From nats at sscrmnl.edu.ph Wed Aug 1 00:24:22 2007 From: nats at sscrmnl.edu.ph (Jose Nathaniel G. Nengasca) Date: Wed Aug 1 00:25:31 2007 Subject: ERROR:: Malformed database In-Reply-To: Message-ID: <20070731232517.A8E591040001@www1.sscrmnl.edu.ph> Hi, How would I fix this kind of problem, ERROR:: Malformed database? I just upgraded to the newest version. Thanks TIA -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From stork at openenterprise.ca Wed Aug 1 01:07:32 2007 From: stork at openenterprise.ca (Johnny Stork) Date: Wed Aug 1 01:08:44 2007 Subject: {Disarmed} Re: CRM114 - Problems with install - Almost There In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA03CEF6@HC-MBX02.herefordshire.gov.uk> References: <27938274.8361185911563784.JavaMail.root@office.splatnix.net> <46AF9CC5.2040707@openenterprise.ca> <7EF0EE5CB3B263488C8C18823239BEBA03CEF6@HC-MBX02.herefordshire.gov.uk> Message-ID: <46AFCEC4.4030403@openenterprise.ca> Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: stork.vcf Type: text/x-vcard Size: 330 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070731/db1ec966/stork.vcf From stork at openenterprise.ca Wed Aug 1 01:13:47 2007 From: stork at openenterprise.ca (Johnny Stork) Date: Wed Aug 1 01:14:34 2007 Subject: {Disarmed} Re: CRM114 - Problems with install - Working Now - Thanks In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA03CEF6@HC-MBX02.herefordshire.gov.uk> References: <27938274.8361185911563784.JavaMail.root@office.splatnix.net> <46AF9CC5.2040707@openenterprise.ca> <7EF0EE5CB3B263488C8C18823239BEBA03CEF6@HC-MBX02.herefordshire.gov.uk> Message-ID: <46AFD03B.9030605@openenterprise.ca> Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: stork.vcf Type: text/x-vcard Size: 330 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070731/6d2652b7/stork.vcf From stork at openenterprise.ca Wed Aug 1 02:57:42 2007 From: stork at openenterprise.ca (Johnny Stork) Date: Wed Aug 1 02:58:04 2007 Subject: Subject Text Not Getting Modified? Message-ID: <46AFE896.1090708@openenterprise.ca> Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: stork.vcf Type: text/x-vcard Size: 330 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070731/5e6d1871/stork.vcf From cmcfadden01 at gmail.com Wed Aug 1 05:46:05 2007 From: cmcfadden01 at gmail.com (Corey McFadden) Date: Wed Aug 1 05:46:14 2007 Subject: Random messages stuck in mqueue Message-ID: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> Guys, We're experiencing an issue on one of our boxes where messages (a good percentage) are hung in /var/spool/mqueue after being processed by MailScanner. Even those to be delivered locally will sit for (sometimes) hours until they're finally delivered. I've never seen this behavior before and something is definitely awry. Here's the environment: This is CentOS release 4.5 (Final) This is Perl version 5.008008 (5.8.8) This is MailScanner version 4.61.7 Executing 'sendmail -q -v' WILL process the stuck messages but can take quite a long time to run because it will try to deliver everything queued in a linear fashion. Here's a good example of a message hung for more than 10 minutes: [root@ewrgga-hst01 mqueue]# cat qfl714YqCD027817 V8 T1185942893 K0 N0 P32072 Fbs HX-x-MailScanner-SpamCheck: spam, SpamAssassin (not cached, score=46.69, required 6, autolearn=spam, BAYES_99 3.50, FH_HOST_ALMOST_IP 1.75, FH_MSGID_01C67 0.00, FM_RATSIGN_1106 3.80, FRT_OFFER2 1.29, FRT_PRICE 3.49, FUZZY_OFFERS 1.25, FUZZY_SOFTWARE 3.47, HELO_LOCALHOST 3.94, OUTLOOK_3416 1.74, RAZOR2_CF_RANGE_51_100 0.50, RAZOR2_CF_RANGE_E4_51_100 1.50, RAZOR2_CF_RANGE_E8_51_100 1.50, RAZOR2_CHECK 0.50, RCVD_IN_BL_SPAMCOP_NET 1.96, RCVD_IN_CBLABUSE 0.25, RCVD_IN_PBL 0.91 , RCVD_IN_SORBS_DUL 0.88, RCVD_IN_XBL 3.03, RDNS_DYNAMIC 0.10, URIBL_AB_SURBL 1.86, URIBL_BLACK 3.00, URIBL_JP_SURBL 1.50, URIBL_OB_SURBL 1.50, URIBL_SBL 1.50, URIBL_SC_SURBL 0.47, URIBL_WS_SURBL 1.50) HX-x-MailScanner-SpamScore: 46.69 HX-x-MailScanner-From: RP: . Analyzing: T1185942893 = Wed Aug 1 00:34:53 2007 Current time: Wed Aug 1 00:44:02 EDT 2007 This is pretty typical of the messages hung. In this case it's waiting to be delivered to a local "spamtrap" mailbox. Can anyone offer me any ideas to troubleshoot this? I've not been too successful hunting so far today. Thanks in advance! -Corey -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070801/47a5ea2e/attachment.html From itdept at fractalweb.com Wed Aug 1 06:00:42 2007 From: itdept at fractalweb.com (Chris Yuzik) Date: Wed Aug 1 06:00:55 2007 Subject: Random messages stuck in mqueue In-Reply-To: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> References: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> Message-ID: <46B0137A.9040609@fractalweb.com> Corey McFadden wrote: > We're experiencing an issue on one of our boxes where messages (a good > percentage) are hung in /var/spool/mqueue after being processed by > MailScanner. Even those to be delivered locally will sit for > (sometimes) hours until they're finally delivered. > > I've never seen this behavior before and something is definitely awry. > > Here's the environment: > > This is CentOS release 4.5 (Final) > This is Perl version 5.008008 (5.8.8) > > This is MailScanner version 4.61.7 Corey, You don't mention whether you're using sendmail or postfix or ?? My guess? Incorrect lock type. For sendmail, you should have "posix". Also, you might consider upgrading to latest version of MailScanner. Hope this helps. Chris From garry at glendown.de Wed Aug 1 07:07:03 2007 From: garry at glendown.de (Garry Glendown) Date: Wed Aug 1 07:07:37 2007 Subject: CRM114 - two questions ... Message-ID: <46B02307.9050601@glendown.de> Well, I put CRM114 into my personal MS installation yesterday evening, seems to work so far, though with only ~270 mails each in the CSS files, I reckon it doesn't really have that much to work with yet. Two things - one, is there a point in letting CRM114 learn known spam/ham from my archives? I've read somewhere that only false positives/negatives should be fed ... !? Second, is there an interface available to make learning easier? I tried something like this: ./mailfilter.crm -u /etc/mail/spamassassin/crm114 --learnspam and pasted a known spam mail, but the .css files were untouched afterwards ... am I missing something here? Tnx! -garry From tim.sattler at nordcapital.com Wed Aug 1 07:53:20 2007 From: tim.sattler at nordcapital.com (Sattler, Tim) Date: Wed Aug 1 07:53:32 2007 Subject: init script on SuSE Linux Message-ID: I am running MailScanner 4.62.9 on SuSE Linux Enterprise Server. When I use the init script from the SuSE tarball, I get an incorrect result for a running MailScanner from "rcMailscanner status". I guess it might fail because /proc//cmdline does not contain the full path to MailScanner, but only the basename. Therefore, I made a minor change to the init script changing line checkproc -p $mspid /usr/sbin/MailScanner to checkproc -p $mspid MailScanner This seems to give the correct results. Best regards Tim From uxbod at splatnix.net Wed Aug 1 08:54:08 2007 From: uxbod at splatnix.net (UxBoD) Date: Wed Aug 1 08:50:02 2007 Subject: Subject Text Not Getting Modified? In-Reply-To: <46AFE896.1090708@openenterprise.ca> Message-ID: <17305916.8541185954848518.JavaMail.root@office.splatnix.net> What rules do you have setup ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Johnny Stork" To: "MailScanner discussion" Sent: Wednesday, August 1, 2007 2:57:42 AM (GMT) Europe/London Subject: Subject Text Not Getting Modified? -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From uxbod at splatnix.net Wed Aug 1 08:55:41 2007 From: uxbod at splatnix.net (UxBoD) Date: Wed Aug 1 08:51:09 2007 Subject: CRM114 - two questions ... In-Reply-To: <46B02307.9050601@glendown.de> Message-ID: <8072804.8571185954941250.JavaMail.root@office.splatnix.net> Run the same command as what is in your crm114.cf. That will allow it to learn then. You can feed old messages in, but ensure the headers are intact. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Garry Glendown" To: mailscanner@lists.mailscanner.info Sent: Wednesday, August 1, 2007 7:07:03 AM (GMT) Europe/London Subject: CRM114 - two questions ... Well, I put CRM114 into my personal MS installation yesterday evening, seems to work so far, though with only ~270 mails each in the CSS files, I reckon it doesn't really have that much to work with yet. Two things - one, is there a point in letting CRM114 learn known spam/ham from my archives? I've read somewhere that only false positives/negatives should be fed ... !? Second, is there an interface available to make learning easier? I tried something like this: ./mailfilter.crm -u /etc/mail/spamassassin/crm114 --learnspam and pasted a known spam mail, but the .css files were untouched afterwards ... am I missing something here? Tnx! -garry -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From glenn.steen at gmail.com Wed Aug 1 08:54:53 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 1 08:54:55 2007 Subject: image content scanning In-Reply-To: <7EF1F27F7292534D82933F70AB6996CC25CE2C@pro-ak-exch01.hosted.pronet.net.nz> References: <7EF1F27F7292534D82933F70AB6996CC25CE23@pro-ak-exch01.hosted.pronet.net.nz> <223f97700707310401s646f4eddg27b5187e65429a3e@mail.gmail.com> <7EF1F27F7292534D82933F70AB6996CC25CE2C@pro-ak-exch01.hosted.pronet.net.nz> Message-ID: <223f97700708010054t7fb7a5bco47002139c17f548d@mail.gmail.com> On 31/07/07, Brent Addis wrote: > yeah I do, its pretty average at what we need. It does catch some, but not some of the more hardcore stuff. > > ________________________________ > > From: mailscanner-bounces@lists.mailscanner.info on behalf of Glenn Steen > Sent: Tue 31/07/2007 11:01 p.m. > To: MailScanner discussion > Subject: Re: image content scanning > > > > On 31/07/07, Brent Addis wrote: > > ? > > Hi, > > > > Has anyone found anything useful for looking at porn images in email, not > > just from a spam perspective, but from a general content perspective. > > Something that checks skin tone for example. I am not really concerned how > > many cpu cycles that this sort of thing consumes. Is there a plugin for > > spamassassin or mailscanner that isn't widely known about that will do this? > > > > Thanks, > > > > Brent > You already use ImageInfo (http://www.rulesemporium.com/plugins.htm), I presume? > Well, the problem with "skin tones detection" is that it is pretty error-prone in more ways than one... - Ethnicity... Plays havoc with this - FP on normal images... Think head shots - FP/FN due to the non-trivial nature of detecting/sampling the images correctly (simply looking on the "bias" of the colour gamut (could be a simple histogram) for that image will not do more than a shoddy work... Will be light on resources though very error prone, IMO). - addendum to the last bit is that it would likely be rather resource hungry. I used to work at a firm making ID cards/drivers licenses (had a monopoly, more or less, back in the early 90's, in Sweden)... We had a rather nifty image capture/"improvement" system, and that had a hard time (well...) finding such simple things as a "white" background (they never are white:-)... And then we didn't have that much variation wrt ethnicity...;). So, in short, what seems like a good idea isn't exactly the best possible one... Might be why, to my knowledge, there is no such thing implemented... yet. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Wed Aug 1 09:37:22 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 1 09:37:24 2007 Subject: CRM114 Installation on Centos 4 In-Reply-To: <441247027D4F274EB760A5F6E1ED9C7E020E89@houpex02.nfsmith.info> References: <441247027D4F274EB760A5F6E1ED9C7E020E79@houpex02.nfsmith.info> <46AF554E.6020308@fractalweb.com> <441247027D4F274EB760A5F6E1ED9C7E020E7F@houpex02.nfsmith.info> <441247027D4F274EB760A5F6E1ED9C7E020E89@houpex02.nfsmith.info> Message-ID: <223f97700708010137x7247cffax3bab65f1a95088a8@mail.gmail.com> On 31/07/07, Mike Kercher wrote: > Looks MUCH better! > > Thanks! > > Mike > > Mike/Scott, I've just "imprived" the looks a bit more... Made it a numbered list/code segments... Left the "automatic links formatting" alone, although I abhor it myself:-). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From R.Sterenborg at netsourcing.nl Wed Aug 1 09:52:34 2007 From: R.Sterenborg at netsourcing.nl (Rob Sterenborg) Date: Wed Aug 1 09:53:24 2007 Subject: CRM114 installation on Debian Etch Message-ID: <74ACEB3E6A055643A89B8CEC74C7BF2488E0FB@WISENT.dcyb.net> Hi, I stole the installation procedure from CentOS and adapted it to work with Debian Etch. IMHO apt-get is a nice package management system but Debian often suffers from old packages residing in the repository, so I decided to build a new package for crm114 from Debian source. The procedure is largely the same as for CentOS; differences are the creation of the package and the location of some files. If anyone is interested I can post it. Grts, Rob From glenn.steen at gmail.com Wed Aug 1 09:54:52 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 1 09:54:54 2007 Subject: CRM114 Installation on Centos 4 In-Reply-To: <46AFA5C8.30100@alexb.ch> References: <8819172.8481185914183040.JavaMail.root@office.splatnix.net> <46AFA5C8.30100@alexb.ch> Message-ID: <223f97700708010154l76b9bccbsa17b372a5df2a5a0@mail.gmail.com> On 31/07/07, Alex Broens wrote: > Note for Wiki unless someone has a better answer/idea/suggestion: > > Apparently there's no provision to limit the size of > > /etc/mail/spamassassin/crm114/reaver_cache's contents. > > Running on a *very* low traffic test box, the directory has grown to > 59MB in less than 24 hrs. > > If you do *not* intend to perform manual re-training to correct ham > /spam detection, it may be wise to set: > > /etc/mail/spamassassin/crm114/mailfilter.cf > > :text_cache: /reaver_cache/ > > to > > :text_cache: // > > This will disable msg caching of all your mail traffic > (keeping a copy of all ham/spam could also be against corp. policy) > > Disabling "reaver_cache" may speed up CRM114 processing by avoiding the > extra msg write operations to "reaver_cache" categories. > > Alex > Added a slightly modified version of this text... Just modified to more easily work with the wiki syntax. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Wed Aug 1 09:56:44 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 1 09:56:45 2007 Subject: CRM114 Installation on Centos 4 In-Reply-To: <8819172.8481185914183040.JavaMail.root@office.splatnix.net> References: <441247027D4F274EB760A5F6E1ED9C7E020E8E@houpex02.nfsmith.info> <8819172.8481185914183040.JavaMail.root@office.splatnix.net> Message-ID: <223f97700708010156l3d6a8098j4a2e2e3ec18d268a@mail.gmail.com> On 31/07/07, UxBoD wrote: > Are okay :) Will add to the wiki tomorrow then to safe if running as non-root then set permissions accordingly. > > Regards, > What exact provisions is needed for postfix use? Should this be interfoliated in Mikes original steps or a separate note? How about more generic installs... Source or otherwise? Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Wed Aug 1 10:22:23 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 1 10:22:25 2007 Subject: CRM114 Installation on Centos 4 In-Reply-To: <223f97700708010156l3d6a8098j4a2e2e3ec18d268a@mail.gmail.com> References: <441247027D4F274EB760A5F6E1ED9C7E020E8E@houpex02.nfsmith.info> <8819172.8481185914183040.JavaMail.root@office.splatnix.net> <223f97700708010156l3d6a8098j4a2e2e3ec18d268a@mail.gmail.com> Message-ID: <223f97700708010222s20e7e3ddje1f377b4433d2364@mail.gmail.com> On 01/08/07, Glenn Steen wrote: > On 31/07/07, UxBoD wrote: > > Are okay :) Will add to the wiki tomorrow then to safe if running as non-root then set permissions accordingly. > > > > Regards, > > > What exact provisions is needed for postfix use? Should this be > interfoliated in Mikes original steps or a separate note? > How about more generic installs... Source or otherwise? > As soon as Phil is done editing for "non-root execution", I'll add some notes on how to get this working (with Mikes step-by-step) on a Mandriva -07.1 ... So far all that need amending is step #1 ... urpmi libtre4 libtre4-devel ...:-). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Wed Aug 1 10:26:34 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 1 10:26:36 2007 Subject: ERROR:: Malformed database In-Reply-To: <20070731232517.A8E591040001@www1.sscrmnl.edu.ph> References: <20070731232517.A8E591040001@www1.sscrmnl.edu.ph> Message-ID: <223f97700708010226u751ab978q21267e7c61feebbe@mail.gmail.com> On 01/08/07, Jose Nathaniel G. Nengasca wrote: > Hi, > > How would I fix this kind of problem, ERROR:: Malformed database? I just > upgraded to the newest version. Thanks > > TIA > Not knowing more... Did you get this in the logs? What was the complete line, and some lines around it? Without knowing more, I'd guess this to be the SA cache (SQLite) DB being corrupted somehow... Just remove it and restart MS and you should be fine. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From uxbod at splatnix.net Wed Aug 1 10:34:10 2007 From: uxbod at splatnix.net (UxBoD) Date: Wed Aug 1 10:32:09 2007 Subject: CRM114 Installation on Centos 4 In-Reply-To: <223f97700708010156l3d6a8098j4a2e2e3ec18d268a@mail.gmail.com> Message-ID: <17029010.8901185960850150.JavaMail.root@office.splatnix.net> Added a note for Postfix and permissions. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ms-list at alexb.ch Wed Aug 1 10:33:26 2007 From: ms-list at alexb.ch (Alex Broens) Date: Wed Aug 1 10:33:35 2007 Subject: CRM114 Installation on Centos 4 In-Reply-To: <223f97700708010154l76b9bccbsa17b372a5df2a5a0@mail.gmail.com> References: <8819172.8481185914183040.JavaMail.root@office.splatnix.net> <46AFA5C8.30100@alexb.ch> <223f97700708010154l76b9bccbsa17b372a5df2a5a0@mail.gmail.com> Message-ID: <46B05366.4030803@alexb.ch> On 8/1/2007 10:54 AM, Glenn Steen wrote: > On 31/07/07, Alex Broens wrote: >> Note for Wiki unless someone has a better answer/idea/suggestion: >> >> Apparently there's no provision to limit the size of >> >> /etc/mail/spamassassin/crm114/reaver_cache's contents. >> >> Running on a *very* low traffic test box, the directory has grown to >> 59MB in less than 24 hrs. >> >> If you do *not* intend to perform manual re-training to correct ham >> /spam detection, it may be wise to set: >> >> /etc/mail/spamassassin/crm114/mailfilter.cf >> >> :text_cache: /reaver_cache/ >> >> to >> >> :text_cache: // >> >> This will disable msg caching of all your mail traffic >> (keeping a copy of all ham/spam could also be against corp. policy) >> >> Disabling "reaver_cache" may speed up CRM114 processing by avoiding the >> extra msg write operations to "reaver_cache" categories. >> >> Alex >> > Added a slightly modified version of this text... Just modified to > more easily work with the wiki syntax. while your at it could you link the CRM114 dox to * Add Ons - Add on more functionality to your MailScanner. http://wiki.mailscanner.info/doku.php?id=add_on For the noob, stuff is sort of hidden in the Wiki Depth. Thanks Alex From garry at glendown.de Wed Aug 1 10:48:47 2007 From: garry at glendown.de (Garry Glendown) Date: Wed Aug 1 10:49:22 2007 Subject: CRM114 - two questions ... In-Reply-To: <8072804.8571185954941250.JavaMail.root@office.splatnix.net> References: <8072804.8571185954941250.JavaMail.root@office.splatnix.net> Message-ID: <46B056FF.6010705@glendown.de> UxBoD wrote: > Run the same command as what is in your crm114.cf. That will allow it to learn then. You can feed old messages in, but ensure the headers are intact. ... which would be the mailreaver.crm script instead ... did some tests with the "-t" option set, both seem to work ... When I feed it old mails - should I grep -v the MailScanner headers and possibly also 'sed'-out the {Spam*} addition to the Subject line? Tnx, -garry From uxbod at splatnix.net Wed Aug 1 09:57:25 2007 From: uxbod at splatnix.net (UxBoD) Date: Wed Aug 1 11:12:57 2007 Subject: CRM114 Installation on Centos 4 In-Reply-To: <223f97700708010137x7247cffax3bab65f1a95088a8@mail.gmail.com> Message-ID: <7247337.8661185958645314.JavaMail.root@office.splatnix.net> Darn, you have the page locked Glenn ;) Was going to add the short description about CRM14 and the URL to the sourceforge site. Its looking good :) Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From glenn.steen at gmail.com Wed Aug 1 11:18:45 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 1 11:18:50 2007 Subject: CRM114 Installation on Centos 4 In-Reply-To: <46B05366.4030803@alexb.ch> References: <8819172.8481185914183040.JavaMail.root@office.splatnix.net> <46AFA5C8.30100@alexb.ch> <223f97700708010154l76b9bccbsa17b372a5df2a5a0@mail.gmail.com> <46B05366.4030803@alexb.ch> Message-ID: <223f97700708010318o36f5403dqb88a742d8fbdcf01@mail.gmail.com> On 01/08/07, Alex Broens wrote: > On 8/1/2007 10:54 AM, Glenn Steen wrote: > > On 31/07/07, Alex Broens wrote: > >> Note for Wiki unless someone has a better answer/idea/suggestion: > >> > >> Apparently there's no provision to limit the size of > >> > >> /etc/mail/spamassassin/crm114/reaver_cache's contents. > >> > >> Running on a *very* low traffic test box, the directory has grown to > >> 59MB in less than 24 hrs. > >> > >> If you do *not* intend to perform manual re-training to correct ham > >> /spam detection, it may be wise to set: > >> > >> /etc/mail/spamassassin/crm114/mailfilter.cf > >> > >> :text_cache: /reaver_cache/ > >> > >> to > >> > >> :text_cache: // > >> > >> This will disable msg caching of all your mail traffic > >> (keeping a copy of all ham/spam could also be against corp. policy) > >> > >> Disabling "reaver_cache" may speed up CRM114 processing by avoiding the > >> extra msg write operations to "reaver_cache" categories. > >> > >> Alex > >> > > Added a slightly modified version of this text... Just modified to > > more easily work with the wiki syntax. > while your at it > > could you link the CRM114 dox to > > * Add Ons - Add on more functionality to your MailScanner. > http://wiki.mailscanner.info/doku.php?id=add_on > > For the noob, stuff is sort of hidden in the Wiki Depth. > > Thanks > > Alex > I'm not a big fan of the Add-Ons thingie, but .. sure, I'll put a link there... Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From MailScanner at ecs.soton.ac.uk Wed Aug 1 11:19:09 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 1 11:19:40 2007 Subject: ERROR:: Malformed database In-Reply-To: <20070731232517.A8E591040001@www1.sscrmnl.edu.ph> References: <20070731232517.A8E591040001@www1.sscrmnl.edu.ph> Message-ID: <46B05E1D.8050601@ecs.soton.ac.uk> That looks like an error from ClamAV. Wipe your clamav signatures database and re-run freshclam. Jose Nathaniel G. Nengasca wrote: > Hi, > > How would I fix this kind of problem, ERROR:: Malformed database? I just > upgraded to the newest version. Thanks > > TIA > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Wed Aug 1 11:19:57 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 1 11:20:09 2007 Subject: Subject Text Not Getting Modified? In-Reply-To: <46AFE896.1090708@openenterprise.ca> References: <46AFE896.1090708@openenterprise.ca> Message-ID: <46B05E4D.40102@ecs.soton.ac.uk> The version in the quarantine won't be modified. It intentionally quarantines it in exactly the form it arrived. Johnny Stork wrote: > I have noticed that none of the detected spam, including high scoring > spam which gets quarantined, are getting the subject lines modified? > I have almost all the Modify Subject settings enable in > mailscanner.conf, but nothing seems to be getting re-written. For > instance, below is the phishing section of mailscanner.conf, followed > by an incoming message. When I checked the message in mailwatch, the > subject is the same/unchanged? > > Any ideas? > > *Phishing Section of mailscanner.conf:* > > Phishing Modify Subject = yes > # This is the text to add to the start of the subject if the "Phishing > # Modify Subhect" option is set. > # This can also be the filename of a ruleset. > Phishing Subject Text = {Phishing Fraud} > > > *Maillog of incoming message that triggered phishing fraud:* > > Jul 31 18:43:18 gateway MailScanner[11052]: Virus and Content > Scanning: Starting > Jul 31 18:43:18 gateway MailScanner[11052]: tag found in message > l711h3YO017623 from me@here.ca > Jul 31 18:43:18 gateway MailScanner[11052]: Virus Scanning completed > at 95858 bytes per second > Jul 31 18:43:18 gateway MailScanner[11052]: Found phishing fraud from > www.w3.org claiming to be www."http: in l711h3YO017623 > Jul 31 18:43:18 gateway MailScanner[11052]: Content Checks: Detected > and have disarmed phishing tags in HTML message in l711h3YO017623 from > me@here.ca > > > > > -- > *Johnny Stork* > Business & Technology Consultant > stork@openenterprise.ca > > > -- > This message has been scanned for viruses and > dangerous content by *MailScanner* , and is > believed to be clean. Check out *Open Enterprise > Solutions * for your own powerful > open-source > Virus/Spam/Content detection solutions and mail gateway. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Wed Aug 1 11:20:30 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 1 11:20:40 2007 Subject: Random messages stuck in mqueue In-Reply-To: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> References: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> Message-ID: <46B05E6E.90009@ecs.soton.ac.uk> What is your "Delivery Method =" set to in MailScanner.conf? Corey McFadden wrote: > > Guys, > > We're experiencing an issue on one of our boxes where messages (a good > percentage) are hung in /var/spool/mqueue after being processed by > MailScanner. Even those to be delivered locally will sit for > (sometimes) hours until they're finally delivered. > > I've never seen this behavior before and something is definitely awry. > > Here's the environment: > > This is CentOS release 4.5 (Final) > This is Perl version 5.008008 (5.8.8) > > This is MailScanner version 4.61.7 > > Executing 'sendmail -q -v' WILL process the stuck messages but can > take quite a long time to run because it will try to deliver > everything queued in a linear fashion. > > Here's a good example of a message hung for more than 10 minutes: > > [root@ewrgga-hst01 mqueue]# cat qfl714YqCD027817 > V8 > T1185942893 > K0 > N0 > P32072 > Fbs > > HX-x-MailScanner-SpamCheck: spam, SpamAssassin (not cached, > score=46.69, required 6, autolearn=spam, BAYES_99 3.50, > FH_HOST_ALMOST_IP 1.75, FH_MSGID_01C67 0.00, FM_RATSIGN_1106 3.80, > FRT_OFFER2 1.29, FRT_PRICE 3.49, FUZZY_OFFERS 1.25, > FUZZY_SOFTWARE 3.47, HELO_LOCALHOST 3.94, OUTLOOK_3416 1.74, > RAZOR2_CF_RANGE_51_100 0.50, RAZOR2_CF_RANGE_E4_51_100 1.50, > RAZOR2_CF_RANGE_E8_51_100 1.50, RAZOR2_CHECK 0.50, > RCVD_IN_BL_SPAMCOP_NET 1.96, RCVD_IN_CBLABUSE 0.25, > RCVD_IN_PBL 0.91, > RCVD_IN_SORBS_DUL 0.88, RCVD_IN_XBL 3.03, RDNS_DYNAMIC 0.10, > URIBL_AB_SURBL 1.86, URIBL_BLACK 3.00, URIBL_JP_SURBL 1.50, > URIBL_OB_SURBL 1.50, URIBL_SBL 1.50, URIBL_SC_SURBL 0.47, > URIBL_WS_SURBL 1.50) > HX-x-MailScanner-SpamScore: 46.69 > HX-x-MailScanner-From: > RP: > . > > Analyzing: > T1185942893 = Wed Aug 1 00:34:53 2007 > Current time: Wed Aug 1 00:44:02 EDT 2007 > > > This is pretty typical of the messages hung. In this case it's > waiting to be delivered to a local "spamtrap" mailbox. > > Can anyone offer me any ideas to troubleshoot this? I've not been too > successful hunting so far today. > > Thanks in advance! > -Corey > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From glenn.steen at gmail.com Wed Aug 1 11:21:32 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 1 11:21:38 2007 Subject: CRM114 Installation on Centos 4 In-Reply-To: <223f97700708010318o36f5403dqb88a742d8fbdcf01@mail.gmail.com> References: <8819172.8481185914183040.JavaMail.root@office.splatnix.net> <46AFA5C8.30100@alexb.ch> <223f97700708010154l76b9bccbsa17b372a5df2a5a0@mail.gmail.com> <46B05366.4030803@alexb.ch> <223f97700708010318o36f5403dqb88a742d8fbdcf01@mail.gmail.com> Message-ID: <223f97700708010321n64eca949jae414d8a029f2742@mail.gmail.com> On 01/08/07, Glenn Steen wrote: > On 01/08/07, Alex Broens wrote: (snip) > > while your at it > > > > could you link the CRM114 dox to > > > > * Add Ons - Add on more functionality to your MailScanner. > > http://wiki.mailscanner.info/doku.php?id=add_on > > > > For the noob, stuff is sort of hidden in the Wiki Depth. > > > > Thanks > > > > Alex > > > I'm not a big fan of the Add-Ons thingie, but .. sure, I'll put a link there... > On second thoughts... I won't:-) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From ms-list at alexb.ch Wed Aug 1 11:31:01 2007 From: ms-list at alexb.ch (Alex Broens) Date: Wed Aug 1 11:31:12 2007 Subject: CRM114 Installation on Centos 4 In-Reply-To: <223f97700708010318o36f5403dqb88a742d8fbdcf01@mail.gmail.com> References: <8819172.8481185914183040.JavaMail.root@office.splatnix.net> <46AFA5C8.30100@alexb.ch> <223f97700708010154l76b9bccbsa17b372a5df2a5a0@mail.gmail.com> <46B05366.4030803@alexb.ch> <223f97700708010318o36f5403dqb88a742d8fbdcf01@mail.gmail.com> Message-ID: <46B060E5.8070205@alexb.ch> On 8/1/2007 12:18 PM, Glenn Steen wrote: > On 01/08/07, Alex Broens wrote: >> On 8/1/2007 10:54 AM, Glenn Steen wrote: >>> On 31/07/07, Alex Broens wrote: >>>> Note for Wiki unless someone has a better answer/idea/suggestion: >>>> >>>> Apparently there's no provision to limit the size of >>>> >>>> /etc/mail/spamassassin/crm114/reaver_cache's contents. >>>> >>>> Running on a *very* low traffic test box, the directory has grown to >>>> 59MB in less than 24 hrs. >>>> >>>> If you do *not* intend to perform manual re-training to correct ham >>>> /spam detection, it may be wise to set: >>>> >>>> /etc/mail/spamassassin/crm114/mailfilter.cf >>>> >>>> :text_cache: /reaver_cache/ >>>> >>>> to >>>> >>>> :text_cache: // >>>> >>>> This will disable msg caching of all your mail traffic >>>> (keeping a copy of all ham/spam could also be against corp. policy) >>>> >>>> Disabling "reaver_cache" may speed up CRM114 processing by avoiding the >>>> extra msg write operations to "reaver_cache" categories. >>>> >>>> Alex >>>> >>> Added a slightly modified version of this text... Just modified to >>> more easily work with the wiki syntax. >> while your at it >> >> could you link the CRM114 dox to >> >> * Add Ons - Add on more functionality to your MailScanner. >> http://wiki.mailscanner.info/doku.php?id=add_on >> >> For the noob, stuff is sort of hidden in the Wiki Depth. >> >> Thanks >> >> Alex >> > I'm not a big fan of the Add-Ons thingie, but .. sure, I'll put a link there... :-) thx I just did a CENTOS 4.5 i386 CRM114 setup from .rpm & working nicely. If someone wants to host them, just yell offlist. (maybe dump in the wiki?) crm114-0-0.4.20070301.i386.rpm tre-0.7.5-1.i386.rpm tre-devel-0.7.5-1.i386.rpm aprox 360k Alex From maillists at conactive.com Wed Aug 1 11:31:18 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Wed Aug 1 11:31:22 2007 Subject: Random messages stuck in mqueue In-Reply-To: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> References: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> Message-ID: Corey McFadden wrote on Wed, 1 Aug 2007 00:46:05 -0400: > We're experiencing an issue on one of our boxes where messages (a good percentage) are hung in /var/spool/mqueue after being processed by MailScanner. And your load is low? Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From uxbod at splatnix.net Wed Aug 1 11:05:50 2007 From: uxbod at splatnix.net (UxBoD) Date: Wed Aug 1 12:55:16 2007 Subject: CRM114 - two questions ... In-Reply-To: <46B056FF.6010705@glendown.de> Message-ID: <5153043.8961185962750688.JavaMail.root@office.splatnix.net> According to the CRM documentation no additional headers should be in the message ie. vanilla as received. So IMHO I would strip the MS headers and any additional tags. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From uxbod at splatnix.net Wed Aug 1 10:03:18 2007 From: uxbod at splatnix.net (UxBoD) Date: Wed Aug 1 13:08:57 2007 Subject: CRM114 installation on Debian Etch In-Reply-To: <74ACEB3E6A055643A89B8CEC74C7BF2488E0FB@WISENT.dcyb.net> Message-ID: <15256576.8691185958998685.JavaMail.root@office.splatnix.net> Update the Wiki ? Once I get back home at the weekend I will do the Gentoo install. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From glenn.steen at gmail.com Wed Aug 1 13:17:57 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 1 13:17:59 2007 Subject: CRM114 installation on Debian Etch In-Reply-To: <74ACEB3E6A055643A89B8CEC74C7BF2488E0FB@WISENT.dcyb.net> References: <74ACEB3E6A055643A89B8CEC74C7BF2488E0FB@WISENT.dcyb.net> Message-ID: <223f97700708010517h3af4eb55r1bac3b0009d3f366@mail.gmail.com> On 01/08/07, Rob Sterenborg wrote: > Hi, > > I stole the installation procedure from CentOS and adapted it to work > with Debian Etch. IMHO apt-get is a nice package management system but > Debian often suffers from old packages residing in the repository, so I > decided to build a new package for crm114 from Debian source. > > The procedure is largely the same as for CentOS; differences are the > creation of the package and the location of some files. If anyone is > interested I can post it. > > > Grts, > Rob Please put it in the wiki at http://wiki.mailscanner.info/doku.php?id=documentation:anti_spam:spamassassin:plugins:crm114 (watch out for linewraps!)... TiA -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From Q.G.Campbell at newcastle.ac.uk Wed Aug 1 13:35:34 2007 From: Q.G.Campbell at newcastle.ac.uk (Quentin Campbell) Date: Wed Aug 1 13:35:50 2007 Subject: 4.62.9-1 & MailScanner --lint Message-ID: <4165CF7A7F12DE4B96622CCBB90586470B1257FE@largo.campus.ncl.ac.uk> I checked my 4.62.9-1 installation with 'MailScanner --lint' and got the "LibClamAV Warning: *** The virus database is older than 7 days. ***" message that I complained about when debugging the beta versions of 4.62 in July. Below is the scripted output. I am running with ClamAV 0.91.1/3846/Wed Aug 1 08:27:07 2007 on a RedHat AS/4 system and SpamAssassin 3.2.2. [root@cheviot4 tmp]# script Script started, file is typescript [root@cheviot4 tmp]# date Wed Aug 1 13:26:56 BST 2007 [root@cheviot4 tmp]# MailScanner --lint Checking version numbers... Version number in MailScanner.conf (4.62.9) is correct. Your envelope_sender_header in spam.assassin.prefs.conf is correct. Checking for SpamAssassin errors (if you use it)... SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp SpamAssassin reported no errors. LibClamAV Warning: ************************************************** LibClamAV Warning: *** The virus database is older than 7 days. *** LibClamAV Warning: *** Please update it IMMEDIATELY! *** LibClamAV Warning: ************************************************** MailScanner.conf says "Virus Scanners = clamavmodule mcafee" Found these virus scanners installed: clamavmodule, mcafee =========================================================================== Ignore errors about failing to find EOCD signature =========================================================================== Virus Scanner test reports: ClamAV Module said "eicar.com was infected: Eicar-Test-Signature" McAfee said "/1/eicar.com Found: EICAR test file NOT a virus." If any of your virus scanners (clamavmodule,mcafee) are not listed there, you should check that they are installed correctly and that MailScanner is finding them correctly via its virus.scanners.conf. [root@cheviot4 tmp]# ls -ld /usr/local/clamav drwxr-xr-x 4 clamav clamav 4096 Aug 1 13:09 /usr/local/clamav [root@cheviot4 tmp]# ls -l /usr/local/clamav total 8 drwxr-xr-x 2 clamav clamav 4096 Aug 1 11:09 daily.inc drwxr-xr-x 2 clamav clamav 4096 Jul 20 18:07 main.inc [root@cheviot4 tmp]# exit Script done, file is typescript [root@cheviot4 tmp]# I would like to get to the bottom of this problem. Any help welcomed. Quentin --- PHONE: +44 191 222 8209??? Information Systems and Services (ISS), ?????????????????????????? Newcastle University, ?????????????????????????? Newcastle upon Tyne, FAX:?? +44 191 222 8765??? United Kingdom, NE1 7RU. ------------------------------------------------------------------------ From R.Sterenborg at netsourcing.nl Wed Aug 1 13:54:16 2007 From: R.Sterenborg at netsourcing.nl (Rob Sterenborg) Date: Wed Aug 1 13:55:56 2007 Subject: CRM114 installation on Debian Etch In-Reply-To: <223f97700708010517h3af4eb55r1bac3b0009d3f366@mail.gmail.com> References: <74ACEB3E6A055643A89B8CEC74C7BF2488E0FB@WISENT.dcyb.net> <223f97700708010517h3af4eb55r1bac3b0009d3f366@mail.gmail.com> Message-ID: <74ACEB3E6A055643A89B8CEC74C7BF2488E0FE@WISENT.dcyb.net> >> I stole the installation procedure from CentOS and adapted it to work >> with Debian Etch. IMHO apt-get is a nice package management system >> but Debian often suffers from old packages residing in the >> repository, so I decided to build a new package for crm114 from >> Debian source. >> >> The procedure is largely the same as for CentOS; differences are the >> creation of the package and the location of some files. If anyone is >> interested I can post it. >> >> >> Grts, >> Rob > Please put it in the wiki at > http://wiki.mailscanner.info/doku.php?id=documentation:anti_sp > am:spamassassin:plugins:crm114 (watch out for linewraps!)... TiA It's there. Grts, Rob From asakawa at quickd.net Wed Aug 1 14:17:27 2007 From: asakawa at quickd.net (Takashi Asakawa) Date: Wed Aug 1 14:18:16 2007 Subject: MailScanner ANNOUNCE: Version 4.62.9 released In-Reply-To: <46AFA330.7010206@ecs.soton.ac.uk> References: <46AFA330.7010206@ecs.soton.ac.uk> Message-ID: <20070801221414.B3EB.ASAKAWA@quickd.net> hi all what's problem Ignore errors about failing to find EOCD signature format error: can't find EOCD signature [root@ns ~]# MailScanner --lint Checking version numbers... Version number in MailScanner.conf (4.62.9) is correct. ERROR: The "envelope_sender_header" in your spam.assassin.prefs.conf ERROR: is not correct, it should match X--MailScanner-From Checking for SpamAssassin errors (if you use it)... SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp SpamAssassin reported no errors. MailScanner.conf says "Virus Scanners = antivir bitdefender f-prot avg f-secure clamav" Found these virus scanners installed: bitdefender, f-prot, clamav, f-secure, avg, antivir =========================================================================== Ignore errors about failing to find EOCD signature format error: can't find EOCD signature at /usr/sbin/MailScanner line 450 /usr/lib/MailScanner/f-secure-wrapper: line 86: /opt/f-secure//fsav: is a directory /usr/lib/MailScanner/f-secure-wrapper: line 86: exec: /opt/f-secure//fsav: cannot execute: ???????? =========================================================================== Virus Scanner test reports: AntiVir said "ALERT: [Eicar-Test-Signature] ./1/eicar.com <<< Contains code of the Eicar-Test-Signature virus" Bitdefender said "Found virus EICAR-Test-File (not a virus) in file eicar.com" F-Prot said "./1/eicar.com Infection: EICAR_Test_File" Avg said "Found virus EICAR_Test in file eicar.com" ClamAV said "eicar.com contains Eicar-Test-Signature" If any of your virus scanners (bitdefender,f-prot,clamav,f-secure,avg,antivir) are not listed there, you should check that they are installed correctly and that MailScanner is finding them correctly via its virus.scanners.conf. From am.lists at gmail.com Wed Aug 1 14:21:24 2007 From: am.lists at gmail.com (am.lists) Date: Wed Aug 1 14:21:28 2007 Subject: Help with large message / blacklists bypassed Message-ID: <25a66d840708010621j7be4a559s8ffa1ec67c74e9f@mail.gmail.com> OK. I admit that I may be in panic mode and not thinking this thorugh as completley as I would otherwise. Standard support disclosure; Linux + Postfix 2.2.2+ MailScanner 4.58.9 (<-- I know, slacker), ClamAV (0.90.3). One of my users is the recipient on an email message that is apparently stuck in the sending MTA's outbound queue. For whatever reason, their MTA has shipped me over 3000 copies of the identical piece of mail. Problem on my side is that it's a 670KB message (has a lot of images attached) and I seem to be ineffective at blocking it and this guy's mailbox keeps getting clogged up. Not to mention how this guy feels each time his Outlook client goes out and tries to fetch 10 copies of a 670KB message. He's getting no work done, essentially. My process: (1) I didn't want to block everything from this particular sender -- it's not his fault, obviously, so I looked for a unique string within the message and created a custom SA rule (50 points) to kick it into definite spam. I'd really like to strangle the mail admin on the otherside, but I can't quite reach him from here. :-) Result: Message too large (I hadn't noticed that detail before) so it skips it with the spam report saying simply "too large" (2) Blacklist by sender -- added to MailScanner/MailWatch via the black/white page. The sender and recipient are fully stated. Result: No Effect. ??? I'm confounded by this. I thought blacks/whites were still checked here. (3) Added the sender name to my spam.blacklists.rules file, relevant lines below: # spam.blacklists.rules file # edited@edited.org problem From: edited@edited.org yes # Never set this to yes. FromOrTo: default no Result: Still no effect. Messages, all 100 or so of them this morning, are coming thorugh just fine. Where to look / what to do next on this? Thanks, Angelo From ms-list at alexb.ch Wed Aug 1 14:46:06 2007 From: ms-list at alexb.ch (Alex Broens) Date: Wed Aug 1 14:46:14 2007 Subject: Help with large message / blacklists bypassed In-Reply-To: <25a66d840708010621j7be4a559s8ffa1ec67c74e9f@mail.gmail.com> References: <25a66d840708010621j7be4a559s8ffa1ec67c74e9f@mail.gmail.com> Message-ID: <46B08E9E.6020008@alexb.ch> On 8/1/2007 3:21 PM, am.lists wrote: > OK. I admit that I may be in panic mode and not thinking this thorugh > as completley as I would otherwise. > > Standard support disclosure; Linux + Postfix 2.2.2+ MailScanner 4.58.9 > (<-- I know, slacker), ClamAV (0.90.3). > > One of my users is the recipient on an email message that is > apparently stuck in the sending MTA's outbound queue. For whatever > reason, their MTA has shipped me over 3000 copies of the identical > piece of mail. I'd block the sender with a Postfix header rule. Alex From mkercher at nfsmith.com Wed Aug 1 14:50:27 2007 From: mkercher at nfsmith.com (Mike Kercher) Date: Wed Aug 1 14:50:30 2007 Subject: Help with large message / blacklists bypassed In-Reply-To: <25a66d840708010621j7be4a559s8ffa1ec67c74e9f@mail.gmail.com> References: <25a66d840708010621j7be4a559s8ffa1ec67c74e9f@mail.gmail.com> Message-ID: <441247027D4F274EB760A5F6E1ED9C7E020EA3@houpex02.nfsmith.info> -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of am.lists Sent: Wednesday, August 01, 2007 8:21 AM To: MailScanner discussion Subject: Help with large message / blacklists bypassed OK. I admit that I may be in panic mode and not thinking this thorugh as completley as I would otherwise. Standard support disclosure; Linux + Postfix 2.2.2+ MailScanner 4.58.9 (<-- I know, slacker), ClamAV (0.90.3). One of my users is the recipient on an email message that is apparently stuck in the sending MTA's outbound queue. For whatever reason, their MTA has shipped me over 3000 copies of the identical piece of mail. Problem on my side is that it's a 670KB message (has a lot of images attached) and I seem to be ineffective at blocking it and this guy's mailbox keeps getting clogged up. Not to mention how this guy feels each time his Outlook client goes out and tries to fetch 10 copies of a 670KB message. He's getting no work done, essentially. My process: (1) I didn't want to block everything from this particular sender -- it's not his fault, obviously, so I looked for a unique string within the message and created a custom SA rule (50 points) to kick it into definite spam. I'd really like to strangle the mail admin on the otherside, but I can't quite reach him from here. :-) Result: Message too large (I hadn't noticed that detail before) so it skips it with the spam report saying simply "too large" (2) Blacklist by sender -- added to MailScanner/MailWatch via the black/white page. The sender and recipient are fully stated. Result: No Effect. ??? I'm confounded by this. I thought blacks/whites were still checked here. (3) Added the sender name to my spam.blacklists.rules file, relevant lines below: # spam.blacklists.rules file # edited@edited.org problem From: edited@edited.org yes # Never set this to yes. FromOrTo: default no Result: Still no effect. Messages, all 100 or so of them this morning, are coming thorugh just fine. Where to look / what to do next on this? Thanks, Angelo -- I've had this happen a few times over the past several years. You will probably notice that the SMTP ID of the offending email is the same...it just gets processed over and over again. I usually just go into the queue and delete the df/qf pair and it takes off again. It happens so rarely that I don't worry about fixing it. Mike From glenn.steen at gmail.com Wed Aug 1 14:51:15 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 1 14:51:17 2007 Subject: Help with large message / blacklists bypassed In-Reply-To: <25a66d840708010621j7be4a559s8ffa1ec67c74e9f@mail.gmail.com> References: <25a66d840708010621j7be4a559s8ffa1ec67c74e9f@mail.gmail.com> Message-ID: <223f97700708010651u172974bfs21ba3e0896059307@mail.gmail.com> On 01/08/07, am.lists wrote: > OK. I admit that I may be in panic mode and not thinking this thorugh > as completley as I would otherwise. > > Standard support disclosure; Linux + Postfix 2.2.2+ MailScanner 4.58.9 > (<-- I know, slacker), ClamAV (0.90.3). > > One of my users is the recipient on an email message that is > apparently stuck in the sending MTA's outbound queue. For whatever > reason, their MTA has shipped me over 3000 copies of the identical > piece of mail. > > Problem on my side is that it's a 670KB message (has a lot of images > attached) and I seem to be ineffective at blocking it and this guy's > mailbox keeps getting clogged up. Not to mention how this guy feels > each time his Outlook client goes out and tries to fetch 10 copies of > a 670KB message. He's getting no work done, essentially. > > My process: > > (1) I didn't want to block everything from this particular sender -- > it's not his fault, obviously, so I looked for a unique string within > the message and created a custom SA rule (50 points) to kick it into > definite spam. I'd really like to strangle the mail admin on the > otherside, but I can't quite reach him from here. :-) > > Result: Message too large (I hadn't noticed that detail before) so it > skips it with the spam report saying simply "too large" (A sort of ...) Solution: Up your Scan and SPamAssassin Size limits in MailScanner.conf ... Don't forget to restart/reload MS to take effect. > (2) Blacklist by sender -- added to MailScanner/MailWatch via the > black/white page. The sender and recipient are fully stated. > > Result: No Effect. ??? I'm confounded by this. I thought blacks/whites > were still checked here. > > (3) Added the sender name to my spam.blacklists.rules file, relevant > lines below: > > # spam.blacklists.rules file > # edited@edited.org problem > From: edited@edited.org yes > # Never set this to yes. > FromOrTo: default no > > Result: Still no effect. Messages, all 100 or so of them this > morning, are coming thorugh just fine. > And you did remember to restart MailScanner after those changes? That will affect the MW SQL B/W-list too, sort of;-). > Where to look / what to do next on this? > > Thanks, > Angelo Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Wed Aug 1 14:54:31 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 1 14:54:36 2007 Subject: CRM114 installation on Debian Etch In-Reply-To: <74ACEB3E6A055643A89B8CEC74C7BF2488E0FE@WISENT.dcyb.net> References: <74ACEB3E6A055643A89B8CEC74C7BF2488E0FB@WISENT.dcyb.net> <223f97700708010517h3af4eb55r1bac3b0009d3f366@mail.gmail.com> <74ACEB3E6A055643A89B8CEC74C7BF2488E0FE@WISENT.dcyb.net> Message-ID: <223f97700708010654o6f02c304w11117919ca0551aa@mail.gmail.com> On 01/08/07, Rob Sterenborg wrote: > >> I stole the installation procedure from CentOS and adapted it to work > >> with Debian Etch. IMHO apt-get is a nice package management system > >> but Debian often suffers from old packages residing in the > >> repository, so I decided to build a new package for crm114 from > >> Debian source. > >> > >> The procedure is largely the same as for CentOS; differences are the > >> creation of the package and the location of some files. If anyone is > >> interested I can post it. > >> > >> > >> Grts, > >> Rob > > Please put it in the wiki at > > http://wiki.mailscanner.info/doku.php?id=documentation:anti_sp > > am:spamassassin:plugins:crm114 (watch out for linewraps!)... TiA > > It's there. > > > Grts, > Rob I took the liberty of changing the layout a teensy bit (no loss of information!), as well as the usual %%--%% thing needed to avoid -- becoming a "big hyphen". Sigh. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From MailScanner at ecs.soton.ac.uk Wed Aug 1 15:07:55 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 1 15:08:06 2007 Subject: 4.62.9-1 & MailScanner --lint In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470B1257FE@largo.campus.ncl.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470B1257FE@largo.campus.ncl.ac.uk> Message-ID: <46B093BB.8050508@ecs.soton.ac.uk> What does grep -i clam /etc/MailScanner/virus.scanners.conf say? Quentin Campbell wrote: > I checked my 4.62.9-1 installation with 'MailScanner --lint' and got the "LibClamAV Warning: *** The virus database is older than 7 days. ***" message that I complained about when debugging the beta versions of 4.62 in July. > > Below is the scripted output. I am running with ClamAV 0.91.1/3846/Wed Aug 1 08:27:07 2007 on a RedHat AS/4 system and SpamAssassin 3.2.2. > > [root@cheviot4 tmp]# script > Script started, file is typescript > [root@cheviot4 tmp]# date > Wed Aug 1 13:26:56 BST 2007 > [root@cheviot4 tmp]# MailScanner --lint > Checking version numbers... > Version number in MailScanner.conf (4.62.9) is correct. > > Your envelope_sender_header in spam.assassin.prefs.conf is correct. > > Checking for SpamAssassin errors (if you use it)... > SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp > SpamAssassin reported no errors. > LibClamAV Warning: ************************************************** > LibClamAV Warning: *** The virus database is older than 7 days. *** > LibClamAV Warning: *** Please update it IMMEDIATELY! *** > LibClamAV Warning: ************************************************** > MailScanner.conf says "Virus Scanners = clamavmodule mcafee" > Found these virus scanners installed: clamavmodule, mcafee > =========================================================================== > Ignore errors about failing to find EOCD signature > =========================================================================== > Virus Scanner test reports: > ClamAV Module said "eicar.com was infected: Eicar-Test-Signature" > McAfee said "/1/eicar.com Found: EICAR test file NOT a virus." > > If any of your virus scanners (clamavmodule,mcafee) > are not listed there, you should check that they are installed correctly > and that MailScanner is finding them correctly via its virus.scanners.conf. > [root@cheviot4 tmp]# ls -ld /usr/local/clamav > drwxr-xr-x 4 clamav clamav 4096 Aug 1 13:09 /usr/local/clamav > [root@cheviot4 tmp]# ls -l /usr/local/clamav > total 8 > drwxr-xr-x 2 clamav clamav 4096 Aug 1 11:09 daily.inc > drwxr-xr-x 2 clamav clamav 4096 Jul 20 18:07 main.inc > [root@cheviot4 tmp]# exit > Script done, file is typescript > [root@cheviot4 tmp]# > > I would like to get to the bottom of this problem. Any help welcomed. > > Quentin > --- > PHONE: +44 191 222 8209 Information Systems and Services (ISS), > Newcastle University, > Newcastle upon Tyne, > FAX: +44 191 222 8765 United Kingdom, NE1 7RU. > ------------------------------------------------------------------------ > > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Wed Aug 1 15:09:29 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 1 15:09:38 2007 Subject: MailScanner ANNOUNCE: Version 4.62.9 released In-Reply-To: <20070801221414.B3EB.ASAKAWA@quickd.net> References: <46AFA330.7010206@ecs.soton.ac.uk> <20070801221414.B3EB.ASAKAWA@quickd.net> Message-ID: <46B09419.6000306@ecs.soton.ac.uk> Takashi Asakawa wrote: > hi all > > what's problem >=20=20=20 What problem? > Ignore errors about failing to find EOCD signature >=20=20=20 Have you not read this line? > format error: can't find EOCD signature=20 >=20=20=20 You should ignore this, as it says in the previous line. > > [root@ns ~]# MailScanner --lint > Checking version numbers... > Version number in MailScanner.conf (4.62.9) is correct. > > ERROR: The "envelope_sender_header" in your spam.assassin.prefs.conf > ERROR: is not correct, it should match X--MailScanner-From >=20=20=20 You should fix this, as it says. > > Checking for SpamAssassin errors (if you use it)... > SpamAssassin temp dir =3D /var/spool/MailScanner/incoming/SpamAssassin-Te= mp > SpamAssassin reported no errors. > MailScanner.conf says "Virus Scanners =3D antivir bitdefender f-prot avg = f-secure clamav" > Found these virus scanners installed: bitdefender, f-prot, clamav, f-secu= re, avg, antivir > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D > Ignore errors about failing to find EOCD signature > format error: can't find EOCD signature=20 > at /usr/sbin/MailScanner line 450 > /usr/lib/MailScanner/f-secure-wrapper: line 86: /opt/f-secure//fsav: is a= directory > /usr/lib/MailScanner/f-secure-wrapper: line 86: exec: /opt/f-secure//fsav= : cannot execute: =90=AC=8C=F7=82=C5=82=B7 >=20=20=20 Your /etc/MailScanner/virus.scanners.conf line for f-secure is wrong. > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D > Virus Scanner test reports: > AntiVir said "ALERT: [Eicar-Test-Signature] ./1/eicar.com <<< Contains co= de of the Eicar-Test-Signature virus" > Bitdefender said "Found virus EICAR-Test-File (not a virus) in file eicar= .com" > F-Prot said "./1/eicar.com Infection: EICAR_Test_File" > Avg said "Found virus EICAR_Test in file eicar.com" > ClamAV said "eicar.com contains Eicar-Test-Signature" > > If any of your virus scanners (bitdefender,f-prot,clamav,f-secure,avg,ant= ivir) > are not listed there, you should check that they are installed correctly > and that MailScanner is finding them correctly via its virus.scanners.con= f. > > > >=20=20=20 Jules --=20 Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 --=20 This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From jase at sensis.com Wed Aug 1 15:10:29 2007 From: jase at sensis.com (Desai, Jason) Date: Wed Aug 1 15:10:47 2007 Subject: CRM114 installation on Debian Etch In-Reply-To: <74ACEB3E6A055643A89B8CEC74C7BF2488E0FB@WISENT.dcyb.net> Message-ID: <1951DC816E1A9F469307B05FA183F4389DC9DE@corpatsmail1.corp.sensis.com> > Debian often suffers from old packages residing in the > repository, so I > decided to build a new package for crm114 from Debian source. FYI - You could always use the crm114 package from backports.org instead. Jase From MailScanner at ecs.soton.ac.uk Wed Aug 1 15:12:48 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 1 15:13:07 2007 Subject: Help with large message / blacklists bypassed In-Reply-To: <223f97700708010651u172974bfs21ba3e0896059307@mail.gmail.com> References: <25a66d840708010621j7be4a559s8ffa1ec67c74e9f@mail.gmail.com> <223f97700708010651u172974bfs21ba3e0896059307@mail.gmail.com> Message-ID: <46B094E0.7030408@ecs.soton.ac.uk> Glenn Steen wrote: > On 01/08/07, am.lists wrote: > >> OK. I admit that I may be in panic mode and not thinking this thorugh >> as completley as I would otherwise. >> >> Standard support disclosure; Linux + Postfix 2.2.2+ MailScanner 4.58.9 >> (<-- I know, slacker), ClamAV (0.90.3). >> >> One of my users is the recipient on an email message that is >> apparently stuck in the sending MTA's outbound queue. For whatever >> reason, their MTA has shipped me over 3000 copies of the identical >> piece of mail. >> >> Problem on my side is that it's a 670KB message (has a lot of images >> attached) and I seem to be ineffective at blocking it and this guy's >> mailbox keeps getting clogged up. Not to mention how this guy feels >> each time his Outlook client goes out and tries to fetch 10 copies of >> a 670KB message. He's getting no work done, essentially. >> >> My process: >> >> (1) I didn't want to block everything from this particular sender -- >> it's not his fault, obviously, so I looked for a unique string within >> the message and created a custom SA rule (50 points) to kick it into >> definite spam. I'd really like to strangle the mail admin on the >> otherside, but I can't quite reach him from here. :-) >> >> Result: Message too large (I hadn't noticed that detail before) so it >> skips it with the spam report saying simply "too large" >> > (A sort of ...) Solution: Up your Scan and SPamAssassin Size limits in > MailScanner.conf ... Don't forget to restart/reload MS to take effect. > > >> (2) Blacklist by sender -- added to MailScanner/MailWatch via the >> black/white page. The sender and recipient are fully stated. >> >> Result: No Effect. ??? I'm confounded by this. I thought blacks/whites >> were still checked here. >> >> (3) Added the sender name to my spam.blacklists.rules file, relevant >> lines below: >> >> # spam.blacklists.rules file >> # edited@edited.org problem >> From: edited@edited.org yes >> # Never set this to yes. >> FromOrTo: default no >> >> Result: Still no effect. Messages, all 100 or so of them this >> morning, are coming thorugh just fine. >> >> > And you did remember to restart MailScanner after those changes? That > will affect the MW SQL B/W-list too, sort of;-). > You could create a SpamAssassin rule that will spot this message, then set SpamAssassin Rule Actions = YOUR_NEW_RULE=>delete then 'service MailScanner reload'. > >> Where to look / what to do next on this? >> >> Thanks, >> Angelo >> > > Cheers > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From prandal at herefordshire.gov.uk Wed Aug 1 15:15:17 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Wed Aug 1 15:15:52 2007 Subject: MailScanner ANNOUNCE: Version 4.62.9 released In-Reply-To: <20070801221414.B3EB.ASAKAWA@quickd.net> References: <46AFA330.7010206@ecs.soton.ac.uk> <20070801221414.B3EB.ASAKAWA@quickd.net> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA01510B4D@HC-MBX02.herefordshire.gov.uk> In MailScanner.conf Envelope From Header = X-%org-name%-MailScanner-From: Yours are coming out as "X--MailScanner-From: asakawa@quickd.net" in /etc/mailscanner/spam.assassin.prefs.conf there's a line like: envelope_sender_header X-MailScanner-From Sort out your %org-name% in MailScanner.conf and change it to match or leave it as is (not recommended) and set envelope_sender_header X--MailScanner-From It's used by spamassassin's SPF handling code. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Takashi Asakawa > Sent: 01 August 2007 14:17 > To: MailScanner discussion > Subject: Re: MailScanner ANNOUNCE: Version 4.62.9 released > > hi all > > what's problem > > Ignore errors about failing to find EOCD signature > format error: can't find EOCD signature > > > [root@ns ~]# MailScanner --lint > Checking version numbers... > Version number in MailScanner.conf (4.62.9) is correct. > > ERROR: The "envelope_sender_header" in your spam.assassin.prefs.conf > ERROR: is not correct, it should match X--MailScanner-From > > > Checking for SpamAssassin errors (if you use it)... > SpamAssassin temp dir = > /var/spool/MailScanner/incoming/SpamAssassin-Temp > SpamAssassin reported no errors. > MailScanner.conf says "Virus Scanners = antivir bitdefender > f-prot avg f-secure clamav" > Found these virus scanners installed: bitdefender, f-prot, > clamav, f-secure, avg, antivir > ============================================================== > ============= > Ignore errors about failing to find EOCD signature > format error: can't find EOCD signature > at /usr/sbin/MailScanner line 450 > /usr/lib/MailScanner/f-secure-wrapper: line 86: > /opt/f-secure//fsav: is a directory > /usr/lib/MailScanner/f-secure-wrapper: line 86: exec: > /opt/f-secure//fsav: cannot execute: ???????? > ============================================================== > ============= > Virus Scanner test reports: > AntiVir said "ALERT: [Eicar-Test-Signature] ./1/eicar.com <<< > Contains code of the Eicar-Test-Signature virus" > Bitdefender said "Found virus EICAR-Test-File (not a virus) > in file eicar.com" > F-Prot said "./1/eicar.com Infection: EICAR_Test_File" > Avg said "Found virus EICAR_Test in file eicar.com" > ClamAV said "eicar.com contains Eicar-Test-Signature" > > If any of your virus scanners > (bitdefender,f-prot,clamav,f-secure,avg,antivir) > are not listed there, you should check that they are > installed correctly > and that MailScanner is finding them correctly via its > virus.scanners.conf. > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From maillists at conactive.com Wed Aug 1 15:16:08 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Wed Aug 1 15:16:12 2007 Subject: Help with large message / blacklists bypassed In-Reply-To: <25a66d840708010621j7be4a559s8ffa1ec67c74e9f@mail.gmail.com> References: <25a66d840708010621j7be4a559s8ffa1ec67c74e9f@mail.gmail.com> Message-ID: Am.lists wrote on Wed, 1 Aug 2007 09:21:24 -0400: > Where to look / what to do next on this? No idea. But if you want to help your user, just block that mailserver right-away and *then* figure out a way to stop it with less drastic measures. And, did you actually try to reach that mail admin? You may not have luck with that all the time, but sometimes there is someone behind the postmaster, even on misbehaving servers. ;-) And it could just be the fault of that sending user, in case it is stuck in his mail client out queue and not on that server. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From uxbod at splatnix.net Wed Aug 1 15:15:05 2007 From: uxbod at splatnix.net (UxBoD) Date: Wed Aug 1 15:23:35 2007 Subject: OT: CRM114 How are you finding it ? Message-ID: <9815720.9411185977705410.JavaMail.root@office.splatnix.net> As people have been running for a couple of days now, have you found it useful in your SPAM battle ? Positive or Negative ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ms-list at alexb.ch Wed Aug 1 15:35:16 2007 From: ms-list at alexb.ch (Alex Broens) Date: Wed Aug 1 15:35:25 2007 Subject: OT: CRM114 How are you finding it ? In-Reply-To: <9815720.9411185977705410.JavaMail.root@office.splatnix.net> References: <9815720.9411185977705410.JavaMail.root@office.splatnix.net> Message-ID: <46B09A24.9030208@alexb.ch> On 8/1/2007 4:15 PM, UxBoD wrote: > As people have been running for a couple of days now, have you found > it useful in your SPAM battle ? Positive or Negative ? tagging spam it's been positive. As its a national holiday here, ham traffic is low and haven't been able to put thru performance tests nor tune at all. Will give CRM114 a week of average traffic before deciding what to do with it. Alex From am.lists at gmail.com Wed Aug 1 15:36:13 2007 From: am.lists at gmail.com (am.lists) Date: Wed Aug 1 15:36:17 2007 Subject: Help with large message / blacklists bypassed In-Reply-To: <46B08E9E.6020008@alexb.ch> References: <25a66d840708010621j7be4a559s8ffa1ec67c74e9f@mail.gmail.com> <46B08E9E.6020008@alexb.ch> Message-ID: <25a66d840708010736n6c2d45d3kec6e48fa4feff2aa@mail.gmail.com> On 8/1/07, Alex Broens wrote: > > I'd block the sender with a Postfix header rule. > > Alex > Thanks for this, Alex... sometimes in panic mode you forget the obvious. I was able to find something unique across all messages, and there was something inserted by their MSExchange server (thread id) that was constant, and I added it as follows to /etc/postfix/header_checks /thread-index: AcfQVR+P5JkcCC8rQ4GAyZsYZ1xAcA==/ REJECT Misbehaving MTA /^Received:/ HOLD Thanks to all replies. Angelo From am.lists at gmail.com Wed Aug 1 15:37:25 2007 From: am.lists at gmail.com (am.lists) Date: Wed Aug 1 15:37:27 2007 Subject: Help with large message / blacklists bypassed In-Reply-To: <223f97700708010651u172974bfs21ba3e0896059307@mail.gmail.com> References: <25a66d840708010621j7be4a559s8ffa1ec67c74e9f@mail.gmail.com> <223f97700708010651u172974bfs21ba3e0896059307@mail.gmail.com> Message-ID: <25a66d840708010737o4f791ef4k9ec587dca9e4b1f1@mail.gmail.com> On 8/1/07, Glenn Steen wrote: > > > And you did remember to restart MailScanner after those changes? That > will affect the MW SQL B/W-list too, sort of;-). > > -- > -- Glenn I actually used the "MSRE" tool which writes the file and schedules a restart. So, in effect, yes. Another fix for the problem a little more upstream is in place now... but thanks for the tip. Angelo From Q.G.Campbell at newcastle.ac.uk Wed Aug 1 15:35:50 2007 From: Q.G.Campbell at newcastle.ac.uk (Quentin Campbell) Date: Wed Aug 1 15:39:22 2007 Subject: 4.62.9-1 & MailScanner --lint In-Reply-To: <46B093BB.8050508@ecs.soton.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470B1257FE@largo.campus.ncl.ac.uk> <46B093BB.8050508@ecs.soton.ac.uk> Message-ID: <4165CF7A7F12DE4B96622CCBB90586470B12584A@largo.campus.ncl.ac.uk> >-----Original Message----- >From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >bounces@lists.mailscanner.info] On Behalf Of Julian Field >Sent: 01 August 2007 15:08 >To: MailScanner discussion >Subject: Re: 4.62.9-1 & MailScanner --lint > >What does >grep -i clam /etc/MailScanner/virus.scanners.conf >say? [snip] [root@cheviot4 log]# grep -i clam /etc/MailScanner/virus.scanners.conf clamav /usr/lib/MailScanner/clamav-wrapper /usr/local clamd /bin/false /usr/local clamavmodule /bin/false /tmp [root@cheviot4 log]# Before requesting help I changed /tmp for /usr/local for the clamavmodule but that made no difference. Quentin From prandal at herefordshire.gov.uk Wed Aug 1 16:02:55 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Wed Aug 1 16:03:07 2007 Subject: CRM114 How are you finding it ? In-Reply-To: <9815720.9411185977705410.JavaMail.root@office.splatnix.net> References: <9815720.9411185977705410.JavaMail.root@office.splatnix.net> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA01510B7D@HC-MBX02.herefordshire.gov.uk> Too soon to tell, really. Only been running it for 21 hours so far. It's pushed some emails into the high-scoring range, but scored negative points on some obvious spam (but not enough to make it end up in users' inboxes). So far so good. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD > Sent: 01 August 2007 15:15 > To: MailScanner discussion > Subject: OT: CRM114 How are you finding it ? > > As people have been running for a couple of days now, have > you found it useful in your SPAM battle ? Positive or Negative ? > > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg > --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B > // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B > // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From hmkash at arl.army.mil Wed Aug 1 16:08:26 2007 From: hmkash at arl.army.mil (Kash, Howard (Civ, ARL/CISD)) Date: Wed Aug 1 16:06:37 2007 Subject: 4.62.9-1 lint error w/mcafee (UNCLASSIFIED) Message-ID: <88991ECEE371C644986F0C8837C207B70173B314@ARLABML01.DS.ARL.ARMY.MIL> Classification: UNCLASSIFIED Caveats: NONE MailScanner.conf says "Virus Scanners = mcafee" Found these virus scanners installed: mcafee ======================================================================== === Ignore errors about failing to find EOCD signature Bad file descriptor,Bad file descriptor at /usr/lib/MailScanner/MailScanner/PFDiskStore.pm line 656. Howard Classification: UNCLASSIFIED Caveats: NONE -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070801/cdd12c87/attachment.html From MailScanner at ecs.soton.ac.uk Wed Aug 1 16:13:40 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 1 16:13:49 2007 Subject: 4.62.9-1 lint error w/mcafee (UNCLASSIFIED) In-Reply-To: <88991ECEE371C644986F0C8837C207B70173B314@ARLABML01.DS.ARL.ARMY.MIL> References: <88991ECEE371C644986F0C8837C207B70173B314@ARLABML01.DS.ARL.ARMY.MIL> Message-ID: <46B0A324.7090208@ecs.soton.ac.uk> Can you try setting MTA=sendmail then give it another go? Kash, Howard (Civ, ARL/CISD) wrote: > > Classification: _* UNCLASSIFIED*_ > Caveats: NONE > > > MailScanner.conf says "Virus Scanners = mcafee" > Found these virus scanners installed: mcafee > =========================================================================== > > Ignore errors about failing to find EOCD signature > Bad file descriptor,Bad file descriptor at > /usr/lib/MailScanner/MailScanner/PFDiskStore.pm line 656. > > > > Howard > > Classification: _* UNCLASSIFIED*_ > Caveats: NONE > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From am.lists at gmail.com Wed Aug 1 16:18:10 2007 From: am.lists at gmail.com (am.lists) Date: Wed Aug 1 16:18:15 2007 Subject: Help with large message / blacklists bypassed In-Reply-To: <46B094E0.7030408@ecs.soton.ac.uk> References: <25a66d840708010621j7be4a559s8ffa1ec67c74e9f@mail.gmail.com> <223f97700708010651u172974bfs21ba3e0896059307@mail.gmail.com> <46B094E0.7030408@ecs.soton.ac.uk> Message-ID: <25a66d840708010818g48234307t61f2018109148bd2@mail.gmail.com> Jules, That's an interesting approach.... but I haven't upgraded to 4.62 yet. I did add this rule to a "mystuff.cf" file: body EEM_FREDMEIJER /It had a heavy infestation of horsetail weed/ score EEM_FREDMEIJER 24.0 describe EEM_FREDMEIJER Special Rule to filter a mail from Fred Meijer that is going crazy in the system. (EEM_ is the prefix I use for all of my own homebrew rules) But as others have pointed out, I have to up my scan size threshold to use SA to score/scan this message. I do use policyd, and I have him blocked in there now. It's effective. The sending mailer is Exchange, and is in farm of sorts, because I'm seeing the same message but so far three unique MTAs sending it. Strange as hell. From glenn.steen at gmail.com Wed Aug 1 16:30:19 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 1 16:30:21 2007 Subject: OT: CRM114 How are you finding it ? In-Reply-To: <9815720.9411185977705410.JavaMail.root@office.splatnix.net> References: <9815720.9411185977705410.JavaMail.root@office.splatnix.net> Message-ID: <223f97700708010830l2a691234x9c325e7bf197d8b5@mail.gmail.com> On 01/08/07, UxBoD wrote: > As people have been running for a couple of days now, have you found it useful in your SPAM battle ? Positive or Negative ? > > Regards, > "On the fence"...:-). As it turned out, it was a bit too aggressive for me to simply just "plopp it into production" straight up... Need run in test a bit first to try finetune things;). Will likely go back to using it once I've found the optimal limits... -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From MailScanner at ecs.soton.ac.uk Wed Aug 1 16:33:00 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 1 16:33:13 2007 Subject: Help with large message / blacklists bypassed In-Reply-To: <25a66d840708010818g48234307t61f2018109148bd2@mail.gmail.com> References: <25a66d840708010621j7be4a559s8ffa1ec67c74e9f@mail.gmail.com> <223f97700708010651u172974bfs21ba3e0896059307@mail.gmail.com> <46B094E0.7030408@ecs.soton.ac.uk> <25a66d840708010818g48234307t61f2018109148bd2@mail.gmail.com> Message-ID: <46B0A7AC.6060609@ecs.soton.ac.uk> am.lists wrote: > Jules, > > That's an interesting approach.... but I haven't upgraded to 4.62 yet. > > I did add this rule to a "mystuff.cf" file: > > > body EEM_FREDMEIJER /It had a heavy infestation of horsetail weed/ > score EEM_FREDMEIJER 24.0 > 24? Isn't that a bit high? On a sidenote, for use in SpamAssassin Rule Actions I would set the score to 0.01. > Strange as hell. > :-) Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From am.lists at gmail.com Wed Aug 1 16:51:27 2007 From: am.lists at gmail.com (am.lists) Date: Wed Aug 1 16:51:37 2007 Subject: Help with large message / blacklists bypassed In-Reply-To: <46B0A7AC.6060609@ecs.soton.ac.uk> References: <25a66d840708010621j7be4a559s8ffa1ec67c74e9f@mail.gmail.com> <223f97700708010651u172974bfs21ba3e0896059307@mail.gmail.com> <46B094E0.7030408@ecs.soton.ac.uk> <25a66d840708010818g48234307t61f2018109148bd2@mail.gmail.com> <46B0A7AC.6060609@ecs.soton.ac.uk> Message-ID: <25a66d840708010851i225f9fd1j103399d432d2ce09@mail.gmail.com> On 8/1/07, Julian Field wrote: > > > am.lists wrote: > > Jules, > > > > That's an interesting approach.... but I haven't upgraded to 4.62 yet. > > > > I did add this rule to a "mystuff.cf" file: > > > > > > body EEM_FREDMEIJER /It had a heavy infestation of horsetail weed/ > > score EEM_FREDMEIJER 24.0 > > > 24? Isn't that a bit high? > On a sidenote, for use in SpamAssassin Rule Actions I would set the > score to 0.01. > Not really since this sender is already in the system with a good history, and thus the AWL will automatically try to negate this penalty based on past message scoring, and with other "good behavior" (well formed MTA, low bayes probability, etc.), I still wanted it to trip my high spam which is set to 6. I do see the benefit of how that would work with the new "SpamAssassin Rule Actions" directive though. And as you say, would only need a 0.01 to trigger it. -Angelo From Q.G.Campbell at newcastle.ac.uk Wed Aug 1 16:56:57 2007 From: Q.G.Campbell at newcastle.ac.uk (Quentin Campbell) Date: Wed Aug 1 16:59:17 2007 Subject: FW: 4.62.9-1 & MailScanner --lint [MORE INFO] Message-ID: <4165CF7A7F12DE4B96622CCBB90586470B125888@largo.campus.ncl.ac.uk> Julian The MailScanner --lint output I am getting is related to the fact that I have "Virus Scanners = clamavmodule mcafee". If I change that line in MailScanner.conf to be "Virus Scanners = clamav mcafee" then I get the following (more sensible) output from MailScanner --lint but also note confusion in the output over clamav/clamavmodule being installed: ------------- cut here [root@cheviot9 MailScanner]# MailScanner --lint Checking version numbers... Version number in MailScanner.conf (4.62.9) is correct. Your envelope_sender_header in spam.assassin.prefs.conf is correct. Checking for SpamAssassin errors (if you use it)... SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp SpamAssassin reported no errors. MailScanner.conf says "Virus Scanners = clamav mcafee" Found these virus scanners installed: clamavmodule, mcafee ======================================================================== === Ignore errors about failing to find EOCD signature ======================================================================== === Virus Scanner test reports: ClamAV said "eicar.com contains Eicar-Test-Signature" McAfee said "/1/eicar.com Found: EICAR test file NOT a virus." If any of your virus scanners (clamavmodule,mcafee) are not listed there, you should check that they are installed correctly and that MailScanner is finding them correctly via its virus.scanners.conf. [root@cheviot9 MailScanner]# ------------- cut here In addition I have just been using CPAN to install Mail::ClamAV on some other gateways and noted that when it does its post install tests it also notices that the database is out of date: ------------- cut here > install Mail::ClamAV ... ... Manifying blib/man3/Mail::ClamAV.3pm /usr/bin/make -- OK Running make test PERL_DL_NONLAZY=1 /usr/bin/perl "-MExtUtils::Command::MM" "-e" "test_harness(0, 'blib/lib', 'blib/arch')" t/*.t t/Mail-ClamAV....ok 2/10LibClamAV Warning: ************************************************** LibClamAV Warning: *** The virus database is older than 7 days. *** LibClamAV Warning: *** Please update it IMMEDIATELY! *** LibClamAV Warning: ************************************************** t/Mail-ClamAV....ok All tests successful. Files=1, Tests=10, 2 wallclock secs ( 1.56 cusr + 0.16 csys = 1.72 CPU) /usr/bin/make test -- OK Running make install Installing /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/auto/Mail/ClamAV/ ClamAV.so Installing /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/auto/Mail/ClamAV/ ClamAV.bs Files found in blib/arch: installing files in blib/lib into architecture dependent library tree Installing /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/Mail/ClamAV.pm Installing /usr/share/man/man3/Mail::ClamAV.3pm Writing /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/auto/Mail/ClamAV/ .packlist Appending installation info to /usr/lib/perl5/5.8.5/i386-linux-thread-multi/perllocal.pod /usr/bin/make install -- OK cpan> ------------- cut here Quentin -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Quentin Campbell Sent: 01 August 2007 15:36 To: MailScanner discussion Subject: RE: 4.62.9-1 & MailScanner --lint >-----Original Message----- >From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >bounces@lists.mailscanner.info] On Behalf Of Julian Field >Sent: 01 August 2007 15:08 >To: MailScanner discussion >Subject: Re: 4.62.9-1 & MailScanner --lint > >What does >grep -i clam /etc/MailScanner/virus.scanners.conf >say? [snip] [root@cheviot4 log]# grep -i clam /etc/MailScanner/virus.scanners.conf clamav /usr/lib/MailScanner/clamav-wrapper /usr/local clamd /bin/false /usr/local clamavmodule /bin/false /tmp [root@cheviot4 log]# Before requesting help I changed /tmp for /usr/local for the clamavmodule but that made no difference. Quentin -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From jase at sensis.com Wed Aug 1 17:02:06 2007 From: jase at sensis.com (Desai, Jason) Date: Wed Aug 1 17:03:55 2007 Subject: CRM114 How are you finding it ? In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA01510B7D@HC-MBX02.herefordshire.gov.uk> Message-ID: <1951DC816E1A9F469307B05FA183F4389DC9E0@corpatsmail1.corp.sensis.com> > Too soon to tell, really. > > Only been running it for 21 hours so far. > > It's pushed some emails into the high-scoring range, but > scored negative > points on some obvious spam (but not enough to make it end up > in users' > inboxes). > > So far so good. Same here. I'm running it with crm114_dynscore_factor -0.01 I'll probably let it run like this for a week or so, and then see how it's doing before changing the factor. Possibly useful to some - I'm using this to analyze the scores (watch the line wraps): grep CRM114_CHECK /var/log/mail.log | sed -re "s/.*: Message ([A-Za-z0-9-]+) .*\bscore=([0-9.-]+), .*\bCRM114_CHECK ([0-9.-]+).*/Id:\1\tSA Score:\2\t\tCRM114 Score:\3 /" This will go through your mail log and print output for messages scored with CRM114 in the format: Id:1IFyHf-0001bf-8j SA Score:39.554 CRM114 Score:0.26 Jase From cmcfadden01 at gmail.com Wed Aug 1 17:09:51 2007 From: cmcfadden01 at gmail.com (Corey McFadden) Date: Wed Aug 1 17:09:56 2007 Subject: Random messages stuck in mqueue In-Reply-To: References: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> Message-ID: <6439a60f0708010909x45298dcal854690f78d1acc63@mail.gmail.com> Guys, Thanks for the replies. I'm running Sendmail (sendmail-8.13.1-3.2.el4). I thought about file locking and DNS as contributing factors but neither seems to be the case. I'm using "posix" now but did run with "flock" for a while to see if it made a difference. Julian: I've tried both "queue" and "batch" as Delivery Method. (It had been batch since the installation and I've had it as queue for about 24-hours without any detectable effect.) For whatever it's worth, not every message seems to get hung. Most seem to be processed expeditiously but the ones that are hung stay that way for a while. Thanks, -Corey On 8/1/07, Kai Schaetzl wrote: > > Corey McFadden wrote on Wed, 1 Aug 2007 00:46:05 -0400: > > > We're experiencing an issue on one of our boxes where messages (a good > percentage) are hung in /var/spool/mqueue after being processed by > MailScanner. > > And your load is low? > > Kai > > -- > Kai Sch?tzl, Berlin, Germany > Get your web at Conactive Internet Services: http://www.conactive.com > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070801/f34966e5/attachment.html From uxbod at splatnix.net Wed Aug 1 17:18:31 2007 From: uxbod at splatnix.net (UxBoD) Date: Wed Aug 1 17:15:42 2007 Subject: CRM114 How are you finding it ? In-Reply-To: <1951DC816E1A9F469307B05FA183F4389DC9E0@corpatsmail1.corp.sensis.com> Message-ID: <21791733.9561185985111398.JavaMail.root@office.splatnix.net> Nice regex Jason. Fancy adding it to the Wiki ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Jason Desai" To: "MailScanner discussion" Sent: Wednesday, August 1, 2007 5:02:06 PM (GMT) Europe/London Subject: RE: CRM114 How are you finding it ? > Too soon to tell, really. > > Only been running it for 21 hours so far. > > It's pushed some emails into the high-scoring range, but > scored negative > points on some obvious spam (but not enough to make it end up > in users' > inboxes). > > So far so good. Same here. I'm running it with crm114_dynscore_factor -0.01 I'll probably let it run like this for a week or so, and then see how it's doing before changing the factor. Possibly useful to some - I'm using this to analyze the scores (watch the line wraps): grep CRM114_CHECK /var/log/mail.log | sed -re "s/.*: Message ([A-Za-z0-9-]+) .*\bscore=([0-9.-]+), .*\bCRM114_CHECK ([0-9.-]+).*/Id:\1\tSA Score:\2\t\tCRM114 Score:\3 /" This will go through your mail log and print output for messages scored with CRM114 in the format: Id:1IFyHf-0001bf-8j SA Score:39.554 CRM114 Score:0.26 Jase -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From prandal at herefordshire.gov.uk Wed Aug 1 17:19:09 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Wed Aug 1 17:19:17 2007 Subject: 4.62.9-1 & MailScanner --lint [MORE INFO] In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470B125888@largo.campus.ncl.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470B125888@largo.campus.ncl.ac.uk> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA01510BA8@HC-MBX02.herefordshire.gov.uk> Works for me: MailScanner --lint Checking version numbers... Version number in MailScanner.conf (4.62.9) is correct. Your envelope_sender_header in spam.assassin.prefs.conf is correct. Checking for SpamAssassin errors (if you use it)... SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp SpamAssassin reported no errors. MailScanner.conf says "Virus Scanners = clamavmodule mcafee" Found these virus scanners installed: clamavmodule, mcafee ======================================================================== === Ignore errors about failing to find EOCD signature format error: can't find EOCD signature at /usr/sbin/MailScanner line 450 ======================================================================== === Virus Scanner test reports: ClamAV Module said "eicar.com was infected: Eicar-Test-Signature" McAfee said "/1/eicar.com Found: EICAR test file NOT a virus." If any of your virus scanners (clamavmodule,mcafee) are not listed there, you should check that they are installed correctly and that MailScanner is finding them correctly via its virus.scanners.conf. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Quentin Campbell > Sent: 01 August 2007 16:57 > To: MailScanner discussion > Subject: FW: 4.62.9-1 & MailScanner --lint [MORE INFO] > > Julian > > The MailScanner --lint output I am getting is related to the > fact that I > have "Virus Scanners = clamavmodule mcafee". If I change that line in > MailScanner.conf to be "Virus Scanners = clamav mcafee" then I get the > following (more sensible) output from MailScanner --lint but also note > confusion in the output over clamav/clamavmodule being installed: > > ------------- cut here > [root@cheviot9 MailScanner]# MailScanner --lint > Checking version numbers... > Version number in MailScanner.conf (4.62.9) is correct. > > Your envelope_sender_header in spam.assassin.prefs.conf is correct. > > Checking for SpamAssassin errors (if you use it)... > SpamAssassin temp dir = > /var/spool/MailScanner/incoming/SpamAssassin-Temp > SpamAssassin reported no errors. > MailScanner.conf says "Virus Scanners = clamav mcafee" > Found these virus scanners installed: clamavmodule, mcafee > ============================================================== > ========== > === > Ignore errors about failing to find EOCD signature > ============================================================== > ========== > === > Virus Scanner test reports: > ClamAV said "eicar.com contains Eicar-Test-Signature" > McAfee said "/1/eicar.com Found: EICAR test file NOT a virus." > > If any of your virus scanners (clamavmodule,mcafee) > are not listed there, you should check that they are > installed correctly > and that MailScanner is finding them correctly via its > virus.scanners.conf. > [root@cheviot9 MailScanner]# > ------------- cut here > > In addition I have just been using CPAN to install > Mail::ClamAV on some > other gateways and noted that when it does its post install tests it > also notices that the database is out of date: > > ------------- cut here > > install Mail::ClamAV > ... > ... > Manifying blib/man3/Mail::ClamAV.3pm > /usr/bin/make -- OK > Running make test > PERL_DL_NONLAZY=1 /usr/bin/perl "-MExtUtils::Command::MM" "-e" > "test_harness(0, 'blib/lib', 'blib/arch')" t/*.t > t/Mail-ClamAV....ok 2/10LibClamAV Warning: > ************************************************** > LibClamAV Warning: *** The virus database is older than 7 days. *** > LibClamAV Warning: *** Please update it IMMEDIATELY! *** > LibClamAV Warning: ************************************************** > t/Mail-ClamAV....ok > > All tests successful. > Files=1, Tests=10, 2 wallclock secs ( 1.56 cusr + 0.16 csys = 1.72 > CPU) > /usr/bin/make test -- OK > Running make install > Installing > /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/auto/Ma > il/ClamAV/ > ClamAV.so > Installing > /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/auto/Ma > il/ClamAV/ > ClamAV.bs > Files found in blib/arch: installing files in blib/lib into > architecture > dependent library tree > Installing > /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/Mail/ClamAV.pm > Installing /usr/share/man/man3/Mail::ClamAV.3pm > Writing > /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/auto/Ma > il/ClamAV/ > .packlist > Appending installation info to > /usr/lib/perl5/5.8.5/i386-linux-thread-multi/perllocal.pod > /usr/bin/make install -- OK > > cpan> > ------------- cut here > > Quentin > > > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Quentin > Campbell > Sent: 01 August 2007 15:36 > To: MailScanner discussion > Subject: RE: 4.62.9-1 & MailScanner --lint > > >-----Original Message----- > >From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > >bounces@lists.mailscanner.info] On Behalf Of Julian Field > >Sent: 01 August 2007 15:08 > >To: MailScanner discussion > >Subject: Re: 4.62.9-1 & MailScanner --lint > > > >What does > >grep -i clam /etc/MailScanner/virus.scanners.conf > >say? > [snip] > > [root@cheviot4 log]# grep -i clam /etc/MailScanner/virus.scanners.conf > clamav /usr/lib/MailScanner/clamav-wrapper /usr/local > clamd /bin/false /usr/local > clamavmodule /bin/false /tmp > [root@cheviot4 log]# > > Before requesting help I changed /tmp for /usr/local for the > clamavmodule but that made no difference. > > Quentin > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From glenn.steen at gmail.com Wed Aug 1 17:20:57 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 1 17:20:59 2007 Subject: 4.62.9-1 lint error w/mcafee (UNCLASSIFIED) In-Reply-To: <46B0A324.7090208@ecs.soton.ac.uk> References: <88991ECEE371C644986F0C8837C207B70173B314@ARLABML01.DS.ARL.ARMY.MIL> <46B0A324.7090208@ecs.soton.ac.uk> Message-ID: <223f97700708010920p6ecbef92tb7eb584e056e6c9e@mail.gmail.com> On 01/08/07, Julian Field wrote: > Can you try setting MTA=sendmail then give it another go? This corrects the lint error. Sorry for not noticing earlier:-( Cannot (of course) run it like that, so ... go do our magic Jules;-):-) > Kash, Howard (Civ, ARL/CISD) wrote: > > > > Classification: _* UNCLASSIFIED*_ > > Caveats: NONE > > > > > > MailScanner.conf says "Virus Scanners = mcafee" > > Found these virus scanners installed: mcafee > > =========================================================================== > > > > Ignore errors about failing to find EOCD signature > > Bad file descriptor,Bad file descriptor at > > /usr/lib/MailScanner/MailScanner/PFDiskStore.pm line 656. > > > > > > > > Howard > > > > Classification: _* UNCLASSIFIED*_ > > Caveats: NONE > > > > Jules > > Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From ssilva at sgvwater.com Wed Aug 1 17:42:46 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Aug 1 17:43:07 2007 Subject: CRM114 Installation on Centos 4 In-Reply-To: <7247337.8661185958645314.JavaMail.root@office.splatnix.net> References: <223f97700708010137x7247cffax3bab65f1a95088a8@mail.gmail.com> <7247337.8661185958645314.JavaMail.root@office.splatnix.net> Message-ID: UxBoD spake the following on 8/1/2007 1:57 AM: > Darn, you have the page locked Glenn ;) Was going to add the short description about CRM14 and the URL to the sourceforge site. > > Its looking good :) > > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B > // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B > // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net > Now that is wiki contributing at its finest! >From a simple short doc to a full multi-distro howto. Now when someone writes a solaris section, and a *BSD section, it should cover the majority of the userbase. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Wed Aug 1 17:50:37 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Aug 1 17:50:49 2007 Subject: MailScanner ANNOUNCE: Version 4.62.9 released In-Reply-To: <46AFA330.7010206@ecs.soton.ac.uk> References: <46AFA330.7010206@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 7/31/2007 2:01 PM: > I have just released a new version of MailScanner, 4.62.9. I don't > normally bother releasing a new version for August, as it's normally > very quiet and it isn't worth it. However, this year July has been > absolutely hectic and the list of new features and changes this month is > enormous! I love the new --lint output! It did everything but tell me to turn my head and cough! ;-P -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Wed Aug 1 17:54:56 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Aug 1 18:00:09 2007 Subject: Subject Text Not Getting Modified? In-Reply-To: <46AFE896.1090708@openenterprise.ca> References: <46AFE896.1090708@openenterprise.ca> Message-ID: Johnny Stork spake the following on 7/31/2007 6:57 PM: > I have noticed that none of the detected spam, including high scoring > spam which gets quarantined, are getting the subject lines modified? I > have almost all the Modify Subject settings enable in mailscanner.conf, > but nothing seems to be getting re-written. For instance, below is the > phishing section of mailscanner.conf, followed by an incoming message. > When I checked the message in mailwatch, the subject is the same/unchanged? > > Any ideas? It won't show up in Mailwatch. It only shows up at the mail client. Send yourself some low spam like all blue and CAPS from a yahoo mail address. That usually will score enough to hit low spam. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From rcooper at dwford.com Wed Aug 1 18:04:38 2007 From: rcooper at dwford.com (Rick Cooper) Date: Wed Aug 1 18:04:42 2007 Subject: CRM114 Installation on Centos 4 In-Reply-To: References: <223f97700708010137x7247cffax3bab65f1a95088a8@mail.gmail.com><7247337.8661185958645314.JavaMail.root@office.splatnix.net> Message-ID: <01b801c7d45e$0b86b3a0$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On > Behalf Of Scott Silva > Sent: Wednesday, August 01, 2007 12:43 PM > To: mailscanner@lists.mailscanner.info > Subject: Re: CRM114 Installation on Centos 4 > > UxBoD spake the following on 8/1/2007 1:57 AM: > > Darn, you have the page locked Glenn ;) Was going to add > the short description about CRM14 and the URL to the > sourceforge site. > > > > Its looking good :) > > > > Regards, > > > > --[ UxBoD ]-- > > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | > gpg --import" > > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B > > // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B > > // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net > > > Now that is wiki contributing at its finest! > >From a simple short doc to a full multi-distro howto. > Now when someone writes a solaris section, and a *BSD > section, it should cover > the majority of the userbase. > Something some one might want to add : On my perl 5.8.0 installations when you lint spamassassin you get a warning about sprintf using an unitialized value at crm114.pm line 235 and if you look at line 235 warn(sprintf("crm114: Error: %s"), $1); Should be warn(sprintf("crm114: Error: %s", $1)); And that change removes the warning. It doesn't happen with perl 5.8.8 though Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ssilva at sgvwater.com Wed Aug 1 18:00:55 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Aug 1 18:05:03 2007 Subject: Random messages stuck in mqueue In-Reply-To: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> References: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> Message-ID: Corey McFadden spake the following on 7/31/2007 9:46 PM: > > Guys, > > We're experiencing an issue on one of our boxes where messages (a good > percentage) are hung in /var/spool/mqueue after being processed by > MailScanner. Even those to be delivered locally will sit for > (sometimes) hours until they're finally delivered. > > I've never seen this behavior before and something is definitely awry. > > Here's the environment: > > This is CentOS release 4.5 (Final) > This is Perl version 5.008008 (5.8.8) > > This is MailScanner version 4.61.7 > > Executing 'sendmail -q -v' WILL process the stuck messages but can take > quite a long time to run because it will try to deliver everything > queued in a linear fashion. > Since it is in mqueue and not mqueue.in, mailscanner is pretty much out of the loop. Check if you have a FQDN that resolves properly as this will choke sendmail quickly. Also try a local caching nameserver, as sendmail might be taking a long time to resolve delivery addresses. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From MailScanner at ecs.soton.ac.uk Wed Aug 1 18:17:45 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 1 18:19:11 2007 Subject: 4.62.9-1 lint error w/mcafee (UNCLASSIFIED) In-Reply-To: <223f97700708010920p6ecbef92tb7eb584e056e6c9e@mail.gmail.com> References: <88991ECEE371C644986F0C8837C207B70173B314@ARLABML01.DS.ARL.ARMY.MIL> <46B0A324.7090208@ecs.soton.ac.uk> <223f97700708010920p6ecbef92tb7eb584e056e6c9e@mail.gmail.com> Message-ID: <46B0C039.4000402@ecs.soton.ac.uk> Skipped content of type multipart/mixed-------------- next part -------------- A non-text attachment was scrubbed... Name: PGP.sig Type: application/pgp-signature Size: 195 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070801/a88c7b94/PGP.bin From MailScanner at ecs.soton.ac.uk Wed Aug 1 18:23:54 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 1 18:24:22 2007 Subject: MailScanner ANNOUNCE: Version 4.62.9 released In-Reply-To: References: <46AFA330.7010206@ecs.soton.ac.uk> Message-ID: <46B0C1AA.1060500@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Scott Silva wrote: > Julian Field spake the following on 7/31/2007 2:01 PM: > >> I have just released a new version of MailScanner, 4.62.9. I don't >> normally bother releasing a new version for August, as it's normally >> very quiet and it isn't worth it. However, this year July has been >> absolutely hectic and the list of new features and changes this month is >> enormous! >> > I love the new --lint output! > It did everything but tell me to turn my head and cough! ;-) > Thanks! I hope you find it useful. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGsMGqEfZZRxQVtlQRAnudAKD+NJk7BYbc6CK/ZBaYVjiXvZJcUQCZAe+g DFHAvUTyMvJPyFpYVrK8zts= =6nR2 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Wed Aug 1 18:24:06 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Aug 1 18:24:27 2007 Subject: Help with large message / blacklists bypassed In-Reply-To: References: <25a66d840708010621j7be4a559s8ffa1ec67c74e9f@mail.gmail.com> Message-ID: Kai Schaetzl spake the following on 8/1/2007 7:16 AM: > Am.lists wrote on Wed, 1 Aug 2007 09:21:24 -0400: > >> Where to look / what to do next on this? > > No idea. But if you want to help your user, just block that mailserver > right-away and *then* figure out a way to stop it with less drastic > measures. > And, did you actually try to reach that mail admin? You may not have luck > with that all the time, but sometimes there is someone behind the > postmaster, even on misbehaving servers. ;-) > And it could just be the fault of that sending user, in case it is stuck > in his mail client out queue and not on that server. > > Kai > That is usually the case. Outlook (and express) have a size limit on their local mailstores. The clients send, try to copy to their sent items, fail on the copy, and send again on the next scheduled run. And you can't e-mail them to tell them, because they can't get their incoming mail either because of the same problem. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From cmcfadden01 at gmail.com Wed Aug 1 18:28:08 2007 From: cmcfadden01 at gmail.com (Corey McFadden) Date: Wed Aug 1 18:28:11 2007 Subject: Random messages stuck in mqueue In-Reply-To: References: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> Message-ID: <6439a60f0708011028y72dec553tcf9b5f5f10c85a79@mail.gmail.com> It does seem as though the problem begins when MailScanner disposes of a message. Maybe someone could clarify the process whereby Sendmail picks up the message and decides to deliver it (locally or relay or whatever.) It doesn't look like a DNS issue. We've got a local resolver (that has a PTR record for the machine's IP) and a backup resolver. I've done a number of DNS tests and haven't been able to produce an error there. On other systems everything happens so quickly that it's hard to see what happens but does it resemble this: - MailScanner finds message in mqueue.in - MailScanner processes message and dumps qf/df into mqueue - Sendmail daemon periodically scans mqueue or: - MailScanner finds message in mqueue.in - MailScanner processes message and spawns a sendmail process for delivery What are the implications of the "Delivery Method" queue vs. batch option on the above? Thanks for the input! -Corey On 8/1/07, Scott Silva wrote: > > Corey McFadden spake the following on 7/31/2007 9:46 PM: > > > > Guys, > > > > We're experiencing an issue on one of our boxes where messages (a good > > percentage) are hung in /var/spool/mqueue after being processed by > > MailScanner. Even those to be delivered locally will sit for > > (sometimes) hours until they're finally delivered. > > > > I've never seen this behavior before and something is definitely awry. > > > > Here's the environment: > > > > This is CentOS release 4.5 (Final) > > This is Perl version 5.008008 (5.8.8) > > > > This is MailScanner version 4.61.7 > > > > Executing 'sendmail -q -v' WILL process the stuck messages but can take > > quite a long time to run because it will try to deliver everything > > queued in a linear fashion. > > > Since it is in mqueue and not mqueue.in, mailscanner is pretty much out of > the > loop. Check if you have a FQDN that resolves properly as this will choke > sendmail quickly. Also try a local caching nameserver, as sendmail might > be > taking a long time to resolve delivery addresses. > > -- > > MailScanner is like deodorant... > You hope everybody uses it, and > you notice quickly if they don't!!!! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070801/c9f2357e/attachment.html From lists at jfworks.net Wed Aug 1 18:28:37 2007 From: lists at jfworks.net (James) Date: Wed Aug 1 18:29:01 2007 Subject: Random messages stuck in mqueue In-Reply-To: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> References: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> Message-ID: <46B0C2C5.4010909@jfworks.net> Corey McFadden wrote: > > Guys, > > We're experiencing an issue on one of our boxes where messages (a good > percentage) are hung in /var/spool/mqueue after being processed by > MailScanner. Even those to be delivered locally will sit for > (sometimes) hours until they're finally delivered. > > I've never seen this behavior before and something is definitely awry. > > Here's the environment: > > This is CentOS release 4.5 (Final) > This is Perl version 5.008008 (5.8.8) > > This is MailScanner version 4.61.7 > > Executing 'sendmail -q -v' WILL process the stuck messages but can > take quite a long time to run because it will try to deliver > everything queued in a linear fashion. > > Here's a good example of a message hung for more than 10 minutes: > > [root@ewrgga-hst01 mqueue]# cat qfl714YqCD027817 > V8 > T1185942893 > K0 > N0 > P32072 > Fbs > > > This is pretty typical of the messages hung. In this case it's > waiting to be delivered to a local "spamtrap" mailbox. > > Can anyone offer me any ideas to troubleshoot this? I've not been too > successful hunting so far today. > > Thanks in advance! > -Corey Actually I have seen this before where the messages sit in the queue, delivery is attempted and failed then retry and it seems to be a loop. This has been caused by some firewalls. I cant say exactly why and I do know that for some reason some recipents will be able to recieve and others not, but its worth looking at. If there is another network device between the boxes try to dissable any "fancy" featues then give a power cycle or remove it all together. If the messages are not able to be delivered to the local machine itself, then you may have some hardware problem. From uxbod at splatnix.net Wed Aug 1 16:52:01 2007 From: uxbod at splatnix.net (UxBoD) Date: Wed Aug 1 18:39:06 2007 Subject: OT: CRM114 How are you finding it ? In-Reply-To: <223f97700708010830l2a691234x9c325e7bf197d8b5@mail.gmail.com> Message-ID: <20546691.9531185983521679.JavaMail.root@office.splatnix.net> :( Glenn. Why not set the following in crm114.cf :- crm114_staticscore_good -0.1 crm114_staticscore_unsure 0.0 crm114_staticscore_spam 0.1 That way you can check for potential FPs, and still allow it to learn. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ssilva at sgvwater.com Wed Aug 1 18:39:35 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Aug 1 18:39:46 2007 Subject: CRM114 Installation on Centos 4 In-Reply-To: <01b801c7d45e$0b86b3a0$0301a8c0@SAHOMELT> References: <223f97700708010137x7247cffax3bab65f1a95088a8@mail.gmail.com><7247337.8661185958645314.JavaMail.root@office.splatnix.net> <01b801c7d45e$0b86b3a0$0301a8c0@SAHOMELT> Message-ID: Rick Cooper spake the following on 8/1/2007 10:04 AM: > > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On > > Behalf Of Scott Silva > > Sent: Wednesday, August 01, 2007 12:43 PM > > To: mailscanner@lists.mailscanner.info > > Subject: Re: CRM114 Installation on Centos 4 > > > > UxBoD spake the following on 8/1/2007 1:57 AM: > > > Darn, you have the page locked Glenn ;) Was going to add > > the short description about CRM14 and the URL to the > > sourceforge site. > > > > > > Its looking good :) > > > > > > Regards, > > > > > > --[ UxBoD ]-- > > > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | > > gpg --import" > > > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B > > > // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B > > > // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net > > > > > Now that is wiki contributing at its finest! > > >From a simple short doc to a full multi-distro howto. > > Now when someone writes a solaris section, and a *BSD > > section, it should cover > > the majority of the userbase. > > > > Something some one might want to add : > > On my perl 5.8.0 installations when you lint spamassassin you get a warning > about sprintf using an unitialized value at crm114.pm line 235 and if you > look at line 235 > > warn(sprintf("crm114: Error: %s"), $1); > > Should be > > warn(sprintf("crm114: Error: %s", $1)); > > And that change removes the warning. It doesn't happen with perl 5.8.8 > though > > Rick Perl 5.8.0 is quite old, but RHEL3 (and CentOS3) are using it, and will be still supported for another year or two. Does that change work with newer perls? Maybe it should be passed up to crm114 writer. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From cmcfadden01 at gmail.com Wed Aug 1 18:44:06 2007 From: cmcfadden01 at gmail.com (Corey McFadden) Date: Wed Aug 1 18:44:09 2007 Subject: Random messages stuck in mqueue In-Reply-To: <46B0C2C5.4010909@jfworks.net> References: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> <46B0C2C5.4010909@jfworks.net> Message-ID: <6439a60f0708011044j95116e5jceae6e8f485632be@mail.gmail.com> Well, in this case sendmail hasn't attempted delivery so it's definitely something in the box itself. (You can confirm the number of attempts, as well as the timestamp of the last sendmail attempt by looking at the qfXXXXXX file.) -Corey On 8/1/07, James wrote: > > Corey McFadden wrote: > > > > Guys, > > > > We're experiencing an issue on one of our boxes where messages (a good > > percentage) are hung in /var/spool/mqueue after being processed by > > MailScanner. Even those to be delivered locally will sit for > > (sometimes) hours until they're finally delivered. > > > > I've never seen this behavior before and something is definitely awry. > > > > Here's the environment: > > > > This is CentOS release 4.5 (Final) > > This is Perl version 5.008008 (5.8.8) > > > > This is MailScanner version 4.61.7 > > > > Executing 'sendmail -q -v' WILL process the stuck messages but can > > take quite a long time to run because it will try to deliver > > everything queued in a linear fashion. > > > > Here's a good example of a message hung for more than 10 minutes: > > > > [root@ewrgga-hst01 mqueue]# cat qfl714YqCD027817 > > V8 > > T1185942893 > > K0 > > N0 > > P32072 > > Fbs > > > > > > This is pretty typical of the messages hung. In this case it's > > waiting to be delivered to a local "spamtrap" mailbox. > > > > Can anyone offer me any ideas to troubleshoot this? I've not been too > > successful hunting so far today. > > > > Thanks in advance! > > -Corey > Actually I have seen this before where the messages sit in the queue, > delivery is attempted and failed then retry and it seems to be a loop. > This has been caused by some firewalls. I cant say exactly why and I do > know that for some reason some recipents will be able to recieve and > others not, but its worth looking at. If there is another network device > between the boxes try to dissable any "fancy" featues then give a power > cycle or remove it all together. If the messages are not able to be > delivered to the local machine itself, then you may have some hardware > problem. > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070801/f5af72d0/attachment-0001.html From stork at openenterprise.ca Wed Aug 1 20:05:44 2007 From: stork at openenterprise.ca (Johnny Stork) Date: Wed Aug 1 20:05:41 2007 Subject: Subject Text Not Getting Modified? In-Reply-To: <17305916.8541185954848518.JavaMail.root@office.splatnix.net> References: <17305916.8541185954848518.JavaMail.root@office.splatnix.net> Message-ID: <46B0D988.806@openenterprise.ca> Sorry for my ignorance, I had setup MS over a year ago and after spending some time setting it up to where I "beleive" I had everything workin, I have not really touched it since. So after getting CRM114 installed I went and upgraded to the newest version. So I went and ran the install-Clam-0.91.1-SA-3.2.2.tar.gz to also update clam and SA. They were not that far behind. When this upgrade finished, since I had been running rulesdujour, when it finished the script indicated I needed to install rulesdujour. But I also just heard that RDJ is not longer working/supported and I should use sa_update so this was my first bit of confusion. So I downloaded the latest rulesdujour and ran the installer but it bailed claiming lint errors. I managed to find these as outdated cf files (rules) and so was able to finish the RDJ install. I also noticed that all the cf files in /etc/mail/spamassasin got moved to /etc/mail/spamassasin/old_cf_files? I then ran the mailscanner install to upgrade to4.62.9. At this point I am not certain I have everything configured and working properly and dont know where to begin cleaning things up. I would not expect anyone to help with this cause it is certainly my mess. It is running, and seems to be working but I am not certain I have things like RDJ and/or sa_update working correctly or which rules are valid. If you would be willing/interested in taking a look I would be greatful. You have already been a great help so I would not expect any more. I do see many new items/rules etc and a couple of strange errors in the lint test though. Below is the lint: root@gateway:~# /usr/bin/spamassassin -D -p /etc/MailScanner/spam.assassin.prefs.conf --lint [21619] dbg: logger: adding facilities: all [21619] dbg: logger: logging level is DBG [21619] dbg: generic: SpamAssassin version 3.2.2 [21619] dbg: config: score set 0 chosen. [21619] dbg: util: running in taint mode? yes [21619] dbg: util: taint mode: deleting unsafe environment variables, resetting PATH [21619] dbg: util: PATH included '/usr/kerberos/sbin', keeping [21619] dbg: util: PATH included '/usr/kerberos/bin', keeping [21619] dbg: util: PATH included '/usr/local/sbin', keeping [21619] dbg: util: PATH included '/usr/local/bin', keeping [21619] dbg: util: PATH included '/sbin', keeping [21619] dbg: util: PATH included '/bin', keeping [21619] dbg: util: PATH included '/usr/sbin', keeping [21619] dbg: util: PATH included '/usr/bin', keeping [21619] dbg: util: PATH included '/usr/X11R6/bin', keeping [21619] dbg: util: PATH included '/root/bin', which doesn't exist, dropping [21619] dbg: util: final PATH set to: /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin:/usr/X11R6/bin [21619] dbg: dns: is Net::DNS::Resolver available? yes [21619] dbg: dns: Net::DNS version: 0.60 [21619] dbg: diag: perl platform: 5.008008 linux [21619] dbg: diag: module installed: Digest::SHA1, version 2.10 [21619] dbg: diag: module installed: HTML::Parser, version 3.56 [21619] dbg: diag: module installed: Net::DNS, version 0.60 [21619] dbg: diag: module installed: MIME::Base64, version 3.07 [21619] dbg: diag: module installed: DB_File, version 1.814 [21619] dbg: diag: module installed: Net::SMTP, version 2.29 [21619] dbg: diag: module installed: Mail::SPF, version v2.004 [21619] dbg: diag: module installed: Mail::SPF::Query, version 1.999001 [21619] dbg: diag: module installed: IP::Country::Fast, version 604.001 [21619] dbg: diag: module installed: Razor2::Client::Agent, version 2.77 [21619] dbg: diag: module installed: Net::Ident, version 1.20 [21619] dbg: diag: module installed: IO::Socket::INET6, version 2.51 [21619] dbg: diag: module installed: IO::Socket::SSL, version 0.97 [21619] dbg: diag: module installed: Compress::Zlib, version 1.41 [21619] dbg: diag: module installed: Time::HiRes, version 1.86 [21619] dbg: diag: module installed: Mail::DomainKeys, version 0.80 [21619] dbg: diag: module not installed: Mail::DKIM ('require' failed) [21619] dbg: diag: module installed: DBI, version 1.56 [21619] dbg: diag: module installed: Getopt::Long, version 2.35 [21619] dbg: diag: module installed: LWP::UserAgent, version 2.033 [21619] dbg: diag: module installed: HTTP::Date, version 1.47 [21619] dbg: diag: module installed: Archive::Tar, version 1.29 [21619] dbg: diag: module installed: IO::Zlib, version 1.04 [21619] dbg: diag: module installed: Encode::Detect, version 1.00 [21619] dbg: ignore: using a test message to lint rules [21619] dbg: config: using "/etc/mail/spamassassin" for site rules pre files [21619] dbg: config: read file /etc/mail/spamassassin/init.pre [21619] dbg: config: read file /etc/mail/spamassassin/v310.pre [21619] dbg: config: read file /etc/mail/spamassassin/v312.pre [21619] dbg: config: read file /etc/mail/spamassassin/v320.pre [21619] dbg: config: using "/usr/share/spamassassin" for sys rules pre files [21619] dbg: config: using "/usr/share/spamassassin" for default rules dir [21619] dbg: config: read file /usr/share/spamassassin/10_default_prefs.cf [21619] dbg: config: read file /usr/share/spamassassin/20_advance_fee.cf [21619] dbg: config: read file /usr/share/spamassassin/20_body_tests.cf [21619] dbg: config: read file /usr/share/spamassassin/20_compensate.cf [21619] dbg: config: read file /usr/share/spamassassin/20_dnsbl_tests.cf [21619] dbg: config: read file /usr/share/spamassassin/20_drugs.cf [21619] dbg: config: read file /usr/share/spamassassin/20_dynrdns.cf [21619] dbg: config: read file /usr/share/spamassassin/20_fake_helo_tests.cf [21619] dbg: config: read file /usr/share/spamassassin/20_head_tests.cf [21619] dbg: config: read file /usr/share/spamassassin/20_html_tests.cf [21619] dbg: config: read file /usr/share/spamassassin/20_imageinfo.cf [21619] dbg: config: read file /usr/share/spamassassin/20_meta_tests.cf [21619] dbg: config: read file /usr/share/spamassassin/20_net_tests.cf [21619] dbg: config: read file /usr/share/spamassassin/20_phrases.cf [21619] dbg: config: read file /usr/share/spamassassin/20_porn.cf [21619] dbg: config: read file /usr/share/spamassassin/20_ratware.cf [21619] dbg: config: read file /usr/share/spamassassin/20_uri_tests.cf [21619] dbg: config: read file /usr/share/spamassassin/20_vbounce.cf [21619] dbg: config: read file /usr/share/spamassassin/23_bayes.cf [21619] dbg: config: read file /usr/share/spamassassin/25_accessdb.cf [21619] dbg: config: read file /usr/share/spamassassin/25_antivirus.cf [21619] dbg: config: read file /usr/share/spamassassin/25_asn.cf [21619] dbg: config: read file /usr/share/spamassassin/25_dcc.cf [21619] dbg: config: read file /usr/share/spamassassin/25_dkim.cf [21619] dbg: config: read file /usr/share/spamassassin/25_domainkeys.cf [21619] dbg: config: read file /usr/share/spamassassin/25_hashcash.cf [21619] dbg: config: read file /usr/share/spamassassin/25_pyzor.cf [21619] dbg: config: read file /usr/share/spamassassin/25_razor2.cf [21619] dbg: config: read file /usr/share/spamassassin/25_replace.cf [21619] dbg: config: read file /usr/share/spamassassin/25_spf.cf [21619] dbg: config: read file /usr/share/spamassassin/25_textcat.cf [21619] dbg: config: read file /usr/share/spamassassin/25_uribl.cf [21619] dbg: config: read file /usr/share/spamassassin/30_text_de.cf [21619] dbg: config: read file /usr/share/spamassassin/30_text_fr.cf [21619] dbg: config: read file /usr/share/spamassassin/30_text_it.cf [21619] dbg: config: read file /usr/share/spamassassin/30_text_nl.cf [21619] dbg: config: read file /usr/share/spamassassin/30_text_pl.cf [21619] dbg: config: read file /usr/share/spamassassin/30_text_pt_br.cf [21619] dbg: config: read file /usr/share/spamassassin/50_scores.cf [21619] dbg: config: read file /usr/share/spamassassin/60_awl.cf [21619] dbg: config: read file /usr/share/spamassassin/60_shortcircuit.cf [21619] dbg: config: read file /usr/share/spamassassin/60_whitelist.cf [21619] dbg: config: read file /usr/share/spamassassin/60_whitelist_dk.cf [21619] dbg: config: read file /usr/share/spamassassin/60_whitelist_dkim.cf [21619] dbg: config: read file /usr/share/spamassassin/60_whitelist_spf.cf [21619] dbg: config: read file /usr/share/spamassassin/60_whitelist_subject.cf [21619] dbg: config: read file /usr/share/spamassassin/72_active.cf [21619] dbg: config: using "/etc/mail/spamassassin" for site rules dir [21619] dbg: config: read file /etc/mail/spamassassin/bogus-virus-warnings.cf [21619] dbg: config: read file /etc/mail/spamassassin/crm114.cf [21619] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf [21619] dbg: config: read file /etc/mail/spamassassin/random.cf [21619] dbg: config: read file /etc/mail/spamassassin/tripwire.cf [21619] dbg: config: using "/etc/MailScanner/spam.assassin.prefs.conf" for user prefs file [21619] dbg: config: read file /etc/MailScanner/spam.assassin.prefs.conf [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::DCC from @INC [21619] dbg: dcc: local tests only, disabling DCC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::SpamCop from @INC [21619] dbg: reporter: local tests only, disabling SpamCop [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::DomainKeys from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::DCC from @INC [21619] dbg: dcc: local tests only, disabling DCC [21619] dbg: plugin: did not register Mail::SpamAssassin::Plugin::DCC=HASH(0xae59fa4), already registered [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC [21619] dbg: pyzor: local tests only, disabling Pyzor [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::SpamCop from @INC [21619] dbg: reporter: local tests only, disabling SpamCop [21619] dbg: plugin: did not register Mail::SpamAssassin::Plugin::SpamCop=HASH(0xae59e90), already registered [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [21619] dbg: razor2: local tests only, skipping Razor [21619] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [21619] dbg: plugin: loading crm114 from /etc/mail/spamassassin/crm114.pm [21619] dbg: rules: __MO_OL_9B90B merged duplicates: __MO_OL_C65FA [21619] dbg: rules: __XM_OL_22B61 merged duplicates: __XM_OL_A842E [21619] dbg: rules: __MO_OL_07794 merged duplicates: __MO_OL_8627E __MO_OL_F3B05 [21619] dbg: rules: __XM_OL_07794 merged duplicates: __XM_OL_25340 __XM_OL_3857F __XM_OL_4F240 __XM_OL_58CB5 __XM_OL_6554A __XM_OL_812FF __XM_OL_C65FA __XM_OL_CF0C0 __XM_OL_F475E __XM_OL_F6D01 [21619] dbg: rules: FH_MSGID_01C67 merged duplicates: __MSGID_VGA [21619] dbg: rules: FS_NEW_SOFT_UPLOAD merged duplicates: HS_SUBJ_NEW_SOFTWARE [21619] dbg: rules: __FH_HAS_XMSMAIL merged duplicates: __HAS_MSMAIL_PRI [21619] dbg: rules: __MO_OL_91287 merged duplicates: __MO_OL_B30D1 __MO_OL_CF0C0 [21619] dbg: rules: KAM_STOCKOTC merged duplicates: KAM_STOCKTIP15 KAM_STOCKTIP20 KAM_STOCKTIP21 KAM_STOCKTIP4 KAM_STOCKTIP6 [21619] dbg: rules: __XM_OL_015D5 merged duplicates: __XM_OL_4BF4C __XM_OL_4EEDB __XM_OL_5B79A __XM_OL_9B90B __XM_OL_ADFF7 __XM_OL_B30D1 __XM_OL_B4B40 __XM_OL_BC7E6 __XM_OL_F3B05 __XM_OL_FF5C8 [21619] dbg: rules: __MO_OL_015D5 merged duplicates: __MO_OL_6554A [21619] dbg: rules: __XM_OL_5E7ED merged duplicates: __XM_OL_D03AB [21619] dbg: rules: __MO_OL_22B61 merged duplicates: __MO_OL_4F240 __MO_OL_ADFF7 [21619] dbg: rules: __MO_OL_812FF merged duplicates: __MO_OL_BC7E6 [21619] dbg: rules: __MO_OL_25340 merged duplicates: __MO_OL_4EEDB __MO_OL_7533E [21619] dbg: rules: __MO_OL_58CB5 merged duplicates: __MO_OL_B4B40 [21619] dbg: rules: VIRUS_WARNING128 merged duplicates: __VBOUNCE_MMS [21619] dbg: rules: __DOS_HAS_ANY_URI merged duplicates: __HAS_ANY_URI [21619] dbg: rules: VIRUS_WARNING123 merged duplicates: VIRUS_WARNING37 [21619] dbg: rules: __XM_OL_C7C33 merged duplicates: __XM_OL_C9068 __XM_OL_EF20B [21619] dbg: rules: VIRUS_WARNING107 merged duplicates: __VBOUNCE_AV_RESULTS [21619] dbg: rules: __MO_OL_72641 merged duplicates: __MO_OL_A842E [21619] dbg: rules: __MO_OL_5E7ED merged duplicates: __MO_OL_C7C33 [21619] dbg: rules: VIRUS_WARNING103 merged duplicates: VIRUS_WARNING52 [21619] dbg: rules: __MO_OL_4BF4C merged duplicates: __MO_OL_F6D01 [21619] dbg: rules: __MO_OL_F475E merged duplicates: __MO_OL_FF5C8 [21619] dbg: conf: finish parsing [21619] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0xacd6294) implements 'finish_parsing_end', priority 0 [21619] dbg: replacetags: replacing tags [21619] dbg: replacetags: done replacing tags [21619] dbg: bayes: tie-ing to DB file R/O /etc/MailScanner/bayes/bayes_toks [21619] dbg: bayes: tie-ing to DB file R/O /etc/MailScanner/bayes/bayes_seen [21619] dbg: bayes: found bayes db version 3 [21619] dbg: bayes: DB journal sync: last sync: 1185990006 [21619] dbg: config: score set 2 chosen. [21619] dbg: message: main message type: text/plain [21619] dbg: message: ---- MIME PARSER START ---- [21619] dbg: message: parsing normal part [21619] dbg: message: ---- MIME PARSER END ---- [21619] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0xade1170) implements 'check_start', priority 0 [21619] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0xadbdeac) implements 'check_main', priority 0 [21619] dbg: conf: trusted_networks are not configured; it is recommended that you configure trusted_networks manually [21619] dbg: metadata: X-Spam-Relays-Trusted: [21619] dbg: metadata: X-Spam-Relays-Untrusted: [21619] dbg: metadata: X-Spam-Relays-Internal: [21619] dbg: metadata: X-Spam-Relays-External: [21619] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xb21266c) implements 'extract_metadata', priority 0 [21619] dbg: metadata: X-Relay-Countries: [21619] dbg: message: no encoding detected [21619] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xb21266c) implements 'parsed_metadata', priority 0 [21619] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0xb2707c8) implements 'parsed_metadata', priority 0 [21619] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0xb2a3c28) implements 'parsed_metadata', priority 0 [21619] dbg: dns: is DNS available? 