 'W32/Sircam-A' found in file ./fAJDs9GT014733/National Diploma in Forestry.doc.com Nov 19 08:54:38 hudson.geog.utoronto.ca mailscanner[13342]: Found 2 viruses in messages fAJDs9GT014733 Nov 19 08:54:50 hudson.geog.utoronto.ca sendmail[14740]: fAJDs9GT014733: to=, delay=00:00:40, xdelay=00:00:15, mailer=esmtp, pri=330797, relay=terre.geog.utoronto.ca. [128.100.91.6], dsn=2.0.0, stat=Sent (IAA02441 Message accepted for delivery) From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:14:12 2006 Subject: No subject Message-ID: (which I had implicitly assumed anyway) would be a great step forward. The Solaris pkg would then be "icing on the cake". > Once that's done, then it should be easier to create packages for any of > the popular package management systems (by causing the installer to put > everything under a previously-empty subdirectory). Agreed: something like gmake install DESTDIR=temp-build-dir cd temp-build-dir I have successfully use this for a completely different project (which had also included the additional (and to us irrelevant) tricky issue of shared libraries). > In the end I would expect that rpm, solaris pkg, *bsd pkg, and debs at least > would be worth having. Certainly. > > 2. If the idea meets with Julian's approval, and if there are several > > other sites which would positively wish for Solaris/pkg, then I might > > be able to volunteer to take an initial look at it (although it would > > have to be at low priority...). > > Once a generic installer is done, it should be much easier to create > platform-specific packages; I'd encourage anyone who's considering trying > to make packages for any particular platform to mail me and offer to help > with the generic installation system, so that we can: a) get it done, and > b) make sure that it really does make it easier to create their particular > type of packages. Given this encourage from you (and from Julian in a separate message) I'm trying to knock up a small automake+autoconf scheme at the moment... -- : David Lee I.T. Service : : Systems Programmer Computer Centre : : University of Durham : : http://www.dur.ac.uk/t.d.lee/ South Road : : Durham : : Phone: +44 191 374 2882 U.K. : From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:14:14 2006 Subject: No subject Message-ID: repeatedable currently, so the config reader may puke on it too. -- Neither sweat, nor blood, nor frustration, or lousy manuals nor missing parts, or wrong parts shall keep me from my task. From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:14:21 2006 Subject: No subject Message-ID: Full headers are: Return-Path: Received: from ......rest of the headers Not a real header you might expect... but it's a start... Browsing back through my old virus warnings, it looks like something concerning this has changed between versions 3.02-1 and 3.03-1 of MailScanner. And btw, yes this last warning was about the MyParty virus. Tnx for being so darn fast with fixing MailScanner to detect it! -- Evert Jan van Ramselaar Van Ramselaar Info Tech ___ This message has been scanned for viruses and other dangerous content by Van Ramselaar Info Tech and is believed to be clean. See http://www.vr-it.com/emailpolicy.php From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:14:24 2006 Subject: No subject Message-ID: fastest way of doing things. Gene > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK]On > Behalf Of Todd Martin > Sent: Wednesday, February 06, 2002 12:27 AM > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: SpamAssassin stand alone or invoked by mailscanner > > > Hi all, > > I'm in the process of testing mailscanner. I want to also use > filtering with SpamAssassin. > > On a cursory glance, it seems like I loose my per-user preferences > (threshold, etc.) for SpamAssassin if mailscanner invokes > SpamAssassin. Is this correct? > > What other trade-offs are there between SpamAssassin stand alone or > invoked by mailscanner? Is one way faster (higher through put)? > > ~Todd > From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:14:29 2006 Subject: No subject Message-ID: collaborative, spam detection and filtering network." Sander -- This mail was scanned for viruses by MailScanner (www.mailscanner.info) From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:14:29 2006 Subject: No subject Message-ID: collaborative, spam detection and filtering network." Sander -- This mail was scanned for viruses by MailScanner (www.mailscanner.info) From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:14:34 2006 Subject: No subject Message-ID: like a lot would have to be rewritten to get mailscanner to rewrite the message to include the report and return it to the main routine. Though I could be wrong, I'd have to review it again. =20 =20 -----Original Message----- From: Kelly Hamlin [mailto:fizz@BOMB.NET]=20 Sent: Tuesday, March 26, 2002 11:31 PM To: MAILSCANNER@JISCMAIL.AC.UK Subject: Feature Request As you may or may not have noticed, people have been wanting the ability to A. Know what spam is being scored even when it doesnt meat the threshold. and B. Be able to include the terse report that spamassassin uses.. Ex:(damnit, cant find example) Anyway it shows which elements of the message scored what. Which would then allow you to further tweak the scores. I think mailscanned is a wonderful utility and as it gets more users/features will continue to be the best. =20 I would love to see better intergration ability with spamassassin and maybe razor in future releases. And maybe a flat text file whitelist for people you dont want mailscanner to mark ANY mail as spam, and still scan for virus's. Basically a little more flexability. I know some requests are a little iffy, but im interested to see how many people would like this functionality from the wonderful mailscanner by its incredibile author Julian :) =09 =20 ------_=_NextPart_001_01C1D550.629EACA8 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Message
It=20 already does the whitelist.  When Mailscanner first started using = SA, I=20 made some modifications in sendmail.pl within the SAForkAndTest sub, = after the=20 line
    $SAResult =3D int($spamness->get_hits()) = if=20 $SAResult;

I added
 
    if ($SAScore >=3D5)=20 {
      $spamness->rewrite_mail=20 ();
      my $SARewrite =3D=20 $spamness->get_full_message_as_text();
    &nbs= p;=20 local(*DOUT);
      open(DOUT,=20 ">>/var/spam/queue/spr$mID") or Log::DieLog("Failed to create copy = of spam=20 message spr$mID");
      print DOUT=20 $SARewrite;
      close = DOUT;
  =20 }
 
This=20 dumps the message including the SA report into a queue.  This = allows me to=20 take samples and also to report the messages as spam to=20 razor.
 
Oh yeh=20 I had to added $mID to the subroutine call so the
 =20 $SAResult =3D SAForkAndTest($SAspamtest, $spammail); =
became  
 =20 $SAResult =3D SAForkAndTest($SAspamtest, $spammail, = $mID);
and=20
  my($Test,=20 $Mail) =3D @_;
became
  my($Test, $Mail, $mID) =3D=20 @_;
Granted I could probably stop doing this since I think Julian = mentioned=20 adding the ability to forward or cc the spam messages to an=20 account.
 
From=20 what I can see in the code with my amateur perl knowledge, it looks like = a lot=20 would have to be rewritten to get mailscanner to rewrite the message to = include=20 the report and return it to the main routine.  Though I could be = wrong, I'd=20 have to review it again.
 
 
-----Original = Message-----
From: Kelly=20 Hamlin [mailto:fizz@BOMB.NET]
Sent: Tuesday, March 26, 2002 = 11:31=20 PM
To: MAILSCANNER@JISCMAIL.AC.UK
Subject: Feature=20 Request

As you may or may not have noticed, = people have=20 been wanting the ability to A. Know what spam is being scored even = when it=20 doesnt meat the threshold. and B. Be able to include the terse report = that=20 spamassassin uses..
Ex:(damnit, cant=20 find example)
Anyway it shows which elements of the = message=20 scored what. Which would then allow you to further tweak the=20 scores.
I think mailscanned is a wonderful = utility and as=20 it gets more users/features will continue to be the best.
 
I would love to see better = intergration ability=20 with spamassassin and maybe razor in future releases. And maybe a flat = text=20 file whitelist for people you dont want mailscanner to mark ANY mail = as spam,=20 and still scan for virus's. Basically a little more flexability. I = know some=20 requests are a little iffy, but im interested to see how many people = would=20 like this functionality from the wonderful mailscanner by its = incredibile=20 author Julian :)
 
=00 ------_=_NextPart_001_01C1D550.629EACA8-- From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:14:35 2006 Subject: No subject Message-ID: color, at least. We're thinking about changing that. Kinda. We're running out of usable color schemes. I'd like to use the same background images in each newsletter, which will actually speed up things for those of you who read more than one regularly (since they'd be cached). This will also decrease our server load, and allow us to use new colors without having to get too creative. "Huh?" The title bars and text colors will stay - they're great visual cues. I'm hoping to make the background images color neutral, like a much lighter (and whiter) spin on the one we're currently using for the Penguin Shell. I may have a mock-up for y'all soon. Of course, by then, we may have switched everything over to the "new" system. This is a functional change, folks. I'm interested in hearing what you have to say about it first, though. Don't make me break out the burnt sienna; it was bad enough when we decided on sea foam (hospital) green for the Bits & Bytes. Paging Dr. Scalability!

See You in August,              
Chris Pirillo       


 GnomeDOWNLOADS

Molecular Weight Calculator v6.12 [2.1M] W9x/2k/XP FREE

http://jjorg.chem.unc.edu/personal/monroe/download/mwt6_12s.zip
http://jjorg.chem.unc.edu/personal/monroe/mwtwin.html
http://screenshot.lockergnome.com/molecularweightcalculator.png

{Weigh them molecules} Who needs a molecular weight calculator? I sure don't. But you see, my friends, I not only feature stuff that's useful to me, but stuff that might be useful to others, as well. Therefore, let me introduce all of you "chem" Gnomies to this lovely little calculator. It contains a formula finder, an amino acid notation converter (I just sold mine on eBay last month), and a capillary calculations monitor - just to name a few features. "Note the notation used to enter a molecular formula and note how the program can display multiple formulas simultaneously, while formatting them with subscripts as needed, plus superscripts for isotopes." Yes, please note that. Don't make me repeat it 6.022 times ten to the 23rd times.


Verbix v4.2 [1.2M] W9x/2k/XP FREE

http://koti.welho.com/elindber/download/vrbxl423.zip
http://www.verbix.com/windowsverbix/
http://screenshot.lockergnome.com/verbix.png

{Mastering foreign verbs} Conjugations can tie a person's head in knots. Not to mention, their tongue. Okay, they might not be too difficult to understand in your native language, but what if you're trying to study a different one? Those things can trip you up bigtime. This program was designed specifically for learning verbs; over one hundred languages are supported (pending registration). Besides being a wonderful learning tool, it can also save you a lot of "look it up in the dictionary" time. "Unlike any other sources, Verbix for Windows also returns the glossary look-up form from any inflection; you no more need to know them by heart!" Free languages include: Arabic, Dalmatian, Ancient Egyptian, Classical Greek, Mandarin Chinese, Japanese, Klingon, and a few others.

Recommend It!


 GnomeCLICKS

Giving you the power to quickly and easily avoid the hassle of junk mail, Inbox Protector is a Microsoft Outlook add-In, which scans incoming E-Mail, redirecting unwanted junk mail to a separate folder for later inspection if necessary. TECHNOLOGY can be frustrating for new and intermediate computer users, UNTIL NOW. Join us for a FREE Windows Newsletter, video tutorials, articles, special reports, and more! IPCheck Server Monitor monitors a network using various protocols (e.g. ping, http, smtp, ftp) and notifies the staff in various ways as soon as an outage occurs. Shortcut to RDesk.exe Webserver Stress Test Tool simulates simultaneous users accessing a web server and helps to streamline your web application. Essential for every web developer, webmaster or web marketer!


 GnomeSYSTEM

How to Use Dates and Times in Microsoft Excel

http://support.microsoft.com/default.aspx?scid=kb;EN-US;Q214094

"Microsoft Excel stores all dates as integers and all times as decimal fractions. With this system, Excel can add, subtract, or compare dates and times just like any other numbers, and all dates are manipulated by using this system. In this system, the serial number 1 represents 1/1/1900 12:00:00 AM. Times are stored as decimal numbers between .0 and .99999, where .0 is 00:00:00 and .99999 is 23:59:59. The date integers and time decimal fractions can be combined to create numbers that have a decimal and an integer portion. For example, the number 32331.06 represents the date and time 7/7/1988 1:26:24 AM. To help you perform complex date and time calculations, Microsoft Excel includes many built-in date and time functions."

Recommend It!


 GnomeASSISTANT

Enough with the Passwords, Already!
Scribbled by Ron Pelton

Jake wrote about e-commerce solutions while explaining the absence of your store. Sounds like he found a good one, but now I get just a little steamed. When grocery shopping, fueling the family transportation system, Christmas shopping, or whatever commerce that is done in the non-digital world, do you have to provide a password so that a merchant will let you browse or (worse) let you make a purchase. Of course not!

At this point, I have password overload and have sworn off online purchases. There are some exceptions, however. To date, 26 online merchants have lost me as customer because of a request for a password. I have written to each one of them after backing out of their shopping carts to let them know that they lost a sale - and to request a rational reason [as to] why I should invoke an accounting program to track passwords when it is not necessary in real life. Even bizrate.com, which provides a wonderful service, has begun some selling on its own and lost a sale to me. NOBODY has even had the courtesy to respond with an attempted answer. The truth is, all you need is enough personal information to conclude that I am a real person with a real credit card, which is more than they do at Wal-Mart where they don't even bother to compare signatures (or even gender). I hope Jake's new program is customer friendly, not just administratively friendly.

(Furo) Agreed. It's stupid to have to register on a site just to place an order with them. It's not like they won't have a way to market to you anyway, so why the registration? Oh, gee whiz, so you remembered my shipping address... big deal. One way I get back at them is to re-register every time I place a new order, creating an email account just long enough to get the receipt, then I destroy the email account so further emails are bounced back to them. Sure, it's a little more work, but bleep 'em. It's worth it! I don't normally do that for large sites like Amazon, but I do for the small shops. I did that exact thing on Monday to a site because they forced me to register. My order should be here today and I'll never have to hear from them again and I don't have to remember a password for their site.

(Jake) Actually, until the legal system gets changed to more closely match the Internet transaction space, or a better verification system gets put in place to make fraud less likely, the more information a site can gather and store about its customers, the better. The burden of proof with all transactions occurring on the Internet lies with the seller. If a purchaser chooses to block the transaction, even after they've already received delivery of the product, too bad for the retailer - they eat the cost of the merchandise and get an extra charge to boot. Lockergnome can't afford those risks; I'm guessing that most small retailers can't either. If that happened with only one transaction, it would take as many as several hundred transactions to make up the lost revenues.

Making customers provide more information about themselves helps ensure that abusers are going to be less likely to want to cheat the system because it becomes inconvenient. It is less expensive for a company to sit on extra inventory, creating a longer inventory turn cycle - even if that inventory might have been sold to a legitimate purchaser if they hadn't been forced to jump through an extra hoop and provide information. In addition to decreasing the likelihood of people defrauding the system in the first place, retaining more information also provides further ammunition for proving that the transaction was legitimate when it gets called into question by the credit card company.

Many Internet sellers, including the previous company that hosted our store's fulfillment, even go so far as to require buyers to FAX a copy of the card for them to keep on file - in an effort to take an extra step to ensure that they weren't dealing with a phony. This did tick off some people (who chose not to purchase), but it also kept their chargebacks down to virtually zero, with their closest competitor in their space incurring upwards of $80k in chargebacks per quarter. It would take a hell of an increase in transactions to justify losing $25k+ / month to fraudulent transactions.

By our collecting names and addresses, forcing people to log in, we've added a layer of protection that should act as a minor fraud deterrent. If that also blocks a few purchases along the way, so be it. If I truly believed that we would do more volume by making the purchasing process easier and simultaneously not lose any money by taking an extra risk, by all means - I'd go with a system that was more "wide open." However, people exist who will take advantage of any easy means of defrauding the system, so until there is a better system for defeating fraud, the "best" system is having as much information as possible.

Discuss This Topic | Recommend It!


 GnomeFAVORITE

Open Diary

http://www.opendiary.com/

{Read my thoughts} If you share your diary openly with other people, should it still be called a diary? That was a rhetorical question, really - it just popped into my head while I was browsing the entries available here. Perhaps I might add my own soon. "Today I almost asked Susie to the Homecoming Dance. I hope my Camaro starts." Anyway, if you have something to say and don't mind sharing it, give this a short spin. There is a charge to use the service, but it's small change, trust me. "Open Diary is the next generation of online diary communities. This community will be limited to only 10,000 members. We are currently home to 2,821 online diarists." There ya go - rather exclusive.

Recommend It!


 GnomeTIP

Who here doesn't use a Microsoft Office application on a regular basis? Wow. I didn't realize there were so many of you. Look at those icons. I mean, each one is a miniature work of art. Except that one. Right there. You know, the ugly one on the end? Right- click on a Toolbar and select the Customize option. Now, right- click on any given "ugly" icon you'd like to change. Yes, that Change Button Image menu is nice for other pre-formatted icons, but what if you don't see what you want in there? Easy. Select the Edit Button Image option. Look at that - a pseudo icon editor. If you're so inclined, you can also edit menu items. As long as that Customize dialog is still open, you can left-click to open a menu, then right-click on any given option and change or add its icon. If you mess up, then simply select the Reset Button Image option. This thing is foolproof. Sure, you don't have many colors to choose from, but how fancy do you really need these things to be? I made a strawberry for Word's Insert Field menu option. It'll stay there forever.

Recommend It!



 Geekathon 2002

 Latest Windows Daily
 Latest Digital Media
 Latest Tech Specialist
 Latest Penguin Shell
 Latest Web Weekly
 Latest Bits & Bytes
 Latest Audio Show

 The GnomeSHOPPER

 Recommend Us!
 Advertise With Us
 High-Tech Job Search
 Chat With Gnomies
 Watch The Webcams
 Chris Pirillo's Blog
 Computer Power User

 Visit Our Forums
 Submit Your Opinion
 Read Past Issues
 Download X-Setup
 About Lockergnome
 Our Privacy Policy
 View More Options
 Get Chris's Book
 Win a Digital Camera

 Questions / Help
 Submit Suggestions
 Rants & Raves
 General Feedback
 E-mail the Editor

 Our XML / RSS Feed
 Syndicate Our Tips
 Link To Lockergnome

Syndicate Today's Content

 


Samsung V1000
Pioneer DV-444
Sony DVP-NS700P
Toshiba SD-5700
Panasonic DVD-RP56
Apex AD-1500
HP Access Point
Sony DVP-NS900V
Philips DVDR1000
RCA RC5240P

 


 Movie Collector
 Make Your Own Music
 ClipManager
 Boomer! Stream Now
 CaptureWizPro
 Pretty Good Solitaire
 Visualize Color Combos
 FirstStop WebSearch
 Ecobuilder
 Tag&Rename
 Financial Advisor
 500+ PC Tips
 EbooksWriter LITE

Get Listed Here

Question: which group is 250,000+ strong and always looking for stuff to make their personal and professional lives run smoother?

 


And now, after you do a little ComputingX, see how stupid I can really be. I dare you to be more stupider. It's not going to happen in my lifetime.

Did You Touch This?

 

Lockergnome Webcam Image
CLICK HERE TO ZOOM

 


©2002, Lockergnome LLC. ISSN: 1095-3965. All Rights Reserved. Please read our Terms of Service. Our Web site is hosted by DigitalDaze. Domain registered at DNS Central. I'll have four fried chickens and a Coke.

 


--------------060303060505010002000705-- From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:14:37 2006 Subject: No subject Message-ID: best way to go. Miguel David Pollard wrote: > Hi There, > > I have a test system up and running with Sophos but I'm having a hard > time finding a single user price for Linux(or in fact any pricing at > all). Their sales guys don't want to talk to me because I don't want to > buy a copy for every machine in the place. > > I have also been digging around on McAfee / Network Associates web site > for pricing but can't figure out which product to use on Linux? > > Can someone give me a point in the right direction please? > > David Pollard. From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:15:12 2006 Subject: No subject Message-ID: mbox variations, but anyway...) seems to state that the date portion will be exactly 24 characters. Currently, df2mbox just calls "date" to get the date when generating the from line: echo From $from `date` My system currently outputs something like this for `date`: Mon Jul 8 19:04:45 EDT 2002 ...which is too long and not liked by pine because it isn't in the mbox format that it expects. As a quick fix, I changed the line to: echo From $from `date "+%a %b %d %T %Y"` ...so that the date generated looks like: Mon Jul 08 19:06:36 2002 ...and, I believe, should always be the required 24 characters. Pine now likes the mbox-formatted file fine. Just wanted to pass that along. - John... From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:15:18 2006 Subject: No subject Message-ID: not, and the message IDis the only thing that changes. See below. With Hide Incoming Work Dir = yes ==> Snippet from notice sent to "sender" ==== The virus detector said this about the message: Report: /var/spool/MailScanner/incoming/g6P1F1l05412/EICAR.COM Infection: EICAR_Test_File ===== Snippet from "VirusWarning.txt" sent to recipient: ===== At Wed Jul 24 18:15:23 2002 the virus scanner said: g6P1F1l05412/EICAR.COM Infection: EICAR_Test_File Note to Help Desk: Look on the MailScanner in /var/spool/MailScanner/quarantine (message g6P1F1l05412). ===== With Hide Incoming Work Dir = no Snippet from notice sent to "sender" ==== The virus detector said this about the message: Report: /var/spool/MailScanner/incoming/g6P1Ie405526/EICAR.COM Infection: EICAR_Test_File ===== Snippet from "VirusWarning.txt" sent to recipient: ===== At Wed Jul 24 18:18:50 2002 the virus scanner said: g6P1Ie405526/EICAR.COM Infection: EICAR_Test_File Note to Help Desk: Look on the MailScanner in /var/spool/MailScanner/quarantine (message g6P1Ie405526). ===== Thanks, Nathan Johanson nathan@tcpnetworks.net From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:15:33 2006 Subject: No subject Message-ID: /usr/~/Sophos.install *.Z It ran and did do an update sucessfully. But when Cron runs Sophos.update or when I (as root) run it manually. We get the line 77 bs from /usr/~/autoupdate still However, After I ran the install IT DID update to the latest av files. But no more nightly updates still :( I am using MS version 3.20.8 with no problems except for the AV update. On RedHat 7.2 Thank You ------=_NextPart_000_000C_01C258B4.ACB2ED00 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Julian, 
 I have done what you previously = stated=20 about Sophos update line 77 failure. And its still reporting it[Matt = Doherty] .
 
I deleted everything Except for the /bin/ = directory=20 under /usr/local/Sophos
 I had already d ownloaded the new = lib6.~.Z file=20 from Sophos.
From the directory where i had downloaded it = to I ran=20 your script
/usr/~/Sophos.install=20 *.Z
 
It ran and did do an update=20 sucessfully.
But when Cron runs Sophos.update or when I = (as=20 root) run it manually. We get the line 77 bs from = /usr/~/autoupdate=20 still
However, After I ran the install IT DID = update to the=20 latest av files. But no more nightly updates still=20 :(
 
I am using MS version 3.20.8 with no problems = except=20 for the AV update. On RedHat 7.2
 
Thank=20 You
------=_NextPart_000_000C_01C258B4.ACB2ED00-- From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:15:45 2006 Subject: No subject Message-ID: - something is wrong with paths in the script, my installation of mcafee is in /usr/local/uvscan? I tried with f-prot and it works fine. So I thought maybe my comp was stupid so I did a try on another comp. There it starts without a bailout but it doesnt finish and no lookfile is writen to /tmp Any good or bad advice for me to try because Im lost. /Anders > -----Ursprungligt meddelande----- > Från: Julian Field [mailto:mailscanner@ECS.SOTON.AC.UK] > Skickat: den 23 september 2002 23:58 > Till: MAILSCANNER@JISCMAIL.AC.UK > Ämne: Re: SV: Fix in uvscan/autoupdate > > > At 17:59 23/09/2002, you wrote: > >As the bad perl knowledge I got I need to ask where these > >lines are supposed to be in the script? > > Around line 66 as it says at the start of the patch. > > > >/Anders > > > > > -----Ursprungligt meddelande----- > > > Från: Julian Field [mailto:mailscanner@ECS.SOTON.AC.UK] > > > Skickat: den 23 september 2002 18:11 > > > Till: MAILSCANNER@JISCMAIL.AC.UK > > > Ämne: Fix in uvscan/autoupdate > > > > > > > > > There appears to have been a change in the syntax of the > McAfee uvscan > > > program, which means that the "autoupdate" script for it will > > > bail out with > > > a "no target specified for scanning" error. > > > > > > To fix this, just apply this tiny change to uvscan/autoupdate (or > > > lib/mcafee-autoupdate in V4). > > > > > > --- autoupdate.old Mon Sep 23 11:01:01 2002 > > > +++ autoupdate Mon Sep 23 11:11:31 2002 > > > @@ -66,7 +66,7 @@ > > > # to see if the new dat's are o.k attempt to run mcafee > > > with them and > > > # check for errors > > > print STDERR "About to run mcafee\n"; > > > -open(MCAFEETEST, "$mcafee -d $mcafeeroot | "); > > > +open(MCAFEETEST, "$mcafee -d $mcafeeroot . | "); > > > print STDERR "Running mcafee\n"; > > > while(){ > > > chomp; > > > -- > > > Julian Field Teaching Systems Manager > > > jkf@ecs.soton.ac.uk Dept. of Electronics & > Computer Science > > > Tel. 023 8059 2817 University of Southampton > > > Southampton SO17 1BJ > > > > > -- > Julian Field Teaching Systems Manager > jkf@ecs.soton.ac.uk Dept. of Electronics & Computer Science > Tel. 023 8059 2817 University of Southampton > Southampton SO17 1BJ > From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:16:29 2006 Subject: No subject Message-ID: (or any other unsupported mail server), which points the reader to Q16 of the of the Installation FAQ, I gather that this is not out of the ordinary and that it indeed can be done. In fact, I observed that there are some instructions on how to do it. However, as a home linux user, I did not quite understand all that was being explained. So I went looking for more information to hopefully help me out. After a few days of digging around, I uncovered the following information. >From the Web site: http://www.tropicseas.net/reference/sysadmin/html/v09/i02/a6.htm I read the article "A Linux Email Server" by Marcel Gagné. In this article he talks about "Setting up Sendmail". (see below for excerpts) My question are, would a configuration like that discussed in Marcel's article: 1. work with MailScanner. 2. fit my scenario for my home linux network? >From the article: "Depending on how your account is set up with your ISP, the domain name of your server may be something like dhch3-ip1.theirdomain.com , which is not the best name for setting up the email gateway. For a return address, user "fred" would wind up as fred@dhcp3-ip.theirdomain.com, when sending mail from the local system. You can have the Sendmail program put in your domain name by making the one modification that I recommend in the Sendmail configuration file. I mentioned that this email server is not going to be connected to the Internet, but if you make this easy change now, you won't need to do it later. Using your editor, open /etc/sendmail.cf and look for the lines shown in Listing 1. Notice the part that talks about my official domain name. The line that reads Dj$w.Foo.COM has been copied and rewritten with the domain name to define the "Dj" macro. A macro in Sendmail parlance is very much like an environment variable in your Bourne, Korn, or C shell. The Dj macro references your canonical hostname. For this article, I'll call the domain mycompany.com. That is the only change needed in the /etc/sendmail.cf file. The next file to modify is /etc/sendmail.cw. This file contains a list of all the domains and systems for which the server will accept mail. For instance, if you edit the file with your editor, and add the domain name (mycompany.com) and the localhost name (localhost), you end up with this simple file: # sendmail.cw - include all aliases for your machine here. mailserv mailserv.mycompany.com mycompany.com localhost This tells the Sendmail daemon to accept mail messages addressed to either user@localhost, or user@mycompany.com, or any of the aliases you have set up. Next, you need to edit /etc/mail/relay-domains. One of the great annoyances of modern email is SPAM (those unwanted bits of advertising that seem to rain down in your email box). Particularly galling are the spammers who use other people's email servers to route their mail traffic. Fortunately, the modern incarnations of Sendmail make it difficult for spammers to use your machine as a relay. In fact, unless otherwise specified, Sendmail will refuse to deliver messages from unfamiliar machines or domains. That is where the relay-domains file comes into play. Edit the file and add the following: localhost 127. mycompany.com 192.168.1. This should cover all hosts in your small, networked office, including any need you have for using Sendmail to relay messages on the server. Be sure to include the dot at the end of your localhost domain address (127.) and at the end of your private network and domain (192.168.1.)." AND "That's all you really need to do with Sendmail and IMAP in order to send and receive mail on this small network. To DNS or Not to DNS For Sendmail to route mail properly, it must be able to resolve domain names to IP addresses. An email server operating on the Internet uses DNS servers for name resolution. Simply put, a DNS, or Domain Name Server, takes a system's IP address and converts it to a more "human" name (like mailserv.mycompany.com). It will also convert that name back to its numeric IP address. On the server, mailserv.mycompany.com would become 192.168.1.100, or vice-versa. This requires the setup of "zone" files and domain tables and can be quite complex. For the small network here, it is easier to list host-to-name-to-IP-address mappings in the /etc/hosts file: 127.0.0.1 localhost 192.168.1.100 mailserv.mycompany.com mailserv mycompany.com 192.168.1.31 john 192.168.1.32 myrtle 192.168.1.33 bonnie 192.168.1.34 gilbert 192.168.1.35 elvis 192.168.1.36 tux Usually, the standard Linux install fires up with a DNS already present. This is a simple version called a "caching nameserver". For this example, you need to get rid of it or it will try to use the DNS to resolve the address of the local machine. The mail client will usually time out waiting for the system to return with a failed DNS lookup, which is not a good idea. The easiest way is to rename the /etc/resolv.conf file: # mv /etc/resolv.conf /etc/resolv.conf.orig Next, stop the DNS by shutting down the named daemon: # /etc/rc.d/init.d/named stop To make sure named does not restart on boot, use this command: # chkconfig --del named Of course, if your network has been set up for a while and you have a fully configured DNS, you should simply continue using it." For the full article: http://www.tropicseas.net/reference/sysadmin/html/v09/i02/a6.htm Thanks! Steve Dawes PH: (403) 268-5527. Mailto: sdawes@calgary.ca NOTICE:: This communication is intended ONLY for the use of the person or entity named above and may contain information that is confidential or legally privileged. If you are not the intended recipient named above or a person responsible for delivering messages or communications to the intended recipient, YOU ARE HEREBY NOTIFIED that any use, distribution, or copying of this communication or any of the information contained in it is strictly prohibited. If you have received this communication in error, please notify us immediately by telephone and then destroy or delete this communication, or return it to us by mail if requested by us. The City of Calgary thanks you for your attention and cooperation. From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:17:04 2006 Subject: No subject Message-ID: But that seems to be wrong. When setting confQUEUE_LA to 0, sendmail never sends mails from its outgoing queue. After changing the value back to 8, my problem disappeared. Background: We are scanning incoming and outgoing mails. Customers who are using some scripts to send mail complained, when our MailScanner machine refused to accept mail when it was under high load. Viele Grüße -- Heinz > -----Original Message----- > From: Knutzen, Heinz (DZ-SH) > Sent: Thursday, January 23, 2003 6:11 PM > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Some mails in outgoing queue don't get processed > > > Hi, > > since yesterday I have trouble with my sendmail/mailscanner setup: > Some mails remain in /var/spool/mqueue and don't get processed. > There are thousands of mails which get processed ok, > but I have about 70 mails with dates from yesterday to now > which stay in /var/spool/mqueue all the time. > > When doing 'mailq', all 70 mails are shown. > But if I do a 'sendmail -v -q', only 1 or two recent mails > are processed. > All of these qfiles have lines like > > qfh0N1Ohvm007970:MDeferred: Connection refused by [10.48.242.10] > qfh0N6Okvm012640:MDeferred: Connection timed out with [10.107.64.10] > > but currently there are now connection problems. > Restarting sendmail and removing /var/spool/mqueue/.hoststat/ > doesn't help either. > > Any ideas, how to get them delivered? > > Version info: > mailscanner-4.05-3 > sendmail-8.12.2-88 > > Viele Grüße > > -- Heinz Knutzen > > Datenzentrale Schleswig-Holstein > Altenholzer Str. 10-14, 24161 Altenholz, Germany > http://www.dzsh.de/ > mailto:heinz.knutzen@dzsh.de > Tel: +49.431.3295.6581 Fax: +49.431.3295.410 > From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:17:48 2006 Subject: No subject Message-ID: gave "Error initialising detection engine - missing part of virus data". Invoked the "autoupdate" script again which appears to run OK. The files under /usr/local/Sophos/* appeared to be updated OK again but the error still appeared. However noticed that when I invoked "sweep" directly on a file it works OK. That is: ./sweep /tmp/eicar.com # OK ./sophoswrapper /tmp/eicar.com # Error initialising detection ... So modified "sophoswrapper" as follows ( added #TMP#) so that "sweep" is run without the $SAV_IDE and $LD_LIBRARY_PATH environment variables being set - "sophoswrapper" is now working OK. Can anyone suggest why the new "sweep" suddenly started behaving differently after the 04:00 IDE update? ------------------------------ cut here (/usr/local/Sophos/bin/sophoswrapper) PackageDir=/usr/local/Sophos prog=sweep # `basename $0` #TMP#SAV_IDE=$PackageDir/ide #TMP#LD_LIBRARY_PATH=$PackageDir/lib #TMP#export SAV_IDE #TMP#export LD_LIBRARY_PATH exec ${PackageDir}/bin/$prog "$@" ------------------------------ cut here Quentin --- PHONE: +44 191 222 8209 Computing Service, University of Newcastle FAX: +44 191 222 8765 Newcastle upon Tyne, United Kingdom, NE1 7RU. ------------------------------------------------------------------------ "Any opinion expressed above is mine. The University can get its own." From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:18:00 2006 Subject: No subject Message-ID: To.
 
Mohan
------=_NextPart_000_0005_01C31583.1F5D8EB0-- From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:18:59 2006 Subject: No subject Message-ID: match are the same. Rule format I can think of is FromTo: emailid or IP,emailid or IP. If second arguement exists, the AND operator applies, if not OR. Mohan -----Original Message----- From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK]On Behalf Of Rob V Sent: Wednesday, July 16, 2003 9:42 PM To: MAILSCANNER@JISCMAIL.AC.UK Subject: Re: forged From: Can I add that in my scan.rules ? like From: 192.168.198. no will that no scan all of 192.168.198 or do I have to add it differently ? At 03:08 PM 7/16/2003 +0100, you wrote: >Rob V wrote: > > Has Anyone got a way to block or detect a forged From: address. > > I am getting spam sent to us with forged From (they are putting that > > the mail is from someone at our domain) > > Since we do not scan our own domain these messages are getting in no > > problem. Any help or suggested would be appreciated. > >You should not whitelist your own domains by their domain name, instead >you should whitelist trusted internal servers by IP, or your IP address blocks. > > > >BMRB International >http://www.bmrb.co.uk >+44 (0)20 8566 5000 >_________________________________________________________________ >This message (and any attachment) is intended only for the >recipient and may contain confidential and/or privileged >material. If you have received this in error, please contact the >sender and delete this message immediately. Disclosure, copying >or other action taken in respect of this email or in >reliance on it is prohibited. BMRB International Limited >accepts no liability in relation to any personal emails, or >content of any email which does not directly relate to our >business. Rob Vicchiullo robv@disaster.com http://www.disaster.com (518) 218-0900 From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:19:00 2006 Subject: No subject Message-ID: "It's also worth noting that training with a very small quantity of ham, will produce atrocious results. You should aim to train with at least the same amount (or more if possible!) of ham data than spam" regards, Tony From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:19:05 2006 Subject: No subject Message-ID: been received. Can this be implemented in the Log.pm from MailScanner? Thanks! -- Jeffrey Koetsier Unix Administrator "I don't believe UNIX is Utopia. It's just the best set of tools around." -- Dick Haight, Unix Review, Jan. 1985, pg. 117 From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:20:34 2006 Subject: No subject Message-ID: To = someuser@domain1.tld To = someuser@domain2.tld It won't only match From=someuser@domain1.tld and To=someuser@domain2.tld which is what Ron originally wanted. Antony. -- Behind the counter a boy with a shaven head stared vacantly into space, a dozen spikes of microsoft protruding from the socket behind his ear. - William Gibson, Neuromancer (1984) From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:20:38 2006 Subject: No subject Message-ID: At 17:03 19/10/2003, you wrote: >Hi all, > >I've got MailScanner set up and working well except that one particular >email address added to the blacklist seems not to work at all, the email >address in question is: > >owner-nolist-x@WWW-TOPSITES.COM > >and a header sequence from an example email is as follows: > >Return-Path: >Received: from top-site.net ([202.9.152.26]) > by NS.MY-NETWORK.COM (8.12.8/8.12.8) with ESMTP id h9IKapUB011724 for >; Sat, 18 Oct 2003 15:36:53 -0500 >Message-Id: <200310182036.h9IKapUB011724@NS.MY-NETWORK.COM> >Received: from topsitesmail (localhost) by top-site.net (LSMTP for Windows >NT v1.1b) with SMTP id <0.0332881E@top-site.net>; Sat, 18 Oct 2003 >16:36:36 -0400 >Date: Sat, 18 Oct 2003 16:36:36 -0400 >From: John >Subject: RE: updated translations of studiofivearch.com into 8 languages >Reply-To: >To: >X-my-network-MailScanner-Information: Please contact your network admin >for more information >X-my-network-MailScanner: Found to be clean >X-my-network-MailScanner-SpamCheck: not spam, SpamAssassin (score=3.718, > required 5, BAYES_44 -0.00, HTML_MESSAGE 0.10, > MSGID_FROM_MTA_HEADER 0.70, RCVD_IN_BL_SPAMCOP_NET 1.50, > RCVD_IN_NJABL 0.10, RCVD_IN_NJABL_RELAY 0.00, RCVD_IN_RFCI 0.10, >RCVD_IN_SBL 1.11, RCVD_IN_SORBS 0.10) >X-my-network-MailScanner-SpamScore: sss > >Normally I'd expect to see some indication that the blacklist had caught >this beast. > >Can anyone shed some light on this issue for me, please? > >TIA > >Ned -- Julian Field www.MailScanner.info Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:21:29 2006 Subject: No subject Message-ID: According to David's correction, it should be written as "Es wurden zuviele Anhänge in der e-mail gefunden." For simplicity, #4 "Zuviele Anhänge in der Email". Regards, Steffan, wondering if he has spent too much time on IRC, resulting in a loss of basic German spelling abilities, LOL. From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:21:35 2006 Subject: No subject Message-ID: Mails are coming in but are not scanned by MailScanner and Spamassassin (2.55) Any help would be welcomed! /Jan Elmqvist Nielsen From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:21:35 2006 Subject: No subject Message-ID: Mails are coming in but are not scanned by MailScanner and Spamassassin (2.55) Any help would be welcomed! /Jan Elmqvist Nielsen From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:21:35 2006 Subject: No subject Message-ID: Mails are coming in but are not scanned by MailScanner and Spamassassin (2.55) Any help would be welcomed! /Jan Elmqvist Nielsen From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:21:55 2006 Subject: No subject Message-ID: to see more detailed documentation (yes, I've checked the mailing list archives, read the FAQs etc - I just like having stuff laid out in one place (read "am lazy")). (Julian - if you'd be interested in having a complete MS newbie draft a for-idiots-by-an-idiot guide I'd be happy to get involved). I still wouldn't be confident enough to setup MailScanner in a production environment myself (I've got FSL.com for that) but isn't that the point - I didn't just learn new stuff, I also got a better feel for what I don't know. I've spent enough time in the Windows world of "plug it in and turn it on straight out of the box without understanding how it works" to have developed a healthy fear of this approach. I won't bore anyone with the horror stories, I've a feeling I'd be preaching to the converted ;) Best Matthew Day University of Buckingham From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:21:59 2006 Subject: No subject Message-ID: also listed as a spammer. The problem is that the from address is different every month by the appendage of a character code. So one month it may be good_user_jan@bad.domain.com and then good_user_feb@bad.domain.com the next month. -=B From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:22:52 2006 Subject: No subject Message-ID: them into the "real" queue directory. So far everything works okay. I get all the messages scanned and put into the "real" queue directory, but from there no messages are delivered, locally or remotely. When sending a message from another host or locally i get something similar to the following in my maillog: Mar 1 21:02:39 u15151422 MailScanner[10150]: New Batch: Scanning 1 messages, 58 5 bytes Mar 1 21:02:39 u15151422 MailScanner[10150]: MCP Checks: Starting Mar 1 21:02:49 u15151422 MailScanner[10150]: Virus and Content Scanning: Starti ng Mar 1 21:02:50 u15151422 MailScanner[10150]: Uninfected: Delivered 1 messages There is no mentioning of qmail. I find this very strange... Before i would get a complete history. Checking the queue status i get: [me@bubu bin]# ./qmail-qstat messages in queue: 31 messages in queue but not yet preprocessed: 0 And qmail-qread returns nothing... [me@bubu bin]# ./qmail-qread [me@bubu bin]# Looking into the real queue directory all messages seem to be at S4, waiting for the qmail-send to kick in. http://www.cyberis.net/support/qmail/misc/INTERNALS.phtml There are no message hung in the "queue.in" directory. I've compared all permissions in my queue directory with a post that i found http://www.google.com/groups?safe=images&ie=UTF-8&oe=UTF-8&as_umsgid=wx0itrfgeif.fsf@sws5.ctd.ornl.gov&lr=&hl=en No discrepancies found. Processes all look fine. qmails 9355 0.0 0.0 1420 348 pts/1 S 18:48 0:00 qmail-send qmaill 9357 0.0 0.0 1380 408 pts/1 S 18:48 0:00 splogger qmail root 9358 0.0 0.0 1412 332 pts/1 S 18:48 0:00 qmail-lspawn ./Maildir/ qmailr 9359 0.0 0.0 1404 312 pts/1 S 18:48 0:00 qmail-rspawn qmailq 9360 0.0 0.0 1376 300 pts/1 S 18:48 0:00 qmail-clean qmailq 10146 0.0 2.3 13580 11828 ? S 20:01 0:00 /usr/bin/perl -I/usr/lib/MailScanner /usr/sbin/MailScanner /etc/MailScanner/MailScanner.conf qmailq 10150 0.0 5.1 28032 26212 ? S 20:01 0:02 /usr/bin/perl -I/usr/lib/MailScanner /usr/sbin/MailScanner /etc/MailScanner/MailScanner.conf qmailq 10245 0.0 5.1 27896 26072 ? S 20:01 0:02 /usr/bin/perl -I/usr/lib/MailScanner /usr/sbin/MailScanner /etc/MailScanner/MailScanner.conf qmailq 10253 0.0 5.1 27832 25984 ? S 20:01 0:01 /usr/bin/perl -I/usr/lib/MailScanner /usr/sbin/MailScanner /etc/MailScanner/MailScanner.conf qmailq 10254 0.0 5.1 27832 25984 ? S 20:01 0:01 /usr/bin/perl -I/usr/lib/MailScanner /usr/sbin/MailScanner /etc/MailScanner/MailScanner.conf qmailq 10255 0.0 5.1 27836 25988 ? S 20:01 0:02 /usr/bin/perl -I/usr/lib/MailScanner /usr/sbin/MailScanner /etc/MailScanner/MailScanner.conf i do not have the qmailctrl script installed on my box, but using splogger i supose everything is logged into maillog. Trying to force the immediate delivery or error message by sending an alarm signal to qmail-send does not produce any output in my maillog file. [me@bubu bin]# kill -s SIGALRM 9355 I wonder if using a supervised qmail is the only way to get more log information or if i'm missing something here. I guess it must be some permission problem, or a simple configuration issue. To give you the complete overview here as well my configuration: [me@bubu bin]# ./qmail-showctl qmail home directory: /var/qmail. user-ext delimiter: -. paternalism (in decimal): 2. silent concurrency limit: 1000. subdirectory split: 23. user ids: 2021, 2020, 2022, 0, 2023, 2520, 2521, 2522. group ids: 2020, 2520. badmailfrom: (Default.) Any MAIL FROM is allowed. bouncefrom: (Default.) Bounce user name is MAILER-DAEMON. bouncehost: (Default.) Bounce host name is bubu.com. concurrencylocal: (Default.) Local concurrency is 10. concurrencyremote: (Default.) Remote concurrency is 20. databytes: SMTP DATA limit is 0 bytes. defaultdomain: (Default.) Default domain name is bubu.com. defaulthost: (Default.) Default host name is bubu.com. doublebouncehost: (Default.) 2B recipient host: bubu.com. doublebounceto: (Default.) 2B recipient user: postmaster. envnoathost: (Default.) Presumed domain name is bubu.com. helohost: (Default.) SMTP client HELO host name is bubu.com. idhost: (Default.) Message-ID host name is bubu.com. localiphost: (Default.) Local IP address becomes bubu.com. locals: Messages for localhost are delivered locally. me: My name is bubu.com. percenthack: (Default.) The percent hack is not allowed. plusdomain: (Default.) Plus domain name is bubu.com. qmqpservers: (Default.) No QMQP servers. queuelifetime: (Default.) Message lifetime in the queue is 604800 seconds. rcpthosts: SMTP clients may send messages to recipients at resotech.org. SMTP clients may send messages to recipients at bubu.com. morercpthosts: (Default.) No effect. morercpthosts.cdb: (Default.) No effect. smtpgreeting: (Default.) SMTP greeting: 220 bubu.com. smtproutes: (Default.) No artificial SMTP routes. timeoutconnect: (Default.) SMTP client connection timeout is 60 seconds. timeoutremote: (Default.) SMTP client data timeout is 1200 seconds. timeoutsmtpd: (Default.) SMTP server data timeout is 1200 seconds. virtualdomains: Virtual domain: resotech.org:3 Virtual domain: bubu.com:2 servercert.pem: I have no idea what this file does. clientcert.pem: I have no idea what this file does. Thank you Stephan From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:23:17 2006 Subject: No subject Message-ID: Dustin From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:23:48 2006 Subject: No subject Message-ID: header RCVD_IN_SPAMHAUS_SBL+XBL eval:check_rbl_txt('sbl-xbl', 'sbl-xbl.spamhaus.org.') describe RCVD_IN_SPAMHAUS_SBL+XBL Listed in SPAMHAUS SBL+XBL tflags RCVD_IN_SPAMHAUS_SBL+XBL net score RCVD_IN_SPAMHAUS_SBL+XBL 4 to my '/etc/mail/spamassassin/local.cf' file, and restarted MailScanner. My MailScanner.conf contains the line: SpamAssassin Site Rules Dir = /etc/mail/spamassassin and it does seem to pickup the bigevil.cf rules file from there. SInce then, I got another spam (surprise surprise) which should have triggered this rule, but doesnt seem to have. X-mycompanyname-MailScanner-SpamCheck: spam, SBL+XBL, SpamAssassin (score=13, required 4.1, BAYES_90 3.00, BigEvilList_29 3.00, BigEvilList_41 3.00, CLICK_BELOW 0.00, HTML_70_80 0.33, HTML_IMAGE_ONLY_04 1.41, HTML_LINK_CLICK_HERE 0.10, HTML_WEB_BUGS 0.10, MAILTO_TO_REMOVE 0.27, MAILTO_WITH_SUBJ 0.57, MAILTO_WITH_SUBJ_REMOVE 0.50, MIME_HTML_ONLY 0.10, SUBJ_REMOVE 0.62) I thought I should see the extra score of 4. What am I missing ? Thanks, Declan From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:23:53 2006 Subject: No subject Message-ID: y sammy.tnjinfl.com (8.12.8/8.12.8) with ESMTP id i2ODTBxR008385 for ; Wed, 24 Mar 2004 08:29:11 -0500=20 Subject: {Spam?} test @ 8:29=20 To: jpifer@obrien-pifer.com=20 X-Mailer: Lotus Notes Release 6.5.1 January 21, 2004=20 Message-ID: =20 From: jamespifer@packagingcorp.com=20 Date: Wed, 24 Mar 2004 08:28:06 -0500=20 X-MIMETrack: Serialize by Router on PCALAKLH01/PackagingCorp(Release 6.5.= 1|January 21, 2004) at 03/24/2004 07:15:14 AM=20 MIME-Version: 1.0=20 X-MailScanner-Information: Please contact the ISP for more information=20 X-MailScanner: Found to be clean=20 X-MailScanner-SpamCheck: spam, Infinite-Monkeys, SpamAssassin (score=3D-1= .364, required 4, BAYES_01 -1.52, NO_REAL_NAME 0.16)=20 James --bound1080138846-- From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:23:56 2006 Subject: No subject Message-ID: You'd need to give us more info if you want us to help you. Please avoid HTML in posts, use plain-text. Ugo From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:23:57 2006 Subject: No subject Message-ID: You'd need to give us more info if you want us to help you. Please avoid HTML in posts, use plain-text. Ugo From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:25:01 2006 Subject: No subject Message-ID: am I better off using an IP based rule? the problem with an IP based rule, is that it wouldn't apply to users on the road, logging in from the outside... thanks for any guidance.... -------------------------- MailScanner list ---------------------- To leave, send leave mailscanner to jiscmail@jiscmail.ac.uk Before posting, please see the Most Asked Questions at http://www.mailscanner.biz/maq/ and the archives at http://www.jiscmail.ac.uk/lists/mailscanner.html From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:25:04 2006 Subject: No subject Message-ID: HTML sanitiziing. -------------------------- MailScanner list ---------------------- To leave, send leave mailscanner to jiscmail@jiscmail.ac.uk Before posting, please see the Most Asked Questions at http://www.mailscanner.biz/maq/ and the archives at http://www.jiscmail.ac.uk/lists/mailscanner.html From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:25:45 2006 Subject: No subject Message-ID: now i just need to get bayes, pyzor/razor setup and i should be catching almost all spam. chris. -------------------------- MailScanner list ---------------------- To leave, send leave mailscanner to jiscmail@jiscmail.ac.uk Before posting, please see the Most Asked Questions at http://www.mailscanner.biz/maq/ and the archives at http://www.jiscmail.ac.uk/lists/mailscanner.html From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:26:26 2006 Subject: No subject Message-ID: configured and working with MailScanner for normal message checksumming. My question is this: Is it possible to do greylisting this way with MailScanner? If not, are there any particular methods for me to try implementing it that anybody has found works well with such a setup? Thanks! matt henkler -------------------------- MailScanner list ---------------------- To leave, send leave mailscanner to jiscmail@jiscmail.ac.uk Before posting, please see the Most Asked Questions at http://www.mailscanner.biz/maq/ and the archives at http://www.jiscmail.ac.uk/lists/mailscanner.html From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:26:32 2006 Subject: No subject Message-ID: (that's a random example - not tested) There are clear examples in the files. Mr Michele Neylon Blacknight Internet Solutions Ltd http://www.blacknight.ie/ Tel. +353 59 9137101 -------------------------- MailScanner list ---------------------- To leave, send leave mailscanner to jiscmail@jiscmail.ac.uk Before posting, please see the Most Asked Questions at http://www.mailscanner.biz/maq/ and the archives at http://www.jiscmail.ac.uk/lists/mailscanner.html From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:26:32 2006 Subject: No subject Message-ID: (that's a random example - not tested) There are clear examples in the files. Mr Michele Neylon Blacknight Internet Solutions Ltd http://www.blacknight.ie/ Tel. +353 59 9137101 -------------------------- MailScanner list ---------------------- To leave, send leave mailscanner to jiscmail@jiscmail.ac.uk Before posting, please see the Most Asked Questions at http://www.mailscanner.biz/maq/ and the archives at http://www.jiscmail.ac.uk/lists/mailscanner.html ------------------------------------------------------ ¥»¶l¥ó¤w¸g¹L080.net ¸s·ù¬ì§Þ¯f¬r±½ºË Viruses Scanned by 080.net ------------------------------------------------------ ¥»¶l¥ó¤w¸g¹L080.net ¸s·ù¬ì§Þ¯f¬r±½ºË Viruses Scanned by 080.net -------------------------- MailScanner list ---------------------- To leave, send leave mailscanner to jiscmail@jiscmail.ac.uk Before posting, please see the Most Asked Questions at http://www.mailscanner.biz/maq/ and the archives at http://www.jiscmail.ac.uk/lists/mailscanner.html From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:27:21 2006 Subject: No subject Message-ID: IO-stringy
MIME-Base64
MailTools
File-Spec
HTML-Tagset
HTML-Parser
MIME-tools
patches 1 - 4
File-Temp
TNEF-Convert

ln -s gcc /usr/local/bin/cc

 
 
 
 
 
 
------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words:
'leave mailscanner' in the body of the email.
Before posting, read the MAQ (http://www.mailscanner.biz/maq/)
and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html).


--
Julian Field
www.MailScanner.info
Buy the MailScanner book at www.MailScanner.info/store

PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654
------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words:
'leave mailscanner' in the body of the email.
Before posting, read the MAQ (http://www.mailscanner.biz/maq/)
and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:27:25 2006 Subject: No subject Message-ID: How hard would it be to perhaps have dspam support in MailScanner? As it calls an external program I don't think it would be too difficult. -- Regards, David Jacobson Technical Director SYNAQ (Pty) Ltd Tel: 011 290 6388 Cell: 083 235 0760 Mail: davidj@synaq.com WWW: http://www.synaq.com Key Fingerprint 8246 FCE1 3C22 7EFB E61B 18DF 6E8B 65E8 BD50 78A1 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). [ Part 2, "This is a digitally signed message part" ] [ Application/PGP-SIGNATURE 196bytes. ] [ Unable to print this part. ] From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:27:41 2006 Subject: No subject Message-ID: the server hosting the xyz.com domain. However, I still get mail routing loop errors. Thanks for your assistance __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:27:44 2006 Subject: No subject Message-ID: Nov 29 11:41:51 smithers MailScanner[2682]: MailScanner E-Mail Virus Scanner version 4.35.11 starting... Nov 29 11:41:51 smithers MailScanner[2682]: lock.pl sees Config LockType = flock Nov 29 11:41:51 smithers MailScanner[2682]: lock.pl sees have_module = 0 Matthew K Bowman Systems Administrator UDCom Tel: 419-524-4330 Fax: 419-524-8757 Web: http://www.udcom.com Email: mbowman@udcom.com Support: techsupport@udcom.com Sales: sales@udcom.com Marco Benton Sent by: MailScanner mailing list 11/26/2004 11:50 AM Please respond to MailScanner mailing list To: MAILSCANNER@JISCMAIL.AC.UK cc: Subject: Re: Help! - MailScanner ceased working (debug output) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Matthew Bowman wrote: | Nothing hits the outbound queue (/var/spool/mqueue). All inbound | email stays put in /var/spool/mqueue.in how about trying to turn off most things in MailScanner.conf like SA and virus checks. then run debug. there seems to be something missing at the end of the debug... like untieing bayes and other stuff. - -- Marco Benton - BOFH, BSMFH Network Consultant BOFH excuse #366: The cause of the problem is: Webmasters kidnapped by evil cult. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFBp1602+PYgoYkw8ERAuoeAJ0fEKXm7t8g+95+Wc/rkLwT7MdJNQCeOASU EYvc78f7CM4+FGV9xxih50E= =2mRo -----END PGP SIGNATURE----- ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:27:55 2006 Subject: No subject Message-ID: either the three characters at the begining or the sequence at the end of each line get ... munged somehow. Could you check with "od -c" which it is? Also, how is the files encoded/sent normally? Not that I'm implying I'll be able to help, but perhaps a better fault- description will make a "bell ring" for someone who can. -- Glenn > -----Original Message----- > From: MailScanner mailing list > [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Zhang(MIS) > Sent: den 10 december 2004 09:31 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: Some Attachments corrupt when enable Dangerous > Content Scanning > > > Hi All, > > I got complaint from our HR staff that their attachments in email was > corrupt. > (the example is simple txt file : > http://210.177.17.196/mis/temp/04120915.53r which is > download from our > absent time recorder ) > > when use diff to compare the orignal file and the emailed one : > > # diff 04120915.53r after/04120915.53r > 1,5c1,5 > < 1000002371015501209D0A > < 1000002371015501209D1A > ... > --- > > 1000002371015501209D0A > > 1000002371015501209D1A > ... > > after many testing I noted the way to avoid this problem is > 1.disable Content Scanning (Dangerous Content Scanning = no) > 2. use text format to send the email > 3. change the file name with xxxx.txt > > * we are using 4.36.4 MS > > Our staff said no problem before alst week (we upgraded to > 4.36.4 last > week), any idea for this? > > Regards > Z. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:27:59 2006 Subject: No subject Message-ID: spam.assassin.prefs.conf file for SA 3.0.x from www.fsl.com/support and install in lieu of the standard file. Be sure and change YOURDOMAIN.COM in our sample file to the value of %org-name% in /etc/MailScanner.conf Hope this helps, Steve Steve Swaney President Fortress Systems Ltd. www.fsl.com steve.swaney@fsl.com -- This message has been scanned for viruses and dangerous content by The MailScanner at Fortress Systems Ltd., www.fsl.com, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:28:13 2006 Subject: No subject Message-ID: Sylvain =========================================================== Sylvain Phaneuf --- Systems Manager | phone : +44 (0)1865 221323 Clinical School Information Management Services Unit (IMSU) Medical Sciences Division University of Oxford | email : sylvain.phaneuf@imsu.ox.ac.uk Room 3A25B John Radcliffe Hospital | fax : +44 (0) 1865 221322 Oxford OX3 9DU England =========================================================== >>> martinh@SOLID-STATE-LOGIC.COM 17/01/2005 09:10:43 >>> Julian from the UK user....happy nth birthday James - hope you don't have to support the hardware! (I did have user in Japan, now localsupport thank goodness, but I still got users in LA that require a 10 hour flight..) -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 James Gray wrote: > On Mon, 17 Jan 2005 06:59 am, Drew Marshall wrote: > >>Just a quick note to wish you a Happy Birthday!! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:28:13 2006 Subject: No subject Message-ID: license expired July of 2004 and as far as I can tell, I can not renew my license. :( I liked Rav a lot. But I see that MailScanner still supports Rav. So my question: Is MailScanner supporting Rav long enough so nobody is left out in the cold? or am I missing something? It would be nice to be able to use it still! :) - Regards Joseph Watson ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:28:23 2006 Subject: No subject Message-ID: relay. I havce searched and searched on this error and tried to see what the problem is on the exchange server. I cannot find what the problem is. Any help on getting these errors taken care of is greatly appreciated. Billy Pumphrey IT Manager Wooden & McLaughlin ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:28:25 2006 Subject: No subject Message-ID: subdomain to in the FQDN for a mail server such as someone@mailscanner.woodmaclaw.com? > > Beyond that, I can't think of what else might be goofy. Hope > this helps... Either way, I am learning as I go along and I do appreciate your time and feedback. > > ...Kevin > -- > Kevin Miller Registered Linux User No: 307357 > CBJ MIS Dept. Network Systems Admin., Mail Admin. > 155 South Seward Street ph: (907) 586-0242 > Juneau, Alaska 99801 fax: (907 586-4500 > > ------------------------ MailScanner list > ------------------------ To unsubscribe, email > jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the MAQ > (http://www.mailscanner.biz/maq/) and the archives > (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:28:25 2006 Subject: No subject Message-ID: - Changed Postfix handling so that "Archive Mail" feature creates files with unique names so that re-used message-ids don't cause overwriting of older files in the same day with the same message-id. Brad >>> John Crossan 2/3/2005 3:42:25 PM >>> I have MailScanner and Mailwatch for MailScanner running. We are running MailScanner, SpamAssassin, postfix, ClamAV, and Mailwatch. I could not use mailwatch to release a message from quarantine today (February 3) because it had the same ID as a message received in December. I had to release it manually. Is there a fix for this? Thanks John Crossan Systems Administrator Valley Presbyterian Hospital Message ID: C3F6017C3BC Message Headers: Received: from adsl-63-196-151-90.dsl.lsan03.pacbell.net (firewall.valleypres.org [192.6.1.253]) by clamav.valleypres.org (Postfix) with ESMTP id C3F6017C3BC for ; Mon, 20 Dec 2004 10:42:01 -0800 (PST) Received: from smtp.jiscmail.ac.uk ([130.246.192.55]) by adsl-63-196-151-90.dsl.lsan03.pacbell.net with esmtp (Exim 3.13 #5) id 1CgSTp-0007Nu-00 for john.crossan@VALLEYPRES.ORG; Mon, 20 Dec 2004 10:42:01 -0800 Received: from LISTSERV.JISCMAIL.AC.UK (jiscmail.ac.uk) by smtp.jiscmail.ac.uk (LSMTP for Windows NT v1.1b) with SMTP id <7.0019BDC2@smtp.jiscmail.ac.uk>; Mon, 20 Dec 2004 18:40:59 +0000 Received: from JISCMAIL.AC.UK by JISCMAIL.AC.UK (LISTSERV-TCP/IP release 1.8e) Message ID:C3F6017C3BC Message Headers: Received: from mail.valleypres.org (firewall.valleypres.org [192.6.1.253]) by clamav.valleypres.org (Postfix) with ESMTP id C3F6017C3BC for ; Thu, 3 Feb 2005 12:10:57 -0800 (PST) Received: from 64-171-32-163.ded.pacbell.net ([64.171.32.163] helo=nts-1.triageconsulting.com) by mail.valleypres.org with esmtp (Exim 3.13 #5) id 1CwnJZ-0000jV-00 for tracey.talley@valleypres.org; Thu, 03 Feb 2005 12:10:57 -0800 X-MimeOLE: Produced By Microsoft Exchange V6.5.7226.0 Content-class: urn:content-classes:message MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----_=_NextPart_001_01C50A2C.789D9C4A" ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:28:36 2006 Subject: No subject Message-ID: and if I could remember where the pieces came from, I'd give full credit. Sorry :(. This should work on any domain. Let me know if there are bugs/etc. I'm still ironing out my cron job, but this was a rather exciting fix for me, that I couldn't wait to share. ---------------------------------- default.asp ---------------------------------- <% Dim rootDSE, domainObject Set rootDSE=GetObject("LDAP://RootDSE") domainContainer = rootDSE.Get("defaultNamingContext") Set domainObject = GetObject("LDAP://" & domainContainer) Set fs = CreateObject ("Scripting.FileSystemObject") ExportUsers(domainObject) Set oDomain = Nothing Sub ExportUsers(oObject) Dim oUser For Each oUser in oObject Select Case oUser.Class Case "user" If oUser.mail <> "" then for each email in oUser.proxyAddresses print_email(email) next End if Case "group" If oUser.mailNickname <> "" then for each email in oUser.proxyAddresses print_email(email) next End if Case "organizationalUnit" , "container" If UsersGroupsinOU (oUser) then ExportUsers(oUser) End if End select Next End Sub Function print_email(email) if Instr(email, "SMTP:") <> 0 or Instr(email, "smtp:") <> 0 then dim n, e ' locate the ":" n = InStr(1, email, ":", 1) ' and chop it off e = Right(email, Len(email) - n) ' write the email address, two tabs, and a LF response.write(e & Chr(9) & Chr(9) & "ACCEPT" & Chr(10)) end if end function Function UsersGroupsinOU (oObject) Dim oUser UsersGroupsinOU = False for Each oUser in oObject Select Case oUser.Class Case "organizationalUnit" , "container" UsersGroupsinOU = UsersGroupsinOU(oUser) Case "user" UsersGroupsinOU = True Case "group" UsersGroupsinOU = True End select Next End Function %> ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:28:39 2006 Subject: No subject Message-ID: score=4.889, required 4.37, DNS_FROM_RFC_ABUSE 0.37, DNS_FROM_RFC_POST 1.38, MISSING_SUBJECT 1.57, NO_REAL_NAME 0.18, UNDISC_RECIPS 1.39) From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:28:39 2006 Subject: No subject Message-ID: score=3.229, required 4.37, AWL 1.66, NO_REAL_NAME 0.18, UNDISC_RECIPS 1.39) From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:28:39 2006 Subject: No subject Message-ID: SpamAssassin (score=1.569, required 4.37, NO_REAL_NAME 0.18, UNDISC_RECIPS 1.39) This email may contain information protected under the Family Educational Rights and Privacy Act (FERPA) or the Health Insurance Portability and Accountability Act (HIPAA). If this email contains confidential and/or privileged health or student information and you are not entitled to access such information under FERPA or HIPAA, federal regulations require that you destroy this email without reviewing it and you may not forward it to anyone. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:28:43 2006 Subject: No subject Message-ID: ... while(($postie,$notice) = each %notices) { $email = $headers{$postie} . "\n" . #MailScanner::Config::LanguageValue($message, 'noticeheading') . ":\n" . #$notices{$postie} . "\n" . $signatures{$postie} . "\n"; MailScanner::Config::LanguageValue($message, 'noticeprefix') . ": " . $reasons . "\n" . $notices{$postie} . "\n" . $signatures{$postie} . "\n"; $global::MS->{mta}->SendMessageString(undef, $email, $postie) or MailScanner::Log::WarnLog("Could not notify postmaster from $postie, %s", $!); } MailScanner::Log::InfoLog("Notices: Warned about %d messages", $counter) if $counter; } Quentin -- PHONE: +44 191 222 8209 Information Systems and Services (ISS), University of Newcastle, Newcastle upon Tyne, FAX: +44 191 222 8765 United Kingdom, NE1 7RU. ------------------------------------------------------------------------ "Any opinion expressed above is mine. The University can get its own." >-----Original Message----- >From: MailScanner mailing list >[mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Julian Field >Sent: 23 February 2005 16:35 >To: MAILSCANNER@JISCMAIL.AC.UK >Subject: Re: 4.39.3-1 bug or is it me? > >In other words neither of us have the faintest clue as to what could be >going wrong here. >:-( > >Quentin Campbell wrote: > >>>-----Original Message----- >>>From: MailScanner mailing list >>>[mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Julian Field >>>Sent: 23 February 2005 14:21 >>>To: MAILSCANNER@JISCMAIL.AC.UK >>>Subject: Re: 4.39.3-1 bug or is it me? >>> >>>Can you compare the configs. It is apparently failing to get >>>the message filenames altogether. No-one else has seen this >problem :-( >>> >>> >>> >> >>Julian >> >>I have carefully checked lists of files from ~reports/en and ~/rules >>against the pre-4.39.3-1 lists of files from those same >sub-directories. >>They are all accounted for and have the same names - this was checked >>with "diff" run against sorted lists of files. >> >>I have also used "diff" to compare the 4.39.3-1 MailScanner.conf file >>against the previous version (4.38.9-1). They are the same except for >>the additional lines you have added since 4.38.9-1 and the different >>Version Number. >> >>Quentin >> >>------------------------ MailScanner list ------------------------ >>To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >>'leave mailscanner' in the body of the email. >>Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and >>the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >> >>Support MailScanner development - buy the book off the website! >> >> >> > >-- >Julian Field >www.MailScanner.info >Buy the MailScanner book at www.MailScanner.info/store > >PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > >------------------------ MailScanner list ------------------------ >To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >'leave mailscanner' in the body of the email. >Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and >the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > >Support MailScanner development - buy the book off the website! > > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:28:47 2006 Subject: No subject Message-ID: "To ensure we can give all customers who purchase support a very high quality of service, we are restricting the number of support packages that we sell." I am just not so lucky, that I can persuade my boss before Monday :( so what to do, if I am not fast enough!... - Is it possible to get updates to the SMGateway products without a service contract? - Do you plan any special educational / non-profit prices? Regards, Henrik Bro -----Oprindelig meddelelse----- Fra: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] På vegne af Stephen Swaney Sendt: 2. marts 2005 17:46 Til: MAILSCANNER@JISCMAIL.AC.UK Emne: Re: MailScanner ANNOUNCE: New commercial product SMGateway > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Michael Baird > Sent: Wednesday, March 02, 2005 11:19 AM > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: MailScanner ANNOUNCE: New commercial product SMGateway > > Is the package pricing below per machine? I think I'd like to switch > to it, but I would only want the minimal support package, but I have > multiple mailscanner boxes (on each incoming MX, and my outbound > relays, with redundant boxes standing by for each). Even the base > package would probably get costly for me. > > Regards > Michael Baird > The SMGateway products if the first of a few products we plan to produce. It's not suitable for all sites. Its primary intended use is for a site that runs 0 or 1 gateways fronting a mailhub. For example it is an excellent product to front an existing Microsoft Exchange 2003 or Domino Server. It can typically reduce the load and storage requirements on the backend mailhub by 50% simply by rejecting or trapping the really obvious junk. Add to that the ability to run multiple virus scanners and you really have a Secure Email Gateway - thanks to MailScanner. The fact that you can load the minimal OS required, load SMGateway and easily restore a backup configuration in less than an hour makes for a reasonable recovery scenario for a single gateway site. Our SMCluster products will introduce an architecture that will control multiple gateways. We expect it to be available later this year. It will be very reasonably priced by server not by mailbox. I hope this helps, Steve Steve Swaney President Fortress Systems Ltd. Phone: 202 338-1670 Cell: 202 352-3262 www.fsl.com steve.swaney@fsl.com ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:28:51 2006 Subject: No subject Message-ID: module's test suite is important. I've just installed 0.16 and that, too, seems fine. I've also written to the author again suggesting that he might simply remove his "scanbuff" tests. -- : David Lee I.T. Service : : Senior Systems Programmer Computer Centre : : University of Durham : : http://www.dur.ac.uk/t.d.lee/ South Road : : Durham : : Phone: +44 191 334 2752 U.K. : ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:28:53 2006 Subject: No subject Message-ID: ########################################################################### # # Handy little feature to let you use the same MailScanner.conf file on # lots of different hosts, where the only difference is the hostname. # Just uncomment the "use Sys::Hostname" line and then set # Hostname = &Hostname # in your MailScanner.conf to use this. # # Many thanks to Tony Finch for this. # ########################################################################### Works in reports as well. -----Original Message----- From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK]On Behalf Of Jason Huddleston Sent: Monday, March 07, 2005 2:43 PM To: MAILSCANNER@JISCMAIL.AC.UK Subject: Hostname I am trying to change the Hostname variable to include the server name with out hard coding the name in the string. I have tried "Hostname = the %org-name% (%HOSTNAME%) MailScanner" and "Hostname = the %org-name% ($HOSTNAME) MailScanner" with no luck. Is their a variable that I am overlooking that will pick up the server name???? This email and any files transmitted with it are confidential and proprietary to Algorithmics Incorporated and its affiliates ("Algorithmics"). If received in error, use is prohibited. Please destroy, and notify sender. Sender does not waive confidentiality or privilege. Internet communications cannot be guaranteed to be timely, secure, error or virus-free. Algorithmics does not accept liability for any errors or omissions. Any commitment intended to bind Algorithmics must be reduced to writing and signed by an authorized signatory. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:29:06 2006 Subject: No subject Message-ID: - Multiple "Subject:" lines are removed. The 1st one is kept. Stef > -----Original Message----- > From: MailScanner mailing list > [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Duncan, Brian M. > Sent: 17 March 2005 15:06 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Spam that puts extra Subject lines in to avoid being > quarantined/caught. > > Trying another time to mail the list about this type of > Spamming. We are starting to get allot more of these and I > could not find anything in the archives dealing with this. (I > looked again) > > Far down below is the original message I sent the list. > > Basically what I am seeing is Spammers that put two subject > lines into the message. Mailscanner only tags one of them. > (99% of these have been ones that fail RBL check) We have > rules setup in exchange that, then say if message subject has > xxx in it, stick it in their Suspect folder. > (Exchange is only paying attention to the LAST subject line in the > headers) > > Anyway to get sendmail/Mailscanner to either cut out multiple > subject lines, or to mark ALL of the subject lines in the headers? > > This is with mailscanner-4.35.11-1 > > Another example: > > Received: from everest by nuuk.nshoster.com with local (Exim 4.44)id > > 1DBgQp-0003Ae-0D; Wed, 16 Mar 2005 16:51:59 -0500 > To: info@udnepal.com, > richard@rotary1900.org > From: fatima@beaconsfield.libdems.org.uk, > bobby@studentnet.lv > Cc: fatima@beaconsfield.libdems.org.uk > REPLY-TO: info@udnepal.com > Subject: {FAILED SC} Online Reservation Inquiry submitted by > > Content-Type: multipart/mixed; > boundary=feawnqj > Subject: Pharm discount > Message-Id: > Date: Wed, 16 Mar 2005 16:51:59 -0500 > X-AntiAbuse: This header was added to track abuse, please > include it with > > any abuse report > X-AntiAbuse: Primary Hostname - nuuk.nshoster.com > X-AntiAbuse: Original Domain - kmzr.com > X-AntiAbuse: Originator/Caller UID/GID - [32079 32079] / [47 12] > X-AntiAbuse: Sender Address Domain - nuuk.nshoster.com > X-Source: > > X-Source-Args: > > X-Source-Dir: > > X-KMZR-MailScanner-Information: > > X-MailScanner-SpamCheck: spam, SpamAssassin (score=9.369, required > > 7,BAYES_80 2.09, DISGUISE_VIAGRA 1.00, DRUGS_ANXIETY > > 0.10,DRUGS_ANXIETY_EREC 0.04, DRUGS_ERECTILE > 0.22,HEADER_COUNT_CTYPE 1.77, > > HTML_20_30 0.23, HTML_MESSAGE 0.00,HTML_MIME_NO_HTML_TAG 0.14, > > MIME_BASE64_TEXT 0.30,MIME_HEADER_CTYPE_ONLY 0.11, MIME_HTML_ONLY > > 0.18,URIBL_OB_SURBL 3.21) > X-MailScanner-SpamScore: sssssssss > X-MailScanner-From: everest@nuuk.nshoster.com > Return-Path: everest@nuuk.nshoster.com > X-OriginalArrivalTime: 16 Mar 2005 21:57:53.0994 (UTC) > FILETIME=[3479F2A0:01C52A73] > > -----Original Message----- > From: Duncan, Brian M. > > Sent: Friday, January 28, 2005 10:45 AM > To: 'MAILSCANNER@JISCMAIL.AC.UK' > Subject: Removing MULTIPLE subject lines in a message. > > > Forgive me if this has been covered in the mailing list. I > searched the archives without any results.. > > We are starting to receive messages now with multiple subject lines. > (Ones with 2 subject lines total) > > In our environment we just modify the subject line on ANY > message that is determined to be Spam. (Black listed, or > scores higher then 7) > > We then rely on Exchange to move any messages with our > modification into a local folder for the end users that is > for Spam. (So they can look > over) > > The problem we are seeing now is that Outlook/Exchange only > seems to pay attention to the LAST subject line in a message. > When one of these messages with 2 subject lines comes > through, it gets caught. The 1st subject line is re-written, > then it's forwarded to our Exchange server. > The exchange server/outlook client only lists the LAST > subject line from the message. So it winds up in their > INBOX. If you look through the headers you can see.. > > I was wondering if there is an easy way to handle this on the > Sendmail/MailScanner side.. > > Thanks! > > I will include headers of a message we have this problem with: > > > Received: from RJX ([218.107.2.59])by venus.KMZR.COM > (8.11.6/8.11.2) with > > SMTP id j0SDSbL06054;Fri, 28 Jan 2005 07:28:38 -0600 > Message-Id: <200501281328.j0SDSbL06054@venus.KMZR.COM> > Received: from abac.com ([28.90.248.212]) by > crisscross.iupi.pt > > (InterMail vK.4.04.00.00 813-535-420 license > > 5uz341wo5802c0kq1v5mts5394z8rdj1) with ESMTP id > > <75579863733746.EUMI071.cosy@abac.com> for ; > Fri, > > 28 Jan 2005 11:21:00 -0200 > Received: from mail pickup service by hotmail.com with > Microsoft SMTPSVC; > > Fri, 28 Jan 2005 19:25:00 +0600 > Received: from 24.240.198.188 by ami.demagogue.hotmail.msn.com with > > HTTP;Fri, 28 Jan 2005 14:27:00 +0100 GMT > X-Originating-IP: [18.219.66.153] > X-Originating-Email: [combat@abac.com] > From: "Augusta Wood" , "Augusta > Wood" > To: mccord@kmzr.com, > "Mccord" > Subject: {FAILED SC} Spyware Aiert - January 25th > Date: Fri, 28 Jan 2005 14:26:00 +0100 > Mime-Version: 1.0 > Received: from abac.com ([100.144.236.240]) by > crisscross.iupi.pt > > (InterMail vK.4.04.00.00 218-712-387 license > > 5uz341wo5802c0kq1v5mts5394z8rdj1) with ESMTP id > > <67078592714268.CCLC9817.crisscross.iupi.pt> for > ; > Fri, 28 Jan 2005 17:26:00 +0400 > Subject: Spyware Aiert - January 25th > Sender: "Augusta Wood" > X-KMZR-MailScanner-Information: > > X-MailScanner-SpamCheck: spam, SpamAssassin (score=22.075, required > > 7,autolearn=spam, BAYES_80 2.09, INVALID_TZ_GMT 0.20, LONGWORD > > 0.30,LONGWORDS 2.26, MR_NOT_ATTRIBUTED_IP 0.20, MR_STRANGE_QUESTION > > 1.50,MSGID_FROM_MTA_HEADER 0.05, MSGID_FROM_MTA_ID 1.72, NO_RDNS2 > > 0.01,RCVD_IN_DSBL 3.81, RCVD_IN_SORBS 1.00, URIBL_OB_SURBL > > 3.21,URIBL_SC_SURBL 4.26, URIBL_WS_SURBL 1.46) > X-MailScanner-SpamScore: ssssssssssssssssssssss > X-MailScanner-From: reevesxfkyy@topteam.bg > Return-Path: Reevesxfkyy@topteam.bg > X-OriginalArrivalTime: 28 Jan 2005 13:30:17.0277 (UTC) > FILETIME=[81717ED0:01C5053D] > > > > Brian M. Duncan > > Katten Muchin Zavis Rosenman > 525 West Monroe Street > Chicago IL 60661-3693 > 312-577-8045 > > brian.duncan@kmzr.com > > =========================================================== > > Important: > This electronic mail message and any attached files contain > information intended for the exclusive use of the individual > or entity to whom it is addressed and may contain information > that is proprietary, privileged, confidential and/or exempt > from disclosure under applicable law. If you are not the > intended recipient, you are hereby notified that any viewing, > copying, disclosure or distribution of this information may > be subject to legal restriction or sanction. Please notify > the sender, by electronic mail or telephone, of any > unintended recipients and delete the original message without > making any copies. > > =========================================================== > > ------------------------ MailScanner list > ------------------------ To unsubscribe, email > jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the MAQ > (http://www.mailscanner.biz/maq/) and the archives > (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > -- > This email has been scanned by the Level 5 Internet > MailCrusader for viruses, spam and dangerous content. > For more information please visit http://www.l5net.net > > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:29:07 2006 Subject: No subject Message-ID: - Multiple "Subject:" lines are removed. The 1st one is kept. Stef > -----Original Message----- > From: MailScanner mailing list > [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Duncan, Brian M. > Sent: 17 March 2005 15:06 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Spam that puts extra Subject lines in to avoid being > quarantined/caught. > > Trying another time to mail the list about this type of > Spamming. We are starting to get allot more of these and I > could not find anything in the archives dealing with this. (I > looked again) > > Far down below is the original message I sent the list. > > Basically what I am seeing is Spammers that put two subject > lines into the message. Mailscanner only tags one of them. > (99% of these have been ones that fail RBL check) We have > rules setup in exchange that, then say if message subject has > xxx in it, stick it in their Suspect folder. > (Exchange is only paying attention to the LAST subject line in the > headers) > > Anyway to get sendmail/Mailscanner to either cut out multiple > subject lines, or to mark ALL of the subject lines in the headers? > > This is with mailscanner-4.35.11-1 > > Another example: > > Received: from everest by nuuk.nshoster.com with local (Exim 4.44)id > > 1DBgQp-0003Ae-0D; Wed, 16 Mar 2005 16:51:59 -0500 > To: info@udnepal.com, > richard@rotary1900.org > From: fatima@beaconsfield.libdems.org.uk, > bobby@studentnet.lv > Cc: fatima@beaconsfield.libdems.org.uk > REPLY-TO: info@udnepal.com > Subject: {FAILED SC} Online Reservation Inquiry submitted by > > Content-Type: multipart/mixed; > boundary=feawnqj > Subject: Pharm discount > Message-Id: > Date: Wed, 16 Mar 2005 16:51:59 -0500 > X-AntiAbuse: This header was added to track abuse, please > include it with > > any abuse report > X-AntiAbuse: Primary Hostname - nuuk.nshoster.com > X-AntiAbuse: Original Domain - kmzr.com > X-AntiAbuse: Originator/Caller UID/GID - [32079 32079] / [47 12] > X-AntiAbuse: Sender Address Domain - nuuk.nshoster.com > X-Source: > > X-Source-Args: > > X-Source-Dir: > > X-KMZR-MailScanner-Information: > > X-MailScanner-SpamCheck: spam, SpamAssassin (score=9.369, required > > 7,BAYES_80 2.09, DISGUISE_VIAGRA 1.00, DRUGS_ANXIETY > > 0.10,DRUGS_ANXIETY_EREC 0.04, DRUGS_ERECTILE > 0.22,HEADER_COUNT_CTYPE 1.77, > > HTML_20_30 0.23, HTML_MESSAGE 0.00,HTML_MIME_NO_HTML_TAG 0.14, > > MIME_BASE64_TEXT 0.30,MIME_HEADER_CTYPE_ONLY 0.11, MIME_HTML_ONLY > > 0.18,URIBL_OB_SURBL 3.21) > X-MailScanner-SpamScore: sssssssss > X-MailScanner-From: everest@nuuk.nshoster.com > Return-Path: everest@nuuk.nshoster.com > X-OriginalArrivalTime: 16 Mar 2005 21:57:53.0994 (UTC) > FILETIME=[3479F2A0:01C52A73] > > -----Original Message----- > From: Duncan, Brian M. > > Sent: Friday, January 28, 2005 10:45 AM > To: 'MAILSCANNER@JISCMAIL.AC.UK' > Subject: Removing MULTIPLE subject lines in a message. > > > Forgive me if this has been covered in the mailing list. I > searched the archives without any results.. > > We are starting to receive messages now with multiple subject lines. > (Ones with 2 subject lines total) > > In our environment we just modify the subject line on ANY > message that is determined to be Spam. (Black listed, or > scores higher then 7) > > We then rely on Exchange to move any messages with our > modification into a local folder for the end users that is > for Spam. (So they can look > over) > > The problem we are seeing now is that Outlook/Exchange only > seems to pay attention to the LAST subject line in a message. > When one of these messages with 2 subject lines comes > through, it gets caught. The 1st subject line is re-written, > then it's forwarded to our Exchange server. > The exchange server/outlook client only lists the LAST > subject line from the message. So it winds up in their > INBOX. If you look through the headers you can see.. > > I was wondering if there is an easy way to handle this on the > Sendmail/MailScanner side.. > > Thanks! > > I will include headers of a message we have this problem with: > > > Received: from RJX ([218.107.2.59])by venus.KMZR.COM > (8.11.6/8.11.2) with > > SMTP id j0SDSbL06054;Fri, 28 Jan 2005 07:28:38 -0600 > Message-Id: <200501281328.j0SDSbL06054@venus.KMZR.COM> > Received: from abac.com ([28.90.248.212]) by > crisscross.iupi.pt > > (InterMail vK.4.04.00.00 813-535-420 license > > 5uz341wo5802c0kq1v5mts5394z8rdj1) with ESMTP id > > <75579863733746.EUMI071.cosy@abac.com> for ; > Fri, > > 28 Jan 2005 11:21:00 -0200 > Received: from mail pickup service by hotmail.com with > Microsoft SMTPSVC; > > Fri, 28 Jan 2005 19:25:00 +0600 > Received: from 24.240.198.188 by ami.demagogue.hotmail.msn.com with > > HTTP;Fri, 28 Jan 2005 14:27:00 +0100 GMT > X-Originating-IP: [18.219.66.153] > X-Originating-Email: [combat@abac.com] > From: "Augusta Wood" , "Augusta > Wood" > To: mccord@kmzr.com, > "Mccord" > Subject: {FAILED SC} Spyware Aiert - January 25th > Date: Fri, 28 Jan 2005 14:26:00 +0100 > Mime-Version: 1.0 > Received: from abac.com ([100.144.236.240]) by > crisscross.iupi.pt > > (InterMail vK.4.04.00.00 218-712-387 license > > 5uz341wo5802c0kq1v5mts5394z8rdj1) with ESMTP id > > <67078592714268.CCLC9817.crisscross.iupi.pt> for > ; > Fri, 28 Jan 2005 17:26:00 +0400 > Subject: Spyware Aiert - January 25th > Sender: "Augusta Wood" > X-KMZR-MailScanner-Information: > > X-MailScanner-SpamCheck: spam, SpamAssassin (score=22.075, required > > 7,autolearn=spam, BAYES_80 2.09, INVALID_TZ_GMT 0.20, LONGWORD > > 0.30,LONGWORDS 2.26, MR_NOT_ATTRIBUTED_IP 0.20, MR_STRANGE_QUESTION > > 1.50,MSGID_FROM_MTA_HEADER 0.05, MSGID_FROM_MTA_ID 1.72, NO_RDNS2 > > 0.01,RCVD_IN_DSBL 3.81, RCVD_IN_SORBS 1.00, URIBL_OB_SURBL > > 3.21,URIBL_SC_SURBL 4.26, URIBL_WS_SURBL 1.46) > X-MailScanner-SpamScore: ssssssssssssssssssssss > X-MailScanner-From: reevesxfkyy@topteam.bg > Return-Path: Reevesxfkyy@topteam.bg > X-OriginalArrivalTime: 28 Jan 2005 13:30:17.0277 (UTC) > FILETIME=[81717ED0:01C5053D] > > > > Brian M. Duncan > > Katten Muchin Zavis Rosenman > 525 West Monroe Street > Chicago IL 60661-3693 > 312-577-8045 > > brian.duncan@kmzr.com > > =========================================================== > > Important: > This electronic mail message and any attached files contain > information intended for the exclusive use of the individual > or entity to whom it is addressed and may contain information > that is proprietary, privileged, confidential and/or exempt > from disclosure under applicable law. If you are not the > intended recipient, you are hereby notified that any viewing, > copying, disclosure or distribution of this information may > be subject to legal restriction or sanction. Please notify > the sender, by electronic mail or telephone, of any > unintended recipients and delete the original message without > making any copies. > > =========================================================== > > ------------------------ MailScanner list > ------------------------ To unsubscribe, email > jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the MAQ > (http://www.mailscanner.biz/maq/) and the archives > (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > -- > This email has been scanned by the Level 5 Internet > MailCrusader for viruses, spam and dangerous content. > For more information please visit http://www.l5net.net > > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! =========================================================== Important: This electronic mail message and any attached files contain information intended for the exclusive use of the individual or entity to whom it is addressed and may contain information that is proprietary, privileged, confidential and/or exempt from disclosure under applicable law. If you are not the intended recipient, you are hereby notified that any viewing, copying, disclosure or distribution of this information may be subject to legal restriction or sanction. Please notify the sender, by electronic mail or telephone, of any unintended recipients and delete the original message without making any copies. =========================================================== ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:29:11 2006 Subject: No subject Message-ID: Trojan.Moo is a Trojan horse program that exploits the Microsoft GDI+ Library JPEG Segment Length Integer Underflow vulnerability (described in the Microsoft Security Bulletin MS04-028). So, yes, there are common clients that have this bug if not properly patched. But I believe only IE supports the cursor property and I am sure only IE 6+ supports the url parameter within a cursor property definition. Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:29:12 2006 Subject: No subject Message-ID: >Is Definitely MCP = %rules-dir%/mcp.rules >I have this in my %rules-dir%/mcp.rules > >From: @domain.com yes >FromOrTo: default no Hope this is clear enough to give you a picture of whats happening or else pleaselet me know i will try again. On Thu, 31 Mar 2005 18:55:51 +0100, Julian Field wrote: >You realise that those MCP actions will deliver the mail to the original >recipient as well as forward it to user@domain.com. > >Venkata Achanta wrote: > >>Julian, >> >>I think you didnt see the MCP config in the e-mail. >> >>Yes ! i am aware that spam actions have nothing to do with MCP. >> >> >> >>>MCP Actions = deliver user@domain.com >>> >>> >>is what i have in the MCP actions and i still the behaviour mentioned >>earlier. >> >> >-- >Julian Field >www.MailScanner.info >Buy the MailScanner book at www.MailScanner.info/store >Professional Support Services at www.MailScanner.biz >MailScanner thanks transtec Computers for their support > >PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > >------------------------ MailScanner list ------------------------ >To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >'leave mailscanner' in the body of the email. >Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and >the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > >Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the MAQ (http://www.mailscanner.biz/maq/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:29:18 2006 Subject: No subject Message-ID: configuration file "/usr/share/spamassassin/20_body_tests.cf" requires version 3.000002 of SpamAssassin, but this is code version 3.000000. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.0/Mail/SpamAssassin/Conf/Parser.pm line 329. (several of those) Then later I see several of these... debug: config: SpamAssassin failed to parse line, skipping: uridnsbl_skip_domain yahoo.com w3.org msn.com com.com yimg.com debug: config: SpamAssassin failed to parse line, skipping: uridnsbl_skip_domain hotmail.com doubleclick.net flowgo.com ebaystatic.com aol.com If I do a which spamassassin I get... /usr/bin/spamassassin If I find /usr/lib/perl5 -name SpamAssassin.pm -print, I get... /usr/lib/perl5/site_perl/5.8.0/Mail/SpamAssassin.pm /usr/lib/perl5/vendor_perl/5.8.0/Mail/SpamAssassin.pm So there still are two? I guess I don't understand... help please? > Just whichever place you start using these RPMs from (Dag's is just > fine) make sure you stick to it. Good tip... I'll add it to my notes. I know you're busy, but if you could maybe give me a short explanation of how I screwed this up I'd appreciate it. I've upgraded 2-3 times using your scripts before without any problems and followed my notes this time with less then successful results. If I knew why/how this happened maybe I keep from doing it again in the future. I do and have read everything I can get my hands on including the list everyday and all the FAQ's MAQ's and now wiki's. But I still seem to get myself into a mess every now and again. :) Many thanks again. k Output from MailScanner -v (just in case) [root@gw-mail /]# MailScanner -v Running on Linux gw-mail.aiainsurance.com 2.4.20-30.9 #1 Wed Feb 4 20:44:26 EST 2004 i686 i686 i386 GNU/Linux This is Red Hat Linux release 9 (Shrike) This is Perl version 5.008000 (5.8.0) This is MailScanner version 4.40.11 Module versions are: 1.00 AnyDBM_File 1.14 Archive::Zip 1.01 Carp 1.119 Convert::BinHex 1.00 DirHandle 1.04 Fcntl 2.71 File::Basename 2.05 File::Copy 2.01 FileHandle 1.05 File::Path 0.13 File::Temp 1.29 HTML::Entities 3.45 HTML::Parser 2.30 HTML::TokeParser 1.20 IO 1.09 IO::File 1.122 IO::Pipe 1.50 Mail::Header 3.05 MIME::Base64 5.417 MIME::Decoder 5.417 MIME::Decoder::UU 5.417 MIME::Head 5.417 MIME::Parser 3.03 MIME::QuotedPrint 5.417 MIME::Tools 0.10 Net::CIDR 1.05 POSIX 1.75 Socket 0.03 Sys::Syslog 1.02 Time::localtime Optional module versions are: 1.806 DB_File 1.08 Digest 1.01 Digest::HMAC 2.33 Digest::MD5 2.10 Digest::SHA1 0.44 Inline 0.13 Mail::ClamAV 3.000000 Mail::SpamAssassin 1.997 Mail::SPF::Query 0.15 Net::CIDR::Lite 0.48 Net::DNS missing Net::LDAP 1.94 Parse::RecDescent missing SAVI 1.2 Sys::Hostname::Long 2.42 Test::Harness 0.47 Test::Simple 1.89 Text::Balanced 1.35 URI Ken Goods Network Administrator AIA Insurance, Inc. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:29:30 2006 Subject: No subject Message-ID: Steve Steve Swaney President Fortress Systems Ltd. Phone: 202 338-1670 Cell: 202 352-3262 www.fsl.com steve.swaney@fsl.com ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:29:31 2006 Subject: No subject Message-ID: Incoming Queue Dir = /var/spool/exim.in/input ... MTA = exim [root@filter etc]# ls -la !$ ls -la /var/spool/exim.in/input total 32 drwxrwxrwx 2 exim exim 4096 May 4 10:56 . drwxr-x--- 5 exim exim 4096 May 2 16:39 .. -rw-r----- 1 exim exim 24 May 4 10:56 1DTO6X-0003mH-2u-D -rw-r----- 1 exim exim 1556 May 4 10:56 1DTO6X-0003mH-2u-H anything else I can look for?? -----Original Message----- From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Julian Field Sent: Wednesday, May 04, 2005 12:49 PM To: MAILSCANNER@JISCMAIL.AC.UK Subject: Re: mailscanner not processing exim queue Check your Incoming Queue Directory point to /var/spool/exim.in/input and MTA = exim. Arif Malik wrote: > Not sure what is wrong - my first attempt running mailscanner... I > have exim now queing up mail in /var/spool/exim.in/input - which is > what i have mailscanner set to look at for incoming mail... my > /var/log/maillog shows only one thing ever: > > May 4 11:22:12 filter MailScanner[15045]: MailScanner E-Mail Virus > Scanner version 4.31.2 starting... > There are no errors or anything, but all my mail just sits in > /var/spool/exim.in/input, and mailscanner doesn't scan/move them into > the outgoing directory. I have browsed the archives and didn't see > anyone having the same problem which makes me think its probably > something simple, but I have been going back over the configs over and > over and don't see what I'm missing.. any help is much appreciated. > Thanks! > ------------------------ MailScanner list ------------------------ To > unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and the > archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > *Support MailScanner development - buy the book off the website!* -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:29:36 2006 Subject: No subject Message-ID: sendmail somebody Blah Blah Blah . And expect it to be in out.txt. It's not, and examining the logs gives me: *********** LOG BEGIN ********************** May 12 13:39:21 computername sendmail[9232]: j4CHdKWv009232: from=dweber, size=5, class=0, nrcpts=1, msgid=<200505121739.j4CHdKWv009232@computername.backbonesecurity.com>, relay=root@localhost May 12 13:39:21 computername sendmail[9233]: j4CHdLQS009233: from=, size=307, class=0, nrcpts=1, msgid=<200505121739.j4CHdKWv009232@computername.backbonesecurity.com>, proto=ESMTP, daemon=MTA, relay=computername.backbonesecurity.com [127.0.0.1] May 12 13:39:21 computername sendmail[9232]: j4CHdKWv009232: to=leads@localhost, ctladdr=dweber (500/501), delay=00:00:01, xdelay=00:00:00, mailer=relay, pri=30005, relay=[127.0.0.1] [127.0.0.1], dsn=2.0.0, stat=Sent (j4CHdLQS009233 Message accepted for delivery) May 12 13:39:23 computername MailScanner[7855]: New Batch: Forwarding 1 unscanned messages, 829 bytes May 12 13:39:23 computername MailScanner[7855]: Unscanned: Delivered 1 messages May 12 13:39:23 computername MailScanner[7855]: Virus and Content Scanning: Starting May 12 13:39:23 computername sendmail[9235]: STARTTLS=client: file /etc/mail/certs/cert.pem unsafe: No such file or directory May 12 13:39:23 computername sendmail[9235]: STARTTLS=client: file /etc/mail/certs/key.pem unsafe: No such file or directory May 12 13:39:23 computername sendmail[9235]: STARTTLS=client: file /etc/mail/certs/cacert.pem unsafe: No such file or directory May 12 13:39:23 computername sendmail[9235]: STARTTLS=client, error: load verify locs /etc/mail/certs, /etc/mail/certs/cacert.pem failed: 0 ***************** LINES OF INTEREST ***************************** May 12 13:39:24 computername sendmail[9241]: j4CHdLQS009233: to="| /post_leads_to_sugar", ctladdr= (8/0), delay=00:00:03, xdelay=00:00:00, mailer=prog, pri=120307, dsn=5.3.0, stat=unknown mailer error 1 May 12 13:39:24 computername sendmail[9241]: j4CHdLQS009233: j4CHdNdt009241: DSN: unknown mailer error 1 May 12 13:39:24 computername sendmail[9241]: j4CHdNdt009241: to=, delay=00:00:00, xdelay=00:00:00, mailer=local, pri=31800, dsn=2.0.0, stat=Sent **************** LOG END ***************************************** ************ BEGIN ACCESS FILE ************************ Here's my /etc/mail/access file (because it's fairly complex) computername.backbonesecurity.com RELAY localhost.localdomain RELAY localhost RELAY 127.0.0.1 RELAY # Block all email not explicitly allowed by the automatic script To:backbonesecurity.com REJECT #allow the internal email server to use this as a smart host 216.144.184.6 RELAY 216.144.184.8 RELAY # --- BEGIN ADDRESSES AUTOMATICALLY GATHERED FROM EXCHANGE SERVER --- ***************** END ACCESS FILE ************************* Thanks for any help ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:29:36 2006 Subject: No subject Message-ID: sendmail somebody Blah Blah Blah . And expect it to be in out.txt. It's not, and examining the logs gives me: *********** LOG BEGIN ********************** May 12 13:39:21 computername sendmail[9232]: j4CHdKWv009232: from=dweber, size=5, class=0, nrcpts=1, msgid=<200505121739.j4CHdKWv009232@computername.backbonesecurity.com>, relay=root@localhost May 12 13:39:21 computername sendmail[9233]: j4CHdLQS009233: from=, size=307, class=0, nrcpts=1, msgid=<200505121739.j4CHdKWv009232@computername.backbonesecurity.com>, proto=ESMTP, daemon=MTA, relay=computername.backbonesecurity.com [127.0.0.1] May 12 13:39:21 computername sendmail[9232]: j4CHdKWv009232: to=leads@localhost, ctladdr=dweber (500/501), delay=00:00:01, xdelay=00:00:00, mailer=relay, pri=30005, relay=[127.0.0.1] [127.0.0.1], dsn=2.0.0, stat=Sent (j4CHdLQS009233 Message accepted for delivery) May 12 13:39:23 computername MailScanner[7855]: New Batch: Forwarding 1 unscanned messages, 829 bytes May 12 13:39:23 computername MailScanner[7855]: Unscanned: Delivered 1 messages May 12 13:39:23 computername MailScanner[7855]: Virus and Content Scanning: Starting May 12 13:39:23 computername sendmail[9235]: STARTTLS=client: file /etc/mail/certs/cert.pem unsafe: No such file or directory May 12 13:39:23 computername sendmail[9235]: STARTTLS=client: file /etc/mail/certs/key.pem unsafe: No such file or directory May 12 13:39:23 computername sendmail[9235]: STARTTLS=client: file /etc/mail/certs/cacert.pem unsafe: No such file or directory May 12 13:39:23 computername sendmail[9235]: STARTTLS=client, error: load verify locs /etc/mail/certs, /etc/mail/certs/cacert.pem failed: 0 ***************** LINES OF INTEREST ***************************** May 12 13:39:24 computername sendmail[9241]: j4CHdLQS009233: to="| /post_leads_to_sugar", ctladdr= (8/0), delay=00:00:03, xdelay=00:00:00, mailer=prog, pri=120307, dsn=5.3.0, stat=unknown mailer error 1 May 12 13:39:24 computername sendmail[9241]: j4CHdLQS009233: j4CHdNdt009241: DSN: unknown mailer error 1 May 12 13:39:24 computername sendmail[9241]: j4CHdNdt009241: to=, delay=00:00:00, xdelay=00:00:00, mailer=local, pri=31800, dsn=2.0.0, stat=Sent **************** LOG END ***************************************** ************ BEGIN ACCESS FILE ************************ Here's my /etc/mail/access file (because it's fairly complex) computername.backbonesecurity.com RELAY localhost.localdomain RELAY localhost RELAY 127.0.0.1 RELAY # Block all email not explicitly allowed by the automatic script To:backbonesecurity.com REJECT #allow the internal email server to use this as a smart host 216.144.184.6 RELAY 216.144.184.8 RELAY # --- BEGIN ADDRESSES AUTOMATICALLY GATHERED FROM EXCHANGE SERVER --- ***************** END ACCESS FILE ************************* Thanks for any help ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:29:38 2006 Subject: No subject Message-ID: This is the current list of tests SpamAssassin(tm) performs on mail messages to determine if they're spam or not. If you wish to change the score from the default, add a line like this to your ~/.spamassassin/user_prefs: -------------------------------------------- And from MailScanner.conf (Debian package) # The per-user files (bayes, auto-whitelist, user_prefs) are looked # for here and in ~/.spamassassin/. Note the files are mutable. # If this is unset then no extra places are searched for. # If using Postfix, you probably want to set this as shown in the example # line at the end of this comment, and do # mkdir /var/spool/MailScanner/spamassassin # chown postfix.postfix /var/spool/MailScanner/spamassassin # NOTE: SpamAssassin is always called from MailScanner as the same user, # and that is the "Run As" user specified above. So you can only # have 1 set of "per-user" files, it's just that you might possibly # need to modify this location. # You should not normally need to set this at all. #SpamAssassin User State Dir = /var/spool/MailScanner/spamassassin SpamAssassin User State Dir = /var/lib/MailScanner > -----Original Message----- > From: MailScanner mailing list > [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Martin Hepworth > Sent: Tuesday, May 17, 2005 9:20 AM > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: Conf file change request spam.assassin.prefs.conf > > Scott > > you could alway put you site specific things in a file in > /etc/mail/spamassassin. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > Hancock, Scott wrote: > > Could this section of spam.assassin.prefs.conf call a file > similar to > > the whitelist file? > > > > # =============== Change SpamAssassin Rules scores =============== > > > > I'm hoping it would make upgrading mailscanner easier. > > > > Thanks > > > > Scott Hancock > > -Morgan > > > > ------------------------ MailScanner list > ------------------------ To > > unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > > 'leave mailscanner' in the body of the email. > > Before posting, read the Wiki > (http://wiki.mailscanner.info/) and the > > archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > > > Support MailScanner development - buy the book off the website! > > ********************************************************************** > > This email and any files transmitted with it are confidential > and intended solely for the use of the individual or entity > to whom they are addressed. If you have received this email > in error please notify the system manager. > > This footnote confirms that this email message has been swept > for the presence of computer viruses and is believed to be clean. > > ********************************************************************** > > ------------------------ MailScanner list > ------------------------ To unsubscribe, email > jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) > and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:29:44 2006 Subject: No subject Message-ID: If you are using this ruleset, a quick hack is to change the __KP_DAEMON rule to header __KP_DAEMON From =~ /./i so that it always matches. The better solution by far is to switch back to Raymond's original ruleset at http://mailscanner.prolocation.net/german.cf The "improvement" someone made to it wasn't as good as it might have looked :( -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:29:44 2006 Subject: No subject Message-ID: While I wept and began to moan suddenly there came a rining on my phone. As of someone urgently phoninig, phonining me to do a chore "Tis some boss," I thought, phoning me to do a chore. Only this and nothing more. Ah, fondly I remember, it was a sunny day in September. And every I.T guy was running around on that floor. Eagrly I wished that google would do it's works. To find me a solution to these virus jerks. It answered my cry and gave me a name. Julian Field ,and much much more And the silken sad clicking of each new web page Thrilled me, filled with fantastic relief never felt before. So that now, to stop the ringing in my ears, I stood repeating. "Tis some boss just calling me on my phone" "Some annoying boss wanting me to do another chore" This it is and nothing more. Presently my courage got stronger, taking it no longer. I reached down and picked up that damn phone. "Sir", said I, what can I do you for? That fact was, that the boss had been napping And the clients had started crapping. Crapping on him like never before. Deep into the phone I began listening, wondering, fearing. Hearing, I must get a solution to this problem before four. To stop the spam and virus' in its tracks So the clients would get off our backs. MailScanner! This I whispered back in the phone. MailScanner and nothing more. Back to the computer turning, all the keys on the keyboard burning. Soon I began learning, learning Mailscanner and how to install. "Surely" said I when I finshed, surely this can't be true. An open source program that does virus scanning, content filter and SPAM checking too. I picked on the phone and made the call. From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:29:44 2006 Subject: No subject Message-ID: But finally in stepped Mailscanner, from a hard days chore. And all around the I.T. guys gathered to see what was the matter. The matter, because this had never been done before. MailScanner sat there saying "Nevermore" "Work!" said I, as I started the new Service And we cowered round the tailed log files of the servers. As we watched the log files start to grow. And started to read the lines, row by row. We saw something new, something we would now adore Quoth the Mailscanner, "Nevermore" And now the Mailscanner, never dying, still working, still working. On all the mailservers in the data center on the ground floor. And its eyes having all that it can see of a daemon using clam-AV. The I.T. guys are not longer running around that floor. And the phone do not ring anymore. All because of Mailscanner. Shall not be lifted - Nevermore! -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:29:45 2006 Subject: No subject Message-ID: qualified domain name, however other information such as MTA name and version is not required. Certainly my banner message is 220 mx1.bmrb.co.uk ESMTP Which I believe to be RFC compliant - until it passes through my PIX that is! -- _________________________________________________________________ KMR Group, KMR Software and BMRB have moved offices. Our new address is: Ealing Gateway 26-30 Uxbridge Road Ealing London W5 2BP t: 020 8433 4000 f: 020 8433 4001 All direct line numbers remain unchanged _________________________________________________________________ BMRB http://www.bmrb.co.uk _________________________________________________________________ This message (and any attachment) is intended only for the recipient and may contain confidential and/or privileged material. If you have received this in error, please contact the sender and delete this message immediately. Disclosure, copying or other action taken in respect of this email or in reliance on it is prohibited. BMRB Limited accepts no liability in relation to any personal emails, or content of any email which does not directly relate to our business. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:29:59 2006 Subject: No subject Message-ID: messages within about an hour or two if left alone. Stopping the service and killing sendmail procs has no effect, while rebooting the server brings the queue down very quickly. This used to happen only every Friday afternoon but now it is getting much more frequent. The mail log will show mostly stat=queued with only a sporadic stat=sent when this happens. Both run tempfs in RAM, have a local mailwatch installation which transfers all its rows to a central database every night and run a local named. Anybody has any idea what could cause this? Thanks, Bart^Å ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:29:59 2006 Subject: No subject Message-ID: messages within about an hour or two if left alone. Stopping the service and killing sendmail procs has no effect while rebooting the server brings the queue down very quickly. This used to happen only every Friday evening but now it is getting much more frequent. The mail log will show mostly stat=queued with only a sporadic stat=sent when this happens. Both run tempfs in RAM, have a local mailwatch installation which transfers all its rows to a central database every night and run a local named. Anybody has any idea what could cause this? Thanks, Bart… ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:30:06 2006 Subject: No subject Message-ID: bad standpoint. Mind you, I'm not defending his ... testiness... Just seeing "the other side":-). -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:30:08 2006 Subject: No subject Message-ID: SpamAssassin score for the message") you might indeed have done something in that area. Added new: Unrar Command = /usr/bin/unrar Added new: Unrar Timeout = 50 Added new: Disarmed Modify Subject = yes Added new: Disarmed Subject Text = {Disarmed} Added new: Spam Lists To Be Spam = 1 Added new: Use Custom Spam Scanner = no Added new: Max Custom Spam Scanner Size = 20000 Added new: Custom Spam Scanner Timeout = 20 Added new: Max Custom Spam Scanner Timeouts = 10 Added new: Custom Spam Scanner Timeout History = 20 Kai -- Kai Schätzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com IE-Center: http://ie5.de & http://msie.winware.org ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:30:14 2006 Subject: No subject Message-ID: called language.conf.new [root@WoodenMS en]# ls deleted.content.message.txt recipient.spam.report.txt deleted.filename.message.txt sender.content.report.txt deleted.virus.message.txt sender.error.report.txt disinfected.report.txt sender.filename.report.txt inline.sig.html sender.mcp.report.txt inline.sig.txt sender.spam.rbl.report.txt inline.spam.warning.txt sender.spam.report.txt inline.warning.html sender.spam.sa.report.txt inline.warning.txt sender.virus.report.txt languages.conf stored.content.message.txt languages.conf.from.new stored.filename.message.txt languages.new stored.virus.message.txt recipient.mcp.report.txt 2) The language.new has nothing in it. I am guessing that since there was no language.rpmnew that it created the file from nothing and hence is blank. The languages.conf.from.new file is the new one that was created. I renamed this so that I could use my original language file and get MailScanner up and running without the lanuage errors. Any idea what happened to my language.rpmnew file? Billy Pumphrey IT Manager Wooden & McLaughlin ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:30:15 2006 Subject: No subject Message-ID: # Do you want to stop any virus-infected spam getting into the spam or MCP # archives? If you have a system where users can release messages from the # spam or MCP archives, then you probably want to stop them being able to # release any infected messages, so set this to yes. # It is set to no by default as it causes a small hit in performance, and # many people don't allow users to access the spam quarantine, so don't # need it. # This can also be the filename of a ruleset. Keep Spam And MCP Archive Clean = no ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:30:15 2006 Subject: No subject Message-ID: the Envelope-From. So I suppose the Envelope-From contained user@monster.com (your mail log would tell) and that's why it got whitelisted. As for the general whitelist problem. You can use SA whitelisting. That allows to whitelist from addresses coming over certain relays. I think it's called whitelist_received or so. If you look in /usr/share/spamassassin (which holds the basic rules SA comes with, don't change anything there!) you will find some of these rules in the xx_whitelisted.cf file or what it's called. But beware: SA whitelisting works only on the header not on the envelope! Kai -- Kai Schätzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com IE-Center: http://ie5.de & http://msie.winware.org ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:30:17 2006 Subject: No subject Message-ID: but Linux beats fBSD when everything runs in RAM. Considering our machines are always running with zero swap used, we "should" get a bit more out of them on Linux. How much will probably be a matter for speculation, as the benchmarks we've used are fairly artificial - they are purely programatic tests that bypass certain things in order to work. Cheers, James ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:30:19 2006 Subject: No subject Message-ID: "There are many examples, Freedman says. Information about NASA's Mars explorer program was deleted from library Internet access because when the two words Mars and explorer are merged, they form the word "sex." Likewise, library computer searches for information about Super Bowl XXX are often fruitless because the filtering technology cannot differentiate between the use of Roman numerals to specify a championship football game and the use of three X's to designate a pornographic video" ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:30:21 2006 Subject: No subject Message-ID: mystique.winnefox.org. [Preference = 20] mail.winnefox.org. [Preference = 10] destiny.winnefox.org. [Preference = 15] > When mail hits on Destiny some problem oocurs (it can be a connection > time out or a busy server ) and the mail goes to Mystique instead. > But in normal scenarios when there is no load or much traffic on the > server you are observing that the mail still goes to mystique. Close. Mail goes to mail.winn... Then get's bounced to destiny. Destiny scans that mail, then sends it off to mail.winn... Mystique.winn... Is only there as a fail safe in case there's a problem with destiny. Does that make any sense? > 2) Is Destiny and Mystique directly available on the Internet via MX > records Yes. - jody ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:30:27 2006 Subject: No subject Message-ID: works. What's weird to me is that net checks are working, but you're not seeing any network tests hitting. Do you have skip_rbl_checks 1 in your spam.assassin.prefs.conf? > > And I want to get bayes running as well. > > This is from my maillog... > > Jul 29 00:50:19 ... from 201.29.117.228 (hellen@sexyhot.com.br) to > pcplace.ca is not spam, SpamAssassin (score=0, required 4) > Jul 29 11:05:24 ... from 142.165.20.172 (tracycarroll@sasktel.net) to > pcplace.ca is not spam (whitelisted), SpamAssassin (score=-100, required > 4, USER_IN_WHITELIST -100.00) > > I think it's reasonable that the sexyhot message would trip at least one > test. Or am I mistaken... clearly the whitelist rules are tested. Without seeing the message, I couldn't tell you what should or should not have hit. I can tell you that 201.29.117.228 isn't listed by any RBLs other than spamcop, and it's listing in spamcop is under 24hours old, so it may not have been listed at 00:50. I can tell you there's no rules that look for "sexyhot" in the from address or return path. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:30:36 2006 Subject: No subject Message-ID: So, now i have the following problem: Maybe someone tries to send a mail with this from-header this mail would not got scanned. So i wonder, as those mails are only from one ip possible, to set this rule more exact: Like: From xyc@xyc.com AND From: 255.255.255.255 (this ip is for example only ;) no Is this possible? I cannot put the ip only to no, as some mails from this ip should get scanned.. Any ideas are appreciated.. Thanks in advance Marcel ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:30:37 2006 Subject: No subject Message-ID: pgpgin/s Total number of kilobytes the system paged in from disk per second. pgpgout/s Total number of kilobytes the system paged out to disk per second. % swap used is steady at 1.05% > It doesn't seem to be I/O depraved either > (mine show worst iowait but I only have a single disk). This is a single raid 0 array, IDE 7200 RPM. > > What processes are displayed by top when this happens? > Can't tell right now, i'll check next time such a burst happens. We are running with 10 child processes on a HT 2.8 P4 with 2 GB RAM. Here is a sample of 'vmstat 5' when the load was ~ 7. procs memory swap io system cpu r b swpd free buff cache si so bi bo in cs us sy id wa 10 3 43196 98388 198936 629980 0 0 1 1 1 0 0 1 0 1 11 3 43196 138004 198956 617896 0 0 6 573 193 295 73 27 0 0 7 1 43196 130760 198976 612512 0 0 2 394 178 516 83 17 0 0 9 3 43196 147580 198980 624544 0 0 0 2716 145 328 86 14 0 0 5 4 43196 151496 200456 623460 0 0 4 2714 190 606 84 16 0 0 Maybe we'd need a more powerful CPU? > Denis > Merci bien Denis ;) -- Ugo -> Please don't send a copy of your reply by e-mail. I read the list. -> Please avoid top-posting, long signatures and HTML, and cut the irrelevant parts in your replies. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:30:38 2006 Subject: No subject Message-ID: from the picture... there hardly seem to be any taking place. What fs do you use? Perhaps an issue with that... Or perhaps some really crummy NIC driver and a spell of network congestion driving the CPU nuts? It has been known to happen (mostly back in the dark ages, but still:-). Oh well, 'nuff rambling -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:30:50 2006 Subject: No subject Message-ID: " * No syncs on logs - edit your syslog.conf file #mail.* /var/log/maillog (commented out) mail.* -/var/log/maillog (new line) " Notice the '-' in front of the logfile name. Nate ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:31:02 2006 Subject: No subject Message-ID: ========================================================================= BitDefender Linux Edition uses the most advanced multi-platform virus inspection technology which scans for viruses and other malware on your personal system. The On-Demand Scanner, for command line or shell scripts, features manual scan of individual files or entire file systems, malicious code detection and disinfection. After each scan, the solution displays a detailed report on positive virus detections. Thanks to BitDefender scan engine advanced features, new, undiscovered threats can be detected and immediately eliminated from the system. Available for most UNIX platforms, the product has the role to keep you away from worms like Morris or Scalper ^Ö UNIX malware, as well as from all the Windows viruses. BitDefender Linux Edition is a freeware product, which doesn't require a license to be used. ========================================================================= The free version is just an on-demand scanning engine, the commercial linux version is much, much more and you can see some of the features here http://www.bitdefender.com/PRODUCT-100-en--BitDefender-Antivirus-&-Antispam- for-Linux-and-FreeBSD-Mail-Servers.html or here http://download.bitdefender.com/linux/mailserver/RELEASE_NOTES The free windows desktop version is strictly on-demand and doesn't have the realtime scanning or a whole host of other features. Therefor it's a useless product compared to, say, AVG free home addition which doesn't allow much in configuration or cleaning options but does include email scanner, and realtime scanning as well as on demand. Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:31:10 2006 Subject: No subject Message-ID: How long will Sophos Anti-Virus for Linux, version 3.xx, be available after the launch of Sophos Anti-Virus for Linux, version 5.0? Because administrators have to uninstall Sophos Anti-Virus for Linux, version 3.xx, in order to upgrade to version 5.0, we will support version 3.xx for one year after version 5.0 becomes available. It also appears that there will also be better updating capabilities with the new version. -- Aaron Kent Moore Information Technology Services DeKalb Memorial Hospital, Inc. Auburn, IN E-mail: amoore@dekalbmemorial.com ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:31:12 2006 Subject: No subject Message-ID: my mailscanner servers get quarantined due to pyzor seeing a URL in the bounce and assigning a relatively high score to it. These are legitimate bounced messages where a user has incorrectly typed a recipient email address. Is there a known way that this can be overcome? Many thanks in advance. Tony. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:31:13 2006 Subject: No subject Message-ID: I receive this error, root....connecting to [127.0.0.1] via relay root....Deferred: Connection refused by [127.0.0.1] What files do I need to modify under /etc/mail? Marc Dufresne, Corporate IT Officer St. Lawrence Parks Commission 13740 County Road 2 Morrisburg, ON K0C 1X0 E-mail: Marc.Dufresne@parks.on.ca Voice: 613-543-3704 Ext#2455 Fax: 613-543-2847 Corporate website: www.parks.on.ca >>> BB 11/20/2005 9:38 PM >>> Marc, I have attached working sendmail.mc and sendmail.cffiles along with /etc/rc.conf startup. There are a number of things in the rc.conf that you don't need just use the sendmail portion for examples. BTW /etc/defaults/rc.conf show examples and are used if /etc/rc.conf does not exist. /etc/rc.conf will override /etc/defaults/rc.conf. The first thing is to get a working copy of sendmail running. Make your edits to /etc/rc.conf with the examples sent. Copy sendmail.cf /etc/mail Verify no sendmail processes are running and if they are kill the pid of them. Verify again they are gone. Run "sh /etc/rc.sendmail start" . No quotes. This should start sendmail. Send your self a test message from the MTA level - sendmail -v root . It does not make sense to me why sendmail is running if it is marked to "NONE". If that dosen't do it mark the first instance with NONE and all the others with NO BTW: There is also a nice webmin modual for MailScanner. Once setup things don't change much other then whitelists/blacklists. The latest version of mailwatch can do this hence Is Definitely Not Spam = &SQLWhitelist Is Definitely Spam = &SQLBlacklist Hang on for the ride... On 11/20/05, Marc Dufresne wrote: > > I am going to explain my understanding of the MailScanner setup. Please > reveiw and let me know if I'm understanding this correctly? > > When MailScanner.conf is configured, the following parameters should be > set if I'm using sendmail on FreeBSD 5.4: > > #MTA used for the Gateway > MTA=sendmail > > #Set how to invoke MTA when sending messages MailScanner has created > (e.g. to sender/recipient saying "found a virus in your message"). This > can also be the filename of a ruleset. > sendmail=/usr/sbin/sendmail > > #Incoming mail queue directory for Sendmail > Incoming Queue Directory=/var/spool/mqueue > > #Outgoing mail queue directory for Sendmail > Outgoing Queue Directory=/var/spool/mqueue > > #Incoming Queue Directory for MailScanner > /var/spool/MailScanner/incoming > > #Quarantine Directory for MailScanner > /var/spool/MailScanner/quaratine > > System Startup should be as follows: > > 1) #Disable sendmail from loading at system startup > modify /etc/rc.conf to disable sendmail load > > http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/mail-changingmta.html > > > Section 23.4.2.3 FreeBSD 5.0-STABLE and Later > > /etc/rc.conf > > sendmail_enable="NO" > sendmail_submit_enable="NO" > sendmail_outbound_enable="NO" > sendmail_msp_queue_enable="NO" > > 2) #Load MailScanner at system startup. > #Make sure mailscanner.sh file is located under /usr/local/etc/rc.d > in order to load MailScannner process at startup. Mailscanner.sh should > invoke sendmail and mailscanner process to start scanning/delivering > mail. > > /usr/local/etc/rc.d/mailscanner.sh > _________________________________ > > First Problem > > I cannot disable sendmail on bootup on FreeBSD 5.4!!!! I tried > everything. Sendmail still loads at startup??????? > > Second Problem > > Once system is completly loaded and sitting at the login prompt, I > receive an error > NOQUEUE:SYSERROR(root):opendaemon socket:daeomon IPv4:cannot bind > address already in use > > I login, and run ps -ax (This is what I see) > > 375 ?? Ss 0:00.07 sendmail: accepting connections (sendmail) > 379 ?? Is 0:00.00 sendmail: Queue runner@00:30:00 for > /var/spool/client > > 426 ?? Is 0:00.01 sendmail: Queue runner@00:15:00 for > /var/spool/mqueue > 430 ?? Is 0:00.01 sendmail: Queue runner@00:15:00 for > /var/spool/client > > 613 ?? Ss 0:00.02 /usr/bin/perl -I/usr/local/lib/MailScanner > /usr/local 614 ?? S 0:02.33 /usr/bin/perl > -I/usr/local/lib/MailScanner /usr/local > 627 ?? S 0:02.19 /usr/bin/perl -I/usr/local/lib/MailScanner > /usr/local > 630 ?? S 0:02.15 /usr/bin/perl -I/usr/local/lib/MailScanner > /usr/local > 635 ?? S 0:02.17 /usr/bin/perl -I/usr/local/lib/MailScanner > /usr/local > 636 ?? S 0:00.11 /usr/bin/perl -I/usr/local/lib/MailScanner > /usr/local > > Third Problem > > I run tail -f /var/log/maillog > > I will send test e-mails from the outside and watch sendmail receive > and process incoming mail. Everyone receives e-mails from the outside, > but mailscanner does not scan any messages. > > I will issue a mailq to view /var/spool/mqueue directory. Directory is > always empty. > > I'm completely stumped here as to why Sendmail refuses to disable at > startup and MailScanner refuses to scan e-mail messages!!!!! > > Any ideas???? > > > Marc Dufresne, Corporate IT Officer > St. Lawrence Parks Commission > 13740 County Road 2 > Morrisburg, ON K0C 1X0 > > E-mail: Marc.Dufresne@parks.on.ca > Voice: 613-543-3704 Ext#2455 > Fax: 613-543-2847 > Corporate website: www.parks.on.ca > > >>> BB 11/19/2005 12:38 AM >>> > Don't know if they ever got the list fixed for my replies, so I'm doing > it > direct and through the list. > > Change /etc/rc.conf or /etc/defaults/rc.conf > sendmail_enable=NONE > > Verify mailscanner is starting up with /usr/local/etc/rc.d/mailscanner > .sh > > Think you need to manually create some of the directores. Verify > MailScanner.conf for directories. > > tail -f /var/log/maillog will show you the details > > The only reason to rebuild sendmail.cf > is to > remove > IPv6 stuff. I would use m4 macro for that. Webmin would be a good > choice to > use. > > # SMTP daemon options > > O DaemonPortOptions=Name=IPv4, Family=inet > O DaemonPortOptions=Name=IPv6, Family=inet6, Modifiers=O > O DaemonPortOptions=Port=587, Name=MSA, M=E > > > -- > ACK and you shall receive > > > -- ACK and you shall receive ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! [ Part 2, Text/PLAIN (Name: "Marc Dufresne.vcf") 20 lines. ] [ Unable to print this part. ] From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:31:15 2006 Subject: No subject Message-ID: with what made the installer easier. -- Anthony Peacock CHIME, Royal Free & University College Medical School WWW: http://www.chime.ucl.ac.uk/~rmhiajp/ "The most exciting phrase to hear in science, the one that heralds new discoveries, is not 'Eureka!' but 'That's funny....'" -- Isaac Asimov ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:31:17 2006 Subject: No subject Message-ID: Mcafee: total of 288 viruses were found and filtered. ClamAV: A total of 292 viruses were found and filtered. Sophos: A total of 252 viruses were found and filtered. F-Secure: A total of 71 viruses were found and filtered. Considering that in recent months F-Secure was the complete opposite and double the detection rate of the other AVs, I'm a bit surprised by this. Is anyone using F-Secure? Am I using an out of date version? F-Secure Anti-Virus Command line client version: F-Secure Anti-Virus for Linux version 4.52 build 2461 F-Secure Corporation Libra database version 2005-11-25 F-Secure Corporation Orion database version 2005-11-25 Kaspersky Labs. AVP FPI Engine database version 2005-11-25 ... so the db's are current, but the binary is getting a bit long in the tooth. ---------------------------------------------------------------------------------------------------> Peter Bates, Systems Support Officer, IT Services. London School of Hygiene & Tropical Medicine. Telephone:0207-958 8353 / Fax: 0207- 636 9838 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:31:20 2006 Subject: No subject Message-ID: [85.68.2.82]) by mailscanftp.parks.on.ca (8.13.3/8.13.3) with ESMTP id jAUFjUU7016465; Wed, 30 Nov 2005 10:45:35 -0500 (EST) (envelope-from dirkmaxwell_os@lycos.com) Message-ID: From: "Dirk Maxwell" To: forms@parks.on.ca, getawaya@parks.on.ca Subject: {Spam?} Investment Idea For You Date: Wed, 30 Nov 2005 15:42:47 +0000 MIME-Version: 1.0 Content-Type: text/plain X-SLPC-MailScanner-Information: Please contact the ISP for more information X-SLPC-MailScanner: Found to be clean X-SLPC-MailScanner-SpamCheck: X-SLPC-MailScanner-From: dirkmaxwell_os@lycos.com Content-Transfer-Encoding: 8bit X-MIME-Autoconverted: from base64 to 8bit by mailscanftp.parks.on.ca id jAUFjUU7 016465 Marc Dufresne, Corporate IT Officer St. Lawrence Parks Commission 13740 County Road 2 Morrisburg, ON K0C 1X0 E-mail: Marc.Dufresne@parks.on.ca Voice: 613-543-3704 Ext#2455 Fax: 613-543-2847 Corporate website: www.parks.on.ca >>> Marc.Dufresne@PARKS.ON.CA 11/30/2005 1:55 PM >>> All SPAM detected is forwarded to my FreeBSD local account under /var/mail. Everyday I view the file and noticed that the Subject line is being modified at the beginning with {Spam?} with no spam score (ssss). I was under the impression that once SPAM is detected, it would score it accordingly by placing an "s" within the subject line. Why is this happenng? Marc Dufresne, Corporate IT Officer St. Lawrence Parks Commission 13740 County Road 2 Morrisburg, ON K0C 1X0 E-mail: Marc.Dufresne@parks.on.ca Voice: 613-543-3704 Ext#2455 Fax: 613-543-2847 Corporate website: www.parks.on.ca ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! [ Part 2, Text/PLAIN (Name: "Marc Dufresne.vcf") 20 lines. ] [ Unable to print this part. ] From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:31:25 2006 Subject: No subject Message-ID: :) Rob Morin Dido Internet Inc. Montreal, Canada 514-990-4444 http://www.dido.ca ----- Original Message ----- From: "Martin Hepworth" To: Sent: Wednesday, December 07, 2005 9:08 AM Subject: Re: Web site working? > Jules > > Another me too, but it to does take a while for the ipv6 to give up before > it tries for a ipv4. This happens (of course) only for the first lookup of > the day. > > Could be firewall/content restrictions at his end? > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > >> -----Original Message----- >> From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On >> Behalf Of Julian Field >> Sent: 07 December 2005 13:57 >> To: MAILSCANNER@JISCMAIL.AC.UK >> Subject: [MAILSCANNER] Web site working? >> >> -----BEGIN PGP SIGNED MESSAGE----- >> >> I'm getting reports from a journalist that although he can traceroute >> to www.mailscanner.info, his web browser cannot connect to it. >> Can someone check the website is visible and working please? >> - -- >> Julian Field >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> >> >> -----BEGIN PGP SIGNATURE----- >> Version: PGP Desktop 9.0.3 (Build 2932) >> >> iQEVAwUBQ5bqQ/w32o+k+q+hAQF4WQf/X5Lo5WjulNDTw5EBcM9BGDUde9xcHSm0 >> oskRqLjhu7YfAat8iDMRkedbsvg3CjG/Ch6NTQ7iJ7bo6mLuqOleGOOdwDxj5+rW >> GheJCw0rKVUyzQuXpBhuKrQ/j1CkEGEHXpcQAE/+n1un6uicZLFQspM1KmH5M3UJ >> /QNM1njbdExM5xKh2OM5YQrKIfPgLZmZmIvpuMzskUEufMcIcxJTw3Z3pRwKqz/x >> +Zu3PX3lf8k7iUZndOV5Yadj07sj0Fzi7X9bfJVHS5E7WShzPWPvqaf0HK8GWREQ >> CKa3mTpBKbaCphyTgl2kz/N9FK2ANLKcIr/7cHlY6rl20QCD4I6yog== >> =KN44 >> -----END PGP SIGNATURE----- >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> >> ------------------------ MailScanner list ------------------------ >> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >> 'leave mailscanner' in the body of the email. >> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >> >> Support MailScanner development - buy the book off the website! > > > ********************************************************************** > > This email and any files transmitted with it are confidential and > intended solely for the use of the individual or entity to whom they > are addressed. If you have received this email in error please notify > the system manager. > > This footnote confirms that this email message has been swept > for the presence of computer viruses and is believed to be clean. > > ********************************************************************** > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:31:29 2006 Subject: No subject Message-ID: Might be a php re-director that pulls from a bad location for you. -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:31:31 2006 Subject: No subject Message-ID: -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Aslan Carlos M. Ramos > Sent: 13 December 2005 13:24 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: [MAILSCANNER] SOPHOS MODULES SOPHOS-SAVI > > Hi Group, > > The Problem with the Perl Module for Antivirus Sophos are fixed or are > problems with the module? > > Some last versions I've problems to run the MailScanner w/ Sophos-Savi > (PerlModule), I like this module because it's more fast than the line > command with sweep. > > Thanks so Much. > > -- > Aslan Carlos M. Ramos > Aeon Technologies > (21) 2705 - 3139 > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:31:34 2006 Subject: No subject Message-ID: Would you add another comment line stating all the valid options. Thanks Brad ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Sun Jan 1 14:06:08 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:36 2006 Subject: MailScanner ANNOUNCE: Stable 4.49 released -- faster! Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Happy New Year to you all! I have just released the latest stable version of MailScanner, 4.49. This should be noticeably faster than previous releases. Noticeable changes are: - Speed improvements for sendmail, Postfix and Exim systems. - The output of "ps" now states what each MailScanner process is doing at the time so you can easily see any problems and it helps you monitor the state of your system. - New configuration options to make simple filename and filetype rules much easier to handle, especially when you want different filename/type restrictions for different people. The old system is still there, is still used, and works just as before. But now with the extra new "Allow Filenames", "Deny Filenames", "Accept Filetypes", "Deny Filetypes" configuration options you can easily write conventional rulesets to control these features. These are applied before the filename.rules.conf and filetype.rules.conf files. The order is "Accept" then "Deny" then file{name,type}.rules.conf. Download as usual from www.mailscanner.info. The full Change Log is this: * New Features and Improvements * - Speed improvements for sendmail systems by changing the way temporary files are handled and how attachments are parsed. This should be really noticeable if I've got it right. Thanks for the great help of the Vodafone SHARK team. - Added speed improvements for Exim. - Added speed improvements for Postfix. - Now changes the command line listed in `ps` (ie $0) to show what MailScanner is doing. Should help diagnose slow system problems. - 4 new configuration options, which list patterns against which filenames and filetypes are matched to see if we should allow them or block them. This is implemented for the benefit of web-based configuration systems for MailScanner, it is not really intended for human use as it will complicate the filename/filetype matching unless you understand it. Read the comments in the MailScanner.conf and suggest better explanations! "Allow Filenames", "Deny Filenames", "Allow Filetypes", "Deny Filetypes". Note: There are 2 new entries in languages.conf so remember to run an upgrade_languages_conf. - Upgraded tnef program to 1.3.4. - Added message 'actions' property for MailWatch reporting. - Custom Function filenames must end in .pm or .pl. Others will be logged and skipped. - Various minor speed improvements. * Fixes * - Changed Postfix code to better support latest revision of Perl. - Now stops MailScanner more reliably on SuSE systems. - Logging of tags only done if logging HTML tags. - Fixed minor array ref problem in Perl 5.8.7 on FreeBSD 6.0 (which is not a public stable release anyway). -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dl6mpg at GMAIL.COM Sun Jan 1 15:19:45 2006 From: dl6mpg at GMAIL.COM (Uwe) Date: Thu Jan 12 21:31:36 2006 Subject: Script check_mailscanner.linux broken in 4.49.7 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Hi, every 20 minutes i check MailScanner with check_mailscanner.linux via crontab. But for the script the output of "ps axww" must be like this : 8305 ? S 0:00 /usr/bin/perl -I/opt/MailScanner/lib /opt/MailScanner/bin/MailScanner /opt/MailScanner/etc/MailScanner.conf (Output of ps axww Version 4.48.4) Here ist the Output of MS Version 4.49.7 : 7456 ? S 0:00 MailScanner: master waiting for children, sleeping 7457 ? S 0:11 MailScanner: waiting for messages 7463 ? S 0:11 MailScanner: waiting for messages 7614 ? S 0:00 MailScanner: master waiting for children, sleeping 7617 ? S 0:11 MailScanner: waiting for messages 7657 ? S 0:11 MailScanner: waiting for messages 7807 ? S 0:00 MailScanner: master waiting for children, sleeping 7808 ? S 0:11 MailScanner: waiting for messages 7816 ? S 0:00 MailScanner: master waiting for children, sleeping 7817 ? S 0:11 MailScanner: waiting for messages 7819 ? S 0:11 MailScanner: waiting for messages 7825 ? S 0:11 MailScanner: waiting for messages The script looks fo the binary path ... btw, HNY ! Uwe ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Sun Jan 1 15:28:28 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:36 2006 Subject: Script check_mailscanner.linux broken in 4.49.7 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Have you tried just using the "check_mailscanner" script? (Often called check_MailScanner) I must get around to removing check_mailscanner.linux, it shouldn't really be in there now. Uwe wrote: >Hi, > >every 20 minutes i check MailScanner with check_mailscanner.linux via crontab. > >But for the script the output of "ps axww" must be like this : > >8305 ? S 0:00 /usr/bin/perl -I/opt/MailScanner/lib >/opt/MailScanner/bin/MailScanner /opt/MailScanner/etc/MailScanner.conf > >(Output of ps axww Version 4.48.4) > >Here ist the Output of MS Version 4.49.7 : > > 7456 ? S 0:00 MailScanner: master waiting for children, sleeping > 7457 ? S 0:11 MailScanner: waiting for messages > 7463 ? S 0:11 MailScanner: waiting for messages > 7614 ? S 0:00 MailScanner: master waiting for children, sleeping > 7617 ? S 0:11 MailScanner: waiting for messages > 7657 ? S 0:11 MailScanner: waiting for messages > 7807 ? S 0:00 MailScanner: master waiting for children, sleeping > 7808 ? S 0:11 MailScanner: waiting for messages > 7816 ? S 0:00 MailScanner: master waiting for children, sleeping > 7817 ? S 0:11 MailScanner: waiting for messages > 7819 ? S 0:11 MailScanner: waiting for messages > 7825 ? S 0:11 MailScanner: waiting for messages > >The script looks fo the binary path ... > >btw, HNY ! > > >Uwe > >------------------------ MailScanner list ------------------------ >To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >'leave mailscanner' in the body of the email. >Before posting, read the Wiki (http://wiki.mailscanner.info/) and >the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > >Support MailScanner development - buy the book off the website! > > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dl6mpg at GMAIL.COM Sun Jan 1 15:45:09 2006 From: dl6mpg at GMAIL.COM (Uwe) Date: Thu Jan 12 21:31:36 2006 Subject: Script check_mailscanner.linux broken in 4.49.7 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] 2006/1/1, Julian Field : > Have you tried just using the "check_mailscanner" script? (Often called > check_MailScanner) I must get around to removing > check_mailscanner.linux, it shouldn't really be in there now. Thank´s, check_MailScanner works fine here ! Uwe ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Sun Jan 1 17:11:23 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:36 2006 Subject: Mac OSX programmers? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Are there any Mac programmers out there? What I would like to do is build a Mac version of MailScanner. Basically all I'm after at the moment is 1) Easy to install (dpkg) 2) System Prefs item for it just giving the ability to start and stop it, and monitor maillog 3) Automatically starts on boot 4) Integrates itself into the Postfix(?) MTA queues already there I would prefer it all in Perl, probably using XCode and CamelBones unless anyone has better suggestions. Once someone can get me started, I can then take it and expand it gradually to do more. I'm just stuck on getting started with this project. Can anyone offer any help please? Thanks folks! -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From spamtrap71892316634 at ANIME.NET Sun Jan 1 17:53:47 2006 From: spamtrap71892316634 at ANIME.NET (Dan Hollis) Date: Thu Jan 12 21:31:36 2006 Subject: Mac OSX programmers? Message-ID: On Sun, 1 Jan 2006, Julian Field wrote: > I would prefer it all in Perl, probably using XCode and CamelBones unless > anyone has better suggestions. From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:31:36 2006 Subject: No subject Message-ID: want to use xcode. Keeping it real just using stock perl, makefiles or scons, and using packagemaker/hdiutil is my preferred method. Not that i'm offering to write it of course ;) -Dan ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From glenn.steen at GMAIL.COM Sun Jan 1 22:42:39 2006 From: glenn.steen at GMAIL.COM (Glenn Steen) Date: Thu Jan 12 21:31:36 2006 Subject: OT: Happy New Year! Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 31/12/05, Drew Marshall wrote: > On 30 Dec 2005, at 20:29, Glenn Steen wrote: > > > ... to all of you who recognize december 31 as the final day of the > > "old" year... Well, I'm a bit early, but in the timetested traditional > > swedish way... I'm headed straight into the usual alcohol-induced > > mists... Will probably not be able to email anything before sometime > > in january:-) > > > > Also would like to extend a special thanks to Jules and Steve > > (Freegard). Keep up the fantastic work another year guys! > > > > Anyway, have a good one! > > Cheers > > Have a good one yourself Glenn and to everyone else out there in > 'MailScanner land' :-) > > May 2006 bring spam and infection free inboxes (But not so clear that > Jules' commercial adventure doesn't achieve the success it deserves) > > Drew > Well, the year could've ended in a more .... fortuitous way for me.... Spent three hours at the ER getting my leg into a cast... Sigh. Grown men should know better than to borrow the kids bobsleigh (Amazingly enough, not a whole lot of alcohol had been ingested beforehand:-):-). Oh well. Hope you all fared better;). -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From doc at MADDOC.NET Mon Jan 2 03:19:09 2006 From: doc at MADDOC.NET (Doc Schneider) Date: Thu Jan 12 21:31:36 2006 Subject: OT: Happy New Year! Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Glenn Steen wrote: > On 31/12/05, Drew Marshall wrote: >> On 30 Dec 2005, at 20:29, Glenn Steen wrote: >> >>> ... to all of you who recognize december 31 as the final day of the >>> "old" year... Well, I'm a bit early, but in the timetested traditional >>> swedish way... I'm headed straight into the usual alcohol-induced >>> mists... Will probably not be able to email anything before sometime >>> in january:-) >>> >>> Also would like to extend a special thanks to Jules and Steve >>> (Freegard). Keep up the fantastic work another year guys! >>> >>> Anyway, have a good one! >>> Cheers >> Have a good one yourself Glenn and to everyone else out there in >> 'MailScanner land' :-) >> >> May 2006 bring spam and infection free inboxes (But not so clear that >> Jules' commercial adventure doesn't achieve the success it deserves) >> >> Drew >> > > Well, the year could've ended in a more .... fortuitous way for me.... > Spent three hours at the ER getting my leg into a cast... Sigh. Grown > men should know better than to borrow the kids bobsleigh (Amazingly > enough, not a whole lot of alcohol had been ingested beforehand:-):-). > Oh well. Hope you all fared better;). > > -- Glenn, Just be glad it was only your leg... my wife has a friend who did something almost exactly like this and is now in a wheelchair--she broke her neck! (This happened a few years ago and no alcohol was involved) Hope the rest of this year goes well for the rest of the list folks. (Now to download the latest and greatest and see about getting my MailScanner upgraded. -- -Doc Lincoln, NE. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mailscanner at BARENDSE.TO Mon Jan 2 03:46:11 2006 From: mailscanner at BARENDSE.TO (Remco Barendse) Date: Thu Jan 12 21:31:36 2006 Subject: upgrade_languages_conf broken and updating languages questions? Message-ID: Hi list! Just a small remark, for some releases already upgrade_languages_conf doesn't seem to be working for the RPM install, see the output below. Are there any upgrade scripts that provide a quick and easy way to get rid of all the .rpmnew files for all the languages and just replace the old versions? Also if somebody knows of a way to do some sort of grepping and deleting the 'MS thanks transtec' etc. lines from the various reports through a script that would be really neat :) For the error, when I change to the reports/en directory and run upgrade_languages_conf I get this: [root@gw en]# upgrade_languages_conf languages.conf languages.conf.rpmnew > languages.new Usage: RPM === If you are using the RPM distributions then try this: cd /etc/MailScanner/reports/en upgrade_languages_conf languages.conf languages.conf.rpmnew > languages.new mv -f languages.conf languages.old mv -f languages.new languages.conf TAR === If you are using the tar distribution so that the old version is in /opt/MailScanner and the new one is in /opt/MailScanner.new then: cd /opt/MailScanner.new/etc/reports/en ../../../bin/upgrade_languages_conf /opt/MailScanner/etc/reports/en/languages.conf /opt/MailScanner.new/etc/reports/en/languages.conf > languages.new mv -f languages.conf languages.old mv -f languages.new languages.conf NOTE ==== To keep your old comments in your original file, add "--keep-comments" to the command line. Note that this will mean you don't get to find out any extra new values you might be able to use in existing "improved" configuration options. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dh at UPTIME.AT Mon Jan 2 14:17:28 2006 From: dh at UPTIME.AT (David H.) Date: Thu Jan 12 21:31:36 2006 Subject: Mac OSX programmers? Message-ID: [ The following text is in the "UTF-8" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Julian Field wrote: > Are there any Mac programmers out there? > > What I would like to do is build a Mac version of MailScanner. Basically > all I'm after at the moment is > 1) Easy to install (dpkg) > 2) System Prefs item for it just giving the ability to start and stop > it, and monitor maillog > 3) Automatically starts on boot > 4) Integrates itself into the Postfix(?) MTA queues already there > Well, with some convincing you might get someone to make you a Fink package (fink.sf.net) which is the most popular package manager for Unix based apps and ports for Mac os x (I shoudl know I am on a mac and I worked a long time for them) -d ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Mon Jan 2 14:48:01 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:37 2006 Subject: upgrade_languages_conf broken and updating languages questions? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Does upgrade_MailScanner_conf work okay for you? Remco Barendse wrote: > Hi list! > > Just a small remark, for some releases already upgrade_languages_conf > doesn't seem to be working for the RPM install, see the output below. > > Are there any upgrade scripts that provide a quick and easy way to get > rid of all the .rpmnew files for all the languages and just replace > the old versions? > > Also if somebody knows of a way to do some sort of grepping and > deleting the 'MS thanks transtec' etc. lines from the various reports > through a script that would be really neat :) > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mailscanner at BARENDSE.TO Mon Jan 2 15:43:48 2006 From: mailscanner at BARENDSE.TO (Remco Barendse) Date: Thu Jan 12 21:31:37 2006 Subject: upgrade_languages_conf broken and updating languages questions? Message-ID: > Does upgrade_MailScanner_conf work okay for you? Yes, flawlessly :) I just copy & paste the whole buch of lines and everything is upgraded automagically ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Mon Jan 2 15:55:11 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:37 2006 Subject: upgrade_languages_conf broken and updating languages questions? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] That's interesting, because upgrade_MailScanner_conf and upgrade_languages_conf are the same script! # ls -l /usr/sbin/upgrade_languages_conf lrwxrwxrwx 1 root root 24 Nov 26 12:42 /usr/sbin/upgrade_languages_conf -> upgrade_MailScanner_conf Something's wrong with how you entered the command, or one of the files was missing or similar. Remco Barendse wrote: >> Does upgrade_MailScanner_conf work okay for you? > > > Yes, flawlessly :) > > > I just copy & paste the whole buch of lines and everything is upgraded > automagically > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From jaearick at COLBY.EDU Mon Jan 2 16:04:45 2006 From: jaearick at COLBY.EDU (Jeff A. Earickson) Date: Thu Jan 12 21:31:37 2006 Subject: 4.49.7 microbug in filename.rules.conf Message-ID: Julian, I uncommented line 14 (the wmf line) in filename.rules.conf, and 4.49.7 complained about a syntax error at startup. I realized the fourth argument of the line was missing and added it (with a tab in there). Happy after that. Jeff Earickson Colby College ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ard at pergamentum.com Mon Jan 2 16:44:10 2006 From: ard at pergamentum.com (Alisdair Davey) Date: Thu Jan 12 21:31:37 2006 Subject: upgrade_languages_conf broken and updating languages questions? Message-ID: On Mon, 2006-01-02 at 15:55 +0000, Julian Field wrote: > That's interesting, because upgrade_MailScanner_conf and > upgrade_languages_conf are the same script! > > # ls -l /usr/sbin/upgrade_languages_conf > lrwxrwxrwx 1 root root 24 Nov 26 12:42 /usr/sbin/upgrade_languages_conf > -> upgrade_MailScanner_conf > > Something's wrong with how you entered the command, or one of the files > was missing or similar. > > Remco Barendse wrote: > > >> Does upgrade_MailScanner_conf work okay for you? I have had exactly the same problem on 3 different installation of 4.48.4 (and yes upgrade_MailScanner_conf works flawlessly). In each case there does not seem to be a languages.conf.rpmnew file (from the rpm install.) Cheers Alisdair ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From lhaig at HAIGMAIL.COM Mon Jan 2 17:58:15 2006 From: lhaig at HAIGMAIL.COM (Lance Haig) Date: Thu Jan 12 21:31:37 2006 Subject: Mailscanner on Freebsd Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] I am looking at installing MS on a freebsd 6 system. Has anyone done this before? How does it compare with Suse or Redhat with regards to management. Thanks Lance ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Mon Jan 2 17:30:48 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:37 2006 Subject: upgrade_languages_conf broken and updating languages questions? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Alisdair Davey wrote: >On Mon, 2006-01-02 at 15:55 +0000, Julian Field wrote: > > >>That's interesting, because upgrade_MailScanner_conf and >>upgrade_languages_conf are the same script! >> >># ls -l /usr/sbin/upgrade_languages_conf >>lrwxrwxrwx 1 root root 24 Nov 26 12:42 /usr/sbin/upgrade_languages_conf >>-> upgrade_MailScanner_conf >> >>Something's wrong with how you entered the command, or one of the files >>was missing or similar. >> >>Remco Barendse wrote: >> >> >> >>>>Does upgrade_MailScanner_conf work okay for you? >>>> >>>> > >I have had exactly the same problem on 3 different installation of >4.48.4 (and yes upgrade_MailScanner_conf works flawlessly). In each case >there does not seem to be a languages.conf.rpmnew file (from the rpm >install.) > If there haven't been any changes to it (which there haven't) then it won't bother creating the .rpmnew as you don't need it. So just ignore it as you don't need to upgrade that file. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Mon Jan 2 18:10:42 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:37 2006 Subject: Mailscanner on Freebsd Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Use the "port". cd /usr/ports make install name=mailscanner Once you've done all that, I've got a little list of things you have to do extra, as I've just done this myself. I hope you're not using this in production, freebsd 6 isn't finished yet! Lance Haig wrote: > I am looking at installing MS on a freebsd 6 system. > > Has anyone done this before? > How does it compare with Suse or Redhat with regards to management. > > Thanks > > Lance > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From lhaig at HAIGMAIL.COM Mon Jan 2 18:33:45 2006 From: lhaig at HAIGMAIL.COM (Lance Haig) Date: Thu Jan 12 21:31:37 2006 Subject: Mailscanner on Freebsd Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Hi Julian, I have just looked on their website and it says 6 is a production release. Does that mean it is unstable? Where can I find the documentation for installing MS on Freebsd. I have seen the document on http://www.sng.ecs.soton.ac.uk/mailscanner/FreeBSD.html Are there other documents ? Thanks Lance Julian Field wrote: Use the "port". cd /usr/ports make install name=mailscanner Once you've done all that, I've got a little list of things you have to do extra, as I've just done this myself. I hope you're not using this in production, freebsd 6 isn't finished yet! Lance Haig wrote: I am looking at installing MS on a freebsd 6 system. Has anyone done this before? How does it compare with Suse or Redhat with regards to management. Thanks Lance ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Mon Jan 2 18:45:31 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:37 2006 Subject: Mailscanner on Freebsd Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Need to install Mail::SPF::Query Install the following: make install name=clamav make install name=p5-Mail-ClamAV make install name=p5-DBI make install name=p5-Net-Ident You need to make all the queue directories by hand and rename all the silly .sample files freebsd seems to use, which just makes life harder for you. Start by getting the modules installed. /usr/local/libexec/MailScanner/MailScanner -v shoulud produce everything installed except Mail::ClamAV, Net::LDAP and SAVI, they aren't needed. Then hunt /usr/local for every ".sample" file and rename them so they don't end in that. mkdir -p /var/spool/MailScanner/incoming mkdir /var/spool/MailScanner/quarantine That should be enough to get you started. If you could document what you do and add it to the wiki at wiki.mailscanner.info that would be *REALLY* helpful for other people. Lance Haig wrote: > Hi Julian, > > I have just looked on their website and it says 6 is a production release. > > Does that mean it is unstable? > > Where can I find the documentation for installing MS on Freebsd. > > I have seen the document on > http://www.sng.ecs.soton.ac.uk/*mailscanner*/FreeBSD.html > > Are there other documents ? > > Thanks > > Lance > > Julian Field wrote: > >> Use the "port". >> cd /usr/ports >> make install name=mailscanner >> >> Once you've done all that, I've got a little list of things you have >> to do extra, as I've just done this myself. >> I hope you're not using this in production, freebsd 6 isn't finished >> yet! >> >> Lance Haig wrote: >> >>> I am looking at installing MS on a freebsd 6 system. >>> >>> Has anyone done this before? >>> How does it compare with Suse or Redhat with regards to management. >>> >>> Thanks >>> >>> Lance >>> >>> ------------------------ MailScanner list ------------------------ >>> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >>> 'leave mailscanner' in the body of the email. >>> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >>> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >>> >>> Support MailScanner development - buy the book off the website! >> >> >> > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) > and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > *Support MailScanner development - buy the book off the website!* -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From hermit921 at YAHOO.COM Mon Jan 2 19:03:48 2006 From: hermit921 at YAHOO.COM (hermit921) Date: Thu Jan 12 21:31:37 2006 Subject: phishing from same domain? Message-ID: Count me in as wanting this, too. hermit At 04:40 PM 12/28/2005, Ken A wrote: >I'd like it if MailScanner had an option so it would decide something was >phishing ONLY if the domain name didn't match, but ignore the hostname. >This assumes that most people can control hosts within their own domain, >but I think it would be a nice option. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From kevins at BMRB.CO.UK Mon Jan 2 19:01:55 2006 From: kevins at BMRB.CO.UK (Kevin Spicer) Date: Thu Jan 12 21:31:37 2006 Subject: WMF Exploit Message-ID: On Fri, 2005-12-30 at 10:06 +0000, Randal, Phil wrote: > My head hurts after reading this :-) > > http://www.skynet.ie/~caolan/publink/libwmf/libwmf/doc/ora-wmf.html > Damn, so my 'file' rule only matches one type of wmf file and not the one used in the public exploit. Thats unfortunate to say the least. It also seems from SANS that there is a new harder to detect version of the exploit about http://isc.sans.org/diary.php?date=2006-01-01 Not looking forward to tomorrow when everyone goes back to work... ================================================================= BMRB wins two BMRA awards - http://www.bmrb.co.uk _________________________________________________________________ This message (and any attachment) is intended only for the recipient and may contain confidential and/or privileged material. If you have received this in error, please contact the sender and delete this message immediately. Disclosure, copying or other action taken in respect of this email or in reliance on it is prohibited. BMRB Limited accepts no liability in relation to any personal emails, or content of any email which does not directly relate to our business. +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From lhaig at HAIGMAIL.COM Mon Jan 2 18:58:40 2006 From: lhaig at HAIGMAIL.COM (Lance Haig) Date: Thu Jan 12 21:31:37 2006 Subject: Mailscanner on Freebsd Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Will do sir :-) I will try as soon as I can find a spare machine. ( need to test it before I go live) Ta Lance Julian Field wrote: > Need to install Mail::SPF::Query > > Install the following: > make install name=clamav > make install name=p5-Mail-ClamAV > make install name=p5-DBI > make install name=p5-Net-Ident > > You need to make all the queue directories by hand and rename all the > silly .sample files freebsd seems to use, which just makes life harder > for you. > > Start by getting the modules installed. > /usr/local/libexec/MailScanner/MailScanner -v > shoulud produce everything installed except Mail::ClamAV, Net::LDAP > and SAVI, they aren't needed. > Then hunt /usr/local for every ".sample" file and rename them so they > don't end in that. > mkdir -p /var/spool/MailScanner/incoming > mkdir /var/spool/MailScanner/quarantine > > That should be enough to get you started. > > If you could document what you do and add it to the wiki at > wiki.mailscanner.info that would be *REALLY* helpful for other people. > > > Lance Haig wrote: > >> Hi Julian, >> >> I have just looked on their website and it says 6 is a production >> release. >> >> Does that mean it is unstable? >> >> Where can I find the documentation for installing MS on Freebsd. >> >> I have seen the document on >> http://www.sng.ecs.soton.ac.uk/*mailscanner*/FreeBSD.html >> >> Are there other documents ? >> >> Thanks >> >> Lance >> >> Julian Field wrote: >> >>> Use the "port". >>> cd /usr/ports >>> make install name=mailscanner >>> >>> Once you've done all that, I've got a little list of things you have >>> to do extra, as I've just done this myself. >>> I hope you're not using this in production, freebsd 6 isn't finished >>> yet! >>> >>> Lance Haig wrote: >>> >>>> I am looking at installing MS on a freebsd 6 system. >>>> >>>> Has anyone done this before? >>>> How does it compare with Suse or Redhat with regards to management. >>>> >>>> Thanks >>>> >>>> Lance >>>> >>>> ------------------------ MailScanner list ------------------------ >>>> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >>>> 'leave mailscanner' in the body of the email. >>>> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >>>> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >>>> >>>> Support MailScanner development - buy the book off the website! >>> >>> >>> >> >> ------------------------ MailScanner list ------------------------ >> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >> 'leave mailscanner' in the body of the email. >> Before posting, read the Wiki (http://wiki.mailscanner.info/) >> and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >> >> *Support MailScanner development - buy the book off the website!* > > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From martinh at SOLID-STATE-LOGIC.COM Mon Jan 2 19:39:22 2006 From: martinh at SOLID-STATE-LOGIC.COM (Martin Hepworth) Date: Thu Jan 12 21:31:37 2006 Subject: Mailscanner on Freebsd Message-ID: Jules FreeBSD is never finished ;-), but 6 is now the stable version...and hopefully better then 5.x in SMP systems.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Julian Field > Sent: 02 January 2006 18:11 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: [MAILSCANNER] Mailscanner on Freebsd > > Use the "port". > cd /usr/ports > make install name=mailscanner > > Once you've done all that, I've got a little list of things you have to > do extra, as I've just done this myself. > I hope you're not using this in production, freebsd 6 isn't finished yet! > > Lance Haig wrote: > > > I am looking at installing MS on a freebsd 6 system. > > > > Has anyone done this before? > > How does it compare with Suse or Redhat with regards to management. > > > > Thanks > > > > Lance > > > > ------------------------ MailScanner list ------------------------ > > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > > 'leave mailscanner' in the body of the email. > > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > > > Support MailScanner development - buy the book off the website! > > > -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > Professional Support Services at www.MailScanner.biz > MailScanner thanks transtec Computers for their support > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From brent.bolin at GMAIL.COM Mon Jan 2 20:28:08 2006 From: brent.bolin at GMAIL.COM (BB) Date: Thu Jan 12 21:31:37 2006 Subject: Mailscanner on Freebsd Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] After the mailscanner install it gives a brief message to make the install complete. Something like - make config Don't recall exactly but you will see it. It copes all the sample filename extensions to the usable ones. I have not installed mailscanner on 6.x . Haven't heard of any problems on 6.x Use the standard cvsup so your not running on the bleeding edge. On 1/2/06, Julian Field wrote: Need to install Mail::SPF::Query Install the following: make install name=clamav make install name=p5-Mail-ClamAV make install name=p5-DBI make install name=p5-Net-Ident You need to make all the queue directories by hand and rename all the silly .sample files freebsd seems to use, which just makes life harder for you. Start by getting the modules installed. /usr/local/libexec/MailScanner/MailScanner -v shoulud produce everything installed except Mail::ClamAV, Net::LDAP and SAVI, they aren't needed. Then hunt /usr/local for every ".sample" file and rename them so they don't end in that. mkdir -p /var/spool/MailScanner/incoming mkdir /var/spool/MailScanner/quarantine That should be enough to get you started. If you could document what you do and add it to the wiki at wiki.mailscanner.info that would be *REALLY* helpful for other people. Lance Haig wrote: > Hi Julian, > > I have just looked on their website and it says 6 is a production release. > > Does that mean it is unstable? > > Where can I find the documentation for installing MS on Freebsd. > > I have seen the document on > http://www.sng.ecs.soton.ac.uk/*mailscanner*/FreeBSD.html > > Are there other documents ? > > Thanks > > Lance > > Julian Field wrote: > >> Use the "port". >> cd /usr/ports >> make install name=mailscanner >> >> Once you've done all that, I've got a little list of things you have >> to do extra, as I've just done this myself. >> I hope you're not using this in production, freebsd 6 isn't finished >> yet! >> >> Lance Haig wrote: >> >>> I am looking at installing MS on a freebsd 6 system. >>> >>> Has anyone done this before? >>> How does it compare with Suse or Redhat with regards to management. >>> >>> Thanks >>> >>> Lance >>> >>> ------------------------ MailScanner list ------------------------ >>> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >>> 'leave mailscanner' in the body of the email. >>> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >>> the archives ( http://www.jiscmail.ac.uk/lists/mailscanner.html). >>> >>> Support MailScanner development - buy the book off the website! >> >> >> > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki ( http://wiki.mailscanner.info/) > and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > *Support MailScanner development - buy the book off the website!* -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives ( http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From drew at THEMARSHALLS.CO.UK Mon Jan 2 20:43:49 2006 From: drew at THEMARSHALLS.CO.UK (Drew Marshall) Date: Thu Jan 12 21:31:37 2006 Subject: Mailscanner on Freebsd Message-ID: On 2 Jan 2006, at 18:45, Julian Field wrote: > Need to install Mail::SPF::Query > > Install the following: > make install name=clamav > make install name=p5-Mail-ClamAV > make install name=p5-DBI > make install name=p5-Net-Ident > > You need to make all the queue directories by hand and rename all > the silly .sample files freebsd seems to use, which just makes life > harder for you. > > Start by getting the modules installed. > /usr/local/libexec/MailScanner/MailScanner -v > shoulud produce everything installed except Mail::ClamAV, Net::LDAP > and SAVI, they aren't needed. > Then hunt /usr/local for every ".sample" file and rename them so > they don't end in that. > mkdir -p /var/spool/MailScanner/incoming > mkdir /var/spool/MailScanner/quarantine > > That should be enough to get you started. > > If you could document what you do and add it to the wiki at > wiki.mailscanner.info that would be *REALLY* helpful for other people. I have MailScanner running on FreeBSD 6 boxes with out problem. As I understand (From the FBSD site) 6 is the current production release. They regard everything else as 'legacy'. The 'silly' .sample files are there to stop any existing files being automatically over written when the port is updated but if you make sure you don't run make clean after installation, JP has kindly added a load of text that describes how to rename the .sample files to working copies (For the reports, and auto update scripts and the wrapper scripts and a MailScanner.conf if this is a new install). If you have MS running on another machine with a MailScanner.conf file you would like to use, just drop a copy in to /usr/local/etc/ MailScanner (Make this) before you run the port installation and you will find the port install will upgrade your MailScanner.conf automatically as well. In this same directory you will find some more .sample files, which you can either remove the .sample ending if you don't have copies or diff them if this is an upgrade (Hence them being installed as .sample) and delete them if not required. You will need to make the queue files as the port doesn't know which MTA you will be using and you will also need to rename the start up scripts in /usr/local/etc/rc.d, where you will also find a start up called mta.sh.sample which you can use to start your Exim or Sendmail MTA. HTH Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Mon Jan 2 20:58:36 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:37 2006 Subject: Mailscanner on Freebsd Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] BB wrote: > After the mailscanner install it gives a brief message to make the > install complete. > > Something like - > > make config > > Don't recall exactly but you will see it. It copes all the sample > filename extensions to the usable ones. Ah! Missed that. Ended up doing it by hand which was pretty time-consuming. > > On 1/2/06, * Julian Field* > wrote: > > Need to install Mail::SPF::Query > > Install the following: > make install name=clamav > make install name=p5-Mail-ClamAV > make install name=p5-DBI > make install name=p5-Net-Ident > > You need to make all the queue directories by hand and rename all the > silly .sample files freebsd seems to use, which just makes life harder > for you. > > Start by getting the modules installed. > /usr/local/libexec/MailScanner/MailScanner -v > shoulud produce everything installed except Mail::ClamAV, > Net::LDAP and > SAVI, they aren't needed. > Then hunt /usr/local for every ".sample" file and rename them so they > don't end in that. > mkdir -p /var/spool/MailScanner/incoming > mkdir /var/spool/MailScanner/quarantine > > That should be enough to get you started. > > If you could document what you do and add it to the wiki at > wiki.mailscanner.info that would be > *REALLY* helpful for other people. > > > Lance Haig wrote: > > > Hi Julian, > > > > I have just looked on their website and it says 6 is a > production release. > > > > Does that mean it is unstable? > > > > Where can I find the documentation for installing MS on Freebsd. > > > > I have seen the document on > > http://www.sng.ecs.soton.ac.uk/*mailscanner*/FreeBSD.html > > > > Are there other documents ? > > > > Thanks > > > > Lance > > > > Julian Field wrote: > > > >> Use the "port". > >> cd /usr/ports > >> make install name=mailscanner > >> > >> Once you've done all that, I've got a little list of things you > have > >> to do extra, as I've just done this myself. > >> I hope you're not using this in production, freebsd 6 isn't > finished > >> yet! > >> > >> Lance Haig wrote: > >> > >>> I am looking at installing MS on a freebsd 6 system. > >>> > >>> Has anyone done this before? > >>> How does it compare with Suse or Redhat with regards to > management. > >>> > >>> Thanks > >>> > >>> Lance > >>> > >>> ------------------------ MailScanner list ------------------------ > >>> To unsubscribe, email jiscmail@jiscmail.ac.uk > with the words: > >>> 'leave mailscanner' in the body of the email. > >>> Before posting, read the Wiki (http://wiki.mailscanner.info/) and > >>> the archives ( http://www.jiscmail.ac.uk/lists/mailscanner.html). > >>> > >>> Support MailScanner development - buy the book off the website! > >> > >> > >> > > > > ------------------------ MailScanner list ------------------------ > > To unsubscribe, email jiscmail@jiscmail.ac.uk > with the words: > > 'leave mailscanner' in the body of the email. > > Before posting, read the Wiki ( http://wiki.mailscanner.info/) > > and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > > > *Support MailScanner development - buy the book off the website!* > > > -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > Professional Support Services at www.MailScanner.biz > > MailScanner thanks transtec Computers for their support > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk > with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives ( http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) > and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > *Support MailScanner development - buy the book off the website!* -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Mon Jan 2 21:21:56 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:37 2006 Subject: Mailscanner on Freebsd Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Sorry, didn't mean to insult the FreeBSD community. I didn't look hard enough for instructions on how to use the port, so misunderstood the way things are done on that platform. I'm a bit off a *BSD newbie and should have watched my words rather more carefully. Sorry about that, now I understand the how and why. Jules. P.S. Been testing some code today which should give you a nice surprise when it is released. It relies on the stupidity of bad people, and appears to work well so far :-) Drew Marshall wrote: > On 2 Jan 2006, at 18:45, Julian Field wrote: > >> Need to install Mail::SPF::Query >> >> Install the following: >> make install name=clamav >> make install name=p5-Mail-ClamAV >> make install name=p5-DBI >> make install name=p5-Net-Ident >> >> You need to make all the queue directories by hand and rename all >> the silly .sample files freebsd seems to use, which just makes life >> harder for you. >> >> Start by getting the modules installed. >> /usr/local/libexec/MailScanner/MailScanner -v >> shoulud produce everything installed except Mail::ClamAV, Net::LDAP >> and SAVI, they aren't needed. >> Then hunt /usr/local for every ".sample" file and rename them so >> they don't end in that. >> mkdir -p /var/spool/MailScanner/incoming >> mkdir /var/spool/MailScanner/quarantine >> >> That should be enough to get you started. >> >> If you could document what you do and add it to the wiki at >> wiki.mailscanner.info that would be *REALLY* helpful for other people. > > > I have MailScanner running on FreeBSD 6 boxes with out problem. As I > understand (From the FBSD site) 6 is the current production release. > They regard everything else as 'legacy'. > > The 'silly' .sample files are there to stop any existing files being > automatically over written when the port is updated but if you make > sure you don't run make clean after installation, JP has kindly added > a load of text that describes how to rename the .sample files to > working copies (For the reports, and auto update scripts and the > wrapper scripts and a MailScanner.conf if this is a new install). If > you have MS running on another machine with a MailScanner.conf file > you would like to use, just drop a copy in to /usr/local/etc/ > MailScanner (Make this) before you run the port installation and you > will find the port install will upgrade your MailScanner.conf > automatically as well. In this same directory you will find some more > .sample files, which you can either remove the .sample ending if you > don't have copies or diff them if this is an upgrade (Hence them > being installed as .sample) and delete them if not required. > > You will need to make the queue files as the port doesn't know which > MTA you will be using and you will also need to rename the start up > scripts in /usr/local/etc/rc.d, where you will also find a start up > called mta.sh.sample which you can use to start your Exim or Sendmail > MTA. > > HTH > > Drew > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From brent.bolin at GMAIL.COM Mon Jan 2 22:38:30 2006 From: brent.bolin at GMAIL.COM (BB) Date: Thu Jan 12 21:31:37 2006 Subject: Mailscanner on Freebsd Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Once you understand BSD you have a hard time going back.. It's complete and well documented. Yes I do use Linux. Debian, Fedora etc... Humm let the distro just put anything anywhere depending on the distro. Very confusing. Now if I can just finger out Mac osx, Darwin and fink. Never a dull moment. Julian, spend your time on MailScanner your very good at it. Cheers...btb On 1/2/06, Julian Field wrote: Sorry, didn't mean to insult the FreeBSD community. I didn't look hard enough for instructions on how to use the port, so misunderstood the way things are done on that platform. I'm a bit off a *BSD newbie and should have watched my words rather more carefully. Sorry about that, now I understand the how and why. Jules. P.S. Been testing some code today which should give you a nice surprise when it is released. It relies on the stupidity of bad people, and appears to work well so far :-) Drew Marshall wrote: > On 2 Jan 2006, at 18:45, Julian Field wrote: > >> Need to install Mail::SPF::Query >> >> Install the following: >> make install name=clamav >> make install name=p5-Mail-ClamAV >> make install name=p5-DBI >> make install name=p5-Net-Ident >> >> You need to make all the queue directories by hand and rename all >> the silly .sample files freebsd seems to use, which just makes life >> harder for you. >> >> Start by getting the modules installed. >> /usr/local/libexec/MailScanner/MailScanner -v >> shoulud produce everything installed except Mail::ClamAV, Net::LDAP >> and SAVI, they aren't needed. >> Then hunt /usr/local for every ".sample" file and rename them so >> they don't end in that. >> mkdir -p /var/spool/MailScanner/incoming >> mkdir /var/spool/MailScanner/quarantine >> >> That should be enough to get you started. >> >> If you could document what you do and add it to the wiki at >> wiki.mailscanner.info that would be *REALLY* helpful for other people. > > > I have MailScanner running on FreeBSD 6 boxes with out problem. As I > understand (From the FBSD site) 6 is the current production release. > They regard everything else as 'legacy'. > > The 'silly' .sample files are there to stop any existing files being > automatically over written when the port is updated but if you make > sure you don't run make clean after installation, JP has kindly added > a load of text that describes how to rename the .sample files to > working copies (For the reports, and auto update scripts and the > wrapper scripts and a MailScanner.conf if this is a new install). If > you have MS running on another machine with a MailScanner.conf file > you would like to use, just drop a copy in to /usr/local/etc/ > MailScanner (Make this) before you run the port installation and you > will find the port install will upgrade your MailScanner.conf > automatically as well. In this same directory you will find some more > .sample files, which you can either remove the .sample ending if you > don't have copies or diff them if this is an upgrade (Hence them > being installed as .sample) and delete them if not required. > > You will need to make the queue files as the port doesn't know which > MTA you will be using and you will also need to rename the start up > scripts in /usr/local/etc/rc.d, where you will also find a start up > called mta.sh.sample which you can use to start your Exim or Sendmail > MTA. > > HTH > > Drew > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki ( http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From raylund.lai at KANKANWOO.COM Tue Jan 3 01:26:51 2006 From: raylund.lai at KANKANWOO.COM (Raylund Lai) Date: Thu Jan 12 21:31:37 2006 Subject: Mailscanner on Freebsd Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Here are some of my notes/steps on installing MS on FreeBSD 6. I'm not having time to sort them out and some are not relevant to you (it's a mail gateway), but you could follow the logic in setting up. Cheers Raylund Free BSD 6 Installation 1. sysinstall Main Menu + Standard 2. Install Boot Manager for boot drive + Standard - Install a standard MBR (no boot manager) 3. Choose Distributions + [8] User o Install FreeBSD ports collection - No + [B] Custom o src o All 4. enable SSH login - Yes 5. enable Linux binary compatibility - No 6. browse the FreeBSD package collection - Yes + perl-5.8.7 7. add initial user account - No Installation of ports 1. cd /usr/ports/sysutils/webmin/ + make + make install + /usr/local/lib/webmin/setup.sh + cd /etc/ + cp rc.conf rc.conf.ORIG + vi rc.conf o add: webmin_enable="YES" o or echo 'webmin_enable="YES"' >> rc.conf 2. cd /usr/ports/mail/p5-Mail-ClamAV/ + make + make install 3. cd /usr/ports/mail/p5-Mail-Spamassassin/ + make o select AS_ROOT, RAZOR, SPF_QUERY only + make install 4. cd /usr/ports/security/f-prot/ + make + make install 5. install BitDefender + cd /usr/ports/distfiles/ + fetch -v ftp://ftp.bitdefender.com/pub/freebsd/5/final/bdc-7.0.1.2-fbsd5.tar.gz + cd /usr/ports/security/bdc/ + make + make install + vi rc.conf o add: compat5x_enable="YES" o or echo 'compat5x_enable="YES"' >> rc.conf 6. cd /usr/ports/misc/compat4x/ (somehow bdc needs compat4x instead of compat5x, may be fixed already) + make + make install + vi rc.conf o add: compat4x_enable="YES" o or echo 'compat4x_enable="YES"' >> rc.conf 7. cd /usr/ports/mail/mailscanner/ + make + make install + make initial-config 8. cd /usr/ports/sysutils/portupgrade/ + make + make install 9. reboot 10. pkgdb -F Configuration of sendmail 1. cd /etc/mail/ 2. cp freebsd.mc freebsd.mc.ORIG 3. cp access.sample access 4. cp mailertable.sample mailertable 5. vi freebsd.mc + add: FEATURE(`relay_hosts_only') + add: define(`confPRIVACY_FLAGS', `authwarnings, ..., nobodyreturn') + dnl FEATURE(blacklist_recipients) + dnl FEATURE(virtusertable,....) + dnl DAEMON_OPTIONS(`Name=IPv6,...) 6. m4 /usr/share/sendmail/cf/m4/cf.m4 freebsd.mc > sendmail.cf 7. vi mailertable + only entry is: yourdomain.com smtp:[192.168.0.1] 8. makemap hash mailertable < mailertable 9. vi access + only entry is: Connect:192.168.0.1 RELAY 10. makemap hash access < access 11. vi relay-domains + only entry is: yourdomain.com 12. cd /etc/ 13. vi rc.conf + add: sendmail_enable="NONE" + or echo 'sendmail_enable="NONE"' >> rc.conf Install milter-ahead 1. transfer downloaded files (www.SnertSoft.com) of LibSnert and milter-ahead to ~/tmp/ 2. cd ~/tmp/ 3. tar zxvf libsnert-1.48.tar.gz 4. tar zxvf milter-ahead-0.9.tar.gz 5. cd ~/tmp/com/snert/src/lib/ 6. ./configure --without-db 7. make build 8. cd ../milter-ahead 9. ./configure --without-db 10. make build 11. make install 12. modify /etc/mail/freebsd.mc accordingly Configuration of MailScanner 1. mkdir -p /var/spool/MailScanner/incoming/ 2. mkdir /var/spool/MailScanner/quarantine/ 3. mkdir /var/spool/mqueue.in/ 4. chgrp daemon /var/spool/MailScanner 5. chgrp daemon /var/spool/MailScanner/* 6. chgrp daemon /var/spool/mqueue.in 7. cd /usr/local/etc/rc.d 8. cp mta.sh.sample mta.sh 9. cp mailscanner.sh.sample mailscanner.sh 10. cd /usr/local/etc/MailScanner/mcp/ 11. cp mcp.spam.assassin.prefs.conf.sample mcp.spam.assassin.prefs.conf 12. mkdir /var/spool/spamassassin/ 13. chgrp daemon /var/spool/spamassassin 14. edit/create file bounce.rules to /usr/local/etc/MailScanner/rules/ 15. edit/create file notices.to.rules to /usr/local/etc/MailScanner/rules/ 16. edit/create file spam.checks.rules to /usr/local/etc/MailScanner/rules/ 17. edit/create file spam.header.rules to /usr/local/etc/MailScanner/rules/ 18. edit/create file virus.scanning.rules to /usr/local/etc/MailScanner/rules/ 19. edit /usr/local/etc/MailScanner/MailScanner.conf 20. edit /usr/local/etc/MailScanner/spam.assassin.prefs.conf 21. edit /usr/local/etc/MailScanner/virus.scanners.conf 22. edit /usr/local/libexec/MailScanner/bitdefender-autoupdate 23. edit /usr/local/libexec/MailScanner/f-prot-autoupdate 24. add cron job for update_virus_scanners every 15 minutes + crontab -e + 6,21,36,51 * * * * /usr/local/libexec/MailScanner/update_virus_scanners 25. transfer file bayes_backup /var/spool/spamassassin/ 26. restore bayes backup BB wrote: After the mailscanner install it gives a brief message to make the install complete. Something like - make config Don't recall exactly but you will see it. It copes all the sample filename extensions to the usable ones. I have not installed mailscanner on 6.x . Haven't heard of any problems on 6.x Use the standard cvsup so your not running on the bleeding edge. On 1/2/06, Julian Field wrote: Need to install Mail::SPF::Query Install the following: make install name=clamav make install name=p5-Mail-ClamAV make install name=p5-DBI make install name=p5-Net-Ident You need to make all the queue directories by hand and rename all the silly .sample files freebsd seems to use, which just makes life harder for you. Start by getting the modules installed. /usr/local/libexec/MailScanner/MailScanner -v shoulud produce everything installed except Mail::ClamAV, Net::LDAP and SAVI, they aren't needed. Then hunt /usr/local for every ".sample" file and rename them so they don't end in that. mkdir -p /var/spool/MailScanner/incoming mkdir /var/spool/MailScanner/quarantine That should be enough to get you started. If you could document what you do and add it to the wiki at wiki.mailscanner.info that would be *REALLY* helpful for other people. Lance Haig wrote: > Hi Julian, > > I have just looked on their website and it says 6 is a production release. > > Does that mean it is unstable? > > Where can I find the documentation for installing MS on Freebsd. > > I have seen the document on > http://www.sng.ecs.soton.ac.uk/*mailscanner*/FreeBSD.html > > Are there other documents ? > > Thanks > > Lance > > Julian Field wrote: > >> Use the "port". >> cd /usr/ports >> make install name=mailscanner >> >> Once you've done all that, I've got a little list of things you have >> to do extra, as I've just done this myself. >> I hope you're not using this in production, freebsd 6 isn't finished >> yet! >> >> Lance Haig wrote: >> >>> I am looking at installing MS on a freebsd 6 system. >>> >>> Has anyone done this before? >>> How does it compare with Suse or Redhat with regards to management. >>> >>> Thanks >>> >>> Lance >>> >>> ------------------------ MailScanner list ------------------------ >>> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >>> 'leave mailscanner' in the body of the email. >>> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >>> the archives ( http://www.jiscmail.ac.uk/lists/mailscanner.html). >>> >>> Support MailScanner development - buy the book off the website! >> >> >> > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki ( http://wiki.mailscanner.info/) > and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > *Support MailScanner development - buy the book off the website!* -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives ( http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Jeff.Mills at VERSACOLD.COM.AU Tue Jan 3 02:35:11 2006 From: Jeff.Mills at VERSACOLD.COM.AU (Jeff Mills) Date: Thu Jan 12 21:31:37 2006 Subject: Automated response per domain Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK]On > Behalf Of Drew Marshall > Sent: Thursday, 22 December 2005 8:20 PM > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: Automated response per domain > > > > I'm always nervous about sending what amounts to bounces for > this sort of > thing as spam, mailing lists, postmaster notices, other > unknown people all > get the notifiction (Speak to Michelle Neylon about vacation > messages to > mailing lists :-) ) but if you are under pressure to deliver > this then you > could look at some thing like Reply-o-matic > http://sourceforge.net/projects/reply-o-matic which I have > used will do > what you are looking for. Put this on your MailScanner gateway for the > short term. > reply-o-matic doesnt seem to be able to send the email onto the original intended recipient. You can specify a addresses to send the original mail to, but I cant see a way to deliver to the original recipient, unless I'm missing something. *** "This company is now part of the Versacold Holdings Corp. and is no longer owned by or affiliated with the P&O Group" *** ************** www.versacold.com ************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From brent.bolin at GMAIL.COM Tue Jan 3 03:26:27 2006 From: brent.bolin at GMAIL.COM (BB) Date: Thu Jan 12 21:31:37 2006 Subject: Mailscanner on Freebsd Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Lets not forget to add this to your sendmail.mc file if you use sendmail. We don't want the perly gates to work harder then they should. Add others if you like... On 1/2/06, Raylund Lai wrote: Here are some of my notes/steps on installing MS on FreeBSD 6. I'm not having time to sort them out and some are not relevant to you (it's a mail gateway), but you could follow the logic in setting up. Cheers Raylund Free BSD 6 Installation 1. sysinstall Main Menu o Standard 2. Install Boot Manager for boot drive o Standard - Install a standard MBR (no boot manager) 3. Choose Distributions o [8] User # Install FreeBSD ports collection - No o [B] Custom # src # All 4. enable SSH login - Yes 5. enable Linux binary compatibility - No 6. browse the FreeBSD package collection - Yes o perl-5.8.7 7. add initial user account - No Installation of ports 1. cd /usr/ports/sysutils/webmin/ o make o make install o /usr/local/lib/webmin/setup.sh o cd /etc/ o cp rc.conf rc.conf.ORIG o vi rc.conf # add: webmin_enable="YES" # or echo 'webmin_enable="YES"' >> rc.conf 2. cd /usr/ports/mail/p5-Mail-ClamAV/ o make o make install 3. cd /usr/ports/mail/p5-Mail-Spamassassin/ o make # select AS_ROOT, RAZOR, SPF_QUERY only o make install 4. cd /usr/ports/security/f-prot/ o make o make install 5. install BitDefender o cd /usr/ports/distfiles/ o fetch -v ftp://ftp.bitdefender.com/pub/freebsd/5/final/bdc-7.0.1.2-fbsd5.tar.gz o cd /usr/ports/security/bdc/ o make o make install o vi rc.conf # add: compat5x_enable="YES" # or echo 'compat5x_enable="YES"' >> rc.conf 6. cd /usr/ports/misc/compat4x/ (somehow bdc needs compat4x instead of compat5x, may be fixed already) o make o make install o vi rc.conf # add: compat4x_enable="YES" # or echo 'compat4x_enable="YES"' >> rc.conf 7. cd /usr/ports/mail/mailscanner/ o make o make install o make initial-config 8. cd /usr/ports/sysutils/portupgrade/ o make o make install 9. reboot 10. pkgdb -F Configuration of sendmail 1. cd /etc/mail/ 2. cp freebsd.mc freebsd.mc.ORIG 3. cp access.sample access 4. cp mailertable.sample mailertable 5. vi freebsd.mc o add: FEATURE(`relay_hosts_only') o add: define(`confPRIVACY_FLAGS', `authwarnings, ..., nobodyreturn') o dnl FEATURE(blacklist_recipients) o dnl FEATURE(virtusertable,....) o dnl DAEMON_OPTIONS(`Name=IPv6,...) 6. m4 /usr/share/sendmail/cf/m4/cf.m4 freebsd.mc > sendmail.cf 7. vi mailertable o only entry is: yourdomain.com smtp:[numericlinkwarning 192.168.0.1] 8. makemap hash mailertable < mailertable 9. vi access o only entry is: Connect:numericlinkwarning 192.168.0.1 RELAY 10. makemap hash access < access 11. vi relay-domains o only entry is: yourdomain.com 12. cd /etc/ 13. vi rc.conf o add: sendmail_enable="NONE" o or echo 'sendmail_enable="NONE"' >> rc.conf Install milter-ahead 1. transfer downloaded files (www.SnertSoft.com) of LibSnert and milter-ahead to ~/tmp/ 2. cd ~/tmp/ 3. tar zxvf libsnert-1.48.tar.gz 4. tar zxvf milter-ahead-0.9.tar.gz 5. cd ~/tmp/com/snert/src/lib/ 6. ./configure --without-db 7. make build 8. cd ../milter-ahead 9. ./configure --without-db 10. make build 11. make install 12. modify /etc/mail/freebsd.mc accordingly Configuration of MailScanner 1. mkdir -p /var/spool/MailScanner/incoming/ 2. mkdir /var/spool/MailScanner/quarantine/ 3. mkdir /var/spool/mqueue.in/ 4. chgrp daemon /var/spool/MailScanner 5. chgrp daemon /var/spool/MailScanner/* 6. chgrp daemon /var/spool/mqueue.in 7. cd /usr/local/etc/rc.d 8. cp mta.sh.sample mta.sh 9. cp mailscanner.sh.sample mailscanner.sh 10. cd /usr/local/etc/MailScanner/mcp/ 11. cp mcp.spam.assassin.prefs.conf.sample mcp.spam.assassin.prefs.conf 12. mkdir /var/spool/spamassassin/ 13. chgrp daemon /var/spool/spamassassin 14. edit/create file bounce.rules to /usr/local/etc/MailScanner/rules/ 15. edit/create file notices.to.rules to /usr/local/etc/MailScanner/rules/ 16. edit/create file spam.checks.rules to /usr/local/etc/MailScanner/rules/ 17. edit/create file spam.header.rules to /usr/local/etc/MailScanner/rules/ 18. edit/create file virus.scanning.rules to /usr/local/etc/MailScanner/rules/ 19. edit /usr/local/etc/MailScanner/MailScanner.conf 20. edit /usr/local/etc/MailScanner/spam.assassin.prefs.conf 21. edit /usr/local/etc/MailScanner/virus.scanners.conf 22. edit /usr/local/libexec/MailScanner/bitdefender-autoupdate 23. edit /usr/local/libexec/MailScanner/f-prot-autoupdate 24. add cron job for update_virus_scanners every 15 minutes o crontab -e o 6,21,36,51 * * * * /usr/local/libexec/MailScanner/update_virus_scanners 25. transfer file bayes_backup /var/spool/spamassassin/ 26. restore bayes backup BB wrote: After the mailscanner install it gives a brief message to make the install complete. Something like - make config Don't recall exactly but you will see it. It copes all the sample filename extensions to the usable ones. I have not installed mailscanner on 6.x . Haven't heard of any problems on 6.x Use the standard cvsup so your not running on the bleeding edge. On 1/2/06, Julian Field wrote: Need to install Mail::SPF::Query Install the following: make install name=clamav make install name=p5-Mail-ClamAV make install name=p5-DBI make install name=p5-Net-Ident You need to make all the queue directories by hand and rename all the silly .sample files freebsd seems to use, which just makes life harder for you. Start by getting the modules installed. /usr/local/libexec/MailScanner/MailScanner -v shoulud produce everything installed except Mail::ClamAV, Net::LDAP and SAVI, they aren't needed. Then hunt /usr/local for every ".sample" file and rename them so they don't end in that. mkdir -p /var/spool/MailScanner/incoming mkdir /var/spool/MailScanner/quarantine That should be enough to get you started. If you could document what you do and add it to the wiki at wiki.mailscanner.info that would be *REALLY* helpful for other people. Lance Haig wrote: > Hi Julian, > > I have just looked on their website and it says 6 is a production release. > > Does that mean it is unstable? > > Where can I find the documentation for installing MS on Freebsd. > > I have seen the document on > http://www.sng.ecs.soton.ac.uk/*mailscanner*/FreeBSD.html > > Are there other documents ? > > Thanks > > Lance > > Julian Field wrote: > >> Use the "port". >> cd /usr/ports >> make install name=mailscanner >> >> Once you've done all that, I've got a little list of things you have >> to do extra, as I've just done this myself. >> I hope you're not using this in production, freebsd 6 isn't finished >> yet! >> >> Lance Haig wrote: >> >>> I am looking at installing MS on a freebsd 6 system. >>> >>> Has anyone done this before? >>> How does it compare with Suse or Redhat with regards to management. >>> >>> Thanks >>> >>> Lance >>> >>> ------------------------ MailScanner list ------------------------ >>> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >>> 'leave mailscanner' in the body of the email. >>> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >>> the archives ( http://www.jiscmail.ac.uk/lists/mailscanner.html). >>> >>> Support MailScanner development - buy the book off the website! >> >> >> > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki ( http://wiki.mailscanner.info/) > and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > *Support MailScanner development - buy the book off the website!* -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives ( http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! [ Part 2, Application/OCTET-STREAM (Name: "freebsd.mc") 4.6KB. ] [ Unable to print this part. ] From drew at THEMARSHALLS.CO.UK Tue Jan 3 08:52:38 2006 From: drew at THEMARSHALLS.CO.UK (Drew Marshall) Date: Thu Jan 12 21:31:37 2006 Subject: Automated response per domain Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Tue, January 3, 2006 02:35, Jeff Mills wrote: > reply-o-matic doesnt seem to be able to send the email onto the original intended recipient. > You can specify a addresses to send the original mail to, but I cant see a > way to deliver to the original recipient, unless I'm missing something. True, with out creating loads of alias entries (One for each user) which I am not sure how practical this would be for your user base as I don't know how many users you need to do this for. You could possibly look at BCCing all mail to an auto reponder address, which is easy to do in Postfix (Don't know about any other MTA). Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dhawal at NETMAGICSOLUTIONS.COM Tue Jan 3 09:41:59 2006 From: dhawal at NETMAGICSOLUTIONS.COM (Dhawal Doshy) Date: Thu Jan 12 21:31:37 2006 Subject: Maximum Message size and Attachmnet size no working for me Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Julian Field wrote: > Oh and there's also > > the "Happy" virus > Dangerously long MIME boundary strings used to exploit a bug in Eudora > filename.rules.conf and new "allow filenames" and "deny filenames" checks > filetype.rules.conf and new "allow filetypes" and "deny filetypes" checks > > That's about it. > > Raymond Dijkxhoorn wrote: > >> Hi! >> >>>> I can never remember what's included in Dangerous Content :-) Kosta >>>> Lekas wrote: >>> >> >>>>> I set dangerous content scanning to yes and it is working now. That >>>>> was >>>>> it. Thanks for your help. >>>> >> >>> Julian, it would be a nice idea to have a list of all such >>> dependencies on the wiki.. i too have been troubled by this more than >>> once.. what do you think? maybe sometime in jan'06? Julian, would you be kind enough to spare some time and review this? http://wiki.mailscanner.info/doku.php?id=documentation:configuration:dependencies Thanks, - dhawal ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From martelm at QUARK.VSC.EDU Tue Jan 3 15:49:28 2006 From: martelm at QUARK.VSC.EDU (Michael H. Martel) Date: Thu Jan 12 21:31:37 2006 Subject: Question about Spam and Virus Checks. Message-ID: Greetings! I've got a question about how MailScanner handles Spam Scoring and Anti Virus Checks. We're running MailScanner 4.48.4 on RedHat Linux 7.3 (MailScanner -v output below). I believe that Spam checks are done before the Anti virus checks yes ? I've got the folowing settings. Required SpamAssassin Score = 5 High SpamAssassin Score = 10 I've got my Spam Actions" set to: Spam Actions = /opt/VSC-MailScanner/rules/spam.actions.rules Where the spam.action.rules file contains : To: default store deliver I've also set "High Scoring Spam Actions" : High Scoring Spam Actions = /opt/VSC-MailScanner/rules/high.scoring.spam.actions.rules Where the high.scoring.spam.actions.rules file contains : To: default store For completeness, I have "Non Spam Actions" set to : Non Spam Actions = deliver I've been seeing messages come in that are a virus, with an infected file, but they are tagged as high scoring spam (>10) . So it looks like MailScanner never scans them for viruses because they're stored. Is that how it's supposed to work ? Messages that score between 5 and 10, are identified as Spam and hgaving a virus (if in fact they have a virus). Thanks for any thoughts! [root@hemlock /]# /opt/MailScanner/bin/MailScanner -v Running on Linux hemlock.vsc.edu 2.4.20-28.7smp #1 SMP Thu Dec 18 11:18:31 EST 2003 i686 unknown This is Red Hat Linux release 7.3 (Valhalla) This is Perl version 5.008006 (5.8.6) This is MailScanner version 4.48.4 Module versions are: 1.00 AnyDBM_File 1.14 Archive::Zip 1.03 Carp 1.119 Convert::BinHex 1.00 DirHandle 1.05 Fcntl 2.73 File::Basename 2.08 File::Copy 2.01 FileHandle 1.06 File::Path 0.16 File::Temp 1.29 HTML::Entities 3.45 HTML::Parser 2.30 HTML::TokeParser 1.21 IO 1.10 IO::File 1.123 IO::Pipe 1.50 Mail::Header 3.05 MIME::Base64 5.417 MIME::Decoder 5.417 MIME::Decoder::UU 5.417 MIME::Head 5.417 MIME::Parser 3.03 MIME::QuotedPrint 5.417 MIME::Tools 0.10 Net::CIDR 1.08 POSIX 1.77 Socket 0.05 Sys::Syslog 1.02 Time::localtime Optional module versions are: 0.17 Convert::TNEF 1.811 DB_File 1.08 Digest 1.01 Digest::HMAC 2.33 Digest::MD5 2.10 Digest::SHA1 0.44 Inline missing Mail::ClamAV 3.001000 Mail::SpamAssassin 1.997 Mail::SPF::Query 0.15 Net::CIDR::Lite 0.48 Net::DNS 0.32 Net::LDAP 1.94 Parse::RecDescent missing SAVI 1.2 Sys::Hostname::Long 2.42 Test::Harness 0.47 Test::Simple 1.95 Text::Balanced 1.35 URI Michael -- --------------------------------o--------------------------------- Michael H. Martel | Systems Administrator michael.martel@vsc.edu | Vermont State Colleges http://www.vsc.edu/~michael | PH:802-241-2544 FX:802-241-3363 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Tue Jan 3 16:04:17 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:37 2006 Subject: Question about Spam and Virus Checks. Message-ID: -----BEGIN PGP SIGNED MESSAGE----- The Spam archive is not kept clean of viruses unless you specify Keep Spam And MCP Archive Clean = yes Otherwise the version that is archived in the quarantine is an exact copy of the original message. On 3 Jan 2006, at 15:49, Michael H. Martel wrote: > Greetings! > > I've got a question about how MailScanner handles Spam Scoring and > Anti Virus Checks. We're running MailScanner 4.48.4 on RedHat Linux > 7.3 (MailScanner -v output below). > > I believe that Spam checks are done before the Anti virus checks yes ? > > I've got the folowing settings. > > Required SpamAssassin Score = 5 > High SpamAssassin Score = 10 > > I've got my Spam Actions" set to: > > Spam Actions = /opt/VSC-MailScanner/rules/spam.actions.rules > > Where the spam.action.rules file contains : > > To: default store deliver > > I've also set "High Scoring Spam Actions" : > > High Scoring Spam Actions = /opt/VSC-MailScanner/rules/ > high.scoring.spam.actions.rules > > Where the high.scoring.spam.actions.rules file contains : > > To: default store > > > For completeness, I have "Non Spam Actions" set to : > > Non Spam Actions = deliver > > > I've been seeing messages come in that are a virus, with an > infected file, but they are tagged as high scoring spam (>10) . So > it looks like MailScanner never scans them for viruses because > they're stored. Is that how it's supposed to work ? > > Messages that score between 5 and 10, are identified as Spam and > hgaving a virus (if in fact they have a virus). > > > Thanks for any thoughts! > > > [root@hemlock /]# /opt/MailScanner/bin/MailScanner -v > Running on > Linux hemlock.vsc.edu 2.4.20-28.7smp #1 SMP Thu Dec 18 11:18:31 EST > 2003 i686 unknown > This is Red Hat Linux release 7.3 (Valhalla) > This is Perl version 5.008006 (5.8.6) > > This is MailScanner version 4.48.4 > Module versions are: > 1.00 AnyDBM_File > 1.14 Archive::Zip > 1.03 Carp > 1.119 Convert::BinHex > 1.00 DirHandle > 1.05 Fcntl > 2.73 File::Basename > 2.08 File::Copy > 2.01 FileHandle > 1.06 File::Path > 0.16 File::Temp > 1.29 HTML::Entities > 3.45 HTML::Parser > 2.30 HTML::TokeParser > 1.21 IO > 1.10 IO::File > 1.123 IO::Pipe > 1.50 Mail::Header > 3.05 MIME::Base64 > 5.417 MIME::Decoder > 5.417 MIME::Decoder::UU > 5.417 MIME::Head > 5.417 MIME::Parser > 3.03 MIME::QuotedPrint > 5.417 MIME::Tools > 0.10 Net::CIDR > 1.08 POSIX > 1.77 Socket > 0.05 Sys::Syslog > 1.02 Time::localtime > > Optional module versions are: > 0.17 Convert::TNEF > 1.811 DB_File > 1.08 Digest > 1.01 Digest::HMAC > 2.33 Digest::MD5 > 2.10 Digest::SHA1 > 0.44 Inline > missing Mail::ClamAV > 3.001000 Mail::SpamAssassin > 1.997 Mail::SPF::Query > 0.15 Net::CIDR::Lite > 0.48 Net::DNS > 0.32 Net::LDAP > 1.94 Parse::RecDescent > missing SAVI > 1.2 Sys::Hostname::Long > 2.42 Test::Harness > 0.47 Test::Simple > 1.95 Text::Balanced > 1.35 URI > > > > Michael > > -- > > --------------------------------o--------------------------------- > Michael H. Martel | Systems Administrator > michael.martel@vsc.edu | Vermont State Colleges > http://www.vsc.edu/~michael | PH:802-241-2544 FX:802-241-3363 > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ7qgg/w32o+k+q+hAQFTCwf8C/ET2bC640yF2sFMMOPjZixBfXT/IJRV 6w6pYu1bA22pqu4UShV1aWBZVQM6n+bNHhDzG9vXacFcHwopCfVsN7G6Z3F62Pi2 wz3ZcnABrIBsj/tyukIWPL+0I1ekZ5Ms6sKID2SJitBLNBb9EtvxgHcXK7PTzUPg oNj/5/KR5TKVuYW7CVa1cP4KRCpm9B/34jZHCcg58fPioulCmL4AlP5HRoH+9kv8 u7KvcesW4JWCM15Jn4CIpVmi8syXpguZzbL3FoflquNYU6clh+Y/dO/VHycTMV3C 5UHIEcOns8+fiG18GX4jaU2CozU8MI1FPT6hMVUS8vMQxjYQWtarvA== =Hntk -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dhawal at NETMAGICSOLUTIONS.COM Tue Jan 3 15:55:41 2006 From: dhawal at NETMAGICSOLUTIONS.COM (Dhawal Doshy) Date: Thu Jan 12 21:31:37 2006 Subject: Question about Spam and Virus Checks. Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Michael H. Martel wrote: > Greetings! > > I've got a question about how MailScanner handles Spam Scoring and Anti > Virus Checks. We're running MailScanner 4.48.4 on RedHat Linux 7.3 > (MailScanner -v output below). > > I believe that Spam checks are done before the Anti virus checks yes ? > > I've got the folowing settings. > > Required SpamAssassin Score = 5 > High SpamAssassin Score = 10 > > I've got my Spam Actions" set to: > > Spam Actions = /opt/VSC-MailScanner/rules/spam.actions.rules > > Where the spam.action.rules file contains : > > To: default store deliver > > I've also set "High Scoring Spam Actions" : > > High Scoring Spam Actions = > /opt/VSC-MailScanner/rules/high.scoring.spam.actions.rules > > Where the high.scoring.spam.actions.rules file contains : > > To: default store > > > For completeness, I have "Non Spam Actions" set to : > > Non Spam Actions = deliver > > > I've been seeing messages come in that are a virus, with an infected > file, but they are tagged as high scoring spam (>10) . So it looks like > MailScanner never scans them for viruses because they're stored. Is > that how it's supposed to work ? Yes.. anything that is not delivered is not checked for viruses.. 2 ways around this. a. Set forwarding for high spam to a local account aliased to "dev/null" b. See the "Keep Spam And MCP Archive Clean" option in MailScanner.conf - dhawal ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From max at KIPNESS.COM Tue Jan 3 15:58:19 2006 From: max at KIPNESS.COM (Max Kipness) Date: Thu Jan 12 21:31:37 2006 Subject: No subject Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] I've been getting reports of this new vulnerability that is out now that seems pretty hard to prevent. Has anybody dealt with this virus as of yet? Any tips? I'm thinking about blocking all images for the time being. Here is the info I've received: A new vulnerability has surfaced which at this moment in time has no fix for. It relates to how Windows renders WMF (Windows Meta Files) and it is a new threat in that for the first time you don^Òt have to click anything to be hit, simply viewing an image that takes advantage of the vulnerability can execute commands on your PC, such as installing spyware/virus code. The vulnerability is in a core Windows rendering component, shimgvw.dll which is called to render WMF images from any application so you can be hit whether viewing a web page, previewing an email etc. More information can be found at - http://www.microsoft.com/technet/security/advisory/912840.mspx - http://www.kb.cert.org/vuls/id/181038 At this time the only workaround is to disable the problem component: Un-register the Windows Picture and Fax Viewer (Shimgvw.dll) 1. Click Start, click Run, type "regsvr32 -u %windir%\system32\shimgvw.dll" (without the quotation marks), and then click OK. 2. A dialog box appears to confirm that the un-registration process has succeeded. Click OK to close the dialog box. Impact of Workaround: The Windows Picture and Fax Viewer will no longer be started when users click on a link to an image type that is associated with the Windows Picture and Fax Viewer. To undo this change, re-register Shimgvw.dll by following the above steps. Replace the text in Step 1 with ^Óregsvr32 %windir%\system32\shimgvw.dll^Ô (without the quotation marks). Just blocking WMF files will not work as a the other image types could also be used. I will keep you informed of any updates but for now you should visit only ^Ótrusted^Ô web sites as the number of sites now using this vulnerability is growing. Also since we use Outlook 2003 it does not download images automatically so for now ensure do not download is configured (Tools ^Ö Options ^Ö Security ^Ö Change Automatic Download Settings^Å) Just wanted to make everyone aware the vulnerability has now been updated to bypass most anti-virus programs. It is thought MS may not release a fix for another week and so if you did not follow the instructions to unregister shimgvw.dll you should now or another option is there is also an ^Óunofficial^Ô fix at http://www.hexblog.com/2005/12/wmf_vuln.html which has been tested by several 3rd party vendors and validated for use until an official Microsoft fix is released. Once installed you need to reboot the computer. This vulnerability has already seen many types of attack already, for example: ^ÓThe emails have a Subject: "Happy New Year", body: "picture of 2006" and contain an exploit WMF as an attachment, named "HappyNewYear.jpg" (MD5: DBB27F839C8491E57EBCC9445BABB755). We detect this as PFV-Exploit.D. When the HappyNewYear.jpg hits the hard drive and is accessed (file opened, folder viewed, file indexed by Google Desktop), it executes and downloads a Bifrose backdoor (detected by us as Backdoor.Win32.Bifrose.kt) from www[dot]ritztours.com. Admins, filter this domain at your firewalls^Ô Thanks, Max ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From alan at ESSEX.AC.UK Tue Jan 3 16:01:47 2006 From: alan at ESSEX.AC.UK (Stanier, Alan M) Date: Thu Jan 12 21:31:37 2006 Subject: Junk mail with lots of short lines Message-ID: My Boss is complaining of a large increase in untagged spam consisting mostly of short lines, such as the one below. Looking at the text, I noticed that taking blocks of 9 lines and stringing them together, you get Mereidia $9 Levitra $9 Etc I am wondering if the text is that which remains after stripping out HTML that uses some trick with DIV or SPAM to construct whole words from the parts. Does that seem feasible? Does anyone have any suggestion for how such spam could be caught? Thanks -----Original Message----- From: Varlam Kuebler [mailto:varlame@huj.ch] Sent: 21 December 2005 14:17 If the link does not work automatically, copy it into your browser - www.chestain com Me Lev Am Xa So ClA VlA Pro VA ridia itra bien nax ma LlS GRA pecia LlUM $9 $9 $6 $1 $7 $9 $6 $6 $8 9.95 9.95 8.00 23.45 5.95 9.95 9.95 4.95 5.45 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Tue Jan 3 16:01:54 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:37 2006 Subject: No subject Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/3/06, Max Kipness wrote: I've been getting reports of this new vulnerability that is out now that seems pretty hard to prevent. Has anybody dealt with this virus as of yet? Any tips? I'm thinking about blocking all images for the time being. There's a long thread about this already. Clam detects it since the 29th I think, today they cover 93 variants. -- /Peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Tue Jan 3 15:59:36 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:37 2006 Subject: Question about Spam and Virus Checks. Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/3/06, Michael H. Martel wrote: I've got my Spam Actions" set to: Spam Actions = /opt/VSC-MailScanner/rules/spam.actions.rules Where the spam.action.rules file contains : To: default store deliver I've also set "High Scoring Spam Actions" : High Scoring Spam Actions = /opt/VSC-MailScanner/rules/high.scoring.spam.actions.rules Where the high.scoring.spam.actions.rules file contains : To: default store For completeness, I have "Non Spam Actions" set to : Non Spam Actions = deliver As you don't seem to use the rule sets I would skip them and put "store deliver" and "store" respectively directly on Spam/High Actions like you do with Non Spam Actions. I've been seeing messages come in that are a virus, with an infected file, but they are tagged as high scoring spam (>10) . So it looks like MailScanner never scans them for viruses because they're stored. Is that how it's supposed to work ? Yes, since nothing is delivered in your case it's no risk not scanning it and it saves some load. There are ways around it if it's important to you. -- /Peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ryan at MARINOCRANE.COM Tue Jan 3 16:05:56 2006 From: ryan at MARINOCRANE.COM (Ryan Pitt) Date: Thu Jan 12 21:31:37 2006 Subject: Mail Server OS Choices Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Hi Everyone, Happy New Year! We are in the process of upgrading our mail server and are just not sure which OS to go with. We are currently running with Fedora but they seem to upgrade way to often for a production server. Any feedback here would be greatly appreciated. Thanks Ryan Pitt ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From alex at NKPANAMA.COM Tue Jan 3 16:07:36 2006 From: alex at NKPANAMA.COM (Alex Neuman van der Hans) Date: Thu Jan 12 21:31:37 2006 Subject: Mail Server OS Choices Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Ryan Pitt wrote: > Hi Everyone, > Happy New Year! > We are in the process of upgrading our mail server and are just not > sure which OS to go with. > We are currently running with Fedora but they seem to upgrade way to > often for a production server. > Any feedback here would be greatly appreciated. > Thanks > Ryan Pitt > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! How about CentOS? I use it a lot, works like a charm. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From martinh at SOLID-STATE-LOGIC.COM Tue Jan 3 16:08:41 2006 From: martinh at SOLID-STATE-LOGIC.COM (Martin Hepworth) Date: Thu Jan 12 21:31:37 2006 Subject: Junk mail with lots of short lines Message-ID: Have you got the full email (headers and everything) you can post to a web site and I'll run it on my very comprehensive setup to see what fires.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Stanier, Alan M > Sent: 03 January 2006 16:02 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: [MAILSCANNER] Junk mail with lots of short lines > > My Boss is complaining of a large increase in untagged spam consisting > mostly of short lines, such as the one below. > > Looking at the text, I noticed that taking blocks of 9 lines and > stringing them together, you get > > Mereidia $9 > Levitra $9 > Etc > > I am wondering if the text is that which remains after stripping out > HTML that uses some trick with DIV or SPAM to construct whole words from > the parts. Does that seem feasible? > > Does anyone have any suggestion for how such spam could be caught? > > Thanks > > > > > > > -----Original Message----- > From: Varlam Kuebler [mailto:varlame@huj.ch] > Sent: 21 December 2005 14:17 > > > If the link does not work automatically, copy it into your browser - > > www.chestain > com > > Me > Lev > Am > Xa > So > ClA > VlA > Pro > VA > ridia > itra > bien > nax > ma > LlS > GRA > pecia > LlUM > $9 > $9 > $6 > $1 > $7 > $9 > $6 > $6 > $8 > 9.95 > 9.95 > 8.00 > 23.45 > 5.95 > 9.95 > 9.95 > 4.95 > 5.45 > > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From G.Pentland at SOTON.AC.UK Tue Jan 3 16:19:02 2006 From: G.Pentland at SOTON.AC.UK (Pentland G.) Date: Thu Jan 12 21:31:37 2006 Subject: Mail Server OS Choices Message-ID: >> Happy New Year! And the same to you... >> We are in the process of upgrading our mail server and are just not >> sure which OS to go with. We are currently running with Fedora but >> they seem to upgrade way to often for a production server. >> Any feedback here would be greatly appreciated. We are currently sendmail 8.13.x on Redhat Enterprise Linux 4 (AS) on our production kit but... As with most things, THE single most important thing to consider is what do YOU know how to use. I may suggest any one of a dozen platforms for various reasons but if your sysadmin only knows how to use IRIX or something then use that! The same goes for MTA as well. I will always go for sendmail but that is because I know it and trust it! thats my 2c anyway... Gary ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dhawal at NETMAGICSOLUTIONS.COM Tue Jan 3 16:35:55 2006 From: dhawal at NETMAGICSOLUTIONS.COM (Dhawal Doshy) Date: Thu Jan 12 21:31:37 2006 Subject: Mail Server OS Choices Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Ryan Pitt wrote: > Hi Everyone, > Happy New Year! > We are in the process of upgrading our mail server and are just not sure > which OS to go with. > We are currently running with Fedora but they seem to upgrade way to > often for a production server. > Any feedback here would be greatly appreciated. > Thanks > Ryan Pitt Are you looking at an alternative to fedora? if yes, centos is a great choice. a. based on rhel4 srpms and hence uses rpms b. mailscanner installs and upgrades are a breeze c. supports sendmail, postfix and exim out of the box d. easy to update and yum is quite fast as well e. tonnes of good repositories (including fedora extras) are available f. good track record (so far) g. a large and growing community h. a committed 5 year life (may extend to 7) The only downside being a small delay in security updates, which are launched only after redhat has released the updated srpms (obviously). other free and not so free options exist namely: rhel4 whitebox or tao (more rhel4 clones) freebsd debian opensuse (also my current desktop and the distro to watch out for) suse 10 (the paid option) distrowatch.com lists tonnes others You need to choose the one you are most comfortable with, rest will fall into place automagically. - dhawal ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From itdept at REDRED.COM Tue Jan 3 16:22:17 2006 From: itdept at REDRED.COM (RedRed!com IT Department) Date: Thu Jan 12 21:31:37 2006 Subject: Mail Server OS Choices Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] We felt the same about Fedora so we went with RHEL and it has been great. It has the same look and feel that I'm used to with Red Hat and it costs a fraction of what we would have paid to Microsoft or Sun. Alex Neuman van der Hans wrote: > Ryan Pitt wrote: > >> Hi Everyone, >> Happy New Year! >> We are in the process of upgrading our mail server and are just not >> sure which OS to go with. >> We are currently running with Fedora but they seem to upgrade way to >> often for a production server. >> Any feedback here would be greatly appreciated. >> Thanks >> Ryan Pitt >> >> ------------------------ MailScanner list ------------------------ >> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >> 'leave mailscanner' in the body of the email. >> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >> >> Support MailScanner development - buy the book off the website! > > > How about CentOS? I use it a lot, works like a charm. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mcalnek at PCPLACE.CA Tue Jan 3 16:36:21 2006 From: mcalnek at PCPLACE.CA (Milton Calnek) Date: Thu Jan 12 21:31:37 2006 Subject: Mail Server OS Choices Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I like fedora. If you are worried about the upgrade cycle, check out http://www.fedoralegacy.org/ RedRed!com IT Department wrote: > We felt the same about Fedora so we went with RHEL and it has been > great. It has the same look and feel that I'm used to with Red Hat and > it costs a fraction of what we would have paid to Microsoft or Sun. > - -- PC Place - Just clicks away Milton Calnek PC Place www.pcplace.ca 306-359-6939 mcalnek@pcplace.ca -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (GNU/Linux) Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org iD8DBQFDuqgFHgnbf2T2QqMRAqq4AJ4/OOtKanY+M+vy+BYX6pv3C8xgiACdFSGA A7psOpPTwqUiCxETagGQ5/M= =Jzxl -----END PGP SIGNATURE----- -- DISCLAIMER: The information transmitted is intended only for the addressee and may contain confidential, proprietary and/or privileged material. Any unauthorized review, distribution or other use of or the taking of any action in reliance upon this information is prohibited. If you received this in error, please contact the sender and delete or destroy this message and any copies. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. MailScanner thanks transtec Computers for their support. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mbneto at gmail.com Tue Jan 3 17:36:15 2006 From: mbneto at gmail.com (mbneto) Date: Thu Jan 12 21:31:37 2006 Subject: MailScanner ANNOUNCE: Stable 4.49 released -- faster! Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Hi, I was wondering if anyone has a benchmark of "how much faster" this new version is with sendmail and exim. tks. On 1/1/06, Julian Field wrote: > Happy New Year to you all! > > I have just released the latest stable version of MailScanner, 4.49. > This should be noticeably faster than previous releases. Noticeable > changes are: > > - Speed improvements for sendmail, Postfix and Exim systems. > - The output of "ps" now states what each MailScanner process is doing > at the time so you can easily see any problems and it helps you monitor > the state of your system. > - New configuration options to make simple filename and filetype rules > much easier to handle, especially when you want different filename/type > restrictions for different people. The old system is still there, is > still used, and works just as before. But now with the extra new "Allow > Filenames", "Deny Filenames", "Accept Filetypes", "Deny Filetypes" > configuration options you can easily write conventional rulesets to > control these features. These are applied before the filename.rules.conf > and filetype.rules.conf files. The order is "Accept" then "Deny" then > file{name,type}.rules.conf. > > Download as usual from www.mailscanner.info. > > The full Change Log is this: > > * New Features and Improvements * > - Speed improvements for sendmail systems by changing the > way temporary files are handled and how attachments are parsed. This > should be really noticeable if I've got it right. > Thanks for the great help of the Vodafone SHARK team. > - Added speed improvements for Exim. > - Added speed improvements for Postfix. > - Now changes the command line listed in `ps` (ie $0) to show what > MailScanner is doing. Should help diagnose slow system problems. > - 4 new configuration options, which list patterns against which filenames > and filetypes are matched to see if we should allow them or block them. > This is implemented for the benefit of web-based configuration systems for > MailScanner, it is not really intended for human use as it will complicate > the filename/filetype matching unless you understand it. Read the comments > in the MailScanner.conf and suggest better explanations! > "Allow Filenames", "Deny Filenames", "Allow Filetypes", "Deny Filetypes". > Note: There are 2 new entries in languages.conf so remember to > run an upgrade_languages_conf. > - Upgraded tnef program to 1.3.4. > - Added message 'actions' property for MailWatch reporting. > - Custom Function filenames must end in .pm or .pl. Others will be logged > and skipped. > - Various minor speed improvements. > > * Fixes * > - Changed Postfix code to better support latest revision of Perl. > - Now stops MailScanner more reliably on SuSE systems. > - Logging of tags only done if logging HTML tags. > - Fixed minor array ref problem in Perl 5.8.7 on FreeBSD 6.0 (which is not > a public stable release anyway). > > -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > Professional Support Services at www.MailScanner.biz > MailScanner thanks transtec Computers for their support > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From martinh at SOLID-STATE-LOGIC.COM Tue Jan 3 17:38:35 2006 From: martinh at SOLID-STATE-LOGIC.COM (Martin Hepworth) Date: Thu Jan 12 21:31:37 2006 Subject: MailScanner ANNOUNCE: Stable 4.49 released -- faster! Message-ID: I'm seeing scan times of around 20 seconds, down from 30....but I run a check of a lot of checks on the email which is why the times are so huge.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of mbneto > Sent: 03 January 2006 17:36 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: [MAILSCANNER] MailScanner ANNOUNCE: Stable 4.49 released -- > faster! > > Hi, > > I was wondering if anyone has a benchmark of "how much faster" this > new version is with sendmail and exim. > > tks. > > On 1/1/06, Julian Field wrote: > > Happy New Year to you all! > > > > I have just released the latest stable version of MailScanner, 4.49. > > This should be noticeably faster than previous releases. Noticeable > > changes are: > > > > - Speed improvements for sendmail, Postfix and Exim systems. > > - The output of "ps" now states what each MailScanner process is doing > > at the time so you can easily see any problems and it helps you monitor > > the state of your system. > > - New configuration options to make simple filename and filetype rules > > much easier to handle, especially when you want different filename/type > > restrictions for different people. The old system is still there, is > > still used, and works just as before. But now with the extra new "Allow > > Filenames", "Deny Filenames", "Accept Filetypes", "Deny Filetypes" > > configuration options you can easily write conventional rulesets to > > control these features. These are applied before the filename.rules.conf > > and filetype.rules.conf files. The order is "Accept" then "Deny" then > > file{name,type}.rules.conf. > > > > Download as usual from www.mailscanner.info. > > > > The full Change Log is this: > > > > * New Features and Improvements * > > - Speed improvements for sendmail systems by changing the > > way temporary files are handled and how attachments are parsed. This > > should be really noticeable if I've got it right. > > Thanks for the great help of the Vodafone SHARK team. > > - Added speed improvements for Exim. > > - Added speed improvements for Postfix. > > - Now changes the command line listed in `ps` (ie $0) to show what > > MailScanner is doing. Should help diagnose slow system problems. > > - 4 new configuration options, which list patterns against which > filenames > > and filetypes are matched to see if we should allow them or block > them. > > This is implemented for the benefit of web-based configuration systems > for > > MailScanner, it is not really intended for human use as it will > complicate > > the filename/filetype matching unless you understand it. Read the > comments > > in the MailScanner.conf and suggest better explanations! > > "Allow Filenames", "Deny Filenames", "Allow Filetypes", "Deny > Filetypes". > > Note: There are 2 new entries in languages.conf so remember to > > run an upgrade_languages_conf. > > - Upgraded tnef program to 1.3.4. > > - Added message 'actions' property for MailWatch reporting. > > - Custom Function filenames must end in .pm or .pl. Others will be > logged > > and skipped. > > - Various minor speed improvements. > > > > * Fixes * > > - Changed Postfix code to better support latest revision of Perl. > > - Now stops MailScanner more reliably on SuSE systems. > > - Logging of tags only done if logging HTML tags. > > - Fixed minor array ref problem in Perl 5.8.7 on FreeBSD 6.0 (which is > not > > a public stable release anyway). > > > > -- > > Julian Field > > www.MailScanner.info > > Buy the MailScanner book at www.MailScanner.info/store > > Professional Support Services at www.MailScanner.biz > > MailScanner thanks transtec Computers for their support > > > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > > > > -- > > This message has been scanned for viruses and > > dangerous content by MailScanner, and is > > believed to be clean. > > > > ------------------------ MailScanner list ------------------------ > > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > > 'leave mailscanner' in the body of the email. > > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > > > Support MailScanner development - buy the book off the website! > > > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From jaearick at COLBY.EDU Tue Jan 3 18:29:06 2006 From: jaearick at COLBY.EDU (Jeff A. Earickson) Date: Thu Jan 12 21:31:37 2006 Subject: MailScanner ANNOUNCE: Stable 4.49 released -- faster! Message-ID: On Tue, 3 Jan 2006, mbneto wrote: > Hi, > > I was wondering if anyone has a benchmark of "how much faster" this > new version is with sendmail and exim. My setup: sendmail, Solaris 9, SA 3.1, dcc and razor. While things are pretty slow right now (no students), a couple of big mailing lists got launched yesterday, after upgrade to 4.49. I definitely noticed how much faster MailScanner churned thru the multi-hundred message lists. We use VERP, so there is one message per subscriber on a list. Martin Hepworth's "1/3 faster" estimate agrees with my subjective eyeball measure from watching xload for my mail server. Great work, Julian!! Jeff Earickson Colby College ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ka at PACIFIC.NET Tue Jan 3 18:50:02 2006 From: ka at PACIFIC.NET (Ken A) Date: Thu Jan 12 21:31:37 2006 Subject: mail processed but abandoned qf files in mqueue.in? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] I'm seeing a few left over qf files in the incoming queue. The mail is being processed fine. I've tried changing flock to posix and this seems to help, but I'm not sure why this is happening with a 2.6 kernel and sendmail 13.4x, or is this issue still around with 2.6 kernels? Just upgraded a couple MS/SA boxes to the latest MailScanner/SA on Fedora Core 4. Thanks, Ken Anderson Pacific.Net ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From cstone at axint.net Tue Jan 3 19:07:02 2006 From: cstone at axint.net (Chris Stone) Date: Thu Jan 12 21:31:37 2006 Subject: mail processed but abandoned qf files in mqueue.in? Message-ID: On Tue, Jan 03, 2006 at 10:50:02AM -0800, Ken A wrote: > I'm seeing a few left over qf files in the incoming queue. The mail is > being processed fine. I've tried changing flock to posix and this seems > to help, but I'm not sure why this is happening with a 2.6 kernel and > sendmail 13.4x, or is this issue still around with 2.6 kernels? > Just upgraded a couple MS/SA boxes to the latest MailScanner/SA on > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Am seeing this also with MS 4.48.x under a 2.4 kernel with RH9. What I have noticed also is that it appears to be happening only for messages that have the recipient address set to NOT receive scanning (neither virus or spam). The messages seem to be processed and sent along ok, but some files linger in mqueue.in as you are seeing. Have not messed with changing flock, so don't know if that'd help or not here at all. Chris ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! [ Part 2, "Digital signature" Application/PGP-SIGNATURE 196bytes. ] [ Unable to print this part. ] From MailScanner at ecs.soton.ac.uk Tue Jan 3 19:28:55 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:37 2006 Subject: mail processed but abandoned qf files in mqueue.in? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Ken A wrote: > I'm seeing a few left over qf files in the incoming queue. The mail is > being processed fine. I've tried changing flock to posix and this > seems to help, but I'm not sure why this is happening with a 2.6 > kernel and sendmail 13.4x, or is this issue still around with 2.6 > kernels? > Just upgraded a couple MS/SA boxes to the latest MailScanner/SA on > Fedora Core 4. If using sendmail 8.13.1 or upwards, you need "Lock Type = posix" on Linux. This will make a critical difference. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From richard.thomas at PSYSOLUTIONS.COM Tue Jan 3 20:20:19 2006 From: richard.thomas at PSYSOLUTIONS.COM (Richard Thomas) Date: Thu Jan 12 21:31:37 2006 Subject: Log summaries Message-ID: Nathan Olson wrote: >The attached may be up your alley. > >Nate > > > Thanks. I'll take a look when I get the chance. Things like Mailwatch are very nice but no way we'd get the nod to roll it out to users at this point (quite apart from the support calls it would generate). All I'm looking for is to have some *very* simple stats up on a web page to show that we are not just completely ignoring the spam issue as some users seem to think. Rich >------------------------ MailScanner list ------------------------ >To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >'leave mailscanner' in the body of the email. >Before posting, read the Wiki (http://wiki.mailscanner.info/) and >the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > >Support MailScanner development - buy the book off the website! > > -- MIS Department | Psychiatric Solutions Inc |Phone: +1 615 312 5787 840 Crescent Ctr Dr | |Fax: +1 615 312 5711 Suite 460 +---------------------------+---------------------- Franklin, TN 37067 |Support: helpdesk@psysolutions.com +1 615 312 5888 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! [ Part 2, "S/MIME Cryptographic Signature" ] [ Application/X-PKCS7-SIGNATURE 4.4KB. ] [ Unable to print this part. ] From ka at PACIFIC.NET Tue Jan 3 21:06:02 2006 From: ka at PACIFIC.NET (Ken A) Date: Thu Jan 12 21:31:37 2006 Subject: mail processed but abandoned qf files in mqueue.in? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Julian Field wrote: > Ken A wrote: > >> I'm seeing a few left over qf files in the incoming queue. The mail is >> being processed fine. I've tried changing flock to posix and this >> seems to help, but I'm not sure why this is happening with a 2.6 >> kernel and sendmail 13.4x, or is this issue still around with 2.6 >> kernels? >> Just upgraded a couple MS/SA boxes to the latest MailScanner/SA on >> Fedora Core 4. > > If using sendmail 8.13.1 or upwards, you need "Lock Type = posix" on Linux. > This will make a critical difference. > # Don't set this unless you *know* you need to. # For sendmail, it defaults to "flock". # For sendmail 8.13 onwards, you will probably need to change it to posix. Now I _know_ I need to change this. :-) Thanks, Ken A Pacific.Net ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mailscanner at MANGO.ZW Tue Jan 3 21:14:43 2006 From: mailscanner at MANGO.ZW (Jim Holland) Date: Thu Jan 12 21:31:37 2006 Subject: Cannot create + lock headers file - Debian Sarge Message-ID: Hi all I have just started using Debian for the first time on a new live server and have installed MailScanner 4.46.2-3 from the unstable distribution on a server otherwise running Sarge - the latest Debian stable distribution. Unfortunately 4.46.2-3 is the latest MailScanner package that is available from Debian. It is running with sendmail 8.13.4-3 (Lock Type = posix) and ClamAV 0.87.1-0volatile.3. I am having a problem that has been repeatedly mentioned in the archives: MailScanner[2295]: Cannot create + lock headers file /var/spool/MailScanner/incoming/2295/jBVJNUGm002368.header Fortunately the error seems to arise only when doing a force-reload (or the equivalent stop then start) from the init.d/mailscanner script, so it is not causing any apparent problems in practice, but clearly something is wrong. I presume that the problem relates to a failure to kill off the old process, but I just cannot see any obvious problem with the init.d script or with the location of the lock files. (It is unfortunately complicated somewhat by the use of the terms "mailscanner" and "MailScanner" in different places). It is using the standard init.d script that came with the package. Related errors that also show up in the messages log are root: Process did not exit cleanly, returned 0 with signal 15 and once in mail.log: MailScanner[8448]: ERROR: Can't get absolute pathname of current working directory Is this a known bug with the Debian package? I haven't come across it before when using MailScanner compiled from the tarball under Red Hat 7.2. I append the relevant part of the init.d script that I think is the cause of the problem. I notice that the "waiting" loop almose always seems to iterate up to 10, and that a ps ax shows a left-over MailScanner process. I have checked the following in MailScanner.conf: Lockfile Dir = /var/lock/subsys/MailScanner Regards Jim Holland System Administrator MANGO - Zimbabwe's non-profit e-mail service stop) echo -n "Stopping $DESC: " start-stop-daemon --stop --quiet \ --name $NAME --quiet >/dev/null 2>&1 RETVAL=$? if [ $RETVAL -eq 0 ]; then rm -f /var/lock/subsys/mailscanner touch /var/lock/subsys/MailScanner.off fi if ps axww | grep -i $DAEMON | grep -qv grep; then echo -n "(waiting" for i in 1 2 3 4 5 6 7 8 9 10; do sleep $i if ! ps axww | grep -i $DAEMON | grep -qv grep; then break; fi echo -n . done echo -n ") " fi rm -f /var/run/$NAME/* echo "$NAME." ;; ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Jeff.Mills at VERSACOLD.COM.AU Tue Jan 3 22:06:26 2006 From: Jeff.Mills at VERSACOLD.COM.AU (Jeff Mills) Date: Thu Jan 12 21:31:37 2006 Subject: Automated response per domain Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK]On > Behalf Of Drew Marshall > Sent: Tuesday, 3 January 2006 7:53 PM > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: Automated response per domain > You could possibly > look at BCCing > all mail to an auto reponder address, which is easy to do in Postfix > (Don't know about any other MTA). > > Drew Ahhh yes, this seems a much better way of doing it. We have GFI Mail Essentials on the Exchange box which can do Auto Replies, but it cant do a whole domain, so we would have to add all of our users (over 300) to it. BCC to a single Auto Reply address though.. that could work! Thanks for your help. *** "This company is now part of the Versacold Holdings Corp. and is no longer owned by or affiliated with the P&O Group" *** ************** www.versacold.com ************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From drew at THEMARSHALLS.CO.UK Tue Jan 3 23:15:05 2006 From: drew at THEMARSHALLS.CO.UK (Drew Marshall) Date: Thu Jan 12 21:31:37 2006 Subject: Automated response per domain Message-ID: On 3 Jan 2006, at 22:06, Jeff Mills wrote: >> -----Original Message----- >> From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK]On >> Behalf Of Drew Marshall >> Sent: Tuesday, 3 January 2006 7:53 PM >> To: MAILSCANNER@JISCMAIL.AC.UK >> Subject: Re: Automated response per domain >> > You could possibly >> look at BCCing >> all mail to an auto reponder address, which is easy to do in Postfix >> (Don't know about any other MTA). >> >> Drew > > Ahhh yes, this seems a much better way of doing it. > We have GFI Mail Essentials on the Exchange box which can do Auto > Replies, but it cant do a whole domain, so we would have to add all > of our users (over 300) to it. BCC to a single Auto Reply address > though.. that could work! Excellent! Sounds like a plan. > Thanks for your help. A pleasure! Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Jan-Peter.Koopmann at SECEIDOS.DE Wed Jan 4 08:04:00 2006 From: Jan-Peter.Koopmann at SECEIDOS.DE (Koopmann, Jan-Peter) Date: Thu Jan 12 21:31:37 2006 Subject: Mailscanner on Freebsd Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Monday, January 02, 2006 9:59 PM Julian Field wrote: > Ah! Missed that. Ended up doing it by hand which was pretty > time-consuming. So you don't read my documentation? Shame on you! :-) >> Need to install Mail::SPF::Query >> >> Install the following: >> make install name=clamav >> make install name=p5-Mail-ClamAV >> make install name=p5-DBI >> make install name=p5-Net-Ident Damn. Missed that somehow. p5-Mail-ClamAV is quite old (need to tackle that sometime during the next days). What is p5-DBI used for? I will definately add p5-Net-Ident to the port if it is needed. The port is supposed to install everything absolutly necessary for MailScanner to work automatically, esp. all perl modules. Guys please let me know directly (best via personal e-mail) if you have any wishes for the FreeBSD port. Kind regards Jan-Peter Koopmann Dipl.-Wirtschaftsinformatiker Geschäftsführer -- Seceidos GmbH&Co. KG | Tel: +49 6151 66843-43 Robert-Bosch-Str. 7 | Fax: +49 6151 66843-52 64293 Darmstadt / Germany | IAX: guest@voip.seceidos.de/43 http://www.seceidos.de | SIP: 43@voip.seceidos.de ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From pete at ENITECH.COM.AU Wed Jan 4 08:13:21 2006 From: pete at ENITECH.COM.AU (Pete Russell) Date: Thu Jan 12 21:31:37 2006 Subject: Mail Server OS Choices Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] hard to imagine going past centos for mailscanner Alex Neuman van der Hans wrote: > Ryan Pitt wrote: > >> Hi Everyone, >> Happy New Year! >> We are in the process of upgrading our mail server and are just not >> sure which OS to go with. >> We are currently running with Fedora but they seem to upgrade way to >> often for a production server. >> Any feedback here would be greatly appreciated. >> Thanks >> Ryan Pitt >> >> ------------------------ MailScanner list ------------------------ >> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >> 'leave mailscanner' in the body of the email. >> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >> >> Support MailScanner development - buy the book off the website! > > > How about CentOS? I use it a lot, works like a charm. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From pete at ENITECH.COM.AU Wed Jan 4 08:15:01 2006 From: pete at ENITECH.COM.AU (Pete Russell) Date: Thu Jan 12 21:31:37 2006 Subject: Mail Server OS Choices Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] > The only downside being a small delay in security updates, which are > launched only after redhat has released the updated srpms (obviously). Isnt this normally within 24hours of security update release from Red Hat for RHEL? ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mailscanner at MANGO.ZW Wed Jan 4 12:36:22 2006 From: mailscanner at MANGO.ZW (Jim Holland) Date: Thu Jan 12 21:31:37 2006 Subject: OT: Use of MailScanner code for extracting attachments Message-ID: Hi Julian Happy New Year to you, and thanks once more for your most appreciated work. We here in Zimbabwe are still offering FidoNet protocols to around 2500 of our users. Our Fido server delivers files in binary form to our users separately from the actual messages. We currently use a Perl script to handle attachments, and it in turn calls metamail for the actual MIME decoding. This is not very elegant or reliable, and I am looking for a better way of decoding attachments - such as that used by MailScanner. It is a shame to see all the work that MailScanner does to decode messages only for us to then have to go through that process all over again before we can deliver the attachments to our Fido users. Sadly I am not a Perl expert - just a hacker who can develop scripts at a far lower level of complexity - so I find your code beyond my understanding. However if you were able to simply point me in the right direction - eg which packages are needed, where is the point of entry where a message is passed to those packages, and any other brief suggestions - I should be able to take it from there with a little help from another Perl enthusiast here. Any help would be most appreciated. Regards Jim Holland System Administrator MANGO - Zimbabwe's non-profit e-mail service ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Wed Jan 4 13:12:09 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:37 2006 Subject: OT: Use of MailScanner code for extracting attachments Message-ID: -----BEGIN PGP SIGNED MESSAGE----- There is a function "Explode" which does all the attachment extraction. You should be able to do what you want with a Custom Function attached to the "Always Looked Up Last" configuration option. See /usr/lib/MailScanner/MailScanner/CustomConfig.pm and the contents of the CustomFunctions directory (in the same place). You will have attachments expanded out in the /var/spool/MailScanner/ incoming/// directory. On 4 Jan 2006, at 12:36, Jim Holland wrote: > Hi Julian > > Happy New Year to you, and thanks once more for your most > appreciated work. > > We here in Zimbabwe are still offering FidoNet protocols to around > 2500 of > our users. Our Fido server delivers files in binary form to our users > separately from the actual messages. We currently use a Perl > script to > handle attachments, and it in turn calls metamail for the actual MIME > decoding. This is not very elegant or reliable, and I am looking > for a > better way of decoding attachments - such as that used by MailScanner. > It is a shame to see all the work that MailScanner does to decode > messages > only for us to then have to go through that process all over again > before > we can deliver the attachments to our Fido users. > > Sadly I am not a Perl expert - just a hacker who can develop > scripts at a > far lower level of complexity - so I find your code beyond my > understanding. However if you were able to simply point me in the > right > direction - eg which packages are needed, where is the point of entry > where a message is passed to those packages, and any other brief > suggestions - I should be able to take it from there with a little > help > from another Perl enthusiast here. > > Any help would be most appreciated. > > Regards > > Jim Holland > System Administrator > MANGO - Zimbabwe's non-profit e-mail service > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ7vJq/w32o+k+q+hAQE8Zwf/d5ZKPSSBNOlAPvus/MW2xgLlr6NzVVRZ lFL51vEnZjrpWaT/Xsfh5t30vF6nqWL8k4w+5MA9amlq7qxBHtOrmK8rN0uvMmHX P84mmzPVndNUS1IZ1w9OPgJuJXt5jkB5F0QJ0ecMV5RvQ7HUzGOhmjOew7s+r+Ip T2XZjTI5DuSJxU8N7892X/3mnretjKTkYfsCXAGYmelp7nfsL+O6bGyX61V58vlZ 7a3hczTXGAKCPcqAPkHb+MDiKyTRbHnjDNlezKU+SrCRuyyMkiIkuk8FEiET1zht cXNqQV9Xu4bP/mrY0EuHH7Dw3qnGbJGESaVAotaemgDp2XVHbfzHLQ== =4AfB -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ebruce at HPMICH.COM Wed Jan 4 14:45:22 2006 From: ebruce at HPMICH.COM (Ed Bruce) Date: Thu Jan 12 21:31:37 2006 Subject: I've seen the future and it is good Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Just looking over the Change Log for 4.49.7-1 and this is the first line: 2/1/2006 New in Version 4.50.3-1 - Speed increased by nearly a factor of 2! Julian can you also tell me next weeks Lotto numbers :) ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From glenn.steen at GMAIL.COM Wed Jan 4 15:09:10 2006 From: glenn.steen at GMAIL.COM (Glenn Steen) Date: Thu Jan 12 21:31:37 2006 Subject: OT: Happy New Year! Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 02/01/06, Doc Schneider wrote: > Glenn Steen wrote: > > On 31/12/05, Drew Marshall wrote: > >> On 30 Dec 2005, at 20:29, Glenn Steen wrote: > >> > >>> ... to all of you who recognize december 31 as the final day of the > >>> "old" year... Well, I'm a bit early, but in the timetested traditional > >>> swedish way... I'm headed straight into the usual alcohol-induced > >>> mists... Will probably not be able to email anything before sometime > >>> in january:-) > >>> > >>> Also would like to extend a special thanks to Jules and Steve > >>> (Freegard). Keep up the fantastic work another year guys! > >>> > >>> Anyway, have a good one! > >>> Cheers > >> Have a good one yourself Glenn and to everyone else out there in > >> 'MailScanner land' :-) > >> > >> May 2006 bring spam and infection free inboxes (But not so clear that > >> Jules' commercial adventure doesn't achieve the success it deserves) > >> > >> Drew > >> > > > > Well, the year could've ended in a more .... fortuitous way for me.... > > Spent three hours at the ER getting my leg into a cast... Sigh. Grown > > men should know better than to borrow the kids bobsleigh (Amazingly > > enough, not a whole lot of alcohol had been ingested beforehand:-):-). > > Oh well. Hope you all fared better;). > > > > -- > > Glenn, > > Just be glad it was only your leg... my wife has a friend who did > something almost exactly like this and is now in a wheelchair--she broke > her neck! (This happened a few years ago and no alcohol was involved) > > Hope the rest of this year goes well for the rest of the list folks. > > (Now to download the latest and greatest and see about getting my > MailScanner upgraded. > > -- > -Doc > Lincoln, NE. You are of course right Doc. I'll be an invalid for the next 6 weeks, but there are a lot of people like your wifes friend who end up hurt for life. About a decade ago the best Swedish slalom/downhill skier at the time, Thomas Fogdö, decided he didn't have to tighten things up going the short way from the lift to the pist... I understand there was a general fooling around, and he happened to take an "easy" fall that turned out to be really bad. A disc slipped in his back and tore the vertebrea(sp?), so he's in a wheelchair for life. Thing is, I knew this but never thought anything like that could happen to me. Now I know better. Oh well.... Back to getting this blasted VPN thingie working so that I don't have to be on sickleave the entire time ... I too would like to get the latest MS onto my MXs, and I don't trust that to my collegues:-) -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From jaearick at COLBY.EDU Wed Jan 4 14:59:15 2006 From: jaearick at COLBY.EDU (Jeff A. Earickson) Date: Thu Jan 12 21:31:37 2006 Subject: I've seen the future and it is good Message-ID: Judging from the New Year's Office party pictures, this prediction may be due to too much booze and people dancing in funny hats. But lets hope not, 4.49.7 was a significant speedup over prior versions. Whoo Hooo! Jeff Earickson Colby College On Wed, 4 Jan 2006, Ed Bruce wrote: > Date: Wed, 4 Jan 2006 09:45:22 -0500 > From: Ed Bruce > Reply-To: MailScanner mailing list > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: I've seen the future and it is good > > Just looking over the Change Log for 4.49.7-1 and this is the first line: > > 2/1/2006 New in Version 4.50.3-1 > - Speed increased by nearly a factor of 2! > > Julian can you also tell me next weeks Lotto numbers :) > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Wed Jan 4 10:42:13 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:37 2006 Subject: Mailscanner on Freebsd Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] -----BEGIN PGP SIGNED MESSAGE----- 4.50 will need DBI and DBD-SQLite. SpamAssassin needs DBI as well., that's probably why I put it in the list. On 4 Jan 2006, at 08:04, Koopmann, Jan-Peter wrote: > On Monday, January 02, 2006 9:59 PM Julian Field wrote: > >> Ah! Missed that. Ended up doing it by hand which was pretty >> time-consuming. > > So you don't read my documentation? Shame on you! :-) > >>> Need to install Mail::SPF::Query >>> >>> Install the following: >>> make install name=clamav >>> make install name=p5-Mail-ClamAV >>> make install name=p5-DBI >>> make install name=p5-Net-Ident > > Damn. Missed that somehow. p5-Mail-ClamAV is quite old (need to > tackle that sometime during the next days). What is p5-DBI used > for? I will definately add p5-Net-Ident to the port if it is > needed. The port is supposed to install everything absolutly > necessary for MailScanner to work automatically, esp. all perl > modules. > > Guys please let me know directly (best via personal e-mail) if you > have any wishes for the FreeBSD port. > > > > Kind regards > > Jan-Peter Koopmann > Dipl.-Wirtschaftsinformatiker > Geschäftsführer > > -- > Seceidos GmbH&Co. KG | Tel: +49 6151 66843-43 > Robert-Bosch-Str. 7 | Fax: +49 6151 66843-52 > 64293 Darmstadt / Germany | IAX: guest@voip.seceidos.de/43 > http://www.seceidos.de | SIP: 43@voip.seceidos.de > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ7umjPw32o+k+q+hAQHQwQf/apyD35SxEKgAuamDetLNXbsCCp5L+BfX b5qxoxV8OiBtnC1M/VBEEAopf58GA9+16mmvPG+15NjbqxRdvrROnCV4na846SVb 0bNLegg1n+D66Asolfa4hKapSzxYK+oNr04VeEC/y8Z0u57tlrmR6tBFNzoIG6x+ Za467MhVeT2KwbQ+KEE+O+AlgIIRKT1at8tbZjm2AdmjYetzC4rsRQ9c7k8iQTa9 PV6Dcb/ONJ1Rx0ibNhjPuyD8rYNQjjG3VqR3PYHhL51ABrQGTsuHQSg+BLZiTXJw 2f1fsfsVsxl4Dx7dCBnllSZBCPANRgN0+Cw0n6hRYIOGD6BQR6s6gg== =DjxE -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From fajarep at SIMPLIMOBILE.COM Wed Jan 4 09:53:28 2006 From: fajarep at SIMPLIMOBILE.COM (Fajar) Date: Thu Jan 12 21:31:37 2006 Subject: Mail Server OS Choices Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] I'm using Ubuntu Linux with MailScanner from source, others using mix Ubuntu Breezy & Dapper. Running fine here :D Fajar ----- Original Message ----- From: "Ryan Pitt" To: Sent: Tuesday, January 03, 2006 11:05 PM Subject: Mail Server OS Choices > Hi Everyone, > Happy New Year! > We are in the process of upgrading our mail server and are just not sure > which OS to go with. > We are currently running with Fedora but they seem to upgrade way to > often for a production server. > Any feedback here would be greatly appreciated. > Thanks > Ryan Pitt > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From glenn.steen at GMAIL.COM Wed Jan 4 15:36:40 2006 From: glenn.steen at GMAIL.COM (Glenn Steen) Date: Thu Jan 12 21:31:37 2006 Subject: Mail Server OS Choices Message-ID: [ The following text is in the "WINDOWS-1252" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 03/01/06, Pentland G. wrote: > >> Happy New Year! > > And the same to you... CC > >> We are in the process of upgrading our mail server and are just not > >> sure which OS to go with. We are currently running with Fedora but > >> they seem to upgrade way to often for a production server. > >> Any feedback here would be greatly appreciated. > > We are currently sendmail 8.13.x on Redhat Enterprise Linux 4 (AS) on > our production kit but... Mandriva/Postfix here:-) > > As with most things, THE single most important thing to consider is what > do YOU know how to use. I may suggest any one of a dozen platforms for > various reasons but if your sysadmin only knows how to use IRIX or > something then use that! > > The same goes for MTA as well. I will always go for sendmail but that > is because I know it and trust it! > > thats my 2c anyway... > > Gary > I'll happily add my .02^À to Gary's! The choice of OS/distribution is often "over-dramatized", looking at more or less irrelevant details... Any OS/distro can pretty much do anything any other OS/distro can, provided you have a knowledgeable sysadmin AND some time. Lacking either (it's usually time that is wanting...:-) one absolutely HAS to go with what one already knows, or as close a facsimile as possible. This probably means you should either go with one of the RH clones (like CentOS) or buy it, depending on what level of support you/your PHB "needs". -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From MailScanner at ecs.soton.ac.uk Wed Jan 4 16:36:57 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:37 2006 Subject: I've seen the future and it is good Message-ID: -----BEGIN PGP SIGNED MESSAGE----- From tests I have done, the speedup you see over 4.49 is dependent on the amount and type of spam/viruses you get. I am seeing only about 20% improvement in my tests, but another tester has seen nearly a doubling in speed. But we get less spam than a lot of sites. Once the code is stable I will release a beta for you to try. My charge for providing future Lotto numbers is more expensive than you could afford :-) On 4 Jan 2006, at 14:45, Ed Bruce wrote: > Just looking over the Change Log for 4.49.7-1 and this is the first > line: > > 2/1/2006 New in Version 4.50.3-1 > - Speed increased by nearly a factor of 2! > > Julian can you also tell me next weeks Lotto numbers :) - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ7v5q/w32o+k+q+hAQFt+Qf/YV5Gs5PvmaPYE9c4bSMj0y3gBDfEPcus 8qKCBLo3Ou/EocUDkooZ/pF2oDutLT2Qby4qo3aj0pbwoeODXyuMlMiKGF450t40 lxQ9JpsTHhAOVaW9OWQ7RML4hi5OMt5TN4ZsEyAqhZiFGW6nl+4QYQpQZPCf+1BZ oJlJbUTt1/bZUnbFqFDdSCXduTIpvyNyuzBadugaiMJ4EmhHRWvdKY3tTPJx9PIq BSa0v3+gTwP1iUNSaPAXdBF/srP4kwzoy+Yo8/7V7InyUtlSNaJ9DNEgS1a5vmzg yG5sYekRwVn+NZa7ddreNpTx5LznzQe8xrH6mZzgks3NWa8JhQexkA== =Q94m -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mailscanner at MANGO.ZW Wed Jan 4 16:33:05 2006 From: mailscanner at MANGO.ZW (Jim Holland) Date: Thu Jan 12 21:31:37 2006 Subject: upgrade_languages_conf broken and updating languages questions? Message-ID: Hi On Mon, 2 Jan 2006, Remco Barendse wrote: > Date: Mon, 2 Jan 2006 04:46:11 +0100 > From: Remco Barendse > Reply-To: MailScanner mailing list > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: upgrade_languages_conf broken and updating languages questions? > Also if somebody knows of a way to do some sort of grepping and deleting > the 'MS thanks transtec' etc. lines from the various reports through a > script that would be really neat :) This Perl one-liner should do the trick from the command line in the reports directory: perl -pi -e 's/MailScanner thanks transtec Computers for their support//' *.txt (See "man perlrun" for explanation of switches) I am not sure that Julian would approve of the change, however, if transtec are sponsoring the MailScanner development. Regards Jim Holland System Administrator MANGO - Zimbabwe's non-profit e-mail service ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From rabellino at DI.UNITO.IT Wed Jan 4 09:03:40 2006 From: rabellino at DI.UNITO.IT (Rabellino Sergio) Date: Thu Jan 12 21:31:37 2006 Subject: MailScanner ANNOUNCE: Stable 4.49 released -- faster! Message-ID: Jeff A. Earickson wrote: > On Tue, 3 Jan 2006, mbneto wrote: > >> Hi, >> >> I was wondering if anyone has a benchmark of "how much faster" this >> new version is with sendmail and exim. > > We've sendmail 8.13.3, with mcafee/clamav/sa ona Solaris 9 /4-cpu/ Sun-Fire-V440. I changed only the release of MS, without changing any configuration parameter; the cpu load average has changed from 2.5/3 to 1.2/1.6. It seems to be really faster than previous MS. Thanks again and again. -- Dott. Mag. Sergio Rabellino Technical Staff Department of Computer Science University of Torino (Italy) http://www.di.unito.it/~rabser Tel. +39-0116706701 Fax. +39-011751603 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mailscanner at MANGO.ZW Wed Jan 4 16:36:25 2006 From: mailscanner at MANGO.ZW (Jim Holland) Date: Thu Jan 12 21:31:37 2006 Subject: OT: Use of MailScanner code for extracting attachments Message-ID: Hi Julian Thanks very much for the tips. (Now I will go away and poke around in the code for a few weeks . . .) Regards Jim Holland System Administrator MANGO - Zimbabwe's non-profit e-mail service On Wed, 4 Jan 2006, Julian Field wrote: > Date: Wed, 4 Jan 2006 13:12:09 +0000 > From: Julian Field > Reply-To: MailScanner mailing list > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: OT: Use of MailScanner code for extracting attachments > > -----BEGIN PGP SIGNED MESSAGE----- > > There is a function "Explode" which does all the attachment > extraction. You should be able to do what you want with a Custom > Function attached to the "Always Looked Up Last" configuration > option. See /usr/lib/MailScanner/MailScanner/CustomConfig.pm and the > contents of the CustomFunctions directory (in the same place). > You will have attachments expanded out in the /var/spool/MailScanner/ > incoming/// directory. > > On 4 Jan 2006, at 12:36, Jim Holland wrote: > > > Hi Julian > > > > Happy New Year to you, and thanks once more for your most > > appreciated work. > > > > We here in Zimbabwe are still offering FidoNet protocols to around > > 2500 of > > our users. Our Fido server delivers files in binary form to our users > > separately from the actual messages. We currently use a Perl > > script to > > handle attachments, and it in turn calls metamail for the actual MIME > > decoding. This is not very elegant or reliable, and I am looking > > for a > > better way of decoding attachments - such as that used by MailScanner. > > It is a shame to see all the work that MailScanner does to decode > > messages > > only for us to then have to go through that process all over again > > before > > we can deliver the attachments to our Fido users. > > > > Sadly I am not a Perl expert - just a hacker who can develop > > scripts at a > > far lower level of complexity - so I find your code beyond my > > understanding. However if you were able to simply point me in the > > right > > direction - eg which packages are needed, where is the point of entry > > where a message is passed to those packages, and any other brief > > suggestions - I should be able to take it from there with a little > > help > > from another Perl enthusiast here. > > > > Any help would be most appreciated. > > > > Regards > > > > Jim Holland > > System Administrator > > MANGO - Zimbabwe's non-profit e-mail service > > > > ------------------------ MailScanner list ------------------------ > > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > > 'leave mailscanner' in the body of the email. > > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > > > Support MailScanner development - buy the book off the website! > > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.3 (Build 2932) > > iQEVAwUBQ7vJq/w32o+k+q+hAQE8Zwf/d5ZKPSSBNOlAPvus/MW2xgLlr6NzVVRZ > lFL51vEnZjrpWaT/Xsfh5t30vF6nqWL8k4w+5MA9amlq7qxBHtOrmK8rN0uvMmHX > P84mmzPVndNUS1IZ1w9OPgJuJXt5jkB5F0QJ0ecMV5RvQ7HUzGOhmjOew7s+r+Ip > T2XZjTI5DuSJxU8N7892X/3mnretjKTkYfsCXAGYmelp7nfsL+O6bGyX61V58vlZ > 7a3hczTXGAKCPcqAPkHb+MDiKyTRbHnjDNlezKU+SrCRuyyMkiIkuk8FEiET1zht > cXNqQV9Xu4bP/mrY0EuHH7Dw3qnGbJGESaVAotaemgDp2XVHbfzHLQ== > =4AfB > -----END PGP SIGNATURE----- > > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From craigwhite at AZAPPLE.COM Wed Jan 4 16:57:05 2006 From: craigwhite at AZAPPLE.COM (Craig White) Date: Thu Jan 12 21:31:38 2006 Subject: I've seen the future and it is good Message-ID: On Wed, 2006-01-04 at 16:36 +0000, Julian Field wrote: > My charge for providing future Lotto numbers is more expensive than > you could afford :-) > ---- fortune cookie makers everywhere would likely get cease and desist orders against you anyway since that is clearly their turf. Craig ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Wed Jan 4 17:13:06 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:38 2006 Subject: Speed tests of 4.48-4.49-4.50 Message-ID: -----BEGIN PGP SIGNED MESSAGE----- I have done some speed tests on a batch of mail on 2 different servers. 1 server is Opteron-based, the other Xeon-based. I was not using a DNS server on the MailScanner itself, but our main department one which should manage to cache a lot of it. Conclusion is that 4.49 is 11% faster than 4.48 (which sounds very suspicious to me, other people have reported much better than that). 4.50 is 15% or so faster than 4.49, which corresponds almost exactly with the cache hit rate. The more spammers you have who send the exact same message many times, and the number of virus-laden messages you are seeing, the higher your speedup will be. It would be great if another few people could do quantitative tests on 4.49 versus 4.48 as I don't believe the figures I have got. Here are the gory details. Many of the tests were run twice to try to counteract the effects of not having many of the DNS responses cached by BIND on the DNS server I'm using. 9001 messages taken from one MX server on 2006-01-03 Dual 2.2GHz Opteron, 4GB RAM, 70GB disk 15,000rpm SCSI 4.48 (4.50 with cache off and old forking code) 20:47:00 - 21:18:45 = 31:45 = 31*60+45 = 1905 408 K messages/day 4.49 (4.50 with cache off) 19:02:30 - 19:41:41 = 39:11 = 39*60+11 = 2351 331 K messages/day 331/408*100 < 100% XXX 2nd Run 21:22:43 - 21:51:52 = 29:09 = 29*60+09 = 1749 445 K messages/day 445/408*100 = 9% faster than 4.48 4.50 (4.50 with cache on) 19:48:36 - 20:13:37 = 25:01 = 25*60+1 = 1501 518 K messages/day 17% cache hit rate 518/331*100 = 56% faster than 4.49 2nd run 21:57:41 - 22:23:00 = 25:19 = 25*60+19 = 1519 512 K messages/day 512/445*100 = 15% faster than 4.49-2 4.49 run was done first, suspect 156% due to DNS caching ======================================================== Dual 2.4GHz Xeon, 2GB RAM, 36GB disk 10,000rpm SCSI 4.48 (4.50 with cache off and old forking code) 12:53:30 - 13:48:07 = 54:37 = 54*60+37 = 3277 237 K messages/day 2nd run 16:06:14 - 17:00:44 = 54:30 = 54*60+30 = 3270 238 K messages/day 4.49 (4.50 with cache off) 10:30:09 - 11:29:11 = 59:02 = 59*60+2 = 3542 220 K messages/day Ignore run 1 2nd run 13:54:22 - 14:43:29 = 49:07 = 49*60+7 = 2947 264 K messages/day 4.49 11% faster than 4.48 15:10:40 - 15:58:48 = 48:08 = 48*60+8 = 2888 270 K messages/day 4.49 13% faster than 4.48 4.50 (4.50 with cache on) 12:01:20 - 12:43:04 = 41:44 = 41*60+44 = 2504 311 K messages/day 4.50 18% faster than 4.49 2nd run 14:53:35 - 15:07:54 = 14:19 = 14*60+19 = 859 905 K messages/day This must be due to DNS caching, it is so much higher - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ7wCJfw32o+k+q+hAQEY8gf/Y93WOXv08nIEO9YLTiMEfL6u7iNLnEzM P2/sJlhdRkJfc8JhKKgiclO3/97N6MUQyMhqflfAesS2KQ2dANJNY/VqRFXimGYk /JbBwRA9tnyO2AGVyFRFFIGpQ05ZD/wW+awbUF69E0ywBRxnrhmTvlOHwxKDD52E WPdr2Jq88Ebz1lSwmh2TF6wIwpeGt+khkpoK5Z3134MOMa6Eglr8QfsIuKnrmOPN pXPNbZoPvC045X2X5PwUDHjqFGO0S3/aHQ9v2gtqVATEqVhg9z2PKaiCUMZ4cfpP 0y+AvpkGZbgePDwOorOGWcRz2BSDROEu0I3IVBmQiXL1pJsR5Apejw== =remZ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Wed Jan 4 17:36:39 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:38 2006 Subject: MailScanner ANNOUNCE: Stable 4.49 released -- faster! Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/4/06, Rabellino Sergio wrote: We've sendmail 8.13.3, with mcafee/clamav/sa ona Solaris 9 /4-cpu/ Sun-Fire-V440. I changed only the release of MS, without changing any configuration parameter; the cpu load average has changed from 2.5/3 to 1.2/1.6. It seems to be really faster than previous MS. Have you looked at the delay times in the logs from Sendmail? Do you see a similar decrease there? -- /Peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From jkf at ecs.soton.ac.uk Wed Jan 4 17:18:47 2006 From: jkf at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:38 2006 Subject: upgrade_languages_conf broken and updating languages questions? Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 4 Jan 2006, at 16:33, Jim Holland wrote: > On Mon, 2 Jan 2006, Remco Barendse wrote: >> Date: Mon, 2 Jan 2006 04:46:11 +0100 >> From: Remco Barendse >> Reply-To: MailScanner mailing list >> To: MAILSCANNER@JISCMAIL.AC.UK >> Subject: upgrade_languages_conf broken and updating languages >> questions? > >> Also if somebody knows of a way to do some sort of grepping and >> deleting >> the 'MS thanks transtec' etc. lines from the various reports >> through a >> script that would be really neat :) > > This Perl one-liner should do the trick from the command line in the > reports directory: > > perl -pi -e 's/MailScanner thanks transtec Computers for their > support//' *.txt > > (See "man perlrun" for explanation of switches) > > I am not sure that Julian would approve of the change, however, if > transtec are sponsoring the MailScanner development. I don't mind you doing this. I have left it in there as they did give me a dual 2.4GHz Xeon with 2Gb RAM and a 10,000rpm disk, when they were the best thing you could get. But they haven't contributed since then. I'm going to leave it in there for another year or so, but they haven't bought that slot forever. Anyone else interesting in buying that advertising space is welcome to contact me. It doesn't come cheap! But as I now switch the inline signature on by default, it does get you quite a lot of advertising for your money. Jules. - -- Julian Field jkf@ecs.soton.ac.uk Teaching Systems Manager Electronics & Computer Science University of Southampton SO17 1BJ, UK -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ7wDevw32o+k+q+hAQHqqQf+Oi3ue4OMwfMDr3PAu7tF48FEQL2A/PFf ME4ziit1f3BmWzt1rK4h+8/6wAzPfiDBfa+6IARyT6keLaAQhtnzl/Piy1u1zlrH rvBRbc5Mmsnc1strrU1WY5DgGLjkyL6XEG6HaNI63pWHTymejMiGT2KQhPZFchx4 WiYWvTTBMIXbmA3E30MmMTAt1e68TSRjAF8uk7IUnHqiLFx2aHtunptB17yfQhmV KbLSQFHKz3c/Jqxo02MnusCI+SFwSdBmmtFFVnTAgNwtcsDeuVFjlDj5iFitCUDm lkpWFCuNuAHBVfPLnRHdpx09TkWkpRUJMwuR4u0FMd8lLBghDDEA8w== =h7GX -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Chris.Boyd at USIT.IE Wed Jan 4 17:10:02 2006 From: Chris.Boyd at USIT.IE (Chris Boyd) Date: Thu Jan 12 21:31:38 2006 Subject: Infected mails from mydomain Message-ID: Am i getting these messages sent to my admin alias (ie admin@mydomain.ie) because someone is spoofing my email address and sending out infected attachments? Here's the header: TIA Return-path: Received: from smtp.mydomain.ie ([10.133.1.49]) by 10.133.1.50; Thu, 22 Dec 2005 13:11:18 +0000 Received: from exchange2.comsys.gr (exchange2.comsys.gr [194.219.54.100]) by smtp.mydomain.ie (Postfix) with SMTP id DA2ABA3B1B for ; Thu, 22 Dec 2005 13:14:00 +0000 (GMT) Subject: {Spam?} Virus Found in message "Mail_delivery_failed" MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----_=_NextPart_001_01C606F9.9D62A1EF" Date: Thu, 22 Dec 2005 15:14:18 +0200 Message-ID: <4096695D89BC47478DEB397E37BC43B8010ED9@exchange2.comsys.gr> Content-class: urn:content-classes:message X-MimeOLE: Produced By Microsoft Exchange V6.5 X-MS-Has-Attach: X-MS-TNEF-Correlator: <4096695D89BC47478DEB397E37BC43B8010ED9@exchange2.comsys.gr> Thread-Topic: Virus Found in message "Mail_delivery_failed" Thread-Index: AcYG+Z1isZIWGUALQdyv5DhTa2cEPg== From: =?iso-8859-7?B?w/Hh7Ozh9OXf4Q==?= To: X-USIT-MailScanner-OpenProtect-Information: Please contact the ISP for more information X-USIT-MailScanner-OpenProtect: Found to be clean X-USIT-MailScanner-OpenProtect-MCPCheck: X-USIT-MailScanner-OpenProtect-SpamCheck: spam, SpamAssassin (score=15.601, required 3, ALL_TRUSTED -3.30, BAYES_00 -2.60, VIRUS_WARNING188 1.50, VIRUS_WARNING59 20.00) X-USIT-MailScanner-OpenProtect-SpamScore: 15 X-USIT-MailScanner-OpenProtect-From: grammateia@comsys.gr This is a multi-part message in MIME format. ------_=_NextPart_001_01C606F9.9D62A1EF Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Symantec AntiVirus found a virus in an attachment you (Admin@mydomain.ie ) sent to priv-mail@comsys.gr. To ensure the recipient(s) are able to use the files you sent, perform a virus scan on your computer, clean any infected files, then resend this attachment. Attachment: mail.zip Virus name: W32.Sober.X@mm!zip Action taken: Quarantine succeeded : File status: Infected ------_=_NextPart_001_01C606F9.9D62A1EF Content-Type: application/ms-tnef; name="winmail.dat" Content-Transfer-Encoding: base64 ----------------------------------------------------------------- This email message is intended only for the addressee(s) and contains information that may be confidential and/or copyrighted. If you are not the intended recipient please notify the sender by reply email and immediately delete this email. Use, disclosure or reproduction of this email by anyone other than the intended recipient(s) is strictly prohibited. USIT has scanned this email for viruses and dangerous content and believes it to be clean. However, virus scanning is ultimately the responsibility of the recipient. ----------------------------------------------------------------- ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mkettler at EVI-INC.COM Wed Jan 4 18:11:58 2006 From: mkettler at EVI-INC.COM (Matt Kettler) Date: Thu Jan 12 21:31:38 2006 Subject: Infected mails from mydomain Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Chris Boyd wrote: > Am i getting these messages sent to my admin alias (ie admin@mydomain.ie) because someone is spoofing my email address and sending out infected attachments? > Given that Symantec found a Sober variant virus in it, I'd say with 99.9999% certainty that forgery is the case. Sober tries hard to always forge the return-path and From: headers. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mailscanner at MANGO.ZW Wed Jan 4 18:55:44 2006 From: mailscanner at MANGO.ZW (Jim Holland) Date: Thu Jan 12 21:31:38 2006 Subject: Infected mails from mydomain Message-ID: Hi On Wed, 4 Jan 2006, Matt Kettler wrote: > Date: Wed, 4 Jan 2006 13:11:58 -0500 > From: Matt Kettler > Reply-To: MailScanner mailing list > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: Infected mails from mydomain > > Chris Boyd wrote: > > Am i getting these messages sent to my admin alias (ie admin@mydomain.ie) because someone is spoofing my email address and sending out infected attachments? > Given that Symantec found a Sober variant virus in it, I'd say with 99.9999% > certainty that forgery is the case. Sober tries hard to always forge the > return-path and From: headers. While that is true, I would put the explanation the other way around: Chris Boyd is receiving these notices because Symantec stupidly bounces known viruses back to the spoofed sender address. Whenever I get one of these bounces I send back a polite but firm response to the system sending it pointing out the unacceptability of this annoying behaviour (and suggesting that they switch to MailScanner of course). Regards Jim Holland System Administrator MANGO - Zimbabwe's non-profit e-mail service ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ssilva at SGVWATER.COM Wed Jan 4 18:59:47 2006 From: ssilva at SGVWATER.COM (Scott Silva) Date: Thu Jan 12 21:31:38 2006 Subject: Infected mails from mydomain Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Chris Boyd spake the following on 1/4/2006 9:10 AM: > Am i getting these messages sent to my admin alias (ie admin@mydomain.ie) because someone is spoofing my email address and sending out infected attachments? > > Here's the header: > > TIA This is why everyone here is soo adamant about NOT bouncing virus notices! The notices never actually go to the virus infected sender (with a very few exceptions). -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Wed Jan 4 19:06:33 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:38 2006 Subject: Infected mails from mydomain Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Jim Holland wrote: >Hi > >On Wed, 4 Jan 2006, Matt Kettler wrote: > > > >>Date: Wed, 4 Jan 2006 13:11:58 -0500 >>From: Matt Kettler >>Reply-To: MailScanner mailing list >>To: MAILSCANNER@JISCMAIL.AC.UK >>Subject: Re: Infected mails from mydomain >> >>Chris Boyd wrote: >> >> >>>Am i getting these messages sent to my admin alias (ie admin@mydomain.ie) because someone is spoofing my email address and sending out infected attachments? >>> >>> > > > >>Given that Symantec found a Sober variant virus in it, I'd say with 99.9999% >>certainty that forgery is the case. Sober tries hard to always forge the >>return-path and From: headers. >> >> > >While that is true, I would put the explanation the other way around: >Chris Boyd is receiving these notices because Symantec stupidly bounces >known viruses back to the spoofed sender address. Whenever I get one of >these bounces I send back a polite but firm response to the system sending >it pointing out the unacceptability of this annoying behaviour (and >suggesting that they switch to MailScanner of course). > > Surely they have changed the default to not do this any more, haven't they? This is grossly irresponsible, and I am very surprised they haven't been sued by someone for causing a DoS attack resulting from the inevitable Joe-jobs. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From jstevens at ATHENSDISTRIBUTING.COM Wed Jan 4 20:45:15 2006 From: jstevens at ATHENSDISTRIBUTING.COM (James R. Stevens) Date: Thu Jan 12 21:31:38 2006 Subject: .wmf vulnerability Message-ID: Sorry if this has been answered. I'm curious if there is a test file posted somewhere allowing me to test my configuration for wmf exploit attachments. -----Original Message----- From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Dave Sent: Thursday, December 29, 2005 1:29 PM To: MAILSCANNER@JISCMAIL.AC.UK Subject: Re: .wmf vulnerability On 12/29/05, Ken A wrote: > Any suggestions for blocking the latest unpatched remote hole in windows? I just added wmf also. But will that only catch attachments? What about links in the message body? Anyone know if the virus scanners scan embedded images as well? ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by Athens Hyperion Scanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by Athens Hyperion Scanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Wed Jan 4 21:21:40 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] We have implemented some more speedups since version 4.49, which was already faster than 4.48. It depends on the nature of the spam you get, and the quantity of viruses that you get. The more dumb spam, and viruses, that you get, the faster it will go. Note that 1) you must use ./install.sh to install it as there are 2 more Perl modules required by (and provided with) this version, and 2) you must run upgrade_MailScanner_conf to add new configuration settings to your MailScanner.conf file. I would be very interested to hear what speedups you see from this new faster version. Download as usual from www.mailscanner.info. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ka at PACIFIC.NET Wed Jan 4 21:31:46 2006 From: ka at PACIFIC.NET (Ken A) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Julian Field wrote: > We have implemented some more speedups since version 4.49, which was > already faster than 4.48. It depends on the nature of the spam you get, > and the quantity of viruses that you get. > > The more dumb spam, and viruses, that you get, the faster it will go. Any way to get the faster speed without getting more dumb spam? heh heh.. I'm putting a new box online today, so I'll give it a go! Thanks, Ken A Pacific.Net > Note that > 1) you must use ./install.sh to install it as there are 2 more Perl > modules required by (and provided with) this version, and > 2) you must run upgrade_MailScanner_conf to add new configuration > settings to your MailScanner.conf file. > > I would be very interested to hear what speedups you see from this new > faster version. > > Download as usual from www.mailscanner.info. > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From raymond at PROLOCATION.NET Wed Jan 4 21:37:27 2006 From: raymond at PROLOCATION.NET (Raymond Dijkxhoorn) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: Hi Julian, > We have implemented some more speedups since version 4.49, which was already > faster than 4.48. It depends on the nature of the spam you get, and the > quantity of viruses that you get. > > The more dumb spam, and viruses, that you get, the faster it will go. > > Note that > 1) you must use ./install.sh to install it as there are 2 more Perl modules > required by (and provided with) this version, and > 2) you must run upgrade_MailScanner_conf to add new configuration settings to > your MailScanner.conf file. > > I would be very interested to hear what speedups you see from this new faster > version. # The SpamAssassin cache uses a database file which needs to be writable # by the MailScanner "Run As User". This file will be created and setup for # you automatically when MailScanner is started. SpamAssassin Cache Database File = /var/spool/MailScanner/incoming/SpamAssassin.cache.db Can you tell a littme more about this? What is stored, will the database be auto pruned? Or does it grow till my disk fills :) I am really interested in this since we use rcpts splitting, on what base you say its a identical message? Bye, Raymond. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From michele at BLACKNIGHT.IE Wed Jan 4 22:02:26 2006 From: michele at BLACKNIGHT.IE (Michele Neylon :: Blacknight) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Julian Field wrote: > We have implemented some more speedups since version 4.49, which was > already faster than 4.48. It depends on the nature of the spam you get, > and the quantity of viruses that you get. > > The more dumb spam, and viruses, that you get, the faster it will go. How do you define "dumb spam" ? -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Wed Jan 4 21:43:15 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] One thing worth mentioning: if you use rcpt splitting (one message per recipient) then you should see a massive speed improvement with this version. Raymond --- this may help you! Julian Field wrote: > We have implemented some more speedups since version 4.49, which was > already faster than 4.48. It depends on the nature of the spam you > get, and the quantity of viruses that you get. > > The more dumb spam, and viruses, that you get, the faster it will go. > > Note that > 1) you must use ./install.sh to install it as there are 2 more Perl > modules required by (and provided with) this version, and > 2) you must run upgrade_MailScanner_conf to add new configuration > settings to your MailScanner.conf file. > > I would be very interested to hear what speedups you see from this new > faster version. > > Download as usual from www.mailscanner.info. > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From raymond at PROLOCATION.NET Wed Jan 4 21:58:06 2006 From: raymond at PROLOCATION.NET (Raymond Dijkxhoorn) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: Hi Jules, > One thing worth mentioning: if you use rcpt splitting (one message per > recipient) then you should see a massive speed improvement with this version. > > Raymond --- this may help you! Yes, i am sure! :) Only need to get Sqlite going now. CPAN.pm: Going to build M/MS/MSERGEANT/DBD-SQLite-1.11.tar.gz Checking installed SQLite version... SQLite version must be at least 3.1.3. No header file at that version or higher was found. Using the local version instead. Checking if your kit is complete... Looks good Using DBI 1.37 installed in /usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI Writing Makefile for DBD::SQLite cp lib/DBD/SQLite.pm blib/lib/DBD/SQLite.pm /usr/bin/perl -p -e "s/~DRIVER~/SQLite/g" < /usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI/Driver.xst > SQLite.xsi /usr/bin/perl /usr/lib/perl5/5.8.3/ExtUtils/xsubpp -typemap /usr/lib/perl5/5.8.3/ExtUtils/typemap SQLite.xs > SQLite.xsc && mv SQLite.xsc SQLite.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id SQLite.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id alter.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id analyze.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id attach.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id auth.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id btree.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id build.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id callback.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id date.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id dbdimp.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id delete.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id experimental.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id expr.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id func.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id hash.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id insert.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id legacy.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id main.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id opcodes.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id os_test.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id os_unix.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id os_win.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id pager.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id parse.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id pragma.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id prepare.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id printf.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id random.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id select.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id table.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id tokenize.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id trigger.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id update.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id utf.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id util.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id vacuum.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id vdbe.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id vdbeapi.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id vdbeaux.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id vdbefifo.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id vdbemem.c gcc -c -I. -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" -DXS_VERSION=\"1.11\" -fPIC "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id where.c Running Mkbootstrap for DBD::SQLite () chmod 644 SQLite.bs rm -f blib/arch/auto/DBD/SQLite/SQLite.so LD_RUN_PATH="" gcc -shared -L/usr/local/lib SQLite.o alter.o analyze.o attach.o auth.o btree.o build.o callback.o date.o dbdimp.o delete.o experimental.o expr.o func.o hash.o insert.o legacy.o main.o opcodes.o os_test.o os_unix.o os_win.o pager.o parse.o pragma.o prepare.o printf.o random.o select.o table.o tokenize.o trigger.o update.o utf.o util.o vacuum.o vdbe.o vdbeapi.o vdbeaux.o vdbefifo.o vdbemem.o where.o -o blib/arch/auto/DBD/SQLite/SQLite.so chmod 755 blib/arch/auto/DBD/SQLite/SQLite.so cp SQLite.bs blib/arch/auto/DBD/SQLite/SQLite.bs chmod 644 blib/arch/auto/DBD/SQLite/SQLite.bs Manifying blib/man3/DBD::SQLite.3pm /usr/bin/make -- OK Running make test PERL_DL_NONLAZY=1 /usr/bin/perl "-MExtUtils::Command::MM" "-e" "test_harness(0, 'blib/lib', 'blib/arch')" t/*.t t/00basic...............ok t/01logon...............ok t/02cr_table............ok t/03insert..............ok 2/10Can't locate object method "last_insert_id" via package "DBI::db" at t/03insert.t line 13. t/03insert..............dubious Test returned status 2 (wstat 512, 0x200) Scalar found where operator expected at (eval 153) line 1, near "'int' $__val" (Missing operator before $__val?) DIED. FAILED tests 6-10 Failed 5/10 tests, 50.00% okay t/04select..............ok t/05tran................ok t/06error...............ok t/08create_function.....ok t/09create_aggregate....ok t/10dsnlist.............ok t/20createdrop..........ok t/30insertfetch.........ok t/40bindparam...........ok t/40blobs...............ok t/40blobtext............ok t/40listfields..........ok t/40nulls...............ok t/40numrows.............ok t/50chopblanks..........ok t/50commit..............ok t/60metadata............ok t/90cppcomments.........ok t/99cleanup.............ok t/ak-dbd................ok t/dbdadmin..............ok Failed Test Stat Wstat Total Fail Failed List of Failed ------------------------------------------------------------------------------- t/03insert.t 2 512 10 10 100.00% 6-10 Failed 1/25 test scripts, 96.00% okay. 5/406 subtests failed, 98.77% okay. make: *** [test_dynamic] Error 255 /usr/bin/make test -- NOT OK Running make install make test had returned bad status, won't install without force cpan> Bye, Raymond. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From raymond at PROLOCATION.NET Wed Jan 4 22:27:54 2006 From: raymond at PROLOCATION.NET (Raymond Dijkxhoorn) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: Hi! >>> Ok, after fetching a RPM from DAG we got SQLite going, the version on CPAN >>> gave errors on FC1. > >> Issues with SQLite on FC4 too. > > Upgrading DBD did fix it on FC1. Uhrm ... i ment DBI. (DBI-1.50) Bye, Raymond. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From raymond at PROLOCATION.NET Wed Jan 4 22:22:47 2006 From: raymond at PROLOCATION.NET (Raymond Dijkxhoorn) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: Hi! > You need to install a newer DBI I think. DBD::SQLite doesn't appear to work > with your DBI that you have installed. Investigate why the install.sh didn't > successfully install DBI for you. > >> Yes, i am sure! :) Correct. Had it going with the DAG RPM but if i upgrade DBI to 1.50 i can also build SQLite... so thats cool. Will upgrade DBI on the other ones also. Bye, Raymond. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ka at PACIFIC.NET Wed Jan 4 22:22:50 2006 From: ka at PACIFIC.NET (Ken A) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Raymond Dijkxhoorn wrote: > Hi! > >> One thing worth mentioning: if you use rcpt splitting (one message per >> recipient) then you should see a massive speed improvement with this >> version. >> >> Raymond --- this may help you! > >>> I would be very interested to hear what speedups you see from this >>> new faster version. > > Ok, after fetching a RPM from DAG we got SQLite going, the version on > CPAN gave errors on FC1. Issues with SQLite on FC4 too. > Checking installed SQLite version... > SQLite version must be at least 3.1.3. No header file at that > version or higher was found. Using the local version instead. > Checking if your kit is complete... > Looks good > Warning: prerequisite DBI 1.21 not found. > Writing Makefile for DBD::SQLite > + make > cp lib/DBD/SQLite.pm blib/lib/DBD/SQLite.pm > /usr/bin/perl /usr/lib/perl5/5.8.6/ExtUtils/xsubpp -typemap /usr/lib/perl5/5.8.6/ExtUtils/typemap SQLite.xs > SQLite.xsc && mv SQLite.xsc SQLite.c > Cannot open 'SQLite.xsi': No such file or directory in SQLite.xs, line 72 > make: *** [SQLite.c] Error 1 > error: Bad exit status from /var/tmp/rpm-tmp.78484 (%build) > > RPM build errors: > Bad exit status from /var/tmp/rpm-tmp.78484 (%build) > > Missing file /usr/src/redhat/RPMS/noarch/perl-DBD-SQLite-1.11-1.noarch.rpm. > Maybe it did not build correctly? Ken A > Works: > > Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message > k04M8POB022446 > Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message > k04M8POC022446 > Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message > k04M8POA022446 > Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message > k04M8PO8022446 > Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message > k04M8PO9022446 > Jan 4 23:08:36 vmx30 MailScanner[21955]: Cache hit for message > k04M8Zcb022532 > Jan 4 23:08:40 vmx30 MailScanner[21232]: Cache hit for message > k04M8d8h022583 > Jan 4 23:08:48 vmx30 MailScanner[21176]: Cache hit for message > k04M8iIc022599 > Jan 4 23:08:50 vmx30 MailScanner[21176]: Cache hit for message > k04M6gST021587 > Jan 4 23:08:50 vmx30 MailScanner[21176]: Cache hit for message > k04M8hFS022595 > Jan 4 23:08:51 vmx30 MailScanner[21650]: Cache hit for message > k04M8nTe022611 > Jan 4 23:08:51 vmx30 MailScanner[21650]: Cache hit for message > k04M8nTY022611 > > [root@vmx30]# grep "Cache hit for message" current | wc -l > 77 > > In a couple of mins. Looking promising. Cheers! > > Bye, > Raymond. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Wed Jan 4 22:14:31 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] You need to install a newer DBI I think. DBD::SQLite doesn't appear to work with your DBI that you have installed. Investigate why the install.sh didn't successfully install DBI for you. > Yes, i am sure! :) > > Only need to get Sqlite going now. > > CPAN.pm: Going to build M/MS/MSERGEANT/DBD-SQLite-1.11.tar.gz > > Checking installed SQLite version... > SQLite version must be at least 3.1.3. No header file at that > version or higher was found. Using the local version instead. > Checking if your kit is complete... > Looks good > Using DBI 1.37 installed in > /usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > Writing Makefile for DBD::SQLite > cp lib/DBD/SQLite.pm blib/lib/DBD/SQLite.pm > /usr/bin/perl -p -e "s/~DRIVER~/SQLite/g" < > /usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI/Driver.xst > > >> SQLite.xsi > > /usr/bin/perl /usr/lib/perl5/5.8.3/ExtUtils/xsubpp -typemap > /usr/lib/perl5/5.8.3/ExtUtils/typemap SQLite.xs > SQLite.xsc && mv > SQLite.xsc SQLite.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id SQLite.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id alter.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id analyze.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id attach.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id auth.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id btree.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id build.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id callback.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id date.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id dbdimp.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id delete.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id experimental.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id expr.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id func.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id hash.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id insert.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id legacy.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id main.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id opcodes.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id os_test.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id os_unix.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id os_win.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id pager.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id parse.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id pragma.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id prepare.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id printf.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id random.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id select.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id table.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id tokenize.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id trigger.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id update.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id utf.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id util.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id vacuum.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id vdbe.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id vdbeapi.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id vdbeaux.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id vdbefifo.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id vdbemem.c > gcc -c -I. > -I/usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi/auto/DBI > -D_REENTRANT -D_GNU_SOURCE -DTHREADS_HAVE_PIDS -DDEBUGGING > -fno-strict-aliasing -I/usr/local/include -D_LARGEFILE_SOURCE > -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -DVERSION=\"1.11\" > -DXS_VERSION=\"1.11\" -fPIC > "-I/usr/lib/perl5/5.8.3/i386-linux-thread-multi/CORE" -DNDEBUG=1 > -DSQLITE_PTR_SZ=4 -DHAVE_USLEEP=1 -Dno_last_insert_id where.c > Running Mkbootstrap for DBD::SQLite () > chmod 644 SQLite.bs > rm -f blib/arch/auto/DBD/SQLite/SQLite.so > LD_RUN_PATH="" gcc -shared -L/usr/local/lib SQLite.o alter.o > analyze.o attach.o auth.o btree.o build.o callback.o date.o dbdimp.o > delete.o experimental.o expr.o func.o hash.o insert.o legacy.o main.o > opcodes.o os_test.o os_unix.o os_win.o pager.o parse.o pragma.o > prepare.o printf.o random.o select.o table.o tokenize.o trigger.o > update.o utf.o util.o vacuum.o vdbe.o vdbeapi.o vdbeaux.o vdbefifo.o > vdbemem.o where.o -o blib/arch/auto/DBD/SQLite/SQLite.so > chmod 755 blib/arch/auto/DBD/SQLite/SQLite.so > cp SQLite.bs blib/arch/auto/DBD/SQLite/SQLite.bs > chmod 644 blib/arch/auto/DBD/SQLite/SQLite.bs > Manifying blib/man3/DBD::SQLite.3pm > /usr/bin/make -- OK > Running make test > PERL_DL_NONLAZY=1 /usr/bin/perl "-MExtUtils::Command::MM" "-e" > "test_harness(0, 'blib/lib', 'blib/arch')" t/*.t > t/00basic...............ok > t/01logon...............ok > t/02cr_table............ok > t/03insert..............ok 2/10Can't locate object method > "last_insert_id" via package "DBI::db" at t/03insert.t line 13. > t/03insert..............dubious > Test returned status 2 (wstat 512, 0x200) > Scalar found where operator expected at (eval 153) line 1, near "'int' > $__val" > (Missing operator before $__val?) > DIED. FAILED tests 6-10 > Failed 5/10 tests, 50.00% okay > t/04select..............ok > t/05tran................ok > t/06error...............ok > t/08create_function.....ok > t/09create_aggregate....ok > t/10dsnlist.............ok > t/20createdrop..........ok > t/30insertfetch.........ok > t/40bindparam...........ok > t/40blobs...............ok > t/40blobtext............ok > t/40listfields..........ok > t/40nulls...............ok > t/40numrows.............ok > t/50chopblanks..........ok > t/50commit..............ok > t/60metadata............ok > t/90cppcomments.........ok > t/99cleanup.............ok > t/ak-dbd................ok > t/dbdadmin..............ok > Failed Test Stat Wstat Total Fail Failed List of Failed > ------------------------------------------------------------------------------- > > t/03insert.t 2 512 10 10 100.00% 6-10 > Failed 1/25 test scripts, 96.00% okay. 5/406 subtests failed, 98.77% > okay. > make: *** [test_dynamic] Error 255 > /usr/bin/make test -- NOT OK > Running make install > make test had returned bad status, won't install without force > > cpan> > > Bye, > Raymond. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From michele at BLACKNIGHT.IE Wed Jan 4 22:13:39 2006 From: michele at BLACKNIGHT.IE (Michele Neylon :: Blacknight) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Julian Field wrote: >> >> > Spam where exactly the same message body is sent to multiple recipients. > It can be 1 message with many recipients or many messages, it works off > comparing the message bodies across multiple messages. > So it's a wee bit like DCC? -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Wed Jan 4 22:11:24 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Michele Neylon :: Blacknight wrote: >Julian Field wrote: > > >>We have implemented some more speedups since version 4.49, which was >>already faster than 4.48. It depends on the nature of the spam you get, >>and the quantity of viruses that you get. >> >>The more dumb spam, and viruses, that you get, the faster it will go. >> >> > >How do you define "dumb spam" ? > > Spam where exactly the same message body is sent to multiple recipients. It can be 1 message with many recipients or many messages, it works off comparing the message bodies across multiple messages. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From raymond at PROLOCATION.NET Wed Jan 4 22:13:32 2006 From: raymond at PROLOCATION.NET (Raymond Dijkxhoorn) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: Hi! > One thing worth mentioning: if you use rcpt splitting (one message per > recipient) then you should see a massive speed improvement with this version. > > Raymond --- this may help you! >> I would be very interested to hear what speedups you see from this new >> faster version. Ok, after fetching a RPM from DAG we got SQLite going, the version on CPAN gave errors on FC1. Works: Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message k04M8POB022446 Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message k04M8POC022446 Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message k04M8POA022446 Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message k04M8PO8022446 Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message k04M8PO9022446 Jan 4 23:08:36 vmx30 MailScanner[21955]: Cache hit for message k04M8Zcb022532 Jan 4 23:08:40 vmx30 MailScanner[21232]: Cache hit for message k04M8d8h022583 Jan 4 23:08:48 vmx30 MailScanner[21176]: Cache hit for message k04M8iIc022599 Jan 4 23:08:50 vmx30 MailScanner[21176]: Cache hit for message k04M6gST021587 Jan 4 23:08:50 vmx30 MailScanner[21176]: Cache hit for message k04M8hFS022595 Jan 4 23:08:51 vmx30 MailScanner[21650]: Cache hit for message k04M8nTe022611 Jan 4 23:08:51 vmx30 MailScanner[21650]: Cache hit for message k04M8nTY022611 [root@vmx30]# grep "Cache hit for message" current | wc -l 77 In a couple of mins. Looking promising. Cheers! Bye, Raymond. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Wed Jan 4 22:12:49 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Raymond Dijkxhoorn wrote: > Hi Julian, > >> We have implemented some more speedups since version 4.49, which was >> already faster than 4.48. It depends on the nature of the spam you >> get, and the quantity of viruses that you get. >> >> The more dumb spam, and viruses, that you get, the faster it will go. >> >> Note that >> 1) you must use ./install.sh to install it as there are 2 more Perl >> modules required by (and provided with) this version, and >> 2) you must run upgrade_MailScanner_conf to add new configuration >> settings to your MailScanner.conf file. >> >> I would be very interested to hear what speedups you see from this >> new faster version. > > > # The SpamAssassin cache uses a database file which needs to be writable > # by the MailScanner "Run As User". This file will be created and > setup for > # you automatically when MailScanner is started. > SpamAssassin Cache Database File = > /var/spool/MailScanner/incoming/SpamAssassin.cache.db > > Can you tell a littme more about this? > > What is stored, will the database be auto pruned? Or does it grow till > my disk fills :) It will auto-prune, don't worry. It looks at the message body to see if it has seen this message before. If it has, it grabs all the SpamAssassin results out of a cache and doesn't call SpamAssassin at all for this message. > I am really interested in this since we use rcpts splitting, on what > base you say its a identical message? You should see a very dramatic speed improvement on messages with multiple recipients. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From raymond at PROLOCATION.NET Wed Jan 4 22:26:50 2006 From: raymond at PROLOCATION.NET (Raymond Dijkxhoorn) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: Hi! >>>> I would be very interested to hear what speedups you see from this new >>>> faster version. >> Ok, after fetching a RPM from DAG we got SQLite going, the version on CPAN >> gave errors on FC1. > Issues with SQLite on FC4 too. Upgrading DBD did fix it on FC1. Bye, Raymond. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From raymond at PROLOCATION.NET Wed Jan 4 22:40:21 2006 From: raymond at PROLOCATION.NET (Raymond Dijkxhoorn) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: Hi! > One thing worth mentioning: if you use rcpt splitting (one message per > recipient) then you should see a massive speed improvement with this version. > > Raymond --- this may help you! Ok. After some thinking :) This works, but! :) Let me try to explain. Spammer sends spam, SA detects, but low spam score. We feed all those to our analyzer box, analyzer box finds URL thats bad, lists in a RBL... Normally the next messages will have a higher score, since more URI-BL lists will detect them after a few minutes. Same goes for bayes scores and so on. Is it a good idea to make it configurable when to use this feature? Eg, when its high spam? If its high spam i care less about the extra scores, high is high enough. If its low spam i certainly would be interested if its not high spam by then. Makes the difference of delivering or deleting in our case. Some ligic to only cache low spam for lets say 5 mins, and high spam an hour or so would be preferred. Else the detection will go down and thats bad. Just some idea's, hopefully it helps. Really cool move i think this. Saves a lot of power, only need to figure out something for the above... to optimize things. Bye, Raymond. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Wed Jan 4 22:35:50 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/4/06, Julian Field wrote: It looks at the message body to see if it has seen this message before. If it has, it grabs all the SpamAssassin results out of a cache and doesn't call SpamAssassin at all for this message. How does it determine that, by MD5 or similar? Is only the checksum stored in the db or the whole body? I noticed that you in the change log say under Fixes: "Improved reliability of Bayes rebuilds a lot". Do you now use SQLite for Bayes too? Theoretically that should be possible since SA does support it. Is the fix something totally different? -- /Peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ka at PACIFIC.NET Wed Jan 4 22:49:06 2006 From: ka at PACIFIC.NET (Ken A) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Upgrading DBI with CPAN fixed install problems on FC4 as well. Thanks, Ken A Pacific.Net Ken A wrote: > Raymond Dijkxhoorn wrote: >> Hi! >> >>> One thing worth mentioning: if you use rcpt splitting (one message >>> per recipient) then you should see a massive speed improvement with >>> this version. >>> >>> Raymond --- this may help you! >> >>>> I would be very interested to hear what speedups you see from this >>>> new faster version. >> >> Ok, after fetching a RPM from DAG we got SQLite going, the version on >> CPAN gave errors on FC1. > > > Issues with SQLite on FC4 too. > >> Checking installed SQLite version... >> SQLite version must be at least 3.1.3. No header file at that >> version or higher was found. Using the local version instead. >> Checking if your kit is complete... >> Looks good >> Warning: prerequisite DBI 1.21 not found. >> Writing Makefile for DBD::SQLite >> + make >> cp lib/DBD/SQLite.pm blib/lib/DBD/SQLite.pm >> /usr/bin/perl /usr/lib/perl5/5.8.6/ExtUtils/xsubpp -typemap >> /usr/lib/perl5/5.8.6/ExtUtils/typemap SQLite.xs > SQLite.xsc && mv >> SQLite.xsc SQLite.c >> Cannot open 'SQLite.xsi': No such file or directory in SQLite.xs, line 72 >> make: *** [SQLite.c] Error 1 >> error: Bad exit status from /var/tmp/rpm-tmp.78484 (%build) >> >> RPM build errors: >> Bad exit status from /var/tmp/rpm-tmp.78484 (%build) >> >> Missing file >> /usr/src/redhat/RPMS/noarch/perl-DBD-SQLite-1.11-1.noarch.rpm. >> Maybe it did not build correctly? > > > Ken A > > >> Works: >> >> Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message >> k04M8POB022446 >> Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message >> k04M8POC022446 >> Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message >> k04M8POA022446 >> Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message >> k04M8PO8022446 >> Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message >> k04M8PO9022446 >> Jan 4 23:08:36 vmx30 MailScanner[21955]: Cache hit for message >> k04M8Zcb022532 >> Jan 4 23:08:40 vmx30 MailScanner[21232]: Cache hit for message >> k04M8d8h022583 >> Jan 4 23:08:48 vmx30 MailScanner[21176]: Cache hit for message >> k04M8iIc022599 >> Jan 4 23:08:50 vmx30 MailScanner[21176]: Cache hit for message >> k04M6gST021587 >> Jan 4 23:08:50 vmx30 MailScanner[21176]: Cache hit for message >> k04M8hFS022595 >> Jan 4 23:08:51 vmx30 MailScanner[21650]: Cache hit for message >> k04M8nTe022611 >> Jan 4 23:08:51 vmx30 MailScanner[21650]: Cache hit for message >> k04M8nTY022611 >> >> [root@vmx30]# grep "Cache hit for message" current | wc -l >> 77 >> >> In a couple of mins. Looking promising. Cheers! >> >> Bye, >> Raymond. >> >> ------------------------ MailScanner list ------------------------ >> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >> 'leave mailscanner' in the body of the email. >> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >> >> Support MailScanner development - buy the book off the website! >> >> > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From michele at BLACKNIGHT.IE Wed Jan 4 23:18:25 2006 From: michele at BLACKNIGHT.IE (Michele Neylon:: Blacknight.ie) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Julian Field wrote: > We have implemented some more speedups since version 4.49, which was > already faster than 4.48. It depends on the nature of the spam you get, > and the quantity of viruses that you get. > > The more dumb spam, and viruses, that you get, the faster it will go. > > Note that > 1) you must use ./install.sh to install it as there are 2 more Perl > modules required by (and provided with) this version, and For some odd reason the SQLite module either didn't build on Centos 4 or simply wasn't recognised.. Easily fixed via cpan, but still a bit odd -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Kevin_Miller at CI.JUNEAU.AK.US Wed Jan 4 23:14:28 2006 From: Kevin_Miller at CI.JUNEAU.AK.US (Kevin Miller) Date: Thu Jan 12 21:31:38 2006 Subject: All_Trusted Message-ID: I updated one of my MailScanners last week. Running sendmail, with the following (from MailScanner -V): Linux mxl 2.6.11.4-21.10-default #1 Tue Nov 29 14:32:49 UTC 2005 i686 i686 i386 GNU/Linux This is SuSE Linux 9.3 (i586) This is Perl version 5.008006 (5.8.6) This is MailScanner version 4.48.4 3.000003 Mail::SpamAssassin Noticed some spam had made it through the filters this morning which had a -3.14 for ALL_TRUSTED. Bogus. There was a thread last month about ALL_TRUSTED, but it didn't mirror my setup in that I didn't change the local rules dir, whereas that poster did. I ran spamassassin --lint -D and it is reading the mailscanner.cf (link in /etc/mail/spamassassin) just fine. No additional dirs have been set in MailScanner.conf: "Spamassassin Local Rules Dir = " I added trusted_networks and internal_networks to local.cf and no longer see ALL_TRUSTED which is good. Don't know why spamassassin would suddenly start banging on ALL_TRUSTED - I didn't update SA - just MS. It does seem that something changed though, so I guess this is just a heads up to upgraders to make sure to check the logs w/in a short time after upgrading and adding the requisite entries to local.cf if necessary... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From smf at F2S.COM Wed Jan 4 23:17:00 2006 From: smf at F2S.COM (Steve Freegard) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: Hi Raymond, On Wed, 2006-01-04 at 23:40 +0100, Raymond Dijkxhoorn wrote: > Hi! > > > One thing worth mentioning: if you use rcpt splitting (one message per > > recipient) then you should see a massive speed improvement with this version. > > > > Raymond --- this may help you! > > Ok. After some thinking :) > > This works, but! :) > > Let me try to explain. > > Spammer sends spam, SA detects, but low spam score. We feed all those to > our analyzer box, analyzer box finds URL thats bad, lists in a RBL... > > Normally the next messages will have a higher score, since more URI-BL > lists will detect them after a few minutes. Same goes for bayes scores and > so on. > > Is it a good idea to make it configurable when to use this feature? Eg, > when its high spam? If its high spam i care less about the extra scores, > high is high enough. If its low spam i certainly would be interested if > its not high spam by then. Makes the difference of delivering or deleting > in our case. Some ligic to only cache low spam for lets say 5 mins, and > high spam an hour or so would be preferred. Else the detection will go > down and thats bad. > > Just some idea's, hopefully it helps. Really cool move i think this. Saves > a lot of power, only need to figure out something for the above... to > optimize things. Good idea - treating low/high spam differently in the cache expiry timer makes sense - this shouldn't be too difficult to do either. Working out the best amount to time to cache each will be trickier though as it really depends on how much mail you get. The way the expiry works at the moment is to expire: - non-spam after 30mins from the creation of the cache record (to account for lag getting onto RBLs/Pyzor/Razor/DCC). - spam after 6 hours from the initial creation of the cache record. - virus infected messages after 48 hours from the last cache-hit (to give the best possible chance of getting a cache-hit). These values are configurable in SA.pm at the moment as we didn't think it was likely that they would need to be changed. Kind regards, Steve. -- Steve Freegard Fort Systems Ltd. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mkettler at EVI-INC.COM Thu Jan 5 00:26:43 2006 From: mkettler at EVI-INC.COM (Matt Kettler) Date: Thu Jan 12 21:31:38 2006 Subject: All_Trusted Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Kevin Miller wrote: > I updated one of my MailScanners last week. Running sendmail, with the > following (from MailScanner -V): > > Linux mxl 2.6.11.4-21.10-default #1 Tue Nov 29 14:32:49 UTC 2005 i686 > i686 i386 GNU/Linux > This is SuSE Linux 9.3 (i586) > This is Perl version 5.008006 (5.8.6) > This is MailScanner version 4.48.4 > 3.000003 Mail::SpamAssassin > > Noticed some spam had made it through the filters this morning which had > a -3.14 for ALL_TRUSTED. Bogus. There was a thread last month about > ALL_TRUSTED, but it didn't mirror my setup in that I didn't change the > local rules dir, whereas that poster did. Any chance your old spam.assassin.prefs.conf had a "score ALL_TRUSTED 0" in it? (For a while the MS standard distro file had this in it.. very bad) Or some other config file that got disabled when you upgraded? ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Kevin_Miller at CI.JUNEAU.AK.US Thu Jan 5 00:53:12 2006 From: Kevin_Miller at CI.JUNEAU.AK.US (Kevin Miller) Date: Thu Jan 12 21:31:38 2006 Subject: All_Trusted Message-ID: Matt Kettler wrote: > Kevin Miller wrote: >> I updated one of my MailScanners last week. Running sendmail, with >> the following (from MailScanner -V): >> >> Linux mxl 2.6.11.4-21.10-default #1 Tue Nov 29 14:32:49 UTC 2005 >> i686 i686 i386 GNU/Linux This is SuSE Linux 9.3 (i586) >> This is Perl version 5.008006 (5.8.6) >> This is MailScanner version 4.48.4 >> 3.000003 Mail::SpamAssassin >> >> Noticed some spam had made it through the filters this morning which >> had a -3.14 for ALL_TRUSTED. Bogus. There was a thread last month >> about ALL_TRUSTED, but it didn't mirror my setup in that I didn't >> change the local rules dir, whereas that poster did. > > Any chance your old spam.assassin.prefs.conf had a "score ALL_TRUSTED > 0" in it? (For a while the MS standard distro file had this in it.. > very bad) > > Or some other config file that got disabled when you upgraded? My old spam.assassin.prefs.conf did have it in there, but the new one (linked to from /etc/mail) doesn't. That would have set the score to 0 at any rate, not -3.14. Unless I'm reading the line wrong and it's a toggle rather than a level. I'll be upgrading another of my boxes soon - be interesting to see what happens when I do... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From michele at BLACKNIGHT.IE Thu Jan 5 02:01:53 2006 From: michele at BLACKNIGHT.IE (Michele Neylon:: Blacknight.ie) Date: Thu Jan 12 21:31:38 2006 Subject: Just A Silly Question About MailWatch Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Fajar wrote: > You know, Mailwatch for MailScanner is really good for > manage your quarantine, spam/virus report, etc. I wonder, > why Mailwatch not being developed as fast as MailScanner? > Maybe someone willing to answer this silly question :D Both MailScanner and MailWatch are developed by selfless people who devote a considerable amount of their free time to working on them. -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From fajarep at SIMPLIMOBILE.COM Thu Jan 5 01:37:45 2006 From: fajarep at SIMPLIMOBILE.COM (Fajar) Date: Thu Jan 12 21:31:38 2006 Subject: Just A Silly Question About MailWatch Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] You know, Mailwatch for MailScanner is really good for manage your quarantine, spam/virus report, etc. I wonder, why Mailwatch not being developed as fast as MailScanner? Maybe someone willing to answer this silly question :D Thanks ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dbird at SGHMS.AC.UK Thu Jan 5 01:40:15 2006 From: dbird at SGHMS.AC.UK (Daniel Bird) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4, SpamAssassin.cache.db and tmpfs Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] I'm presuming it would be a good idea to move the SpamAssassin.cache.db to somewhere other than /var/spool/MailScanner/incoming if it's mounted as tmpfs since it will be lost if there's a reboot etc? Or does that not matter? How long are the entries cached? Dan -- ____________________________________ Daniel Bird Network and Systems Manager Department Of Information Services St. George's, University Of London Tooting London SW17 0RE P: +44 20 8725 2897 F: +44 20 8725 3583 E: dan@sgul.ac.uk ____________________________________ Computing Services Homepage: http://www.sgul.ac.uk/depts/cu -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mkettler at EVI-INC.COM Thu Jan 5 01:06:49 2006 From: mkettler at EVI-INC.COM (Matt Kettler) Date: Thu Jan 12 21:31:38 2006 Subject: All_Trusted Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Kevin Miller wrote: > Matt Kettler wrote: >>Any chance your old spam.assassin.prefs.conf had a "score ALL_TRUSTED >> 0" in it? (For a while the MS standard distro file had this in it.. >>very bad) >> >>Or some other config file that got disabled when you upgraded? > > > My old spam.assassin.prefs.conf did have it in there, but the new one > (linked to from /etc/mail) doesn't. That would have set the score to 0 > at any rate, not -3.14. Unless I'm reading the line wrong and it's a > toggle rather than a level. Well, yes, but if the score was previously set to 0, the rule would have been disabled and would never match any mail. Hence, with your old config, ALL_TRUSTED never fired due to the score 0 statement, covering up a pervasive problem in Received: header parsing on your system. The upgrade effectively caused this score statement to go away, thus enabling the rule with it's default -3.14 score, and showing that you needed a trusted_networks setting to fix your header parsing. It's a good thing the upgrade removed that statement.. setting ALL_TRUSTED to a 0 score covers up a lot of serious problems. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Kevin_Miller at CI.JUNEAU.AK.US Thu Jan 5 01:31:26 2006 From: Kevin_Miller at CI.JUNEAU.AK.US (Kevin Miller) Date: Thu Jan 12 21:31:38 2006 Subject: All_Trusted Message-ID: Matt Kettler wrote: > Kevin Miller wrote: >> Matt Kettler wrote: > >>> Any chance your old spam.assassin.prefs.conf had a "score >>> ALL_TRUSTED 0" in it? (For a while the MS standard distro file had >>> this in it.. very bad) >>> >>> Or some other config file that got disabled when you upgraded? >> >> >> My old spam.assassin.prefs.conf did have it in there, but the new one >> (linked to from /etc/mail) doesn't. That would have set the score >> to 0 at any rate, not -3.14. Unless I'm reading the line wrong and >> it's a toggle rather than a level. > > > Well, yes, but if the score was previously set to 0, the rule would > have been disabled and would never match any mail. > > Hence, with your old config, ALL_TRUSTED never fired due to the score > 0 statement, covering up a pervasive problem in Received: header > parsing on your system. > > The upgrade effectively caused this score statement to go away, thus > enabling the rule with it's default -3.14 score, and showing that you > needed a trusted_networks setting to fix your header parsing. > > > It's a good thing the upgrade removed that statement.. setting > ALL_TRUSTED to a 0 score covers up a lot of serious problems. Ah, I see what you mean. So having set trusted_networks and internal_networks per Mail::SpamAssassin::Conf, the ALL_TRUSTED trigger went away. But is there anything I should be looking at regarding the Received: header parsing or is that pretty much taken care of now? Things seem to be flowing OK. Hopefully it's catching more spam than ever? I take it that it would be prudent to check my other MS boxes and rem out the "score ALL_TRUSTED 0" if it's there? They're still running older versions so probably have that since it was a default setting... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ka at PACIFIC.NET Thu Jan 5 01:05:49 2006 From: ka at PACIFIC.NET (Ken A) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Just upgraded 3 boxes. Now I only need 2. Messages with multiple recipients that are split no longer incur a big penalty in SA. It's a bad day for spam. Jan 4 17:02:50 MailScanner[21109]: Cache hit for message k0512HE3026793 Jan 4 17:02:52 MailScanner[21264]: Cache hit for message k0512HE6026793 Jan 4 17:02:52 MailScanner[21264]: Cache hit for message k0512HE7026793 Jan 4 17:02:52 MailScanner[21264]: Cache hit for message k0512HE5026793 Jan 4 17:02:52 MailScanner[21264]: Cache hit for message k0512HE8026793 Jan 4 17:02:52 MailScanner[21264]: Cache hit for message k0512HE4026793 :-) Ken A Pacific.Net Steve Freegard wrote: > Hi Raymond, > > On Wed, 2006-01-04 at 23:40 +0100, Raymond Dijkxhoorn wrote: >> Hi! >> >>> One thing worth mentioning: if you use rcpt splitting (one message per >>> recipient) then you should see a massive speed improvement with this version. >>> >>> Raymond --- this may help you! >> Ok. After some thinking :) >> >> This works, but! :) >> >> Let me try to explain. >> >> Spammer sends spam, SA detects, but low spam score. We feed all those to >> our analyzer box, analyzer box finds URL thats bad, lists in a RBL... >> >> Normally the next messages will have a higher score, since more URI-BL >> lists will detect them after a few minutes. Same goes for bayes scores and >> so on. >> >> Is it a good idea to make it configurable when to use this feature? Eg, >> when its high spam? If its high spam i care less about the extra scores, >> high is high enough. If its low spam i certainly would be interested if >> its not high spam by then. Makes the difference of delivering or deleting >> in our case. Some ligic to only cache low spam for lets say 5 mins, and >> high spam an hour or so would be preferred. Else the detection will go >> down and thats bad. >> >> Just some idea's, hopefully it helps. Really cool move i think this. Saves >> a lot of power, only need to figure out something for the above... to >> optimize things. > > Good idea - treating low/high spam differently in the cache expiry timer > makes sense - this shouldn't be too difficult to do either. Working out > the best amount to time to cache each will be trickier though as it > really depends on how much mail you get. > > The way the expiry works at the moment is to expire: > > - non-spam after 30mins from the creation of the cache record (to > account for lag getting onto RBLs/Pyzor/Razor/DCC). > > - spam after 6 hours from the initial creation of the cache record. > > - virus infected messages after 48 hours from the last cache-hit (to > give the best possible chance of getting a cache-hit). > > These values are configurable in SA.pm at the moment as we didn't think > it was likely that they would need to be changed. > > Kind regards, > Steve. > > -- > Steve Freegard > Fort Systems Ltd. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From james at grayonline.id.au Thu Jan 5 02:49:25 2006 From: james at grayonline.id.au (James Gray) Date: Thu Jan 12 21:31:38 2006 Subject: 4.50.4 restarts the child after each batch? Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Just installed 4.49.7 on my production gateways - all is well. They are behaving as I expected them to. However, I've installed the latest beta (4.50.4 from the tar ball) on my test machine (system is an Exim 4.50-8 box running on Debian Sarge, with MailWatch) and noticed it now restarts the child after every batch: ... MailScanner[12542]: New Batch: Scanning 1 messages, 5532 bytes MailScanner[12542]: MCP Checks completed at 5532 bytes per second MailScanner[12542]: Spam Checks: Starting MailScanner[12542]: Message 1EuKE6-0003GA-4z from 82.211.81.173 (foo@example.com) to mydomain.com is not spam, SpamAssassin (score=-30.253, required 5, AWL 0.36, BAYES_00 -2.60, BODY_GAPPY_TEXT 1.92, LISTID_UBUNTU_USR -15.00, RCVD_BY_IP 0.07, TO_UBUNTU_LIST -15.00) MailScanner[12542]: Spam Checks completed at 790 bytes per second MailScanner[12542]: Virus and Content Scanning: Starting MailScanner[12542]: Virus Scanning completed at 1383 bytes per second MailScanner[12542]: Uninfected: Delivered 1 messages MailScanner[12542]: Virus Processing completed at 5532 bytes per second MailScanner[12542]: Disinfection completed at 5532 bytes per second MailScanner[12542]: Batch completed at 502 bytes per second (5532 / 11) MailScanner[12555]: MailScanner E-Mail Virus Scanner version 4.50.4 starting... MailScanner[12555]: Read 695 hostnames from the phishing whitelist MailScanner[12555]: Config: calling custom init function MailWatchLogging MailScanner[12555]: Caching SpamAssassin results MailScanner[12555]: Connected to SpamAssassin cache database MailScanner[12555]: Enabling SpamAssassin auto-whitelist functionality... MailScanner[12555]: Using locktype = posix MailScanner[12555]: Creating hardcoded struct_flock subroutine for linux (Linux-type) ... Notice the new PID? This box only runs a single child process and this behaviour is new since 4.50.4 was installed an hour or so ago. Here's some more diagnostic fru for your reading pleasure: #uname -a Linux ninja 2.4.27-2-686 #1 Wed Aug 17 10:34:09 UTC 2005 i686 GNU/Linux #ps -ef | grep MailScanner 109 12267 1 0 12:35 ? 00:00:00 MailScanner: starting child 109 12642 12267 4 12:51 ? 00:00:14 MailScanner: waiting for messages (109 is a valid UID = Debian-exim...no idea why ps wont show it. Also between teh log dump above and the execution of "ps" the child PID changed...again) # /opt/MailScanner/bin/MailScanner --version Running on Linux ninja 2.4.27-2-686 #1 Wed Aug 17 10:34:09 UTC 2005 i686 GNU/Linux This is Perl version 5.008004 (5.8.4) This is MailScanner version 4.50.4 Module versions are: 1.00 AnyDBM_File 1.14 Archive::Zip 1.02 Carp 1.119 Convert::BinHex 1.00 DirHandle 1.05 Fcntl 2.72 File::Basename 2.07 File::Copy 2.01 FileHandle 1.06 File::Path 0.16 File::Temp 1.29 HTML::Entities 3.45 HTML::Parser 2.30 HTML::TokeParser 1.21 IO 1.10 IO::File 1.123 IO::Pipe 1.50 Mail::Header 3.05 MIME::Base64 5.417 MIME::Decoder 5.417 MIME::Decoder::UU 5.417 MIME::Head 5.417 MIME::Parser 3.03 MIME::QuotedPrint 5.417 MIME::Tools 0.10 Net::CIDR 1.08 POSIX 1.77 Socket 0.05 Sys::Syslog 1.02 Time::localtime Optional module versions are: 0.17 Convert::TNEF 1.808 DB_File 1.06 Digest 1.01 Digest::HMAC 2.33 Digest::MD5 2.10 Digest::SHA1 0.44 Inline 0.17 Mail::ClamAV 3.000004 Mail::SpamAssassin 1.997 Mail::SPF::Query 0.15 Net::CIDR::Lite 0.48 Net::DNS 0.32 Net::LDAP 1.94 Parse::RecDescent missing SAVI 1.4 Sys::Hostname::Long 2.40 Test::Harness 0.47 Test::Simple 1.95 Text::Balanced 1.35 URI Thanks for any help. James -- When we talk of tomorrow, the gods laugh. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From matt at CODERS.CO.UK Thu Jan 5 07:32:47 2006 From: matt at CODERS.CO.UK (Matt Hampton) Date: Thu Jan 12 21:31:38 2006 Subject: 4.50.4 restarts the child after each batch? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] James Gray wrote: >Just installed 4.49.7 on my production gateways - all is well. They are >behaving as I expected them to. > > What happens when you run it in Debug mode in the foreground? >However, I've installed the latest beta (4.50.4 from the tar ball) on my test >machine (system is an Exim 4.50-8 box running on Debian Sarge, with >MailWatch) and noticed it now restarts the child after every batch: >... >MailScanner[12542]: New Batch: Scanning 1 messages, 5532 bytes >MailScanner[12542]: MCP Checks completed at 5532 bytes per second >MailScanner[12542]: Spam Checks: Starting >MailScanner[12542]: Message 1EuKE6-0003GA-4z from 82.211.81.173 >(foo@example.com) to mydomain.com is not spam, SpamAssassin (score=-30.253, >required 5, AWL 0.36, BAYES_00 -2.60, BODY_GAPPY_TEXT 1.92, LISTID_UBUNTU_USR >-15.00, RCVD_BY_IP 0.07, TO_UBUNTU_LIST -15.00) >MailScanner[12542]: Spam Checks completed at 790 bytes per second >MailScanner[12542]: Virus and Content Scanning: Starting >MailScanner[12542]: Virus Scanning completed at 1383 bytes per second >MailScanner[12542]: Uninfected: Delivered 1 messages >MailScanner[12542]: Virus Processing completed at 5532 bytes per second >MailScanner[12542]: Disinfection completed at 5532 bytes per second >MailScanner[12542]: Batch completed at 502 bytes per second (5532 / 11) >MailScanner[12555]: MailScanner E-Mail Virus Scanner version 4.50.4 >starting... >MailScanner[12555]: Read 695 hostnames from the phishing whitelist >MailScanner[12555]: Config: calling custom init function MailWatchLogging >MailScanner[12555]: Caching SpamAssassin results >MailScanner[12555]: Connected to SpamAssassin cache database >MailScanner[12555]: Enabling SpamAssassin auto-whitelist functionality... >MailScanner[12555]: Using locktype = posix >MailScanner[12555]: Creating hardcoded struct_flock subroutine for linux >(Linux-type) >... > >Notice the new PID? This box only runs a single child process and this >behaviour is new since 4.50.4 was installed an hour or so ago. > >Here's some more diagnostic fru for your reading pleasure: > >#uname -a >Linux ninja 2.4.27-2-686 #1 Wed Aug 17 10:34:09 UTC 2005 i686 GNU/Linux > >#ps -ef | grep MailScanner >109 12267 1 0 12:35 ? 00:00:00 MailScanner: starting child >109 12642 12267 4 12:51 ? 00:00:14 MailScanner: waiting for messages > >(109 is a valid UID = Debian-exim...no idea why ps wont show it. Also between >teh log dump above and the execution of "ps" the child PID changed...again) > ># /opt/MailScanner/bin/MailScanner --version >Running on >Linux ninja 2.4.27-2-686 #1 Wed Aug 17 10:34:09 UTC 2005 i686 GNU/Linux >This is Perl version 5.008004 (5.8.4) > >This is MailScanner version 4.50.4 >Module versions are: >1.00 AnyDBM_File >1.14 Archive::Zip >1.02 Carp >1.119 Convert::BinHex >1.00 DirHandle >1.05 Fcntl >2.72 File::Basename >2.07 File::Copy >2.01 FileHandle >1.06 File::Path >0.16 File::Temp >1.29 HTML::Entities >3.45 HTML::Parser >2.30 HTML::TokeParser >1.21 IO >1.10 IO::File >1.123 IO::Pipe >1.50 Mail::Header >3.05 MIME::Base64 >5.417 MIME::Decoder >5.417 MIME::Decoder::UU >5.417 MIME::Head >5.417 MIME::Parser >3.03 MIME::QuotedPrint >5.417 MIME::Tools >0.10 Net::CIDR >1.08 POSIX >1.77 Socket >0.05 Sys::Syslog >1.02 Time::localtime > >Optional module versions are: >0.17 Convert::TNEF >1.808 DB_File >1.06 Digest >1.01 Digest::HMAC >2.33 Digest::MD5 >2.10 Digest::SHA1 >0.44 Inline >0.17 Mail::ClamAV >3.000004 Mail::SpamAssassin >1.997 Mail::SPF::Query >0.15 Net::CIDR::Lite >0.48 Net::DNS >0.32 Net::LDAP >1.94 Parse::RecDescent >missing SAVI >1.4 Sys::Hostname::Long >2.40 Test::Harness >0.47 Test::Simple >1.95 Text::Balanced >1.35 URI > >Thanks for any help. > >James > > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dl6mpg at GMAIL.COM Thu Jan 5 07:36:06 2006 From: dl6mpg at GMAIL.COM (Uwe) Date: Thu Jan 12 21:31:38 2006 Subject: .wmf vulnerability Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] 2006/1/4, James R. Stevens : > Sorry if this has been answered. I'm curious if there is a test file > posted somewhere allowing me to test my configuration for wmf exploit > attachments. Try http://www.heise.de with the following link : http://www.heise.de/security/dienste/emailcheck/demos/go.shtml?mail=wmf and Enter you Email at the formular field. Uwe ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From raymond at PROLOCATION.NET Thu Jan 5 07:59:04 2006 From: raymond at PROLOCATION.NET (Raymond Dijkxhoorn) Date: Thu Jan 12 21:31:38 2006 Subject: 4.50.4 restarts the child after each batch? Message-ID: Hi! >> Just installed 4.49.7 on my production gateways - all is well. They are >> behaving as I expected them to. >> > What happens when you run it in Debug mode in the foreground? You had trouble installing SQLite. See other postings on the list. Either disable the new feature or install the missing stuff :) You had some modules failling during install. Thats why, had the same last night. Bye, Raymond. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 5 09:17:07 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 4 Jan 2006, at 22:13, Michele Neylon :: Blacknight wrote: > Julian Field wrote: >>> >>> >> Spam where exactly the same message body is sent to multiple >> recipients. >> It can be 1 message with many recipients or many messages, it >> works off >> comparing the message bodies across multiple messages. >> > So it's a wee bit like DCC? Yes, but it's local to your own email, which is the great advantage. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ7zkFvw32o+k+q+hAQFQZwf9GtJP68PH62H8Vi1XMeClEfSyafJk1bdl tA3yNEHfn7i2fy1aI8CHbIoxsAVl3UWKIFi3GS7yXJmDqavDIXI0kt0tCzzDkgop CJozo2jwVqd5zxhlxjY/oUrPF8Ua/vBbLQiRMBh6zAOPVnU9Ru8PIlvvYPz05JWB FHA4ObRIUnolGbqQeshxUFS8tW6MLjcR8itHEiw8Ls/wO4o6X3aokuubHKxh4XP3 zceHmphmJ5SX1cyL3qT4MRBul5uMQQjRFxEx14u8/3/Ukj59NrlUydgmG6+4Lyun +qlhg8zGyMUeDbyHctw4uTLOvdXomrnVdkg30W+Kam1HmyKE7Lovzw== =Ok0u -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Thu Jan 5 09:17:27 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:38 2006 Subject: All_Trusted Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/5/06, Matt Kettler wrote: It's a good thing the upgrade removed that statement.. setting ALL_TRUSTED to a 0 score covers up a lot of serious problems. What kind of problems do you mean? Problems regarding other things than the trusted mechanism? -- /Peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From smf at F2S.COM Thu Jan 5 09:19:44 2006 From: smf at F2S.COM (Steve Freegard) Date: Thu Jan 12 21:31:38 2006 Subject: Just A Silly Question About MailWatch Message-ID: On Thu, 2006-01-05 at 08:37 +0700, Fajar wrote: > You know, Mailwatch for MailScanner is really good for > manage your quarantine, spam/virus report, etc. I wonder, > why Mailwatch not being developed as fast as MailScanner? > Maybe someone willing to answer this silly question :D > I'm not sure I understand why you asked this. Is there a feature missing in MailWatch that you want or something? Maybe you should have asked this question on the MailWatch mailing-list first? If it is a philosophical question then: - they are both different products written and maintained by two different people. - MailWatch by definition will have some 'lag' between new features being written into MailScanner and the reporting for the new features being worked into MailWatch. - The MailScanner developer is in a completely different league to the MailWatch developer in developer skill :-) - This is open-source software, the developers write, maintain and support their software in their free time. - The MailWatch developer is lazy or doesn't seem to have much free time. Hope this clears it up for you. Kind regards, Steve. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From rabellino at DI.UNITO.IT Thu Jan 5 09:18:21 2006 From: rabellino at DI.UNITO.IT (Rabellino Sergio) Date: Thu Jan 12 21:31:38 2006 Subject: MailScanner ANNOUNCE: Stable 4.49 released -- faster! Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] shuttlebox wrote: > On 1/4/06, *Rabellino Sergio* > wrote: > > We've sendmail 8.13.3, with mcafee/clamav/sa ona Solaris 9 /4-cpu/ > Sun-Fire-V440. > > I changed only the release of MS, without changing any configuration > parameter; the cpu load average > has changed from 2.5/3 to 1.2/1.6. > > It seems to be really faster than previous MS. > > > Have you looked at the delay times in the logs from Sendmail? Do you > see a similar decrease there? > > -- I've investigated in the syslog, but the delay is strictly connected to the batch delay, so I do not understand how I can see a real speed-up if most of the delay is directly accountable to the batch waiting. (maybe i'm wrong) -- Dott. Mag. Sergio Rabellino Technical Staff Department of Computer Science University of Torino (Italy) http://www.di.unito.it/~rabser Tel. +39-0116706701 Fax. +39-011751603 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 5 09:24:02 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 4 Jan 2006, at 22:40, Raymond Dijkxhoorn wrote: > Hi! > >> One thing worth mentioning: if you use rcpt splitting (one message >> per recipient) then you should see a massive speed improvement >> with this version. >> >> Raymond --- this may help you! > > Ok. After some thinking :) > > This works, but! :) > > Let me try to explain. > > Spammer sends spam, SA detects, but low spam score. We feed all > those to our analyzer box, analyzer box finds URL thats bad, lists > in a RBL... > > Normally the next messages will have a higher score, since more URI- > BL lists will detect them after a few minutes. Same goes for bayes > scores and so on. > > Is it a good idea to make it configurable when to use this feature? > Eg, when its high spam? If its high spam i care less about the > extra scores, high is high enough. If its low spam i certainly > would be interested if its not high spam by then. Makes the > difference of delivering or deleting in our case. Some ligic to > only cache low spam for lets say 5 mins, and high spam an hour or > so would be preferred. Else the detection will go down and thats bad. It currently caches non-spam results for 30 minutes, spam results for 60 minutes. This should be enough to stop your detection rate dropping very much. > Just some idea's, hopefully it helps. Really cool move i think > this. Saves a lot of power, only need to figure out something for > the above... to optimize things. I've done most of what you suggest already. Caching high spam for longer than low spam is an interesting idea, I may well do that. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ7zltfw32o+k+q+hAQEJrwgAl39yh0PXSS1tGIzzLeRU5ns4RiH+w0HS mHjC01n2sMLuDURF8b1uCsXZEiN7xBAPd0GeVwZVLg1wzVYnPRodO9rXb1JqW6JK l9E2jW4k0Wu4A7YBYFNFyl6dNPNPLk8qMjVM6xxMguM5myENHFGy5noihN700jBo 2/WEvpL44XtSUR3i4cFQGOuUkrZdZrXxo9+srGVRGscOvdp66PNETh06eorN5xxH FL1vOItk6VeAb3aHNdhZgF/Nu+tfN/GXMVZJaEdLBIQXHmyhp5D17VtAnMMyy+8I JNXcTsKrxpfWbBSqfP76ZzSrZ/ebII6bK2k1W2T/aUVsyY6xCPSUTQ== =xZ3e -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 5 09:29:17 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 4 Jan 2006, at 23:17, Steve Freegard wrote: > Hi Raymond, > > On Wed, 2006-01-04 at 23:40 +0100, Raymond Dijkxhoorn wrote: >> Hi! >> >>> One thing worth mentioning: if you use rcpt splitting (one >>> message per >>> recipient) then you should see a massive speed improvement with >>> this version. >>> >>> Raymond --- this may help you! >> >> Ok. After some thinking :) >> >> This works, but! :) >> >> Let me try to explain. >> >> Spammer sends spam, SA detects, but low spam score. We feed all >> those to >> our analyzer box, analyzer box finds URL thats bad, lists in a RBL... >> >> Normally the next messages will have a higher score, since more >> URI-BL >> lists will detect them after a few minutes. Same goes for bayes >> scores and >> so on. >> >> Is it a good idea to make it configurable when to use this >> feature? Eg, >> when its high spam? If its high spam i care less about the extra >> scores, >> high is high enough. If its low spam i certainly would be >> interested if >> its not high spam by then. Makes the difference of delivering or >> deleting >> in our case. Some ligic to only cache low spam for lets say 5 >> mins, and >> high spam an hour or so would be preferred. Else the detection >> will go >> down and thats bad. >> >> Just some idea's, hopefully it helps. Really cool move i think >> this. Saves >> a lot of power, only need to figure out something for the above... to >> optimize things. > > Good idea - treating low/high spam differently in the cache expiry > timer > makes sense - this shouldn't be too difficult to do either. > Working out > the best amount to time to cache each will be trickier though as it > really depends on how much mail you get. > > The way the expiry works at the moment is to expire: > > - non-spam after 30mins from the creation of the cache record (to > account for lag getting onto RBLs/Pyzor/Razor/DCC). > > - spam after 6 hours from the initial creation of the cache record. Steve ---- What say we change 6 hours to 3 hours, and add high-spam expiry 6 hours from the "first" time? That should be nothing more than 1 change to the expiry function. Can you work out the SQL for me please? > > - virus infected messages after 48 hours from the last cache-hit (to > give the best possible chance of getting a cache-hit). > > These values are configurable in SA.pm at the moment as we didn't > think > it was likely that they would need to be changed. > > Kind regards, > Steve. > > -- > Steve Freegard > Fort Systems Ltd. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ7zm7/w32o+k+q+hAQGnNwf+JANWf6onFq+Hree2qRHOMxXlPJ2zd1ID LeRZGgynttdyynzxMI9EJeA+Y3wQVLvmSuHeQGncoJX9RIu9jzqQdF1wkCFeJteg Fw3G3hOQO/VqMFDRvqLqi3IPXOdyIZDCLPRmi7PbVHvJAz2uMiV7VbO1uqDVDSXz NpIugb52t8AZtvdD2rJ34URvbwN1PVJSQqYIlLB7gXnJLyoUI8Ekv3pOIp1w2D0b P3p5osjHDd8sIr33y+hNzggjOWP5E+G37YQ13TynoivuAlW9dWbFpNJPIpW1fclb q3/HPNLbFt+Z/sjrgc7DQt5jF/3c5cR1ycBij9EnTDZnyGDYrsxpTg== =M9zp -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From martinh at SOLID-STATE-LOGIC.COM Thu Jan 5 09:05:19 2006 From: martinh at SOLID-STATE-LOGIC.COM (Martin Hepworth) Date: Thu Jan 12 21:31:38 2006 Subject: Just A Silly Question About MailWatch Message-ID: Hi Well now the main Mailwatch Developer has more dedicated time for MW things should progress a little quicker (ie less than 18 months from version to version ;-) -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Fajar > Sent: 05 January 2006 01:38 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: [MAILSCANNER] Just A Silly Question About MailWatch > > You know, Mailwatch for MailScanner is really good for > manage your quarantine, spam/virus report, etc. I wonder, > why Mailwatch not being developed as fast as MailScanner? > Maybe someone willing to answer this silly question :D > > Thanks > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Thu Jan 5 09:27:45 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4, SpamAssassin.cache.db and tmpfs Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/5/06, Daniel Bird wrote: I'm presuming it would be a good idea to move the SpamAssassin.cache.db to somewhere other than /var/spool/MailScanner/incoming if it's mounted as tmpfs since it will be lost if there's a reboot etc? Or does that not matter? How long are the entries cached? In another thread Steve said the longest cache times are for viruses and it's 48 hours. But what would happen if you lost the cache? I think it would be equivalent to a no hit in the cache and the message has to be scanned, not a problem since that's how it's always been done up to 4.50. -- /Peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 5 09:26:00 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 4 Jan 2006, at 22:35, shuttlebox wrote: On 1/4/06, Julian Field wrote: It looks at the message body to see if it has seen this message before. If it has, it grabs all the SpamAssassin results out of a cache and doesn't call SpamAssassin at all for this message. How does it determine that, by MD5 or similar? Is only the checksum stored in the db or the whole body? MD5, Only the checksum. I noticed that you in the change log say under Fixes: "Improved reliability of Bayes rebuilds a lot". Do you now use SQLite for Bayes too? Theoretically that should be possible since SA does support it. Is the fix something totally different? Totally different. It's a very small change so that children doing the Bayes rebuild die immediately after completing it, they don't continue to live after that. It's solving problems like this, that I did the "worker children" architecture in the first place :-) --  Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! [ Part 2, Application/PGP-SIGNATURE 498bytes. ] [ Unable to print this part. ] From MailScanner at ecs.soton.ac.uk Thu Jan 5 09:26:43 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Did you run my ./install.sh? This should upgrade DBI for you anyway. If so, why did my DBI install fail? What output was produced? On 4 Jan 2006, at 22:49, Ken A wrote: > Upgrading DBI with CPAN fixed install problems on FC4 as well. > Thanks, > Ken A > Pacific.Net > > > Ken A wrote: >> Raymond Dijkxhoorn wrote: >>> Hi! >>> >>>> One thing worth mentioning: if you use rcpt splitting (one >>>> message per recipient) then you should see a massive speed >>>> improvement with this version. >>>> >>>> Raymond --- this may help you! >>> >>>>> I would be very interested to hear what speedups you see from >>>>> this new faster version. >>> >>> Ok, after fetching a RPM from DAG we got SQLite going, the >>> version on CPAN gave errors on FC1. >> Issues with SQLite on FC4 too. >>> Checking installed SQLite version... >>> SQLite version must be at least 3.1.3. No header file at that >>> version or higher was found. Using the local version instead. >>> Checking if your kit is complete... >>> Looks good >>> Warning: prerequisite DBI 1.21 not found. >>> Writing Makefile for DBD::SQLite >>> + make >>> cp lib/DBD/SQLite.pm blib/lib/DBD/SQLite.pm >>> /usr/bin/perl /usr/lib/perl5/5.8.6/ExtUtils/xsubpp -typemap /usr/ >>> lib/perl5/5.8.6/ExtUtils/typemap SQLite.xs > SQLite.xsc && mv >>> SQLite.xsc SQLite.c >>> Cannot open 'SQLite.xsi': No such file or directory in SQLite.xs, >>> line 72 >>> make: *** [SQLite.c] Error 1 >>> error: Bad exit status from /var/tmp/rpm-tmp.78484 (%build) >>> >>> RPM build errors: >>> Bad exit status from /var/tmp/rpm-tmp.78484 (%build) >>> >>> Missing file /usr/src/redhat/RPMS/noarch/perl-DBD- >>> SQLite-1.11-1.noarch.rpm. >>> Maybe it did not build correctly? >> Ken A >>> Works: >>> >>> Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message >>> k04M8POB022446 >>> Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message >>> k04M8POC022446 >>> Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message >>> k04M8POA022446 >>> Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message >>> k04M8PO8022446 >>> Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message >>> k04M8PO9022446 >>> Jan 4 23:08:36 vmx30 MailScanner[21955]: Cache hit for message >>> k04M8Zcb022532 >>> Jan 4 23:08:40 vmx30 MailScanner[21232]: Cache hit for message >>> k04M8d8h022583 >>> Jan 4 23:08:48 vmx30 MailScanner[21176]: Cache hit for message >>> k04M8iIc022599 >>> Jan 4 23:08:50 vmx30 MailScanner[21176]: Cache hit for message >>> k04M6gST021587 >>> Jan 4 23:08:50 vmx30 MailScanner[21176]: Cache hit for message >>> k04M8hFS022595 >>> Jan 4 23:08:51 vmx30 MailScanner[21650]: Cache hit for message >>> k04M8nTe022611 >>> Jan 4 23:08:51 vmx30 MailScanner[21650]: Cache hit for message >>> k04M8nTY022611 >>> >>> [root@vmx30]# grep "Cache hit for message" current | wc -l >>> 77 >>> >>> In a couple of mins. Looking promising. Cheers! >>> >>> Bye, >>> Raymond. >>> >>> ------------------------ MailScanner list ------------------------ >>> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >>> 'leave mailscanner' in the body of the email. >>> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >>> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >>> >>> Support MailScanner development - buy the book off the website! >>> >>> >> ------------------------ MailScanner list ------------------------ >> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >> 'leave mailscanner' in the body of the email. >> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >> Support MailScanner development - buy the book off the website! > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ7zmVPw32o+k+q+hAQEPcggAjZ8qaqOD7L+GgxWv4p5SJOSU6RoGf+Uq VO6TIowvJe48+5cxQ2aapV/YMdqVR0XjktNV9nIQDnm2/C/xs1gGbalRWw5NLSUF sFJ+3ZH5PRlOqC1/M8Jmnjxoqwbmhps8EOWHon0EZ0ewfZcfuESFYewm1vQdjPRR buYvq1nlKW+4Q5wuudUhCKqeGGpf7gV/PiKICLM78MzLE3RYgSgYG49jXE2toPPB yMUqJ+UfwlNfTmR1ekph0hErShVOruyZ6V9IoGbvLq+ZqoRdYGK2a3WUke0ahDXt 34ZUsWBM1BZlt5Bj4FdnGFBWtD5husdtLUS9FO527CBFdF4imQGDoA== =OcxF -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 5 09:31:38 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4, SpamAssassin.cache.db and tmpfs Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 5 Jan 2006, at 01:40, Daniel Bird wrote: > I'm presuming it would be a good idea to move the > SpamAssassin.cache.db to somewhere other than /var/spool/ > MailScanner/incoming if it's mounted as tmpfs since it will be lost > if there's a reboot etc? Or does that not matter? How long are the > entries cached? Reboots happen rarely, and the cache will soon rebuild itself, so I didn't worry too much about it getting lost on a reboot. I needed somewhere that I could guarantee was already writable by the "Run As User" without making the installation any more complicated. Feel free to move it if you don't like where I've put it :-) - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ7znfPw32o+k+q+hAQGo6wf/Uk53V0Xl1jRR8T0cRvQVLTza37ThhnAE VHhn9SU0n3EGcuFm+2pLkIu8tHNMc4VHcJoELQdbq1/4X7IaUR38bGrGwXMqlGcm 6MwUnoInC2xiPjRxzY0C719uS5+wFJWQ+/1vJ4xP4QuQTvBjVBsMaUQbk66+/vZE C5vj0e7qXlYEy8xp89mjNDUzOQxFjA5lF/w3FV3/JtUWhJoNYnRCTJdI6okqF2+/ BEM9Jmn8Bgwwr+U74l3y8usRmh/PIC4Na5q3PdIsLJJ52/ariFj7I8qONMjuen6K thfZbe/C7D718rZZQII90H4txW5afzIbNEn6MmT1FBsin37MfumAZQ== =m5gI -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 5 09:34:53 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:38 2006 Subject: MailScanner ANNOUNCE: Stable 4.49 released -- faster! Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 5 Jan 2006, at 09:18, Rabellino Sergio wrote: > shuttlebox wrote: > >> On 1/4/06, *Rabellino Sergio* > > wrote: >> >> We've sendmail 8.13.3, with mcafee/clamav/sa ona Solaris 9 /4- >> cpu/ >> Sun-Fire-V440. >> >> I changed only the release of MS, without changing any >> configuration >> parameter; the cpu load average >> has changed from 2.5/3 to 1.2/1.6. >> >> It seems to be really faster than previous MS. >> >> >> Have you looked at the delay times in the logs from Sendmail? Do >> you see a similar decrease there? >> >> -- > > I've investigated in the syslog, but the delay is strictly > connected to the batch delay, so I do not understand how I can see > a real speed-up if most of the delay is directly accountable to > the batch waiting. > (maybe i'm wrong) Sorry, but I think you are. There is no "batch waiting" delay. That would have been silly. When a child worker process looks at the queue (each child does it every second or so, and there are lots of children running) it always takes whatever complete messages are there, regardless of the fact that there may only be 1. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ7zoQvw32o+k+q+hAQEVggf/XLbXM4BcksU1mVnbdUMWPBhs8Yt2ojYn 7QTFv7Jw5DteolgW1FMakXx5aYLFfMHoU4+JgKM1bH9FLqlMGCrE0EikX8seGQer Tn6Uv7aj8ED6A8kOVzbmhoaKWSQSv2VtuVcWxQDmWeWG/2Yczi48EK+htwDVcTGO qmjY39ZR2BdFSSKTuX0CNcu89HhuemvYOcYX+n/H+gWCTZuNPZQ3nHn9Ugg8cAyJ 7U3dhzO0ATlN3YumqS4MQPqqEpELTFB9Ha/S+UmPE9PlPNkrbo1nzPk3yB5oqCDs syB4h3tjOwgYFR7BXIydetWV5AlNlKx8nlUAwmCnydd2jZeTR4iitw== =3H1T -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Thu Jan 5 09:38:52 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/5/06, Julian Field wrote: On 4 Jan 2006, at 22:35, shuttlebox wrote: On 1/4/06, Julian Field < MailScanner@ecs.soton.ac.uk> wrote: It looks at the message body to see if it has seen this message before. If it has, it grabs all the SpamAssassin results out of a cache and doesn't call SpamAssassin at all for this message. How does it determine that, by MD5 or similar? Is only the checksum stored in the db or the whole body? MD5, Only the checksum. Ok, sounds excellent. Am I right in that this has been discussed on the list before? Caching SA results I mean. We asked, you delivered. :-) I noticed that you in the change log say under Fixes: "Improved reliability of Bayes rebuilds a lot". Do you now use SQLite for Bayes too? Theoretically that should be possible since SA does support it. Is the fix something totally different? Totally different. It's a very small change so that children doing the Bayes rebuild die immediately after completing it, they don't continue to live after that. It's solving problems like this, that I did the "worker children" architecture in the first place :-) Ok, if I ever get time I will look into using SQLite for Bayes. I want to thank you for going with SQLite and not forcing us to have MySQL or something similar on every MS server, good design decision I think. Could you update the version output from MailScanner so it shows the new required modules as well? In another thread someone posted his version output and it lacked the new modules. Or does that mean he failed to install them? When I have a missing required module the command breaks horribly. It would be nice if it just noted them as missing (as with the not required ones), I understand that you of course can't start MS then but it would help to see it missing in clear text, not everyone understands the perl output. -- /Peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From rabellino at DI.UNITO.IT Thu Jan 5 09:44:10 2006 From: rabellino at DI.UNITO.IT (Rabellino Sergio) Date: Thu Jan 12 21:31:38 2006 Subject: Perl SqLite Module and Solaris Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Dear list, i'm going to test the latest release, but installing the SqLite module on my solaris 9 box, i've got a problem: the module bundled with MS is missing a link library in the Makefile (-lrt). I've solved this trouble, doing the usual >perl Makefile.PL then editing the resultant Makefile, adding "-lrt" to the LDFLAGS and LDDFLAGS variable (before doing the make command...). Now the "make test" is successful. Bye. -- Dott. Mag. Sergio Rabellino Technical Staff Department of Computer Science University of Torino (Italy) http://www.di.unito.it/~rabser Tel. +39-0116706701 Fax. +39-011751603 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From raymond at PROLOCATION.NET Thu Jan 5 09:42:26 2006 From: raymond at PROLOCATION.NET (Raymond Dijkxhoorn) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: Hi! >> - spam after 6 hours from the initial creation of the cache record. > > Steve ---- What say we change 6 hours to 3 hours, and add high-spam > expiry 6 hours from the "first" time? That should be nothing more > than 1 change to the expiry function. > Can you work out the SQL for me please? Been chatting with Steve last night, he promised to rewrite some code when he would wake up :) So far its going just fine. I hope it will be configurable, would really help. High spam is perfect as it is now, low spam we want to get higher once they are learned... so a really low timeout to cut out the first batfhes is fine, after that i want to recheck if its not added to more RBLs. So for us low spam caching could even have a 5-10 mins expire... Bye, Raymond. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 5 11:00:53 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:38 2006 Subject: Perl SqLite Module and Solaris Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Can you add this to the wiki please? Most Solaris admins know what they're doing, fortunately. Editing makefiles automatically isn't something I want to get into. On 5 Jan 2006, at 09:44, Rabellino Sergio wrote: > Dear list, > i'm going to test the latest release, but installing the SqLite > module on my solaris 9 box, i've got a problem: > > the module bundled with MS is missing a link library in the > Makefile (-lrt). > > I've solved this trouble, doing the usual > >perl Makefile.PL > > then editing the resultant Makefile, adding "-lrt" to the LDFLAGS > and LDDFLAGS variable (before doing the make command...). > Now the "make test" is successful. > > Bye. > -- > > Dott. Mag. Sergio Rabellino > Technical Staff > Department of Computer Science > University of Torino (Italy) > > http://www.di.unito.it/~rabser > Tel. +39-0116706701 > Fax. +39-011751603 > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ7z8Z/w32o+k+q+hAQGw8Af/RRKrj4qUE+0q7S+bLTIPDpc02MIf4ZZH dYlDSOIb2DhciOrc9QhR0ds9lGsrNgxpooGxzJYT0p/WKzcj/zACeOR4pv50HiEa 4gBF8opp2lwou38z7SVDlhtSMfdcJJ5SbSdq4/f/d5k2CMa/tKKCjJP8r0Cpvkf+ tZ+xw3KmWnRg/79FcG65dUHxgkfjolLrLxcESdwCetBHs/Avy5r3+yYkRstnFHZz yMreVrsuPhTWbOGduQiQwtJMmW72WJIyPN9xHTR3POKSn2CnWErZtVuY3ebYmxJl LfxhFZm8MEQe2lq/nIfDya79+pPeTUt10m3HHky4AvFjiD8hV5wq5w== =Dr3r -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 5 10:59:28 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 5 Jan 2006, at 09:42, Raymond Dijkxhoorn wrote: > Hi! > >>> - spam after 6 hours from the initial creation of the cache record. >> >> Steve ---- What say we change 6 hours to 3 hours, and add high-spam >> expiry 6 hours from the "first" time? That should be nothing more >> than 1 change to the expiry function. >> Can you work out the SQL for me please? > > Been chatting with Steve last night, he promised to rewrite some > code when he would wake up :) > > So far its going just fine. > > I hope it will be configurable, would really help. High spam is > perfect as it is now, low spam we want to get higher once they are > learned... so a really low timeout to cut out the first batfhes is > fine, after that i want to recheck if its not added to more RBLs. > So for us low spam caching could even have a 5-10 mins expire... I would like to get a set of timeouts we basically agree on, then leave them set at that. No-one will ever actually change the values we supply, so I see no great reason to make the conf file any bigger than it already is. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ7z8E/w32o+k+q+hAQGLLwf+MGT14TZBDWuPmqheTSXl1sNUnw9qreHB LCh1jRODJf96VyMBleuWztlZilOXaI45cPD8WUv8bdCHehhpilcSXQfYCLOFZSfG uzrg01Vd3RSQmECuwEw+rO1RmCbJzthFOd32MMzu53qRGVIhPFD58gLynOxO2SEW vsW7sr5MYlzx8pcM4O68HxSs4DPX3BoHzHiCF4vkHwiqcrC5AStcv8z0JWD4h/bz UcgKZZ5jyz1r0zDOmyhswWj/avHSGI9Ug2Ak3PH3oKFMpbO2kMq+De1gGE7D87vU 2J9qNQvSvKjlOB2nTUtVVyBbhuJS3Kd3d+tg8PONT8/i0+HOAQrEFA== =qLwL -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From rabellino at DI.UNITO.IT Thu Jan 5 10:21:46 2006 From: rabellino at DI.UNITO.IT (Rabellino Sergio) Date: Thu Jan 12 21:31:38 2006 Subject: MailScanner ANNOUNCE: Stable 4.49 released -- faster! Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Julian Field wrote: >-----BEGIN PGP SIGNED MESSAGE----- > > >On 5 Jan 2006, at 09:18, Rabellino Sergio wrote: > > > >>shuttlebox wrote: >> >> >> >>>On 1/4/06, *Rabellino Sergio* >>> wrote: >>> >>> We've sendmail 8.13.3, with mcafee/clamav/sa ona Solaris 9 /4- >>>cpu/ >>> Sun-Fire-V440. >>> >>> I changed only the release of MS, without changing any >>>configuration >>> parameter; the cpu load average >>> has changed from 2.5/3 to 1.2/1.6. >>> >>> It seems to be really faster than previous MS. >>> >>> >>>Have you looked at the delay times in the logs from Sendmail? Do >>>you see a similar decrease there? >>> >>>-- >>> >>> >>I've investigated in the syslog, but the delay is strictly >>connected to the batch delay, so I do not understand how I can see >>a real speed-up if most of the delay is directly accountable to >>the batch waiting. >>(maybe i'm wrong) >> >> > >Sorry, but I think you are. There is no "batch waiting" delay. That >would have been silly. When a child worker process looks at the queue >(each child does it every second or so, and there are lots of >children running) it always takes whatever complete messages are >there, regardless of the fact that there may only be 1. >- -- > > Received ! I've checked the logs : the delay is substantially unchanged, the values are between 25-40 secs (I've 2 viruses check, so i'm expecting a delay, but this is too high ??). Bye. -- Dott. Mag. Sergio Rabellino Technical Staff Department of Computer Science University of Torino (Italy) http://www.di.unito.it/~rabser Tel. +39-0116706701 Fax. +39-011751603 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 5 10:57:11 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 5 Jan 2006, at 09:38, shuttlebox wrote: > > Ok, if I ever get time I will look into using SQLite for Bayes. I > want to thank you for going with SQLite and not forcing us to have > MySQL or something similar on every MS server, good design decision > I think. Could you update the version output from MailScanner so it > shows the new required modules as well? Already done, will be in the next release. If you try to use this feature, and don't have the modules installed, it will log the fact and switch the feature off for you. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ7z7ifw32o+k+q+hAQEBeAgApfxo3Uv+2M9GQdPmMr7mZgL/rNHNl7Rd XSSUTO8d4Pekmqics1PQ/+Ol2XepSQAsHruIRb+2+2J/KPiXdz9BukPjdNrssmli hVJZ1qKOrh939I+Ka5x4RnjurFC9++RvY/ryeX+LIWhWEc+ZITBZFlxT+5aOgOPj 9NjRQqImMGWBj5UvzxwylHmJdhduZ+YMvJMLeMGYkzN6E+jnlkSU8L6cDwd4rSQz kERiNjOzqJD+GrIUXj6VIUyRk/cbRYCgmbc0kKjbBxJhh1SsaiwXfETi7OlllRC1 Guh5hUX6X/1rV0VxdgK1nnSb3W6Ai1caXVOMg4osBl79ckurkY55qQ== =NGUv -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From james at grayonline.id.au Thu Jan 5 11:01:45 2006 From: james at grayonline.id.au (James Gray) Date: Thu Jan 12 21:31:38 2006 Subject: 4.50.4 restarts the child after each batch? Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Thu, 5 Jan 2006 18:59, Raymond Dijkxhoorn wrote: > Hi! > > >> Just installed 4.49.7 on my production gateways - all is well. They > >> are behaving as I expected them to. > > > > What happens when you run it in Debug mode in the foreground? > > You had trouble installing SQLite. See other postings on the list. Either > disable the new feature or install the missing stuff :) > > You had some modules failling during install. Thats why, had the same > last night. > > Bye, > Raymond. Care to shed any more light Raymond? I'm not seeing any errors in any log (not even in debug mode) that indicate failed modules etc. Not say there aren't any problems - just that silent errors are a pain to track down. I didn't notice any failures during the installation either. Which modules did you have to fix up? How did you do it - Julian's installer? CPAN? Channelled the spirits of deceased developers? ;) Gotta lay off the single malt when mailing to technical lists. Seriously, any help is very much appreciated :) Cheers, James -- Never trust an operating system you don't have sources for. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From james at grayonline.id.au Thu Jan 5 10:58:09 2006 From: james at grayonline.id.au (James Gray) Date: Thu Jan 12 21:31:38 2006 Subject: 4.50.4 restarts the child after each batch? Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Thu, 5 Jan 2006 18:32, Matt Hampton wrote: > James Gray wrote: > >Just installed 4.49.7 on my production gateways - all is well. They are > >behaving as I expected them to. > > What happens when you run it in Debug mode in the foreground? #/etc/init.d/mailscanner start Starting MailScanner... In Debugging mode, not forking... Ignore errors about failing to find EOCD signature Undefined subroutine &MailScanner::CustomConfig::MailWatchLogging called at /opt/MailScanner/lib/MailScanner/Config.pm line 121. and in /var/log/maillog: 21:47:52 ninja MailScanner[27164]: MailScanner E-Mail Virus Scanner version 4.50.4 starting... 21:47:53 ninja MailScanner[27164]: Read 695 hostnames from the phishing whitelist 21:47:53 ninja MailScanner[27164]: Config: calling custom init function MailWatchLogging 21:47:54 ninja MailScanner[27164]: Caching SpamAssassin results 21:47:54 ninja MailScanner[27164]: Connected to SpamAssassin cache database 21:47:55 ninja MailScanner[27164]: Enabling SpamAssassin auto-whitelist functionality... 21:48:13 ninja MailScanner[27164]: lock.pl sees Config LockType = posix 21:48:13 ninja MailScanner[27164]: lock.pl sees have_module = 0 21:48:13 ninja MailScanner[27164]: Using locktype = posix 21:48:13 ninja MailScanner[27164]: Creating hardcoded struct_flock subroutine for linux (Linux-type) 21:48:13 ninja MailScanner[27164]: New Batch: Scanning 2 messages, 2578 bytes 21:48:13 ninja MailScanner[27164]: Created attachment dirs for 2 messages 21:48:13 ninja MailScanner[27164]: MCP Checks completed at 2578 bytes per second 21:48:13 ninja MailScanner[27164]: Spam Checks: Starting 21:48:13 ninja MailScanner[27164]: Message 1EuSdY-00073K-5O from 10.0.0.3 (mymail@example.com) is whitelisted 21:48:22 ninja MailScanner[27164]: SpamAssassin returned 0 21:48:22 ninja MailScanner[27164]: Message 1EuSdY-00073K-5O from 10.0.0.3 (mymail@example.com) to my-work.domain.com is not spam (whitelisted), SpamAssassin (score=-5.899, required 5, autolearn=not spam, ALL_TRUSTED -3.30, BAYES_00 -2.60) 21:48:22 ninja MailScanner[27164]: Message 1EuSf3-00074K-2Y from 10.0.0.3 (mymail@example.com) is whitelisted 21:48:22 ninja MailScanner[27164]: Cache hit for message 1EuSf3-00074K-2Y 21:48:22 ninja MailScanner[27164]: Message 1EuSf3-00074K-2Y from 10.0.0.3 (mymail@example.com) to my-work.domain.com is not spam (whitelisted), SpamAssassin (score=-5.899, required 5, autolearn=not spam, ALL_TRUSTED -3.30, BAYES_00 -2.60) 21:48:22 ninja MailScanner[27164]: Spam Checks completed at 286 bytes per second 21:48:22 ninja MailScanner[27164]: Virus and Content Scanning: Starting 21:48:22 ninja MailScanner[27164]: Commencing scanning by mcafee... 21:48:25 ninja MailScanner[27164]: Completed scanning by mcafee 21:48:25 ninja MailScanner[27164]: Commencing scanning by clamavmodule... 21:48:25 ninja MailScanner[27164]: Completed scanning by clamavmodule 21:48:25 ninja MailScanner[27164]: Completed checking by /usr/bin/file 21:48:25 ninja MailScanner[27164]: Virus Scanning completed at 859 bytes per second 21:48:25 ninja MailScanner[27164]: About to deliver 2 messages 21:48:25 ninja MailScanner[27164]: Uninfected: Delivered 2 messages 21:48:25 ninja MailScanner[27164]: Virus Processing completed at 2578 bytes per second 21:48:26 ninja MailScanner[27164]: Disinfection completed at 2578 bytes per second 21:48:26 ninja MailScanner[27164]: Batch completed at 198 bytes per second (2578 / 13) At this point the MailWatch loggin would kick in but it barfs when MailScanner is in debug mode. So we don't actually get to see it killing off the child and spawning a new one.... so we rinse and repeat WITHOUT Mailwatch (notice the syntax error reported in maillog) :) #/etc/init.d/mailscanner start Starting MailScanner... In Debugging mode, not forking... Ignore errors about failing to find EOCD signature Stopping now as you are debugging me. /var/log/maillog: 21:52:29 ninja MailScanner[27369]: MailScanner E-Mail Virus Scanner version 4.50.4 starting... 21:52:30 ninja MailScanner[27369]: Syntax error in line 1964, value "" for lastlookup is not one of allowed values "yes","no" 21:52:30 ninja MailScanner[27369]: Read 695 hostnames from the phishing whitelist 21:52:32 ninja MailScanner[27369]: Caching SpamAssassin results 21:52:32 ninja MailScanner[27369]: Connected to SpamAssassin cache database 21:52:32 ninja MailScanner[27369]: Expired 2 records from the SpamAssassin cache 21:52:32 ninja MailScanner[27369]: Enabling SpamAssassin auto-whitelist functionality... 21:52:48 ninja MailScanner[27369]: lock.pl sees Config LockType = posix 21:52:48 ninja MailScanner[27369]: lock.pl sees have_module = 0 21:52:48 ninja MailScanner[27369]: Using locktype = posix 21:52:48 ninja MailScanner[27369]: Creating hardcoded struct_flock subroutine for linux (Linux-type) 21:53:18 ninja MailScanner[27369]: New Batch: Scanning 1 messages, 1289 bytes 21:53:18 ninja MailScanner[27369]: Created attachment dirs for 1 messages 21:53:18 ninja MailScanner[27369]: MCP Checks completed at 1289 bytes per second 21:53:18 ninja MailScanner[27369]: Spam Checks: Starting 21:53:18 ninja MailScanner[27369]: Message 1EuSk8-00077e-42 from 10.0.0.3 (mymail@example.com) is whitelisted 21:53:18 ninja MailScanner[27369]: Cache hit for message 1EuSk8-00077e-42 21:53:18 ninja MailScanner[27369]: Message 1EuSk8-00077e-42 from 10.0.0.3 (mymail@example.com) to my-work.domain.com is not spam (whitelisted), SpamAssassin (score=-5.899, required 5, autolearn=not spam, ALL_TRUSTED -3.30, BAYES_00 -2.60) 21:53:18 ninja MailScanner[27369]: Spam Checks completed at 1289 bytes per second 21:53:18 ninja MailScanner[27369]: Virus and Content Scanning: Starting 21:53:18 ninja MailScanner[27369]: Commencing scanning by mcafee... 21:53:20 ninja MailScanner[27369]: Completed scanning by mcafee 21:53:20 ninja MailScanner[27369]: Commencing scanning by clamavmodule... 21:53:21 ninja MailScanner[27369]: Completed scanning by clamavmodule 21:53:21 ninja MailScanner[27369]: Completed checking by /usr/bin/file 21:53:21 ninja MailScanner[27369]: Virus Scanning completed at 429 bytes per second 21:53:21 ninja MailScanner[27369]: About to deliver 1 messages 21:53:21 ninja MailScanner[27369]: Uninfected: Delivered 1 messages 21:53:21 ninja MailScanner[27369]: Virus Processing completed at 1289 bytes per second 21:53:21 ninja MailScanner[27369]: Disinfection completed at 1289 bytes per second 21:53:21 ninja MailScanner[27369]: Batch completed at 429 bytes per second (1289 / 3) 21:53:21 ninja MailScanner[27369]: MailScanner child dying of old age Cheers, James -- Lookie, lookie, here comes cookie... -- Stephen Sondheim ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From chris at scorpion.nl Thu Jan 5 11:08:46 2006 From: chris at scorpion.nl (Christiaan den Besten) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] > I would like to get a set of timeouts we basically agree on, then > leave them set at that. No-one will ever actually change the values > we supply, so I see no great reason to make the conf file any bigger > than it already is. Jules, Like some of the other SA settings (value for low/high spam) the expire settings for low/high spam are very site specific. As Raymond tried to explain: e-mail body's are analysed by automated tools. This usually leadd to some url's being added to a URIBL. The URIBL will be updated once every couple of minutes. After that -the same message body- would be tagged higher by SA ..... I suppose the same is valid for bayes. If the same message passes the filter more often, it should get a higher bayes value. So, having a lower expire timeout on lowspam messages can be 'required' for some setups. But other, who use less dynamic SA lists probably could cope with a higher value ... bye, Chris > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.3 (Build 2932) > > iQEVAwUBQ7z8E/w32o+k+q+hAQGLLwf+MGT14TZBDWuPmqheTSXl1sNUnw9qreHB > LCh1jRODJf96VyMBleuWztlZilOXaI45cPD8WUv8bdCHehhpilcSXQfYCLOFZSfG > uzrg01Vd3RSQmECuwEw+rO1RmCbJzthFOd32MMzu53qRGVIhPFD58gLynOxO2SEW > vsW7sr5MYlzx8pcM4O68HxSs4DPX3BoHzHiCF4vkHwiqcrC5AStcv8z0JWD4h/bz > UcgKZZ5jyz1r0zDOmyhswWj/avHSGI9Ug2Ak3PH3oKFMpbO2kMq+De1gGE7D87vU > 2J9qNQvSvKjlOB2nTUtVVyBbhuJS3Kd3d+tg8PONT8/i0+HOAQrEFA== > =qLwL > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From adrik at SALESMANAGER.NL Thu Jan 5 12:02:23 2006 From: adrik at SALESMANAGER.NL (Adri Koppes) Date: Thu Jan 12 21:31:38 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: > From: MailScanner mailing list > [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Christiaan den Besten > Sent: donderdag 5 januari 2006 12:09 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: Beta 4.50.4 released -- faster than 4.49 > > > I would like to get a set of timeouts we basically agree on, then > > leave them set at that. No-one will ever actually change > the values we > > supply, so I see no great reason to make the conf file any > bigger than > > it already is. > > Jules, > > Like some of the other SA settings (value for low/high spam) > the expire settings for low/high spam are very site specific. > As Raymond tried to explain: e-mail body's are analysed by > automated tools. This usually leadd to some url's being added > to a URIBL. > The URIBL will be updated once every couple of minutes. After > that -the same message body- would be tagged higher by SA > ..... I suppose the same is valid for bayes. If the same > message passes the filter more often, it should get a higher > bayes value. > > So, having a lower expire timeout on lowspam messages can be > 'required' for some setups. But other, who use less dynamic > SA lists probably could cope with a higher value ... Jules, Something else you might consider implementing, is not to cache or cache with a low timeout, the results when the message is auto-learned by bayes. Since bayes has learned from the message, it will probably affect the score of the next message, unless the score is already sufficiently high enough or low enough for the spam result not be affected by a diffirent bayes score. Adri. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From prandal at HEREFORDSHIRE.GOV.UK Thu Jan 5 12:35:33 2006 From: prandal at HEREFORDSHIRE.GOV.UK (Randal, Phil) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: Adri Koppes wrote: >> Jules, >> >> Like some of the other SA settings (value for low/high spam) the >> expire settings for low/high spam are very site specific. >> As Raymond tried to explain: e-mail body's are analysed by automated >> tools. This usually leadd to some url's being added to a URIBL. >> The URIBL will be updated once every couple of minutes. After that >> -the same message body- would be tagged higher by SA ..... I suppose >> the same is valid for bayes. If the same message passes the filter >> more often, it should get a higher bayes value. >> >> So, having a lower expire timeout on lowspam messages can be >> 'required' for some setups. But other, who use less dynamic SA lists >> probably could cope with a higher value ... > > Jules, > > Something else you might consider implementing, is not to > cache or cache with a low timeout, the results when the > message is auto-learned by bayes. > Since bayes has learned from the message, it will probably > affect the score of the next message, unless the score is > already sufficiently high enough or low enough for the spam > result not be affected by a diffirent bayes score. > > Adri. Not just auto-learning - if I detect a flood of low-scoring spam and manually sa-learn it then I want any new Bayes score to be effective ASAP. With this new infrastructure in place it should be possible to introduce some spam flooding detection into MailScanner. You'd then need a permitted-flooders whitelist too, of course. As a completely unrelated aside, www.mailscanner.info is inaccessible here at the moment. Cheers, Phil ---- Phil Randal Network Engineer Herefordshire Council Hereford, UK ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 5 12:43:08 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.5 released Message-ID: -----BEGIN PGP SIGNED MESSAGE----- I have just released version 4.50.5. This is basically a lot of tidying up done since yesterday's 4.50.4. No dramatic new features. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ70UXvw32o+k+q+hAQHJVgf/eCP3voSq1Oh72JBGi2NoYSRKkikh3Uk2 SOQEoA31UYhJ/a8PDQcg9YTSHDD2Ut5HRWImjU3PmpzHKzKCxYYpX/WVaTVtpfVR +W2GNRdIRsSobnT5KEjlOLNVNQjB/C8CSw5lbXXCBmc9y1QwAE1Ljvvx2oOgoS4U 4pobluFkKOU3yVfJLYFndd0C6PekJtzdiOkxoeTR57s8zeLfMTWMdRViW5szBh69 cDy8PW09YRwM/RwgJr+wjVXgRc+8Ywz9nlhG+jmS2skoSCLnEER5R9A0ZHagJgfj VSgG2aCjv7X3DUhwXY5ywj28RrtoTWTd/LfkjxO45qcpcIi0fR0KJw== =AU7d -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From raymond at PROLOCATION.NET Thu Jan 5 13:00:57 2006 From: raymond at PROLOCATION.NET (Raymond Dijkxhoorn) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: Hi! > Something else you might consider implementing, is not to cache or cache > with a low timeout, the results when the message is auto-learned by > Since bayes has learned from the message, it will probably affect the > score of the next message, unless the score is already sufficiently high > enough or low enough for the spam result not be affected by a diffirent > bayes score. Same idea as with URIBL, most likely low spam will be auto added to SURBL pretty fast after detection, most of the time within 5-10 mins. Can you please consider putting the values in the config? I really see use for this. Bye, Raymond. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From adrik at SALESMANAGER.NL Thu Jan 5 13:05:32 2006 From: adrik at SALESMANAGER.NL (Adri Koppes) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: Hi Raymond, > From: MailScanner mailing list > [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Raymond Dijkxhoorn > Sent: donderdag 5 januari 2006 14:01 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: Beta 4.50.4 released -- faster than 4.49 > > Hi! > > > Something else you might consider implementing, is not to cache or > > cache with a low timeout, the results when the message is > auto-learned > > by Since bayes has learned from the message, it will > probably affect > > the score of the next message, unless the score is already > > sufficiently high enough or low enough for the spam result not be > > affected by a diffirent bayes score. > > Same idea as with URIBL, most likely low spam will be auto > added to SURBL pretty fast after detection, most of the time > within 5-10 mins. Problem with URIBL is MailScanner has no idea if and when SURBL will add those! With bayes, MailScanner know if SA has auto-learned the message. Only option I see is to add messages without any URIBL hits with a lower timeout then messages which have already had one or more URIBL hits in their SA-score. Same could probably be done with RBL hits. Adri. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Dave Thu Jan 5 13:13:12 2006 From: Dave (Dave) Date: Thu Jan 12 21:31:39 2006 Subject: MailScanner version 5 Message-ID: Just curious, what will it take for MailScanner to go to version 5? -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From raymond at PROLOCATION.NET Thu Jan 5 13:09:10 2006 From: raymond at PROLOCATION.NET (Raymond Dijkxhoorn) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: Hi! >> Same idea as with URIBL, most likely low spam will be auto >> added to SURBL pretty fast after detection, most of the time >> within 5-10 mins. > Problem with URIBL is MailScanner has no idea if and when SURBL will add > those! > With bayes, MailScanner know if SA has auto-learned the message. > Only option I see is to add messages without any URIBL hits with a lower > timeout then messages which have already had one or more URIBL hits in > their SA-score. Same could probably be done with RBL hits. Its in my eyes again comming to the same basic point, low spam you want to do different things with, so the score can reach the high value in some time. Bayes is one of them... Bye, Raymond. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From raymond at PROLOCATION.NET Thu Jan 5 13:29:07 2006 From: raymond at PROLOCATION.NET (Raymond Dijkxhoorn) Date: Thu Jan 12 21:31:39 2006 Subject: MailScanner version 5 Message-ID: Hi! > Just curious, what will it take for > MailScanner to go to version 5? I want MailScanner XP, Oh MailScanner 2005... uh its just a number :) Bye, Raymond. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Dave Thu Jan 5 13:44:24 2006 From: Dave (Dave) Date: Thu Jan 12 21:31:39 2006 Subject: MailScanner version 5 Message-ID: On Thu, Jan 05, 2006 at 02:29:07PM +0100, Raymond Dijkxhoorn wrote: > Hi! > > >Just curious, what will it take for > >MailScanner to go to version 5? > > I want MailScanner XP, Oh MailScanner 2005... uh its just a number :) > Are you familiar with Version Numbering contril? > Bye, > Raymond. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From raymond at PROLOCATION.NET Thu Jan 5 13:53:06 2006 From: raymond at PROLOCATION.NET (Raymond Dijkxhoorn) Date: Thu Jan 12 21:31:39 2006 Subject: MailScanner version 5 Message-ID: Hi! >>> Just curious, what will it take for >>> MailScanner to go to version 5? >> I want MailScanner XP, Oh MailScanner 2005... uh its just a number :) > Are you familiar with Version Numbering contril? Yes i am, this posting was more or less /ignore. If you see the version numbers of the last months its one stabil each month. Was there a real need to know for V5? I mean, more or less thats what most vendors do when announcing major design changes. Bye, Raymond. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From martinh at SOLID-STATE-LOGIC.COM Thu Jan 5 14:00:52 2006 From: martinh at SOLID-STATE-LOGIC.COM (Martin Hepworth) Date: Thu Jan 12 21:31:39 2006 Subject: MailScanner version 5 Message-ID: Raymond Well that used to be the case, now it's merely speak for next version.... (first major occurrance of this was Solaris 2.6 to 7 'cos every one else had larger v numbers - AIX 5, HPUX 10..etc) -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Raymond Dijkxhoorn > Sent: 05 January 2006 13:53 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: [MAILSCANNER] MailScanner version 5 > > Hi! > > >>> Just curious, what will it take for > >>> MailScanner to go to version 5? > > >> I want MailScanner XP, Oh MailScanner 2005... uh its just a number :) > > > Are you familiar with Version Numbering contril? > > Yes i am, this posting was more or less /ignore. > > If you see the version numbers of the last months its one stabil each > month. > > Was there a real need to know for V5? I mean, more or less thats what most > vendors do when announcing major design changes. > > Bye, > Raymond. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From chris at scorpion.nl Thu Jan 5 14:14:51 2006 From: chris at scorpion.nl (Christiaan den Besten) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] You are missing the point :) The point is ... 'in time' the SA score would be different from the cached one when re-testing the same message body. (for example due to some url's found in the message body to be put into a spam URIBL after detection). If these messages are initialy tagged as 'low spam', but with the new circumstances would have been tagged as 'high spam' you do not want these messages to still be tagged as 'low spam' cause that is the value currently in the cache. bye, Chris ----- Original Message ----- From: shuttlebox To: MAILSCANNER@JISCMAIL.AC.UK Sent: Thursday, January 05, 2006 3:06 PM Subject: Re: Beta 4.50.4 released -- faster than 4.49 On 1/5/06, Raymond Dijkxhoorn wrote: Its in my eyes again comming to the same basic point, low spam you want to do different things with, so the score can reach the high value in some time. Bayes is one of them... Is this a problem locally also or only with reporting to RBL:s and such? If you parse logs for reporting to them can't the parsing be adjusted instead of complicating things for MS? Is there something missing from the logs to get the required info? Maybe Julian can add from which message the cache hit came from? Or am I missing the point? -- /Peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dhawal at NETMAGICSOLUTIONS.COM Thu Jan 5 14:24:31 2006 From: dhawal at NETMAGICSOLUTIONS.COM (Dhawal Doshy) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Rick Cooper wrote: > [...] >> I would think if caching is going to be implemented there needs to be a >> command line, or separate program, that will allow the admin to flush the >> cache at will. For this very reason. Assuming (I haven't looked at the new >> releases) that the spam, virus, etc caches are in different >> tables, I would >> think a way to flush one, or all should be implemented, for the >> very reasons >> described above. Not to mention, for instance, suppose a message >> is flagged >> as spam and a user requests the sender be whitelisted? Again not having >> looked at the code, what happens if the sender resends the exact same >> message expecting it to come through again *to that user*? Ok, I >> just looked > [...] > > I hate replying to myself but... > > Right after I hit the send button I wonder if MS was logging the MD5 > information? If it is I would think it would be trivial for the MailWatch > author(s) to add it to their database information and allow the MailWatch > users to remove the information via MailWatch... just a thought See http://wiki.mailscanner.info/doku.php?id=custom_config, the hard-workers behind the speed-ups, i guess. - dhawal ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From rcooper at DWFORD.COM Thu Jan 5 14:11:03 2006 From: rcooper at DWFORD.COM (Rick Cooper) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK]On > Behalf Of Randal, Phil > Sent: Thursday, January 05, 2006 7:36 AM > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: Beta 4.50.4 released -- faster than 4.49 > [...] > > Not just auto-learning - if I detect a flood of low-scoring spam and > manually sa-learn it then I want any new Bayes score to be effective > ASAP. > > With this new infrastructure in place it should be possible to introduce > some spam flooding detection into MailScanner. You'd then need a > permitted-flooders whitelist too, of course. > > As a completely unrelated aside, www.mailscanner.info is inaccessible > here at the moment. > I would think if caching is going to be implemented there needs to be a command line, or separate program, that will allow the admin to flush the cache at will. For this very reason. Assuming (I haven't looked at the new releases) that the spam, virus, etc caches are in different tables, I would think a way to flush one, or all should be implemented, for the very reasons described above. Not to mention, for instance, suppose a message is flagged as spam and a user requests the sender be whitelisted? Again not having looked at the code, what happens if the sender resends the exact same message expecting it to come through again *to that user*? Ok, I just looked at the table creation code and do not see a sender address, so if I add the sender to an SA whitelist how do I tell MS to updated or ignore the cache? Perhaps if the sender address is added to the cache information then a utility could be developed fairly easily that would allow the system admin to run it with a sender address and have the cache record flagged as recheck or, removed all together, for any cached information relating to that sender address? It would appear that since the table is created any time it is missing, flushing the cache would be as simple as removing the table and restarting MS. Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Thu Jan 5 14:06:58 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/5/06, Raymond Dijkxhoorn wrote: Its in my eyes again comming to the same basic point, low spam you want to do different things with, so the score can reach the high value in some time. Bayes is one of them... Is this a problem locally also or only with reporting to RBL:s and such? If you parse logs for reporting to them can't the parsing be adjusted instead of complicating things for MS? Is there something missing from the logs to get the required info? Maybe Julian can add from which message the cache hit came from? Or am I missing the point? -- /Peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Thu Jan 5 14:14:44 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:39 2006 Subject: MailScanner version 5 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/5/06, Raymond Dijkxhoorn wrote: Was there a real need to know for V5? I mean, more or less thats what most vendors do when announcing major design changes. I guess if Julian would rewrite MS and make it modularized where we could choose which modules (virus, spam, file name, ...) to use and in which order then he would probably call it 5. Now there's lots of incremental changes that we all can use without starting over so I see no reason for the first number to change. As you said, it's just a number and since Julian is not an evil empire needing to impress the weak there's no need for "impressive" numbers. :-) -- /Peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From prandal at HEREFORDSHIRE.GOV.UK Thu Jan 5 14:21:20 2006 From: prandal at HEREFORDSHIRE.GOV.UK (Randal, Phil) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: Raymond Dijkxhoorn wrote: > Its in my eyes again comming to the same basic point, low > spam you want to do different things with, so the score can > reach the high value in some time. Bayes is one of them... How we should behave could depend on our high/low spam score actions, too. If we quarantine but don't deliver low score spam, then it doesn't matter so much that it isn't having its score ramped up by Bayes learning, except that Bayes learning could help push future variations of that spam from ham to spam scores. Which leads me to think that while spamassassin is flagging mails as "autolearn=spam" they shouldn't be cached. Though if they are high-scoring already we could still cache them without materially affecting the Bayesian stuff. The other thing which occurs to me as highly desirable is a "service MailScanner flushcache" parameter, and possibly a "flush cache on restart" option in MailScanner.conf, so we can flush the cache after changing Spamassassin rules (either manually or automatically in a RulesDuJour type script). The last thing we want is to create a broken rule which flags mail from a legitimate mailing list as spam, discover our error, correct it, and still have straggling emails from that mailing list (to different recipients) being flagged erroneously as spam. Aren't cache coherency issues fun? Cheers, Phil ---- Phil Randal Network Engineer Herefordshire Council Hereford, UK ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From rcooper at DWFORD.COM Thu Jan 5 14:21:07 2006 From: rcooper at DWFORD.COM (Rick Cooper) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK]On > Behalf Of Rick Cooper > Sent: Thursday, January 05, 2006 9:11 AM > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: Beta 4.50.4 released -- faster than 4.49 > > [...] > I would think if caching is going to be implemented there needs to be a > command line, or separate program, that will allow the admin to flush the > cache at will. For this very reason. Assuming (I haven't looked at the new > releases) that the spam, virus, etc caches are in different > tables, I would > think a way to flush one, or all should be implemented, for the > very reasons > described above. Not to mention, for instance, suppose a message > is flagged > as spam and a user requests the sender be whitelisted? Again not having > looked at the code, what happens if the sender resends the exact same > message expecting it to come through again *to that user*? Ok, I > just looked [...] I hate replying to myself but... Right after I hit the send button I wonder if MS was logging the MD5 information? If it is I would think it would be trivial for the MailWatch author(s) to add it to their database information and allow the MailWatch users to remove the information via MailWatch... just a thought Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From rabellino at DI.UNITO.IT Thu Jan 5 15:04:38 2006 From: rabellino at DI.UNITO.IT (Rabellino Sergio) Date: Thu Jan 12 21:31:39 2006 Subject: Perl SqLite Module and Solaris Message-ID: Julian Field wrote: >-----BEGIN PGP SIGNED MESSAGE----- > >Can you add this to the wiki please? >Most Solaris admins know what they're doing, fortunately. Editing >makefiles automatically isn't something I want to get into. > > > done, I hope in the right place: under MAQ/spamassassin related question. Bye. -- Dott. Mag. Sergio Rabellino Technical Staff Department of Computer Science University of Torino (Italy) http://www.di.unito.it/~rabser Tel. +39-0116706701 Fax. +39-011751603 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 5 15:08:36 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 5 Jan 2006, at 14:21, Rick Cooper wrote: >> -----Original Message----- >> From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK]On >> Behalf Of Rick Cooper >> Sent: Thursday, January 05, 2006 9:11 AM >> To: MAILSCANNER@JISCMAIL.AC.UK >> Subject: Re: Beta 4.50.4 released -- faster than 4.49 >> >> > [...] >> I would think if caching is going to be implemented there needs to >> be a >> command line, or separate program, that will allow the admin to >> flush the >> cache at will. For this very reason. Assuming (I haven't looked at >> the new >> releases) that the spam, virus, etc caches are in different >> tables, I would >> think a way to flush one, or all should be implemented, for the >> very reasons >> described above. Not to mention, for instance, suppose a message >> is flagged >> as spam and a user requests the sender be whitelisted? Again not >> having >> looked at the code, what happens if the sender resends the exact same >> message expecting it to come through again *to that user*? Ok, I >> just looked > [...] > > I hate replying to myself but... > > Right after I hit the send button I wonder if MS was logging the MD5 > information? If it is I would think it would be trivial for the > MailWatch > author(s) to add it to their database information and allow the > MailWatch > users to remove the information via MailWatch... just a thought $message->{md5} - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ702d/w32o+k+q+hAQEkGAf/W89epLGHfUJr2ubjMvbPIUb14sX9K5GQ OtGXqM2KKerX0eLw5/48SIS3nO/9WYh2df7EsP4rPmUFj2tuIhRH6He/jD+SAP7p zIfOexttIHD1QOxdDM6l5akujqkGSBflz82a4pmg34shLuH5omoggtBJRM/titiB xvmKC0VZ8FwlwFe2PO4JmYtElDRNw+g5dDiWDGMCRcKJxhZeuPyx16GwTRg60VEF gNjoDraq90+UX1oTDxzvoT0LkRzsfXsw6PMQJmqlBzWru6Psv9ZnNACjZMzFPN2v YeJc9VAFAcTQ/e+lOFxNrS1TD9EBfk+LQ5r6MTdQgXo6qEISRfG8OA== =JuUj -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 5 15:06:17 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 5 Jan 2006, at 14:11, Rick Cooper wrote: >> -----Original Message----- >> From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK]On >> Behalf Of Randal, Phil >> Sent: Thursday, January 05, 2006 7:36 AM >> To: MAILSCANNER@JISCMAIL.AC.UK >> Subject: Re: Beta 4.50.4 released -- faster than 4.49 >> > [...] >> >> Not just auto-learning - if I detect a flood of low-scoring spam and >> manually sa-learn it then I want any new Bayes score to be effective >> ASAP. >> >> With this new infrastructure in place it should be possible to >> introduce >> some spam flooding detection into MailScanner. You'd then need a >> permitted-flooders whitelist too, of course. >> >> As a completely unrelated aside, www.mailscanner.info is inaccessible >> here at the moment. >> > > I would think if caching is going to be implemented there needs to > be a > command line, or separate program, that will allow the admin to > flush the > cache at will. For this very reason. Assuming (I haven't looked at > the new > releases) that the spam, virus, etc caches are in different tables, > I would > think a way to flush one, or all should be implemented, for the > very reasons > described above. Not to mention, for instance, suppose a message is > flagged > as spam and a user requests the sender be whitelisted? Again not > having > looked at the code, what happens if the sender resends the exact same > message expecting it to come through again *to that user*? Ok, I > just looked > at the table creation code and do not see a sender address, so if I > add the > sender to an SA whitelist how do I tell MS to updated or ignore the > cache? > Perhaps if the sender address is added to the cache information then a > utility could be developed fairly easily that would allow the > system admin > to run it with a sender address and have the cache record flagged > as recheck > or, removed all together, for any cached information relating to > that sender > address? It would appear that since the table is created any time > it is > missing, flushing the cache would be as simple as removing the > table and > restarting MS. You can flush the cache with this: rm -f /var/spool/MailScanner/incoming/SpamAssassin.cache.db service MailScanner reload - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ7017Pw32o+k+q+hAQHx1wf/SXkq5M5bCT7ONWq6izpbe/TuegmBt95S EicPFN7quTsmTy5jSoF1NMdGs46Xg5gjQnczq5pese6o+c2bsvI9d//aWnpTVDaV XzYVkGryJAiy2kv0gmBpqh6f03SEE35/kA809yZsxPU/HM6UWjFgo6poDBvgEtBe 4hMqsHfP3ShwTBfGRcSGrvexqJPk1HTwEti51C8pL9L8ddeS+a9GgYSv+b7wOY2H wLR/ih1B7g771to+oFRo6fpJ5ZmYxFtnSlTqttl3wvQ9QWsx+rUwWIBNy3hc26NK NkUhUQ0cpfBSnSFPW+RL/gctblNb/ewFOZSZsUIxNTnZSiQYH42AaQ== =zhve -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mkettler at EVI-INC.COM Thu Jan 5 15:51:13 2006 From: mkettler at EVI-INC.COM (Matt Kettler) Date: Thu Jan 12 21:31:39 2006 Subject: All_Trusted Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Kevin Miller wrote: > > Ah, I see what you mean. So having set trusted_networks and > internal_networks per Mail::SpamAssassin::Conf, the ALL_TRUSTED trigger > went away. But is there anything I should be looking at regarding the > Received: header parsing or is that pretty much taken care of now? That's fixed now. Received: header parsing depends on SA's ability to determine which hosts are trusted/internal and which aren't. Without a trusted_networks declared, SA will try to guess, but that guess doesn't work well for networks with NATed mailservers and some other configurations. > Things seem to be flowing OK. Hopefully it's catching more spam than > ever? You should definitely see better performance out of DUL RBLs, and the HELO_DYNAMIC type rules. There's also a good handful of other rules affected by the trust/untrust decisions. > I take it that it would be prudent to check my other MS boxes and rem > out the "score ALL_TRUSTED 0" if it's there? Yes, that would be prudent, as if ALL_TRUSTED is misfiring, it's a sign you need a manual trusted_networks. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From amoore at DEKALBMEMORIAL.COM Thu Jan 5 15:50:02 2006 From: amoore at DEKALBMEMORIAL.COM (Aaron K. Moore) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.5 released Message-ID: Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > I have just released version 4.50.5. > > This is basically a lot of tidying up done since yesterday's 4.50.4. > No dramatic new features. I've saw SQLite mentioned in a few of the posts. Are you just using it for SpamAssassin in your rpm builds, or is it being used for other parts of MailScanner? I switched my SpamAssassin over to using MySQL for both bayes and auto-white listing several months ago. Not only do the bayes rebuilds run faster, I can expire enteries out of the autowhitelist easily based on a last update time. As well as a custom function in MailScanner to log spam and viruses to a sql table for generating a local blacklist. It works much better than trying to process the mail log to build one. -- Aaron Kent Moore Information Technology Services DeKalb Memorial Hospital, Inc. Auburn, IN Phone: 260.920.2808 E-mail: amoore@dekalbmemorial.com ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From michele at BLACKNIGHT.IE Thu Jan 5 15:38:02 2006 From: michele at BLACKNIGHT.IE (Michele Neylon :: Blacknight Solutions) Date: Thu Jan 12 21:31:39 2006 Subject: MailScanner version 5 Message-ID: Or Julian could call the next release "foo" Mr Michele Neylon Blacknight Solutions Hosting & Colocation, Brand Protection http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 UK: 0870 163 0607 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From jase at SENSIS.COM Thu Jan 5 15:56:39 2006 From: jase at SENSIS.COM (Desai, Jason) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > On 5 Jan 2006, at 09:42, Raymond Dijkxhoorn wrote: >> Hi! >> >>>> - spam after 6 hours from the initial creation of the cache record. >>> >> >> Been chatting with Steve last night, he promised to rewrite some >> code when he would wake up :) >> >> So far its going just fine. >> >> I hope it will be configurable, would really help. High spam is >> perfect as it is now, low spam we want to get higher once they are >> learned... so a really low timeout to cut out the first batfhes is >> fine, after that i want to recheck if its not added to more RBLs. >> So for us low spam caching could even have a 5-10 mins expire... > > I would like to get a set of timeouts we basically agree on, then > leave them set at that. No-one will ever actually change the values > we supply, so I see no great reason to make the conf file any bigger > than it already is. Perhaps the cache time could be specified as one of the options for (Spam|High Scoring Spam|Non Spam) Actions? The defaults could be set if nothing were specified. And if someone wanted different times based on certain entries in SpamAssassin report, they could just write a custom function to do so. Ex. - To cache high scoring spam for 10 minutes High Scoring Spam Actions = store delete cache:10 This way you're not really adding more configuration options, just an additional action, and you can default it to what everyone agrees would be sensible. Just a thought. Jase ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mkettler at EVI-INC.COM Thu Jan 5 16:07:36 2006 From: mkettler at EVI-INC.COM (Matt Kettler) Date: Thu Jan 12 21:31:39 2006 Subject: All_Trusted Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] shuttlebox wrote: > On 1/5/06, *Matt Kettler* > wrote: > > It's a good thing the upgrade removed that statement.. setting > ALL_TRUSTED to a > 0 score covers up a lot of serious problems. > > > What kind of problems do you mean? Problems regarding other things than > the trusted mechanism? Just the trusted mechanism, but this affects a LOT of rules in SA. Most rules that examine the Received: headers are affected by trusted_networks or internal_networks. (and if neither is declared, these two are both set to the same guess). For what it's worth, here's a quick rundown of things affected by trust/internal networks detection in SA 3.1.0. affected by internal_networks: All RBLs checks Affected by trusted_networks: whitelist_from_rcvd RCVD_IN_BSP_TRUSTED HABEAS_* ALL_TRUSTED HELO_DYNAMIC_* rules MSGID_FROM_MTA_ID FORGED_*_RCVD rules FAKE_HELO_* RCVD_HELO_IP_MISMATCH RCVD_NUMERIC_HELO RCVD_ILLEGAL_IP SPF plugin AWL plugin RelayCountry plugin AccessDB plugin ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 5 16:19:15 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 5 Jan 2006, at 15:56, Desai, Jason wrote: > Julian Field wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> >> On 5 Jan 2006, at 09:42, Raymond Dijkxhoorn wrote: >>> Hi! >>> >>>>> - spam after 6 hours from the initial creation of the cache >>>>> record. >>>> >>> >>> Been chatting with Steve last night, he promised to rewrite some >>> code when he would wake up :) >>> >>> So far its going just fine. >>> >>> I hope it will be configurable, would really help. High spam is >>> perfect as it is now, low spam we want to get higher once they are >>> learned... so a really low timeout to cut out the first batfhes is >>> fine, after that i want to recheck if its not added to more RBLs. >>> So for us low spam caching could even have a 5-10 mins expire... >> >> I would like to get a set of timeouts we basically agree on, then >> leave them set at that. No-one will ever actually change the values >> we supply, so I see no great reason to make the conf file any bigger >> than it already is. > > Perhaps the cache time could be specified as one of the options for > (Spam|High Scoring Spam|Non Spam) Actions? The defaults could be > set if > nothing were specified. And if someone wanted different times > based on > certain entries in SpamAssassin report, they could just write a custom > function to do so. > > Ex. - To cache high scoring spam for 10 minutes > > High Scoring Spam Actions = store delete cache:10 > > This way you're not really adding more configuration options, just an > additional action, and you can default it to what everyone agrees > would > be sensible. That's the most sensible suggestion so far. Trouble is it wants a different value for viruses as well, and I'm not sure where to put that. So I'm not sure that will happen. I might just end up putting in the 4 config options to do it. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ71HBfw32o+k+q+hAQF3fwf+NrOP6GfYpTcVOQ/Epq2HofwJUTKt7rRh UAd1UlHRPVYE68gZThSs7aFN4O2t/sLNiIKCcLxqpRs9g9yaMjd62vy/VxggGjVf Br9h0Nn85tpqBf6Elsfz+uzwHlBOuWEGMicoOmajbe7jo9OA+ef/J7HFxcJTkUSP BvB5o6ksmQTBQG3VQZasmQtVLOu6kwoPPqm6KKE0v5T4EWUzE0loip8MAWaWeuxu 3A+nbwuZyjmIrXo+7EQrzmaJFBIYOEFLnpqtxEDBi24wKBSmUsM6SybQnvMCcc5U vBARvnAL8xcPDRGUgV6f4hG6mTeM+0wDRiYSxzJWhK6/VHDK0USHTw== =IA06 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 5 16:21:29 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.5 released Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 5 Jan 2006, at 15:50, Aaron K. Moore wrote: > Julian Field wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> >> I have just released version 4.50.5. >> >> This is basically a lot of tidying up done since yesterday's 4.50.4. >> No dramatic new features. > > I've saw SQLite mentioned in a few of the posts. Are you just > using it > for SpamAssassin in your rpm builds, or is it being used for other > parts > of MailScanner? I'm using it for the new SpamAssassin cache. Very quick and easy shared database. But it is optional. If it's not installed then you can't use the new feature, that's all. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ71Hi/w32o+k+q+hAQHAgwgAmhEtxP2POR2T9VEznquwjONYFsp50E0r /ORdbfrKGhLUlpn1W8OLclLiEzP2xTy0exdZPlOos+CLAZnCqPFhl3aEJTgVbc5x VdGKqXjPWUOKMjq36wT4ML2Ars2FpAECfxhfrJCQ/OEBGNABlEOV10XcOmoQe3GF YhzlR9mvzHUpVGdlTJDiofUB3p8n4z87OqW1EUHDMtZwoC0FYaleV0FNYgx06CML FTigLOnaJA3dSgtMVPCYRN+jFwUX+ORMvZ+JmE29J1D+zEVCH8VRybgpUFlHijbV Nb/XeIUwXlj5r1x9acnMMHMSJN9UNeY/rDtMHGuc6Sl1U37LCtNqiQ== =quyA -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ka at PACIFIC.NET Thu Jan 5 16:21:26 2006 From: ka at PACIFIC.NET (Ken A) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > Did you run my ./install.sh? This should upgrade DBI for you anyway. > If so, why did my DBI install fail? Yes, with ./install.sh. Sorry, but I'm not sure exactly. > What output was produced? Below is the relevant output. Hope this helps. Thanks, Ken A Pacific.Net ---- snip ----- Attempting to build and install perl-DBI-1.50-1 Installing perl-DBI-1.50-1.src.rpm Executing(%prep): /bin/sh -e /var/tmp/rpm-tmp.33425 + umask 022 + cd /usr/src/redhat/BUILD + LANG=C + export LANG + unset DISPLAY + cd /usr/src/redhat/BUILD + rm -rf DBI-1.50 + /bin/gzip -dc /usr/src/redhat/SOURCES/DBI-1.50.tar.gz + tar -xf - + STATUS=0 + '[' 0 -ne 0 ']' + cd DBI-1.50 ++ /usr/bin/id -u + '[' 0 = 0 ']' + /bin/chown -Rhf root . ++ /usr/bin/id -u + '[' 0 = 0 ']' + /bin/chgrp -Rhf root . + /bin/chmod -Rf a+rX,u+w,g-w,o-w . + exit 0 Executing(%build): /bin/sh -e /var/tmp/rpm-tmp.33425 + umask 022 + cd /usr/src/redhat/BUILD + cd DBI-1.50 + LANG=C + export LANG + unset DISPLAY + CFLAGS='-O2 -g -pipe -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -m32 -march=i386 -mtune=pentium4 -fasynchronous-unwind-tables' + perl Makefile.PL PREFIX=/var/tmp/perl-DBI-1.50-1-root/usr *** You are using a perl configured with threading enabled. *** You should be aware that using multiple threads is *** not recommended for production environments. *** Note: The optional PlRPC-modules (RPC::PlServer etc) are not installed. If you want to use the DBD::Proxy driver and DBI::ProxyServer modules, then you'll need to install the RPC::PlServer, RPC::PlClient, Storable and Net::Daemon modules. The CPAN Bundle::DBI may help you. You can install them any time after installing the DBI. You do *not* need these modules for typical DBI usage. Optional modules are available from any CPAN mirror, in particular http://search.cpan.org/ http://www.perl.com/CPAN/modules/by-module http://www.perl.org/CPAN/modules/by-module ftp://ftp.funet.fi/pub/languages/perl/CPAN/modules/by-module Creating DBI::PurePerl test variant: t/zvpp_01basics.t Creating DBI::PurePerl test variant: t/zvpp_02dbidrv.t Creating DBI::PurePerl test variant: t/zvpp_03handle.t Creating DBI::PurePerl test variant: t/zvpp_04mods.t Creating DBI::PurePerl test variant: t/zvpp_05thrclone.t (use threads) Creating DBI::PurePerl test variant: t/zvpp_06attrs.t Creating DBI::PurePerl test variant: t/zvpp_07kids.t Creating DBI::PurePerl test variant: t/zvpp_08keeperr.t Creating DBI::PurePerl test variant: t/zvpp_09trace.t Creating DBI::PurePerl test variant: t/zvpp_10examp.t Creating DBI::PurePerl test variant: t/zvpp_11fetch.t Creating DBI::PurePerl test variant: t/zvpp_14utf8.t Creating DBI::PurePerl test variant: t/zvpp_15array.t Creating DBI::PurePerl test variant: t/zvpp_20meta.t Creating DBI::PurePerl test variant: t/zvpp_30subclass.t Creating DBI::PurePerl test variant: t/zvpp_40profile.t Creating DBI::PurePerl test variant: t/zvpp_41prof_dump.t Creating DBI::PurePerl test variant: t/zvpp_42prof_data.t Creating DBI::PurePerl test variant: t/zvpp_43profenv.t Creating DBI::PurePerl test variant: t/zvpp_50dbm.t Creating DBI::PurePerl test variant: t/zvpp_60preparse.t Creating DBI::PurePerl test variant: t/zvpp_70callbacks.t Creating DBI::PurePerl test variant: t/zvpp_72childhandles.t Creating DBI::PurePerl test variant: t/zvpp_80proxy.t Checking if your kit is complete... Looks good I see you're using perl 5.008006 on i386-linux-thread-multi, okay. Remember to actually *read* the README file! Use 'make' to build the software (dmake or nmake on Windows). Then 'make test' to execute self tests. Then 'make install' to install the DBI and then delete this working directory before unpacking and building any DBD::* drivers. Writing Makefile for DBI + make /usr/bin/perl "-MExtUtils::Command" -e mkpath blib/lib/DBI rm -f blib/lib/DBI/Changes.pm cp Changes blib/lib/DBI/Changes.pm /usr/bin/perl "-MExtUtils::Command" -e mkpath blib/lib/DBI rm -f blib/lib/DBI/Roadmap.pm cp Roadmap.pod blib/lib/DBI/Roadmap.pm cp dbd_xsh.h blib/arch/auto/DBI/dbd_xsh.h cp dbivport.h blib/arch/auto/DBI/dbivport.h cp lib/DBI/FAQ.pm blib/lib/DBI/FAQ.pm cp Driver_xst.h blib/arch/auto/DBI/Driver_xst.h cp lib/DBI/SQL/Nano.pm blib/lib/DBI/SQL/Nano.pm cp lib/DBD/Proxy.pm blib/lib/DBD/Proxy.pm cp lib/DBI/Const/GetInfo/ANSI.pm blib/lib/DBI/Const/GetInfo/ANSI.pm cp lib/DBD/DBM.pm blib/lib/DBD/DBM.pm cp DBI.pm blib/lib/DBI.pm cp lib/DBI/Const/GetInfoReturn.pm blib/lib/DBI/Const/GetInfoReturn.pm cp DBIXS.h blib/arch/auto/DBI/DBIXS.h cp lib/DBD/Sponge.pm blib/lib/DBD/Sponge.pm cp Roadmap.pod blib/lib/Roadmap.pod cp lib/DBI/Const/GetInfoType.pm blib/lib/DBI/Const/GetInfoType.pm cp lib/DBI/W32ODBC.pm blib/lib/DBI/W32ODBC.pm cp lib/DBI/DBD/Metadata.pm blib/lib/DBI/DBD/Metadata.pm cp lib/DBI/Const/GetInfo/ODBC.pm blib/lib/DBI/Const/GetInfo/ODBC.pm cp lib/DBI/ProfileDumper/Apache.pm blib/lib/DBI/ProfileDumper/Apache.pm cp lib/Bundle/DBI.pm blib/lib/Bundle/DBI.pm cp lib/DBI/Profile.pm blib/lib/DBI/Profile.pm cp lib/DBI/ProfileDumper.pm blib/lib/DBI/ProfileDumper.pm cp lib/DBD/File.pm blib/lib/DBD/File.pm cp Driver.xst blib/arch/auto/DBI/Driver.xst cp lib/DBI/ProxyServer.pm blib/lib/DBI/ProxyServer.pm cp dbipport.h blib/arch/auto/DBI/dbipport.h cp lib/DBD/NullP.pm blib/lib/DBD/NullP.pm cp lib/DBI/DBD.pm blib/lib/DBI/DBD.pm cp lib/Win32/DBIODBC.pm blib/lib/Win32/DBIODBC.pm cp lib/DBI/PurePerl.pm blib/lib/DBI/PurePerl.pm cp lib/DBD/ExampleP.pm blib/lib/DBD/ExampleP.pm cp dbi_sql.h blib/arch/auto/DBI/dbi_sql.h cp lib/DBI/ProfileData.pm blib/lib/DBI/ProfileData.pm /usr/bin/perl -p -e "s/~DRIVER~/Perl/g" ./Driver.xst > Perl.xsi /usr/bin/perl /usr/lib/perl5/5.8.6/ExtUtils/xsubpp -typemap /usr/lib/perl5/5.8.6/ExtUtils/typemap -typemap typemap Perl.xs > Perl.xsc && mv Perl.xsc Perl.c gcc -c -D_REENTRANT -D_GNU_SOURCE -DDEBUGGING -fno-strict-aliasing -pipe -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -g -pipe -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -m32 -march=i386 -mtune=pentium4 -fasynchronous-unwind-tables -DVERSION=\"1.50\" -DXS_VERSION=\"1.50\" -fPIC "-I/usr/lib/perl5/5.8.6/i386-linux-thread-multi/CORE" -W -Wall -Wpointer-arith -Wbad-function-cast -Wno-comment -Wno-sign-compare -Wno-cast-qual -Wdisabled-optimization -Wmissing-noreturn -Wno-unused-parameter Perl.c /usr/bin/perl /usr/lib/perl5/5.8.6/ExtUtils/xsubpp -typemap /usr/lib/perl5/5.8.6/ExtUtils/typemap -typemap typemap DBI.xs > DBI.xsc && mv DBI.xsc DBI.c gcc -c -D_REENTRANT -D_GNU_SOURCE -DDEBUGGING -fno-strict-aliasing -pipe -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -g -pipe -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -m32 -march=i386 -mtune=pentium4 -fasynchronous-unwind-tables -DVERSION=\"1.50\" -DXS_VERSION=\"1.50\" -fPIC "-I/usr/lib/perl5/5.8.6/i386-linux-thread-multi/CORE" -W -Wall -Wpointer-arith -Wbad-function-cast -Wno-comment -Wno-sign-compare -Wno-cast-qual -Wdisabled-optimization -Wmissing-noreturn -Wno-unused-parameter DBI.c Running Mkbootstrap for DBI () chmod 644 DBI.bs rm -f blib/arch/auto/DBI/DBI.so gcc -shared -L/usr/local/lib DBI.o -o blib/arch/auto/DBI/DBI.so chmod 755 blib/arch/auto/DBI/DBI.so cp DBI.bs blib/arch/auto/DBI/DBI.bs chmod 644 blib/arch/auto/DBI/DBI.bs /usr/bin/perl "-Iblib/arch" "-Iblib/lib" dbiprof.PL dbiprof Extracted dbiprof from dbiprof.PL with variable substitutions. cp dbiprof blib/script/dbiprof /usr/bin/perl "-MExtUtils::MY" -e "MY->fixin(shift)" blib/script/dbiprof /usr/bin/perl "-Iblib/arch" "-Iblib/lib" dbiproxy.PL dbiproxy Extracted dbiproxy from dbiproxy.PL with variable substitutions. cp dbiproxy blib/script/dbiproxy /usr/bin/perl "-MExtUtils::MY" -e "MY->fixin(shift)" blib/script/dbiproxy Manifying blib/man1/dbiprof.1 Manifying blib/man1/dbiproxy.1 Manifying blib/man3/DBI::FAQ.3pm Manifying blib/man3/DBD::Proxy.3pm Manifying blib/man3/DBI::SQL::Nano.3pm Manifying blib/man3/DBI::Const::GetInfo::ANSI.3pm Manifying blib/man3/DBD::DBM.3pm Manifying blib/man3/DBI::Const::GetInfoReturn.3pm Manifying blib/man3/DBI.3pm Manifying blib/man3/DBD::Sponge.3pm Manifying blib/man3/DBI::Const::GetInfoType.3pm Manifying blib/man3/Roadmap.3pm Manifying blib/man3/DBI::DBD::Metadata.3pm Manifying blib/man3/DBI::W32ODBC.3pm Manifying blib/man3/DBI::Const::GetInfo::ODBC.3pm Manifying blib/man3/DBI::ProfileDumper::Apache.3pm Manifying blib/man3/Bundle::DBI.3pm Manifying blib/man3/DBI::Profile.3pm Manifying blib/man3/DBD::File.3pm Manifying blib/man3/DBI::ProfileDumper.3pm Manifying blib/man3/DBI::ProxyServer.3pm Manifying blib/man3/DBI::DBD.3pm Manifying blib/man3/Win32::DBIODBC.3pm Manifying blib/man3/DBI::PurePerl.3pm Manifying blib/man3/DBI::ProfileData.3pm + make test PERL_DL_NONLAZY=1 /usr/bin/perl "-MExtUtils::Command::MM" "-e" "test_harness(0, 'blib/lib', 'blib/arch')" t/*.t t/01basics...............ok 4/131 skipped: developer tests t/02dbidrv...............ok t/03handle...............ok t/04mods.................ok t/05thrclone.............ok t/06attrs................ok t/07kids.................ok t/08keeperr..............ok t/09trace................ok t/10examp................ok t/11fetch................ok t/14utf8.................ok t/15array................ok t/20meta.................ok t/30subclass.............ok t/40profile..............ok t/41prof_dump............ok t/42prof_data............ok t/43profenv..............ok t/50dbm..................ok t/60preparse.............ok t/70callbacks............ok t/72childhandles.........ok t/80proxy................skipped all skipped: modules required for proxy are probably not installed (e.g., RPC/PlClient.pm) t/pod....................skipped all skipped: Test::Pod 1.00 required for testing POD t/zvpp_01basics..........ok 4/131 skipped: developer tests t/zvpp_02dbidrv..........ok 10/51 skipped: various reasons t/zvpp_03handle..........ok 76/135 skipped: various reasons t/zvpp_04mods............ok t/zvpp_05thrclone........ok t/zvpp_06attrs...........ok 7/137 skipped: various reasons t/zvpp_07kids............skipped all skipped: $h->{Kids} attribute not supported for DBI::PurePerl t/zvpp_08keeperr.........ok t/zvpp_09trace...........ok t/zvpp_10examp...........ok 39/253 skipped: various reasons t/zvpp_11fetch...........ok t/zvpp_14utf8............ok t/zvpp_15array...........ok t/zvpp_20meta............ok t/zvpp_30subclass........ok t/zvpp_40profile.........skipped all skipped: profiling not supported for DBI::PurePerl t/zvpp_41prof_dump.......skipped all skipped: profiling not supported for DBI::PurePerl t/zvpp_42prof_data.......skipped all skipped: profiling not supported for DBI::PurePerl t/zvpp_43profenv.........skipped all skipped: profiling not supported for DBI::PurePerl t/zvpp_50dbm.............ok t/zvpp_60preparse........skipped all skipped: preparse not supported for DBI::PurePerl t/zvpp_70callbacks.......skipped all skipped: $h->{Callbacks} attribute not supported for DBI::PurePerl t/zvpp_72childhandles....ok t/zvpp_80proxy...........skipped all skipped: modules required for proxy are probably not installed (e.g., RPC/PlClient.pm) All tests successful, 10 tests and 140 subtests skipped. Files=49, Tests=2306, 39 wallclock secs (26.86 cusr + 9.98 csys = 36.84 CPU) PERL_DL_NONLAZY=1 /usr/bin/perl "-Iblib/lib" "-Iblib/arch" test.pl test.pl DBI test application $Revision: 11.7 $ Switch: DBI 1.50 by Tim Bunce, 1.50 Available Drivers: DBM, ExampleP, File, Proxy, Sponge dbi:ExampleP:: testing 5 sets of 20 connections: Connecting... 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 Disconnecting... Connecting... 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 Disconnecting... Connecting... 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 Disconnecting... Connecting... 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 Disconnecting... Connecting... 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 Disconnecting... Made 100 connections in 0 wallclock secs ( 0.02 usr + 0.00 sys = 0.02 CPU) Testing handle creation speed... 8064 NullP sth/s perl 5.008006 i386-linux-thread-multi (gcc 4.0.2 -O2 -g -pipe -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -m32 -march=i386 -mtune=pentium4 -fasynchronous-unwind-tables) test.pl done + exit 0 Executing(%install): /bin/sh -e /var/tmp/rpm-tmp.47884 + umask 022 + cd /usr/src/redhat/BUILD + cd DBI-1.50 + LANG=C + export LANG + unset DISPLAY + rm -rf /var/tmp/perl-DBI-1.50-1-root ++ perl -V:installarchlib + eval 'installarchlib='\''/usr/lib/perl5/5.8.6/i386-linux-thread-multi'\'';' ++ installarchlib=/usr/lib/perl5/5.8.6/i386-linux-thread-multi + mkdir -p /var/tmp/perl-DBI-1.50-1-root//usr/lib/perl5/5.8.6/i386-linux-thread-multi + make install Manifying blib/man1/dbiprof.1 Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/dbipport.h Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/DBI.so Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/Driver.xst Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/dbd_xsh.h Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/dbivport.h Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/DBIXS.h Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/dbi_sql.h Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/DBI.bs Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/Driver_xst.h Files found in blib/arch: installing files in blib/lib into architecture dependent library tree Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/Roadmap.pod Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/Win32/DBIODBC.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/ProfileDumper.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/Changes.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/Roadmap.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/ProfileData.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/W32ODBC.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/FAQ.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/DBD.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/Profile.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/ProxyServer.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/PurePerl.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/SQL/Nano.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/ProfileDumper/Apache.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/DBD/Metadata.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/Const/GetInfoType.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/Const/GetInfoReturn.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/Const/GetInfo/ANSI.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/Const/GetInfo/ODBC.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBD/File.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBD/NullP.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBD/Sponge.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBD/DBM.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBD/ExampleP.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBD/Proxy.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/Bundle/DBI.pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man1/dbiprof.1 Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man1/dbiproxy.1 Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBD::Proxy.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBI::W32ODBC.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBD::File.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBI::SQL::Nano.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/Roadmap.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBI::Const::GetInfoType.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBI::FAQ.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBI::Const::GetInfo::ODBC.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBI::PurePerl.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBD::DBM.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBI::Const::GetInfo::ANSI.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/Bundle::DBI.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBI::ProxyServer.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBI::ProfileDumper::Apache.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBI::ProfileData.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBI.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/Win32::DBIODBC.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBD::Sponge.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBI::DBD::Metadata.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBI::DBD.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBI::Const::GetInfoReturn.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBI::Profile.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/share/man/man3/DBI::ProfileDumper.3pm Installing /var/tmp/perl-DBI-1.50-1-root/usr/bin/dbiproxy Installing /var/tmp/perl-DBI-1.50-1-root/usr/bin/dbiprof Writing /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/.packlist Appending installation info to /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/5.8.6/i386-linux-thread-multi/perllocal.pod + '[' -x /usr/lib/rpm/brp-compress ']' + /usr/lib/rpm/brp-compress + find /var/tmp/perl-DBI-1.50-1-root/usr -type f -print + sed 's@^/var/tmp/perl-DBI-1.50-1-root@@g' + grep -v perllocal.pod + grep -v '\.packlist' ++ cat DBI-1.50-filelist + '[' '/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/Bundle/DBI.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/Win32/DBIODBC.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/Const/GetInfo/ANSI.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/Const/GetInfo/ODBC.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/Const/GetInfoReturn.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/Const/GetInfoType.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/FAQ.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/SQL/Nano.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/ProfileDumper/Apache.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/ProxyServer.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/Profile.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/Changes.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/ProfileDumper.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/PurePerl.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/W32ODBC.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/Roadmap.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/ProfileData.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/DBD/Metadata.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBI/DBD.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/Roadmap.pod /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBD/DBM.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBD/Sponge.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBD/File.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBD/Proxy.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBD/NullP.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/DBD/ExampleP.pm /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/Driver.xst /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/dbd_xsh.h /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/dbivport.h /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/DBIXS.h /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/Driver_xst.h /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/DBI.so /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/DBI.bs /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/dbi_sql.h /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/dbipport.h /usr/share/man/man3/DBI::ProfileData.3pm.gz /usr/share/man/man3/DBI::Profile.3pm.gz /usr/share/man/man3/DBI::ProfileDumper.3pm.gz /usr/share/man/man3/DBD::Sponge.3pm.gz /usr/share/man/man3/DBI::Const::GetInfo::ODBC.3pm.gz /usr/share/man/man3/DBI::PurePerl.3pm.gz /usr/share/man/man3/Roadmap.3pm.gz /usr/share/man/man3/DBI::ProxyServer.3pm.gz /usr/share/man/man3/DBI::FAQ.3pm.gz /usr/share/man/man3/DBD::DBM.3pm.gz /usr/share/man/man3/DBD::File.3pm.gz /usr/share/man/man3/Bundle::DBI.3pm.gz /usr/share/man/man3/DBI::ProfileDumper::Apache.3pm.gz /usr/share/man/man3/DBI::Const::GetInfo::ANSI.3pm.gz /usr/share/man/man3/Win32::DBIODBC.3pm.gz /usr/share/man/man3/DBI::Const::GetInfoType.3pm.gz /usr/share/man/man3/DBI::DBD.3pm.gz /usr/share/man/man3/DBI::SQL::Nano.3pm.gz /usr/share/man/man3/DBI::W32ODBC.3pm.gz /usr/share/man/man3/DBD::Proxy.3pm.gz /usr/share/man/man3/DBI.3pm.gz /usr/share/man/man3/DBI::Const::GetInfoReturn.3pm.gz /usr/share/man/man3/DBI::DBD::Metadata.3pm.gz /usr/share/man/man1/dbiprof.1.gz /usr/share/man/man1/dbiproxy.1.gz /usr/bin/dbiprof /usr/bin/dbiproxyX' = X ']' + /usr/lib/rpm/find-debuginfo.sh /usr/src/redhat/BUILD/DBI-1.50 extracting debug info from /var/tmp/perl-DBI-1.50-1-root/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/DBI.so 643 blocks + /usr/lib/rpm/redhat/brp-compress + /usr/lib/rpm/redhat/brp-strip-static-archive /usr/bin/strip + /usr/lib/rpm/redhat/brp-strip-comment-note /usr/bin/strip /usr/bin/objdump Processing files: perl-DBI-1.50-1 Provides: DBI.so perl(Bundle::DBI) = 11.3 perl(DBD::DBM) = 0.03 perl(DBD::DBM::Statement) perl(DBD::DBM::Table) perl(DBD::DBM::db) perl(DBD::DBM::dr) perl(DBD::DBM::st) perl(DBD::ExampleP) = 11.12 perl(DBD::File) = 0.33 perl(DBD::File::Statement) perl(DBD::File::Table) perl(DBD::File::db) perl(DBD::File::dr) perl(DBD::File::st) perl(DBD::NullP) = 11.4 perl(DBD::Proxy) = 0.2004 perl(DBD::Proxy::db) perl(DBD::Proxy::dr) perl(DBD::Proxy::st) perl(DBD::Sponge) = 11.10 perl(DBDI) perl(DBI) perl(DBI::Const::GetInfo::ANSI) = 1.3 perl(DBI::Const::GetInfo::ODBC) = 1.3 perl(DBI::Const::GetInfoReturn) = 1.4 perl(DBI::Const::GetInfoType) = 1.5 perl(DBI::DBD) = 11.21 perl(DBI::DBD::Metadata) = 1.5 perl(DBI::FAQ) = 0.38 perl(DBI::Profile) = 1.7 perl(DBI::ProfileData) = 1.0 perl(DBI::ProfileDumper) = 1.0 perl(DBI::ProfileDumper::Apache) = 1.1 perl(DBI::ProxyServer) = 0.3005 perl(DBI::ProxyServer::db) perl(DBI::ProxyServer::dr) perl(DBI::ProxyServer::st) perl(DBI::SQL::Nano) = 0.03 perl(DBI::SQL::Nano::Statement_) perl(DBI::SQL::Nano::Table_) perl(DBI::common) Requires(rpmlib): rpmlib(CompressedFileNames) <= 3.0.4-1 rpmlib(PayloadFilesHavePrefix) <= 4.0-1 rpmlib(VersionedDependencies) <= 3.0.3-1 Requires: /usr/bin/perl libc.so.6 libc.so.6(GLIBC_2.0) libc.so.6(GLIBC_2.1.3) libc.so.6(GLIBC_2.3) libc.so.6(GLIBC_2.3.4) perl >= 0:5.004 perl >= 0:5.005_03 perl >= 0:5.006_00 perl(Carp) perl(Config) perl(Cwd) perl(DBI) perl(DBI::Const::GetInfo::ANSI) perl(DBI::Const::GetInfo::ODBC) perl(DBI::Const::GetInfoType) perl(DBI::Profile) perl(DBI::ProfileData) perl(DBI::ProfileDumper) perl(DBI::ProxyServer) perl(DBI::SQL::Nano) perl(Data::Dumper) perl(DynaLoader) perl(Exporter) perl(Fcntl) perl(File::Spec) perl(Getopt::Long) perl(IO::File) perl(RPC::PlClient) >= 0.2000 perl(RPC::PlServer) >= 0.2001 perl(Symbol) perl(UNIVERSAL) perl(Win32::ODBC) perl(base) perl(constant) perl(strict) perl(utf8) perl(vars) perl(warnings) Checking for unpackaged file(s): /usr/lib/rpm/check-files /var/tmp/perl-DBI-1.50-1-root warning: Installed (but unpackaged) file(s) found: /usr/lib/debug/usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/DBI.so.debug /usr/lib/perl5/5.8.6/i386-linux-thread-multi/perllocal.pod /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi/auto/DBI/.packlist /usr/src/debug/DBI-1.50/DBI.c /usr/src/debug/DBI-1.50/DBI.xs /usr/src/debug/DBI-1.50/DBIXS.h Wrote: /usr/src/redhat/RPMS/noarch/perl-DBI-1.50-1.noarch.rpm Executing(%clean): /bin/sh -e /var/tmp/rpm-tmp.23721 + umask 022 + cd /usr/src/redhat/BUILD + cd DBI-1.50 + rm -rf /var/tmp/perl-DBI-1.50-1-root + exit 0 Executing(--clean): /bin/sh -e /var/tmp/rpm-tmp.23721 + umask 022 + cd /usr/src/redhat/BUILD + rm -rf DBI-1.50 + exit 0 Do not worry too much about errors from the next command. It is quite likely that some of the Perl modules are already installed on your system. The important ones are HTML-Parser and MIME-tools. I have to force installation of DBI. Sorry. error: Failed dependencies: perl(RPC::PlClient) >= 0.2000 is needed by perl-DBI-1.50-1.noarch perl(RPC::PlServer) >= 0.2001 is needed by perl-DBI-1.50-1.noarch perl(Win32::ODBC) is needed by perl-DBI-1.50-1.noarch Attempting to build and install perl-DBD-SQLite-1.11-1 Installing perl-DBD-SQLite-1.11-1.src.rpm Executing(%prep): /bin/sh -e /var/tmp/rpm-tmp.41844 + umask 022 + cd /usr/src/redhat/BUILD + LANG=C + export LANG + unset DISPLAY + cd /usr/src/redhat/BUILD + rm -rf DBD-SQLite-1.11 + /bin/gzip -dc /usr/src/redhat/SOURCES/DBD-SQLite-1.11.tar.gz + tar -xf - + STATUS=0 + '[' 0 -ne 0 ']' + cd DBD-SQLite-1.11 ++ /usr/bin/id -u + '[' 0 = 0 ']' + /bin/chown -Rhf root . ++ /usr/bin/id -u + '[' 0 = 0 ']' + /bin/chgrp -Rhf root . + /bin/chmod -Rf a+rX,u+w,g-w,o-w . + exit 0 Executing(%build): /bin/sh -e /var/tmp/rpm-tmp.41844 + umask 022 + cd /usr/src/redhat/BUILD + cd DBD-SQLite-1.11 + LANG=C + export LANG + unset DISPLAY + CFLAGS='-O2 -g -pipe -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -m32 -march=i386 -mtune=pentium4 -fasynchronous-unwind-tables' + perl Makefile.PL PREFIX=/var/tmp/perl-DBD-SQLite-1.11-1-root/usr Checking installed SQLite version... SQLite version must be at least 3.1.3. No header file at that version or higher was found. Using the local version instead. Checking if your kit is complete... Looks good Warning: prerequisite DBI 1.21 not found. Writing Makefile for DBD::SQLite + make cp lib/DBD/SQLite.pm blib/lib/DBD/SQLite.pm /usr/bin/perl /usr/lib/perl5/5.8.6/ExtUtils/xsubpp -typemap /usr/lib/perl5/5.8.6/ExtUtils/typemap SQLite.xs > SQLite.xsc && mv SQLite.xsc SQLite.c Cannot open 'SQLite.xsi': No such file or directory in SQLite.xs, line 72 make: *** [SQLite.c] Error 1 error: Bad exit status from /var/tmp/rpm-tmp.41844 (%build) RPM build errors: Bad exit status from /var/tmp/rpm-tmp.41844 (%build) Missing file /usr/src/redhat/RPMS/noarch/perl-DBD-SQLite-1.11-1.noarch.rpm. Maybe it did not build correctly? --- snip --- > On 4 Jan 2006, at 22:49, Ken A wrote: > >> Upgrading DBI with CPAN fixed install problems on FC4 as well. >> Thanks, >> Ken A >> Pacific.Net >> >> >> Ken A wrote: >>> Raymond Dijkxhoorn wrote: >>>> Hi! >>>> >>>>> One thing worth mentioning: if you use rcpt splitting (one >>>>> message per recipient) then you should see a massive speed >>>>> improvement with this version. >>>>> >>>>> Raymond --- this may help you! >>>>>> I would be very interested to hear what speedups you see from >>>>>> this new faster version. >>>> Ok, after fetching a RPM from DAG we got SQLite going, the >>>> version on CPAN gave errors on FC1. >>> Issues with SQLite on FC4 too. >>>> Checking installed SQLite version... >>>> SQLite version must be at least 3.1.3. No header file at that >>>> version or higher was found. Using the local version instead. >>>> Checking if your kit is complete... >>>> Looks good >>>> Warning: prerequisite DBI 1.21 not found. >>>> Writing Makefile for DBD::SQLite >>>> + make >>>> cp lib/DBD/SQLite.pm blib/lib/DBD/SQLite.pm >>>> /usr/bin/perl /usr/lib/perl5/5.8.6/ExtUtils/xsubpp -typemap /usr/ >>>> lib/perl5/5.8.6/ExtUtils/typemap SQLite.xs > SQLite.xsc && mv >>>> SQLite.xsc SQLite.c >>>> Cannot open 'SQLite.xsi': No such file or directory in SQLite.xs, >>>> line 72 >>>> make: *** [SQLite.c] Error 1 >>>> error: Bad exit status from /var/tmp/rpm-tmp.78484 (%build) >>>> >>>> RPM build errors: >>>> Bad exit status from /var/tmp/rpm-tmp.78484 (%build) >>>> >>>> Missing file /usr/src/redhat/RPMS/noarch/perl-DBD- >>>> SQLite-1.11-1.noarch.rpm. >>>> Maybe it did not build correctly? >>> Ken A >>>> Works: >>>> >>>> Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message >>>> k04M8POB022446 >>>> Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message >>>> k04M8POC022446 >>>> Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message >>>> k04M8POA022446 >>>> Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message >>>> k04M8PO8022446 >>>> Jan 4 23:08:26 vmx30 MailScanner[21711]: Cache hit for message >>>> k04M8PO9022446 >>>> Jan 4 23:08:36 vmx30 MailScanner[21955]: Cache hit for message >>>> k04M8Zcb022532 >>>> Jan 4 23:08:40 vmx30 MailScanner[21232]: Cache hit for message >>>> k04M8d8h022583 >>>> Jan 4 23:08:48 vmx30 MailScanner[21176]: Cache hit for message >>>> k04M8iIc022599 >>>> Jan 4 23:08:50 vmx30 MailScanner[21176]: Cache hit for message >>>> k04M6gST021587 >>>> Jan 4 23:08:50 vmx30 MailScanner[21176]: Cache hit for message >>>> k04M8hFS022595 >>>> Jan 4 23:08:51 vmx30 MailScanner[21650]: Cache hit for message >>>> k04M8nTe022611 >>>> Jan 4 23:08:51 vmx30 MailScanner[21650]: Cache hit for message >>>> k04M8nTY022611 >>>> >>>> [root@vmx30]# grep "Cache hit for message" current | wc -l >>>> 77 >>>> >>>> In a couple of mins. Looking promising. Cheers! >>>> >>>> Bye, >>>> Raymond. >>>> >>>> ------------------------ MailScanner list ------------------------ >>>> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >>>> 'leave mailscanner' in the body of the email. >>>> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >>>> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >>>> >>>> Support MailScanner development - buy the book off the website! >>>> >>>> >>> ------------------------ MailScanner list ------------------------ >>> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >>> 'leave mailscanner' in the body of the email. >>> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >>> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >>> Support MailScanner development - buy the book off the website! >> ------------------------ MailScanner list ------------------------ >> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >> 'leave mailscanner' in the body of the email. >> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >> >> Support MailScanner development - buy the book off the website! > > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.3 (Build 2932) > > iQEVAwUBQ7zmVPw32o+k+q+hAQEPcggAjZ8qaqOD7L+GgxWv4p5SJOSU6RoGf+Uq > VO6TIowvJe48+5cxQ2aapV/YMdqVR0XjktNV9nIQDnm2/C/xs1gGbalRWw5NLSUF > sFJ+3ZH5PRlOqC1/M8Jmnjxoqwbmhps8EOWHon0EZ0ewfZcfuESFYewm1vQdjPRR > buYvq1nlKW+4Q5wuudUhCKqeGGpf7gV/PiKICLM78MzLE3RYgSgYG49jXE2toPPB > yMUqJ+UfwlNfTmR1ekph0hErShVOruyZ6V9IoGbvLq+ZqoRdYGK2a3WUke0ahDXt > 34ZUsWBM1BZlt5Bj4FdnGFBWtD5husdtLUS9FO527CBFdF4imQGDoA== > =OcxF > -----END PGP SIGNATURE----- > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From a.peacock at CHIME.UCL.AC.UK Thu Jan 5 16:29:25 2006 From: a.peacock at CHIME.UCL.AC.UK (Anthony Peacock) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: Hi, > -----BEGIN PGP SIGNED MESSAGE----- > > > On 5 Jan 2006, at 15:56, Desai, Jason wrote: > > > Julian Field wrote: > >> -----BEGIN PGP SIGNED MESSAGE----- > >> > >> On 5 Jan 2006, at 09:42, Raymond Dijkxhoorn wrote: > >>> Hi! > >>> > > > > Perhaps the cache time could be specified as one of the options for > > (Spam|High Scoring Spam|Non Spam) Actions? The defaults could be > > set if > > nothing were specified. And if someone wanted different times > > based on > > certain entries in SpamAssassin report, they could just write a custom > > function to do so. > > > > Ex. - To cache high scoring spam for 10 minutes > > > > High Scoring Spam Actions = store delete cache:10 > > > > This way you're not really adding more configuration options, just an > > additional action, and you can default it to what everyone agrees > > would > > be sensible. > > That's the most sensible suggestion so far. Trouble is it wants a > different value for viruses as well, and I'm not sure where to put > that. So I'm not sure that will happen. > I might just end up putting in the 4 config options to do it. Just a thought. Could you create a single config option that took one or more parameters, a little like the way SpamAssassin sets the scores for rules. For example: Cache Timeout = 10 60 120 Which would set the time outs as Spam = 10 High Scoring Spam = 60 Viruses = 120 If a single value is given all are set to that one value: Cache Timeout = 0 Would disable all caching. I am not too sure if this fits in with any other config styles in MailScanner. Just a thought to throw into the pot. -- Anthony Peacock CHIME, Royal Free & University College Medical School WWW: http://www.chime.ucl.ac.uk/~rmhiajp/ "In the beginning of a change, the patriot is a brave and scarce man, hated and scorned. When the cause succeeds, however, the timid join him...for then it costs nothing to be a patriot." -Mark Twain ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 5 16:45:26 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: -----BEGIN PGP SIGNED MESSAGE----- The critical lines are these: On 5 Jan 2006, at 16:21, Ken A wrote: > error: Failed dependencies: > perl(RPC::PlClient) >= 0.2000 is needed by perl- > DBI-1.50-1.noarch > perl(RPC::PlServer) >= 0.2001 is needed by perl- > DBI-1.50-1.noarch > perl(Win32::ODBC) is needed by perl-DBI-1.50-1.noarch I don't understand why it thinks it needs these. My system hasn't got them installed and didn't need them for DBI. The output of Makefile.PL includes this: *** Note: The optional PlRPC-modules (RPC::PlServer etc) are not installed. If you want to use the DBD::Proxy driver and DBI::ProxyServer modules, then you'll need to install the RPC::PlServer, RPC::PlClient, Storable and Net::Daemon modules. The CPAN Bundle::DBI may help you. You can install them any time after installing the DBI. You do *not* need these modules for typical DBI usage. So it knows they are optional. So why does it think it needs them? Confused. There is a Bundle::DBI, but I don't see why I should need to install all these modules that it knows are optional anyway. What OS and version are you using? - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ71NKPw32o+k+q+hAQGtcgf/SbDCigMgj/kLdZWOewFY0OYPM21jDSfj DH9j5c4CHyFw80jaNMtC6hgtFWGzjOkXVjG5578NFwNhDTB9lEhonnik0/nBtRHu qNE8JiGE+ix0pIckEb+LoKMYkXuNCrwU/YA1h/CrqwLSt1niU5breaGxRIBa1The 4thvuSzD9+Bl3wKhlDAYv1hAInZFg2v7QOwg/MEpaunnvOn9QKUXJaFK+u1BqjGt ixTT78T7wYt65DG3yxX0TOfRK0PH/arnvCnIM0DuVd5z1pihI3WfqT0lQj65uIIz DlTDhvpDE22QxkpVw3CXSEKQ7unwQ5GbAVZXRRX9SvxM02gCryLaFw== =iTds -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 5 16:50:34 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Also what do you see when you do this? [root@karla noarch]# rpm -q --requires -p perl-DBI-1.50-1.noarch.rpm I get this: /usr/bin/perl libc.so.6()(64bit) libc.so.6(GLIBC_2.2.5)(64bit) libc.so.6(GLIBC_2.3)(64bit) rpmlib(CompressedFileNames) <= 3.0.4-1 rpmlib(PayloadFilesHavePrefix) <= 4.0-1 rpmlib(VersionedDependencies) <= 3.0.3-1 On 5 Jan 2006, at 16:21, Ken A wrote: > error: Failed dependencies: > perl(RPC::PlClient) >= 0.2000 is needed by perl- > DBI-1.50-1.noarch > perl(RPC::PlServer) >= 0.2001 is needed by perl- > DBI-1.50-1.noarch > perl(Win32::ODBC) is needed by perl-DBI-1.50-1.noarch - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ71OW/w32o+k+q+hAQHLjgf/b/YNs6CfsgnQE1GznykPZ5trgM+wVmmA 7mQ6sekWlYxcQ5hZIQ3wGwFQUmX9gvgRVRfz+DahrYENVg09pr86wB3DvLzVJGD4 2AlpOC7gMOSDbwA8Q1vWD8wx1bwNDeWrQ8zyPz7qfI5Ia/cbohyIJn48QOB5W6bW xWHpLS8Ds31rmQq3TV5xHB0fefvK22IyY4iVK250NA0zJSeCjo9AZIR83umSHI2u 44qm8zB5N29pkRXezTHvg8fQTp6Mq1GVm0D9urshnmyBibcWNHd3j4KOntPRJGOu Z/59rrcy5GcaBTLq70+iuZKGRNHPD1tbzLLr0lHU1Cee5g/20Yn6Cg== =aMgG -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ka at PACIFIC.NET Thu Jan 5 16:57:29 2006 From: ka at PACIFIC.NET (Ken A) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > The critical lines are these: > > On 5 Jan 2006, at 16:21, Ken A wrote: > >> error: Failed dependencies: >> perl(RPC::PlClient) >= 0.2000 is needed by perl- >> DBI-1.50-1.noarch >> perl(RPC::PlServer) >= 0.2001 is needed by perl- >> DBI-1.50-1.noarch >> perl(Win32::ODBC) is needed by perl-DBI-1.50-1.noarch > > I don't understand why it thinks it needs these. My system hasn't got > them installed and didn't need them for DBI. > > The output of Makefile.PL includes this: > > *** Note: > The optional PlRPC-modules (RPC::PlServer etc) are not installed. > If you want to use the DBD::Proxy driver and DBI::ProxyServer > modules, then you'll need to install the RPC::PlServer, > RPC::PlClient, > Storable and Net::Daemon modules. The CPAN Bundle::DBI may help > you. > You can install them any time after installing the DBI. > You do *not* need these modules for typical DBI usage. > > So it knows they are optional. So why does it think it needs them? > Confused. There is a Bundle::DBI, but I don't see why I should need > to install all these modules that it knows are optional anyway. This is on Fedora Core 4. After the install failed, I used CPAN to "install DBI", I did not have to install "Bundle::DBI". It installed okay. After installing DBI, I used the SQLlite you provided: cd /usr/src/redhat/BUILD/DBD-SQLite-1.11/ perl Makefile.PL make make install Then MailScanner found the SA cache db. So, it seems to me that something is wrong with the DBI that's in the MailScanner package, or at least it's not happy on FC4.. Thanks, Ken A Pacific.Net > What OS and version are you using? > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.3 (Build 2932) > > iQEVAwUBQ71NKPw32o+k+q+hAQGtcgf/SbDCigMgj/kLdZWOewFY0OYPM21jDSfj > DH9j5c4CHyFw80jaNMtC6hgtFWGzjOkXVjG5578NFwNhDTB9lEhonnik0/nBtRHu > qNE8JiGE+ix0pIckEb+LoKMYkXuNCrwU/YA1h/CrqwLSt1niU5breaGxRIBa1The > 4thvuSzD9+Bl3wKhlDAYv1hAInZFg2v7QOwg/MEpaunnvOn9QKUXJaFK+u1BqjGt > ixTT78T7wYt65DG3yxX0TOfRK0PH/arnvCnIM0DuVd5z1pihI3WfqT0lQj65uIIz > DlTDhvpDE22QxkpVw3CXSEKQ7unwQ5GbAVZXRRX9SvxM02gCryLaFw== > =iTds > -----END PGP SIGNATURE----- > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From smf at F2S.COM Thu Jan 5 16:57:56 2006 From: smf at F2S.COM (Steve Freegard) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: Hi Julian, On Thu, 2006-01-05 at 16:45 +0000, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > The critical lines are these: > > On 5 Jan 2006, at 16:21, Ken A wrote: > > > error: Failed dependencies: > > perl(RPC::PlClient) >= 0.2000 is needed by perl- > > DBI-1.50-1.noarch > > perl(RPC::PlServer) >= 0.2001 is needed by perl- > > DBI-1.50-1.noarch > > perl(Win32::ODBC) is needed by perl-DBI-1.50-1.noarch > > I don't understand why it thinks it needs these. My system hasn't got > them installed and didn't need them for DBI. > I had exactly the same issues building Perl modules for DefenderMX - it is caused by the RPM find-requires script that searches for all the dependencies for the RPM including the optional libraries too. Personally I use the cpan2rpm script http://perl.arix.com/cpan2rpm/ which you can tell to ignore requirements: # - DBI - # This spec file was automatically generated by cpan2rpm [ver: 2.028] # The following arguments were used: # '--packager=Steve Freegard ' '--distribution=Fort Systems - DefenderMX' --make-maker=PREFIX=/opt/Fortress/utils --make-install=DESTDIR= %{buildroot} --spec-only --no-prfx '--define=_defaultdocdir /opt/Fortress/utils/doc' '--define=_prefix /' --name=fsmg-perl-DBI --no-requires=perl(Win32::Registry) --no-requires=perl(RPC::PlClient) --no-requires=perl(RPC::PlServer) --no-requires=perl(Win32::ODBC) --no-requires=perl(Apache) ../SOURCES/DBI-1.48.tar.gz Hope this helps. Kind regards, Steve. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ka at PACIFIC.NET Thu Jan 5 17:02:34 2006 From: ka at PACIFIC.NET (Ken A) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] rpm -q --requires -p /usr/src/redhat/RPMS/noarch/perl-DBI-1.50-1.noarch.rpm /usr/bin/perl libc.so.6 libc.so.6(GLIBC_2.0) libc.so.6(GLIBC_2.1.3) libc.so.6(GLIBC_2.3) libc.so.6(GLIBC_2.3.4) perl >= 0:5.004 perl >= 0:5.005_03 perl >= 0:5.006_00 perl(Carp) perl(Config) perl(Cwd) perl(DBI) perl(DBI::Const::GetInfo::ANSI) perl(DBI::Const::GetInfo::ODBC) perl(DBI::Const::GetInfoType) perl(DBI::Profile) perl(DBI::ProfileData) perl(DBI::ProfileDumper) perl(DBI::ProxyServer) perl(DBI::SQL::Nano) perl(Data::Dumper) perl(DynaLoader) perl(Exporter) perl(Fcntl) perl(File::Spec) perl(Getopt::Long) perl(IO::File) perl(RPC::PlClient) >= 0.2000 perl(RPC::PlServer) >= 0.2001 perl(Symbol) perl(UNIVERSAL) perl(Win32::ODBC) perl(base) perl(constant) perl(strict) perl(utf8) perl(vars) perl(warnings) rpmlib(CompressedFileNames) <= 3.0.4-1 rpmlib(PayloadFilesHavePrefix) <= 4.0-1 rpmlib(VersionedDependencies) <= 3.0.3-1 However, I did not have to install the RPC Proxy stuff to get DBI to install, I just installed DBI from CPAN. Ken A Pacific.Net Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > Also what do you see when you do this? > > [root@karla noarch]# rpm -q --requires -p perl-DBI-1.50-1.noarch.rpm > > I get this: > > /usr/bin/perl > libc.so.6()(64bit) > libc.so.6(GLIBC_2.2.5)(64bit) > libc.so.6(GLIBC_2.3)(64bit) > rpmlib(CompressedFileNames) <= 3.0.4-1 > rpmlib(PayloadFilesHavePrefix) <= 4.0-1 > rpmlib(VersionedDependencies) <= 3.0.3-1 > > > On 5 Jan 2006, at 16:21, Ken A wrote: > >> error: Failed dependencies: >> perl(RPC::PlClient) >= 0.2000 is needed by perl- >> DBI-1.50-1.noarch >> perl(RPC::PlServer) >= 0.2001 is needed by perl- >> DBI-1.50-1.noarch >> perl(Win32::ODBC) is needed by perl-DBI-1.50-1.noarch > > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.3 (Build 2932) > > iQEVAwUBQ71OW/w32o+k+q+hAQHLjgf/b/YNs6CfsgnQE1GznykPZ5trgM+wVmmA > 7mQ6sekWlYxcQ5hZIQ3wGwFQUmX9gvgRVRfz+DahrYENVg09pr86wB3DvLzVJGD4 > 2AlpOC7gMOSDbwA8Q1vWD8wx1bwNDeWrQ8zyPz7qfI5Ia/cbohyIJn48QOB5W6bW > xWHpLS8Ds31rmQq3TV5xHB0fefvK22IyY4iVK250NA0zJSeCjo9AZIR83umSHI2u > 44qm8zB5N29pkRXezTHvg8fQTp6Mq1GVm0D9urshnmyBibcWNHd3j4KOntPRJGOu > Z/59rrcy5GcaBTLq70+iuZKGRNHPD1tbzLLr0lHU1Cee5g/20Yn6Cg== > =aMgG > -----END PGP SIGNATURE----- > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 5 18:21:06 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Steve Freegard wrote: >Hi Julian, > >On Thu, 2006-01-05 at 16:45 +0000, Julian Field wrote: > > >>-----BEGIN PGP SIGNED MESSAGE----- >> >>The critical lines are these: >> >>On 5 Jan 2006, at 16:21, Ken A wrote: >> >> >> >>>error: Failed dependencies: >>> perl(RPC::PlClient) >= 0.2000 is needed by perl- >>>DBI-1.50-1.noarch >>> perl(RPC::PlServer) >= 0.2001 is needed by perl- >>>DBI-1.50-1.noarch >>> perl(Win32::ODBC) is needed by perl-DBI-1.50-1.noarch >>> >>> >>I don't understand why it thinks it needs these. My system hasn't got >>them installed and didn't need them for DBI. >> >> >> > > >I had exactly the same issues building Perl modules for DefenderMX - it >is caused by the RPM find-requires script that searches for all the >dependencies for the RPM including the optional libraries too. > > I have already fixed that. Just make /usr/lib/rpm/perl.req start with "exit 0;". That stops it trying to be too clever. If I try building the DBI RPM on an older host, we can see if that helps. I haven't got any real ancient hosts to build RPMs on any more, older ==> better for building perl rpms. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From P.G.M.Peters at UTWENTE.NL Thu Jan 5 20:12:40 2006 From: P.G.M.Peters at UTWENTE.NL (Peter Peters) Date: Thu Jan 12 21:31:39 2006 Subject: MailScanner version 5 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem wrote on 05-01-2006 14:13: > Just curious, what will it take for > MailScanner to go to version 5? It will be called MailScanner X (MSX for short) when it supports Sendmail X. - -- Peter Peters, senior beheerder (Security) Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE) Universiteit Twente, Postbus 217, 7500 AE Enschede telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQFDvX24Mbmy+DDgnIURAjWUAKDFBhX09tCO25EIyIohVa1E50a70gCfTopH hgM0zBcWJHij0lkN3LLirIA= =TXJt -----END PGP SIGNATURE----- ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mkettler at EVI-INC.COM Thu Jan 5 21:00:18 2006 From: mkettler at EVI-INC.COM (Matt Kettler) Date: Thu Jan 12 21:31:39 2006 Subject: MailScanner version 5 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Gerry Doris wrote: > I would like to see Julian release Version MS XP Pro 7.1. > No thanks.. I'd rather my MailScanner not be associated with a product so readily exploitable by simple data files. http://isc.sans.org/diary.php?storyid=972 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From james at grayonline.id.au Thu Jan 5 21:28:41 2006 From: james at grayonline.id.au (James Gray) Date: Thu Jan 12 21:31:39 2006 Subject: 4.50.4 restarts the child after each batch? Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Thu, 5 Jan 2006 13:49, James Gray wrote: > Just installed 4.49.7 on my production gateways - all is well. They are > behaving as I expected them to. > > However, I've installed the latest beta (4.50.4 from the tar ball) on my > test machine (system is an Exim 4.50-8 box running on Debian Sarge, with > MailWatch) and noticed it now restarts the child after every batch: ---8<--- SNIPPED ---8<--- I installed 4.50.5 and the behaviour is the same. The install.sh script rebuilt the following Perl modules (sorry if the names are no 100% exact, I just scribbled them on a piece of paper): IO::String 2.108 - no errors or skipped/failed tests Mime::Base64 3.05 - as above. TimeDate 1.1301 - as above. Mail::Tools 1.50 - as above. DBI 1.50 - Warning about running in production with threaded Perl Warning during thrclone tests about dereferencing a scalar vector during global destroy. I have DBD:SQLite 1.11 installed and tested with no warnings or errors. I'm stumped. The debug output is the same as 4.50.4 - after every batch, MailScanner kills off the child due to old age, even though it's (often) less than a minute old. The "Restart MailScanner" option in MailScanner.conf is set to "14400" (4 hours right?). As always - any help is very welcome :) Cheers, James -- Fred Brooks, Jr., _The Mythical Man Month_ ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From gdoris at rogers.com Thu Jan 5 20:56:58 2006 From: gdoris at rogers.com (Gerry Doris) Date: Thu Jan 12 21:31:39 2006 Subject: MailScanner version 5 Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Dave Shariff Yadallee - System Administrator a.k.a. The Root of the > Problem wrote on 05-01-2006 14:13: >> Just curious, what will it take for >> MailScanner to go to version 5? > > It will be called MailScanner X (MSX for short) when it supports Sendmail > X. > I would like to see Julian release Version MS XP Pro 7.1. MS = MailScanner XP = eXtra Powerful Pro = for the Professional Jumping levels would indicate that something really, really good has occurred. It avoids the issue that all even releases are buggy and that Julian has moved directly to the solid odd numbered fix release. It also has the advantage that the announcement of an MS XP Pro release at such a high level will trigger a flood of cheques from those so conditioned. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From alex at NKPANAMA.COM Thu Jan 5 21:08:03 2006 From: alex at NKPANAMA.COM (Alex Neuman van der Hans) Date: Thu Jan 12 21:31:39 2006 Subject: MailScanner version 5 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Matt Kettler wrote: >Gerry Doris wrote: > > I would like to see Julian release Version MS XP Pro 7.1. > > > >No thanks.. I'd rather my MailScanner not be associated with a product so >readily exploitable by simple data files. > > > WMF is more like PostScript in the sense that it's not really a data file, it's more like high-level programming language that you can store GDI functions in. In that sense it's more of a logical design flaw in the way the WMF concept is allowed to do this than a flaw in the "product". It's just that nobody seemed to care/think about it that way until now. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mailscanner at ELIQUID.COM Thu Jan 5 21:05:26 2006 From: mailscanner at ELIQUID.COM (Wess Bechard) Date: Thu Jan 12 21:31:39 2006 Subject: MailScanner version 5 Message-ID: [ The following text is in the "utf-8" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Thanks, I really needed a good laugh. The odd version numbers bit is golden. :) On Thu, 2006-01-05 at 15:56 -0500, Gerry Doris wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Dave Shariff Yadallee - System Administrator a.k.a. The Root of the > Problem wrote on 05-01-2006 14:13: >> Just curious, what will it take for >> MailScanner to go to version 5? > > It will be called MailScanner X (MSX for short) when it supports Sendmail > X. > I would like to see Julian release Version MS XP Pro 7.1. MS = MailScanner XP = eXtra Powerful Pro = for the Professional Jumping levels would indicate that something really, really good has occurred. It avoids the issue that all even releases are buggy and that Julian has moved directly to the solid odd numbered fix release. It also has the advantage that the announcement of an MS XP Pro release at such a high level will trigger a flood of cheques from those so conditioned. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ___________________________________________ Wess Bechard Information Technology Manager eliquidMEDIA International Inc. Visit: www.eliquid.com Office: 519.973.1930 - 1.800.561.7525 Fax: 519.253.0337 Cell: 519.791.9492 ___________________________________________ ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From james at grayonline.id.au Thu Jan 5 21:43:36 2006 From: james at grayonline.id.au (James Gray) Date: Thu Jan 12 21:31:39 2006 Subject: 4.50.4 restarts the child after each batch? -=SOLVED=- Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Thu, 5 Jan 2006 13:49, James Gray wrote: > Just installed 4.49.7 on my production gateways - all is well. They are > behaving as I expected them to. > > However, I've installed the latest beta (4.50.4 from the tar ball) on my > test machine (system is an Exim 4.50-8 box running on Debian Sarge, with > MailWatch) and noticed it now restarts the child after every batch: ... > MailScanner[12542]: New Batch: Scanning 1 messages, 5532 bytes The failure to complete in debug mode with MailWatch enabled should have pointed me in the right direction. Now repeat after me: when installing a new tar-ball version COPY THE CUSTOM FUNCTIONS TO THE NEW VERSION! Once I copied the MailWatch.pm from /opt/MailScanner-4.42.9/lib/MailScanner/CustomFunctions to /opt/MailScanner-4.50.5/lib/MailScanner/CustomFunctions restarted and VOILA! I'm such a tool. That'll teach me to leave it so long between upgrades - I completely forgot all the bits I needed to copy. Really makes me appreciate the effort Julian puts into the RPM packages. The CentOS gateways and such a breeze to upgrade!! Thanks Julian :) Thanks also to Matt Hampton and Raymond Dijkxhoorn who offered suggestions. Cheers, James -- add a GF2/3, a sizable hard drive, and a 15" flat panel and you've got a pretty damned portable machine. a GeForce Two-Thirds? Coderjoe: yes, a GeForce two-thirds, ie, any card from ATI. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From raymond at PROLOCATION.NET Thu Jan 5 21:46:08 2006 From: raymond at PROLOCATION.NET (Raymond Dijkxhoorn) Date: Thu Jan 12 21:31:39 2006 Subject: Beta 4.50.4 released -- faster than 4.49 Message-ID: Hi! > I might just end up putting in the 4 config options to do it. Hooray! :) Bye, Raymond. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From jaearick at COLBY.EDU Thu Jan 5 22:27:14 2006 From: jaearick at COLBY.EDU (Jeff A. Earickson) Date: Thu Jan 12 21:31:39 2006 Subject: MailScanner version 5 Message-ID: Hi, Come on, you guys are kicking the question around like it was totally bogus. I thought that it was a reasonable if somewhat out-there question. Julian has the final word here, but I would guess: a) The version that allows one to specify the order of scanning, ie virus then spam or vice-versa. This topic comes up regularly and Julian says it is non-trivial. If he ever does implement this, then maybe that version is 5.0. b) Julian sells MailScanner off to a Major Corporation and we all have to start paying license fees. Then Major Widgets LTD will raise the version number, make it incompatible with all previous versions, have a call center that plays obnoxious music, and charge us beaucoup dollars/euros. Jeff Earickson Colby College ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Thu Jan 5 23:31:05 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:39 2006 Subject: MailScanner version 5 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/5/06, Jeff A. Earickson wrote: b) Julian sells MailScanner off to a Major Corporation and we all have to start paying license fees. Then Major Widgets LTD will raise the version number, make it incompatible with all previous versions, have a call center that plays obnoxious music, and charge us beaucoup dollars/euros. :-) -- /peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From alex at NKPANAMA.COM Fri Jan 6 00:01:48 2006 From: alex at NKPANAMA.COM (Alex Neuman van der Hans) Date: Thu Jan 12 21:31:39 2006 Subject: MailScanner version 5 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Isn't MailScanner GPL? Wouldn't such an action be called "pulling a Nessus"? (compare to http://en.wikipedia.org/wiki/Pull_a_homer) :) Jeff A. Earickson wrote: > Hi, > Come on, you guys are kicking the question around like it was > totally bogus. I thought that it was a reasonable if somewhat out-there > question. Julian has the final word here, but I would guess: > > a) The version that allows one to specify the order of scanning, ie > virus then spam or vice-versa. This topic comes up regularly and > Julian says it is non-trivial. If he ever does implement this, > then maybe that version is 5.0. > > b) Julian sells MailScanner off to a Major Corporation and we all > have to start paying license fees. Then Major Widgets LTD will raise > the version number, make it incompatible with all previous versions, > have a call center that plays obnoxious music, and charge us beaucoup > dollars/euros. > > Jeff Earickson > Colby College > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From jlmiller at MMTNETWORKS.COM.AU Fri Jan 6 06:30:29 2006 From: jlmiller at MMTNETWORKS.COM.AU (Jon Miller) Date: Thu Jan 12 21:31:39 2006 Subject: test setup Message-ID: First like to say my copy of the MailScanner book has just arrived and I'm ready to try to set up a test system to install MS, SA, SAV, MCP,etc. What I would like to do is have mail from our regular mail server send a copy to this server, so we can see how the setup works with real mail. We are using a Debian server with postfix as our MTA. Any ideas or diagram/instructions available on the subject? Thanks JLM ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! [ Part 2, "HTML" Text/PLAIN 24 lines. ] [ Unable to print this part. ] From MailScanner at ecs.soton.ac.uk Fri Jan 6 09:05:14 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:39 2006 Subject: MailScanner version 5 Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 5 Jan 2006, at 22:27, Jeff A. Earickson wrote: > b) Julian sells MailScanner off to a Major Corporation and we all > have to start paying license fees. Then Major Widgets LTD will raise > the version number, make it incompatible with all previous versions, > have a call center that plays obnoxious music, and charge us > beaucoup dollars/euros. Now there's a good idea! Just need to choose the music. t.A.T.u. should do nicely. The one thing you forgot is that I will of course be the majority stockholder in Major Corporation. Why make money once when you can make it twice? - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ74yzfw32o+k+q+hAQFCzggAk+MaHoc0/NanP5TK/nf8h/3zcmU2Vvlg yPSksdov+TfpdQLHM/cOLsioNMxzj0bNUyRvVwCdC0ZZIuUKAM1VYWGMAiW1JfGr Iev+1o4LOwb0xabmzgovwzyUF/CpCEg3rdhsy9Tzk8Ys2sX8keG5pl5R0i0Z7wXS FNdGkweh/oa/KWIPKIHJPOud4UKboAxsis6wLPNuOK9/9PL5A84JdD0+WCjXsNQM 5GteoZw+q7e9WnhlSpNAifZmFE7khZ61yuSJFACD4vBEOKZAgZMADlyYNCbdoz1B xHASzV0LdblmBHpbAu4eYLysDssO9t0BjsFt9bGKza4LgioCdQq6pg== =j0u7 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Fri Jan 6 09:29:09 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:39 2006 Subject: test setup Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/6/06, Jon Miller wrote: First like to say my copy of the MailScanner book has just arrived and I'm ready to try to set up a test system to install MS, SA, SAV, MCP,etc. What I would like to do is have mail from our regular mail server send a copy to this server, so we can see how the setup works with real mail. We are using a Debian server with postfix as our MTA. Any ideas or diagram/instructions available on the subject? I test mine by manually sending mail from them to an external account (e.g. Gmail). Then I can test plain text, forbidden attachments, eicar viruses and spam (gtube). It doesn't really matter which way mail travels through a mail server. When you know it delivers mail you can put it into production, just limit its use to a few people by using rulesets. Then you can test reasonable values and actions for spam and other things. -- /peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From glenn.steen at GMAIL.COM Fri Jan 6 09:50:42 2006 From: glenn.steen at GMAIL.COM (Glenn Steen) Date: Thu Jan 12 21:31:39 2006 Subject: MailScanner version 5 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 06/01/06, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > > On 5 Jan 2006, at 22:27, Jeff A. Earickson wrote: > > > b) Julian sells MailScanner off to a Major Corporation and we all > > have to start paying license fees. Then Major Widgets LTD will raise > > the version number, make it incompatible with all previous versions, > > have a call center that plays obnoxious music, and charge us > > beaucoup dollars/euros. Um, Jules, Steve and Steve are just too nice people... What fsl sell is pretty much the light version of this, wouldn't you say?:-) > > Now there's a good idea! > Just need to choose the music. > t.A.T.u. should do nicely. euw... Please Jules, stick to programming.... You're way to evil as a muzak selector....:-) (Sorry all you t.A.T.u. lovers.... Just can't stand them... please don't flame me for my tender ears:-) > > The one thing you forgot is that I will of course be the majority > stockholder in Major Corporation. Why make money once when you can > make it twice? ... So you'll be buying into fsl now?-):-) (Just couldn't resist... As usual, just ignore;-) -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From glenn.steen at GMAIL.COM Fri Jan 6 09:58:25 2006 From: glenn.steen at GMAIL.COM (Glenn Steen) Date: Thu Jan 12 21:31:39 2006 Subject: test setup Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 06/01/06, shuttlebox wrote: > On 1/6/06, Jon Miller wrote: > > First like to say my copy of the MailScanner book has just arrived and I'm > ready to try to set up a test system to install MS, SA, SAV, MCP,etc. > > What I would like to do is have mail from our regular mail server send a > copy to this server, so we can see how the setup works with real mail. > > We are using a Debian server with postfix as our MTA. > > Any ideas or diagram/instructions available on the subject? > > > > I test mine by manually sending mail from them to an external account (e.g. > Gmail). Then I can test plain text, forbidden attachments, eicar viruses and > spam (gtube). It doesn't really matter which way mail travels through a mail > server. When you know it delivers mail you can put it into production, just > limit its use to a few people by using rulesets. Then you can test > reasonable values and actions for spam and other things. > > -- > /peter > Good thought. What I tend to do (to test out all the postfix UCE stuff) is to "script up some telnets" from an untrusted local client. No test like putting it into the loop though:-). -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From drew at THEMARSHALLS.CO.UK Fri Jan 6 12:29:05 2006 From: drew at THEMARSHALLS.CO.UK (Drew Marshall) Date: Thu Jan 12 21:31:39 2006 Subject: test setup Message-ID: On 6 Jan 2006, at 06:30, Jon Miller wrote: > First like to say my copy of the MailScanner book has just arrived > and I'm ready to try to set up a test system to install MS, SA, > SAV, MCP,etc. > What I would like to do is have mail from our regular mail server > send a copy to this server, so we can see how the setup works with > real mail. > We are using a Debian server with postfix as our MTA. > Any ideas or diagram/instructions available on the subject? > When the test server is up and running you could always just tell your existing Postfix server to BCC an account on the test box with all mail. That would give it a real life testing (Although it would only test mail that has made it's way through the existing server, so valid recipients, non RBL listed IP's etc. This shouldn't be too bad though as you are after testing MailScanner, right?). Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From radislav.vrnata at PORCELA.CZ Fri Jan 6 13:10:31 2006 From: radislav.vrnata at PORCELA.CZ (Radislav Vrnata) Date: Thu Jan 12 21:31:39 2006 Subject: Filetype code BUG ? Message-ID: [ The following text is in the "ISO-8859-2" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Hi all, I have big problem with regular detecting of MPEG attachments based on Filetype rules. When I sent "PLAIN TEXT" e-mail with ISO-8859-2 encoding and first two characters of body are "Vá" e.g. in Czech "Vá¾ený" (in English "Dear"), then MS recognize him as "MPEG movie" !!! (log says "Filetype Checks: No MPEG movies (42C121B907CA.60823 msg-24637-201.txt)"). If I write "space character" before "Vá", then everything is all right... Any suggestions ? Regards, Radislav. Postfix 2.1.5 Cyrus IMAP 2.2.12 This is Fedora Core release 3 (Heidelberg) This is Perl version 5.008005 (5.8.5) This is MailScanner version 4.49.7 Module versions are: 1.00 AnyDBM_File 1.14 Archive::Zip 1.03 Carp 1.119 Convert::BinHex 1.00 DirHandle 1.05 Fcntl 2.73 File::Basename 2.08 File::Copy 2.01 FileHandle 1.06 File::Path 0.16 File::Temp 1.29 HTML::Entities 3.45 HTML::Parser 2.30 HTML::TokeParser 1.21 IO 1.10 IO::File 1.123 IO::Pipe 1.67 Mail::Header 3.05 MIME::Base64 5.417 MIME::Decoder 5.417 MIME::Decoder::UU 5.417 MIME::Head 5.417 MIME::Parser 3.03 MIME::QuotedPrint 5.417 MIME::Tools 0.10 Net::CIDR 1.08 POSIX 1.77 Socket 0.08 Sys::Syslog 1.02 Time::localtime Optional module versions are: 0.17 Convert::TNEF 1.814 DB_File 1.08 Digest 1.01 Digest::HMAC 2.36 Digest::MD5 2.10 Digest::SHA1 0.44 Inline 0.17 Mail::ClamAV 3.000004 Mail::SpamAssassin 1.997 Mail::SPF::Query 0.18 Net::CIDR::Lite 0.55 Net::DNS 0.31 Net::LDAP 1.94 Parse::RecDescent missing SAVI 1.4 Sys::Hostname::Long 2.56 Test::Harness 0.62 Test::Simple 1.95 Text::Balanced 1.35 URI ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Fri Jan 6 14:40:17 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:39 2006 Subject: Filetype code BUG ? Message-ID: [ The following text is in the "WINDOWS-1252" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] -----BEGIN PGP SIGNED MESSAGE----- This is a bug in the "file" command. Please report it to the authors. On 6 Jan 2006, at 13:10, Radislav Vrnata wrote: > Hi all, > > I have big problem with regular detecting of MPEG attachments based on > Filetype rules. > > When I sent "PLAIN TEXT" e-mail with ISO-8859-2 encoding and first two > characters of body are "Vá" e.g. in Czech "Vá^Þený" (in English > "Dear"), > then MS recognize him as "MPEG movie" !!! (log says "Filetype > Checks: No > MPEG movies (42C121B907CA.60823 msg-24637-201.txt)"). > If I write "space character" before "Vá", then everything is all > right... > > Any suggestions ? > > Regards, > > Radislav. > > > Postfix 2.1.5 > Cyrus IMAP 2.2.12 > This is Fedora Core release 3 (Heidelberg) > This is Perl version 5.008005 (5.8.5) > This is MailScanner version 4.49.7 > Module versions are: > 1.00 AnyDBM_File > 1.14 Archive::Zip > 1.03 Carp > 1.119 Convert::BinHex > 1.00 DirHandle > 1.05 Fcntl > 2.73 File::Basename > 2.08 File::Copy > 2.01 FileHandle > 1.06 File::Path > 0.16 File::Temp > 1.29 HTML::Entities > 3.45 HTML::Parser > 2.30 HTML::TokeParser > 1.21 IO > 1.10 IO::File > 1.123 IO::Pipe > 1.67 Mail::Header > 3.05 MIME::Base64 > 5.417 MIME::Decoder > 5.417 MIME::Decoder::UU > 5.417 MIME::Head > 5.417 MIME::Parser > 3.03 MIME::QuotedPrint > 5.417 MIME::Tools > 0.10 Net::CIDR > 1.08 POSIX > 1.77 Socket > 0.08 Sys::Syslog > 1.02 Time::localtime > > Optional module versions are: > 0.17 Convert::TNEF > 1.814 DB_File > 1.08 Digest > 1.01 Digest::HMAC > 2.36 Digest::MD5 > 2.10 Digest::SHA1 > 0.44 Inline > 0.17 Mail::ClamAV > 3.000004 Mail::SpamAssassin > 1.997 Mail::SPF::Query > 0.18 Net::CIDR::Lite > 0.55 Net::DNS > 0.31 Net::LDAP > 1.94 Parse::RecDescent > missing SAVI > 1.4 Sys::Hostname::Long > 2.56 Test::Harness > 0.62 Test::Simple > 1.95 Text::Balanced > 1.35 URI > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ76BU/w32o+k+q+hAQEKpgf/flzxnvz8WW0hPDagWUY/N55lsc38IPB1 UKppx93ykrkO+3t86DJNABC9yQOyR1+pq/eLiv0LzRTio9NhSKoPg79B164Q8Rcq PGIU7jowFo0fsD01qvfxGOTcl1wdkDzr49X2l2xZULvKPvZW+3kkGDxTdjzFg99A jz4ZbLYENZax60F76Sf7NEsWCczs158zYMk9+DZhvnfdMh5Pd5PjjH+mVcG9XfPD EcBLRRspjZMfsw17o3ba6udb4LOomG/iyyP0Athc6JANc8agkpmvI2AvedOoiTQ9 yMOkSGDaqiSipEHDTo7Ggl0iWquM3dFfjRltFLyWETb/7sS3DqhkOw== =QS9P -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From cgi at BYTESINTERACTIVE.COM Fri Jan 6 15:03:58 2006 From: cgi at BYTESINTERACTIVE.COM (David Jay) Date: Thu Jan 12 21:31:39 2006 Subject: Recover Attachments Message-ID: Hi, I'm fairly new to administrating e-mail. I've installed mailscanner with spam assassin and clam. I like the fact that the program removes attachements but a customer asked to recover a particular attachment. The attachements are in: /var/spool/MailScanner/quarantine/20060103 (message k0406wN7026968) I see that the attachments are there. How does one recover the attachments and send them to the client by e-mail without being quarantined again. Thank-you in advance David J. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Fri Jan 6 15:47:52 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:39 2006 Subject: Recover Attachments Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/6/06, David Jay wrote: I like the fact that the program removes attachements but a customer asked to recover a particular attachment. The attachements are in: /var/spool/MailScanner/quarantine/20060103 (message k0406wN7026968) I see that the attachments are there. How does one recover the attachments and send them to the client by e-mail without being quarantined again. That depends on your MTA. Look here: http://wiki.mailscanner.info/doku.php?id=maq:index#misc._questions -- /peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dave.list at PIXELHAMMER.COM Fri Jan 6 16:35:15 2006 From: dave.list at PIXELHAMMER.COM (DAve) Date: Thu Jan 12 21:31:39 2006 Subject: Virus slow down? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Is anyone else noticing a huge drop in viruses? Last night at 10pm EST my virus captures dropped to an all time low. I generally catch around 1100 per day, per server, and I have only caught 60 so far today. Everything else in MailScanner MRTG looks good, Clam and BD are up to date, no problems in the logs. I don't suspect anything wrong on my end, just a pleasent lack of viruses. DAve ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From cgi at BYTESINTERACTIVE.COM Fri Jan 6 16:36:43 2006 From: cgi at BYTESINTERACTIVE.COM (David Jourard) Date: Thu Jan 12 21:31:39 2006 Subject: Recover Attachments Message-ID: Hi, Thanks Peter, At 04:47 PM 06/01/2006 +0100, shuttlebox wrote: >/var/spool/MailScanner/quarantine/20060103 (message k0406wN7026968) >> >>That depends on your MTA. Look here: >>http:/ >>/wiki.mailscanner.info/doku.php?id=maq:index#misc._questions I have sendmail. From Wiki: Copy the qf- and df- files in the outgoing queue (usually /var/spool/mqueue) How do I create qf and df files into the outgoing queue given the fact that the attachments are in a folder called: k0406wN7026968 Again Thanks David J. -- No virus found in this outgoing message. Checked by AVG Anti-Virus. Version: 7.1.371 / Virus Database: 267.14.13/221 - Release Date: 04/01/2006 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From alvaro at HOSTALIA.COM Fri Jan 6 16:24:46 2006 From: alvaro at HOSTALIA.COM (Alvaro Marin) Date: Thu Jan 12 21:31:39 2006 Subject: Problems with clamavmodule Message-ID: Hi, I'm using version 4.49.7 of MailScanner and I trying to use Clamavmodule to scan messages for virus. Here the configuration: Virus Scanners = clamavmodule ClamAVmodule Maximum Recursion Level = 8 ClamAVmodule Maximum Files = 1000 ClamAVmodule Maximum File Size = 10000000 ClamAVmodule Maximum Compression Ratio = 250 Some attachments are scanned and detected fine : Jan 6 16:30:16 linux01 MailScanner[8985]: ClamAVModule::INFECTED:: Worm.SomeFool.P:: ./1EutXc-0005QP-F0/message.scr but other ones: Jan 6 13:02:38 linux01 MailScanner[19498]: ClamAVModule::ERROR:: File size limit exceeded.:: ./1EuqIj-0005Gm-Fs/downloadm.zip where downloadm.zip is a 55ks file (sober.U-3) sent by me: -rw-r--r-- 1 split users 55K ene 6 11:56 downloadm.zip In other servers with same MS configuration (different SO) this virus is detected. Here MailScanner -v output: This is Red Hat Linux release 7.3 (Valhalla) This is Perl version 5.008007 (5.8.7) This is MailScanner version 4.49.7 Module versions are: 1.00 AnyDBM_File 1.16 Archive::Zip 1.04 Carp 1.119 Convert::BinHex 1.00 DirHandle 1.05 Fcntl 2.73 File::Basename 2.08 File::Copy 2.01 FileHandle 1.07 File::Path 0.16 File::Temp 1.32 HTML::Entities 3.48 HTML::Parser 2.35 HTML::TokeParser 1.21 IO 1.11 IO::File 1.123 IO::Pipe 1.50 Mail::Header 3.07 MIME::Base64 5.418 MIME::Decoder 5.418 MIME::Decoder::UU 5.418 MIME::Head 5.418 MIME::Parser 3.07 MIME::QuotedPrint 5.418 MIME::Tools 0.10 Net::CIDR 1.08 POSIX 1.77 Socket 0.06 Sys::Syslog 1.02 Time::localtime Optional module versions are: 0.17 Convert::TNEF 1.814 DB_File 1.10 Digest 1.01 Digest::HMAC 2.36 Digest::MD5 2.10 Digest::SHA1 0.44 Inline 0.17 Mail::ClamAV 3.001000 Mail::SpamAssassin 1.997 Mail::SPF::Query 0.18 Net::CIDR::Lite 0.55 Net::DNS 0.33 Net::LDAP 1.94 Parse::RecDescent missing SAVI 1.4 Sys::Hostname::Long 2.48 Test::Harness 0.54 Test::Simple 1.95 Text::Balanced 1.35 URI Any ideas? Thx :) ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ard at pergamentum.com Fri Jan 6 16:44:26 2006 From: ard at pergamentum.com (Alisdair Davey) Date: Thu Jan 12 21:31:39 2006 Subject: Virus slow down? Message-ID: On Fri, 2006-01-06 at 11:35 -0500, DAve wrote: > Is anyone else noticing a huge drop in viruses? Last night at 10pm EST > my virus captures dropped to an all time low. I generally catch around > 1100 per day, per server, and I have only caught 60 so far today. > > Everything else in MailScanner MRTG looks good, Clam and BD are up to > date, no problems in the logs. I don't suspect anything wrong on my end, > just a pleasent lack of viruses. Since I upgraded to 4.48.4, I have had a week with pretty much zero virus detections (some filename catches by MailScanner)...after a couple of days of this it scared me! So I tried sending EICAR and a few less friendly viruses through the system and the detection seems to work fine. On the other hand spam detection is at an all time high! It looks like pretty much everything is being detected as High Spam. Cheers Alisdair -- Pergamentum Solutions Alisdair Davey ard@pergamentum.com 2066 Dailey Ln www.pergamentum.com Superior, CO 80027 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Fri Jan 6 17:01:57 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:39 2006 Subject: Recover Attachments Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/6/06, David Jourard wrote: I have sendmail. From Wiki: Copy the qf- and df- files in the outgoing queue (usually /var/spool/mqueue) How do I create qf and df files into the outgoing queue given the fact that the attachments are in a folder called: k0406wN7026968 It's there to: If you don't quarantine as queue files: * Sendmail : sendmail -toi user@domain < messagefile Otherwise set "Quarantine Whole Messages As Queue Files" to yes. I use that. -- /peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From lbcadmin at gmail.com Fri Jan 6 16:46:48 2006 From: lbcadmin at gmail.com (Information Services) Date: Thu Jan 12 21:31:39 2006 Subject: Hard Lock Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] I posted this on the CentOS forumn, and received no responses. I am really not sure where the issue is coming from, but my mailscanner systems occassionally lock up, and I have been unable to resolve why this is happening. can anyone shed some light on this for me. here is what I have on the centos forumn ---------------------------------------------------------------------------- I have two CentOS 4.1 mailscanner servers that like to lock up for some unknown reason. Both machines are Dell Optiplex G1's with powerleaps installed to make them 1.1Ghz processors. 512 RAM As I said above, running 4.1 Other information: mailscanner-4.47.4-2 clamav-0.87 inoculate mailwatch-1.0.1 sendmail-8.13.4-1 webmin-1.210 phpmyadmin-2.6.3-pl1 spamassassin-3.1.0 Both machines are setup this way. I have two issues with both, and cannot figure them out. First, When I reboot the systems, it takes about 20 minutes before the login screen appears. I am able to shell into the systems themselves and work on them, but I would like to resolve why they don't bring the login screen up right away after the boot process. The GUI either sets at the blank screen with the black curser outlined in white and is an 'X' symbol, or at the progress bar at 100 percent until it finally shows the login screen. Issue 2: I have been havin problems with both servers locking up. One server more than the other. Here is information I have from the logs and am not sure what do to about them. Today I downloaded chkrootkit to see if my systems have been tampered with, but not sure what to make of a line of information. Below is information from my var/log/messages, var/log/maillog, and piped info from running the chkrootkit. /VAR/LOG/MAILLOG ------------------------------ Dec 23 00:37:55 wks-lin9 MailScanner[24300]: Started SQL Logging child Dec 23 00:38:00 wks-lin9 MailScanner[24300]: Logging message jBN6bgKn030181 to SQL Dec 23 00:38:00 wks-lin9 MailScanner[24300]: Logging message jBN6bfED030180 to SQL Dec 23 00:38:00 wks-lin9 MailScanner[30202]: jBN6bgKn030181: Logged to MailWatch SQL Dec 23 00:38:00 wks-lin9 MailScanner[30202]: jBN6bfED030180: Logged to MailWatch SQL Dec 23 00:40:01 wks-lin9 sendmail[30089]: jBMLmqie001220: timeout waiting for input from jacobson-fw.jacobsonco.com. during client greeting Dec 23 00:40:01 wks-lin9 sendmail[30089]: jBMLmqie001220: to=,, delay=08:51:09, xdelay=00:05:00, mailer=esmtp, pri=4906016, relay=jacobson-fw.jacobsonco.com. [numericlinkwarning 65.201.33.146], dsn=4.0.0, stat=Deferred: Connection timed out with jacobson-fw.jacobsonco.com. Dec 23 14:28:27 wks-lin9 sendmail[2295]: alias database /etc/aliases rebuilt by root ------------------------------ /VAR/LOG/MESSAGES ------------------------------ Dec 23 00:35:01 wks-lin9 crond(pam_unix)[30112]: session opened for user root by (uid=0) Dec 23 00:35:01 wks-lin9 crond(pam_unix)[30114]: session opened for user root by (uid=0) Dec 23 00:35:02 wks-lin9 crond(pam_unix)[30112]: session closed for user root Dec 23 00:35:09 wks-lin9 crond(pam_unix)[30114]: session closed for user root Dec 23 00:40:01 wks-lin9 crond(pam_unix)[30204]: session opened for user root by (uid=0) Dec 23 00:40:01 wks-lin9 crond(pam_unix)[30207]: session opened for user root by (uid=0) Dec 23 00:40:01 wks-lin9 crond(pam_unix)[30205]: session opened for user root by (uid=0) Dec 23 00:40:02 wks-lin9 crond(pam_unix)[30207]: session closed for user root Dec 23 00:40:03 wks-lin9 crond(pam_unix)[30204]: session closed for user root Dec 23 00:40:10 wks-lin9 crond(pam_unix)[30205]: session closed for user root Dec 23 14:28:22 wks-lin9 syslogd 1.4.1: restart. Dec 23 14:28:22 wks-lin9 syslog: syslogd startup succeeded Dec 23 14:28:22 wks-lin9 kernel: klogd 1.4.1, log source = /proc/kmsg started. ------------------------------ OUTPUT FROM RUNNING CHKROOTKIT ------------------------------ [snip] Searching for suspicious files and dirs, it may take a while... /usr/lib/perl5/vendor_perl/5.8.5/i386-linux-thread-multi/auto/Gaim/.packlist/usr/lib/perl5/vendor_perl/5.8.5/i386-linux-thread-multi/auto/mod_perl/.packlis /usr/lib/perl5/5.8.5/i386-linux-thread-multi/.packlist/usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/auto/razor-agents/.packl st/usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/auto/Mail/SpamAssassin/. acklist/usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/auto/razor-agents-sdk/.p cklist /usr/lib/qt-3.3/etc/settings/.qt_plugins_3.3rc.lock /usr/lib/qt-3.3/etc/settings/.qtrc.lock [snip] ------------------------------ I am stuck at the moment. It does not appear to me that my systems have been 'hijacked' or any other meaningful information has been given so I can narrow down the cause of my problems. Of course, that is from my knowledge level, maybe someone else can tell me what they see from this information, or I could provide even further information to figure this out. I checked my cron jobs to see if there would be anything that would be causing this lockup, but I have the nothing out of the ordinary, and I am not too concerned with it because I think it would be causing a problem at a set time if it was something in cron causing the issue. Any help is appreciated. Casey ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ralloway at WINBEAM.COM Fri Jan 6 17:30:50 2006 From: ralloway at WINBEAM.COM (Richard D Alloway) Date: Thu Jan 12 21:31:39 2006 Subject: Virus slow down? Message-ID: On Fri, 6 Jan 2006, DAve wrote: > Is anyone else noticing a huge drop in viruses? Last night at 10pm EST my > virus captures dropped to an all time low. I generally catch around 1100 per > day, per server, and I have only caught 60 so far today. > > Everything else in MailScanner MRTG looks good, Clam and BD are up to date, > no problems in the logs. I don't suspect anything wrong on my end, just a > pleasent lack of viruses. I've noticed a HUGE drop is viruses, too. About 1/4 to 1/8 the "normal" traffic....not that I'm complaining! :) -Richard D Alloway, Esq Chief Technical Officer Winbeam ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Fri Jan 6 17:30:25 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:39 2006 Subject: Problem installing DBI solved Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Just to let you know that I have found the problem with DBI not installing on Fedora (and other) systems. The /usr/lib/rpm/perl.req is far too keen to find Perl dependencies where there are none. So I replace it with an "exit 0;" script and save the original, which is replaced at the end of the script. It doesn't matter too much if you lose perl.req, it's pretty useless anyway as it works very badly. This will be in the next release. For now, just use CPAN which doesn't suffer this problem, or use "-- nodeps" which will force it to work. It shouldn't do any harm. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ76pM/w32o+k+q+hAQG/qgf/VWD0E7sKWcC3oMdInbyEHkSOp/tiF1By TRJp4+qrnah2BAyHyfC8m6tfncFg8vNKRD/XpySqNJgLVYv77JZCIkfAU+yNVJbL ht8E9x523cmgbdpUlwPHuUuqYL9uxXgejW/fM9L1mYQyYeoGD6ezJIonIDXNdvdY 01BgZzQQm4HDTSTGuP5BAciey0tzH5ytseMZ4cPI/1u1Lg7xdBDr/Yj6q9j4OWqe wx8HZ4/kBRBumDnlOyEYEEra9BtAuqDDa6LrqU9O1A9vdkhc/R5IG9ffNcpfcck2 tAY1kQZlp4VmzzUaO3LxA2iJsP7N8hxLydbS108tHan0k1VmK8/0og== =usaX -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From P.G.M.Peters at UTWENTE.NL Fri Jan 6 17:17:25 2006 From: P.G.M.Peters at UTWENTE.NL (Peter Peters) Date: Thu Jan 12 21:31:39 2006 Subject: Virus slow down? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 DAve wrote on 06-01-2006 17:35: > Is anyone else noticing a huge drop in viruses? Last night at 10pm EST > my virus captures dropped to an all time low. I generally catch around > 1100 per day, per server, and I have only caught 60 so far today. I can see a rise at the end of november. And it dropped down at midnight monday to tuesday. I have had a rise during the afternoon on tuesday (3 times the amount per minute compared to monday) but after that I haven't seen barely any virusses. An average of 1 virus every two minutes. December was top with 20 virusses per minute. - -- Peter Peters, senior beheerder (Security) Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE) Universiteit Twente, Postbus 217, 7500 AE Enschede telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQFDvqYlMbmy+DDgnIURAjhkAKD4+5fRKvtBvQX5LX7epMo62IseEwCdF+9B cS6/V64dQH/X5F++jyrqmBw= =fH/h -----END PGP SIGNATURE----- ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ssilva at SGVWATER.COM Fri Jan 6 17:13:10 2006 From: ssilva at SGVWATER.COM (Scott Silva) Date: Thu Jan 12 21:31:39 2006 Subject: Virus slow down? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Alisdair Davey spake the following on 1/6/2006 8:44 AM: > On Fri, 2006-01-06 at 11:35 -0500, DAve wrote: > >>Is anyone else noticing a huge drop in viruses? Last night at 10pm EST >>my virus captures dropped to an all time low. I generally catch around >>1100 per day, per server, and I have only caught 60 so far today. >> >>Everything else in MailScanner MRTG looks good, Clam and BD are up to >>date, no problems in the logs. I don't suspect anything wrong on my end, >>just a pleasent lack of viruses. > > > Since I upgraded to 4.48.4, I have had a week with pretty much zero > virus detections (some filename catches by MailScanner)...after a couple > of days of this it scared me! So I tried sending EICAR and a few less > friendly viruses through the system and the detection seems to work > fine. On the other hand spam detection is at an all time high! It looks > like pretty much everything is being detected as High Spam. > Cheers > Alisdair > > If you are using Pyzor, Razor, DCC a lot of the viruses that don't mutate heavily are getting marked as spam. Be careful if you let users release their own spam! -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From prandal at HEREFORDSHIRE.GOV.UK Fri Jan 6 17:22:09 2006 From: prandal at HEREFORDSHIRE.GOV.UK (Randal, Phil) Date: Thu Jan 12 21:31:39 2006 Subject: Virus slow down? Message-ID: The latest Sober variant switched off yesterday - we've only received 4 copies today. See http://www.f-secure.com/weblog/#00000772 Cheers, Phil ---- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: MailScanner mailing list > [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Peter Peters > Sent: 06 January 2006 17:17 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: Virus slow down? > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > DAve wrote on 06-01-2006 17:35: > > Is anyone else noticing a huge drop in viruses? Last night > at 10pm EST > > my virus captures dropped to an all time low. I generally > catch around > > 1100 per day, per server, and I have only caught 60 so far today. > > I can see a rise at the end of november. And it dropped down > at midnight monday to tuesday. I have had a rise during the > afternoon on tuesday (3 times the amount per minute compared > to monday) but after that I haven't seen barely any virusses. > An average of 1 virus every two minutes. > December was top with 20 virusses per minute. > > - -- > Peter Peters, senior beheerder (Security) Dienst > Informatietechnologie, Bibliotheek en Educatie (ITBE) > Universiteit Twente, Postbus 217, 7500 AE Enschede > telefoon: 053 - 489 2301, fax: 053 - 489 2383, > http://www.utwente.nl/itbe -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.2 (MingW32) > Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org > > iD8DBQFDvqYlMbmy+DDgnIURAjhkAKD4+5fRKvtBvQX5LX7epMo62IseEwCdF+9B > cS6/V64dQH/X5F++jyrqmBw= > =fH/h > -----END PGP SIGNATURE----- > > ------------------------ MailScanner list > ------------------------ To unsubscribe, email > jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) > and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From prandal at HEREFORDSHIRE.GOV.UK Fri Jan 6 17:28:08 2006 From: prandal at HEREFORDSHIRE.GOV.UK (Randal, Phil) Date: Thu Jan 12 21:31:39 2006 Subject: Virus slow down? Message-ID: See http://www.sng.ecs.soton.ac.uk/mailscanner/serve/cache/277.html We're still seeing a drop in virus numbers today. The calm before the next storm, probably. Phil ---- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: MailScanner mailing list > [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Scott Silva > Sent: 06 January 2006 17:13 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: Virus slow down? > > Alisdair Davey spake the following on 1/6/2006 8:44 AM: > > On Fri, 2006-01-06 at 11:35 -0500, DAve wrote: > > > >>Is anyone else noticing a huge drop in viruses? Last night > at 10pm EST > >>my virus captures dropped to an all time low. I generally > catch around > >>1100 per day, per server, and I have only caught 60 so far today. > >> > >>Everything else in MailScanner MRTG looks good, Clam and BD > are up to > >>date, no problems in the logs. I don't suspect anything wrong on my > >>end, just a pleasent lack of viruses. > > > > > > Since I upgraded to 4.48.4, I have had a week with pretty much zero > > virus detections (some filename catches by MailScanner)...after a > > couple of days of this it scared me! So I tried sending EICAR and a > > few less friendly viruses through the system and the > detection seems > > to work fine. On the other hand spam detection is at an all > time high! > > It looks like pretty much everything is being detected as High Spam. > > Cheers > > Alisdair > > > > > If you are using Pyzor, Razor, DCC a lot of the viruses that > don't mutate heavily are getting marked as spam. Be careful > if you let users release their own spam! > > > -- > > /-----------------------\ |~~\_____/~~\__ | > | MailScanner; The best |___________ \N1____====== )-+ > | protection on the net!| ~~~|/~~ | > \-----------------------/ () > > ------------------------ MailScanner list > ------------------------ To unsubscribe, email > jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) > and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From cgi at BYTESINTERACTIVE.COM Fri Jan 6 17:26:17 2006 From: cgi at BYTESINTERACTIVE.COM (David Jourard) Date: Thu Jan 12 21:31:39 2006 Subject: Recover Attachments Message-ID: Hi, Thanks. At 06:01 PM 06/01/2006 +0100, you wrote: > * Sendmail : sendmail -toi user@domain < messagefile It comes in the message body. Any ideas? Thanks David J. -- No virus found in this outgoing message. Checked by AVG Anti-Virus. Version: 7.1.371 / Virus Database: 267.14.13/221 - Release Date: 04/01/2006 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From lbergman at WTXS.NET Fri Jan 6 17:59:33 2006 From: lbergman at WTXS.NET (Lewis Bergman) Date: Thu Jan 12 21:31:39 2006 Subject: Virus slow down? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] DAve wrote: > Is anyone else noticing a huge drop in viruses? Last night at 10pm EST > my virus captures dropped to an all time low. I generally catch around > 1100 per day, per server, and I have only caught 60 so far today. > > Everything else in MailScanner MRTG looks good, Clam and BD are up to > date, no problems in the logs. I don't suspect anything wrong on my end, > just a pleasent lack of viruses. Yep, We were catching around 26,000 a day up till today. Today sitting at 80 so far. -- Lewis Bergman Texas Communications 4309 Maple St. Abilene, TX 79602-8044 Off. 325-691-1301 Cell 325-439-0533 fax 325-695-6841 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dhawal at NETMAGICSOLUTIONS.COM Fri Jan 6 20:01:15 2006 From: dhawal at NETMAGICSOLUTIONS.COM (Dhawal Doshy) Date: Thu Jan 12 21:31:40 2006 Subject: Hard Lock Message-ID: [ The following text is in the "utf-8" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Information Services writes: > I posted this on the CentOS forumn, and received no responses. I am really > not sure where the issue is coming from, but my mailscanner systems > occassionally lock up, and I have been unable to resolve why this is > happening. can anyone shed some light on this for me. > > here is what I have on the centos forumn > > ---------------------------------------------------------------------------- > I have two CentOS 4.1 mailscanner servers that like to lock up for some > unknown reason. > > Both machines are Dell Optiplex G1's with powerleaps installed to make them > 1.1Ghz processors. > 512 RAM > > As I said above, running 4.1 > > Other information: > > mailscanner-4.47.4-2 > clamav-0.87 > inoculate > mailwatch-1.0.1 > sendmail-8.13.4-1 > webmin-1.210 > phpmyadmin-2.6.3-pl1 > spamassassin-3.1.0 > > > Both machines are setup this way. I have two issues with both, and cannot > figure them out. > > First, > > When I reboot the systems, it takes about 20 minutes before the login screen > appears. I am able to shell into the systems themselves and work on them, > but I would like to resolve why they don't bring the login screen up right > away after the boot process. The GUI either sets at the blank screen with > the black curser outlined in white and is an 'X' symbol, or at the progress > bar at 100 percent until it finally shows the login screen. > > Issue 2: > > I have been havin problems with both servers locking up. One server more > than the other. > > Here is information I have from the logs and am not sure what do to about > them. Today I downloaded chkrootkit to see if my systems have been tampered > with, but not sure what to make of a line of information. Below is > information from my var/log/messages, var/log/maillog, and piped info from > running the chkrootkit. > > /VAR/LOG/MAILLOG > ------------------------------ > Dec 23 00:37:55 wks-lin9 MailScanner[24300]: Started SQL Logging child > Dec 23 00:38:00 wks-lin9 MailScanner[24300]: Logging message jBN6bgKn030181 > to SQL > Dec 23 00:38:00 wks-lin9 MailScanner[24300]: Logging message jBN6bfED030180 > to SQL > Dec 23 00:38:00 wks-lin9 MailScanner[30202]: jBN6bgKn030181: Logged to > MailWatch SQL > Dec 23 00:38:00 wks-lin9 MailScanner[30202]: jBN6bfED030180: Logged to > MailWatch SQL > Dec 23 00:40:01 wks-lin9 sendmail[30089]: jBMLmqie001220: timeout waiting > for input from jacobson-fw.jacobsonco.com. during client greeting > Dec 23 00:40:01 wks-lin9 sendmail[30089]: jBMLmqie001220: to=< > Jarrod.Carley@jacobsonco.com>,, delay=08:51:09, > xdelay=00:05:00, mailer=esmtp, pri=4906016, relay=jacobson-fw.jacobsonco.com. > [65.201.33.146], dsn=4.0.0, stat=Deferred: Connection timed out with > jacobson-fw.jacobsonco.com. > Dec 23 14:28:27 wks-lin9 sendmail[2295]: alias database /etc/aliases rebuilt > by root > ------------------------------ > > /VAR/LOG/MESSAGES > ------------------------------ > Dec 23 00:35:01 wks-lin9 crond(pam_unix)[30112]: session opened for user > root by (uid=0) > Dec 23 00:35:01 wks-lin9 crond(pam_unix)[30114]: session opened for user > root by (uid=0) > Dec 23 00:35:02 wks-lin9 crond(pam_unix)[30112]: session closed for user > root > Dec 23 00:35:09 wks-lin9 crond(pam_unix)[30114]: session closed for user > root > Dec 23 00:40:01 wks-lin9 crond(pam_unix)[30204]: session opened for user > root by (uid=0) > Dec 23 00:40:01 wks-lin9 crond(pam_unix)[30207]: session opened for user > root by (uid=0) > Dec 23 00:40:01 wks-lin9 crond(pam_unix)[30205]: session opened for user > root by (uid=0) > Dec 23 00:40:02 wks-lin9 crond(pam_unix)[30207]: session closed for user > root > Dec 23 00:40:03 wks-lin9 crond(pam_unix)[30204]: session closed for user > root > Dec 23 00:40:10 wks-lin9 crond(pam_unix)[30205]: session closed for user > root > Dec 23 14:28:22 wks-lin9 syslogd 1.4.1: restart. > Dec 23 14:28:22 wks-lin9 syslog: syslogd startup succeeded > Dec 23 14:28:22 wks-lin9 kernel: klogd 1.4.1, log source = /proc/kmsg > started. > ------------------------------ > > OUTPUT FROM RUNNING CHKROOTKIT > ------------------------------ > [snip] > > Searching for suspicious files and dirs, it may take a while... > /usr/lib/perl5/vendor_perl/5.8.5/i386-linux-thread-multi/auto/Gaim/.packlist > /usr/lib/perl5/vendor_perl/5.8.5/i386-linux-thread-multi/auto/mod_perl/.packlist > /usr/lib/perl5/5.8.5/i386-linux-thread-multi/.packlist > /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/auto/razor-agents/.packlist > /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/auto/Mail/SpamAssassin/.packlist > /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/auto/razor-agents-sdk/.packlist > /usr/lib/qt-3.3/etc/settings/.qt_plugins_3.3rc.lock /usr/lib/qt-3.3 > /etc/settings/.qtrc.lock > > [snip] > ------------------------------ > > I am stuck at the moment. It does not appear to me that my systems have been > 'hijacked' or any other meaningful information has been given so I can > narrow down the cause of my problems. Of course, that is from my knowledge > level, maybe someone else can tell me what they see from this information, > or I could provide even further information to figure this out. I checked my > cron jobs to see if there would be anything that would be causing this > lockup, but I have the nothing out of the ordinary, and I am not too > concerned with it because I think it would be causing a problem at a set > time if it was something in cron causing the issue. > > Any help is appreciated. Nothing really odd from what you've posted.. here's a few things to try. An alternate to chkrootkit. wget http://downloads.rootkit.nl/rkhunter-1.2.7.tar.gz md5sum -b rkhunter-1.2.7.tar.gz # this ought to be 288ba8a87352716384823c9ea1958fa7 rpmbuild -tb rkhunter-1.2.7.tar.gz rkhunter --update rkhunter -c Next check the output of dmesg carefully (and slowly) Also why do your servers need to run in 'init 5'? i would change it to '3' Also install sysstat (yum -y install sysstat) and monitor the output of 'iostat -x 5' for some time. Could be a bad Disk causing IO contention. Check the output of 'chkconfig --list | grep 3:on | sort' and shutdown unnecessary services (spamd,clamd etc.) Finally, install some utilities from dell (omsa or something) to check the physical state of the machine. All i can think of now, HTH. - dhawal ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mrm at MEDICINE.WISC.EDU Fri Jan 6 20:16:33 2006 From: mrm at MEDICINE.WISC.EDU (Michael Masse) Date: Thu Jan 12 21:31:40 2006 Subject: Virus slow down? Message-ID: Same here.. Typically average around 2k/day. Sitting at 60 right now. Is this the calm before the storm? Mike >>> dave.list@PIXELHAMMER.COM 1/6/2006 2:13 PM >>> Lewis Bergman wrote: > DAve wrote: > >> Is anyone else noticing a huge drop in viruses? Last night at 10pm EST >> my virus captures dropped to an all time low. I generally catch around >> 1100 per day, per server, and I have only caught 60 so far today. >> >> Everything else in MailScanner MRTG looks good, Clam and BD are up to >> date, no problems in the logs. I don't suspect anything wrong on my >> end, just a pleasent lack of viruses. > > Yep, We were catching around 26,000 a day up till today. Today sitting > at 80 so far. Don't misunderstand me, I am not complaining, but it is kinda spooky to see MailScanner so quiet. DAve ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dave.list at PIXELHAMMER.COM Fri Jan 6 20:19:42 2006 From: dave.list at PIXELHAMMER.COM (DAve) Date: Thu Jan 12 21:31:40 2006 Subject: Virus slow down? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] DAve wrote: > Lewis Bergman wrote: > >> DAve wrote: >> >>> Is anyone else noticing a huge drop in viruses? Last night at 10pm >>> EST my virus captures dropped to an all time low. I generally catch >>> around 1100 per day, per server, and I have only caught 60 so far today. >>> >>> Everything else in MailScanner MRTG looks good, Clam and BD are up to >>> date, no problems in the logs. I don't suspect anything wrong on my >>> end, just a pleasent lack of viruses. >> >> >> Yep, We were catching around 26,000 a day up till today. Today sitting >> at 80 so far. > > > Don't misunderstand me, I am not complaining, but it is kinda spooky to > see MailScanner so quiet. > > DAve Spooky as in... "I feel like one of those survivors who peers out from beneath the fire blanket after noise dies down". I know the levels of Viruses we saw in the last 18 months would have burned us if not for MailScanner. Thanks Julian, DAve ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dave.list at PIXELHAMMER.COM Fri Jan 6 20:13:10 2006 From: dave.list at PIXELHAMMER.COM (DAve) Date: Thu Jan 12 21:31:40 2006 Subject: Virus slow down? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Lewis Bergman wrote: > DAve wrote: > >> Is anyone else noticing a huge drop in viruses? Last night at 10pm EST >> my virus captures dropped to an all time low. I generally catch around >> 1100 per day, per server, and I have only caught 60 so far today. >> >> Everything else in MailScanner MRTG looks good, Clam and BD are up to >> date, no problems in the logs. I don't suspect anything wrong on my >> end, just a pleasent lack of viruses. > > Yep, We were catching around 26,000 a day up till today. Today sitting > at 80 so far. Don't misunderstand me, I am not complaining, but it is kinda spooky to see MailScanner so quiet. DAve ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From richard.siddall at ELIRION.NET Fri Jan 6 20:25:17 2006 From: richard.siddall at ELIRION.NET (Richard Siddall) Date: Thu Jan 12 21:31:40 2006 Subject: Problem installing DBI solved Message-ID: Julian Field wrote: > The /usr/lib/rpm/perl.req is far too keen to find Perl dependencies > where there are none. > So I replace it with an "exit 0;" script and save the original, which > is replaced at the end of the script. > It doesn't matter too much if you lose perl.req, it's pretty useless > anyway as it works very badly. > Oh, yuck. Julian, could you do something like: rpm --define='__perl_requires=/path/to/julians/script' in install.sh, so you don't make any persistent changes to the development environment? Regards, Richard Siddall ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From richard.siddall at ELIRION.NET Fri Jan 6 20:32:13 2006 From: richard.siddall at ELIRION.NET (Richard Siddall) Date: Thu Jan 12 21:31:40 2006 Subject: CPAN -> RPM, was: Beta 4.50.4 released -- faster than 4.49 Message-ID: Steve Freegard wrote: [snip] > > Personally I use the cpan2rpm script http://perl.arix.com/cpan2rpm/ > which you can tell to ignore requirements: > [snip] FWIW, I've been using Ovid (http://search.cpan.org/~gyepi/Ovid-0.06/) recently, mainly because it's recursive and builds RPMs for all the dependencies. (OTOH, it's not perfect: it generates horrible .spec files and doesn't handle embedded Bundles or Module::Build Makefiles correctly.) Regards, Richard Siddall ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Edge at TWU.CA Fri Jan 6 20:47:17 2006 From: Edge at TWU.CA (Richard Edge) Date: Thu Jan 12 21:31:40 2006 Subject: MailScanner problem Message-ID: I am having a problem with MailScanner after upgrading both email gateways yesterday to 4.50.4. Both gateways were upgraded using exactly the same steps but on the primary gateway it is having an issue with delivering email to our Exchange servers. It is receiving the email fine, but it is not being logged to the MailWatch database or being forwarded on to our Exchange server. When starting MailScanner on this gateway I no longer see it finding new batches of received email. and when runnin ps -ax | grep MailScanner I get the following output: 19323 ? S 0:00 MailScanner: starting children 19324 ? Z 0:00 [MailScanner ] 19352 ? Z 0:00 [MailScanner ] 19360 pts/0 S 0:00 grep MailScanner I have checked other log files but cannot see anything out of the ordinary. As mentioned the second gateway is working fine with exactly the same setup. Any suggestion of where to look next? Richard Edge Senior Systems Administrator | Technology Services Trinity Western University | t: 604.513.2089 f: 604.513.2038 | e: edge twu.ca| www.twu.ca/technology ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From martelm at QUARK.VSC.EDU Fri Jan 6 21:07:40 2006 From: martelm at QUARK.VSC.EDU (Michael H. Martel) Date: Thu Jan 12 21:31:40 2006 Subject: MailScanner problem Message-ID: --On Friday, January 06, 2006 12:47 PM -0800 Richard Edge wrote: > I am having a problem with MailScanner after upgrading both email > gateways yesterday to 4.50.4. Both gateways were upgraded using exactly I saw this myself, and it was beause I hadn't moved over the MailWatch.pm file from the old directory. Michael -- --------------------------------o--------------------------------- Michael H. Martel | Vermont State Colleges martelm@quark.vsc.edu | Systems Administrator http://probe.vsc.edu/~michael | PH:802-241-2544 FX:802-241-3363 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dhawal at NETMAGICSOLUTIONS.COM Fri Jan 6 21:07:42 2006 From: dhawal at NETMAGICSOLUTIONS.COM (Dhawal Doshy) Date: Thu Jan 12 21:31:40 2006 Subject: MailScanner problem Message-ID: [ The following text is in the "utf-8" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Richard Edge writes: > I am having a problem with MailScanner after upgrading both email > gateways yesterday to 4.50.4. Both gateways were upgraded using exactly > the same steps but on the primary gateway it is having an issue with > delivering email to our Exchange servers. It is receiving the email > fine, but it is not being logged to the MailWatch database or being > forwarded on to our Exchange server. When starting MailScanner on this > gateway I no longer see it finding new batches of received email. and > when runnin ps -ax | grep MailScanner I get the following output: > > 19323 ? S 0:00 MailScanner: starting children > > 19324 ? Z 0:00 [MailScanner ] > 19352 ? Z 0:00 [MailScanner ] > 19360 pts/0 S 0:00 grep MailScanner > > I have checked other log files but cannot see anything out of the > ordinary. > > As mentioned the second gateway is working fine with exactly the same > setup. Any suggestion of where to look next? Did you remember to copy the files in the CustomFunctions dir to the new installation (not required for RPM based installs) - dhawal ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Fri Jan 6 21:29:18 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:40 2006 Subject: Problem installing DBI solved Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Richard Siddall wrote: >Julian Field wrote: > > >>The /usr/lib/rpm/perl.req is far too keen to find Perl dependencies >>where there are none. >>So I replace it with an "exit 0;" script and save the original, which >>is replaced at the end of the script. >>It doesn't matter too much if you lose perl.req, it's pretty useless >>anyway as it works very badly. >> >> >> > >Oh, yuck. > >Julian, could you do something like: > rpm --define='__perl_requires=/path/to/julians/script' >in install.sh, so you don't make any persistent changes to the >development environment? > > Don't see quite what you mean. What I need to do is kill perl.req, I don't see what I can do apart from put it back afterwards. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mrm at MEDICINE.WISC.EDU Fri Jan 6 21:42:26 2006 From: mrm at MEDICINE.WISC.EDU (Michael Masse) Date: Thu Jan 12 21:31:40 2006 Subject: 4.49.7-1 process name feature keeps adding processes Message-ID: Using the 4.49.7-1 rpm install on a RHEL3 system. My max processes setting is set to 5 and PS shows I have 5 "mailScanner" master waiting for children, sleeping" lines and a bunch of "MailScanner: waiting for messages" lines. System seems to be working fine. The problem is that the number "MailScanner:waiting for messages" processes are increasing linearly with time with no relavance to load. Mailscanner-mrtg shows a linear graph of these processes increasing in a very straight line.. Essentially every hour on the hour 5 more of these processes are added to the running total regardless of load. I've been paranoid about this so I've been restarting MailScanner about once a day since I noticed this because I don't know if it will stop creating new processes before running out of ram, and I really don't want to find out the hard way. A look at PS after a day or so of MS running makes unfiltered PS very hard to read with the hundred+ waiting for messages entries. Is this something I should be concerned with? Will the number of these processes eventually cap out at a safe level before running out of ram? Mike ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From res at AUSICS.NET Fri Jan 6 21:44:43 2006 From: res at AUSICS.NET (Res) Date: Thu Jan 12 21:31:40 2006 Subject: MailScanner version 5 Message-ID: On Thu, 5 Jan 2006, Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem wrote: > On Thu, Jan 05, 2006 at 02:29:07PM +0100, Raymond Dijkxhoorn wrote: >> Hi! >> >>> Just curious, what will it take for >>> MailScanner to go to version 5? >> >> I want MailScanner XP, Oh MailScanner 2005... uh its just a number :) >> > > > Are you familiar with Version Numbering contril? yep, most of us are, but how can you be taken seriously with a username like yours :) > >> Bye, >> Raymond. >> >> ------------------------ MailScanner list ------------------------ >> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >> 'leave mailscanner' in the body of the email. >> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >> >> Support MailScanner development - buy the book off the website! >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> > > -- Cheers Res ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mrm at MEDICINE.WISC.EDU Fri Jan 6 22:20:09 2006 From: mrm at MEDICINE.WISC.EDU (Michael Masse) Date: Thu Jan 12 21:31:40 2006 Subject: 4.49.7-1 process name feature keeps adding processes Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Julian Field wrote: > Try killing mailscanner-mrtg, just to prove that it's not guilty of > generating them... > It appears to be a problem with check_MailScanner which I have running once an hour. It can't seem to detect that MailScanner is running, so it starts up new processes. If I do a ps axww the relavant lines are: 15006 ? S 0:00 MailScanner: master waiting for children, sleeping 15007 ? S 0:02 MailScanner: waiting for messages 15068 ? S 0:02 MailScanner: waiting for messages 15187 ? S 0:02 MailScanner: waiting for messages 15234 ? S 0:02 MailScanner: waiting for messages 15258 ? S 0:01 MailScanner: waiting for messages and I'm running check_MailScanner version 1.13.2.8 dated 2003/07/29 Is there a newer version that the rpm install isn't updating for some reason? Mike ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From richard.siddall at ELIRION.NET Fri Jan 6 21:48:43 2006 From: richard.siddall at ELIRION.NET (Richard Siddall) Date: Thu Jan 12 21:31:40 2006 Subject: Problem installing DBI solved Message-ID: Julian Field wrote: > Don't see quite what you mean. What I need to do is kill perl.req, I > don't see what I can do apart from put it back afterwards. > Well, first off, I meant rpmbuild, not rpm. If I understand rpmbuild correctly, it calls perl.req because that's the program specified in the __perl_requires macro. Do an rpmbuild --showrc and look for __perl_requires. If you redefine the macro successfully then the standard perl.req shouldn't be called. You can get rpmbuild to call your replacement script instead, without making any changes to perl.req. I was just suggesting trying to redefine the macro on the command line. I don't know if that would work. You could also try redefining it in the .spec file or in an rcfile you pass via the --rcfile command line switch. Does that make more sense? Regards, Richard Siddall ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Fri Jan 6 21:47:03 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:40 2006 Subject: 4.49.7-1 process name feature keeps adding processes Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Try killing mailscanner-mrtg, just to prove that it's not guilty of generating them... Michael Masse wrote: >Using the 4.49.7-1 rpm install on a RHEL3 system. >My max processes setting is set to 5 and PS shows I have 5 >"mailScanner" master waiting for children, sleeping" lines and a bunch >of >"MailScanner: waiting for messages" lines. > >System seems to be working fine. > >The problem is that the number "MailScanner:waiting for messages" >processes are increasing linearly with time with no relavance to load. > Mailscanner-mrtg shows a linear graph of these processes increasing in >a very straight line.. Essentially every hour on the hour 5 more of >these processes are added to the running total regardless of load. >I've been paranoid about this so I've been restarting MailScanner about >once a day since I noticed this because I don't know if it will stop >creating new processes before running out of ram, and I really don't >want to find out the hard way. A look at PS after a day or so of >MS running makes unfiltered PS very hard to read with the hundred+ >waiting for messages entries. Is this something I should be concerned >with? Will the number of these processes eventually cap out at a safe >level before running out of ram? > >Mike > >------------------------ MailScanner list ------------------------ >To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >'leave mailscanner' in the body of the email. >Before posting, read the Wiki (http://wiki.mailscanner.info/) and >the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > >Support MailScanner development - buy the book off the website! > > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Edge at TWU.CA Fri Jan 6 22:05:34 2006 From: Edge at TWU.CA (Richard Edge) Date: Thu Jan 12 21:31:40 2006 Subject: MailScanner problem Message-ID: Whew!! Problem solved. Thanks for everyone's suggestions. It appears that during my cleanup yesterday on the one gateway, I had deleted the /var/clamav directory and its contents. It was a left over from a previous ClamAV install I must have done for version .81. There are obviously some configuration files somewhere still pointing to that directory. I re-install version .87 from an RPM which put things back the way they were except with version .87 until I can find where the real problem is. This now allowed MailScanner to load and do its thing as it should. Now I will just have to hunt down which config is still pointing to that directory. Richard Edge Senior Systems Administrator | Technology Services Trinity Western University | t: 604.513.2089 f: 604.513.2038 | e: edge twu.ca| www.twu.ca/technology -----Original Message----- From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Dhawal Doshy Sent: Friday, January 06, 2006 1:08 PM To: MAILSCANNER@JISCMAIL.AC.UK Subject: Re: [MAILSCANNER] MailScanner problem Richard Edge writes: > I am having a problem with MailScanner after upgrading both email > gateways yesterday to 4.50.4. Both gateways were upgraded using > exactly the same steps but on the primary gateway it is having an > issue with delivering email to our Exchange servers. It is receiving > the email fine, but it is not being logged to the MailWatch database > or being forwarded on to our Exchange server. When starting > MailScanner on this gateway I no longer see it finding new batches of > received email. and when runnin ps -ax | grep MailScanner I get the following output: > > 19323 ? S 0:00 MailScanner: starting children > > 19324 ? Z 0:00 [MailScanner ] > 19352 ? Z 0:00 [MailScanner ] > 19360 pts/0 S 0:00 grep MailScanner > > I have checked other log files but cannot see anything out of the > ordinary. > > As mentioned the second gateway is working fine with exactly the same > setup. Any suggestion of where to look next? Did you remember to copy the files in the CustomFunctions dir to the new installation (not required for RPM based installs) - dhawal ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ssilva at SGVWATER.COM Fri Jan 6 22:31:32 2006 From: ssilva at SGVWATER.COM (Scott Silva) Date: Thu Jan 12 21:31:40 2006 Subject: 4.49.7-1 process name feature keeps adding processes Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Michael Masse spake the following on 1/6/2006 2:20 PM: > Julian Field wrote: > >> Try killing mailscanner-mrtg, just to prove that it's not guilty of >> generating them... >> > It appears to be a problem with check_MailScanner which I have running > once an hour. It can't seem to detect that MailScanner is running, so > it starts up new processes. If I do a ps axww the relavant lines are: > > 15006 ? S 0:00 MailScanner: master waiting for children, > sleeping 15007 ? S > 0:02 MailScanner: waiting for > messages 15068 > ? S 0:02 MailScanner: waiting for > messages 15187 > ? S 0:02 MailScanner: waiting for > messages 15234 > ? S 0:02 MailScanner: waiting for > messages 15258 > ? S 0:01 MailScanner: waiting for messages > > > and I'm running > check_MailScanner version 1.13.2.8 dated 2003/07/29 > > Is there a newer version that the rpm install isn't updating for some > reason? > > Mike > Sorry! Brainfart... Mine is as follows; $Id: check_mailscanner,v 1.13.2.11 2005/12/09 11:42:42 jkf Exp $ -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ssilva at SGVWATER.COM Fri Jan 6 22:29:42 2006 From: ssilva at SGVWATER.COM (Scott Silva) Date: Thu Jan 12 21:31:40 2006 Subject: 4.49.7-1 process name feature keeps adding processes Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Michael Masse spake the following on 1/6/2006 2:20 PM: > Julian Field wrote: > >> Try killing mailscanner-mrtg, just to prove that it's not guilty of >> generating them... >> > It appears to be a problem with check_MailScanner which I have running > once an hour. It can't seem to detect that MailScanner is running, so > it starts up new processes. If I do a ps axww the relavant lines are: > > 15006 ? S 0:00 MailScanner: master waiting for children, > sleeping 15007 ? S > 0:02 MailScanner: waiting for > messages 15068 > ? S 0:02 MailScanner: waiting for > messages 15187 > ? S 0:02 MailScanner: waiting for > messages 15234 > ? S 0:02 MailScanner: waiting for > messages 15258 > ? S 0:01 MailScanner: waiting for messages > > > and I'm running > check_MailScanner version 1.13.2.8 dated 2003/07/29 > > Is there a newer version that the rpm install isn't updating for some > reason? > > Mike > Mine has no version info, but is dated 1/1/2006. Maybe yours is locked in some way (immutable bit set?), and the rpm install can't get it. -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From pete at ENITECH.COM.AU Fri Jan 6 23:58:45 2006 From: pete at ENITECH.COM.AU (Pete Russell) Date: Thu Jan 12 21:31:40 2006 Subject: MailScanner version 5 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] > > The one thing you forgot is that I will of course be the majority > stockholder in Major Corporation. Why make money once when you can > make it twice? > Um Julian, what about world domination? ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From res at AUSICS.NET Sat Jan 7 06:34:47 2006 From: res at AUSICS.NET (Res) Date: Thu Jan 12 21:31:40 2006 Subject: 4.49.7-1 process name feature keeps adding processes Message-ID: On Fri, 6 Jan 2006, Michael Masse wrote: > It appears to be a problem with check_MailScanner which I have running once > an hour. It can't seem to detect that MailScanner is running, so it starts > up new processes. If I do a ps axww the relavant lines are: Run this (pid= is all on one line, change path to MailScanner if not in /opt #!/bin/sh pid=`ps axww |egrep MailScanner'[:]|\['MailScanner'\]|[ ]'/opt/MailScanner/bin/MailScanner | awk '{ print $1 }'` ; echo MailScanner running with pid $pid if [ "x$pid" = "x" ]; then echo MailScanner not running else if [ "x$1" != "x-q" ]; then echo MailScanner running with pid $pid fi fi thats all the check process does what does it print out ? and example here is: root@valhalla:/opt/MailScanner/bin# ./test MailScanner running with pid 13863 26862 27237 27411 27429 28249 root@valhalla:/opt/MailScanner/bin# /etc/rc.d/rc.sendmail stop root@valhalla:/opt/MailScanner/bin# ./test MailScanner not running root@valhalla:/opt/MailScanner/bin# -- Cheers Res ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From radislav.vrnata at PORCELA.CZ Sat Jan 7 11:33:26 2006 From: radislav.vrnata at PORCELA.CZ (Radislav Vrnata) Date: Thu Jan 12 21:31:40 2006 Subject: Filetype code BUG ? Message-ID: [ The following text is in the "windows-1252" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Yes. Fedora Core 3, 4 (file ver. 4.10 - 4.16(author latest)) have this bug... Fedora Core 2 (file ver. 4.07) is O.K. Radislav. Julian Field napsal(a): > This is a bug in the "file" command. Please report it to the authors. > > On 6 Jan 2006, at 13:10, Radislav Vrnata wrote: > >>> Hi all, >>> >>> I have big problem with regular detecting of MPEG attachments based on >>> Filetype rules. >>> >>> When I sent "PLAIN TEXT" e-mail with ISO-8859-2 encoding and first two >>> characters of body are "Vá" e.g. in Czech "Vá~ený" (in English >>> "Dear"), >>> then MS recognize him as "MPEG movie" !!! (log says "Filetype >>> Checks: No >>> MPEG movies (42C121B907CA.60823 msg-24637-201.txt)"). >>> If I write "space character" before "Vá", then everything is all >>> right... >>> >>> Any suggestions ? >>> >>> Regards, >>> >>> Radislav. >>> >>> >>> Postfix 2.1.5 >>> Cyrus IMAP 2.2.12 >>> This is Fedora Core release 3 (Heidelberg) >>> This is Perl version 5.008005 (5.8.5) >>> This is MailScanner version 4.49.7 >>> Module versions are: >>> 1.00 AnyDBM_File >>> 1.14 Archive::Zip >>> 1.03 Carp >>> 1.119 Convert::BinHex >>> 1.00 DirHandle >>> 1.05 Fcntl >>> 2.73 File::Basename >>> 2.08 File::Copy >>> 2.01 FileHandle >>> 1.06 File::Path >>> 0.16 File::Temp >>> 1.29 HTML::Entities >>> 3.45 HTML::Parser >>> 2.30 HTML::TokeParser >>> 1.21 IO >>> 1.10 IO::File >>> 1.123 IO::Pipe >>> 1.67 Mail::Header >>> 3.05 MIME::Base64 >>> 5.417 MIME::Decoder >>> 5.417 MIME::Decoder::UU >>> 5.417 MIME::Head >>> 5.417 MIME::Parser >>> 3.03 MIME::QuotedPrint >>> 5.417 MIME::Tools >>> 0.10 Net::CIDR >>> 1.08 POSIX >>> 1.77 Socket >>> 0.08 Sys::Syslog >>> 1.02 Time::localtime >>> >>> Optional module versions are: >>> 0.17 Convert::TNEF >>> 1.814 DB_File >>> 1.08 Digest >>> 1.01 Digest::HMAC >>> 2.36 Digest::MD5 >>> 2.10 Digest::SHA1 >>> 0.44 Inline >>> 0.17 Mail::ClamAV >>> 3.000004 Mail::SpamAssassin >>> 1.997 Mail::SPF::Query >>> 0.18 Net::CIDR::Lite >>> 0.55 Net::DNS >>> 0.31 Net::LDAP >>> 1.94 Parse::RecDescent >>> missing SAVI >>> 1.4 Sys::Hostname::Long >>> 2.56 Test::Harness >>> 0.62 Test::Simple >>> 1.95 Text::Balanced >>> 1.35 URI >>> >>> ------------------------ MailScanner list ------------------------ >>> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >>> 'leave mailscanner' in the body of the email. >>> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >>> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >>> >>> Support MailScanner development - buy the book off the website! > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Sat Jan 7 13:14:10 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:40 2006 Subject: Problem installing DBI solved Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Good idea, I see your point now. Unfortunately, I can't quite see what to put in the /tmp/MSrpmrc file. I have tried %__perl_requires /bin/true but that doesn't appear to work. I'll carry on digging. Richard Siddall wrote: >Julian Field wrote: > > >>Don't see quite what you mean. What I need to do is kill perl.req, I >>don't see what I can do apart from put it back afterwards. >> >> >> > >Well, first off, I meant rpmbuild, not rpm. > >If I understand rpmbuild correctly, it calls perl.req because that's the >program specified in the __perl_requires macro. Do an > > rpmbuild --showrc > >and look for __perl_requires. > >If you redefine the macro successfully then the standard perl.req >shouldn't be called. You can get rpmbuild to call your replacement >script instead, without making any changes to perl.req. > >I was just suggesting trying to redefine the macro on the command line. > I don't know if that would work. You could also try redefining it in >the .spec file or in an rcfile you pass via the --rcfile command line >switch. > >Does that make more sense? > >Regards, > > Richard Siddall > >------------------------ MailScanner list ------------------------ >To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >'leave mailscanner' in the body of the email. >Before posting, read the Wiki (http://wiki.mailscanner.info/) and >the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > >Support MailScanner development - buy the book off the website! > > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Sat Jan 7 13:52:32 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:40 2006 Subject: Problem installing DBI solved Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] All sorted now. Works a treat. Julian Field wrote: > Good idea, I see your point now. > Unfortunately, I can't quite see what to put in the /tmp/MSrpmrc file. > I have tried > %__perl_requires /bin/true > but that doesn't appear to work. > I'll carry on digging. > > Richard Siddall wrote: > >> Julian Field wrote: >> >> >>> Don't see quite what you mean. What I need to do is kill perl.req, I >>> don't see what I can do apart from put it back afterwards. >>> >>> >> >> >> Well, first off, I meant rpmbuild, not rpm. >> >> If I understand rpmbuild correctly, it calls perl.req because that's the >> program specified in the __perl_requires macro. Do an >> >> rpmbuild --showrc >> >> and look for __perl_requires. >> >> If you redefine the macro successfully then the standard perl.req >> shouldn't be called. You can get rpmbuild to call your replacement >> script instead, without making any changes to perl.req. >> >> I was just suggesting trying to redefine the macro on the command line. >> I don't know if that would work. You could also try redefining it in >> the .spec file or in an rcfile you pass via the --rcfile command line >> switch. >> >> Does that make more sense? >> >> Regards, >> >> Richard Siddall >> >> ------------------------ MailScanner list ------------------------ >> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >> 'leave mailscanner' in the body of the email. >> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >> >> Support MailScanner development - buy the book off the website! >> >> > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Edge at TWU.CA Fri Jan 6 21:17:48 2006 From: Edge at TWU.CA (Richard Edge) Date: Thu Jan 12 21:31:40 2006 Subject: MailScanner problem Message-ID: Where is is supposed to be and where can this information be found? Richard Edge Senior Systems Administrator | Technology Services Trinity Western University | t: 604.513.2089 f: 604.513.2038 | e: edge twu.ca| www.twu.ca/technology -----Original Message----- From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Michael H. Martel Sent: Friday, January 06, 2006 1:08 PM To: MAILSCANNER@JISCMAIL.AC.UK Subject: Re: [MAILSCANNER] MailScanner problem --On Friday, January 06, 2006 12:47 PM -0800 Richard Edge wrote: > I am having a problem with MailScanner after upgrading both email > gateways yesterday to 4.50.4. Both gateways were upgraded using > exactly I saw this myself, and it was beause I hadn't moved over the MailWatch.pm file from the old directory. Michael -- --------------------------------o--------------------------------- Michael H. Martel | Vermont State Colleges martelm@quark.vsc.edu | Systems Administrator http://probe.vsc.edu/~michael | PH:802-241-2544 FX:802-241-3363 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From BBourdage at TECHPRO.COM Sat Jan 7 22:24:10 2006 From: BBourdage at TECHPRO.COM (Barry Bourdage) Date: Thu Jan 12 21:31:40 2006 Subject: Field in a message object. Message-ID: I am trying to find the action ("Deliver/Store/Delete/...) in the $message object. I have used the dump.pm, but cannot seem to find the info. Could anyone please shed some light on this for me. Thank you. Barry Bourdage ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From glenn.steen at GMAIL.COM Sun Jan 8 04:09:11 2006 From: glenn.steen at GMAIL.COM (Glenn Steen) Date: Thu Jan 12 21:31:40 2006 Subject: Hard Lock Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 06/01/06, Information Services wrote: (snip) > clamav-0.87 Update cöam asap. (snip) > > First, > > When I reboot the systems, it takes about 20 minutes before the login > screen appears. I am able to shell into the systems themselves and work on > them, but I would like to resolve why they don't bring the login screen up > right away after the boot process. The GUI either sets at the blank screen > with the black curser outlined in white and is an 'X' symbol, or at the > progress bar at 100 percent until it finally shows the login screen. Assuming you are referring to a graphical logon screen, this is usually a display manager for X.... Which in turn usually means that extreme slowness is due to a network misconfiguration. Having no valid name lookup (in /etc/hosts) for the loopback IF address usually has this effect... So check that all names (including loopback) resolve as they should. If you have it configured for a X font sever, check that it is running, and that you have no network issues in reaching it. > > Issue 2: > > I have been havin problems with both servers locking up. One server more > than the other. > (snip) Nothing jumps out and grabs ones attention.... So suspect the usual things: HW and kernel. One is easy to change.... so why not try your hand on doing a "custom kernel";-). since both machines are more or less of an age, and fairly similar in makeup..... shoddy drivers come to mind, as well as diverse age-related cr*p. -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From jlmiller at MMTNETWORKS.COM.AU Sun Jan 8 07:43:40 2006 From: jlmiller at MMTNETWORKS.COM.AU (Jon Miller) Date: Thu Jan 12 21:31:40 2006 Subject: test setup Message-ID: Correct and thanks Jon >>> drew@THEMARSHALLS.CO.UK 8:29:05 pm 6/01/2006 >>> On 6 Jan 2006, at 06:30, Jon Miller wrote: > First like to say my copy of the MailScanner book has just arrived > and I'm ready to try to set up a test system to install MS, SA, > SAV, MCP,etc. > What I would like to do is have mail from our regular mail server > send a copy to this server, so we can see how the setup works with > real mail. > We are using a Debian server with postfix as our MTA. > Any ideas or diagram/instructions available on the subject? > When the test server is up and running you could always just tell your existing Postfix server to BCC an account on the test box with all mail. That would give it a real life testing (Although it would only test mail that has made it's way through the existing server, so valid recipients, non RBL listed IP's etc. This shouldn't be too bad though as you are after testing MailScanner, right?). Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From martelm at QUARK.VSC.EDU Sun Jan 8 11:03:34 2006 From: martelm at QUARK.VSC.EDU (Michael H. Martel) Date: Thu Jan 12 21:31:40 2006 Subject: MailScanner problem Message-ID: --On Friday, January 06, 2006 1:17 PM -0800 Richard Edge wrote: > Where is is supposed to be and where can this information be found? MailWatch.pm should be in the CustomFunctions directory. Did you install from tar file or RPM ? If it's the tar file, it's wherever you put it. For me its : /opt/MailScanner/lib/MailScanner/CustomFunctions In the RPM version it's : /usr/lib/MailScanner/MailScanner/CustomFunctions Michael -- --------------------------------o--------------------------------- Michael H. Martel | Vermont State Colleges martelm@quark.vsc.edu | Systems Administrator http://probe.vsc.edu/~michael | PH:802-241-2544 FX:802-241-3363 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Sun Jan 8 11:33:22 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:40 2006 Subject: Field in a message object. Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] The reason you can't find it is that it isn't there :-) It wasn't needed, so I didn't put it in. Barry Bourdage wrote: > I am trying to find the action ("Deliver/Store/Delete/...) in the > $message object. > > I have used the dump.pm, but cannot seem to find the info. > > Could anyone please shed some light on this for me. > > Thank you. > > Barry Bourdage > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) > and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > *Support MailScanner development - buy the book off the website!* -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From glenn.steen at GMAIL.COM Sun Jan 8 13:22:25 2006 From: glenn.steen at GMAIL.COM (Glenn Steen) Date: Thu Jan 12 21:31:40 2006 Subject: MailScanner problem Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 08/01/06, Michael H. Martel wrote: > --On Friday, January 06, 2006 1:17 PM -0800 Richard Edge > wrote: > > > Where is is supposed to be and where can this information be found? > > MailWatch.pm should be in the CustomFunctions directory. Did you install > from tar file or RPM ? > > If it's the tar file, it's wherever you put it. For me its : > > /opt/MailScanner/lib/MailScanner/CustomFunctions > > In the RPM version it's : > > /usr/lib/MailScanner/MailScanner/CustomFunctions > > > > Michael > > -- I think Richard is talking about where clamav is supposed to be, or rather where the config files are.... Your answer is correct for that too:-) If installed from source and using the defaults (just a plain ./configure) then it's installed to /usr/local ... so any config files are in /usr/local/etc ... If you've used any RPMs, well then anything goes... Probably in /etc, but ...:-) -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From alex at NKPANAMA.COM Sun Jan 8 15:47:48 2006 From: alex at NKPANAMA.COM (Alex Neuman van der Hans) Date: Thu Jan 12 21:31:40 2006 Subject: Virus slow down? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Since I "discovered" clamav-milter I've barely - if ever - seen MailScanner detect a virus. Most things that get past clamav-milter get picked up by filename rules. Now that I've implemented greylisting it's even lower. Michael Masse wrote: >Same here.. Typically average around 2k/day. Sitting at 60 right >now. > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Sun Jan 8 16:21:23 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:40 2006 Subject: Virus slow down? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] We are still seeing 1500 viruses out of 180k messages per day. No drop off here at all. Alex Neuman van der Hans wrote: > Since I "discovered" clamav-milter I've barely - if ever - seen > MailScanner detect a virus. Most things that get past clamav-milter > get picked up by filename rules. Now that I've implemented greylisting > it's even lower. > > Michael Masse wrote: > >> Same here.. Typically average around 2k/day. Sitting at 60 right >> now. > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From BBourdage at TECHPRO.COM Sun Jan 8 17:40:34 2006 From: BBourdage at TECHPRO.COM (Barry Bourdage) Date: Thu Jan 12 21:31:40 2006 Subject: Field in a message object. Message-ID: Thank you Julian, I have written a custom function that allows for individual actions per user/Domain/Admin, for each No-Spam, Low Spam, and High spam score, from a SQL Table. I would like to have the ability to display the action that was taken in the detail side of the report. Barry -----Original Message----- From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Julian Field Sent: Sunday, January 08, 2006 5:33 AM To: MAILSCANNER@JISCMAIL.AC.UK Subject: Re: Field in a message object. The reason you can't find it is that it isn't there :-) It wasn't needed, so I didn't put it in. Barry Bourdage wrote: > I am trying to find the action ("Deliver/Store/Delete/...) in the > $message object. > > I have used the dump.pm, but cannot seem to find the info. > > Could anyone please shed some light on this for me. > > Thank you. > > Barry Bourdage > > ------------------------ MailScanner list ------------------------ To > unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and the > archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > *Support MailScanner development - buy the book off the website!* -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From smf at F2S.COM Sun Jan 8 21:50:34 2006 From: smf at F2S.COM (Steve Freegard) Date: Thu Jan 12 21:31:40 2006 Subject: Field in a message object. Message-ID: Hi Barry, I've already submitted a patch to Julian for this (as I want to put this in the next MailWatch release) and is in the current beta so it will be in the next stable MailScanner release. The new property is called $message->{actions} and contains a comma separated list of the actions that were taken on a message. Cheers, Steve. On Sun, 2006-01-08 at 11:40 -0600, Barry Bourdage wrote: > Thank you Julian, > I have written a custom function that allows for individual actions per > user/Domain/Admin, for each No-Spam, Low Spam, and High spam score, from > a SQL Table. I would like to have the ability to display the action that > was taken in the detail side of the report. > > > Barry > > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Julian Field > Sent: Sunday, January 08, 2006 5:33 AM > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: Field in a message object. > > The reason you can't find it is that it isn't there :-) It wasn't > needed, so I didn't put it in. > > Barry Bourdage wrote: > > > I am trying to find the action ("Deliver/Store/Delete/...) in the > > $message object. > > > > I have used the dump.pm, but cannot seem to find the info. > > > > Could anyone please shed some light on this for me. > > > > Thank you. > > > > Barry Bourdage > > > > ------------------------ MailScanner list ------------------------ To > > unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > > 'leave mailscanner' in the body of the email. > > Before posting, read the Wiki (http://wiki.mailscanner.info/) and the > > archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > > > *Support MailScanner development - buy the book off the website!* > > > -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store Professional > Support Services at www.MailScanner.biz MailScanner thanks transtec > Computers for their support > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > > ------------------------ MailScanner list ------------------------ To > unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and the > archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From BBourdage at TECHPRO.COM Sun Jan 8 21:54:57 2006 From: BBourdage at TECHPRO.COM (Barry Bourdage) Date: Thu Jan 12 21:31:40 2006 Subject: Field in a message object. Message-ID: Thank you Steve, I also sent you a minor update to support a refresh from the SQL table, rather than require a MailScanner restart. Please let me know if you have any other questions ?. Barry -----Original Message----- From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Steve Freegard Sent: Sunday, January 08, 2006 3:51 PM To: MAILSCANNER@JISCMAIL.AC.UK Subject: Re: Field in a message object. Hi Barry, I've already submitted a patch to Julian for this (as I want to put this in the next MailWatch release) and is in the current beta so it will be in the next stable MailScanner release. The new property is called $message->{actions} and contains a comma separated list of the actions that were taken on a message. Cheers, Steve. On Sun, 2006-01-08 at 11:40 -0600, Barry Bourdage wrote: > Thank you Julian, > I have written a custom function that allows for individual actions > per user/Domain/Admin, for each No-Spam, Low Spam, and High spam > score, from a SQL Table. I would like to have the ability to display > the action that was taken in the detail side of the report. > > > Barry > > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Julian Field > Sent: Sunday, January 08, 2006 5:33 AM > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: Field in a message object. > > The reason you can't find it is that it isn't there :-) It wasn't > needed, so I didn't put it in. > > Barry Bourdage wrote: > > > I am trying to find the action ("Deliver/Store/Delete/...) in the > > $message object. > > > > I have used the dump.pm, but cannot seem to find the info. > > > > Could anyone please shed some light on this for me. > > > > Thank you. > > > > Barry Bourdage > > > > ------------------------ MailScanner list ------------------------ > > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > > 'leave mailscanner' in the body of the email. > > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > > > *Support MailScanner development - buy the book off the website!* > > > -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store Professional > Support Services at www.MailScanner.biz MailScanner thanks transtec > Computers for their support > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > > ------------------------ MailScanner list ------------------------ To > unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and the > archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Dave Sun Jan 8 23:01:35 2006 From: Dave (Dave) Date: Thu Jan 12 21:31:40 2006 Subject: Exclusion List Message-ID: Quick question. With MailScanner, is their an exclusion list for a user that does not have their mail scanned? -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From michele at BLACKNIGHT.IE Sun Jan 8 23:20:35 2006 From: michele at BLACKNIGHT.IE (Michele Neylon:: Blacknight.ie) Date: Thu Jan 12 21:31:40 2006 Subject: Exclusion List Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem wrote: > Quick question. > > With MailScanner, is their an exclusion list for a user that > does not have their mail scanned? > Have a look in MailScanner.conf and search the archives for rulesets Short answer - yes you can do it -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From martinh at SOLID-STATE-LOGIC.COM Mon Jan 9 09:07:29 2006 From: martinh at SOLID-STATE-LOGIC.COM (Martin Hepworth) Date: Thu Jan 12 21:31:40 2006 Subject: Exclusion List Message-ID: As Michelle said, the short answer is yes, The longer answer is, you'll have to create a ruleset for all tests to exclude that user from that test. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Dave Shariff Yadallee - System Administrator a.k.a. The Root of > the Problem > Sent: 08 January 2006 23:02 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: [MAILSCANNER] Exclusion List > > Quick question. > > With MailScanner, is their an exclusion list for a user that > does not have their mail scanned? > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Mon Jan 9 09:39:19 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:40 2006 Subject: Exclusion List Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/9/06, Martin Hepworth wrote: As Michelle said, the short answer is yes, The longer answer is, you'll have to create a ruleset for all tests to exclude that user from that test. Yes, but "Scan Messages" is the big switch so if he wants to avoid scanning totally he only needs one ruleset. -- /peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From martinh at SOLID-STATE-LOGIC.COM Mon Jan 9 09:46:34 2006 From: martinh at SOLID-STATE-LOGIC.COM (Martin Hepworth) Date: Thu Jan 12 21:31:40 2006 Subject: Exclusion List Message-ID: Ah yes of course I'd forgot about that....... Hey, its still early Monday AM - that's my excuse and I'm sticking by it.... :-) -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of shuttlebox > Sent: 09 January 2006 09:39 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: [MAILSCANNER] Exclusion List > > On 1/9/06, Martin Hepworth wrote: > > As Michelle said, the short answer is yes, > > The longer answer is, you'll have to create a ruleset for all tests > to > exclude that user from that test. > > > > Yes, but "Scan Messages" is the big switch so if he wants to avoid > scanning totally he only needs one ruleset. > > -- > /peter > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) > and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From michele at BLACKNIGHT.IE Mon Jan 9 12:08:11 2006 From: michele at BLACKNIGHT.IE (Michele Neylon :: Blacknight Solutions) Date: Thu Jan 12 21:31:40 2006 Subject: Exclusion List Message-ID: Martin Hepworth <> said on 09 January 2006 09:07: > As Michelle said, the short answer is yes, > Oi! Stop changing my gender!! Mr Michele Neylon Blacknight Solutions Hosting & Colocation, Brand Protection http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 UK: 0870 163 0607 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Dave Mon Jan 9 15:13:06 2006 From: Dave (Dave) Date: Thu Jan 12 21:31:40 2006 Subject: Exclusion List Message-ID: On Mon, Jan 09, 2006 at 12:08:11PM -0000, Michele Neylon :: Blacknight Solutions wrote: > Martin Hepworth <> said on 09 January 2006 09:07: > > > As Michelle said, the short answer is yes, > > > > Oi! Stop changing my gender!! > So is Michele Irish for Michael? > > Mr Michele Neylon > Blacknight Solutions > Hosting & Colocation, Brand Protection > http://www.blacknight.ie/ > Tel. 1850 927 280 > Intl. +353 (0) 59 9183072 > UK: 0870 163 0607 > Direct Dial: +353 (0)59 9183090 > Fax. +353 (0) 59 9164239 > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From martinh at SOLID-STATE-LOGIC.COM Mon Jan 9 15:18:31 2006 From: martinh at SOLID-STATE-LOGIC.COM (Martin Hepworth) Date: Thu Jan 12 21:31:40 2006 Subject: Exclusion List Message-ID: Yup - its pronounced differently though Mickayli I think is a reasonable phonetically.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Dave Shariff Yadallee - System Administrator a.k.a. The Root of > the Problem > Sent: 09 January 2006 15:13 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: [MAILSCANNER] Exclusion List > > On Mon, Jan 09, 2006 at 12:08:11PM -0000, Michele Neylon :: Blacknight > Solutions wrote: > > Martin Hepworth <> said on 09 January 2006 09:07: > > > > > As Michelle said, the short answer is yes, > > > > > > > Oi! Stop changing my gender!! > > > > So is Michele Irish for Michael? > > > > > Mr Michele Neylon > > Blacknight Solutions > > Hosting & Colocation, Brand Protection > > http://www.blacknight.ie/ > > Tel. 1850 927 280 > > Intl. +353 (0) 59 9183072 > > UK: 0870 163 0607 > > Direct Dial: +353 (0)59 9183090 > > Fax. +353 (0) 59 9164239 > > > > ------------------------ MailScanner list ------------------------ > > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > > 'leave mailscanner' in the body of the email. > > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > > > Support MailScanner development - buy the book off the website! > > > > -- > > This message has been scanned for viruses and > > dangerous content by MailScanner, and is > > believed to be clean. > > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From lbcadmin at GMAIL.COM Mon Jan 9 17:03:28 2006 From: lbcadmin at GMAIL.COM (Information Services) Date: Thu Jan 12 21:31:40 2006 Subject: Hard Lock Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] I am going to check into the HDs. All three systems have the exact same HDs in them. All the same sw is running on them also, except for squid on the two mailscanner boxes. I will also try the suggestions posted in a previous reply to this also. I definitely need to resolve this issue. I don't want my production systems to be locking up, especially not at 0200 hours. On 1/7/06, Glenn Steen wrote: On 06/01/06, Information Services wrote: (snip) > clamav-0.87 Update cöam asap. (snip) > > First, > > When I reboot the systems, it takes about 20 minutes before the login > screen appears. I am able to shell into the systems themselves and work on > them, but I would like to resolve why they don't bring the login screen up > right away after the boot process. The GUI either sets at the blank screen > with the black curser outlined in white and is an 'X' symbol, or at the > progress bar at 100 percent until it finally shows the login screen. Assuming you are referring to a graphical logon screen, this is usually a display manager for X.... Which in turn usually means that extreme slowness is due to a network misconfiguration. Having no valid name lookup (in /etc/hosts) for the loopback IF address usually has this effect... So check that all names (including loopback) resolve as they should. If you have it configured for a X font sever, check that it is running, and that you have no network issues in reaching it. > > Issue 2: > > I have been havin problems with both servers locking up. One server more > than the other. > (snip) Nothing jumps out and grabs ones attention.... So suspect the usual things: HW and kernel. One is easy to change.... so why not try your hand on doing a "custom kernel";-). since both machines are more or less of an age, and fairly similar in makeup..... shoddy drivers come to mind, as well as diverse age-related cr*p. -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html ). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From martinh at SOLID-STATE-LOGIC.COM Mon Jan 9 17:47:50 2006 From: martinh at SOLID-STATE-LOGIC.COM (Martin Hepworth) Date: Thu Jan 12 21:31:40 2006 Subject: exe extension in url Message-ID: The reason why you need anti-virus on the desktop.... ;-) -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Information Services > Sent: 09 January 2006 17:42 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: [MAILSCANNER] exe extension in url > > Here is something I haven't seen, and maybe these have been coming through > but this is the first I have taken notice too. > > I have an email (posted below), that tries to get the user to go to a link > with an executable file. Where would I go in order to block this type of > email? > I could block the postcard domain, but that would resolve only them. I am > concerned about hackers sending to less knowledgeable users. > > ################################################ > > From: Best Postcard [mailto:service@postcard.com] > Sent: Friday, January 06, 2006 5:46 PM > To: munged@munged.com > Subject: Online Greeting Card Waiting For You > > > > Hello, > > A Greeting Card is waiting for you at our virtual post office! > > Sender: your dear friend > > If you don't pick up your Greeting Card within 4 weeks, our postal clerk > may discard it! > > CLICK this pick-up address or COPY and PASTE into your browser : > > http://www.freeforall.home.ro/postcard.gif.exe > > > (c) All-Yours Greeting Cards Provided as a free service by All-Yours > Greeting Cards http://www.freeforall.home.ro > > > > > > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) > and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From lbcadmin at GMAIL.COM Mon Jan 9 17:41:58 2006 From: lbcadmin at GMAIL.COM (Information Services) Date: Thu Jan 12 21:31:40 2006 Subject: exe extension in url Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Here is something I haven't seen, and maybe these have been coming through but this is the first I have taken notice too. I have an email (posted below), that tries to get the user to go to a link with an executable file. Where would I go in order to block this type of email? I could block the postcard domain, but that would resolve only them. I am concerned about hackers sending to less knowledgeable users. ################################################ From: Best Postcard [mailto:service@postcard.com] Sent: Friday, January 06, 2006 5:46 PM To: munged@munged.com Subject: Online Greeting Card Waiting For You Hello, A Greeting Card is waiting for you at our virtual post office! Sender: your dear friend If you don't pick up your Greeting Card within 4 weeks, our postal clerk may discard it! CLICK this pick-up address or COPY and PASTE into your browser : http://www.freeforall.home.ro/postcard.gif.exe (c) All-Yours Greeting Cards Provided as a free service by All-Yours Greeting Cards http://www.freeforall.home.ro ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Mon Jan 9 21:11:20 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:40 2006 Subject: exe extension in url Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/9/06, Information Services wrote: Here is something I haven't seen, and maybe these have been coming through but this is the first I have taken notice too. I have an email (posted below), that tries to get the user to go to a link with an executable file. Where would I go in order to block this type of email? I could block the postcard domain, but that would resolve only them. I am concerned about hackers sending to less knowledgeable users. ################################################ From: Best Postcard [mailto:service@postcard.com ] Sent: Friday, January 06, 2006 5:46 PM To: munged@munged.com Subject: Online Greeting Card Waiting For You Hello, A Greeting Card is waiting for you at our virtual post office! Sender: your dear friend If you don't pick up your Greeting Card within 4 weeks, our postal clerk may discard it! CLICK this pick-up address or COPY and PASTE into your browser : http://www.freeforall.home.ro/postcard.gif.exe You could write a SpamAssassin rule to score web links to executable files. -- /peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From miguelk at KONSULTEX.COM.BR Mon Jan 9 20:00:30 2006 From: miguelk at KONSULTEX.COM.BR (Miguel Koren O'Brien de Lacy) Date: Thu Jan 12 21:31:40 2006 Subject: Header Syntax Error Message-ID: [ The following text is in the "UTF-8" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Gentlemen; I never saw this message in the logs of a new server installed this weekend: Jan 9 16:49:37 aradhana sendmail[3186]: k09JnWfC003175: SYSERR(root): header syntax error, line "X-Sesamo Regalos-MailScanner-From: " Environment: Fedora Core 4 (fully patched) MailScanner 4.47.4-2 Clamav 0.87.1 Sendmail 8.13.4 mail clients: Outlook/Outlook Express with versions ranging from Win98 to WinXP. Is this header syntax error something to worry about? Is it because the "From:" is empty? Miguel -- Esta mensagem foi verificada pelo sistema de antivírus e acredita-se estar livre de perigo. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Dave Mon Jan 9 21:24:15 2006 From: Dave (Dave) Date: Thu Jan 12 21:31:40 2006 Subject: Exclusion List Message-ID: On Mon, Jan 09, 2006 at 09:46:34AM -0000, Martin Hepworth wrote: > Ah yes of course I'd forgot about that....... > > Hey, its still early Monday AM - that's my excuse and I'm sticking by it.... > :-) > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > > Behalf Of shuttlebox > > Sent: 09 January 2006 09:39 > > To: MAILSCANNER@JISCMAIL.AC.UK > > Subject: Re: [MAILSCANNER] Exclusion List > > > > On 1/9/06, Martin Hepworth wrote: > > > > As Michelle said, the short answer is yes, > > > > The longer answer is, you'll have to create a ruleset for all tests > > to > > exclude that user from that test. > > > > > > > > Yes, but "Scan Messages" is the big switch so if he wants to avoid > > scanning totally he only needs one ruleset. > > So far so good, but what about case sensitivity issues? > > -- > > /peter > > ------------------------ MailScanner list ------------------------ > > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > > 'leave mailscanner' in the body of the email. > > Before posting, read the Wiki (http://wiki.mailscanner.info/) > > and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > > > Support MailScanner development - buy the book off the website! > > > > ********************************************************************** > > This email and any files transmitted with it are confidential and > intended solely for the use of the individual or entity to whom they > are addressed. If you have received this email in error please notify > the system manager. > > This footnote confirms that this email message has been swept > for the presence of computer viruses and is believed to be clean. > > ********************************************************************** > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dhawal at NETMAGICSOLUTIONS.COM Mon Jan 9 21:25:11 2006 From: dhawal at NETMAGICSOLUTIONS.COM (Dhawal Doshy) Date: Thu Jan 12 21:31:40 2006 Subject: ClamAV 0.88 is out!! Message-ID: [ The following text is in the "utf-8" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] For those waiting for the stable release of clamav, which is supposed to correct the scanning of certain new sober variants.. http://freshmeat.net/projects/clamav/?branch_id=29355&release_id=216552 - dhawal ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mkettler at EVI-INC.COM Mon Jan 9 20:08:03 2006 From: mkettler at EVI-INC.COM (Matt Kettler) Date: Thu Jan 12 21:31:40 2006 Subject: Header Syntax Error Message-ID: [ The following text is in the "UTF-8" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Miguel Koren O'Brien de Lacy wrote: > Gentlemen; > > I never saw this message in the logs of a new server installed this > weekend: > > Jan 9 16:49:37 aradhana sendmail[3186]: k09JnWfC003175: SYSERR(root): > header syntax error, line "X-Sesamo Regalos-MailScanner-From: " > > Environment: > Fedora Core 4 (fully patched) > MailScanner 4.47.4-2 > Clamav 0.87.1 > Sendmail 8.13.4 > mail clients: Outlook/Outlook Express with versions ranging from Win98 > to WinXP. > > Is this header syntax error something to worry about? Is it because the > "From:" is empty? > The syntax error is because the header name has a space in it between Sesamo and Regalos. That's an RFC violation. Check your %org-name% setting in Mailscanner.conf and make sure it has no spaces in it. Use - instead. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dhawal at NETMAGICSOLUTIONS.COM Mon Jan 9 21:31:14 2006 From: dhawal at NETMAGICSOLUTIONS.COM (Dhawal Doshy) Date: Thu Jan 12 21:31:40 2006 Subject: Exclusion List Message-ID: [ The following text is in the "utf-8" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem writes: > On Mon, Jan 09, 2006 at 09:46:34AM -0000, Martin Hepworth wrote: >> Ah yes of course I'd forgot about that....... >> >> Hey, its still early Monday AM - that's my excuse and I'm sticking by it.... >> :-) >> >> -- >> Martin Hepworth >> Snr Systems Administrator >> Solid State Logic >> Tel: +44 (0)1865 842300 >> >> > -----Original Message----- >> > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On >> > Behalf Of shuttlebox >> > Sent: 09 January 2006 09:39 >> > To: MAILSCANNER@JISCMAIL.AC.UK >> > Subject: Re: [MAILSCANNER] Exclusion List >> > >> > On 1/9/06, Martin Hepworth wrote: >> > >> > As Michelle said, the short answer is yes, >> > >> > The longer answer is, you'll have to create a ruleset for all tests >> > to >> > exclude that user from that test. >> > >> > >> > >> > Yes, but "Scan Messages" is the big switch so if he wants to avoid >> > scanning totally he only needs one ruleset. >> > > > So far so good, but what about case sensitivity issues? Well.. if you are a 'System Administrator' you will just go ahead and try it out.. won't you? - dhawal ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Mon Jan 9 22:18:56 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:40 2006 Subject: Header Syntax Error Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/9/06, Miguel Koren O'Brien de Lacy wrote: Gentlemen; I never saw this message in the logs of a new server installed this weekend: Jan 9 16:49:37 aradhana sendmail[3186]: k09JnWfC003175: SYSERR(root): header syntax error, line "X-Sesamo Regalos-MailScanner-From: " This is a very common question. However, I don't think Julian can make it any more clear: # RULE: It must not contain any spaces! %org-name% = yoursite -- /peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Mon Jan 9 22:21:48 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:40 2006 Subject: Exclusion List Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/9/06, Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem wrote: So far so good, but what about case sensitivity issues? It's in the documentation, you should try it sometime. :-) etc/rules/README: "You can put them in upper or lower case, it doesn't matter." -- /peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From james at grayonline.id.au Mon Jan 9 22:29:19 2006 From: james at grayonline.id.au (James Gray) Date: Thu Jan 12 21:31:40 2006 Subject: exe extension in url Message-ID: [ The following text is in the "utf-8" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Tuesday 10 January 2006 04:41, Information Services wrote: > Here is something I haven't seen, and maybe these have been coming through > but this is the first I have taken notice too. > > I have an email (posted below), that tries to get the user to go to a link > with an executable file. Where would I go in order to block this type of > email? > I could block the postcard domain, but that would resolve only them. I am > concerned about hackers sending to less knowledgeable users. I have written a number of SpamAssassin rules that increase the score for messages that link to executables (exe/dll/bat/etc... but NOT ".com"...think about it :P). Unfortunately some of them also hit legitimate websites (like www.ht.com.au which uses a program called "xworks.exe" for its dynamic content). All my rules are available at http://files.grayonline.id.au - all the URL/URI rules are in the "local_uri.cf" which is in the tar ball. The rest of the instructions are on the website. Pick and choose as you see fit :) Cheers, James -- You will triumph over your enemy. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From james at grayonline.id.au Mon Jan 9 22:34:52 2006 From: james at grayonline.id.au (James Gray) Date: Thu Jan 12 21:31:40 2006 Subject: Header Syntax Error Message-ID: [ The following text is in the "utf-8" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Tuesday 10 January 2006 09:18, shuttlebox wrote: > On 1/9/06, Miguel Koren O'Brien de Lacy wrote: > > Gentlemen; > > > > I never saw this message in the logs of a new server installed this > > weekend: > > > > Jan 9 16:49:37 aradhana sendmail[3186]: k09JnWfC003175: SYSERR(root): > > header syntax error, line "X-Sesamo Regalos-MailScanner-From: " > > This is a very common question. However, I don't think Julian can make it > any more clear: > > # RULE: It must not contain any spaces! > %org-name% = yoursite ..and some characters (the dot "." specifically) have caused problems for people as well. James -- mophobia, n.: Fear of being verbally abused by a Mississippian. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From penguin at DHCP.NET Mon Jan 9 23:11:03 2006 From: penguin at DHCP.NET (A. Eijkhoudt) Date: Thu Jan 12 21:31:40 2006 Subject: Mail subject not getting modified Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Hello all, I'm getting a lot of mail recently that is correctly being recognized as spam, yet not having it subject modified. This shouldn't be happening, at all, as they're usually high-scoring spam E-mails (think >10.0), and therefore they should be quarantined by my config settings. Does anyone have an idea why this would happen? I've copied example headers of an E-mail in question: X-MS-INFO: Contact the network management staff if you have questions X-MS: **CLEAN** X-MS-SPAM: not spam X-MS-SPAM-SCORE: 40 X-MS-FROM: Doesn't seem right... Kind regards, A. Eijkhoudt -- This message has been scanned for viruses and dangerous HTML content by Valethosting. Dit bericht is gecontroleerd op virussen en gevaarlijke HTML door Valethosting's MailScanner. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mkettler at EVI-INC.COM Mon Jan 9 23:30:33 2006 From: mkettler at EVI-INC.COM (Matt Kettler) Date: Thu Jan 12 21:31:40 2006 Subject: Mail subject not getting modified Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] A. Eijkhoudt wrote: > Hello all, > > I'm getting a lot of mail recently that is correctly being recognized as > spam, yet not having it subject modified. This shouldn't be happening, > at all, as they're usually high-scoring spam E-mails (think >10.0), and > therefore they should be quarantined by my config settings. Does anyone > have an idea why this would happen? I've copied example headers of an > E-mail in question: > > X-MS-INFO: Contact the network management staff if you have questions > X-MS: **CLEAN** > X-MS-SPAM: not spam > X-MS-SPAM-SCORE: 40 > X-MS-FROM: > > Doesn't seem right... No it doesn't... Suggestion turn on this setting in your MailScanner.conf: Always Include SpamAssassin Report = yes That should give us a better idea as to what's going on. My guess is that the message in question is matching your MailScanner whitelist, which will cause the mail to go un-marked no matter how high the spamassassin score is. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mkettler at EVI-INC.COM Mon Jan 9 23:33:47 2006 From: mkettler at EVI-INC.COM (Matt Kettler) Date: Thu Jan 12 21:31:40 2006 Subject: exe extension in url Message-ID: [ The following text is in the "UTF-8" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] James Gray wrote: > I have written a number of SpamAssassin rules that increase the score for > messages that link to executables (exe/dll/bat/etc... but NOT ".com"...think > about it :P). Unfortunately some of them also hit legitimate websites (like > www.ht.com.au which uses a program called "xworks.exe" for its dynamic > content). Suggestion: use a $ to look for uris that END in .exe, instead of just looking for URIs that contain them. Most dynamic content sites using exe have parameters passed after it, such as the above site which ends in "/xworks.exe?M" Something like this would work: uri L_URI_EXE /\/.+\.exe$/i score L_URI_EXE 0.1 describe L_URI_EXE Contains link to a .exe file > > > All my rules are available at http://files.grayonline.id.au - all the URL/URI > rules are in the "local_uri.cf" which is in the tar ball. The rest of the > instructions are on the website. > Erm, you don't seem to have them in the 12/02/2005 tarball, which is the latest that's up there. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From nerijus at USERS.SOURCEFORGE.NET Tue Jan 10 00:43:53 2006 From: nerijus at USERS.SOURCEFORGE.NET (Nerijus Baliunas) Date: Thu Jan 12 21:31:40 2006 Subject: tnef rpm Message-ID: Hello, On RH 7.3 system I get: Installing tnef decoder error: failed dependencies: libc.so.6(GLIBC_2.3) is needed by tnef-1.3.4-1 I suggest including tnef source rpm, instead of binary one. Regards, Nerijus ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Dave Tue Jan 10 01:17:28 2006 From: Dave (Dave) Date: Thu Jan 12 21:31:40 2006 Subject: Exclusion List Message-ID: On Mon, Jan 09, 2006 at 11:21:48PM +0100, shuttlebox wrote: > On 1/9/06, Dave Shariff Yadallee - System Administrator a.k.a. The Root of > the Problem wrote: > > > > So far so good, but what about case sensitivity issues? > > > > It's in the documentation, you should try it sometime. :-) > > etc/rules/README: > > "You can put them in upper or lower case, it doesn't matter." > For the to/from rules yes, but it is not clear on the subject of e-mail addreses, ie. field 2. > -- > /peter > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From nerijus at USERS.SOURCEFORGE.NET Tue Jan 10 01:46:53 2006 From: nerijus at USERS.SOURCEFORGE.NET (Nerijus Baliunas) Date: Thu Jan 12 21:31:40 2006 Subject: cron message is incorrect Message-ID: Hello, When I stop MailScanner, I get such message from cron every hour: /etc/cron.hourly/check_MailScanner: MailScanner manually shut down (no /var/lock/subsys/MailScanner.off file). Not restarting. It is incorrect. Actually /var/lock/subsys/MailScanner.off file exists. Regards, Nerijus ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From miguelk at KONSULTEX.COM.BR Tue Jan 10 01:50:05 2006 From: miguelk at KONSULTEX.COM.BR (Miguel Koren OBrien de Lacy) Date: Thu Jan 12 21:31:40 2006 Subject: Header Syntax Error Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Thanks everyone for the suggestions. I replaced the space with a dash and the errors disappeared. Some things are taken for granted and not read enough times ;-) Miguel -- Konsultex Informatica (http://www.konsultex.com.br) ---------- Original Message ----------- From: James Gray To: MAILSCANNER@JISCMAIL.AC.UK Sent: Tue, 10 Jan 2006 09:34:52 +1100 Subject: Re: Header Syntax Error > On Tuesday 10 January 2006 09:18, shuttlebox wrote: > > On 1/9/06, Miguel Koren O'Brien de Lacy wrote: > > > Gentlemen; > > > > > > I never saw this message in the logs of a new server installed this > > > weekend: > > > > > > Jan 9 16:49:37 aradhana sendmail[3186]: k09JnWfC003175: SYSERR(root): > > > header syntax error, line "X-Sesamo Regalos-MailScanner-From: " > > > > This is a very common question. However, I don't think Julian can make it > > any more clear: > > > > # RULE: It must not contain any spaces! > > %org-name% = yoursite > > ..and some characters (the dot "." specifically) have caused problems for > people as well. > > James > -- > mophobia, n.: > Fear of being verbally abused by a Mississippian. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > -- > Esta mensagem foi verificada pelo sistema de [UTF-8?]antivírus e > acredita-se estar livre de perigo. ------- End of Original Message ------- -- Esta mensagem foi verificada pelo sistema de antivírus e acredita-se estar livre de perigo. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From nerijus at USERS.SOURCEFORGE.NET Tue Jan 10 02:53:55 2006 From: nerijus at USERS.SOURCEFORGE.NET (Nerijus Baliunas) Date: Thu Jan 12 21:31:40 2006 Subject: unneeded archive in MailScanner-4.49.7-1.tar.gz Message-ID: Hello, There is unneeded archive cz.tar.gz (older Czech messages) in /etc/reports directory of MailScanner-4.49.7-1.tar.gz. Regards, Nerijus ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From alex at NKPANAMA.COM Tue Jan 10 03:49:44 2006 From: alex at NKPANAMA.COM (Alex Neuman van der Hans) Date: Thu Jan 12 21:31:40 2006 Subject: Feature request - sort of... Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Would it be possible to have: http://www.sng.ecs.soton.ac.uk/mailscanner/files/4/rpm/MailScanner-latest.rpm.tar.gz and http://www.sng.ecs.soton.ac.uk/mailscanner/files/4/rpm/MailScanner-beta.rpm.tar.gz redirect or point to the latest stable and beta releases? I'm updating my automation scripts (which save me at least an hour when installing a server with MS+ClamAV+BitDefender+SpamAssassin(razor+pyzor+dcc)+clamavmilter+spf+greylisting+domainkeys+SMTPAuth+imaps/pop3s+webmail+everythingelse) and I thought it would save a couple of lines of code and prevent changes to the design of the webpage from breaking my scripts. I currently do it with: export LATESTMSURL=http://www.sng.ecs.soton.ac.uk/mailscanner/`lynx --source http://www.sng.ecs.soton.ac.uk/mailscanner/downloads.shtml | grep .tar.gz |head -1 | cut -d \" -f 2` export LATESTMS=`echo $LATESTMSURL|cut -d / -f 8` wget $LATESTMSURL tar xvfz $LATESTMS ... and so on. Any suggestions? ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From nerijus at USERS.SOURCEFORGE.NET Tue Jan 10 03:48:41 2006 From: nerijus at USERS.SOURCEFORGE.NET (Nerijus Baliunas) Date: Thu Jan 12 21:31:40 2006 Subject: zombie processes Message-ID: Hello, On a Debian woody box with exim3, I get zombie process after starting MailScanner: # ps axw|grep -i mailsc 15355 ? S 0:00 MailScanner: starting children 15356 ? S 0:00 MailScanner: waiting for messages 15360 ? Z 0:00 [MailScanner ] 15366 ? S 0:00 MailScanner: waiting for messages After some time: # ps axw|grep -i mailsc 15355 ? S 0:00 MailScanner: master waiting for children, sleeping 15356 ? S 0:00 MailScanner: waiting for messages 15360 ? Z 0:00 [MailScanner ] 15366 ? S 0:00 MailScanner: waiting for messages After message is received: # ps axw|grep -i mailsc 15355 ? S 0:00 MailScanner: master waiting for children, sleeping 15356 ? S 0:00 MailScanner: waiting for messages 15360 ? Z 0:00 [MailScanner ] 15366 ? S 0:00 MailScanner: waiting for messages 15396 ? Z 0:00 [MailScanner ] Sometimes some zombies disappear and new ones appear, but usually there are 2 of them. They don't seem to be doing any harm and they disappear after stopping mailscanner, but still something is wrong. Any ideas? Nothing wrong in logs. Regards, Nerijus ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From james at grayonline.id.au Tue Jan 10 04:22:46 2006 From: james at grayonline.id.au (James Gray) Date: Thu Jan 12 21:31:40 2006 Subject: exe extension in url Message-ID: [ The following text is in the "utf-8" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Tuesday 10 January 2006 10:33, Matt Kettler wrote: > James Gray wrote: > > I have written a number of SpamAssassin rules that increase the score for > > messages that link to executables (exe/dll/bat/etc... but NOT > > ".com"...think about it :P). Unfortunately some of them also hit > > legitimate websites (like www.ht.com.au which uses a program called > > "xworks.exe" for its dynamic content). > > Suggestion: use a $ to look for uris that END in .exe, instead of just > looking for URIs that contain them. Most dynamic content sites using exe > have parameters passed after it, such as the above site which ends in > "/xworks.exe?M" > > > Something like this would work: > > > uri L_URI_EXE /\/.+\.exe$/i > score L_URI_EXE 0.1 > describe L_URI_EXE Contains link to a .exe file Good suggestion - done. New tar ball uploaded and change logs edited. > > > > All my rules are available at http://files.grayonline.id.au - all the > > URL/URI rules are in the "local_uri.cf" which is in the tar ball. The > > rest of the instructions are on the website. > > > > Erm, you don't seem to have them in the 12/02/2005 tarball, which is the > latest that's up there. Really? It was in there when I opened it. Anyway, there's a new tar ball dated 10-Jan-2006 that I KNOW has the local_uri.cf file in it. Cheers, James > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! James -- It's hard to argue that God hated Oklahoma. If He didn't, why is it so close to Texas? ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Tue Jan 10 09:18:11 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:40 2006 Subject: zombie processes Message-ID: -----BEGIN PGP SIGNED MESSAGE----- And on my DOS 6.2 machine I find the multi-tasking a little slow too :-) You have an error in your MailScanner.conf, check your maillog. What version of MailScanner are you running? woody shipped with 3.27. On 10 Jan 2006, at 03:48, Nerijus Baliunas wrote: > Hello, > > On a Debian woody box with exim3, I get zombie process after > starting MailScanner: > > # ps axw|grep -i mailsc > 15355 ? S 0:00 MailScanner: starting children > 15356 ? S 0:00 MailScanner: waiting for messages > 15360 ? Z 0:00 [MailScanner ] > 15366 ? S 0:00 MailScanner: waiting for messages > > After some time: > > # ps axw|grep -i mailsc > 15355 ? S 0:00 MailScanner: master waiting for > children, sleeping > 15356 ? S 0:00 MailScanner: waiting for messages > 15360 ? Z 0:00 [MailScanner ] > 15366 ? S 0:00 MailScanner: waiting for messages > > After message is received: > > # ps axw|grep -i mailsc > 15355 ? S 0:00 MailScanner: master waiting for > children, sleeping > 15356 ? S 0:00 MailScanner: waiting for messages > 15360 ? Z 0:00 [MailScanner ] > 15366 ? S 0:00 MailScanner: waiting for messages > 15396 ? Z 0:00 [MailScanner ] > > Sometimes some zombies disappear and new ones appear, but usually > there are 2 of them. They don't seem to be doing any harm and they > disappear after stopping mailscanner, but still something is wrong. > Any ideas? Nothing wrong in logs. > > Regards, > Nerijus > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ8N72Pw32o+k+q+hAQHPYgf/e9D10rZYB7dNmvW9NDXIJKnooucROE8T bbiKX7HQ/Hk/bgxRyp9W89zuaTNWyEi5jF9qyoICdPFQWXMgwmmmGTN1KlJucHaP XbPq223AcaCwZmuBu1yBd92NkORFwT10LJe5u33McOvgrCA4H4jbpW+vJioR5ad3 WZvNrya7Net4em7c0ecBpy+X/nEBoMdAWYKBfDA460/zyZ/LUQ2F3ccxRU2Lgw55 F5610DW2XE8t51tQiPlwm7kfkK3ePQQ6Fgh6CqYXeeb+3JjAroVAKWkiLYsbFcPu MTWlPDyKLnm3CwgeTAbanrFwstKUeXBjYfHxpQr8bzT62uOx7BJviA== =23Ln -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Tue Jan 10 09:11:50 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:40 2006 Subject: ClamAV 0.88 is out!! Message-ID: -----BEGIN PGP SIGNED MESSAGE----- I have updated by easy-to-install ClamAV+SpamAssassin package at www.sng.ecs.soton.ac.uk/mailscanner/files/4/install-Clam-SA.tar.gz to include this update. On 9 Jan 2006, at 21:25, Dhawal Doshy wrote: > For those waiting for the stable release of clamav, which is > supposed to correct the scanning of certain new sober variants.. > http://freshmeat.net/projects/clamav/? > branch_id=29355&release_id=216552 > - dhawal - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ8N6Wfw32o+k+q+hAQFd2wf/ZHOWckS9fpolxIQ4wOWnV/Xg8uDV7jsS d4dbO8kizefb4gle7lEmwPDhGFC6iRiHmyrD+Q1BTEFxvwwXj7Wz1Q3zU8+dXUWz tge2ZcSq03cBT0ogmq7sDc6XP01KdMhyqXzI/bQhsOuGo1vC2vWZuK+uk0b7YlUb NNsaW8v0cXNdSEhjHXPdfcW0uVcxY779itLJUI2rlAz26iE35FDmD4lZw1qHx3rx kTtnwDwDNRh2FKYYcaF9PAFwOw/whTtKjX4E2Cm6HQUdziZ9rKSxFO/y3It5m7rO tHSAwMoHshkBZUVVhQxjlhRMN27OTKQ52mB7ZlrBtVVOwrlnjjVoAg== =IUJ+ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From martinh at SOLID-STATE-LOGIC.COM Tue Jan 10 09:51:36 2006 From: martinh at SOLID-STATE-LOGIC.COM (Martin Hepworth) Date: Thu Jan 12 21:31:40 2006 Subject: exe extension in url Message-ID: James Any chance you could modify the rules dir so they are individual ones and then I can create a RuleDuJour setup for them. Yes I could you update_spam script, but then I'd have two scripts to do this when I only really one. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of James Gray > Sent: 10 January 2006 04:23 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: [MAILSCANNER] exe extension in url > > On Tuesday 10 January 2006 10:33, Matt Kettler wrote: > > James Gray wrote: > > > I have written a number of SpamAssassin rules that increase the score > for > > > messages that link to executables (exe/dll/bat/etc... but NOT > > > ".com"...think about it :P). Unfortunately some of them also hit > > > legitimate websites (like www.ht.com.au which uses a program called > > > "xworks.exe" for its dynamic content). > > > > Suggestion: use a $ to look for uris that END in .exe, instead of just > > looking for URIs that contain them. Most dynamic content sites using exe > > have parameters passed after it, such as the above site which ends in > > "/xworks.exe?M" > > > > > > Something like this would work: > > > > > > uri L_URI_EXE /\/.+\.exe$/i > > score L_URI_EXE 0.1 > > describe L_URI_EXE Contains link to a .exe file > > Good suggestion - done. New tar ball uploaded and change logs edited. > > > > > > > All my rules are available at http://files.grayonline.id.au - all the > > > URL/URI rules are in the "local_uri.cf" which is in the tar ball. The > > > rest of the instructions are on the website. > > > > > > > Erm, you don't seem to have them in the 12/02/2005 tarball, which is the > > latest that's up there. > > Really? It was in there when I opened it. Anyway, there's a new tar ball > dated 10-Jan-2006 that I KNOW has the local_uri.cf file in it. > > Cheers, > > James > > > ------------------------ MailScanner list ------------------------ > > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > > 'leave mailscanner' in the body of the email. > > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > > > Support MailScanner development - buy the book off the website! > James > -- > It's hard to argue that God hated Oklahoma. If He didn't, why is it so > close to Texas? > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From james at grayonline.id.au Tue Jan 10 10:08:13 2006 From: james at grayonline.id.au (James Gray) Date: Thu Jan 12 21:31:40 2006 Subject: exe extension in url Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Tue, 10 Jan 2006 20:51, Martin Hepworth wrote: > James > > Any chance you could modify the rules dir so they are individual ones and > then I can create a RuleDuJour setup for them. Yes I could you > update_spam script, but then I'd have two scripts to do this when I only > really one. I *could* but then the 20 odd people who requested the current version\file-foo.cf hierachy will scream blue murder. All the scripts I've written were for my own use, but I can write you an "unpack-flat" script or something if you want. Alternatively, if you want to contact me off-list I could sort out direct access to the rules in CVS, then you can bundle them up however you want :) I'm aware of RuleDuJour stuff, but it didn't do what I wanted (back when I inherited the mail administrator hat 5 years ago) with simple "roll-back-to-previous" simply by changing a symlink etc. My rules kinda evolved by accident to where they are now...I guess if I had intended to fit in with what everyone else was doing from the start it would've been a little more friendly to our friends over at RuleDuJour. Like everything in the F/OSS world - if you don't like it, make it better :) Cheers, James -- I respect faith, but doubt is what gives you an education. -- Wilson Mizner ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! [ Part 2, Application/PGP-SIGNATURE 196bytes. ] [ Unable to print this part. ] From penguin at DHCP.NET Tue Jan 10 10:20:12 2006 From: penguin at DHCP.NET (Arnim Eijkhoudt) Date: Thu Jan 12 21:31:40 2006 Subject: Mail subject not getting modified Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Hi, I'd do that if it weren't enabled already! Which is why I haven't been able to troubleshoot this myself, incidentally :P Here's a complete copy of all the headers (excuse the spam): ---- SNIP Return-Path: Received: from STARRSTRUCKHOME.ironoh.adelphia.net (winchester-motorola1--70-35-219-251.ironoh.adelphia.net [70.35.219.251]) by www.valethosting.net (8.13.4/8.13.4) with SMTP id k0AAEHWD021224 for ; Tue, 10 Jan 2006 11:14:23 +0100 Date: Tue, 10 Jan 2006 11:14:18 +0100 Message-Id: From: Millie Costa To: penguin@dhcp.net Subject: Re: from you MIME-Version: 1.0 Content-Type: text/html; charset="ISO-8859-1" X-Priority: 3 (Normal) X-Mailer: 0013$01a2ca59$094bea57@STARRSTRUCKHOME X-MS-INFO: Contact the network management staff if you have questions X-MS: **CLEAN** X-MS-SPAM: not spam X-MS-SPAM-SCORE: 44.90 X-MS-FROM: ----- SNIP I still don't understand why this is happening. I find the Return-Path's and empty X-MS-FROM: headers a bit odd though. Kind regards, A. Eijkhoudt Matt Kettler wrote: > Suggestion turn on this setting in your MailScanner.conf: > > Always Include SpamAssassin Report = yes > > That should give us a better idea as to what's going on. My guess is that the > message in question is matching your MailScanner whitelist, which will cause the > mail to go un-marked no matter how high the spamassassin score is. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From helge.waastad at SMARTNET.NO Tue Jan 10 11:04:23 2006 From: helge.waastad at SMARTNET.NO (Helge Waastad) Date: Thu Jan 12 21:31:40 2006 Subject: MailScanner login Message-ID: Hi, I've just installed the 4.49.7 version of MailScanner and it works great. Hoewever I hvae a question regarding logging. When I catch spam messages, I get: mail postfix/smtpd[29931]: 439FF49C00D: reject_warning: RCPT from unknown[217.219.173.8]: 450 Client host rejected: cannot find your hostname, [217.219.173.8]; from=<[spamuser]@hotmail.com> to=<[user]@[mydomain]> proto=SMTP helo= Jan 10 11:28:24 mail postfix/cleanup[29934]: 439FF49C00D: hold: header Received: from mail.[mydomain] (unknown [217.219.173.8])??by mail.[mydomain] (Postfix) with SMTP id 439FF49C00D??for <[user]@[mydomain]>; Tue, 10 Jan 2006 11:28:23 +0100 (CET) from unknown[217.219.173.8]; from=<[spamuser]@hotmail.com> to=<[user]@[mydomain]> proto=SMTP helo= Jan 10 11:28:30 mail MailScanner[29925]: Message 439FF49C00D.C2AA0 from 217.219.173.8 ([spamuser]@hotmail.com) to [mydomain] is NJABL, DSBL It is actually the last linje I'm wondering about. Is it correct that only the domain should be printed out in the to address? br, hw ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From support-lists at PETDOCTORS.CO.UK Tue Jan 10 11:39:04 2006 From: support-lists at PETDOCTORS.CO.UK (Nigel kendrick) Date: Thu Jan 12 21:31:40 2006 Subject: Upgraded to 4.49 now I have language messages in log file Message-ID: Upgraded to 4.49 OK (and DID run the upgrade scripts), but in the maillog I am getting: Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown string score in language translation file /etc/MailScanner/reports/en/languages.conf Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown string required in language translation file /etc/MailScanner/reports/en/languages.conf Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown string spamassassin in language translation file /etc/MailScanner/reports/en/languages.conf Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown string mailscanner in language translation file /etc/MailScanner/reports/en/languages.conf Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown string unreadablearchive in language translation file /etc/MailScanner/reports/en/languages.conf Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown string passwordedarchive in language translation file /etc/MailScanner/reports/en/languages.conf Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown string archivetoodeep in language translation file /etc/MailScanner/reports/en/languages.conf Is this expected? Thanks NK ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From support-lists at PETDOCTORS.CO.UK Tue Jan 10 12:04:05 2006 From: support-lists at PETDOCTORS.CO.UK (Nigel kendrick) Date: Thu Jan 12 21:31:41 2006 Subject: Upgraded to 4.49 now I have language messages in log file Message-ID: Following the upgrade routine gives me a zero byte languages.conf -----Original Message----- From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Martin Hepworth Sent: 10 January 2006 11:56 To: MAILSCANNER@JISCMAIL.AC.UK Subject: Re: Upgraded to 4.49 now I have language messages in log file Nigel You sure you rand upgrade_languages_conf ? -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Nigel kendrick > Sent: 10 January 2006 11:39 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: [MAILSCANNER] Upgraded to 4.49 now I have language messages > in log file > > Upgraded to 4.49 OK (and DID run the upgrade scripts), but in the > maillog I am getting: > > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string score in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string required in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string spamassassin in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string mailscanner in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string unreadablearchive in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string passwordedarchive in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string archivetoodeep in language translation file > /etc/MailScanner/reports/en/languages.conf > > Is this expected? > > Thanks > > NK > > ------------------------ MailScanner list ------------------------ To > unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and the > archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From devonharding at GMAIL.COM Tue Jan 10 12:22:58 2006 From: devonharding at GMAIL.COM (Devon Harding) Date: Thu Jan 12 21:31:41 2006 Subject: Beta 4.50.5 released Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] What is the procedure in converting bayes to MYSQL? I'm getting too much Spamassassin time outs. On 1/5/06, Julian Field < MailScanner@ecs.soton.ac.uk> wrote: -----BEGIN PGP SIGNED MESSAGE----- On 5 Jan 2006, at 15:50, Aaron K. Moore wrote: > Julian Field wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> >> I have just released version 4.50.5. >> >> This is basically a lot of tidying up done since yesterday's 4.50.4. >> No dramatic new features. > > I've saw SQLite mentioned in a few of the posts. Are you just > using it > for SpamAssassin in your rpm builds, or is it being used for other > parts > of MailScanner? I'm using it for the new SpamAssassin cache. Very quick and easy shared database. But it is optional. If it's not installed then you can't use the new feature, that's all. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ71Hi/w32o+k+q+hAQHAgwgAmhEtxP2POR2T9VEznquwjONYFsp50E0r /ORdbfrKGhLUlpn1W8OLclLiEzP2xTy0exdZPlOos+CLAZnCqPFhl3aEJTgVbc5x VdGKqXjPWUOKMjq36wT4ML2Ars2FpAECfxhfrJCQ/OEBGNABlEOV10XcOmoQe3GF YhzlR9mvzHUpVGdlTJDiofUB3p8n4z87OqW1EUHDMtZwoC0FYaleV0FNYgx06CML FTigLOnaJA3dSgtMVPCYRN+jFwUX+ORMvZ+JmE29J1D+zEVCH8VRybgpUFlHijbV Nb/XeIUwXlj5r1x9acnMMHMSJN9UNeY/rDtMHGuc6Sl1U37LCtNqiQ== =quyA -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki ( http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From martinh at SOLID-STATE-LOGIC.COM Tue Jan 10 11:56:05 2006 From: martinh at SOLID-STATE-LOGIC.COM (Martin Hepworth) Date: Thu Jan 12 21:31:41 2006 Subject: Upgraded to 4.49 now I have language messages in log file Message-ID: Nigel You sure you rand upgrade_languages_conf ? -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Nigel kendrick > Sent: 10 January 2006 11:39 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: [MAILSCANNER] Upgraded to 4.49 now I have language messages in > log file > > Upgraded to 4.49 OK (and DID run the upgrade scripts), but in the maillog > I > am getting: > > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown string > score in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown string > required in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown string > spamassassin in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown string > mailscanner in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown string > unreadablearchive in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown string > passwordedarchive in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown string > archivetoodeep in language translation file > /etc/MailScanner/reports/en/languages.conf > > Is this expected? > > Thanks > > NK > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From support-lists at PETDOCTORS.CO.UK Tue Jan 10 12:01:17 2006 From: support-lists at PETDOCTORS.CO.UK (Nigel kendrick) Date: Thu Jan 12 21:31:41 2006 Subject: Upgraded to 4.49 now I have language messages in log file Message-ID: Yep - on two servers - will do it again tho' -----Original Message----- From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Martin Hepworth Sent: 10 January 2006 11:56 To: MAILSCANNER@JISCMAIL.AC.UK Subject: Re: Upgraded to 4.49 now I have language messages in log file Nigel You sure you rand upgrade_languages_conf ? -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Nigel kendrick > Sent: 10 January 2006 11:39 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: [MAILSCANNER] Upgraded to 4.49 now I have language messages > in log file > > Upgraded to 4.49 OK (and DID run the upgrade scripts), but in the > maillog I am getting: > > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string score in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string required in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string spamassassin in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string mailscanner in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string unreadablearchive in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string passwordedarchive in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string archivetoodeep in language translation file > /etc/MailScanner/reports/en/languages.conf > > Is this expected? > > Thanks > > NK > > ------------------------ MailScanner list ------------------------ To > unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and the > archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Tue Jan 10 12:27:00 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:41 2006 Subject: Upgraded to 4.49 now I have language messages in log file Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Can the MailScanner "Run As User" read the languages.conf file? For some reason it isn't finding it or managing to read it. On 10 Jan 2006, at 11:39, Nigel kendrick wrote: > Upgraded to 4.49 OK (and DID run the upgrade scripts), but in the > maillog I > am getting: > > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string > score in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string > required in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string > spamassassin in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string > mailscanner in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string > unreadablearchive in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string > passwordedarchive in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string > archivetoodeep in language translation file > /etc/MailScanner/reports/en/languages.conf > > Is this expected? - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ8OoHPw32o+k+q+hAQHaKwf/SqpUv3uMjybA8fO6g7cleHgRX11W/3AD i3SkZ/e52JzSZlJ4RgSrYfsG68BoCYumrteWmXHP8Ca8D/JJI7ArQDdfAk83Mz3D A65PiNv9gQCDSftn/9oBc/htJF+n4Fv3tLyoB6ckziSJHG+7gFXPw++hhU3HIbc3 sc31T9dvalxG492z9gHAsQFLC0Crt3cPNno6MpIkxvkig3uptxSTnEfJDEmEekmR FhFJqMtG6OIKhPSp4P9Os6VFIvr2C1XpQPkgGVYdbu3BV4gS6pFtmWNmz2zDi4Vv dwGn91vOuY2qiufr68eAO378gOWQDV92ab37HxRZpJIV/QnZmacPkw== =eVsP -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Tue Jan 10 12:24:34 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:41 2006 Subject: MailScanner login Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Yes, that's correct. That is what most people wanted. Feel free to edit the code :-) On 10 Jan 2006, at 11:04, Helge Waastad wrote: > Hi, I've just installed the 4.49.7 version of MailScanner and it > works great. > Hoewever I hvae a question regarding logging. > When I catch spam messages, I get: > > mail postfix/smtpd[29931]: 439FF49C00D: reject_warning: RCPT from > unknown[217.219.173.8]: 450 Client host rejected: cannot find your > hostname, > [217.219.173.8]; from=<[spamuser]@hotmail.com> to=<[user]@[mydomain]> > proto=SMTP helo= > Jan 10 11:28:24 mail postfix/cleanup[29934]: 439FF49C00D: hold: header > Received: from mail.[mydomain] (unknown [217.219.173.8])??by mail. > [mydomain] > (Postfix) with SMTP id 439FF49C00D??for <[user]@[mydomain]>; Tue, > 10 Jan > 2006 11:28:23 +0100 (CET) from unknown[217.219.173.8]; > from=<[spamuser]@hotmail.com> to=<[user]@[mydomain]> proto=SMTP > helo= > Jan 10 11:28:30 mail MailScanner[29925]: Message 439FF49C00D.C2AA0 > from > 217.219.173.8 ([spamuser]@hotmail.com) to [mydomain] is NJABL, DSBL > > It is actually the last linje I'm wondering about. Is it correct > that only > the domain should be printed out in the to address? > > br, > hw > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ8Onhvw32o+k+q+hAQHXLAf/Wt8bu5MkZIhgOIjoBvbF+phkSR4ZAxJm TB2ywHXdHVIBdloy5A4g1exd8PKZ1mTVmDF9ov+JcrmGxvdXYyvkNlGXkW7sdrIm jbl2ki/L9OSlQ/OLCNQgH+8R+oHpiluEJcxfGtR8LBJXHccsR/xApWMkP78d85IE rtIK7ieDw9vccf5J5wKYlfonXNSd6Rzd8xiHUXRFZ01+mGJqJnRl+ZpoD3l0oxCq RDrKGiVUdIOykB6Zq9LxsJiLM7FZWpEm4w6O9h+/RTfGLMlSt3Hfw+NNx18SGskJ HdL3rACZJ5tfyI2sqW92HsNpK4BRcBYKPQZ3jPVsjPP1eaEt1O1jXw== =gzMc -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From drew at THEMARSHALLS.CO.UK Tue Jan 10 12:47:13 2006 From: drew at THEMARSHALLS.CO.UK (Drew Marshall) Date: Thu Jan 12 21:31:41 2006 Subject: Beta 4.50.5 released Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Tue, January 10, 2006 12:22, Devon Harding wrote: > What is the procedure in converting bayes to MYSQL? I'm getting too much > Spamassassin time outs. It's in the wiki http://wiki.mailscanner.info/doku.php?id=documentation:anti_spam:spamassassin:bayes:sql will do it! Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From support-lists at PETDOCTORS.CO.UK Tue Jan 10 13:12:13 2006 From: support-lists at PETDOCTORS.CO.UK (Nigel kendrick) Date: Thu Jan 12 21:31:41 2006 Subject: Upgraded to 4.49 now I have language messages in log file Message-ID: Yes - I can read the file. This is what is happening if I blindly follow the upgrade instructions.. 1) There's no .rpmnew (problem?) 2) upgrade_languages_conf languages.conf languages.conf.rpmnew > languages.new throws up the 'usage' screen and creates a zero byte .new file. 3) mv -f languages.conf languages.old backs up existing .conf 4) mv -f languages.new languages.conf puts zero byte file in place Just tried this on a third server (all CentOS4 uaing redHat rpm) - same result. NK -----Original Message----- From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Julian Field Sent: 10 January 2006 12:27 To: MAILSCANNER@JISCMAIL.AC.UK Subject: Re: Upgraded to 4.49 now I have language messages in log file -----BEGIN PGP SIGNED MESSAGE----- Can the MailScanner "Run As User" read the languages.conf file? For some reason it isn't finding it or managing to read it. On 10 Jan 2006, at 11:39, Nigel kendrick wrote: > Upgraded to 4.49 OK (and DID run the upgrade scripts), but in the > maillog I am getting: > > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string score in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string required in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string spamassassin in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string mailscanner in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string unreadablearchive in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string passwordedarchive in language translation file > /etc/MailScanner/reports/en/languages.conf > Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown > string archivetoodeep in language translation file > /etc/MailScanner/reports/en/languages.conf > > Is this expected? - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ8OoHPw32o+k+q+hAQHaKwf/SqpUv3uMjybA8fO6g7cleHgRX11W/3AD i3SkZ/e52JzSZlJ4RgSrYfsG68BoCYumrteWmXHP8Ca8D/JJI7ArQDdfAk83Mz3D A65PiNv9gQCDSftn/9oBc/htJF+n4Fv3tLyoB6ckziSJHG+7gFXPw++hhU3HIbc3 sc31T9dvalxG492z9gHAsQFLC0Crt3cPNno6MpIkxvkig3uptxSTnEfJDEmEekmR FhFJqMtG6OIKhPSp4P9Os6VFIvr2C1XpQPkgGVYdbu3BV4gS6pFtmWNmz2zDi4Vv dwGn91vOuY2qiufr68eAO378gOWQDV92ab37HxRZpJIV/QnZmacPkw== =eVsP -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Tue Jan 10 13:40:55 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:41 2006 Subject: Upgraded to 4.49 now I have language messages in log file Message-ID: -----BEGIN PGP SIGNED MESSAGE----- If there is no .rpmnew file then you don't need to upgrade it anyway. On 10 Jan 2006, at 13:12, Nigel kendrick wrote: > Yes - I can read the file. > > This is what is happening if I blindly follow the upgrade > instructions.. > > 1) There's no .rpmnew (problem?) > 2) upgrade_languages_conf languages.conf languages.conf.rpmnew > > languages.new throws up the 'usage' screen and creates a zero > byte .new > file. > 3) mv -f languages.conf languages.old backs up existing .conf > 4) mv -f languages.new languages.conf puts zero byte file in place > > Just tried this on a third server (all CentOS4 uaing redHat rpm) - > same > result. > > NK > > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] > On Behalf > Of Julian Field > Sent: 10 January 2006 12:27 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: Upgraded to 4.49 now I have language messages in log file > > * PGP Bad Signature, Signed by a unverified key: 01/10/06 at 12:27:08 > > Can the MailScanner "Run As User" read the languages.conf file? > For some reason it isn't finding it or managing to read it. > > On 10 Jan 2006, at 11:39, Nigel kendrick wrote: > >> Upgraded to 4.49 OK (and DID run the upgrade scripts), but in the >> maillog I am getting: >> >> Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown >> string score in language translation file >> /etc/MailScanner/reports/en/languages.conf >> Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown >> string required in language translation file >> /etc/MailScanner/reports/en/languages.conf >> Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown >> string spamassassin in language translation file >> /etc/MailScanner/reports/en/languages.conf >> Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown >> string mailscanner in language translation file >> /etc/MailScanner/reports/en/languages.conf >> Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown >> string unreadablearchive in language translation file >> /etc/MailScanner/reports/en/languages.conf >> Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown >> string passwordedarchive in language translation file >> /etc/MailScanner/reports/en/languages.conf >> Jan 10 11:32:18 petdoctors MailScanner[15670]: Looked up unknown >> string archivetoodeep in language translation file >> /etc/MailScanner/reports/en/languages.conf >> >> Is this expected? > > -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store PGP > footprint: EE81 > D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > * Julian Field > * 0xA4FAAFA1 - Unverified (L) > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ8O5a/w32o+k+q+hAQEqEAgAu5B3kYDbg02x2onRGCaeKn0tn9VTDUZn YVJJJUiYT/NbFYfes5HiIWPqF5NOLcL8oRef4a96lHsi/fKMkJihginYoCa5s/KF 4AMnLDyQYrtxIwxRtaQhi9Z2YrwIdMZ6154J6h8jGJevj/9ZdM98vkW7wBZwaERv yUrssoaFrOvjC0kwf7cnNGVXOefn6LhA80m70DwSVWbKQS4qo6izdXWmxwbi+/6D yrE2oMHxNnW1/42oS6r7Tb0GG1gkWlXnLXmNL1OQCeX9JoS4h52i+9PpNqktWXVo HS7lbpMIaO3VCEdMT03iZsArKqO/c1NVCZxPH//TBemosJJSLLGF3w== =Rwp0 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Tue Jan 10 14:03:27 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:41 2006 Subject: MailScanner login Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/10/06, Helge Waastad wrote: Jan 10 11:28:30 mail MailScanner[29925]: Message 439FF49C00D.C2AA0 from numericlinkwarning 217.219.173.8 ([spamuser]@hotmail.com) to [mydomain] is NJABL, DSBL It is actually the last linje I'm wondering about. Is it correct that only the domain should be printed out in the to address? I've always assumed that it would be a problem to log correctly if the spam was addressed to 10:s or 100:s of recipients. I think a syslog line can be only 512 bytes, I might be wrong about that but it definitely has some limit since I've seen truncated lines. -- /peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From lhaig at HAIGMAIL.COM Tue Jan 10 13:38:20 2006 From: lhaig at HAIGMAIL.COM (Lance Haig) Date: Thu Jan 12 21:31:41 2006 Subject: How did I turn off html emails? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Hi Guys I know that this is not a good idea but I am getting calls about html e-mail looking like this http://www.google.co.uk/imghp?hl=en&tab=wi&client=firefox-a&rls=org.mozilla:en-GB:official_s Images http://groups.google.co.uk/grphp?hl=en&tab=wg&client=firefox-a&rls=org.mozilla:en-GB:official_s Groups http://news.google.co.uk/nwshp?hl=en&tab=wn&client=firefox-a&rls=org.mozilla:en-GB:official_s News I must have implemented a setting in MS that caused this can someone help point me in the right direction. Thanks Lance ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Tue Jan 10 14:06:12 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:41 2006 Subject: How did I turn off html emails? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/10/06, Lance Haig wrote: Hi Guys I know that this is not a good idea but I am getting calls about html e-mail looking like this http://www.google.co.uk/imghp?hl=en&tab=wi&client=firefox-a&rls=org.mozilla:en- B:official_s Images http://groups.google.co.uk/grphp?hl=en&tab=wg&client=firefox-a&rls=org.mozilla: n-GB:official_s Groups http://news.google.co.uk/nwshp?hl=en&tab=wn&client=firefox-a&rls=org.mozilla:en GB:official_s News I must have implemented a setting in MS that caused this can someone help point me in the right direction. Could you have used this one? # Do you want to convert all HTML messages into plain text? # This is very useful for users who are children or are easily offended # by nasty things like pornographic spam. # This can also be the filename of a ruleset, so you can switch this # feature on and off for particular users or domains. Convert HTML To Text = no -- /peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From lhaig at HAIGMAIL.COM Tue Jan 10 14:10:38 2006 From: lhaig at HAIGMAIL.COM (Lance Haig) Date: Thu Jan 12 21:31:41 2006 Subject: How did I turn off html emails? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Peter, Yup that is what I had. I need to set-up a rule for the complainers. thanks again. Lance shuttlebox wrote: On 1/10/06, Lance Haig wrote: Hi Guys I know that this is not a good idea but I am getting calls about html e-mail looking like this http://www.google.co.uk/imghp?hl=en&tab=wi&client=firefox-a&rls=org.mozilla:en- B:official_s Images http://groups.google.co.uk/grphp?hl=en&tab=wg&client=firefox-a&rls=org.mozilla: n-GB:official_s Groups http://news.google.co.uk/nwshp?hl=en&tab=wn&client=firefox-a&rls=org.mozilla:en GB:official_s News I must have implemented a setting in MS that caused this can someone help point me in the right direction. Could you have used this one? # Do you want to convert all HTML messages into plain text? # This is very useful for users who are children or are easily offended # by nasty things like pornographic spam. # This can also be the filename of a ruleset, so you can switch this # feature on and off for particular users or domains. Convert HTML To Text = no -- /peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by Red Armour MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From roger at RUDNICK.COM.BR Tue Jan 10 15:20:13 2006 From: roger at RUDNICK.COM.BR (Roger Jochem) Date: Thu Jan 12 21:31:41 2006 Subject: ClamAV Database Update Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Anyone having trouble upgrading Clamav? The last successfull database update was done in January 8 in my installation... Regards Roger Jochem ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From alex at NKPANAMA.COM Tue Jan 10 15:23:23 2006 From: alex at NKPANAMA.COM (Alex Neuman van der Hans) Date: Thu Jan 12 21:31:41 2006 Subject: ClamAV Database Update Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Roger Jochem wrote: > Anyone having trouble upgrading Clamav? The last successfull database > update was done in January 8 in my installation... > > Regards > > Roger Jochem > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! Depends... how old *is* your install? Are you using 0.88? ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Tue Jan 10 15:24:38 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:41 2006 Subject: ClamAV Database Update Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/10/06, Roger Jochem wrote: Anyone having trouble upgrading Clamav? The last successfull database update was done in January 8 in my installation... I just got 1236 an hour ago. They always publish the latest file on clamav.net. -- /peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From roger at RUDNICK.COM.BR Tue Jan 10 15:33:55 2006 From: roger at RUDNICK.COM.BR (Roger Jochem) Date: Thu Jan 12 21:31:41 2006 Subject: ClamAV Database Update Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] I was using 0.87.1. I just upgraded and it is working fine again... Regards ----- Original Message ----- From: "Alex Neuman van der Hans" To: Sent: Tuesday, January 10, 2006 1:23 PM Subject: Re: ClamAV Database Update > Roger Jochem wrote: > >> Anyone having trouble upgrading Clamav? The last successfull database >> update was done in January 8 in my installation... >> >> Regards >> >> Roger Jochem >> >> ------------------------ MailScanner list ------------------------ >> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >> 'leave mailscanner' in the body of the email. >> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >> >> Support MailScanner development - buy the book off the website! > > Depends... how old *is* your install? Are you using 0.88? > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ryan at MARINOCRANE.COM Tue Jan 10 15:37:30 2006 From: ryan at MARINOCRANE.COM (Ryan Pitt) Date: Thu Jan 12 21:31:41 2006 Subject: ClamAV Database Update Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Can I ask how you upgraded. I am having trouble. FC2 ClamAV 0.87.1 Thanks Ryan Roger Jochem wrote: > I was using 0.87.1. > I just upgraded and it is working fine again... > > Regards > > ----- Original Message ----- From: "Alex Neuman van der Hans" > > To: > Sent: Tuesday, January 10, 2006 1:23 PM > Subject: Re: ClamAV Database Update > > >> Roger Jochem wrote: >> >>> Anyone having trouble upgrading Clamav? The last successfull >>> database update was done in January 8 in my installation... >>> >>> Regards >>> >>> Roger Jochem >>> >>> ------------------------ MailScanner list ------------------------ >>> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >>> 'leave mailscanner' in the body of the email. >>> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >>> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >>> >>> Support MailScanner development - buy the book off the website! >> >> >> Depends... how old *is* your install? Are you using 0.88? >> >> ------------------------ MailScanner list ------------------------ >> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >> 'leave mailscanner' in the body of the email. >> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >> >> Support MailScanner development - buy the book off the website! > > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dyioulos at FIRSTBHPH.COM Tue Jan 10 15:51:03 2006 From: dyioulos at FIRSTBHPH.COM (Dimitri Yioulos) Date: Thu Jan 12 21:31:41 2006 Subject: ClamAV Database Update Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Tuesday January 10 2006 10:20 am, Roger Jochem wrote: > Anyone having trouble upgrading Clamav? The last successfull database > update was done in January 8 in my installation... > > Regards > > Roger Jochem > I was running 0.87-1 until this morning (when I upgraded to 0.88) on CentOS 3 and 4 and FC2 boxes without a problem. Dimitri -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From alex at NKPANAMA.COM Tue Jan 10 15:52:23 2006 From: alex at NKPANAMA.COM (Alex Neuman van der Hans) Date: Thu Jan 12 21:31:41 2006 Subject: ClamAV Database Update Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Best way to upgrade is usually, in the following order: 1. Download from clamav.net - extract, ./configure && make && make install && freshclam 2. Use Julian's script (updates SpamAssassin too, which is something you *may* or *may not* want) 3. Update from RPM's at dag.wieers.com or other repositories (if you're using RHEL or FC) Ryan Pitt wrote: > Can I ask how you upgraded. > I am having trouble. > FC2 > ClamAV 0.87.1 > Thanks > Ryan > > Roger Jochem wrote: > >> I was using 0.87.1. >> I just upgraded and it is working fine again... >> >> Regards >> >> ----- Original Message ----- From: "Alex Neuman van der Hans" >> >> To: >> Sent: Tuesday, January 10, 2006 1:23 PM >> Subject: Re: ClamAV Database Update >> >> >>> Roger Jochem wrote: >>> >>>> Anyone having trouble upgrading Clamav? The last successfull >>>> database update was done in January 8 in my installation... >>>> >>>> Regards >>>> >>>> Roger Jochem >>>> >>>> ------------------------ MailScanner list ------------------------ >>>> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >>>> 'leave mailscanner' in the body of the email. >>>> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >>>> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >>>> >>>> Support MailScanner development - buy the book off the website! >>> >>> >>> >>> Depends... how old *is* your install? Are you using 0.88? >>> >>> ------------------------ MailScanner list ------------------------ >>> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >>> 'leave mailscanner' in the body of the email. >>> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >>> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >>> >>> Support MailScanner development - buy the book off the website! >> >> >> >> ------------------------ MailScanner list ------------------------ >> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >> 'leave mailscanner' in the body of the email. >> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >> >> Support MailScanner development - buy the book off the website! >> > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Peter.Bates at LSHTM.AC.UK Tue Jan 10 16:22:24 2006 From: Peter.Bates at LSHTM.AC.UK (Peter Bates) Date: Thu Jan 12 21:31:41 2006 Subject: MailScanner init-script (feature request?) Message-ID: Hello all... When I'm upgrading MailScanner (this is on a RH Linux box), I generally like to shut down MS and bring up the MTA (Postfix in our case)... so as to at least receive the mail during the 'downtime'. At the moment the init-script (as in the RPM package) handles shutting down/starting up the MTA and MailScanner in one... Is it possible to add some sort of 'custom' setting to /etc/sysconfig/MailScanner so the script *only* stops/starts MS? At the moment I edit the init-script by hand, but naturally every time I upgrade I end up with an .rpmnew ... Just a slight request... I appreciate that for some cases handling both tasks is easier. ---------------------------------------------------------------------------------------------------> Peter Bates, Systems Support Officer, IT Services. London School of Hygiene & Tropical Medicine. Telephone:0207-958 8353 / Fax: 0207- 636 9838 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From craig at CSFS.CO.ZA Tue Jan 10 16:13:53 2006 From: craig at CSFS.CO.ZA (Craig) Date: Thu Jan 12 21:31:41 2006 Subject: Child Process Hangs Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Hi All, I freshly installed MailScanner 4.50.5, spamassassin, clamav 0.88, razor, pyzor, dcc and MailWatch 1.0.3. I also updated all perl modules to the latest. When I send a message, the MailScanner proccess stays is the "MailScanner: finishing batch" state. I noticed that MailScanner dies after all the child processes have processed a batch. If I kill one of the child processes, the MailScanner master starts a new process thus indicating that something in the processing of the message batch prevents the child process of dying. Is there a way that I can check what might be causing this as I have checked the logs and done spamassassin lint test which produces no errors that indicate anything??? Thanks Craig ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From michele at BLACKNIGHT.IE Tue Jan 10 16:48:50 2006 From: michele at BLACKNIGHT.IE (Michele Neylon :: Blacknight Solutions) Date: Thu Jan 12 21:31:41 2006 Subject: OT: Open Proxy DNSBL Message-ID: Any recommendations? Preferably one that would allow rsync access ... Michele Mr Michele Neylon Blacknight Solutions Hosting & Colocation, Brand Protection http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 UK: 0870 163 0607 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dyioulos at FIRSTBHPH.COM Tue Jan 10 16:38:20 2006 From: dyioulos at FIRSTBHPH.COM (Dimitri Yioulos) Date: Thu Jan 12 21:31:41 2006 Subject: help with these errors Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Tuesday January 10 2006 11:35 am, Michael Baird wrote: > On Tue, 2006-01-10 at 11:28 -0500, Dimitri Yioulos wrote: > > Hello to all. > > > > After upgrading to the latest version of MS, following "errors" are > > reported by logwatch: > > > > Unrecognised keyword "spamassassinprefsfile" at line 1335 : 29 > > Time(s) Closing down by-domain spam blacklist : 29 Time(s) > > Closing down by-domain spam whitelist : 29 Time(s) > > Looks like you have a syntax error in your MailScanner.conf, where are > the spaces in that directive? > > SpamAssassin Prefs File = %etc-dir%/spam.assassin.prefs.conf > > Regards > Michael Baird > I checked MailScanner.conf, and the line in question is as it should be. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From craig at CSFS.CO.ZA Tue Jan 10 16:47:27 2006 From: craig at CSFS.CO.ZA (Craig Retief (CSFS)) Date: Thu Jan 12 21:31:41 2006 Subject: Child Process Hangs Message-ID: Hi Julian: I checked and debug = no. You are right on the DB logging, it is not taking place. Hi Steve: I changed the Always Looked Up Last to no and it seems to have done the trick – thanks ;-). I ran the perl -w MailWatch.pm command and got this -> “Useless use of private variable in void context at MailWatch.pm line 247.” This is the section of MailWatch.pm that it is complaining about: while(($file, $text) = each %{$message->{allreports}}) { $file = "the entire message" if $file eq ""; # Use the sanitised filename to avoid problems caused by people forcing # logging of attachment filenames which contain nasty SQL instructions. $file = $message->{file2safefile}{$file} or $file; $text =~ s/\n/ /; # Make sure text report only contains 1 line $text =~ s/\t/ /; # and no tab characters push (@report_array, $text); } Is this as Julian made me realize maybe a DB logging error? ________________________________________________________________________________ From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Julian Field Sent: 10 January 2006 06:33 PM To: MAILSCANNER@JISCMAIL.AC.UK Subject: Re: Child Process Hangs On 10 Jan 2006, at 16:13, Craig wrote: Hi All, I freshly installed MailScanner 4.50.5, spamassassin, clamav 0.88, razor, pyzor, dcc and MailWatch 1.0.3. I also updated all perl modules to the latest. When I send a message, the MailScanner proccess stays is the "MailScanner: finishing batch" state. This sounds like it is failing to do the MailWatch database logging. I noticed that MailScanner dies after all the child processes have processed a batch. If I kill one of the child processes, the MailScanner master starts a new process thus indicating that something in the processing of the message batch prevents the child process of dying. Are you sure you do not have "Debug = yes" in MailScanner.conf? Is there a way that I can check what might be causing this as I have checked the logs and done spamassassin lint test which produces no errors that indicate anything??? -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dyioulos at FIRSTBHPH.COM Tue Jan 10 16:28:08 2006 From: dyioulos at FIRSTBHPH.COM (Dimitri Yioulos) Date: Thu Jan 12 21:31:41 2006 Subject: help with these errors Message-ID: Hello to all. After upgrading to the latest version of MS, following "errors" are reported by logwatch: Unrecognised keyword "spamassassinprefsfile" at line 1335 : 29 Time(s) Closing down by-domain spam blacklist : 29 Time(s) Closing down by-domain spam whitelist : 29 Time(s) what's cauing this? Thanks. Dimitri -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From smf at F2S.COM Tue Jan 10 16:32:00 2006 From: smf at F2S.COM (Steve Freegard) Date: Thu Jan 12 21:31:41 2006 Subject: Child Process Hangs Message-ID: Hi Craig, On Tue, 2006-01-10 at 18:13 +0200, Craig wrote: > Hi All, > > I freshly installed MailScanner 4.50.5, spamassassin, clamav 0.88, > razor, pyzor, dcc and MailWatch 1.0.3. I also updated all perl modules > to the latest. > > When I send a message, the MailScanner proccess stays is the > "MailScanner: finishing batch" state. The 'finishing batch' state would indicate that MailScanner is processing the 'Always Looked Up Last' value. See if disabling MailWatch fixes this problem by setting 'Always Looked Up Last = no' and restarting MailScanner. If this does fix the problem then run 'perl -w MailWatch.pm' from the CustomFunctions directory to make sure that no errors are reported. Hope this helps. Kind regards, Steve. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Tue Jan 10 16:31:08 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:41 2006 Subject: MailScanner init-script (feature request?) Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 10 Jan 2006, at 16:22, Peter Bates wrote: > Hello all... > > When I'm upgrading MailScanner (this is on a RH Linux box), > I generally like to shut down MS and bring up the MTA > (Postfix in our case)... so as to at least receive the mail > during the 'downtime'. > > At the moment the init-script (as in the RPM package) > handles shutting down/starting up the MTA and MailScanner > in one... > > Is it possible to add some sort of 'custom' setting to > /etc/sysconfig/MailScanner so the script *only* stops/starts MS? I've implemented it the other way around. You can service MailScanner stop service MailScanner startin service MailScanner startout Do all the MailScanner stuff you want to do service MailScanner restart - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ8PhTvw32o+k+q+hAQGjFggAkAVnUpzJZd9XpfXGSa0iXBnEmk2SRc33 euJ3YpophZs8RahjoqLdP79lMkDI+fn4z6AODd8esn2VodZe4790ByPLN7F8bCRn yue+bBpq8c/rp+Cd2c6nXZfoCiqjicYrxbIkWoYlfzDGpqCVwvlfMi+i9m6Z7dTE r8izuOZw02KPjUPoCycVXp48grchCVgVPmdKvVdoy/DBnO1xeh91vWo+WTr8YdEK Jx/l4rfFWDsjbBFQkCEip23Te6fjdX6s5pUmgi2rgXw+E0UygrgHIQKYRpHZBoP+ g9jjZSJIEvvHcwF8yyIVrINjsW9Iy5nLuwH0K0J0Lg+K2n1Qe+WHsw== =ULRs -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Tue Jan 10 16:29:02 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:41 2006 Subject: ClamAV Database Update Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 10 Jan 2006, at 15:52, Alex Neuman van der Hans wrote: > Best way to upgrade is usually, in the following order: > > 2. Use Julian's script (updates SpamAssassin too, which is > something you *may* or *may not* want) If you don't want it to update SpamAssassin, just press Ctrl-C before it gets that far. Today I just thumped Ctrl-C as it was starting to install the various Perl modules, as I just want ClamAV updated and nothing else. > Ryan Pitt wrote: > >> Can I ask how you upgraded. >> I am having trouble. >> FC2 >> ClamAV 0.87.1 >> Thanks >> Ryan >> >> Roger Jochem wrote: >> >>> I was using 0.87.1. >>> I just upgraded and it is working fine again... >>> >>> Regards >>> >>> ----- Original Message ----- From: "Alex Neuman van der Hans" >>> >>> To: >>> Sent: Tuesday, January 10, 2006 1:23 PM >>> Subject: Re: ClamAV Database Update >>> >>> >>>> Roger Jochem wrote: >>>> >>>>> Anyone having trouble upgrading Clamav? The last successfull >>>>> database update was done in January 8 in my installation... >>>>> >>>>> Regards >>>>> >>>>> Roger Jochem >>>>> >>>>> ------------------------ MailScanner list ------------------------ >>>>> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >>>>> 'leave mailscanner' in the body of the email. >>>>> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >>>>> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >>>>> >>>>> Support MailScanner development - buy the book off the website! >>>> >>>> >>>> >>>> Depends... how old *is* your install? Are you using 0.88? >>>> >>>> ------------------------ MailScanner list ------------------------ >>>> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >>>> 'leave mailscanner' in the body of the email. >>>> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >>>> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >>>> >>>> Support MailScanner development - buy the book off the website! >>> >>> >>> >>> ------------------------ MailScanner list ------------------------ >>> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >>> 'leave mailscanner' in the body of the email. >>> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >>> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >>> >>> Support MailScanner development - buy the book off the website! >>> >> >> ------------------------ MailScanner list ------------------------ >> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >> 'leave mailscanner' in the body of the email. >> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >> >> Support MailScanner development - buy the book off the website! > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ8Pgz/w32o+k+q+hAQHsQwf/SyTp31YH+6ZsuPDlmtZKDG7qZ2NFgZVb xCcZSxnjC3NtIpzUnw7Y3U0qJnXnMhtu9ETG4a2HlLEM7USp/SDnmhynJt3Am4sx Mu6KqixgTgbmwN2Wi4TaNjljO+3mXfr8C6niZ984W/Q6xag4Ti/fcaRHLKaX0XfO 6wHyOcBx9PQkfjQRkxsuNnVDjYvebOcOblR33puu0LrSof4lQ4V+xvkwdhP5bG+f yLuh9fxnsyOxXQnV3NeuzL46n4Ut061uy0igbO8oYsZDV5KSYGVdX62LAuCKwxUl TSaSxslNp8Zw0SE6Mcrb5RXqPBiruO2lr5Jq03yy1+k67n7gG4muaA== =AWUj -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dyioulos at FIRSTBHPH.COM Tue Jan 10 17:05:04 2006 From: dyioulos at FIRSTBHPH.COM (Dimitri Yioulos) Date: Thu Jan 12 21:31:41 2006 Subject: help with these errors Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Tuesday January 10 2006 11:52 am, Dimitri Yioulos wrote: > On Tuesday January 10 2006 11:41 am, Randal, Phil wrote: > > > On Tue, 2006-01-10 at 11:28 -0500, Dimitri Yioulos wrote: > > > > Hello to all. > > > > > > > > After upgrading to the latest version of MS, following "errors" are > > > > reported by logwatch: > > > > > > > > Unrecognised keyword "spamassassinprefsfile" at line > > > > > > 1335 : 29 Time(s) > > > > > > > Closing down by-domain spam blacklist : 29 Time(s) > > > > Closing down by-domain spam whitelist : 29 Time(s) > > > > > > Looks like you have a syntax error in your MailScanner.conf, > > > where are the spaces in that directive? > > > > > > SpamAssassin Prefs File = %etc-dir%/spam.assassin.prefs.conf > > > > > > Regards > > > Michael Baird > > > > Looks like upgrade_MailScanner_conf wasn't run properly. I see no such > > option in mu /etc/MailScanner/MailScanner.conf. > > > > Phil > > ---- > > I've run upgrade_MailScanner_conf with each version upgrade (including this > one) without incident. Is the line "SpamAssassin Prefs File = > %etc-dir%/spam.assassin.prefs.conf" deprecated? Oh, my own stupidity kills me (hope it's not killing you. :-) ) I was leaving out a step in the upgrade process! Once done, joy. Sorry to take up needless space. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From smf at F2S.COM Tue Jan 10 16:58:41 2006 From: smf at F2S.COM (Steve Freegard) Date: Thu Jan 12 21:31:41 2006 Subject: OT: Open Proxy DNSBL Message-ID: Hi Michele, http://cbl.abuseat.org/ http://opm.blitzed.org/info/ And possibly: http://www.njabl.org/ All three are used to build xbl.spamhaus.org list - so are well trusted. Cheers, Steve. On Tue, 2006-01-10 at 16:48 +0000, Michele Neylon :: Blacknight Solutions wrote: > Any recommendations? > > Preferably one that would allow rsync access ... > > Michele > > Mr Michele Neylon > Blacknight Solutions > Hosting & Colocation, Brand Protection > http://www.blacknight.ie/ > Tel. 1850 927 280 > Intl. +353 (0) 59 9183072 > UK: 0870 163 0607 > Direct Dial: +353 (0)59 9183090 > Fax. +353 (0) 59 9164239 > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From prandal at HEREFORDSHIRE.GOV.UK Tue Jan 10 17:03:10 2006 From: prandal at HEREFORDSHIRE.GOV.UK (Randal, Phil) Date: Thu Jan 12 21:31:41 2006 Subject: help with these errors Message-ID: > > Looks like upgrade_MailScanner_conf wasn't run properly. I see no > > such option in mu /etc/MailScanner/MailScanner.conf. > > I've run upgrade_MailScanner_conf with each version upgrade > (including this > one) without incident. Is the line "SpamAssassin Prefs File > = %etc-dir%/spam.assassin.prefs.conf" deprecated? Yes, which is why I queried whether your conf file upgrade was successful. From bogus@does.not.exist.com Thu Jan 12 21:14:02 2006 From: bogus@does.not.exist.com () Date: Thu Jan 12 21:31:41 2006 Subject: No subject Message-ID: "1/12/2005 Released stable version 4.48.4. Major new feature this month is a rearrangement of how the spam.assassin.prefs.conf is used. This is now linked into the site-rules directory of SpamAssassin, so it is automatically read by SpamAssassin's startup code, and no special file-reading code is done in MailScanner any more. The installation scripts should take care of all of this for you, don't worry." Cheers, Phil ---- Phil Randal Network Engineer Herefordshire Council Hereford, UK ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dyioulos at FIRSTBHPH.COM Tue Jan 10 16:52:55 2006 From: dyioulos at FIRSTBHPH.COM (Dimitri Yioulos) Date: Thu Jan 12 21:31:41 2006 Subject: help with these errors Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Tuesday January 10 2006 11:41 am, Randal, Phil wrote: > > On Tue, 2006-01-10 at 11:28 -0500, Dimitri Yioulos wrote: > > > Hello to all. > > > > > > After upgrading to the latest version of MS, following "errors" are > > > reported by logwatch: > > > > > > Unrecognised keyword "spamassassinprefsfile" at line > > > > 1335 : 29 Time(s) > > > > > Closing down by-domain spam blacklist : 29 Time(s) > > > Closing down by-domain spam whitelist : 29 Time(s) > > > > Looks like you have a syntax error in your MailScanner.conf, > > where are the spaces in that directive? > > > > SpamAssassin Prefs File = %etc-dir%/spam.assassin.prefs.conf > > > > Regards > > Michael Baird > > Looks like upgrade_MailScanner_conf wasn't run properly. I see no such > option in mu /etc/MailScanner/MailScanner.conf. > > Phil > ---- I've run upgrade_MailScanner_conf with each version upgrade (including this one) without incident. Is the line "SpamAssassin Prefs File = %etc-dir%/spam.assassin.prefs.conf" deprecated? -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From alex at NKPANAMA.COM Tue Jan 10 16:51:02 2006 From: alex at NKPANAMA.COM (Alex Neuman van der Hans) Date: Thu Jan 12 21:31:41 2006 Subject: ClamAV Database Update Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] You could also have a --clamav-only option, for example. Wouldn't be too hard to code in; I've modified install.sh a few times to add stuff like --enable-milter to clamav's config. Julian Field wrote: >-----BEGIN PGP SIGNED MESSAGE----- > > >>2. Use Julian's script (updates SpamAssassin too, which is >>something you *may* or *may not* want) >> >> > >If you don't want it to update SpamAssassin, just press Ctrl-C before >it gets that far. Today I just thumped Ctrl-C as it was starting to >install the various Perl modules, as I just want ClamAV updated and >nothing else. > > > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From nerijus at USERS.SOURCEFORGE.NET Tue Jan 10 17:26:35 2006 From: nerijus at USERS.SOURCEFORGE.NET (Nerijus Baliunas) Date: Thu Jan 12 21:31:41 2006 Subject: zombie processes Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Tue, 10 Jan 2006 09:18:11 +0000 Julian Field wrote: > You have an error in your MailScanner.conf, check your maillog. > What version of MailScanner are you running? woody shipped with 3.27. Nothing wrong in log: Jan 10 05:40:03 mail MailScanner[15356]: MailScanner E-Mail Virus Scanner version 4.49.7 starting... Jan 10 05:40:03 mail MailScanner[15356]: Read 695 hostnames from the phishing whitelist Jan 10 05:40:03 mail MailScanner[15356]: Using locktype = posix Jan 10 05:40:03 mail MailScanner[15356]: Creating hardcoded struct_flock subroutine for linux (Linux-type) Jan 10 05:40:03 mail MailScanner[15356]: New Batch: Scanning 1 messages, 4259 bytes Jan 10 05:40:03 mail MailScanner[15356]: Virus and Content Scanning: Starting Jan 10 05:40:03 mail MailScanner[15356]: Uninfected: Delivered 1 messages Jan 10 05:40:14 mail MailScanner[15366]: MailScanner E-Mail Virus Scanner version 4.49.7 starting... Jan 10 05:40:14 mail MailScanner[15366]: Read 695 hostnames from the phishing whitelist Jan 10 05:40:14 mail MailScanner[15366]: Using locktype = posix Jan 10 05:40:14 mail MailScanner[15366]: Creating hardcoded struct_flock subroutine for linux (Linux-type) Regards, Nerijus ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From gmatt at NERC.AC.UK Tue Jan 10 17:17:41 2006 From: gmatt at NERC.AC.UK (Greg Matthews) Date: Thu Jan 12 21:31:41 2006 Subject: MailScanner init-script (feature request?) Message-ID: On Tue, 2006-01-10 at 16:31 +0000, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > I've implemented it the other way around. You can > service MailScanner stop > service MailScanner startin > service MailScanner startout > Do all the MailScanner stuff you want to do > service MailScanner restart It would be really useful to have fine grained control of these processes. I've been meaning to hack at this for ages but its a matter of time... for instance, it is useful to be able to stop the incoming listener and let the queue drain. Or just start MailScanner to process some sample emails from one queue to another with no real delivery. If I ever get around to it I'll post to the list unless someone beats me to it... G > > - -- > Julian Field -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From roger at RUDNICK.COM.BR Tue Jan 10 17:11:42 2006 From: roger at RUDNICK.COM.BR (Roger Jochem) Date: Thu Jan 12 21:31:41 2006 Subject: ClamAV 0.88 is out!! Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] It would be nice if this script had an option to install only Clamav. SpamAssassin is not updated so often like clamav, and I allways use the ctrl-c to stop the script like you said before, Julian. But this option would be intersting, i guess... ./install.sh ./install.sh clamav ./install.sh spamassassin The fist option would install both, and the others would install one or another... Regards Roger Jochem ----- Original Message ----- From: "Julian Field" To: Sent: Tuesday, January 10, 2006 7:11 AM Subject: Re: ClamAV 0.88 is out!! > -----BEGIN PGP SIGNED MESSAGE----- > > I have updated by easy-to-install ClamAV+SpamAssassin package at > > www.sng.ecs.soton.ac.uk/mailscanner/files/4/install-Clam-SA.tar.gz > > to include this update. > > On 9 Jan 2006, at 21:25, Dhawal Doshy wrote: > >> For those waiting for the stable release of clamav, which is >> supposed to correct the scanning of certain new sober variants.. >> http://freshmeat.net/projects/clamav/? >> branch_id=29355&release_id=216552 >> - dhawal > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.3 (Build 2932) > > iQEVAwUBQ8N6Wfw32o+k+q+hAQFd2wf/ZHOWckS9fpolxIQ4wOWnV/Xg8uDV7jsS > d4dbO8kizefb4gle7lEmwPDhGFC6iRiHmyrD+Q1BTEFxvwwXj7Wz1Q3zU8+dXUWz > tge2ZcSq03cBT0ogmq7sDc6XP01KdMhyqXzI/bQhsOuGo1vC2vWZuK+uk0b7YlUb > NNsaW8v0cXNdSEhjHXPdfcW0uVcxY779itLJUI2rlAz26iE35FDmD4lZw1qHx3rx > kTtnwDwDNRh2FKYYcaF9PAFwOw/whTtKjX4E2Cm6HQUdziZ9rKSxFO/y3It5m7rO > tHSAwMoHshkBZUVVhQxjlhRMN27OTKQ52mB7ZlrBtVVOwrlnjjVoAg== > =IUJ+ > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Tue Jan 10 16:32:51 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:41 2006 Subject: Child Process Hangs Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 10 Jan 2006, at 16:13, Craig wrote: Hi All,   I freshly installed MailScanner 4.50.5, spamassassin, clamav 0.88, razor, pyzor, dcc and MailWatch 1.0.3. I also updated all perl modules to the latest.   When I send a message, the MailScanner proccess stays is the "MailScanner: finishing batch" state. This sounds like it is failing to do the MailWatch database logging. I noticed that MailScanner dies after all the child processes have processed a batch. If I kill one of the child processes, the MailScanner master starts a new process thus indicating that something in the processing of the message batch prevents the child process of dying. Are you sure you do not have "Debug = yes" in MailScanner.conf? Is there a way that I can check what might be causing this as I have checked the logs and done spamassassin lint test which produces no errors that indicate anything??? --  Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! [ Part 2, Application/PGP-SIGNATURE 498bytes. ] [ Unable to print this part. ] From smf at F2S.COM Tue Jan 10 17:13:05 2006 From: smf at F2S.COM (Steve Freegard) Date: Thu Jan 12 21:31:41 2006 Subject: Child Process Hangs Message-ID: [ The following text is in the "UTF-8" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Hi Craig, On Tue, 2006-01-10 at 18:47 +0200, Craig Retief (CSFS) wrote: > > > I ran the perl -w MailWatch.pm command and got this -> â^À^ÜUseless use of > private variable in void context at MailWatch.pm line 247.â^À^Ý > This is a harmless warning - it can be ignored. > > Is this as Julian made me realize maybe a DB logging error? > Yes - it looks to be - though I've never seen MailWatch.pm hang a MailScanner system like this before. Check that DBI, DBD-MySQL, Sys::Hostname, Socket and Storable perl modules are installed correctly - also make sure that you aren't doing anything 'funky' with TCP port 11553 (e.g. delaying or dropping packets using iptables etc.). Cheers, Steve. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From prandal at HEREFORDSHIRE.GOV.UK Tue Jan 10 17:00:28 2006 From: prandal at HEREFORDSHIRE.GOV.UK (Randal, Phil) Date: Thu Jan 12 21:31:41 2006 Subject: Open Proxy DNSBL Message-ID: cbl.abuseat.org springs to mind. They support rsync too. http://cbl.abuseat.org/ Phil ---- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: MailScanner mailing list > [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Michele > Neylon :: Blacknight Solutions > Sent: 10 January 2006 16:49 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: OT: Open Proxy DNSBL > > Any recommendations? > > Preferably one that would allow rsync access ... > > Michele > > Mr Michele Neylon > Blacknight Solutions > Hosting & Colocation, Brand Protection > http://www.blacknight.ie/ > Tel. 1850 927 280 > Intl. +353 (0) 59 9183072 > UK: 0870 163 0607 > Direct Dial: +353 (0)59 9183090 > Fax. +353 (0) 59 9164239 > > ------------------------ MailScanner list > ------------------------ To unsubscribe, email > jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) > and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From prandal at HEREFORDSHIRE.GOV.UK Tue Jan 10 16:41:03 2006 From: prandal at HEREFORDSHIRE.GOV.UK (Randal, Phil) Date: Thu Jan 12 21:31:41 2006 Subject: help with these errors Message-ID: > On Tue, 2006-01-10 at 11:28 -0500, Dimitri Yioulos wrote: > > Hello to all. > > > > After upgrading to the latest version of MS, following "errors" are > > reported by logwatch: > > > > Unrecognised keyword "spamassassinprefsfile" at line > 1335 : 29 Time(s) > > Closing down by-domain spam blacklist : 29 Time(s) > > Closing down by-domain spam whitelist : 29 Time(s) > Looks like you have a syntax error in your MailScanner.conf, > where are the spaces in that directive? > > SpamAssassin Prefs File = %etc-dir%/spam.assassin.prefs.conf > > Regards > Michael Baird Looks like upgrade_MailScanner_conf wasn't run properly. I see no such option in mu /etc/MailScanner/MailScanner.conf. Phil ---- Phil Randal Network Engineer Herefordshire Council Hereford, UK ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mike at TC3NET.COM Tue Jan 10 16:35:46 2006 From: mike at TC3NET.COM (Michael Baird) Date: Thu Jan 12 21:31:41 2006 Subject: help with these errors Message-ID: On Tue, 2006-01-10 at 11:28 -0500, Dimitri Yioulos wrote: > Hello to all. > > After upgrading to the latest version of MS, following "errors" are reported > by logwatch: > > Unrecognised keyword "spamassassinprefsfile" at line 1335 : 29 Time(s) > Closing down by-domain spam blacklist : 29 Time(s) > Closing down by-domain spam whitelist : 29 Time(s) Looks like you have a syntax error in your MailScanner.conf, where are the spaces in that directive? SpamAssassin Prefs File = %etc-dir%/spam.assassin.prefs.conf Regards Michael Baird ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From penguin at DHCP.NET Tue Jan 10 18:16:49 2006 From: penguin at DHCP.NET (A. Eijkhoudt) Date: Thu Jan 12 21:31:41 2006 Subject: Mail subject not getting modified Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Hi Matt & others, Small follow-up with more info: Detailed Spam Report = yes Include Scores In SpamAssassin Report = yes Always Include SpamAssassin Report = yes Multiple Headers = append There should be a full report in the headers but it's not there. Can anyone please shed some light on this, since there are a lot of spam E-mails getting through now. Kind regards, A. Eijkhoudt Arnim Eijkhoudt wrote: > Hi, > > I'd do that if it weren't enabled already! Which is why I haven't been > able to troubleshoot this myself, incidentally :P Here's a complete copy > of all the headers (excuse the spam): > > ---- SNIP > Return-Path: > Received: from STARRSTRUCKHOME.ironoh.adelphia.net > (winchester-motorola1--70-35-219-251.ironoh.adelphia.net [70.35.219.251]) > by www.valethosting.net (8.13.4/8.13.4) with SMTP id k0AAEHWD021224 > for ; Tue, 10 Jan 2006 11:14:23 +0100 > Date: Tue, 10 Jan 2006 11:14:18 +0100 > Message-Id: > From: Millie Costa > To: penguin@dhcp.net > Subject: Re: from you > MIME-Version: 1.0 > Content-Type: text/html; > charset="ISO-8859-1" > X-Priority: 3 (Normal) > X-Mailer: 0013$01a2ca59$094bea57@STARRSTRUCKHOME > X-MS-INFO: Contact the network management staff if you have questions > X-MS: **CLEAN** > X-MS-SPAM: not spam > X-MS-SPAM-SCORE: 44.90 > X-MS-FROM: > ----- SNIP > > I still don't understand why this is happening. I find the Return-Path's > and empty X-MS-FROM: headers a bit odd though. > > Kind regards, > > A. Eijkhoudt -- This message has been scanned for viruses and dangerous HTML content by Valethosting. Dit bericht is gecontroleerd op virussen en gevaarlijke HTML door Valethosting's MailScanner. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Denis.Beauchemin at USHERBROOKE.CA Tue Jan 10 18:55:37 2006 From: Denis.Beauchemin at USHERBROOKE.CA (Denis Beauchemin) Date: Thu Jan 12 21:31:41 2006 Subject: Mail subject not getting modified Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Just a dumb question: are you sure these headers come from YOUR MailScanner? I see some headers that my MS doesn't add... Denis A. Eijkhoudt wrote: > Hi Matt & others, > > Small follow-up with more info: > > Detailed Spam Report = yes > Include Scores In SpamAssassin Report = yes > Always Include SpamAssassin Report = yes > Multiple Headers = append > > There should be a full report in the headers but it's not there. Can > anyone please shed some light on this, since there are a lot of spam > E-mails getting through now. > > Kind regards, > > A. Eijkhoudt > > Arnim Eijkhoudt wrote: > >> Hi, >> >> I'd do that if it weren't enabled already! Which is why I haven't >> been able to troubleshoot this myself, incidentally :P Here's a >> complete copy of all the headers (excuse the spam): >> >> ---- SNIP >> Return-Path: >> Received: from STARRSTRUCKHOME.ironoh.adelphia.net >> (winchester-motorola1--70-35-219-251.ironoh.adelphia.net >> [70.35.219.251]) >> by www.valethosting.net (8.13.4/8.13.4) with SMTP id k0AAEHWD021224 >> for ; Tue, 10 Jan 2006 11:14:23 +0100 >> Date: Tue, 10 Jan 2006 11:14:18 +0100 >> Message-Id: >> From: Millie Costa >> To: penguin@dhcp.net >> Subject: Re: from you >> MIME-Version: 1.0 >> Content-Type: text/html; >> charset="ISO-8859-1" >> X-Priority: 3 (Normal) >> X-Mailer: 0013$01a2ca59$094bea57@STARRSTRUCKHOME >> X-MS-INFO: Contact the network management staff if you have questions >> X-MS: **CLEAN** >> X-MS-SPAM: not spam >> X-MS-SPAM-SCORE: 44.90 >> X-MS-FROM: >> ----- SNIP >> >> I still don't understand why this is happening. I find the >> Return-Path's and empty X-MS-FROM: headers a bit odd though. >> >> Kind regards, >> >> A. Eijkhoudt > > -- _ °v° Denis Beauchemin, analyste /(_)\ Université de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x2252 F: 819.821.8045 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From penguin at DHCP.NET Tue Jan 10 19:15:19 2006 From: penguin at DHCP.NET (A. Eijkhoudt) Date: Thu Jan 12 21:31:41 2006 Subject: Mail subject not getting modified Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Yes they are... I have modified mine to report X-MS-... instead of X-MailScanner- etc. It makes it easier for me to track what mine does in case an E-mail passes through several MailScanners on its way. --- From my config --- Mail Header = X-MS: Spam Header = X-MS-SPAM: Spam Score Header = X-MS-SPAM-SCORE: Information Header = X-MS-INFO: ---------------------- So I don't think that's the reason the mails are not being tagged correctly... Arnim. Denis Beauchemin wrote: > Just a dumb question: are you sure these headers come from YOUR > MailScanner? I see some headers that my MS doesn't add... > > Denis > A. Eijkhoudt wrote: > >> Hi Matt & others, >> >> Small follow-up with more info: >> >> Detailed Spam Report = yes >> Include Scores In SpamAssassin Report = yes >> Always Include SpamAssassin Report = yes >> Multiple Headers = append >> >> There should be a full report in the headers but it's not there. Can >> anyone please shed some light on this, since there are a lot of spam >> E-mails getting through now. >> >> Kind regards, >> >> A. Eijkhoudt >> >> Arnim Eijkhoudt wrote: >> >>> Hi, >>> >>> I'd do that if it weren't enabled already! Which is why I haven't >>> been able to troubleshoot this myself, incidentally :P Here's a >>> complete copy of all the headers (excuse the spam): >>> >>> ---- SNIP >>> Return-Path: >>> Received: from STARRSTRUCKHOME.ironoh.adelphia.net >>> (winchester-motorola1--70-35-219-251.ironoh.adelphia.net >>> [70.35.219.251]) >>> by www.valethosting.net (8.13.4/8.13.4) with SMTP id k0AAEHWD021224 >>> for ; Tue, 10 Jan 2006 11:14:23 +0100 >>> Date: Tue, 10 Jan 2006 11:14:18 +0100 >>> Message-Id: >>> From: Millie Costa >>> To: penguin@dhcp.net >>> Subject: Re: from you >>> MIME-Version: 1.0 >>> Content-Type: text/html; >>> charset="ISO-8859-1" >>> X-Priority: 3 (Normal) >>> X-Mailer: 0013$01a2ca59$094bea57@STARRSTRUCKHOME >>> X-MS-INFO: Contact the network management staff if you have questions >>> X-MS: **CLEAN** >>> X-MS-SPAM: not spam >>> X-MS-SPAM-SCORE: 44.90 >>> X-MS-FROM: >>> ----- SNIP >>> >>> I still don't understand why this is happening. I find the >>> Return-Path's and empty X-MS-FROM: headers a bit odd though. >>> >>> Kind regards, >>> >>> A. Eijkhoudt >> >> > > -- This message has been scanned for viruses and dangerous HTML content by Valethosting. Dit bericht is gecontroleerd op virussen en gevaarlijke HTML door Valethosting's MailScanner. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Tue Jan 10 19:20:47 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:41 2006 Subject: help with these errors Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Dimitri Yioulos wrote: >On Tuesday January 10 2006 11:41 am, Randal, Phil wrote: > > >>>On Tue, 2006-01-10 at 11:28 -0500, Dimitri Yioulos wrote: >>> >>> >>>>Hello to all. >>>> >>>>After upgrading to the latest version of MS, following "errors" are >>>>reported by logwatch: >>>> >>>> Unrecognised keyword "spamassassinprefsfile" at line >>>> >>>> >>>1335 : 29 Time(s) >>> >>> >>> >>>> Closing down by-domain spam blacklist : 29 Time(s) >>>> Closing down by-domain spam whitelist : 29 Time(s) >>>> >>>> >>>Looks like you have a syntax error in your MailScanner.conf, >>>where are the spaces in that directive? >>> >>>SpamAssassin Prefs File = %etc-dir%/spam.assassin.prefs.conf >>> >>>Regards >>>Michael Baird >>> >>> >>Looks like upgrade_MailScanner_conf wasn't run properly. I see no such >>option in mu /etc/MailScanner/MailScanner.conf. >> >>Phil >>---- >> >> > >I've run upgrade_MailScanner_conf with each version upgrade (including this >one) without incident. Is the line "SpamAssassin Prefs File = >%etc-dir%/spam.assassin.prefs.conf" deprecated? > > > Yes. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From marcel-ml at IRC-ADDICTS.DE Tue Jan 10 19:22:22 2006 From: marcel-ml at IRC-ADDICTS.DE (Marcel Blenkers) Date: Thu Jan 12 21:31:41 2006 Subject: Question about start.. Message-ID: Hi there, i am using OpenSuse (SuSE10) with sendmail. Sendmail version 8.13.4 After a reboot of the System, within the Mail-Log i can find a line like: Jan 10 20:17:20 s23 sendmail-in[4084]: unable to write pid to /var/run/sendmail.pid: file in use by another process but, connects via port 25 are possible. After typing: rcMailScanner restart there is the following within the Maillog: Jan 10 20:19:07 s23 sendmail-client[4874]: starting daemon (8.13.4): persistent-queueing@00:01:00 and no connects on port 25 are possible. Is there a way to change this behaviour? Marcel ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Tue Jan 10 19:27:07 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:41 2006 Subject: Question about start.. Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Have you disabled the sendmail init.d script? The install.sh in MailScanner tells you what to type at the end. Marcel Blenkers wrote: >Hi there, > >i am using OpenSuse (SuSE10) with sendmail. > Sendmail version 8.13.4 > >After a reboot of the System, within the Mail-Log i can find a line like: > >Jan 10 20:17:20 s23 sendmail-in[4084]: unable to write pid to >/var/run/sendmail.pid: file in use by another process > >but, connects via port 25 are possible. >After typing: rcMailScanner restart there is the following within the >Maillog: > >Jan 10 20:19:07 s23 sendmail-client[4874]: starting daemon (8.13.4): >persistent-queueing@00:01:00 > > >and no connects on port 25 are possible. > >Is there a way to change this behaviour? > >Marcel > >------------------------ MailScanner list ------------------------ >To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >'leave mailscanner' in the body of the email. >Before posting, read the Wiki (http://wiki.mailscanner.info/) and >the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > >Support MailScanner development - buy the book off the website! > > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From steve.swaney at fsl.com Tue Jan 10 19:42:13 2006 From: steve.swaney at fsl.com (Stephen Swaney) Date: Thu Jan 12 21:31:41 2006 Subject: Question about start.. Message-ID: > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Marcel Blenkers > Sent: Tuesday, January 10, 2006 2:22 PM > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Question about start.. > > Hi there, > > i am using OpenSuse (SuSE10) with sendmail. > Sendmail version 8.13.4 > > After a reboot of the System, within the Mail-Log i can find a line like: > > Jan 10 20:17:20 s23 sendmail-in[4084]: unable to write pid to > /var/run/sendmail.pid: file in use by another process > > but, connects via port 25 are possible. > After typing: rcMailScanner restart there is the following within the > Maillog: > > Jan 10 20:19:07 s23 sendmail-client[4874]: starting daemon (8.13.4): > persistent-queueing@00:01:00 > > > and no connects on port 25 are possible. > > Is there a way to change this behaviour? > > Marcel Try stopping MailScanner. Kill all sendmail processes and restart MailScanner. Also make sure that sendmail is not starting from an init script: chkconfig sendmail off The MailScanner init script starts and stops sendmail so the sendmail init script should never be enabled. Hope this helps, Steve Stephen Swaney Fort Systems Ltd. stephen.swaney@fsl.com www.fsl.com ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From steve.swaney at fsl.com Tue Jan 10 20:41:30 2006 From: steve.swaney at fsl.com (Stephen Swaney) Date: Thu Jan 12 21:31:41 2006 Subject: MailScanner and sendmail - Problems Message-ID: > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Marcel Blenkers > Sent: Tuesday, January 10, 2006 3:32 PM > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: MailScanner and sendmail - Problems > > Damn, > > MailServer blocked ML. > ok. > > But found the replies on the weblist. > > Julian, Stephen: > > sendmail is not started. > Only MailScanner is started with init-script. > > Tried it, with not starting MailScanner and sendmail. > Rebooted, then started MailScanner. > > Still the same. > > > Sorry > > Marcel > Are there any sendmail processes running after you stop sendmail? Steve Stephen Swaney Fort Systems Ltd. stephen.swaney@fsl.com www.fsl.com ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From marcel-ml at IRC-ADDICTS.DE Tue Jan 10 20:40:34 2006 From: marcel-ml at IRC-ADDICTS.DE (Marcel Blenkers) Date: Thu Jan 12 21:31:41 2006 Subject: MailScanner and sendmail - Problems Message-ID: Hi Michele, no i did not replaced the ini-files. I did disable the ini-file for sendmail on startup, and enabled the MailScanner one. as stated before, i even tried to reboot the maschine without any type of sendmail or MailScanner, and then started MailScanner with rcMailScanner. And still the same bugs then i tried downgrading. still the same. Marcel ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From marcel-ml at IRC-ADDICTS.DE Tue Jan 10 20:31:58 2006 From: marcel-ml at IRC-ADDICTS.DE (Marcel Blenkers) Date: Thu Jan 12 21:31:41 2006 Subject: MailScanner and sendmail - Problems Message-ID: Damn, MailServer blocked ML. ok. But found the replies on the weblist. Julian, Stephen: sendmail is not started. Only MailScanner is started with init-script. Tried it, with not starting MailScanner and sendmail. Rebooted, then started MailScanner. Still the same. Sorry Marcel ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From michele at BLACKNIGHT.IE Tue Jan 10 20:31:17 2006 From: michele at BLACKNIGHT.IE (Michele Neylon:: Blacknight.ie) Date: Thu Jan 12 21:31:41 2006 Subject: MailScanner and sendmail - Problems Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Marcel Blenkers wrote: > Hi there, > > i am trying to use the latest Version of MailScanner on SuSE10. > This looks very similar to an issue someone else posted about earlier this evening... Have you replaced the sendmail init file with the MailScanner one? -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From marcel-ml at IRC-ADDICTS.DE Tue Jan 10 20:24:44 2006 From: marcel-ml at IRC-ADDICTS.DE (Marcel Blenkers) Date: Thu Jan 12 21:31:41 2006 Subject: MailScanner and sendmail - Problems Message-ID: Hi there, i am trying to use the latest Version of MailScanner on SuSE10. Starting MailScanner does not really work: rcMailScanner start Jan 10 21:21:29 s23 sendmail-in[5024]: starting daemon (8.13.4): SMTP Jan 10 21:21:29 s23 sendmail-client[5027]: starting daemon (8.13.4): persistent-queueing@00:01:00 Jan 10 21:21:29 s23 sendmail-out[5031]: starting daemon (8.13.4): queueing@00:30:00 Jan 10 21:21:29 s23 sendmail-out[5031]: unable to write pid to /var/run/sendmail.pid: file in use by another process Jan 10 21:21:31 s23 MailScanner[5051]: MailScanner E-Mail Virus Scanner version 4.49.7 starting... rcMailScanner stop does kill MailScanner, but there is still an istance of sendmail. The PID-File contains of the following: 5024 /usr/sbin/sendmail -OPrivacyOptions=noetrn -ODeliveryMode=queueonly -OQueueDirectory=/var/spool/mqueue.in -L sendmail-in -Am -bd -om on a working system, the pid-file contains of this: 3310 /usr/sbin/sendmail -L sendmail-out -Am -q30m -om i am running the following: Sendmail: Sendmail version 8.13.4, config V10/Berkeley SuSE 10.0 Linux s23 2.6.13-15.7-default #1 Tue Nov 29 14:32:29 UTC 2005 i686 i686 i386 GNU/Linux MailScanner: Linux s23 2.6.13-15.7-default #1 Tue Nov 29 14:32:29 UTC 2005 i686 i686 i386 GNU/Linux This is SUSE LINUX 10.0 (i586) This is Perl version 5.008007 (5.8.7) This is MailScanner version 4.49.7 Module versions are: 1.00 AnyDBM_File 1.16 Archive::Zip 1.04 Carp 1.119 Convert::BinHex 1.00 DirHandle 1.05 Fcntl 2.73 File::Basename 2.08 File::Copy 2.01 FileHandle 1.06 File::Path 0.16 File::Temp 1.32 HTML::Entities 3.48 HTML::Parser 2.35 HTML::TokeParser 1.21 IO 1.11 IO::File 1.123 IO::Pipe 1.71 Mail::Header 3.05 MIME::Base64 5.417 MIME::Decoder 5.417 MIME::Decoder::UU 5.417 MIME::Head 5.417 MIME::Parser 3.03 MIME::QuotedPrint 5.417 MIME::Tools 0.11 Net::CIDR 1.08 POSIX 1.77 Socket 0.06 Sys::Syslog 1.02 Time::localtime Optional module versions are: 0.17 Convert::TNEF 1.814 DB_File 1.10 Digest 1.01 Digest::HMAC 2.36 Digest::MD5 2.10 Digest::SHA1 missing Inline missing Mail::ClamAV 3.001000 Mail::SpamAssassin 1.998 Mail::SPF::Query 0.18 Net::CIDR::Lite 0.55 Net::DNS 0.33 Net::LDAP 1.80 Parse::RecDescent missing SAVI 1.4 Sys::Hostname::Long 2.56 Test::Harness 0.62 Test::Simple 1.95 Text::Balanced 1.35 URI Any Ideas are welcome.. Thanks in advance Marcel ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From marcel-ml at IRC-ADDICTS.DE Tue Jan 10 20:53:04 2006 From: marcel-ml at IRC-ADDICTS.DE (Marcel Blenkers) Date: Thu Jan 12 21:31:41 2006 Subject: MailScanner and sendmail - Problems Message-ID: Hi Stephen, > > > > Are there any sendmail processes running after you stop sendmail? > i tried the following: rcMailScanner start ps -aef | grep -i mail Tasks are running rcMailScanner stop ps -aef | grep -i mail root 5031 1 0 21:21 ? 00:00:00 sendmail: Queue runner@00:30:00 for /var/spool/mqueue killed this task then i tried: rcsendmail start ps -aef | grep -i mail root 5199 1 0 21:48 ? 00:00:00 sendmail: accepting connections mail 5204 1 0 21:48 ? 00:00:00 sendmail: Queue control mail 5205 5204 0 21:48 ? 00:00:00 sendmail: running queue: /var/spool/clientmqueue rcsendmail stop no sendmail-task this is what i do see on the running maschine after rcMailScanner start marcel:/etc # ps -aef | grep -i mail root 3841 1 0 21:50 ? 00:00:00 sendmail: accepting connections mail 3844 1 0 21:50 ? 00:00:00 sendmail: Queue control mail 3846 3844 0 21:50 ? 00:00:00 sendmail: running queue: /var/spool/clientmqueue root 3848 1 0 21:50 ? 00:00:00 sendmail: Queue runner@00:30:00 for /var/spool/mqueue root 3869 1 0 21:50 ? 00:00:00 /usr/bin/perl -I/usr/lib/MailScanner /usr/sbin/MailScanner /etc/MailScanner/MailScanner.conf root 3870 3869 15 21:50 ? 00:00:08 /usr/bin/perl -I/usr/lib/MailScanner /usr/sbin/MailScanner /etc/MailScanner/MailScanner.conf root 3873 3869 18 21:50 ? 00:00:08 /usr/bin/perl -I/usr/lib/MailScanner /usr/sbin/MailScanner /etc/MailScanner/MailScanner.conf root 3877 3141 0 21:51 pts/2 00:00:00 grep -i mail marcel:/etc # and this on the not really working maschine: s23:/var/run # ps -aef | grep -i mail root 5250 1 0 21:51 ? 00:00:00 sendmail: accepting connections mail 5253 1 0 21:51 ? 00:00:00 sendmail: Queue control mail 5254 5253 0 21:51 ? 00:00:00 sendmail: running queue: /var/spool/clientmqueue root 5257 1 0 21:51 ? 00:00:00 sendmail: Queue runner@00:30:00 for /var/spool/mqueue root 5276 1 0 21:51 ? 00:00:00 MailScanner: master waiting for children, sleeping root 5277 5276 3 21:51 ? 00:00:02 MailScanner: waiting for messages root 5281 5276 4 21:51 ? 00:00:02 MailScanner: waiting for messages root 5284 4715 0 21:52 pts/0 00:00:00 grep -i mail s23:/var/run # hope maybe this helps if needed i could grant access to the maschine, as this maschine is just in the state of setup. Greetings Marcel ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From carl.andrews at CRACKERBARREL.COM Tue Jan 10 21:58:00 2006 From: carl.andrews at CRACKERBARREL.COM (Carl Andrews) Date: Thu Jan 12 21:31:41 2006 Subject: [Fwd: [SA18368] Microsoft Outlook / Exchange TNEF Decoding Arbitrary Code Execution Vulnerability] Message-ID: Anyone blocking these? My /etc/mime-magic does not have the ms/tnef and I can not find a winmail.dat file. Can anyone tell me what I need to add to mime-magic so I can put these in my filetype.rules ? Thanks! Carl -------- Forwarded Message -------- From: Secunia Security Advisories To: carl.andrews@crackerbarrel.com Subject: [SA18368] Microsoft Outlook / Exchange TNEF Decoding Arbitrary Code Execution Vulnerability Date: 10 Jan 2006 21:02:44 -0000 TITLE: Microsoft Outlook / Exchange TNEF Decoding Arbitrary Code Execution Vulnerability SECUNIA ADVISORY ID: SA18368 VERIFY ADVISORY: http://secunia.com/advisories/18368/ CRITICAL: Highly critical IMPACT: System access WHERE: >From remote SOFTWARE: Microsoft Exchange 2000 Enterprise Server http://secunia.com/product/42/ Microsoft Exchange 5 http://secunia.com/product/177/ Microsoft Exchange 5.5 http://secunia.com/product/148/ Microsoft Exchange Server 2000 http://secunia.com/product/41/ Microsoft Outlook 2000 http://secunia.com/product/33/ Microsoft Outlook 2002 http://secunia.com/product/34/ Microsoft Outlook 2003 http://secunia.com/product/3292/ DESCRIPTION: A vulnerability has been reported in Microsoft Outlook / Exchange, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to boundary error when decoding the Transport Neutral Encapsulation Format (TNEF) MIME attachment. This can be exploited to execute arbitrary code when the user opens or previews a specially crafted TNEF email message or when the Microsoft Exchange Server Information Store processes the message. SOLUTION: Apply patches. -- Microsoft Office 2000 Service Pack 3 -- Microsoft Outlook 2000: http://www.microsoft.com/downloads/details.aspx?FamilyId=64D0336D-F962-4AB1-A724-9F6BA2108CB9 Microsoft Office 2000 MultiLanguage Packs: http://www.microsoft.com/downloads/details.aspx?FamilyId=2C0FA7C7-91AA-49B4-9731-9E83E3E0823D Microsoft Outlook 2000 English MultiLanguage Packs: http://www.microsoft.com/downloads/details.aspx?FamilyId=2C0FA7C7-91AA-49B4-9731-9E83E3E0823D -- Microsoft Office XP Service Pack 3 -- Microsoft Outlook 2002: http://www.microsoft.com/downloads/details.aspx?FamilyId=9A85CEBB-0D9A-465D-A4BC-AF501562772D Microsoft Office XP Multilingual User Interface Packs: http://www.microsoft.com/downloads/details.aspx?FamilyId=CCA9399A-6DA3-4163-8398-C58DC328182B -- Microsoft Office 2003 Service Pack 1 and Service Pack 2 -- Microsoft Outlook 2003: http://www.microsoft.com/downloads/details.aspx?FamilyId=1D156043-B041-4305-8442-3C4E3B832788 Microsoft Office 2003 Multilingual User Interface Packs: http://www.microsoft.com/downloads/details.aspx?FamilyId=D69554AD-196F-4789-91E5-B2A753EED854 Microsoft Office 2003 Language Interface Packs: http://www.microsoft.com/downloads/details.aspx?FamilyID=db080de8-8193-4c32-9019-9980ecd6874a -- Microsoft Exchange Server -- Microsoft Exchange Server 5.0 Service Pack 2: http://www.microsoft.com/downloads/details.aspx?FamilyId=0A8DF1C3-ABF9-4A21-9B49-81FA362B251F Microsoft Exchange Server 5.5 Service Pack 4: http://www.microsoft.com/downloads/details.aspx?FamilyId=EC6BD30E-12DE-4CA1-9432-D2E73AF62427 Microsoft Exchange 2000 Server Pack 3 (with the Exchange 2000 Post-Service Pack 3 Update Rollup of August 2004): http://www.microsoft.com/downloads/details.aspx?FamilyId=372FF07F-C3CA-4301-8559-9B90344EDC02 Note: Microsoft Exchange Server 2003 SP1/SP2 are not affected. PROVIDED AND/OR DISCOVERED BY: The vendor credits John Heasman and Mark Litchfield of NGS Software. ORIGINAL ADVISORY: MS06-003 (KB902412): http://www.microsoft.com/technet/security/Bulletin/MS06-003.mspx ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=carl.andrews%40crackerbarrel.com ---------------------------------------------------------------------- ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From lbcadmin at GMAIL.COM Tue Jan 10 22:15:03 2006 From: lbcadmin at GMAIL.COM (Information Services) Date: Thu Jan 12 21:31:41 2006 Subject: Hard Lock Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Once again one of my mailscanner systems locked up. I had quite a scare with this one, and I am sure I will be in during the weekend building another system for when this one kills over. This time I had to take out the RAM and replug the HDs in order to it to get a sense of itself, but I am wondering if it has something to do with the powerleaps we have in the Dell Optiplex G1s. Could they be overheating and causing the lockups? If this is possible that would explain why it booted after I messed with the other hardware. But this is what I retried from the /var/log/messages. Better information, but not something I understand. Can you make sense of it?? --------------------------- Jan 10 13:05:03 wks-lin9 crond(pam_unix)[11999]: session closed for user root Jan 10 13:05:15 wks-lin9 crond(pam_unix)[12000]: session closed for user root Jan 10 13:05:22 wks-lin9 crond(pam_unix)[11473]: session closed for user root Jan 10 13:06:49 wks-lin9 smbd[12451]: [2006/01/10 13:06:49, 0] lib/util_sock.c:get_peer_addr(1000) Jan 10 13:06:49 wks-lin9 smbd[12451]: getpeername failed. Error was Transport endpoint is not connected Jan 10 13:06:49 wks-lin9 smbd[12451]: [2006/01/10 13:06:49, 0] lib/util_sock.c:get_peer_addr(1000) Jan 10 13:06:49 wks-lin9 smbd[12451]: getpeername failed. Error was Transport endpoint is not connected Jan 10 13:06:49 wks-lin9 smbd[12451]: [2006/01/10 13:06:49, 0] lib/util_sock.c:write_socket_data(430) Jan 10 13:06:49 wks-lin9 smbd[12451]: write_socket_data: write failure. Error = Connection reset by peer Jan 10 13:06:49 wks-lin9 smbd[12451]: [2006/01/10 13:06:49, 0] lib/util_sock.c:write_socket(455) Jan 10 13:06:49 wks-lin9 smbd[12451]: write_socket: Error writing 4 bytes to socket 24: ERRNO = Connection reset by peer Jan 10 13:06:49 wks-lin9 smbd[12451]: [2006/01/10 13:06:49, 0] lib/util_sock.c:send_smb(647) Jan 10 13:06:49 wks-lin9 smbd[12451]: Error writing 4 bytes to client. -1. (Connection reset by peer) Jan 10 13:06:50 wks-lin9 winbindd[2518]: [2006/01/10 13:06:50, 0] tdb/tdbutil.c:tdb_log(725) Jan 10 13:06:50 wks-lin9 winbindd[2518]: tdb(/var/cache/samba/netsamlogon_cache.tdb): rec_free_read bad magic 0x42424242 at offset=7252 ------------------- that is the last information posted to messages before the boot up information is written. On 1/9/06, Information Services wrote: I am going to check into the HDs. All three systems have the exact same HDs in them. All the same sw is running on them also, except for squid on the two mailscanner boxes. I will also try the suggestions posted in a previous reply to this also. I definitely need to resolve this issue. I don't want my production systems to be locking up, especially not at 0200 hours. On 1/7/06, Glenn Steen wrote: On 06/01/06, Information Services wrote: (snip) > clamav-0.87 Update cöam asap. (snip) > > First, > > When I reboot the systems, it takes about 20 minutes before the login > screen appears. I am able to shell into the systems themselves and work on > them, but I would like to resolve why they don't bring the login screen up > right away after the boot process. The GUI either sets at the blank screen > with the black curser outlined in white and is an 'X' symbol, or at the > progress bar at 100 percent until it finally shows the login screen. Assuming you are referring to a graphical logon screen, this is usually a display manager for X.... Which in turn usually means that extreme slowness is due to a network misconfiguration. Having no valid name lookup (in /etc/hosts) for the loopback IF address usually has this effect... So check that all names (including loopback) resolve as they should. If you have it configured for a X font sever, check that it is running, and that you have no network issues in reaching it. > > Issue 2: > > I have been havin problems with both servers locking up. One server more > than the other. > (snip) Nothing jumps out and grabs ones attention.... So suspect the usual things: HW and kernel. One is easy to change.... so why not try your hand on doing a "custom kernel";-). since both machines are more or less of an age, and fairly similar in makeup..... shoddy drivers come to mind, as well as diverse age-related cr*p. -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives ( http://www.jiscmail.ac.uk/lists/mailscanner.html ). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From lbcadmin at GMAIL.COM Tue Jan 10 22:43:45 2006 From: lbcadmin at GMAIL.COM (Information Services) Date: Thu Jan 12 21:31:41 2006 Subject: exe extension in url Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Thanks for the information. Also, just so I can be clear, will there be more RDJ rules we can be expecting that cover this, and its variants? (information based on the conversation between James and Martin) On 1/9/06, Matt Kettler wrote: James Gray wrote: > I have written a number of SpamAssassin rules that increase the score for > messages that link to executables (exe/dll/bat/etc... but NOT ".com"...think > about it :P). Unfortunately some of them also hit legitimate websites (like > www.ht.com.au which uses a program called "xworks.exe" for its dynamic > content). Suggestion: use a $ to look for uris that END in .exe, instead of just looking for URIs that contain them. Most dynamic content sites using exe have parameters passed after it, such as the above site which ends in "/xworks.exe?M" Something like this would work: uri L_URI_EXE /\/.+\.exe$/i score L_URI_EXE 0.1 describe L_URI_EXE Contains link to a .exe file > > > All my rules are available at http://files.grayonline.id.au - all the URL/URI > rules are in the "local_uri.cf" which is in the tar ball. The rest of the > instructions are on the website. > Erm, you don't seem to have them in the 12/02/2005 tarball, which is the latest that's up there. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives ( http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ssilva at SGVWATER.COM Tue Jan 10 22:55:10 2006 From: ssilva at SGVWATER.COM (Scott Silva) Date: Thu Jan 12 21:31:41 2006 Subject: Hard Lock Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Information Services spake the following on 1/10/2006 2:15 PM: > Once again one of my mailscanner systems locked up. I had quite a scare > with this one, and I am sure I will be in during the weekend building > another system for when this one kills over. This time I had to take > out the RAM and replug the HDs in order to it to get a sense of itself, > but I am wondering if it has something to do with the powerleaps we have > in the Dell Optiplex G1s. Could they be overheating and causing the > lockups? If this is possible that would explain why it booted after I > messed with the other hardware. But this is what I retried from the > /var/log/messages. Better information, but not something I understand. > Can you make sense of it?? > Do you have the original processors? If so, swap out the powerleap and see if problem goes away. Also could see if cooling fans are slowing down/stopped, or accumulation of dust in fins. -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From drew at THEMARSHALLS.CO.UK Tue Jan 10 23:33:41 2006 From: drew at THEMARSHALLS.CO.UK (Drew Marshall) Date: Thu Jan 12 21:31:41 2006 Subject: #!/bin/bash Message-ID: On 10 Jan 2006, at 23:29, Nerijus Baliunas wrote: > Hello, > > Some scripts (update_virus_scanners.cron, update_phishing_sites.cron, > check_MailScanner.cron, update_virus_scanners) from tar.gz > distribution > have #!/bin/bash at the first line, and I have to change it to > #!/usr/local/bin/bash on my FreeBSD system. If they are not using > any bash'isms it would be better to change all #!/bin/bash to #!/ > bin/sh. Did you install from the ports tree? This is all fixed in there automagically. Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From nerijus at USERS.SOURCEFORGE.NET Tue Jan 10 23:42:22 2006 From: nerijus at USERS.SOURCEFORGE.NET (Nerijus Baliunas) Date: Thu Jan 12 21:31:41 2006 Subject: #!/bin/bash Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Tue, 10 Jan 2006 23:33:41 +0000 Drew Marshall wrote: > > have #!/bin/bash at the first line, and I have to change it to > > #!/usr/local/bin/bash on my FreeBSD system. If they are not using > > any bash'isms it would be better to change all #!/bin/bash to #!/ > > bin/sh. > > Did you install from the ports tree? This is all fixed in there > automagically. No, but I want it to be fixed in distribution (and then it will be one less patch in ports :). Regards, Nerijus ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Dave Wed Jan 11 00:23:48 2006 From: Dave (Dave) Date: Thu Jan 12 21:31:41 2006 Subject: [customer: RE: FW: test tues] Message-ID: The MailScanner Lines were not suppose to show up! I have placed scan.messages.rules in the rules directory and with the correct no statement and still MailScanner is scannong mail and yet and exclusion statement has been made. Any Explanation? ----- Forwarded message from ----- X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org Date: Tue, 10 Jan 2006 17:10:38 -0700 From: customer Subject: RE: FW: test tues In-reply-to: <20060110235810.GC5904@doctor.nl2k.ab.ca> To: root@nk.ca X-MIMEOLE: Produced By Microsoft MimeOLE V6.00.2900.2180 X-Mailer: Microsoft Office Outlook 11 Thread-index: AcYWQbYS/k+bFbCKR+Oc/1Qv8C3hkQAAbIcg X-Virus-Scanned: ClamAV version 0.88, clamav-milter version 0.87 on doctor.nl2k.ab.ca X-Virus-Status: Clean X-netknowJan2006-MailScanner-Information: Please contact the ISP for more information X-netknowJan2006-MailScanner: Found to be clean X-netknowJan2006-MailScanner-From: customer Return-Path: Received: from doctor.nl2k.ab.ca (smmsp@localhost.nl2k.ab.ca [127.0.0.1]) by doctor.nl2k.ab.ca (8.13.5/8.13.5) with ESMTP id k0ANwBCA008085 for ; Tue, 10 Jan 2006 16:58:11 -0700 (MST) X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org Received: (from root@localhost) by doctor.nl2k.ab.ca (8.13.5/8.13.5/Submit) id k0ANwAm4008083 for customer; Tue, 10 Jan 2006 16:58:10 -0700 (MST) Date: Tue, 10 Jan 2006 16:58:10 -0700 From: "Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem" To: customer Subject: Re: FW: test tues Message-ID: <20060110235810.GC5904@doctor.nl2k.ab.ca> Reply-To: root@nk.ca, customer References: <000801c61628$0856d890$b700a8c0@mac> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <000801c61628$0856d890$b700a8c0@mac> User-Agent: Mutt/1.5.9i X-Virus-Scanned: ClamAV version 0.88, clamav-milter version 0.87 on doctor.nl2k.ab.ca X-Virus-Status: Clean X-netknowJan2006-MailScanner-Information: Please contact the ISP for more information X-netknowJan2006-MailScanner: Found to be clean X-netknowJan2006-MailScanner-From: doctor@doctor.nl2k.ab.ca X-UIDL: AO`!!>/,#!C/h!!iO4!! -----Original Message----- From: Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem [mailto:root@doctor.nl2k.ab.ca] Sent: January 10, 2006 16:58 PM To: customer Subject: Re: FW: test tues This should be correct now. Please send me headers from this one. On Tue, Jan 10, 2006 at 01:54:21PM -0700, customer wrote: > Return-Path: > Received: from wproxy.gmail.com (customer) > by doctor.nl2k.ab.ca (8.13.5/8.13.5) with ESMTP id k0AJlNgB020946 > for ; Tue, 10 Jan 2006 12:47:24 -0700 (MST) > X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org > Received: by wproxy.gmail.com with SMTP id i24so2908959wra > for ; Tue, 10 Jan 2006 11:47:23 -0800 (PST) > DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; > s=beta; d=gmail.com; > > h=received:message-id:date:from:to:subject:mime-version:content-type; > > b=i5n7W4F7v7zvZdtGqf0mqPRoQanauxlz4/69a76wcWS3MKkOjI2wHnVxsc5lyRuq3sbMkqLQe4 > nUOYh6DlFamCkAVwyeM/BVHjBJToIA3R5X7j5YvA4NSTfYnjpbh8b6iE/K7Dr0bZ8VMgrm+Zc4Nc > MDyn7eXp28hg2DSqTItEo= > Received: by 10.54.67.10 with SMTP id p10mr5662418wra; > Tue, 10 Jan 2006 11:47:22 -0800 (PST) > Received: by 10.54.102.5 with HTTP; Tue, 10 Jan 2006 11:47:22 -0800 (PST) > Message-ID: <7266dd760601101147t486c71f7l475df69e699ed986@mail.gmail.com> > Date: Tue, 10 Jan 2006 12:47:22 -0700 > From: customer > To: customer > Subject: test tues > MIME-Version: 1.0 > Content-Type: multipart/alternative; > boundary="----=_Part_31960_20255549.1136922442864" > X-Virus-Scanned: ClamAV version 0.88, clamav-milter version 0.87 on > doctor.nl2k.ab.ca > X-Virus-Status: Clean > X-netknowJan2006-MailScanner-Information: Please contact the ISP for more > information > X-netknowJan2006-MailScanner: Found to be clean > X-netknowJan2006-MailScanner-SpamScore: s > X-netknowJan2006-MailScanner-From: customer > X-UIDL: &JW"!)F&"!LCS"!>6c!! > > > -----Original Message----- > From: Customer [mailto:customer] > Sent: January 10, 2006 12:47 PM > To: customer > Subject: test tues > > test tyues > -- > This message has been scanned for viruses and > dangerous content by MailScanner , and is > believed to be clean. > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > Thank you customer. I can -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ----- End forwarded message ----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From nerijus at USERS.SOURCEFORGE.NET Tue Jan 10 23:29:33 2006 From: nerijus at USERS.SOURCEFORGE.NET (Nerijus Baliunas) Date: Thu Jan 12 21:31:41 2006 Subject: #!/bin/bash Message-ID: Hello, Some scripts (update_virus_scanners.cron, update_phishing_sites.cron, check_MailScanner.cron, update_virus_scanners) from tar.gz distribution have #!/bin/bash at the first line, and I have to change it to #!/usr/local/bin/bash on my FreeBSD system. If they are not using any bash'isms it would be better to change all #!/bin/bash to #!/bin/sh. Regards, Nerijus ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mkettler at EVI-INC.COM Wed Jan 11 00:13:09 2006 From: mkettler at EVI-INC.COM (Matt Kettler) Date: Thu Jan 12 21:31:41 2006 Subject: #!/bin/bash Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Nerijus Baliunas wrote: > On Tue, 10 Jan 2006 23:33:41 +0000 Drew Marshall wrote: > > >>>have #!/bin/bash at the first line, and I have to change it to >>>#!/usr/local/bin/bash on my FreeBSD system. If they are not using >>>any bash'isms it would be better to change all #!/bin/bash to #!/ >>>bin/sh. >> >>Did you install from the ports tree? This is all fixed in there >>automagically. > > > No, but I want it to be fixed in distribution (and then it will be one less > patch in ports :). > I would tend to agree.. if you're not really using any bash features, you should be using /bin/sh for the scripts. It makes things so much more portable. Fixing it in the ports tree solves the symptoms, but there's a more general problem here of "upping the bar higher than is required". I make these three points: 1) Pretty much everybody has a /bin/sh. This is a POSIX standard, and nearly every *nix out there conforms to this part of the standard. Sure there are a few exceptions, but these are very rare. 2) There is no standard that specifies bash configuration that's common to different major *nix flavors (Linux, *BSD, Solaris, etc). For example LSB might specify bash, but that only applies to Linux variants. 3) Everybody who has bash has sh, since bash supports being invoked as sh. However, not everybody who has sh has bash. (Yes, there are folks out there who consider bash an optional add-on, not a core OS feature, hence it appearing in /usr/bin.) ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From devonharding at GMAIL.COM Wed Jan 11 00:24:54 2006 From: devonharding at GMAIL.COM (Devon Harding) Date: Thu Jan 12 21:31:41 2006 Subject: Beta 4.50.5 released Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] hmm.. Can't seem to locate the bayes_mysql.sql file on my FC3 system. How can I get it? On 1/10/06, Drew Marshall < drew@themarshalls.co.uk> wrote: On Tue, January 10, 2006 12:22, Devon Harding wrote: > What is the procedure in converting bayes to MYSQL? I'm getting too much > Spamassassin time outs. It's in the wiki http://wiki.mailscanner.info/doku.php?id=documentation:anti_spam:spamassassin:b yes:sql will do it! Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/ ) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From devonharding at GMAIL.COM Wed Jan 11 00:39:11 2006 From: devonharding at GMAIL.COM (Devon Harding) Date: Thu Jan 12 21:31:41 2006 Subject: Beta 4.50.5 released Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Got it! Download the SA source from apache.org On 1/10/06, Devon Harding wrote: hmm.. Can't seem to locate the bayes_mysql.sql file on my FC3 system. How can I get it? On 1/10/06, Drew Marshall < drew@themarshalls.co.uk> wrote: On Tue, January 10, 2006 12:22, Devon Harding wrote: > What is the procedure in converting bayes to MYSQL? I'm getting too much > Spamassassin time outs. It's in the wiki http://wiki.mailscanner.info/doku.php?id=documentation:anti_spam:spamassassin:b yes:sql will do it! Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki ( http://wiki.mailscanner.info/ ) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mailscanner at ecs.soton.ac.uk Wed Jan 11 04:10:51 2006 From: mailscanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:41 2006 Subject: #!/bin/bash Message-ID: On 11 Jan 2006, at 00:13, Matt Kettler wrote: > Nerijus Baliunas wrote: >> On Tue, 10 Jan 2006 23:33:41 +0000 Drew Marshall >> wrote: >> >> >>>> have #!/bin/bash at the first line, and I have to change it to >>>> #!/usr/local/bin/bash on my FreeBSD system. If they are not using >>>> any bash'isms it would be better to change all #!/bin/bash to #!/ >>>> bin/sh. >>> >>> Did you install from the ports tree? This is all fixed in there >>> automagically. >> >> >> No, but I want it to be fixed in distribution (and then it will be >> one less >> patch in ports :). >> > > I would tend to agree.. if you're not really using any bash > features, you should > be using /bin/sh for the scripts. It makes things so much more > portable. > > Fixing it in the ports tree solves the symptoms, but there's a more > general > problem here of "upping the bar higher than is required". > > I make these three points: > > 1) Pretty much everybody has a /bin/sh. This is a POSIX standard, > and nearly > every *nix out there conforms to this part of the standard. Sure > there are a few > exceptions, but these are very rare. > > 2) There is no standard that specifies bash configuration that's > common to > different major *nix flavors (Linux, *BSD, Solaris, etc). For > example LSB might > specify bash, but that only applies to Linux variants. > > 3) Everybody who has bash has sh, since bash supports being invoked > as sh. > However, not everybody who has sh has bash. (Yes, there are folks > out there who > consider bash an optional add-on, not a core OS feature, hence it > appearing in > /usr/bin.) I entirely agree with you. I will have to go through the scripts that have this and try to check that they don't have any bash-isms that I know of. The only one that springs to mind is export VARIABLE=value which I will need to change to VARIABLE=value export VARIABLE What else should I be looking for? I tend to write for whatever version of sh happens to be on the system I'm writing on at the time. Bad practice, I know :-( -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mailscanner at ecs.soton.ac.uk Wed Jan 11 04:13:45 2006 From: mailscanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:41 2006 Subject: MailScanner and sendmail - Problems Message-ID: All I can contribute at this point is that I have specifically tested MailScanner on SuSE10 and if you follow the instructions correctly it works fine. Not that that helps you much... On 10 Jan 2006, at 20:31, Michele Neylon:: Blacknight.ie wrote: > Marcel Blenkers wrote: >> Hi there, >> >> i am trying to use the latest Version of MailScanner on SuSE10. >> -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mailscanner at ecs.soton.ac.uk Wed Jan 11 05:00:47 2006 From: mailscanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:42 2006 Subject: [Fwd: [SA18368] Microsoft Outlook / Exchange TNEF Decoding Arbitrary Code Execution Vulnerability] Message-ID: That one got me very worried. I checked to see that blocking tnef master-files worked, and it appeared not to. So loads of debugging later, I finally find I had commented out the filename.rules.conf and filetype.rules.conf settings in MailScanner.conf. Grrrr.... but also Phew! :-( :-) Blocking these in filename.rules.conf and filetype.rules.conf works just fine. If you block them in filetype.rules.conf you need to block 2 different strings to be sure to always block them on Linux systems, as some of these have 2 entries for the same filetype in /usr/share/ magic: TNEF Transport Neutral Encapsulation Format Also, now you see why I insist on tabs separating the 4 fields and not just spaces :-) I would advise blocking them in filename.rules.conf and filetype.rules.conf to be safe. On 10 Jan 2006, at 21:58, Carl Andrews wrote: > Anyone blocking these? > > My /etc/mime-magic does not have the ms/tnef and I can not find a > winmail.dat file. Can anyone tell me what I need to add to mime- > magic so > I can put these in my filetype.rules ? > > > Thanks! > Carl > -------- Forwarded Message -------- > From: Secunia Security Advisories > To: carl.andrews@crackerbarrel.com > Subject: [SA18368] Microsoft Outlook / Exchange TNEF Decoding > Arbitrary > Code Execution Vulnerability > Date: 10 Jan 2006 21:02:44 -0000 > > TITLE: > Microsoft Outlook / Exchange TNEF Decoding Arbitrary Code Execution > Vulnerability > > SECUNIA ADVISORY ID: > SA18368 > > VERIFY ADVISORY: > http://secunia.com/advisories/18368/ > > CRITICAL: > Highly critical > > IMPACT: > System access > > WHERE: >> From remote > > SOFTWARE: > Microsoft Exchange 2000 Enterprise Server > http://secunia.com/product/42/ > Microsoft Exchange 5 > http://secunia.com/product/177/ > Microsoft Exchange 5.5 > http://secunia.com/product/148/ > Microsoft Exchange Server 2000 > http://secunia.com/product/41/ > Microsoft Outlook 2000 > http://secunia.com/product/33/ > Microsoft Outlook 2002 > http://secunia.com/product/34/ > Microsoft Outlook 2003 > http://secunia.com/product/3292/ > > DESCRIPTION: > A vulnerability has been reported in Microsoft Outlook / Exchange, > which can be exploited by malicious people to compromise a vulnerable > system. > > The vulnerability is caused due to boundary error when decoding the > Transport Neutral Encapsulation Format (TNEF) MIME attachment. This > can be exploited to execute arbitrary code when the user opens or > previews a specially crafted TNEF email message or when the Microsoft > Exchange Server Information Store processes the message. > > SOLUTION: > Apply patches. > > -- Microsoft Office 2000 Service Pack 3 -- > > Microsoft Outlook 2000: > http://www.microsoft.com/downloads/details.aspx?FamilyId=64D0336D- > F962-4AB1-A724-9F6BA2108CB9 > > Microsoft Office 2000 MultiLanguage Packs: > http://www.microsoft.com/downloads/details.aspx? > FamilyId=2C0FA7C7-91AA-49B4-9731-9E83E3E0823D > > Microsoft Outlook 2000 English MultiLanguage Packs: > http://www.microsoft.com/downloads/details.aspx? > FamilyId=2C0FA7C7-91AA-49B4-9731-9E83E3E0823D > > -- Microsoft Office XP Service Pack 3 -- > > Microsoft Outlook 2002: > http://www.microsoft.com/downloads/details.aspx? > FamilyId=9A85CEBB-0D9A-465D-A4BC-AF501562772D > > Microsoft Office XP Multilingual User Interface Packs: > http://www.microsoft.com/downloads/details.aspx? > FamilyId=CCA9399A-6DA3-4163-8398-C58DC328182B > > -- Microsoft Office 2003 Service Pack 1 and Service Pack 2 -- > > Microsoft Outlook 2003: > http://www.microsoft.com/downloads/details.aspx?FamilyId=1D156043- > B041-4305-8442-3C4E3B832788 > > Microsoft Office 2003 Multilingual User Interface Packs: > http://www.microsoft.com/downloads/details.aspx? > FamilyId=D69554AD-196F-4789-91E5-B2A753EED854 > > Microsoft Office 2003 Language Interface Packs: > http://www.microsoft.com/downloads/details.aspx? > FamilyID=db080de8-8193-4c32-9019-9980ecd6874a > > -- Microsoft Exchange Server -- > > Microsoft Exchange Server 5.0 Service Pack 2: > http://www.microsoft.com/downloads/details.aspx?FamilyId=0A8DF1C3- > ABF9-4A21-9B49-81FA362B251F > > Microsoft Exchange Server 5.5 Service Pack 4: > http://www.microsoft.com/downloads/details.aspx? > FamilyId=EC6BD30E-12DE-4CA1-9432-D2E73AF62427 > > Microsoft Exchange 2000 Server Pack 3 (with the Exchange 2000 > Post-Service Pack 3 Update Rollup of August 2004): > http://www.microsoft.com/downloads/details.aspx?FamilyId=372FF07F- > C3CA-4301-8559-9B90344EDC02 > > Note: Microsoft Exchange Server 2003 SP1/SP2 are not affected. > > PROVIDED AND/OR DISCOVERED BY: > The vendor credits John Heasman and Mark Litchfield of NGS Software. > > ORIGINAL ADVISORY: > MS06-003 (KB902412): > http://www.microsoft.com/technet/security/Bulletin/MS06-003.mspx > > ---------------------------------------------------------------------- > > About: > This Advisory was delivered by Secunia as a free service to help > everybody keeping their systems up to date against the latest > vulnerabilities. > > Subscribe: > http://secunia.com/secunia_security_advisories/ > > Definitions: (Criticality, Where etc.) > http://secunia.com/about_secunia_advisories/ > > > Please Note: > Secunia recommends that you verify all advisories you receive by > clicking the link. > Secunia NEVER sends attached files with advisories. > Secunia does not advise people to install third party patches, only > use those supplied by the vendor. > > ---------------------------------------------------------------------- > > Unsubscribe: Secunia Security Advisories > http://secunia.com/sec_adv_unsubscribe/?email=carl.andrews% > 40crackerbarrel.com > > ---------------------------------------------------------------------- > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From craig at CSFS.CO.ZA Wed Jan 11 06:03:56 2006 From: craig at CSFS.CO.ZA (Craig Retief (CSFS)) Date: Thu Jan 12 21:31:42 2006 Subject: Child Process Hangs Message-ID: Thanks Steve!!! I checked the modules and found that the system updated the Storable perl module. I also checked the Firewall rules and added a rule for the loopback and the eth0 interface to be able to connect to itself. This has done the trick and MailWatch.pm is working and logging to the database. ('Funky'ness Resolved ;->) After the Firewall rule update I restarted MailScanner with the MailWatch.pm enabled. My log now shows these additional lines: Logging message k0B5wnS0006856 to SQL k0B5wnS0006856: Logged to MailWatch SQL Thank you Steve and Julian!!! ;-)) Cheers, Craig Hi Craig, On Tue, 2006-01-10 at 18:47 +0200, Craig Retief (CSFS) wrote: > > > I ran the perl -w MailWatch.pm command and got this -> "Useless use of > private variable in void context at MailWatch.pm line 247." > This is a harmless warning - it can be ignored. > > Is this as Julian made me realize maybe a DB logging error? > Yes - it looks to be - though I've never seen MailWatch.pm hang a MailScanner system like this before. Check that DBI, DBD-MySQL, Sys::Hostname, Socket and Storable perl modules are installed correctly - also make sure that you aren't doing anything 'funky' with TCP port 11553 (e.g. delaying or dropping packets using iptables etc.). Cheers, Steve. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From nerijus at USERS.SOURCEFORGE.NET Wed Jan 11 06:59:57 2006 From: nerijus at USERS.SOURCEFORGE.NET (Nerijus Baliunas) Date: Thu Jan 12 21:31:42 2006 Subject: #!/bin/bash Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Wed, 11 Jan 2006 04:10:51 +0000 Julian Field wrote: > I entirely agree with you. I will have to go through the scripts that > have this and try to check that they don't have any bash-isms that I > know of. The only one that springs to mind is > export VARIABLE=value > which I will need to change to > VARIABLE=value > export VARIABLE > > What else should I be looking for? I tend to write for whatever > version of sh happens to be on the system I'm writing on at the time. > Bad practice, I know :-( The easiest thing would be to release a new beta version with /bin/sh everywhere and let the users test it :) Regards, Nerijus ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From nerijus at USERS.SOURCEFORGE.NET Wed Jan 11 08:03:50 2006 From: nerijus at USERS.SOURCEFORGE.NET (Nerijus Baliunas) Date: Thu Jan 12 21:31:42 2006 Subject: filename.rules.conf Message-ID: Hello, Now .wmf files are allowed, but .ico, .cur, .hlp are not. IMHO it should be the other way around. So I suggest the following: When new vulnerability is discovered, extensions should be added (.wmf in this case) to filename.rules.conf. After some time (half a year?) extensions, which are not so popular like .pif, .scr, .com, .bat should be removed (comented out) - i.e. .ico and .hlp should be allowed now. Because filename.rules.conf is most useful when new vulnerability is discovered and not all antiviruses detect them (or not everyone is upgraded), but it is quite safe to suggest that in a half year time either antivirus software is updated or Windows systems are patched (or both). Regards, Nerijus ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From P.G.M.Peters at UTWENTE.NL Wed Jan 11 09:08:54 2006 From: P.G.M.Peters at UTWENTE.NL (Peter Peters) Date: Thu Jan 12 21:31:42 2006 Subject: Question about start.. Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Marcel Blenkers wrote on 10-1-2006 20:22: > i am using OpenSuse (SuSE10) with sendmail. > Sendmail version 8.13.4 > > After a reboot of the System, within the Mail-Log i can find a line like: > > Jan 10 20:17:20 s23 sendmail-in[4084]: unable to write pid to > /var/run/sendmail.pid: file in use by another process > > but, connects via port 25 are possible. In Suse it appears both the incoming sendmail and the queue processing sendmail want to write in /var/run/sendmail.pid. One of the two complains but both still work. > After typing: rcMailScanner restart there is the following within the > Maillog: > > Jan 10 20:19:07 s23 sendmail-client[4874]: starting daemon (8.13.4): > persistent-queueing@00:01:00 > > > and no connects on port 25 are possible. > > Is there a way to change this behaviour? I haven't seen this before. I use /etc/init.d/MailScanner restart but rcMailScanner is just a link to that. So that should be no different. I tried using rcMailScanner and I get this: Jan 11 10:06:57 netlx094 sendmail-in[5416]: starting daemon (8.12.10): SMTP Jan 11 10:06:57 netlx094 sendmail-client[5419]: starting daemon (8.12.10): persistent-queueing@00:30:00 Jan 11 10:06:57 netlx094 sendmail-out[5423]: starting daemon (8.12.10): queueing@00:30:00 Jan 11 10:06:57 netlx094 sendmail-out[5423]: unable to write /var/run/sendmail.pid: Permission denied And I can connect to both localhost and de configured IP address for SMTP. - -- Peter Peters, senior beheerder (Security) Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE) Universiteit Twente, Postbus 217, 7500 AE Enschede telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQFDxMsmMbmy+DDgnIURAgfuAJ9+AIpeUFt3ytVNoav0uOIkT93iAwCdEmyG VO3FP0rcM8xidd/hEOOSLmk= =wjpj -----END PGP SIGNATURE----- ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From martinh at SOLID-STATE-LOGIC.COM Wed Jan 11 09:17:41 2006 From: martinh at SOLID-STATE-LOGIC.COM (Martin Hepworth) Date: Thu Jan 12 21:31:42 2006 Subject: #!/bin/bash Message-ID: Hi Given I do a lot of testing with MS I use the tar.gz generic unix installer on FreeBSD too. I get around this by creating a symbolic from /bin/bash to /usr/local/bin/bash ln -s /usr/local/bin/bash /bin/bash -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Nerijus Baliunas > Sent: 10 January 2006 23:30 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: [MAILSCANNER] #!/bin/bash > > Hello, > > Some scripts (update_virus_scanners.cron, update_phishing_sites.cron, > check_MailScanner.cron, update_virus_scanners) from tar.gz distribution > have #!/bin/bash at the first line, and I have to change it to > #!/usr/local/bin/bash on my FreeBSD system. If they are not using > any bash'isms it would be better to change all #!/bin/bash to #!/bin/sh. > > Regards, > Nerijus > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From martinh at SOLID-STATE-LOGIC.COM Wed Jan 11 09:48:51 2006 From: martinh at SOLID-STATE-LOGIC.COM (Martin Hepworth) Date: Thu Jan 12 21:31:42 2006 Subject: #!/bin/bash Message-ID: Crikey DG/UX that bring back memories...I remember struggling to port code this pile of wackiness (login/authentication stuff) And SUNOS 4 - still used in production here! -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Glenn Steen > Sent: 11 January 2006 09:42 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: [MAILSCANNER] #!/bin/bash > > On 11/01/06, Nerijus Baliunas wrote: > > On Wed, 11 Jan 2006 04:10:51 +0000 Julian Field > wrote: > > > > > I entirely agree with you. I will have to go through the scripts that > > > have this and try to check that they don't have any bash-isms that I > > > know of. The only one that springs to mind is > > > export VARIABLE=value > > > which I will need to change to > > > VARIABLE=value > > > export VARIABLE > > > > > > What else should I be looking for? I tend to write for whatever > > > version of sh happens to be on the system I'm writing on at the time. > > > Bad practice, I know :-( > > Using features you can test reliably being a bad practise? no:-). > Look for variable arithmetics... and almost any substitution can be > problematic (usually aren't, but still:). > I'm not sure I agree about the portability of bourne shells though... > nor korn for that matter. Been bitten in the past by things like "cmd > 2>&1 > file" needing to be "cmd > file 2>&1" (more posixly correct, > true)... So insisting on bash isn't an entirely stoopid thing, since > things like that will be the same across platforms... My problems were > mainly in the ancient past (sunos4->aix 2.1-> diab denix, and more > recently going from DG/UX R4.20MU06&07 -> AIX 5.2), so might not be > that relevant:-):-). > > > The easiest thing would be to release a new beta version with /bin/sh > > everywhere and let the users test it :) > > Definitely the most effective method:) > -- > -- Glenn > email: glenn < dot > steen < at > gmail < dot > com > work: glenn < dot > steen < at > ap1 < dot > se > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From philipp.snizek at TERREACTIVE.CH Wed Jan 11 09:08:10 2006 From: philipp.snizek at TERREACTIVE.CH (Philipp Snizek) Date: Thu Jan 12 21:31:42 2006 Subject: running only local SA tests Message-ID: Hi I have a box here that cannot access the internet directly. Thus, to have a higher SpamAssassin rule score I would like to have MailScanner run SpamAssassin with the parameter -L (local tests only). Alternatively, would it be possible to start spamd -L and have MailScanner inject mails via spamc < email? I've searched the Howto, the MailScanner book, Google, the wiki and even SA.pm for a solution. I coudn't find anything. thank you Best regards, Philipp ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From glenn.steen at GMAIL.COM Wed Jan 11 09:42:10 2006 From: glenn.steen at GMAIL.COM (Glenn Steen) Date: Thu Jan 12 21:31:42 2006 Subject: #!/bin/bash Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 11/01/06, Nerijus Baliunas wrote: > On Wed, 11 Jan 2006 04:10:51 +0000 Julian Field wrote: > > > I entirely agree with you. I will have to go through the scripts that > > have this and try to check that they don't have any bash-isms that I > > know of. The only one that springs to mind is > > export VARIABLE=value > > which I will need to change to > > VARIABLE=value > > export VARIABLE > > > > What else should I be looking for? I tend to write for whatever > > version of sh happens to be on the system I'm writing on at the time. > > Bad practice, I know :-( Using features you can test reliably being a bad practise? no:-). Look for variable arithmetics... and almost any substitution can be problematic (usually aren't, but still:). I'm not sure I agree about the portability of bourne shells though... nor korn for that matter. Been bitten in the past by things like "cmd 2>&1 > file" needing to be "cmd > file 2>&1" (more posixly correct, true)... So insisting on bash isn't an entirely stoopid thing, since things like that will be the same across platforms... My problems were mainly in the ancient past (sunos4->aix 2.1-> diab denix, and more recently going from DG/UX R4.20MU06&07 -> AIX 5.2), so might not be that relevant:-):-). > The easiest thing would be to release a new beta version with /bin/sh > everywhere and let the users test it :) Definitely the most effective method:) -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Wed Jan 11 09:13:40 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:42 2006 Subject: filename.rules.conf Message-ID: -----BEGIN PGP SIGNED MESSAGE----- I concur. Please remind me when something is due for removal. On 11 Jan 2006, at 08:03, Nerijus Baliunas wrote: > Hello, > > Now .wmf files are allowed, but .ico, .cur, .hlp are not. IMHO it > should be > the other way around. So I suggest the following: > When new vulnerability is discovered, extensions should be added (.wmf > in this case) to filename.rules.conf. After some time (half a year?) > extensions, which are not so popular like .pif, .scr, .com, .bat > should be > removed (comented out) - i.e. .ico and .hlp should be allowed now. > Because filename.rules.conf is most useful when new vulnerability > is discovered and not all antiviruses detect them (or not everyone is > upgraded), but it is quite safe to suggest that in a half year time > either antivirus software is updated or Windows systems are patched > (or both). - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ8TMR/w32o+k+q+hAQF/hAgAop0WKLIS61shjQSEr4h7yu0mURq9ktAY JRKjqn7j+HgpCybmsjYMPb23HOrNuhPRbZF/Qb/whTcjfBEZuK3AwYHJ1NGW36Pa K2uVQYFbldTOWeabGg4/i+k3OdBH71+bymKwT4oFMXDyqoG8eyi/d+BpY803aOsc DqaVMYQm2z/nOs29PiHmwHek9zkeecd08xGkeHrLa12CE5llrxWungp9TAtA3IIo iVHz2JJITdWu0X2J5git2ky1i4YglL4iziSJtH2V3hwFgfmXDSKKF+1yrSoCbuk4 WbF8EqVs6ltU/FE9JG7FHVwdX1yK+vJzJqpXUH3hMxPvppiwRIDcng== =LEjL -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From glenn.steen at GMAIL.COM Wed Jan 11 09:10:11 2006 From: glenn.steen at GMAIL.COM (Glenn Steen) Date: Thu Jan 12 21:31:42 2006 Subject: Hard Lock Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 10/01/06, Information Services wrote: > Once again one of my mailscanner systems locked up. I had quite a scare > with this one, and I am sure I will be in during the weekend building > another system for when this one kills over. This time I had to take out > the RAM and replug the HDs in order to it to get a sense of itself, but I am > wondering if it has something to do with the powerleaps we have in the Dell > Optiplex G1s. Could they be overheating and causing the lockups? If this > is possible that would explain why it booted after I messed with the other > hardware. But this is what I retried from the /var/log/messages. Better > information, but not something I understand. Can you make sense of it?? Yes, definitely. If you have a budget, try getting new boxes.... In my experience it is very seldom cost-effective to muck about with CPU upgrades.... When you do them, the rest of the system is getting old.... and even though the system _should_ work OK with the new parts, *something* almost always has "gone marginal". Do as Scott says and revert at least this box to the original CPUs, or just replace it with something new and shiny.... Opteron systems are getting _cheap_ these days;-). > --------------------------- > Jan 10 13:05:03 wks-lin9 crond(pam_unix)[11999]: session closed for user > root > Jan 10 13:05:15 wks-lin9 crond(pam_unix)[12000]: session closed for user > root > Jan 10 13:05:22 wks-lin9 crond(pam_unix)[11473]: session closed for user > root > > Jan 10 13:06:49 wks-lin9 smbd[12451]: [2006/01/10 13:06:49, 0] > lib/util_sock.c:get_peer_addr(1000) > Jan 10 13:06:49 wks-lin9 smbd[12451]: getpeername failed. Error was > Transport endpoint is not connected > Jan 10 13:06:49 wks-lin9 smbd[12451]: [2006/01/10 13:06:49, 0] > lib/util_sock.c:get_peer_addr(1000) > > Jan 10 13:06:49 wks-lin9 smbd[12451]: getpeername failed. Error was > Transport endpoint is not connected > Jan 10 13:06:49 wks-lin9 smbd[12451]: [2006/01/10 13:06:49, 0] > lib/util_sock.c:write_socket_data(430) > Jan 10 13:06:49 wks-lin9 smbd[12451]: write_socket_data: write failure. > Error = Connection reset by peer > > Jan 10 13:06:49 wks-lin9 smbd[12451]: [2006/01/10 13:06:49, 0] > lib/util_sock.c:write_socket(455) > Jan 10 13:06:49 wks-lin9 smbd[12451]: write_socket: Error writing 4 bytes to > socket 24: ERRNO = Connection reset by peer > > Jan 10 13:06:49 wks-lin9 smbd[12451]: [2006/01/10 13:06:49, 0] > lib/util_sock.c:send_smb(647) > Jan 10 13:06:49 wks-lin9 smbd[12451]: Error writing 4 bytes to client. -1. > (Connection reset by peer) > Jan 10 13:06:50 wks-lin9 winbindd[2518]: [2006/01/10 13:06:50, 0] > tdb/tdbutil.c:tdb_log(725) > > Jan 10 13:06:50 wks-lin9 winbindd[2518]: > tdb(/var/cache/samba/netsamlogon_cache.tdb): rec_free_read > bad magic 0x42424242 at offset=7252 > ------------------- > > that is the last information posted to messages before the boot up > information is written. > Interrestingly enough, this is "microsoft networking" (samba) complaining loudly on the inability to resolve names to addresses, because the "nameserver" (winbindd) died... and that seem to have died from a database corruption. Could mean nothing, of course, just show that these died first. Most likely show a problem with your CPU, RAM or HDDs (likely contoller promlems in the third case), with CPU and RAM being most likely culprits. standard measures apply.... Swap _ONE_ thing at a time and see if that helps... Although, with intermittent hangs like this, it's often very hard to be sure if some action has solved the problem. Simlest solution is to get brand new HW. -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Wed Jan 11 10:17:45 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:42 2006 Subject: [customer: RE: FW: test tues] Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/11/06, Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem wrote: The MailScanner Lines were not suppose to show up! I have placed scan.messages.rules in the rules directory and with the correct no statement and still MailScanner is scannong mail and yet and exclusion statement has been made. Any Explanation? Could you post the ruleset? -- /peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From glenn.steen at GMAIL.COM Wed Jan 11 10:49:55 2006 From: glenn.steen at GMAIL.COM (Glenn Steen) Date: Thu Jan 12 21:31:42 2006 Subject: #!/bin/bash Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 11/01/06, Martin Hepworth wrote: > > Crikey DG/UX that bring back memories...I remember struggling to port code > this pile of wackiness (login/authentication stuff) Well, during the few years I managed a couple of semi-big DB servers running it, it kind of grew on me:-).Wackiest of all was the lisp-like device filehandles..... sd(npsc((pci(1),0,1)) would be a simple one, I've actively forgotten the FC ones:-). But although people like Brandon Allberry has been known to call it "the DG abomination", it had its high points.... clustering and VDM (kind of like a very nice LVM with a very nice approach to mirroring) included in the base package made it nice for HA solutions.... Oh well, it's dead now. > And SUNOS 4 - still used in production here! Ah the good ol workhorse that refuse to die?-):-) > > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > -----Original Message----- > > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > > Behalf Of Glenn Steen > > Sent: 11 January 2006 09:42 > > To: MAILSCANNER@JISCMAIL.AC.UK > > Subject: Re: [MAILSCANNER] #!/bin/bash > > > > On 11/01/06, Nerijus Baliunas wrote: > > > On Wed, 11 Jan 2006 04:10:51 +0000 Julian Field > > wrote: > > > > > > > I entirely agree with you. I will have to go through the scripts that > > > > have this and try to check that they don't have any bash-isms that I > > > > know of. The only one that springs to mind is > > > > export VARIABLE=value > > > > which I will need to change to > > > > VARIABLE=value > > > > export VARIABLE > > > > > > > > What else should I be looking for? I tend to write for whatever > > > > version of sh happens to be on the system I'm writing on at the time. > > > > Bad practice, I know :-( > > > > Using features you can test reliably being a bad practise? no:-). > > Look for variable arithmetics... and almost any substitution can be > > problematic (usually aren't, but still:). > > I'm not sure I agree about the portability of bourne shells though... > > nor korn for that matter. Been bitten in the past by things like "cmd > > 2>&1 > file" needing to be "cmd > file 2>&1" (more posixly correct, > > true)... So insisting on bash isn't an entirely stoopid thing, since > > things like that will be the same across platforms... My problems were > > mainly in the ancient past (sunos4->aix 2.1-> diab denix, and more > > recently going from DG/UX R4.20MU06&07 -> AIX 5.2), so might not be > > that relevant:-):-). > > > > > The easiest thing would be to release a new beta version with /bin/sh > > > everywhere and let the users test it :) > > > > Definitely the most effective method:) > > -- > > -- Glenn > > email: glenn < dot > steen < at > gmail < dot > com > > work: glenn < dot > steen < at > ap1 < dot > se > > -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From a.peacock at CHIME.UCL.AC.UK Wed Jan 11 11:18:45 2006 From: a.peacock at CHIME.UCL.AC.UK (Anthony Peacock) Date: Thu Jan 12 21:31:42 2006 Subject: Question about start.. Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Hi, Peter Peters wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Marcel Blenkers wrote on 10-1-2006 20:22: > > >>i am using OpenSuse (SuSE10) with sendmail. >> Sendmail version 8.13.4 >> >>After a reboot of the System, within the Mail-Log i can find a line like: >> >>Jan 10 20:17:20 s23 sendmail-in[4084]: unable to write pid to >>/var/run/sendmail.pid: file in use by another process >> >>but, connects via port 25 are possible. > > > In Suse it appears both the incoming sendmail and the queue processing > sendmail want to write in /var/run/sendmail.pid. One of the two > complains but both still work. Yes, this was discussed last year (Oct/Nov check the archives). I believe that Julian has fixed the MailScanner startup script now. If you see this problem, make sure you are using the latest version of the script. > > >>After typing: rcMailScanner restart there is the following within the >>Maillog: >> >>Jan 10 20:19:07 s23 sendmail-client[4874]: starting daemon (8.13.4): >>persistent-queueing@00:01:00 >> >> >>and no connects on port 25 are possible. >> >>Is there a way to change this behaviour? > > > I haven't seen this before. I use /etc/init.d/MailScanner restart but > rcMailScanner is just a link to that. So that should be no different. > > I tried using rcMailScanner and I get this: > Jan 11 10:06:57 netlx094 sendmail-in[5416]: starting daemon (8.12.10): SMTP > Jan 11 10:06:57 netlx094 sendmail-client[5419]: starting daemon > (8.12.10): persistent-queueing@00:30:00 > Jan 11 10:06:57 netlx094 sendmail-out[5423]: starting daemon (8.12.10): > queueing@00:30:00 > Jan 11 10:06:57 netlx094 sendmail-out[5423]: unable to write > /var/run/sendmail.pid: Permission denied > > And I can connect to both localhost and de configured IP address for SMTP. > > - -- > Peter Peters, senior beheerder (Security) > Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE) > Universiteit Twente, Postbus 217, 7500 AE Enschede > telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.2 (MingW32) > Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org > > iD8DBQFDxMsmMbmy+DDgnIURAgfuAJ9+AIpeUFt3ytVNoav0uOIkT93iAwCdEmyG > VO3FP0rcM8xidd/hEOOSLmk= > =wjpj > -----END PGP SIGNATURE----- > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > -- Anthony Peacock CHIME, Royal Free & University College Medical School WWW: http://www.chime.ucl.ac.uk/~rmhiajp/ "The most exciting phrase to hear in science, the one that heralds new discoveries, is not 'Eureka!' but 'That's funny....'" -- Isaac Asimov ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From tenderby at mailwash.com.au Wed Jan 11 10:38:28 2006 From: tenderby at mailwash.com.au (Tony Enderby) Date: Thu Jan 12 21:31:42 2006 Subject: SA cache database. Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Hi All, I have not yet seen a cache hit in my mail logs since upgrading to the latest MS beta with the new SA cache database but often I see entries like these in the logs. Expired 1 records from the SpamAssassin cache Am I correct to assume that perl DBI and SQL Lite are successfully installed and talking to MailScanner ok? I ask because perl DBI failed during the install script execution and I've since installed the module via CPAN. Just wanted to make sure. Tony. ----------------------------------------------------------------------------------- Scanned by MailWash Australia - http://www.mailwash.com.au ----------------------------------------------------------------------------------- ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Dave Wed Jan 11 12:42:35 2006 From: Dave (Dave) Date: Thu Jan 12 21:31:42 2006 Subject: [customer: RE: FW: test tues] Message-ID: On Wed, Jan 11, 2006 at 11:17:45AM +0100, shuttlebox wrote: > On 1/11/06, Dave Shariff Yadallee - System Administrator a.k.a. The Root of > the Problem wrote: > > > > The MailScanner Lines were not suppose to show up! > > I have placed scan.messages.rules in the rules directory and > > with the correct no statement and > > still MailScanner is scannong mail and yet and exclusion statement > > has been made. Any Explanation? > > > > Could you post the ruleset? > To: hvg@hvgsys.com no From: evg@hvgsys.com and To: hvg@hvgsys.com no #From: ignore.domain.com no FromOrTo: default yes -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From drew at THEMARSHALLS.CO.UK Wed Jan 11 13:01:59 2006 From: drew at THEMARSHALLS.CO.UK (Drew Marshall) Date: Thu Jan 12 21:31:42 2006 Subject: MailScanner and sendmail - Problems Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Might I suggest some thing stronger for insomnia??? vvvvv On Wed, January 11, 2006 04:13, Julian Field wrote: > All I can contribute at this point is that I have specifically tested > MailScanner on SuSE10 and if you follow the instructions correctly it > works fine. > > Not that that helps you much... > > On 10 Jan 2006, at 20:31, Michele Neylon:: Blacknight.ie wrote: > >> Marcel Blenkers wrote: >>> Hi there, >>> >>> i am trying to use the latest Version of MailScanner on SuSE10. >>> > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From joshua.hirsh at PARTNERSOLUTIONS.CA Wed Jan 11 14:18:54 2006 From: joshua.hirsh at PARTNERSOLUTIONS.CA (Joshua Hirsh) Date: Thu Jan 12 21:31:42 2006 Subject: MS06-003 TNEF Decoding vulnerability in Outlook and Exchange Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Hi List, MS06-003 was released last night: "Vulnerability in TNEF Decoding in Microsoft Outlook and Microsoft Exchange Could Allow Remote Code Execution" http://www.microsoft.com/technet/security/Bulletin/MS06-003.mspx I can't verify for sure, but I have a feeling that if "Deliver Unparsable TNEF" is set to no, this attack might very well be mitigated, at least until some virus signatures exist. -Joshua ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From joshua.hirsh at PARTNERSOLUTIONS.CA Wed Jan 11 14:21:47 2006 From: joshua.hirsh at PARTNERSOLUTIONS.CA (Joshua Hirsh) Date: Thu Jan 12 21:31:42 2006 Subject: MS06-003 TNEF Decoding vulnerability in Outlook and Exchange Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] I guess it helps to finish reading the other threads first ;-) -Joshua ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Wed Jan 11 14:04:18 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:42 2006 Subject: [customer: RE: FW: test tues] Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/11/06, Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem wrote: To: hvg@hvgsys.com no From: evg@hvgsys.com and To: hvg@hvgsys.com no #From: ignore.domain.com no FromOrTo: default yes But the message headers you posted shows the message came from the below address which is not in the ruleset. It then uses the default-line and gets scanned. X-netknowJan2006-MailScanner-From: doctor@doctor.nl2k.ab.ca -- /peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From KevinS at BMRB.CO.UK Wed Jan 11 14:20:45 2006 From: KevinS at BMRB.CO.UK (Spicer, Kevin) Date: Thu Jan 12 21:31:42 2006 Subject: #!/bin/bash Message-ID: On Wed, 11 Jan 2006 04:10:51 +0000 Julian Field wrote: > I entirely agree with you. I will have to go through the scripts that > have this and try to check that they don't have any bash-isms that I > know of. The only one that springs to mind is > export VARIABLE=value > which I will need to change to > VARIABLE=value > export VARIABLE > > What else should I be looking for? I tend to write for whatever > version of sh happens to be on the system I'm writing on at the time. > Bad practice, I know :-( I always get bitten by if [ "X$something" == "something" ]; then which works fine on bash, but sh only wants a single = ================================================================= BMRB wins two BMRA awards - http://www.bmrb.co.uk _________________________________________________________________ This message (and any attachment) is intended only for the recipient and may contain confidential and/or privileged material. If you have received this in error, please contact the sender and delete this message immediately. Disclosure, copying or other action taken in respect of this email or in reliance on it is prohibited. BMRB Limited accepts no liability in relation to any personal emails, or content of any email which does not directly relate to our business. +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From martinh at SOLID-STATE-LOGIC.COM Wed Jan 11 14:25:23 2006 From: martinh at SOLID-STATE-LOGIC.COM (Martin Hepworth) Date: Thu Jan 12 21:31:42 2006 Subject: SA cache database. Message-ID: Tony If its noting the expiry then it's using the SA cache. You won't see anything in the logs part from it processing emails that hit the cache a lot lot quicker. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Tony Enderby > Sent: 11 January 2006 10:38 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: [MAILSCANNER] SA cache database. > > Hi All, > > I have not yet seen a cache hit in my mail logs since upgrading to the > latest MS beta with the new SA cache database but often I see entries > like these in the logs. > > Expired 1 records from the SpamAssassin cache > > Am I correct to assume that perl DBI and SQL Lite are successfully > installed and talking to MailScanner ok? > > I ask because perl DBI failed during the install script execution and > I've since installed the module via CPAN. > > Just wanted to make sure. > > Tony. > > -------------------------------------------------------------------------- > --------- > Scanned by MailWash Australia - http://www.mailwash.com.au > -------------------------------------------------------------------------- > --------- > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From P.G.M.Peters at UTWENTE.NL Wed Jan 11 14:37:13 2006 From: P.G.M.Peters at UTWENTE.NL (Peter Peters) Date: Thu Jan 12 21:31:42 2006 Subject: Question about start.. Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Anthony Peacock wrote on 11-1-2006 12:18: >> I believe that Julian has fixed the MailScanner startup script now. If >> you see this problem, make sure you are using the latest version of the >> script. This is on a new system completly set up with the latest MS as of december last year. - -- Peter Peters, senior beheerder (Security) Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE) Universiteit Twente, Postbus 217, 7500 AE Enschede telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQFDxRgZMbmy+DDgnIURAh8iAJ9c+6ItgBhE1zZcUq5bK2M2DJtI7QCg3EBo MuutSVJSwmW2rroe/itgp3Y= =ZXdx -----END PGP SIGNATURE----- ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Wed Jan 11 14:48:14 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:42 2006 Subject: #!/bin/bash Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 11 Jan 2006, at 14:20, Spicer, Kevin wrote: > On Wed, 11 Jan 2006 04:10:51 +0000 Julian Field > wrote: > >> I entirely agree with you. I will have to go through the scripts that > >> have this and try to check that they don't have any bash-isms that I >> know of. The only one that springs to mind is >> export VARIABLE=value >> which I will need to change to >> VARIABLE=value >> export VARIABLE >> >> What else should I be looking for? I tend to write for whatever >> version of sh happens to be on the system I'm writing on at the time. > >> Bad practice, I know :-( > > I always get bitten by > > if [ "X$something" == "something" ]; then > > which works fine on bash, but sh only wants a single = Didn't know == would work on bash, so I'm probably safe on that one. There were only 2 or 3 offending scripts anyway. I have done what people suggested, and have released 4.50.6 for you all to play with. I'm running it on 1 production server so far, and it appears fine, and has much lower load average than 4.47 which it was running before. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ8Uasvw32o+k+q+hAQFFqgf+LifagjcLPqJFdabtze1PIO8TzfioPG9a ZYq2MlsqbA9acYEOvr72xiLybBoP/KuPxsI093uidq/fgFd2mNMVG/2eaQekr2UI 2cTm65RokyKISU/j2IurhOx+1HQduG5jVfLVWLjNJR34/+JYZGfCTI/Gj+t3x97A jjpOxQ3f7ZIrmQT+QtOps3HDOnL4+Uc/w0W8/dDiBqmsCNALmURSFqc+emIJ9QMq QrE7YLHPN9+QHq8fPZeTIvpUHzVElCzTZqTJWwtji3zDw0XNHvbYS01U68ujUWLN sotpWZt9nfxWNnfdpjMJiiZIXj9eyjlqHWPJXNu4MaRXKSBHlejqQQ== =HgIt -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Dave Wed Jan 11 16:15:59 2006 From: Dave (Dave) Date: Thu Jan 12 21:31:42 2006 Subject: [customer: RE: FW: test tues] Message-ID: On Wed, Jan 11, 2006 at 03:04:18PM +0100, shuttlebox wrote: > On 1/11/06, Dave Shariff Yadallee - System Administrator a.k.a. The Root of > the Problem wrote: > > > > To: hvg@hvgsys.com no > > From: evg@hvgsys.com and To: hvg@hvgsys.com no > > #From: ignore.domain.com no > > FromOrTo: default yes > > > > But the message headers you posted shows the message came from the below > address which is not in the ruleset. It then uses the default-line and gets > scanned. > Hold on, the customer is hvg@hvgsys.com and that is who it is going to. I only want the first 2 lines to work and the rest is the default. > X-netknowJan2006-MailScanner-From: doctor@doctor.nl2k.ab.ca > > -- > /peter > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From jeremy.henty at nec.ac.uk Wed Jan 11 16:04:08 2006 From: jeremy.henty at nec.ac.uk (Jeremy Henty) Date: Thu Jan 12 21:31:42 2006 Subject: #!/bin/bash Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Wednesday, January 11, 2006 2:20 pm, Spicer, Kevin wrote: >On Wed, 11 Jan 2006 04:10:51 +0000 Julian Field > wrote: > >> What else should I be looking for? I tend to write for whatever >> version of sh happens to be on the system I'm writing on at >>the time. Don't use $( ... ) . Vanilla sh will only recognise backticks ` ... ` . >I always get bitten by > >if [ "X$something" == "something" ]; then > >which works fine on bash, but sh only wants a single = test and [ are builtins in bash, but sh calls the executable in /bin which doesn't recognise == . $ test 6 == 7 $ /bin/test 6 == 7 test: ==: unknown operand $ [ 6 == 7 ] $ /bin/[ 6 == 7 ] [: ==: unknown operand Cheers, Jeremy Henty ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From shuttlebox at GMAIL.COM Wed Jan 11 16:24:00 2006 From: shuttlebox at GMAIL.COM (shuttlebox) Date: Thu Jan 12 21:31:42 2006 Subject: [customer: RE: FW: test tues] Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/11/06, Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem wrote: Hold on, the customer is hvg@hvgsys.com and that is who it is going to. Ok, missed that one. Could you then post the Sendmail logs regarding that exact message because the received headers doesn't contain the hvg-address either. -- /peter ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From campbell at CNPAPERS.COM Wed Jan 11 16:37:19 2006 From: campbell at CNPAPERS.COM (Steve Campbell) Date: Thu Jan 12 21:31:42 2006 Subject: Bayes expire file problems Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] I think it's about time to beat this horse a little more - I have two machines that are almost identical. One continues to get the bayes_toks.expire files, the other never does. Both machines are running the same version, though a little old. (I will upgrade when I and the machines get the time!) I have checked and compared : Mailscanner.conf spam.assassin.prefs.conf check_mailscanner update_virus_scanners clean.quarantine mailscanner-mrtg.crond mailscanner-mrtg.cfg mailscanner-mrtg.conf Both machines' files are identical, with the exceptions of what is not pertinent to expiry. There is no files in the root's .spamassassin directory. What have I missed this time? I know some of the above files are not related, but figured I check anyway. BTW version is 4.36. I'm thinking it's related to mailscanner-mrtg, but just can't seem to find the problem. Anyone who cares to throw mud at me for asking this for the 2 trillionth time, and offer the obvious solution that I'm not seeing, please have at it. Thanks Steve Campbell campbell@cnpapers.com Charleston Newspapers ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From campbell at CNPAPERS.COM Wed Jan 11 17:13:54 2006 From: campbell at CNPAPERS.COM (Steve Campbell) Date: Thu Jan 12 21:31:42 2006 Subject: Bayes expire file problems Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Thanks Julian, As I said, I would upgrade as soon as possible, and I did remember all the posts and problems that were around for a while. I had this problem licked once, with your help. I still don't understand how two machines that are essentially identical can behave so differently. This is what I'd really like to figure out about this problem. Could there be an issue with email volume that contributes to this? The machine that fails (by filling up the root partition) has considerably more traffic than the one that doesn't. I realize this is an old issue with such an old version, so if everyone feels like letting it fade away, I totally understand. I just don't know, though, when I can upgrade. No one wants to let me have the machines, we're 24/7 here except for Sundays, and I'm not allowed to have overtime. Anyway, thanks again. Steve Campbell campbell@cnpapers.com Charleston Newspapers ----- Original Message ----- From: "Julian Field" To: Sent: Wednesday, January 11, 2006 11:48 AM Subject: Re: Bayes expire file problems > -----BEGIN PGP SIGNED MESSAGE----- > > I have fixed a bayes expiry problem in 4.50. > > On 11 Jan 2006, at 16:37, Steve Campbell wrote: > >> I think it's about time to beat this horse a little more - >> >> I have two machines that are almost identical. One continues to get >> the bayes_toks.expire files, the other never does. >> >> Both machines are running the same version, though a little old. (I >> will upgrade when I and the machines get the time!) >> >> I have checked and compared : >> >> Mailscanner.conf >> spam.assassin.prefs.conf >> check_mailscanner >> update_virus_scanners >> clean.quarantine >> mailscanner-mrtg.crond >> mailscanner-mrtg.cfg >> mailscanner-mrtg.conf >> >> Both machines' files are identical, with the exceptions of what is >> not pertinent to expiry. There is no files in the >> root's .spamassassin directory. >> >> What have I missed this time? I know some of the above files are >> not related, but figured I check anyway. >> >> BTW version is 4.36. >> >> I'm thinking it's related to mailscanner-mrtg, but just can't seem >> to find the problem. >> >> Anyone who cares to throw mud at me for asking this for the 2 >> trillionth time, and offer the obvious solution that I'm not >> seeing, please have at it. > > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Wed Jan 11 16:48:11 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:42 2006 Subject: Bayes expire file problems Message-ID: -----BEGIN PGP SIGNED MESSAGE----- I have fixed a bayes expiry problem in 4.50. On 11 Jan 2006, at 16:37, Steve Campbell wrote: > I think it's about time to beat this horse a little more - > > I have two machines that are almost identical. One continues to get > the bayes_toks.expire files, the other never does. > > Both machines are running the same version, though a little old. (I > will upgrade when I and the machines get the time!) > > I have checked and compared : > > Mailscanner.conf > spam.assassin.prefs.conf > check_mailscanner > update_virus_scanners > clean.quarantine > mailscanner-mrtg.crond > mailscanner-mrtg.cfg > mailscanner-mrtg.conf > > Both machines' files are identical, with the exceptions of what is > not pertinent to expiry. There is no files in the > root's .spamassassin directory. > > What have I missed this time? I know some of the above files are > not related, but figured I check anyway. > > BTW version is 4.36. > > I'm thinking it's related to mailscanner-mrtg, but just can't seem > to find the problem. > > Anyone who cares to throw mud at me for asking this for the 2 > trillionth time, and offer the obvious solution that I'm not > seeing, please have at it. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ8U2z/w32o+k+q+hAQHLtwf8Dd4bierAQW/N0iXpocRNN6FkRmmB7PI+ +SQE3EBeqMo2auBwSWLmGdnQiL2gd+7e75X8n7gXGxlvd9UWnsHygPFK9BUS9veh 8yAAJmQskya1AJuZUNRdrGppr0H0V+aOu/lwrB7Vv2+s/C+J3nnKSlsW0wtUEFLf vXX8yXLCXEw8kP9Vjjtc18j1jE23lmx+0ufCufXJtGOjxEebE9suHTTZwepqHRvc w4lKQh0BKHpCkW6LGXeqA7GknYTuSNA9clYydtjb8YocD+FmkKZ8W3j/GCB0aX8b oB7+riAkSBXlqMJN8dVke1U/fNis9xprro7pXBuKEKh1rcSxDmHH9w== =MaSx -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From naolson at GMAIL.COM Wed Jan 11 17:11:39 2006 From: naolson at GMAIL.COM (Nathan Olson) Date: Thu Jan 12 21:31:42 2006 Subject: running only local SA tests Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On 1/11/06, Matt Kettler wrote: > There's no good way to do that directly, but you can get the same effect with a > few setting changes in a local.cf file Not so much. http://bugzilla.spamassassin.org/show_bug.cgi?id=4165 Nate ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mkettler at EVI-INC.COM Wed Jan 11 17:04:03 2006 From: mkettler at EVI-INC.COM (Matt Kettler) Date: Thu Jan 12 21:31:42 2006 Subject: running only local SA tests Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Philipp Snizek wrote: > Hi > > I have a box here that cannot access the internet directly. Thus, to > have a higher SpamAssassin rule score I would like to have MailScanner > run SpamAssassin with the parameter -L (local tests only). > > Alternatively, would it be possible to start spamd -L and have > MailScanner inject mails via spamc < email? There's no good way to do that directly, but you can get the same effect with a few setting changes in a local.cf file: dns_available no And If you're using SA 3.0.x or older: use_razor2 0 use_dcc 0 use_pyzor 0 (With SA 3.1.0 these are all plugins, and are disabled by editing v310.pre) Also, edit your init.pre and disable the loadplugin lines for URIBL and SPF. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Wed Jan 11 18:10:41 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:42 2006 Subject: Bayes expire file problems Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] The mail load on the machine would make a difference. If the bayes rebuild completed while no mail happened to come in, nothing would be competing for the lock on the db file. A busier machine would have several competing processes trying to lock it. Steve Campbell wrote: > Thanks Julian, > > As I said, I would upgrade as soon as possible, and I did remember all > the posts and problems that were around for a while. > > I had this problem licked once, with your help. I still don't > understand how two machines that are essentially identical can behave > so differently. This is what I'd really like to figure out about this > problem. > > Could there be an issue with email volume that contributes to this? > The machine that fails (by filling up the root partition) has > considerably more traffic than the one that doesn't. > > I realize this is an old issue with such an old version, so if > everyone feels like letting it fade away, I totally understand. I just > don't know, though, when I can upgrade. No one wants to let me have > the machines, we're 24/7 here except for Sundays, and I'm not allowed > to have overtime. > > Anyway, thanks again. > > Steve Campbell > campbell@cnpapers.com > Charleston Newspapers > > ----- Original Message ----- From: "Julian Field" > > To: > Sent: Wednesday, January 11, 2006 11:48 AM > Subject: Re: Bayes expire file problems > > >> -----BEGIN PGP SIGNED MESSAGE----- >> >> I have fixed a bayes expiry problem in 4.50. >> >> On 11 Jan 2006, at 16:37, Steve Campbell wrote: >> >>> I think it's about time to beat this horse a little more - >>> >>> I have two machines that are almost identical. One continues to get >>> the bayes_toks.expire files, the other never does. >>> >>> Both machines are running the same version, though a little old. (I >>> will upgrade when I and the machines get the time!) >>> >>> I have checked and compared : >>> >>> Mailscanner.conf >>> spam.assassin.prefs.conf >>> check_mailscanner >>> update_virus_scanners >>> clean.quarantine >>> mailscanner-mrtg.crond >>> mailscanner-mrtg.cfg >>> mailscanner-mrtg.conf >>> >>> Both machines' files are identical, with the exceptions of what is >>> not pertinent to expiry. There is no files in the >>> root's .spamassassin directory. >>> >>> What have I missed this time? I know some of the above files are >>> not related, but figured I check anyway. >>> >>> BTW version is 4.36. >>> >>> I'm thinking it's related to mailscanner-mrtg, but just can't seem >>> to find the problem. >>> >>> Anyone who cares to throw mud at me for asking this for the 2 >>> trillionth time, and offer the obvious solution that I'm not >>> seeing, please have at it. >> >> >> - -- Julian Field >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> >> ------------------------ MailScanner list ------------------------ >> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >> 'leave mailscanner' in the body of the email. >> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >> >> Support MailScanner development - buy the book off the website! >> > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Dave Wed Jan 11 18:14:36 2006 From: Dave (Dave) Date: Thu Jan 12 21:31:42 2006 Subject: [customer: RE: FW: test tues] Message-ID: On Wed, Jan 11, 2006 at 05:24:00PM +0100, shuttlebox wrote: > On 1/11/06, Dave Shariff Yadallee - System Administrator a.k.a. The Root of > the Problem wrote: > > > > Hold on, the customer is hvg@hvgsys.com and that is who it is going to. > > > > Ok, missed that one. Could you then post the Sendmail logs regarding that > exact message because the received headers doesn't contain the hvg-address > either. > Odd!! Here is what the maillog produced. Jan 10 12:47:24 doctor clamav-milter[768]: clamfi_envfrom: Jan 10 12:47:24 doctor clamav-milter[768]: clamfi_envrcpt: Jan 10 12:47:25 doctor sendmail[20946]: k0AJlNgB020946: from=, size=1337, class=0, nrcpts=1, msgid=<7266dd760601101147t486c71f7l475df6 9e699ed986@mail.gmail.com>, proto=ESMTP, daemon=MTA, relay=wproxy.gmail.com [64. 233.184.207] Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: Received: by wproxy.gm ail.com with SMTP id i24so2908959wra\n for ; Tue, 10 Jan 2006 11:47:23 -0800 (PST) Jan 10 12:47:25 doctor clamd[765]: Accepted connection on port 30890, fd 9 Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: DomainKey-Signature: a =rsa-sha1; q=dns; c=nofws;\n s=beta; d=gmail.com;\n h=received:mes sage-id:date:from:to:subject:mime-version:content-type;\n b=i5n7W4F7v7zvZ dtGqf0mqPRoQanauxlz4/69a76wcWS3MKkOjI2wHnVxsc5lyRuq3sbMkqLQe4nUOYh6DlFamCkAVwyeM /BVHjBJToIA3R5X7j5YvA4NSTfYnjpbh8b6iE/K7Dr0bZ8VMgrm+Zc4NcMDyn7eXp28hg2DSqTItEo= Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: Received: by 10.54.67. 10 with SMTP id p10mr5662418wra;\n Tue, 10 Jan 2006 11:47:22 -0800 (PST) Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: Received: by 10.54.102 .5 with HTTP; Tue, 10 Jan 2006 11:47:22 -0800 (PST) Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: Message-ID: <7266dd760 601101147t486c71f7l475df69e699ed986@mail.gmail.com> Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: Date: Tue, 10 Jan 2006 12:47:22 -0700 Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: From: Hartmut von Gaza Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: To: hvg@hvgsys.com Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: Subject: test tues Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: MIME-Version: 1.0 Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: Content-Type: multipar t/alternative; \n boundary="----=_Part_31960_20255549.1136922442864" Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_eoh Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_envbody: 402 bytes Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_eom Jan 10 12:47:25 doctor clamd[765]: stream: OK Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_eom: read stream: OK Jan 10 12:47:25 doctor clamav-milter[768]: k0AJlNgB020946: clean message from Jan 10 12:47:25 doctor sendmail[20946]: k0AJlNgB020946: Milter add: header: X-Vi rus-Scanned: ClamAV version 0.88, clamav-milter version 0.87 on doctor.nl2k.ab.c a Jan 10 12:47:25 doctor sendmail[20946]: k0AJlNgB020946: Milter add: header: X-Vi rus-Status: Clean Jan 10 12:48:20 doctor sendmail[21172]: k0AJlNgB020946: to=, del ay=00:00:56, xdelay=00:00:00, mailer=local, pri=121337, dsn=2.0.0, stat=Sent Jan 10 12:48:20 doctor sendmail[21172]: k0AJlNgB020946: done; delay=00:00:56, nt ries=1 > -- > /peter > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mailscanner at PDSCC.COM Wed Jan 11 20:15:37 2006 From: mailscanner at PDSCC.COM (Harondel J. Sibble) Date: Thu Jan 12 21:31:42 2006 Subject: problem with queues Message-ID: Okay, got an mail relay box with an older version of MS on it. It's been pretty much happily running for a couple years now, planning an upgrade to the latest version later this month. System is running Mandrake 9.x and using postfix for the mta in the dual queue mode. The long and short of it, is that the queues appear to be backed up with lots of crap. If I rename the queue dirs under /var/spool/postfix/defer and deferred and same under postfix.in and create new dirs, mail is flowing fine both in and out. The largest amount of mail is under the postfix.in subdirectories. The following is an example of one of the mesasges, all the ones I looked at so far look like this. It was all one long line in the queue file, I've edited it and added hard returns to hopefully have this display properly C/ 1143 320 1T 1136943998S^Sdalma2@katamail.comA&client_name=sonicwall.internal-lan- address.netA^\cli ent_address=10.10.10.1A8message_origin=sonicwall.internal-lan- address.net[192.168.1 68.1]A^Nhelo_name=mailA^Rprotocol_name=SMTPO^Rinfo@eredirocca.itR^Rinfo@eredir occa.itW^O 0M^O 1463N@Received: from mail (sonicwall.internal-lan-address.net [10.10.10.1])N9 by mailscan.mailrelay.company.net (Postfix) with SMTP id F423A207FD9N@ for ; Tue, 10 Jan 2006 20:46:37 -0500 (EST)N'Reply-To: "Dalma" N#From: "Dalma" N^XTo: N&Subject: Risparmia benzina fino al 25%N%Date: Wed, 11 Jan 2006 02:55:28 +0100N^QMIME-Version: 1.0N^YContent-Type: text/plain;N^S charset="us-ascii"N^_Content-Transfer-Encoding: 7bitN^MX-Priority: 3N^YX-MSMail-Priority: NormalN#X-Mailer: Microsoft Outlook ExpressN8X- MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106N;Message-Id: <20060111014638.F423A207FD9@mailscan.mailrelay.company.net>N^@N^@NGCon il nuovo FuelSaver la tua auto consumera' fino al 25% di carburanteNLin meno.Adatta a tutti i modelli di auto,camion,scooter,furgoni,ecc.Benzina,N.diesel o gpl e di semplicissima installazione.N^N* Meno consumiN^R* Maggiore potenzaNQPer vedere il FuelSaver,come funziona e i risultati dei test ufficiali clicca su:NBhttp://fuelsaver2006.iscool.net/ o su http://www.fuelsaver2006.tkN^@NKGaranzia 2 anni.14 giorni per provarlo di persona.Soddisfatti o rimborsati!N^@X^@r^@e^Sdalma2@katamail.comE^@ I am not quite sure what to make of this, Client has a Fortigate FG60 firewall and I did a mime block on the dalma2@katamail.com address (both to and from fields) and then the firewall showed the emails being blocked, but connections every second from 82.56.160.243, so I set that ip address to reject in the logs. So the queues don't seem to be accumulating any more of this junk, however the onsite admin was concerned that there may be legitimate in and outbound emails still in the queues, what do folks suggest as the best way to get rid of all these junk mails from the queue but still allow any good mail to be delivered. In one of the subqueue dirs alone "F" there is about 15 messages. -- Harondel J. Sibble Sibble Computer Consulting Creating solutions for the small business and home computer user. help@pdscc.com (use pgp keyid 0x3AD5C11D) http://www.pdscc.com (604) 739-3709 (voice/fax) (604) 686-2253 (pager) ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dnsadmin at 1BIGTHINK.COM Wed Jan 11 20:23:00 2006 From: dnsadmin at 1BIGTHINK.COM (dnsadmin 1bigthink.com) Date: Thu Jan 12 21:31:42 2006 Subject: filename.rules.conf Message-ID: At 04:13 AM 1/11/2006, you wrote: >-----BEGIN PGP SIGNED MESSAGE----- > >I concur. >Please remind me when something is due for removal. > >On 11 Jan 2006, at 08:03, Nerijus Baliunas wrote: > > > Hello, > > > > Now .wmf files are allowed, but .ico, .cur, .hlp are not. IMHO it > > should be > > the other way around. So I suggest the following: > > When new vulnerability is discovered, extensions should be added (.wmf > > in this case) to filename.rules.conf. After some time (half a year?) > > extensions, which are not so popular like .pif, .scr, .com, .bat > > should be > > removed (comented out) - i.e. .ico and .hlp should be allowed now. > > Because filename.rules.conf is most useful when new vulnerability > > is discovered and not all antiviruses detect them (or not everyone is > > upgraded), but it is quite safe to suggest that in a half year time > > either antivirus software is updated or Windows systems are patched > > (or both). I still see lots of .pif attempts. Allow at your own demise! I've yet to see a valid .scr, .hlp, .ico, or .cur and I've definitely run into some mentally debilitated users! Cheers, Glenn ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Kevin_Miller at CI.JUNEAU.AK.US Wed Jan 11 20:36:01 2006 From: Kevin_Miller at CI.JUNEAU.AK.US (Kevin Miller) Date: Thu Jan 12 21:31:42 2006 Subject: filename.rules.conf Message-ID: dnsadmin 1bigthink.com wrote: > At 04:13 AM 1/11/2006, you wrote: > >> -----BEGIN PGP SIGNED MESSAGE----- >> >> I concur. >> Please remind me when something is due for removal. >> snip > > I still see lots of .pif attempts. Allow at your own demise! I've yet > to see a valid .scr, .hlp, .ico, or .cur and I've definitely run into > some mentally debilitated users! I agree. I guess if it could be shown that none of the viruses on the wild list use those extensions I'd say remove them, but if there's a potential for exploitation then leave 'em. It's a lot cheaper timewise for an end user to zip the file or other method like ftp if it's legitimate, than it is for me to clean several hundred machines if a virus gets loose in our internal email. DAMHIKT! S'later... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Wed Jan 11 20:48:18 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:42 2006 Subject: filename.rules.conf Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Kevin Miller wrote: >dnsadmin 1bigthink.com wrote: > > >>At 04:13 AM 1/11/2006, you wrote: >> >> >> >>>-----BEGIN PGP SIGNED MESSAGE----- >>> >>>I concur. >>>Please remind me when something is due for removal. >>> >>> >>> >snip > > >>I still see lots of .pif attempts. Allow at your own demise! I've yet >>to see a valid .scr, .hlp, .ico, or .cur and I've definitely run into >>some mentally debilitated users! >> >> > >I agree. I guess if it could be shown that none of the viruses on the >wild list use those extensions I'd say remove them, but if there's a >potential for exploitation then leave 'em. It's a lot cheaper timewise >for an end user to zip the file or other method like ftp if it's >legitimate, than it is for me to clean several hundred machines if a >virus gets loose in our internal email. DAMHIKT! > > DAMHIKT? I also see the other side of this argument. However, given that both sides have valid points, I can only come down on the safe side. If you don't like the rules, edit them. I will play safe for now. Any more thoughts on this argument? -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Kevin_Miller at CI.JUNEAU.AK.US Wed Jan 11 20:54:46 2006 From: Kevin_Miller at CI.JUNEAU.AK.US (Kevin Miller) Date: Thu Jan 12 21:31:42 2006 Subject: filename.rules.conf Message-ID: Julian Field wrote: > Kevin Miller wrote: > >> dnsadmin 1bigthink.com wrote: >> >> >>> At 04:13 AM 1/11/2006, you wrote: >>> >>> >>> >>>> -----BEGIN PGP SIGNED MESSAGE----- >>>> >>>> I concur. >>>> Please remind me when something is due for removal. >>>> >>>> >>>> >> snip >> >> >>> I still see lots of .pif attempts. Allow at your own demise! I've >>> yet to see a valid .scr, .hlp, .ico, or .cur and I've definitely >>> run into some mentally debilitated users! >>> >>> >> >> I agree. I guess if it could be shown that none of the viruses on >> the wild list use those extensions I'd say remove them, but if >> there's a potential for exploitation then leave 'em. It's a lot >> cheaper timewise for an end user to zip the file or other method >> like ftp if it's legitimate, than it is for me to clean several >> hundred machines if a virus gets loose in our internal email. >> DAMHIKT! >> >> > DAMHIKT? Don't Ask Me How I Know This. > > I also see the other side of this argument. However, given that both > sides have valid points, I can only come down on the safe side. If you > don't like the rules, edit them. I will play safe for now. > Any more thoughts on this argument? I think I'm missing something. Wouldn't the safe side be to leave the deny entries in the filename.rules.conf and filetype.rules.conf files for extensions like .scr .hlp, .ico, etc.? Or were you speaking toungue in cheek when you said "Please remind me when something is due for removal."? ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Wed Jan 11 21:33:47 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:42 2006 Subject: filename.rules.conf Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Kevin Miller wrote: >Julian Field wrote: > > >>Kevin Miller wrote: >> >> >> >>>dnsadmin 1bigthink.com wrote: >>> >>> >>> >>> >>>>At 04:13 AM 1/11/2006, you wrote: >>>> >>>> >>>> >>>> >>>> >>>>>-----BEGIN PGP SIGNED MESSAGE----- >>>>> >>>>>I concur. >>>>>Please remind me when something is due for removal. >>>>> >>>>> >>>>> >>>>> >>>>> >>>snip >>> >>> >>> >>> >>>>I still see lots of .pif attempts. Allow at your own demise! I've >>>>yet to see a valid .scr, .hlp, .ico, or .cur and I've definitely >>>>run into some mentally debilitated users! >>>> >>>> >>>> >>>> >>>I agree. I guess if it could be shown that none of the viruses on >>>the wild list use those extensions I'd say remove them, but if >>>there's a potential for exploitation then leave 'em. It's a lot >>>cheaper timewise for an end user to zip the file or other method >>>like ftp if it's legitimate, than it is for me to clean several >>>hundred machines if a virus gets loose in our internal email. >>>DAMHIKT! >>> >>> >>> >>> >>DAMHIKT? >> >> > >Don't Ask Me How I Know This. > > > >>I also see the other side of this argument. However, given that both >>sides have valid points, I can only come down on the safe side. If you >>don't like the rules, edit them. I will play safe for now. >>Any more thoughts on this argument? >> >> > >I think I'm missing something. Wouldn't the safe side be to leave the >deny entries in the filename.rules.conf and filetype.rules.conf files >for extensions like .scr .hlp, .ico, etc.? > >Or were you speaking toungue in cheek when you said "Please remind me >when something is due for removal."? > > No, that was when I was siding with the dangerous side (removing traps against old vulnerabilities). I am now siding with the safe side (leave the traps in, let people delete them if and when they want to). Stay on the safe side, I will. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Kevin_Miller at CI.JUNEAU.AK.US Wed Jan 11 21:16:29 2006 From: Kevin_Miller at CI.JUNEAU.AK.US (Kevin Miller) Date: Thu Jan 12 21:31:42 2006 Subject: [Fwd: [SA18368] Microsoft Outlook / Exchange TNEF Decoding Arbitrary Code Execution Vulnerability] Message-ID: Julian Field wrote: > That one got me very worried. I checked to see that blocking tnef > master-files worked, and it appeared not to. So loads of debugging > later, I finally find I had commented out the filename.rules.conf and > filetype.rules.conf settings in MailScanner.conf. > Grrrr.... but also Phew! > :-( :-) > > Blocking these in filename.rules.conf and filetype.rules.conf works > just fine. > If you block them in filetype.rules.conf you need to block 2 > different strings to be sure to always block them on Linux systems, > as some of these have 2 entries for the same filetype in /usr/share/ > magic: > TNEF > Transport Neutral Encapsulation Format > > Also, now you see why I insist on tabs separating the 4 fields and > not just spaces :-) > > I would advise blocking them in filename.rules.conf and > filetype.rules.conf to be safe. Quick reality check here. In filename.rules.conf I'd use deny \winmail.dat$ Windows TNEF security vulnerability Possible buffer overflow in Windows and in filetype.rules.conf something like: deny TNEF No Windows TNEF No Winmail.dat files allowed deny Transport Neutral Encapsulation Format No Windows TNEF No Winmail.dat files allowed (Paying attention to the distinction between tabs and spaces as mentioned above, which Outlook may strip out when I send this) TIA... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dnsadmin at 1BIGTHINK.COM Wed Jan 11 21:20:50 2006 From: dnsadmin at 1BIGTHINK.COM (dnsadmin 1bigthink.com) Date: Thu Jan 12 21:31:42 2006 Subject: filename.rules.conf Message-ID: At 03:54 PM 1/11/2006, you wrote: >Julian Field wrote: > > Kevin Miller wrote: > > > >> dnsadmin 1bigthink.com wrote: > >> > >> > >>> At 04:13 AM 1/11/2006, you wrote: > >>> > >>> > >>> > >>>> -----BEGIN PGP SIGNED MESSAGE----- > >>>> > >>>> I concur. > >>>> Please remind me when something is due for removal. > >>>> > >>>> > >>>> > >> snip > >> > >> > >>> I still see lots of .pif attempts. Allow at your own demise! I've > >>> yet to see a valid .scr, .hlp, .ico, or .cur and I've definitely > >>> run into some mentally debilitated users! > >>> > >>> > >> > >> I agree. I guess if it could be shown that none of the viruses on > >> the wild list use those extensions I'd say remove them, but if > >> there's a potential for exploitation then leave 'em. It's a lot > >> cheaper timewise for an end user to zip the file or other method > >> like ftp if it's legitimate, than it is for me to clean several > >> hundred machines if a virus gets loose in our internal email. > >> DAMHIKT! > >> > >> > > DAMHIKT? > >Don't Ask Me How I Know This. > > > > > I also see the other side of this argument. However, given that both > > sides have valid points, I can only come down on the safe side. If you > > don't like the rules, edit them. I will play safe for now. > > Any more thoughts on this argument? > >I think I'm missing something. Wouldn't the safe side be to leave the >deny entries in the filename.rules.conf and filetype.rules.conf files >for extensions like .scr .hlp, .ico, etc.? > >Or were you speaking toungue in cheek when you said "Please remind me >when something is due for removal."? > > >...Kevin The initial 'I concur ..' was Julian, yesterday. The sequence got out of sorts. Julian advocated keeping in the rules originally suggested as outdated. I'd rather the rules stay with the safe defaults as has been the case. They are easier removed than installed anyway. Cheers, Glenn ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From nerijus at USERS.SOURCEFORGE.NET Wed Jan 11 21:26:02 2006 From: nerijus at USERS.SOURCEFORGE.NET (Nerijus Baliunas) Date: Thu Jan 12 21:31:42 2006 Subject: filename.rules.conf Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Wed, 11 Jan 2006 11:54:46 -0900 Kevin Miller wrote: > I think I'm missing something. Wouldn't the safe side be to leave the > deny entries in the filename.rules.conf and filetype.rules.conf files > for extensions like .scr .hlp, .ico, etc.? .scr should be left, as it is used along with .pif, but .hlp and .ico should be commented out. Regards, Nerijus ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From nerijus at USERS.SOURCEFORGE.NET Wed Jan 11 21:28:46 2006 From: nerijus at USERS.SOURCEFORGE.NET (Nerijus Baliunas) Date: Thu Jan 12 21:31:42 2006 Subject: filename.rules.conf Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Wed, 11 Jan 2006 20:48:18 +0000 Julian Field wrote: > I also see the other side of this argument. However, given that both > sides have valid points, I can only come down on the safe side. If you > don't like the rules, edit them. I will play safe for now. > Any more thoughts on this argument? Then please uncomment .wmf, as it makes no sense to not allow .hlp and allow .wmf by default. But I still think that .hlp and .ico should be allowed, I never saw viruses with these extensions, while there are plenty with .com, .exe, .bat, .pif and .scr. Regards, Nerijus ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Wed Jan 11 21:58:22 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:42 2006 Subject: [Fwd: [SA18368] Microsoft Outlook / Exchange TNEF Decoding Arbitrary Code Execution Vulnerability] Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Kevin Miller wrote: >Julian Field wrote: > > >>That one got me very worried. I checked to see that blocking tnef >>master-files worked, and it appeared not to. So loads of debugging >>later, I finally find I had commented out the filename.rules.conf and >>filetype.rules.conf settings in MailScanner.conf. >>Grrrr.... but also Phew! >>:-( :-) >> >>Blocking these in filename.rules.conf and filetype.rules.conf works >>just fine. >>If you block them in filetype.rules.conf you need to block 2 >>different strings to be sure to always block them on Linux systems, >>as some of these have 2 entries for the same filetype in /usr/share/ >>magic: >>TNEF >>Transport Neutral Encapsulation Format >> >>Also, now you see why I insist on tabs separating the 4 fields and >>not just spaces :-) >> >>I would advise blocking them in filename.rules.conf and >>filetype.rules.conf to be safe. >> >> > >Quick reality check here. In filename.rules.conf I'd use >deny \winmail.dat$ Windows TNEF security vulnerability >Possible buffer overflow in Windows > > Should be winmail\.dat$ >and in filetype.rules.conf something like: > >deny TNEF No Windows TNEF No Winmail.dat files >allowed >deny Transport Neutral Encapsulation Format No Windows TNEF >No Winmail.dat files allowed > > Correct. >(Paying attention to the distinction between tabs and spaces as >mentioned above, which Outlook may strip out when I send this) > >TIA... > >...Kevin > > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From carl.andrews at CRACKERBARREL.COM Wed Jan 11 22:06:38 2006 From: carl.andrews at CRACKERBARREL.COM (Carl Andrews) Date: Thu Jan 12 21:31:42 2006 Subject: [Fwd: [SA18368] Microsoft Outlook / Exchange TNEF Decoding Arbitrary Code Execution Vulnerability] Message-ID: Thanks Everyone! On Wed, 2006-01-11 at 21:58 +0000, Julian Field wrote: > Kevin Miller wrote: > > >Julian Field wrote: > > > > > >>That one got me very worried. I checked to see that blocking tnef > >>master-files worked, and it appeared not to. So loads of debugging > >>later, I finally find I had commented out the filename.rules.conf and > >>filetype.rules.conf settings in MailScanner.conf. > >>Grrrr.... but also Phew! > >>:-( :-) > >> > >>Blocking these in filename.rules.conf and filetype.rules.conf works > >>just fine. > >>If you block them in filetype.rules.conf you need to block 2 > >>different strings to be sure to always block them on Linux systems, > >>as some of these have 2 entries for the same filetype in /usr/share/ > >>magic: > >>TNEF > >>Transport Neutral Encapsulation Format > >> > >>Also, now you see why I insist on tabs separating the 4 fields and > >>not just spaces :-) > >> > >>I would advise blocking them in filename.rules.conf and > >>filetype.rules.conf to be safe. > >> > >> > > > >Quick reality check here. In filename.rules.conf I'd use > >deny \winmail.dat$ Windows TNEF security vulnerability > >Possible buffer overflow in Windows > > > > > Should be winmail\.dat$ > > >and in filetype.rules.conf something like: > > > >deny TNEF No Windows TNEF No Winmail.dat files > >allowed > >deny Transport Neutral Encapsulation Format No Windows TNEF > >No Winmail.dat files allowed > > > > > Correct. > > >(Paying attention to the distinction between tabs and spaces as > >mentioned above, which Outlook may strip out when I send this) > > > >TIA... > > > >...Kevin > > > > > > -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > Professional Support Services at www.MailScanner.biz > MailScanner thanks transtec Computers for their support > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ssilva at SGVWATER.COM Wed Jan 11 22:29:10 2006 From: ssilva at SGVWATER.COM (Scott Silva) Date: Thu Jan 12 21:31:42 2006 Subject: filename.rules.conf Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] >> >> > DAMHIKT? > An acronym for "Don't ask me how I know this" -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Kevin_Miller at CI.JUNEAU.AK.US Wed Jan 11 22:31:38 2006 From: Kevin_Miller at CI.JUNEAU.AK.US (Kevin Miller) Date: Thu Jan 12 21:31:42 2006 Subject: filename.rules.conf Message-ID: Nerijus Baliunas wrote: > On Wed, 11 Jan 2006 20:48:18 +0000 Julian Field > wrote: > >> I also see the other side of this argument. However, given that both >> sides have valid points, I can only come down on the safe side. If >> you don't like the rules, edit them. I will play safe for now. >> Any more thoughts on this argument? > > Then please uncomment .wmf, as it makes no sense to not allow .hlp > and allow .wmf by default. But I still think that .hlp and .ico > should be > allowed, I never saw viruses with these extensions, while there are > plenty with .com, .exe, .bat, .pif and .scr. The wmf vulnerability is pretty new - week or so old I think. Not sure what you mean by uncomment, as it wasn't even in filename.rules.conf unless it's manually added. Julian may have put it in the latest release, but I'm behind a bit. Bottom line is that what comes with MailScanner is a set of sensible defaults, but it's intended that some customization be done on every install since no two businesses have the same requirements. Feel free to allow/deny whatever is appropriate for your situation. If you don't have any trouble with .hlp and .ico files then by all means comment those out. I don't know if any have ever even been sent to us. If not, then it's irrelivant whether they're commented out or not. If some have, it makes more sense to me to have the sender zip them and resend than take a chance on some old virus slipping through. Most home users are very ignorant of computer security. They may or may not have up to date service packs or antivirus. Or antivirus and security updates at all. I'm not going to trust my network to the digilance of clueless home users. YMMV... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From spamtrap71892316634 at ANIME.NET Wed Jan 11 23:59:30 2006 From: spamtrap71892316634 at ANIME.NET (Dan Hollis) Date: Thu Jan 12 21:31:42 2006 Subject: mailscanner breaks etrn Message-ID: If I run sendmail by itself (/etc/rc.d/init.d/sendmail), etrn works: Connected to x.com (x.x.x.x). Escape character is '^]'. 220 x.com ESMTP Sendmail 8.13.1/8.13.1; Wed, 11 Jan 2006 14:33:39 -0800 ehlo customer.com 250-x.com Hello customer.com [y.y.y.y], pleased to meet you 250-ENHANCEDSTATUSCODES 250-PIPELINING 250-8BITMIME 250-SIZE 250-DSN 250-ETRN 250-AUTH LOGIN PLAIN GSSAPI DIGEST-MD5 CRAM-MD5 250-DELIVERBY 250 HELP ETRN customer.com 250 2.0.0 Queuing for node customer.com started If I run mailscanner (/etc/rc.d/init.d/MailScanner), etrn is disabled: Connected to x.com (x.x.x.x). Escape character is '^]'. 220 x.com ESMTP Sendmail 8.13.1/8.13.1; Wed, 11 Jan 2006 14:31:58 -0800 ehlo customer.com 250-x.com Hello customer.com [y.y.y.u], pleased to meet you 250-ENHANCEDSTATUSCODES 250-PIPELINING 250-8BITMIME 250-SIZE 250-DSN 250-AUTH LOGIN PLAIN GSSAPI DIGEST-MD5 CRAM-MD5 250-DELIVERBY 250 HELP ETRN customer.com 502 5.7.0 Sorry, we do not allow this operation I have spent hours trying to figure out why mailscanner disables etrn, but failed. Anyone know what's up with this? -Dan ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From raymond at PROLOCATION.NET Thu Jan 12 00:04:09 2006 From: raymond at PROLOCATION.NET (Raymond Dijkxhoorn) Date: Thu Jan 12 21:31:42 2006 Subject: mailscanner breaks etrn Message-ID: Hi! > If I run sendmail by itself (/etc/rc.d/init.d/sendmail), etrn works: > I have spent hours trying to figure out why mailscanner disables etrn, > but failed. Anyone know what's up with this? This is by design... your ETRN on a incomming sendmail, that one doesnt have scanning, so how would you combine this? You will break things if you do. Most likely you have to add a extra box to start using ETRN. If MailScanner is running on a high volume mail server and if SMTP ETRN commands are allowed, a remote attacker could create malicious emails that would be held in the incoming mail queue (mqueue.in) for a long period of time, which would bypass the MailScanner virus protection. An attacker could exploit this vulnerability to launch further attacks against the affected server. Bye, Raymond. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From spamtrap71892316634 at ANIME.NET Thu Jan 12 00:17:52 2006 From: spamtrap71892316634 at ANIME.NET (Dan Hollis) Date: Thu Jan 12 21:31:42 2006 Subject: mailscanner breaks etrn Message-ID: On Thu, 12 Jan 2006, Raymond Dijkxhoorn wrote: >> If I run sendmail by itself (/etc/rc.d/init.d/sendmail), etrn works: >> I have spent hours trying to figure out why mailscanner disables etrn, but >> failed. Anyone know what's up with this? > This is by design... your ETRN on a incomming sendmail, that one doesnt have > scanning, so how would you combine this? You will break things if you do. > Most likely you have to add a extra box to start using ETRN. > If MailScanner is running on a high volume mail server and if SMTP ETRN > commands are allowed, a remote attacker could create malicious emails that > would be held in the incoming mail queue (mqueue.in) for a long period of > time, which would bypass the MailScanner virus protection. An attacker could > exploit this vulnerability to launch further attacks against the affected > server. you can restrict what IP addresses are allowed ETRN via a local ruleset. sendmail book 3rd edition, chapter 19. see check_etrn policy rule set. so this is no problem whatsoever. -Dan ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From nerijus at USERS.SOURCEFORGE.NET Thu Jan 12 00:47:51 2006 From: nerijus at USERS.SOURCEFORGE.NET (Nerijus Baliunas) Date: Thu Jan 12 21:31:42 2006 Subject: filename.rules.conf Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Wed, 11 Jan 2006 13:31:38 -0900 Kevin Miller wrote: > The wmf vulnerability is pretty new - week or so old I think. Not sure > what you mean by uncomment, as it wasn't even in filename.rules.conf > unless it's manually added. In 4.49.7 it is commented out: #deny \.wmf$ Windows Metafile security vulnerability But I see in 4.50.6 it is uncommented already, so everything is OK now. > users are very ignorant of computer security. They may or may not have > up to date service packs or antivirus. Or antivirus and security > updates at all. I'm not going to trust my network to the digilance of > clueless home users. YMMV... I meant not only updates and antivirus software on a client machine, but antivirus on MailScanner box itself. It really shoud catch such old vulnerabilities. But anyway, it doesn't matter, Julian already decided. Regards, Nerijus ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From nerijus at USERS.SOURCEFORGE.NET Thu Jan 12 01:22:11 2006 From: nerijus at USERS.SOURCEFORGE.NET (Nerijus Baliunas) Date: Thu Jan 12 21:31:42 2006 Subject: #!/bin/bash Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Wed, 11 Jan 2006 14:48:14 +0000 Julian Field wrote: > Didn't know == would work on bash, so I'm probably safe on that one. > There were only 2 or 3 offending scripts anyway. > > I have done what people suggested, and have released 4.50.6 for you > all to play with. You replaced in Sophos.install and update_virus_scanners, but there are still /bin/bash in: panda-autoupdate Sophos.install.linux Sophos.install.solaris check_MailScanner.cron update_phishing_sites.cron update_virus_scanners.cron These files can probably be deleted: bin/.#mailscanner.1.142.2.157 docs/.#ChangeLog* docs/.#downloads.shtml* empty directories /bin/old, /bin/wrappers, SpamAssassin.patches, /etc/old, /etc/reports/cat, /etc/tcp, /lib/MailScanner/Custom, /docs/install/tcp Regards, Nerijus ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From tenderby at mailwash.com.au Thu Jan 12 02:44:57 2006 From: tenderby at mailwash.com.au (Tony Enderby) Date: Thu Jan 12 21:31:42 2006 Subject: SA 3.1.0 for FC3 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Hi List, Just wondering if anyone has a link to an RPM for SA 3.1.0 for Fedora Core 3 that they have successfully installed in production. Many thanks, Tony. ----------------------------------------------------------------------------------- Scanned by MailWash Australia - http://www.mailwash.com.au ----------------------------------------------------------------------------------- ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From devonharding at GMAIL.COM Thu Jan 12 02:50:28 2006 From: devonharding at GMAIL.COM (Devon Harding) Date: Thu Jan 12 21:31:42 2006 Subject: SA 3.1.0 for FC3 Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] I always use CPAN for my SA installs. On 1/11/06, Tony Enderby wrote: Hi List, Just wondering if anyone has a link to an RPM for SA 3.1.0 for Fedora Core 3 that they have successfully installed in production. Many thanks, Tony. ------------------------------------------------------------------------------- --- Scanned by MailWash Australia - http://www.mailwash.com.au ------------------------------------------------------------------------------- --- ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives ( http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From steve at MALLER.COM Thu Jan 12 02:56:52 2006 From: steve at MALLER.COM (Steve Maller) Date: Thu Jan 12 21:31:42 2006 Subject: MailScanner and SpamAssassin sitewide help! Message-ID: OK, I've built and installed MailScanner 4.49 and SpamAssassin 3.1.0 on a mostly stock Fedora Core 4 box. I'm running Sendmail with a bunch of RBLs and TLS enabled. Email comes through MailScanner, but whatever I do, I do not seem to get any mail to go through SpamAssassin. I tried manually starting spamd with the -d option. I have the "Use SpamAssassin" directive enabled, but like I said, nothing works. My intention is to run this site-wide, and I have consulted with the various FAQs and nothing seems to work. Again, email *is* being delivered, but SpamAssassin is never getting used. Thanks! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From craigwhite at AZAPPLE.COM Thu Jan 12 03:29:06 2006 From: craigwhite at AZAPPLE.COM (Craig White) Date: Thu Jan 12 21:31:42 2006 Subject: MailScanner and SpamAssassin sitewide help! Message-ID: [ The following text is in the "utf-8" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Wed, 2006-01-11 at 18:56 -0800, Steve Maller wrote: > OK, I've built and installed MailScanner 4.49 and SpamAssassin 3.1.0 > on a mostly stock Fedora Core 4 box. I'm running Sendmail with a > bunch of RBLs and TLS enabled. > > Email comes through MailScanner, but whatever I do, I do not seem to > get any mail to go through SpamAssassin. I tried manually starting > spamd with the -d option. > > I have the "Use SpamAssassin" directive enabled, but like I said, > nothing works. > > My intention is to run this site-wide, and I have consulted with the > various FAQs and nothing seems to work. > > Again, email *is* being delivered, but SpamAssassin is never getting used. ---- http://wiki.mailscanner.info/doku.php?id=maq:index (there is a whole section on spamassassin on this wiki page but also...) Post-install Now your server should accept, process, and route messages properly. Time to set back and relax? Nah, not yetâ^À¦ 1. Read carefully the config file (MailScanner.conf) and define what settings you need to change to comply with your needs 2. Test for spam and viruses 3. Make sure everything is installed and configured to your best knowledge before testing. 4. Test mailscanner in debug mode frequently 5. You can test Spamassassin using the command spamassassin -D â^À^Ó lint -p /path/to/your/prefs/file (on a regular redhat system: spamassassin -D â^À^Ólint -p /etc/MailScanner/spam.assassin.prefs.conf ) 6. To test spam, make a gtube go through MailScanner 7. To test the anti-virus, make the eicar test virus go through MailScanner 8. To test your whole mail setup try GFI Email Security Testing Zone 9. Determine which SpamAssassin plugins you want to install and install them 10. See optimization tips below 11. See FSL's support page, youâ^À^Ùll find many tools to help you 12. Read the MailScanner Manual or, even better, Buy the book! and support MailScannerâ^À^Ùs development. 13. Ask questions on the mailing list if needed. what do you get when you run... spamassassin -D --lint -p /etc/MailScanner/spam.assassin.prefs.conf did you? service sendmail stop chkconfig sendmail off service MailScanner start chkconfig MailScanner on and another thought comes to mind...you can set... Always Include SpamAssassin Report = no to yes to see what is working Craig ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From mailscanner at PDSCC.COM Thu Jan 12 06:44:43 2006 From: mailscanner at PDSCC.COM (Harondel J. Sibble) Date: Thu Jan 12 21:31:42 2006 Subject: problem with queues Message-ID: On 12 Jan 2006 at 3:54, Glenn Steen wrote: > Ehm, Mdk 9 has been out of circulation for quite some time now.... Do > you even find relevant security updates for it anymore? Manually applied. > Not to mention that the dual-PF setup has been deprecated for well > more than a year now... The HOLD feature and one postfix is much > safer (from queue corruption, no less). I know, problem was being able to take it down for long enough to get a new box setup. > You should perhaps not wait until the end of the month;-). Scheduled down time for Jan 21/22. > Why didn't you just run postcat on the queue file? Would have given us > something more intelligibel;-) I'd completely forgotten about the postcat command ..... -- Harondel J. Sibble Sibble Computer Consulting Creating solutions for the small business and home computer user. help@pdscc.com (use pgp keyid 0x3AD5C11D) http://www.pdscc.com (604) 739-3709 (voice/fax) (604) 686-2253 (pager) ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From philipp.snizek at TERREACTIVE.CH Thu Jan 12 07:52:19 2006 From: philipp.snizek at TERREACTIVE.CH (Philipp Snizek) Date: Thu Jan 12 21:31:42 2006 Subject: running only local SA tests Message-ID: > There's no good way to do that directly, but you can get the same effect with a > few setting changes in a local.cf file: > > > dns_available no > > And If you're using SA 3.0.x or older: > use_razor2 0 > use_dcc 0 > use_pyzor 0 > > (With SA 3.1.0 these are all plugins, and are disabled by editing v310.pre) > > > Also, edit your init.pre and disable the loadplugin lines for URIBL and SPF. Thanks for your answer. I did all that, restarted MailScanner but it still uses the SA scoreset with network tests enabled. I use SA 3.1.0 and MailScanner 4.49-7.1 Philipp ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 12 09:26:10 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:42 2006 Subject: mailscanner breaks etrn Message-ID: -----BEGIN PGP SIGNED MESSAGE----- It's very simple. ETRN extracts mail from the incoming queue, before MailScanner has had a chance to process it. So it is an ideal route for your users to get viruses and spam. So I have to disable ETRN. On 11 Jan 2006, at 23:59, Dan Hollis wrote: > If I run sendmail by itself (/etc/rc.d/init.d/sendmail), etrn works: > > Connected to x.com (x.x.x.x). > Escape character is '^]'. > 220 x.com ESMTP Sendmail 8.13.1/8.13.1; Wed, 11 Jan 2006 14:33:39 > -0800 > ehlo customer.com > 250-x.com Hello customer.com [y.y.y.y], pleased to meet you > 250-ENHANCEDSTATUSCODES > 250-PIPELINING > 250-8BITMIME > 250-SIZE > 250-DSN > 250-ETRN > 250-AUTH LOGIN PLAIN GSSAPI DIGEST-MD5 CRAM-MD5 > 250-DELIVERBY > 250 HELP > ETRN customer.com > 250 2.0.0 Queuing for node customer.com started > > If I run mailscanner (/etc/rc.d/init.d/MailScanner), etrn is disabled: > > Connected to x.com (x.x.x.x). > Escape character is '^]'. > 220 x.com ESMTP Sendmail 8.13.1/8.13.1; Wed, 11 Jan 2006 14:31:58 > -0800 > ehlo customer.com > 250-x.com Hello customer.com [y.y.y.u], pleased to meet you > 250-ENHANCEDSTATUSCODES > 250-PIPELINING > 250-8BITMIME > 250-SIZE > 250-DSN > 250-AUTH LOGIN PLAIN GSSAPI DIGEST-MD5 CRAM-MD5 > 250-DELIVERBY > 250 HELP > ETRN customer.com > 502 5.7.0 Sorry, we do not allow this operation > > I have spent hours trying to figure out why mailscanner disables > etrn, but failed. Anyone know what's up with this? > > -Dan > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ8Ygtfw32o+k+q+hAQHdMAgAr6taUWbY4pfd1B8c41qfkEeKGxvEzhYd URHiN0LdN14Mqjdi0IhLg+SUA3C8QglN3wZVpy3uL/ERpGdZt8bAc7UYzDOrYfWy 8TtE535Mptzu1pIKdIVUtyBsqeFsKjzgbLHxsiCGc6JigOjDbIOLGN406Xhs/iZZ Z+jh9MxfojvgmdiU3oDA9cej3kbeN4dUTVx8zlgN76HEC/oPGC1gQYHHFI6U9HOi 25hktWPKcftXNkX/97te4lq6hGyarYLAE0jDXHqL7WNNq9WCkuBVHUUkSjBGsHWc 44/yeaF1pCX8iyGyloy5pg01eb7lTkXuAlCG4GXvLuFdrMWoIPV2ng== =lyXc -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 12 09:30:43 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:42 2006 Subject: #!/bin/bash Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 12 Jan 2006, at 01:22, Nerijus Baliunas wrote: > On Wed, 11 Jan 2006 14:48:14 +0000 Julian Field > wrote: > >> Didn't know == would work on bash, so I'm probably safe on that one. >> There were only 2 or 3 offending scripts anyway. >> >> I have done what people suggested, and have released 4.50.6 for you >> all to play with. > > You replaced in Sophos.install and update_virus_scanners, but there > are > still /bin/bash in: > panda-autoupdate Only used on Linux, where bash is available anyway. > Sophos.install.linux > Sophos.install.solaris Must remove these, they are deprecated. Just use Sophos.install. > check_MailScanner.cron > update_phishing_sites.cron > update_virus_scanners.cron These are only used in Linux installs to control the cron jobs, so bash is available. > > These files can probably be deleted: > > bin/.#mailscanner.1.142.2.157 > docs/.#ChangeLog* > docs/.#downloads.shtml* > empty directories /bin/old, /bin/wrappers, SpamAssassin.patches, / > etc/old, > /etc/reports/cat, /etc/tcp, /lib/MailScanner/Custom, /docs/install/tcp Will do. Thanks for reporting those. > > Regards, > Nerijus > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ8Yhxfw32o+k+q+hAQFjlQgArjflS6d8IQx+M6lQQnsf/7/B1Fhx/uKP HXdmnMJMhlz1pZzKKAetWGudP8hQxBNNumlaWXU0RnFuvCNutakybTWa0PhiR/0G zjSwrxzYunpPfgPmbcm9OPJQEe7TNG7+q0UxSlZp+3IMuYJ0b9qOctbB39uJZUDf Jxhk0Z/qEYpQonLMNRqHs+Akijdjyg4gxMO0QFkDhb/92ylCMx6ZRkGcyU+kSuYs XJl6AGLsag+F1sGjzt64geUhYbQfExw2QbFQxoym9bQJzrqtsxd5Hu8bBiKruVS6 F30FI6zm+DktqMqgQeJIbEdS65EAImt4XU0bxxNlBFIVUfXTKBex8Q== =Xk1U -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 12 09:33:27 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:42 2006 Subject: MailScanner and SpamAssassin sitewide help! Message-ID: -----BEGIN PGP SIGNED MESSAGE----- If, by saying it is not working, that nothing is going through spamc or spamd, then that is because MailScanner doesn't use them. It does it more efficiently than that and calls the SpamAssassin function library directly. On 12 Jan 2006, at 02:56, Steve Maller wrote: > OK, I've built and installed MailScanner 4.49 and SpamAssassin > 3.1.0 on a mostly stock Fedora Core 4 box. I'm running Sendmail > with a bunch of RBLs and TLS enabled. > > Email comes through MailScanner, but whatever I do, I do not seem > to get any mail to go through SpamAssassin. I tried manually > starting spamd with the -d option. > > I have the "Use SpamAssassin" directive enabled, but like I said, > nothing works. > > My intention is to run this site-wide, and I have consulted with > the various FAQs and nothing seems to work. > > Again, email *is* being delivered, but SpamAssassin is never > getting used. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ8Yiafw32o+k+q+hAQEp2Qf+ISL+o7t8KCE53opIf+XTjl3IIXf0TqN+ QHtqI76xpCH5BF4ZoD64NpzmHl8gJ3VbSF0VeLwgJSbczEWowcIY/bA2+vfERY6u 74cop00TM12BdIm+StXgs72QfazuXBVyBWhF1VnMtNneRYs5KAXDeB8MXfwAsQty o6sB64tpBcTeAl5ND58XB0pAl/xVIQ5prLbPFsYsWLS97RDtuTjVEPnP5Sr5IRCx jE9K1Ei9WXkJ7wJu7z+NBtJRytesuMMsrZDJbU8Rp2Pm1P0bafBdl14UCfDgVbgf 7dAAcgeBwZxpJSZPs8BGez74VCqZ1kj3EzSKpTVFXf3VfNdXm6ahIw== =L8XQ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 12 09:31:35 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:42 2006 Subject: SA 3.1.0 for FC3 Message-ID: -----BEGIN PGP SIGNED MESSAGE----- My easy-to-install ClamAV-SA-install.tar.gz package will install it for you and do some of the setup as well. On 12 Jan 2006, at 02:44, Tony Enderby wrote: > Hi List, > > Just wondering if anyone has a link to an RPM for SA 3.1.0 for Fedora > Core 3 that they have successfully installed in production. > > Many thanks, > > Tony. > > ---------------------------------------------------------------------- > ------------- > Scanned by MailWash Australia - http://www.mailwash.com.au > ---------------------------------------------------------------------- > ------------- > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.3 (Build 2932) iQEVAwUBQ8Yh+Pw32o+k+q+hAQEW2wgAu/+0hMoiwkTPh1o2z0/hCl9hF2xoUGCq 5UqBGEIpWXTu7jXfm10k/+snq/8krLScuT8J/U9Uz0ktqfZDxtQHF/XqhRQGJWp5 Whihqt8xz/4ejftkp88oxsKZB+MLuXB24oG1EpKTZoymT67TZRPJO/cUOMhKDYel viAUP9MU9Rn/gWcdOpHgHoccSns3YjiOt98t7RyF8YAdyQSSjw+I9XimNaMy39Bj oejN62H4urAaTxr6VfY2x/rIrYjNUVPO4A+Fy0ZPlMLKn9Bkpwvkz4GrswqVDkil Gk1nunO1ElqJeqMxt1uxnQlfFjB2swHxHX0d0i5CK6hUAPVuCZdgaA== =DPo3 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From P.G.M.Peters at UTWENTE.NL Thu Jan 12 10:44:52 2006 From: P.G.M.Peters at UTWENTE.NL (Peter Peters) Date: Thu Jan 12 21:31:42 2006 Subject: mailscanner breaks etrn Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Julian Field wrote on 12-1-2006 10:26: > It's very simple. ETRN extracts mail from the incoming queue, before > MailScanner has had a chance to process it. So it is an ideal route > for your users to get viruses and spam. > So I have to disable ETRN. I am looking at a system using ETRN and MailScanner. ETRN and the normal sendmail run on different IP addresses with different .cf files. Mail is delivered on the normal sendmail (with ETRN disabled), gets scanned and is forwarded with mailertable entries to the etrn system which only accepts incoming mail from the normal sendmail system (as far as I have tested this now). The ETRN system uses his own mail queue and there is no interaction on queue level between the two sendmail instances. - -- Peter Peters, senior beheerder (Security) Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE) Universiteit Twente, Postbus 217, 7500 AE Enschede telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQFDxjMjMbmy+DDgnIURAu7mAKDV2y5nfhdPdFj32AD0G8RN1hZCcACg2G9Z 6DhlmoqMqjHO7pFEV3KgRhk= =UQa3 -----END PGP SIGNATURE----- ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From chardlist at CHARD.NET Thu Jan 12 11:29:30 2006 From: chardlist at CHARD.NET (chardlist) Date: Thu Jan 12 21:31:42 2006 Subject: Some Messages Double Scanned Message-ID: I'm noticing that some messages are getting double-scanned by MailScanner. Any thoughts on this? Here are headers from a sample message. X-ChardNet-MailScanner-SpamCheck: not spam, SpamAssassin (score=3.593, required 5, DATE_IN_FUTURE_03_06 0.07, HTML_50_60 0.10, HTML_MESSAGE 0.00, MIME_HTML_MOSTLY 0.28, MPART_ALT_DIFF 1.50, RAZOR2_CF_RANGE_51_100 1.49, RAZOR2_CHECK 0.15), not spam, SpamAssassin (score=3.199, required 5, BAYES_50 0.00, DATE_IN_FUTURE_03_06 1.96, HTML_50_60 0.13, HTML_MESSAGE 0.00, MIME_HTML_MOSTLY 1.10) X-ChardNet-MailScanner-SpamScore: 3, 3 I'm running MailScanner 4.47.4 on Redhat 9 with Exim 4.52 Thanks for any assistance, -Brendan ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From KevinS at BMRB.CO.UK Thu Jan 12 11:32:07 2006 From: KevinS at BMRB.CO.UK (Spicer, Kevin) Date: Thu Jan 12 21:31:42 2006 Subject: New virus Message-ID: See below... http://isc.sans.org/diary.php?storyid=1035 Has anyone seen these? Looks like an interesting attack vector, I don't think these files would be blocked by any of the default rules - so we have to rely on AV only. For now we're blocking those domains on our web proxies and blocking message.zip in MailScanner -- Kevin Spicer Unix Systems Specialist Millward Brown UK Limited ================================================================= BMRB wins two BMRA awards - http://www.bmrb.co.uk _________________________________________________________________ This message (and any attachment) is intended only for the recipient and may contain confidential and/or privileged material. If you have received this in error, please contact the sender and delete this message immediately. Disclosure, copying or other action taken in respect of this email or in reliance on it is prohibited. BMRB Limited accepts no liability in relation to any personal emails, or content of any email which does not directly relate to our business. +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 12 11:07:27 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:42 2006 Subject: Thunderbird understanding SpamAssassin Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Thunderbird 1.5 has been released. To quote from the help: "Trust junk mail headers set by will automatically recognize mail that is marked by a separate junk mail filtering program. Very often, your ISP or mail server will install such a filtering program, which adds special headers to your email before it is retrieved by Thunderbird. By setting this option, you do not have to create special filters to recognize these. Currently supports: SpamAssassin and SpamPal." What headers is it using? I obviously want to change the default spam actions in MailScanner to generate the headers that it recognises. I have googled for it and can't find anything useful. --  Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! [ Part 2, Application/PGP-SIGNATURE 498bytes. ] [ Unable to print this part. ] From MailScanner at ecs.soton.ac.uk Thu Jan 12 12:11:46 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:42 2006 Subject: SpamAssassin cache stats Message-ID: -----BEGIN PGP SIGNED MESSAGE----- > - --------- TOTALS --------- > Total records: 560 > First seen (oldest): 74137 sec > First seen (newest): 3 sec > Last seen (oldest): 74137 sec > Last seen (newest): 3 sec > Cache Hit Rate 40% 40% hit rate! It's making a great difference to the load on the machine. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8ZHhPw32o+k+q+hAQGWhwf9GgIGj8EopMT4M8k8cH38SsdSUAoNCE4g Pzv+EgJlcZxAzC0xspMHmtNdVwIgZa8H1pGCcah6BU6OnsWXFNMgHQYtybg35qEF N2iZ/w4LnICErJZ7TKU9d/crN6Ocf5vGPug/vfUkYQRMRM9wr2xndS5HTHAE9dcF KEyRJUs0sC1oxEPtorsVYe8uOgZwve+5VFcJ+GBpZBS5OUPfnkPjwCVbRivnIdJ4 BqArcb93voVLrEyoi5nLJ39iZA2NfmS0vdxraxLF6nR3t8eRdw0htd8yESIz19LA icrIEuwHY79aoi6MnvTi1Mp15ACylggtvFwpJ2oeEEvWbrCamCCP1g== =1iQw -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From john at TRADOC.FR Thu Jan 12 11:37:00 2006 From: john at TRADOC.FR (John Wilcock) Date: Thu Jan 12 21:31:42 2006 Subject: Thunderbird understanding SpamAssassin Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Julian Field wrote: > Thunderbird 1.5 has been released. > > To quote from the help: > > "Trust junk mail headers set by will automatically recognize mail that > is marked by a separate junk mail filtering program. Very often, your > ISP or mail server will install such a filtering program, which adds > special headers to your email before it is retrieved by Thunderbird. By > setting this option, you do not have to create special filters to > recognize these. Currently supports: SpamAssassin and SpamPal." > > What headers is it using? > I obviously want to change the default spam actions in MailScanner to > generate the headers that it recognises. > > I have googled for it and can't find anything useful. You can find out exactly what it's looking for in the SpamAssassin.sfd file in C:\Program Files\Mozilla Thunderbird\defaults\messenger Alternatively you can tell people to use a custom definition file in their profile folder to teach it about MailScanner's headers. See http://forums.mozillazine.org/viewtopic.php?t=276420 for a brief explanation. I've attached my MailScanner.sfd file but of course it needs adapting for each user to take account of the %org-name%. John. -- -- Over 3000 webcams from ski resorts around the world - www.snoweye.com -- Translate your technical documents and web pages - www.tradoc.fr ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! [ Part 2: "Attached Text" ] version="8" logging="yes" name="MailScannerYes" enabled="yes" type="1" action="JunkScore" actionValue="100" condition="OR (\"X-Tradoc-MailScanner-SpamCheck\",begins with,"spam")" name="MailScannerNo" enabled="yes" type="1" action="JunkScore" actionValue="0" condition="OR (\"X-Tradoc-MailScanner-SpamCheck\",begins with,"not spam")" ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From KevinS at BMRB.CO.UK Thu Jan 12 12:17:15 2006 From: KevinS at BMRB.CO.UK (Spicer, Kevin) Date: Thu Jan 12 21:31:42 2006 Subject: New virus Message-ID: Typical, that arrived around the same time I sent the message. However my point really was not the virus itself, but the attack vector which isn't (I think) caught by anything other than the AV scanners. -----Original Message----- From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Craig Retief (CSFS) Sent: 12 January 2006 11:53 To: MAILSCANNER@JISCMAIL.AC.UK Subject: Re: [MAILSCANNER] New virus ClamAV has been Updated to 1239 which includes the Virus. Notification from ClamAV follows: ClamAV database updated (2006-Jan-12 11:36 +0000): daily.cvd version: 1239 Submission: 196768 Sender: Anonymous Submission notes: Same as 197535. Added: No Submission: 197535 Sender: Alex Added: JS.Feebs.C Added: Worm.Feebs.C Added: Worm.Feebs.C-rkit Virus name alias: Worm.Win32.Feebs.k (Kaspersky AVP) Submission: 197678 Sender: Anonymous Submission notes: Same as 197535. Added: No Best regards, Diego d'Ambra See below... http://isc.sans.org/diary.php?storyid=1035 Has anyone seen these? Looks like an interesting attack vector, I don't think these files would be blocked by any of the default rules - so we have to rely on AV only. For now we're blocking those domains on our web proxies and blocking message.zip in MailScanner -- Kevin Spicer Unix Systems Specialist Millward Brown UK Limited ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ================================================================= BMRB wins two BMRA awards - http://www.bmrb.co.uk _________________________________________________________________ This message (and any attachment) is intended only for the recipient and may contain confidential and/or privileged material. If you have received this in error, please contact the sender and delete this message immediately. Disclosure, copying or other action taken in respect of this email or in reliance on it is prohibited. BMRB Limited accepts no liability in relation to any personal emails, or content of any email which does not directly relate to our business. +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From spamtrap71892316634 at ANIME.NET Thu Jan 12 11:02:16 2006 From: spamtrap71892316634 at ANIME.NET (Dan Hollis) Date: Thu Jan 12 21:31:42 2006 Subject: mailscanner breaks etrn Message-ID: Julian Field wrote on 12-1-2006 10:26: > It's very simple. ETRN extracts mail from the incoming queue, before > MailScanner has had a chance to process it. So it is an ideal route > for your users to get viruses and spam. > So I have to disable ETRN. The whole point of ETRN in our case is we are a backup MX for a customer who runs their own mail server. They dont care one whit about mailscanner, and in fact do not want mailscanner processing it. They run their own filtering software on their own mailserver. We are a backup MX for their mailserver since they are in a remote location with poor satellite connectivity which often goes down. Can we please have ETRN an option? -Dan ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From lhaig at HAIGMAIL.COM Thu Jan 12 11:29:43 2006 From: lhaig at HAIGMAIL.COM (Lance Haig) Date: Thu Jan 12 21:31:43 2006 Subject: Lotus Notes Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Anyone here administer a notes environment? I have inherited a 6.5 system and would like to ask you a few questions off list. Apologies for using the list but I need to talk to someone who is a good administrator and this is the first place I thought of. Thanks Lance ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From drew at THEMARSHALLS.CO.UK Thu Jan 12 11:28:50 2006 From: drew at THEMARSHALLS.CO.UK (Drew Marshall) Date: Thu Jan 12 21:31:43 2006 Subject: problem with queues Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] On Wed, January 11, 2006 20:15, Harondel J. Sibble wrote: > Okay, got an mail relay box with an older version of MS on it. It's been pretty much happily running for a couple years now, planning an upgrade to the latest version later this month. > > System is running Mandrake 9.x and using postfix for the mta in the dual queue mode. And this time for the list. Please don't set your reply address as it does mean the list won't see replies and therefore there is a good chance you might only get half the help you could. Are these messaged truncated (An old MailScanner/ Postfix issue)? If so then that could be why they are sitting there. There is a good chance that they have been delivered previously. Are they reported with mailq? I would suggest moving to the single queue method, which should prevent this happening in the future. Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From craig at CSFS.CO.ZA Thu Jan 12 11:52:41 2006 From: craig at CSFS.CO.ZA (Craig Retief (CSFS)) Date: Thu Jan 12 21:31:43 2006 Subject: New virus Message-ID: ClamAV has been Updated to 1239 which includes the Virus. Notification from ClamAV follows: ClamAV database updated (2006-Jan-12 11:36 +0000): daily.cvd version: 1239 Submission: 196768 Sender: Anonymous Submission notes: Same as 197535. Added: No Submission: 197535 Sender: Alex Added: JS.Feebs.C Added: Worm.Feebs.C Added: Worm.Feebs.C-rkit Virus name alias: Worm.Win32.Feebs.k (Kaspersky AVP) Submission: 197678 Sender: Anonymous Submission notes: Same as 197535. Added: No Best regards, Diego d'Ambra See below... http://isc.sans.org/diary.php?storyid=1035 Has anyone seen these? Looks like an interesting attack vector, I don't think these files would be blocked by any of the default rules - so we have to rely on AV only. For now we're blocking those domains on our web proxies and blocking message.zip in MailScanner -- Kevin Spicer Unix Systems Specialist Millward Brown UK Limited ================================================================= BMRB wins two BMRA awards - http://www.bmrb.co.uk _________________________________________________________________ This message (and any attachment) is intended only for the recipient and may contain confidential and/or privileged material. If you have received this in error, please contact the sender and delete this message immediately. Disclosure, copying or other action taken in respect of this email or in reliance on it is prohibited. BMRB Limited accepts no liability in relation to any personal emails, or content of any email which does not directly relate to our business. +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From dmaluski at n1ety.com Thu Jan 12 13:23:48 2006 From: dmaluski at n1ety.com (Dean Maluski) Date: Thu Jan 12 21:31:43 2006 Subject: dccm active? Message-ID: I just setup dccm on a RedHat ES4 box. I followed instruction found in wiki here. http://wiki.mailscanner.info/doku.php? id=documentation:anti_spam:spamassassin:plugins:dcc:dccm_instead&s=Spamassassin I'm getting these statements in maillog. _____________________________________________ Jan 12 08:15:25 punk sendmail[15699]: k0CDFORG015699: Milter: data, reject=452 4.2.1 mail k0CDFORG015699 from 144.142.2.20 temporary greylist embargoed Jan 12 08:15:25 punk sendmail[15699]: k0CDFORG015699: to=, delay=00:00:01, pri=30776, stat=mail k0CDFORG015699 from 144.142.2.20 temporary greylist embargoed Jan 12 08:16:04 punk sendmail[15990]: k0CDG4wv015990: from=, size=2915, class=-60, nrcpts=1, msgid=<43C6567A.6080305@sterndata.com>, proto=SMTP, daemon=MTA, relay=hermes.apache.org [209.237.227.199] Jan 12 08:16:04 punk sendmail[15990]: k0CDG4wv015990: Milter: data, reject=452 4.2.1 mail k0CDG4wv015990 from 209.237.227.199 temporary greylist embargoed Jan 12 08:16:04 punk sendmail[15990]: k0CDG4wv015990: to=, delay=00:00:00, pri=140915, stat=mail k0CDG4wv015990 from 209.237.227.199 temporary greylist embargoed Jan 12 08:16:42 punk sendmail[15992]: k0CDGIiB015992: from=, size=577, class=0, nrcpts=1, msgid=<200601121316.k0CDGIiB015992@punk.n1ety.com>, proto=SMTP, daemon=MTA, relay=219-84-82-1-adsl-tpe.static.so-net.net.tw [219.84.82.1] ___________________________________________________________ And mail header looks like this. __________________________________________________________ X-DCC-NIET-Metrics: punk.n1ety.com 1080; bulk env_From=1 Body=1 Fuz1=1 Fuz2=many __________________________________________________________ Does temporary greylist embargoed mean that it is not in use? ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 12 14:24:24 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:43 2006 Subject: mailscanner breaks etrn Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 12 Jan 2006, at 11:02, Dan Hollis wrote: > Julian Field wrote on 12-1-2006 10:26: >> It's very simple. ETRN extracts mail from the incoming queue, before >> MailScanner has had a chance to process it. So it is an ideal route >> for your users to get viruses and spam. >> So I have to disable ETRN. > > The whole point of ETRN in our case is we are a backup MX for a > customer who runs their own mail server. They dont care one whit > about mailscanner, and in fact do not want mailscanner processing > it. They run their own filtering software on their own mailserver. > We are a backup MX for their mailserver since they are in a remote > location with poor satellite connectivity which often goes down. > > Can we please have ETRN an option? Just edit the init.d script. It's pretty obvious if I remember right. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8Zmmfw32o+k+q+hAQFgYAf9HQD7dTsLNNzRlCOkDka3kAf+nmN9zp7O SdT2xRrGVIlisMb1YnmriGoX878U7QZ4UAOP+UkY2agCV+sM+8sY54LoXK4N65ul /5XqFWMaFc3mQOEjyBmA60h4U1Na0aYY31VpccCqp5Jh4zlUPZfVY08/Kj2H8tBB 1VPM0kTs+8wp3aONBpN89FwvVpIccg0ODD1sFbm71oNsTDhxYSgL5ee4riOIk4Xu lAT7vzAb/guNX6tTCq72VlGJE3tDP1bE8Mn3MjElZG2t5JXZOw9jL5SsI6YOyvef 8fjKaLtV00NlTluEFKPfd8m5mIjQ6lGBeUR3pXwbaV1ZMM8TMClDqw== =5FdT -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 12 14:06:41 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:43 2006 Subject: Thunderbird understanding SpamAssassin Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 12 Jan 2006, at 11:37, John Wilcock wrote: > Julian Field wrote: >> Thunderbird 1.5 has been released. >> To quote from the help: >> "Trust junk mail headers set by will automatically recognize mail >> that is marked by a separate junk mail filtering program. Very >> often, your ISP or mail server will install such a filtering >> program, which adds special headers to your email before it is >> retrieved by Thunderbird. By setting this option, you do not have >> to create special filters to recognize these. Currently supports: >> SpamAssassin and SpamPal." >> What headers is it using? >> I obviously want to change the default spam actions in MailScanner >> to generate the headers that it recognises. >> I have googled for it and can't find anything useful. > > You can find out exactly what it's looking for in the > SpamAssassin.sfd file in C:\Program Files\Mozilla Thunderbird > \defaults\messenger > > Alternatively you can tell people to use a custom definition file > in their profile folder to teach it about MailScanner's headers. > See http://forums.mozillazine.org/viewtopic.php?t=276420 for a > brief explanation. > > I've attached my MailScanner.sfd file but of course it needs > adapting for each user to take account of the %org-name%. > > version="8" > logging="yes" > name="MailScannerYes" > enabled="yes" > type="1" > action="JunkScore" > actionValue="100" > condition="OR (\"X-Tradoc-MailScanner-SpamCheck\",begins with,"spam")" > name="MailScannerNo" > enabled="yes" > type="1" > action="JunkScore" > actionValue="0" > condition="OR (\"X-Tradoc-MailScanner-SpamCheck\",begins with,"not > spam")" To save users having to craft their own, the default SpamAssassin one can be used. Just use settings like this Spam Actions = deliver header "X-Spam-Status: Yes" High Scoring Spam Actions = delete Non Spam Actions = deliver header "X-Spam-Status: No" in your MailScanner.conf. Can someone add this to the Wiki please? - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8Zic/w32o+k+q+hAQGg5AgAhE5/fG/uovcgn8c8JsAUUwtbydNt7wZC OPwYEd4BS3D6ASREHB3RNyM4RMi4csEW5SdurjaAXVHfGbo4oufSvN0f+ITH9ssb gs6UWt0NBa4UqyHbpx7G6pJdw9n1pX2EXes57MGkcMklei6ENhOkVXztM50NrdyJ czIxcIVC2GW4CcJxkY8a8efGRffWq9Trpc/45/VMjxnR7ROYWg7o7JxcKCUmqsFS dnC0Gw6pP9Fi4VmRb7OZ0/uoLKlhNcpaY8c+c4x2ghtm3OlQTh2yJuRs8k6n87Kg Yk5wWPw06bv9s+50Ct7ji5qUW2INzn6GHWYuha+kmMoybAgc4zuPwQ== =q/EP -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 12 14:23:40 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:43 2006 Subject: New virus Message-ID: -----BEGIN PGP SIGNED MESSAGE----- The filename.rules.conf should by default be trapping *.hta files, even inside zip files. So it should still be caught by MailScanner, even without the AV engines. On 12 Jan 2006, at 12:17, Spicer, Kevin wrote: > Typical, that arrived around the same time I sent the message. > However > my point really was not the virus itself, but the attack vector which > isn't (I think) caught by anything other than the AV scanners. > > -----Original Message----- > From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On > Behalf Of Craig Retief (CSFS) > Sent: 12 January 2006 11:53 > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Re: [MAILSCANNER] New virus > > ClamAV has been Updated to 1239 which includes the Virus. > > Notification from ClamAV follows: > > ClamAV database updated (2006-Jan-12 11:36 +0000): daily.cvd > version: 1239 > > Submission: 196768 > Sender: Anonymous > Submission notes: Same as 197535. > Added: No > > Submission: 197535 > Sender: Alex > Added: JS.Feebs.C > Added: Worm.Feebs.C > Added: Worm.Feebs.C-rkit > Virus name alias: Worm.Win32.Feebs.k (Kaspersky AVP) > > Submission: 197678 > Sender: Anonymous > Submission notes: Same as 197535. > Added: No > > Best regards, > Diego d'Ambra > > > > > See below... > > http://isc.sans.org/diary.php?storyid=1035 > > Has anyone seen these? Looks like an interesting attack vector, I > don't > think these files would be blocked by any of the default rules - so we > have to rely on AV only. > > For now we're blocking those domains on our web proxies and blocking > message.zip in MailScanner > > -- > Kevin Spicer > Unix Systems Specialist > Millward Brown UK Limited > > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > ================================================================= > > BMRB wins two BMRA awards - http://www.bmrb.co.uk > _________________________________________________________________ > This message (and any attachment) is intended only for the > recipient and may contain confidential and/or privileged > material. If you have received this in error, please contact the > sender and delete this message immediately. Disclosure, copying > or other action taken in respect of this email or in > reliance on it is prohibited. BMRB Limited accepts no liability > in relation to any personal emails, or content of any email which > does not directly relate to our business. > +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8Zmbfw32o+k+q+hAQFz6ggAgl/hDhYJ2yhXP8kloRtQQLpdpXnb8sdK iaCkrpF2TjKgQf/cIXmFUnBbImZGEG62yrfWi73LlsYze+qtm8w54Cz+VDBE2EvP 4l1Npk3l0aYiUmRM1PhjFm2gneaNd1OIXzTVV113sKNyfMJlnQ+/MeLHZNMPciSp t9g+yiJfayVjmuolyvtasnEmJeDhwkTAqlyaa0oosJ2lUPhMrtng2FLx/72T8WeR em6wDYxTUWcgQXDtACKZuYRvU6uwvUy0HiZJ/QyokUo/BLt0nPcAW1iX2A8SwHw3 IYLh51YffN3HA0VZR2LfxHUR5i3DvhVM+HBwZ7AB06vFwVrGmMe7pQ== =4Xw7 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From prandal at HEREFORDSHIRE.GOV.UK Thu Jan 12 13:56:28 2006 From: prandal at HEREFORDSHIRE.GOV.UK (Randal, Phil) Date: Thu Jan 12 21:31:43 2006 Subject: Thunderbird understanding SpamAssassin Message-ID: Details are in bug 290237 (add UI for honoring ISP spam headers) here: https://bugzilla.mozilla.org/show_bug.cgi?id=290237 Cheers, Phil ---- Phil Randal Network Engineer Herefordshire Council Hereford, UK ________________________________________________________________________________ From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Julian Field Sent: 12 January 2006 11:07 To: MAILSCANNER@JISCMAIL.AC.UK Subject: Thunderbird understanding SpamAssassin Thunderbird 1.5 has been released. To quote from the help: "Trust junk mail headers set by will automatically recognize mail that is marked by a separate junk mail filtering program. Very often, your ISP or mail server will install such a filtering program, which adds special headers to your email before it is retrieved by Thunderbird. By setting this option, you do not have to create special filters to recognize these. Currently supports: SpamAssassin and SpamPal." What headers is it using? I obviously want to change the default spam actions in MailScanner to generate the headers that it recognises. I have googled for it and can't find anything useful. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ugob at CAMO-ROUTE.COM Thu Jan 12 14:11:28 2006 From: ugob at CAMO-ROUTE.COM (Ugo Bellavance) Date: Thu Jan 12 21:31:43 2006 Subject: dccm active? Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Dean Maluski wrote: > I just setup dccm on a RedHat ES4 box. > I followed instruction found in wiki here. > http://wiki.mailscanner.info/doku.php? > id=documentation:anti_spam:spamassassin:plugins:dcc:dccm_instead&s=Spamassassin > I'm getting these statements in maillog. > _____________________________________________ > Jan 12 08:15:25 punk sendmail[15699]: k0CDFORG015699: Milter: data, > reject=452 4.2.1 mail k0CDFORG015699 from 144.142.2.20 temporary > greylist embargoed > Jan 12 08:15:25 punk sendmail[15699]: k0CDFORG015699: > to=, delay=00:00:01, pri=30776, stat=mail > k0CDFORG015699 from 144.142.2.20 temporary greylist embargoed > Jan 12 08:16:04 punk sendmail[15990]: k0CDG4wv015990: from= return-36327-dmaluski=n1ety.com@spamassassin.apache.org>, size=2915, > class=-60, nrcpts=1, msgid=<43C6567A.6080305@sterndata.com>, proto=SMTP, > daemon=MTA, relay=hermes.apache.org [209.237.227.199] > Jan 12 08:16:04 punk sendmail[15990]: k0CDG4wv015990: Milter: data, > reject=452 4.2.1 mail k0CDG4wv015990 from 209.237.227.199 temporary > greylist embargoed > Jan 12 08:16:04 punk sendmail[15990]: k0CDG4wv015990: > to=, delay=00:00:00, pri=140915, stat=mail > k0CDG4wv015990 from 209.237.227.199 temporary greylist embargoed > Jan 12 08:16:42 punk sendmail[15992]: k0CDGIiB015992: > from=, size=577, class=0, nrcpts=1, > msgid=<200601121316.k0CDGIiB015992@punk.n1ety.com>, proto=SMTP, > daemon=MTA, relay=219-84-82-1-adsl-tpe.static.so-net.net.tw > [219.84.82.1] > ___________________________________________________________ > And mail header looks like this. > __________________________________________________________ > X-DCC-NIET-Metrics: punk.n1ety.com 1080; bulk env_From=1 Body=1 Fuz1=1 > Fuz2=many > __________________________________________________________ > Does temporary greylist embargoed mean that it is not in use? > From what I can see, it means that greylist if enabled and working. -- Ugo -> Please don't send a copy of your reply by e-mail. I read the list. -> Please avoid top-posting, long signatures and HTML, and cut the irrelevant parts in your replies. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From prandal at HEREFORDSHIRE.GOV.UK Thu Jan 12 14:05:28 2006 From: prandal at HEREFORDSHIRE.GOV.UK (Randal, Phil) Date: Thu Jan 12 21:31:43 2006 Subject: Thunderbird understanding SpamAssassin Message-ID: In C:\Program Files\Mozilla Thunderbird\defaults\messenger there's a SpamAssassin.sfd file whaich contails the lines: version="8" logging="yes" name="SpamAssassinYes" enabled="yes" type="1" action="JunkScore" actionValue="100" condition="OR (\"X-Spam-Status\",begins with,Yes) OR (\"X-Spam-Flag\",begins with,YES) OR (subject,begins with,***SPAM***)" name="SpamAssassinNo" enabled="yes" type="1" action="JunkScore" actionValue="0" condition="OR (\"X-Spam-Status\",begins with,No)" Key bits are the conditions tested. Phil ---- Phil Randal Network Engineer Herefordshire Council Hereford, UK ________________________________________________________________________________ From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of Julian Field Sent: 12 January 2006 11:07 To: MAILSCANNER@JISCMAIL.AC.UK Subject: Thunderbird understanding SpamAssassin Thunderbird 1.5 has been released. To quote from the help: "Trust junk mail headers set by will automatically recognize mail that is marked by a separate junk mail filtering program. Very often, your ISP or mail server will install such a filtering program, which adds special headers to your email before it is retrieved by Thunderbird. By setting this option, you do not have to create special filters to recognize these. Currently supports: SpamAssassin and SpamPal." What headers is it using? I obviously want to change the default spam actions in MailScanner to generate the headers that it recognises. I have googled for it and can't find anything useful. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From chardlist at CHARD.NET Thu Jan 12 15:39:11 2006 From: chardlist at CHARD.NET (chardlist) Date: Thu Jan 12 21:31:43 2006 Subject: Some Messages Double Scanned Message-ID: Some more information. It seems like the bayes rule checks are what is causing the problem. I have had a cron job that runs every week to execute the following commands to rebuild the bayes files and clear out old tokens. service MailScanner stop then... /usr/bin/sa-learn -C /usr/mailscanner/etc/spam.assassin.prefs.conf --force-expire then... chown mailnull:nobody /usr/mailscanner/bayes/bayes_* and finally... service MailScanner start The commands above are all executing just fine, but what I’ve noticed is that the bayes_seen file does not reduce in size as it normally has done. The bayes_toks file does get smaller as I would expect and has grown to 42MB. What’s the best way to proceed from here? Should I can the bayes files and have it start rebuilding from scratch, or is there a way to get them all working again? Thanks, -Brendan -----Original Message----- From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of chardlist Sent: Thursday, January 12, 2006 5:30 AM To: MAILSCANNER@JISCMAIL.AC.UK Subject: Some Messages Double Scanned I'm noticing that some messages are getting double-scanned by MailScanner. Any thoughts on this? Here are headers from a sample message. X-ChardNet-MailScanner-SpamCheck: not spam, SpamAssassin (score=3.593, required 5, DATE_IN_FUTURE_03_06 0.07, HTML_50_60 0.10, HTML_MESSAGE 0.00, MIME_HTML_MOSTLY 0.28, MPART_ALT_DIFF 1.50, RAZOR2_CF_RANGE_51_100 1.49, RAZOR2_CHECK 0.15), not spam, SpamAssassin (score=3.199, required 5, BAYES_50 0.00, DATE_IN_FUTURE_03_06 1.96, HTML_50_60 0.13, HTML_MESSAGE 0.00, MIME_HTML_MOSTLY 1.10) X-ChardNet-MailScanner-SpamScore: 3, 3 I'm running MailScanner 4.47.4 on Redhat 9 with Exim 4.52 Thanks for any assistance, -Brendan ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 12 16:28:29 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:43 2006 Subject: Some Messages Double Scanned Message-ID: [ The following text is in the "WINDOWS-1252" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] A couple of (okay, 3) points. If you decide to scrap the Bayes db, then you can get a good "starter" database from www.fsl.com/support. 4.50 has fixed problems with MailScanner doing the expiry run itself. So you can just let MailScanner handle the job for you. I would add a delay after the "service MailScanner stop" for, say, 30 to 60 seconds to give it time to shutdown as it may have locks on the file still in use when it runs the sa-learn. On 12 Jan 2006, at 15:39, chardlist wrote: Some more information.  It seems like the bayes rule checks are what is causing the problem.   I have had a cron job that runs every week to execute the following commands to rebuild the bayes files and clear out old tokens.   service MailScanner stop then... /usr/bin/sa-learn -C /usr/mailscanner/etc/spam.assassin.prefs.conf --force-expire then... chown mailnull:nobody /usr/mailscanner/bayes/bayes_* and finally... service MailScanner start   The commands above are all executing just fine, but what I^Òve noticed is that the bayes_seen file does not reduce in size as it normally has done.  The bayes_toks file does get smaller as I would expect and has grown to 42MB.   What^Òs the best way to proceed from here?  Should I can the bayes files and have it start rebuilding from scratch, or is there a way to get them all working again?   Thanks, -Brendan       -----Original Message----- From: MailScanner mailing list [mailto:MAILSCANNER@JISCMAIL.AC.UK] On Behalf Of chardlist Sent: Thursday, January 12, 2006 5:30 AM To: MAILSCANNER@JISCMAIL.AC.UK Subject: Some Messages Double Scanned   I'm noticing that some messages are getting double-scanned by MailScanner. Any thoughts on this?  Here are headers from a sample message.   X-ChardNet-MailScanner-SpamCheck: not spam, SpamAssassin (score=3.593,       required 5, DATE_IN_FUTURE_03_06 0.07, HTML_50_60 0.10,       HTML_MESSAGE 0.00, MIME_HTML_MOSTLY 0.28, MPART_ALT_DIFF 1.50,       RAZOR2_CF_RANGE_51_100 1.49, RAZOR2_CHECK 0.15), not spam, SpamAssassin (score=3.199,       required 5, BAYES_50 0.00, DATE_IN_FUTURE_03_06 1.96,       HTML_50_60 0.13, HTML_MESSAGE 0.00, MIME_HTML_MOSTLY 1.10) X-ChardNet-MailScanner-SpamScore: 3, 3     I'm running MailScanner 4.47.4 on Redhat 9 with Exim 4.52     Thanks for any assistance,   -Brendan --  Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! [ Part 2, Application/PGP-SIGNATURE 498bytes. ] [ Unable to print this part. ] From steve.swaney at fsl.com Thu Jan 12 18:18:21 2006 From: steve.swaney at fsl.com (Stephen Swaney) Date: Thu Jan 12 21:31:43 2006 Subject: Problems with charset gb2312 and mime headers Message-ID: [ The following text is in the "iso-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] We have a client who is having a problem with mailscanner/spamassassin that I have not seen before. Apparently mailscanner/spamassassin decodes replaces the RFC1522 encoded header if it's in charset gb2312, it doesn't replace the header if the header is encoded with UTF-8 or any other encoding. Here is a sample Subject: =?UTF-8?B?57q957qmMTHmnIjljp/msrnmnJ/otKfku7fmoLzov4XpgJ/kuIo=?= =?UTF-8?B?5omsM+e+juWFgw==?= this is not modified by mailscanner/spamassassin and when you view the raw source of the email in the mailbox it looks like: Subject: =?UTF-8?B?57q957qmMTHmnIjljp/msrnmnJ/otKfku7fmoLzov4XpgJ/kuIo=?= =?UTF-8?B?5omsM+e+juWFgw==?= which is correct whereas =?gb2312?B?xabUvDEx1MLUrdPNxtq79bzbuPHRuMvZyc/R7zPDwNSqIA==?= is replaced with gobblygook in the raw email by mailscanner/spamassassin when you view the raw source of the email in the mailbox as: Subject: ŦԼ11ÔÂÔ­ÓÍÆÚ»õ¼Û¸ñѸËÙÉÏÑï3ÃÀÔª Has anyone else run across this one? Thanks, Steve Stephen Swaney Fort Systems Ltd. stephen.swaney@fsl.com www.fsl.com ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From ssilva at SGVWATER.COM Thu Jan 12 17:34:55 2006 From: ssilva at SGVWATER.COM (Scott Silva) Date: Thu Jan 12 21:31:43 2006 Subject: New virus Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Julian Field spake the following on 1/12/2006 6:23 AM: > The filename.rules.conf should by default be trapping *.hta files, > even inside zip files. So it should still be caught by MailScanner, > even without the AV engines. > But having Maximum Archive Depth = 0 will prevent MailScanner from catching this in zip files, won't it? -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 12 18:45:38 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:43 2006 Subject: New virus Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Scott Silva wrote: >Julian Field spake the following on 1/12/2006 6:23 AM: > > >>The filename.rules.conf should by default be trapping *.hta files, >>even inside zip files. So it should still be caught by MailScanner, >>even without the AV engines. >> >> >> >But having Maximum Archive Depth = 0 will prevent MailScanner from >catching this in zip files, won't it? > > Yes. That is your choice to use that setting, I don't personally advise it. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Kevin_Miller at CI.JUNEAU.AK.US Thu Jan 12 19:25:10 2006 From: Kevin_Miller at CI.JUNEAU.AK.US (Kevin Miller) Date: Thu Jan 12 21:31:43 2006 Subject: New virus Message-ID: Julian Field wrote: > Scott Silva wrote: > >> Julian Field spake the following on 1/12/2006 6:23 AM: >> >> >>> The filename.rules.conf should by default be trapping *.hta files, >>> even inside zip files. So it should still be caught by MailScanner, >>> even without the AV engines. >>> >>> >>> >> But having Maximum Archive Depth = 0 will prevent MailScanner from >> catching this in zip files, won't it? >> >> > Yes. That is your choice to use that setting, I don't personally > advise it. What are the implications of setting Maximum Archive Depth = 2 (the default IIRC) and Allow Password-protected Archives = no? Will that break anything? The comments indicate that the archive depth should be set to 0 if disabling password-protected archives. I have a rules file for password protected archives, but it defaults for no. I like the protection from the passworded zip virus files, but would also like to insure that I'm protected on the hta, etc. front. And if I do set the archive depth back to 2, won't I start putting the kiebosh on legitimate .exe, and other files that folks zip to get past the normal attachment checking? Don't know how much of an issue that is right now but you know how users can get.... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 12 19:33:26 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 21:31:43 2006 Subject: New virus Message-ID: [ The following text is in the "ISO-8859-1" character set. ] [ Your display is set for the "US-ASCII" character set. ] [ Some characters may be displayed incorrectly. ] Kevin Miller wrote: > Julian Field wrote: > >> Scott Silva wrote: >> >> >>> Julian Field spake the following on 1/12/2006 6:23 AM: >>> >>> >>> >>>> The filename.rules.conf should by default be trapping *.hta files, >>>> even inside zip files. So it should still be caught by MailScanner, >>>> even without the AV engines. >>>> >>>> >>>> >>>> >>> But having Maximum Archive Depth = 0 will prevent MailScanner from >>> catching this in zip files, won't it? >>> >>> >>> >> Yes. That is your choice to use that setting, I don't personally >> advise it. >> > > What are the implications of setting Maximum Archive Depth = 2 (the > default IIRC) and Allow Password-protected Archives = no? Will that > break anything? > > The comments indicate that the archive depth should be set to 0 if > disabling password-protected archives. I have a rules file for password > protected archives, but it defaults for no. I like the protection from > the passworded zip virus files, but would also like to insure that I'm > protected on the hta, etc. front. > > And if I do set the archive depth back to 2, won't I start putting the > kiebosh on legitimate .exe, and other files that folks zip to get past > the normal attachment checking? Don't know how much of an issue that is > right now but you know how users can get.... > > ...Kevin > Yes, if you put the archive depth to 2, people won't be able to hide exes by putting them in zip files. If you do that, you will definitely need a way for users to pull files out of quarantine. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From Dave Thu Jan 12 19:35:45 2006 From: Dave (Dave) Date: Thu Jan 12 21:31:43 2006 Subject: [customer: RE: FW: test tues] Message-ID: On Wed, Jan 11, 2006 at 11:14:36AM -0700, Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem wrote: > On Wed, Jan 11, 2006 at 05:24:00PM +0100, shuttlebox wrote: > > On 1/11/06, Dave Shariff Yadallee - System Administrator a.k.a. The Root of > > the Problem wrote: > > > > > > Hold on, the customer is hvg@hvgsys.com and that is who it is going to. > > > > > > > Ok, missed that one. Could you then post the Sendmail logs regarding that > > exact message because the received headers doesn't contain the hvg-address > > either. > > > > Odd!! Here is what the maillog produced. > > Jan 10 12:47:24 doctor clamav-milter[768]: clamfi_envfrom: .com> > Jan 10 12:47:24 doctor clamav-milter[768]: clamfi_envrcpt: > Jan 10 12:47:25 doctor sendmail[20946]: k0AJlNgB020946: from= il.com>, size=1337, class=0, nrcpts=1, msgid=<7266dd760601101147t486c71f7l475df6 > 9e699ed986@mail.gmail.com>, proto=ESMTP, daemon=MTA, relay=wproxy.gmail.com [64. > 233.184.207] > Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: Received: by wproxy.gm > ail.com with SMTP id i24so2908959wra\n for ; Tue, 10 Jan > 2006 11:47:23 -0800 (PST) > Jan 10 12:47:25 doctor clamd[765]: Accepted connection on port 30890, fd 9 > Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: DomainKey-Signature: a > =rsa-sha1; q=dns; c=nofws;\n s=beta; d=gmail.com;\n h=received:mes > sage-id:date:from:to:subject:mime-version:content-type;\n b=i5n7W4F7v7zvZ > dtGqf0mqPRoQanauxlz4/69a76wcWS3MKkOjI2wHnVxsc5lyRuq3sbMkqLQe4nUOYh6DlFamCkAVwyeM > /BVHjBJToIA3R5X7j5YvA4NSTfYnjpbh8b6iE/K7Dr0bZ8VMgrm+Zc4NcMDyn7eXp28hg2DSqTItEo= > Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: Received: by 10.54.67. > 10 with SMTP id p10mr5662418wra;\n Tue, 10 Jan 2006 11:47:22 -0800 (PST) > Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: Received: by 10.54.102 > .5 with HTTP; Tue, 10 Jan 2006 11:47:22 -0800 (PST) > Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: Message-ID: <7266dd760 > 601101147t486c71f7l475df69e699ed986@mail.gmail.com> > Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: Date: Tue, 10 Jan 2006 > 12:47:22 -0700 > Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: From: Hartmut von Gaza > > Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: To: hvg@hvgsys.com > Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: Subject: test tues > Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: MIME-Version: 1.0 > Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_header: Content-Type: multipar > t/alternative; \n boundary="----=_Part_31960_20255549.1136922442864" > Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_eoh > Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_envbody: 402 bytes > Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_eom > Jan 10 12:47:25 doctor clamd[765]: stream: OK > Jan 10 12:47:25 doctor clamav-milter[768]: clamfi_eom: read stream: OK > Jan 10 12:47:25 doctor clamav-milter[768]: k0AJlNgB020946: clean message from artmutvongaza@gmail.com> > Jan 10 12:47:25 doctor sendmail[20946]: k0AJlNgB020946: Milter add: header: X-Vi > rus-Scanned: ClamAV version 0.88, clamav-milter version 0.87 on doctor.nl2k.ab.c > a > Jan 10 12:47:25 doctor sendmail[20946]: k0AJlNgB020946: Milter add: header: X-Vi > rus-Status: Clean > Jan 10 12:48:20 doctor sendmail[21172]: k0AJlNgB020946: to=, del > ay=00:00:56, xdelay=00:00:00, mailer=local, pri=121337, dsn=2.0.0, stat=Sent > Jan 10 12:48:20 doctor sendmail[21172]: k0AJlNgB020946: done; delay=00:00:56, nt > ries=1 > > > -- > > /peter > > > > ------------------------ MailScanner list ------------------------ > > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > > 'leave mailscanner' in the body of the email. > > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > > > Support MailScanner development - buy the book off the website! > > Any luck or do I need to produce any more logs? ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: 'leave mailscanner' in the body of the email. Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Jan 12 22:09:59 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 22:10:25 2006 Subject: ANNOUNCE: This list is moving too. Message-ID: <43C6D3B7.8000004@ecs.soton.ac.uk> The 2nd of the two MailScanner mailing lists is also moving home. I am disappointed at the level of service provided by Jiscmail.ac.uk as they appear to have a continuous trickle of server problems, usually just running out of disk space or their virus scanner failing and blocking all postings. I am now moving the main discussion list. The new address of this list will be mailscanner@lists.mailscanner.info I will move your subscription for you. Very many thanks are due to the folks at Blacknight Solutions for hosting the lists to me. They have provided me with a very good reliable service so far, and I am sure that will continue. If you have any hosting requirements, drop them a line! The only people who should have to move themselves are those who hide their address from the subscribers list on the Jiscmail list, as I cannot read your email address. You may need to update your mail filtering rules to reflect the new address. Thankyou for your continued support! -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From michele at blacknight.ie Thu Jan 12 22:12:40 2006 From: michele at blacknight.ie (Michele Neylon :: Blacknight) Date: Thu Jan 12 22:12:43 2006 Subject: first post? Message-ID: <43C6D458.9050309@blacknight.ie> Do I get to be the first to post to the new list's home? -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 From dhawal at netmagicsolutions.com Thu Jan 12 22:22:10 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Thu Jan 12 22:22:15 2006 Subject: ANNOUNCE: This list is moving too. In-Reply-To: <43C6D3B7.8000004@ecs.soton.ac.uk> References: <43C6D3B7.8000004@ecs.soton.ac.uk> Message-ID: <20060112222210.24328.qmail@mymail.netmagicians.com> Julian Field writes: > The 2nd of the two MailScanner mailing lists is also moving home. Excellent.. btw, what is the first one? [SNIP] > The new address of this list will be > mailscanner@lists.mailscanner.info > I will move your subscription for you. Just got mine.. :) > Very many thanks are due to the folks at Blacknight Solutions for hosting > the lists to me. They have provided me with a very good reliable service > so far, and I am sure that will continue. If you have any hosting > requirements, drop them a line! Thanks to the folks @ Blacknight from me as well. - dhawal From MailScanner at ecs.soton.ac.uk Thu Jan 12 22:35:34 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 12 22:35:52 2006 Subject: SpamAssassin cache stats In-Reply-To: <200601130827.28016.james@grayonline.id.au> References: <6CDD5AEB-A9FC-40DC-90B3-2C6ECB6EBCB1@ecs.soton.ac.uk> <200601130827.28016.james@grayonline.id.au> Message-ID: <43C6D9B6.3080805@ecs.soton.ac.uk> James Gray wrote: > On Thursday 12 January 2006 23:11, Julian Field wrote: > >> ?: subkeys.pgp.net: Host not found >> gpgkeys: HKP fetch error: Connection refused >> >> >>> - --------- TOTALS --------- >>> Total records: 560 >>> First seen (oldest): 74137 sec >>> First seen (newest): 3 sec >>> Last seen (oldest): 74137 sec >>> Last seen (newest): 3 sec >>> Cache Hit Rate 40% >>> >> 40% hit rate! It's making a great difference to the load on the machine. >> > > Hey that's a neat little stats display! Maybe I missed the note in the change > log...but how do you get it reveal the inner magic?? > analyse_SpamAssassin_cache (or analyze_SpamAssaassin_cache for those of you who can't spell real English :-) -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From paul at blacknight.ie Thu Jan 12 22:38:26 2006 From: paul at blacknight.ie (Paul Kelly :: Blacknight) Date: Thu Jan 12 22:38:26 2006 Subject: first post? In-Reply-To: <43C6D458.9050309@blacknight.ie> References: <43C6D458.9050309@blacknight.ie> Message-ID: <1137105506.20488.3.camel@localhost.localdomain> Bah! On Thu, 2006-01-12 at 22:12 +0000, Michele Neylon :: Blacknight wrote: > Do I get to be the first to post to the new list's home? > > -- > Mr Michele Neylon > Blacknight Solutions > Quality Business Hosting & Colocation > http://www.blacknight.ie/ > Tel. 1850 927 280 > Intl. +353 (0) 59 9183072 > Direct Dial: +353 (0)59 9183090 > Fax. +353 (0) 59 9164239 -- Paul Kelly Technical Director Blacknight Internet Solutions ltd Hosting, Colocation, Dedicated servers Tel: 059 9183072 DDI: 059 9183091 e-mail: paul@blacknight.ie From drew at themarshalls.co.uk Thu Jan 12 22:43:46 2006 From: drew at themarshalls.co.uk (Drew Marshall) Date: Thu Jan 12 22:43:59 2006 Subject: [MAILSCANNER] ANNOUNCE: This list is moving too. In-Reply-To: <20060112222210.24328.qmail@mymail.netmagicians.com> References: <43C6D3B7.8000004@ecs.soton.ac.uk> <20060112222210.24328.qmail@mymail.netmagicians.com> Message-ID: On 12 Jan 2006, at 22:22, Dhawal Doshy wrote: > Julian Field writes: >> The 2nd of the two MailScanner mailing lists is also moving home. > > Excellent.. btw, what is the first one? The announce list. > [SNIP] >> The new address of this list will be >> mailscanner@lists.mailscanner.info >> I will move your subscription for you. > > Just got mine.. :) Me too and the announce one. >> Very many thanks are due to the folks at Blacknight Solutions for >> hosting the lists to me. They have provided me with a very good >> reliable service so far, and I am sure that will continue. If you >> have any hosting requirements, drop them a line! > > Thanks to the folks @ Blacknight from me as well. Add me to that also. Drew PS the old list is now bouncing mail so the new one it is. Does this make me the first poster?? -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy From Kevin_Miller at ci.juneau.ak.us Thu Jan 12 22:44:15 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Thu Jan 12 22:44:20 2006 Subject: first post? Message-ID: <82895A755D1EA5458EC9E64021922AD2D155D7@city-exch-w3e.cbj.local> Michele Neylon :: Blacknight wrote: > Do I get to be the first to post to the new list's home? Looks like it. And a well deserved honor it is! Thanks for hosting the lists... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From brian at generationz.com Thu Jan 12 23:00:03 2006 From: brian at generationz.com (Brian Dowling) Date: Thu Jan 12 23:00:14 2006 Subject: [MAILSCANNER] ANNOUNCE: This list is moving too. In-Reply-To: References: <43C6D3B7.8000004@ecs.soton.ac.uk> <20060112222210.24328.qmail@mymail.netmagicians.com> Message-ID: <4619.90.0.0.38.1137106803.squirrel@texnet.com> OK, this thing is beginning to work to well. Where do I change my delivery address so it goes to my 'lists' address? > On 12 Jan 2006, at 22:22, Dhawal Doshy wrote: > >> Julian Field writes: >>> The 2nd of the two MailScanner mailing lists is also moving home. >> >> Excellent.. btw, what is the first one? > > The announce list. >> [SNIP] >>> The new address of this list will be >>> mailscanner@lists.mailscanner.info >>> I will move your subscription for you. >> >> Just got mine.. :) > Me too and the announce one. > >>> Very many thanks are due to the folks at Blacknight Solutions for >>> hosting the lists to me. They have provided me with a very good >>> reliable service so far, and I am sure that will continue. If you >>> have any hosting requirements, drop them a line! >> >> Thanks to the folks @ Blacknight from me as well. > > Add me to that also. > > Drew > > PS the old list is now bouncing mail so the new one it is. Does this > make me the first poster?? > > -- > In line with our policy, this message has > been scanned for viruses and dangerous > content by MailScanner, and is believed to be clean. > www.themarshalls.co.uk/policy > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! > From mkettler at evi-inc.com Thu Jan 12 23:07:13 2006 From: mkettler at evi-inc.com (Matt Kettler) Date: Thu Jan 12 23:07:26 2006 Subject: Some Messages Double Scanned In-Reply-To: References: <019201c6178e$577fb560$a000a8c0@sangria> Message-ID: <43C6E121.80006@evi-inc.com> Julian Field wrote: > A couple of (okay, 3) points. > > If you decide to scrap the Bayes db, then you can get a good "starter" > database from www.fsl.com/support . I know it's been talked about before, but you talk about starter databases as being a good thing in all respects. I feel it necessary to point out the drawbacks. Starter databases, while necessary for some, are in general at best highly suboptimal. You really should discourage their use except when necessary due to lack of starter training data from the actual site to work with. Drawback 1: SA extensively tokenizes mail headers, inclusive of sender and recipient addresses. None of these tokens will be at all useful on any site other than the site that generated it and are a complete waste space. Drawback 1.1: You're forcing SA to activate bayes by inflating the mail counts without ANY relevant header tokens. This creates a pretty distorted view until some local training kicks in. Drawback 2: The strength of bayes lies in it's adaptation to YOUR mail patterns. While most sites have common spam patterns, most sites have very different nonspam patterns. A starter database lacks this knowledge of what YOUR nonspam looks like. Unless your email precisely fits the profile of the starter database your results will be less than optimal. If your profile differs greatly your results will be fairly poor. Conclusion: If you don't have 200 spam and 200 ham emails, a starter database may be useful to you. However, it should be supplemented with at least a few local messages, and preferably as many as possible to get the header tokens up to par. If you have plenty of samples to work with, you'll be much better off using your own mail and passing on the starter. From steve.swaney at fsl.com Thu Jan 12 23:09:24 2006 From: steve.swaney at fsl.com (Stephen Swaney) Date: Thu Jan 12 23:09:27 2006 Subject: first post? In-Reply-To: <43C6D458.9050309@blacknight.ie> Message-ID: <200601122309.k0CN9PdT004900@bkserver.blacknight.ie> Guess so :) Thanks for taking over the list! Steve Stephen Swaney Fort Systems Ltd. stephen.swaney@fsl.com www.fsl.com > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Michele Neylon :: Blacknight > Sent: Thursday, January 12, 2006 5:13 PM > To: mailscanner@lists.mailscanner.info > Subject: first post? > > Do I get to be the first to post to the new list's home? > > -- > Mr Michele Neylon > Blacknight Solutions > Quality Business Hosting & Colocation > http://www.blacknight.ie/ > Tel. 1850 927 280 > Intl. +353 (0) 59 9183072 > Direct Dial: +353 (0)59 9183090 > Fax. +353 (0) 59 9164239 > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! From nerijus at users.sourceforge.net Thu Jan 12 23:12:32 2006 From: nerijus at users.sourceforge.net (Nerijus Baliunas) Date: Thu Jan 12 23:12:41 2006 Subject: ANNOUNCE: This list is moving too. In-Reply-To: <20060112222210.24328.qmail@mymail.netmagicians.com> References: <43C6D3B7.8000004@ecs.soton.ac.uk> <20060112222210.24328.qmail@mymail.netmagicians.com> Message-ID: <20060112231120.DF4B5BB9B@mx.dtiltas.lt> On Fri, 13 Jan 2006 03:52:10 +0530 Dhawal Doshy wrote: > > The 2nd of the two MailScanner mailing lists is also moving home. > > Excellent.. btw, what is the first one? Announce list. Regards, Nerijus From mcalnek at pcplace.ca Thu Jan 12 23:16:40 2006 From: mcalnek at pcplace.ca (Milton Calnek) Date: Thu Jan 12 23:16:41 2006 Subject: first post? In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D155D7@city-exch-w3e.cbj.local> References: <82895A755D1EA5458EC9E64021922AD2D155D7@city-exch-w3e.cbj.local> Message-ID: <43C6E358.8030300@pcplace.ca> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, Any chance we can get the list name in the subject? Kevin Miller wrote: > Michele Neylon :: Blacknight wrote: > >>Do I get to be the first to post to the new list's home? > > > Looks like it. And a well deserved honor it is! Thanks for hosting the > lists... > > ...Kevin - -- PC Place - Just clicks away Milton Calnek PC Place www.pcplace.ca 306-359-6939 mcalnek@pcplace.ca -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (GNU/Linux) Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org iD8DBQFDxuNXHgnbf2T2QqMRAvtZAJ90r5683b7Bqq0jr0g6KN+kcFjvPACgrjHk Q+BQkqVzfZTw9/KJ+HFNanE= =A15T -----END PGP SIGNATURE----- -- DISCLAIMER: The information transmitted is intended only for the addressee and may contain confidential, proprietary and/or privileged material. Any unauthorized review, distribution or other use of or the taking of any action in reliance upon this information is prohibited. If you received this in error, please contact the sender and delete or destroy this message and any copies. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. MailScanner thanks transtec Computers for their support. From michele at blacknight.ie Thu Jan 12 23:26:29 2006 From: michele at blacknight.ie (Michele Neylon :: Blacknight) Date: Thu Jan 12 23:26:33 2006 Subject: [MAILSCANNER] ANNOUNCE: This list is moving too. In-Reply-To: <4619.90.0.0.38.1137106803.squirrel@texnet.com> References: <43C6D3B7.8000004@ecs.soton.ac.uk> <20060112222210.24328.qmail@mymail.netmagicians.com> <4619.90.0.0.38.1137106803.squirrel@texnet.com> Message-ID: <43C6E5A5.3020300@blacknight.ie> Brian Dowling wrote: > OK, this thing is beginning to work to well. Where do I change my delivery > address so it goes to my 'lists' address? To change your options go to: http://lists.mailscanner.info/mailman/listinfo/mailscanner -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 From dnsadmin at 1bigthink.com Thu Jan 12 23:32:47 2006 From: dnsadmin at 1bigthink.com (dnsadmin 1bigthink.com) Date: Thu Jan 12 23:32:56 2006 Subject: first post? In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D155D7@city-exch-w3e.cbj.l ocal> References: <82895A755D1EA5458EC9E64021922AD2D155D7@city-exch-w3e.cbj.local> Message-ID: <6.2.3.4.0.20060112183128.0640d688@mxt.1bigthink.com> At 05:44 PM 1/12/2006, you wrote: >Michele Neylon :: Blacknight wrote: > > Do I get to be the first to post to the new list's home? > >Looks like it. And a well deserved honor it is! Thanks for hosting the >lists... > >...Kevin The sender's address is being revealed in the FROM: field. The previous list did not behave that way. Simple tweak? Cheers, Glenn From ka at pacific.net Fri Jan 13 00:30:07 2006 From: ka at pacific.net (Ken A) Date: Fri Jan 13 00:30:09 2006 Subject: ANNOUNCE: This list is moving too. In-Reply-To: <43C6D3B7.8000004@ecs.soton.ac.uk> References: <43C6D3B7.8000004@ecs.soton.ac.uk> Message-ID: <43C6F48F.5000704@pacific.net> > ...believes that the attachment to this > message sent to you is Unsolicited Commercial Email (spam). > From: mailscanner-bounces@lists.mailscanner.info > Subject: Welcome to the "MailScanner" mailing list And your whitelists! Ken Julian Field wrote: > > You may need to update your mail filtering rules to reflect the new > address. > From michele at blacknight.ie Fri Jan 13 00:34:28 2006 From: michele at blacknight.ie (Michele Neylon:: Blacknight.ie) Date: Fri Jan 13 00:34:30 2006 Subject: first post? In-Reply-To: <6.2.3.4.0.20060112183128.0640d688@mxt.1bigthink.com> References: <82895A755D1EA5458EC9E64021922AD2D155D7@city-exch-w3e.cbj.local> <6.2.3.4.0.20060112183128.0640d688@mxt.1bigthink.com> Message-ID: <43C6F594.5090309@blacknight.ie> dnsadmin 1bigthink.com wrote: > At 05:44 PM 1/12/2006, you wrote: > >> Michele Neylon :: Blacknight wrote: >> > Do I get to be the first to post to the new list's home? >> >> Looks like it. And a well deserved honor it is! Thanks for hosting the >> lists... >> >> ...Kevin > > > The sender's address is being revealed in the FROM: field. The previous > list did not behave that way. Simple tweak? I've just looked at an email that Julian posted to the old list from earlier today and it looks the same to me -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 From paul at welshfamily.com Fri Jan 13 00:44:04 2006 From: paul at welshfamily.com (Paul Welsh) Date: Fri Jan 13 00:44:21 2006 Subject: Which control panel, distro and MTA? Message-ID: <200601130044.k0D0iBtY009729@mail.espmail.net> It's new server time again. I'm currently running RH9 with the 42go control panel and Sendmail. I run SpamAssassin as well as MailScanner. I'm happy enough with this configuration but Progeny have stopped supplying patches for RH9 and my server can't cope with the traffic (a faster server will cure this). I want to accomplish the move to a new server in the least possible length of time. I want the server to last around 3 years before I have to upgrade the OS. I'm therefore inclined to go for CentOS. My second choice would be Debian. In terms of MTA I'm happy with Sendmail and would really prefer to stick with it, rather than have to learn Postfix or Exim. From what I can see, RHEL 4 (and therefore CentOS 4) uses Sendmail by default, which suits me well. Debian, it seems, uses Exim4 by default. The 42go control panel is, apparently, very slow to write changes but I can live with this. I'm familiar with it and it doesn't interfere with MailScanner or SpamAssassin. So, I either stick with 42go or move to DirectAdmin or another control panel. DirectAdmin uses Exim4 as its MTA and, from reading the DirectAdmin forum, it seems there's a fair bit of fiddling about to get MailScanner working on it. On the other hand, if DirectAdmin will save me time in other ways then I'll consider it. Advice and comments appreciated. From shuttlebox at gmail.com Fri Jan 13 00:57:43 2006 From: shuttlebox at gmail.com (shuttlebox) Date: Fri Jan 13 00:57:47 2006 Subject: Some Messages Double Scanned In-Reply-To: <43C6E121.80006@evi-inc.com> References: <019201c6178e$577fb560$a000a8c0@sangria> <43C6E121.80006@evi-inc.com> Message-ID: <625385e30601121657s4c7cafa2hac29cb39f314fbb5@mail.gmail.com> On 1/13/06, Matt Kettler wrote: > > Conclusion: If you don't have 200 spam and 200 ham emails, a starter > database > may be useful to you. I have never used the starter db:s, it takes only an hour or so until Bayes starts scoring in my case. Unless the mail flow is really low it might be easiest to just wait for it to kick in. -- /peter -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060113/f1da17eb/attachment.html From michele at blacknight.ie Fri Jan 13 00:58:38 2006 From: michele at blacknight.ie (Michele Neylon:: Blacknight.ie) Date: Fri Jan 13 00:58:41 2006 Subject: Which control panel, distro and MTA? In-Reply-To: <200601130044.k0D0iBtY009729@mail.espmail.net> References: <200601130044.k0D0iBtY009729@mail.espmail.net> Message-ID: <43C6FB3E.3000807@blacknight.ie> Paul Welsh wrote: > It's new server time again. I'm currently running RH9 with the 42go control > panel and Sendmail. I run SpamAssassin as well as MailScanner. I'm happy > enough with this configuration but Progeny have stopped supplying patches > for RH9 and my server can't cope with the traffic (a faster server will cure > this). > > I want to accomplish the move to a new server in the least possible length > of time. I want the server to last around 3 years before I have to upgrade > the OS. I'm therefore inclined to go for CentOS. My second choice would be > Debian. In terms of MTA I'm happy with Sendmail and would really prefer to > stick with it, rather than have to learn Postfix or Exim. From what I can > see, RHEL 4 (and therefore CentOS 4) uses Sendmail by default, which suits > me well. Debian, it seems, uses Exim4 by default. > > The 42go control panel is, apparently, very slow to write changes but I can > live with this. I'm familiar with it and it doesn't interfere with > MailScanner or SpamAssassin. So, I either stick with 42go or move to > DirectAdmin or another control panel. DirectAdmin uses Exim4 as its MTA > and, from reading the DirectAdmin forum, it seems there's a fair bit of > fiddling about to get MailScanner working on it. On the other hand, if > DirectAdmin will save me time in other ways then I'll consider it. > > Advice and comments appreciated. > Paul I've configured MailScanner on plenty of DirectAdmin servers on our network without any issues. The HOWTO on the DirectAdmin forums is terrible, so I'm not surprised that you found it confusing :) I've written a rough howto, which I intend to put online once I've cleaned it up a bit Michele -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 From paul at blacknight.ie Fri Jan 13 01:02:45 2006 From: paul at blacknight.ie (Paul Kelly :: Blacknight) Date: Fri Jan 13 01:02:44 2006 Subject: Which control panel, distro and MTA? In-Reply-To: <200601130044.k0D0iBtY009729@mail.espmail.net> References: <200601130044.k0D0iBtY009729@mail.espmail.net> Message-ID: <1137114165.20488.14.camel@localhost.localdomain> Hi Paul, On Fri, 2006-01-13 at 00:44 +0000, Paul Welsh wrote: > It's new server time again. I'm currently running RH9 with the 42go control > panel and Sendmail. I run SpamAssassin as well as MailScanner. I'm happy > enough with this configuration but Progeny have stopped supplying patches > for RH9 and my server can't cope with the traffic (a faster server will cure > this). > *cough* 42go Is probably the worst webhosting control panel available. I say this because we used it for quite some time (still have 3 redhat 9 boxes running with it). > I want to accomplish the move to a new server in the least possible length > of time. I want the server to last around 3 years before I have to upgrade > the OS. I'm therefore inclined to go for CentOS. My second choice would be > Debian. In terms of MTA I'm happy with Sendmail and would really prefer to > stick with it, rather than have to learn Postfix or Exim. From what I can > see, RHEL 4 (and therefore CentOS 4) uses Sendmail by default, which suits > me well. Debian, it seems, uses Exim4 by default. We're currently in a migration cycle. Moving old DA boxes to newer hardware and moving 42go boxes to DA. As far as I know the MailScanner configs are mostly the same for both types of boxes. Obviously Exim has a few gotchas .. but once you know what they are, itis fine to work with. CentOs is indeed a good choice. We've probably got 60 or so boxes running it, maybe a few more. Its life cycle is perfect for web hosting as it means you can get at least 2.5/3 years out of it while it is fully supported. > > The 42go control panel is, apparently, very slow to write changes but I can > live with this. I'm familiar with it and it doesn't interfere with > MailScanner or SpamAssassin. So, I either stick with 42go or move to > DirectAdmin or another control panel. DirectAdmin uses Exim4 as its MTA > and, from reading the DirectAdmin forum, it seems there's a fair bit of > fiddling about to get MailScanner working on it. On the other hand, if > DirectAdmin will save me time in other ways then I'll consider it. The guys on the forum are not known for their excellent skill sets. Mostly they use DA because it allows "point and drool" administration. Anything outside the box is a mammoth task for them. We've about 15-20 shared hosting boxes running Directadmin and all have MailScanner/spamassasin/pyzor/rayzor etc installed. Take a leap of faith, go with directadmin/centos/mailscanner. I assure you once its all working you won't look back. You can always ask here for tips etc ;) Paul -- Paul Kelly Technical Director Blacknight Internet Solutions ltd Hosting, Colocation, Dedicated servers Tel: 059 9183072 DDI: 059 9183091 e-mail: paul@blacknight.ie From mkettler at evi-inc.com Fri Jan 13 01:07:22 2006 From: mkettler at evi-inc.com (Matt Kettler) Date: Fri Jan 13 01:07:42 2006 Subject: ANNOUNCE: This list is moving too. In-Reply-To: <43C6F48F.5000704@pacific.net> References: <43C6D3B7.8000004@ecs.soton.ac.uk> <43C6F48F.5000704@pacific.net> Message-ID: <43C6FD4A.5070705@evi-inc.com> Ken A wrote: >> ...believes that the attachment to this message sent to you is >> Unsolicited Commercial Email (spam). From: >> mailscanner-bounces@lists.mailscanner.info Subject: Welcome to the >> "MailScanner" mailing list > > > And your whitelists! > > Ken And for what it's worth, SA 3.1.0's whitelist_from_spf won't work anymore (lists.mailscanner.info has no SPF record unlike jiscmail). So here's what I'm running with for now in case anyone wants to copy it. Caution: beware of word-wrap: #whitelist mailscanner mailing list whitelist_from_rcvd mailscanner-bounces@lists.mailscanner.info bkserver.blacknight.ie #Force bayes autolearning to be disabled for MailScanner list # (don't want to learn as ham any messages containing spam quotes) bayes_ignore_from mailscanner-bounces@lists.mailscanner.info bayes_ignore_to mailscanner@lists.mailscanner.info From mkettler at evi-inc.com Fri Jan 13 01:17:38 2006 From: mkettler at evi-inc.com (Matt Kettler) Date: Fri Jan 13 01:17:57 2006 Subject: first post? In-Reply-To: <6.2.3.4.0.20060112183128.0640d688@mxt.1bigthink.com> References: <82895A755D1EA5458EC9E64021922AD2D155D7@city-exch-w3e.cbj.local> <6.2.3.4.0.20060112183128.0640d688@mxt.1bigthink.com> Message-ID: <43C6FFB2.5060902@evi-inc.com> dnsadmin 1bigthink.com wrote: > At 05:44 PM 1/12/2006, you wrote: > >> Michele Neylon :: Blacknight wrote: >> > Do I get to be the first to post to the new list's home? >> >> Looks like it. And a well deserved honor it is! Thanks for hosting the >> lists... >> >> ...Kevin > > > The sender's address is being revealed in the FROM: field. The previous > list did not behave that way. Simple tweak? > Eh? Old: Reply-To: MailScanner mailing list Sender: MailScanner mailing list From: Matt Kettler To: MAILSCANNER@JISCMAIL.AC.UK X-MailScanner-From: owner-mailscanner@jiscmail.ac.uk New: From: Matt Kettler To: mailscanner@lists.mailscanner.info Reply-To: MailScanner discussion Sender: mailscanner-bounces@lists.mailscanner.info Errors-To: mailscanner-bounces@lists.mailscanner.info X-MailScanner-From: mailscanner-bounces@lists.mailscanner.info Both reveal the sender's address. In fact, I've *NEVER* seen a mailing list that does not. From michele at blacknight.ie Fri Jan 13 01:18:14 2006 From: michele at blacknight.ie (Michele Neylon:: Blacknight.ie) Date: Fri Jan 13 01:18:15 2006 Subject: ANNOUNCE: This list is moving too. In-Reply-To: <43C6FD4A.5070705@evi-inc.com> References: <43C6D3B7.8000004@ecs.soton.ac.uk> <43C6F48F.5000704@pacific.net> <43C6FD4A.5070705@evi-inc.com> Message-ID: <43C6FFD6.1010607@blacknight.ie> Matt Kettler wrote: > Ken A wrote: > >>>...believes that the attachment to this message sent to you is >>>Unsolicited Commercial Email (spam). From: >>>mailscanner-bounces@lists.mailscanner.info Subject: Welcome to the >>>"MailScanner" mailing list >> >> >>And your whitelists! >> >>Ken > > > > And for what it's worth, SA 3.1.0's whitelist_from_spf won't work anymore > (lists.mailscanner.info has no SPF record unlike jiscmail). gah I was going to give it one, but forgot :( -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 From Joshua.Koch at paccoast.com Fri Jan 13 01:23:52 2006 From: Joshua.Koch at paccoast.com (Joshua Koch) Date: Fri Jan 13 01:27:51 2006 Subject: Which control panel, distro and MTA? Message-ID: <2BD3058086A2A44896622E7CB3720BC2AFBB70@DRIFTWOOD.corporate.paccoast.com> We are running Red Hat 4.0 ES, sendmail, and webmin with the Mailscanner snap in, and it is running like a champ, we process around 160K e-mails a day, its been about 6 months since I had to reboot and that was only because I increased the RAM. Hope this helps. Joshua Koch -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Paul Welsh Sent: Thursday, January 12, 2006 4:44 PM To: mailscanner@lists.mailscanner.info Subject: Which control panel, distro and MTA? It's new server time again. I'm currently running RH9 with the 42go control panel and Sendmail. I run SpamAssassin as well as MailScanner. I'm happy enough with this configuration but Progeny have stopped supplying patches for RH9 and my server can't cope with the traffic (a faster server will cure this). I want to accomplish the move to a new server in the least possible length of time. I want the server to last around 3 years before I have to upgrade the OS. I'm therefore inclined to go for CentOS. My second choice would be Debian. In terms of MTA I'm happy with Sendmail and would really prefer to stick with it, rather than have to learn Postfix or Exim. From what I can see, RHEL 4 (and therefore CentOS 4) uses Sendmail by default, which suits me well. Debian, it seems, uses Exim4 by default. The 42go control panel is, apparently, very slow to write changes but I can live with this. I'm familiar with it and it doesn't interfere with MailScanner or SpamAssassin. So, I either stick with 42go or move to DirectAdmin or another control panel. DirectAdmin uses Exim4 as its MTA and, from reading the DirectAdmin forum, it seems there's a fair bit of fiddling about to get MailScanner working on it. On the other hand, if DirectAdmin will save me time in other ways then I'll consider it. Advice and comments appreciated. -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read the Wiki (http://wiki.mailscanner.info/). Support MailScanner development - buy the book off the website! This communication and any files or attachments transmitted with it may contain information that is copyrighted or confidential and exempt from disclosure under applicable law. It is intended solely for the use of the individual or the entity to which it is addressed. If you are not the intended recipient, you are herby notified that any use, dissemination, or copying of this communication is strictly prohibited. If you have received this communication in error, please notify us at once so that we may take the appropriate action and avoid troubling you further. Thank you for your cooperation. Contact information: Pacific Coast Companies, Inc. 1-916-631-6600 and ask for the e-mail administrator. -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 4495 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060112/65a8fce4/smime.bin From michael at dilworth.net Fri Jan 13 01:33:45 2006 From: michael at dilworth.net (Michael R. Dilworth (E-mail)) Date: Fri Jan 13 01:34:05 2006 Subject: first post? In-Reply-To: <43C6FFB2.5060902@evi-inc.com> Message-ID: <02ae01c617e1$65d38800$5713cc40@OCEANII> I support the first message, thanks for hosting the list.... However my inbox is beginning to look like a slashdot thread! I guess I better fix my filtering... fyi filter on headers: (with out the quotes) "List-Id: MailScanner discussion " From brent.bolin at gmail.com Fri Jan 13 03:33:08 2006 From: brent.bolin at gmail.com (BB) Date: Fri Jan 13 03:33:11 2006 Subject: (no subject) Message-ID: <787dcac20601121933h6acda715teee352fc3a9789ff@mail.gmail.com> -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060112/47183cca/attachment.html From james at grayonline.id.au Fri Jan 13 04:23:59 2006 From: james at grayonline.id.au (James Gray) Date: Fri Jan 13 04:24:38 2006 Subject: first post? In-Reply-To: <43C6D458.9050309@blacknight.ie> References: <43C6D458.9050309@blacknight.ie> Message-ID: <200601131524.00549.james@grayonline.id.au> On Friday 13 January 2006 09:12, Michele Neylon :: Blacknight wrote: > Do I get to be the first to post to the new list's home? Looks like you're the lucky one :) Thanks for taking over the list too! Cheers, James (The other reason I posted this "me too" type post, was I wanted to see if the new list munges my GPG sig like the old one did :P) -- He's like a function -- he returns a value, in the form of his opinion. It's up to you to cast it into a void or not. -- Phil Lapsley -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060113/e8c3a930/attachment.bin From glenn.steen at gmail.com Fri Jan 13 08:20:16 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Jan 13 08:20:19 2006 Subject: ANNOUNCE: This list is moving too. In-Reply-To: <43C6FFD6.1010607@blacknight.ie> References: <43C6D3B7.8000004@ecs.soton.ac.uk> <43C6F48F.5000704@pacific.net> <43C6FD4A.5070705@evi-inc.com> <43C6FFD6.1010607@blacknight.ie> Message-ID: <223f97700601130020q783fcad0w@mail.gmail.com> On 13/01/06, Michele Neylon:: Blacknight.ie wrote: > Matt Kettler wrote: (snip) > > And for what it's worth, SA 3.1.0's whitelist_from_spf won't work anymore > > (lists.mailscanner.info has no SPF record unlike jiscmail). > > gah > I was going to give it one, but forgot :( > Looks OK now. And I see you moved the archive too.... Very good work guys, thank you. -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From mailing_lists+mailscanner at caleotech.com Fri Jan 13 08:27:54 2006 From: mailing_lists+mailscanner at caleotech.com (Jens Ahlin) Date: Fri Jan 13 08:28:00 2006 Subject: Problems with charset gb2312 and mime headers Message-ID: <1485.172.16.1.115.1137140874.squirrel@www.caleotech.com> Hi, I have seen this happen sporadically but with charset ISO8859-1 encoded subject line. The client is a Outlook 2003 client. This does not happen often and I cannot se any pattern in the behaviour. I only notice this when the subject line contains swedish charchters. Any ideas ? Jens > We have a client who is having a problem with mailscanner/spamassassin that > I have not seen before. Apparently mailscanner/spamassassin decodes replaces > the RFC1522 encoded header if it's in charset gb2312, it doesn't replace the > header if the header is encoded with UTF-8 or any other encoding. > > Here is a sample > > Subject: =?UTF-8?B?57q957qmMTHmnIjljp/msrnmnJ/otKfku7fmoLzov4XpgJ/kuIo=? =?UTF-8?B?5omsM+e+juWFgw==? > this is not modified by mailscanner/spamassassin and when you view the raw source of the email in the mailbox it looks like: > > Subject: =?UTF-8?B?57q957qmMTHmnIjljp/msrnmnJ/otKfku7fmoLzov4XpgJ/kuIo=? =?UTF-8?B?5omsM+e+juWFgw==? > which is correct > > whereas > > =?gb2312?B?xabUvDEx1MLUrdPNxtq79bzbuPHRuMvZyc/R7zPDwNSqIA==? > is replaced with gobblygook in the raw email by mailscanner/spamassassin when you view the raw source of the email in the mailbox as: > > Subject: ????11??????????????????????3???? > > Has anyone else run across this one? > > Thanks, > > Steve > > Stephen Swaney > Fort Systems Ltd. > stephen.swaney@fsl.com > www.fsl.com > > ------------------------ MailScanner list ------------------------ To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > > From MailScanner at ecs.soton.ac.uk Fri Jan 13 09:00:30 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 13 09:00:41 2006 Subject: ANNOUNCE: This list is moving too. In-Reply-To: <43C6FD4A.5070705@evi-inc.com> References: <43C6D3B7.8000004@ecs.soton.ac.uk> <43C6F48F.5000704@pacific.net> <43C6FD4A.5070705@evi-inc.com> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Matt, Can you write an SPF record for me please? On 13 Jan 2006, at 01:07, Matt Kettler wrote: > Ken A wrote: >>> ...believes that the attachment to this message sent to you is >>> Unsolicited Commercial Email (spam). From: >>> mailscanner-bounces@lists.mailscanner.info Subject: Welcome to the >>> "MailScanner" mailing list >> >> >> And your whitelists! >> >> Ken > > > And for what it's worth, SA 3.1.0's whitelist_from_spf won't work > anymore > (lists.mailscanner.info has no SPF record unlike jiscmail). > > > So here's what I'm running with for now in case anyone wants to > copy it. > > Caution: beware of word-wrap: > > #whitelist mailscanner mailing list > whitelist_from_rcvd mailscanner-bounces@lists.mailscanner.info > bkserver.blacknight.ie > > #Force bayes autolearning to be disabled for MailScanner list > # (don't want to learn as ham any messages containing spam quotes) > > bayes_ignore_from mailscanner-bounces@lists.mailscanner.info > bayes_ignore_to mailscanner@lists.mailscanner.info > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8dsMvw32o+k+q+hAQHTPAgAi1jhbPohLc90IoeTT5Q70lzggKXL4BkU SmncBsdTc55EV0MjcnVcH5js5hr8Ibbf6uit4ZfB6q1Ae1Lp3yDwAcFUDngFfdll XhjfsGoTHQSlqfUfdn83wPKAszc047oFiuK7a6M9unWftLuwBqx34qBxWxRbUJLh 9MpNbR+BxMlehql8deWqZaa+WSlzWukD03Wwhx7ZEHcKQnQ2aEELmnSCvAZcYiRf cKgVPKpGYjEjurpIpH5tw3tvX2GrMQdNDo3DUMI21PamV5G/BUHBv9aGT0CtzEsz aHdAiZQThrSst/O6yud3ymYATvtmPza7DCG3+gRJR30NiuzjOwTjYA== =UHsW -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Fri Jan 13 09:03:17 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 13 09:03:28 2006 Subject: first post? In-Reply-To: <43C6E358.8030300@pcplace.ca> References: <82895A755D1EA5458EC9E64021922AD2D155D7@city-exch-w3e.cbj.local> <43C6E358.8030300@pcplace.ca> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Sorry, I think that looks really ugly and just means I get to see less of the subject in my mail app. It's easy enough to filter on other headers. On 12 Jan 2006, at 23:16, Milton Calnek wrote: > * PGP Signed by an unverified key: 01/12/06 at 23:16:39 > > Hi, > > Any chance we can get the list name in the subject? > > Kevin Miller wrote: >> Michele Neylon :: Blacknight wrote: >> >>> Do I get to be the first to post to the new list's home? >> >> >> Looks like it. And a well deserved honor it is! Thanks for >> hosting the >> lists... >> >> ...Kevin > > -- > PC Place - Just clicks away > > Milton Calnek > PC Place > www.pcplace.ca > 306-359-6939 > mcalnek@pcplace.ca > > * Milton Calnek > * 0x64F642A3 - Unverified (L) > > > -- > DISCLAIMER: The information transmitted is intended only for the > addressee and may contain confidential, proprietary and/or privileged > material. Any unauthorized review, distribution or other use of or > the taking of any action in reliance upon this information is > prohibited. If you received this in error, please contact the sender > and delete or destroy this message and any copies. > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. MailScanner thanks transtec > Computers for their support. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8ds2Pw32o+k+q+hAQHucAf+OXn55bUgoEt2PGMFZiiiGuBfh1Zi+aUP q7EMBCtLF8dpXhnfhc9DZ9Evk/VGytoDYIGO9U65tis2N8+tC0lpTMxzdjwUz2j9 apcJyxXnAZrPbd6vnXvNCohwvYGS9vIDBC6fv5oRnOQLQdhLxe8+wcx6gXK2/TCi 0L1KLx+EWpzJQdFi+Fb5GBQcPX98R6N+rka1BMp8thaeT/zsJcDSbhVDWIv5V7BB 988sdMG0J+B83cNQMwQQY1r03EySJqhWRwkVaQuZ3JNzdr85UemiiqpDKscqfLoo 7BsfsRA17m6JvsmNI85QeA/LcgLXor7gp2ncvCgqWXQ7iKzOifzH0g== =mxv1 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Fri Jan 13 09:04:38 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 13 09:04:51 2006 Subject: ANNOUNCE: This list is moving too. In-Reply-To: <223f97700601130020q783fcad0w@mail.gmail.com> References: <43C6D3B7.8000004@ecs.soton.ac.uk> <43C6F48F.5000704@pacific.net> <43C6FD4A.5070705@evi-inc.com> <43C6FFD6.1010607@blacknight.ie> <223f97700601130020q783fcad0w@mail.gmail.com> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 13 Jan 2006, at 08:20, Glenn Steen wrote: > On 13/01/06, Michele Neylon:: Blacknight.ie > wrote: >> Matt Kettler wrote: > (snip) >>> And for what it's worth, SA 3.1.0's whitelist_from_spf won't work >>> anymore >>> (lists.mailscanner.info has no SPF record unlike jiscmail). >> >> gah >> I was going to give it one, but forgot :( >> > Looks OK now. > And I see you moved the archive too.... Very good work guys, thank > you. I try not to do half-jobs :-) Fortunately I have a mailbox with every posting ever made to the list back to about 2001. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8dtKPw32o+k+q+hAQEb4wf9FaUrmziAXHJQL+MQclgkRoZisxE3VtME Fr3/pVIHmrOPRYl91y3u2V19IwX4BNh2ttAs9NdRPIdYsHURKWUoAyM8snM0YcSZ 7mIM2nFDVuQ4unfcBLEcIFQ9lKV1M/+AulSOq8MLL2mIvgfgtcXWChf05EC7zAem X8AZOUccc3ck/cs12TcOnCCNVJt7EcMzdIscRAiAfMZAAFwXwBtchYbPhIU/wGcL vUd4/C7wkM0Ai2qvFXSxmBFwQ5P8MQP5t7F/JsOuXrepTNTnA6giItiDCSvjaDM6 8kEwjwe8AhVzCUWzvJAG0jseSGCuGNJgV3No01iYtBmKMN9nA4HhMw== =p96W -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From nilesh.shastrakar at gmail.com Fri Jan 13 08:32:29 2006 From: nilesh.shastrakar at gmail.com (Nilesh Shastrakar) Date: Fri Jan 13 09:15:10 2006 Subject: [MailScanner] Spam Mails Message-ID: <95873e560601130032q54e44d8er3078ea68f2636178@mail.gmail.com> It was working fine till lastweek but now I am getting lots of spam mails How do I solve it ? The spams are Vigra and adult contents My configuration MailScanner-4.45.4-1 Clamav 0.88 Spammassassin -3.0.4-2.fc4 Please help Regards Nilesh -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060113/1d3ae4eb/attachment.html From glenn.steen at gmail.com Fri Jan 13 09:15:37 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Jan 13 09:15:41 2006 Subject: [MailScanner] Re: Problems with charset gb2312 and mime headers In-Reply-To: <1485.172.16.1.115.1137140874.squirrel@www.caleotech.com> References: <1485.172.16.1.115.1137140874.squirrel@www.caleotech.com> Message-ID: <223f97700601130115q24d12176h@mail.gmail.com> On 13/01/06, Jens Ahlin wrote: > Hi, > > I have seen this happen sporadically but with charset ISO8859-1 encoded > subject line. The client is a Outlook 2003 client. This does not happen > often and I cannot se any pattern in the behaviour. I only notice this > when the subject line contains swedish charchters. > > Any ideas ? > > Jens I have a vague recollection of seeing something like this a while back, but I think it got cleared be an MS upgrade.... I might be recollecting wrong though:-). What version of MS are you running? (snip) -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From paul at blacknight.ie Fri Jan 13 09:16:10 2006 From: paul at blacknight.ie (Paul Kelly :: Blacknight) Date: Fri Jan 13 09:16:12 2006 Subject: [MailScanner] test - Message-ID: <1137143770.9448.4.camel@localhost.localdomain> the subject should be prefixed by [MailScanner] .. /me crosses his fingers -- Paul Kelly Technical Director Blacknight Internet Solutions ltd Hosting, Colocation, Dedicated servers Tel: 059 9183072 DDI: 059 9183091 e-mail: paul@blacknight.ie From raymond at prolocation.net Fri Jan 13 09:33:10 2006 From: raymond at prolocation.net (raymond@prolocation.net) Date: Fri Jan 13 09:33:11 2006 Subject: [MailScanner] Spam Mails In-Reply-To: <95873e560601130032q54e44d8er3078ea68f2636178@mail.gmail.com> References: <95873e560601130032q54e44d8er3078ea68f2636178@mail.gmail.com> Message-ID: Hi! > It was working fine till lastweek but now I am getting lots of spam mails > How do I solve it ? > The spams are Vigra and adult contents > > My configuration > > MailScanner-4.45.4-1 > Clamav 0.88 > Spammassassin -3.0.4-2.fc4 You need to alter your rules continuesly. You cvan either have a look at SARE rules or start buying rules :) Bye, Raymond. From sathyakrishnadas at yahoo.co.in Fri Jan 13 09:37:29 2006 From: sathyakrishnadas at yahoo.co.in (sathya prakash) Date: Fri Jan 13 09:35:23 2006 Subject: setup on hpux Message-ID: <20060113093729.15463.qmail@web8322.mail.in.yahoo.com> hi, how to install MailScanner on HPUX. reply soon. confidence is key to success Send instant messages to your online friends http://in.messenger.yahoo.com -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060113/7fd4ee38/attachment.html From mailing_lists+mailscanner at caleotech.com Fri Jan 13 09:38:30 2006 From: mailing_lists+mailscanner at caleotech.com (Jens Ahlin) Date: Fri Jan 13 09:38:41 2006 Subject: [MailScanner] Re: Problems with charset gb2312 and mime headers In-Reply-To: <223f97700601130115q24d12176h@mail.gmail.com> References: <1485.172.16.1.115.1137140874.squirrel@www.caleotech.com> <223f97700601130115q24d12176h@mail.gmail.com> Message-ID: <1889.172.16.1.115.1137145110.squirrel@www.caleotech.com> Hi, When I saw this the last time I was running 4.45.4-1. I upgraded mailscanner yesterday to latest stable and have not seen it today but it's only happen sporadically. Hopefully I will never see this anymore... thanks, Jens > On 13/01/06, Jens Ahlin wrote: >> Hi, >> >> I have seen this happen sporadically but with charset ISO8859-1 encoded >> subject line. The client is a Outlook 2003 client. This does not happen >> often and I cannot se any pattern in the behaviour. I only notice this >> when the subject line contains swedish charchters. >> >> Any ideas ? >> >> Jens > > > I have a vague recollection of seeing something like this a while > back, but I think it got cleared be an MS upgrade.... I might be > recollecting wrong though:-). > What version of MS are you running? > (snip) > > -- > -- Glenn > email: glenn < dot > steen < at > gmail < dot > com > work: glenn < dot > steen < at > ap1 < dot > se > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! > > From wietse at boudisque.nl Fri Jan 13 09:38:34 2006 From: wietse at boudisque.nl (Wietse Muizelaar) Date: Fri Jan 13 09:38:44 2006 Subject: [MailScanner] test - References: <1137143770.9448.4.camel@localhost.localdomain> Message-ID: <01b901c61825$1f940a10$1373a8c0@BOUDIEWEB10> Is there also an option to disable this on individual base? Or does someone know a procmail recipe to delete such from the Subject-line? Kind regards, Wietse On Friday, January 13, 2006 10:16 AM, Paul Kelly :: Blacknight wrote: > the subject should be prefixed by [MailScanner] .. > > /me crosses his fingers > -- > Paul Kelly > Technical Director > Blacknight Internet Solutions ltd > Hosting, Colocation, Dedicated servers > Tel: 059 9183072 > DDI: 059 9183091 > e-mail: paul@blacknight.ie -- Met vriendelijke groet, Wietse Muizelaar ------------------------------------------- W.G. Muizelaar Boudisque Webmaster / ICT Drieharingstraat 5-31, 3511 BH Utrecht Telefoon: +31 (0)30 - 2394030 E-mail: wietse@boudisque.nl Website: www.boudisque.nl ------------------------------------------- From ramon at linux-labs.net Fri Jan 13 09:37:48 2006 From: ramon at linux-labs.net (Ramon Acedo) Date: Fri Jan 13 09:39:12 2006 Subject: Bounce non-spam messages Message-ID: <1137145068.30556.15.camel@pangeadm.upc.es> Hello, from time to time users ask if is there the possibility of bouncing emails from a particular sender. This sender can be a legitimate sender for the system (but not for the user asking for his messages to be dropped). Is there any way of managing this in MS? I'm trying to do it with Sendmail feature "delay_checks hater" and "access_db" but it isn't work as I expect. AFAIK MS doesn't implement this feature but I'm wondering if one could play with the bounce of the "Enable Spam Bounce" rules. I actually think it wouldn't be very complicated because the current rules allow 2 condition rules (i.e "From: a@b.c and To: myuser@mydoma.in bounce") Thanks, Ramon From technician at cenpac.net.nr Fri Jan 13 09:39:03 2006 From: technician at cenpac.net.nr (Jon Leeman) Date: Fri Jan 13 09:39:14 2006 Subject: [MailScanner] test - In-Reply-To: <1137143770.9448.4.camel@localhost.localdomain> References: <1137143770.9448.4.camel@localhost.localdomain> Message-ID: <43C77537.2050303@cenpac.net.nr> Paul Kelly :: Blacknight wrote: > the subject should be prefixed by [MailScanner] .. > > /me crosses his fingers uncross them.......it's working. Jon [Nauru, Central Pacific) From glenn.steen at gmail.com Fri Jan 13 09:44:25 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Jan 13 09:44:29 2006 Subject: [MailScanner] test - In-Reply-To: <1137143770.9448.4.camel@localhost.localdomain> References: <1137143770.9448.4.camel@localhost.localdomain> Message-ID: <223f97700601130144t4a780005s@mail.gmail.com> On 13/01/06, Paul Kelly :: Blacknight wrote: > the subject should be prefixed by [MailScanner] .. > Looks ugly, makes poor use of the screen resources ( less seen of the actual Subject in most MUAs), and will fool systems that rely on where Re: etc are inserted (gmail for one) into not threading conversations properly (cf the mailwatch list archives/forums)..... Can we please _not_ have this? It's easy enough making sorting rules on To: ...;) > /me crosses his fingers Cross them again and undo this:-) -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From martinh at solid-state-logic.com Fri Jan 13 09:56:33 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Fri Jan 13 09:56:43 2006 Subject: [MailScanner] test - In-Reply-To: <1137143770.9448.4.camel@localhost.localdomain> Message-ID: <007101c61827$a4246e80$3004010a@martinhlaptop> yay -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Paul Kelly :: Blacknight > Sent: 13 January 2006 09:16 > To: MailScanner discussion > Subject: [MailScanner] test - > > the subject should be prefixed by [MailScanner] .. > > /me crosses his fingers > -- > Paul Kelly > Technical Director > Blacknight Internet Solutions ltd > Hosting, Colocation, Dedicated servers > Tel: 059 9183072 > DDI: 059 9183091 > e-mail: paul@blacknight.ie > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From martinh at solid-state-logic.com Fri Jan 13 09:57:35 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Fri Jan 13 09:57:47 2006 Subject: [MailScanner] Spam Mails In-Reply-To: <95873e560601130032q54e44d8er3078ea68f2636178@mail.gmail.com> Message-ID: <007201c61827$c79b6940$3004010a@martinhlaptop> Hi Can you drop an example (full headers etc) to a web page somewhere. I can then run it over my comprehensive set of tests and see what SA rules fire. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Nilesh Shastrakar > Sent: 13 January 2006 08:32 > To: mailscanner@lists.mailscanner.info > Subject: [MailScanner] Spam Mails > > It was working fine till lastweek but now I am getting lots of spam mails > How do I solve it ? > The spams are Vigra and adult contents > > My configuration > > MailScanner-4.45.4-1 > Clamav 0.88 > Spammassassin -3.0.4-2.fc4 > > Please help > > Regards > Nilesh ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From sathya.prakash at hp.com Fri Jan 13 09:59:28 2006 From: sathya.prakash at hp.com (prakash, sathya) Date: Fri Jan 13 09:59:59 2006 Subject: Mailscanner on hpux Message-ID: Hi, How to install Mailscanner on hpux. From jags at csa.iisc.ernet.in Fri Jan 13 09:23:49 2006 From: jags at csa.iisc.ernet.in (jags@csa.iisc.ernet.in) Date: Fri Jan 13 10:00:12 2006 Subject: ANNOUNCE: This list is moving too. In-Reply-To: References: <43C6D3B7.8000004@ecs.soton.ac.uk> <43C6F48F.5000704@pacific.net> <43C6FD4A.5070705@evi-inc.com> Message-ID: <20060113092349.GA7669@purana.csa.iisc.ernet.in> UNSUBSCRIBE ME PLEASE... DONT KNOW HOW TO DO jagadish On Fri, Jan 13, 2006 at 09:00:30AM +0000, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > Matt, > > Can you write an SPF record for me please? > > On 13 Jan 2006, at 01:07, Matt Kettler wrote: > > > Ken A wrote: > >>> ...believes that the attachment to this message sent to you is > >>> Unsolicited Commercial Email (spam). From: > >>> mailscanner-bounces@lists.mailscanner.info Subject: Welcome to the > >>> "MailScanner" mailing list > >> > >> > >> And your whitelists! > >> > >> Ken > > > > > > And for what it's worth, SA 3.1.0's whitelist_from_spf won't work > > anymore > > (lists.mailscanner.info has no SPF record unlike jiscmail). > > > > > > So here's what I'm running with for now in case anyone wants to > > copy it. > > > > Caution: beware of word-wrap: > > > > #whitelist mailscanner mailing list > > whitelist_from_rcvd mailscanner-bounces@lists.mailscanner.info > > bkserver.blacknight.ie > > > > #Force bayes autolearning to be disabled for MailScanner list > > # (don't want to learn as ham any messages containing spam quotes) > > > > bayes_ignore_from mailscanner-bounces@lists.mailscanner.info > > bayes_ignore_to mailscanner@lists.mailscanner.info > > > > -- > > MailScanner mailing list > > MailScanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > > > Support MailScanner development - buy the book off the website! > > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.4 (Build 4042) > > iQEVAwUBQ8dsMvw32o+k+q+hAQHTPAgAi1jhbPohLc90IoeTT5Q70lzggKXL4BkU > SmncBsdTc55EV0MjcnVcH5js5hr8Ibbf6uit4ZfB6q1Ae1Lp3yDwAcFUDngFfdll > XhjfsGoTHQSlqfUfdn83wPKAszc047oFiuK7a6M9unWftLuwBqx34qBxWxRbUJLh > 9MpNbR+BxMlehql8deWqZaa+WSlzWukD03Wwhx7ZEHcKQnQ2aEELmnSCvAZcYiRf > cKgVPKpGYjEjurpIpH5tw3tvX2GrMQdNDo3DUMI21PamV5G/BUHBv9aGT0CtzEsz > aHdAiZQThrSst/O6yud3ymYATvtmPza7DCG3+gRJR30NiuzjOwTjYA== > =UHsW > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! From drew at themarshalls.co.uk Fri Jan 13 10:00:12 2006 From: drew at themarshalls.co.uk (Drew Marshall) Date: Fri Jan 13 10:00:19 2006 Subject: [MailScanner] test - In-Reply-To: <1137143770.9448.4.camel@localhost.localdomain> References: <1137143770.9448.4.camel@localhost.localdomain> Message-ID: <64273.194.70.180.170.1137146412.squirrel@webmail.r-bit.net> On Fri, January 13, 2006 09:16, Paul Kelly :: Blacknight wrote: > the subject should be prefixed by [MailScanner] .. > > /me crosses his fingers Indeed it is! /he can uncross fingers :-) Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy From jags at csa.iisc.ernet.in Fri Jan 13 09:27:23 2006 From: jags at csa.iisc.ernet.in (jags@csa.iisc.ernet.in) Date: Fri Jan 13 10:02:52 2006 Subject: ANNOUNCE: This list is moving too. In-Reply-To: References: <43C6D3B7.8000004@ecs.soton.ac.uk> <43C6F48F.5000704@pacific.net> <43C6FD4A.5070705@evi-inc.com> <43C6FFD6.1010607@blacknight.ie> <223f97700601130020q783fcad0w@mail.gmail.com> Message-ID: <20060113092723.GB7669@purana.csa.iisc.ernet.in> UNSUBSCRIBE ME PLEASE. jagadish On Fri, Jan 13, 2006 at 09:04:38AM +0000, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > > On 13 Jan 2006, at 08:20, Glenn Steen wrote: > > > On 13/01/06, Michele Neylon:: Blacknight.ie > > wrote: > >> Matt Kettler wrote: > > (snip) > >>> And for what it's worth, SA 3.1.0's whitelist_from_spf won't work > >>> anymore > >>> (lists.mailscanner.info has no SPF record unlike jiscmail). > >> > >> gah > >> I was going to give it one, but forgot :( > >> > > Looks OK now. > > And I see you moved the archive too.... Very good work guys, thank > > you. > > I try not to do half-jobs :-) > > Fortunately I have a mailbox with every posting ever made to the list > back to about 2001. > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.4 (Build 4042) > > iQEVAwUBQ8dtKPw32o+k+q+hAQEb4wf9FaUrmziAXHJQL+MQclgkRoZisxE3VtME > Fr3/pVIHmrOPRYl91y3u2V19IwX4BNh2ttAs9NdRPIdYsHURKWUoAyM8snM0YcSZ > 7mIM2nFDVuQ4unfcBLEcIFQ9lKV1M/+AulSOq8MLL2mIvgfgtcXWChf05EC7zAem > X8AZOUccc3ck/cs12TcOnCCNVJt7EcMzdIscRAiAfMZAAFwXwBtchYbPhIU/wGcL > vUd4/C7wkM0Ai2qvFXSxmBFwQ5P8MQP5t7F/JsOuXrepTNTnA6giItiDCSvjaDM6 > 8kEwjwe8AhVzCUWzvJAG0jseSGCuGNJgV3No01iYtBmKMN9nA4HhMw== > =p96W > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! From drew at themarshalls.co.uk Fri Jan 13 10:02:53 2006 From: drew at themarshalls.co.uk (Drew Marshall) Date: Fri Jan 13 10:03:01 2006 Subject: [MailScanner] Spam Mails In-Reply-To: <95873e560601130032q54e44d8er3078ea68f2636178@mail.gmail.com> References: <95873e560601130032q54e44d8er3078ea68f2636178@mail.gmail.com> Message-ID: <64285.194.70.180.170.1137146573.squirrel@webmail.r-bit.net> On Fri, January 13, 2006 08:32, Nilesh Shastrakar wrote: > It was working fine till lastweek but now I am getting lots of spam mails > How do I solve it ? > The spams are Vigra and adult contents > > My configuration > > MailScanner-4.45.4-1 > Clamav 0.88 > Spammassassin -3.0.4-2.fc4 Can you post some logs or example extracts. Have you check out the wiki as there is some good advice in there. Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy From glenn.steen at gmail.com Fri Jan 13 10:03:33 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Jan 13 10:03:37 2006 Subject: [MailScanner] test - In-Reply-To: <01b901c61825$1f940a10$1373a8c0@BOUDIEWEB10> References: <1137143770.9448.4.camel@localhost.localdomain> <01b901c61825$1f940a10$1373a8c0@BOUDIEWEB10> Message-ID: <223f97700601130203t42ceb7a0h@mail.gmail.com> On 13/01/06, Wietse Muizelaar wrote: > Is there also an option to disable this on individual base? Or does someone > know a procmail recipe to delete such from the Subject-line? > > Kind regards, > Wietse > If I remember correctly this is a global administrative setting in mailman, unfortunately, so unless we can cinvince Paul to undo this, we'll have to dream up a "subject scrubber":). That wont work for us who read this list through things like gmail etc though. -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From a.peacock at chime.ucl.ac.uk Fri Jan 13 10:03:31 2006 From: a.peacock at chime.ucl.ac.uk (Anthony Peacock) Date: Fri Jan 13 10:03:40 2006 Subject: first post? In-Reply-To: <43C6E358.8030300@pcplace.ca> References: <82895A755D1EA5458EC9E64021922AD2D155D7@city-exch-w3e.cbj.local> <43C6E358.8030300@pcplace.ca> Message-ID: <43C77AF3.5060703@chime.ucl.ac.uk> Hi, Milton Calnek wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Hi, > > Any chance we can get the list name in the subject? Please don't put the list name in the Subject. There are plenty of suitable headers that enable filtering, and the extra charaters in the Subject line just push the real information further to the right. > > Kevin Miller wrote: >> Michele Neylon :: Blacknight wrote: >> >>> Do I get to be the first to post to the new list's home? >> >> Looks like it. And a well deserved honor it is! Thanks for hosting the >> lists... >> >> ...Kevin > > - -- > PC Place - Just clicks away > > Milton Calnek > PC Place > www.pcplace.ca > 306-359-6939 > mcalnek@pcplace.ca > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.2 (GNU/Linux) > Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org > > iD8DBQFDxuNXHgnbf2T2QqMRAvtZAJ90r5683b7Bqq0jr0g6KN+kcFjvPACgrjHk > Q+BQkqVzfZTw9/KJ+HFNanE= > =A15T > -----END PGP SIGNATURE----- > > -- > DISCLAIMER: The information transmitted is intended only for the > addressee and may contain confidential, proprietary and/or privileged > material. Any unauthorized review, distribution or other use of or > the taking of any action in reliance upon this information is > prohibited. If you received this in error, please contact the sender > and delete or destroy this message and any copies. > -- Anthony Peacock CHIME, Royal Free & University College Medical School WWW: http://www.chime.ucl.ac.uk/~rmhiajp/ "The most exciting phrase to hear in science, the one that heralds new discoveries, is not 'Eureka!' but 'That's funny....'" -- Isaac Asimov From a.peacock at chime.ucl.ac.uk Fri Jan 13 10:04:45 2006 From: a.peacock at chime.ucl.ac.uk (Anthony Peacock) Date: Fri Jan 13 10:04:52 2006 Subject: [MailScanner] test - In-Reply-To: <1137143770.9448.4.camel@localhost.localdomain> References: <1137143770.9448.4.camel@localhost.localdomain> Message-ID: <43C77B3D.8070001@chime.ucl.ac.uk> Paul Kelly :: Blacknight wrote: > the subject should be prefixed by [MailScanner] .. > > /me crosses his fingers I want to vote for turning this off again. -- Anthony Peacock CHIME, Royal Free & University College Medical School WWW: http://www.chime.ucl.ac.uk/~rmhiajp/ "The most exciting phrase to hear in science, the one that heralds new discoveries, is not 'Eureka!' but 'That's funny....'" -- Isaac Asimov From john at tradoc.fr Fri Jan 13 10:10:10 2006 From: john at tradoc.fr (John Wilcock) Date: Fri Jan 13 10:10:29 2006 Subject: [MailScanner] test - In-Reply-To: <1137143770.9448.4.camel@localhost.localdomain> References: <1137143770.9448.4.camel@localhost.localdomain> Message-ID: <43C77C82.8030600@tradoc.fr> Paul Kelly :: Blacknight wrote: > the subject should be prefixed by [MailScanner] .. > > /me crosses his fingers Is this a user-selectable option, like it was on the Jiscmail listserv? John. -- -- Over 3000 webcams from ski resorts around the world - www.snoweye.com -- Translate your technical documents and web pages - www.tradoc.fr From paul at blacknight.ie Fri Jan 13 10:16:01 2006 From: paul at blacknight.ie (Paul Kelly :: Blacknight) Date: Fri Jan 13 10:16:05 2006 Subject: [MailScanner] test - In-Reply-To: <223f97700601130144t4a780005s@mail.gmail.com> References: <1137143770.9448.4.camel@localhost.localdomain> <223f97700601130144t4a780005s@mail.gmail.com> Message-ID: <1137147362.9448.8.camel@localhost.localdomain> On Fri, 2006-01-13 at 10:44 +0100, Glenn Steen wrote: > Looks ugly, makes poor use of the screen resources ( less seen of the > actual Subject in most MUAs), and will fool systems that rely on where > Re: etc are inserted (gmail for one) into not threading conversations > properly (cf the mailwatch list archives/forums)..... Can we please > _not_ have this? > It's easy enough making sorting rules on To: ...;) Its gone. Julian doesn't want it. Regards, Paul -- Paul Kelly Technical Director Blacknight Internet Solutions ltd Hosting, Colocation, Dedicated servers Tel: 059 9183072 DDI: 059 9183091 e-mail: paul@blacknight.ie From sathya.prakash at hp.com Fri Jan 13 10:15:37 2006 From: sathya.prakash at hp.com (prakash, sathya) Date: Fri Jan 13 10:16:55 2006 Subject: (no subject) Message-ID: Hi, How to install Mailscanner on hpux. Please answer. Please reply soon. Waiting for ur reply.. Regards sathya From martinh at solid-state-logic.com Fri Jan 13 10:17:18 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Fri Jan 13 10:17:28 2006 Subject: setup on hpux In-Reply-To: <20060113093729.15463.qmail@web8322.mail.in.yahoo.com> Message-ID: <007d01c6182a$88de9760$3004010a@martinhlaptop> Hi Have you looked at the generic Unix installer and instructions? -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of sathya prakash > Sent: 13 January 2006 09:37 > To: mailscanner@lists.mailscanner.info > Subject: setup on hpux > > hi, > how to install MailScanner on HPUX. > reply soon. > > > > > > > > > > > > confidence is key to success > > > HP.com home > > > > > Send instant messages to your online friends http://in.messenger.yahoo.com ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From MailScanner at ecs.soton.ac.uk Fri Jan 13 10:18:49 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 13 10:19:00 2006 Subject: test - In-Reply-To: <223f97700601130144t4a780005s@mail.gmail.com> References: <1137143770.9448.4.camel@localhost.localdomain> <223f97700601130144t4a780005s@mail.gmail.com> Message-ID: <7D722953-F6D1-4332-A90B-56519C551834@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- On 13 Jan 2006, at 09:44, Glenn Steen wrote: > On 13/01/06, Paul Kelly :: Blacknight wrote: >> the subject should be prefixed by [MailScanner] .. >> > > Looks ugly, makes poor use of the screen resources ( less seen of the > actual Subject in most MUAs), and will fool systems that rely on where > Re: etc are inserted (gmail for one) into not threading conversations > properly (cf the mailwatch list archives/forums)..... Can we please > _not_ have this? > It's easy enough making sorting rules on To: ...;) I entirely agree with you. You should find it is switched off if you make a new post. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8d+jPw32o+k+q+hAQGaTQf/VkO0DCipkzNbmXp5HY1ZwgPyz7UNc/pg p+hn9KGKkQAtruyWlJ/PtEVPNEBAqvuYZm61CP+U8S0njX8Z0+sWy9q7d5fPdVOY Be45uO06G3MUk7ZU79RuuqUbI0o9HlbiBnADMBJlrSdkvOsurzsz/f8MmgSJ4eIH hbqUSoV7UOrSK8nazfz7b4Z0HbFznWUjTRbRrRXWbvL0sciuOfZDdNry7Jt0WrxE 1d3nexVwn1zKnRtEHbt81YK9CsSFceeHvIIBXIbAk7t2YR2bR4f28Y1gTl6lpEsr WTQnwNOP2PjsVVzjoPgy3aj3pZtBLWHBjQxh2iQIjmbjaZ8DRdJUgg== =YsZJ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Fri Jan 13 10:31:35 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 13 10:31:44 2006 Subject: [MailScanner] test - In-Reply-To: <223f97700601130203t42ceb7a0h@mail.gmail.com> References: <1137143770.9448.4.camel@localhost.localdomain> <01b901c61825$1f940a10$1373a8c0@BOUDIEWEB10> <223f97700601130203t42ceb7a0h@mail.gmail.com> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 13 Jan 2006, at 10:03, Glenn Steen wrote: > On 13/01/06, Wietse Muizelaar wrote: >> Is there also an option to disable this on individual base? Or >> does someone >> know a procmail recipe to delete such from the Subject-line? >> >> Kind regards, >> Wietse >> > If I remember correctly this is a global administrative setting in > mailman, unfortunately, so unless we can cinvince Paul to undo this, > we'll have to dream up a "subject scrubber":). > That wont work for us who read this list through things like gmail > etc though. Which is why it is switched off :-) - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8eBivw32o+k+q+hAQHBaAf/X9of4c9oLGhcfmP7pP6A9gQi/c/OFOeM p62LKbu6Q5vq4WdPvKOhuc/KTLlEKCLgWHcXjl8XHkTLTX4gi5Y91uFz7EaVEvIZ N80xBZE/g/3CDQYdEc5v7/a05M4B8ICPkfSFEY1WyNtrf8f1NsV31C1pAaP3pv8a QbCbDjbrNZ1h31YeJA+1FiHg0rF56c05hBvBJXmGDfRDn2Ae7IxJCNHZeHtMKJsO /alKbjIPElU3FtzAQqeRbJe134X8PqU5IM5hTyyW+WHDcDgdc/UEA/cuhhM6eFXZ IEpBXGp7ZieCsSGfT4JHgLacF9MHdPj7+gRSfVJgBBLZKWe4TPfa7A== =mGxA -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Fri Jan 13 10:43:36 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 13 10:43:48 2006 Subject: [MailScanner] test - In-Reply-To: <43C77C82.8030600@tradoc.fr> References: <1137143770.9448.4.camel@localhost.localdomain> <43C77C82.8030600@tradoc.fr> Message-ID: <9D0C3DF0-6AAE-4746-AF46-96C7E7A14D37@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- On 13 Jan 2006, at 10:10, John Wilcock wrote: > Paul Kelly :: Blacknight wrote: >> the subject should be prefixed by [MailScanner] .. >> /me crosses his fingers > > Is this a user-selectable option, like it was on the Jiscmail > listserv? Apparently not. Rather an important feature to be missing, IMHO. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8eEW/w32o+k+q+hAQHrgAgAqTyZf+SFZ6SmCLJk5EzOi9yPcCvWZA// Ufh7zudVtnTSzQpGz39MkbIfq5OWdtpVBFPGv654WuKaBXJwh9MEe0DoVxseoQj3 bs2DDZmOMvQWcbCpT5dh/hUQXMpVzEEtCHQuqLPRmDwiRPvTNxQAkUQqvxmLpd3o zSFOWkCv1MNiAgLtiO49/izeTp9Mwu1ZxwOZ8KCud+5e8Nx7ORkk1nGh38SvojiC /E+F0wRhzX3vzk2R7fDgZSEp+NrWjn19I/1H0talJ8bB0AqCqSjitn8wDG8kPw+y hCc6txib7bnWZMTipIz6wd5zlhGWROmFl7RN8IwJIqWhpLJOf3XY0w== =cSz+ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From nilesh.shastrakar at gmail.com Fri Jan 13 08:47:43 2006 From: nilesh.shastrakar at gmail.com (Nilesh Shastrakar) Date: Fri Jan 13 10:44:47 2006 Subject: Spam Mails Message-ID: <95873e560601130047p797bd051nfaec6f8607e254f1@mail.gmail.com> It was working fine till lastweek but now I am getting lots of spam mails How do I solve it ? The spams are Vigra and adult contents My configuration MailScanner-4.45.4-1 Clamav 0.88 Spammassassin -3.0.4-2.fc4 Please help Regards Nilesh, -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060113/b1d3e984/attachment.html From paul at blacknight.ie Fri Jan 13 10:47:57 2006 From: paul at blacknight.ie (Paul Kelly :: Blacknight) Date: Fri Jan 13 10:48:00 2006 Subject: [MailScanner] test - In-Reply-To: <43C77C82.8030600@tradoc.fr> References: <1137143770.9448.4.camel@localhost.localdomain> <43C77C82.8030600@tradoc.fr> Message-ID: <1137149278.9448.14.camel@localhost.localdomain> On Fri, 2006-01-13 at 11:10 +0100, John Wilcock wrote: > Is this a user-selectable option, like it was on the Jiscmail listserv? > Nope. We're looking at all the options available in mailman. We'll see if there are any hacks or plugins that might be available for this sort of thing. Paul -- Paul Kelly Technical Director Blacknight Internet Solutions ltd Hosting, Colocation, Dedicated servers Tel: 059 9183072 DDI: 059 9183091 e-mail: paul@blacknight.ie From shuttlebox at gmail.com Fri Jan 13 10:50:33 2006 From: shuttlebox at gmail.com (shuttlebox) Date: Fri Jan 13 10:50:37 2006 Subject: ANNOUNCE: This list is moving too. In-Reply-To: <20060113092349.GA7669@purana.csa.iisc.ernet.in> References: <43C6D3B7.8000004@ecs.soton.ac.uk> <43C6F48F.5000704@pacific.net> <43C6FD4A.5070705@evi-inc.com> <20060113092349.GA7669@purana.csa.iisc.ernet.in> Message-ID: <625385e30601130250j7d44df14u58ffb47759864183@mail.gmail.com> On 1/13/06, jags@csa.iisc.ernet.in wrote: > > UNSUBSCRIBE ME PLEASE... > > DONT KNOW HOW TO DO > > > jagadish Maybe this link can be of some help... > http://lists.mailscanner.info/mailman/listinfo/mailscanner > -- /peter -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060113/8e05c754/attachment.html From steve.freegard at fsl.com Fri Jan 13 11:16:42 2006 From: steve.freegard at fsl.com (Steve Freegard) Date: Fri Jan 13 11:16:00 2006 Subject: Bounce non-spam messages In-Reply-To: <1137145068.30556.15.camel@pangeadm.upc.es> References: <1137145068.30556.15.camel@pangeadm.upc.es> Message-ID: <1137151002.26473.175.camel@localhost.localdomain> Hi Ramon, On Fri, 2006-01-13 at 10:37 +0100, Ramon Acedo wrote: > Hello, > > from time to time users ask if is there the possibility of bouncing > emails from a particular sender. This sender can be a legitimate sender > for the system (but not for the user asking for his messages to be > dropped). > > Is there any way of managing this in MS? I'm trying to do it with > Sendmail feature "delay_checks hater" and "access_db" but it isn't > work as I expect. This is definitely better done at the MTA level - you could use the Sendmail compat_check feature for this. After the access_db definition in sendmail.mc add: FEATURE(`compat_check')dnl Then in the access database put the entries: Compat:sender<@>recipient ERROR: Note that the sender and recipient must be the from the envelope and not the headers. See http://www.sendmail.org/m4/features.html#compat_check for details. Hope this helps. Cheers, Steve. -- Steve Freegard Development Director Fort Systems Ltd. From MailScanner at ecs.soton.ac.uk Fri Jan 13 11:18:45 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 13 11:18:58 2006 Subject: (no subject) In-Reply-To: References: Message-ID: -----BEGIN PGP SIGNED MESSAGE----- I have already replied to you. Go to the downloads page and follow the very simple instructions. Please give it a good try first before relying on other people. :-) On 13 Jan 2006, at 10:15, prakash, sathya wrote: > Hi, > How to install Mailscanner on hpux. > Please answer. Please reply soon. > > Waiting for ur reply.. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8eMlvw32o+k+q+hAQHD7gf9EAbLVU/ovtjovRGNAkoSLi9pJRQEWTKN OH6wHHvwSLutPfgIdiAgeyaXM02rlE7xCSjMG2Hs+bhKE8jPocFeLK9XK6cG1Kc9 rvqQRACLGT1zU6LCkgP7d7ROxAYcy3Gk9AflgdhGuq0g8oT6RD853lp60zHyFHlR gfoKAKRwQ+KkO6K6cMr50fH2gkZYLg2HNQIT7FbEv++gjogPehD9oxZdXD9ErRYL U7pv+zJRfRBnWmljmqgwfHA01wrULLW/TTiH2N0OJNvXfq2PzAowX5/CiCudVLyf x+ADTR2v7Y1h9ufS/RuS+ip3KbSz4LzghuZa2nswOxoBvodytPfYAQ== =ZakL -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From drew at themarshalls.co.uk Fri Jan 13 11:20:41 2006 From: drew at themarshalls.co.uk (Drew Marshall) Date: Fri Jan 13 11:20:48 2006 Subject: [MailScanner] test - In-Reply-To: <1137149278.9448.14.camel@localhost.localdomain> References: <1137143770.9448.4.camel@localhost.localdomain> <43C77C82.8030600@tradoc.fr> <1137149278.9448.14.camel@localhost.localdomain> Message-ID: <64711.194.70.180.170.1137151241.squirrel@webmail.r-bit.net> On Fri, January 13, 2006 10:47, Paul Kelly :: Blacknight wrote: > On Fri, 2006-01-13 at 11:10 +0100, John Wilcock wrote: > >> Is this a user-selectable option, like it was on the Jiscmail listserv? >> > Nope. We're looking at all the options available in mailman. We'll see > if there are any hacks or plugins that might be available for this sort > of thing. One other minor comment (Which may or may not be significant) but is the list a tiny bit 'laggy'? Received: from bkserver.blacknight.ie (bkserver.blacknight.ie [83.98.166.45]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by cro-mx2.r-bit.net (Postfix) with ESMTP id DBF8F11542 for ; Fri, 13 Jan 2006 10:40:28 +0000 (GMT) ^^^^^^^^ Received: from bkserver.blacknight.ie (bkserver.blacknight.ie [127.0.0.1]) by bkserver.blacknight.ie (8.13.1/8.13.1) with ESMTP id k0DA91wN026589; Fri, 13 Jan 2006 10:11:36 GMT X-Mailman-Handler: $Id: mm-handler,v 1.2 2002/04/05 19:41:09 bwarsaw Exp $ Received: from cro-mx1.r-bit.net (cro-mx1.r-bit.net [84.92.197.220]) by bkserver.blacknight.ie (8.13.1/8.13.1) with ESMTP id k0DA0Hto025417 for ; Fri, 13 Jan 2006 10:00:17 GMT ^^^^^^^^ I do appreciate what Blacknight are doing so this is not any form of dig but just in case this is an unknown or bedding in 'feature'. Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy From paul at blacknight.ie Fri Jan 13 11:29:24 2006 From: paul at blacknight.ie (Paul Kelly :: Blacknight) Date: Fri Jan 13 11:29:27 2006 Subject: [MailScanner] test - In-Reply-To: <64711.194.70.180.170.1137151241.squirrel@webmail.r-bit.net> References: <1137143770.9448.4.camel@localhost.localdomain> <43C77C82.8030600@tradoc.fr> <1137149278.9448.14.camel@localhost.localdomain> <64711.194.70.180.170.1137151241.squirrel@webmail.r-bit.net> Message-ID: <1137151764.9448.19.camel@localhost.localdomain> Hi Drew, On Fri, 2006-01-13 at 11:20 +0000, Drew Marshall wrote: > One other minor comment (Which may or may not be significant) but is the > list a tiny bit 'laggy'? > Aye just a bit. Currently tweaking sendmail to handle the large volumes of mail per mail to the list. > Received: from bkserver.blacknight.ie (bkserver.blacknight.ie [83.98.166.45]) > (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) > (No client certificate requested) > by cro-mx2.r-bit.net (Postfix) with ESMTP id DBF8F11542 > for ; Fri, 13 Jan 2006 10:40:28 +0000 (GMT) > ^^^^^^^^ > Received: from bkserver.blacknight.ie (bkserver.blacknight.ie [127.0.0.1]) > by bkserver.blacknight.ie (8.13.1/8.13.1) with ESMTP id k0DA91wN026589; > Fri, 13 Jan 2006 10:11:36 GMT > X-Mailman-Handler: $Id: mm-handler,v 1.2 2002/04/05 19:41:09 bwarsaw Exp $ > Received: from cro-mx1.r-bit.net (cro-mx1.r-bit.net [84.92.197.220]) > by bkserver.blacknight.ie (8.13.1/8.13.1) with ESMTP id k0DA0Hto025417 > for ; Fri, 13 Jan 2006 10:00:17 GMT > ^^^^^^^^ > > I do appreciate what Blacknight are doing so this is not any form of dig > but just in case this is an unknown or bedding in 'feature'. > Tweaking is always a requirement for this sort of thing! :) I'm closely monitoring it. Regards, Paul > Drew > > > -- > In line with our policy, this message has > been scanned for viruses and dangerous > content by MailScanner, and is believed to be clean. > www.themarshalls.co.uk/policy > -- Paul Kelly Technical Director Blacknight Internet Solutions ltd Hosting, Colocation, Dedicated servers Tel: 059 9183072 DDI: 059 9183091 e-mail: paul@blacknight.ie From Sylvain.Phaneuf at imsu.ox.ac.uk Fri Jan 13 11:32:22 2006 From: Sylvain.Phaneuf at imsu.ox.ac.uk (Sylvain Phaneuf) Date: Fri Jan 13 11:32:54 2006 Subject: test - In-Reply-To: <7D722953-F6D1-4332-A90B-56519C551834@ecs.soton.ac.uk> References: <1137143770.9448.4.camel@localhost.localdomain> <223f97700601130144t4a780005s@mail.gmail.com> <7D722953-F6D1-4332-A90B-56519C551834@ecs.soton.ac.uk> Message-ID: <43C78FC5.6567.00EB.0@imsu.ox.ac.uk> > On 13/01/06, Paul Kelly :: Blacknight wrote: >> the subject should be prefixed by [MailScanner] .. >> > > Looks ugly, makes poor use of the screen resources ( less seen of the > actual Subject in most MUAs), and will fool systems that rely on where > Re: etc are inserted (gmail for one) into not threading conversations > properly (cf the mailwatch list archives/forums)..... Can we please > _not_ have this? > It's easy enough making sorting rules on To: ...;) Except when someone sends a message and puts the list address in the CC field... as someone did a few minutes ago Sylvain -- ============================================ Sylvain Phaneuf --- Systems Manager | phone : +44 (0)1865 221323 Information Management Services Unit - Medical Sciences Division Oxford University | email : sylvain.phaneuf@imsu.ox.ac.uk Room 3A25B John Radcliffe Hospital | fax : +44 (0) 1865 221322 Oxford OX3 9DU England ============================================ From MailScanner at ecs.soton.ac.uk Fri Jan 13 11:41:18 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 13 11:41:27 2006 Subject: test - In-Reply-To: <43C78FC5.6567.00EB.0@imsu.ox.ac.uk> References: <1137143770.9448.4.camel@localhost.localdomain> <223f97700601130144t4a780005s@mail.gmail.com> <7D722953-F6D1-4332-A90B-56519C551834@ecs.soton.ac.uk> <43C78FC5.6567.00EB.0@imsu.ox.ac.uk> Message-ID: <0556E8CE-0BA0-4DFE-A0E5-E57840009049@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- On 13 Jan 2006, at 11:32, Sylvain Phaneuf wrote: >> On 13/01/06, Paul Kelly :: Blacknight wrote: >>> the subject should be prefixed by [MailScanner] .. >>> >> >> Looks ugly, makes poor use of the screen resources ( less seen of > the >> actual Subject in most MUAs), and will fool systems that rely on > where >> Re: etc are inserted (gmail for one) into not threading > conversations >> properly (cf the mailwatch list archives/forums)..... Can we please >> _not_ have this? >> It's easy enough making sorting rules on To: ...;) > > > Except when someone sends a message and puts the list address in > the CC > field... as someone did a few minutes ago In which case either add the CC as another header to check, or get a decent mail client that lets you filter on any recipient. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8eR4Pw32o+k+q+hAQFTDwgAizemF1qUeyslRH1T6iGP8RAssXdXijV3 3n4cceTP9XsilBxkV5xRA0lzsYHBBHB84C8GFeuw8qdE95p3mwxcjWWN1SeWjykC sFgM7Q62pJ69n2c+W/YEsTs5jHiW5sASyMwlmF/ldjrQUCnb1Gc0AoTvRE11VZTg Q3r3vi/4HvDl0xwE/4hNVrWF2GrG1ruvmBGL8ztmA1aOMznq/AdKY89v8pfrom2s H8sbKrOCZ9BsL9mQHizvL3s44zIuqmUS+s8pr3YU1QW1Cj68aKfjNa3ew1BLk/+h fHi2OT9sLXGfwrmhoCoL8qZWH3KDmmpVIaiBuo6IPaOPWQ14ovb6Mw== =0ct7 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From sathya.prakash at hp.com Fri Jan 13 11:40:43 2006 From: sathya.prakash at hp.com (prakash, sathya) Date: Fri Jan 13 11:42:05 2006 Subject: Starting MS Message-ID: Hi folks, Please tell me how to start Mailscanner. I have downloaded and installed in by running ./install.sh. Regards sathya From a.peacock at chime.ucl.ac.uk Fri Jan 13 11:45:39 2006 From: a.peacock at chime.ucl.ac.uk (Anthony Peacock) Date: Fri Jan 13 11:45:51 2006 Subject: test - In-Reply-To: <43C78FC5.6567.00EB.0@imsu.ox.ac.uk> References: <1137143770.9448.4.camel@localhost.localdomain> <223f97700601130144t4a780005s@mail.gmail.com> <7D722953-F6D1-4332-A90B-56519C551834@ecs.soton.ac.uk> <43C78FC5.6567.00EB.0@imsu.ox.ac.uk> Message-ID: <43C792E3.9060304@chime.ucl.ac.uk> Sylvain Phaneuf wrote: >> On 13/01/06, Paul Kelly :: Blacknight wrote: >>> the subject should be prefixed by [MailScanner] .. >>> >> Looks ugly, makes poor use of the screen resources ( less seen of > the >> actual Subject in most MUAs), and will fool systems that rely on > where >> Re: etc are inserted (gmail for one) into not threading > conversations >> properly (cf the mailwatch list archives/forums)..... Can we please >> _not_ have this? >> It's easy enough making sorting rules on To: ...;) > > > Except when someone sends a message and puts the list address in the CC > field... as someone did a few minutes ago > > Sylvain > But you can now use the List-ID header field, which is a much more reliable filtering item. -- Anthony Peacock CHIME, Royal Free & University College Medical School WWW: http://www.chime.ucl.ac.uk/~rmhiajp/ "The most exciting phrase to hear in science, the one that heralds new discoveries, is not 'Eureka!' but 'That's funny....'" -- Isaac Asimov From sathya.prakash at hp.com Fri Jan 13 11:48:11 2006 From: sathya.prakash at hp.com (prakash, sathya) Date: Fri Jan 13 11:49:26 2006 Subject: setup on hpux Message-ID: Hi, Thanks for reply. No, Where is that page. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Martin Hepworth Sent: Friday, January 13, 2006 3:47 PM To: 'MailScanner discussion' Subject: RE: setup on hpux Hi Have you looked at the generic Unix installer and instructions? -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of sathya prakash > Sent: 13 January 2006 09:37 > To: mailscanner@lists.mailscanner.info > Subject: setup on hpux > > hi, > how to install MailScanner on HPUX. > reply soon. > > > > > > > > > > > > confidence is key to success > > > HP.com home > > > > > Send instant messages to your online friends > http://in.messenger.yahoo.com ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read the Wiki (http://wiki.mailscanner.info/). Support MailScanner development - buy the book off the website! From Sylvain.Phaneuf at imsu.ox.ac.uk Fri Jan 13 11:59:29 2006 From: Sylvain.Phaneuf at imsu.ox.ac.uk (Sylvain Phaneuf) Date: Fri Jan 13 12:00:00 2006 Subject: test - In-Reply-To: <0556E8CE-0BA0-4DFE-A0E5-E57840009049@ecs.soton.ac.uk> References: <1137143770.9448.4.camel@localhost.localdomain> <223f97700601130144t4a780005s@mail.gmail.com> <7D722953-F6D1-4332-A90B-56519C551834@ecs.soton.ac.uk> <43C78FC5.6567.00EB.0@imsu.ox.ac.uk> <0556E8CE-0BA0-4DFE-A0E5-E57840009049@ecs.soton.ac.uk> Message-ID: <43C7961F.6567.00EB.0@imsu.ox.ac.uk> >>> It's easy enough making sorting rules on To: ...;) >> >> >> Except when someone sends a message and puts the list address in >> the CC >> field... as someone did a few minutes ago > > In which case either add the CC as another header to check, or get a > decent mail client that lets you filter on any recipient. Sorry, I forgot to put a :-) at the end of my comment... I will also create another rule to exclude messages with subject line "RE: setup on hpux" ;-) Sylvain From martinh at solid-state-logic.com Fri Jan 13 12:02:31 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Fri Jan 13 12:02:38 2006 Subject: setup on hpux In-Reply-To: Message-ID: <00c901c61839$3b6e6190$3004010a@martinhlaptop> http://www.sng.ecs.soton.ac.uk/mailscanner/install/ and specifically.. http://www.sng.ecs.soton.ac.uk/mailscanner/install/other.html -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of prakash, sathya > Sent: 13 January 2006 11:48 > To: MailScanner discussion > Subject: RE: setup on hpux > > Hi, > Thanks for reply. > No, Where is that page. > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Martin > Hepworth > Sent: Friday, January 13, 2006 3:47 PM > To: 'MailScanner discussion' > Subject: RE: setup on hpux > > Hi > > Have you looked at the generic Unix installer and instructions? > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of sathya prakash > > Sent: 13 January 2006 09:37 > > To: mailscanner@lists.mailscanner.info > > Subject: setup on hpux > > > > hi, > > how to install MailScanner on HPUX. > > reply soon. > > > > > > > > > > > > > > > > > > > > > > > > confidence is key to success > > > > > > HP.com home > > > > > > > > > > Send instant messages to your online friends > > http://in.messenger.yahoo.com > > > ********************************************************************** > > This email and any files transmitted with it are confidential and > intended solely for the use of the individual or entity to whom they are > addressed. If you have received this email in error please notify the > system manager. > > This footnote confirms that this email message has been swept > for the presence of computer viruses and is believed to be clean. > > ********************************************************************** > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From David.While at uce.ac.uk Fri Jan 13 12:06:42 2006 From: David.While at uce.ac.uk (David While) Date: Fri Jan 13 12:06:47 2006 Subject: Starting MS Message-ID: <294B4B3243E76C4BA4FF7F54003B3BE1EFAD70@exchangea.staff.uce.ac.uk> You are not endearing yourself to the population of this list :) You should take the advice on the bottom of every email from the list: Before posting, read the Wiki (http://wiki.mailscanner.info/). I think you will find answers to the questions you have been asking. -------------------------------------------- David While BSc CEng MBCS CITP Department of Computing University of Central England Tel: 0121 331 6211 -------------------------------------------- -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of prakash, sathya Sent: 13 January 2006 11:41 To: mailscanner@lists.mailscanner.info Subject: Starting MS Hi folks, Please tell me how to start Mailscanner. I have downloaded and installed in by running ./install.sh. Regards sathya -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read the Wiki (http://wiki.mailscanner.info/). Support MailScanner development - buy the book off the website! From drew at themarshalls.co.uk Fri Jan 13 12:07:45 2006 From: drew at themarshalls.co.uk (Drew Marshall) Date: Fri Jan 13 12:07:51 2006 Subject: [MailScanner] test - In-Reply-To: <1137151764.9448.19.camel@localhost.localdomain> References: <1137143770.9448.4.camel@localhost.localdomain> <43C77C82.8030600@tradoc.fr> <1137149278.9448.14.camel@localhost.localdomain> <64711.194.70.180.170.1137151241.squirrel@webmail.r-bit.net> <1137151764.9448.19.camel@localhost.localdomain> Message-ID: <64864.194.70.180.170.1137154065.squirrel@webmail.r-bit.net> On Fri, January 13, 2006 11:29, Paul Kelly :: Blacknight wrote: Hi Paul > Tweaking is always a requirement for this sort of thing! :) I'm closely > monitoring it. Did I have the slightest doubt??!! :-) Looks better already. Well done and thanks for all you have done and are doing. Much appreciated. Kindest regards Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy From sathya.prakash at hp.com Fri Jan 13 12:11:15 2006 From: sathya.prakash at hp.com (prakash, sathya) Date: Fri Jan 13 12:12:06 2006 Subject: Starting MS Message-ID: Hi, Ok thanks -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of David While Sent: Friday, January 13, 2006 5:37 PM To: MailScanner discussion Subject: RE: Starting MS You are not endearing yourself to the population of this list :) You should take the advice on the bottom of every email from the list: Before posting, read the Wiki (http://wiki.mailscanner.info/). I think you will find answers to the questions you have been asking. -------------------------------------------- David While BSc CEng MBCS CITP Department of Computing University of Central England Tel: 0121 331 6211 -------------------------------------------- -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of prakash, sathya Sent: 13 January 2006 11:41 To: mailscanner@lists.mailscanner.info Subject: Starting MS Hi folks, Please tell me how to start Mailscanner. I have downloaded and installed in by running ./install.sh. Regards sathya -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read the Wiki (http://wiki.mailscanner.info/). Support MailScanner development - buy the book off the website! -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read the Wiki (http://wiki.mailscanner.info/). Support MailScanner development - buy the book off the website! From dhawal at netmagicsolutions.com Fri Jan 13 12:27:25 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Fri Jan 13 12:27:32 2006 Subject: Maximum Message size and Attachmnet size no working for me In-Reply-To: <43BA46E7.5060806@netmagicsolutions.com> References: <8D8A77DC1FA09546936E74FC3EEC627AA4B9@FREXGENEVA-01.frfr.foxriver.com> <43A712C5.8020304@ecs.soton.ac.uk> <20051219204339.15916.qmail@mymail.netmagicians.com> <43A71EA1.6070903@ecs.soton.ac.uk> <43BA46E7.5060806@netmagicsolutions.com> Message-ID: <43C79CAD.6060805@netmagicsolutions.com> Dhawal Doshy wrote: > Julian Field wrote: >> Oh and there's also >> >> the "Happy" virus >> Dangerously long MIME boundary strings used to exploit a bug in Eudora >> filename.rules.conf and new "allow filenames" and "deny filenames" checks >> filetype.rules.conf and new "allow filetypes" and "deny filetypes" checks >> >> That's about it. >> >> Raymond Dijkxhoorn wrote: >> >>> Hi! >>> >>>>> I can never remember what's included in Dangerous Content :-) Kosta >>>>> Lekas wrote: >>>> >>> >>>>>> I set dangerous content scanning to yes and it is working now. >>>>>> That was >>>>>> it. Thanks for your help. >>>>> >>> >>>> Julian, it would be a nice idea to have a list of all such >>>> dependencies on the wiki.. i too have been troubled by this more >>>> than once.. what do you think? maybe sometime in jan'06? > > Julian, would you be kind enough to spare some time and review this? > http://wiki.mailscanner.info/doku.php?id=documentation:configuration:dependencies Hi Julian, Sorry for being a pain, but please spare some time for reviewing this? http://wiki.mailscanner.info/doku.php?id=documentation:configuration:dependencies Thanks, - dhawal From P.G.M.Peters at utwente.nl Fri Jan 13 12:41:00 2006 From: P.G.M.Peters at utwente.nl (Peter Peters) Date: Fri Jan 13 12:41:04 2006 Subject: first post? In-Reply-To: <200601131524.00549.james@grayonline.id.au> References: <43C6D458.9050309@blacknight.ie> <200601131524.00549.james@grayonline.id.au> Message-ID: <43C79FDC.1010101@utwente.nl> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 James Gray wrote on 13-1-2006 5:23: > (The other reason I posted this "me too" type post, was I wanted to see if the > new list munges my GPG sig like the old one did :P) At least I get a "Good signature" after downloading your public key. - -- Peter Peters, senior beheerder (Security) Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE) Universiteit Twente, Postbus 217, 7500 AE Enschede telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQFDx5/bMbmy+DDgnIURAmWrAKDP/I8r9i9PpGR4XwlqU3KLydG7wgCcDlYs s3C0a0fUrcE5OoY9lGAk5nY= =Yw9s -----END PGP SIGNATURE----- From michele at blacknight.ie Fri Jan 13 12:50:12 2006 From: michele at blacknight.ie (Michele Neylon :: Blacknight Solutions) Date: Fri Jan 13 12:50:17 2006 Subject: test - In-Reply-To: <43C7961F.6567.00EB.0@imsu.ox.ac.uk> Message-ID: <200601131250.k0DCoEVR017631@merlin.blacknight.ie> Sylvain Phaneuf <> said on 13 January 2006 11:59: >>>> It's easy enough making sorting rules on To: ...;) >>> >>> >>> Except when someone sends a message and puts the list address in the >>> CC field... as someone did a few minutes ago >> >> In which case either add the CC as another header to check, or get a > >> decent mail client that lets you filter on any recipient. > > > Sorry, I forgot to put a :-) at the end of my comment... I will also > create another rule to exclude messages with subject line "RE: setup > on hpux" That probably won't be necessary ... /me pokes Paul and Julian to unsub the person in question Mr Michele Neylon Blacknight Solutions Hosting & Colocation, Brand Protection http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 UK: 0870 163 0607 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 From steve.swaney at fsl.com Fri Jan 13 13:04:09 2006 From: steve.swaney at fsl.com (Stephen Swaney) Date: Fri Jan 13 13:04:14 2006 Subject: [MailScanner] Re: Problems with charset gb2312 and mime headers In-Reply-To: <223f97700601130115q24d12176h@mail.gmail.com> Message-ID: <200601131304.k0DD4Bta024400@bkserver.blacknight.ie> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Glenn Steen > Sent: Friday, January 13, 2006 4:16 AM > To: MailScanner discussion > Subject: [MailScanner] Re: Problems with charset gb2312 and mime headers > > On 13/01/06, Jens Ahlin wrote: > > Hi, > > > > I have seen this happen sporadically but with charset ISO8859-1 encoded > > subject line. The client is a Outlook 2003 client. This does not happen > > often and I cannot se any pattern in the behaviour. I only notice this > > when the subject line contains swedish charchters. > > > > Any ideas ? > > > > Jens > > > I have a vague recollection of seeing something like this a while > back, but I think it got cleared be an MS upgrade.... I might be > recollecting wrong though:-). > What version of MS are you running? MailScanner version 4.48.4 > > -- > -- Glenn > email: glenn < dot > steen < at > gmail < dot > com > work: glenn < dot > steen < at > ap1 < dot > se Stephen Swaney Fort Systems Ltd. stephen.swaney@fsl.com www.fsl.com From paul at blacknight.ie Fri Jan 13 13:06:11 2006 From: paul at blacknight.ie (Paul Kelly :: Blacknight) Date: Fri Jan 13 13:06:12 2006 Subject: test - In-Reply-To: <200601131250.k0DCoEVR017631@merlin.blacknight.ie> References: <200601131250.k0DCoEVR017631@merlin.blacknight.ie> Message-ID: <1137157572.9448.26.camel@localhost.localdomain> > That probably won't be necessary ... > /me pokes Paul and Julian to unsub the person in question I'm sure Julian will deal with it, if he warrants that sort of action :) /me flees to lunch -- Paul Kelly Technical Director Blacknight Internet Solutions ltd Hosting, Colocation, Dedicated servers Tel: 059 9183072 DDI: 059 9183091 e-mail: paul@blacknight.ie From michele at blacknight.ie Fri Jan 13 13:26:19 2006 From: michele at blacknight.ie (Michele Neylon :: Blacknight Solutions) Date: Fri Jan 13 13:26:24 2006 Subject: first post? In-Reply-To: <43C79FDC.1010101@utwente.nl> Message-ID: <200601131326.k0DDQMa3012326@merlin.blacknight.ie> Peter Peters <> said on 13 January 2006 12:41: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > James Gray wrote on 13-1-2006 5:23: > >> (The other reason I posted this "me too" type post, was I wanted to >> see if the new list munges my GPG sig like the old one did :P) > > At least I get a "Good signature" after downloading your public key. > You shouldn't see any issues with signatures as the list is not filtered (as yet) Mr Michele Neylon Blacknight Solutions Hosting & Colocation, Brand Protection http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 UK: 0870 163 0607 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 From MailScanner at ecs.soton.ac.uk Fri Jan 13 14:18:51 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 13 14:19:03 2006 Subject: Maximum Message size and Attachmnet size no working for me In-Reply-To: <43C79CAD.6060805@netmagicsolutions.com> References: <8D8A77DC1FA09546936E74FC3EEC627AA4B9@FREXGENEVA-01.frfr.foxriver.com> <43A712C5.8020304@ecs.soton.ac.uk> <20051219204339.15916.qmail@mymail.netmagicians.com> <43A71EA1.6070903@ecs.soton.ac.uk> <43BA46E7.5060806@netmagicsolutions.com> <43C79CAD.6060805@netmagicsolutions.com> Message-ID: <87AAF345-3E7A-4090-A97C-5E2D0036BBFC@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- On 13 Jan 2006, at 12:27, Dhawal Doshy wrote: > Dhawal Doshy wrote: >> Julian Field wrote: >>> Oh and there's also >>> >>> the "Happy" virus >>> Dangerously long MIME boundary strings used to exploit a bug in >>> Eudora >>> filename.rules.conf and new "allow filenames" and "deny >>> filenames" checks >>> filetype.rules.conf and new "allow filetypes" and "deny >>> filetypes" checks >>> >>> That's about it. >>> >>> Raymond Dijkxhoorn wrote: >>> >>>> Hi! >>>> >>>>>> I can never remember what's included in Dangerous Content :-) >>>>>> Kosta Lekas wrote: >>>>> >>>> >>>>>>> I set dangerous content scanning to yes and it is working >>>>>>> now. That was >>>>>>> it. Thanks for your help. >>>>>> >>>> >>>>> Julian, it would be a nice idea to have a list of all such >>>>> dependencies on the wiki.. i too have been troubled by this >>>>> more than once.. what do you think? maybe sometime in jan'06? >> Julian, would you be kind enough to spare some time and review this? >> http://wiki.mailscanner.info/doku.php? >> id=documentation:configuration:dependencies > > Hi Julian, > > Sorry for being a pain, but please spare some time for reviewing this? > http://wiki.mailscanner.info/doku.php? > id=documentation:configuration:dependencies That's a pretty big job. Surely you can do most of it and just get me to check it? I would have to resort to the code for 1 or 2 of them that I can't remember any more. I don't really have the time to write the whole of this for you, sorry. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8e2z/w32o+k+q+hAQFCJQf/ZtXw5Hw4e+vQBGrxS1xr0zlyREi2HTjJ PRTStgOC2czGqqzvX19PR0iiT3sL2axlLhoOXPKe+1ntVsQP3qZrOFGANU/No1iQ AqZQ4O8mov7zYo/H5JXJzf0LxgOM3W1qFQG9aAzHiJHoDZ5PKjtjGHjWEoHhkZEJ hejyzb6FAFD+b6rQNM+UtC+UqKK7dMkPEyaqil5SL+F2yAEczydHC17CMZawvANs jY9cAh8MsVCBwEgOfHUa7Z3NpxmNHVj+/BhT9acf/o2J24hdC6EfzS5fw1oN2N15 LJAPG3gk0isemzDcKe3M3p0w92oRO+oNcwsNfXfQTTy6fL1fvguurw== =mPIS -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Fri Jan 13 14:27:47 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 13 14:27:58 2006 Subject: [MailScanner] Re: Problems with charset gb2312 and mime headers In-Reply-To: <200601131304.k0DD4Bta024400@bkserver.blacknight.ie> References: <200601131304.k0DD4Bta024400@bkserver.blacknight.ie> Message-ID: <9F0A9120-F49C-44E8-B0D9-619C1591F719@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- On 13 Jan 2006, at 13:04, Stephen Swaney wrote: > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Glenn Steen >> Sent: Friday, January 13, 2006 4:16 AM >> To: MailScanner discussion >> Subject: [MailScanner] Re: Problems with charset gb2312 and mime >> headers >> >> On 13/01/06, Jens Ahlin >> wrote: >>> Hi, >>> >>> I have seen this happen sporadically but with charset ISO8859-1 >>> encoded >>> subject line. The client is a Outlook 2003 client. This does not >>> happen >>> often and I cannot se any pattern in the behaviour. I only notice >>> this >>> when the subject line contains swedish charchters. >>> >>> Any ideas ? >>> >>> Jens >> >> >> I have a vague recollection of seeing something like this a while >> back, but I think it got cleared be an MS upgrade.... I might be >> recollecting wrong though:-). >> What version of MS are you running? > > MailScanner version 4.48.4 Bother. From the Changelog for 4.48: - - Subject lines are all MIME-decoded properly now. Obviously not quite true, or some other external change is causing it. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8e45/w32o+k+q+hAQHhaAgAp73KtAjg5oXVagWul5HRZXZ/E5+RKJa0 O/MGkvtmwiAlpUNXVarPK6vyanYlq9FenRaMmgDBk03W9WZD96cwI0gVzisXoACD ubVbXy5JROHcWw39bLirxr7hSO4PTsSH16blIpQisK9rzvuyC4MLBs3wi7nc97Qs 2FeAXQyoyZagPQUpW9Noldlgdj4cdOpwYsfjwjD1a6X4CgbkKyPs2XSzs6hg5tJq 9T46Alf1CUkVY+xagPdcKMgn9FsGNiEO6frTzhFICpYyYjo78scomevtyKOxuCPU bX0XBve8oDNN1avTbeWi1EcAbWipXuN3tXCgg1A+f/sNyKiM+h2eDQ== =bs9l -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From bpumphrey at WoodMacLaw.com Fri Jan 13 14:49:37 2006 From: bpumphrey at WoodMacLaw.com (Billy A. Pumphrey) Date: Fri Jan 13 14:49:41 2006 Subject: Disk is full Message-ID: <04D932B0071FE34FA63EBB1977B48D15ACDC3C@woodenex.woodmaclaw.local> My disk is full on my spam box. What can I delete? Here is a rundown. I am guessing that I can delete quarantine and stuff, but I do not know. [root@WoodenMS log]# df -h Filesystem Size Used Avail Use% Mounted on /dev/mapper/VolGroup00-LogVol00 32G 30G 0 100% / /dev/ida/c0d0p1 99M 25M 69M 27% /boot none 506M 0 506M 0% /dev/shm Billy Pumphrey IT Manager Wooden & McLaughlin -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060113/0ceb70a8/attachment.html From raymond at prolocation.net Fri Jan 13 14:55:12 2006 From: raymond at prolocation.net (raymond@prolocation.net) Date: Fri Jan 13 14:55:11 2006 Subject: Disk is full In-Reply-To: <04D932B0071FE34FA63EBB1977B48D15ACDC3C@woodenex.woodmaclaw.local> References: <04D932B0071FE34FA63EBB1977B48D15ACDC3C@woodenex.woodmaclaw.local> Message-ID: Hi! > My disk is full on my spam box. What can I delete? Here is a rundown. > I am guessing that I can delete quarantine and stuff, but I do not know. > > [root@WoodenMS log]# df -h > Filesystem Size Used Avail Use% Mounted on > /dev/mapper/VolGroup00-LogVol00 > 32G 30G 0 100% / > /dev/ida/c0d0p1 99M 25M 69M 27% /boot > none 506M 0 506M 0% /dev/shm Check the delete script for your quarantine dir... :) You could safely empty the quarantine dir ... if you need some space. Bye, Raymond. From Jason.Burzenski at americanhm.com Fri Jan 13 14:56:27 2006 From: Jason.Burzenski at americanhm.com (Jason Burzenski) Date: Fri Jan 13 14:56:38 2006 Subject: Disk is full Message-ID: <886D3239155F3742B2C9EE8D05FEB95AAC0CA6@melpsechdbs11> Default quarantine is in /var/spool/MailScanner/quarantine/[datecode]/ You can delete pretty much anything you want from in there. You should probably delete the older directories first as you probably won't need them. I also notice bayes expire files take up a lot of room. For me, they are here: /root/.spamassassin/*expire* These are safe to delete as far as I know. Jason ________________________________ From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Sent: Friday, January 13, 2006 9:50 AM To: mailscanner@lists.mailscanner.info Subject: Disk is full My disk is full on my spam box. What can I delete? Here is a rundown. I am guessing that I can delete quarantine and stuff, but I do not know. [root@WoodenMS log]# df -h Filesystem Size Used Avail Use% Mounted on /dev/mapper/VolGroup00-LogVol00 32G 30G 0 100% / /dev/ida/c0d0p1 99M 25M 69M 27% /boot none 506M 0 506M 0% /dev/shm Billy Pumphrey IT Manager Wooden & McLaughlin From steve.swaney at fsl.com Fri Jan 13 15:03:51 2006 From: steve.swaney at fsl.com (Stephen Swaney) Date: Fri Jan 13 15:03:55 2006 Subject: Disk is full In-Reply-To: Message-ID: <200601131503.k0DF3rRo029707@bkserver.blacknight.ie> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of raymond@prolocation.net > Sent: Friday, January 13, 2006 9:55 AM > To: MailScanner discussion > Subject: Re: Disk is full > > Hi! > > > My disk is full on my spam box. What can I delete? Here is a rundown. > > I am guessing that I can delete quarantine and stuff, but I do not know. > > > > [root@WoodenMS log]# df -h > > Filesystem Size Used Avail Use% Mounted on > > /dev/mapper/VolGroup00-LogVol00 > > 32G 30G 0 100% / > > /dev/ida/c0d0p1 99M 25M 69M 27% /boot > > none 506M 0 506M 0% /dev/shm > > Check the delete script for your quarantine dir... :) > > You could safely empty the quarantine dir ... if you need some space. > > Bye, > Raymond. You should also look for old systems log files. If you're running razor, look for a razor-agent.log. If you find a large razor log, set debuglevel = 0 in the razor-agent.conf file. Steve Stephen Swaney Fort Systems Ltd. stephen.swaney@fsl.com www.fsl.com From rpoe at plattesheriff.org Fri Jan 13 15:11:27 2006 From: rpoe at plattesheriff.org (Rob Poe) Date: Fri Jan 13 15:11:58 2006 Subject: first post? In-Reply-To: References: <82895A755D1EA5458EC9E64021922AD2D155D7@city-exch-w3e.cbj.local> <43C6E358.8030300@pcplace.ca> Message-ID: <43C76EC0.65ED.00A2.0@plattesheriff.org> PLEASE reconsider. I'm having problems filtering on header for some reason!!! >>> MailScanner@ecs.soton.ac.uk 1/13/2006 3:03:17 am >>> Sorry, I think that looks really ugly and just means I get to see less of the subject in my mail app. It's easy enough to filter on other headers. ---------------------------------------------------------------------------- CONFIDENTIALITY NOTICE This e-mail message and all documents that accompany it are intended only for the use of the individual or entity to which addressed, and may contain information that is privileged, confidential or exempt from disclosure under applicable law. If the reader is not the intended recipient, any disclosure, distribution or other use of this e-mail message is prohibited. If you have received this e-mail message in error, please notify the sender immediately. Thank you. From bpumphrey at WoodMacLaw.com Fri Jan 13 15:16:28 2006 From: bpumphrey at WoodMacLaw.com (Billy A. Pumphrey) Date: Fri Jan 13 15:16:31 2006 Subject: Disk is full Message-ID: <04D932B0071FE34FA63EBB1977B48D15ACDC81@woodenex.woodmaclaw.local> [root@WoodenMS bayes]# df -h Filesystem Size Used Avail Use% Mounted on /dev/mapper/VolGroup00-LogVol00 32G 4.1G 26G 14% / /dev/ida/c0d0p1 99M 25M 69M 27% /boot none 506M 0 506M 0% /dev/shm The bayes exp tokens took it all up. I delete the quarantine but that wasn't much. After the tokens I got the above. Thanks guys. Billy Pumphrey IT Manager Wooden & McLaughlin > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Stephen Swaney > Sent: Friday, January 13, 2006 10:04 AM > To: 'MailScanner discussion' > Subject: RE: Disk is full > > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of raymond@prolocation.net > > Sent: Friday, January 13, 2006 9:55 AM > > To: MailScanner discussion > > Subject: Re: Disk is full > > > > Hi! > > > > > My disk is full on my spam box. What can I delete? Here is a > rundown. > > > I am guessing that I can delete quarantine and stuff, but I do not > know. > > > > > > [root@WoodenMS log]# df -h > > > Filesystem Size Used Avail Use% Mounted on > > > /dev/mapper/VolGroup00-LogVol00 > > > 32G 30G 0 100% / > > > /dev/ida/c0d0p1 99M 25M 69M 27% /boot > > > none 506M 0 506M 0% /dev/shm > > > > Check the delete script for your quarantine dir... :) > > > > You could safely empty the quarantine dir ... if you need some space. > > > > Bye, > > Raymond. > > You should also look for old systems log files. > > If you're running razor, look for a razor-agent.log. If you find a large > razor log, set > > debuglevel = 0 > > in the razor-agent.conf file. > > Steve > > Stephen Swaney > Fort Systems Ltd. > stephen.swaney@fsl.com > www.fsl.com > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! From mcalnek at pcplace.ca Fri Jan 13 15:20:06 2006 From: mcalnek at pcplace.ca (Milton Calnek) Date: Fri Jan 13 15:20:06 2006 Subject: Procmail recipe to add MailScanner to the subject line. In-Reply-To: References: <04D932B0071FE34FA63EBB1977B48D15ACDC3C@woodenex.woodmaclaw.local> Message-ID: <43C7C526.1060006@pcplace.ca> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, I'm looking for a procmail recipe that will add MailScanner to the Subject line. TIA. - -- PC Place - Just clicks away Milton Calnek PC Place www.pcplace.ca 306-359-6939 mcalnek@pcplace.ca -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (GNU/Linux) Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org iD8DBQFDx8UmHgnbf2T2QqMRAiEqAKClkELDFtOiM36avFozp+nu9ktz9wCcDNm2 BxIJyVAoSxUY557PWzvZVMM= =U1NG -----END PGP SIGNATURE----- -- DISCLAIMER: The information transmitted is intended only for the addressee and may contain confidential, proprietary and/or privileged material. Any unauthorized review, distribution or other use of or the taking of any action in reliance upon this information is prohibited. If you received this in error, please contact the sender and delete or destroy this message and any copies. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. MailScanner thanks transtec Computers for their support. From rpoe at plattesheriff.org Fri Jan 13 15:24:56 2006 From: rpoe at plattesheriff.org (Rob Poe) Date: Fri Jan 13 15:25:24 2006 Subject: first post? In-Reply-To: <43C76EC0.65ED.00A2.0@plattesheriff.org> References: <82895A755D1EA5458EC9E64021922AD2D155D7@city-exch-w3e.cbj.local> <43C6E358.8030300@pcplace.ca> <43C76EC0.65ED.00A2.0@plattesheriff.org> Message-ID: <43C771E9.65ED.00A2.0@plattesheriff.org> NEVERMIND. Rule was corrupt. -------------------------------------------------------- PLEASE reconsider. I'm having problems filtering on header for some reason!!! >>> MailScanner@ecs.soton.ac.uk 1/13/2006 3:03:17 am >>> Sorry, I think that looks really ugly and just means I get to see less of the subject in my mail app. It's easy enough to filter on other headers. ---------------------------------------------------------------------------- CONFIDENTIALITY NOTICE This e-mail message and all documents that accompany it are intended only for the use of the individual or entity to which addressed, and may contain information that is privileged, confidential or exempt from disclosure under applicable law. If the reader is not the intended recipient, any disclosure, distribution or other use of this e-mail message is prohibited. If you have received this e-mail message in error, please notify the sender immediately. Thank you. From Sylvain.Phaneuf at imsu.ox.ac.uk Fri Jan 13 15:27:29 2006 From: Sylvain.Phaneuf at imsu.ox.ac.uk (Sylvain Phaneuf) Date: Fri Jan 13 15:27:52 2006 Subject: first post? In-Reply-To: <43C76EC0.65ED.00A2.0@plattesheriff.org> References: <82895A755D1EA5458EC9E64021922AD2D155D7@city-exch-w3e.cbj.local> <43C6E358.8030300@pcplace.ca> <43C76EC0.65ED.00A2.0@plattesheriff.org> Message-ID: <43C7C6E2.6567.00EB.0@imsu.ox.ac.uk> you can surely filter on To field, no? Sylvain >>> On 13/01/2006 at 15:11, in message <43C76EC0.65ED.00A2.0@plattesheriff.org>, rpoe@plattesheriff.org wrote: > PLEASE reconsider. I'm having problems filtering on header for some > reason!!! > > >>>> MailScanner@ecs.soton.ac.uk 1/13/2006 3:03:17 am >>> > > Sorry, I think that looks really ugly and just means I get to see > less of the subject in my mail app. > > It's easy enough to filter on other headers. > > > ---------------------------------------------------------------------------- > CONFIDENTIALITY NOTICE > This e-mail message and all documents that accompany it are intended only > for the use of the individual or entity to which addressed, and may contain > information that is privileged, confidential or exempt from disclosure under > applicable law. If the reader is not the intended recipient, any disclosure, > distribution or other use of this e-mail message is prohibited. If you have > received this e-mail message in error, please notify the sender immediately. > Thank you. > From KShortt at ussco.com Fri Jan 13 15:53:10 2006 From: KShortt at ussco.com (Shortt, Kevin) Date: Fri Jan 13 15:52:56 2006 Subject: Procmail recipe to add MailScanner to the subject line. Message-ID: :0 hfw * ^Tomailscanner@lists.mailscanner.info |sed -e 's/^Subject:/Subject: \[mailscanner\] /' > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Milton Calnek > Sent: Friday, January 13, 2006 10:20 AM > To: MailScanner discussion > Subject: Procmail recipe to add MailScanner to the subject line. > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Hi, > > I'm looking for a procmail recipe that will add MailScanner > to the Subject line. > > TIA. > > - -- > PC Place - Just clicks away > > Milton Calnek > PC Place > www.pcplace.ca > 306-359-6939 > mcalnek@pcplace.ca > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.2 (GNU/Linux) > Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org > > iD8DBQFDx8UmHgnbf2T2QqMRAiEqAKClkELDFtOiM36avFozp+nu9ktz9wCcDNm2 > BxIJyVAoSxUY557PWzvZVMM= > =U1NG > -----END PGP SIGNATURE----- > > -- > DISCLAIMER: The information transmitted is intended only for > the addressee and may contain confidential, proprietary > and/or privileged material. Any unauthorized review, > distribution or other use of or the taking of any action in > reliance upon this information is prohibited. If you received > this in error, please contact the sender and delete or > destroy this message and any copies. > > -- > This message has been scanned for viruses and dangerous > content by MailScanner, and is believed to be clean. > MailScanner thanks transtec Computers for their support. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! > From kevinp at webpipe.net Fri Jan 13 15:55:15 2006 From: kevinp at webpipe.net (Kevin Pendleton) Date: Fri Jan 13 15:55:24 2006 Subject: Disk is full In-Reply-To: <04D932B0071FE34FA63EBB1977B48D15ACDC81@woodenex.woodmaclaw.local> References: <04D932B0071FE34FA63EBB1977B48D15ACDC81@woodenex.woodmaclaw.local> Message-ID: <43C7CD63.20401@webpipe.net> If I remember correctly you can fix it so those files are not created by setting "bayes_auto_expire 0" in your spam.assassin.prefs.conf file. Kevin Billy A. Pumphrey wrote: > [root@WoodenMS bayes]# df -h > Filesystem Size Used Avail Use% Mounted on > /dev/mapper/VolGroup00-LogVol00 > 32G 4.1G 26G 14% / > /dev/ida/c0d0p1 99M 25M 69M 27% /boot > none 506M 0 506M 0% /dev/shm > > The bayes exp tokens took it all up. I delete the quarantine but that > wasn't much. After the tokens I got the above. Thanks guys. > > > Billy Pumphrey > IT Manager > Wooden & McLaughlin > > From bpumphrey at WoodMacLaw.com Fri Jan 13 15:59:54 2006 From: bpumphrey at WoodMacLaw.com (Billy A. Pumphrey) Date: Fri Jan 13 15:59:59 2006 Subject: Disk is full Message-ID: <04D932B0071FE34FA63EBB1977B48D15ACDCBE@woodenex.woodmaclaw.local> Snip I am not out of the water quite yet. My MailWatch is not working correctly now. If I should move this to the mailwatch list, please say so. This happened because of the full disk I would assume, as it worked before then. When I go to the web page for mailwatch I get: Error executing query: Can't open file: 'maillog.MYI' (errno: 145) SQL: SELECT COUNT(*) AS processed, SUM( CASE WHEN ( (virusinfected=0 OR virusinfected IS NULL) AND (nameinfected=0 OR nameinfected IS NULL) AND (otherinfected=0 OR otherinfected IS NULL) AND (isspam=0 OR isspam IS NULL) AND (ishighspam=0 OR ishighspam IS NULL) AND (ismcp=0 OR ismcp IS NULL) AND (ishighmcp=0 OR ishighmcp IS NULL) ) THEN 1 ELSE 0 END ) AS clean, ROUND(( SUM( CASE WHEN ( (virusinfected=0 OR virusinfected IS NULL) AND (nameinfected=0 OR nameinfected IS NULL) AND (otherinfected=0 OR otherinfected IS NULL) AND (isspam=0 OR isspam IS NULL) AND (ishighspam=0 OR ishighspam IS NULL) AND (ismcp=0 OR ismcp IS NULL) AND (ishighmcp=0 OR ishighmcp IS NULL) ) THEN 1 ELSE 0 END )/COUNT(*))*100,1 ) AS cleanpercent, SUM( CASE WHEN virusinfected>0 THEN 1 ELSE 0 END ) AS viruses, ROUND(( SUM( MailScanner seems to start ok: [root@WoodenMS log]# tail -f /var/log/maillog Jan 13 10:52:07 WoodenMS MailScanner[3969]: Read 188 hostnames from the phishing whitelist Jan 13 10:52:07 WoodenMS MailScanner[3969]: Config: calling custom init function SQLBlacklist Jan 13 10:52:07 WoodenMS MailScanner[3969]: Starting up SQL Blacklist Jan 13 10:52:07 WoodenMS MailScanner[3969]: Read 2 blacklist entries Jan 13 10:52:07 WoodenMS MailScanner[3969]: Config: calling custom init function MailWatchLogging Jan 13 10:52:07 WoodenMS MailScanner[3969]: Started SQL Logging child Jan 13 10:52:07 WoodenMS MailScanner[3969]: Config: calling custom init function SQLWhitelist Jan 13 10:52:07 WoodenMS MailScanner[3969]: Starting up SQL Whitelist Jan 13 10:52:07 WoodenMS MailScanner[3969]: Read 4 whitelist entries Jan 13 10:52:08 WoodenMS MailScanner[3969]: Enabling SpamAssassin auto-whitelist functionality... Jan 13 10:52:17 WoodenMS MailScanner[3988]: MailScanner E-Mail Virus Scanner ver sion 4.43.8 starting... Jan 13 10:52:18 WoodenMS MailScanner[3988]: Read 188 hostnames from the phishing whitelist Jan 13 10:52:18 WoodenMS MailScanner[3988]: Config: calling custom init function SQLBlacklist Jan 13 10:52:18 WoodenMS MailScanner[3988]: Starting up SQL Blacklist Jan 13 10:52:18 WoodenMS MailScanner[3988]: Read 2 blacklist entries Jan 13 10:52:18 WoodenMS MailScanner[3988]: Config: calling custom init function MailWatchLogging Jan 13 10:52:18 WoodenMS MailScanner[3988]: Started SQL Logging child Jan 13 10:52:18 WoodenMS MailScanner[3988]: Config: calling custom init function SQLWhitelist Jan 13 10:52:18 WoodenMS MailScanner[3988]: Starting up SQL Whitelist Jan 13 10:52:18 WoodenMS MailScanner[3988]: Read 4 whitelist entries Jan 13 10:52:19 WoodenMS MailScanner[3988]: Enabling SpamAssassin auto-whitelist functionality... Jan 13 10:52:24 WoodenMS MailScanner[3969]: Using locktype = posix Jan 13 10:52:24 WoodenMS MailScanner[3969]: Creating hardcoded struct_flock subr outine for linux (Linux-type) Jan 13 10:52:28 WoodenMS MailScanner[3995]: MailScanner E-Mail Virus Scanner ver sion 4.43.8 starting... Jan 13 10:52:29 WoodenMS MailScanner[3995]: Read 188 hostnames from the phishing whitelist Jan 13 10:52:29 WoodenMS MailScanner[3995]: Config: calling custom init function SQLBlacklist Jan 13 10:52:29 WoodenMS MailScanner[3995]: Starting up SQL Blacklist Jan 13 10:52:29 WoodenMS MailScanner[3995]: Read 2 blacklist entries Jan 13 10:52:29 WoodenMS MailScanner[3995]: Config: calling custom init function MailWatchLogging Jan 13 10:52:29 WoodenMS MailScanner[3995]: Started SQL Logging child Jan 13 10:52:29 WoodenMS MailScanner[3995]: Config: calling custom init function SQLWhitelist Jan 13 10:52:29 WoodenMS MailScanner[3995]: Starting up SQL Whitelist Jan 13 10:52:29 WoodenMS MailScanner[3995]: Read 4 whitelist entries Jan 13 10:52:30 WoodenMS MailScanner[3988]: Using locktype = posix Jan 13 10:52:30 WoodenMS MailScanner[3988]: Creating hardcoded struct_flock subr outine for linux (Linux-type) Jan 13 10:52:31 WoodenMS MailScanner[3995]: Enabling SpamAssassin auto-whitelist functionality... Jan 13 10:52:39 WoodenMS MailScanner[4012]: MailScanner E-Mail Virus Scanner ver sion 4.43.8 starting... Jan 13 10:52:40 WoodenMS MailScanner[4012]: Read 188 hostnames from the phishing whitelist Jan 13 10:52:40 WoodenMS MailScanner[4012]: Config: calling custom init function SQLBlacklist Jan 13 10:52:40 WoodenMS MailScanner[4012]: Starting up SQL Blacklist Jan 13 10:52:40 WoodenMS MailScanner[4012]: Read 2 blacklist entries Jan 13 10:52:40 WoodenMS MailScanner[4012]: Config: calling custom init function MailWatchLogging Jan 13 10:52:40 WoodenMS MailScanner[4012]: Started SQL Logging child Jan 13 10:52:40 WoodenMS MailScanner[4012]: Config: calling custom init function SQLWhitelist Jan 13 10:52:40 WoodenMS MailScanner[4012]: Starting up SQL Whitelist Jan 13 10:52:40 WoodenMS MailScanner[4012]: Read 4 whitelist entries Jan 13 10:52:41 WoodenMS MailScanner[3995]: Using locktype = posix Jan 13 10:52:41 WoodenMS MailScanner[3995]: Creating hardcoded struct_flock subr outine for linux (Linux-type) Jan 13 10:52:42 WoodenMS MailScanner[4012]: Enabling SpamAssassin auto-whitelist functionality... My Versions: CentOS 4 MailScanner 4.40.11 PHP 4.3.9 Sendmail 8.13.4 MailWatch 1.0.1 MySQL mysql Ver 14.7 Distrib 4.1.10a, for redhat-linux-gnu (i686) Apache 2.0 ClamAV 0.87.1 Spamassassin 3.0.4 Bitdefender 7.0.1-3.linux-gcc29x.i586 Created /var/bdc/infected /var/bdc/suspected Installed in dir /opt/bdc Quarantine dir /var/bdc Update - Update bit defender From KShortt at ussco.com Fri Jan 13 16:01:51 2006 From: KShortt at ussco.com (Shortt, Kevin) Date: Fri Jan 13 16:01:33 2006 Subject: Procmail recipe to add MailScanner to the subject line. Message-ID: Typo on my first post.... To == TO :0 hfw * ^TOmailscanner@lists.mailscanner.info |sed -e 's/^Subject:/Subject: \[mailscanner\] /' It's also noteable, that this recipe creates multiple tags with replies to messages that already have them. So if you do not post a lot, and are mindful of your Subject line, then this solution works. I.e. - Subject: [mailscanner] Re: [mailscannner] RE: Original Topic Buyer beware.. -k > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Shortt, Kevin > Sent: Friday, January 13, 2006 10:53 AM > To: MailScanner discussion > Subject: RE: Procmail recipe to add MailScanner to the subject line. > > > :0 hfw > * ^Tomailscanner@lists.mailscanner.info > |sed -e 's/^Subject:/Subject: \[mailscanner\] /' > > > > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of > > Milton Calnek > > Sent: Friday, January 13, 2006 10:20 AM > > To: MailScanner discussion > > Subject: Procmail recipe to add MailScanner to the subject line. > > > > -----BEGIN PGP SIGNED MESSAGE----- > > Hash: SHA1 > > > > Hi, > > > > I'm looking for a procmail recipe that will add MailScanner to the > > Subject line. > > > > TIA. > > > > - -- > > PC Place - Just clicks away > > > > Milton Calnek > > PC Place > > www.pcplace.ca > > 306-359-6939 > > mcalnek@pcplace.ca > > -----BEGIN PGP SIGNATURE----- > > Version: GnuPG v1.4.2 (GNU/Linux) > > Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org > > > > iD8DBQFDx8UmHgnbf2T2QqMRAiEqAKClkELDFtOiM36avFozp+nu9ktz9wCcDNm2 > > BxIJyVAoSxUY557PWzvZVMM= > > =U1NG > > -----END PGP SIGNATURE----- > > > > -- > > DISCLAIMER: The information transmitted is intended only for the > > addressee and may contain confidential, proprietary and/or > privileged > > material. Any unauthorized review, distribution or other > use of or the > > taking of any action in reliance upon this information is > prohibited. > > If you received this in error, please contact the sender > and delete or > > destroy this message and any copies. > > > > -- > > This message has been scanned for viruses and dangerous > > content by MailScanner, and is believed to be clean. > > MailScanner thanks transtec Computers for their support. > > > > -- > > MailScanner mailing list > > MailScanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > > > Support MailScanner development - buy the book off the website! > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! > From dks at schooler.net Fri Jan 13 16:01:51 2006 From: dks at schooler.net (Dave) Date: Fri Jan 13 16:01:55 2006 Subject: unsubscribe In-Reply-To: <43C7CD63.20401@webpipe.net> References: <04D932B0071FE34FA63EBB1977B48D15ACDC81@woodenex.woodmaclaw.local> <43C7CD63.20401@webpipe.net> Message-ID: <43C7CEEF.4000803@schooler.net> unsubscribe Get me off the list. Please! Thanks. Kevin Pendleton wrote: > If I remember correctly you can fix it so those files are not created by > setting "bayes_auto_expire 0" in your spam.assassin.prefs.conf file. > > Kevin > > Billy A. Pumphrey wrote: > >> [root@WoodenMS bayes]# df -h >> Filesystem Size Used Avail Use% Mounted on >> /dev/mapper/VolGroup00-LogVol00 >> 32G 4.1G 26G 14% / >> /dev/ida/c0d0p1 99M 25M 69M 27% /boot >> none 506M 0 506M 0% /dev/shm >> >> The bayes exp tokens took it all up. I delete the quarantine but that >> wasn't much. After the tokens I got the above. Thanks guys. >> >> >> Billy Pumphrey >> IT Manager >> Wooden & McLaughlin >> >> From bpumphrey at WoodMacLaw.com Fri Jan 13 16:05:18 2006 From: bpumphrey at WoodMacLaw.com (Billy A. Pumphrey) Date: Fri Jan 13 16:05:22 2006 Subject: Disk is full Message-ID: <04D932B0071FE34FA63EBB1977B48D15ACDCC8@woodenex.woodmaclaw.local> Ok, I will set it. Good info! Billy Pumphrey IT Manager Wooden & McLaughlin > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Kevin Pendleton > Sent: Friday, January 13, 2006 10:55 AM > To: MailScanner discussion > Subject: Re: Disk is full > > If I remember correctly you can fix it so those files are not created by > setting "bayes_auto_expire 0" in your spam.assassin.prefs.conf file. > > Kevin > > Billy A. Pumphrey wrote: > > [root@WoodenMS bayes]# df -h > > Filesystem Size Used Avail Use% Mounted on > > /dev/mapper/VolGroup00-LogVol00 > > 32G 4.1G 26G 14% / > > /dev/ida/c0d0p1 99M 25M 69M 27% /boot > > none 506M 0 506M 0% /dev/shm > > > > The bayes exp tokens took it all up. I delete the quarantine but that > > wasn't much. After the tokens I got the above. Thanks guys. > > > > > > Billy Pumphrey > > IT Manager > > Wooden & McLaughlin > > > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! From bpumphrey at WoodMacLaw.com Fri Jan 13 16:08:41 2006 From: bpumphrey at WoodMacLaw.com (Billy A. Pumphrey) Date: Fri Jan 13 16:08:43 2006 Subject: Disk is full Message-ID: <04D932B0071FE34FA63EBB1977B48D15ACDCCF@woodenex.woodmaclaw.local> > > Snip > > I am not out of the water quite yet. My MailWatch is not working > correctly now. If I should move this to the mailwatch list, please say > so. This happened because of the full disk I would assume, as it worked > before then. > > When I go to the web page for mailwatch I get: > > Error executing query: > > Can't open file: 'maillog.MYI' (errno: 145) > Snip After trying some things in mysql such as... Use mailscanner I got: Didn't find any fields in table 'maillog' mysql> select * from maillog -> ; ERROR 1016 (HY000): Can't open file: 'maillog.MYI' (errno: 145) So..... Does this mean that my maillog table got messed up/deleted and I cannot get my rows back? From richard.gray at dns.co.uk Fri Jan 13 16:13:07 2006 From: richard.gray at dns.co.uk (Gray, Richard) Date: Fri Jan 13 16:13:13 2006 Subject: Subject rewriting quarantined messages Message-ID: Is it possible to re-write the subject line AND quarantine a message? As far as I can make it, either the message action is set to deliver and the subject gets rewritten, or the action is set to store in which case the subject remains the same. Any pointers you guys have would be great, Thanks. R ________________________________ richard gray dns ltd 83 princes street, edinburgh, eh2 2er t: +44 (0) 870 085 8555 f: +44 (0) 870 085 8556 m: +44 (0) 777 569 2145 w: http://www.dns.co.uk/ ----------------------- This email from dns has been validated by dnsMSS(TM) Managed Email Security and is free from all known viruses. For further information contact email-integrity@dns.co.uk -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060113/f62a6183/attachment-0001.html From JVolckaert at Bellmemorial.org Fri Jan 13 16:15:44 2006 From: JVolckaert at Bellmemorial.org (Jeff A. Volckaert) Date: Fri Jan 13 16:14:33 2006 Subject: Digest mode? Message-ID: <50AB1578C809C34B9B72A778CADF6AFB54D719@exchange.bellmemorial.org> Hello Everybody, I changed my options this morning for Digest mode (which I used on the old list), but that hasn't seemed to take effect. Is digest mode not working? Jeff -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060113/d00c0636/attachment.html From MailScanner at ecs.soton.ac.uk Fri Jan 13 16:18:06 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 13 16:18:21 2006 Subject: Disk is full In-Reply-To: <04D932B0071FE34FA63EBB1977B48D15ACDC81@woodenex.woodmaclaw.local> References: <04D932B0071FE34FA63EBB1977B48D15ACDC81@woodenex.woodmaclaw.local> Message-ID: <0D137A2D-A5A6-4AB9-B950-2CD85B3873C5@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- The most recent version of MailScanner has improved the reliability of the Bayes expiry process a lot. Hopefully you will get far less bayes expiry files now. Also, you have a script in place that will automatically clean up your quarantine for you, deleting anything over a certain age. Take a look at /etc/cron.daily/clean.quarantine and flip the "$disabled = 1;" to "$disabled = 0;" at the top of the file. I must do a bit of work on this script and move the switches to /etc/ sysconfig/MailScanner. But it works perfectly well now. On 13 Jan 2006, at 15:16, Billy A. Pumphrey wrote: > [root@WoodenMS bayes]# df -h > Filesystem Size Used Avail Use% Mounted on > /dev/mapper/VolGroup00-LogVol00 > 32G 4.1G 26G 14% / > /dev/ida/c0d0p1 99M 25M 69M 27% /boot > none 506M 0 506M 0% /dev/shm > > The bayes exp tokens took it all up. I delete the quarantine but that > wasn't much. After the tokens I got the above. Thanks guys. > > > Billy Pumphrey > IT Manager > Wooden & McLaughlin > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Stephen Swaney >> Sent: Friday, January 13, 2006 10:04 AM >> To: 'MailScanner discussion' >> Subject: RE: Disk is full >> >> >>> -----Original Message----- >>> From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- >>> bounces@lists.mailscanner.info] On Behalf Of raymond@prolocation.net >>> Sent: Friday, January 13, 2006 9:55 AM >>> To: MailScanner discussion >>> Subject: Re: Disk is full >>> >>> Hi! >>> >>>> My disk is full on my spam box. What can I delete? Here is a >> rundown. >>>> I am guessing that I can delete quarantine and stuff, but I do not >> know. >>>> >>>> [root@WoodenMS log]# df -h >>>> Filesystem Size Used Avail Use% Mounted on >>>> /dev/mapper/VolGroup00-LogVol00 >>>> 32G 30G 0 100% / >>>> /dev/ida/c0d0p1 99M 25M 69M 27% /boot >>>> none 506M 0 506M 0% /dev/shm >>> >>> Check the delete script for your quarantine dir... :) >>> >>> You could safely empty the quarantine dir ... if you need some > space. >>> >>> Bye, >>> Raymond. >> >> You should also look for old systems log files. >> >> If you're running razor, look for a razor-agent.log. If you find a > large >> razor log, set >> >> debuglevel = 0 >> >> in the razor-agent.conf file. >> >> Steve >> >> Stephen Swaney >> Fort Systems Ltd. >> stephen.swaney@fsl.com >> www.fsl.com >> >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read the Wiki (http://wiki.mailscanner.info/). >> >> Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8fSwfw32o+k+q+hAQGd6Af+LYyDgm53kZzQE77ZcvxAdbTYQGoACfp7 wSQMmrNiGcTAWK4Q3RnevsQRZndIRFQwqCOSuMFwxzCNDJ1/gelcgWUo6V2V+Gkt gQeX3kI6si30G6FSHutOvLGs7vXiq8uYaosAWSNdeZyWwjvcS65x6CojuPuyuF3b 5UdZIf9aaxuVIY1r6UAp8uJOrQDHHaDhh1PrBxKe7sVXGXoD6/hXeeCoscvxrZm7 M5+ovSbeTF+loFEbP0lPdd02v6locCciFEsGI5lZWUYafHRg5DMHhj7XHEwY1/rY mgzdICDDSyBCLgIHXagd5NBPmnG+LNxJycSw9KxSX6OK2UxhFN0jdw== =iWIJ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Fri Jan 13 16:24:45 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 13 16:24:57 2006 Subject: Subject rewriting quarantined messages In-Reply-To: References: Message-ID: Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: PGP.sig Type: application/pgp-signature Size: 483 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060113/56e95cac/PGP.bin From Kevin_Miller at ci.juneau.ak.us Fri Jan 13 16:35:34 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Fri Jan 13 16:35:37 2006 Subject: ANNOUNCE: This list is moving too. Message-ID: <82895A755D1EA5458EC9E64021922AD2D155DA@city-exch-w3e.cbj.local> Matt Kettler wrote: > #whitelist mailscanner mailing list > whitelist_from_rcvd mailscanner-bounces@lists.mailscanner.info > bkserver.blacknight.ie > > #Force bayes autolearning to be disabled for MailScanner list > # (don't want to learn as ham any messages containing spam quotes) > > bayes_ignore_from mailscanner-bounces@lists.mailscanner.info > bayes_ignore_to mailscanner@lists.mailscanner.info Morning Matt, Am I correct in thinking that the above lines should go in spam.assassin.rules.conf? Or is local.cf the better place? TIA... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From shuttlebox at gmail.com Fri Jan 13 16:41:03 2006 From: shuttlebox at gmail.com (shuttlebox) Date: Fri Jan 13 16:41:06 2006 Subject: unsubscribe In-Reply-To: <43C7CEEF.4000803@schooler.net> References: <04D932B0071FE34FA63EBB1977B48D15ACDC81@woodenex.woodmaclaw.local> <43C7CD63.20401@webpipe.net> <43C7CEEF.4000803@schooler.net> Message-ID: <625385e30601130841k38eb75c8p37d050d422f4289b@mail.gmail.com> On 1/13/06, Dave wrote: > > unsubscribe > > Get me off the list. Please! > Get yourself off the list. Your mom doesn't subscribe here. ;-) http://lists.mailscanner.info/mailman/listinfo/mailscanner -- /peter -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060113/eda8da06/attachment.html From martinh at solid-state-logic.com Fri Jan 13 16:54:21 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Fri Jan 13 16:54:54 2006 Subject: ANNOUNCE: This list is moving too. In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D155DA@city-exch-w3e.cbj.local> Message-ID: <014e01c61862$01147f60$3004010a@martinhlaptop> I put a ruleset against Is Definitely Not Spam = %rules-dir%/spam.whitelist.rules And this rule says.. From: mailscanner-bounces@lists.mailscanner.info yes That way MS list emails go no where near SA. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Kevin Miller > Sent: 13 January 2006 16:36 > To: MailScanner discussion > Subject: RE: ANNOUNCE: This list is moving too. > > Matt Kettler wrote: > > #whitelist mailscanner mailing list > > whitelist_from_rcvd mailscanner-bounces@lists.mailscanner.info > > bkserver.blacknight.ie > > > > #Force bayes autolearning to be disabled for MailScanner list > > # (don't want to learn as ham any messages containing spam quotes) > > > > bayes_ignore_from mailscanner-bounces@lists.mailscanner.info > > bayes_ignore_to mailscanner@lists.mailscanner.info > > Morning Matt, > > Am I correct in thinking that the above lines should go in > spam.assassin.rules.conf? Or is local.cf the better place? > > TIA... > > ...Kevin > -- > Kevin Miller Registered Linux User No: 307357 > CBJ MIS Dept. Network Systems Admin., Mail Admin. > 155 South Seward Street ph: (907) 586-0242 > Juneau, Alaska 99801 fax: (907 586-4500 > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From glenn.steen at gmail.com Fri Jan 13 16:59:50 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Jan 13 16:59:54 2006 Subject: Disk is full In-Reply-To: <04D932B0071FE34FA63EBB1977B48D15ACDCCF@woodenex.woodmaclaw.local> References: <04D932B0071FE34FA63EBB1977B48D15ACDCCF@woodenex.woodmaclaw.local> Message-ID: <223f97700601130859o6df5f025g@mail.gmail.com> On 13/01/06, Billy A. Pumphrey wrote: > > > > Snip > > > > I am not out of the water quite yet. My MailWatch is not working > > correctly now. If I should move this to the mailwatch list, please > say > > so. This happened because of the full disk I would assume, as it > worked > > before then. > > > > When I go to the web page for mailwatch I get: > > > > Error executing query: > > > > Can't open file: 'maillog.MYI' (errno: 145) > > > > Snip > > After trying some things in mysql such as... > > Use mailscanner > I got: > Didn't find any fields in table 'maillog' > > mysql> select * from maillog > -> ; > ERROR 1016 (HY000): Can't open file: 'maillog.MYI' (errno: 145) > > > > So..... > Does this mean that my maillog table got messed up/deleted and I cannot > get my rows back? Messed up ISAM file(s), yes. Try running mysqlismchk on it/them. IIRC mysql will not touch it before you do. -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From campbell at cnpapers.com Fri Jan 13 17:20:43 2006 From: campbell at cnpapers.com (Steve Campbell) Date: Fri Jan 13 17:20:56 2006 Subject: Disk is full References: <04D932B0071FE34FA63EBB1977B48D15ACDCCF@woodenex.woodmaclaw.local> <223f97700601130859o6df5f025g@mail.gmail.com> Message-ID: <005801c61865$af6b82e0$0705000a@DDF5DW71> ----- Original Message ----- From: "Glenn Steen" To: "MailScanner discussion" Sent: Friday, January 13, 2006 11:59 AM Subject: Re: Disk is full > On 13/01/06, Billy A. Pumphrey wrote: >> > >> > Snip >> > >> > I am not out of the water quite yet. My MailWatch is not working >> > correctly now. If I should move this to the mailwatch list, please >> say >> > so. This happened because of the full disk I would assume, as it >> worked >> > before then. >> > >> > When I go to the web page for mailwatch I get: >> > >> > Error executing query: >> > >> > Can't open file: 'maillog.MYI' (errno: 145) >> > >> >> Snip >> >> After trying some things in mysql such as... >> >> Use mailscanner >> I got: >> Didn't find any fields in table 'maillog' >> >> mysql> select * from maillog >> -> ; >> ERROR 1016 (HY000): Can't open file: 'maillog.MYI' (errno: 145) >> >> >> >> So..... >> Does this mean that my maillog table got messed up/deleted and I cannot >> get my rows back? > > Messed up ISAM file(s), yes. Try running mysqlismchk on it/them. IIRC > mysql will not touch it before you do. > -- > -- Glenn > email: glenn < dot > steen < at > gmail < dot > com > work: glenn < dot > steen < at > ap1 < dot > se > -- You'll probably need to use the -r or -o option with that check. I usually run the checks as follows: cd /var/lib/mysql/mailscanner myisamchk maillog.MYI if that returns an error other than the one saying a user is still using the db then stop mysql myisamchk -r maillog.MYI restart mysql You may have more problems with more databases and tables. If mysql doesn't start, try checking all tables in all databases. use something like in each database directory myisamchk *.MYI then run myisamchk with the -r or -o option as above on each index that reports an error with mysql stopped. Steve Campbell campbell@cnpapers.com Charleston Newspapers From ssilva at sgvwater.com Fri Jan 13 18:46:18 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Jan 13 18:46:47 2006 Subject: unsubscribe In-Reply-To: <625385e30601130841k38eb75c8p37d050d422f4289b@mail.gmail.com> References: <04D932B0071FE34FA63EBB1977B48D15ACDC81@woodenex.woodmaclaw.local> <43C7CD63.20401@webpipe.net> <43C7CEEF.4000803@schooler.net> <625385e30601130841k38eb75c8p37d050d422f4289b@mail.gmail.com> Message-ID: <43C7F57A.80905@sgvwater.com> shuttlebox spake the following on 1/13/2006 8:41 AM: > On 1/13/06, *Dave* > wrote: > > unsubscribe > > Get me off the list. Please! > > > Get yourself off the list. Your mom doesn't subscribe here. ;-) > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > -- > /peter > Here Here!!! Having a fit with GMANE... Have to post directly to the list. Let me know if it mucks up anything. -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () This message has been scanned for viruses and dangerous content by the San Gabriel Valley Water Co. MailScanner, and is believed to be clean. From alex at nkpanama.com Fri Jan 13 18:55:09 2006 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Fri Jan 13 18:55:23 2006 Subject: unsubscribe In-Reply-To: <43C7F57A.80905@sgvwater.com> References: <04D932B0071FE34FA63EBB1977B48D15ACDC81@woodenex.woodmaclaw.local> <43C7CD63.20401@webpipe.net> <43C7CEEF.4000803@schooler.net> <625385e30601130841k38eb75c8p37d050d422f4289b@mail.gmail.com> <43C7F57A.80905@sgvwater.com> Message-ID: <43C7F78D.2030106@nkpanama.com> Makes me wonder how people who can't be bothered to read the unsubscribe instructions are subscribed to the list. If they can't handle a simple web form, how can they manage a mailserver? Scott Silva wrote: > shuttlebox spake the following on 1/13/2006 8:41 AM: > >> On 1/13/06, *Dave* > wrote: >> >> unsubscribe >> >> Get me off the list. Please! >> >> >> Get yourself off the list. Your mom doesn't subscribe here. ;-) >> >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> -- >> /peter >> >> > Here Here!!! > Having a fit with GMANE... Have to post directly to the list. > Let me know if it mucks up anything. > > From joey at joesmith.net Fri Jan 13 18:55:36 2006 From: joey at joesmith.net (Joe Smith) Date: Fri Jan 13 18:55:40 2006 Subject: unsubscribe In-Reply-To: <43C7F57A.80905@sgvwater.com> Message-ID: On Fri, 13 Jan 2006, Scott Silva wrote: > > http://lists.mailscanner.info/mailman/listinfo/mailscanner I wanted to set mine back to digest mode but got no reply from Mr. Mailman. From michele at blacknight.ie Fri Jan 13 19:02:45 2006 From: michele at blacknight.ie (Michele Neylon :: Blacknight) Date: Fri Jan 13 19:02:48 2006 Subject: unsubscribe In-Reply-To: <43C7F78D.2030106@nkpanama.com> References: <04D932B0071FE34FA63EBB1977B48D15ACDC81@woodenex.woodmaclaw.local> <43C7CD63.20401@webpipe.net> <43C7CEEF.4000803@schooler.net> <625385e30601130841k38eb75c8p37d050d422f4289b@mail.gmail.com> <43C7F57A.80905@sgvwater.com> <43C7F78D.2030106@nkpanama.com> Message-ID: <43C7F955.7020506@blacknight.ie> Alex Neuman van der Hans wrote: > Makes me wonder how people who can't be bothered to read the unsubscribe > instructions are subscribed to the list. If they can't handle a simple > web form, how can they manage a mailserver? Maybe they're "special" ? :) -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 From chrisk at os-it.net Fri Jan 13 19:02:19 2006 From: chrisk at os-it.net (Chris Kissinger) Date: Fri Jan 13 19:04:17 2006 Subject: Trend-autoupdate Message-ID: <200601131904.k0DJ4CSu013099@tsissvr01.tsis.net> Well as Stefan stated back in 8/2004 the update made to the script would only work up to ver 999 and as of December 2005 Trend has rolled to a 100 series again. Without a complete rewrite of the script here's 2 quick and easy changes that should make it continue to work. Change line 24: CURRENTVER=`ls $PackageDir/* | grep lpt | tail -1 | cut -d. -f 2` To: CURRENTVER=`ls -rt $PackageDir/* | grep lpt | tail -1 | cut -d. -f 2` And line 42: if [ $CURRENTVER -lt $NEWVER ] To: if [ $CURRENTVER -ne $NEWVER ] I'm pretty sure if Trend's numbers are going backwards it's going to be for good reason so no need to check for anything actually being a smaller number. Chris Kissinger From jaearick at colby.edu Fri Jan 13 19:15:17 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Fri Jan 13 19:15:35 2006 Subject: 4.50.6: SA cache, a syslog suggestion Message-ID: Julian, I upgraded to 4.50.6 today on Solaris 9; thank God for the MAQ Wiki and the tip there about SQLite (-lrt) for Solaris. That one had me baffled for a while. A suggestion for the syslog output regarding caching. Whilst grepping for "cache" in my syslog, I saw: SpamAssassin cache hit for message k0DIeO6M000601 so then I grepped for the messageID. Another syslog related to this was: Spam Actions: message k0DIeO6M000601 actions are [whatever] How about noting if the Spam Action was a result of caching, eg: Spam Actions: message k0DIeO6M000601 actions are [whatever] (cached) if the action resulted from a hit in the SA cache? Jeff Earickson Colby College From ramon at linux-labs.net Fri Jan 13 19:24:30 2006 From: ramon at linux-labs.net (Ramon Acedo) Date: Fri Jan 13 19:27:57 2006 Subject: Bounce non-spam messages In-Reply-To: <1137151002.26473.175.camel@localhost.localdomain> References: <1137145068.30556.15.camel@pangeadm.upc.es> <1137151002.26473.175.camel@localhost.localdomain> Message-ID: <1137180270.31907.19.camel@pangeadm.upc.es> Hi Steve, El vie, 13--2006 a las 11:16 +0000, Steve Freegard escribi?: > > > > from time to time users ask if is there the possibility of bouncing > > emails from a particular sender. This sender can be a legitimate sender > > for the system (but not for the user asking for his messages to be > > dropped). > > > > Is there any way of managing this in MS? I'm trying to do it with > > Sendmail feature "delay_checks hater" and "access_db" but it isn't > > work as I expect. > > This is definitely better done at the MTA level - you could use the > Sendmail compat_check feature for this. > > After the access_db definition in sendmail.mc add: > > FEATURE(`compat_check')dnl > See http://www.sendmail.org/m4/features.html#compat_check for details. > > Hope this helps. Thanks for pointing me to the right way, it was exactly what I needed although the delay_checks with the "hater" config should also work (http://www.sendmail.org/m4/anti_spam.html#delay_check) this feature is much better for this purpose. In Debian I configured it in this way: # cd /etc/mail # vi sendmail.mc FEATURE(`compat_check')dnl <-- Somewhere after the line FEATURE(`access_db', , `skip')dnl # vi access Compat:sender@a.b<@>recipient@mydoma.in ERROR:553 Message not delivered # make # /etc/init.d/sendmail reload That's it Ramon From MailScanner at ecs.soton.ac.uk Fri Jan 13 20:32:46 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 13 20:32:54 2006 Subject: Trend-autoupdate In-Reply-To: <200601131904.k0DJ4CSu013099@tsissvr01.tsis.net> References: <200601131904.k0DJ4CSu013099@tsissvr01.tsis.net> Message-ID: <43C80E6E.1020900@ecs.soton.ac.uk> These 2 changes will be in the next release. Chris Kissinger wrote: > Well as Stefan stated back in 8/2004 the update made to the script would > only work up to ver 999 and as of December 2005 Trend has rolled to a 100 > series again. Without a complete rewrite of the script here's 2 quick and > easy changes that should make it continue to work. > > Change line 24: > CURRENTVER=`ls $PackageDir/* | grep lpt | tail -1 | cut -d. -f 2` > To: > CURRENTVER=`ls -rt $PackageDir/* | grep lpt | tail -1 | cut -d. -f 2` > > And line 42: > if [ $CURRENTVER -lt $NEWVER ] > To: > if [ $CURRENTVER -ne $NEWVER ] > > I'm pretty sure if Trend's numbers are going backwards it's going to be for > good reason so no need to check for anything actually being a smaller > number. > > Chris Kissinger > > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Fri Jan 13 20:35:37 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 13 20:35:42 2006 Subject: 4.50.6: SA cache, a syslog suggestion In-Reply-To: References: Message-ID: <43C80F19.3070502@ecs.soton.ac.uk> Jeff A. Earickson wrote: > Julian, > > I upgraded to 4.50.6 today on Solaris 9; thank God for the MAQ > Wiki and the tip there about SQLite (-lrt) for Solaris. That > one had me baffled for a while. > > A suggestion for the syslog output regarding caching. Whilst > grepping for "cache" in my syslog, I saw: > > SpamAssassin cache hit for message k0DIeO6M000601 > > so then I grepped for the messageID. Another syslog related to > this was: > > Spam Actions: message k0DIeO6M000601 actions are [whatever] > > How about noting if the Spam Action was a result of caching, eg: > > Spam Actions: message k0DIeO6M000601 actions are [whatever] (cached) > > if the action resulted from a hit in the SA cache? The actions are not cached, just the SpamAssassin result. So if a ruleset depending on the sender address had different spam actions, then it would be stating something wrong. The actions weren't as a result of the cache, they were as a result of the SpamAssassin cache as usual. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From doc at maddoc.net Sat Jan 14 04:26:37 2006 From: doc at maddoc.net (Doc Schneider) Date: Sat Jan 14 04:26:42 2006 Subject: processing backlog Message-ID: <43C87D7D.4050605@maddoc.net> Is there a way for me to just have MailScanner handle a huge backlog of e-mails and not accept any new incoming? I've got a big mqueue.in full of new mail and MS seems to be only churning through like 20 or so an hour. What happened was my main mail server dropped a drive in its RAID array and I had to replace it and then rebuild the raid. So there's now like a couple days worth of mail sitting on my old slow secondary server that needs to be processed. I did turn off the "outgoing" while the mail server was down. But at this rate it is going to take a month to get through all the mail sitting there.... and intermixed with the good mail is the spam crap that always hits my secondary server... Any ideas? Thanks, -- -Doc Lincoln, NE. From michele at blacknight.ie Sat Jan 14 05:06:24 2006 From: michele at blacknight.ie (Michele Neylon:: Blacknight.ie) Date: Sat Jan 14 05:06:25 2006 Subject: processing backlog In-Reply-To: <43C87D7D.4050605@maddoc.net> References: <43C87D7D.4050605@maddoc.net> Message-ID: <43C886D0.1090609@blacknight.ie> Doc Schneider wrote: > Is there a way for me to just have MailScanner handle a huge backlog of > e-mails and not accept any new incoming? > An iptables rule? Simply block inbound connections while you process the backlog. I know we've done it on servers in the past -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 From doc at maddoc.net Sat Jan 14 05:12:15 2006 From: doc at maddoc.net (Doc Schneider) Date: Sat Jan 14 05:12:16 2006 Subject: processing backlog In-Reply-To: <43C886D0.1090609@blacknight.ie> References: <43C87D7D.4050605@maddoc.net> <43C886D0.1090609@blacknight.ie> Message-ID: <43C8882F.70707@maddoc.net> Michele Neylon:: Blacknight.ie wrote: > Doc Schneider wrote: >> Is there a way for me to just have MailScanner handle a huge backlog of >> e-mails and not accept any new incoming? >> > > An iptables rule? > Simply block inbound connections while you process the backlog. I know > we've done it on servers in the past > Michele, Yeah I would do that is I could... did I saw this was an old slow box? 8*( Before the other server needed to be fixed I had it planned to upgrade that boxens OS. Guess I should see if I shouldn't do that. -- -Doc Lincoln, NE. From matt at coders.co.uk Sat Jan 14 10:02:57 2006 From: matt at coders.co.uk (Matt Hampton) Date: Sat Jan 14 10:04:05 2006 Subject: processing backlog In-Reply-To: <43C87D7D.4050605@maddoc.net> References: <43C87D7D.4050605@maddoc.net> Message-ID: <43C8CC51.60309@coders.co.uk> Doc Schneider wrote: > Is there a way for me to just have MailScanner handle a huge backlog of > e-mails and not accept any new incoming? Not a mailscanner function - this is the MTA responsibility. If it was my machine and I was happy of the stability of the primary then I would stop the MTA process that is listening for new mail. > > I've got a big mqueue.in full of new mail and MS seems to be only > churning through like 20 or so an hour. Ouch! matt From paul at blacknight.ie Sat Jan 14 10:43:20 2006 From: paul at blacknight.ie (Paul Kelly :: Blacknight) Date: Sat Jan 14 10:43:23 2006 Subject: processing backlog In-Reply-To: <43C87D7D.4050605@maddoc.net> References: <43C87D7D.4050605@maddoc.net> Message-ID: <1137235400.9666.1.camel@localhost.localdomain> Hi, On Fri, 2006-01-13 at 22:26 -0600, Doc Schneider wrote: > What happened was my main mail server dropped a drive in its RAID array > and I had to replace it and then rebuild the raid. So there's now like a > couple days worth of mail sitting on my old slow secondary server that > needs to be processed. I did turn off the "outgoing" while the mail > server was down. But at this rate it is going to take a month to get > through all the mail sitting there.... and intermixed with the good mail > is the spam crap that always hits my secondary server... > stop the mta on both boxes. tar up /var/spool/mqueue.in/ on slow secondary. Untar on fast primary. Restart MTA's (obviously remove the mail from the old box) Paul > Any ideas? > > Thanks, > -- > -Doc > Lincoln, NE. -- Paul Kelly Technical Director Blacknight Internet Solutions ltd Hosting, Colocation, Dedicated servers Tel: 059 9183072 DDI: 059 9183091 e-mail: paul@blacknight.ie From MailScanner at ecs.soton.ac.uk Sat Jan 14 12:44:19 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat Jan 14 12:44:28 2006 Subject: processing backlog In-Reply-To: <43C8CC51.60309@coders.co.uk> References: <43C87D7D.4050605@maddoc.net> <43C8CC51.60309@coders.co.uk> Message-ID: <43C8F223.1070208@ecs.soton.ac.uk> Matt Hampton wrote: > Doc Schneider wrote: > >> Is there a way for me to just have MailScanner handle a huge backlog of >> e-mails and not accept any new incoming? >> > > Not a mailscanner function - this is the MTA responsibility. If it was > my machine and I was happy of the stability of the primary then I would > stop the MTA process that is listening for new mail. > > > >> I've got a big mqueue.in full of new mail and MS seems to be only >> churning through like 20 or so an hour. >> > > Ouch! If you are using sendmail, you can move the qf and df files into the /var/spool/mqueue.in on the fast server to get the backlog cleared quickly. On a RedHat box, you could easily kill the incoming sendmail with this: service MailScanner stop service MailScanner startout check_MailScanner <--- Wait a minute before you do this step -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From smf at f2s.com Sat Jan 14 14:08:18 2006 From: smf at f2s.com (Steve Freegard) Date: Sat Jan 14 14:07:25 2006 Subject: Exclusion List In-Reply-To: <20060109212415.GJ8774@doctor.nl2k.ab.ca> References: <625385e30601090139q2284270cu4960fbbd138be351@mail.gmail.com> <013101c61501$95706700$3004010a@martinhlaptop> <20060109212415.GJ8774@doctor.nl2k.ab.ca> Message-ID: <1137247699.26473.251.camel@localhost.localdomain> On Mon, 2006-01-09 at 14:24 -0700, Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem wrote: > > So far so good, but what about case sensitivity issues? > I've looked at the source - the to/from pairs from the queue file are always lc()'d as are the values read from the ruleset so case really doesn't matter. Before anyone mentions - yes RFC2821 does say that local-parts can and and must be treated as case-sensitive but it also states in the same paragraph - 'exploiting the case sensitivity of mailbox local-parts impedes interoperability and is discouraged', so in reality this shouldn't cause any issues. Regards, Steve. From maillists at conactive.com Sat Jan 14 14:31:16 2006 From: maillists at conactive.com (Kai Schaetzl) Date: Sat Jan 14 14:31:23 2006 Subject: Spam Mails In-Reply-To: <95873e560601130047p797bd051nfaec6f8607e254f1@mail.gmail.com> References: <95873e560601130047p797bd051nfaec6f8607e254f1@mail.gmail.com> Message-ID: Nilesh Shastrakar wrote on Fri, 13 Jan 2006 14:17:43 +0530: > How do I solve it ? Not with MailScanner. You may want to - subscribe to the sa-talk list - visit www.rulesemporium.com Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From root at doctor.nl2k.ab.ca Sat Jan 14 14:38:38 2006 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Sat Jan 14 14:39:52 2006 Subject: Exclusion List In-Reply-To: <1137247699.26473.251.camel@localhost.localdomain> References: <625385e30601090139q2284270cu4960fbbd138be351@mail.gmail.com> <013101c61501$95706700$3004010a@martinhlaptop> <20060109212415.GJ8774@doctor.nl2k.ab.ca> <1137247699.26473.251.camel@localhost.localdomain> Message-ID: <20060114143838.GA6770@doctor.nl2k.ab.ca> On Sat, Jan 14, 2006 at 02:08:18PM +0000, Steve Freegard wrote: > On Mon, 2006-01-09 at 14:24 -0700, Dave Shariff Yadallee - System > Administrator a.k.a. The Root of the Problem wrote: > > > > So far so good, but what about case sensitivity issues? > > > > I've looked at the source - the to/from pairs from the queue file are > always lc()'d as are the values read from the ruleset so case really > doesn't matter. > > Before anyone mentions - yes RFC2821 does say that local-parts can and > and must be treated as case-sensitive but it also states in the same > paragraph - 'exploiting the case sensitivity of mailbox local-parts > impedes interoperability and is discouraged', so in reality this > shouldn't cause any issues. > Still why are some e-mail being scanned when they are told not to do so? > Regards, > Steve. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Sat Jan 14 15:04:50 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat Jan 14 15:04:59 2006 Subject: Exclusion List In-Reply-To: <1137247699.26473.251.camel@localhost.localdomain> References: <625385e30601090139q2284270cu4960fbbd138be351@mail.gmail.com> <013101c61501$95706700$3004010a@martinhlaptop> <20060109212415.GJ8774@doctor.nl2k.ab.ca> <1137247699.26473.251.camel@localhost.localdomain> Message-ID: <43C91312.7080408@ecs.soton.ac.uk> Steve Freegard wrote: > On Mon, 2006-01-09 at 14:24 -0700, Dave Shariff Yadallee - System > Administrator a.k.a. The Root of the Problem wrote: > >> So far so good, but what about case sensitivity issues? >> >> > > I've looked at the source - the to/from pairs from the queue file are > always lc()'d as are the values read from the ruleset so case really > doesn't matter. > > Before anyone mentions - yes RFC2821 does say that local-parts can and > and must be treated as case-sensitive but it also states in the same > paragraph - 'exploiting the case sensitivity of mailbox local-parts > impedes interoperability and is discouraged', so in reality this > shouldn't cause any issues. > MailScanner breaks RFC2821 by ignoring case in local parts of addresses. It's fully intentional. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From smf at f2s.com Sat Jan 14 15:25:22 2006 From: smf at f2s.com (Steve Freegard) Date: Sat Jan 14 15:24:30 2006 Subject: Exclusion List In-Reply-To: <20060114143838.GA6770@doctor.nl2k.ab.ca> References: <625385e30601090139q2284270cu4960fbbd138be351@mail.gmail.com> <013101c61501$95706700$3004010a@martinhlaptop> <20060109212415.GJ8774@doctor.nl2k.ab.ca> <1137247699.26473.251.camel@localhost.localdomain> <20060114143838.GA6770@doctor.nl2k.ab.ca> Message-ID: <1137252322.26473.273.camel@localhost.localdomain> On Sat, 2006-01-14 at 07:38 -0700, Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem wrote: > Still why are some e-mail being scanned when they are told not to do so? >From the information you've provided so far - I haven't got a clue (see http://www.chiark.greenend.org.uk/~sgtatham/bugs.html). You need to do some basic troubleshooting - for instance, set up the 'Archive Mail' option for the domain that shouldn't be scanned so that you can refer to the original message to find out what might have caused it be scanned. The message could be 'To' multiple recipients with conflicting settings (in which case the default setting in the ruleset is used) - it could be the messages are being sent to an alias instead of what you have in your ruleset which isn't causing the rules to match or a whole load of other things. If you want help with something then actually *show* the problem (I don't mean by posting pages of log data which nobody will be bothered to sift through), I mean show the relevant lines from the ruleset and the default rule and which configuration value you have attached the ruleset to and show the actual message headers of two example messages that illustrate your point. Regards, Steve. From jomartial at yahoo.fr Sat Jan 14 15:43:01 2006 From: jomartial at yahoo.fr (martial monthe) Date: Sat Jan 14 15:43:04 2006 Subject: www.tchatche.ci In-Reply-To: <1137252322.26473.273.camel@localhost.localdomain> Message-ID: <20060114154301.52987.qmail@web25602.mail.ukl.yahoo.com> Salut ? tous, juste une petite infos pour les tchatcheurs. et bien sachez que la C?te d'Ivoire a un tchatche qui se nomme www.tchatche.ci fait avec des Logiciels Libres et heberger sur une plate forme Libre. Visitez le et donner moi votre avis. Martial Steve Freegard a ?crit : On Sat, 2006-01-14 at 07:38 -0700, Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem wrote: > Still why are some e-mail being scanned when they are told not to do so? >From the information you've provided so far - I haven't got a clue (see http://www.chiark.greenend.org.uk/~sgtatham/bugs.html). You need to do some basic troubleshooting - for instance, set up the 'Archive Mail' option for the domain that shouldn't be scanned so that you can refer to the original message to find out what might have caused it be scanned. The message could be 'To' multiple recipients with conflicting settings (in which case the default setting in the ruleset is used) - it could be the messages are being sent to an alias instead of what you have in your ruleset which isn't causing the rules to match or a whole load of other things. If you want help with something then actually *show* the problem (I don't mean by posting pages of log data which nobody will be bothered to sift through), I mean show the relevant lines from the ruleset and the default rule and which configuration value you have attached the ruleset to and show the actual message headers of two example messages that illustrate your point. Regards, Steve. -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read the Wiki (http://wiki.mailscanner.info/). Support MailScanner development - buy the book off the website! MONTHE DJOMBISSIE IDRISS MARTIAL monthemartial@yahoo.fr 25 bp 1670 abidjan 25 22437831 --------------------------------- Nouveau : t?l?phonez moins cher avec Yahoo! Messenger ! D?couvez les tarifs exceptionnels pour appeler la France et l'international.T?l?chargez la version beta. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060114/5bd8af1f/attachment.html From root at doctor.nl2k.ab.ca Sat Jan 14 16:41:50 2006 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Sat Jan 14 16:42:17 2006 Subject: Exclusion List In-Reply-To: <43C91312.7080408@ecs.soton.ac.uk> References: <625385e30601090139q2284270cu4960fbbd138be351@mail.gmail.com> <013101c61501$95706700$3004010a@martinhlaptop> <20060109212415.GJ8774@doctor.nl2k.ab.ca> <1137247699.26473.251.camel@localhost.localdomain> <43C91312.7080408@ecs.soton.ac.uk> Message-ID: <20060114164150.GA27959@doctor.nl2k.ab.ca> On Sat, Jan 14, 2006 at 03:04:50PM +0000, Julian Field wrote: > Steve Freegard wrote: > >On Mon, 2006-01-09 at 14:24 -0700, Dave Shariff Yadallee - System > >Administrator a.k.a. The Root of the Problem wrote: > > > >>So far so good, but what about case sensitivity issues? > >> > >> > > > >I've looked at the source - the to/from pairs from the queue file are > >always lc()'d as are the values read from the ruleset so case really > >doesn't matter. > > > >Before anyone mentions - yes RFC2821 does say that local-parts can and > >and must be treated as case-sensitive but it also states in the same > >paragraph - 'exploiting the case sensitivity of mailbox local-parts > >impedes interoperability and is discouraged', so in reality this > >shouldn't cause any issues. > > > MailScanner breaks RFC2821 by ignoring case in local parts of addresses. > It's fully intentional. > That is a good thing. Still what am I doing wrong? > -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > Professional Support Services at www.MailScanner.biz > MailScanner thanks transtec Computers for their support > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From samp at arial-concept.com Sat Jan 14 17:05:07 2006 From: samp at arial-concept.com (Sam Przyswa) Date: Sat Jan 14 17:05:29 2006 Subject: www.tchatche.ci In-Reply-To: <20060114154301.52987.qmail@web25602.mail.ukl.yahoo.com> References: <20060114154301.52987.qmail@web25602.mail.ukl.yahoo.com> Message-ID: <43C92F43.3080105@arial-concept.com> martial monthe a ?crit : >Salut ? tous, juste une petite infos pour les tchatcheurs. et bien sachez que la C?te d'Ivoire a un tchatche qui se nomme www.tchatche.ci fait avec des Logiciels Libres et heberger sur une plate forme Libre. Visitez le et donner moi votre avis. Martial > Bonjour, Votre site est tr?s beau et je suis content de voir que malgr? la tourmente il se cr?? des choses int?ressantes en C?te d'Ivoire mais lancer ce type de message sur un forum public de plus en anglais n'est pas tr?s respectueux des usages. Sam Przyswa. -- Sam Przyswa - Chef de projet Arial Concept - Int???rateur Internet 36, rue de Turin - 75008 - Paris - France Tel: 01 40 54 86 04 - 0870 444 596 - Fax: 01 40 54 83 01 Skype ID: arial-concept Web: http://www.arial-concept.com - Email: Info@arial-concept.com -- Ce message a ?t? v?rifi? par MailScanner pour des virus ou des polluriels et rien de suspect n'a ?t? trouv?. From MailScanner at ecs.soton.ac.uk Sat Jan 14 17:45:37 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat Jan 14 17:45:44 2006 Subject: --lint patch for Mailscanner Message-ID: <43C938C1.8090503@ecs.soton.ac.uk> The attached tar.gz file contains 2 patches, one for /usr/sbin/MailScanner and the other for /usr/lib/MailScanner/MailScanner/CustomConfig.pm. Once you have applied the patches (they are both very simple and small), you will be able to run MailScanner --lint or MailScanner --lint path-to-MailScanner.conf-file It should just check the syntax of the configuration files and then stop. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -------------- next part -------------- A non-text attachment was scrubbed... Name: link.patch.tar.gz Type: application/x-gzip Size: 1222 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060114/43cc16b9/link.patch.tar.gz From glenn.steen at gmail.com Sat Jan 14 18:06:09 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Sat Jan 14 18:06:12 2006 Subject: www.tchatche.ci In-Reply-To: <43C92F43.3080105@arial-concept.com> References: <20060114154301.52987.qmail@web25602.mail.ukl.yahoo.com> <43C92F43.3080105@arial-concept.com> Message-ID: <223f97700601141006t11734cc7q@mail.gmail.com> On 14/01/06, Sam Przyswa wrote: > martial monthe a ?crit : > > >Salut ? tous, juste une petite infos pour les tchatcheurs. et bien sachez que la C?te d'Ivoire a un tchatche qui se nomme www.tchatche.ci fait avec des Logiciels Libres et heberger sur une plate forme Libre. Visitez le et donner moi votre avis. Martial > > > > Bonjour, > > Votre site est tr?s beau et je suis content de voir que malgr? la > tourmente il se cr?? des choses int?ressantes en C?te d'Ivoire mais > lancer ce type de message sur un forum public de plus en anglais n'est > pas tr?s respectueux des usages. > > Sam Przyswa. > Couldn't have said it better myself Sam (literal truth, my french is abominably bad:), .... Not to mention that I can't really see what that site has to do with MailScanner....;-) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From samp at arial-concept.com Sat Jan 14 18:27:16 2006 From: samp at arial-concept.com (Sam Przyswa) Date: Sat Jan 14 18:27:41 2006 Subject: www.tchatche.ci In-Reply-To: <223f97700601141006t11734cc7q@mail.gmail.com> References: <20060114154301.52987.qmail@web25602.mail.ukl.yahoo.com> <43C92F43.3080105@arial-concept.com> <223f97700601141006t11734cc7q@mail.gmail.com> Message-ID: <43C94284.4070300@arial-concept.com> Glenn Steen a ?crit : >On 14/01/06, Sam Przyswa wrote: > > >>martial monthe a ?crit : >> >> >> >>>Salut ? tous, juste une petite infos pour les tchatcheurs. et bien sachez que la C?te d'Ivoire a un tchatche qui se nomme www.tchatche.ci fait avec des Logiciels Libres et heberger sur une plate forme Libre. Visitez le et donner moi votre avis. Martial >>> >>> >>> >>Bonjour, >> >>Votre site est tr?s beau et je suis content de voir que malgr? la >>tourmente il se cr?? des choses int?ressantes en C?te d'Ivoire mais >>lancer ce type de message sur un forum public de plus en anglais n'est >>pas tr?s respectueux des usages. >> >>Sam Przyswa. >> >> >> >Couldn't have said it better myself Sam (literal truth, my french is >abominably bad:), .... Not to mention that I can't really see what >that site has to do with MailScanner....;-) > > It's exactly what I said to the sender of the previous message, in french sorry. Sam. -- Ce message a ?t? v?rifi? par MailScanner pour des virus ou des polluriels et rien de suspect n'a ?t? trouv?. From MailScanner at ecs.soton.ac.uk Sat Jan 14 18:44:06 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat Jan 14 18:44:13 2006 Subject: www.tchatche.ci In-Reply-To: <43C94284.4070300@arial-concept.com> References: <20060114154301.52987.qmail@web25602.mail.ukl.yahoo.com> <43C92F43.3080105@arial-concept.com> <223f97700601141006t11734cc7q@mail.gmail.com> <43C94284.4070300@arial-concept.com> Message-ID: <43C94676.8050007@ecs.soton.ac.uk> I am glad to see all the work put in by the translators is getting some use, I rarely see it used (being in a mostly English-based country). Anyone fancy doing an Urdu translation and other Asian languages like that? Would be very useful here. One of my friends teaches in a primary school where the children have 33 different first languages! Sam Przyswa wrote: -- Ce message a ?t? v?rifi? par MailScanner pour des virus ou des polluriels et rien de suspect n'a ?t? trouv?. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From dhawal at netmagicsolutions.com Sat Jan 14 20:33:14 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Sat Jan 14 20:33:20 2006 Subject: www.tchatche.ci In-Reply-To: <43C94676.8050007@ecs.soton.ac.uk> References: <20060114154301.52987.qmail@web25602.mail.ukl.yahoo.com> <43C92F43.3080105@arial-concept.com> <223f97700601141006t11734cc7q@mail.gmail.com> <43C94284.4070300@arial-concept.com> <43C94676.8050007@ecs.soton.ac.uk> Message-ID: <20060114203314.27426.qmail@mymail.netmagicians.com> Julian Field writes: > I am glad to see all the work put in by the translators is getting some > use, I rarely see it used (being in a mostly English-based country). > > Anyone fancy doing an Urdu translation and other Asian languages like > that? Would be very useful here. One of my friends teaches in a primary > school where the children have 33 different first languages! It's more to do with the demand.. it is very very common for quite a few Indians to speak / write / read / understand 3-4 languages, but businesses require only english. Though local state govenments do require all communication in both english and the local state language, there yet isn't such a demand.. Once the need arises, someone will hopefully oblige :) The last 7 years or so of being in local email industry, i have yet to see a requirement for the local language.. at the same time i see a lot of work being done on Indian languages, check sarovar.org (the Indian sourceforge) which tells me to get a second opinion from the local LUGs. - dhawal From glenn.steen at gmail.com Sun Jan 15 01:40:04 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Sun Jan 15 01:40:08 2006 Subject: www.tchatche.ci In-Reply-To: <43C94284.4070300@arial-concept.com> References: <20060114154301.52987.qmail@web25602.mail.ukl.yahoo.com> <43C92F43.3080105@arial-concept.com> <223f97700601141006t11734cc7q@mail.gmail.com> <43C94284.4070300@arial-concept.com> Message-ID: <223f97700601141740p2cbaf078q@mail.gmail.com> On 14/01/06, Sam Przyswa wrote: > Glenn Steen a ?crit : > > >On 14/01/06, Sam Przyswa wrote: > > > > > >>martial monthe a ?crit : > >> > >> > >> > >>>Salut ? tous, juste une petite infos pour les tchatcheurs. et bien sachez que la C?te d'Ivoire a un tchatche qui se nomme www.tchatche.ci fait avec des Logiciels Libres et heberger sur une plate forme Libre. Visitez le et donner moi votre avis. Martial > >>> > >>> > >>> > >>Bonjour, > >> > >>Votre site est tr?s beau et je suis content de voir que malgr? la > >>tourmente il se cr?? des choses int?ressantes en C?te d'Ivoire mais > >>lancer ce type de message sur un forum public de plus en anglais n'est > >>pas tr?s respectueux des usages. > >> > >>Sam Przyswa. > >> > >> > >> > >Couldn't have said it better myself Sam (literal truth, my french is > >abominably bad:), .... Not to mention that I can't really see what > >that site has to do with MailScanner....;-) > > > > > > It's exactly what I said to the sender of the previous message, in > french sorry. > > Sam. > Oh. I thought you were saying that it was a tad rude to post in french to a predominantly engish-speaking forum.... Just goes to show how bad my french is:-) -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From michele at blacknight.ie Sun Jan 15 13:28:41 2006 From: michele at blacknight.ie (Michele Neylon:: Blacknight.ie) Date: Sun Jan 15 13:28:43 2006 Subject: OT: Greylisting For Exim Message-ID: <43CA4E09.6070701@blacknight.ie> Hi all Can anyone recommend a greylisting implementation for Exim that does not require a MySQL database? TIA Michele -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 From h.swensson at hccnet.nl Sun Jan 15 15:42:07 2006 From: h.swensson at hccnet.nl (Herman Swensson) Date: Sun Jan 15 15:42:11 2006 Subject: ClamAV Perl module Message-ID: <200601151542.k0FFg8aZ015414@smtp10.hccnet.nl> Mail::ClamAV is up to date (0.17) I have installed the Clamavmodule version 0.17) but get the bext error: MailScanner[19198]: ClamAV Perl module not found, did you install it? My version of MailScanner is 4.47.4 What must I change in the configuration Regards Herman -- No virus found in this outgoing message. Checked by AVG Free Edition. Version: 7.1.371 / Virus Database: 267.14.18/230 - Release Date: 14-1-2006 -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060115/ecdfc449/attachment.html From MailScanner at ecs.soton.ac.uk Sun Jan 15 18:12:30 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun Jan 15 18:12:37 2006 Subject: Released 4.50.8 --- Re: Time::HiRes for MessageBatch timing In-Reply-To: <20051125215601.72E29BCE3@mx.dtiltas.lt> References: <50E43938-0090-4900-A222-7301D38D6A06@ecs.soton.ac.uk> <20051125215601.72E29BCE3@mx.dtiltas.lt> Message-ID: <43CA908E.50004@ecs.soton.ac.uk> Now done. At the end of the batch, the wall-clock time taken to process that batch is logged. This is in 4.50.8, which I have just released. This version has added lots of command-line options that you can use to do things like - Check your configuration for errors (--lint) - Switch on "Debug = yes" (--debug) - Calculate the value of a configuration option, given a set of message values, to provide a ruleset checker and Custom Function checker (several options) - Display command line usage (--help) Don't forget that you can easily change the amount of logs generated by MailScanner by editing /etc/syslog.conf and changing the "mail" log priorities that are logged in /var/log/maillog. And if you don't want to do that, then change MailScanner.conf to log to "local0" instead of "mail" and separate it out into its own log channel completely. Nerijus Baliunas wrote: > Hi, > > if/when you do it, you could do it like spamassassin does - uses Time::HiRes > only when it is available. From SA INSTALL: > > - Time::HiRes (from CPAN) > > If this module is installed, the processing times are logged/reported > more precisely. > > Nerijus > > On Thu, 24 Nov 2005 10:03:00 +0000 Julian Field wrote: > > >> This just didn't happen as I haven't had the time to add a whole new >> Perl module to the MailScanner distribution. >> >> On 4 Nov 2005, at 16:27, Jeff A. Earickson wrote: >> >> >>> Julian, >>> >>> Per my recent request for batch timing in the logs, please >>> look at my suggested changes for MessageBatch.pm (attached, >>> against 4.47.4). My changes have NOT been tested at all, so I >>> don't know if this will work. The changes: >>> >>> * added Time::HiRes for timing the start and end timing on >>> a batch of messages. >>> >>> * changed output of information in EndBatch from integer >>> to float >>> >>> * Added a "Batch Completed in x.x seconds" syslog, even if >>> "Log Speed" is not turned on in the config file. >>> >>> Please see if my idea makes sense. Since HighRes is required >>> for SpamAssassin, why not use it here too to give better info? >>> >>> Jeff Earickson >>> Colby College >>> > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Sun Jan 15 18:25:06 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun Jan 15 18:25:11 2006 Subject: Released 4.50.8 --- Re: Time::HiRes for MessageBatch timing In-Reply-To: <43CA908E.50004@ecs.soton.ac.uk> References: <50E43938-0090-4900-A222-7301D38D6A06@ecs.soton.ac.uk> <20051125215601.72E29BCE3@mx.dtiltas.lt> <43CA908E.50004@ecs.soton.ac.uk> Message-ID: <43CA9382.1020305@ecs.soton.ac.uk> Could someone add some documentation to the wiki about the new command-line options please? They are fairly obvious once you've tried them, but their existence and purpose should be documented. And they all need adding to the trouble-shooting sections. I would be very grateful if someone could do this for me. Thankyou folks! Julian Field wrote: > Now done. At the end of the batch, the wall-clock time taken to > process that batch is logged. > > This is in 4.50.8, which I have just released. > > This version has added lots of command-line options that you can use > to do things like > - Check your configuration for errors (--lint) > - Switch on "Debug = yes" (--debug) > - Calculate the value of a configuration option, > given a set of message values, > to provide a ruleset checker and > Custom Function checker (several options) > - Display command line usage (--help) > > Don't forget that you can easily change the amount of logs generated > by MailScanner by editing /etc/syslog.conf and changing the "mail" log > priorities that are logged in /var/log/maillog. And if you don't want > to do that, then change MailScanner.conf to log to "local0" instead of > "mail" and separate it out into its own log channel completely. > > > Nerijus Baliunas wrote: >> Hi, >> >> if/when you do it, you could do it like spamassassin does - uses >> Time::HiRes >> only when it is available. From SA INSTALL: >> >> - Time::HiRes (from CPAN) >> >> If this module is installed, the processing times are >> logged/reported >> more precisely. >> >> Nerijus >> >> On Thu, 24 Nov 2005 10:03:00 +0000 Julian Field >> wrote: >> >> >>> This just didn't happen as I haven't had the time to add a whole >>> new Perl module to the MailScanner distribution. >>> >>> On 4 Nov 2005, at 16:27, Jeff A. Earickson wrote: >>> >>> >>>> Julian, >>>> >>>> Per my recent request for batch timing in the logs, please >>>> look at my suggested changes for MessageBatch.pm (attached, >>>> against 4.47.4). My changes have NOT been tested at all, so I >>>> don't know if this will work. The changes: >>>> >>>> * added Time::HiRes for timing the start and end timing on >>>> a batch of messages. >>>> >>>> * changed output of information in EndBatch from integer >>>> to float >>>> >>>> * Added a "Batch Completed in x.x seconds" syslog, even if >>>> "Log Speed" is not turned on in the config file. >>>> >>>> Please see if my idea makes sense. Since HighRes is required >>>> for SpamAssassin, why not use it here too to give better info? >>>> >>>> Jeff Earickson >>>> Colby College >>>> >> >> ------------------------ MailScanner list ------------------------ >> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >> 'leave mailscanner' in the body of the email. >> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >> >> Support MailScanner development - buy the book off the website! >> > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Sun Jan 15 18:26:50 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun Jan 15 18:26:57 2006 Subject: Released 4.50.8 --- Re: Time::HiRes for MessageBatch timing In-Reply-To: <43CA908E.50004@ecs.soton.ac.uk> References: <50E43938-0090-4900-A222-7301D38D6A06@ecs.soton.ac.uk> <20051125215601.72E29BCE3@mx.dtiltas.lt> <43CA908E.50004@ecs.soton.ac.uk> Message-ID: <43CA93EA.3080507@ecs.soton.ac.uk> One note about 4.50.8 ---- Please install it, or upgrade to it, with my ./install.sh as you may well need the new modules I have added to it. Julian Field wrote: > Now done. At the end of the batch, the wall-clock time taken to > process that batch is logged. > > This is in 4.50.8, which I have just released. > > This version has added lots of command-line options that you can use > to do things like > - Check your configuration for errors (--lint) > - Switch on "Debug = yes" (--debug) > - Calculate the value of a configuration option, > given a set of message values, > to provide a ruleset checker and > Custom Function checker (several options) > - Display command line usage (--help) > > Don't forget that you can easily change the amount of logs generated > by MailScanner by editing /etc/syslog.conf and changing the "mail" log > priorities that are logged in /var/log/maillog. And if you don't want > to do that, then change MailScanner.conf to log to "local0" instead of > "mail" and separate it out into its own log channel completely. > > > Nerijus Baliunas wrote: >> Hi, >> >> if/when you do it, you could do it like spamassassin does - uses >> Time::HiRes >> only when it is available. From SA INSTALL: >> >> - Time::HiRes (from CPAN) >> >> If this module is installed, the processing times are >> logged/reported >> more precisely. >> >> Nerijus >> >> On Thu, 24 Nov 2005 10:03:00 +0000 Julian Field >> wrote: >> >> >>> This just didn't happen as I haven't had the time to add a whole >>> new Perl module to the MailScanner distribution. >>> >>> On 4 Nov 2005, at 16:27, Jeff A. Earickson wrote: >>> >>> >>>> Julian, >>>> >>>> Per my recent request for batch timing in the logs, please >>>> look at my suggested changes for MessageBatch.pm (attached, >>>> against 4.47.4). My changes have NOT been tested at all, so I >>>> don't know if this will work. The changes: >>>> >>>> * added Time::HiRes for timing the start and end timing on >>>> a batch of messages. >>>> >>>> * changed output of information in EndBatch from integer >>>> to float >>>> >>>> * Added a "Batch Completed in x.x seconds" syslog, even if >>>> "Log Speed" is not turned on in the config file. >>>> >>>> Please see if my idea makes sense. Since HighRes is required >>>> for SpamAssassin, why not use it here too to give better info? >>>> >>>> Jeff Earickson >>>> Colby College >>>> >> >> ------------------------ MailScanner list ------------------------ >> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >> 'leave mailscanner' in the body of the email. >> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >> >> Support MailScanner development - buy the book off the website! >> > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From nerijus at users.sourceforge.net Sun Jan 15 19:28:28 2006 From: nerijus at users.sourceforge.net (Nerijus Baliunas) Date: Sun Jan 15 19:30:17 2006 Subject: no announce list archive? Message-ID: <20060115192834.8A08ABC8B@mx.dtiltas.lt> Hello, only January 2006 in http://lists.mailscanner.info/pipermail/mailscanner-announce/ Regards, Nerijus From jkf at ecs.soton.ac.uk Sun Jan 15 20:03:45 2006 From: jkf at ecs.soton.ac.uk (Julian Field) Date: Sun Jan 15 20:11:04 2006 Subject: no announce list archive? In-Reply-To: <20060115192834.8A08ABC8B@mx.dtiltas.lt> References: <20060115192834.8A08ABC8B@mx.dtiltas.lt> Message-ID: <43CAAAA1.2090407@ecs.soton.ac.uk> I didn't see much point trying to port the announcements archive. I haven't got my own copy anyway, so it would have been _very_ hard to do. Nerijus Baliunas wrote: > Hello, > > only January 2006 in http://lists.mailscanner.info/pipermail/mailscanner-announce/ > > Regards, > Nerijus > -- Julian Field Teaching Systems Manager jkf@ecs.soton.ac.uk Electronics & Computer Science Tel. 023 8059 2817 University of Southampton Southampton SO17 1BJ -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From jaearick at colby.edu Sun Jan 15 22:08:09 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Sun Jan 15 22:08:17 2006 Subject: Released 4.50.8 --- Re: Time::HiRes for MessageBatch timing In-Reply-To: <43CA908E.50004@ecs.soton.ac.uk> References: <50E43938-0090-4900-A222-7301D38D6A06@ecs.soton.ac.uk> <20051125215601.72E29BCE3@mx.dtiltas.lt> <43CA908E.50004@ecs.soton.ac.uk> Message-ID: Julian, Thank you, thank you. I'll roll this out tomorrow morning. I went from 4.49.7 to 4.50.6 on Friday (the 13th!), and it has worked great! SA cache rates in the 40 to 50% range. The system load ("sar" output) is down since the upgrade. This is like a hardware upgrade for us. Jeff Earickson Colby College On Sun, 15 Jan 2006, Julian Field wrote: > Date: Sun, 15 Jan 2006 18:12:30 +0000 > From: Julian Field > Reply-To: MailScanner discussion > To: MailScanner discussion > Subject: Released 4.50.8 --- Re: Time::HiRes for MessageBatch timing > > Now done. At the end of the batch, the wall-clock time taken to process that > batch is logged. > > This is in 4.50.8, which I have just released. > > This version has added lots of command-line options that you can use to do > things like > - Check your configuration for errors (--lint) > - Switch on "Debug = yes" (--debug) > - Calculate the value of a configuration option, > given a set of message values, > to provide a ruleset checker and > Custom Function checker (several options) > - Display command line usage (--help) > > Don't forget that you can easily change the amount of logs generated by > MailScanner by editing /etc/syslog.conf and changing the "mail" log > priorities that are logged in /var/log/maillog. And if you don't want to do > that, then change MailScanner.conf to log to "local0" instead of "mail" and > separate it out into its own log channel completely. > > > Nerijus Baliunas wrote: >> Hi, >> >> if/when you do it, you could do it like spamassassin does - uses >> Time::HiRes >> only when it is available. From SA INSTALL: >> >> - Time::HiRes (from CPAN) >> >> If this module is installed, the processing times are logged/reported >> more precisely. >> >> Nerijus >> >> On Thu, 24 Nov 2005 10:03:00 +0000 Julian Field >> wrote: >> >> >>> This just didn't happen as I haven't had the time to add a whole new Perl >>> module to the MailScanner distribution. >>> >>> On 4 Nov 2005, at 16:27, Jeff A. Earickson wrote: >>> >>> >>>> Julian, >>>> >>>> Per my recent request for batch timing in the logs, please >>>> look at my suggested changes for MessageBatch.pm (attached, >>>> against 4.47.4). My changes have NOT been tested at all, so I don't >>>> know if this will work. The changes: >>>> >>>> * added Time::HiRes for timing the start and end timing on >>>> a batch of messages. >>>> >>>> * changed output of information in EndBatch from integer >>>> to float >>>> >>>> * Added a "Batch Completed in x.x seconds" syslog, even if >>>> "Log Speed" is not turned on in the config file. >>>> >>>> Please see if my idea makes sense. Since HighRes is required >>>> for SpamAssassin, why not use it here too to give better info? >>>> >>>> Jeff Earickson >>>> Colby College >>>> >> >> ------------------------ MailScanner list ------------------------ >> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >> 'leave mailscanner' in the body of the email. >> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >> >> Support MailScanner development - buy the book off the website! >> > > -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > Professional Support Services at www.MailScanner.biz > MailScanner thanks transtec Computers for their support > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Sun Jan 15 22:44:12 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun Jan 15 22:44:19 2006 Subject: Released 4.50.8 --- Re: Time::HiRes for MessageBatch timing In-Reply-To: References: <50E43938-0090-4900-A222-7301D38D6A06@ecs.soton.ac.uk> <20051125215601.72E29BCE3@mx.dtiltas.lt> <43CA908E.50004@ecs.soton.ac.uk> Message-ID: <43CAD03C.9050103@ecs.soton.ac.uk> Glad you like it. Make sure you use the latest beta. Good luck, Jules. Jeff A. Earickson wrote: > Julian, > Thank you, thank you. I'll roll this out tomorrow morning. I went > from 4.49.7 to 4.50.6 on Friday (the 13th!), and it has worked great! > SA cache rates in the 40 to 50% range. The system load ("sar" output) > is down since the upgrade. This is like a hardware upgrade for us. > > Jeff Earickson > Colby College > > On Sun, 15 Jan 2006, Julian Field wrote: > >> Date: Sun, 15 Jan 2006 18:12:30 +0000 >> From: Julian Field >> Reply-To: MailScanner discussion >> To: MailScanner discussion >> Subject: Released 4.50.8 --- Re: Time::HiRes for MessageBatch timing >> >> Now done. At the end of the batch, the wall-clock time taken to >> process that batch is logged. >> >> This is in 4.50.8, which I have just released. >> >> This version has added lots of command-line options that you can use >> to do things like >> - Check your configuration for errors (--lint) >> - Switch on "Debug = yes" (--debug) >> - Calculate the value of a configuration option, >> given a set of message values, >> to provide a ruleset checker and >> Custom Function checker (several options) >> - Display command line usage (--help) >> >> Don't forget that you can easily change the amount of logs generated >> by MailScanner by editing /etc/syslog.conf and changing the "mail" >> log priorities that are logged in /var/log/maillog. And if you don't >> want to do that, then change MailScanner.conf to log to "local0" >> instead of "mail" and separate it out into its own log channel >> completely. >> >> >> Nerijus Baliunas wrote: >>> Hi, >>> >>> if/when you do it, you could do it like spamassassin does - uses >>> Time::HiRes >>> only when it is available. From SA INSTALL: >>> >>> - Time::HiRes (from CPAN) >>> >>> If this module is installed, the processing times are >>> logged/reported >>> more precisely. >>> >>> Nerijus >>> >>> On Thu, 24 Nov 2005 10:03:00 +0000 Julian Field >>> wrote: >>> >>> >>>> This just didn't happen as I haven't had the time to add a whole >>>> new Perl module to the MailScanner distribution. >>>> >>>> On 4 Nov 2005, at 16:27, Jeff A. Earickson wrote: >>>> >>>> >>>>> Julian, >>>>> >>>>> Per my recent request for batch timing in the logs, please >>>>> look at my suggested changes for MessageBatch.pm (attached, >>>>> against 4.47.4). My changes have NOT been tested at all, so I >>>>> don't know if this will work. The changes: >>>>> >>>>> * added Time::HiRes for timing the start and end timing on >>>>> a batch of messages. >>>>> >>>>> * changed output of information in EndBatch from integer >>>>> to float >>>>> >>>>> * Added a "Batch Completed in x.x seconds" syslog, even if >>>>> "Log Speed" is not turned on in the config file. >>>>> >>>>> Please see if my idea makes sense. Since HighRes is required >>>>> for SpamAssassin, why not use it here too to give better info? >>>>> >>>>> Jeff Earickson >>>>> Colby College >>>>> >>> >>> ------------------------ MailScanner list ------------------------ >>> To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: >>> 'leave mailscanner' in the body of the email. >>> Before posting, read the Wiki (http://wiki.mailscanner.info/) and >>> the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). >>> >>> Support MailScanner development - buy the book off the website! >>> >> >> -- >> Julian Field >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> Professional Support Services at www.MailScanner.biz >> MailScanner thanks transtec Computers for their support >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read the Wiki (http://wiki.mailscanner.info/). >> >> Support MailScanner development - buy the book off the website! -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From lhaig at haigmail.com Mon Jan 16 00:02:51 2006 From: lhaig at haigmail.com (Lance Haig) Date: Mon Jan 16 00:02:54 2006 Subject: Lotus Notes end Message-ID: <43CAE2AB.4000805@haigmail.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Thanks to the great experience here on the list I was able to solve my problem. Thanks again guys H?kon Peter Norbert Lance -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFDyuKrM4kHBIBZ61gRAoWlAJ9iSiKIuONTPm1MwqtV0i31yZbK7gCfQrZo 4eQmgFn5ZzareR7/Ylfu/u8= =4DjC -----END PGP SIGNATURE----- From james at grayonline.id.au Mon Jan 16 01:35:56 2006 From: james at grayonline.id.au (James Gray) Date: Mon Jan 16 01:36:17 2006 Subject: OT: Greylisting For Exim In-Reply-To: <43CA4E09.6070701@blacknight.ie> References: <43CA4E09.6070701@blacknight.ie> Message-ID: <200601161235.57469.james@grayonline.id.au> On Mon, 16 Jan 2006 00:28, Michele Neylon:: Blacknight.ie wrote: > Hi all > > Can anyone recommend a greylisting implementation for Exim that does not > require a MySQL database? > > TIA > > Michele Hi Michele, I installed "greylistd" from the Debian repositories just last week and have been VERY happy with the results. No MySQL database necessary - it creates files in /var/lib/greylistd/ (much the same way "milter-greylist" for sendmail does). It's written in Python, so you'll need that installed, and runs as a stand-alone daemon. Here's the debain package: http://packages.debian.org/unstable/mail/greylistd ...and this is as close as I've got to a homepage: http://slett.net/spam-filtering-for-mx/exim-greylisting.html Seems Tor Slettnes is the author AND Debian maintainer of greylistd. The only feature that greylistd is missing (that would be "nice") is multiple server synchronisation - like milter-greylist. But as you're not wanting a MySQL database, I'm guessing that level of complexity is not required. Although, I'm sure you could achieve something similar by storing the greylistd data files on an NFS share (no idea how it locks the files though). Hope that points you in the right direction :) James -- The Phone Booth Rule: A lone dime always gets the number nearly right. -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060116/fe3c5bd7/attachment.bin From ugob at camo-route.com Mon Jan 16 02:31:50 2006 From: ugob at camo-route.com (Ugo Bellavance) Date: Mon Jan 16 02:32:17 2006 Subject: Test Message-ID: This is a test to see if we can post through gmane again. -- Ugo -> Please don't send a copy of your reply by e-mail. I read the list. -> Please avoid top-posting, long signatures and HTML, and cut the irrelevant parts in your replies. From technician at cenpac.net.nr Mon Jan 16 02:49:41 2006 From: technician at cenpac.net.nr (Jon Leeman) Date: Mon Jan 16 02:49:06 2006 Subject: Test In-Reply-To: References: Message-ID: <43CB09C5.5030307@cenpac.net.nr> Ugo Bellavance wrote: > This is a test to see if we can post through gmane again. from sunny Nauru From james at grayonline.id.au Mon Jan 16 05:13:39 2006 From: james at grayonline.id.au (James Gray) Date: Mon Jan 16 05:14:02 2006 Subject: OT: GPG sigs work :) Message-ID: <200601161613.43709.james@grayonline.id.au> Finally, my mail client can send messages to this list without the GPG signature being borked in transit! Woot. (Just wanted to get that off my chest) Cheers, James -- The universe is made of stories, not of atoms. -- Muriel Rukeyser -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060116/4ec0560b/attachment.bin From sathya.prakash at hp.com Mon Jan 16 06:46:40 2006 From: sathya.prakash at hp.com (prakash, sathya) Date: Mon Jan 16 06:47:02 2006 Subject: Mailscanner slow ? Message-ID: Hi all, Is Mailscanner slow in processing then mqueue.in. I use sendmail and Mailscanner. I can see the unprossed mails in mqueue.in. Please reply...... Thanks and regards sathya From jsp_prakash_test at yahoo.co.in Mon Jan 16 06:57:58 2006 From: jsp_prakash_test at yahoo.co.in (sathy prakash) Date: Mon Jan 16 06:58:03 2006 Subject: mailscanner Message-ID: <20060116065758.71218.qmail@web8609.mail.in.yahoo.com> hi all , When I start the Mailscanner by runing script /opt/MailScanner/bin/check_mailscanner i see 4 Mailscanner processes running in my system why? thanks and regards.... sathya Send instant messages to your online friends http://in.messenger.yahoo.com -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060116/26dafd49/attachment.html From tenderby at mailwash.com.au Mon Jan 16 07:07:10 2006 From: tenderby at mailwash.com.au (Tony Enderby) Date: Mon Jan 16 07:07:25 2006 Subject: mailscanner In-Reply-To: <20060116065758.71218.qmail@web8609.mail.in.yahoo.com> Message-ID: From your mailscanner.conf file ... # How many MailScanner processes do you want to run at a time? # There is no point increasing this figure if your MailScanner server # is happily keeping up with your mail traffic. # If you are running on a server with more than 1 CPU, or you have a # high mail load (and/or slow DNS lookups) then you should see better # performance if you increase this figure. # If you are running on a small system with limited RAM, you should # note that each child takes just over 20MB. # # As a rough guide, try 5 children per CPU. But read the notes above. Max Children = 5 On 1/16/2006, "sathy prakash" wrote: >hi all , > When I start the Mailscanner by runing script > /opt/MailScanner/bin/check_mailscanner i see 4 Mailscanner processes > running in my system why? > > thanks and regards.... > > sathya > >Send instant messages to your online friends http://in.messenger.yahoo.com >----------------------------------------------------------------------------------- >Scanned by MailWash Australia - http://www.mailwash.com.au >----------------------------------------------------------------------------------- > ----------------------------------------------------------------------------------- Scanned by MailWash Australia - http://www.mailwash.com.au ----------------------------------------------------------------------------------- From jsp_prakash_test at yahoo.co.in Mon Jan 16 07:39:57 2006 From: jsp_prakash_test at yahoo.co.in (sathy prakash) Date: Mon Jan 16 07:40:03 2006 Subject: mailscanner In-Reply-To: Message-ID: <20060116073957.89639.qmail@web8609.mail.in.yahoo.com> thanks.... Tony Enderby wrote: >From your mailscanner.conf file ... # How many MailScanner processes do you want to run at a time? # There is no point increasing this figure if your MailScanner server # is happily keeping up with your mail traffic. # If you are running on a server with more than 1 CPU, or you have a # high mail load (and/or slow DNS lookups) then you should see better # performance if you increase this figure. # If you are running on a small system with limited RAM, you should # note that each child takes just over 20MB. # # As a rough guide, try 5 children per CPU. But read the notes above. Max Children = 5 On 1/16/2006, "sathy prakash" wrote: >hi all , > When I start the Mailscanner by runing script > /opt/MailScanner/bin/check_mailscanner i see 4 Mailscanner processes > running in my system why? > > thanks and regards.... > > sathya > >Send instant messages to your online friends http://in.messenger.yahoo.com >----------------------------------------------------------------------------------- >Scanned by MailWash Australia - http://www.mailwash.com.au >----------------------------------------------------------------------------------- > ----------------------------------------------------------------------------------- Scanned by MailWash Australia - http://www.mailwash.com.au ----------------------------------------------------------------------------------- -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read the Wiki (http://wiki.mailscanner.info/). Support MailScanner development - buy the book off the website! Send instant messages to your online friends http://in.messenger.yahoo.com Send instant messages to your online friends http://in.messenger.yahoo.com -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060116/ecc9f128/attachment.html From sathya.prakash at hp.com Mon Jan 16 07:47:43 2006 From: sathya.prakash at hp.com (prakash, sathya) Date: Mon Jan 16 07:47:49 2006 Subject: bogofilter Message-ID: Hi, can I use any other spam filter (other than spamassassin) with mail scanner Thanks and regards sathya From michele at blacknight.ie Mon Jan 16 07:58:07 2006 From: michele at blacknight.ie (Michele Neylon:: Blacknight.ie) Date: Mon Jan 16 07:58:10 2006 Subject: bogofilter In-Reply-To: References: Message-ID: <43CB520F.5050404@blacknight.ie> prakash, sathya wrote: > Hi, > can I use any other spam filter (other than spamassassin) with mail > scanner > > Thanks and regards > sathya Sathya Why don't you go and read the documentation? It's not hard. Really it's not. Go and read. When you've finished reading it all (and I include the comments inside all the configuration files), why don't you come back here and ask an intelligent question. -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 From james at grayonline.id.au Mon Jan 16 08:05:55 2006 From: james at grayonline.id.au (James Gray) Date: Mon Jan 16 08:06:22 2006 Subject: bogofilter In-Reply-To: References: Message-ID: <200601161906.00894.james@grayonline.id.au> On Mon, 16 Jan 2006 18:47, prakash, sathya wrote: > Hi, > can I use any other spam filter (other than spamassassin) with mail > scanner Yes. It's in the documentation, in the mail archives, heck I found relevant info on google with a basic search. http://www.catb.org/~esr/faqs/smart-questions.html Cheers, James -- Já é permitido a uma mulher católica recorrer à Matemática para evitar a gravidez, mas continua sendo-lhe proibido recorrer à Física e à Química. -- H. L. Mencken -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060116/416d37f9/attachment.bin From nilesh.shastrakar at gmail.com Mon Jan 16 08:41:36 2006 From: nilesh.shastrakar at gmail.com (Nilesh Shastrakar) Date: Mon Jan 16 08:41:38 2006 Subject: Mail Archiving Message-ID: <95873e560601160041u67b62b69r745149396a7be13c@mail.gmail.com> Hello All, I want to Archive all outgoing and Incoming mails of all users on my server. Could anyone please help how do I do it. or is there a monitoring software I am using Sendmail + MailScanner Regards Nilesh, -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060116/073da706/attachment.html From P.G.M.Peters at utwente.nl Mon Jan 16 08:55:02 2006 From: P.G.M.Peters at utwente.nl (Peter Peters) Date: Mon Jan 16 08:55:08 2006 Subject: Exclusion List In-Reply-To: <1137252322.26473.273.camel@localhost.localdomain> References: <625385e30601090139q2284270cu4960fbbd138be351@mail.gmail.com> <013101c61501$95706700$3004010a@martinhlaptop> <20060109212415.GJ8774@doctor.nl2k.ab.ca> <1137247699.26473.251.camel@localhost.localdomain> <20060114143838.GA6770@doctor.nl2k.ab.ca> <1137252322.26473.273.camel@localhost.localdomain> Message-ID: <43CB5F66.5000809@utwente.nl> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Steve Freegard wrote on 14-1-2006 16:25: >>Still why are some e-mail being scanned when they are told not to do so? > > >>From the information you've provided so far - I haven't got a clue (see > http://www.chiark.greenend.org.uk/~sgtatham/bugs.html). > > You need to do some basic troubleshooting - for instance, set up the > 'Archive Mail' option for the domain that shouldn't be scanned so that > you can refer to the original message to find out what might have caused > it be scanned. > > The message could be 'To' multiple recipients with conflicting settings > (in which case the default setting in the ruleset is used) - it could be > the messages are being sent to an alias instead of what you have in your > ruleset which isn't causing the rules to match or a whole load of other > things. > > If you want help with something then actually *show* the problem (I > don't mean by posting pages of log data which nobody will be bothered to > sift through), I mean show the relevant lines from the ruleset and the > default rule and which configuration value you have attached the ruleset > to and show the actual message headers of two example messages that > illustrate your point. Do you mean MS depends on the information in the headers? I hope not. I thought MS uses the envelop information and that information is logged (at least with sendmail). If sendmail logs a message is coming in for a@b.nl I presume that address is used by MS to chech the rules. - -- Peter Peters, senior beheerder (Security) Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE) Universiteit Twente, Postbus 217, 7500 AE Enschede telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQFDy19mMbmy+DDgnIURAnVxAJ4+qc1pGDkxIBqUZN2BpmyfAy0QBwCeNOnK E8OmJH/fjGx2ZubkwFwOVrA= =X4ot -----END PGP SIGNATURE----- From martinh at solid-state-logic.com Mon Jan 16 09:04:04 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Mon Jan 16 09:04:22 2006 Subject: Mailscanner slow ? In-Reply-To: Message-ID: <011801c61a7b$d03ce870$3004010a@martinhlaptop> Hi Have you gone through the wiki.mailscanner.info and looked at the info on performance tuning? -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of prakash, sathya > Sent: 16 January 2006 06:47 > To: mailscanner@lists.mailscanner.info > Subject: Mailscanner slow ? > > Hi all, > Is Mailscanner slow in processing then mqueue.in. > I use sendmail and Mailscanner. I can see the unprossed mails in > mqueue.in. > Please reply...... > > Thanks and regards > sathya > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From smf at f2s.com Mon Jan 16 09:05:51 2006 From: smf at f2s.com (Steve Freegard) Date: Mon Jan 16 09:04:43 2006 Subject: Exclusion List In-Reply-To: <43CB5F66.5000809@utwente.nl> References: <625385e30601090139q2284270cu4960fbbd138be351@mail.gmail.com> <013101c61501$95706700$3004010a@martinhlaptop> <20060109212415.GJ8774@doctor.nl2k.ab.ca> <1137247699.26473.251.camel@localhost.localdomain> <20060114143838.GA6770@doctor.nl2k.ab.ca> <1137252322.26473.273.camel@localhost.localdomain> <43CB5F66.5000809@utwente.nl> Message-ID: <1137402352.26473.334.camel@localhost.localdomain> On Mon, 2006-01-16 at 09:55 +0100, Peter Peters wrote: > > Do you mean MS depends on the information in the headers? I hope not. I > thought MS uses the envelop information and that information is logged > (at least with sendmail). If sendmail logs a message is coming in for > a@b.nl I presume that address is used by MS to chech the rules. > No - it *always* uses the envelope data. In this case - header information would have been useful to at least go some way toward seeing the problem being reported by that individual. Regards, Steve. From martinh at solid-state-logic.com Mon Jan 16 09:09:16 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Mon Jan 16 09:09:24 2006 Subject: Mail Archiving In-Reply-To: <95873e560601160041u67b62b69r745149396a7be13c@mail.gmail.com> Message-ID: <011901c61a7c$86f1d3a0$3004010a@martinhlaptop> Hi In MailScanner.conf there's a setting.. Archive Mail = Set this to a directory and it will keep all you email there in date sub directories, see the comment in the file before this setting for more info. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Nilesh Shastrakar > Sent: 16 January 2006 08:42 > To: MailScanner mailing list; mailscanner list; > MailScanner@ecs.soton.ac.uk > Subject: Mail Archiving > > Hello All, > > I want to Archive all outgoing and Incoming mails of all users on my > server. > Could anyone please help how do I do it. > or is there a monitoring software > I am using Sendmail + MailScanner > > Regards > Nilesh, ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From martinh at solid-state-logic.com Mon Jan 16 09:13:45 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Mon Jan 16 09:13:52 2006 Subject: HAPPY BIRTHDAY Message-ID: <011a01c61a7d$2753df00$3004010a@martinhlaptop> Julian Happy Birthday to you..... -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From anders.andersson at ltkalmar.se Mon Jan 16 09:26:48 2006 From: anders.andersson at ltkalmar.se (Anders Andersson, IT) Date: Mon Jan 16 09:27:38 2006 Subject: HAPPY BIRTHDAY Message-ID: <5EBABD62DC5AC048AD8AEC3312E02D4CCD2EF2@exchange03.lkl.ltkalmar.se> > > Julian > > Happy Birthday to you..... > > Grattis p? f?delsedagen fr?n alla i sverige :) From MailScanner at ecs.soton.ac.uk Mon Jan 16 09:35:10 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 16 09:35:18 2006 Subject: HAPPY BIRTHDAY In-Reply-To: <5EBABD62DC5AC048AD8AEC3312E02D4CCD2EF2@exchange03.lkl.ltkalmar.se> References: <5EBABD62DC5AC048AD8AEC3312E02D4CCD2EF2@exchange03.lkl.ltkalmar.se> Message-ID: <2C8D9E31-D9A5-4105-9632-AE0E28707EAF@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- On 16 Jan 2006, at 09:26, Anders Andersson, IT wrote: >> >> Julian >> >> Happy Birthday to you..... >> > > Grattis p? f?delsedagen fr?n alla i sverige :) Thankyou very much! (I think...) - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8to0Pw32o+k+q+hAQGSHggAoM+hXX/428Z6AmvMzhxkXjHJJdkmGTP/ auFhWztouHVUbcXQSqMlsaib5vfWfI1nFL4klEsetHYgUdBGGsq/30wIkz0BskCH tiMtZsgrfwig7uiWJT9QsUu3FmMya4y3SMh0jmdyFCIyAtb+vQDwn/TBObM44lsm 4UPMhMPUKIZ/b7gBTiPcGsXvFuB5S45a84yH3qKbQq2pkEP8TF8cYmXiBKbdsfPk BGZ9ikuFRQy7sHC0Na9pF0T7UDdpihqackVB4G1GfipdbxiJwst7e9W4hFNXEsxa /Uw2F+xa+SwmpziOG9CV3Vnn3+kDoc3p1kzYX80wv9HPKJ5wf7Ap5w== =WDk/ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From nilesh.shastrakar at gmail.com Mon Jan 16 09:50:59 2006 From: nilesh.shastrakar at gmail.com (Nilesh Shastrakar) Date: Mon Jan 16 09:51:01 2006 Subject: Mail Archiving In-Reply-To: <011901c61a7c$86f1d3a0$3004010a@martinhlaptop> References: <95873e560601160041u67b62b69r745149396a7be13c@mail.gmail.com> <011901c61a7c$86f1d3a0$3004010a@martinhlaptop> Message-ID: <95873e560601160150o57aee927y16c531ba09399e6d@mail.gmail.com> Thanks But How can I download that emails in Outlook or can forward all mails to one user. On 1/16/06, Martin Hepworth wrote: > > Hi > > In MailScanner.conf there's a setting.. > > Archive Mail = > > Set this to a directory and it will keep all you email there in date sub > directories, see the comment in the file before this setting for more > info. > > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Nilesh Shastrakar > > Sent: 16 January 2006 08:42 > > To: MailScanner mailing list; mailscanner list; > > MailScanner@ecs.soton.ac.uk > > Subject: Mail Archiving > > > > Hello All, > > > > I want to Archive all outgoing and Incoming mails of all users on my > > server. > > Could anyone please help how do I do it. > > or is there a monitoring software > > I am using Sendmail + MailScanner > > > > Regards > > Nilesh, > > > ********************************************************************** > > This email and any files transmitted with it are confidential and > intended solely for the use of the individual or entity to whom they > are addressed. If you have received this email in error please notify > the system manager. > > This footnote confirms that this email message has been swept > for the presence of computer viruses and is believed to be clean. > > ********************************************************************** > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060116/d0cdb1a4/attachment.html From martinh at solid-state-logic.com Mon Jan 16 09:58:49 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Mon Jan 16 09:58:55 2006 Subject: Mail Archiving In-Reply-To: <95873e560601160150o57aee927y16c531ba09399e6d@mail.gmail.com> Message-ID: <016801c61a83$72dc3570$3004010a@martinhlaptop> Hi See the notes in the comments...it explains how to forward to another email address.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Nilesh Shastrakar > Sent: 16 January 2006 09:51 > To: MailScanner discussion > Subject: Re: Mail Archiving > > Thanks > > But How can I download that emails in Outlook > or can forward all mails to one user. > > > On 1/16/06, Martin Hepworth wrote: > > Hi > > In MailScanner.conf there's a setting.. > > Archive Mail = > > Set this to a directory and it will keep all you email there in date > sub > directories, see the comment in the file before this setting for > more info. > > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto: > mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Nilesh Shastrakar > > Sent: 16 January 2006 08:42 > > To: MailScanner mailing list; mailscanner list; > > MailScanner@ecs.soton.ac.uk > > Subject: Mail Archiving > > > > Hello All, > > > > I want to Archive all outgoing and Incoming mails of all users on > my > > server. > > Could anyone please help how do I do it. > > or is there a monitoring software > > I am using Sendmail + MailScanner > > > > Regards > > Nilesh, > > > ******************************************************************** > ** > > This email and any files transmitted with it are confidential and > intended solely for the use of the individual or entity to whom they > are addressed. If you have received this email in error please > notify > the system manager. > > This footnote confirms that this email message has been swept > for the presence of computer viruses and is believed to be clean. > > ******************************************************************** > ** > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! > > ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From glenn.steen at gmail.com Mon Jan 16 10:07:08 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Mon Jan 16 10:07:11 2006 Subject: HAPPY BIRTHDAY In-Reply-To: <2C8D9E31-D9A5-4105-9632-AE0E28707EAF@ecs.soton.ac.uk> References: <5EBABD62DC5AC048AD8AEC3312E02D4CCD2EF2@exchange03.lkl.ltkalmar.se> <2C8D9E31-D9A5-4105-9632-AE0E28707EAF@ecs.soton.ac.uk> Message-ID: <223f97700601160207g31d8cecdx@mail.gmail.com> On 16/01/06, Julian Field wrote: > On 16 Jan 2006, at 09:26, Anders Andersson, IT wrote: > >> > >> Julian > >> > >> Happy Birthday to you..... > >> > > > > Grattis p? f?delsedagen fr?n alla i sverige :) CC (for convenience, a quick/straight (and therefore slightly odd) translation is: "Congratulations on the birthday from everyone in Sweden"... In other words "We wish you a Happy birthday, from all us swedes" (yes, there should be a capital S on swedes:-)). > Thankyou very much! (I think...) > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From drew at themarshalls.co.uk Mon Jan 16 10:23:23 2006 From: drew at themarshalls.co.uk (Drew Marshall) Date: Mon Jan 16 10:23:27 2006 Subject: HAPPY BIRTHDAY In-Reply-To: <011a01c61a7d$2753df00$3004010a@martinhlaptop> References: <011a01c61a7d$2753df00$3004010a@martinhlaptop> Message-ID: <34513.194.70.180.170.1137407003.squirrel@webmail.r-bit.net> On Mon, January 16, 2006 09:13, Martin Hepworth wrote: > > Julian > > Happy Birthday to you..... And a very Happy Birthday from me too!! Not too much cake now and watch the candles near the fire detection kit :-) Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy From oliver at linux-kernel.at Mon Jan 16 10:30:34 2006 From: oliver at linux-kernel.at (Oliver Falk) Date: Mon Jan 16 10:30:38 2006 Subject: HAPPY BIRTHDAY In-Reply-To: <2C8D9E31-D9A5-4105-9632-AE0E28707EAF@ecs.soton.ac.uk> References: <5EBABD62DC5AC048AD8AEC3312E02D4CCD2EF2@exchange03.lkl.ltkalmar.se> <2C8D9E31-D9A5-4105-9632-AE0E28707EAF@ecs.soton.ac.uk> Message-ID: <43CB75CA.4050008@linux-kernel.at> On 01/16/2006 10:35 AM, Julian Field wrote: > On 16 Jan 2006, at 09:26, Anders Andersson, IT wrote: >>> Julian >>> >>> Happy Birthday to you..... >>> >> Grattis p? f?delsedagen fr?n alla i sverige :) > > Thankyou very much! (I think...) Because we are soooo international today: Alles Gute zum Geburtstag, Julian! Best, Oliver From rabellino at di.unito.it Mon Jan 16 12:15:24 2006 From: rabellino at di.unito.it (Rabellino Sergio) Date: Mon Jan 16 12:15:59 2006 Subject: HAPPY BIRTHDAY In-Reply-To: <43CB75CA.4050008@linux-kernel.at> References: <5EBABD62DC5AC048AD8AEC3312E02D4CCD2EF2@exchange03.lkl.ltkalmar.se> <2C8D9E31-D9A5-4105-9632-AE0E28707EAF@ecs.soton.ac.uk> <43CB75CA.4050008@linux-kernel.at> Message-ID: <43CB8E5C.1030009@di.unito.it> Oliver Falk wrote: > On 01/16/2006 10:35 AM, Julian Field wrote: > >> On 16 Jan 2006, at 09:26, Anders Andersson, IT wrote: >> >>>> Julian >>>> >>>> Happy Birthday to you..... >>>> >>> Grattis p? f?delsedagen fr?n alla i sverige :) >> >> >> Thankyou very much! (I think...) > > > Because we are soooo international today: Alles Gute zum Geburtstag, > Julian! > > Best, > Oliver Tanti Auguri anche dall'Italia ! -- Dott. Mag. Sergio Rabellino Technical Staff Department of Computer Science University of Torino (Italy) http://www.di.unito.it/~rabser Tel. +39-0116706701 Fax. +39-011751603 From jsp_prakash_test at yahoo.co.in Mon Jan 16 12:25:52 2006 From: jsp_prakash_test at yahoo.co.in (sathy prakash) Date: Mon Jan 16 12:30:00 2006 Subject: Is Mailscanner slow Message-ID: <20060116122552.14454.qmail@web8606.mail.in.yahoo.com> hi, Is Mailscanner slow in processing then mqueue.in Send instant messages to your online friends http://in.messenger.yahoo.com -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060116/d7960613/attachment.html From jorgen at giversen.net Mon Jan 16 13:06:50 2006 From: jorgen at giversen.net (sysadm) Date: Mon Jan 16 13:08:19 2006 Subject: HAPPY BIRTHDAY In-Reply-To: <5EBABD62DC5AC048AD8AEC3312E02D4CCD2EF2@exchange03.lkl.ltkalmar.se> References: <5EBABD62DC5AC048AD8AEC3312E02D4CCD2EF2@exchange03.lkl.ltkalmar.se> Message-ID: <43CB9A6A.5030504@giversen.net> An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060116/3b157b54/attachment.html From martinh at solid-state-logic.com Mon Jan 16 13:13:46 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Mon Jan 16 13:13:52 2006 Subject: Is Mailscanner slow In-Reply-To: <20060116122552.14454.qmail@web8606.mail.in.yahoo.com> Message-ID: <01a501c61a9e$aeb43b40$3004010a@martinhlaptop> Depends on how you define slow.. Please give more info, hardware spec, what O/S, MTA any performance tuning done as per the wiki.... Also what version of spamassassin and what rules/plugins you have above the default. Same for any anti-virus. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of sathy prakash > Sent: 16 January 2006 12:26 > To: MailScanner discussion > Subject: Is Mailscanner slow > > hi, > Is Mailscanner slow in processing then mqueue.in > > Send instant messages to your online friends http://in.messenger.yahoo.com ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From alex at nkpanama.com Mon Jan 16 13:24:59 2006 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Mon Jan 16 13:25:12 2006 Subject: HAPPY BIRTHDAY In-Reply-To: <2C8D9E31-D9A5-4105-9632-AE0E28707EAF@ecs.soton.ac.uk> References: <5EBABD62DC5AC048AD8AEC3312E02D4CCD2EF2@exchange03.lkl.ltkalmar.se> <2C8D9E31-D9A5-4105-9632-AE0E28707EAF@ecs.soton.ac.uk> Message-ID: <43CB9EAB.1080206@nkpanama.com> FELIZ CUMPLEA?OS DE PARTE DE TODOS LOS HISPANOPARLANTES USUARIOS DE MAILSCANNER! Y gracias por todo tu esfuerzo... Saludos, Alex Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > On 16 Jan 2006, at 09:26, Anders Andersson, IT wrote: > >>> Julian >>> >>> Happy Birthday to you..... >>> >>> >> Grattis p? f?delsedagen fr?n alla i sverige :) >> > > Thankyou very much! (I think...) > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.4 (Build 4042) > > iQEVAwUBQ8to0Pw32o+k+q+hAQGSHggAoM+hXX/428Z6AmvMzhxkXjHJJdkmGTP/ > auFhWztouHVUbcXQSqMlsaib5vfWfI1nFL4klEsetHYgUdBGGsq/30wIkz0BskCH > tiMtZsgrfwig7uiWJT9QsUu3FmMya4y3SMh0jmdyFCIyAtb+vQDwn/TBObM44lsm > 4UPMhMPUKIZ/b7gBTiPcGsXvFuB5S45a84yH3qKbQq2pkEP8TF8cYmXiBKbdsfPk > BGZ9ikuFRQy7sHC0Na9pF0T7UDdpihqackVB4G1GfipdbxiJwst7e9W4hFNXEsxa > /Uw2F+xa+SwmpziOG9CV3Vnn3+kDoc3p1kzYX80wv9HPKJ5wf7Ap5w== > =WDk/ > -----END PGP SIGNATURE----- > > From Denis.Beauchemin at USherbrooke.ca Mon Jan 16 15:12:45 2006 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Mon Jan 16 15:13:26 2006 Subject: --lint patch for Mailscanner In-Reply-To: <43C938C1.8090503@ecs.soton.ac.uk> References: <43C938C1.8090503@ecs.soton.ac.uk> Message-ID: <43CBB7ED.90600@USherbrooke.ca> Julian Field wrote: > The attached tar.gz file contains 2 patches, one for > /usr/sbin/MailScanner and the other for > /usr/lib/MailScanner/MailScanner/CustomConfig.pm. > > Once you have applied the patches (they are both very simple and > small), you will be able to run > MailScanner --lint > or > MailScanner --lint path-to-MailScanner.conf-file > > It should just check the syntax of the configuration files and then stop. > Julian, Just installed the patch on mailscanner-4.50.6-2 and the results are interesting ;-) : # MailScanner --lint 773 Is that my lucky number of the day? Did you confuse the patch with your lotto numbers generator? :-D I had no error installing the patches: # cd /usr/lib/MailScanner/MailScanner # patch < CustomConfig.pm.patch patching file CustomConfig.pm # cd /usr/sbin/ # patch < /usr/lib/MailScanner/MailScanner/usr.sbin.MailScanner.patch patching file MailScanner # Happy birthday! :-) Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x2252 F: 819.821.8045 From bpumphrey at WoodMacLaw.com Mon Jan 16 15:18:00 2006 From: bpumphrey at WoodMacLaw.com (Billy A. Pumphrey) Date: Mon Jan 16 15:18:06 2006 Subject: Disk is full Message-ID: <04D932B0071FE34FA63EBB1977B48D15ACE020@woodenex.woodmaclaw.local> > > You'll probably need to use the -r or -o option with that check. > > I usually run the checks as follows: > > cd /var/lib/mysql/mailscanner > myisamchk maillog.MYI > > if that returns an error other than the one saying a user is still using > the > db then > > stop mysql > myisamchk -r maillog.MYI > > restart mysql > > You may have more problems with more databases and tables. If mysql > doesn't > start, try checking all tables in all databases. > > use something like in each database directory > > myisamchk *.MYI > > then run myisamchk with the -r or -o option as above on each index that > reports an error with mysql stopped. > > Steve Campbell > campbell@cnpapers.com > Charleston Newspapers Hot Dog! You guys rule. That worked perfectly. I did get the error and had to do part 2 of the instructions. Thank you so much. From jaearick at colby.edu Mon Jan 16 15:29:27 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Mon Jan 16 15:29:37 2006 Subject: 4.50.8: some comments Message-ID: Julian, I rolled out 4.50.8 this morning, cool, working great so far. Some comments about what I found with it: * Tracking a batch: Now that we have a cool timing feature for batches of messages, I wonder if batches could be uniquely identified by something like a "bid" (batch id number, like pid), eg: New Batch 12345: Found 4 messages waiting New Batch 12345: Scanning 1 messages, 9020 bytes Batch 12345 processed in 4.11 seconds Where "12345" is the bid number. Just a suggestion... * lint feature: When I ran this, it said: ./MailScanner --lint Read 696 hostnames from the phishing whitelist Config: calling custom init function IPBlock Could not use Custom Function code MailScanner::CustomConfig::InitIPBlock, it could not be "eval"ed. Make sure the module is correct with perl -wc at /opt/MailScanner/lib/MailScanner/Config.pm line 798 Checking SpamAssassin errors (if you use it), this may take some time... Using SpamAssassin results cache Connected to SpamAssassin cache database SpamAssassin reported no errors. I'm probably one of the few people who use IPBlock. * perl modules: What's up to date? The first thing I do with a new install is comment out the perl modules install portion of install.sh. I'm paranoid, and I want to do this by hand. Then I compare what you have in perl-tar to what I have installed in perl (I use pmdesc from pmtools, see CPAN), and also compare to what CPAN has for the modules. I tend to run the latest versions from CPAN, and MailScanner upgrades are the perfect time to check CPAN for new stuff. Here's a comparison of yours versus CPAN: Yours CPAN Archive-Zip 1.14 1.16 Compress-Zlib 1.34 1.41 File-Spec 0.82 * (see below) HTML-Parser 3.45 3.48 HTML-Tagset 3.03 3.10 IO-stringy 2.108 2.110 MIME-Base64 3.05 3.07 MIME-Tools 5.417 5.419 MailTools 1.50 1.71 Net-CIDR 0.10 0.11 TimeDate 1.1301 1.16 (**) * File-Spec seems to have been superseded by PathTools-3.15 ** TimeDate-1.16 is nearly two years old and seems to have been absorbed into the perl 5.8.7 release, maybe. I wonder if this one is needed anymore? Maybe time to upgrade a few modules in perl-tar? It seems like a bunch of module authors released new versions in late December. Jeff Earickson Colby College From steve.swaney at fsl.com Mon Jan 16 15:36:31 2006 From: steve.swaney at fsl.com (Stephen Swaney) Date: Mon Jan 16 15:36:34 2006 Subject: mailscanner In-Reply-To: <20060116073957.89639.qmail@web8609.mail.in.yahoo.com> Message-ID: <200601161536.k0GFaW8E018447@bkserver.blacknight.ie> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of sathy prakash > Sent: Monday, January 16, 2006 2:40 AM > To: MailScanner discussion > Subject: Re: mailscanner > > thanks.... > > Tony Enderby wrote: > > > From your mailscanner.conf file ... > > # How many MailScanner processes do you want to run at a time? > # There is no point increasing this figure if your MailScanner > server > # is happily keeping up with your mail traffic. > # If you are running on a server with more than 1 CPU, or you have a > # high mail load (and/or slow DNS lookups) then you should see > better > # performance if you increase this figure. > # If you are running on a small system with limited RAM, you should > # note that each child takes just over 20MB. > # > # As a rough guide, try 5 children per CPU. But read the notes > above. > > Max Children = 5 > > > On 1/16/2006, "sathy prakash" wrote: > > >hi all , > > When I start the Mailscanner by! runing script > > /opt/MailScanner/bin/check_mailscanner i see 4 Mailscanner > processes > > running in my system why? > > > > thanks and regards.... > > > > sathya Although it's mentioned at the bottom of each list message, it might be a good time to remind new users to Support MailScanner development - buy the book off the website (happy birthday Julian): http://www.cafepress.com/mailscanner2,mailscanner.13170076 Also remember in addition to the wiki, a basic MailScanner manual is available thanks to the assistance of many people on this list. It may be found at: http://www.fsl.com/support.html It is always a good idea to check the MailScanner wiki and documentation before posting. Those of us who document MailScanner like to think that someone actually reads the docs at least once in a while :) Steve Stephen Swaney Fort Systems Ltd. stephen.swaney@fsl.com www.fsl.com From drolland at kdinet.com Mon Jan 16 15:42:47 2006 From: drolland at kdinet.com (Diane Rolland) Date: Mon Jan 16 15:42:52 2006 Subject: Archive and delete messages? Message-ID: <018c01c61ab3$817b2fc0$6500a8c0@kdinet.local> I have an archive rule that if mail is sent to a particular user, it is copied off to another directory. I also want to delete the mail from the mailbox. Here is my rule in the archive.rules file: To: docs_test@domain.com /docs_test/ How can I delete the mail for this user? Is this possible? Thanks in Advance, Diane -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060116/4e8c2e3d/attachment.html From MailScanner at ecs.soton.ac.uk Mon Jan 16 15:47:37 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 16 15:47:50 2006 Subject: --lint patch for Mailscanner In-Reply-To: <43CBB7ED.90600@USherbrooke.ca> References: <43C938C1.8090503@ecs.soton.ac.uk> <43CBB7ED.90600@USherbrooke.ca> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- That's a bug that I have since fixed. On 16 Jan 2006, at 15:12, Denis Beauchemin wrote: > Julian Field wrote: > >> The attached tar.gz file contains 2 patches, one for /usr/sbin/ >> MailScanner and the other for /usr/lib/MailScanner/MailScanner/ >> CustomConfig.pm. >> >> Once you have applied the patches (they are both very simple and >> small), you will be able to run >> MailScanner --lint >> or >> MailScanner --lint path-to-MailScanner.conf-file >> >> It should just check the syntax of the configuration files and >> then stop. >> > Julian, > > Just installed the patch on mailscanner-4.50.6-2 and the results > are interesting ;-) : > # MailScanner --lint > 773 > > Is that my lucky number of the day? Did you confuse the patch with > your lotto numbers generator? :-D > > I had no error installing the patches: > # cd /usr/lib/MailScanner/MailScanner > # patch < CustomConfig.pm.patch > patching file CustomConfig.pm > # cd /usr/sbin/ > # patch < /usr/lib/MailScanner/MailScanner/usr.sbin.MailScanner.patch > patching file MailScanner > # > > Happy birthday! :-) > > Denis > > -- > _ > ?v? Denis Beauchemin, analyste > /(_)\ Universit? de Sherbrooke, S.T.I. > ^ ^ T: 819.821.8000x2252 F: 819.821.8045 > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8vAHfw32o+k+q+hAQEqPgf+MGXf/Ry+RS11OqbFXRFla8ep3xmRCUiv QhqYjZaiNSkjZbXmYJ9vWMHeY8fQylANBejszubRuIObdNUfVj15hJhm9mHAFYZ2 KJB8NQo7QaaKcja1FrYSRcQnUvo4M/zJqek4/dAm0pNWuEIY2zOoOmI0F1CrSmK6 4j6l7jE0CZH1gpbl2GOBDyhn3dpp1MaeJC1SY9aDGuC3UUofwjCJeMP+Cde4o8o6 QV8u2jm+yAt1+RQs7uJXbVHWwtPcvvb9dM33wo5GVfW2+7l9GcYyHmW4EcjCg7uF DkmhClHxA9N9kibYK2OEw/gTJ/KLU1mTfTM8Hs2Xo56g+Mm9nFy8Nw== =uY5k -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From P.G.M.Peters at utwente.nl Mon Jan 16 15:48:14 2006 From: P.G.M.Peters at utwente.nl (Peter Peters) Date: Mon Jan 16 15:48:18 2006 Subject: bhx files Message-ID: <43CBC03E.3030201@utwente.nl> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I got about a hundred messages with .bhx files. They seem to come from online books @ oreilly. Anybody know what a bhx is? (I got the same one with a pif-file). - -- Peter Peters, senior beheerder (Security) Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE) Universiteit Twente, Postbus 217, 7500 AE Enschede telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQFDy8A9Mbmy+DDgnIURAn3nAKDbn0FilzCVZTx9JdYGAj4x/Xp90gCfatQU oE86pQwae482Djl3WInyx+U= =JB2g -----END PGP SIGNATURE----- From MailScanner at ecs.soton.ac.uk Mon Jan 16 15:52:05 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 16 15:52:15 2006 Subject: 4.50.8: some comments In-Reply-To: References: Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 16 Jan 2006, at 15:29, Jeff A. Earickson wrote: > Julian, > I rolled out 4.50.8 this morning, cool, working great so far. > Some comments about what I found with it: > > * Tracking a batch: Now that we have a cool timing feature for > batches of messages, I wonder if batches could be uniquely > identified by something like a "bid" (batch id number, like pid), > eg: > > New Batch 12345: Found 4 messages waiting > New Batch 12345: Scanning 1 messages, 9020 bytes > Batch 12345 processed in 4.11 seconds > > Where "12345" is the bid number. Just a suggestion... > > * lint feature: When I ran this, it said: > > ./MailScanner --lint > Read 696 hostnames from the phishing whitelist > Config: calling custom init function IPBlock > Could not use Custom Function code > MailScanner::CustomConfig::InitIPBlock, > it could not be "eval"ed. Make sure the module is correct with > perl -wc at > /opt/MailScanner/lib/MailScanner/Config.pm line 798 > Checking SpamAssassin errors (if you use it), this may take some > time... > Using SpamAssassin results cache > Connected to SpamAssassin cache database > SpamAssassin reported no errors. > > I'm probably one of the few people who use IPBlock. Dunno about that one. > > * perl modules: What's up to date? > > The first thing I do with a new install is comment out the perl > modules install portion of install.sh. I'm paranoid, and I want > to do this by hand. Then I compare what you have in perl-tar to > what I have installed in perl (I use pmdesc from pmtools, see CPAN), > and also compare to what CPAN has for the modules. I tend to run > the latest versions from CPAN, and MailScanner upgrades are the > perfect time to check CPAN for new stuff. Here's a comparison > of yours versus CPAN: I don't always track the absolutely latest versions. I know the versions I have work, and I don't like randomly upgrading to the latest code they publish without some reassurance that there's a good reason to do it. Have you actually had any faults that can be isolated to bugs in the versions of Perl modules which I ship? - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8vBJ/w32o+k+q+hAQGjMgf+KYky2YJA1fIQ0qS36jjMH2V4r8TDqbmy SZeAfVzckRJuG9rPOzjkIdoBnCghI4GDlYnlfP0bfWYXAL6iOepjQxyg9sJccxzi RR6Urp5ZInGsmAMd+Y5EYmGosQWHh9UYcAjkn+3r1m6VIIlRXS/RDuMr4u3100DY sxkUMRR/PVJ9xkH62Rgs3h445Nz0Vc/9kwzFAUohsMy8BOGdcDR8679IXz0V2Ftz atNBzzBe6I0q1um4mhvZFw9MdjRfluhP/EusxsCYvRFMjKaqwR0ROOgKXeIT6LyD O55K92dXOqn6StHtcnYP2wrUGAtTRA7FL+1LCZ8PNpIIvYVuWcfWfg== =mnc0 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Mon Jan 16 15:58:18 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 16 15:58:27 2006 Subject: Archive and delete messages? In-Reply-To: <018c01c61ab3$817b2fc0$6500a8c0@kdinet.local> References: <018c01c61ab3$817b2fc0$6500a8c0@kdinet.local> Message-ID: <0BD3D786-EC0B-45F7-A929-2DCC651AD458@ecs.soton.ac.uk> Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: PGP.sig Type: application/pgp-signature Size: 487 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060116/1042f917/PGP.bin From shuttlebox at gmail.com Mon Jan 16 16:00:21 2006 From: shuttlebox at gmail.com (shuttlebox) Date: Mon Jan 16 16:00:25 2006 Subject: Archive and delete messages? In-Reply-To: <018c01c61ab3$817b2fc0$6500a8c0@kdinet.local> References: <018c01c61ab3$817b2fc0$6500a8c0@kdinet.local> Message-ID: <625385e30601160800j1ef11381x3c3f2daa95518ad0@mail.gmail.com> On 1/16/06, Diane Rolland wrote: > > I have an archive rule that if mail is sent to a particular user, it is > copied off to another directory. > > > > I also want to delete the mail from the mailbox. > > > > Here is my rule in the archive.rules file: > > To: docs_test@domain.com /docs_test/ > > How can I delete the mail for this user? Is this possible? > Make a similar ruleset for the actions (Spam, High Scoring Spam and Non Spam) and do not include deliver for that user but for default. -- /peter -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060116/54e05bb3/attachment.html From MailScanner at ecs.soton.ac.uk Mon Jan 16 16:03:58 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 16 16:04:08 2006 Subject: bhx files In-Reply-To: <43CBC03E.3030201@utwente.nl> References: <43CBC03E.3030201@utwente.nl> Message-ID: <09189735-F213-4B78-84A9-4B92B87A2E9C@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- binhex? On 16 Jan 2006, at 15:48, Peter Peters wrote: > * PGP Signed by an unverified key: 01/16/06 at 15:48:13 > > I got about a hundred messages with .bhx files. They seem to come from > online books @ oreilly. > > Anybody know what a bhx is? (I got the same one with a pif-file). > > -- > Peter Peters, senior beheerder (Security) > Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE) > Universiteit Twente, Postbus 217, 7500 AE Enschede > telefoon: 053 - 489 2301, fax: 053 - 489 2383, http:// > www.utwente.nl/itbe > > * P.G.M. Peters > * 0x30E09C85 - Unverified (L) > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read the Wiki (http://wiki.mailscanner.info/). > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8vD8Pw32o+k+q+hAQGmNAf/YAYhnccmvaRjWnTza1F08r6gQ+OxGybn 4xEWNpkwrtslP9MQK3pX1Kp+YT6avu0f2Pi+NLQUOo3o2f7IRc5RhL7pae7bSwTo T3C5YxqWzw3XA4uu14vUwTapUDKG0izOha4tPVH0GQ+DSqUCI5U80YzGbCsawP7S nuUX1AyW+5U54Qd8tHZR4HKk18Az7RaHXIeYuei4FBAyAcQe76YBCuh/O/4Lha1p NAgxCsF1LNuPOHfWGhh6yzFsnHlDeL4HuIpe9YtRd/Vub4v5j6nBfxiYrtHwszgq hS+NKZPphDZoawsBvsilujKrMqkgrT4rPvkU2zciNQJaTKrTxy1Pgg== =IjdC -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From mkettler at evi-inc.com Mon Jan 16 16:14:08 2006 From: mkettler at evi-inc.com (Matt Kettler) Date: Mon Jan 16 16:14:35 2006 Subject: bhx files In-Reply-To: <43CBC03E.3030201@utwente.nl> References: <43CBC03E.3030201@utwente.nl> Message-ID: <43CBC650.3080508@evi-inc.com> Peter Peters wrote: > I got about a hundred messages with .bhx files. They seem to come from > online books @ oreilly. > > Anybody know what a bhx is? (I got the same one with a pif-file). Google: bhx extension turned this up as the first hit: http://filext.com/detaillist.php?extdetail=BHX From jaearick at colby.edu Mon Jan 16 16:17:43 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Mon Jan 16 16:17:49 2006 Subject: 4.50.8: some comments In-Reply-To: References: Message-ID: On Mon, 16 Jan 2006, Julian Field wrote: >> * lint feature: When I ran this, it said: >> >> I'm probably one of the few people who use IPBlock. > > Dunno about that one. I'll chase this and see if I can figure it out... > >> >> * perl modules: What's up to date? >> > > I don't always track the absolutely latest versions. I know the > versions I have work, and I don't like randomly upgrading to the > latest code they publish without some reassurance that there's a good > reason to do it. > > Have you actually had any faults that can be isolated to bugs in the > versions of Perl modules which I ship? No, nothing like that. It sounds like you are more conservative than I am on perl modules. If a newer version caused me MS trouble, I would try your version as a first test. I've not (yet) had problems with newer perl modules and MailScanner. The versions I noted in my original email are where I'm at with 4.50.8 right now. Thanks, Jeff Earickson Colby College From Denis.Beauchemin at USherbrooke.ca Mon Jan 16 16:19:28 2006 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Mon Jan 16 16:19:57 2006 Subject: bhx files In-Reply-To: <43CBC03E.3030201@utwente.nl> References: <43CBC03E.3030201@utwente.nl> Message-ID: <43CBC790.2080604@USherbrooke.ca> According to Google: *.*bhx* file extension, .*bhx* file type* - BinHex compressed file ascii archive This is a Mac format. Denis Peter Peters wrote: >-----BEGIN PGP SIGNED MESSAGE----- >Hash: SHA1 > >I got about a hundred messages with .bhx files. They seem to come from >online books @ oreilly. > >Anybody know what a bhx is? (I got the same one with a pif-file). > >- -- >Peter Peters, senior beheerder (Security) >Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE) >Universiteit Twente, Postbus 217, 7500 AE Enschede >telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe >-----BEGIN PGP SIGNATURE----- >Version: GnuPG v1.4.2 (MingW32) >Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org > >iD8DBQFDy8A9Mbmy+DDgnIURAn3nAKDbn0FilzCVZTx9JdYGAj4x/Xp90gCfatQU >oE86pQwae482Djl3WInyx+U= >=JB2g >-----END PGP SIGNATURE----- > > > -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x2252 F: 819.821.8045 -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3226 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060116/c12b5568/smime.bin From mailscanner at mango.zw Mon Jan 16 09:53:18 2006 From: mailscanner at mango.zw (Jim Holland) Date: Mon Jan 16 16:35:14 2006 Subject: Virus slow down? In-Reply-To: <43BE9C43.4000400@pixelhammer.com> Message-ID: Hi Sorry for delayed response On Fri, 6 Jan 2006, DAve wrote: > Date: Fri, 6 Jan 2006 11:35:15 -0500 > From: DAve > Reply-To: MailScanner mailing list > To: MAILSCANNER@JISCMAIL.AC.UK > Subject: Virus slow down? > > Is anyone else noticing a huge drop in viruses? Last night at 10pm EST > my virus captures dropped to an all time low. I generally catch around > 1100 per day, per server, and I have only caught 60 so far today. I also noticed a big drop from 6 January, which is the date of the last Sober worm to arrive. Not a single Sober worm since then. Perhaps it is because I started blocking sites that had been "streaming" Sober to us. Regards Jim Holland System Administrator MANGO - Zimbabwe's non-profit e-mail service From ssilva at sgvwater.com Mon Jan 16 16:47:01 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Mon Jan 16 16:48:44 2006 Subject: Test In-Reply-To: <43CB09C5.5030307@cenpac.net.nr> References: <43CB09C5.5030307@cenpac.net.nr> Message-ID: Jon Leeman spake the following on 1/15/2006 6:49 PM: > Ugo Bellavance wrote: >> This is a test to see if we can post through gmane again. > > from sunny Nauru I have sent a thank you to Lars at GMANE for fixing this. I love using GMANE through a newsreader, so much easier to follow the threading. -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () From ssilva at sgvwater.com Mon Jan 16 17:20:52 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Mon Jan 16 17:21:49 2006 Subject: Is Mailscanner slow In-Reply-To: <20060116122552.14454.qmail@web8606.mail.in.yahoo.com> References: <20060116122552.14454.qmail@web8606.mail.in.yahoo.com> Message-ID: sathy prakash spake the following on 1/16/2006 4:25 AM: > hi, > Is Mailscanner slow in processing then mqueue.in > > Send instant messages to your online friends http://in.messenger.yahoo.com > Please, Please, read the documentation!! We are all sysadmins on busy systems, and although helping others is a way to give back to open source software, you will have to do "some" of the work yourself! We have all started at the beginning at some point in our lives, and have all learned to consult the "Vast repository of documents" on the Internet. And you will learn soo much more by trying to work things out on your own first. Also, please do not ask the same question over and over again. It is like having my children ask repeatedly, "are we there yet?". -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () From MailScanner at ecs.soton.ac.uk Mon Jan 16 17:53:00 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 16 17:53:11 2006 Subject: Is Mailscanner slow In-Reply-To: References: <20060116122552.14454.qmail@web8606.mail.in.yahoo.com> Message-ID: <43CBDD7C.9070509@ecs.soton.ac.uk> Scott Silva wrote: > sathy prakash spake the following on 1/16/2006 4:25 AM: > >> hi, >> Is Mailscanner slow in processing then mqueue.in >> >> Send instant messages to your online friends http://in.messenger.yahoo.com >> >> > Please, Please, read the documentation!! > We are all sysadmins on busy systems, and although helping others is a way to > give back to open source software, you will have to do "some" of the work > yourself! We have all started at the beginning at some point in our lives, and > have all learned to consult the "Vast repository of documents" on the > Internet. And you will learn soo much more by trying to work things out on > your own first. > > Also, please do not ask the same question over and over again. It is like > having my children ask repeatedly, "are we there yet?". > And please at least read http://wiki.mailscanner.info/doku.php?id=lists:posting_guidelines -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From support at spyproductions.com Mon Jan 16 18:14:07 2006 From: support at spyproductions.com (SpyProductions Support Team) Date: Mon Jan 16 18:13:04 2006 Subject: Need Contract Admin Help In-Reply-To: <43CBDD7C.9070509@ecs.soton.ac.uk> Message-ID: <13c001c61ac8$a4741450$0500a8c0@bullet> Gents, I'm not a sys admin. I'm the business owner. I may need some assistance on occasion. I'd like to get an outside perspective from time-to-time so that I know my system admin is worth his salt. If anyone is interested in some per job work, please contact me at staff@spyproductions.com. -Lars SpyProductions Achieve Web Success http://spyproductions.com From fajarep at simplimobile.com Tue Jan 17 01:13:24 2006 From: fajarep at simplimobile.com (Fajar) Date: Tue Jan 17 01:14:03 2006 Subject: dccfid performance improvement? Message-ID: <028e01c61b03$432cd020$2f01a8c0@Fajar> One of the suggestion to tune mailscanner by using dccfid, i'm already setup the dcc, and from spamasassin --list seems the dcc workingfine, i saw some connection made from my computer to some host with destination port 6277. And now, how do I make sure mailscanner using dcc too? Thanks in advance. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060117/1fa1089c/attachment.html From ugob at camo-route.com Tue Jan 17 01:22:30 2006 From: ugob at camo-route.com (Ugo Bellavance) Date: Tue Jan 17 01:22:57 2006 Subject: Test In-Reply-To: References: <43CB09C5.5030307@cenpac.net.nr> Message-ID: Scott Silva wrote: > Jon Leeman spake the following on 1/15/2006 6:49 PM: >> Ugo Bellavance wrote: >>> This is a test to see if we can post through gmane again. >> from sunny Nauru > I have sent a thank you to Lars at GMANE for fixing this. > I love using GMANE through a newsreader, so much easier to follow the threading. > Eheh, I deserve some thanks too... I told lars ;). I also _love_ using GMANE :)! -- Ugo -> Please don't send a copy of your reply by e-mail. I read the list. -> Please avoid top-posting, long signatures and HTML, and cut the irrelevant parts in your replies. From ugob at camo-route.com Tue Jan 17 01:27:38 2006 From: ugob at camo-route.com (Ugo Bellavance) Date: Tue Jan 17 01:41:45 2006 Subject: HAPPY BIRTHDAY In-Reply-To: <5EBABD62DC5AC048AD8AEC3312E02D4CCD2EF2@exchange03.lkl.ltkalmar.se> References: <5EBABD62DC5AC048AD8AEC3312E02D4CCD2EF2@exchange03.lkl.ltkalmar.se> Message-ID: Anders Andersson, IT wrote: > >> Julian >> >> Happy Birthday to you..... >> >> > > Grattis p? f?delsedagen fr?n alla i sverige :) Joyeux anniversaire de tous les francophones au Canada (Aussi en France et ailleurs...) :) -- Ugo -> Please don't send a copy of your reply by e-mail. I read the list. -> Please avoid top-posting, long signatures and HTML, and cut the irrelevant parts in your replies. From ugob at camo-route.com Tue Jan 17 04:07:21 2006 From: ugob at camo-route.com (Ugo Bellavance) Date: Tue Jan 17 04:07:34 2006 Subject: dccfid performance improvement? In-Reply-To: <028e01c61b03$432cd020$2f01a8c0@Fajar> References: <028e01c61b03$432cd020$2f01a8c0@Fajar> Message-ID: Fajar wrote: > One of the suggestion to tune mailscanner by using dccfid, i'm already > setup the dcc, and from spamasassin --list seems the dcc workingfine, i > saw some connection made from my computer to some host with destination > port 6277. Ok, how is that related to the subject of your post? > > And now, how do I make sure mailscanner using dcc too? > Run a lint test. Please see the wiki, especially the MAQ part. Feel free to post again if you haven't found. > Thanks in advance. > -- Ugo -> Please don't send a copy of your reply by e-mail. I read the list. -> Please avoid top-posting, long signatures and HTML, and cut the irrelevant parts in your replies. From pz at christ-net.sk Tue Jan 17 08:15:53 2006 From: pz at christ-net.sk (Peter Zimen) Date: Tue Jan 17 08:16:06 2006 Subject: Spam filter configuration Message-ID: <3F0DF81F-77FE-4396-958A-75EDF783F60E@christ-net.sk> Hello, can you tell me your know how to "optimal" setup of Spam Check rules for better spam filtration? How to set RBL and DOMAINs check and Spam Assassian score with rules? Thanks for your ideas. Peter From shuttlebox at gmail.com Tue Jan 17 08:32:14 2006 From: shuttlebox at gmail.com (shuttlebox) Date: Tue Jan 17 08:32:19 2006 Subject: dccfid performance improvement? In-Reply-To: <028e01c61b03$432cd020$2f01a8c0@Fajar> References: <028e01c61b03$432cd020$2f01a8c0@Fajar> Message-ID: <625385e30601170032ieda71b0nccb96096de28e7ef@mail.gmail.com> On 1/17/06, Fajar wrote: > > One of the suggestion to tune mailscanner by using dccfid, i'm already > setup the dcc, and from spamasassin --list seems the dcc workingfine, i saw > some connection made from my computer to some host with destination port > 6277. > > And now, how do I make sure mailscanner using dcc too? > It's on by default in MailScanner and if SA can find DCC it will use it. Grep for DCC in your mail log. -- /peter -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060117/d3e52bf1/attachment.html From fajarep at simplimobile.com Tue Jan 17 08:53:05 2006 From: fajarep at simplimobile.com (Fajar) Date: Tue Jan 17 08:53:30 2006 Subject: dccfid performance improvement? References: <028e01c61b03$432cd020$2f01a8c0@Fajar> <625385e30601170032ieda71b0nccb96096de28e7ef@mail.gmail.com> Message-ID: <056001c61b43$6f88c170$2f01a8c0@Fajar> it seems dccifd running fine, the now mailscanner almost instanly scanning the message, dunno if this because of the dcc or not. But thanks. Sorry for bad subject, wrong subject :D ----- Original Message ----- From: shuttlebox To: MailScanner discussion Sent: Tuesday, January 17, 2006 3:32 PM Subject: Re: dccfid performance improvement? It's on by default in MailScanner and if SA can find DCC it will use it. Grep for DCC in your mail log. -- /peter ------------------------------------------------------------------------------ -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060117/2ba9b8c5/attachment.html From amirse at gmail.com Tue Jan 17 09:11:00 2006 From: amirse at gmail.com (Amir Sela) Date: Tue Jan 17 09:11:02 2006 Subject: Dropping spam into a different a custom mailbox Message-ID: <814064980601170111r23b50c81s6466e9d9f9a33ac2@mail.gmail.com> Hi, I'm using MailScanner+SpamAssassin+Postfix. I couldn't find anywhere in the docs a way to setup my system such that instead of (or in addtion to) appending the {spam?} string to subject lines, I will get all spam redirected to some mbox inside the user's home directory. I tried using Procmail inside postfix, but as soon as I don't get any mail at all. Filtering on the client-side is not an option in my case, so I must do this server-side. What's the best way of doing that with my setup? I simply didn't see anything pertinent I can use in "Spam Actions =" to deliver to a custom mailbox. Thanks a lot, -amir From martinh at solid-state-logic.com Tue Jan 17 09:23:15 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Tue Jan 17 09:23:23 2006 Subject: Spam filter configuration In-Reply-To: <3F0DF81F-77FE-4396-958A-75EDF783F60E@christ-net.sk> Message-ID: <004401c61b47$a58b0fe0$3004010a@martinhlaptop> Peter Depends on what spam you get, but there's this http://wiki.mailscanner.info/doku.php?id=documentation:anti_spam:spamassassi n:rules:recommended also check out the www.rulesemporium.com rules (and Rules Du Jour to update them). Good starting point -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Peter Zimen > Sent: 17 January 2006 08:16 > To: mailscanner@lists.mailscanner.info > Subject: Spam filter configuration > > Hello, > can you tell me your know how to "optimal" setup of Spam Check rules > for better spam filtration? > > How to set RBL and DOMAINs check and Spam Assassian score with rules? > > Thanks for your ideas. > > Peter > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From MailScanner at ecs.soton.ac.uk Tue Jan 17 09:37:08 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Jan 17 09:37:17 2006 Subject: Dropping spam into a different a custom mailbox In-Reply-To: <814064980601170111r23b50c81s6466e9d9f9a33ac2@mail.gmail.com> References: <814064980601170111r23b50c81s6466e9d9f9a33ac2@mail.gmail.com> Message-ID: <7E70D91B-F777-4DA9-9054-7B6C41969590@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- MailScanner does not get involved with final message delivery at all. You will need to either get Postfix to do this or procmail. On 17 Jan 2006, at 09:11, Amir Sela wrote: > Hi, > I'm using MailScanner+SpamAssassin+Postfix. I couldn't find anywhere > in the docs a way > to setup my system such that instead of (or in addtion to) appending > the {spam?} string to > subject lines, I will get all spam redirected to some mbox inside the > user's home directory. > I tried using Procmail inside postfix, but as soon as I don't get any > mail at all. > Filtering on the client-side is not an option in my case, so I must do > this server-side. > What's the best way of doing that with my setup? > I simply didn't see anything pertinent I can use in "Spam Actions =" > to deliver to a custom > mailbox. > Thanks a lot, > > -amir > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8y6x/w32o+k+q+hAQG1uQf/TfIZ1BQeoqvVF1eN/Gn+y3FULRtffWR2 daXxTrLWlWfOOraRDCcws23HPsnOqs2kQUUcdPpL+MqAfwHXN3TijY+yHHYD6iXW NFOQeoX6taB42kgZy8dkxmMd7CJ3aNineT0p6V/M8CK5ja5R991R4tGk1SfWzbpV IlNKDSicwdAhkpHf34kwYvygf+a/MvkCuYruVb+SG+gAoa0DJEi5IyjVlcGq+dcW dTMp8+7J28vB/F1idIxZCFte6ILq0yC49/GxyYIdZKx2lUtgLAtPxOWGuYtcCNa0 SjMekda2ubCVf+gbjjYbxidtlOra+VRtJyQCMi0xG4IKYrwlc2h7KA== =ag/A -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From amirse at gmail.com Tue Jan 17 09:45:29 2006 From: amirse at gmail.com (Amir Sela) Date: Tue Jan 17 09:45:31 2006 Subject: Dropping spam into a different a custom mailbox In-Reply-To: <7E70D91B-F777-4DA9-9054-7B6C41969590@ecs.soton.ac.uk> References: <814064980601170111r23b50c81s6466e9d9f9a33ac2@mail.gmail.com> <7E70D91B-F777-4DA9-9054-7B6C41969590@ecs.soton.ac.uk> Message-ID: <814064980601170145x42914300y3c23f45e910aa67f@mail.gmail.com> First of all, thanks for the reply. The problem is that if I define postfix to use procmail, it simply doesn't deliver mail. And since this is a MailScanner specific problem, since it uses postfix, I thought someone here might give me an exact idea on how this is done when using postfix with mailscanner. It's not on the postfix docs because it's a MailScanner issue, and here I get "this is not a Mailscanner issue", and I'm kind of stuck because there are no docs on how this is done. Thanks again, -Amir On 1/17/06, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > MailScanner does not get involved with final message delivery at all. > You will need to either get Postfix to do this or procmail. > > On 17 Jan 2006, at 09:11, Amir Sela wrote: > > > Hi, > > I'm using MailScanner+SpamAssassin+Postfix. I couldn't find anywhere > > in the docs a way > > to setup my system such that instead of (or in addtion to) appending > > the {spam?} string to > > subject lines, I will get all spam redirected to some mbox inside the > > user's home directory. > > I tried using Procmail inside postfix, but as soon as I don't get any > > mail at all. > > Filtering on the client-side is not an option in my case, so I must do > > this server-side. > > What's the best way of doing that with my setup? > > I simply didn't see anything pertinent I can use in "Spam Actions =" > > to deliver to a custom > > mailbox. > > Thanks a lot, > > > > -amir > > -- > > MailScanner mailing list > > MailScanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.4 (Build 4042) > > iQEVAwUBQ8y6x/w32o+k+q+hAQG1uQf/TfIZ1BQeoqvVF1eN/Gn+y3FULRtffWR2 > daXxTrLWlWfOOraRDCcws23HPsnOqs2kQUUcdPpL+MqAfwHXN3TijY+yHHYD6iXW > NFOQeoX6taB42kgZy8dkxmMd7CJ3aNineT0p6V/M8CK5ja5R991R4tGk1SfWzbpV > IlNKDSicwdAhkpHf34kwYvygf+a/MvkCuYruVb+SG+gAoa0DJEi5IyjVlcGq+dcW > dTMp8+7J28vB/F1idIxZCFte6ILq0yC49/GxyYIdZKx2lUtgLAtPxOWGuYtcCNa0 > SjMekda2ubCVf+gbjjYbxidtlOra+VRtJyQCMi0xG4IKYrwlc2h7KA== > =ag/A > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From matt at coders.co.uk Tue Jan 17 10:17:42 2006 From: matt at coders.co.uk (Matt Hampton) Date: Tue Jan 17 10:19:06 2006 Subject: Dropping spam into a different a custom mailbox In-Reply-To: <814064980601170145x42914300y3c23f45e910aa67f@mail.gmail.com> References: <814064980601170111r23b50c81s6466e9d9f9a33ac2@mail.gmail.com> <7E70D91B-F777-4DA9-9054-7B6C41969590@ecs.soton.ac.uk> <814064980601170145x42914300y3c23f45e910aa67f@mail.gmail.com> Message-ID: <43CCC446.70800@coders.co.uk> Amir Sela wrote: > First of all, thanks for the reply. > The problem is that if I define postfix to use procmail, it simply > doesn't deliver mail. > And since this is a MailScanner specific problem, since it uses > postfix, I thought someone > here might give me an exact idea on how this is done when using > postfix with mailscanner. > It's not on the postfix docs because it's a MailScanner issue, and > here I get "this is not a Mailscanner issue", and I'm kind of stuck > because there are no docs on how this is done. > Thanks again, > -Amir > Amir Even though MailScanner "doesn't use postfix in the proper way" it is not involved in the delivery of mail to the mailboxes of your users. Here is a document that explains how to set up procmail with postfix http://ccfaq.valar.co.uk/modules.php?name=News&file=article&sid=245 This has basically everything you need matt From glenn.steen at gmail.com Tue Jan 17 10:45:31 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue Jan 17 10:45:36 2006 Subject: Dropping spam into a different a custom mailbox In-Reply-To: <43CCC446.70800@coders.co.uk> References: <814064980601170111r23b50c81s6466e9d9f9a33ac2@mail.gmail.com> <7E70D91B-F777-4DA9-9054-7B6C41969590@ecs.soton.ac.uk> <814064980601170145x42914300y3c23f45e910aa67f@mail.gmail.com> <43CCC446.70800@coders.co.uk> Message-ID: <223f97700601170245i127196bbu@mail.gmail.com> On 17/01/06, Matt Hampton wrote: > Amir Sela wrote: > > First of all, thanks for the reply. > > The problem is that if I define postfix to use procmail, it simply > > doesn't deliver mail. > > And since this is a MailScanner specific problem, since it uses > > postfix, I thought someone > > here might give me an exact idea on how this is done when using > > postfix with mailscanner. > > It's not on the postfix docs because it's a MailScanner issue, and > > here I get "this is not a Mailscanner issue", and I'm kind of stuck > > because there are no docs on how this is done. > > Thanks again, > > -Amir > > > > Amir > > Even though MailScanner "doesn't use postfix in the proper way" it is > not involved in the delivery of mail to the mailboxes of your users. > > Here is a document that explains how to set up procmail with postfix > > http://ccfaq.valar.co.uk/modules.php?name=News&file=article&sid=245 > > This has basically everything you need > > matt CC Matt. One might also note that at least some distros of linux will have procmail configured for postfix by default (for example Mandriva/Mandrake has had it like that for quite some time). So in that case it is just a matter of making a reasonable /etc/procmailrc (or more likely a per user setup). Amir, when you say that you don't get anything delivered when using procmail, might it be that you had a bum setup for procmail/thatuser? Or could you see in the maillog that "everything borked out" (no hand-off to the local delivery)? -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Tue Jan 17 16:30:15 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue Jan 17 16:30:19 2006 Subject: Fwd: MS gateway checking for valid users before delivery In-Reply-To: <223f97700601170224t5b4a98c6s@mail.gmail.com> References: <200512281855.57658@cs.axint.net> <43B3003B.B662.0038.0@tac.esi.net> <43B36A2D.8030302@enitech.com.au> <223f97700512282121p4acadb85x@mail.gmail.com> <223f97700512282126w6ac0f74bn@mail.gmail.com> <43B3F5EB.1080107@enitech.com.au> <223f97700601170224t5b4a98c6s@mail.gmail.com> Message-ID: <223f97700601170830r4de21c3bo@mail.gmail.com> And now to the (new) list..... Sigh, didn't even pause to think about it...:-) ---------- Forwarded message ---------- From: Glenn Steen Date: 17-Jan-2006 11:24 Subject: Re: MS gateway checking for valid users before delivery To: MailScanner mailing list On 29/12/05, Pete Russell wrote: > Hmmm - buggar. Those files are now lost, i didnt grab them when i moved > hosts. I will clean up the ones i use at work and put them back in the > wiki - next week when i return from hols. > > IN the meantime do you want me to em ail the exhcnage one to you Erick? > > Pete > Hi Pete, Just a prod... Could you please put 'em in? Perhaps you could just upload them to the wiki page (not cut'n'past:-). -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From mkettler at evi-inc.com Tue Jan 17 16:54:26 2006 From: mkettler at evi-inc.com (Matt Kettler) Date: Tue Jan 17 16:54:36 2006 Subject: dccfid performance improvement? In-Reply-To: References: <028e01c61b03$432cd020$2f01a8c0@Fajar> Message-ID: <43CD2142.5090809@evi-inc.com> Ugo Bellavance wrote: > Fajar wrote: > >>One of the suggestion to tune mailscanner by using dccfid, i'm already >>setup the dcc, and from spamasassin --list seems the dcc workingfine, i >>saw some connection made from my computer to some host with destination >>port 6277. > > > Ok, how is that related to the subject of your post? Because dccifd is the other way of handling DCC. Fajar is apparently pointing out DCC is currently working. I assume that the subject implies that Fajar is wondering what benefit there is to adding dccifd, over just plain dcc (which uses dccproc). Fajar, there's some modest improvement to enabling dccifd. Normally to do a DCC lookup SpamAssassin invokes dccproc as a new process. However, if dccifd is running, it will simply pass the message off to dccifd over a socket, without having to create a new process. I would say the speed gains are marginal, but then again it doesn't really cost you anything other than a little ram. (My dccifd has a RSS of 1368 K) If you run spamassassin --lint -D the debug output will let you see SA checking for the dccifd socket, and see if it used dccifd or dccproc. From gmatt at nerc.ac.uk Tue Jan 17 17:15:19 2006 From: gmatt at nerc.ac.uk (Greg Matthews) Date: Tue Jan 17 17:15:26 2006 Subject: OT: signature protocol Message-ID: <1137518119.30908.114.camel@lea.nerc-wallingford.ac.uk> I have a 2 line personal signature which you can see on the end of this message. I'm also testing our corporate signature that I've been asked to implement which you should also see after my personal one. My question is, should the corporate sig have the initial '--' as in the default inline.sig.{txt,html} files? Not everyone will have a personal sig so perhaps it should be left in? GREG -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford NERC is subject to the Freedom of Information Act 2000 and the contents of this email and any reply you make may be disclosed by NERC unless it is exempt from release under the Act. Any material supplied to NERC may be stored in an electronic records management system. If you are providing attachments, please confirm that you are legally authorised to pass them to us. From martinh at solid-state-logic.com Tue Jan 17 17:23:50 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Tue Jan 17 17:23:57 2006 Subject: signature protocol In-Reply-To: <1137518119.30908.114.camel@lea.nerc-wallingford.ac.uk> Message-ID: <001301c61b8a$c8920f50$3004010a@martinhlaptop> Greg I'd say yes add in the -- if not everyone has a personal signature -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Greg Matthews > Sent: 17 January 2006 17:15 > To: MailScanner discussion > Subject: OT: signature protocol > > I have a 2 line personal signature which you can see on the end of this > message. I'm also testing our corporate signature that I've been asked > to implement which you should also see after my personal one. > > My question is, should the corporate sig have the initial '--' as in the > default inline.sig.{txt,html} files? > > Not everyone will have a personal sig so perhaps it should be left in? > > GREG > -- > Greg Matthews 01491 692445 > Head of UNIX/Linux, iTSS Wallingford > > > > NERC is subject to the Freedom of Information Act 2000 and the > contents of this email and any reply you make may be disclosed by NERC > unless it is exempt from release under the Act. Any material supplied > to NERC may be stored in an electronic records management system. If > you are providing attachments, please confirm that you are legally > authorised to pass them to us. > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From gmatt at nerc.ac.uk Tue Jan 17 17:35:53 2006 From: gmatt at nerc.ac.uk (Greg Matthews) Date: Tue Jan 17 17:36:00 2006 Subject: signature protocol In-Reply-To: <001301c61b8a$c8920f50$3004010a@martinhlaptop> References: <001301c61b8a$c8920f50$3004010a@martinhlaptop> Message-ID: <1137519353.30908.127.camel@lea.nerc-wallingford.ac.uk> On Tue, 2006-01-17 at 17:23 +0000, Martin Hepworth wrote: > Greg > > I'd say yes add in the -- if not everyone has a personal signature I realise of course that the mailscanner list also adds its own sig with the "--" Thanks for the advice/opinion Martin, must try to get to another oxlug meeting! G -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford -- NERC is subject to the Freedom of Information Act 2000 and the contents of this email and any reply you make may be disclosed by NERC unless it is exempt from release under the Act. Any material supplied to NERC may be stored in an electronic records management system. If you are providing attachments, please confirm that you are legally authorised to pass them to us. From Andrea.bazzanini at premiereglobal.it Tue Jan 17 18:37:21 2006 From: Andrea.bazzanini at premiereglobal.it (Andrea) Date: Tue Jan 17 17:36:18 2006 Subject: Test Message Message-ID: <1137523042.32667.50.camel@digimon.xpedite.co.uk> Test Message !! Pls ignore me !! AndreA -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060117/c13bd187/attachment.html From MailScanner at ecs.soton.ac.uk Tue Jan 17 17:36:52 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Jan 17 17:36:56 2006 Subject: OT: signature protocol In-Reply-To: <1137518119.30908.114.camel@lea.nerc-wallingford.ac.uk> References: <1137518119.30908.114.camel@lea.nerc-wallingford.ac.uk> Message-ID: <43CD2B34.4050008@ecs.soton.ac.uk> The official signature separator isn't '--' but '-- ' i.e. dash dash space. You don't need to start the corporate one with --, but I think it looks better. Notice that this reply has had your sig stripped off, this is done automatically by Thunderbird now. It has stripped the whole sig, not just the first one. Greg Matthews wrote: > I have a 2 line personal signature which you can see on the end of this > message. I'm also testing our corporate signature that I've been asked > to implement which you should also see after my personal one. > > My question is, should the corporate sig have the initial '--' as in the > default inline.sig.