0 [21619] dbg: asn: DNS is not available, skipping ASN checks [21619] dbg: rules: local tests only, ignoring RBL eval [21619] dbg: check: running tests for priority: -1000 [21619] dbg: rules: running head tests; score so far=0 [21619] dbg: rules: compiled head tests [21619] dbg: eval: all '*From' addrs: ignore@compiling.spamassassin.taint.org [21619] dbg: eval: all '*To' addrs: [21619] dbg: rules: running body tests; score so far=0 [21619] dbg: rules: compiled body tests [21619] dbg: rules: running uri tests; score so far=0 [21619] dbg: rules: compiled uri tests [21619] dbg: rules: running rawbody tests; score so far=0 [21619] dbg: rules: compiled rawbody tests [21619] dbg: rules: running full tests; score so far=0 [21619] dbg: rules: compiled full tests [21619] dbg: rules: running meta tests; score so far=0 [21619] dbg: rules: compiled meta tests [21619] dbg: check: running tests for priority: -950 [21619] dbg: rules: running head tests; score so far=0 [21619] dbg: rules: compiled head tests [21619] dbg: rules: running body tests; score so far=0 [21619] dbg: rules: compiled body tests [21619] dbg: rules: running uri tests; score so far=0 [21619] dbg: rules: compiled uri tests [21619] dbg: rules: running rawbody tests; score so far=0 [21619] dbg: rules: compiled rawbody tests [21619] dbg: rules: running full tests; score so far=0 [21619] dbg: rules: compiled full tests [21619] dbg: rules: running meta tests; score so far=0 [21619] dbg: rules: compiled meta tests [21619] dbg: check: running tests for priority: -900 [21619] dbg: rules: running head tests; score so far=0 [21619] dbg: rules: compiled head tests [21619] dbg: rules: running body tests; score so far=0 [21619] dbg: rules: compiled body tests [21619] dbg: rules: running uri tests; score so far=0 [21619] dbg: rules: compiled uri tests [21619] dbg: rules: running rawbody tests; score so far=0 [21619] dbg: rules: compiled rawbody tests [21619] dbg: rules: running full tests; score so far=0 [21619] dbg: rules: compiled full tests [21619] dbg: rules: running meta tests; score so far=0 [21619] dbg: rules: compiled meta tests [21619] dbg: check: running tests for priority: -400 [21619] dbg: rules: running head tests; score so far=0 [21619] dbg: rules: compiled head tests [21619] dbg: rules: running body tests; score so far=0 [21619] dbg: rules: compiled body tests [21619] dbg: rules: running uri tests; score so far=0 [21619] dbg: rules: compiled uri tests [21619] dbg: plugin: Mail::SpamAssassin::Plugin::WLBLEval=HASH(0xb1de9ac) implements 'check_wb_list', priority 0 [21619] dbg: bayes: DB journal sync: last sync: 1185990006 [21619] dbg: bayes: corpus size: nspam = 29392, nham = 72771 [21619] dbg: bayes: score = 0.514551900437487 [21619] dbg: bayes: DB journal sync: last sync: 1185990006 [21619] dbg: bayes: untie-ing [21619] dbg: rules: running rawbody tests; score so far=0 [21619] dbg: rules: compiled rawbody tests [21619] dbg: rules: running full tests; score so far=0 [21619] dbg: rules: compiled full tests [21619] dbg: rules: running meta tests; score so far=0 [21619] dbg: rules: compiled meta tests [21619] dbg: check: running tests for priority: 0 [21619] dbg: rules: running head tests; score so far=0 [21619] dbg: rules: compiled head tests [21619] dbg: rules: ran header rule __MISSING_REF ======> got hit: "UNSET" [21619] dbg: rules: ran header rule __MSOE_MID_WRONG_CASE ======> got hit: " [21619] dbg: rules: Message-Id: " [21619] dbg: rules: ran header rule MISSING_DATE ======> got hit: "UNSET" [21619] dbg: rules: ran header rule __MSGID_OK_HOST ======> got hit: "@lint_rules>" [21619] dbg: rules: ran header rule __MSGID_OK_DIGITS ======> got hit: "1185995043" [21619] dbg: rules: ran header rule __HAS_MSGID ======> got hit: "<" [21619] dbg: rules: ran header rule __SANE_MSGID ======> got hit: "<1185995043@lint_rules> [21619] dbg: rules: " [21619] dbg: spf: checking to see if the message has a Received-SPF header that we can use [21619] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [21619] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [21619] dbg: rules: ran eval rule NO_RELAYS ======> got hit (1) [21619] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [21619] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [21619] dbg: spf: cannot get Envelope-From, cannot use SPF [21619] dbg: spf: def_spf_whitelist_from: could not find useable envelope sender [21619] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [21619] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [21619] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [21619] dbg: rules: ran eval rule __UNUSABLE_MSGID ======> got hit (1) [21619] dbg: spf: spf_whitelist_from: could not find useable envelope sender [21619] dbg: rules: ran eval rule MISSING_HEADERS ======> got hit (1) [21619] dbg: rules: running body tests; score so far=1.5 [21619] dbg: rules: compiled body tests [21619] dbg: rules: ran body rule __NONEMPTY_BODY ======> got hit: "I" [21619] dbg: rules: running uri tests; score so far=1.5 [21619] dbg: rules: compiled uri tests [21619] dbg: https_http_mismatch: anchors 0 [21619] dbg: eval: stock info total: 0 [21619] dbg: rules: ran eval rule BAYES_50 ======> got hit (1) [21619] dbg: rules: running rawbody tests; score so far=1.501 [21619] dbg: rules: compiled rawbody tests [21619] dbg: rules: running full tests; score so far=1.501 [21619] dbg: rules: compiled full tests [21619] dbg: rules: running meta tests; score so far=1.501 [21619] dbg: rules: compiled meta tests [21619] dbg: check: running tests for priority: 500 [21619] dbg: rules: running head tests; score so far=1.501 [21619] dbg: rules: compiled head tests [21619] dbg: rules: running body tests; score so far=1.501 [21619] dbg: rules: compiled body tests [21619] dbg: rules: running uri tests; score so far=1.501 [21619] dbg: rules: compiled uri tests [21619] dbg: rules: running rawbody tests; score so far=1.501 [21619] dbg: rules: compiled rawbody tests [21619] dbg: rules: running full tests; score so far=1.501 [21619] dbg: rules: compiled full tests [21619] dbg: rules: running meta tests; score so far=1.501 [21619] info: rules: meta test FM_DDDD_TIMES_2 has dependency 'FH_HOST_EQ_D_D_D_D' with a zero score [21619] info: rules: meta test FM_SEX_HOSTDDDD has dependency 'FH_HOST_EQ_D_D_D_D' with a zero score [21619] dbg: rules: meta test VIRUS_WARNING_DOOM_BNC has undefined dependency 'VIRUS_WARNING_MYDOOM4' [21619] dbg: rules: compiled meta tests [21619] dbg: check: running tests for priority: 899 [21619] dbg: rules: running head tests; score so far=3.976 [21619] dbg: rules: compiled head tests [21619] dbg: rules: running body tests; score so far=3.976 [21619] dbg: rules: compiled body tests [21619] dbg: rules: running uri tests; score so far=3.976 [21619] dbg: rules: compiled uri tests [21619] dbg: rules: running rawbody tests; score so far=3.976 [21619] dbg: rules: compiled rawbody tests [21619] dbg: rules: running full tests; score so far=3.976 [21619] dbg: rules: compiled full tests [21619] dbg: crm114: call_crm() called, action: check [21619] dbg: info: entering helper-app run mode [21619] dbg: crm114: crm114_command run [21619] dbg: crm114: found version 20070301-BlameBaltar ( 0.6.8 ) MR-BD9991E2 [21619] dbg: crm114: found CacheID sfid-20070801_120406_723057_3BE53491 [21619] dbg: crm114: found status UNSURE and score 0.32 [21619] dbg: crm114: found Notice Please train this message. [21619] dbg: info: leaving helper-app run mode [21619] dbg: crm114: call_crm returns (UNSURE, 0.32) [21619] dbg: crm114: score is 0.3200, translated to SA score: -0.0032, linear factor was -0.0100 [21619] dbg: rules: running meta tests; score so far=3.9728 [21619] dbg: rules: compiled meta tests [21619] dbg: check: running tests for priority: 1000 [21619] dbg: rules: running head tests; score so far=3.9728 [21619] dbg: rules: compiled head tests [21619] dbg: rules: running body tests; score so far=3.9728 [21619] dbg: rules: compiled body tests [21619] dbg: rules: running uri tests; score so far=3.9728 [21619] dbg: rules: compiled uri tests [21619] dbg: rules: running rawbody tests; score so far=3.9728 [21619] dbg: rules: compiled rawbody tests [21619] dbg: rules: running full tests; score so far=3.9728 [21619] dbg: rules: compiled full tests [21619] dbg: rules: running meta tests; score so far=3.9728 [21619] dbg: rules: compiled meta tests [21619] dbg: check: is spam? score=3.973 required=5 [21619] dbg: check: tests=BAYES_50,CRM114_CHECK,MISSING_DATE,MISSING_HEADERS,MISSING_SUBJECT,NO_RECEIVED,NO_RELAYS [21619] dbg: check: subtests=__HAS_MSGID,__MISSING_REF,__MSGID_OK_DIGITS,__MSGID_OK_HOST,__MSOE_MID_WRONG_CASE,__NONEMPTY_BODY,__SANE_MSGID,__UNUSABLE_MSGID UxBoD wrote: > What rules do you have setup ? > > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B > // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B > // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net > > ----- Original Message ----- > From: "Johnny Stork" > To: "MailScanner discussion" > Sent: Wednesday, August 1, 2007 2:57:42 AM (GMT) Europe/London > Subject: Subject Text Not Getting Modified? > > -------------- next part -------------- A non-text attachment was scrubbed... Name: stork.vcf Type: text/x-vcard Size: 330 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070801/d3388636/stork.vcf From MailScanner at ecs.soton.ac.uk Wed Aug 1 20:06:35 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 1 20:07:03 2007 Subject: Random messages stuck in mqueue In-Reply-To: <6439a60f0708011028y72dec553tcf9b5f5f10c85a79@mail.gmail.com> References: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> <6439a60f0708011028y72dec553tcf9b5f5f10c85a79@mail.gmail.com> Message-ID: <46B0D9BB.9030607@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Corey McFadden wrote: > > It does seem as though the problem begins when MailScanner disposes of > a message. Maybe someone could clarify the process whereby Sendmail > picks up the message and decides to deliver it (locally or relay or > whatever.) See my explanation below. The normal setting to use is "Delivery Method = batch". Though for debugging MailScanner, I run no outgoing queue runner process at all, and have "Delivery Method = queue". The result is that processed messages are placed in the outgoing mqueue and no attempt to deliver them is made at all. I can then look at the messages, check whether they are correct and that the development code is working, and then just delete them from the mqueue by hand. I don't want to ever actually deliver these messages, all the information I want is in the df+qf files. > > It doesn't look like a DNS issue. We've got a local resolver (that > has a PTR record for the machine's IP) and a backup resolver. I've > done a number of DNS tests and haven't been able to produce an error > there. It's usually fairly easy to test DNS speed problems with a few "dig" commands for some random domains (most English words .com exist, so picking a random word is usually pretty reliable, and probably won't be in your DNS cache already). > > On other systems everything happens so quickly that it's hard to see > what happens but does it resemble this: > - MailScanner finds message in mqueue.in > - MailScanner processes message and dumps qf/df into mqueue > - Sendmail daemon periodically scans mqueue > > or: > - MailScanner finds message in mqueue.in > - MailScanner processes message and spawns a sendmail process for > delivery It always put the qf/df in the mqueue first. It doesn't directly pass the message text to sendmail, that would involve an extra copy of the message being written down a pipe which slows things down. I try quite hard to make MailScanner as fast and efficient as I can. Which is why I have a full MailScanner+SpamAssassin+ClamAV setup on one box in my office which can process 2.2 million messages per day, on 1 server. > What are the implications of the "Delivery Method" queue vs. batch > option on the above? The explanation below is described for sendmail, but the same basic design applies to all the other supported MTAs as well. They all work in pretty much the same way, more or less. With "Delivery Method = queue" the processed message(s) is placed in the mqueue. That's it. You will then have a sendmail queue runner regularly attempting delivery of everything in the queue that's due for a delivery attempt. So if the outgoing sendmail process is running (ie the queue runner) then delivery will be delayed until the next regular queue run. You can start and stop this bit with "service MailScanner startout" and "service MailScanner stopout". With "Delivery Method = batch" the processed message(s) are placed in the mqueue. Then a "sendmail -qI....." command is then executed, with "....." set to the IDs of the message files just placed in the mqueue. This tells sendmail to immediately make 1 delivery attempt of each message. If this succeeds, the net result is instant message delivery. If it fails, then it is left to be retried by the outgoing sendmail queue runner process, as described above. In cases where the batch is large, measures are taken to ensure that the "sendmail -qI....." command is not too long for the operating system to be able to handle. When there are multiple mqueues in use, a separate "sendmail -qI....." command is issued for the messages in each outgoing queue, so that delivery of all messages is attempted, regardless of the number of outgoing queues they are spread across. This is needed as the mqueue directory can be specified by a ruleset or Custom Function, allowing you to use different queue runner parameters for each of several queues (e.g. a fast queue runner for local or small messages, with a slower one for remote or large messages, for example). Hopefully that explains what happens in full detail. > > Thanks for the input! > > -Corey > > > > > On 8/1/07, * Scott Silva* > wrote: > > Corey McFadden spake the following on 7/31/2007 9:46 PM: > > > > Guys, > > > > We're experiencing an issue on one of our boxes where messages > (a good > > percentage) are hung in /var/spool/mqueue after being processed by > > MailScanner. Even those to be delivered locally will sit for > > (sometimes) hours until they're finally delivered. > > > > I've never seen this behavior before and something is definitely > awry. > > > > Here's the environment: > > > > This is CentOS release 4.5 (Final) > > This is Perl version 5.008008 (5.8.8) > > > > This is MailScanner version 4.61.7 > > > > Executing 'sendmail -q -v' WILL process the stuck messages but > can take > > quite a long time to run because it will try to deliver everything > > queued in a linear fashion. > > > Since it is in mqueue and not mqueue.in , > mailscanner is pretty much out of the > loop. Check if you have a FQDN that resolves properly as this will > choke > sendmail quickly. Also try a local caching nameserver, as sendmail > might be > taking a long time to resolve delivery addresses. > > -- > > MailScanner is like deodorant... > You hope everybody uses it, and > you notice quickly if they don't!!!! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > > Support MailScanner development - buy the book off the website! > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGsNm8EfZZRxQVtlQRAuAWAJ9bWzKisXCEcEeJGZ5TrFdMcBFAKgCcCMjh gmylU66oi8Mi4/pxd+5q+wg= =Sru3 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Wed Aug 1 20:16:07 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Aug 1 20:16:30 2007 Subject: Random messages stuck in mqueue In-Reply-To: <6439a60f0708011028y72dec553tcf9b5f5f10c85a79@mail.gmail.com> References: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> <6439a60f0708011028y72dec553tcf9b5f5f10c85a79@mail.gmail.com> Message-ID: Corey McFadden spake the following on 8/1/2007 10:28 AM: > > It does seem as though the problem begins when MailScanner disposes of a > message. Maybe someone could clarify the process whereby Sendmail picks > up the message and decides to deliver it (locally or relay or whatever.) > > It doesn't look like a DNS issue. We've got a local resolver (that has > a PTR record for the machine's IP) and a backup resolver. I've done a > number of DNS tests and haven't been able to produce an error there. > > On other systems everything happens so quickly that it's hard to see > what happens but does it resemble this: > - MailScanner finds message in mqueue.in -- but not with http --strike > - MailScanner processes message and dumps qf/df into mqueue > - Sendmail daemon periodically scans mqueue This is the queue delivery method > > or: > - MailScanner finds message in mqueue.in MailScanner processes message and drops qf/df into mqueue Then calls a sendmail process to process mqueue This is the batch method > > > What are the implications of the "Delivery Method" queue vs. batch > option on the above? The batch method might be faster on the delivery, as the queue method queue runner looks to be set at 15 minutes. It depends on how much mail you process. > > Thanks for the input! > > -Corey -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From MailScanner at ecs.soton.ac.uk Wed Aug 1 20:20:26 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 1 20:21:01 2007 Subject: Subject Text Not Getting Modified? In-Reply-To: <46B0D988.806@openenterprise.ca> References: <17305916.8541185954848518.JavaMail.root@office.splatnix.net> <46B0D988.806@openenterprise.ca> Message-ID: <46B0DCFA.7070508@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Have you run "upgrade_MailScanner_conf" and "upgrade_languages_conf" and "MailScanner --lint" ? Johnny Stork wrote: > Sorry for my ignorance, I had setup MS over a year ago and after > spending some time setting it up to where I "beleive" I had everything > workin, I have not really touched it since. So after getting CRM114 > installed I went and upgraded to the newest version. > > So I went and ran the install-Clam-0.91.1-SA-3.2.2.tar.gz to also > update clam and SA. They were not that far behind. When this upgrade > finished, since I had been running rulesdujour, when it finished the > script indicated I needed to install rulesdujour. But I also just > heard that RDJ is not longer working/supported and I should use > sa_update so this was my first bit of confusion. > > So I downloaded the latest rulesdujour and ran the installer but it > bailed claiming lint errors. I managed to find these as outdated cf > files (rules) and so was able to finish the RDJ install. I also > noticed that all the cf files in /etc/mail/spamassasin got moved to > /etc/mail/spamassasin/old_cf_files? > > I then ran the mailscanner install to upgrade to4.62.9. > > At this point I am not certain I have everything configured and > working properly and dont know where to begin cleaning things up. I > would not expect anyone to help with this cause it is certainly my > mess. It is running, and seems to be working but I am not certain I > have things like RDJ and/or sa_update working correctly or which rules > are valid. If you would be willing/interested in taking a look I would > be greatful. You have already been a great help so I would not expect > any more. > > I do see many new items/rules etc and a couple of strange errors in > the lint test though. Below is the lint: > > > > > > > > > UxBoD wrote: >> What rules do you have setup ? >> >> Regards, >> >> --[ UxBoD ]-- >> // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" >> // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B >> // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B >> // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net >> >> ----- Original Message ----- >> From: "Johnny Stork" >> To: "MailScanner discussion" >> Sent: Wednesday, August 1, 2007 2:57:42 AM (GMT) Europe/London >> Subject: Subject Text Not Getting Modified? >> >> > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGsNz7EfZZRxQVtlQRAu8GAJ9YSq0srCtPbynvFhyDK1yP8kI9OQCgzTAE rdOvJlENaB15yDEQZw6nTPc= =DuNF -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From rcooper at dwford.com Wed Aug 1 20:32:02 2007 From: rcooper at dwford.com (Rick Cooper) Date: Wed Aug 1 20:32:08 2007 Subject: CRM114 Installation on Centos 4 In-Reply-To: References: <223f97700708010137x7247cffax3bab65f1a95088a8@mail.gmail.com><7247337.8661185958645314.JavaMail.root@office.splatnix.net> <01b801c7d45e$0b86b3a0$0301a8c0@SAHOMELT> Message-ID: <022401c7d472$a2e07dd0$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On > Behalf Of Scott Silva > Sent: Wednesday, August 01, 2007 1:40 PM > To: mailscanner@lists.mailscanner.info > Subject: Re: CRM114 Installation on Centos 4 > > Rick Cooper spake the following on 8/1/2007 10:04 AM: [...] > > Something some one might want to add : > > > > On my perl 5.8.0 installations when you lint spamassassin > you get a warning > > about sprintf using an unitialized value at crm114.pm line > 235 and if you > > look at line 235 > > > > warn(sprintf("crm114: Error: %s"), $1); > > > > Should be > > > > warn(sprintf("crm114: Error: %s", $1)); > > > > And that change removes the warning. It doesn't happen > with perl 5.8.8 > > though > > > > Rick > Perl 5.8.0 is quite old, but RHEL3 (and CentOS3) are using > it, and will be > still supported for another year or two. Does that change > work with newer perls? > Maybe it should be passed up to crm114 writer. > -- Yes 5.8.8 accepts it fine, if you look closely at the sprintf statement it's malformed so I am not sure why my 5.8.8 installations didn't yak on it as well. The original source isn't in the form of sprintf("text with format code",$variable) it has the ')' before the ', $variable'. I have sent a note to the author. It didn't cause the program to bail, but it's pretty annoying and (I could be mistaken) obviously incorrect. Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From stork at openenterprise.ca Wed Aug 1 20:39:52 2007 From: stork at openenterprise.ca (Johnny Stork) Date: Wed Aug 1 20:39:56 2007 Subject: Subject Text Not Getting Modified? In-Reply-To: <46B0DCFA.7070508@ecs.soton.ac.uk> References: <17305916.8541185954848518.JavaMail.root@office.splatnix.net> <46B0D988.806@openenterprise.ca> <46B0DCFA.7070508@ecs.soton.ac.uk> Message-ID: <46B0E188.3000207@openenterprise.ca> Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: stork.vcf Type: text/x-vcard Size: 330 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070801/5db82aca/stork.vcf From MailScanner at ecs.soton.ac.uk Wed Aug 1 20:50:16 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 1 20:50:45 2007 Subject: Subject Text Not Getting Modified? In-Reply-To: <46B0E188.3000207@openenterprise.ca> References: <17305916.8541185954848518.JavaMail.root@office.splatnix.net> <46B0D988.806@openenterprise.ca> <46B0DCFA.7070508@ecs.soton.ac.uk> <46B0E188.3000207@openenterprise.ca> Message-ID: <46B0E3F8.3090607@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Johnny Stork wrote: > Yes I did run the "upgrade_MailScanner_conf" and followed the instr. > But I seem to recall not running that languages one, and cant seem to > now since I dont see an " languages.conf.rpmnew" in > /etc/MailScanner/reports/en. > > I didnt know about"MailScanner --lint" ...but below is the output. I > can certainly fix the first error. > > The main questions I have are.... > > 1: Whether I should use both sa_update and RDJ sa-update preferably. Search the mailing list archive for "HOWTO" in the subject line, and you'll find the docs explaining how to do it. > > 2: If either are setup correctly. sa-update will put the new rules elsewhere (i.e. not in /etc/mail/spamassassin). Don't worry, SpamAssassin will find them. Take a look in /etc/cron.daily and check the code at the top of update_spamassassin and clean.quarantine to make sure they aren't disabled. It's obvious, don't worry. > > 3: Do I have a reasonably optimized/configured setup with proper > RBLS's and rules all setup > > > > root@gateway:/etc/MailScanner/reports/en# MailScanner --lint > Checking version numbers... > Version number in MailScanner.conf (4.62.9) is correct. > > ERROR: The "envelope_sender_header" in your spam.assassin.prefs.conf > ERROR: is not correct, it should match > X-Johnny_Storks_Home_Page-MailScanner-From > > > Checking for SpamAssassin errors (if you use it)... > SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp > SpamAssassin reported no errors. > MailScanner.conf says "Virus Scanners = clamd" > Found these virus scanners installed: clamavmodule, clamd > =========================================================================== > Ignore errors about failing to find EOCD signature > format error: can't find EOCD signature > at /usr/sbin/MailScanner line 450 > =========================================================================== > Virus Scanner test reports: > Clamd said "eicar.com was infected: Eicar-Test-Signature FOUND" > > If any of your virus scanners (clamavmodule,clamd) > are not listed there, you should check that they are installed correctly > and that MailScanner is finding them correctly via its > virus.scanners.conf. > > > > > Julian Field wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> Have you run "upgrade_MailScanner_conf" and "upgrade_languages_conf" and >> "MailScanner --lint" ? >> >> Johnny Stork wrote: >> >>> Sorry for my ignorance, I had setup MS over a year ago and after >>> spending some time setting it up to where I "beleive" I had everything >>> workin, I have not really touched it since. So after getting CRM114 >>> installed I went and upgraded to the newest version. >>> >>> So I went and ran the install-Clam-0.91.1-SA-3.2.2.tar.gz to also >>> update clam and SA. They were not that far behind. When this upgrade >>> finished, since I had been running rulesdujour, when it finished the >>> script indicated I needed to install rulesdujour. But I also just >>> heard that RDJ is not longer working/supported and I should use >>> sa_update so this was my first bit of confusion. >>> >>> So I downloaded the latest rulesdujour and ran the installer but it >>> bailed claiming lint errors. I managed to find these as outdated cf >>> files (rules) and so was able to finish the RDJ install. I also >>> noticed that all the cf files in /etc/mail/spamassasin got moved to >>> /etc/mail/spamassasin/old_cf_files? >>> >>> I then ran the mailscanner install to upgrade to4.62.9. >>> >>> At this point I am not certain I have everything configured and >>> working properly and dont know where to begin cleaning things up. I >>> would not expect anyone to help with this cause it is certainly my >>> mess. It is running, and seems to be working but I am not certain I >>> have things like RDJ and/or sa_update working correctly or which rules >>> are valid. If you would be willing/interested in taking a look I would >>> be greatful. You have already been a great help so I would not expect >>> any more. >>> >>> I do see many new items/rules etc and a couple of strange errors in >>> the lint test though. Below is the lint: >>> >>> >>> >>> >>> >>> >>> >>> >>> UxBoD wrote: >>> >>>> What rules do you have setup ? >>>> >>>> Regards, >>>> >>>> --[ UxBoD ]-- >>>> Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGsOP5EfZZRxQVtlQRArF7AJ90UYQwy3aX6jJq1hwZXMXlzkSqLwCfee2H ACgG6sAX21k5NmmNU88ujPA= =Htil -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From uxbod at splatnix.net Wed Aug 1 21:10:35 2007 From: uxbod at splatnix.net (UxBoD) Date: Wed Aug 1 21:05:22 2007 Subject: Subject Text Not Getting Modified? In-Reply-To: <46B0E188.3000207@openenterprise.ca> Message-ID: <672653.9591185999035308.JavaMail.root@office.splatnix.net> IMHO I would make a note of the main settings that have been changed in MailScanner.conf, virus.scanners.conf and spam.assassin.prefs.conf plus any MS rules you have setup. And then tidy up the installation and start fresh with the latest release after cleaning down the directories. I would certainly do aware with RDJ and use the facility available within sa-update as you can download the SARE rules via a channel. I know others may frown on this approach, but I believe to get a full grasp of the setup this would be a good approach. Just my 2p worth. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From rcooper at dwford.com Wed Aug 1 21:18:18 2007 From: rcooper at dwford.com (Rick Cooper) Date: Wed Aug 1 21:18:23 2007 Subject: CRM114 False Negatives Message-ID: <023401c7d479$198a16c0$0301a8c0@SAHOMELT> Ok, I have been pretty quiet amidst the whole CRM114 thread because I installed this a couple weeks ago and turned it off because of false negative issues. I turned it back on a tried again but here is the issue I have. If CRM learns a message as ham nothing I have done will cause it to unlearn the message as ham and relearn as spam. I have tried all the recommended ways of using mailreaver, etc and I have even seen (in verbose mode) mailreaver say it learned as spam but if I rerun the same message I still have CRM reporting as good (with scores as high as +40!). Does anyone have a definite method of re-learning ham as spam? (yes I have used spamassassin --report also) Rick Cooper -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From uxbod at splatnix.net Wed Aug 1 21:27:01 2007 From: uxbod at splatnix.net (UxBoD) Date: Wed Aug 1 21:21:45 2007 Subject: MS Hanging Message-ID: <22697775.9621186000021119.JavaMail.root@office.splatnix.net> Today, our secondary MX, was hit by a large SPAM storm. The message subject was all the same so I presume a new set of bots was unleashed. Anyway, I saw the inbound queue jump up to 1000, and MailScanner stop logging anything too /var/log/maillog. I reloaded MS and it began to process again. After getting through ~ 250 messages it started building up again. I checked running processes and all the MS processes were running, but they all said Checking SPAM lists. My settings are the same on both primary and secondary, the only difference being hardware processing power. Primary is a dual Opteron 8GB RAM, children set @ 20 with a 100 message batch size and all okay. Secondary is single P4 with 1GB RAM, children set @ 5 with a 25 message batch size. Has anybody seen this before? We have ordered a matching server to replace the secondary but that is on a two week lead time. Any ideas? I will run a strace tomorrow if it happens again to see where it is sticking. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From uxbod at splatnix.net Wed Aug 1 21:43:24 2007 From: uxbod at splatnix.net (UxBoD) Date: Wed Aug 1 21:38:07 2007 Subject: CRM114 False Negatives In-Reply-To: <023401c7d479$198a16c0$0301a8c0@SAHOMELT> Message-ID: <21613556.9651186001004647.JavaMail.root@office.splatnix.net> What version of CRM are you running Rick. I haven't seen this behaviour (yet). Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Rick Cooper" To: "MailScanner List" Sent: Wednesday, August 1, 2007 9:18:18 PM (GMT) Europe/London Subject: CRM114 False Negatives Ok, I have been pretty quiet amidst the whole CRM114 thread because I installed this a couple weeks ago and turned it off because of false negative issues. I turned it back on a tried again but here is the issue I have. If CRM learns a message as ham nothing I have done will cause it to unlearn the message as ham and relearn as spam. I have tried all the recommended ways of using mailreaver, etc and I have even seen (in verbose mode) mailreaver say it learned as spam but if I rerun the same message I still have CRM reporting as good (with scores as high as +40!). Does anyone have a definite method of re-learning ham as spam? (yes I have used spamassassin --report also) Rick Cooper -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From glenn.steen at gmail.com Wed Aug 1 22:03:11 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 1 22:03:14 2007 Subject: OT: CRM114 How are you finding it ? In-Reply-To: <20546691.9531185983521679.JavaMail.root@office.splatnix.net> References: <223f97700708010830l2a691234x9c325e7bf197d8b5@mail.gmail.com> <20546691.9531185983521679.JavaMail.root@office.splatnix.net> Message-ID: <223f97700708011403t13365af8j6cf52cd032f6c34f@mail.gmail.com> On 01/08/07, UxBoD wrote: > > :( Glenn. Why not set the following in crm114.cf :- > > crm114_staticscore_good -0.1 > crm114_staticscore_unsure 0.0 > crm114_staticscore_spam 0.1 > > That way you can check for potential FPs, and still allow it to learn. > > Regards, > > More a question of "When I find the time to not just dunk it in, but > actually read (and understand) the docs";-). Thanks for doing that for me:-). It'll be back tomorrow... Along with the PF lint patch from Jules... Now, it's bedtime(!) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070801/a143b85b/attachment.html From theodrake at comcast.net Wed Aug 1 22:06:02 2007 From: theodrake at comcast.net (Ed Bruce) Date: Wed Aug 1 22:06:17 2007 Subject: CRM114 How are you finding it ? In-Reply-To: <1951DC816E1A9F469307B05FA183F4389DC9E0@corpatsmail1.corp.sensis.com> References: <1951DC816E1A9F469307B05FA183F4389DC9E0@corpatsmail1.corp.sensis.com> Message-ID: <46B0F5BA.3050708@comcast.net> Desai, Jason wrote: > > >> Too soon to tell, really. >> >> Only been running it for 21 hours so far. >> >> It's pushed some emails into the high-scoring range, but >> scored negative >> points on some obvious spam (but not enough to make it end up >> in users' >> inboxes). >> >> So far so good. > > Same here. I'm running it with > > crm114_dynscore_factor -0.01 > > I'll probably let it run like this for a week or so, and then see how > it's doing before changing the factor. > > Possibly useful to some - I'm using this to analyze the scores (watch > the line wraps): > > grep CRM114_CHECK /var/log/mail.log | sed -re "s/.*: Message > ([A-Za-z0-9-]+) .*\bscore=([0-9.-]+), .*\bCRM114_CHECK > ([0-9.-]+).*/Id:\1\tSA Score:\2\t\tCRM114 Score:\3 /" > > > This will go through your mail log and print output for messages scored > with CRM114 in the format: For future reference with what MTA does this work? It does not work with Postfix. From glenn.steen at gmail.com Wed Aug 1 22:10:43 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 1 22:10:45 2007 Subject: MS Hanging In-Reply-To: <22697775.9621186000021119.JavaMail.root@office.splatnix.net> References: <22697775.9621186000021119.JavaMail.root@office.splatnix.net> Message-ID: <223f97700708011410g78c67c0teb435851be007532@mail.gmail.com> On 01/08/07, UxBoD wrote: > > Today, our secondary MX, was hit by a large SPAM storm. The message > subject was all the same so I presume a new set of bots was unleashed. > > Anyway, I saw the inbound queue jump up to 1000, and MailScanner stop > logging anything too /var/log/maillog. I reloaded MS and it began to > process again. After getting through ~ 250 messages it started building up > again. I checked running processes and all the MS processes were running, > but they all said Checking SPAM lists. > > My settings are the same on both primary and secondary, the only > difference being hardware processing power. > > Primary is a dual Opteron 8GB RAM, children set @ 20 with a 100 message > batch size and all okay. Secondary is single P4 with 1GB RAM, children set > @ 5 with a 25 message batch size. > > Has anybody seen this before? We have ordered a matching server to > replace the secondary but that is on a two week lead time. Any ideas? > > I will run a strace tomorrow if it happens again to see where it is > sticking. > > Regards, Haven't seen this particular incarnation, but... What you describe is a bit reminiscent of the old "I've got some non-queue file in the hold queue, and MS just .... hangs...", wouldn't you agree? So look for anything non-PF-queuefile-like in the hold queue. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070801/d327556b/attachment-0001.html From ssilva at sgvwater.com Wed Aug 1 22:13:18 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Aug 1 22:13:38 2007 Subject: MS Hanging In-Reply-To: <22697775.9621186000021119.JavaMail.root@office.splatnix.net> References: <22697775.9621186000021119.JavaMail.root@office.splatnix.net> Message-ID: UxBoD spake the following on 8/1/2007 1:27 PM: > Today, our secondary MX, was hit by a large SPAM storm. The message subject was all the same so I presume a new set of bots was unleashed. > > Anyway, I saw the inbound queue jump up to 1000, and MailScanner stop logging anything too /var/log/maillog. I reloaded MS and it began to process again. After getting through ~ 250 messages it started building up again. I checked running processes and all the MS processes were running, but they all said Checking SPAM lists. > > My settings are the same on both primary and secondary, the only difference being hardware processing power. > > Primary is a dual Opteron 8GB RAM, children set @ 20 with a 100 message batch size and all okay. Secondary is single P4 with 1GB RAM, children set @ 5 with a 25 message batch size. > > Has anybody seen this before? We have ordered a matching server to replace the secondary but that is on a two week lead time. Any ideas? > > I will run a strace tomorrow if it happens again to see where it is sticking. > > Regards, > Are you running any optimizations on the servers, like dnsbl's on the MTA or greylisting? Anything that might stop stuff before it gets to the queue will benefit you. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From MailScanner at ecs.soton.ac.uk Wed Aug 1 22:13:38 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 1 22:14:25 2007 Subject: Subject Text Not Getting Modified? In-Reply-To: <672653.9591185999035308.JavaMail.root@office.splatnix.net> References: <672653.9591185999035308.JavaMail.root@office.splatnix.net> Message-ID: <46B0F782.7010406@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 UxBoD wrote: > IMHO I would make a note of the main settings that have been changed in MailScanner.conf, Run "MailScanner --changed" to get this. > virus.scanners.conf and spam.assassin.prefs.conf plus any MS rules you have setup. And then tidy up the installation and start fresh with the latest release after cleaning down the directories. > > I would certainly do aware with RDJ and use the facility available within sa-update as you can download the SARE rules via a channel. > > I know others may frown on this approach, but I believe to get a full grasp of the setup this would be a good approach. > > Just my 2p worth. > > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B > // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B > // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: UTF-8 wj8DBQFGsPeCEfZZRxQVtlQRAsZIAJ4p7G0PNAD29HeNkoXnDH2x+LOm3gCg2ZK1 R0xPsGxWuX5IxMlpL5se2qI= =e4i1 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Wed Aug 1 22:15:26 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Aug 1 22:20:06 2007 Subject: CRM114 How are you finding it ? In-Reply-To: <46B0F5BA.3050708@comcast.net> References: <1951DC816E1A9F469307B05FA183F4389DC9E0@corpatsmail1.corp.sensis.com> <46B0F5BA.3050708@comcast.net> Message-ID: Ed Bruce spake the following on 8/1/2007 2:06 PM: > Desai, Jason wrote: >> >> >>> Too soon to tell, really. >>> >>> Only been running it for 21 hours so far. >>> >>> It's pushed some emails into the high-scoring range, but >>> scored negative >>> points on some obvious spam (but not enough to make it end up >>> in users' >>> inboxes). >>> >>> So far so good. >> Same here. I'm running it with >> >> crm114_dynscore_factor -0.01 >> >> I'll probably let it run like this for a week or so, and then see how >> it's doing before changing the factor. >> >> Possibly useful to some - I'm using this to analyze the scores (watch >> the line wraps): >> >> grep CRM114_CHECK /var/log/mail.log | sed -re "s/.*: Message >> ([A-Za-z0-9-]+) .*\bscore=([0-9.-]+), .*\bCRM114_CHECK >> ([0-9.-]+).*/Id:\1\tSA Score:\2\t\tCRM114 Score:\3 /" >> >> >> This will go through your mail log and print output for messages scored >> with CRM114 in the format: > > For future reference with what MTA does this work? It does not work with > Postfix. Did you fix the initial path to your maillog, as mail.log might not be correct for you. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From matt at coders.co.uk Wed Aug 1 22:31:12 2007 From: matt at coders.co.uk (Matt Hampton) Date: Wed Aug 1 22:28:40 2007 Subject: CRM114 How are you finding it ? In-Reply-To: <1951DC816E1A9F469307B05FA183F4389DC9E0@corpatsmail1.corp.sensis.com> References: <1951DC816E1A9F469307B05FA183F4389DC9E0@corpatsmail1.corp.sensis.com> Message-ID: <46B0FBA0.6060601@coders.co.uk> Desai, Jason wrote: > > >> Too soon to tell, really. >> >> Only been running it for 21 hours so far. >> Taking the idea behind Jason's script and switching it to perl (download from http://www.coders.co.uk/crm.txt and run it catting your maillog in to STDIN) My recent stats (don't know time period) Total Messages: 1286 How many times was CRM114 wrong? False Negative: 21 (1.63%) False Positive: 22 (1.71%) Total Errors: 43 (3.34%) How many times did CRM114 cause an error? False Negative: 2 (0.15%) False Positive: 0 (0%) Total Errors: 2 (0.15%) This was with NO training and autolearn turned on with default values matt From matt at coders.co.uk Wed Aug 1 22:50:29 2007 From: matt at coders.co.uk (Matt Hampton) Date: Wed Aug 1 22:48:24 2007 Subject: Random messages stuck in mqueue In-Reply-To: <6439a60f0708011044j95116e5jceae6e8f485632be@mail.gmail.com> References: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> <46B0C2C5.4010909@jfworks.net> <6439a60f0708011044j95116e5jceae6e8f485632be@mail.gmail.com> Message-ID: <46B10025.70208@coders.co.uk> Corey McFadden wrote: > > Well, in this case sendmail hasn't attempted delivery so it's definitely > something in the box itself. (You can confirm the number of attempts, > as well as the timestamp of the last sendmail attempt by looking at the > qfXXXXXX file.) > what do you get when you do a "mailq"... matt From cmcfadden01 at gmail.com Wed Aug 1 22:55:01 2007 From: cmcfadden01 at gmail.com (Corey McFadden) Date: Wed Aug 1 22:55:05 2007 Subject: Random messages stuck in mqueue In-Reply-To: <46B10025.70208@coders.co.uk> References: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> <46B0C2C5.4010909@jfworks.net> <6439a60f0708011044j95116e5jceae6e8f485632be@mail.gmail.com> <46B10025.70208@coders.co.uk> Message-ID: <6439a60f0708011455u472affd1u658498e31df1f82f@mail.gmail.com> Matt, mailq will display the messages in the mqueue folder. (All the messages, including those that haven't been processed.) -Corey On 8/1/07, Matt Hampton wrote: > > Corey McFadden wrote: > > > > Well, in this case sendmail hasn't attempted delivery so it's definitely > > something in the box itself. (You can confirm the number of attempts, > > as well as the timestamp of the last sendmail attempt by looking at the > > qfXXXXXX file.) > > > > what do you get when you do a "mailq"... > > matt > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070801/2fa65b4e/attachment.html From cmcfadden01 at gmail.com Wed Aug 1 23:01:06 2007 From: cmcfadden01 at gmail.com (Corey McFadden) Date: Wed Aug 1 23:01:09 2007 Subject: Random messages stuck in mqueue In-Reply-To: <46B0D9BB.9030607@ecs.soton.ac.uk> References: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> <6439a60f0708011028y72dec553tcf9b5f5f10c85a79@mail.gmail.com> <46B0D9BB.9030607@ecs.soton.ac.uk> Message-ID: <6439a60f0708011501i395a58f2rb7d47424d8e5f1f9@mail.gmail.com> Julian, Thanks for the clarification on the Delivery Method behavior. What you're saying makes a lot of sense and seems the optimal way to deliver the best results under normal circumstances. It's starting to look like it may be a DNS issue after all. The server has a local DNS resolver bound to its IP address and configured via /etc/resolv.conf. All DNS tests performed in the shell were very clean. It seems though that sendmail (for whatever reason and despite its lack of presence in resolv.conf) is attempting (on occasion) to talk to localhost. About an hour ago I modified the bind configuration to listen on everything and it seems like things may be improving. Thanks for all the responses on this guys. I'll monitor this box for a few hours and see what happens. -Corey On 8/1/07, Julian Field wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Corey McFadden wrote: > > > > It does seem as though the problem begins when MailScanner disposes of > > a message. Maybe someone could clarify the process whereby Sendmail > > picks up the message and decides to deliver it (locally or relay or > > whatever.) > See my explanation below. The normal setting to use is "Delivery Method > = batch". Though for debugging MailScanner, I run no outgoing queue > runner process at all, and have "Delivery Method = queue". The result is > that processed messages are placed in the outgoing mqueue and no attempt > to deliver them is made at all. I can then look at the messages, check > whether they are correct and that the development code is working, and > then just delete them from the mqueue by hand. I don't want to ever > actually deliver these messages, all the information I want is in the > df+qf files. > > > > It doesn't look like a DNS issue. We've got a local resolver (that > > has a PTR record for the machine's IP) and a backup resolver. I've > > done a number of DNS tests and haven't been able to produce an error > > there. > It's usually fairly easy to test DNS speed problems with a few "dig" > commands for some random domains (most English words .com exist, so > picking a random word is usually pretty reliable, and probably won't be > in your DNS cache already). > > > > On other systems everything happens so quickly that it's hard to see > > what happens but does it resemble this: > > - MailScanner finds message in mqueue.in > > - MailScanner processes message and dumps qf/df into mqueue > > - Sendmail daemon periodically scans mqueue > > > > or: > > - MailScanner finds message in mqueue.in > > - MailScanner processes message and spawns a sendmail process for > > delivery > It always put the qf/df in the mqueue first. It doesn't directly pass > the message text to sendmail, that would involve an extra copy of the > message being written down a pipe which slows things down. I try quite > hard to make MailScanner as fast and efficient as I can. Which is why I > have a full MailScanner+SpamAssassin+ClamAV setup on one box in my > office which can process 2.2 million messages per day, on 1 server. > > What are the implications of the "Delivery Method" queue vs. batch > > option on the above? > The explanation below is described for sendmail, but the same basic > design applies to all the other supported MTAs as well. They all work in > pretty much the same way, more or less. > > With "Delivery Method = queue" the processed message(s) is placed in the > mqueue. That's it. You will then have a sendmail queue runner regularly > attempting delivery of everything in the queue that's due for a delivery > attempt. So if the outgoing sendmail process is running (ie the queue > runner) then delivery will be delayed until the next regular queue run. > You can start and stop this bit with "service MailScanner startout" and > "service MailScanner stopout". > > With "Delivery Method = batch" the processed message(s) are placed in > the mqueue. Then a "sendmail -qI....." command is then executed, with > "....." set to the IDs of the message files just placed in the mqueue. > This tells sendmail to immediately make 1 delivery attempt of each > message. If this succeeds, the net result is instant message delivery. > If it fails, then it is left to be retried by the outgoing sendmail > queue runner process, as described above. In cases where the batch is > large, measures are taken to ensure that the "sendmail -qI....." command > is not too long for the operating system to be able to handle. When > there are multiple mqueues in use, a separate "sendmail -qI....." > command is issued for the messages in each outgoing queue, so that > delivery of all messages is attempted, regardless of the number of > outgoing queues they are spread across. This is needed as the mqueue > directory can be specified by a ruleset or Custom Function, allowing you > to use different queue runner parameters for each of several queues > (e.g. a fast queue runner for local or small messages, with a slower one > for remote or large messages, for example). > > Hopefully that explains what happens in full detail. > > > > > Thanks for the input! > > > > -Corey > > > > > > > > > > On 8/1/07, * Scott Silva* > > wrote: > > > > Corey McFadden spake the following on 7/31/2007 9:46 PM: > > > > > > Guys, > > > > > > We're experiencing an issue on one of our boxes where messages > > (a good > > > percentage) are hung in /var/spool/mqueue after being processed by > > > MailScanner. Even those to be delivered locally will sit for > > > (sometimes) hours until they're finally delivered. > > > > > > I've never seen this behavior before and something is definitely > > awry. > > > > > > Here's the environment: > > > > > > This is CentOS release 4.5 (Final) > > > This is Perl version 5.008008 (5.8.8) > > > > > > This is MailScanner version 4.61.7 > > > > > > Executing 'sendmail -q -v' WILL process the stuck messages but > > can take > > > quite a long time to run because it will try to deliver everything > > > queued in a linear fashion. > > > > > Since it is in mqueue and not mqueue.in , > > mailscanner is pretty much out of the > > loop. Check if you have a FQDN that resolves properly as this will > > choke > > sendmail quickly. Also try a local caching nameserver, as sendmail > > might be > > taking a long time to resolve delivery addresses. > > > > -- > > > > MailScanner is like deodorant... > > You hope everybody uses it, and > > you notice quickly if they don't!!!! > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > > > > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.2 (Build 2014) > Charset: ISO-8859-1 > > wj8DBQFGsNm8EfZZRxQVtlQRAuAWAJ9bWzKisXCEcEeJGZ5TrFdMcBFAKgCcCMjh > gmylU66oi8Mi4/pxd+5q+wg= > =Sru3 > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070801/379bf9b1/attachment.html From matt at coders.co.uk Wed Aug 1 23:04:34 2007 From: matt at coders.co.uk (Matt Hampton) Date: Wed Aug 1 23:01:53 2007 Subject: Random messages stuck in mqueue In-Reply-To: <6439a60f0708011455u472affd1u658498e31df1f82f@mail.gmail.com> References: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> <46B0C2C5.4010909@jfworks.net> <6439a60f0708011044j95116e5jceae6e8f485632be@mail.gmail.com> <46B10025.70208@coders.co.uk> <6439a60f0708011455u472affd1u658498e31df1f82f@mail.gmail.com> Message-ID: <46B10372.5080802@coders.co.uk> Corey McFadden wrote: > Matt, > > mailq will display the messages in the mqueue folder. (All the > messages, including those that haven't been processed.) > Yes but inbound messages are in mqueue.in which is not the standard location. So you only see the messages waiting for delivery matt From cmcfadden01 at gmail.com Wed Aug 1 23:11:37 2007 From: cmcfadden01 at gmail.com (Corey McFadden) Date: Wed Aug 1 23:11:41 2007 Subject: Random messages stuck in mqueue In-Reply-To: <46B10372.5080802@coders.co.uk> References: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> <46B0C2C5.4010909@jfworks.net> <6439a60f0708011044j95116e5jceae6e8f485632be@mail.gmail.com> <46B10025.70208@coders.co.uk> <6439a60f0708011455u472affd1u658498e31df1f82f@mail.gmail.com> <46B10372.5080802@coders.co.uk> Message-ID: <6439a60f0708011511l6cdbe595wbcd965c2ee70e613@mail.gmail.com> Matt, Sorry for the confusion. When I said "hadn't been processed" I meant "hadn't been processed by sendmail". Everything in mqueue.in is being properly handled by MailScanner. mailq shows the contents of /var/spool/mqueue Anyhow, I'm monitoring the effects of a change to the DNS resolver to see if it has an effect and will reply to this thread with an update. Thanks again, -Corey On 8/1/07, Matt Hampton wrote: > > Corey McFadden wrote: > > Matt, > > > > mailq will display the messages in the mqueue folder. (All the > > messages, including those that haven't been processed.) > > > > Yes but inbound messages are in mqueue.in which is not the standard > location. > > So you only see the messages waiting for delivery > > matt > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070801/0d0fb628/attachment.html From rcooper at dwford.com Wed Aug 1 23:16:04 2007 From: rcooper at dwford.com (Rick Cooper) Date: Wed Aug 1 23:16:07 2007 Subject: CRM114 False Negatives In-Reply-To: <21613556.9651186001004647.JavaMail.root@office.splatnix.net> References: <023401c7d479$198a16c0$0301a8c0@SAHOMELT> <21613556.9651186001004647.JavaMail.root@office.splatnix.net> Message-ID: <025001c7d489$8d25c7e0$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On > Behalf Of UxBoD > Sent: Wednesday, August 01, 2007 4:43 PM > To: MailScanner discussion > Subject: Re: CRM114 False Negatives > > What version of CRM are you running Rick. I haven't seen > this behaviour (yet). > 0.4.20070301 I thought if I sat back and waited a while someone else might run into this and figure it out. One thing I hate about crm is it's really poor documentation. You pretty much have to look through the .crm files to find out what they can really do. Rick > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | > gpg --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B > // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B > // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net > > ----- Original Message ----- > From: "Rick Cooper" > To: "MailScanner List" > Sent: Wednesday, August 1, 2007 9:18:18 PM (GMT) Europe/London > Subject: CRM114 False Negatives > > Ok, I have been pretty quiet amidst the whole CRM114 thread because I > installed this a couple weeks ago and turned it off because of false > negative issues. I turned it back on a tried again but here > is the issue I > have. If CRM learns a message as ham nothing I have done > will cause it to > unlearn the message as ham and relearn as spam. I have tried all the > recommended ways of using mailreaver, etc and I have even > seen (in verbose > mode) mailreaver say it learned as spam but if I rerun the > same message I > still have CRM reporting as good (with scores as high as > +40!). Does anyone > have a definite method of re-learning ham as spam? (yes I have used > spamassassin --report also) > > > > Rick Cooper > > > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From res at ausics.net Wed Aug 1 23:33:45 2007 From: res at ausics.net (Res) Date: Wed Aug 1 23:33:53 2007 Subject: Random messages stuck in mqueue In-Reply-To: <46B10372.5080802@coders.co.uk> References: <6439a60f0707312146x6d41d1f2ra6ca13448e3faee9@mail.gmail.com> <46B0C2C5.4010909@jfworks.net> <6439a60f0708011044j95116e5jceae6e8f485632be@mail.gmail.com> <46B10025.70208@coders.co.uk> <6439a60f0708011455u472affd1u658498e31df1f82f@mail.gmail.com> <46B10372.5080802@coders.co.uk> Message-ID: On Wed, 1 Aug 2007, Matt Hampton wrote: > Corey McFadden wrote: >> Matt, >> >> mailq will display the messages in the mqueue folder. (All the >> messages, including those that haven't been processed.) >> > > Yes but inbound messages are in mqueue.in which is not the standard > location. > > So you only see the messages waiting for delivery mailq -OQueueDirectory=/var/spool/mqueue.in which takes half a day to type so you're better off to add this into /etc/profile: alias mailq.in='mailq -OQueueDirectory=/var/spool/mqueue.in' -- Cheers Res From rcooper at dwford.com Thu Aug 2 00:20:29 2007 From: rcooper at dwford.com (Rick Cooper) Date: Thu Aug 2 00:20:34 2007 Subject: CRM114 False Negatives In-Reply-To: <21613556.9651186001004647.JavaMail.root@office.splatnix.net> References: <023401c7d479$198a16c0$0301a8c0@SAHOMELT> <21613556.9651186001004647.JavaMail.root@office.splatnix.net> Message-ID: <025d01c7d492$8d4bb050$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On > Behalf Of UxBoD > Sent: Wednesday, August 01, 2007 4:43 PM > To: MailScanner discussion > Subject: Re: CRM114 False Negatives > > What version of CRM are you running Rick. I haven't seen > this behaviour (yet). > > Regards, > Here, BTW is an example of rather odd behavior after forcing crm to learn message as spam X-CRM114-Action: LEARNED SPAM (FORCED) X-CRM114-Status: Good (Spam Learn) Retest the saved message with sa and you get 2.5 BAYES_99 BODY: Bayesian spam probability is 99 to 100% [score: 1.0000] 0.0 MONEY_BACK BODY: Money back guarantee 0.0 HTML_MESSAGE BODY: HTML included in message 1.5 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level above 50% [cf: 100] 1.5 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/) 1.0 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50% [cf: 100] 1.5 DCC_CHECK Listed in DCC (http://rhyolite.com/anti-spam/dcc/) 0.0 DIGEST_MULTIPLE Message hits more than one network digest check -50 CRM114_CHECK CRM114: message is GOOD with crm114-score 999.9900 So this message would clearly be spam but crm upped it into great ham. When I try the forward to me with command command password learnspam Not only doesn't it fix the problem but it doesn't add the subject prefix designated in mailfilter.cf Ackkkkk! Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From FStein at thehill.org Thu Aug 2 01:31:32 2007 From: FStein at thehill.org (Stein, Mr. Fred) Date: Thu Aug 2 01:35:03 2007 Subject: MailScanner --lint error Message-ID: I am getting the following error when I run MailScanner --lint on a Centos 4.2, Postfix install. Any help would appreciated. Checking version numbers... Version number in MailScanner.conf (4.62.9) is correct. Your envelope_sender_header in spam.assassin.prefs.conf is correct. Checking for SpamAssassin errors (if you use it)... SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp netset: cannot include 127.0.0.1/32 as it has already been included SpamAssassin reported no errors. MailScanner.conf says "Virus Scanners = auto" Found these virus scanners installed: bitdefender, f-prot, clamavmodule =========================================================================== Ignore errors about failing to find EOCD signature Bad file descriptor,Bad file descriptor at /usr/lib/MailScanner/MailScanner/PFDiskStore.pm line 656. Fred Stein Network Administrator The Hill School 717 High Street Pottstown, PA 19464 610-326-1000 ext. 7356 fstein@thehill.org www.thehill.org From R.Sterenborg at netsourcing.nl Thu Aug 2 06:51:51 2007 From: R.Sterenborg at netsourcing.nl (Rob Sterenborg) Date: Thu Aug 2 06:59:23 2007 Subject: CRM114 installation on Debian Etch In-Reply-To: <223f97700708010654o6f02c304w11117919ca0551aa@mail.gmail.com> References: <74ACEB3E6A055643A89B8CEC74C7BF2488E0FB@WISENT.dcyb.net><223f97700708010517h3af4eb55r1bac3b0009d3f366@mail.gmail.com><74ACEB3E6A055643A89B8CEC74C7BF2488E0FE@WISENT.dcyb.net> <223f97700708010654o6f02c304w11117919ca0551aa@mail.gmail.com> Message-ID: <74ACEB3E6A055643A89B8CEC74C7BF2488E100@WISENT.dcyb.net> >>> Please put it in the wiki at >>> http://wiki.mailscanner.info/doku.php?id=documentation:anti_sp >>> am:spamassassin:plugins:crm114 (watch out for linewraps!)... TiA >> >> It's there. > > I took the liberty of changing the layout a teensy bit (no loss of > information!), as well as the usual %%--%% thing needed to avoid -- > becoming a "big hyphen". Sigh. Sure, no problem. I've never used this webinterface before and looked at the previous entries but I still could have made mistakes and/or used formating that is not consistent. Grts, Rob From R.Sterenborg at netsourcing.nl Thu Aug 2 06:52:17 2007 From: R.Sterenborg at netsourcing.nl (Rob Sterenborg) Date: Thu Aug 2 06:59:28 2007 Subject: CRM114 installation on Debian Etch In-Reply-To: <1951DC816E1A9F469307B05FA183F4389DC9DE@corpatsmail1.corp.sensis.com> References: <74ACEB3E6A055643A89B8CEC74C7BF2488E0FB@WISENT.dcyb.net> <1951DC816E1A9F469307B05FA183F4389DC9DE@corpatsmail1.corp.sensis.com> Message-ID: <74ACEB3E6A055643A89B8CEC74C7BF2488E101@WISENT.dcyb.net> >> Debian often suffers from old packages residing in the repository, >> so I decided to build a new package for crm114 from Debian source. > > FYI - You could always use the crm114 package from backports.org > instead. Ah thanks.. Didn't know that one! Grts, Rob From Q.G.Campbell at newcastle.ac.uk Thu Aug 2 08:37:34 2007 From: Q.G.Campbell at newcastle.ac.uk (Quentin Campbell) Date: Thu Aug 2 08:39:50 2007 Subject: 4.62.9-1 & MailScanner --lint [FIXED - but why?] In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA01510BA8@HC-MBX02.herefordshire.gov.uk> References: <4165CF7A7F12DE4B96622CCBB90586470B125888@largo.campus.ncl.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBA01510BA8@HC-MBX02.herefordshire.gov.uk> Message-ID: <4165CF7A7F12DE4B96622CCBB90586470B1258A7@largo.campus.ncl.ac.uk> Phil Thanks for the reply. Where are your 'main.cvd' and 'daily.cvd' files kept? A little more research and digging found the problem but I am unclear as to how the situation came about. There is now a new maintenance problem to be resolved and some worrying questions. The " LibClamAV Warning: *** The virus database is older than 7 days. ***" message arises because there was a second location containing very old (July 26, 2005) copies of main.cvd and daily.cvd under /usr/local/share/clamav. In my current installation I keep the '.cvd' files under /usr/local/clamav. If I remove the 'clamav' sub-directory from /usr/local/share or remove the two files from under it then 'MailScanner --lint' complains. If I copy my current two '.cvd' files from /usr/local/clamav to /usr/local/share/clamav then MailScanner --lint works OK. QUESTIONS: 1. When was the /usr/local/share/clamv sub-directory created and why? 2. Why is a /usr/local/share/clamav needed when my /usr/local/etc/freshclam.conf file specifies /usr/local/clamav as the '.cvd' files location? 3. Has 'clamavmodule' been using these very old '.cvd' files for virus detection? 4. There is the maintenance issue - how do I keep the /usr/local/share/clamav/*.cvd files up to date? ANSWER: I suppose when using 'clamavmodule' I should change /usr/local/etc/freshclam.conf and replace DatabaseDirectory /usr/local/clamav with DatabaseDirectory /usr/local/share/clamav Alternately I can make /usr/local/share/clamav a link to /usr/local/clamav (or vice versa). What is best? Had I missed and important documented step when I swapped from using 'clamscan' to using 'clamavmodule'? If so I cannot find it! Quentin >-----Original Message----- >From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >bounces@lists.mailscanner.info] On Behalf Of Randal, Phil >Sent: 01 August 2007 17:19 >To: MailScanner discussion >Subject: RE: 4.62.9-1 & MailScanner --lint [MORE INFO] > >Works for me: > >MailScanner --lint >Checking version numbers... >Version number in MailScanner.conf (4.62.9) is correct. > >Your envelope_sender_header in spam.assassin.prefs.conf is correct. > >Checking for SpamAssassin errors (if you use it)... >SpamAssassin temp dir = >/var/spool/MailScanner/incoming/SpamAssassin-Temp >SpamAssassin reported no errors. >MailScanner.conf says "Virus Scanners = clamavmodule mcafee" >Found these virus scanners installed: clamavmodule, mcafee >======================================================================= = >=== >Ignore errors about failing to find EOCD signature >format error: can't find EOCD signature > at /usr/sbin/MailScanner line 450 >======================================================================= = >=== >Virus Scanner test reports: >ClamAV Module said "eicar.com was infected: Eicar-Test-Signature" >McAfee said "/1/eicar.com Found: EICAR test file NOT a virus." > >If any of your virus scanners (clamavmodule,mcafee) >are not listed there, you should check that they are installed correctly >and that MailScanner is finding them correctly via its >virus.scanners.conf. > >Cheers, > >Phil > >-- >Phil Randal >Network Engineer >Herefordshire Council >Hereford, UK > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf >> Of Quentin Campbell >> Sent: 01 August 2007 16:57 >> To: MailScanner discussion >> Subject: FW: 4.62.9-1 & MailScanner --lint [MORE INFO] >> >> Julian >> >> The MailScanner --lint output I am getting is related to the >> fact that I >> have "Virus Scanners = clamavmodule mcafee". If I change that line in >> MailScanner.conf to be "Virus Scanners = clamav mcafee" then I get the >> following (more sensible) output from MailScanner --lint but also note >> confusion in the output over clamav/clamavmodule being installed: >> >> ------------- cut here >> [root@cheviot9 MailScanner]# MailScanner --lint >> Checking version numbers... >> Version number in MailScanner.conf (4.62.9) is correct. >> >> Your envelope_sender_header in spam.assassin.prefs.conf is correct. >> >> Checking for SpamAssassin errors (if you use it)... >> SpamAssassin temp dir = >> /var/spool/MailScanner/incoming/SpamAssassin-Temp >> SpamAssassin reported no errors. >> MailScanner.conf says "Virus Scanners = clamav mcafee" >> Found these virus scanners installed: clamavmodule, mcafee >> ============================================================== >> ========== >> === >> Ignore errors about failing to find EOCD signature >> ============================================================== >> ========== >> === >> Virus Scanner test reports: >> ClamAV said "eicar.com contains Eicar-Test-Signature" >> McAfee said "/1/eicar.com Found: EICAR test file NOT a virus." >> >> If any of your virus scanners (clamavmodule,mcafee) >> are not listed there, you should check that they are >> installed correctly >> and that MailScanner is finding them correctly via its >> virus.scanners.conf. >> [root@cheviot9 MailScanner]# >> ------------- cut here >> >> In addition I have just been using CPAN to install >> Mail::ClamAV on some >> other gateways and noted that when it does its post install tests it >> also notices that the database is out of date: >> >> ------------- cut here >> > install Mail::ClamAV >> ... >> ... >> Manifying blib/man3/Mail::ClamAV.3pm >> /usr/bin/make -- OK >> Running make test >> PERL_DL_NONLAZY=1 /usr/bin/perl "-MExtUtils::Command::MM" "-e" >> "test_harness(0, 'blib/lib', 'blib/arch')" t/*.t >> t/Mail-ClamAV....ok 2/10LibClamAV Warning: >> ************************************************** >> LibClamAV Warning: *** The virus database is older than 7 days. *** >> LibClamAV Warning: *** Please update it IMMEDIATELY! *** >> LibClamAV Warning: ************************************************** >> t/Mail-ClamAV....ok >> >> All tests successful. >> Files=1, Tests=10, 2 wallclock secs ( 1.56 cusr + 0.16 csys = 1.72 >> CPU) >> /usr/bin/make test -- OK >> Running make install >> Installing >> /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/auto/Ma >> il/ClamAV/ >> ClamAV.so >> Installing >> /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/auto/Ma >> il/ClamAV/ >> ClamAV.bs >> Files found in blib/arch: installing files in blib/lib into >> architecture >> dependent library tree >> Installing >> /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/Mail/ClamAV.pm >> Installing /usr/share/man/man3/Mail::ClamAV.3pm >> Writing >> /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/auto/Ma >> il/ClamAV/ >> .packlist >> Appending installation info to >> /usr/lib/perl5/5.8.5/i386-linux-thread-multi/perllocal.pod >> /usr/bin/make install -- OK >> >> cpan> >> ------------- cut here >> >> Quentin >> >> >> >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf >> Of Quentin >> Campbell >> Sent: 01 August 2007 15:36 >> To: MailScanner discussion >> Subject: RE: 4.62.9-1 & MailScanner --lint >> >> >-----Original Message----- >> >From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> >bounces@lists.mailscanner.info] On Behalf Of Julian Field >> >Sent: 01 August 2007 15:08 >> >To: MailScanner discussion >> >Subject: Re: 4.62.9-1 & MailScanner --lint >> > >> >What does >> >grep -i clam /etc/MailScanner/virus.scanners.conf >> >say? >> [snip] >> >> [root@cheviot4 log]# grep -i clam /etc/MailScanner/virus.scanners.conf >> clamav /usr/lib/MailScanner/clamav-wrapper /usr/local >> clamd /bin/false /usr/local >> clamavmodule /bin/false /tmp >> [root@cheviot4 log]# >> >> Before requesting help I changed /tmp for /usr/local for the >> clamavmodule but that made no difference. >> >> Quentin >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >-- >MailScanner mailing list >mailscanner@lists.mailscanner.info >http://lists.mailscanner.info/mailman/listinfo/mailscanner > >Before posting, read http://wiki.mailscanner.info/posting > >Support MailScanner development - buy the book off the website! From paul.hutchings at mira.co.uk Thu Aug 2 08:42:32 2007 From: paul.hutchings at mira.co.uk (Paul Hutchings) Date: Thu Aug 2 08:42:35 2007 Subject: Location of signature? References: <46ADE7EF.60107@ecs.soton.ac.uk> Message-ID: Thanks, makes sense. Presume same thing goes about not keep adding the disclaimer every time an email is replied to? Paul Hutchings Network Administrator, MIRA Ltd. Tel: 44 (0)24 7635 5378 Fax: 44 (0)24 7635 8378 mailto:paul.hutchings@mira.co.uk -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian Field Sent: 30 July 2007 14:30 To: MailScanner discussion Subject: Re: Location of signature? You're quite right, it can't be done. It can only be added at the end of the message. Paul Hutchings wrote: > From what I've read in the docs I think I know the answer to this one > but here goes.. > > Is there any way to specify where in an email to insert the > signature/disclaimer? I ask because if an email is finally being > forwarded outside of the company, the signature will appear at the very > end of the email rather than after the senders message. > > Can't see it being possible because after all, how would it "know" where > the latest addition to the message ends, but I may as well check for > sure. > > Cheers, > Paul > > Paul Hutchings > Network Administrator, MIRA Ltd. > Tel: 44 (0)24 7635 5378 > Fax: 44 (0)24 7635 8378 > mailto:paul.hutchings@mira.co.uk > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MIRA Ltd Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. Registered in England and Wales No. 402570 VAT Registration GB 114 5409 96 The contents of this e-mail are confidential and are solely for the use of the intended recipient. If you receive this e-mail in error, please delete it and notify us either by e-mail, telephone or fax. You should not copy, forward or otherwise disclose the content of the e-mail as this is prohibited. From glenn.steen at gmail.com Thu Aug 2 08:46:11 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu Aug 2 08:46:15 2007 Subject: MailScanner ANNOUNCE: Version 4.62.9 released In-Reply-To: <46AFA330.7010206@ecs.soton.ac.uk> References: <46AFA330.7010206@ecs.soton.ac.uk> Message-ID: <223f97700708020046y350c68cet4828ef4fb522d4f3@mail.gmail.com> On 31/07/07, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > I have just released a new version of MailScanner, 4.62.9. I don't (snip) > - --- New "ClamAV Full Message Scan" setting, and improvements to the > ClamAV parser so that the SANESecurity phishing- and spam-detection > signatures can be reliably used. Note this new setting is disabled by > default, as it has a slight speed impact. (snip) Enabling this setting isn't only beneficial for ClamAV, but also for McAfee ... Note the McAfee line in this report snippet: ----- Subject: You've received a postcard from a Friend! MessageID: D6DC4E452.39523 Quarantine: /var/spool/MailScanner/quarantine/20070801/D6DC4E452.39523 Report: ClamAV Module: message was infected: Email.Phishing.RB-1221 McAfee: /D6DC4E452.39523.message Found the W32/Zhelatin.gen!eml virus !!! ----- As you can see, it isn't just ClamAV phishing signatures triggering on the "complete message" file... Pretty cool side effect:-). Perhaps makes the name ... less than intuitive:-):-). But since I'll want this and always use ClamAV, it's OK by me... Otherwise it'd have to be "Antivirus Full Message Scan" or something similar:-). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From martinh at solidstatelogic.com Thu Aug 2 08:50:28 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Thu Aug 2 08:50:32 2007 Subject: Location of signature? In-Reply-To: Message-ID: <52e53fa14dc2c04f9463c99a5fbb4ae2@solidstatelogic.com> Paul Yeah stupid disclaimer it even worse in the UK now...company details etc have to included as you obviously know (BTW don't need to include the CAT number ;-) -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Paul Hutchings > Sent: 02 August 2007 08:43 > To: MailScanner discussion > Subject: RE: Location of signature? > > Thanks, makes sense. Presume same thing goes about not keep adding the > disclaimer every time an email is replied to? > > Paul Hutchings > Network Administrator, MIRA Ltd. > Tel: 44 (0)24 7635 5378 > Fax: 44 (0)24 7635 8378 > mailto:paul.hutchings@mira.co.uk > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian > Field > Sent: 30 July 2007 14:30 > To: MailScanner discussion > Subject: Re: Location of signature? > > You're quite right, it can't be done. It can only be added at the end of > > the message. > > Paul Hutchings wrote: > > From what I've read in the docs I think I know the answer to this one > > but here goes.. > > > > Is there any way to specify where in an email to insert the > > signature/disclaimer? I ask because if an email is finally being > > forwarded outside of the company, the signature will appear at the > very > > end of the email rather than after the senders message. > > > > Can't see it being possible because after all, how would it "know" > where > > the latest addition to the message ends, but I may as well check for > > sure. > > > > Cheers, > > Paul > > > > Paul Hutchings > > Network Administrator, MIRA Ltd. > > Tel: 44 (0)24 7635 5378 > > Fax: 44 (0)24 7635 8378 > > mailto:paul.hutchings@mira.co.uk > > > > > > > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > Need help customising MailScanner? > Contact me! > Need help fixing or optimising your systems? > Contact me! > Need help getting you started solving new requirements from your boss? > Contact me! > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > MIRA Ltd > > Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. > > Registered in England and Wales No. 402570 > VAT Registration GB 114 5409 96 > > The contents of this e-mail are confidential and are solely for the use of > the intended recipient. > If you receive this e-mail in error, please delete it and notify us either > by e-mail, telephone or fax. > You should not copy, forward or otherwise disclose the content of the e- > mail as this is prohibited. > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From martinh at solidstatelogic.com Thu Aug 2 08:50:46 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Thu Aug 2 08:50:50 2007 Subject: Location of signature? In-Reply-To: Message-ID: <6b07c240122424419940ceb7259ec7b2@solidstatelogic.com> Paul Bother, too quick on the send - VAT number ;-) -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Paul Hutchings > Sent: 02 August 2007 08:43 > To: MailScanner discussion > Subject: RE: Location of signature? > > Thanks, makes sense. Presume same thing goes about not keep adding the > disclaimer every time an email is replied to? > > Paul Hutchings > Network Administrator, MIRA Ltd. > Tel: 44 (0)24 7635 5378 > Fax: 44 (0)24 7635 8378 > mailto:paul.hutchings@mira.co.uk > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian > Field > Sent: 30 July 2007 14:30 > To: MailScanner discussion > Subject: Re: Location of signature? > > You're quite right, it can't be done. It can only be added at the end of > > the message. > > Paul Hutchings wrote: > > From what I've read in the docs I think I know the answer to this one > > but here goes.. > > > > Is there any way to specify where in an email to insert the > > signature/disclaimer? I ask because if an email is finally being > > forwarded outside of the company, the signature will appear at the > very > > end of the email rather than after the senders message. > > > > Can't see it being possible because after all, how would it "know" > where > > the latest addition to the message ends, but I may as well check for > > sure. > > > > Cheers, > > Paul > > > > Paul Hutchings > > Network Administrator, MIRA Ltd. > > Tel: 44 (0)24 7635 5378 > > Fax: 44 (0)24 7635 8378 > > mailto:paul.hutchings@mira.co.uk > > > > > > > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > Need help customising MailScanner? > Contact me! > Need help fixing or optimising your systems? > Contact me! > Need help getting you started solving new requirements from your boss? > Contact me! > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > MIRA Ltd > > Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. > > Registered in England and Wales No. 402570 > VAT Registration GB 114 5409 96 > > The contents of this e-mail are confidential and are solely for the use of > the intended recipient. > If you receive this e-mail in error, please delete it and notify us either > by e-mail, telephone or fax. > You should not copy, forward or otherwise disclose the content of the e- > mail as this is prohibited. > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From glenn.steen at gmail.com Thu Aug 2 08:59:57 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu Aug 2 08:59:59 2007 Subject: 4.62.9-1 lint error w/mcafee (UNCLASSIFIED) In-Reply-To: <46B0C039.4000402@ecs.soton.ac.uk> References: <88991ECEE371C644986F0C8837C207B70173B314@ARLABML01.DS.ARL.ARMY.MIL> <46B0A324.7090208@ecs.soton.ac.uk> <223f97700708010920p6ecbef92tb7eb584e056e6c9e@mail.gmail.com> <46B0C039.4000402@ecs.soton.ac.uk> Message-ID: <223f97700708020059i278015favd1f0db1b1eb00590@mail.gmail.com> On 01/08/07, Julian Field wrote: > Apply the attached patch to /usr/sbin/MailScanner. > I'll release a -2 in a minute. > > Glenn Steen wrote: > > On 01/08/07, Julian Field wrote: > > > >> Can you try setting MTA=sendmail then give it another go? > >> > > > > This corrects the lint error. Sorry for not noticing earlier:-( > > Cannot (of course) run it like that, so ... go do our magic Jules;-):-) > > > > > >> Kash, Howard (Civ, ARL/CISD) wrote: > >> > >>> Classification: _* UNCLASSIFIED*_ > >>> Caveats: NONE > >>> > >>> > >>> MailScanner.conf says "Virus Scanners = mcafee" > >>> Found these virus scanners installed: mcafee > >>> =========================================================================== > >>> > >>> Ignore errors about failing to find EOCD signature > >>> Bad file descriptor,Bad file descriptor at > >>> /usr/lib/MailScanner/MailScanner/PFDiskStore.pm line 656. > >>> > >>> > >>> > >>> Howard > >>> > >>> Classification: _* UNCLASSIFIED*_ > >>> Caveats: NONE > >>> > >>> > >> Jules > >> > >> > >> > > > > Cheers > > > > Jules > Works as intended... But you knew that:-). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From uxbod at splatnix.net Thu Aug 2 09:15:12 2007 From: uxbod at splatnix.net (UxBoD) Date: Thu Aug 2 09:09:31 2007 Subject: MS Hanging In-Reply-To: <223f97700708011410g78c67c0teb435851be007532@mail.gmail.com> Message-ID: <21252893.9831186042512802.JavaMail.root@office.splatnix.net> Hi Glenn, I lowered the batch queue size to 10 to force things through faster. This has got us over the initial problem, but still 1600 messages in the queue to process :( Damn those spammers! Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From glenn.steen at gmail.com Thu Aug 2 09:10:17 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu Aug 2 09:10:19 2007 Subject: MailScanner --lint error In-Reply-To: References: Message-ID: <223f97700708020110o441b6713w4711556f930bb393@mail.gmail.com> On 02/08/07, Stein, Mr. Fred wrote: > I am getting the following error when I run MailScanner --lint on a Centos 4.2, Postfix install. Any help would appreciated. > Checking version numbers... > Version number in MailScanner.conf (4.62.9) is correct. > Your envelope_sender_header in spam.assassin.prefs.conf is correct. > Checking for SpamAssassin errors (if you use it)... > SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp > netset: cannot include 127.0.0.1/32 as it has already been included > SpamAssassin reported no errors. > MailScanner.conf says "Virus Scanners = auto" > Found these virus scanners installed: bitdefender, f-prot, clamavmodule > =========================================================================== > Ignore errors about failing to find EOCD signature > Bad file descriptor,Bad file descriptor at /usr/lib/MailScanner/MailScanner/PFDiskStore.pm line 656. > > Fred Stein > Network Administrator > The Hill School > 717 High Street > Pottstown, PA 19464 > 610-326-1000 ext. 7356 > fstein@thehill.org > www.thehill.org Hi Fred, Either use the one-line patch Jules sent to me (In thread with subject: "4.62.9-1 lint error w/mcafee (UNCLASSIFIED)"), or donwload and install 4.62.9-2 from the usual place...The patch is to "lie" a bit and pretend you're using sendmail if you do a lint only call of MailScanner:-). I haven't looked at if this has any side effects that are unforseen, but... I trust Jules...:-). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Thu Aug 2 09:56:29 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu Aug 2 09:56:30 2007 Subject: 4.62.9-1 & MailScanner --lint [FIXED - but why?] In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470B1258A7@largo.campus.ncl.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470B125888@largo.campus.ncl.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBA01510BA8@HC-MBX02.herefordshire.gov.uk> <4165CF7A7F12DE4B96622CCBB90586470B1258A7@largo.campus.ncl.ac.uk> Message-ID: <223f97700708020156x5b90d0ccu65f5c4e529b7ef2@mail.gmail.com> On 02/08/07, Quentin Campbell wrote: (snip) > DatabaseDirectory /usr/local/share/clamav This is the default location, so you need only comment out the one you had. > Alternately I can make /usr/local/share/clamav a link to > /usr/local/clamav (or vice versa). What is best? Just check that freshclam (after your changes to the conf file) update the default location and you'll be fine. Remember to amend the loaction in MailScanner.conf too (if you use clamavmodule). > Had I missed and important documented step when I swapped from using > 'clamscan' to using 'clamavmodule'? If so I cannot find it! Don't think so. Most never bother to change the defaults (what would be the point, unless you are a packaging fascist at some distro maker...:-) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From MailScanner at ecs.soton.ac.uk Thu Aug 2 09:57:41 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 2 09:58:31 2007 Subject: 4.62.9-1 & MailScanner --lint [FIXED - but why?] In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470B1258A7@largo.campus.ncl.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470B125888@largo.campus.ncl.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBA01510BA8@HC-MBX02.herefordshire.gov.uk> <4165CF7A7F12DE4B96622CCBB90586470B1258A7@largo.campus.ncl.ac.uk> Message-ID: <46B19C85.5060901@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Quentin Campbell wrote: > Phil > > Thanks for the reply. > > Where are your 'main.cvd' and 'daily.cvd' files kept? > > A little more research and digging found the problem but I am unclear as > to how the situation came about. There is now a new maintenance problem > to be resolved and some worrying questions. > > The " LibClamAV Warning: *** The virus database is older than 7 days. > ***" message arises because there was a second location containing very > old (July 26, 2005) copies of main.cvd and daily.cvd under > /usr/local/share/clamav. In my current installation I keep the '.cvd' > files under /usr/local/clamav. > > If I remove the 'clamav' sub-directory from /usr/local/share or remove > the two files from under it then 'MailScanner --lint' complains. If I > copy my current two '.cvd' files from /usr/local/clamav to > /usr/local/share/clamav then MailScanner --lint works OK. > > QUESTIONS: > > 1. When was the /usr/local/share/clamv sub-directory created and why? > A long time ago, it's where my sigs have always been. > 2. Why is a /usr/local/share/clamav needed when my > /usr/local/etc/freshclam.conf file specifies /usr/local/clamav as the > '.cvd' files location? > But only freshclam looks at freshclam.conf. > 3. Has 'clamavmodule' been using these very old '.cvd' files for virus > detection? > Probably. > 4. There is the maintenance issue - how do I keep the > /usr/local/share/clamav/*.cvd files up to date? ANSWER: I suppose when > using 'clamavmodule' I should change /usr/local/etc/freshclam.conf and > replace > > DatabaseDirectory /usr/local/clamav > > with > > DatabaseDirectory /usr/local/share/clamav > Yes, I would do that. AFAIAA the DatabaseDirectory has always been /usr/local/share/clamav. > Alternately I can make /usr/local/share/clamav a link to > /usr/local/clamav (or vice versa). What is best? > Correct your DatabaseDirectory. > Had I missed and important documented step when I swapped from using > 'clamscan' to using 'clamavmodule'? If so I cannot find it! > I don't think so, no. > Quentin > > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Randal, Phil >> Sent: 01 August 2007 17:19 >> To: MailScanner discussion >> Subject: RE: 4.62.9-1 & MailScanner --lint [MORE INFO] >> >> Works for me: >> >> MailScanner --lint >> Checking version numbers... >> Version number in MailScanner.conf (4.62.9) is correct. >> >> Your envelope_sender_header in spam.assassin.prefs.conf is correct. >> >> Checking for SpamAssassin errors (if you use it)... >> SpamAssassin temp dir = >> /var/spool/MailScanner/incoming/SpamAssassin-Temp >> SpamAssassin reported no errors. >> MailScanner.conf says "Virus Scanners = clamavmodule mcafee" >> Found these virus scanners installed: clamavmodule, mcafee >> ======================================================================= >> > = > >> === >> Ignore errors about failing to find EOCD signature >> format error: can't find EOCD signature >> at /usr/sbin/MailScanner line 450 >> ======================================================================= >> > = > >> === >> Virus Scanner test reports: >> ClamAV Module said "eicar.com was infected: Eicar-Test-Signature" >> McAfee said "/1/eicar.com Found: EICAR test file NOT a virus." >> >> If any of your virus scanners (clamavmodule,mcafee) >> are not listed there, you should check that they are installed >> > correctly > >> and that MailScanner is finding them correctly via its >> virus.scanners.conf. >> >> Cheers, >> >> Phil >> >> -- >> Phil Randal >> Network Engineer >> Herefordshire Council >> Hereford, UK >> >> >>> -----Original Message----- >>> From: mailscanner-bounces@lists.mailscanner.info >>> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf >>> Of Quentin Campbell >>> Sent: 01 August 2007 16:57 >>> To: MailScanner discussion >>> Subject: FW: 4.62.9-1 & MailScanner --lint [MORE INFO] >>> >>> Julian >>> >>> The MailScanner --lint output I am getting is related to the >>> fact that I >>> have "Virus Scanners = clamavmodule mcafee". If I change that line in >>> MailScanner.conf to be "Virus Scanners = clamav mcafee" then I get >>> > the > >>> following (more sensible) output from MailScanner --lint but also >>> > note > >>> confusion in the output over clamav/clamavmodule being installed: >>> >>> ------------- cut here >>> [root@cheviot9 MailScanner]# MailScanner --lint >>> Checking version numbers... >>> Version number in MailScanner.conf (4.62.9) is correct. >>> >>> Your envelope_sender_header in spam.assassin.prefs.conf is correct. >>> >>> Checking for SpamAssassin errors (if you use it)... >>> SpamAssassin temp dir = >>> /var/spool/MailScanner/incoming/SpamAssassin-Temp >>> SpamAssassin reported no errors. >>> MailScanner.conf says "Virus Scanners = clamav mcafee" >>> Found these virus scanners installed: clamavmodule, mcafee >>> ============================================================== >>> ========== >>> === >>> Ignore errors about failing to find EOCD signature >>> ============================================================== >>> ========== >>> === >>> Virus Scanner test reports: >>> ClamAV said "eicar.com contains Eicar-Test-Signature" >>> McAfee said "/1/eicar.com Found: EICAR test file NOT a virus." >>> >>> If any of your virus scanners (clamavmodule,mcafee) >>> are not listed there, you should check that they are >>> installed correctly >>> and that MailScanner is finding them correctly via its >>> virus.scanners.conf. >>> [root@cheviot9 MailScanner]# >>> ------------- cut here >>> >>> In addition I have just been using CPAN to install >>> Mail::ClamAV on some >>> other gateways and noted that when it does its post install tests it >>> also notices that the database is out of date: >>> >>> ------------- cut here >>> >>>> install Mail::ClamAV >>>> >>> ... >>> ... >>> Manifying blib/man3/Mail::ClamAV.3pm >>> /usr/bin/make -- OK >>> Running make test >>> PERL_DL_NONLAZY=1 /usr/bin/perl "-MExtUtils::Command::MM" "-e" >>> "test_harness(0, 'blib/lib', 'blib/arch')" t/*.t >>> t/Mail-ClamAV....ok 2/10LibClamAV Warning: >>> ************************************************** >>> LibClamAV Warning: *** The virus database is older than 7 days. *** >>> LibClamAV Warning: *** Please update it IMMEDIATELY! *** >>> LibClamAV Warning: ************************************************** >>> t/Mail-ClamAV....ok >>> >>> All tests successful. >>> Files=1, Tests=10, 2 wallclock secs ( 1.56 cusr + 0.16 csys = 1.72 >>> CPU) >>> /usr/bin/make test -- OK >>> Running make install >>> Installing >>> /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/auto/Ma >>> il/ClamAV/ >>> ClamAV.so >>> Installing >>> /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/auto/Ma >>> il/ClamAV/ >>> ClamAV.bs >>> Files found in blib/arch: installing files in blib/lib into >>> architecture >>> dependent library tree >>> Installing >>> /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/Mail/ClamAV.pm >>> Installing /usr/share/man/man3/Mail::ClamAV.3pm >>> Writing >>> /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/auto/Ma >>> il/ClamAV/ >>> .packlist >>> Appending installation info to >>> /usr/lib/perl5/5.8.5/i386-linux-thread-multi/perllocal.pod >>> /usr/bin/make install -- OK >>> >>> cpan> >>> ------------- cut here >>> >>> Quentin >>> >>> >>> >>> -----Original Message----- >>> From: mailscanner-bounces@lists.mailscanner.info >>> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf >>> Of Quentin >>> Campbell >>> Sent: 01 August 2007 15:36 >>> To: MailScanner discussion >>> Subject: RE: 4.62.9-1 & MailScanner --lint >>> >>> >>>> -----Original Message----- >>>> From: mailscanner-bounces@lists.mailscanner.info >>>> > [mailto:mailscanner- > >>>> bounces@lists.mailscanner.info] On Behalf Of Julian Field >>>> Sent: 01 August 2007 15:08 >>>> To: MailScanner discussion >>>> Subject: Re: 4.62.9-1 & MailScanner --lint >>>> >>>> What does >>>> grep -i clam /etc/MailScanner/virus.scanners.conf >>>> say? >>>> >>> [snip] >>> >>> [root@cheviot4 log]# grep -i clam >>> > /etc/MailScanner/virus.scanners.conf > >>> clamav /usr/lib/MailScanner/clamav-wrapper /usr/local >>> clamd /bin/false /usr/local >>> clamavmodule /bin/false /tmp >>> [root@cheviot4 log]# >>> >>> Before requesting help I changed /tmp for /usr/local for the >>> clamavmodule but that made no difference. >>> >>> Quentin >>> -- >>> MailScanner mailing list >>> mailscanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> >>> Before posting, read http://wiki.mailscanner.info/posting >>> >>> Support MailScanner development - buy the book off the website! >>> -- >>> MailScanner mailing list >>> mailscanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> >>> Before posting, read http://wiki.mailscanner.info/posting >>> >>> Support MailScanner development - buy the book off the website! >>> >>> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGsZyGEfZZRxQVtlQRAgS8AKCMuXdVu8AD+PsafhQF8to2D7R9qgCffFe8 St60mrZGJM2BN+9fuIOeiwg= =gRmZ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Thu Aug 2 10:00:10 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 2 10:00:41 2007 Subject: MailScanner ANNOUNCE: Version 4.62.9 released In-Reply-To: <223f97700708020046y350c68cet4828ef4fb522d4f3@mail.gmail.com> References: <46AFA330.7010206@ecs.soton.ac.uk> <223f97700708020046y350c68cet4828ef4fb522d4f3@mail.gmail.com> Message-ID: <46B19D1A.9080102@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Glenn Steen wrote: > On 31/07/07, Julian Field wrote: > >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> I have just released a new version of MailScanner, 4.62.9. I don't >> > (snip) > >> - --- New "ClamAV Full Message Scan" setting, and improvements to the >> ClamAV parser so that the SANESecurity phishing- and spam-detection >> signatures can be reliably used. Note this new setting is disabled by >> default, as it has a slight speed impact. >> > (snip) > > Enabling this setting isn't only beneficial for ClamAV, but also for > McAfee ... Note the McAfee line in this report snippet: > ----- > Subject: You've received a postcard from a Friend! > MessageID: D6DC4E452.39523 > Quarantine: /var/spool/MailScanner/quarantine/20070801/D6DC4E452.39523 > Report: ClamAV Module: message was infected: Email.Phishing.RB-1221 > McAfee: /D6DC4E452.39523.message Found the > W32/Zhelatin.gen!eml virus !!! > ----- > As you can see, it isn't just ClamAV phishing signatures triggering on > the "complete message" file... Pretty cool side effect:-). > > Perhaps makes the name ... less than intuitive:-):-). But since I'll > want this and always use ClamAV, it's OK by me... Otherwise it'd have > to be "Antivirus Full Message Scan" or something similar:-). > That's worth knowing. I wrote it for ClamAV's benefit, and the full message file will only be put there if you are using one of the ClamAV scanner methods. If you only use Mcafee it won't be written. In the next version it looks like I might need to move the code and rename the configuration setting. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGsZ0bEfZZRxQVtlQRAo4FAJ9roYMQlgsiBP3ps8prvbRYraVf+wCg3vcW y69nqnBCFwaXhSw55jjo3Tk= =Ws7o -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From glenn.steen at gmail.com Thu Aug 2 10:10:52 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu Aug 2 10:10:53 2007 Subject: MS Hanging In-Reply-To: <21252893.9831186042512802.JavaMail.root@office.splatnix.net> References: <223f97700708011410g78c67c0teb435851be007532@mail.gmail.com> <21252893.9831186042512802.JavaMail.root@office.splatnix.net> Message-ID: <223f97700708020210y4999c14bqdd94b04325188eff@mail.gmail.com> On 02/08/07, UxBoD wrote: > Hi Glenn, > > I lowered the batch queue size to 10 to force things through faster. This has got us over the initial problem, but still 1600 messages in the queue to process :( Damn those spammers! > > Regards, > Could be an RBL going slightly bonkers for you .... Since all the children said "Checking SPAM lists"... What lists do you have in MailScanner? Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From uxbod at splatnix.net Thu Aug 2 10:16:50 2007 From: uxbod at splatnix.net (UxBoD) Date: Thu Aug 2 10:11:08 2007 Subject: MailScanner ANNOUNCE: Version 4.62.9 released In-Reply-To: <46B19D1A.9080102@ecs.soton.ac.uk> Message-ID: <2661943.9861186046210916.JavaMail.root@office.splatnix.net> I believe, and expressed by others, that a lot of the AV suppliers will be going this way. They have to keep up with Clam ;) Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From support-lists at petdoctors.co.uk Thu Aug 2 10:13:07 2007 From: support-lists at petdoctors.co.uk (Nigel Kendrick) Date: Thu Aug 2 10:14:38 2007 Subject: CRM114 How are you finding it ? In-Reply-To: <46B0FBA0.6060601@coders.co.uk> Message-ID: <016e01c7d4e5$570a7190$3c65a8c0@support01> Taking the idea behind Jason's script and switching it to perl (download from http://www.coders.co.uk/crm.txt and run it catting your maillog in to STDIN) My recent stats (don't know time period) Total Messages: 1286 How many times was CRM114 wrong? False Negative: 21 (1.63%) False Positive: 22 (1.71%) Total Errors: 43 (3.34%) How many times did CRM114 cause an error? False Negative: 2 (0.15%) False Positive: 0 (0%) Total Errors: 2 (0.15%) This was with NO training and autolearn turned on with default values matt Hi Matt, With check_crm.pl < /var/log/maillog or cat /var/log/maillog | check_crm.pl I get: Illegal division by zero at ./crm114_check.pl line 33, <> line 29633. For me that line is the start of the final print statement I don't think CRM114 has kicked in for me yet so could this be because I have no matching lines? Thanks From uxbod at splatnix.net Thu Aug 2 10:30:16 2007 From: uxbod at splatnix.net (UxBoD) Date: Thu Aug 2 10:24:33 2007 Subject: MS Hanging In-Reply-To: <223f97700708020210y4999c14bqdd94b04325188eff@mail.gmail.com> Message-ID: <31327980.9891186047016995.JavaMail.root@office.splatnix.net> Hi Glenn, Spam List = ORDB-RBL spamhaus.org spamhaus-XBL spamhaus-ZEN spamcop.net NJABL CBL RSL DSBL BLITZEDALL SORBS-DNSBL SORBS-HTTP SORBS-SOCKS SORBS-MISC SORBS-SMTP SORBS-WEB SORBS-SPAM SORBS-BLOCK SORBS-ZOMBIE SORBS-DUL SORBS-RHSBL Spam List Timeout = 15 but have dropped it down too 10 now. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Glenn Steen" To: "MailScanner discussion" Sent: Thursday, August 2, 2007 10:10:52 AM (GMT) Europe/London Subject: Re: MS Hanging On 02/08/07, UxBoD wrote: > Hi Glenn, > > I lowered the batch queue size to 10 to force things through faster. This has got us over the initial problem, but still 1600 messages in the queue to process :( Damn those spammers! > > Regards, > Could be an RBL going slightly bonkers for you .... Since all the children said "Checking SPAM lists"... What lists do you have in MailScanner? Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From martinh at solidstatelogic.com Thu Aug 2 10:32:16 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Thu Aug 2 10:32:21 2007 Subject: MS Hanging In-Reply-To: <31327980.9891186047016995.JavaMail.root@office.splatnix.net> Message-ID: <3d5332e73f8131488ab054abf0fa4385@solidstatelogic.com> You gotta check those rbls for dead ones.... Ordb went offline a few months ago, spamhause-zen covers all the spamhause lists so you can remove these..... I'd really keeps these down a couple of trusted ones, otherwise the DNS look ups will takes ages.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of UxBoD > Sent: 02 August 2007 10:30 > To: MailScanner discussion > Subject: Re: MS Hanging > > Hi Glenn, > > Spam List = ORDB-RBL spamhaus.org spamhaus-XBL spamhaus-ZEN spamcop.net > NJABL CBL RSL DSBL BLITZEDALL SORBS-DNSBL SORBS-HTTP SORBS-SOCKS SORBS- > MISC SORBS-SMTP SORBS-WEB SORBS-SPAM SORBS-BLOCK SORBS-ZOMBIE SORBS-DUL > SORBS-RHSBL > > Spam List Timeout = 15 > > but have dropped it down too 10 now. > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B > // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B > // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net > > ----- Original Message ----- > From: "Glenn Steen" > To: "MailScanner discussion" > Sent: Thursday, August 2, 2007 10:10:52 AM (GMT) Europe/London > Subject: Re: MS Hanging > > On 02/08/07, UxBoD wrote: > > Hi Glenn, > > > > I lowered the batch queue size to 10 to force things through faster. > This has got us over the initial problem, but still 1600 messages in the > queue to process :( Damn those spammers! > > > > Regards, > > > Could be an RBL going slightly bonkers for you .... Since all the > children said "Checking SPAM lists"... What lists do you have in > MailScanner? > > Cheers > -- > -- Glenn > email: glenn < dot > steen < at > gmail < dot > com > work: glenn < dot > steen < at > ap1 < dot > se > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From glenn.steen at gmail.com Thu Aug 2 10:35:29 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu Aug 2 10:35:31 2007 Subject: MS Hanging In-Reply-To: <31327980.9891186047016995.JavaMail.root@office.splatnix.net> References: <223f97700708020210y4999c14bqdd94b04325188eff@mail.gmail.com> <31327980.9891186047016995.JavaMail.root@office.splatnix.net> Message-ID: <223f97700708020235q7bdc2512jeac06b62782b6cdf@mail.gmail.com> On 02/08/07, UxBoD wrote: > Hi Glenn, > > Spam List = ORDB-RBL spamhaus.org spamhaus-XBL spamhaus-ZEN spamcop.net NJABL CBL RSL DSBL BLITZEDALL SORBS-DNSBL SORBS-HTTP SORBS-SOCKS SORBS-MISC SORBS-SMTP SORBS-WEB SORBS-SPAM SORBS-BLOCK SORBS-ZOMBIE SORBS-DUL SORBS-RHSBL > > Spam List Timeout = 15 > > but have dropped it down too 10 now. > Regards, > Phil, That is just plain too many lists ... Reason? Because MailScanner will test them in sequence, not parallel... SA does them in parallell... Which is much better. If I were you, I'd drop that down to perhaps two BLs I really trust/that are most effective. If you want them to block, do it in PF, then a very few in MS and the vast majority (perhaps with "doctored" scores) in SA. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From MailScanner at ecs.soton.ac.uk Thu Aug 2 10:35:53 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 2 10:36:29 2007 Subject: MS Hanging In-Reply-To: <31327980.9891186047016995.JavaMail.root@office.splatnix.net> References: <31327980.9891186047016995.JavaMail.root@office.splatnix.net> Message-ID: <46B1A579.7000509@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Oh my! You shouldn't list more than 1 or 2 spam lists there. This many will run very slowly! Let SpamAssassin look them up for you, it does them in parallel. I would just advise Spam List = spamhaus-ZEN You also have dead lists and many overlaps in there. UxBoD wrote: > Hi Glenn, > > Spam List = ORDB-RBL spamhaus.org spamhaus-XBL spamhaus-ZEN spamcop.net NJABL CBL RSL DSBL BLITZEDALL SORBS-DNSBL SORBS-HTTP SORBS-SOCKS SORBS-MISC SORBS-SMTP SORBS-WEB SORBS-SPAM SORBS-BLOCK SORBS-ZOMBIE SORBS-DUL SORBS-RHSBL > > Spam List Timeout = 15 > > but have dropped it down too 10 now. > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B > // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B > // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net > > ----- Original Message ----- > From: "Glenn Steen" > To: "MailScanner discussion" > Sent: Thursday, August 2, 2007 10:10:52 AM (GMT) Europe/London > Subject: Re: MS Hanging > > On 02/08/07, UxBoD wrote: > >> Hi Glenn, >> >> I lowered the batch queue size to 10 to force things through faster. This has got us over the initial problem, but still 1600 messages in the queue to process :( Damn those spammers! >> >> Regards, >> >> > Could be an RBL going slightly bonkers for you .... Since all the > children said "Checking SPAM lists"... What lists do you have in > MailScanner? > > Cheers > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: UTF-8 wj8DBQFGsaV6EfZZRxQVtlQRAmRXAJkBJjExng2cCle7nOG6Zwn7u/y9KgCfVR9Q xyAvZKly/McrYJ042UOo0OM= =GqDx -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From uxbod at splatnix.net Thu Aug 2 10:45:48 2007 From: uxbod at splatnix.net (UxBoD) Date: Thu Aug 2 10:40:03 2007 Subject: MS Hanging In-Reply-To: <3d5332e73f8131488ab054abf0fa4385@solidstatelogic.com> Message-ID: <31015761.9951186047948295.JavaMail.root@office.splatnix.net> Cheers Martin, What would be nice is a script that validates the Spam List line from MailScanner.conf ? Anybody have anything already they would wish to share ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From uxbod at splatnix.net Thu Aug 2 10:48:40 2007 From: uxbod at splatnix.net (UxBoD) Date: Thu Aug 2 10:43:11 2007 Subject: MS Hanging In-Reply-To: <223f97700708020235q7bdc2512jeac06b62782b6cdf@mail.gmail.com> Message-ID: <21250634.9981186048120159.JavaMail.root@office.splatnix.net> Okay, I have thought about blocking @ PF level, as we have own internal RBL now. Problem is that I cannot see anyway in PF too check the return code ie. whether it is 127.0.0.2 (Blacklist) or 127.0.0.3 (Whitelist). This can be down in SA using a META and check_rbl_sub but cannot see the same in PF. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From uxbod at splatnix.net Thu Aug 2 10:52:06 2007 From: uxbod at splatnix.net (UxBoD) Date: Thu Aug 2 10:46:26 2007 Subject: MS Hanging In-Reply-To: <46B1A579.7000509@ecs.soton.ac.uk> Message-ID: <13946479.10011186048326524.JavaMail.root@office.splatnix.net> Thanks Guys - Me bad :( Have made the suggested changes and things look better now. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From telsek at paragon-software.com Thu Aug 2 10:49:39 2007 From: telsek at paragon-software.com (Andrey V. Dudarev) Date: Thu Aug 2 10:46:27 2007 Subject: init script on openSuSE problem Message-ID: <1186048179.17253.69.camel@x5.paragon-software.com> I use Mailscanner 4.62.9 on openSuse 10.2 x86-84 with sendmail. When I restart Mailscanner with the help of init script from Suse tarball sendmail doesn't start. ------------------- mx10:/etc/init.d # /etc/init.d/MailScanner restart Shutting down sendmail and MailScanner done Initializing incoming sendmail done Initializing outgoing sendmail done Initializing MailScanner mx10:/etc/init.d # ps ax | grep MailScanner 10437 ? Ss 0:00 MailScanner: starting children 10438 ? S 0:00 MailScanner: checking with SpamAssassin 10479 ? S 0:02 MailScanner: checking with SpamAssassin 10481 ? S 0:00 MailScanner: checking with SpamAssassin 10491 ? S 0:01 MailScanner: checking with SpamAssassin 10505 pts/1 S+ 0:00 grep MailScanner mx10:/etc/init.d # telnet localhost 25 Trying 127.0.0.1... telnet: connect to address 127.0.0.1: Connection refused Trying ::1... telnet: connect to address ::1: Connection refused ------------------ Can you advise how to fix it? From prandal at herefordshire.gov.uk Thu Aug 2 11:33:38 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Thu Aug 2 11:33:45 2007 Subject: McAfee 5200 Engine Released Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA01510C4C@HC-MBX02.herefordshire.gov.uk> Folks, McAfee have released their 5200 scan engine and along with it new scanners for Unix / Linux. You can download them from the corporate download site (needs your NAI grant number). Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK From glenn.steen at gmail.com Thu Aug 2 11:36:28 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu Aug 2 11:36:30 2007 Subject: init script on openSuSE problem In-Reply-To: <1186048179.17253.69.camel@x5.paragon-software.com> References: <1186048179.17253.69.camel@x5.paragon-software.com> Message-ID: <223f97700708020336u60a4b734gc3f3267c0618748d@mail.gmail.com> On 02/08/07, Andrey V. Dudarev wrote: > I use Mailscanner 4.62.9 on openSuse 10.2 x86-84 with sendmail. When I > restart Mailscanner with the help of init script from Suse tarball > sendmail doesn't start. > ------------------- > mx10:/etc/init.d # /etc/init.d/MailScanner restart > Shutting down sendmail and MailScanner done > Initializing incoming sendmail > done > Initializing outgoing sendmail > done > Initializing MailScanner > mx10:/etc/init.d # ps ax | grep MailScanner > 10437 ? Ss 0:00 MailScanner: starting children > 10438 ? S 0:00 MailScanner: checking with SpamAssassin > 10479 ? S 0:02 MailScanner: checking with SpamAssassin > 10481 ? S 0:00 MailScanner: checking with SpamAssassin > 10491 ? S 0:01 MailScanner: checking with SpamAssassin > 10505 pts/1 S+ 0:00 grep MailScanner > mx10:/etc/init.d # telnet localhost 25 > Trying 127.0.0.1... > telnet: connect to address 127.0.0.1: Connection refused > Trying ::1... > telnet: connect to address ::1: Connection refused > ------------------ > Can you advise how to fix it? > Does your sendmail start up? Do your sendmail listen on the loopback interface/address? Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From FStein at thehill.org Thu Aug 2 13:06:47 2007 From: FStein at thehill.org (Stein, Mr. Fred) Date: Thu Aug 2 13:14:24 2007 Subject: MailScanner --lint error In-Reply-To: <223f97700708020110o441b6713w4711556f930bb393@mail.gmail.com> References: <223f97700708020110o441b6713w4711556f930bb393@mail.gmail.com> Message-ID: -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Glenn Steen Sent: Thursday, August 02, 2007 4:10 AM To: MailScanner discussion Subject: Re: MailScanner --lint error On 02/08/07, Stein, Mr. Fred wrote: > I am getting the following error when I run MailScanner --lint on a Centos 4.2, Postfix install. Any help would appreciated. > Checking version numbers... > Version number in MailScanner.conf (4.62.9) is correct. > Your envelope_sender_header in spam.assassin.prefs.conf is correct. > Checking for SpamAssassin errors (if you use it)... > SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp > netset: cannot include 127.0.0.1/32 as it has already been included > SpamAssassin reported no errors. > MailScanner.conf says "Virus Scanners = auto" > Found these virus scanners installed: bitdefender, f-prot, clamavmodule > ======================================================================== === > Ignore errors about failing to find EOCD signature > Bad file descriptor,Bad file descriptor at /usr/lib/MailScanner/MailScanner/PFDiskStore.pm line 656. > > Fred Stein > Network Administrator > The Hill School > 717 High Street > Pottstown, PA 19464 > 610-326-1000 ext. 7356 > fstein@thehill.org > www.thehill.org Hi Fred, Either use the one-line patch Jules sent to me (In thread with subject: "4.62.9-1 lint error w/mcafee (UNCLASSIFIED)"), or donwload and install 4.62.9-2 from the usual place...The patch is to "lie" a bit and pretend you're using sendmail if you do a lint only call of MailScanner:-). I haven't looked at if this has any side effects that are unforseen, but... I trust Jules...:-). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! Glenn Thanks, I realized that after I posted and read the earlier posts. I guess I should read first post second. Thanks again, Fred From rcooper at dwford.com Thu Aug 2 13:26:39 2007 From: rcooper at dwford.com (Rick Cooper) Date: Thu Aug 2 13:26:44 2007 Subject: 4.62.9-1 & MailScanner --lint [FIXED - but why?] In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470B1258A7@largo.campus.ncl.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470B125888@largo.campus.ncl.ac.uk><7EF0EE5CB3B263488C8C18823239BEBA01510BA8@HC-MBX02.herefordshire.gov.uk> <4165CF7A7F12DE4B96622CCBB90586470B1258A7@largo.campus.ncl.ac.uk> Message-ID: <03c801c7d500$60e40120$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On > Behalf Of Quentin Campbell > Sent: Thursday, August 02, 2007 3:38 AM > To: MailScanner discussion > Subject: RE: 4.62.9-1 & MailScanner --lint [FIXED - but why?] > > Phil > > Thanks for the reply. > > Where are your 'main.cvd' and 'daily.cvd' files kept? > > A little more research and digging found the problem but I > am unclear as > to how the situation came about. There is now a new > maintenance problem > to be resolved and some worrying questions. > > The " LibClamAV Warning: *** The virus database is older > than 7 days. > ***" message arises because there was a second location > containing very > old (July 26, 2005) copies of main.cvd and daily.cvd under > /usr/local/share/clamav. In my current installation I keep the '.cvd' > files under /usr/local/clamav. > > If I remove the 'clamav' sub-directory from /usr/local/share > or remove > the two files from under it then 'MailScanner --lint' complains. If I > copy my current two '.cvd' files from /usr/local/clamav to > /usr/local/share/clamav then MailScanner --lint works OK. > > QUESTIONS: > > 1. When was the /usr/local/share/clamv sub-directory created and why? > 2. Why is a /usr/local/share/clamav needed when my > /usr/local/etc/freshclam.conf file specifies /usr/local/clamav as the > '.cvd' files location? > 3. Has 'clamavmodule' been using these very old '.cvd' files > for virus > detection? > 4. There is the maintenance issue - how do I keep the > /usr/local/share/clamav/*.cvd files up to date? ANSWER: I > suppose when > using 'clamavmodule' I should change > /usr/local/etc/freshclam.conf and > replace > > DatabaseDirectory /usr/local/clamav > > with > > DatabaseDirectory /usr/local/share/clamav > > Alternately I can make /usr/local/share/clamav a link to > /usr/local/clamav (or vice versa). What is best? > > Had I missed and important documented step when I swapped from using > 'clamscan' to using 'clamavmodule'? If so I cannot find it! > This is more common than you might think. The most common complaint resulting from this (on the clamav list) is not catching viruses through (MailScanner|AMAVIS|Other) scanners, but from the command line the scanner works fine. The most common cause is installing clamav with two differing methods, RPM then source or visa versa which would generally result in two different --prefix designations. The best thing you could do is uninstall both installations and reinstall, and always install with the same method. Make sure and locate both sets of binaries and libraries (example: locate libclamav.so && locate bin/clamscan). I would reinstall ClamAVModule after you have done that. Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From theodrake at comcast.net Thu Aug 2 13:29:22 2007 From: theodrake at comcast.net (Ed Bruce) Date: Thu Aug 2 13:28:10 2007 Subject: CRM114 How are you finding it ? In-Reply-To: References: <1951DC816E1A9F469307B05FA183F4389DC9E0@corpatsmail1.corp.sensis.com> <46B0F5BA.3050708@comcast.net> Message-ID: <46B1CE22.8000304@comcast.net> Scott Silva wrote: > Ed Bruce spake the following on 8/1/2007 2:06 PM: >> Desai, Jason wrote: >>> >>> >>>> Too soon to tell, really. >>>> >>>> Only been running it for 21 hours so far. >>>> >>>> It's pushed some emails into the high-scoring range, but >>>> scored negative >>>> points on some obvious spam (but not enough to make it end up >>>> in users' >>>> inboxes). >>>> >>>> So far so good. >>> Same here. I'm running it with >>> >>> crm114_dynscore_factor -0.01 >>> >>> I'll probably let it run like this for a week or so, and then see how >>> it's doing before changing the factor. >>> >>> Possibly useful to some - I'm using this to analyze the scores (watch >>> the line wraps): >>> >>> grep CRM114_CHECK /var/log/mail.log | sed -re "s/.*: Message >>> ([A-Za-z0-9-]+) .*\bscore=([0-9.-]+), .*\bCRM114_CHECK >>> ([0-9.-]+).*/Id:\1\tSA Score:\2\t\tCRM114 Score:\3 /" >>> >>> >>> This will go through your mail log and print output for messages scored >>> with CRM114 in the format: >> For future reference with what MTA does this work? It does not work with >> Postfix. > Did you fix the initial path to your maillog, as mail.log might not be correct > for you. > lol. Yes I did but then I ran it on the wrong server. Amazing how things work when you use it on the machine where crm114 is installed. -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 249 bytes Desc: OpenPGP digital signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070802/b21bf395/signature.bin From telsek at paragon-software.com Thu Aug 2 13:29:22 2007 From: telsek at paragon-software.com (Andrey V. Dudarev) Date: Thu Aug 2 13:29:43 2007 Subject: init script on openSuSE problem In-Reply-To: <200708021100.l72B0ASD029233@safir.blacknight.ie> References: <200708021100.l72B0ASD029233@safir.blacknight.ie> Message-ID: <1186057762.17253.83.camel@x5.paragon-software.com> On Thu, 2007-08-02 at 12:00 +0100, mailscanner-request@lists.mailscanner.info wrote: > On 02/08/07, Andrey V. Dudarev wrote: > > I use Mailscanner 4.62.9 on openSuse 10.2 x86-84 with sendmail. > When I > > restart Mailscanner with the help of init script from Suse tarball > > sendmail doesn't start. > > ------------------- > > mx10:/etc/init.d # /etc/init.d/MailScanner restart > > Shutting down sendmail and MailScanner done > > Initializing incoming sendmail > > done > > Initializing outgoing sendmail > > done > > Initializing MailScanner > > mx10:/etc/init.d # ps ax | grep MailScanner > > 10437 ? Ss 0:00 MailScanner: starting children > > 10438 ? S 0:00 MailScanner: checking with SpamAssassin > > 10479 ? S 0:02 MailScanner: checking with SpamAssassin > > 10481 ? S 0:00 MailScanner: checking with SpamAssassin > > 10491 ? S 0:01 MailScanner: checking with SpamAssassin > > 10505 pts/1 S+ 0:00 grep MailScanner > > mx10:/etc/init.d # telnet localhost 25 > > Trying 127.0.0.1... > > telnet: connect to address 127.0.0.1: Connection refused > > Trying ::1... > > telnet: connect to address ::1: Connection refused > > ------------------ > > Can you advise how to fix it? > > > Does your sendmail start up? the matter that it is yes so mx10:/etc/mail # /etc/init.d/MailScanner stop Shutting down sendmail and MailScanner done mx10:/etc/mail # ps ax | grep Mail 16463 pts/1 S+ 0:00 grep Mail mx10:/etc/mail # ps ax | grep sendmail mx10:/etc/mail # /etc/init.d/MailScanner start Initializing incoming sendmail done Initializing outgoing sendmail done Initializing MailScanner mx10:/etc/mail # mx10:/var/run # ps ax | grep Mail 16517 ? Ss 0:00 MailScanner: master waiting for children, sleeping 16518 ? S 0:00 MailScanner: checking with SpamAssassin 16520 ? S 0:00 MailWatch SQL 16545 ? S 0:00 MailScanner: waiting for messages 16552 ? S 0:00 MailScanner: waiting for messages 16568 ? S 0:00 MailScanner: waiting for messages 16592 ? S 0:00 MailScanner: waiting for messages 16656 ? S 0:01 MailScanner: checking with SpamAssassin 16659 pts/1 S+ 0:00 grep Mail 16494 ? Ss 0:00 sendmail: Queue control 16495 ? S 0:00 sendmail: running queue: /var/spool/clientmqueue 16498 ? Ss 0:00 sendmail: Queue runner@00:30:00 for /var/spool/mqueue 16499 ? S 0:00 sendmail: ./l72BYOMe002289 www.jerboa.com.: user open 16551 pts/1 S+ 0:00 grep sendmail mx10:/etc/mail # mx10:/var/run # ps ax | grep sendmail 16494 ? Ss 0:00 sendmail: Queue control 16495 ? S 0:00 sendmail: running queue: /var/spool/clientmqueue 16498 ? Ss 0:00 sendmail: Queue runner@00:30:00 for /var/spool/mqueue 16499 ? S 0:00 sendmail: ./l72BYOMe002289 www.jerboa.com.: user open 16551 pts/1 S+ 0:00 grep sendmail mx10:/etc/mail # telnet localhost 25 Trying 127.0.0.1... telnet: connect to address 127.0.0.1: Connection refused Trying ::1... telnet: connect to address ::1: Connection refused > Do your sendmail listen on the loopback interface/address? yes mx10:/var/log # netstat -anp | grep LISTEN tcp 0 0 127.0.0.1:11553 0.0.0.0:* LISTEN 16444/MailWatch SQL tcp 0 0 0.0.0.0:5666 0.0.0.0:* LISTEN 3296/nrpe tcp 0 0 0.0.0.0:3306 0.0.0.0:* LISTEN 3394/mysqld tcp 0 0 127.0.0.1:2544 0.0.0.0:* LISTEN 3308/zmd tcp 0 0 0.0.0.0:4949 0.0.0.0:* LISTEN 3396/munin-node tcp 0 0 0.0.0.0:25 0.0.0.0:* LISTEN 3418/sendmail: acce From maillists at conactive.com Thu Aug 2 13:31:11 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu Aug 2 13:31:14 2007 Subject: MS Hanging In-Reply-To: <31327980.9891186047016995.JavaMail.root@office.splatnix.net> References: <31327980.9891186047016995.JavaMail.root@office.splatnix.net> Message-ID: UxBoD wrote on Thu, 2 Aug 2007 10:30:16 +0100 (BST): > Spam List = ORDB-RBL spamhaus.org spamhaus-XBL spamhaus-ZEN spamcop.net NJABL CBL RSL DSBL BLITZEDALL SORBS-DNSBL SORBS-HTTP SORBS-SOCKS SORBS-MISC SORBS-SMTP SORBS-WEB SORBS-SPAM SORBS-BLOCK SORBS-ZOMBIE SORBS-DUL SORBS-RHSBL Oh, my god. No wonder, that it's slow. Compile some stats which of these lists really give you an advantage. You will see that after two or three good ones any other will only add marginally and are not worth the query as those few are caught by SA, anyway. Especially this is totally insane (sorry): SORBS-DNSBL SORBS-HTTP SORBS-SOCKS SORBS-MISC SORBS-SMTP SORBS-WEB SORBS-SPAM SORBS-BLOCK SORBS-ZOMBIE SORBS-DUL SORBS-RHSBL These lists are all included in SORBS-DNSBL. And, as Martin, says, ZEN includes all Spamhaus lists *plus* CBL. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From prandal at herefordshire.gov.uk Thu Aug 2 13:45:50 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Thu Aug 2 13:46:04 2007 Subject: MS Hanging In-Reply-To: References: <31327980.9891186047016995.JavaMail.root@office.splatnix.net> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA01510CBA@HC-MBX02.herefordshire.gov.uk> cbl.abuseat.org by itself gets a huge proportion of the spam here. Remember that spamhaus requires a subscription for high-volume users. >From http://www.spamhaus.org/zen/index.lasso "Use of the Spamhaus DNSBLs via DNS queries to our public DNSBL mirrors is free for low-traffic mail servers serving less than 100 users. Use of the Spamhaus DNSBLs by commercial or corporate networks, ISPs and ESPs, requires a subscription to Spamhaus's Data Feed service." Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Kai Schaetzl > Sent: 02 August 2007 13:31 > To: mailscanner@lists.mailscanner.info > Subject: Re: MS Hanging > > UxBoD wrote on Thu, 2 Aug 2007 10:30:16 +0100 (BST): > > > Spam List = ORDB-RBL spamhaus.org spamhaus-XBL spamhaus-ZEN > spamcop.net NJABL CBL > RSL DSBL BLITZEDALL SORBS-DNSBL SORBS-HTTP SORBS-SOCKS > SORBS-MISC SORBS-SMTP SORBS-WEB > SORBS-SPAM SORBS-BLOCK SORBS-ZOMBIE SORBS-DUL SORBS-RHSBL > > Oh, my god. No wonder, that it's slow. Compile some stats > which of these lists really > give you an advantage. You will see that after two or three > good ones any other will > only add marginally and are not worth the query as those few > are caught by SA, anyway. > > Especially this is totally insane (sorry): > SORBS-DNSBL SORBS-HTTP SORBS-SOCKS SORBS-MISC SORBS-SMTP > SORBS-WEB SORBS-SPAM > SORBS-BLOCK SORBS-ZOMBIE SORBS-DUL SORBS-RHSBL > > These lists are all included in SORBS-DNSBL. > > And, as Martin, says, ZEN includes all Spamhaus lists *plus* CBL. > > > Kai > > -- > Kai Sch?tzl, Berlin, Germany > Get your web at Conactive Internet Services: http://www.conactive.com > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From uxbod at splatnix.net Thu Aug 2 13:58:55 2007 From: uxbod at splatnix.net (UxBoD) Date: Thu Aug 2 13:53:09 2007 Subject: MS Hanging In-Reply-To: Message-ID: <14307428.10341186059535002.JavaMail.root@office.splatnix.net> Feeling like a complete muppet today! Thanks all. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Kai Schaetzl" To: mailscanner@lists.mailscanner.info Sent: Thursday, August 2, 2007 1:31:11 PM (GMT) Europe/London Subject: Re: MS Hanging UxBoD wrote on Thu, 2 Aug 2007 10:30:16 +0100 (BST): > Spam List = ORDB-RBL spamhaus.org spamhaus-XBL spamhaus-ZEN spamcop.net NJABL CBL RSL DSBL BLITZEDALL SORBS-DNSBL SORBS-HTTP SORBS-SOCKS SORBS-MISC SORBS-SMTP SORBS-WEB SORBS-SPAM SORBS-BLOCK SORBS-ZOMBIE SORBS-DUL SORBS-RHSBL Oh, my god. No wonder, that it's slow. Compile some stats which of these lists really give you an advantage. You will see that after two or three good ones any other will only add marginally and are not worth the query as those few are caught by SA, anyway. Especially this is totally insane (sorry): SORBS-DNSBL SORBS-HTTP SORBS-SOCKS SORBS-MISC SORBS-SMTP SORBS-WEB SORBS-SPAM SORBS-BLOCK SORBS-ZOMBIE SORBS-DUL SORBS-RHSBL These lists are all included in SORBS-DNSBL. And, as Martin, says, ZEN includes all Spamhaus lists *plus* CBL. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From pmb1 at york.ac.uk Thu Aug 2 14:00:57 2007 From: pmb1 at york.ac.uk (Mike Brudenell) Date: Thu Aug 2 14:00:58 2007 Subject: MS Hanging In-Reply-To: References: <31327980.9891186047016995.JavaMail.root@office.splatnix.net> Message-ID: <5143214D-AB7B-4DCF-9A76-A0DE58138E2F@york.ac.uk> Greetings - On 2 Aug 2007, at 13:31, Kai Schaetzl wrote: > UxBoD wrote on Thu, 2 Aug 2007 10:30:16 +0100 (BST): > >> Spam List = ORDB-RBL spamhaus.org spamhaus-XBL spamhaus-ZEN >> spamcop.net NJABL CBL > RSL DSBL BLITZEDALL SORBS-DNSBL SORBS-HTTP SORBS-SOCKS SORBS-MISC > SORBS-SMTP SORBS-WEB SORBS-SPAM SORBS-BLOCK SORBS-ZOMBIE SORBS-DUL > SORBS-RHSBL > > Oh, my god. No wonder, that it's slow. Compile some stats which of > these lists really give you an advantage. You will see that after > two or three good ones any other will only add marginally and are > not worth the query as those few are caught by SA, anyway. ...And if "ORDB-RBL" is the ordb.org list then remove that one too: it closed down on 31 December 2006. Cheers, Mike B-) -- The Computing Service, University of York, Heslington, York Yo10 5DD, UK Tel:+44-1904-433811 FAX:+44-1904-433740 * Unsolicited commercial e-mail is NOT welcome at this e-mail address. * From mikael at syska.dk Thu Aug 2 14:15:35 2007 From: mikael at syska.dk (Mikael Syska) Date: Thu Aug 2 14:14:27 2007 Subject: MS Hanging In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA01510CBA@HC-MBX02.herefordshire.gov.uk> References: <31327980.9891186047016995.JavaMail.root@office.splatnix.net> <7EF0EE5CB3B263488C8C18823239BEBA01510CBA@HC-MBX02.herefordshire.gov.uk> Message-ID: <46B1D8F7.4000002@syska.dk> Hi, Little off-topic .... Caching dns would also lower the traffic ... or am I wrong here ? Is it safe to only make spams get one hit from the ZEN-SPAMHAUS, I can see that the default in the MailScanner.conf is 1 ? // ouT Randal, Phil wrote: > cbl.abuseat.org by itself gets a huge proportion of the spam here. > > Remember that spamhaus requires a subscription for high-volume users. > > >From http://www.spamhaus.org/zen/index.lasso > > "Use of the Spamhaus DNSBLs via DNS queries to our public DNSBL mirrors is free for low-traffic mail servers serving less than 100 users. Use of the Spamhaus DNSBLs by commercial or corporate networks, ISPs and ESPs, requires a subscription to Spamhaus's Data Feed service." > > Cheers, > > Phil > -- > Phil Randal > Network Engineer > Herefordshire Council > Hereford, UK > > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf >> Of Kai Schaetzl >> Sent: 02 August 2007 13:31 >> To: mailscanner@lists.mailscanner.info >> Subject: Re: MS Hanging >> >> UxBoD wrote on Thu, 2 Aug 2007 10:30:16 +0100 (BST): >> >> >>> Spam List = ORDB-RBL spamhaus.org spamhaus-XBL spamhaus-ZEN >>> >> spamcop.net NJABL CBL >> RSL DSBL BLITZEDALL SORBS-DNSBL SORBS-HTTP SORBS-SOCKS >> SORBS-MISC SORBS-SMTP SORBS-WEB >> SORBS-SPAM SORBS-BLOCK SORBS-ZOMBIE SORBS-DUL SORBS-RHSBL >> >> Oh, my god. No wonder, that it's slow. Compile some stats >> which of these lists really >> give you an advantage. You will see that after two or three >> good ones any other will >> only add marginally and are not worth the query as those few >> are caught by SA, anyway. >> >> Especially this is totally insane (sorry): >> SORBS-DNSBL SORBS-HTTP SORBS-SOCKS SORBS-MISC SORBS-SMTP >> SORBS-WEB SORBS-SPAM >> SORBS-BLOCK SORBS-ZOMBIE SORBS-DUL SORBS-RHSBL >> >> These lists are all included in SORBS-DNSBL. >> >> And, as Martin, says, ZEN includes all Spamhaus lists *plus* CBL. >> >> >> Kai >> >> -- >> Kai Sch?tzl, Berlin, Germany >> Get your web at Conactive Internet Services: http://www.conactive.com >> >> >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >> From MailScanner at ecs.soton.ac.uk Thu Aug 2 15:00:02 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 2 15:00:26 2007 Subject: MS Hanging In-Reply-To: <46B1D8F7.4000002@syska.dk> References: <31327980.9891186047016995.JavaMail.root@office.splatnix.net> <7EF0EE5CB3B263488C8C18823239BEBA01510CBA@HC-MBX02.herefordshire.gov.uk> <46B1D8F7.4000002@syska.dk> Message-ID: <46B1E362.7090005@ecs.soton.ac.uk> That's what I do here, with no complaints from very fussy academic users. Mikael Syska wrote: > Hi, > > Little off-topic .... > > Caching dns would also lower the traffic ... or am I wrong here ? > > Is it safe to only make spams get one hit from the ZEN-SPAMHAUS, I can > see that the default in the MailScanner.conf is 1 ? > > // ouT > > Randal, Phil wrote: >> cbl.abuseat.org by itself gets a huge proportion of the spam here. >> >> Remember that spamhaus requires a subscription for high-volume users. >> >> >From http://www.spamhaus.org/zen/index.lasso >> "Use of the Spamhaus DNSBLs via DNS queries to our public DNSBL >> mirrors is free for low-traffic mail servers serving less than 100 >> users. Use of the Spamhaus DNSBLs by commercial or corporate >> networks, ISPs and ESPs, requires a subscription to Spamhaus's Data >> Feed service." >> >> Cheers, >> >> Phil >> -- >> Phil Randal >> Network Engineer >> Herefordshire Council >> Hereford, UK >> >>> -----Original Message----- >>> From: mailscanner-bounces@lists.mailscanner.info >>> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Kai >>> Schaetzl >>> Sent: 02 August 2007 13:31 >>> To: mailscanner@lists.mailscanner.info >>> Subject: Re: MS Hanging >>> >>> UxBoD wrote on Thu, 2 Aug 2007 10:30:16 +0100 (BST): >>> >>> >>>> Spam List = ORDB-RBL spamhaus.org spamhaus-XBL spamhaus-ZEN >>> spamcop.net NJABL CBL RSL DSBL BLITZEDALL SORBS-DNSBL SORBS-HTTP >>> SORBS-SOCKS SORBS-MISC SORBS-SMTP SORBS-WEB SORBS-SPAM SORBS-BLOCK >>> SORBS-ZOMBIE SORBS-DUL SORBS-RHSBL >>> >>> Oh, my god. No wonder, that it's slow. Compile some stats which of >>> these lists really >>> give you an advantage. You will see that after two or three good >>> ones any other will only add marginally and are not worth the query >>> as those few are caught by SA, anyway. >>> >>> Especially this is totally insane (sorry): >>> SORBS-DNSBL SORBS-HTTP SORBS-SOCKS SORBS-MISC SORBS-SMTP SORBS-WEB >>> SORBS-SPAM SORBS-BLOCK SORBS-ZOMBIE SORBS-DUL SORBS-RHSBL >>> >>> These lists are all included in SORBS-DNSBL. >>> >>> And, as Martin, says, ZEN includes all Spamhaus lists *plus* CBL. >>> >>> >>> Kai >>> >>> -- >>> Kai Sch?tzl, Berlin, Germany >>> Get your web at Conactive Internet Services: http://www.conactive.com >>> >>> >>> >>> -- >>> MailScanner mailing list >>> mailscanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> >>> Before posting, read http://wiki.mailscanner.info/posting >>> >>> Support MailScanner development - buy the book off the website! >>> > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From uxbod at splatnix.net Thu Aug 2 15:36:14 2007 From: uxbod at splatnix.net (UxBoD) Date: Thu Aug 2 15:30:28 2007 Subject: CRM114 How are you finding it ? In-Reply-To: <46B1CE22.8000304@comcast.net> Message-ID: <23561118.10401186065374089.JavaMail.root@office.splatnix.net> This is for the last hour :- Msg:AB1D67D1052.7DA6B Total Score:7.603 CRM114: 0.99 Without CRM114: 6.613 *** Msg:2F7E37D1054.26F5C Total Score:7.448 CRM114: 1.74 Without CRM114: 5.708 *** Msg:0C5BF7D1063.38163 Total Score:7.603 CRM114: 0.99 Without CRM114: 6.613 *** Msg:A5D417D1054.A5466 Total Score:7.603 CRM114: 0.99 Without CRM114: 6.613 *** Msg:B743A7D1060.41A63 Total Score:7.275 CRM114: 0.87 Without CRM114: 6.405 *** Msg:5F5297D105E.C9D42 Total Score:7.603 CRM114: 0.99 Without CRM114: 6.613 *** Total Messages: 794 How many times was CRM114 wrong? False Negative: 0 (0%) False Positive: 6 (0.75%) Total Errors: 6 (0.75%) How many times did CRM114 cause an error? False Negative: 0 (0%) False Positive: 6 (0.75%) Total Errors: 6 (0.75%) I have checked all the messages and they are indeed SPAM :) Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From maillists at conactive.com Thu Aug 2 15:31:29 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu Aug 2 15:31:33 2007 Subject: init script on openSuSE problem In-Reply-To: <1186057762.17253.83.camel@x5.paragon-software.com> References: <200708021100.l72B0ASD029233@safir.blacknight.ie> <1186057762.17253.83.camel@x5.paragon-software.com> Message-ID: Andrey V. Dudarev wrote on Thu, 02 Aug 2007 16:29:22 +0400: > > Do your sendmail listen on the loopback interface/address? > yes Well, have you ever tried to start sendmail alone without MailScanner (so, with the sendmail init script)? I bet that you get the same problem. It's not correctly configured or there is a firewall blocking the connect. > tcp 0 0 0.0.0.0:25 0.0.0.0:* > LISTEN 3418/sendmail: acce It's listening on all interfaces, not just loopback. Have you verified that you cannot connect to other interfaces either? (Just to be sure it's not an obscure problem affecting only loopback.) SuSE usually comes preconfigured so sendmail listens only on loopback, but this doesn't seem to be your problem here. So, as said above, it's either a firewall or a sendmail misconfiguration. To troubleshoot this set the Log Level in sendmail to 14 and start it by it's own and check the mail log. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Thu Aug 2 15:40:11 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu Aug 2 15:40:13 2007 Subject: MS Hanging In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA01510CBA@HC-MBX02.herefordshire.gov.uk> References: <31327980.9891186047016995.JavaMail.root@office.splatnix.net> <7EF0EE5CB3B263488C8C18823239BEBA01510CBA@HC-MBX02.herefordshire.gov.uk> Message-ID: Phil Randal wrote on Thu, 2 Aug 2007 13:45:50 +0100: > "Use of the Spamhaus DNSBLs via DNS queries to our public DNSBL mirrors is free for low-traffic mail servers serving less than 100 users. Use of the Spamhaus DNSBLs by commercial or corporate networks, ISPs and ESPs, requires a subscription to Spamhaus's Data Feed service." yeah, this could also add to his problems as I understand from earlier postings that he's got high volume servers. SORBS has also starting restricting high volume queries, so basically most of the RBLs used are timing out, especially if he's unnecessarily multiplying the checks. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Thu Aug 2 15:40:11 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu Aug 2 15:40:14 2007 Subject: MS Hanging In-Reply-To: <46B1D8F7.4000002@syska.dk> References: <31327980.9891186047016995.JavaMail.root@office.splatnix.net> <7EF0EE5CB3B263488C8C18823239BEBA01510CBA@HC-MBX02.herefordshire.gov.uk> <46B1D8F7.4000002@syska.dk> Message-ID: Mikael Syska wrote on Thu, 02 Aug 2007 15:15:35 +0200: > Is it safe to only make spams get one hit from the ZEN-SPAMHAUS, I can > see that the default in the MailScanner.conf is 1 ? Spamhaus can be safely used at MTA level, anyway. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From uxbod at splatnix.net Thu Aug 2 15:56:10 2007 From: uxbod at splatnix.net (UxBoD) Date: Thu Aug 2 15:50:30 2007 Subject: MS Hanging In-Reply-To: Message-ID: <25644788.10431186066570733.JavaMail.root@office.splatnix.net> I have reduced our list now to one, plus have setup our own internal RBL server for black/white list entries. Using the MailWatch SQL table and some PHP I generate the two lists and feed them into RBLDNSD. For both lists if I source IP appears > 5 times within last seven days then it will be added. SA scores are the same as the score to mark a message as spam but positive for black and negative for white. If a IP addresses appeared on both then score would be zero, and would take the normal generated SA score. Seems to be working okay at the moment. All private IPs are suppressed. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Kai Schaetzl" To: mailscanner@lists.mailscanner.info Sent: Thursday, August 2, 2007 3:40:11 PM (GMT) Europe/London Subject: Re: MS Hanging Phil Randal wrote on Thu, 2 Aug 2007 13:45:50 +0100: > "Use of the Spamhaus DNSBLs via DNS queries to our public DNSBL mirrors is free for low-traffic mail servers serving less than 100 users. Use of the Spamhaus DNSBLs by commercial or corporate networks, ISPs and ESPs, requires a subscription to Spamhaus's Data Feed service." yeah, this could also add to his problems as I understand from earlier postings that he's got high volume servers. SORBS has also starting restricting high volume queries, so basically most of the RBLs used are timing out, especially if he's unnecessarily multiplying the checks. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From mikael at syska.dk Thu Aug 2 16:48:06 2007 From: mikael at syska.dk (Mikael Syska) Date: Thu Aug 2 16:46:57 2007 Subject: MS Hanging In-Reply-To: References: <31327980.9891186047016995.JavaMail.root@office.splatnix.net> <7EF0EE5CB3B263488C8C18823239BEBA01510CBA@HC-MBX02.herefordshire.gov.uk> <46B1D8F7.4000002@syska.dk> Message-ID: <46B1FCB6.2040606@syska.dk> Kai Schaetzl wrote: > Mikael Syska wrote on Thu, 02 Aug 2007 15:15:35 +0200: > > >> Is it safe to only make spams get one hit from the ZEN-SPAMHAUS, I can >> see that the default in the MailScanner.conf is 1 ? >> > > Spamhaus can be safely used at MTA level, anyway. > Well ... I want the logs in mailwatch and also to be used with bayes .... we dont have that much traffic here ... about 20k mail in a day, and 85% of them are spam. Many of you are taking about timeouts because of high amount of quries. How much would a local bind dns benifit? how many quries would come from the cache? (I'm thinking of using BIND here ... ) > Kai > Syska From binaryflow at gmail.com Thu Aug 2 17:58:23 2007 From: binaryflow at gmail.com (Douglas Ward) Date: Thu Aug 2 17:58:28 2007 Subject: pdfassassin Message-ID: http://freshmeat.net/projects/pdfassassin/ Looks interesting. Has anyone given this a look? -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070802/5bfe838d/attachment.html From ssilva at sgvwater.com Thu Aug 2 18:00:42 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 2 18:01:03 2007 Subject: MailScanner --lint error In-Reply-To: References: Message-ID: Stein, Mr. Fred spake the following on 8/1/2007 5:31 PM: > I am getting the following error when I run MailScanner --lint on a Centos 4.2, Postfix install. Any help would appreciated. Not related, but you might want to run yum update if you are truly running at CentOS 4.2. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From Kevin_Miller at ci.juneau.ak.us Thu Aug 2 18:07:53 2007 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Thu Aug 2 18:07:25 2007 Subject: init script on openSuSE problem In-Reply-To: References: <200708021100.l72B0ASD029233@safir.blacknight.ie><1186057762.17253.83.camel@x5.paragon-software.com> Message-ID: Kai Schaetzl wrote: > Andrey V. Dudarev wrote on Thu, 02 Aug 2007 16:29:22 +0400: > >>> Do your sendmail listen on the loopback interface/address? yes > > Well, have you ever tried to start sendmail alone without MailScanner > (so, with the sendmail init script)? I bet that you get the same > problem. It's not correctly configured or there is a firewall > blocking the connect. > >> tcp 0 0 0.0.0.0:25 0.0.0.0:* >> LISTEN 3418/sendmail: acce > > It's listening on all interfaces, not just loopback. Have you verified > that you cannot connect to other interfaces either? (Just to be sure > it's not an obscure problem affecting only loopback.) > SuSE usually comes preconfigured so sendmail listens only on > loopback, but this doesn't seem to be your problem here. So, as said > above, it's either a firewall or a sendmail misconfiguration. To > troubleshoot this set the Log Level in sendmail to 14 and start it by > it's own and check the mail log. It's been a while, but I think he needs to go to /etc/sysconfig/mail (or thereabouts) and set sendmail to listen to remote connections. By default it's set to only listen to localhost... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From maillists at conactive.com Thu Aug 2 18:29:30 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu Aug 2 18:29:33 2007 Subject: init script on openSuSE problem In-Reply-To: References: <200708021100.l72B0ASD029233@safir.blacknight.ie> <1186057762.17253.83.camel@x5.paragon-software.com> Message-ID: Kevin Miller wrote on Thu, 2 Aug 2007 09:07:53 -0800: > It's been a while, but I think he needs to go to /etc/sysconfig/mail (or > thereabouts) and set sendmail to listen to remote connections. By > default it's set to only listen to localhost... Yes, but: as I already said it *does* listen on all interfaces (0.0.0.0 means all IPv4 interfaces), so this is not the problem! He cannot even connect on loopback, so it's basically dead. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From MailScanner at ecs.soton.ac.uk Thu Aug 2 18:38:53 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 2 18:39:23 2007 Subject: Improved init.d script Message-ID: <46B216AD.1010204@ecs.soton.ac.uk> Skipped content of type multipart/mixed-------------- next part -------------- A non-text attachment was scrubbed... Name: PGP.sig Type: application/pgp-signature Size: 195 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070802/33266001/PGP.bin From uxbod at splatnix.net Thu Aug 2 18:45:53 2007 From: uxbod at splatnix.net (UxBoD) Date: Thu Aug 2 18:39:56 2007 Subject: pdfassassin In-Reply-To: Message-ID: <26414104.10461186076753928.JavaMail.root@office.splatnix.net> Does not work on the latest PDF spam as they are encrypted. PDFInfo from SARE does the trick for me. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Douglas Ward" To: "MailScanner discussion" Sent: Thursday, August 2, 2007 5:58:23 PM (GMT) Europe/London Subject: pdfassassin -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From Kevin_Miller at ci.juneau.ak.us Thu Aug 2 18:49:45 2007 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Thu Aug 2 18:49:21 2007 Subject: init script on openSuSE problem In-Reply-To: References: <200708021100.l72B0ASD029233@safir.blacknight.ie><1186057762.17253.83.camel@x5.paragon-software.com> Message-ID: Kai Schaetzl wrote: > Kevin Miller wrote on Thu, 2 Aug 2007 09:07:53 -0800: > >> It's been a while, but I think he needs to go to /etc/sysconfig/mail >> (or thereabouts) and set sendmail to listen to remote connections. >> By default it's set to only listen to localhost... > > Yes, but: as I already said it *does* listen on all interfaces > (0.0.0.0 means all IPv4 interfaces), so this is not the problem! He > cannot even connect on loopback, so it's basically dead. Ah, so you did. That's what I get for skimming the messages instead of reading. ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From lists at jfworks.net Thu Aug 2 18:52:47 2007 From: lists at jfworks.net (James) Date: Thu Aug 2 18:52:56 2007 Subject: Improved init.d script In-Reply-To: <46B216AD.1010204@ecs.soton.ac.uk> References: <46B216AD.1010204@ecs.soton.ac.uk> Message-ID: <46B219EF.3070900@jfworks.net> Julian Field wrote: > Attached are new versions of the RedHat and SuSE > /etc/init.d/MailScanner scripts. > The improvement is obvious when you do > /etc/init.d/MailScanner restart > or > service MailScanner restart > > It used to just wait for a fixed length of time (30 seconds by default). > Now it watches to see when the old MailScanner processes have actually > died, and starts it all back up again as soon as the previous > MailScanner is dead. > > It is important not to 'kill -9' the MailScanner processes, as they do > quite a bit of cleanup so they don't leave a mess behind, for example > in /var/spool/MailScanner/incoming. > > Please let me know what you think of them, and if they work for you okay. > > Jules > Works for me CentOS 4.5 From ssilva at sgvwater.com Thu Aug 2 19:00:48 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 2 19:01:13 2007 Subject: Improved init.d script In-Reply-To: <46B216AD.1010204@ecs.soton.ac.uk> References: <46B216AD.1010204@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 8/2/2007 10:38 AM: > Attached are new versions of the RedHat and SuSE /etc/init.d/MailScanner > scripts. > The improvement is obvious when you do > /etc/init.d/MailScanner restart > or > service MailScanner restart > > It used to just wait for a fixed length of time (30 seconds by default). > Now it watches to see when the old MailScanner processes have actually > died, and starts it all back up again as soon as the previous > MailScanner is dead. > > It is important not to 'kill -9' the MailScanner processes, as they do > quite a bit of cleanup so they don't leave a mess behind, for example in > /var/spool/MailScanner/incoming. > > Please let me know what you think of them, and if they work for you okay. > > Jules > Tried it on 2 of my servers, and it is working great! I'll do some beating on them tonite after the minions go home. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From itdept at fractalweb.com Thu Aug 2 19:09:04 2007 From: itdept at fractalweb.com (Chris Yuzik) Date: Thu Aug 2 19:09:29 2007 Subject: CRM114 How are you finding it ? In-Reply-To: <46B0FBA0.6060601@coders.co.uk> References: <1951DC816E1A9F469307B05FA183F4389DC9E0@corpatsmail1.corp.sensis.com> <46B0FBA0.6060601@coders.co.uk> Message-ID: <46B21DC0.1070603@fractalweb.com> Matt Hampton wrote: > Taking the idea behind Jason's script and switching it to perl Matt, Nice. Thanks for the excellent little perl script. I've added a feature to your script to pass all the false negatives to sa-learn and teach as spam. Assuming one has set 'crm114_learn 1' in crm114.cf, this should work fine. The ever so slightly improved script is available at: http://www.fractalweb.com/scripts/crm_train.zip I'm this could be improved by perhaps adding some logic where only messages where CRM114 was wrong by greater than 3 points gets retrained or something. Not sure what would give the best results. Thoughts? Cheers, Chris From hmkash at arl.army.mil Thu Aug 2 19:13:33 2007 From: hmkash at arl.army.mil (Kash, Howard (Civ, ARL/CISD)) Date: Thu Aug 2 19:11:42 2007 Subject: MailScanner ANNOUNCE: Version 4.62.9 released (UNCLASSIFIED) In-Reply-To: <223f97700708020046y350c68cet4828ef4fb522d4f3@mail.gmail.com> References: <46AFA330.7010206@ecs.soton.ac.uk> <223f97700708020046y350c68cet4828ef4fb522d4f3@mail.gmail.com> Message-ID: <88991ECEE371C644986F0C8837C207B70173B323@ARLABML01.DS.ARL.ARMY.MIL> Classification: UNCLASSIFIED Caveats: NONE I'm wondering if this "side effect" works if you only use McAfee - or does it only work if you happen to also use ClamAV? If the latter, I would like to request it be made to work for McAfee as well. I enabled this setting this morning, but have not yet seen any McAfee logs referring to .message files. Thanks, Howard -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Glenn Steen Sent: Thursday, August 02, 2007 3:46 AM To: MailScanner discussion Subject: Re: MailScanner ANNOUNCE: Version 4.62.9 released On 31/07/07, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > I have just released a new version of MailScanner, 4.62.9. I don't (snip) > - --- New "ClamAV Full Message Scan" setting, and improvements to the > ClamAV parser so that the SANESecurity phishing- and spam-detection > signatures can be reliably used. Note this new setting is disabled by > default, as it has a slight speed impact. (snip) Enabling this setting isn't only beneficial for ClamAV, but also for McAfee ... Note the McAfee line in this report snippet: ----- Subject: You've received a postcard from a Friend! MessageID: D6DC4E452.39523 Quarantine: /var/spool/MailScanner/quarantine/20070801/D6DC4E452.39523 Report: ClamAV Module: message was infected: Email.Phishing.RB-1221 McAfee: /D6DC4E452.39523.message Found the W32/Zhelatin.gen!eml virus !!! ----- As you can see, it isn't just ClamAV phishing signatures triggering on the "complete message" file... Pretty cool side effect:-). Perhaps makes the name ... less than intuitive:-):-). But since I'll want this and always use ClamAV, it's OK by me... Otherwise it'd have to be "Antivirus Full Message Scan" or something similar:-). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! Classification: UNCLASSIFIED Caveats: NONE From sandrews at andrewscompanies.com Thu Aug 2 19:22:43 2007 From: sandrews at andrewscompanies.com (Steven Andrews) Date: Thu Aug 2 19:22:47 2007 Subject: CRM114 css not updating In-Reply-To: <21252893.9831186042512802.JavaMail.root@office.splatnix.net> References: <223f97700708011410g78c67c0teb435851be007532@mail.gmail.com> <21252893.9831186042512802.JavaMail.root@office.splatnix.net> Message-ID: <1964AAFBC212F742958F9275BF63DBB04B1052@winchester.andrewscompanies.com> Centos4 Been throught wiki regarding install twice and I haven't missed anything. Spamassassin -D --lint shows it's being called and allmail.txt is catching incoming mail; no errors. Running the test from MailWatch, blows up with: [12961] dbg: crm114: crm114_command run 0.01892 ERROR: mailreaver.crm broke. Here's the error\: 0.02391 ERROR: 0.00025 /usr/bin/crm: *ERROR* 9E-05 For some reason, I was unable to write-open the file named allmail.txt 9E-05 Sorry, but this program is very sick and probably should be killed off. 8E-05 This happened at line 165 of file mailreaver.crm 8E-05 [12961] dbg: info: leaving helper-app run mode 0.0009 [12961] dbg: crm114: call_crm returns (UNKNOWN, 0) 0.00069 [12961] warn: crm114: Error. Failed to get CRM114-Status. at /etc/mail/spamassassin/crm114.pm line 315. I kind of expect that since it's running as apache; everything else as root. So, I give it a quick chmod 777 and I get a little further: [13748] dbg: crm114: crm114_command run 0.01103 ERROR: maillib.crm broke. Here's the error\: 0.06252 ERROR: 0.00026 /usr/bin/crm: *WARNING* 9E-05 Couldn't memory-map the table file spam.css 8E-05 I'll try to keep working. 7E-05 This happened at line 662 of file mailreaver.crm 8E-05 [13748] dbg: info: leaving helper-app run mode 0.00086 [13748] dbg: crm114: call_crm returns (UNKNOWN, 0) 0.00069 [13748] warn: crm114: Error. Failed to get CRM114-Status. at /etc/mail/spamassassin/crm114.pm line 315. Got it, Ok, 777 for the css files too. [14005] dbg: crm114: crm114_command run 0.02064 [14005] dbg: crm114: found version 20070301-BlameBaltar ( TRE 0.7.5 (LGPL) ) MR-BD9991E2 0.07717 [14005] dbg: crm114: found CacheID sfid-20070802_140925_378605_D6AAF116 0.00043 [14005] dbg: crm114: found status UNSURE and score 0.00 0.00029 [14005] dbg: crm114: found Notice Please train this message. 0.00029 [14005] dbg: info: leaving helper-app run mode 0.00125 [14005] dbg: crm114: call_crm returns (UNSURE, 0.00) 0.00069 [14005] dbg: crm114: score is 0.0000, translated to SA score: -0.0000, linear factor was -0.2000 Looks good; doublecheck spamassassin -D --lint show no errors. The spam.css and nospam.css files still refuse to move beyond the timestamp from their creation time. Cssutil -b -r /etc/mail/spamassassin/crm114 still shows the base info. Messages have -0.00 CRM114_CHECK. I even set it to use static scoring and all I get is the unsure score. I do see items adding to the /reaver_cache/texts directory. Nothing in the other reaver_cache directories. I've done the requisite banging on my mouse and pounding my head on the desk, but that didn't work either. Any thoughts? From MailScanner at ecs.soton.ac.uk Thu Aug 2 19:43:35 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 2 19:44:01 2007 Subject: MailScanner ANNOUNCE: Version 4.62.9 released (UNCLASSIFIED) In-Reply-To: <88991ECEE371C644986F0C8837C207B70173B323@ARLABML01.DS.ARL.ARMY.MIL> References: <46AFA330.7010206@ecs.soton.ac.uk> <223f97700708020046y350c68cet4828ef4fb522d4f3@mail.gmail.com> <88991ECEE371C644986F0C8837C207B70173B323@ARLABML01.DS.ARL.ARMY.MIL> Message-ID: <46B225D7.1070406@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 The option only has an effect if you run at least ClamAV in some form. Kash, Howard (Civ, ARL/CISD) wrote: > Classification: UNCLASSIFIED > Caveats: NONE > > > I'm wondering if this "side effect" works if you only use McAfee - or > does it only work if you happen to also use ClamAV? If the latter, I > would like to request it be made to work for McAfee as well. I enabled > this setting this morning, but have not yet seen any McAfee logs > referring to .message files. > > Thanks, > Howard > > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Glenn > Steen > Sent: Thursday, August 02, 2007 3:46 AM > To: MailScanner discussion > Subject: Re: MailScanner ANNOUNCE: Version 4.62.9 released > > On 31/07/07, Julian Field wrote: > >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> I have just released a new version of MailScanner, 4.62.9. I don't >> > (snip) > >> - --- New "ClamAV Full Message Scan" setting, and improvements to the >> ClamAV parser so that the SANESecurity phishing- and spam-detection >> signatures can be reliably used. Note this new setting is disabled by >> default, as it has a slight speed impact. >> > (snip) > > Enabling this setting isn't only beneficial for ClamAV, but also for > McAfee ... Note the McAfee line in this report snippet: > ----- > Subject: You've received a postcard from a Friend! > MessageID: D6DC4E452.39523 > Quarantine: /var/spool/MailScanner/quarantine/20070801/D6DC4E452.39523 > Report: ClamAV Module: message was infected: Email.Phishing.RB-1221 > McAfee: /D6DC4E452.39523.message Found the > W32/Zhelatin.gen!eml virus !!! > ----- > As you can see, it isn't just ClamAV phishing signatures triggering on > the "complete message" file... Pretty cool side effect:-). > > Perhaps makes the name ... less than intuitive:-):-). But since I'll > want this and always use ClamAV, it's OK by me... Otherwise it'd have > to be "Antivirus Full Message Scan" or something similar:-). > > Cheers > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGsiXYEfZZRxQVtlQRAhf1AKD81uoYl5HXQ3VbXcMJKV0xLqmyNQCfSQ0a v1Uu5hZaERX9yfexO51LMUI= =1vFY -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From uxbod at splatnix.net Thu Aug 2 19:54:36 2007 From: uxbod at splatnix.net (UxBoD) Date: Thu Aug 2 19:48:35 2007 Subject: CRM114 css not updating In-Reply-To: <1964AAFBC212F742958F9275BF63DBB04B1052@winchester.andrewscompanies.com> Message-ID: <27348762.10521186080876081.JavaMail.root@office.splatnix.net> Have you set it to autolearn in crm114.cf ? What does it show if you do a cssutil -b -r spam.css and cssutil -b -r nonspam.css ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Steven Andrews" To: "MailScanner discussion" Sent: Thursday, August 2, 2007 7:22:43 PM (GMT) Europe/London Subject: CRM114 css not updating Centos4 Been throught wiki regarding install twice and I haven't missed anything. Spamassassin -D --lint shows it's being called and allmail.txt is catching incoming mail; no errors. Running the test from MailWatch, blows up with: [12961] dbg: crm114: crm114_command run 0.01892 ERROR: mailreaver.crm broke. Here's the error\: 0.02391 ERROR: 0.00025 /usr/bin/crm: *ERROR* 9E-05 For some reason, I was unable to write-open the file named allmail.txt 9E-05 Sorry, but this program is very sick and probably should be killed off. 8E-05 This happened at line 165 of file mailreaver.crm 8E-05 [12961] dbg: info: leaving helper-app run mode 0.0009 [12961] dbg: crm114: call_crm returns (UNKNOWN, 0) 0.00069 [12961] warn: crm114: Error. Failed to get CRM114-Status. at /etc/mail/spamassassin/crm114.pm line 315. I kind of expect that since it's running as apache; everything else as root. So, I give it a quick chmod 777 and I get a little further: [13748] dbg: crm114: crm114_command run 0.01103 ERROR: maillib.crm broke. Here's the error\: 0.06252 ERROR: 0.00026 /usr/bin/crm: *WARNING* 9E-05 Couldn't memory-map the table file spam.css 8E-05 I'll try to keep working. 7E-05 This happened at line 662 of file mailreaver.crm 8E-05 [13748] dbg: info: leaving helper-app run mode 0.00086 [13748] dbg: crm114: call_crm returns (UNKNOWN, 0) 0.00069 [13748] warn: crm114: Error. Failed to get CRM114-Status. at /etc/mail/spamassassin/crm114.pm line 315. Got it, Ok, 777 for the css files too. [14005] dbg: crm114: crm114_command run 0.02064 [14005] dbg: crm114: found version 20070301-BlameBaltar ( TRE 0.7.5 (LGPL) ) MR-BD9991E2 0.07717 [14005] dbg: crm114: found CacheID sfid-20070802_140925_378605_D6AAF116 0.00043 [14005] dbg: crm114: found status UNSURE and score 0.00 0.00029 [14005] dbg: crm114: found Notice Please train this message. 0.00029 [14005] dbg: info: leaving helper-app run mode 0.00125 [14005] dbg: crm114: call_crm returns (UNSURE, 0.00) 0.00069 [14005] dbg: crm114: score is 0.0000, translated to SA score: -0.0000, linear factor was -0.2000 Looks good; doublecheck spamassassin -D --lint show no errors. The spam.css and nospam.css files still refuse to move beyond the timestamp from their creation time. Cssutil -b -r /etc/mail/spamassassin/crm114 still shows the base info. Messages have -0.00 CRM114_CHECK. I even set it to use static scoring and all I get is the unsure score. I do see items adding to the /reaver_cache/texts directory. Nothing in the other reaver_cache directories. I've done the requisite banging on my mouse and pounding my head on the desk, but that didn't work either. Any thoughts? -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From itdept at fractalweb.com Thu Aug 2 19:53:42 2007 From: itdept at fractalweb.com (Chris Yuzik) Date: Thu Aug 2 19:53:55 2007 Subject: zip only spam In-Reply-To: <46AF6B68.1040706@pa.net> References: <46AF6B68.1040706@pa.net> Message-ID: <46B22836.8000308@fractalweb.com> Leland J. Steinke wrote: >> # ZIP only spam >> full ZIP_ONLY_SPAM >> /encoding\:\s+7bit(\n?)+[\-0-9]+.{1,40}type\:\s+application\/zip\;.{1,40}name\=.{1,40}\.zip.{1,50}disposition\:\s+inline\;.{1,40}filename\=.{1,40}\.zip/is > > > s/zip/octet-stream/ I'm using the following rule, but getting no joy: full ZIP_ONLY_SPAM /encoding\:\s+7bit(\n?)+[\-0-9]+.{1,40}type\:\s+application\/octet-stream\;.{1,40}name\=.{1,40}\.zip.{1,50}disposition\:\s+inline\;.{1,40}filename\=.{1,40}\.zip/is I have a similar rule which does trigger for PDF only spam and works fine. What am I doing wrong? Chris From sandrews at andrewscompanies.com Thu Aug 2 19:55:27 2007 From: sandrews at andrewscompanies.com (Steven Andrews) Date: Thu Aug 2 19:55:30 2007 Subject: CRM114 css not updating In-Reply-To: <27348762.10521186080876081.JavaMail.root@office.splatnix.net> References: <1964AAFBC212F742958F9275BF63DBB04B1052@winchester.andrewscompanies.com> <27348762.10521186080876081.JavaMail.root@office.splatnix.net> Message-ID: <1964AAFBC212F742958F9275BF63DBB04B1056@winchester.andrewscompanies.com> I have. Crm114.cf: # these two lines are necessary to activate the plugin: loadplugin crm114 crm114.pm full CRM114_CHECK eval:check_crm() # this high priority is not necessary. but running late allows us # to compare the CRM score and the result of all previous SA tests # # 899 is chosen as an optimization because FuzzyOCR runs at 900 # thus if CRM already yields a high SA score, # then FuzzyOCR will decide to skip its tests priority CRM114_CHECK 899 # commandline to execute CRM114 # default: crm -u ~/.crm114 mailreaver.crm #crm114_command /usr/local/bin/crm -u /var/amavis/.crm114 mailreaver.crm crm114_command /usr/bin/crm -u /etc/mail/spamassassin/crm114 mailreaver.crm # let SA add header lines to processed mails #add_header all CRM114-Version _CRM114VERSION_ #add_header all CRM114-CacheID _CRM114CACHEID_ add_header all CRM114-Status _CRM114STATUS_ ( _CRM114SCORE_ ) # ignore existing X-Spam or X-Virus headers # if SpamAssassin is called by Amavis then use the same value as Amavis does. # that way a SA-check from Amavis and on from the command line both see the same # Headers # default: 0 #crm114_remove_existing_spam_headers 1 #crm114_remove_existing_virus_headers 1 # dynamic score # values: 0 - returns subtest results # 1 - returns a dynamic CRM score (default) #crm114_dynscore 1 # dynamic score normalization factor # CRM score have much higher absolute values and different signs than SA scores # (usual ham-scores are between 15 and 40, scores from -10 to 10 are undecided, # previously seen spam easily gets -200). # With dynamic scoring the SA score is calculated by: * crm114_dynscore_factor # # Notes: - this has to be a negative number! # - the absolute value should be quite low (certainly <.3, probably <=.2), # otherwise the returned score would override all other tests. # default: calculate factor so that CRM-score -25 yields the SA required spam threshold #crm114_dynscore_factor -0.05 # static scores # without dynamic scores these scores are used # default values are respectively -3, 0, 3 for good, unsure, spam #crm114_staticscore_good -3.0 #crm114_staticscore_unsure 0.0 #crm114_staticscore_spam 3.0 # should CRM114 be trained by SA? # If enabled, then a call to Mail::SpamAssassin->learn() or # "spamassassin --report/--revoke" also calls the CRM114 plugin. # Since CRM114 uses a "Train On Error" strategy the plugin will check the # reported mail and only learn it if it is not not classified correctly. # default: 0 #crm114_learn 1 # should CRM114 be trained by SA-autolearn? # If enabled, then SA's autolearn also calls the CRM114 plugin. # # This is different from :automatic_training: in CRM114's mailfilter.cf # because SA's score is influenced by several different factors while # CRM114 has to rely on its own classification. # But anyway: Only activate this if you know what you're doing! # default: 0 crm114_autolearn 1 # should we preserve the CRM114-CacheID for training or discard it? # # to use the cache enable it in mailfilter.cf, set this option, and # include the CacheID into all Mails with # "add_header all CRM114-CacheID _CRM114CACHEID_" # -- otherwise disable this option to strip CacheIDs before training # default: 0 #crm114_use_cacheid 1 # should we skip CRM114 if other tests indicate certain spam/ham? # # disable CRM114 if a message already has a score (from other tests) # less than crm114_autodisable_negative_score or # more than crm114_autodisable_score. # # default: -999/999 # crm114_autodisable_negative_score -999 # crm114_autodisable_score 999 Output: Using username "root". Last login: Thu Aug 2 14:50:43 2007 from 192.168.1.200 [root@spamfilter ~]# cssutil -b -r /etc/mail/spamassassin/crm114/spam.css Sparse spectra file /etc/mail/spamassassin/crm114/spam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 1 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 [root@spamfilter ~]# cssutil -b -r /etc/mail/spamassassin/crm114/nonspam.css Sparse spectra file /etc/mail/spamassassin/crm114/nonspam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 1 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Thursday, August 02, 2007 2:55 PM To: MailScanner discussion Subject: Re: CRM114 css not updating Have you set it to autolearn in crm114.cf ? What does it show if you do a cssutil -b -r spam.css and cssutil -b -r nonspam.css ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Steven Andrews" To: "MailScanner discussion" Sent: Thursday, August 2, 2007 7:22:43 PM (GMT) Europe/London Subject: CRM114 css not updating Centos4 Been throught wiki regarding install twice and I haven't missed anything. Spamassassin -D --lint shows it's being called and allmail.txt is catching incoming mail; no errors. Running the test from MailWatch, blows up with: [12961] dbg: crm114: crm114_command run 0.01892 ERROR: mailreaver.crm broke. Here's the error\: 0.02391 ERROR: 0.00025 /usr/bin/crm: *ERROR* 9E-05 For some reason, I was unable to write-open the file named allmail.txt 9E-05 Sorry, but this program is very sick and probably should be killed off. 8E-05 This happened at line 165 of file mailreaver.crm 8E-05 [12961] dbg: info: leaving helper-app run mode 0.0009 [12961] dbg: crm114: call_crm returns (UNKNOWN, 0) 0.00069 [12961] warn: crm114: Error. Failed to get CRM114-Status. at /etc/mail/spamassassin/crm114.pm line 315. I kind of expect that since it's running as apache; everything else as root. So, I give it a quick chmod 777 and I get a little further: [13748] dbg: crm114: crm114_command run 0.01103 ERROR: maillib.crm broke. Here's the error\: 0.06252 ERROR: 0.00026 /usr/bin/crm: *WARNING* 9E-05 Couldn't memory-map the table file spam.css 8E-05 I'll try to keep working. 7E-05 This happened at line 662 of file mailreaver.crm 8E-05 [13748] dbg: info: leaving helper-app run mode 0.00086 [13748] dbg: crm114: call_crm returns (UNKNOWN, 0) 0.00069 [13748] warn: crm114: Error. Failed to get CRM114-Status. at /etc/mail/spamassassin/crm114.pm line 315. Got it, Ok, 777 for the css files too. [14005] dbg: crm114: crm114_command run 0.02064 [14005] dbg: crm114: found version 20070301-BlameBaltar ( TRE 0.7.5 (LGPL) ) MR-BD9991E2 0.07717 [14005] dbg: crm114: found CacheID sfid-20070802_140925_378605_D6AAF116 0.00043 [14005] dbg: crm114: found status UNSURE and score 0.00 0.00029 [14005] dbg: crm114: found Notice Please train this message. 0.00029 [14005] dbg: info: leaving helper-app run mode 0.00125 [14005] dbg: crm114: call_crm returns (UNSURE, 0.00) 0.00069 [14005] dbg: crm114: score is 0.0000, translated to SA score: -0.0000, linear factor was -0.2000 Looks good; doublecheck spamassassin -D --lint show no errors. The spam.css and nospam.css files still refuse to move beyond the timestamp from their creation time. Cssutil -b -r /etc/mail/spamassassin/crm114 still shows the base info. Messages have -0.00 CRM114_CHECK. I even set it to use static scoring and all I get is the unsure score. I do see items adding to the /reaver_cache/texts directory. Nothing in the other reaver_cache directories. I've done the requisite banging on my mouse and pounding my head on the desk, but that didn't work either. Any thoughts? -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From itdept at fractalweb.com Thu Aug 2 20:01:06 2007 From: itdept at fractalweb.com (Chris Yuzik) Date: Thu Aug 2 20:01:16 2007 Subject: Improved init.d script In-Reply-To: <46B216AD.1010204@ecs.soton.ac.uk> References: <46B216AD.1010204@ecs.soton.ac.uk> Message-ID: <46B229F2.1080709@fractalweb.com> Julian Field wrote: > Please let me know what you think of them, and if they work for you okay. Jules, Works great! Thanks, Chris From uxbod at splatnix.net Thu Aug 2 20:19:08 2007 From: uxbod at splatnix.net (UxBoD) Date: Thu Aug 2 20:13:08 2007 Subject: CRM114 css not updating In-Reply-To: <1964AAFBC212F742958F9275BF63DBB04B1056@winchester.andrewscompanies.com> Message-ID: <5097116.10551186082348420.JavaMail.root@office.splatnix.net> Steven, >From /etc/mail/spamassassin can you do a ls -l crm114 just to check perms. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ssilva at sgvwater.com Thu Aug 2 20:13:46 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 2 20:13:56 2007 Subject: McAfee 5200 Engine Released In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA01510C4C@HC-MBX02.herefordshire.gov.uk> References: <7EF0EE5CB3B263488C8C18823239BEBA01510C4C@HC-MBX02.herefordshire.gov.uk> Message-ID: Randal, Phil spake the following on 8/2/2007 3:33 AM: > Folks, > > McAfee have released their 5200 scan engine and along with it new > scanners for Unix / Linux. > > You can download them from the corporate download site (needs your NAI > grant number). > And I don't remember them having a 64 bit Linux scanner before. I wonder if it is any faster? -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Thu Aug 2 20:14:24 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 2 20:15:14 2007 Subject: Improved init.d script In-Reply-To: References: <46B216AD.1010204@ecs.soton.ac.uk> Message-ID: Scott Silva spake the following on 8/2/2007 11:00 AM: > Julian Field spake the following on 8/2/2007 10:38 AM: >> Attached are new versions of the RedHat and SuSE /etc/init.d/MailScanner >> scripts. >> The improvement is obvious when you do >> /etc/init.d/MailScanner restart >> or >> service MailScanner restart >> >> It used to just wait for a fixed length of time (30 seconds by default). >> Now it watches to see when the old MailScanner processes have actually >> died, and starts it all back up again as soon as the previous >> MailScanner is dead. >> >> It is important not to 'kill -9' the MailScanner processes, as they do >> quite a bit of cleanup so they don't leave a mess behind, for example in >> /var/spool/MailScanner/incoming. >> >> Please let me know what you think of them, and if they work for you okay. >> >> Jules >> > Tried it on 2 of my servers, and it is working great! > I'll do some beating on them tonite after the minions go home. > Forgot to add -- also Centos 4 -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From sandrews at andrewscompanies.com Thu Aug 2 20:34:23 2007 From: sandrews at andrewscompanies.com (Steven Andrews) Date: Thu Aug 2 20:34:25 2007 Subject: CRM114 css not updating In-Reply-To: <5097116.10551186082348420.JavaMail.root@office.splatnix.net> References: <1964AAFBC212F742958F9275BF63DBB04B1056@winchester.andrewscompanies.com> <5097116.10551186082348420.JavaMail.root@office.splatnix.net> Message-ID: <1964AAFBC212F742958F9275BF63DBB04B1058@winchester.andrewscompanies.com> Using username "root". Last login: Thu Aug 2 14:52:11 2007 from 192.168.1.200 [root@spamfilter ~]# cd /etc/mail/spamassassin [root@spamfilter spamassassin]# ls -l crm114 total 24768 -rwxrwxrwx 1 root root 0 Aug 2 13:47 blacklist.mfp -rwxrwxrwx 1 root root 17454 Aug 2 13:18 mailfilter.cf -rwxrwxrwx 1 root root 44537 Aug 2 13:47 mailfilter.crm -rwxrwxrwx 1 root root 14511 Aug 2 13:47 maillib.crm -rwxrwxrwx 1 root root 22740 Aug 2 13:47 mailreaver.crm -rwxrwxrwx 1 root root 37621 Aug 2 13:47 mailtrainer.crm -rwxrwxrwx 1 root root 12582924 Aug 2 13:47 nonspam.css -rwxrwxrwx 1 root root 49 Aug 2 13:47 priolist.mfp drwxrwxrwx 8 root root 4096 Aug 2 12:25 reaver_cache -rwxrwxrwx 1 root root 0 Aug 2 13:47 rewrites.mfp -rwxrwxrwx 1 root root 12582924 Aug 2 13:47 spam.css -rwxrwxrwx 1 root root 0 Aug 2 13:47 whitelist.mfp [root@spamfilter spamassassin]# -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Thursday, August 02, 2007 3:19 PM To: MailScanner discussion Subject: Re: CRM114 css not updating Steven, >From /etc/mail/spamassassin can you do a ls -l crm114 just to check perms. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From itdept at fractalweb.com Thu Aug 2 20:34:52 2007 From: itdept at fractalweb.com (Chris Yuzik) Date: Thu Aug 2 20:35:01 2007 Subject: Improved init.d script In-Reply-To: <46B229F2.1080709@fractalweb.com> References: <46B216AD.1010204@ecs.soton.ac.uk> <46B229F2.1080709@fractalweb.com> Message-ID: <46B231DC.10808@fractalweb.com> Chris Yuzik wrote: > Julian Field wrote: > >> Please let me know what you think of them, and if they work for you okay. > > Jules, > > Works great! > > Thanks, > Chris Jules, Forgot to mention I tested on Centos 4.4. Thanks! Chris From itdept at fractalweb.com Thu Aug 2 20:37:59 2007 From: itdept at fractalweb.com (Chris Yuzik) Date: Thu Aug 2 20:38:25 2007 Subject: updated CRM114 training script. In-Reply-To: <46B21DC0.1070603@fractalweb.com> References: <1951DC816E1A9F469307B05FA183F4389DC9E0@corpatsmail1.corp.sensis.com> <46B0FBA0.6060601@coders.co.uk> <46B21DC0.1070603@fractalweb.com> Message-ID: <46B23297.7010206@fractalweb.com> I now have an updated script that trains only crm, not spamassassin. It's available here: http://www.fractalweb.com/scripts/crm_train2.zip The old version which used sa-learn is still available as well. http://www.fractalweb.com/scripts/crm_train.zip Any feedback? Chris From uxbod at splatnix.net Thu Aug 2 20:45:26 2007 From: uxbod at splatnix.net (UxBoD) Date: Thu Aug 2 20:39:29 2007 Subject: CRM114 css not updating In-Reply-To: <1964AAFBC212F742958F9275BF63DBB04B1058@winchester.andrewscompanies.com> Message-ID: <32667771.10581186083926579.JavaMail.root@office.splatnix.net> Steve, Are you able to kill of MailScanner and then run it in debug mode (MailScanner --debug) to see if any errors are getting kicked out when SA runs. All looks fine on the face of it. Does SA lint okay ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From sandrews at andrewscompanies.com Thu Aug 2 21:19:29 2007 From: sandrews at andrewscompanies.com (Steven Andrews) Date: Thu Aug 2 21:19:36 2007 Subject: CRM114 css not updating In-Reply-To: <32667771.10581186083926579.JavaMail.root@office.splatnix.net> References: <1964AAFBC212F742958F9275BF63DBB04B1058@winchester.andrewscompanies.com> <32667771.10581186083926579.JavaMail.root@office.splatnix.net> Message-ID: <1964AAFBC212F742958F9275BF63DBB04B105A@winchester.andrewscompanies.com> Yep; did that. All looks good. Attached. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Thursday, August 02, 2007 3:45 PM To: MailScanner discussion Subject: Re: CRM114 css not updating Steve, Are you able to kill of MailScanner and then run it in debug mode (MailScanner --debug) to see if any errors are getting kicked out when SA runs. All looks fine on the face of it. Does SA lint okay ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -------------- next part -------------- Starting MailScanner daemons: incoming sendmail: [ OK ] outgoing sendmail: [ OK ] MailScanner: In Debugging mode, not forking... SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp [23692] dbg: logger: adding facilities: all [23692] dbg: logger: logging level is DBG [23692] dbg: generic: SpamAssassin version 3.2.2 [23692] dbg: config: score set 0 chosen. [23692] dbg: util: running in taint mode? no [23692] dbg: dns: no ipv6 [23692] dbg: dns: is Net::DNS::Resolver available? yes [23692] dbg: dns: Net::DNS version: 0.60 [23692] dbg: ignore: test message to precompile patterns and load modules [23692] dbg: config: using "/etc/mail/spamassassin" for site rules pre files [23692] dbg: config: read file /etc/mail/spamassassin/init.pre [23692] dbg: config: read file /etc/mail/spamassassin/v310.pre [23692] dbg: config: read file /etc/mail/spamassassin/v312.pre [23692] dbg: config: read file /etc/mail/spamassassin/v320.pre [23692] dbg: config: using "/usr/share/spamassassin" for sys rules pre files [23692] dbg: config: using "/usr/share/spamassassin" for default rules dir [23692] dbg: config: read file /usr/share/spamassassin/10_default_prefs.cf [23692] dbg: config: read file /usr/share/spamassassin/20_advance_fee.cf [23692] dbg: config: read file /usr/share/spamassassin/20_body_tests.cf [23692] dbg: config: read file /usr/share/spamassassin/20_compensate.cf [23692] dbg: config: read file /usr/share/spamassassin/20_dnsbl_tests.cf [23692] dbg: config: read file /usr/share/spamassassin/20_drugs.cf [23692] dbg: config: read file /usr/share/spamassassin/20_dynrdns.cf [23692] dbg: config: read file /usr/share/spamassassin/20_fake_helo_tests.cf [23692] dbg: config: read file /usr/share/spamassassin/20_head_tests.cf [23692] dbg: config: read file /usr/share/spamassassin/20_html_tests.cf [23692] dbg: config: read file /usr/share/spamassassin/20_imageinfo.cf [23692] dbg: config: read file /usr/share/spamassassin/20_meta_tests.cf [23692] dbg: config: read file /usr/share/spamassassin/20_net_tests.cf [23692] dbg: config: read file /usr/share/spamassassin/20_phrases.cf [23692] dbg: config: read file /usr/share/spamassassin/20_porn.cf [23692] dbg: config: read file /usr/share/spamassassin/20_ratware.cf [23692] dbg: config: read file /usr/share/spamassassin/20_uri_tests.cf [23692] dbg: config: read file /usr/share/spamassassin/20_vbounce.cf [23692] dbg: config: read file /usr/share/spamassassin/23_bayes.cf [23692] dbg: config: read file /usr/share/spamassassin/25_accessdb.cf [23692] dbg: config: read file /usr/share/spamassassin/25_antivirus.cf [23692] dbg: config: read file /usr/share/spamassassin/25_asn.cf [23692] dbg: config: read file /usr/share/spamassassin/25_dcc.cf [23692] dbg: config: read file /usr/share/spamassassin/25_dkim.cf [23692] dbg: config: read file /usr/share/spamassassin/25_domainkeys.cf [23692] dbg: config: read file /usr/share/spamassassin/25_hashcash.cf [23692] dbg: config: read file /usr/share/spamassassin/25_pyzor.cf [23692] dbg: config: read file /usr/share/spamassassin/25_razor2.cf [23692] dbg: config: read file /usr/share/spamassassin/25_replace.cf [23692] dbg: config: read file /usr/share/spamassassin/25_spf.cf [23692] dbg: config: read file /usr/share/spamassassin/25_textcat.cf [23692] dbg: config: read file /usr/share/spamassassin/25_uribl.cf [23692] dbg: config: read file /usr/share/spamassassin/30_text_de.cf [23692] dbg: config: read file /usr/share/spamassassin/30_text_fr.cf [23692] dbg: config: read file /usr/share/spamassassin/30_text_it.cf [23692] dbg: config: read file /usr/share/spamassassin/30_text_nl.cf [23692] dbg: config: read file /usr/share/spamassassin/30_text_pl.cf [23692] dbg: config: read file /usr/share/spamassassin/30_text_pt_br.cf [23692] dbg: config: read file /usr/share/spamassassin/50_scores.cf [23692] dbg: config: read file /usr/share/spamassassin/60_awl.cf [23692] dbg: config: read file /usr/share/spamassassin/60_shortcircuit.cf [23692] dbg: config: read file /usr/share/spamassassin/60_whitelist.cf [23692] dbg: config: read file /usr/share/spamassassin/60_whitelist_dk.cf [23692] dbg: config: read file /usr/share/spamassassin/60_whitelist_dkim.cf [23692] dbg: config: read file /usr/share/spamassassin/60_whitelist_spf.cf [23692] dbg: config: read file /usr/share/spamassassin/60_whitelist_subject.cf [23692] dbg: config: read file /usr/share/spamassassin/72_active.cf [23692] dbg: config: using "/etc/mail/spamassassin" for site rules dir [23692] dbg: config: read file /etc/mail/spamassassin/70_andrews_badlink.cf [23692] dbg: config: read file /etc/mail/spamassassin/70_andrews_badpdf.cf [23692] dbg: config: read file /etc/mail/spamassassin/70_andrews_badsource.cf [23692] dbg: config: read file /etc/mail/spamassassin/FuzzyOcr.cf [23692] dbg: config: read file /etc/mail/spamassassin/crm114.cf [23692] dbg: config: read file /etc/mail/spamassassin/local.cf [23692] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf [23692] dbg: config: read file /etc/mail/spamassassin/pdfinfo.cf [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [23692] dbg: razor2: razor2 is available, version 2.81 [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC [23692] dbg: pyzor: network tests on, attempting Pyzor [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [23692] dbg: razor2: razor2 is available, version 2.81 [23692] dbg: plugin: did not register Mail::SpamAssassin::Plugin::Razor2=HASH(0xa213c68), already registered [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::SpamCop from @INC [23692] dbg: reporter: network tests on, attempting SpamCop [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [23692] dbg: plugin: did not register Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xa61fb80), already registered [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [23692] dbg: plugin: did not register Mail::SpamAssassin::Plugin::SPF=HASH(0xa611d38), already registered [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [23692] dbg: plugin: did not register Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0xa144954), already registered [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [23692] dbg: plugin: did not register Mail::SpamAssassin::Plugin::ASN=HASH(0xa0f7478), already registered [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [23692] dbg: plugin: did not register Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xa7aab3c), already registered [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [23692] dbg: plugin: did not register Mail::SpamAssassin::Plugin::SPF=HASH(0xa786bd0), already registered [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [23692] dbg: plugin: did not register Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0xa608f30), already registered [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [23692] dbg: razor2: razor2 is available, version 2.81 [23692] dbg: plugin: did not register Mail::SpamAssassin::Plugin::Razor2=HASH(0xa613ab0), already registered [23692] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [23692] dbg: plugin: did not register Mail::SpamAssassin::Plugin::ASN=HASH(0xa53fd68), already registered [23692] dbg: config: fixed relative path: /etc/mail/spamassassin/FuzzyOcr.pm [23692] dbg: plugin: loading FuzzyOcr from /etc/mail/spamassassin/FuzzyOcr.pm [23692] dbg: plugin: FuzzyOcr=HASH(0xa9534e0) implements 'parse_config', priority 0 [23692] dbg: FuzzyOcr: Found scan: $gocr -i $pfile [23692] dbg: FuzzyOcr: Found scan: $gocr -l 180 -d 2 -i $pfile [23692] dbg: FuzzyOcr: Found scan: $gocr -l 140 -d 2 -i $pfile [23692] dbg: FuzzyOcr: Score{base} = 5 [23692] dbg: FuzzyOcr: Score{add} = 0.375 [23692] dbg: FuzzyOcr: Score{autodisable} = 20 [23692] dbg: FuzzyOcr: Option counts_required = 3 [23692] dbg: FuzzyOcr: Option enable_image_hashing = 2 [23692] dbg: FuzzyOcr: Option digest_db = /etc/mail/spamassassin/FuzzyOcr.hashdb [23692] dbg: FuzzyOcr: Option db_hash = /etc/mail/spamassassin/FuzzyOcr.db [23692] dbg: FuzzyOcr: Option db_safe = /etc/mail/spamassassin/FuzzyOcr.safe.db [23692] dbg: FuzzyOcr: Option db_max_days = 35 [23692] dbg: FuzzyOcr: Option hashing_learn_scanned = 1 [23692] dbg: FuzzyOcr: Option score_ham = 1 [23692] dbg: config: fixed relative path: /etc/mail/spamassassin/crm114.pm [23692] dbg: plugin: loading crm114 from /etc/mail/spamassassin/crm114.pm [23692] dbg: plugin: FuzzyOcr=HASH(0xa9534e0) implements 'parse_config', priority 0 [23692] dbg: FuzzyOcr: unknown Option: dcc_path [23692] dbg: rules: __MO_OL_9B90B merged duplicates: __MO_OL_C65FA [23692] dbg: rules: __XM_OL_22B61 merged duplicates: __XM_OL_A842E [23692] dbg: rules: __MO_OL_07794 merged duplicates: __MO_OL_8627E __MO_OL_F3B05 [23692] dbg: rules: __XM_OL_07794 merged duplicates: __XM_OL_25340 __XM_OL_3857F __XM_OL_4F240 __XM_OL_58CB5 __XM_OL_6554A __XM_OL_812FF __XM_OL_C65FA __XM_OL_CF0C0 __XM_OL_F475E __XM_OL_F6D01 [23692] dbg: rules: FH_MSGID_01C67 merged duplicates: __MSGID_VGA [23692] dbg: rules: FS_NEW_SOFT_UPLOAD merged duplicates: HS_SUBJ_NEW_SOFTWARE [23692] dbg: rules: __FH_HAS_XMSMAIL merged duplicates: __HAS_MSMAIL_PRI [23692] dbg: rules: __MO_OL_015D5 merged duplicates: __MO_OL_6554A [23692] dbg: rules: __MO_OL_91287 merged duplicates: __MO_OL_B30D1 __MO_OL_CF0C0 [23692] dbg: rules: KAM_STOCKOTC merged duplicates: KAM_STOCKTIP15 KAM_STOCKTIP20 KAM_STOCKTIP21 KAM_STOCKTIP4 KAM_STOCKTIP6 [23692] dbg: rules: __XM_OL_015D5 merged duplicates: __XM_OL_4BF4C __XM_OL_4EEDB __XM_OL_5B79A __XM_OL_9B90B __XM_OL_ADFF7 __XM_OL_B30D1 __XM_OL_B4B40 __XM_OL_BC7E6 __XM_OL_F3B05 __XM_OL_FF5C8 [23692] dbg: rules: __XM_OL_5E7ED merged duplicates: __XM_OL_D03AB [23692] dbg: rules: __MO_OL_22B61 merged duplicates: __MO_OL_4F240 __MO_OL_ADFF7 [23692] dbg: rules: __MO_OL_812FF merged duplicates: __MO_OL_BC7E6 [23692] dbg: rules: __MO_OL_25340 merged duplicates: __MO_OL_4EEDB __MO_OL_7533E [23692] dbg: rules: __MO_OL_58CB5 merged duplicates: __MO_OL_B4B40 [23692] dbg: rules: __DOS_HAS_ANY_URI merged duplicates: __HAS_ANY_URI [23692] dbg: rules: __XM_OL_C7C33 merged duplicates: __XM_OL_C9068 __XM_OL_EF20B [23692] dbg: rules: __MO_OL_72641 merged duplicates: __MO_OL_A842E [23692] dbg: rules: FUZZY_OCR_CORRUPT_IMG merged duplicates: FUZZY_OCR_KNOWN_HASH FUZZY_OCR_WRONG_CTYPE [23692] dbg: rules: __MO_OL_5E7ED merged duplicates: __MO_OL_C7C33 [23692] dbg: rules: __MO_OL_4BF4C merged duplicates: __MO_OL_F6D01 [23692] dbg: rules: __MO_OL_F475E merged duplicates: __MO_OL_FF5C8 [23692] dbg: conf: finish parsing [23692] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0xa213ec0) implements 'finish_parsing_end', priority 0 [23692] dbg: plugin: FuzzyOcr=HASH(0xa9534e0) implements 'finish_parsing_end', priority 0 [23692] dbg: replacetags: replacing tags [23692] dbg: replacetags: done replacing tags [23692] dbg: FuzzyOcr: Using giffix => /usr/bin/giffix [23692] dbg: FuzzyOcr: Using giftext => /usr/bin/giftext [23692] dbg: FuzzyOcr: Using gifinter => /usr/bin/gifinter [23692] dbg: FuzzyOcr: Using giftopnm => /usr/local/netpbm/bin/giftopnm [23692] dbg: FuzzyOcr: Using jpegtopnm => /usr/local/netpbm/bin/jpegtopnm [23692] dbg: FuzzyOcr: Using pngtopnm => /usr/local/netpbm/bin/pngtopnm [23692] dbg: FuzzyOcr: Using bmptopnm => /usr/local/netpbm/bin/bmptopnm [23692] dbg: FuzzyOcr: Using ppmhist => /usr/local/netpbm/bin/ppmhist [23692] dbg: FuzzyOcr: Using gocr => /usr/local/bin/gocr [23692] dbg: FuzzyOcr: Loaded <43> words from "/etc/mail/spamassassin/FuzzyOcr.words" [23692] dbg: FuzzyOcr: Using scan: $gocr -i $pfile [23692] dbg: FuzzyOcr: Using scan: $gocr -l 180 -d 2 -i $pfile [23692] dbg: FuzzyOcr: Using scan: $gocr -l 140 -d 2 -i $pfile [23692] dbg: config: score set 1 chosen. [23692] dbg: message: main message type: text/plain [23692] dbg: message: ---- MIME PARSER START ---- [23692] dbg: message: parsing normal part [23692] dbg: message: ---- MIME PARSER END ---- [23692] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0xa686c8c) implements 'check_start', priority 0 [23692] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0xa2152f4) implements 'check_main', priority 0 [23692] dbg: conf: trusted_networks are not configured; it is recommended that you configure trusted_networks manually [23692] dbg: metadata: X-Spam-Relays-Trusted: [23692] dbg: metadata: X-Spam-Relays-Untrusted: [23692] dbg: metadata: X-Spam-Relays-Internal: [23692] dbg: metadata: X-Spam-Relays-External: [23692] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xa1449c0) implements 'extract_metadata', priority 0 [23692] dbg: metadata: X-Relay-Countries: [23692] dbg: message: no encoding detected [23692] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0xa0cb3b8) implements 'parsed_metadata', priority 0 [23692] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xa1449c0) implements 'parsed_metadata', priority 0 [23692] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0xa0ffd94) implements 'parsed_metadata', priority 0 [23692] dbg: dns: dns_available set to yes in config file, skipping test [23692] dbg: uridnsbl: domains to query: [23692] dbg: asn: could not parse IP from first external relay, skipping ASN check [23692] dbg: dns: checking RBL sa-other.bondedsender.org., set bsp-untrusted [23692] dbg: dns: checking RBL combined.njabl.org., set njabl [23692] dbg: dns: checking RBL bl.spamcop.net., set spamcop [23692] dbg: dns: checking RBL dob.sibl.support-intelligence.net., set dob [23692] dbg: dns: checking RBL zen.spamhaus.org., set zen-lastexternal [23692] dbg: dns: checking RBL dnsbl.sorbs.net., set sorbs-lastexternal [23692] dbg: dns: checking RBL dnsbl.sorbs.net., set sorbs [23692] dbg: dns: checking RBL zen.spamhaus.org., set zen-lastexternal [23692] dbg: dns: checking RBL list.dnswl.org., set dnswl-firsttrusted [23692] dbg: dns: checking RBL sa-accredit.habeas.com., set habeas-firsttrusted [23692] dbg: dns: checking RBL combined-HIB.dnsiplists.completewhois.com., set whois [23692] dbg: dns: checking RBL list.dsbl.org., set dsbl-lastexternal [23692] dbg: dns: checking RBL sa-trusted.bondedsender.org., set bsp-firsttrusted [23692] dbg: dns: checking RBL combined-HIB.dnsiplists.completewhois.com., set whois-lastexternal [23692] dbg: dns: checking RBL zen.spamhaus.org., set zen [23692] dbg: dns: checking RBL iadb.isipp.com., set iadb-firsttrusted [23692] dbg: check: running tests for priority: -1000 [23692] dbg: rules: running head tests; score so far=0 [23692] dbg: rules: compiled head tests [23692] dbg: eval: all '*From' addrs: ignore@compiling.spamassassin.taint.org [23692] dbg: eval: all '*To' addrs: [23692] dbg: rules: running body tests; score so far=0 [23692] dbg: rules: compiled body tests [23692] dbg: rules: running uri tests; score so far=0 [23692] dbg: rules: compiled uri tests [23692] dbg: rules: running rawbody tests; score so far=0 [23692] dbg: rules: compiled rawbody tests [23692] dbg: rules: running full tests; score so far=0 [23692] dbg: rules: compiled full tests [23692] dbg: rules: running meta tests; score so far=0 [23692] dbg: rules: compiled meta tests [23692] dbg: check: running tests for priority: -950 [23692] dbg: rules: running head tests; score so far=0 [23692] dbg: rules: compiled head tests [23692] dbg: rules: running body tests; score so far=0 [23692] dbg: rules: compiled body tests [23692] dbg: rules: running uri tests; score so far=0 [23692] dbg: rules: compiled uri tests [23692] dbg: rules: running rawbody tests; score so far=0 [23692] dbg: rules: compiled rawbody tests [23692] dbg: rules: running full tests; score so far=0 [23692] dbg: rules: compiled full tests [23692] dbg: rules: running meta tests; score so far=0 [23692] dbg: rules: compiled meta tests [23692] dbg: check: running tests for priority: -900 [23692] dbg: rules: running head tests; score so far=0 [23692] dbg: rules: compiled head tests [23692] dbg: rules: running body tests; score so far=0 [23692] dbg: rules: compiled body tests [23692] dbg: rules: running uri tests; score so far=0 [23692] dbg: rules: compiled uri tests [23692] dbg: rules: running rawbody tests; score so far=0 [23692] dbg: rules: compiled rawbody tests [23692] dbg: rules: running full tests; score so far=0 [23692] dbg: rules: compiled full tests [23692] dbg: rules: running meta tests; score so far=0 [23692] dbg: rules: compiled meta tests [23692] dbg: check: running tests for priority: -400 [23692] dbg: rules: running head tests; score so far=0 [23692] dbg: rules: compiled head tests [23692] dbg: rules: running body tests; score so far=0 [23692] dbg: rules: compiled body tests [23692] dbg: rules: running uri tests; score so far=0 [23692] dbg: rules: compiled uri tests [23692] dbg: rules: running rawbody tests; score so far=0 [23692] dbg: rules: compiled rawbody tests [23692] dbg: rules: running full tests; score so far=0 [23692] dbg: rules: compiled full tests [23692] dbg: rules: running meta tests; score so far=0 [23692] dbg: rules: compiled meta tests [23692] dbg: check: running tests for priority: 0 [23692] dbg: rules: running head tests; score so far=0 [23692] dbg: rules: compiled head tests [23692] dbg: rules: ran header rule __MISSING_REF ======> got hit: "UNSET" [23692] dbg: rules: ran header rule __MSGID_OK_HOST ======> got hit: "@spamassassin_spamd_init>" [23692] dbg: rules: ran header rule __MSGID_OK_DIGITS ======> got hit: "1186085582" [23692] dbg: rules: ran header rule __MSOE_MID_WRONG_CASE ======> got hit: " [23692] dbg: rules: Message-Id: " [23692] dbg: rules: ran header rule __HAS_MSGID ======> got hit: "<" [23692] dbg: rules: ran header rule __SANE_MSGID ======> got hit: "<1186085582.70098@spamassassin_spamd_init> [23692] dbg: rules: " [23692] dbg: rules: ran header rule MISSING_DATE ======> got hit: "UNSET" [23692] dbg: spf: checking to see if the message has a Received-SPF header that we can use [23692] dbg: spf: using Mail::SPF for SPF checks [23692] dbg: spf: no suitable relay for spf use found, skipping SPF-helo check [23692] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [23692] dbg: spf: no suitable relay for spf use found, skipping SPF check [23692] dbg: rules: ran eval rule NO_RELAYS ======> got hit (1) [23692] dbg: spf: def_spf_whitelist_from: already checked spf and didn't get pass, skipping whitelist check [23692] dbg: rules: ran eval rule __UNUSABLE_MSGID ======> got hit (1) [23692] dbg: rules: ran eval rule MISSING_HEADERS ======> got hit (1) [23692] dbg: spf: whitelist_from_spf: already checked spf and didn't get pass, skipping whitelist check [23692] dbg: rules: running body tests; score so far=1.581 [23692] dbg: rules: compiled body tests [23692] dbg: rules: ran body rule __NONEMPTY_BODY ======> got hit: "I" [23692] dbg: rules: running uri tests; score so far=1.581 [23692] dbg: rules: compiled uri tests [23692] dbg: https_http_mismatch: anchors 0 [23692] dbg: eval: stock info total: 0 [23692] dbg: rules: running rawbody tests; score so far=1.581 [23692] dbg: rules: compiled rawbody tests [23692] dbg: rules: running full tests; score so far=1.581 [23692] dbg: rules: compiled full tests [23692] dbg: info: entering helper-app run mode [23692] dbg: info: leaving helper-app run mode [23692] dbg: razor2: part=0 engine=4 contested=0 confidence=0 [23692] dbg: razor2: results: spam? 0 [23692] dbg: razor2: results: engine 8, highest cf score: 0 [23692] dbg: razor2: results: engine 4, highest cf score: 0 [23692] dbg: pyzor: pyzor is available: /usr/bin/pyzor [23692] dbg: info: entering helper-app run mode [23692] dbg: pyzor: opening pipe: /usr/bin/pyzor check < /var/spool/MailScanner/incoming/SpamAssassin-Temp/.spamassassin23692ZbHXoFtmp [23713] dbg: util: setuid: ruid=0 euid=0 [23692] dbg: pyzor: [23713] finished: exit=0x0100 [23692] dbg: pyzor: got response: 82.94.255.100:24441 (200, 'OK') 0 0 [23692] dbg: info: leaving helper-app run mode [23692] dbg: rules: running meta tests; score so far=1.581 [23692] dbg: rules: compiled meta tests [23692] dbg: check: running tests for priority: 500 [23692] dbg: rules: running head tests; score so far=1.581 [23692] dbg: rules: compiled head tests [23692] dbg: rules: running body tests; score so far=1.581 [23692] dbg: rules: compiled body tests [23692] dbg: rules: running uri tests; score so far=1.581 [23692] dbg: rules: compiled uri tests [23692] dbg: rules: running rawbody tests; score so far=1.581 [23692] dbg: rules: compiled rawbody tests [23692] dbg: rules: running full tests; score so far=1.581 [23692] dbg: rules: compiled full tests [23692] dbg: rules: running meta tests; score so far=1.581 [23692] dbg: rules: meta test DIGEST_MULTIPLE has undefined dependency 'DCC_CHECK' [23692] info: rules: meta test FM_DDDD_TIMES_2 has dependency 'FH_HOST_EQ_D_D_D_D' with a zero score [23692] info: rules: meta test FM_SEX_HOSTDDDD has dependency 'FH_HOST_EQ_D_D_D_D' with a zero score [23692] info: rules: meta test HS_PHARMA_1 has dependency 'HS_SUBJ_ONLINE_PHARMACEUTICAL' with a zero score [23692] dbg: rules: compiled meta tests [23692] dbg: check: running tests for priority: 899 [23692] dbg: rules: running head tests; score so far=2.865 [23692] dbg: rules: compiled head tests [23692] dbg: rules: running body tests; score so far=2.865 [23692] dbg: rules: compiled body tests [23692] dbg: rules: running uri tests; score so far=2.865 [23692] dbg: rules: compiled uri tests [23692] dbg: rules: running rawbody tests; score so far=2.865 [23692] dbg: rules: compiled rawbody tests [23692] dbg: rules: running full tests; score so far=2.865 [23692] dbg: rules: compiled full tests [23692] dbg: crm114: call_crm() called, action: check [23692] dbg: info: entering helper-app run mode [23692] dbg: crm114: crm114_command run [23692] dbg: crm114: found version 20070301-BlameBaltar ( TRE 0.7.5 (LGPL) ) MR-BD9991E2 [23692] dbg: crm114: found CacheID sfid-20070802_161310_448149_0815E087 [23692] dbg: crm114: found status UNSURE and score 0.00 [23692] dbg: crm114: found Notice Please train this message. [23692] dbg: info: leaving helper-app run mode [23692] dbg: crm114: call_crm returns (UNSURE, 0.00) [23692] dbg: crm114: score is 0.0000, translated to SA score: -0.0000, linear factor was -0.2000 [23692] dbg: rules: running meta tests; score so far=2.865 [23692] dbg: rules: compiled meta tests [23692] dbg: check: running tests for priority: 900 [23692] dbg: rules: running head tests; score so far=2.865 [23692] dbg: rules: compiled head tests [23692] dbg: rules: running body tests; score so far=2.865 [23692] dbg: rules: compiled body tests [23692] dbg: rules: running uri tests; score so far=2.865 [23692] dbg: rules: compiled uri tests [23692] dbg: rules: running rawbody tests; score so far=2.865 [23692] dbg: rules: compiled rawbody tests [23692] dbg: rules: running full tests; score so far=2.865 [23692] dbg: rules: compiled full tests [23692] dbg: rules: running meta tests; score so far=2.865 [23692] dbg: rules: compiled meta tests [23692] dbg: check: running tests for priority: 1000 [23692] dbg: rules: running head tests; score so far=2.865 [23692] dbg: rules: compiled head tests [23692] dbg: rules: running body tests; score so far=2.865 [23692] dbg: rules: compiled body tests [23692] dbg: rules: running uri tests; score so far=2.865 [23692] dbg: rules: compiled uri tests [23692] dbg: rules: running rawbody tests; score so far=2.865 [23692] dbg: rules: compiled rawbody tests [23692] dbg: rules: running full tests; score so far=2.865 [23692] dbg: rules: compiled full tests [23692] dbg: rules: running meta tests; score so far=2.865 [23692] dbg: rules: compiled meta tests [23692] dbg: check: is spam? score=2.865 required=5 [23692] dbg: check: tests=CRM114_CHECK,MISSING_DATE,MISSING_HEADERS,MISSING_SUBJECT,NO_RECEIVED,NO_RELAYS [23692] dbg: check: subtests=__HAS_MSGID,__MISSING_REF,__MSGID_OK_DIGITS,__MSGID_OK_HOST,__MSOE_MID_WRONG_CASE,__NONEMPTY_BODY,__SANE_MSGID,__UNUSABLE_MSGID I got I am generating a hash using the input of: 1186690399.65511, laratone@fun2reademail.com, 1186085562, AndrewsScan-bdx84cd9k, <001b01c7d58c$eb796e10$00798d94@yourf03e8146b4> [23724] dbg: dns: name server: 192.168.1.50, LocalAddr: 0.0.0.0 [23724] dbg: message: main message type: text/plain [23724] dbg: message: ---- MIME PARSER START ---- [23724] dbg: message: parsing normal part [23724] dbg: message: ---- MIME PARSER END ---- [23724] dbg: conf: trusted_networks are not configured; it is recommended that you configure trusted_networks manually [23724] dbg: received-header: parsed as [ ip=124.216.232.158 rdns= helo=fun2reademail.com by=spamfilter.andrewscompanies.com ident= envfrom= intl=0 id=l72KDCrD023712 auth= msa=0 ] [23724] dbg: received-header: do not trust any hosts from here on [23724] dbg: received-header: relay 124.216.232.158 trusted? no internal? no msa? no [23724] dbg: metadata: X-Spam-Relays-Trusted: [23724] dbg: metadata: X-Spam-Relays-Untrusted: [ ip=124.216.232.158 rdns= helo=fun2reademail.com by=spamfilter.andrewscompanies.com ident= envfrom= intl=0 id=l72KDCrD023712 auth= msa=0 ] [23724] dbg: metadata: X-Spam-Relays-Internal: [23724] dbg: metadata: X-Spam-Relays-External: [ ip=124.216.232.158 rdns= helo=fun2reademail.com by=spamfilter.andrewscompanies.com ident= envfrom= intl=0 id=l72KDCrD023712 auth= msa=0 ] [23724] dbg: metadata: X-Relay-Countries: XX [23724] dbg: message: decoding other encoding type (7bit), ignoring [23724] dbg: uridnsbl: domains to query: edlyonwi.cn [23724] dbg: dns: URIBL_RED lookup start [23724] dbg: dns: URIBL_GREY lookup start [23724] dbg: dns: WHOIS_SECUREWHOIS lookup start [23724] dbg: dns: WHOIS_MYPRIVREG lookup start [23724] dbg: dns: WHOIS_NETSOLPR lookup start [23724] dbg: dns: WHOIS_AITPRIV lookup start [23724] dbg: dns: URIBL_SC_SURBL lookup start [23724] dbg: dns: URIBL_AB_SURBL lookup start [23724] dbg: dns: WHOIS_CONTACTPRIV lookup start [23724] dbg: dns: WHOIS_NAMEKING lookup start [23724] dbg: dns: WHOIS_PRIVPROT lookup start [23724] dbg: dns: WHOIS_WHOISGUARD lookup start [23724] dbg: dns: URIBL_PH_SURBL lookup start [23724] dbg: dns: URIBL_BLACK lookup start [23724] dbg: dns: WHOIS_PRIVACYPOST lookup start [23724] dbg: dns: URIBL_RHS_DOB lookup start [23724] dbg: dns: URIBL_JP_SURBL lookup start [23724] dbg: dns: URIBL_WS_SURBL lookup start [23724] dbg: dns: URIBL_OB_SURBL lookup start [23724] dbg: dns: WHOIS_DMNBYPROXY lookup start [23724] dbg: dns: WHOIS_REGISTERFLY lookup start [23724] dbg: dns: WHOIS_UNLISTED lookup start [23724] dbg: dns: WHOIS_MONIKER_PRIV lookup start [23724] dbg: dns: URIBL_SBL lookup start [23724] dbg: asn: using first external relay IP for lookups: 124.216.232.158 [23724] dbg: asn: launched DNS TXT query for 158.232.216.124.asn.routeviews.org. in background [23724] dbg: dns: checking RBL sa-other.bondedsender.org., set bsp-untrusted [23724] dbg: dns: IPs found: full-external: 124.216.232.158 untrusted: 124.216.232.158 originating: [23724] dbg: dns: only inspecting the following IPs: [23724] dbg: dns: checking RBL combined.njabl.org., set njabl [23724] dbg: dns: IPs found: full-external: 124.216.232.158 untrusted: 124.216.232.158 originating: [23724] dbg: dns: only inspecting the following IPs: 124.216.232.158 [23724] dbg: dns: launching DNS A query for 158.232.216.124.combined.njabl.org. in background [23724] dbg: dns: checking RBL bl.spamcop.net., set spamcop [23724] dbg: dns: IPs found: full-external: 124.216.232.158 untrusted: 124.216.232.158 originating: [23724] dbg: dns: only inspecting the following IPs: 124.216.232.158 [23724] dbg: dns: launching DNS TXT query for 158.232.216.124.bl.spamcop.net. in background [23724] dbg: dns: _check_rbl_addresses RBL blackhole.securitysage.com., set securitysage [23724] dbg: dns: launching DNS A query for fun2reademail.com.blackhole.securitysage.com. in background [23724] dbg: dns: _check_rbl_addresses RBL rhsbl.ahbl.org., set ahbl [23724] dbg: dns: launching DNS A query for fun2reademail.com.rhsbl.ahbl.org. in background [23724] dbg: dns: checking RBL dob.sibl.support-intelligence.net., set dob [23724] dbg: dns: IPs found: full-external: 124.216.232.158 untrusted: 124.216.232.158 originating: [23724] dbg: dns: only inspecting the following IPs: 124.216.232.158 [23724] dbg: dns: launching DNS A query for 158.232.216.124.dob.sibl.support-intelligence.net. in background [23724] dbg: dns: checking A and MX for host fun2reademail.com [23724] dbg: dns: launching DNS A query for fun2reademail.com in background [23724] dbg: dns: launching DNS MX query for fun2reademail.com in background [23724] dbg: dns: checking RBL zen.spamhaus.org., set zen-lastexternal [23724] dbg: dns: IPs found: full-external: 124.216.232.158 untrusted: 124.216.232.158 originating: [23724] dbg: dns: only inspecting the following IPs: 124.216.232.158 [23724] dbg: dns: launching DNS A query for 158.232.216.124.zen.spamhaus.org. in background [23724] dbg: dns: checking RBL dnsbl.sorbs.net., set sorbs-lastexternal [23724] dbg: dns: IPs found: full-external: 124.216.232.158 untrusted: 124.216.232.158 originating: [23724] dbg: dns: only inspecting the following IPs: 124.216.232.158 [23724] dbg: dns: launching DNS A query for 158.232.216.124.dnsbl.sorbs.net. in background [23724] dbg: dns: checking RBL dnsbl.sorbs.net., set sorbs [23724] dbg: dns: IPs found: full-external: 124.216.232.158 untrusted: 124.216.232.158 originating: [23724] dbg: dns: only inspecting the following IPs: 124.216.232.158 [23724] dbg: dns: _check_rbl_addresses RBL dob.sibl.support-intelligence.net., set dob [23724] dbg: dns: launching DNS A query for fun2reademail.com.dob.sibl.support-intelligence.net. in background [23724] dbg: dns: checking RBL zen.spamhaus.org., set zen-lastexternal [23724] dbg: dns: IPs found: full-external: 124.216.232.158 untrusted: 124.216.232.158 originating: [23724] dbg: dns: only inspecting the following IPs: 124.216.232.158 [23724] dbg: dns: checking RBL list.dnswl.org., set dnswl-firsttrusted [23724] dbg: dns: IPs found: full-external: 124.216.232.158 untrusted: 124.216.232.158 originating: [23724] dbg: dns: only inspecting the following IPs: 124.216.232.158 [23724] dbg: dns: launching DNS A query for 158.232.216.124.list.dnswl.org. in background [23724] dbg: dns: checking RBL sa-accredit.habeas.com., set habeas-firsttrusted [23724] dbg: dns: IPs found: full-external: 124.216.232.158 untrusted: 124.216.232.158 originating: [23724] dbg: dns: only inspecting the following IPs: 124.216.232.158 [23724] dbg: dns: launching DNS A query for 158.232.216.124.sa-accredit.habeas.com. in background [23724] dbg: dns: checking RBL combined-HIB.dnsiplists.completewhois.com., set whois [23724] dbg: dns: IPs found: full-external: 124.216.232.158 untrusted: 124.216.232.158 originating: [23724] dbg: dns: only inspecting the following IPs: 124.216.232.158 [23724] dbg: dns: launching DNS A query for 158.232.216.124.combined-HIB.dnsiplists.completewhois.com. in background [23724] dbg: dns: checking RBL list.dsbl.org., set dsbl-lastexternal [23724] dbg: dns: IPs found: full-external: 124.216.232.158 untrusted: 124.216.232.158 originating: [23724] dbg: dns: only inspecting the following IPs: 124.216.232.158 [23724] dbg: dns: launching DNS TXT query for 158.232.216.124.list.dsbl.org. in background [23724] dbg: dns: checking RBL sa-trusted.bondedsender.org., set bsp-firsttrusted [23724] dbg: dns: IPs found: full-external: 124.216.232.158 untrusted: 124.216.232.158 originating: [23724] dbg: dns: only inspecting the following IPs: 124.216.232.158 [23724] dbg: dns: launching DNS TXT query for 158.232.216.124.sa-trusted.bondedsender.org. in background [23724] dbg: dns: checking RBL combined-HIB.dnsiplists.completewhois.com., set whois-lastexternal [23724] dbg: dns: IPs found: full-external: 124.216.232.158 untrusted: 124.216.232.158 originating: [23724] dbg: dns: only inspecting the following IPs: 124.216.232.158 [23724] dbg: dns: checking RBL zen.spamhaus.org., set zen [23724] dbg: dns: IPs found: full-external: 124.216.232.158 untrusted: 124.216.232.158 originating: [23724] dbg: dns: only inspecting the following IPs: 124.216.232.158 [23724] dbg: dns: _check_rbl_addresses RBL bl.open-whois.org., set openwhois [23724] dbg: dns: launching DNS A query for fun2reademail.com.bl.open-whois.org. in background [23724] dbg: dns: _check_rbl_addresses RBL fulldom.rfc-ignorant.org., set rfci_envfrom [23724] dbg: dns: launching DNS A query for fun2reademail.com.fulldom.rfc-ignorant.org. in background [23724] dbg: dns: checking RBL iadb.isipp.com., set iadb-firsttrusted [23724] dbg: dns: IPs found: full-external: 124.216.232.158 untrusted: 124.216.232.158 originating: [23724] dbg: dns: only inspecting the following IPs: 124.216.232.158 [23724] dbg: dns: launching DNS A query for 158.232.216.124.iadb.isipp.com. in background [23724] dbg: check: running tests for priority: -1000 [23724] dbg: rules: running head tests; score so far=0 [23724] dbg: eval: all '*From' addrs: laratone@fun2reademail.com [23724] dbg: eval: all '*To' addrs: contact@andrewscompanies.com [23724] dbg: rules: running body tests; score so far=0 [23724] dbg: rules: running uri tests; score so far=0 [23724] dbg: rules: running rawbody tests; score so far=0 [23724] dbg: rules: running full tests; score so far=0 [23724] dbg: rules: running meta tests; score so far=0 [23724] dbg: check: running tests for priority: -950 [23724] dbg: rules: running head tests; score so far=0 [23724] dbg: rules: running body tests; score so far=0 [23724] dbg: rules: running uri tests; score so far=0 [23724] dbg: rules: running rawbody tests; score so far=0 [23724] dbg: rules: running full tests; score so far=0 [23724] dbg: rules: running meta tests; score so far=0 [23724] dbg: check: running tests for priority: -900 [23724] dbg: rules: running head tests; score so far=0 [23724] dbg: rules: running body tests; score so far=0 [23724] dbg: rules: running uri tests; score so far=0 [23724] dbg: rules: running rawbody tests; score so far=0 [23724] dbg: rules: running full tests; score so far=0 [23724] dbg: rules: running meta tests; score so far=0 [23724] dbg: check: running tests for priority: -400 [23724] dbg: rules: running head tests; score so far=0 [23724] dbg: rules: running body tests; score so far=0 [23724] dbg: rules: running uri tests; score so far=0 [23724] dbg: rules: running rawbody tests; score so far=0 [23724] dbg: rules: running full tests; score so far=0 [23724] dbg: rules: running meta tests; score so far=0 [23724] dbg: check: running tests for priority: 0 [23724] dbg: rules: running head tests; score so far=0 [23724] dbg: rules: ran header rule __CT_TEXT_PLAIN ======> got hit: "text/plain" [23724] dbg: rules: ran header rule STOX_REPLY_TYPE ======> got hit: "text/plain; format=flowed; charset="windows-1252"; reply-type=original" [23724] dbg: rules: ran header rule __CT ======> got hit: "t" [23724] dbg: rules: ran header rule TVD_FINGER_02 ======> got hit: "text/plain; format=flowed; charset="windows-1252"; reply-type=original" [23724] dbg: rules: ran header rule __CTYPE_CHARSET_QUOTED ======> got hit: "charset="" [23724] dbg: rules: ran header rule RDNS_NONE ======> got hit: "[ ip=124.216.232.158 rdns= " [23724] dbg: rules: ran header rule __DOS_SINGLE_EXT_RELAY ======> got hit: "[ ip=124.216.232.158 rdns= helo=fun2reademail.com by=spamfilter.andrewscompanies.com ident= envfrom= intl=0 id=l72KDCrD023712 auth= msa=0 ]" [23724] dbg: rules: ran header rule __MISSING_REF ======> got hit: "UNSET" [23724] dbg: rules: ran header rule __FH_HAS_XPRIORITY ======> got hit: "3" [23724] dbg: rules: ran header rule __MIME_VERSION ======> got hit: "1" [23724] dbg: rules: ran header rule __HAS_RCVD ======> got hit: "f" [23724] dbg: rules: ran header rule __DOS_RCVD_THU ======> got hit: " Thu, " [23724] dbg: rules: ran header rule __TOCC_EXISTS ======> got hit: """ [23724] dbg: rules: ran header rule __MSGID_RANDY ======> got hit: "<001b01c7d58c$eb796e10$00798d94@yourf03e8146b4>" [23724] dbg: rules: ran header rule __MSGID_OK_HEX ======> got hit: "eb796e10" [23724] dbg: rules: ran header rule __MIMEOLE_MS ======> got hit: "Produced By Microsoft MimeOLE" [23724] dbg: rules: ran header rule __HDR_ORDER_FTSDMCXXXX ======> got hit: " [23724] dbg: rules: From: "Kayla Carroll" [23724] dbg: rules: To: "contact" [23724] dbg: rules: Subject: No more being shy of your manhood [23724] dbg: rules: Date: Fri, 3 Aug 2007 05:12:42 +0900 [23724] dbg: rules: MIME-Version: 1.0 [23724] dbg: rules: Content-Type: text/plain; format=flowed; charset="windows-1252"; reply-type=original [23724] dbg: rules: Content-Transfer-Encoding: 7bit [23724] dbg: rules: X-Priority: 3 [23724] dbg: rules: X-MSMail-Priority: Normal [23724] dbg: rules: X-Mailer: Microsoft Outlook Express 6.00.2800.2962 [23724] dbg: rules: X-MimeOLE:" [23724] dbg: rules: ran header rule __HAS_MSGID ======> got hit: "<" [23724] dbg: rules: ran header rule __SANE_MSGID ======> got hit: "<001b01c7d58c$eb796e10$00798d94@yourf03e8146b4> [23724] dbg: rules: " [23724] dbg: rules: ran header rule __MSGID_DOLLARS_MAYBE ======> got hit: "<001b01c7d58c$eb796e10$00798d94@yourf03e8146b4>" [23724] dbg: rules: ran header rule __MSGID_DOLLARS_OK ======> got hit: "<001b01c7d58c$eb796e10$00798d94@yourf03e8146b4>" [23724] dbg: rules: ran header rule __OE_MSGID_2 ======> got hit: "<001b01c7d58c$eb796e10$00798d94@yourf03e8146b4>" [23724] dbg: rules: ran header rule __CTE ======> got hit: "7" [23724] dbg: rules: ran header rule __FH_HAS_XMSMAIL ======> got hit: "N" [23724] dbg: rules: ran header rule __HAS_SUBJECT ======> got hit: "N" [23724] dbg: rules: ran header rule __XM_MS_IN_GENERAL ======> got hit: "Microsoft Outlook" [23724] dbg: rules: ran header rule __XM_OUTLOOK_EXPRESS ======> got hit: "Microsoft Outlook Express 6" [23724] dbg: rules: ran header rule __ANY_OUTLOOK_MUA ======> got hit: "Microsoft Outlook" [23724] dbg: rules: ran header rule __OE_MUA ======> got hit: "Outlook Express 6." [23724] dbg: rules: ran header rule __HAS_X_MAILER ======> got hit: "M" [23724] dbg: rules: ran header rule __XM_MSOE6 ======> got hit: "Microsoft Outlook Express 6" [23724] dbg: rules: ran header rule __MO_OL_1ECD5 ======> got hit: "Produced By Microsoft MimeOLE V6.00.2800.1081" [23724] dbg: rules: ran header rule __HAS_MIMEOLE ======> got hit: "P" [23724] dbg: spf: checking to see if the message has a Received-SPF header that we can use [23724] dbg: spf: checking HELO (helo=fun2reademail.com, ip=124.216.232.158) [23724] dbg: dns: hit 209.85.112.44 [23724] dbg: dns: hit 127.0.0.4 [23724] dbg: dns: hit "Blocked - see http://www.spamcop.net/bl.shtml?124.216.232.158" [23724] dbg: dns: hit 0 fun2reademail.com. [23724] dbg: dns: hit 127.0.0.7 [23724] dbg: asn: asn.routeviews.org.: lookup result packet: '158.232.216.124.asn.routeviews.org. 600 IN TXT "10191" "124.216.224.0" "19"' [23724] dbg: spf: query for /124.216.232.158/fun2reademail.com: result: none, comment: , text: No applicable sender policy available [23724] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [23724] dbg: spf: checking EnvelopeFrom (helo=fun2reademail.com, ip=124.216.232.158, envfrom=laratone@fun2reademail.com) [23724] dbg: spf: query for laratone@fun2reademail.com/124.216.232.158/fun2reademail.com: result: none, comment: , text: No applicable sender policy available [23724] dbg: rules: ran eval rule __ENV_AND_HDR_FROM_MATCH ======> got hit (1) [23724] dbg: spf: def_spf_whitelist_from: already checked spf and didn't get pass, skipping whitelist check [23724] dbg: spf: whitelist_from_spf: already checked spf and didn't get pass, skipping whitelist check [23724] dbg: rules: running body tests; score so far=9.022 [23724] dbg: rules: ran body rule __MBA ======> got hit: "mba" [23724] dbg: rules: ran body rule BODY_ENHANCEMENT2 ======> got hit: "dick size by your shoes size" [23724] dbg: rules: ran body rule BODY_ENHANCEMENT ======> got hit: "bigger shoes to make women think you have a huge dick" [23724] dbg: rules: ran body rule __NONEMPTY_BODY ======> got hit: "N" [23724] dbg: rules: running uri tests; score so far=11.344 [23724] dbg: rules: ran uri rule __DOS_HAS_ANY_URI ======> got hit: "h" [23724] dbg: https_http_mismatch: anchors 0 [23724] dbg: eval: stock info total: 0 [23724] dbg: rules: relay fun2reademail.com doesn't match any whitelist [23724] dbg: rules: running rawbody tests; score so far=11.344 [23724] dbg: rules: running full tests; score so far=11.344 [23724] dbg: info: entering helper-app run mode [23724] dbg: info: leaving helper-app run mode [23724] dbg: razor2: part=0 engine=4 contested=0 confidence=0 [23724] dbg: razor2: part=0 engine=8 contested=0 confidence=100 [23724] dbg: razor2: results: spam? 1 [23724] dbg: razor2: results: engine 8, highest cf score: 100 [23724] dbg: razor2: results: engine 4, highest cf score: 0 [23724] dbg: rules: ran eval rule RAZOR2_CF_RANGE_E8_51_100 ======> got hit (1) [23724] dbg: rules: ran eval rule RAZOR2_CHECK ======> got hit (1) [23724] dbg: rules: ran eval rule RAZOR2_CF_RANGE_51_100 ======> got hit (1) [23724] dbg: pyzor: pyzor is available: /usr/bin/pyzor [23724] dbg: info: entering helper-app run mode [23724] dbg: pyzor: opening pipe: /usr/bin/pyzor check < /var/spool/MailScanner/incoming/SpamAssassin-Temp/.spamassassin23724QET9actmp [23725] dbg: util: setuid: ruid=0 euid=0 [23724] dbg: pyzor: [23725] finished: exit=0x0100 [23724] dbg: pyzor: got response: 82.94.255.100:24441 (200, 'OK') 0 0 [23724] dbg: info: leaving helper-app run mode [23724] dbg: rules: running meta tests; score so far=13.844 [23724] dbg: check: running tests for priority: 500 [23724] dbg: async: select found no socks ready [23724] dbg: uridnsbl: domain "edlyonwi.cn" listed (URIBL_AB_SURBL): 127.0.0.118 [23724] dbg: dns: URIBL_AB_SURBL lookup finished [23724] dbg: uridnsbl: domain "edlyonwi.cn" listed (URIBL_WS_SURBL): 127.0.0.118 [23724] dbg: dns: URIBL_WS_SURBL lookup finished [23724] dbg: uridnsbl: domain "edlyonwi.cn" listed (URIBL_JP_SURBL): 127.0.0.118 [23724] dbg: dns: URIBL_JP_SURBL lookup finished [23724] dbg: uridnsbl: domain "edlyonwi.cn" listed (URIBL_OB_SURBL): 127.0.0.118 [23724] dbg: dns: URIBL_OB_SURBL lookup finished [23724] dbg: uridnsbl: domain "edlyonwi.cn" listed (URIBL_SC_SURBL): 127.0.0.118 [23724] dbg: dns: URIBL_SC_SURBL lookup finished [23724] dbg: uridnsbl: query for edlyonwi.cn took 2 seconds to look up (multi.surbl.org.:edlyonwi.cn) [23724] dbg: uridnsbl: domain "edlyonwi.cn" listed (URIBL_BLACK): 127.0.0.2 [23724] dbg: dns: URIBL_BLACK lookup finished [23724] dbg: uridnsbl: domain "edlyonwi.cn" listed (URIBL_RHS_URIBL_BLACK): 127.0.0.2 [23724] dbg: uridnsbl: query for edlyonwi.cn took 2 seconds to look up (multi.uribl.com.:edlyonwi.cn) [23724] dbg: uridnsbl: query for edlyonwi.cn took 2 seconds to look up (dob.sibl.support-intelligence.net:edlyonwi.cn) [23724] dbg: uridnsbl: query for edlyonwi.cn took 2 seconds to look up (bl.open-whois.org.:edlyonwi.cn) [23724] dbg: async: queries completed: 21 started: 0 [23724] dbg: async: queries active: DNSBL-A=1 TXT=1 URI-NS=1 at Thu Aug 2 16:13:22 2007 [23724] dbg: async: select found 1 socks ready [23724] dbg: async: queries completed: 1 started: 0 [23724] dbg: async: queries active: DNSBL-A=1 TXT=1 at Thu Aug 2 16:13:22 2007 [23724] dbg: async: select found no socks ready [23724] dbg: async: queries completed: 0 started: 0 [23724] dbg: async: queries active: DNSBL-A=1 TXT=1 at Thu Aug 2 16:13:23 2007 [23724] dbg: async: select found no socks ready [23724] dbg: async: queries completed: 0 started: 0 [23724] dbg: async: queries active: DNSBL-A=1 TXT=1 at Thu Aug 2 16:13:24 2007 [23724] dbg: async: select found no socks ready [23724] dbg: async: queries completed: 0 started: 0 [23724] dbg: async: queries active: DNSBL-A=1 TXT=1 at Thu Aug 2 16:13:25 2007 [23724] dbg: async: select found no socks ready [23724] dbg: async: queries completed: 0 started: 0 [23724] dbg: async: queries active: DNSBL-A=1 TXT=1 at Thu Aug 2 16:13:26 2007 [23724] dbg: async: select found no socks ready [23724] dbg: async: queries completed: 0 started: 0 [23724] dbg: async: queries active: DNSBL-A=1 TXT=1 at Thu Aug 2 16:13:27 2007 [23724] dbg: dns: success for 22 of 24 queries [23724] dbg: dns: timeout for whois, whois-lastexternal, __RCVD_IN_WHOIS, DNSBL-A, dns:A:158.232.216.124.combined-HIB.dnsiplists.completewhois.com. after 7 seconds [23724] dbg: dns: timeout for TXT, asnlookup-0-asn.routeviews.org. after 7 seconds [23724] dbg: async: aborting remaining lookups [23724] dbg: rules: running head tests; score so far=27.03 [23724] dbg: rules: running body tests; score so far=27.03 [23724] dbg: rules: running uri tests; score so far=27.03 [23724] dbg: rules: running rawbody tests; score so far=27.03 [23724] dbg: rules: running full tests; score so far=27.03 [23724] dbg: rules: running meta tests; score so far=27.03 [23724] dbg: check: running tests for priority: 899 [23724] dbg: rules: running head tests; score so far=27.03 [23724] dbg: rules: running body tests; score so far=27.03 [23724] dbg: rules: running uri tests; score so far=27.03 [23724] dbg: rules: running rawbody tests; score so far=27.03 [23724] dbg: rules: running full tests; score so far=27.03 [23724] dbg: crm114: call_crm() called, action: check [23724] dbg: info: entering helper-app run mode [23724] dbg: crm114: crm114_command run [23724] dbg: crm114: found version 20070301-BlameBaltar ( TRE 0.7.5 (LGPL) ) MR-BD9991E2 [23724] dbg: crm114: found CacheID sfid-20070802_161327_863524_4207CBA1 [23724] dbg: crm114: found status UNSURE and score 0.00 [23724] dbg: crm114: found Notice Please train this message. [23724] dbg: info: leaving helper-app run mode [23724] dbg: crm114: call_crm returns (UNSURE, 0.00) [23724] dbg: crm114: score is 0.0000, translated to SA score: -0.0000, linear factor was -0.2000 [23724] dbg: rules: running meta tests; score so far=27.03 [23724] dbg: check: running tests for priority: 900 [23724] dbg: rules: running head tests; score so far=27.03 [23724] dbg: rules: running body tests; score so far=27.03 [23724] dbg: rules: running uri tests; score so far=27.03 [23724] dbg: FuzzyOcr: Scan canceled, message has already more than 20 points. [23724] dbg: rules: running rawbody tests; score so far=27.03 [23724] dbg: rules: running full tests; score so far=27.03 [23724] dbg: rules: running meta tests; score so far=27.03 [23724] dbg: check: running tests for priority: 1000 [23724] dbg: rules: running head tests; score so far=27.03 [23724] dbg: rules: running body tests; score so far=27.03 [23724] dbg: rules: running uri tests; score so far=27.03 [23724] dbg: rules: running rawbody tests; score so far=27.03 [23724] dbg: rules: running full tests; score so far=27.03 [23724] dbg: rules: running meta tests; score so far=27.03 [23724] dbg: check: is spam? score=27.03 required=5 [23724] dbg: check: tests=BODY_ENHANCEMENT,BODY_ENHANCEMENT2,CRM114_CHECK,RAZOR2_CF_RANGE_51_100,RAZOR2_CF_RANGE_E8_51_100,RAZOR2_CHECK,RCVD_IN_BL_SPAMCOP_NET,RCVD_IN_SORBS_WEB,RCVD_IN_XBL,RDNS_NONE,STOX_REPLY_TYPE,TVD_FINGER_02,URIBL_AB_SURBL,URIBL_BLACK,URIBL_JP_SURBL,URIBL_OB_SURBL,URIBL_SC_SURBL,URIBL_WS_SURBL [23724] dbg: check: subtests=__ANY_OUTLOOK_MUA,__CT,__CTE,__CTYPE_CHARSET_QUOTED,__CT_TEXT_PLAIN,__DOS_HAS_ANY_URI,__DOS_RCVD_THU,__DOS_SINGLE_EXT_RELAY,__ENV_AND_HDR_FROM_MATCH,__FH_HAS_XMSMAIL,__FH_HAS_XPRIORITY,__HAS_ANY_URI,__HAS_MIMEOLE,__HAS_MSGID,__HAS_MSMAIL_PRI,__HAS_RCVD,__HAS_SUBJECT,__HAS_X_MAILER,__HDR_ORDER_FTSDMCXXXX,__MBA,__MIMEOLE_MS,__MIME_VERSION,__MISSING_REF,__MO_OL_1ECD5,__MSGID_DOLLARS_MAYBE,__MSGID_DOLLARS_OK,__MSGID_OK_HEX,__MSGID_RANDY,__NONEMPTY_BODY,__NO_INR_YES_REF,__OE_MSGID_2,__OE_MUA,__RCVD_IN_SORBS,__RCVD_IN_ZEN,__SANE_MSGID,__TOCC_EXISTS,__XM_MSOE6,__XM_MS_IN_GENERAL,__XM_OUTLOOK_EXPRESS Ignore errors about failing to find EOCD signature Stopping now as you are debugging me. commit ineffective with AutoCommit enabled at /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, line 47. Commmit ineffective while AutoCommit is on at /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, line 47. [ OK ] [root@spamfilter ~]# service MailScanner restart Shutting down MailScanner daemons: MailScanner: [FAILED] incoming sendmail: [ OK ] outgoing sendmail: [ OK ] Starting MailScanner daemons: incoming sendmail: [ OK ] outgoing sendmail: [ OK ] MailScanner: [ OK ] [root@spamfilter ~]# From cleveland at winnefox.org Thu Aug 2 21:52:02 2007 From: cleveland at winnefox.org (Jody Cleveland) Date: Thu Aug 2 21:52:29 2007 Subject: Improved init.d script In-Reply-To: <46B216AD.1010204@ecs.soton.ac.uk> Message-ID: Is this part of 4.62.9-2? Or should I do this after that's finished? (just getting ready to install 4.62.9-2) - jody On 8/2/07 12:38 PM, "Julian Field" wrote: > Attached are new versions of the RedHat and SuSE /etc/init.d/MailScanner > scripts. > The improvement is obvious when you do > /etc/init.d/MailScanner restart > or > service MailScanner restart > > It used to just wait for a fixed length of time (30 seconds by default). > Now it watches to see when the old MailScanner processes have actually > died, and starts it all back up again as soon as the previous > MailScanner is dead. > > It is important not to 'kill -9' the MailScanner processes, as they do > quite a bit of cleanup so they don't leave a mess behind, for example in > /var/spool/MailScanner/incoming. > > Please let me know what you think of them, and if they work for you okay. > > Jules From MailScanner at ecs.soton.ac.uk Thu Aug 2 22:00:21 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 2 22:00:49 2007 Subject: Improved init.d script In-Reply-To: References: Message-ID: <46B245E5.2070102@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 After that's finished. It's not part of 4.62. Jody Cleveland wrote: > Is this part of 4.62.9-2? Or should I do this after that's finished? (just > getting ready to install 4.62.9-2) > > - jody > > > On 8/2/07 12:38 PM, "Julian Field" wrote: > > >> Attached are new versions of the RedHat and SuSE /etc/init.d/MailScanner >> scripts. >> The improvement is obvious when you do >> /etc/init.d/MailScanner restart >> or >> service MailScanner restart >> >> It used to just wait for a fixed length of time (30 seconds by default). >> Now it watches to see when the old MailScanner processes have actually >> died, and starts it all back up again as soon as the previous >> MailScanner is dead. >> >> It is important not to 'kill -9' the MailScanner processes, as they do >> quite a bit of cleanup so they don't leave a mess behind, for example in >> /var/spool/MailScanner/incoming. >> >> Please let me know what you think of them, and if they work for you okay. >> >> Jules >> > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGskXmEfZZRxQVtlQRAuXqAKDRuy4eJKBCIpYEvMO4RmrgjaDEswCdFneg VoZTqdo72QOBLh+rfF5DeMc= =uO4+ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Thu Aug 2 22:08:19 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 2 22:08:36 2007 Subject: MailScanner --lint error Message-ID: I am getting the following error on my boxes; ERROR: The "envelope_sender_header" in your spam.assassin.prefs.conf ERROR: is not correct, it should match X-BlaBla-MailScanner-From But I have the exact text it is looking for in spam.assassin.prefs.conf Obviously BlaBla is not the organization name. I tried with an = between envelope_sender_header and the header text and without the =. I only changed it because it recommended I have %orgname% in the envelope from and to headers. So it is nagging me to change it, and then complains when I do. Did I suddenly get married this thing? -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Thu Aug 2 22:12:49 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 2 22:15:06 2007 Subject: Improved init.d script In-Reply-To: References: <46B216AD.1010204@ecs.soton.ac.uk> Message-ID: Jody Cleveland spake the following on 8/2/2007 1:52 PM: > Is this part of 4.62.9-2? Or should I do this after that's finished? (just > getting ready to install 4.62.9-2) > It looks like it came out after 4.62.9-2. I think in answer to someone having trouble with the SUSE script. Either way, you will tell quickly if you do a restart. It says it is waiting for the processes to die and dot leaders until they do. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From lists at jfworks.net Thu Aug 2 22:22:53 2007 From: lists at jfworks.net (James) Date: Thu Aug 2 22:23:03 2007 Subject: MailScanner --lint error In-Reply-To: References: Message-ID: <46B24B2D.8020602@jfworks.net> Scott Silva wrote: > I am getting the following error on my boxes; > ERROR: The "envelope_sender_header" in your spam.assassin.prefs.conf > ERROR: is not correct, it should match X-BlaBla-MailScanner-From > > But I have the exact text it is looking for in spam.assassin.prefs.conf > Obviously BlaBla is not the organization name. > I tried with an = between envelope_sender_header and the header text and > without the =. > I only changed it because it recommended I have %orgname% in the envelope from > and to headers. > So it is nagging me to change it, and then complains when I do. Did I suddenly > get married this thing? > > I saw the same thing. I simply changed the line to what it said it wanted then when I ran it MailScanner --lint again it was happy. I copied and pasted so I wouldn't have a spelling error. Like this: envelope_sender_header X-BlaBla-MailScanner-From Maybe one wife wasn't enough for you? HTH, James From stinkybob at gmail.com Thu Aug 2 22:27:50 2007 From: stinkybob at gmail.com (Eugene MacDougal) Date: Thu Aug 2 22:27:54 2007 Subject: Upgrading Minor versions Message-ID: <2579c6b20708021427w6521a719na27d657ffe7d6b6d@mail.gmail.com> This morning I upgraded from 4.62.9-1 to 4.62.9-2 using the tar method on Solaris 10 x86. After installing, I was unfortunate enough to find that the installer had overwritten my config files. Apparantly if there is a minor version change, the folder does not change names....so if you already have a folder with that name, it kills your config. This is very bad if someone hasn't been using MailScanner for a while and has dozens of backups laying around. Is there some way to make the installer check to see if its about to overwrite files? -Gene -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070802/a81b91f9/attachment.html From glenn.steen at gmail.com Thu Aug 2 22:28:25 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu Aug 2 22:28:27 2007 Subject: CRM114 css not updating In-Reply-To: <1964AAFBC212F742958F9275BF63DBB04B105A@winchester.andrewscompanies.com> References: <1964AAFBC212F742958F9275BF63DBB04B1058@winchester.andrewscompanies.com> <32667771.10581186083926579.JavaMail.root@office.splatnix.net> <1964AAFBC212F742958F9275BF63DBB04B105A@winchester.andrewscompanies.com> Message-ID: <223f97700708021428x5333ecb5r5b406072ececa62d@mail.gmail.com> On 02/08/07, Steven Andrews wrote: > Yep; did that. All looks good. Attached. Two more things to check (that differ from my setup on a Mandriva (that works))... I've got the learn flag set too (so that SA can be used to train it all in one sweep)... Shouldn't matter, but why not test it. Either check set the actual directory to 777 as well, or reset the perms and make the owner (or group) accessible to apache (and leave either as root so MS can get at it). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From ssilva at sgvwater.com Thu Aug 2 22:32:48 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 2 22:33:06 2007 Subject: MailScanner --lint error In-Reply-To: <46B24B2D.8020602@jfworks.net> References: <46B24B2D.8020602@jfworks.net> Message-ID: James spake the following on 8/2/2007 2:22 PM: > Scott Silva wrote: >> I am getting the following error on my boxes; >> ERROR: The "envelope_sender_header" in your spam.assassin.prefs.conf >> ERROR: is not correct, it should match X-BlaBla-MailScanner-From >> >> But I have the exact text it is looking for in spam.assassin.prefs.conf >> Obviously BlaBla is not the organization name. >> I tried with an = between envelope_sender_header and the header text and >> without the =. >> I only changed it because it recommended I have %orgname% in the >> envelope from >> and to headers. >> So it is nagging me to change it, and then complains when I do. Did I >> suddenly >> get married this thing? >> >> > I saw the same thing. I simply changed the line to what it said it > wanted then when I ran it MailScanner --lint again it was happy. > I copied and pasted so I wouldn't have a spelling error. > > Like this: > envelope_sender_header X-BlaBla-MailScanner-From > > Maybe one wife wasn't enough for you? > > > HTH, > James I also tried the copy and paste bit, and restarted, and still it whines at me endlessly. And believe me, polygamy is not worth it!!! I am ready to go back to the original header, without the %org-name% in it. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Thu Aug 2 22:57:50 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 2 22:58:17 2007 Subject: MailScanner --lint error--SOLVED In-Reply-To: References: Message-ID: Scott Silva spake the following on 8/2/2007 2:08 PM: > I am getting the following error on my boxes; > ERROR: The "envelope_sender_header" in your spam.assassin.prefs.conf > ERROR: is not correct, it should match X-BlaBla-MailScanner-From > > But I have the exact text it is looking for in spam.assassin.prefs.conf > Obviously BlaBla is not the organization name. > I tried with an = between envelope_sender_header and the header text and > without the =. > I only changed it because it recommended I have %orgname% in the envelope from > and to headers. > So it is nagging me to change it, and then complains when I do. Did I suddenly > get married this thing? > I found the problem -- there can be only 1 space between envelope_sender_header and the header text. I had 2 spaces and the parser must think the extra space is part of the header text. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From jorge.prado at solidspace.com Thu Aug 2 18:01:27 2007 From: jorge.prado at solidspace.com (jorge.prado) Date: Thu Aug 2 23:01:31 2007 Subject: automated response Message-ID: <10708021801.AA54644@solidspace.com> I am currently out of the office, returning Monday, August 6. Regards, Jorge Prado From mailscanner at eltofts.homelinux.com Thu Aug 2 23:42:47 2007 From: mailscanner at eltofts.homelinux.com (Andy Wright) Date: Thu Aug 2 23:43:16 2007 Subject: Using ClamAV to find spam Message-ID: <46B25DE7.8020904@eltofts.homelinux.com> Hi list, I've enabled the "ClamAV Full Message Scan" option and installed the sanesecurity sigs. Clam is nicely finding loads (and loads... and loads...!) of spam, but of course is causing all these messages to be tagged as Virused. This is making my MailWatch screen a sea of red and skewing the stats such that I appear to be receiving loads of viruses instead of spam. Is it possible to get MailScanner to look at the report from ClamAV and determine if the message is really spam rather than virused ? Cheers, Andy. From brent.addis at pronet.co.nz Thu Aug 2 23:49:42 2007 From: brent.addis at pronet.co.nz (Brent Addis) Date: Thu Aug 2 23:52:25 2007 Subject: Using ClamAV to find spam References: <46B25DE7.8020904@eltofts.homelinux.com> Message-ID: <7EF1F27F7292534D82933F70AB6996CC25CE45@pro-ak-exch01.hosted.pronet.net.nz> Try the clamav spamassassin plugin. If your spam scores high enough it shouldn't be virus scanned and won't scew your stats. http://www.nabble.com/My-bash-script-to-upload-PDFinfo-daily,-safely-t4115144.html has an example about halfway through the comments at the bottom. ________________________________ From: mailscanner-bounces@lists.mailscanner.info on behalf of Andy Wright Sent: Fri 3/08/2007 10:42 a.m. To: mailscanner@lists.mailscanner.info Subject: Using ClamAV to find spam Hi list, I've enabled the "ClamAV Full Message Scan" option and installed the sanesecurity sigs. Clam is nicely finding loads (and loads... and loads...!) of spam, but of course is causing all these messages to be tagged as Virused. This is making my MailWatch screen a sea of red and skewing the stats such that I appear to be receiving loads of viruses instead of spam. Is it possible to get MailScanner to look at the report from ClamAV and determine if the message is really spam rather than virused ? Cheers, Andy. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/ms-tnef Size: 4538 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070803/da1a4b41/attachment.bin From mailscanner at eltofts.homelinux.com Fri Aug 3 00:09:28 2007 From: mailscanner at eltofts.homelinux.com (Andy Wright) Date: Fri Aug 3 00:10:11 2007 Subject: Using ClamAV to find spam In-Reply-To: <7EF1F27F7292534D82933F70AB6996CC25CE45@pro-ak-exch01.hosted.pronet.net.nz> References: <46B25DE7.8020904@eltofts.homelinux.com> <7EF1F27F7292534D82933F70AB6996CC25CE45@pro-ak-exch01.hosted.pronet.net.nz> Message-ID: <46B26428.9060607@eltofts.homelinux.com> Brent Addis wrote: > Try the clamav spamassassin plugin. If your spam scores high enough it shouldn't be virus scanned and won't scew your stats. > > http://www.nabble.com/My-bash-script-to-upload-PDFinfo-daily,-safely-t4115144.html has an example about halfway through the comments at the bottom. > > > > ________________________________ > > From: mailscanner-bounces@lists.mailscanner.info on behalf of Andy Wright > Sent: Fri 3/08/2007 10:42 a.m. > To: mailscanner@lists.mailscanner.info > Subject: Using ClamAV to find spam > > > > Hi list, > > I've enabled the "ClamAV Full Message Scan" option and installed the > sanesecurity sigs. Clam is nicely finding loads (and loads... and > loads...!) of spam, but of course is causing all these messages to be > tagged as Virused. This is making my MailWatch screen a sea of red and > skewing the stats such that I appear to be receiving loads of viruses > instead of spam. > > Is it possible to get MailScanner to look at the report from ClamAV and > determine if the message is really spam rather than virused ? > > Cheers, > Andy. > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > Hi Brent, thanks for the suggestion, although I'm reluctant to add yet more plugins - most of the spams are already being scored at 20+ (how high does this have to get before virus scanning is skipped?) I guess what I'm after is a way for MailScanner to handle things differently if the return from ClamAV is "Email.*, Html.