{txt,html} files? > > Not everyone will have a personal sig so perhaps it should be left in? > > GREG > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From martinh at solid-state-logic.com Tue Jan 17 17:45:11 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Tue Jan 17 17:45:20 2006 Subject: signature protocol In-Reply-To: <1137519353.30908.127.camel@lea.nerc-wallingford.ac.uk> Message-ID: <002801c61b8d$c39a5d10$3004010a@martinhlaptop> Must try and make an oxlug meeting and not just the email list/irc ;-) -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Greg Matthews > Sent: 17 January 2006 17:36 > To: MailScanner discussion > Subject: RE: signature protocol > > On Tue, 2006-01-17 at 17:23 +0000, Martin Hepworth wrote: > > Greg > > > > I'd say yes add in the -- if not everyone has a personal signature > > I realise of course that the mailscanner list also adds its own sig with > the "--" > > Thanks for the advice/opinion Martin, must try to get to another oxlug > meeting! > > G > > -- > Greg Matthews 01491 692445 > Head of UNIX/Linux, iTSS Wallingford > > > -- > NERC is subject to the Freedom of Information Act 2000 and the > contents of this email and any reply you make may be disclosed by NERC > unless it is exempt from release under the Act. Any material supplied > to NERC may be stored in an electronic records management system. If > you are providing attachments, please confirm that you are legally > authorised to pass them to us. > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From gdoris at rogers.com Tue Jan 17 22:05:29 2006 From: gdoris at rogers.com (Gerry Doris) Date: Tue Jan 17 22:06:00 2006 Subject: favicon.ico is missing??? Message-ID: <1137535529.6572.4.camel@jaguar.dorfam.ca> I have been seeing large numbers of httpd errors in the ssl_access_errors logs. These seem to indicate that a file called favicon.ico is not being found and appear to be occurring when MailScanner is being accessed. I've located this file (or one by the same name) in several locations but none of them have anything to do with MailScanner. Is favicon.ico used by MailScanner or MailWatch??? From penguin at dhcp.net Tue Jan 17 22:15:01 2006 From: penguin at dhcp.net (A. Eijkhoudt) Date: Tue Jan 17 22:15:15 2006 Subject: favicon.ico is missing??? In-Reply-To: <1137535529.6572.4.camel@jaguar.dorfam.ca> References: <1137535529.6572.4.camel@jaguar.dorfam.ca> Message-ID: On Tue, 17 Jan 2006, Gerry Doris wrote: > Is favicon.ico used by MailScanner or MailWatch??? What you're seeing is people using Internet Explorer and/or Firefox accessing the webserver on your machine. It's the neat little icon that appears in the address bar next to the URL. It has nothing to do with MailScanner or MailWatch, therefore ;) Kind regards, A. Eijkhoudt -- This message has been scanned for viruses and dangerous HTML content by Valethosting. Dit bericht is gecontroleerd op virussen en gevaarlijke HTML door Valethosting's MailScanner. From naolson at gmail.com Tue Jan 17 22:16:40 2006 From: naolson at gmail.com (Nathan Olson) Date: Tue Jan 17 22:16:46 2006 Subject: favicon.ico is missing??? In-Reply-To: <1137535529.6572.4.camel@jaguar.dorfam.ca> References: <1137535529.6572.4.camel@jaguar.dorfam.ca> Message-ID: <8f54b4330601171416v69e3512fvadd7505d59f779e5@mail.gmail.com> Many browsers request it. It's the little picture to the left of the URL in the "location bar". Nate From mkettler at evi-inc.com Tue Jan 17 22:17:24 2006 From: mkettler at evi-inc.com (Matt Kettler) Date: Tue Jan 17 22:17:31 2006 Subject: favicon.ico is missing??? In-Reply-To: <1137535529.6572.4.camel@jaguar.dorfam.ca> References: <1137535529.6572.4.camel@jaguar.dorfam.ca> Message-ID: <43CD6CF4.6060306@evi-inc.com> Gerry Doris wrote: > I have been seeing large numbers of httpd errors in the > ssl_access_errors logs. > > These seem to indicate that a file called favicon.ico is not being found > and appear to be occurring when MailScanner is being accessed. I've > located this file (or one by the same name) in several locations but > none of them have anything to do with MailScanner. > > Is favicon.ico used by MailScanner or MailWatch??? No, it's used by browsers.. Pretty much every modern browser will request this file off a website when connecting. It's used to create those custom icons in your bookmarks/favorites list. You can ignore the errors, or create an icon file to put there. From james at grayonline.id.au Tue Jan 17 23:10:10 2006 From: james at grayonline.id.au (James Gray) Date: Tue Jan 17 23:10:43 2006 Subject: favicon.ico is missing??? In-Reply-To: <43CD6CF4.6060306@evi-inc.com> References: <1137535529.6572.4.camel@jaguar.dorfam.ca> <43CD6CF4.6060306@evi-inc.com> Message-ID: <200601181010.14170.james@grayonline.id.au> On Wed, 18 Jan 2006 09:17, Matt Kettler wrote: > Gerry Doris wrote: > > I have been seeing large numbers of httpd errors in the > > ssl_access_errors logs. > > > > These seem to indicate that a file called favicon.ico is not being > > found and appear to be occurring when MailScanner is being accessed. > > I've located this file (or one by the same name) in several locations > > but none of them have anything to do with MailScanner. > > > > Is favicon.ico used by MailScanner or MailWatch??? > > No, it's used by browsers.. Pretty much every modern browser will request > this file off a website when connecting. > > It's used to create those custom icons in your bookmarks/favorites list. > > You can ignore the errors, or create an icon file to put there. Or to change the 404 error into a 200 response, simply "touch favicon.ico" in the document root. That will serve up a zero-length file to the browser :) James -- Freedom is what you do with what's been done to you. -- Jean-Paul Sartre -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060118/59a704af/attachment.bin From gdoris at rogers.com Tue Jan 17 23:10:13 2006 From: gdoris at rogers.com (Gerry Doris) Date: Tue Jan 17 23:10:48 2006 Subject: favicon.ico is missing??? In-Reply-To: <43CD6CF4.6060306@evi-inc.com> References: <1137535529.6572.4.camel@jaguar.dorfam.ca> <43CD6CF4.6060306@evi-inc.com> Message-ID: <1137539413.4381.6.camel@jaguar.dorfam.ca> On Tue, 2006-01-17 at 17:17 -0500, Matt Kettler wrote: > Gerry Doris wrote: > > I have been seeing large numbers of httpd errors in the > > ssl_access_errors logs. > > > > These seem to indicate that a file called favicon.ico is not being found > > and appear to be occurring when MailScanner is being accessed. I've > > located this file (or one by the same name) in several locations but > > none of them have anything to do with MailScanner. > > > > Is favicon.ico used by MailScanner or MailWatch??? > > No, it's used by browsers.. Pretty much every modern browser will request this > file off a website when connecting. > > It's used to create those custom icons in your bookmarks/favorites list. > > You can ignore the errors, or create an icon file to put there. OK, I pulled a favicon.ico file from the Apache manual directory and now when I connect to using MailWatch I get a cute little Apache feather! However, I was hoping that this file would fix my real problem and it didn't. I use MailWatch and I've just noticed that I am no longer able to view a message. I used to be able to click the little box on the far left, a detail window with the header + lots of good stuff would appear. This still happens but I'm missing the ability at the bottom of this screen to click on the message id to view the message. There is nothing there??? I was wondering if this has resulted from using Julian's new beta so I reloaded the last stable release. That didn't fix the problem. From gdoris at rogers.com Tue Jan 17 23:28:55 2006 From: gdoris at rogers.com (Gerry Doris) Date: Tue Jan 17 23:29:20 2006 Subject: favicon.ico is missing??? In-Reply-To: <1137539413.4381.6.camel@jaguar.dorfam.ca> References: <1137535529.6572.4.camel@jaguar.dorfam.ca> <43CD6CF4.6060306@evi-inc.com> <1137539413.4381.6.camel@jaguar.dorfam.ca> Message-ID: <1137540536.4381.8.camel@jaguar.dorfam.ca> On Tue, 2006-01-17 at 18:10 -0500, Gerry Doris wrote: > > OK, I pulled a favicon.ico file from the Apache manual directory and now > when I connect to using MailWatch I get a cute little Apache feather! > However, I was hoping that this file would fix my real problem and it > didn't. > > I use MailWatch and I've just noticed that I am no longer able to view a > message. I used to be able to click the little box on the far left, a > detail window with the header + lots of good stuff would appear. This > still happens but I'm missing the ability at the bottom of this screen > to click on the message id to view the message. There is nothing > there??? > > I was wondering if this has resulted from using Julian's new beta so I > reloaded the last stable release. That didn't fix the problem. I hate to answer my own email but I found the problem. I don't like the date format used in MailWatch so I made some changes...badly. I have since noticed the typo and everything is working again. From jon.bates at summitmotors.com.au Wed Jan 18 01:12:35 2006 From: jon.bates at summitmotors.com.au (Jon Bates) Date: Wed Jan 18 01:12:42 2006 Subject: (no subject) Message-ID: <007501c61bcc$43eb24c0$0e64a8c0@jonlaptop> help Jon Bates PC Support Technician Summit Investment Australia Pty Ltd E-mail: jon.bates@summitmotors.com.au Phone: (02) 8846-1292 Mobile: 0400-381-030 020 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060118/54ba45ca/attachment.html From naolson at gmail.com Wed Jan 18 01:27:16 2006 From: naolson at gmail.com (Nathan Olson) Date: Wed Jan 18 01:27:19 2006 Subject: (no subject) In-Reply-To: <007501c61bcc$43eb24c0$0e64a8c0@jonlaptop> References: <007501c61bcc$43eb24c0$0e64a8c0@jonlaptop> Message-ID: <8f54b4330601171727w7b2e0127lf9030dd8e5b00d74@mail.gmail.com> On 1/17/06, Jon Bates wrote: > help me Rhonda? Nate From doc at maddoc.net Wed Jan 18 03:46:12 2006 From: doc at maddoc.net (Doc Schneider) Date: Wed Jan 18 03:46:19 2006 Subject: (no subject) In-Reply-To: <8f54b4330601171727w7b2e0127lf9030dd8e5b00d74@mail.gmail.com> References: <007501c61bcc$43eb24c0$0e64a8c0@jonlaptop> <8f54b4330601171727w7b2e0127lf9030dd8e5b00d74@mail.gmail.com> Message-ID: <43CDBA04.5080009@maddoc.net> Nathan Olson wrote: > On 1/17/06, Jon Bates wrote: >> help > > me Rhonda? > > Nate I love the Beach Boys! (GASP -- Showing my age again!) -- -Doc Lincoln, NE. From glenn.steen at gmail.com Wed Jan 18 08:30:10 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Jan 18 08:30:16 2006 Subject: (no subject) In-Reply-To: <007501c61bcc$43eb24c0$0e64a8c0@jonlaptop> References: <007501c61bcc$43eb24c0$0e64a8c0@jonlaptop> Message-ID: <223f97700601180030s49f60503r@mail.gmail.com> On 18/01/06, Jon Bates wrote: > > help > > > > > > Jon Bates > PC Support Technician > Summit Investment Australia Pty Ltd > E-mail: jon.bates@summitmotors.com.au Phone: (02) 8846-1292 > Mobile: 0400-381-030 020 > Ahem, Jon .... You are aware that most sensible people (like the subscribers to this list) won't look at the HTML fun you've had with your .sig .... They simply don't trust HTML in emails... (I'm one of those, but just had to look at this one:-) That has the result that your plain-text message looks pretty .... stoopid;) Anyone remember the fun one used to have with the .plan and .project? Many many years ago, I remember that "fingering" people would either give you a nice (ascii art) biplane going by, or giving you the finger (also in ascii art)... Ah VAX 11/7XX and BSD... Those were the days.... Not (this reminiscence is your fault Doc... got me thinking of times gone by:-) -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From Dirk.Heuvels at inovasec.de Mon Jan 16 20:14:11 2006 From: Dirk.Heuvels at inovasec.de (Dirk.Heuvels@inovasec.de) Date: Wed Jan 18 08:47:42 2006 Subject: Saving public keys from email messages Message-ID: Hi there. There is a powerpoint presentation on the net called julianfield.ppt, that says it would be possible to save public keys from email messages with mailscanner to deploy email encryption. Apart from the saving-the-keys part. Is this a mailscanner feature or does it just mean, that it might be implementet using a &function hook in the mailscanner.conf? Thanks in advance, Dirk -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060116/39b75149/attachment.html From vaughn at solarword.net Wed Jan 18 03:09:42 2006 From: vaughn at solarword.net (Vaughn Skinner) Date: Wed Jan 18 08:47:45 2006 Subject: Faster MailScanner Message-ID: <200601171909.43051.vaughn@bluemtnet.com> Kudos to Julian for the faster mailscanner. Thank you very much. I have a small patch for 4.50.8-2 which ignores directories in the CustomFunctions directory. This prevents my RCS directory from generating lots of log messages. Vaughn -------------- next part -------------- A non-text attachment was scrubbed... Name: Config.pm-diff Type: text/x-diff Size: 685 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060117/8f8d427b/Config.bin From mailscanner at mango.zw Wed Jan 18 09:19:58 2006 From: mailscanner at mango.zw (Jim Holland) Date: Wed Jan 18 09:21:38 2006 Subject: Worm.VB-8 not detected by filename or filetype Message-ID: Hi Julian This morning I noticed that we were being bombarded with mail from one particular yahoo.it address with file attachments having names such as: Attachments00.HQX Original_Message.B64 Video_part.mim Word_Document.hqx Word_Document.uu 392315089702606E02.UUE eBook.Uu The files are all of approximately 134 000 bytes, and consist of uuencoded text, with headers such as: begin 664 392315089702606E-02,UUE .scR or begin 664 Attachments,zip .SCR The extracted files are identified by ClamAV as being infected with Worm.VB-8, but the actual uuencoded attachment is just regarded by ClamAV as being plain text and so does not get flagged as a virus. The problem therefore is that the messages themselves are still getting through. For the moment I am blocking the following extensions: .bhx .b64 .hqx .uu .uue I presume that a user would have to manually decode these files before running the executable within, so infection is not likely to be very common. However in our case we are finding the sheer volume a problem, so are blocking the identified senders at MTA level. Can you see a way that scanning of such attachments can be forced? I see that "file -i" reports these attachments as being plain text, but "file" reports them correctly as "uuencoded or xxencoded text". Regards Jim Holland System Administrator MANGO - Zimbabwe's non-profit e-mail service From MailScanner at ecs.soton.ac.uk Wed Jan 18 09:22:26 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Jan 18 09:22:38 2006 Subject: Saving public keys from email messages In-Reply-To: References: Message-ID: <10C29953-AE37-4D5A-8C31-5209508D0130@ecs.soton.ac.uk> Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: PGP.sig Type: application/pgp-signature Size: 487 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060118/f4259582/PGP.bin From MailScanner at ecs.soton.ac.uk Wed Jan 18 09:27:19 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Jan 18 09:27:29 2006 Subject: Faster MailScanner In-Reply-To: <200601171909.43051.vaughn@bluemtnet.com> References: <200601171909.43051.vaughn@bluemtnet.com> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Unless the directory name ends in .pm or .pl it should be ignored anyway. On 18 Jan 2006, at 03:09, Vaughn Skinner wrote: > Kudos to Julian for the faster mailscanner. Thank you very much. > > I have a small patch for 4.50.8-2 which ignores directories in the > CustomFunctions directory. This prevents my RCS directory from > generating > lots of log messages. > > Vaughn > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ84J+fw32o+k+q+hAQFWOQf+Nuf3+TCoY8FM4vHucMKGCzLzj7tsZA8j Kd6AIrJ7/L0nEO2SAEyhkrr85RfrpBTwjOkExJf354lt0Ym2AIrU0glP63zukVmI O0FoUz6S3oglsDuiO5iXVzKY7mqxITKn/bRkgXqZa6tgOzNkUR6iCU2Mqqv2C0ZD LNZnjTfz4PsoE/txIUsjoWTdJZta4t0SAm8yWH7KmRPdyyDUrx5guV++qq8qhlrS H5OJgQQyqbGOfnyIgJXwvdENLxsmew2lFQyuZmATCqJuKU2zWVZrww3f4f/YN3Xd u5PlRSrZ1LS6qLw52UF/B4KuPPnSp3mEo7IwDxRbl8f0H+eDCNwWLQ== =Qvkb -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From martinh at solid-state-logic.com Wed Jan 18 09:29:28 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Wed Jan 18 09:29:37 2006 Subject: Worm.VB-8 not detected by filename or filetype In-Reply-To: Message-ID: <004b01c61c11$ae4d4880$3004010a@martinhlaptop> Jim Another user identified this problem last night on the IRC channel. Looks like the problem is with MIME::Tools perl module. Julian has contacted the maintainer of this module in order to get to fix. In the mean time you might want to see if virustotal.com's list of scanners give any results. When I tried last night with the example given (was a uuencoded .hqx file) clamav and some others didn't spot it either. From memory Sophos, F-prot, Kapersky and a couple of others did... -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Jim Holland > Sent: 18 January 2006 09:20 > To: MailScanner mailing list > Subject: Worm.VB-8 not detected by filename or filetype > > Hi Julian > > This morning I noticed that we were being bombarded with mail from one > particular yahoo.it address with file attachments having names such as: > > Attachments00.HQX > Original_Message.B64 > Video_part.mim > Word_Document.hqx > Word_Document.uu > 392315089702606E02.UUE > eBook.Uu > > The files are all of approximately 134 000 bytes, and consist of uuencoded > text, with headers such as: > > begin 664 392315089702606E-02,UUE .scR > or > begin 664 Attachments,zip .SCR > > The extracted files are identified by ClamAV as being infected with > Worm.VB-8, but the actual uuencoded attachment is just regarded by ClamAV > as being plain text and so does not get flagged as a virus. > > The problem therefore is that the messages themselves are still getting > through. For the moment I am blocking the following extensions: > > .bhx > .b64 > .hqx > .uu > .uue > > I presume that a user would have to manually decode these files before > running the executable within, so infection is not likely to be very > common. However in our case we are finding the sheer volume a problem, so > are blocking the identified senders at MTA level. > > Can you see a way that scanning of such attachments can be forced? > > I see that "file -i" reports these attachments as being plain text, but > "file" reports them correctly as "uuencoded or xxencoded text". > > Regards > > Jim Holland > System Administrator > MANGO - Zimbabwe's non-profit e-mail service > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From a.peacock at chime.ucl.ac.uk Wed Jan 18 09:29:38 2006 From: a.peacock at chime.ucl.ac.uk (Anthony Peacock) Date: Wed Jan 18 09:29:45 2006 Subject: Worm.VB-8 not detected by filename or filetype In-Reply-To: References: Message-ID: <43CE0A82.9010705@chime.ucl.ac.uk> Hi, Jim Holland wrote: > Hi Julian > > This morning I noticed that we were being bombarded with mail from one > particular yahoo.it address with file attachments having names such as: > > Attachments00.HQX > Original_Message.B64 > Video_part.mim > Word_Document.hqx > Word_Document.uu > 392315089702606E02.UUE > eBook.Uu > > The files are all of approximately 134 000 bytes, and consist of uuencoded > text, with headers such as: > > begin 664 392315089702606E-02,UUE .scR > or > begin 664 Attachments,zip .SCR > > The extracted files are identified by ClamAV as being infected with > Worm.VB-8, but the actual uuencoded attachment is just regarded by ClamAV > as being plain text and so does not get flagged as a virus. > > The problem therefore is that the messages themselves are still getting > through. For the moment I am blocking the following extensions: > > .bhx > .b64 > .hqx > .uu > .uue > > I presume that a user would have to manually decode these files before > running the executable within, so infection is not likely to be very > common. However in our case we are finding the sheer volume a problem, so > are blocking the identified senders at MTA level. > > Can you see a way that scanning of such attachments can be forced? > > I see that "file -i" reports these attachments as being plain text, but > "file" reports them correctly as "uuencoded or xxencoded text". > > Regards > > Jim Holland > System Administrator > MANGO - Zimbabwe's non-profit e-mail service > I know this doesn't help you in your situation, but Sophos is correctly detecting these files for me. I also use ClamAV and that does not yet detect these files. -- Anthony Peacock CHIME, Royal Free & University College Medical School WWW: http://www.chime.ucl.ac.uk/~rmhiajp/ "The most exciting phrase to hear in science, the one that heralds new discoveries, is not 'Eureka!' but 'That's funny....'" -- Isaac Asimov From dhawal at netmagicsolutions.com Wed Jan 18 09:38:42 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Wed Jan 18 09:38:45 2006 Subject: Worm.VB-8 not detected by filename or filetype In-Reply-To: <004b01c61c11$ae4d4880$3004010a@martinhlaptop> References: <004b01c61c11$ae4d4880$3004010a@martinhlaptop> Message-ID: <43CE0CA2.6090805@netmagicsolutions.com> Martin Hepworth wrote: > Jim > > Another user identified this problem last night on the IRC channel. > > Looks like the problem is with MIME::Tools perl module. Julian has contacted > the maintainer of this module in order to get to fix. > > In the mean time you might want to see if virustotal.com's list of scanners > give any results. When I tried last night with the example given (was a > uuencoded .hqx file) clamav and some others didn't spot it either. From > memory Sophos, F-prot, Kapersky and a couple of others did... Bitdefender and mcafee's uvscan seem to catch them well enough. McAfee: W32/Generic.worm!p2p virus Bitdefender: Win32.Worm.P2P.ABM ClamAV doesn't catch them all. - dhawal > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Jim Holland >> Sent: 18 January 2006 09:20 >> To: MailScanner mailing list >> Subject: Worm.VB-8 not detected by filename or filetype >> >> Hi Julian >> >> This morning I noticed that we were being bombarded with mail from one >> particular yahoo.it address with file attachments having names such as: >> >> Attachments00.HQX >> Original_Message.B64 >> Video_part.mim >> Word_Document.hqx >> Word_Document.uu >> 392315089702606E02.UUE >> eBook.Uu >> >> The files are all of approximately 134 000 bytes, and consist of uuencoded >> text, with headers such as: >> >> begin 664 392315089702606E-02,UUE .scR >> or >> begin 664 Attachments,zip .SCR >> >> The extracted files are identified by ClamAV as being infected with >> Worm.VB-8, but the actual uuencoded attachment is just regarded by ClamAV >> as being plain text and so does not get flagged as a virus. >> >> The problem therefore is that the messages themselves are still getting >> through. For the moment I am blocking the following extensions: >> >> .bhx >> .b64 >> .hqx >> .uu >> .uue >> >> I presume that a user would have to manually decode these files before >> running the executable within, so infection is not likely to be very >> common. However in our case we are finding the sheer volume a problem, so >> are blocking the identified senders at MTA level. >> >> Can you see a way that scanning of such attachments can be forced? >> >> I see that "file -i" reports these attachments as being plain text, but >> "file" reports them correctly as "uuencoded or xxencoded text". >> >> Regards >> >> Jim Holland >> System Administrator >> MANGO - Zimbabwe's non-profit e-mail service >> >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > > ********************************************************************** > > This email and any files transmitted with it are confidential and > intended solely for the use of the individual or entity to whom they > are addressed. If you have received this email in error please notify > the system manager. > > This footnote confirms that this email message has been swept > for the presence of computer viruses and is believed to be clean. > > ********************************************************************** > From glenn.steen at gmail.com Wed Jan 18 09:46:47 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Jan 18 09:46:51 2006 Subject: Worm.VB-8 not detected by filename or filetype In-Reply-To: <43CE0CA2.6090805@netmagicsolutions.com> References: <004b01c61c11$ae4d4880$3004010a@martinhlaptop> <43CE0CA2.6090805@netmagicsolutions.com> Message-ID: <223f97700601180146k3ea7cb6ej@mail.gmail.com> On 18/01/06, Dhawal Doshy wrote: > Martin Hepworth wrote: > > Jim > > > > Another user identified this problem last night on the IRC channel. > > > > Looks like the problem is with MIME::Tools perl module. Julian has contacted > > the maintainer of this module in order to get to fix. > > > > In the mean time you might want to see if virustotal.com's list of scanners > > give any results. When I tried last night with the example given (was a > > uuencoded .hqx file) clamav and some others didn't spot it either. From > > memory Sophos, F-prot, Kapersky and a couple of others did... > > Bitdefender and mcafee's uvscan seem to catch them well enough. > > McAfee: W32/Generic.worm!p2p virus > Bitdefender: Win32.Worm.P2P.ABM > > ClamAV doesn't catch them all. > > - dhawal > Thank you Dahwal! This gave me a real scare... since I'm at home with my broken leg at least this week... And I don't really trust my collegues to do "the right thing" if something like this slips through... A really bad feeling to the stomoch there ... But since those two get them, I'm good. Phew. -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From MailScanner at ecs.soton.ac.uk Wed Jan 18 09:59:16 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Jan 18 09:59:27 2006 Subject: Worm.VB-8 not detected by filename or filetype In-Reply-To: <004b01c61c11$ae4d4880$3004010a@martinhlaptop> References: <004b01c61c11$ae4d4880$3004010a@martinhlaptop> Message-ID: <4DF34A0A-C8A3-42B5-9492-6E35EFDD5B83@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- The problem is not one of filenames or filetypes, nor any problem with the MIME-tools. That is working fine. MailScanner correctly extracts the ATTACHMENT.HQX or whatever it was called, no problem. The contents of the file is not HQX (Binhex) at all, it is uuencoded data. So trying to stop binhex files won't help you, that's a red herring. What happens if you set filetype.rules.conf to stop "uuencoded" or "xxencoded" attachments? I think this should work, I see no reason why it wouldn't. I would try not to block .hqx files by name as you may well upset some of your Mac users. I'll talk to David Skoll some more about possible resolutions for this problem. On 18 Jan 2006, at 09:29, Martin Hepworth wrote: > Jim > > Another user identified this problem last night on the IRC channel. > > Looks like the problem is with MIME::Tools perl module. Julian has > contacted > the maintainer of this module in order to get to fix. > > In the mean time you might want to see if virustotal.com's list of > scanners > give any results. When I tried last night with the example given > (was a > uuencoded .hqx file) clamav and some others didn't spot it either. > From > memory Sophos, F-prot, Kapersky and a couple of others did... > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Jim Holland >> Sent: 18 January 2006 09:20 >> To: MailScanner mailing list >> Subject: Worm.VB-8 not detected by filename or filetype >> >> Hi Julian >> >> This morning I noticed that we were being bombarded with mail from >> one >> particular yahoo.it address with file attachments having names >> such as: >> >> Attachments00.HQX >> Original_Message.B64 >> Video_part.mim >> Word_Document.hqx >> Word_Document.uu >> 392315089702606E02.UUE >> eBook.Uu >> >> The files are all of approximately 134 000 bytes, and consist of >> uuencoded >> text, with headers such as: >> >> begin 664 392315089702606E-02,UUE .scR >> or >> begin 664 Attachments,zip .SCR >> >> The extracted files are identified by ClamAV as being infected with >> Worm.VB-8, but the actual uuencoded attachment is just regarded by >> ClamAV >> as being plain text and so does not get flagged as a virus. >> >> The problem therefore is that the messages themselves are still >> getting >> through. For the moment I am blocking the following extensions: >> >> .bhx >> .b64 >> .hqx >> .uu >> .uue >> >> I presume that a user would have to manually decode these files >> before >> running the executable within, so infection is not likely to be very >> common. However in our case we are finding the sheer volume a >> problem, so >> are blocking the identified senders at MTA level. >> >> Can you see a way that scanning of such attachments can be forced? >> >> I see that "file -i" reports these attachments as being plain >> text, but >> "file" reports them correctly as "uuencoded or xxencoded text". >> >> Regards >> >> Jim Holland >> System Administrator >> MANGO - Zimbabwe's non-profit e-mail service >> >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > > ********************************************************************** > > This email and any files transmitted with it are confidential and > intended solely for the use of the individual or entity to whom they > are addressed. If you have received this email in error please notify > the system manager. > > This footnote confirms that this email message has been swept > for the presence of computer viruses and is believed to be clean. > > ********************************************************************** > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ84Rdvw32o+k+q+hAQHV5QgAjUHML/GG75hl/ykS3V1haNUeqkeqvF4Q UKO9FDRs4RTOi6HARYoHkqn1dMB/vWZaK+4nX8pCDJxmQ7DWCUPi9Lp6pxaVpnUK /kpwgqX0YmzahJn15UQp4HbfClK+PfRaK2dQi1VdPOAPZJtxp/3sMPxG9pnhEPC1 oTgbcXWFpP7DYaZ8J1Ke2A8XHyXBc3calNjg6hayGeYrhuAFGhoXiUljQCioeNYF djiN/1rshAVM+1A9VJS2r1+BklPMQO4y5ELISvXAe7sqc6O8Tbux/S0NESP4wGru 6hWc/uWaOyRpmEP1wpookZK0thguyzOPcw5iqrN6VT0t+/E/LIwCIw== =hGAE -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From mailscanner at mango.zw Wed Jan 18 10:09:25 2006 From: mailscanner at mango.zw (Jim Holland) Date: Wed Jan 18 10:13:21 2006 Subject: Worm.VB-8 not detected by filename or filetype In-Reply-To: <43CE0CA2.6090805@netmagicsolutions.com> Message-ID: Hi On Wed, 18 Jan 2006, Dhawal Doshy wrote: > Martin Hepworth wrote: > > Jim > > > > Another user identified this problem last night on the IRC channel. > > > > Looks like the problem is with MIME::Tools perl module. Julian has contacted > > the maintainer of this module in order to get to fix. > > > > In the mean time you might want to see if virustotal.com's list of scanners > > give any results. When I tried last night with the example given (was a > > uuencoded .hqx file) clamav and some others didn't spot it either. From > > memory Sophos, F-prot, Kapersky and a couple of others did... > > Bitdefender and mcafee's uvscan seem to catch them well enough. > > McAfee: W32/Generic.worm!p2p virus > Bitdefender: Win32.Worm.P2P.ABM > > ClamAV doesn't catch them all. This worm arrives in two forms. One form has an executable attachment which is immediately recognised by ClamAV as being the worm, and is being blocked successfully as a result. The other form sends the virus inside an attached text file. The text file is uuencoded, so ideally should be decoded before being presented to ClamAV for scanning. Then it would be recognised. However at the moment this form of the virus is not being caught by ClamAV. I also suspect that the other virus scanners are not catching the worm when it arrives in this form, so would like to warn those who are relying on McAfee and Bitdefender not to be complacent. My point is that we need to ask Julian if he can arrange for MailScanner to decode such attachments automatically, and then apply normal filename and filetype rules as well as sending them for virus scanning. Then we would have the usual protection even with new variants which were not recognised by their viral signatures. Regards Jim Holland System Administrator MANGO - Zimbabwe's non-profit e-mail service > - dhawal > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > >> -----Original Message----- > >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > >> bounces@lists.mailscanner.info] On Behalf Of Jim Holland > >> Sent: 18 January 2006 09:20 > >> To: MailScanner mailing list > >> Subject: Worm.VB-8 not detected by filename or filetype > >> > >> Hi Julian > >> > >> This morning I noticed that we were being bombarded with mail from one > >> particular yahoo.it address with file attachments having names such as: > >> > >> Attachments00.HQX > >> Original_Message.B64 > >> Video_part.mim > >> Word_Document.hqx > >> Word_Document.uu > >> 392315089702606E02.UUE > >> eBook.Uu > >> > >> The files are all of approximately 134 000 bytes, and consist of uuencoded > >> text, with headers such as: > >> > >> begin 664 392315089702606E-02,UUE .scR > >> or > >> begin 664 Attachments,zip .SCR > >> > >> The extracted files are identified by ClamAV as being infected with > >> Worm.VB-8, but the actual uuencoded attachment is just regarded by ClamAV > >> as being plain text and so does not get flagged as a virus. > >> > >> The problem therefore is that the messages themselves are still getting > >> through. For the moment I am blocking the following extensions: > >> > >> .bhx > >> .b64 > >> .hqx > >> .uu > >> .uue > >> > >> I presume that a user would have to manually decode these files before > >> running the executable within, so infection is not likely to be very > >> common. However in our case we are finding the sheer volume a problem, so > >> are blocking the identified senders at MTA level. > >> > >> Can you see a way that scanning of such attachments can be forced? > >> > >> I see that "file -i" reports these attachments as being plain text, but > >> "file" reports them correctly as "uuencoded or xxencoded text". > >> > >> Regards > >> > >> Jim Holland > >> System Administrator > >> MANGO - Zimbabwe's non-profit e-mail service > >> > >> -- > >> MailScanner mailing list > >> MailScanner@lists.mailscanner.info > >> http://lists.mailscanner.info/mailman/listinfo/mailscanner > >> > >> Before posting, read http://wiki.mailscanner.info/posting > >> > >> Support MailScanner development - buy the book off the website! > > > > > > ********************************************************************** > > > > This email and any files transmitted with it are confidential and > > intended solely for the use of the individual or entity to whom they > > are addressed. If you have received this email in error please notify > > the system manager. > > > > This footnote confirms that this email message has been swept > > for the presence of computer viruses and is believed to be clean. > > > > ********************************************************************** > > > > From a.peacock at chime.ucl.ac.uk Wed Jan 18 10:23:59 2006 From: a.peacock at chime.ucl.ac.uk (Anthony Peacock) Date: Wed Jan 18 10:24:04 2006 Subject: Worm.VB-8 not detected by filename or filetype In-Reply-To: References: Message-ID: <43CE173F.1080002@chime.ucl.ac.uk> Jim Holland wrote: > Hi > > On Wed, 18 Jan 2006, Dhawal Doshy wrote: > >> Martin Hepworth wrote: >>> Jim >>> >>> Another user identified this problem last night on the IRC channel. >>> >>> Looks like the problem is with MIME::Tools perl module. Julian has contacted >>> the maintainer of this module in order to get to fix. >>> >>> In the mean time you might want to see if virustotal.com's list of scanners >>> give any results. When I tried last night with the example given (was a >>> uuencoded .hqx file) clamav and some others didn't spot it either. From >>> memory Sophos, F-prot, Kapersky and a couple of others did... >> Bitdefender and mcafee's uvscan seem to catch them well enough. >> >> McAfee: W32/Generic.worm!p2p virus >> Bitdefender: Win32.Worm.P2P.ABM >> >> ClamAV doesn't catch them all. > > This worm arrives in two forms. One form has an executable attachment > which is immediately recognised by ClamAV as being the worm, and is being > blocked successfully as a result. The other form sends the virus inside > an attached text file. The text file is uuencoded, so ideally should be > decoded before being presented to ClamAV for scanning. Then it would be > recognised. However at the moment this form of the virus is not being > caught by ClamAV. I also suspect that the other virus scanners are not > catching the worm when it arrives in this form, so would like to warn > those who are relying on McAfee and Bitdefender not to be complacent. None of us should be complacent. However, Sophos is correctly detecting these viruses in their UUencoded incarnation. But see below... > My point is that we need to ask Julian if he can arrange for MailScanner > to decode such attachments automatically, and then apply normal filename > and filetype rules as well as sending them for virus scanning. Then we > would have the usual protection even with new variants which were not > recognised by their viral signatures. In the spirit of trying to trap at as many points as possible, I would agree that extending the extracting options in MailScanner to include UUE might also be a useful tool. We already have RAR and ZIP support. -- Anthony Peacock CHIME, Royal Free & University College Medical School WWW: http://www.chime.ucl.ac.uk/~rmhiajp/ "The most exciting phrase to hear in science, the one that heralds new discoveries, is not 'Eureka!' but 'That's funny....'" -- Isaac Asimov From mailscanner at mango.zw Wed Jan 18 10:37:44 2006 From: mailscanner at mango.zw (Jim Holland) Date: Wed Jan 18 10:41:26 2006 Subject: Worm.VB-8 not detected by filename or filetype In-Reply-To: <4DF34A0A-C8A3-42B5-9492-6E35EFDD5B83@ecs.soton.ac.uk> Message-ID: Hi Julian On Wed, 18 Jan 2006, Julian Field wrote: > The problem is not one of filenames or filetypes, nor any problem > with the MIME-tools. That is working fine. > > MailScanner correctly extracts the ATTACHMENT.HQX or whatever it was > called, no problem. The contents of the file is not HQX (Binhex) at > all, it is uuencoded data. So trying to stop binhex files won't help > you, that's a red herring. Agreed. I was simply working on the basis of the actual filenames that I saw being used by the worm, as I needed a quick fix to block further copies getting through. > What happens if you set filetype.rules.conf to stop "uuencoded" or > "xxencoded" attachments? I think this should work, I see no reason > why it wouldn't. I will also add this restriction - thanks for the suggestion. > I would try not to block .hqx files by name as you may well upset some > of your Mac users. > > I'll talk to David Skoll some more about possible resolutions for > this problem. I think the real solution is to apply the same principle to uuencoded attachments inside MIME base64 encoding that is currently applied to zip files - the encapsulation should be removed by extracting whatever is inside an attachment and the files that are finally extracted/decoded should then be tested for filename, filetype and also sent for virus scanning. More work I do appreciate . . . Regards Jim > On 18 Jan 2006, at 09:29, Martin Hepworth wrote: > > > Jim > > > > Another user identified this problem last night on the IRC channel. > > > > Looks like the problem is with MIME::Tools perl module. Julian has > > contacted > > the maintainer of this module in order to get to fix. > > > > In the mean time you might want to see if virustotal.com's list of > > scanners > > give any results. When I tried last night with the example given > > (was a > > uuencoded .hqx file) clamav and some others didn't spot it either. > > From > > memory Sophos, F-prot, Kapersky and a couple of others did... > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > >> -----Original Message----- > >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > >> bounces@lists.mailscanner.info] On Behalf Of Jim Holland > >> Sent: 18 January 2006 09:20 > >> To: MailScanner mailing list > >> Subject: Worm.VB-8 not detected by filename or filetype > >> > >> Hi Julian > >> > >> This morning I noticed that we were being bombarded with mail from > >> one > >> particular yahoo.it address with file attachments having names > >> such as: > >> > >> Attachments00.HQX > >> Original_Message.B64 > >> Video_part.mim > >> Word_Document.hqx > >> Word_Document.uu > >> 392315089702606E02.UUE > >> eBook.Uu > >> > >> The files are all of approximately 134 000 bytes, and consist of > >> uuencoded > >> text, with headers such as: > >> > >> begin 664 392315089702606E-02,UUE .scR > >> or > >> begin 664 Attachments,zip .SCR > >> > >> The extracted files are identified by ClamAV as being infected with > >> Worm.VB-8, but the actual uuencoded attachment is just regarded by > >> ClamAV > >> as being plain text and so does not get flagged as a virus. > >> > >> The problem therefore is that the messages themselves are still > >> getting > >> through. For the moment I am blocking the following extensions: > >> > >> .bhx > >> .b64 > >> .hqx > >> .uu > >> .uue > >> > >> I presume that a user would have to manually decode these files > >> before > >> running the executable within, so infection is not likely to be very > >> common. However in our case we are finding the sheer volume a > >> problem, so > >> are blocking the identified senders at MTA level. > >> > >> Can you see a way that scanning of such attachments can be forced? > >> > >> I see that "file -i" reports these attachments as being plain > >> text, but > >> "file" reports them correctly as "uuencoded or xxencoded text". > >> > >> Regards > >> > >> Jim Holland > >> System Administrator > >> MANGO - Zimbabwe's non-profit e-mail service > >> > >> -- > >> MailScanner mailing list > >> MailScanner@lists.mailscanner.info > >> http://lists.mailscanner.info/mailman/listinfo/mailscanner > >> > >> Before posting, read http://wiki.mailscanner.info/posting > >> > >> Support MailScanner development - buy the book off the website! > > > > > > ********************************************************************** > > > > This email and any files transmitted with it are confidential and > > intended solely for the use of the individual or entity to whom they > > are addressed. If you have received this email in error please notify > > the system manager. > > > > This footnote confirms that this email message has been swept > > for the presence of computer viruses and is believed to be clean. > > > > ********************************************************************** > > > > -- > > MailScanner mailing list > > MailScanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.4 (Build 4042) > > iQEVAwUBQ84Rdvw32o+k+q+hAQHV5QgAjUHML/GG75hl/ykS3V1haNUeqkeqvF4Q > UKO9FDRs4RTOi6HARYoHkqn1dMB/vWZaK+4nX8pCDJxmQ7DWCUPi9Lp6pxaVpnUK > /kpwgqX0YmzahJn15UQp4HbfClK+PfRaK2dQi1VdPOAPZJtxp/3sMPxG9pnhEPC1 > oTgbcXWFpP7DYaZ8J1Ke2A8XHyXBc3calNjg6hayGeYrhuAFGhoXiUljQCioeNYF > djiN/1rshAVM+1A9VJS2r1+BklPMQO4y5ELISvXAe7sqc6O8Tbux/S0NESP4wGru > 6hWc/uWaOyRpmEP1wpookZK0thguyzOPcw5iqrN6VT0t+/E/LIwCIw== > =hGAE > -----END PGP SIGNATURE----- > > Regards Jim Holland System Administrator MANGO - Zimbabwe's non-profit e-mail service From gmatt at nerc.ac.uk Wed Jan 18 13:17:19 2006 From: gmatt at nerc.ac.uk (Greg Matthews) Date: Wed Jan 18 13:17:30 2006 Subject: OT: signature protocol In-Reply-To: <43CD2B34.4050008@ecs.soton.ac.uk> References: <1137518119.30908.114.camel@lea.nerc-wallingford.ac.uk> <43CD2B34.4050008@ecs.soton.ac.uk> Message-ID: <1137590239.7668.26.camel@lea.nerc-wallingford.ac.uk> On Tue, 2006-01-17 at 17:36 +0000, Julian Field wrote: > The official signature separator isn't '--' but '-- ' i.e. dash dash space. ah ok. > You don't need to start the corporate one with --, but I think it looks > better. Notice that this reply has had your sig stripped off, this is > done automatically by Thunderbird now. It has stripped the whole sig, > not just the first one. oooh... shiny. I like that. G -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford -- NERC is subject to the Freedom of Information Act 2000 and the contents of this email and any reply you make may be disclosed by NERC unless it is exempt from release under the Act. Any material supplied to NERC may be stored in an electronic records management system. If you are providing attachments, please confirm that you are legally authorised to pass them to us. From dcmwai at pl.jaring.my Wed Jan 18 13:18:47 2006 From: dcmwai at pl.jaring.my (Chan Min Wai) Date: Wed Jan 18 13:21:20 2006 Subject: Worm.VB-8 not detected by filename or filetype In-Reply-To: References: Message-ID: <43CE4037.7030007@pl.jaring.my> Anyone can help me to stop this files.. I've try to include these but not success filename.rules.conf deny \.bhx$ Found possible filename hiding Worm VB-8 Dangerous attachment deny \.b64$ Found possible filename hiding Worm VB-8 Dangerous attachment deny \.hqx$ Found possible filename hiding Worm VB-8 Dangerous attachment deny \.uu$ Found possible filename hiding Worm VB-8 Dangerous attachment deny \.uue$ Found possible filename hiding Worm VB-8 Dangerous attachment filetype.rules.conf deny uuencoded - - Regards, Jim Holland ??: >Hi Julian > >This morning I noticed that we were being bombarded with mail from one >particular yahoo.it address with file attachments having names such as: > > Attachments00.HQX > Original_Message.B64 > Video_part.mim > Word_Document.hqx > Word_Document.uu > 392315089702606E02.UUE > eBook.Uu > >The files are all of approximately 134 000 bytes, and consist of uuencoded >text, with headers such as: > > begin 664 392315089702606E-02,UUE .scR >or > begin 664 Attachments,zip .SCR > >The extracted files are identified by ClamAV as being infected with >Worm.VB-8, but the actual uuencoded attachment is just regarded by ClamAV >as being plain text and so does not get flagged as a virus. > >The problem therefore is that the messages themselves are still getting >through. For the moment I am blocking the following extensions: > > .bhx > .b64 > .hqx > .uu > .uue > >I presume that a user would have to manually decode these files before >running the executable within, so infection is not likely to be very >common. However in our case we are finding the sheer volume a problem, so >are blocking the identified senders at MTA level. > >Can you see a way that scanning of such attachments can be forced? > >I see that "file -i" reports these attachments as being plain text, but >"file" reports them correctly as "uuencoded or xxencoded text". > >Regards > >Jim Holland >System Administrator >MANGO - Zimbabwe's non-profit e-mail service > > > From devi.sambamoorthy at inmail.tranquilmoney.com Wed Jan 18 13:30:23 2006 From: devi.sambamoorthy at inmail.tranquilmoney.com (Devi Sambamoorthy) Date: Wed Jan 18 13:30:43 2006 Subject: Worm.VB-8 not detected by filename or filetype In-Reply-To: <43CE4037.7030007@pl.jaring.my> References: <43CE4037.7030007@pl.jaring.my> Message-ID: please try deny \.bhx$ deny \.BHX$ -Devi (list - pls ignore my signature & confidentiality statement) On Wed, 18 Jan 2006, Chan Min Wai wrote: > Anyone can help me to stop this files.. > > I've try to include these but not success > filename.rules.conf > deny \.bhx$ Found possible filename hiding Worm VB-8 Dangerous attachment > deny \.b64$ Found possible filename hiding Worm VB-8 Dangerous attachment > deny \.hqx$ Found possible filename hiding Worm VB-8 Dangerous attachment > deny \.uu$ Found possible filename hiding Worm VB-8 Dangerous attachment > deny \.uue$ Found possible filename hiding Worm VB-8 Dangerous attachment > > > filetype.rules.conf > deny uuencoded - - > > Regards, > > > > Jim Holland ??: > >> Hi Julian >> >> This morning I noticed that we were being bombarded with mail from one >> particular yahoo.it address with file attachments having names such as: >> >> Attachments00.HQX >> Original_Message.B64 >> Video_part.mim >> Word_Document.hqx >> Word_Document.uu >> 392315089702606E02.UUE >> eBook.Uu >> >> The files are all of approximately 134 000 bytes, and consist of uuencoded >> text, with headers such as: >> >> begin 664 392315089702606E-02,UUE .scR >> or >> begin 664 Attachments,zip .SCR >> >> The extracted files are identified by ClamAV as being infected with >> Worm.VB-8, but the actual uuencoded attachment is just regarded by ClamAV >> as being plain text and so does not get flagged as a virus. >> >> The problem therefore is that the messages themselves are still getting >> through. For the moment I am blocking the following extensions: >> >> .bhx >> .b64 >> .hqx >> .uu >> .uue >> >> I presume that a user would have to manually decode these files before >> running the executable within, so infection is not likely to be very >> common. However in our case we are finding the sheer volume a problem, so >> are blocking the identified senders at MTA level. >> >> Can you see a way that scanning of such attachments can be forced? >> >> I see that "file -i" reports these attachments as being plain text, but >> "file" reports them correctly as "uuencoded or xxencoded text". >> >> Regards >> >> Jim Holland >> System Administrator >> MANGO - Zimbabwe's non-profit e-mail service >> >> >> > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > CONFIDENTIALITY NOTICE: This e-mail and its attachments may contain PRIVILEGED and CONFIDENTIAL INFORMATION and/or PROTECTED PATIENT HEALTH INFORMATION intended solely for the use of Tranquilmoney Inc. it's clients and the recipient(s) named above. If you are not the intended recipient, or the employee or agent responsible for delivering this message to the intended recipient, you are hereby notified that any review, dissemination, distribution, printing, or copying of this e-mail message and/or any attachments is strictly prohibited. If you have received this transmission in error, please notify the sender immediately and permanently delete this e-mail [shred the document] and any attachments. From dcmwai at pl.jaring.my Wed Jan 18 13:45:04 2006 From: dcmwai at pl.jaring.my (Chan Min Wai) Date: Wed Jan 18 13:47:20 2006 Subject: Worm.VB-8 not detected by filename or filetype In-Reply-To: References: <43CE4037.7030007@pl.jaring.my> Message-ID: <43CE4660.3040200@pl.jaring.my> Devi Sambamoorthy ??: > please try > > deny \.bhx$ > deny \.BHX$ > > -Devi I've got a sample of the files ... wan to try :) No it got pass :( From joshua.hirsh at partnersolutions.ca Wed Jan 18 14:11:18 2006 From: joshua.hirsh at partnersolutions.ca (Joshua Hirsh) Date: Wed Jan 18 14:11:22 2006 Subject: OT: Re: (no subject) Message-ID: > Anyone remember the fun one used to have with the .plan and .project? > Many many years ago, I remember that "fingering" people would either > give you a nice (ascii art) biplane going by, or giving you the finger > (also in ascii art)... Ah VAX 11/7XX and BSD... Those were the > days.... Not (this reminiscence is your fault Doc... got me thinking > of times gone by:-) Funny... I remember trying to explain how finger worked to my mom as a teen (she was looking over my shoulder and saw me type it). She then proceeded to ask me why I never fingered her before.. I don't talk computer lingo to her anymore. =p -Joshua From MailScanner at ecs.soton.ac.uk Wed Jan 18 14:19:05 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Jan 18 14:19:15 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: <43CE4660.3040200@pl.jaring.my> References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- I have just released 4.50.9 which will decode the UU-encoded file attached to these messages, so that the virus scanners should all catch it, filename traps will work on the .scr file inside the .bhx file, filetype traps will work on it too. On 18 Jan 2006, at 13:45, Chan Min Wai wrote: > Devi Sambamoorthy ??: > >> please try >> >> deny \.bhx$ >> deny \.BHX$ >> >> -Devi > > I've got a sample of the files ... wan to try :) > > No it got pass :( > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ85OXPw32o+k+q+hAQHqVAf/elgw5Jyz+e0tCsaw1k7eYhk4ARyMpviU EY4nd8c0K4drNBt3SiyaYNNJOktVwq7bYPzpC/xY0eKImWJt3XljPlIhlegvxyVy SnPD0pkLxD42ISB5gIIb5M9g9PY33VIjuxEj0Ukm6hZBZhIxs9N7BWVl997AIzEg E8wahou7lnuP5yjB5825zOk7CTzSGxEK1zKlo4eLv3s1u2VDU2z0kljWicp1vFpD ZXhQvuidRzwtMjda0bfxeFL2MofbBg1ISGFAbxfI8bVF7fwRV/+DrVLTNDTFKy86 awy8O0j6WEApm5mJwpdyGhMEglmjvxbpoThSRjKKCbcuK44pLK237g== =cV9I -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From dhawal at netmagicsolutions.com Wed Jan 18 15:10:45 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Wed Jan 18 15:10:49 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> Message-ID: <43CE5A75.1000000@netmagicsolutions.com> Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > I have just released 4.50.9 which will decode the UU-encoded file > attached to these messages, so that the virus scanners should all > catch it, filename traps will work on the .scr file inside the .bhx > file, filetype traps will work on it too. Just successfully upgraded a couple of production servers.. thankfully your beta standards are quite high (and a bit of testing on the previous betas also helped) A small error.. Attempting to build and install perl-MailTools-1.50-1 Missing file perl-MailTools-1.50-1.src.rpm. Are you in the right directory? Also this was quite a surprise.. I have to force installation of DBI. Sorry. thanks for the amazing work.. - dhawal From MailScanner at ecs.soton.ac.uk Wed Jan 18 15:25:34 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Jan 18 15:25:43 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: <43CE5A75.1000000@netmagicsolutions.com> References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> <43CE5A75.1000000@netmagicsolutions.com> Message-ID: <4611CFFC-9407-4546-978B-76CB0C398429@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- On 18 Jan 2006, at 15:10, Dhawal Doshy wrote: > Julian Field wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> I have just released 4.50.9 which will decode the UU-encoded file >> attached to these messages, so that the virus scanners should all >> catch it, filename traps will work on the .scr file inside >> the .bhx file, filetype traps will work on it too. > > Just successfully upgraded a couple of production servers.. > thankfully your beta standards are quite high (and a bit of testing > on the previous betas also helped) > > A small error.. > Attempting to build and install perl-MailTools-1.50-1 > Missing file perl-MailTools-1.50-1.src.rpm. Are you in the right > directory? Packaging error. Already fixed in 4.50.9-2. > > Also this was quite a surprise.. > I have to force installation of DBI. Sorry. That's expected. > thanks for the amazing work.. No problem. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ85d8Pw32o+k+q+hAQG+hAgAmJOaOWIqwtPuJUgQAfn+IaThB8TUQH0S hGdmvL62IuIf968VKTHqf0GIE8pLj1vfqeOAQEmuKPu10O920d9Nk7VGODHNiFWe BVUT23gwwctrGK/9qZ1nllWRlGr3yMWQtMUosiPFOjTn07pGz0cnn0+qqya8ljf0 EJ3SseT4yAnyQqZ3zHFkZADjR7t9Ly0WgrTeu6/IPSeDN9zV5buuEeuDRgUlSY6a 2UQMImPRIIoX83819QOV8scQYEn+ebewff6g1a65l9PRs1fGy1FyES+J+XZ7HAjA baYLKd6ni49oCpXx9m60x2gguLwjZUOjnMGZZCKP7A6PMiNp9aqRGQ== =fZkp -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From dhawal at netmagicsolutions.com Wed Jan 18 15:26:28 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Wed Jan 18 15:26:28 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: <43CE5A75.1000000@netmagicsolutions.com> References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> <43CE5A75.1000000@netmagicsolutions.com> Message-ID: <43CE5E24.6080103@netmagicsolutions.com> Dhawal Doshy wrote: > Julian Field wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> >> I have just released 4.50.9 which will decode the UU-encoded file >> attached to these messages, so that the virus scanners should all >> catch it, filename traps will work on the .scr file inside the .bhx >> file, filetype traps will work on it too. > > Just successfully upgraded a couple of production servers.. I notice this in the logs.. Jan 18 20:54:00 mx1 MailScanner[13545]: Infected message 73CEF28ABDE.D9736 came from The IP address is blank :-(, i'll try and run this through the debug sometime later. - dhawal From steve.freegard at fsl.com Wed Jan 18 16:16:38 2006 From: steve.freegard at fsl.com (Steve Freegard) Date: Wed Jan 18 16:15:06 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> Message-ID: <1137600999.26473.489.camel@localhost.localdomain> On Wed, 2006-01-18 at 14:19 +0000, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > I have just released 4.50.9 which will decode the UU-encoded file > attached to these messages, so that the virus scanners should all > catch it, filename traps will work on the .scr file inside the .bhx > file, filetype traps will work on it too. > Further to this - I've installed 4.50.9 on the Fort Systems test box but I do not have any examples of Worm.VB-8 to test it with. Please send your examples of this virus to virustest@fsg.com (DO NOT send them to the list!!). You may then log-in to MailWatch on this system at http://mail.fsg.com/mailscanner and use the username 'virustest@fsg.com' with a password of 'guest' to see the messages being received. The system runs ClamAV 0.88 with Mail::ClamAV 0.17 and BitDefender - I've also just manually run the virus scanner update. Thanks for your help. Kind regards, Steve. -- Steve Freegard Development Director Fort Systems Ltd. From ssilva at sgvwater.com Wed Jan 18 16:13:05 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Jan 18 16:15:40 2006 Subject: Saving public keys from email messages In-Reply-To: <10C29953-AE37-4D5A-8C31-5209508D0130@ecs.soton.ac.uk> References: <10C29953-AE37-4D5A-8C31-5209508D0130@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 1/18/2006 1:22 AM: > MailScanner can do this, it's just not documented (because I wrote it > for only 1 person). > In your MailScanner.info, set these 2 options: > > Archive Public Keys = yes > Public Key Archive Dir = /var/spool/MailScanner/keys > > Make sure that directory exists and is writeable by the "Run As User" user. > > On 16 Jan 2006, at 20:14, Dirk.Heuvels@inovasec.de > wrote: > Can MailScanner make my coffee/tea in the morning? It seems like it can do everything else!! Maybe it can even toast a bagel now and then. Although a few months ago it was toasting bagle's (the virus)! -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () From ssilva at sgvwater.com Wed Jan 18 16:16:31 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Jan 18 16:23:31 2006 Subject: Worm.VB-8 not detected by filename or filetype In-Reply-To: References: Message-ID: Jim Holland spake the following on 1/18/2006 1:19 AM: > Hi Julian > > This morning I noticed that we were being bombarded with mail from one > particular yahoo.it address with file attachments having names such as: > > Attachments00.HQX > Original_Message.B64 > Video_part.mim > Word_Document.hqx > Word_Document.uu > 392315089702606E02.UUE > eBook.Uu > > The files are all of approximately 134 000 bytes, and consist of uuencoded > text, with headers such as: > > begin 664 392315089702606E-02,UUE .scR > or > begin 664 Attachments,zip .SCR > > The extracted files are identified by ClamAV as being infected with > Worm.VB-8, but the actual uuencoded attachment is just regarded by ClamAV > as being plain text and so does not get flagged as a virus. > > The problem therefore is that the messages themselves are still getting > through. For the moment I am blocking the following extensions: > > .bhx > .b64 > .hqx > .uu > .uue > > I presume that a user would have to manually decode these files before > running the executable within, so infection is not likely to be very > common. However in our case we are finding the sheer volume a problem, so > are blocking the identified senders at MTA level. > > Can you see a way that scanning of such attachments can be forced? > > I see that "file -i" reports these attachments as being plain text, but > "file" reports them correctly as "uuencoded or xxencoded text". > > Regards > > Jim Holland > System Administrator > MANGO - Zimbabwe's non-profit e-mail service > If it can be opened, you will, sooner or later, find a user that opens it and infects their system. -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () From MailScanner at ecs.soton.ac.uk Wed Jan 18 16:32:06 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Jan 18 16:32:19 2006 Subject: Worm.VB-8 not detected by filename or filetype In-Reply-To: References: Message-ID: <14EAD9DD-5A17-414A-9DD1-A22469B10DB6@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- On 18 Jan 2006, at 16:16, Scott Silva wrote: > Jim Holland spake the following on 1/18/2006 1:19 AM: >> Hi Julian >> >> This morning I noticed that we were being bombarded with mail from >> one >> particular yahoo.it address with file attachments having names >> such as: >> >> Attachments00.HQX >> Original_Message.B64 >> Video_part.mim >> Word_Document.hqx >> Word_Document.uu >> 392315089702606E02.UUE >> eBook.Uu >> >> The files are all of approximately 134 000 bytes, and consist of >> uuencoded >> text, with headers such as: >> >> begin 664 392315089702606E-02,UUE .scR >> or >> begin 664 Attachments,zip .SCR >> >> The extracted files are identified by ClamAV as being infected with >> Worm.VB-8, but the actual uuencoded attachment is just regarded by >> ClamAV >> as being plain text and so does not get flagged as a virus. >> >> The problem therefore is that the messages themselves are still >> getting >> through. For the moment I am blocking the following extensions: >> >> .bhx >> .b64 >> .hqx >> .uu >> .uue >> >> I presume that a user would have to manually decode these files >> before >> running the executable within, so infection is not likely to be very >> common. However in our case we are finding the sheer volume a >> problem, so >> are blocking the identified senders at MTA level. >> >> Can you see a way that scanning of such attachments can be forced? >> >> I see that "file -i" reports these attachments as being plain >> text, but >> "file" reports them correctly as "uuencoded or xxencoded text". Please upgrade to the latest beta. I have already solved all this. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ85tivw32o+k+q+hAQEuRAgApxBg2J/0KGcj1cur8wb6Xr3Ld2FHY/Mz QKJ4P01iL9dW3dkkyZ2kjr1jzSuIMeSjLvv7JyiyM4eOZ7BbEDIcmhioJqRZNsml KXLaUdThH9lu12bvTB0M47oasAolqSFy/kCHCvnkR2QPOli//aT3astcGh1sm3KE En3QySb22m65wXM3SJB7ZkukWUkqdrOBag9e813dB0BjjWRR4V5312jXbbq+mqja BltvKepZUJ9a8HnFSBLj9PmKKmo6C0A8nWD6enOaafAyRwm+BifFXgjeBQ0R71Jl CUBu9psE3h3FLJhpyYBaUr2JLPTEC4/O9i3gW8IFxW1RlfhN+UzPRw== =BFb5 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Wed Jan 18 16:33:52 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Jan 18 16:34:05 2006 Subject: Saving public keys from email messages In-Reply-To: References: <10C29953-AE37-4D5A-8C31-5209508D0130@ecs.soton.ac.uk> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 18 Jan 2006, at 16:13, Scott Silva wrote: > Julian Field spake the following on 1/18/2006 1:22 AM: >> MailScanner can do this, it's just not documented (because I wrote it >> for only 1 person). >> In your MailScanner.info, set these 2 options: >> >> Archive Public Keys = yes >> Public Key Archive Dir = /var/spool/MailScanner/keys >> >> Make sure that directory exists and is writeable by the "Run As >> User" user. >> >> On 16 Jan 2006, at 20:14, Dirk.Heuvels@inovasec.de >> wrote: >> > > Can MailScanner make my coffee/tea in the morning? > It seems like it can do everything else!! :-) I could make the temperature of the coffee proportional (or inversely) to the rate of viruses coming in. > > Maybe it can even toast a bagel now and then. > Although a few months ago it was toasting bagle's (the virus)! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ85t9vw32o+k+q+hAQFekAgAtdRIELuW6UHNkCHEkLdI9kwV8TzqhP1d ektdeUBD1r5+tnqxNcoQNa0HcGPqPKJM1KKIASRgDuP/Vs4TqlAgLipbgx6Y5Afg 53VuEOmBGuURdPsgoCHi6ZfalejmgO0dBP8dI0s5cvcf2iEMlATu8PFkxO4Z9vbR pNnsU/xYYw63yZhRg3roavqIy7N7PL+r4wowNsAYjspqnqc5lyEpIdtlQtkL/Yow 1x6DcVm6QhPwQkMYHyjOvJCpLEbqcyIjT7aDHHqpWh5m4LwouskBGAhHIYvehRy/ 8qo86+7kfzXo/ye9VRFkKqtk5XYFbWfwooITsD2bhdveq1H+ylbFKA== =6La4 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ssilva at sgvwater.com Wed Jan 18 16:30:45 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Jan 18 16:35:04 2006 Subject: OT: Re: (no subject) In-Reply-To: References: Message-ID: Joshua Hirsh spake the following on 1/18/2006 6:11 AM: >> Anyone remember the fun one used to have with the .plan and .project? >> Many many years ago, I remember that "fingering" people would either >> give you a nice (ascii art) biplane going by, or giving you the finger >> (also in ascii art)... Ah VAX 11/7XX and BSD... Those were the >> days.... Not (this reminiscence is your fault Doc... got me thinking >> of times gone by:-) > > > Funny... I remember trying to explain how finger worked to my mom as a teen (she was looking over my shoulder and saw me type it). She then proceeded to ask me why I never fingered her before.. > > I don't talk computer lingo to her anymore. =p > > > -Joshua Terrible! I wouldn't even be able to look at her with a straight face for months if that happened to me! -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () From amirse at gmail.com Wed Jan 18 16:37:02 2006 From: amirse at gmail.com (Amir Sela) Date: Wed Jan 18 16:37:04 2006 Subject: Dropping spam into a different a custom mailbox In-Reply-To: <223f97700601170245i127196bbu@mail.gmail.com> References: <814064980601170111r23b50c81s6466e9d9f9a33ac2@mail.gmail.com> <7E70D91B-F777-4DA9-9054-7B6C41969590@ecs.soton.ac.uk> <814064980601170145x42914300y3c23f45e910aa67f@mail.gmail.com> <43CCC446.70800@coders.co.uk> <223f97700601170245i127196bbu@mail.gmail.com> Message-ID: <814064980601180837i1c2a6e11n51641e97f08d71b3@mail.gmail.com> Well it seems that I got it to work with Procmail. I set Postfix up to use it and now all spam marked messages get dropped to a separate folder. Dunno what went wrong before :) In any case, thanks a lot everyone. Very nice mailing list! Gonna keep reading it.. -Amir On 1/17/06, Glenn Steen wrote: > On 17/01/06, Matt Hampton wrote: > > Amir Sela wrote: > > > First of all, thanks for the reply. > > > The problem is that if I define postfix to use procmail, it simply > > > doesn't deliver mail. > > > And since this is a MailScanner specific problem, since it uses > > > postfix, I thought someone > > > here might give me an exact idea on how this is done when using > > > postfix with mailscanner. > > > It's not on the postfix docs because it's a MailScanner issue, and > > > here I get "this is not a Mailscanner issue", and I'm kind of stuck > > > because there are no docs on how this is done. > > > Thanks again, > > > -Amir > > > > > > > Amir > > > > Even though MailScanner "doesn't use postfix in the proper way" it is > > not involved in the delivery of mail to the mailboxes of your users. > > > > Here is a document that explains how to set up procmail with postfix > > > > http://ccfaq.valar.co.uk/modules.php?name=News&file=article&sid=245 > > > > This has basically everything you need > > > > matt > CC Matt. > One might also note that at least some distros of linux will have > procmail configured for postfix by default (for example > Mandriva/Mandrake has had it like that for quite some time). So in > that case it is just a matter of making a reasonable /etc/procmailrc > (or more likely a per user setup). > > Amir, when you say that you don't get anything delivered when using > procmail, might it be that you had a bum setup for procmail/thatuser? > Or could you see in the maillog that "everything borked out" (no > hand-off to the local delivery)? > -- > -- Glenn > email: glenn < dot > steen < at > gmail < dot > com > work: glenn < dot > steen < at > ap1 < dot > se > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From rgreen at trayerproducts.com Wed Jan 18 17:00:01 2006 From: rgreen at trayerproducts.com (Rodney Green) Date: Wed Jan 18 17:00:26 2006 Subject: OT: Add procmail to the mix Message-ID: <43CE7411.6010903@trayerproducts.com> Hello, I'm using Postfix as my MTA along with MailScanner and SpamAssassin. I'm wondering how I could add procmail into the mix so users can have their own spam mailbox. Can someone please give me some ideas on how procmail can be used? Thanks, Rod -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From dhawal at netmagicsolutions.com Wed Jan 18 17:12:38 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Wed Jan 18 17:12:40 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: <43CE5E24.6080103@netmagicsolutions.com> References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> <43CE5A75.1000000@netmagicsolutions.com> <43CE5E24.6080103@netmagicsolutions.com> Message-ID: <43CE7706.8070909@netmagicsolutions.com> Dhawal Doshy wrote: > Dhawal Doshy wrote: >> Julian Field wrote: >>> -----BEGIN PGP SIGNED MESSAGE----- >>> >>> I have just released 4.50.9 which will decode the UU-encoded file >>> attached to these messages, so that the virus scanners should all >>> catch it, filename traps will work on the .scr file inside the .bhx >>> file, filetype traps will work on it too. >> >> Just successfully upgraded a couple of production servers.. > > I notice this in the logs.. > Jan 18 20:54:00 mx1 MailScanner[13545]: Infected message > 73CEF28ABDE.D9736 came from > > The IP address is blank :-(, i'll try and run this through the debug > sometime later. The debug mode didn't tell me anything (apart from the EOCD thingy).. how do i track this problem? Jan 18 22:40:53 mx2 MailScanner[21952]: Infected message 77CE7288647.0EFC0 came from <== this is blank However the same thing works fine for spam Jan 18 22:40:55 mx1 MailScanner[13710]: Message 57DC728AC5B.E055B from 58.20.176.23 (info@galaxy-wars.com) to netmagicsolutions.com is spam, SpamAssassin (score=12.361, required 5, BAYES_99 4.00, DCC_CHECK 2.17, DRUGS_ERECTILE 0.22, HTML_30_40 0.02, HTML_MESSAGE 0.00, MIME_HTML_ONLY 0.18, SARE_MILLIONSOF 0.32, URIBL_BLACK 4.00, URIBL_WS_SURBL 1.46) - dhawal From ssilva at sgvwater.com Wed Jan 18 17:36:40 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Jan 18 17:38:43 2006 Subject: Saving public keys from email messages In-Reply-To: References: <10C29953-AE37-4D5A-8C31-5209508D0130@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 1/18/2006 8:33 AM: > On 18 Jan 2006, at 16:13, Scott Silva wrote: > >>> Julian Field spake the following on 1/18/2006 1:22 AM: >>>> MailScanner can do this, it's just not documented (because I wrote it >>>> for only 1 person). >>>> In your MailScanner.info, set these 2 options: >>>> >>>> Archive Public Keys = yes >>>> Public Key Archive Dir = /var/spool/MailScanner/keys >>>> >>>> Make sure that directory exists and is writeable by the "Run As >>>> User" user. >>>> >>>> On 16 Jan 2006, at 20:14, Dirk.Heuvels@inovasec.de >>>> wrote: >>>> >>> Can MailScanner make my coffee/tea in the morning? >>> It seems like it can do everything else!! > > :-) > I could make the temperature of the coffee proportional (or > inversely) to the rate of viruses coming in. > >>> Maybe it can even toast a bagel now and then. >>> Although a few months ago it was toasting bagle's (the virus)! > That probably wouldn't be ready to make February's stable release, as someone would have to write the coffee pot interface, and the brewer manufacturers probably won't release Linux versions of the drivers, anyway. ;-) -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () From MailScanner at ecs.soton.ac.uk Wed Jan 18 17:40:37 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Jan 18 17:40:41 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: <43CE7706.8070909@netmagicsolutions.com> References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> <43CE5A75.1000000@netmagicsolutions.com> <43CE5E24.6080103@netmagicsolutions.com> <43CE7706.8070909@netmagicsolutions.com> Message-ID: <43CE7D95.2040900@ecs.soton.ac.uk> Dhawal Doshy wrote: > Dhawal Doshy wrote: >> Dhawal Doshy wrote: >>> Julian Field wrote: >>>> -----BEGIN PGP SIGNED MESSAGE----- >>>> >>>> I have just released 4.50.9 which will decode the UU-encoded file >>>> attached to these messages, so that the virus scanners should all >>>> catch it, filename traps will work on the .scr file inside the >>>> .bhx file, filetype traps will work on it too. >>> >>> Just successfully upgraded a couple of production servers.. >> >> I notice this in the logs.. >> Jan 18 20:54:00 mx1 MailScanner[13545]: Infected message >> 73CEF28ABDE.D9736 came from >> >> The IP address is blank :-(, i'll try and run this through the debug >> sometime later. > > The debug mode didn't tell me anything (apart from the EOCD thingy).. > how do i track this problem? > > Jan 18 22:40:53 mx2 MailScanner[21952]: Infected message > 77CE7288647.0EFC0 came from <== this is blank > > However the same thing works fine for spam Could the message have been generated on the server? If it is generated by invoking postfix (via the sendmail soft-link) directly, then there won't be any client IP as there was never an SMTP transaction. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From William.Burns at Aeroflex.com Wed Jan 18 17:51:08 2006 From: William.Burns at Aeroflex.com (William Burns) Date: Wed Jan 18 17:54:23 2006 Subject: OT: HomeBrew Coffee was Re: Saving public keys from email messages In-Reply-To: References: <10C29953-AE37-4D5A-8C31-5209508D0130@ecs.soton.ac.uk> Message-ID: <43CE800C.40001@Aeroflex.com> Scott Silva wrote: > >That probably wouldn't be ready to make February's stable release, as someone >would have to write the coffee pot interface, and the brewer manufacturers >probably won't release Linux versions of the drivers, anyway. ;-) > > This is a solved problem. http://www.tldp.org/HOWTO/Coffee.html -Bill From sailer at bnl.gov Wed Jan 18 17:59:52 2006 From: sailer at bnl.gov (Tim Sailer) Date: Wed Jan 18 18:00:03 2006 Subject: OT: HomeBrew Coffee was Re: Saving public keys from email messages In-Reply-To: <43CE800C.40001@Aeroflex.com> References: <10C29953-AE37-4D5A-8C31-5209508D0130@ecs.soton.ac.uk> <43CE800C.40001@Aeroflex.com> Message-ID: <20060118175952.GB7210@bnl.gov> On Wed, Jan 18, 2006 at 12:51:08PM -0500, William Burns wrote: > Scott Silva wrote: > > > > >That probably wouldn't be ready to make February's stable release, as > >someone > >would have to write the coffee pot interface, and the brewer manufacturers > >probably won't release Linux versions of the drivers, anyway. ;-) > > > > > This is a solved problem. > http://www.tldp.org/HOWTO/Coffee.html Bah. Coffee pots. www.toddycafe.com Tim -- Tim Sailer Information and Special Technologies Program Office of Counterintelligence Brookhaven National Laboratory (631) 344-3001 From dhawal at netmagicsolutions.com Wed Jan 18 18:00:58 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Wed Jan 18 18:00:58 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: <43CE7D95.2040900@ecs.soton.ac.uk> References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> <43CE5A75.1000000@netmagicsolutions.com> <43CE5E24.6080103@netmagicsolutions.com> <43CE7706.8070909@netmagicsolutions.com> <43CE7D95.2040900@ecs.soton.ac.uk> Message-ID: <43CE825A.9030901@netmagicsolutions.com> Julian Field wrote: > Dhawal Doshy wrote: >> Dhawal Doshy wrote: >>> Dhawal Doshy wrote: >>>> Julian Field wrote: >>>>> -----BEGIN PGP SIGNED MESSAGE----- >>>>> >>>>> I have just released 4.50.9 which will decode the UU-encoded file >>>>> attached to these messages, so that the virus scanners should all >>>>> catch it, filename traps will work on the .scr file inside the >>>>> .bhx file, filetype traps will work on it too. >>>> >>>> Just successfully upgraded a couple of production servers.. >>> >>> I notice this in the logs.. >>> Jan 18 20:54:00 mx1 MailScanner[13545]: Infected message >>> 73CEF28ABDE.D9736 came from >>> >>> The IP address is blank :-(, i'll try and run this through the debug >>> sometime later. >> >> The debug mode didn't tell me anything (apart from the EOCD thingy).. >> how do i track this problem? >> >> Jan 18 22:40:53 mx2 MailScanner[21952]: Infected message >> 77CE7288647.0EFC0 came from <== this is blank >> >> However the same thing works fine for spam > Could the message have been generated on the server? If it is generated > by invoking postfix (via the sendmail soft-link) directly, then there > won't be any client IP as there was never an SMTP transaction. Nopes Julian, none of the mails are generated locally.. further checks reveal that this seems to be blank only if there the reverse lookup can't be done.. for all IPs that can be reverse looked up the message is normal like this: Jan 18 23:25:17 mx1 MailScanner[9679]: Infected message 3872D28ABB4.BF0A3 came from 59.144.45.244 <== resolves to BTNL-KK-DSL244.45.144.59.touchtelindia.net Jan 18 23:28:09 mx2 MailScanner[31926]: Infected message 8459A288833.82F31 came from <== this one is from 203.78.173.10 which doesn't have a reverse lookup. Hope this makes sense.. - dhawal From ssilva at sgvwater.com Wed Jan 18 18:29:18 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Jan 18 18:30:07 2006 Subject: OT: HomeBrew Coffee was Re: Saving public keys from email messages In-Reply-To: <43CE800C.40001@Aeroflex.com> References: <10C29953-AE37-4D5A-8C31-5209508D0130@ecs.soton.ac.uk> <43CE800C.40001@Aeroflex.com> Message-ID: William Burns spake the following on 1/18/2006 9:51 AM: > Scott Silva wrote: > >> >> That probably wouldn't be ready to make February's stable release, as >> someone >> would have to write the coffee pot interface, and the brewer >> manufacturers >> probably won't release Linux versions of the drivers, anyway. ;-) >> >> > This is a solved problem. > http://www.tldp.org/HOWTO/Coffee.html > > -Bill > Now we'll get into which is better for brewing coffee-- Linux or Free BSD ;-) --Jumps back from the ensuing fray! -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () From Kevin_Miller at ci.juneau.ak.us Wed Jan 18 18:32:39 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Wed Jan 18 18:32:43 2006 Subject: HomeBrew Coffee was Re: Saving public keys from email messages Message-ID: <82895A755D1EA5458EC9E64021922AD2D155FD@city-exch-w3e.cbj.local> William Burns wrote: > Scott Silva wrote: > >> >> That probably wouldn't be ready to make February's stable release, >> as someone would have to write the coffee pot interface, and the >> brewer manufacturers probably won't release Linux versions of the >> drivers, anyway. ;-) >> >> > This is a solved problem. > http://www.tldp.org/HOWTO/Coffee.html > > -Bill And if it's late, you just have to run the coffee through caffeineassassin to get decaf. Be sure to configure /etc/MailScanner/caffeine.assassan.prefs.conf to point to the RBL (robusta bean list) to filter out the canned stuff... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From KShortt at ussco.com Wed Jan 18 19:08:03 2006 From: KShortt at ussco.com (Shortt, Kevin) Date: Wed Jan 18 19:07:39 2006 Subject: Add procmail to the mix Message-ID: This is only feasible if you are delivering mail locally on your server. Procmail is a local delivery agent. If you are delivering local, then I can furnish you with some ideas that I use. -k > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Rodney Green > Sent: Wednesday, January 18, 2006 12:00 PM > To: MailScanner discussion > Subject: OT: Add procmail to the mix > > > Hello, > > I'm using Postfix as my MTA along with MailScanner and > SpamAssassin. I'm wondering how I could add procmail into the > mix so users can have their own spam mailbox. Can someone > please give me some ideas on how procmail can be used? > > Thanks, > Rod > > -- > This message has been scanned for viruses and dangerous > content by MailScanner, and is believed to be clean. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From nerijus at users.sourceforge.net Wed Jan 18 19:09:06 2006 From: nerijus at users.sourceforge.net (Nerijus Baliunas) Date: Wed Jan 18 19:10:14 2006 Subject: bayes_toks.expire1090 Message-ID: <20060118191054.8E364BFAF@mx.dtiltas.lt> Hello, I have lots of bayes_toks.expire1090, bayes_toks.expire15302, etc files in /var/spool/MailScanner/spamassassin. Where are they appearing from? RH AS 4, mailscanner-4.49.7, postfix, spamassassin-3.0.4. Regards, Nerijus From nerijus at users.sourceforge.net Wed Jan 18 19:01:19 2006 From: nerijus at users.sourceforge.net (Nerijus Baliunas) Date: Wed Jan 18 19:10:17 2006 Subject: Worm.VB-8 not detected by filename or filetype In-Reply-To: References: Message-ID: <20060118191054.881C0BEE5@mx.dtiltas.lt> On Wed, 18 Jan 2006 11:19:58 +0200 (CAT) Jim Holland wrote: > The problem therefore is that the messages themselves are still getting > through. For the moment I am blocking the following extensions: > > .bhx > .b64 > .hqx > .uu > .uue > > I presume that a user would have to manually decode these files before > running the executable within, so infection is not likely to be very > common. IIRC Winzip decodes them automatically. Regards, Nerijus From lhaig at haigmail.com Wed Jan 18 19:12:25 2006 From: lhaig at haigmail.com (Lance Haig) Date: Wed Jan 18 19:12:28 2006 Subject: Sendmail not relaying Message-ID: <43CE9319.6070009@haigmail.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Guys I have hit a snag. I have configured a new set of domains and have configured the mailertable relay-domains I have added the domains to the access file domain RELAY and the sending IP of the mailserver ipaddress RELAY When I try to send a mail to a domain outside the Mailscanner machine it says relaying denied. I have tried this command on the access file makemap hash /etc/mail/access < /etc/mail/access but is still does not want to allow the mailserver to relay e-mail. What am I missing guys I am using sendmail Thanks Lance -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFDzpMZM4kHBIBZ61gRAkVOAJ9YQtob1XltgzMgYBjTL0xXNoFG1gCeKU/m jwvHoQDAvVxWV7GVRMEYGqE= =EZk2 -----END PGP SIGNATURE----- From glenn.steen at gmail.com Wed Jan 18 19:15:56 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Jan 18 19:16:00 2006 Subject: OT: HomeBrew Coffee was Re: Saving public keys from email messages In-Reply-To: References: <10C29953-AE37-4D5A-8C31-5209508D0130@ecs.soton.ac.uk> <43CE800C.40001@Aeroflex.com> Message-ID: <223f97700601181115j69631cc1o@mail.gmail.com> On 18/01/06, Scott Silva wrote: > William Burns spake the following on 1/18/2006 9:51 AM: > > Scott Silva wrote: > > > >> > >> That probably wouldn't be ready to make February's stable release, as > >> someone > >> would have to write the coffee pot interface, and the brewer > >> manufacturers > >> probably won't release Linux versions of the drivers, anyway. ;-) > >> > >> > > This is a solved problem. > > http://www.tldp.org/HOWTO/Coffee.html > > > > -Bill > > > Now we'll get into which is better for brewing coffee-- Linux or Free BSD ;-) Nah, the question will be either "Robusta vs Arabica" or "brew vs boil"...:-). All the UK people on this list are (of course) automatically disqualified from having an opinion.... No Englishman can make coffee:-):-) ... And Americans aren't much better... What?! Me being a bit bigott? Yeah, well.... Opinionated when it comes to coffee:-). If one is out for the real caffeine kick, one should always boil, not brew.... Tastes better too, provided you 1) make it strong enough (this is were the English/Americans usually fail... think mug-sized espresso, and you'll at least get close;) and 2) drink it literally boiling hot. That way it'll taste sublime and you'll not rot your gut with pesky tannins(sp?). > --Jumps back from the ensuing fray! :-) > -- > > /-----------------------\ |~~\_____/~~\__ | > | MailScanner; The best |___________ \N1____====== )-+ > | protection on the net!| ~~~|/~~ | > \-----------------------/ () > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From MailScanner at ecs.soton.ac.uk Wed Jan 18 19:24:36 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Jan 18 19:24:47 2006 Subject: bayes_toks.expire1090 In-Reply-To: <20060118191054.8E364BFAF@mx.dtiltas.lt> References: <20060118191054.8E364BFAF@mx.dtiltas.lt> Message-ID: <43CE95F4.3030105@ecs.soton.ac.uk> Nerijus Baliunas wrote: > I have lots of bayes_toks.expire1090, bayes_toks.expire15302, etc files > in /var/spool/MailScanner/spamassassin. Where are they appearing from? > RH AS 4, mailscanner-4.49.7, postfix, spamassassin-3.0.4. > They are due to SpamAssassin timeouts occurring during Bayes database rebuilds. Your best bet is to upgrade to 4.50, as I fixed an issue connected to this, and configure MailScanner to do the Bayes rebuilds. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From KShortt at ussco.com Wed Jan 18 19:27:39 2006 From: KShortt at ussco.com (Shortt, Kevin) Date: Wed Jan 18 19:27:30 2006 Subject: Sendmail not relaying Message-ID: Is your mailscanner server just scrubbing the mail and passing onto another host for deliver? If so, then you need to use the mailertable. What does your mailertable look like? -k > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Lance Haig > Sent: Wednesday, January 18, 2006 2:12 PM > To: MailScanner discussion > Subject: Sendmail not relaying > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Guys I have hit a snag. > > I have configured a new set of domains and have configured > the mailertable relay-domains > > I have added the domains to the access file > domain RELAY > > and the sending IP of the mailserver > ipaddress RELAY > > When I try to send a mail to a domain outside the Mailscanner > machine it says relaying denied. > > I have tried this command on the access file > > makemap hash /etc/mail/access < /etc/mail/access > > but is still does not want to allow the mailserver to relay e-mail. > > What am I missing guys > > I am using sendmail > > Thanks > > Lance > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.2 (MingW32) > Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org > > iD8DBQFDzpMZM4kHBIBZ61gRAkVOAJ9YQtob1XltgzMgYBjTL0xXNoFG1gCeKU/m > jwvHoQDAvVxWV7GVRMEYGqE= > =EZk2 > -----END PGP SIGNATURE----- > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From Kevin_Miller at ci.juneau.ak.us Wed Jan 18 19:33:03 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Wed Jan 18 19:33:09 2006 Subject: Sendmail not relaying Message-ID: <82895A755D1EA5458EC9E64021922AD2D15603@city-exch-w3e.cbj.local> Lance Haig wrote: snip > > What am I missing guys > > I am using sendmail You also need to do: makemap hash mailertable < mailertable That may or may not fix it, but it's a step you didn't list which should be done. ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From mailscanner at mango.zw Wed Jan 18 19:37:28 2006 From: mailscanner at mango.zw (Jim Holland) Date: Wed Jan 18 19:40:44 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: Message-ID: On Wed, 18 Jan 2006, Julian Field wrote: > I have just released 4.50.9 which will decode the UU-encoded file > attached to these messages, so that the virus scanners should all > catch it, filename traps will work on the .scr file inside the .bhx > file, filetype traps will work on it too. Thanks very much for your extraordinarily fast response. Regards Jim Holland System Administrator MANGO - Zimbabwe's non-profit e-mail service From lhaig at haigmail.com Wed Jan 18 19:41:19 2006 From: lhaig at haigmail.com (Lance Haig) Date: Wed Jan 18 19:41:22 2006 Subject: Sendmail not relaying In-Reply-To: References: Message-ID: <43CE99DF.4000309@haigmail.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi Kevin, I have been watching the mail log and have seen this error server1.megas.co.za [196.31.65.238] (may be forged) This is a valid mail server on the guys site my mailertable looks like this domain.co.za esmtp:[xx.xx.xx.xx] I can send e-mail to his site but he cant send mail out through my server Hope this helps Lance Shortt, Kevin wrote: > Is your mailscanner server just scrubbing the mail and passing onto another > host for deliver? > If so, then you need to use the mailertable. What does your mailertable > look like? > > -k > > > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf >> Of Lance Haig >> Sent: Wednesday, January 18, 2006 2:12 PM >> To: MailScanner discussion >> Subject: Sendmail not relaying >> > Guys I have hit a snag. > > I have configured a new set of domains and have configured > the mailertable relay-domains > > I have added the domains to the access file > domain RELAY > > and the sending IP of the mailserver > ipaddress RELAY > > When I try to send a mail to a domain outside the Mailscanner > machine it says relaying denied. > > I have tried this command on the access file > > makemap hash /etc/mail/access < /etc/mail/access > > but is still does not want to allow the mailserver to relay e-mail. > > What am I missing guys > > I am using sendmail > > Thanks > > Lance - -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner >> Before posting, read http://wiki.mailscanner.info/posting >> Support MailScanner development - buy the book off the website! >> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFDzpnfM4kHBIBZ61gRAuk4AJ0dsEgLw2rLsJAy90YhJZ36p3vJZwCdFIcv pcUqw/GYQdJNsddxPbOvIAM= =qFwZ -----END PGP SIGNATURE----- From ebruce at hpmich.com Wed Jan 18 19:41:32 2006 From: ebruce at hpmich.com (Ed Bruce) Date: Wed Jan 18 19:41:40 2006 Subject: OT: HomeBrew Coffee was Re: Saving public keys from email messages In-Reply-To: <223f97700601181115j69631cc1o@mail.gmail.com> References: <10C29953-AE37-4D5A-8C31-5209508D0130@ecs.soton.ac.uk> <43CE800C.40001@Aeroflex.com> <223f97700601181115j69631cc1o@mail.gmail.com> Message-ID: <43CE99EC.7050905@hpmich.com> Glenn Steen wrote: > If one is out for the real caffeine kick, one should always boil, not > brew.... Tastes better too, provided you 1) make it strong enough > (this is were the English/Americans usually fail... think mug-sized > espresso, and you'll at least get close;) and 2) drink it literally > boiling hot. That way it'll taste sublime and you'll not rot your gut > with pesky tannins(sp?) I guess that Englishman I worked with in Belgium was an aberation. One cup of his brew and I was pretty much wired for the day :) But I've got to admit some of the best coffee I had was in Germany. And for some reason they didn't server any coffee or tea in that teahouse in Belgium??? From KGoods at AIAInsurance.com Wed Jan 18 19:41:43 2006 From: KGoods at AIAInsurance.com (Ken Goods) Date: Wed Jan 18 19:45:32 2006 Subject: Sendmail not relaying Message-ID: <13C0059880FDD3118DC600508B6D4A6D013D868A@aiainsurance.com> Lance Haig wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Guys I have hit a snag. > > I have configured a new set of domains and have configured the > mailertable > relay-domains > > I have added the domains to the access file > domain RELAY > > and the sending IP of the mailserver > ipaddress RELAY > > When I try to send a mail to a domain outside the Mailscanner machine > it says relaying denied. > > I have tried this command on the access file > > makemap hash /etc/mail/access < /etc/mail/access > > but is still does not want to allow the mailserver to relay e-mail. > > What am I missing guys > > I am using sendmail > > Thanks > > Lance Lance, I'm by no means a sendmail expert but thought I'd take a quick look at my config for you. In my access file I have: localhost.localdomain RELAY localhost RELAY 127.0.0.1 RELAY Then in my mailertable I have: .domain1.com smtp:xxx.xxx.xxx.xxx .domain2.com smtp:xxx.xxx.xxx.xxx .domain3.com smtp:xxx.xxx.xxx.xxx .domain4.com smtp:xxx.xxx.xxx.xxx Then in my relay-domains I have: domain1.com domain2.com domain3.com domain4.com I also have in my virtuser-domain: domain1.com domain2.com domain3.com domain4.com although I don't know if this is absolutly necessary... This works fine for me as I'm only using the MailScanner box to filter for domains hosted on our exchange server. Hope this helps... Ken Goods Network Administrator AIA/CropUSA Insurance, Inc. From MailScanner at ecs.soton.ac.uk Wed Jan 18 19:47:39 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Jan 18 19:47:46 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: References: Message-ID: <43CE9B5B.6020801@ecs.soton.ac.uk> Jim Holland wrote: > On Wed, 18 Jan 2006, Julian Field wrote: > > >> I have just released 4.50.9 which will decode the UU-encoded file >> attached to these messages, so that the virus scanners should all >> catch it, filename traps will work on the .scr file inside the .bhx >> file, filetype traps will work on it too. >> > > Thanks very much for your extraordinarily fast response. > I do try to get these little problems sorted as fast as I can :-) Note that it will now quite happily unpack uue within zip within rar within uue within uue, for example. How deep it unpacks zip,rar and uue is controlled by the "Maximum Archive Depth", uue is treated as another archive format. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From Kevin_Miller at ci.juneau.ak.us Wed Jan 18 19:54:41 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Wed Jan 18 19:54:44 2006 Subject: Sendmail not relaying Message-ID: <82895A755D1EA5458EC9E64021922AD2D15605@city-exch-w3e.cbj.local> Lance Haig wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Hi Kevin, > > I have been watching the mail log and have seen this error > > server1.megas.co.za [196.31.65.238] (may be forged) > > This is a valid mail server on the guys site > > my mailertable looks like this > > domain.co.za esmtp:[xx.xx.xx.xx] > > > I can send e-mail to his site but he cant send mail out through my > server > > Hope this helps > > Lance There seems to be some problem with your DNS I think: ==================================================== G:\>nslookup server1.megas.co.za Server: city-dc1-w3s.cbj.local Address: 199.58.55.25 *** city-dc1-w3s.cbj.local can't find server1.megas.co.za: Non-existent domain ==================================================== G:\>nslookup 196.31.65.238 Server: city-dc1-w3s.cbj.local Address: 199.58.55.25 Name: server1.megas.co.za Address: 196.31.65.238 ==================================================== I can resolve your IP so your reverse zone is OK, but your forward zone doesn't seem to have an A record for server1.megas.co.za. Might look into that. Also, when you say "domain.co.za esmtp:[xx.xx.xx.xx]", is the word domain just a placeholder for the actual domain? That is, does the mailertable actually say: megas.co.za emspt:[xx.xx.xx.xx] (where the xx.xx.xx.xx is the IP of the mailserver to send to). If it literally says "domain.co.za" you need to change the word domain to the actual domain you want to relay to (unless domain.co.za is really the name of the domain). HTH... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From dhawal at netmagicsolutions.com Wed Jan 18 20:01:03 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Wed Jan 18 20:01:06 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: <43CE825A.9030901@netmagicsolutions.com> References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> <43CE5A75.1000000@netmagicsolutions.com> <43CE5E24.6080103@netmagicsolutions.com> <43CE7706.8070909@netmagicsolutions.com> <43CE7D95.2040900@ecs.soton.ac.uk> <43CE825A.9030901@netmagicsolutions.com> Message-ID: <43CE9E7F.7010700@netmagicsolutions.com> Dhawal Doshy wrote: >>>>> Julian Field wrote: >>>>>> -----BEGIN PGP SIGNED MESSAGE----- >>>>>> >>>>>> I have just released 4.50.9 which will decode the UU-encoded file >>>>>> attached to these messages, so that the virus scanners should all >>>>>> catch it, filename traps will work on the .scr file inside the >>>>>> .bhx file, filetype traps will work on it too. >>>>> >>>>> Just successfully upgraded a couple of production servers.. >>>> >>>> I notice this in the logs.. >>>> Jan 18 20:54:00 mx1 MailScanner[13545]: Infected message >>>> 73CEF28ABDE.D9736 came from >>>> >>>> The IP address is blank :-(, i'll try and run this through the debug >>>> sometime later. >>> >>> The debug mode didn't tell me anything (apart from the EOCD thingy).. >>> how do i track this problem? >>> [SNIP] This is getting wierder :([root@db ~]# tail -f /var/log/maillog | grep "came from" [root@db ~]# tail -f /var/log/maillog | grep "came from" Jan 19 01:27:56 mx2 MailScanner[24329]: Infected message CEC922880B7.161E3 came from 220.227.146.91 Jan 19 01:28:20 mx2 MailScanner[24329]: Infected message CEC922880B7.161E3 came from Jan 19 01:28:23 mx2 MailScanner[24329]: Infected message CEC922880B7.161E3 came from Jan 19 01:28:41 mx2 MailScanner[24329]: Infected message CEC922880B7.161E3 came from Jan 19 01:28:43 mx2 MailScanner[24329]: Infected message CEC922880B7.161E3 came from Jan 19 01:29:08 mx2 MailScanner[24290]: Infected message 342082881C5.4425B came from 59.161.64.25 Jan 19 01:29:26 mx2 MailScanner[24290]: Infected message 342082881C5.4425B came from Jan 19 01:29:37 mx2 MailScanner[24388]: Infected message 740E4288309.62BC0 came from 210.18.63.180 Jan 19 01:29:45 mx2 MailScanner[24388]: Infected message 740E4288309.62BC0 came from Jan 19 01:29:46 mx2 MailScanner[24329]: Infected message CEC922880B7.161E3 came from Jan 19 01:29:46 mx2 MailScanner[24290]: Infected message 342082881C5.4425B came from Notice the duplication, now why would that happen? - dhawal From mailscanner at mango.zw Wed Jan 18 20:05:37 2006 From: mailscanner at mango.zw (Jim Holland) Date: Wed Jan 18 20:09:05 2006 Subject: Sendmail not relaying In-Reply-To: <43CE99DF.4000309@haigmail.com> Message-ID: Hi On Wed, 18 Jan 2006, Lance Haig wrote: > I have been watching the mail log and have seen this error > > server1.megas.co.za [196.31.65.238] (may be forged) > > This is a valid mail server on the guys site While this won't fix the problem, it should be pointed out that you need to have an A record for the above hostname on your nameservers. At the moment it is listed as NXDOMAIN (domain does not exist). > my mailertable looks like this > > domain.co.za esmtp:[xx.xx.xx.xx] The mailertable is only relevant for delivering mail to their system, and will not affect their ability to relay outgoing mail through you. > I can send e-mail to his site but he cant send mail out through my server If the mail is coming from the above server, then you should be using the following entry in your access file: Connect:196.31.65.238 RELAY not 196.31.65.238 RELAY if you are using a current version of sendmail. If you are using SMTP AUTH then of course that should be set up correctly as well, as that will also affect outgoing relaying. Regards Jim Holland System Administrator MANGO - Zimbabwe's non-profit e-mail service > Hope this helps > > Lance > > Shortt, Kevin wrote: > > Is your mailscanner server just scrubbing the mail and passing onto another > > host for deliver? > > If so, then you need to use the mailertable. What does your mailertable > > look like? > > > > -k > > > > > > > >> -----Original Message----- > >> From: mailscanner-bounces@lists.mailscanner.info > >> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > >> Of Lance Haig > >> Sent: Wednesday, January 18, 2006 2:12 PM > >> To: MailScanner discussion > >> Subject: Sendmail not relaying > >> > > Guys I have hit a snag. > > > > I have configured a new set of domains and have configured > > the mailertable relay-domains > > > > I have added the domains to the access file > > domain RELAY > > > > and the sending IP of the mailserver > > ipaddress RELAY > > > > When I try to send a mail to a domain outside the Mailscanner > > machine it says relaying denied. > > > > I have tried this command on the access file > > > > makemap hash /etc/mail/access < /etc/mail/access > > > > but is still does not want to allow the mailserver to relay e-mail. > > > > What am I missing guys > > > > I am using sendmail > > > > Thanks > > > > Lance > - -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > >> > Before posting, read http://wiki.mailscanner.info/posting > >> > Support MailScanner development - buy the book off the website! > >> > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.2 (MingW32) > Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org > > iD8DBQFDzpnfM4kHBIBZ61gRAuk4AJ0dsEgLw2rLsJAy90YhJZ36p3vJZwCdFIcv > pcUqw/GYQdJNsddxPbOvIAM= > =qFwZ > -----END PGP SIGNATURE----- > From MailScanner at ecs.soton.ac.uk Wed Jan 18 20:12:05 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Jan 18 20:12:16 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: <43CE9E7F.7010700@netmagicsolutions.com> References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> <43CE5A75.1000000@netmagicsolutions.com> <43CE5E24.6080103@netmagicsolutions.com> <43CE7706.8070909@netmagicsolutions.com> <43CE7D95.2040900@ecs.soton.ac.uk> <43CE825A.9030901@netmagicsolutions.com> <43CE9E7F.7010700@netmagicsolutions.com> Message-ID: <43CEA115.90800@ecs.soton.ac.uk> Dhawal Doshy wrote: > Dhawal Doshy wrote: >>>>>> Julian Field wrote: >>>>>>> -----BEGIN PGP SIGNED MESSAGE----- >>>>>>> >>>>>>> I have just released 4.50.9 which will decode the UU-encoded >>>>>>> file attached to these messages, so that the virus scanners >>>>>>> should all catch it, filename traps will work on the .scr file >>>>>>> inside the .bhx file, filetype traps will work on it too. >>>>>> >>>>>> Just successfully upgraded a couple of production servers.. >>>>> >>>>> I notice this in the logs.. >>>>> Jan 18 20:54:00 mx1 MailScanner[13545]: Infected message >>>>> 73CEF28ABDE.D9736 came from >>>>> >>>>> The IP address is blank :-(, i'll try and run this through the >>>>> debug sometime later. >>>> >>>> The debug mode didn't tell me anything (apart from the EOCD >>>> thingy).. how do i track this problem? >>>> > [SNIP] > This is getting wierder :([root@db ~]# tail -f /var/log/maillog | grep > "came from" > > [root@db ~]# tail -f /var/log/maillog | grep "came from" > Jan 19 01:27:56 mx2 MailScanner[24329]: Infected message > CEC922880B7.161E3 came from 220.227.146.91 > Jan 19 01:28:20 mx2 MailScanner[24329]: Infected message > CEC922880B7.161E3 came from > Jan 19 01:28:23 mx2 MailScanner[24329]: Infected message > CEC922880B7.161E3 came from > Jan 19 01:28:41 mx2 MailScanner[24329]: Infected message > CEC922880B7.161E3 came from > Jan 19 01:28:43 mx2 MailScanner[24329]: Infected message > CEC922880B7.161E3 came from > Jan 19 01:29:08 mx2 MailScanner[24290]: Infected message > 342082881C5.4425B came from 59.161.64.25 > Jan 19 01:29:26 mx2 MailScanner[24290]: Infected message > 342082881C5.4425B came from > Jan 19 01:29:37 mx2 MailScanner[24388]: Infected message > 740E4288309.62BC0 came from 210.18.63.180 > Jan 19 01:29:45 mx2 MailScanner[24388]: Infected message > 740E4288309.62BC0 came from > Jan 19 01:29:46 mx2 MailScanner[24329]: Infected message > CEC922880B7.161E3 came from > Jan 19 01:29:46 mx2 MailScanner[24290]: Infected message > 342082881C5.4425B came from > > Notice the duplication, now why would that happen? You get 1 line for each infection report. Not quite sure why I wrote it that way, but that's the reason. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From rgreen at trayerproducts.com Wed Jan 18 20:21:22 2006 From: rgreen at trayerproducts.com (Rodney Green) Date: Wed Jan 18 20:21:49 2006 Subject: Add procmail to the mix In-Reply-To: References: Message-ID: <43CEA342.7050306@trayerproducts.com> An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060118/d7066b8d/attachment.html -------------- next part -------------- A non-text attachment was scrubbed... Name: secplus.jpg Type: image/jpeg Size: 6398 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060118/d7066b8d/secplus.jpg From dhawal at netmagicsolutions.com Wed Jan 18 20:23:04 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Wed Jan 18 20:23:06 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: <43CEA115.90800@ecs.soton.ac.uk> References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> <43CE5A75.1000000@netmagicsolutions.com> <43CE5E24.6080103@netmagicsolutions.com> <43CE7706.8070909@netmagicsolutions.com> <43CE7D95.2040900@ecs.soton.ac.uk> <43CE825A.9030901@netmagicsolutions.com> <43CE9E7F.7010700@netmagicsolutions.com> <43CEA115.90800@ecs.soton.ac.uk> Message-ID: <43CEA3A8.70703@netmagicsolutions.com> Julian Field wrote: > Dhawal Doshy wrote: >> Dhawal Doshy wrote: >>>>>>> Julian Field wrote: >>>>>>>> -----BEGIN PGP SIGNED MESSAGE----- >>>>>>>> >>>>>>>> I have just released 4.50.9 which will decode the UU-encoded >>>>>>>> file attached to these messages, so that the virus scanners >>>>>>>> should all catch it, filename traps will work on the .scr file >>>>>>>> inside the .bhx file, filetype traps will work on it too. >>>>>>> >>>>>>> Just successfully upgraded a couple of production servers.. >>>>>> >>>>>> I notice this in the logs.. >>>>>> Jan 18 20:54:00 mx1 MailScanner[13545]: Infected message >>>>>> 73CEF28ABDE.D9736 came from >>>>>> >>>>>> The IP address is blank :-(, i'll try and run this through the >>>>>> debug sometime later. >>>>> >>>>> The debug mode didn't tell me anything (apart from the EOCD >>>>> thingy).. how do i track this problem? >>>>> >> [SNIP] >> This is getting wierder :([root@db ~]# tail -f /var/log/maillog | grep >> "came from" >> >> [root@db ~]# tail -f /var/log/maillog | grep "came from" >> Jan 19 01:27:56 mx2 MailScanner[24329]: Infected message >> CEC922880B7.161E3 came from 220.227.146.91 >> Jan 19 01:28:20 mx2 MailScanner[24329]: Infected message >> CEC922880B7.161E3 came from >> Jan 19 01:28:23 mx2 MailScanner[24329]: Infected message >> CEC922880B7.161E3 came from >> Jan 19 01:28:41 mx2 MailScanner[24329]: Infected message >> CEC922880B7.161E3 came from [SNIP] >> Notice the duplication, now why would that happen? > You get 1 line for each infection report. Not quite sure why I wrote it > that way, but that's the reason. Wasn't like this before the upgrade.. here are logs for an hour from 15th Jan (way before the upgrade) I have a SEC script looking for this entry in the maillogs and creating a local virus-rbl.. else i wouldn't be so deeply concerned. - dhawal Jan 15 05:01:00 mx1 MailScanner[20397]: Infected message 8A325CDF35.0CBBE came from 69.42.9.31 Jan 15 05:01:06 mx2 MailScanner[19797]: Infected message 01C8C140003.DD0FF came from 202.159.241.134 Jan 15 05:01:56 mx1 MailScanner[20581]: Infected message 52A87CDF2D.62A70 came from 203.94.231.35 Jan 15 05:02:57 mx1 MailScanner[20636]: Infected message F2B06CDF3D.404BA came from 202.88.130.8 Jan 15 05:04:25 mx2 MailScanner[19797]: Infected message 30DDC140008.EF836 came from 83.39.6.46 Jan 15 05:04:43 mx2 MailScanner[20457]: Infected message 34AC0140003.405BC came from 152.101.52.20 Jan 15 05:06:33 mx1 MailScanner[20682]: Infected message 9B75DCB9B3.61D1D came from 203.199.13.210 Jan 15 05:07:14 mx1 MailScanner[20241]: Infected message DE01DCDF35.4F8B4 came from 83.110.220.215 Jan 15 05:07:24 mx1 MailScanner[20581]: Infected message C84FFCD015.7D16C came from 203.199.13.210 Jan 15 05:11:50 mx1 MailScanner[19975]: Infected message 9150FCB9B3.1112B came from 83.110.221.191 Jan 15 05:12:04 mx1 MailScanner[20581]: Infected message 6D6B5CDF2F.3E842 came from 200.193.163.222 Jan 15 05:12:41 mx1 MailScanner[19975]: Infected message 5B27DCB9B3.1A013 came from 209.239.37.109 Jan 15 05:17:18 mx1 MailScanner[20581]: Infected message 72C50CBA87.288F0 came from 205.214.42.229 Jan 15 05:20:38 mx1 MailScanner[20725]: Infected message D1AF3CDF2E.6F1F6 came from 81.192.19.191 Jan 15 05:21:39 mx2 MailScanner[20531]: Infected message 21EBA140006.7F4D2 came from 82.148.120.140 Jan 15 05:21:51 mx2 MailScanner[20299]: Infected message E607B140012.31D82 came from 202.159.241.134 Jan 15 05:22:37 mx1 MailScanner[20173]: Infected message F3539CBA87.73A80 came from 83.110.220.215 Jan 15 05:23:12 mx2 MailScanner[19922]: Infected message CA577140002.C4826 came from 85.176.6.61 Jan 15 05:23:51 mx1 MailScanner[20397]: Infected message D373CCDF2E.4FCE2 came from 203.94.231.35 Jan 15 05:23:54 mx1 MailScanner[20682]: Infected message DEA2ECDF3E.D15A4 came from 83.110.220.215 Jan 15 05:26:06 mx1 MailScanner[20241]: Infected message B89ECCDF2C.1A06A came from 83.110.220.215 Jan 15 05:26:16 mx1 MailScanner[20792]: Infected message 1155ACDF40.C6C78 came from 202.159.241.134 Jan 15 05:29:57 mx1 MailScanner[20274]: Infected message CD095CDF2C.6756C came from 152.101.52.20 Jan 15 05:36:24 mx1 MailScanner[20702]: Infected message DA4A2CDF2B.B7695 came from 24.218.188.31 Jan 15 05:37:29 mx2 MailScanner[20299]: Infected message C94DA140004.3EA49 came from 85.154.20.71 Jan 15 05:40:28 mx1 MailScanner[20636]: Infected message 95CCBCDF40.D3E3E came from 195.188.213.7 Jan 15 05:42:45 mx1 MailScanner[20173]: Infected message 52B94CB9B3.2CDAB came from 203.94.231.35 Jan 15 05:45:41 mx1 MailScanner[20212]: Infected message E961ACDF3A.71A21 came from 201.9.79.201 Jan 15 05:48:55 mx1 MailScanner[19975]: Infected message 70432CDF21.99A5C came from 64.95.65.108 Jan 15 05:49:00 mx2 MailScanner[20841]: Infected message DD605140002.1AC9B came from 152.101.52.20 Jan 15 05:49:18 mx1 MailScanner[20173]: Infected message 4A418CDF3A.6E6CF came from 196.192.100.67 Jan 15 05:50:45 mx1 MailScanner[20173]: Infected message 5B4AACBA0C.8853F came from 207.106.22.53 Jan 15 05:51:15 mx1 MailScanner[20702]: Infected message C180CCDF3D.B7005 came from 202.159.241.134 Jan 15 05:51:30 mx2 MailScanner[20398]: Infected message 97683140004.3A373 came from 222.166.19.22 Jan 15 05:51:38 mx1 MailScanner[20725]: Infected message 5E48BCB9EA.9B3E0 came from 83.237.235.20 From MailScanner at ecs.soton.ac.uk Wed Jan 18 20:26:38 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Jan 18 20:26:45 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: <43CEA115.90800@ecs.soton.ac.uk> References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> <43CE5A75.1000000@netmagicsolutions.com> <43CE5E24.6080103@netmagicsolutions.com> <43CE7706.8070909@netmagicsolutions.com> <43CE7D95.2040900@ecs.soton.ac.uk> <43CE825A.9030901@netmagicsolutions.com> <43CE9E7F.7010700@netmagicsolutions.com> <43CEA115.90800@ecs.soton.ac.uk> Message-ID: <43CEA47E.2020301@ecs.soton.ac.uk> Julian Field wrote: > Dhawal Doshy wrote: >> Dhawal Doshy wrote: >>>>>>> Julian Field wrote: >>>>>>>> -----BEGIN PGP SIGNED MESSAGE----- >>>>>>>> >>>>>>>> I have just released 4.50.9 which will decode the UU-encoded >>>>>>>> file attached to these messages, so that the virus scanners >>>>>>>> should all catch it, filename traps will work on the .scr file >>>>>>>> inside the .bhx file, filetype traps will work on it too. >>>>>>> >>>>>>> Just successfully upgraded a couple of production servers.. >>>>>> >>>>>> I notice this in the logs.. >>>>>> Jan 18 20:54:00 mx1 MailScanner[13545]: Infected message >>>>>> 73CEF28ABDE.D9736 came from >>>>>> >>>>>> The IP address is blank :-(, i'll try and run this through the >>>>>> debug sometime later. >>>>> >>>>> The debug mode didn't tell me anything (apart from the EOCD >>>>> thingy).. how do i track this problem? >>>>> >> [SNIP] >> This is getting wierder :([root@db ~]# tail -f /var/log/maillog | >> grep "came from" >> >> [root@db ~]# tail -f /var/log/maillog | grep "came from" >> Jan 19 01:27:56 mx2 MailScanner[24329]: Infected message >> CEC922880B7.161E3 came from 220.227.146.91 >> Jan 19 01:28:20 mx2 MailScanner[24329]: Infected message >> CEC922880B7.161E3 came from >> Jan 19 01:28:23 mx2 MailScanner[24329]: Infected message >> CEC922880B7.161E3 came from >> Jan 19 01:28:41 mx2 MailScanner[24329]: Infected message >> CEC922880B7.161E3 came from >> Jan 19 01:28:43 mx2 MailScanner[24329]: Infected message >> CEC922880B7.161E3 came from >> Jan 19 01:29:08 mx2 MailScanner[24290]: Infected message >> 342082881C5.4425B came from 59.161.64.25 >> Jan 19 01:29:26 mx2 MailScanner[24290]: Infected message >> 342082881C5.4425B came from >> Jan 19 01:29:37 mx2 MailScanner[24388]: Infected message >> 740E4288309.62BC0 came from 210.18.63.180 >> Jan 19 01:29:45 mx2 MailScanner[24388]: Infected message >> 740E4288309.62BC0 came from >> Jan 19 01:29:46 mx2 MailScanner[24329]: Infected message >> CEC922880B7.161E3 came from >> Jan 19 01:29:46 mx2 MailScanner[24290]: Infected message >> 342082881C5.4425B came from >> >> Notice the duplication, now why would that happen? > You get 1 line for each infection report. Not quite sure why I wrote > it that way, but that's the reason. I'll improve it so it only prints it once for each infected message. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From smf at f2s.com Wed Jan 18 20:42:50 2006 From: smf at f2s.com (Steve Freegard) Date: Wed Jan 18 20:41:18 2006 Subject: Sendmail not relaying In-Reply-To: <43CE9319.6070009@haigmail.com> References: <43CE9319.6070009@haigmail.com> Message-ID: <1137616970.26473.499.camel@localhost.localdomain> Hi Lance, On Wed, 2006-01-18 at 19:12 +0000, Lance Haig wrote: > makemap hash /etc/mail/access < /etc/mail/access Is this a typo? - it should be: makemap hash /etc/mail/access.db < /etc/mail/access ^^^ If you are using a RPM style system - you could also just edit the /etc/mail/access then run 'make -C /etc/mail' and it will take care of everything for you :-) Cheers, Steve. From dhawal at netmagicsolutions.com Wed Jan 18 20:41:28 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Wed Jan 18 20:41:30 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: <43CEA47E.2020301@ecs.soton.ac.uk> References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> <43CE5A75.1000000@netmagicsolutions.com> <43CE5E24.6080103@netmagicsolutions.com> <43CE7706.8070909@netmagicsolutions.com> <43CE7D95.2040900@ecs.soton.ac.uk> <43CE825A.9030901@netmagicsolutions.com> <43CE9E7F.7010700@netmagicsolutions.com> <43CEA115.90800@ecs.soton.ac.uk> <43CEA47E.2020301@ecs.soton.ac.uk> Message-ID: <43CEA7F8.2020609@netmagicsolutions.com> Julian Field wrote: > Julian Field wrote: >> Dhawal Doshy wrote: >>> Dhawal Doshy wrote: >>>>>>>> Julian Field wrote: >>>>>>>>> -----BEGIN PGP SIGNED MESSAGE----- >>>>>>>>> >>>>>>>>> I have just released 4.50.9 which will decode the UU-encoded >>>>>>>>> file attached to these messages, so that the virus scanners >>>>>>>>> should all catch it, filename traps will work on the .scr file >>>>>>>>> inside the .bhx file, filetype traps will work on it too. >>>>>>>> >>>>>>>> Just successfully upgraded a couple of production servers.. >>>>>>> >>>>>>> I notice this in the logs.. >>>>>>> Jan 18 20:54:00 mx1 MailScanner[13545]: Infected message >>>>>>> 73CEF28ABDE.D9736 came from >>>>>>> >>>>>>> The IP address is blank :-(, i'll try and run this through the >>>>>>> debug sometime later. >>>>>> >>>>>> The debug mode didn't tell me anything (apart from the EOCD >>>>>> thingy).. how do i track this problem? >>>>>> >>> [SNIP] >>> This is getting wierder :([root@db ~]# tail -f /var/log/maillog | >>> grep "came from" >>> >>> Jan 19 01:29:37 mx2 MailScanner[24388]: Infected message >>> 740E4288309.62BC0 came from 210.18.63.180 >>> Jan 19 01:29:45 mx2 MailScanner[24388]: Infected message >>> 740E4288309.62BC0 came from >>> >>> Notice the duplication, now why would that happen? >> You get 1 line for each infection report. Not quite sure why I wrote >> it that way, but that's the reason. > I'll improve it so it only prints it once for each infected message. Thanks Julian, You are a lifesaver.. if it wasn't for mailscanner i'd still be struggling with amavis/qmail-scanner OR would have to depend on barracuda support for a living :-) Thanks again, - dhawal From Kevin_Miller at ci.juneau.ak.us Wed Jan 18 20:45:46 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Wed Jan 18 20:45:50 2006 Subject: Sendmail not relaying Message-ID: <82895A755D1EA5458EC9E64021922AD2D15608@city-exch-w3e.cbj.local> Steve Freegard wrote: > Hi Lance, > > On Wed, 2006-01-18 at 19:12 +0000, Lance Haig wrote: > >> makemap hash /etc/mail/access < /etc/mail/access > > Is this a typo? - it should be: > > makemap hash /etc/mail/access.db < /etc/mail/access > ^^^ > > If you are using a RPM style system - you could also just edit > the /etc/mail/access then run 'make -C /etc/mail' and it will take > care of everything for you :-) > > Cheers, > Steve. Nope, not a type. It's smart enough to know that and adds the .db itself. If one is in the /etc/mail directory the paths aren't even necessary. 'makemap hash access < access' works just fine. The additional bits can certainly give one a bit of a reality check as to what's actually happening although more characters also means more potential for typos. At least the way I type... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From KShortt at ussco.com Wed Jan 18 20:47:43 2006 From: KShortt at ussco.com (Shortt, Kevin) Date: Wed Jan 18 20:47:12 2006 Subject: Add procmail to the mix Message-ID: Rodney, This is what I do... My recipes are listed below the write up. I hope this helps. Let me know if you need any thing else. 1. Global procmail config backs up every piece of local email that hits my server into mbox format files on an hourly basis. 2. User procmailrc files filters tagged spam (by MailScanner) and places them into a /spam//-CCYY-MM-DD file. (One file for each day.) These files are accessible by each user with their email client by a sym link from their mail directory. i.e. Username is "joe". A quick list of their spam folder would look like this... -rw------- 1 joe staff 802964 Jan 13 23:02 joe-2006-01-13 -rw------- 1 joe staff 664589 Jan 14 23:41 joe-2006-01-14 -rw------- 1 joe staff 618340 Jan 15 23:45 joe-2006-01-15 -rw------- 1 joe staff 1141547 Jan 16 22:44 joe-2006-01-16 -rw------- 1 joe staff 809962 Jan 17 23:50 joe-2006-01-17 -rw------- 1 joe staff 197969 Jan 18 14:34 joe-2006-01-18 3. I have a three week purge of all files in that structure. This gives each user three weeks to sift through their spam folders for false positives. My recipies: Global rc file: # Make sure you rotate this file. LOGFILE=/var/log/procmail.log.system LOGABSTRACT=all HOURLY_DATE=`/bin/date +%Y-%m-%d-%H` #VERBOSE=off ##### # DO NOT REMOVE THIS RECIPE!!! # This backs up every incoming message. :0 c /backup/mail/incoming/$HOURLY_DATE ##### Typical User .procmailrc: SHELL=/bin/sh HOME=/home/joe MAILDIR=$HOME/Mail # You'd better make sure it exists DEFAULT=/var/spool/mail/joe # Make sure you are rotating this log. LOGFILE=$MAILDIR/procmail.log LOGABSTRACT=all VERBOSE=on LOCKFILE=$HOME/.lockmail SENDMAIL=/usr/sbin/sendmail # used only if you need to super-cede the spam filter recipe below. #INCLUDERC=$HOME/.procmail-preprocess USERNAME=joe SPAMFOLDER=/spam/joe DATE=`/usr/bin/date +%Y-%m-%d` HOURLY_DATE=`/usr/bin/date +%Y-%m-%d-%H` # These three lines sort the mail into the spam folder. Remove them to have it just in the inbox. :0: * ^X-MailScanner-SpamCheck: spam,.* $SPAMFOLDER/$USERNAME-$DATE # This recipe backs up all email that is not recognized as Spam. :0 c $MAILDIR/backup/$HOURLY_DATE From aslan at aeon.com.br Wed Jan 18 20:53:03 2006 From: aslan at aeon.com.br (Aslan Carlos) Date: Wed Jan 18 20:53:04 2006 Subject: Sendmail not relaying In-Reply-To: <1137616970.26473.499.camel@localhost.localdomain> References: <43CE9319.6070009@haigmail.com> <1137616970.26473.499.camel@localhost.localdomain> Message-ID: <200601181853.03813.aslan@aeon.com.br> On Wednesday 18 January 2006 18:42, Steve Freegard wrote: > Hi Lance, > > On Wed, 2006-01-18 at 19:12 +0000, Lance Haig wrote: > > makemap hash /etc/mail/access < /etc/mail/access > > Is this a typo? - it should be: > > makemap hash /etc/mail/access.db < /etc/mail/access HI, sometime, people make a change on sendmail.cf and not sendmail.mc, and create a big problem, I'd pass one that. AUTH actived on sendmail.cf , but on sendmail.mc not, when make -C /etc/mail, or than on simple make in path /etc/mail (Redhat Style), make this. Use the always makemap hash access < access and You'll make the access.db C'ya. sorry my poor English! > ^^^ > > If you are using a RPM style system - you could also just edit > the /etc/mail/access then run 'make -C /etc/mail' and it will take care > of everything for you :-) > > Cheers, > Steve. -- Aslan Carlos M. Ramos Aeon Technologies From dhawal at netmagicsolutions.com Wed Jan 18 21:01:28 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Wed Jan 18 21:01:39 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: <1137600999.26473.489.camel@localhost.localdomain> References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> <1137600999.26473.489.camel@localhost.localdomain> Message-ID: <43CEACA8.2040407@netmagicsolutions.com> Steve Freegard wrote: > On Wed, 2006-01-18 at 14:19 +0000, Julian Field wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> >> I have just released 4.50.9 which will decode the UU-encoded file >> attached to these messages, so that the virus scanners should all >> catch it, filename traps will work on the .scr file inside the .bhx >> file, filetype traps will work on it too. >> > > Further to this - I've installed 4.50.9 on the Fort Systems test box but > I do not have any examples of Worm.VB-8 to test it with. > > Please send your examples of this virus to virustest@fsg.com (DO NOT > send them to the list!!). > > You may then log-in to MailWatch on this system at > http://mail.fsg.com/mailscanner and use the username 'virustest@fsg.com' > with a password of 'guest' to see the messages being received. > > The system runs ClamAV 0.88 with Mail::ClamAV 0.17 and BitDefender - > I've also just manually run the virus scanner update. Done.. see http://mail.fsg.com/mailscanner/detail.php?id=k0IKuIGS015183 - dhawal From dhawal at netmagicsolutions.com Wed Jan 18 21:01:28 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Wed Jan 18 21:10:42 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: <1137600999.26473.489.camel@localhost.localdomain> References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> <1137600999.26473.489.camel@localhost.localdomain> Message-ID: <43CEACA8.2040407@netmagicsolutions.com> Steve Freegard wrote: > On Wed, 2006-01-18 at 14:19 +0000, Julian Field wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> >> I have just released 4.50.9 which will decode the UU-encoded file >> attached to these messages, so that the virus scanners should all >> catch it, filename traps will work on the .scr file inside the .bhx >> file, filetype traps will work on it too. >> > > Further to this - I've installed 4.50.9 on the Fort Systems test box but > I do not have any examples of Worm.VB-8 to test it with. > > Please send your examples of this virus to virustest@fsg.com (DO NOT > send them to the list!!). > > You may then log-in to MailWatch on this system at > http://mail.fsg.com/mailscanner and use the username 'virustest@fsg.com' > with a password of 'guest' to see the messages being received. > > The system runs ClamAV 0.88 with Mail::ClamAV 0.17 and BitDefender - > I've also just manually run the virus scanner update. Done.. see http://mail.fsg.com/mailscanner/detail.php?id=k0IKuIGS015183 - dhawal From jon.bates at summitmotors.com.au Wed Jan 18 21:57:15 2006 From: jon.bates at summitmotors.com.au (Jon Bates) Date: Wed Jan 18 21:57:39 2006 Subject: (no subject) In-Reply-To: <223f97700601180030s49f60503r@mail.gmail.com> Message-ID: <003701c61c7a$262821f0$0e64a8c0@jonlaptop> Yeah, sorry about that everyone. I stuffed up and sent that to the wrong address. No harm or funny business intended! -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Glenn Steen Sent: Wednesday, 18 January 2006 7:30 PM To: MailScanner discussion Subject: Re: (no subject) On 18/01/06, Jon Bates wrote: > > help > > > > > > Jon Bates > PC Support Technician > Summit Investment Australia Pty Ltd > E-mail: jon.bates@summitmotors.com.au Phone: (02) 8846-1292 > Mobile: 0400-381-030 020 > Ahem, Jon .... You are aware that most sensible people (like the subscribers to this list) won't look at the HTML fun you've had with your .sig .... They simply don't trust HTML in emails... (I'm one of those, but just had to look at this one:-) That has the result that your plain-text message looks pretty .... stoopid;) Anyone remember the fun one used to have with the .plan and .project? Many many years ago, I remember that "fingering" people would either give you a nice (ascii art) biplane going by, or giving you the finger (also in ascii art)... Ah VAX 11/7XX and BSD... Those were the days.... Not (this reminiscence is your fault Doc... got me thinking of times gone by:-) -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ----------- This message has been scanned for viruses and inappropriate content or attachments as deemed by Summit Investment Australia P/L and is believed to be clean. Although Summit Investment Australia has taken reasonable precautions to ensure no viruses are present in this email, the company cannot accept responsibility for any loss or damage arising from the use of this email or attachments. All messages scanned by MailScanner ----------- This message has been scanned for viruses and inappropriate content or attachments as deemed by Summit Investment Australia P/L and is believed to be clean. Although Summit Investment Australia has taken reasonable precautions to ensure no viruses are present in this email, the company cannot accept responsibility for any loss or damage arising from the use of this email or attachments. All messages scanned by MailScanner From MailScanner at ecs.soton.ac.uk Wed Jan 18 22:00:21 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Jan 18 22:00:31 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: <43CEA7F8.2020609@netmagicsolutions.com> References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> <43CE5A75.1000000@netmagicsolutions.com> <43CE5E24.6080103@netmagicsolutions.com> <43CE7706.8070909@netmagicsolutions.com> <43CE7D95.2040900@ecs.soton.ac.uk> <43CE825A.9030901@netmagicsolutions.com> <43CE9E7F.7010700@netmagicsolutions.com> <43CEA115.90800@ecs.soton.ac.uk> <43CEA47E.2020301@ecs.soton.ac.uk> <43CEA7F8.2020609@netmagicsolutions.com> Message-ID: <43CEBA75.5080309@ecs.soton.ac.uk> Dhawal Doshy wrote: > Julian Field wrote: >> Julian Field wrote: >>> Dhawal Doshy wrote: >>>> Dhawal Doshy wrote: >>>>>>>>> Julian Field wrote: >>>>>>>>>> -----BEGIN PGP SIGNED MESSAGE----- >>>>>>>>>> >>>>>>>>>> I have just released 4.50.9 which will decode the UU-encoded >>>>>>>>>> file attached to these messages, so that the virus scanners >>>>>>>>>> should all catch it, filename traps will work on the .scr >>>>>>>>>> file inside the .bhx file, filetype traps will work on it too. >>>>>>>>> >>>>>>>>> Just successfully upgraded a couple of production servers.. >>>>>>>> >>>>>>>> I notice this in the logs.. >>>>>>>> Jan 18 20:54:00 mx1 MailScanner[13545]: Infected message >>>>>>>> 73CEF28ABDE.D9736 came from >>>>>>>> >>>>>>>> The IP address is blank :-(, i'll try and run this through the >>>>>>>> debug sometime later. >>>>>>> >>>>>>> The debug mode didn't tell me anything (apart from the EOCD >>>>>>> thingy).. how do i track this problem? >>>>>>> >>>> [SNIP] >>>> This is getting wierder :([root@db ~]# tail -f /var/log/maillog | >>>> grep "came from" >>>> >>>> Jan 19 01:29:37 mx2 MailScanner[24388]: Infected message >>>> 740E4288309.62BC0 came from 210.18.63.180 >>>> Jan 19 01:29:45 mx2 MailScanner[24388]: Infected message >>>> 740E4288309.62BC0 came from >>>> >>>> Notice the duplication, now why would that happen? >>> You get 1 line for each infection report. Not quite sure why I wrote >>> it that way, but that's the reason. >> I'll improve it so it only prints it once for each infected message. > > Thanks Julian, > > You are a lifesaver.. if it wasn't for mailscanner i'd still be > struggling with amavis/qmail-scanner OR would have to depend on > barracuda support for a living :-) All donations are always gratefully received :-) -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From billvera at hotmail.com Wed Jan 18 22:12:20 2006 From: billvera at hotmail.com (Bill Vera) Date: Wed Jan 18 22:12:24 2006 Subject: remove In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D15608@city-exch-w3e.cbj.local> Message-ID: An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060118/8684ac77/attachment.html From dhawal at netmagicsolutions.com Wed Jan 18 22:12:43 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Wed Jan 18 22:12:43 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: <43CEA7F8.2020609@netmagicsolutions.com> References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> <43CE5A75.1000000@netmagicsolutions.com> <43CE5E24.6080103@netmagicsolutions.com> <43CE7706.8070909@netmagicsolutions.com> <43CE7D95.2040900@ecs.soton.ac.uk> <43CE825A.9030901@netmagicsolutions.com> <43CE9E7F.7010700@netmagicsolutions.com> <43CEA115.90800@ecs.soton.ac.uk> <43CEA47E.2020301@ecs.soton.ac.uk> <43CEA7F8.2020609@netmagicsolutions.com> Message-ID: <43CEBD5B.8030501@netmagicsolutions.com> Dhawal Doshy wrote: >>>>>>>>> Julian Field wrote: >>>>>>>>>> -----BEGIN PGP SIGNED MESSAGE----- >>>>>>>>>> >>>>>>>>>> I have just released 4.50.9 which will decode the UU-encoded >>>>>>>>>> file attached to these messages, so that the virus scanners >>>>>>>>>> should all catch it, filename traps will work on the .scr >>>>>>>>>> file inside the .bhx file, filetype traps will work on it too. >>>>>>>>> >>>>>>>>> Just successfully upgraded a couple of production servers.. >>>>>>>> >>>>>>>> I notice this in the logs.. >>>>>>>> Jan 18 20:54:00 mx1 MailScanner[13545]: Infected message >>>>>>>> 73CEF28ABDE.D9736 came from >>>>>>>> >>>>>>>> The IP address is blank :-(, i'll try and run this through the >>>>>>>> debug sometime later. >>>>>>> >>>>>>> The debug mode didn't tell me anything (apart from the EOCD >>>>>>> thingy).. how do i track this problem? Julian, I *might* have figured the error, here's the situation.. Notify Senders Of Viruses = no Notify Senders Of Blocked Filenames Or Filetypes = yes But filename.rules.conf has been modified to use deny+delete rather than simply deny. deny+delete \.pif$ - - deny+delete \.scr$ - - deny+delete \.cpl$ - - Yet MailScanner (i think) tries to send out a notification for the policy violation and yes.. this time being sent from localhost it obviously doesn't show the IP address. The problem is it goes into an endless loop post this situation of trying to send out the notification. Any ideas? - dhawal From glenn.steen at gmail.com Wed Jan 18 22:13:10 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Jan 18 22:13:13 2006 Subject: OT: HomeBrew Coffee was Re: Saving public keys from email messages In-Reply-To: <43CE99EC.7050905@hpmich.com> References: <10C29953-AE37-4D5A-8C31-5209508D0130@ecs.soton.ac.uk> <43CE800C.40001@Aeroflex.com> <223f97700601181115j69631cc1o@mail.gmail.com> <43CE99EC.7050905@hpmich.com> Message-ID: <223f97700601181413i137ce2e9g@mail.gmail.com> On 18/01/06, Ed Bruce wrote: > Glenn Steen wrote: > > If one is out for the real caffeine kick, one should always boil, not > > brew.... Tastes better too, provided you 1) make it strong enough > > (this is were the English/Americans usually fail... think mug-sized > > espresso, and you'll at least get close;) and 2) drink it literally > > boiling hot. That way it'll taste sublime and you'll not rot your gut > > with pesky tannins(sp?) > I guess that Englishman I worked with in Belgium was an aberation. One > cup of his brew and I was pretty much wired for the day :) Guess it depends on what oine is used to....;) > But I've got > to admit some of the best coffee I had was in Germany. And for some > reason they didn't server any coffee or tea in that teahouse in Belgium??? Well, I guess the Germans can do a passable brew.... Don't need to add instant coffee to the cup in Berlin, as I'm forced to do whilst in London...:-). I don't think you'd expect coffee in a coffeeshop in Amsterdam either, but perhaps a "space cookie":-). -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From michele at blacknight.ie Wed Jan 18 22:18:50 2006 From: michele at blacknight.ie (Michele Neylon:: Blacknight.ie) Date: Wed Jan 18 22:18:51 2006 Subject: remove In-Reply-To: References: Message-ID: <43CEBECA.70002@blacknight.ie> and reading the footer of the email is too hard for you? -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 From wietse at boudisque.nl Wed Jan 18 22:25:50 2006 From: wietse at boudisque.nl (Wietse Muizelaar) Date: Wed Jan 18 22:23:55 2006 Subject: Log "Always Looked Up Last" Message-ID: <02ab01c61c7e$2b653d70$630a0a0a@wietse> Hi, I installed the latest beta, and had one question about it: is there a reason that the log "Always Looked Up Last" took 0.00 seconds (or, as long as it took, ofcourse), had the quotes with it? Jan 18 23:02:07 boudams MailScanner[4658]: "Always Looked Up Last" took 0.00 seconds Jan 18 23:02:14 boudams MailScanner[4596]: "Always Looked Up Last" took 0.00 seconds Etc. Is it possible to remove those quotes? Or are they there for some reason I don't know? :) Thnx, Wietse From jon.bates at summitmotors.com.au Wed Jan 18 22:40:42 2006 From: jon.bates at summitmotors.com.au (Jon Bates) Date: Wed Jan 18 22:41:13 2006 Subject: remove In-Reply-To: <43CEBECA.70002@blacknight.ie> Message-ID: <004501c61c80$37182a40$0e64a8c0@jonlaptop> Cheers for the sarcastic remark. That was totally called for! -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Michele Neylon:: Blacknight.ie Sent: Thursday, 19 January 2006 9:19 AM To: MailScanner discussion Subject: Re: remove and reading the footer of the email is too hard for you? -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ----------- This message has been scanned for viruses and inappropriate content or attachments as deemed by Summit Investment Australia P/L and is believed to be clean. Although Summit Investment Australia has taken reasonable precautions to ensure no viruses are present in this email, the company cannot accept responsibility for any loss or damage arising from the use of this email or attachments. All messages scanned by MailScanner ----------- This message has been scanned for viruses and inappropriate content or attachments as deemed by Summit Investment Australia P/L and is believed to be clean. Although Summit Investment Australia has taken reasonable precautions to ensure no viruses are present in this email, the company cannot accept responsibility for any loss or damage arising from the use of this email or attachments. All messages scanned by MailScanner From james at grayonline.id.au Wed Jan 18 21:45:45 2006 From: james at grayonline.id.au (James Gray) Date: Wed Jan 18 22:56:27 2006 Subject: OT: Add procmail to the mix In-Reply-To: <43CE7411.6010903@trayerproducts.com> References: <43CE7411.6010903@trayerproducts.com> Message-ID: <200601190845.50026.james@grayonline.id.au> On Thursday 19 January 2006 04:00, Rodney Green wrote: > Hello, > > I'm using Postfix as my MTA along with MailScanner and SpamAssassin. I'm > wondering how I could add procmail into the mix so users can have their > own spam mailbox. Can someone please give me some ideas on how procmail > can be used? It's easy - just write a .procmailrc recipe for the users and dump it in their home directories. Once the mail reaches procmail, MailScanner is well and truly finished with it. I have a few users that wrote their own procmail recipes and the fact the mail is initially parsed by MailScanner in no way affects them being able to use procmail. Not sure how this all fits with virtual users/domains; my procmail users are all "real". HTH James -- "Open the pod bay doors, HAL." -- Dave Bowman, 2001 -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060119/c8103326/attachment.bin From paul at blacknight.ie Wed Jan 18 23:02:41 2006 From: paul at blacknight.ie (Paul Kelly :: Blacknight) Date: Wed Jan 18 23:02:41 2006 Subject: Sendmail not relaying In-Reply-To: <43CE9319.6070009@haigmail.com> References: <43CE9319.6070009@haigmail.com> Message-ID: <1137625362.22303.2.camel@localhost.localdomain> Hi there, On Wed, 2006-01-18 at 19:12 +0000, Lance Haig wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Guys I have hit a snag. > > I have configured a new set of domains and have configured the > mailertable needed. > relay-domains > not needed. I'm presuming that its a mail gateway? If so the only place domains should be added is the mailertable file. > I have added the domains to the access file > domain RELAY Remove. > > and the sending IP of the mailserver > ipaddress RELAY > Are you filtering outbound email aswell? If not remove this, if so leave it in. Access.db is for allowing mail servers/people to relay through you or to block them etc. mailertable defines the end point mailserver for the domain that is to be scanned. > When I try to send a mail to a domain outside the Mailscanner machine it > says relaying denied. > > I have tried this command on the access file > > makemap hash /etc/mail/access < /etc/mail/access > > but is still does not want to allow the mailserver to relay e-mail. > I think that is your problem. Remove the entries from access db and you should be set. Paul -- Paul Kelly Technical Director Blacknight Internet Solutions ltd Hosting, Colocation, Dedicated servers Tel: 059 9183072 DDI: 059 9183091 e-mail: paul@blacknight.ie From ryanb at aacrao.org Thu Jan 19 02:01:19 2006 From: ryanb at aacrao.org (Bingham, Ryan) Date: Thu Jan 19 02:01:26 2006 Subject: bayes autolearn stopped working Message-ID: Hi All, I recently upgraded from MailScanner 4.48.4-2 to 4.49.7-1 and also upgraded to SpamAssassin 3.10 at the same time. Before the upgrades, Bayes autolearning worked just fine. None of the autolearn settings in spam.assassin.prefs.conf have changed, but now autolearn refuses to, well, autolearn. Has anyone had this problem or have any ideas what the cause could be? Thanks, Ryan -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060118/1e4896fd/attachment.html From Jeff.Mills at versacold.com.au Thu Jan 19 02:40:28 2006 From: Jeff.Mills at versacold.com.au (Jeff Mills) Date: Thu Jan 19 02:40:39 2006 Subject: Virus still being picked up an hour later Message-ID: <197F21E06E4D2A478519EA9078D6AA1C01B0AC3B@poclexch.AU.POCOLD.POCL> Hi all, I have a problem with mailscanner where it doesnt seem to be getting rid of a virus from the filesystem once its found. Heres an example: Below is the first instance. Jan 19 12:35:22 proxy2 MailScanner[27476]: /var/spool/MailScanner/incoming/27476/./6BCB544E5D5.ED322/eBook.PIF: Worm.VB-8 FOUND Sometimes (but not every time) mailscanner also picks up the bad filename. Jan 19 12:35:22 proxy2 MailScanner[27476]: Filename Checks: Possible MS-Dos program shortcut attack (6BCB544E5D5.ED322 eBook.PIF) As of this moment, mailscanner is still picking up this same instance (1 hour later) Jan 19 13:35:04 proxy2 MailScanner[27476]: /var/spool/MailScanner/incoming/27476/./6BCB544E5D5.ED322/eBook.PIF: Worm.VB-8 FOUND Any idea why this might be happening? My mailscanner version: ?/opt/MailScanner/bin/MailScanner --version Running on Linux SMP PREEMPT Wed Nov 16 15:16:39 EST 2005 i686 Intel(R) Xeon(TM) CPU 2.00GHz GenuineIntel GNU/Linux This is Perl version 5.008007 (5.8.7) This is MailScanner version 4.50.4 Module versions are: 1.00 AnyDBM_File 1.14 Archive::Zip 1.04 Carp 1.119 Convert::BinHex 1.00 DirHandle 1.05 Fcntl 2.73 File::Basename 2.08 File::Copy 2.01 FileHandle 1.07 File::Path 0.16 File::Temp 1.29 HTML::Entities 3.45 HTML::Parser 2.30 HTML::TokeParser 1.21 IO 1.11 IO::File 1.123 IO::Pipe 1.50 Mail::Header 3.05 MIME::Base64 5.415 MIME::Decoder 5.415 MIME::Decoder::UU 5.415 MIME::Head 5.415 MIME::Parser 3.03 MIME::QuotedPrint 5.415 MIME::Tools 0.11 Net::CIDR 1.08 POSIX 1.77 Socket 0.06 Sys::Syslog 1.02 Time::localtime Optional module versions are: 0.17 Convert::TNEF 1.814 DB_File 1.13 Digest 1.01 Digest::HMAC 2.33 Digest::MD5 2.10 Digest::SHA1 missing Inline missing Mail::ClamAV 3.001000 Mail::SpamAssassin missing Mail::SPF::Query missing Net::CIDR::Lite 0.53 Net::DNS 0.32 Net::LDAP missing Parse::RecDescent missing SAVI missing Sys::Hostname::Long 2.42 Test::Harness 0.62 Test::Simple 1.95 Text::Balanced 1.35 URI *** "This company is now part of the Versacold Holdings Corp. and is no longer owned by or affiliated with the P&O Group" *** ************** www.versacold.com ************** From dhawal at netmagicsolutions.com Thu Jan 19 03:00:06 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Thu Jan 19 03:00:20 2006 Subject: Virus still being picked up an hour later In-Reply-To: <197F21E06E4D2A478519EA9078D6AA1C01B0AC3B@poclexch.AU.POCOLD.POCL> References: <197F21E06E4D2A478519EA9078D6AA1C01B0AC3B@poclexch.AU.POCOLD.POCL> Message-ID: <43CF00B6.50508@netmagicsolutions.com> Jeff Mills wrote: > Hi all, > > I have a problem with mailscanner where it doesnt seem to be getting rid of a virus from the filesystem once its found. > Heres an example: > Below is the first instance. > Jan 19 12:35:22 proxy2 MailScanner[27476]: /var/spool/MailScanner/incoming/27476/./6BCB544E5D5.ED322/eBook.PIF: Worm.VB-8 FOUND > > Sometimes (but not every time) mailscanner also picks up the bad filename. > Jan 19 12:35:22 proxy2 MailScanner[27476]: Filename Checks: Possible MS-Dos program shortcut attack (6BCB544E5D5.ED322 eBook.PIF) > > As of this moment, mailscanner is still picking up this same instance (1 hour later) > Jan 19 13:35:04 proxy2 MailScanner[27476]: /var/spool/MailScanner/incoming/27476/./6BCB544E5D5.ED322/eBook.PIF: Worm.VB-8 FOUND > > Any idea why this might be happening? This is precisely what i have been unsuccessfully trying to convey all evening to Julian.. somehow no else seemed to be in this situation.. Here's what i observed.. all files (even legit ones) continue to be lying in the MailScanner incoming directory (within their respective PID directory) and do NOT get deleted post batch processing.. as a result MailScanner keeps on checking them again and again.. I am at a loss to take it any forward, since i haven't slept all night long trying to figure out the reason.. :-( - dhawal > My mailscanner version: > ?/opt/MailScanner/bin/MailScanner --version > Running on > Linux SMP PREEMPT Wed Nov 16 15:16:39 EST 2005 i686 Intel(R) Xeon(TM) CPU 2.00GHz GenuineIntel GNU/Linux > This is Perl version 5.008007 (5.8.7) > > This is MailScanner version 4.50.4 > Module versions are: > 1.00 AnyDBM_File > 1.14 Archive::Zip > 1.04 Carp > 1.119 Convert::BinHex > 1.00 DirHandle > 1.05 Fcntl > 2.73 File::Basename > 2.08 File::Copy > 2.01 FileHandle > 1.07 File::Path > 0.16 File::Temp > 1.29 HTML::Entities > 3.45 HTML::Parser > 2.30 HTML::TokeParser > 1.21 IO > 1.11 IO::File > 1.123 IO::Pipe > 1.50 Mail::Header > 3.05 MIME::Base64 > 5.415 MIME::Decoder > 5.415 MIME::Decoder::UU > 5.415 MIME::Head > 5.415 MIME::Parser > 3.03 MIME::QuotedPrint > 5.415 MIME::Tools > 0.11 Net::CIDR > 1.08 POSIX > 1.77 Socket > 0.06 Sys::Syslog > 1.02 Time::localtime > > Optional module versions are: > 0.17 Convert::TNEF > 1.814 DB_File > 1.13 Digest > 1.01 Digest::HMAC > 2.33 Digest::MD5 > 2.10 Digest::SHA1 > missing Inline > missing Mail::ClamAV > 3.001000 Mail::SpamAssassin > missing Mail::SPF::Query > missing Net::CIDR::Lite > 0.53 Net::DNS > 0.32 Net::LDAP > missing Parse::RecDescent > missing SAVI > missing Sys::Hostname::Long > 2.42 Test::Harness > 0.62 Test::Simple > 1.95 Text::Balanced > 1.35 URI From nerijus at users.sourceforge.net Thu Jan 19 03:07:17 2006 From: nerijus at users.sourceforge.net (Nerijus Baliunas) Date: Thu Jan 19 03:10:06 2006 Subject: remove In-Reply-To: <004501c61c80$37182a40$0e64a8c0@jonlaptop> References: <004501c61c80$37182a40$0e64a8c0@jonlaptop> Message-ID: <20060119031053.0DFBDBC7F@mx.dtiltas.lt> I've just yesterday read what I liked a lot :) : There's an old saying: unsubscribing from a mailing list that you previously subscribed to is a basic intelligence test on the Internet. On Thu, 19 Jan 2006 09:40:42 +1100 Jon Bates wrote: > Cheers for the sarcastic remark. That was totally called for! > > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Michele > Neylon:: Blacknight.ie > Sent: Thursday, 19 January 2006 9:19 AM > To: MailScanner discussion > Subject: Re: remove > > and reading the footer of the email is too hard for you? From Jeff.Mills at versacold.com.au Thu Jan 19 03:17:55 2006 From: Jeff.Mills at versacold.com.au (Jeff Mills) Date: Thu Jan 19 03:18:00 2006 Subject: Virus still being picked up an hour later Message-ID: <197F21E06E4D2A478519EA9078D6AA1C01B0AC3D@poclexch.AU.POCOLD.POCL> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Dhawal > Doshy > Sent: Thursday, 19 January 2006 2:00 PM > To: MailScanner discussion > Subject: Re: Virus still being picked up an hour later > > > This is precisely what i have been unsuccessfully trying to > convey all > evening to Julian.. somehow no else seemed to be in this situation.. > > Here's what i observed.. all files (even legit ones) continue to be > lying in the MailScanner incoming directory (within their > respective PID > directory) and do NOT get deleted post batch processing.. as a result > MailScanner keeps on checking them again and again.. > > I am at a loss to take it any forward, since i haven't slept > all night > long trying to figure out the reason.. :-( > > - dhawal > I hadnt noticed mine scanning clean messages again, but you could be right. When I check my incoming dir for that process, there are alot of directories in there - all dated today, and all with a time after I first saw this problem. So maybe once this problem rears its head, no more mail processed by this process gets deleted? *** "This company is now part of the Versacold Holdings Corp. and is no longer owned by or affiliated with the P&O Group" *** ************** www.versacold.com ************** From MailScanner at ecs.soton.ac.uk Thu Jan 19 08:53:05 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 19 08:53:14 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: <43CEBD5B.8030501@netmagicsolutions.com> References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> <43CE5A75.1000000@netmagicsolutions.com> <43CE5E24.6080103@netmagicsolutions.com> <43CE7706.8070909@netmagicsolutions.com> <43CE7D95.2040900@ecs.soton.ac.uk> <43CE825A.9030901@netmagicsolutions.com> <43CE9E7F.7010700@netmagicsolutions.com> <43CEA115.90800@ecs.soton.ac.uk> <43CEA47E.2020301@ecs.soton.ac.uk> <43CEA7F8.2020609@netmagicsolutions.com> <43CEBD5B.8030501@netmagicsolutions.com> Message-ID: <91442C0A-22E0-45B3-BA2A-3647FEE16C34@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- On 18 Jan 2006, at 22:12, Dhawal Doshy wrote: > Dhawal Doshy wrote: >>>>>>>>>> Julian Field wrote: >>>>>>>>>>> -----BEGIN PGP SIGNED MESSAGE----- >>>>>>>>>>> >>>>>>>>>>> I have just released 4.50.9 which will decode the UU- >>>>>>>>>>> encoded file attached to these messages, so that the >>>>>>>>>>> virus scanners should all catch it, filename traps will >>>>>>>>>>> work on the .scr file inside the .bhx file, filetype >>>>>>>>>>> traps will work on it too. >>>>>>>>>> >>>>>>>>>> Just successfully upgraded a couple of production servers.. >>>>>>>>> >>>>>>>>> I notice this in the logs.. >>>>>>>>> Jan 18 20:54:00 mx1 MailScanner[13545]: Infected message >>>>>>>>> 73CEF28ABDE.D9736 came from >>>>>>>>> >>>>>>>>> The IP address is blank :-(, i'll try and run this through >>>>>>>>> the debug sometime later. >>>>>>>> >>>>>>>> The debug mode didn't tell me anything (apart from the EOCD >>>>>>>> thingy).. how do i track this problem? > > Julian, > > I *might* have figured the error, here's the situation.. > > Notify Senders Of Viruses = no > Notify Senders Of Blocked Filenames Or Filetypes = yes > > But filename.rules.conf has been modified to use deny+delete rather > than simply deny. > deny+delete \.pif$ - - > deny+delete \.scr$ - - > deny+delete \.cpl$ - - > > Yet MailScanner (i think) tries to send out a notification for the > policy violation and yes.. this time being sent from localhost it > obviously doesn't show the IP address. The problem is it goes into > an endless loop post this situation of trying to send out the > notification. Any ideas? I don't understand your explanation. Are you saying that MailScanner gets stuck in an endless loop? - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ89TdPw32o+k+q+hAQH65wf/WqALqA0StDI/N1ZTL9q5QJIwb5u4fI2D yy0mdpgbbaJ4ZxTH/pNWDW4Ng+Upoaq/t2W8AwQ+1LGWce4toLPxpOmj2gvGf/L2 kkivTdtwnwNYsD1FhUFoXuuAlA5TDKXk3w6i5mbkJo6BNhkYH0hcgrFKnl0aYy9d mZmn9SDRRSwwbvJ9/Xgu6Ms1+RttRofPIcIIsaiqiLovtYjX+GEdkYVwu7D/l4vM bMVyjUisr27WKZyY6T+7OCThD/aABjCBQ30a6cYRt2FTmZP25S2fzXVZ6cg19vJ4 AccD4fEwCN3q6gYN8w0NMePsJdEZxzWHqJWEq0gpKaltQtxT5Xxk/g== =H8Vi -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Thu Jan 19 08:55:30 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 19 08:55:40 2006 Subject: Log "Always Looked Up Last" In-Reply-To: <02ab01c61c7e$2b653d70$630a0a0a@wietse> References: <02ab01c61c7e$2b653d70$630a0a0a@wietse> Message-ID: <5610539E-5911-4F65-A4F2-D2DD67648A5B@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- On 18 Jan 2006, at 22:25, Wietse Muizelaar wrote: > Hi, > > I installed the latest beta, and had one question about it: > is there a reason that the log "Always Looked Up Last" took 0.00 > seconds > (or, as long as it took, ofcourse), had the quotes with it? > > Jan 18 23:02:07 boudams MailScanner[4658]: "Always Looked Up Last" > took 0.00 > seconds > Jan 18 23:02:14 boudams MailScanner[4596]: "Always Looked Up Last" > took 0.00 > seconds > > Etc. Is it possible to remove those quotes? Or are they there for some > reason I don't know? :) That's just because it is the name of the configuration option it is looking up. Why not have the quotes? Do they cause you some problem? - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ89UBfw32o+k+q+hAQFQ5Af+O51ceU4zMAriLO+dw0Qx0tOY1ENGAmh7 0E8E9Puk0goxW4yZe5AuDR6FrUZ00ChBREZaH5x/MRjUjmDbogDULUuYtypMfk5A XKD6bGv/V0SOtsGe75a1ECPmfjYZa2tajLQoxS4dPh9/h8qeVSRxRLOt+3nX0seQ 6zzLuc/XvXeqG6MJLXkR1BeYVM3+Gakq6tOOe4QQAlNeJHAU+aUPF3e1XDEcKt5O ytxoGM3A/Up9xBqAL97HAlIvCeBLL2g+OszSKhc+Mu59pbR+cmUooK21jS5HTqCA iX8L2QKtkXRSN6WEt1Qj3pmyfWQ0nLCdK+EVvVrKYzQxJmyEFyG13w== =nnQi -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Thu Jan 19 08:59:15 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 19 08:59:26 2006 Subject: Virus still being picked up an hour later In-Reply-To: <197F21E06E4D2A478519EA9078D6AA1C01B0AC3D@poclexch.AU.POCOLD.POCL> References: <197F21E06E4D2A478519EA9078D6AA1C01B0AC3D@poclexch.AU.POCOLD.POCL> Message-ID: <2413DAE9-6C39-47BF-9F65-86192F48AE1E@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- On 19 Jan 2006, at 03:17, Jeff Mills wrote: > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of >> Dhawal >> Doshy >> Sent: Thursday, 19 January 2006 2:00 PM >> To: MailScanner discussion >> Subject: Re: Virus still being picked up an hour later >> > >> >> This is precisely what i have been unsuccessfully trying to >> convey all >> evening to Julian.. somehow no else seemed to be in this situation.. >> >> Here's what i observed.. all files (even legit ones) continue to be >> lying in the MailScanner incoming directory (within their >> respective PID >> directory) and do NOT get deleted post batch processing.. as a result >> MailScanner keeps on checking them again and again.. >> >> I am at a loss to take it any forward, since i haven't slept >> all night >> long trying to figure out the reason.. :-( >> >> - dhawal >> > > I hadnt noticed mine scanning clean messages again, but you could > be right. > When I check my incoming dir for that process, there are alot of > directories in there - all dated today, and all with a time after I > first saw this problem. > So maybe once this problem rears its head, no more mail processed > by this process gets deleted? Right, I understand the symptom now. What configuration option do you think is causing it? What MTA are you using? Have you run MailScanner in debug mode to see what it prints when this happens? - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ89U5fw32o+k+q+hAQEd5Qf+NfdqgV+xgfnAXCremq84iM5aX1wEN+Ii Iit0kweyjThDmfZNYgiTFek+U0EXPga7Jn9MVy+hTurkoAEZEqEi17h86/Qv+A2D 0LVXSgRKnsbq/8bwggq+7CzGZHXt/BN8RiGOCBg5rgQ8YrfpzFDlq1IywQ07SOz6 9Pg5PIsgVN0kYSFBx31WlkxeLUirGBZc9j2bd5d0vfDAWeablnPP76v82WyMjoE8 +RVJOcblAIgucybUZe7ns6u9zxi4jot/xauTJQglOsrTLAYjt+O1RtYcPQ9tFVhG Ed7r69I4VjH4aKCjmIa0B6z3nzWKyMDSDvlVI44y3PmWYrHgqtPk7g== =DIco -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From dhawal at netmagicsolutions.com Thu Jan 19 09:04:02 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Thu Jan 19 09:04:02 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: <91442C0A-22E0-45B3-BA2A-3647FEE16C34@ecs.soton.ac.uk> References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> <43CE5A75.1000000@netmagicsolutions.com> <43CE5E24.6080103@netmagicsolutions.com> <43CE7706.8070909@netmagicsolutions.com> <43CE7D95.2040900@ecs.soton.ac.uk> <43CE825A.9030901@netmagicsolutions.com> <43CE9E7F.7010700@netmagicsolutions.com> <43CEA115.90800@ecs.soton.ac.uk> <43CEA47E.2020301@ecs.soton.ac.uk> <43CEA7F8.2020609@netmagicsolutions.com> <43CEBD5B.8030501@netmagicsolutions.com> <91442C0A-22E0-45B3-BA2A-3647FEE16C34@ecs.soton.ac.uk> Message-ID: <43CF5602.4070000@netmagicsolutions.com> Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > > On 18 Jan 2006, at 22:12, Dhawal Doshy wrote: > >> Dhawal Doshy wrote: >>>>>>>>>>> Julian Field wrote: >>>>>>>>>>>> -----BEGIN PGP SIGNED MESSAGE----- >>>>>>>>>>>> >>>>>>>>>>>> I have just released 4.50.9 which will decode the UU- >>>>>>>>>>>> encoded file attached to these messages, so that the >>>>>>>>>>>> virus scanners should all catch it, filename traps will >>>>>>>>>>>> work on the .scr file inside the .bhx file, filetype >>>>>>>>>>>> traps will work on it too. >>>>>>>>>>> Just successfully upgraded a couple of production servers.. >>>>>>>>>> I notice this in the logs.. >>>>>>>>>> Jan 18 20:54:00 mx1 MailScanner[13545]: Infected message >>>>>>>>>> 73CEF28ABDE.D9736 came from >>>>>>>>>> >>>>>>>>>> The IP address is blank :-(, i'll try and run this through >>>>>>>>>> the debug sometime later. >>>>>>>>> The debug mode didn't tell me anything (apart from the EOCD >>>>>>>>> thingy).. how do i track this problem? >> Julian, >> >> I *might* have figured the error, here's the situation.. >> >> Notify Senders Of Viruses = no >> Notify Senders Of Blocked Filenames Or Filetypes = yes >> >> But filename.rules.conf has been modified to use deny+delete rather >> than simply deny. >> deny+delete \.pif$ - - >> deny+delete \.scr$ - - >> deny+delete \.cpl$ - - >> >> Yet MailScanner (i think) tries to send out a notification for the >> policy violation and yes.. this time being sent from localhost it >> obviously doesn't show the IP address. The problem is it goes into >> an endless loop post this situation of trying to send out the >> notification. Any ideas? > > I don't understand your explanation. Are you saying that MailScanner > gets stuck in an endless loop? [root@mx1 MailScanner]# find /var/spool/MailScanner/incoming/ -type f | wc -l 3402 [root@mx1 MailScanner]# find /var/spool/postfix/hold/ -type f | wc -l 57 Nothing from mailscanner incoming workdir gets deleted.. and hence it continues processing the message again and again.. - dhawal From dhawal at netmagicsolutions.com Thu Jan 19 09:09:30 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Thu Jan 19 09:09:43 2006 Subject: Virus still being picked up an hour later In-Reply-To: <2413DAE9-6C39-47BF-9F65-86192F48AE1E@ecs.soton.ac.uk> References: <197F21E06E4D2A478519EA9078D6AA1C01B0AC3D@poclexch.AU.POCOLD.POCL> <2413DAE9-6C39-47BF-9F65-86192F48AE1E@ecs.soton.ac.uk> Message-ID: <43CF574A.3090402@netmagicsolutions.com> Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > > On 19 Jan 2006, at 03:17, Jeff Mills wrote: > >>> -----Original Message----- >>> From: mailscanner-bounces@lists.mailscanner.info >>> [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of >>> Dhawal >>> Doshy >>> Sent: Thursday, 19 January 2006 2:00 PM >>> To: MailScanner discussion >>> Subject: Re: Virus still being picked up an hour later >>> >>> This is precisely what i have been unsuccessfully trying to >>> convey all >>> evening to Julian.. somehow no else seemed to be in this situation.. >>> >>> Here's what i observed.. all files (even legit ones) continue to be >>> lying in the MailScanner incoming directory (within their >>> respective PID >>> directory) and do NOT get deleted post batch processing.. as a result >>> MailScanner keeps on checking them again and again.. >>> >>> I am at a loss to take it any forward, since i haven't slept >>> all night >>> long trying to figure out the reason.. :-( >>> >>> - dhawal >>> >> I hadnt noticed mine scanning clean messages again, but you could >> be right. >> When I check my incoming dir for that process, there are alot of >> directories in there - all dated today, and all with a time after I >> first saw this problem. >> So maybe once this problem rears its head, no more mail processed >> by this process gets deleted? > > Right, I understand the symptom now. What configuration option do you > think is causing it? What MTA are you using? > > Have you run MailScanner in debug mode to see what it prints when > this happens? Postfix 2.2.5, here's the mailscanner extract from a debug batch Jan 19 08:41:41 mx2 MailScanner[16198]: MailScanner E-Mail Virus Scanner version 4.50.9 starting... Jan 19 08:41:41 mx2 MailScanner[16198]: Read 697 hostnames from the phishing whitelist Jan 19 08:41:41 mx2 MailScanner[16198]: Config: calling custom init function SQLBlacklist Jan 19 08:41:41 mx2 MailScanner[16198]: Starting up SQL Blacklist Jan 19 08:41:41 mx2 MailScanner[16198]: Read 109 blacklist entries Jan 19 08:41:41 mx2 MailScanner[16198]: Config: calling custom init function MailWatchLogging Jan 19 08:41:41 mx2 MailScanner[16198]: Started SQL Logging child Jan 19 08:41:41 mx2 MailScanner[16198]: Config: calling custom init function SQLWhitelist Jan 19 08:41:41 mx2 MailScanner[16198]: Starting up SQL Whitelist Jan 19 08:41:41 mx2 MailScanner[16198]: Read 36 whitelist entries Jan 19 08:41:41 mx2 MailScanner[16198]: Using SpamAssassin results cache Jan 19 08:41:41 mx2 MailScanner[16198]: Connected to SpamAssassin cache database Jan 19 08:41:42 mx2 MailScanner[16198]: Expired 81 records from the SpamAssassin cache Jan 19 08:41:48 mx2 MailScanner[16198]: lock.pl sees Config LockType = flock Jan 19 08:41:48 mx2 MailScanner[16198]: lock.pl sees have_module = 0 Jan 19 08:41:48 mx2 MailScanner[16198]: Using locktype = flock Jan 19 08:41:48 mx2 MailScanner[16198]: New Batch: Scanning 9 messages, 562949 bytes Jan 19 08:41:48 mx2 MailScanner[16198]: Created attachment dirs for 9 messages Jan 19 08:41:48 mx2 MailScanner[16198]: MCP Checks completed at 1200396157 bytes per second Jan 19 08:41:48 mx2 MailScanner[16198]: Spam Checks: Starting Jan 19 08:41:48 mx2 MailScanner[16198]: SpamAssassin cache hit for message 18962288609.B799A Jan 19 08:41:48 mx2 MailScanner[16198]: Message 18962288609.B799A from 221.160.246.58 (floydmcgowanwb@mindspring.com) to xxx.com is spam, SpamAssassin (score=16.037, required 5, BAYES_99 4.00, DATE_IN_FUTURE_12_24 3.03, DCC_CHECK 2.17, MIME_BASE64_TEXT 0.30, SARE_OBFU_NUMS3a 0.97, SARE_OBFU_NUMS3b 1.28, SARE_OBFU_NUMS3c 1.26, SARE_OBFU_NUMS3d 1.37, SARE_RECV_IP_061052 1.67) Jan 19 08:41:48 mx2 MailScanner[16198]: SpamAssassin cache hit for message E91632885B3.39157 Jan 19 08:41:48 mx2 MailScanner[16198]: SpamAssassin cache hit for message C4A1A2885BE.E137B Jan 19 08:41:48 mx2 MailScanner[16198]: Message C4A1A2885BE.E137B from 219.156.95.47 (rufusm.bradleylp@jhaweb.com) to xxxx.com is spam, SpamAssassin (score=16.037, required 5, BAYES_99 4.00, DATE_IN_FUTURE_12_24 3.03, DCC_CHECK 2.17, MIME_BASE64_TEXT 0.30, SARE_OBFU_NUMS3a 0.97, SARE_OBFU_NUMS3b 1.28, SARE_OBFU_NUMS3c 1.26, SARE_OBFU_NUMS3d 1.37, SARE_RECV_IP_061052 1.67) Jan 19 08:41:52 mx2 MailScanner[16198]: SpamAssassin returned 0 Jan 19 08:41:52 mx2 MailScanner[16198]: SpamAssassin cache hit for message 6211A2885D1.3EBEA Jan 19 08:41:52 mx2 MailScanner[16198]: Message 6211A2885D1.3EBEA from 59.19.19.120 (wilmacassidyua@knsacs.com) to xxxx.com is spam, SpamAssassin (score=16.037, required 5, BAYES_99 4.00, DATE_IN_FUTURE_12_24 3.03, DCC_CHECK 2.17, MIME_BASE64_TEXT 0.30, SARE_OBFU_NUMS3a 0.97, SARE_OBFU_NUMS3b 1.28, SARE_OBFU_NUMS3c 1.26, SARE_OBFU_NUMS3d 1.37, SARE_RECV_IP_061052 1.67) Jan 19 08:41:52 mx2 MailScanner[16198]: SpamAssassin cache hit for message 796AD28860B.B2A37 Jan 19 08:41:52 mx2 MailScanner[16198]: Message 796AD28860B.B2A37 from 222.132.40.221 (forresttr@execpc.com) to xxxx.com is spam, SpamAssassin (score=16.037, required 5, BAYES_99 4.00, DATE_IN_FUTURE_12_24 3.03, DCC_CHECK 2.17, MIME_BASE64_TEXT 0.30, SARE_OBFU_NUMS3a 0.97, SARE_OBFU_NUMS3b 1.28, SARE_OBFU_NUMS3c 1.26, SARE_OBFU_NUMS3d 1.37, SARE_RECV_IP_061052 1.67) Jan 19 08:41:52 mx2 MailScanner[16198]: SpamAssassin cache hit for message E7B612885B2.605FA Jan 19 08:41:52 mx2 MailScanner[16198]: SpamAssassin cache hit for message 986B62885B5.DE050 Jan 19 08:41:52 mx2 MailScanner[16198]: SpamAssassin cache hit for message 1B89C2885D0.D3F07 Jan 19 08:41:52 mx2 MailScanner[16198]: Message 1B89C2885D0.D3F07 from 219.135.96.106 (c.contrerasek@larsonengineering.com) to xxxx.com is spam, SpamAssassin (score=16.037, required 5, BAYES_99 4.00, DATE_IN_FUTURE_12_24 3.03, DCC_CHECK 2.17, MIME_BASE64_TEXT 0.30, SARE_OBFU_NUMS3a 0.97, SARE_OBFU_NUMS3b 1.28, SARE_OBFU_NUMS3c 1.26, SARE_OBFU_NUMS3d 1.37, SARE_RECV_IP_061052 1.67) Jan 19 08:41:52 mx2 MailScanner[16198]: Spam Checks: Found 5 spam messages Jan 19 08:41:52 mx2 MailScanner[16198]: Spam Actions: message 18962288609.B799A actions are store Jan 19 08:41:52 mx2 MailScanner[16198]: Spam Actions: message C4A1A2885BE.E137B actions are store Jan 19 08:41:52 mx2 MailScanner[16198]: Spam Actions: message 6211A2885D1.3EBEA actions are store Jan 19 08:41:52 mx2 MailScanner[16198]: Spam Actions: message 796AD28860B.B2A37 actions are store Jan 19 08:41:52 mx2 MailScanner[16198]: Spam Actions: message 1B89C2885D0.D3F07 actions are store Jan 19 08:41:52 mx2 MailScanner[16198]: Spam Checks completed at 130236 bytes per second Jan 19 08:41:52 mx2 MailScanner[16198]: Virus and Content Scanning: Starting Jan 19 08:41:52 mx2 MailScanner[16198]: Commencing scanning by clamavmodule... Jan 19 08:41:53 mx2 MailScanner[16198]: Completed scanning by clamavmodule Jan 19 08:41:53 mx2 MailScanner[16198]: Commencing scanning by mcafee... Jan 19 08:41:53 mx2 MailScanner[16198]: Completed scanning by mcafee Jan 19 08:41:53 mx2 MailScanner[16198]: Commencing scanning by bitdefender... Jan 19 08:41:54 mx2 MailScanner[16198]: Completed scanning by bitdefender Jan 19 08:41:54 mx2 MailScanner[16198]: Virus Scanning completed at 256145 bytes per second Jan 19 08:41:54 mx2 MailScanner[16198]: Requeue: E91632885B3.39157 to 32306288198 Jan 19 08:41:54 mx2 MailScanner[16198]: Requeue: F16ED28805B.F2283 to 65296288199 Jan 19 08:41:54 mx2 MailScanner[16198]: Requeue: E7B612885B2.605FA to 90C9428805B Jan 19 08:41:55 mx2 MailScanner[16198]: Requeue: 986B62885B5.DE050 to 31B6128819A Jan 19 08:41:55 mx2 MailScanner[16198]: About to deliver 4 messages Jan 19 08:41:55 mx2 MailScanner[16198]: Uninfected: Delivered 4 messages Jan 19 08:41:55 mx2 MailScanner[16198]: Virus Processing completed at 2172893 bytes per second Jan 19 08:41:55 mx2 MailScanner[16198]: Disinfection completed at -411448806 bytes per second Jan 19 08:41:55 mx2 MailScanner[16198]: Batch completed at 82503 bytes per second (562949 / 6) Jan 19 08:41:55 mx2 MailScanner[16198]: Batch processed in 6.82 seconds Jan 19 08:41:55 mx2 MailScanner[16198]: Logging message 18962288609.B799A to SQL Jan 19 08:41:55 mx2 MailScanner[16198]: Logging message E91632885B3.39157 to SQL Jan 19 08:41:55 mx2 MailScanner[16198]: Logging message C4A1A2885BE.E137B to SQL Jan 19 08:41:55 mx2 MailScanner[16198]: Logging message F16ED28805B.F2283 to SQL Jan 19 08:41:55 mx2 MailScanner[16198]: Logging message 6211A2885D1.3EBEA to SQL Jan 19 08:41:55 mx2 MailScanner[16198]: Logging message 796AD28860B.B2A37 to SQL Jan 19 08:41:55 mx2 MailScanner[16198]: Logging message E7B612885B2.605FA to SQL Jan 19 08:41:55 mx2 MailScanner[16198]: Logging message 986B62885B5.DE050 to SQL Jan 19 08:41:55 mx2 MailScanner[16198]: Logging message 1B89C2885D0.D3F07 to SQL Jan 19 08:41:55 mx2 MailScanner[16198]: "Always Looked Up Last" took 0.01 seconds Jan 19 08:41:55 mx2 MailScanner[16198]: Config: calling custom end function SQLBlacklist Jan 19 08:41:55 mx2 MailScanner[16198]: Closing down by-domain spam blacklist Jan 19 08:41:55 mx2 MailScanner[16198]: Config: calling custom end function MailWatchLogging Jan 19 08:41:55 mx2 MailScanner[16198]: Config: calling custom end function SQLWhitelist Jan 19 08:41:55 mx2 MailScanner[16198]: Closing down by-domain spam whitelist Jan 19 08:41:55 mx2 MailScanner[16198]: MailScanner child dying of old age Jan 19 08:41:55 mx2 MailScanner[16209]: 18962288609.B799A: Logged to MailWatch SQL Jan 19 08:41:55 mx2 MailScanner[16209]: E91632885B3.39157: Logged to MailWatch SQL Jan 19 08:41:55 mx2 MailScanner[16209]: C4A1A2885BE.E137B: Logged to MailWatch SQL Jan 19 08:41:55 mx2 MailScanner[16209]: F16ED28805B.F2283: Logged to MailWatch SQL Jan 19 08:41:55 mx2 MailScanner[16209]: 6211A2885D1.3EBEA: Logged to MailWatch SQL Jan 19 08:41:55 mx2 MailScanner[16209]: 796AD28860B.B2A37: Logged to MailWatch SQL Jan 19 08:41:55 mx2 MailScanner[16209]: E7B612885B2.605FA: Logged to MailWatch SQL Jan 19 08:41:55 mx2 MailScanner[16209]: 986B62885B5.DE050: Logged to MailWatch SQL Jan 19 08:41:55 mx2 MailScanner[16209]: 1B89C2885D0.D3F07: Logged to MailWatch SQL Also here's the output of "mailscanner -v" [root@mx2 MailScanner]# MailScanner -v Running on Linux mx2.netmagicians.com 2.6.9-22.0.1.ELsmp #1 SMP Thu Oct 27 13:14:25 CDT 2005 i686 i686 i386 GNU/Linux This is CentOS release 4.2 (Final) This is Perl version 5.008005 (5.8.5) This is MailScanner version 4.50.9 Module versions are: 1.00 AnyDBM_File 1.14 Archive::Zip 1.03 Carp 1.119 Convert::BinHex 1.00 DirHandle 1.05 Fcntl 2.73 File::Basename 2.08 File::Copy 2.01 FileHandle 1.06 File::Path 0.14 File::Temp 1.29 HTML::Entities 3.45 HTML::Parser 2.30 HTML::TokeParser 1.21 IO 1.10 IO::File 1.123 IO::Pipe 1.71 Mail::Header 3.05 MIME::Base64 5.419 MIME::Decoder 5.419 MIME::Decoder::UU 5.419 MIME::Head 5.419 MIME::Parser 3.03 MIME::QuotedPrint 5.419 MIME::Tools 0.10 Net::CIDR 1.08 POSIX 1.77 Socket 0.08 Sys::Syslog 1.86 Time::HiRes 1.02 Time::localtime Optional module versions are: 0.17 Convert::TNEF 1.809 DB_File 1.11 DBD::SQLite 1.50 DBI 1.08 Digest 1.01 Digest::HMAC 2.33 Digest::MD5 2.10 Digest::SHA1 0.44 Inline 0.17 Mail::ClamAV 3.000004 Mail::SpamAssassin 1.997 Mail::SPF::Query 0.15 Net::CIDR::Lite 0.23 Net::DNS 0.31 Net::LDAP 1.94 Parse::RecDescent missing SAVI 1.2 Sys::Hostname::Long 2.42 Test::Harness 0.47 Test::Simple 1.95 Text::Balanced 1.35 URI From wietse at boudisque.nl Thu Jan 19 09:19:19 2006 From: wietse at boudisque.nl (Wietse Muizelaar) Date: Thu Jan 19 09:21:00 2006 Subject: Log "Always Looked Up Last" References: <02ab01c61c7e$2b653d70$630a0a0a@wietse> <5610539E-5911-4F65-A4F2-D2DD67648A5B@ecs.soton.ac.uk> Message-ID: <005e01c61cd9$a2382fb0$1373a8c0@BOUDIEWEB10> Hi, On Thursday, January 19, 2006 9:55 AM, Julian Field wrote: >> I installed the latest beta, and had one question about it: >> is there a reason that the log "Always Looked Up Last" took 0.00 >> seconds >> (or, as long as it took, ofcourse), had the quotes with it? >> >> Jan 18 23:02:07 boudams MailScanner[4658]: "Always Looked Up Last" >> took 0.00 >> seconds >> Jan 18 23:02:14 boudams MailScanner[4596]: "Always Looked Up Last" >> took 0.00 >> seconds >> >> Etc. Is it possible to remove those quotes? Or are they there for >> some reason I don't know? :) > > That's just because it is the name of the configuration option it is > looking up. Why not have the quotes? Do they cause you some problem? No, they don't...I was just wondering :) -- Kind regards, Wietse Muizelaar ------------------------------------------- W.G. Muizelaar Boudisque Webmaster / ICT Drieharingstraat 5-31, 3511 BH Utrecht Telefoon: +31 (0)30 - 2394030 E-mail: wietse@boudisque.nl Website: www.boudisque.nl ------------------------------------------- From lhaig at haigmail.com Thu Jan 19 09:40:05 2006 From: lhaig at haigmail.com (Lance Haig) Date: Thu Jan 19 09:40:08 2006 Subject: Sendmail not relaying In-Reply-To: References: Message-ID: <43CF5E75.7020103@haigmail.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi Jim, > While this won't fix the problem, it should be pointed out that you need > to have an A record for the above hostname on your nameservers. At the > moment it is listed as NXDOMAIN (domain does not exist). > I have spoken to my brother in-law and advised him to do this >> I can send e-mail to his site but he cant send mail out through my server > > If the mail is coming from the above server, then you should be using the > following entry in your access file: > > Connect:196.31.65.238 RELAY > not > 196.31.65.238 RELAY I tried both incarnations and it still wont allow relay. > > if you are using a current version of sendmail. > I am using sendmail version 8.13.3 > If you are using SMTP AUTH then of course that should be set up correctly > as well, as that will also affect outgoing relaying. Nope not using SMTP AUTH Thanks for the help Lance -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFDz151M4kHBIBZ61gRAreNAJ9D3jGD+UrEUJX1JPBFm+yCXF++twCfSRyl V0wRnSjkBCOn/DUSUsEB2aA= =rvWn -----END PGP SIGNATURE----- From lhaig at haigmail.com Thu Jan 19 09:40:35 2006 From: lhaig at haigmail.com (Lance Haig) Date: Thu Jan 19 09:40:38 2006 Subject: Sendmail not relaying In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D15603@city-exch-w3e.cbj.local> References: <82895A755D1EA5458EC9E64021922AD2D15603@city-exch-w3e.cbj.local> Message-ID: <43CF5E93.4000600@haigmail.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi Kevin, Thanks I have added that to my procedure document Lance Kevin Miller wrote: > Lance Haig wrote: > snip >> What am I missing guys >> >> I am using sendmail > > You also need to do: > > makemap hash mailertable < mailertable > > That may or may not fix it, but it's a step you didn't list which should > be done. > > > ...Kevin -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFDz16TM4kHBIBZ61gRAmBnAJoDHke3UZayiNWt5L79SdKFHbSihwCfcbDo SsW0ev4aQvffj/Th9c2Hwe8= =CKG1 -----END PGP SIGNATURE----- From lhaig at haigmail.com Thu Jan 19 09:47:28 2006 From: lhaig at haigmail.com (Lance Haig) Date: Thu Jan 19 09:47:31 2006 Subject: Sendmail not relaying In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D15605@city-exch-w3e.cbj.local> References: <82895A755D1EA5458EC9E64021922AD2D15605@city-exch-w3e.cbj.local> Message-ID: <43CF6030.3000207@haigmail.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Kevin Miller wrote: > > There seems to be some problem with your DNS I think: > ==================================================== > G:\>nslookup server1.megas.co.za > Server: city-dc1-w3s.cbj.local > Address: 199.58.55.25 Spoke to my Brother in-law seems like he forgot to add the a record just the ptr it is his domain > megas.co.za emspt:[xx.xx.xx.xx] This is how it is entered the other was my attempt at domain masking :-) not very good I am afraid. Thanks a million Lance -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFDz2AwM4kHBIBZ61gRAp8YAKCK/lB9csGNXEtUyYS2GHxNZY+ZWwCgi3LN Uh5Gsl73GUXqrlRFf4mt2mk= =7mYm -----END PGP SIGNATURE----- From lhaig at haigmail.com Thu Jan 19 09:48:15 2006 From: lhaig at haigmail.com (Lance Haig) Date: Thu Jan 19 09:48:18 2006 Subject: Sendmail not relaying In-Reply-To: <1137616970.26473.499.camel@localhost.localdomain> References: <43CE9319.6070009@haigmail.com> <1137616970.26473.499.camel@localhost.localdomain> Message-ID: <43CF605F.6060206@haigmail.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Thanks Steve, BTW I added all 90 domains to the filter We will see how it copes :-) Lance Steve Freegard wrote: > Hi Lance, > > On Wed, 2006-01-18 at 19:12 +0000, Lance Haig wrote: > >> makemap hash /etc/mail/access < /etc/mail/access > > Is this a typo? - it should be: > > makemap hash /etc/mail/access.db < /etc/mail/access > ^^^ > > If you are using a RPM style system - you could also just edit > the /etc/mail/access then run 'make -C /etc/mail' and it will take care > of everything for you :-) > > Cheers, > Steve. > -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFDz2BfM4kHBIBZ61gRAp5UAJ9e7mYAiGL4QrZssOjHnCZZUutBywCfS6dt Ne0ew9fdClADe1C+Njk/fnk= =eepN -----END PGP SIGNATURE----- From lhaig at haigmail.com Thu Jan 19 09:49:45 2006 From: lhaig at haigmail.com (Lance Haig) Date: Thu Jan 19 09:49:47 2006 Subject: Sendmail not relaying In-Reply-To: <200601181853.03813.aslan@aeon.com.br> References: <43CE9319.6070009@haigmail.com> <1137616970.26473.499.camel@localhost.localdomain> <200601181853.03813.aslan@aeon.com.br> Message-ID: <43CF60B9.6070009@haigmail.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Thank for the tip Lance Aslan Carlos wrote: > On Wednesday 18 January 2006 18:42, Steve Freegard wrote: >> Hi Lance, >> >> On Wed, 2006-01-18 at 19:12 +0000, Lance Haig wrote: >>> makemap hash /etc/mail/access < /etc/mail/access >> Is this a typo? - it should be: >> >> makemap hash /etc/mail/access.db < /etc/mail/access > HI, > sometime, people make a change on sendmail.cf and not sendmail.mc, and create > a big problem, I'd pass one that. > AUTH actived on sendmail.cf , but on sendmail.mc not, when make -C /etc/mail, > or than on simple make in path /etc/mail (Redhat Style), make this. > > > Use the always makemap hash access < access and You'll make the access.db > > C'ya. > sorry my poor English! >> ^^^ >> >> If you are using a RPM style system - you could also just edit >> the /etc/mail/access then run 'make -C /etc/mail' and it will take care >> of everything for you :-) >> >> Cheers, >> Steve. > -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFDz2C5M4kHBIBZ61gRAkX7AJwI6TPgKq4Gc8e7hsPbQLZl9ThLWACfcm7h UivfrnyUCf38LnjVukoCOek= =8Vxc -----END PGP SIGNATURE----- From lhaig at haigmail.com Thu Jan 19 09:55:08 2006 From: lhaig at haigmail.com (Lance Haig) Date: Thu Jan 19 09:55:12 2006 Subject: Sendmail not relaying In-Reply-To: <1137625362.22303.2.camel@localhost.localdomain> References: <43CE9319.6070009@haigmail.com> <1137625362.22303.2.camel@localhost.localdomain> Message-ID: <43CF61FC.4070006@haigmail.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi Paul, I was only filtering inbound mail and now want to start filtering outbound as well. I have looked at a config of one the company's I used to work for that Steve Swaney setup for us and my files look exactly the same. I have a feeling that the missing A record could be the problem. I am stumped. Thanks for the advice Lance Paul Kelly :: Blacknight wrote: > Hi there, > > On Wed, 2006-01-18 at 19:12 +0000, Lance Haig wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> Guys I have hit a snag. >> >> I have configured a new set of domains and have configured the >> mailertable > > needed. > >> relay-domains >> > > not needed. I'm presuming that its a mail gateway? If so the only place > domains should be added is the mailertable file. > >> I have added the domains to the access file >> domain RELAY > > Remove. > >> and the sending IP of the mailserver >> ipaddress RELAY >> > Are you filtering outbound email aswell? If not remove this, if so leave > it in. > > Access.db is for allowing mail servers/people to relay through you or to > block them etc. > > mailertable defines the end point mailserver for the domain that is to > be scanned. > >> When I try to send a mail to a domain outside the Mailscanner machine it >> says relaying denied. >> >> I have tried this command on the access file >> >> makemap hash /etc/mail/access < /etc/mail/access >> >> but is still does not want to allow the mailserver to relay e-mail. >> > > I think that is your problem. Remove the entries from access db and you > should be set. > > Paul > -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFDz2H8M4kHBIBZ61gRApj0AKCQ4fkl4EPHmlCzqH6FAzq5g1FjQQCffBsc AC3z1sgKdleGOLaZjlZ4PFY= =HxUA -----END PGP SIGNATURE----- From MailScanner at ecs.soton.ac.uk Thu Jan 19 09:58:17 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 19 09:58:31 2006 Subject: Release 4.50.9 : Re: Worm.VB-8 not detected by filename or filetype In-Reply-To: <91442C0A-22E0-45B3-BA2A-3647FEE16C34@ecs.soton.ac.uk> References: <43CE4037.7030007@pl.jaring.my> <43CE4660.3040200@pl.jaring.my> <43CE5A75.1000000@netmagicsolutions.com> <43CE5E24.6080103@netmagicsolutions.com> <43CE7706.8070909@netmagicsolutions.com> <43CE7D95.2040900@ecs.soton.ac.uk> <43CE825A.9030901@netmagicsolutions.com> <43CE9E7F.7010700@netmagicsolutions.com> <43CEA115.90800@ecs.soton.ac.uk> <43CEA47E.2020301@ecs.soton.ac.uk> <43CEA7F8.2020609@netmagicsolutions.com> <43CEBD5B.8030501@netmagicsolutions.com> <91442C0A-22E0-45B3-BA2A-3647FEE16C34@ecs.soton.ac.uk> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 19 Jan 2006, at 08:53, Julian Field wrote: > * PGP Signed: 01/19/06 at 08:53:08 > > > On 18 Jan 2006, at 22:12, Dhawal Doshy wrote: > >> Dhawal Doshy wrote: >>>>>>>>>>> Julian Field wrote: >>>>>>>>>>>> -----BEGIN PGP SIGNED MESSAGE----- >>>>>>>>>>>> >>>>>>>>>>>> I have just released 4.50.9 which will decode the UU- >>>>>>>>>>>> encoded file attached to these messages, so that the >>>>>>>>>>>> virus scanners should all catch it, filename traps will >>>>>>>>>>>> work on the .scr file inside the .bhx file, filetype >>>>>>>>>>>> traps will work on it too. >>>>>>>>>>> >>>>>>>>>>> Just successfully upgraded a couple of production servers.. >>>>>>>>>> >>>>>>>>>> I notice this in the logs.. >>>>>>>>>> Jan 18 20:54:00 mx1 MailScanner[13545]: Infected message >>>>>>>>>> 73CEF28ABDE.D9736 came from >>>>>>>>>> >>>>>>>>>> The IP address is blank :-(, i'll try and run this through >>>>>>>>>> the debug sometime later. >>>>>>>>> >>>>>>>>> The debug mode didn't tell me anything (apart from the EOCD >>>>>>>>> thingy).. how do i track this problem? >> >> Julian, >> >> I *might* have figured the error, here's the situation.. >> >> Notify Senders Of Viruses = no >> Notify Senders Of Blocked Filenames Or Filetypes = yes >> >> But filename.rules.conf has been modified to use deny+delete >> rather than simply deny. >> deny+delete \.pif$ - - >> deny+delete \.scr$ - - >> deny+delete \.cpl$ - - >> >> Yet MailScanner (i think) tries to send out a notification for the >> policy violation and yes.. this time being sent from localhost it >> obviously doesn't show the IP address. The problem is it goes into >> an endless loop post this situation of trying to send out the >> notification. Any ideas? > > I don't understand your explanation. Are you saying that > MailScanner gets stuck in an endless loop? Please use 4.50.10-1 instead. That contains the bugfix. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ89ivPw32o+k+q+hAQEttgf/Q2nvy93V0DOrdPwSvOAkyG/gLHbA5+6t Veg42eQsX7E1YmKdjamAAoSWqn1RSl72Ql9ocWvlc0LSWlLLh97TGC00IhyLIs0R 52M+080JuhVy081J57lpTmTq8Xj9ADmOywqtz1NhnTT1i6nkUMjdJQs1v9d/sY4s BF7pxWuVmY7bAnpv+DkJ6XV1jkpakTZgTD1aafaJW1IywC2jB2JtnazfSpAG5Z4Q g+4aWwDWW9x/pBusVh9nS4BimRzuZ7paPo4Iy6FTZJgA4ZpzXLgBlmpSQxbGN413 n8WjMMGkWtT3ax+pTjVcHyDXzTNwLpo6vGhONaGo7UmxrI+lKwePcQ== =kTFi -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From wietse at boudisque.nl Thu Jan 19 11:08:31 2006 From: wietse at boudisque.nl (Wietse Muizelaar) Date: Thu Jan 19 11:08:47 2006 Subject: Timing of -1? Message-ID: <022d01c61ce8$aeb362a0$1373a8c0@BOUDIEWEB10> Hi, Another thing seeing right now in the logs; is that sometimes, the timing mechanism fails. Or at least, it says: Jan 19 11:45:05 boudams MailScanner[3944]: Found phishing fraud from www.solomusic.nl claiming to be www.solomusic.n in k0JAipjC026202 Jan 19 11:45:05 boudams MailScanner[3944]: Content Checks: Detected and have disarmed phishing tags in HTML message in k0JAipjC026202 from nicolette@solomusic.nl Jan 19 11:45:05 boudams MailScanner[3944]: Disinfection completed at -1 bytes per second Also, the MCP checks sometimes have a speed rate of -1 bytes per second. -- Met vriendelijke groet, Wietse Muizelaar ------------------------------------------- W.G. Muizelaar Boudisque Webmaster / ICT Drieharingstraat 5-31, 3511 BH Utrecht Telefoon: +31 (0)30 - 2394030 E-mail: wietse@boudisque.nl Website: www.boudisque.nl ------------------------------------------- From martinh at solid-state-logic.com Thu Jan 19 11:22:07 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Thu Jan 19 11:22:17 2006 Subject: Timing of -1? In-Reply-To: <022d01c61ce8$aeb362a0$1373a8c0@BOUDIEWEB10> Message-ID: <002701c61cea$950dea80$3004010a@martinhlaptop> Does that mean they'll be detecting tomorrow's spam soon ;-) -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Wietse Muizelaar > Sent: 19 January 2006 11:09 > To: MailScanner discussion > Subject: Timing of -1? > > Hi, > > Another thing seeing right now in the logs; is that sometimes, the timing > mechanism fails. Or at least, it says: > > Jan 19 11:45:05 boudams MailScanner[3944]: Found phishing fraud from > www.solomusic.nl claiming to be www.solomusic.n in k0JAipjC026202 > Jan 19 11:45:05 boudams MailScanner[3944]: Content Checks: Detected and > have > disarmed phishing tags in HTML message in k0JAipjC026202 from > nicolette@solomusic.nl > Jan 19 11:45:05 boudams MailScanner[3944]: Disinfection completed at -1 > bytes per second > > Also, the MCP checks sometimes have a speed rate of -1 bytes per second. > > -- > Met vriendelijke groet, > > Wietse Muizelaar > > ------------------------------------------- > W.G. Muizelaar > Boudisque Webmaster / ICT > Drieharingstraat 5-31, 3511 BH Utrecht > Telefoon: +31 (0)30 - 2394030 > E-mail: wietse@boudisque.nl > Website: www.boudisque.nl > ------------------------------------------- > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From MailScanner at ecs.soton.ac.uk Thu Jan 19 11:22:31 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 19 11:22:40 2006 Subject: Timing of -1? In-Reply-To: <022d01c61ce8$aeb362a0$1373a8c0@BOUDIEWEB10> References: <022d01c61ce8$aeb362a0$1373a8c0@BOUDIEWEB10> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- It's just a rounding error, don't worry about it. On 19 Jan 2006, at 11:08, Wietse Muizelaar wrote: > Hi, > > Another thing seeing right now in the logs; is that sometimes, the > timing mechanism fails. Or at least, it says: > > Jan 19 11:45:05 boudams MailScanner[3944]: Found phishing fraud > from www.solomusic.nl claiming to be www.solomusic.n in k0JAipjC026202 > Jan 19 11:45:05 boudams MailScanner[3944]: Content Checks: Detected > and have disarmed phishing tags in HTML message in k0JAipjC026202 > from nicolette@solomusic.nl > Jan 19 11:45:05 boudams MailScanner[3944]: Disinfection completed > at -1 bytes per second > > Also, the MCP checks sometimes have a speed rate of -1 bytes per > second. > > -- > Met vriendelijke groet, > > Wietse Muizelaar > > ------------------------------------------- > W.G. Muizelaar > Boudisque Webmaster / ICT > Drieharingstraat 5-31, 3511 BH Utrecht > Telefoon: +31 (0)30 - 2394030 > E-mail: wietse@boudisque.nl > Website: www.boudisque.nl > ------------------------------------------- > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ892evw32o+k+q+hAQE4hAgApDGpILqbCg+ot4Bf75U55ci3QwJwgGU8 06CsVoijgaAXMeFFAwrqXMjyRe+iWDes7nKnubc9EcE7oUk9zJUVKfrb8G4ZafKV Xq44rx+ub0CiFdBUSA4NDMo6kXWtHqJepXT8kaUH7+0nw78115Y6Nkbsop5T2SZm etu6/kg8yHp4jRQOShqSehNESdOFef8/6emN9FdroF0lf2rBTeQ3r6P3VXT+PLbU jUT8C2EuPC8wU+hPwOBGSFPANLy85hrcSOv8nuVunBGGFMuuFlYn4oFFGxmFjvFH RwdqWOS4iKWHi8yre1OCplF6Xmk+Z7HyRhuR3KZ7RFLuSO6Bqi770w== =5WmH -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From wietse at boudisque.nl Thu Jan 19 11:42:58 2006 From: wietse at boudisque.nl (Wietse Muizelaar) Date: Thu Jan 19 11:43:12 2006 Subject: Timing of -1? References: <022d01c61ce8$aeb362a0$1373a8c0@BOUDIEWEB10> Message-ID: <024201c61ced$7f021e70$1373a8c0@BOUDIEWEB10> Ok, thnx! On Thursday, January 19, 2006 12:22 PM, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > It's just a rounding error, don't worry about it. > > On 19 Jan 2006, at 11:08, Wietse Muizelaar wrote: > >> Hi, >> >> Another thing seeing right now in the logs; is that sometimes, the >> timing mechanism fails. Or at least, it says: >> >> Jan 19 11:45:05 boudams MailScanner[3944]: Found phishing fraud >> from www.solomusic.nl claiming to be www.solomusic.n in >> k0JAipjC026202 Jan 19 11:45:05 boudams MailScanner[3944]: Content >> Checks: Detected and have disarmed phishing tags in HTML message in >> k0JAipjC026202 from nicolette@solomusic.nl >> Jan 19 11:45:05 boudams MailScanner[3944]: Disinfection completed >> at -1 bytes per second >> >> Also, the MCP checks sometimes have a speed rate of -1 bytes per >> second. >> >> -- >> Met vriendelijke groet, >> >> Wietse Muizelaar >> >> ------------------------------------------- >> W.G. Muizelaar >> Boudisque Webmaster / ICT >> Drieharingstraat 5-31, 3511 BH Utrecht >> Telefoon: +31 (0)30 - 2394030 >> E-mail: wietse@boudisque.nl >> Website: www.boudisque.nl >> ------------------------------------------- >> >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.4 (Build 4042) > > iQEVAwUBQ892evw32o+k+q+hAQE4hAgApDGpILqbCg+ot4Bf75U55ci3QwJwgGU8 > 06CsVoijgaAXMeFFAwrqXMjyRe+iWDes7nKnubc9EcE7oUk9zJUVKfrb8G4ZafKV > Xq44rx+ub0CiFdBUSA4NDMo6kXWtHqJepXT8kaUH7+0nw78115Y6Nkbsop5T2SZm > etu6/kg8yHp4jRQOShqSehNESdOFef8/6emN9FdroF0lf2rBTeQ3r6P3VXT+PLbU > jUT8C2EuPC8wU+hPwOBGSFPANLy85hrcSOv8nuVunBGGFMuuFlYn4oFFGxmFjvFH > RwdqWOS4iKWHi8yre1OCplF6Xmk+Z7HyRhuR3KZ7RFLuSO6Bqi770w== > =5WmH > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. -- Met vriendelijke groet, Wietse Muizelaar ------------------------------------------- W.G. Muizelaar Boudisque Webmaster / ICT Drieharingstraat 5-31, 3511 BH Utrecht Telefoon: +31 (0)30 - 2394030 E-mail: wietse@boudisque.nl Website: www.boudisque.nl ------------------------------------------- From MailScanner at ecs.soton.ac.uk Thu Jan 19 12:09:33 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 19 12:10:13 2006 Subject: Timing of -1? In-Reply-To: <024201c61ced$7f021e70$1373a8c0@BOUDIEWEB10> References: <022d01c61ce8$aeb362a0$1373a8c0@BOUDIEWEB10> <024201c61ced$7f021e70$1373a8c0@BOUDIEWEB10> Message-ID: <706ED5D4-2215-45CA-92E6-D7C0FCFB98CF@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- What version of MailScanner are you running? I have made some changes to the timing code in 4.50, so you may well find I have already fixed your problem. On 19 Jan 2006, at 11:42, Wietse Muizelaar wrote: > Ok, thnx! > > On Thursday, January 19, 2006 12:22 PM, > Julian Field wrote: > >> -----BEGIN PGP SIGNED MESSAGE----- >> It's just a rounding error, don't worry about it. >> On 19 Jan 2006, at 11:08, Wietse Muizelaar wrote: >>> Hi, >>> Another thing seeing right now in the logs; is that sometimes, the >>> timing mechanism fails. Or at least, it says: >>> Jan 19 11:45:05 boudams MailScanner[3944]: Found phishing fraud >>> from www.solomusic.nl claiming to be www.solomusic.n in >>> k0JAipjC026202 Jan 19 11:45:05 boudams MailScanner[3944]: Content >>> Checks: Detected and have disarmed phishing tags in HTML message in >>> k0JAipjC026202 from nicolette@solomusic.nl >>> Jan 19 11:45:05 boudams MailScanner[3944]: Disinfection completed >>> at -1 bytes per second >>> Also, the MCP checks sometimes have a speed rate of -1 bytes per >>> second. >>> -- >>> Met vriendelijke groet, >>> Wietse Muizelaar >>> ------------------------------------------- >>> W.G. Muizelaar >>> Boudisque Webmaster / ICT >>> Drieharingstraat 5-31, 3511 BH Utrecht >>> Telefoon: +31 (0)30 - 2394030 >>> E-mail: wietse@boudisque.nl >>> Website: www.boudisque.nl >>> ------------------------------------------- >>> -- >>> MailScanner mailing list >>> MailScanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> Before posting, read http://wiki.mailscanner.info/posting >>> Support MailScanner development - buy the book off the website! >> - -- >> Julian Field >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> -----BEGIN PGP SIGNATURE----- >> Version: PGP Desktop 9.0.4 (Build 4042) >> iQEVAwUBQ892evw32o+k+q+hAQE4hAgApDGpILqbCg+ot4Bf75U55ci3QwJwgGU8 >> 06CsVoijgaAXMeFFAwrqXMjyRe+iWDes7nKnubc9EcE7oUk9zJUVKfrb8G4ZafKV >> Xq44rx+ub0CiFdBUSA4NDMo6kXWtHqJepXT8kaUH7+0nw78115Y6Nkbsop5T2SZm >> etu6/kg8yHp4jRQOShqSehNESdOFef8/6emN9FdroF0lf2rBTeQ3r6P3VXT+PLbU >> jUT8C2EuPC8wU+hPwOBGSFPANLy85hrcSOv8nuVunBGGFMuuFlYn4oFFGxmFjvFH >> RwdqWOS4iKWHi8yre1OCplF6Xmk+Z7HyRhuR3KZ7RFLuSO6Bqi770w== >> =5WmH >> -----END PGP SIGNATURE----- >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. > > -- > Met vriendelijke groet, > > Wietse Muizelaar > > ------------------------------------------- > W.G. Muizelaar > Boudisque Webmaster / ICT > Drieharingstraat 5-31, 3511 BH Utrecht > Telefoon: +31 (0)30 - 2394030 > E-mail: wietse@boudisque.nl > Website: www.boudisque.nl > ------------------------------------------- > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8+Bf/w32o+k+q+hAQFhugf+OC83i6o1VawdjrSGoboFd7CIotmrPIDA Igk5yjFFBpPSe2mdh/528g8Vmfq1BECBVyjG9FO1ary8OIAXGMV+gk46m2Dh48ld Zc0el/Vu+yXiBKYImjjXBLjqmEOn1ihpeBuPs4Zp02Al0sRNamKr/2/81uhWmTTS GAslfxGL7gYHgRZN33p740RpynglpRqwqGjez2o9nKPvkXk5nSsIvt0nzn4EmlEL c/8kuhvu0a0C6TkWzP9T9yI+M/ODJXO0uX0AeW8BeY1wQNB+xJP1VGp8Yj0oY1+N lke0o/rFhf2RIhOsxP8wbn6uHk+W3DXpmWgOA5PHm33OmI0d0Vewrg== =KkTY -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From wietse at boudisque.nl Thu Jan 19 12:25:05 2006 From: wietse at boudisque.nl (Wietse Muizelaar) Date: Thu Jan 19 12:25:20 2006 Subject: Timing of -1? References: <022d01c61ce8$aeb362a0$1373a8c0@BOUDIEWEB10><024201c61ced$7f021e70$1373a8c0@BOUDIEWEB10> <706ED5D4-2215-45CA-92E6-D7C0FCFB98CF@ecs.soton.ac.uk> Message-ID: <02b901c61cf3$6113dc40$1373a8c0@BOUDIEWEB10> It's MailScanner version 4.50.9 (from last night) When searching the logfiles; I found this timing thing started when using this version. (I installed it last night). Also I found this one: Jan 19 12:11:45 boudams MailScanner[4581]: Disinfection completed at -1756120872 bytes per second (and the below-zero-figures only appear at the Disinfection and the MCP Checks, not at the Spam Checks, or Virus Scanning and Processing). Complete output of the MailScanner --version command: Running on Linux boudams 2.6.8-2-mppe-boudams #1 Fri Dec 16 14:51:00 CET 2005 i686 GNU/Linu x This is Perl version 5.008004 (5.8.4) This is MailScanner version 4.50.9 Module versions are: 1.00 AnyDBM_File 1.14 Archive::Zip 1.02 Carp 1.119 Convert::BinHex 1.00 DirHandle 1.05 Fcntl 2.72 File::Basename 2.07 File::Copy 2.01 FileHandle 1.06 File::Path 0.16 File::Temp 1.29 HTML::Entities 3.45 HTML::Parser 2.30 HTML::TokeParser 1.21 IO 1.10 IO::File 1.123 IO::Pipe 1.71 Mail::Header 3.05 MIME::Base64 5.419 MIME::Decoder 5.419 MIME::Decoder::UU 5.419 MIME::Head 5.419 MIME::Parser 3.03 MIME::QuotedPrint 5.419 MIME::Tools 0.10 Net::CIDR 1.08 POSIX 1.77 Socket 0.05 Sys::Syslog 1.86 Time::HiRes 1.02 Time::localtime Optional module versions are: 0.17 Convert::TNEF 1.808 DB_File 1.11 DBD::SQLite 1.50 DBI 1.06 Digest 1.01 Digest::HMAC 2.33 Digest::MD5 2.10 Digest::SHA1 0.44 Inline 0.17 Mail::ClamAV 3.001000 Mail::SpamAssassin 1.997 Mail::SPF::Query 0.15 Net::CIDR::Lite 0.49 Net::DNS missing Net::LDAP 1.94 Parse::RecDescent missing SAVI 1.2 Sys::Hostname::Long 2.40 Test::Harness 0.47 Test::Simple 1.95 Text::Balanced 1.35 URI On Thursday, January 19, 2006 1:09 PM, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > What version of MailScanner are you running? > I have made some changes to the timing code in 4.50, so you may well > find I have already fixed your problem. > > On 19 Jan 2006, at 11:42, Wietse Muizelaar wrote: > >> Ok, thnx! >> >> On Thursday, January 19, 2006 12:22 PM, >> Julian Field wrote: >> >>> -----BEGIN PGP SIGNED MESSAGE----- >>> It's just a rounding error, don't worry about it. >>> On 19 Jan 2006, at 11:08, Wietse Muizelaar wrote: >>>> Hi, >>>> Another thing seeing right now in the logs; is that sometimes, the >>>> timing mechanism fails. Or at least, it says: >>>> Jan 19 11:45:05 boudams MailScanner[3944]: Found phishing fraud >>>> from www.solomusic.nl claiming to be www.solomusic.n in >>>> k0JAipjC026202 Jan 19 11:45:05 boudams MailScanner[3944]: Content >>>> Checks: Detected and have disarmed phishing tags in HTML message in >>>> k0JAipjC026202 from nicolette@solomusic.nl >>>> Jan 19 11:45:05 boudams MailScanner[3944]: Disinfection completed >>>> at -1 bytes per second >>>> Also, the MCP checks sometimes have a speed rate of -1 bytes per >>>> second. >>>> -- >>>> Met vriendelijke groet, >>>> Wietse Muizelaar >>>> ------------------------------------------- >>>> W.G. Muizelaar >>>> Boudisque Webmaster / ICT >>>> Drieharingstraat 5-31, 3511 BH Utrecht >>>> Telefoon: +31 (0)30 - 2394030 >>>> E-mail: wietse@boudisque.nl >>>> Website: www.boudisque.nl >>>> ------------------------------------------- >>>> -- >>>> MailScanner mailing list >>>> MailScanner@lists.mailscanner.info >>>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>>> Before posting, read http://wiki.mailscanner.info/posting >>>> Support MailScanner development - buy the book off the website! >>> - -- >>> Julian Field >>> www.MailScanner.info >>> Buy the MailScanner book at www.MailScanner.info/store >>> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >>> -----BEGIN PGP SIGNATURE----- >>> Version: PGP Desktop 9.0.4 (Build 4042) >>> iQEVAwUBQ892evw32o+k+q+hAQE4hAgApDGpILqbCg+ot4Bf75U55ci3QwJwgGU8 >>> 06CsVoijgaAXMeFFAwrqXMjyRe+iWDes7nKnubc9EcE7oUk9zJUVKfrb8G4ZafKV >>> Xq44rx+ub0CiFdBUSA4NDMo6kXWtHqJepXT8kaUH7+0nw78115Y6Nkbsop5T2SZm >>> etu6/kg8yHp4jRQOShqSehNESdOFef8/6emN9FdroF0lf2rBTeQ3r6P3VXT+PLbU >>> jUT8C2EuPC8wU+hPwOBGSFPANLy85hrcSOv8nuVunBGGFMuuFlYn4oFFGxmFjvFH >>> RwdqWOS4iKWHi8yre1OCplF6Xmk+Z7HyRhuR3KZ7RFLuSO6Bqi770w== >>> =5WmH >>> -----END PGP SIGNATURE----- >>> -- >>> This message has been scanned for viruses and >>> dangerous content by MailScanner, and is >>> believed to be clean. >> >> -- >> Met vriendelijke groet, >> >> Wietse Muizelaar >> >> ------------------------------------------- >> W.G. Muizelaar >> Boudisque Webmaster / ICT >> Drieharingstraat 5-31, 3511 BH Utrecht >> Telefoon: +31 (0)30 - 2394030 >> E-mail: wietse@boudisque.nl >> Website: www.boudisque.nl >> ------------------------------------------- >> >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.4 (Build 4042) > > iQEVAwUBQ8+Bf/w32o+k+q+hAQFhugf+OC83i6o1VawdjrSGoboFd7CIotmrPIDA > Igk5yjFFBpPSe2mdh/528g8Vmfq1BECBVyjG9FO1ary8OIAXGMV+gk46m2Dh48ld > Zc0el/Vu+yXiBKYImjjXBLjqmEOn1ihpeBuPs4Zp02Al0sRNamKr/2/81uhWmTTS > GAslfxGL7gYHgRZN33p740RpynglpRqwqGjez2o9nKPvkXk5nSsIvt0nzn4EmlEL > c/8kuhvu0a0C6TkWzP9T9yI+M/ODJXO0uX0AeW8BeY1wQNB+xJP1VGp8Yj0oY1+N > lke0o/rFhf2RIhOsxP8wbn6uHk+W3DXpmWgOA5PHm33OmI0d0Vewrg== > =KkTY > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. -- Met vriendelijke groet, Wietse Muizelaar ------------------------------------------- W.G. Muizelaar Boudisque Webmaster / ICT Drieharingstraat 5-31, 3511 BH Utrecht Telefoon: +31 (0)30 - 2394030 E-mail: wietse@boudisque.nl Website: www.boudisque.nl ------------------------------------------- From lhaig at haigmail.com Thu Jan 19 13:02:48 2006 From: lhaig at haigmail.com (Lance Haig) Date: Thu Jan 19 13:02:52 2006 Subject: Sendmail not relaying In-Reply-To: <43CE9319.6070009@haigmail.com> References: <43CE9319.6070009@haigmail.com> Message-ID: <43CF8DF8.4050406@haigmail.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 just so that everyone knows it was the A record that caused the problem thank for all the help Lance Lance Haig wrote: > Guys I have hit a snag. > > I have configured a new set of domains and have configured the > mailertable > relay-domains > > I have added the domains to the access file > domain RELAY > > and the sending IP of the mailserver > ipaddress RELAY > > When I try to send a mail to a domain outside the Mailscanner machine it > says relaying denied. > > I have tried this command on the access file > > makemap hash /etc/mail/access < /etc/mail/access > > but is still does not want to allow the mailserver to relay e-mail. > > What am I missing guys > > I am using sendmail > > Thanks > > Lance -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFDz434M4kHBIBZ61gRAvSSAKCVZWvqsZtF8qhpa8/DMHxou40GwgCeLY25 ysj5mPQclocIwQSdE6Yn6Nw= =jeDP -----END PGP SIGNATURE----- From mailscanner at mango.zw Thu Jan 19 14:18:02 2006 From: mailscanner at mango.zw (Jim Holland) Date: Thu Jan 19 14:21:06 2006 Subject: Virus still being picked up an hour later In-Reply-To: <43CF00B6.50508@netmagicsolutions.com> Message-ID: Hi On Thu, 19 Jan 2006, Dhawal Doshy wrote: > > I have a problem with mailscanner where it doesnt seem to be getting rid of a virus from the filesystem once its found. > > Heres an example: > > Below is the first instance. > > Jan 19 12:35:22 proxy2 MailScanner[27476]: /var/spool/MailScanner/incoming/27476/./6BCB544E5D5.ED322/eBook.PIF: Worm.VB-8 FOUND > > > > Sometimes (but not every time) mailscanner also picks up the bad filename. > > Jan 19 12:35:22 proxy2 MailScanner[27476]: Filename Checks: Possible MS-Dos program shortcut attack (6BCB544E5D5.ED322 eBook.PIF) > > > > As of this moment, mailscanner is still picking up this same instance (1 hour later) > > Jan 19 13:35:04 proxy2 MailScanner[27476]: /var/spool/MailScanner/incoming/27476/./6BCB544E5D5.ED322/eBook.PIF: Worm.VB-8 FOUND > > > > Any idea why this might be happening? > > This is precisely what i have been unsuccessfully trying to convey all > evening to Julian.. somehow no else seemed to be in this situation.. > > Here's what i observed.. all files (even legit ones) continue to be > lying in the MailScanner incoming directory (within their respective PID > directory) and do NOT get deleted post batch processing.. as a result > MailScanner keeps on checking them again and again.. > > I am at a loss to take it any forward, since i haven't slept all night > long trying to figure out the reason.. :-( I come across this problem every couple of months, but it is generally only a single batch of messages that keeps get processed over and over again. I have always found that if I start by archiving the first message in the batch, then wait for the rest to be reprocessed, then archiving the next one if the problem continues, it will eventually sort itself out. Oddly enough the archived message can sometimes be processed perfectly by simply putting it back in the queue. At other times a message is apparently unprocessable and then I just check it manually and if OK I dump it into mqueue, bypassing MailScanner. I am using sendmail 8.13.1 and MailScanner-4.45.4-1 (definitely time to upgrade - I had just been waiting for latest beta to pass all user tests). Regards Jim Holland System Administrator MANGO - Zimbabwe's non-profit e-mail service From MailScanner at ecs.soton.ac.uk Thu Jan 19 14:58:10 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 19 14:58:26 2006 Subject: Virus still being picked up an hour later In-Reply-To: References: Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 19 Jan 2006, at 14:18, Jim Holland wrote: > Hi > > On Thu, 19 Jan 2006, Dhawal Doshy wrote: > >>> I have a problem with mailscanner where it doesnt seem to be >>> getting rid of a virus from the filesystem once its found. >>> Heres an example: >>> Below is the first instance. >>> Jan 19 12:35:22 proxy2 MailScanner[27476]: /var/spool/MailScanner/ >>> incoming/27476/./6BCB544E5D5.ED322/eBook.PIF: Worm.VB-8 FOUND >>> >>> Sometimes (but not every time) mailscanner also picks up the bad >>> filename. >>> Jan 19 12:35:22 proxy2 MailScanner[27476]: Filename Checks: >>> Possible MS-Dos program shortcut attack (6BCB544E5D5.ED322 >>> eBook.PIF) >>> >>> As of this moment, mailscanner is still picking up this same >>> instance (1 hour later) >>> Jan 19 13:35:04 proxy2 MailScanner[27476]: /var/spool/MailScanner/ >>> incoming/27476/./6BCB544E5D5.ED322/eBook.PIF: Worm.VB-8 FOUND >>> >>> Any idea why this might be happening? >> >> This is precisely what i have been unsuccessfully trying to convey >> all >> evening to Julian.. somehow no else seemed to be in this situation.. >> >> Here's what i observed.. all files (even legit ones) continue to be >> lying in the MailScanner incoming directory (within their >> respective PID >> directory) and do NOT get deleted post batch processing.. as a result >> MailScanner keeps on checking them again and again.. >> >> I am at a loss to take it any forward, since i haven't slept all >> night >> long trying to figure out the reason.. :-( Fixed in the latest beta. There was a typo in one file. I must have pressed something in vi by mistake and not noticed. Sorry about that. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ8+pBPw32o+k+q+hAQF3Egf9GvhcnkAjek5hshcuh7OxBglAjJYykOrH C3nvZ9Zl6bF0Lwt+kIPnoIMDMQnOirbask+g7zMlIjpE8bnW1u/CcLDTlLhTYvB0 UrA5cJHHyROjgmD+e4OQ28oMtxqf3Esc88w+BGdhjUD/l5ulcvp+AYcRD3KdXl6g hfZ/AtfpMiafMXMsNX+QjQZfMB+2L8/SVQu+S7PP1bq6AmgSluLd3hp7+InndKtg GPQlZw87Zl0GDFawg62R68mQ3ERKC8xBXvKYW6dWyDpdVvV6WQuuByt+Byf4k0rF vsWrUkL5Ou8448s8f3fUenLLhNKQx0pDUdnIR9VzZBTHC3pCfXRTrA== =X2ok -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From jaearick at colby.edu Thu Jan 19 16:28:53 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Thu Jan 19 16:29:09 2006 Subject: where went searchable list archives? Message-ID: Hi, I wanted to search the list archives this morning so I went to: http://www.sng.ecs.soton.ac.uk/mailscanner/support.html and clicked on "search the list archive", thus ending up at: http://www.jiscmail.ac.uk/cgi-bin/wa.exe?S1=mailscanner which said "no list called MailScanner". I tried searching at Gmane, and figured out that I needed to try list "gmane.mail.virus.mailscanner". Right? Maybe the "search the list archive" link needs to be updated? Jeff Earickson Colby College From jaearick at colby.edu Thu Jan 19 16:40:27 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Thu Jan 19 16:40:45 2006 Subject: 4.50.9: winmail.dat rejections Message-ID: Julian, It has been pointed out to me by an Outlook user that the new message in filename.rules.conf is misleading: deny winmail\.dat$ Windows security vulnerability No Outlook Rich Text Format messages due to security hole, use HTML instead That it should say: deny winmail\.dat$ Windows security vulnerability No Outlook Rich Text Format messages due to security hole, use plain-text instead My reading of a couple of googled pages on "winmail.dat problem" implies that selecting HTML mail will generate a winmail.dat file anyway. Jeff Earickson Colby College From Kevin_Miller at ci.juneau.ak.us Thu Jan 19 16:45:20 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Thu Jan 19 16:45:24 2006 Subject: Sendmail not relaying Message-ID: <82895A755D1EA5458EC9E64021922AD2D1561D@city-exch-w3e.cbj.local> Lance Haig wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > just so that everyone knows > > it was the A record that caused the problem > > thank for all the help Glad it's working. And the best part is you get to blame your brother-in-law! That ought to be worth a tall cold one. ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From lhaig at haigmail.com Thu Jan 19 16:49:49 2006 From: lhaig at haigmail.com (Lance Haig) Date: Thu Jan 19 16:49:52 2006 Subject: Sendmail not relaying In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D1561D@city-exch-w3e.cbj.local> References: <82895A755D1EA5458EC9E64021922AD2D1561D@city-exch-w3e.cbj.local> Message-ID: <43CFC32D.1000903@haigmail.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Yip, but I would have to travel 11 hours by plane to get it :-) Lance Kevin Miller wrote: > Lance Haig wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> just so that everyone knows >> >> it was the A record that caused the problem >> >> thank for all the help > > Glad it's working. And the best part is you get to blame your > brother-in-law! That ought to be worth a tall cold one. > > > ...Kevin -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFDz8MtM4kHBIBZ61gRAnchAJ9aiojC+gdIdXybwXJ7sZFSCELrKQCdE8Tt rOHqSgC1PfJ4qGOSVyWOnAE= =8zNW -----END PGP SIGNATURE----- From Kevin_Miller at ci.juneau.ak.us Thu Jan 19 16:51:08 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Thu Jan 19 16:51:11 2006 Subject: Worm.VB-8 Message-ID: <82895A755D1EA5458EC9E64021922AD2D1561E@city-exch-w3e.cbj.local> From Kevin_Miller at ci.juneau.ak.us Thu Jan 19 17:09:22 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Thu Jan 19 17:09:26 2006 Subject: -Worm.VB-8 Message-ID: <82895A755D1EA5458EC9E64021922AD2D15620@city-exch-w3e.cbj.local> Sorry about the previous blank post. My keyboard stuck just as I was finishing and apparently wiped out all I'd typed then sent itself. Sigh. Anyway, what I was asking is who designated this work Worm.VB-8 and what other antivirus companies are catching it. I'm running Trend, F-Secure, and ClamAV. I believe F-Secure is calling it Worm.vb.vi http://www.f-secure.com/v-descs/vb_bi.shtml Not sure if any of the others I use is catching it yet or not. If they are, what are they calling it? Thanks... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From glenn.steen at gmail.com Thu Jan 19 17:48:45 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu Jan 19 17:48:49 2006 Subject: where went searchable list archives? In-Reply-To: References: Message-ID: <223f97700601190948r44805114v@mail.gmail.com> On 19/01/06, Jeff A. Earickson wrote: > Hi, > I wanted to search the list archives this morning so I went to: > > http://www.sng.ecs.soton.ac.uk/mailscanner/support.html > > and clicked on "search the list archive", thus ending up at: > > http://www.jiscmail.ac.uk/cgi-bin/wa.exe?S1=mailscanner > > which said "no list called MailScanner". I tried searching > at Gmane, and figured out that I needed to try list > "gmane.mail.virus.mailscanner". Right? Yup. You might like http://blog.gmane.org/gmane.mail.virus.mailscanner too... there's a prominent search box to the left of the "blogified" ML. > Maybe the "search the > list archive" link needs to be updated? Definitely. Although everything is present in MailMans pipermail, I seem to be unable to find a viable search option... But then, I used gmane (and now my gmail) for that even with the old list...:-) -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From marcel-ml at irc-addicts.de Thu Jan 19 17:00:47 2006 From: marcel-ml at irc-addicts.de (Marcel Blenkers) Date: Thu Jan 19 18:20:49 2006 Subject: MailScanner and sendmail - Problems In-Reply-To: References: <43C41995.3070508@blacknight.ie> Message-ID: Hi there, sorry for the late answer.. my first day at work after a few days ill in bed.. ok.. reinstalled a fresh installation. went through the config-file, edited it..and then set MailScanner to be started at systemreboot Works fine.. rcMailscanner restart works fine rcMailScanner stop just stops MailScanner, sendmail-out and sendmail-client, but sendmail-in still exists. at least, it accepts connections: root 4095 1 0 17:58 ? 00:00:00 sendmail: accepting connections so.. if i do type rcMailScanner stop and then after editing configs rcMailScanner start there are problems.. but restart seems to work fine.. at least.. i hope.. if needed there is still the option to check on my system ;) Greetings Marcel On Wed, 11 Jan 2006, Julian Field wrote: > All I can contribute at this point is that I have specifically tested > MailScanner on SuSE10 and if you follow the instructions correctly it works > fine. > > Not that that helps you much... > > On 10 Jan 2006, at 20:31, Michele Neylon:: Blacknight.ie wrote: > > > Marcel Blenkers wrote: > > > Hi there, > > > > > > i am trying to use the latest Version of MailScanner on SuSE10. > > > > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > ------------------------ MailScanner list ------------------------ > To unsubscribe, email jiscmail@jiscmail.ac.uk with the words: > 'leave mailscanner' in the body of the email. > Before posting, read the Wiki (http://wiki.mailscanner.info/) and > the archives (http://www.jiscmail.ac.uk/lists/mailscanner.html). > > Support MailScanner development - buy the book off the website! > From steve.swaney at fsl.com Thu Jan 19 18:29:07 2006 From: steve.swaney at fsl.com (Stephen Swaney) Date: Thu Jan 19 18:29:10 2006 Subject: MailScanner and sendmail - Problems In-Reply-To: Message-ID: <200601191829.k0JIT8B4008615@bkserver.blacknight.ie> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Marcel Blenkers > Sent: Thursday, January 19, 2006 12:01 PM > To: MailScanner mailing list > Subject: Re: MailScanner and sendmail - Problems > > Hi there, > > sorry for the late answer.. > my first day at work after a few days ill in bed.. > > ok.. > > reinstalled a fresh installation. > went through the config-file, edited it..and then set MailScanner to be > started at systemreboot > > Works fine.. > rcMailscanner restart works fine > rcMailScanner stop just stops MailScanner, sendmail-out and > sendmail-client, but sendmail-in still exists. > at least, it accepts connections: > > root 4095 1 0 17:58 ? 00:00:00 sendmail: accepting > connections > > > so.. > if i do type > rcMailScanner stop > and then after editing configs > rcMailScanner start > there are problems.. > > but restart seems to work fine.. > > at least.. > > i hope.. > > if needed there is still the option to check on my system ;) > > Greetings > > Marcel > > On Wed, 11 Jan 2006, Julian Field wrote: > > > All I can contribute at this point is that I have specifically tested > > MailScanner on SuSE10 and if you follow the instructions correctly it > works > > fine. > > > > Not that that helps you much... > > > > On 10 Jan 2006, at 20:31, Michele Neylon:: Blacknight.ie wrote: > > > > > Marcel Blenkers wrote: > > > > Hi there, > > > > > > > > i am trying to use the latest Version of MailScanner on SuSE10. > > > > > > > > have you tried: sh -x rcMailScanner stop sh -x rcMailScanner stop sh -x rcMailScanner stop to debug the problem? Steve Stephen Swaney Fort Systems Ltd. stephen.swaney@fsl.com www.fsl.com From Kevin_Miller at ci.juneau.ak.us Thu Jan 19 18:54:09 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Thu Jan 19 18:54:15 2006 Subject: FW: F-Secure Security Advisory--Action Required-- Message-ID: <82895A755D1EA5458EC9E64021922AD2D15626@city-exch-w3e.cbj.local> Just an FYI for those that may not have seen it: us-support@f-secure.com wrote: > Dear Valued F-Secure Customer, > > F-Secure Corporation wants to alert you that we released a > security advisory on Thursday January 19th. This advisory > describes a security vulnerability that affects many of our > antivirus products for the Microsoft Windows and Linux > operating systems. Hotfixes for the affected products have > also been published at this time. We want to make sure that > you are aware of the situation so that you can apply the hotfixes as > soon as possible. > > Details of this advisory as well as any required hotfixes can be > found at: > > http://www.f-secure.com/security/fsc-2006-1.shtml > > > > Thank you for your attention, > > F-Secure Inc. ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From alex at nkpanama.com Thu Jan 19 20:01:10 2006 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Thu Jan 19 20:01:23 2006 Subject: 4.50.9: winmail.dat rejections In-Reply-To: References: Message-ID: <43CFF006.8040008@nkpanama.com> Jeff A. Earickson wrote: > Julian, > > It has been pointed out to me by an Outlook user that the > new message in filename.rules.conf is misleading: > > deny winmail\.dat$ Windows security > vulnerability No Outlook Rich Text Format > messages due to security hole, use HTML instead > > That it should say: > > deny winmail\.dat$ Windows security > vulnerability No Outlook Rich Text Format > messages due to security hole, use plain-text instead > > My reading of a couple of googled pages on "winmail.dat problem" > implies that selecting HTML mail will generate a winmail.dat > file anyway. > > Jeff Earickson > Colby College Only in some outlook incarnations. Depends on several factors, including whether or not M-Sexchange compatibility is installed, or if there's an M-Sexchange server in the middle, etc. -- Alex Neuman van der Hans N&K Technology Consultants Tel. +507 214-9002 - http://nkpanama.com/ From marcel-ml at irc-addicts.de Thu Jan 19 20:03:27 2006 From: marcel-ml at irc-addicts.de (Marcel Blenkers) Date: Thu Jan 19 20:04:12 2006 Subject: Nothing to receive Message-ID: Hi there, is there a way to receive mails again? Maybe i am stupid, but as seen on the webinterface, mails are received but not bounced to me? I looked for the IP within the Mail-Logs, but nothing found.. Any ideas? Marcel From marcel-ml at irc-addicts.de Thu Jan 19 20:10:55 2006 From: marcel-ml at irc-addicts.de (Marcel Blenkers) Date: Thu Jan 19 20:11:12 2006 Subject: Additional Infos Message-ID: hi there, tried with the webinterface on http://lists.mailscanner.info/mailman/listinfo/mailscanner to receive a password reminder or even unsubscribe of the mails. But.. no mails are here on the server.. :( Any there any problems currently known? Greetings Marcel From marcel-ml at irc-addicts.de Thu Jan 19 20:21:11 2006 From: marcel-ml at irc-addicts.de (Marcel Blenkers) Date: Thu Jan 19 20:21:49 2006 Subject: Problem solved. Message-ID: Sorry for the Problems.. now it seems to work.. and i was able to reactivate my account. Marcel From mailscanner at mango.zw Thu Jan 19 20:40:24 2006 From: mailscanner at mango.zw (Jim Holland) Date: Thu Jan 19 20:42:49 2006 Subject: -Worm.VB-8 In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D15620@city-exch-w3e.cbj.local> Message-ID: On Thu, 19 Jan 2006, Kevin Miller wrote: > Anyway, what I was asking is who designated this work Worm.VB-8 and what > other antivirus companies are catching it. I'm running Trend, F-Secure, > and ClamAV. ClamAV called the original variant, which involved executable attachments, Worm.VB-8. The problem variant now seems to be called Worm.VB-9, which is the one that involves the uuencoded attachments that when decoded produce what ClamAV calls Worm.VB-8. > I believe F-Secure is calling it Worm.vb.vi > http://www.f-secure.com/v-descs/vb_bi.shtml > > Not sure if any of the others I use is catching it yet or not. If they > are, what are they calling it? I have no info on other scanners. Regards Jim Holland System Administrator MANGO - Zimbabwe's non-profit e-mail service From gborders at jlewiscooper.com Thu Jan 19 21:03:29 2006 From: gborders at jlewiscooper.com (Greg Borders) Date: Thu Jan 19 21:06:05 2006 Subject: MailScanner and sendmail - Problems In-Reply-To: References: <43C41995.3070508@blacknight.ie> Message-ID: <43CFFEA1.4020804@jlewiscooper.com> Marcel Blenkers wrote: > reinstalled a fresh installation. > went through the config-file, edited it..and then set MailScanner to be > started at systemreboot > > Works fine.. > rcMailscanner restart works fine > rcMailScanner stop just stops MailScanner, sendmail-out and > sendmail-client, but sendmail-in still exists Perhaps you still have the sendmail running in daemon mode? I've seen all too often of those putting in new installs that don't turn off the MTA first. It's not directly intuitive to some that MailScanner takes over the control of the MTA, in launching it's own copies of sendmail as it needs too. Typically, scanners are boltons to the MTA, or run as independant daemons like SA can. Julian's clever coding takes great advantage of the ability to run dedicated instances of sendmail (or any MTA) and SA. They act like lil mail soldiers under Admiral MailScanner, ridding us of evil SPAM juggernauts that try to invade our toasters! I've not heard my boss even mention things like dedicated boxes like the Baraccudas since we've installed MS here at my company. ^_^ Thanks Julian for the hard work! I'll get the boss to order up a copy of your book soon. Greg Borders Sys. Admin. JLC Co. -- This transmission may contain information that is privileged, confidential and/or exempt from disclosure under applicable law. If you are not the intended recipient, you are hereby notified that any disclosure, copying, distribution, or use of the information contained herein (including any reliance thereon) is STRICTLY PROHIBITED. If you received this transmission in error, please immediately contact the sender and destroy the material in its entirety, whether in electronic or hard copy format. Thank you. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From pete at enitech.com.au Fri Jan 20 03:34:27 2006 From: pete at enitech.com.au (Peter Russell) Date: Fri Jan 20 03:34:32 2006 Subject: Non Spam Notify? Message-ID: <43D05A43.9080802@enitech.com.au> I want to make a rule set that does the following but also notifies mark@whoknows.com wwith a custom message. # Non Spam Actions From: mark@whoknows.com and To: my.user@* forward feedback@domain.com FromOrTo: default deliver Is it possible to notify non spam recipients in MS orr do i need to look to my MTA for these features? I have looked in examples and the book and see no obvious way off using Notify equivilent with Non Spam actions. Kind regards and thanks Pete From Carl.Andrews at crackerbarrel.com Fri Jan 20 04:18:16 2006 From: Carl.Andrews at crackerbarrel.com (Andrews Carl 448) Date: Fri Jan 20 04:19:17 2006 Subject: rc.status & rc_status ?? - 4.50.10-1 Message-ID: <18BAD67B3136234285A06EB137C5CBD102F9EC44@exchange03.CBOCS.com> Hi! I have just downloaded and installed(?) 4.50.10-1 and the /etc/init.d/MailScanner calls rc.status and rc_status, which appear to be suse - I installed the rpm version on CentOS. From what I can find rc.status is a suse program. Did I install the wrong version or can I get rc.status for CentOS? Thanks! Carl From Carl.Andrews at crackerbarrel.com Fri Jan 20 04:27:31 2006 From: Carl.Andrews at crackerbarrel.com (Andrews Carl 448) Date: Fri Jan 20 04:28:29 2006 Subject: rc.status & rc_status ?? - 4.50.10-1 Message-ID: <18BAD67B3136234285A06EB137C5CBD102F9EC45@exchange03.CBOCS.com> I extracted /etc/rc.d/init.d/MailScanner from the 4.49.7-1 rpm and placed it in /etc/init.d. I am able to stop and start MailScanner, did I loose or break anything by doing this? Thanks Again! -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Andrews Carl 448 Sent: Thursday, January 19, 2006 10:18 PM To: MailScanner discussion Subject: rc.status & rc_status ?? - 4.50.10-1 Hi! I have just downloaded and installed(?) 4.50.10-1 and the /etc/init.d/MailScanner calls rc.status and rc_status, which appear to be suse - I installed the rpm version on CentOS. From what I can find rc.status is a suse program. Did I install the wrong version or can I get rc.status for CentOS? Thanks! Carl -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From fajarep at simplimobile.com Fri Jan 20 06:49:16 2006 From: fajarep at simplimobile.com (Fajar) Date: Fri Jan 20 06:49:27 2006 Subject: Bug with mailwatch or mailscanner? Message-ID: <00ec01c61d8d$a21d47e0$2f01a8c0@Fajar> Dear All, I'm using mailwatch to watch my mailscanner activities. But I found a little bug doesn't know it's the problem with my mailscanner or my mailwatch. I'm enable blacklist function, so every mail that blacklisted using mailwatch will get dropped. Situation : No blacklist in mysql database, restart mailscanner, adding some blacklists, yep, it's working.Nothing wrong. Next restart my mailscanner, i still have my blacklisted emails, yep, it's working. But then I'm deleting my blacklist, yep, my mysql blacklist table is clear, but mailscanner still mark the email that comes from that user as blacklisted. Here is the log after I clear my blacklist. Jan 20 13:38:41 alpha MailScanner[16730]: Starting up SQL Blacklist Jan 20 13:38:41 alpha MailScanner[16730]: Read 0 blacklist entries Jan 20 13:38:41 alpha MailScanner[16730]: Spam Checks: Found 1 spam messages And those spam message is marked as blacklist. But if I restart my mailscanner again, those emails won't be marked as blacklisted email. Someone know what is the problem? Thanks I'm using the latest MailScanner, with Mysql 4, latest MailWatch, Ubuntu, Postfix, Policyd. Fajar -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060120/93e6f69a/attachment.html From smf at f2s.com Fri Jan 20 08:50:38 2006 From: smf at f2s.com (Steve Freegard) Date: Fri Jan 20 08:48:50 2006 Subject: Bug with mailwatch or mailscanner? In-Reply-To: <00ec01c61d8d$a21d47e0$2f01a8c0@Fajar> References: <00ec01c61d8d$a21d47e0$2f01a8c0@Fajar> Message-ID: <1137747038.26473.527.camel@localhost.localdomain> Hi Fajar, On Fri, 2006-01-20 at 13:49 +0700, Fajar wrote: > > But if I restart my mailscanner again, those emails won't be marked as > blacklisted email. > This isn't a bug in either MailWatch or MailScanner - the MailScanner rules files and configuration are read into memory when MailScanner starts (for speed) and are not re-read until you either reload/restart MailScanner or when the MailScanner child is restarted automatically (see the 'Restart Every' value in MailScanner.conf - default is 4 hours). The blacklist supplied with MailWatch doesn't support all of the options available to you in a MailScanner ruleset (it does exact matching on user, domain, IP address or a default entry - no wildcards are supported at all) and this data is re-read every 15 minutes by default (configurable in the .pm file). Kind regards, Steve. From john at tradoc.fr Fri Jan 20 09:04:12 2006 From: john at tradoc.fr (John Wilcock) Date: Fri Jan 20 09:04:19 2006 Subject: -Worm.VB-8 In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D15620@city-exch-w3e.cbj.local> References: <82895A755D1EA5458EC9E64021922AD2D15620@city-exch-w3e.cbj.local> Message-ID: <43D0A78C.9040404@tradoc.fr> Kevin Miller wrote: > I believe F-Secure is calling it Worm.vb.vi > http://www.f-secure.com/v-descs/vb_bi.shtml > > Not sure if any of the others I use is catching it yet or not. If they > are, what are they calling it? F-Prot are calling it W32/Kapser.A@mm, FWIW. John. -- -- Over 3000 webcams from ski resorts around the world - www.snoweye.com -- Translate your technical documents and web pages - www.tradoc.fr From philipp.snizek at terreactive.ch Fri Jan 20 09:11:55 2006 From: philipp.snizek at terreactive.ch (Philipp Snizek) Date: Fri Jan 20 09:12:03 2006 Subject: still wrong SA score set used In-Reply-To: <1137747038.26473.527.camel@localhost.localdomain> References: <00ec01c61d8d$a21d47e0$2f01a8c0@Fajar> <1137747038.26473.527.camel@localhost.localdomain> Message-ID: <1137748315.31962.6.camel@philipp.terreactive.ch> Hi I use SA 3.1 and MailScanner 4.49.7 When I run `spamassassin --lint -D -C /etc/MailScanner/spam.assassin.prefs.conf` SpamAssassin tells me that it would use score set 3 which is, what I want. When I send a spam email through my exim/mailscanner/sa box score set 2 is used. MailScanner uses /etc/MailScanner/spam.assassin.prefs.conf too. Is this MailScanner default to use SA score set 2 or what do I miss in my MailScanner.conf file? Thanks a lot Best, Philipp From martinh at solid-state-logic.com Fri Jan 20 09:25:17 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Fri Jan 20 09:25:30 2006 Subject: still wrong SA score set used In-Reply-To: <1137748315.31962.6.camel@philipp.terreactive.ch> Message-ID: <008d01c61da3$6d5e9e30$3004010a@martinhlaptop> What rules fire when the email is scanned with 'spamassassin' and what rules fire when you scan using MailScanner? You may need to edit the MailScanner.conf to get it include the SA rules and scores always in order for you to get this info from MailScanner. If you're not sure which settings to change reply back and I'll me more verbose. BTW in 4.49 you don't need the "-C" (which should actually be "-P") as /etc/mail/spamassassin/mailscanner should be a symbolic link to spam.assassin.prefs.conf. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Philipp Snizek > Sent: 20 January 2006 09:12 > To: MailScanner discussion > Subject: still wrong SA score set used > > Hi > > I use SA 3.1 and MailScanner 4.49.7 > > When I run > `spamassassin --lint -D -C /etc/MailScanner/spam.assassin.prefs.conf` > SpamAssassin tells me that it would use score set 3 which is, what I > want. > When I send a spam email through my exim/mailscanner/sa box score set 2 > is used. MailScanner uses /etc/MailScanner/spam.assassin.prefs.conf too. > > > Is this MailScanner default to use SA score set 2 or what do I miss in > my MailScanner.conf file? > > Thanks a lot > > Best, > Philipp > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From tenderby at mailwash.com.au Fri Jan 20 09:34:24 2006 From: tenderby at mailwash.com.au (Tony Enderby) Date: Fri Jan 20 09:33:48 2006 Subject: Test Message-ID: <43D0AEA0.2020109@mailwash.com.au> Testing, haven't received messages from the list for 48 hours - please ignore and delete. From lhaig at haigmail.com Fri Jan 20 11:26:54 2006 From: lhaig at haigmail.com (Lance Haig) Date: Fri Jan 20 11:27:03 2006 Subject: Which version to upgrade to Message-ID: <43D0C8FE.4040607@haigmail.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi Guys, I am running SUSE 9.3 with MS Version 4.47.4 I want to upgrade but want to know which would be the best version to use. Thanks Lance -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFD0Mj+M4kHBIBZ61gRAuAxAKCBHz56dEPUOAKhaNmgEicc3lf9rgCdEB0R Twqdo4ssjRdUJ0lzWkdPwKQ= =6oYi -----END PGP SIGNATURE----- From richard.gray at dns.co.uk Fri Jan 20 12:18:41 2006 From: richard.gray at dns.co.uk (Gray, Richard) Date: Fri Jan 20 12:18:45 2006 Subject: Ruleset based Content Filtering Message-ID: Hi, I'd like to use the Content based filtering to implement a clean language policy. However, I want to have different languages used for different domains. E.G. testdomain.de should have the German MCP rules applied to it, while testdomain.co.uk should have british MCP rules applied. I have investigated this and can't see where i need to change a setting in order to make this the case, can anyone give me any pointers? I've tried changing the MCP Spamassassin rules, but these are fixed as simple values rather than rulesets. :( Thanks in advance for your help, Richard ________________________________ richard gray dns ltd 83 princes street, edinburgh, eh2 2er t: +44 (0) 870 085 8555 f: +44 (0) 870 085 8556 m: +44 (0) 777 569 2145 w: http://www.dns.co.uk/ ----------------------- This email from dns has been validated by dnsMSS(TM) Managed Email Security and is free from all known viruses. For further information contact email-integrity@dns.co.uk -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060120/8495e225/attachment.html From martinh at solid-state-logic.com Fri Jan 20 12:50:28 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Fri Jan 20 12:50:51 2006 Subject: Ruleset based Content Filtering In-Reply-To: Message-ID: <002501c61dc0$1761a780$3004010a@martinhlaptop> Richard There's the thing in the wiki I wrote (well OK I transcribed one of Julian's emails ;-) where it talks about ruleset overloading.... That should get you started... http://wiki.mailscanner.info/doku.php?id=documentation:configuration:ruleset s:overloading -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Gray, Richard > Sent: 20 January 2006 12:19 > To: MailScanner discussion > Subject: Ruleset based Content Filtering > > Hi, > > I'd like to use the Content based filtering to implement a clean language > policy. However, I want to have different languages used for different > domains. > > E.G. testdomain.de should have the German MCP rules applied to it, while > testdomain.co.uk should have british MCP rules applied. > > I have investigated this and can't see where i need to change a setting in > order to make this the case, can anyone give me any pointers? I've tried > changing the MCP Spamassassin rules, but these are fixed as simple values > rather than rulesets. :( > > Thanks in advance for your help, > > Richard > > ________________________________ > > richard gray > dns ltd > > 83 princes street, edinburgh, eh2 2er > > t: +44 (0) 870 085 8555 > f: +44 (0) 870 085 8556 > m: +44 (0) 777 569 2145 > w: http://www.dns.co.uk/ > > ________________________________ > > > This email from dns has been validated by dnsMSSTM Managed Email Security > and is free from all known viruses. > > For further information contact email-integrity@dns.co.uk ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From richard.gray at dns.co.uk Fri Jan 20 13:25:20 2006 From: richard.gray at dns.co.uk (Gray, Richard) Date: Fri Jan 20 13:25:27 2006 Subject: Ruleset based Content Filtering Message-ID: I had previously looked at that, but couldn't over come the fact that all the rule locations for SA have to be simple values rather than rulesets, so I can't overload as described. Or am I misunderstanding something more fundamental? R > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Martin Hepworth > Sent: 20 January 2006 12:50 > To: 'MailScanner discussion' > Subject: RE: Ruleset based Content Filtering > > Richard > > There's the thing in the wiki I wrote (well OK I transcribed > one of Julian's emails ;-) where it talks about ruleset > overloading.... > > That should get you started... > > http://wiki.mailscanner.info/doku.php?id=documentation:configu > ration:ruleset > s:overloading > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Gray, Richard > > Sent: 20 January 2006 12:19 > > To: MailScanner discussion > > Subject: Ruleset based Content Filtering > > > > Hi, > > > > I'd like to use the Content based filtering to implement a clean > > language policy. However, I want to have different > languages used for > > different domains. > > > > E.G. testdomain.de should have the German MCP rules applied to it, > > while testdomain.co.uk should have british MCP rules applied. > > > > I have investigated this and can't see where i need to change a > > setting in order to make this the case, can anyone give me any > > pointers? I've tried changing the MCP Spamassassin rules, but these > > are fixed as simple values rather than rulesets. :( > > > > Thanks in advance for your help, > > > > Richard > > > > ________________________________ > > > > richard gray > > dns ltd > > > > 83 princes street, edinburgh, eh2 2er > > > > t: +44 (0) 870 085 8555 > > f: +44 (0) 870 085 8556 > > m: +44 (0) 777 569 2145 > > w: http://www.dns.co.uk/ > > > > ________________________________ > > > > > > This email from dns has been validated by dnsMSSTM Managed Email > > Security and is free from all known viruses. > > > > For further information contact email-integrity@dns.co.uk > > > > ********************************************************************** > > This email and any files transmitted with it are confidential > and intended solely for the use of the individual or entity > to whom they are addressed. If you have received this email > in error please notify the system manager. > > This footnote confirms that this email message has been swept > for the presence of computer viruses and is believed to be clean. > > ********************************************************************** > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > ----------------------- This email from dns has been validated by dnsMSS(TM) Managed Email Security and is free from all known viruses. For further information contact email-integrity@dns.co.uk From mailstodevi at yahoo.com Fri Jan 20 13:29:51 2006 From: mailstodevi at yahoo.com (Devi S) Date: Fri Jan 20 13:29:54 2006 Subject: zip file blocked, but some mails coming Message-ID: <20060120132952.13244.qmail@web50610.mail.yahoo.com> I have blocked all the zip files using the filename.rules.conf. But, few mails, particularly from few senders the mails are not blocked. my filename.rules is, FromOrTo: default /etc/MailScanner/filename.rules.conf MY configuration for filename.rules in MailScanner.conf is, Filename Rules = %rules-dir%/filename.rules Can someone guide me on what is going wrong in my configuration? (I am running MailScanner in whitebox linux) Thank you. Regards Devi S. Our greatest glory is not in never falling- but in rising every time we fall - Confucius --------------------------------- Yahoo! Photos ? Showcase holiday pictures in hardcover Photo Books. You design it and we?ll bind it! -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060120/0af974f1/attachment.html From MailScanner at ecs.soton.ac.uk Fri Jan 20 13:47:21 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 20 13:47:32 2006 Subject: zip file blocked, but some mails coming In-Reply-To: <20060120132952.13244.qmail@web50610.mail.yahoo.com> References: <20060120132952.13244.qmail@web50610.mail.yahoo.com> Message-ID: Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: PGP.sig Type: application/pgp-signature Size: 487 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060120/31895bdf/PGP.bin From martinh at solid-state-logic.com Fri Jan 20 13:50:41 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Fri Jan 20 13:50:54 2006 Subject: Ruleset based Content Filtering In-Reply-To: Message-ID: <003901c61dc8$80f655d0$3004010a@martinhlaptop> Ah sorry I get your drift. I think (willing to be corrected) Only way of doing this would be to have different MS instances looking at the different MTAs for each domain.... Unless Jules is feeling kind and makes the MCP_DIR be available as a ruleset....somehow.... -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Gray, Richard > Sent: 20 January 2006 13:25 > To: MailScanner discussion > Subject: RE: Ruleset based Content Filtering > > I had previously looked at that, but couldn't over come the fact that > all the rule locations for SA have to be simple values rather than > rulesets, so I can't overload as described. > > Or am I misunderstanding something more fundamental? > > R > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > > Of Martin Hepworth > > Sent: 20 January 2006 12:50 > > To: 'MailScanner discussion' > > Subject: RE: Ruleset based Content Filtering > > > > Richard > > > > There's the thing in the wiki I wrote (well OK I transcribed > > one of Julian's emails ;-) where it talks about ruleset > > overloading.... > > > > That should get you started... > > > > http://wiki.mailscanner.info/doku.php?id=documentation:configu > > ration:ruleset > > s:overloading > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner- > > > bounces@lists.mailscanner.info] On Behalf Of Gray, Richard > > > Sent: 20 January 2006 12:19 > > > To: MailScanner discussion > > > Subject: Ruleset based Content Filtering > > > > > > Hi, > > > > > > I'd like to use the Content based filtering to implement a clean > > > language policy. However, I want to have different > > languages used for > > > different domains. > > > > > > E.G. testdomain.de should have the German MCP rules applied to it, > > > while testdomain.co.uk should have british MCP rules applied. > > > > > > I have investigated this and can't see where i need to change a > > > setting in order to make this the case, can anyone give me any > > > pointers? I've tried changing the MCP Spamassassin rules, but these > > > are fixed as simple values rather than rulesets. :( > > > > > > Thanks in advance for your help, > > > > > > Richard > > > > > > ________________________________ > > > > > > richard gray > > > dns ltd > > > > > > 83 princes street, edinburgh, eh2 2er > > > > > > t: +44 (0) 870 085 8555 > > > f: +44 (0) 870 085 8556 > > > m: +44 (0) 777 569 2145 > > > w: http://www.dns.co.uk/ > > > > > > ________________________________ > > > > > > > > > This email from dns has been validated by dnsMSSTM Managed Email > > > Security and is free from all known viruses. > > > > > > For further information contact email-integrity@dns.co.uk > > > > > > > > ********************************************************************** > > > > This email and any files transmitted with it are confidential > > and intended solely for the use of the individual or entity > > to whom they are addressed. If you have received this email > > in error please notify the system manager. > > > > This footnote confirms that this email message has been swept > > for the presence of computer viruses and is believed to be clean. > > > > ********************************************************************** > > > > -- > > MailScanner mailing list > > MailScanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > ----------------------- > This email from dns has been validated by dnsMSS(TM) Managed Email > Security and is free from all known viruses. > > For further information contact email-integrity@dns.co.uk > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From MailScanner at ecs.soton.ac.uk Fri Jan 20 13:59:25 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 20 13:59:34 2006 Subject: Ruleset based Content Filtering In-Reply-To: <003901c61dc8$80f655d0$3004010a@martinhlaptop> References: <003901c61dc8$80f655d0$3004010a@martinhlaptop> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Almost impossible to do, sorry. On 20 Jan 2006, at 13:50, Martin Hepworth wrote: > > > Ah sorry I get your drift. > > I think (willing to be corrected) Only way of doing this would be > to have > different MS instances looking at the different MTAs for each > domain.... > > Unless Jules is feeling kind and makes the MCP_DIR be available as a > ruleset....somehow.... > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Gray, Richard >> Sent: 20 January 2006 13:25 >> To: MailScanner discussion >> Subject: RE: Ruleset based Content Filtering >> >> I had previously looked at that, but couldn't over come the fact that >> all the rule locations for SA have to be simple values rather than >> rulesets, so I can't overload as described. >> >> Or am I misunderstanding something more fundamental? >> >> R >> >>> -----Original Message----- >>> From: mailscanner-bounces@lists.mailscanner.info >>> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf >>> Of Martin Hepworth >>> Sent: 20 January 2006 12:50 >>> To: 'MailScanner discussion' >>> Subject: RE: Ruleset based Content Filtering >>> >>> Richard >>> >>> There's the thing in the wiki I wrote (well OK I transcribed >>> one of Julian's emails ;-) where it talks about ruleset >>> overloading.... >>> >>> That should get you started... >>> >>> http://wiki.mailscanner.info/doku.php?id=documentation:configu >>> ration:ruleset >>> s:overloading >>> >>> -- >>> Martin Hepworth >>> Snr Systems Administrator >>> Solid State Logic >>> Tel: +44 (0)1865 842300 >>> >>>> -----Original Message----- >>>> From: mailscanner-bounces@lists.mailscanner.info >>> [mailto:mailscanner- >>>> bounces@lists.mailscanner.info] On Behalf Of Gray, Richard >>>> Sent: 20 January 2006 12:19 >>>> To: MailScanner discussion >>>> Subject: Ruleset based Content Filtering >>>> >>>> Hi, >>>> >>>> I'd like to use the Content based filtering to implement a clean >>>> language policy. However, I want to have different >>> languages used for >>>> different domains. >>>> >>>> E.G. testdomain.de should have the German MCP rules applied to it, >>>> while testdomain.co.uk should have british MCP rules applied. >>>> >>>> I have investigated this and can't see where i need to change a >>>> setting in order to make this the case, can anyone give me any >>>> pointers? I've tried changing the MCP Spamassassin rules, but these >>>> are fixed as simple values rather than rulesets. :( >>>> >>>> Thanks in advance for your help, >>>> >>>> Richard >>>> >>>> ________________________________ >>>> >>>> richard gray >>>> dns ltd >>>> >>>> 83 princes street, edinburgh, eh2 2er >>>> >>>> t: +44 (0) 870 085 8555 >>>> f: +44 (0) 870 085 8556 >>>> m: +44 (0) 777 569 2145 >>>> w: http://www.dns.co.uk/ >>>> >>>> ________________________________ >>>> >>>> >>>> This email from dns has been validated by dnsMSSTM Managed Email >>>> Security and is free from all known viruses. >>>> >>>> For further information contact email-integrity@dns.co.uk >>> >>> >>> >>> ******************************************************************** >>> ** >>> >>> This email and any files transmitted with it are confidential >>> and intended solely for the use of the individual or entity >>> to whom they are addressed. If you have received this email >>> in error please notify the system manager. >>> >>> This footnote confirms that this email message has been swept >>> for the presence of computer viruses and is believed to be clean. >>> >>> ******************************************************************** >>> ** >>> >>> -- >>> MailScanner mailing list >>> MailScanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> >>> Before posting, read http://wiki.mailscanner.info/posting >>> >>> Support MailScanner development - buy the book off the website! >>> >> >> ----------------------- >> This email from dns has been validated by dnsMSS(TM) Managed Email >> Security and is free from all known viruses. >> >> For further information contact email-integrity@dns.co.uk >> >> >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > > ********************************************************************** > > This email and any files transmitted with it are confidential and > intended solely for the use of the individual or entity to whom they > are addressed. If you have received this email in error please notify > the system manager. > > This footnote confirms that this email message has been swept > for the presence of computer viruses and is believed to be clean. > > ********************************************************************** > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ9DswPw32o+k+q+hAQHJ0ggAg7ac5XvRfqmzLyPCrtOwneBOVA+zCZ0c hlwyt+7KJqNdMh2KjbCK2To3kSNHo2jRCAVcoSB6vY1eUwkgt2TFrZWNZwByzkvw l//jCZn16u4CEWsF4bf4ycYeU37UiP4BzEyNwkKJwcpcd96+h2fq34hzp1ethDH/ cCeZIOzQ6oe/0iYedmrQUxRGUAeXz5GL5J36toKjPc+c98sgvV6g8qKpeIpa4bHl ECgd8t6V997uyQsp8l0GlWvkr6LPVqWCYwwms+MBEOjYRPPMLsYnWLIZOEHza7OC DfXf677NDf9ElObK3PwIUiF1KdFCwFx8Sovv3eJWtE+RnEnKVDQeaQ== =8Ms7 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ka at pacific.net Fri Jan 20 15:55:18 2006 From: ka at pacific.net (Ken A) Date: Fri Jan 20 15:55:21 2006 Subject: Which version to upgrade to In-Reply-To: <43D0C8FE.4040607@haigmail.com> References: <43D0C8FE.4040607@haigmail.com> Message-ID: <43D107E6.4080603@pacific.net> We just did a similar upgrade on 3 redhat boxes. The latest 4.5x is much faster than < 4.49, and is quite stable here on 300k + emails a day. Ken Pacific.Net Lance Haig wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Hi Guys, > > I am running SUSE 9.3 with MS Version 4.47.4 > > I want to upgrade but want to know which would be the best version to use. > > Thanks > > Lance > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.2 (MingW32) > Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org > > iD8DBQFD0Mj+M4kHBIBZ61gRAuAxAKCBHz56dEPUOAKhaNmgEicc3lf9rgCdEB0R > Twqdo4ssjRdUJ0lzWkdPwKQ= > =6oYi > -----END PGP SIGNATURE----- From lhaig at haigmail.com Fri Jan 20 16:06:28 2006 From: lhaig at haigmail.com (Lance Haig) Date: Fri Jan 20 16:06:34 2006 Subject: Which version to upgrade to In-Reply-To: <43D107E6.4080603@pacific.net> References: <43D0C8FE.4040607@haigmail.com> <43D107E6.4080603@pacific.net> Message-ID: <43D10A84.80100@haigmail.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi Ken, I don't do anywhere near what you are doing so I think I will be fine. Thanks Lance Ken A wrote: > We just did a similar upgrade on 3 redhat boxes. The latest 4.5x is much > faster than < 4.49, and is quite stable here on 300k + emails a day. > > Ken > Pacific.Net > > > Lance Haig wrote: > Hi Guys, > > I am running SUSE 9.3 with MS Version 4.47.4 > > I want to upgrade but want to know which would be the best version to > use. > > Thanks > > Lance -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFD0QqEM4kHBIBZ61gRAsFPAJwJEORaFTqfhwCRrnONnHnhsPzOAgCfcuL+ B5hTQGTPM5FDfc9tqyMrGzM= =ZynT -----END PGP SIGNATURE----- From andrew at pirates.armstrong.edu Fri Jan 20 20:03:51 2006 From: andrew at pirates.armstrong.edu (andrew@pirates.armstrong.edu) Date: Fri Jan 20 20:03:55 2006 Subject: /tmp/McAfeeBusy.lock Message-ID: <20060120200351.GA20468@pirates.Armstrong.EDU> I somehow got a lockfile owned by root left around on my system, /tmp/McAfeeBusy.lock. This caused mailscanner to skip the virus checking and deliver infected email. Would it be possible just to stop delivery under these circumstances? I tested using Mailscanner version 4.49.7 and 4.39.6. -- Andrew Eason System Administrator andrew@armstrong.edu From ssilva at sgvwater.com Fri Jan 20 21:28:58 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Jan 20 21:29:45 2006 Subject: /tmp/McAfeeBusy.lock In-Reply-To: <20060120200351.GA20468@pirates.Armstrong.EDU> References: <20060120200351.GA20468@pirates.Armstrong.EDU> Message-ID: andrew@pirates.armstrong.edu spake the following on 1/20/2006 12:03 PM: > I somehow got a lockfile owned by root left around on my system, > /tmp/McAfeeBusy.lock. This caused mailscanner to skip the virus checking > and deliver infected email. Would it be possible just to stop delivery > under these circumstances? > > > > I tested using Mailscanner version 4.49.7 and 4.39.6. > > Another reason to have more than 1 virus scanner. ClamAV and Bitdefender are free. -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () From MailScanner at ecs.soton.ac.uk Fri Jan 20 21:41:19 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 20 21:41:24 2006 Subject: /tmp/McAfeeBusy.lock In-Reply-To: <20060120200351.GA20468@pirates.Armstrong.EDU> References: <20060120200351.GA20468@pirates.Armstrong.EDU> Message-ID: <43D158FF.7010907@ecs.soton.ac.uk> andrew@pirates.armstrong.edu wrote: > I somehow got a lockfile owned by root left around on my system, > /tmp/McAfeeBusy.lock. This caused mailscanner to skip the virus checking > and deliver infected email. Would it be possible just to stop delivery > under these circumstances? > That certainly shouldn't happen! Please can you double-check your results. It should just cause the virus scanner to wait until the file was lockable. Please try it with the EICAR virus pattern (from www.eicar.org) which is a harmless test file, and let me know the result. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Fri Jan 20 21:54:57 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 20 21:55:02 2006 Subject: /tmp/McAfeeBusy.lock In-Reply-To: <43D158FF.7010907@ecs.soton.ac.uk> References: <20060120200351.GA20468@pirates.Armstrong.EDU> <43D158FF.7010907@ecs.soton.ac.uk> Message-ID: <43D15C31.3070406@ecs.soton.ac.uk> Julian Field wrote: > andrew@pirates.armstrong.edu wrote: >> I somehow got a lockfile owned by root left around on my system, >> /tmp/McAfeeBusy.lock. This caused mailscanner to skip the virus >> checking >> and deliver infected email. Would it be possible just to stop delivery >> under these circumstances? >> > That certainly shouldn't happen! Please can you double-check your > results. > It should just cause the virus scanner to wait until the file was > lockable. > Please try it with the EICAR virus pattern (from www.eicar.org) which > is a harmless test file, and let me know the result. > I have just tested this and it worked just fine. Not sure what you did, but I would request that you re-do your tests. I cannot reproduce the behaviour that you found. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From jayesha_shinde at yahoo.com Fri Jan 20 11:12:56 2006 From: jayesha_shinde at yahoo.com (jay shi) Date: Sat Jan 21 12:23:10 2006 Subject: sendmail :- how to mail attchment restriction Message-ID: <20060120111256.62697.qmail@web32201.mail.mud.yahoo.com> Hi all , I need help from u all . I am using sendmail sever along with Mailscanner . I want to configure the sendmail server in such way that , each user must get differernet mail attchment size restriction , And on priority bases i can vary the mail attchment size per user . In Mailscanner there is potion for userwise message size & userwise mail attchment restriction under /etc/MailScanner/MailScanner.conf Maximum Attachment Size = -1 Minimum Message Size = -1 I change the above for the required result Is ther any way to do this , wating for u all , Thanks & Regards jayesha __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com From MailScanner at ecs.soton.ac.uk Sat Jan 21 12:45:19 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat Jan 21 12:45:28 2006 Subject: sendmail :- how to mail attchment restriction In-Reply-To: <20060120111256.62697.qmail@web32201.mail.mud.yahoo.com> References: <20060120111256.62697.qmail@web32201.mail.mud.yahoo.com> Message-ID: <43D22CDF.2010105@ecs.soton.ac.uk> Please read about rulesets. And please read the documentation before you post messages here. jay shi wrote: > Hi all , > I need help from u all . > I am using sendmail sever along with Mailscanner . > I want to configure the sendmail server in such way > that , each user must get differernet mail > attchment size restriction , And on priority bases i > can vary the mail attchment size per user . > > In Mailscanner there is potion for userwise message > size & userwise mail attchment restriction > under /etc/MailScanner/MailScanner.conf > Maximum Attachment Size = -1 > Minimum Message Size = -1 > > I change the above for the required result > > > > Is ther any way to do this , > wating for u all , > Thanks & Regards > jayesha > > > __________________________________________________ > Do You Yahoo!? > Tired of spam? Yahoo! Mail has the best spam protection around > http://mail.yahoo.com > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From jaearick at colby.edu Sat Jan 21 12:59:17 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Sat Jan 21 12:59:23 2006 Subject: MS 4.50: way cool... Message-ID: Julian, In my nightly report at 4 AM last night, the cache hit rate was 72%. Wowee! With the HighRes timings, I use that information to compute how long batches take, and some statistics. From yesterday: ===Mailscanner Summaries: Total messages scanned: 28180 Total Message Batches: 20368 Average Messages per Batch: 1.38 Minimum Batch Time (sec): 2.57 Maximum Batch Time (sec): 185.12 Average Batch Time (sec): 8.45 Total MBytes scanned: 1011.47 Total virii detected: 31 Total spams tagged: 4702 Total spams delivered: 1679 Total spams deleted: 3274 The batch timing gives a good overall clue as to the speed/efficiency of one's system. Thanks! Jeff Earickson Colby College From MailScanner at ecs.soton.ac.uk Sat Jan 21 13:03:33 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat Jan 21 13:03:39 2006 Subject: MS 4.50: way cool... In-Reply-To: References: Message-ID: <43D23125.4020407@ecs.soton.ac.uk> Glad you like it, it is much appreciated. Cheers, Jules. Jeff A. Earickson wrote: > Julian, > In my nightly report at 4 AM last night, the cache hit rate > was 72%. Wowee! > > With the HighRes timings, I use that information to compute how > long batches take, and some statistics. From yesterday: > > ===Mailscanner Summaries: > Total messages scanned: 28180 > Total Message Batches: 20368 > Average Messages per Batch: 1.38 > Minimum Batch Time (sec): 2.57 > Maximum Batch Time (sec): 185.12 > Average Batch Time (sec): 8.45 > Total MBytes scanned: 1011.47 > Total virii detected: 31 > Total spams tagged: 4702 > Total spams delivered: 1679 > Total spams deleted: 3274 > > The batch timing gives a good overall clue as to the speed/efficiency > of one's system. Thanks! > > Jeff Earickson > Colby College -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Sat Jan 21 15:02:53 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat Jan 21 15:03:02 2006 Subject: MS 4.50: way cool... In-Reply-To: <43D23125.4020407@ecs.soton.ac.uk> References: <43D23125.4020407@ecs.soton.ac.uk> Message-ID: <43D24D1D.7070109@ecs.soton.ac.uk> I just installed the latest version on my own MX servers. They used to thump along, keeping up okay apart from when things got really busy. They are now just ticking along happily, not even breaking into a sweat. It's good when a plan comes together :-) Julian Field wrote: > Glad you like it, it is much appreciated. > > Cheers, > Jules. > > Jeff A. Earickson wrote: >> Julian, >> In my nightly report at 4 AM last night, the cache hit rate >> was 72%. Wowee! >> >> With the HighRes timings, I use that information to compute how >> long batches take, and some statistics. From yesterday: >> >> ===Mailscanner Summaries: >> Total messages scanned: 28180 >> Total Message Batches: 20368 >> Average Messages per Batch: 1.38 >> Minimum Batch Time (sec): 2.57 >> Maximum Batch Time (sec): 185.12 >> Average Batch Time (sec): 8.45 >> Total MBytes scanned: 1011.47 >> Total virii detected: 31 >> Total spams tagged: 4702 >> Total spams delivered: 1679 >> Total spams deleted: 3274 >> >> The batch timing gives a good overall clue as to the speed/efficiency >> of one's system. Thanks! >> >> Jeff Earickson >> Colby College > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From pete at enitech.com.au Sun Jan 22 23:40:36 2006 From: pete at enitech.com.au (Peter Russell) Date: Sun Jan 22 23:40:42 2006 Subject: Non Spam Notify? In-Reply-To: <43D05A43.9080802@enitech.com.au> References: <43D05A43.9080802@enitech.com.au> Message-ID: <43D417F4.8020501@enitech.com.au> does Non Spam Action support Notify at all? Peter Russell wrote: > I want to make a rule set that does the following but also notifies > mark@whoknows.com wwith a custom message. > > # Non Spam Actions > From: mark@whoknows.com and To: my.user@* forward feedback@domain.com > FromOrTo: default deliver > > Is it possible to notify non spam recipients in MS orr do i need to look > to my MTA for these features? > > I have looked in examples and the book and see no obvious way off using > Notify equivilent with Non Spam actions. > > Kind regards and thanks > Pete From fajarep at simplimobile.com Mon Jan 23 01:25:52 2006 From: fajarep at simplimobile.com (Fajar) Date: Mon Jan 23 01:26:02 2006 Subject: Bug with mailwatch or mailscanner? References: <00ec01c61d8d$a21d47e0$2f01a8c0@Fajar> <1137747038.26473.527.camel@localhost.localdomain> Message-ID: <00a701c61fbb$f3a8a8e0$2f01a8c0@Fajar> Hmm, I'm already reduce the 15 minutes into 10 seconds only. The only think I don't like here, I must export the blacklist table, clear the blacklist table, restart mailscanner, import the blacklist table again. Oh, well, I can't do anything now :D Thanks ----- Original Message ----- From: "Steve Freegard" To: "MailScanner discussion" Sent: Friday, January 20, 2006 3:50 PM Subject: Re: Bug with mailwatch or mailscanner? > Hi Fajar, > > On Fri, 2006-01-20 at 13:49 +0700, Fajar wrote: >> >> But if I restart my mailscanner again, those emails won't be marked as >> blacklisted email. >> > > This isn't a bug in either MailWatch or MailScanner - the MailScanner > rules files and configuration are read into memory when MailScanner > starts (for speed) and are not re-read until you either reload/restart > MailScanner or when the MailScanner child is restarted automatically > (see the 'Restart Every' value in MailScanner.conf - default is 4 > hours). > > The blacklist supplied with MailWatch doesn't support all of the options > available to you in a MailScanner ruleset (it does exact matching on > user, domain, IP address or a default entry - no wildcards are supported > at all) and this data is re-read every 15 minutes by default > (configurable in the .pm file). > > Kind regards, > Steve. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From nilesh.shastrakar at gmail.com Mon Jan 23 05:45:13 2006 From: nilesh.shastrakar at gmail.com (Nilesh Shastrakar) Date: Mon Jan 23 05:45:16 2006 Subject: weird priblems with server Message-ID: <95873e560601222145o384b0123me1909f33318c2950@mail.gmail.com> Hello, Today I am facing some weird problem with my mail server. some mails I have received which is not maked to me in To,CC,or in BCC, I personally phone called to users who sent mail to me and asked about that mail but he said he has not send me that mail, the mail contains some confedential containts, also same problem happend with other users. could any one please help me how to fix this problem or tell me what would be the reason. also I have checked its not a spam mail. it is send to other users but I got it. I am using Fedora Core 4 with Kernel 2.6.14 Senamil 8.13.4-2 MailScanner 4-45.4-1 Spamassassin-3.0.4-2 Clamav 0.87 regards Nilesh -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060123/edf2884a/attachment.html From mailscanner at mango.zw Mon Jan 23 06:36:21 2006 From: mailscanner at mango.zw (Jim Holland) Date: Mon Jan 23 06:39:12 2006 Subject: weird priblems with server In-Reply-To: <95873e560601222145o384b0123me1909f33318c2950@mail.gmail.com> Message-ID: Hi On Mon, 23 Jan 2006, Nilesh Shastrakar wrote: > Today I am facing some weird problem with my mail server. some mails I > have received which is not maked to me in To,CC,or in BCC, I personally > phone called to users who sent mail to me and asked about that mail but > he said he has not send me that mail, the mail contains some > confedential containts, also same problem happend with other users. > could any one please help me how to fix this problem or tell me what > would be the reason. also I have checked its not a spam mail. it is send > to other users but I got it. As usual, the first thing to do when facing a problem is to analyse the logs. Grep your mail log for all lines with the pid that corresponds to the message (check the headers of a copy of the message to find the pid). Regards Jim Holland System Administrator MANGO - Zimbabwe's non-profit e-mail service From glenn.steen at gmail.com Mon Jan 23 07:05:53 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Mon Jan 23 07:05:56 2006 Subject: weird priblems with server In-Reply-To: <95873e560601222145o384b0123me1909f33318c2950@mail.gmail.com> References: <95873e560601222145o384b0123me1909f33318c2950@mail.gmail.com> Message-ID: <223f97700601222305gedf0a38v@mail.gmail.com> On 23/01/06, Nilesh Shastrakar wrote: > Hello, > > Today I am facing some weird problem with my mail server. > some mails I have received which is not maked to me in To,CC,or in BCC, > I personally phone called to users who sent mail to me and asked about that > mail but he said > he has not send me that mail, the mail contains some confedential > containts, also same problem happend with other users. > could any one please help me how to fix this problem or tell me what would > be the reason. > also I have checked its not a spam mail. it is send to other users but I got > it. > > > I am using > > Fedora Core 4 with Kernel 2.6.14 > Senamil 8.13.4-2 > MailScanner 4-45.4-1 > Spamassassin-3.0.4-2 > Clamav 0.87 > > regards > Nilesh > Well, have you checked your mail log that the _envelope_ recipient doesn't differ from the things in the headers? It is very common for these to differ, and it is just the envelope ones that matter... These are the ones used during the (E)SMTP conversation (the "RCPT TO: " thingies). It is quite "normal" for spam, viruses and even normal mails to be forged in this way. Or had you already looked at this...? If you run MailWatch, that will log the mails with the envelope sender/recipients....;) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From MailScanner at ecs.soton.ac.uk Mon Jan 23 08:42:13 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 23 08:42:27 2006 Subject: Non Spam Notify? In-Reply-To: <43D417F4.8020501@enitech.com.au> References: <43D05A43.9080802@enitech.com.au> <43D417F4.8020501@enitech.com.au> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Yes. Please read the docs. On 22 Jan 2006, at 23:40, Peter Russell wrote: > does Non Spam Action support Notify at all? > > > > Peter Russell wrote: >> I want to make a rule set that does the following but also >> notifies mark@whoknows.com wwith a custom message. >> # Non Spam Actions >> From: mark@whoknows.com and To: my.user@* forward feedback@domain.com >> FromOrTo: default deliver >> Is it possible to notify non spam recipients in MS orr do i need >> to look to my MTA for these features? >> I have looked in examples and the book and see no obvious way off >> using Notify equivilent with Non Spam actions. >> Kind regards and thanks >> Pete > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ9SW6Pw32o+k+q+hAQHGFgf+I/4ZPiz2B6npx0FohGSRWTFNBhCysXp/ PlK+f3XRQjbU55Nwm24IEyPL8/0mHkZpJtBjzx4z1jctz/4dKZj+8In/qXWDoz0b WHHbNINr4CjyVVFZDEspq9iEdGOclWn2KmgbJY9QgX/5eSwWQpsLGgLZnTULkgYT FBS3bMxaspVDo6JklPMJKt2U1drA/8Qf3OYgDXUhoS8E5kdU0Qf5xLt7EmoZT/GH cnBGoXK5lwegtctQL2rladqdM+5Lwnhmo8zn4ZjmrKI0qB+SGWcttY7dXmTiq8y5 MocnxKs7Je5RUJfr9jmp3anNSVlwexhSmjlWLLKNluTHjEYwNuUemQ== =3GMl -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Mon Jan 23 11:54:02 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 23 11:54:11 2006 Subject: 4.50.12 - please test Message-ID: -----BEGIN PGP SIGNED MESSAGE----- I have just released a new beta 4.50.12. See the Change Log for all the details, it's getting pretty long this month. 1 particular feature I would like you to test for me: please set Virus Scanners = auto and see what it does. Thanks guys! ================================ For your reference, here is the Change Log for 4.50 so far. Sorry, but they are in chronological order so you will have to read the whole thing. * New Features and Improvements * - - Speed increased significantly! Note you need to run my install.sh script to get the new modules required. - - Added DBI and DBD::SQLite Perl modules. Please use my install.sh scripts when you upgrade or install this version. - - Added SpamAssassin cache analyser (analyse_SpamAssassin_cache) to the - - Added American spelling of "analyze_SpamAssassin_cache" as well as English spelling of "analyse_SpamAssassin_cache". - - DBI installation is forced in RPM distributions. - - Improved RPM installer to handle DBI module dependencies better. It now installs cleanly on the systems I have tested it on. These include Fedora Core 3, Fedora Core 4, SuSE 9.3, SuSE 10, RedHat Enterprise 4. - - Updated man pages. - - Made log warnings more obvious when DBI/DBD::SQLite/Digest::MD5 are not all installed properly. - - Improved comments about "Allow Filenames" and "Allow Filetypes" in MailScanner.conf. - - Improvement to F-Prot output parser to handle new strings. distributions. 99% written by Steve Freegard of MailWatch fame. - - Upgraded ClamAV+SA bundle to ClamAV 0.88. - - Changed filename/type traps to account for new vulnerability in TNEF files. - - Added default headers that Thunderbird 1.5 will use to automatically identify spam based on SpamAssassin's spam headers. - - Adapted trend-autoupdate for 2006 onwards. - - Added a new command-line parameter "--lint" to verify the config file. - - --lint now checks SpamAssassin configuration too. - - --check ruleset-checker now written. Takes max 1 from address, multiple to addresses, client IP address and virus name. - - --debug now written. Works just like "Debug = yes" in MailScanner.conf. - - --help implemented so you can see how to use it now. - - Added hi-res timing so the batch speed timings are now displayed to micro- second accuracy. - - Added Time::HiRes to the list of required modules. You must use ./ install.sh to upgrade to, or install, this version in order to get the new module. Time taken to process the entire batch is logged, and time taken to do "Always Looked Up Last" is logged separately if it is being used at all. - - Added check that MailScanner.conf has at least been customised to set the organisation name, long name and web site. - - Added "SpamAssassin Cache Timings" configuration option for the few people who need to adjust these settings. Do *not* change it unless you really know what you are doing, the default settings will work nicely. - - Updated important perl modules. - - Added UU-decoder to automatically extract files from attachments that were stored in uu-encoded form. This behaves similarly to the zip and rar decoders. The virus scanners should check inside these files for themselves anyway, but this assists them when they do not. It also allows for filename and filetype checking of files stored in uu-encoded attachments. - - Added configuration option "Find UU-Encoded Files" to set whether uu-encoded files are decoded or not. These files are very rarely used, and the overhead of finding them is fairly large as it involves reading all existing attachments looking for the signature of them. So the default is to not look for them. A ruleset can be used to protect particularly vulnerable recipients or senders. - - Removed duplicate logging of warnings about infected messages. - - Changed default setting to "Use SpamAssassin = yes" and now auto- detect installation of SpamAssassin, logging installation instructions if it is not already installed and working. - - Added detection of no virus scanners being installed, giving the user advice about how to install ClamAV using my easy-installation package. - - Improved ClamAV+SA easy-installation package so that it automatically enables the updates by commenting out the "Example" lines. - - If "Virus Scanners = auto" (ie. the installed default value) then it searches for and uses every available installed virus scanner. - - You can now start up MailScanner without changing MailScanner.conf at all. It will auto-detect SpamAssassin and all available virus scanners. * Fixes * - - Improved reliability of Bayes rebuilds a lot. - - Force installation of DBI as previous versions cause problems. - - Should you need to change the default SpamAssassin cache lifetimes and expiry frequency, you can now do it easily at the top of SA.pm. *Very* few people will ever change these values. If more people start changing them, I will add them to MailScanner.conf. - - Removed broken patch I was given, which was temporarily in 4.50. - - Packaging bug in 4.50.9-1 fixed. MailTools version typo. - - Fixed bug where temporary files were not cleaned up properly. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ9TD3Pw32o+k+q+hAQFJGQgAny8JTfv7gYgcQsJCBG2XKL/GP8k7WLa5 PpYNB97u5Uin9PHi36KLzL4Ai/9ZwBHKAvru2nBkSl5rqgQehPPNKxXK7fmimd7k gEq9appB5Yd3N5EPLQ3kh2tA/apX1/Dqm5bwYGAp5u1GPhcqaxb75Z1JH4iqgzZ0 CA6/OqZLl4mvw6tohdg6czBHwQKluveGaqOJRnCF/gG3JF0YST377PcKrlH4SgPi rX174si+Nu+etZeEq1bTrc54M2F74v3u6+FKPNtl7YPYL6JHoHGH90FjHGGiwXBD DxZpcwMjAvbAFNs/bUSfegNfhos3/0w9RatgGX1r/GV5Ej68NQtRcw== =ej7Z -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From shuttlebox at gmail.com Mon Jan 23 12:32:36 2006 From: shuttlebox at gmail.com (shuttlebox) Date: Mon Jan 23 12:32:39 2006 Subject: 4.50.12 - please test In-Reply-To: References: Message-ID: <625385e30601230432n246d2683pce61ad9a794f5d6@mail.gmail.com> On 1/23/06, Julian Field wrote: > > 1 particular feature I would like you to test for me: please set > Virus Scanners = auto > and see what it does. Nice, that's exactly what I need. I'm testing eTrust on one server and when I rsync the config from the other one I always have to add eTrust to that one, now I can leave it at auto. Thanks! * New Features and Improvements * > - - Added "SpamAssassin Cache Timings" configuration option for the few > people > who need to adjust these settings. Do *not* change it unless you > really > know what you are doing, the default settings will work nicely. > > * Fixes * > - - Should you need to change the default SpamAssassin cache lifetimes and > expiry frequency, you can now do it easily at the top of SA.pm. > *Very* few people will ever change these values. If more people start > changing them, I will add them to MailScanner.conf. > Did you add this as a feature after all? Or am I just confused? :-) -- /peter -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060123/78f7cb0d/attachment.html From prandal at herefordshire.gov.uk Mon Jan 23 12:42:09 2006 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Mon Jan 23 12:42:30 2006 Subject: 4.50.12 - please test Message-ID: <86144ED6CE5B004DA23E1EAC0B569B580AB9ED7C@isabella.herefordshire.gov.uk> MailWatch 0.51 doesn't know what to do with "Virus Scanners = auto", of course, so that breaks. Cheers, Phil ---- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Julian Field > Sent: 23 January 2006 11:54 > To: MailScanner mailing list > Subject: 4.50.12 - please test > > -----BEGIN PGP SIGNED MESSAGE----- > > I have just released a new beta 4.50.12. See the Change Log > for all the details, it's getting pretty long this month. > > 1 particular feature I would like you to test for me: please set > Virus Scanners = auto > and see what it does. > > Thanks guys! > > ================================ > > For your reference, here is the Change Log for 4.50 so far. > Sorry, but they are in chronological order so you will have > to read the whole thing. > > * New Features and Improvements * > - - Speed increased significantly! > Note you need to run my install.sh script to get the new > modules required. > - - Added DBI and DBD::SQLite Perl modules. Please use my > install.sh scripts > when you upgrade or install this version. > - - Added SpamAssassin cache analyser > (analyse_SpamAssassin_cache) to the > - - Added American spelling of "analyze_SpamAssassin_cache" > as well as English > spelling of "analyse_SpamAssassin_cache". > - - DBI installation is forced in RPM distributions. > - - Improved RPM installer to handle DBI module dependencies > better. It now > installs cleanly on the systems I have tested it on. These > include Fedora > Core 3, Fedora Core 4, SuSE 9.3, SuSE 10, RedHat Enterprise 4. > - - Updated man pages. > - - Made log warnings more obvious when > DBI/DBD::SQLite/Digest::MD5 are not > all installed properly. > - - Improved comments about "Allow Filenames" and "Allow Filetypes" in > MailScanner.conf. > - - Improvement to F-Prot output parser to handle new strings. > distributions. 99% written by Steve Freegard of MailWatch fame. > - - Upgraded ClamAV+SA bundle to ClamAV 0.88. > - - Changed filename/type traps to account for new > vulnerability in TNEF files. > - - Added default headers that Thunderbird 1.5 will use to > automatically > identify spam based on SpamAssassin's spam headers. > - - Adapted trend-autoupdate for 2006 onwards. > - - Added a new command-line parameter "--lint" to verify the > config file. > - - --lint now checks SpamAssassin configuration too. > - - --check ruleset-checker now written. Takes max 1 from > address, multiple to > addresses, client IP address and virus name. > - - --debug now written. Works just like "Debug = yes" in > MailScanner.conf. > - - --help implemented so you can see how to use it now. > - - Added hi-res timing so the batch speed timings are now > displayed to > micro- > second accuracy. > - - Added Time::HiRes to the list of required modules. You > must use ./ install.sh > to upgrade to, or install, this version in order to get > the new module. > Time taken to process the entire batch is logged, and time > taken to do > "Always Looked Up Last" is logged separately if it is > being used at all. > - - Added check that MailScanner.conf has at least been > customised to set the > organisation name, long name and web site. > - - Added "SpamAssassin Cache Timings" configuration option > for the few people > who need to adjust these settings. Do *not* change it > unless you really > know what you are doing, the default settings will work nicely. > - - Updated important perl modules. > - - Added UU-decoder to automatically extract files from > attachments that were > stored in uu-encoded form. This behaves similarly to the > zip and rar > decoders. The virus scanners should check inside these > files for themselves > anyway, but this assists them when they do not. It also > allows for filename > and filetype checking of files stored in uu-encoded attachments. > - - Added configuration option "Find UU-Encoded Files" to set > whether uu-encoded > files are decoded or not. These files are very rarely used, and the > overhead of finding them is fairly large as it involves reading all > existing attachments looking for the signature of them. So > the default is > to not look for them. A ruleset can be used to protect particularly > vulnerable recipients or senders. > - - Removed duplicate logging of warnings about infected messages. > - - Changed default setting to "Use SpamAssassin = yes" and > now auto- detect > installation of SpamAssassin, logging installation instructions if > it is not already installed and working. > - - Added detection of no virus scanners being installed, > giving the user > advice about how to install ClamAV using my > easy-installation package. > - - Improved ClamAV+SA easy-installation package so that it > automatically > enables the updates by commenting out the "Example" lines. > - - If "Virus Scanners = auto" (ie. the installed default > value) then it > searches for and uses every available installed virus scanner. > - - You can now start up MailScanner without changing > MailScanner.conf at all. > It will auto-detect SpamAssassin and all available virus scanners. > > * Fixes * > - - Improved reliability of Bayes rebuilds a lot. > - - Force installation of DBI as previous versions cause problems. > - - Should you need to change the default SpamAssassin cache > lifetimes and > expiry frequency, you can now do it easily at the top of SA.pm. > *Very* few people will ever change these values. If more > people start > changing them, I will add them to MailScanner.conf. > - - Removed broken patch I was given, which was temporarily in 4.50. > - - Packaging bug in 4.50.9-1 fixed. MailTools version typo. > - - Fixed bug where temporary files were not cleaned up properly. > > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store PGP > footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.4 (Build 4042) > > iQEVAwUBQ9TD3Pw32o+k+q+hAQFJGQgAny8JTfv7gYgcQsJCBG2XKL/GP8k7WLa5 > PpYNB97u5Uin9PHi36KLzL4Ai/9ZwBHKAvru2nBkSl5rqgQehPPNKxXK7fmimd7k > gEq9appB5Yd3N5EPLQ3kh2tA/apX1/Dqm5bwYGAp5u1GPhcqaxb75Z1JH4iqgzZ0 > CA6/OqZLl4mvw6tohdg6czBHwQKluveGaqOJRnCF/gG3JF0YST377PcKrlH4SgPi > rX174si+Nu+etZeEq1bTrc54M2F74v3u6+FKPNtl7YPYL6JHoHGH90FjHGGiwXBD > DxZpcwMjAvbAFNs/bUSfegNfhos3/0w9RatgGX1r/GV5Ej68NQtRcw== > =ej7Z > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From martelm at quark.vsc.edu Mon Jan 23 12:43:22 2006 From: martelm at quark.vsc.edu (Michael H. Martel) Date: Mon Jan 23 12:43:35 2006 Subject: 4.50.12 - please test In-Reply-To: References: Message-ID: <726B358AF2C56E9D3F41A4D7@sherlockholmes.local> --On January 23, 2006 11:54:02 AM +0000 Julian Field wrote: > 1 particular feature I would like you to test for me: please set > Virus Scanners = auto > and see what it does. Seems to work for me. I set it on my test machine and it found my Bitdefender, Clamav, McAfee, F-Prot and AntiVir. However, MailWatch doesn't like it. It gives me : Error: Unable to select a regular expression for your primary virus scanner (auto) - please see the examples in functions.php to create one. I haven't even looked at functions.php yet. Michael -- --------------------------------o--------------------------------- Michael H. Martel | Systems Administrator michael.martel@vsc.edu | Vermont State Colleges http://www.vsc.edu/~michael | PH:802-241-2544 FX:802-241-3363 From martelm at quark.vsc.edu Mon Jan 23 12:50:35 2006 From: martelm at quark.vsc.edu (Michael H. Martel) Date: Mon Jan 23 12:50:42 2006 Subject: 4.50.12 - please test In-Reply-To: <726B358AF2C56E9D3F41A4D7@sherlockholmes.local> References: <726B358AF2C56E9D3F41A4D7@sherlockholmes.local> Message-ID: <9E5806F13320A79C97388E73@sherlockholmes.local> --On January 23, 2006 7:43:22 AM -0500 "Michael H. Martel" wrote: > However, MailWatch doesn't like it. It gives me : > > Error: Unable to select a regular expression for your primary virus > scanner (auto) - please see the examples in functions.php to create one. > > I haven't even looked at functions.php yet. I'm not sure what the "correct" fix is. I know what I did. I added this to functions.php : case 'auto': define(VIRUS_REGEX, '/(.+) contains (\S+)/'); break; Now I'm sure I madea typo, but I just grabbed the regex for ClamAV and used that for auto. Now MailWatch is quite happy. Michael -- --------------------------------o--------------------------------- Michael H. Martel | Systems Administrator michael.martel@vsc.edu | Vermont State Colleges http://www.vsc.edu/~michael | PH:802-241-2544 FX:802-241-3363 From prandal at herefordshire.gov.uk Mon Jan 23 13:11:18 2006 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Mon Jan 23 13:11:28 2006 Subject: 4.50.12 - please test Message-ID: <86144ED6CE5B004DA23E1EAC0B569B580AB9ED8E@isabella.herefordshire.gov.uk> On my box it detected ClamAV, McAfee uvscan, and Bitdefender. But I have clamavmodule installed, and it would be useful to autodetect and use that in preference to the command line clamav. Cheers, Phil ---- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Julian Field > Sent: 23 January 2006 11:54 > To: MailScanner mailing list > Subject: 4.50.12 - please test > > -----BEGIN PGP SIGNED MESSAGE----- > > I have just released a new beta 4.50.12. See the Change Log > for all the details, it's getting pretty long this month. > > 1 particular feature I would like you to test for me: please set > Virus Scanners = auto > and see what it does. > > Thanks guys! > > ================================ > > For your reference, here is the Change Log for 4.50 so far. > Sorry, but they are in chronological order so you will have > to read the whole thing. > > * New Features and Improvements * > - - Speed increased significantly! > Note you need to run my install.sh script to get the new > modules required. > - - Added DBI and DBD::SQLite Perl modules. Please use my > install.sh scripts > when you upgrade or install this version. > - - Added SpamAssassin cache analyser > (analyse_SpamAssassin_cache) to the > - - Added American spelling of "analyze_SpamAssassin_cache" > as well as English > spelling of "analyse_SpamAssassin_cache". > - - DBI installation is forced in RPM distributions. > - - Improved RPM installer to handle DBI module dependencies > better. It now > installs cleanly on the systems I have tested it on. These > include Fedora > Core 3, Fedora Core 4, SuSE 9.3, SuSE 10, RedHat Enterprise 4. > - - Updated man pages. > - - Made log warnings more obvious when > DBI/DBD::SQLite/Digest::MD5 are not > all installed properly. > - - Improved comments about "Allow Filenames" and "Allow Filetypes" in > MailScanner.conf. > - - Improvement to F-Prot output parser to handle new strings. > distributions. 