*" etc Now that Clam seems to be more than just a *virus* finder might it make sense for MailScanner to look more closely at the returned result ? Maybe an excuse for Julian to up the options well beyond the 300 mark ?! Andy. From maillists at conactive.com Fri Aug 3 00:31:17 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Fri Aug 3 00:31:19 2007 Subject: Upgrading Minor versions In-Reply-To: <2579c6b20708021427w6521a719na27d657ffe7d6b6d@mail.gmail.com> References: <2579c6b20708021427w6521a719na27d657ffe7d6b6d@mail.gmail.com> Message-ID: Eugene MacDougal wrote on Thu, 2 Aug 2007 16:27:50 -0500: > Is there some way to make the installer check to see if its about to overwrite files? Eugene, it normally doesn't overwrite existing config files, not on major, not on minor version changes. Can you provide more details? Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From ssilva at sgvwater.com Fri Aug 3 00:30:27 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Aug 3 00:35:12 2007 Subject: Using ClamAV to find spam In-Reply-To: <46B26428.9060607@eltofts.homelinux.com> References: <46B25DE7.8020904@eltofts.homelinux.com> <7EF1F27F7292534D82933F70AB6996CC25CE45@pro-ak-exch01.hosted.pronet.net.nz> <46B26428.9060607@eltofts.homelinux.com> Message-ID: Andy Wright spake the following on 8/2/2007 4:09 PM: > Brent Addis wrote: >> Try the clamav spamassassin plugin. If your spam scores high enough it >> shouldn't be virus scanned and won't scew your stats. >> >> http://www.nabble.com/My-bash-script-to-upload-PDFinfo-daily,-safely-t4115144.html >> has an example about halfway through the comments at the bottom. >> >> >> >> ________________________________ >> >> From: mailscanner-bounces@lists.mailscanner.info on behalf of Andy Wright >> Sent: Fri 3/08/2007 10:42 a.m. >> To: mailscanner@lists.mailscanner.info >> Subject: Using ClamAV to find spam >> >> >> >> Hi list, >> >> I've enabled the "ClamAV Full Message Scan" option and installed the >> sanesecurity sigs. Clam is nicely finding loads (and loads... and >> loads...!) of spam, but of course is causing all these messages to be >> tagged as Virused. This is making my MailWatch screen a sea of red and >> skewing the stats such that I appear to be receiving loads of viruses >> instead of spam. >> >> Is it possible to get MailScanner to look at the report from ClamAV and >> determine if the message is really spam rather than virused ? >> >> Cheers, >> Andy. >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >> >> > Hi Brent, > > thanks for the suggestion, although I'm reluctant to add yet more > plugins - most of the spams are already being scored at 20+ (how high > does this have to get before virus scanning is skipped?) > > I guess what I'm after is a way for MailScanner to handle things > differently if the return from ClamAV is "Email.*, Html.*" etc Now that > Clam seems to be more than just a *virus* finder might it make sense for > MailScanner to look more closely at the returned result ? Maybe an > excuse for Julian to up the options well beyond the 300 mark ?! > > Andy. AFAIK all their signatures give sanesecurity in their responses. Maybe an option to look for this and just give spam scores. For me, I don't really care right now what stops them, as long as it doesn't go to the users. Maybe later if I start reporting ratios to someone, I might. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From mailscanner at eltofts.homelinux.com Fri Aug 3 00:44:20 2007 From: mailscanner at eltofts.homelinux.com (Andy Wright) Date: Fri Aug 3 00:44:35 2007 Subject: Using ClamAV to find spam In-Reply-To: References: <46B25DE7.8020904@eltofts.homelinux.com> <7EF1F27F7292534D82933F70AB6996CC25CE45@pro-ak-exch01.hosted.pronet.net.nz> <46B26428.9060607@eltofts.homelinux.com> Message-ID: <46B26C54.4030400@eltofts.homelinux.com> Scott Silva wrote: > Andy Wright spake the following on 8/2/2007 4:09 PM: > >> Brent Addis wrote: >> >>> Try the clamav spamassassin plugin. If your spam scores high enough it >>> shouldn't be virus scanned and won't scew your stats. >>> >>> http://www.nabble.com/My-bash-script-to-upload-PDFinfo-daily,-safely-t4115144.html >>> has an example about halfway through the comments at the bottom. >>> >>> >>> >>> ________________________________ >>> >>> From: mailscanner-bounces@lists.mailscanner.info on behalf of Andy Wright >>> Sent: Fri 3/08/2007 10:42 a.m. >>> To: mailscanner@lists.mailscanner.info >>> Subject: Using ClamAV to find spam >>> >>> >>> >>> Hi list, >>> >>> I've enabled the "ClamAV Full Message Scan" option and installed the >>> sanesecurity sigs. Clam is nicely finding loads (and loads... and >>> loads...!) of spam, but of course is causing all these messages to be >>> tagged as Virused. This is making my MailWatch screen a sea of red and >>> skewing the stats such that I appear to be receiving loads of viruses >>> instead of spam. >>> >>> Is it possible to get MailScanner to look at the report from ClamAV and >>> determine if the message is really spam rather than virused ? >>> >>> Cheers, >>> Andy. >>> -- >>> MailScanner mailing list >>> mailscanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> >>> Before posting, read http://wiki.mailscanner.info/posting >>> >>> Support MailScanner development - buy the book off the website! >>> >>> >>> >>> >> Hi Brent, >> >> thanks for the suggestion, although I'm reluctant to add yet more >> plugins - most of the spams are already being scored at 20+ (how high >> does this have to get before virus scanning is skipped?) >> >> I guess what I'm after is a way for MailScanner to handle things >> differently if the return from ClamAV is "Email.*, Html.*" etc Now that >> Clam seems to be more than just a *virus* finder might it make sense for >> MailScanner to look more closely at the returned result ? Maybe an >> excuse for Julian to up the options well beyond the 300 mark ?! >> >> Andy. >> > AFAIK all their signatures give sanesecurity in their responses. Maybe an > option to look for this and just give spam scores. > For me, I don't really care right now what stops them, as long as it doesn't > go to the users. Maybe later if I start reporting ratios to someone, I might. > > Most do, but there are a few along the lines of "Email.Phising.RB-1221" I do report results to clients so this would be a nice thing to be able to correct. From itdept at fractalweb.com Fri Aug 3 01:12:54 2007 From: itdept at fractalweb.com (Chris Yuzik) Date: Fri Aug 3 01:13:06 2007 Subject: updated CRM114 training script. In-Reply-To: <46B23297.7010206@fractalweb.com> References: <1951DC816E1A9F469307B05FA183F4389DC9E0@corpatsmail1.corp.sensis.com> <46B0FBA0.6060601@coders.co.uk> <46B21DC0.1070603@fractalweb.com> <46B23297.7010206@fractalweb.com> Message-ID: <46B27306.1080401@fractalweb.com> Chris Yuzik wrote: > I now have an updated script that trains only crm, not spamassassin. > It's available here: Nothing like having a conversation with myself, not that it's unusual. :-) Found a better way of doing things, and so overwrote the older less-functional file with the new one: http://www.fractalweb.com/scripts/crm_train2.zip Training seems pretty fast. Unfortunately, I don't understand why sometimes I feed it a message, tell it that the message is spam and to force-learn it, then push it through spamassassin again, and CRM114 responds with "unsure" and scores it with -1.9. Any thoughts? Chris From glenn.steen at gmail.com Fri Aug 3 01:52:17 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Aug 3 01:52:20 2007 Subject: MailScanner --lint error--SOLVED In-Reply-To: References: Message-ID: <223f97700708021752k49d7762au79034cae747596ad@mail.gmail.com> So it is back to monogamy then? :) . . . Glad you found it, and shared. Cheers On 02/08/07, Scott Silva wrote: > Scott Silva spake the following on 8/2/2007 2:08 PM: > > I am getting the following error on my boxes; > > ERROR: The "envelope_sender_header" in your spam.assassin.prefs.conf > > ERROR: is not correct, it should match X-BlaBla-MailScanner-From > > > > But I have the exact text it is looking for in spam.assassin.prefs.conf > > Obviously BlaBla is not the organization name. > > I tried with an = between envelope_sender_header and the header text and > > without the =. > > I only changed it because it recommended I have %orgname% in the envelope > from > > and to headers. > > So it is nagging me to change it, and then complains when I do. Did I > suddenly > > get married this thing? > > > I found the problem -- there can be only 1 space between > envelope_sender_header and the header text. I had 2 spaces and the parser > must > think the extra space is part of the header text. > > -- > > MailScanner is like deodorant... > You hope everybody uses it, and > you notice quickly if they don't!!!! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From res at ausics.net Fri Aug 3 02:39:20 2007 From: res at ausics.net (Res) Date: Fri Aug 3 02:39:30 2007 Subject: Upgrading Minor versions In-Reply-To: References: <2579c6b20708021427w6521a719na27d657ffe7d6b6d@mail.gmail.com> Message-ID: Hi Kai, On Fri, 3 Aug 2007, Kai Schaetzl wrote: > Eugene MacDougal wrote on Thu, 2 Aug 2007 16:27:50 -0500: > >> Is there some way to make the installer check to see if its about to overwrite files? > > Eugene, it normally doesn't overwrite existing config files, not on major, not on minor > version changes. Can you provide more details? Yes, on source versions, its happened to me before, thankfully its all under /opt and backed up nightly anyway, even on dummy test machines :) This is why I mentioned a couple of days ago about bringing it into line with most other software versioning, major.minor.beta_number as in 4.63.b1, 4.63.b2 etc reaching the official release as 4.63 (as only 4.63) major. MailScanners installer does not understand at all 4.63.3-5 only 4.63.3, thereby over-writting. As Julian ignored my comments I dare say he has no intention of changing it, as no one else commented, it seems most are happy with it, and I also gather after years of observations 95% of people here use RPM base OS's so they may not be affected by the installers tarball shortfall. -- Cheers Res From itdept at fractalweb.com Fri Aug 3 04:06:37 2007 From: itdept at fractalweb.com (Chris Yuzik) Date: Fri Aug 3 04:06:50 2007 Subject: automated response In-Reply-To: <10708021801.AA54644@solidspace.com> References: <10708021801.AA54644@solidspace.com> Message-ID: <46B29BBD.5060803@fractalweb.com> jorge.prado wrote: > I am currently out of the office, returning Monday, August 6. Jorge, Wow, that's great to know. Hope you had a good long weekend. :-) Chris From uxbod at splatnix.net Fri Aug 3 07:32:03 2007 From: uxbod at splatnix.net (UxBoD) Date: Fri Aug 3 07:25:47 2007 Subject: Using ClamAV to find spam In-Reply-To: <46B26C54.4030400@eltofts.homelinux.com> Message-ID: <9489358.10611186122723027.JavaMail.root@office.splatnix.net> The problem with putting the logic inside MS is that it would be an ever moving target. I believe it has already been reported that McAfee is also checking headers now, and reports when a SPAM is found. It is great that MailWatch exists, even if you don't use the front-end as you can roll your own reports from the maillog table. Regex away and you have your results split by virii or SPAM. If this type of request is included * number of virus scanners being used then slow but sure MS will begin to get slower and slower when processing the mail queue. IMHO lets leave MS to do what it it does well, and let us create the fancy reports :) Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From uxbod at splatnix.net Fri Aug 3 07:33:59 2007 From: uxbod at splatnix.net (UxBoD) Date: Fri Aug 3 07:27:40 2007 Subject: updated CRM114 training script. In-Reply-To: <46B27306.1080401@fractalweb.com> Message-ID: <32076139.10641186122839256.JavaMail.root@office.splatnix.net> Perhaps a question for the CRM114 mailing list Chris ;) All I know is that it works :) Though, remember it does have multiple algorithms and the Hyperspace one appears to get good results aswell. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From uxbod at splatnix.net Fri Aug 3 07:37:52 2007 From: uxbod at splatnix.net (UxBoD) Date: Fri Aug 3 07:31:32 2007 Subject: CRM114 How are you finding it ? In-Reply-To: <46B21DC0.1070603@fractalweb.com> Message-ID: <20217261.10671186123072159.JavaMail.root@office.splatnix.net> Well ours have been running for a good 18 hours now and I am very pleased with the results. Using CRM has tipped a lot of messages that would not have been marked as SPAM over the SA score threshold. Very impressed. Msg:AB1D67D1052.7DA6B Total Score:7.603 CRM114: 0.99 Without CRM114: 6.613 *** Msg:2F7E37D1054.26F5C Total Score:7.448 CRM114: 1.74 Without CRM114: 5.708 *** Msg:0C5BF7D1063.38163 Total Score:7.603 CRM114: 0.99 Without CRM114: 6.613 *** Msg:A5D417D1054.A5466 Total Score:7.603 CRM114: 0.99 Without CRM114: 6.613 *** Msg:B743A7D1060.41A63 Total Score:7.275 CRM114: 0.87 Without CRM114: 6.405 *** Msg:5F5297D105E.C9D42 Total Score:7.603 CRM114: 0.99 Without CRM114: 6.613 *** Msg:1C8907D0E8A.04B46 Total Score:8.542 CRM114: 1.66 Without CRM114: 6.882 *** Msg:E75C47D1054.13B07 Total Score:7.603 CRM114: 0.99 Without CRM114: 6.613 *** Msg:95F577D1054.E4449 Total Score:7.509 CRM114: 0.96 Without CRM114: 6.549 *** Msg:B27F37CFBE8.F1E04 Total Score:8.462 CRM114: 1.68 Without CRM114: 6.782 *** Msg:3C4457CF9E5.7337E Total Score:7.356 CRM114: 0.78 Without CRM114: 6.576 *** Msg:AA5517CF9E1.CA98D Total Score:7.356 CRM114: 0.78 Without CRM114: 6.576 *** Msg:8D81A7D1052.200EF Total Score:7.298 CRM114: 0.79 Without CRM114: 6.508 *** Msg:C618F7D02E3.407C4 Total Score:7.356 CRM114: 0.78 Without CRM114: 6.576 *** Msg:B1A617D1051.4E364 Total Score:7.96 CRM114: 1.81 Without CRM114: 6.15 *** Msg:EA08E7CF9E1.E1268 Total Score:7.483 CRM114: 1.68 Without CRM114: 5.803 *** Msg:9DA387CF9E5.987DB Total Score:8.065 CRM114: 1.66 Without CRM114: 6.405 *** Msg:253D17D02E3.E7E89 Total Score:7.877 CRM114: 0.90 Without CRM114: 6.977 *** Msg:EA55D7D105F.EF0D8 Total Score:7.302 CRM114: 0.61 Without CRM114: 6.692 *** Msg:F30327CF9E1.E6803 Total Score:7.463 CRM114: 1.78 Without CRM114: 5.683 *** Msg:4426A7CF229.B2403 Total Score:7.356 CRM114: 0.78 Without CRM114: 6.576 *** Msg:AE6F87CF229.BDAEB Total Score:7.684 CRM114: 0.71 Without CRM114: 6.974 *** Msg:F130B7CF9E1.35CA4 Total Score:7.685 CRM114: 0.78 Without CRM114: 6.905 *** Msg:943627CF9E1.CF091 Total Score:7.356 CRM114: 0.78 Without CRM114: 6.576 *** Msg:6B94D7CF229.62869 Total Score:7.356 CRM114: 0.78 Without CRM114: 6.576 *** Msg:B88F97CF415.5C697 Total Score:7.341 CRM114: 1.61 Without CRM114: 5.731 *** Msg:A9E937CF9E1.82931 Total Score:7.68 CRM114: 0.96 Without CRM114: 6.72 *** Msg:9CA137CF9E1.E262D Total Score:7.485 CRM114: 1.18 Without CRM114: 6.305 *** Msg:0CB967CF415.24D82 Total Score:7.205 CRM114: 1.63 Without CRM114: 5.575 *** Msg:6ADBD7CFBE8.F3ADA Total Score:7.492 CRM114: 0.72 Without CRM114: 6.772 *** Msg:C892B7CF415.DC8E9 Total Score:7.501 CRM114: 0.92 Without CRM114: 6.581 *** Msg:284407CF415.F1F44 Total Score:8.181 CRM114: 1.80 Without CRM114: 6.381 *** Msg:E07BE7CF415.05A28 Total Score:7.501 CRM114: 0.92 Without CRM114: 6.581 *** Msg:290F67CF415.34303 Total Score:7.132 CRM114: 0.86 Without CRM114: 6.272 *** Msg:695DB7D02E3.B4E24 Total Score:7.272 CRM114: 0.85 Without CRM114: 6.422 *** Msg:1D6667D103B.82CD3 Total Score:7.388 CRM114: 0.83 Without CRM114: 6.558 *** Msg:AB5E67D0E8A.5D5C3 Total Score:8.679 CRM114: 1.77 Without CRM114: 6.909 *** Msg:CC1E77D02E3.C9E09 Total Score:7.471 CRM114: 0.86 Without CRM114: 6.611 *** Msg:7AADE7D02E3.8389E Total Score:8.21 CRM114: 1.66 Without CRM114: 6.55 *** Msg:CC86B7CF229.9347D Total Score:7.772 CRM114: 1.03 Without CRM114: 6.742 *** Msg:F34FF7CF229.03948 Total Score:7.305 CRM114: 0.97 Without CRM114: 6.335 *** Msg:1B3797CF9E5.CA60A Total Score:7.62 CRM114: 0.88 Without CRM114: 6.74 *** Msg:064FD7CFBE8.78095 Total Score:7.419 CRM114: 0.92 Without CRM114: 6.499 *** Msg:52D037D103B.81D71 Total Score:7.342 CRM114: 0.94 Without CRM114: 6.402 *** Msg:66BCA7D02E3.E2406 Total Score:8.423 CRM114: 1.64 Without CRM114: 6.783 *** Msg:AEBA37CFCA6.06BB8 Total Score:8.029 CRM114: 1.49 Without CRM114: 6.539 *** Msg:858097CFBE8.13C31 Total Score:7.143 CRM114: 0.68 Without CRM114: 6.463 *** Msg:409AB7CF415.90A60 Total Score:7.143 CRM114: 0.68 Without CRM114: 6.463 *** Msg:D9E3D7CF9E5.CBDA0 Total Score:7.969 CRM114: 1.52 Without CRM114: 6.449 *** Msg:620417CF9E5.1C7FF Total Score:8.447 CRM114: 1.50 Without CRM114: 6.947 *** Msg:46B007D0F74.73156 Total Score:8.025 CRM114: 1.68 Without CRM114: 6.345 *** Msg:BC9607D103C.757DE Total Score:7.24 CRM114: 0.87 Without CRM114: 6.37 *** Msg:123417D0F74.A1185 Total Score:7.347 CRM114: 0.96 Without CRM114: 6.387 *** Msg:0BC247CF9E1.188E7 Total Score:8.505 CRM114: 1.81 Without CRM114: 6.695 *** Msg:2D0FA7CF9E1.73AB9 Total Score:7.347 CRM114: 0.96 Without CRM114: 6.387 *** Msg:C6D137CF9E1.060E9 Total Score:7.347 CRM114: 0.96 Without CRM114: 6.387 *** Msg:616317D0E8A.7E11A Total Score:7.347 CRM114: 0.96 Without CRM114: 6.387 *** Msg:C987A7D02E3.22298 Total Score:7.347 CRM114: 0.96 Without CRM114: 6.387 *** Msg:93CCB7CF9E1.D5F7A Total Score:7.34 CRM114: 0.93 Without CRM114: 6.41 *** Msg:9651A7CF9E1.AA4AB Total Score:7.059 CRM114: 0.85 Without CRM114: 6.209 *** Msg:AA3057CFCA6.DA191 Total Score:7.191 CRM114: 0.70 Without CRM114: 6.491 *** Msg:43D727CF9E5.06307 Total Score:7.438 CRM114: 1.50 Without CRM114: 5.938 *** Msg:F1EF37CF9E1.C2A19 Total Score:7.353 CRM114: 1.64 Without CRM114: 5.713 *** Msg:DB8827CF9E1.035C9 Total Score:7.519 CRM114: 0.83 Without CRM114: 6.689 *** Msg:5EB1B7D0E8A.A96BC Total Score:8.49 CRM114: 1.50 Without CRM114: 6.99 *** Msg:21A6F7CFCA6.53761 Total Score:8.033 CRM114: 1.64 Without CRM114: 6.393 *** Msg:6E5927D02E3.479C9 Total Score:7.346 CRM114: 0.99 Without CRM114: 6.356 *** Msg:4D41F7CF9E5.154C4 Total Score:7.063 CRM114: 0.91 Without CRM114: 6.153 *** Msg:BD72E7CF9E5.1B068 Total Score:7.685 CRM114: 0.72 Without CRM114: 6.965 *** Msg:766F97CF9E5.4E6BA Total Score:7.49 CRM114: 0.70 Without CRM114: 6.79 *** Msg:B69F07D02E3.1F9E6 Total Score:7.599 CRM114: 1.81 Without CRM114: 5.789 *** Msg:820E87D0E8A.30704 Total Score:7.063 CRM114: 0.91 Without CRM114: 6.153 *** Msg:DDB617CF9E5.81892 Total Score:7.592 CRM114: 0.90 Without CRM114: 6.692 *** Msg:8964F7CF9E5.F03CD Total Score:7.062 CRM114: 0.90 Without CRM114: 6.162 *** Msg:AE6137CF9E5.88C6A Total Score:7.501 CRM114: 0.82 Without CRM114: 6.681 *** Msg:B7DD07CF9E5.03A41 Total Score:7.063 CRM114: 0.91 Without CRM114: 6.153 *** Msg:087127D0E8A.C972E Total Score:7.094 CRM114: 0.97 Without CRM114: 6.124 *** Msg:3B3E07CFCA6.57EE7 Total Score:7.49 CRM114: 0.70 Without CRM114: 6.79 *** Msg:F18947CFBE8.CCC68 Total Score:8.202 CRM114: 1.81 Without CRM114: 6.392 *** Msg:1B5CD7CFCA6.D39B6 Total Score:7.344 CRM114: 1.59 Without CRM114: 5.754 *** Msg:8BDA07D0FF0.45490 Total Score:7.65 CRM114: 1.03 Without CRM114: 6.62 *** Msg:9735B7CFCA6.B6340 Total Score:7.787 CRM114: 1.65 Without CRM114: 6.137 *** Total Messages: 7496 How many times was CRM114 wrong? False Negative: 0 (0%) False Positive: 82 (1.09%) Total Errors: 82 (1.09%) How many times did CRM114 cause an error? False Negative: 0 (0%) False Positive: 82 (1.09%) Total Errors: 82 (1.09%) And yes, I have checked all 82 messages ! :) This is with a factor of -0.2 Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From martinh at solidstatelogic.com Fri Aug 3 08:20:49 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Fri Aug 3 08:21:02 2007 Subject: pdfassassin In-Reply-To: Message-ID: Won't help with the latest incarnation, zipped excel files! -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Douglas Ward > Sent: 02 August 2007 17:58 > To: MailScanner discussion > Subject: pdfassassin > > http://freshmeat.net/projects/pdfassassin/ > > Looks interesting. Has anyone given this a look? ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From glenn.steen at gmail.com Fri Aug 3 08:49:02 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Aug 3 08:49:04 2007 Subject: Upgrading Minor versions In-Reply-To: References: <2579c6b20708021427w6521a719na27d657ffe7d6b6d@mail.gmail.com> Message-ID: <223f97700708030049m695c6a91laa44c2df243b20f4@mail.gmail.com> On 03/08/07, Res wrote: > Hi Kai, > > On Fri, 3 Aug 2007, Kai Schaetzl wrote: > > > Eugene MacDougal wrote on Thu, 2 Aug 2007 16:27:50 -0500: > > > >> Is there some way to make the installer check to see if its about to overwrite files? > > > > Eugene, it normally doesn't overwrite existing config files, not on major, not on minor > > version changes. Can you provide more details? > > Yes, on source versions, its happened to me before, thankfully its > all under /opt and backed up nightly anyway, even on dummy test machines > :) > > This is why I mentioned a couple of days ago about bringing it into line > with most other software versioning, major.minor.beta_number as in > 4.63.b1, 4.63.b2 etc reaching the official release as 4.63 (as only 4.63) > major. MailScanners installer does not understand at all 4.63.3-5 only > 4.63.3, thereby over-writting. As Julian ignored my comments I dare say he > has no intention of changing it, as no one else commented, it seems most > are happy with it, and I also gather after years of observations 95% of > people here use RPM base OS's so they may not be affected by the > installers tarball shortfall. > In the RPM case the - isn't really part of the packaged software version number... it is more considered to be a package revision number. Indeed, RPM (and other packagers) will take note of that difference and act accordingly/safely. So perhaps it is the "tarball install method" that need be amended, more than the actual numbering scheme... Or one could make it a documentation thing... Prominently (on the download page) warn to make a cakcup of the /opt/MailScanner<.whatever> directory prior to unpacking/installing the tarball. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From Q.G.Campbell at newcastle.ac.uk Fri Aug 3 08:47:09 2007 From: Q.G.Campbell at newcastle.ac.uk (Quentin Campbell) Date: Fri Aug 3 08:49:31 2007 Subject: The new watermarking feature in 4.62 - an unexpected side effect? Message-ID: <4165CF7A7F12DE4B96622CCBB90586470B125A14@largo.campus.ncl.ac.uk> Julian Am running 4.62.9-2 on 8 gateways with the new watermarking feature enabled. It has given rise to an increase in requests to "whitelist" addresses of messages that are being tagged. The messages in question have a blank 'From:' address following the "Our MailScanner believes that the attachment to this message sent to you..." rubric. On inspection these messages are almost always 'vacation' or OoO messages. It seems that there are good operational reasons for these sorts of auto responders to set the envelope-sender address to be null. However this causes them to be tagged as spam by MailScanner if watermarking is enabled. I don't consider it appropriate to whitelist addresses in this situation but they are 'genuine' messages nonethelees and may well be missed if people are filtering into a 'junk mail' folder on the tag. I can't see a way around this. I note, however, that JANET in its latest guidance on avoiding inappropriate e-mail bounces (April 2007) - http://www.ja.net/cert/email/dontbounce.html - deprecate the use of vacation/OoO so perhaps we will see the use of OoO responders reduce in future? Quentin --- PHONE: +44 191 222 8209??? Information Systems and Services (ISS), ?????????????????????????? Newcastle University, ?????????????????????????? Newcastle upon Tyne, FAX:?? +44 191 222 8765??? United Kingdom, NE1 7RU. ------------------------------------------------------------------------ From glenn.steen at gmail.com Fri Aug 3 08:56:42 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Aug 3 08:56:44 2007 Subject: Using ClamAV to find spam In-Reply-To: <46B26428.9060607@eltofts.homelinux.com> References: <46B25DE7.8020904@eltofts.homelinux.com> <7EF1F27F7292534D82933F70AB6996CC25CE45@pro-ak-exch01.hosted.pronet.net.nz> <46B26428.9060607@eltofts.homelinux.com> Message-ID: <223f97700708030056j5e541d9cp45f6810a5bcfe007@mail.gmail.com> On 03/08/07, Andy Wright wrote: (snip) > thanks for the suggestion, although I'm reluctant to add yet more > plugins - most of the spams are already being scored at 20+ (how high > does this have to get before virus scanning is skipped?) Set "Keep Spam And MCP Archive Clean" to "no" and see if that does what you want... You'll need keep an eye on things when released, since most have whitelisted localhost (more or less completely) to be able to release at all... Might get ugly if the users can release things (perhaps from MailWatch) themselves. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From martinh at solidstatelogic.com Fri Aug 3 08:57:02 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Fri Aug 3 08:57:09 2007 Subject: The new watermarking feature in 4.62 - an unexpected side effect? In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470B125A14@largo.campus.ncl.ac.uk> Message-ID: <2b2c68de43249c43bf76ad34cdbca67a@solidstatelogic.com> Quentin I do hope OoO responders die, they are a PITA. A lot of people here have started to used them again (now I've made it easy to do - d'oh) and it caused at least 1 email storm from a bad list. Personally I haven't used them for years - hmm lets see one of the senior IT guys is out, let attack the network... -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Quentin Campbell > Sent: 03 August 2007 08:47 > To: MailScanner discussion > Subject: The new watermarking feature in 4.62 - an unexpected side effect? > > Julian > > Am running 4.62.9-2 on 8 gateways with the new watermarking feature > enabled. > > It has given rise to an increase in requests to "whitelist" addresses of > messages that are being tagged. > > The messages in question have a blank 'From:' address following the "Our > MailScanner believes that the attachment to this message sent to you..." > rubric. > > On inspection these messages are almost always 'vacation' or OoO messages. > It seems that there are good operational reasons for these sorts of auto > responders to set the envelope-sender address to be null. However this > causes them to be tagged as spam by MailScanner if watermarking is > enabled. > > I don't consider it appropriate to whitelist addresses in this situation > but they are 'genuine' messages nonethelees and may well be missed if > people are filtering into a 'junk mail' folder on the tag. I can't see a > way around this. > > I note, however, that JANET in its latest guidance on avoiding > inappropriate e-mail bounces (April 2007) - > http://www.ja.net/cert/email/dontbounce.html - deprecate the use of > vacation/OoO so perhaps we will see the use of OoO responders reduce in > future? > > Quentin > --- > PHONE: +44 191 222 8209??? Information Systems and Services (ISS), > ?????????????????????????? Newcastle University, > ?????????????????????????? Newcastle upon Tyne, > FAX:?? +44 191 222 8765??? United Kingdom, NE1 7RU. > ------------------------------------------------------------------------ > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From glenn.steen at gmail.com Fri Aug 3 09:03:11 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Aug 3 09:03:13 2007 Subject: updated CRM114 training script. In-Reply-To: <46B27306.1080401@fractalweb.com> References: <1951DC816E1A9F469307B05FA183F4389DC9E0@corpatsmail1.corp.sensis.com> <46B0FBA0.6060601@coders.co.uk> <46B21DC0.1070603@fractalweb.com> <46B23297.7010206@fractalweb.com> <46B27306.1080401@fractalweb.com> Message-ID: <223f97700708030103i7ee683eesd18da5d39fbe2e08@mail.gmail.com> On 03/08/07, Chris Yuzik wrote: (snip) > Nothing like having a conversation with myself, not that it's unusual. So you're a closet Postfix user then? Good. Wellcome to the bunch:-) (snip) > Unfortunately, I don't understand why sometimes I feed it a message, > tell it that the message is spam and to force-learn it, then push it > through spamassassin again, and CRM114 responds with "unsure" and scores > it with -1.9. > > Any thoughts? I certainly haven't read up enough on how crm works, but I would guess that a negative "unsure" bias is far ebtter than a "positive sure SPAM" thing:-).Probably needs a bit more than just one factor saying it's good... So that one misstrained message doesn't skew everything to .... a bad place. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Fri Aug 3 09:06:38 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Aug 3 09:06:40 2007 Subject: CRM114 How are you finding it ? In-Reply-To: <20217261.10671186123072159.JavaMail.root@office.splatnix.net> References: <46B21DC0.1070603@fractalweb.com> <20217261.10671186123072159.JavaMail.root@office.splatnix.net> Message-ID: <223f97700708030106j7403d897u30ee16d5590e4130@mail.gmail.com> On 03/08/07, UxBoD wrote: > Well ours have been running for a good 18 hours now and I am very pleased with the results. Using CRM has tipped a lot of messages that would not have been marked as SPAM over the SA score threshold. Very impressed. > (snip) What scaling factor do you use for the dynamic scores? I saw pretty .-.. wild ... scoring with the default -0.05 ... Might be because of the nature of my mailflow.... being in the financial sector:-) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From P.G.M.Peters at utwente.nl Fri Aug 3 09:13:31 2007 From: P.G.M.Peters at utwente.nl (Peter Peters) Date: Fri Aug 3 09:13:35 2007 Subject: The new watermarking feature in 4.62 - an unexpected side effect? In-Reply-To: <2b2c68de43249c43bf76ad34cdbca67a@solidstatelogic.com> References: <2b2c68de43249c43bf76ad34cdbca67a@solidstatelogic.com> Message-ID: <46B2E3AB.1010707@utwente.nl> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Martin.Hepworth wrote on 3-8-2007 9:57: > Quentin > > I do hope OoO responders die, they are a PITA. A lot of people here > have started to used them again (now I've made it easy to do - d'oh) > and it caused at least 1 email storm from a bad list. The queue on our outgoing servers always grows 10-fold during holiday seasons. And that are only OoO's that are destined to addresses at unreachable mailservers. I can't imagine how many get through. - -- Peter Peters, senior beheerder (Security) Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE) Universiteit Twente, Postbus 217, 7500 AE Enschede telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFGsuOrelLo80lrIdIRAv9qAJ9Eckhmyf/9EJLxtpY5u+SUZUoIGACeKBqs LvOAEJMoqHR17OSBWVMwyT8= =h7KI -----END PGP SIGNATURE----- From uxbod at splatnix.net Fri Aug 3 09:20:42 2007 From: uxbod at splatnix.net (UxBoD) Date: Fri Aug 3 09:14:22 2007 Subject: The new watermarking feature in 4.62 - an unexpected side effect? In-Reply-To: <2b2c68de43249c43bf76ad34cdbca67a@solidstatelogic.com> Message-ID: <33089163.10821186129242896.JavaMail.root@office.splatnix.net> Perhaps instead of marking as Spam straight off a score could be applied instead ? That may be a solution ?? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Martin.Hepworth" To: "MailScanner discussion" Sent: Friday, August 3, 2007 8:57:02 AM (GMT) Europe/London Subject: RE: The new watermarking feature in 4.62 - an unexpected side effect? Quentin I do hope OoO responders die, they are a PITA. A lot of people here have started to used them again (now I've made it easy to do - d'oh) and it caused at least 1 email storm from a bad list. Personally I haven't used them for years - hmm lets see one of the senior IT guys is out, let attack the network... -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Quentin Campbell > Sent: 03 August 2007 08:47 > To: MailScanner discussion > Subject: The new watermarking feature in 4.62 - an unexpected side effect? > > Julian > > Am running 4.62.9-2 on 8 gateways with the new watermarking feature > enabled. > > It has given rise to an increase in requests to "whitelist" addresses of > messages that are being tagged. > > The messages in question have a blank 'From:' address following the "Our > MailScanner believes that the attachment to this message sent to you..." > rubric. > > On inspection these messages are almost always 'vacation' or OoO messages. > It seems that there are good operational reasons for these sorts of auto > responders to set the envelope-sender address to be null. However this > causes them to be tagged as spam by MailScanner if watermarking is > enabled. > > I don't consider it appropriate to whitelist addresses in this situation > but they are 'genuine' messages nonethelees and may well be missed if > people are filtering into a 'junk mail' folder on the tag. I can't see a > way around this. > > I note, however, that JANET in its latest guidance on avoiding > inappropriate e-mail bounces (April 2007) - > http://www.ja.net/cert/email/dontbounce.html - deprecate the use of > vacation/OoO so perhaps we will see the use of OoO responders reduce in > future? > > Quentin > --- > PHONE: +44 191 222 8209 Information Systems and Services (ISS), > Newcastle University, > Newcastle upon Tyne, > FAX: +44 191 222 8765 United Kingdom, NE1 7RU. > ------------------------------------------------------------------------ > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From uxbod at splatnix.net Fri Aug 3 09:26:44 2007 From: uxbod at splatnix.net (UxBoD) Date: Fri Aug 3 09:20:24 2007 Subject: CRM114 How are you finding it ? In-Reply-To: <223f97700708030106j7403d897u30ee16d5590e4130@mail.gmail.com> Message-ID: <19991711.10851186129604390.JavaMail.root@office.splatnix.net> -0.2 Glenn. Note from crm114.cf :- the absolute value should be quite low (certainly <.3, probably <=.2) Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Glenn Steen" To: "MailScanner discussion" Sent: Friday, August 3, 2007 9:06:38 AM (GMT) Europe/London Subject: Re: CRM114 How are you finding it ? On 03/08/07, UxBoD wrote: > Well ours have been running for a good 18 hours now and I am very pleased with the results. Using CRM has tipped a lot of messages that would not have been marked as SPAM over the SA score threshold. Very impressed. > (snip) What scaling factor do you use for the dynamic scores? I saw pretty .-.. wild ... scoring with the default -0.05 ... Might be because of the nature of my mailflow.... being in the financial sector:-) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From wjohns at balita.ph Fri Aug 3 09:52:48 2007 From: wjohns at balita.ph (Wayne) Date: Fri Aug 3 09:52:49 2007 Subject: Error after upgrade Message-ID: <200708030852.l738qkTp030708@balita.ph> Hi I upgraded MailScanner and Spamassassin yesterday to 4.62 and 3.2.2 (from Clamav SA package). Previously the package ran without problems however I am getting this error. (show below) Line 396 (first part of the error) seems to contradict or even make sense to me - what needs altering What plugin is missing from the second part? Because of the error MS runs in a loop. Afraid I am not highly expert on MS/SA I can install but get lost when it throws errors like this. Anyones help would be appreciated. - Wayne - I started MailScanner in debug mode:- In Debugging mode, not forking... SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp config: 'rbl_timeout' is obsolete, use 'rbl_timeout' instead at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Plugin/URIDNSBL.pm line 396. check: no loaded plugin implements 'check_main': cannot scan! at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/PerMsgStatus.pm line 164. From prandal at herefordshire.gov.uk Fri Aug 3 09:53:46 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Fri Aug 3 09:53:56 2007 Subject: CRM114 How are you finding it ? In-Reply-To: <223f97700708030106j7403d897u30ee16d5590e4130@mail.gmail.com> References: <46B21DC0.1070603@fractalweb.com><20217261.10671186123072159.JavaMail.root@office.splatnix.net> <223f97700708030106j7403d897u30ee16d5590e4130@mail.gmail.com> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA01510DCC@HC-MBX02.herefordshire.gov.uk> Actually, the documentation in the readme is not clear, but the default is NOT -0.05. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Glenn Steen > Sent: 03 August 2007 09:07 > To: MailScanner discussion > Subject: Re: CRM114 How are you finding it ? > > On 03/08/07, UxBoD wrote: > > Well ours have been running for a good 18 hours now and I > am very pleased with the results. Using CRM has tipped a lot > of messages that would not have been marked as SPAM over the > SA score threshold. Very impressed. > > > (snip) > What scaling factor do you use for the dynamic scores? > I saw pretty .-.. wild ... scoring with the default -0.05 ... > Might be because of the nature of my mailflow.... being in the > financial sector:-) > > Cheers > -- > -- Glenn > email: glenn < dot > steen < at > gmail < dot > com > work: glenn < dot > steen < at > ap1 < dot > se > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From ajcartmell at fonant.com Fri Aug 3 09:57:02 2007 From: ajcartmell at fonant.com (Anthony Cartmell) Date: Fri Aug 3 09:57:04 2007 Subject: Improved init.d script In-Reply-To: <46B216AD.1010204@ecs.soton.ac.uk> References: <46B216AD.1010204@ecs.soton.ac.uk> Message-ID: > Please let me know what you think of them, and if they work for you okay. Works nicely on Fedora Core 6 (with and without Xen-ified kernel). Cheers! Anthony -- www.fonant.com - Quality web sites From glenn.steen at gmail.com Fri Aug 3 10:19:31 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Aug 3 10:19:32 2007 Subject: CRM114 How are you finding it ? In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA01510DCC@HC-MBX02.herefordshire.gov.uk> References: <46B21DC0.1070603@fractalweb.com> <20217261.10671186123072159.JavaMail.root@office.splatnix.net> <223f97700708030106j7403d897u30ee16d5590e4130@mail.gmail.com> <7EF0EE5CB3B263488C8C18823239BEBA01510DCC@HC-MBX02.herefordshire.gov.uk> Message-ID: <223f97700708030219t436142f8ufe6d4bed9d3978e8@mail.gmail.com> On 03/08/07, Randal, Phil wrote: > Actually, the documentation in the readme is not clear, but the default > is NOT -0.05. > Oh really? The file the install plopped into place could've fooled me... ----- # dynamic score normalization factor # CRM score have much higher absolute values and different signs than SA scores # (usual ham-scores are between 15 and 40, scores from -10 to 10 are undecided, # previously seen spam easily gets -200). # With dynamic scoring the SA score is calculated by: * crm114_dynsc ore_factor # # Notes: - this has to be a negative number! # - the absolute value should be quite low (certainly <.3, probably <=.2) , # otherwise the returned score would override all other tests. # default: calculate factor so that CRM-score -25 yields the SA required spam th reshold crm114_dynscore_factor -0.05 ----- So ... as a score "normalizer" and "sign changer" .... I do believe I'm correct in stating that this is a "default" (very ... relative... term that;-). So... If one don't want to have crm114 as the "sole deciding factor", but rather as just another "score contributor"... I'd say the -0.005 would be reasonable... -0.2 would potentially give very high values. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From prandal at herefordshire.gov.uk Fri Aug 3 10:25:44 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Fri Aug 3 10:25:55 2007 Subject: CRM114 How are you finding it ? In-Reply-To: <223f97700708030219t436142f8ufe6d4bed9d3978e8@mail.gmail.com> References: <46B21DC0.1070603@fractalweb.com><20217261.10671186123072159.JavaMail.root@office.splatnix.net><223f97700708030106j7403d897u30ee16d5590e4130@mail.gmail.com><7EF0EE5CB3B263488C8C18823239BEBA01510DCC@HC-MBX02.herefordshire.gov.uk> <223f97700708030219t436142f8ufe6d4bed9d3978e8@mail.gmail.com> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA01510DDD@HC-MBX02.herefordshire.gov.uk> In mine it was #crm114_dynscore_factor -0.05 And when I removed the # the scores went down dramatically. Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Glenn Steen > Sent: 03 August 2007 10:20 > To: MailScanner discussion > Subject: Re: CRM114 How are you finding it ? > > On 03/08/07, Randal, Phil wrote: > > Actually, the documentation in the readme is not clear, but > the default > > is NOT -0.05. > > > Oh really? The file the install plopped into place could've > fooled me... > ----- > # dynamic score normalization factor > # CRM score have much higher absolute values and different > signs than SA scores > # (usual ham-scores are between 15 and 40, scores from -10 to > 10 are undecided, > # previously seen spam easily gets -200). > # With dynamic scoring the SA score is calculated by: score> * crm114_dynsc > ore_factor > # > # Notes: - this has to be a negative number! > # - the absolute value should be quite low (certainly > <.3, probably <=.2) > , > # otherwise the returned score would override all > other tests. > # default: calculate factor so that CRM-score -25 yields the > SA required spam th > reshold > crm114_dynscore_factor -0.05 > ----- > So ... as a score "normalizer" and "sign changer" .... I do believe > I'm correct in stating that this is a "default" (very ... relative... > term that;-). > > So... If one don't want to have crm114 as the "sole deciding factor", > but rather as just another "score contributor"... I'd say the -0.005 > would be reasonable... -0.2 would potentially give very high values. > > Cheers > -- > -- Glenn > email: glenn < dot > steen < at > gmail < dot > com > work: glenn < dot > steen < at > ap1 < dot > se > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From mikael at syska.dk Fri Aug 3 10:28:52 2007 From: mikael at syska.dk (mikael@syska.dk) Date: Fri Aug 3 10:29:02 2007 Subject: Special rules for archives Message-ID: <53675.80.63.34.182.1186133332.squirrel@mail.syska.dk> Hi, How can I allow a special rulesset for archives and a other for files directly attached to the mail itself .... filename.rules.conf and filetypes.rules.conf We have some users that recieves exe files and we want to allow this if they are attached as archives ... but ofcause we still want to scan for viruses ... best regards Mikael Syska From res at ausics.net Fri Aug 3 10:49:10 2007 From: res at ausics.net (Res) Date: Fri Aug 3 10:49:20 2007 Subject: Upgrading Minor versions In-Reply-To: <223f97700708030049m695c6a91laa44c2df243b20f4@mail.gmail.com> References: <2579c6b20708021427w6521a719na27d657ffe7d6b6d@mail.gmail.com> <223f97700708030049m695c6a91laa44c2df243b20f4@mail.gmail.com> Message-ID: On Fri, 3 Aug 2007, Glenn Steen wrote: >> This is why I mentioned a couple of days ago about bringing it into line >> with most other software versioning, major.minor.beta_number as in >> 4.63.b1, 4.63.b2 etc reaching the official release as 4.63 (as only 4.63) >> major. MailScanners installer does not understand at all 4.63.3-5 only >> 4.63.3, thereby over-writting. As Julian ignored my comments I dare say he >> has no intention of changing it, as no one else commented, it seems most >> are happy with it, and I also gather after years of observations 95% of >> people here use RPM base OS's so they may not be affected by the >> installers tarball shortfall. >> > In the RPM case the - isn't really part of the packaged > software version number... it is more considered to be a package > revision number. Indeed, RPM (and other packagers) will take note of > that difference and act accordingly/safely. > So perhaps it is the "tarball install method" that need be amended, > more than the actual numbering scheme... Or one could make it a > documentation thing... Prominently (on the download page) warn to make > a cakcup of the /opt/MailScanner<.whatever> directory prior to > unpacking/installing the tarball. Yes, but wouldn't it make more sense to use the unified versioning method that everyone around the entire world is acustomed to? -- Cheers Res From res at ausics.net Fri Aug 3 10:52:02 2007 From: res at ausics.net (Res) Date: Fri Aug 3 10:52:11 2007 Subject: The new watermarking feature in 4.62 - an unexpected side effect? In-Reply-To: <2b2c68de43249c43bf76ad34cdbca67a@solidstatelogic.com> References: <2b2c68de43249c43bf76ad34cdbca67a@solidstatelogic.com> Message-ID: On Fri, 3 Aug 2007, Martin.Hepworth wrote: > Quentin > > I do hope OoO responders die, they are a PITA. A lot of people here have started to used them again (now I've made it easy to do - d'oh) and it caused at least 1 email storm from a bad list. > > Personally I haven't used them for years - hmm lets see one of the senior IT guys is out, let attack the network... We should set reply to postmaster@ :) Oh wait, these lamers tend to use M$ crap and wouldnt know what a postmaster is, so pointless... -- Cheers Res From glenn.steen at gmail.com Fri Aug 3 10:59:28 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Aug 3 10:59:29 2007 Subject: CRM114 How are you finding it ? In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA01510DDD@HC-MBX02.herefordshire.gov.uk> References: <46B21DC0.1070603@fractalweb.com> <20217261.10671186123072159.JavaMail.root@office.splatnix.net> <223f97700708030106j7403d897u30ee16d5590e4130@mail.gmail.com> <7EF0EE5CB3B263488C8C18823239BEBA01510DCC@HC-MBX02.herefordshire.gov.uk> <223f97700708030219t436142f8ufe6d4bed9d3978e8@mail.gmail.com> <7EF0EE5CB3B263488C8C18823239BEBA01510DDD@HC-MBX02.herefordshire.gov.uk> Message-ID: <223f97700708030259p44e038f2t9309e8511d1db32c@mail.gmail.com> On 03/08/07, Randal, Phil wrote: > In mine it was > > #crm114_dynscore_factor -0.05 > > And when I removed the # the scores went down dramatically. > Quite correct. The default (from crm114.pm) is my $default_crm114_dynscore_factor = $conf->{required_score} / -25; ... which aims at calculating a normalizer value that would put a CRM score of (-)25 at your required SA spam score... I think this might not be the best of things, since the values can fluctuate quite a bit more than that, and I imagine most *don't* want CRM114 to be the sole deciding factor. Anyway, did you install according to the wiki page? If so, I obviously have made some changes that I've promptly forgot about(:-)... else the "default" in the crm114.cf file was what I mentioned. > Phil > > -- > Phil Randal > Network Engineer > Herefordshire Council > Hereford, UK > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > > Of Glenn Steen > > Sent: 03 August 2007 10:20 > > To: MailScanner discussion > > Subject: Re: CRM114 How are you finding it ? > > > > On 03/08/07, Randal, Phil wrote: > > > Actually, the documentation in the readme is not clear, but > > the default > > > is NOT -0.05. > > > > > Oh really? The file the install plopped into place could've > > fooled me... > > ----- > > # dynamic score normalization factor > > # CRM score have much higher absolute values and different > > signs than SA scores > > # (usual ham-scores are between 15 and 40, scores from -10 to > > 10 are undecided, > > # previously seen spam easily gets -200). > > # With dynamic scoring the SA score is calculated by: > score> * crm114_dynsc > > ore_factor > > # > > # Notes: - this has to be a negative number! > > # - the absolute value should be quite low (certainly > > <.3, probably <=.2) > > , > > # otherwise the returned score would override all > > other tests. > > # default: calculate factor so that CRM-score -25 yields the > > SA required spam th > > reshold > > crm114_dynscore_factor -0.05 > > ----- > > So ... as a score "normalizer" and "sign changer" .... I do believe > > I'm correct in stating that this is a "default" (very ... relative... > > term that;-). > > > > So... If one don't want to have crm114 as the "sole deciding factor", > > but rather as just another "score contributor"... I'd say the -0.005 > > would be reasonable... -0.2 would potentially give very high values. > > > > Cheers Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Fri Aug 3 11:08:01 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Aug 3 11:08:02 2007 Subject: Upgrading Minor versions In-Reply-To: References: <2579c6b20708021427w6521a719na27d657ffe7d6b6d@mail.gmail.com> <223f97700708030049m695c6a91laa44c2df243b20f4@mail.gmail.com> Message-ID: <223f97700708030308n4d0c57d3j360e7283a9def359@mail.gmail.com> On 03/08/07, Res wrote: > On Fri, 3 Aug 2007, Glenn Steen wrote: > > >> This is why I mentioned a couple of days ago about bringing it into line > >> with most other software versioning, major.minor.beta_number as in > >> 4.63.b1, 4.63.b2 etc reaching the official release as 4.63 (as only 4.63) > >> major. MailScanners installer does not understand at all 4.63.3-5 only > >> 4.63.3, thereby over-writting. As Julian ignored my comments I dare say he > >> has no intention of changing it, as no one else commented, it seems most > >> are happy with it, and I also gather after years of observations 95% of > >> people here use RPM base OS's so they may not be affected by the > >> installers tarball shortfall. > >> > > In the RPM case the - isn't really part of the packaged > > software version number... it is more considered to be a package > > revision number. Indeed, RPM (and other packagers) will take note of > > that difference and act accordingly/safely. > > So perhaps it is the "tarball install method" that need be amended, > > more than the actual numbering scheme... Or one could make it a > > documentation thing... Prominently (on the download page) warn to make > > a cakcup of the /opt/MailScanner<.whatever> directory prior to > > unpacking/installing the tarball. > > Yes, but wouldn't it make more sense to use the unified versioning method > that everyone around the entire world is acustomed to? > That scheme was dreamed up in the linux kernel dev... and (perhaps... It was not always so:-) suits them very well. And it has spilled over on a lot of projects. But it is hardly the one true unified version numbering method about. And it's not sure to cure anything like this, where _packaging versions_, not software versions, handling is the real issue. We/Jules will just have to think of some more or less clever way of handling it. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From MailScanner at ecs.soton.ac.uk Fri Aug 3 11:19:14 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 3 11:19:48 2007 Subject: Special rules for archives In-Reply-To: <53675.80.63.34.182.1186133332.squirrel@mail.syska.dk> References: <53675.80.63.34.182.1186133332.squirrel@mail.syska.dk> Message-ID: <46B30122.4030606@ecs.soton.ac.uk> The "Maximum Archive Depth" setting has no effect on virus-scanning, as I believe the docs mention. So you can set it to 0 quite safely. mikael@syska.dk wrote: > Hi, > > How can I allow a special rulesset for archives and a other for files > directly attached to the mail itself .... > > filename.rules.conf and filetypes.rules.conf > > We have some users that recieves exe files and we want to allow this if > they are attached as archives ... but ofcause we still want to scan for > viruses ... > > best regards > Mikael Syska > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Fri Aug 3 11:25:26 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 3 11:25:49 2007 Subject: MailScanner --lint error--SOLVED In-Reply-To: References: Message-ID: <46B30296.8020203@ecs.soton.ac.uk> Scott Silva wrote: > Scott Silva spake the following on 8/2/2007 2:08 PM: > >> I am getting the following error on my boxes; >> ERROR: The "envelope_sender_header" in your spam.assassin.prefs.conf >> ERROR: is not correct, it should match X-BlaBla-MailScanner-From >> >> But I have the exact text it is looking for in spam.assassin.prefs.conf >> Obviously BlaBla is not the organization name. >> I tried with an = between envelope_sender_header and the header text and >> without the =. >> I only changed it because it recommended I have %orgname% in the envelope from >> and to headers. >> So it is nagging me to change it, and then complains when I do. Did I suddenly >> get married this thing? >> >> > I found the problem -- there can be only 1 space between > envelope_sender_header and the header text. I had 2 spaces and the parser must > think the extra space is part of the header text. > I just tried adding some extra spaces in my envelope_sender_header line and it correctly ignored them. Wonder why it didn't work for you, the regex uses a \s+ to match the required space in the line. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From mikael at syska.dk Fri Aug 3 11:26:17 2007 From: mikael at syska.dk (mikael@syska.dk) Date: Fri Aug 3 11:26:27 2007 Subject: Special rules for archives In-Reply-To: <46B30122.4030606@ecs.soton.ac.uk> References: <53675.80.63.34.182.1186133332.squirrel@mail.syska.dk> <46B30122.4030606@ecs.soton.ac.uk> Message-ID: <61266.80.63.34.182.1186136777.squirrel@mail.syska.dk> Hey, Will just test that setting ... but what if I still want to block some file extensions in the archive ? with the filenames and filetypes rules ? // ouT > The "Maximum Archive Depth" setting has no effect on virus-scanning, as > I believe the docs mention. So you can set it to 0 quite safely. > > mikael@syska.dk wrote: >> Hi, >> >> How can I allow a special rulesset for archives and a other for files >> directly attached to the mail itself .... >> >> filename.rules.conf and filetypes.rules.conf >> >> We have some users that recieves exe files and we want to allow this if >> they are attached as archives ... but ofcause we still want to scan for >> viruses ... >> >> best regards >> Mikael Syska >> >> > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > Need help customising MailScanner? > Contact me! > Need help fixing or optimising your systems? > Contact me! > Need help getting you started solving new requirements from your boss? > Contact me! > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From res at ausics.net Fri Aug 3 11:29:29 2007 From: res at ausics.net (Res) Date: Fri Aug 3 11:29:37 2007 Subject: Upgrading Minor versions In-Reply-To: <223f97700708030308n4d0c57d3j360e7283a9def359@mail.gmail.com> References: <2579c6b20708021427w6521a719na27d657ffe7d6b6d@mail.gmail.com> <223f97700708030049m695c6a91laa44c2df243b20f4@mail.gmail.com> <223f97700708030308n4d0c57d3j360e7283a9def359@mail.gmail.com> Message-ID: On Fri, 3 Aug 2007, Glenn Steen wrote: > That scheme was dreamed up in the linux kernel dev... and (perhaps... > It was not always so:-) suits them very well. And it has spilled over > on a lot of projects. But it is hardly the one true unified version spilled over to just about 90% of the software around :) > And it's not sure to cure anything like this, where _packaging it would, as it would install to /opt as 4.63.b2 etc and not over write the existing 4.63 directory. > will just have to think of some more or less clever way of handling > it. and until such time, its probably going to be recommended those using tarball don't bother with such upgrades. -- Cheers Res From MailScanner at ecs.soton.ac.uk Fri Aug 3 11:42:43 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 3 11:42:59 2007 Subject: Upgrading Minor versions In-Reply-To: References: <2579c6b20708021427w6521a719na27d657ffe7d6b6d@mail.gmail.com> <223f97700708030049m695c6a91laa44c2df243b20f4@mail.gmail.com> <223f97700708030308n4d0c57d3j360e7283a9def359@mail.gmail.com> Message-ID: <46B306A3.40902@ecs.soton.ac.uk> Res wrote: > On Fri, 3 Aug 2007, Glenn Steen wrote: > >> That scheme was dreamed up in the linux kernel dev... and (perhaps... >> It was not always so:-) suits them very well. And it has spilled over >> on a lot of projects. But it is hardly the one true unified version > > spilled over to just about 90% of the software around :) > >> And it's not sure to cure anything like this, where _packaging > > it would, as it would install to /opt as 4.63.b2 etc and not over > write the existing 4.63 directory. > >> will just have to think of some more or less clever way of handling >> it. > > and until such time, its probably going to be recommended those using > tarball don't bother with such upgrades. > I don't need to completely rewrite my version numbering scheme or anything crazy like that. All I need is to add 4 characters to install.tar-fns.sh. Please try the attached patch. You will discover it adds the build number in the directory it creates for the new version of MailScanner you're installing. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -------------- next part -------------- A non-text attachment was scrubbed... Name: install.tar-fns.sh.patch.gz Type: application/x-gzip Size: 330 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070803/24f4a9f6/install.tar-fns.sh.patch.gz From gerard at seibercom.net Fri Aug 3 11:48:39 2007 From: gerard at seibercom.net (Gerard) Date: Fri Aug 3 11:48:38 2007 Subject: The new watermarking feature in 4.62 - an unexpected side effect? In-Reply-To: References: <2b2c68de43249c43bf76ad34cdbca67a@solidstatelogic.com> Message-ID: <20070803064521.852D.GERARD@seibercom.net> On August 03, 2007 at 05:52AM Res wrote: > On Fri, 3 Aug 2007, Martin.Hepworth wrote: > > > Quentin > > > > I do hope OoO responders die, they are a PITA. A lot of people here have started to used them again (now I've made it easy to do - d'oh) and it caused at least 1 email storm from a bad list. > > > > Personally I haven't used them for years - hmm lets see one of the senior IT guys is out, let attack the network... > > We should set reply to postmaster@ :) > Oh wait, these lamers tend to use M$ crap and wouldnt know what a > postmaster is, so pointless... Sorry, but that isn't limited to Microsoft applications either. Personally, I find that silently discarding such rubbish is the best solution. At least it is in my case. Creating additional backscatter is just pointless. -- Gerard From uxbod at splatnix.net Fri Aug 3 12:07:50 2007 From: uxbod at splatnix.net (UxBoD) Date: Fri Aug 3 12:01:23 2007 Subject: Error after upgrade In-Reply-To: <200708030852.l738qkTp030708@balita.ph> Message-ID: <30884165.10941186139270824.JavaMail.root@office.splatnix.net> Run a spamassassin -D --lint and post the output please. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Wayne" To: "MailScanner discussion" Sent: 03 August 2007 09:52:48 o'clock (GMT) Europe/London Subject: Error after upgrade Hi I upgraded MailScanner and Spamassassin yesterday to 4.62 and 3.2.2 (from Clamav SA package). Previously the package ran without problems however I am getting this error. (show below) Line 396 (first part of the error) seems to contradict or even make sense to me - what needs altering What plugin is missing from the second part? Because of the error MS runs in a loop. Afraid I am not highly expert on MS/SA I can install but get lost when it throws errors like this. Anyones help would be appreciated. - Wayne - I started MailScanner in debug mode:- In Debugging mode, not forking... SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp config: 'rbl_timeout' is obsolete, use 'rbl_timeout' instead at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Plugin/URIDNSBL.pm line 396. check: no loaded plugin implements 'check_main': cannot scan! at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/PerMsgStatus.pm line 164. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From glenn.steen at gmail.com Fri Aug 3 12:20:04 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Aug 3 12:20:05 2007 Subject: Upgrading Minor versions In-Reply-To: <46B306A3.40902@ecs.soton.ac.uk> References: <2579c6b20708021427w6521a719na27d657ffe7d6b6d@mail.gmail.com> <223f97700708030049m695c6a91laa44c2df243b20f4@mail.gmail.com> <223f97700708030308n4d0c57d3j360e7283a9def359@mail.gmail.com> <46B306A3.40902@ecs.soton.ac.uk> Message-ID: <223f97700708030420h213a6275wab078b4fc87e7374@mail.gmail.com> On 03/08/07, Julian Field wrote: > > > Res wrote: > > On Fri, 3 Aug 2007, Glenn Steen wrote: > > > >> That scheme was dreamed up in the linux kernel dev... and (perhaps... > >> It was not always so:-) suits them very well. And it has spilled over > >> on a lot of projects. But it is hardly the one true unified version > > > > spilled over to just about 90% of the software around :) > > > >> And it's not sure to cure anything like this, where _packaging > > > > it would, as it would install to /opt as 4.63.b2 etc and not over > > write the existing 4.63 directory. > > > >> will just have to think of some more or less clever way of handling > >> it. > > > > and until such time, its probably going to be recommended those using > > tarball don't bother with such upgrades. > > > I don't need to completely rewrite my version numbering scheme or > anything crazy like that. All I need is to add 4 characters to > install.tar-fns.sh. > > Please try the attached patch. You will discover it adds the build > number in the directory it creates for the new version of MailScanner > you're installing. > > Jules > Clever indeed:-). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From wjohns at balita.ph Fri Aug 3 12:20:52 2007 From: wjohns at balita.ph (Wayne) Date: Fri Aug 3 12:20:53 2007 Subject: Error after upgrade In-Reply-To: <30884165.10941186139270824.JavaMail.root@office.splatnix.n et> References: <200708030852.l738qkTp030708@balita.ph> <30884165.10941186139270824.JavaMail.root@office.splatnix.net> Message-ID: <200708031120.l73BKo5w029434@balita.ph> At 12:07 03/08/2007, you wrote: Many thanks for reply - I have since reinstalled SA 3.1.9 (at the advice of server managers) we run RHEL 4. I have also noticed if I start MS it seems to be stuck in a loop (this snippet of log shows) Aug 3 12:12:24 eul0001188 MailScanner[28068]: MailScanner E-Mail Virus Scanner version 4.62.9 starting... Aug 3 12:12:24 eul0001188 MailScanner[28068]: Read 797 hostnames from the phishing whitelist Aug 3 12:12:24 eul0001188 MailScanner[28068]: SpamAssassin temporary working directory is /var/spool/MailScanner/incoming/SpamAssassin-Temp Aug 3 12:12:25 eul0001188 MailScanner[28068]: Using SpamAssassin results cache Aug 3 12:12:25 eul0001188 MailScanner[28068]: Connected to SpamAssassin cache database Aug 3 12:12:25 eul0001188 MailScanner[28068]: Enabling SpamAssassin auto-whitelist functionality... Aug 3 12:12:29 eul0001188 MailScanner: waiting for children to die: Process did not exit cleanly, returned 2 with signal 0 Aug 3 12:12:29 eul0001188 MailScanner[28082]: MailScanner E-Mail Virus Scanner version 4.62.9 starting... Aug 3 12:12:29 eul0001188 MailScanner[28082]: Read 797 hostnames from the phishing whitelist As request here's the output of spamassassin -D --lint (below) Wayne [28578] dbg: logger: adding facilities: all [28578] dbg: logger: logging level is DBG [28578] dbg: generic: SpamAssassin version 3.1.9 [28578] dbg: config: score set 0 chosen. [28578] dbg: util: running in taint mode? yes [28578] dbg: util: taint mode: deleting unsafe environment variables, resetting PATH [28578] dbg: util: PATH included '/sbin', keeping [28578] dbg: util: PATH included '/bin', keeping [28578] dbg: util: PATH included '/usr/sbin', keeping [28578] dbg: util: PATH included '/usr/bin', keeping [28578] dbg: util: PATH included '/usr/X11R6/bin', keeping [28578] dbg: util: PATH included '/bin', keeping [28578] dbg: util: PATH included '/usr/bin', keeping [28578] dbg: util: PATH included '/sbin', keeping [28578] dbg: util: PATH included '/usr/sbin', keeping [28578] dbg: util: PATH included '/usr/local/bin', keeping [28578] dbg: util: final PATH set to: /sbin:/bin:/usr/sbin:/usr/bin:/usr/X11R6/bin:/bin:/usr/bin:/sbin:/usr/sbin:/usr/local/bin [28578] dbg: message: ---- MIME PARSER START ---- [28578] dbg: message: main message type: text/plain [28578] dbg: message: parsing normal part [28578] dbg: message: added part, type: text/plain [28578] dbg: message: ---- MIME PARSER END ---- [28578] dbg: dns: is Net::DNS::Resolver available? yes [28578] dbg: dns: Net::DNS version: 0.48 [28578] dbg: diag: perl platform: 5.008005 linux [28578] dbg: diag: module installed: Digest::SHA1, version 2.10 [28578] dbg: diag: module installed: LWP::UserAgent, version 2.031 [28578] dbg: diag: module installed: HTTP::Date, version 1.46 [28578] dbg: diag: module installed: Archive::Tar, version 1.29 [28578] dbg: diag: module installed: IO::Zlib, version 1.04 [28578] dbg: diag: module installed: DB_File, version 1.814 [28578] dbg: diag: module installed: HTML::Parser, version 3.56 [28578] dbg: diag: module installed: MIME::Base64, version 3.07 [28578] dbg: diag: module installed: Net::DNS, version 0.48 [28578] dbg: diag: module installed: Net::SMTP, version 2.29 [28578] dbg: diag: module installed: Mail::SPF::Query, version 1.999001 [28578] dbg: diag: module installed: IP::Country::Fast, version 604.001 [28578] dbg: diag: module installed: Razor2::Client::Agent, version 2.40 [28578] dbg: diag: module not installed: Net::Ident ('require' failed) [28578] dbg: diag: module not installed: IO::Socket::INET6 ('require' failed) [28578] dbg: diag: module not installed: IO::Socket::SSL ('require' failed) [28578] dbg: diag: module installed: Time::HiRes, version 1.9707 [28578] dbg: diag: module installed: DBI, version 1.56 [28578] dbg: diag: module installed: Getopt::Long, version 2.34 [28578] dbg: ignore: using a test message to lint rules [28578] dbg: config: using "/etc/mail/spamassassin" for site rules pre files [28578] dbg: config: read file /etc/mail/spamassassin/init.pre [28578] dbg: config: read file /etc/mail/spamassassin/v310.pre [28578] dbg: config: read file /etc/mail/spamassassin/v312.pre [28578] dbg: config: read file /etc/mail/spamassassin/v320.pre [28578] dbg: config: using "/usr/share/spamassassin" for sys rules pre files [28578] dbg: config: using "/usr/share/spamassassin" for default rules dir [28578] dbg: config: read file /usr/share/spamassassin/10_default_prefs.cf [28578] dbg: config: read file /usr/share/spamassassin/10_misc.cf [28578] dbg: config: read file /usr/share/spamassassin/20_advance_fee.cf [28578] dbg: config: read file /usr/share/spamassassin/20_anti_ratware.cf [28578] dbg: config: read file /usr/share/spamassassin/20_body_tests.cf [28578] dbg: config: read file /usr/share/spamassassin/20_compensate.cf [28578] dbg: config: read file /usr/share/spamassassin/20_dnsbl_tests.cf [28578] dbg: config: read file /usr/share/spamassassin/20_drugs.cf [28578] dbg: config: read file /usr/share/spamassassin/20_dynrdns.cf [28578] dbg: config: read file /usr/share/spamassassin/20_fake_helo_tests.cf [28578] dbg: config: read file /usr/share/spamassassin/20_head_tests.cf [28578] dbg: config: read file /usr/share/spamassassin/20_html_tests.cf [28578] dbg: config: read file /usr/share/spamassassin/20_imageinfo.cf [28578] dbg: config: read file /usr/share/spamassassin/20_meta_tests.cf [28578] dbg: config: read file /usr/share/spamassassin/20_net_tests.cf [28578] dbg: config: read file /usr/share/spamassassin/20_phrases.cf [28578] dbg: config: read file /usr/share/spamassassin/20_porn.cf [28578] dbg: config: read file /usr/share/spamassassin/20_ratware.cf [28578] dbg: config: read file /usr/share/spamassassin/20_uri_tests.cf [28578] dbg: config: read file /usr/share/spamassassin/20_vbounce.cf [28578] dbg: config: read file /usr/share/spamassassin/23_bayes.cf [28578] dbg: config: read file /usr/share/spamassassin/25_accessdb.cf [28578] dbg: config: read file /usr/share/spamassassin/25_antivirus.cf [28578] dbg: config: read file /usr/share/spamassassin/25_asn.cf [28578] dbg: config: read file /usr/share/spamassassin/25_body_tests_es.cf [28578] dbg: config: read file /usr/share/spamassassin/25_body_tests_pl.cf [28578] dbg: config: read file /usr/share/spamassassin/25_dcc.cf [28578] dbg: config: read file /usr/share/spamassassin/25_dkim.cf [28578] dbg: config: read file /usr/share/spamassassin/25_domainkeys.cf [28578] dbg: config: read file /usr/share/spamassassin/25_hashcash.cf [28578] dbg: config: read file /usr/share/spamassassin/25_pyzor.cf [28578] dbg: config: read file /usr/share/spamassassin/25_razor2.cf [28578] dbg: config: read file /usr/share/spamassassin/25_replace.cf [28578] dbg: config: read file /usr/share/spamassassin/25_spf.cf [28578] dbg: config: read file /usr/share/spamassassin/25_textcat.cf [28578] dbg: config: read file /usr/share/spamassassin/25_uribl.cf [28578] dbg: config: read file /usr/share/spamassassin/30_text_de.cf [28578] dbg: config: read file /usr/share/spamassassin/30_text_fr.cf [28578] dbg: config: read file /usr/share/spamassassin/30_text_it.cf [28578] dbg: config: read file /usr/share/spamassassin/30_text_nl.cf [28578] dbg: config: read file /usr/share/spamassassin/30_text_pl.cf [28578] dbg: config: read file /usr/share/spamassassin/30_text_pt_br.cf [28578] dbg: config: read file /usr/share/spamassassin/50_scores.cf [28578] dbg: config: read file /usr/share/spamassassin/60_awl.cf [28578] dbg: config: read file /usr/share/spamassassin/60_shortcircuit.cf [28578] dbg: config: read file /usr/share/spamassassin/60_whitelist.cf [28578] dbg: config: read file /usr/share/spamassassin/60_whitelist_dk.cf [28578] dbg: config: read file /usr/share/spamassassin/60_whitelist_dkim.cf [28578] dbg: config: read file /usr/share/spamassassin/60_whitelist_spf.cf [28578] dbg: config: read file /usr/share/spamassassin/60_whitelist_subject.cf [28578] dbg: config: read file /usr/share/spamassassin/72_active.cf [28578] dbg: config: using "/etc/mail/spamassassin" for site rules dir [28578] dbg: config: read file /etc/mail/spamassassin/10_misc.cf [28578] dbg: config: read file /etc/mail/spamassassin/20_advance_fee.cf [28578] dbg: config: read file /etc/mail/spamassassin/20_anti_ratware.cf [28578] dbg: config: read file /etc/mail/spamassassin/20_body_tests.cf [28578] dbg: config: read file /etc/mail/spamassassin/20_compensate.cf [28578] dbg: config: read file /etc/mail/spamassassin/20_dnsbl_tests.cf [28578] dbg: config: read file /etc/mail/spamassassin/20_drugs.cf [28578] dbg: config: read file /etc/mail/spamassassin/20_fake_helo_tests.cf [28578] dbg: config: read file /etc/mail/spamassassin/20_head_tests.cf [28578] dbg: config: read file /etc/mail/spamassassin/20_html_tests.cf [28578] dbg: config: read file /etc/mail/spamassassin/20_meta_tests.cf [28578] dbg: config: read file /etc/mail/spamassassin/20_net_tests.cf [28578] dbg: config: read file /etc/mail/spamassassin/20_phrases.cf [28578] dbg: config: read file /etc/mail/spamassassin/20_porn.cf [28578] dbg: config: read file /etc/mail/spamassassin/20_ratware.cf [28578] dbg: config: read file /etc/mail/spamassassin/20_uri_tests.cf [28578] dbg: config: read file /etc/mail/spamassassin/23_bayes.cf [28578] dbg: config: read file /etc/mail/spamassassin/25_accessdb.cf [28578] dbg: config: read file /etc/mail/spamassassin/25_antivirus.cf [28578] dbg: config: read file /etc/mail/spamassassin/25_body_tests_es.cf [28578] dbg: config: read file /etc/mail/spamassassin/25_body_tests_pl.cf [28578] dbg: config: read file /etc/mail/spamassassin/25_dcc.cf [28578] dbg: config: read file /etc/mail/spamassassin/25_dkim.cf [28578] dbg: config: read file /etc/mail/spamassassin/25_domainkeys.cf [28578] dbg: config: read file /etc/mail/spamassassin/25_hashcash.cf [28578] dbg: config: read file /etc/mail/spamassassin/25_pyzor.cf [28578] dbg: config: read file /etc/mail/spamassassin/25_razor2.cf [28578] dbg: config: read file /etc/mail/spamassassin/25_replace.cf [28578] dbg: config: read file /etc/mail/spamassassin/25_spf.cf [28578] dbg: config: read file /etc/mail/spamassassin/25_textcat.cf [28578] dbg: config: read file /etc/mail/spamassassin/30_text_de.cf [28578] dbg: config: read file /etc/mail/spamassassin/30_text_fr.cf [28578] dbg: config: read file /etc/mail/spamassassin/30_text_it.cf [28578] dbg: config: read file /etc/mail/spamassassin/30_text_nl.cf [28578] dbg: config: read file /etc/mail/spamassassin/30_text_pl.cf [28578] dbg: config: read file /etc/mail/spamassassin/30_text_pt_br.cf [28578] dbg: config: read file /etc/mail/spamassassin/50_scores.cf [28578] dbg: config: read file /etc/mail/spamassassin/60_awl.cf [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_adult.cf [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_bayes_poison_nxm.cf [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_evilnum0.cf [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_evilnum1.cf [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_evilnum2.cf [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_header0.cf [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_highrisk.cf [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_html.cf [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_obfu.cf [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_obfu0.cf [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_oem.cf [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_random.cf [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_specific.cf [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_spoof.cf [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_stocks.cf [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_unsub.cf [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_uri0.cf [28578] dbg: config: read file /etc/mail/spamassassin/70_sc_top200.cf [28578] dbg: config: read file /etc/mail/spamassassin/71_sare_redirect_pre3.0.0.cf [28578] dbg: config: read file /etc/mail/spamassassin/72_sare_redirect_post3.0.0.cf [28578] dbg: config: read file /etc/mail/spamassassin/99_FVGT_Tripwire.cf [28578] dbg: config: read file /etc/mail/spamassassin/99_sare_fraud_post25x.cf [28578] dbg: config: read file /etc/mail/spamassassin/Botnet.cf [28578] dbg: config: read file /etc/mail/spamassassin/antidrug.cf [28578] dbg: config: read file /etc/mail/spamassassin/bigevil.cf [28578] dbg: config: read file /etc/mail/spamassassin/bogus-virus-warnings.cf [28578] dbg: config: read file /etc/mail/spamassassin/chickenpox.cf [28578] dbg: config: read file /etc/mail/spamassassin/evilnumbers.cf [28578] dbg: config: read file /etc/mail/spamassassin/imageinfo.cf [28578] dbg: config: read file /etc/mail/spamassassin/local.cf [28578] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf [28578] dbg: config: read file /etc/mail/spamassassin/tripwire.cf [28578] dbg: config: using "/root/.spamassassin/user_prefs" for user prefs file [28578] dbg: config: read file /root/.spamassassin/user_prefs [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [28578] dbg: plugin: registered Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x94e1208) [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC [28578] dbg: plugin: registered Mail::SpamAssassin::Plugin::Hashcash=HASH(0x94f54bc) [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [28578] dbg: plugin: registered Mail::SpamAssassin::Plugin::SPF=HASH(0x951d144) [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC [28578] dbg: pyzor: local tests only, disabling Pyzor [28578] dbg: plugin: registered Mail::SpamAssassin::Plugin::Pyzor=HASH(0x95201f0) [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [28578] dbg: razor2: local tests only, skipping Razor [28578] dbg: plugin: registered Mail::SpamAssassin::Plugin::Razor2=HASH(0x94f7638) [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::SpamCop from @INC [28578] dbg: reporter: local tests only, disabling SpamCop [28578] dbg: plugin: registered Mail::SpamAssassin::Plugin::SpamCop=HASH(0x94f96fc) [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC [28578] dbg: plugin: registered Mail::SpamAssassin::Plugin::AWL=HASH(0x95c4ef0) [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold from @INC [28578] dbg: plugin: registered Mail::SpamAssassin::Plugin::AutoLearnThreshold=HASH(0x95e7460) [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject from @INC [28578] dbg: plugin: registered Mail::SpamAssassin::Plugin::WhiteListSubject=HASH(0x95d93e4) [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from @INC [28578] dbg: plugin: registered Mail::SpamAssassin::Plugin::MIMEHeader=HASH(0x95fba80) [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from @INC [28578] dbg: plugin: registered Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x960a794) [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::DCC from @INC [28578] dbg: dcc: local tests only, disabling DCC [28578] dbg: plugin: registered Mail::SpamAssassin::Plugin::DCC=HASH(0x95438f8) [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC [28578] dbg: pyzor: local tests only, disabling Pyzor [28578] dbg: plugin: did not register Mail::SpamAssassin::Plugin::Pyzor=HASH(0x9d6fc88), already registered [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::SpamCop from @INC [28578] dbg: reporter: local tests only, disabling SpamCop [28578] dbg: plugin: did not register Mail::SpamAssassin::Plugin::SpamCop=HASH(0x9d6fda8), already registered [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC [28578] dbg: plugin: did not register Mail::SpamAssassin::Plugin::AWL=HASH(0x9544000), already registered [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold from @INC [28578] dbg: plugin: did not register Mail::SpamAssassin::Plugin::AutoLearnThreshold=HASH(0x9d6fe5c), already registered [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject from @INC [28578] dbg: plugin: did not register Mail::SpamAssassin::Plugin::WhiteListSubject=HASH(0x9d6fd9c), already registered [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from @INC [28578] dbg: plugin: did not register Mail::SpamAssassin::Plugin::MIMEHeader=HASH(0x95444bc), already registered [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from @INC [28578] dbg: plugin: did not register Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9d6ffb8), already registered [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [28578] dbg: plugin: registered Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x95450e0) [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [28578] dbg: plugin: did not register Mail::SpamAssassin::Plugin::SPF=HASH(0x954514c), already registered [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [28578] dbg: plugin: did not register Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x951d378), already registered [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [28578] dbg: razor2: local tests only, skipping Razor [28578] dbg: plugin: did not register Mail::SpamAssassin::Plugin::Razor2=HASH(0x94e3c18), already registered [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [28578] dbg: plugin: registered Mail::SpamAssassin::Plugin::ASN=HASH(0x9545644) [28578] warn: config: configuration file "/usr/share/spamassassin/20_dynrdns.cf" requires version 3.002002 of SpamAssassin, but this is code version 3.001009. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/vendor_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 345. [28578] dbg: config: adding redirector regex: /^http:\/\/chkpt\.zdnet\.com\/chkpt\/\w+\/(.*)$/i [28578] dbg: config: adding redirector regex: /^http:\/\/www(?:\d+)?\.nate\.com\/r\/\w+\/(.*)$/i [28578] dbg: config: adding redirector regex: /^http:\/\/.+\.gov\/(?:.*\/)?externalLink\.jhtml\?.*url=(.*?)(?:&.*)?$/i [28578] dbg: config: adding redirector regex: /^http:\/\/redir\.internet\.com\/.+?\/.+?\/(.*)$/i [28578] dbg: config: adding redirector regex: /^http:\/\/(?:.*?\.)?adtech\.de\/.*(?:;|\|)link=(.*?)(?:;|$)/i [28578] dbg: config: adding redirector regex: m'^http.*?/redirect\.php\?.*(?<=[?&])goto=(.*?)(?:$|[&#])'i [28578] dbg: config: adding redirector regex: m'^https?:/*(?:[^/]+\.)?emf\d\.com/r\.cfm.*?&r=(.*)'i [28578] dbg: config: adding redirector regex: m'/(?:index.php)?\?.*(?<=[?&])URL=(.*?)(?:$|[&#])'i [28578] dbg: config: adding redirector regex: m'^http:/*(?:\w+\.)?google(?:\.\w{2,3}){1,2}/url\?.*?(?<=[?&])q=(.*?)(?:$|[&#])'i [28578] dbg: config: adding redirector regex: m'^http:/*(?:\w+\.)?google(?:\.\w{2,3}){1,2}/search\?.*?(?<=[?&])q=[^&]*?(?<=%20|..[=+\s])site:(.*?)(?:$|%20|[\s+&#])'i [28578] dbg: config: adding redirector regex: m'^http:/*(?:\w+\.)?google(?:\.\w{2,3}){1,2}/search\?.*?(?<=[?&])q=[^&]*?(?<=%20|..[=+\s])(?:"|%22)(.*?)(?:$|%22|["\s+&#])'i [28578] dbg: config: adding redirector regex: m'^http:/*(?:\w+\.)?google(?:\.\w{2,3}){1,2}/translate\?.*?(?<=[?&])u=(.*?)(?:$|[&#])'i [28578] warn: config: configuration file "/usr/share/spamassassin/72_active.cf" requires version 3.002002 of SpamAssassin, but this is code version 3.001009. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/vendor_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 345. [28578] dbg: config: adding redirector regex: /^http:\/\/chkpt\.zdnet\.com\/chkpt\/\w+\/(.*)$/i [28578] dbg: config: adding redirector regex: /^http:\/\/www(?:\d+)?\.nate\.com\/r\/\w+\/(.*)$/i [28578] dbg: config: adding redirector regex: /^http:\/\/.+\.gov\/(?:.*\/)?externalLink\.jhtml\?.*url=(.*?)(?:&.*)?$/i [28578] dbg: config: adding redirector regex: /^http:\/\/redir\.internet\.com\/.+?\/.+?\/(.*)$/i [28578] dbg: config: adding redirector regex: /^http:\/\/(?:.*?\.)?adtech\.de\/.*(?:;|\|)link=(.*?)(?:;|$)/i [28578] dbg: config: adding redirector regex: m'^http.*?/redirect\.php\?.*(?<=[?&])goto=(.*?)(?:$|[&#])'i [28578] dbg: config: adding redirector regex: m'^https?:/*(?:[^/]+\.)?emf\d\.com/r\.cfm.*?&r=(.*)'i [28578] dbg: plugin: fixed relative path: /etc/mail/spamassassin/Botnet.pm [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::Botnet from /etc/mail/spamassassin/Botnet.pm [28578] dbg: Botnet: version 0.7 [28578] dbg: plugin: registered Mail::SpamAssassin::Plugin::Botnet=HASH(0x9f21950) [28578] dbg: plugin: Mail::SpamAssassin::Plugin::Botnet=HASH(0x9f21950) implements 'parse_config' [28578] dbg: Botnet: setting botnet_pass_auth to 0 [28578] dbg: Botnet: setting botnet_pass_trusted to public [28578] dbg: Botnet: adding ^127\.0\.0\.1$ to botnet_skip_ip [28578] dbg: Botnet: adding ^10\..*$ to botnet_skip_ip [28578] dbg: Botnet: adding ^172\.1[6789]\..*$ to botnet_skip_ip [28578] dbg: Botnet: adding ^172\.2[0-9]\..*$ to botnet_skip_ip [28578] dbg: Botnet: adding ^172\.3[01]\..*$ to botnet_skip_ip [28578] dbg: Botnet: adding ^192\.168\..*$ to botnet_skip_ip [28578] dbg: Botnet: adding ^128\.223\.98\.16$ to botnet_pass_ip [28578] dbg: Botnet: adding (\.|\A)amazon\.com$ to botnet_pass_domains [28578] dbg: Botnet: adding (\.|\A)apple\.com$ to botnet_pass_domains [28578] dbg: Botnet: adding (\.|\A)ebay\.com$ to botnet_pass_domains [28578] dbg: Botnet: adding (\b|\d)(a|s|d(yn)?)?dsl(\b|\d) to botnet_clientwords [28578] dbg: Botnet: adding (\b|\d)cable(\b|\d) to botnet_clientwords [28578] dbg: Botnet: adding (\b|\d)catv(\b|\d) to botnet_clientwords [28578] dbg: Botnet: adding (\b|\d)ddns(\b|\d) to botnet_clientwords [28578] dbg: Botnet: adding (\b|\d)dhcp(\b|\d) to botnet_clientwords [28578] dbg: Botnet: adding (\b|\d)dial(-?up)?(\b|\d) to botnet_clientwords [28578] dbg: Botnet: adding (\b|\d)dip(\b|\d) to botnet_clientwords [28578] dbg: Botnet: adding (\b|\d)docsis(\b|\d) to botnet_clientwords [28578] dbg: Botnet: adding (\b|\d)dyn(amic)?(ip)?(\b|\d) to botnet_clientwords [28578] dbg: Botnet: adding (\b|\d)modem(\b|\d) to botnet_clientwords [28578] dbg: Botnet: adding (\b|\d)ppp(\b|\d) to botnet_clientwords [28578] dbg: Botnet: adding (\b|\d)res(net|ident(ial)?)?(\b|\d) to botnet_clientwords [28578] dbg: Botnet: adding (\b|\d)client(\b|\d) to botnet_clientwords [28578] dbg: Botnet: adding (\b|\d)fixed(\b|\d) to botnet_clientwords [28578] dbg: Botnet: adding (\b|\d)ip(\b|\d) to botnet_clientwords [28578] dbg: Botnet: adding (\b|\d)pool(\b|\d) to botnet_clientwords [28578] dbg: Botnet: adding (\b|\d)static(\b|\d) to botnet_clientwords [28578] dbg: Botnet: adding (\b|\d)user(\b|\d) to botnet_clientwords [28578] dbg: Botnet: adding (\b|\d)mail(\b|\d) to botnet_serverwords [28578] dbg: Botnet: adding (\b|\d)mta(\b|\d) to botnet_serverwords [28578] dbg: Botnet: adding (\b|\d)mx(\b|\d) to botnet_serverwords [28578] dbg: Botnet: adding (\b|\d)relay(\b|\d) to botnet_serverwords [28578] dbg: Botnet: adding (\b|\d)smtp(\b|\d) to botnet_serverwords [28578] dbg: Botnet: adding (\b|\d)exch(ange)?(\b|\d) to botnet_serverwords [28578] info: config: pyzor_path "/usr/bin/pyzor" isn't an executable [28578] warn: config: SpamAssassin failed to parse line, "/usr/bin/pyzor" is not valid for "pyzor_path", skipping: pyzor_path /usr/bin/pyzor [28578] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x960a794) implements 'finish_parsing_end' [28578] dbg: replacetags: replacing tags [28578] dbg: replacetags: done replacing tags [28578] dbg: bayes: tie-ing to DB file R/O /root/.spamassassin/bayes_toks [28578] dbg: bayes: tie-ing to DB file R/O /root/.spamassassin/bayes_seen [28578] dbg: bayes: found bayes db version 3 [28578] dbg: bayes: DB journal sync: last sync: 1186071636 [28578] dbg: config: score set 2 chosen. [28578] dbg: message: ---- MIME PARSER START ---- [28578] dbg: message: main message type: text/plain [28578] dbg: message: parsing normal part [28578] dbg: message: added part, type: text/plain [28578] dbg: message: ---- MIME PARSER END ---- [28578] dbg: dns: is DNS available? 0 [28578] dbg: metadata: X-Spam-Relays-Trusted: [28578] dbg: metadata: X-Spam-Relays-Untrusted: [28578] dbg: metadata: X-Spam-Relays-Internal: [28578] dbg: metadata: X-Spam-Relays-External: [28578] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x95450e0) implements 'extract_metadata' [28578] dbg: metadata: X-Relay-Countries: [28578] dbg: message: no encoding detected [28578] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x94e1208) implements 'parsed_metadata' [28578] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x95450e0) implements 'parsed_metadata' [28578] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x9545644) implements 'parsed_metadata' [28578] dbg: asn: DNS is not available, skipping ASN checks [28578] dbg: rules: local tests only, ignoring RBL eval [28578] dbg: check: running tests for priority: -1000 [28578] dbg: rules: running header regexp tests; score so far=0 [28578] dbg: eval: all '*From' addrs: ignore@compiling.spamassassin.taint.org [28578] dbg: eval: all '*To' addrs: [28578] dbg: rules: running body-text per-line regexp tests; score so far=0 [28578] dbg: uri: running uri tests; score so far=0 [28578] dbg: rules: running raw-body-text per-line regexp tests; score so far=0 [28578] dbg: rules: running full-text regexp tests; score so far=0 [28578] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x94e1208) implements 'check_tick' [28578] dbg: check: running tests for priority: -950 [28578] dbg: rules: running header regexp tests; score so far=0 [28578] dbg: rules: running body-text per-line regexp tests; score so far=0 [28578] dbg: uri: running uri tests; score so far=0 [28578] dbg: rules: running raw-body-text per-line regexp tests; score so far=0 [28578] dbg: rules: running full-text regexp tests; score so far=0 [28578] dbg: check: running tests for priority: -900 [28578] dbg: rules: running header regexp tests; score so far=0 [28578] dbg: rules: running body-text per-line regexp tests; score so far=0 [28578] dbg: uri: running uri tests; score so far=0 [28578] dbg: rules: running raw-body-text per-line regexp tests; score so far=0 [28578] dbg: rules: running full-text regexp tests; score so far=0 [28578] dbg: check: running tests for priority: -400 [28578] dbg: rules: running header regexp tests; score so far=0 [28578] dbg: rules: running body-text per-line regexp tests; score so far=0 [28578] dbg: uri: running uri tests; score so far=0 [28578] dbg: bayes: DB journal sync: last sync: 1186071636 [28578] dbg: bayes: corpus size: nspam = 1637, nham = 347 [28578] dbg: bayes: score = 0.442179793344652 [28578] dbg: bayes: DB journal sync: last sync: 1186071636 [28578] dbg: bayes: untie-ing [28578] dbg: bayes: untie-ing db_toks [28578] dbg: bayes: untie-ing db_seen [28578] dbg: rules: running raw-body-text per-line regexp tests; score so far=0 [28578] dbg: rules: running full-text regexp tests; score so far=0 [28578] dbg: check: running tests for priority: 0 [28578] dbg: rules: running header regexp tests; score so far=0 [28578] dbg: rules: ran header rule __HAS_MSGID ======> got hit: "<" [28578] dbg: rules: ran header rule __SANE_MSGID ======> got hit: "<1186139684@lint_rules> [28578] dbg: rules: " [28578] dbg: rules: ran header rule __MSGID_OK_HOST ======> got hit: "@lint_rules>" [28578] dbg: rules: ran header rule __BOTNET_NOTRUST ======> got hit: "negative match" [28578] dbg: rules: ran header rule __MSGID_OK_DIGITS ======> got hit: "1186139684" [28578] dbg: rules: ran eval rule NO_RELAYS ======> got hit [28578] dbg: Botnet: starting [28578] dbg: Botnet: no trusted relays [28578] dbg: Botnet: All skipped/no untrusted [28578] dbg: Botnet: skipping [28578] dbg: rules: ran eval rule __UNUSABLE_MSGID ======> got hit [28578] dbg: rules: running body-text per-line regexp tests; score so far=-0.001 [28578] dbg: rules: ran body rule __SARE_HTML_HAS_MSG ======> got hit: "I" [28578] dbg: rules: ran body rule __NONEMPTY_BODY ======> got hit: "I" [28578] dbg: uri: running uri tests; score so far=-0.001 [28578] dbg: rules: ran eval rule BAYES_50 ======> got hit [28578] dbg: rules: running raw-body-text per-line regexp tests; score so far=0 [28578] dbg: rules: running full-text regexp tests; score so far=0 [28578] dbg: check: running tests for priority: 500 [28578] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x94e1208) implements 'check_post_dnsbl' [28578] dbg: rules: running meta tests; score so far=0 [28578] info: rules: meta test CRBOUNCE_MESSAGE has undefined dependency '__MY_SERVERS_FOUND' [28578] info: rules: meta test DRUGS_ERECTILE has undefined dependency '__DRUGS_ERECTILE7' [28578] info: rules: meta test VBOUNCE_MESSAGE has undefined dependency '__MY_SERVERS_FOUND' [28578] info: rules: meta test BOUNCE_MESSAGE has undefined dependency '__HAVE_BOUNCE_RELAYS' [28578] info: rules: meta test BOUNCE_MESSAGE has undefined dependency '__MY_SERVERS_FOUND' [28578] info: rules: meta test SARE_HEAD_SUBJ_RAND has undefined dependency 'SARE_XMAIL_SUSP2' [28578] info: rules: meta test SARE_HEAD_SUBJ_RAND has undefined dependency 'SARE_HEAD_XAUTH_WARN' [28578] info: rules: meta test SARE_RD_SAFE has undefined dependency 'SARE_RD_SAFE_MKSHRT' [28578] info: rules: meta test SARE_RD_SAFE has undefined dependency 'SARE_RD_SAFE_GT' [28578] info: rules: meta test SARE_RD_SAFE has undefined dependency 'SARE_RD_SAFE_TINY' [28578] info: rules: meta test VIRUS_WARNING_DOOM_BNC has undefined dependency 'VIRUS_WARNING_MYDOOM4' [28578] dbg: rules: running header regexp tests; score so far=2.157 [28578] dbg: rules: running body-text per-line regexp tests; score so far=2.157 [28578] dbg: uri: running uri tests; score so far=2.157 [28578] dbg: rules: running raw-body-text per-line regexp tests; score so far=2.157 [28578] dbg: rules: running full-text regexp tests; score so far=2.157 [28578] dbg: check: running tests for priority: 1000 [28578] dbg: rules: running meta tests; score so far=2.157 [28578] dbg: rules: running header regexp tests; score so far=2.157 [28578] dbg: rules: running body-text per-line regexp tests; score so far=2.157 [28578] dbg: uri: running uri tests; score so far=2.157 [28578] dbg: rules: running raw-body-text per-line regexp tests; score so far=2.157 [28578] dbg: rules: running full-text regexp tests; score so far=2.157 [28578] dbg: check: is spam? score=2.157 required=5 [28578] dbg: check: tests=BAYES_50,MISSING_SUBJECT,NO_RECEIVED,NO_RELAYS,TO_CC_NONE [28578] dbg: check: subtests=__BOTNET_NOTRUST,__HAS_MSGID,__MSGID_OK_DIGITS,__MSGID_OK_HOST,__NONEMPTY_BODY,__SANE_MSGID,__SARE_HTML_HAS_MSG,__UNUSABLE_MSGID [28578] warn: lint: 3 issues detected, please rerun with debug enabled for more information >Run a spamassassin -D --lint and post the output please. > >Regards, > >--[ UxBoD ]-- >// PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" >// Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B >// Keyserver: www.keyserver.net Key-ID: 0x5DB5687B >// Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net > >----- Original Message ----- >From: "Wayne" >To: "MailScanner discussion" >Sent: 03 August 2007 09:52:48 o'clock (GMT) Europe/London >Subject: Error after upgrade > >Hi > >I upgraded MailScanner and Spamassassin yesterday to 4.62 and 3.2.2 >(from Clamav SA package). > >Previously the package ran without problems however I am getting this >error. (show below) > >Line 396 (first part of the error) seems to contradict or even make >sense to me - what needs altering > >What plugin is missing from the second part? > >Because of the error MS runs in a loop. > >Afraid I am not highly expert on MS/SA I can install but get lost >when it throws errors like this. > >Anyones help would be appreciated. > >- Wayne - > > >I started MailScanner in debug mode:- > >In Debugging mode, not forking... >SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp >config: 'rbl_timeout' is obsolete, use 'rbl_timeout' instead at >/usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Plugin/URIDNSBL.pm line 396. > >check: no loaded plugin implements 'check_main': cannot scan! at >/usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/PerMsgStatus.pm line 164. > >-- >MailScanner mailing list >mailscanner@lists.mailscanner.info >http://lists.mailscanner.info/mailman/listinfo/mailscanner > >Before posting, read http://wiki.mailscanner.info/posting > >Support MailScanner development - buy the book off the website! > >-- >This message has been scanned for viruses and >dangerous content by MailScanner, and is >believed to be clean. > > > >-- >This message has been scanned for viruses and >dangerous content by MailScanner, and is >believed to be clean. > >-- >MailScanner mailing list >mailscanner@lists.mailscanner.info >http://lists.mailscanner.info/mailman/listinfo/mailscanner > >Before posting, read http://wiki.mailscanner.info/posting > >Support MailScanner development - buy the book off the website! From prandal at herefordshire.gov.uk Fri Aug 3 12:37:11 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Fri Aug 3 12:37:25 2007 Subject: CRM114 How are you finding it ? In-Reply-To: <223f97700708030259p44e038f2t9309e8511d1db32c@mail.gmail.com> References: <46B21DC0.1070603@fractalweb.com><20217261.10671186123072159.JavaMail.root@office.splatnix.net><223f97700708030106j7403d897u30ee16d5590e4130@mail.gmail.com><7EF0EE5CB3B263488C8C18823239BEBA01510DCC@HC-MBX02.herefordshire.gov.uk><223f97700708030219t436142f8ufe6d4bed9d3978e8@mail.gmail.com><7EF0EE5CB3B263488C8C18823239BEBA01510DDD@HC-MBX02.herefordshire.gov.uk> <223f97700708030259p44e038f2t9309e8511d1db32c@mail.gmail.com> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA01510E45@HC-MBX02.herefordshire.gov.uk> Using CentOS 5 x64, I installed according to the wiki as it was. I had to make the crm114/*.crm files executable for it to work, so I added that step to the wiki. The only changes I made in crm114.cf were: crm114_learn 1 crm114_autolearn 1 crm114_dynscore_factor -0.2 Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Glenn Steen > Sent: 03 August 2007 10:59 > To: MailScanner discussion > Subject: Re: CRM114 How are you finding it ? > > On 03/08/07, Randal, Phil wrote: > > In mine it was > > > > #crm114_dynscore_factor -0.05 > > > > And when I removed the # the scores went down dramatically. > > > Quite correct. The default (from crm114.pm) is > my $default_crm114_dynscore_factor = $conf->{required_score} / -25; > ... which aims at calculating a normalizer value that would put a CRM > score of (-)25 at your required SA spam score... I think this might > not be the best of things, since the values can fluctuate quite a bit > more than that, and I imagine most *don't* want CRM114 to be the sole > deciding factor. > Anyway, did you install according to the wiki page? If so, I obviously > have made some changes that I've promptly forgot about(:-)... else the > "default" in the crm114.cf file was what I mentioned. > > > Phil > > > > -- > > Phil Randal > > Network Engineer > > Herefordshire Council > > Hereford, UK > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > > > Of Glenn Steen > > > Sent: 03 August 2007 10:20 > > > To: MailScanner discussion > > > Subject: Re: CRM114 How are you finding it ? > > > > > > On 03/08/07, Randal, Phil wrote: > > > > Actually, the documentation in the readme is not clear, but > > > the default > > > > is NOT -0.05. > > > > > > > Oh really? The file the install plopped into place could've > > > fooled me... > > > ----- > > > # dynamic score normalization factor > > > # CRM score have much higher absolute values and different > > > signs than SA scores > > > # (usual ham-scores are between 15 and 40, scores from -10 to > > > 10 are undecided, > > > # previously seen spam easily gets -200). > > > # With dynamic scoring the SA score is calculated by: > > score> * crm114_dynsc > > > ore_factor > > > # > > > # Notes: - this has to be a negative number! > > > # - the absolute value should be quite low (certainly > > > <.3, probably <=.2) > > > , > > > # otherwise the returned score would override all > > > other tests. > > > # default: calculate factor so that CRM-score -25 yields the > > > SA required spam th > > > reshold > > > crm114_dynscore_factor -0.05 > > > ----- > > > So ... as a score "normalizer" and "sign changer" .... I > do believe > > > I'm correct in stating that this is a "default" (very ... > relative... > > > term that;-). > > > > > > So... If one don't want to have crm114 as the "sole > deciding factor", > > > but rather as just another "score contributor"... I'd say > the -0.005 > > > would be reasonable... -0.2 would potentially give very > high values. > > > > > > Cheers > > Cheers > -- > -- Glenn > email: glenn < dot > steen < at > gmail < dot > com > work: glenn < dot > steen < at > ap1 < dot > se > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From dward at nccumc.org Fri Aug 3 13:27:13 2007 From: dward at nccumc.org (Douglas Ward) Date: Fri Aug 3 13:27:17 2007 Subject: pdfassassin In-Reply-To: References: Message-ID: We block .zip and .rar at the mta. I finally ducked a new spam wave! :) On 8/3/07, Martin.Hepworth wrote: > > Won't help with the latest incarnation, zipped excel files! > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Douglas Ward > > Sent: 02 August 2007 17:58 > > To: MailScanner discussion > > Subject: pdfassassin > > > > http://freshmeat.net/projects/pdfassassin/ > > > > Looks interesting. Has anyone given this a look? > > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070803/197e740f/attachment.html From glenn.steen at gmail.com Fri Aug 3 13:32:40 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Aug 3 13:32:42 2007 Subject: CRM114 How are you finding it ? In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA01510E45@HC-MBX02.herefordshire.gov.uk> References: <46B21DC0.1070603@fractalweb.com> <20217261.10671186123072159.JavaMail.root@office.splatnix.net> <223f97700708030106j7403d897u30ee16d5590e4130@mail.gmail.com> <7EF0EE5CB3B263488C8C18823239BEBA01510DCC@HC-MBX02.herefordshire.gov.uk> <223f97700708030219t436142f8ufe6d4bed9d3978e8@mail.gmail.com> <7EF0EE5CB3B263488C8C18823239BEBA01510DDD@HC-MBX02.herefordshire.gov.uk> <223f97700708030259p44e038f2t9309e8511d1db32c@mail.gmail.com> <7EF0EE5CB3B263488C8C18823239BEBA01510E45@HC-MBX02.herefordshire.gov.uk> Message-ID: <223f97700708030532j7594a7aan1c178a5b751a675@mail.gmail.com> On 03/08/07, Randal, Phil wrote: > Using CentOS 5 x64, I installed according to the wiki as it was. > > I had to make the crm114/*.crm files executable for it to work, so I > added that step to the wiki. > > The only changes I made in crm114.cf were: > > crm114_learn 1 > crm114_autolearn 1 > crm114_dynscore_factor -0.2 > > Cheers, > > Phil I just did the install on another host and... Indeed it is my memory that is at fault:-). I've amended the "rescoring" note accordingly in the wiki. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From hvdkooij at vanderkooij.org Fri Aug 3 13:37:18 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Fri Aug 3 13:37:23 2007 Subject: DoS condition on OCR? Message-ID: Hi, Is anyone else seeing problems when using OCR scanning in their anti-spam solution? I suspect there are messages going round where the PDF file explodes to a set of images which in term drive a OCR solution nuts because it explodes to aburd sizes. In effect it seems to cause a DoS condition. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From glenn.steen at gmail.com Fri Aug 3 13:45:47 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Aug 3 13:45:49 2007 Subject: Error after upgrade In-Reply-To: <200708030852.l738qkTp030708@balita.ph> References: <200708030852.l738qkTp030708@balita.ph> Message-ID: <223f97700708030545g4d6d5741hfb7ceef46f6b4739@mail.gmail.com> On 03/08/07, Wayne wrote: > Hi > > I upgraded MailScanner and Spamassassin yesterday to 4.62 and 3.2.2 > (from Clamav SA package). > > Previously the package ran without problems however I am getting this > error. (show below) > > Line 396 (first part of the error) seems to contradict or even make > sense to me - what needs altering > > What plugin is missing from the second part? > > Because of the error MS runs in a loop. > > Afraid I am not highly expert on MS/SA I can install but get lost > when it throws errors like this. > > Anyones help would be appreciated. > > - Wayne - > > > I started MailScanner in debug mode:- > > In Debugging mode, not forking... > SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp > config: 'rbl_timeout' is obsolete, use 'rbl_timeout' instead at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Plugin/URIDNSBL.pm line 396. > > check: no loaded plugin implements 'check_main': cannot scan! at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/PerMsgStatus.pm line 164. > You could've searched the archives and you would've found http://thread.gmane.org/gmane.mail.virus.mailscanner/53215/focus=53261 ... Denis had more or less this problem, which is due to the Check plugin not being loaded (in his case he seems to have missed the v320.pre file entirely). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From dave.list at pixelhammer.com Fri Aug 3 13:46:45 2007 From: dave.list at pixelhammer.com (DAve) Date: Fri Aug 3 13:48:56 2007 Subject: Using ClamAV to find spam In-Reply-To: <46B26C54.4030400@eltofts.homelinux.com> References: <46B25DE7.8020904@eltofts.homelinux.com> <7EF1F27F7292534D82933F70AB6996CC25CE45@pro-ak-exch01.hosted.pronet.net.nz> <46B26428.9060607@eltofts.homelinux.com> <46B26C54.4030400@eltofts.homelinux.com> Message-ID: <46B323B5.7090706@pixelhammer.com> Andy Wright wrote: > Scott Silva wrote: >> Andy Wright spake the following on 8/2/2007 4:09 PM: >> >>> Brent Addis wrote: >>> >>>> Try the clamav spamassassin plugin. If your spam scores high enough it >>>> shouldn't be virus scanned and won't scew your stats. >>>> >>>> http://www.nabble.com/My-bash-script-to-upload-PDFinfo-daily,-safely-t4115144.html >>>> >>>> has an example about halfway through the comments at the bottom. >>>> >>>> Hi list, >>>> >>>> I've enabled the "ClamAV Full Message Scan" option and installed the >>>> sanesecurity sigs. Clam is nicely finding loads (and loads... and >>>> loads...!) of spam, but of course is causing all these messages to be >>>> tagged as Virused. This is making my MailWatch screen a sea of red and >>>> skewing the stats such that I appear to be receiving loads of viruses >>>> instead of spam. >>>> >>>> Is it possible to get MailScanner to look at the report from ClamAV and >>>> determine if the message is really spam rather than virused ? >>> Hi Brent, >>> >>> thanks for the suggestion, although I'm reluctant to add yet more >>> plugins - most of the spams are already being scored at 20+ (how high >>> does this have to get before virus scanning is skipped?) >>> >>> I guess what I'm after is a way for MailScanner to handle things >>> differently if the return from ClamAV is "Email.*, Html.*" etc Now that >>> Clam seems to be more than just a *virus* finder might it make sense for >>> MailScanner to look more closely at the returned result ? Maybe an >>> excuse for Julian to up the options well beyond the 300 mark ?! >>> >>> Andy. >>> >> AFAIK all their signatures give sanesecurity in their responses. Maybe an >> option to look for this and just give spam scores. >> For me, I don't really care right now what stops them, as long as it >> doesn't >> go to the users. Maybe later if I start reporting ratios to someone, I >> might. >> >> > Most do, but there are a few along the lines of "Email.Phising.RB-1221" > > I do report results to clients so this would be a nice thing to be able > to correct. > I think so as well, see my response to "Re: Request for comments 3 - Re: MailScanner and password protected archives" I posted on the 25th of last month. ClamAV does not always equal virus, SA does not always equal spam. I think the gap will close even more as time goes on. The more I think about it the more I like the idea of separating the identification/tagging from the reporting/action of each message. I am apparently alone in this. DAve -- Three years now I've asked Google why they don't have a logo change for Memorial Day. Why do they choose to do logos for other non-international holidays, but nothing for Veterans? Maybe they forgot who made that choice possible. From MailScanner at ecs.soton.ac.uk Fri Aug 3 13:48:46 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 3 13:49:02 2007 Subject: Error after upgrade In-Reply-To: <200708031120.l73BKo5w029434@balita.ph> References: <200708030852.l738qkTp030708@balita.ph> <30884165.10941186139270824.JavaMail.root@office.splatnix.net> <200708031120.l73BKo5w029434@balita.ph> Message-ID: <46B3242E.5060701@ecs.soton.ac.uk> Run MailScanner --debug and post the results here. and also MailScanner --lint and also MailScanner -v Wayne wrote: > At 12:07 03/08/2007, you wrote: > > Many thanks for reply - I have since reinstalled SA 3.1.9 (at the > advice of server managers) we run RHEL 4. > > I have also noticed if I start MS it seems to be stuck in a loop (this > snippet of log shows) > > Aug 3 12:12:24 eul0001188 MailScanner[28068]: MailScanner E-Mail > Virus Scanner version 4.62.9 starting... > Aug 3 12:12:24 eul0001188 MailScanner[28068]: Read 797 hostnames from > the phishing whitelist > Aug 3 12:12:24 eul0001188 MailScanner[28068]: SpamAssassin temporary > working directory is /var/spool/MailScanner/incoming/SpamAssassin-Temp > Aug 3 12:12:25 eul0001188 MailScanner[28068]: Using SpamAssassin > results cache > Aug 3 12:12:25 eul0001188 MailScanner[28068]: Connected to > SpamAssassin cache database > Aug 3 12:12:25 eul0001188 MailScanner[28068]: Enabling SpamAssassin > auto-whitelist functionality... > Aug 3 12:12:29 eul0001188 MailScanner: waiting for children to die: > Process did not exit cleanly, returned 2 with signal 0 > Aug 3 12:12:29 eul0001188 MailScanner[28082]: MailScanner E-Mail > Virus Scanner version 4.62.9 starting... > Aug 3 12:12:29 eul0001188 MailScanner[28082]: Read 797 hostnames from > the phishing whitelist > > As request here's the output of spamassassin -D --lint (below) > > Wayne > > > [28578] dbg: logger: adding facilities: all > [28578] dbg: logger: logging level is DBG > [28578] dbg: generic: SpamAssassin version 3.1.9 > [28578] dbg: config: score set 0 chosen. > [28578] dbg: util: running in taint mode? yes > [28578] dbg: util: taint mode: deleting unsafe environment variables, > resetting PATH > [28578] dbg: util: PATH included '/sbin', keeping > [28578] dbg: util: PATH included '/bin', keeping > [28578] dbg: util: PATH included '/usr/sbin', keeping > [28578] dbg: util: PATH included '/usr/bin', keeping > [28578] dbg: util: PATH included '/usr/X11R6/bin', keeping > [28578] dbg: util: PATH included '/bin', keeping > [28578] dbg: util: PATH included '/usr/bin', keeping > [28578] dbg: util: PATH included '/sbin', keeping > [28578] dbg: util: PATH included '/usr/sbin', keeping > [28578] dbg: util: PATH included '/usr/local/bin', keeping > [28578] dbg: util: final PATH set to: > /sbin:/bin:/usr/sbin:/usr/bin:/usr/X11R6/bin:/bin:/usr/bin:/sbin:/usr/sbin:/usr/local/bin > > [28578] dbg: message: ---- MIME PARSER START ---- > [28578] dbg: message: main message type: text/plain > [28578] dbg: message: parsing normal part > [28578] dbg: message: added part, type: text/plain > [28578] dbg: message: ---- MIME PARSER END ---- > [28578] dbg: dns: is Net::DNS::Resolver available? yes > [28578] dbg: dns: Net::DNS version: 0.48 > [28578] dbg: diag: perl platform: 5.008005 linux > [28578] dbg: diag: module installed: Digest::SHA1, version 2.10 > [28578] dbg: diag: module installed: LWP::UserAgent, version 2.031 > [28578] dbg: diag: module installed: HTTP::Date, version 1.46 > [28578] dbg: diag: module installed: Archive::Tar, version 1.29 > [28578] dbg: diag: module installed: IO::Zlib, version 1.04 > [28578] dbg: diag: module installed: DB_File, version 1.814 > [28578] dbg: diag: module installed: HTML::Parser, version 3.56 > [28578] dbg: diag: module installed: MIME::Base64, version 3.07 > [28578] dbg: diag: module installed: Net::DNS, version 0.48 > [28578] dbg: diag: module installed: Net::SMTP, version 2.29 > [28578] dbg: diag: module installed: Mail::SPF::Query, version 1.999001 > [28578] dbg: diag: module installed: IP::Country::Fast, version 604.001 > [28578] dbg: diag: module installed: Razor2::Client::Agent, version 2.40 > [28578] dbg: diag: module not installed: Net::Ident ('require' failed) > [28578] dbg: diag: module not installed: IO::Socket::INET6 ('require' > failed) > [28578] dbg: diag: module not installed: IO::Socket::SSL ('require' > failed) > [28578] dbg: diag: module installed: Time::HiRes, version 1.9707 > [28578] dbg: diag: module installed: DBI, version 1.56 > [28578] dbg: diag: module installed: Getopt::Long, version 2.34 > [28578] dbg: ignore: using a test message to lint rules > [28578] dbg: config: using "/etc/mail/spamassassin" for site rules pre > files > [28578] dbg: config: read file /etc/mail/spamassassin/init.pre > [28578] dbg: config: read file /etc/mail/spamassassin/v310.pre > [28578] dbg: config: read file /etc/mail/spamassassin/v312.pre > [28578] dbg: config: read file /etc/mail/spamassassin/v320.pre > [28578] dbg: config: using "/usr/share/spamassassin" for sys rules pre > files > [28578] dbg: config: using "/usr/share/spamassassin" for default rules > dir > [28578] dbg: config: read file > /usr/share/spamassassin/10_default_prefs.cf > [28578] dbg: config: read file /usr/share/spamassassin/10_misc.cf > [28578] dbg: config: read file /usr/share/spamassassin/20_advance_fee.cf > [28578] dbg: config: read file /usr/share/spamassassin/20_anti_ratware.cf > [28578] dbg: config: read file /usr/share/spamassassin/20_body_tests.cf > [28578] dbg: config: read file /usr/share/spamassassin/20_compensate.cf > [28578] dbg: config: read file /usr/share/spamassassin/20_dnsbl_tests.cf > [28578] dbg: config: read file /usr/share/spamassassin/20_drugs.cf > [28578] dbg: config: read file /usr/share/spamassassin/20_dynrdns.cf > [28578] dbg: config: read file > /usr/share/spamassassin/20_fake_helo_tests.cf > [28578] dbg: config: read file /usr/share/spamassassin/20_head_tests.cf > [28578] dbg: config: read file /usr/share/spamassassin/20_html_tests.cf > [28578] dbg: config: read file /usr/share/spamassassin/20_imageinfo.cf > [28578] dbg: config: read file /usr/share/spamassassin/20_meta_tests.cf > [28578] dbg: config: read file /usr/share/spamassassin/20_net_tests.cf > [28578] dbg: config: read file /usr/share/spamassassin/20_phrases.cf > [28578] dbg: config: read file /usr/share/spamassassin/20_porn.cf > [28578] dbg: config: read file /usr/share/spamassassin/20_ratware.cf > [28578] dbg: config: read file /usr/share/spamassassin/20_uri_tests.cf > [28578] dbg: config: read file /usr/share/spamassassin/20_vbounce.cf > [28578] dbg: config: read file /usr/share/spamassassin/23_bayes.cf > [28578] dbg: config: read file /usr/share/spamassassin/25_accessdb.cf > [28578] dbg: config: read file /usr/share/spamassassin/25_antivirus.cf > [28578] dbg: config: read file /usr/share/spamassassin/25_asn.cf > [28578] dbg: config: read file > /usr/share/spamassassin/25_body_tests_es.cf > [28578] dbg: config: read file > /usr/share/spamassassin/25_body_tests_pl.cf > [28578] dbg: config: read file /usr/share/spamassassin/25_dcc.cf > [28578] dbg: config: read file /usr/share/spamassassin/25_dkim.cf > [28578] dbg: config: read file /usr/share/spamassassin/25_domainkeys.cf > [28578] dbg: config: read file /usr/share/spamassassin/25_hashcash.cf > [28578] dbg: config: read file /usr/share/spamassassin/25_pyzor.cf > [28578] dbg: config: read file /usr/share/spamassassin/25_razor2.cf > [28578] dbg: config: read file /usr/share/spamassassin/25_replace.cf > [28578] dbg: config: read file /usr/share/spamassassin/25_spf.cf > [28578] dbg: config: read file /usr/share/spamassassin/25_textcat.cf > [28578] dbg: config: read file /usr/share/spamassassin/25_uribl.cf > [28578] dbg: config: read file /usr/share/spamassassin/30_text_de.cf > [28578] dbg: config: read file /usr/share/spamassassin/30_text_fr.cf > [28578] dbg: config: read file /usr/share/spamassassin/30_text_it.cf > [28578] dbg: config: read file /usr/share/spamassassin/30_text_nl.cf > [28578] dbg: config: read file /usr/share/spamassassin/30_text_pl.cf > [28578] dbg: config: read file /usr/share/spamassassin/30_text_pt_br.cf > [28578] dbg: config: read file /usr/share/spamassassin/50_scores.cf > [28578] dbg: config: read file /usr/share/spamassassin/60_awl.cf > [28578] dbg: config: read file /usr/share/spamassassin/60_shortcircuit.cf > [28578] dbg: config: read file /usr/share/spamassassin/60_whitelist.cf > [28578] dbg: config: read file /usr/share/spamassassin/60_whitelist_dk.cf > [28578] dbg: config: read file > /usr/share/spamassassin/60_whitelist_dkim.cf > [28578] dbg: config: read file > /usr/share/spamassassin/60_whitelist_spf.cf > [28578] dbg: config: read file > /usr/share/spamassassin/60_whitelist_subject.cf > [28578] dbg: config: read file /usr/share/spamassassin/72_active.cf > [28578] dbg: config: using "/etc/mail/spamassassin" for site rules dir > [28578] dbg: config: read file /etc/mail/spamassassin/10_misc.cf > [28578] dbg: config: read file /etc/mail/spamassassin/20_advance_fee.cf > [28578] dbg: config: read file /etc/mail/spamassassin/20_anti_ratware.cf > [28578] dbg: config: read file /etc/mail/spamassassin/20_body_tests.cf > [28578] dbg: config: read file /etc/mail/spamassassin/20_compensate.cf > [28578] dbg: config: read file /etc/mail/spamassassin/20_dnsbl_tests.cf > [28578] dbg: config: read file /etc/mail/spamassassin/20_drugs.cf > [28578] dbg: config: read file > /etc/mail/spamassassin/20_fake_helo_tests.cf > [28578] dbg: config: read file /etc/mail/spamassassin/20_head_tests.cf > [28578] dbg: config: read file /etc/mail/spamassassin/20_html_tests.cf > [28578] dbg: config: read file /etc/mail/spamassassin/20_meta_tests.cf > [28578] dbg: config: read file /etc/mail/spamassassin/20_net_tests.cf > [28578] dbg: config: read file /etc/mail/spamassassin/20_phrases.cf > [28578] dbg: config: read file /etc/mail/spamassassin/20_porn.cf > [28578] dbg: config: read file /etc/mail/spamassassin/20_ratware.cf > [28578] dbg: config: read file /etc/mail/spamassassin/20_uri_tests.cf > [28578] dbg: config: read file /etc/mail/spamassassin/23_bayes.cf > [28578] dbg: config: read file /etc/mail/spamassassin/25_accessdb.cf > [28578] dbg: config: read file /etc/mail/spamassassin/25_antivirus.cf > [28578] dbg: config: read file /etc/mail/spamassassin/25_body_tests_es.cf > [28578] dbg: config: read file /etc/mail/spamassassin/25_body_tests_pl.cf > [28578] dbg: config: read file /etc/mail/spamassassin/25_dcc.cf > [28578] dbg: config: read file /etc/mail/spamassassin/25_dkim.cf > [28578] dbg: config: read file /etc/mail/spamassassin/25_domainkeys.cf > [28578] dbg: config: read file /etc/mail/spamassassin/25_hashcash.cf > [28578] dbg: config: read file /etc/mail/spamassassin/25_pyzor.cf > [28578] dbg: config: read file /etc/mail/spamassassin/25_razor2.cf > [28578] dbg: config: read file /etc/mail/spamassassin/25_replace.cf > [28578] dbg: config: read file /etc/mail/spamassassin/25_spf.cf > [28578] dbg: config: read file /etc/mail/spamassassin/25_textcat.cf > [28578] dbg: config: read file /etc/mail/spamassassin/30_text_de.cf > [28578] dbg: config: read file /etc/mail/spamassassin/30_text_fr.cf > [28578] dbg: config: read file /etc/mail/spamassassin/30_text_it.cf > [28578] dbg: config: read file /etc/mail/spamassassin/30_text_nl.cf > [28578] dbg: config: read file /etc/mail/spamassassin/30_text_pl.cf > [28578] dbg: config: read file /etc/mail/spamassassin/30_text_pt_br.cf > [28578] dbg: config: read file /etc/mail/spamassassin/50_scores.cf > [28578] dbg: config: read file /etc/mail/spamassassin/60_awl.cf > [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_adult.cf > [28578] dbg: config: read file > /etc/mail/spamassassin/70_sare_bayes_poison_nxm.cf > [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_evilnum0.cf > [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_evilnum1.cf > [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_evilnum2.cf > [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_header0.cf > [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_highrisk.cf > [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_html.cf > [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_obfu.cf > [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_obfu0.cf > [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_oem.cf > [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_random.cf > [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_specific.cf > [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_spoof.cf > [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_stocks.cf > [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_unsub.cf > [28578] dbg: config: read file /etc/mail/spamassassin/70_sare_uri0.cf > [28578] dbg: config: read file /etc/mail/spamassassin/70_sc_top200.cf > [28578] dbg: config: read file > /etc/mail/spamassassin/71_sare_redirect_pre3.0.0.cf > [28578] dbg: config: read file > /etc/mail/spamassassin/72_sare_redirect_post3.0.0.cf > [28578] dbg: config: read file /etc/mail/spamassassin/99_FVGT_Tripwire.cf > [28578] dbg: config: read file > /etc/mail/spamassassin/99_sare_fraud_post25x.cf > [28578] dbg: config: read file /etc/mail/spamassassin/Botnet.cf > [28578] dbg: config: read file /etc/mail/spamassassin/antidrug.cf > [28578] dbg: config: read file /etc/mail/spamassassin/bigevil.cf > [28578] dbg: config: read file > /etc/mail/spamassassin/bogus-virus-warnings.cf > [28578] dbg: config: read file /etc/mail/spamassassin/chickenpox.cf > [28578] dbg: config: read file /etc/mail/spamassassin/evilnumbers.cf > [28578] dbg: config: read file /etc/mail/spamassassin/imageinfo.cf > [28578] dbg: config: read file /etc/mail/spamassassin/local.cf > [28578] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf > [28578] dbg: config: read file /etc/mail/spamassassin/tripwire.cf > [28578] dbg: config: using "/root/.spamassassin/user_prefs" for user > prefs file > [28578] dbg: config: read file /root/.spamassassin/user_prefs > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from > @INC > [28578] dbg: plugin: registered > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x94e1208) > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from > @INC > [28578] dbg: plugin: registered > Mail::SpamAssassin::Plugin::Hashcash=HASH(0x94f54bc) > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [28578] dbg: plugin: registered > Mail::SpamAssassin::Plugin::SPF=HASH(0x951d144) > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC > [28578] dbg: pyzor: local tests only, disabling Pyzor > [28578] dbg: plugin: registered > Mail::SpamAssassin::Plugin::Pyzor=HASH(0x95201f0) > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [28578] dbg: razor2: local tests only, skipping Razor > [28578] dbg: plugin: registered > Mail::SpamAssassin::Plugin::Razor2=HASH(0x94f7638) > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::SpamCop from > @INC > [28578] dbg: reporter: local tests only, disabling SpamCop > [28578] dbg: plugin: registered > Mail::SpamAssassin::Plugin::SpamCop=HASH(0x94f96fc) > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC > [28578] dbg: plugin: registered > Mail::SpamAssassin::Plugin::AWL=HASH(0x95c4ef0) > [28578] dbg: plugin: loading > Mail::SpamAssassin::Plugin::AutoLearnThreshold from @INC > [28578] dbg: plugin: registered > Mail::SpamAssassin::Plugin::AutoLearnThreshold=HASH(0x95e7460) > [28578] dbg: plugin: loading > Mail::SpamAssassin::Plugin::WhiteListSubject from @INC > [28578] dbg: plugin: registered > Mail::SpamAssassin::Plugin::WhiteListSubject=HASH(0x95d93e4) > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader > from @INC > [28578] dbg: plugin: registered > Mail::SpamAssassin::Plugin::MIMEHeader=HASH(0x95fba80) > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags > from @INC > [28578] dbg: plugin: registered > Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x960a794) > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::DCC from @INC > [28578] dbg: dcc: local tests only, disabling DCC > [28578] dbg: plugin: registered > Mail::SpamAssassin::Plugin::DCC=HASH(0x95438f8) > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC > [28578] dbg: pyzor: local tests only, disabling Pyzor > [28578] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Pyzor=HASH(0x9d6fc88), already registered > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::SpamCop from > @INC > [28578] dbg: reporter: local tests only, disabling SpamCop > [28578] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SpamCop=HASH(0x9d6fda8), already registered > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC > [28578] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::AWL=HASH(0x9544000), already registered > [28578] dbg: plugin: loading > Mail::SpamAssassin::Plugin::AutoLearnThreshold from @INC > [28578] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::AutoLearnThreshold=HASH(0x9d6fe5c), > already registered > [28578] dbg: plugin: loading > Mail::SpamAssassin::Plugin::WhiteListSubject from @INC > [28578] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::WhiteListSubject=HASH(0x9d6fd9c), already > registered > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader > from @INC > [28578] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::MIMEHeader=HASH(0x95444bc), already > registered > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags > from @INC > [28578] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9d6ffb8), already > registered > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry > from @INC > [28578] dbg: plugin: registered > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x95450e0) > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [28578] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x954514c), already registered > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from > @INC > [28578] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x951d378), already registered > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [28578] dbg: razor2: local tests only, skipping Razor > [28578] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x94e3c18), already registered > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [28578] dbg: plugin: registered > Mail::SpamAssassin::Plugin::ASN=HASH(0x9545644) > [28578] warn: config: configuration file > "/usr/share/spamassassin/20_dynrdns.cf" requires version 3.002002 of > SpamAssassin, but this is code version 3.001009. Maybe you need to use > the -C switch, or remove the old config files? Skipping this file at > /usr/lib/perl5/vendor_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line > 345. > [28578] dbg: config: adding redirector regex: > /^http:\/\/chkpt\.zdnet\.com\/chkpt\/\w+\/(.*)$/i > [28578] dbg: config: adding redirector regex: > /^http:\/\/www(?:\d+)?\.nate\.com\/r\/\w+\/(.*)$/i > [28578] dbg: config: adding redirector regex: > /^http:\/\/.+\.gov\/(?:.*\/)?externalLink\.jhtml\?.*url=(.*?)(?:&.*)?$/i > [28578] dbg: config: adding redirector regex: > /^http:\/\/redir\.internet\.com\/.+?\/.+?\/(.*)$/i > [28578] dbg: config: adding redirector regex: > /^http:\/\/(?:.*?\.)?adtech\.de\/.*(?:;|\|)link=(.*?)(?:;|$)/i > [28578] dbg: config: adding redirector regex: > m'^http.*?/redirect\.php\?.*(?<=[?&])goto=(.*?)(?:$|[&#])'i > [28578] dbg: config: adding redirector regex: > m'^https?:/*(?:[^/]+\.)?emf\d\.com/r\.cfm.*?&r=(.*)'i > [28578] dbg: config: adding redirector regex: > m'/(?:index.php)?\?.*(?<=[?&])URL=(.*?)(?:$|[&#])'i > [28578] dbg: config: adding redirector regex: > m'^http:/*(?:\w+\.)?google(?:\.\w{2,3}){1,2}/url\?.*?(?<=[?&])q=(.*?)(?:$|[&#])'i > > [28578] dbg: config: adding redirector regex: > m'^http:/*(?:\w+\.)?google(?:\.\w{2,3}){1,2}/search\?.*?(?<=[?&])q=[^&]*?(?<=%20|..[=+\s])site:(.*?)(?:$|%20|[\s+&#])'i > > [28578] dbg: config: adding redirector regex: > m'^http:/*(?:\w+\.)?google(?:\.\w{2,3}){1,2}/search\?.*?(?<=[?&])q=[^&]*?(?<=%20|..[=+\s])(?:"|%22)(.*?)(?:$|%22|["\s+&#])'i > > [28578] dbg: config: adding redirector regex: > m'^http:/*(?:\w+\.)?google(?:\.\w{2,3}){1,2}/translate\?.*?(?<=[?&])u=(.*?)(?:$|[&#])'i > > [28578] warn: config: configuration file > "/usr/share/spamassassin/72_active.cf" requires version 3.002002 of > SpamAssassin, but this is code version 3.001009. Maybe you need to use > the -C switch, or remove the old config files? Skipping this file at > /usr/lib/perl5/vendor_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line > 345. > [28578] dbg: config: adding redirector regex: > /^http:\/\/chkpt\.zdnet\.com\/chkpt\/\w+\/(.*)$/i > [28578] dbg: config: adding redirector regex: > /^http:\/\/www(?:\d+)?\.nate\.com\/r\/\w+\/(.*)$/i > [28578] dbg: config: adding redirector regex: > /^http:\/\/.+\.gov\/(?:.*\/)?externalLink\.jhtml\?.*url=(.*?)(?:&.*)?$/i > [28578] dbg: config: adding redirector regex: > /^http:\/\/redir\.internet\.com\/.+?\/.+?\/(.*)$/i > [28578] dbg: config: adding redirector regex: > /^http:\/\/(?:.*?\.)?adtech\.de\/.*(?:;|\|)link=(.*?)(?:;|$)/i > [28578] dbg: config: adding redirector regex: > m'^http.*?/redirect\.php\?.*(?<=[?&])goto=(.*?)(?:$|[&#])'i > [28578] dbg: config: adding redirector regex: > m'^https?:/*(?:[^/]+\.)?emf\d\.com/r\.cfm.*?&r=(.*)'i > [28578] dbg: plugin: fixed relative path: > /etc/mail/spamassassin/Botnet.pm > [28578] dbg: plugin: loading Mail::SpamAssassin::Plugin::Botnet from > /etc/mail/spamassassin/Botnet.pm > [28578] dbg: Botnet: version 0.7 > [28578] dbg: plugin: registered > Mail::SpamAssassin::Plugin::Botnet=HASH(0x9f21950) > [28578] dbg: plugin: > Mail::SpamAssassin::Plugin::Botnet=HASH(0x9f21950) implements > 'parse_config' > [28578] dbg: Botnet: setting botnet_pass_auth to 0 > [28578] dbg: Botnet: setting botnet_pass_trusted to public > [28578] dbg: Botnet: adding ^127\.0\.0\.1$ to botnet_skip_ip > [28578] dbg: Botnet: adding ^10\..*$ to botnet_skip_ip > [28578] dbg: Botnet: adding ^172\.1[6789]\..*$ to botnet_skip_ip > [28578] dbg: Botnet: adding ^172\.2[0-9]\..*$ to botnet_skip_ip > [28578] dbg: Botnet: adding ^172\.3[01]\..*$ to botnet_skip_ip > [28578] dbg: Botnet: adding ^192\.168\..*$ to botnet_skip_ip > [28578] dbg: Botnet: adding ^128\.223\.98\.16$ to botnet_pass_ip > [28578] dbg: Botnet: adding (\.|\A)amazon\.com$ to botnet_pass_domains > [28578] dbg: Botnet: adding (\.|\A)apple\.com$ to botnet_pass_domains > [28578] dbg: Botnet: adding (\.|\A)ebay\.com$ to botnet_pass_domains > [28578] dbg: Botnet: adding (\b|\d)(a|s|d(yn)?)?dsl(\b|\d) to > botnet_clientwords > [28578] dbg: Botnet: adding (\b|\d)cable(\b|\d) to botnet_clientwords > [28578] dbg: Botnet: adding (\b|\d)catv(\b|\d) to botnet_clientwords > [28578] dbg: Botnet: adding (\b|\d)ddns(\b|\d) to botnet_clientwords > [28578] dbg: Botnet: adding (\b|\d)dhcp(\b|\d) to botnet_clientwords > [28578] dbg: Botnet: adding (\b|\d)dial(-?up)?(\b|\d) to > botnet_clientwords > [28578] dbg: Botnet: adding (\b|\d)dip(\b|\d) to botnet_clientwords > [28578] dbg: Botnet: adding (\b|\d)docsis(\b|\d) to botnet_clientwords > [28578] dbg: Botnet: adding (\b|\d)dyn(amic)?(ip)?(\b|\d) to > botnet_clientwords > [28578] dbg: Botnet: adding (\b|\d)modem(\b|\d) to botnet_clientwords > [28578] dbg: Botnet: adding (\b|\d)ppp(\b|\d) to botnet_clientwords > [28578] dbg: Botnet: adding (\b|\d)res(net|ident(ial)?)?(\b|\d) to > botnet_clientwords > [28578] dbg: Botnet: adding (\b|\d)client(\b|\d) to botnet_clientwords > [28578] dbg: Botnet: adding (\b|\d)fixed(\b|\d) to botnet_clientwords > [28578] dbg: Botnet: adding (\b|\d)ip(\b|\d) to botnet_clientwords > [28578] dbg: Botnet: adding (\b|\d)pool(\b|\d) to botnet_clientwords > [28578] dbg: Botnet: adding (\b|\d)static(\b|\d) to botnet_clientwords > [28578] dbg: Botnet: adding (\b|\d)user(\b|\d) to botnet_clientwords > [28578] dbg: Botnet: adding (\b|\d)mail(\b|\d) to botnet_serverwords > [28578] dbg: Botnet: adding (\b|\d)mta(\b|\d) to botnet_serverwords > [28578] dbg: Botnet: adding (\b|\d)mx(\b|\d) to botnet_serverwords > [28578] dbg: Botnet: adding (\b|\d)relay(\b|\d) to botnet_serverwords > [28578] dbg: Botnet: adding (\b|\d)smtp(\b|\d) to botnet_serverwords > [28578] dbg: Botnet: adding (\b|\d)exch(ange)?(\b|\d) to > botnet_serverwords > [28578] info: config: pyzor_path "/usr/bin/pyzor" isn't an executable > [28578] warn: config: SpamAssassin failed to parse line, > "/usr/bin/pyzor" is not valid for "pyzor_path", skipping: pyzor_path > /usr/bin/pyzor > [28578] dbg: plugin: > Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x960a794) implements > 'finish_parsing_end' > [28578] dbg: replacetags: replacing tags > [28578] dbg: replacetags: done replacing tags > [28578] dbg: bayes: tie-ing to DB file R/O /root/.spamassassin/bayes_toks > [28578] dbg: bayes: tie-ing to DB file R/O /root/.spamassassin/bayes_seen > [28578] dbg: bayes: found bayes db version 3 > [28578] dbg: bayes: DB journal sync: last sync: 1186071636 > [28578] dbg: config: score set 2 chosen. > [28578] dbg: message: ---- MIME PARSER START ---- > [28578] dbg: message: main message type: text/plain > [28578] dbg: message: parsing normal part > [28578] dbg: message: added part, type: text/plain > [28578] dbg: message: ---- MIME PARSER END ---- > [28578] dbg: dns: is DNS available? 0 > [28578] dbg: metadata: X-Spam-Relays-Trusted: > [28578] dbg: metadata: X-Spam-Relays-Untrusted: > [28578] dbg: metadata: X-Spam-Relays-Internal: > [28578] dbg: metadata: X-Spam-Relays-External: > [28578] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x95450e0) implements > 'extract_metadata' > [28578] dbg: metadata: X-Relay-Countries: > [28578] dbg: message: no encoding detected > [28578] dbg: plugin: > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x94e1208) implements > 'parsed_metadata' > [28578] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x95450e0) implements > 'parsed_metadata' > [28578] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x9545644) > implements 'parsed_metadata' > [28578] dbg: asn: DNS is not available, skipping ASN checks > [28578] dbg: rules: local tests only, ignoring RBL eval > [28578] dbg: check: running tests for priority: -1000 > [28578] dbg: rules: running header regexp tests; score so far=0 > [28578] dbg: eval: all '*From' addrs: > ignore@compiling.spamassassin.taint.org > [28578] dbg: eval: all '*To' addrs: > [28578] dbg: rules: running body-text per-line regexp tests; score so > far=0 > [28578] dbg: uri: running uri tests; score so far=0 > [28578] dbg: rules: running raw-body-text per-line regexp tests; score > so far=0 > [28578] dbg: rules: running full-text regexp tests; score so far=0 > [28578] dbg: plugin: > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x94e1208) implements > 'check_tick' > [28578] dbg: check: running tests for priority: -950 > [28578] dbg: rules: running header regexp tests; score so far=0 > [28578] dbg: rules: running body-text per-line regexp tests; score so > far=0 > [28578] dbg: uri: running uri tests; score so far=0 > [28578] dbg: rules: running raw-body-text per-line regexp tests; score > so far=0 > [28578] dbg: rules: running full-text regexp tests; score so far=0 > [28578] dbg: check: running tests for priority: -900 > [28578] dbg: rules: running header regexp tests; score so far=0 > [28578] dbg: rules: running body-text per-line regexp tests; score so > far=0 > [28578] dbg: uri: running uri tests; score so far=0 > [28578] dbg: rules: running raw-body-text per-line regexp tests; score > so far=0 > [28578] dbg: rules: running full-text regexp tests; score so far=0 > [28578] dbg: check: running tests for priority: -400 > [28578] dbg: rules: running header regexp tests; score so far=0 > [28578] dbg: rules: running body-text per-line regexp tests; score so > far=0 > [28578] dbg: uri: running uri tests; score so far=0 > [28578] dbg: bayes: DB journal sync: last sync: 1186071636 > [28578] dbg: bayes: corpus size: nspam = 1637, nham = 347 > [28578] dbg: bayes: score = 0.442179793344652 > [28578] dbg: bayes: DB journal sync: last sync: 1186071636 > [28578] dbg: bayes: untie-ing > [28578] dbg: bayes: untie-ing db_toks > [28578] dbg: bayes: untie-ing db_seen > [28578] dbg: rules: running raw-body-text per-line regexp tests; score > so far=0 > [28578] dbg: rules: running full-text regexp tests; score so far=0 > [28578] dbg: check: running tests for priority: 0 > [28578] dbg: rules: running header regexp tests; score so far=0 > [28578] dbg: rules: ran header rule __HAS_MSGID ======> got hit: "<" > [28578] dbg: rules: ran header rule __SANE_MSGID ======> got hit: > "<1186139684@lint_rules> > [28578] dbg: rules: " > [28578] dbg: rules: ran header rule __MSGID_OK_HOST ======> got hit: > "@lint_rules>" > [28578] dbg: rules: ran header rule __BOTNET_NOTRUST ======> got hit: > "negative match" > [28578] dbg: rules: ran header rule __MSGID_OK_DIGITS ======> got hit: > "1186139684" > [28578] dbg: rules: ran eval rule NO_RELAYS ======> got hit > [28578] dbg: Botnet: starting > [28578] dbg: Botnet: no trusted relays > [28578] dbg: Botnet: All skipped/no untrusted > [28578] dbg: Botnet: skipping > [28578] dbg: rules: ran eval rule __UNUSABLE_MSGID ======> got hit > [28578] dbg: rules: running body-text per-line regexp tests; score so > far=-0.001 > [28578] dbg: rules: ran body rule __SARE_HTML_HAS_MSG ======> got hit: > "I" > [28578] dbg: rules: ran body rule __NONEMPTY_BODY ======> got hit: "I" > [28578] dbg: uri: running uri tests; score so far=-0.001 > [28578] dbg: rules: ran eval rule BAYES_50 ======> got hit > [28578] dbg: rules: running raw-body-text per-line regexp tests; score > so far=0 > [28578] dbg: rules: running full-text regexp tests; score so far=0 > [28578] dbg: check: running tests for priority: 500 > [28578] dbg: plugin: > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x94e1208) implements > 'check_post_dnsbl' > [28578] dbg: rules: running meta tests; score so far=0 > [28578] info: rules: meta test CRBOUNCE_MESSAGE has undefined > dependency '__MY_SERVERS_FOUND' > [28578] info: rules: meta test DRUGS_ERECTILE has undefined dependency > '__DRUGS_ERECTILE7' > [28578] info: rules: meta test VBOUNCE_MESSAGE has undefined > dependency '__MY_SERVERS_FOUND' > [28578] info: rules: meta test BOUNCE_MESSAGE has undefined dependency > '__HAVE_BOUNCE_RELAYS' > [28578] info: rules: meta test BOUNCE_MESSAGE has undefined dependency > '__MY_SERVERS_FOUND' > [28578] info: rules: meta test SARE_HEAD_SUBJ_RAND has undefined > dependency 'SARE_XMAIL_SUSP2' > [28578] info: rules: meta test SARE_HEAD_SUBJ_RAND has undefined > dependency 'SARE_HEAD_XAUTH_WARN' > [28578] info: rules: meta test SARE_RD_SAFE has undefined dependency > 'SARE_RD_SAFE_MKSHRT' > [28578] info: rules: meta test SARE_RD_SAFE has undefined dependency > 'SARE_RD_SAFE_GT' > [28578] info: rules: meta test SARE_RD_SAFE has undefined dependency > 'SARE_RD_SAFE_TINY' > [28578] info: rules: meta test VIRUS_WARNING_DOOM_BNC has undefined > dependency 'VIRUS_WARNING_MYDOOM4' > [28578] dbg: rules: running header regexp tests; score so far=2.157 > [28578] dbg: rules: running body-text per-line regexp tests; score so > far=2.157 > [28578] dbg: uri: running uri tests; score so far=2.157 > [28578] dbg: rules: running raw-body-text per-line regexp tests; score > so far=2.157 > [28578] dbg: rules: running full-text regexp tests; score so far=2.157 > [28578] dbg: check: running tests for priority: 1000 > [28578] dbg: rules: running meta tests; score so far=2.157 > [28578] dbg: rules: running header regexp tests; score so far=2.157 > [28578] dbg: rules: running body-text per-line regexp tests; score so > far=2.157 > [28578] dbg: uri: running uri tests; score so far=2.157 > [28578] dbg: rules: running raw-body-text per-line regexp tests; score > so far=2.157 > [28578] dbg: rules: running full-text regexp tests; score so far=2.157 > [28578] dbg: check: is spam? score=2.157 required=5 > [28578] dbg: check: > tests=BAYES_50,MISSING_SUBJECT,NO_RECEIVED,NO_RELAYS,TO_CC_NONE > [28578] dbg: check: > subtests=__BOTNET_NOTRUST,__HAS_MSGID,__MSGID_OK_DIGITS,__MSGID_OK_HOST,__NONEMPTY_BODY,__SANE_MSGID,__SARE_HTML_HAS_MSG,__UNUSABLE_MSGID > > [28578] warn: lint: 3 issues detected, please rerun with debug enabled > for more information > > > > > > > > > >> Run a spamassassin -D --lint and post the output please. >> >> Regards, >> >> --[ UxBoD ]-- >> // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" >> // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B >> // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B >> // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net >> >> ----- Original Message ----- >> From: "Wayne" >> To: "MailScanner discussion" >> Sent: 03 August 2007 09:52:48 o'clock (GMT) Europe/London >> Subject: Error after upgrade >> >> Hi >> >> I upgraded MailScanner and Spamassassin yesterday to 4.62 and 3.2.2 >> (from Clamav SA package). >> >> Previously the package ran without problems however I am getting this >> error. (show below) >> >> Line 396 (first part of the error) seems to contradict or even make >> sense to me - what needs altering >> >> What plugin is missing from the second part? >> >> Because of the error MS runs in a loop. >> >> Afraid I am not highly expert on MS/SA I can install but get lost >> when it throws errors like this. >> >> Anyones help would be appreciated. >> >> - Wayne - >> >> >> I started MailScanner in debug mode:- >> >> In Debugging mode, not forking... >> SpamAssassin temp dir = >> /var/spool/MailScanner/incoming/SpamAssassin-Temp >> config: 'rbl_timeout' is obsolete, use 'rbl_timeout' instead at >> /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Plugin/URIDNSBL.pm >> line 396. >> >> check: no loaded plugin implements 'check_main': cannot scan! at >> /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/PerMsgStatus.pm line >> 164. >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> >> >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Fri Aug 3 14:01:10 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 3 14:01:35 2007 Subject: Using ClamAV to find spam In-Reply-To: <46B323B5.7090706@pixelhammer.com> References: <46B25DE7.8020904@eltofts.homelinux.com> <7EF1F27F7292534D82933F70AB6996CC25CE45@pro-ak-exch01.hosted.pronet.net.nz> <46B26428.9060607@eltofts.homelinux.com> <46B26C54.4030400@eltofts.homelinux.com> <46B323B5.7090706@pixelhammer.com> Message-ID: <46B32716.4090903@ecs.soton.ac.uk> DAve wrote: > Andy Wright wrote: >> Scott Silva wrote: >>> Andy Wright spake the following on 8/2/2007 4:09 PM: >>> >>>> Brent Addis wrote: >>>> >>>>> Try the clamav spamassassin plugin. If your spam scores high >>>>> enough it >>>>> shouldn't be virus scanned and won't scew your stats. >>>>> >>>>> http://www.nabble.com/My-bash-script-to-upload-PDFinfo-daily,-safely-t4115144.html >>>>> >>>>> has an example about halfway through the comments at the bottom. > >>>>> >>>>> Hi list, >>>>> >>>>> I've enabled the "ClamAV Full Message Scan" option and installed the >>>>> sanesecurity sigs. Clam is nicely finding loads (and loads... and >>>>> loads...!) of spam, but of course is causing all these messages to be >>>>> tagged as Virused. This is making my MailWatch screen a sea of >>>>> red and >>>>> skewing the stats such that I appear to be receiving loads of viruses >>>>> instead of spam. >>>>> >>>>> Is it possible to get MailScanner to look at the report from >>>>> ClamAV and >>>>> determine if the message is really spam rather than virused ? > >>>> Hi Brent, >>>> >>>> thanks for the suggestion, although I'm reluctant to add yet more >>>> plugins - most of the spams are already being scored at 20+ (how high >>>> does this have to get before virus scanning is skipped?) >>>> >>>> I guess what I'm after is a way for MailScanner to handle things >>>> differently if the return from ClamAV is "Email.*, Html.*" etc Now >>>> that >>>> Clam seems to be more than just a *virus* finder might it make >>>> sense for >>>> MailScanner to look more closely at the returned result ? Maybe an >>>> excuse for Julian to up the options well beyond the 300 mark ?! >>>> >>>> Andy. >>>> >>> AFAIK all their signatures give sanesecurity in their responses. >>> Maybe an >>> option to look for this and just give spam scores. >>> For me, I don't really care right now what stops them, as long as it >>> doesn't >>> go to the users. Maybe later if I start reporting ratios to someone, >>> I might. >>> >>> >> Most do, but there are a few along the lines of "Email.Phising.RB-1221" >> >> I do report results to clients so this would be a nice thing to be >> able to correct. >> > > I think so as well, see my response to "Re: Request for comments 3 - > Re: MailScanner and password protected archives" I posted on the 25th > of last month. ClamAV does not always equal virus, SA does not always > equal spam. I think the gap will close even more as time goes on. > > The more I think about it the more I like the idea of separating the > identification/tagging from the reporting/action of each message. I am > apparently alone in this. What do you have in mind? Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From campbell at cnpapers.com Fri Aug 3 14:04:17 2007 From: campbell at cnpapers.com (Steve Campbell) Date: Fri Aug 3 14:04:24 2007 Subject: PDFInfo for zips? Message-ID: <46B327D1.7020100@cnpapers.com> I can't find it now, but did I see on the list a plugin for the zips that was very similar to the PDFInfo plugin? I'm starting to get quite a few now. Thanks, as always, for any help. Steve Campbell From sandrews at andrewscompanies.com Fri Aug 3 14:45:45 2007 From: sandrews at andrewscompanies.com (Steven Andrews) Date: Fri Aug 3 14:45:49 2007 Subject: CRM114 css not updating In-Reply-To: <1964AAFBC212F742958F9275BF63DBB04B105A@winchester.andrewscompanies.com> References: <1964AAFBC212F742958F9275BF63DBB04B1058@winchester.andrewscompanies.com><32667771.10581186083926579.JavaMail.root@office.splatnix.net> <1964AAFBC212F742958F9275BF63DBB04B105A@winchester.andrewscompanies.com> Message-ID: <1964AAFBC212F742958F9275BF63DBB04B105F@winchester.andrewscompanies.com> I did notice this morning some volume in the reaver_cache/prob_good directory. Is there a threshold here it has to hit before it start scoring? Still no change in the timestamps on the css files... -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Steven Andrews Sent: Thursday, August 02, 2007 4:19 PM To: MailScanner discussion Subject: RE: CRM114 css not updating Yep; did that. All looks good. Attached. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Thursday, August 02, 2007 3:45 PM To: MailScanner discussion Subject: Re: CRM114 css not updating Steve, Are you able to kill of MailScanner and then run it in debug mode (MailScanner --debug) to see if any errors are getting kicked out when SA runs. All looks fine on the face of it. Does SA lint okay ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From uxbod at splatnix.net Fri Aug 3 14:56:06 2007 From: uxbod at splatnix.net (UxBoD) Date: Fri Aug 3 14:49:35 2007 Subject: CRM114 css not updating In-Reply-To: <1964AAFBC212F742958F9275BF63DBB04B105F@winchester.andrewscompanies.com> Message-ID: <12603203.11061186149366921.JavaMail.root@office.splatnix.net> What happens if you run the crm command interactively, as in crm114.cf, and enter some text? Do this as the user MS is running as. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Steven Andrews" To: "MailScanner discussion" Sent: 03 August 2007 14:45:45 o'clock (GMT) Europe/London Subject: RE: CRM114 css not updating I did notice this morning some volume in the reaver_cache/prob_good directory. Is there a threshold here it has to hit before it start scoring? Still no change in the timestamps on the css files... -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Steven Andrews Sent: Thursday, August 02, 2007 4:19 PM To: MailScanner discussion Subject: RE: CRM114 css not updating Yep; did that. All looks good. Attached. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Thursday, August 02, 2007 3:45 PM To: MailScanner discussion Subject: Re: CRM114 css not updating Steve, Are you able to kill of MailScanner and then run it in debug mode (MailScanner --debug) to see if any errors are getting kicked out when SA runs. All looks fine on the face of it. Does SA lint okay ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From sandrews at andrewscompanies.com Fri Aug 3 14:56:58 2007 From: sandrews at andrewscompanies.com (Steven Andrews) Date: Fri Aug 3 14:57:04 2007 Subject: CRM114 css not updating In-Reply-To: <12603203.11061186149366921.JavaMail.root@office.splatnix.net> References: <1964AAFBC212F742958F9275BF63DBB04B105F@winchester.andrewscompanies.com> <12603203.11061186149366921.JavaMail.root@office.splatnix.net> Message-ID: <1964AAFBC212F742958F9275BF63DBB04B1060@winchester.andrewscompanies.com> As the risk showing my stupidity.... How do I do that? -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Friday, August 03, 2007 9:56 AM To: MailScanner discussion Subject: Re: CRM114 css not updating What happens if you run the crm command interactively, as in crm114.cf, and enter some text? Do this as the user MS is running as. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Steven Andrews" To: "MailScanner discussion" Sent: 03 August 2007 14:45:45 o'clock (GMT) Europe/London Subject: RE: CRM114 css not updating I did notice this morning some volume in the reaver_cache/prob_good directory. Is there a threshold here it has to hit before it start scoring? Still no change in the timestamps on the css files... -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Steven Andrews Sent: Thursday, August 02, 2007 4:19 PM To: MailScanner discussion Subject: RE: CRM114 css not updating Yep; did that. All looks good. Attached. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Thursday, August 02, 2007 3:45 PM To: MailScanner discussion Subject: Re: CRM114 css not updating Steve, Are you able to kill of MailScanner and then run it in debug mode (MailScanner --debug) to see if any errors are getting kicked out when SA runs. All looks fine on the face of it. Does SA lint okay ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From brose at med.wayne.edu Fri Aug 3 15:03:52 2007 From: brose at med.wayne.edu (Rose, Bobby) Date: Fri Aug 3 15:04:08 2007 Subject: The new watermarking feature in 4.62 - an unexpected side effect? In-Reply-To: <33089163.10821186129242896.JavaMail.root@office.splatnix.net> References: <2b2c68de43249c43bf76ad34cdbca67a@solidstatelogic.com> <33089163.10821186129242896.JavaMail.root@office.splatnix.net> Message-ID: <8F2A53954C22554EB75D9643FCCE0C6B0472D406@MED-CORE03-MS1.med.wayne.edu> That's would be an SA rule then. What was the reason for this check again...treating invalid watermark with no sender? Watermarking is still a good idea especially if you have multipled systems but not sure about no sender part. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Friday, August 03, 2007 4:21 AM To: MailScanner discussion Subject: Re: The new watermarking feature in 4.62 - an unexpected side effect? Perhaps instead of marking as Spam straight off a score could be applied instead ? That may be a solution ?? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Martin.Hepworth" To: "MailScanner discussion" Sent: Friday, August 3, 2007 8:57:02 AM (GMT) Europe/London Subject: RE: The new watermarking feature in 4.62 - an unexpected side effect? Quentin I do hope OoO responders die, they are a PITA. A lot of people here have started to used them again (now I've made it easy to do - d'oh) and it caused at least 1 email storm from a bad list. Personally I haven't used them for years - hmm lets see one of the senior IT guys is out, let attack the network... -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Quentin Campbell > Sent: 03 August 2007 08:47 > To: MailScanner discussion > Subject: The new watermarking feature in 4.62 - an unexpected side effect? > > Julian > > Am running 4.62.9-2 on 8 gateways with the new watermarking feature > enabled. > > It has given rise to an increase in requests to "whitelist" addresses > of messages that are being tagged. > > The messages in question have a blank 'From:' address following the > "Our MailScanner believes that the attachment to this message sent to you..." > rubric. > > On inspection these messages are almost always 'vacation' or OoO messages. > It seems that there are good operational reasons for these sorts of > auto responders to set the envelope-sender address to be null. However > this causes them to be tagged as spam by MailScanner if watermarking > is enabled. > > I don't consider it appropriate to whitelist addresses in this > situation but they are 'genuine' messages nonethelees and may well be > missed if people are filtering into a 'junk mail' folder on the tag. I > can't see a way around this. > > I note, however, that JANET in its latest guidance on avoiding > inappropriate e-mail bounces (April 2007) - > http://www.ja.net/cert/email/dontbounce.html - deprecate the use of > vacation/OoO so perhaps we will see the use of OoO responders reduce > in future? > > Quentin > --- > PHONE: +44 191 222 8209 Information Systems and Services (ISS), > Newcastle University, > Newcastle upon Tyne, > FAX: +44 191 222 8765 United Kingdom, NE1 7RU. > ---------------------------------------------------------------------- > -- > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From theodrake at comcast.net Fri Aug 3 15:07:54 2007 From: theodrake at comcast.net (Ed Bruce) Date: Fri Aug 3 15:08:07 2007 Subject: Improved init.d script In-Reply-To: <46B216AD.1010204@ecs.soton.ac.uk> References: <46B216AD.1010204@ecs.soton.ac.uk> Message-ID: <46B336BA.9040602@comcast.net> Julian Field wrote: > Attached are new versions of the RedHat and SuSE /etc/init.d/MailScanner > scripts. > The improvement is obvious when you do > /etc/init.d/MailScanner restart > or > service MailScanner restart > Works on my Redhat AS 3 (2.4.21-47.0.1.ELsmp) and 4 (2.6.9-55.ELsmp) MS servers. -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 249 bytes Desc: OpenPGP digital signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070803/bd148e69/signature.bin From MailScanner at ecs.soton.ac.uk Fri Aug 3 15:14:31 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 3 15:14:56 2007 Subject: Improved init.d script In-Reply-To: <46B336BA.9040602@comcast.net> References: <46B216AD.1010204@ecs.soton.ac.uk> <46B336BA.9040602@comcast.net> Message-ID: <46B33847.30409@ecs.soton.ac.uk> Ed Bruce wrote: > Julian Field wrote: > >> Attached are new versions of the RedHat and SuSE /etc/init.d/MailScanner >> scripts. >> The improvement is obvious when you do >> /etc/init.d/MailScanner restart >> or >> service MailScanner restart >> >> > > Works on my Redhat AS 3 (2.4.21-47.0.1.ELsmp) and 4 (2.6.9-55.ELsmp) MS > servers. > Thanks for all the testing guys, it looks like it works everywhere it's been tried (which is now quite a lot of places). It will be in the next release. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From theodrake at comcast.net Fri Aug 3 15:15:47 2007 From: theodrake at comcast.net (Ed Bruce) Date: Fri Aug 3 15:15:58 2007 Subject: The new watermarking feature in 4.62 - an unexpected side effect? In-Reply-To: <2b2c68de43249c43bf76ad34cdbca67a@solidstatelogic.com> References: <2b2c68de43249c43bf76ad34cdbca67a@solidstatelogic.com> Message-ID: <46B33893.7020701@comcast.net> Martin.Hepworth wrote: > Quentin > > I do hope OoO responders die, they are a PITA. A lot of people here have started to used them again (now I've made it easy to do - d'oh) and it caused at least 1 email storm from a bad list. > > Personally I haven't used them for years - hmm lets see one of the senior IT guys is out, let attack the network... > I believe OoO replies are bad business practice. To me if you are that important you should have an assistant or co-worker that you forward all emails too while you are away. Also if you are stupid enough to have personal emails that nobody should ever read being sent to you at your place of work... Of course your "Confidentiality" notice is a PITA also :) -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 249 bytes Desc: OpenPGP digital signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070803/66ee7401/signature.bin From wjohns at balita.ph Fri Aug 3 15:22:10 2007 From: wjohns at balita.ph (Wayne) Date: Fri Aug 3 15:22:13 2007 Subject: Error after upgrade In-Reply-To: <46B3242E.5060701@ecs.soton.ac.uk> References: <200708030852.l738qkTp030708@balita.ph> <30884165.10941186139270824.JavaMail.root@office.splatnix.net> <200708031120.l73BKo5w029434@balita.ph> <46B3242E.5060701@ecs.soton.ac.uk> Message-ID: <200708031422.l73EM8xq024251@balita.ph> At 13:48 03/08/2007, you wrote: Julian output below many thanks Wayne >Run >MailScanner --debug >and post the results here. >and also >MailScanner --lint >and also >MailScanner -v Please note I did upgrade to SA 3.2.2 as per the file on mailscanner.info our server managers NTT asked me to put it back to 3.1.9 the one recommended by RHEL 4 (they said) so I am aware of the extra files added by 3.2.2 which I have to remove. > MailScanner --debug In Debugging mode, not forking... SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp config: configuration file "/usr/share/spamassassin/20_advance_fee.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_body_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_compensate.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_dnsbl_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_drugs.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_fake_helo_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_head_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_html_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_meta_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_net_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_phrases.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_porn.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_uri_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/23_bayes.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: 'rbl_timeout' is obsolete, use 'rbl_timeout' instead at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Plugin/URIDNSBL.pm line 396. check: no loaded plugin implements 'check_main': cannot scan! at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/PerMsgStatus.pm line 164. > MailScanner --lint Checking version numbers... Version number in MailScanner.conf (4.62.9) is correct. Your envelope_sender_header in spam.assassin.prefs.conf is correct. Checking for SpamAssassin errors (if you use it)... SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp config: configuration file "/usr/share/spamassassin/20_advance_fee.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_advance_fee.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file config: configuration file "/usr/share/spamassassin/20_body_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_body_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file config: configuration file "/usr/share/spamassassin/20_compensate.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_compensate.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file config: configuration file "/usr/share/spamassassin/20_dnsbl_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_dnsbl_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file config: configuration file "/usr/share/spamassassin/20_drugs.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_drugs.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file config: configuration file "/usr/share/spamassassin/20_fake_helo_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_fake_helo_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file config: configuration file "/usr/share/spamassassin/20_head_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_head_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file config: configuration file "/usr/share/spamassassin/20_html_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_html_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file config: configuration file "/usr/share/spamassassin/20_meta_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_meta_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file config: configuration file "/usr/share/spamassassin/20_net_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_net_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file config: configuration file "/usr/share/spamassassin/20_phrases.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_phrases.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file config: configuration file "/usr/share/spamassassin/20_porn.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_porn.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file config: configuration file "/usr/share/spamassassin/20_uri_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/20_uri_tests.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file config: configuration file "/usr/share/spamassassin/23_bayes.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. config: configuration file "/usr/share/spamassassin/23_bayes.cf" requires version 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you need to use the -C switch, or remove the old config files? Skipping this file config: failed to parse line, skipping, in "/usr/share/spamassassin/25_uribl.cf": uridnsbl_timeout 2 config: failed to parse, now a plugin, skipping, in "/etc/mail/spamassassin/local.cf": ok_languages de en gd tl config: 'rbl_timeout' is obsolete, use 'rbl_timeout' instead at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Plugin/URIDNSBL.pm line 396. config: warning: score set for non-existent rule URI_TRUNCATED check: no loaded plugin implements 'check_main': cannot scan! at /usr/lib/perl5/site_perl/5.8.5/Mail/Spam Module Config Command Shell > MailScanner -v Running on Linux xxxx.ph 2.6.9-42.ELsmp #1 SMP Wed Jul 12 23:27:17 EDT 2006 i686 i686 i386 GNU/Linux This is Red Hat Enterprise Linux ES release 4 (Nahant Update 5) This is Perl version 5.008005 (5.8.5) This is MailScanner version 4.62.9 Module versions are: 1.00 AnyDBM_File 1.16 Archive::Zip 1.03 Carp 1.119 Convert::BinHex 1.00 DirHandle 1.05 Fcntl 2.73 File::Basename 2.08 File::Copy 2.01 FileHandle 1.06 File::Path 0.14 File::Temp 0.90 Filesys::Df 1.35 HTML::Entities 3.56 HTML::Parser 2.37 HTML::TokeParser 1.21 IO 1.10 IO::File 1.123 IO::Pipe 1.71 Mail::Header 1.86 Math::BigInt 3.05 MIME::Base64 5.420 MIME::Decoder 5.420 MIME::Decoder::UU 5.420 MIME::Head 5.420 MIME::Parser 3.03 MIME::QuotedPrint 5.420 MIME::Tools 0.11 Net::CIDR 1.08 POSIX 1.14 Scalar::Util 1.77 Socket 1.4 Sys::Hostname::Long 0.18 Sys::Syslog 1.9707 Time::HiRes 1.02 Time::localtime Optional module versions are: 1.29 Archive::Tar 0.21 bignum 1.82 Business::ISBN 1.10 Business::ISBN::Data 0.17 Convert::TNEF 1.08 Data::Dump 1.814 DB_File 1.13 DBD::SQLite 1.56 DBI 1.15 Digest 1.01 Digest::HMAC 2.36 Digest::MD5 2.10 Digest::SHA1 1.00 Encode::Detect 0.17008 Error 0.18 ExtUtils::CBuilder 2.18 ExtUtils::ParseXS 0.44 Inline 1.08 IO::String 1.04 IO::Zlib 2.21 IP::Country 0.20 Mail::ClamAV 3.002002 Mail::SpamAssassin v2.004 Mail::SPF 1.999001 Mail::SPF::Query 0.19 Math::BigRat 0.2808 Module::Build 0.20 Net::CIDR::Lite 0.60 Net::DNS 0.002.2 Net::DNS::Resolver::Programmable 0.31 Net::LDAP 4.004 NetAddr::IP 1.94 Parse::RecDescent missing SAVI 2.56 Test::Harness 0.95 Test::Manifest 1.95 Text::Balanced 1.35 URI 0.7203 version 0.62 YAML Enter a shell command to execute in the text field below. The cd command may be used to change directory for subsequent commands. From wjohns at balita.ph Fri Aug 3 15:23:14 2007 From: wjohns at balita.ph (Wayne) Date: Fri Aug 3 15:23:14 2007 Subject: Error after upgrade In-Reply-To: <223f97700708030545g4d6d5741hfb7ceef46f6b4739@mail.gmail.co m> References: <200708030852.l738qkTp030708@balita.ph> <223f97700708030545g4d6d5741hfb7ceef46f6b4739@mail.gmail.com> Message-ID: <200708031423.l73ENC0x024439@balita.ph> At 13:45 03/08/2007, you wrote: Hi I will look only joined the list today haven't found the archives yet. Wayne > > Hi > > > > I upgraded MailScanner and Spamassassin yesterday to 4.62 and 3.2.2 > > (from Clamav SA package). > ...snip... > > check: no loaded plugin implements 'check_main': cannot scan! at > > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/PerMsgStatus.pm line 164. > >You could've searched the archives and you would've found >http://thread.gmane.org/gmane.mail.virus.mailscanner/53215/focus=53261 >... Denis had more or less this problem, which is due to the Check >plugin not being loaded (in his case he seems to have missed the >v320.pre file entirely). From hvdkooij at vanderkooij.org Fri Aug 3 15:26:00 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Fri Aug 3 15:26:16 2007 Subject: Upgrading Minor versions In-Reply-To: <223f97700708030049m695c6a91laa44c2df243b20f4@mail.gmail.com> References: <2579c6b20708021427w6521a719na27d657ffe7d6b6d@mail.gmail.com> <223f97700708030049m695c6a91laa44c2df243b20f4@mail.gmail.com> Message-ID: On Fri, 3 Aug 2007, Glenn Steen wrote: > So perhaps it is the "tarball install method" that need be amended, > more than the actual numbering scheme... Or one could make it a > documentation thing... Prominently (on the download page) warn to make > a cakcup of the /opt/MailScanner<.whatever> directory prior to > unpacking/installing the tarball. I think one could argue that any admin who does not backup the configuration before doing any software upgrade pretty much is entitled to upgrade problems. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From MailScanner at ecs.soton.ac.uk Fri Aug 3 15:34:07 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 3 15:34:30 2007 Subject: Error after upgrade In-Reply-To: <200708031422.l73EM8xq024251@balita.ph> References: <200708030852.l738qkTp030708@balita.ph> <30884165.10941186139270824.JavaMail.root@office.splatnix.net> <200708031120.l73BKo5w029434@balita.ph> <46B3242E.5060701@ecs.soton.ac.uk> <200708031422.l73EM8xq024251@balita.ph> Message-ID: <46B33CDF.4040806@ecs.soton.ac.uk> 3.1.9 stuff is utter rubbish. Tens of thousands of sites run 3.2.2 on RHEL4 without any issues whatsoever. Downgrading will be asking for trouble. Check you /etc/mail/spamassassin/*.pre files for the main plugin. The main scanning code is all in a plugin now, that has to be enabled or nothing works. But for that to not get set for you means something went very wrong. Wayne wrote: > At 13:48 03/08/2007, you wrote: > > Julian output below many thanks > > Wayne > > >> Run >> MailScanner --debug >> and post the results here. >> and also >> MailScanner --lint >> and also >> MailScanner -v > > Please note I did upgrade to SA 3.2.2 as per the file on > mailscanner.info our server managers NTT asked me to put it back to > 3.1.9 the one recommended by RHEL 4 (they said) so I am aware of the > extra files added by 3.2.2 which I have to remove. > > > MailScanner --debug > In Debugging mode, not forking... > SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp > config: configuration file "/usr/share/spamassassin/20_advance_fee.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_body_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_compensate.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_dnsbl_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_drugs.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file > "/usr/share/spamassassin/20_fake_helo_tests.cf" requires version > 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you > need to use the -C switch, or remove the old config files? Skipping > this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_head_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_html_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_meta_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_net_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_phrases.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_porn.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_uri_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/23_bayes.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: 'rbl_timeout' is obsolete, use 'rbl_timeout' instead at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Plugin/URIDNSBL.pm > line 396. > check: no loaded plugin implements 'check_main': cannot scan! at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/PerMsgStatus.pm line > 164. > > > MailScanner --lint > Checking version numbers... > Version number in MailScanner.conf (4.62.9) is correct. > > Your envelope_sender_header in spam.assassin.prefs.conf is correct. > > Checking for SpamAssassin errors (if you use it)... > SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp > config: configuration file "/usr/share/spamassassin/20_advance_fee.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_advance_fee.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file > config: configuration file "/usr/share/spamassassin/20_body_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_body_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file > config: configuration file "/usr/share/spamassassin/20_compensate.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_compensate.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file > config: configuration file "/usr/share/spamassassin/20_dnsbl_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_dnsbl_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file > config: configuration file "/usr/share/spamassassin/20_drugs.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_drugs.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file > config: configuration file > "/usr/share/spamassassin/20_fake_helo_tests.cf" requires version > 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you > need to use the -C switch, or remove the old config files? Skipping > this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file > "/usr/share/spamassassin/20_fake_helo_tests.cf" requires version > 3.001009 of SpamAssassin, but this is code version 3.002002. Maybe you > need to use the -C switch, or remove the old config files? Skipping > this file > config: configuration file "/usr/share/spamassassin/20_head_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_head_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file > config: configuration file "/usr/share/spamassassin/20_html_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_html_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file > config: configuration file "/usr/share/spamassassin/20_meta_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_meta_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file > config: configuration file "/usr/share/spamassassin/20_net_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_net_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file > config: configuration file "/usr/share/spamassassin/20_phrases.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_phrases.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file > config: configuration file "/usr/share/spamassassin/20_porn.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_porn.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file > config: configuration file "/usr/share/spamassassin/20_uri_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/20_uri_tests.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file > config: configuration file "/usr/share/spamassassin/23_bayes.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Conf/Parser.pm line 372. > config: configuration file "/usr/share/spamassassin/23_bayes.cf" > requires version 3.001009 of SpamAssassin, but this is code version > 3.002002. Maybe you need to use the -C switch, or remove the old > config files? Skipping this file > config: failed to parse line, skipping, in > "/usr/share/spamassassin/25_uribl.cf": uridnsbl_timeout 2 > config: failed to parse, now a plugin, skipping, in > "/etc/mail/spamassassin/local.cf": ok_languages de en gd tl > config: 'rbl_timeout' is obsolete, use 'rbl_timeout' instead at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Plugin/URIDNSBL.pm > line 396. > config: warning: score set for non-existent rule URI_TRUNCATED > > check: no loaded plugin implements 'check_main': cannot scan! at > /usr/lib/perl5/site_perl/5.8.5/Mail/Spam > > Module Config > Command Shell > > > MailScanner -v > Running on > Linux xxxx.ph 2.6.9-42.ELsmp #1 SMP Wed Jul 12 23:27:17 EDT 2006 i686 > i686 i386 GNU/Linux > This is Red Hat Enterprise Linux ES release 4 (Nahant Update 5) > This is Perl version 5.008005 (5.8.5) > > This is MailScanner version 4.62.9 > Module versions are: > 1.00 AnyDBM_File > 1.16 Archive::Zip > 1.03 Carp > 1.119 Convert::BinHex > 1.00 DirHandle > 1.05 Fcntl > 2.73 File::Basename > 2.08 File::Copy > 2.01 FileHandle > 1.06 File::Path > 0.14 File::Temp > 0.90 Filesys::Df > 1.35 HTML::Entities > 3.56 HTML::Parser > 2.37 HTML::TokeParser > 1.21 IO > 1.10 IO::File > 1.123 IO::Pipe > 1.71 Mail::Header > 1.86 Math::BigInt > 3.05 MIME::Base64 > 5.420 MIME::Decoder > 5.420 MIME::Decoder::UU > 5.420 MIME::Head > 5.420 MIME::Parser > 3.03 MIME::QuotedPrint > 5.420 MIME::Tools > 0.11 Net::CIDR > 1.08 POSIX > 1.14 Scalar::Util > 1.77 Socket > 1.4 Sys::Hostname::Long > 0.18 Sys::Syslog > 1.9707 Time::HiRes > 1.02 Time::localtime > > Optional module versions are: > 1.29 Archive::Tar > 0.21 bignum > 1.82 Business::ISBN > 1.10 Business::ISBN::Data > 0.17 Convert::TNEF > 1.08 Data::Dump > 1.814 DB_File > 1.13 DBD::SQLite > 1.56 DBI > 1.15 Digest > 1.01 Digest::HMAC > 2.36 Digest::MD5 > 2.10 Digest::SHA1 > 1.00 Encode::Detect > 0.17008 Error > 0.18 ExtUtils::CBuilder > 2.18 ExtUtils::ParseXS > 0.44 Inline > 1.08 IO::String > 1.04 IO::Zlib > 2.21 IP::Country > 0.20 Mail::ClamAV > 3.002002 Mail::SpamAssassin > v2.004 Mail::SPF > 1.999001 Mail::SPF::Query > 0.19 Math::BigRat > 0.2808 Module::Build > 0.20 Net::CIDR::Lite > 0.60 Net::DNS > 0.002.2 Net::DNS::Resolver::Programmable > 0.31 Net::LDAP > 4.004 NetAddr::IP > 1.94 Parse::RecDescent > missing SAVI > 2.56 Test::Harness > 0.95 Test::Manifest > 1.95 Text::Balanced > 1.35 URI > 0.7203 version > 0.62 YAML > > Enter a shell command to execute in the text field below. The cd > command may be used to change directory for subsequent commands. > > > > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From uxbod at splatnix.net Fri Aug 3 15:59:54 2007 From: uxbod at splatnix.net (UxBoD) Date: Fri Aug 3 15:53:26 2007 Subject: CRM114 css not updating In-Reply-To: <1964AAFBC212F742958F9275BF63DBB04B1060@winchester.andrewscompanies.com> Message-ID: <32245662.11091186153194625.JavaMail.root@office.splatnix.net> /usr/bin/crm -u /etc/mail/spamassassin/crm114 mailreaver.crm run this as the user MS runs as. Type in some text and then Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Steven Andrews" To: "MailScanner discussion" Sent: 03 August 2007 14:56:58 o'clock (GMT) Europe/London Subject: RE: CRM114 css not updating As the risk showing my stupidity.... How do I do that? -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Friday, August 03, 2007 9:56 AM To: MailScanner discussion Subject: Re: CRM114 css not updating What happens if you run the crm command interactively, as in crm114.cf, and enter some text? Do this as the user MS is running as. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Steven Andrews" To: "MailScanner discussion" Sent: 03 August 2007 14:45:45 o'clock (GMT) Europe/London Subject: RE: CRM114 css not updating I did notice this morning some volume in the reaver_cache/prob_good directory. Is there a threshold here it has to hit before it start scoring? Still no change in the timestamps on the css files... -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Steven Andrews Sent: Thursday, August 02, 2007 4:19 PM To: MailScanner discussion Subject: RE: CRM114 css not updating Yep; did that. All looks good. Attached. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Thursday, August 02, 2007 3:45 PM To: MailScanner discussion Subject: Re: CRM114 css not updating Steve, Are you able to kill of MailScanner and then run it in debug mode (MailScanner --debug) to see if any errors are getting kicked out when SA runs. All looks fine on the face of it. Does SA lint okay ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ms-list at alexb.ch Fri Aug 3 16:08:04 2007 From: ms-list at alexb.ch (Alex Broens) Date: Fri Aug 3 16:08:11 2007 Subject: ETP.DAT: mc68k executable (shared demand paged) not stripped Message-ID: <46B344D4.4070101@alexb.ch> Guys Need your help Blackberry's damm ETP.DAT files are being blocked as executable. ETP.DAT: mc68k executable (shared demand paged) not stripped in my filetype.rules.conf I added allow mc68k executable - - also tried the full "mc68k executable (shared demand paged) not stripped" string but they're still being held in Mailwatch's Quarantine. Does anybody have a brilliant/helpful idea of whjat I may be doing wrong? Thanks Alex From sandrews at andrewscompanies.com Fri Aug 3 16:08:19 2007 From: sandrews at andrewscompanies.com (Steven Andrews) Date: Fri Aug 3 16:08:21 2007 Subject: CRM114 css not updating In-Reply-To: <32245662.11091186153194625.JavaMail.root@office.splatnix.net> References: <1964AAFBC212F742958F9275BF63DBB04B1060@winchester.andrewscompanies.com> <32245662.11091186153194625.JavaMail.root@office.splatnix.net> Message-ID: <1964AAFBC212F742958F9275BF63DBB04B1064@winchester.andrewscompanies.com> Ok, yeah...did that according to the faq. It works. I also used the cssdiff tool of CRM to check the spam/nonspam.css files against eachother since I read up that they're really memory maps. Files show the same; nothing added to them. It's calling the program OK, near as I can tell, as I can get it to log to allmail.txt, as well there is some stuff showing up in the reaver_cache under texts and prob_good. Just can't get it to trigger a change in timestamp on the css files that everyone reports; not will it give me a score other than -0.00. Pretty odd, eh? Steve Using username "root". Last login: Fri Aug 3 10:40:10 2007 from 192.168.1.200 [root@spamfilter ~]# /usr/bin/crm -u /etc/mail/spamassassin/crm114 mailreaver.crm boogidy test test test this is a testboogidy test test test this is a test X-CRM114-Version: 20070301-BlameBaltar ( TRE 0.7.5 (LGPL) ) MR-BD9991E2 X-CRM114-CacheID: sfid-20070803_110504_690108_5ACDDE9E Message-Id: (sfid-20070803_110504_690108_5ACDDE9E) X-CRM114-Status: UNSURE ( 0.00 ) X-CRM114-Notice: Please train this message. [root@spamfilter ~]# -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Friday, August 03, 2007 11:00 AM To: MailScanner discussion Subject: Re: CRM114 css not updating /usr/bin/crm -u /etc/mail/spamassassin/crm114 mailreaver.crm run this as the user MS runs as. Type in some text and then Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Steven Andrews" To: "MailScanner discussion" Sent: 03 August 2007 14:56:58 o'clock (GMT) Europe/London Subject: RE: CRM114 css not updating As the risk showing my stupidity.... How do I do that? -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Friday, August 03, 2007 9:56 AM To: MailScanner discussion Subject: Re: CRM114 css not updating What happens if you run the crm command interactively, as in crm114.cf, and enter some text? Do this as the user MS is running as. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Steven Andrews" To: "MailScanner discussion" Sent: 03 August 2007 14:45:45 o'clock (GMT) Europe/London Subject: RE: CRM114 css not updating I did notice this morning some volume in the reaver_cache/prob_good directory. Is there a threshold here it has to hit before it start scoring? Still no change in the timestamps on the css files... -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Steven Andrews Sent: Thursday, August 02, 2007 4:19 PM To: MailScanner discussion Subject: RE: CRM114 css not updating Yep; did that. All looks good. Attached. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Thursday, August 02, 2007 3:45 PM To: MailScanner discussion Subject: Re: CRM114 css not updating Steve, Are you able to kill of MailScanner and then run it in debug mode (MailScanner --debug) to see if any errors are getting kicked out when SA runs. All looks fine on the face of it. Does SA lint okay ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From doc at maddoc.net Fri Aug 3 16:19:28 2007 From: doc at maddoc.net (Doc Schneider) Date: Fri Aug 3 16:19:38 2007 Subject: ETP.DAT: mc68k executable (shared demand paged) not stripped In-Reply-To: <46B344D4.4070101@alexb.ch> References: <46B344D4.4070101@alexb.ch> Message-ID: <46B34780.9000507@maddoc.net> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Alex Broens wrote: > Guys > > Need your help > > Blackberry's damm ETP.DAT files are being blocked as executable. > > ETP.DAT: mc68k executable (shared demand paged) not stripped > > in my filetype.rules.conf > > I added > > allow mc68k executable - - > > also tried the full "mc68k executable (shared demand paged) not > stripped" string but they're still being held in Mailwatch's Quarantine. > > Does anybody have a brilliant/helpful idea of whjat I may be doing wrong? > > Thanks > > Alex > Is the file called mc68k? Try this allow \.dat$ - - I don't see anything in my own filetype.rules.conf that this would be hitting on. But then too I don't allow Crackberry stuff in. 8*) - -- - -Doc Lincoln, NE. http://www.genealogyforyou.com/ http://www.cairnproductions.com/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (GNU/Linux) Comment: Using GnuPG with CentOS - http://enigmail.mozdev.org iD8DBQFGs0eAqOEeBwEpgcsRArrwAJ0UzQQerGuaWBCtrAfQoSKB+Ia2VQCfVZ6B 52KWwgw21vO07U3s/DXNFBk= =okQw -----END PGP SIGNATURE----- From stinkybob at gmail.com Fri Aug 3 16:20:13 2007 From: stinkybob at gmail.com (Eugene MacDougal) Date: Fri Aug 3 16:20:16 2007 Subject: Upgrading Minor versions In-Reply-To: <2579c6b20708021427w6521a719na27d657ffe7d6b6d@mail.gmail.com> References: <2579c6b20708021427w6521a719na27d657ffe7d6b6d@mail.gmail.com> Message-ID: <2579c6b20708030820n4340104ey218933f5edb46c69@mail.gmail.com> I just tried Julian's patch.... no luck. It seems to have changed the paths that it references in the script (ie.. echos and such)..but the archive is still untarred as MailScanner-4.62.9. Probably because that path is hard set in the tar file. That's where the real problem is. -Gene -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070803/30f4c11c/attachment.html From gmatt at nerc.ac.uk Fri Aug 3 16:20:47 2007 From: gmatt at nerc.ac.uk (Greg Matthews) Date: Fri Aug 3 16:21:03 2007 Subject: ETP.DAT: mc68k executable (shared demand paged) not stripped In-Reply-To: <46B344D4.4070101@alexb.ch> References: <46B344D4.4070101@alexb.ch> Message-ID: <46B347CF.8060509@nerc.ac.uk> Alex Broens wrote: > Guys > > Need your help > > Blackberry's damm ETP.DAT files are being blocked as executable. > > ETP.DAT: mc68k executable (shared demand paged) not stripped > > in my filetype.rules.conf > > I added > > allow mc68k executable - - should probably be: allowmc68k-- G > > also tried the full "mc68k executable (shared demand paged) not > stripped" string but they're still being held in Mailwatch's Quarantine. > > Does anybody have a brilliant/helpful idea of whjat I may be doing wrong? > > Thanks > > Alex > -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford -- This message (and any attachments) is for the recipient only. NERC is subject to the Freedom of Information Act 2000 and the contents of this email and any reply you make may be disclosed by NERC unless it is exempt from release under the Act. Any material supplied to NERC may be stored in an electronic records management system. From ms-list at alexb.ch Fri Aug 3 16:25:56 2007 From: ms-list at alexb.ch (Alex Broens) Date: Fri Aug 3 16:26:03 2007 Subject: ETP.DAT: mc68k executable (shared demand paged) not stripped In-Reply-To: <46B34780.9000507@maddoc.net> References: <46B344D4.4070101@alexb.ch> <46B34780.9000507@maddoc.net> Message-ID: <46B34904.2040402@alexb.ch> On 8/3/2007 5:19 PM, Doc Schneider wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Alex Broens wrote: >> Guys >> >> Need your help >> >> Blackberry's damm ETP.DAT files are being blocked as executable. >> >> ETP.DAT: mc68k executable (shared demand paged) not stripped >> >> in my filetype.rules.conf >> >> I added >> >> allow mc68k executable - - >> >> also tried the full "mc68k executable (shared demand paged) not >> stripped" string but they're still being held in Mailwatch's Quarantine. >> >> Does anybody have a brilliant/helpful idea of whjat I may be doing wrong? >> >> Thanks >> >> Alex >> > > Is the file called mc68k? > Try this > allow \.dat$ - - > > I don't see anything in my own filetype.rules.conf that this would be > hitting on. > > But then too I don't allow Crackberry stuff in. 8*) Doc I'm talking filetype - not filename the filename is ETP.DAT the filetype is "mc68k executable (shared demand paged) not stripped" (according to file".exe" :-) Don't really want to open up to fileNAME *.dat Alex From prandal at herefordshire.gov.uk Fri Aug 3 16:33:22 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Fri Aug 3 16:33:32 2007 Subject: CRM114 css not updating In-Reply-To: <1964AAFBC212F742958F9275BF63DBB04B1064@winchester.andrewscompanies.com> References: <1964AAFBC212F742958F9275BF63DBB04B1060@winchester.andrewscompanies.com><32245662.11091186153194625.JavaMail.root@office.splatnix.net> <1964AAFBC212F742958F9275BF63DBB04B1064@winchester.andrewscompanies.com> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA01510EDA@HC-MBX02.herefordshire.gov.uk> Did you chmod +x the .crm files? That's what got it working for me. Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Steven Andrews > Sent: 03 August 2007 16:08 > To: MailScanner discussion > Subject: RE: CRM114 css not updating > > Ok, yeah...did that according to the faq. It works. I also used the > cssdiff tool of CRM to check the spam/nonspam.css files against > eachother since I read up that they're really memory maps. Files show > the same; nothing added to them. > > It's calling the program OK, near as I can tell, as I can get > it to log > to allmail.txt, as well there is some stuff showing up in the > reaver_cache under texts and prob_good. Just can't get it to > trigger a > change in timestamp on the css files that everyone reports; > not will it > give me a score other than -0.00. > > Pretty odd, eh? > > Steve > > Using username "root". > Last login: Fri Aug 3 10:40:10 2007 from 192.168.1.200 > [root@spamfilter ~]# /usr/bin/crm -u /etc/mail/spamassassin/crm114 > mailreaver.crm > boogidy test test test > this is a testboogidy test test test > this is a test > X-CRM114-Version: 20070301-BlameBaltar ( TRE 0.7.5 (LGPL) ) > MR-BD9991E2 > X-CRM114-CacheID: sfid-20070803_110504_690108_5ACDDE9E > Message-Id: (sfid-20070803_110504_690108_5ACDDE9E) > X-CRM114-Status: UNSURE ( 0.00 ) > X-CRM114-Notice: Please train this message. > [root@spamfilter ~]# > > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD > Sent: Friday, August 03, 2007 11:00 AM > To: MailScanner discussion > Subject: Re: CRM114 css not updating > > /usr/bin/crm -u /etc/mail/spamassassin/crm114 mailreaver.crm > > run this as the user MS runs as. Type in some text and then > > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg > --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // > Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 > 2749 SIP Phone: uxbod@sip.splatnix.net > > ----- Original Message ----- > From: "Steven Andrews" > To: "MailScanner discussion" > Sent: 03 August 2007 14:56:58 o'clock (GMT) Europe/London > Subject: RE: CRM114 css not updating > > As the risk showing my stupidity.... How do I do that? > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD > Sent: Friday, August 03, 2007 9:56 AM > To: MailScanner discussion > Subject: Re: CRM114 css not updating > > What happens if you run the crm command interactively, as in > crm114.cf, > and enter some text? Do this as the user MS is running as. > > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg > --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // > Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 > 2749 SIP Phone: uxbod@sip.splatnix.net > > ----- Original Message ----- > From: "Steven Andrews" > To: "MailScanner discussion" > Sent: 03 August 2007 14:45:45 o'clock (GMT) Europe/London > Subject: RE: CRM114 css not updating > > I did notice this morning some volume in the reaver_cache/prob_good > directory. Is there a threshold here it has to hit before it start > scoring? Still no change in the timestamps on the css files... > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Steven > Andrews > Sent: Thursday, August 02, 2007 4:19 PM > To: MailScanner discussion > Subject: RE: CRM114 css not updating > > Yep; did that. All looks good. Attached. > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD > Sent: Thursday, August 02, 2007 3:45 PM > To: MailScanner discussion > Subject: Re: CRM114 css not updating > > Steve, > > Are you able to kill of MailScanner and then run it in debug mode > (MailScanner --debug) to see if any errors are getting kicked out when > SA runs. > > All looks fine on the face of it. Does SA lint okay ? > > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg > --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // > Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 > 2749 SIP Phone: uxbod@sip.splatnix.net > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > > > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From sandrews at andrewscompanies.com Fri Aug 3 16:47:16 2007 From: sandrews at andrewscompanies.com (Steven Andrews) Date: Fri Aug 3 16:47:21 2007 Subject: CRM114 css not updating In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA01510EDA@HC-MBX02.herefordshire.gov.uk> References: <1964AAFBC212F742958F9275BF63DBB04B1060@winchester.andrewscompanies.com><32245662.11091186153194625.JavaMail.root@office.splatnix.net><1964AAFBC212F742958F9275BF63DBB04B1064@winchester.andrewscompanies.com> <7EF0EE5CB3B263488C8C18823239BEBA01510EDA@HC-MBX02.herefordshire.gov.uk> Message-ID: <1964AAFBC212F742958F9275BF63DBB04B1067@winchester.andrewscompanies.com> I did; and they are executing; I can run them manually. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Randal, Phil Sent: Friday, August 03, 2007 11:33 AM To: MailScanner discussion Subject: RE: CRM114 css not updating Did you chmod +x the .crm files? That's what got it working for me. Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of > Steven Andrews > Sent: 03 August 2007 16:08 > To: MailScanner discussion > Subject: RE: CRM114 css not updating > > Ok, yeah...did that according to the faq. It works. I also used the > cssdiff tool of CRM to check the spam/nonspam.css files against > eachother since I read up that they're really memory maps. Files show > the same; nothing added to them. > > It's calling the program OK, near as I can tell, as I can get it to > log to allmail.txt, as well there is some stuff showing up in the > reaver_cache under texts and prob_good. Just can't get it to trigger > a change in timestamp on the css files that everyone reports; not will > it give me a score other than -0.00. > > Pretty odd, eh? > > Steve > > Using username "root". > Last login: Fri Aug 3 10:40:10 2007 from 192.168.1.200 > [root@spamfilter ~]# /usr/bin/crm -u /etc/mail/spamassassin/crm114 > mailreaver.crm boogidy test test test this is a testboogidy test test > test this is a test > X-CRM114-Version: 20070301-BlameBaltar ( TRE 0.7.5 (LGPL) ) > MR-BD9991E2 > X-CRM114-CacheID: sfid-20070803_110504_690108_5ACDDE9E > Message-Id: (sfid-20070803_110504_690108_5ACDDE9E) > X-CRM114-Status: UNSURE ( 0.00 ) > X-CRM114-Notice: Please train this message. > [root@spamfilter ~]# > > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD > Sent: Friday, August 03, 2007 11:00 AM > To: MailScanner discussion > Subject: Re: CRM114 css not updating > > /usr/bin/crm -u /etc/mail/spamassassin/crm114 mailreaver.crm > > run this as the user MS runs as. Type in some text and then > > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg > --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // > Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 > 2749 SIP Phone: uxbod@sip.splatnix.net > > ----- Original Message ----- > From: "Steven Andrews" > To: "MailScanner discussion" > Sent: 03 August 2007 14:56:58 o'clock (GMT) Europe/London > Subject: RE: CRM114 css not updating > > As the risk showing my stupidity.... How do I do that? > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD > Sent: Friday, August 03, 2007 9:56 AM > To: MailScanner discussion > Subject: Re: CRM114 css not updating > > What happens if you run the crm command interactively, as in > crm114.cf, and enter some text? Do this as the user MS is running as. > > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg > --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // > Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 > 2749 SIP Phone: uxbod@sip.splatnix.net > > ----- Original Message ----- > From: "Steven Andrews" > To: "MailScanner discussion" > Sent: 03 August 2007 14:45:45 o'clock (GMT) Europe/London > Subject: RE: CRM114 css not updating > > I did notice this morning some volume in the reaver_cache/prob_good > directory. Is there a threshold here it has to hit before it start > scoring? Still no change in the timestamps on the css files... > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of > Steven Andrews > Sent: Thursday, August 02, 2007 4:19 PM > To: MailScanner discussion > Subject: RE: CRM114 css not updating > > Yep; did that. All looks good. Attached. > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD > Sent: Thursday, August 02, 2007 3:45 PM > To: MailScanner discussion > Subject: Re: CRM114 css not updating > > Steve, > > Are you able to kill of MailScanner and then run it in debug mode > (MailScanner --debug) to see if any errors are getting kicked out when > SA runs. > > All looks fine on the face of it. Does SA lint okay ? > > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg > --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // > Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 > 2749 SIP Phone: uxbod@sip.splatnix.net > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > > > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > > > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From ja at conviator.com Fri Aug 3 16:53:14 2007 From: ja at conviator.com (Jan Agermose) Date: Fri Aug 3 16:53:56 2007 Subject: OT: stopping spam with "421 Message rejected"? Message-ID: <6B59FCF2EFD0334A8147A1BB463F111E02A7C213@mail-17ps.atlarge.net> Hi I've noticed that a lot of mails on some of our mailservers are queued and resend/retried A LOT because of 1. its prob. spam 2. the reciver is "rejecting" the mails with a 421 message and that's just a temp. error, correct? Looks like it as the mails are set in the retry queue on our mailserver. Im sure this is some sysadmin' clever "strike back" idea, but to me it seams like its hitting the middle man :-| its not that we are a openrelay, simply that some customers are hosting domains on our servers, where they have setup forwarding rules to other mailboxes. And yes, have not enabled a spamfilter on our end :-) But am I misunderstanding what is going on here or is it OK to reject spam mails using a temp. error message - are there any rules on that? Best regards Jan 80.160.76.XXX [00000B68] Fri, 03 Aug 2007 00:00:28 +0200 Client session <<< 421 Message rejected 80.160.76.XXX [00000B68] Fri, 03 Aug 2007 00:00:28 +0200 Client session *** 1 1986 00:00:00 ERROR 80.160.76.XXX [00000B68] Fri, 03 Aug 2007 00:00:28 +0200 Client session >>> QUIT SYSTEM [00000B68] Fri, 03 Aug 2007 00:00:28 +0200 Client session Disconnected From uxbod at splatnix.net Fri Aug 3 17:09:33 2007 From: uxbod at splatnix.net (UxBoD) Date: Fri Aug 3 17:03:07 2007 Subject: CRM114 css not updating In-Reply-To: <1964AAFBC212F742958F9275BF63DBB04B1067@winchester.andrewscompanies.com> Message-ID: <21196711.11121186157373384.JavaMail.root@office.splatnix.net> Sorry to be a pain Steven, Can you do a ls -lR /etc/mail/spamassassin/crm* again, and also include the crm114.cf and mailfilter.cf. Must be missing something silly, but I cannot see it :( Friday feeling! Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Steven Andrews" To: "MailScanner discussion" Sent: 03 August 2007 16:47:16 o'clock (GMT) Europe/London Subject: RE: CRM114 css not updating I did; and they are executing; I can run them manually. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Randal, Phil Sent: Friday, August 03, 2007 11:33 AM To: MailScanner discussion Subject: RE: CRM114 css not updating Did you chmod +x the .crm files? That's what got it working for me. Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of > Steven Andrews > Sent: 03 August 2007 16:08 > To: MailScanner discussion > Subject: RE: CRM114 css not updating > > Ok, yeah...did that according to the faq. It works. I also used the > cssdiff tool of CRM to check the spam/nonspam.css files against > eachother since I read up that they're really memory maps. Files show > the same; nothing added to them. > > It's calling the program OK, near as I can tell, as I can get it to > log to allmail.txt, as well there is some stuff showing up in the > reaver_cache under texts and prob_good. Just can't get it to trigger > a change in timestamp on the css files that everyone reports; not will > it give me a score other than -0.00. > > Pretty odd, eh? > > Steve > > Using username "root". > Last login: Fri Aug 3 10:40:10 2007 from 192.168.1.200 > [root@spamfilter ~]# /usr/bin/crm -u /etc/mail/spamassassin/crm114 > mailreaver.crm boogidy test test test this is a testboogidy test test > test this is a test > X-CRM114-Version: 20070301-BlameBaltar ( TRE 0.7.5 (LGPL) ) > MR-BD9991E2 > X-CRM114-CacheID: sfid-20070803_110504_690108_5ACDDE9E > Message-Id: (sfid-20070803_110504_690108_5ACDDE9E) > X-CRM114-Status: UNSURE ( 0.00 ) > X-CRM114-Notice: Please train this message. > [root@spamfilter ~]# > > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD > Sent: Friday, August 03, 2007 11:00 AM > To: MailScanner discussion > Subject: Re: CRM114 css not updating > > /usr/bin/crm -u /etc/mail/spamassassin/crm114 mailreaver.crm > > run this as the user MS runs as. Type in some text and then > > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg > --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // > Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 > 2749 SIP Phone: uxbod@sip.splatnix.net > > ----- Original Message ----- > From: "Steven Andrews" > To: "MailScanner discussion" > Sent: 03 August 2007 14:56:58 o'clock (GMT) Europe/London > Subject: RE: CRM114 css not updating > > As the risk showing my stupidity.... How do I do that? > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD > Sent: Friday, August 03, 2007 9:56 AM > To: MailScanner discussion > Subject: Re: CRM114 css not updating > > What happens if you run the crm command interactively, as in > crm114.cf, and enter some text? Do this as the user MS is running as. > > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg > --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // > Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 > 2749 SIP Phone: uxbod@sip.splatnix.net > > ----- Original Message ----- > From: "Steven Andrews" > To: "MailScanner discussion" > Sent: 03 August 2007 14:45:45 o'clock (GMT) Europe/London > Subject: RE: CRM114 css not updating > > I did notice this morning some volume in the reaver_cache/prob_good > directory. Is there a threshold here it has to hit before it start > scoring? Still no change in the timestamps on the css files... > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of > Steven Andrews > Sent: Thursday, August 02, 2007 4:19 PM > To: MailScanner discussion > Subject: RE: CRM114 css not updating > > Yep; did that. All looks good. Attached. > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD > Sent: Thursday, August 02, 2007 3:45 PM > To: MailScanner discussion > Subject: Re: CRM114 css not updating > > Steve, > > Are you able to kill of MailScanner and then run it in debug mode > (MailScanner --debug) to see if any errors are getting kicked out when > SA runs. > > All looks fine on the face of it. Does SA lint okay ? > > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg > --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // > Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 > 2749 SIP Phone: uxbod@sip.splatnix.net > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > > > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > > > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ms-list at alexb.ch Fri Aug 3 17:16:07 2007 From: ms-list at alexb.ch (Alex Broens) Date: Fri Aug 3 17:16:11 2007 Subject: ETP.DAT: mc68k executable (shared demand paged) not stripped In-Reply-To: <46B347CF.8060509@nerc.ac.uk> References: <46B344D4.4070101@alexb.ch> <46B347CF.8060509@nerc.ac.uk> Message-ID: <46B354C7.3090800@alexb.ch> On 8/3/2007 5:20 PM, Greg Matthews wrote: > Alex Broens wrote: >> Guys >> >> Need your help >> >> Blackberry's damm ETP.DAT files are being blocked as executable. >> >> ETP.DAT: mc68k executable (shared demand paged) not stripped >> >> in my filetype.rules.conf >> >> I added >> >> allow mc68k executable - - > > should probably be: > > allowmc68k-- > Thanks Do& Greg The file format was ok. It does make a BIG difference when you edit/update the rule file on the same machines you're sending the test msgs thru.... edit/update file on box1 - send test msg thru box2? YEAH RIGHT! HOW STUPID CAN I BE! TGIF thanks for your patience Alex From dave.list at pixelhammer.com Fri Aug 3 17:24:44 2007 From: dave.list at pixelhammer.com (DAve) Date: Fri Aug 3 17:26:56 2007 Subject: Using ClamAV to find spam In-Reply-To: <46B32716.4090903@ecs.soton.ac.uk> References: <46B25DE7.8020904@eltofts.homelinux.com> <7EF1F27F7292534D82933F70AB6996CC25CE45@pro-ak-exch01.hosted.pronet.net.nz> <46B26428.9060607@eltofts.homelinux.com> <46B26C54.4030400@eltofts.homelinux.com> <46B323B5.7090706@pixelhammer.com> <46B32716.4090903@ecs.soton.ac.uk> Message-ID: <46B356CC.6000801@pixelhammer.com> Julian Field wrote: >>>> AFAIK all their signatures give sanesecurity in their responses. >>>> Maybe an >>>> option to look for this and just give spam scores. >>>> For me, I don't really care right now what stops them, as long as it >>>> doesn't >>>> go to the users. Maybe later if I start reporting ratios to someone, >>>> I might. >>>> >>>> >>> Most do, but there are a few along the lines of "Email.Phising.RB-1221" >>> >>> I do report results to clients so this would be a nice thing to be >>> able to correct. >>> >> >> I think so as well, see my response to "Re: Request for comments 3 - >> Re: MailScanner and password protected archives" I posted on the 25th >> of last month. ClamAV does not always equal virus, SA does not always >> equal spam. I think the gap will close even more as time goes on. >> >> The more I think about it the more I like the idea of separating the >> identification/tagging from the reporting/action of each message. I am >> apparently alone in this. > What do you have in mind? > > Jules > Well I hesitate to speak up. I prefer to offer solutions before I whine ;^) Here is what I posted earlier, "I see a trend here, maybe it is just me. We (the MS community) have SA rules that catch viruses, we have Clam signatures that catch spam, we have MCP that catches stuff nobody wants to 'see'. It looks like people want a way to decide which messages go to which quarantine based on the rule that was triggered, and not the tool that was used. Some messages caught by Clam should go into the spam quarantine, some messages caught by SA should go to the virus quarantine. Possibly an override map that says "any rule matching this regex is actually treated as spam, any rule matching this regex is actually a virus". This would remove the need for special flags and custom functions. Create only two quarantines, one that is considered safe for release/viewing, one that is not. Then third party tools such as MailWatch could allow a user access to any message stored in quarantine 'safe', and no access to any message in quarantine 'unsafe'. Regardless of what tool/rule/function put them there." So I think something along the line of an override map would solve the problem. Think of it like whitelists and blacklists. A whitelisted address causes a message to be treated like it is ham, a blacklisted address causes a message to be treated like it is spam. This is regardless of the actual scoring. Would it be possible to provide a spamlist/viruslist functionality much like whitelist/blacklist? A message processes normally and before the decision to quarantine is made, the spamlist/viruslist rules are checked and the decision of how to handle the message can then be modified based on the rules. message is scanned message found to be infected - spamlist/viruslist consulted - virus tag found in spamlist/viruslist, message action is 'spam' - message tagged as 'spam' - spam action is 'store' - message stored in spam quarantine message is scanned message found to be spam - spamlist/viruslist consulted - spam rule found in spamlist/viruslist, message action is 'virus' - message tagged as 'infected' - infected action is 'store' - message stored in virus quarantine Do I make sense? DAve -- Three years now I've asked Google why they don't have a logo change for Memorial Day. Why do they choose to do logos for other non-international holidays, but nothing for Veterans? Maybe they forgot who made that choice possible. From richard.siddall at elirion.net Fri Aug 3 18:10:08 2007 From: richard.siddall at elirion.net (Richard Siddall) Date: Fri Aug 3 18:11:27 2007 Subject: improvement to install.sh, was: topdir In-Reply-To: <20070803185111.C22169@xos037.xos.nl> References: <46B35133.2000404@vidoop.com> <20070803180234.B22169@xos037.xos.nl> <46B35BE2.2030500@vidoop.com> <20070803185111.C22169@xos037.xos.nl> Message-ID: <46B36170.1050805@elirion.net> Jos Vos wrote: > On Fri, Aug 03, 2007 at 11:46:26AM -0500, Steven Osborn wrote: > >> I'm running rpmbuild from a script, is there anyway to tell rpmbuild to >> use an rpmmacro file I specify? I see how to specify my own spec file, >> but that's not exactly doing the trick. > > A trick you can use is set $HOME to some temp dir, in which you > generate dynamically the .rpmmacros you wish. > Julian, The above e-mail was just posted to the RPM discussion list and contains a technique MailScanner's install.sh script might use to avoid modifying the user's .rpmmacros, namely setting $HOME to a temp dir and writing the install.sh .rpmmacros in there. If it's generally possible to do this, it might make running the install script less intrusive. Regards, Richard Siddall From uxbod at splatnix.net Fri Aug 3 18:44:30 2007 From: uxbod at splatnix.net (UxBoD) Date: Fri Aug 3 18:38:00 2007 Subject: ETP.DAT: mc68k executable (shared demand paged) not stripped In-Reply-To: <46B354C7.3090800@alexb.ch> Message-ID: <33047514.11181186163070884.JavaMail.root@office.splatnix.net> :) and anybody from the UK it is meant to be sunny this weekend ! :) Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Alex Broens" To: "MailScanner discussion" Sent: 03 August 2007 17:16:07 o'clock (GMT) Europe/London Subject: Re: ETP.DAT: mc68k executable (shared demand paged) not stripped On 8/3/2007 5:20 PM, Greg Matthews wrote: > Alex Broens wrote: >> Guys >> >> Need your help >> >> Blackberry's damm ETP.DAT files are being blocked as executable. >> >> ETP.DAT: mc68k executable (shared demand paged) not stripped >> >> in my filetype.rules.conf >> >> I added >> >> allow mc68k executable - - > > should probably be: > > allowmc68k-- > Thanks Do& Greg The file format was ok. It does make a BIG difference when you edit/update the rule file on the same machines you're sending the test msgs thru.... edit/update file on box1 - send test msg thru box2? YEAH RIGHT! HOW STUPID CAN I BE! TGIF thanks for your patience Alex -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From hvdkooij at vanderkooij.org Fri Aug 3 19:33:48 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Fri Aug 3 19:33:53 2007 Subject: automated response In-Reply-To: <46B29BBD.5060803@fractalweb.com> References: <10708021801.AA54644@solidspace.com> <46B29BBD.5060803@fractalweb.com> Message-ID: On Thu, 2 Aug 2007, Chris Yuzik wrote: > jorge.prado wrote: >> I am currently out of the office, returning Monday, August 6. > > Jorge, > > Wow, that's great to know. Hope you had a good long weekend. :-) Let's break the store. No one is watching ;) At least let us break the autoresponder. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From hvdkooij at vanderkooij.org Fri Aug 3 19:38:08 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Fri Aug 3 19:38:16 2007 Subject: Stopping unwanted character sets Message-ID: Hi, There was some discussion a while ago about stopping messages based on country of orrigin. But I see more use in stopping unwanted charactersets. For example: ------=_NextPart_000_0000_7D761D51.CFA8A7DF Content-Type: text/plain; charset="windows-1251" Content-Transfer-Encoding: quoted-printable I have no need for messages in this character set nor anyone else. Is there a way to filter on these? I can find them if they mess with the subject line in postfix with: /^Subject: =\?KOI8-R\?/ REJECT Russian encoding not allowed here. /^Subject: .* =\?windows-1251\?/ REJECT Crappy propriatary encoding not allowed here. /^Subject: .*\[windows-1251\]/ REJECT Crappy propriatary encoding not allowed here. /^Subject: =\?windows-1252\?/ REJECT Crappy propriatary encoding not allowed here. But what if it is proper MIME message and the character set is used only in some mime parts? Is there a SA ruleset for this? (Or even a postfix trick to do this.) Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From steinkel at pa.net Fri Aug 3 19:55:33 2007 From: steinkel at pa.net (Leland J. Steinke) Date: Fri Aug 3 19:55:38 2007 Subject: zip only spam In-Reply-To: <46B22836.8000308@fractalweb.com> References: <46AF6B68.1040706@pa.net> <46B22836.8000308@fractalweb.com> Message-ID: <46B37A25.8050809@pa.net> Chris Yuzik wrote: > full ZIP_ONLY_SPAM > /encoding\:\s+7bit(\n?)+[\-0-9]+.{1,40}type\:\s+application\/octet-stream\;.{1,40}name\=.{1,40}\.zip.{1,50}disposition\:\s+inline\;.{1,40}filename\=.{1,40}\.zip/is > Sorry, "inline" needs to be changed to "attachment" as well. Leland From vernon at comp-wiz.com Fri Aug 3 21:05:44 2007 From: vernon at comp-wiz.com (Vernon Webb) Date: Fri Aug 3 21:09:11 2007 Subject: MailScanner & Fedora Core 7 Message-ID: <20070803200245.M50381@comp-wiz.com> Can anyone tell me if MailScanner works with Fedora Core 7? I have installed it with calmav, spamassasian, rules du jour, dcc, and pyzor using Sendmail but it doesn't appear that any of the messages are actually being scanned as obvious SPAM mails being tagged by other systems as SPAM are not being tagged at all. Anyone have any idea? From mkercher at nfsmith.com Fri Aug 3 21:23:39 2007 From: mkercher at nfsmith.com (Mike Kercher) Date: Fri Aug 3 21:23:43 2007 Subject: MailScanner & Fedora Core 7 In-Reply-To: <20070803200245.M50381@comp-wiz.com> References: <20070803200245.M50381@comp-wiz.com> Message-ID: <224FA7E11EA39E45843E11CEBBD3A36F189516@HOUPEX01.nfsmith.info> -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Vernon Webb Sent: Friday, August 03, 2007 3:06 PM To: mailscanner@lists.mailscanner.info Subject: MailScanner & Fedora Core 7 Can anyone tell me if MailScanner works with Fedora Core 7? I have installed it with calmav, spamassasian, rules du jour, dcc, and pyzor using Sendmail but it doesn't appear that any of the messages are actually being scanned as obvious SPAM mails being tagged by other systems as SPAM are not being tagged at all. Anyone have any idea? -- Did you chkconfig sendmail off and chkconfig MailScanner on; service MailScanner start? Mike From vernon at comp-wiz.com Fri Aug 3 21:27:47 2007 From: vernon at comp-wiz.com (Vernon Webb) Date: Fri Aug 3 21:29:48 2007 Subject: MailScanner & Fedora Core 7 In-Reply-To: <224FA7E11EA39E45843E11CEBBD3A36F189516@HOUPEX01.nfsmith.info> References: <20070803200245.M50381@comp-wiz.com> <224FA7E11EA39E45843E11CEBBD3A36F189516@HOUPEX01.nfsmith.info> Message-ID: <20070803202725.M47316@comp-wiz.com> An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070803/d3aa1a4b/attachment.html From ssilva at sgvwater.com Fri Aug 3 21:50:24 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Aug 3 21:50:41 2007 Subject: MailScanner --lint error--SOLVED In-Reply-To: <46B30296.8020203@ecs.soton.ac.uk> References: <46B30296.8020203@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 8/3/2007 3:25 AM: > > > Scott Silva wrote: >> Scott Silva spake the following on 8/2/2007 2:08 PM: >> >>> I am getting the following error on my boxes; >>> ERROR: The "envelope_sender_header" in your spam.assassin.prefs.conf >>> ERROR: is not correct, it should match X-BlaBla-MailScanner-From >>> >>> But I have the exact text it is looking for in spam.assassin.prefs.conf >>> Obviously BlaBla is not the organization name. >>> I tried with an = between envelope_sender_header and the header text and >>> without the =. >>> I only changed it because it recommended I have %orgname% in the >>> envelope from >>> and to headers. >>> So it is nagging me to change it, and then complains when I do. Did I >>> suddenly >>> get married this thing? >>> >>> >> I found the problem -- there can be only 1 space between >> envelope_sender_header and the header text. I had 2 spaces and the >> parser must >> think the extra space is part of the header text. >> > I just tried adding some extra spaces in my envelope_sender_header line > and it correctly ignored them. Wonder why it didn't work for you, the > regex uses a \s+ to match the required space in the line. > > Jules > That is why you are the programmer, and I am the lowly consumer. I will try adding a space back and linting again. Putting back spaces and it still lints correctly. Must have been some other problem in the file that was corrected when I removed the spaces between and put one back. Or maybe it was because I had my original line before it but commented out and the parser didn't skip the commented line but read it instead. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Fri Aug 3 21:55:08 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Aug 3 22:00:07 2007 Subject: Upgrading Minor versions In-Reply-To: <46B306A3.40902@ecs.soton.ac.uk> References: <2579c6b20708021427w6521a719na27d657ffe7d6b6d@mail.gmail.com> <223f97700708030049m695c6a91laa44c2df243b20f4@mail.gmail.com> <223f97700708030308n4d0c57d3j360e7283a9def359@mail.gmail.com> <46B306A3.40902@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 8/3/2007 3:42 AM: > > > Res wrote: >> On Fri, 3 Aug 2007, Glenn Steen wrote: >> >>> That scheme was dreamed up in the linux kernel dev... and (perhaps... >>> It was not always so:-) suits them very well. And it has spilled over >>> on a lot of projects. But it is hardly the one true unified version >> >> spilled over to just about 90% of the software around :) >> >>> And it's not sure to cure anything like this, where _packaging >> >> it would, as it would install to /opt as 4.63.b2 etc and not over >> write the existing 4.63 directory. >> >>> will just have to think of some more or less clever way of handling >>> it. >> >> and until such time, its probably going to be recommended those using >> tarball don't bother with such upgrades. >> > I don't need to completely rewrite my version numbering scheme or > anything crazy like that. All I need is to add 4 characters to > install.tar-fns.sh. > > Please try the attached patch. You will discover it adds the build > number in the directory it creates for the new version of MailScanner > you're installing. > > Jules > I was just going to suggest that very solution, but being 8 hours later makes me always late to the party! -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Fri Aug 3 22:16:26 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Aug 3 22:16:42 2007 Subject: The new watermarking feature in 4.62 - an unexpected side effect? In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470B125A14@largo.campus.ncl.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470B125A14@largo.campus.ncl.ac.uk> Message-ID: Quentin Campbell spake the following on 8/3/2007 12:47 AM: > Julian > > Am running 4.62.9-2 on 8 gateways with the new watermarking feature enabled. > > It has given rise to an increase in requests to "whitelist" addresses of messages that are being tagged. > > The messages in question have a blank 'From:' address following the "Our MailScanner believes that the attachment to this message sent to you..." rubric. > > On inspection these messages are almost always 'vacation' or OoO messages. It seems that there are good operational reasons for these sorts of auto responders to set the envelope-sender address to be null. However this causes them to be tagged as spam by MailScanner if watermarking is enabled. > > I don't consider it appropriate to whitelist addresses in this situation but they are 'genuine' messages nonethelees and may well be missed if people are filtering into a 'junk mail' folder on the tag. I can't see a way around this. > > I note, however, that JANET in its latest guidance on avoiding inappropriate e-mail bounces (April 2007) - http://www.ja.net/cert/email/dontbounce.html - deprecate the use of vacation/OoO so perhaps we will see the use of OoO responders reduce in future? > I have seen some of this with read receipts marked as spam with a 0.0 score, but am hoping it is from the transition period.. IE -- message went out before the upgrade, but the receipt came in after. Will keep an eye out. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Fri Aug 3 22:22:57 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Aug 3 22:23:04 2007 Subject: Special rules for archives In-Reply-To: <61266.80.63.34.182.1186136777.squirrel@mail.syska.dk> References: <53675.80.63.34.182.1186133332.squirrel@mail.syska.dk> <46B30122.4030606@ecs.soton.ac.uk> <61266.80.63.34.182.1186136777.squirrel@mail.syska.dk> Message-ID: mikael@syska.dk spake the following on 8/3/2007 3:26 AM: > Hey, > > Will just test that setting ... > > but what if I still want to block some file extensions in the archive ? > with the filenames and filetypes rules ? > Then you need to use rulesets that allow the normally blocked files to the exception users. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Fri Aug 3 22:20:38 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Aug 3 22:25:07 2007 Subject: Error after upgrade In-Reply-To: <200708031120.l73BKo5w029434@balita.ph> References: <200708030852.l738qkTp030708@balita.ph> <30884165.10941186139270824.JavaMail.root@office.splatnix.net> <30884165.10941186139270824.JavaMail.root@office.splatnix.n et> <200708031120.l73BKo5w029434@balita.ph> Message-ID: Wayne spake the following on 8/3/2007 4:20 AM: > At 12:07 03/08/2007, you wrote: > > Many thanks for reply - I have since reinstalled SA 3.1.9 (at the advice > of server managers) we run RHEL 4. > Was your original spamassassin installed via rpm by any chance? -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From mkettler at evi-inc.com Fri Aug 3 22:24:38 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Fri Aug 3 22:26:23 2007 Subject: Stopping unwanted character sets In-Reply-To: References: Message-ID: <46B39D16.1010201@evi-inc.com> Hugo van der Kooij wrote: > Hi, > > There was some discussion a while ago about stopping messages based on > country of orrigin. > > But I see more use in stopping unwanted charactersets. > > For example: > ------=_NextPart_000_0000_7D761D51.CFA8A7DF > Content-Type: text/plain; > charset="windows-1251" > Content-Transfer-Encoding: quoted-printable > > > I have no need for messages in this character set nor anyone else. > > Is there a way to filter on these? If you've got the mimeheader plugin loaded (defaults to being loaded in 3.1.0 and higher) you can use a mimeheader rule something like this should work: mimehader MIME_WIN_1251 Content-Type =~/windows-1251/i > I can find them if they mess with the subject line in postfix with: > > /^Subject: =\?KOI8-R\?/ REJECT Russian encoding not > allowed here. > /^Subject: .* =\?windows-1251\?/ REJECT Crappy propriatary > encoding not allowed here. > /^Subject: .*\[windows-1251\]/ REJECT Crappy propriatary > encoding not allowed here. > /^Subject: =\?windows-1252\?/ REJECT Crappy propriatary > encoding not allowed here. > > But what if it is proper MIME message and the character set is used only > in some mime parts? > > Is there a SA ruleset for this? (Or even a postfix trick to do this.) > > Hugo. > From ssilva at sgvwater.com Fri Aug 3 22:25:05 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Aug 3 22:30:06 2007 Subject: ETP.DAT: mc68k executable (shared demand paged) not stripped In-Reply-To: <46B34904.2040402@alexb.ch> References: <46B344D4.4070101@alexb.ch> <46B34780.9000507@maddoc.net> <46B34904.2040402@alexb.ch> Message-ID: Alex Broens spake the following on 8/3/2007 8:25 AM: > On 8/3/2007 5:19 PM, Doc Schneider wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> Alex Broens wrote: >>> Guys >>> >>> Need your help >>> >>> Blackberry's damm ETP.DAT files are being blocked as executable. >>> >>> ETP.DAT: mc68k executable (shared demand paged) not stripped >>> >>> in my filetype.rules.conf >>> >>> I added >>> >>> allow mc68k executable - - >>> >>> also tried the full "mc68k executable (shared demand paged) not >>> stripped" string but they're still being held in Mailwatch's Quarantine. >>> >>> Does anybody have a brilliant/helpful idea of whjat I may be doing >>> wrong? >>> >>> Thanks >>> >>> Alex >>> >> >> Is the file called mc68k? >> Try this >> allow \.dat$ - - >> >> I don't see anything in my own filetype.rules.conf that this would be >> hitting on. >> >> But then too I don't allow Crackberry stuff in. 8*) > > Doc > > I'm talking filetype - not filename > > the filename is ETP.DAT > the filetype is "mc68k executable (shared demand paged) not stripped" > (according to file".exe" :-) > > Don't really want to open up to fileNAME *.dat > Alex > > Search the archives, as there is a ruleset example to allow these from the blackberry servers and no one else. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Fri Aug 3 22:31:43 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Aug 3 22:35:03 2007 Subject: OT: stopping spam with "421 Message rejected"? In-Reply-To: <6B59FCF2EFD0334A8147A1BB463F111E02A7C213@mail-17ps.atlarge.net> References: <6B59FCF2EFD0334A8147A1BB463F111E02A7C213@mail-17ps.atlarge.net> Message-ID: Jan Agermose spake the following on 8/3/2007 8:53 AM: > Hi > > I've noticed that a lot of mails on some of our mailservers are queued > and resend/retried A LOT because of > > 1. its prob. spam > 2. the reciver is "rejecting" the mails with a 421 message > > and that's just a temp. error, correct? Looks like it as the mails are > set in the retry queue on our mailserver. Im sure this is some sysadmin' > clever "strike back" idea, but to me it seams like its hitting the > middle man :-| > > its not that we are a openrelay, simply that some customers are hosting > domains on our servers, where they have setup forwarding rules to other > mailboxes. And yes, have not enabled a spamfilter on our end :-) > > But am I misunderstanding what is going on here or is it OK to reject > spam mails using a temp. error message - are there any rules on that? > The rule is if it is leaving your network, you are partially responsible. Add a spam filter before you end up on a blacklist. Just my personal warning. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Fri Aug 3 22:35:47 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Aug 3 22:40:05 2007 Subject: MailScanner & Fedora Core 7 In-Reply-To: <20070803200245.M50381@comp-wiz.com> References: <20070803200245.M50381@comp-wiz.com> Message-ID: Vernon Webb spake the following on 8/3/2007 1:05 PM: > Can anyone tell me if MailScanner works with Fedora Core 7? I have installed it with > calmav, spamassasian, rules du jour, dcc, and pyzor using Sendmail but it doesn't > appear that any of the messages are actually being scanned as obvious SPAM mails being > tagged by other systems as SPAM are not being tagged at all. > > Anyone have any idea? It works if installed properly. Do you have a current version? Try a MailScanner --lint and a MailScanner -V and post the results. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From res at ausics.net Fri Aug 3 23:12:59 2007 From: res at ausics.net (Res) Date: Fri Aug 3 23:13:08 2007 Subject: Upgrading Minor versions In-Reply-To: <46B306A3.40902@ecs.soton.ac.uk> References: <2579c6b20708021427w6521a719na27d657ffe7d6b6d@mail.gmail.com> <223f97700708030049m695c6a91laa44c2df243b20f4@mail.gmail.com> <223f97700708030308n4d0c57d3j360e7283a9def359@mail.gmail.com> <46B306A3.40902@ecs.soton.ac.uk> Message-ID: On Fri, 3 Aug 2007, Julian Field wrote: > Please try the attached patch. You will discover it adds the build number in > the directory it creates for the new version of MailScanner you're > installing. root@fox:/tmp# ls /opt MailScanner@ MailScanner-4.62.9/ courier-imap/ newms.txt root@fox:/tmp# cp -a /opt/MailScanner-4.62.9/ /opt/working.MailScanner-4.62.9 root@fox:/tmp# ls /opt MailScanner@ courier-imap/ working.MailScanner-4.62.9/ MailScanner-4.62.9/ newms.txt root@fox:/tmp/MailScanner-install-4.62.9# patch -p0 < ../install.tar-fns.sh.patch patching file install.tar-fns.sh root@fox:/tmp/MailScanner-install-4.62.9# root@fox:/tmp/MailScanner-install-4.62.9# ./install.sh --nomodules --fast to the new version before starting it. ./install.tar-fns.sh: line 249: cd: /opt/MailScanner-4.62.9-2/bin: No such file or directory I have setup tnef (which decodes Microsoft Outlook Rich Text attachments) in the /opt/MailScanner/bin directory. root@fox:/tmp/MailScanner-install-4.62.9# ls /opt MailScanner@ courier-imap/ working.MailScanner-4.62.9/ MailScanner-4.62.9/ newms.txt -- Cheers Res From vernon at comp-wiz.com Sat Aug 4 00:17:20 2007 From: vernon at comp-wiz.com (Vernon Webb) Date: Sat Aug 4 00:23:44 2007 Subject: MailScanner & Fedora Core 7 In-Reply-To: References: <20070803200245.M50381@comp-wiz.com> Message-ID: <20070803231504.M86730@comp-wiz.com> An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070803/25df2fc1/attachment.html From mailscanner at home.carlo65.de Sat Aug 4 00:38:54 2007 From: mailscanner at home.carlo65.de (MailScanner Mailinglist) Date: Sat Aug 4 00:39:11 2007 Subject: AW: RE: CRM114 css not updating In-Reply-To: <1964AAFBC212F742958F9275BF63DBB04B1056@winchester.andrewscompanies.com> References: <1964AAFBC212F742958F9275BF63DBB04B1052@winchester.andrewscompanies.com> <27348762.10521186080876081.JavaMail.root@office.splatnix.net> <1964AAFBC212F742958F9275BF63DBB04B1056@winchester.andrewscompanies.com> Message-ID: <4D1CD0994309F84BA83DF998BF0075AF35AA2DC4@ts-dc2.TS-Webarts.local> Hi, please make sure, you have copied the file /usr/share/doc/crm114-0/mailfilter.cf into the directory /etc/mail/spamassassin/crm114 Please make also sure you have the following files in your /etc/mail/spamassassin/crm114 directory: priolist.mfp allmail.txt rewrites.mfp Last but not least you need to set chmod -R 777 to /etc/mail/spamassassin/crm114/reaver_cache Regards, Roland -----Urspr?ngliche Nachricht----- Von: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Im Auftrag von Steven Andrews Gesendet: Donnerstag, 2. August 2007 20:55 An: MailScanner discussion Betreff: RE: CRM114 css not updating I have. Crm114.cf: # these two lines are necessary to activate the plugin: loadplugin crm114 crm114.pm full CRM114_CHECK eval:check_crm() # this high priority is not necessary. but running late allows us # to compare the CRM score and the result of all previous SA tests # # 899 is chosen as an optimization because FuzzyOCR runs at 900 # thus if CRM already yields a high SA score, # then FuzzyOCR will decide to skip its tests priority CRM114_CHECK 899 # commandline to execute CRM114 # default: crm -u ~/.crm114 mailreaver.crm #crm114_command /usr/local/bin/crm -u /var/amavis/.crm114 mailreaver.crm crm114_command /usr/bin/crm -u /etc/mail/spamassassin/crm114 mailreaver.crm # let SA add header lines to processed mails #add_header all CRM114-Version _CRM114VERSION_ #add_header all CRM114-CacheID _CRM114CACHEID_ add_header all CRM114-Status _CRM114STATUS_ ( _CRM114SCORE_ ) # ignore existing X-Spam or X-Virus headers # if SpamAssassin is called by Amavis then use the same value as Amavis does. # that way a SA-check from Amavis and on from the command line both see the same # Headers # default: 0 #crm114_remove_existing_spam_headers 1 #crm114_remove_existing_virus_headers 1 # dynamic score # values: 0 - returns subtest results # 1 - returns a dynamic CRM score (default) #crm114_dynscore 1 # dynamic score normalization factor # CRM score have much higher absolute values and different signs than SA scores # (usual ham-scores are between 15 and 40, scores from -10 to 10 are undecided, # previously seen spam easily gets -200). # With dynamic scoring the SA score is calculated by: * crm114_dynscore_factor # # Notes: - this has to be a negative number! # - the absolute value should be quite low (certainly <.3, probably <=.2), # otherwise the returned score would override all other tests. # default: calculate factor so that CRM-score -25 yields the SA required spam threshold #crm114_dynscore_factor -0.05 # static scores # without dynamic scores these scores are used # default values are respectively -3, 0, 3 for good, unsure, spam #crm114_staticscore_good -3.0 #crm114_staticscore_unsure 0.0 #crm114_staticscore_spam 3.0 # should CRM114 be trained by SA? # If enabled, then a call to Mail::SpamAssassin->learn() or # "spamassassin --report/--revoke" also calls the CRM114 plugin. # Since CRM114 uses a "Train On Error" strategy the plugin will check the # reported mail and only learn it if it is not not classified correctly. # default: 0 #crm114_learn 1 # should CRM114 be trained by SA-autolearn? # If enabled, then SA's autolearn also calls the CRM114 plugin. # # This is different from :automatic_training: in CRM114's mailfilter.cf # because SA's score is influenced by several different factors while # CRM114 has to rely on its own classification. # But anyway: Only activate this if you know what you're doing! # default: 0 crm114_autolearn 1 # should we preserve the CRM114-CacheID for training or discard it? # # to use the cache enable it in mailfilter.cf, set this option, and # include the CacheID into all Mails with # "add_header all CRM114-CacheID _CRM114CACHEID_" # -- otherwise disable this option to strip CacheIDs before training # default: 0 #crm114_use_cacheid 1 # should we skip CRM114 if other tests indicate certain spam/ham? # # disable CRM114 if a message already has a score (from other tests) # less than crm114_autodisable_negative_score or # more than crm114_autodisable_score. # # default: -999/999 # crm114_autodisable_negative_score -999 # crm114_autodisable_score 999 Output: Using username "root". Last login: Thu Aug 2 14:50:43 2007 from 192.168.1.200 [root@spamfilter ~]# cssutil -b -r /etc/mail/spamassassin/crm114/spam.css Sparse spectra file /etc/mail/spamassassin/crm114/spam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 1 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 [root@spamfilter ~]# cssutil -b -r /etc/mail/spamassassin/crm114/nonspam.css Sparse spectra file /etc/mail/spamassassin/crm114/nonspam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 1 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Thursday, August 02, 2007 2:55 PM To: MailScanner discussion Subject: Re: CRM114 css not updating Have you set it to autolearn in crm114.cf ? What does it show if you do a cssutil -b -r spam.css and cssutil -b -r nonspam.css ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Steven Andrews" To: "MailScanner discussion" Sent: Thursday, August 2, 2007 7:22:43 PM (GMT) Europe/London Subject: CRM114 css not updating Centos4 Been throught wiki regarding install twice and I haven't missed anything. Spamassassin -D --lint shows it's being called and allmail.txt is catching incoming mail; no errors. Running the test from MailWatch, blows up with: [12961] dbg: crm114: crm114_command run 0.01892 ERROR: mailreaver.crm broke. Here's the error\: 0.02391 ERROR: 0.00025 /usr/bin/crm: *ERROR* 9E-05 For some reason, I was unable to write-open the file named allmail.txt 9E-05 Sorry, but this program is very sick and probably should be killed off. 8E-05 This happened at line 165 of file mailreaver.crm 8E-05 [12961] dbg: info: leaving helper-app run mode 0.0009 [12961] dbg: crm114: call_crm returns (UNKNOWN, 0) 0.00069 [12961] warn: crm114: Error. Failed to get CRM114-Status. at /etc/mail/spamassassin/crm114.pm line 315. I kind of expect that since it's running as apache; everything else as root. So, I give it a quick chmod 777 and I get a little further: [13748] dbg: crm114: crm114_command run 0.01103 ERROR: maillib.crm broke. Here's the error\: 0.06252 ERROR: 0.00026 /usr/bin/crm: *WARNING* 9E-05 Couldn't memory-map the table file spam.css 8E-05 I'll try to keep working. 7E-05 This happened at line 662 of file mailreaver.crm 8E-05 [13748] dbg: info: leaving helper-app run mode 0.00086 [13748] dbg: crm114: call_crm returns (UNKNOWN, 0) 0.00069 [13748] warn: crm114: Error. Failed to get CRM114-Status. at /etc/mail/spamassassin/crm114.pm line 315. Got it, Ok, 777 for the css files too. [14005] dbg: crm114: crm114_command run 0.02064 [14005] dbg: crm114: found version 20070301-BlameBaltar ( TRE 0.7.5 (LGPL) ) MR-BD9991E2 0.07717 [14005] dbg: crm114: found CacheID sfid-20070802_140925_378605_D6AAF116 0.00043 [14005] dbg: crm114: found status UNSURE and score 0.00 0.00029 [14005] dbg: crm114: found Notice Please train this message. 0.00029 [14005] dbg: info: leaving helper-app run mode 0.00125 [14005] dbg: crm114: call_crm returns (UNSURE, 0.00) 0.00069 [14005] dbg: crm114: score is 0.0000, translated to SA score: -0.0000, linear factor was -0.2000 Looks good; doublecheck spamassassin -D --lint show no errors. The spam.css and nospam.css files still refuse to move beyond the timestamp from their creation time. Cssutil -b -r /etc/mail/spamassassin/crm114 still shows the base info. Messages have -0.00 CRM114_CHECK. I even set it to use static scoring and all I get is the unsure score. I do see items adding to the /reaver_cache/texts directory. Nothing in the other reaver_cache directories. I've done the requisite banging on my mouse and pounding my head on the desk, but that didn't work either. Any thoughts? -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ---------------------------------------------------------- Diese Nachricht wurde von mailMind(R) auf Viren und andere gefaehrliche Inhalte untersucht und ist sauber. --- mailMind(R) - we have your Mailsecurity in mind! http://www.mailmind.de --- From wjohns at balita.ph Sat Aug 4 00:41:29 2007 From: wjohns at balita.ph (Wayne) Date: Sat Aug 4 00:41:29 2007 Subject: Error after upgrade In-Reply-To: References: <200708030852.l738qkTp030708@balita.ph> <30884165.10941186139270824.JavaMail.root@office.splatnix.net> <30884165.10941186139270824.JavaMail.root@office.splatnix.n et> <200708031120.l73BKo5w029434@balita.ph> Message-ID: <200708032341.l73NfRYq018027@balita.ph> At 22:20 03/08/2007, you wrote: Hi Scott It was as part of the RHEL 4 installation >Was your original spamassassin installed via rpm by any chance? reading between the lines sounds like that could be a problem. :-( Wayne- From wjohns at balita.ph Sat Aug 4 00:53:42 2007 From: wjohns at balita.ph (Wayne) Date: Sat Aug 4 00:53:43 2007 Subject: Error after upgrade In-Reply-To: References: <200708030852.l738qkTp030708@balita.ph> <30884165.10941186139270824.JavaMail.root@office.splatnix.net> <30884165.10941186139270824.JavaMail.root@office.splatnix.n et> <200708031120.l73BKo5w029434@balita.ph> Message-ID: <200708032353.l73Nrf7L019909@balita.ph> At 22:20 03/08/2007, you wrote: Scott It should have said 'yes' in my previous email. - Wayne - >Was your original spamassassin installed via rpm by any chance? From sandrews at andrewscompanies.com Sat Aug 4 01:05:34 2007 From: sandrews at andrewscompanies.com (Steven Andrews) Date: Sat Aug 4 01:05:38 2007 Subject: CRM114 css not updating In-Reply-To: <4D1CD0994309F84BA83DF998BF0075AF35AA2DC4@ts-dc2.TS-Webarts.local> References: <1964AAFBC212F742958F9275BF63DBB04B1052@winchester.andrewscompanies.com><27348762.10521186080876081.JavaMail.root@office.splatnix.net><1964AAFBC212F742958F9275BF63DBB04B1056@winchester.andrewscompanies.com> <4D1CD0994309F84BA83DF998BF0075AF35AA2DC4@ts-dc2.TS-Webarts.local> Message-ID: <1964AAFBC212F742958F9275BF63DBB04B1074@winchester.andrewscompanies.com> Thanks for the tips; been down that road a few dozen times already; but I reviewed it just the same. When I turn that option on, it does actually log mail to allmail.txt and I do get content into the reaver_cache under texts and prob_good; but no updates to the css files and no scoring. Steve -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of MailScanner Mailinglist Sent: Friday, August 03, 2007 7:39 PM To: MailScanner discussion Subject: AW: RE: CRM114 css not updating Hi, please make sure, you have copied the file /usr/share/doc/crm114-0/mailfilter.cf into the directory /etc/mail/spamassassin/crm114 Please make also sure you have the following files in your /etc/mail/spamassassin/crm114 directory: priolist.mfp allmail.txt rewrites.mfp Last but not least you need to set chmod -R 777 to /etc/mail/spamassassin/crm114/reaver_cache Regards, Roland -----Urspr?ngliche Nachricht----- Von: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Im Auftrag von Steven Andrews Gesendet: Donnerstag, 2. August 2007 20:55 An: MailScanner discussion Betreff: RE: CRM114 css not updating I have. Crm114.cf: # these two lines are necessary to activate the plugin: loadplugin crm114 crm114.pm full CRM114_CHECK eval:check_crm() # this high priority is not necessary. but running late allows us # to compare the CRM score and the result of all previous SA tests # # 899 is chosen as an optimization because FuzzyOCR runs at 900 # thus if CRM already yields a high SA score, # then FuzzyOCR will decide to skip its tests priority CRM114_CHECK 899 # commandline to execute CRM114 # default: crm -u ~/.crm114 mailreaver.crm #crm114_command /usr/local/bin/crm -u /var/amavis/.crm114 mailreaver.crm crm114_command /usr/bin/crm -u /etc/mail/spamassassin/crm114 mailreaver.crm # let SA add header lines to processed mails #add_header all CRM114-Version _CRM114VERSION_ #add_header all CRM114-CacheID _CRM114CACHEID_ add_header all CRM114-Status _CRM114STATUS_ ( _CRM114SCORE_ ) # ignore existing X-Spam or X-Virus headers # if SpamAssassin is called by Amavis then use the same value as Amavis does. # that way a SA-check from Amavis and on from the command line both see the same # Headers # default: 0 #crm114_remove_existing_spam_headers 1 #crm114_remove_existing_virus_headers 1 # dynamic score # values: 0 - returns subtest results # 1 - returns a dynamic CRM score (default) #crm114_dynscore 1 # dynamic score normalization factor # CRM score have much higher absolute values and different signs than SA scores # (usual ham-scores are between 15 and 40, scores from -10 to 10 are undecided, # previously seen spam easily gets -200). # With dynamic scoring the SA score is calculated by: * crm114_dynscore_factor # # Notes: - this has to be a negative number! # - the absolute value should be quite low (certainly <.3, probably <=.2), # otherwise the returned score would override all other tests. # default: calculate factor so that CRM-score -25 yields the SA required spam threshold #crm114_dynscore_factor -0.05 # static scores # without dynamic scores these scores are used # default values are respectively -3, 0, 3 for good, unsure, spam #crm114_staticscore_good -3.0 #crm114_staticscore_unsure 0.0 #crm114_staticscore_spam 3.0 # should CRM114 be trained by SA? # If enabled, then a call to Mail::SpamAssassin->learn() or # "spamassassin --report/--revoke" also calls the CRM114 plugin. # Since CRM114 uses a "Train On Error" strategy the plugin will check the # reported mail and only learn it if it is not not classified correctly. # default: 0 #crm114_learn 1 # should CRM114 be trained by SA-autolearn? # If enabled, then SA's autolearn also calls the CRM114 plugin. # # This is different from :automatic_training: in CRM114's mailfilter.cf # because SA's score is influenced by several different factors while # CRM114 has to rely on its own classification. # But anyway: Only activate this if you know what you're doing! # default: 0 crm114_autolearn 1 # should we preserve the CRM114-CacheID for training or discard it? # # to use the cache enable it in mailfilter.cf, set this option, and # include the CacheID into all Mails with # "add_header all CRM114-CacheID _CRM114CACHEID_" # -- otherwise disable this option to strip CacheIDs before training # default: 0 #crm114_use_cacheid 1 # should we skip CRM114 if other tests indicate certain spam/ham? # # disable CRM114 if a message already has a score (from other tests) # less than crm114_autodisable_negative_score or # more than crm114_autodisable_score. # # default: -999/999 # crm114_autodisable_negative_score -999 # crm114_autodisable_score 999 Output: Using username "root". Last login: Thu Aug 2 14:50:43 2007 from 192.168.1.200 [root@spamfilter ~]# cssutil -b -r /etc/mail/spamassassin/crm114/spam.css Sparse spectra file /etc/mail/spamassassin/crm114/spam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 1 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 [root@spamfilter ~]# cssutil -b -r /etc/mail/spamassassin/crm114/nonspam.css Sparse spectra file /etc/mail/spamassassin/crm114/nonspam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 1 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Thursday, August 02, 2007 2:55 PM To: MailScanner discussion Subject: Re: CRM114 css not updating Have you set it to autolearn in crm114.cf ? What does it show if you do a cssutil -b -r spam.css and cssutil -b -r nonspam.css ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Steven Andrews" To: "MailScanner discussion" Sent: Thursday, August 2, 2007 7:22:43 PM (GMT) Europe/London Subject: CRM114 css not updating Centos4 Been throught wiki regarding install twice and I haven't missed anything. Spamassassin -D --lint shows it's being called and allmail.txt is catching incoming mail; no errors. Running the test from MailWatch, blows up with: [12961] dbg: crm114: crm114_command run 0.01892 ERROR: mailreaver.crm broke. Here's the error\: 0.02391 ERROR: 0.00025 /usr/bin/crm: *ERROR* 9E-05 For some reason, I was unable to write-open the file named allmail.txt 9E-05 Sorry, but this program is very sick and probably should be killed off. 8E-05 This happened at line 165 of file mailreaver.crm 8E-05 [12961] dbg: info: leaving helper-app run mode 0.0009 [12961] dbg: crm114: call_crm returns (UNKNOWN, 0) 0.00069 [12961] warn: crm114: Error. Failed to get CRM114-Status. at /etc/mail/spamassassin/crm114.pm line 315. I kind of expect that since it's running as apache; everything else as root. So, I give it a quick chmod 777 and I get a little further: [13748] dbg: crm114: crm114_command run 0.01103 ERROR: maillib.crm broke. Here's the error\: 0.06252 ERROR: 0.00026 /usr/bin/crm: *WARNING* 9E-05 Couldn't memory-map the table file spam.css 8E-05 I'll try to keep working. 