99% written by Steve Freegard of MailWatch fame. > - - Upgraded ClamAV+SA bundle to ClamAV 0.88. > - - Changed filename/type traps to account for new > vulnerability in TNEF files. > - - Added default headers that Thunderbird 1.5 will use to > automatically > identify spam based on SpamAssassin's spam headers. > - - Adapted trend-autoupdate for 2006 onwards. > - - Added a new command-line parameter "--lint" to verify the > config file. > - - --lint now checks SpamAssassin configuration too. > - - --check ruleset-checker now written. Takes max 1 from > address, multiple to > addresses, client IP address and virus name. > - - --debug now written. Works just like "Debug = yes" in > MailScanner.conf. > - - --help implemented so you can see how to use it now. > - - Added hi-res timing so the batch speed timings are now > displayed to > micro- > second accuracy. > - - Added Time::HiRes to the list of required modules. You > must use ./ install.sh > to upgrade to, or install, this version in order to get > the new module. > Time taken to process the entire batch is logged, and time > taken to do > "Always Looked Up Last" is logged separately if it is > being used at all. > - - Added check that MailScanner.conf has at least been > customised to set the > organisation name, long name and web site. > - - Added "SpamAssassin Cache Timings" configuration option > for the few people > who need to adjust these settings. Do *not* change it > unless you really > know what you are doing, the default settings will work nicely. > - - Updated important perl modules. > - - Added UU-decoder to automatically extract files from > attachments that were > stored in uu-encoded form. This behaves similarly to the > zip and rar > decoders. The virus scanners should check inside these > files for themselves > anyway, but this assists them when they do not. It also > allows for filename > and filetype checking of files stored in uu-encoded attachments. > - - Added configuration option "Find UU-Encoded Files" to set > whether uu-encoded > files are decoded or not. These files are very rarely used, and the > overhead of finding them is fairly large as it involves reading all > existing attachments looking for the signature of them. So > the default is > to not look for them. A ruleset can be used to protect particularly > vulnerable recipients or senders. > - - Removed duplicate logging of warnings about infected messages. > - - Changed default setting to "Use SpamAssassin = yes" and > now auto- detect > installation of SpamAssassin, logging installation instructions if > it is not already installed and working. > - - Added detection of no virus scanners being installed, > giving the user > advice about how to install ClamAV using my > easy-installation package. > - - Improved ClamAV+SA easy-installation package so that it > automatically > enables the updates by commenting out the "Example" lines. > - - If "Virus Scanners = auto" (ie. the installed default > value) then it > searches for and uses every available installed virus scanner. > - - You can now start up MailScanner without changing > MailScanner.conf at all. > It will auto-detect SpamAssassin and all available virus scanners. > > * Fixes * > - - Improved reliability of Bayes rebuilds a lot. > - - Force installation of DBI as previous versions cause problems. > - - Should you need to change the default SpamAssassin cache > lifetimes and > expiry frequency, you can now do it easily at the top of SA.pm. > *Very* few people will ever change these values. If more > people start > changing them, I will add them to MailScanner.conf. > - - Removed broken patch I was given, which was temporarily in 4.50. > - - Packaging bug in 4.50.9-1 fixed. MailTools version typo. > - - Fixed bug where temporary files were not cleaned up properly. > > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store PGP > footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.4 (Build 4042) > > iQEVAwUBQ9TD3Pw32o+k+q+hAQFJGQgAny8JTfv7gYgcQsJCBG2XKL/GP8k7WLa5 > PpYNB97u5Uin9PHi36KLzL4Ai/9ZwBHKAvru2nBkSl5rqgQehPPNKxXK7fmimd7k > gEq9appB5Yd3N5EPLQ3kh2tA/apX1/Dqm5bwYGAp5u1GPhcqaxb75Z1JH4iqgzZ0 > CA6/OqZLl4mvw6tohdg6czBHwQKluveGaqOJRnCF/gG3JF0YST377PcKrlH4SgPi > rX174si+Nu+etZeEq1bTrc54M2F74v3u6+FKPNtl7YPYL6JHoHGH90FjHGGiwXBD > DxZpcwMjAvbAFNs/bUSfegNfhos3/0w9RatgGX1r/GV5Ej68NQtRcw== > =ej7Z > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From smf at f2s.com Mon Jan 23 13:14:51 2006 From: smf at f2s.com (Steve Freegard) Date: Mon Jan 23 13:12:31 2006 Subject: 4.50.12 - please test In-Reply-To: <9E5806F13320A79C97388E73@sherlockholmes.local> References: <726B358AF2C56E9D3F41A4D7@sherlockholmes.local> <9E5806F13320A79C97388E73@sherlockholmes.local> Message-ID: <1138022091.26473.624.camel@localhost.localdomain> Hi Michael, On Mon, 2006-01-23 at 07:50 -0500, Michael H. Martel wrote: > --On January 23, 2006 7:43:22 AM -0500 "Michael H. Martel" > wrote: > > > However, MailWatch doesn't like it. It gives me : > > > > Error: Unable to select a regular expression for your primary virus > > scanner (auto) - please see the examples in functions.php to create one. > > > > I haven't even looked at functions.php yet. > > I'm not sure what the "correct" fix is. I know what I did. > > I added this to functions.php : > > case 'auto': > define(VIRUS_REGEX, '/(.+) contains (\S+)/'); > break; > This will work just fine provided that ClamAV is installed. In the longer term I'm not sure what default is best for this - but I'll release a new version soon to address this. I'm working on MailWatch 2.0 at the moment - and plan on removing the VIRUS_REGEX requirement in MailWatch and moving the functionality into MailScanner instead (e.g. capture the names of the viruses caught per scanner) so this should be a non-issue by then. Cheers, Steve. From martelm at quark.vsc.edu Mon Jan 23 13:25:05 2006 From: martelm at quark.vsc.edu (Michael H. Martel) Date: Mon Jan 23 13:25:11 2006 Subject: 4.50.12 - please test In-Reply-To: <1138022091.26473.624.camel@localhost.localdomain> References: <726B358AF2C56E9D3F41A4D7@sherlockholmes.local> <9E5806F13320A79C97388E73@sherlockholmes.local> <1138022091.26473.624.camel@localhost.localdomain> Message-ID: --On January 23, 2006 1:14:51 PM +0000 Steve Freegard wrote: > This will work just fine provided that ClamAV is installed. In the > longer term I'm not sure what default is best for this - but I'll > release a new version soon to address this. I know. I just wanted something so I had MailWatch back. I don't think I could survive without it. :) > I'm working on MailWatch 2.0 at the moment - and plan on removing the Cool. Is there a list of features somewhere so we can see what you're planning ? Thanks for your hard work! (Yours too Julian!) Michael -- --------------------------------o--------------------------------- Michael H. Martel | Systems Administrator michael.martel@vsc.edu | Vermont State Colleges http://www.vsc.edu/~michael | PH:802-241-2544 FX:802-241-3363 From MailScanner at ecs.soton.ac.uk Mon Jan 23 13:51:03 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 23 13:51:16 2006 Subject: 4.50.12 - please test In-Reply-To: <625385e30601230432n246d2683pce61ad9a794f5d6@mail.gmail.com> References: <625385e30601230432n246d2683pce61ad9a794f5d6@mail.gmail.com> Message-ID: Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: PGP.sig Type: application/pgp-signature Size: 487 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060123/f7b303aa/PGP.bin From jaearick at colby.edu Mon Jan 23 13:57:03 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Mon Jan 23 13:57:10 2006 Subject: 4.50.12 - please test In-Reply-To: References: Message-ID: On Mon, 23 Jan 2006, Julian Field wrote: > Date: Mon, 23 Jan 2006 11:54:02 +0000 > From: Julian Field > Reply-To: MailScanner discussion > To: MailScanner mailing list > Subject: 4.50.12 - please test > > -----BEGIN PGP SIGNED MESSAGE----- > > I have just released a new beta 4.50.12. See the Change Log for all > the details, it's getting pretty long this month. > > 1 particular feature I would like you to test for me: please set > Virus Scanners = auto > and see what it does. Julian, Does auto give preference to the perl modules over the standalone, or vice versa? I use "Virus Scanners = sophossavi clamav"; I've given up on clamavmodule because of problems in the past. Jeff Earickson Colby College From prandal at herefordshire.gov.uk Mon Jan 23 14:08:26 2006 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Mon Jan 23 14:08:46 2006 Subject: 4.50.12 - please test Message-ID: <86144ED6CE5B004DA23E1EAC0B569B580AB9EDAC@isabella.herefordshire.gov.uk> > Julian, > Does auto give preference to the perl modules over the > standalone, or vice versa? I use "Virus Scanners = > sophossavi clamav"; I've given up on clamavmodule because of > problems in the past. > > Jeff Earickson > Colby College Jeff, What problems do (or did) you have with clamavmodule? I know there were problems in the past with incompatibilities with dev builds of clamav, but that's well in the past. It works without problem here. Cheers, Phil ---- Phil Randal Network Engineer Herefordshire Council Hereford, UK From rob at robhq.com Mon Jan 23 14:14:23 2006 From: rob at robhq.com (rob) Date: Mon Jan 23 14:12:23 2006 Subject: pyzor problems Message-ID: <20060123141405.M91569@robhq.com> I just install did a fresh install of MailScanner and spamassassin on a fresh CentOS 4 install. I used the cool spamassassin / clamav script on the mailscanner site. For the first time, I have run into pyzor errors: Jan 23 07:30:30 gollum spamd[26023]: internal error Jan 23 07:30:30 gollum spamd[26023]: pyzor: check failed: internal error I read on the wiki that pyzor may have to be patched, so I patched and reinstalled pyzor but I keep getting the same errors on every message. I checked the client.py file and it has the same size as the patched file. [root@gollum ~]# cd /usr/lib/python2.3/site-packages/pyzor [root@gollum pyzor]# ls -l total 216 -rw-r--r-- 1 root root 29714 Jan 23 07:09 client.py -rw-r--r-- 1 root root 40814 Jan 23 07:09 client.pyc -rw-r--r-- 1 root root 28842 Jan 23 06:26 client.py.orig -rw-r--r-- 1 root root 12430 Sep 6 2002 __init__.py -rw-r--r-- 1 root root 28516 Jan 22 11:24 __init__.pyc -rw-r--r-- 1 root root 17515 Sep 7 2002 server.py -rw-r--r-- 1 root root 25618 Jan 22 11:24 server.pyc a spamassassin --lint does not return any errors. [26335] dbg: pyzor: pyzor is available: /usr/bin/pyzor [26335] dbg: info: entering helper-app run mode [26335] dbg: pyzor: opening pipe: /usr/bin/pyzor check < /tmp/.spamassassin26335gEye0Otmp [26336] dbg: util: setuid: ruid=0 euid=0 [26335] dbg: pyzor: [26336] finished: exit=0x0100 [26335] dbg: pyzor: got response: 66.250.40.33:24441_(200, 'OK')_0_0 [root@gollum pyzor]# spamassassin -V SpamAssassin version 3.1.0 running on Perl version 5.8.5 [root@gollum pyzor]# Never have run into this on the multiple MailScanner installs in the past. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Mon Jan 23 14:13:16 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 23 14:13:26 2006 Subject: 4.50.12 - please test In-Reply-To: <86144ED6CE5B004DA23E1EAC0B569B580AB9ED8E@isabella.herefordshire.gov.uk> References: <86144ED6CE5B004DA23E1EAC0B569B580AB9ED8E@isabella.herefordshire.gov.uk> Message-ID: <69AD1B70-14EE-4CC1-809E-7F6D1DFC2605@ecs.soton.ac.uk> Skipped content of type multipart/mixed-------------- next part -------------- A non-text attachment was scrubbed... Name: PGP.sig Type: application/pgp-signature Size: 487 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060123/76520b22/PGP.bin From MailScanner at ecs.soton.ac.uk Mon Jan 23 14:15:02 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 23 14:15:13 2006 Subject: 4.50.12 - please test In-Reply-To: References: Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 23 Jan 2006, at 13:57, Jeff A. Earickson wrote: > On Mon, 23 Jan 2006, Julian Field wrote: > >> Date: Mon, 23 Jan 2006 11:54:02 +0000 >> From: Julian Field >> Reply-To: MailScanner discussion >> To: MailScanner mailing list >> Subject: 4.50.12 - please test >> -----BEGIN PGP SIGNED MESSAGE----- >> >> I have just released a new beta 4.50.12. See the Change Log for all >> the details, it's getting pretty long this month. >> >> 1 particular feature I would like you to test for me: please set >> Virus Scanners = auto >> and see what it does. > > Julian, > Does auto give preference to the perl modules over the standalone, > or vice versa? I use "Virus Scanners = sophossavi clamav"; I've given > up on clamavmodule because of problems in the past. It now (with the patch I just posted) gives preference to the Perl modules over the standalone. If you don't like what it came up with, then you will have to edit the setting yourself. It will log what scanners it is going to use, so it is easy to check. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ9Tk6vw32o+k+q+hAQG5dwf9HMc+0wyUhEs8NsPCj3zPmctKn6IPVdcf eyJWmDm1MufPDDunU8EC/9dcJFR5956HyRLaec2MpVleUDdnrw9A9yM4UaK8GYcE +dUgByGcI34FA4xb24dUGhL1MgnZydXgEKgkVrqKOm1gD3yOG10jJVApHJx6RguI JWdpgoHW/CRluJ83E6rXc4ooQ0aREAHM4RrtcEU9yCepqYEfR74CiuGqywkNGmf9 BtvTPNnLeAWZHqS6kRlLYHbtMGlmIxK7WXO6FJxU5XjRz1OL84Hklrorox5k2s1c tE8tMPNeU/LhFqHP8KWtqiWbLyda15t/b97GvvxkDqQJ1pImjMmoNQ== =YNIk -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From wietse at boudisque.nl Mon Jan 23 14:22:03 2006 From: wietse at boudisque.nl (Wietse Muizelaar) Date: Mon Jan 23 14:22:12 2006 Subject: 4.50.12 - please test References: Message-ID: <01ea01c62028$61e6bc90$1373a8c0@BOUDIEWEB10> Hi, Works great, but as others also mentioned clamav is used; but clamavmodule is -also- installed. Trying the patch right now :) Also still seeing the negative number of disinfected or MCP speedrate in the logs, like: Jan 23 14:40:39 boudams MailScanner[15242]: Disinfection completed at -1548421332 bytes per second -- Kind Regards, Wietse Muizelaar ------------------------------------------- W.G. Muizelaar Boudisque Webmaster / ICT Drieharingstraat 5-31, 3511 BH Utrecht Telefoon: +31 (0)30 - 2394030 E-mail: wietse@boudisque.nl Website: www.boudisque.nl ------------------------------------------- From MailScanner at ecs.soton.ac.uk Mon Jan 23 14:39:50 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 23 14:40:01 2006 Subject: 4.50.12 - please test In-Reply-To: <01ea01c62028$61e6bc90$1373a8c0@BOUDIEWEB10> References: <01ea01c62028$61e6bc90$1373a8c0@BOUDIEWEB10> Message-ID: <99C953E8-31DF-47D7-AC38-0269A3CF5EFC@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- On 23 Jan 2006, at 14:22, Wietse Muizelaar wrote: > Works great, but as others also mentioned clamav is used; but > clamavmodule is -also- installed. Trying the patch right now :) > > Also still seeing the negative number of disinfected or MCP > speedrate in the logs, like: > Jan 23 14:40:39 boudams MailScanner[15242]: Disinfection completed > at -1548421332 bytes per second Try changing line 104 of MessageBatch.pm so it says $totaltime = 1 unless $totaltime > 0.001; # Minimum of 1 m-second Then restart MailScanner. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ9Tqufw32o+k+q+hAQFtsAgApqpqlE+dVjcEH/g5sZXZE8Brdp89sPrI ZnF9DKEzX39CP504TRTTzRdyODQaZcFPUE82O/hpTqKFd7DGOAZGbqn0O740CX5A lu1cwBbskfyvpPMkC1Bq7Y+U5S48+JZrJwwZ96l44JKKzfppHUn3G3JMtj60ue0K oHse+5LL5vlU3JCk/QYcjpIgzsJLisToG7wfcrmpqVHUky4l6O+NoOk892zIlK5B vEkIEnVvGil3LNkeDxL+f5xWdphB+r542szSv3Z56M6KubV0Ueb/TPqpQPEY5Tw+ vWFjwl5TUaUkiwwO+jdkx1A9na6htxbX4Jh/7YQD4si5TJhdXxmsBA== =mPQs -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From PHachey at city.cornwall.on.ca Mon Jan 23 14:43:11 2006 From: PHachey at city.cornwall.on.ca (Philip Hachey) Date: Mon Jan 23 14:43:14 2006 Subject: Whitelisted mail is still scanned by SA? Message-ID: I noticed that mail which has been whitelisted in MS is still sent to SpamAssassin (see log snip below). This is not a problem, but.. why? Performance would be better if this did not happen. Jan 23 07:04:09 mx1 sendmail[12734]: k0NC48Yg012734: from=, size=21721, class=-30, nrcpts=1, msgid=<200601231204.k0NC45Ma012483@bkserver.blacknight.ie>, proto=ESMTP, daemon=MTA, relay=bkserver.blacknight.ie [83.98.166.45] Jan 23 07:04:09 mx1 sendmail[12734]: k0NC48Yg012734: Milter add: header: Received-SPF: pass (mx1.city.cornwall.on.ca: domain of mailscanner-bounces@lists.mailscanner.info designates 83.98.166.45 as permitted sender) Jan 23 07:04:10 mx1 sendmail[12734]: k0NC48Yg012734: Milter change (add): header: X-DCC-CollegeOfNewCaledonia-Metrics: mx1.city.cornwall.on.ca 1189; Body=1\n\tFuz1=1 Fuz2=1 Jan 23 07:04:10 mx1 sendmail[12734]: k0NC48Yg012734: to=, delay=00:00:01, mailer=relay, pri=105721, stat=queued Jan 23 07:04:13 mx1 MailScanner[8896]: Message k0NC48Yg012734 from 83.98.166.45 (mailscanner-bounces@lists.mailscanner.info) is whitelisted Jan 23 07:04:18 mx1 MailScanner[8896]: Message k0NC48Yg012734 from 83.98.166.45 (mailscanner-bounces@lists.mailscanner.info) to city.cornwall.on.ca is not spam (whitelisted), SpamAssassin (score=8.119, required 5, AWL 0.21, BAYES_50 0.00, HTML_30_40 0.37, HTML_MESSAGE 0.00, INFO_TLD 1.27, J_CHICKENPOX_12 0.60, J_CHICKENPOX_22 0.60, J_CHICKENPOX_62 0.60, NO_REAL_NAME 0.96, SPF_PASS -0.00, VIRUS_WARNING62 3.50) Jan 23 07:04:23 mx1 MailScanner[8896]: Logging message k0NC48Yg012734 to SQL Jan 23 07:04:23 mx1 MailScanner[11001]: k0NC48Yg012734: Logged to MailWatch SQL Jan 23 07:04:23 mx1 sendmail[12754]: k0NC48Yg012734: to=, delay=00:00:14, xdelay=00:00:00, mailer=relay, pri=195721, relay=######, dsn=2.0.0, stat=Sent (Message accepted for delivery) From glenn.steen at gmail.com Mon Jan 23 14:47:18 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Mon Jan 23 14:47:22 2006 Subject: pyzor problems In-Reply-To: <20060123141405.M91569@robhq.com> References: <20060123141405.M91569@robhq.com> Message-ID: <223f97700601230647g2edd9f47k@mail.gmail.com> On 23/01/06, rob wrote: (snip) > Jan 23 07:30:30 gollum spamd[26023]: internal error > Jan 23 07:30:30 gollum spamd[26023]: pyzor: check failed: internal error (snip) spamd is not used by MailScanner. Stop using it (turn it of with appropriate chkconfig cmd... I'm sure it's mentioned in the wiki;), and make sure you don't have any system-wide procmail thing calling spamc. -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From Denis.Beauchemin at USherbrooke.ca Mon Jan 23 14:54:29 2006 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Mon Jan 23 14:55:15 2006 Subject: /tmp/McAfeeBusy.lock In-Reply-To: <43D15C31.3070406@ecs.soton.ac.uk> References: <20060120200351.GA20468@pirates.Armstrong.EDU> <43D158FF.7010907@ecs.soton.ac.uk> <43D15C31.3070406@ecs.soton.ac.uk> Message-ID: <43D4EE25.9000002@USherbrooke.ca> Julian Field wrote: > Julian Field wrote: > >> andrew@pirates.armstrong.edu wrote: >> >>> I somehow got a lockfile owned by root left around on my system, >>> /tmp/McAfeeBusy.lock. This caused mailscanner to skip the virus >>> checking >>> and deliver infected email. Would it be possible just to stop delivery >>> under these circumstances? >>> >> >> That certainly shouldn't happen! Please can you double-check your >> results. >> It should just cause the virus scanner to wait until the file was >> lockable. >> Please try it with the EICAR virus pattern (from www.eicar.org) which >> is a harmless test file, and let me know the result. >> > I have just tested this and it worked just fine. > Not sure what you did, but I would request that you re-do your tests. > I cannot reproduce the behaviour that you found. > Julian, I also have this file on my systems, but it seems to get updated quite often: [root@smtpe1 ~]# cat /tmp/McAfeeBusy.lock Virus checker locked for scanning by mcafee 3546 [root@smtpe1 ~]# cat /tmp/McAfeeBusy.lock Virus checker locked for scanning by mcafee 2284 [root@smtpe1 ~]# cat /tmp/McAfeeBusy.lock Virus checker locked for scanning by mcafee 2284 [root@smtpe1 ~]# cat /tmp/McAfeeBusy.lock Virus checker locked for scanning by mcafee 3794 My McAfee does detect viruses! I'm using mailscanner-4.50.10-1 under RHEL 4. Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x2252 F: 819.821.8045 From MailScanner at ecs.soton.ac.uk Mon Jan 23 14:58:45 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 23 14:58:54 2006 Subject: Whitelisted mail is still scanned by SA? In-Reply-To: References: Message-ID: <1A9264DF-5ABE-46D0-9EB1-C1422FB493EA@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- On 23 Jan 2006, at 14:43, Philip Hachey wrote: > I noticed that mail which has been whitelisted in MS is still sent to > SpamAssassin (see log snip below). This is not a problem, but.. why? > Performance would be better if this did not happen. > Always Include SpamAssassin Report = no Check SpamAssassin If On Spam List = no is what you want. You probably have the 2nd one set to "yes". - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ9TvJ/w32o+k+q+hAQEZWQf+PkytpgWbPYSN53Jx/mJy2hDVHLnsaRPN 908zgRiDAEKtZZ6pCeyjLLSI6RV4qQaR+zpw1bHmGdiucsxUroFJ217FA/bKA0xo CNV4AeM5iV3wCh7ETRkEj0TUBGRmGvvW8tsZ8u2TGPpjL78qmBE17wboyRZ72AhI F2bLlojLuVu0r8ads97LzmKEyAIEnf5315XYZE+sNS7zW8XZHYfRL2rvarbGRvZP 3J2m+FF2FzCizwjHscFJNAvd7K33Jxqyh4OdY+B5QEnS8RdprrQtJVWO/BOAlWE1 4ixj3DsMtHSdhW/g7Vhj8JILu1lnnDlewvEQmkJlT3bM5Ul6BYLKYA== =Jm1y -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Mon Jan 23 15:07:27 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 23 15:07:36 2006 Subject: Use up your old Sun hardware Message-ID: Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: PGP.sig Type: application/pgp-signature Size: 487 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060123/96ef162e/PGP.bin From MailScanner at ecs.soton.ac.uk Mon Jan 23 15:12:15 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 23 15:12:23 2006 Subject: /tmp/McAfeeBusy.lock In-Reply-To: <43D4EE25.9000002@USherbrooke.ca> References: <20060120200351.GA20468@pirates.Armstrong.EDU> <43D158FF.7010907@ecs.soton.ac.uk> <43D15C31.3070406@ecs.soton.ac.uk> <43D4EE25.9000002@USherbrooke.ca> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 23 Jan 2006, at 14:54, Denis Beauchemin wrote: > Julian Field wrote: > >> Julian Field wrote: >> >>> andrew@pirates.armstrong.edu wrote: >>> >>>> I somehow got a lockfile owned by root left around on my system, >>>> /tmp/McAfeeBusy.lock. This caused mailscanner to skip the virus >>>> checking >>>> and deliver infected email. Would it be possible just to stop >>>> delivery >>>> under these circumstances? >>>> >>> >>> That certainly shouldn't happen! Please can you double-check your >>> results. >>> It should just cause the virus scanner to wait until the file was >>> lockable. >>> Please try it with the EICAR virus pattern (from www.eicar.org) >>> which is a harmless test file, and let me know the result. >>> >> I have just tested this and it worked just fine. >> Not sure what you did, but I would request that you re-do your >> tests. I cannot reproduce the behaviour that you found. >> > Julian, > > I also have this file on my systems, but it seems to get updated > quite often: > [root@smtpe1 ~]# cat /tmp/McAfeeBusy.lock > Virus checker locked for scanning by mcafee 3546 > [root@smtpe1 ~]# cat /tmp/McAfeeBusy.lock > Virus checker locked for scanning by mcafee 2284 > [root@smtpe1 ~]# cat /tmp/McAfeeBusy.lock > Virus checker locked for scanning by mcafee 2284 > [root@smtpe1 ~]# cat /tmp/McAfeeBusy.lock > Virus checker locked for scanning by mcafee 3794 > > My McAfee does detect viruses! I'm using mailscanner-4.50.10-1 > under RHEL 4. It is there so that MailScanner and the mcafee-autoupdate processes lock out each other. If you were in the middle of a mcafee-autoupdate when you tried to scan a message, it is possible (but very unlikely) that the virus definitions would be partially complete, so you may miss a virus. So they lock out each other so that the two processes cannot happen at the same time. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ9TyUfw32o+k+q+hAQGbVggAtqDdqw6JR3itTvG/Y/fwWtFe920JEQ+8 3iOAkevnEJjALEctOaREJ0UQ20x5tZhDhIrUlMZ4JxM03u/6magN+vjnlvD1/LVP tUWvscArSFwN0/4GXHoXgFXJIcrm7rIbCHQucAvdvOtAksmaIDfxdoC9U3h5VKV7 ReGApexIq7CQUjhu48iJDwzQ6PULFjJRFNftahDHJeu0Iekzg0r7iOSjxdoo1YnP a5mDh91ybfpSuVxsYZ5bJEkznP6M8mEIhD1AeaLW6Q6stSU+9kOvbOmOoEKC22hO YIJ6FN4jiiq7osOk4PqhKJjw4swE6VCXBtnWs6dOG8QAASkcpkjkjQ== =iHOK -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From jaearick at colby.edu Mon Jan 23 15:19:42 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Mon Jan 23 15:20:03 2006 Subject: 4.50.12 - please test In-Reply-To: <86144ED6CE5B004DA23E1EAC0B569B580AB9EDAC@isabella.herefordshire.gov.uk> References: <86144ED6CE5B004DA23E1EAC0B569B580AB9EDAC@isabella.herefordshire.gov.uk> Message-ID: I had a lot of headaches in the 0.86 thru 0.87 era (Solaris 9) where Clam didn't seem to pick up the latest viruses. By eliminating Mail-ClamAV, I was trying to cut down on the number of possible failure points. Things have seemed good with 0.88 again. I'll retry clamavmodule. Jeff Earickson Colby College On Mon, 23 Jan 2006, Randal, Phil wrote: > Date: Mon, 23 Jan 2006 14:08:26 -0000 > From: "Randal, Phil" > Reply-To: MailScanner discussion > To: MailScanner discussion > Subject: RE: 4.50.12 - please test > >> Julian, >> Does auto give preference to the perl modules over the >> standalone, or vice versa? I use "Virus Scanners = >> sophossavi clamav"; I've given up on clamavmodule because of >> problems in the past. >> >> Jeff Earickson >> Colby College > > Jeff, > > What problems do (or did) you have with clamavmodule? I know there were > problems in the past with incompatibilities with dev builds of clamav, > but that's well in the past. > > It works without problem here. > > Cheers, > > Phil > ---- > Phil Randal > Network Engineer > Herefordshire Council > Hereford, UK > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From shuttlebox at gmail.com Mon Jan 23 15:30:00 2006 From: shuttlebox at gmail.com (shuttlebox) Date: Mon Jan 23 15:30:05 2006 Subject: Use up your old Sun hardware In-Reply-To: References: Message-ID: <625385e30601230730i73e71932pfd0c3310f95a434f@mail.gmail.com> On 1/23/06, Julian Field wrote: > > One of our students has found the perfect use for old Sun hardware: > http://www.soton.ac.uk/~tjr304/mail_scanner.jpg > Hehe, maybe a tad slow for a MailScanner setup but it will happily serve static web pages and ftp files for years after current PC hardware has given up. You know it's the worlds most sold Unix workstation? -- /peter -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060123/e04d47a7/attachment.html From MailScanner at ecs.soton.ac.uk Mon Jan 23 15:31:22 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 23 15:31:30 2006 Subject: Change default Lock Type for sendmail ? Message-ID: <276DC8B5-0910-426D-A9ED-D726E8DC5F1A@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Is it about time I changed the default setting for "Lock Type" to "posix" for sendmail users? It applies to most sendmail 8.13 (and upwards) users. Other people would have to change it to "flock" if required. It's just that most newbie users will be using whatever their Linux distro ships with, which is now likely to be 8.13 these days, isn't it? Opinions, please? - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ9T2zPw32o+k+q+hAQHlkAf+OMTEJIAZhpR8FWKA/t/yEKC0652zv8sY 0j2btJdpdVSKzDRKFOHgf+Y8ZaTJJiLfJRfovR1BISrxPR/tniEsI5FmcqL5Mdhr ZB+Ns+kOd5a6FPIoC8u30HFA1uv2H5mrtTRkgY5nyHBoSzmlfosrP0L8RjBN1LUm Jy/kaddAl0eIimzJqYrd7zF5vXjlcmMHxLLPAtsfSSw+giD9hYIARvrRlxxmnVbc nU4t8ryA/VKMA5qPPmMbIcXxy2ZbnhHewxYttHcMl847ImCU9zbKZzGgBpM3K4IC 9f1vOhkk2f8neUSo62hsSZDAj5xQsb6JlyHnV4rt2GiNbGTqsUoOkQ== =Q0nE -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From prandal at herefordshire.gov.uk Mon Jan 23 15:32:35 2006 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Mon Jan 23 15:32:50 2006 Subject: 4.50.12 - please test Message-ID: <86144ED6CE5B004DA23E1EAC0B569B580AB9EDCD@isabella.herefordshire.gov.uk> Julian's patch to SweepViruses.pm works a treat, clamavmodule is now autodetected. analyse_SpamAssassin_cache reports a 20 to 25 percent hit rate here. Our MailScanner box processes around 15,000 emails a day. MailScanner 4.50 rocks. You're a star, Julian. Cheers, Phil ---- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Jeff A. Earickson > Sent: 23 January 2006 15:20 > To: MailScanner discussion > Subject: RE: 4.50.12 - please test > > I had a lot of headaches in the 0.86 thru 0.87 era (Solaris > 9) where Clam didn't seem to pick up the latest viruses. By > eliminating Mail-ClamAV, I was trying to cut down on the > number of possible failure points. Things have seemed good > with 0.88 again. I'll retry clamavmodule. > > Jeff Earickson > Colby College > > On Mon, 23 Jan 2006, Randal, Phil wrote: > > > Date: Mon, 23 Jan 2006 14:08:26 -0000 > > From: "Randal, Phil" > > Reply-To: MailScanner discussion > > > To: MailScanner discussion > > Subject: RE: 4.50.12 - please test > > > >> Julian, > >> Does auto give preference to the perl modules over the > >> standalone, or vice versa? I use "Virus Scanners = sophossavi > >> clamav"; I've given up on clamavmodule because of problems in the > >> past. > >> > >> Jeff Earickson > >> Colby College > > > > Jeff, > > > > What problems do (or did) you have with clamavmodule? I know there > > were problems in the past with incompatibilities with dev builds of > > clamav, but that's well in the past. > > > > It works without problem here. > > > > Cheers, > > > > Phil > > ---- > > Phil Randal > > Network Engineer > > Herefordshire Council > > Hereford, UK > > -- > > MailScanner mailing list > > MailScanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From prandal at herefordshire.gov.uk Mon Jan 23 15:37:59 2006 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Mon Jan 23 15:38:19 2006 Subject: 4.50.12 - please test Message-ID: <86144ED6CE5B004DA23E1EAC0B569B580AB9EDCE@isabella.herefordshire.gov.uk> > It now (with the patch I just posted) gives preference to the > Perl modules over the standalone. If you don't like what it > came up with, then you will have to edit the setting > yourself. It will log what scanners it is going to use, so it > is easy to check. Julian, It would be useful if "MailScanner --lint" reported which virus scanners it was using, especially now we have the "auto" setting. Cheers, Phil ---- Phil Randal Network Engineer Herefordshire Council Hereford, UK From prandal at herefordshire.gov.uk Mon Jan 23 15:39:02 2006 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Mon Jan 23 15:39:10 2006 Subject: Change default Lock Type for sendmail ? Message-ID: <86144ED6CE5B004DA23E1EAC0B569B580AB9EDCF@isabella.herefordshire.gov.uk> Julian, Is there any sane way to autodetect it and just do the right thing? Cheers, Phil ---- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Julian Field > Sent: 23 January 2006 15:31 > To: MailScanner mailing list > Subject: Change default Lock Type for sendmail ? > > -----BEGIN PGP SIGNED MESSAGE----- > > Is it about time I changed the default setting for "Lock > Type" to "posix" for sendmail users? > > It applies to most sendmail 8.13 (and upwards) users. Other > people would have to change it to "flock" if required. > It's just that most newbie users will be using whatever their > Linux distro ships with, which is now likely to be 8.13 these > days, isn't it? > > Opinions, please? > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store PGP > footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.4 (Build 4042) > > iQEVAwUBQ9T2zPw32o+k+q+hAQHlkAf+OMTEJIAZhpR8FWKA/t/yEKC0652zv8sY > 0j2btJdpdVSKzDRKFOHgf+Y8ZaTJJiLfJRfovR1BISrxPR/tniEsI5FmcqL5Mdhr > ZB+Ns+kOd5a6FPIoC8u30HFA1uv2H5mrtTRkgY5nyHBoSzmlfosrP0L8RjBN1LUm > Jy/kaddAl0eIimzJqYrd7zF5vXjlcmMHxLLPAtsfSSw+giD9hYIARvrRlxxmnVbc > nU4t8ryA/VKMA5qPPmMbIcXxy2ZbnhHewxYttHcMl847ImCU9zbKZzGgBpM3K4IC > 9f1vOhkk2f8neUSo62hsSZDAj5xQsb6JlyHnV4rt2GiNbGTqsUoOkQ== > =Q0nE > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From wietse at boudisque.nl Mon Jan 23 15:40:56 2006 From: wietse at boudisque.nl (Wietse Muizelaar) Date: Mon Jan 23 15:41:37 2006 Subject: 4.50.12 - please test References: <01ea01c62028$61e6bc90$1373a8c0@BOUDIEWEB10> <99C953E8-31DF-47D7-AC38-0269A3CF5EFC@ecs.soton.ac.uk> Message-ID: <02f101c62033$7818f400$1373a8c0@BOUDIEWEB10> Hi, On Monday, January 23, 2006 3:39 PM, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > On 23 Jan 2006, at 14:22, Wietse Muizelaar wrote: > >> Works great, but as others also mentioned clamav is used; but >> clamavmodule is -also- installed. Trying the patch right now :) This one works! >> Also still seeing the negative number of disinfected or MCP >> speedrate in the logs, like: >> Jan 23 14:40:39 boudams MailScanner[15242]: Disinfection completed >> at -1548421332 bytes per second > > Try changing line 104 of MessageBatch.pm so it says > $totaltime = 1 unless $totaltime > 0.001; # Minimum of 1 m-second > > Then restart MailScanner. Did so. It works for the "-1" speedrates, but not for the large negative numbers, unfortunately. Anything else I can try? -- Kind regards, Wietse Muizelaar ------------------------------------------- W.G. Muizelaar Boudisque Webmaster / ICT Drieharingstraat 5-31, 3511 BH Utrecht Telefoon: +31 (0)30 - 2394030 E-mail: wietse@boudisque.nl Website: www.boudisque.nl ------------------------------------------- From jaearick at colby.edu Mon Jan 23 15:51:47 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Mon Jan 23 15:51:58 2006 Subject: Change default Lock Type for sendmail ? In-Reply-To: <276DC8B5-0910-426D-A9ED-D726E8DC5F1A@ecs.soton.ac.uk> References: <276DC8B5-0910-426D-A9ED-D726E8DC5F1A@ecs.soton.ac.uk> Message-ID: Julian, Hmmm, I don't ever remember fiddling with this knob. It is blank right now in my setup: Solaris 9, MS 4.50.9, sendmail 8.13.5. I know that us Solaris geezers are a dying breed. Jeff Earickson Colby College On Mon, 23 Jan 2006, Julian Field wrote: > Date: Mon, 23 Jan 2006 15:31:22 +0000 > From: Julian Field > Reply-To: MailScanner discussion > To: MailScanner mailing list > Subject: Change default Lock Type for sendmail ? > > -----BEGIN PGP SIGNED MESSAGE----- > > Is it about time I changed the default setting for "Lock Type" to > "posix" for sendmail users? > > It applies to most sendmail 8.13 (and upwards) users. Other people > would have to change it to "flock" if required. > It's just that most newbie users will be using whatever their Linux > distro ships with, which is now likely to be 8.13 these days, isn't it? > > Opinions, please? > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.4 (Build 4042) > > iQEVAwUBQ9T2zPw32o+k+q+hAQHlkAf+OMTEJIAZhpR8FWKA/t/yEKC0652zv8sY > 0j2btJdpdVSKzDRKFOHgf+Y8ZaTJJiLfJRfovR1BISrxPR/tniEsI5FmcqL5Mdhr > ZB+Ns+kOd5a6FPIoC8u30HFA1uv2H5mrtTRkgY5nyHBoSzmlfosrP0L8RjBN1LUm > Jy/kaddAl0eIimzJqYrd7zF5vXjlcmMHxLLPAtsfSSw+giD9hYIARvrRlxxmnVbc > nU4t8ryA/VKMA5qPPmMbIcXxy2ZbnhHewxYttHcMl847ImCU9zbKZzGgBpM3K4IC > 9f1vOhkk2f8neUSo62hsSZDAj5xQsb6JlyHnV4rt2GiNbGTqsUoOkQ== > =Q0nE > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From G.Pentland at soton.ac.uk Mon Jan 23 15:54:11 2006 From: G.Pentland at soton.ac.uk (Pentland G.) Date: Mon Jan 23 15:54:46 2006 Subject: Change default Lock Type for sendmail ? Message-ID: <71437982F5B13A4D9A5B2669BDB89EE401711F41@ISS-CL-EX-V1.soton.ac.uk> >From sendmail 8.12.5 release notes... NOTE: Linux appears to have broken flock() again. Unless the bug is fixed before sendmail 8.13 is shipped, 8.13 will change the default locking method to fcntl() for Linux kernel 2.4 and later. You may want to do this in 8.12 by compiling with -DHASFLOCK=0. Be sure to update other sendmail related programs to match locking techniques. So from sendmail 8.12.5 it was set-able easily in site.config.m4. Trouble is that sendmail on BSD/Solaris will quite possibly be using flock still. I don't think there is an easy way to detect it. I think it may be easier for newbies to change it but theres still a lot of sendmail 8.12.x out there. just my thoughts, Gary mailscanner-bounces@lists.mailscanner.info wrote: > Julian, > > Is there any sane way to autodetect it and just do the right thing? > > Cheers, > > Phil > > ---- > Phil Randal > Network Engineer > Herefordshire Council > Hereford, UK > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of >> Julian Field Sent: 23 January 2006 15:31 >> To: MailScanner mailing list >> Subject: Change default Lock Type for sendmail ? >> >> -----BEGIN PGP SIGNED MESSAGE----- >> >> Is it about time I changed the default setting for "Lock >> Type" to "posix" for sendmail users? >> >> It applies to most sendmail 8.13 (and upwards) users. Other >> people would have to change it to "flock" if required. >> It's just that most newbie users will be using whatever their >> Linux distro ships with, which is now likely to be 8.13 these days, >> isn't it? >> >> Opinions, please? >> - -- >> Julian Field >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store PGP >> footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> >> >> -----BEGIN PGP SIGNATURE----- >> Version: PGP Desktop 9.0.4 (Build 4042) >> >> iQEVAwUBQ9T2zPw32o+k+q+hAQHlkAf+OMTEJIAZhpR8FWKA/t/yEKC0652zv8sY >> 0j2btJdpdVSKzDRKFOHgf+Y8ZaTJJiLfJRfovR1BISrxPR/tniEsI5FmcqL5Mdhr >> ZB+Ns+kOd5a6FPIoC8u30HFA1uv2H5mrtTRkgY5nyHBoSzmlfosrP0L8RjBN1LUm >> Jy/kaddAl0eIimzJqYrd7zF5vXjlcmMHxLLPAtsfSSw+giD9hYIARvrRlxxmnVbc >> nU4t8ryA/VKMA5qPPmMbIcXxy2ZbnhHewxYttHcMl847ImCU9zbKZzGgBpM3K4IC >> 9f1vOhkk2f8neUSo62hsSZDAj5xQsb6JlyHnV4rt2GiNbGTqsUoOkQ== =Q0nE >> -----END PGP SIGNATURE----- >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! From wietse at boudisque.nl Mon Jan 23 15:57:04 2006 From: wietse at boudisque.nl (Wietse Muizelaar) Date: Mon Jan 23 15:57:12 2006 Subject: Change default Lock Type for sendmail ? References: <86144ED6CE5B004DA23E1EAC0B569B580AB9EDCF@isabella.herefordshire.gov.uk> Message-ID: <033901c62035$a796ef00$1373a8c0@BOUDIEWEB10> Hi, On Monday, January 23, 2006 4:39 PM, Randal, Phil wrote: > Julian, > > Is there any sane way to autodetect it and just do the right thing? AFAIK there is not a failsafe way to autodetect this one; I remember seeing something in the list-archive about this. But I guess it's a good thing to put the posix-locktype to default; yes. -- Cheers, Wietse Muizelaar ------------------------------------------- W.G. Muizelaar Boudisque Webmaster / ICT Drieharingstraat 5-31, 3511 BH Utrecht Telefoon: +31 (0)30 - 2394030 E-mail: wietse@boudisque.nl Website: www.boudisque.nl ------------------------------------------- From penguin at dhcp.net Mon Jan 23 15:58:35 2006 From: penguin at dhcp.net (Arnim Eijkhoudt) Date: Mon Jan 23 15:58:42 2006 Subject: Use up your old Sun hardware In-Reply-To: <625385e30601230730i73e71932pfd0c3310f95a434f@mail.gmail.com> References: <625385e30601230730i73e71932pfd0c3310f95a434f@mail.gmail.com> Message-ID: <43D4FD2B.2050106@dhcp.net> It is nice, isn't it? I have a 320MB UltraSPARC 10 running backup SMTP with MailScanner right here ;-) AE shuttlebox wrote: > On 1/23/06, *Julian Field* > wrote: > > One of our students has found the perfect use for old Sun hardware: > http://www.soton.ac.uk/~tjr304/mail_scanner.jpg > > > > Hehe, maybe a tad slow for a MailScanner setup but it will happily serve > static web pages and ftp files for years after current PC hardware has > given up. You know it's the worlds most sold Unix workstation? > > -- > /peter > -- > This message has been scanned for viruses and > dangerous HTML content by Valethosting. > Dit bericht is gecontroleerd op virussen en gevaarlijke > HTML door Valethosting's MailScanner. > From MailScanner at ecs.soton.ac.uk Mon Jan 23 16:00:13 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 23 16:00:24 2006 Subject: 4.50.12 - please test In-Reply-To: <86144ED6CE5B004DA23E1EAC0B569B580AB9EDCE@isabella.herefordshire.gov.uk> References: <86144ED6CE5B004DA23E1EAC0B569B580AB9EDCE@isabella.herefordshire.gov.uk> Message-ID: <9E35653F-8D2D-44D0-A81C-546C858A6A93@ecs.soton.ac.uk> Skipped content of type multipart/mixed-------------- next part -------------- A non-text attachment was scrubbed... Name: PGP.sig Type: application/pgp-signature Size: 487 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060123/b0adca72/PGP.bin From matt at coders.co.uk Mon Jan 23 16:04:06 2006 From: matt at coders.co.uk (Matt Hampton) Date: Mon Jan 23 16:05:13 2006 Subject: Change default Lock Type for sendmail ? In-Reply-To: <033901c62035$a796ef00$1373a8c0@BOUDIEWEB10> References: <86144ED6CE5B004DA23E1EAC0B569B580AB9EDCF@isabella.herefordshire.gov.uk> <033901c62035$a796ef00$1373a8c0@BOUDIEWEB10> Message-ID: <43D4FE76.3080405@coders.co.uk> Wietse Muizelaar wrote: > Hi, > > On Monday, January 23, 2006 4:39 PM, > Randal, Phil wrote: > >> Julian, >> >> Is there any sane way to autodetect it and just do the right thing? > > AFAIK there is not a failsafe way to autodetect this one; I remember > seeing something in the list-archive about this. > But I guess it's a good thing to put the posix-locktype to default; yes. > Can't the output of "sendmail -d0.13 -bt References: <20060120200351.GA20468@pirates.Armstrong.EDU> <43D158FF.7010907@ecs.soton.ac.uk> <43D15C31.3070406@ecs.soton.ac.uk> <43D4EE25.9000002@USherbrooke.ca> Message-ID: <20060123161035.GB20468@pirates.Armstrong.EDU> I can't replicate this today. The same virus file that I was having trouble with on friday catches the virus, even with that lock file in place. On friday, I could scan mydoom.o on the command line, but when I sent it through the scanner, it wasn't detected. Today the file works either way. Thank you for looking at this. I was so sure that removing this file got the scanner working that I didn't think to try adding it back. Now I know that I may not have fixed the problem completely. My apologies for the bad bug report. On Mon, Jan 23, 2006 at 03:12:15PM +0000, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > > On 23 Jan 2006, at 14:54, Denis Beauchemin wrote: > > > Julian Field wrote: > > > >> Julian Field wrote: > >> > >>> andrew@pirates.armstrong.edu wrote: > >>> > >>>> I somehow got a lockfile owned by root left around on my system, > >>>> /tmp/McAfeeBusy.lock. This caused mailscanner to skip the virus > >>>> checking > >>>> and deliver infected email. Would it be possible just to stop > >>>> delivery > >>>> under these circumstances? > >>>> > >>> > >>> That certainly shouldn't happen! Please can you double-check your > >>> results. > >>> It should just cause the virus scanner to wait until the file was > >>> lockable. > >>> Please try it with the EICAR virus pattern (from www.eicar.org) > >>> which is a harmless test file, and let me know the result. > >>> > >> I have just tested this and it worked just fine. > >> Not sure what you did, but I would request that you re-do your > >> tests. I cannot reproduce the behaviour that you found. > >> > > Julian, > > > > I also have this file on my systems, but it seems to get updated > > quite often: > > [root@smtpe1 ~]# cat /tmp/McAfeeBusy.lock > > Virus checker locked for scanning by mcafee 3546 > > [root@smtpe1 ~]# cat /tmp/McAfeeBusy.lock > > Virus checker locked for scanning by mcafee 2284 > > [root@smtpe1 ~]# cat /tmp/McAfeeBusy.lock > > Virus checker locked for scanning by mcafee 2284 > > [root@smtpe1 ~]# cat /tmp/McAfeeBusy.lock > > Virus checker locked for scanning by mcafee 3794 > > > > My McAfee does detect viruses! I'm using mailscanner-4.50.10-1 > > under RHEL 4. > > It is there so that MailScanner and the mcafee-autoupdate processes > lock out each other. If you were in the middle of a mcafee-autoupdate > when you tried to scan a message, it is possible (but very unlikely) > that the virus definitions would be partially complete, so you may > miss a virus. > > So they lock out each other so that the two processes cannot happen > at the same time. > > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.4 (Build 4042) > > iQEVAwUBQ9TyUfw32o+k+q+hAQGbVggAtqDdqw6JR3itTvG/Y/fwWtFe920JEQ+8 > 3iOAkevnEJjALEctOaREJ0UQ20x5tZhDhIrUlMZ4JxM03u/6magN+vjnlvD1/LVP > tUWvscArSFwN0/4GXHoXgFXJIcrm7rIbCHQucAvdvOtAksmaIDfxdoC9U3h5VKV7 > ReGApexIq7CQUjhu48iJDwzQ6PULFjJRFNftahDHJeu0Iekzg0r7iOSjxdoo1YnP > a5mDh91ybfpSuVxsYZ5bJEkznP6M8mEIhD1AeaLW6Q6stSU+9kOvbOmOoEKC22hO > YIJ6FN4jiiq7osOk4PqhKJjw4swE6VCXBtnWs6dOG8QAASkcpkjkjQ== > =iHOK > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! -- Andrew Eason System Administrator andrew@armstrong.edu From philipp.snizek at terreactive.ch Mon Jan 23 16:13:12 2006 From: philipp.snizek at terreactive.ch (Philipp Snizek) Date: Mon Jan 23 16:13:20 2006 Subject: still wrong SA score set used In-Reply-To: <43D4FD2B.2050106@dhcp.net> References: <625385e30601230730i73e71932pfd0c3310f95a434f@mail.gmail.com> <43D4FD2B.2050106@dhcp.net> Message-ID: <1138032792.7791.17.camel@philipp.terreactive.ch> It's exacty the same rules that fire (as my testemail uses the same keywords). However, the SA score set that is uses is the wrong one. I'd need with network tests disabled and bayes enabled. Instead, I get network tests enabled and bayes disabled. With both enabled I'd be happy too. When I run `spamassassin < email` both, network tests and bayes tests are enabled, so score set 3 is chosen. MailScanner unfortunaltey choses score set 2. Yes, please let me know what parameters in MailScanner.conf I have to change. Thanks a lot Best, Philipp What rules fire when the email is scanned with 'spamassassin' and what rules fire when you scan using MailScanner? You may need to edit the MailScanner.conf to get it include the SA rules and scores always in order for you to get this info from MailScanner. If you're not sure which settings to change reply back and I'll me more verbose. BTW in 4.49 you don't need the "-C" (which should actually be "-P") as /etc/mail/spamassassin/mailscanner should be a symbolic link to spam.assassin.prefs.conf. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces at lists.mailscanner.info [mailto:mailscanner- > bounces at lists.mailscanner.info] On Behalf Of Philipp Snizek > Sent: 20 January 2006 09:12 > To: MailScanner discussion > Subject: still wrong SA score set used > > Hi > > I use SA 3.1 and MailScanner 4.49.7 > > When I run > `spamassassin --lint -D -C /etc/MailScanner/spam.assassin.prefs.conf` > SpamAssassin tells me that it would use score set 3 which is, what I > want. > When I send a spam email through my exim/mailscanner/sa box score set 2 > is used. MailScanner uses /etc/MailScanner/spam.assassin.prefs.conf too. > > > Is this MailScanner default to use SA score set 2 or what do I miss in > my MailScanner.conf file? > > Thanks a lot > > Best, > Philipp > > -- > MailScanner mailing list > MailScanner at lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From shuttlebox at gmail.com Mon Jan 23 16:21:51 2006 From: shuttlebox at gmail.com (shuttlebox) Date: Mon Jan 23 16:21:53 2006 Subject: Change default Lock Type for sendmail ? In-Reply-To: <43D4FE76.3080405@coders.co.uk> References: <86144ED6CE5B004DA23E1EAC0B569B580AB9EDCF@isabella.herefordshire.gov.uk> <033901c62035$a796ef00$1373a8c0@BOUDIEWEB10> <43D4FE76.3080405@coders.co.uk> Message-ID: <625385e30601230821t62d10f70t5579078b8112e2fe@mail.gmail.com> On 1/23/06, Matt Hampton wrote: > > Can't the output of "sendmail -d0.13 -bt used? > > My 8.12 box returns a line, my 8.13 doesn't........ > Not in a reliable way, my Solaris systems run with flock but they don't have HASFLOCK in the debug output. I think that's why Julian removed the autodetection that was part of MS for one release. -- /peter -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060123/7ac06b41/attachment.html From steve.swaney at fsl.com Mon Jan 23 16:22:54 2006 From: steve.swaney at fsl.com (Stephen Swaney) Date: Mon Jan 23 16:22:57 2006 Subject: Change default Lock Type for sendmail ? In-Reply-To: <43D4FE76.3080405@coders.co.uk> Message-ID: <200601231622.k0NGMttc021424@bkserver.blacknight.ie> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Matt Hampton > Sent: Monday, January 23, 2006 11:04 AM > To: MailScanner discussion > Subject: Re: Change default Lock Type for sendmail ? > > Wietse Muizelaar wrote: > > Hi, > > > > On Monday, January 23, 2006 4:39 PM, > > Randal, Phil wrote: > > > >> Julian, > >> > >> Is there any sane way to autodetect it and just do the right thing? > > > > AFAIK there is not a failsafe way to autodetect this one; I remember > > seeing something in the list-archive about this. > > But I guess it's a good thing to put the posix-locktype to default; yes. > > > > Can't the output of "sendmail -d0.13 -bt used? > > My 8.12 box returns a line, my 8.13 doesn't........ > sendmail -d0.13 -bt < /dev/null | grep Version | awk '{print $2}' At least returns the correct version on the systems I've tested on. Steve Stephen Swaney Fort Systems Ltd. stephen.swaney@fsl.com www.fsl.com From shuttlebox at gmail.com Mon Jan 23 16:24:15 2006 From: shuttlebox at gmail.com (shuttlebox) Date: Mon Jan 23 16:24:18 2006 Subject: Use up your old Sun hardware In-Reply-To: <43D4FD2B.2050106@dhcp.net> References: <625385e30601230730i73e71932pfd0c3310f95a434f@mail.gmail.com> <43D4FD2B.2050106@dhcp.net> Message-ID: <625385e30601230824i50a2e81h7bc74807ee73cfb5@mail.gmail.com> On 1/23/06, Arnim Eijkhoudt wrote: > > It is nice, isn't it? I have a 320MB UltraSPARC 10 running backup SMTP > with MailScanner right here ;-) > I have an Ultra 10 system as my test bed for MailScanner too. Works like a charm. I'm testing BlastWave on it right now. -- /peter -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060123/3f00f8c2/attachment.html From listuser at peternixon.net Mon Jan 23 16:28:21 2006 From: listuser at peternixon.net (Peter Nixon) Date: Mon Jan 23 16:28:23 2006 Subject: OT: signature protocol In-Reply-To: <1137590239.7668.26.camel@lea.nerc-wallingford.ac.uk> References: <1137518119.30908.114.camel@lea.nerc-wallingford.ac.uk> <43CD2B34.4050008@ecs.soton.ac.uk> <1137590239.7668.26.camel@lea.nerc-wallingford.ac.uk> Message-ID: <200601231828.31122.listuser@peternixon.net> On Wed 18 Jan 2006 15:17, Greg Matthews wrote: > On Tue, 2006-01-17 at 17:36 +0000, Julian Field wrote: > > The official signature separator isn't '--' but '-- ' i.e. dash dash > > space. > > ah ok. > > > You don't need to start the corporate one with --, but I think it looks > > better. Notice that this reply has had your sig stripped off, this is > > done automatically by Thunderbird now. It has stripped the whole sig, > > not just the first one. > > oooh... shiny. I like that. KMail also does that same thing (For the last few years anyway) Cheers -- Peter Nixon http://www.peternixon.net/ PGP Key: http://www.peternixon.net/public.asc -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060123/e1ad44b6/attachment.bin From G.Pentland at soton.ac.uk Mon Jan 23 17:16:17 2006 From: G.Pentland at soton.ac.uk (Pentland G.) Date: Mon Jan 23 17:16:32 2006 Subject: Change default Lock Type for sendmail ? Message-ID: <71437982F5B13A4D9A5B2669BDB89EE401711F42@ISS-CL-EX-V1.soton.ac.uk> mailscanner-bounces@lists.mailscanner.info wrote: > Can't the output of "sendmail -d0.13 -bt used? > > My 8.12 box returns a line, my 8.13 doesn't........ As echoed elsewhere... this may OK on Linux but on BSD/Solaris it is not reliable... I think that whatever the "default" is it should be well documented and set up so that if it is not set by a human then MS will not start... maybe have it as a question in install.sh? ./install.sh ... ... Are you using flock (yes/no)? * if you don't know what this means then type "no". > Just another maybe, and the Solaris/BSD people will be less likely to get caught out. Gary From MailScanner at ecs.soton.ac.uk Mon Jan 23 17:57:35 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 23 17:57:41 2006 Subject: Change default Lock Type for sendmail ? In-Reply-To: <71437982F5B13A4D9A5B2669BDB89EE401711F42@ISS-CL-EX-V1.soton.ac.uk> References: <71437982F5B13A4D9A5B2669BDB89EE401711F42@ISS-CL-EX-V1.soton.ac.uk> Message-ID: <43D5190F.8050108@ecs.soton.ac.uk> Pentland G. wrote: > mailscanner-bounces@lists.mailscanner.info wrote: > >> Can't the output of "sendmail -d0.13 -bt > used? >> >> My 8.12 box returns a line, my 8.13 doesn't........ >> > > As echoed elsewhere... this may OK on Linux but on BSD/Solaris it is not > reliable... > > I think that whatever the "default" is it should be well documented and > set up so that if it is not set by a human then MS will not start... > maybe have it as a question in install.sh? > > ./install.sh > ... > ... > Are you using flock (yes/no)? > * if you don't know what this means then type "no". > > > > Just another maybe, and the Solaris/BSD people will be less likely to > get caught out. > But the Solaris people tend to know more what they are doing. As it stands with flock being the default, the people caught out are the people who predominantly know the least (the Linux point-and-click crowd). With the default being posix, the people caught out are the people who know a lot more. I have never asked the users before which to go for, and it hasn't generated many problems, so I don't see this as a huge issue really. The install.sh works everything else out for itself, I don't want to make it interactive if I can possibly avoid it. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From jaearick at colby.edu Mon Jan 23 18:29:32 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Mon Jan 23 18:29:51 2006 Subject: Change default Lock Type for sendmail ? In-Reply-To: <43D5190F.8050108@ecs.soton.ac.uk> References: <71437982F5B13A4D9A5B2669BDB89EE401711F42@ISS-CL-EX-V1.soton.ac.uk> <43D5190F.8050108@ecs.soton.ac.uk> Message-ID: On Mon, 23 Jan 2006, Julian Field wrote: > But the Solaris people tend to know more what they are doing. As it stands > with flock being the default, the people caught out are the people who > predominantly know the least (the Linux point-and-click crowd). With the > default being posix, the people caught out are the people who know a lot > more. Thanks for the words of praise for the Solaris crowd, but please add a few comments in this spot for what *you* think the setting should be for various common OS'es. It might save some head scratching for some poor soul in the future (or us who are looking at things again). Jeff Earickson Colby College From G.Pentland at soton.ac.uk Mon Jan 23 18:47:26 2006 From: G.Pentland at soton.ac.uk (Pentland G.) Date: Mon Jan 23 18:47:34 2006 Subject: Change default Lock Type for sendmail ? Message-ID: <71437982F5B13A4D9A5B2669BDB89EE401711F43@ISS-CL-EX-V1.soton.ac.uk> mailscanner-bounces@lists.mailscanner.info wrote: > I have never asked the users before which to go for, and it hasn't > generated many problems, so I don't see this as a huge issue really. > The install.sh works everything else out for itself, I don't want to > make it interactive if I can possibly avoid it. That is a fair and true point... I also appreciate the "those that know the most" comments:-) Gary From dwinkler at algorithmics.com Mon Jan 23 18:51:12 2006 From: dwinkler at algorithmics.com (Derek Winkler) Date: Mon Jan 23 18:51:16 2006 Subject: Old Sys::Hostname::Long Message-ID: <570A16F7DB56C242B26876067D682FD001E6D5BD@TORMAIL.algorithmics.com> Skipped content of type multipart/alternative From steve.swaney at fsl.com Mon Jan 23 19:01:59 2006 From: steve.swaney at fsl.com (Stephen Swaney) Date: Mon Jan 23 19:02:02 2006 Subject: w32.pinf virus Message-ID: <200601231902.k0NJ20dn024572@bkserver.blacknight.ie> We've just had a report that the w32.pinf virus slipped through updated current versions of ClamAV and Bitdefender. http://securityresponse.symantec.com/avcenter/venc/data/w32.pinfi.html Has anyone else seen this? Maybe it's time to start the "which virus scanners do you use?" and "how much does it cost" threads again :) Steve Stephen Swaney Fort Systems Ltd. stephen.swaney@fsl.com www.fsl.com From shuttlebox at gmail.com Mon Jan 23 19:02:16 2006 From: shuttlebox at gmail.com (shuttlebox) Date: Mon Jan 23 19:02:21 2006 Subject: Old Sys::Hostname::Long In-Reply-To: <570A16F7DB56C242B26876067D682FD001E6D5BD@TORMAIL.algorithmics.com> References: <570A16F7DB56C242B26876067D682FD001E6D5BD@TORMAIL.algorithmics.com> Message-ID: <625385e30601231102u9dc0d2cge7fa7ceb85a0b089@mail.gmail.com> On 1/23/06, Derek Winkler wrote: > > The install-Clam-SA has a version 1.2 Sys::Hostname::Long which has been > changing the hostname on my Solaris 8 system to "--fqdn". > > Version 1.4 of Sys::Hostname::Long does not do this, you may want to > update it. > What's it used for? I'm on Solaris and I've avoided it because of the -fqdn issue and I've never had any problems being without it. -- /peter -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060123/34c32ff6/attachment.html From Denis.Beauchemin at USherbrooke.ca Mon Jan 23 19:10:21 2006 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Mon Jan 23 19:10:34 2006 Subject: Change default Lock Type for sendmail ? In-Reply-To: <200601231622.k0NGMttc021424@bkserver.blacknight.ie> References: <200601231622.k0NGMttc021424@bkserver.blacknight.ie> Message-ID: <43D52A1D.3060507@USherbrooke.ca> Stephen Swaney wrote: >>-----Original Message----- >>From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >>bounces@lists.mailscanner.info] On Behalf Of Matt Hampton >>Sent: Monday, January 23, 2006 11:04 AM >>To: MailScanner discussion >>Subject: Re: Change default Lock Type for sendmail ? >> >>Wietse Muizelaar wrote: >> >> >>>Hi, >>> >>>On Monday, January 23, 2006 4:39 PM, >>>Randal, Phil wrote: >>> >>> >>> >>>>Julian, >>>> >>>>Is there any sane way to autodetect it and just do the right thing? >>>> >>>> >>>AFAIK there is not a failsafe way to autodetect this one; I remember >>>seeing something in the list-archive about this. >>>But I guess it's a good thing to put the posix-locktype to default; yes. >>> >>> >>> >>Can't the output of "sendmail -d0.13 -bt >used? >> >>My 8.12 box returns a line, my 8.13 doesn't........ >> >> >> > >sendmail -d0.13 -bt < /dev/null | grep Version | awk '{print $2}' > > Or with optimization on ;-) sendmail -d0.13 -bt < /dev/null | awk '/Version/{print $2}' Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x2252 F: 819.821.8045 From ssilva at sgvwater.com Mon Jan 23 19:22:08 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Mon Jan 23 19:23:36 2006 Subject: Change default Lock Type for sendmail ? In-Reply-To: <43D5190F.8050108@ecs.soton.ac.uk> References: <71437982F5B13A4D9A5B2669BDB89EE401711F42@ISS-CL-EX-V1.soton.ac.uk> <43D5190F.8050108@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 1/23/2006 9:57 AM: > Pentland G. wrote: >> mailscanner-bounces@lists.mailscanner.info wrote: >> >>> Can't the output of "sendmail -d0.13 -bt >> used? >>> My 8.12 box returns a line, my 8.13 doesn't........ >>> >> >> As echoed elsewhere... this may OK on Linux but on BSD/Solaris it is not >> reliable... >> >> I think that whatever the "default" is it should be well documented and >> set up so that if it is not set by a human then MS will not start... >> maybe have it as a question in install.sh? >> >> ./install.sh >> ... >> ... >> Are you using flock (yes/no)? * if you don't know what this means >> then type "no". >> >> >> Just another maybe, and the Solaris/BSD people will be less likely to >> get caught out. >> > But the Solaris people tend to know more what they are doing. As it > stands with flock being the default, the people caught out are the > people who predominantly know the least (the Linux point-and-click > crowd). With the default being posix, the people caught out are the > people who know a lot more. > > I have never asked the users before which to go for, and it hasn't > generated many problems, so I don't see this as a huge issue really. The > install.sh works everything else out for itself, I don't want to make it > interactive if I can possibly avoid it. > Won't posix locking work either way, maybe just a little slower? That would make posix a "safe" setting. Or maybe I'm just a little slow this Monday... ;-) -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () From lhaig at haigmail.com Mon Jan 23 21:23:47 2006 From: lhaig at haigmail.com (Lance Haig) Date: Mon Jan 23 21:23:49 2006 Subject: how to allow .js files. Message-ID: <43D54963.5040802@haigmail.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I have created a filename.rules.conf and a filetype.rules.conf for a specific domain and I need to allow .js files and .vbs files as this is a web development company. I can't see the deny rule for .js and vbs What do I need to change to allow these files. Thanks Lance -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD4DBQFD1UljM4kHBIBZ61gRAqByAJja3aCgurltQMmEB3AISvxPopqpAKCQ6lgL qBQqDe8Of7i+TAUf0gkD1w== =D/wP -----END PGP SIGNATURE----- From batkins at tlcdelivers.com Mon Jan 23 22:00:31 2006 From: batkins at tlcdelivers.com (Brian Atkins) Date: Mon Jan 23 22:07:14 2006 Subject: Mailscanner being bypassed? Message-ID: <43D551FF.90000@tlcdelivers.com> Greetings. I'm relatively new to Mailscanner. I have a server running Sendmail 8.13.5, SpamAssassin 3.1.0, and Mailscanner (not sure which version). Today, I was working with the greet_pause setting in sendmail. I originally set it to default (700) and custom connection times for our internal clients (from our custom setting (5000)) to try and deal with local clients timing out when trying to establish a connection. It sped up the connection for the internal clients, but seems to have caused issues with Mailscanner. At this time, I have moved the previous sendmail.[cf|mc] back in place and restarted both Mailscanner and sendmail separately seveal times, but it appears that I'm now getting a very heavy influx of spam messages. Also, the X headers (Mail Header = X-%org-name%-MailScanner:) seem to have disappeared. I combed back through my sendmail config files and Mailscanner (also glossed over spamassassin), but cannot find any issues. I also dug into the documentation on the .info site and reviewed the list archives. I would appreciate any input. -- Brian Atkins "An adventure is never an adventure when it's happening. Challenging experiences need time to ferment, and an adventure is simply physical and emotional discomfort recollected in tranquility." -- Tim Cahill From Jeff.Mills at versacold.com.au Mon Jan 23 22:24:02 2006 From: Jeff.Mills at versacold.com.au (Jeff Mills) Date: Mon Jan 23 22:24:07 2006 Subject: Turning off certain subject modifications Message-ID: <197F21E06E4D2A478519EA9078D6AA1C01B0AC61@poclexch.AU.POCOLD.POCL> Since upgrading MailScanner, I'm now getting quite a few emails being modified similar to the following: "[SPAM] - original subject here - Email found in subject" I have turned subject modification off for low scoring spam, but this didnt get rid of it. Is there another setting I'm missing somewhere to turn this off? Some people get a bit ansty when their business related email is tagged this way and they have to reply to the person who sent it. Thanks! *** "This company is now part of the Versacold Holdings Corp. and is no longer owned by or affiliated with the P&O Group" *** ************** www.versacold.com ************** From steve.swaney at fsl.com Mon Jan 23 22:25:53 2006 From: steve.swaney at fsl.com (Stephen Swaney) Date: Mon Jan 23 22:25:56 2006 Subject: how to allow .js files. In-Reply-To: <43D54963.5040802@haigmail.com> Message-ID: <200601232225.k0NMPs56027491@bkserver.blacknight.ie> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Lance Haig > Sent: Monday, January 23, 2006 4:24 PM > To: MailScanner discussion > Subject: how to allow .js files. > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > I have created a filename.rules.conf and a filetype.rules.conf for a > specific domain and I need to allow .js files and .vbs files as this is > a web development company. > > I can't see the deny rule for .js and vbs > > What do I need to change to allow these files. > Try looking at the settings for: Allow Script Tags = You may need a rule set that allows Script Tags To and From your domain. This can be dangerousif you don't know where the email is from so if you can limit to: From: xyz.com and To: mydomain.com allow You'd be safer :) Steve Stephen Swaney Fort Systems Ltd. stephen.swaney@fsl.com www.fsl.com > Thanks > > Lance > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.2 (MingW32) > Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org > > iD4DBQFD1UljM4kHBIBZ61gRAqByAJja3aCgurltQMmEB3AISvxPopqpAKCQ6lgL > qBQqDe8Of7i+TAUf0gkD1w== > =D/wP > -----END PGP SIGNATURE----- > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From ddelao at oucpm.org Mon Jan 23 22:25:32 2006 From: ddelao at oucpm.org (Darryl DeLao) Date: Mon Jan 23 22:26:03 2006 Subject: RDNS Message-ID: <000001c6206b$ec624310$0632a8c0@oucpm1> Is there a way to turn on RDNS in Mailscanner, or is this done in Sendmail? If so, how is it done? Basically, if an email comes in and the originating domain can not be resolved, I do not want to accept the email in the system. Thanks, Darryl -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060123/82e0a760/attachment.html From matt at coders.co.uk Mon Jan 23 22:26:01 2006 From: matt at coders.co.uk (Matt Hampton) Date: Mon Jan 23 22:26:15 2006 Subject: Mailscanner being bypassed? In-Reply-To: <43D551FF.90000@tlcdelivers.com> References: <43D551FF.90000@tlcdelivers.com> Message-ID: <43D557F9.4080801@coders.co.uk> Brian Atkins wrote: > At this time, I have moved the previous sendmail.[cf|mc] back in place > and restarted both Mailscanner and sendmail separately seveal times, but > it appears that I'm now getting a very heavy influx of spam messages. > Also, the X headers (Mail Header = X-%org-name%-MailScanner:) seem to > have disappeared. > That's because you have probably started sendmail as a standalone system and not started it through MailScanner. You should not start sendmail through it's start up scripts. Assuming you are on a Linux distribution: chkconfig sendmail off service sendmail stop service MailScanner stop service MailScanner start matt From michele at blacknight.ie Mon Jan 23 22:30:06 2006 From: michele at blacknight.ie (Michele Neylon:: Blacknight.ie) Date: Mon Jan 23 22:30:21 2006 Subject: Turning off certain subject modifications In-Reply-To: <197F21E06E4D2A478519EA9078D6AA1C01B0AC61@poclexch.AU.POCOLD.POCL> References: <197F21E06E4D2A478519EA9078D6AA1C01B0AC61@poclexch.AU.POCOLD.POCL> Message-ID: <43D558EE.8070506@blacknight.ie> Jeff Mills wrote: > Since upgrading MailScanner, I'm now getting quite a few emails being modified similar to the following: > "[SPAM] - original subject here - Email found in subject" > > I have turned subject modification off for low scoring spam, but this didnt get rid of it. > Is there another setting I'm missing somewhere to turn this off? > Some people get a bit ansty when their business related email is tagged this way and they have to reply to the person who sent it. > Upgrading from which version to which version? >From memory, which can be flaky as the evening progresses, there were some changes to message tagging a couple of versions back... I'd recommend reading MailScanner.conf very carefully.. I know it's long, but it could be the key... You could also diff your previous config against the new one? -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 From mkettler at evi-inc.com Mon Jan 23 22:42:18 2006 From: mkettler at evi-inc.com (Matt Kettler) Date: Mon Jan 23 22:42:32 2006 Subject: RDNS In-Reply-To: <000001c6206b$ec624310$0632a8c0@oucpm1> References: <000001c6206b$ec624310$0632a8c0@oucpm1> Message-ID: <43D55BCA.6020501@evi-inc.com> Darryl DeLao wrote: > Is there a way to turn on RDNS in Mailscanner, or is this done in > Sendmail? If so, how is it done? Basically, if an email comes in and > the originating domain can not be resolved, I do not want to accept the > email in the system. Well, MailScanner can't ever prevent any email from being accepted. MailScanner acts on the queue files, so by the time MS sees it, it's long since been accepted. However, the feature you want is a standard sendmail feature. Look up the "accept_unresolvable_domains" feature, and disable it. If you're using m4 to build your sendmail.cf (highly recommended unless you're a sendmail master) edit /etc/mail/sendmail.mc add a "dnl" to the start of the feature line, line this: dnl FEATURE(`accept_unresolvable_domains')dnl rebuild your sendmail.cf by running make in the /etc/mail directory restart your MailScanner service to restart the sendmail's. From michele at blacknight.ie Mon Jan 23 22:44:28 2006 From: michele at blacknight.ie (Michele Neylon:: Blacknight.ie) Date: Mon Jan 23 22:44:30 2006 Subject: RDNS In-Reply-To: <000001c6206b$ec624310$0632a8c0@oucpm1> References: <000001c6206b$ec624310$0632a8c0@oucpm1> Message-ID: <43D55C4C.8010704@blacknight.ie> Darryl DeLao wrote: > Is there a way to turn on RDNS in Mailscanner, or is this done in > Sendmail? If so, how is it done? Basically, if an email comes in and > the originating domain can not be resolved, I do not want to accept the > email in the system. That's sendmail as far as I can remember By the way, mailscanner-announce is not the place to send that :) -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 From Jeff.Mills at versacold.com.au Mon Jan 23 22:46:17 2006 From: Jeff.Mills at versacold.com.au (Jeff Mills) Date: Mon Jan 23 22:46:27 2006 Subject: Turning off certain subject modifications Message-ID: <197F21E06E4D2A478519EA9078D6AA1C01B0AC64@poclexch.AU.POCOLD.POCL> > > > > Upgrading from which version to which version? > > >From memory, which can be flaky as the evening progresses, there were > some changes to message tagging a couple of versions back... > > I'd recommend reading MailScanner.conf very carefully.. I know it's > long, but it could be the key... > > You could also diff your previous config against the new one? I believe it started in 4.50.4 for me - I think I was using 4.34.x before that. I've gone through the config file, but I cant find anything else that could turn it off. Unless of course my config file is missing some parameters, but I doubt it, as I have used the config update script to update the config files. *** "This company is now part of the Versacold Holdings Corp. and is no longer owned by or affiliated with the P&O Group" *** ************** www.versacold.com ************** From ddelao at oucpm.org Mon Jan 23 22:47:01 2006 From: ddelao at oucpm.org (Darryl DeLao) Date: Mon Jan 23 22:47:31 2006 Subject: RDNS In-Reply-To: <43D55BCA.6020501@evi-inc.com> Message-ID: <000c01c6206e$ec852d00$0632a8c0@oucpm1> Sweet! Thanks a lot, I will try this tomorrow. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Matt Kettler Sent: Monday, January 23, 2006 4:42 PM To: MailScanner discussion Cc: mailscanner-announce@lists.mailscanner.info Subject: Re: RDNS Darryl DeLao wrote: > Is there a way to turn on RDNS in Mailscanner, or is this done in > Sendmail? If so, how is it done? Basically, if an email comes in and > the originating domain can not be resolved, I do not want to accept the > email in the system. Well, MailScanner can't ever prevent any email from being accepted. MailScanner acts on the queue files, so by the time MS sees it, it's long since been accepted. However, the feature you want is a standard sendmail feature. Look up the "accept_unresolvable_domains" feature, and disable it. If you're using m4 to build your sendmail.cf (highly recommended unless you're a sendmail master) edit /etc/mail/sendmail.mc add a "dnl" to the start of the feature line, line this: dnl FEATURE(`accept_unresolvable_domains')dnl rebuild your sendmail.cf by running make in the /etc/mail directory restart your MailScanner service to restart the sendmail's. -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From lhaig at haigmail.com Mon Jan 23 22:47:31 2006 From: lhaig at haigmail.com (Lance Haig) Date: Mon Jan 23 22:47:35 2006 Subject: how to allow .js files. In-Reply-To: <200601232225.k0NMPs56027491@bkserver.blacknight.ie> References: <200601232225.k0NMPs56027491@bkserver.blacknight.ie> Message-ID: <43D55D03.70201@haigmail.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi Stephen, Thanks for the tip. I will let them know Thanks Lance Stephen Swaney wrote: >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Lance Haig >> Sent: Monday, January 23, 2006 4:24 PM >> To: MailScanner discussion >> Subject: how to allow .js files. >> > I have created a filename.rules.conf and a filetype.rules.conf for a > specific domain and I need to allow .js files and .vbs files as this is > a web development company. > > I can't see the deny rule for .js and vbs > > What do I need to change to allow these files. > >> Try looking at the settings for: > >> Allow Script Tags = > >> You may need a rule set that allows Script Tags To and From your domain. >> This can be dangerousif you don't know where the email is from so if you can >> limit to: > >> From: xyz.com and To: mydomain.com allow > >> You'd be safer :) > >> Steve > >> Stephen Swaney >> Fort Systems Ltd. >> stephen.swaney@fsl.com >> www.fsl.com > > Thanks > > Lance - -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner >> Before posting, read http://wiki.mailscanner.info/posting >> Support MailScanner development - buy the book off the website! -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFD1V0DM4kHBIBZ61gRAh/qAJ9tWHI2jEKumdKZ1IMsMwx+GL+auACeLp7o 5LG/qH6yZ+0kTvIKpVHUeuM= =T39W -----END PGP SIGNATURE----- From brose at med.wayne.edu Mon Jan 23 23:23:54 2006 From: brose at med.wayne.edu (Rose, Bobby) Date: Mon Jan 23 23:24:02 2006 Subject: RDNS Message-ID: <8F2A53954C22554EB75D9643FCCE0C6B887E@MED-CORE03-MS1.med.wayne.edu> I thought that it was a default action in sendmail to not accept from unresolvable hosts and in setting FEATURE(`accept_unresolvable_domains')dnl you are actually disabling so that it does accept from unresolvable hosts. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Matt Kettler Sent: Monday, January 23, 2006 5:42 PM To: MailScanner discussion Cc: mailscanner-announce@lists.mailscanner.info Subject: Re: RDNS Darryl DeLao wrote: > Is there a way to turn on RDNS in Mailscanner, or is this done in > Sendmail? If so, how is it done? Basically, if an email comes in and > the originating domain can not be resolved, I do not want to accept > the email in the system. Well, MailScanner can't ever prevent any email from being accepted. MailScanner acts on the queue files, so by the time MS sees it, it's long since been accepted. However, the feature you want is a standard sendmail feature. Look up the "accept_unresolvable_domains" feature, and disable it. If you're using m4 to build your sendmail.cf (highly recommended unless you're a sendmail master) edit /etc/mail/sendmail.mc add a "dnl" to the start of the feature line, line this: dnl FEATURE(`accept_unresolvable_domains')dnl rebuild your sendmail.cf by running make in the /etc/mail directory restart your MailScanner service to restart the sendmail's. -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From steve.swaney at fsl.com Mon Jan 23 23:32:53 2006 From: steve.swaney at fsl.com (Stephen Swaney) Date: Mon Jan 23 23:32:55 2006 Subject: RDNS In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B887E@MED-CORE03-MS1.med.wayne.edu> Message-ID: <200601232332.k0NNWrJ4030163@bkserver.blacknight.ie> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Rose, Bobby > Sent: Monday, January 23, 2006 6:24 PM > To: MailScanner discussion > Cc: mailscanner-announce@lists.mailscanner.info > Subject: RE: RDNS > > I thought that it was a default action in sendmail to not accept from > unresolvable hosts and in setting > FEATURE(`accept_unresolvable_domains')dnl you are actually disabling so > that it does accept from unresolvable hosts. > Nope :( Steve Stephen Swaney Fort Systems Ltd. stephen.swaney@fsl.com www.fsl.com > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Matt > Kettler > Sent: Monday, January 23, 2006 5:42 PM > To: MailScanner discussion > Cc: mailscanner-announce@lists.mailscanner.info > Subject: Re: RDNS > > Darryl DeLao wrote: > > Is there a way to turn on RDNS in Mailscanner, or is this done in > > Sendmail? If so, how is it done? Basically, if an email comes in and > > > the originating domain can not be resolved, I do not want to accept > > the email in the system. > > Well, MailScanner can't ever prevent any email from being accepted. > MailScanner acts on the queue files, so by the time MS sees it, it's > long since been accepted. > > > However, the feature you want is a standard sendmail feature. Look up > the "accept_unresolvable_domains" feature, and disable it. > > If you're using m4 to build your sendmail.cf (highly recommended unless > you're a sendmail master) > > edit /etc/mail/sendmail.mc > > add a "dnl" to the start of the feature line, line this: > > dnl FEATURE(`accept_unresolvable_domains')dnl > > rebuild your sendmail.cf by running make in the /etc/mail directory > > restart your MailScanner service to restart the sendmail's. > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From mailscanner at PDSCC.COM Tue Jan 24 01:34:01 2006 From: mailscanner at PDSCC.COM (Harondel J. Sibble) Date: Tue Jan 24 01:34:11 2006 Subject: switching from dual queue to single queue with postfix Message-ID: <200601271259.EAA25759@sheridan.sibble.net> I remember there being a MAQ entry for switching from dual queue to single queue mode with postfix, however I can't seem to find that info. I have found the instructions for setting up the single queue method for a new install, but not for migrating. I remember there was lot of discussion on the list when this new method came about but so far so I haven't found the answer I need at the searchable list archives in gmane, can someone point me in the right direction? Thanks -- Harondel J. Sibble Sibble Computer Consulting Creating solutions for the small business and home computer user. help@pdscc.com (use pgp keyid 0x3AD5C11D) http://www.pdscc.com (604) 739-3709 (voice/fax) (604) 686-2253 (pager) From pete at enitech.com.au Tue Jan 24 01:50:24 2006 From: pete at enitech.com.au (Peter Russell) Date: Tue Jan 24 01:50:27 2006 Subject: MS 4.50: way cool... In-Reply-To: References: Message-ID: <43D587E0.2020403@enitech.com.au> How did you do this report? Jeff A. Earickson wrote: > Julian, > In my nightly report at 4 AM last night, the cache hit rate > was 72%. Wowee! > > With the HighRes timings, I use that information to compute how > long batches take, and some statistics. From yesterday: > > ===Mailscanner Summaries: > Total messages scanned: 28180 > Total Message Batches: 20368 > Average Messages per Batch: 1.38 > Minimum Batch Time (sec): 2.57 > Maximum Batch Time (sec): 185.12 > Average Batch Time (sec): 8.45 > Total MBytes scanned: 1011.47 > Total virii detected: 31 > Total spams tagged: 4702 > Total spams delivered: 1679 > Total spams deleted: 3274 > > The batch timing gives a good overall clue as to the speed/efficiency > of one's system. Thanks! > > Jeff Earickson > Colby College From drew at themarshalls.co.uk Tue Jan 24 02:22:26 2006 From: drew at themarshalls.co.uk (Drew Marshall) Date: Tue Jan 24 02:22:38 2006 Subject: switching from dual queue to single queue with postfix In-Reply-To: <200601271259.EAA25759@sheridan.sibble.net> References: <200601271259.EAA25759@sheridan.sibble.net> Message-ID: <63468B53-81D4-4595-B492-54DB53A2FCED@themarshalls.co.uk> On 24 Jan 2006, at 01:34, Harondel J. Sibble wrote: > I remember there being a MAQ entry for switching from dual queue to > single > queue mode with postfix, however I can't seem to find that info. > > I have found the instructions for setting up the single queue > method for a > new install, but not for migrating. I remember there was lot of > discussion > on the list when this new method came about but so far so I haven't > found the > answer I need at the searchable list archives in gmane, can someone > point me > in the right direction? It's fairly simple really. Stop the incoming Postfix instance Check mailq to ensure all the mail has been cleared from the mail queue. Then stop Postfix.in and MailScanner Set up your current postfix directory in line with the set up docs (Pay attention to any smtpd_ lines you have in /postfix.in/main.cf and make sure you have copied them over) Amend MailScanner.conf as per the instructions When you are happy, fire up just the new Postfix single instance and put a test message through to ensure it's being held correctly, then fire up MailScanner. I don't think I have missed anything but it's been a wile since I have played with a dual set up :-) Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy From drew at themarshalls.co.uk Tue Jan 24 02:32:00 2006 From: drew at themarshalls.co.uk (Drew Marshall) Date: Tue Jan 24 02:32:06 2006 Subject: Bad free() ignored (PERL_CORE) Message-ID: <86740C53-53EB-407D-9823-DF3FA4B40FFA@themarshalls.co.uk> Hi All I think I should be concerned by this. Anyone have any ideas as to what could be causing it? Bad free() ignored (PERL_CORE) during global destruction. Ignore errors about failing to find EOCD signature Bad free() ignored (PERL_CORE) during global destruction. Bad free() ignored (PERL_CORE) during global destruction. This came from the end of running MS in debug mode and SA debug. When I checked I also had a shed load of TNEF directories living in / tmp which I just deleted. Why do I suspect these are related...? OS - FreeBSD 6 (All items installed from Ports tree) Perl - 5.8.7 MTA - Postfix MailScanner - 4.49.7 Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. www.themarshalls.co.uk/policy From brose at med.wayne.edu Tue Jan 24 04:14:37 2006 From: brose at med.wayne.edu (Rose, Bobby) Date: Tue Jan 24 04:14:42 2006 Subject: RDNS Message-ID: <8F2A53954C22554EB75D9643FCCE0C6B8880@MED-CORE03-MS1.med.wayne.edu> >From the http://www.sendmail.org/tips/relaying.html FEATURE(accept_unresolvable_domains). Normally, sendmail will refuse to accept mail that has a return address with a domain that cannot be resolved using the regular host lookups (a technique commonly used by spammers). This feature permits acceptance of such addresses. Unresolvable domains can be selectively accepted using the access database. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Stephen Swaney Sent: Monday, January 23, 2006 6:33 PM To: 'MailScanner discussion' Subject: RE: RDNS > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Rose, Bobby > Sent: Monday, January 23, 2006 6:24 PM > To: MailScanner discussion > Cc: mailscanner-announce@lists.mailscanner.info > Subject: RE: RDNS > > I thought that it was a default action in sendmail to not accept from > unresolvable hosts and in setting > FEATURE(`accept_unresolvable_domains')dnl you are actually disabling > so that it does accept from unresolvable hosts. > Nope :( Steve Stephen Swaney Fort Systems Ltd. stephen.swaney@fsl.com www.fsl.com > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Matt > Kettler > Sent: Monday, January 23, 2006 5:42 PM > To: MailScanner discussion > Cc: mailscanner-announce@lists.mailscanner.info > Subject: Re: RDNS > > Darryl DeLao wrote: > > Is there a way to turn on RDNS in Mailscanner, or is this done in > > Sendmail? If so, how is it done? Basically, if an email comes in > > and > > > the originating domain can not be resolved, I do not want to accept > > the email in the system. > > Well, MailScanner can't ever prevent any email from being accepted. > MailScanner acts on the queue files, so by the time MS sees it, it's > long since been accepted. > > > However, the feature you want is a standard sendmail feature. Look up > the "accept_unresolvable_domains" feature, and disable it. > > If you're using m4 to build your sendmail.cf (highly recommended > unless you're a sendmail master) > > edit /etc/mail/sendmail.mc > > add a "dnl" to the start of the feature line, line this: > > dnl FEATURE(`accept_unresolvable_domains')dnl > > rebuild your sendmail.cf by running make in the /etc/mail directory > > restart your MailScanner service to restart the sendmail's. > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From nilesh.shastrakar at gmail.com Tue Jan 24 06:09:31 2006 From: nilesh.shastrakar at gmail.com (Nilesh Shastrakar) Date: Tue Jan 24 06:09:33 2006 Subject: weird priblems with server In-Reply-To: <223f97700601222305gedf0a38v@mail.gmail.com> References: <95873e560601222145o384b0123me1909f33318c2950@mail.gmail.com> <223f97700601222305gedf0a38v@mail.gmail.com> Message-ID: <95873e560601232209s5db78e73j9ef63bbc79f25cb1@mail.gmail.com> Thanks everybody for replying me, I have checked the mailogs but confused I found from address and ctladdr is different is my server is hacked or its a virus problem on ther server but I am using Fedora 4, Sendmail, MailScanner and Clamav how my server infect with virus. is there easy way to find out what was the problem. Regards Nilesh. On 1/23/06, Glenn Steen wrote: > > On 23/01/06, Nilesh Shastrakar wrote: > > Hello, > > > > Today I am facing some weird problem with my mail server. > > some mails I have received which is not maked to me in To,CC,or in BCC, > > > I personally phone called to users who sent mail to me and asked about > that > > mail but he said > > he has not send me that mail, the mail contains some confedential > > containts, also same problem happend with other users. > > could any one please help me how to fix this problem or tell me what > would > > be the reason. > > also I have checked its not a spam mail. it is send to other users but I > got > > it. > > > > > > I am using > > > > Fedora Core 4 with Kernel 2.6.14 > > Senamil 8.13.4-2 > > MailScanner 4-45.4-1 > > Spamassassin-3.0.4-2 > > Clamav 0.87 > > > > regards > > Nilesh > > > Well, have you checked your mail log that the _envelope_ recipient > doesn't differ from the things in the headers? > It is very common for these to differ, and it is just the envelope > ones that matter... These are the ones used during the (E)SMTP > conversation (the "RCPT TO: < add@re.ss>" thingies). > It is quite "normal" for spam, viruses and even normal mails to be > forged in this way. > > Or had you already looked at this...? > > If you run MailWatch, that will log the mails with the envelope > sender/recipients....;) > > Cheers > -- > -- Glenn > email: glenn < dot > steen < at > gmail < dot > com > work: glenn < dot > steen < at > ap1 < dot > se > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060124/7fea2b3e/attachment.html From MailScanner at ecs.soton.ac.uk Tue Jan 24 09:05:22 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Jan 24 09:05:36 2006 Subject: Old Sys::Hostname::Long In-Reply-To: <570A16F7DB56C242B26876067D682FD001E6D5BD@TORMAIL.algorithmics.com> References: <570A16F7DB56C242B26876067D682FD001E6D5BD@TORMAIL.algorithmics.com> Message-ID: <2AE85C0B-98FA-4069-A828-F7949140723C@ecs.soton.ac.uk> Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: PGP.sig Type: application/pgp-signature Size: 487 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060124/ff03433b/PGP.bin From glenn.steen at gmail.com Tue Jan 24 09:13:14 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue Jan 24 09:13:21 2006 Subject: weird priblems with server In-Reply-To: <95873e560601232209s5db78e73j9ef63bbc79f25cb1@mail.gmail.com> References: <95873e560601222145o384b0123me1909f33318c2950@mail.gmail.com> <223f97700601222305gedf0a38v@mail.gmail.com> <95873e560601232209s5db78e73j9ef63bbc79f25cb1@mail.gmail.com> Message-ID: <223f97700601240113t3412a1f8o@mail.gmail.com> On 24/01/06, Nilesh Shastrakar wrote: > Thanks everybody for replying me, > > I have checked the mailogs but confused I found from address and ctladdr is > different > is my server is hacked or its a virus problem on ther server > but I am using Fedora 4, Sendmail, MailScanner and Clamav how my server > infect with virus. > is there easy way to find out what was the problem. > > > Regards > Nilesh. Hi Nilesh, I'm not 100% sure I decipher what you eman correctly... Could you post some examples from your log, and possibly some headers too... We'll help you try to make sense of them;). -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From martinh at solid-state-logic.com Tue Jan 24 08:53:41 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Tue Jan 24 09:25:26 2006 Subject: MS 4.50: way cool... In-Reply-To: <43D587E0.2020403@enitech.com.au> Message-ID: <003301c620c3$aec0a490$3004010a@martinhlaptop> Peter In 4.50.5 (I think it first appeared in that beta) there's a script in the bin directory called "analyse_spamassassin_cache" -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Peter Russell > Sent: 24 January 2006 01:50 > To: MailScanner discussion > Subject: Re: MS 4.50: way cool... > > How did you do this report? > > > > > Jeff A. Earickson wrote: > > Julian, > > In my nightly report at 4 AM last night, the cache hit rate > > was 72%. Wowee! > > > > With the HighRes timings, I use that information to compute how > > long batches take, and some statistics. From yesterday: > > > > ===Mailscanner Summaries: > > Total messages scanned: 28180 > > Total Message Batches: 20368 > > Average Messages per Batch: 1.38 > > Minimum Batch Time (sec): 2.57 > > Maximum Batch Time (sec): 185.12 > > Average Batch Time (sec): 8.45 > > Total MBytes scanned: 1011.47 > > Total virii detected: 31 > > Total spams tagged: 4702 > > Total spams delivered: 1679 > > Total spams deleted: 3274 > > > > The batch timing gives a good overall clue as to the speed/efficiency > > of one's system. Thanks! > > > > Jeff Earickson > > Colby College > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From joost at waversveld.nl Tue Jan 24 10:57:52 2006 From: joost at waversveld.nl (Joost Waversveld) Date: Tue Jan 24 10:56:48 2006 Subject: MS 4.50: way cool... In-Reply-To: <003301c620c3$aec0a490$3004010a@martinhlaptop> References: <003301c620c3$aec0a490$3004010a@martinhlaptop> Message-ID: <20060124115752.80ejlddpzc40k08o@dev.waversveld.nl> I ran Version 4.50.8 for a while, I saw the timings in the maillog. When I saw this post, I thought "Cool, that's a nice feature!". I tried it and I did not saw the timings. The output of analyse_SpamAssassin_cache was: ============================================================= [root@server MailScanner]# analyse_SpamAssassin_cache --------- TOTALS --------- Total records: 42 First seen (oldest): 137447 sec First seen (newest): 309 sec Last seen (oldest): 137447 sec Last seen (newest): 309 sec Cache Hit Rate 4% -------- NON-SPAM -------- Total records: 4 First seen (oldest): 1587 sec First seen (newest): 1345 sec Last seen (oldest): 1587 sec Last seen (newest): 1345 sec -------- LOW-SPAM -------- Total records: 0 First seen (oldest): 0 sec First seen (newest): 0 sec Last seen (oldest): 0 sec Last seen (newest): 0 sec ------- HIGH-SPAM -------- Total records: 27 First seen (oldest): 10793 sec First seen (newest): 309 sec Last seen (oldest): 10793 sec Last seen (newest): 309 sec -------- VIRUSES -------- Total records: 11 First seen (oldest): 137447 sec First seen (newest): 3896 sec Last seen (oldest): 137447 sec Last seen (newest): 3896 sec ----- TOP 5 HASHES ------- MD5 COUNT FIRST LAST 4241bc4eef8c5c2ed34c112b2401397d 2 8005 1754 12bc9faf120bea4712776cabfbeca4a5 2 5363 5356 ============================================================= I was disappointed, but decided to install the latest BETA available on mailscanner.info. Maybe it was an newer version. But after the upgrade I still see the same output from this command. I do not see the timings. What am I doing wrong?? Best regards, Joost Waversveld ----- Message from martinh@solid-state-logic.com --------- Date: Tue, 24 Jan 2006 08:53:41 -0000 From: Martin Hepworth Reply-To: MailScanner discussion Subject: RE: MS 4.50: way cool... To: 'MailScanner discussion' > Peter > > In 4.50.5 (I think it first appeared in that beta) there's a script in the > bin directory called "analyse_spamassassin_cache" > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Peter Russell >> Sent: 24 January 2006 01:50 >> To: MailScanner discussion >> Subject: Re: MS 4.50: way cool... >> >> How did you do this report? >> >> >> >> >> Jeff A. Earickson wrote: >> > Julian, >> > In my nightly report at 4 AM last night, the cache hit rate >> > was 72%. Wowee! >> > >> > With the HighRes timings, I use that information to compute how >> > long batches take, and some statistics. From yesterday: >> > >> > ===Mailscanner Summaries: >> > Total messages scanned: 28180 >> > Total Message Batches: 20368 >> > Average Messages per Batch: 1.38 >> > Minimum Batch Time (sec): 2.57 >> > Maximum Batch Time (sec): 185.12 >> > Average Batch Time (sec): 8.45 >> > Total MBytes scanned: 1011.47 >> > Total virii detected: 31 >> > Total spams tagged: 4702 >> > Total spams delivered: 1679 >> > Total spams deleted: 3274 >> > >> > The batch timing gives a good overall clue as to the speed/efficiency >> > of one's system. Thanks! >> > >> > Jeff Earickson >> > Colby College >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > > ********************************************************************** > > This email and any files transmitted with it are confidential and > intended solely for the use of the individual or entity to whom they > are addressed. If you have received this email in error please notify > the system manager. > > This footnote confirms that this email message has been swept > for the presence of computer viruses and is believed to be clean. > > ********************************************************************** > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > ----- End message from martinh@solid-state-logic.com ----- From martinh at solid-state-logic.com Tue Jan 24 11:10:00 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Tue Jan 24 11:10:08 2006 Subject: MS 4.50: way cool... In-Reply-To: <20060124115752.80ejlddpzc40k08o@dev.waversveld.nl> Message-ID: <008001c620d6$b7ed24e0$3004010a@martinhlaptop> Hmm Maybe jeff's got his own stats analysis engine (or runs vispan or something..) -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Joost Waversveld > Sent: 24 January 2006 10:58 > To: mailscanner@lists.mailscanner.info > Subject: RE: MS 4.50: way cool... > > I ran Version 4.50.8 for a while, I saw the timings in the maillog. > When I saw this post, > I thought "Cool, that's a nice feature!". I tried it and I did not saw > the timings. The > output of analyse_SpamAssassin_cache was: > > ============================================================= > > [root@server MailScanner]# analyse_SpamAssassin_cache --------- TOTALS > --------- > Total records: 42 > First seen (oldest): 137447 sec > First seen (newest): 309 sec > Last seen (oldest): 137447 sec > Last seen (newest): 309 sec > Cache Hit Rate 4% > -------- NON-SPAM -------- > Total records: 4 > First seen (oldest): 1587 sec > First seen (newest): 1345 sec > Last seen (oldest): 1587 sec > Last seen (newest): 1345 sec > -------- LOW-SPAM -------- > Total records: 0 > First seen (oldest): 0 sec > First seen (newest): 0 sec > Last seen (oldest): 0 sec > Last seen (newest): 0 sec > ------- HIGH-SPAM -------- > Total records: 27 > First seen (oldest): 10793 sec > First seen (newest): 309 sec > Last seen (oldest): 10793 sec > Last seen (newest): 309 sec > -------- VIRUSES -------- > Total records: 11 > First seen (oldest): 137447 sec > First seen (newest): 3896 sec > Last seen (oldest): 137447 sec > Last seen (newest): 3896 sec > ----- TOP 5 HASHES ------- > MD5 COUNT FIRST LAST > 4241bc4eef8c5c2ed34c112b2401397d 2 8005 1754 > 12bc9faf120bea4712776cabfbeca4a5 2 5363 5356 > ============================================================= > > I was disappointed, but decided to install the latest BETA available on > mailscanner.info. > Maybe it was an newer version. But after the upgrade I still see the > same output from > this command. I do not see the timings. > > What am I doing wrong?? > > Best regards, > > Joost Waversveld > > > ----- Message from martinh@solid-state-logic.com --------- > Date: Tue, 24 Jan 2006 08:53:41 -0000 > From: Martin Hepworth > Reply-To: MailScanner discussion > Subject: RE: MS 4.50: way cool... > To: 'MailScanner discussion' > > > > Peter > > > > In 4.50.5 (I think it first appeared in that beta) there's a script in > the > > bin directory called "analyse_spamassassin_cache" > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > >> -----Original Message----- > >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > >> bounces@lists.mailscanner.info] On Behalf Of Peter Russell > >> Sent: 24 January 2006 01:50 > >> To: MailScanner discussion > >> Subject: Re: MS 4.50: way cool... > >> > >> How did you do this report? > >> > >> > >> > >> > >> Jeff A. Earickson wrote: > >> > Julian, > >> > In my nightly report at 4 AM last night, the cache hit rate > >> > was 72%. Wowee! > >> > > >> > With the HighRes timings, I use that information to compute how > >> > long batches take, and some statistics. From yesterday: > >> > > >> > ===Mailscanner Summaries: > >> > Total messages scanned: 28180 > >> > Total Message Batches: 20368 > >> > Average Messages per Batch: 1.38 > >> > Minimum Batch Time (sec): 2.57 > >> > Maximum Batch Time (sec): 185.12 > >> > Average Batch Time (sec): 8.45 > >> > Total MBytes scanned: 1011.47 > >> > Total virii detected: 31 > >> > Total spams tagged: 4702 > >> > Total spams delivered: 1679 > >> > Total spams deleted: 3274 > >> > > >> > The batch timing gives a good overall clue as to the speed/efficiency > >> > of one's system. Thanks! > >> > > >> > Jeff Earickson > >> > Colby College > >> -- > >> MailScanner mailing list > >> MailScanner@lists.mailscanner.info > >> http://lists.mailscanner.info/mailman/listinfo/mailscanner > >> > >> Before posting, read http://wiki.mailscanner.info/posting > >> > >> Support MailScanner development - buy the book off the website! > > > > > > ********************************************************************** > > > > This email and any files transmitted with it are confidential and > > intended solely for the use of the individual or entity to whom they > > are addressed. If you have received this email in error please notify > > the system manager. > > > > This footnote confirms that this email message has been swept > > for the presence of computer viruses and is believed to be clean. > > > > ********************************************************************** > > > > -- > > MailScanner mailing list > > MailScanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > ----- End message from martinh@solid-state-logic.com ----- > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From Anjana.Patel at Cranfield.ac.uk Tue Jan 24 11:53:07 2006 From: Anjana.Patel at Cranfield.ac.uk (Patel, Anjana) Date: Tue Jan 24 11:53:20 2006 Subject: phishing detection not working? Message-ID: <56D9735674D05043AFC1E97F1CD49AF601CD3565@ccexchange-2.cns.cranfield.ac.uk> Hello, I'm having problems getting the phishing detection to work. I've noticed from the mailing list archives that a couple of other people also had the same problem but I didn't see a resolution. I've upgraded Mailscanner to the latest stable (4.49.7) but after several tests it appears that the phishing detection is still not working. It had also failed to work in version 4.47.4. The maillog shows that the phishing whitelist is being read: "Read 701 hostnames from the phishing whitelist" Here are the relevant paramaters: Dangerous Content Scanning = yes Find Phishing Fraud = yes Also Find Numeric Phishing = yes Highlight Phishing Fraud = yes Phishing Safe Sites File = %etc-dir%/phishing.safe.sites.conf Phishing Modify Subject = yes Phishing Subject Text = {FRAUD?} ./MailScanner --version Running on Linux mailgate-1 2.6.9-11.ELsmp #1 SMP Fri May 20 18:26:27 EDT 2005 i686 i686 i386 GNU/Linux This is Red Hat Enterprise Linux AS release 4 (Nahant Update 2) This is Perl version 5.008005 (5.8.5) This is MailScanner version 4.49.7 Module versions are: 1.00 AnyDBM_File 1.16 Archive::Zip 1.03 Carp 1.119 Convert::BinHex 1.00 DirHandle 1.05 Fcntl 2.73 File::Basename 2.08 File::Copy 2.01 FileHandle 1.06 File::Path 0.16 File::Temp 1.32 HTML::Entities 3.48 HTML::Parser 2.35 HTML::TokeParser 1.21 IO 1.10 IO::File 1.123 IO::Pipe 1.71 Mail::Header 3.07 MIME::Base64 5.419 MIME::Decoder 5.419 MIME::Decoder::UU 5.419 MIME::Head 5.419 MIME::Parser 3.07 MIME::QuotedPrint 5.419 MIME::Tools 0.11 Net::CIDR 1.08 POSIX 1.77 Socket 0.08 Sys::Syslog 1.02 Time::localtime Optional module versions are: 0.17 Convert::TNEF 1.809 DB_File 1.08 Digest 1.01 Digest::HMAC 2.33 Digest::MD5 2.07 Digest::SHA1 0.44 Inline 0.17 Mail::ClamAV 3.001000 Mail::SpamAssassin missing Mail::SPF::Query missing Net::CIDR::Lite 0.55 Net::DNS 0.31 Net::LDAP 1.94 Parse::RecDescent missing SAVI missing Sys::Hostname::Long 2.42 Test::Harness 0.47 Test::Simple 1.95 Text::Balanced 1.30 URI I don't think the settings for these are relevant but I have included them as extra information Allow IFrame Tags = yes Allow Form Tags = yes Allow Script Tags = yes Allow WebBugs = yes Allow Object Codebase Tags = yes Convert Dangerous HTML To Text = no Any advice would be appreciated. Thanks Anjana From MailScanner at ecs.soton.ac.uk Tue Jan 24 12:03:26 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Jan 24 12:03:37 2006 Subject: phishing detection not working? In-Reply-To: <56D9735674D05043AFC1E97F1CD49AF601CD3565@ccexchange-2.cns.cranfield.ac.uk> References: <56D9735674D05043AFC1E97F1CD49AF601CD3565@ccexchange-2.cns.cranfield.ac.uk> Message-ID: <1510D4E0-0E29-4CA5-9087-EACC3444BA44@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- This is fixed in 4.50. Sorry, I missed putting it in the Change Log. For now, just set one of the dangerous content checks to disarm or no. Then it will work again. On 24 Jan 2006, at 11:53, Patel, Anjana wrote: > > Hello, > > I'm having problems getting the phishing detection to work. I've > noticed from the mailing list archives that a couple of other people > also had the same problem but I didn't see a resolution. > > I've upgraded Mailscanner to the latest stable (4.49.7) but after > several tests it appears that the phishing detection is still not > working. It had also failed to work in version 4.47.4. > > The maillog shows that the phishing whitelist is being read: > > "Read 701 hostnames from the phishing whitelist" > > Here are the relevant paramaters: > > Dangerous Content Scanning = yes > Find Phishing Fraud = yes > Also Find Numeric Phishing = yes > Highlight Phishing Fraud = yes > Phishing Safe Sites File = %etc-dir%/phishing.safe.sites.conf > Phishing Modify Subject = yes > Phishing Subject Text = {FRAUD?} > > > ./MailScanner --version > Running on > Linux mailgate-1 2.6.9-11.ELsmp #1 SMP Fri May 20 18:26:27 EDT 2005 > i686 > i686 i386 GNU/Linux > This is Red Hat Enterprise Linux AS release 4 (Nahant Update 2) > This is Perl version 5.008005 (5.8.5) > > This is MailScanner version 4.49.7 > Module versions are: > 1.00 AnyDBM_File > 1.16 Archive::Zip > 1.03 Carp > 1.119 Convert::BinHex > 1.00 DirHandle > 1.05 Fcntl > 2.73 File::Basename > 2.08 File::Copy > 2.01 FileHandle > 1.06 File::Path > 0.16 File::Temp > 1.32 HTML::Entities > 3.48 HTML::Parser > 2.35 HTML::TokeParser > 1.21 IO > 1.10 IO::File > 1.123 IO::Pipe > 1.71 Mail::Header > 3.07 MIME::Base64 > 5.419 MIME::Decoder > 5.419 MIME::Decoder::UU > 5.419 MIME::Head > 5.419 MIME::Parser > 3.07 MIME::QuotedPrint > 5.419 MIME::Tools > 0.11 Net::CIDR > 1.08 POSIX > 1.77 Socket > 0.08 Sys::Syslog > 1.02 Time::localtime > > Optional module versions are: > 0.17 Convert::TNEF > 1.809 DB_File > 1.08 Digest > 1.01 Digest::HMAC > 2.33 Digest::MD5 > 2.07 Digest::SHA1 > 0.44 Inline > 0.17 Mail::ClamAV > 3.001000 Mail::SpamAssassin > missing Mail::SPF::Query > missing Net::CIDR::Lite > 0.55 Net::DNS > 0.31 Net::LDAP > 1.94 Parse::RecDescent > missing SAVI > missing Sys::Hostname::Long > 2.42 Test::Harness > 0.47 Test::Simple > 1.95 Text::Balanced > 1.30 URI > > > I don't think the settings for these are relevant but I have included > them as extra information > > Allow IFrame Tags = yes > Allow Form Tags = yes > Allow Script Tags = yes > Allow WebBugs = yes > Allow Object Codebase Tags = yes > Convert Dangerous HTML To Text = no > > > Any advice would be appreciated. > > Thanks > Anjana > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ9YXkPw32o+k+q+hAQGRkQgAvDuTutHCZMwNg9k/1qwxqc9DpUscAosJ wX78IG6xpYS3aD6ojFt4BFaXovVrhQfpRuLvx1wzOFRi0MtjVmf8dJ+Sp56Rsquw IJxng6/pGeJZROe8bLNK/S6tBWS32CpgNIAQVY57NntJ5e8u/2SPiRMSgZaiEsyC vL7vjQ1P+L0Ltvq0daC73OlXTd/YQFBca5g9WDOK5pp2Uso1S9v1iCenMUU9p0hj kGiAnBzTKAADWA1/OE7IqiRBFkn2OCwnRlXW38UtH95Qn2s77Sy/WSdAc6ieIJs+ TSMuGT3UKlYAnj3fqOIaPVv+3oPfZV5DmFZoqdB+Q9YqNKo737uILw== =bJW0 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From tenderby at mailwash.com.au Tue Jan 24 12:12:07 2006 From: tenderby at mailwash.com.au (Tony Enderby) Date: Tue Jan 24 12:12:18 2006 Subject: phishing detection not working? In-Reply-To: <56D9735674D05043AFC1E97F1CD49AF601CD3565@ccexchange-2.cns.cranfield.ac.uk> Message-ID: <7aa5cesw.1138104727.1581920.tenderby@mailwash.com.au> Hi there, This is interesting, I have been using MailScanner for about a year and have installed all major releases and betas and phishing detection has never worked until I installed Beta 4.50.9 at which stage it magically started working! So I'm not sure if it was a repackaged module in the distribution or whether I had installed something else during a version change window which the phishing code needed. My OS is FC3. On 1/24/2006, "Patel, Anjana" wrote: > >Hello, > >I'm having problems getting the phishing detection to work. I've >noticed from the mailing list archives that a couple of other people >also had the same problem but I didn't see a resolution. > >I've upgraded Mailscanner to the latest stable (4.49.7) but after >several tests it appears that the phishing detection is still not >working. It had also failed to work in version 4.47.4. > >The maillog shows that the phishing whitelist is being read: > > "Read 701 hostnames from the phishing whitelist" > >Here are the relevant paramaters: > >Dangerous Content Scanning = yes >Find Phishing Fraud = yes >Also Find Numeric Phishing = yes >Highlight Phishing Fraud = yes >Phishing Safe Sites File = %etc-dir%/phishing.safe.sites.conf >Phishing Modify Subject = yes >Phishing Subject Text = {FRAUD?} > > >./MailScanner --version >Running on >Linux mailgate-1 2.6.9-11.ELsmp #1 SMP Fri May 20 18:26:27 EDT 2005 i686 >i686 i386 GNU/Linux >This is Red Hat Enterprise Linux AS release 4 (Nahant Update 2) >This is Perl version 5.008005 (5.8.5) > >This is MailScanner version 4.49.7 >Module versions are: >1.00 AnyDBM_File >1.16 Archive::Zip >1.03 Carp >1.119 Convert::BinHex >1.00 DirHandle >1.05 Fcntl >2.73 File::Basename >2.08 File::Copy >2.01 FileHandle >1.06 File::Path >0.16 File::Temp >1.32 HTML::Entities >3.48 HTML::Parser >2.35 HTML::TokeParser >1.21 IO >1.10 IO::File >1.123 IO::Pipe >1.71 Mail::Header >3.07 MIME::Base64 >5.419 MIME::Decoder >5.419 MIME::Decoder::UU >5.419 MIME::Head >5.419 MIME::Parser >3.07 MIME::QuotedPrint >5.419 MIME::Tools >0.11 Net::CIDR >1.08 POSIX >1.77 Socket >0.08 Sys::Syslog >1.02 Time::localtime > >Optional module versions are: >0.17 Convert::TNEF >1.809 DB_File >1.08 Digest >1.01 Digest::HMAC >2.33 Digest::MD5 >2.07 Digest::SHA1 >0.44 Inline >0.17 Mail::ClamAV >3.001000 Mail::SpamAssassin >missing Mail::SPF::Query >missing Net::CIDR::Lite >0.55 Net::DNS >0.31 Net::LDAP >1.94 Parse::RecDescent >missing SAVI >missing Sys::Hostname::Long >2.42 Test::Harness >0.47 Test::Simple >1.95 Text::Balanced >1.30 URI > > >I don't think the settings for these are relevant but I have included >them as extra information > >Allow IFrame Tags = yes >Allow Form Tags = yes >Allow Script Tags = yes >Allow WebBugs = yes >Allow Object Codebase Tags = yes >Convert Dangerous HTML To Text = no > > >Any advice would be appreciated. > >Thanks >Anjana > >-- >MailScanner mailing list >MailScanner@lists.mailscanner.info >http://lists.mailscanner.info/mailman/listinfo/mailscanner > >Before posting, read http://wiki.mailscanner.info/posting > >Support MailScanner development - buy the book off the website! > >----------------------------------------------------------------------------------- >Scanned by MailWash Australia - http://www.mailwash.com.au >----------------------------------------------------------------------------------- > ----------------------------------------------------------------------------------- Scanned by MailWash Australia - http://www.mailwash.com.au ----------------------------------------------------------------------------------- From tenderby at mailwash.com.au Tue Jan 24 12:17:18 2006 From: tenderby at mailwash.com.au (Tony Enderby) Date: Tue Jan 24 12:17:27 2006 Subject: phishing detection not working? In-Reply-To: <1510D4E0-0E29-4CA5-9087-EACC3444BA44@ecs.soton.ac.uk> Message-ID: Oops, it wasn't magic .. thanks Julian =) On 1/24/2006, "Julian Field" wrote: >-----BEGIN PGP SIGNED MESSAGE----- > >This is fixed in 4.50. Sorry, I missed putting it in the Change Log. >For now, just set one of the dangerous content checks to disarm or no. >Then it will work again. > >On 24 Jan 2006, at 11:53, Patel, Anjana wrote: > >> >> Hello, >> >> I'm having problems getting the phishing detection to work. I've >> noticed from the mailing list archives that a couple of other people >> also had the same problem but I didn't see a resolution. >> >> I've upgraded Mailscanner to the latest stable (4.49.7) but after >> several tests it appears that the phishing detection is still not >> working. It had also failed to work in version 4.47.4. >> >> The maillog shows that the phishing whitelist is being read: >> >> "Read 701 hostnames from the phishing whitelist" >> >> Here are the relevant paramaters: >> >> Dangerous Content Scanning = yes >> Find Phishing Fraud = yes >> Also Find Numeric Phishing = yes >> Highlight Phishing Fraud = yes >> Phishing Safe Sites File = %etc-dir%/phishing.safe.sites.conf >> Phishing Modify Subject = yes >> Phishing Subject Text = {FRAUD?} >> >> >> ./MailScanner --version >> Running on >> Linux mailgate-1 2.6.9-11.ELsmp #1 SMP Fri May 20 18:26:27 EDT 2005 >> i686 >> i686 i386 GNU/Linux >> This is Red Hat Enterprise Linux AS release 4 (Nahant Update 2) >> This is Perl version 5.008005 (5.8.5) >> >> This is MailScanner version 4.49.7 >> Module versions are: >> 1.00 AnyDBM_File >> 1.16 Archive::Zip >> 1.03 Carp >> 1.119 Convert::BinHex >> 1.00 DirHandle >> 1.05 Fcntl >> 2.73 File::Basename >> 2.08 File::Copy >> 2.01 FileHandle >> 1.06 File::Path >> 0.16 File::Temp >> 1.32 HTML::Entities >> 3.48 HTML::Parser >> 2.35 HTML::TokeParser >> 1.21 IO >> 1.10 IO::File >> 1.123 IO::Pipe >> 1.71 Mail::Header >> 3.07 MIME::Base64 >> 5.419 MIME::Decoder >> 5.419 MIME::Decoder::UU >> 5.419 MIME::Head >> 5.419 MIME::Parser >> 3.07 MIME::QuotedPrint >> 5.419 MIME::Tools >> 0.11 Net::CIDR >> 1.08 POSIX >> 1.77 Socket >> 0.08 Sys::Syslog >> 1.02 Time::localtime >> >> Optional module versions are: >> 0.17 Convert::TNEF >> 1.809 DB_File >> 1.08 Digest >> 1.01 Digest::HMAC >> 2.33 Digest::MD5 >> 2.07 Digest::SHA1 >> 0.44 Inline >> 0.17 Mail::ClamAV >> 3.001000 Mail::SpamAssassin >> missing Mail::SPF::Query >> missing Net::CIDR::Lite >> 0.55 Net::DNS >> 0.31 Net::LDAP >> 1.94 Parse::RecDescent >> missing SAVI >> missing Sys::Hostname::Long >> 2.42 Test::Harness >> 0.47 Test::Simple >> 1.95 Text::Balanced >> 1.30 URI >> >> >> I don't think the settings for these are relevant but I have included >> them as extra information >> >> Allow IFrame Tags = yes >> Allow Form Tags = yes >> Allow Script Tags = yes >> Allow WebBugs = yes >> Allow Object Codebase Tags = yes >> Convert Dangerous HTML To Text = no >> >> >> Any advice would be appreciated. >> >> Thanks >> Anjana >> >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > >- -- >Julian Field >www.MailScanner.info >Buy the MailScanner book at www.MailScanner.info/store >PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > >-----BEGIN PGP SIGNATURE----- >Version: PGP Desktop 9.0.4 (Build 4042) > >iQEVAwUBQ9YXkPw32o+k+q+hAQGRkQgAvDuTutHCZMwNg9k/1qwxqc9DpUscAosJ >wX78IG6xpYS3aD6ojFt4BFaXovVrhQfpRuLvx1wzOFRi0MtjVmf8dJ+Sp56Rsquw >IJxng6/pGeJZROe8bLNK/S6tBWS32CpgNIAQVY57NntJ5e8u/2SPiRMSgZaiEsyC >vL7vjQ1P+L0Ltvq0daC73OlXTd/YQFBca5g9WDOK5pp2Uso1S9v1iCenMUU9p0hj >kGiAnBzTKAADWA1/OE7IqiRBFkn2OCwnRlXW38UtH95Qn2s77Sy/WSdAc6ieIJs+ >TSMuGT3UKlYAnj3fqOIaPVv+3oPfZV5DmFZoqdB+Q9YqNKo737uILw== >=bJW0 >-----END PGP SIGNATURE----- > >-- >This message has been scanned for viruses and >dangerous content by MailScanner, and is >believed to be clean. > >-- >MailScanner mailing list >MailScanner@lists.mailscanner.info >http://lists.mailscanner.info/mailman/listinfo/mailscanner > >Before posting, read http://wiki.mailscanner.info/posting > >Support MailScanner development - buy the book off the website! > >----------------------------------------------------------------------------------- >Scanned by MailWash Australia - http://www.mailwash.com.au >----------------------------------------------------------------------------------- ----------------------------------------------------------------------------------- Scanned by MailWash Australia - http://www.mailwash.com.au ----------------------------------------------------------------------------------- From MailScanner at ecs.soton.ac.uk Tue Jan 24 12:20:40 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Jan 24 12:21:06 2006 Subject: phishing detection not working? In-Reply-To: <7aa5cesw.1138104727.1581920.tenderby@mailwash.com.au> References: <7aa5cesw.1138104727.1581920.tenderby@mailwash.com.au> Message-ID: <24B9EEDB-C6E9-4503-9BE6-284583301243@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Before 4.50, if you had all the "Dangerous Content" checks set to "yes" (i.e. allow everything) then the phishing net would be disabled too. I have now fixed this problem, as it was only first reported to me earlier this month, with enough information that I could actually find the problem. The latest betas of 4.50 work just fine, I have them in production use on several systems, and am having no problems at all. On 24 Jan 2006, at 12:12, Tony Enderby wrote: > > Hi there, > > This is interesting, I have been using MailScanner for about a year > and > have installed all major releases and betas and phishing detection has > never worked until I installed Beta 4.50.9 at which stage it magically > started working! > > So I'm not sure if it was a repackaged module in the distribution or > whether I had installed something else during a version change window > which the phishing code needed. > > My OS is FC3. > > > > On 1/24/2006, "Patel, Anjana" wrote: > >> >> Hello, >> >> I'm having problems getting the phishing detection to work. I've >> noticed from the mailing list archives that a couple of other people >> also had the same problem but I didn't see a resolution. >> >> I've upgraded Mailscanner to the latest stable (4.49.7) but after >> several tests it appears that the phishing detection is still not >> working. It had also failed to work in version 4.47.4. >> >> The maillog shows that the phishing whitelist is being read: >> >> "Read 701 hostnames from the phishing whitelist" >> >> Here are the relevant paramaters: >> >> Dangerous Content Scanning = yes >> Find Phishing Fraud = yes >> Also Find Numeric Phishing = yes >> Highlight Phishing Fraud = yes >> Phishing Safe Sites File = %etc-dir%/phishing.safe.sites.conf >> Phishing Modify Subject = yes >> Phishing Subject Text = {FRAUD?} >> >> >> ./MailScanner --version >> Running on >> Linux mailgate-1 2.6.9-11.ELsmp #1 SMP Fri May 20 18:26:27 EDT >> 2005 i686 >> i686 i386 GNU/Linux >> This is Red Hat Enterprise Linux AS release 4 (Nahant Update 2) >> This is Perl version 5.008005 (5.8.5) >> >> This is MailScanner version 4.49.7 >> Module versions are: >> 1.00 AnyDBM_File >> 1.16 Archive::Zip >> 1.03 Carp >> 1.119 Convert::BinHex >> 1.00 DirHandle >> 1.05 Fcntl >> 2.73 File::Basename >> 2.08 File::Copy >> 2.01 FileHandle >> 1.06 File::Path >> 0.16 File::Temp >> 1.32 HTML::Entities >> 3.48 HTML::Parser >> 2.35 HTML::TokeParser >> 1.21 IO >> 1.10 IO::File >> 1.123 IO::Pipe >> 1.71 Mail::Header >> 3.07 MIME::Base64 >> 5.419 MIME::Decoder >> 5.419 MIME::Decoder::UU >> 5.419 MIME::Head >> 5.419 MIME::Parser >> 3.07 MIME::QuotedPrint >> 5.419 MIME::Tools >> 0.11 Net::CIDR >> 1.08 POSIX >> 1.77 Socket >> 0.08 Sys::Syslog >> 1.02 Time::localtime >> >> Optional module versions are: >> 0.17 Convert::TNEF >> 1.809 DB_File >> 1.08 Digest >> 1.01 Digest::HMAC >> 2.33 Digest::MD5 >> 2.07 Digest::SHA1 >> 0.44 Inline >> 0.17 Mail::ClamAV >> 3.001000 Mail::SpamAssassin >> missing Mail::SPF::Query >> missing Net::CIDR::Lite >> 0.55 Net::DNS >> 0.31 Net::LDAP >> 1.94 Parse::RecDescent >> missing SAVI >> missing Sys::Hostname::Long >> 2.42 Test::Harness >> 0.47 Test::Simple >> 1.95 Text::Balanced >> 1.30 URI >> >> >> I don't think the settings for these are relevant but I have included >> them as extra information >> >> Allow IFrame Tags = yes >> Allow Form Tags = yes >> Allow Script Tags = yes >> Allow WebBugs = yes >> Allow Object Codebase Tags = yes >> Convert Dangerous HTML To Text = no >> >> >> Any advice would be appreciated. >> >> Thanks >> Anjana >> >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >> --------------------------------------------------------------------- >> -------------- >> Scanned by MailWash Australia - http://www.mailwash.com.au >> --------------------------------------------------------------------- >> -------------- >> > > ---------------------------------------------------------------------- > ------------- > Scanned by MailWash Australia - http://www.mailwash.com.au > ---------------------------------------------------------------------- > ------------- > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ9Ybm/w32o+k+q+hAQF4cAf+Mxc2uxVcyD1hS/PNyrIh4s2tWuMy61ox K5GcML+b+xUPv/NTKcOGp0w5stCMobvAJrYs8KslifrZJlWkBDOCR+4OewUod3wB dGu9IUMy0S1v5qI7CR2XMN4k3nhKZrdlpcVPleBSKUHBO6dU482qWNu7eHIi0Lpw Dil1kZyY+y7Io22T4S+3+3hbqIBLFq4ex5Ft0BbSB+040OryAxN5UEPdHpyaKqrN 1mhZbarroFxYixhtLSgybLhKi1pIyQSXGuwdfyGVLcZwFEKa6NqS/OB0fBJBousi X5pQbgsHUQj1UfgKohCtxn3joGJrRjsdxTQyVr5AIfai8Qa5dX3sIA== =aPtD -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From jaearick at colby.edu Tue Jan 24 13:40:01 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Tue Jan 24 13:40:09 2006 Subject: MS 4.50: way cool... In-Reply-To: <008001c620d6$b7ed24e0$3004010a@martinhlaptop> References: <008001c620d6$b7ed24e0$3004010a@martinhlaptop> Message-ID: Gang, My perl script, or Julian's, or Peter Peters' script is attached. As you can see from the copyright comment at the top, those two cooked this script up long ago. Then I've been modifying it for my own environment over the years. The Batch timing stats were this month's addition due to HighRes. Note: syslogging on my systems sends *everything* to a single file: MailScanner logging, sendmail, the works. The script parses out sendmail and MS logging and analyzes the results. I hope it is useful. I really should get MailWatch or vispan going... Jeff Earickson Colby College On Tue, 24 Jan 2006, Martin Hepworth wrote: > Date: Tue, 24 Jan 2006 11:10:00 -0000 > From: Martin Hepworth > Reply-To: MailScanner discussion > To: 'MailScanner discussion' > Subject: RE: MS 4.50: way cool... > > Hmm > > Maybe jeff's got his own stats analysis engine (or runs vispan or > something..) > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Joost Waversveld >> Sent: 24 January 2006 10:58 >> To: mailscanner@lists.mailscanner.info >> Subject: RE: MS 4.50: way cool... >> >> I ran Version 4.50.8 for a while, I saw the timings in the maillog. >> When I saw this post, >> I thought "Cool, that's a nice feature!". I tried it and I did not saw >> the timings. The >> output of analyse_SpamAssassin_cache was: >> >> ============================================================= >> >> [root@server MailScanner]# analyse_SpamAssassin_cache --------- TOTALS >> --------- >> Total records: 42 >> First seen (oldest): 137447 sec >> First seen (newest): 309 sec >> Last seen (oldest): 137447 sec >> Last seen (newest): 309 sec >> Cache Hit Rate 4% >> -------- NON-SPAM -------- >> Total records: 4 >> First seen (oldest): 1587 sec >> First seen (newest): 1345 sec >> Last seen (oldest): 1587 sec >> Last seen (newest): 1345 sec >> -------- LOW-SPAM -------- >> Total records: 0 >> First seen (oldest): 0 sec >> First seen (newest): 0 sec >> Last seen (oldest): 0 sec >> Last seen (newest): 0 sec >> ------- HIGH-SPAM -------- >> Total records: 27 >> First seen (oldest): 10793 sec >> First seen (newest): 309 sec >> Last seen (oldest): 10793 sec >> Last seen (newest): 309 sec >> -------- VIRUSES -------- >> Total records: 11 >> First seen (oldest): 137447 sec >> First seen (newest): 3896 sec >> Last seen (oldest): 137447 sec >> Last seen (newest): 3896 sec >> ----- TOP 5 HASHES ------- >> MD5 COUNT FIRST LAST >> 4241bc4eef8c5c2ed34c112b2401397d 2 8005 1754 >> 12bc9faf120bea4712776cabfbeca4a5 2 5363 5356 >> ============================================================= >> >> I was disappointed, but decided to install the latest BETA available on >> mailscanner.info. >> Maybe it was an newer version. But after the upgrade I still see the >> same output from >> this command. I do not see the timings. >> >> What am I doing wrong?? >> >> Best regards, >> >> Joost Waversveld >> >> >> ----- Message from martinh@solid-state-logic.com --------- >> Date: Tue, 24 Jan 2006 08:53:41 -0000 >> From: Martin Hepworth >> Reply-To: MailScanner discussion >> Subject: RE: MS 4.50: way cool... >> To: 'MailScanner discussion' >> >> >>> Peter >>> >>> In 4.50.5 (I think it first appeared in that beta) there's a script in >> the >>> bin directory called "analyse_spamassassin_cache" >>> >>> -- >>> Martin Hepworth >>> Snr Systems Administrator >>> Solid State Logic >>> Tel: +44 (0)1865 842300 >>> >>>> -----Original Message----- >>>> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >>>> bounces@lists.mailscanner.info] On Behalf Of Peter Russell >>>> Sent: 24 January 2006 01:50 >>>> To: MailScanner discussion >>>> Subject: Re: MS 4.50: way cool... >>>> >>>> How did you do this report? >>>> >>>> >>>> >>>> >>>> Jeff A. Earickson wrote: >>>>> Julian, >>>>> In my nightly report at 4 AM last night, the cache hit rate >>>>> was 72%. Wowee! >>>>> >>>>> With the HighRes timings, I use that information to compute how >>>>> long batches take, and some statistics. From yesterday: >>>>> >>>>> ===Mailscanner Summaries: >>>>> Total messages scanned: 28180 >>>>> Total Message Batches: 20368 >>>>> Average Messages per Batch: 1.38 >>>>> Minimum Batch Time (sec): 2.57 >>>>> Maximum Batch Time (sec): 185.12 >>>>> Average Batch Time (sec): 8.45 >>>>> Total MBytes scanned: 1011.47 >>>>> Total virii detected: 31 >>>>> Total spams tagged: 4702 >>>>> Total spams delivered: 1679 >>>>> Total spams deleted: 3274 >>>>> >>>>> The batch timing gives a good overall clue as to the speed/efficiency >>>>> of one's system. Thanks! >>>>> >>>>> Jeff Earickson >>>>> Colby College >>>> -- >>>> MailScanner mailing list >>>> MailScanner@lists.mailscanner.info >>>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>>> >>>> Before posting, read http://wiki.mailscanner.info/posting >>>> >>>> Support MailScanner development - buy the book off the website! >>> >>> >>> ********************************************************************** >>> >>> This email and any files transmitted with it are confidential and >>> intended solely for the use of the individual or entity to whom they >>> are addressed. If you have received this email in error please notify >>> the system manager. >>> >>> This footnote confirms that this email message has been swept >>> for the presence of computer viruses and is believed to be clean. >>> >>> ********************************************************************** >>> >>> -- >>> MailScanner mailing list >>> MailScanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> >>> Before posting, read http://wiki.mailscanner.info/posting >>> >>> Support MailScanner development - buy the book off the website! >>> >> >> >> ----- End message from martinh@solid-state-logic.com ----- >> >> >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > > ********************************************************************** > > This email and any files transmitted with it are confidential and > intended solely for the use of the individual or entity to whom they > are addressed. If you have received this email in error please notify > the system manager. > > This footnote confirms that this email message has been swept > for the presence of computer viruses and is believed to be clean. > > ********************************************************************** > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- #!/usr/bin/perl # # Analog4MailScanner - Log Analyzer for MailScanner from Julian Field # Copyright (C) 2002 Peter Peters, universiteit Twente, # Enschede, The Netherlands # # Main program.... #unshift @INC, "/opt/mailscanner/bin"; #show only this number of viruses, 0 = all $limit = 20; $Logfile = "/var/adm/syslog/0"; $Logfile = $ARGV[0] if defined $ARGV[0]; # counters for sendmail $TotalMails = 0; $Discarded = 0; $REFUSED_mail_abuse = 0; $REFUSED_spamcop = 0; $REFUSED_spamhaus_sbl = 0; $REFUSED_spamhaus_xbl = 0; $REFUSED_relays_ordb = 0; $Connection_rate_limit = 0; $Too_many_connections = 0; $Banned_spam_domain = 0; $Banned_spam_IP = 0; $Banned_spammer = 0; $Pregreeting_punts = 0; #$Fix_reverse_DNS = 0; #$Does_not_resolve = 0; #$Possibly_forged = 0; #---counters for mailscanner $BatchCounter = 0; $MinBatchTime = 999999.0; $MaxBatchTime = 0.0; $TotalBatchTime = 0.0; $TotalMsgsScanned = 0; $TotalBytesScanned = 0; #$TotalSecondsScanned = 0; $TotalViruses = 0; $TotalSpam = 0; $TotalSpamsDeleted = 0; $TotalSpamsDelivered = 0; $TotalAssassin = 0; $TotalAssassinTimeouts = 0; $TotalAssassinScore = 0; $TotalSpamCop = 0; $TotalSpamHaus = 0; $TotalORDB_RBL = 0; $TotalCBL = 0; $TotalDSBL = 0; $TotalNJABL = 0; $TotalSBL_XBL = 0; if ($Logfile =~ /\.gz$/) { open(LOG, "zcat $Logfile |") or (warn("Cannot access log file $file, skipping, $!"), next); } else { open(LOG, $Logfile) or (warn("Cannot access log file $file, skipping, $!"), next); } while() { chomp; if(/sendmail/) { $TotalMails += $1 if /nrcpts=(\d+),/; if(/ruleset=check_rcpt/) { $Discarded++ if /discard$/; $REFUSED_mail_abuse++ if/See http:\/\/mail-abuse.com\/cgi-bin\/lookup/; #$REFUSED_spamcop++ if/spamcop.net/; $REFUSED_spamcop++ if/See http:\/\/spamcop.net\/bl.shtml for further information/; $REFUSED_spamhaus_sbl++ if/http:\/\/www.abuse.net\/sbl.phtml/; $REFUSED_spamhaus_xbl++ if/http:\/\/cbl.abuseat.org/; $REFUSED_relays_ordb++ if/ordb.org/; $Banned_spam_domain++ if/Domain banned because of SPAM/; $Banned_spam_IP++ if/IP number banned because of SPAM/; $Banned_spammer++ if/Mail from SPAMMERs rejected/; } if(/\[(\S+)\] due to pre-greeting traffic/) { $pregreet{$1}++; $Pregreeting_punts++; } if(/relay=\[(\S+)\], discard$/) { $Discarded++; $discard{$1}++; } if(/\[(\S+)\], reject=421 4.3.2 Connection rate limit exceeded/) { $Connection_rate_limit++; $ratelimit{$1}++; } if(/\[(\S+)\], reject=421 4.3.2 Too many open connections/) { $Too_many_connections++; $connlimit{$1}++; } #---from require_rdns.m4 # if(/Fix reverse DNS for (\S+),/) # { # $Fix_reverse_DNS++; # $fixdns{$1}++; # } if(/Client IP address (\S+) does not resolve/) { $Does_not_resolve++; } if(/Possibly forged hostname for (\S+)/) { $Possibly_forged++; } next; } if(/mailscanner/i) { #---v4 if(/New Batch: Scanning (\d+) messages, (\d+) bytes/) { $BatchCounter++; $TotalMsgsScanned += $1; $TotalBytesScanned += $2; } if(/Batch processed in (\d+).(\d+) seconds/) { $batchtime = sprintf("%d.%d", $1, $2); $MinBatchTime = $batchtime if ($batchtime < $MinBatchTime); $MaxBatchTime = $batchtime if ($batchtime > $MaxBatchTime); $TotalBatchTime += $batchtime; } $TotalViruses++ if/>>> Virus/; $TotalViruses++ if/INFECTED::/; $TotalSpamsDeleted++ if/actions are delete/; $TotalSpamsDelivered++ if/actions are deliver/; $TotalSpamsDelivered++ if/actions are store,deliver/; $TotalAssassinTimeouts++ if/SpamAssassin timed out/; if(/is spam/) { $TotalSpam++; $TotalSpamCop++ if/spamcop.net/; $TotalSpamHaus++ if/spamhaus.org/; $TotalORDB_RBL++ if/ORDB-RBL/; $TotalCBL++ if/CBL/; $TotalDSBL++ if/DSBL/; $TotalNJABL++ if/NJABL/; $TotalSBL_XBL++ if/SBL+XBL/; if (/SpamAssassin/) { $TotalAssassinScore += $1+($2/100) if /score=(\d+)\.(\d+),/; $TotalAssassin++; } } #---phishing fraud if(/Found phishing fraud from (\S+) claiming to be (\S+)/) { $tag = $1 . "\t" . $2; $Phishing{$tag}++; } if(/ClamAV: (\S+) contains (\S+) $/) { $tag = "ClamAV" . "\t" . $2; $Virus{$tag}++; } #---sophos or clamavmodule output (perl) if(/(\S+)::INFECTED:: (\S+)::/) { $tag = $1 . "\t" . $2; $Virus{$tag}++; } $Virusfrom{$2}++ if /Infected message (\S+) came from (\S+)/; #--- from mailscanner filename.rules.conf $Rule{$1}++ if / Possible (.*)/; # $Virus{$1}++ if / in email in (\S+)/; # $Virus{$1}++ if / attack in (\S+)/; # $Virus{$1}++ if / often mailicious in (\S+)/; # $Virus{$1}++ if / extension in (\S+)/; # $Virus{$1}++ if / part of it (\S+)/; } } close LOG; print "===Sendmail Summaries:\n"; print "Total recipients: $TotalMails\n"; print "Total Discards: $Discarded\n"; print "Total Refused by MAPS: $REFUSED_mail_abuse\n"; print "Total Refused by Spamcop: $REFUSED_spamcop\n"; print "Total Refused by SpamHaus SBL: $REFUSED_spamhaus_sbl\n"; print "Total Refused by SpamHaus XBL: $REFUSED_spamhaus_xbl\n"; print "Total Refused by ORDB: $REFUSED_relays_ordb\n"; print "Total Connection rate limit: $Connection_rate_limit\n"; print "Total Too many connections: $Too_many_connections\n"; print "Total Banned by Domain: $Banned_spam_domain\n"; print "Total Banned by IP: $Banned_spam_IP\n"; print "Total Banned Spammers: $Banned_spammer\n"; print "Total Pre-Greeting Punts: $Pregreeting_punts\n"; #print "Total RDNS Fix Reverse DNS: $Fix_reverse_DNS\n"; #print "Total RDNS no resolve: $Does_not_resolve\n"; #print "Total RDNS Possible forgery: $Possibly_forged\n"; print "\n===Mailscanner Summaries:\n"; print "Total messages scanned: $TotalMsgsScanned\n"; print "Total Message Batches: $BatchCounter\n"; $AveMessageBatch = $TotalMsgsScanned/$BatchCounter; printf("Average Messages per Batch: %.2f\n",$AveMessageBatch); print "Minimum Batch Time (sec): $MinBatchTime\n"; print "Maximum Batch Time (sec): $MaxBatchTime\n"; $AveBatchTime = $TotalBatchTime/$BatchCounter; printf("Average Batch Time (sec): %.2f\n",$AveBatchTime); $MBytes = $TotalBytesScanned/(1024 * 1024); printf "Total MBytes scanned: %-6.2f\n", $MBytes; #print "Total Seconds scanned: $TotalSecondsScanned\n"; print "Total virii detected: $TotalViruses\n"; print "Total spams tagged: $TotalSpam\n"; print "Total spams delivered: $TotalSpamsDelivered\n"; print "Total spams deleted: $TotalSpamsDeleted\n"; print "\n"; print "Total SpamAssassin: $TotalAssassin\n"; print "Total SpamAssassin Timeouts: $TotalAssassinTimeouts\n"; #printf "Total SpamAssassin score: %-8.2f\n", $TotalAssassinScore; $AverageScore = $TotalAssassinScore/$TotalAssassin; printf "Avg SpamAssassin score: %-6.2f\n", $AverageScore; #print "\n"; print "Total MailScanner SpamCop: $TotalSpamCop\n"; print "Total MailScanner SpamHaus: $TotalSpamHaus\n"; print "Total MailScanner ORDB-RBL: $TotalORDB_RBL\n"; print "Total MailScanner CBL: $TotalCBL\n"; print "Total MailScanner DSBL: $TotalDSBL\n"; print "Total MailScanner NJABL: $TotalNJABL\n"; print "Total MailScanner SBL+XBL: $TotalSBL_XBL\n"; print "\n=== Pre-greeting Rejections"; print " (top $limit)" if $limit; print ":\n"; @pregreets = sort {$pregreet{$b} <=> $pregreet{$a}} keys(%pregreet); @pregreets = splice(@pregreets,0,$limit) if $limit; for $pregid (@pregreets) { printf ("%6d: %-s\n",$pregreet{$pregid},$pregid); } print "\n=== Connection rate limit exceeded"; print " (top $limit)" if $limit; print ":\n"; @ratelimits = sort {$ratelimit{$b} <=> $ratelimit{$a}} keys(%ratelimit); @ratelimits = splice(@ratelimits,0,$limit) if $limit; for $rateid (@ratelimits) { printf ("%6d: %-s\n",$ratelimit{$rateid},$rateid); } print "\n=== Open Connections limit exceeded"; print " (top $limit)" if $limit; print ":\n"; @connlimits = sort {$connlimit{$b} <=> $connlimit{$a}} keys(%connlimit); @connlimits = splice(@connlimits,0,$limit) if $limit; for $connid (@connlimits) { printf ("%6d: %-s\n",$connlimit{$connid},$connid); } #print "\n=== Fix Reverse DNS rejections"; #print " (top $limit)" if $limit; #print ":\n"; #@fixdnss = sort {$fixdns{$b} <=> $fixdns{$a}} keys(%fixdns); #@fixdnss = splice(@fixdnss,0,$limit) if $limit; #for $fixid (@fixdnss) #{ # printf ("%6d: %-s\n",$fixdns{$fixid},$fixid); #} print "\n=== Discards"; print " (top $limit)" if $limit; print ":\n"; @discards = sort {$discard{$b} <=> $discard{$a}} keys(%discard); @discards = splice(@discards,0,$limit) if $limit; for $discardid (@discards) { printf ("%6d: %-s\n",$discard{$discardid},$discardid); } print "\n=== Virus Senders"; print " (top $limit)" if $limit; print ":\n"; @viruses = sort {$Virusfrom{$b} <=> $Virusfrom{$a}} keys(%Virusfrom); @viruses = splice(@viruses,0,$limit) if $limit; for $virusid (@viruses) { #printf ("%29s: %d\n",$virusid,$Virus{$virusid}); printf ("%6d: %-s\n",$Virusfrom{$virusid},$virusid); } print "\n=== Viruses found"; print " (top $limit)" if $limit; print ":\n"; @viruses = sort {$Virus{$b} <=> $Virus{$a}} keys(%Virus); @viruses = splice(@viruses,0,$limit) if $limit; for $virusid (@viruses) { #printf ("%29s: %d\n",$virusid,$Virus{$virusid}); printf ("%6d: %-s\n",$Virus{$virusid},$virusid); } print "\n=== Phishing fraud URLs"; print " (top $limit)" if $limit; print ":\n"; @phish = sort {$Phishing{$b} <=> $Phishing{$a}} keys(%Phishing); @phish = splice(@phish,0,$limit) if $limit; for $phishid (@phish) { printf ("%6d: %-s\n",$Phishing{$phishid},$phishid); } # print "\n=== Mailscanner Rules Complaints Found"; # print " (top $limit)" if $limit; # print ":\n"; # @rules = sort {$Rule{$b} <=> $Rule{$a}} keys(%Rule); # @rules = splice(@rules,0,$limit) if $limit; # for $ruleid (@rules) # { # #printf ("%29s: %d\n",$ruleid,$Rule{$ruleid}); # printf ("%6d: %-s\n",$Rule{$ruleid},$ruleid); # } From PHachey at city.cornwall.on.ca Tue Jan 24 13:50:32 2006 From: PHachey at city.cornwall.on.ca (Philip Hachey) Date: Tue Jan 24 13:50:35 2006 Subject: Whitelisted mail is still scanned by SA? In-Reply-To: <200601231524.k0NFOv8g018255@bkserver.blacknight.ie> Message-ID: Julian Field wrote: > Always Include SpamAssassin Report = no > Check SpamAssassin If On Spam List = no > > is what you want. You probably have the 2nd one set to "yes". I had both set to yes. When I was searching through the config file for something like this, I had looked in the SpamAssassin sections and didn't think to look in the headers section. Changing the first one back to "no" now stops whitelisted mail from being sent to SA. Thanks for the assistance! Philip Hachey From MailScanner at ecs.soton.ac.uk Tue Jan 24 13:58:33 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Jan 24 13:58:47 2006 Subject: Whitelisted mail is still scanned by SA? In-Reply-To: References: Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 24 Jan 2006, at 13:50, Philip Hachey wrote: > Julian Field wrote: > >> Always Include SpamAssassin Report = no >> Check SpamAssassin If On Spam List = no >> >> is what you want. You probably have the 2nd one set to "yes". > > I had both set to yes. When I was searching through the config > file for > something like this, I had looked in the SpamAssassin sections and > didn't > think to look in the headers section. Changing the first one back > to "no" > now stops whitelisted mail from being sent to SA. Thanks for the > assistance! Sorry for it not being more obvious. I often have trouble trying to work out what section an option should be in. It's not always an easy choice. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ9YyjPw32o+k+q+hAQEmpAf9GUki071uLyoLiI3cdMk9sIwlZcMZ0SrP 1PvCbnU0zU9BuEbDNoU9WK7Q9TCeOb0Z4xuMgbiIMlBv/skkrcF1MVEarzokpJ5Q TWx619rdSIFCsuhrYqPurTFOD2+XO/YzEiQOOupm2t/Vm7y7WG2FboQjLo+wWBqj b8TP0ug3GlN+tQ4PUCpLbKs1w9Wvb8BDTQ4RccYCP3obbTHjazBTs7wvjHGz7Zbk ITRFeer/ThpbCPCNz8qPsLdgO+Rlreepk9YyBSal8SI7DZlNer59hsLJP/Q1Ad5O aSrw8z28DFvqgO3SCjGfxpcl0Ve4C2OJVssPXSw2lhoivKcz7uAwUQ== =rise -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From alex at nkpanama.com Tue Jan 24 14:26:19 2006 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Tue Jan 24 14:26:27 2006 Subject: weird priblems with server In-Reply-To: <223f97700601240113t3412a1f8o@mail.gmail.com> References: <95873e560601222145o384b0123me1909f33318c2950@mail.gmail.com> <223f97700601222305gedf0a38v@mail.gmail.com> <95873e560601232209s5db78e73j9ef63bbc79f25cb1@mail.gmail.com> <223f97700601240113t3412a1f8o@mail.gmail.com> Message-ID: <43D6390B.7000004@nkpanama.com> Glenn Steen wrote: > On 24/01/06, Nilesh Shastrakar wrote: >> Thanks everybody for replying me, >> >> I have checked the mailogs but confused I found from address and ctladdr is >> different >> is my server is hacked or its a virus problem on ther server >> but I am using Fedora 4, Sendmail, MailScanner and Clamav how my server >> infect with virus. >> is there easy way to find out what was the problem. >> >> >> Regards >> Nilesh. > > Hi Nilesh, > > I'm not 100% sure I decipher what you eman correctly... Could you post > some examples from your log, and possibly some headers too... We'll > help you try to make sense of them;). > -- > -- Glenn > email: glenn < dot > steen < at > gmail < dot > com > work: glenn < dot > steen < at > ap1 < dot > se Chances are... ... your server is not infected. ... your server is not hacked. So sit down, have a cup of tea, and think serene thoughts. You have been, more probably by accident than choice, entrusted with the operation and maintenance of an e-mail server with a number of different programs that each do its own thing. The problem you have right now is probably being caused by a simple configuration error - and is probably very simple to fix. So please take the time to, at the very least, read through the very helpful comments on the configuration file /etc/MailScanner/MailScanner.conf". Remember that the "from" address INSIDE an e-mail message can be different from the "from" address on the message "envelope". Also remember MailScanner relies on properly configured tools like SpamAssassin (which you have to enable), and SpamAssassin relies on tools you also have to configure (and sometimes enable) properly, such as Razor2, Pyzor and DCC. So read, read again, rest, and read. The answer will probably jump right at you. In the meantime, it helps to have examples of what you mean, especially since you haven't been able to express your problem in a meaningful way. -- Alex Neuman van der Hans N&K Technology Consultants Tel. +507 214-9002 - http://nkpanama.com/ From jaearick at colby.edu Tue Jan 24 14:39:17 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Tue Jan 24 14:39:23 2006 Subject: question on "Always Looked Up Last" timing Message-ID: Julian, Does the "Batch Processed in..." time include the "Always Looked up Last" time? Jeff Earickson Colby College From MailScanner at ecs.soton.ac.uk Tue Jan 24 14:48:36 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Jan 24 14:48:49 2006 Subject: question on "Always Looked Up Last" timing In-Reply-To: References: Message-ID: <3BA47D68-E5EE-49BC-A356-B4FA12614AF5@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Depends on what version you are running. If you have "Always Looked Up Last" set to anything other than "no" then you should get separate timing for that. If that happens, then the "Batch Processed in" time will *not* include "Always Looked Up Last". This will happen with a recent beta. Otherwise, it usually does include it. Try looking at "sub EndBatch" in MessageBatch.pm to see if it includes stuff about printing timing. On 24 Jan 2006, at 14:39, Jeff A. Earickson wrote: > Julian, > > Does the "Batch Processed in..." time include the "Always > Looked up Last" time? > > Jeff Earickson > Colby College > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ9Y+R/w32o+k+q+hAQFQDgf/chzki866XGkJ+2DDd1wGhcIICxz4Zvyh bYXbNmKwWrRHbppBUqf2UlsITUafur32cANsYVlc1rpSSwZMtZAmw6OzU7Ah/V1S fZ2poTEgL0ktIciXqRb6LE8K70wTsFaoJWy+SnkFTug9fKnR5bxN6vlspqVCd/ge HAj1O547kx83XBUc7jiZ/Y6e0AzcKTBg57zQEOcVyHmFmi5tPAqpsWPzweiYU8Bx exFS7rwIwn8rp6Vr1ln86mGvETRJz7fHmEgdC958CNoCuyoT20M0qZYH0e08VL5S IhZYW7iDgpA9ux4sdFw/iRv3QE/awuGQJc4PZVuFHVUel1g54+axOQ== =qwns -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From jaearick at colby.edu Tue Jan 24 14:53:23 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Tue Jan 24 14:53:32 2006 Subject: question on "Always Looked Up Last" timing In-Reply-To: <3BA47D68-E5EE-49BC-A356-B4FA12614AF5@ecs.soton.ac.uk> References: <3BA47D68-E5EE-49BC-A356-B4FA12614AF5@ecs.soton.ac.uk> Message-ID: Just installed 4.50.12. I use IPBlock. I'm modifying my mailsummary.pl script to do averages on "Looked up Last" times. Hmmm, they look very similar to the Batch processed times. I'll dig a bit after my next meeting. Jeff Earickson On Tue, 24 Jan 2006, Julian Field wrote: > Date: Tue, 24 Jan 2006 14:48:36 +0000 > From: Julian Field > Reply-To: MailScanner discussion > To: MailScanner discussion > Subject: Re: question on "Always Looked Up Last" timing > > -----BEGIN PGP SIGNED MESSAGE----- > > Depends on what version you are running. If you have "Always Looked > Up Last" set to anything other than "no" then you should get separate > timing for that. If that happens, then the "Batch Processed in" time > will *not* include "Always Looked Up Last". This will happen with a > recent beta. > > Otherwise, it usually does include it. > > Try looking at "sub EndBatch" in MessageBatch.pm to see if it > includes stuff about printing timing. > > On 24 Jan 2006, at 14:39, Jeff A. Earickson wrote: > >> Julian, >> >> Does the "Batch Processed in..." time include the "Always >> Looked up Last" time? >> >> Jeff Earickson >> Colby College >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.4 (Build 4042) > > iQEVAwUBQ9Y+R/w32o+k+q+hAQFQDgf/chzki866XGkJ+2DDd1wGhcIICxz4Zvyh > bYXbNmKwWrRHbppBUqf2UlsITUafur32cANsYVlc1rpSSwZMtZAmw6OzU7Ah/V1S > fZ2poTEgL0ktIciXqRb6LE8K70wTsFaoJWy+SnkFTug9fKnR5bxN6vlspqVCd/ge > HAj1O547kx83XBUc7jiZ/Y6e0AzcKTBg57zQEOcVyHmFmi5tPAqpsWPzweiYU8Bx > exFS7rwIwn8rp6Vr1ln86mGvETRJz7fHmEgdC958CNoCuyoT20M0qZYH0e08VL5S > IhZYW7iDgpA9ux4sdFw/iRv3QE/awuGQJc4PZVuFHVUel1g54+axOQ== > =qwns > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From ddelao at oucpm.org Tue Jan 24 14:56:29 2006 From: ddelao at oucpm.org (Darryl DeLao) Date: Tue Jan 24 14:57:00 2006 Subject: Connection refused In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B8880@MED-CORE03-MS1.med.wayne.edu> Message-ID: <006501c620f6$5b951b60$0632a8c0@oucpm1> I got mailscanner installed correctly, along with Spamassassin and Clamav. It was working fine yesterday, but now connections are no longer allowed. Everything is being deferred. Any ideas? Thanks, Darryl From alex at nkpanama.com Tue Jan 24 14:59:01 2006 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Tue Jan 24 14:59:07 2006 Subject: Connection refused In-Reply-To: <006501c620f6$5b951b60$0632a8c0@oucpm1> References: <006501c620f6$5b951b60$0632a8c0@oucpm1> Message-ID: <43D640B5.3080503@nkpanama.com> Darryl DeLao wrote: > I got mailscanner installed correctly, along with Spamassassin and Clamav. > It was working fine yesterday, but now connections are no longer allowed. > Everything is being deferred. Any ideas? > > Thanks, > Darryl > > > > Utilization? -- Alex Neuman van der Hans N&K Technology Consultants Tel. +507 214-9002 - http://nkpanama.com/ From MailScanner at ecs.soton.ac.uk Tue Jan 24 15:00:23 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Jan 24 15:00:32 2006 Subject: Connection refused In-Reply-To: <006501c620f6$5b951b60$0632a8c0@oucpm1> References: <006501c620f6$5b951b60$0632a8c0@oucpm1> Message-ID: <77D3894F-C5B4-4A79-82A1-80C641FDE4AC@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- What is your load average? (run "uptime" and tell us the output). On 24 Jan 2006, at 14:56, Darryl DeLao wrote: > > I got mailscanner installed correctly, along with Spamassassin and > Clamav. > It was working fine yesterday, but now connections are no longer > allowed. > Everything is being deferred. Any ideas? > > Thanks, > Darryl > > > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ9ZBCfw32o+k+q+hAQHMbwf/Tu7KqQT0b4wet981B4RiDSxhaXZSZdnp jTe17ksbw4G6nidSmcUppWGITN2FjmxksIeUlhtckc1kSoJw+8hFcVAj4oljqtGh rxo1vAg+LK4bifEDCYWy/1j2GdZ9fgb9RsXKGGkO8n0gLVciwAOLwTiC3hQEecV1 5ntacwXzEdH0zLed8JH8dI6ArODinxKeQnvq57Uudd5NHcNJj5DEaxKBA8QW9SUi npLvlrvDc4NTLGZC4HTqE/MDHBmZqIF5cOS2i7qTMwZEX7FNGEexeE1FqrS5Yw7j FDO6Xd6iXDE5xk1r3HzSXIeiOzK7ATOk5rITnVockadCre8Lq0CMhA== =xUZ4 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ddelao at oucpm.org Tue Jan 24 15:00:52 2006 From: ddelao at oucpm.org (Darryl DeLao) Date: Tue Jan 24 15:01:22 2006 Subject: Connection refused In-Reply-To: <43D640B5.3080503@nkpanama.com> Message-ID: <006c01c620f6$f8340440$0632a8c0@oucpm1> It's a test server. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Alex Neuman van der Hans Sent: Tuesday, January 24, 2006 8:59 AM To: MailScanner discussion Subject: Re: Connection refused Darryl DeLao wrote: > I got mailscanner installed correctly, along with Spamassassin and Clamav. > It was working fine yesterday, but now connections are no longer allowed. > Everything is being deferred. Any ideas? > > Thanks, > Darryl > > > > Utilization? -- Alex Neuman van der Hans N&K Technology Consultants Tel. +507 214-9002 - http://nkpanama.com/ -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From ddelao at oucpm.org Tue Jan 24 15:01:18 2006 From: ddelao at oucpm.org (Darryl DeLao) Date: Tue Jan 24 15:01:48 2006 Subject: Connection refused In-Reply-To: <77D3894F-C5B4-4A79-82A1-80C641FDE4AC@ecs.soton.ac.uk> Message-ID: <006d01c620f7$07d701e0$0632a8c0@oucpm1> 09:01:11 up 27 min, 3 users, load average: 0.17, 0.06, 0.05 -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian Field Sent: Tuesday, January 24, 2006 9:00 AM To: MailScanner discussion Subject: Re: Connection refused -----BEGIN PGP SIGNED MESSAGE----- What is your load average? (run "uptime" and tell us the output). On 24 Jan 2006, at 14:56, Darryl DeLao wrote: > > I got mailscanner installed correctly, along with Spamassassin and > Clamav. > It was working fine yesterday, but now connections are no longer > allowed. > Everything is being deferred. Any ideas? > > Thanks, > Darryl > > > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ9ZBCfw32o+k+q+hAQHMbwf/Tu7KqQT0b4wet981B4RiDSxhaXZSZdnp jTe17ksbw4G6nidSmcUppWGITN2FjmxksIeUlhtckc1kSoJw+8hFcVAj4oljqtGh rxo1vAg+LK4bifEDCYWy/1j2GdZ9fgb9RsXKGGkO8n0gLVciwAOLwTiC3hQEecV1 5ntacwXzEdH0zLed8JH8dI6ArODinxKeQnvq57Uudd5NHcNJj5DEaxKBA8QW9SUi npLvlrvDc4NTLGZC4HTqE/MDHBmZqIF5cOS2i7qTMwZEX7FNGEexeE1FqrS5Yw7j FDO6Xd6iXDE5xk1r3HzSXIeiOzK7ATOk5rITnVockadCre8Lq0CMhA== =xUZ4 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From prandal at herefordshire.gov.uk Tue Jan 24 15:06:32 2006 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Tue Jan 24 15:06:57 2006 Subject: Connection refused Message-ID: <86144ED6CE5B004DA23E1EAC0B569B580AB9EECB@isabella.herefordshire.gov.uk> That looks fine, but how about telling us which OS and Mail Transfer Agent you're using. If it's linux and sendmail, service MailScanner stop service sendmail stop waiting 30 seconds or so service MailScanner start should bring it back to life. Check /var/log/maillog for any error messages. Cheers, Phil ---- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Darryl DeLao > Sent: 24 January 2006 15:01 > To: 'MailScanner discussion' > Subject: RE: Connection refused > > 09:01:11 up 27 min, 3 users, load average: 0.17, 0.06, 0.05 > > > > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Julian Field > Sent: Tuesday, January 24, 2006 9:00 AM > To: MailScanner discussion > Subject: Re: Connection refused > > -----BEGIN PGP SIGNED MESSAGE----- > > What is your load average? (run "uptime" and tell us the output). > > On 24 Jan 2006, at 14:56, Darryl DeLao wrote: > > > > > I got mailscanner installed correctly, along with Spamassassin and > > Clamav. > > It was working fine yesterday, but now connections are no longer > > allowed. > > Everything is being deferred. Any ideas? > > > > Thanks, > > Darryl > > > > > > > > > > -- > > MailScanner mailing list > > MailScanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store PGP > footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.4 (Build 4042) > > iQEVAwUBQ9ZBCfw32o+k+q+hAQHMbwf/Tu7KqQT0b4wet981B4RiDSxhaXZSZdnp > jTe17ksbw4G6nidSmcUppWGITN2FjmxksIeUlhtckc1kSoJw+8hFcVAj4oljqtGh > rxo1vAg+LK4bifEDCYWy/1j2GdZ9fgb9RsXKGGkO8n0gLVciwAOLwTiC3hQEecV1 > 5ntacwXzEdH0zLed8JH8dI6ArODinxKeQnvq57Uudd5NHcNJj5DEaxKBA8QW9SUi > npLvlrvDc4NTLGZC4HTqE/MDHBmZqIF5cOS2i7qTMwZEX7FNGEexeE1FqrS5Yw7j > FDO6Xd6iXDE5xk1r3HzSXIeiOzK7ATOk5rITnVockadCre8Lq0CMhA== > =xUZ4 > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From campbell at cnpapers.com Tue Jan 24 15:07:51 2006 From: campbell at cnpapers.com (Steve Campbell) Date: Tue Jan 24 15:08:00 2006 Subject: OT: RNDS or whatever it was yesterday Message-ID: <001101c620f7$f1e1b5f0$0705000a@DDF5DW71> I had always misunderstood the "accept_unresolvable_domains" feature in sendmail. I guess it's my age, but I thought it worked backwards from the way it does work. I'm just too old to be doing this stuff. Anyway, I implemented it this morning due to the fact that I have been getting a lot of notices from sendmail in the form of: "lost input channel from [XXX.XXX.XXX.XXX] to MTA after rcpt" but I don't think it will resolve much due to the fact that these are from real domains that are spoofed. I'm getting a lot of bayes_tok.expire files and not sure why, so I thought this may be part of the problem. (Older version of MS) My questions are: What should I see in my maillogs when sendmail rejects an unresolvable domain message? I don't see anything yet. What is the best way to block the "lost input channel" type messages? (Is there a way?) Thanks for any help. Steve Campbell campbell@cnpapers.com Charleston Newspapers From batkins at tlcdelivers.com Tue Jan 24 14:55:19 2006 From: batkins at tlcdelivers.com (Brian Atkins) Date: Tue Jan 24 15:08:06 2006 Subject: Mailscanner being bypassed? In-Reply-To: <43D557F9.4080801@coders.co.uk> References: <43D551FF.90000@tlcdelivers.com> <43D557F9.4080801@coders.co.uk> Message-ID: <43D63FD7.4010701@tlcdelivers.com> Yes. That's it. Thanks. I'm allowed 1 dumb mistake, right? Brian Atkins "An adventure is never an adventure when it's happening. Challenging experiences need time to ferment, and an adventure is simply physical and emotional discomfort recollected in tranquility." -- Tim Cahill Matt Hampton wrote: > Brian Atkins wrote: > >> At this time, I have moved the previous sendmail.[cf|mc] back in place >> and restarted both Mailscanner and sendmail separately seveal times, but >> it appears that I'm now getting a very heavy influx of spam messages. >> Also, the X headers (Mail Header = X-%org-name%-MailScanner:) seem to >> have disappeared. >> > > That's because you have probably started sendmail as a standalone system > and not started it through MailScanner. > > You should not start sendmail through it's start up scripts. > > Assuming you are on a Linux distribution: > > chkconfig sendmail off > > service sendmail stop > service MailScanner stop > service MailScanner start > > matt From ddelao at oucpm.org Tue Jan 24 15:10:08 2006 From: ddelao at oucpm.org (Darryl DeLao) Date: Tue Jan 24 15:10:39 2006 Subject: Connection refused In-Reply-To: <86144ED6CE5B004DA23E1EAC0B569B580AB9EECB@isabella.herefordshire.gov.uk> Message-ID: <006e01c620f8$43d68bb0$0632a8c0@oucpm1> Yes, its red hat and sendmail. Followed your instructions below, same problem exists. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Randal, Phil Sent: Tuesday, January 24, 2006 9:07 AM To: MailScanner discussion Subject: RE: Connection refused That looks fine, but how about telling us which OS and Mail Transfer Agent you're using. If it's linux and sendmail, service MailScanner stop service sendmail stop waiting 30 seconds or so service MailScanner start should bring it back to life. Check /var/log/maillog for any error messages. Cheers, Phil ---- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Darryl DeLao > Sent: 24 January 2006 15:01 > To: 'MailScanner discussion' > Subject: RE: Connection refused > > 09:01:11 up 27 min, 3 users, load average: 0.17, 0.06, 0.05 > > > > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Julian Field > Sent: Tuesday, January 24, 2006 9:00 AM > To: MailScanner discussion > Subject: Re: Connection refused > > -----BEGIN PGP SIGNED MESSAGE----- > > What is your load average? (run "uptime" and tell us the output). > > On 24 Jan 2006, at 14:56, Darryl DeLao wrote: > > > > > I got mailscanner installed correctly, along with Spamassassin and > > Clamav. > > It was working fine yesterday, but now connections are no longer > > allowed. > > Everything is being deferred. Any ideas? > > > > Thanks, > > Darryl > > > > > > > > > > -- > > MailScanner mailing list > > MailScanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store PGP > footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.4 (Build 4042) > > iQEVAwUBQ9ZBCfw32o+k+q+hAQHMbwf/Tu7KqQT0b4wet981B4RiDSxhaXZSZdnp > jTe17ksbw4G6nidSmcUppWGITN2FjmxksIeUlhtckc1kSoJw+8hFcVAj4oljqtGh > rxo1vAg+LK4bifEDCYWy/1j2GdZ9fgb9RsXKGGkO8n0gLVciwAOLwTiC3hQEecV1 > 5ntacwXzEdH0zLed8JH8dI6ArODinxKeQnvq57Uudd5NHcNJj5DEaxKBA8QW9SUi > npLvlrvDc4NTLGZC4HTqE/MDHBmZqIF5cOS2i7qTMwZEX7FNGEexeE1FqrS5Yw7j > FDO6Xd6iXDE5xk1r3HzSXIeiOzK7ATOk5rITnVockadCre8Lq0CMhA== > =xUZ4 > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From alex at nkpanama.com Tue Jan 24 15:18:50 2006 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Tue Jan 24 15:18:56 2006 Subject: Connection refused In-Reply-To: <006e01c620f8$43d68bb0$0632a8c0@oucpm1> References: <006e01c620f8$43d68bb0$0632a8c0@oucpm1> Message-ID: <43D6455A.6000001@nkpanama.com> >>> It was working fine yesterday, but now connections are no longer >>> allowed. Exactly *what* do you mean by connections are no longer allowed? Do you mean that if you, say, "telnet yourmailserver.com 25" you get a message saying "Connection not allowed"? >>> Everything is being deferred. Any ideas? Exactly *what* do you mean by everything is being deferred? Do you mean that if you, for example, check /var/log/maillog, you get something like: Jan 24 10:16:05 yourmailserver sendmail[22098]: k0OFFoEd022891: from=, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA-v6, relay=... never mind, I'm deferring everything! MWAHAHAHAH!!! From ishukor at gmail.com Tue Jan 24 15:22:27 2006 From: ishukor at gmail.com (Ishukor) Date: Tue Jan 24 15:22:40 2006 Subject: Own domain login not log? Message-ID: <43D64633.40807@gmail.com> Hi, I just notice that when a sender from user@mydomain.com send to anotheruser@mydomain.com it is not log to my /var/log/maillog, so my mailwatch does not show any logging from user in the same domain is it normal or do I need to set anything so I can log all activities? I am using MailScanner version 4.49 with postfix as a gateway relay for my exchange. Thanks in Adavance. From martinh at solid-state-logic.com Tue Jan 24 15:26:48 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Tue Jan 24 15:26:58 2006 Subject: Own domain login not log? In-Reply-To: <43D64633.40807@gmail.com> Message-ID: <001b01c620fa$97f0a080$3004010a@martinhlaptop> Hi Depends if Exchange routes email for itself to the MailScanner box.. Hopefully its intelligent enough to notice it's the email server for mydomain.com and tries to deliver it to itself, rather than using it's default email relay. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Ishukor > Sent: 24 January 2006 15:22 > To: mailscanner@lists.mailscanner.info > Subject: Own domain login not log? > > Hi, > > I just notice that when a sender from user@mydomain.com send to > anotheruser@mydomain.com it is not log to my /var/log/maillog, so my > mailwatch does not show any logging from user in the same domain is it > normal or do I need to set anything so I can log all activities? I am > using MailScanner version 4.49 with postfix as a gateway relay for my > exchange. > > Thanks in Adavance. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From ddelao at oucpm.org Tue Jan 24 15:29:48 2006 From: ddelao at oucpm.org (Darryl DeLao) Date: Tue Jan 24 15:30:18 2006 Subject: Connection refused In-Reply-To: <43D6455A.6000001@nkpanama.com> Message-ID: <007201c620fb$02cce3a0$0632a8c0@oucpm1> There is no indication in the logs that something is wrong. I can not telnet to the server, and when I flush out my other mail server, which has messages qued up, it says connection deferred, not accepting connections. There is no firewall running on the server itself. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Alex Neuman van der Hans Sent: Tuesday, January 24, 2006 9:19 AM To: MailScanner discussion Subject: Re: Connection refused >>> It was working fine yesterday, but now connections are no longer >>> allowed. Exactly *what* do you mean by connections are no longer allowed? Do you mean that if you, say, "telnet yourmailserver.com 25" you get a message saying "Connection not allowed"? >>> Everything is being deferred. Any ideas? Exactly *what* do you mean by everything is being deferred? Do you mean that if you, for example, check /var/log/maillog, you get something like: Jan 24 10:16:05 yourmailserver sendmail[22098]: k0OFFoEd022891: from=, size=0, class=0, nrcpts=0, proto=SMTP, daemon=MTA-v6, relay=... never mind, I'm deferring everything! MWAHAHAHAH!!! -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From alex at nkpanama.com Tue Jan 24 15:36:25 2006 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Tue Jan 24 15:36:32 2006 Subject: Connection refused In-Reply-To: <007201c620fb$02cce3a0$0632a8c0@oucpm1> References: <007201c620fb$02cce3a0$0632a8c0@oucpm1> Message-ID: <43D64979.4040602@nkpanama.com> Darryl DeLao wrote: > There is no indication in the logs that something is wrong. I can not > telnet to the server, and when I flush out my other mail server, which has > messages qued up, it says connection deferred, not accepting connections. > There is no firewall running on the server itself. > > > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Alex Neuman > van der Hans > Sent: Tuesday, January 24, 2006 9:19 AM > To: MailScanner discussion > Subject: Re: Connection refused > >>>> It was working fine yesterday, but now connections are no longer >>>> allowed. > > Exactly *what* do you mean by connections are no longer allowed? Do you > mean that if you, say, "telnet yourmailserver.com 25" you get a message > saying "Connection not allowed"? > >>>> Everything is being deferred. Any ideas? > > Exactly *what* do you mean by everything is being deferred? Do you mean > that if you, for example, check /var/log/maillog, you get something like: > > Jan 24 10:16:05 yourmailserver sendmail[22098]: k0OFFoEd022891: > from=, size=0, class=0, nrcpts=0, proto=SMTP, > daemon=MTA-v6, relay=... never mind, I'm deferring everything! MWAHAHAHAH!!! > > > Ok, so your server is not actually deferring anything, it's your *other* server that's deferring since the main server isn't accepting connections. So... Can you physically access the server? If you can, can you do a "telnet localhost 25"? If you can, you may have a default sendmail.mc -> sendmail.cf set to only listen on the 127.0.0.1 interface. -- Alex Neuman van der Hans N&K Technology Consultants Tel. +507 214-9002 - http://nkpanama.com/ From prandal at herefordshire.gov.uk Tue Jan 24 15:37:04 2006 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Tue Jan 24 15:37:22 2006 Subject: Connection refused Message-ID: <86144ED6CE5B004DA23E1EAC0B569B580AB9EED7@isabella.herefordshire.gov.uk> check your /etc/mail/sendmail.mc make sure you have the line dnl DAEMON_OPTIONS(`Port=smtp,Addr=127.0.0.1, Name=MTA')dnl without the dnl in front only locahost will be able to connect to sendmail then do a "service MailScanner restart" Phil ---- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Darryl DeLao > Sent: 24 January 2006 15:30 > To: 'MailScanner discussion' > Subject: RE: Connection refused > > There is no indication in the logs that something is wrong. > I can not telnet to the server, and when I flush out my other > mail server, which has messages qued up, it says connection > deferred, not accepting connections. > There is no firewall running on the server itself. > > > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Alex Neuman van der Hans > Sent: Tuesday, January 24, 2006 9:19 AM > To: MailScanner discussion > Subject: Re: Connection refused > > >>> It was working fine yesterday, but now connections are no longer > >>> allowed. > > Exactly *what* do you mean by connections are no longer > allowed? Do you mean that if you, say, "telnet > yourmailserver.com 25" you get a message saying "Connection > not allowed"? > > >>> Everything is being deferred. Any ideas? > > Exactly *what* do you mean by everything is being deferred? > Do you mean that if you, for example, check /var/log/maillog, > you get something like: > > Jan 24 10:16:05 yourmailserver sendmail[22098]: k0OFFoEd022891: > from=, size=0, class=0, nrcpts=0, > proto=SMTP, daemon=MTA-v6, relay=... never mind, I'm > deferring everything! MWAHAHAHAH!!! > > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From jaearick at colby.edu Tue Jan 24 15:39:09 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Tue Jan 24 15:39:14 2006 Subject: question on "Always Looked Up Last" timing In-Reply-To: <3BA47D68-E5EE-49BC-A356-B4FA12614AF5@ecs.soton.ac.uk> References: <3BA47D68-E5EE-49BC-A356-B4FA12614AF5@ecs.soton.ac.uk> Message-ID: Julian, Thinking out loud here, but in bin/MailScanner (4.50.12) you have: $batch->EndBatch(); $batch->LastLookup(); Wouldn't it make more sense to have the two operations return their times, then add and print the batch process time? I don't really understand object-oriented code, but could the my($batch) at the top of this while() loop generate a batch ID number which is then printed with the "start batch" and "end batch" statements? Jeff Earickson Colby College On Tue, 24 Jan 2006, Julian Field wrote: > Date: Tue, 24 Jan 2006 14:48:36 +0000 > From: Julian Field > Reply-To: MailScanner discussion > To: MailScanner discussion > Subject: Re: question on "Always Looked Up Last" timing > > -----BEGIN PGP SIGNED MESSAGE----- > > Depends on what version you are running. If you have "Always Looked > Up Last" set to anything other than "no" then you should get separate > timing for that. If that happens, then the "Batch Processed in" time > will *not* include "Always Looked Up Last". This will happen with a > recent beta. > > Otherwise, it usually does include it. > > Try looking at "sub EndBatch" in MessageBatch.pm to see if it > includes stuff about printing timing. > > On 24 Jan 2006, at 14:39, Jeff A. Earickson wrote: > >> Julian, >> >> Does the "Batch Processed in..." time include the "Always >> Looked up Last" time? >> >> Jeff Earickson >> Colby College >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.4 (Build 4042) > > iQEVAwUBQ9Y+R/w32o+k+q+hAQFQDgf/chzki866XGkJ+2DDd1wGhcIICxz4Zvyh > bYXbNmKwWrRHbppBUqf2UlsITUafur32cANsYVlc1rpSSwZMtZAmw6OzU7Ah/V1S > fZ2poTEgL0ktIciXqRb6LE8K70wTsFaoJWy+SnkFTug9fKnR5bxN6vlspqVCd/ge > HAj1O547kx83XBUc7jiZ/Y6e0AzcKTBg57zQEOcVyHmFmi5tPAqpsWPzweiYU8Bx > exFS7rwIwn8rp6Vr1ln86mGvETRJz7fHmEgdC958CNoCuyoT20M0qZYH0e08VL5S > IhZYW7iDgpA9ux4sdFw/iRv3QE/awuGQJc4PZVuFHVUel1g54+axOQ== > =qwns > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From shuttlebox at gmail.com Tue Jan 24 15:47:18 2006 From: shuttlebox at gmail.com (shuttlebox) Date: Tue Jan 24 15:47:22 2006 Subject: OT: RNDS or whatever it was yesterday In-Reply-To: <001101c620f7$f1e1b5f0$0705000a@DDF5DW71> References: <001101c620f7$f1e1b5f0$0705000a@DDF5DW71> Message-ID: <625385e30601240747x27941169o5bb0eeae1d6fdf5c@mail.gmail.com> On 1/24/06, Steve Campbell wrote: > > What should I see in my maillogs when sendmail rejects an unresolvable > domain message? I don't see anything yet. > > What is the best way to block the "lost input channel" type messages? (Is > there a way?) > Here's an example: Jan 24 15:39:10 viola sendmail[15806]: [ID 801593 mail.notice] k0OEaoQZ015806: ruleset=check_mail, arg1=<4m244yof3h@neaccess.com>, relay= wasamail.wasadata.com [193.15.177.100], reject=451 4.1.8 Domain of sender address 4m244yof3h@neaccess.com does not resolve About the "lost input channel" - aren't those often from spammers? They usually don't behave correctly and you can't do much about it on your end. -- /peter -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060124/bcb9f904/attachment.html From alex at nkpanama.com Tue Jan 24 16:14:32 2006 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Tue Jan 24 16:15:24 2006 Subject: OT: RNDS or whatever it was yesterday In-Reply-To: <625385e30601240747x27941169o5bb0eeae1d6fdf5c@mail.gmail.com> References: <001101c620f7$f1e1b5f0$0705000a@DDF5DW71> <625385e30601240747x27941169o5bb0eeae1d6fdf5c@mail.gmail.com> Message-ID: <43D65268.5050004@nkpanama.com> shuttlebox wrote: > On 1/24/06, *Steve Campbell* > wrote: > > What should I see in my maillogs when sendmail rejects an unresolvable > domain message? I don't see anything yet. > > What is the best way to block the "lost input channel" type > messages? (Is > there a way?) > > > Here's an example: > > Jan 24 15:39:10 viola sendmail[15806]: [ID 801593 mail.notice] > k0OEaoQZ015806: ruleset=check_mail, arg1=<4m244yof3h@neaccess.com > >, relay=wasamail.wasadata.com > [193.15.177.100 ], > reject=451 4.1.8 Domain of sender address 4m244yof3h@neaccess.com > does not resolve > > About the "lost input channel" - aren't those often from spammers? They > usually don't behave correctly and you can't do much about it on your end. > > -- > /peter > Unless there's a milter somewhere that somebody here on the list knows about that can trigger an iptables command to block port 25 from anywhere that does this, say, three times in one minute or some other configurable setting... -- Alex Neuman van der Hans N&K Technology Consultants Tel. +507 214-9002 - http://nkpanama.com/ From mkettler at evi-inc.com Tue Jan 24 16:23:38 2006 From: mkettler at evi-inc.com (Matt Kettler) Date: Tue Jan 24 16:23:47 2006 Subject: RDNS In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B887E@MED-CORE03-MS1.med.wayne.edu> References: <8F2A53954C22554EB75D9643FCCE0C6B887E@MED-CORE03-MS1.med.wayne.edu> Message-ID: <43D6548A.5080404@evi-inc.com> Rose, Bobby wrote: > I thought that it was a default action in sendmail to not accept from > unresolvable hosts and in setting > FEATURE(`accept_unresolvable_domains')dnl you are actually disabling so > that it does accept from unresolvable hosts. That is correct. Which is why I told him to make sure it's COMMENTED OUT. Many Linux Distros (ie: redhat variants) ship with this enabled by default. From campbell at cnpapers.com Tue Jan 24 16:37:00 2006 From: campbell at cnpapers.com (Steve Campbell) Date: Tue Jan 24 16:37:12 2006 Subject: OT: RNDS or whatever it was yesterday References: <001101c620f7$f1e1b5f0$0705000a@DDF5DW71><625385e30601240747x27941169o5bb0eeae1d6fdf5c@mail.gmail.com> <43D65268.5050004@nkpanama.com> Message-ID: <002701c62104$66164880$0705000a@DDF5DW71> Thanks for the responses. These lost channel emails are coming at an incredible rate, with a different IP for each message. They are indeed from spammers, and to mostly unknown users, so they get dropped, but after sendmail has accepted them. A little bit of a load problem. iptables rules would not be a likely solution since they are from the varying IPs. Thanks all, for the help Steve ----- Original Message ----- From: "Alex Neuman van der Hans" To: "MailScanner discussion" Sent: Tuesday, January 24, 2006 11:14 AM Subject: Re: OT: RNDS or whatever it was yesterday > shuttlebox wrote: >> On 1/24/06, *Steve Campbell* > > wrote: >> >> What should I see in my maillogs when sendmail rejects an >> unresolvable >> domain message? I don't see anything yet. >> >> What is the best way to block the "lost input channel" type >> messages? (Is >> there a way?) >> >> >> Here's an example: >> >> Jan 24 15:39:10 viola sendmail[15806]: [ID 801593 mail.notice] >> k0OEaoQZ015806: ruleset=check_mail, arg1=<4m244yof3h@neaccess.com >> >, relay=wasamail.wasadata.com >> [193.15.177.100 ], >> reject=451 4.1.8 Domain of sender address 4m244yof3h@neaccess.com >> does not resolve >> >> About the "lost input channel" - aren't those often from spammers? They >> usually don't behave correctly and you can't do much about it on your >> end. >> >> -- >> /peter >> > > Unless there's a milter somewhere that somebody here on the list knows > about that can trigger an iptables command to block port 25 from anywhere > that does this, say, three times in one minute or some other configurable > setting... > > -- > > Alex Neuman van der Hans > N&K Technology Consultants > Tel. +507 214-9002 - http://nkpanama.com/ > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From rpoe at plattesheriff.org Tue Jan 24 16:39:57 2006 From: rpoe at plattesheriff.org (Rob Poe) Date: Tue Jan 24 16:40:12 2006 Subject: Sendmail not relaying In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D15608@city-exch-w3e.cbj.local> References: <82895A755D1EA5458EC9E64021922AD2D15608@city-exch-w3e.cbj.local> Message-ID: <43D603FD.65ED.00A2.0@plattesheriff.org> - - snip - - itself. If one is in the /etc/mail directory the paths aren't even necessary. 'makemap hash access < access' works just fine. The additional bits can certainly give one a bit of a reality check as to what's actually happening although more characters also means more potential for typos. At least the way I type... - - snip - - I use makem hash ac. < ac But im lazy ---------------------------------------------------------------------------- CONFIDENTIALITY NOTICE This e-mail message and all documents that accompany it are intended only for the use of the individual or entity to which addressed, and may contain information that is privileged, confidential or exempt from disclosure under applicable law. If the reader is not the intended recipient, any disclosure, distribution or other use of this e-mail message is prohibited. If you have received this e-mail message in error, please notify the sender immediately. Thank you. From alex at nkpanama.com Tue Jan 24 16:41:41 2006 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Tue Jan 24 16:41:47 2006 Subject: OT: RNDS or whatever it was yesterday In-Reply-To: <002701c62104$66164880$0705000a@DDF5DW71> References: <001101c620f7$f1e1b5f0$0705000a@DDF5DW71><625385e30601240747x27941169o5bb0eeae1d6fdf5c@mail.gmail.com> <43D65268.5050004@nkpanama.com> <002701c62104$66164880$0705000a@DDF5DW71> Message-ID: <43D658C5.9050808@nkpanama.com> Steve Campbell wrote: > Thanks for the responses. > > These lost channel emails are coming at an incredible rate, with a > different IP for each message. They are indeed from spammers, and to > mostly unknown users, so they get dropped, but after sendmail has > accepted them. A little bit of a load problem. iptables rules would not > be a likely solution since they are from the varying IPs. > > Thanks all, for the help > > Steve > > > ----- Original Message ----- From: "Alex Neuman van der Hans" > > To: "MailScanner discussion" > Sent: Tuesday, January 24, 2006 11:14 AM > Subject: Re: OT: RNDS or whatever it was yesterday > > >> shuttlebox wrote: >>> On 1/24/06, *Steve Campbell* >> > wrote: >>> >>> What should I see in my maillogs when sendmail rejects an >>> unresolvable >>> domain message? I don't see anything yet. >>> >>> What is the best way to block the "lost input channel" type >>> messages? (Is >>> there a way?) >>> >>> >>> Here's an example: >>> >>> Jan 24 15:39:10 viola sendmail[15806]: [ID 801593 mail.notice] >>> k0OEaoQZ015806: ruleset=check_mail, arg1=<4m244yof3h@neaccess.com >>> >, relay=wasamail.wasadata.com >>> [193.15.177.100 >>> ], reject=451 4.1.8 Domain of sender address >>> 4m244yof3h@neaccess.com does not >>> resolve >>> >>> About the "lost input channel" - aren't those often from spammers? >>> They usually don't behave correctly and you can't do much about it on >>> your end. >>> >>> -- >>> /peter >>> >> >> Unless there's a milter somewhere that somebody here on the list knows >> about that can trigger an iptables command to block port 25 from >> anywhere that does this, say, three times in one minute or some other >> configurable setting... >> >> -- >> >> Alex Neuman van der Hans >> N&K Technology Consultants >> Tel. +507 214-9002 - http://nkpanama.com/ >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > Rules in iptables would be good if it were dynamic - that is, usually you'll find more than a few repeated requests from the same IP. Some form of throttling would be good if it could be set on a temporary basis. The other remedy would be to implement greylisting. In any case, these "lost input channel" messages happen before sendmail actually accepts the message, not after (AFAIK). -- Alex Neuman van der Hans N&K Technology Consultants Tel. +507 214-9002 - http://nkpanama.com/ From rpoe at plattesheriff.org Tue Jan 24 16:45:00 2006 From: rpoe at plattesheriff.org (Rob Poe) Date: Tue Jan 24 16:45:25 2006 Subject: OT: RNDS or whatever it was yesterday In-Reply-To: à References: <001101c620f7$f1e1b5f0$0705000a@DDF5DW71> <625385e30601240747x27941169o5bb0eeae1d6fdf5c@mail.gmail.com> à Message-ID: <43D6052C.65ED.00A2.0@plattesheriff.org> http://www.wanlink.com/spamilter/ Looks like the same thing the Snert Soft people are doing, without the license per server... Not discounting Snert Soft or their product! But to test something I can't see outlaying $$ first. >>> alex@nkpanama.com 1/24/2006 10:41:41 am >>> Steve Campbell wrote: > Thanks for the responses. > > These lost channel emails are coming at an incredible rate, with a > different IP for each message. They are indeed from spammers, and to > mostly unknown users, so they get dropped, but after sendmail has > accepted them. A little bit of a load problem. iptables rules would not > be a likely solution since they are from the varying IPs. > > Thanks all, for the help > > Steve > > > ----- Original Message ----- From: "Alex Neuman van der Hans" > > To: "MailScanner discussion" > Sent: Tuesday, January 24, 2006 11:14 AM > Subject: Re: OT: RNDS or whatever it was yesterday > > >> shuttlebox wrote: >>> On 1/24/06, *Steve Campbell* >> > wrote: >>> >>> What should I see in my maillogs when sendmail rejects an >>> unresolvable >>> domain message? I don't see anything yet. >>> >>> What is the best way to block the "lost input channel" type >>> messages? (Is >>> there a way?) >>> >>> >>> Here's an example: >>> >>> Jan 24 15:39:10 viola sendmail[15806]: [ID 801593 mail.notice] >>> k0OEaoQZ015806: ruleset=check_mail, arg1=<4m244yof3h@neaccess.com >>> >, relay=wasamail.wasadata.com >>> [193.15.177.100 >>> ], reject=451 4.1.8 Domain of sender address >>> 4m244yof3h@neaccess.com does not >>> resolve >>> >>> About the "lost input channel" - aren't those often from spammers? >>> They usually don't behave correctly and you can't do much about it on >>> your end. >>> >>> -- >>> /peter >>> >> >> Unless there's a milter somewhere that somebody here on the list knows >> about that can trigger an iptables command to block port 25 from >> anywhere that does this, say, three times in one minute or some other >> configurable setting... >> >> -- >> >> Alex Neuman van der Hans >> N&K Technology Consultants >> Tel. +507 214-9002 - http://nkpanama.com/ >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > Rules in iptables would be good if it were dynamic - that is, usually you'll find more than a few repeated requests from the same IP. Some form of throttling would be good if it could be set on a temporary basis. The other remedy would be to implement greylisting. In any case, these "lost input channel" messages happen before sendmail actually accepts the message, not after (AFAIK). -- Alex Neuman van der Hans N&K Technology Consultants Tel. +507 214-9002 - http://nkpanama.com/ -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ---------------------------------------------------------------------------- CONFIDENTIALITY NOTICE This e-mail message and all documents that accompany it are intended only for the use of the individual or entity to which addressed, and may contain information that is privileged, confidential or exempt from disclosure under applicable law. If the reader is not the intended recipient, any disclosure, distribution or other use of this e-mail message is prohibited. If you have received this e-mail message in error, please notify the sender immediately. Thank you. From rpoe at plattesheriff.org Tue Jan 24 16:49:27 2006 From: rpoe at plattesheriff.org (Rob Poe) Date: Tue Jan 24 16:49:47 2006 Subject: OT: RNDS or whatever it was yesterday In-Reply-To: <43D6052C.65ED.00A2.0@plattesheriff.org> References: <001101c620f7$f1e1b5f0$0705000a@DDF5DW71> <625385e30601240747x27941169o5bb0eeae1d6fdf5c@mail.gmail.com> ððÈ <43D6052C.65ED.00A2.0@plattesheriff.org> Message-ID: <43D60637.65ED.00A2.0@plattesheriff.org> And, to reply to my own email, if you're running CentOS 3.x (my test machine, ATM) you'll need the latest.tar.gz .. otherwise it won't compile correctly (that's my experience). If you want my howto for an RPM (read Centos/RHEL 3.x / 4.x) let me know .. It needs the sendmail source installed, and if you have an RPM based system the -devel package doesn't give you what you need.. The short, short version is you need to download the SRPM, install it (rpm -i sendmail.x.x.x), go to /usr/src/redhat/SPECS .. rpmbuild -bc (which just compiles) the spec file and then build the spamilter against that (it's so it'll link against libmilter). Whew! >>> rpoe@plattesheriff.org 1/24/2006 10:45:00 am >>> http://www.wanlink.com/spamilter/ Looks like the same thing the Snert Soft people are doing, without the license per server... Not discounting Snert Soft or their product! But to test something I can't see outlaying $$ first. >>> alex@nkpanama.com 1/24/2006 10:41:41 am >>> Steve Campbell wrote: > Thanks for the responses. > > These lost channel emails are coming at an incredible rate, with a > different IP for each message. They are indeed from spammers, and to > mostly unknown users, so they get dropped, but after sendmail has > accepted them. A little bit of a load problem. iptables rules would not > be a likely solution since they are from the varying IPs. > > Thanks all, for the help > > Steve > > > ----- Original Message ----- From: "Alex Neuman van der Hans" > > To: "MailScanner discussion" > Sent: Tuesday, January 24, 2006 11:14 AM > Subject: Re: OT: RNDS or whatever it was yesterday > > >> shuttlebox wrote: >>> On 1/24/06, *Steve Campbell* >> > wrote: >>> >>> What should I see in my maillogs when sendmail rejects an >>> unresolvable >>> domain message? I don't see anything yet. >>> >>> What is the best way to block the "lost input channel" type >>> messages? (Is >>> there a way?) >>> >>> >>> Here's an example: >>> >>> Jan 24 15:39:10 viola sendmail[15806]: [ID 801593 mail.notice] >>> k0OEaoQZ015806: ruleset=check_mail, arg1=<4m244yof3h@neaccess.com >>> >, relay=wasamail.wasadata.com >>> [193.15.177.100 >>> ], reject=451 4.1.8 Domain of sender address >>> 4m244yof3h@neaccess.com does not >>> resolve >>> >>> About the "lost input channel" - aren't those often from spammers? >>> They usually don't behave correctly and you can't do much about it on >>> your end. >>> >>> -- >>> /peter >>> >> >> Unless there's a milter somewhere that somebody here on the list knows >> about that can trigger an iptables command to block port 25 from >> anywhere that does this, say, three times in one minute or some other >> configurable setting... >> >> -- >> >> Alex Neuman van der Hans >> N&K Technology Consultants >> Tel. +507 214-9002 - http://nkpanama.com/ >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > Rules in iptables would be good if it were dynamic - that is, usually you'll find more than a few repeated requests from the same IP. Some form of throttling would be good if it could be set on a temporary basis. The other remedy would be to implement greylisting. In any case, these "lost input channel" messages happen before sendmail actually accepts the message, not after (AFAIK). -- Alex Neuman van der Hans N&K Technology Consultants Tel. +507 214-9002 - http://nkpanama.com/ -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ---------------------------------------------------------------------------- CONFIDENTIALITY NOTICE This e-mail message and all documents that accompany it are intended only for the use of the individual or entity to which addressed, and may contain information that is privileged, confidential or exempt from disclosure under applicable law. If the reader is not the intended recipient, any disclosure, distribution or other use of this e-mail message is prohibited. If you have received this e-mail message in error, please notify the sender immediately. Thank you. -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ---------------------------------------------------------------------------- CONFIDENTIALITY NOTICE This e-mail message and all documents that accompany it are intended only for the use of the individual or entity to which addressed, and may contain information that is privileged, confidential or exempt from disclosure under applicable law. If the reader is not the intended recipient, any disclosure, distribution or other use of this e-mail message is prohibited. If you have received this e-mail message in error, please notify the sender immediately. Thank you. From alex at nkpanama.com Tue Jan 24 16:59:18 2006 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Tue Jan 24 16:59:36 2006 Subject: OT: RNDS or whatever it was yesterday In-Reply-To: <43D60637.65ED.00A2.0@plattesheriff.org> References: <001101c620f7$f1e1b5f0$0705000a@DDF5DW71> <625385e30601240747x27941169o5bb0eeae1d6fdf5c@mail.gmail.com> ððÈ <43D6052C.65ED.00A2.0@plattesheriff.org> <43D60637.65ED.00A2.0@plattesheriff.org> Message-ID: <43D65CE6.7070007@nkpanama.com> Rob Poe wrote: > And, to reply to my own email, if you're running CentOS 3.x (my test machine, ATM) you'll need the latest.tar.gz .. otherwise it won't compile correctly (that's my experience). If you want my howto for an RPM (read Centos/RHEL 3.x / 4.x) let me know .. It needs the sendmail source installed, and if you have an RPM based system the -devel package doesn't give you what you need.. > > The short, short version is you need to download the SRPM, install it (rpm -i sendmail.x.x.x), go to /usr/src/redhat/SPECS .. rpmbuild -bc (which just compiles) the spec file and then build the spamilter against that (it's so it'll link against libmilter). > > Whew! > > > >>>> rpoe@plattesheriff.org 1/24/2006 10:45:00 am >>> > http://www.wanlink.com/spamilter/ > > Looks like the same thing the Snert Soft people are doing, without the license per server... > > Not discounting Snert Soft or their product! But to test something I can't see outlaying $$ first. > > > >>>> alex@nkpanama.com 1/24/2006 10:41:41 am >>> > Steve Campbell wrote: >> Thanks for the responses. >> >> These lost channel emails are coming at an incredible rate, with a >> different IP for each message. They are indeed from spammers, and to >> mostly unknown users, so they get dropped, but after sendmail has >> accepted them. A little bit of a load problem. iptables rules would not >> be a likely solution since they are from the varying IPs. >> >> Thanks all, for the help >> >> Steve >> >> >> ----- Original Message ----- From: "Alex Neuman van der Hans" >> >> To: "MailScanner discussion" >> Sent: Tuesday, January 24, 2006 11:14 AM >> Subject: Re: OT: RNDS or whatever it was yesterday >> >> >>> shuttlebox wrote: >>>> On 1/24/06, *Steve Campbell* >>> > wrote: >>>> >>>> What should I see in my maillogs when sendmail rejects an >>>> unresolvable >>>> domain message? I don't see anything yet. >>>> >>>> What is the best way to block the "lost input channel" type >>>> messages? (Is >>>> there a way?) >>>> >>>> >>>> Here's an example: >>>> >>>> Jan 24 15:39:10 viola sendmail[15806]: [ID 801593 mail.notice] >>>> k0OEaoQZ015806: ruleset=check_mail, arg1=<4m244yof3h@neaccess.com >>>> >, relay=wasamail.wasadata.com >>>> [193.15.177.100 >>>> ], reject=451 4.1.8 Domain of sender address >>>> 4m244yof3h@neaccess.com does not >>>> resolve >>>> >>>> About the "lost input channel" - aren't those often from spammers? >>>> They usually don't behave correctly and you can't do much about it on >>>> your end. >>>> >>>> -- >>>> /peter >>>> >>> Unless there's a milter somewhere that somebody here on the list knows >>> about that can trigger an iptables command to block port 25 from >>> anywhere that does this, say, three times in one minute or some other >>> configurable setting... >>> >>> -- >>> >>> Alex Neuman van der Hans >>> N&K Technology Consultants >>> Tel. +507 214-9002 - http://nkpanama.com/ >>> -- >>> MailScanner mailing list >>> MailScanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> >>> Before posting, read http://wiki.mailscanner.info/posting >>> >>> Support MailScanner development - buy the book off the website! >> > Rules in iptables would be good if it were dynamic - that is, usually > you'll find more than a few repeated requests from the same IP. Some > form of throttling would be good if it could be set on a temporary > basis. The other remedy would be to implement greylisting. > > In any case, these "lost input channel" messages happen before sendmail > actually accepts the message, not after (AFAIK). > I see it actually uses freebsd-specific ipfwadm commands instead of sendmail. Anybody want to tackle making a CentOS4 RPM or howto on this one? I could probably try doing it over the weekend, but if anybody's already worked on it... -- Alex Neuman van der Hans N&K Technology Consultants Tel. +507 214-9002 - http://nkpanama.com/ From ssilva at sgvwater.com Tue Jan 24 17:16:48 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Tue Jan 24 17:23:47 2006 Subject: Sendmail not relaying In-Reply-To: <43D603FD.65ED.00A2.0@plattesheriff.org> References: <82895A755D1EA5458EC9E64021922AD2D15608@city-exch-w3e.cbj.local> <43D603FD.65ED.00A2.0@plattesheriff.org> Message-ID: Rob Poe spake the following on 1/24/2006 8:39 AM: > - - snip - - > itself. If one is in the /etc/mail directory the paths aren't even > necessary. 'makemap hash access < access' works just fine. > > The additional bits can certainly give one a bit of a reality check as > to what's actually happening although more characters also means more > potential for typos. At least the way I type... > - - snip - - > > I use > > makem hash ac. < ac > > But im lazy Since when is economy of motion lazy? More like an efficient use of mental and physical resources ;-) -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () From ssilva at sgvwater.com Tue Jan 24 17:25:39 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Tue Jan 24 17:32:06 2006 Subject: Mailscanner being bypassed? In-Reply-To: <43D63FD7.4010701@tlcdelivers.com> References: <43D551FF.90000@tlcdelivers.com> <43D557F9.4080801@coders.co.uk> <43D63FD7.4010701@tlcdelivers.com> Message-ID: Brian Atkins spake the following on 1/24/2006 6:55 AM: > Yes. That's it. Thanks. > > I'm allowed 1 dumb mistake, right? > It isn't the volume of mistakes, it is the variety that shows you are learning. And it is only a dumb mistake if it is the 4th or 5th time you made it this week, so you are doing fine!! -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () From mrm at medicine.wisc.edu Tue Jan 24 19:37:12 2006 From: mrm at medicine.wisc.edu (Michael Masse) Date: Tue Jan 24 19:37:29 2006 Subject: individual spamassassin score thresholds Message-ID: I tried looking in the archive for an answer but the link is to the old server which just says the archive is not available. Is there a new url? We have been running mailscanner for years now totally separate from spamassassin (using spamc/spamd) so that users could have their own adjustable black/whitelists as well as individually adjust their spam threshold score. In the past we've been able to just throw more hardware at the server in order to cope with the increased utilization that this setup uses. Recently our email volume has gotten to the point that new hardware isn't going to cut it, so I'm seriously looking at running MS in the suggested method and have it make it's own spamassassin calls. I see in the documentation that if I were to switch the config to do this I can still allow users to have their own individual white/blacklists, but can't find anything about individually adjustable spam score thresholds. Is this possible? Mike From MailScanner at ecs.soton.ac.uk Tue Jan 24 19:49:38 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Jan 24 19:49:40 2006 Subject: individual spamassassin score thresholds In-Reply-To: References: Message-ID: <43D684D2.7080105@ecs.soton.ac.uk> Michael Masse wrote: > I tried looking in the archive for an answer but the link is to the old > server which just says the archive is not available. Is there a new > url? > > We have been running mailscanner for years now totally separate from > spamassassin (using spamc/spamd) so that users could have their own > adjustable black/whitelists as well as individually adjust their spam > threshold score. In the past we've been able to just throw more > hardware at the server in order to cope with the increased utilization > that this setup uses. Recently our email volume has gotten to the point > that new hardware isn't going to cut it, so I'm seriously looking at > running MS in the suggested method and have it make it's own > spamassassin calls. I see in the documentation that if I were to > switch the config to do this I can still allow users to have their own > individual white/blacklists, but can't find anything about individually > adjustable spam score thresholds. Is this possible? > You need to read up about rulesets. Using this you can given virtually any configuration option (including the Required SpamAssassin Score) a different value for different users, domains, groups of users, whatever. This is documented well on the wiki at wiki.mailscanner.info. It is also documented with examples in the MailScanner Book. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From shuttlebox at gmail.com Tue Jan 24 19:54:24 2006 From: shuttlebox at gmail.com (shuttlebox) Date: Tue Jan 24 19:54:27 2006 Subject: individual spamassassin score thresholds In-Reply-To: References: Message-ID: <625385e30601241154y2becdb9fid284cf08a153bd9d@mail.gmail.com> On 1/24/06, Michael Masse wrote: > > We have been running mailscanner for years now totally separate from > spamassassin (using spamc/spamd) so that users could have their own > adjustable black/whitelists as well as individually adjust their spam > threshold score. In the past we've been able to just throw more > hardware at the server in order to cope with the increased utilization > that this setup uses. Recently our email volume has gotten to the point > that new hardware isn't going to cut it, so I'm seriously looking at > running MS in the suggested method and have it make it's own > spamassassin calls. I see in the documentation that if I were to > switch the config to do this I can still allow users to have their own > individual white/blacklists, but can't find anything about individually > adjustable spam score thresholds. Is this possible? > Just make a ruleset for these two: Required SpamAssassin Score = 6 High SpamAssassin Score = 10 -- /peter -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060124/f2b7dd36/attachment.html From rpoe at plattesheriff.org Tue Jan 24 20:07:06 2006 From: rpoe at plattesheriff.org (Rob Poe) Date: Tue Jan 24 20:07:27 2006 Subject: Sendmail not relaying In-Reply-To: References: <82895A755D1EA5458EC9E64021922AD2D15608@city-exch-w3e.cbj.local> <43D603FD.65ED.00A2.0@plattesheriff.org> Message-ID: <43D6348A.65ED.00A2.0@plattesheriff.org> True. Like on Windows .. CTRL-ESC U R usually reboots the computer. (I dont use windows key because some still dont have it on their keyboard .. me being one). CTRL-ESC R firefox for me if my fingers are on the keyboard than START | RUN (or clicking on the desktop). People watch me breeze windows and do things quickly on the computer, and are amazed at how fast I am. Its usually me amazed that their malware infested compjter can keep up with me .. I'm not fast, I've just done it a billion times. >>> ssilva@sgvwater.com 1/24/2006 11:16:48 am >>> Rob Poe spake the following on 1/24/2006 8:39 AM: > - - snip - - > itself. If one is in the /etc/mail directory the paths aren't even > necessary. 'makemap hash access < access' works just fine. > > The additional bits can certainly give one a bit of a reality check as > to what's actually happening although more characters also means more > potential for typos. At least the way I type... > - - snip - - > > I use > > makem hash ac. < ac > > But im lazy Since when is economy of motion lazy? More like an efficient use of mental and physical resources ;-) -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ---------------------------------------------------------------------------- CONFIDENTIALITY NOTICE This e-mail message and all documents that accompany it are intended only for the use of the individual or entity to which addressed, and may contain information that is privileged, confidential or exempt from disclosure under applicable law. If the reader is not the intended recipient, any disclosure, distribution or other use of this e-mail message is prohibited. If you have received this e-mail message in error, please notify the sender immediately. Thank you. From martelm at quark.vsc.edu Tue Jan 24 20:16:39 2006 From: martelm at quark.vsc.edu (Michael H. Martel) Date: Tue Jan 24 20:16:48 2006 Subject: individual spamassassin score thresholds In-Reply-To: <43D684D2.7080105@ecs.soton.ac.uk> References: <43D684D2.7080105@ecs.soton.ac.uk> Message-ID: <656DD98A8B90AC266A14A37D@sherlockholmes.local> --On January 24, 2006 7:49:38 PM +0000 Julian Field wrote: > This is documented well on the wiki at wiki.mailscanner.info. It is also > documented with examples in the MailScanner Book. Speaking of, when is the book going to be updated again ? Will it be updated with the 4.50 release ? I really need to get a new copy if it is. Thanks for your hard work! Michael -- --------------------------------o--------------------------------- Michael H. Martel | Systems Administrator michael.martel@vsc.edu | Vermont State Colleges http://www.vsc.edu/~michael | PH:802-241-2544 FX:802-241-3363 From MailScanner at ecs.soton.ac.uk Tue Jan 24 20:20:28 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Jan 24 20:20:33 2006 Subject: individual spamassassin score thresholds In-Reply-To: <656DD98A8B90AC266A14A37D@sherlockholmes.local> References: <43D684D2.7080105@ecs.soton.ac.uk> <656DD98A8B90AC266A14A37D@sherlockholmes.local> Message-ID: <43D68C0C.7020608@ecs.soton.ac.uk> Michael H. Martel wrote: > --On January 24, 2006 7:49:38 PM +0000 Julian Field > wrote: > >> This is documented well on the wiki at wiki.mailscanner.info. It is also >> documented with examples in the MailScanner Book. > > Speaking of, when is the book going to be updated again ? Will it be > updated with the 4.50 release ? I really need to get a new copy if it > is. I wasn't planning on upgrading it till the summer. And then I expect I will do the same as last time and give away a PDF containing the new content for you. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From alex at nkpanama.com Tue Jan 24 20:23:32 2006 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Tue Jan 24 20:23:42 2006 Subject: Sendmail not relaying In-Reply-To: <43D6348A.65ED.00A2.0@plattesheriff.org> References: <82895A755D1EA5458EC9E64021922AD2D15608@city-exch-w3e.cbj.local> <43D603FD.65ED.00A2.0@plattesheriff.org> <43D6348A.65ED.00A2.0@plattesheriff.org> Message-ID: <43D68CC4.6090802@nkpanama.com> Ditto here... and how about when you blindly reset people's monitors to more with "windows-D mousemove mousemove rightclick R shift-control-tab alt-s left left left left enter-enter". Rob Poe wrote: > People watch me breeze windows and do things quickly on the computer, and are amazed at how fast I am. Its usually me amazed that their malware infested compjter can keep up with me .. I'm not fast, I've just done it a billion times. > -- Alex Neuman van der Hans N&K Technology Consultants Tel. +507 214-9002 - http://nkpanama.com/ From jurness at tomsawyer.com Tue Jan 24 21:32:54 2006 From: jurness at tomsawyer.com (John Urness) Date: Tue Jan 24 21:33:10 2006 Subject: Whitelisted mail is still scanned by SA? In-Reply-To: Message-ID: <028601c6212d$bfb01230$8f82160a@tomsawyer.com> -----Original Message----- From: Philip Hachey [mailto:PHachey@city.cornwall.on.ca] Sent: Tuesday, January 24, 2006 5:51 AM To: mailscanner@lists.mailscanner.info Subject: Re: Whitelisted mail is still scanned by SA? Julian Field wrote: > Always Include SpamAssassin Report = no Check SpamAssassin If On Spam > List = no > > is what you want. You probably have the 2nd one set to "yes". I had both set to yes. When I was searching through the config file for something like this, I had looked in the SpamAssassin sections and didn't think to look in the headers section. Changing the first one back to "no" now stops whitelisted mail from being sent to SA. Thanks for the assistance! Philip Hachey ++++++++++++++++++++++++++++++++++++++++++++++++++ Hi all, I think my question is related- I have a lot of email from a yahoo group that is getting tagged as spam because spamcop has the group listed. Even if I whitelist the sending address with the mailscanner whitelist file, it never gets whitelisted. This works with other domains and/or email addresses that I use in the whitelist file. I *do* want it to check spam lists as well as score the email using spam assassin, but still let it through if it is whitelisted. Here is a sample below of a before and an after header from an individual user on this mailing list. This is actually tagged as spam after I set the second setting from "yes" to "no" and Mailscanner was then restarted. The original one scores correctly as ham, yet because of spamcop, gets tagged. What might be wrong with my configuration? >Check SpamAssassin If On Spam List = no Before: Received: from n3a.bullet.dcn.yahoo.com (n3a.bullet.dcn.yahoo.com [216.155.203.223]) by unixserv0.tomsawyer.com (8.12.9/8.12.9) with SMTP id k0OGKpW1005083 for ; Tue, 24 Jan 2006 08:20:51 -0800 (PST) Comment: DomainKeys? See http://antispam.yahoo.com/domainkeys DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=lima; d=yahoogroups.com; b=qetIEaEi1xsxVujqQoZOw79i62uA2AIMh8n8/UGdA+ua/tZyl9mBc0JwqbUlJGyJJ2OkxcoiLh 85j4TDnd4kiqV2sWgz++FVfeoWBz9O+5c97puwEOIcG8flVazD1pr5; Received: from [216.155.201.64] by n3.bullet.dcn.yahoo.com with NNFMP; 24 Jan 2006 16:20:42 -0000 Received: from [66.218.69.5] by t1.bullet.dcn.yahoo.com with NNFMP; 24 Jan 2006 16:20:41 -0000 Received: from [66.218.66.99] by t5.bullet.scd.yahoo.com with NNFMP; 24 Jan 2006 16:20:41 -0000 X-Yahoo-Newman-Property: groups-email X-Sender: senderemail X-Apparently-To: HATT@yahoogroups.com Received: (qmail 57516 invoked from network); 24 Jan 2006 16:20:40 -0000 Received: from unknown (66.218.66.218) by m34.grp.scd.yahoo.com with QMQP; 24 Jan 2006 16:20:40 -0000 Received: from unknown (HELO uproxy.gmail.com) (66.249.92.202) by mta3.grp.scd.yahoo.com with SMTP; 24 Jan 2006 16:20:40 -0000 Received: by uproxy.gmail.com with SMTP id m3so365979uge for ; Tue, 24 Jan 2006 08:20:39 -0800 (PST) Received: by 10.48.225.3 with SMTP id x3mr443884nfg; Tue, 24 Jan 2006 06:52:01 -0800 (PST) Received: by 10.48.12.20 with HTTP; Tue, 24 Jan 2006 06:52:01 -0800 (PST) Message-ID: <375e3cb30601240652x675f83b0ia4c64904eefad906@mail.gmail.com> To: Howard Lebowitz Cc: HATT@yahoogroups.com In-Reply-To: <205CA9DB99DA0A42B1317BCC83E95FCCCE38BF@ex-lkm1.harlandfs.com> References: <205CA9DB99DA0A42B1317BCC83E95FCCCE38BF@ex-lkm1.harlandfs.com> X-Originating-IP: 66.249.92.202 X-eGroups-Msg-Info: 1:12:0:0 From: senderemail X-Yahoo-Profile: Sender: HATT@yahoogroups.com MIME-Version: 1.0 Mailing-List: list HATT@yahoogroups.com; contact HATT-owner@yahoogroups.com Delivered-To: mailing list HATT@yahoogroups.com List-Id: Precedence: bulk List-Unsubscribe: Date: Tue, 24 Jan 2006 09:52:01 -0500 Subject: <<<>>> Re: [HATT] RE: Q: What's Up With Madcap? (PROMO PRICING) Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit X-TSS-MailScanner-Information: See www.mailscanner.info for information X-TSS-MailScanner: Appears to be free of infection X-TSS-MailScanner-SpamCheck: spam, spamcop.net, SpamAssassin (score=-1.414, required 4, AWL -1.01, BAYES_00 -2.60, RCVD_IN_BL_SPAMCOP_NET 1.56, SARE_MSGID_LONG40 0.64) X-TSS-MailScanner-From: sentto-2077532-60082-1138119641-localuser=tomsawyer.com@returns.groups.yahoo .com After: Received: from n6a.bullet.dcn.yahoo.com (n6a.bullet.dcn.yahoo.com [216.155.203.226]) by unixserv0.tomsawyer.com (8.12.9/8.12.9) with SMTP id k0OK3GW1006867 for ; Tue, 24 Jan 2006 12:03:17 -0800 (PST) Comment: DomainKeys? See http://antispam.yahoo.com/domainkeys DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=lima; d=yahoogroups.com; b=FihSN52cWuzYyiKLCtL83i5/tFr2zLxV5NYDfgL70GyglzVZlNwhMv6E0o+qJ6r51wJer9/nAr YIll8vU3QSgLoFcLnLqrwEwX4b5eLIyN9SBYF59KyoFz/KkZGD++gI; Received: from [216.155.201.65] by n6.bullet.dcn.yahoo.com with NNFMP; 24 Jan 2006 20:03:11 -0000 Received: from [66.218.69.2] by t2.bullet.dcn.yahoo.com with NNFMP; 24 Jan 2006 20:03:10 -0000 Received: from [66.218.66.35] by t2.bullet.scd.yahoo.com with NNFMP; 24 Jan 2006 20:03:10 -0000 X-Yahoo-Newman-Property: groups-email X-Sender: senderemail X-Apparently-To: HATT@yahoogroups.com Received: (qmail 34688 invoked from network); 24 Jan 2006 20:03:09 -0000 Received: from unknown (66.218.66.172) by m29.grp.scd.yahoo.com with QMQP; 24 Jan 2006 20:03:09 -0000 Received: from unknown (HELO uproxy.gmail.com) (66.249.92.200) by mta4.grp.scd.yahoo.com with SMTP; 24 Jan 2006 20:03:07 -0000 Received: by uproxy.gmail.com with SMTP id m3so120564ugc for ; Tue, 24 Jan 2006 12:02:42 -0800 (PST) Received: by 10.49.88.3 with SMTP id q3mr479305nfl; Tue, 24 Jan 2006 12:02:42 -0800 (PST) Received: by 10.48.12.20 with HTTP; Tue, 24 Jan 2006 12:02:42 -0800 (PST) Message-ID: <375e3cb30601241202g747298d3w386e4c26210a4aed@mail.gmail.com> To: address0 Cc: address1, address2, HATT@yahoogroups.com In-Reply-To: <162e01c620f8$691cc830$0401a8c0@RicksPC> References: <162e01c620f8$691cc830$0401a8c0@RicksPC> X-Originating-IP: 66.249.92.200 X-eGroups-Msg-Info: 1:12:0:0 From: senderemail X-Yahoo-Profile: ##### Sender: HATT@yahoogroups.com MIME-Version: 1.0 Mailing-List: list HATT@yahoogroups.com; contact HATT-owner@yahoogroups.com Delivered-To: mailing list HATT@yahoogroups.com List-Id: Precedence: bulk List-Unsubscribe: Date: Tue, 24 Jan 2006 15:02:42 -0500 Subject: <<<>>> Re: [HATT] What happens to RoboHelp when IE 7.0 is released? Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit X-TSS-MailScanner-Information: See www.mailscanner.info for information X-TSS-MailScanner: Appears to be free of infection X-TSS-MailScanner-SpamCheck: spam, spamcop.net X-TSS-MailScanner-From: sentto-2077532-60089-1138132990-localuser=tomsawyer.com@returns.groups.yahoo .com Best, John From ka at pacific.net Tue Jan 24 22:49:51 2006 From: ka at pacific.net (Ken A) Date: Tue Jan 24 22:49:58 2006 Subject: individual spamassassin score thresholds In-Reply-To: <43D684D2.7080105@ecs.soton.ac.uk> References: <43D684D2.7080105@ecs.soton.ac.uk> Message-ID: <43D6AF0F.4030502@pacific.net> Julian Field wrote: > > > Michael Masse wrote: >> I tried looking in the archive for an answer but the link is to the old >> server which just says the archive is not available. Is there a new >> url? >> >> We have been running mailscanner for years now totally separate from >> spamassassin (using spamc/spamd) so that users could have their own >> adjustable black/whitelists as well as individually adjust their spam >> threshold score. In the past we've been able to just throw more >> hardware at the server in order to cope with the increased utilization >> that this setup uses. Recently our email volume has gotten to the point >> that new hardware isn't going to cut it, so I'm seriously looking at >> running MS in the suggested method and have it make it's own >> spamassassin calls. I see in the documentation that if I were to >> switch the config to do this I can still allow users to have their own >> individual white/blacklists, but can't find anything about individually >> adjustable spam score thresholds. Is this possible? >> > You need to read up about rulesets. Using this you can given virtually > any configuration option (including the Required SpamAssassin Score) a > different value for different users, domains, groups of users, whatever. > > This is documented well on the wiki at wiki.mailscanner.info. It is also > documented with examples in the MailScanner Book. > I just received my copy of the MailScanner book today. It's a long overdue addition to the bookshelf here, and I'd highly recommend it to anyone who is installing MailScanner, or turning over a MailScanner installation to someone who doesn't have time to scan the thousands of emails on this list for answers. It's a condensed user guide, not a 'too technical' book, and seems aimed at new or relatively new email admins who want to get the most out of MailScanner. Ken A Pacific.Net From antony at rdihost.com Tue Jan 24 22:59:28 2006 From: antony at rdihost.com (Antony Puckey) Date: Tue Jan 24 23:03:23 2006 Subject: remove Message-ID: <20060124233405.4E28C50AB@debian> -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060125/4a3036e2/attachment.html From BBourdage at techpro.com Tue Jan 24 23:31:23 2006 From: BBourdage at techpro.com (Barry Bourdage) Date: Tue Jan 24 23:31:26 2006 Subject: individual spamassassin score thresholds Message-ID: <2E09A52C9852E24A9A084352AB68F2C5C1ECE4@w2k3-tp.techpro.local> I have created an addon to MailWatch that allows for this, it should be committed to source soon. If you would like a copy please let me know. This is only for MailWatch. Barry -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Michael Masse Sent: Tuesday, January 24, 2006 1:37 PM To: mailscanner@lists.mailscanner.info Subject: individual spamassassin score thresholds I tried looking in the archive for an answer but the link is to the old server which just says the archive is not available. Is there a new url? We have been running mailscanner for years now totally separate from spamassassin (using spamc/spamd) so that users could have their own adjustable black/whitelists as well as individually adjust their spam threshold score. In the past we've been able to just throw more hardware at the server in order to cope with the increased utilization that this setup uses. Recently our email volume has gotten to the point that new hardware isn't going to cut it, so I'm seriously looking at running MS in the suggested method and have it make it's own spamassassin calls. I see in the documentation that if I were to switch the config to do this I can still allow users to have their own individual white/blacklists, but can't find anything about individually adjustable spam score thresholds. Is this possible? Mike -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From alex at nkpanama.com Wed Jan 25 00:18:59 2006 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Wed Jan 25 00:19:12 2006 Subject: remove In-Reply-To: <20060124233405.4E28C50AB@debian> References: <20060124233405.4E28C50AB@debian> Message-ID: <43D6C3F3.6050606@nkpanama.com> check http://lists.mailscanner.info/mailman/listinfo/mailscanner Antony Puckey wrote: > > > -- Alex Neuman van der Hans N&K Technology Consultants Tel. +507 214-9002 - http://nkpanama.com/ -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060124/dbc09fec/attachment.html From padma at eis.iisc.ernet.in Wed Jan 25 03:26:00 2006 From: padma at eis.iisc.ernet.in (padma@eis.iisc.ernet.in) Date: Wed Jan 25 03:36:07 2006 Subject: (Mailscanner+spamassassin) not working Message-ID: Mailscanner-4.40.11 SpamAssassin version 3.0.4 running on Perl version 5.8.0 F-PROT ANTIVIRUS Program version: 4.5.4 Engine version: 3.16.6 All running on RedHat 9.0 Mailscanner seems to be not using spamassassin at all, even after i set the option in mailscanner.conf as Use SpamAssassin=yes should i install a spamass-milter separately for spamassassin to function with sendmail????? The exact problem is : When i forward a genuine spam from some machine which has spamassassin running to a machine which has mailscanner+spamassasin running, it doesn't get tagged as spam. Mailscanner seems to be giving some spam score with character s, but that mail must get a high score in case mailscanner is successfully using spamassassin. Regards Padma From ugob at camo-route.com Wed Jan 25 04:06:00 2006 From: ugob at camo-route.com (Ugo Bellavance) Date: Wed Jan 25 04:06:38 2006 Subject: (Mailscanner+spamassassin) not working In-Reply-To: References: Message-ID: padma@eis.iisc.ernet.in wrote: > > Mailscanner-4.40.11 Fairly old. Did you just installed it? > > SpamAssassin version 3.0.4 Fairly old as well... > running on Perl version 5.8.0 > > F-PROT ANTIVIRUS > Program version: 4.5.4 > Engine version: 3.16.6 > > All running on RedHat 9.0 > Hope you use fedoralegacy.org updates. > Mailscanner seems to be not using spamassassin at all, even after i set > the option in mailscanner.conf as > > Use SpamAssassin=yes Did you try the Gtube? Do you get MailScanner-related headers in messages? What do logs say? > > should i install a spamass-milter separately for spamassassin to > function with sendmail????? > No, you can use SA in MailScanner. > The exact problem is : When i forward a genuine spam from some machine > which has spamassassin running to a machine which has > mailscanner+spamassasin running, it doesn't get tagged as spam. > Mailscanner seems to be giving some spam score with character s, but > that mail must get a high score in case mailscanner is successfully > using spamassassin. > Forwarded messages loose headers that bumps the score up. > > Regards > Padma -- Ugo -> Please don't send a copy of your reply by e-mail. I read the list. -> Please avoid top-posting, long signatures and HTML, and cut the irrelevant parts in your replies. From martinh at solid-state-logic.com Wed Jan 25 09:20:03 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Wed Jan 25 09:20:49 2006 Subject: (Mailscanner+spamassassin) not working In-Reply-To: Message-ID: <079b01c62190$89a866c0$3004010a@martinhlaptop> Hi There's some settings in MailScanner.conf you might want to adjust so you can actually see the SA score in more detail.. SpamScore Number Instead Of Stars = yes Detailed Spam Report = yes Include Scores In SpamAssassin Report = yes Always Include SpamAssassin Report = yes Spam Score Number Format = %5.2f Changing these settings should help with norrowing down the problem Also check the "SpamAssassin Site Rules Dir" is set to a sensible value and the spam.assassin.prefs.conf isn't turning a load of rules off. (spamassassin -P /spam.assassin.prefs.conf -D --lint spam.email.file) -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of padma@eis.iisc.ernet.in > Sent: 25 January 2006 03:26 > To: MailScanner discussion > Subject: (Mailscanner+spamassassin) not working > > > Mailscanner-4.40.11 > > SpamAssassin version 3.0.4 > running on Perl version 5.8.0 > > F-PROT ANTIVIRUS > Program version: 4.5.4 > Engine version: 3.16.6 > > All running on RedHat 9.0 > > Mailscanner seems to be not using spamassassin at all, even after i set > the option in mailscanner.conf as > > Use SpamAssassin=yes > > should i install a spamass-milter separately for spamassassin to function > with sendmail????? > > The exact problem is : When i forward a genuine spam from some machine > which has spamassassin running to a machine which has > mailscanner+spamassasin running, it doesn't get tagged as spam. > Mailscanner seems to be giving some spam score with character s, but that > mail must get a high score in case mailscanner is successfully using > spamassassin. > > > Regards > Padma > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From MailScanner at ecs.soton.ac.uk Wed Jan 25 09:25:44 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Jan 25 09:25:59 2006 Subject: individual spamassassin score thresholds In-Reply-To: <43D6AF0F.4030502@pacific.net> References: <43D684D2.7080105@ecs.soton.ac.uk> <43D6AF0F.4030502@pacific.net> Message-ID: <427CFD1A-BDF4-4603-8380-07A73A38EC3D@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- On 24 Jan 2006, at 22:49, Ken A wrote: > > I just received my copy of the MailScanner book today. It's a long > overdue addition to the bookshelf here, and I'd highly recommend it > to anyone who is installing MailScanner, or turning over a > MailScanner installation to someone who doesn't have time to scan > the thousands of emails on this list for answers. It's a condensed > user guide, not a 'too technical' book, and seems aimed at new or > relatively new email admins who want to get the most out of > MailScanner. > > Ken A > Pacific.Net I'm glad to hear you like the book. Your deduction of the "aim" of the book is exactly what I intended, which is great. The really advanced guys can just do and read the on-line docs, but most of my users are relatively new email admins as you say. They have some clue as to what they are doing, and want to learn more; this is to be encouraged! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ9dEG/w32o+k+q+hAQEiFAgAt6QPETAc8WFwEBxUjGrkP9QUcHRdpq1P xV/kix05lRBX+HSEPmGp3duVCUaHxB6nFZ+Ci06TnRVNvcx7NXZnkuSRW+NwA2Ea c9W4MatHaD2IwoMwL9EC/XqlGOM+VoW+AZRfHZ1Lm6Mm6yQ/4Y3FtGGYda+65Azy yaRAA6NaU3ykkbJVD+HQ2e345SuWN5RDoSakdGKXgoRibjJNbNAgzKmtipyaDQWW dRAjSDYVqwDyZgGqCyLw7nXD1MyWPLfqe8ynlB8pxJbXXitq23fzTqiWXO+sFpG5 aCfUXC46V+TV4nnxf+e70MnFZoLd2D68NOwuuwHSCwihQNu95BheWw== =5Mp5 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From R.A.Gardener at shu.ac.uk Wed Jan 25 09:42:18 2006 From: R.A.Gardener at shu.ac.uk (Ray Gardener) Date: Wed Jan 25 09:43:01 2006 Subject: Sophos sweep and password protected zip files Message-ID: Hi, yesterday, an end user reported that some of his mail was not being delivered. On inspection the mail was a password protected zip file. Within our mailscanner setup we have two virus scanners Sophos sweep and ClamAV. Sophos was generating reports regarding this which caused mailscanner to treat this as a virus (mailscanner report shown below) which was then silently deleted. Is there an easy was to stop this happening? version details: sophos: Product version : 4.00.0 Engine version : 2.32.5 Virus data version : 4.00 User interface version : 2.07.119 Platform : Linux/Intel Released : 05 December 2005 mailscanner: version 4.46.2 and within Mailscanner.conf I already have set: Non-Forging Viruses = Joke/ OF97/ WM97/ W97M/ Zip-Password mailscanner report starts _______________________________________________________________________ The following e-mails were found to have: Virus Detected Quarantine: Report: Sophos: Password protected file ./1F1NHK-00083Q-Fe/SHU-fw.zip/whatwasthesecondary.txt Sophos: Password protected file ./1F1NHK-00083Q-Fe/SHU-fw.zip/primary.txt ____________________________________________________________________ mailscanner report ends Regards, Ray Gardener LITS Sheffield Hallam University 0114 225 4926 From martinh at solid-state-logic.com Wed Jan 25 09:50:53 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Wed Jan 25 09:51:02 2006 Subject: Sophos sweep and password protected zip files In-Reply-To: Message-ID: <085b01c62194$d4a09d10$3004010a@martinhlaptop> Ray Check out the "Allowed Sophos Error Messages" setting in MailScanner.conf. Add in "Password protected file" to the list.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Ray Gardener > Sent: 25 January 2006 09:42 > To: MailScanner discussion > Subject: Sophos sweep and password protected zip files > > Hi, > > yesterday, an end user reported that some of his mail was not being > delivered. On inspection the mail was a password protected zip file. > Within our mailscanner setup we have two virus scanners Sophos sweep and > ClamAV. > Sophos was generating reports regarding this which caused mailscanner to > treat this as a virus (mailscanner report shown below) which was then > silently > deleted. Is there an easy was to stop > this happening? > > > version details: > > sophos: > Product version : 4.00.0 > Engine version : 2.32.5 > Virus data version : 4.00 > User interface version : 2.07.119 > Platform : Linux/Intel > Released : 05 December 2005 > > mailscanner: version 4.46.2 > > > and within Mailscanner.conf I already have set: > > Non-Forging Viruses = Joke/ OF97/ WM97/ W97M/ Zip-Password > > > mailscanner report starts > _______________________________________________________________________ > The following e-mails were found to have: Virus Detected > > > Quarantine: > Report: Sophos: Password protected file > ./1F1NHK-00083Q-Fe/SHU-fw.zip/whatwasthesecondary.txt > Sophos: Password protected file > ./1F1NHK-00083Q-Fe/SHU-fw.zip/primary.txt > ____________________________________________________________________ > mailscanner report ends > > > Regards, > > Ray Gardener > LITS > Sheffield Hallam University > 0114 225 4926 > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From hans.wong at cityline.com.hk Wed Jan 25 09:55:50 2006 From: hans.wong at cityline.com.hk (Hans Wong) Date: Wed Jan 25 09:56:15 2006 Subject: Sophos sweep and password protected zip files References: Message-ID: <128501c62195$8cad2900$eb018080@cityline.com.hk> Hi Ray, There are two options in MailScanner.conf that you might want to have a try: Allow Password-Protected Archives = yes Allowed Sophos Error Messages = "corrupt", "format not supported", "encrypted", "Password protected file" Best Regards Hans ----- Original Message ----- From: "Ray Gardener" To: "MailScanner discussion" Sent: Wednesday, January 25, 2006 5:42 PM Subject: Sophos sweep and password protected zip files > Hi, > > yesterday, an end user reported that some of his mail was not being > delivered. On inspection the mail was a password protected zip file. > Within our mailscanner setup we have two virus scanners Sophos sweep and > ClamAV. > Sophos was generating reports regarding this which caused mailscanner to > treat this as a virus (mailscanner report shown below) which was then > silently deleted. Is there an easy was to stop this happening? > > > version details: > > sophos: > Product version : 4.00.0 > Engine version : 2.32.5 > Virus data version : 4.00 > User interface version : 2.07.119 > Platform : Linux/Intel > Released : 05 December 2005 > > mailscanner: version 4.46.2 > > > and within Mailscanner.conf I already have set: > > Non-Forging Viruses = Joke/ OF97/ WM97/ W97M/ Zip-Password > > > mailscanner report starts > _______________________________________________________________________ > The following e-mails were found to have: Virus Detected > > > Quarantine: > Report: Sophos: Password protected file > ./1F1NHK-00083Q-Fe/SHU-fw.zip/whatwasthesecondary.txt > Sophos: Password protected file > ./1F1NHK-00083Q-Fe/SHU-fw.zip/primary.txt > ____________________________________________________________________ > mailscanner report ends > > > Regards, > > Ray Gardener > LITS > Sheffield Hallam University > 0114 225 4926 > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From P.G.M.Peters at utwente.nl Wed Jan 25 10:47:49 2006 From: P.G.M.Peters at utwente.nl (Peter Peters) Date: Wed Jan 25 10:48:04 2006 Subject: MS 4.50: way cool... In-Reply-To: References: <008001c620d6$b7ed24e0$3004010a@martinhlaptop> Message-ID: <43D75755.5080903@utwente.nl> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Jeff, Jeff A. Earickson wrote on 24-1-2006 14:40: > My perl script, or Julian's, or Peter Peters' script is attached. > As you can see from the copyright comment at the top, those two cooked > this script up long ago. Then I've been modifying it for my own > environment over the years. The Batch timing stats were this month's > addition due to HighRes. I prefer you add your own copyright comment at the top so we all know I am not the only one working on this. Perhaps a repository of homebrew scripts on the MS site is a good idea. > I really should get MailWatch or vispan going... That is on my to-do list for our new servers. I have been working on it for months now. And every time I think I can migrate the server I build to the other servers standing ready Julian comes up with a new neat feature that I have to test. - -- Peter Peters, senior beheerder (Security) Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE) Universiteit Twente, Postbus 217, 7500 AE Enschede telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQFD11dVMbmy+DDgnIURAk7PAJ0dFGWH3DOCKssTiBLey9DR/3ap6gCePB1U VEt0i5H5LXl94kH6bYPF/pA= =2EdW -----END PGP SIGNATURE----- From micoots at yahoo.com Wed Jan 25 11:58:53 2006 From: micoots at yahoo.com (Michael Mansour) Date: Wed Jan 25 11:58:56 2006 Subject: Additional perl modules Message-ID: <20060125115853.20605.qmail@web36209.mail.mud.yahoo.com> Hi, I have installed the MailScanner 4.50.12-2 rpm. I run through the install.sh and everything installs fine, but the following are not installed (for whatever reason): perl-File-Spec perl-File-Temp perl-Getopt-Long What do each of these modules do? I can/do run "rpmbuild --rebuild blah.src.rpm" and they rebuild fine, where I can then install them. If I manually install the RPM's in that way, will MailScanner actually use them? (ie. does MailScanner detect features when it runs/is running?) Thanks. Michael. ____________________________________________________ Do you Yahoo!? The New Yahoo! Movies: Check out the Latest Trailers, Premiere Photos and full Actor Database. http://au.movies.yahoo.com From MailScanner at ecs.soton.ac.uk Wed Jan 25 12:08:38 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Jan 25 12:08:47 2006 Subject: Additional perl modules In-Reply-To: <20060125115853.20605.qmail@web36209.mail.mud.yahoo.com> References: <20060125115853.20605.qmail@web36209.mail.mud.yahoo.com> Message-ID: <3494263C-CE5F-4BAF-B1BA-E3981950A55E@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Don't worry about those, they are probably already included in your Perl installation anyway. On 25 Jan 2006, at 11:58, Michael Mansour wrote: > Hi, > > I have installed the MailScanner 4.50.12-2 rpm. > > I run through the install.sh and everything installs > fine, but the following are not installed (for > whatever reason): > > perl-File-Spec > perl-File-Temp > perl-Getopt-Long > > What do each of these modules do? > > I can/do run "rpmbuild --rebuild blah.src.rpm" and > they rebuild fine, where I can then install them. If I > manually install the RPM's in that way, will > MailScanner actually use them? (ie. does MailScanner > detect features when it runs/is running?) > Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ9dqSPw32o+k+q+hAQG2uAgAo4fOMl0+ob8Q5XMhE6W5gDSo//SkjgvS ijv7ffM4vZd09Zlutj7NzJf52TWMegCcvwaiGIC5fgAzRsOAmG/cEmuIlo/mbEs4 EeqbQ3GBqL/wc6U3DDTpCRsViYeUp5O0gHmfnVKv6ZGTGNKMafzGHvQ18k5yRVJc 2PVL/Mu9AWvyCqWIuXn+gX+sqmQNpXYSlfCeK7ZbD+A4zGhTdFbXqklFVzL1hIZZ FMt5T5PFm2jym6iJnqFNm3oCMz8VpvSksIlDAUX/l9cLlH658/3LqiKoplOm6LG4 NoZ+kBOUKSEafFOm+4Zm+Gj25/4HSSz3pXpDitn9zxH3yw3Y0i378g== =nxE/ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From res at ausics.net Wed Jan 25 12:10:18 2006 From: res at ausics.net (Res) Date: Wed Jan 25 12:10:27 2006 Subject: RDNS In-Reply-To: <000001c6206b$ec624310$0632a8c0@oucpm1> References: <000001c6206b$ec624310$0632a8c0@oucpm1> Message-ID: On Mon, 23 Jan 2006, Darryl DeLao wrote: > Is there a way to turn on RDNS in Mailscanner, or is this done in Sendmail? > If so, how is it done? Basically, if an email comes in and the originating > domain can not be resolved, I do not want to accept the email in the system. > This is Sendmails job, remake your sendmail.cf with this hack http://support.ausics.net/require_rdns.m4 > > > Thanks, > > Darryl > > -- Cheers Res From jaearick at colby.edu Wed Jan 25 12:41:24 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Wed Jan 25 12:41:30 2006 Subject: Sophos sweep and password protected zip files In-Reply-To: References: Message-ID: I ran into this a while back. The following addition to MailScanner.conf solved this problem and let the encrypted files thru: Allowed Sophos Error Messages = "File was encrypted" Jeff Earickson Colby College On Wed, 25 Jan 2006, Ray Gardener wrote: > Date: Wed, 25 Jan 2006 09:42:18 +0000 (GMT) > From: Ray Gardener > Reply-To: MailScanner discussion > To: MailScanner discussion > Subject: Sophos sweep and password protected zip files > > Hi, > > yesterday, an end user reported that some of his mail was not being > delivered. On inspection the mail was a password protected zip file. Within > our mailscanner setup we have two virus scanners Sophos sweep and ClamAV. > Sophos was generating reports regarding this which caused mailscanner to > treat this as a virus (mailscanner report shown below) which was then > silently deleted. Is there an easy was to stop this happening? > > > version details: > > sophos: > Product version : 4.00.0 > Engine version : 2.32.5 > Virus data version : 4.00 > User interface version : 2.07.119 > Platform : Linux/Intel > Released : 05 December 2005 > > mailscanner: version 4.46.2 > > > and within Mailscanner.conf I already have set: > > Non-Forging Viruses = Joke/ OF97/ WM97/ W97M/ Zip-Password > > > mailscanner report starts > _______________________________________________________________________ > The following e-mails were found to have: Virus Detected > > > Quarantine: > Report: Sophos: Password protected file > ./1F1NHK-00083Q-Fe/SHU-fw.zip/whatwasthesecondary.txt > Sophos: Password protected file > ./1F1NHK-00083Q-Fe/SHU-fw.zip/primary.txt > ____________________________________________________________________ > mailscanner report ends > > > Regards, > > Ray Gardener > LITS > Sheffield Hallam University > 0114 225 4926 > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From glenn.steen at gmail.com Wed Jan 25 15:55:21 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Jan 25 15:55:24 2006 Subject: MS 4.50: way cool... In-Reply-To: <43D75755.5080903@utwente.nl> References: <008001c620d6$b7ed24e0$3004010a@martinhlaptop> <43D75755.5080903@utwente.nl> Message-ID: <223f97700601250755s5b21b54en@mail.gmail.com> On 25/01/06, Peter Peters wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Jeff, > > Jeff A. Earickson wrote on 24-1-2006 14:40: > > > My perl script, or Julian's, or Peter Peters' script is attached. > > As you can see from the copyright comment at the top, those two cooked > > this script up long ago. Then I've been modifying it for my own > > environment over the years. The Batch timing stats were this month's > > addition due to HighRes. > > I prefer you add your own copyright comment at the top so we all know I > am not the only one working on this. Perhaps a repository of homebrew > scripts on the MS site is a good idea. > I haven't checked, but if Jules permit file upload to the wiki, there is where it should go. -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From ugob at camo-route.com Wed Jan 25 16:02:28 2006 From: ugob at camo-route.com (Ugo Bellavance) Date: Wed Jan 25 16:10:27 2006 Subject: The article I wrote about mailscanner has been published Message-ID: (IN)SECURE Magazine is a freely available digital security magazine discussing some of the hottest information security topics. Issue 5 was just released. Download it from: http://www.insecuremag.com The covered topics are: * Web application firewalls primer * Review: Trustware BufferZone 1.6 * Threat analysis using log data * Looking back at computer security in 2005 * Writing an enterprise handheld security policy * Digital Rights Management * Revenge of the Web mob * Hardening Windows Server 2003 platforms made easy * Filtering spam server-side Visit the (IN)SECURE Magazine web site at: http://www.insecuremag.com ===================================== -> "Filtering spam server-side" is my article. Hope there are no major issues in it, I wrote it some time ago and I had something like 2 hours to do the final revision. I especially remember asking to add a comma between 'spam' and 'server' in the title, but, eh... BTW, this magazine is usually quite good, feel free to not only read my article ;). Regards, -- Ugo -> Please don't send a copy of your reply by e-mail. I read the list. -> Please avoid top-posting, long signatures and HTML, and cut the irrelevant parts in your replies. From ugob at camo-route.com Wed Jan 25 16:10:37 2006 From: ugob at camo-route.com (Ugo Bellavance) Date: Wed Jan 25 16:24:38 2006 Subject: Connection refused In-Reply-To: <006501c620f6$5b951b60$0632a8c0@oucpm1> References: <8F2A53954C22554EB75D9643FCCE0C6B8880@MED-CORE03-MS1.med.wayne.edu> <006501c620f6$5b951b60$0632a8c0@oucpm1> Message-ID: Darryl DeLao wrote: > I got mailscanner installed correctly, along with Spamassassin and Clamav. > It was working fine yesterday, but now connections are no longer allowed. > Everything is being deferred. Any ideas? Logs? > > Thanks, > Darryl > > > > -- Ugo -> Please don't send a copy of your reply by e-mail. I read the list. -> Please avoid top-posting, long signatures and HTML, and cut the irrelevant parts in your replies. From dave.list at pixelhammer.com Wed Jan 25 17:09:26 2006 From: dave.list at pixelhammer.com (DAve) Date: Wed Jan 25 17:09:42 2006 Subject: The article I wrote about mailscanner has been published In-Reply-To: References: Message-ID: <43D7B0C6.4030009@pixelhammer.com> Ugo Bellavance wrote: > (IN)SECURE Magazine is a freely available digital security magazine > discussing some of the hottest information security topics. > > Issue 5 was just released. Download it from: > http://www.insecuremag.com "Individual or small businesses will usually rely on the usually not-very-effective ISP spam filters or try client-side software." Ouch, that hurts. DAve From MailScanner at ecs.soton.ac.uk Wed Jan 25 17:27:05 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Jan 25 17:27:10 2006 Subject: The article I wrote about mailscanner has been published In-Reply-To: <43D7B0C6.4030009@pixelhammer.com> References: <43D7B0C6.4030009@pixelhammer.com> Message-ID: <43D7B4E9.3080601@ecs.soton.ac.uk> DAve wrote: > Ugo Bellavance wrote: >> (IN)SECURE Magazine is a freely available digital security magazine >> discussing some of the hottest information security topics. >> >> Issue 5 was just released. Download it from: >> http://www.insecuremag.com > > "Individual or small businesses will usually rely on > the usually not-very-effective ISP spam filters or try > client-side software." For "small businesses", include Microsoft in the list. They use manually, yes I said manually, maintained black-lists plus Outlook's spam filter. They deliver all their spam to the desktop and then try to filter it there! Read this if you want a laugh: http://www.microsoft.com/technet/itsolutions/msit/security/messaginghygienewp.mspx -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Wed Jan 25 17:30:46 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Jan 25 17:30:49 2006 Subject: The article I wrote about mailscanner has been published In-Reply-To: <43D7B4E9.3080601@ecs.soton.ac.uk> References: <43D7B0C6.4030009@pixelhammer.com> <43D7B4E9.3080601@ecs.soton.ac.uk> Message-ID: <43D7B5C6.5080605@ecs.soton.ac.uk> Julian Field wrote: > DAve wrote: >> Ugo Bellavance wrote: >>> (IN)SECURE Magazine is a freely available digital security magazine >>> discussing some of the hottest information security topics. >>> >>> Issue 5 was just released. Download it from: >>> http://www.insecuremag.com >> >> "Individual or small businesses will usually rely on >> the usually not-very-effective ISP spam filters or try >> client-side software." > For "small businesses", include Microsoft in the list. They use > manually, yes I said manually, maintained black-lists plus Outlook's > spam filter. They deliver all their spam to the desktop and then try > to filter it there! > > Read this if you want a laugh: > > http://www.microsoft.com/technet/itsolutions/msit/security/messaginghygienewp.mspx > > To be fair to them, they have changed this document rather a lot since they first published it back in April, and they now have some spam-scoring based system on Exchange. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ssilva at sgvwater.com Wed Jan 25 17:44:51 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Jan 25 17:48:57 2006 Subject: The article I wrote about mailscanner has been published In-Reply-To: <43D7B4E9.3080601@ecs.soton.ac.uk> References: <43D7B0C6.4030009@pixelhammer.com> <43D7B4E9.3080601@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 1/25/2006 9:27 AM: > DAve wrote: >> Ugo Bellavance wrote: >>> (IN)SECURE Magazine is a freely available digital security magazine >>> discussing some of the hottest information security topics. >>> >>> Issue 5 was just released. Download it from: >>> http://www.insecuremag.com >> >> "Individual or small businesses will usually rely on >> the usually not-very-effective ISP spam filters or try >> client-side software." > For "small businesses", include Microsoft in the list. They use > manually, yes I said manually, maintained black-lists plus Outlook's > spam filter. They deliver all their spam to the desktop and then try to > filter it there! > > Read this if you want a laugh: > > http://www.microsoft.com/technet/itsolutions/msit/security/messaginghygienewp.mspx > > I guess it does say something about "eating your own cooking", no matter how bad it might taste. -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () From glenn.steen at gmail.com Wed Jan 25 19:30:04 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Jan 25 19:30:07 2006 Subject: The article I wrote about mailscanner has been published In-Reply-To: References: Message-ID: <223f97700601251130l1912ca5cg@mail.gmail.com> On 25/01/06, Ugo Bellavance wrote: (snip) > -> "Filtering spam server-side" is my article. > > Hope there are no major issues in it, I wrote it some time ago and I had > something like 2 hours to do the final revision. I especially remember > asking to add a comma between 'spam' and 'server' in the title, but, eh... Well, there's some unbalanced quotes and the odd "will look at these 3...." and then go on to mention four....:-) But on the whole, it really turned out nice. Good job, Ugo! ... And who would've known you're an avid telemark skier! :-) -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From ka at pacific.net Wed Jan 25 21:49:40 2006 From: ka at pacific.net (Ken A) Date: Wed Jan 25 21:49:44 2006 Subject: SA cache not expiring entries? Message-ID: <43D7F274.8060300@pacific.net> On one server (FC4), the SA cache seemed to not be expiring entries. I was still seeing cache hits in the log, but no expiries running 4.50.5 It grew to about 650Mb before I decided to nuke it and start over to reclaim RAM (../incoming is in a tmpfs). I then installed the latest 4.50.12-2 from mailscanner.info and now I see the Expired entries again in the log so all is well. I'm wondering if updating the box with yum might have done something: The log shows these updates: Dec 16 11:11:17 Updated: perl-IO-stringy.noarch 2.110-2 Dec 16 11:11:18 Updated: perl-TimeDate.noarch 1:1.16-3 Dec 16 11:11:19 Updated: perl-MailTools.noarch 1.67-1.fc4 Dec 16 11:11:20 Updated: perl-MIME-tools.noarch 5.417-2 Dec 16 11:11:20 Updated: perl-Convert-TNEF.noarch 0.17-4 Could any of these have been the culprit? Perhaps I should tell YUM to leave perl modules alone, and just install those provided with MailScanner? Or, any other ideas why MailScanner might suddenly stop expiring entries from the cache? Thanks, Ken Pacific.Net From smf at f2s.com Wed Jan 25 22:27:11 2006 From: smf at f2s.com (Steve Freegard) Date: Wed Jan 25 22:27:04 2006 Subject: SA cache not expiring entries? In-Reply-To: <43D7F274.8060300@pacific.net> References: <43D7F274.8060300@pacific.net> Message-ID: <1138228032.8413.28.camel@localhost.localdomain> Hi Ken, On Wed, 2006-01-25 at 13:49 -0800, Ken A wrote: > Could any of these have been the culprit? > Perhaps I should tell YUM to leave perl modules alone, and just install > those provided with MailScanner? Nope - I don't think so. I uses regular SQL to expire the entries so if the cache actually works then the expiry should too. Next time, before nuking the database - run analyse_SpamAssassin_cache and post the output as it will show up any irregularities straight away. Cheers, Steve. From ka at pacific.net Wed Jan 25 22:43:14 2006 From: ka at pacific.net (Ken A) Date: Wed Jan 25 22:43:19 2006 Subject: SA cache not expiring entries? In-Reply-To: <1138228032.8413.28.camel@localhost.localdomain> References: <43D7F274.8060300@pacific.net> <1138228032.8413.28.camel@localhost.localdomain> Message-ID: <43D7FF02.7010202@pacific.net> Steve Freegard wrote: > Hi Ken, > > On Wed, 2006-01-25 at 13:49 -0800, Ken A wrote: > >> Could any of these have been the culprit? >> Perhaps I should tell YUM to leave perl modules alone, and just install >> those provided with MailScanner? > > Nope - I don't think so. I uses regular SQL to expire the entries so if > the cache actually works then the expiry should too. > > Next time, before nuking the database - run analyse_SpamAssassin_cache > and post the output as it will show up any irregularities straight away. Will do. Thanks, Ken > > Cheers, > Steve. > From Kevin_Miller at ci.juneau.ak.us Thu Jan 26 00:09:28 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Thu Jan 26 00:09:36 2006 Subject: winmail.dat Message-ID: <82895A755D1EA5458EC9E64021922AD2D15674@city-exch-w3e.cbj.local> Is it possible to strip the RTF junk out of inbound RTF messages? (something like the strip HTML option) I'm blocking them now via filetype but that's sorta draconian. When HTML mail comes in, it often has a text component, and the HTML "attachment". Does RTF do this too, or is the RTF MIME section the whole of the email? I'm under the impression that the winmail.dat section is the mail and it isn't replicated in the text body area but don't really know that for sure. I'd like to let the message through but throw away the winmail.dat attachment if possible. I waded through MailScanner.conf but nothing jumped out at me... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From hermit921 at yahoo.com Thu Jan 26 00:36:46 2006 From: hermit921 at yahoo.com (hermit921) Date: Thu Jan 26 00:40:03 2006 Subject: MailScanner chokes In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D15674@city-exch-w3e.cbj.l ocal> References: <82895A755D1EA5458EC9E64021922AD2D15674@city-exch-w3e.cbj.local> Message-ID: <6.2.1.2.2.20060125161634.0322c788@pop.mail.yahoo.com> We are starting to see a problem on 1 or 2 of our three MailScanner systems where mail starts accumulating in the hold queue. We tried various things, with little success. Turning off spamassassin in MailScanner made no difference. Stopping MailScanner and starting postfix, then doing postsuper -H ALL followed by postfix flush pushes out all the messages. Of course this bypasses MailScanner. In Debug mode, we get the following, which isn't much. We waited several minutes and this output never changed. Any ideas what is wrong? hermit921 Starting MailScanner - C to stop tail of /var/log/mail Initializing incoming postfixInitializing outgoing postfix done done Initializing MailScanner Jan 25 15:09:37 mail1 MailScanner[13530]: Config: calling custom end function MailWatchLogging Jan 25 15:09:37 mail1 MailScanner[13353]: MailScanner child caught a SIGHUP Jan 25 15:09:37 mail1 MailScanner[13353]: Config: calling custom end function MailWatchLogging Jan 25 15:09:37 mail1 MailScanner[13305]: MailScanner child caught a SIGHUP Jan 25 15:09:37 mail1 MailScanner[13305]: Config: calling custom end function MailWatchLogging Jan 25 15:09:37 mail1 MailScanner[13130]: MailScanner child caught a SIGHUP Jan 25 15:09:37 mail1 MailScanner[13130]: Config: calling custom end function MailWatchLogging Jan 25 15:09:47 mail1 postfix/postfix-script: starting the Postfix mail system Jan 25 15:09:47 mail1 postfix/master[13744]: daemon started -- version 2.1.1 In Debugging mode, not forking... Jan 25 15:09:48 mail1 MailScanner[13770]: MailScanner E-Mail Virus Scanner version 4.48.4 starting... Jan 25 15:09:48 mail1 MailScanner[13770]: Read 699 hostnames from the phishing whitelist Jan 25 15:09:48 mail1 MailScanner[13770]: Config: calling custom init function MailWatchLogging Jan 25 15:09:48 mail1 MailScanner[13770]: Started SQL Logging child = = = = = = = = = = = = = = = = = = = = = MailScanner version info: MailScanner --version Running on Linux mail1 2.6.5-7.202.7-smp #1 SMP Tue Nov 29 14:32:53 UTC 2005 i686 i686 i386 GNU/Linux This is SUSE LINUX Enterprise Server 9 (i586) This is Perl version 5.008003 (5.8.3) This is MailScanner version 4.48.4 Module versions are: 1.00 AnyDBM_File 1.14 Archive::Zip 1.01 Carp 1.119 Convert::BinHex 1.00 DirHandle 1.05 Fcntl 2.72 File::Basename 2.07 File::Copy 2.01 FileHandle 1.06 File::Path 0.14 File::Temp 1.29 HTML::Entities 3.45 HTML::Parser 2.30 HTML::TokeParser 1.21 IO 1.10 IO::File 1.122 IO::Pipe 1.60 Mail::Header 3.05 MIME::Base64 5.417 MIME::Decoder 5.417 MIME::Decoder::UU 5.417 MIME::Head 5.417 MIME::Parser 3.03 MIME::QuotedPrint 5.417 MIME::Tools 0.10 Net::CIDR 1.07 POSIX 1.76 Socket 0.04 Sys::Syslog 1.02 Time::localtime Optional module versions are: 0.17 Convert::TNEF 1.808 DB_File 1.08 Digest 1.01 Digest::HMAC 2.33 Digest::MD5 2.10 Digest::SHA1 0.44 Inline 0.17 Mail::ClamAV 3.001000 Mail::SpamAssassin 1.997 Mail::SPF::Query 0.18 Net::CIDR::Lite 0.53 Net::DNS missing Net::LDAP 1.94 Parse::RecDescent 0.30 SAVI 1.4 Sys::Hostname::Long 2.40 Test::Harness 0.47 Test::Simple 1.95 Text::Balanced 1.35 URI From ssilva at sgvwater.com Thu Jan 26 00:55:07 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Jan 26 00:55:29 2006 Subject: MailScanner chokes In-Reply-To: <6.2.1.2.2.20060125161634.0322c788@pop.mail.yahoo.com> References: <82895A755D1EA5458EC9E64021922AD2D15674@city-exch-w3e.cbj.local> <82895A755D1EA5458EC9E64021922AD2D15674@city-exch-w3e.cbj.l ocal> <6.2.1.2.2.20060125161634.0322c788@pop.mail.yahoo.com> Message-ID: hermit921 spake the following on 1/25/2006 4:36 PM: > We are starting to see a problem on 1 or 2 of our three MailScanner > systems where mail starts accumulating in the hold queue. We tried > various things, with little success. Turning off spamassassin in > MailScanner made no difference. Stopping MailScanner and starting > postfix, then doing postsuper -H ALL followed by postfix flush pushes > out all the messages. Of course this bypasses MailScanner. > > In Debug mode, we get the following, which isn't much. We waited > several minutes and this output never changed. Any ideas what is wrong? > Could the database be full? Corrupted? The file system the database is on full or out of inodes? Try and remove the call to the MailWatch logging module, and see if things clear up. That should clear up any doubt about the database being the culprit. -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () From ugob at camo-route.com Thu Jan 26 01:09:58 2006 From: ugob at camo-route.com (Ugo Bellavance) Date: Thu Jan 26 01:10:08 2006 Subject: The article I wrote about mailscanner has been published In-Reply-To: <223f97700601251130l1912ca5cg@mail.gmail.com> References: <223f97700601251130l1912ca5cg@mail.gmail.com> Message-ID: Glenn Steen wrote: > On 25/01/06, Ugo Bellavance wrote: > (snip) >> -> "Filtering spam server-side" is my article. >> >> Hope there are no major issues in it, I wrote it some time ago and I had >> something like 2 hours to do the final revision. I especially remember >> asking to add a comma between 'spam' and 'server' in the title, but, eh... > > Well, there's some unbalanced quotes and the odd "will look at these > 3...." and then go on to mention four....:-) > But on the whole, it really turned out nice. Good job, Ugo! > ... And who would've known you're an avid telemark skier! :-) Yeah, I thought they'd do more proofreading than that... and the final revision was done in less than hour, with my brain having a big sleep deficit... > > -- > -- Glenn > email: glenn < dot > steen < at > gmail < dot > com > work: glenn < dot > steen < at > ap1 < dot > se -- Ugo -> Please don't send a copy of your reply by e-mail. I read the list. -> Please avoid top-posting, long signatures and HTML, and cut the irrelevant parts in your replies. From jtwatson at linux-consulting.us Thu Jan 26 03:38:44 2006 From: jtwatson at linux-consulting.us (Joseph Watson) Date: Thu Jan 26 03:38:54 2006 Subject: Spam Header Content Message-ID: <200601252238.44176.jtwatson@linux-consulting.us> Hello, I am looking for information wether it is possible to change the content of the "Spam Header" when "Detailed Spam Report" is turned on. I am using MailScanner 4.49.7 and SpamAssassin 3.0.4. Currently I am getting the following in my Spam Header. X-Spam-Status: not spam, SpamAssassin (score=0.659, required 6, INFO_TLD 0.48, NO_REAL_NAME 0.18) Is it possible to change it to something like this?? Primarily I would like to get the score= and required= in the following format (Kmail uses this header format to display Spam Status). X-Spam-Status: No, score=1.7 required=7.0 tests=AWL,FORGED_RCVD_HELO, FR_SPAMSITE_GAOLAND autolearn=no version=3.0.4, not spam, SpamAssassin (score=0.05, required 6,autolearn=not spam, FORGED_RCVD_HELO 0.05) -- Regards Joseph Watson From superbaby at myjaring.net Thu Jan 26 08:23:31 2006 From: superbaby at myjaring.net (Lawrence Lam) Date: Thu Jan 26 08:23:43 2006 Subject: HOW: Setting "Spam List" ruleset. Message-ID: <43D88703.7000400@myjaring.net> When I send out emails from "*@mydomain.com", I do not want it to check the SBL+XBL list. How do I set the "sbl_xbl.rules" file below? Do I specify the IPs or the domain names to exclude? # This is the list of spam blacklists (RBLs) which you are using. # See the "Spam List Definitions" file for more information about what # you can put here. # This can also be the filename of a ruleset. Spam List = SBL+XBL spamcop.net CHANGED TO: Spam List = %rules-dir%/sbl_xbl.rules HOW DO I SET THE "sbl_xbl.rules" file? Thanks. From shuttlebox at gmail.com Thu Jan 26 09:01:59 2006 From: shuttlebox at gmail.com (shuttlebox) Date: Thu Jan 26 09:02:06 2006 Subject: HOW: Setting "Spam List" ruleset. In-Reply-To: <43D88703.7000400@myjaring.net> References: <43D88703.7000400@myjaring.net> Message-ID: <625385e30601260101h6c059eebg6830645fb5931050@mail.gmail.com> On 1/26/06, Lawrence Lam wrote: > > When I send out emails from "*@mydomain.com", I do not want it to check > the SBL+XBL list. How do I set the "sbl_xbl.rules" file below? Do I > specify the IPs or the domain names to exclude? > > # This is the list of spam blacklists (RBLs) which you are using. > # See the "Spam List Definitions" file for more information about what > # you can put here. > # This can also be the filename of a ruleset. > > Spam List = SBL+XBL spamcop.net > > CHANGED TO: > > Spam List = %rules-dir%/sbl_xbl.rules > > HOW DO I SET THE "sbl_xbl.rules" file? > This should work: From: @mydomain.com spamcop.net FromOrTo: default SBL+XBL spamcop.net But you should use the ip addresses of your mail servers instead of the domain name. Like this: From: 1.2.3.4 spamcop.net -- /peter -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060126/31c94e44/attachment.html From martinh at solid-state-logic.com Thu Jan 26 09:01:19 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Thu Jan 26 09:02:59 2006 Subject: Spam Header Content In-Reply-To: <200601252238.44176.jtwatson@linux-consulting.us> Message-ID: <05ae01c62257$39ea18a0$3004010a@martinhlaptop> Joseph That's a spamassassin header not a mailscanner header. Are you sure you're not calling SA from the MTA rather than MailScanner? -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Joseph Watson > Sent: 26 January 2006 03:39 > To: mailscanner@lists.mailscanner.info > Subject: Spam Header Content > > Hello, > > I am looking for information wether it is possible to change the content > of > the "Spam Header" when "Detailed Spam Report" is turned on. I am using > MailScanner 4.49.7 and SpamAssassin 3.0.4. > > Currently I am getting the following in my Spam Header. > > X-Spam-Status: not spam, SpamAssassin (score=0.659, required 6, > INFO_TLD 0.48, NO_REAL_NAME 0.18) > > Is it possible to change it to something like this?? Primarily I would > like > to get the score= and required= in the following format (Kmail uses this > header format to display Spam Status). > > X-Spam-Status: No, score=1.7 required=7.0 tests=AWL,FORGED_RCVD_HELO, > FR_SPAMSITE_GAOLAND autolearn=no version=3.0.4, not spam, > SpamAssassin (score=0.05, required 6,autolearn=not spam, > FORGED_RCVD_HELO 0.05) > > > -- > Regards > > Joseph Watson > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From superbaby at myjaring.net Thu Jan 26 12:43:28 2006 From: superbaby at myjaring.net (Lawrence Lam) Date: Thu Jan 26 12:43:43 2006 Subject: HOW: Setting "Spam List" ruleset. In-Reply-To: <625385e30601260101h6c059eebg6830645fb5931050@mail.gmail.com> References: <43D88703.7000400@myjaring.net> <625385e30601260101h6c059eebg6830645fb5931050@mail.gmail.com> Message-ID: <43D8C3F0.9080601@myjaring.net> I thought it should be like the below if I do not want my emails checked: FromOrTo: 61.50.* FromOrTo: default SBL+XBL spamcop.net I use dynamic IP that starts with 61.50.* But I don't think I should include "spamcop.net" after the IP, right (since I do not want my emails checked)? shuttlebox wrote: > On 1/26/06, *Lawrence Lam* > wrote: > > When I send out emails from "*@mydomain.com ", > I do not want it to check > the SBL+XBL list. How do I set the "sbl_xbl.rules" file below? Do I > specify the IPs or the domain names to exclude? > > # This is the list of spam blacklists (RBLs) which you are using. > # See the "Spam List Definitions" file for more information about what > # you can put here. > # This can also be the filename of a ruleset. > > Spam List = SBL+XBL spamcop.net > > CHANGED TO: > > Spam List = %rules-dir%/sbl_xbl.rules > > HOW DO I SET THE "sbl_xbl.rules" file? > > > This should work: > > From: @mydomain.com spamcop.net > FromOrTo: default SBL+XBL spamcop.net > > But you should use the ip addresses of your mail servers instead of the > domain name. Like this: > > From: 1.2.3.4 spamcop.net > > -- > /peter > From shuttlebox at gmail.com Thu Jan 26 13:23:51 2006 From: shuttlebox at gmail.com (shuttlebox) Date: Thu Jan 26 13:23:55 2006 Subject: HOW: Setting "Spam List" ruleset. In-Reply-To: <43D8C3F0.9080601@myjaring.net> References: <43D88703.7000400@myjaring.net> <625385e30601260101h6c059eebg6830645fb5931050@mail.gmail.com> <43D8C3F0.9080601@myjaring.net> Message-ID: <625385e30601260523m7d4debb3ua0eb164fd6626528@mail.gmail.com> On 1/26/06, Lawrence Lam wrote: > > I thought it should be like the below if I do not want my emails checked: > > FromOrTo: 61.50.* > FromOrTo: default SBL+XBL spamcop.net > > I use dynamic IP that starts with 61.50.* > > But I don't think I should include "spamcop.net" after the IP, right > (since I do not want my emails checked)? > I thought you still wanted to check with spamcop and just remove SBL+XBL if the mail was local. Note that by using FromOrTo with your IP you match everything and that's probably not what you want. -- /peter -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060126/4b54e44b/attachment.html From superbaby at myjaring.net Thu Jan 26 14:17:48 2006 From: superbaby at myjaring.net (Lawrence Lam) Date: Thu Jan 26 14:17:07 2006 Subject: HOW: Setting "Spam List" ruleset. In-Reply-To: <625385e30601260523m7d4debb3ua0eb164fd6626528@mail.gmail.com> References: <43D88703.7000400@myjaring.net> <625385e30601260101h6c059eebg6830645fb5931050@mail.gmail.com> <43D8C3F0.9080601@myjaring.net> <625385e30601260523m7d4debb3ua0eb164fd6626528@mail.gmail.com> Message-ID: <43D8DA0C.9030607@myjaring.net> So it should be like this, correct? From: 61.50.* spamcop.net FromOrTo: default SBL+XBL spamcop.net shuttlebox wrote: > On 1/26/06, *Lawrence Lam* > wrote: > > I thought it should be like the below if I do not want my emails > checked: > > FromOrTo: 61.50.* > FromOrTo: default SBL+XBL spamcop.net > > I use dynamic IP that starts with 61.50.* > > But I don't think I should include "spamcop.net > " after the IP, right > (since I do not want my emails checked)? > > > I thought you still wanted to check with spamcop and just remove SBL+XBL > if the mail was local. > > Note that by using FromOrTo with your IP you match everything and that's > probably not what you want. > > -- > /peter > From MailScanner at ecs.soton.ac.uk Thu Jan 26 14:26:44 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 26 14:26:54 2006 Subject: HOW: Setting "Spam List" ruleset. In-Reply-To: <43D8DA0C.9030607@myjaring.net> References: <43D88703.7000400@myjaring.net> <625385e30601260101h6c059eebg6830645fb5931050@mail.gmail.com> <43D8C3F0.9080601@myjaring.net> <625385e30601260523m7d4debb3ua0eb164fd6626528@mail.gmail.com> <43D8DA0C.9030607@myjaring.net> Message-ID: <2D68B069-4234-4386-87C2-33A3718FD054@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Correct. On 26 Jan 2006, at 14:17, Lawrence Lam wrote: > > So it should be like this, correct? > > From: 61.50.* spamcop.net > FromOrTo: default SBL+XBL spamcop.net > > > shuttlebox wrote: >> On 1/26/06, *Lawrence Lam* > > wrote: >> I thought it should be like the below if I do not want my emails >> checked: >> FromOrTo: 61.50.* >> FromOrTo: default SBL+XBL spamcop.net >> I use dynamic IP that starts with 61.50.* >> But I don't think I should include "spamcop.net >> " after the IP, right >> (since I do not want my emails checked)? >> I thought you still wanted to check with spamcop and just remove >> SBL+XBL if the mail was local. >> Note that by using FromOrTo with your IP you match everything and >> that's probably not what you want. >> -- >> /peter - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ9jcJvw32o+k+q+hAQFLaAgApddj2LApaxOGWLUVKSXmNBDJrXZ2yBIa 0e6dUv9/Vt8/QMH4TLzNSVj9+3Vbecmd7Ub55eVp5VBc/a3OEiTS1Sjjo6N7w3oY N8X5O8nTSNKXezzyPP28vU7oCjtRDwE7AbblrVaZ/UeTl3Oi90dMSflffaMqXY0R il6cULl6trkMDFBy1m9i4P+AbZu0q6oM+xhceHqZipth1DqCZsVwVcn20qxuZ/lp 2e3VlVLF4BfOPDTQ8Om0m9Kcztn+fQkJqa6vMtS34kyqOVCyphlAVOMA4JkqW2a1 9ONukm20sjINQqzufBaq1uefplOrh16elxu4DwYIYQO7Cv/fdiyF6g== =ifa9 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From superbaby at myjaring.net Thu Jan 26 14:32:27 2006 From: superbaby at myjaring.net (Lawrence Lam) Date: Thu Jan 26 14:31:34 2006 Subject: HOW: Setting "Spam List" ruleset. In-Reply-To: <2D68B069-4234-4386-87C2-33A3718FD054@ecs.soton.ac.uk> References: <43D88703.7000400@myjaring.net> <625385e30601260101h6c059eebg6830645fb5931050@mail.gmail.com> <43D8C3F0.9080601@myjaring.net> <625385e30601260523m7d4debb3ua0eb164fd6626528@mail.gmail.com> <43D8DA0C.9030607@myjaring.net> <2D68B069-4234-4386-87C2-33A3718FD054@ecs.soton.ac.uk> Message-ID: <43D8DD7B.4090107@myjaring.net> Thanks. Just implemented. Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > > Correct. > > On 26 Jan 2006, at 14:17, Lawrence Lam wrote: > > >>So it should be like this, correct? >> >>From: 61.50.* spamcop.net >>FromOrTo: default SBL+XBL spamcop.net >> >> >>shuttlebox wrote: >> >>>On 1/26/06, *Lawrence Lam* >>> wrote: >>> I thought it should be like the below if I do not want my emails >>> checked: >>> FromOrTo: 61.50.* >>> FromOrTo: default SBL+XBL spamcop.net >>> I use dynamic IP that starts with 61.50.* >>> But I don't think I should include "spamcop.net >>> " after the IP, right >>> (since I do not want my emails checked)? >>>I thought you still wanted to check with spamcop and just remove >>>SBL+XBL if the mail was local. >>>Note that by using FromOrTo with your IP you match everything and >>>that's probably not what you want. >>>-- >>>/peter > > > - -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.0.4 (Build 4042) > > iQEVAwUBQ9jcJvw32o+k+q+hAQFLaAgApddj2LApaxOGWLUVKSXmNBDJrXZ2yBIa > 0e6dUv9/Vt8/QMH4TLzNSVj9+3Vbecmd7Ub55eVp5VBc/a3OEiTS1Sjjo6N7w3oY > N8X5O8nTSNKXezzyPP28vU7oCjtRDwE7AbblrVaZ/UeTl3Oi90dMSflffaMqXY0R > il6cULl6trkMDFBy1m9i4P+AbZu0q6oM+xhceHqZipth1DqCZsVwVcn20qxuZ/lp > 2e3VlVLF4BfOPDTQ8Om0m9Kcztn+fQkJqa6vMtS34kyqOVCyphlAVOMA4JkqW2a1 > 9ONukm20sjINQqzufBaq1uefplOrh16elxu4DwYIYQO7Cv/fdiyF6g== > =ifa9 > -----END PGP SIGNATURE----- > From jtwatson at linux-consulting.us Thu Jan 26 14:37:29 2006 From: jtwatson at linux-consulting.us (Joseph Watson) Date: Thu Jan 26 14:37:42 2006 Subject: Spam Header Content In-Reply-To: <05ae01c62257$39ea18a0$3004010a@martinhlaptop> References: <05ae01c62257$39ea18a0$3004010a@martinhlaptop> Message-ID: <200601260937.29934.jtwatson@linux-consulting.us> That is what I thought initially, but you have the option in MailScanner to set the name of this header with the "Spam Header" config option, so it seems that MailScanner has some role in it. Yes SpamAssassin is invoked by MailScanner and not my MTA (Postfix). Thanks much for the reply. -- Regards Joseph Watson On Thursday January 26 2006 04:01 am, Martin Hepworth wrote: > Joseph > > That's a spamassassin header not a mailscanner header. Are you sure you're > not calling SA from the MTA rather than MailScanner? > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Joseph Watson > > Sent: 26 January 2006 03:39 > > To: mailscanner@lists.mailscanner.info > > Subject: Spam Header Content > > > > Hello, > > > > I am looking for information wether it is possible to change the content > > of > > the "Spam Header" when "Detailed Spam Report" is turned on. I am using > > MailScanner 4.49.7 and SpamAssassin 3.0.4. > > > > Currently I am getting the following in my Spam Header. > > > > X-Spam-Status: not spam, SpamAssassin (score=0.659, required 6, > > INFO_TLD 0.48, NO_REAL_NAME 0.18) > > > > Is it possible to change it to something like this?? Primarily I would > > like > > to get the score= and required= in the following format (Kmail uses this > > header format to display Spam Status). > > > > X-Spam-Status: No, score=1.7 required=7.0 tests=AWL,FORGED_RCVD_HELO, > > FR_SPAMSITE_GAOLAND autolearn=no version=3.0.4, not spam, > > SpamAssassin (score=0.05, required 6,autolearn=not spam, > > FORGED_RCVD_HELO 0.05) > > > > > > -- > > Regards > > > > Joseph Watson > > -- > > MailScanner mailing list > > MailScanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > ********************************************************************** > > This email and any files transmitted with it are confidential and > intended solely for the use of the individual or entity to whom they > are addressed. If you have received this email in error please notify > the system manager. > > This footnote confirms that this email message has been swept > for the presence of computer viruses and is believed to be clean. > > ********************************************************************** > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From root at doctor.nl2k.ab.ca Thu Jan 26 14:43:05 2006 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Thu Jan 26 14:45:12 2006 Subject: [management@wellsfargo.com: Wells Fargo Bank Online] Message-ID: <20060126144305.GA8869@doctor.nl2k.ab.ca> Received: from george.networkeleven.net (george.networkeleven.net [66.162.134.138]) Can we add 66.162.134.138 to phishing sites? ----- Forwarded message from Wells Fargo Bank Online ----- Return-Path: doctor@doctor.nl2k.ab.ca Received: from doctor.nl2k.ab.ca (doctor@localhost.nl2k.ab.ca [127.0.0.1]) by doctor.nl2k.ab.ca (8.13.5/8.13.5) with ESMTP id k0QDPsFb023804 for ; Thu, 26 Jan 2006 06:25:54 -0700 (MST) Received: (from doctor@localhost) by doctor.nl2k.ab.ca (8.13.5/8.13.5/Submit) id k0QDPsYQ023802 for root@doctor.nl2k.ab.ca; Thu, 26 Jan 2006 06:25:54 -0700 (MST) Resent-From: doctor@doctor.nl2k.ab.ca Resent-Date: Thu, 26 Jan 2006 06:25:53 -0700 Resent-Message-ID: <20060126132553.GA22882@doctor.nl2k.ab.ca> Resent-To: "Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem" Received: from george.networkeleven.net (george.networkeleven.net [66.162.134.138]) by doctor.nl2k.ab.ca (8.13.5/8.13.5) with ESMTP id k0QBWrM5011011 for ; Thu, 26 Jan 2006 04:32:54 -0700 (MST) X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org Received: from nobody by george.networkeleven.net with local (Exim 4.52) id 1F25N0-0007gs-U2 for doctor@doctor.nl2k.ab.ca; Thu, 26 Jan 2006 03:32:54 -0800 To: doctor@doctor.nl2k.ab.ca Subject: Wells Fargo Bank Online From: Wells Fargo Bank Online Reply-To: MIME-Version: 1.0 Content-Type: text/html Content-Transfer-Encoding: 8bit Message-Id: Date: Thu, 26 Jan 2006 03:32:54 -0800 X-AntiAbuse: This header was added to track abuse, please include it with any abuse report X-AntiAbuse: Primary Hostname - george.networkeleven.net X-AntiAbuse: Original Domain - doctor.nl2k.ab.ca X-AntiAbuse: Originator/Caller UID/GID - [99 99] / [47 12] X-AntiAbuse: Sender Address Domain - george.networkeleven.net X-Source: X-Source-Args: X-Source-Dir: X-Virus-Scanned: ClamAV version 0.88, clamav-milter version 0.87 on doctor.nl2k.ab.ca X-Virus-Scanned: ClamAV version 0.88, clamav-milter version 0.87 on doctor.nl2k.ab.ca X-Virus-Status: Clean X-netknowJan2006-MailScanner: Found to be clean, Found to be clean X-netknowJan2006-MailScanner-SpamScore: ssss X-netknowJan2006-MailScanner-Information: Please contact the ISP for more information X-netknowJan2006-MailScanner-From: doctor@doctor.nl2k.ab.ca Untitled Document