7E-05 This happened at line 662 of file mailreaver.crm 8E-05 [13748] dbg: info: leaving helper-app run mode 0.00086 [13748] dbg: crm114: call_crm returns (UNKNOWN, 0) 0.00069 [13748] warn: crm114: Error. Failed to get CRM114-Status. at /etc/mail/spamassassin/crm114.pm line 315. Got it, Ok, 777 for the css files too. [14005] dbg: crm114: crm114_command run 0.02064 [14005] dbg: crm114: found version 20070301-BlameBaltar ( TRE 0.7.5 (LGPL) ) MR-BD9991E2 0.07717 [14005] dbg: crm114: found CacheID sfid-20070802_140925_378605_D6AAF116 0.00043 [14005] dbg: crm114: found status UNSURE and score 0.00 0.00029 [14005] dbg: crm114: found Notice Please train this message. 0.00029 [14005] dbg: info: leaving helper-app run mode 0.00125 [14005] dbg: crm114: call_crm returns (UNSURE, 0.00) 0.00069 [14005] dbg: crm114: score is 0.0000, translated to SA score: -0.0000, linear factor was -0.2000 Looks good; doublecheck spamassassin -D --lint show no errors. The spam.css and nospam.css files still refuse to move beyond the timestamp from their creation time. Cssutil -b -r /etc/mail/spamassassin/crm114 still shows the base info. Messages have -0.00 CRM114_CHECK. I even set it to use static scoring and all I get is the unsure score. I do see items adding to the /reaver_cache/texts directory. Nothing in the other reaver_cache directories. I've done the requisite banging on my mouse and pounding my head on the desk, but that didn't work either. Any thoughts? -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ---------------------------------------------------------- Diese Nachricht wurde von mailMind(R) auf Viren und andere gefaehrliche Inhalte untersucht und ist sauber. --- mailMind(R) - we have your Mailsecurity in mind! http://www.mailmind.de --- -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From v at vladville.com Sat Aug 4 05:18:31 2007 From: v at vladville.com (Vlad Mazek) Date: Sat Aug 4 05:18:35 2007 Subject: zip only spam In-Reply-To: <46AF6E9F.2080502@evi-inc.com> References: <46AF6B68.1040706@pa.net> <46AF6E9F.2080502@evi-inc.com> Message-ID: Actually, they are showing up under random dictionary names names, here are just a few: Cheque.zip Complaint.zip Data.zip log.zip -Vlad On 7/31/07, Matt Kettler wrote: > > Leland J. Steinke wrote: > > Rob Freeman wrote: > >> I see instead of using pdf spam, they have switched to zip spam. I > >> have a rule to block the pdf only spam, but when I changed it to zip, > >> it is not working: > >> > >> # ZIP only spam > >> full ZIP_ONLY_SPAM > >> > /encoding\:\s+7bit(\n?)+[\-0-9]+.{1,40}type\:\s+application\/zip\;.{1,40}name\=.{1,40}\.zip.{1,50}disposition\:\s+inline\;.{1,40}filename\=.{1,40}\.zip/is > > > > > > s/zip/octet-stream/ > > > > Also, these are RAR files. I updated my filetype.rules.conf to block > > 'em, after jacking up the spam score to get the sending IPs blocked as > > well. > > I'm blocking them in filename.rules.conf, the zipfile names are the same > generic > ones used by the old Beagle/Bagel worms.. The rules I had in place forever > ago > appear to be covering it just fine. > > deny ^msg\.zip$ Beagle.H worm Beagle.H worm > deny ^moreinfo\.zip$ Beagle.H worm Beagle.H worm > deny ^attachedfile\.zip$ Beagle.H worm Beagle.H worm > deny ^TextDocument\.zip$ Beagle.H worm Beagle.H worm > deny ^Readme\.zip$ Beagle.H worm Beagle.H worm > deny ^Msginfo\.zip$ Beagle.H worm Beagle.H worm > deny ^Document\.zip$ Beagle.H worm Beagle.H worm > deny ^Info\.zip$ Beagle.H worm Beagle.H worm > deny ^Attacheddocument\.zip$ Beagle.H worm Beagle.H worm > deny ^Text\.zip$ Beagle.H worm Beagle.H worm > deny ^TextFile\.zip$ Beagle.H worm Beagle.H worm > deny ^Letter\.zip$ Beagle.H worm Beagle.H worm > deny ^MoreInfo\.zip$ Beagle.H worm Beagle.H worm > deny ^Message\.zip$ Beagle.H worm Beagle.H worm > deny ^Attach\.zip$ Beagle.K worm Beagle.K worm > deny ^Information\.zip$ Beagle.K worm Beagle.K worm > > > Also, spamassassin is tearing them up, mostly on RBLs: > > X-EVI-MailScanner-SpamCheck: spam, SpamAssassin (score=10.811, required 5, > BAYES_99 3.50, INFO_GREYLIST_DELAYED 0.40, > RCVD_IN_BL_SPAMCOP_NET 1.56, RCVD_IN_SORBS_WEB 1.46, > RCVD_IN_XBL 3.90) > > X-EVI-MailScanner-SpamCheck: spam, SpamAssassin (score=12.311, required 5, > BAYES_99 3.50, DCC_CHECK 1.50, INFO_GREYLIST_DELAYED 0.40, > RCVD_IN_BL_SPAMCOP_NET 1.56, RCVD_IN_SORBS_WEB 1.46, > RCVD_IN_XBL 3.90) > > (note: INFO_GREYLIST_DELAYED is a local rule, and points out the message > was > delayed by my milter-greylist config) > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- -Vlad -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070804/c355b286/attachment.html From res at ausics.net Sat Aug 4 06:20:36 2007 From: res at ausics.net (Res) Date: Sat Aug 4 06:20:44 2007 Subject: Upgrading Minor versions In-Reply-To: <46B306A3.40902@ecs.soton.ac.uk> References: <2579c6b20708021427w6521a719na27d657ffe7d6b6d@mail.gmail.com> <223f97700708030049m695c6a91laa44c2df243b20f4@mail.gmail.com> <223f97700708030308n4d0c57d3j360e7283a9def359@mail.gmail.com> <46B306A3.40902@ecs.soton.ac.uk> Message-ID: Eugene is correct.. >I just tried Julian's patch.... > >no luck. > >It seems to have changed the paths that it references in the script (ie.. >echos and such)..but the archive is still untarred as MailScanner-4.62.9. >Probably because that path is hard set in the tar file. That's where the >real problem is. Correct, all that's needed is the name of the directory changed, which comes back to my earlier suggestion, but none the less the installer script matters not, not when the tarred up directory name is in fact only .9 not .9-2 -- Cheers Res From glenn.steen at gmail.com Sat Aug 4 06:55:35 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Sat Aug 4 06:55:42 2007 Subject: MailScanner & Fedora Core 7 In-Reply-To: <20070803231504.M86730@comp-wiz.com> References: <20070803200245.M50381@comp-wiz.com> <20070803231504.M86730@comp-wiz.com> Message-ID: <223f97700708032255o774c877aw314e46a9dc17444c@mail.gmail.com> On 04/08/07, Vernon Webb wrote: > > > > > MailScanner --lint > > Checking version numbers... > Version number in MailScanner.conf (4.62.9) is correct. > > ERROR: The "envelope_sender_header" in your spam.assassin.prefs.conf > ERROR: is not correct, it should match X-comp-wiz_com-MailScanner-From Two things wit this error: 1) Obviously do what it tells you..... and 2) The underscore character is *not* an allowed header name character, so you need adjust your org-name setting accordingly in MailScanner.conf ... > Checking for SpamAssassin errors (if you use it)... > SpamAssassin temp dir = > /var/spool/MailScanner/incoming/SpamAssassin-Temp > SpamAssassin reported no errors. > MailScanner.conf says "Virus Scanners = f-prot, clamav" > Found these virus scanners installed: f-prot, clamav > =========================================================================== > Ignore errors about failing to find EOCD signature > format error: can't find EOCD signature > at /usr/sbin/MailScanner line 451 > LibClamAV Warning: > ************************************************** > LibClamAV Warning: *** The virus database is older than 7 days. *** > LibClamAV Warning: *** Please update it IMMEDIATELY! *** > LibClamAV Warning: > ************************************************** > LibClamAV Error: cli_loaddb(): No supported database files found in > /var/lib/cla mav/daily.inc Something is seriously wrong with your clamav setup.... Likely a problem with freshclam ... Make this go away;-). As to your origina question.... I would recommend you take some time and read at least the MAQ and some selected pages on the wiki ... you find both via http://wiki.mailscanner.info ... There is both info on making it all more effective as well as perform better... Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From mailscanner at home.carlo65.de Sat Aug 4 07:57:58 2007 From: mailscanner at home.carlo65.de (MailScanner Mailinglist) Date: Sat Aug 4 07:58:27 2007 Subject: AW: RE: RE: CRM114 css not updating In-Reply-To: <1964AAFBC212F742958F9275BF63DBB04B1074@winchester.andrewscompanies.com> References: <1964AAFBC212F742958F9275BF63DBB04B1052@winchester.andrewscompanies.com><27348762.10521186080876081.JavaMail.root@office.splatnix.net><1964AAFBC212F742958F9275BF63DBB04B1056@winchester.andrewscompanies.com> <4D1CD0994309F84BA83DF998BF0075AF35AA2DC4@ts-dc2.TS-Webarts.local> <1964AAFBC212F742958F9275BF63DBB04B1074@winchester.andrewscompanies.com> Message-ID: <4D1CD0994309F84BA83DF998BF0075AF35AA2DC5@ts-dc2.TS-Webarts.local> Steve, just found 2 things in your crm114.cf, which need to be changed: #crm114_learn 1 This line needs to be activated by removing the # Same needs to be done for #crm114_dynscore_factor -0.05 Regards, Roland -----Urspr?ngliche Nachricht----- Von: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Im Auftrag von Steven Andrews Gesendet: Samstag, 4. August 2007 02:06 An: MailScanner discussion Betreff: RE: RE: CRM114 css not updating Thanks for the tips; been down that road a few dozen times already; but I reviewed it just the same. When I turn that option on, it does actually log mail to allmail.txt and I do get content into the reaver_cache under texts and prob_good; but no updates to the css files and no scoring. Steve -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of MailScanner Mailinglist Sent: Friday, August 03, 2007 7:39 PM To: MailScanner discussion Subject: AW: RE: CRM114 css not updating Hi, please make sure, you have copied the file /usr/share/doc/crm114-0/mailfilter.cf into the directory /etc/mail/spamassassin/crm114 Please make also sure you have the following files in your /etc/mail/spamassassin/crm114 directory: priolist.mfp allmail.txt rewrites.mfp Last but not least you need to set chmod -R 777 to /etc/mail/spamassassin/crm114/reaver_cache Regards, Roland -----Urspr?ngliche Nachricht----- Von: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Im Auftrag von Steven Andrews Gesendet: Donnerstag, 2. August 2007 20:55 An: MailScanner discussion Betreff: RE: CRM114 css not updating I have. Crm114.cf: # these two lines are necessary to activate the plugin: loadplugin crm114 crm114.pm full CRM114_CHECK eval:check_crm() # this high priority is not necessary. but running late allows us # to compare the CRM score and the result of all previous SA tests # # 899 is chosen as an optimization because FuzzyOCR runs at 900 # thus if CRM already yields a high SA score, # then FuzzyOCR will decide to skip its tests priority CRM114_CHECK 899 # commandline to execute CRM114 # default: crm -u ~/.crm114 mailreaver.crm #crm114_command /usr/local/bin/crm -u /var/amavis/.crm114 mailreaver.crm crm114_command /usr/bin/crm -u /etc/mail/spamassassin/crm114 mailreaver.crm # let SA add header lines to processed mails #add_header all CRM114-Version _CRM114VERSION_ #add_header all CRM114-CacheID _CRM114CACHEID_ add_header all CRM114-Status _CRM114STATUS_ ( _CRM114SCORE_ ) # ignore existing X-Spam or X-Virus headers # if SpamAssassin is called by Amavis then use the same value as Amavis does. # that way a SA-check from Amavis and on from the command line both see the same # Headers # default: 0 #crm114_remove_existing_spam_headers 1 #crm114_remove_existing_virus_headers 1 # dynamic score # values: 0 - returns subtest results # 1 - returns a dynamic CRM score (default) #crm114_dynscore 1 # dynamic score normalization factor # CRM score have much higher absolute values and different signs than SA scores # (usual ham-scores are between 15 and 40, scores from -10 to 10 are undecided, # previously seen spam easily gets -200). # With dynamic scoring the SA score is calculated by: * crm114_dynscore_factor # # Notes: - this has to be a negative number! # - the absolute value should be quite low (certainly <.3, probably <=.2), # otherwise the returned score would override all other tests. # default: calculate factor so that CRM-score -25 yields the SA required spam threshold #crm114_dynscore_factor -0.05 # static scores # without dynamic scores these scores are used # default values are respectively -3, 0, 3 for good, unsure, spam #crm114_staticscore_good -3.0 #crm114_staticscore_unsure 0.0 #crm114_staticscore_spam 3.0 # should CRM114 be trained by SA? # If enabled, then a call to Mail::SpamAssassin->learn() or # "spamassassin --report/--revoke" also calls the CRM114 plugin. # Since CRM114 uses a "Train On Error" strategy the plugin will check the # reported mail and only learn it if it is not not classified correctly. # default: 0 #crm114_learn 1 # should CRM114 be trained by SA-autolearn? # If enabled, then SA's autolearn also calls the CRM114 plugin. # # This is different from :automatic_training: in CRM114's mailfilter.cf # because SA's score is influenced by several different factors while # CRM114 has to rely on its own classification. # But anyway: Only activate this if you know what you're doing! # default: 0 crm114_autolearn 1 # should we preserve the CRM114-CacheID for training or discard it? # # to use the cache enable it in mailfilter.cf, set this option, and # include the CacheID into all Mails with # "add_header all CRM114-CacheID _CRM114CACHEID_" # -- otherwise disable this option to strip CacheIDs before training # default: 0 #crm114_use_cacheid 1 # should we skip CRM114 if other tests indicate certain spam/ham? # # disable CRM114 if a message already has a score (from other tests) # less than crm114_autodisable_negative_score or # more than crm114_autodisable_score. # # default: -999/999 # crm114_autodisable_negative_score -999 # crm114_autodisable_score 999 Output: Using username "root". Last login: Thu Aug 2 14:50:43 2007 from 192.168.1.200 [root@spamfilter ~]# cssutil -b -r /etc/mail/spamassassin/crm114/spam.css Sparse spectra file /etc/mail/spamassassin/crm114/spam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 1 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 [root@spamfilter ~]# cssutil -b -r /etc/mail/spamassassin/crm114/nonspam.css Sparse spectra file /etc/mail/spamassassin/crm114/nonspam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 1 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Thursday, August 02, 2007 2:55 PM To: MailScanner discussion Subject: Re: CRM114 css not updating Have you set it to autolearn in crm114.cf ? What does it show if you do a cssutil -b -r spam.css and cssutil -b -r nonspam.css ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Steven Andrews" To: "MailScanner discussion" Sent: Thursday, August 2, 2007 7:22:43 PM (GMT) Europe/London Subject: CRM114 css not updating Centos4 Been throught wiki regarding install twice and I haven't missed anything. Spamassassin -D --lint shows it's being called and allmail.txt is catching incoming mail; no errors. Running the test from MailWatch, blows up with: [12961] dbg: crm114: crm114_command run 0.01892 ERROR: mailreaver.crm broke. Here's the error\: 0.02391 ERROR: 0.00025 /usr/bin/crm: *ERROR* 9E-05 For some reason, I was unable to write-open the file named allmail.txt 9E-05 Sorry, but this program is very sick and probably should be killed off. 8E-05 This happened at line 165 of file mailreaver.crm 8E-05 [12961] dbg: info: leaving helper-app run mode 0.0009 [12961] dbg: crm114: call_crm returns (UNKNOWN, 0) 0.00069 [12961] warn: crm114: Error. Failed to get CRM114-Status. at /etc/mail/spamassassin/crm114.pm line 315. I kind of expect that since it's running as apache; everything else as root. So, I give it a quick chmod 777 and I get a little further: [13748] dbg: crm114: crm114_command run 0.01103 ERROR: maillib.crm broke. Here's the error\: 0.06252 ERROR: 0.00026 /usr/bin/crm: *WARNING* 9E-05 Couldn't memory-map the table file spam.css 8E-05 I'll try to keep working. 7E-05 This happened at line 662 of file mailreaver.crm 8E-05 [13748] dbg: info: leaving helper-app run mode 0.00086 [13748] dbg: crm114: call_crm returns (UNKNOWN, 0) 0.00069 [13748] warn: crm114: Error. Failed to get CRM114-Status. at /etc/mail/spamassassin/crm114.pm line 315. Got it, Ok, 777 for the css files too. [14005] dbg: crm114: crm114_command run 0.02064 [14005] dbg: crm114: found version 20070301-BlameBaltar ( TRE 0.7.5 (LGPL) ) MR-BD9991E2 0.07717 [14005] dbg: crm114: found CacheID sfid-20070802_140925_378605_D6AAF116 0.00043 [14005] dbg: crm114: found status UNSURE and score 0.00 0.00029 [14005] dbg: crm114: found Notice Please train this message. 0.00029 [14005] dbg: info: leaving helper-app run mode 0.00125 [14005] dbg: crm114: call_crm returns (UNSURE, 0.00) 0.00069 [14005] dbg: crm114: score is 0.0000, translated to SA score: -0.0000, linear factor was -0.2000 Looks good; doublecheck spamassassin -D --lint show no errors. The spam.css and nospam.css files still refuse to move beyond the timestamp from their creation time. Cssutil -b -r /etc/mail/spamassassin/crm114 still shows the base info. Messages have -0.00 CRM114_CHECK. I even set it to use static scoring and all I get is the unsure score. I do see items adding to the /reaver_cache/texts directory. Nothing in the other reaver_cache directories. I've done the requisite banging on my mouse and pounding my head on the desk, but that didn't work either. Any thoughts? -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ---------------------------------------------------------- Diese Nachricht wurde von mailMind(R) auf Viren und andere gefaehrliche Inhalte untersucht und ist sauber. --- mailMind(R) - we have your Mailsecurity in mind! http://www.mailmind.de --- -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ---------------------------------------------------------- Diese Nachricht wurde von mailMind(R) auf Viren und andere gefaehrliche Inhalte untersucht und ist sauber. --- mailMind(R) - we have your Mailsecurity in mind! http://www.mailmind.de --- From hvdkooij at vanderkooij.org Sat Aug 4 09:10:55 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sat Aug 4 09:11:05 2007 Subject: Stopping unwanted character sets In-Reply-To: <46B39D16.1010201@evi-inc.com> References: <46B39D16.1010201@evi-inc.com> Message-ID: On Fri, 3 Aug 2007, Matt Kettler wrote: > Hugo van der Kooij wrote: >> Hi, >> >> There was some discussion a while ago about stopping messages based on >> country of orrigin. >> >> But I see more use in stopping unwanted charactersets. >> >> For example: >> ------=_NextPart_000_0000_7D761D51.CFA8A7DF >> Content-Type: text/plain; >> charset="windows-1251" >> Content-Transfer-Encoding: quoted-printable >> >> >> I have no need for messages in this character set nor anyone else. >> >> Is there a way to filter on these? > > If you've got the mimeheader plugin loaded (defaults to being loaded in 3.1.0 > and higher) you can use a mimeheader rule > > something like this should work: > mimehader MIME_WIN_1251 Content-Type =~/windows-1251/i It seems it is accepting this fine. Now let us see if there will be hits. And I needed to clean up a bit I noticed. I understood it is not recommended to put your own ruleset in a private file. So they now live in spam.hvdkooij.rules.conf Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From hvdkooij at vanderkooij.org Sat Aug 4 09:21:00 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sat Aug 4 09:21:07 2007 Subject: MailScanner & Fedora Core 7 In-Reply-To: <224FA7E11EA39E45843E11CEBBD3A36F189516@HOUPEX01.nfsmith.info> References: <20070803200245.M50381@comp-wiz.com> <224FA7E11EA39E45843E11CEBBD3A36F189516@HOUPEX01.nfsmith.info> Message-ID: On Fri, 3 Aug 2007, Mike Kercher wrote: > Did you chkconfig sendmail off and chkconfig MailScanner on; service > MailScanner start? If you only did this you need to do a windows thing and reboot the system. That is rather silly if one can stop and restart services manually. chkconfig is there to tell you how a service should start or stop at changing runlevels. But it will not do anything with a service at the moment itself. (The MS manual had this wrong in the past.) Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From hvdkooij at vanderkooij.org Sat Aug 4 09:31:15 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sat Aug 4 09:31:22 2007 Subject: Stopping unwanted character sets In-Reply-To: References: <46B39D16.1010201@evi-inc.com> Message-ID: On Sat, 4 Aug 2007, Hugo van der Kooij wrote: > So they now live in spam.hvdkooij.rules.conf For anyone who wants to use them: # CHARACTERSETS # Chinees mimehader MIME_BIG5 Content-Type =~/big5/i score MIME_BIG5 10 describe MIME_BIG5 Unwanted character set big5 # Chinees mimehader MIME_GB2312 Content-Type =~/GB2312/i score MIME_GB2312 10 describe MIME_GB2312 Unwanted character set GB2312 # Korean mimehader MIME_EUC_KR Content-Type =~/EUC-KR/i score MIME_EUC_KR 10 describe MIME_EUC_KR Unwanted character set EUC-KR # Russian mimehader MIME_KIO8_R Content-Type =~/KIO8-R/i score MIME_KIO8_R 10 describe MIME_KIO8_R Unwanted character set KIO8-R # Crappy windows mimehader MIME_WIN_1251 Content-Type =~/windows-1251/i score MIME_WIN_1251 10 describe MIME_WIN_1251 Unwanted character set windows-1251 # Crappy windows mimehader MIME_WIN_1252 Content-Type =~/windows-1252/i score MIME_WIN_1252 10 describe MIME_WIN_1252 Unwanted character set windows-1252 # Crappy windows mimehader MIME_WIN_1255 Content-Type =~/windows-1255/i score MIME_WIN_1255 10 describe MIME_WIN_1255 Unwanted character set windows-1255 Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From uxbod at splatnix.net Sat Aug 4 10:19:08 2007 From: uxbod at splatnix.net (UxBoD) Date: Sat Aug 4 10:12:28 2007 Subject: AW: RE: RE: CRM114 css not updating In-Reply-To: <4D1CD0994309F84BA83DF998BF0075AF35AA2DC5@ts-dc2.TS-Webarts.local> Message-ID: <19492048.11271186219148677.JavaMail.root@office.splatnix.net> Steven, I checked the listing you emailed me. I presume MS is running under apache:apache as you have files in reaver_cache with those IDs? Have you set the perms on /etc/mail/spamassassin/crm114 ? Also, after making all the changes did you restart MS ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "MailScanner Mailinglist" To: "MailScanner discussion" Sent: 04 August 2007 07:57:58 o'clock (GMT) Europe/London Subject: AW: RE: RE: CRM114 css not updating Steve, just found 2 things in your crm114.cf, which need to be changed: #crm114_learn 1 This line needs to be activated by removing the # Same needs to be done for #crm114_dynscore_factor -0.05 Regards, Roland -----Urspr?ngliche Nachricht----- Von: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Im Auftrag von Steven Andrews Gesendet: Samstag, 4. August 2007 02:06 An: MailScanner discussion Betreff: RE: RE: CRM114 css not updating Thanks for the tips; been down that road a few dozen times already; but I reviewed it just the same. When I turn that option on, it does actually log mail to allmail.txt and I do get content into the reaver_cache under texts and prob_good; but no updates to the css files and no scoring. Steve -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of MailScanner Mailinglist Sent: Friday, August 03, 2007 7:39 PM To: MailScanner discussion Subject: AW: RE: CRM114 css not updating Hi, please make sure, you have copied the file /usr/share/doc/crm114-0/mailfilter.cf into the directory /etc/mail/spamassassin/crm114 Please make also sure you have the following files in your /etc/mail/spamassassin/crm114 directory: priolist.mfp allmail.txt rewrites.mfp Last but not least you need to set chmod -R 777 to /etc/mail/spamassassin/crm114/reaver_cache Regards, Roland -----Urspr?ngliche Nachricht----- Von: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Im Auftrag von Steven Andrews Gesendet: Donnerstag, 2. August 2007 20:55 An: MailScanner discussion Betreff: RE: CRM114 css not updating I have. Crm114.cf: # these two lines are necessary to activate the plugin: loadplugin crm114 crm114.pm full CRM114_CHECK eval:check_crm() # this high priority is not necessary. but running late allows us # to compare the CRM score and the result of all previous SA tests # # 899 is chosen as an optimization because FuzzyOCR runs at 900 # thus if CRM already yields a high SA score, # then FuzzyOCR will decide to skip its tests priority CRM114_CHECK 899 # commandline to execute CRM114 # default: crm -u ~/.crm114 mailreaver.crm #crm114_command /usr/local/bin/crm -u /var/amavis/.crm114 mailreaver.crm crm114_command /usr/bin/crm -u /etc/mail/spamassassin/crm114 mailreaver.crm # let SA add header lines to processed mails #add_header all CRM114-Version _CRM114VERSION_ #add_header all CRM114-CacheID _CRM114CACHEID_ add_header all CRM114-Status _CRM114STATUS_ ( _CRM114SCORE_ ) # ignore existing X-Spam or X-Virus headers # if SpamAssassin is called by Amavis then use the same value as Amavis does. # that way a SA-check from Amavis and on from the command line both see the same # Headers # default: 0 #crm114_remove_existing_spam_headers 1 #crm114_remove_existing_virus_headers 1 # dynamic score # values: 0 - returns subtest results # 1 - returns a dynamic CRM score (default) #crm114_dynscore 1 # dynamic score normalization factor # CRM score have much higher absolute values and different signs than SA scores # (usual ham-scores are between 15 and 40, scores from -10 to 10 are undecided, # previously seen spam easily gets -200). # With dynamic scoring the SA score is calculated by: * crm114_dynscore_factor # # Notes: - this has to be a negative number! # - the absolute value should be quite low (certainly <.3, probably <=.2), # otherwise the returned score would override all other tests. # default: calculate factor so that CRM-score -25 yields the SA required spam threshold #crm114_dynscore_factor -0.05 # static scores # without dynamic scores these scores are used # default values are respectively -3, 0, 3 for good, unsure, spam #crm114_staticscore_good -3.0 #crm114_staticscore_unsure 0.0 #crm114_staticscore_spam 3.0 # should CRM114 be trained by SA? # If enabled, then a call to Mail::SpamAssassin->learn() or # "spamassassin --report/--revoke" also calls the CRM114 plugin. # Since CRM114 uses a "Train On Error" strategy the plugin will check the # reported mail and only learn it if it is not not classified correctly. # default: 0 #crm114_learn 1 # should CRM114 be trained by SA-autolearn? # If enabled, then SA's autolearn also calls the CRM114 plugin. # # This is different from :automatic_training: in CRM114's mailfilter.cf # because SA's score is influenced by several different factors while # CRM114 has to rely on its own classification. # But anyway: Only activate this if you know what you're doing! # default: 0 crm114_autolearn 1 # should we preserve the CRM114-CacheID for training or discard it? # # to use the cache enable it in mailfilter.cf, set this option, and # include the CacheID into all Mails with # "add_header all CRM114-CacheID _CRM114CACHEID_" # -- otherwise disable this option to strip CacheIDs before training # default: 0 #crm114_use_cacheid 1 # should we skip CRM114 if other tests indicate certain spam/ham? # # disable CRM114 if a message already has a score (from other tests) # less than crm114_autodisable_negative_score or # more than crm114_autodisable_score. # # default: -999/999 # crm114_autodisable_negative_score -999 # crm114_autodisable_score 999 Output: Using username "root". Last login: Thu Aug 2 14:50:43 2007 from 192.168.1.200 [root@spamfilter ~]# cssutil -b -r /etc/mail/spamassassin/crm114/spam.css Sparse spectra file /etc/mail/spamassassin/crm114/spam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 1 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 [root@spamfilter ~]# cssutil -b -r /etc/mail/spamassassin/crm114/nonspam.css Sparse spectra file /etc/mail/spamassassin/crm114/nonspam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 1 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Thursday, August 02, 2007 2:55 PM To: MailScanner discussion Subject: Re: CRM114 css not updating Have you set it to autolearn in crm114.cf ? What does it show if you do a cssutil -b -r spam.css and cssutil -b -r nonspam.css ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Steven Andrews" To: "MailScanner discussion" Sent: Thursday, August 2, 2007 7:22:43 PM (GMT) Europe/London Subject: CRM114 css not updating Centos4 Been throught wiki regarding install twice and I haven't missed anything. Spamassassin -D --lint shows it's being called and allmail.txt is catching incoming mail; no errors. Running the test from MailWatch, blows up with: [12961] dbg: crm114: crm114_command run 0.01892 ERROR: mailreaver.crm broke. Here's the error\: 0.02391 ERROR: 0.00025 /usr/bin/crm: *ERROR* 9E-05 For some reason, I was unable to write-open the file named allmail.txt 9E-05 Sorry, but this program is very sick and probably should be killed off. 8E-05 This happened at line 165 of file mailreaver.crm 8E-05 [12961] dbg: info: leaving helper-app run mode 0.0009 [12961] dbg: crm114: call_crm returns (UNKNOWN, 0) 0.00069 [12961] warn: crm114: Error. Failed to get CRM114-Status. at /etc/mail/spamassassin/crm114.pm line 315. I kind of expect that since it's running as apache; everything else as root. So, I give it a quick chmod 777 and I get a little further: [13748] dbg: crm114: crm114_command run 0.01103 ERROR: maillib.crm broke. Here's the error\: 0.06252 ERROR: 0.00026 /usr/bin/crm: *WARNING* 9E-05 Couldn't memory-map the table file spam.css 8E-05 I'll try to keep working. 7E-05 This happened at line 662 of file mailreaver.crm 8E-05 [13748] dbg: info: leaving helper-app run mode 0.00086 [13748] dbg: crm114: call_crm returns (UNKNOWN, 0) 0.00069 [13748] warn: crm114: Error. Failed to get CRM114-Status. at /etc/mail/spamassassin/crm114.pm line 315. Got it, Ok, 777 for the css files too. [14005] dbg: crm114: crm114_command run 0.02064 [14005] dbg: crm114: found version 20070301-BlameBaltar ( TRE 0.7.5 (LGPL) ) MR-BD9991E2 0.07717 [14005] dbg: crm114: found CacheID sfid-20070802_140925_378605_D6AAF116 0.00043 [14005] dbg: crm114: found status UNSURE and score 0.00 0.00029 [14005] dbg: crm114: found Notice Please train this message. 0.00029 [14005] dbg: info: leaving helper-app run mode 0.00125 [14005] dbg: crm114: call_crm returns (UNSURE, 0.00) 0.00069 [14005] dbg: crm114: score is 0.0000, translated to SA score: -0.0000, linear factor was -0.2000 Looks good; doublecheck spamassassin -D --lint show no errors. The spam.css and nospam.css files still refuse to move beyond the timestamp from their creation time. Cssutil -b -r /etc/mail/spamassassin/crm114 still shows the base info. Messages have -0.00 CRM114_CHECK. I even set it to use static scoring and all I get is the unsure score. I do see items adding to the /reaver_cache/texts directory. Nothing in the other reaver_cache directories. I've done the requisite banging on my mouse and pounding my head on the desk, but that didn't work either. Any thoughts? -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ---------------------------------------------------------- Diese Nachricht wurde von mailMind(R) auf Viren und andere gefaehrliche Inhalte untersucht und ist sauber. --- mailMind(R) - we have your Mailsecurity in mind! http://www.mailmind.de --- -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ---------------------------------------------------------- Diese Nachricht wurde von mailMind(R) auf Viren und andere gefaehrliche Inhalte untersucht und ist sauber. --- mailMind(R) - we have your Mailsecurity in mind! http://www.mailmind.de --- -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Sat Aug 4 11:05:40 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat Aug 4 11:06:14 2007 Subject: MailScanner & Fedora Core 7 In-Reply-To: <20070803202725.M47316@comp-wiz.com> References: <20070803200245.M50381@comp-wiz.com> <224FA7E11EA39E45843E11CEBBD3A36F189516@HOUPEX01.nfsmith.info> <20070803202725.M47316@comp-wiz.com> Message-ID: <46B44F74.60508@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Do service MailScanner stop service sendmail stop service MailScanner start and then try putting some mail through it again. Vernon Webb wrote: > I did and MailScanner is running when I check processes. > > ------------------------------------------------------------------------ > Vernon Webb > (201) 703-1232 > web designs & web hosting > by comp-wiz.com, inc. > Information in this transmission is privileged & confidential. It is > intended for the use of the individual or entity named above. Any > review, dissemination, disclosure, alteration, printing, circulation > or transmission of this email or it's attachments is prohibited and > unlawful. > > *---------- Original Message -----------* > From: "Mike Kercher" > To: "MailScanner discussion" > Sent: Fri, 3 Aug 2007 15:23:39 -0500 > Subject: RE: MailScanner & Fedora Core 7 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Vernon > > Webb > > Sent: Friday, August 03, 2007 3:06 PM > > To: mailscanner@lists.mailscanner.info > > Subject: MailScanner & Fedora Core 7 > > > > Can anyone tell me if MailScanner works with Fedora Core 7? I have > > installed it with calmav, spamassasian, rules du jour, dcc, and pyzor > > using Sendmail but it doesn't appear that any of the messages are > > actually being scanned as obvious SPAM mails being tagged by other > > systems as SPAM are not being tagged at all. > > > > Anyone have any idea? > > -- > > > > Did you chkconfig sendmail off and chkconfig MailScanner on; service > > MailScanner start? > > > > Mike > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > -- > > This message has been scanned for viruses and > > dangerous content and is believed to be clean. > *------- End of Original Message -------* Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGtE91EfZZRxQVtlQRAsPnAKCk162UnPpZPCi4APWVXcLGYZB3ugCfWXyh hZkcaisGojNAw2D205A0LM4= =SJ+9 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Sat Aug 4 11:17:58 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat Aug 4 11:18:48 2007 Subject: Upgrading Minor versions In-Reply-To: References: <2579c6b20708021427w6521a719na27d657ffe7d6b6d@mail.gmail.com> <223f97700708030049m695c6a91laa44c2df243b20f4@mail.gmail.com> <223f97700708030308n4d0c57d3j360e7283a9def359@mail.gmail.com> <46B306A3.40902@ecs.soton.ac.uk> Message-ID: <46B45256.6030708@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Res wrote: > Eugene is correct.. > >> I just tried Julian's patch.... >> >> no luck. >> >> It seems to have changed the paths that it references in the script >> (ie.. >> echos and such)..but the archive is still untarred as >> MailScanner-4.62.9. >> Probably because that path is hard set in the tar file. That's where >> the >> real problem is. > > Correct, all that's needed is the name of the directory changed, which > comes back to my earlier suggestion, but none the less the installer > script matters not, not when the tarred up directory name is in fact > only .9 not .9-2 This will be fixed in the next release. I don't see any point in releasing a .9-3. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj4DBQFGtFJXEfZZRxQVtlQRAv3gAJdUepzpckrnuLiX297gNd4WrqkeAKDAdFP6 qDkCfFsY+BBPBAjTXRPaAA== =VXhg -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From gerard at seibercom.net Sat Aug 4 12:04:23 2007 From: gerard at seibercom.net (Gerard) Date: Sat Aug 4 12:04:16 2007 Subject: pdfassassin In-Reply-To: References: Message-ID: <20070804070054.BD60.GERARD@seibercom.net> On August 03, 2007 at 08:27AM Douglas Ward wrote: > We block .zip and .rar at the mta. I finally ducked a new spam wave! :) Unconditionally blocking "zip or rar' files is not a viable option here. -- Gerard From hvdkooij at vanderkooij.org Sat Aug 4 12:12:22 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sat Aug 4 12:12:33 2007 Subject: pdfassassin In-Reply-To: <20070804070054.BD60.GERARD@seibercom.net> References: <20070804070054.BD60.GERARD@seibercom.net> Message-ID: On Sat, 4 Aug 2007, Gerard wrote: > On August 03, 2007 at 08:27AM Douglas Ward wrote: > >> We block .zip and .rar at the mta. I finally ducked a new spam wave! :) > > Unconditionally blocking "zip or rar' files is not a viable option > here. Is there a method to detect extension spoofing? I would block all message with extension spoofing. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From glenn.steen at gmail.com Sat Aug 4 12:27:16 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Sat Aug 4 12:27:18 2007 Subject: pdfassassin In-Reply-To: References: <20070804070054.BD60.GERARD@seibercom.net> Message-ID: <223f97700708040427r4ce4719fqeb700c4417d9a74b@mail.gmail.com> On 04/08/07, Hugo van der Kooij wrote: > On Sat, 4 Aug 2007, Gerard wrote: > > > On August 03, 2007 at 08:27AM Douglas Ward wrote: > > > >> We block .zip and .rar at the mta. I finally ducked a new spam wave! :) > > > > Unconditionally blocking "zip or rar' files is not a viable option > > here. > > Is there a method to detect extension spoofing? > I would block all message with extension spoofing. > > Hugo. > That would have to rely on the file command in an even more ... dependant... manner than the filetype checking does already... Or some other "file magic facility". Could be ... Less than perfect. I'd imagine that making that as a CustonFunction, _could_ work, or perhaps type up your own SA plugin for it:-) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From ms-list at alexb.ch Sat Aug 4 13:05:10 2007 From: ms-list at alexb.ch (Alex Broens) Date: Sat Aug 4 13:05:15 2007 Subject: pdfassassin In-Reply-To: <223f97700708040427r4ce4719fqeb700c4417d9a74b@mail.gmail.com> References: <20070804070054.BD60.GERARD@seibercom.net> <223f97700708040427r4ce4719fqeb700c4417d9a74b@mail.gmail.com> Message-ID: <46B46B76.3020307@alexb.ch> On 8/4/2007 1:27 PM, Glenn Steen wrote: > On 04/08/07, Hugo van der Kooij wrote: >> On Sat, 4 Aug 2007, Gerard wrote: >> >>> On August 03, 2007 at 08:27AM Douglas Ward wrote: >>> >>>> We block .zip and .rar at the mta. I finally ducked a new spam wave! :) >>> Unconditionally blocking "zip or rar' files is not a viable option >>> here. >> Is there a method to detect extension spoofing? >> I would block all message with extension spoofing. >> >> Hugo. >> > That would have to rely on the file command in an even more ... > dependant... manner than the filetype checking does already... Or some > other "file magic facility". Could be ... Less than perfect. > I'd imagine that making that as a CustonFunction, _could_ work, or > perhaps type up your own SA plugin for it:-) It can be done quite easily with full and mimeheader rules meta'd together. Alex From rcooper at dwford.com Sat Aug 4 15:34:50 2007 From: rcooper at dwford.com (Rick Cooper) Date: Sat Aug 4 15:34:57 2007 Subject: MailScanner & Fedora Core 7 In-Reply-To: <20070803200245.M50381@comp-wiz.com> References: <20070803200245.M50381@comp-wiz.com> Message-ID: <020201c7d6a4$9e1d7620$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On > Behalf Of Vernon Webb > Sent: Friday, August 03, 2007 4:06 PM > To: mailscanner@lists.mailscanner.info > Subject: MailScanner & Fedora Core 7 > > Can anyone tell me if MailScanner works with Fedora Core 7? > I have installed it with > calmav, spamassasian, rules du jour, dcc, and pyzor using > Sendmail but it doesn't > appear that any of the messages are actually being scanned > as obvious SPAM mails being > tagged by other systems as SPAM are not being tagged at all. > > Anyone have any idea? I would not install rules du jour, check the wiki I *think* there is an item describing how to pull/update those rules via sa-update which would be the currently preffered method Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From vernon at comp-wiz.com Sat Aug 4 16:14:29 2007 From: vernon at comp-wiz.com (Vernon Webb) Date: Sat Aug 4 16:15:47 2007 Subject: MailScanner & Fedora Core 7 In-Reply-To: <46B44F74.60508@ecs.soton.ac.uk> References: <20070803200245.M50381@comp-wiz.com> <224FA7E11EA39E45843E11CEBBD3A36F189516@HOUPEX01.nfsmith.info> <20070803202725.M47316@comp-wiz.com> <46B44F74.60508@ecs.soton.ac.uk> Message-ID: <20070804151332.M57658@comp-wiz.com> An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070804/807eeeea/attachment.html From iulianld at gmail.com Sat Aug 4 17:04:00 2007 From: iulianld at gmail.com (Iulian L Dragomir) Date: Sat Aug 4 17:04:05 2007 Subject: MailScanner & Fedora Core 7 In-Reply-To: <20070804151332.M57658@comp-wiz.com> References: <20070803200245.M50381@comp-wiz.com> <224FA7E11EA39E45843E11CEBBD3A36F189516@HOUPEX01.nfsmith.info> <20070803202725.M47316@comp-wiz.com> <46B44F74.60508@ecs.soton.ac.uk> <20070804151332.M57658@comp-wiz.com> Message-ID: On 8/4/07, Vernon Webb wrote: > > > Do > > service MailScanner stop > > service sendmail stop > > service MailScanner start > > and then try putting some mail through it again. > > I have tried this. I have tried rebooting the server and yet nothing is > being labeled as SPAM. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > You need also for reboot: service sendmail stop chkconfig sendmail off chkconfig --level 2345 sendmail off chkconfig MailScanner on chkconfig --level 2345 MailScanner on service MailScanner start as MailScanner need to be started as a service and sendmail service must be stop. look also to /etc/MailScanner/MailScanner.conf and check if Scan Messages = yes Spam Checks = yes Use SpamAssassin = yes Spam Modify Subject = start Spam Subject Text = {Spam?} for taging of the spam. From MailScanner at ecs.soton.ac.uk Sat Aug 4 17:33:21 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat Aug 4 17:33:53 2007 Subject: MailScanner & Fedora Core 7 In-Reply-To: <20070804151332.M57658@comp-wiz.com> References: <20070803200245.M50381@comp-wiz.com> <224FA7E11EA39E45843E11CEBBD3A36F189516@HOUPEX01.nfsmith.info> <20070803202725.M47316@comp-wiz.com> <46B44F74.60508@ecs.soton.ac.uk> <20070804151332.M57658@comp-wiz.com> Message-ID: <46B4AA51.8070102@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Are you getting any MailScanner headers in the messages at all by the time you see them? If not, it's not going anywhere near MailScanner. Unless you have tweaked a lot of options, it will always leave some trace behind. Vernon Webb wrote: > > Do > > service MailScanner stop > > service sendmail stop > > service MailScanner start > > and then try putting some mail through it again. > > I have tried this. I have tried rebooting the server and yet nothing > is being labeled as SPAM. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGtKpSEfZZRxQVtlQRAkWeAKDzkTTY3erv7H+XDuLGmkOjMziKyACcClnx exztZzDX2sl1C7AWGrGcNMI= =DafC -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Sat Aug 4 17:34:37 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat Aug 4 17:35:05 2007 Subject: MailScanner & Fedora Core 7 In-Reply-To: <20070804151332.M57658@comp-wiz.com> References: <20070803200245.M50381@comp-wiz.com> <224FA7E11EA39E45843E11CEBBD3A36F189516@HOUPEX01.nfsmith.info> <20070803202725.M47316@comp-wiz.com> <46B44F74.60508@ecs.soton.ac.uk> <20070804151332.M57658@comp-wiz.com> Message-ID: <46B4AA9D.2070701@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 And if you want to send me your remote login details and root pw (off list!) then I'll happily log in and take a quick look for you to see what's going on. It's probably something obvious (to me). Don't worry, you can trust me, I've got a reputation to protect! Jules Vernon Webb wrote: > > Do > > service MailScanner stop > > service sendmail stop > > service MailScanner start > > and then try putting some mail through it again. > > I have tried this. I have tried rebooting the server and yet nothing > is being labeled as SPAM. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGtKqdEfZZRxQVtlQRApRYAJ9aLmVgWGgvnA+9Psa5Cm3qcqotCgCfQywZ FWOIPzvpMaKmYHBTYKyATs8= =11zI -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From sandrews at andrewscompanies.com Sun Aug 5 00:47:48 2007 From: sandrews at andrewscompanies.com (Steven Andrews) Date: Sun Aug 5 00:47:53 2007 Subject: CRM114 css not updating In-Reply-To: <4D1CD0994309F84BA83DF998BF0075AF35AA2DC5@ts-dc2.TS-Webarts.local> References: <1964AAFBC212F742958F9275BF63DBB04B1052@winchester.andrewscompanies.com><27348762.10521186080876081.JavaMail.root@office.splatnix.net><1964AAFBC212F742958F9275BF63DBB04B1056@winchester.andrewscompanies.com><4D1CD0994309F84BA83DF998BF0075AF35AA2DC4@ts-dc2.TS-Webarts.local><1964AAFBC212F742958F9275BF63DBB04B1074@winchester.andrewscompanies.com> <4D1CD0994309F84BA83DF998BF0075AF35AA2DC5@ts-dc2.TS-Webarts.local> Message-ID: <1964AAFBC212F742958F9275BF63DBB04B1077@winchester.andrewscompanies.com> Thanks Roland; not sure how that happened; but those lines do have the comment removed, must have provided an old copy of the file here. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of MailScanner Mailinglist Sent: Saturday, August 04, 2007 2:58 AM To: MailScanner discussion Subject: AW: RE: RE: CRM114 css not updating Steve, just found 2 things in your crm114.cf, which need to be changed: #crm114_learn 1 This line needs to be activated by removing the # Same needs to be done for #crm114_dynscore_factor -0.05 Regards, Roland -----Urspr?ngliche Nachricht----- Von: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Im Auftrag von Steven Andrews Gesendet: Samstag, 4. August 2007 02:06 An: MailScanner discussion Betreff: RE: RE: CRM114 css not updating Thanks for the tips; been down that road a few dozen times already; but I reviewed it just the same. When I turn that option on, it does actually log mail to allmail.txt and I do get content into the reaver_cache under texts and prob_good; but no updates to the css files and no scoring. Steve -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of MailScanner Mailinglist Sent: Friday, August 03, 2007 7:39 PM To: MailScanner discussion Subject: AW: RE: CRM114 css not updating Hi, please make sure, you have copied the file /usr/share/doc/crm114-0/mailfilter.cf into the directory /etc/mail/spamassassin/crm114 Please make also sure you have the following files in your /etc/mail/spamassassin/crm114 directory: priolist.mfp allmail.txt rewrites.mfp Last but not least you need to set chmod -R 777 to /etc/mail/spamassassin/crm114/reaver_cache Regards, Roland -----Urspr?ngliche Nachricht----- Von: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Im Auftrag von Steven Andrews Gesendet: Donnerstag, 2. August 2007 20:55 An: MailScanner discussion Betreff: RE: CRM114 css not updating I have. Crm114.cf: # these two lines are necessary to activate the plugin: loadplugin crm114 crm114.pm full CRM114_CHECK eval:check_crm() # this high priority is not necessary. but running late allows us # to compare the CRM score and the result of all previous SA tests # # 899 is chosen as an optimization because FuzzyOCR runs at 900 # thus if CRM already yields a high SA score, # then FuzzyOCR will decide to skip its tests priority CRM114_CHECK 899 # commandline to execute CRM114 # default: crm -u ~/.crm114 mailreaver.crm #crm114_command /usr/local/bin/crm -u /var/amavis/.crm114 mailreaver.crm crm114_command /usr/bin/crm -u /etc/mail/spamassassin/crm114 mailreaver.crm # let SA add header lines to processed mails #add_header all CRM114-Version _CRM114VERSION_ #add_header all CRM114-CacheID _CRM114CACHEID_ add_header all CRM114-Status _CRM114STATUS_ ( _CRM114SCORE_ ) # ignore existing X-Spam or X-Virus headers # if SpamAssassin is called by Amavis then use the same value as Amavis does. # that way a SA-check from Amavis and on from the command line both see the same # Headers # default: 0 #crm114_remove_existing_spam_headers 1 #crm114_remove_existing_virus_headers 1 # dynamic score # values: 0 - returns subtest results # 1 - returns a dynamic CRM score (default) #crm114_dynscore 1 # dynamic score normalization factor # CRM score have much higher absolute values and different signs than SA scores # (usual ham-scores are between 15 and 40, scores from -10 to 10 are undecided, # previously seen spam easily gets -200). # With dynamic scoring the SA score is calculated by: * crm114_dynscore_factor # # Notes: - this has to be a negative number! # - the absolute value should be quite low (certainly <.3, probably <=.2), # otherwise the returned score would override all other tests. # default: calculate factor so that CRM-score -25 yields the SA required spam threshold #crm114_dynscore_factor -0.05 # static scores # without dynamic scores these scores are used # default values are respectively -3, 0, 3 for good, unsure, spam #crm114_staticscore_good -3.0 #crm114_staticscore_unsure 0.0 #crm114_staticscore_spam 3.0 # should CRM114 be trained by SA? # If enabled, then a call to Mail::SpamAssassin->learn() or # "spamassassin --report/--revoke" also calls the CRM114 plugin. # Since CRM114 uses a "Train On Error" strategy the plugin will check the # reported mail and only learn it if it is not not classified correctly. # default: 0 #crm114_learn 1 # should CRM114 be trained by SA-autolearn? # If enabled, then SA's autolearn also calls the CRM114 plugin. # # This is different from :automatic_training: in CRM114's mailfilter.cf # because SA's score is influenced by several different factors while # CRM114 has to rely on its own classification. # But anyway: Only activate this if you know what you're doing! # default: 0 crm114_autolearn 1 # should we preserve the CRM114-CacheID for training or discard it? # # to use the cache enable it in mailfilter.cf, set this option, and # include the CacheID into all Mails with # "add_header all CRM114-CacheID _CRM114CACHEID_" # -- otherwise disable this option to strip CacheIDs before training # default: 0 #crm114_use_cacheid 1 # should we skip CRM114 if other tests indicate certain spam/ham? # # disable CRM114 if a message already has a score (from other tests) # less than crm114_autodisable_negative_score or # more than crm114_autodisable_score. # # default: -999/999 # crm114_autodisable_negative_score -999 # crm114_autodisable_score 999 Output: Using username "root". Last login: Thu Aug 2 14:50:43 2007 from 192.168.1.200 [root@spamfilter ~]# cssutil -b -r /etc/mail/spamassassin/crm114/spam.css Sparse spectra file /etc/mail/spamassassin/crm114/spam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 1 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 [root@spamfilter ~]# cssutil -b -r /etc/mail/spamassassin/crm114/nonspam.css Sparse spectra file /etc/mail/spamassassin/crm114/nonspam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 1 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Thursday, August 02, 2007 2:55 PM To: MailScanner discussion Subject: Re: CRM114 css not updating Have you set it to autolearn in crm114.cf ? What does it show if you do a cssutil -b -r spam.css and cssutil -b -r nonspam.css ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Steven Andrews" To: "MailScanner discussion" Sent: Thursday, August 2, 2007 7:22:43 PM (GMT) Europe/London Subject: CRM114 css not updating Centos4 Been throught wiki regarding install twice and I haven't missed anything. Spamassassin -D --lint shows it's being called and allmail.txt is catching incoming mail; no errors. Running the test from MailWatch, blows up with: [12961] dbg: crm114: crm114_command run 0.01892 ERROR: mailreaver.crm broke. Here's the error\: 0.02391 ERROR: 0.00025 /usr/bin/crm: *ERROR* 9E-05 For some reason, I was unable to write-open the file named allmail.txt 9E-05 Sorry, but this program is very sick and probably should be killed off. 8E-05 This happened at line 165 of file mailreaver.crm 8E-05 [12961] dbg: info: leaving helper-app run mode 0.0009 [12961] dbg: crm114: call_crm returns (UNKNOWN, 0) 0.00069 [12961] warn: crm114: Error. Failed to get CRM114-Status. at /etc/mail/spamassassin/crm114.pm line 315. I kind of expect that since it's running as apache; everything else as root. So, I give it a quick chmod 777 and I get a little further: [13748] dbg: crm114: crm114_command run 0.01103 ERROR: maillib.crm broke. Here's the error\: 0.06252 ERROR: 0.00026 /usr/bin/crm: *WARNING* 9E-05 Couldn't memory-map the table file spam.css 8E-05 I'll try to keep working. 7E-05 This happened at line 662 of file mailreaver.crm 8E-05 [13748] dbg: info: leaving helper-app run mode 0.00086 [13748] dbg: crm114: call_crm returns (UNKNOWN, 0) 0.00069 [13748] warn: crm114: Error. Failed to get CRM114-Status. at /etc/mail/spamassassin/crm114.pm line 315. Got it, Ok, 777 for the css files too. [14005] dbg: crm114: crm114_command run 0.02064 [14005] dbg: crm114: found version 20070301-BlameBaltar ( TRE 0.7.5 (LGPL) ) MR-BD9991E2 0.07717 [14005] dbg: crm114: found CacheID sfid-20070802_140925_378605_D6AAF116 0.00043 [14005] dbg: crm114: found status UNSURE and score 0.00 0.00029 [14005] dbg: crm114: found Notice Please train this message. 0.00029 [14005] dbg: info: leaving helper-app run mode 0.00125 [14005] dbg: crm114: call_crm returns (UNSURE, 0.00) 0.00069 [14005] dbg: crm114: score is 0.0000, translated to SA score: -0.0000, linear factor was -0.2000 Looks good; doublecheck spamassassin -D --lint show no errors. The spam.css and nospam.css files still refuse to move beyond the timestamp from their creation time. Cssutil -b -r /etc/mail/spamassassin/crm114 still shows the base info. Messages have -0.00 CRM114_CHECK. I even set it to use static scoring and all I get is the unsure score. I do see items adding to the /reaver_cache/texts directory. Nothing in the other reaver_cache directories. I've done the requisite banging on my mouse and pounding my head on the desk, but that didn't work either. Any thoughts? -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ---------------------------------------------------------- Diese Nachricht wurde von mailMind(R) auf Viren und andere gefaehrliche Inhalte untersucht und ist sauber. --- mailMind(R) - we have your Mailsecurity in mind! http://www.mailmind.de --- -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ---------------------------------------------------------- Diese Nachricht wurde von mailMind(R) auf Viren und andere gefaehrliche Inhalte untersucht und ist sauber. --- mailMind(R) - we have your Mailsecurity in mind! http://www.mailmind.de --- -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From ajos1 at onion.demon.co.uk Sun Aug 5 16:47:20 2007 From: ajos1 at onion.demon.co.uk (ajos1@onion.demon.co.uk) Date: Sun Aug 5 16:47:26 2007 Subject: MailScanner & Fedora Core 7 Message-ID: - For Fc7 (Fc6/Fc5/...) install I do... /sbin/chkconfig sendmail off /sbin/chkconfig --level 12345 MailScanner on /bin/sh /etc/rc.d/init.d/sendmail stop /bin/sh /etc/rc.d/init.d/spamassassin restart /bin/sh /etc/rc.d/init.d/MailScanner restart From hvdkooij at vanderkooij.org Sun Aug 5 17:17:30 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sun Aug 5 17:17:40 2007 Subject: MailScanner & Fedora Core 7 In-Reply-To: References: Message-ID: On Sun, 5 Aug 2007, ajos1@onion.demon.co.uk wrote: > For Fc7 (Fc6/Fc5/...) install I do... > > /sbin/chkconfig sendmail off > /sbin/chkconfig --level 12345 MailScanner on I would not dream of starting MailScanner in single-user mode. What good would that run level be if everything get started anyway? Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From wizard at jimhermann.com Sun Aug 5 21:05:03 2007 From: wizard at jimhermann.com (Jim Hermann) Date: Sun Aug 5 21:07:04 2007 Subject: Reporting Score in inline.spam.warning.txt In-Reply-To: <20070804070054.BD60.GERARD@seibercom.net> References: <20070804070054.BD60.GERARD@seibercom.net> Message-ID: <004901c7d79b$e9536d50$cc01a8c0@Dual> Is there a way to report the total Score in the inline.spam.warning.txt? Thanks. Jim From MailScanner at ecs.soton.ac.uk Sun Aug 5 22:01:15 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun Aug 5 22:01:50 2007 Subject: Reporting Score in inline.spam.warning.txt In-Reply-To: <004901c7d79b$e9536d50$cc01a8c0@Dual> References: <20070804070054.BD60.GERARD@seibercom.net> <004901c7d79b$e9536d50$cc01a8c0@Dual> Message-ID: <46B63A9B.3050702@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 The sample reports I provide include every variable available to each one. They are the ones people have ever asked for. If it's not there, let me know and I'll probably add it for you. Jim Hermann wrote: > Is there a way to report the total Score in the inline.spam.warning.txt? > > Thanks. > > Jim > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGtjqgEfZZRxQVtlQRAu9tAJ9q+k/gmYnpEhgPCHscZz4b3g9vQACgqwKm F9f04nLprFwEWNmsuzlZeyA= =bh4t -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Mon Aug 6 00:02:28 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon Aug 6 00:02:38 2007 Subject: Error after upgrade In-Reply-To: <200708032341.l73NfRYq018027@balita.ph> References: <200708030852.l738qkTp030708@balita.ph> <30884165.10941186139270824.JavaMail.root@office.splatnix.net> <30884165.10941186139270824.JavaMail.root@office.splatnix.n et> <200708031120.l73BKo5w029434@balita.ph> <200708032341.l73NfRYq018027@balita.ph> Message-ID: Wayne spake the following on 8/3/2007 4:41 PM: > At 22:20 03/08/2007, you wrote: > > Hi Scott > > It was as part of the RHEL 4 installation > >> Was your original spamassassin installed via rpm by any chance? > > reading between the lines sounds like that could be a problem. :-( > > Wayne- If you originally had spamassasin installed by rpm, you need to remove that rpm before you install Julian's clamav/spamassassin tarball. You can do "rpm -e spamassassin" and then re-run Julian's installer. That should fix things up. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Mon Aug 6 00:04:46 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon Aug 6 00:05:07 2007 Subject: Stopping unwanted character sets In-Reply-To: References: <46B39D16.1010201@evi-inc.com> Message-ID: Hugo van der Kooij spake the following on 8/4/2007 1:10 AM: > On Fri, 3 Aug 2007, Matt Kettler wrote: > >> Hugo van der Kooij wrote: >>> Hi, >>> >>> There was some discussion a while ago about stopping messages based on >>> country of orrigin. >>> >>> But I see more use in stopping unwanted charactersets. >>> >>> For example: >>> ------=_NextPart_000_0000_7D761D51.CFA8A7DF >>> Content-Type: text/plain; >>> charset="windows-1251" >>> Content-Transfer-Encoding: quoted-printable >>> >>> >>> I have no need for messages in this character set nor anyone else. >>> >>> Is there a way to filter on these? >> >> If you've got the mimeheader plugin loaded (defaults to being loaded >> in 3.1.0 >> and higher) you can use a mimeheader rule >> >> something like this should work: >> mimehader MIME_WIN_1251 Content-Type =~/windows-1251/i > > It seems it is accepting this fine. Now let us see if there will be hits. > > And I needed to clean up a bit I noticed. I understood it is not > recommended to put your own ruleset in a private file. > > So they now live in spam.hvdkooij.rules.conf > > Hugo. > Doesn't that need to be a .cf file? -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Mon Aug 6 00:07:01 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon Aug 6 00:10:04 2007 Subject: MailScanner & Fedora Core 7 In-Reply-To: <46B4AA9D.2070701@ecs.soton.ac.uk> References: <20070803200245.M50381@comp-wiz.com> <224FA7E11EA39E45843E11CEBBD3A36F189516@HOUPEX01.nfsmith.info> <20070803202725.M47316@comp-wiz.com> <46B44F74.60508@ecs.soton.ac.uk> <20070804151332.M57658@comp-wiz.com> <46B4AA9D.2070701@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 8/4/2007 9:34 AM: > And if you want to send me your remote login details and root pw (off > list!) then I'll happily log in and take a quick look for you to see > what's going on. It's probably something obvious (to me). > > Don't worry, you can trust me, I've got a reputation to protect! > > Jules > > Vernon Webb wrote: >>> Do >>> service MailScanner stop >>> service sendmail stop >>> service MailScanner start >>> and then try putting some mail through it again. >> I have tried this. I have tried rebooting the server and yet nothing >> is being labeled as SPAM. > > Jules > And if Julian fixes it for you, be sure and make some kind of contribution. http://www.mailscanner.info/donate.html -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Mon Aug 6 00:13:58 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon Aug 6 00:15:07 2007 Subject: MailScanner & Fedora Core 7 In-Reply-To: References: Message-ID: ajos1@onion.demon.co.uk spake the following on 8/5/2007 9:47 AM: > - > > For Fc7 (Fc6/Fc5/...) install I do... > > /sbin/chkconfig sendmail off > /sbin/chkconfig --level 12345 MailScanner on > /bin/sh /etc/rc.d/init.d/sendmail stop > /bin/sh /etc/rc.d/init.d/spamassassin restart > /bin/sh /etc/rc.d/init.d/MailScanner restart Chkconfig MailScanner on is sufficient. It will start in the normal run-levels of 3,4,and 5. You don't want a bunch of stuff starting in 1 as this is your single user "emergency" level. And level 2 is useful for remote maintenance with most un-necessary stuff turned off. Almost can be set up as a rescue level with networking and maybe ssh running. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From hvdkooij at vanderkooij.org Mon Aug 6 06:37:12 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Mon Aug 6 06:37:40 2007 Subject: Stopping unwanted character sets In-Reply-To: References: <46B39D16.1010201@evi-inc.com> Message-ID: On Sun, 5 Aug 2007, Scott Silva wrote: > Hugo van der Kooij spake the following on 8/4/2007 1:10 AM: >> >> So they now live in spam.hvdkooij.rules.conf >> > Doesn't that need to be a .cf file? Right you are. Silly me. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From paul.hutchings at mira.co.uk Mon Aug 6 09:01:36 2007 From: paul.hutchings at mira.co.uk (Paul Hutchings) Date: Mon Aug 6 09:01:40 2007 Subject: "Could not parse Outlook Rich Text attachment"? Message-ID: Seeing the above a fair bit since upgrading to the latest stable. Any suggestions please? Paul Hutchings Network Administrator, MIRA Ltd. Tel: 44 (0)24 7635 5378 Fax: 44 (0)24 7635 8378 mailto:paul.hutchings@mira.co.uk -- MIRA Ltd Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. Registered in England and Wales No. 402570 VAT Registration GB 114 5409 96 The contents of this e-mail are confidential and are solely for the use of the intended recipient. If you receive this e-mail in error, please delete it and notify us either by e-mail, telephone or fax. You should not copy, forward or otherwise disclose the content of the e-mail as this is prohibited. From martinh at solidstatelogic.com Mon Aug 6 09:12:46 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Mon Aug 6 09:12:50 2007 Subject: "Could not parse Outlook Rich Text attachment"? In-Reply-To: Message-ID: <24000b51a3c12f4ea974e335b9372c6c@solidstatelogic.com> Paul RTF is a bad idea anyway (use html is less risky), but check what "TNEF Expander" you're using. There was a change to the External one in this release.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Paul Hutchings > Sent: 06 August 2007 09:02 > To: MailScanner discussion > Subject: "Could not parse Outlook Rich Text attachment"? > > Seeing the above a fair bit since upgrading to the latest stable. > > Any suggestions please? > > Paul Hutchings > Network Administrator, MIRA Ltd. > Tel: 44 (0)24 7635 5378 > Fax: 44 (0)24 7635 8378 > mailto:paul.hutchings@mira.co.uk > > > -- > MIRA Ltd > > Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. > > Registered in England and Wales No. 402570 > VAT Registration GB 114 5409 96 > > The contents of this e-mail are confidential and are solely for the use of > the intended recipient. > If you receive this e-mail in error, please delete it and notify us either > by e-mail, telephone or fax. > You should not copy, forward or otherwise disclose the content of the e- > mail as this is prohibited. > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From paul.hutchings at mira.co.uk Mon Aug 6 09:19:46 2007 From: paul.hutchings at mira.co.uk (Paul Hutchings) Date: Mon Aug 6 09:19:55 2007 Subject: "Could not parse Outlook Rich Text attachment"? References: <24000b51a3c12f4ea974e335b9372c6c@solidstatelogic.com> Message-ID: "TNEF Expander = /usr/bin/tnef --maxsize=100000000" My previous Mailscanner.conf has the same in it, tnef shows as v1.4.3. It doesn't appear to be affecting all TNEF's just some show up as corrupt. These are on inbound email so we have no control over the format (our mail server converts RTF email to HTML before sending out). Cheers, Paul Paul Hutchings Network Administrator, MIRA Ltd. Tel: 44 (0)24 7635 5378 Fax: 44 (0)24 7635 8378 mailto:paul.hutchings@mira.co.uk -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Martin.Hepworth Sent: 06 August 2007 09:13 To: MailScanner discussion Subject: RE: "Could not parse Outlook Rich Text attachment"? Paul RTF is a bad idea anyway (use html is less risky), but check what "TNEF Expander" you're using. There was a change to the External one in this release.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Paul Hutchings > Sent: 06 August 2007 09:02 > To: MailScanner discussion > Subject: "Could not parse Outlook Rich Text attachment"? > > Seeing the above a fair bit since upgrading to the latest stable. > > Any suggestions please? > > Paul Hutchings > Network Administrator, MIRA Ltd. > Tel: 44 (0)24 7635 5378 > Fax: 44 (0)24 7635 8378 > mailto:paul.hutchings@mira.co.uk > > > -- > MIRA Ltd > > Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. > > Registered in England and Wales No. 402570 > VAT Registration GB 114 5409 96 > > The contents of this e-mail are confidential and are solely for the use of > the intended recipient. > If you receive this e-mail in error, please delete it and notify us either > by e-mail, telephone or fax. > You should not copy, forward or otherwise disclose the content of the e- > mail as this is prohibited. > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MIRA Ltd Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. Registered in England and Wales No. 402570 VAT Registration GB 114 5409 96 The contents of this e-mail are confidential and are solely for the use of the intended recipient. If you receive this e-mail in error, please delete it and notify us either by e-mail, telephone or fax. You should not copy, forward or otherwise disclose the content of the e-mail as this is prohibited. From martinh at solidstatelogic.com Mon Aug 6 09:25:40 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Mon Aug 6 09:25:48 2007 Subject: "Could not parse Outlook Rich Text attachment"? In-Reply-To: Message-ID: Paul Yeah that would be affected by the change, try "Internal" and see If that works. If not Jules may be able to help to sort out the problem... -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Paul Hutchings > Sent: 06 August 2007 09:20 > To: MailScanner discussion > Subject: RE: "Could not parse Outlook Rich Text attachment"? > > "TNEF Expander = /usr/bin/tnef --maxsize=100000000" > > My previous Mailscanner.conf has the same in it, tnef shows as v1.4.3. > > It doesn't appear to be affecting all TNEF's just some show up as > corrupt. > > These are on inbound email so we have no control over the format (our > mail server converts RTF email to HTML before sending out). > > Cheers, > Paul > > Paul Hutchings > Network Administrator, MIRA Ltd. > Tel: 44 (0)24 7635 5378 > Fax: 44 (0)24 7635 8378 > mailto:paul.hutchings@mira.co.uk > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of > Martin.Hepworth > Sent: 06 August 2007 09:13 > To: MailScanner discussion > Subject: RE: "Could not parse Outlook Rich Text attachment"? > > Paul > > RTF is a bad idea anyway (use html is less risky), but check what "TNEF > Expander" you're using. > > There was a change to the External one in this release.. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Paul Hutchings > > Sent: 06 August 2007 09:02 > > To: MailScanner discussion > > Subject: "Could not parse Outlook Rich Text attachment"? > > > > Seeing the above a fair bit since upgrading to the latest stable. > > > > Any suggestions please? > > > > Paul Hutchings > > Network Administrator, MIRA Ltd. > > Tel: 44 (0)24 7635 5378 > > Fax: 44 (0)24 7635 8378 > > mailto:paul.hutchings@mira.co.uk > > > > > > -- > > MIRA Ltd > > > > Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. > > > > Registered in England and Wales No. 402570 > > VAT Registration GB 114 5409 96 > > > > The contents of this e-mail are confidential and are solely for the > use of > > the intended recipient. > > If you receive this e-mail in error, please delete it and notify us > either > > by e-mail, telephone or fax. > > You should not copy, forward or otherwise disclose the content of the > e- > > mail as this is prohibited. > > > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > MIRA Ltd > > Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. > > Registered in England and Wales No. 402570 > VAT Registration GB 114 5409 96 > > The contents of this e-mail are confidential and are solely for the use of > the intended recipient. > If you receive this e-mail in error, please delete it and notify us either > by e-mail, telephone or fax. > You should not copy, forward or otherwise disclose the content of the e- > mail as this is prohibited. > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From wjohns at balita.ph Mon Aug 6 09:40:19 2007 From: wjohns at balita.ph (Wayne) Date: Mon Aug 6 09:40:20 2007 Subject: Error after upgrade In-Reply-To: References: <200708030852.l738qkTp030708@balita.ph> <30884165.10941186139270824.JavaMail.root@office.splatnix.net> <30884165.10941186139270824.JavaMail.root@office.splatnix.n et> <200708031120.l73BKo5w029434@balita.ph> <200708032341.l73NfRYq018027@balita.ph> Message-ID: <200708060840.l768eHRQ026636@balita.ph> At 00:02 06/08/2007, you wrote: Hi Scott That was the procedure I followed will take another look. Many thanks Wayne >If you originally had spamassasin installed by rpm, you need to remove that >rpm before you install Julian's clamav/spamassassin tarball. >You can do "rpm -e spamassassin" and then re-run Julian's installer. That >should fix things up. From ms-list at alexb.ch Mon Aug 6 11:12:22 2007 From: ms-list at alexb.ch (Alex Broens) Date: Mon Aug 6 11:12:27 2007 Subject: Blackberry - part II Message-ID: <46B6F406.8020008@alexb.ch> Guys Blackberry's ETP.DAT files are becomming a daily challenge: Today: ETP.DAT: SVR2 pure executable (Amdahl-UTS) not stripped - version 1197568626 Last Friday ETP.DAT.old: mc68k executable (shared demand paged) not stripped a few weeks ago: ETP.DAT executable not stripped anybody know someone at Blackberry? Can't imagine a company that size can't produce a consistent file header. or any better ideas? Thanks Alex From wjohns at balita.ph Mon Aug 6 11:50:53 2007 From: wjohns at balita.ph (Wayne) Date: Mon Aug 6 11:50:53 2007 Subject: Error after upgrade In-Reply-To: <200708060840.l768eHRQ026636@balita.ph> References: <200708030852.l738qkTp030708@balita.ph> <30884165.10941186139270824.JavaMail.root@office.splatnix.net> <30884165.10941186139270824.JavaMail.root@office.splatnix.n et> <200708031120.l73BKo5w029434@balita.ph> <200708032341.l73NfRYq018027@balita.ph> <200708060840.l768eHRQ026636@balita.ph> Message-ID: <200708061050.l76AoosW015077@balita.ph> I have checked everything I can think of and this is the error SA 3.2.2 still throws up. First part relates to Razor.pm _which is_ at /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi despite the error saying it is not. The 'PerMsgStatus' errors leave me completely blank. I have also included a MailScanner -v output Please help. Wayne spamassassin --lint [13929] warn: plugin: failed to parse plugin (from @INC): Can't locate Mail/Spamassassin/Plugin/Razor2.pm in @INC (@INC contains: lib /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi /usr/lib/perl5/site_perl/5.8.5 /usr/lib/perl5/5.8.5/i386-linux-thread-multi /usr/lib/perl5/5.8.5 /usr/lib/perl5/site_perl/5.8.4/i386-linux-thread-multi /usr/lib/perl5/site_perl/5.8.3/i386-linux-thread-multi /usr/lib/perl5/site_perl/5.8.2/i386-linux-thread-multi /usr/lib/perl5/site_perl/5.8.1/i386-linux-thread-multi /usr/lib/perl5/site_perl/5.8.0/i386-linux-thread-multi /usr/lib/perl5/site_perl/5.8.4 /usr/lib/perl5/site_perl/5.8.3 /usr/lib/perl5/site_perl/5.8.2 /usr/lib/perl5/site_perl/5.8.1 /usr/lib/perl5/site_perl/5.8.0 /usr/lib/perl5/site_perl /usr/lib/perl5/vendor_perl/5.8.5/i386-linux-thread-multi /usr/lib/perl5/vendor_perl/5.8.4/i386-linux-thread-multi /usr/lib/perl5/vendor_perl/5.8.3/i386-linux-thread-multi /usr/lib/perl5/vendor_perl/5.8.2/i386-linux-thread-multi /usr/lib/perl5/vendor_perl/5.8.1/i386-linux-thread-multi /usr/lib/perl5/vendor_perl/5.8.0/i386-linux-thread-multi /usr/lib/perl5/vendor_perl/5.8.5 /usr/lib/perl5/vendor_perl/5.8.4 /usr/lib/perl5/vendor_perl/5.8.3 /usr/lib/perl5/vendor_perl/5.8.2 /usr/lib/perl5/vendor_perl/5.8.1 /usr/lib/perl5/vendor_perl/5.8.0 /usr/lib/perl5/vendor_perl) at (eval 81) line 1. [13929] warn: rules: failed to run FORGED_RCVD_HELO test, skipping: [13929] warn: (Can't locate object method "check_for_forged_received_helo" via package "Mail::SpamAssassin::PerMsgStatus" at (eval 1372) line 105. [13929] warn: ) [13929] warn: rules: failed to run MSGID_FROM_MTA_ID test, skipping: [13929] warn: (Can't locate object method "message_id_from_mta" via package "Mail::SpamAssassin::PerMsgStatus" at (eval 1372) line 540. [13929] warn: ) [13929] warn: rules: failed to run FROM_AND_TO_SAME test, skipping: [13929] warn: (Can't locate object method "check_for_from_to_same" via package "Mail::SpamAssassin::PerMsgStatus" at (eval 1372) line 579. [13929] warn: ) [13929] warn: rules: failed to run DOMAIN_RATIO test, skipping: [13929] warn: (Can't locate object method "check_domain_ratio" via package "Mail::SpamAssassin::PerMsgStatus" at (eval 1423) line 303. [13929] warn: ) [13929] warn: rules: failed to run UNIQUE_WORDS test, skipping: [13929] warn: (Can't locate object method "check_unique_words" via package "Mail::SpamAssassin::PerMsgStatus" at (eval 1423) line 1728. [13929] warn: ) [13929] warn: lint: 5 issues detected, please rerun with debug enabled for more information MailScanner -v Running on Linux balita.ph 2.6.9-42.ELsmp #1 SMP Wed Jul 12 23:27:17 EDT 2006 i686 i686 i386 GNU/Linux This is Red Hat Enterprise Linux ES release 4 (Nahant Update 5) This is Perl version 5.008005 (5.8.5) This is MailScanner version 4.62.9 Module versions are: 1.00 AnyDBM_File 1.16 Archive::Zip 1.03 Carp 1.119 Convert::BinHex 1.00 DirHandle 1.05 Fcntl 2.73 File::Basename 2.08 File::Copy 2.01 FileHandle 1.06 File::Path 0.14 File::Temp 0.90 Filesys::Df 1.35 HTML::Entities 3.56 HTML::Parser 2.37 HTML::TokeParser 1.21 IO 1.10 IO::File 1.123 IO::Pipe 1.71 Mail::Header 1.70 Math::BigInt 3.05 MIME::Base64 5.420 MIME::Decoder 5.420 MIME::Decoder::UU 5.420 MIME::Head 5.420 MIME::Parser 3.03 MIME::QuotedPrint 5.420 MIME::Tools 0.11 Net::CIDR 1.08 POSIX 1.14 Scalar::Util 1.77 Socket 1.4 Sys::Hostname::Long 0.08 Sys::Syslog 1.9707 Time::HiRes 1.02 Time::localtime Optional module versions are: 1.29 Archive::Tar 0.15 bignum 1.82 Business::ISBN 1.10 Business::ISBN::Data 0.17 Convert::TNEF 1.08 Data::Dump 1.809 DB_File 1.13 DBD::SQLite 1.56 DBI 1.08 Digest 1.01 Digest::HMAC 2.33 Digest::MD5 2.10 Digest::SHA1 1.00 Encode::Detect 0.17008 Error 0.18 ExtUtils::CBuilder 2.18 ExtUtils::ParseXS 0.44 Inline 1.08 IO::String 1.04 IO::Zlib 2.21 IP::Country 0.20 Mail::ClamAV 3.002002 Mail::SpamAssassin v2.004 Mail::SPF 1.999001 Mail::SPF::Query 0.12 Math::BigRat 0.2808 Module::Build 0.20 Net::CIDR::Lite 0.60 Net::DNS 0.002.2 Net::DNS::Resolver::Programmable 0.31 Net::LDAP 4.004 NetAddr::IP 1.94 Parse::RecDescent missing SAVI 2.42 Test::Harness 0.95 Test::Manifest 1.95 Text::Balanced 1.35 URI 0.7203 version 0.62 YAML From list-mailscanner at linguaphone.com Mon Aug 6 12:19:03 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon Aug 6 12:19:16 2007 Subject: Phishing.Heuristics.Email.SpoofedDomain false positives Message-ID: <1186399142.31893.6.camel@gblades-suse.linguaphone-intranet.co.uk> I have just upgraded MailScanner and enabled full message scanning but I am getting a few false positives on Phishing.Heuristics.Email.SpoofedDomain against some genuine Amazon emails and a couple of others. Strangely when I use clamscan and scan the message file the message is reported as being clean. Quarantine Modified Body = no Quarantine Whole Message = yes Quarantine Whole Messages As Queue Files = no How does Mailscanner save the raw mail file for clamavmodule to scan? Could there be a slight difference which is causing the heuristics to misbehave? Thanks Gareth From gmatt at nerc.ac.uk Mon Aug 6 12:42:27 2007 From: gmatt at nerc.ac.uk (Greg Matthews) Date: Mon Aug 6 12:42:40 2007 Subject: ClamAV module logging changed in 4.62 Message-ID: <46B70923.6040309@nerc.ac.uk> One snag noticed on upgrade to 4.62.9-2 is that the logging of infections for ClamAV module has changed so that instead of: Jul 22 07:21:12 mailr-w MailScanner[8906]: ClamAVModule::INFECTED:: Html.Phishing.Bank.Sanesecurity.05082901:: ./l6M6L5eZ010196/msg-8906-8.html It now looks like: Aug 6 09:59:42 mailr-w MailScanner[3719]: INFECTED:: Html.Phishing.Bank.Gen2049.Sanesecurity.07080201:: ./l768xRdk022394/msg-3719-104.html Note the missing ClamAVModule:: on the log line. Is this a casualty of the recent trend to use clamd? I've been perfectly happy with the module until now. GREG -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford -- This message (and any attachments) is for the recipient only. NERC is subject to the Freedom of Information Act 2000 and the contents of this email and any reply you make may be disclosed by NERC unless it is exempt from release under the Act. Any material supplied to NERC may be stored in an electronic records management system. From glenn.steen at gmail.com Mon Aug 6 13:00:15 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Mon Aug 6 13:00:18 2007 Subject: Blackberry - part II In-Reply-To: <46B6F406.8020008@alexb.ch> References: <46B6F406.8020008@alexb.ch> Message-ID: <223f97700708060500k66ebdc2ex4070027e15f07333@mail.gmail.com> On 06/08/07, Alex Broens wrote: > Guys > > Blackberry's ETP.DAT files are becomming a daily challenge: > > Today: > > ETP.DAT: SVR2 pure executable (Amdahl-UTS) not stripped - version > 1197568626 > > Last Friday > ETP.DAT.old: mc68k executable (shared demand paged) not stripped > > a few weeks ago: > > ETP.DAT executable not stripped > > > anybody know someone at Blackberry? > > Can't imagine a company that size can't produce a consistent file header. > > or any better ideas? > > Thanks > > Alex > As I'm sure you've done, you can look at the message ... and see that it contains two parts: 1) the ETP.DAT in ascii armour 2) the pure binary file, containing the encrypted activation data. If the idiots could code their system to only work with the prior, and dispensed entirely with the second... everything would be just dandy. As is, to be sure there is no problems activating a new handset, you'll have to do something like: - In /etc/MailScanner/rules/filetype.rules (referenced in the Filetype Rules setting in MailScanner.conf, of course): # Bloody ETP.DAT object files from blackberry... From: *.blackberry.net %etc-dir%/filetype.whitelist.rules.conf (beware of linewrapping....:-) - In /etc/MailScanner/filetype.whitelist.rules.conf .... basically just say "allow" to anything. You could make that a one-liner, or copy the normal filetypes rule file and change all the "deny" to "allow" There is no real way around this idiocy, since you cannot predetermine exactly which hosts (IP addresses/ranges) they might be sending from, nor determine exactly which file magics it can happen to match. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From ms-list at alexb.ch Mon Aug 6 13:35:02 2007 From: ms-list at alexb.ch (Alex Broens) Date: Mon Aug 6 13:35:11 2007 Subject: Blackberry - part II In-Reply-To: <223f97700708060500k66ebdc2ex4070027e15f07333@mail.gmail.com> References: <46B6F406.8020008@alexb.ch> <223f97700708060500k66ebdc2ex4070027e15f07333@mail.gmail.com> Message-ID: <46B71576.7040203@alexb.ch> Hi Glenn, On 8/6/2007 2:00 PM, Glenn Steen wrote: > On 06/08/07, Alex Broens wrote: >> Guys >> >> Blackberry's ETP.DAT files are becomming a daily challenge: >> >> Today: >> >> ETP.DAT: SVR2 pure executable (Amdahl-UTS) not stripped - version >> 1197568626 >> >> Last Friday >> ETP.DAT.old: mc68k executable (shared demand paged) not stripped >> >> a few weeks ago: >> >> ETP.DAT executable not stripped >> >> >> anybody know someone at Blackberry? >> >> Can't imagine a company that size can't produce a consistent file header. >> >> or any better ideas? >> >> Thanks >> >> Alex >> > As I'm sure you've done, you can look at the message ... and see that > it contains two parts: > 1) the ETP.DAT in ascii armour > 2) the pure binary file, containing the encrypted activation data. > > If the idiots could code their system to only work with the prior, and > dispensed entirely with the second... everything would be just dandy. exactly - and do would expect to get a reply from their Support? YEAH RIGHT! > As is, to be sure there is no problems activating a new handset, > you'll have to do something like: > - In /etc/MailScanner/rules/filetype.rules (referenced in the Filetype > Rules setting in MailScanner.conf, of course): > # Bloody ETP.DAT object files from blackberry... > From: *.blackberry.net > %etc-dir%/filetype.whitelist.rules.conf > (beware of linewrapping....:-) > > - In /etc/MailScanner/filetype.whitelist.rules.conf .... basically > just say "allow" to anything. You could make that a one-liner, or copy > the normal filetypes rule file and change all the "deny" to "allow" Using Mailwatch, I have "content.scanning.rules" From: 127.0.0.1 no FromOrTo: default yes do you think it would make make more sense to add From: *.blackberry.net no to that? (and spare wathcing an extra rule file :-) > There is no real way around this idiocy, since you cannot predetermine > exactly which hosts (IP addresses/ranges) they might be sending from, > nor determine exactly which file magics it can happen to match. frustrating - just hard to believe nobody else has come across this before :-) thanks Alex From glenn.steen at gmail.com Mon Aug 6 13:49:53 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Mon Aug 6 13:49:54 2007 Subject: Blackberry - part II In-Reply-To: <46B71576.7040203@alexb.ch> References: <46B6F406.8020008@alexb.ch> <223f97700708060500k66ebdc2ex4070027e15f07333@mail.gmail.com> <46B71576.7040203@alexb.ch> Message-ID: <223f97700708060549r72cf4eb8n6db4fadfc89bd029@mail.gmail.com> On 06/08/07, Alex Broens wrote: > Hi Glenn, > > On 8/6/2007 2:00 PM, Glenn Steen wrote: > > On 06/08/07, Alex Broens wrote: > >> Guys > >> > >> Blackberry's ETP.DAT files are becomming a daily challenge: > >> > >> Today: > >> > >> ETP.DAT: SVR2 pure executable (Amdahl-UTS) not stripped - version > >> 1197568626 > >> > >> Last Friday > >> ETP.DAT.old: mc68k executable (shared demand paged) not stripped > >> > >> a few weeks ago: > >> > >> ETP.DAT executable not stripped > >> > >> > >> anybody know someone at Blackberry? > >> > >> Can't imagine a company that size can't produce a consistent file header. > >> > >> or any better ideas? > >> > >> Thanks > >> > >> Alex > >> > > As I'm sure you've done, you can look at the message ... and see that > > it contains two parts: > > 1) the ETP.DAT in ascii armour > > 2) the pure binary file, containing the encrypted activation data. > > > > If the idiots could code their system to only work with the prior, and > > dispensed entirely with the second... everything would be just dandy. > > exactly - and do would expect to get a reply from their Support? YEAH RIGHT! > > > As is, to be sure there is no problems activating a new handset, > > you'll have to do something like: > > - In /etc/MailScanner/rules/filetype.rules (referenced in the Filetype > > Rules setting in MailScanner.conf, of course): > > # Bloody ETP.DAT object files from blackberry... > > From: *.blackberry.net > > %etc-dir%/filetype.whitelist.rules.conf > > (beware of linewrapping....:-) > > > > - In /etc/MailScanner/filetype.whitelist.rules.conf .... basically > > just say "allow" to anything. You could make that a one-liner, or copy > > the normal filetypes rule file and change all the "deny" to "allow" > > Using Mailwatch, I have "content.scanning.rules" > > From: 127.0.0.1 no > FromOrTo: default yes > > > do you think it would make make more sense to add > > From: *.blackberry.net no > > > to that? (and spare wathcing an extra rule file :-) The MailWatch rules can't handle wildcards, so .. nope, that likely won't work. One of the reasons I stick to MailScanner rules... Of course, that is provided one don't have a need for lots and lots of rules:-). > > There is no real way around this idiocy, since you cannot predetermine > > exactly which hosts (IP addresses/ranges) they might be sending from, > > nor determine exactly which file magics it can happen to match. > > frustrating - just hard to believe nobody else has come across this > before :-) > Oh, we have... The "BB expert" from Telenor was adamant that we needed do some "exceptions" (_very_ non-specific on the details about what to expect...). So, since the trials went OK, I didn't do any exceptions... until things were going production, and not working out that well:-). > thanks > > Alex > Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From ms-list at alexb.ch Mon Aug 6 14:04:49 2007 From: ms-list at alexb.ch (Alex Broens) Date: Mon Aug 6 14:04:52 2007 Subject: Blackberry - part II In-Reply-To: <223f97700708060549r72cf4eb8n6db4fadfc89bd029@mail.gmail.com> References: <46B6F406.8020008@alexb.ch> <223f97700708060500k66ebdc2ex4070027e15f07333@mail.gmail.com> <46B71576.7040203@alexb.ch> <223f97700708060549r72cf4eb8n6db4fadfc89bd029@mail.gmail.com> Message-ID: <46B71C71.1000606@alexb.ch> On 8/6/2007 2:49 PM, Glenn Steen wrote: >>> >>> - In /etc/MailScanner/filetype.whitelist.rules.conf .... basically >>> just say "allow" to anything. You could make that a one-liner, or copy >>> the normal filetypes rule file and change all the "deny" to "allow" >> Using Mailwatch, I have "content.scanning.rules" >> >> From: 127.0.0.1 no >> FromOrTo: default yes >> >> >> do you think it would make make more sense to add >> >> From: *.blackberry.net no >> >> >> to that? (and spare wathcing an extra rule file :-) > > The MailWatch rules can't handle wildcards, so .. nope, that likely won't work. > One of the reasons I stick to MailScanner rules... Of course, that is > provided one don't have a need for lots and lots of rules:-). This is a MailScanner rule Dangerous Content Scanning = %rules-dir%/content.scanning.rules and Content Filtering is not managed by MailWatch so It may work, though spoofable >>> There is no real way around this idiocy, since you cannot predetermine >>> exactly which hosts (IP addresses/ranges) they might be sending from, >>> nor determine exactly which file magics it can happen to match. >> frustrating - just hard to believe nobody else has come across this >> before :-) >> > Oh, we have... The "BB expert" from Telenor was adamant that we needed > do some "exceptions" (_very_ non-specific on the details about what to > expect...). So, since the trials went OK, I didn't do any > exceptions... until things were going production, and not working out > that well:-). hehe - I see quite a lot of crackberry stuff being delivered without issues and one or two users have all the problems. Try to find a pattern .-) Alex From list-mailscanner at linguaphone.com Mon Aug 6 14:30:34 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon Aug 6 14:30:44 2007 Subject: PATCH SweepViruses.pm - clamavmodule false positives Message-ID: <1186407034.31893.47.camel@gblades-suse.linguaphone-intranet.co.uk> Attached is a patch for SweepViruses.pm which fixes the false positives issue with Phishing.Heuristics.Email.SpoofedDomain when using Clamavmodule and the full message scan option. It passes the CL_SCAN_PHISHING_DOMAINLIST option which according to the clamavmodule source :- =item CL_SCAN_PHISHING_DOMAINLIST Phishing module: restrict URL scanning to domains from .pdf (RECOMMENDED). I believe that as this option was not previously set it is equivalent to the following clamscan option :- --no-phishing-restrictedscan Enable url-based heuristic phishing detection for all domains (might lead to false positives!). Personally I think CL_SCAN_PHISHING_DOMAINLIST should do the same as --no-phishing-restrictedscan and not be the inverse of it. Maybe a bug. I will contact the author about it anyway. I dont really know what this option does exactly but it is a recommended setting, its name seems to indicate it is related to the false positives I was getting, and setting it does seem to have cured the problem. -------------- next part -------------- A non-text attachment was scrubbed... Name: SweepViruses.pm.patch Type: text/x-patch Size: 176 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070806/9f8eea98/SweepViruses.pm.bin From MailScanner at ecs.soton.ac.uk Mon Aug 6 15:07:08 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 6 15:07:29 2007 Subject: Phishing.Heuristics.Email.SpoofedDomain false positives In-Reply-To: <1186399142.31893.6.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1186399142.31893.6.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <46B72B0C.4030502@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Gareth wrote: > I have just upgraded MailScanner and enabled full message scanning but I > am getting a few false positives on > Phishing.Heuristics.Email.SpoofedDomain against some genuine Amazon > emails and a couple of others. > > Strangely when I use clamscan and scan the message file the message is > reported as being clean. > > Quarantine Modified Body = no > Quarantine Whole Message = yes > Quarantine Whole Messages As Queue Files = no > > How does Mailscanner save the raw mail file for clamavmodule to scan? > Could there be a slight difference which is causing the heuristics to > misbehave? > Not as far as I am aware, no. Though the full message is reconstructed from the message entity structure, so it's always possible that something might be in a different order. Have you got a sample message you can give me that demonstrates this problem in action? If so, please put it on a www server somewhere, don't mail it to me. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Comment: (pgp-secured) Charset: ISO-8859-1 wj8DBQFGtysNEfZZRxQVtlQRAkRJAJ40d+zlCMsGtHNmBnnuSfkRiJWuugCg/kAj oHoGZCIdZ2w8GlL/1Kk+FUo= =v+1p -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Mon Aug 6 15:08:04 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 6 15:08:22 2007 Subject: ClamAV module logging changed in 4.62 In-Reply-To: <46B70923.6040309@nerc.ac.uk> References: <46B70923.6040309@nerc.ac.uk> Message-ID: <46B72B44.9090105@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I'll take a look. I use clamavmodule myself, I have no interest in switching to clamd at all. Greg Matthews wrote: > One snag noticed on upgrade to 4.62.9-2 is that the logging of > infections for ClamAV module has changed so that instead of: > > Jul 22 07:21:12 mailr-w MailScanner[8906]: ClamAVModule::INFECTED:: > Html.Phishing.Bank.Sanesecurity.05082901:: > ./l6M6L5eZ010196/msg-8906-8.html > > It now looks like: > > Aug 6 09:59:42 mailr-w MailScanner[3719]: INFECTED:: > Html.Phishing.Bank.Gen2049.Sanesecurity.07080201:: > ./l768xRdk022394/msg-3719-104.html > > Note the missing ClamAVModule:: on the log line. Is this a casualty of > the recent trend to use clamd? I've been perfectly happy with the > module until now. > > GREG Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Comment: (pgp-secured) Charset: ISO-8859-1 wj8DBQFGtytEEfZZRxQVtlQRAsh+AKC0PPNeh/kog3r3aIvz/S97A+5pfgCePoA/ 4zEhI1utR0Pa3PaFr6vWClM= =OhH9 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From list-mailscanner at linguaphone.com Mon Aug 6 15:11:39 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon Aug 6 15:11:49 2007 Subject: Phishing.Heuristics.Email.SpoofedDomain false positives In-Reply-To: <46B72B0C.4030502@ecs.soton.ac.uk> References: <1186399142.31893.6.camel@gblades-suse.linguaphone-intranet.co.uk> <46B72B0C.4030502@ecs.soton.ac.uk> Message-ID: <1186409499.31893.55.camel@gblades-suse.linguaphone-intranet.co.uk> Fixed it and mailed the patch to the list earlier. Personally I think it is a bug with clamavmodule as it has enforced a default action which is not so safe and different to clamscan/clamd but it has been there for a while no so I suppose it is not something which can be changed without introducing more problems. On Mon, 2007-08-06 at 15:07, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Gareth wrote: > > I have just upgraded MailScanner and enabled full message scanning but I > > am getting a few false positives on > > Phishing.Heuristics.Email.SpoofedDomain against some genuine Amazon > > emails and a couple of others. > > > > Strangely when I use clamscan and scan the message file the message is > > reported as being clean. > > > > Quarantine Modified Body = no > > Quarantine Whole Message = yes > > Quarantine Whole Messages As Queue Files = no > > > > How does Mailscanner save the raw mail file for clamavmodule to scan? > > Could there be a slight difference which is causing the heuristics to > > misbehave? > > > Not as far as I am aware, no. Though the full message is reconstructed > from the message entity structure, so it's always possible that > something might be in a different order. > > Have you got a sample message you can give me that demonstrates this > problem in action? > If so, please put it on a www server somewhere, don't mail it to me. > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > Need help customising MailScanner? > Contact me! > Need help fixing or optimising your systems? > Contact me! > Need help getting you started solving new requirements from your boss? > Contact me! > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.2 (Build 2014) > Comment: (pgp-secured) > Charset: ISO-8859-1 > > wj8DBQFGtysNEfZZRxQVtlQRAkRJAJ40d+zlCMsGtHNmBnnuSfkRiJWuugCg/kAj > oHoGZCIdZ2w8GlL/1Kk+FUo= > =v+1p > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Mon Aug 6 15:16:14 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 6 15:16:33 2007 Subject: PATCH SweepViruses.pm - clamavmodule false positives In-Reply-To: <1186407034.31893.47.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1186407034.31893.47.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <46B72D2E.2000208@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 You only actually want to apply the first of the 2 patches, as you only want to affect the code that scans the *.message and *.header files. It will be in the next release. Please can some other people test this and confirm it works reliably? Gareth wrote: > Attached is a patch for SweepViruses.pm which fixes the false positives > issue with Phishing.Heuristics.Email.SpoofedDomain when using > Clamavmodule and the full message scan option. > > It passes the CL_SCAN_PHISHING_DOMAINLIST option which according to the > clamavmodule source :- > =item CL_SCAN_PHISHING_DOMAINLIST > Phishing module: restrict URL scanning to domains from .pdf > (RECOMMENDED). > > I believe that as this option was not previously set it is equivalent to > the following clamscan option :- > --no-phishing-restrictedscan > Enable url-based heuristic phishing detection for all domains > (might lead to false positives!). > > Personally I think CL_SCAN_PHISHING_DOMAINLIST should do the same as > --no-phishing-restrictedscan and not be the inverse of it. Maybe a bug. > I will contact the author about it anyway. > > I dont really know what this option does exactly but it is a recommended > setting, its name seems to indicate it is related to the false positives > I was getting, and setting it does seem to have cured the problem. > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Comment: (pgp-secured) Charset: ISO-8859-1 wj8DBQFGty0vEfZZRxQVtlQRAgNvAKClvd3nYnkZaaePge//JWDYGr8gVACgv7+H ApgOZBY/pz0cF9ZPiEkxnxs= =Jnzy -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From list-mailscanner at linguaphone.com Mon Aug 6 15:33:26 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon Aug 6 15:33:37 2007 Subject: PATCH SweepViruses.pm - clamavmodule false positives In-Reply-To: <46B72D2E.2000208@ecs.soton.ac.uk> References: <1186407034.31893.47.camel@gblades-suse.linguaphone-intranet.co.uk> <46B72D2E.2000208@ecs.soton.ac.uk> Message-ID: <1186410806.31898.61.camel@gblades-suse.linguaphone-intranet.co.uk> What does the 2nd patch affect? Is that when you are not using the full message scan option? In that case I would still suggest applying the 2nd patch as when I looked through my logs I noticed that it did have a single false positive where it matched a legit failed delivery notice. Since the option disables a check on raw messages which should not be there and the fact that the option is the default in clamscan/clamd it makes sense to me for it to be in. On Mon, 2007-08-06 at 15:16, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > You only actually want to apply the first of the 2 patches, as you only > want to affect the code that scans the *.message and *.header files. > > It will be in the next release. > > Please can some other people test this and confirm it works reliably? > > Gareth wrote: > > Attached is a patch for SweepViruses.pm which fixes the false positives > > issue with Phishing.Heuristics.Email.SpoofedDomain when using > > Clamavmodule and the full message scan option. > > > > It passes the CL_SCAN_PHISHING_DOMAINLIST option which according to the > > clamavmodule source :- > > =item CL_SCAN_PHISHING_DOMAINLIST > > Phishing module: restrict URL scanning to domains from .pdf > > (RECOMMENDED). > > > > I believe that as this option was not previously set it is equivalent to > > the following clamscan option :- > > --no-phishing-restrictedscan > > Enable url-based heuristic phishing detection for all domains > > (might lead to false positives!). > > > > Personally I think CL_SCAN_PHISHING_DOMAINLIST should do the same as > > --no-phishing-restrictedscan and not be the inverse of it. Maybe a bug. > > I will contact the author about it anyway. > > > > I dont really know what this option does exactly but it is a recommended > > setting, its name seems to indicate it is related to the false positives > > I was getting, and setting it does seem to have cured the problem. > > > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > Need help customising MailScanner? > Contact me! > Need help fixing or optimising your systems? > Contact me! > Need help getting you started solving new requirements from your boss? > Contact me! > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.2 (Build 2014) > Comment: (pgp-secured) > Charset: ISO-8859-1 > > wj8DBQFGty0vEfZZRxQVtlQRAgNvAKClvd3nYnkZaaePge//JWDYGr8gVACgv7+H > ApgOZBY/pz0cF9ZPiEkxnxs= > =Jnzy > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Mon Aug 6 15:48:55 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 6 15:49:16 2007 Subject: PATCH SweepViruses.pm - clamavmodule false positives In-Reply-To: <1186410806.31898.61.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1186407034.31893.47.camel@gblades-suse.linguaphone-intranet.co.uk> <46B72D2E.2000208@ecs.soton.ac.uk> <1186410806.31898.61.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <46B734D7.5020205@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Okay, if it has caused a second false positive in that situation, then I would advise both patches after all. By the way, when doing diffs for use in patches, please do a "diff - -Naur" as that gives patches in a nice concise format but with enough context. Diffs without any context are impossible to reliably apply. Gareth wrote: > What does the 2nd patch affect? > Is that when you are not using the full message scan option? > > In that case I would still suggest applying the 2nd patch as when I > looked through my logs I noticed that it did have a single false > positive where it matched a legit failed delivery notice. > Since the option disables a check on raw messages which should not be > there and the fact that the option is the default in clamscan/clamd it > makes sense to me for it to be in. > > On Mon, 2007-08-06 at 15:16, Julian Field wrote: > >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> You only actually want to apply the first of the 2 patches, as you only >> want to affect the code that scans the *.message and *.header files. >> >> It will be in the next release. >> >> Please can some other people test this and confirm it works reliably? >> >> Gareth wrote: >> >>> Attached is a patch for SweepViruses.pm which fixes the false positives >>> issue with Phishing.Heuristics.Email.SpoofedDomain when using >>> Clamavmodule and the full message scan option. >>> >>> It passes the CL_SCAN_PHISHING_DOMAINLIST option which according to the >>> clamavmodule source :- >>> =item CL_SCAN_PHISHING_DOMAINLIST >>> Phishing module: restrict URL scanning to domains from .pdf >>> (RECOMMENDED). >>> >>> I believe that as this option was not previously set it is equivalent to >>> the following clamscan option :- >>> --no-phishing-restrictedscan >>> Enable url-based heuristic phishing detection for all domains >>> (might lead to false positives!). >>> >>> Personally I think CL_SCAN_PHISHING_DOMAINLIST should do the same as >>> --no-phishing-restrictedscan and not be the inverse of it. Maybe a bug. >>> I will contact the author about it anyway. >>> >>> I dont really know what this option does exactly but it is a recommended >>> setting, its name seems to indicate it is related to the false positives >>> I was getting, and setting it does seem to have cured the problem. >>> >>> >> Jules >> >> - -- >> Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> Need help customising MailScanner? >> Contact me! >> Need help fixing or optimising your systems? >> Contact me! >> Need help getting you started solving new requirements from your boss? >> Contact me! >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> >> >> -----BEGIN PGP SIGNATURE----- >> Version: PGP Desktop 9.6.2 (Build 2014) >> Comment: (pgp-secured) >> Charset: ISO-8859-1 >> >> wj8DBQFGty0vEfZZRxQVtlQRAgNvAKClvd3nYnkZaaePge//JWDYGr8gVACgv7+H >> ApgOZBY/pz0cF9ZPiEkxnxs= >> =Jnzy >> -----END PGP SIGNATURE----- >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> For all your IT requirements visit www.transtec.co.uk >> > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Comment: (pgp-secured) Charset: ISO-8859-1 wj8DBQFGtzTYEfZZRxQVtlQRAk1vAKCWacUcv9e74uvL/BXJjw8AL84PcACgpXVk eTYXKllqJ7aYY7qaQt0X4XU= =s29h -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Mon Aug 6 16:41:23 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon Aug 6 16:41:35 2007 Subject: "Could not parse Outlook Rich Text attachment"? In-Reply-To: References: <24000b51a3c12f4ea974e335b9372c6c@solidstatelogic.com> Message-ID: Paul Hutchings spake the following on 8/6/2007 1:19 AM: > "TNEF Expander = /usr/bin/tnef --maxsize=100000000" > > My previous Mailscanner.conf has the same in it, tnef shows as v1.4.3. > > It doesn't appear to be affecting all TNEF's just some show up as > corrupt. > > These are on inbound email so we have no control over the format (our > mail server converts RTF email to HTML before sending out). > Probably Exchange 2007 or Outlook 2007 has changed the format of TNEF slightly to accommodate something new. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From iad.scoot at gmail.com Mon Aug 6 17:38:30 2007 From: iad.scoot at gmail.com (Iad Scoot) Date: Mon Aug 6 17:38:34 2007 Subject: converting attachments Message-ID: <88bd43930708060938r53b7824dsba4a59f1a38ee025@mail.gmail.com> Hi, Does MailScanner have a feature that can convert certain types of attachments to other types (.rtf to text, etc)? Here's my situation - I run a BES behind my firewall and some of my BlackBerry users are routinely getting attachments with .rtf extensions. Our BES does not appear to support .rtf so my users can't get to the content when they are away. I'd like to be able to convert these attachments (or make a copy and convert) them to a readable format - could be .txt, .pdf, whatever will be readable by the BlackBerrys. Any thoughts? I saw "unrtf" but I'm not sure how I would integrate that or if it even supports attachments. Thanks... -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070806/135eb402/attachment.html From martinh at solidstatelogic.com Mon Aug 6 17:45:56 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Mon Aug 6 17:46:00 2007 Subject: converting attachments In-Reply-To: <88bd43930708060938r53b7824dsba4a59f1a38ee025@mail.gmail.com> Message-ID: Hi For this particular situation yes it can. There's an option "use TNEF Contents" which can be set to replace.. http://www.mailscanner.info/MailScanner.conf.index.html#Use%20TNEF%20Contents -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Iad Scoot > Sent: 06 August 2007 17:39 > To: MailScanner discussion > Subject: converting attachments > > Hi, > > Does MailScanner have a feature that can convert certain types of > attachments to other types (.rtf to text, etc)? > > Here's my situation - I run a BES behind my firewall and some of my > BlackBerry users are routinely getting attachments with .rtf extensions. > Our BES does not appear to support .rtf so my users can't get to the > content when they are away. I'd like to be able to convert these > attachments (or make a copy and convert) them to a readable format - could > be .txt, .pdf, whatever will be readable by the BlackBerrys. > > Any thoughts? I saw "unrtf" but I'm not sure how I would integrate that or > if it even supports attachments. > > > Thanks... ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From martinh at solidstatelogic.com Mon Aug 6 17:47:16 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Mon Aug 6 17:47:20 2007 Subject: converting attachments In-Reply-To: <88bd43930708060938r53b7824dsba4a59f1a38ee025@mail.gmail.com> Message-ID: Oops my mistake.....you're taking about rft documents not winmail.dat things.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Iad Scoot > Sent: 06 August 2007 17:39 > To: MailScanner discussion > Subject: converting attachments > > Hi, > > Does MailScanner have a feature that can convert certain types of > attachments to other types (.rtf to text, etc)? > > Here's my situation - I run a BES behind my firewall and some of my > BlackBerry users are routinely getting attachments with .rtf extensions. > Our BES does not appear to support .rtf so my users can't get to the > content when they are away. I'd like to be able to convert these > attachments (or make a copy and convert) them to a readable format - could > be .txt, .pdf, whatever will be readable by the BlackBerrys. > > Any thoughts? I saw "unrtf" but I'm not sure how I would integrate that or > if it even supports attachments. > > > Thanks... ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From MailScanner at ecs.soton.ac.uk Mon Aug 6 18:22:08 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 6 18:22:42 2007 Subject: converting attachments In-Reply-To: <88bd43930708060938r53b7824dsba4a59f1a38ee025@mail.gmail.com> References: <88bd43930708060938r53b7824dsba4a59f1a38ee025@mail.gmail.com> Message-ID: <46B758C0.3050501@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 It doesn't at the moment, no. But if your coding is up to it, you could look at the auto-zip code and base a new feature around that code. It shows you how to detect, delete and add new attachments to a message. If you can think of a decent way whereby it could be made generic and customisable, then I would consider it as a feature. It would need to be some form of table of filetypes or filename regexps, a list of conversion tools, and a list of what filenames the conversion tools would produce. How would we express the source and target filenames? The conversion tools are easy, they could even be wrapper scripts if necessary. Basically it needs to be told 1) Look for "foobar" file command output, or *.foo filenames. 2) Path to conversion program with command-line options, including substitutions for source and target filenames, with and without extensions. 3) Name of output file, possibly based on input filename. What does anyone think? Iad Scoot wrote: > Hi, > > Does MailScanner have a feature that can convert certain types of > attachments to other types (.rtf to text, etc)? > > Here's my situation - I run a BES behind my firewall and some of my > BlackBerry users are routinely getting attachments with .rtf > extensions. Our BES does not appear to support .rtf so my users can't > get to the content when they are away. I'd like to be able to convert > these attachments (or make a copy and convert) them to a readable > format - could be .txt, .pdf, whatever will be readable by the > BlackBerrys. > > Any thoughts? I saw "unrtf" but I'm not sure how I would integrate > that or if it even supports attachments. > > > Thanks... Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGt1jDEfZZRxQVtlQRAodLAJ9n5/7mg1PLzP0b2+R1hR9NBbgWzQCfSBbE GwBW2jbo773tUth5DEFzCl4= =Fn9M -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From maillists at conactive.com Mon Aug 6 19:31:13 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Mon Aug 6 19:31:16 2007 Subject: converting attachments In-Reply-To: References: Message-ID: Martin.Hepworth wrote on Mon, 06 Aug 2007 17:47:16 +0100: > you're taking about rft documents not winmail.dat things.. Maybe he *is* ... Iad, you are aware that Exchange can send the mail as an rtf attachment as well? That then just contains the same text as the plain text email. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From r.berber at computer.org Mon Aug 6 19:39:41 2007 From: r.berber at computer.org (=?ISO-8859-1?Q?Ren=E9_Berber?=) Date: Mon Aug 6 19:39:56 2007 Subject: DSN and 4.62.9 problem Message-ID: Hi, Similar problem to that reported for OoO and watermarking, read receipts (DSN) messages do not return the watermark header and MailScanner is tagging all of them as spam with the log showing: MailScanner[2081]: Message l76HJGJu004811 from ... has no (or invalid) NULL-Header or sender address This wasn't the case with the previous version used (4.62.7), I'm testing now with watermarking off. Any other solutions? -- Ren? Berber From rcooper at dwford.com Mon Aug 6 19:43:27 2007 From: rcooper at dwford.com (Rick Cooper) Date: Mon Aug 6 19:43:32 2007 Subject: ClamAV module logging changed in 4.62 In-Reply-To: <46B72B44.9090105@ecs.soton.ac.uk> References: <46B70923.6040309@nerc.ac.uk> <46B72B44.9090105@ecs.soton.ac.uk> Message-ID: <012401c7d859$adeeb620$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On > Behalf Of Julian Field > Sent: Monday, August 06, 2007 10:08 AM > To: MailScanner discussion > Subject: Re: ClamAV module logging changed in 4.62 > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > I'll take a look. I use clamavmodule myself, I have no interest in > switching to clamd at all. > Bear in mind that when clamd was added the name of the scanner is taked from the structure and not hard coded so if he has the display of virus scanners off there would be no name Rick > Greg Matthews wrote: > > One snag noticed on upgrade to 4.62.9-2 is that the logging of > > infections for ClamAV module has changed so that instead of: > > > > Jul 22 07:21:12 mailr-w MailScanner[8906]: > ClamAVModule::INFECTED:: > > Html.Phishing.Bank.Sanesecurity.05082901:: > > ./l6M6L5eZ010196/msg-8906-8.html > > > > It now looks like: > > > > Aug 6 09:59:42 mailr-w MailScanner[3719]: INFECTED:: > > Html.Phishing.Bank.Gen2049.Sanesecurity.07080201:: > > ./l768xRdk022394/msg-3719-104.html > > > > Note the missing ClamAVModule:: on the log line. Is this a > casualty of > > the recent trend to use clamd? I've been perfectly happy with the > > module until now. > > > > GREG > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > Need help customising MailScanner? > Contact me! > Need help fixing or optimising your systems? > Contact me! > Need help getting you started solving new requirements from > your boss? > Contact me! > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.2 (Build 2014) > Comment: (pgp-secured) > Charset: ISO-8859-1 > > wj8DBQFGtytEEfZZRxQVtlQRAsh+AKC0PPNeh/kog3r3aIvz/S97A+5pfgCePoA/ > 4zEhI1utR0Pa3PaFr6vWClM= > =OhH9 > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Mon Aug 6 19:52:57 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 6 19:53:34 2007 Subject: ClamAV module logging changed in 4.62 In-Reply-To: <012401c7d859$adeeb620$0301a8c0@SAHOMELT> References: <46B70923.6040309@nerc.ac.uk> <46B72B44.9090105@ecs.soton.ac.uk> <012401c7d859$adeeb620$0301a8c0@SAHOMELT> Message-ID: <46B76E09.50401@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Rick Cooper wrote: > > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On > > Behalf Of Julian Field > > Sent: Monday, August 06, 2007 10:08 AM > > To: MailScanner discussion > > Subject: Re: ClamAV module logging changed in 4.62 > > > > -----BEGIN PGP SIGNED MESSAGE----- > > Hash: SHA1 > > > > I'll take a look. I use clamavmodule myself, I have no interest in > > switching to clamd at all. > > > > > Bear in mind that when clamd was added the name of the scanner is taked from > the structure and not hard coded so if he has the display of virus scanners > off there would be no name > Good point. That's probably it, I didn't think any of the clamavmodule logging should have changed. > Rick > > > > Greg Matthews wrote: > > > One snag noticed on upgrade to 4.62.9-2 is that the logging of > > > infections for ClamAV module has changed so that instead of: > > > > > > Jul 22 07:21:12 mailr-w MailScanner[8906]: > > ClamAVModule::INFECTED:: > > > Html.Phishing.Bank.Sanesecurity.05082901:: > > > ./l6M6L5eZ010196/msg-8906-8.html > > > > > > It now looks like: > > > > > > Aug 6 09:59:42 mailr-w MailScanner[3719]: INFECTED:: > > > Html.Phishing.Bank.Gen2049.Sanesecurity.07080201:: > > > ./l768xRdk022394/msg-3719-104.html > > > > > > Note the missing ClamAVModule:: on the log line. Is this a > > casualty of > > > the recent trend to use clamd? I've been perfectly happy with the > > > module until now. > > > > > > GREG > > > > Jules > > > > - -- > > Julian Field MEng CITP > > www.MailScanner.info > > Buy the MailScanner book at www.MailScanner.info/store > > > > Need help customising MailScanner? > > Contact me! > > Need help fixing or optimising your systems? > > Contact me! > > Need help getting you started solving new requirements from > > your boss? > > Contact me! > > > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > > > > -----BEGIN PGP SIGNATURE----- > > Version: PGP Desktop 9.6.2 (Build 2014) > > Comment: (pgp-secured) > > Charset: ISO-8859-1 > > > > wj8DBQFGtytEEfZZRxQVtlQRAsh+AKC0PPNeh/kog3r3aIvz/S97A+5pfgCePoA/ > > 4zEhI1utR0Pa3PaFr6vWClM= > > =OhH9 > > -----END PGP SIGNATURE----- > > > > -- > > This message has been scanned for viruses and > > dangerous content by MailScanner, and is > > believed to be clean. > > For all your IT requirements visit www.transtec.co.uk > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > -- > > This message has been scanned for viruses and > > dangerous content by MailScanner, and is > > believed to be clean. > > > > > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGt24MEfZZRxQVtlQRAo7jAJ9GPGiIpzV1805QuKwRr4j5PWIrCQCgxTHS hseB1RQQvycvI77a9+Ual40= =BYyi -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From uxbod at splatnix.net Mon Aug 6 20:37:16 2007 From: uxbod at splatnix.net (UxBoD) Date: Mon Aug 6 20:29:14 2007 Subject: converting attachments In-Reply-To: <46B758C0.3050501@ecs.soton.ac.uk> Message-ID: <25741494.11631186429036639.JavaMail.root@office.splatnix.net> Couldn't the custom action facility be used ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Julian Field" To: "MailScanner discussion" Sent: Monday, August 6, 2007 6:22:08 PM (GMT) Europe/London Subject: Re: converting attachments -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 It doesn't at the moment, no. But if your coding is up to it, you could look at the auto-zip code and base a new feature around that code. It shows you how to detect, delete and add new attachments to a message. If you can think of a decent way whereby it could be made generic and customisable, then I would consider it as a feature. It would need to be some form of table of filetypes or filename regexps, a list of conversion tools, and a list of what filenames the conversion tools would produce. How would we express the source and target filenames? The conversion tools are easy, they could even be wrapper scripts if necessary. Basically it needs to be told 1) Look for "foobar" file command output, or *.foo filenames. 2) Path to conversion program with command-line options, including substitutions for source and target filenames, with and without extensions. 3) Name of output file, possibly based on input filename. What does anyone think? Iad Scoot wrote: > Hi, > > Does MailScanner have a feature that can convert certain types of > attachments to other types (.rtf to text, etc)? > > Here's my situation - I run a BES behind my firewall and some of my > BlackBerry users are routinely getting attachments with .rtf > extensions. Our BES does not appear to support .rtf so my users can't > get to the content when they are away. I'd like to be able to convert > these attachments (or make a copy and convert) them to a readable > format - could be .txt, .pdf, whatever will be readable by the > BlackBerrys. > > Any thoughts? I saw "unrtf" but I'm not sure how I would integrate > that or if it even supports attachments. > > > Thanks... Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGt1jDEfZZRxQVtlQRAodLAJ9n5/7mg1PLzP0b2+R1hR9NBbgWzQCfSBbE GwBW2jbo773tUth5DEFzCl4= =Fn9M -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From iad.scoot at gmail.com Mon Aug 6 22:13:08 2007 From: iad.scoot at gmail.com (Iad Scoot) Date: Mon Aug 6 22:13:11 2007 Subject: converting attachments In-Reply-To: References: Message-ID: <88bd43930708061413n4d8bb9b9k8f5c6ebcf9354fca@mail.gmail.com> This particular issue is one of attachments - someone writes a document and saves it as a .rtf doc (Wordpad, etc) and then sends it attached to an inbound email. My BB users get the message but can't open the attachment. Its not the same issue (AFAIK) as the winmail.dat issue - I already have the TNEF expander configured for that issue. Thanks again... On 8/6/07, Kai Schaetzl wrote: > > Martin.Hepworth wrote on Mon, 06 Aug 2007 17:47:16 +0100: > > > you're taking about rft documents not winmail.dat things.. > > Maybe he *is* ... Iad, you are aware that Exchange can send the mail as an > rtf attachment as well? That then just contains the same text as the plain > text email. > > Kai > > -- > Kai Sch?tzl, Berlin, Germany > Get your web at Conactive Internet Services: http://www.conactive.com > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070806/e8ef3f1b/attachment.html From iad.scoot at gmail.com Mon Aug 6 22:15:48 2007 From: iad.scoot at gmail.com (Iad Scoot) Date: Mon Aug 6 22:15:52 2007 Subject: converting attachments In-Reply-To: <25741494.11631186429036639.JavaMail.root@office.splatnix.net> References: <46B758C0.3050501@ecs.soton.ac.uk> <25741494.11631186429036639.JavaMail.root@office.splatnix.net> Message-ID: <88bd43930708061415r3df376ffxaef5eecce5254f18@mail.gmail.com> Sorry, showing my ignorance - what is the "custom action facility"? Thanks... On 8/6/07, UxBoD wrote: > > Couldn't the custom action facility be used ? > > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B > // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B > // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net > > ----- Original Message ----- > From: "Julian Field" > To: "MailScanner discussion" > Sent: Monday, August 6, 2007 6:22:08 PM (GMT) Europe/London > Subject: Re: converting attachments > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > It doesn't at the moment, no. But if your coding is up to it, you could > look at the auto-zip code and base a new feature around that code. It > shows you how to detect, delete and add new attachments to a message. > > If you can think of a decent way whereby it could be made generic and > customisable, then I would consider it as a feature. It would need to be > some form of table of filetypes or filename regexps, a list of > conversion tools, and a list of what filenames the conversion tools > would produce. How would we express the source and target filenames? The > conversion tools are easy, they could even be wrapper scripts if > necessary. > > Basically it needs to be told > 1) Look for "foobar" file command output, or *.foo filenames. > 2) Path to conversion program with command-line options, including > substitutions for source and target filenames, with and without > extensions. > 3) Name of output file, possibly based on input filename. > > What does anyone think? > > Iad Scoot wrote: > > Hi, > > > > Does MailScanner have a feature that can convert certain types of > > attachments to other types (.rtf to text, etc)? > > > > Here's my situation - I run a BES behind my firewall and some of my > > BlackBerry users are routinely getting attachments with .rtf > > extensions. Our BES does not appear to support .rtf so my users can't > > get to the content when they are away. I'd like to be able to convert > > these attachments (or make a copy and convert) them to a readable > > format - could be .txt, .pdf, whatever will be readable by the > > BlackBerrys. > > > > Any thoughts? I saw "unrtf" but I'm not sure how I would integrate > > that or if it even supports attachments. > > > > > > Thanks... > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.2 (Build 2014) > Charset: ISO-8859-1 > > wj8DBQFGt1jDEfZZRxQVtlQRAodLAJ9n5/7mg1PLzP0b2+R1hR9NBbgWzQCfSBbE > GwBW2jbo773tUth5DEFzCl4= > =Fn9M > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070806/9062688c/attachment.html From ssilva at sgvwater.com Mon Aug 6 22:44:42 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon Aug 6 22:44:53 2007 Subject: converting attachments In-Reply-To: <88bd43930708060938r53b7824dsba4a59f1a38ee025@mail.gmail.com> References: <88bd43930708060938r53b7824dsba4a59f1a38ee025@mail.gmail.com> Message-ID: Iad Scoot spake the following on 8/6/2007 9:38 AM: > Hi, > > Does MailScanner have a feature that can convert certain types of > attachments to other types (.rtf to text, etc)? > > Here's my situation - I run a BES behind my firewall and some of my > BlackBerry users are routinely getting attachments with .rtf extensions. > Our BES does not appear to support .rtf so my users can't get to the > content when they are away. I'd like to be able to convert these > attachments (or make a copy and convert) them to a readable format - > could be .txt, .pdf, whatever will be readable by the BlackBerrys. > > Any thoughts? I saw "unrtf" but I'm not sure how I would integrate that > or if it even supports attachments. > > > Thanks... > Will your BES pass them through unmolested? If so, you could try something like beamberry on the blackberrys. http://www.beamberry.com -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From maillists at conactive.com Mon Aug 6 22:52:33 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Mon Aug 6 22:52:37 2007 Subject: Error after upgrade In-Reply-To: <200708061050.l76AoosW015077@balita.ph> References: <200708030852.l738qkTp030708@balita.ph> <30884165.10941186139270824.JavaMail.root@office.splatnix.net> <30884165.10941186139270824.JavaMail.root@office.splatnix.n et> <200708031120.l73BKo5w029434@balita.ph> <200708032341.l73NfRYq018027@balita.ph> <200708060840.l768eHRQ026636@balita.ph> <200708061050.l76AoosW015077@balita.ph> Message-ID: Wayne wrote on Mon, 06 Aug 2007 11:50:53 +0100: > First part relates to Razor.pm _which is_ at > /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi despite the > error saying it is not. But that is not where your sa is looking for it. It looks like you have a mixed version of sa installed, something from the earlier rpm and something from Julian's all-in-one package (I assume this is from Julian's package: Mail/Spamassassin/Plugin/Razor2.pm - I've never installed any of his all-inone packages, though). Maybe just that the spamassassin executable is still the old one or that you have *two* spamassassin executables installed and one of them (the older one) is first in your path. I'd say: updatedb and locate, then remove all traces of SA and reinstall from Julian's package. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From res at ausics.net Mon Aug 6 22:54:32 2007 From: res at ausics.net (Res) Date: Mon Aug 6 22:54:41 2007 Subject: Error after upgrade In-Reply-To: References: <200708030852.l738qkTp030708@balita.ph> <30884165.10941186139270824.JavaMail.root@office.splatnix.net> <30884165.10941186139270824.JavaMail.root@office.splatnix.n et> <200708031120.l73BKo5w029434@balita.ph> <200708032341.l73NfRYq018027@balita.ph> <200708060840.l768eHRQ026636@balita.ph> <200708061050.l76AoosW015077@balita.ph> Message-ID: On Mon, 6 Aug 2007, Kai Schaetzl wrote: > Wayne wrote on Mon, 06 Aug 2007 11:50:53 +0100: > >> First part relates to Razor.pm _which is_ at >> /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi despite the >> error saying it is not. > > But that is not where your sa is looking for it. It looks like you have a > mixed version of sa installed, something from the earlier rpm and and a very OLD version of perl -- Cheers Res From matt at coders.co.uk Mon Aug 6 23:05:11 2007 From: matt at coders.co.uk (Matt Hampton) Date: Mon Aug 6 23:03:33 2007 Subject: DSN and 4.62.9 problem In-Reply-To: References: Message-ID: <46B79B17.90005@coders.co.uk> Ren? Berber wrote: > Hi, > > Similar problem to that reported for OoO and watermarking, read receipts (DSN) > messages do not return the watermark header and MailScanner is tagging all of > them as spam with the log showing: > > MailScanner[2081]: Message l76HJGJu004811 from ... has no (or invalid) > NULL-Header or sender address > > This wasn't the case with the previous version used (4.62.7), I'm testing now > with watermarking off. Any other solutions? The actual Watermarking code did not change between these versions - the only change was wrapping the whole thing in a "Use Watermarking" control. The code works in the same way as milter-null so anyone who is using milter-null would experience the same problems (and additional testing in the last couple of hours confirms this). If anyone else can send me raw queue files (offlist) of any incorrectly marked messages I can try and do something - I have one from Martin but a few more would be good. OoO will never be fixable without straying in to the patented method of changing the Message-ID a la http://arstechnica.com/news.ars/post/20050713-5090.html There may be a way to fix read receipts but this would require maintaining state (which would break the ability to have multiple independent servers) or possibly find a way of allowing read receipts. matt From cleveland at winnefox.org Mon Aug 6 23:05:47 2007 From: cleveland at winnefox.org (Jody Cleveland) Date: Mon Aug 6 23:06:18 2007 Subject: MailScanner --lint error Message-ID: Hello, I just upgraded to the most current stable release of MailScanner, and when I do a MailScanner --lint, I get this error: Cannot open config file --lint, No such file or directory at /usr/lib/MailScanner/MailScanner/Config.pm line 656. Compilation failed in require at /usr/sbin/MailScanner line 69. BEGIN failed--compilation aborted at /usr/sbin/MailScanner line 69. Any idea how I can fix this? - jody From r.berber at computer.org Mon Aug 6 23:28:28 2007 From: r.berber at computer.org (=?ISO-8859-1?Q?Ren=E9_Berber?=) Date: Mon Aug 6 23:28:51 2007 Subject: DSN and 4.62.9 problem In-Reply-To: <46B79B17.90005@coders.co.uk> References: <46B79B17.90005@coders.co.uk> Message-ID: Matt Hampton wrote: > Ren? Berber wrote: >> >> Similar problem to that reported for OoO and watermarking, read receipts (DSN) >> messages do not return the watermark header and MailScanner is tagging all of >> them as spam with the log showing: >> >> MailScanner[2081]: Message l76HJGJu004811 from ... has no (or invalid) >> NULL-Header or sender address >> >> This wasn't the case with the previous version used (4.62.7), I'm testing now >> with watermarking off. Any other solutions? > > The actual Watermarking code did not change between these versions - the > only change was wrapping the whole thing in a "Use Watermarking" control. Perhaps I'm wrong with the versions, I don't think so but is a possibility (in fact I only have seen these errors since I installed 4.62.9 a week ago, but I think some DSN messages are not marked which I attributed to an IP whitelisted). Anyway, confirmed: testing with watermarking off allows DSN reception without marking them as spam. > The code works in the same way as milter-null so anyone who is using > milter-null would experience the same problems (and additional testing > in the last couple of hours confirms this). > > If anyone else can send me raw queue files (offlist) of any incorrectly > marked messages I can try and do something - I have one from Martin but > a few more would be good. Do you need raw queue files (the pair)? I only have samples of the received message. > OoO will never be fixable without straying in to the patented method of > changing the Message-ID a la > > http://arstechnica.com/news.ars/post/20050713-5090.html > > There may be a way to fix read receipts but this would require > maintaining state (which would break the ability to have multiple > independent servers) or possibly find a way of allowing read receipts. If the DSN doesn't return the watermark there is nothing to check... -- Ren? Berber From ssilva at sgvwater.com Mon Aug 6 23:41:35 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon Aug 6 23:41:48 2007 Subject: MailScanner --lint error In-Reply-To: References: Message-ID: Jody Cleveland spake the following on 8/6/2007 3:05 PM: > Hello, > > I just upgraded to the most current stable release of MailScanner, and when > I do a MailScanner --lint, I get this error: > > Cannot open config file --lint, No such file or directory at > /usr/lib/MailScanner/MailScanner/Config.pm line 656. > Compilation failed in require at /usr/sbin/MailScanner line 69. > BEGIN failed--compilation aborted at /usr/sbin/MailScanner line 69. > > Any idea how I can fix this? > > - jody > Current stable from www.mailscanner.info, or current stable from a packager like debian or freebsd? Check for .rpmnew files in /usr/lib/MailScanner/MailScanner -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From mailscanner at home.carlo65.de Mon Aug 6 23:56:06 2007 From: mailscanner at home.carlo65.de (R. Ehle (MailScanner Mailinglist)) Date: Mon Aug 6 23:56:27 2007 Subject: AW: DSN and 4.62.9 problem In-Reply-To: <46B79B17.90005@coders.co.uk> References: <46B79B17.90005@coders.co.uk> Message-ID: <4D1CD0994309F84BA83DF998BF0075AF4328E173@ts-dc2.TS-Webarts.local> Hi all, I experienced problems with the watermarking function too. As far as I found out, the errors only appear, when the DSN is sent from a Microsoft Exchange Server. Actually the Exchange Server sends a complete new message, which does not contain the header from the original message. So I don't think, that there will be a possibility to solve this issue. Regards, Roland -----Urspr?ngliche Nachricht----- Von: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Im Auftrag von Matt Hampton Gesendet: Dienstag, 7. August 2007 00:05 An: MailScanner discussion Betreff: Re: DSN and 4.62.9 problem Ren? Berber wrote: > Hi, > > Similar problem to that reported for OoO and watermarking, read receipts (DSN) > messages do not return the watermark header and MailScanner is tagging all of > them as spam with the log showing: > > MailScanner[2081]: Message l76HJGJu004811 from ... has no (or invalid) > NULL-Header or sender address > > This wasn't the case with the previous version used (4.62.7), I'm testing now > with watermarking off. Any other solutions? The actual Watermarking code did not change between these versions - the only change was wrapping the whole thing in a "Use Watermarking" control. The code works in the same way as milter-null so anyone who is using milter-null would experience the same problems (and additional testing in the last couple of hours confirms this). If anyone else can send me raw queue files (offlist) of any incorrectly marked messages I can try and do something - I have one from Martin but a few more would be good. OoO will never be fixable without straying in to the patented method of changing the Message-ID a la http://arstechnica.com/news.ars/post/20050713-5090.html There may be a way to fix read receipts but this would require maintaining state (which would break the ability to have multiple independent servers) or possibly find a way of allowing read receipts. matt -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ---------------------------------------------------------- Diese Nachricht wurde von mailMind(R) auf Viren und andere gefaehrliche Inhalte untersucht und ist sauber. --- mailMind(R) - we have your Mailsecurity in mind! http://www.mailmind.de --- From cleveland at winnefox.org Tue Aug 7 00:28:52 2007 From: cleveland at winnefox.org (Jody Cleveland) Date: Tue Aug 7 00:29:23 2007 Subject: MailScanner --lint error In-Reply-To: Message-ID: On 8/6/07 5:41 PM, "Scott Silva" wrote: > Jody Cleveland spake the following on 8/6/2007 3:05 PM: >> Hello, >> >> I just upgraded to the most current stable release of MailScanner, and when >> I do a MailScanner --lint, I get this error: >> >> Cannot open config file --lint, No such file or directory at >> /usr/lib/MailScanner/MailScanner/Config.pm line 656. >> Compilation failed in require at /usr/sbin/MailScanner line 69. >> BEGIN failed--compilation aborted at /usr/sbin/MailScanner line 69. >> >> Any idea how I can fix this? >> >> - jody >> > Current stable from www.mailscanner.info, or current stable from a packager > like debian or freebsd? The current stable from www.mailscanner.info > Check for .rpmnew files in /usr/lib/MailScanner/MailScanner There's one .rpmnew file. CustomConfig.pm.rpmnew Should I delete this file? - jody From maillists at conactive.com Tue Aug 7 00:31:10 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Tue Aug 7 00:31:13 2007 Subject: Error after upgrade In-Reply-To: References: <200708030852.l738qkTp030708@balita.ph> <30884165.10941186139270824.JavaMail.root@office.splatnix.net> <30884165.10941186139270824.JavaMail.root@office.splatnix.n et> <200708031120.l73BKo5w029434@balita.ph> <200708032341.l73NfRYq018027@balita.ph> <200708060840.l768eHRQ026636@balita.ph> <200708061050.l76AoosW015077@balita.ph> Message-ID: Res wrote on Tue, 7 Aug 2007 07:54:32 +1000 (EST): > and a very OLD version of perl I wouldn't consider 5.8.5 "very old". My oldest installations are 5.8.0 (security-patched) and all SA versions are just fine on them. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From ssilva at sgvwater.com Tue Aug 7 00:40:50 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue Aug 7 00:41:01 2007 Subject: MailScanner --lint error In-Reply-To: References: Message-ID: Jody Cleveland spake the following on 8/6/2007 4:28 PM: > > > On 8/6/07 5:41 PM, "Scott Silva" wrote: > >> Jody Cleveland spake the following on 8/6/2007 3:05 PM: >>> Hello, >>> >>> I just upgraded to the most current stable release of MailScanner, and when >>> I do a MailScanner --lint, I get this error: >>> >>> Cannot open config file --lint, No such file or directory at >>> /usr/lib/MailScanner/MailScanner/Config.pm line 656. >>> Compilation failed in require at /usr/sbin/MailScanner line 69. >>> BEGIN failed--compilation aborted at /usr/sbin/MailScanner line 69. >>> >>> Any idea how I can fix this? >>> >>> - jody >>> >> Current stable from www.mailscanner.info, or current stable from a packager >> like debian or freebsd? > > The current stable from www.mailscanner.info > >> Check for .rpmnew files in /usr/lib/MailScanner/MailScanner > > There's one .rpmnew file. CustomConfig.pm.rpmnew > > Should I delete this file? > > - jody > NO!! Try renaming the CustomConfig.pm to CustomConfig.pm.old and rename CustomConfig.pm.rpmnew CustomConfig.pm Then retry the --lint -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From res at ausics.net Tue Aug 7 00:45:44 2007 From: res at ausics.net (Res) Date: Tue Aug 7 00:45:52 2007 Subject: Error after upgrade In-Reply-To: References: <200708030852.l738qkTp030708@balita.ph> <30884165.10941186139270824.JavaMail.root@office.splatnix.net> <30884165.10941186139270824.JavaMail.root@office.splatnix.n et> <200708031120.l73BKo5w029434@balita.ph> <200708032341.l73NfRYq018027@balita.ph> <200708060840.l768eHRQ026636@balita.ph> <200708061050.l76AoosW015077@balita.ph> Message-ID: On Tue, 7 Aug 2007, Kai Schaetzl wrote: > Res wrote on Tue, 7 Aug 2007 07:54:32 +1000 (EST): > >> and a very OLD version of perl > > I wouldn't consider 5.8.5 "very old". My oldest installations are 5.8.0 it's about 3.5 years, and in perl development/errata time that might as well be 8 years :) -- Cheers Res From stork at openenterprise.ca Tue Aug 7 01:30:11 2007 From: stork at openenterprise.ca (Johnny Stork) Date: Tue Aug 7 01:30:16 2007 Subject: Subject Text Not Getting Modified? In-Reply-To: <17305916.8541185954848518.JavaMail.root@office.splatnix.net> References: <17305916.8541185954848518.JavaMail.root@office.splatnix.net> Message-ID: <46B7BD13.7010703@openenterprise.ca> I had to reboot the server recently for something else, and strangely enough the subject lines are getting rewritten? maybe something related was hung? Either way its working now....strange indeed. Thanks UxBoD wrote: > What rules do you have setup ? > > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B > // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B > // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net > > ----- Original Message ----- > From: "Johnny Stork" > To: "MailScanner discussion" > Sent: Wednesday, August 1, 2007 2:57:42 AM (GMT) Europe/London > Subject: Subject Text Not Getting Modified? > > From r.berber at computer.org Tue Aug 7 01:41:32 2007 From: r.berber at computer.org (=?ISO-8859-1?Q?Ren=E9_Berber?=) Date: Tue Aug 7 01:42:00 2007 Subject: AW: DSN and 4.62.9 problem In-Reply-To: <4D1CD0994309F84BA83DF998BF0075AF4328E173@ts-dc2.TS-Webarts.local> References: <46B79B17.90005@coders.co.uk> <4D1CD0994309F84BA83DF998BF0075AF4328E173@ts-dc2.TS-Webarts.local> Message-ID: R. Ehle wrote: > I experienced problems with the watermarking function too. > > As far as I found out, the errors only appear, when the DSN is sent from a > Microsoft Exchange Server. Actually the Exchange Server sends a complete new > message, which does not contain the header from the original message. So I > don't think, that there will be a possibility to solve this issue. No, I don't agree, I'm seeing the problem with only sendmail involved as server, Outlook as client. It's our own read receipts that are being marked as spam, as well as our (business) clients, some of which do have Exchange. FWIW I've never seen the need for milter-null or similar, greylisting + Botnet takes care of that problem. -- Ren? Berber From stork at openenterprise.ca Tue Aug 7 03:25:43 2007 From: stork at openenterprise.ca (Johnny Stork) Date: Tue Aug 7 03:25:59 2007 Subject: Help with sa-update, SARE and RDJ ---Please Message-ID: <46B7D827.2010004@openenterprise.ca> I am trying to cleanup my current MS install which I have been happily running for a few years and just updated to the most current version. I had previously been running RDJ but the daily reports showed many errors and so I am trying to get a final, working and relatively clean setup. After a number of attempts and a great deal of reading, searching and a few posts, this whole automated update process seems very unnecessarily confusing. Many sites are outdated, no docs available on SARE, some sites say to use RDJ, others say RDJ is broken and use sa-update and recently Julian indicated I could find some how-to's on the mailing list archive but after searching each monthly archive going back around 1 year, I could find not HOWTO for sa-update. Please dont take this as a complaint, just some frustration likely brought on through my own ignorance. I would be greatful if someone could help me with some instructions on setting up sa-update and if it is usefull or recommended, RDJ. The simpler the overall setup thye better and if I can get ALL possible updates, and of course update/edit locations/channels for rules etc like in a custom text file to use with sa-update, that might be preferable. I also seem to have rules files all over the place and dont know which are necessary, correctly installed or even being used. I beleive that sa-update is putting files correctly in /var/lib/spamassassin/3.002002/updates_spamassassin_org as I can see some recent dates (see ls listings below). I also downloaded a current RDJ, wiped out my /etc/mail/spamassassin/RulesDuJour folder, removed the apparently outdated RDJ wrapper script from /'etc/cron.daily and used the newer rules_du_jour file and followed the instructions contained in it. When I ran the newer /etc/cron.daily/rules_du_jour file, the /etc/mail/spamassassin/RulesDuJour folder got populated with a bunch of new files so I think I am getting both the updates from sa-update and RDJ now, but how can I ensure that SA is actually using them? I also provide a "spamassassin -D --lint" test below if this helps. From looking at the output it "appears" as if all my rules are getting loaded, although I am a bit confused with them lines "[4544] dbg: config: read file /etc/mail/spamassassin/70_sare_adult.cf" etc since the files actually exist in "/etc/mail/spamassassin'RulesDuJour"? This may be a confusing post so I will try and straighten it out with clear, numbered questions: 1: /etc/cron.daily has "sa-update", "rules_du_jour" and "update_spamassassin". Are all these necessary? 2: Can the sa-update rules and RDJ rules download all be combined into a single script/tool? 3: Does it look like all my rules are currently being used and update? 4: Does anyone have a suggested rules set, or channels file that can be used to manage and update all SA rules in a clear and simple location/file? 5: Any other suggestions for a simple to manage, and clean setup of SA and SARE rules and automatic update? Contents of /etc/mail/spamassassin/RulesDuJour/ ls -la /etc/mail/spamassassin/RulesDuJour/ total 1048 drwxr-xr-x 2 root root 4096 Aug 6 19:11 . drwxr-xr-x 5 root root 4096 Aug 6 19:11 .. -rw-r--r-- 1 root root 53932 May 21 00:00 70_sare_adult.cf -rw-r--r-- 1 root root 3839 Jun 1 2005 70_sare_bayes_poison_nxm.cf -rw-r--r-- 1 root root 6970 Jun 1 2005 70_sare_evilnum2.cf -rw-r--r-- 1 root root 45933 Dec 26 2005 70_sare_genlsubj0.cf -rw-r--r-- 1 root root 75181 Nov 14 2006 70_sare_genlsubj1.cf -rw-r--r-- 1 root root 17533 Dec 26 2005 70_sare_genlsubj2.cf -rw-r--r-- 1 root root 49125 Dec 26 2005 70_sare_genlsubj3.cf -rw-r--r-- 1 root root 28066 Jun 3 2006 70_sare_html0.cf -rw-r--r-- 1 root root 39625 Jun 3 2006 70_sare_html1.cf -rw-r--r-- 1 root root 21296 Jun 3 2006 70_sare_html2.cf -rw-r--r-- 1 root root 17773 Jun 3 2006 70_sare_html3.cf -rw-r--r-- 1 root root 158982 Jun 5 01:00 70_sare_obfu.cf -rw-r--r-- 1 root root 12739 Dec 27 2005 70_sare_oem.cf -rw-r--r-- 1 root root 18190 Dec 12 2005 70_sare_random.cf -rw-r--r-- 1 root root 97820 May 27 2006 70_sare_specific.cf -rw-r--r-- 1 root root 20429 Jan 15 2007 70_sare_spoof.cf -rw-r--r-- 1 root root 60307 May 6 14:00 70_sare_stocks.cf -rw-r--r-- 1 root root 25124 Nov 12 2005 70_sare_unsub.cf -rw-r--r-- 1 root root 17879 Oct 4 2005 70_sare_uri0.cf -rw-r--r-- 1 root root 24248 Oct 10 2005 70_sare_uri1.cf -rw-r--r-- 1 root root 8502 Oct 4 2005 70_sare_uri3.cf -rw-r--r-- 1 root root 36610 May 15 2006 70_sare_whitelist_rcvd.cf -rw-r--r-- 1 root root 31789 Aug 27 2006 70_sare_whitelist_spf.cf -rw-r--r-- 1 root root 8956 May 24 02:00 70_sc_top200.cf -rw-r--r-- 1 root root 13217 May 21 00:00 72_sare_bml_post25x.cf -rw-r--r-- 1 root root 15481 May 15 2006 72_sare_redirect_post3.0.0.cf -rw-r--r-- 1 root root 10147 Jun 1 2005 99_sare_fraud_post25x.cf -rw-r--r-- 1 root root 62898 Dec 8 2006 rules_du_jour Contents of /var/lib/spamassassin/3.002002/updates_spamassassin_org ls -la /var/lib/spamassassin/3.002002/updates_spamassassin_org total 604 drwxr-xr-x 2 root root 4096 Aug 5 05:08 . drwxr-xr-x 3 root root 4096 Aug 6 19:00 .. -rw-r--r-- 1 root root 5656 Aug 5 05:08 10_default_prefs.cf -rw-r--r-- 1 root root 7509 Aug 5 05:08 20_advance_fee.cf -rw-r--r-- 1 root root 6779 Aug 5 05:08 20_body_tests.cf -rw-r--r-- 1 root root 1894 Aug 5 05:08 20_compensate.cf -rw-r--r-- 1 root root 14836 Aug 5 05:08 20_dnsbl_tests.cf -rw-r--r-- 1 root root 14998 Aug 5 05:08 20_drugs.cf -rw-r--r-- 1 root root 10908 Aug 5 05:08 20_dynrdns.cf -rw-r--r-- 1 root root 8386 Aug 5 05:08 20_fake_helo_tests.cf -rw-r--r-- 1 root root 24693 Aug 5 05:08 20_head_tests.cf -rw-r--r-- 1 root root 10480 Aug 5 05:08 20_html_tests.cf -rw-r--r-- 1 root root 5290 Aug 5 05:08 20_imageinfo.cf -rw-r--r-- 1 root root 3330 Aug 5 05:08 20_meta_tests.cf -rw-r--r-- 1 root root 2524 Aug 5 05:08 20_net_tests.cf -rw-r--r-- 1 root root 8645 Aug 5 05:08 20_phrases.cf -rw-r--r-- 1 root root 2062 Aug 5 05:08 20_porn.cf -rw-r--r-- 1 root root 15880 Aug 5 05:08 20_ratware.cf -rw-r--r-- 1 root root 5480 Aug 5 05:08 20_uri_tests.cf -rw-r--r-- 1 root root 18018 Aug 5 05:08 20_vbounce.cf -rw-r--r-- 1 root root 2576 Aug 5 05:08 23_bayes.cf -rw-r--r-- 1 root root 1547 Aug 5 05:08 25_accessdb.cf -rw-r--r-- 1 root root 1539 Aug 5 05:08 25_antivirus.cf -rw-r--r-- 1 root root 1547 Aug 5 05:08 25_asn.cf -rw-r--r-- 1 root root 1312 Aug 5 05:08 25_dcc.cf -rw-r--r-- 1 root root 2187 Aug 5 05:08 25_dkim.cf -rw-r--r-- 1 root root 2129 Aug 5 05:08 25_domainkeys.cf -rw-r--r-- 1 root root 2932 Aug 5 05:08 25_hashcash.cf -rw-r--r-- 1 root root 1313 Aug 5 05:08 25_pyzor.cf -rw-r--r-- 1 root root 3392 Aug 5 05:08 25_razor2.cf -rw-r--r-- 1 root root 7642 Aug 5 05:08 25_replace.cf -rw-r--r-- 1 root root 2904 Aug 5 05:08 25_spf.cf -rw-r--r-- 1 root root 1771 Aug 5 05:08 25_textcat.cf -rw-r--r-- 1 root root 7618 Aug 5 05:08 25_uribl.cf -rw-r--r-- 1 root root 29748 Aug 5 05:08 30_text_de.cf -rw-r--r-- 1 root root 22167 Aug 5 05:08 30_text_fr.cf -rw-r--r-- 1 root root 1861 Aug 5 05:08 30_text_it.cf -rw-r--r-- 1 root root 22510 Aug 5 05:08 30_text_nl.cf -rw-r--r-- 1 root root 19405 Aug 5 05:08 30_text_pl.cf -rw-r--r-- 1 root root 2883 Aug 5 05:08 30_text_pt_br.cf -rw-r--r-- 1 root root 49430 Aug 5 05:08 50_scores.cf -rw-r--r-- 1 root root 1307 Aug 5 05:08 60_awl.cf -rw-r--r-- 1 root root 2775 Aug 5 05:08 60_shortcircuit.cf -rw-r--r-- 1 root root 5150 Aug 5 05:08 60_whitelist.cf -rw-r--r-- 1 root root 2537 Aug 5 05:08 60_whitelist_dk.cf -rw-r--r-- 1 root root 2561 Aug 5 05:08 60_whitelist_dkim.cf -rw-r--r-- 1 root root 3587 Aug 5 05:08 60_whitelist_spf.cf -rw-r--r-- 1 root root 1917 Aug 5 05:08 60_whitelist_subject.cf -rw-r--r-- 1 root root 118877 Aug 5 05:08 72_active.cf -rw-r--r-- 1 root root 1392 Aug 5 05:08 72_scores.cf -rw-r--r-- 1 root root 1700 Aug 5 05:08 80_additional.cf -rw-r--r-- 1 root root 235 Aug 5 05:08 MIRRORED.BY Results of spamassassin -D --lint: root@gateway:/etc/cron.daily# spamassassin -D --lint [4544] dbg: logger: adding facilities: all [4544] dbg: logger: logging level is DBG [4544] dbg: generic: SpamAssassin version 3.2.2 [4544] dbg: config: score set 0 chosen. [4544] dbg: util: running in taint mode? yes [4544] dbg: util: taint mode: deleting unsafe environment variables, resetting PATH [4544] dbg: util: PATH included '/usr/kerberos/sbin', keeping [4544] dbg: util: PATH included '/usr/kerberos/bin', keeping [4544] dbg: util: PATH included '/usr/local/sbin', keeping [4544] dbg: util: PATH included '/usr/local/bin', keeping [4544] dbg: util: PATH included '/sbin', keeping [4544] dbg: util: PATH included '/bin', keeping [4544] dbg: util: PATH included '/usr/sbin', keeping [4544] dbg: util: PATH included '/usr/bin', keeping [4544] dbg: util: PATH included '/usr/X11R6/bin', keeping [4544] dbg: util: PATH included '/root/bin', which doesn't exist, dropping [4544] dbg: util: final PATH set to: /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin:/usr/X11R6/bin [4544] dbg: dns: is Net::DNS::Resolver available? yes [4544] dbg: dns: Net::DNS version: 0.60 [4544] dbg: diag: perl platform: 5.008008 linux [4544] dbg: diag: module installed: Digest::SHA1, version 2.10 [4544] dbg: diag: module installed: HTML::Parser, version 3.56 [4544] dbg: diag: module installed: Net::DNS, version 0.60 [4544] dbg: diag: module installed: MIME::Base64, version 3.07 [4544] dbg: diag: module installed: DB_File, version 1.814 [4544] dbg: diag: module installed: Net::SMTP, version 2.29 [4544] dbg: diag: module installed: Mail::SPF, version v2.004 [4544] dbg: diag: module installed: Mail::SPF::Query, version 1.999001 [4544] dbg: diag: module installed: IP::Country::Fast, version 604.001 [4544] dbg: diag: module installed: Razor2::Client::Agent, version 2.77 [4544] dbg: diag: module installed: Net::Ident, version 1.20 [4544] dbg: diag: module installed: IO::Socket::INET6, version 2.51 [4544] dbg: diag: module installed: IO::Socket::SSL, version 0.97 [4544] dbg: diag: module installed: Compress::Zlib, version 1.41 [4544] dbg: diag: module installed: Time::HiRes, version 1.86 [4544] dbg: diag: module installed: Mail::DomainKeys, version 0.80 [4544] dbg: diag: module not installed: Mail::DKIM ('require' failed) [4544] dbg: diag: module installed: DBI, version 1.56 [4544] dbg: diag: module installed: Getopt::Long, version 2.35 [4544] dbg: diag: module installed: LWP::UserAgent, version 2.033 [4544] dbg: diag: module installed: HTTP::Date, version 1.47 [4544] dbg: diag: module installed: Archive::Tar, version 1.29 [4544] dbg: diag: module installed: IO::Zlib, version 1.04 [4544] dbg: diag: module installed: Encode::Detect, version 1.00 [4544] dbg: ignore: using a test message to lint rules [4544] dbg: config: using "/etc/mail/spamassassin" for site rules pre files [4544] dbg: config: read file /etc/mail/spamassassin/init.pre [4544] dbg: config: read file /etc/mail/spamassassin/v310.pre [4544] dbg: config: read file /etc/mail/spamassassin/v312.pre [4544] dbg: config: read file /etc/mail/spamassassin/v320.pre [4544] dbg: config: using "/var/lib/spamassassin/3.002002" for sys rules pre files [4544] dbg: config: using "/var/lib/spamassassin/3.002002" for default rules dir [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org.cf [4544] dbg: config: using "/etc/mail/spamassassin" for site rules dir [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_adult.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_bayes_poison_nxm.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_evilnum2.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_genlsubj0.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_genlsubj1.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_genlsubj2.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_genlsubj3.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_html0.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_html1.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_html2.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_html3.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_obfu.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_oem.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_random.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_specific.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_spoof.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_stocks.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_unsub.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_uri0.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_uri1.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_uri3.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_whitelist_rcvd.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sare_whitelist_spf.cf [4544] dbg: config: read file /etc/mail/spamassassin/70_sc_top200.cf [4544] dbg: config: read file /etc/mail/spamassassin/72_sare_bml_post25x.cf [4544] dbg: config: read file /etc/mail/spamassassin/72_sare_redirect_post3.0.0.cf [4544] dbg: config: read file /etc/mail/spamassassin/99_sare_fraud_post25x.cf [4544] dbg: config: read file /etc/mail/spamassassin/bogus-virus-warnings.cf [4544] dbg: config: read file /etc/mail/spamassassin/crm114.cf [4544] dbg: config: read file /etc/mail/spamassassin/random.cf [4544] dbg: config: read file /etc/mail/spamassassin/tripwire.cf [4544] dbg: config: using "/root/.spamassassin/user_prefs" for user prefs file [4544] dbg: config: read file /root/.spamassassin/user_prefs [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::DCC from @INC [4544] dbg: dcc: local tests only, disabling DCC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::SpamCop from @INC [4544] dbg: reporter: local tests only, disabling SpamCop [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::DomainKeys from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::DCC from @INC [4544] dbg: dcc: local tests only, disabling DCC [4544] dbg: plugin: did not register Mail::SpamAssassin::Plugin::DCC=HASH(0xa3b299c), already registered [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC [4544] dbg: pyzor: local tests only, disabling Pyzor [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::SpamCop from @INC [4544] dbg: reporter: local tests only, disabling SpamCop [4544] dbg: plugin: did not register Mail::SpamAssassin::Plugin::SpamCop=HASH(0xa3b2888), already registered [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [4544] dbg: razor2: local tests only, skipping Razor [4544] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/10_default_prefs.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/10_default_prefs.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/10_default_prefs.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_advance_fee.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/20_advance_fee.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_advance_fee.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_body_tests.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/20_body_tests.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_body_tests.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_compensate.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/20_compensate.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_compensate.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_dnsbl_tests.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/20_dnsbl_tests.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_dnsbl_tests.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_drugs.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/20_drugs.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_drugs.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_dynrdns.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/20_dynrdns.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_dynrdns.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_fake_helo_tests.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/20_fake_helo_tests.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_fake_helo_tests.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_head_tests.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/20_head_tests.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_head_tests.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_html_tests.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/20_html_tests.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_html_tests.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_imageinfo.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/20_imageinfo.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_imageinfo.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_meta_tests.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/20_meta_tests.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_meta_tests.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_net_tests.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/20_net_tests.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_net_tests.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_phrases.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/20_phrases.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_phrases.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_porn.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/20_porn.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_porn.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_ratware.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/20_ratware.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_ratware.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_uri_tests.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/20_uri_tests.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_uri_tests.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_vbounce.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/20_vbounce.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/20_vbounce.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/23_bayes.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/23_bayes.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/23_bayes.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_accessdb.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/25_accessdb.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_accessdb.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_antivirus.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/25_antivirus.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_antivirus.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_asn.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/25_asn.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_asn.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_dcc.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/25_dcc.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_dcc.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_dkim.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/25_dkim.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_dkim.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_domainkeys.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/25_domainkeys.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_domainkeys.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_hashcash.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/25_hashcash.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_hashcash.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_pyzor.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/25_pyzor.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_pyzor.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_razor2.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/25_razor2.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_razor2.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_replace.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/25_replace.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_replace.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_spf.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/25_spf.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_spf.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_textcat.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/25_textcat.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_textcat.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_uribl.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/25_uribl.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/25_uribl.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/30_text_de.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/30_text_de.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/30_text_de.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/30_text_fr.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/30_text_fr.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/30_text_fr.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/30_text_it.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/30_text_it.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/30_text_it.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/30_text_nl.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/30_text_nl.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/30_text_nl.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/30_text_pl.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/30_text_pl.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/30_text_pl.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/30_text_pt_br.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/30_text_pt_br.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/30_text_pt_br.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/50_scores.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/50_scores.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/50_scores.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/60_awl.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/60_awl.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/60_awl.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/60_shortcircuit.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/60_shortcircuit.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/60_shortcircuit.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/60_whitelist.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/60_whitelist.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/60_whitelist.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/60_whitelist_dk.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/60_whitelist_dk.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/60_whitelist_dk.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/60_whitelist_dkim.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/60_whitelist_dkim.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/60_whitelist_dkim.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/60_whitelist_spf.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/60_whitelist_spf.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/60_whitelist_spf.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/60_whitelist_subject.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/60_whitelist_subject.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/60_whitelist_subject.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/72_active.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/72_active.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/72_active.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/72_scores.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/72_scores.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/72_scores.cf [4544] dbg: config: fixed relative path: /var/lib/spamassassin/3.002002/updates_spamassassin_org/80_additional.cf [4544] dbg: config: using "/var/lib/spamassassin/3.002002/updates_spamassassin_org/80_additional.cf" for included file [4544] dbg: config: read file /var/lib/spamassassin/3.002002/updates_spamassassin_org/80_additional.cf [4544] dbg: plugin: loading crm114 from /etc/mail/spamassassin/crm114.pm [4544] dbg: rules: __XM_OL_22B61 merged duplicates: __XM_OL_A842E [4544] dbg: rules: __XM_OL_07794 merged duplicates: __XM_OL_25340 __XM_OL_3857F __XM_OL_4F240 __XM_OL_58CB5 __XM_OL_6554A __XM_OL_812FF __XM_OL_C65FA __XM_OL_CF0C0 __XM_OL_F475E __XM_OL_F6D01 [4544] dbg: rules: __HTML_IMG_ONLY merged duplicates: __IMG_ONLY [4544] dbg: rules: FU_UKGEOCITIES merged duplicates: __SARE_SPEC_XX2GEOCIT [4544] dbg: rules: FB_FAKE_NUMBERS merged duplicates: SARE_OBFU_NUMBERS [4544] dbg: rules: FH_MSGID_01C67 merged duplicates: __MSGID_VGA [4544] dbg: rules: FS_NEW_SOFT_UPLOAD merged duplicates: HS_SUBJ_NEW_SOFTWARE [4544] dbg: rules: __XM_OL_5E7ED merged duplicates: __XM_OL_D03AB [4544] dbg: rules: SARE_SUB_2UNDERSCORES merged duplicates: SARE_SUB_6_FIG_INC SARE_SUB_ACCT_UPD SARE_SUB_ACQUISITION SARE_SUB_ACTION_OB SARE_SUB_ADV_DB SARE_SUB_ADV_SEARCH SARE_SUB_AGING SARE_SUB_AM_MED_DICT SARE_SUB_BETTER SARE_SUB_BETTER_OB1 SARE_SUB_BETTER_OB2 SARE_SUB_BE_HERE SARE_SUB_BIGGER SARE_SUB_BIGGER_OB SARE_SUB_BOOST_OB SARE_SUB_BREAKTHRU_OB SARE_SUB_BRKING_NEWS SARE_SUB_BULK_EMAIL SARE_SUB_BUY_CHEAP SARE_SUB_BUY_OB SARE_SUB_BUY_OB1 SARE_SUB_CALL_NOW SARE_SUB_CARD_BILLED SARE_SUB_CARTRIDGE_OB SARE_SUB_CASINO_OB SARE_SUB_CHANGE_LIFE SARE_SUB_CHARGE_OB SARE_SUB_CHEAP_OB SARE_SUB_CHRISTIAN SARE_SUB_COMMA_LEAD SARE_SUB_COMM_MAILERS SARE_SUB_CONFID_OB SARE_SUB_CONSULTN_OB SARE_SUB_COPYDVD SARE_SUB_DBL_MEDICTN SARE_SUB_DBL_PHARM SARE_SUB_DEBTS_COURT SARE_SUB_DOWNLOAD_OB SARE_SUB_EBAY_OB SARE_SUB_EXCITING_NEW SARE_SUB_EXCL_OB SARE_SUB_EXPIRED SARE_SUB_FOR_WOMEN SARE_SUB_FREE SARE_SUB_FREE_BANG SARE_SUB_GAPPY_3 SARE_SUB_GAPPY_4 SARE_SUB_GAPPY_5 SARE_SUB_GAPPY_6 SARE_SUB_GAPPY_7 SARE_SUB_GAPPY_8 SARE_SUB_GROW_BUSINESS SARE_SUB_HARD_OB SARE_SUB_HOMEOWNER_OB SARE_SUB_INC_ONLINE SARE_SUB_INKJET SARE_SUB_INKJET_OB SARE_SUB_KICKBACK SARE_SUB_LAST_CHANCE SARE_SUB_LEAD_PUNCT SARE_SUB_LETTERS_NUMS SARE_SUB_LONG_SUBJ_140 SARE_SUB_LONG_SUBJ_170 SARE_SUB_LOOKING_FOR SARE_SUB_LOSE_OB SARE_SUB_LOTS_PUNC_21 SARE_SUB_LOTS_PUNC_26 SARE_SUB_MEDICAL_NEWS SARE_SUB_MED_USE SARE_SUB_MENS_HEALTH SARE_SUB_MISC_1 SARE_SUB_MORTGAGE_OB SARE_SUB_MOVE_OB SARE_SUB_MSGSUB SARE_SUB_NOW_TIME SARE_SUB_ONLINE_OB SARE_SUB_ORIG_SOFT_OB SARE_SUB_PASSION_OB SARE_SUB_PENIS_OB SARE_SUB_PERFECT SARE_SUB_PERFECTLY SARE_SUB_PHOTOS_OB SARE_SUB_PHYSICIAN SARE_SUB_PHYSICIAN_OB SARE_SUB_PLEASE_OB SARE_SUB_PRICES_CAP SARE_SUB_PRINTER_OB SARE_SUB_PROFILE SARE_SUB_PROVEN_OB SARE_SUB_RAND_UC SARE_SUB_REAL_OB SARE_SUB_SAVE_PCT SARE_SUB_SAVE_UP_TO SARE_SUB_SION_OB SARE_SUB_SPECIAL_BANG SARE_SUB_STRETCH_MARK SARE_SUB_STRONG SARE_SUB_STRONG_OB SARE_SUB_TAXES SARE_SUB_THOU_CLI SARE_SUB_TION_OB SARE_SUB_TONER SARE_SUB_TONER_OB SARE_SUB_VIDEO_OB SARE_SUB_VIRUSQ SARE_SUB_WEBMASTER SARE_SUB_WEBMASTER2 SARE_SUB_WIN SARE_SUB_WINNER SARE_SUB_YOUNGER_OB SARE_SUB_YOUR_WOMAN [4544] dbg: rules: __MO_OL_22B61 merged duplicates: __MO_OL_4F240 __MO_OL_ADFF7 [4544] dbg: rules: __MO_OL_812FF merged duplicates: __MO_OL_BC7E6 [4544] dbg: rules: __SARE_HEAD_FALSE merged duplicates: __SARE_SUB_FALSE [4544] dbg: rules: VIRUS_WARNING128 merged duplicates: __VBOUNCE_MMS [4544] dbg: rules: SARE_SUBJ_SLUT merged duplicates: __FPS_SLUT [4544] dbg: rules: __FVGT_RAPE merged duplicates: __WORD_RAPED [4544] dbg: rules: VIRUS_WARNING123 merged duplicates: VIRUS_WARNING37 [4544] dbg: rules: __XM_OL_C7C33 merged duplicates: __XM_OL_C9068 __XM_OL_EF20B [4544] dbg: rules: __FH_RCV_53 merged duplicates: __RCVD_53 [4544] dbg: rules: __MO_OL_72641 merged duplicates: __MO_OL_A842E [4544] dbg: rules: SARE_OBFU_AFFORD merged duplicates: SARE_OBFU_AMP SARE_OBFU_BETTER_SUB SARE_OBFU_CARTRDGE_SUB SARE_OBFU_CIALIS SARE_OBFU_OBLIGATION SARE_OBFU_SEX_SPL SARE_OBFU_TBL_05 SARE_URI_AFF_DIG SARE_URI_CAMPAIGNID SARE_URI_CASINO SARE_URI_DIG_LET_PIC SARE_URI_H0 SARE_URI_HARRYDAV SARE_URI_HOUSE SARE_URI_IPPORT3333 SARE_URI_MIXED_CASE SARE_URI_MRTG SARE_URI_NUMASP8 SARE_URI_NUM_SUBDOM SARE_URI_OC SARE_URI_P8 SARE_URI_PERV SARE_URI_PORTD4 SARE_URI_REFID2 SARE_URI_REFID3 SARE_URI_SHARE_DIG SARE_URI_SIXCAPS SARE_URI_SQUARE SARE_URI_SUCCEZZ [4544] dbg: rules: __MO_OL_5E7ED merged duplicates: __MO_OL_C7C33 [4544] dbg: rules: VIRUS_WARNING103 merged duplicates: VIRUS_WARNING52 [4544] dbg: rules: __MO_OL_4BF4C merged duplicates: __MO_OL_F6D01 [4544] dbg: rules: __MO_OL_07794 merged duplicates: __MO_OL_8627E __MO_OL_F3B05 [4544] dbg: rules: SARE_SPOOF_COM2OTH merged duplicates: SPOOF_COM2COM [4544] dbg: rules: __MO_OL_9B90B merged duplicates: __MO_OL_C65FA [4544] dbg: rules: __FH_FRM_53 merged duplicates: __FROM_53 [4544] dbg: rules: KAM_STOCKOTC merged duplicates: KAM_STOCKTIP15 KAM_STOCKTIP20 KAM_STOCKTIP21 KAM_STOCKTIP4 KAM_STOCKTIP6 [4544] dbg: rules: __XM_OL_015D5 merged duplicates: __XM_OL_4BF4C __XM_OL_4EEDB __XM_OL_5B79A __XM_OL_9B90B __XM_OL_ADFF7 __XM_OL_B30D1 __XM_OL_B4B40 __XM_OL_BC7E6 __XM_OL_F3B05 __XM_OL_FF5C8 [4544] dbg: rules: __MO_OL_91287 merged duplicates: __MO_OL_B30D1 __MO_OL_CF0C0 [4544] dbg: rules: __MO_OL_015D5 merged duplicates: __MO_OL_6554A [4544] dbg: rules: __FH_HAS_XMSMAIL merged duplicates: __HAS_MSMAIL_PRI [4544] dbg: rules: __MO_OL_25340 merged duplicates: __MO_OL_4EEDB __MO_OL_7533E [4544] dbg: rules: __MO_OL_58CB5 merged duplicates: __MO_OL_B4B40 [4544] dbg: rules: __DOS_HAS_ANY_URI merged duplicates: __HAS_ANY_URI __SARE_URI_ANY [4544] dbg: rules: SARE_HTML_ALT_WAIT1 merged duplicates: SARE_HTML_ALT_WAIT2 SARE_HTML_A_NULL SARE_HTML_BADOPEN SARE_HTML_BAD_FG_CLR SARE_HTML_COLOR_NWHT3 SARE_HTML_FONT_INVIS2 SARE_HTML_FSIZE_1ALL SARE_HTML_GIF_DIM SARE_HTML_H2_CLK SARE_HTML_HTML_AFTER SARE_HTML_INV_TAGA SARE_HTML_JSCRIPT_ENC SARE_HTML_JVS_HREF SARE_HTML_MANY_BR10 SARE_HTML_NO_BODY SARE_HTML_NO_HTML1 SARE_HTML_P_JUSTIFY SARE_HTML_URI_2SLASH SARE_HTML_URI_AXEL SARE_HTML_URI_BADQRY SARE_HTML_URI_BUG SARE_HTML_URI_FORMPHP SARE_HTML_URI_HREF SARE_HTML_URI_MANYP2 SARE_HTML_URI_MANYP3 SARE_HTML_URI_NUMPHP3 SARE_HTML_URI_OBFU4 SARE_HTML_URI_OBFU4a SARE_HTML_URI_OPTPHP SARE_HTML_URI_REFID SARE_HTML_URI_RID SARE_HTML_URI_RM SARE_HTML_USL_MULT [4544] dbg: rules: VIRUS_WARNING107 merged duplicates: __VBOUNCE_AV_RESULTS [4544] dbg: rules: __MO_OL_F475E merged duplicates: __MO_OL_FF5C8 [4544] dbg: conf: finish parsing [4544] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0xa30f72c) implements 'finish_parsing_end', priority 0 [4544] dbg: replacetags: replacing tags [4544] dbg: replacetags: done replacing tags [4544] dbg: bayes: tie-ing to DB file R/O /root/.spamassassin/bayes_toks [4544] dbg: bayes: tie-ing to DB file R/O /root/.spamassassin/bayes_seen [4544] dbg: bayes: found bayes db version 3 [4544] dbg: bayes: DB journal sync: last sync: 0 [4544] dbg: bayes: not available for scanning, only 0 spam(s) in bayes DB < 200 [4544] dbg: bayes: untie-ing [4544] dbg: config: score set 0 chosen. [4544] dbg: message: main message type: text/plain [4544] dbg: message: ---- MIME PARSER START ---- [4544] dbg: message: parsing normal part [4544] dbg: message: ---- MIME PARSER END ---- [4544] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0xa453060) implements 'check_start', priority 0 [4544] dbg: bayes: tie-ing to DB file R/O /root/.spamassassin/bayes_toks [4544] dbg: bayes: tie-ing to DB file R/O /root/.spamassassin/bayes_seen [4544] dbg: bayes: found bayes db version 3 [4544] dbg: bayes: DB journal sync: last sync: 0 [4544] dbg: bayes: not available for scanning, only 0 spam(s) in bayes DB < 200 [4544] dbg: bayes: untie-ing [4544] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0xa4271cc) implements 'check_main', priority 0 [4544] dbg: conf: trusted_networks are not configured; it is recommended that you configure trusted_networks manually [4544] dbg: metadata: X-Spam-Relays-Trusted: [4544] dbg: metadata: X-Spam-Relays-Untrusted: [4544] dbg: metadata: X-Spam-Relays-Internal: [4544] dbg: metadata: X-Spam-Relays-External: [4544] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xa8c7044) implements 'extract_metadata', priority 0 [4544] dbg: metadata: X-Relay-Countries: [4544] dbg: message: no encoding detected [4544] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xa8c7044) implements 'parsed_metadata', priority 0 [4544] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0xa93c2e0) implements 'parsed_metadata', priority 0 [4544] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0xa967ce8) implements 'parsed_metadata', priority 0 [4544] dbg: dns: is_dns_available() last checked 1186453055 seconds ago; re-checking [4544] dbg: dns: is DNS available? 0 [4544] dbg: asn: DNS is not available, skipping ASN checks [4544] dbg: rules: local tests only, ignoring RBL eval [4544] dbg: check: running tests for priority: -1000 [4544] dbg: rules: running head tests; score so far=0 [4544] dbg: rules: compiled head tests [4544] dbg: eval: all '*From' addrs: ignore@compiling.spamassassin.taint.org [4544] dbg: eval: all '*To' addrs: [4544] dbg: rules: running body tests; score so far=0 [4544] dbg: rules: compiled body tests [4544] dbg: rules: running uri tests; score so far=0 [4544] dbg: rules: compiled uri tests [4544] dbg: rules: running rawbody tests; score so far=0 [4544] dbg: rules: compiled rawbody tests [4544] dbg: rules: running full tests; score so far=0 [4544] dbg: rules: compiled full tests [4544] dbg: rules: running meta tests; score so far=0 [4544] dbg: rules: compiled meta tests [4544] dbg: check: running tests for priority: -950 [4544] dbg: rules: running head tests; score so far=0 [4544] dbg: rules: compiled head tests [4544] dbg: rules: running body tests; score so far=0 [4544] dbg: rules: compiled body tests [4544] dbg: rules: running uri tests; score so far=0 [4544] dbg: rules: compiled uri tests [4544] dbg: rules: running rawbody tests; score so far=0 [4544] dbg: rules: compiled rawbody tests [4544] dbg: rules: running full tests; score so far=0 [4544] dbg: rules: compiled full tests [4544] dbg: rules: running meta tests; score so far=0 [4544] dbg: rules: compiled meta tests [4544] dbg: check: running tests for priority: -900 [4544] dbg: rules: running head tests; score so far=0 [4544] dbg: rules: compiled head tests [4544] dbg: rules: running body tests; score so far=0 [4544] dbg: rules: compiled body tests [4544] dbg: rules: running uri tests; score so far=0 [4544] dbg: rules: compiled uri tests [4544] dbg: rules: running rawbody tests; score so far=0 [4544] dbg: rules: compiled rawbody tests [4544] dbg: rules: running full tests; score so far=0 [4544] dbg: rules: compiled full tests [4544] dbg: rules: running meta tests; score so far=0 [4544] dbg: rules: compiled meta tests [4544] dbg: check: running tests for priority: -400 [4544] dbg: rules: running head tests; score so far=0 [4544] dbg: rules: compiled head tests [4544] dbg: rules: running body tests; score so far=0 [4544] dbg: rules: compiled body tests [4544] dbg: rules: running uri tests; score so far=0 [4544] dbg: rules: compiled uri tests [4544] dbg: rules: running rawbody tests; score so far=0 [4544] dbg: rules: compiled rawbody tests [4544] dbg: rules: running full tests; score so far=0 [4544] dbg: rules: compiled full tests [4544] dbg: rules: running meta tests; score so far=0 [4544] dbg: rules: compiled meta tests [4544] dbg: check: running tests for priority: 0 [4544] dbg: rules: running head tests; score so far=0 [4544] dbg: rules: compiled head tests [4544] dbg: rules: ran header rule __MISSING_REF ======> got hit: "UNSET" [4544] dbg: rules: ran header rule __MSOE_MID_WRONG_CASE ======> got hit: " [4544] dbg: rules: Message-Id: " [4544] dbg: rules: ran header rule MISSING_DATE ======> got hit: "UNSET" [4544] dbg: rules: ran header rule __SARE_WHITELIST_FLAG ======> got hit: "i" [4544] dbg: rules: ran header rule __MSGID_OK_HOST ======> got hit: "@lint_rules>" [4544] dbg: rules: ran header rule __MSGID_OK_DIGITS ======> got hit: "1186453051" [4544] dbg: rules: ran header rule __HAS_MSGID ======> got hit: "<" [4544] dbg: rules: ran header rule __SANE_MSGID ======> got hit: "<1186453051@lint_rules> [4544] dbg: rules: " [4544] dbg: spf: checking to see if the message has a Received-SPF header that we can use [4544] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [4544] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [4544] dbg: rules: ran eval rule NO_RELAYS ======> got hit (1) [4544] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [4544] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [4544] dbg: spf: cannot get Envelope-From, cannot use SPF [4544] dbg: spf: def_spf_whitelist_from: could not find useable envelope sender [4544] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [4544] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [4544] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [4544] dbg: rules: ran eval rule __UNUSABLE_MSGID ======> got hit (1) [4544] dbg: rules: ran eval rule MISSING_HEADERS ======> got hit (1) [4544] dbg: spf: spf_whitelist_from: could not find useable envelope sender [4544] dbg: rules: running body tests; score so far=1.899 [4544] dbg: rules: compiled body tests [4544] dbg: rules: ran body rule __NONEMPTY_BODY ======> got hit: "I" [4544] dbg: rules: running uri tests; score so far=1.899 [4544] dbg: rules: compiled uri tests [4544] dbg: https_http_mismatch: anchors 0 [4544] dbg: eval: stock info total: 0 [4544] dbg: rules: running rawbody tests; score so far=1.899 [4544] dbg: rules: compiled rawbody tests [4544] dbg: rules: ran rawbody rule __TVD_BODY ======> got hit: "need" [4544] dbg: rules: running full tests; score so far=1.899 [4544] dbg: rules: compiled full tests [4544] dbg: rules: running meta tests; score so far=1.899 [4544] dbg: rules: compiled meta tests [4544] dbg: check: running tests for priority: 500 [4544] dbg: rules: running head tests; score so far=1.899 [4544] dbg: rules: compiled head tests [4544] dbg: rules: running body tests; score so far=1.899 [4544] dbg: rules: compiled body tests [4544] dbg: rules: running uri tests; score so far=1.899 [4544] dbg: rules: compiled uri tests [4544] dbg: rules: running rawbody tests; score so far=1.899 [4544] dbg: rules: compiled rawbody tests [4544] dbg: rules: running full tests; score so far=1.899 [4544] dbg: rules: compiled full tests [4544] dbg: rules: running meta tests; score so far=1.899 [4544] info: rules: meta test FM_DDDD_TIMES_2 has dependency 'FH_HOST_EQ_D_D_D_D' with a zero score [4544] info: rules: meta test FM_SEX_HOSTDDDD has dependency 'FH_HOST_EQ_D_D_D_D' with a zero score [4544] dbg: rules: meta test SARE_RD_SAFE has undefined dependency 'SARE_RD_SAFE_MKSHRT' [4544] dbg: rules: meta test SARE_RD_SAFE has undefined dependency 'SARE_RD_SAFE_GT' [4544] dbg: rules: meta test SARE_RD_SAFE has undefined dependency 'SARE_RD_SAFE_TINY' [4544] info: rules: meta test HS_PHARMA_1 has dependency 'HS_SUBJ_ONLINE_PHARMACEUTICAL' with a zero score [4544] dbg: rules: meta test VIRUS_WARNING_DOOM_BNC has undefined dependency 'VIRUS_WARNING_MYDOOM4' [4544] dbg: rules: compiled meta tests [4544] dbg: check: running tests for priority: 899 [4544] dbg: rules: running head tests; score so far=4.205 [4544] dbg: rules: compiled head tests [4544] dbg: rules: running body tests; score so far=4.205 [4544] dbg: rules: compiled body tests [4544] dbg: rules: running uri tests; score so far=4.205 [4544] dbg: rules: compiled uri tests [4544] dbg: rules: running rawbody tests; score so far=4.205 [4544] dbg: rules: compiled rawbody tests [4544] dbg: rules: running full tests; score so far=4.205 [4544] dbg: rules: compiled full tests [4544] dbg: crm114: call_crm() called, action: check [4544] dbg: info: entering helper-app run mode [4544] dbg: crm114: crm114_command run [4544] dbg: crm114: found version 20070301-BlameBaltar ( 0.6.8 ) MR-BD9991E2 [4544] dbg: crm114: found CacheID sfid-20070806_191738_212125_E4C93C94 [4544] dbg: crm114: found status UNSURE and score 0.29 [4544] dbg: crm114: found Notice Please train this message. [4544] dbg: info: leaving helper-app run mode [4544] dbg: crm114: call_crm returns (UNSURE, 0.29) [4544] dbg: crm114: score is 0.2900, translated to SA score: -0.0580, linear factor was -0.2000 [4544] dbg: rules: running meta tests; score so far=4.147 [4544] dbg: rules: compiled meta tests [4544] dbg: check: running tests for priority: 1000 [4544] dbg: rules: running head tests; score so far=4.147 [4544] dbg: rules: compiled head tests [4544] dbg: rules: running body tests; score so far=4.147 [4544] dbg: rules: compiled body tests [4544] dbg: rules: running uri tests; score so far=4.147 [4544] dbg: rules: compiled uri tests [4544] dbg: rules: running rawbody tests; score so far=4.147 [4544] dbg: rules: compiled rawbody tests [4544] dbg: rules: running full tests; score so far=4.147 [4544] dbg: rules: compiled full tests [4544] dbg: rules: running meta tests; score so far=4.147 [4544] dbg: rules: compiled meta tests [4544] dbg: check: is spam? score=4.147 required=5 [4544] dbg: check: tests=CRM114_CHECK,MISSING_DATE,MISSING_HEADERS,MISSING_SUBJECT,NO_RECEIVED,NO_RELAYS [4544] dbg: check: subtests=__HAS_MSGID,__MISSING_REF,__MSGID_OK_DIGITS,__MSGID_OK_HOST,__MSOE_MID_WRONG_CASE,__NONEMPTY_BODY,__SANE_MSGID,__SARE_WHITELIST_FLAG,__TVD_BODY,__UNUSABLE_MSGID -- *Johnny Stork* Business & Technology Consultant stork@openenterprise.ca From r.berber at computer.org Tue Aug 7 03:43:02 2007 From: r.berber at computer.org (=?ISO-8859-1?Q?Ren=E9_Berber?=) Date: Tue Aug 7 03:45:19 2007 Subject: Performance of 'ClamAV Full Message Scan' Message-ID: From the changelog: "When clamav, clamavmodule or clamd parsers are being used and new setting "ClamAV Full Message Scan" is set to "yes", pass each of the entire messages to ClamAV as well as the attachments so that the signatures that detect spam can work reliably. This is set to "no" be default as it has a speed impact." Why pass the message AND attachments? ClamAV can detect the virus in the message in any possible form, MailScanner is just making clam do double work, plus the work done by MS to extract the attachments. Looking at the logs: Aug 6 20:45:52 sunfire MailScanner[7019]: INFECTED:: Email.Stk.Gen592.Sanesecurity.07071801.pdf FOUND :: ./l771jcte008468/file.pdf Aug 6 20:45:52 sunfire MailScanner[7019]: INFECTED:: Email.Stk.Gen592.Sanesecurity.07071801.pdf FOUND :: ./l771jcte008468/ Aug 6 20:45:53 sunfire MailScanner[7019]: Virus Scanning: Clamd found 2 infections I'm not sure if this was a 2 line report from clamd about the directory, or it really was "2 infections", the message and the attachment... which really show that clamd worked twice on the same infection. For instance, with the quarantine directory I can do: # clamdscan /var/spool/MailScanner/quarantine/20070806/l771jcte008468 /var/spool/MailScanner/quarantine/20070806/l771jcte008468/message: Email.Stk.Gen592.Sanesecurity.07071801.pdf FOUND /var/spool/MailScanner/quarantine/20070806/l771jcte008468/file.pdf: Email.Stk.Gen592.Sanesecurity.07071801.pdf FOUND ----------- SCAN SUMMARY ----------- Infected files: 2 Time: 0.139 sec (0 m 0 s) # clamdscan /var/spool/MailScanner/quarantine/20070806/l771jcte008468/message /var/spool/MailScanner/quarantine/20070806/l771jcte008468/message: Email.Stk.Gen592.Sanesecurity.07071801.pdf FOUND ----------- SCAN SUMMARY ----------- Infected files: 1 Time: 0.118 sec (0 m 0 s) OK, the time difference is not double, is just 18% more work, but still significant. -- Ren? Berber From r.berber at computer.org Tue Aug 7 04:02:41 2007 From: r.berber at computer.org (=?ISO-8859-1?Q?Ren=E9_Berber?=) Date: Tue Aug 7 04:05:11 2007 Subject: Help with sa-update, SARE and RDJ ---Please In-Reply-To: <46B7D827.2010004@openenterprise.ca> References: <46B7D827.2010004@openenterprise.ca> Message-ID: Johnny Stork wrote: > 1: /etc/cron.daily has "sa-update", "rules_du_jour" and > "update_spamassassin". Are all these necessary? No. The 1st and the 3rd do the same thing, the 1st could do the work of the 2nd. > 2: Can the sa-update rules and RDJ rules download all be combined into a > single script/tool? Yes, sa-update can replace RDJ. > 3: Does it look like all my rules are currently being used and update? If you use sa-update and RDJ all the rules will be used. If sa-update is configured to get SARE rules, and you also use RDJ, both sets of rules will be used, the redundancy (of 2 copies of the same rule) will be handled by SA, the last one read wins... but you waste time reading it twice. I say redundancy because the RDJ script stores the files in one place, sa-update in a different place. > 4: Does anyone have a suggested rules set, or channels file that can be > used to manage and update all SA rules in a clear and simple location/file? The recommended guide is: http://daryl.dostech.ca/sa-update/sare/sare-sa-update-howto.txt > 5: Any other suggestions for a simple to manage, and clean setup of SA > and SARE rules and automatic update? sa-update has (currently) an advantage, it uses distributed/mirrored sites, RDJ doesn't, the first one lets you check often (which is unnecessary), no blacklisting. Both methods work fine. I use the RDJ script from Fortress and never did have a problem with RDJ. -- Ren? Berber From stork at openenterprise.ca Tue Aug 7 04:36:58 2007 From: stork at openenterprise.ca (Johnny Stork) Date: Tue Aug 7 04:37:03 2007 Subject: Help with sa-update, SARE and RDJ ---Please In-Reply-To: References: <46B7D827.2010004@openenterprise.ca> Message-ID: <46B7E8DA.8000702@openenterprise.ca> Hey thanks for replying with your suggestions. I think I am getting closer. 1: I removed the "update_spamassassin" script from /etc/cron.daily 2: I did another test of /etc/cron.daily/rules_du_jour and noticed that the *.cf files went into two locations /etc/mail/spamassassin & /etc/mail/spamassassin/RulesDuJour Is this what is supposed to happen? Same files in 2 locations. 3: What should I have in sare-sa-update-channels.txt to get ALL SARE rules and the standard SA rules? I would rather not have to manage this file with removing outdated rules, or adding new rules, just want them all or some sort of suggested set, and all the standard SA rules. I could then not even have to run rules_du_jour any longer. Contents of /etc/rulesdujour: ############################################################################### # Fort Systems # Local RulesDuJour settings # Fri Nov 11 11:18:06 EST 2005 ############################################################################### #DEBUG="true" TRUSTED_RULESETS="SARE_REDIRECT_POST300 SARE_EVILNUMBERS2 SARE_BAYES_POISON_NXM SARE_HTML0 SARE_HTML1 SARE_HTML2 SARE_HTML3 SARE_HTML0 SARE_HTML1 SARE_HTML2 SARE_HTML3 SARE_SPECIFIC SARE_ADULT SARE_BML SARE_FRAUD SARE_SPOOF SARE_RANDOM SARE_SPAMCOP_TOP200 SARE_OEM SARE_GENLSUBJ0 SARE_GENLSUBJ1 SARE_GENLSUBJ2 SARE_GENLSUBJ3 SARE_UNSUB SARE_URI0 SARE_URI1 SARE_URI3 SARE_WHITELIST_SPF SARE_WHITELIST_RCVD SARE_OBFU SARE_STOCKS" SA_DIR="/etc/mail/spamassassin" MAIL_ADDRESS="root" SINGLE_EMAIL_ONLY="true" SA_LINT="/usr/bin/spamassassin -p /etc/MailScanner/spam.assassin.prefs.conf --lint" SA_RESTART="/etc/init.d/MailScanner reload" Ren? Berber wrote: > Johnny Stork wrote: > > >> 1: /etc/cron.daily has "sa-update", "rules_du_jour" and >> "update_spamassassin". Are all these necessary? >> > > No. The 1st and the 3rd do the same thing, the 1st could do the work of the 2nd. > > >> 2: Can the sa-update rules and RDJ rules download all be combined into a >> single script/tool? >> > > Yes, sa-update can replace RDJ. > > >> 3: Does it look like all my rules are currently being used and update? >> > > If you use sa-update and RDJ all the rules will be used. > > If sa-update is configured to get SARE rules, and you also use RDJ, both sets of > rules will be used, the redundancy (of 2 copies of the same rule) will be > handled by SA, the last one read wins... but you waste time reading it twice. > > I say redundancy because the RDJ script stores the files in one place, sa-update > in a different place. > > >> 4: Does anyone have a suggested rules set, or channels file that can be >> used to manage and update all SA rules in a clear and simple location/file? >> > > The recommended guide is: > > http://daryl.dostech.ca/sa-update/sare/sare-sa-update-howto.txt > > >> 5: Any other suggestions for a simple to manage, and clean setup of SA >> and SARE rules and automatic update? >> > > sa-update has (currently) an advantage, it uses distributed/mirrored sites, RDJ > doesn't, the first one lets you check often (which is unnecessary), no > blacklisting. Both methods work fine. > > I use the RDJ script from Fortress and never did have a problem with RDJ. > From stork at openenterprise.ca Tue Aug 7 04:53:50 2007 From: stork at openenterprise.ca (Johnny Stork) Date: Tue Aug 7 04:53:55 2007 Subject: Help with sa-update, SARE and RDJ ---Please In-Reply-To: <46B7E8DA.8000702@openenterprise.ca> References: <46B7D827.2010004@openenterprise.ca> <46B7E8DA.8000702@openenterprise.ca> Message-ID: <46B7ECCE.4020606@openenterprise.ca> Ok, I created the following channel file below from suggestions I found at http://www.indomino.net/blog/. I also imported the GPG file suggested from http://daryl.dostech.ca/sa-update/sare/sare-sa-update-howto.txt. But when I ran this command below.... /usr/bin/sa-update ?channelfile /etc/mail/spamassassin/sare-sa-update-channels.txt ?gpgkey 856AA88A ...it returned to the prompt almost immediatley and no files were downloaded (I removed them from /etc/mail/spamassassin & /etc/mail/spamassassin/RulesDuJour) Any suggestions? Contents of channel file: cat /etc/mail/spamassassin/sare-sa-update-channels.txt updates.spamassassin.org 70_sare_adult.cf.sare.sa-update.dostech.net 70_sare_stocks.cf.sare.sa-update.dostech.net 70_sare_bayes_poison_nxm.cf.sare.sa-update.dostech.net 70_sare_unsub.cf.sare.sa-update.dostech.net 70_sare_evilnum0.cf.sare.sa-update.dostech.net 70_sare_uri0.cf.sare.sa-update.dostech.net 70_sare_evilnum1.cf.sare.sa-update.dostech.net 70_sare_uri1.cf.sare.sa-update.dostech.net 70_sare_evilnum2.cf.sare.sa-update.dostech.net 70_sare_uri3.cf.sare.sa-update.dostech.net 70_sare_genlsubj0.cf.sare.sa-update.dostech.net 70_sare_whitelist_rcvd.cf.sare.sa-update.dostech.net 70_sare_genlsubj1.cf.sare.sa-update.dostech.net 70_sare_whitelist_spf.cf.sare.sa-update.dostech.net 70_sare_genlsubj2.cf.sare.sa-update.dostech.net 70_sare_genlsubj3.cf.sare.sa-update.dostech.net 72_sare_bml_post25x.cf.sare.sa-update.dostech.net 70_sare_header0.cf.sare.sa-update.dostech.net 99_sare_fraud_post25x.cf.sare.sa-update.dostech.net 70_sare_header1.cf.sare.sa-update.dostech.net 70_sare_header2.cf.sare.sa-update.dostech.net 70_sare_header3.cf.sare.sa-update.dostech.net 70_sare_html0.cf.sare.sa-update.dostech.net 70_sare_html1.cf.sare.sa-update.dostech.net 70_sare_html2.cf.sare.sa-update.dostech.net 70_sare_html3.cf.sare.sa-update.dostech.net 70_sare_obfu.cf.sare.sa-update.dostech.net 70_sare_oem.cf.sare.sa-update.dostech.net 70_sare_random.cf.sare.sa-update.dostech.net 70_sare_specific.cf.sare.sa-update.dostech.net 70_sare_spoof.cf.sare.sa-update.dostech.net Johnny Stork wrote: > Hey thanks for replying with your suggestions. I think I am getting > closer. > > 1: I removed the "update_spamassassin" script from /etc/cron.daily > > 2: I did another test of /etc/cron.daily/rules_du_jour and noticed > that the *.cf files went into two locations > > /etc/mail/spamassassin > & > /etc/mail/spamassassin/RulesDuJour > > > Is this what is supposed to happen? Same files in 2 locations. > > 3: What should I have in sare-sa-update-channels.txt to get ALL SARE > rules and the standard SA rules? I would rather not have to manage > this file with removing outdated rules, or adding new rules, just want > them all or some sort of suggested set, and all the standard SA rules. > I could then not even have to run rules_du_jour any longer. > > > Contents of /etc/rulesdujour: > > ############################################################################### > > # Fort Systems > # Local RulesDuJour settings > # Fri Nov 11 11:18:06 EST 2005 > ############################################################################### > > > #DEBUG="true" > > TRUSTED_RULESETS="SARE_REDIRECT_POST300 SARE_EVILNUMBERS2 > SARE_BAYES_POISON_NXM SARE_HTML0 SARE_HTML1 SARE_HTML2 SARE_HTML3 > SARE_HTML0 SARE_HTML1 SARE_HTML2 SARE_HTML3 SARE_SPECIFIC SARE_ADULT > SARE_BML SARE_FRAUD SARE_SPOOF SARE_RANDOM SARE_SPAMCOP_TOP200 > SARE_OEM SARE_GENLSUBJ0 SARE_GENLSUBJ1 SARE_GENLSUBJ2 SARE_GENLSUBJ3 > SARE_UNSUB SARE_URI0 SARE_URI1 SARE_URI3 SARE_WHITELIST_SPF > SARE_WHITELIST_RCVD SARE_OBFU SARE_STOCKS" > > SA_DIR="/etc/mail/spamassassin" > MAIL_ADDRESS="root" > SINGLE_EMAIL_ONLY="true" > SA_LINT="/usr/bin/spamassassin -p > /etc/MailScanner/spam.assassin.prefs.conf --lint" > SA_RESTART="/etc/init.d/MailScanner reload" > > > > > Ren? Berber wrote: >> Johnny Stork wrote: >> >>> 1: /etc/cron.daily has "sa-update", "rules_du_jour" and >>> "update_spamassassin". Are all these necessary? >> >> No. The 1st and the 3rd do the same thing, the 1st could do the work >> of the 2nd. >> >>> 2: Can the sa-update rules and RDJ rules download all be combined >>> into a >>> single script/tool? >> >> Yes, sa-update can replace RDJ. >> >>> 3: Does it look like all my rules are currently being used and update? >> >> If you use sa-update and RDJ all the rules will be used. >> >> If sa-update is configured to get SARE rules, and you also use RDJ, >> both sets of >> rules will be used, the redundancy (of 2 copies of the same rule) >> will be >> handled by SA, the last one read wins... but you waste time reading >> it twice. >> >> I say redundancy because the RDJ script stores the files in one >> place, sa-update >> in a different place. >> >>> 4: Does anyone have a suggested rules set, or channels file that can be >>> used to manage and update all SA rules in a clear and simple >>> location/file? >> >> The recommended guide is: >> >> http://daryl.dostech.ca/sa-update/sare/sare-sa-update-howto.txt >> >>> 5: Any other suggestions for a simple to manage, and clean setup of SA >>> and SARE rules and automatic update? >> >> sa-update has (currently) an advantage, it uses distributed/mirrored >> sites, RDJ >> doesn't, the first one lets you check often (which is unnecessary), no >> blacklisting. Both methods work fine. >> >> I use the RDJ script from Fortress and never did have a problem with >> RDJ. From r.berber at computer.org Tue Aug 7 05:12:56 2007 From: r.berber at computer.org (=?UTF-8?B?UmVuw6kgQmVyYmVy?=) Date: Tue Aug 7 05:13:11 2007 Subject: Help with sa-update, SARE and RDJ ---Please In-Reply-To: <46B7E8DA.8000702@openenterprise.ca> References: <46B7D827.2010004@openenterprise.ca> <46B7E8DA.8000702@openenterprise.ca> Message-ID: Johnny Stork wrote: > Hey thanks for replying with your suggestions. I think I am getting closer. > > 1: I removed the "update_spamassassin" script from /etc/cron.daily > > 2: I did another test of /etc/cron.daily/rules_du_jour and noticed that the > *.cf files went into two locations > > /etc/mail/spamassassin & /etc/mail/spamassassin/RulesDuJour > > > Is this what is supposed to happen? Same files in 2 locations. Yes, the script first downloads on one place, sees if there are no problems (running spamassassin --lint), then copies them in place. > 3: What should I have in sare-sa-update-channels.txt to get ALL SARE rules > and the standard SA rules? I would rather not have to manage this file with > removing outdated rules, or adding new rules, just want them all or some sort > of suggested set, and all the standard SA rules. I could then not even have > to run rules_du_jour any longer. Sorry, I don't use that method, as I said before, I use RDJ. You don't want all the rules, that would make SA very slow, some suggestions are on the SA list but it really depends on the languages expected, what seems effective, and so on. I just started with the minimum recommended (I think it was recommended inside the rules_du_jour script, but lately it doesn't have a good recommendation). > But when I ran this command below.... > > /usr/bin/sa-update ?channelfile > /etc/mail/spamassassin/sare-sa-update-channels.txt ?gpgkey 856AA88A It's --channelfile . -- Ren? Berber From mailscanner at home.carlo65.de Tue Aug 7 07:58:52 2007 From: mailscanner at home.carlo65.de (R. Ehle (MailScanner Mailinglist)) Date: Tue Aug 7 07:59:29 2007 Subject: AW: AW: DSN and 4.62.9 problem In-Reply-To: References: <46B79B17.90005@coders.co.uk> <4D1CD0994309F84BA83DF998BF0075AF4328E173@ts-dc2.TS-Webarts.local> Message-ID: <4D1CD0994309F84BA83DF998BF0075AF4328E174@ts-dc2.TS-Webarts.local> I partly agree with you. We have to distinguish "Read Notifications" from "Delivery Notifications". Delivery Notifications are sent by the MTA. If the delivery notification is sent by a MTA like sendmail, postfix or qmail, the Watermarking function works fine. If the Delivery Notification is sent by a Microsoft Exchange Server, especially, if it is the new one (Exchange 2007), then the header of the original message is not included and so Watermarking function fails to recognize the message. Regards, Roland -----Urspr?ngliche Nachricht----- Von: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Im Auftrag von Ren? Berber Gesendet: Dienstag, 7. August 2007 02:42 An: mailscanner@lists.mailscanner.info Betreff: Re: AW: DSN and 4.62.9 problem R. Ehle wrote: > I experienced problems with the watermarking function too. > > As far as I found out, the errors only appear, when the DSN is sent from a > Microsoft Exchange Server. Actually the Exchange Server sends a complete new > message, which does not contain the header from the original message. So I > don't think, that there will be a possibility to solve this issue. No, I don't agree, I'm seeing the problem with only sendmail involved as server, Outlook as client. It's our own read receipts that are being marked as spam, as well as our (business) clients, some of which do have Exchange. FWIW I've never seen the need for milter-null or similar, greylisting + Botnet takes care of that problem. -- Ren? Berber -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ---------------------------------------------------------- Diese Nachricht wurde von mailMind(R) auf Viren und andere gefaehrliche Inhalte untersucht und ist sauber. --- mailMind(R) - we have your Mailsecurity in mind! http://www.mailmind.de --- From Q.G.Campbell at newcastle.ac.uk Tue Aug 7 08:05:59 2007 From: Q.G.Campbell at newcastle.ac.uk (Quentin Campbell) Date: Tue Aug 7 08:06:03 2007 Subject: PATCH SweepViruses.pm - clamavmodule false positives - A PLEA! In-Reply-To: <46B72D2E.2000208@ecs.soton.ac.uk> References: <1186407034.31893.47.camel@gblades-suse.linguaphone-intranet.co.uk> <46B72D2E.2000208@ecs.soton.ac.uk> Message-ID: <4165CF7A7F12DE4B96622CCBB90586470B125CA8@largo.campus.ncl.ac.uk> Julian If you do release a new version of 4.62.9 to fix this I would be grateful if you could also make available a copy of the updated SweepViruses.pm file. I have just finished upgrading 12 mail gateways to 4.62.9-2 and SA 3.2.2 and cannot afford to go through the whole process of installing MS again so soon. If it is just a single *.pm that needs replacing then that is easy enough. How serious is this 'false positive' problem? Is it correct that I can avoid the bug by setting "ClamAV Full Message Scan = no" and do I lose much by doing that? Thanks Quentin >-----Original Message----- >From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >bounces@lists.mailscanner.info] On Behalf Of Julian Field >Sent: 06 August 2007 15:16 >To: MailScanner discussion >Subject: Re: PATCH SweepViruses.pm - clamavmodule false positives > >-----BEGIN PGP SIGNED MESSAGE----- >Hash: SHA1 > >You only actually want to apply the first of the 2 patches, as you only >want to affect the code that scans the *.message and *.header files. > >It will be in the next release. > >Please can some other people test this and confirm it works reliably? > >Gareth wrote: >> Attached is a patch for SweepViruses.pm which fixes the false >positives >> issue with Phishing.Heuristics.Email.SpoofedDomain when using >> Clamavmodule and the full message scan option. >> >> It passes the CL_SCAN_PHISHING_DOMAINLIST option which according to >the >> clamavmodule source :- >> =item CL_SCAN_PHISHING_DOMAINLIST >> Phishing module: restrict URL scanning to domains from .pdf >> (RECOMMENDED). >> >> I believe that as this option was not previously set it is equivalent >to >> the following clamscan option :- >> --no-phishing-restrictedscan >> Enable url-based heuristic phishing detection for all domains >> (might lead to false positives!). >> >> Personally I think CL_SCAN_PHISHING_DOMAINLIST should do the same as >> --no-phishing-restrictedscan and not be the inverse of it. Maybe a >bug. >> I will contact the author about it anyway. >> >> I dont really know what this option does exactly but it is a >recommended >> setting, its name seems to indicate it is related to the false >positives >> I was getting, and setting it does seem to have cured the problem. >> > >Jules > >- -- >Julian Field MEng CITP >www.MailScanner.info >Buy the MailScanner book at www.MailScanner.info/store > >Need help customising MailScanner? >Contact me! >Need help fixing or optimising your systems? >Contact me! >Need help getting you started solving new requirements from your boss? >Contact me! > >PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > >-----BEGIN PGP SIGNATURE----- >Version: PGP Desktop 9.6.2 (Build 2014) >Comment: (pgp-secured) >Charset: ISO-8859-1 > >wj8DBQFGty0vEfZZRxQVtlQRAgNvAKClvd3nYnkZaaePge//JWDYGr8gVACgv7+H >ApgOZBY/pz0cF9ZPiEkxnxs= >=Jnzy >-----END PGP SIGNATURE----- > >-- >This message has been scanned for viruses and >dangerous content by MailScanner, and is >believed to be clean. >For all your IT requirements visit www.transtec.co.uk > >-- >MailScanner mailing list >mailscanner@lists.mailscanner.info >http://lists.mailscanner.info/mailman/listinfo/mailscanner > >Before posting, read http://wiki.mailscanner.info/posting > >Support MailScanner development - buy the book off the website! From fajarep at simplimobile.com Tue Aug 7 08:07:15 2007 From: fajarep at simplimobile.com (Fajar) Date: Tue Aug 7 08:07:32 2007 Subject: ClamAV and MailScanner SPAM or Virus Message-ID: <0dfc01c7d8c1$95db3f50$060a0aac@Fajar> Hello, I'm testing our email server that powered by mailscanner(4.61), spamassassin bayes stored in database, clamav 0.91, and 3rd party clamav database(sanesecurity and mslbr). By using several testing website, I get eicar test virus identified as spam in mailwatch report? Is that something wrong, or usuall? Fajar -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070807/fbe8c801/attachment.html From martinh at solidstatelogic.com Tue Aug 7 08:24:38 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Tue Aug 7 08:24:53 2007 Subject: converting attachments In-Reply-To: <88bd43930708061413n4d8bb9b9k8f5c6ebcf9354fca@mail.gmail.com> Message-ID: <951d652c81cee64aaeff236d2534935e@solidstatelogic.com> Iad Policy here - default filetype is .doc anyother cannot be supported. It's similar to what we've had to do here when we moved from Appleworks/Claris works as tnhe default office platform. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Iad Scoot > Sent: 06 August 2007 22:13 > To: MailScanner discussion > Subject: Re: converting attachments > > This particular issue is one of attachments - someone writes a document > and saves it as a .rtf doc (Wordpad, etc) and then sends it attached to an > inbound email. My BB users get the message but can't open the attachment. > Its not the same issue (AFAIK) as the winmail.dat issue - I already have > the TNEF expander configured for that issue. > > > Thanks again... > > > On 8/6/07, Kai Schaetzl wrote: > > Martin.Hepworth wrote on Mon, 06 Aug 2007 17:47:16 +0100: > > > you're taking about rft documents not winmail.dat things.. > > Maybe he *is* ... Iad, you are aware that Exchange can send the mail > as an > rtf attachment as well? That then just contains the same text as the > plain > text email. > > Kai > > -- > Kai Sch?tzl, Berlin, Germany > Get your web at Conactive Internet Services: > http://www.conactive.com > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From uxbod at splatnix.net Tue Aug 7 08:45:14 2007 From: uxbod at splatnix.net (UxBoD) Date: Tue Aug 7 08:37:05 2007 Subject: converting attachments In-Reply-To: <88bd43930708061415r3df376ffxaef5eecce5254f18@mail.gmail.com> Message-ID: <14998225.11841186472714827.JavaMail.root@office.splatnix.net> Iad, The Custom function allows you to write you own actions based on where spam, high-spam or not spam. Take a look in /usr/lib/MailScanner/MailScanner/CustomFunctions/CustomAction.pm. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Iad Scoot" To: "MailScanner discussion" Sent: Monday, August 6, 2007 10:15:48 PM (GMT) Europe/London Subject: Re: converting attachments -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From list-mailscanner at linguaphone.com Tue Aug 7 08:43:28 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue Aug 7 08:43:42 2007 Subject: PATCH SweepViruses.pm - clamavmodule false positives - A PLEA! In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470B125CA8@largo.campus.ncl.ac.uk> References: <1186407034.31893.47.camel@gblades-suse.linguaphone-intranet.co.uk> <46B72D2E.2000208@ecs.soton.ac.uk> <4165CF7A7F12DE4B96622CCBB90586470B125CA8@largo.campus.ncl.ac.uk> Message-ID: <1186472608.2344.3.camel@gblades-suse.linguaphone-intranet.co.uk> You only get the false positives problem if you are using clamavmodule and have "ClamAV Full Message Scan = yes". Yo can turn off full message scanning but then some of the clamav signatures are unable to detect some of the phishing attacks. This is most noticeable if you are using the sanesecurity additional rules. It is just a couple of lines which need adding to SweepViruses.pm and I can send you an updated file if you wish. On Tue, 2007-08-07 at 08:05, Quentin Campbell wrote: > Julian > > If you do release a new version of 4.62.9 to fix this I would be > grateful if you could also make available a copy of the updated > SweepViruses.pm file. > > I have just finished upgrading 12 mail gateways to 4.62.9-2 and SA 3.2.2 > and cannot afford to go through the whole process of installing MS again > so soon. If it is just a single *.pm that needs replacing then that is > easy enough. > > How serious is this 'false positive' problem? Is it correct that I can > avoid the bug by setting "ClamAV Full Message Scan = no" and do I lose > much by doing that? > > Thanks > > Quentin > > > >-----Original Message----- > >From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > >bounces@lists.mailscanner.info] On Behalf Of Julian Field > >Sent: 06 August 2007 15:16 > >To: MailScanner discussion > >Subject: Re: PATCH SweepViruses.pm - clamavmodule false positives > > > >-----BEGIN PGP SIGNED MESSAGE----- > >Hash: SHA1 > > > >You only actually want to apply the first of the 2 patches, as you only > >want to affect the code that scans the *.message and *.header files. > > > >It will be in the next release. > > > >Please can some other people test this and confirm it works reliably? > > > >Gareth wrote: > >> Attached is a patch for SweepViruses.pm which fixes the false > >positives > >> issue with Phishing.Heuristics.Email.SpoofedDomain when using > >> Clamavmodule and the full message scan option. > >> > >> It passes the CL_SCAN_PHISHING_DOMAINLIST option which according to > >the > >> clamavmodule source :- > >> =item CL_SCAN_PHISHING_DOMAINLIST > >> Phishing module: restrict URL scanning to domains from .pdf > >> (RECOMMENDED). > >> > >> I believe that as this option was not previously set it is equivalent > >to > >> the following clamscan option :- > >> --no-phishing-restrictedscan > >> Enable url-based heuristic phishing detection for all domains > >> (might lead to false positives!). > >> > >> Personally I think CL_SCAN_PHISHING_DOMAINLIST should do the same as > >> --no-phishing-restrictedscan and not be the inverse of it. Maybe a > >bug. > >> I will contact the author about it anyway. > >> > >> I dont really know what this option does exactly but it is a > >recommended > >> setting, its name seems to indicate it is related to the false > >positives > >> I was getting, and setting it does seem to have cured the problem. > >> > > > >Jules > > > >- -- > >Julian Field MEng CITP > >www.MailScanner.info > >Buy the MailScanner book at www.MailScanner.info/store > > > >Need help customising MailScanner? > >Contact me! > >Need help fixing or optimising your systems? > >Contact me! > >Need help getting you started solving new requirements from your boss? > >Contact me! > > > >PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > > > >-----BEGIN PGP SIGNATURE----- > >Version: PGP Desktop 9.6.2 (Build 2014) > >Comment: (pgp-secured) > >Charset: ISO-8859-1 > > > >wj8DBQFGty0vEfZZRxQVtlQRAgNvAKClvd3nYnkZaaePge//JWDYGr8gVACgv7+H > >ApgOZBY/pz0cF9ZPiEkxnxs= > >=Jnzy > >-----END PGP SIGNATURE----- > > > >-- > >This message has been scanned for viruses and > >dangerous content by MailScanner, and is > >believed to be clean. > >For all your IT requirements visit www.transtec.co.uk > > > >-- > >MailScanner mailing list > >mailscanner@lists.mailscanner.info > >http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > >Before posting, read http://wiki.mailscanner.info/posting > > > >Support MailScanner development - buy the book off the website! From gmatt at nerc.ac.uk Tue Aug 7 10:14:17 2007 From: gmatt at nerc.ac.uk (Greg Matthews) Date: Tue Aug 7 10:14:46 2007 Subject: ClamAV module logging changed in 4.62 In-Reply-To: <46B76E09.50401@ecs.soton.ac.uk> References: <46B70923.6040309@nerc.ac.uk> <46B72B44.9090105@ecs.soton.ac.uk> <012401c7d859$adeeb620$0301a8c0@SAHOMELT> <46B76E09.50401@ecs.soton.ac.uk> Message-ID: <46B837E9.4020309@nerc.ac.uk> Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Rick Cooper wrote: >> Bear in mind that when clamd was added the name of the scanner is taked from >> the structure and not hard coded so if he has the display of virus scanners >> off there would be no name ok. but I dont understand, what is "the structure" if you mean my MailScanner.conf, then clamavmodule is explicitly specified. I'm not sure what you mean by having "the display of virus scanners off" either. My SophosSAVI still shows log lines like the following: Aug 6 08:29:20 mailr-w MailScanner[17999]: SophosSAVI::INFECTED:: Troj/Dloadr-BCP Troj/Dloadr-BCP:: ./l767T9Op023287/amazing.zip but the corresponding clamavmodule line for the same message is: Aug 6 08:29:21 mailr-w MailScanner[17999]: INFECTED:: Trojan.Downloader-12155:: ./l767T9Op023287/amazing.zip > Good point. That's probably it, I didn't think any of the clamavmodule > logging should have changed. excuse my ignorance, please explain the solution... GREG >> Rick -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford -- This message (and any attachments) is for the recipient only. NERC is subject to the Freedom of Information Act 2000 and the contents of this email and any reply you make may be disclosed by NERC unless it is exempt from release under the Act. Any material supplied to NERC may be stored in an electronic records management system. From glenn.steen at gmail.com Tue Aug 7 10:29:59 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue Aug 7 10:30:00 2007 Subject: MailScanner --lint error In-Reply-To: References: Message-ID: <223f97700708070229h620fb3advccf26622f7846ac4@mail.gmail.com> On 07/08/07, Scott Silva wrote: > Jody Cleveland spake the following on 8/6/2007 4:28 PM: > > > > > > On 8/6/07 5:41 PM, "Scott Silva" wrote: > > > >> Jody Cleveland spake the following on 8/6/2007 3:05 PM: > >>> Hello, > >>> > >>> I just upgraded to the most current stable release of MailScanner, and when > >>> I do a MailScanner --lint, I get this error: > >>> > >>> Cannot open config file --lint, No such file or directory at > >>> /usr/lib/MailScanner/MailScanner/Config.pm line 656. > >>> Compilation failed in require at /usr/sbin/MailScanner line 69. > >>> BEGIN failed--compilation aborted at /usr/sbin/MailScanner line 69. > >>> > >>> Any idea how I can fix this? > >>> > >>> - jody > >>> > >> Current stable from www.mailscanner.info, or current stable from a packager > >> like debian or freebsd? > > > > The current stable from www.mailscanner.info > > > >> Check for .rpmnew files in /usr/lib/MailScanner/MailScanner > > > > There's one .rpmnew file. CustomConfig.pm.rpmnew > > > > Should I delete this file? > > > > - jody > > > NO!! Try renaming the CustomConfig.pm to CustomConfig.pm.old and rename > CustomConfig.pm.rpmnew CustomConfig.pm > > Then retry the --lint > The question is _why_ there is an .rpmnew file... Did you perhaps use the old way of incorporating MailWatch? You might benefit from looking through the old CustomConfig.pm file to see what's there:) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From iad.scoot at gmail.com Tue Aug 7 12:38:40 2007 From: iad.scoot at gmail.com (Iad Scoot) Date: Tue Aug 7 12:38:43 2007 Subject: converting attachments In-Reply-To: <14998225.11841186472714827.JavaMail.root@office.splatnix.net> References: <88bd43930708061415r3df376ffxaef5eecce5254f18@mail.gmail.com> <14998225.11841186472714827.JavaMail.root@office.splatnix.net> Message-ID: <88bd43930708070438n5cfd3b6eydf8c8cb6e78dec66@mail.gmail.com> Thanks UxBoD, I'll have a look at that - maybe I can work the unrtf tool into this. - Iad On 8/7/07, UxBoD wrote: > > Iad, > > The Custom function allows you to write you own actions based on where > spam, high-spam or not spam. Take a look in > /usr/lib/MailScanner/MailScanner/CustomFunctions/CustomAction.pm. > > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B > // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B > // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net > > ----- Original Message ----- > From: "Iad Scoot" > To: "MailScanner discussion" > Sent: Monday, August 6, 2007 10:15:48 PM (GMT) Europe/London > Subject: Re: converting attachments > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070807/d7360da9/attachment.html From iad.scoot at gmail.com Tue Aug 7 12:41:12 2007 From: iad.scoot at gmail.com (Iad Scoot) Date: Tue Aug 7 12:41:16 2007 Subject: converting attachments In-Reply-To: <951d652c81cee64aaeff236d2534935e@solidstatelogic.com> References: <88bd43930708061413n4d8bb9b9k8f5c6ebcf9354fca@mail.gmail.com> <951d652c81cee64aaeff236d2534935e@solidstatelogic.com> Message-ID: <88bd43930708070441y908c750pdbc96e533bae6ad8@mail.gmail.com> Yeah, as much as I would like to do that, management will get bent out of shape. The problem is not local users but folks from remote domains - no real control over how they send it and management does not inconvenience these senders (clients, etc). Thanks... On 8/7/07, Martin.Hepworth wrote: > > Iad > > Policy here - default filetype is .doc anyother cannot be supported. It's > similar to what we've had to do here when we moved from Appleworks/Claris > works as tnhe default office platform. > > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Iad Scoot > > Sent: 06 August 2007 22:13 > > To: MailScanner discussion > > Subject: Re: converting attachments > > > > This particular issue is one of attachments - someone writes a document > > and saves it as a .rtf doc (Wordpad, etc) and then sends it attached to > an > > inbound email. My BB users get the message but can't open the > attachment. > > Its not the same issue (AFAIK) as the winmail.dat issue - I already have > > the TNEF expander configured for that issue. > > > > > > Thanks again... > > > > > > On 8/6/07, Kai Schaetzl wrote: > > > > Martin.Hepworth wrote on Mon, 06 Aug 2007 17:47:16 +0100: > > > > > you're taking about rft documents not winmail.dat things.. > > > > Maybe he *is* ... Iad, you are aware that Exchange can send the > mail > > as an > > rtf attachment as well? That then just contains the same text as > the > > plain > > text email. > > > > Kai > > > > -- > > Kai Sch?tzl, Berlin, Germany > > Get your web at Conactive Internet Services: > > http://www.conactive.com > > > > > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070807/02928927/attachment.html From glenn.steen at gmail.com Tue Aug 7 12:55:54 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue Aug 7 12:55:56 2007 Subject: converting attachments In-Reply-To: <88bd43930708070441y908c750pdbc96e533bae6ad8@mail.gmail.com> References: <88bd43930708061413n4d8bb9b9k8f5c6ebcf9354fca@mail.gmail.com> <951d652c81cee64aaeff236d2534935e@solidstatelogic.com> <88bd43930708070441y908c750pdbc96e533bae6ad8@mail.gmail.com> Message-ID: <223f97700708070455m35415315p6ec0dc760a67e44c@mail.gmail.com> On 07/08/07, Iad Scoot wrote: > Yeah, as much as I would like to do that, management will get bent out of > shape. The problem is not local users but folks from remote domains - no > real control over how they send it and management does not inconvenience > these senders (clients, etc). > > > Thanks... > Sometimes it's just a matter of saying "Live with it!"... Depending on your situation, that might not be a viable option though:-). What does BB support (.... yeah , I know...:-) tell you? If they aren't likely to solve a problem "endemic" to their apps... why should you? That might eb a good question to ask the PHB:-):-). Glenn -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From theodrake at comcast.net Tue Aug 7 15:30:09 2007 From: theodrake at comcast.net (Ed Bruce) Date: Tue Aug 7 15:30:24 2007 Subject: Improved init.d script In-Reply-To: <46B33847.30409@ecs.soton.ac.uk> References: <46B216AD.1010204@ecs.soton.ac.uk> <46B336BA.9040602@comcast.net> <46B33847.30409@ecs.soton.ac.uk> Message-ID: <46B881F1.80408@comcast.net> Julian Field wrote: > > > Ed Bruce wrote: >> Julian Field wrote: >> >>> Attached are new versions of the RedHat and SuSE /etc/init.d/MailScanner >>> scripts. >>> The improvement is obvious when you do >>> /etc/init.d/MailScanner restart >>> or >>> service MailScanner restart >>> >>> >> >> Works on my Redhat AS 3 (2.4.21-47.0.1.ELsmp) and 4 (2.6.9-55.ELsmp) MS >> servers. >> > Thanks for all the testing guys, it looks like it works everywhere it's > been tried (which is now quite a lot of places). It will be in the next > release. > > Jules > Well just did a another accidental test and this appears to have failed. I made some changes to the MS config and did a restart. This worked great, but I then realized I had forgot one change. I quickly made this and did another restart before all the child processes had started. The MS restart appears to have got stuck on the "Waiting for MailScanner to die gracefully.........................." step. I killed the restart followed by a a stop and then start to get MS running. -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 249 bytes Desc: OpenPGP digital signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070807/01aa5133/signature.bin From cleveland at winnefox.org Tue Aug 7 16:03:54 2007 From: cleveland at winnefox.org (Jody Cleveland) Date: Tue Aug 7 16:04:29 2007 Subject: MailScanner --lint error In-Reply-To: Message-ID: On 8/6/07 6:40 PM, "Scott Silva" wrote: > Jody Cleveland spake the following on 8/6/2007 4:28 PM: >> >> >> On 8/6/07 5:41 PM, "Scott Silva" wrote: >> >>> Jody Cleveland spake the following on 8/6/2007 3:05 PM: >>>> Hello, >>>> >>>> I just upgraded to the most current stable release of MailScanner, and when >>>> I do a MailScanner --lint, I get this error: >>>> >>>> Cannot open config file --lint, No such file or directory at >>>> /usr/lib/MailScanner/MailScanner/Config.pm line 656. >>>> Compilation failed in require at /usr/sbin/MailScanner line 69. >>>> BEGIN failed--compilation aborted at /usr/sbin/MailScanner line 69. >>>> >>>> Any idea how I can fix this? >>>> >>>> - jody >>>> >>> Current stable from www.mailscanner.info, or current stable from a packager >>> like debian or freebsd? >> >> The current stable from www.mailscanner.info >> >>> Check for .rpmnew files in /usr/lib/MailScanner/MailScanner >> >> There's one .rpmnew file. CustomConfig.pm.rpmnew >> >> Should I delete this file? >> >> - jody >> > NO!! Try renaming the CustomConfig.pm to CustomConfig.pm.old and rename > CustomConfig.pm.rpmnew CustomConfig.pm > > Then retry the --lint Ok, I did that, and --lint ran just fine. It did come up with two errors though: Checking version numbers... Version number in MailScanner.conf (4.62.9) is correct. Your envelope_sender_header in spam.assassin.prefs.conf is correct. Checking for SpamAssassin errors (if you use it)... SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp [11798] warn: FuzzyOcr: Cannot find executable for tesseract SpamAssassin reported no errors. MailScanner.conf says "Virus Scanners = f-prot clamd" Found these virus scanners installed: f-prot, clamavmodule =========================================================================== Ignore errors about failing to find EOCD signature format error: can't find EOCD signature at /usr/sbin/MailScanner line 451 =========================================================================== Virus Scanner test reports: F-Prot said "./1/eicar.com Infection: EICAR_Test_File" If any of your virus scanners (f-prot,clamavmodule) are not listed there, you should check that they are installed correctly and that MailScanner is finding them correctly via its virus.scanners.conf. From list-mailscanner at linguaphone.com Tue Aug 7 16:16:47 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue Aug 7 16:16:51 2007 Subject: Improved init.d script In-Reply-To: <46B216AD.1010204@ecs.soton.ac.uk> References: <46B216AD.1010204@ecs.soton.ac.uk> Message-ID: <1186499807.2352.49.camel@gblades-suse.linguaphone-intranet.co.uk> Hello Jules, I have made a few changes to your redhat script to add some additional options that I use and to fix a minor bug. 1) Modified the postfix detection 'if' command to check for the postfix.in directory at an earlier point so that the code to detect if postfix is working in hold queue mode now works and displays a suitable message. 2) Added postfix hold queue detection to the stop routine. 3) Added stopms and restartms command options so that you can stop and restart mailscanner independantly. 4) Added stopmswait command option to stop mailscanner and wait for processes to finish. This is handy in cron scripts when you want to stop mailscanner in order to backup the database or any other maintenance. It needs testing for people not using the postfix hold queue method. On Thu, 2007-08-02 at 18:38, Julian Field wrote: > Attached are new versions of the RedHat and SuSE /etc/init.d/MailScanner > scripts. > The improvement is obvious when you do > /etc/init.d/MailScanner restart > or > service MailScanner restart > > It used to just wait for a fixed length of time (30 seconds by default). > Now it watches to see when the old MailScanner processes have actually > died, and starts it all back up again as soon as the previous > MailScanner is dead. > > It is important not to 'kill -9' the MailScanner processes, as they do > quite a bit of cleanup so they don't leave a mess behind, for example in > /var/spool/MailScanner/incoming. > > Please let me know what you think of them, and if they work for you okay. > > Jules -------------- next part -------------- A non-text attachment was scrubbed... Name: RedHat.MailScanner.diff.gz Type: application/x-gzip Size: 1034 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070807/90fc5a09/RedHat.MailScanner.diff.gz From glenn.steen at gmail.com Tue Aug 7 16:35:28 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue Aug 7 16:35:30 2007 Subject: MailScanner --lint error In-Reply-To: References: Message-ID: <223f97700708070835i5501944emef8b80e5be2195e4@mail.gmail.com> On 07/08/07, Jody Cleveland wrote: > > > > On 8/6/07 6:40 PM, "Scott Silva" wrote: (snip) > > Then retry the --lint > > Ok, I did that, and --lint ran just fine. It did come up with two errors > though: > > Checking version numbers... > Version number in MailScanner.conf (4.62.9) is correct. > > Your envelope_sender_header in spam.assassin.prefs.conf is correct. > > Checking for SpamAssassin errors (if you use it)... > SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp > [11798] warn: FuzzyOcr: Cannot find executable for tesseract Might mean FuzzyOcr isn't setup correctly... "he said altruistically...":-). > SpamAssassin reported no errors. > MailScanner.conf says "Virus Scanners = f-prot clamd" > Found these virus scanners installed: f-prot, clamavmodule > =========================================================================== > Ignore errors about failing to find EOCD signature > format error: can't find EOCD signature > at /usr/sbin/MailScanner line 451 > =========================================================================== > Virus Scanner test reports: > F-Prot said "./1/eicar.com Infection: EICAR_Test_File" So your clamd setup isn't working. Either work your way through that, or switch to clamavmodule, which it seems to find OK... > If any of your virus scanners (f-prot,clamavmodule) Seems to be a display buglet here...:) > are not listed there, you should check that they are installed correctly > and that MailScanner is finding them correctly via its virus.scanners.conf. > Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From itdept at fractalweb.com Tue Aug 7 17:10:27 2007 From: itdept at fractalweb.com (Chris Yuzik) Date: Tue Aug 7 17:11:14 2007 Subject: zip only spam In-Reply-To: <46B37A25.8050809@pa.net> References: <46AF6B68.1040706@pa.net> <46B22836.8000308@fractalweb.com> <46B37A25.8050809@pa.net> Message-ID: <46B89973.6080300@fractalweb.com> Leland J. Steinke wrote: > Sorry, "inline" needs to be changed to "attachment" as well. Leland, So this then? full ZIP_ONLY_SPAM /encoding\:\s+7bit(\n?)+[\-0-9]+.{1,40}type\:\s+application\/octet-stream\;.{1,40}name\=.{1,40}\.zip.{1,50}disposition\:\s+attachment\;.{1,40}filename\=.{1,40}\.zip/is Chris From cleveland at winnefox.org Tue Aug 7 17:17:28 2007 From: cleveland at winnefox.org (Jody Cleveland) Date: Tue Aug 7 17:18:02 2007 Subject: MailScanner --lint error In-Reply-To: <223f97700708070835i5501944emef8b80e5be2195e4@mail.gmail.com> Message-ID: On 8/7/07 10:35 AM, "Glenn Steen" wrote: (snip) >>> Then retry the --lint >> >> Ok, I did that, and --lint ran just fine. It did come up with two errors >> though: >> >> Checking version numbers... >> Version number in MailScanner.conf (4.62.9) is correct. >> >> Your envelope_sender_header in spam.assassin.prefs.conf is correct. >> >> Checking for SpamAssassin errors (if you use it)... >> SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp >> [11798] warn: FuzzyOcr: Cannot find executable for tesseract > Might mean FuzzyOcr isn't setup correctly... "he said altruistically...":-). Ok, I'll try to track that one down. >> SpamAssassin reported no errors. >> MailScanner.conf says "Virus Scanners = f-prot clamd" >> Found these virus scanners installed: f-prot, clamavmodule >> =========================================================================== >> Ignore errors about failing to find EOCD signature >> format error: can't find EOCD signature >> at /usr/sbin/MailScanner line 451 >> =========================================================================== >> Virus Scanner test reports: >> F-Prot said "./1/eicar.com Infection: EICAR_Test_File" > > So your clamd setup isn't working. Either work your way through that, > or switch to clamavmodule, which it seems to find OK... Isn't clamavmodule the slow one? I had switched to clamd because of clam using 100% of the processor. - jody From maillists at conactive.com Tue Aug 7 17:31:21 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Tue Aug 7 17:31:25 2007 Subject: DSN and 4.62.9 problem In-Reply-To: <46B79B17.90005@coders.co.uk> References: <46B79B17.90005@coders.co.uk> Message-ID: Matt Hampton wrote on Mon, 06 Aug 2007 23:05:11 +0100: > OoO will never be fixable without straying in to the patented method of > changing the Message-ID a la I'd say it's not fixable at all because the OoO reply usually doesn't quote any header lines. > > http://arstechnica.com/news.ars/post/20050713-5090.html Another example of patent trolling. :-( > There may be a way to fix read receipts but this would require > maintaining state (which would break the ability to have multiple > independent servers) or possibly find a way of allowing read receipts. maintain state? What do you mean by that? It seems that read receipts *do* contain in-reply-to/references headers, so you could reuse these. Another method would be to allow read receipts up to a certain length at all. Would it make sense for spammers to disguise as read receipts? I'm not sure what most mail clients do with them, at least mine would just display it. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From sandrews at andrewscompanies.com Tue Aug 7 17:32:17 2007 From: sandrews at andrewscompanies.com (Steven Andrews) Date: Tue Aug 7 17:32:21 2007 Subject: zip only spam In-Reply-To: <46B89973.6080300@fractalweb.com> References: <46AF6B68.1040706@pa.net> <46B22836.8000308@fractalweb.com><46B37A25.8050809@pa.net> <46B89973.6080300@fractalweb.com> Message-ID: <1964AAFBC212F742958F9275BF63DBB04B10A4@winchester.andrewscompanies.com> This code (below) is tested and working for me. full ZIP_ONLY_SPAM /encoding\:\s+7bit(\n?)+[\-0-9]+.{1,40}type\:\s+application\/octet-strea m\;.{1,40}name\=.{1,40}\.zip.{1,50}disposition\:\s+attachment\;.{1,40}fi lename\=.{1,40}\.zip/is describe ZIP_ONLY_SPAM ZIP only Message, no text in message body score ZIP_ONLY_SPAM 5.0 -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Chris Yuzik Sent: Tuesday, August 07, 2007 12:10 PM To: MailScanner discussion Subject: Re: zip only spam Leland J. Steinke wrote: > Sorry, "inline" needs to be changed to "attachment" as well. Leland, So this then? full ZIP_ONLY_SPAM /encoding\:\s+7bit(\n?)+[\-0-9]+.{1,40}type\:\s+application\/octet-strea m\;.{1,40}name\=.{1,40}\.zip.{1,50}disposition\:\s+attachment\;.{1,40}fi lename\=.