Dear Customer Of The WellsFargo Internet Banking

?
We Have Noticed That Your Wells Fargo Online Bank Account Needs To Be Updated, because we have made a new updates on our online banking service and we lost some information of our customer online banking accounts, we are sorry for that but you should update your Wells Fargo online bank account. To verify your online account and access your bank account, to be able to send and recive money online.

please click on the link below to continue :

simply sign on from Account Services to Active Your Account .

Have additional questions? Send us an email by clicking on "Contact Us" while you are signed on to Online Banking, or call 1-800-956-4442. We're available 24 hours a day, 7 days a week.

Sincerely,

R. Thomas
Senior Vice President

A Note About Online Security
Be advised, Wells Fargo will never require you to send personal or financial information through email or pop-up windows. If you receive an email or pop-up requesting your Wells Fargo account information, consider it fraudulent and report it immediately to Wells Fargo Online Fraud Prevention at: https://www.wellsfargo.com/help/signon.jhtml.


About Wells Fargo | Employment | PRIVACY, Security & Legal | Report Email Fraud | Home
Diversity & Accessibility | Online Access Agreement (9/10/05) | Important Notice on Trading in Fast Markets

? 1999 - 2006 Wells Fargo. All Rights Reserved. Member FDIC.


--
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean. ----- End forwarded message ----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ddelao at oucpm.org Thu Jan 26 15:02:38 2006 From: ddelao at oucpm.org (Darryl DeLao) Date: Thu Jan 26 15:03:11 2006 Subject: Running as root Message-ID: <00d901c62289$8c907860$0632a8c0@oucpm1> Is there any dangers to running MailScanner as root? What user should it run under? -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060126/293ac412/attachment.html From michele at blacknight.ie Thu Jan 26 15:12:44 2006 From: michele at blacknight.ie (Michele Neylon :: Blacknight Solutions) Date: Thu Jan 26 15:12:48 2006 Subject: [management@wellsfargo.com: Wells Fargo Bank Online] In-Reply-To: <20060126144305.GA8869@doctor.nl2k.ab.ca> Message-ID: <006f01c6228a$f5c70550$453711d4@arthur> Dave Shariff Yadallee - System Administrator a.k.a. The Root of theProblem <> said on 26 January 2006 14:43: > Received: from george.networkeleven.net (george.networkeleven.net > [66.162.134.138]) > > Can we add 66.162.134.138 to phishing sites? > What's the point? I presume you are referring to the phishing sites list, which is actually a whitelist not a blocklist .. Mr Michele Neylon Blacknight Solutions Hosting & Colocation, Brand Protection http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 UK: 0870 163 0607 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 From MailScanner at ecs.soton.ac.uk Thu Jan 26 15:29:06 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 26 15:29:17 2006 Subject: Running as root In-Reply-To: <00d901c62289$8c907860$0632a8c0@oucpm1> References: <00d901c62289$8c907860$0632a8c0@oucpm1> Message-ID: <9B3D9F52-FF0D-487E-B029-7DF3D07C27A1@ecs.soton.ac.uk> Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: PGP.sig Type: application/pgp-signature Size: 487 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060126/87797a43/PGP.bin From ddelao at oucpm.org Thu Jan 26 15:31:33 2006 From: ddelao at oucpm.org (Darryl DeLao) Date: Thu Jan 26 15:32:20 2006 Subject: Running as root In-Reply-To: <9B3D9F52-FF0D-487E-B029-7DF3D07C27A1@ecs.soton.ac.uk> Message-ID: <00ee01c6228d$969ef210$0632a8c0@oucpm1> If I leave those settings blank in the conf file, does it run as root by default? _____ From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian Field Sent: Thursday, January 26, 2006 9:29 AM To: MailScanner discussion Subject: Re: Running as root On 26 Jan 2006, at 15:02, Darryl DeLao wrote: Is there any dangers to running MailScanner as root? What user should it run under? It needs to run as the same user as your MTA. It does not interact with the outside world at all (that's the job of your MTA) so root is pretty safe. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060126/9cce4be3/attachment.html From jaearick at colby.edu Thu Jan 26 15:39:18 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Thu Jan 26 15:39:26 2006 Subject: winmail.dat In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D15674@city-exch-w3e.cbj.local> References: <82895A755D1EA5458EC9E64021922AD2D15674@city-exch-w3e.cbj.local> Message-ID: I have to second this idea. I'm using 4.50.12 with the "deny winmail.dat" line in filename.rules.conf and I've gotten some complaints about rejected emails as a result. Rejection is harsh if the winmail.dat file can be snipped off without loosing the basic message. Jeff Earickson Colby College On Wed, 25 Jan 2006, Kevin Miller wrote: > Date: Wed, 25 Jan 2006 15:09:28 -0900 > From: Kevin Miller > Reply-To: MailScanner discussion > To: MailScanner discussion > Subject: winmail.dat > > Is it possible to strip the RTF junk out of inbound RTF messages? > (something like the strip HTML option) I'm blocking them now via > filetype but that's sorta draconian. When HTML mail comes in, it often > has a text component, and the HTML "attachment". Does RTF do this too, > or is the RTF MIME section the whole of the email? I'm under the > impression that the winmail.dat section is the mail and it isn't > replicated in the text body area but don't really know that for sure. > I'd like to let the message through but throw away the winmail.dat > attachment if possible. > > I waded through MailScanner.conf but nothing jumped out at me... > > ...Kevin > -- > Kevin Miller Registered Linux User No: 307357 > CBJ MIS Dept. Network Systems Admin., Mail Admin. > 155 South Seward Street ph: (907) 586-0242 > Juneau, Alaska 99801 fax: (907 586-4500 > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From MailScanner at ecs.soton.ac.uk Thu Jan 26 15:56:38 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 26 15:56:51 2006 Subject: Running as root In-Reply-To: <00ee01c6228d$969ef210$0632a8c0@oucpm1> References: <00ee01c6228d$969ef210$0632a8c0@oucpm1> Message-ID: Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: PGP.sig Type: application/pgp-signature Size: 487 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060126/9f78dbf6/PGP.bin From martinh at solid-state-logic.com Thu Jan 26 15:59:28 2006 From: martinh at solid-state-logic.com (Martin Hepworth) Date: Thu Jan 26 16:00:35 2006 Subject: winmail.dat In-Reply-To: Message-ID: <067301c62291$9791b9b0$3004010a@martinhlaptop> >From what I've seen of the winmail.dat's I've had to release.. I'd say you'd have to unpack the thing with tnef......but I agree blanket ban on winmail.dat is harsh and I've to remove this check. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Jeff A. Earickson > Sent: 26 January 2006 15:39 > To: MailScanner discussion > Subject: Re: winmail.dat > > I have to second this idea. I'm using 4.50.12 with the "deny winmail.dat" > line in filename.rules.conf and I've gotten some complaints about > rejected emails as a result. Rejection is harsh if the winmail.dat > file can be snipped off without loosing the basic message. > > Jeff Earickson > Colby College > > On Wed, 25 Jan 2006, Kevin Miller wrote: > > > Date: Wed, 25 Jan 2006 15:09:28 -0900 > > From: Kevin Miller > > Reply-To: MailScanner discussion > > To: MailScanner discussion > > Subject: winmail.dat > > > > Is it possible to strip the RTF junk out of inbound RTF messages? > > (something like the strip HTML option) I'm blocking them now via > > filetype but that's sorta draconian. When HTML mail comes in, it often > > has a text component, and the HTML "attachment". Does RTF do this too, > > or is the RTF MIME section the whole of the email? I'm under the > > impression that the winmail.dat section is the mail and it isn't > > replicated in the text body area but don't really know that for sure. > > I'd like to let the message through but throw away the winmail.dat > > attachment if possible. > > > > I waded through MailScanner.conf but nothing jumped out at me... > > > > ...Kevin > > -- > > Kevin Miller Registered Linux User No: 307357 > > CBJ MIS Dept. Network Systems Admin., Mail Admin. > > 155 South Seward Street ph: (907) 586-0242 > > Juneau, Alaska 99801 fax: (907 586-4500 > > > > -- > > MailScanner mailing list > > MailScanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the system manager. This footnote confirms that this email message has been swept for the presence of computer viruses and is believed to be clean. ********************************************************************** From mkettler at evi-inc.com Thu Jan 26 16:48:44 2006 From: mkettler at evi-inc.com (Matt Kettler) Date: Thu Jan 26 16:49:04 2006 Subject: Running as root In-Reply-To: <9B3D9F52-FF0D-487E-B029-7DF3D07C27A1@ecs.soton.ac.uk> References: <00d901c62289$8c907860$0632a8c0@oucpm1> <9B3D9F52-FF0D-487E-B029-7DF3D07C27A1@ecs.soton.ac.uk> Message-ID: <43D8FD6C.3010102@evi-inc.com> Julian Field wrote: > On 26 Jan 2006, at 15:02, Darryl DeLao wrote: > >> Is there any dangers to running MailScanner as root? What user should >> it run under? >> > It needs to run as the same user as your MTA. It does not interact with > the outside world at all (that's the job of your MTA) so root is pretty > safe. Unless of course your AV has a security flaw which can be exploited by feeding it malformed data. Many AV products have recently had fixes for such holes in their handling of various compressed or "encrypted" executables. From ssilva at sgvwater.com Thu Jan 26 17:00:22 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Jan 26 17:01:43 2006 Subject: HOW: Setting "Spam List" ruleset. In-Reply-To: <43D8C3F0.9080601@myjaring.net> References: <43D88703.7000400@myjaring.net> <625385e30601260101h6c059eebg6830645fb5931050@mail.gmail.com> <43D8C3F0.9080601@myjaring.net> Message-ID: Lawrence Lam spake the following on 1/26/2006 4:43 AM: > I thought it should be like the below if I do not want my emails checked: > > FromOrTo: 61.50.* > FromOrTo: default SBL+XBL spamcop.net > > I use dynamic IP that starts with 61.50.* > You do realize that if your dynamic ip range is picked up when you send on those lists, you will be blocked, or at least tagged as spam, by a large portion of the people you send mail to. My site drops mails found on the SBL+XBL list, as do many other sites. If you want reliable mail service, you should look into getting either a static IP, or a smarthost somewhere to route your mail through. Just trying to help you avoid problems. -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () From ugob at camo-route.com Thu Jan 26 18:17:37 2006 From: ugob at camo-route.com (Ugo Bellavance) Date: Thu Jan 26 18:19:00 2006 Subject: Running as root In-Reply-To: <43D8FD6C.3010102@evi-inc.com> References: <00d901c62289$8c907860$0632a8c0@oucpm1> <9B3D9F52-FF0D-487E-B029-7DF3D07C27A1@ecs.soton.ac.uk> <43D8FD6C.3010102@evi-inc.com> Message-ID: Matt Kettler wrote: > Julian Field wrote: >> On 26 Jan 2006, at 15:02, Darryl DeLao wrote: >> >>> Is there any dangers to running MailScanner as root? What user should >>> it run under? >>> >> It needs to run as the same user as your MTA. It does not interact with >> the outside world at all (that's the job of your MTA) so root is pretty >> safe. > > Unless of course your AV has a security flaw which can be exploited by feeding > it malformed data. Many AV products have recently had fixes for such holes in > their handling of various compressed or "encrypted" executables. > Here is a recent one: http://www.f-secure.com/security/fsc-2006-1.shtml -- Ugo -> Please don't send a copy of your reply by e-mail. I read the list. -> Please avoid top-posting, long signatures and HTML, and cut the irrelevant parts in your replies. From hermit921 at yahoo.com Thu Jan 26 18:53:25 2006 From: hermit921 at yahoo.com (hermit921) Date: Thu Jan 26 18:53:30 2006 Subject: MailScanner chokes In-Reply-To: References: <82895A755D1EA5458EC9E64021922AD2D15674@city-exch-w3e.cbj.local> <82895A755D1EA5458EC9E64021922AD2D15674@city-exch-w3e.cbj.l ocal> <6.2.1.2.2.20060125161634.0322c788@pop.mail.yahoo.com> Message-ID: <6.2.1.2.2.20060126105139.03169d00@pop.mail.yahoo.com> At 04:55 PM 1/25/2006, Scott Silva wrote: >hermit921 spake the following on 1/25/2006 4:36 PM: > > We are starting to see a problem on 1 or 2 of our three MailScanner > > systems where mail starts accumulating in the hold queue. We tried > > various things, with little success. Turning off spamassassin in > > MailScanner made no difference. Stopping MailScanner and starting > > postfix, then doing postsuper -H ALL followed by postfix flush pushes > > out all the messages. Of course this bypasses MailScanner. > > > > In Debug mode, we get the following, which isn't much. We waited > > several minutes and this output never changed. Any ideas what is wrong? > > >Could the database be full? Corrupted? The file system the database is on full >or out of inodes? >Try and remove the call to the MailWatch logging module, and see if things >clear up. That should clear up any doubt about the database being the culprit. > >-- We had changed the Always Looked Up Last line to no, but that made no difference. The system has lots of free disk space, inodes, etc. hermit921 From Kevin_Miller at ci.juneau.ak.us Thu Jan 26 19:15:42 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Thu Jan 26 19:15:51 2006 Subject: Typo in the reports Message-ID: <82895A755D1EA5458EC9E64021922AD2D1567F@city-exch-w3e.cbj.local> In sender.error.report.txt there's a typo. It says: 2) Got to the "Mail Format" tab _____^_________________________ Believe that should be "Go", not "Got". Edited mine, but thought I'd mention it for future releases... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From ddelao at oucpm.org Thu Jan 26 19:54:41 2006 From: ddelao at oucpm.org (Darryl DeLao) Date: Thu Jan 26 19:55:13 2006 Subject: Mail Test Message-ID: <012901c622b2$590c76f0$0632a8c0@oucpm1> Does anyone know of a program or site that allows me to send hundreds of test emails at once? I want to load test my server with Mailscanner running. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060126/ee8a17f4/attachment.html From mhw at WittsEnd.com Thu Jan 26 20:00:08 2006 From: mhw at WittsEnd.com (Michael H. Warfield) Date: Thu Jan 26 20:00:16 2006 Subject: Evolution + GPG + MailScanner = Bad Juju... Message-ID: <1138305608.15604.189.camel@canyon.wittsend.com> Ok all, I'm cross posting this to both Evolution and MailScanner because I can already predict the finger pointing that's naturally going to result. A few months ago, someone brought it to my attention that my GPG signatures (messages signed only, not encrypted) where suddenly turning up "bad". The signature on this message will probably be "bad". It took some major head scratching to figure out what changed, what the parameters where, and what the hell was happening but I think I've got in narrowed down to some poor behavior on the part of BOTH Evolution AND MailScanner (or a component of MailScanner - not sure). It seems to have initially broken with an upgrade to MailScanner. I think upgrading to 4.47.4-2 or there abouts might have been the triggering event, but I don't remember what I was running on that server prior to that. Before then, all my signatures GPG signatures were good. After, they were bad. If I turn off MailScanner on my server, the signatures are good. I have accounts on several servers and the signatures are bad if I forward mail through one running a recent version of MailScanner. I just upgraded one of my servers to 4.50.5-12 and now I've got bad signatures through that server as well (I wasn't running MailScanner on that one before). But, that doesn't get Evolution off the hook. It's only happening for messages that I'm composing in Evolution! If I compose them in Mutt or vi a text file and send it, everything is fine. Also, my saved copies in the Evolution sent box is fine. Sooo... I compare what was saved in the "sent" box with what was received with a bad signature... What was the difference? Carriage Returns! Evolution is terminating lines with CR-LF when composing a message. MailScanner is removing the CR and leaving the LF. Apparently, Evolution called gpg in binary mode to create the signature. Modifying even the line termination then breaks the signature. No other mailer I use generates the DOS/Windows line termination, they all end lines with *NIX convention of LF only (no I haven't tried ThunderBird or KMail or other GUI client as yet). 1) Why must we be adding extraneous CR on text messages? Is this REALLY necessary? 2) Why is MailScanner reformating my messages and stripping the CR's? That's not merely appending a "scanned by". That's modifying the body of the messages itself. Now, maybe it's the way MailScanner is parsing and reassembling the Mime parts, I don't know there. But it should not do ANYTHING that's going to break a signature. That's verboden. 3) Why is GPG signing the message in text mode instead of binary mode? We can go round and round on the merits and demerits of that and get nowhere. Looking at my .muttrc file, Mutt uses "--textmode --clearsign" when generating PGP/Mime signed attachments or old style signed text message. If you think it should be signed in text mode, that still recurses back to an Evolution problem and the parameters that it's calling gpg with, so it's not a gpg problem. Unlike Mutt, I don't see any way to alter the gpg calling parameters in Evolution (ignoring the fact that it should just work out of the box). I would argue that BOTH packages are doing something wrong here. I don't think we should have this extra CR cruft on text but I don't think MailScanner should be stripping it off legitimate clean messages either. Maybe gpg should be clearsigning in text mode as well. All I know is that this combination does NOT work. Fixing any of the three points would fix the immediate breakage, but, maybe, we should fix all three points and really fix it, least it come back and bite us in the ass from another direction? Sooo... Can we have some discussion and comments about how to fix this thing so GPG signatures can work with this combination? Regards, Mike -- Michael H. Warfield (AI4NB) | (770) 985-6132 | mhw@WittsEnd.com /\/\|=mhw=|\/\/ | (678) 463-0932 | http://www.wittsend.com/mhw/ NIC whois: MHW9 | An optimist believes we live in the best of all PGP Key: 0xDF1DD471 | possible worlds. A pessimist is sure of it! -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 307 bytes Desc: This is a digitally signed message part Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060126/9f7cf0c6/attachment.bin From mkettler at evi-inc.com Thu Jan 26 20:08:14 2006 From: mkettler at evi-inc.com (Matt Kettler) Date: Thu Jan 26 20:08:42 2006 Subject: Running as root In-Reply-To: References: <00d901c62289$8c907860$0632a8c0@oucpm1> <9B3D9F52-FF0D-487E-B029-7DF3D07C27A1@ecs.soton.ac.uk> <43D8FD6C.3010102@evi-inc.com> Message-ID: <43D92C2E.9060900@evi-inc.com> Ugo Bellavance wrote: > Matt Kettler wrote: >>Unless of course your AV has a security flaw which can be exploited by feeding >>it malformed data. Many AV products have recently had fixes for such holes in >>their handling of various compressed or "encrypted" executables. >> > > > Here is a recent one: > > http://www.f-secure.com/security/fsc-2006-1.shtml > Not to mention Clamav: http://www.securityfocus.com/bid/16191 http://www.securityfocus.com/bid/14866 Sophos: http://www.securityfocus.com/bid/14362 McAfee http://www.securityfocus.com/bid/12832 BitDefender: http://www.securityfocus.com/bid/14968 How many more do ya want? :) From dhawal at netmagicsolutions.com Thu Jan 26 20:13:21 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Thu Jan 26 20:13:27 2006 Subject: Mail Test In-Reply-To: <012901c622b2$590c76f0$0632a8c0@oucpm1> References: <012901c622b2$590c76f0$0632a8c0@oucpm1> Message-ID: <20060126201321.27860.qmail@mymail.netmagicians.com> Darryl DeLao writes: > Does anyone know of a program or site that allows me to send hundreds of > test emails at once? I want to load test my server with Mailscanner > running. http://www.coker.com.au/postal/ - dhawal From marcel-ml at irc-addicts.de Thu Jan 26 20:16:13 2006 From: marcel-ml at irc-addicts.de (Marcel Blenkers) Date: Thu Jan 26 20:16:27 2006 Subject: Question about blocking Mail (fwd) Message-ID: Sorry, again wrong recipient ;) should update my adress-book.. ---- Hi there, i have one Question regarding blocking mails. But not from the outside, but from the inside. Here is the Problem: Let?s suppose we do habe a sender xy@yx.com and an recipient (outside) with qw@wq.com I would like to block mails from the internal Sender xy to the outside recipient qw. And i would like to block mails from inside sender yx with subject "something". As sender xy does first of all a lot of unnecessary mails with subject something to the outside world, just to test if the mail-server is working. Which is a pain in the ass. And it does create traffic. Also this person does send mails to another person, who does not want to receive no longer mails from this user, but the recipient is the only person who does not want to receive those mails. So my question: Is there any kind of ruleset to accomplish these kind of things? Like: From: yx@xy.com To: qw@wq.com warn And the sender yx should receive a mail that this mail got blocked, due to the wishes from recipient qw. Any ideas? Thanks for any kind of help Greetings Marcel From denis at croombs.org Thu Jan 26 20:17:15 2006 From: denis at croombs.org (Denis Croombs) Date: Thu Jan 26 20:17:48 2006 Subject: Mail Test In-Reply-To: <012901c622b2$590c76f0$0632a8c0@oucpm1> Message-ID: <200601262019.k0QKJj6X016886@rack2.justlinux1.net> I can do that if you want, please email offlist details of what you want denis@croombs.org _____ From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Darryl DeLao Sent: 26 January 2006 19:55 To: 'MailScanner discussion' Subject: Mail Test Does anyone know of a program or site that allows me to send hundreds of test emails at once? I want to load test my server with Mailscanner running. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060126/c552f89a/attachment.html From root at doctor.nl2k.ab.ca Thu Jan 26 20:25:52 2006 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Thu Jan 26 20:26:05 2006 Subject: [management@wellsfargo.com: Wells Fargo Bank Online] In-Reply-To: <006f01c6228a$f5c70550$453711d4@arthur> References: <20060126144305.GA8869@doctor.nl2k.ab.ca> <006f01c6228a$f5c70550$453711d4@arthur> Message-ID: <20060126202552.GB618@doctor.nl2k.ab.ca> On Thu, Jan 26, 2006 at 03:12:44PM -0000, Michele Neylon :: Blacknight Solutions wrote: > Dave Shariff Yadallee - System Administrator a.k.a. The Root of theProblem > <> said on 26 January 2006 14:43: > > > Received: from george.networkeleven.net (george.networkeleven.net > > [66.162.134.138]) > > > > Can we add 66.162.134.138 to phishing sites? > > > > What's the point? > > I presume you are referring to the phishing sites list, which is actually a > whitelist not a blocklist .. > I see. Still is it possible to warn someone about phishing? > Mr Michele Neylon > Blacknight Solutions > Hosting & Colocation, Brand Protection > http://www.blacknight.ie/ > Tel. 1850 927 280 > Intl. +353 (0) 59 9183072 > UK: 0870 163 0607 > Direct Dial: +353 (0)59 9183090 > Fax. +353 (0) 59 9164239 > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From Kevin_Miller at ci.juneau.ak.us Thu Jan 26 20:28:23 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Thu Jan 26 20:28:26 2006 Subject: Upgrading to latest stable Message-ID: <82895A755D1EA5458EC9E64021922AD2D15680@city-exch-w3e.cbj.local> I just upgraded one of my machines from 4.33.x to the current stable (4.49.7-1), and the clam/spamassassin package on the MS website. I'm running on SuSE 9.1. After making all the updates and such to the config files I tried to kick off MailScanner and got the following: mail3:/etc/init.d # l MailScanner.rpmsave -rwxr-xr-x 1 mkm users 5469 2004-07-06 12:53 MailScanner.rpmsave* mail3:/etc/init.d # mv MailScanner.rpmsave MailScanner mail3:/etc/init.d # mail3:/etc/init.d # MailScanner start Cannot open config file start, No such file or directory at /usr/lib/MailScanner/MailScanner/Config.pm line 597. Compilation failed in require at /usr/sbin/MailScanner line 65. BEGIN failed--compilation aborted at /usr/sbin/MailScanner line 65. mail3:/etc/init.d # cd /usr/lib/MailScanner/MailScanner/ mail3:/usr/lib/MailScanner/MailScanner # l So what went wrong? It seemed to all install normally... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From michele at blacknight.ie Thu Jan 26 20:32:08 2006 From: michele at blacknight.ie (Michele Neylon:: Blacknight.ie) Date: Thu Jan 26 20:32:10 2006 Subject: [management@wellsfargo.com: Wells Fargo Bank Online] In-Reply-To: <20060126202552.GB618@doctor.nl2k.ab.ca> References: <20060126144305.GA8869@doctor.nl2k.ab.ca> <006f01c6228a$f5c70550$453711d4@arthur> <20060126202552.GB618@doctor.nl2k.ab.ca> Message-ID: <43D931C8.9090409@blacknight.ie> Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem wrote: > > I see. Still is it possible to warn someone about phishing? Contacting the bank directly is hopeless (other banks might be better but the US ones seem totally incapable of dealing with it) I'd contact the abuse@ for the IP space and let them deal with it. In a lot of cases the hosting is very much 0day :) HTH M -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 From jaearick at colby.edu Thu Jan 26 20:37:30 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Thu Jan 26 20:37:35 2006 Subject: blank "is" report lines in syslog? Message-ID: Hi, I remember this got asked recently, but can't find it in the archives. I am getting blank "is" report lines in my syslog. Here is a complete example: Jan 25 23:56:47 basalt sendmail[18030]: [ID 801593 mail.info] k0Q4uYDT018030: from=, size=2582, class=0, nrcpts=1, msgid=<49d45aa50601252056v65696a6cq7ad783ff4c593daa@mail.gmail.com>, proto=ESMTP, daemon=MTA, relay=uproxy.gmail.com [66.249.92.205] Jan 25 23:56:49 basalt <22>MailScanner[11372]: RBL checks: k0Q4uYDT018030 found in spamcop.net Jan 25 23:56:52 basalt <22>MailScanner[11372]: Message k0Q4uYDT018030 from 66.249.92.205 (katiepoirier@gmail.com) to colby.edu is Jan 25 23:56:52 basalt <22>MailScanner[11372]: Spam Actions: message k0Q4uYDT018030 actions are deliver Jan 25 23:56:54 basalt sendmail[18101]: [ID 801593 mail.info] k0Q4uYDT018030: to=, delay=00:00:07, xdelay=00:00:00, mailer=local, pri=122582, dsn=2.0.0, stat=Sent Jan 25 23:56:54 basalt sendmail[18101]: [ID 801593 mail.info] k0Q4uYDT018030: done; delay=00:00:07, ntries=1 Note the "to colby.edu is" above. I thought this was a bug that got fixed? My setup: 4.50.12, Solaris 9, SA 3.1. Jeff Earickson Colby College From Kevin_Miller at ci.juneau.ak.us Thu Jan 26 20:42:10 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Thu Jan 26 20:42:13 2006 Subject: Upgrading to latest stable Message-ID: <82895A755D1EA5458EC9E64021922AD2D15681@city-exch-w3e.cbj.local> Kevin Miller wrote: > I just upgraded one of my machines from 4.33.x to the current stable > (4.49.7-1), and the clam/spamassassin package on the MS website. Nevermind. Did the old bonehead "wrong RPM" install. Downloading the SuSE specific on now... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From mhw at WittsEnd.com Thu Jan 26 20:46:19 2006 From: mhw at WittsEnd.com (Michael H. Warfield) Date: Thu Jan 26 20:46:24 2006 Subject: [management@wellsfargo.com: Wells Fargo Bank Online] In-Reply-To: <43D931C8.9090409@blacknight.ie> References: <20060126144305.GA8869@doctor.nl2k.ab.ca> <006f01c6228a$f5c70550$453711d4@arthur> <20060126202552.GB618@doctor.nl2k.ab.ca> <43D931C8.9090409@blacknight.ie> Message-ID: <1138308379.15604.196.camel@canyon.wittsend.com> On Thu, 2006-01-26 at 20:32 +0000, Michele Neylon:: Blacknight.ie wrote: > Dave Shariff Yadallee - System Administrator a.k.a. The Root of the > Problem wrote: > > > > I see. Still is it possible to warn someone about phishing? > Contacting the bank directly is hopeless (other banks might be better > but the US ones seem totally incapable of dealing with it) > I'd contact the abuse@ for the IP space and let them deal with it. 1) uce@ftc.gov Yes, they are set up for phishing, not just spam. 2) Antiphishing Working Group: http://www.antiphishing.org/report_phishing.html reportphishing@antiphishing.org 3) Messaging Anti-Abuse Working Group (MAAWG) Not for reporting, just more information... http://www.maawg.org > In a lot of cases the hosting is very much 0day :) A lot of the phishers don't even expect a site to survive a day. Half life of a phishing site is now down to only a few hours in many cases, or less... Mike > HTH > M > > -- > Mr Michele Neylon > Blacknight Solutions > Quality Business Hosting & Colocation > http://www.blacknight.ie/ > Tel. 1850 927 280 > Intl. +353 (0) 59 9183072 > Direct Dial: +353 (0)59 9183090 > Fax. +353 (0) 59 9164239 > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- Michael H. Warfield (AI4NB) | (770) 985-6132 | mhw@WittsEnd.com /\/\|=mhw=|\/\/ | (678) 463-0932 | http://www.wittsend.com/mhw/ NIC whois: MHW9 | An optimist believes we live in the best of all PGP Key: 0xDF1DD471 | possible worlds. A pessimist is sure of it! -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 307 bytes Desc: This is a digitally signed message part Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060126/ee84e1c8/attachment.bin From mhw at WittsEnd.com Thu Jan 26 20:53:31 2006 From: mhw at WittsEnd.com (Michael H. Warfield) Date: Thu Jan 26 20:53:41 2006 Subject: [Evolution] Evolution + GPG + MailScanner = Bad Juju... In-Reply-To: <1138308251.4609.8.camel@linux.site> References: <1138305608.15604.189.camel@canyon.wittsend.com> <1138308251.4609.8.camel@linux.site> Message-ID: <1138308812.15604.199.camel@canyon.wittsend.com> On Thu, 2006-01-26 at 15:44 -0500, Jeffrey Stedfast wrote: > On Thu, 2006-01-26 at 15:00 -0500, Michael H. Warfield wrote: > > Ok all, > > > > I'm cross posting this to both Evolution and MailScanner because I can > > already predict the finger pointing that's naturally going to result. > > > > A few months ago, someone brought it to my attention that my GPG > > signatures (messages signed only, not encrypted) where suddenly turning > > up "bad". The signature on this message will probably be "bad". It > > took some major head scratching to figure out what changed, what the > > parameters where, and what the hell was happening but I think I've got > > in narrowed down to some poor behavior on the part of BOTH Evolution AND > > MailScanner (or a component of MailScanner - not sure). > > > > It seems to have initially broken with an upgrade to MailScanner. I > > think upgrading to 4.47.4-2 or there abouts might have been the > > triggering event, but I don't remember what I was running on that server > > prior to that. Before then, all my signatures GPG signatures were good. > > After, they were bad. If I turn off MailScanner on my server, the > > signatures are good. I have accounts on several servers and the > > signatures are bad if I forward mail through one running a recent > > version of MailScanner. I just upgraded one of my servers to 4.50.5-12 > > and now I've got bad signatures through that server as well (I wasn't > > running MailScanner on that one before). > > > > But, that doesn't get Evolution off the hook. It's only happening for > > messages that I'm composing in Evolution! If I compose them in Mutt or > > vi a text file and send it, everything is fine. Also, my saved copies > > in the Evolution sent box is fine. > > > > Sooo... I compare what was saved in the "sent" box with what was > > received with a bad signature... What was the difference? Carriage > > Returns! Evolution is terminating lines with CR-LF when composing a > > message. MailScanner is removing the CR and leaving the LF. > > Apparently, Evolution called gpg in binary mode to create the signature. > > Modifying even the line termination then breaks the signature. > > > > No other mailer I use generates the DOS/Windows line termination, they > > all end lines with *NIX convention of LF only (no I haven't tried > > ThunderBird or KMail or other GUI client as yet). > > > > 1) Why must we be adding extraneous CR on text messages? Is this > > REALLY necessary? > > Yes. From rfc3156: > > When the OpenPGP digital signature is generated: > > (1) The data to be signed MUST first be converted to its content- > type specific canonical form. For text/plain, this means > conversion to an appropriate character set and conversion of > line endings to the canonical sequence. > This is what Evolution does. Ok... I'll concede that point. Then what about the signing mode, text vs binary. We're still broken here. > -- > Jeffrey Stedfast > Evolution Hacker - Novell, Inc. > fejj@ximian.com - www.novell.com Mike -- Michael H. Warfield (AI4NB) | (770) 985-6132 | mhw@WittsEnd.com /\/\|=mhw=|\/\/ | (678) 463-0932 | http://www.wittsend.com/mhw/ NIC whois: MHW9 | An optimist believes we live in the best of all PGP Key: 0xDF1DD471 | possible worlds. A pessimist is sure of it! -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 307 bytes Desc: This is a digitally signed message part Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060126/0076267b/attachment.bin From jaearick at colby.edu Thu Jan 26 20:52:54 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Thu Jan 26 20:57:27 2006 Subject: high spam ruleset, is this right? Message-ID: Hi, Writing a ruleset for high spam actions, is this correct? To:\tadmissions@colby.edu\tforward jaearick@colby.edu,dsjones@colby.edu delete FromOrTo:\tdefault\tdelete Tabs (\t above) are required, right? I want high spam for admissions to be forwarded to myself and dsjones and be deleted from the admissions mailbox. Will this work? Jeff Earickson Colby College From mailscanner at mango.zw Thu Jan 26 21:15:16 2006 From: mailscanner at mango.zw (Jim Holland) Date: Thu Jan 26 21:19:35 2006 Subject: winmail.dat In-Reply-To: <067301c62291$9791b9b0$3004010a@martinhlaptop> Message-ID: I guess I'll have to stay with the flow and top-post here :-) I have long had complaints from users who are unable to open these things called winmail.dat because they aren't using MS Outlook. So I consider it a plus that they now receive the message with the winmail.dat file removed and a helpful notice in its place . . . It sounds as if some correspondents are having the full message blocked, and not just the attachment. I assume that this is because they have not set: Deliver Cleaned Messages = yes in MailScanner.conf Mostly the files don't contain anything important, so can be ignored, but sometimes they do have documents or image files etc which the users do want to receive. I would consider it a definite plus if there was an option to extract the contents and send them along instead - similar to the "Convert HTML To Text" option already available. Regards Jim Holland System Administrator MANGO - Zimbabwe's non-profit e-mail service On Thu, 26 Jan 2006, Martin Hepworth wrote: > From what I've seen of the winmail.dat's I've had to release.. I'd say > you'd have to unpack the thing with tnef......but I agree blanket ban on > winmail.dat is harsh and I've to remove this check. > > I have to second this idea. I'm using 4.50.12 with the "deny winmail.dat" > > line in filename.rules.conf and I've gotten some complaints about > > rejected emails as a result. Rejection is harsh if the winmail.dat > > file can be snipped off without loosing the basic message. > > > Is it possible to strip the RTF junk out of inbound RTF messages? > > > (something like the strip HTML option) I'm blocking them now via > > > filetype but that's sorta draconian. When HTML mail comes in, it often > > > has a text component, and the HTML "attachment". Does RTF do this too, > > > or is the RTF MIME section the whole of the email? I'm under the > > > impression that the winmail.dat section is the mail and it isn't > > > replicated in the text body area but don't really know that for sure. > > > I'd like to let the message through but throw away the winmail.dat > > > attachment if possible. From shuttlebox at gmail.com Thu Jan 26 21:23:50 2006 From: shuttlebox at gmail.com (shuttlebox) Date: Thu Jan 26 21:23:54 2006 Subject: high spam ruleset, is this right? In-Reply-To: References: Message-ID: <625385e30601261323r47ad3ce1g55141f6668151f3d@mail.gmail.com> On 1/26/06, Jeff A. Earickson wrote: > > Hi, > Writing a ruleset for high spam actions, is this correct? > > To:\tadmissions@colby.edu\tforward jaearick@colby.edu,dsjones@colby.edudelete > FromOrTo:\tdefault\tdelete > > Tabs (\t above) are required, right? I want high spam for > admissions to be forwarded to myself and dsjones and be > deleted from the admissions mailbox. Will this work? > Tabs are only required in the filename and filetype files. The delete action on the first row is redundant and it might be on the second too, I'm not sure about that but it might feel more logical to put something there. Another thing I'm not sure about is if you can have multiple addresses in the forward action. -- /peter -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060126/ca67a28e/attachment.html From Kevin_Miller at ci.juneau.ak.us Thu Jan 26 21:26:58 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Thu Jan 26 21:27:01 2006 Subject: winmail.dat Message-ID: <82895A755D1EA5458EC9E64021922AD2D15682@city-exch-w3e.cbj.local> Jim Holland wrote: > I guess I'll have to stay with the flow and top-post here :-) Not me. > I have long had complaints from users who are unable to open these > things called winmail.dat because they aren't using MS Outlook. So I > consider it a plus that they now receive the message with the > winmail.dat file removed and a helpful notice in its place . . . > > It sounds as if some correspondents are having the full message > blocked, and not just the attachment. I assume that this is because > they have not set: > > Deliver Cleaned Messages = yes > > in MailScanner.conf > > Mostly the files don't contain anything important, so can be ignored, > but sometimes they do have documents or image files etc which the > users do want to receive. I would consider it a definite plus if > there was an option to extract the contents and send them along > instead - similar to the "Convert HTML To Text" option already > available. So what do you have in your filename and filetype conf files? How are you filtering the winmail.dat? ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From jaearick at colby.edu Thu Jan 26 21:32:03 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Thu Jan 26 21:32:15 2006 Subject: high spam ruleset, is this right? In-Reply-To: <625385e30601261323r47ad3ce1g55141f6668151f3d@mail.gmail.com> References: <625385e30601261323r47ad3ce1g55141f6668151f3d@mail.gmail.com> Message-ID: > On Thu, 26 Jan 2006, shuttlebox wrote: > > > Date: Thu, 26 Jan 2006 22:23:50 +0100 > > From: shuttlebox > > Reply-To: MailScanner discussion > > To: MailScanner discussion > > Subject: Re: high spam ruleset, is this right? > > > > On 1/26/06, Jeff A. Earickson wrote: > > > > Hi, > > Writing a ruleset for high spam actions, is this correct? > > > > To:\tadmissions@colby.edu\tforward jaearick@colby.edu,dsjones@colby.edudelete > > FromOrTo:\tdefault\tdelete > > > > Tabs (\t above) are required, right? I want high spam for > > admissions to be forwarded to myself and dsjones and be > > deleted from the admissions mailbox. Will this work? > > > > Tabs are only required in the filename and filetype files. The delete action > on the first row is redundant and it might be on the second too, I'm not > sure about that but it might feel more logical to put something there. > Another thing I'm not sure about is if you can have multiple addresses in > the forward action. Ehhh, that doesn't sound right. I'm replacing the MailScanner.conf line: High Scoring Spam Actions = delete with: High Scoring Spam Actions = %localrules-dir%/highspam.rules so I better have a default action in there (2nd line). The comma seperated list of email addresses doesn't have any spaces and is RFC822 compliant so that *ought* to work. Don't know if I need the delete on the first line. I've got the ruleset in place, just waiting for something to admissions to trigger it. Where's a spammer when you need one??? Jeff Earickson Colby College From shuttlebox at gmail.com Thu Jan 26 21:47:35 2006 From: shuttlebox at gmail.com (shuttlebox) Date: Thu Jan 26 21:47:38 2006 Subject: high spam ruleset, is this right? In-Reply-To: References: <625385e30601261323r47ad3ce1g55141f6668151f3d@mail.gmail.com> Message-ID: <625385e30601261347k194fb2aen9c8d01a44c5dcd65@mail.gmail.com> On 1/26/06, Jeff A. Earickson wrote: > > Ehhh, that doesn't sound right. I'm replacing the MailScanner.conf line: > High Scoring Spam Actions = delete > with: > High Scoring Spam Actions = %localrules-dir%/highspam.rules > so I better have a default action in there (2nd line). The comma > seperated > list of email addresses doesn't have any spaces and is RFC822 compliant > so that *ought* to work. Don't know if I need the delete on the first > line. > I'm 100% sure the first delete is not needed. The other might only be needed if it fails the syntax check otherwise. To me, delete is when you don't want something more productive done to the mail, like store or deliver for example. I see strange combos like "store delete" all the time that seem to work so I think that delete is very much redundant. But maybe it will fail the syntax check if there's nothing at all there, I haven't tried it. :-) Another thing I haven't tried is to forward to multiple addresses but it would be great if it worked like you say and I think it probably does. -- /peter -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060126/d0d90410/attachment.html From dnsadmin at 1bigthink.com Thu Jan 26 22:10:22 2006 From: dnsadmin at 1bigthink.com (dnsadmin 1bigthink.com) Date: Thu Jan 26 22:10:29 2006 Subject: winmail.dat In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D15682@city-exch-w3e.cbj.l ocal> References: <82895A755D1EA5458EC9E64021922AD2D15682@city-exch-w3e.cbj.local> Message-ID: <6.2.3.4.0.20060126170436.09916160@mxt.1bigthink.com> At 04:26 PM 1/26/2006, you wrote: >Jim Holland wrote: > > I guess I'll have to stay with the flow and top-post here :-) > >Not me. > > > I have long had complaints from users who are unable to open these > > things called winmail.dat because they aren't using MS Outlook. So I > > consider it a plus that they now receive the message with the > > winmail.dat file removed and a helpful notice in its place . . . > > > > It sounds as if some correspondents are having the full message > > blocked, and not just the attachment. I assume that this is because > > they have not set: > > > > Deliver Cleaned Messages = yes > > > > in MailScanner.conf > > > > Mostly the files don't contain anything important, so can be ignored, > > but sometimes they do have documents or image files etc which the > > users do want to receive. I would consider it a definite plus if > > there was an option to extract the contents and send them along > > instead - similar to the "Convert HTML To Text" option already > > available. > >So what do you have in your filename and filetype conf files? How are >you filtering the winmail.dat? > > >...Kevin Me neither! The majority of my customers insist on Outlook. I H8 it! I insist I won't put it on my machine. I initially started blocking the attachements and then saw that I had caught three, known valid emails in a matter of hours. I turned it off. I apologized to the senders and the recipients. I then described the vulnerability, told them they had better religiously apply Microsoft patches every second Tuesday and wished them luck! I don't know what more you can do?!!! QUIT USING OUTLOOK! Glenn From MailScanner at ecs.soton.ac.uk Thu Jan 26 22:21:00 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 26 22:21:05 2006 Subject: [Evolution] Evolution + GPG + MailScanner = Bad Juju... In-Reply-To: <1138308812.15604.199.camel@canyon.wittsend.com> References: <1138305608.15604.189.camel@canyon.wittsend.com> <1138308251.4609.8.camel@linux.site> <1138308812.15604.199.camel@canyon.wittsend.com> Message-ID: <43D94B4C.2090709@ecs.soton.ac.uk> I have posted this problem to the maintainer of the MIME-tools module, which MailScanner uses to manage the MIME attachments in messages. It appears that it output \n instead or \r\n which it should, according to RFC2822. I will let you know what I hear from him. Hopefully he comes back with something useful :-) Michael H. Warfield wrote: > On Thu, 2006-01-26 at 15:44 -0500, Jeffrey Stedfast wrote: > >> On Thu, 2006-01-26 at 15:00 -0500, Michael H. Warfield wrote: >> >>> Ok all, >>> >>> I'm cross posting this to both Evolution and MailScanner because I can >>> already predict the finger pointing that's naturally going to result. >>> >>> A few months ago, someone brought it to my attention that my GPG >>> signatures (messages signed only, not encrypted) where suddenly turning >>> up "bad". The signature on this message will probably be "bad". It >>> took some major head scratching to figure out what changed, what the >>> parameters where, and what the hell was happening but I think I've got >>> in narrowed down to some poor behavior on the part of BOTH Evolution AND >>> MailScanner (or a component of MailScanner - not sure). >>> >>> It seems to have initially broken with an upgrade to MailScanner. I >>> think upgrading to 4.47.4-2 or there abouts might have been the >>> triggering event, but I don't remember what I was running on that server >>> prior to that. Before then, all my signatures GPG signatures were good. >>> After, they were bad. If I turn off MailScanner on my server, the >>> signatures are good. I have accounts on several servers and the >>> signatures are bad if I forward mail through one running a recent >>> version of MailScanner. I just upgraded one of my servers to 4.50.5-12 >>> and now I've got bad signatures through that server as well (I wasn't >>> running MailScanner on that one before). >>> >>> But, that doesn't get Evolution off the hook. It's only happening for >>> messages that I'm composing in Evolution! If I compose them in Mutt or >>> vi a text file and send it, everything is fine. Also, my saved copies >>> in the Evolution sent box is fine. >>> >>> Sooo... I compare what was saved in the "sent" box with what was >>> received with a bad signature... What was the difference? Carriage >>> Returns! Evolution is terminating lines with CR-LF when composing a >>> message. MailScanner is removing the CR and leaving the LF. >>> Apparently, Evolution called gpg in binary mode to create the signature. >>> Modifying even the line termination then breaks the signature. >>> >>> No other mailer I use generates the DOS/Windows line termination, they >>> all end lines with *NIX convention of LF only (no I haven't tried >>> ThunderBird or KMail or other GUI client as yet). >>> >>> 1) Why must we be adding extraneous CR on text messages? Is this >>> REALLY necessary? >>> >> Yes. From rfc3156: >> >> When the OpenPGP digital signature is generated: >> >> (1) The data to be signed MUST first be converted to its content- >> type specific canonical form. For text/plain, this means >> conversion to an appropriate character set and conversion of >> line endings to the canonical sequence. >> > > >> This is what Evolution does. >> > > Ok... I'll concede that point. Then what about the signing mode, text > vs binary. We're still broken here. > > >> -- >> Jeffrey Stedfast >> Evolution Hacker - Novell, Inc. >> fejj@ximian.com - www.novell.com >> > > Mike > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From mhw at wittsend.com Thu Jan 26 22:21:41 2006 From: mhw at wittsend.com (Michael H. Warfield) Date: Thu Jan 26 22:21:52 2006 Subject: [Evolution] Evolution + GPG + MailScanner = Bad Juju... In-Reply-To: <1138308966.4609.10.camel@linux.site> References: <1138305608.15604.189.camel@canyon.wittsend.com> <1138308251.4609.8.camel@linux.site> <1138308812.15604.199.camel@canyon.wittsend.com> <1138308966.4609.10.camel@linux.site> Message-ID: <1138314101.15604.250.camel@canyon.wittsend.com> On Thu, 2006-01-26 at 15:56 -0500, Jeffrey Stedfast wrote: > On Thu, 2006-01-26 at 15:53 -0500, Michael H. Warfield wrote: > > On Thu, 2006-01-26 at 15:44 -0500, Jeffrey Stedfast wrote: > > > On Thu, 2006-01-26 at 15:00 -0500, Michael H. Warfield wrote: : > > > > 1) Why must we be adding extraneous CR on text messages? Is this > > > > REALLY necessary? > > > > > > Yes. From rfc3156: > > > > > > When the OpenPGP digital signature is generated: > > > > > > (1) The data to be signed MUST first be converted to its content- > > > type specific canonical form. For text/plain, this means > > > conversion to an appropriate character set and conversion of > > > line endings to the canonical sequence. > > > > > This is what Evolution does. > > Ok... I'll concede that point. Then what about the signing mode, text > > vs binary. We're still broken here. > How so? The only difference between text and binary mode is the > canonical CRLF endings, and, guess what, Evolution converts to CRLF. So > no problem there. Oh crap... Wait a minute... There is something else that's been staring me in the face here, all along. There's a difference in the Mime quoted printable encoding. I wasn't paying close enough attention to that, rather than the text it was encoding. On the messages that result in a "good signature" (saved in the "sent" mailbox) I looked closely at the lines and the encoding... What I see is something like this: --=20^M Michael H. Warfield (AI4NB) | (770) 985-6132 | mhw@WittsEnd.com^M Now... Looking at the message which has passed through MailScanner, I see those same two lines as this: --=20=0A= Michael H. Warfield (AI4NB) | (770) 985-6132 | mhw@WittsEnd.com=0A= So, in the former case, the Mime quoted printable has the CR's as real CR's (^M) and in the later case the quoted printable has the CR's as quoted printable CRs (=0A). Not good. So that's what's really causing the problem. It's the difference in encoding... The messages are identical other than that encoding difference. The signature is on the encoded Mime part. That's a more serious discrepancy than merely text vs binary. My bad for not looking closer at the Mime encoding itself and thinking it was just an issue with the text format itself. Which is correct? Obviously the signature was generated with the ^M in the encoded Mime part and won't match if it's encoded with =0A even though they should be equivalent from a quoted printable standpoint. If their both "correct", they have to, at least, agree in order to get the signature to verify. Obviously there IS a problem here with MailScanner re-encoding those parts. That's modifying that attachment and breaking the signature. Someone with MailScanner want to jump in on this? Ball's in your court now... Mike > > > -- > > > Jeffrey Stedfast > > > Evolution Hacker - Novell, Inc. > > > fejj@ximian.com - www.novell.com > > > > Mike > -- > Jeffrey Stedfast > Evolution Hacker - Novell, Inc. > fejj@ximian.com - www.novell.com Mike -- Michael H. Warfield (AI4NB) | (770) 985-6132 | mhw@WittsEnd.com /\/\|=mhw=|\/\/ | (678) 463-0932 | http://www.wittsend.com/mhw/ NIC whois: MHW9 | An optimist believes we live in the best of all PGP Key: 0xDF1DD471 | possible worlds. A pessimist is sure of it! -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 307 bytes Desc: This is a digitally signed message part Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060126/419e699d/attachment.bin From mhw at WittsEnd.com Thu Jan 26 22:24:37 2006 From: mhw at WittsEnd.com (Michael H. Warfield) Date: Thu Jan 26 22:24:53 2006 Subject: [Evolution] Evolution + GPG + MailScanner = Bad Juju... In-Reply-To: <43D94B4C.2090709@ecs.soton.ac.uk> References: <1138305608.15604.189.camel@canyon.wittsend.com> <1138308251.4609.8.camel@linux.site> <1138308812.15604.199.camel@canyon.wittsend.com> <43D94B4C.2090709@ecs.soton.ac.uk> Message-ID: <1138314277.15604.253.camel@canyon.wittsend.com> Hey Julian, On Thu, 2006-01-26 at 22:21 +0000, Julian Field wrote: > I have posted this problem to the maintainer of the MIME-tools module, > which MailScanner uses to manage the MIME attachments in messages. It > appears that it output \n instead or \r\n which it should, according to > RFC2822. It's worse than that... It's outputing =0A\n for the quoted printable instead of \r\n and REALLY hosing things up. That's a serious problem. > I will let you know what I hear from him. Hopefully he comes back with > something useful :-) Yeah... I think that needs to be escalated, somehow. Mike -- Michael H. Warfield (AI4NB) | (770) 985-6132 | mhw@WittsEnd.com /\/\|=mhw=|\/\/ | (678) 463-0932 | http://www.wittsend.com/mhw/ NIC whois: MHW9 | An optimist believes we live in the best of all PGP Key: 0xDF1DD471 | possible worlds. A pessimist is sure of it! -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 307 bytes Desc: This is a digitally signed message part Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060126/43df4923/attachment.bin From MailScanner at ecs.soton.ac.uk Thu Jan 26 22:25:07 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 26 22:25:16 2006 Subject: Typo in the reports In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D1567F@city-exch-w3e.cbj.local> References: <82895A755D1EA5458EC9E64021922AD2D1567F@city-exch-w3e.cbj.local> Message-ID: <43D94C43.5050008@ecs.soton.ac.uk> Thanks! Kevin Miller wrote: > In sender.error.report.txt there's a typo. It says: > > 2) Got to the "Mail Format" tab > _____^_________________________ > > Believe that should be "Go", not "Got". > > Edited mine, but thought I'd mention it for future releases... > > ...Kevin > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ssilva at sgvwater.com Thu Jan 26 22:36:27 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Jan 26 22:37:05 2006 Subject: winmail.dat In-Reply-To: References: <067301c62291$9791b9b0$3004010a@martinhlaptop> Message-ID: Jim Holland spake the following on 1/26/2006 1:15 PM: > I guess I'll have to stay with the flow and top-post here :-) > > I have long had complaints from users who are unable to open these things > called winmail.dat because they aren't using MS Outlook. So I consider it > a plus that they now receive the message with the winmail.dat file removed > and a helpful notice in its place . . . > > It sounds as if some correspondents are having the full message blocked, > and not just the attachment. I assume that this is because they have not > set: > > Deliver Cleaned Messages = yes > > in MailScanner.conf > > Mostly the files don't contain anything important, so can be ignored, but > sometimes they do have documents or image files etc which the users do > want to receive. I would consider it a definite plus if there was an > option to extract the contents and send them along instead - similar to > the "Convert HTML To Text" option already available. > Although this "might" be possible, a better alternative would be to send a bounce that asks the sender to not use this vendor locked format to send mail to the rest of the world. Not everyone uses, or has a desire to use, Outlook. Outlook should not default to sending in this format. Or at least have a warning that the message might not be readable to the rest of the world and it might cause nasty e-mails and phone calls from the receivers. -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () From mhw at WittsEnd.com Thu Jan 26 22:39:24 2006 From: mhw at WittsEnd.com (Michael H. Warfield) Date: Thu Jan 26 22:39:38 2006 Subject: [Evolution] Evolution + GPG + MailScanner = Bad Juju... In-Reply-To: <43D94B4C.2090709@ecs.soton.ac.uk> References: <1138305608.15604.189.camel@canyon.wittsend.com> <1138308251.4609.8.camel@linux.site> <1138308812.15604.199.camel@canyon.wittsend.com> <43D94B4C.2090709@ecs.soton.ac.uk> Message-ID: <1138315164.15604.261.camel@canyon.wittsend.com> On Thu, 2006-01-26 at 22:21 +0000, Julian Field wrote: > I have posted this problem to the maintainer of the MIME-tools module, > which MailScanner uses to manage the MIME attachments in messages. It > appears that it output \n instead or \r\n which it should, according to > RFC2822. > I will let you know what I hear from him. Hopefully he comes back with > something useful :-) I've now also send a message off to Dave Skoll about this, since he seems to have taken on maintainership of MIME-Tools. Mike -- Michael H. Warfield (AI4NB) | (770) 985-6132 | mhw@WittsEnd.com /\/\|=mhw=|\/\/ | (678) 463-0932 | http://www.wittsend.com/mhw/ NIC whois: MHW9 | An optimist believes we live in the best of all PGP Key: 0xDF1DD471 | possible worlds. A pessimist is sure of it! -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 307 bytes Desc: This is a digitally signed message part Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060126/ae12cae6/attachment.bin From MailScanner at ecs.soton.ac.uk Thu Jan 26 23:00:56 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Jan 26 23:01:05 2006 Subject: high spam ruleset, is this right? In-Reply-To: References: Message-ID: <43D954A8.8020206@ecs.soton.ac.uk> Jeff A. Earickson wrote: > Hi, > Writing a ruleset for high spam actions, is this correct? > > To:\tadmissions@colby.edu\tforward > jaearick@colby.edu,dsjones@colby.edu delete > FromOrTo:\tdefault\tdelete > > Tabs (\t above) are required, right? I want high spam for > admissions to be forwarded to myself and dsjones and be > deleted from the admissions mailbox. Will this work? I've just read all the responses to this one, all sorts of interesting theories :-) The tabs are not necessary, any whitespace will do. The "delete" makes it look better, if that sort of thing yanks your chain. Separate the multiple email addresses with spaces, not commas. And the "forward" only actually makes it look pretty, too, but don't tell the syntax police I said that... This should do the same thing, and still look quite nice. To: admissions@colby.edu forward jaearick@colby.edu dsjones@colby.edu FromOrTo: default delete A million other variants would work too, I'm not particularly fussy about syntax, I can usually work out what you meant to write (for the value of me == MailScanner). -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ssilva at sgvwater.com Thu Jan 26 23:24:02 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Jan 26 23:24:22 2006 Subject: high spam ruleset, is this right? In-Reply-To: References: <625385e30601261323r47ad3ce1g55141f6668151f3d@mail.gmail.com> Message-ID: Jeff A. Earickson spake the following on 1/26/2006 1:32 PM: >> On Thu, 26 Jan 2006, shuttlebox wrote: >> >> > Date: Thu, 26 Jan 2006 22:23:50 +0100 >> > From: shuttlebox >> > Reply-To: MailScanner discussion >> > To: MailScanner discussion >> > Subject: Re: high spam ruleset, is this right? >> > > On 1/26/06, Jeff A. Earickson wrote: >> > >> > Hi, >> > Writing a ruleset for high spam actions, is this correct? >> > >> > To:\tadmissions@colby.edu\tforward >> jaearick@colby.edu,dsjones@colby.edudelete >> > FromOrTo:\tdefault\tdelete >> > >> > Tabs (\t above) are required, right? I want high spam for >> > admissions to be forwarded to myself and dsjones and be >> > deleted from the admissions mailbox. Will this work? >> > >> >> Tabs are only required in the filename and filetype files. The delete >> action >> on the first row is redundant and it might be on the second too, I'm not >> sure about that but it might feel more logical to put something there. >> Another thing I'm not sure about is if you can have multiple addresses in >> the forward action. > > Ehhh, that doesn't sound right. I'm replacing the MailScanner.conf line: > High Scoring Spam Actions = delete > with: > High Scoring Spam Actions = %localrules-dir%/highspam.rules > so I better have a default action in there (2nd line). The comma seperated > list of email addresses doesn't have any spaces and is RFC822 compliant > so that *ought* to work. Don't know if I need the delete on the first > line. > > I've got the ruleset in place, just waiting for something to admissions > to trigger it. Where's a spammer when you need one??? > > Jeff Earickson > Colby College Send a gtube message to admissions. That should hit any high scoring list. -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () From Kevin_Miller at ci.juneau.ak.us Thu Jan 26 23:46:56 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Thu Jan 26 23:47:00 2006 Subject: winmail.dat Message-ID: <82895A755D1EA5458EC9E64021922AD2D15685@city-exch-w3e.cbj.local> Scott Silva wrote: > Although this "might" be possible, a better alternative would be to > send a bounce that asks the sender to not use this vendor locked > format to send mail > to the rest of the world. Not everyone uses, or has a desire to use, > Outlook. Outlook should not default to sending in this format. > Or at least have a warning that the message might not be readable to > the rest of the world and it might cause nasty e-mails and phone calls > from the receivers. That's what I'm currently doing. Stole the verbage on how to change the sending format from sender.error.report.txt and pasted it into sender.content.report.txt. I turned on postmaster virus notification so I could see how much of an impact I'm having. Naturally, the mail that's coming in is naturally for the mucky-mucks at the top of the food chain. And, just as naturally some of the senders are frequent fliers who either 1) can't read, 2) can't follow directions, or 3) won't follow directions. So far I've gotten 9 messages today (out of 4000+ inbound). Could be worse I guess... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From ssilva at sgvwater.com Thu Jan 26 23:59:46 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Jan 26 23:59:55 2006 Subject: winmail.dat In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D15685@city-exch-w3e.cbj.local> References: <82895A755D1EA5458EC9E64021922AD2D15685@city-exch-w3e.cbj.local> Message-ID: Kevin Miller spake the following on 1/26/2006 3:46 PM: > Scott Silva wrote: >> Although this "might" be possible, a better alternative would be to >> send a bounce that asks the sender to not use this vendor locked >> format to send mail >> to the rest of the world. Not everyone uses, or has a desire to use, >> Outlook. Outlook should not default to sending in this format. >> Or at least have a warning that the message might not be readable to >> the rest of the world and it might cause nasty e-mails and phone calls > >> from the receivers. > > That's what I'm currently doing. Stole the verbage on how to change the > sending format from sender.error.report.txt and pasted it into > sender.content.report.txt. I turned on postmaster virus notification so > I could see how much of an impact I'm having. Naturally, the mail > that's coming in is naturally for the mucky-mucks at the top of the food > chain. And, just as naturally some of the senders are frequent fliers > who either 1) can't read, 2) can't follow directions, or 3) won't follow > directions. > > So far I've gotten 9 messages today (out of 4000+ inbound). Could be > worse I guess... > > ...Kevin I had to cave to the pressure and allow them -- for now. Ours are from lawyers -- need I say more? -- /-----------------------\ |~~\_____/~~\__ | | MailScanner; The best |___________ \N1____====== )-+ | protection on the net!| ~~~|/~~ | \-----------------------/ () From Kevin_Miller at ci.juneau.ak.us Fri Jan 27 00:29:47 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Fri Jan 27 00:29:56 2006 Subject: winmail.dat Message-ID: <82895A755D1EA5458EC9E64021922AD2D15686@city-exch-w3e.cbj.local> Scott Silva wrote: > I had to cave to the pressure and allow them -- for now. > Ours are from lawyers -- need I say more? So were a couple of mine, but I have one of these: http://www.thinkgeek.com/geektoys/warfare/753d/ so they leave me alone! No sysop should be w/o one... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From ssilva at sgvwater.com Fri Jan 27 00:34:25 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Jan 27 00:34:42 2006 Subject: winmail.dat In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D15686@city-exch-w3e.cbj.local> References: <82895A755D1EA5458EC9E64021922AD2D15686@city-exch-w3e.cbj.local> Message-ID: Kevin Miller spake the following on 1/26/2006 4:29 PM: > Scott Silva wrote: > >> I had to cave to the pressure and allow them -- for now. >> Ours are from lawyers -- need I say more? > > So were a couple of mine, but I have one of these: > http://www.thinkgeek.com/geektoys/warfare/753d/ > so they leave me alone! > > No sysop should be w/o one... > > ...Kevin To quote Will Smith in Independence Day, "I gotta get me one of these!" -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ugob at camo-route.com Fri Jan 27 01:23:14 2006 From: ugob at camo-route.com (Ugo Bellavance) Date: Fri Jan 27 01:23:31 2006 Subject: blank "is" report lines in syslog? In-Reply-To: References: Message-ID: Jeff A. Earickson wrote: > Hi, > I remember this got asked recently, but can't find it in > the archives. I am getting blank "is" report lines in my > syslog. Here is a complete example: > > Jan 25 23:56:47 basalt sendmail[18030]: [ID 801593 mail.info] > k0Q4uYDT018030: from=, size=2582, class=0, > nrcpts=1, > msgid=<49d45aa50601252056v65696a6cq7ad783ff4c593daa@mail.gmail.com>, > proto=ESMTP, daemon=MTA, relay=uproxy.gmail.com [66.249.92.205] > Jan 25 23:56:49 basalt <22>MailScanner[11372]: RBL checks: > k0Q4uYDT018030 found in spamcop.net > Jan 25 23:56:52 basalt <22>MailScanner[11372]: Message k0Q4uYDT018030 > from 66.249.92.205 (katiepoirier@gmail.com) to colby.edu is Jan 25 > 23:56:52 basalt <22>MailScanner[11372]: Spam Actions: message > k0Q4uYDT018030 actions are deliver > Jan 25 23:56:54 basalt sendmail[18101]: [ID 801593 mail.info] > k0Q4uYDT018030: to=, delay=00:00:07, xdelay=00:00:00, > mailer=local, pri=122582, dsn=2.0.0, stat=Sent > Jan 25 23:56:54 basalt sendmail[18101]: [ID 801593 mail.info] > k0Q4uYDT018030: done; delay=00:00:07, ntries=1 > > Note the "to colby.edu is" above. I thought this was a bug > that got fixed? My setup: 4.50.12, Solaris 9, SA 3.1. Looks like a language file problem... did you check that? Any other errors at MailScanner startup? > > Jeff Earickson > Colby College -- Ugo -> Please don't send a copy of your reply by e-mail. I read the list. -> Please avoid top-posting, long signatures and HTML, and cut the irrelevant parts in your replies. From mailscanner at mango.zw Fri Jan 27 09:30:58 2006 From: mailscanner at mango.zw (Jim Holland) Date: Fri Jan 27 09:37:09 2006 Subject: winmail.dat In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D15682@city-exch-w3e.cbj.local> Message-ID: On Thu, 26 Jan 2006, Kevin Miller wrote: > > I have long had complaints from users who are unable to open these > > things called winmail.dat because they aren't using MS Outlook. So I > > consider it a plus that they now receive the message with the > > winmail.dat file removed and a helpful notice in its place . . . > > > > It sounds as if some correspondents are having the full message > > blocked, and not just the attachment. I assume that this is because > > they have not set: > > > > Deliver Cleaned Messages = yes > > > > in MailScanner.conf > > > > Mostly the files don't contain anything important, so can be ignored, > > but sometimes they do have documents or image files etc which the > > users do want to receive. I would consider it a definite plus if > > there was an option to extract the contents and send them along > > instead - similar to the "Convert HTML To Text" option already > > available. > > So what do you have in your filename and filetype conf files? How are > you filtering the winmail.dat? I am just using MailScanner 4.50.10-1 beta with the default blocking and slightly modified comments: filename.rules.conf: JKF 11/01/2006 Another Microsoft security vulnerability deny winmail\.dat$ Windows security vulnerability Microsoft Outlook Rich Text Format attachments blocked due to security hole - ask sender to use plain text or HTML instead filetype.rules.conf: deny TNEF Windows security vulnerability No Outlook Rich Text Format attachments due to security hole - ask sender to use plain text or HTML instead deny Transport Neutral Encapsulation Format Windows security vulnerability No Outlook Rich Text Format attachments due to security hole - ask sender to use plain text or HTML instead In all the cases I have checked so far I have found that the recipients were not using MS Outlook, so would not have been able to read the files anyway. I do also like the suggestion of an automated bounce to sender asking them not to use this format - one of the rare cases where a bounce to sender is very unlikely to do harm and should cause some good. Regards Jim Holland System Administrator MANGO - Zimbabwe's non-profit e-mail service From tac.forums at gmail.com Fri Jan 27 12:44:19 2006 From: tac.forums at gmail.com (TAC Forums) Date: Fri Jan 27 12:44:21 2006 Subject: spam rules In-Reply-To: References: Message-ID: Hi All, I have a strange problem with spam detection on one of our servers, A domain hosted with us, has th efollowing rules in spam.whitelist.rules From:*@abc.com yes Still, when they send Emails even to someone in abc.com, the message is checked for Spam. The Default rules is, >From or To: default no Is there any thing wrong with this? -- TAC Support Team -- TAC Support Team From MailScanner at ecs.soton.ac.uk Fri Jan 27 13:55:13 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 27 13:55:29 2006 Subject: spam rules In-Reply-To: References: Message-ID: <378D92FB-F14C-4DAB-A58D-696584737894@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- You appear to have the spaces in rather the wrong places. Try this From: *@abc.com yes FromOrTo: default no (I have doubled-up the spaces just to make it more obvious). Also, check your maillog for error reports. On 27 Jan 2006, at 12:44, TAC Forums wrote: > Hi All, > > I have a strange problem with spam detection on one of our servers, > > A domain hosted with us, has th efollowing rules in > spam.whitelist.rules > > From:*@abc.com yes > > Still, when they send Emails even to someone in abc.com, the message > is checked for Spam. > The Default rules is, > >> From or To: default no > > Is there any thing wrong with this? > > -- > TAC Support Team > > > -- > TAC Support Team > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ9omRfw32o+k+q+hAQFCOQf/ap/izXsH1xhJK/DrCTdH8AulAJrcn5QG nUusQsvOa75id+CTtL2kZE870uY9HADiE3PaK8GgFXLpvnP7nVEPW+3FRSJWncpO Z102z42F3V9dC1IZrES71775a/AcBPb4P4scxhx53deu8XaVhOTAJWn0WH8yvHvU NIhU1N77/UkyFsyeMgFNihASgwwpG/xOd4HnJOBSOH0s4id4B8crFJiPotXQWC2f VkupX2Jd2Vv+Y71CzwkcB/C7YDD+Ki9zYW/bXgQz8lIsX8Lm+qL6+RUvJEU4yQPR +LDhnc/LbKr8duAY7SUgmzPRIGrtbB+7wnRtxBeoDsYBEDPmh0rQ3A== =cVqV -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ajos1 at onion.demon.co.uk Fri Jan 27 14:29:59 2006 From: ajos1 at onion.demon.co.uk (ajos1@onion.demon.co.uk) Date: Fri Jan 27 14:30:08 2006 Subject: Has anyone seen anything like this before Message-ID: - Has anyone seen anything like this before... xxxxx was the username... Has MailScanner gone mental... or is the system sending out messages in the wrong format? ------- From: Tom Stewart [mailto:xxxxxxxx@tbshs.herts.sch.uk] Sent: Fri 27/01/2006 11:30 To: frank.beran Subject: TBSHS: Mr Jolley- comments MailScanner has detected a possible fraud attempt from "83.245.15.39" claiming to be TBSHS » MailScanner has detected a possible fraud attempt from "83.245.15.39" claiming to be Forums » MailScanner has detected a possible fraud attempt from "83.245.15.39" claiming to be Moodle, What do you think? » MailScanner has detected a possible fraud attempt from "83.245.15.39" claiming to be Mr Jolley- comments MailScanner has detected a possible fraud attempt from "83.245.15.39" claiming to be Mr Jolley- comments by MailScanner has detected a possible fraud attempt from "83.245.15.39" claiming to be Tom Stewart - Wednesday, 25 January 2006, 05:51 PM I feel that moodle has is potentially a great tool. It makes it quicker for comments on work to be returned, and I like the quiz you did. I feel being able to send messages is good if we have any trouble. However, I am still having trouble uploading my work. I feel to make it easier for me you could: * Have a larger uploading size * Accept WPS formats * Allow more than one file to be uploaded (So I can split it) Thanks Tom MailScanner has detected a possible fraud attempt from "83.245.15.39" claiming to be Reply MailScanner has detected a possible fraud attempt from "83.245.15.39" claiming to be See this post in context MailScanner has detected a possible fraud attempt from "83.245.15.39" claiming to be Unsubscribe from this forum ---- == ===================================================================== = = "A committee of one... gets things done." = = "It is always sunny in my life..." - Ajos1 = = "There will be a press feeding frenzy now - if anyone else has any = skeletons in their closets, they'll soon be out and dancing." = = Need help dealing with Parking Tickets, Bailiffs, Capita or NTL... = Call... +44 8457 90 90 90 http://www.samaritans.org/ ===================================================================== From jaearick at colby.edu Fri Jan 27 14:57:18 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Fri Jan 27 14:57:32 2006 Subject: high spam ruleset, is this right? In-Reply-To: <43D954A8.8020206@ecs.soton.ac.uk> References: <43D954A8.8020206@ecs.soton.ac.uk> Message-ID: Julian, Thanks. I didn't realize the syntax was so forgiving. Jeff Earickson Colby College On Thu, 26 Jan 2006, Julian Field wrote: > Date: Thu, 26 Jan 2006 23:00:56 +0000 > From: Julian Field > Reply-To: MailScanner discussion > To: MailScanner discussion > Subject: Re: high spam ruleset, is this right? > > > > Jeff A. Earickson wrote: >> Hi, >> Writing a ruleset for high spam actions, is this correct? >> >> To:\tadmissions@colby.edu\tforward jaearick@colby.edu,dsjones@colby.edu >> delete >> FromOrTo:\tdefault\tdelete >> >> Tabs (\t above) are required, right? I want high spam for >> admissions to be forwarded to myself and dsjones and be >> deleted from the admissions mailbox. Will this work? > I've just read all the responses to this one, all sorts of interesting > theories :-) > The tabs are not necessary, any whitespace will do. > The "delete" makes it look better, if that sort of thing yanks your chain. > Separate the multiple email addresses with spaces, not commas. > And the "forward" only actually makes it look pretty, too, but don't tell the > syntax police I said that... > > This should do the same thing, and still look quite nice. > To: admissions@colby.edu forward jaearick@colby.edu dsjones@colby.edu > FromOrTo: default delete > > A million other variants would work too, I'm not particularly fussy about > syntax, I can usually work out what you meant to write (for the value of me > == MailScanner). > > -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > Professional Support Services at www.MailScanner.biz > MailScanner thanks transtec Computers for their support > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From jaearick at colby.edu Fri Jan 27 16:40:10 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Fri Jan 27 16:40:26 2006 Subject: blank "is" report lines in syslog? In-Reply-To: References: Message-ID: On Thu, 26 Jan 2006, Ugo Bellavance wrote: > Jeff A. Earickson wrote: >> Hi, >> I remember this got asked recently, but can't find it in >> the archives. I am getting blank "is" report lines in my >> syslog. Here is an example: >> >> Jan 25 23:56:49 basalt <22>MailScanner[11372]: RBL checks: >> k0Q4uYDT018030 found in spamcop.net >> Jan 25 23:56:52 basalt <22>MailScanner[11372]: Message k0Q4uYDT018030 >> from 66.249.92.205 (katiepoirier@gmail.com) to colby.edu is >> >> Note the "to colby.edu is" above. I thought this was a bug >> that got fixed? My setup: 4.50.12, Solaris 9, SA 3.1. > > Looks like a language file problem... did you check that? Any other > errors at MailScanner startup? > Ugo, thanks for the suggestion. I ran upgrade_languages_conf and got no changes in languages.conf. MS in debug mode revealed nothing. However, I've noticed that the mangled syslog messages correlate to messages found in spamcop.net, ie I had the following: Spam List = spamcop.net ORDB-RBL I've removed the spamcop.net entry and I'll see what changes. ===> BTW <==== Who uses spamcop anymore for either an RBL or SpamAssassin scoring? I dropped them from my RBLs several months ago. The change above may become permanent anyway because they tag a lot of stuff from gmail, yahoo, etc. They seem to have got their heads wedged in the wrong place. Anybody else feel this way??? Jeff Earickson Colby College From campbell at cnpapers.com Fri Jan 27 17:10:18 2006 From: campbell at cnpapers.com (Steve Campbell) Date: Fri Jan 27 17:10:35 2006 Subject: Upgrade to new Beta stops logging to MailWatch Message-ID: <000301c62364$8c487b60$0705000a@DDF5DW71> I seem to recall a problem asked before, but can't locate it. I have just tried the new Beta, as an upgrade. It does not seem to be calling the MailWatch functions. Is there something I have overlooked? There is nothing in the maillog indicating a call to this function. Upgraded from 4.41 Thanks for any help. Steve Campbell campbell@cnpapers.com Charleston Newspapers From ssilva at sgvwater.com Fri Jan 27 17:27:28 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Jan 27 17:28:18 2006 Subject: Upgrade to new Beta stops logging to MailWatch In-Reply-To: <000301c62364$8c487b60$0705000a@DDF5DW71> References: <000301c62364$8c487b60$0705000a@DDF5DW71> Message-ID: Steve Campbell spake the following on 1/27/2006 9:10 AM: > I seem to recall a problem asked before, but can't locate it. > > I have just tried the new Beta, as an upgrade. It does not seem to be > calling the MailWatch functions. Is there something I have overlooked? > There is nothing in the maillog indicating a call to this function. > Upgraded from 4.41 > > Thanks for any help. > > Steve Campbell > campbell@cnpapers.com > Charleston Newspapers > > Make sure of the following; MailScanner.conf has the Always Looked Up Last = &MailWatchLogging make sure that /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm is there -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From campbell at cnpapers.com Fri Jan 27 17:37:12 2006 From: campbell at cnpapers.com (Steve Campbell) Date: Fri Jan 27 17:37:25 2006 Subject: Upgrade to new Beta stops logging to MailWatch References: <000301c62364$8c487b60$0705000a@DDF5DW71> Message-ID: <002e01c62368$4e56f350$0705000a@DDF5DW71> Scott, ----- Original Message ----- From: "Scott Silva" To: Sent: Friday, January 27, 2006 12:27 PM Subject: Re: Upgrade to new Beta stops logging to MailWatch > Steve Campbell spake the following on 1/27/2006 9:10 AM: >> I seem to recall a problem asked before, but can't locate it. >> >> I have just tried the new Beta, as an upgrade. It does not seem to be >> calling the MailWatch functions. Is there something I have overlooked? >> There is nothing in the maillog indicating a call to this function. >> Upgraded from 4.41 >> >> Thanks for any help. >> >> Steve Campbell >> campbell@cnpapers.com >> Charleston Newspapers >> >> > Make sure of the following; > MailScanner.conf has the Always Looked Up Last = &MailWatchLogging Yep, this is on. No changes here from the old release. > make sure that > /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm > is there > > -- Yep it is. I get a maillog entry stating the call now, after removing some rules from spam.assassin.prefs.conf. But nothing is getting included on MailWatch. I get no errors, though. I am still running MW 0.5.1. This was originally in /usr/lib/MailScanner, but I copied it to /usr/lib/MailScanner/MailScanner/CustomFunctions, just in case there was something going on there. (I'm not sure which it belongs in - the new or old directory) > > MailScanner is like deodorant... > You hope everybody uses it, and > you notice quickly if they don't!!!! > > -- Thanks Steve From shuttlebox at gmail.com Fri Jan 27 17:45:27 2006 From: shuttlebox at gmail.com (shuttlebox) Date: Fri Jan 27 17:45:30 2006 Subject: blank "is" report lines in syslog? In-Reply-To: References: Message-ID: <625385e30601270945o6d0651ferbb3482b6f3b1d12c@mail.gmail.com> On 1/27/06, Jeff A. Earickson wrote: > > Who uses spamcop anymore for either an RBL or SpamAssassin scoring? > I dropped them from my RBLs several months ago. The change above > may become permanent anyway because they tag a lot of stuff from > gmail, yahoo, etc. They seem to have got their heads wedged in the wrong > place. Anybody else feel this way??? > I give them 4 points in SA and have no complaints about it ever. My problems are due to ill configured Microsoft servers with mail applications like ASPmail, they default to 7-bit ASCII and when the messages contain, in my case, Swedish characters SA tags them with SUBJECT_ILLEGAL_CHARS and similar. It's a pain to convince the system owners that their systems are the cause and not mine. -- /peter -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060127/3ba84f4d/attachment.html From smf at f2s.com Fri Jan 27 18:03:32 2006 From: smf at f2s.com (Steve Freegard) Date: Fri Jan 27 18:03:07 2006 Subject: Upgrade to new Beta stops logging to MailWatch In-Reply-To: <002e01c62368$4e56f350$0705000a@DDF5DW71> References: <000301c62364$8c487b60$0705000a@DDF5DW71> <002e01c62368$4e56f350$0705000a@DDF5DW71> Message-ID: <1138385012.31572.104.camel@localhost.localdomain> On Fri, 2006-01-27 at 12:37 -0500, Steve Campbell wrote: > >> I seem to recall a problem asked before, but can't locate it. > >> > >> I have just tried the new Beta, as an upgrade. It does not seem to be > >> calling the MailWatch functions. Is there something I have overlooked? > >> There is nothing in the maillog indicating a call to this function. > >> Upgraded from 4.41 > >> Do you have a CustomConfig.pm.rpmsave file in /usr/lib/MailScanner/MailScanner?? If so, you need to copy the 'require MailScanner/MailWatch.pm' line and put it in the CustomConfig.pm file. Regards, Steve. From dave.list at pixelhammer.com Fri Jan 27 18:18:20 2006 From: dave.list at pixelhammer.com (DAve) Date: Fri Jan 27 18:18:38 2006 Subject: blank "is" report lines in syslog? In-Reply-To: References: Message-ID: <43DA63EC.7010400@pixelhammer.com> Jeff A. Earickson wrote: > > ===> BTW <==== > > Who uses spamcop anymore for either an RBL or SpamAssassin scoring? > I dropped them from my RBLs several months ago. The change above > may become permanent anyway because they tag a lot of stuff from > gmail, yahoo, etc. They seem to have got their heads wedged in the wrong > place. Anybody else feel this way??? > > Jeff Earickson > Colby College We dropped them after going round and round with them about bounce messages. My new concern is AOL. I am almost to the point of not allowing AOL addresses in any maillist we manage. If I could I would refuse to send any mail destind for AOL at all. I recently signed up on another AOL notification list and they began Joe-Jobbing me with obvious messages containing headers like so, Received: from isnjqvm.net (12-205-12-168.client.insightbb.com [12.205.12.168]) by rly-xl02.mx.aol.com (v108.32) with ESMTP id MAILRELAYINXL26-5ba43bbca4ec8; Wed, 04 Jan 2006 08:14:58 -0500 From: postmaster@tls.net To: mailingbox433@aim.com I need a new career, I do not see this ever getting better. :^( DAve From mkettler at evi-inc.com Fri Jan 27 18:29:26 2006 From: mkettler at evi-inc.com (Matt Kettler) Date: Fri Jan 27 18:29:34 2006 Subject: blank "is" report lines in syslog? In-Reply-To: <43DA63EC.7010400@pixelhammer.com> References: <43DA63EC.7010400@pixelhammer.com> Message-ID: <43DA6686.9050508@evi-inc.com> DAve wrote: > Jeff A. Earickson wrote: > >> >> ===> BTW <==== >> >> Who uses spamcop anymore for either an RBL or SpamAssassin scoring? > > We dropped them after going round and round with them about bounce > messages. I for one am SOOO glad spamcop blacklists sites generating backwash. In this day and age blind-accepting mail queues are just as bad a smurf amplifiers. Blacklist them all to hell until they clean up their act. From glenn.steen at gmail.com Fri Jan 27 18:38:20 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Jan 27 18:38:24 2006 Subject: MailScanner chokes In-Reply-To: <6.2.1.2.2.20060126105139.03169d00@pop.mail.yahoo.com> References: <82895A755D1EA5458EC9E64021922AD2D15674@city-exch-w3e.cbj.local> <6.2.1.2.2.20060125161634.0322c788@pop.mail.yahoo.com> <6.2.1.2.2.20060126105139.03169d00@pop.mail.yahoo.com> Message-ID: <223f97700601271038m41168b9ax@mail.gmail.com> On 26/01/06, hermit921 wrote: > At 04:55 PM 1/25/2006, Scott Silva wrote: > >hermit921 spake the following on 1/25/2006 4:36 PM: > > > We are starting to see a problem on 1 or 2 of our three MailScanner > > > systems where mail starts accumulating in the hold queue. We tried > > > various things, with little success. Turning off spamassassin in > > > MailScanner made no difference. Stopping MailScanner and starting > > > postfix, then doing postsuper -H ALL followed by postfix flush pushes > > > out all the messages. Of course this bypasses MailScanner. > > > > > > In Debug mode, we get the following, which isn't much. We waited > > > several minutes and this output never changed. Any ideas what is wrong? > > > > >Could the database be full? Corrupted? The file system the database is on full > >or out of inodes? > >Try and remove the call to the MailWatch logging module, and see if things > >clear up. That should clear up any doubt about the database being the culprit. > > > >-- > > We had changed the Always Looked Up Last line to no, but that made no > difference. The system has lots of free disk space, inodes, etc. > > hermit921 > If you postcat the fqueue files "on hold", do they look OK? You don't see dropped connections or other oddities in the mail log? -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From MailScanner at ecs.soton.ac.uk Fri Jan 27 18:42:30 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 27 18:42:35 2006 Subject: high spam ruleset, is this right? In-Reply-To: References: <43D954A8.8020206@ecs.soton.ac.uk> Message-ID: <43DA6996.4070509@ecs.soton.ac.uk> I try to work out what you meant, regardless of typos, mis-spellings, whatever. If I am trying to work out whether you said From, To, or FromOrTo, then all I actually need is look for an "f", a "t" or both in the word. And things like the ":" usually put after it is purely visual, it doesn't affect my ability to parse the line. It's all just part of the first word of the line. Jeff A. Earickson wrote: > Julian, > Thanks. I didn't realize the syntax was so forgiving. > > Jeff Earickson > Colby College > > On Thu, 26 Jan 2006, Julian Field wrote: > >> Date: Thu, 26 Jan 2006 23:00:56 +0000 >> From: Julian Field >> Reply-To: MailScanner discussion >> To: MailScanner discussion >> Subject: Re: high spam ruleset, is this right? >> >> >> >> Jeff A. Earickson wrote: >>> Hi, >>> Writing a ruleset for high spam actions, is this correct? >>> >>> To:\tadmissions@colby.edu\tforward >>> jaearick@colby.edu,dsjones@colby.edu delete >>> FromOrTo:\tdefault\tdelete >>> >>> Tabs (\t above) are required, right? I want high spam for >>> admissions to be forwarded to myself and dsjones and be >>> deleted from the admissions mailbox. Will this work? >> I've just read all the responses to this one, all sorts of >> interesting theories :-) >> The tabs are not necessary, any whitespace will do. >> The "delete" makes it look better, if that sort of thing yanks your >> chain. >> Separate the multiple email addresses with spaces, not commas. >> And the "forward" only actually makes it look pretty, too, but don't >> tell the syntax police I said that... >> >> This should do the same thing, and still look quite nice. >> To: admissions@colby.edu forward jaearick@colby.edu dsjones@colby.edu >> FromOrTo: default delete >> >> A million other variants would work too, I'm not particularly fussy >> about syntax, I can usually work out what you meant to write (for the >> value of me == MailScanner). >> >> -- >> Julian Field >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> Professional Support Services at www.MailScanner.biz >> MailScanner thanks transtec Computers for their support >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ugob at camo-route.com Fri Jan 27 18:49:46 2006 From: ugob at camo-route.com (Ugo Bellavance) Date: Fri Jan 27 18:50:09 2006 Subject: The article I wrote about mailscanner has been published In-Reply-To: <223f97700601251130l1912ca5cg@mail.gmail.com> References: <223f97700601251130l1912ca5cg@mail.gmail.com> Message-ID: Glenn Steen wrote: > On 25/01/06, Ugo Bellavance wrote: > (snip) >> -> "Filtering spam server-side" is my article. >> >> Hope there are no major issues in it, I wrote it some time ago and I had >> something like 2 hours to do the final revision. I especially remember >> asking to add a comma between 'spam' and 'server' in the title, but, eh... > > Well, there's some unbalanced quotes and the odd "will look at these > 3...." and then go on to mention four....:-) > But on the whole, it really turned out nice. Good job, Ugo! > ... And who would've known you're an avid telemark skier! :-) If you guys feel like sending me a list of corrections, feel free to do so, I'll ask the editor if they can re-create the PDF. TIA, -- Ugo -> Please don't send a copy of your reply by e-mail. I read the list. -> Please avoid top-posting, long signatures and HTML, and cut the irrelevant parts in your replies. From jaearick at colby.edu Fri Jan 27 18:50:18 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Fri Jan 27 18:50:30 2006 Subject: blank "is" report lines in syslog? In-Reply-To: <625385e30601270945o6d0651ferbb3482b6f3b1d12c@mail.gmail.com> References: <625385e30601270945o6d0651ferbb3482b6f3b1d12c@mail.gmail.com> Message-ID: Julian, After taking spamcop.net out of "Spam List =", my syslogs "Message... to colby.edu is " with the blank ending ceased. I dug thru the perl and it looks like $rblspamheader must not get set at either line 475 or 498 in Message.pm. So is something going wrong in MailScanner::RBLs::Checks with spamcop? Jeff Earickson Colby College From campbell at cnpapers.com Fri Jan 27 19:05:58 2006 From: campbell at cnpapers.com (Steve Campbell) Date: Fri Jan 27 19:06:11 2006 Subject: Upgrade to new Beta stops logging to MailWatch References: <000301c62364$8c487b60$0705000a@DDF5DW71> <002e01c62368$4e56f350$0705000a@DDF5DW71> <1138385012.31572.104.camel@localhost.localdomain> Message-ID: <004a01c62374$b518d5c0$0705000a@DDF5DW71> Steve, ----- Original Message ----- From: "Steve Freegard" To: "MailScanner discussion" Sent: Friday, January 27, 2006 1:03 PM Subject: Re: Upgrade to new Beta stops logging to MailWatch > On Fri, 2006-01-27 at 12:37 -0500, Steve Campbell wrote: >> >> I seem to recall a problem asked before, but can't locate it. >> >> >> >> I have just tried the new Beta, as an upgrade. It does not seem to be >> >> calling the MailWatch functions. Is there something I have overlooked? >> >> There is nothing in the maillog indicating a call to this function. >> >> Upgraded from 4.41 >> >> > > Do you have a CustomConfig.pm.rpmsave file > in /usr/lib/MailScanner/MailScanner?? There is no CustomConfig.pm.rpmsave (or rpmnew). > > If so, you need to copy the 'require MailScanner/MailWatch.pm' line and > put it in the CustomConfig.pm file. I did add this, though, as the one that was in there didn't have it. I'm a little confused now. It is still not working, and by that, I mean the Recent Messages are not showing any updates. Running "Reports" on a message I am sure went through after the upgrade does not show also. It appears that the logging to the database is now happening. I do see the "Config: calling custom init function MailWatchLogging" in the logs but never see the "disconnected from the database" line. locate returns nothing obvious for rpmnew and nothing for rpmsave (after running slocate -u, of course). Thanks > > Regards, > Steve. > > -- From campbell at cnpapers.com Fri Jan 27 19:08:08 2006 From: campbell at cnpapers.com (Steve Campbell) Date: Fri Jan 27 19:08:23 2006 Subject: Upgrade to new Beta stops logging to MailWatch References: <000301c62364$8c487b60$0705000a@DDF5DW71> <002e01c62368$4e56f350$0705000a@DDF5DW71> <1138385012.31572.104.camel@localhost.localdomain> Message-ID: <004f01c62375$02ad1080$0705000a@DDF5DW71> Steve, Never mind. The addition of the "require" seemed to fix it. I just wasn't patient enough. Some how, though, I'm not sure how it got removed, as this worked before the update, and it must have been there. Thanks all. Steve ----- Original Message ----- From: "Steve Freegard" To: "MailScanner discussion" Sent: Friday, January 27, 2006 1:03 PM Subject: Re: Upgrade to new Beta stops logging to MailWatch > On Fri, 2006-01-27 at 12:37 -0500, Steve Campbell wrote: >> >> I seem to recall a problem asked before, but can't locate it. >> >> >> >> I have just tried the new Beta, as an upgrade. It does not seem to be >> >> calling the MailWatch functions. Is there something I have overlooked? >> >> There is nothing in the maillog indicating a call to this function. >> >> Upgraded from 4.41 >> >> > > Do you have a CustomConfig.pm.rpmsave file > in /usr/lib/MailScanner/MailScanner?? > > If so, you need to copy the 'require MailScanner/MailWatch.pm' line and > put it in the CustomConfig.pm file. > > Regards, > Steve. > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From MailScanner at ecs.soton.ac.uk Fri Jan 27 19:09:06 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 27 19:09:12 2006 Subject: blank "is" report lines in syslog? In-Reply-To: References: <625385e30601270945o6d0651ferbb3482b6f3b1d12c@mail.gmail.com> Message-ID: <43DA6FD2.8080500@ecs.soton.ac.uk> Jeff A. Earickson wrote: > After taking spamcop.net out of "Spam List =", my syslogs > "Message... to colby.edu is " with the blank ending ceased. > I dug thru the perl and it looks like $rblspamheader must > not get set at either line 475 or 498 in Message.pm. So > is something going wrong in MailScanner::RBLs::Checks > with spamcop? Did it always do it? Or only occasionally? -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From glenn.steen at gmail.com Fri Jan 27 19:39:22 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Jan 27 19:39:25 2006 Subject: The article I wrote about mailscanner has been published In-Reply-To: References: <223f97700601251130l1912ca5cg@mail.gmail.com> Message-ID: <223f97700601271139t15766456q@mail.gmail.com> On 27/01/06, Ugo Bellavance wrote: > Glenn Steen wrote: > > On 25/01/06, Ugo Bellavance wrote: > > (snip) > >> -> "Filtering spam server-side" is my article. > >> > >> Hope there are no major issues in it, I wrote it some time ago and I had > >> something like 2 hours to do the final revision. I especially remember > >> asking to add a comma between 'spam' and 'server' in the title, but, eh... > > > > Well, there's some unbalanced quotes and the odd "will look at these > > 3...." and then go on to mention four....:-) > > But on the whole, it really turned out nice. Good job, Ugo! > > ... And who would've known you're an avid telemark skier! :-) > > If you guys feel like sending me a list of corrections, feel free to do > so, I'll ask the editor if they can re-create the PDF. > > TIA, > > -- > Ugo > ' Will take a .... more serious look..... But not tonight, after the beverages I've imbibed, you don't want my .... corrections. Perhaps tomorrow. -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From ugob at camo-route.com Fri Jan 27 19:45:04 2006 From: ugob at camo-route.com (Ugo Bellavance) Date: Fri Jan 27 19:45:59 2006 Subject: The article I wrote about mailscanner has been published In-Reply-To: <223f97700601271139t15766456q@mail.gmail.com> References: <223f97700601251130l1912ca5cg@mail.gmail.com> <223f97700601271139t15766456q@mail.gmail.com> Message-ID: Glenn Steen wrote: > On 27/01/06, Ugo Bellavance wrote: >> Glenn Steen wrote: >>> On 25/01/06, Ugo Bellavance wrote: >>> (snip) >>>> -> "Filtering spam server-side" is my article. >>>> >>>> Hope there are no major issues in it, I wrote it some time ago and I had >>>> something like 2 hours to do the final revision. I especially remember >>>> asking to add a comma between 'spam' and 'server' in the title, but, eh... >>> Well, there's some unbalanced quotes and the odd "will look at these >>> 3...." and then go on to mention four....:-) >>> But on the whole, it really turned out nice. Good job, Ugo! >>> ... And who would've known you're an avid telemark skier! :-) >> If you guys feel like sending me a list of corrections, feel free to do >> so, I'll ask the editor if they can re-create the PDF. >> >> TIA, >> >> -- >> Ugo >> > ' > Will take a .... more serious look..... But not tonight, after the > beverages I've imbibed, you don't want my .... corrections. > Perhaps tomorrow. > There is no rush... I'm leaving tonight to spend the w/e in a ski resort... Yes, telemark skiing, and maybe snowboard (in fact, the truth is that I'm an alpine snowboarder first, then a freeride snowboarder, then a telemark skier... So I won't have time to look at that before monday anyway. Thanks a lot, > -- > -- Glenn > email: glenn < dot > steen < at > gmail < dot > com > work: glenn < dot > steen < at > ap1 < dot > se -- Ugo -> Please don't send a copy of your reply by e-mail. I read the list. -> Please avoid top-posting, long signatures and HTML, and cut the irrelevant parts in your replies. From dave.list at pixelhammer.com Fri Jan 27 19:51:06 2006 From: dave.list at pixelhammer.com (DAve) Date: Fri Jan 27 19:51:24 2006 Subject: blank "is" report lines in syslog? In-Reply-To: <43DA6686.9050508@evi-inc.com> References: <43DA63EC.7010400@pixelhammer.com> <43DA6686.9050508@evi-inc.com> Message-ID: <43DA79AA.9040208@pixelhammer.com> Matt Kettler wrote: > DAve wrote: > >>Jeff A. Earickson wrote: >> >> >>>===> BTW <==== >>> >>>Who uses spamcop anymore for either an RBL or SpamAssassin scoring? > > >>We dropped them after going round and round with them about bounce >>messages. > > > I for one am SOOO glad spamcop blacklists sites generating backwash. In this day > and age blind-accepting mail queues are just as bad a smurf amplifiers. > Blacklist them all to hell until they clean up their act. We don't blindly accept messages. But we do send a bounce if the mailbox doesn't exist, or if the box is overquota, or if the message is too large, or delivery fails for any other reason. Some of these bounces will be after the connection and the message has been accepted. Email requires post-smtp bouncing, not just because of RFCs, but to work properly. But I won't go further as this has been torched in all directions on many many lists. Suffice to say he asked if anyone dropped SpamCop, I responded that we had, and stated why. DAve From jaearick at colby.edu Fri Jan 27 19:58:43 2006 From: jaearick at colby.edu (Jeff A. Earickson) Date: Fri Jan 27 19:58:48 2006 Subject: blank "is" report lines in syslog? In-Reply-To: <43DA6FD2.8080500@ecs.soton.ac.uk> References: <625385e30601270945o6d0651ferbb3482b6f3b1d12c@mail.gmail.com> <43DA6FD2.8080500@ecs.soton.ac.uk> Message-ID: On Fri, 27 Jan 2006, Julian Field wrote: > > Jeff A. Earickson wrote: >> After taking spamcop.net out of "Spam List =", my syslogs >> "Message... to colby.edu is " with the blank ending ceased. >> I dug thru the perl and it looks like $rblspamheader must >> not get set at either line 475 or 498 in Message.pm. So >> is something going wrong in MailScanner::RBLs::Checks >> with spamcop? > Did it always do it? Or only occasionally? Julian, After a bit of shell scripting and grepping on my syslog, I found that every instance of a blank ending had also triggered a hit from spamcop.net, eg: RBL checks: k0RGE4ch011484 found in spamcop.net for that same message. There's a 1:1 correspondence. Happy weekend! Jeff Earickson Colby College From mkettler at evi-inc.com Fri Jan 27 20:06:03 2006 From: mkettler at evi-inc.com (Matt Kettler) Date: Fri Jan 27 20:06:17 2006 Subject: blank "is" report lines in syslog? In-Reply-To: <43DA79AA.9040208@pixelhammer.com> References: <43DA63EC.7010400@pixelhammer.com> <43DA6686.9050508@evi-inc.com> <43DA79AA.9040208@pixelhammer.com> Message-ID: <43DA7D2B.8040907@evi-inc.com> DAve wrote: >> >> >> I for one am SOOO glad spamcop blacklists sites generating backwash. >> In this day >> and age blind-accepting mail queues are just as bad a smurf amplifiers. >> Blacklist them all to hell until they clean up their act. > > > We don't blindly accept messages. But we do send a bounce if the mailbox > doesn't exist, or if the box is overquota, or if the message is too > large, or delivery fails for any other reason. Some of these bounces > will be after the connection and the message has been accepted. Only overquota or "other reason" should be bounced post-accept. Message to large should be failed at the end of the SMTP data phase. Nonexistent mailbox should be failed at the SMTP RCPT TO phase. Anything else is bad practice. The problem is if you're doing post-delivery bounces for Nonexistent mailboxes, your server is effectively an open relay that spammers can abuse. This is the behavior I meant by "blind accepting mail queues".. The server will blindly accept any message to the local domain, even for nonexistent users. Spammers can abuse this as a relaying method by sending to a known nonexistent user. The return-path is the spammers intended recipient. This is called "reverse NDR" style spam relaying. If a spammer uses your box for reverse NDR spam relaying, IMHO you're a spam relay and should be treated the same as an open relay operator. I know that's a bit harsh, but the reality is that while post delivery bounces for nonexistent users are RFC legal, so is open relaying. Both are just insecurity problems and bad practice, but both provide spammers the same tools. > Email requires post-smtp bouncing, not just because of RFCs, but to work properly. But I won't go further as this has been torched in all directions on many many lists. I agree 100%.. We do need post-delivery bouncing. I just think that post-smtp bouncing should not be used when it could be prevented by properly validating the recipient mailbox at SMTP time. From dave.list at pixelhammer.com Fri Jan 27 20:41:33 2006 From: dave.list at pixelhammer.com (DAve) Date: Fri Jan 27 20:41:51 2006 Subject: blank "is" report lines in syslog? In-Reply-To: <43DA7D2B.8040907@evi-inc.com> References: <43DA63EC.7010400@pixelhammer.com> <43DA6686.9050508@evi-inc.com> <43DA79AA.9040208@pixelhammer.com> <43DA7D2B.8040907@evi-inc.com> Message-ID: <43DA857D.9080803@pixelhammer.com> If I had someone to just stand behind me and beat me on the head with a bat, I could save all this typing, and I would never have to answer the phone. The result at the end of my day, would be the same. Matt Kettler wrote: > DAve wrote: > > >>> >>>I for one am SOOO glad spamcop blacklists sites generating backwash. >>>In this day >>>and age blind-accepting mail queues are just as bad a smurf amplifiers. >>>Blacklist them all to hell until they clean up their act. >> >> >>We don't blindly accept messages. But we do send a bounce if the mailbox >>doesn't exist, or if the box is overquota, or if the message is too >>large, or delivery fails for any other reason. Some of these bounces >>will be after the connection and the message has been accepted. > > > Only overquota or "other reason" should be bounced post-accept. > > Message to large should be failed at the end of the SMTP data phase. > > Nonexistent mailbox should be failed at the SMTP RCPT TO phase. > > Anything else is bad practice. > > The problem is if you're doing post-delivery bounces for Nonexistent mailboxes, > your server is effectively an open relay that spammers can abuse. > > This is the behavior I meant by "blind accepting mail queues".. The server will > blindly accept any message to the local domain, even for nonexistent users. > Spammers can abuse this as a relaying method by sending to a known nonexistent > user. The return-path is the spammers intended recipient. This is called > "reverse NDR" style spam relaying. > > > If a spammer uses your box for reverse NDR spam relaying, IMHO you're a spam > relay and should be treated the same as an open relay operator. > > > I know that's a bit harsh, but the reality is that while post delivery bounces > for nonexistent users are RFC legal, so is open relaying. Both are just > insecurity problems and bad practice, but both provide spammers the same tools. > > >>Email requires post-smtp bouncing, not just because of RFCs, but to work properly. But I won't go further as this has been torched in all directions on many many lists. > > > I agree 100%.. We do need post-delivery bouncing. > > I just think that post-smtp bouncing should not be used when it could be > prevented by properly validating the recipient mailbox at SMTP time. > > From drolland at kdinet.com Fri Jan 27 20:56:20 2006 From: drolland at kdinet.com (Diane Rolland) Date: Fri Jan 27 20:56:25 2006 Subject: Upgrading from 4.37 (I know, I know, it's OLD) Message-ID: <01ee01c62384$212adbf0$6500a8c0@kdinet.local> I want to upgrade my older MailScanner version to (probably) the latest stable. I would be using the rpm installation for RedHat. So, normally, I'm comfortable with that type of upgrade. My concern is that since my version is SO old, is there anything I need to look out for in upgrading to the latest? I'm using pretty standard rulesets (whitelist, blacklist, archive, non.spam.actions). So, any insights on what I should look out for would be greatly appreciated. For those of you who also subscribe to mailwatch-users, you are probably laughing out loud at my question... My mailwatch upgrade from 0.5.1 --> 1.0 --> 1.03 on my MailScanner 4.37 version wasn't exactly smooth... My GREATEST THANKS goes to Steve Freegard who helped me through it. Steve, you ROCK! Thanks, Diane p.s. And, yes, I do have the book; (I've purchased the last two revisions). From mkettler at evi-inc.com Fri Jan 27 20:56:43 2006 From: mkettler at evi-inc.com (Matt Kettler) Date: Fri Jan 27 20:56:51 2006 Subject: blank "is" report lines in syslog? In-Reply-To: <43DA857D.9080803@pixelhammer.com> References: <43DA63EC.7010400@pixelhammer.com> <43DA6686.9050508@evi-inc.com> <43DA79AA.9040208@pixelhammer.com> <43DA7D2B.8040907@evi-inc.com> <43DA857D.9080803@pixelhammer.com> Message-ID: <43DA890B.4080402@evi-inc.com> DAve wrote: > If I had someone to just stand behind me and beat me on the head with a > bat, I could save all this typing, and I would never have to answer the > phone. The result at the end of my day, would be the same. Easy.. I'm not meaning to flame you, just pointing out the basic truth.. Validating recipients isn't that hard, even for qmail users. You're in the same basic place that many mail operators were in when spammers discovered making use of open relays. At the time open relays were commonly accepted. Ditto for router operators when DoS kiddies discovered the smurf technique. Abuse patterns change over time, your servers need to adapt to avoid being exploited to abuse others. This is just another new abuse pattern. Fix it, deal with it. You don't even need to violate any RFCs or break email to do it. Nobody is telling you to never send bounces. All you need to do is validate recipients with something like qmail-ldap. If you head-in-sand the problem and put up arguments about RFC requirements, you're going to get blacklisted. You don't have to do that. This isn't very hard to fix. From michele at blacknight.ie Fri Jan 27 21:19:47 2006 From: michele at blacknight.ie (Michele Neylon:: Blacknight.ie) Date: Fri Jan 27 21:19:49 2006 Subject: Upgrading from 4.37 (I know, I know, it's OLD) In-Reply-To: <01ee01c62384$212adbf0$6500a8c0@kdinet.local> References: <01ee01c62384$212adbf0$6500a8c0@kdinet.local> Message-ID: <43DA8E73.8050309@blacknight.ie> Diane I'd recommend you grab a copy of the non-rpm version and examine the config files locally before deploying onto your live environment. I can't think of the changes offhand, though the changelog would probably be a good place to start. I'd also recommend you look at the beta, as Julian normally releases a stable version on the first of each month, so a "play" with the beta would lead you to a nice clean upgrade when the next stable comes out HTH M -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 From MailScanner at ecs.soton.ac.uk Fri Jan 27 21:34:48 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Jan 27 21:34:52 2006 Subject: Upgrading from 4.37 (I know, I know, it's OLD) In-Reply-To: <01ee01c62384$212adbf0$6500a8c0@kdinet.local> References: <01ee01c62384$212adbf0$6500a8c0@kdinet.local> Message-ID: <43DA91F8.6080809@ecs.soton.ac.uk> Diane Rolland wrote: > I want to upgrade my older MailScanner version to (probably) the latest > stable. > New stable version due out on the 1st of Feb, wait until then as you really do want the new features in 4.50. > > I would be using the rpm installation for RedHat. So, normally, I'm > comfortable with that type of upgrade. > > My concern is that since my version is SO old, is there anything I need to > look out for in upgrading to the latest? I'm using pretty standard rulesets > (whitelist, blacklist, archive, non.spam.actions). > Don't forget about running upgrade_languages_conf and upgrade_MailScanner_conf. Once you have 4.50 installed, you can run MailScanner --lint to syntax check your configuration. As someone else has suggested, it might be a good idea to do a dummy run of the upgrade (particularly be able to run upgrade_MailScanner_conf) so you can see all the new configuration options being installed into your setup. Either install the RPM version onto another machine, or use the non-RPM version to get the new MailScanner.conf. You should find all the new settings are set to sensible values, but you may well want to see the new ones and read about them. If you want some help, do ask for it. I'm usually around on IRC during sensible GMT hours if you need me. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From steve.swaney at fsl.com Fri Jan 27 13:00:40 2006 From: steve.swaney at fsl.com (Stephen Swaney) Date: Fri Jan 27 22:00:46 2006 Subject: spam rules In-Reply-To: Message-ID: <200601272200.k0RM0i6C019546@bkserver.blacknight.ie> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of TAC Forums > Sent: Friday, January 27, 2006 7:44 AM > To: mailscanner@lists.mailscanner.info > Subject: spam rules > > Hi All, > > I have a strange problem with spam detection on one of our servers, > > A domain hosted with us, has th efollowing rules in spam.whitelist.rules > > From:*@abc.com yes > > Still, when they send Emails even to someone in abc.com, the message > is checked for Spam. > The Default rules is, > > >From or To: default no > > Is there any thing wrong with this? > > -- > TAC Support Team > > > -- > TAC Support Team > -- Did you really mean? From:*@abc.com yes There should be white space, spaces or tabs, between the fields: From: *@abc.com yes Steve Stephen Swaney Fort Systems Ltd. stephen.swaney@fsl.com www.fsl.com From dave.list at pixelhammer.com Fri Jan 27 22:02:14 2006 From: dave.list at pixelhammer.com (DAve) Date: Fri Jan 27 22:02:36 2006 Subject: blank "is" report lines in syslog? In-Reply-To: <43DA890B.4080402@evi-inc.com> References: <43DA63EC.7010400@pixelhammer.com> <43DA6686.9050508@evi-inc.com> <43DA79AA.9040208@pixelhammer.com> <43DA7D2B.8040907@evi-inc.com> <43DA857D.9080803@pixelhammer.com> <43DA890B.4080402@evi-inc.com> Message-ID: <43DA9866.9070009@pixelhammer.com> Matt Kettler wrote: > DAve wrote: > >>If I had someone to just stand behind me and beat me on the head with a >>bat, I could save all this typing, and I would never have to answer the >>phone. The result at the end of my day, would be the same. > > Easy.. I'm not meaning to flame you, just pointing out the basic truth.. Didn't take it that way. I'm already numb, no bat needed, I'll keep typing. > Validating recipients isn't that hard, even for qmail users. Thanks, but I don't consider myself challenged. > You're in the same basic place that many mail operators were in when spammers > discovered making use of open relays. At the time open relays were commonly > accepted. Why would that be? I'm not an open relay. If you connect to one of my MailScanner boxes, milter-ahead will check for the existance of the recipient account on my toasters, and accept or reject the connection. How does that make me an open relay? As I said, "I don't blindly accept messages". Please read the entire message again. Maybe my point needed an example, or two. If a message (or a thousand) is accepted based on milter-ahead, and MailScanner picks it up from the incoming queue, scans it, places it in the outgoing queue, as a support tech deletes the target domain, KAPOW!, the message(s) is(are) bounced. This has happened, to me. A message comes in on MailScanner box #1, it is a 15mb attachment. It takes awhile to get through MailScanner and be delivered to the toaster, and for the toaster to update the users quota. But Milter-ahead checked before the message was accepted, and there is room to deliver the message. Unfortunately, MailScanner box #2 has a 3mb message that gets through a bit faster, lands on the toaster, and gets delivered. Now when MailScanner box #1 tries to deliver, the message won't fit within the quota. KAPOW!, the message is bounced. This has happened as well, to me. This is a result of the way MailScanner works when sitting in front of other servers. Those servers can be Exchange, qmail Toasters, Postfix campus relays, it doesn't matter. When you have multiple MailScanner boxes the problem is compounded. post-smtp bounces can and will happen. Milter-ahead has a caching timeout which can be useful here, and CHECKUSER has a quota setting which can help to avoid message overlap as well (reject at a percentage of full, leaving room for deliveries from other queues). I utilise several techniques to minimize failures. But problems do arise, messages will get bounced after they are accepted. It's a fact of life, it's a fact of SMTP. I'm tired. I need a drink. From Kevin_Miller at ci.juneau.ak.us Fri Jan 27 22:28:45 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Fri Jan 27 22:28:53 2006 Subject: This is weird Message-ID: <82895A755D1EA5458EC9E64021922AD2D15693@city-exch-w3e.cbj.local> This morning I started directing our firewall logging to a syslog server. I noticed a *whole lot* of these: Jan 27 10:18:34 199.58.55.6 %PIX-4-106023: Deny icmp src inside:mxg dst outside:66.250.40.33 (type 3, code 3) by access-group "acl_inside" There were a couple other outside IP addresses too, like 37.208.8.26 (samantha.wu-wien.ac.at), 208.201.249.233 (eth0.c.spam.sonic.net), and 66.250.40.33 (clapton.quatro.com), as well as a few others. Gotta love that, ...spam.sonic.net! Get several every second or so. There's no reason (that I can figure) for mxg (my mail gateway) to be sending icmp type 3, code 3 packets, which I understand to be 'destination unreachable' responses. When I stop MailScanner the packets immediately dry up (hence my posting here). MailScanner is utilizing MailWatch, pyzor, razor and spamassassin. As soon as I restart MailScanner the warnings resume. I'm stumped... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From ka at pacific.net Fri Jan 27 22:42:09 2006 From: ka at pacific.net (Ken A) Date: Fri Jan 27 22:42:12 2006 Subject: This is weird In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D15693@city-exch-w3e.cbj.local> References: <82895A755D1EA5458EC9E64021922AD2D15693@city-exch-w3e.cbj.local> Message-ID: <43DAA1C1.3050704@pacific.net> sonic.net (a neighbor of ours) runs a dccd server, as I bet these others do as well. Probably something dccifd does, though I'm not sure why. Ken Pacific.Net Kevin Miller wrote: > This morning I started directing our firewall logging to a syslog > server. I noticed a *whole lot* of these: > Jan 27 10:18:34 199.58.55.6 %PIX-4-106023: Deny icmp src inside:mxg dst > outside:66.250.40.33 (type 3, code 3) by access-group "acl_inside" > > There were a couple other outside IP addresses too, like 37.208.8.26 > (samantha.wu-wien.ac.at), 208.201.249.233 (eth0.c.spam.sonic.net), and > 66.250.40.33 (clapton.quatro.com), as well as a few others. > > Gotta love that, ...spam.sonic.net! > > Get several every second or so. There's no reason (that I can figure) > for mxg (my mail gateway) to be sending icmp type 3, code 3 packets, > which I understand to be 'destination unreachable' responses. > > When I stop MailScanner the packets immediately dry up (hence my posting > here). MailScanner is utilizing MailWatch, pyzor, razor and > spamassassin. > > As soon as I restart MailScanner the warnings resume. I'm stumped... > > ...Kevin From ssilva at sgvwater.com Fri Jan 27 23:01:37 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Jan 27 23:02:26 2006 Subject: Upgrading from 4.37 (I know, I know, it's OLD) In-Reply-To: <01ee01c62384$212adbf0$6500a8c0@kdinet.local> References: <01ee01c62384$212adbf0$6500a8c0@kdinet.local> Message-ID: Diane Rolland spake the following on 1/27/2006 12:56 PM: > I want to upgrade my older MailScanner version to (probably) the latest > stable. > > I would be using the rpm installation for RedHat. So, normally, I'm > comfortable with that type of upgrade. > > My concern is that since my version is SO old, is there anything I need to > look out for in upgrading to the latest? I'm using pretty standard rulesets > (whitelist, blacklist, archive, non.spam.actions). > > So, any insights on what I should look out for would be greatly appreciated. > > For those of you who also subscribe to mailwatch-users, you are probably > laughing out loud at my question... My mailwatch upgrade from 0.5.1 --> 1.0 > --> 1.03 on my MailScanner 4.37 version wasn't exactly smooth... My > GREATEST THANKS goes to Steve Freegard who helped me through it. Steve, you > ROCK! > > Thanks, > Diane > > p.s. And, yes, I do have the book; (I've purchased the last two revisions). > This upgrade, might negate some of the changes you had to make to get this working in the first place. Some of the code that Steve had you comment out can be uncommented. I would recommend you run the install.sh script in the rpm install tarball, and I have attached quick and dirty script to back up your current configuration before you start. It isn't hard to follow, and allows you to quickly go back if need be. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! -------------- next part -------------- A non-text attachment was scrubbed... Name: msup.tgz Type: application/x-compressed Size: 197 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060127/f51aaa34/msup.bin From jose at iqcd.ucsb.edu Fri Jan 27 23:27:31 2006 From: jose at iqcd.ucsb.edu (Jose Guevarra) Date: Fri Jan 27 23:27:45 2006 Subject: MS not allowing ANY attachments Message-ID: <43DAAC63.7070102@iqcd.ucsb.edu> Hi, I'm using MS 4.4.3 MS seems to be catching ALL attachments. Every time I try to start MS I get errors like these Jan 27 15:25:48 saibot MailScanner[7485]: Syntax error in first field in line 17 of ruleset /etc/MailScanner/filetype.rules Jan 27 15:25:48 saibot MailScanner[7485]: Syntax error in first field in line 18 of ruleset /etc/MailScanner/filetype.rules Jan 27 15:25:48 saibot MailScanner[7485]: Syntax error in first field in line 19 of ruleset /etc/MailScanner/filetype.rules Jan 27 15:25:48 saibot MailScanner[7485]: Syntax error in first field in line 20 of ruleset /etc/MailScanner/filetype.rules Jan 27 15:25:48 saibot MailScanner[7485]: Syntax error in first field in line 21 of ruleset /etc/MailScanner/filetype.rules However, I haven't edited the rules and I even replaced them with rules from the original source code. Any ideas? From Kevin_Miller at ci.juneau.ak.us Fri Jan 27 23:34:16 2006 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Fri Jan 27 23:34:26 2006 Subject: This is weird Message-ID: <82895A755D1EA5458EC9E64021922AD2D15698@city-exch-w3e.cbj.local> Ken A wrote: > sonic.net (a neighbor of ours) runs a dccd server, as I bet these > others do as well. Probably something dccifd does, though I'm not > sure why. Ken > Pacific.Net Thought it might be something like that. Figured sonic's host was a spamtrap or tarpit. Not likely we've got a really really honest spammer out there! I have UDP port 6277 open for outbound so DCC should be OK. I ran "spamassassin -D --lint" and did see the following output: debug: DCCifd is not available: no r/w dccifd socket found. debug: DCC is not available: no executable dccproc found. so maybe not all is well in DCC land. Not sure what it's telling me there. In spam.assassin.rules.conf I uncommented the "use DCC 0" line to disable it and restarted. I'm still seeing attempted traffic to 66.250.40.33 (clapton.quatro.com), but the others seem to have abated. Maybe I'll disable razor and pyzor too and see what happens, then add things back in when I absolve them. Guess I can look to troubleshooting DCC Monday morning. Any clues to that appreciated. Thanks... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From mkettler at evi-inc.com Fri Jan 27 23:51:21 2006 From: mkettler at evi-inc.com (Matt Kettler) Date: Fri Jan 27 23:51:31 2006 Subject: blank "is" report lines in syslog? In-Reply-To: <43DA9866.9070009@pixelhammer.com> References: <43DA63EC.7010400@pixelhammer.com> <43DA6686.9050508@evi-inc.com> <43DA79AA.9040208@pixelhammer.com> <43DA7D2B.8040907@evi-inc.com> <43DA857D.9080803@pixelhammer.com> <43DA890B.4080402@evi-inc.com> <43DA9866.9070009@pixelhammer.com> Message-ID: <43DAB1F9.6090003@evi-inc.com> DAve wrote: >> You're in the same basic place that many mail operators were in when >> spammers >> discovered making use of open relays. At the time open relays were >> commonly >> accepted. > > > Why would that be? I'm not an open relay. If you connect to one of my > MailScanner boxes, milter-ahead will check for the existance of the > recipient account on my toasters, and accept or reject the connection. > How does that make me an open relay? Well then you don't have the problem I'm talking about. When you said you "weren't blind queuing" it was unclear you understood what I meant. Some people claim that checking the domain only is enough to be "non blind". > A message comes in on MailScanner box #1, it is a 15mb attachment. It takes awhile to get through MailScanner and be delivered to the toaster, and for the toaster to update the users quota. But Milter-ahead checked before the message was accepted, and there is room to deliver the message. Unfortunately, MailScanner box #2 has a 3mb message that gets through a bit faster, lands on the toaster, and gets delivered. Now when MailScanner box #1 tries to deliver, the message won't fit within the quota. KAPOW!, the message is bounced. This has happened as well, to me. Are you sure milter-ahead verifies the storage at all? I did not realize it had this ability. However, I originally said that insufficient queue was a reasonable case to cause post-delivery bounces. > post-smtp bounces can and will happen. Agreed.. They only shouldn't happen for nonexistent users, except the corner-case of arrives-at-instant of deletion. From steve.swaney at fsl.com Fri Jan 27 23:53:34 2006 From: steve.swaney at fsl.com (Stephen Swaney) Date: Fri Jan 27 23:53:36 2006 Subject: MS not allowing ANY attachments In-Reply-To: <43DAAC63.7070102@iqcd.ucsb.edu> Message-ID: <200601272353.k0RNrZlD021770@bkserver.blacknight.ie> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Jose Guevarra > Sent: Friday, January 27, 2006 6:28 PM > To: mailscanner@lists.mailscanner.info > Subject: MS not allowing ANY attachments > > Hi, > > I'm using MS 4.4.3 > > MS seems to be catching ALL attachments. Every time I try to start MS I > get errors like these > > Jan 27 15:25:48 saibot MailScanner[7485]: Syntax error in first field in > line 17 of ruleset /etc/MailScanner/filetype.rules > Jan 27 15:25:48 saibot MailScanner[7485]: Syntax error in first field in > line 18 of ruleset /etc/MailScanner/filetype.rules > Jan 27 15:25:48 saibot MailScanner[7485]: Syntax error in first field in > line 19 of ruleset /etc/MailScanner/filetype.rules > Jan 27 15:25:48 saibot MailScanner[7485]: Syntax error in first field in > line 20 of ruleset /etc/MailScanner/filetype.rules > Jan 27 15:25:48 saibot MailScanner[7485]: Syntax error in first field in > line 21 of ruleset /etc/MailScanner/filetype.rules > > However, I haven't edited the rules and I even replaced them with rules > from the original source code. > > Any ideas? > Check that the files in the file are separated by TABs not spaces I quote from the filename.rules.conf file: # # NOTE: Fields are separated by TAB characters --- Important! # # Syntax is allow/deny/deny+delete, then regular expression, then log text, # then user report text. Hope this helps, Steve Stephen Swaney Fort Systems Ltd. stephen.swaney@fsl.com www.fsl.com From mkettler at evi-inc.com Fri Jan 27 23:54:24 2006 From: mkettler at evi-inc.com (Matt Kettler) Date: Fri Jan 27 23:54:32 2006 Subject: This is weird In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D15693@city-exch-w3e.cbj.local> References: <82895A755D1EA5458EC9E64021922AD2D15693@city-exch-w3e.cbj.local> Message-ID: <43DAB2B0.3020203@evi-inc.com> Kevin Miller wrote: > This morning I started directing our firewall logging to a syslog > server. I noticed a *whole lot* of these: > Jan 27 10:18:34 199.58.55.6 %PIX-4-106023: Deny icmp src inside:mxg dst > outside:66.250.40.33 (type 3, code 3) by access-group "acl_inside" You deny ICMP port unreachable messages??? Ouch. That will hurt network performance under error conditions. Perhaps you should rethink what ICMP codes you're filtering on your PIX ACLs. From cplists at princeservices.com Fri Jan 27 23:55:49 2006 From: cplists at princeservices.com (Cameron B. Prince) Date: Fri Jan 27 23:55:57 2006 Subject: Sending mail to /dev/null without scanning Message-ID: <017a01c6239d$3398d710$0201a8c0@PSLAPTOP1> Hey guys, I have been getting a lot of emails coming in with CC's to every-name-known to-man@mydomain.com. It bothered me that so many of my mail server's resources and my internet connection were both being used to send bounces and that this could also be an attempt to determine valid addresses. I did some research and came up with creating an alias like this: garbage: /dev/null Then in my virtusertable I have something like this: bob@host.com bob tim@host.com tim @host.com garbage It works, but now instead of bouncing, the messages are all scanned and then sent to /dev/null. I need to configure MailScanner so that it doesn't scan these messages destined for oblivion. Jan 27 17:41:00 p2 sendmail[14975]: k0RNeu33014975: from=, size=1421, class=0, nrcpts=1, msgid=, proto=SMTP, daemon=MTA, relay=[221.0.209.135] Jan 27 17:41:00 p2 MailScanner[14330]: New Batch: Scanning 1 messages, 1883 bytes Jan 27 17:41:01 p2 MailScanner[14330]: Virus and Content Scanning: Starting Jan 27 17:41:01 p2 MailScanner[14330]: Uninfected: Delivered 1 messages Jan 27 17:41:01 p2 MailScanner[14330]: Logging message k0RNeu33014975 to SQL Jan 27 17:41:01 p2 MailScanner[14294]: k0RNeu33014975: Logged to MailWatch SQL Jan 27 17:41:01 p2 sendmail[14980]: k0RNeu33014975: to=/dev/null, ctladdr= (8/0), delay=00:00:03, xdelay=00:00:00, mailer=*file*, pri=121421, dsn=2.0.0, stat=Sent I setup a ruleset like this in the scan.messages.rules file: To: /dev/null no FromOrTo: default yes I have this in the .conf file Scan Messages = %rules-dir%/scan.messages.rules MailScanner continues to scan the mail even though the to line states " to=/dev/null" Can anyone tell me if this is possible and what I may be doing wrong? Thanks, Cameron From ka at pacific.net Sat Jan 28 00:05:04 2006 From: ka at pacific.net (Ken A) Date: Sat Jan 28 00:05:05 2006 Subject: This is weird In-Reply-To: <82895A755D1EA5458EC9E64021922AD2D15698@city-exch-w3e.cbj.local> References: <82895A755D1EA5458EC9E64021922AD2D15698@city-exch-w3e.cbj.local> Message-ID: <43DAB530.3070809@pacific.net> Kevin Miller wrote: > Ken A wrote: >> sonic.net (a neighbor of ours) runs a dccd server, as I bet these >> others do as well. Probably something dccifd does, though I'm not >> sure why. Ken >> Pacific.Net > > Thought it might be something like that. Figured sonic's host was a > spamtrap or tarpit. Not likely we've got a really really honest spammer > out there! > > I have UDP port 6277 open for outbound so DCC should be OK. I ran > "spamassassin -D --lint" and did see the following output: > > debug: DCCifd is not available: no r/w dccifd socket found. > debug: DCC is not available: no executable dccproc found. > > so maybe not all is well in DCC land. Not sure what it's telling me > there. > > In spam.assassin.rules.conf I uncommented the "use DCC 0" line to > disable it and restarted. I'm still seeing attempted traffic to > 66.250.40.33 (clapton.quatro.com), but the others seem to have abated. > Maybe I'll disable razor and pyzor too and see what happens, then add > things back in when I absolve them. > > Guess I can look to troubleshooting DCC Monday morning. Any clues to > that appreciated. dcc is a bit of an odd bird when it comes to installing and configuring. Just grab the source, configure, make, make install it and it puts itself in /var/dcc. _All_ of it is in /var/dcc. The cron jobs, the config file, init scripts, the executables, everything. Here's the wiki entry that explains how to install it: http://wiki.mailscanner.info/doku.php?id=documentation:anti_spam:spamassassin:plugins:dcc:dccifd_install&s=dcc Ken Pacific.Net > > Thanks... > > ...Kevin From ka at pacific.net Sat Jan 28 00:08:05 2006 From: ka at pacific.net (Ken A) Date: Sat Jan 28 00:08:06 2006 Subject: Sending mail to /dev/null without scanning In-Reply-To: <017a01c6239d$3398d710$0201a8c0@PSLAPTOP1> References: <017a01c6239d$3398d710$0201a8c0@PSLAPTOP1> Message-ID: <43DAB5E5.9000000@pacific.net> Put entries in your access table instead. To:bob@mydomain.com RELAY To:tim@mydomain.com RELAY # # Default Entry to Reject all others # To:mydomain.com ERROR:5.1.1:550 User unknown That way sendmail will reject them for you and mailscanner will never see them. (don't forget to "makemap hash access < access") Ken Pacific.Net Cameron B. Prince wrote: > Hey guys, > > I have been getting a lot of emails coming in with CC's to every-name-known > to-man@mydomain.com. It bothered me that so many of my mail server's > resources and my internet connection were both being used to send bounces > and that this could also be an attempt to determine valid addresses. > > I did some research and came up with creating an alias like this: > > garbage: /dev/null > > Then in my virtusertable I have something like this: > > bob@host.com bob > tim@host.com tim > @host.com garbage > > It works, but now instead of bouncing, the messages are all scanned and then > sent to /dev/null. I need to configure MailScanner so that it doesn't scan > these messages destined for oblivion. > > Jan 27 17:41:00 p2 sendmail[14975]: k0RNeu33014975: > from=, size=1421, class=0, nrcpts=1, > msgid=, proto=SMTP, daemon=MTA, > relay=[221.0.209.135] > Jan 27 17:41:00 p2 MailScanner[14330]: New Batch: Scanning 1 messages, 1883 > bytes > Jan 27 17:41:01 p2 MailScanner[14330]: Virus and Content Scanning: Starting > Jan 27 17:41:01 p2 MailScanner[14330]: Uninfected: Delivered 1 messages > Jan 27 17:41:01 p2 MailScanner[14330]: Logging message k0RNeu33014975 to SQL > Jan 27 17:41:01 p2 MailScanner[14294]: k0RNeu33014975: Logged to MailWatch > SQL > Jan 27 17:41:01 p2 sendmail[14980]: k0RNeu33014975: to=/dev/null, > ctladdr= (8/0), delay=00:00:03, xdelay=00:00:00, > mailer=*file*, pri=121421, dsn=2.0.0, stat=Sent > > I setup a ruleset like this in the scan.messages.rules file: > > To: /dev/null no > FromOrTo: default yes > > I have this in the .conf file > > Scan Messages = %rules-dir%/scan.messages.rules > > MailScanner continues to scan the mail even though the to line states " > to=/dev/null" > > Can anyone tell me if this is possible and what I may be doing wrong? > > Thanks, > Cameron > From cplists at princeservices.com Sat Jan 28 00:20:58 2006 From: cplists at princeservices.com (Cameron B. Prince) Date: Sat Jan 28 00:21:00 2006 Subject: Sending mail to /dev/null without scanning In-Reply-To: <43DAB5E5.9000000@pacific.net> Message-ID: <017e01c623a0$b68f4520$0201a8c0@PSLAPTOP1> Hi Ken, Thanks for your reply... This does not do what I need. I don't want to send a bounce. I want the sender to have no idea that the address isn't good. Cameron > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Ken A > Sent: Friday, January 27, 2006 6:08 PM > To: MailScanner discussion > Subject: Re: Sending mail to /dev/null without scanning > > Put entries in your access table instead. > > To:bob@mydomain.com RELAY > To:tim@mydomain.com RELAY > # > # Default Entry to Reject all others > # > To:mydomain.com ERROR:5.1.1:550 User unknown > > That way sendmail will reject them for you and mailscanner will never > see them. (don't forget to "makemap hash access < access") > > Ken > Pacific.Net > > > Cameron B. Prince wrote: > > Hey guys, > > > > I have been getting a lot of emails coming in with CC's to every-name- > known > > to-man@mydomain.com. It bothered me that so many of my mail server's > > resources and my internet connection were both being used to send > bounces > > and that this could also be an attempt to determine valid addresses. > > > > I did some research and came up with creating an alias like this: > > > > garbage: /dev/null > > > > Then in my virtusertable I have something like this: > > > > bob@host.com bob > > tim@host.com tim > > @host.com garbage > > > > It works, but now instead of bouncing, the messages are all scanned and > then > > sent to /dev/null. I need to configure MailScanner so that it doesn't > scan > > these messages destined for oblivion. > > > > Jan 27 17:41:00 p2 sendmail[14975]: k0RNeu33014975: > > from=, size=1421, class=0, nrcpts=1, > > msgid=, proto=SMTP, daemon=MTA, > > relay=[221.0.209.135] > > Jan 27 17:41:00 p2 MailScanner[14330]: New Batch: Scanning 1 messages, > 1883 > > bytes > > Jan 27 17:41:01 p2 MailScanner[14330]: Virus and Content Scanning: > Starting > > Jan 27 17:41:01 p2 MailScanner[14330]: Uninfected: Delivered 1 messages > > Jan 27 17:41:01 p2 MailScanner[14330]: Logging message k0RNeu33014975 to > SQL > > Jan 27 17:41:01 p2 MailScanner[14294]: k0RNeu33014975: Logged to > MailWatch > > SQL > > Jan 27 17:41:01 p2 sendmail[14980]: k0RNeu33014975: to=/dev/null, > > ctladdr= (8/0), delay=00:00:03, xdelay=00:00:00, > > mailer=*file*, pri=121421, dsn=2.0.0, stat=Sent > > > > I setup a ruleset like this in the scan.messages.rules file: > > > > To: /dev/null no > > FromOrTo: default yes > > > > I have this in the .conf file > > > > Scan Messages = %rules-dir%/scan.messages.rules > > > > MailScanner continues to scan the mail even though the to line states " > > to=/dev/null" > > > > Can anyone tell me if this is possible and what I may be doing wrong? > > > > Thanks, > > Cameron > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From ka at pacific.net Sat Jan 28 00:39:29 2006 From: ka at pacific.net (Ken A) Date: Sat Jan 28 00:39:30 2006 Subject: Sending mail to /dev/null without scanning In-Reply-To: <017e01c623a0$b68f4520$0201a8c0@PSLAPTOP1> References: <017e01c623a0$b68f4520$0201a8c0@PSLAPTOP1> Message-ID: <43DABD41.3020106@pacific.net> Ah, well that's a spam magnet you are engineering! Anyhow, you can change RELAY to DISCARD for the desired effect. Ken Pacific.Net Cameron B. Prince wrote: > Hi Ken, > > Thanks for your reply... This does not do what I need. > > I don't want to send a bounce. I want the sender to have no idea that the > address isn't good. > > Cameron > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Ken A >> Sent: Friday, January 27, 2006 6:08 PM >> To: MailScanner discussion >> Subject: Re: Sending mail to /dev/null without scanning >> >> Put entries in your access table instead. >> >> To:bob@mydomain.com RELAY >> To:tim@mydomain.com RELAY >> # >> # Default Entry to Reject all others >> # >> To:mydomain.com ERROR:5.1.1:550 User unknown >> >> That way sendmail will reject them for you and mailscanner will never >> see them. (don't forget to "makemap hash access < access") >> >> Ken >> Pacific.Net >> >> >> Cameron B. Prince wrote: >>> Hey guys, >>> >>> I have been getting a lot of emails coming in with CC's to every-name- >> known >>> to-man@mydomain.com. It bothered me that so many of my mail server's >>> resources and my internet connection were both being used to send >> bounces >>> and that this could also be an attempt to determine valid addresses. >>> >>> I did some research and came up with creating an alias like this: >>> >>> garbage: /dev/null >>> >>> Then in my virtusertable I have something like this: >>> >>> bob@host.com bob >>> tim@host.com tim >>> @host.com garbage >>> >>> It works, but now instead of bouncing, the messages are all scanned and >> then >>> sent to /dev/null. I need to configure MailScanner so that it doesn't >> scan >>> these messages destined for oblivion. >>> >>> Jan 27 17:41:00 p2 sendmail[14975]: k0RNeu33014975: >>> from=, size=1421, class=0, nrcpts=1, >>> msgid=, proto=SMTP, daemon=MTA, >>> relay=[221.0.209.135] >>> Jan 27 17:41:00 p2 MailScanner[14330]: New Batch: Scanning 1 messages, >> 1883 >>> bytes >>> Jan 27 17:41:01 p2 MailScanner[14330]: Virus and Content Scanning: >> Starting >>> Jan 27 17:41:01 p2 MailScanner[14330]: Uninfected: Delivered 1 messages >>> Jan 27 17:41:01 p2 MailScanner[14330]: Logging message k0RNeu33014975 to >> SQL >>> Jan 27 17:41:01 p2 MailScanner[14294]: k0RNeu33014975: Logged to >> MailWatch >>> SQL >>> Jan 27 17:41:01 p2 sendmail[14980]: k0RNeu33014975: to=/dev/null, >>> ctladdr= (8/0), delay=00:00:03, xdelay=00:00:00, >>> mailer=*file*, pri=121421, dsn=2.0.0, stat=Sent >>> >>> I setup a ruleset like this in the scan.messages.rules file: >>> >>> To: /dev/null no >>> FromOrTo: default yes >>> >>> I have this in the .conf file >>> >>> Scan Messages = %rules-dir%/scan.messages.rules >>> >>> MailScanner continues to scan the mail even though the to line states " >>> to=/dev/null" >>> >>> Can anyone tell me if this is possible and what I may be doing wrong? >>> >>> Thanks, >>> Cameron >>> >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > From cplists at princeservices.com Sat Jan 28 01:02:17 2006 From: cplists at princeservices.com (Cameron B. Prince) Date: Sat Jan 28 01:02:19 2006 Subject: Sending mail to /dev/null without scanning In-Reply-To: <43DABD41.3020106@pacific.net> Message-ID: <018601c623a6$7c3ec6b0$0201a8c0@PSLAPTOP1> This doesn't really solve it either. You are talking about a list of valid users. I don't want to DISCARD their mail. I also don't want to list each address I want to DISCARD mail for or maintain two lists of users, one in access and another in virtuser. I think you totally misunderstood my original request. I am trying to understand why the ruleset doesn't work. I suppose an alternative is to create a user with a .forward that sends mail to /dev/null with a ruleset to not scan his mail. Thanks, Cameron > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Ken A > Sent: Friday, January 27, 2006 6:39 PM > To: MailScanner discussion > Subject: Re: Sending mail to /dev/null without scanning > > Ah, well that's a spam magnet you are engineering! Anyhow, you can > change RELAY to DISCARD for the desired effect. > Ken > Pacific.Net > > > Cameron B. Prince wrote: > > Hi Ken, > > > > Thanks for your reply... This does not do what I need. > > > > I don't want to send a bounce. I want the sender to have no idea that > the > > address isn't good. > > > > Cameron > > > >> -----Original Message----- > >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > >> bounces@lists.mailscanner.info] On Behalf Of Ken A > >> Sent: Friday, January 27, 2006 6:08 PM > >> To: MailScanner discussion > >> Subject: Re: Sending mail to /dev/null without scanning > >> > >> Put entries in your access table instead. > >> > >> To:bob@mydomain.com RELAY > >> To:tim@mydomain.com RELAY > >> # > >> # Default Entry to Reject all others > >> # > >> To:mydomain.com ERROR:5.1.1:550 User unknown > >> > >> That way sendmail will reject them for you and mailscanner will never > >> see them. (don't forget to "makemap hash access < access") > >> > >> Ken > >> Pacific.Net > >> > >> > >> Cameron B. Prince wrote: > >>> Hey guys, > >>> > >>> I have been getting a lot of emails coming in with CC's to every-name- > >> known > >>> to-man@mydomain.com. It bothered me that so many of my mail server's > >>> resources and my internet connection were both being used to send > >> bounces > >>> and that this could also be an attempt to determine valid addresses. > >>> > >>> I did some research and came up with creating an alias like this: > >>> > >>> garbage: /dev/null > >>> > >>> Then in my virtusertable I have something like this: > >>> > >>> bob@host.com bob > >>> tim@host.com tim > >>> @host.com garbage > >>> > >>> It works, but now instead of bouncing, the messages are all scanned > and > >> then > >>> sent to /dev/null. I need to configure MailScanner so that it doesn't > >> scan > >>> these messages destined for oblivion. > >>> > >>> Jan 27 17:41:00 p2 sendmail[14975]: k0RNeu33014975: > >>> from=, size=1421, class=0, nrcpts=1, > >>> msgid=, proto=SMTP, > daemon=MTA, > >>> relay=[221.0.209.135] > >>> Jan 27 17:41:00 p2 MailScanner[14330]: New Batch: Scanning 1 messages, > >> 1883 > >>> bytes > >>> Jan 27 17:41:01 p2 MailScanner[14330]: Virus and Content Scanning: > >> Starting > >>> Jan 27 17:41:01 p2 MailScanner[14330]: Uninfected: Delivered 1 > messages > >>> Jan 27 17:41:01 p2 MailScanner[14330]: Logging message k0RNeu33014975 > to > >> SQL > >>> Jan 27 17:41:01 p2 MailScanner[14294]: k0RNeu33014975: Logged to > >> MailWatch > >>> SQL > >>> Jan 27 17:41:01 p2 sendmail[14980]: k0RNeu33014975: to=/dev/null, > >>> ctladdr= (8/0), delay=00:00:03, > xdelay=00:00:00, > >>> mailer=*file*, pri=121421, dsn=2.0.0, stat=Sent > >>> > >>> I setup a ruleset like this in the scan.messages.rules file: > >>> > >>> To: /dev/null no > >>> FromOrTo: default yes > >>> > >>> I have this in the .conf file > >>> > >>> Scan Messages = %rules-dir%/scan.messages.rules > >>> > >>> MailScanner continues to scan the mail even though the to line states > " > >>> to=/dev/null" > >>> > >>> Can anyone tell me if this is possible and what I may be doing wrong? > >>> > >>> Thanks, > >>> Cameron > >>> > >> -- > >> MailScanner mailing list > >> MailScanner@lists.mailscanner.info > >> http://lists.mailscanner.info/mailman/listinfo/mailscanner > >> > >> Before posting, read http://wiki.mailscanner.info/posting > >> > >> Support MailScanner development - buy the book off the website! > > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From dave.list at pixelhammer.com Sat Jan 28 03:11:34 2006 From: dave.list at pixelhammer.com (DAve) Date: Sat Jan 28 03:11:54 2006 Subject: blank "is" report lines in syslog? In-Reply-To: <43DAB1F9.6090003@evi-inc.com> References: <43DA63EC.7010400@pixelhammer.com> <43DA6686.9050508@evi-inc.com> <43DA79AA.9040208@pixelhammer.com> <43DA7D2B.8040907@evi-inc.com> <43DA857D.9080803@pixelhammer.com> <43DA890B.4080402@evi-inc.com> <43DA9866.9070009@pixelhammer.com> <43DAB1F9.6090003@evi-inc.com> Message-ID: <43DAE0E6.2050200@pixelhammer.com> Matt Kettler wrote: > DAve wrote: > >>A message comes in on MailScanner box #1, it is a 15mb attachment. It takes awhile to get through MailScanner and be delivered to the toaster, and for the toaster to update the users quota. But Milter-ahead checked before the message was accepted, and there is room to deliver the message. Unfortunately, MailScanner box #2 has a 3mb message that gets through a bit faster, lands on the toaster, and gets delivered. Now when MailScanner box #1 tries to deliver, the message won't fit within the quota. KAPOW!, the message is bounced. This has happened as well, to me. > > > Are you sure milter-ahead verifies the storage at all? I did not realize it had > this ability. However, I originally said that insufficient queue was a > reasonable case to cause post-delivery bounces. > Milter-ahead calls the toaster to check if the user exists, if the toaster sees the user is above 90% of the quota, it gives a negative response. From glenn.steen at gmail.com Sat Jan 28 09:21:09 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Sat Jan 28 09:21:13 2006 Subject: The article I wrote about mailscanner has been published In-Reply-To: References: <223f97700601251130l1912ca5cg@mail.gmail.com> <223f97700601271139t15766456q@mail.gmail.com> Message-ID: <223f97700601280121j4d92b23ex@mail.gmail.com> On 27/01/06, Ugo Bellavance wrote: > Glenn Steen wrote: > > On 27/01/06, Ugo Bellavance wrote: > >> Glenn Steen wrote: > >>> On 25/01/06, Ugo Bellavance wrote: > >>> (snip) > >>>> -> "Filtering spam server-side" is my article. > >>>> > >>>> Hope there are no major issues in it, I wrote it some time ago and I had > >>>> something like 2 hours to do the final revision. I especially remember > >>>> asking to add a comma between 'spam' and 'server' in the title, but, eh... > >>> Well, there's some unbalanced quotes and the odd "will look at these > >>> 3...." and then go on to mention four....:-) > >>> But on the whole, it really turned out nice. Good job, Ugo! > >>> ... And who would've known you're an avid telemark skier! :-) > >> If you guys feel like sending me a list of corrections, feel free to do > >> so, I'll ask the editor if they can re-create the PDF. > >> > >> TIA, > >> > >> -- > >> Ugo > >> > > ' > > Will take a .... more serious look..... But not tonight, after the > > beverages I've imbibed, you don't want my .... corrections. > > Perhaps tomorrow. > > > > There is no rush... I'm leaving tonight to spend the w/e in a ski > resort... Yes, telemark skiing, and maybe snowboard (in fact, the truth > is that I'm an alpine snowboarder first, then a freeride snowboarder, > then a telemark skier... Hmmmm..... You're slightly evil, you know?:-). Here I sit (with my leg in a cast) looking out the window at all that glorious snow.......:-) (Glenn turning a somewhat darker shade of green (from envy)) > So I won't have time to look at that before monday anyway. > > Thanks a lot, No problem, will probably do it tomorrow then (why do today what you can do tomorrow....:-). -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Sat Jan 28 09:56:41 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Sat Jan 28 09:56:44 2006 Subject: Sending mail to /dev/null without scanning In-Reply-To: <018601c623a6$7c3ec6b0$0201a8c0@PSLAPTOP1> References: <43DABD41.3020106@pacific.net> <018601c623a6$7c3ec6b0$0201a8c0@PSLAPTOP1> Message-ID: <223f97700601280156y13673926h@mail.gmail.com> On 28/01/06, Cameron B. Prince wrote: > This doesn't really solve it either. You are talking about a list of valid > users. I don't want to DISCARD their mail. I also don't want to list each > address I want to DISCARD mail for or maintain two lists of users, one in > access and another in virtuser. > > I think you totally misunderstood my original request. I think you misunderstand Kens intentions here.... And the viability of what you are trying to do "in MailScanner/MTA" so to speak. By accepting the messages, YOU are responsible for them. By _delivering_ them to a recipient (garbage) Mailscanner will have to handle them. Sure, you can have a ruleset on "Scan Messages" or whatever, but that'll use more resources than just rejecting or discarding at MTA level. Having to maintain the two lists would of course be simple with a little scripting;-). Note that Discarding a valid message actually breaks RFC-comliance, while rejecting at MTA (SMTP conversation stage) does not. And the spamers/smaptools don't actually look at the replies, so you're rather safe to just reject them... Not to mention that you'll be nice to the VALID message senders who happen to mistype an address (with your idea or the DISCARD, they will never know). And you are NOT generating a "bounce" when you reject a message at SMTP conversation stage. Any NDN is generated by the SENDING MTA, not you... since you haven't accepted the message, it isn't your headache to handle! (snip) -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From MailScanner at ecs.soton.ac.uk Sat Jan 28 13:58:45 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat Jan 28 13:58:51 2006 Subject: MS not allowing ANY attachments In-Reply-To: <200601272353.k0RNrZlD021770@bkserver.blacknight.ie> References: <200601272353.k0RNrZlD021770@bkserver.blacknight.ie> Message-ID: <43DB7895.5090907@ecs.soton.ac.uk> Stephen Swaney wrote: >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Jose Guevarra >> Sent: Friday, January 27, 2006 6:28 PM >> To: mailscanner@lists.mailscanner.info >> Subject: MS not allowing ANY attachments >> >> Hi, >> >> I'm using MS 4.4.3 >> >> MS seems to be catching ALL attachments. Every time I try to start MS I >> get errors like these >> >> Jan 27 15:25:48 saibot MailScanner[7485]: Syntax error in first field in >> line 17 of ruleset /etc/MailScanner/filetype.rules >> Jan 27 15:25:48 saibot MailScanner[7485]: Syntax error in first field in >> line 18 of ruleset /etc/MailScanner/filetype.rules >> Jan 27 15:25:48 saibot MailScanner[7485]: Syntax error in first field in >> line 19 of ruleset /etc/MailScanner/filetype.rules >> Jan 27 15:25:48 saibot MailScanner[7485]: Syntax error in first field in >> line 20 of ruleset /etc/MailScanner/filetype.rules >> Jan 27 15:25:48 saibot MailScanner[7485]: Syntax error in first field in >> line 21 of ruleset /etc/MailScanner/filetype.rules >> >> However, I haven't edited the rules and I even replaced them with rules >> from the original source code. >> >> Any ideas? >> >> > > Check that the files in the file are separated by TABs not spaces > > I quote from the filename.rules.conf file: > > # > # NOTE: Fields are separated by TAB characters --- Important! > # > # Syntax is allow/deny/deny+delete, then regular expression, then log text, > # then user report text. > Also, make sure it is called filename.rules.conf and not filename.rules. This is one of the rare places where the filename is relatively important. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Sat Jan 28 14:08:11 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat Jan 28 14:08:17 2006 Subject: Sending mail to /dev/null without scanning In-Reply-To: <017a01c6239d$3398d710$0201a8c0@PSLAPTOP1> References: <017a01c6239d$3398d710$0201a8c0@PSLAPTOP1> Message-ID: <43DB7ACB.7090600@ecs.soton.ac.uk> Cameron B. Prince wrote: > Hey guys, > > I have been getting a lot of emails coming in with CC's to every-name-known > to-man@mydomain.com. It bothered me that so many of my mail server's > resources and my internet connection were both being used to send bounces > and that this could also be an attempt to determine valid addresses. > > I did some research and came up with creating an alias like this: > > garbage: /dev/null > > Then in my virtusertable I have something like this: > > bob@host.com bob > tim@host.com tim > @host.com garbage > > It works, but now instead of bouncing, the messages are all scanned and then > sent to /dev/null. I need to configure MailScanner so that it doesn't scan > these messages destined for oblivion. > You cannot use a destination location (such as /dev/null) in a ruleset, as MailScanner is not involved with the final mail delivery, and so doesn't know anything about any aliases files. The only way to do it would be to have a ruleset which knows all about the exact addresses you want to keep, and trash the rest. Whether you do this in your MTA or in MailScanner, you still need a list of the legal addresses. In MailScanner you could switch off scanning for unknown addresses, by using Scan Messages = %rules-dir%/scan.messages.rules And then in scan.messages.rule put To: bob@host.com yes To: tim@host.com yes To: *@host.com no FromOrTo: default yes You could easily automatically generate this file from your virtusertable with a short script. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From patrick at pdebrabander.nl Sat Jan 28 23:00:53 2006 From: patrick at pdebrabander.nl (Patrick de Brabander) Date: Sat Jan 28 23:01:23 2006 Subject: Mailscanner 4.50.12-2 upgrade stops working Message-ID: I?ve installed the new beta 4.50.12-2 over my working MailScanner-4.50.10-1. New mail in arriving in the mail box and in my log file is see the following Jan 28 22:57:51 server MailScanner: MailScanner -15 succeeded Jan 28 22:57:51 server MailScanner: succeeded Jan 28 22:57:52 server MailScanner: succeeded Jan 28 22:58:00 server postfix: succeeded Jan 28 23:14:06 server postfix: succeeded Jan 28 23:14:14 server last message repeated 2 times Jan 28 23:14:23 server MailScanner: MailScanner -15 succeeded Jan 28 23:14:23 server MailScanner: succeeded Jan 28 23:14:34 server last message repeated 3 times Jan 28 23:14:39 server root: MailScanner setting GID to postfix (89) Jan 28 23:14:39 server root: MailScanner setting UID to postfix (89) Jan 28 23:14:40 server MailScanner: succeeded Jan 28 23:15:35 server postfix: Process did not exit cleanly, returned 255 with signal 0 Jan 28 23:16:08 server last message repeated 3 times Jan 28 23:17:14 server last message repeated 6 times Jan 28 23:18:20 server last message repeated 6 times Jan 28 23:19:26 server last message repeated 6 times Jan 28 23:20:32 server last message repeated 6 times Jan 28 23:21:39 server last message repeated 6 times Jan 28 23:22:45 server last message repeated 6 times Jan 28 23:23:51 server last message repeated 6 times Jan 28 23:24:57 server last message repeated 6 times Jan 28 23:26:03 server last message repeated 6 times Jan 28 23:27:10 server last message repeated 6 times Jan 28 23:27:21 server postfix: Process did not exit cleanly, returned 255 with signal 0 Jan 28 23:27:22 server postfix: succeeded Can somebody help me. Is it possible to go back to an older version. Thanks Patrick From craigwhite at azapple.com Sat Jan 28 23:24:34 2006 From: craigwhite at azapple.com (Craig White) Date: Sat Jan 28 23:24:43 2006 Subject: Mailscanner 4.50.12-2 upgrade stops working In-Reply-To: References: Message-ID: <1138490674.26160.47.camel@lin-workstation.azapple.com> On Sun, 2006-01-29 at 00:00 +0100, Patrick de Brabander wrote: > I?ve installed the new beta 4.50.12-2 over my working MailScanner-4.50.10-1. > New mail in arriving in the mail box and in my log file is see the following > > Jan 28 22:57:51 server MailScanner: MailScanner -15 succeeded > Jan 28 22:57:51 server MailScanner: succeeded > Jan 28 22:57:52 server MailScanner: succeeded > Jan 28 22:58:00 server postfix: succeeded > Jan 28 23:14:06 server postfix: succeeded > Jan 28 23:14:14 server last message repeated 2 times > Jan 28 23:14:23 server MailScanner: MailScanner -15 succeeded > Jan 28 23:14:23 server MailScanner: succeeded > Jan 28 23:14:34 server last message repeated 3 times > Jan 28 23:14:39 server root: MailScanner setting GID to postfix (89) > Jan 28 23:14:39 server root: MailScanner setting UID to postfix (89) > Jan 28 23:14:40 server MailScanner: succeeded > Jan 28 23:15:35 server postfix: Process did not exit cleanly, returned 255 > with signal 0 > Jan 28 23:16:08 server last message repeated 3 times > Jan 28 23:17:14 server last message repeated 6 times > Jan 28 23:18:20 server last message repeated 6 times > Jan 28 23:19:26 server last message repeated 6 times > Jan 28 23:20:32 server last message repeated 6 times > Jan 28 23:21:39 server last message repeated 6 times > Jan 28 23:22:45 server last message repeated 6 times > Jan 28 23:23:51 server last message repeated 6 times > Jan 28 23:24:57 server last message repeated 6 times > Jan 28 23:26:03 server last message repeated 6 times > Jan 28 23:27:10 server last message repeated 6 times > Jan 28 23:27:21 server postfix: Process did not exit cleanly, returned 255 > with signal 0 > Jan 28 23:27:22 server postfix: succeeded > > > Can somebody help me. > > Is it possible to go back to an older version. ---- I believe that this has come up before. This isn't an issue with versions, this is an issue with postfix being unable to find it's 'K' scripts in SysV. If this is a redhat type system... chkconfig --add postfix chkconfig postfix off should fix this. Craig From patrick at pdebrabander.nl Sat Jan 28 23:42:16 2006 From: patrick at pdebrabander.nl (Patrick de Brabander) Date: Sat Jan 28 23:42:54 2006 Subject: Mailscanner 4.50.12-2 upgrade stops working In-Reply-To: <1138490674.26160.47.camel@lin-workstation.azapple.com> Message-ID: This did the trick. All the mail was held in /var/spool/postfix/hold Thanks Patrick > -----Oorspronkelijk bericht----- > Van: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Namens Craig White > Verzonden: zondag 29 januari 2006 00.25 > Aan: mailscanner@lists.mailscanner.info > Onderwerp: Re: Mailscanner 4.50.12-2 upgrade stops working > > On Sun, 2006-01-29 at 00:00 +0100, Patrick de Brabander wrote: > > I?ve installed the new beta 4.50.12-2 over my working > MailScanner-4.50.10-1. > > New mail in arriving in the mail box and in my log file is see the > > following > > > > Jan 28 22:57:51 server MailScanner: MailScanner -15 > succeeded Jan 28 > > 22:57:51 server MailScanner: succeeded Jan 28 22:57:52 server > > MailScanner: succeeded Jan 28 22:58:00 server postfix: > succeeded Jan > > 28 23:14:06 server postfix: succeeded Jan 28 23:14:14 server last > > message repeated 2 times Jan 28 23:14:23 server MailScanner: > > MailScanner -15 succeeded Jan 28 23:14:23 server MailScanner: > > succeeded Jan 28 23:14:34 server last message repeated 3 > times Jan 28 > > 23:14:39 server root: MailScanner setting GID to postfix > (89) Jan 28 > > 23:14:39 server root: MailScanner setting UID to postfix > (89) Jan 28 > > 23:14:40 server MailScanner: succeeded Jan 28 23:15:35 > server postfix: > > Process did not exit cleanly, returned 255 with signal 0 Jan 28 > > 23:16:08 server last message repeated 3 times Jan 28 > 23:17:14 server > > last message repeated 6 times Jan 28 23:18:20 server last message > > repeated 6 times Jan 28 23:19:26 server last message > repeated 6 times > > Jan 28 23:20:32 server last message repeated 6 times Jan 28 > 23:21:39 > > server last message repeated 6 times Jan 28 23:22:45 server last > > message repeated 6 times Jan 28 23:23:51 server last > message repeated > > 6 times Jan 28 23:24:57 server last message repeated 6 times Jan 28 > > 23:26:03 server last message repeated 6 times Jan 28 > 23:27:10 server > > last message repeated 6 times Jan 28 23:27:21 server > postfix: Process > > did not exit cleanly, returned 255 with signal 0 Jan 28 23:27:22 > > server postfix: succeeded > > > > > > Can somebody help me. > > > > Is it possible to go back to an older version. > ---- > I believe that this has come up before. This isn't an issue > with versions, this is an issue with postfix being unable to > find it's 'K' > scripts in SysV. If this is a redhat type system... > > chkconfig --add postfix > chkconfig postfix off > > should fix this. > > Craig > > -- > MailScanner mailing list > MailScanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ---------------------------------------------------------------------- This message is scanned for virusses and other harmfull contents by MailScanner and appear to be clean. This e-mail is intended for the addressee shown. It contains information that is confidential and protected from disclosure. Any review, dissemination or use of this transmission or its contents by persons or unauthorized employees of the intended organisations is strictly prohibited. Postmaster @ www.pdebrabander.nl ---------------------------------------------------------------------- From MailScanner at ecs.soton.ac.uk Sun Jan 29 12:47:25 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun Jan 29 12:47:41 2006 Subject: Mailscanner 4.50.12-2 upgrade stops working In-Reply-To: References: Message-ID: <43DCB95D.8070206@ecs.soton.ac.uk> Can someone add this one to the wiki please? Patrick de Brabander wrote: > This did the trick. > > All the mail was held in /var/spool/postfix/hold > > > Thanks > > Patrick > > >> -----Oorspronkelijk bericht----- >> Van: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] Namens Craig White >> Verzonden: zondag 29 januari 2006 00.25 >> Aan: mailscanner@lists.mailscanner.info >> Onderwerp: Re: Mailscanner 4.50.12-2 upgrade stops working >> >> On Sun, 2006-01-29 at 00:00 +0100, Patrick de Brabander wrote: >> >>> I?ve installed the new beta 4.50.12-2 over my working >>> >> MailScanner-4.50.10-1. >> >>> New mail in arriving in the mail box and in my log file is see the >>> following >>> >>> Jan 28 22:57:51 server MailScanner: MailScanner -15 >>> >> succeeded Jan 28 >> >>> 22:57:51 server MailScanner: succeeded Jan 28 22:57:52 server >>> MailScanner: succeeded Jan 28 22:58:00 server postfix: >>> >> succeeded Jan >> >>> 28 23:14:06 server postfix: succeeded Jan 28 23:14:14 server last >>> message repeated 2 times Jan 28 23:14:23 server MailScanner: >>> MailScanner -15 succeeded Jan 28 23:14:23 server MailScanner: >>> succeeded Jan 28 23:14:34 server last message repeated 3 >>> >> times Jan 28 >> >>> 23:14:39 server root: MailScanner setting GID to postfix >>> >> (89) Jan 28 >> >>> 23:14:39 server root: MailScanner setting UID to postfix >>> >> (89) Jan 28 >> >>> 23:14:40 server MailScanner: succeeded Jan 28 23:15:35 >>> >> server postfix: >> >>> Process did not exit cleanly, returned 255 with signal 0 Jan 28 >>> 23:16:08 server last message repeated 3 times Jan 28 >>> >> 23:17:14 server >> >>> last message repeated 6 times Jan 28 23:18:20 server last message >>> repeated 6 times Jan 28 23:19:26 server last message >>> >> repeated 6 times >> >>> Jan 28 23:20:32 server last message repeated 6 times Jan 28 >>> >> 23:21:39 >> >>> server last message repeated 6 times Jan 28 23:22:45 server last >>> message repeated 6 times Jan 28 23:23:51 server last >>> >> message repeated >> >>> 6 times Jan 28 23:24:57 server last message repeated 6 times Jan 28 >>> 23:26:03 server last message repeated 6 times Jan 28 >>> >> 23:27:10 server >> >>> last message repeated 6 times Jan 28 23:27:21 server >>> >> postfix: Process >> >>> did not exit cleanly, returned 255 with signal 0 Jan 28 23:27:22 >>> server postfix: succeeded >>> >>> >>> Can somebody help me. >>> >>> Is it possible to go back to an older version. >>> >> ---- >> I believe that this has come up before. This isn't an issue >> with versions, this is an issue with postfix being unable to >> find it's 'K' >> scripts in SysV. If this is a redhat type system... >> >> chkconfig --add postfix >> chkconfig postfix off >> >> should fix this. >> >> Craig >> >> -- >> MailScanner mailing list >> MailScanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> > > > ---------------------------------------------------------------------- > This message is scanned for virusses and other harmfull contents by MailScanner > and appear to be clean. This e-mail is intended for the addressee shown. > It contains information that is confidential and protected from disclosure. > Any review, dissemination or use of this transmission or its contents by persons > or unauthorized employees of the intended organisations is strictly prohibited. > Postmaster @ www.pdebrabander.nl > ---------------------------------------------------------------------- > > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 From gdoris at rogers.com Sun Jan 29 16:37:02 2006 From: gdoris at rogers.com (Gerry Doris) Date: Sun Jan 29 16:37:32 2006 Subject: Remove times from logwatch reports Message-ID: <43DCEF2E.2020501@rogers.com> Ever since we added the batch processing times I've been getting reams of lines in my logcheck reports giving the batch times for each message being processed. I haven't been able to find where I can turn these off. Is this configurable? From MailScanner at ecs.soton.ac.uk Sun Jan 29 16:59:02 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun Jan 29 16:59:16 2006 Subject: Remove times from logwatch reports In-Reply-To: <43DCEF2E.2020501@rogers.com> References: <43DCEF2E.2020501@rogers.com> Message-ID: <43DCF456.8040302@ecs.soton.ac.uk> Gerry Doris wrote: > Ever since we added the batch processing times I've been getting reams > of lines in my logcheck reports giving the batch times for each message > being processed. > > I haven't been able to find where I can turn these off. Is this > configurable? I would much prefer it if the logcheck settings were adjusted to handle this output. I currently have 272 configuration options, I don't want to make it 273 just for this. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 From xterm1 at Tatorz.com Sun Jan 29 17:17:17 2006 From: xterm1 at Tatorz.com (Xterm1) Date: Sun Jan 29 17:16:20 2006 Subject: [V-SPAM:3] RE: Remove times from logwatch reports In-Reply-To: <43DCEF2E.2020501@rogers.com> Message-ID: -----Original Message----- Subject: Remove times from logwatch reports Ever since we added the batch processing times I've been getting reams of lines in my logcheck reports giving the batch times for each message being processed. I haven't been able to find where I can turn these off. Is this configurable? -- /etc/log.d/scripts/services Edit mailscanner rem out Lines 399-404 just a quick fix.. Brian From john at tradoc.fr Mon Jan 30 08:20:20 2006 From: john at tradoc.fr (John Wilcock) Date: Mon Jan 30 08:20:28 2006 Subject: Remove times from logwatch reports In-Reply-To: <43DCEF2E.2020501@rogers.com> References: <43DCEF2E.2020501@rogers.com> Message-ID: <43DDCC44.4010304@tradoc.fr> Gerry Doris wrote: > Ever since we added the batch processing times I've been getting reams > of lines in my logcheck reports giving the batch times for each message > being processed. > > I haven't been able to find where I can turn these off. Is this > configurable? Have a look in /usr/share/logwatch/scripts/services/mailscanner (or /etc/log.d/conf/services/mailscanner if you're using an older version of logwatch). There's a longish list near the top of the file of regexes for lines to be totally ignored - just add to it as needed. John. -- -- Over 3000 webcams from ski resorts around the world - www.snoweye.com -- Translate your technical documents and web pages - www.tradoc.fr From ron at neversleep.net Mon Jan 30 06:52:48 2006 From: ron at neversleep.net (Ron) Date: Mon Jan 30 08:54:41 2006 Subject: Patch: Always Virus Scan (Even if Undeliv or Delete due to SPAM/MCP) Message-ID: <43DDB7C0.7090400@neversleep.net> Here is a patch for MailScanner 4.49.7 which adds a configuration option to Virus Scan messages, even if they have been tagged as "Deleted" or "DontDeliver". (attached: AlwaysVirusScan.patch.tar.gz; patch with -p1) This allows me to keep accurate Virus counts and statistics. This basically mimics the "Old" way MailScanner behaved for Virus Scanning. This is my first time tweaking on the MS source; so I hope this is the sensible approach. I considered implementing as a ruleset per each domain/message; but this Statistical option only seemed to make sense globally. If anybody is interested in this give feedback. -Ron Allred (new list member also..) -------------- next part -------------- A non-text attachment was scrubbed... Name: AlwaysVirusScan.patch.tar.gz Type: application/gzip Size: 2562 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060129/23e084e5/AlwaysVirusScan.patch.tar.bin From mgt at stellarcore.net Mon Jan 30 14:50:34 2006 From: mgt at stellarcore.net (Mike Tremaine) Date: Mon Jan 30 14:50:42 2006 Subject: Remove time from logwatch reports In-Reply-To: <200601301200.k0UC0JgL009618@bkserver.blacknight.ie> References: <200601301200.k0UC0JgL009618@bkserver.blacknight.ie> Message-ID: <1138632634.3244.3.camel@dwarfstar.stellarcore.net> On Mon, 2006-01-30 at 12:00 +0000, mailscanner- request@lists.mailscanner.info wrote: > Message: 2 > Date: Sun, 29 Jan 2006 11:37:02 -0500 > From: Gerry Doris > Subject: Remove times from logwatch reports > To: mailscanner@lists.mailscanner.info > Message-ID: <43DCEF2E.2020501@rogers.com> > Content-Type: text/plain; charset=ISO-8859-1; format=flowed > > Ever since we added the batch processing times I've been getting reams > of lines in my logcheck reports giving the batch times for each > message > being processed. > > I haven't been able to find where I can turn these off. Is this > configurable? > > Depending on the version of logwatch you have running you might be able to use the ignore.conf file to filter out the noise. Look at see if you have /etc/logwatch/conf/ignore.conf [or maybe /etc/log.d/ for versions before 7.0 ] Then just drop the first part of the line you want ignored into this file and you are done. In the long run as soon as I upgrade to 4.50 I'll patch the mailscanner script to do the right thing. -Mike From zichovsky at trul.cz Mon Jan 30 15:34:10 2006 From: zichovsky at trul.cz (Pavel Zichovsky) Date: Mon Jan 30 15:34:39 2006 Subject: Problem with AVG scanner - MailScanner does not recognize virus Message-ID: <002d01c625b2$a0f428c0$1701a8c0@NBZICHOVSKY2> Hi there! I am using Mailscanner (currently updated to beta 4.50.12) with two virus scanners - AVG and Bitdefender. It seems to me, that from certain update of AVG system MailScanner stoped recognizing viruses identified by AVG. I tested it by sending eicar to me. Message was processed by MS and in /tmp dir I have found log from AVG scanning: avg log file (/tmp/log.avg.29936): ---------------------------------------------------------------------------- - AVG 7.1 Anti-Virus Copyright (c) GRISOFT,s.r.o. 2005 Program version 7.1.23 Engine: 718 database version 267.14.23/243 Command line: [-report /tmp/log.avg.29936 -arc -ext=* .] "./k0UF45M29934/eicar.com" Virus identified EICAR_Test ------------------------------------------------------------ Test start Mon Jan 30 16:04:15 2006 Elapsed time 0 sec. ------------------------------------------------------------ Scanned files : 3 Scanned sectors : 0 Infected files : 1 Infected sectors : 0 ------------------------------------------------------------ Acording to this log, AVG detected eicar, but MS did not recognize that AVG found virus. Here are maillog entries for that batch: ----------------------------------------------------------------------- Jan 30 16:04:13 server MailScanner[29912]: New Batch: Scanning 1 messages, 3946 bytes Jan 30 16:04:13 server MailScanner[29912]: MCP Checks completed at 12453516 bytes per second Jan 30 16:04:13 server MailScanner[29912]: Spam Checks: Starting Jan 30 16:04:13 server MailScanner[29912]: SpamAssassin cache hit for message k0UF45M29934 Jan 30 16:04:14 server MailScanner[29912]: Spam Checks completed at 17675 bytes per second Jan 30 16:04:14 server MailScanner[29912]: Virus and Content Scanning: Starting Jan 30 16:04:18 server MailScanner[29912]: k0UF45M29934/eicar.com:infected: EICAR-Test-File (not a virus) Jan 30 16:04:18 server MailScanner[29912]: Virus Scanning: Bitdefender found 1 infections Jan 30 16:04:18 server MailScanner[29912]: Infected message k0UF45M29934 came from 69.20.55.130 Jan 30 16:04:18 server MailScanner[29912]: Virus Scanning: Found 1 viruses Jan 30 16:04:18 server MailScanner[29912]: Virus Scanning completed at 891 bytes per second Jan 30 16:04:18 server MailScanner[29912]: Saved entire message to /home/data/mailscanner/quarantine/20060130/k0UF45M29934 Jan 30 16:04:18 server MailScanner[29912]: Saved infected "eicar.com" to /home/data/mailscanner/quarantine/20060130/k0UF45M29934 Jan 30 16:04:18 server MailScanner[29912]: Viruses marked as silent: Bitdefender: Found virus EICAR-Test-File (not a virus) in file eicar.com Jan 30 16:04:18 server sendmail[29943]: k0UF4Ie29943: from=postmaster@trul.cz, size=1447, class=0, nrcpts=1, msgid=<200601301504.k0UF4Ie29943@server.trul>, relay=root@localhost Jan 30 16:04:18 server MailScanner[29912]: Notices: Warned about 1 messages Jan 30 16:04:18 server MailScanner[29912]: Virus Processing completed at 22175 bytes per second Jan 30 16:04:18 server MailScanner[29912]: Disinfection completed at 23212796 bytes per second Jan 30 16:04:18 server MailScanner[29912]: Batch completed at 794 bytes per second (3946 / 4) Jan 30 16:04:18 server MailScanner[29912]: Batch processed in 4.97 seconds Jan 30 16:04:18 server MailScanner[29912]: "Always Looked Up Last" took 0.00 seconds ---------------------------------------------------------------------------- --------- So if I am right, then MS reconizes that only Bitdefender found virus, however AVG found that too (according to log). I have run AVG via wrapper on whole quarantine dir and got this: ---------------------------------------------------------------------- [root@server quarantine]# /usr/lib/MailScanner/avg-wrapper /usr/local . AVG7 Anti-Virus command line scanner Copyright (c) 2005 GRISOFT, s.r.o. Program version 7.1.23, engine 718 Virus Database: Version 267.14.23/243 2006-01-27 License type is FULL for SERVER. Expiration day: 25. 10. 2007 ./20060124/spam/k0O2Fbq19306 Virus found Worm/Feebs ./20060124/spam/k0OD9Cq01779 Virus found Worm/Feebs ./20060124/spam/k0ODACq01874 Virus found Worm/Feebs ./20060125/k0PAM9829845/eicar.com Virus identified EICAR_Test ./20060125/k0PAM9829845/message Virus identified EICAR_Test (+1) ./20060125/k0PAeen30411/eicar.com Virus identified EICAR_Test ./20060125/k0PAeen30411/message Virus identified EICAR_Test (+1) ./20060125/nonspam/k0PAM9829845 Virus identified EICAR_Test (+1) ./20060125/nonspam/k0PAeen30411 Virus identified EICAR_Test (+1) ./20060125/nonspam/k0PIOtn08366 Virus found Worm/Feebs ./20060125/spam/k0PA5cq29321 Virus found Worm/Feebs ./20060130/k0UEuSM29727/eicar.com Virus identified EICAR_Test ./20060130/k0UEuSM29727/message Virus identified EICAR_Test (+1) ./20060130/k0UF45M29934/eicar.com Virus identified EICAR_Test ./20060130/k0UF45M29934/message Virus identified EICAR_Test (+1) ./20060130/nonspam/k0UEuSM29727 Virus identified EICAR_Test (+1) ./20060130/nonspam/k0UF45M29934 Virus identified EICAR_Test (+1) Tested: 2660 files, 0 sectors Infections: 17 Errors: 0 ------------------------------------------------------------------------ So I think that there is problem in parsing AVG output in MS. And 1 more problem with avg-wrapper - it does not delete report files in /tmp dir. Files are staying there until manualy deleted. With regards Pavel Zichovsky (zichovsky@trul) From vlad at univap.br Mon Jan 30 18:41:42 2006 From: vlad at univap.br (Vladimir M Costa) Date: Mon Jan 30 18:42:02 2006 Subject: Problem with AVG scanner - MailScanner does not recognize virus In-Reply-To: <002d01c625b2$a0f428c0$1701a8c0@NBZICHOVSKY2> References: <002d01c625b2$a0f428c0$1701a8c0@NBZICHOVSKY2> Message-ID: <43DE5DE6.1020802@univap.br> Pavel, For AVG for linux versions 7.0.12 and higher, new instalation is into /opt/grisoft/avg7 subtree. Change the installation directory in the configuration file /etc/Mailscanner/virus.scanners.conf to /opt/grisoft/avg7 regards, Vladimir M Costa > Hi there! > > I am using Mailscanner (currently updated to beta 4.50.12) with two virus > scanners - AVG and Bitdefender. > It seems to me, that from certain update of AVG system MailScanner stoped > recognizing viruses identified by AVG. > > I tested it by sending eicar to me. > > Message was processed by MS and in /tmp dir I have found log from AVG > scanning: > > avg log file (/tmp/log.avg.29936): > ---------------------------------------------------------------------------- > - > AVG 7.1 Anti-Virus > Copyright (c) GRISOFT,s.r.o. 2005 > Program version 7.1.23 Engine: 718 database version 267.14.23/243 > Command line: [-report /tmp/log.avg.29936 -arc -ext=* .] > "./k0UF45M29934/eicar.com" Virus identified EICAR_Test > > > ------------------------------------------------------------ > Test start Mon Jan 30 16:04:15 2006 > > Elapsed time 0 sec. > ------------------------------------------------------------ > Scanned files : 3 > Scanned sectors : 0 > Infected files : 1 > Infected sectors : 0 > ------------------------------------------------------------ > > Acording to this log, AVG detected eicar, but MS did not recognize that AVG > found virus. > Here are maillog entries for that batch: > ----------------------------------------------------------------------- > Jan 30 16:04:13 server MailScanner[29912]: New Batch: Scanning 1 messages, > 3946 bytes > Jan 30 16:04:13 server MailScanner[29912]: MCP Checks completed at 12453516 > bytes per second > Jan 30 16:04:13 server MailScanner[29912]: Spam Checks: Starting > Jan 30 16:04:13 server MailScanner[29912]: SpamAssassin cache hit for > message k0UF45M29934 > Jan 30 16:04:14 server MailScanner[29912]: Spam Checks completed at 17675 > bytes per second > Jan 30 16:04:14 server MailScanner[29912]: Virus and Content Scanning: > Starting > Jan 30 16:04:18 server MailScanner[29912]: k0UF45M29934/eicar.com:infected: > EICAR-Test-File (not a virus) > Jan 30 16:04:18 server MailScanner[29912]: Virus Scanning: Bitdefender found > 1 infections > Jan 30 16:04:18 server MailScanner[29912]: Infected message k0UF45M29934 > came from 69.20.55.130 > Jan 30 16:04:18 server MailScanner[29912]: Virus Scanning: Found 1 viruses > Jan 30 16:04:18 server MailScanner[29912]: Virus Scanning completed at 891 > bytes per second > Jan 30 16:04:18 server MailScanner[29912]: Saved entire message to > /home/data/mailscanner/quarantine/20060130/k0UF45M29934 > Jan 30 16:04:18 server MailScanner[29912]: Saved infected "eicar.com" to > /home/data/mailscanner/quarantine/20060130/k0UF45M29934 > Jan 30 16:04:18 server MailScanner[29912]: Viruses marked as silent: > Bitdefender: Found virus EICAR-Test-File (not a virus) in file eicar.com > Jan 30 16:04:18 server sendmail[29943]: k0UF4Ie29943: > from=postmaster@trul.cz, size=1447, class=0, nrcpts=1, > msgid=<200601301504.k0UF4Ie29943@server.trul>, relay=root@localhost > Jan 30 16:04:18 server MailScanner[29912]: Notices: Warned about 1 messages > Jan 30 16:04:18 server MailScanner[29912]: Virus Processing completed at > 22175 bytes per second > Jan 30 16:04:18 server MailScanner[29912]: Disinfection completed at > 23212796 bytes per second > Jan 30 16:04:18 server MailScanner[29912]: Batch completed at 794 bytes per > second (3946 / 4) > Jan 30 16:04:18 server MailScanner[29912]: Batch processed in 4.97 seconds > Jan 30 16:04:18 server MailScanner[29912]: "Always Looked Up Last" took 0.00 > seconds > ---------------------------------------------------------------------------- > --------- > > So if I am right, then MS reconizes that only Bitdefender found virus, > however AVG found that too (according to log). > > I have run AVG via wrapper on whole quarantine dir and got this: > ---------------------------------------------------------------------- > [root@server quarantine]# /usr/lib/MailScanner/avg-wrapper /usr/local . > AVG7 Anti-Virus command line scanner > Copyright (c) 2005 GRISOFT, s.r.o. > Program version 7.1.23, engine 718 > Virus Database: Version 267.14.23/243 2006-01-27 > License type is FULL for SERVER. > Expiration day: 25. 10. 2007 > ./20060124/spam/k0O2Fbq19306 Virus found Worm/Feebs > ./20060124/spam/k0OD9Cq01779 Virus found Worm/Feebs > ./20060124/spam/k0ODACq01874 Virus found Worm/Feebs > ./20060125/k0PAM9829845/eicar.com Virus identified EICAR_Test > ./20060125/k0PAM9829845/message Virus identified EICAR_Test (+1) > ./20060125/k0PAeen30411/eicar.com Virus identified EICAR_Test > ./20060125/k0PAeen30411/message Virus identified EICAR_Test (+1) > ./20060125/nonspam/k0PAM9829845 Virus identified EICAR_Test (+1) > ./20060125/nonspam/k0PAeen30411 Virus identified EICAR_Test (+1) > ./20060125/nonspam/k0PIOtn08366 Virus found Worm/Feebs > ./20060125/spam/k0PA5cq29321 Virus found Worm/Feebs > ./20060130/k0UEuSM29727/eicar.com Virus identified EICAR_Test > ./20060130/k0UEuSM29727/message Virus identified EICAR_Test (+1) > ./20060130/k0UF45M29934/eicar.com Virus identified EICAR_Test > ./20060130/k0UF45M29934/message Virus identified EICAR_Test (+1) > ./20060130/nonspam/k0UEuSM29727 Virus identified EICAR_Test (+1) > ./20060130/nonspam/k0UF45M29934 Virus identified EICAR_Test (+1) > Tested: 2660 files, 0 sectors > Infections: 17 > Errors: 0 > ------------------------------------------------------------------------ > > So I think that there is problem in parsing AVG output in MS. > > And 1 more problem with avg-wrapper - it does not delete report files in > /tmp dir. Files are staying there until manualy deleted. > > With regards > Pavel Zichovsky (zichovsky@trul) > > From MailScanner at ecs.soton.ac.uk Mon Jan 30 19:00:23 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 30 19:00:26 2006 Subject: Problem with AVG scanner - MailScanner does not recognize virus In-Reply-To: <43DE5DE6.1020802@univap.br> References: <002d01c625b2$a0f428c0$1701a8c0@NBZICHOVSKY2> <43DE5DE6.1020802@univap.br> Message-ID: <43DE6247.5040209@ecs.soton.ac.uk> There is a slight adaptation that needs to be written for the output parser as well. return 0 unless $line =~ /Virus identified +(.+)$/; instead of the line very like it at the top of ProcessAvgOutput in SweepViruses.pm. This will be in the next release. Vladimir M Costa wrote: > Pavel, > > > For AVG for linux versions 7.0.12 and higher, new instalation > is into /opt/grisoft/avg7 subtree. > > Change the installation directory in the configuration file > /etc/Mailscanner/virus.scanners.conf to /opt/grisoft/avg7 > > > regards, > > Vladimir M Costa > > >> Hi there! >> >> I am using Mailscanner (currently updated to beta 4.50.12) with two virus >> scanners - AVG and Bitdefender. >> It seems to me, that from certain update of AVG system MailScanner stoped >> recognizing viruses identified by AVG. >> >> I tested it by sending eicar to me. >> >> Message was processed by MS and in /tmp dir I have found log from AVG >> scanning: >> >> avg log file (/tmp/log.avg.29936): >> ---------------------------------------------------------------------------- >> - >> AVG 7.1 Anti-Virus >> Copyright (c) GRISOFT,s.r.o. 2005 >> Program version 7.1.23 Engine: 718 database version 267.14.23/243 >> Command line: [-report /tmp/log.avg.29936 -arc -ext=* .] >> "./k0UF45M29934/eicar.com" Virus identified EICAR_Test >> >> >> ------------------------------------------------------------ >> Test start Mon Jan 30 16:04:15 2006 >> >> Elapsed time 0 sec. >> ------------------------------------------------------------ >> Scanned files : 3 >> Scanned sectors : 0 >> Infected files : 1 >> Infected sectors : 0 >> ------------------------------------------------------------ >> >> Acording to this log, AVG detected eicar, but MS did not recognize that AVG >> found virus. >> Here are maillog entries for that batch: >> ----------------------------------------------------------------------- >> Jan 30 16:04:13 server MailScanner[29912]: New Batch: Scanning 1 messages, >> 3946 bytes >> Jan 30 16:04:13 server MailScanner[29912]: MCP Checks completed at 12453516 >> bytes per second >> Jan 30 16:04:13 server MailScanner[29912]: Spam Checks: Starting >> Jan 30 16:04:13 server MailScanner[29912]: SpamAssassin cache hit for >> message k0UF45M29934 >> Jan 30 16:04:14 server MailScanner[29912]: Spam Checks completed at 17675 >> bytes per second >> Jan 30 16:04:14 server MailScanner[29912]: Virus and Content Scanning: >> Starting >> Jan 30 16:04:18 server MailScanner[29912]: k0UF45M29934/eicar.com:infected: >> EICAR-Test-File (not a virus) >> Jan 30 16:04:18 server MailScanner[29912]: Virus Scanning: Bitdefender found >> 1 infections >> Jan 30 16:04:18 server MailScanner[29912]: Infected message k0UF45M29934 >> came from 69.20.55.130 >> Jan 30 16:04:18 server MailScanner[29912]: Virus Scanning: Found 1 viruses >> Jan 30 16:04:18 server MailScanner[29912]: Virus Scanning completed at 891 >> bytes per second >> Jan 30 16:04:18 server MailScanner[29912]: Saved entire message to >> /home/data/mailscanner/quarantine/20060130/k0UF45M29934 >> Jan 30 16:04:18 server MailScanner[29912]: Saved infected "eicar.com" to >> /home/data/mailscanner/quarantine/20060130/k0UF45M29934 >> Jan 30 16:04:18 server MailScanner[29912]: Viruses marked as silent: >> Bitdefender: Found virus EICAR-Test-File (not a virus) in file eicar.com >> Jan 30 16:04:18 server sendmail[29943]: k0UF4Ie29943: >> from=postmaster@trul.cz, size=1447, class=0, nrcpts=1, >> msgid=<200601301504.k0UF4Ie29943@server.trul>, relay=root@localhost >> Jan 30 16:04:18 server MailScanner[29912]: Notices: Warned about 1 messages >> Jan 30 16:04:18 server MailScanner[29912]: Virus Processing completed at >> 22175 bytes per second >> Jan 30 16:04:18 server MailScanner[29912]: Disinfection completed at >> 23212796 bytes per second >> Jan 30 16:04:18 server MailScanner[29912]: Batch completed at 794 bytes per >> second (3946 / 4) >> Jan 30 16:04:18 server MailScanner[29912]: Batch processed in 4.97 seconds >> Jan 30 16:04:18 server MailScanner[29912]: "Always Looked Up Last" took 0.00 >> seconds >> ---------------------------------------------------------------------------- >> --------- >> >> So if I am right, then MS reconizes that only Bitdefender found virus, >> however AVG found that too (according to log). >> >> I have run AVG via wrapper on whole quarantine dir and got this: >> ---------------------------------------------------------------------- >> [root@server quarantine]# /usr/lib/MailScanner/avg-wrapper /usr/local . >> AVG7 Anti-Virus command line scanner >> Copyright (c) 2005 GRISOFT, s.r.o. >> Program version 7.1.23, engine 718 >> Virus Database: Version 267.14.23/243 2006-01-27 >> License type is FULL for SERVER. >> Expiration day: 25. 10. 2007 >> ./20060124/spam/k0O2Fbq19306 Virus found Worm/Feebs >> ./20060124/spam/k0OD9Cq01779 Virus found Worm/Feebs >> ./20060124/spam/k0ODACq01874 Virus found Worm/Feebs >> ./20060125/k0PAM9829845/eicar.com Virus identified EICAR_Test >> ./20060125/k0PAM9829845/message Virus identified EICAR_Test (+1) >> ./20060125/k0PAeen30411/eicar.com Virus identified EICAR_Test >> ./20060125/k0PAeen30411/message Virus identified EICAR_Test (+1) >> ./20060125/nonspam/k0PAM9829845 Virus identified EICAR_Test (+1) >> ./20060125/nonspam/k0PAeen30411 Virus identified EICAR_Test (+1) >> ./20060125/nonspam/k0PIOtn08366 Virus found Worm/Feebs >> ./20060125/spam/k0PA5cq29321 Virus found Worm/Feebs >> ./20060130/k0UEuSM29727/eicar.com Virus identified EICAR_Test >> ./20060130/k0UEuSM29727/message Virus identified EICAR_Test (+1) >> ./20060130/k0UF45M29934/eicar.com Virus identified EICAR_Test >> ./20060130/k0UF45M29934/message Virus identified EICAR_Test (+1) >> ./20060130/nonspam/k0UEuSM29727 Virus identified EICAR_Test (+1) >> ./20060130/nonspam/k0UF45M29934 Virus identified EICAR_Test (+1) >> Tested: 2660 files, 0 sectors >> Infections: 17 >> Errors: 0 >> ------------------------------------------------------------------------ >> >> So I think that there is problem in parsing AVG output in MS. >> >> And 1 more problem with avg-wrapper - it does not delete report files in >> /tmp dir. Files are staying there until manualy deleted. >> >> With regards >> Pavel Zichovsky (zichovsky@trul) >> >> >> > > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From zichovsky at trul.cz Mon Jan 30 19:43:43 2006 From: zichovsky at trul.cz (Pavel Zichovsky) Date: Mon Jan 30 19:43:50 2006 Subject: Problem with AVG scanner - MailScanner does not recognize virus In-Reply-To: <43DE5DE6.1020802@univap.br> Message-ID: <001801c625d5$7a36c7b0$0200a8c0@NBZICHOVSKY2> Hi there, > -----P?vodn? zpr?va----- > Pavel, > > > For AVG for linux versions 7.0.12 and higher, new > instalation is into /opt/grisoft/avg7 subtree. > > Change the installation directory in the configuration file > /etc/Mailscanner/virus.scanners.conf to /opt/grisoft/avg7 Thanks, but this is not my case, I have AVG installed long time ago and only updating via avgupdate, so my AVG is still in /usr/local. But with Julian's help (editing SweepViruses) it is now working OK. With regards Pavel Zichovsky (zichovsky@trul) From mhw at WittsEnd.com Mon Jan 30 20:12:26 2006 From: mhw at WittsEnd.com (Michael H. Warfield) Date: Mon Jan 30 20:12:32 2006 Subject: MailScanner being a little TOO fussy about case? Message-ID: <1138651946.3987.46.camel@canyon.wittsend.com> Hmmm... Just noticed this in an E-Mail message: MailScanner has detected a possible fraud attempt from "www.rglegal.com" claiming to bewww.RGLegal.com Ok... Other than needing a space after the "be" to be clearer, it's fussing that the case doesn't match in an FQDN? That's a bit much. It shouldn't be case sensitive there, should it? While there MIGHT be a problem with the paths in some URL's being case sensitive, a domain name is case insensitive. In fact, I quite often mix case on my own domain name - wittsend.com == WittsEnd.com == WittsEnd.Com - depending on context. Mike -- Michael H. Warfield (AI4NB) | (770) 985-6132 | mhw@WittsEnd.com /\/\|=mhw=|\/\/ | (678) 463-0932 | http://www.wittsend.com/mhw/ NIC whois: MHW9 | An optimist believes we live in the best of all PGP Key: 0xDF1DD471 | possible worlds. A pessimist is sure of it! -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 307 bytes Desc: This is a digitally signed message part Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060130/83df4bc3/attachment.bin From mailscanner at eliquid.com Mon Jan 30 20:21:09 2006 From: mailscanner at eliquid.com (Wess Bechard) Date: Mon Jan 30 20:19:52 2006 Subject: MailScanner being a little TOO fussy about case? In-Reply-To: <1138651946.3987.46.camel@canyon.wittsend.com> References: <1138651946.3987.46.camel@canyon.wittsend.com> Message-ID: <1138652469.18755.42.camel@localhost.localdomain> I have had this same problem too, and actually disabled phishing detection when I noticed it. Version 4.50-12 here. On Mon, 2006-01-30 at 15:12 -0500, Michael H. Warfield wrote: > Hmmm... > > Just noticed this in an E-Mail message: > > MailScanner has detected a possible fraud attempt from "www.rglegal.com" > claiming to bewww.RGLegal.com > > Ok... Other than needing a space after the "be" to be clearer, it's > fussing that the case doesn't match in an FQDN? That's a bit much. It > shouldn't be case sensitive there, should it? While there MIGHT be a > problem with the paths in some URL's being case sensitive, a domain name > is case insensitive. In fact, I quite often mix case on my own domain > name - wittsend.com == WittsEnd.com == WittsEnd.Com - depending on > context. > > Mike ___________________________________________ Wess Bechard IT & Digital Signage Solutions Manager eliquidMEDIA International Inc. Visit: www.eliquid.com Office: 519.973.1930 - 1.800.561.7525 Fax: 519.253.0337 Cell: 519.791.9492 ___________________________________________ -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060130/4692e7c6/attachment.html From ugob at camo-route.com Mon Jan 30 20:35:26 2006 From: ugob at camo-route.com (Ugo Bellavance) Date: Mon Jan 30 20:36:19 2006 Subject: Remove times from logwatch reports In-Reply-To: <43DCF456.8040302@ecs.soton.ac.uk> References: <43DCEF2E.2020501@rogers.com> <43DCF456.8040302@ecs.soton.ac.uk> Message-ID: Julian Field wrote: > Gerry Doris wrote: >> Ever since we added the batch processing times I've been getting reams >> of lines in my logcheck reports giving the batch times for each message >> being processed. >> >> I haven't been able to find where I can turn these off. Is this >> configurable? > I would much prefer it if the logcheck settings were adjusted to handle > this output. > I currently have 272 configuration options, I don't want to make it 273 > just for this. > Log speed = no? -- Ugo -> Please don't send a copy of your reply by e-mail. I read the list. -> Please avoid top-posting, long signatures and HTML, and cut the irrelevant parts in your replies. From MailScanner at ecs.soton.ac.uk Mon Jan 30 20:47:03 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Jan 30 20:47:06 2006 Subject: MailScanner being a little TOO fussy about case? In-Reply-To: <1138652469.18755.42.camel@localhost.localdomain> References: <1138651946.3987.46.camel@canyon.wittsend.com> <1138652469.18755.42.camel@localhost.localdomain> Message-ID: <43DE7B47.3070800@ecs.soton.ac.uk> It is case insensitive. I just tested it. And I just checked the code. It really is case insensitive, I've even doubled it up in 1 place just to be sure. So I'm sorry, but I don't understand how you got your results. :-( Wess Bechard wrote: > I have had this same problem too, and actually disabled phishing > detection when I noticed it. > > Version 4.50-12 here. > > > > On Mon, 2006-01-30 at 15:12 -0500, Michael H. Warfield wrote: >> Hmmm... >> >> Just noticed this in an E-Mail message: >> >> MailScanner has detected a possible fraud attempt from "www.rglegal.com" >> claiming to bewww.RGLegal.com >> >> Ok... Other than needing a space after the "be" to be clearer, it's >> fussing that the case doesn't match in an FQDN? That's a bit much. It >> shouldn't be case sensitive there, should it? While there MIGHT be a >> problem with the paths in some URL's being case sensitive, a domain name >> is case insensitive. In fact, I quite often mix case on my own domain >> name - wittsend.com == WittsEnd.com == WittsEnd.Com - depending on >> context. >> -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From mhw at WittsEnd.com Mon Jan 30 20:58:56 2006 From: mhw at WittsEnd.com (Michael H. Warfield) Date: Mon Jan 30 20:59:04 2006 Subject: MailScanner being a little TOO fussy about case? In-Reply-To: <43DE7B47.3070800@ecs.soton.ac.uk> References: <1138651946.3987.46.camel@canyon.wittsend.com> <1138652469.18755.42.camel@localhost.localdomain> <43DE7B47.3070800@ecs.soton.ac.uk> Message-ID: <1138654736.3987.53.camel@canyon.wittsend.com> On Mon, 2006-01-30 at 20:47 +0000, Julian Field wrote: > It is case insensitive. I just tested it. And I just checked the code. > It really is case insensitive, I've even doubled it up in 1 place just > to be sure. > So I'm sorry, but I don't understand how you got your results. > :-( Oh, hells bells... I guess it wasn't case after all. It looks like it's some sort of html inanity. Here's the text: MailScanner has detected a possible fraud attempt from "www.rglegal.com" claiming to be www.RGLegal.com What a bunch of garbage. Splitting an href around PART of the FQDN and all. Gag... The site is owned by a couple of friends of mine. I'll bring this to their attention. Mike > Wess Bechard wrote: > > I have had this same problem too, and actually disabled phishing > > detection when I noticed it. > > > > Version 4.50-12 here. > > > > > > > > On Mon, 2006-01-30 at 15:12 -0500, Michael H. Warfield wrote: > >> Hmmm... > >> > >> Just noticed this in an E-Mail message: > >> > >> MailScanner has detected a possible fraud attempt from "www.rglegal.com" > >> claiming to bewww.RGLegal.com > >> > >> Ok... Other than needing a space after the "be" to be clearer, it's > >> fussing that the case doesn't match in an FQDN? That's a bit much. It > >> shouldn't be case sensitive there, should it? While there MIGHT be a > >> problem with the paths in some URL's being case sensitive, a domain name > >> is case insensitive. In fact, I quite often mix case on my own domain > >> name - wittsend.com == WittsEnd.com == WittsEnd.Com - depending on > >> context. > >> > > -- > Julian Field > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > Professional Support Services at www.MailScanner.biz > MailScanner thanks transtec Computers for their support > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > -- Michael H. Warfield (AI4NB) | (770) 985-6132 | mhw@WittsEnd.com /\/\|=mhw=|\/\/ | (678) 463-0932 | http://www.wittsend.com/mhw/ NIC whois: MHW9 | An optimist believes we live in the best of all PGP Key: 0xDF1DD471 | possible worlds. A pessimist is sure of it! -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 307 bytes Desc: This is a digitally signed message part Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060130/f4abea90/attachment.bin From mailstodevi at yahoo.com Tue Jan 31 05:39:12 2006 From: mailstodevi at yahoo.com (Devi S) Date: Tue Jan 31 05:39:15 2006 Subject: spamassassinprefsfile at line 1377 In-Reply-To: Message-ID: <20060131053912.24406.qmail@web50615.mail.yahoo.com> I am getting this error when i restart MailScanner, Jan 31 10:41:26 inmail MailScanner[29528]: MailScanner E-Mail Virus Scanner version 4.50.9 starting... Jan 31 10:41:26 inmail MailScanner[29528]: Syntax error(s) in configuration file: Jan 31 10:41:26 inmail MailScanner[29528]: Unrecognised keyword "spamassassinprefsfile" at line 1377 Jan 31 10:41:26 inmail MailScanner[29528]: Aborting due to syntax errors in /etc/MailScanner/MailScanner.conf. Jan 31 10:41:26 inmail MailScanner[29528]: Read 699 hostnames from the phishing whitelist Jan 31 10:41:26 inmail MailScanner[29528]: Using SpamAssassin results cache Jan 31 10:41:27 inmail MailScanner[29528]: Connected to SpamAssassin cache database Jan 31 10:41:27 inmail MailScanner[29528]: Using locktype = flock I am using "MailScanner version 4.50.9", SpamAssasin - 3.001000 Mail::SpamAssassin Should I comment that line # 1377? I am not able to judge the impact of commenting that line. Please advice. Thank you. Regards Devi S. Our greatest glory is not in never falling- but in rising every time we fall - Confucius --------------------------------- Bring words and photos together (easily) with PhotoMail - it's free and works with Yahoo! Mail. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060130/2fe741e2/attachment.html From Jeff.Mills at versacold.com.au Tue Jan 31 05:57:18 2006 From: Jeff.Mills at versacold.com.au (Jeff Mills) Date: Tue Jan 31 05:57:26 2006 Subject: spamassassinprefsfile at line 1377 Message-ID: <197F21E06E4D2A478519EA9078D6AA1C01B0AC7B@poclexch.AU.POCOLD.POCL> >-----Original Message----- >From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Devi S >Sent: Tuesday, 31 January 2006 4:39 PM >To: MailScanner discussion >Subject: spamassassinprefsfile at line 1377 > >Should I comment that line # 1377? I am not able to judge the impact of commenting that line. > >Please advice. Thank you. Did you recently upgrade? I also had this message after upgrading. I commented out the offending line with no ill effects. *** "This company is now part of the Versacold Holdings Corp. and is no longer owned by or affiliated with the P&O Group" *** Please update your address books: Was: firstname.lastname@pocold.com.au Now: firstname.lastname@versacold.com.au ************** www.versacold.com ************** From mailstodevi at yahoo.com Tue Jan 31 06:15:08 2006 From: mailstodevi at yahoo.com (Devi S) Date: Tue Jan 31 06:15:10 2006 Subject: spamassassinprefsfile at line 1377 In-Reply-To: <197F21E06E4D2A478519EA9078D6AA1C01B0AC7B@poclexch.AU.POCOLD.POCL> Message-ID: <20060131061508.37114.qmail@web50615.mail.yahoo.com> Jeff Mills wrote: >Should I comment that line # 1377? I am not able to judge the impact of commenting that line. > >Please advice. Thank you. Did you recently upgrade? I also had this message after upgrading. I commented out the offending line with no ill effects. Yes, Ok I will comment and see. thank you. Regards Devi S. Our greatest glory is not in never falling- but in rising every time we fall - Confucius --------------------------------- Bring words and photos together (easily) with PhotoMail - it's free and works with Yahoo! Mail. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060130/d945f727/attachment.html From MailScanner at ecs.soton.ac.uk Tue Jan 31 08:54:43 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Jan 31 08:54:54 2006 Subject: spamassassinprefsfile at line 1377 In-Reply-To: <197F21E06E4D2A478519EA9078D6AA1C01B0AC7B@poclexch.AU.POCOLD.POCL> References: <197F21E06E4D2A478519EA9078D6AA1C01B0AC7B@poclexch.AU.POCOLD.POCL> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- On 31 Jan 2006, at 05:57, Jeff Mills wrote: > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of >> Devi S >> Sent: Tuesday, 31 January 2006 4:39 PM >> To: MailScanner discussion >> Subject: spamassassinprefsfile at line 1377 >> >> Should I comment that line # 1377? I am not able to judge the >> impact of commenting that line. >> >> Please advice. Thank you. > > Did you recently upgrade? > I also had this message after upgrading. > I commented out the offending line with no ill effects. After upgrading, please *always* run upgrade_MailScanner_conf and upgrade_languages_conf. They will both show you how to use them when you run them. If you don't do this, you won't be able to find out about new configuration options, and hence new features, that have been added since you last ran it. - -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.0.4 (Build 4042) iQEVAwUBQ98l1vw32o+k+q+hAQF+5gf/TXCz72SAR+khGEQ+nrWUjUrTZ/StbyGs crfcayC72lFPUg9IrNC2CvIqc7Dj0jWkjs7YUacmS/snC9U0m6HUDkd4K7W2VGrL c6oykA/G6XoO1zPC0ykztMIQvGwH5VMN7g5e8nwXrfddumYBgFKfroSY8ORfShtj lWFrEOJq5Pkg7mPwzyiovVrhvS9jCqEDx+C58fHdP2P05NqJZ0Aufv2c21fhnL8X rUmdW53ESPu6UFytItV0lC9vQVEsevaT+AqTY5hNDyAFD/umt9LNKwfz5WYURvXP qPo+9xAz51yptQMHj4qafmO9RBDv6nnBDz1aEtB3xidDxBjGpJwW0w== =no9J -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From P.G.M.Peters at utwente.nl Tue Jan 31 09:32:15 2006 From: P.G.M.Peters at utwente.nl (Peter Peters) Date: Tue Jan 31 09:32:17 2006 Subject: blank "is" report lines in syslog? In-Reply-To: <43DA7D2B.8040907@evi-inc.com> References: <43DA63EC.7010400@pixelhammer.com> <43DA6686.9050508@evi-inc.com> <43DA79AA.9040208@pixelhammer.com> <43DA7D2B.8040907@evi-inc.com> Message-ID: <43DF2E9F.7050107@utwente.nl> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Matt Kettler wrote on 27-1-2006 21:06: >>We don't blindly accept messages. But we do send a bounce if the mailbox >>doesn't exist, or if the box is overquota, or if the message is too >>large, or delivery fails for any other reason. Some of these bounces >>will be after the connection and the message has been accepted. > > Only overquota or "other reason" should be bounced post-accept. > > Message to large should be failed at the end of the SMTP data phase. > > Nonexistent mailbox should be failed at the SMTP RCPT TO phase. I talked to an ISP this morning who was having problems with bounces making it to spamcop. They have implemented mail-ahead to at least lessen the problem. But they still have customers using Exchange (only a few), UUCP (a lot) or fetchmail (a few). - -- Peter Peters, senior beheerder (Security) Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE) Universiteit Twente, Postbus 217, 7500 AE Enschede telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2 (MingW32) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQFD3y6eelLo80lrIdIRAjbpAJ9hhtLNXs1Gc0md7hqwVfAvlVc04QCgkkWZ YCOf0Ou9XTVqTRzWFJjYYUw= =meKL -----END PGP SIGNATURE----- From ssilva at sgvwater.com Tue Jan 31 16:53:44 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Tue Jan 31 16:55:06 2006 Subject: spamassassinprefsfile at line 1377 In-Reply-To: <20060131053912.24406.qmail@web50615.mail.yahoo.com> References: <20060131053912.24406.qmail@web50615.mail.yahoo.com> Message-ID: Devi S spake the following on 1/30/2006 9:39 PM: > I am getting this error when i restart MailScanner, > > Jan 31 10:41:26 inmail MailScanner[29528]: MailScanner E-Mail Virus > Scanner version 4.50.9 starting... > Jan 31 10:41:26 inmail MailScanner[29528]: Syntax error(s) in > configuration file: > Jan 31 10:41:26 inmail MailScanner[29528]: Unrecognised keyword > "spamassassinprefsfile" at line 1377 > Jan 31 10:41:26 inmail MailScanner[29528]: Aborting due to syntax errors > in /etc/MailScanner/MailScanner.conf. > Jan 31 10:41:26 inmail MailScanner[29528]: Read 699 hostnames from the > phishing whitelist > Jan 31 10:41:26 inmail MailScanner[29528]: Using SpamAssassin results cache > Jan 31 10:41:27 inmail MailScanner[29528]: Connected to SpamAssassin > cache database > Jan 31 10:41:27 inmail MailScanner[29528]: Using locktype = flock > > > I am using "MailScanner version 4.50.9", SpamAssasin - 3.001000 > Mail::SpamAssassin > > Should I comment that line # 1377? I am not able to judge the impact of > commenting that line. > > Please advice. Thank you. Is this an upgrade? Did you run the upgrade_MailScanner_conf script? -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From victor at pixelmagicfx.com Tue Jan 31 18:48:41 2006 From: victor at pixelmagicfx.com (Victor DiMichina) Date: Tue Jan 31 18:48:56 2006 Subject: Panda Wrapper reporting zero Message-ID: <43DFB109.7030609@pixelmagicfx.com> I've been wrestling with the Panda Wrapper for some time now. It's *probably* working, but with no reporting. The only way I can see it working is when I run it manually on an Eicar virus, I have the -ren option selected so that it actually renames the eicar.com to eicar.com.vir. It still returns a Virus=0 status. I get no updates from MailScanner the way I do for the f-secure wrapper. Does anyone have success in getting Panda's wrapper to report a virus when found? Even though it's probably working, it's not a very secure feeling just trusting a piece of code to do its job with no feedback. MailScanner Version 4.47.4 Thanks Vic From MailScanner at ecs.soton.ac.uk Tue Jan 31 19:07:15 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Jan 31 19:07:19 2006 Subject: Panda Wrapper reporting zero In-Reply-To: <43DFB109.7030609@pixelmagicfx.com> References: <43DFB109.7030609@pixelmagicfx.com> Message-ID: <43DFB563.3040505@ecs.soton.ac.uk> Victor DiMichina wrote: > > I've been wrestling with the Panda Wrapper for some time now. It's > *probably* working, but with no reporting. The only way I can see > it working is when I run it manually on an Eicar virus, I have the > -ren option selected so that it actually renames the eicar.com to > eicar.com.vir. It still returns a Virus=0 status. I get no > updates from MailScanner the way I do for the f-secure wrapper. Does > anyone have success in getting Panda's wrapper to report a virus when > found? Even though it's probably working, it's not a very secure > feeling just trusting a piece of code to do its job with no feedback. > MailScanner Version 4.47.4 Very few people have ever had much luck getting Panda to work properly. It is the worst of all the virus scanners I support. Check you /etc/MailScanner/virus.scanners.conf file to be sure you have the right path. Run this /usr/lib/MailScanner/panda-wrapper /usr /tmp will scan /tmp for you, the "/usr" argument is the path taken from the end of the corresponding line in virus.scanners.conf. -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From victor at pixelmagicfx.com Tue Jan 31 19:21:24 2006 From: victor at pixelmagicfx.com (Victor DiMichina) Date: Tue Jan 31 19:21:41 2006 Subject: Panda Wrapper reporting zero In-Reply-To: <43DFB563.3040505@ecs.soton.ac.uk> References: <43DFB109.7030609@pixelmagicfx.com> <43DFB563.3040505@ecs.soton.ac.uk> Message-ID: <43DFB8B4.20309@pixelmagicfx.com> Julian Field wrote: > Very few people have ever had much luck getting Panda to work > properly. It is the worst of all the virus scanners I support. Check > you /etc/MailScanner/virus.scanners.conf file to be sure you have the > right path. > > Run this > /usr/lib/MailScanner/panda-wrapper /usr /tmp > will scan /tmp for you, the "/usr" argument is the path taken from the > end of the corresponding line in virus.scanners.conf. > I figured as much. I had it working when the wrapper was all in Spanish and before Panda went to their over-engineered output. :) Looking through the archives, it seems like some had a measure of success with Rick's new wrapper. I can actually see results of the wrapper detecting and eliminating virus files, but can't get an accurate report. The only reason I'm bothering is because I'm under support for one more year, and I'd like to use it. Just got my MS book and BRIGHT YELLOW MS shirt for Christmas. Cool stuff, Julian. Vic From mstandish at gmail.com Tue Jan 31 20:42:34 2006 From: mstandish at gmail.com (Matt Standish) Date: Tue Jan 31 20:36:51 2006 Subject: List Archive? Message-ID: <43DFCBBA.8060103@gmail.com> Is there a list archive online anywhere besides http://lists.mailscanner.info/pipermail/mailscanner/ ? I am working a postfix problem and I am sure it has been solved before. From michele at blacknight.ie Tue Jan 31 20:45:21 2006 From: michele at blacknight.ie (Michele Neylon:: Blacknight.ie) Date: Tue Jan 31 20:45:22 2006 Subject: List Archive? In-Reply-To: <43DFCBBA.8060103@gmail.com> References: <43DFCBBA.8060103@gmail.com> Message-ID: <43DFCC61.1090304@blacknight.ie> Matt Standish wrote: > Is there a list archive online anywhere besides > http://lists.mailscanner.info/pipermail/mailscanner/ ? I am working a > postfix problem and I am sure it has been solved before. > > Not at present (as far as I know) Are you having issues finding things? -- Mr Michele Neylon Blacknight Solutions Quality Business Hosting & Colocation http://www.blacknight.ie/ Tel. 1850 927 280 Intl. +353 (0) 59 9183072 Direct Dial: +353 (0)59 9183090 Fax. +353 (0) 59 9164239 From ssilva at sgvwater.com Tue Jan 31 20:47:30 2006 From: ssilva at sgvwater.com (Scott Silva) Date: Tue Jan 31 20:48:26 2006 Subject: List Archive? In-Reply-To: <43DFCBBA.8060103@gmail.com> References: <43DFCBBA.8060103@gmail.com> Message-ID: Matt Standish spake the following on 1/31/2006 12:42 PM: > Is there a list archive online anywhere besides > http://lists.mailscanner.info/pipermail/mailscanner/ ? I am working a > postfix problem and I am sure it has been solved before. > > http://dir.gmane.org/gmane.mail.virus.mailscanner is a good point to start -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From dhawal at netmagicsolutions.com Tue Jan 31 20:49:53 2006 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Tue Jan 31 20:49:46 2006 Subject: List Archive? In-Reply-To: <43DFCBBA.8060103@gmail.com> References: <43DFCBBA.8060103@gmail.com> Message-ID: <43DFCD71.4060405@netmagicsolutions.com> Matt Standish wrote: > Is there a list archive online anywhere besides > http://lists.mailscanner.info/pipermail/mailscanner/ ? I am working a > postfix problem and I am sure it has been solved before. Try http://dir.gmane.org/gmane.mail.virus.mailscanner - dhawal From mstandish at gmail.com Tue Jan 31 21:01:05 2006 From: mstandish at gmail.com (Matt Standish) Date: Tue Jan 31 20:55:24 2006 Subject: Postfix message stuck in incoming queue WAS: Re: List Archive? In-Reply-To: <43DFCC61.1090304@blacknight.ie> References: <43DFCBBA.8060103@gmail.com> <43DFCC61.1090304@blacknight.ie> Message-ID: <43DFD011.1000703@gmail.com> >Not at present (as far as I know) > >Are you having issues finding things? A little bit. I followed this guide http://www.sng.ecs.soton.ac.uk/mailscanner/install/postfix.shtml to install mailscanner on Suse 10 with postfix. I used the latest beta release and the SA/CLAMAV install from the download page. When I receive a message it just sits in the /var/spool/postfix/hold folder. Looking at the mail logs I am not finding any clues. Are there some debugging options I can enable? I am only using postfix because it is what I know. Not sure what other info I can give you. Michele Neylon:: Blacknight.ie wrote: > Matt Standish wrote: > >> Is there a list archive online anywhere besides >> http://lists.mailscanner.info/pipermail/mailscanner/ ? I am working a >> postfix problem and I am sure it has been solved before. >> >> >> > > > From mailscanner at eliquid.com Tue Jan 31 20:58:08 2006 From: mailscanner at eliquid.com (Wess Bechard) Date: Tue Jan 31 20:56:48 2006 Subject: List Archive? In-Reply-To: <43DFCBBA.8060103@gmail.com> References: <43DFCBBA.8060103@gmail.com> Message-ID: <1138741088.26300.37.camel@localhost.localdomain> You could always join us on IRC at irc.freenode.net #mailscanner We're usually around answering questions, so please feel free to stop in. On Tue, 2006-01-31 at 15:42 -0500, Matt Standish wrote: > Is there a list archive online anywhere besides > http://lists.mailscanner.info/pipermail/mailscanner/ ? I am working a > postfix problem and I am sure it has been solved before. > > ___________________________________________ Wess Bechard IT & Digital Signage Solutions Manager eliquidMEDIA International Inc. Visit: www.eliquid.com Office: 519.973.1930 - 1.800.561.7525 Fax: 519.253.0337 Cell: 519.791.9492 ___________________________________________ -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060131/cb525586/attachment.html From mstandish at gmail.com Tue Jan 31 21:17:27 2006 From: mstandish at gmail.com (Matt Standish) Date: Tue Jan 31 21:11:44 2006 Subject: Postfix message stuck in incoming queue WAS: Re: List Archive? In-Reply-To: <43DFD011.1000703@gmail.com> References: <43DFCBBA.8060103@gmail.com> <43DFCC61.1090304@blacknight.ie> <43DFD011.1000703@gmail.com> Message-ID: <43DFD3E7.8010708@gmail.com> And here is the fix. http://thread.gmane.org/gmane.mail.virus.mailscanner/19876 Thanks everyone for posting the link to the archives. Matt Standish wrote: > >> Not at present (as far as I know) >> >> Are you having issues finding things? > > A little bit. I followed this guide > http://www.sng.ecs.soton.ac.uk/mailscanner/install/postfix.shtml to > install mailscanner on Suse 10 with postfix. I used the latest beta > release and the SA/CLAMAV install from the download page. > When I receive a message it just sits in the /var/spool/postfix/hold > folder. Looking at the mail logs I am not finding any clues. Are > there some debugging options I can enable? > > I am only using postfix because it is what I know. Not sure what other > info I can give you. > > > > Michele Neylon:: Blacknight.ie wrote: >> Matt Standish wrote: >> >>> Is there a list archive online anywhere besides >>> http://lists.mailscanner.info/pipermail/mailscanner/ ? I am working a >>> postfix problem and I am sure it has been solved before. >>> >>> >>> >> >> >> > From Edge at twu.ca Tue Jan 31 21:15:22 2006 From: Edge at twu.ca (Richard Edge) Date: Tue Jan 31 21:14:21 2006 Subject: ALL_TRUSTED problems Message-ID: I am have a problem with the ALL_TRUSTED test. No matter what what I set the ALL_TRUSTED score to in spam.assassin.prefs.conf it still fires with a score of -1.80. I have also added "trusted_networks" settings with the IP addresses of our internal mail server and it also fires on messages received from untrusted IP's. I am using MailScanner 4.50.12-2 and SA 3.1. Richard Edge Senior Systems Administrator | Technology Services Trinity Western University | t: 604.513.2089 f: 604.513.2038 | e: edge twu.ca| www.twu.ca/technology -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060131/9c89a2f9/attachment.html From mailscanner at eliquid.com Tue Jan 31 21:19:51 2006 From: mailscanner at eliquid.com (Wess Bechard) Date: Tue Jan 31 21:19:01 2006 Subject: ALL_TRUSTED problems In-Reply-To: References: Message-ID: <1138742391.26300.40.camel@localhost.localdomain> Have you linked the MailScanner/etc/Spam.assassin.prefs.conf to /etc/spamassassin/mailscanner.cf? Try a spamassassin --lint -D after verifying the link, and see what it tells you. On Tue, 2006-01-31 at 13:15 -0800, Richard Edge wrote: > I am have a problem with the ALL_TRUSTED test. No matter what what I > set the ALL_TRUSTED score to in spam.assassin.prefs.conf it still > fires with a score of -1.80. I have also added "trusted_networks" > settings with the IP addresses of our internal mail server and it also > fires on messages received from untrusted IP's. > > I am using MailScanner 4.50.12-2 and SA 3.1. > > Richard Edge > Senior Systems Administrator | Technology Services > Trinity Western University | t: 604.513.2089 > f: 604.513.2038 | e: edge twu.ca| www.twu.ca/technology > > ___________________________________________ Wess Bechard IT & Digital Signage Solutions Manager eliquidMEDIA International Inc. Visit: www.eliquid.com Office: 519.973.1930 - 1.800.561.7525 Fax: 519.253.0337 Cell: 519.791.9492 ___________________________________________ -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060131/833e7121/attachment.html From Edge at twu.ca Tue Jan 31 21:23:59 2006 From: Edge at twu.ca (Richard Edge) Date: Tue Jan 31 21:22:57 2006 Subject: ALL_TRUSTED problems Message-ID: Yes the link is there. Richard Edge Senior Systems Administrator | Technology Services Trinity Western University | t: 604.513.2089 f: 604.513.2038 | e: edge twu.ca| www.twu.ca/technology ________________________________ From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Wess Bechard Sent: Tuesday, January 31, 2006 1:20 PM To: MailScanner discussion Subject: Re: ALL_TRUSTED problems Have you linked the MailScanner/etc/Spam.assassin.prefs.conf to /etc/spamassassin/mailscanner.cf? Try a spamassassin --lint -D after verifying the link, and see what it tells you. On Tue, 2006-01-31 at 13:15 -0800, Richard Edge wrote: I am have a problem with the ALL_TRUSTED test. No matter what what I set the ALL_TRUSTED score to in spam.assassin.prefs.conf it still fires with a score of -1.80. I have also added "trusted_networks" settings with the IP addresses of our internal mail server and it also fires on messages received from untrusted IP's. I am using MailScanner 4.50.12-2 and SA 3.1. Richard Edge Senior Systems Administrator | Technology Services Trinity Western University | t: 604.513.2089 f: 604.513.2038 | e: edge twu.ca| www.twu.ca/technology ___________________________________________ Wess Bechard IT & Digital Signage Solutions Manager eliquidMEDIA International Inc. Visit: www.eliquid.com Office: 519.973.1930 - 1.800.561.7525 Fax: 519.253.0337 Cell: 519.791.9492 ___________________________________________ From MailScanner at ecs.soton.ac.uk Tue Jan 31 21:31:31 2006 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Jan 31 21:31:35 2006 Subject: ALL_TRUSTED problems In-Reply-To: References: Message-ID: <43DFD733.4010504@ecs.soton.ac.uk> You might need to add clear_trusted_networks before you set the trusted_networks value. Richard Edge wrote: > I am have a problem with the ALL_TRUSTED test. No matter what what I > set the ALL_TRUSTED score to in spam.assassin.prefs.conf it still > fires with a score of -1.80. I have also added "trusted_networks" > settings with the IP addresses of our internal mail server and it also > fires on messages received from untrusted IP's. > > I am using MailScanner 4.50.12-2 and SA 3.1. > > > *Richard Edge* > /Senior Systems Administrator |/ Technology Services > Trinity Western University | t: 604.513.2089 > f: 604.513.2038 | e: edge twu.ca| _www.twu.ca/technology_ > > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From mkettler at evi-inc.com Tue Jan 31 21:41:57 2006 From: mkettler at evi-inc.com (Matt Kettler) Date: Tue Jan 31 21:42:05 2006 Subject: ALL_TRUSTED problems In-Reply-To: <1138742391.26300.40.camel@localhost.localdomain> References: <1138742391.26300.40.camel@localhost.localdomain> Message-ID: <43DFD9A5.5030602@evi-inc.com> Wess Bechard wrote: > Have you linked the MailScanner/etc/Spam.assassin.prefs.conf to > /etc/spamassassin/mailscanner.cf? Are you sure that /etc/spamassassin is the right place? It's not on my system, on my system it's /etc/mail/spamassassin. Don't assume that other people have the same site rules dir as you, verify. > Try a spamassassin --lint -D after verifying the link, and see what it > tells you. Well, I'd run that, check the top of the output for the "site rules dir" and make sure it matches the target of the link. After that, I'd run spamassassin --lint (without the -D). This should run quietly with no error messages. If it prints anything, fix the problems it mentions. From mkettler at evi-inc.com Tue Jan 31 21:54:02 2006 From: mkettler at evi-inc.com (Matt Kettler) Date: Tue Jan 31 21:54:20 2006 Subject: ALL_TRUSTED problems In-Reply-To: <43DFD733.4010504@ecs.soton.ac.uk> References: <43DFD733.4010504@ecs.soton.ac.uk> Message-ID: <43DFDC7A.6010800@evi-inc.com> Julian Field wrote: > You might need to add > clear_trusted_networks > before you set the trusted_networks value. Nah, the only time you should need to do that is if there's a trusted_networks already declared in another config file. If you're dealing at the site rules level, only one file should have a trusted_networks statement at all. Better to verify that than try to fix it with a clear. I run my site with one trusted_networks statement (in my local.cf) and no clear_trusted_networks. This worked fine on 2.64 and still works fine on 3.1.0. In general clear_trusted_networks is really only useful in user_prefs files. It can be used where one user wants a different trust path than the one called out by the config at the site_rules level. They might want that if they get their mail forwarded from some other site. From glenn.steen at gmail.com Tue Jan 31 22:15:18 2006 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue Jan 31 22:15:22 2006 Subject: Panda Wrapper reporting zero In-Reply-To: <43DFB8B4.20309@pixelmagicfx.com> References: <43DFB109.7030609@pixelmagicfx.com> <43DFB563.3040505@ecs.soton.ac.uk> <43DFB8B4.20309@pixelmagicfx.com> Message-ID: <223f97700601311415p7d41b97m@mail.gmail.com> On 31/01/06, Victor DiMichina wrote: > > Julian Field wrote: > > > Very few people have ever had much luck getting Panda to work > > properly. It is the worst of all the virus scanners I support. Check > > you /etc/MailScanner/virus.scanners.conf file to be sure you have the > > right path. > > > > Run this > > /usr/lib/MailScanner/panda-wrapper /usr /tmp > > will scan /tmp for you, the "/usr" argument is the path taken from the > > end of the corresponding line in virus.scanners.conf. > > > I figured as much. I had it working when the wrapper was all in > Spanish and before Panda went to their over-engineered output. :) > > Looking through the archives, it seems like some had a measure of > success with Rick's new wrapper. I can actually see results of the > wrapper detecting and eliminating virus files, but can't get an > accurate report. The only reason I'm bothering is because I'm under > support for one more year, and I'd like to use it. > > Just got my MS book and BRIGHT YELLOW MS shirt for Christmas. Cool > stuff, Julian. > > Vic > Hi Vic, I suppose you've looked at my scribblings at http://wiki.mailscanner.info/doku.php?id=documentation:anti_virus:panda:install ? IIRC you still need supply a directory structure "mimicking" the layout present when running on a message batch in MailScanner. And I _think_ it still ignores the /path/to/batch argument. It's very possible I recall wrong though:-), and I'm not near an MS box where I can look at it until tomorrow... And I'm simply too lazy to DL and read code @home:-). I'm sure Rick and/or Julian will correct any misconceptions in the above:) -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From Edge at twu.ca Tue Jan 31 23:03:56 2006 From: Edge at twu.ca (Richard Edge) Date: Tue Jan 31 23:03:17 2006 Subject: ALL_TRUSTED problems Message-ID: I have tried adding "clear_trusted_networks" and have confirmed that I only have one configuration file with trusted_networks, /etc/mail/spamassasin/mailscanner.cf which is linked to /etc/MailScanner/spam.assassin.prefs.conf and it is still firing and with a score of -1.80. This is in spite of also adding a "score ALL_TRUSTED -0.01" to the spam.assassin.prefs.conf and commenting out the "trusted_networks". The "score ALL_TRUSTED -0.01" setting does not seem to have any effect on the scoring of this test. I have also tried leaving the trusted_networks commented out and removing "score ALL_TRUSTED -0.01" from spam.assassin.prefs.conf and adding it to /etc/mail/spamassassin/local.cf without any change. This occurs on both gateways with identical configurations. Richard Edge Senior Systems Administrator | Technology Services Trinity Western University | t: 604.513.2089 f: 604.513.2038 | e: edge twu.ca| www.twu.ca/technology -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian Field Sent: Tuesday, January 31, 2006 1:32 PM To: MailScanner discussion Subject: Re: ALL_TRUSTED problems You might need to add clear_trusted_networks before you set the trusted_networks value. Richard Edge wrote: > I am have a problem with the ALL_TRUSTED test. No matter what what I > set the ALL_TRUSTED score to in spam.assassin.prefs.conf it still > fires with a score of -1.80. I have also added "trusted_networks" > settings with the IP addresses of our internal mail server and it also > fires on messages received from untrusted IP's. > > I am using MailScanner 4.50.12-2 and SA 3.1. > > > *Richard Edge* > /Senior Systems Administrator |/ Technology Services Trinity Western > University | t: 604.513.2089 > f: 604.513.2038 | e: edge twu.ca| _www.twu.ca/technology_ > > -- Julian Field www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Professional Support Services at www.MailScanner.biz MailScanner thanks transtec Computers for their support PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list MailScanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From mkettler at evi-inc.com Tue Jan 31 23:12:28 2006 From: mkettler at evi-inc.com (Matt Kettler) Date: Tue Jan 31 23:12:36 2006 Subject: ALL_TRUSTED problems In-Reply-To: References: Message-ID: <43DFEEDC.6050405@evi-inc.com> Richard Edge wrote: > I have tried adding "clear_trusted_networks" and have confirmed that I > only have one configuration file with trusted_networks, > /etc/mail/spamassasin/mailscanner.cf which is linked to > /etc/MailScanner/spam.assassin.prefs.conf and it is still firing and > with a score of -1.80. This is in spite of also adding a "score > ALL_TRUSTED -0.01" to the spam.assassin.prefs.conf and commenting out > the "trusted_networks". The "score ALL_TRUSTED -0.01" setting does not > seem to have any effect on the scoring of this test. > > I have also tried leaving the trusted_networks commented out and > removing "score ALL_TRUSTED -0.01" from spam.assassin.prefs.conf and > adding it to /etc/mail/spamassassin/local.cf without any change. This > occurs on both gateways with identical configurations. Did you do a reload on mailscanner after editing? I'd also STRONGLY suggest running: spamassassin --lint. As previously suggested. You should run that EVERY time you edit a config file. Every time. There should be no output for the above command, unless there are problems in your config. Also make sure "/etc/mail/spamassassin/" is your site rules dir when running: spamassassin --lint -D From Edge at twu.ca Tue Jan 31 23:52:48 2006 From: Edge at twu.ca (Richard Edge) Date: Tue Jan 31 23:51:18 2006 Subject: ALL_TRUSTED problems Message-ID: -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Matt Kettler Sent: Tuesday, January 31, 2006 3:12 PM To: MailScanner discussion Subject: Re: ALL_TRUSTED problems >Did you do a reload on mailscanner after editing? Yes >I'd also STRONGLY suggest running: >spamassassin --lint. >As previously suggested. You should run that EVERY time you edit a config file. Which I always do. No problems reported. Please use https://helpdesk.twu.ca for all Technical support requests. Richard Edge Senior Systems Administrator | Technology Services Trinity Western University | t: 604.513.2089 f: 604.513.2038 | e: edge@twu.ca | www.twu.ca/technology From mradzinschi at gmail.com Tue Jan 31 00:01:03 2006 From: mradzinschi at gmail.com (Marco Radzinschi) Date: Wed Feb 1 11:59:23 2006 Subject: Attachment Warnings - End of Line Behavior Changed (CR, LF) Message-ID: <6a4915590601301601s5399fd75jabf461d86eaf5d71@mail.gmail.com> Hello: I noticed that the CR/LF behavior has changed in the newest version of MailScanner (4.49) from DOS (LF only) to Unix-type text files (+) for the generated attachment warnings. I treid removing the excess characters in the report templates myself, but I noticed that the Perl script still appends to the report templates with +, which makes it appear mangled on a GroupWise system running on Windows. I did not see a configuration option for this, so I am assuming that it is hard-coded somewhere in the script. Does anyone know how to change this behavior? Please respond directly, as I am not subscribed to the list. Thank You, Marco Radzinschi -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20060130/5ef9d995/attachment-0001.html