{1,40}\.zip/is Chris -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From fssilva at gmail.com Tue Aug 7 17:38:38 2007 From: fssilva at gmail.com (Fabio Silva) Date: Tue Aug 7 17:38:42 2007 Subject: Question... Message-ID: Hi list, is there any way to configure Mailscanner that.... i can create a list of extensions like .exe .wma .ppt .... and ... and when emails arrives with files like theses that are confiured in my list... it send this emails to an especific email address... like garbage@domain.com. Thanks. Fabio From MailScanner at ecs.soton.ac.uk Tue Aug 7 17:40:55 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 7 17:41:28 2007 Subject: Improved init.d script In-Reply-To: <46B881F1.80408@comcast.net> References: <46B216AD.1010204@ecs.soton.ac.uk> <46B336BA.9040602@comcast.net> <46B33847.30409@ecs.soton.ac.uk> <46B881F1.80408@comcast.net> Message-ID: <46B8A097.6050305@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 This isn't caused by the init.d script, it appears that in some situations it can take a long time for the MailScanner child process to exit. Killing the rogue child causes the script to continue normally. Ed Bruce wrote: > Julian Field wrote: > >> Ed Bruce wrote: >> >>> Julian Field wrote: >>> >>> >>>> Attached are new versions of the RedHat and SuSE /etc/init.d/MailScanner >>>> scripts. >>>> The improvement is obvious when you do >>>> /etc/init.d/MailScanner restart >>>> or >>>> service MailScanner restart >>>> >>>> >>>> >>> Works on my Redhat AS 3 (2.4.21-47.0.1.ELsmp) and 4 (2.6.9-55.ELsmp) MS >>> servers. >>> >>> >> Thanks for all the testing guys, it looks like it works everywhere it's >> been tried (which is now quite a lot of places). It will be in the next >> release. >> >> Jules >> >> > > Well just did a another accidental test and this appears to have failed. > I made some changes to the MS config and did a restart. This worked > great, but I then realized I had forgot one change. I quickly made this > and did another restart before all the child processes had started. The > MS restart appears to have got stuck on the "Waiting for MailScanner to > die gracefully.........................." step. I killed the restart > followed by a a stop and then start to get MS running. > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGuKCYEfZZRxQVtlQRAs+UAJ9TZfdClC4C6SpCAbyxdQuv1LzC5wCeL9rj Va7Dae5dB4BX8xL1Izp6fM8= =7Olv -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Tue Aug 7 17:42:19 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 7 17:42:51 2007 Subject: MailScanner --lint error In-Reply-To: References: Message-ID: <46B8A0EB.70205@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Jody Cleveland wrote: > > On 8/7/07 10:35 AM, "Glenn Steen" wrote: > > (snip) > >>>> Then retry the --lint >>>> >>> Ok, I did that, and --lint ran just fine. It did come up with two errors >>> though: >>> >>> Checking version numbers... >>> Version number in MailScanner.conf (4.62.9) is correct. >>> >>> Your envelope_sender_header in spam.assassin.prefs.conf is correct. >>> >>> Checking for SpamAssassin errors (if you use it)... >>> SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp >>> [11798] warn: FuzzyOcr: Cannot find executable for tesseract >>> >> Might mean FuzzyOcr isn't setup correctly... "he said altruistically...":-). >> > > Ok, I'll try to track that one down. > > >>> SpamAssassin reported no errors. >>> MailScanner.conf says "Virus Scanners = f-prot clamd" >>> Found these virus scanners installed: f-prot, clamavmodule >>> =========================================================================== >>> Ignore errors about failing to find EOCD signature >>> format error: can't find EOCD signature >>> at /usr/sbin/MailScanner line 451 >>> =========================================================================== >>> Virus Scanner test reports: >>> F-Prot said "./1/eicar.com Infection: EICAR_Test_File" >>> >> So your clamd setup isn't working. Either work your way through that, >> or switch to clamavmodule, which it seems to find OK... >> > > Isn't clamavmodule the slow one? I had switched to clamd because of clam > using 100% of the processor. > No its clamav (ie. using clamscan command) that is the slow one. The clamavmodule works fine. > - jody > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGuKDsEfZZRxQVtlQRAtmLAJ4y7pwHFGwZcbr42i8xfRnon5kP6ACgj41c ouYzcM9lsw50pOtFBZzDT18= =hTYO -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From cleveland at winnefox.org Tue Aug 7 17:55:46 2007 From: cleveland at winnefox.org (Jody Cleveland) Date: Tue Aug 7 17:56:21 2007 Subject: MailScanner --lint error In-Reply-To: <46B8A0EB.70205@ecs.soton.ac.uk> Message-ID: On 8/7/07 11:42 AM, "Julian Field" wrote: >>> So your clamd setup isn't working. Either work your way through that, >>> or switch to clamavmodule, which it seems to find OK... >>> >> >> Isn't clamavmodule the slow one? I had switched to clamd because of clam >> using 100% of the processor. >> > No its clamav (ie. using clamscan command) that is the slow one. The > clamavmodule works fine. So, if I want to use the sanesecurity thing, should I be using clamavmodule? - jody From MailScanner at ecs.soton.ac.uk Tue Aug 7 18:18:21 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 7 18:18:57 2007 Subject: Question... In-Reply-To: References: Message-ID: <46B8A95D.8000209@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Generate a simple SpamAssassin rule that detects the attachment filenames you are interested in. Then use SpamAssassin Rule Actions = rule=>forward garbage@domain.com, rule=>delete where "rule" is the name of your SpamAssassin rule. Fabio Silva wrote: > Hi list, is there any way to configure Mailscanner that.... i can > create a list of extensions like .exe .wma .ppt .... and ... and when > emails arrives with files like theses that are confiured in my list... > it send this emails to an especific email address... like > garbage@domain.com. > > Thanks. > > Fabio > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGuKleEfZZRxQVtlQRArOOAKDZGOfc2VTFLHRBSX28w8iXvfMurQCfXIIy C6DDmGQ+gpIXEwv2zFqUCfE= =66He -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Tue Aug 7 18:18:50 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 7 18:19:20 2007 Subject: MailScanner --lint error In-Reply-To: References: Message-ID: <46B8A97A.9050500@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Any of clamav, clamavmodule or clamd will do fine. Jody Cleveland wrote: > > On 8/7/07 11:42 AM, "Julian Field" wrote: > > >>>> So your clamd setup isn't working. Either work your way through that, >>>> or switch to clamavmodule, which it seems to find OK... >>>> >>>> >>> Isn't clamavmodule the slow one? I had switched to clamd because of clam >>> using 100% of the processor. >>> >>> >> No its clamav (ie. using clamscan command) that is the slow one. The >> clamavmodule works fine. >> > > So, if I want to use the sanesecurity thing, should I be using clamavmodule? > > - jody > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGuKl7EfZZRxQVtlQRAtz+AJ9K2H2Ab9P0d21WefIBCUkITZgiDwCfVtMz cNl+z4pvC44rCrlYbAqryNU= =pkpw -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From cleveland at winnefox.org Tue Aug 7 18:30:51 2007 From: cleveland at winnefox.org (Jody Cleveland) Date: Tue Aug 7 18:31:26 2007 Subject: MailScanner --lint error In-Reply-To: <46B8A0EB.70205@ecs.soton.ac.uk> Message-ID: On 8/7/07 11:42 AM, "Julian Field" wrote: >>>> SpamAssassin reported no errors. >>>> MailScanner.conf says "Virus Scanners = f-prot clamd" >>>> Found these virus scanners installed: f-prot, clamavmodule >>>> =========================================================================== >>>> Ignore errors about failing to find EOCD signature >>>> format error: can't find EOCD signature >>>> at /usr/sbin/MailScanner line 451 >>>> =========================================================================== >>>> Virus Scanner test reports: >>>> F-Prot said "./1/eicar.com Infection: EICAR_Test_File" >>>> >>> So your clamd setup isn't working. Either work your way through that, >>> or switch to clamavmodule, which it seems to find OK... >>> >> >> Isn't clamavmodule the slow one? I had switched to clamd because of clam >> using 100% of the processor. >> > No its clamav (ie. using clamscan command) that is the slow one. The > clamavmodule works fine. Ok, I changed it to clamavmodule, and now --lint gives me this error: None of the files matched by the "Monitors For ClamAV Updates" patterns exist! at /usr/lib/MailScanner/MailScanner/SweepViruses.pm line 527 - jody From glenn.steen at gmail.com Tue Aug 7 19:00:28 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue Aug 7 19:00:29 2007 Subject: MailScanner --lint error In-Reply-To: References: <46B8A0EB.70205@ecs.soton.ac.uk> Message-ID: <223f97700708071100k5214cb59rf8f973c9e6f89ae@mail.gmail.com> On 07/08/07, Jody Cleveland wrote: > > > > On 8/7/07 11:42 AM, "Julian Field" wrote: > > >>>> SpamAssassin reported no errors. > >>>> MailScanner.conf says "Virus Scanners = f-prot clamd" > >>>> Found these virus scanners installed: f-prot, clamavmodule > >>>> =========================================================================== > >>>> Ignore errors about failing to find EOCD signature > >>>> format error: can't find EOCD signature > >>>> at /usr/sbin/MailScanner line 451 > >>>> =========================================================================== > >>>> Virus Scanner test reports: > >>>> F-Prot said "./1/eicar.com Infection: EICAR_Test_File" > >>>> > >>> So your clamd setup isn't working. Either work your way through that, > >>> or switch to clamavmodule, which it seems to find OK... > >>> > >> > >> Isn't clamavmodule the slow one? I had switched to clamd because of clam > >> using 100% of the processor. > >> > > No its clamav (ie. using clamscan command) that is the slow one. The > > clamavmodule works fine. > > Ok, I changed it to clamavmodule, and now --lint gives me this error: > > None of the files matched by the "Monitors For ClamAV Updates" patterns > exist! at /usr/lib/MailScanner/MailScanner/SweepViruses.pm line 527 > > - jody > There is a section in MailScanner.conf for this.... Mainly what you need change is the monitor line so that it: a) Mathces where you have put your clamav signature databas(es), and b) match all the possible files comprising your DBs... That means one item for *,cvd, one item for *.inc/* and one item for *.*db (more or less...:-). separate the items by space. This has been covered several times over the last ... oh... 6 months or so... on this list, so if you need something to cut'n'paste, please look through the archives (there was a recent ... spat... of "misconfigurations" revealed by the last major incremental clamavdb update:-). IIRC Jules have enhanced the upgrade script to determine if this is set, although I think he doesn't really check if they seem sane... After all, only one of the .cvd or .inc items need be correct:-). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From ssilva at sgvwater.com Tue Aug 7 19:08:01 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue Aug 7 19:08:17 2007 Subject: Help with sa-update, SARE and RDJ ---Please In-Reply-To: <46B7D827.2010004@openenterprise.ca> References: <46B7D827.2010004@openenterprise.ca> Message-ID: Johnny Stork spake the following on 8/6/2007 7:25 PM: > I am trying to cleanup my current MS install which I have been happily > running for a few years and just updated to the most current version. I > had previously been running RDJ but the daily reports showed many errors > and so I am trying to get a final, working and relatively clean setup. > After a number of attempts and a great deal of reading, searching and a > few posts, this whole automated update process seems very unnecessarily > confusing. Many sites are outdated, no docs available on SARE, some > sites say to use RDJ, others say RDJ is broken and use sa-update and > recently Julian indicated I could find some how-to's on the mailing list > archive but after searching each monthly archive going back around 1 > year, I could find not HOWTO for sa-update. Please dont take this as a > complaint, just some frustration likely brought on through my own > ignorance. The message is dated July 8, 2007 by Julian. The complete subject is HOWTO: Adding extra rulesets to SpamAssassin There is some pre-done scripts and a channel file that you can modify. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Tue Aug 7 19:21:00 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue Aug 7 19:21:13 2007 Subject: Performance of 'ClamAV Full Message Scan' In-Reply-To: References: Message-ID: Ren? Berber spake the following on 8/6/2007 7:43 PM: > From the changelog: > > "When clamav, clamavmodule or clamd parsers are being used and new setting > "ClamAV Full Message Scan" is set to "yes", pass each of the entire > messages to ClamAV as well as the attachments so that the signatures that > detect spam can work reliably. This is set to "no" be default as it has a > speed impact." > > Why pass the message AND attachments? ClamAV can detect the virus in the > message in any possible form, MailScanner is just making clam do double work, > plus the work done by MS to extract the attachments. > Some of the sanesecurity signatures need the full raw message to detect the nasties. It does it this way to stay compatible with any other virus scanners you might be running. Many of us run several virus scanners to catch more 0-day stuff. The double scoring is a side effect, but I expect more virus scanners to pick up things in the raw messages like clam and mcafee now do. I don't think Julian is going to have an option of "whole message only", but you never know. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From itdept at fractalweb.com Tue Aug 7 19:28:38 2007 From: itdept at fractalweb.com (Chris Yuzik) Date: Tue Aug 7 19:28:50 2007 Subject: zip only spam In-Reply-To: <1964AAFBC212F742958F9275BF63DBB04B10A4@winchester.andrewscompanies.com> References: <46AF6B68.1040706@pa.net> <46B22836.8000308@fractalweb.com><46B37A25.8050809@pa.net> <46B89973.6080300@fractalweb.com> <1964AAFBC212F742958F9275BF63DBB04B10A4@winchester.andrewscompanies.com> Message-ID: <46B8B9D6.3000106@fractalweb.com> Steven Andrews wrote: > This code (below) is tested and working for me. > > full ZIP_ONLY_SPAM > /encoding\:\s+7bit(\n?)+[\-0-9]+.{1,40}type\:\s+application\/octet-strea > m\;.{1,40}name\=.{1,40}\.zip.{1,50}disposition\:\s+attachment\;.{1,40}fi > lename\=.{1,40}\.zip/is > describe ZIP_ONLY_SPAM ZIP only Message, no text in message > body > score ZIP_ONLY_SPAM 5.0 Steven, I'm using this, but so far not getting any hits. # ZIP only spam full ZIP_ONLY_SPAM /encoding\:\s+7bit(\n?)+[\-0-9]+.{1,40}type\:\s+application\/octet-stream\;.{1,40}name\=.{1,40}\.zip.{1,50}disposition\:\s+attachment\;.{1,40}filename\=.{1,40}\.zip/is describe ZIP_ONLY_SPAM ZIP only Message, no text in message body score ZIP_ONLY_SPAM 3.95 Not sure what I've done wrong. Chris From ssilva at sgvwater.com Tue Aug 7 19:25:05 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue Aug 7 19:30:09 2007 Subject: ClamAV and MailScanner SPAM or Virus In-Reply-To: <0dfc01c7d8c1$95db3f50$060a0aac@Fajar> References: <0dfc01c7d8c1$95db3f50$060a0aac@Fajar> Message-ID: Fajar spake the following on 8/7/2007 12:07 AM: > Hello, > > I'm testing our email server that powered by mailscanner(4.61), > spamassassin bayes stored in database, > clamav 0.91, and 3rd party clamav database(sanesecurity and mslbr). By > using several testing website, > I get eicar test virus identified as spam in mailwatch report? Is that > something wrong, or usuall? > > Fajar > Did it mark as spam in all the test sites or just some of them? You can enable the setting "Keep Spam And MCP Archive Clean = yes" if you want to check spam messages for viruses. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From steinkel at pa.net Tue Aug 7 19:47:45 2007 From: steinkel at pa.net (Leland J. Steinke) Date: Tue Aug 7 19:47:52 2007 Subject: zip only spam In-Reply-To: <46B8B9D6.3000106@fractalweb.com> References: <46AF6B68.1040706@pa.net> <46B22836.8000308@fractalweb.com><46B37A25.8050809@pa.net> <46B89973.6080300@fractalweb.com> <1964AAFBC212F742958F9275BF63DBB04B10A4@winchester.andrewscompanies.com> <46B8B9D6.3000106@fractalweb.com> Message-ID: <46B8BE51.2010805@pa.net> Chris Yuzik wrote: > > I'm using this, but so far not getting any hits. I am finding that the spammers are working around this pattern with an empty text/plain body, a text/html body with a bunch of markup around " ", and then the actual ZIP. SA3.2.2 is catching the bulk of these with its built-in rules. You might have to look at the actual message source to see where it is differing from what the ZIP_ONLY_SPAM rule is expecting. Leland From sandrews at andrewscompanies.com Tue Aug 7 20:27:47 2007 From: sandrews at andrewscompanies.com (Steven Andrews) Date: Tue Aug 7 20:27:55 2007 Subject: zip only spam In-Reply-To: <46B8B9D6.3000106@fractalweb.com> References: <46AF6B68.1040706@pa.net> <46B22836.8000308@fractalweb.com><46B37A25.8050809@pa.net> <46B89973.6080300@fractalweb.com><1964AAFBC212F742958F9275BF63DBB04B10A4@winchester.andrewscompanies.com> <46B8B9D6.3000106@fractalweb.com> Message-ID: <1964AAFBC212F742958F9275BF63DBB04B10B2@winchester.andrewscompanies.com> Grab my file just in case; cd /etc/mail/spamassassin wget http://www.andrewscompanies.com/files/mailscanner/70_andrews_badzip.cf dos2unix 70_andrews_badzip.cf chmod 644 70_andrews_badzip.cf Then do a test, mailwatch if you have it, mailscanner -D --lint if you don't and make sure you see it loading. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Chris Yuzik Sent: Tuesday, August 07, 2007 2:29 PM To: MailScanner discussion Subject: Re: zip only spam Steven Andrews wrote: > This code (below) is tested and working for me. > > full ZIP_ONLY_SPAM > /encoding\:\s+7bit(\n?)+[\-0-9]+.{1,40}type\:\s+application\/octet-str > ea > m\;.{1,40}name\=.{1,40}\.zip.{1,50}disposition\:\s+attachment\;.{1,40} > fi > lename\=.{1,40}\.zip/is > describe ZIP_ONLY_SPAM ZIP only Message, no text in message > body > score ZIP_ONLY_SPAM 5.0 Steven, I'm using this, but so far not getting any hits. # ZIP only spam full ZIP_ONLY_SPAM /encoding\:\s+7bit(\n?)+[\-0-9]+.{1,40}type\:\s+application\/octet-strea m\;.{1,40}name\=.{1,40}\.zip.{1,50}disposition\:\s+attachment\;.{1,40}fi lename\=.{1,40}\.zip/is describe ZIP_ONLY_SPAM ZIP only Message, no text in message body score ZIP_ONLY_SPAM 3.95 Not sure what I've done wrong. Chris -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Tue Aug 7 20:46:31 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 7 20:47:08 2007 Subject: Performance of 'ClamAV Full Message Scan' In-Reply-To: References: Message-ID: <46B8CC17.4040807@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Scott Silva wrote: > Ren? Berber spake the following on 8/6/2007 7:43 PM: > >> From the changelog: >> >> "When clamav, clamavmodule or clamd parsers are being used and new setting >> "ClamAV Full Message Scan" is set to "yes", pass each of the entire >> messages to ClamAV as well as the attachments so that the signatures that >> detect spam can work reliably. This is set to "no" be default as it has a >> speed impact." >> >> Why pass the message AND attachments? ClamAV can detect the virus in the >> message in any possible form, MailScanner is just making clam do double work, >> plus the work done by MS to extract the attachments. >> >> > Some of the sanesecurity signatures need the full raw message to detect the > nasties. It does it this way to stay compatible with any other virus scanners > you might be running. Many of us run several virus scanners to catch more > 0-day stuff. > The double scoring is a side effect, but I expect more virus scanners to pick > up things in the raw messages like clam and mcafee now do. > > I don't think Julian is going to have an option of "whole message only", but > you never know. > You're right, he's not. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGuMwYEfZZRxQVtlQRAlDPAKCH5ZbGqR+M7xi3NH6x+E0fbzvK0wCfQgm0 gKDEUdaDaZw9z6CQHCEY3kw= =Lqdb -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From asakawa at quickd.net Tue Aug 7 20:50:30 2007 From: asakawa at quickd.net (Takashi Asakawa) Date: Tue Aug 7 20:51:07 2007 Subject: Failed to get CRM114-Status Message-ID: <20070808044706.E68A.ASAKAWA@quickd.net> I was just finds it -------------------------- OSSEC HIDS Notification. 2007 Aug 08 03:01:56 Received From: ns->/var/log/maillog Rule: 1002 fired (level 7) -> "Unknown problem somewhere in the system." Portion of the log(s): Aug 8 03:01:56 ns spamd[1868]: crm114: Error. Failed to get CRM114-Status. at /etc/mail/spamassassin/crm114.pm line 312 -------------------------- Failed to get CRM114-Status what does this mean? Takashi Asakawa From cleveland at winnefox.org Tue Aug 7 21:02:09 2007 From: cleveland at winnefox.org (Jody Cleveland) Date: Tue Aug 7 21:02:43 2007 Subject: MailScanner --lint error In-Reply-To: <223f97700708071100k5214cb59rf8f973c9e6f89ae@mail.gmail.com> Message-ID: On 8/7/07 1:00 PM, "Glenn Steen" wrote: >>>>>> SpamAssassin reported no errors. >>>>>> MailScanner.conf says "Virus Scanners = f-prot clamd" >>>>>> Found these virus scanners installed: f-prot, clamavmodule >>>>>> ========================================================================= >>>>>> == >>>>>> Ignore errors about failing to find EOCD signature >>>>>> format error: can't find EOCD signature >>>>>> at /usr/sbin/MailScanner line 451 >>>>>> ========================================================================= >>>>>> == >>>>>> Virus Scanner test reports: >>>>>> F-Prot said "./1/eicar.com Infection: EICAR_Test_File" >>>>>> >>>>> So your clamd setup isn't working. Either work your way through that, >>>>> or switch to clamavmodule, which it seems to find OK... >>>>> >>>> >>>> Isn't clamavmodule the slow one? I had switched to clamd because of clam >>>> using 100% of the processor. >>>> >>> No its clamav (ie. using clamscan command) that is the slow one. The >>> clamavmodule works fine. >> >> Ok, I changed it to clamavmodule, and now --lint gives me this error: >> >> None of the files matched by the "Monitors For ClamAV Updates" patterns >> exist! at /usr/lib/MailScanner/MailScanner/SweepViruses.pm line 527 >> >> - jody >> > There is a section in MailScanner.conf for this.... Mainly what you > need change is the monitor line so that it: > a) Mathces where you have put your clamav signature databas(es), and > b) match all the possible files comprising your DBs... That means one > item for *,cvd, one item for *.inc/* and one item for *.*db (more or > less...:-). separate the items by space. > This has been covered several times over the last ... oh... 6 months > or so... on this list, so if you need something to cut'n'paste, please > look through the archives (there was a recent ... spat... of > "misconfigurations" revealed by the last major incremental clamavdb > update:-). > IIRC Jules have enhanced the upgrade script to determine if this is > set, although I think he doesn't really check if they seem sane... > After all, only one of the .cvd or .inc items need be correct:-). I actually found it on the front page of mailscanner.info You also need to make one change to your MailScanner.conf file: "Monitors for ClamAV Updates = /usr/local/share/clamav/*.inc/* /usr/local/share/clamav/*.cvd" I also added in /usr/local/share/clamav/*.*db like you suggested, and --lint works fine now. Thank you so much for taking the time to help me with this! - jody From leolists at seidkr.com Tue Aug 7 21:12:57 2007 From: leolists at seidkr.com (=?ISO-8859-1?Q?Philip_Leonard_WV=D8T?=) Date: Tue Aug 7 21:13:10 2007 Subject: Upgrade from 4.51.6 to latest on Gentoo box Message-ID: <46B8D249.6000101@seidkr.com> To upgrade from 4.51.6 to the latest version on a Gentoo box can I just run the install.sh script (after a backup of course) or is there something else I should do? Basically this is a .tar installation. Spamassassin and clamav are currently up to date. Thanks, Philip From glenn.steen at gmail.com Tue Aug 7 22:34:53 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue Aug 7 22:34:57 2007 Subject: Failed to get CRM114-Status In-Reply-To: <20070808044706.E68A.ASAKAWA@quickd.net> References: <20070808044706.E68A.ASAKAWA@quickd.net> Message-ID: <223f97700708071434v353646b4r7573f1970baa56fa@mail.gmail.com> On 07/08/07, Takashi Asakawa wrote: > I was just finds it > > -------------------------- > > OSSEC HIDS Notification. > 2007 Aug 08 03:01:56 > > Received From: ns->/var/log/maillog > Rule: 1002 fired (level 7) -> "Unknown problem somewhere in the system." > Portion of the log(s): > > Aug 8 03:01:56 ns spamd[1868]: crm114: Error. Failed to get CRM114-Status. at /etc/mail/spamassassin/crm114.pm line 312 > spamd is most certainly not a part of MailScanner, nor needed by it. Simply turn it off. More interesting is if you get something similar from a spamassassin lint or in the logs produced by MailScanner ... I would rather think not, since I suspect the reason that spamd is having trouble is due to permission issues ... But I can't be sure, since I don't use it;) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From ssilva at sgvwater.com Tue Aug 7 22:36:12 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue Aug 7 22:36:34 2007 Subject: MailScanner --lint error In-Reply-To: References: <223f97700708071100k5214cb59rf8f973c9e6f89ae@mail.gmail.com> Message-ID: Jody Cleveland spake the following on 8/7/2007 1:02 PM: > > > On 8/7/07 1:00 PM, "Glenn Steen" wrote: > >>>>>>> SpamAssassin reported no errors. >>>>>>> MailScanner.conf says "Virus Scanners = f-prot clamd" >>>>>>> Found these virus scanners installed: f-prot, clamavmodule >>>>>>> ========================================================================= >>>>>>> == >>>>>>> Ignore errors about failing to find EOCD signature >>>>>>> format error: can't find EOCD signature >>>>>>> at /usr/sbin/MailScanner line 451 >>>>>>> ========================================================================= >>>>>>> == >>>>>>> Virus Scanner test reports: >>>>>>> F-Prot said "./1/eicar.com Infection: EICAR_Test_File" >>>>>>> >>>>>> So your clamd setup isn't working. Either work your way through that, >>>>>> or switch to clamavmodule, which it seems to find OK... >>>>>> >>>>> Isn't clamavmodule the slow one? I had switched to clamd because of clam >>>>> using 100% of the processor. >>>>> >>>> No its clamav (ie. using clamscan command) that is the slow one. The >>>> clamavmodule works fine. >>> Ok, I changed it to clamavmodule, and now --lint gives me this error: >>> >>> None of the files matched by the "Monitors For ClamAV Updates" patterns >>> exist! at /usr/lib/MailScanner/MailScanner/SweepViruses.pm line 527 >>> >>> - jody >>> >> There is a section in MailScanner.conf for this.... Mainly what you >> need change is the monitor line so that it: >> a) Mathces where you have put your clamav signature databas(es), and >> b) match all the possible files comprising your DBs... That means one >> item for *,cvd, one item for *.inc/* and one item for *.*db (more or >> less...:-). separate the items by space. >> This has been covered several times over the last ... oh... 6 months >> or so... on this list, so if you need something to cut'n'paste, please >> look through the archives (there was a recent ... spat... of >> "misconfigurations" revealed by the last major incremental clamavdb >> update:-). >> IIRC Jules have enhanced the upgrade script to determine if this is >> set, although I think he doesn't really check if they seem sane... >> After all, only one of the .cvd or .inc items need be correct:-). > > I actually found it on the front page of mailscanner.info > > You also need to make one change to your MailScanner.conf file: "Monitors > for ClamAV Updates = /usr/local/share/clamav/*.inc/* > /usr/local/share/clamav/*.cvd" > > I also added in /usr/local/share/clamav/*.*db like you suggested, and --lint > works fine now. > > Thank you so much for taking the time to help me with this! > > - jody > Another satisfied user! Might I suggest buying the MailScanner book as a way to help reward the developer and creator of this fine piece of software engineering? http://www.cafepress.com/mailscanner2,mailscanner.140046559 -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From r.berber at computer.org Tue Aug 7 22:59:59 2007 From: r.berber at computer.org (=?ISO-8859-1?Q?Ren=E9_Berber?=) Date: Tue Aug 7 23:00:16 2007 Subject: AW: AW: DSN and 4.62.9 problem In-Reply-To: <4D1CD0994309F84BA83DF998BF0075AF4328E174@ts-dc2.TS-Webarts.local> References: <46B79B17.90005@coders.co.uk> <4D1CD0994309F84BA83DF998BF0075AF4328E173@ts-dc2.TS-Webarts.local> <4D1CD0994309F84BA83DF998BF0075AF4328E174@ts-dc2.TS-Webarts.local> Message-ID: R. Ehle wrote: > I partly agree with you. We have to distinguish "Read Notifications" from > "Delivery Notifications". Yes, I see that the read receipt messages have a MIME part with: Content-Type: message/disposition-notification ... Reporting-UA: user; Microsoft Office Outlook 11 Final-Recipient: rfc822;user@whatever.com Original-Message-ID: Disposition: manual-action/MDN-sent-manually; displayed So the precise term would be MDN (ref: RFC 2298) not DSN (ref: RFC 1891, 1892, 1894). My mistake on the subject. > Delivery Notifications are sent by the MTA. If the delivery notification is > sent by a MTA like sendmail, postfix or qmail, the Watermarking function > works fine. > > If the Delivery Notification is sent by a Microsoft Exchange Server, > especially, if it is the new one (Exchange 2007), then the header of the > original message is not included and so Watermarking function fails to > recognize the message. Thanks for the clarification. -- Ren? Berber From cleveland at winnefox.org Tue Aug 7 23:21:53 2007 From: cleveland at winnefox.org (Jody Cleveland) Date: Tue Aug 7 23:22:26 2007 Subject: MailScanner --lint error In-Reply-To: Message-ID: On 8/7/07 4:36 PM, "Scott Silva" wrote: >> I actually found it on the front page of mailscanner.info >> >> You also need to make one change to your MailScanner.conf file: "Monitors >> for ClamAV Updates = /usr/local/share/clamav/*.inc/* >> /usr/local/share/clamav/*.cvd" >> >> I also added in /usr/local/share/clamav/*.*db like you suggested, and --lint >> works fine now. >> >> Thank you so much for taking the time to help me with this! >> >> - jody >> > Another satisfied user! > Might I suggest buying the MailScanner book as a way to help reward the > developer and creator of this fine piece of software engineering? > > http://www.cafepress.com/mailscanner2,mailscanner.140046559 I am satisfied beyond words, have been since I started using MS. Thanks for reminding me about the book, I'll definitely be ordering one. - jody From maillists at conactive.com Tue Aug 7 23:31:14 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Tue Aug 7 23:31:18 2007 Subject: DSN and 4.62.9 problem In-Reply-To: References: <46B79B17.90005@coders.co.uk> Message-ID: One more comment. There are other occasions where watermarking rejects legitimate messages. Sent a complaint to abuse@oneandone.net today. Got back the typical automated confirmation from <> with a correct in-reply-to but not quoting everything else (of, course, why should they?). milter-null (that I'm currently testing) marked it as "DSN or MDN for message that did not originate here". This whole anti-backscatter stuff is based on the idea that the only stuff coming from <> are delayed DSNs, and that's simply not true. I guess it works great if you are in the middle of a backscatter storm from a joejob, but it doesn't work as a daily production solution. And in the case of a backscatter storm you could just reject all messages from <> without producing much more false positives than watermarking does. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From ssilva at sgvwater.com Tue Aug 7 23:34:20 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue Aug 7 23:35:05 2007 Subject: DSN and 4.62.9 problem In-Reply-To: References: Message-ID: Ren? Berber spake the following on 8/6/2007 11:39 AM: > Hi, > > Similar problem to that reported for OoO and watermarking, read receipts (DSN) > messages do not return the watermark header and MailScanner is tagging all of > them as spam with the log showing: > > MailScanner[2081]: Message l76HJGJu004811 from ... has no (or invalid) > NULL-Header or sender address > > This wasn't the case with the previous version used (4.62.7), I'm testing now > with watermarking off. Any other solutions? I had to turn off watermarking also because of the read receipts. It was also marking stuff that should have been whitelisted (internal to internal). -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From MailScanner at ecs.soton.ac.uk Tue Aug 7 23:48:25 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 7 23:48:55 2007 Subject: MailScanner --lint error In-Reply-To: References: Message-ID: <46B8F6B9.3060300@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Jody Cleveland wrote: > > On 8/7/07 4:36 PM, "Scott Silva" wrote: > > >>> I actually found it on the front page of mailscanner.info >>> >>> You also need to make one change to your MailScanner.conf file: "Monitors >>> for ClamAV Updates = /usr/local/share/clamav/*.inc/* >>> /usr/local/share/clamav/*.cvd" >>> >>> I also added in /usr/local/share/clamav/*.*db like you suggested, and --lint >>> works fine now. >>> >>> Thank you so much for taking the time to help me with this! >>> >>> - jody >>> >>> >> Another satisfied user! >> Might I suggest buying the MailScanner book as a way to help reward the >> developer and creator of this fine piece of software engineering? >> >> http://www.cafepress.com/mailscanner2,mailscanner.140046559 >> > > I am satisfied beyond words, have been since I started using MS. Thanks for > reminding me about the book, I'll definitely be ordering one. > Thank you! Take a look at the new feature in 4.63.1. You can see it in the Change Log at http://www.mailscanner.info/ChangeLog You might find it useful. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGuPa6EfZZRxQVtlQRAsKBAJ9Skg0euNFcbmyXZYuvPO8Df8v+JQCeNF84 n13ADhkfJ6WMzLRTvyZu9wo= =kWpc -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Tue Aug 7 23:51:34 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 7 23:52:04 2007 Subject: DSN and 4.62.9 problem In-Reply-To: References: Message-ID: <46B8F776.90500@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Scott Silva wrote: > Ren? Berber spake the following on 8/6/2007 11:39 AM: > >> Hi, >> >> Similar problem to that reported for OoO and watermarking, read receipts (DSN) >> messages do not return the watermark header and MailScanner is tagging all of >> them as spam with the log showing: >> >> MailScanner[2081]: Message l76HJGJu004811 from ... has no (or invalid) >> NULL-Header or sender address >> >> This wasn't the case with the previous version used (4.62.7), I'm testing now >> with watermarking off. Any other solutions? >> > I had to turn off watermarking also because of the read receipts. It was also > marking stuff that should have been whitelisted (internal to internal). > Should I leave it switched off by default? What are people's opinion on this? P.S. Check out the new feature in 4.63, it's in the Change Log at http://www.mailscanner.info/ChangeLog You might find it useful. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGuPd2EfZZRxQVtlQRAg8iAKCGeh4njnKTDpC2CCk7Je4PPSJpgACeJD+/ CDCEpEoZmAj0Hkjh1SXwqts= =+BUb -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From gmane at tippingmar.com Wed Aug 8 00:52:54 2007 From: gmane at tippingmar.com (Mark Nienberg) Date: Wed Aug 8 00:53:09 2007 Subject: DSN and 4.62.9 problem In-Reply-To: <46B8F776.90500@ecs.soton.ac.uk> References: <46B8F776.90500@ecs.soton.ac.uk> Message-ID: Julian Field wrote: > Should I leave it switched off by default? > What are people's opinion on this? I had to turn it off because of the out-of-office replies that it was blocking. If all my users were as sensible as my comrades on this list, then that wouldn't be a problem. My users think they work in the real world and I live in a fantasy. I've gotten over it. Mark Nienberg From itdept at fractalweb.com Wed Aug 8 01:03:13 2007 From: itdept at fractalweb.com (Chris Yuzik) Date: Wed Aug 8 01:03:21 2007 Subject: zip only spam In-Reply-To: <1964AAFBC212F742958F9275BF63DBB04B10B2@winchester.andrewscompanies.com> References: <46AF6B68.1040706@pa.net> <46B22836.8000308@fractalweb.com><46B37A25.8050809@pa.net> <46B89973.6080300@fractalweb.com><1964AAFBC212F742958F9275BF63DBB04B10A4@winchester.andrewscompanies.com> <46B8B9D6.3000106@fractalweb.com> <1964AAFBC212F742958F9275BF63DBB04B10B2@winchester.andrewscompanies.com> Message-ID: <46B90841.7020407@fractalweb.com> Steven Andrews wrote: > Grab my file just in case; > > cd /etc/mail/spamassassin > wget > http://www.andrewscompanies.com/files/mailscanner/70_andrews_badzip.cf Steven, I get a 404 on that file. Can you check the URL again? Thanks, Chris From r.berber at computer.org Wed Aug 8 01:27:33 2007 From: r.berber at computer.org (=?ISO-8859-1?Q?Ren=E9_Berber?=) Date: Wed Aug 8 01:27:49 2007 Subject: DSN and 4.62.9 problem In-Reply-To: <46B8F776.90500@ecs.soton.ac.uk> References: <46B8F776.90500@ecs.soton.ac.uk> Message-ID: Julian Field wrote: > Scott Silva wrote: >> I had to turn off watermarking also because of the read receipts. It was also >> marking stuff that should have been whitelisted (internal to internal). > > Should I leave it switched off by default? Yes. > What are people's opinion on this? It definitely gives false positives with all MDN messages. -- Ren? Berber From rcooper at dwford.com Wed Aug 8 04:13:06 2007 From: rcooper at dwford.com (Rick Cooper) Date: Wed Aug 8 04:13:13 2007 Subject: ClamAV module logging changed in 4.62 In-Reply-To: <46B837E9.4020309@nerc.ac.uk> References: <46B70923.6040309@nerc.ac.uk><46B72B44.9090105@ecs.soton.ac.uk> <012401c7d859$adeeb620$0301a8c0@SAHOMELT><46B76E09.50401@ecs.soton.ac.uk> <46B837E9.4020309@nerc.ac.uk> Message-ID: <015301c7d96a$0aaed820$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On > Behalf Of Greg Matthews > Sent: Tuesday, August 07, 2007 5:14 AM > To: MailScanner discussion > Subject: Re: ClamAV module logging changed in 4.62 > > Julian Field wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > > Hash: SHA1 > > > > > > > > Rick Cooper wrote: > >> Bear in mind that when clamd was added the name of the > scanner is taked from > >> the structure and not hard coded so if he has the display > of virus scanners > >> off there would be no name > > ok. but I dont understand, what is "the structure" if you mean my > MailScanner.conf, then clamavmodule is explicitly specified. I'm not > sure what you mean by having "the display of virus scanners > off" either. By structure I was referring to the internal information MailScanner passes from function to functions. ClamAVModule used to be hard coded to log ClamAVModule as the virus scanner but since Clamd and ClamAVModule pass the same info back in the same format the code that parses the information is used by both and part of the information that is passed is the scanner name so the name logged now is dependant upon which scanner is being parsed. There is an option to hide the scanner name and I honestly don't remember what it is. If Julian hasn't looked at this yet I will in the morning but it's late and I have been going since 3:00am so it will have to wait until morning > My SophosSAVI still shows log lines like the following: > > Aug 6 08:29:20 mailr-w MailScanner[17999]: SophosSAVI::INFECTED:: > Troj/Dloadr-BCP Troj/Dloadr-BCP:: ./l767T9Op023287/amazing.zip > > but the corresponding clamavmodule line for the same message is: > > Aug 6 08:29:21 mailr-w MailScanner[17999]: INFECTED:: > Trojan.Downloader-12155:: ./l767T9Op023287/amazing.zip > > > Good point. That's probably it, I didn't think any of the > clamavmodule > > logging should have changed. > > excuse my ignorance, please explain the solution... > > GREG > > >> Rick > > > -- > Greg Matthews 01491 692445 > Head of UNIX/Linux, iTSS Wallingford > > -- > This message (and any attachments) is for the recipient only. NERC > is subject to the Freedom of Information Act 2000 and the contents > of this email and any reply you make may be disclosed by NERC unless > it is exempt from release under the Act. Any material supplied to > NERC may be stored in an electronic records management system. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From mailscanner at home.carlo65.de Wed Aug 8 05:42:25 2007 From: mailscanner at home.carlo65.de (R. Ehle (MailScanner Mailinglist)) Date: Wed Aug 8 05:43:26 2007 Subject: AW: zip only spam In-Reply-To: <46B90841.7020407@fractalweb.com> References: <46AF6B68.1040706@pa.net> <46B22836.8000308@fractalweb.com><46B37A25.8050809@pa.net> <46B89973.6080300@fractalweb.com><1964AAFBC212F742958F9275BF63DBB04B10A4@winchester.andrewscompanies.com> <46B8B9D6.3000106@fractalweb.com> <1964AAFBC212F742958F9275BF63DBB04B10B2@winchester.andrewscompanies.com> <46B90841.7020407@fractalweb.com> Message-ID: <4D1CD0994309F84BA83DF998BF0075AF4328E184@ts-dc2.TS-Webarts.local> Hi, as Andrews link seems not to work, just mirrored the file: http://www.mailmind.de/files/70_andrews_badzip.cf Roland -----Urspr?ngliche Nachricht----- Von: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Im Auftrag von Chris Yuzik Gesendet: Mittwoch, 8. August 2007 02:03 An: MailScanner discussion Betreff: Re: zip only spam Steven Andrews wrote: > Grab my file just in case; > > cd /etc/mail/spamassassin > wget > http://www.andrewscompanies.com/files/mailscanner/70_andrews_badzip.cf Steven, I get a 404 on that file. Can you check the URL again? Thanks, Chris -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ---------------------------------------------------------- Diese Nachricht wurde von mailMind(R) auf Viren und andere gefaehrliche Inhalte untersucht und ist sauber. --- mailMind(R) - we have your Mailsecurity in mind! http://www.mailmind.de --- From mailscanner at home.carlo65.de Wed Aug 8 06:01:31 2007 From: mailscanner at home.carlo65.de (R. Ehle (MailScanner Mailinglist)) Date: Wed Aug 8 06:02:25 2007 Subject: Quarantine question Message-ID: <4D1CD0994309F84BA83DF998BF0075AF4328E185@ts-dc2.TS-Webarts.local> Hi, since I started to use SaneSecurity the Quarantine contains all the mails which had been caught by SaneSecurity too. This is uncomfortable, as the daily Quarantine Report is full of the crab. I have set Quarantine Infections = yes Quarantine Silent Viruses = no Quarantine Modified Body = yes Any idea, how I can prevent mails with an infection like Email.Spam.Gen374.Sanesecurity.07041701 from being put into Quarantine? Thanks. Regards, Roland ---------------------------------------------------------- Diese Nachricht wurde von mailMind(R) auf Viren und andere gefaehrliche Inhalte untersucht und ist sauber. --- mailMind(R) - we have your Mailsecurity in mind! http://www.mailmind.de --- -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070808/15dbcd41/attachment.html From Jeff.Mills at versacold.com.au Wed Aug 8 06:27:33 2007 From: Jeff.Mills at versacold.com.au (Jeff Mills) Date: Wed Aug 8 06:27:39 2007 Subject: Spamhaus issues? Message-ID: Is anyone having issues with Spamhaus at the moment? I'm unable to do any lookups from three different servers. postfix/smtpd[21696]: warning: 118.17.51.190.zen.spamhaus.org: RBL lookup error: Host or domain name not found. Name service error for name=118.17.51.190.zen.spamhaus.org type=A: Host not found, try again I cant actually look up zen.spamhaus.org itself, nor sbl or xbl. From res at ausics.net Wed Aug 8 06:45:19 2007 From: res at ausics.net (Res) Date: Wed Aug 8 06:45:28 2007 Subject: Spamhaus issues? In-Reply-To: References: Message-ID: On Wed, 8 Aug 2007, Jeff Mills wrote: > Is anyone having issues with Spamhaus at the moment? > I'm unable to do any lookups from three different servers. > > postfix/smtpd[21696]: warning: 118.17.51.190.zen.spamhaus.org: RBL > lookup error: Host or domain name not found. Name service error for > name=118.17.51.190.zen.spamhaus.org type=A: Host not found, try again > > I cant actually look up zen.spamhaus.org itself, nor sbl or xbl. Works fine here ~$ host 118.17.51.190.zen.spamhaus.org 118.17.51.190.zen.spamhaus.org has address 127.0.0.11 118.17.51.190.zen.spamhaus.org has address 127.0.0.4 -- Cheers Res From Jeff.Mills at versacold.com.au Wed Aug 8 07:27:04 2007 From: Jeff.Mills at versacold.com.au (Jeff Mills) Date: Wed Aug 8 07:27:09 2007 Subject: Spamhaus issues? Message-ID: > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Res > Sent: Wednesday, 8 August 2007 3:45 PM > To: MailScanner discussion > Subject: Re: Spamhaus issues? > > On Wed, 8 Aug 2007, Jeff Mills wrote: > > > Is anyone having issues with Spamhaus at the moment? > > I'm unable to do any lookups from three different servers. > > > > postfix/smtpd[21696]: warning: 118.17.51.190.zen.spamhaus.org: RBL > > lookup error: Host or domain name not found. Name service error for > > name=118.17.51.190.zen.spamhaus.org type=A: Host not found, > try again > > > > I cant actually look up zen.spamhaus.org itself, nor sbl or xbl. > > > Works fine here > > ~$ host 118.17.51.190.zen.spamhaus.org > 118.17.51.190.zen.spamhaus.org has address 127.0.0.11 > 118.17.51.190.zen.spamhaus.org has address 127.0.0.4 > > -- > > Cheers > Res Thanks Res, After looking through their website, I think we may have actually been firewalled due to excess useage. I wasn't aware that it was a subscription service for businesses. Today one of our domains was used for forged addresses, so our traffic has increased substantially. From list-mailscanner at linguaphone.com Wed Aug 8 08:52:08 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 8 08:52:14 2007 Subject: logwatch Message-ID: <1186559528.5148.4.camel@gblades-suse.linguaphone-intranet.co.uk> Does Mailscanner install a plugin for Logwatch or is it just that Logwatch supports Mailscanner by default? The new version of Mailscanner has a different ClamAV logging format which is causing Logwatch not to recognise them. Any idea how I can fix this? From glenn.steen at gmail.com Wed Aug 8 09:01:29 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 8 09:01:31 2007 Subject: logwatch In-Reply-To: <1186559528.5148.4.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1186559528.5148.4.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <223f97700708080101x5091c807x8879632299f8b1be@mail.gmail.com> On 08/08/07, Gareth wrote: > Does Mailscanner install a plugin for Logwatch or is it just that > Logwatch supports Mailscanner by default? AFAIU the latter. > The new version of Mailscanner has a different ClamAV logging format > which is causing Logwatch not to recognise them. Any idea how I can fix > this? Since the latter -> take it up there;-). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From Q.G.Campbell at newcastle.ac.uk Wed Aug 8 09:12:49 2007 From: Q.G.Campbell at newcastle.ac.uk (Quentin Campbell) Date: Wed Aug 8 09:14:45 2007 Subject: What exactly changed between 4.62.9-2 & 4.62.9-3? Message-ID: <4165CF7A7F12DE4B96622CCBB90586470B125E74@largo.campus.ncl.ac.uk> It is not clear to me from the change log what precisely changed between 62.9-2 and 62.9-3. There was talk a couple of days ago about fixing a bug in SweepVirus.pm. It is just a single .pm file that has changed in the 62.9-3 revision and if so can I get the updated file and copy this to my twelve 4.62.9-2 hosts and do a 'service MailScanner restart'? For the moment I have set "ClamAV Full Message Scan = no". I am using clamavmodule but not the SaneSecurity signatures. I go on extended leave from late on Thursday and would like to ensure that I hand over twelve stable and fully functional 4.62.9 MailScanner gateways to my colleagues! Quentin --- PHONE: +44 191 222 8209??? Information Systems and Services (ISS), ?????????????????????????? Newcastle University, ?????????????????????????? Newcastle upon Tyne, FAX:?? +44 191 222 8765??? United Kingdom, NE1 7RU. ------------------------------------------------------------------------ From sandrews at andrewscompanies.com Wed Aug 8 11:51:10 2007 From: sandrews at andrewscompanies.com (Steven Andrews) Date: Wed Aug 8 11:51:16 2007 Subject: zip only spam In-Reply-To: <46B90841.7020407@fractalweb.com> References: <46AF6B68.1040706@pa.net> <46B22836.8000308@fractalweb.com><46B37A25.8050809@pa.net> <46B89973.6080300@fractalweb.com><1964AAFBC212F742958F9275BF63DBB04B10A4@winchester.andrewscompanies.com> <46B8B9D6.3000106@fractalweb.com><1964AAFBC212F742958F9275BF63DBB04B10B2@winchester.andrewscompanies.com> <46B90841.7020407@fractalweb.com> Message-ID: <1964AAFBC212F742958F9275BF63DBB04B10B5@winchester.andrewscompanies.com> Sorry, my bad; we did some cleanup on the directories and I forgot that. Proper link: http://www.andrewscompanies.com/files/mailscanner/rules/70_andrews_badzi p.cf -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Chris Yuzik Sent: Tuesday, August 07, 2007 8:03 PM To: MailScanner discussion Subject: Re: zip only spam Steven Andrews wrote: > Grab my file just in case; > > cd /etc/mail/spamassassin > wget > http://www.andrewscompanies.com/files/mailscanner/70_andrews_badzip.cf Steven, I get a 404 on that file. Can you check the URL again? Thanks, Chris -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From hvdkooij at vanderkooij.org Wed Aug 8 11:58:47 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Wed Aug 8 11:59:01 2007 Subject: logwatch In-Reply-To: <223f97700708080101x5091c807x8879632299f8b1be@mail.gmail.com> References: <1186559528.5148.4.camel@gblades-suse.linguaphone-intranet.co.uk> <223f97700708080101x5091c807x8879632299f8b1be@mail.gmail.com> Message-ID: On Wed, 8 Aug 2007, Glenn Steen wrote: > On 08/08/07, Gareth wrote: >> Does Mailscanner install a plugin for Logwatch or is it just that >> Logwatch supports Mailscanner by default? > AFAIU the latter. > >> The new version of Mailscanner has a different ClamAV logging format >> which is causing Logwatch not to recognise them. Any idea how I can fix >> this? > Since the latter -> take it up there;-). First off. Make sure you are running the latest logwatch version. Usually the more common products are kept pretty much up-to-date. So it may just be a case of an older logwatch version on your system. If the most recent version of logwatch does not match them then please donate a log file to the logwatch developers mailinglist. Unfortunatly I have a few other pressing things to do first so I can not test this myself right now. (I happen to do the occasional bit for logwatch as well.) Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From res at ausics.net Wed Aug 8 12:25:56 2007 From: res at ausics.net (Res) Date: Wed Aug 8 12:26:04 2007 Subject: Spamhaus issues? In-Reply-To: References: Message-ID: Ahh, nasty, time for a change in RBL's I guess... On Wed, 8 Aug 2007, Jeff Mills wrote: > After looking through their website, I think we may have actually been > firewalled due to excess useage. > I wasn't aware that it was a subscription service for businesses. its a a subscription service if you have X number of requests for hour or some crap like that, there are other very good RBL's around that are not analy retentive like them, we use njabl, sorbs and spamcop. Best of luck Jeff, -- Cheers Res From mikael at syska.dk Wed Aug 8 13:29:09 2007 From: mikael at syska.dk (Mikael Syska) Date: Wed Aug 8 13:27:55 2007 Subject: FreeBSD and MailScanner --lint Message-ID: <46B9B715.40007@syska.dk> Hi, Dont knwo if this is intended to be so, but here goes .... root [/usr/local/etc/MailScanner]# /usr/local/etc/rc.d/mailscanner restart Stopping mailscanner. Waiting for PIDS: 778, 778. Starting mailscanner. root [/usr/local/etc/MailScanner]# cat /var/run/MailScanner.pid 3229 Then running running, with MailScanner still running: #MailScanner --lint Its overwriting: root [/usr/local/etc/MailScanner]# cat /var/run/MailScanner.pid ( yes, it writes MailScanner in the pid file ) MailScanner Is this the way its supposed to be or ? I just noticed this today ... best regards Mikael Syska From glenn.steen at gmail.com Wed Aug 8 13:49:15 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 8 13:49:18 2007 Subject: FreeBSD and MailScanner --lint In-Reply-To: <46B9B715.40007@syska.dk> References: <46B9B715.40007@syska.dk> Message-ID: <223f97700708080549p7d058bc7n4533088f484c8b0c@mail.gmail.com> On 08/08/07, Mikael Syska wrote: > Hi, > > Dont knwo if this is intended to be so, but here goes .... > > root [/usr/local/etc/MailScanner]# /usr/local/etc/rc.d/mailscanner restart > Stopping mailscanner. > Waiting for PIDS: 778, 778. > Starting mailscanner. > > root [/usr/local/etc/MailScanner]# cat /var/run/MailScanner.pid > 3229 > > Then running running, with MailScanner still running: > #MailScanner --lint > > Its overwriting: > root [/usr/local/etc/MailScanner]# cat /var/run/MailScanner.pid ( yes, > it writes MailScanner in the pid file ) > MailScanner > > Is this the way its supposed to be or ? I just noticed this today ... > Very likely not. I just verified that it does this on Mandriva with the rpm install method (and hence likely on any rpm-based system, perhaps barring SuSE...). Will have a look. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From MailScanner at ecs.soton.ac.uk Wed Aug 8 13:58:08 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 8 13:58:26 2007 Subject: Release 4.63.1 beta Message-ID: <46B9BDE0.2050507@ecs.soton.ac.uk> I have released a new beta, 4.63.1. The main new feature is a live updated list of known bad phishing sites. The sites in this list have been manually tested and have been compromised or set up specifically as phishing sites. You should update your copy of this list once every hour. RPM installations of MailScanner will do this automatically. Download as usual from www.mailscanner.info. The full Change Log is this: * New Features and Improvements * 1 Improved init.d script, so that 'service MailScanner restart' or '/etc/init.d/MailScanner restart' runs faster. It pauses for just long enough for the old MailScanner to die gracefully, and starts up the new one as soon as the old one has died. Previously, it just waited for a fixed length of time which was much longer than needed for most people. 1 Improved tar installer so the directory created for MailScanner includes the build revision number as well as the main version number. 1 Improved phishing net logging to log entire real URL not just hostname. 1 Improvement to update_spamassassin to stop cron-generated mail. 1 New setting "Phishing Bad Sites File" which is a live continuously-updated list of known bad sites that have been reported to various mechanisms around the world. Please don't ask me for more information as I can't give it to you, but every site on the list has been manually tested and the list can be relied upon. Your installation should update this file every hour. NOTE: Run upgrade_languages_conf after installing this upgrade! * Fixes * 1 Improvement to phishing net to allow HTML tags with contents split over multiple lines. 1 Changed options to ClamAVmodule so it doesn't hit false positives with the phishing and scam email detection signatures. 1-2 Fixed bug where --lint gives "MailScanner.conf file not found" error. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From rcooper at dwford.com Wed Aug 8 13:58:41 2007 From: rcooper at dwford.com (Rick Cooper) Date: Wed Aug 8 13:58:50 2007 Subject: ClamAV module logging changed in 4.62 In-Reply-To: <46B837E9.4020309@nerc.ac.uk> References: <46B70923.6040309@nerc.ac.uk><46B72B44.9090105@ecs.soton.ac.uk> <012401c7d859$adeeb620$0301a8c0@SAHOMELT><46B76E09.50401@ecs.soton.ac.uk> <46B837E9.4020309@nerc.ac.uk> Message-ID: <028c01c7d9bb$d8ec8740$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On > Behalf Of Greg Matthews > Sent: Tuesday, August 07, 2007 5:14 AM > To: MailScanner discussion > Subject: Re: ClamAV module logging changed in 4.62 > > Julian Field wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > > Hash: SHA1 > > > > > > > > Rick Cooper wrote: > >> Bear in mind that when clamd was added the name of the > scanner is taked from > >> the structure and not hard coded so if he has the display > of virus scanners > >> off there would be no name > > ok. but I dont understand, what is "the structure" if you mean my > MailScanner.conf, then clamavmodule is explicitly specified. I'm not > sure what you mean by having "the display of virus scanners > off" either. > My SophosSAVI still shows log lines like the following: > > Aug 6 08:29:20 mailr-w MailScanner[17999]: SophosSAVI::INFECTED:: > Troj/Dloadr-BCP Troj/Dloadr-BCP:: ./l767T9Op023287/amazing.zip > > but the corresponding clamavmodule line for the same message is: > > Aug 6 08:29:21 mailr-w MailScanner[17999]: INFECTED:: > Trojan.Downloader-12155:: ./l767T9Op023287/amazing.zip > [...] Ok I had a look this morning and the only reason I can see would be having the display scanner name set to no. And BTW, The Sohpos scanner name is hard coded so it would display regardless. The setting in MailScanner.conf you are looking for is: Include Scanner Name In Reports = and it is probably set to no and should be set to yes. As a side note, anyone using MailWatch will need this set to yes for the next version as the name is used in his new parsing code (from the MailWatch list) Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From joshua.hirsh at partnersolutions.ca Wed Aug 8 13:59:04 2007 From: joshua.hirsh at partnersolutions.ca (Joshua Hirsh) Date: Wed Aug 8 13:59:09 2007 Subject: Quarantine question In-Reply-To: <4D1CD0994309F84BA83DF998BF0075AF4328E185@ts-dc2.TS-Webarts.local> References: <4D1CD0994309F84BA83DF998BF0075AF4328E185@ts-dc2.TS-Webarts.local> Message-ID: <453468AFB48D2B4287F8F8197FD15F79A7FD@psims003.pshosting.intranet> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of R. Ehle (MailScanner Mailinglist) > Sent: Wednesday, August 08, 2007 1:02 AM > To: MailScanner discussion > Subject: Quarantine question > > Hi, > > since I started to use SaneSecurity the Quarantine contains > all the mails which had been caught by SaneSecurity too. This > is uncomfortable, as the daily Quarantine Report is full of the crab. > > I have set > > Quarantine Infections = yes > Quarantine Silent Viruses = no > Quarantine Modified Body = yes > > Any idea, how I can prevent mails with an infection like > Email.Spam.Gen374.Sanesecurity.07041701 from being put into > Quarantine? What you can do is set 'Quarantine Infections' to a ruleset similar to the following: Virus: Sanesecurity no Virus: default yes Cheers, -Joshua From glenn.steen at gmail.com Wed Aug 8 14:05:41 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 8 14:05:44 2007 Subject: FreeBSD and MailScanner --lint In-Reply-To: <223f97700708080549p7d058bc7n4533088f484c8b0c@mail.gmail.com> References: <46B9B715.40007@syska.dk> <223f97700708080549p7d058bc7n4533088f484c8b0c@mail.gmail.com> Message-ID: <223f97700708080605w4f10e3a9w9d98adc6d7b2a341@mail.gmail.com> On 08/08/07, Glenn Steen wrote: > On 08/08/07, Mikael Syska wrote: > > Hi, > > > > Dont knwo if this is intended to be so, but here goes .... > > > > root [/usr/local/etc/MailScanner]# /usr/local/etc/rc.d/mailscanner restart > > Stopping mailscanner. > > Waiting for PIDS: 778, 778. > > Starting mailscanner. > > > > root [/usr/local/etc/MailScanner]# cat /var/run/MailScanner.pid > > 3229 > > > > Then running running, with MailScanner still running: > > #MailScanner --lint > > > > Its overwriting: > > root [/usr/local/etc/MailScanner]# cat /var/run/MailScanner.pid ( yes, > > it writes MailScanner in the pid file ) > > MailScanner > > > > Is this the way its supposed to be or ? I just noticed this today ... > > > Very likely not. > > I just verified that it does this on Mandriva with the rpm install > method (and hence likely on any rpm-based system, perhaps barring > SuSE...). > > Will have a look. > > Cheers Looking at that init script... it just seems to be set there, never really used... Perhaps check_MailScanner uses it, will look further... Nope, not that I can easily grep/see at a cashual glance. So it should be safe... One can wonder what good it does, setting/managing at all:-). I noticed one thing though... When stopping MailScanner, one process hangs around a _long_ while, claiming to be "compressing attachments"...: # ps -ef|grep MailScanner postfix 31370 1 1 14:52 ? 00:00:05 MailScanner: compressing attachments root 31760 8403 0 15:00 pts/0 00:00:00 grep --color MailScanner But I have: Zip Attachments = no ... Or is this perhaps the tnef repackaging? 'Cause I do use that... Sorry for the semi-hijack of your thread Mikael, hope you don't mind:). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From campbell at cnpapers.com Wed Aug 8 14:15:51 2007 From: campbell at cnpapers.com (Steve Campbell) Date: Wed Aug 8 14:16:03 2007 Subject: What's different with the new PDF only spams? Message-ID: <46B9C207.405@cnpapers.com> Seems like I just stopped seeing those PDF-Only spams using the SA rule that was posted here a week or so back. Now, the rule seem to be insufficient and is letting a lot of the newer ones through. I'm not a RegEx expert, to be sure, so can any one offer a suggestion for a rule to stop this new wave PDF-Only mailings, please? Thanks Steve Campbell From glenn.steen at gmail.com Wed Aug 8 14:17:35 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 8 14:17:37 2007 Subject: FreeBSD and MailScanner --lint In-Reply-To: <223f97700708080605w4f10e3a9w9d98adc6d7b2a341@mail.gmail.com> References: <46B9B715.40007@syska.dk> <223f97700708080549p7d058bc7n4533088f484c8b0c@mail.gmail.com> <223f97700708080605w4f10e3a9w9d98adc6d7b2a341@mail.gmail.com> Message-ID: <223f97700708080617j1bc4dee7l6a4e93d7715ece76@mail.gmail.com> On 08/08/07, Glenn Steen wrote: > On 08/08/07, Glenn Steen wrote: > > On 08/08/07, Mikael Syska wrote: > > > Hi, > > > > > > Dont knwo if this is intended to be so, but here goes .... > > > > > > root [/usr/local/etc/MailScanner]# /usr/local/etc/rc.d/mailscanner restart > > > Stopping mailscanner. > > > Waiting for PIDS: 778, 778. > > > Starting mailscanner. > > > > > > root [/usr/local/etc/MailScanner]# cat /var/run/MailScanner.pid > > > 3229 > > > > > > Then running running, with MailScanner still running: > > > #MailScanner --lint > > > > > > Its overwriting: > > > root [/usr/local/etc/MailScanner]# cat /var/run/MailScanner.pid ( yes, > > > it writes MailScanner in the pid file ) > > > MailScanner > > > > > > Is this the way its supposed to be or ? I just noticed this today ... > > > > > Very likely not. > > > > I just verified that it does this on Mandriva with the rpm install > > method (and hence likely on any rpm-based system, perhaps barring > > SuSE...). > > > > Will have a look. > > > > Cheers > > Looking at that init script... it just seems to be set there, never > really used... Perhaps check_MailScanner uses it, will look further... > Nope, not that I can easily grep/see at a cashual glance. So it should > be safe... One can wonder what good it does, setting/managing at > all:-). > The error seems to be only with how the .lint is implemented... Can't promise any fix or anything (if Jules don't reappear:-), I've got a lot on my plate today... Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Wed Aug 8 14:22:53 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 8 14:22:55 2007 Subject: FreeBSD and MailScanner --lint In-Reply-To: <223f97700708080617j1bc4dee7l6a4e93d7715ece76@mail.gmail.com> References: <46B9B715.40007@syska.dk> <223f97700708080549p7d058bc7n4533088f484c8b0c@mail.gmail.com> <223f97700708080605w4f10e3a9w9d98adc6d7b2a341@mail.gmail.com> <223f97700708080617j1bc4dee7l6a4e93d7715ece76@mail.gmail.com> Message-ID: <223f97700708080622k282006fdi8d56bb1f6360adf4@mail.gmail.com> On 08/08/07, Glenn Steen wrote: > On 08/08/07, Glenn Steen wrote: > > On 08/08/07, Glenn Steen wrote: > > > On 08/08/07, Mikael Syska wrote: > > > > Hi, > > > > > > > > Dont knwo if this is intended to be so, but here goes .... > > > > > > > > root [/usr/local/etc/MailScanner]# /usr/local/etc/rc.d/mailscanner restart > > > > Stopping mailscanner. > > > > Waiting for PIDS: 778, 778. > > > > Starting mailscanner. > > > > > > > > root [/usr/local/etc/MailScanner]# cat /var/run/MailScanner.pid > > > > 3229 > > > > > > > > Then running running, with MailScanner still running: > > > > #MailScanner --lint > > > > > > > > Its overwriting: > > > > root [/usr/local/etc/MailScanner]# cat /var/run/MailScanner.pid ( yes, > > > > it writes MailScanner in the pid file ) > > > > MailScanner > > > > > > > > Is this the way its supposed to be or ? I just noticed this today ... > > > > > > > Very likely not. > > > > > > I just verified that it does this on Mandriva with the rpm install > > > method (and hence likely on any rpm-based system, perhaps barring > > > SuSE...). > > > > > > Will have a look. > > > > > > Cheers > > > > Looking at that init script... it just seems to be set there, never > > really used... Perhaps check_MailScanner uses it, will look further... > > Nope, not that I can easily grep/see at a cashual glance. So it should > > be safe... One can wonder what good it does, setting/managing at > > all:-). > > > The error seems to be only with how the .lint is implemented... Can't > promise any fix or anything (if Jules don't reappear:-), I've got a > lot on my plate today... > Ok, looked at the code, and as teh following snippet implies: ---- # Need to find the PidFile before changing uid/gid as its ownership will need # to be set to the new uid/gid. It must be created first if necessary. # Need PidFile to be able to manage pid of parent process $PidFile = MailScanner::Config::Value('pidfile'); WritePIDFile("MailScanner"); chown $uid, $gid, $PidFile; ----- ...this is all pretty intentional;-). One could argue that Jules should preserve it by not overwriting it, but then ... it seems to be used sparingly, if at all. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From martinh at solidstatelogic.com Wed Aug 8 14:24:36 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed Aug 8 14:24:41 2007 Subject: What's different with the new PDF only spams? In-Reply-To: <46B9C207.405@cnpapers.com> Message-ID: <58767e9a346d1b42adf293e23f972a4a@solidstatelogic.com> Steve I they've fixed the spam now and there's a blank message body attachment as well ;-) -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Steve Campbell > Sent: 08 August 2007 14:16 > To: mailscanner@lists.mailscanner.info > Subject: What's different with the new PDF only spams? > > Seems like I just stopped seeing those PDF-Only spams using the SA rule > that was posted here a week or so back. > > Now, the rule seem to be insufficient and is letting a lot of the newer > ones through. I'm not a RegEx expert, to be sure, so can any one offer a > suggestion for a rule to stop this new wave PDF-Only mailings, please? > > Thanks > > Steve Campbell > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From mikael at syska.dk Wed Aug 8 14:27:01 2007 From: mikael at syska.dk (Mikael Syska) Date: Wed Aug 8 14:25:42 2007 Subject: FreeBSD and MailScanner --lint In-Reply-To: <223f97700708080617j1bc4dee7l6a4e93d7715ece76@mail.gmail.com> References: <46B9B715.40007@syska.dk> <223f97700708080549p7d058bc7n4533088f484c8b0c@mail.gmail.com> <223f97700708080605w4f10e3a9w9d98adc6d7b2a341@mail.gmail.com> <223f97700708080617j1bc4dee7l6a4e93d7715ece76@mail.gmail.com> Message-ID: <46B9C4A5.8080200@syska.dk> Glenn Steen wrote: > On 08/08/07, Glenn Steen wrote: > >> On 08/08/07, Glenn Steen wrote: >> >>> On 08/08/07, Mikael Syska wrote: >>> >>>> Hi, >>>> >>>> Dont knwo if this is intended to be so, but here goes .... >>>> >>>> root [/usr/local/etc/MailScanner]# /usr/local/etc/rc.d/mailscanner restart >>>> Stopping mailscanner. >>>> Waiting for PIDS: 778, 778. >>>> Starting mailscanner. >>>> >>>> root [/usr/local/etc/MailScanner]# cat /var/run/MailScanner.pid >>>> 3229 >>>> >>>> Then running running, with MailScanner still running: >>>> #MailScanner --lint >>>> >>>> Its overwriting: >>>> root [/usr/local/etc/MailScanner]# cat /var/run/MailScanner.pid ( yes, >>>> it writes MailScanner in the pid file ) >>>> MailScanner >>>> >>>> Is this the way its supposed to be or ? I just noticed this today ... >>>> >>>> >>> Very likely not. >>> >>> I just verified that it does this on Mandriva with the rpm install >>> method (and hence likely on any rpm-based system, perhaps barring >>> SuSE...). >>> >>> Will have a look. >>> >>> Cheers >>> >> Looking at that init script... it just seems to be set there, never >> really used... Perhaps check_MailScanner uses it, will look further... >> Nope, not that I can easily grep/see at a cashual glance. So it should >> be safe... One can wonder what good it does, setting/managing at >> all:-). >> >> > The error seems to be only with how the .lint is implemented... Can't > promise any fix or anything (if Jules don't reappear:-), I've got a > lot on my plate today... > > Cheers > Lets hope Jules seems this messeage and will fix it in a release in the future ... just have to remember to stop MS before running --lint or else there will be processes floating around. Its fine you hijacked my thread, as long as it helps MS to become bug free and even better. // ouT From MailScanner at ecs.soton.ac.uk Wed Aug 8 14:32:35 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 8 14:32:56 2007 Subject: FreeBSD and MailScanner --lint In-Reply-To: <223f97700708080617j1bc4dee7l6a4e93d7715ece76@mail.gmail.com> References: <46B9B715.40007@syska.dk> <223f97700708080549p7d058bc7n4533088f484c8b0c@mail.gmail.com> <223f97700708080605w4f10e3a9w9d98adc6d7b2a341@mail.gmail.com> <223f97700708080617j1bc4dee7l6a4e93d7715ece76@mail.gmail.com> Message-ID: <46B9C5F3.3010108@ecs.soton.ac.uk> Glenn Steen wrote: > On 08/08/07, Glenn Steen wrote: > >> On 08/08/07, Glenn Steen wrote: >> >>> On 08/08/07, Mikael Syska wrote: >>> >>>> Hi, >>>> >>>> Dont knwo if this is intended to be so, but here goes .... >>>> >>>> root [/usr/local/etc/MailScanner]# /usr/local/etc/rc.d/mailscanner restart >>>> Stopping mailscanner. >>>> Waiting for PIDS: 778, 778. >>>> Starting mailscanner. >>>> >>>> root [/usr/local/etc/MailScanner]# cat /var/run/MailScanner.pid >>>> 3229 >>>> >>>> Then running running, with MailScanner still running: >>>> #MailScanner --lint >>>> >>>> Its overwriting: >>>> root [/usr/local/etc/MailScanner]# cat /var/run/MailScanner.pid ( yes, >>>> it writes MailScanner in the pid file ) >>>> MailScanner >>>> >>>> Is this the way its supposed to be or ? I just noticed this today ... >>>> >>>> >>> Very likely not. >>> >>> I just verified that it does this on Mandriva with the rpm install >>> method (and hence likely on any rpm-based system, perhaps barring >>> SuSE...). >>> >>> Will have a look. >>> >>> Cheers >>> >> Looking at that init script... it just seems to be set there, never >> really used... Perhaps check_MailScanner uses it, will look further... >> Nope, not that I can easily grep/see at a cashual glance. So it should >> be safe... One can wonder what good it does, setting/managing at >> all:-). >> >> > The error seems to be only with how the .lint is implemented... Can't > promise any fix or anything (if Jules don't reappear:-), I've got a > lot on my plate today... > > Cheers > It doesn't do this on my RPM redhat installs. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Wed Aug 8 14:36:51 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 8 14:37:09 2007 Subject: FreeBSD and MailScanner --lint In-Reply-To: <46B9C4A5.8080200@syska.dk> References: <46B9B715.40007@syska.dk> <223f97700708080549p7d058bc7n4533088f484c8b0c@mail.gmail.com> <223f97700708080605w4f10e3a9w9d98adc6d7b2a341@mail.gmail.com> <223f97700708080617j1bc4dee7l6a4e93d7715ece76@mail.gmail.com> <46B9C4A5.8080200@syska.dk> Message-ID: <46B9C6F3.1090303@ecs.soton.ac.uk> Mikael Syska wrote: > Glenn Steen wrote: >> On 08/08/07, Glenn Steen wrote: >> >>> On 08/08/07, Glenn Steen wrote: >>> >>>> On 08/08/07, Mikael Syska wrote: >>>> >>>>> Hi, >>>>> >>>>> Dont knwo if this is intended to be so, but here goes .... >>>>> >>>>> root [/usr/local/etc/MailScanner]# /usr/local/etc/rc.d/mailscanner >>>>> restart >>>>> Stopping mailscanner. >>>>> Waiting for PIDS: 778, 778. >>>>> Starting mailscanner. >>>>> >>>>> root [/usr/local/etc/MailScanner]# cat /var/run/MailScanner.pid >>>>> 3229 >>>>> >>>>> Then running running, with MailScanner still running: >>>>> #MailScanner --lint >>>>> >>>>> Its overwriting: >>>>> root [/usr/local/etc/MailScanner]# cat /var/run/MailScanner.pid ( >>>>> yes, >>>>> it writes MailScanner in the pid file ) >>>>> MailScanner >>>>> >>>>> Is this the way its supposed to be or ? I just noticed this today ... >>>>> >>>>> >>>> Very likely not. >>>> >>>> I just verified that it does this on Mandriva with the rpm install >>>> method (and hence likely on any rpm-based system, perhaps barring >>>> SuSE...). >>>> >>>> Will have a look. >>>> >>>> Cheers >>>> >>> Looking at that init script... it just seems to be set there, never >>> really used... Perhaps check_MailScanner uses it, will look further... >>> Nope, not that I can easily grep/see at a cashual glance. So it should >>> be safe... One can wonder what good it does, setting/managing at >>> all:-). >>> >>> >> The error seems to be only with how the .lint is implemented... Can't >> promise any fix or anything (if Jules don't reappear:-), I've got a >> lot on my plate today... >> >> Cheers >> > Lets hope Jules seems this messeage and will fix it in a release in > the future ... just have to remember to stop MS before running --lint > or else there will be processes floating around. > > Its fine you hijacked my thread, as long as it helps MS to become bug > free and even better. Can anyone think up a good idea why I was writing a PID file in --lint? I can't think of one :-( I've commented it out for now. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From steinkel at pa.net Wed Aug 8 14:39:05 2007 From: steinkel at pa.net (Leland J. Steinke) Date: Wed Aug 8 14:39:11 2007 Subject: What's different with the new PDF only spams? In-Reply-To: <46B9C207.405@cnpapers.com> References: <46B9C207.405@cnpapers.com> Message-ID: <46B9C779.4050207@pa.net> Steve Campbell wrote: > > Now, the rule seem to be insufficient and is letting a lot of the newer > ones through. I'm not a RegEx expert, to be sure, so can any one offer a > suggestion for a rule to stop this new wave PDF-Only mailings, please? > If you are running SA3.2.2, you can jack up the score for GMD_PDF_EMPTY_BODY. There is also GMD_PDF_ENCRYPTED which is hitting on a number of the messages getting past the PDF_ONLY_SPAM rule. I upgraded from 3.1.7 last week, so I do not know when those rules were added. Leland From list-mailscanner at linguaphone.com Wed Aug 8 14:53:31 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 8 14:53:38 2007 Subject: logwatch In-Reply-To: References: <1186559528.5148.4.camel@gblades-suse.linguaphone-intranet.co.uk> <223f97700708080101x5091c807x8879632299f8b1be@mail.gmail.com> Message-ID: <1186581211.5155.32.camel@gblades-suse.linguaphone-intranet.co.uk> Ok I fixed the issue. If you want to do the same to your logwatch install save the attached file into /etc/logwatch/scripts/services (you might need to create the services directory) and then gunzip it. It will overide the default one so once logwatch has been updated you can simply delete it to start using the standard version again. On Wed, 2007-08-08 at 11:58, Hugo van der Kooij wrote: > On Wed, 8 Aug 2007, Glenn Steen wrote: > > > On 08/08/07, Gareth wrote: > >> Does Mailscanner install a plugin for Logwatch or is it just that > >> Logwatch supports Mailscanner by default? > > AFAIU the latter. > > > >> The new version of Mailscanner has a different ClamAV logging format > >> which is causing Logwatch not to recognise them. Any idea how I can fix > >> this? > > Since the latter -> take it up there;-). > > First off. Make sure you are running the latest logwatch version. Usually > the more common products are kept pretty much up-to-date. So it may just > be a case of an older logwatch version on your system. > > If the most recent version of logwatch does not match them then please > donate a log file to the logwatch developers mailinglist. > > Unfortunatly I have a few other pressing things to do first so I can not > test this myself right now. (I happen to do the occasional bit for > logwatch as well.) > > Hugo. > > -- > hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ > This message is using 100% recycled electrons. > > Some men see computers as they are and say "Windows" > I use computers with Linux and say "Why Windows?" > (Thanks JFK, for the insight.) -------------- next part -------------- A non-text attachment was scrubbed... Name: mailscanner.gz Type: application/x-gzip Size: 4431 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070808/dc3b609c/mailscanner.gz From joshua.hirsh at partnersolutions.ca Wed Aug 8 14:55:56 2007 From: joshua.hirsh at partnersolutions.ca (Joshua Hirsh) Date: Wed Aug 8 14:56:01 2007 Subject: ClamAV module logging changed in 4.62 In-Reply-To: <028c01c7d9bb$d8ec8740$0301a8c0@SAHOMELT> References: <46B70923.6040309@nerc.ac.uk><46B72B44.9090105@ecs.soton.ac.uk> <012401c7d859$adeeb620$0301a8c0@SAHOMELT><46B76E09.50401@ecs.soton.ac.uk><46B837E9.4020309@nerc.ac.uk> <028c01c7d9bb$d8ec8740$0301a8c0@SAHOMELT> Message-ID: <453468AFB48D2B4287F8F8197FD15F79A7FF@psims003.pshosting.intranet> > Ok I had a look this morning and the only reason I can see > would be having the display scanner name set to no. And > BTW, The Sohpos scanner name is hard coded so it would > display regardless. The setting in MailScanner.conf you > are looking for is: Include Scanner Name In Reports = and > it is probably set to no and should be set to yes. This value has always been set to yes on my server, but the ClamAV name stopped showing up anyways.. The bug is on line 1439 of SweepViruses.pm (in the ProcessClamAVModOutput subroutine). If you change this line: MailScanner::Log::InfoLog("$Name::%s", $logout); to this line: MailScanner::Log::InfoLog($Name . "::%s", $logout); The name will display properly in the logs. However, this may not be the "proper" fix, and it may still exist in other areas. In a quick test, it fixed it for me.. Cheers, -Joshua From R.Sterenborg at netsourcing.nl Wed Aug 8 14:56:20 2007 From: R.Sterenborg at netsourcing.nl (Rob Sterenborg) Date: Wed Aug 8 14:58:24 2007 Subject: What's different with the new PDF only spams? In-Reply-To: <46B9C207.405@cnpapers.com> References: <46B9C207.405@cnpapers.com> Message-ID: <74ACEB3E6A055643A89B8CEC74C7BF2488E115@WISENT.dcyb.net> mailscanner-bounces@lists.mailscanner.info wrote: > Seems like I just stopped seeing those PDF-Only spams using > the SA rule that was posted here a week or so back. > > Now, the rule seem to be insufficient and is letting a lot of > the newer ones through. I'm not a RegEx expert, to be sure, so > can any one offer a suggestion for a rule to stop this new > wave PDF-Only mailings, please? If you're usign ClamAV also, consider using the Sanesecurity sigs (and the automatic update script). They're doing a great job here. Grts, Rob From list-mailscanner at linguaphone.com Wed Aug 8 14:58:36 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 8 14:58:42 2007 Subject: ClamAV module logging changed in 4.62 In-Reply-To: <028c01c7d9bb$d8ec8740$0301a8c0@SAHOMELT> References: <46B70923.6040309@nerc.ac.uk><46B72B44.9090105@ecs.soton.ac.uk> <012401c7d859$adeeb620$0301a8c0@SAHOMELT><46B76E09.50401@ecs.soton.ac.uk> <46B837E9.4020309@nerc.ac.uk> <028c01c7d9bb$d8ec8740$0301a8c0@SAHOMELT> Message-ID: <1186581516.5158.41.camel@gblades-suse.linguaphone-intranet.co.uk> On Wed, 2007-08-08 at 13:58, Rick Cooper wrote: > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On > > Behalf Of Greg Matthews > > Sent: Tuesday, August 07, 2007 5:14 AM > > To: MailScanner discussion > > Subject: Re: ClamAV module logging changed in 4.62 > > > > Julian Field wrote: > > > -----BEGIN PGP SIGNED MESSAGE----- > > > Hash: SHA1 > > > > > > > > > > > > Rick Cooper wrote: > > >> Bear in mind that when clamd was added the name of the > > scanner is taked from > > >> the structure and not hard coded so if he has the display > > of virus scanners > > >> off there would be no name > > > > ok. but I dont understand, what is "the structure" if you mean my > > MailScanner.conf, then clamavmodule is explicitly specified. I'm not > > sure what you mean by having "the display of virus scanners > > off" either. > > My SophosSAVI still shows log lines like the following: > > > > Aug 6 08:29:20 mailr-w MailScanner[17999]: SophosSAVI::INFECTED:: > > Troj/Dloadr-BCP Troj/Dloadr-BCP:: ./l767T9Op023287/amazing.zip > > > > but the corresponding clamavmodule line for the same message is: > > > > Aug 6 08:29:21 mailr-w MailScanner[17999]: INFECTED:: > > Trojan.Downloader-12155:: ./l767T9Op023287/amazing.zip > > > [...] > > Ok I had a look this morning and the only reason I can see would be having > the display scanner name set to no. And BTW, The Sohpos scanner name is hard > coded so it would display regardless. The setting in MailScanner.conf you > are looking for is: Include Scanner Name In Reports = and it is probably > set to no and should be set to yes. > > As a side note, anyone using MailWatch will need this set to yes for the > next version as the name is used in his new parsing code (from the MailWatch > list) > > Rick I have encountered a problem with this aswell as it stopped logwatch from recognising the clamavmodule infections. I have tweaked logwatch to just look for INFECTED:: for now which works for me as I am just using clamavmodule and bitdefender. From rcooper at dwford.com Wed Aug 8 15:08:12 2007 From: rcooper at dwford.com (Rick Cooper) Date: Wed Aug 8 15:08:19 2007 Subject: ClamAV module logging changed in 4.62 In-Reply-To: <453468AFB48D2B4287F8F8197FD15F79A7FF@psims003.pshosting.intranet> References: <46B70923.6040309@nerc.ac.uk><46B72B44.9090105@ecs.soton.ac.uk> <012401c7d859$adeeb620$0301a8c0@SAHOMELT><46B76E09.50401@ecs.soton.ac.uk><46B837E9.4020309@nerc.ac.uk><028c01c7d9bb$d8ec8740$0301a8c0@SAHOMELT> <453468AFB48D2B4287F8F8197FD15F79A7FF@psims003.pshosting.intranet> Message-ID: <029f01c7d9c5$8ee9a510$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On > Behalf Of Joshua Hirsh > Sent: Wednesday, August 08, 2007 9:56 AM > To: MailScanner discussion > Subject: RE: ClamAV module logging changed in 4.62 > > > Ok I had a look this morning and the only reason I can see > > would be having the display scanner name set to no. And > > BTW, The Sohpos scanner name is hard coded so it would > > display regardless. The setting in MailScanner.conf you > > are looking for is: Include Scanner Name In Reports = and > > it is probably set to no and should be set to yes. > > > This value has always been set to yes on my server, but the > ClamAV name > stopped showing up anyways.. > > The bug is on line 1439 of SweepViruses.pm (in the > ProcessClamAVModOutput subroutine). If you change this line: > MailScanner::Log::InfoLog("$Name::%s", $logout); > to this line: > MailScanner::Log::InfoLog($Name . "::%s", $logout); > The name will display properly in the logs. However, this > may not be the > "proper" fix, and it may still exist in other areas. In a > quick test, it > fixed it for me.. > Julian I have to ask WTF? That should be functionally the same? In any case it would be more correct to use MailScanner::Log::InfoLog("%s::%s",$Name, $logout); Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Wed Aug 8 15:07:50 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 8 15:08:50 2007 Subject: ClamAV module logging changed in 4.62 In-Reply-To: <453468AFB48D2B4287F8F8197FD15F79A7FF@psims003.pshosting.intranet> References: <46B70923.6040309@nerc.ac.uk><46B72B44.9090105@ecs.soton.ac.uk> <012401c7d859$adeeb620$0301a8c0@SAHOMELT><46B76E09.50401@ecs.soton.ac.uk><46B837E9.4020309@nerc.ac.uk> <028c01c7d9bb$d8ec8740$0301a8c0@SAHOMELT> <453468AFB48D2B4287F8F8197FD15F79A7FF@psims003.pshosting.intranet> Message-ID: <46B9CE36.3050201@ecs.soton.ac.uk> Joshua Hirsh wrote: >> Ok I had a look this morning and the only reason I can see >> would be having the display scanner name set to no. And >> BTW, The Sohpos scanner name is hard coded so it would >> display regardless. The setting in MailScanner.conf you >> are looking for is: Include Scanner Name In Reports = and >> it is probably set to no and should be set to yes. >> > > > This value has always been set to yes on my server, but the ClamAV name > stopped showing up anyways.. > > The bug is on line 1439 of SweepViruses.pm (in the > ProcessClamAVModOutput subroutine). If you change this line: > MailScanner::Log::InfoLog("$Name::%s", $logout); > to this line: > MailScanner::Log::InfoLog($Name . "::%s", $logout); > The name will display properly in the logs. However, this may not be the > "proper" fix, and it may still exist in other areas. In a quick test, it > fixed it for me.. > It happens on line 1431 as well, same fix with do the trick. These fixes will be in the next release. Thanks for spotting them! Cheers, Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Wed Aug 8 15:14:17 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 8 15:14:31 2007 Subject: ClamAV module logging changed in 4.62 In-Reply-To: <029f01c7d9c5$8ee9a510$0301a8c0@SAHOMELT> References: <46B70923.6040309@nerc.ac.uk><46B72B44.9090105@ecs.soton.ac.uk> <012401c7d859$adeeb620$0301a8c0@SAHOMELT><46B76E09.50401@ecs.soton.ac.uk><46B837E9.4020309@nerc.ac.uk><028c01c7d9bb$d8ec8740$0301a8c0@SAHOMELT> <453468AFB48D2B4287F8F8197FD15F79A7FF@psims003.pshosting.intranet> <029f01c7d9c5$8ee9a510$0301a8c0@SAHOMELT> Message-ID: <46B9CFB9.1040607@ecs.soton.ac.uk> Rick Cooper wrote: > > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On > > Behalf Of Joshua Hirsh > > Sent: Wednesday, August 08, 2007 9:56 AM > > To: MailScanner discussion > > Subject: RE: ClamAV module logging changed in 4.62 > > > > > Ok I had a look this morning and the only reason I can see > > > would be having the display scanner name set to no. And > > > BTW, The Sohpos scanner name is hard coded so it would > > > display regardless. The setting in MailScanner.conf you > > > are looking for is: Include Scanner Name In Reports = and > > > it is probably set to no and should be set to yes. > > > > > > This value has always been set to yes on my server, but the > > ClamAV name > > stopped showing up anyways.. > > > > The bug is on line 1439 of SweepViruses.pm (in the > > ProcessClamAVModOutput subroutine). If you change this line: > > MailScanner::Log::InfoLog("$Name::%s", $logout); > > to this line: > > MailScanner::Log::InfoLog($Name . "::%s", $logout); > > The name will display properly in the logs. However, this > > may not be the > > "proper" fix, and it may still exist in other areas. In a > > quick test, it > > fixed it for me.. > > > > Julian I have to ask WTF? That should be functionally the same? > No. If it treats Name as the name of a package, then $Name::hello is the value of the variable "hello" within the package "Name". > In any case it would be more correct to use > MailScanner::Log::InfoLog("%s::%s",$Name, $logout); > It would indeed. I'll do that. > Rick > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From rcooper at dwford.com Wed Aug 8 15:19:47 2007 From: rcooper at dwford.com (Rick Cooper) Date: Wed Aug 8 15:19:52 2007 Subject: ClamAV module logging changed in 4.62 In-Reply-To: <46B9CFB9.1040607@ecs.soton.ac.uk> References: <46B70923.6040309@nerc.ac.uk><46B72B44.9090105@ecs.soton.ac.uk> <012401c7d859$adeeb620$0301a8c0@SAHOMELT><46B76E09.50401@ecs.soton.ac.uk><46B837E9.4020309@nerc.ac.uk><028c01c7d9bb$d8ec8740$0301a8c0@SAHOMELT> <453468AFB48D2B4287F8F8197FD15F79A7FF@psims003.pshosting.intranet><029f01c7d9c5$8ee9a510$0301a8c0@SAHOMELT> <46B9CFB9.1040607@ecs.soton.ac.uk> Message-ID: <02a001c7d9c7$2d84ddb0$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On > Behalf Of Julian Field > Sent: Wednesday, August 08, 2007 10:14 AM > To: MailScanner discussion > Subject: Re: ClamAV module logging changed in 4.62 > > > > Rick Cooper wrote: > > > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > > > [mailto:mailscanner-bounces@lists.mailscanner.info] On > > > Behalf Of Joshua Hirsh > > > Sent: Wednesday, August 08, 2007 9:56 AM > > > To: MailScanner discussion > > > Subject: RE: ClamAV module logging changed in 4.62 > > > > > > > Ok I had a look this morning and the only reason I can see > > > > would be having the display scanner name set to no. And > > > > BTW, The Sohpos scanner name is hard coded so it would > > > > display regardless. The setting in MailScanner.conf you > > > > are looking for is: Include Scanner Name In Reports = and > > > > it is probably set to no and should be set to yes. > > > > > > > > > This value has always been set to yes on my server, but the > > > ClamAV name > > > stopped showing up anyways.. > > > > > > The bug is on line 1439 of SweepViruses.pm (in the > > > ProcessClamAVModOutput subroutine). If you change this line: > > > MailScanner::Log::InfoLog("$Name::%s", $logout); > > > to this line: > > > MailScanner::Log::InfoLog($Name . "::%s", $logout); > > > The name will display properly in the logs. However, this > > > may not be the > > > "proper" fix, and it may still exist in other areas. In a > > > quick test, it > > > fixed it for me.. > > > > > > > Julian I have to ask WTF? That should be functionally the same? > > > No. If it treats Name as the name of a package, then > $Name::hello is the > value of the variable "hello" within the package "Name". > > In any case it would be more correct to use > > MailScanner::Log::InfoLog("%s::%s",$Name, $logout); > > > It would indeed. I'll do that. In the words of a wise and intelligent man with whom I apparently have much in common: DOH! Didn't even notice the xxx::format, if only I had set it as $Name :: %s eh? Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From gmatt at nerc.ac.uk Wed Aug 8 15:30:28 2007 From: gmatt at nerc.ac.uk (Greg Matthews) Date: Wed Aug 8 15:30:43 2007 Subject: ClamAV module logging changed in 4.62 In-Reply-To: <46B9CE36.3050201@ecs.soton.ac.uk> References: <46B70923.6040309@nerc.ac.uk><46B72B44.9090105@ecs.soton.ac.uk> <012401c7d859$adeeb620$0301a8c0@SAHOMELT><46B76E09.50401@ecs.soton.ac.uk><46B837E9.4020309@nerc.ac.uk> <028c01c7d9bb$d8ec8740$0301a8c0@SAHOMELT> <453468AFB48D2B4287F8F8197FD15F79A7FF@psims003.pshosting.intranet> <46B9CE36.3050201@ecs.soton.ac.uk> Message-ID: <46B9D384.2040805@nerc.ac.uk> Julian Field wrote: > It happens on line 1431 as well, same fix with do the trick. > These fixes will be in the next release. Thanks for spotting them! y'all beat me to it! tho my fix was "lower tech". I'll apply this fix to my SweepViruses.pm right now and abort the email I was slowly composing as I trawled through /usr/lib/MailScanner/MailScanner/... many thanks Jules and Rick. G > > Cheers, > > Jules > -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford -- This message (and any attachments) is for the recipient only. NERC is subject to the Freedom of Information Act 2000 and the contents of this email and any reply you make may be disclosed by NERC unless it is exempt from release under the Act. Any material supplied to NERC may be stored in an electronic records management system. From rcooper at dwford.com Wed Aug 8 15:58:27 2007 From: rcooper at dwford.com (Rick Cooper) Date: Wed Aug 8 15:58:34 2007 Subject: ClamAV module logging changed in 4.62 In-Reply-To: <46B9D384.2040805@nerc.ac.uk> References: <46B70923.6040309@nerc.ac.uk><46B72B44.9090105@ecs.soton.ac.uk> <012401c7d859$adeeb620$0301a8c0@SAHOMELT><46B76E09.50401@ecs.soton.ac.uk><46B837E9.4020309@nerc.ac.uk> <028c01c7d9bb$d8ec8740$0301a8c0@SAHOMELT> <453468AFB48D2B4287F8F8197FD15F79A7FF@psims003.pshosting.intranet><46B9CE36.3050201@ecs.soton.ac.uk> <46B9D384.2040805@nerc.ac.uk> Message-ID: <02b001c7d9cc$952823a0$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On > Behalf Of Greg Matthews > Sent: Wednesday, August 08, 2007 10:30 AM > To: MailScanner discussion > Subject: Re: ClamAV module logging changed in 4.62 > > Julian Field wrote: > > It happens on line 1431 as well, same fix with do the trick. > > These fixes will be in the next release. Thanks for spotting them! > > y'all beat me to it! tho my fix was "lower tech". I'll apply > this fix to > my SweepViruses.pm right now and abort the email I was > slowly composing > as I trawled through /usr/lib/MailScanner/MailScanner/... > > many thanks Jules and Rick. > No thanks to me, remember I am Homer in this episode... Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From hmkash at arl.army.mil Wed Aug 8 16:33:26 2007 From: hmkash at arl.army.mil (Kash, Howard (Civ, ARL/CISD)) Date: Wed Aug 8 16:31:29 2007 Subject: RedHat up2date conflicts (UNCLASSIFIED) Message-ID: <88991ECEE371C644986F0C8837C207B70173B34D@ARLABML01.DS.ARL.ARMY.MIL> Classification: UNCLASSIFIED Caveats: NONE I just noticed that up2date was failing on my RHEL4 systems due to conflicts between perl-5.8.5-36.RHEL4 and perl-MIME-Base64-3.07-1 (and possibly bignum, BigInt, and BigRat) distributed with 4.62.9. Also, "MailScanner --version" was still showing MIME::Base64 at version 3.05 due to the MailScanner-perl-MIME-Base64-3.05-5 RPM being installed from previous MailScanner releases. I installed MIME-Base64-3.07, bignum-0.22, Math-BigInt-1.87, and Math-BigRat-0.20 from CPAN and removed the installed RPMs as well as MailScanner-perl-MIME-Base64-3.05-5 and up2date is again happy. MailScanner --version also shows MIME::Base64 at version 3.07 now. Howard Classification: UNCLASSIFIED Caveats: NONE -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070808/a96086fb/attachment.html From mailadmin at baladia.gov.kw Wed Aug 8 18:16:36 2007 From: mailadmin at baladia.gov.kw (mailadmin@baladia.gov.kw) Date: Wed Aug 8 18:20:18 2007 Subject: cron daemon error Message-ID: <3365.62.150.152.226.1186593396.squirrel@webmail.baladia.gov.kw> Dear All, I have MailSacnner + jules SA+CLAMAV script installed and its workin fine on Centos but i see this error in root mail /etc/cron.hourly/update_virus_scanners: /usr/sbin/update_virus_scanners: line 39: /usr/lib/MailScanner/clamd-wrapper: No such file or directory and when i check in /usr/lib/MailScanner/ the file is not there clamd-wrapper apprecite your help Regards simon -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Wed Aug 8 18:36:17 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 8 18:37:01 2007 Subject: cron daemon error In-Reply-To: <3365.62.150.152.226.1186593396.squirrel@webmail.baladia.gov.kw> References: <3365.62.150.152.226.1186593396.squirrel@webmail.baladia.gov.kw> Message-ID: <46B9FF11.50208@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Look in your /etc/MailScanner/virus.scanners.conf file. The entry for clamd should say this: clamd /bin/false /usr/local if you have ClamAV installed in /usr/local/ or clamd /bin/false /usr if you have ClamAV installed in /usr/bin. To find out, type "which clamscan" and and if finds it in /usr/local/bin then ClamAV is installed in /usr/local. If it finds it in /usr/bin then ClamAV is installed in /usr. That should do the trick for you. In virus.scanners.conf, the only bit you should edit is the bit at the right-hand end of each line, don't change the others. mailadmin@baladia.gov.kw wrote: > Dear All, > > I have MailSacnner + jules SA+CLAMAV script installed and its workin fine > on Centos but i see this error in root mail > > /etc/cron.hourly/update_virus_scanners: > > /usr/sbin/update_virus_scanners: line 39: > /usr/lib/MailScanner/clamd-wrapper: No such file or directory > > and when i check in /usr/lib/MailScanner/ > the file is not there clamd-wrapper > > apprecite your help > > Regards > > > simon > > > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGuf8SEfZZRxQVtlQRAuhRAKD6cjPrijUghhJoQ375A/+l7dtdowCdFHJm iudIW23BHwUAKg7HTgBNAPI= =oZyx -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From root at doctor.nl2k.ab.ca Wed Aug 8 18:47:20 2007 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Wed Aug 8 18:48:21 2007 Subject: ClamAV module logging changed in 4.62 In-Reply-To: <02b001c7d9cc$952823a0$0301a8c0@SAHOMELT> References: <028c01c7d9bb$d8ec8740$0301a8c0@SAHOMELT> <46B9D384.2040805@nerc.ac.uk> <02b001c7d9cc$952823a0$0301a8c0@SAHOMELT> Message-ID: <20070808174720.GC2071@doctor.nl2k.ab.ca> On Wed, Aug 08, 2007 at 10:58:27AM -0400, Rick Cooper wrote: > > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On > > Behalf Of Greg Matthews > > Sent: Wednesday, August 08, 2007 10:30 AM > > To: MailScanner discussion > > Subject: Re: ClamAV module logging changed in 4.62 > > > > Julian Field wrote: > > > It happens on line 1431 as well, same fix with do the trick. > > > These fixes will be in the next release. Thanks for spotting them! > > > > y'all beat me to it! tho my fix was "lower tech". I'll apply > > this fix to > > my SweepViruses.pm right now and abort the email I was > > slowly composing > > as I trawled through /usr/lib/MailScanner/MailScanner/... > > > > many thanks Jules and Rick. > > > > No thanks to me, remember I am Homer in this episode... > Talk about self inflicted insults. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ajcartmell at fonant.com Wed Aug 8 19:14:26 2007 From: ajcartmell at fonant.com (Anthony Cartmell) Date: Wed Aug 8 19:14:48 2007 Subject: cron daemon error In-Reply-To: <46B9FF11.50208@ecs.soton.ac.uk> References: <3365.62.150.152.226.1186593396.squirrel@webmail.baladia.gov.kw> <46B9FF11.50208@ecs.soton.ac.uk> Message-ID: >> /usr/sbin/update_virus_scanners: line 39: >> /usr/lib/MailScanner/clamd-wrapper: No such file or directory >> >> and when i check in /usr/lib/MailScanner/ >> the file is not there clamd-wrapper I get this too, and /usr/lib/MailScanner/clamd-wrapper doesn't exist (but clamav-wrapper is there) in my installation either. I think it's the missing file, rather than the incorrect path, that is the problem. There is a clamd-wrapper in my backup taken on 22 June 2007, so I've copied that across for now. Anthony -- www.fonant.com - Quality web sites From MailScanner at ecs.soton.ac.uk Wed Aug 8 19:22:23 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 8 19:22:56 2007 Subject: cron daemon error In-Reply-To: References: <3365.62.150.152.226.1186593396.squirrel@webmail.baladia.gov.kw> <46B9FF11.50208@ecs.soton.ac.uk> Message-ID: <46BA09DF.8040801@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Anthony Cartmell wrote: >>> /usr/sbin/update_virus_scanners: line 39: >>> /usr/lib/MailScanner/clamd-wrapper: No such file or directory >>> >>> and when i check in /usr/lib/MailScanner/ >>> the file is not there clamd-wrapper > > I get this too, and /usr/lib/MailScanner/clamd-wrapper doesn't exist > (but clamav-wrapper is there) in my installation either. I think it's > the missing file, rather than the incorrect path, that is the problem. > > There is a clamd-wrapper in my backup taken on 22 June 2007, so I've > copied that across for now. If you look in that directory, you may find a virus.scanners.conf.rpmnew which should be copied over virus.scanners.conf (and then checked to ensure the paths are right for your virus scanners. There is no "missing file". Clamd-wrapper only existed in 1 version, I optimised it out of existence. You shouldn't copy it back and use it, your system will run slower as you'll be scanning everything twice with clamd. Replace the clamd-wrapper entry with /bin/false. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: UTF-8 wj8DBQFGugngEfZZRxQVtlQRAq96AKDjWTtl1w963D7POXF66qA3Fz8jnACgp/LW pF7Uv1+e3Bn4KuolYehBllw= =7QRV -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Wed Aug 8 19:52:02 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Aug 8 19:52:19 2007 Subject: DSN and 4.62.9 problem In-Reply-To: <46B8F776.90500@ecs.soton.ac.uk> References: <46B8F776.90500@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 8/7/2007 3:51 PM: > > > Scott Silva wrote: >> Ren? Berber spake the following on 8/6/2007 11:39 AM: > >>> Hi, >>> >>> Similar problem to that reported for OoO and watermarking, read receipts (DSN) >>> messages do not return the watermark header and MailScanner is tagging all of >>> them as spam with the log showing: >>> >>> MailScanner[2081]: Message l76HJGJu004811 from ... has no (or invalid) >>> NULL-Header or sender address >>> >>> This wasn't the case with the previous version used (4.62.7), I'm testing now >>> with watermarking off. Any other solutions? >>> >> I had to turn off watermarking also because of the read receipts. It was also >> marking stuff that should have been whitelisted (internal to internal). > > Should I leave it switched off by default? > What are people's opinion on this? > > P.S. Check out the new feature in 4.63, it's in the Change Log at > http://www.mailscanner.info/ChangeLog > You might find it useful. > > > Jules > I say leave it off, because it is a more advanced configuration option, and you used to set the defaults to a sensible set that would make a running system "just work" after an install. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From bernard.lheureux at bbsoft4.org Wed Aug 8 20:21:32 2007 From: bernard.lheureux at bbsoft4.org (Bernard Lheureux) Date: Wed Aug 8 20:21:50 2007 Subject: Not blocking fileattach type from a certain adress Message-ID: <1186600892.3826.1.camel@localhost.localdomain> I was wondering if it was possible to leave the common file-type/filenames blocked but allowing certain of those filetype pass through if they come from a particular address... If it is possible, could you tell me how to do it ? Thank you for your help and for this SPLENDID product that makes Mail server management a piece of joy ! M$-Internet Exploder est le cancer de l'Internet, voyez pourquoi ici : --> http://www.decroissance.info/Ateliers-Liberez-votre-ordinateur <-- Et plus vous ?viterez les produits Micro$oft, plus libres vous serez : -------------> http://libre-fan.apinc.org/article21.html <------------ -- (?- Bernard Lheureux Gestionnaire des MailingLists ML, TechML, LinuxML //\ http://www.bbsoft4.org/Mailinglists.htm ** MailTo:root@bbsoft4.org v_/_ http://www.bbsoft4.org/ <<<<<< * >>>>>> http://www.portalinux.org/ From MailScanner at ecs.soton.ac.uk Wed Aug 8 20:36:41 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 8 20:37:14 2007 Subject: Not blocking fileattach type from a certain adress In-Reply-To: <1186600892.3826.1.camel@localhost.localdomain> References: <1186600892.3826.1.camel@localhost.localdomain> Message-ID: <46BA1B49.6050303@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 This has been discussed countless times on this list. Look in the archives for filename.rules.conf or filetype.rules.conf. You basically set up a little ruleset which chooses between different filename.rules.conf files for different users. Then choose what you want in the different filename.rules.conf files. It's documented in the wiki and the book as well. Bernard Lheureux wrote: > I was wondering if it was possible to leave the common > file-type/filenames blocked but allowing certain of those filetype pass > through if they come from a particular address... > If it is possible, could you tell me how to do it ? > Thank you for your help and for this SPLENDID product that makes > Mail server management a piece of joy ! > > > M$-Internet Exploder est le cancer de l'Internet, voyez pourquoi ici : > --> http://www.decroissance.info/Ateliers-Liberez-votre-ordinateur <-- > Et plus vous ?viterez les produits Micro$oft, plus libres vous serez : > -------------> http://libre-fan.apinc.org/article21.html <------------ > > -- > (?- Bernard Lheureux Gestionnaire des MailingLists ML, TechML, LinuxML > //\ http://www.bbsoft4.org/Mailinglists.htm ** MailTo:root@bbsoft4.org > v_/_ http://www.bbsoft4.org/ <<<<<< * >>>>>> http://www.portalinux.org/ > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-15 wj8DBQFGuhtLEfZZRxQVtlQRAv2cAKCA2dUJ8j4Zid4zsKc+jUNjcW7UXwCfQk5C XrWE27JrNLRnI8V4GfkH9IY= =2VKK -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From asakawa at quickd.net Wed Aug 8 20:48:12 2007 From: asakawa at quickd.net (Takashi Asakawa) Date: Wed Aug 8 20:48:57 2007 Subject: Failed to get CRM114-Status In-Reply-To: <223f97700708071434v353646b4r7573f1970baa56fa@mail.gmail.com> References: <20070808044706.E68A.ASAKAWA@quickd.net> <223f97700708071434v353646b4r7573f1970baa56fa@mail.gmail.com> Message-ID: <20070809044619.9B1B.ASAKAWA@quickd.net> Thank you for advice. I want to report as soon as details are understood > spamd is most certainly not a part of MailScanner, nor needed by it. > Simply turn it off. > > More interesting is if you get something similar from a spamassassin > lint or in the logs produced by MailScanner ... I would rather think > not, since I suspect the reason that spamd is having trouble is due to > permission issues ... But I can't be sure, since I don't use it;) From asakawa at quickd.net Wed Aug 8 20:53:47 2007 From: asakawa at quickd.net (Takashi Asakawa) Date: Wed Aug 8 20:54:23 2007 Subject: logwatch In-Reply-To: <1186581211.5155.32.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1186581211.5155.32.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <20070809045014.9B1D.ASAKAWA@quickd.net> I don't think that there is a bug like it though the here latest is used http://www2.cvs.logwatch.org:81/index.cgi/logwatch/scripts/services/mailscanner?sortby=date > Ok I fixed the issue. If you want to do the same to your logwatch > install save the attached file into /etc/logwatch/scripts/services (you > might need to create the services directory) and then gunzip it. > It will overide the default one so once logwatch has been updated you > can simply delete it to start using the standard version again. Takashi From ajcartmell at fonant.com Wed Aug 8 21:38:29 2007 From: ajcartmell at fonant.com (Anthony Cartmell) Date: Wed Aug 8 21:38:35 2007 Subject: cron daemon error In-Reply-To: <46BA09DF.8040801@ecs.soton.ac.uk> References: <3365.62.150.152.226.1186593396.squirrel@webmail.baladia.gov.kw> <46B9FF11.50208@ecs.soton.ac.uk> <46BA09DF.8040801@ecs.soton.ac.uk> Message-ID: >> I get this too, and /usr/lib/MailScanner/clamd-wrapper doesn't exist >> (but clamav-wrapper is there) in my installation either. I think it's >> the missing file, rather than the incorrect path, that is the problem. >> >> There is a clamd-wrapper in my backup taken on 22 June 2007, so I've >> copied that across for now. > If you look in that directory, you may find a virus.scanners.conf.rpmnew > which should be copied over virus.scanners.conf (and then checked to > ensure the paths are right for your virus scanners. Aha, that explains things. I'd better check the other .rpmnew files too... Cheers! Anthony -- www.fonant.com - Quality web sites From hvdkooij at vanderkooij.org Thu Aug 9 00:58:18 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Thu Aug 9 00:58:30 2007 Subject: FreeBSD and MailScanner --lint In-Reply-To: <46B9C6F3.1090303@ecs.soton.ac.uk> References: <46B9B715.40007@syska.dk> <223f97700708080549p7d058bc7n4533088f484c8b0c@mail.gmail.com> <223f97700708080605w4f10e3a9w9d98adc6d7b2a341@mail.gmail.com> <223f97700708080617j1bc4dee7l6a4e93d7715ece76@mail.gmail.com> <46B9C4A5.8080200@syska.dk> <46B9C6F3.1090303@ecs.soton.ac.uk> Message-ID: On Wed, 8 Aug 2007, Julian Field wrote: > Can anyone think up a good idea why I was writing a PID file in --lint? > I can't think of one :-( The positive version would that you were under just plain drunk. Some might considere that the negative version. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From seamus at rheelweb.co.nz Thu Aug 9 02:03:46 2007 From: seamus at rheelweb.co.nz (Seamus Allan) Date: Thu Aug 9 02:04:02 2007 Subject: Watermarking quirks still in 4.62.8 In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA013584C5@HC-MBX02.herefordshire.gov.uk> References: <7EF0EE5CB3B263488C8C18823239BEBA013584B1@HC-MBX02.herefordshire.gov.uk> <46ADDBBA.3080701@coders.co.uk> <7EF0EE5CB3B263488C8C18823239BEBA013584C5@HC-MBX02.herefordshire.gov.uk> Message-ID: <46BA67F2.1070005@rheelweb.co.nz> Randal, Phil wrote: > Oops, my bad. > > Double-checked and can't reproduce the bounce problem. > > Note to myself: Make sure all MailScanner boxes are configured > identically! > > An internal user sends an email to the ouside world requesting a > read-receipt. > > Recipient's Outlook generates a read-receipt which gets blocked by > MailScanner. > > The orginal email's headers are not included in the receipt message, so > there is no watermark to check. > > Sanitised read receipt below: > > Subject: Read: xxxxx > Date: Mon, 30 Jul 2007 12:54:18 +0100 > MIME-Version: 1.0 > Content-Type: multipart/report; > boundary="----=_NextPart_000_0025_01C7D2A8.BE212390"; > report-type=disposition-notification > X-Mailer: Microsoft Office Outlook, Build 11.0.6353 > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3138 > Thread-Index: AcfKzQ0n7j/g6jVpSo6RfWZRbz2L0gDFrJygACqgSvABBFFGYAAAL41L > In-Reply-To: AAAAALxmnSrmiFpFjRWg8ttEtPck1iMA > Message-Id: <20070730115101.368B748B8A@raq2.kc3.net> > X-Virus-Scanned: by amavisd-new at localhost > X-Greylist: Default is to whitelist mail, not delayed by > milter-greylist-3.0 (mx0.herefordshire.gov.uk [172.29.97.109]); Mon, 30 > Jul 2007 12:54:35 +0100 (BST) > > This is a multi-part message in MIME format. > > ------=_NextPart_000_0025_01C7D2A8.BE212390 > Content-Type: multipart/alternative; > boundary="----=_NextPart_001_0026_01C7D2A8.BE212390" > > > ------=_NextPart_001_0026_01C7D2A8.BE212390 > Content-Type: text/plain; > charset="iso-8859-1" > Content-Transfer-Encoding: 7bit > > Your message > > To: someone@out.there > Subject: FW: xxxxxx > Sent: 30/07/2007 12:50 > > was read on 30/07/2007 12:53. > > ------=_NextPart_001_0026_01C7D2A8.BE212390 > Content-Type: text/html; > charset="iso-8859-1" > Content-Transfer-Encoding: quoted-printable > > > > > charset=3DWindows-1252"> > 6.5.7036.0"> > Read: Heritage Open Days > > > > >

Your message
>
>     To:  someone@out.there
>     Subject:  FW: xxxxxxxx
>     Sent:  30/07/2007 12:50
>
> was read on 30/07/2007 12:53.
>

> > > > ------=_NextPart_001_0026_01C7D2A8.BE212390-- > > ------=_NextPart_000_0025_01C7D2A8.BE212390 > Content-Type: message/disposition-notification > Content-Transfer-Encoding: 7bit > > Reporting-UA: D71QML1J; Microsoft Office Outlook, Build 11.0.6353 > Final-Recipient: rfc822;someone@out.there > Original-Message-ID: AAAAALxmnSrmiFpFjRWg8ttEtPck1iMA > Disposition: manual-action/MDN-sent-automatically; displayed > > ------=_NextPart_000_0025_01C7D2A8.BE212390-- > > > Cheers, > > Phil > -- > Phil Randal > Network Engineer > Herefordshire Council > Hereford, UK > > > I too, am having this issue. In the interim I have disabled watermarks, as we have a couple of clients who require Read Receipts. Have you found a resolution Phil? Cheers Seamus -- *Seamus Allan* Network Engineer Rheel Electronics Ltd From mailscanner at home.carlo65.de Thu Aug 9 05:50:06 2007 From: mailscanner at home.carlo65.de (R. Ehle (MailScanner Mailinglist)) Date: Thu Aug 9 05:50:25 2007 Subject: ClamAV: Zip module failure Message-ID: <4D1CD0994309F84BA83DF998BF0075AF4328E191@ts-dc2.TS-Webarts.local> Hi, just as a hint: ClamAV sometimes seems to have a problem with scanning PDF type documents. I found several entries in my maillog like the following: Aug 8 12:53:24 s15221293 MailScanner[20045]: ERROR:: Zip module failure ERROR :: ./l78AoC4k017231/PRESSETEXTE PI_XOUNTS-AG.PDF The messages had been delivered, as far as I found out and the problem already existed in ClamAV version 0.90. @Julian: Does MailScanner ignore these errors? If not, is it possible to have a setting like Allowed Clam Error Messages? Regards, Roland ---------------------------------------------------------- Diese Nachricht wurde von mailMind(R) auf Viren und andere gefaehrliche Inhalte untersucht und ist sauber. --- mailMind(R) - we have your Mailsecurity in mind! http://www.mailmind.de --- -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070809/1699dce0/attachment.html From glenn.steen at gmail.com Thu Aug 9 08:41:07 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu Aug 9 08:41:09 2007 Subject: FreeBSD and MailScanner --lint In-Reply-To: References: <46B9B715.40007@syska.dk> <223f97700708080549p7d058bc7n4533088f484c8b0c@mail.gmail.com> <223f97700708080605w4f10e3a9w9d98adc6d7b2a341@mail.gmail.com> <223f97700708080617j1bc4dee7l6a4e93d7715ece76@mail.gmail.com> <46B9C4A5.8080200@syska.dk> <46B9C6F3.1090303@ecs.soton.ac.uk> Message-ID: <223f97700708090041r6baf018fvd14958fdd6860710@mail.gmail.com> On 09/08/07, Hugo van der Kooij wrote: > On Wed, 8 Aug 2007, Julian Field wrote: > > > Can anyone think up a good idea why I was writing a PID file in --lint? > > I can't think of one :-( > > The positive version would that you were under just plain drunk. Some > might considere that the negative version. > > Hugo. > Nice exokanation Hugo, but... Might this not have been to avoid some pif-file check ... Preventing the lint to run if MS wasn't running? ISTR something along those lines... way back. Might be remembering wrong though:) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Thu Aug 9 08:42:50 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu Aug 9 08:42:52 2007 Subject: FreeBSD and MailScanner --lint In-Reply-To: <223f97700708090041r6baf018fvd14958fdd6860710@mail.gmail.com> References: <46B9B715.40007@syska.dk> <223f97700708080549p7d058bc7n4533088f484c8b0c@mail.gmail.com> <223f97700708080605w4f10e3a9w9d98adc6d7b2a341@mail.gmail.com> <223f97700708080617j1bc4dee7l6a4e93d7715ece76@mail.gmail.com> <46B9C4A5.8080200@syska.dk> <46B9C6F3.1090303@ecs.soton.ac.uk> <223f97700708090041r6baf018fvd14958fdd6860710@mail.gmail.com> Message-ID: <223f97700708090042j4b5bbdf8o4ee1299aa71207c5@mail.gmail.com> On 09/08/07, Glenn Steen wrote: > On 09/08/07, Hugo van der Kooij wrote: > > On Wed, 8 Aug 2007, Julian Field wrote: > > > > > Can anyone think up a good idea why I was writing a PID file in --lint? > > > I can't think of one :-( > > > > The positive version would that you were under just plain drunk. Some > > might considere that the negative version. > > > > Hugo. > > > Nice exokanation Hugo, but... Might this not have been to avoid some Fat finger of monumetal proportion there... exokanation -> explanation...;) (Yes, I'm a self-replying postmixer... And proud of it!:-) > pif-file check ... Preventing the lint to run if MS wasn't running? > ISTR something along those lines... way back. Might be remembering > wrong though:) > > Cheers > -- Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From martinh at solidstatelogic.com Thu Aug 9 08:48:46 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Thu Aug 9 08:48:53 2007 Subject: Not blocking fileattach type from a certain adress In-Reply-To: <1186600892.3826.1.camel@localhost.localdomain> Message-ID: <9f19e475c598ef4baa84c479c0d9185c@solidstatelogic.com> Bernard There's a little more on this in wiki.. http://wiki.mailscanner.info/doku.php?id=documentation:configuration:rulesets:overloading -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Bernard Lheureux > Sent: 08 August 2007 20:22 > To: MailingList MailScanner > Subject: Not blocking fileattach type from a certain adress > > I was wondering if it was possible to leave the common > file-type/filenames blocked but allowing certain of those filetype pass > through if they come from a particular address... > If it is possible, could you tell me how to do it ? > Thank you for your help and for this SPLENDID product that makes > Mail server management a piece of joy ! > > > M$-Internet Exploder est le cancer de l'Internet, voyez pourquoi ici : > --> http://www.decroissance.info/Ateliers-Liberez-votre-ordinateur <-- > Et plus vous ?viterez les produits Micro$oft, plus libres vous serez : > -------------> http://libre-fan.apinc.org/article21.html <------------ > > -- > (?- Bernard Lheureux Gestionnaire des MailingLists ML, TechML, LinuxML > //\ http://www.bbsoft4.org/Mailinglists.htm ** MailTo:root@bbsoft4.org > v_/_ http://www.bbsoft4.org/ <<<<<< * >>>>>> http://www.portalinux.org/ > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From daniel at bokko.nl Thu Aug 9 11:30:02 2007 From: daniel at bokko.nl (Daniel Eiland) Date: Thu Aug 9 11:42:32 2007 Subject: MCP not working Message-ID: <2f018d4f4bf70e5feeeddba4bc9383fa@localhost> Hello, I hope someone can help me out. I have a question regarding MCP. It works, but rules never match. I am running MailScanner 4.61.7 on FreeBSD. Everything works fine except for MCP. In my maillog i can see MCP is enabled and is scanning: Aug 9 12:10:55 panther MailScanner[44602]: New Batch: Found 3 messages waiting Aug 9 12:10:55 panther MailScanner[44602]: New Batch: Scanning 1 messages, 9602 bytes Aug 9 12:10:55 panther MailScanner[44602]: MCP Checks: Starting Aug 9 12:10:57 panther MailScanner[44602]: MCP Checks completed at 8542 bytes per second Aug 9 12:10:57 panther MailScanner[44602]: Spam Checks: Starting Aug 9 12:10:57 panther MailScanner[44620]: Virus Scanning completed at 2586 bytes per second Aug 9 12:10:57 panther MailScanner[44620]: Requeue: F134C11713.526DA to D4F5A119A2 Aug 9 12:10:57 panther MailScanner[44620]: Uninfected: Delivered 1 messages Aug 9 12:10:57 panther MailScanner[44620]: Virus Processing completed at 319425 bytes per second Aug 9 12:10:57 panther MailScanner[44620]: Batch completed at 630 bytes per second (6453 / 10) Aug 9 12:10:57 panther MailScanner[44620]: Batch (1 message) processed in 10.24 seconds I defined af cf file named 10_w32_zhelatin_gen.cf that is located in %mcp-dir% for catching email with specific subjects. The subjects i want to catch are in the form of: You've received a greeting card from a friend! header MCP_W32_ZHELATIN_GEN Subject =~ /received a greeting card from a/i describe MCP_W32_ZHELATIN_GEN Banned Subject score MCP_W32_ZHELATIN_GEN 10 header MCP_W32_ZHELATIN_GEN Subject =~ /received a greeting ecard from a/i describe MCP_W32_ZHELATIN_GEN Banned Subject score MCP_W32_ZHELATIN_GEN 10 header MCP_W32_ZHELATIN_GEN Subject =~ /received a greeting postcard from a/i describe MCP_W32_ZHELATIN_GEN Banned Subject score MCP_W32_ZHELATIN_GEN 10 header MCP_W32_ZHELATIN_GEN Subject =~ /received a postcard from a/i describe MCP_W32_ZHELATIN_GEN Banned Subject score MCP_W32_ZHELATIN_GEN 10 header MCP_W32_ZHELATIN_GEN Subject =~ /received an ecard from a/i describe MCP_W32_ZHELATIN_GEN Banned Subject score MCP_W32_ZHELATIN_GEN 10 My MCP config in MailScanner.conf is: %mcp-dir% = /usr/local/etc/MailScanner/mcp MCP Checks = yes First Check = mcp MCP Required SpamAssassin Score = 1 MCP High SpamAssassin Score = 10 MCP Error Score = 1 MCP Header = X-%org-name%-MailScanner-MCPCheck: Non MCP Actions = deliver MCP Actions = %rules-dir%/spam.actions.rules High Scoring MCP Actions = %rules-dir%/spam.actions.rules Bounce MCP As Attachment = no MCP Modify Subject = yes MCP Subject Text = {Evil?} High Scoring MCP Modify Subject = yes High Scoring MCP Subject Text = {Evil?} Is Definitely MCP = %rules-dir%/spam.blacklist.rules Is Definitely Not MCP = %rules-dir%/spam.whitelist.rules Definite MCP Is High Scoring = no Always Include MCP Report = yes Detailed MCP Report = yes Include Scores In MCP Report = yes Log MCP = yes MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf MCP SpamAssassin User State Dir = MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin Default Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = %mcp-dir% Recipient MCP Report = %report-dir%/recipient.mcp.report.txt Sender MCP Report = %report-dir%/sender.mcp.report.txt In my email these are the headers: Subject: You've received an ecard from a Class-mate! Message-Id: <20070809093143.DFAD711920@panther> Date: Thu, 9 Aug 2007 11:31:39 +0200 (CEST) From: bla@bla.com To: undisclosed-recipients:; X-Panther-MailScanner-Information: Please contact ISP for more information X-Panther-MailScanner: Found to be clean X-Panther-MailScanner-MCPCheck: MCP-Clean, MCP-Checker (score=0, required 1) X-Panther-MailScanner-SpamCheck: not spam, SpamAssassin (score=0, required 5) X-Panther-MailScanner-From: bla@bla.com X-Spam-Status: No, No X-MailScanner: Found to be clean X-MailScanner-SpamCheck: not spam, SpamAssassin (not cached, score=1.618, required 5, BAYES_40 -0.18, DK_POLICY_SIGNSOME 0.00, NO_REAL_NAME 0.96, UNDISC_RECIPS 0.84) X-MailScanner-SpamScore: 1 -- :wq! From uxbod at splatnix.net Thu Aug 9 12:58:22 2007 From: uxbod at splatnix.net (UxBoD) Date: Thu Aug 9 12:50:22 2007 Subject: MCP not working In-Reply-To: <2f018d4f4bf70e5feeeddba4bc9383fa@localhost> Message-ID: <2439085.13841186660702158.JavaMail.root@office.splatnix.net> You are redefining your rule each time. try :- header __MCP_W32_ZHELATIN_GEN1 Subject =~ /received a greeting (card|ecard|postcard) from a/i header __MCP_W32_ZHELATIN_GEN2 Subject =~ /received a postcard from a/i header __MCP_W32_ZHELATIN_GEN3 Subject =~ /received an ecard from a/i meta MCP_W32_ZHELATIN_GEN __MCP_W32_ZHELATIN_GEN1 || __MCP_W32_ZHELATIN_GEN2 || __MCP_W32_ZHELATIN_GEN3 describe MCP_W32_ZHELATIN_GEN Banned Subject score MCP_W32_ZHELATIN_GEN 10 Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Daniel Eiland" To: mailscanner@lists.mailscanner.info Sent: Thursday, August 9, 2007 11:30:02 AM (GMT) Europe/London Subject: MCP not working Hello, I hope someone can help me out. I have a question regarding MCP. It works, but rules never match. I am running MailScanner 4.61.7 on FreeBSD. Everything works fine except for MCP. In my maillog i can see MCP is enabled and is scanning: Aug 9 12:10:55 panther MailScanner[44602]: New Batch: Found 3 messages waiting Aug 9 12:10:55 panther MailScanner[44602]: New Batch: Scanning 1 messages, 9602 bytes Aug 9 12:10:55 panther MailScanner[44602]: MCP Checks: Starting Aug 9 12:10:57 panther MailScanner[44602]: MCP Checks completed at 8542 bytes per second Aug 9 12:10:57 panther MailScanner[44602]: Spam Checks: Starting Aug 9 12:10:57 panther MailScanner[44620]: Virus Scanning completed at 2586 bytes per second Aug 9 12:10:57 panther MailScanner[44620]: Requeue: F134C11713.526DA to D4F5A119A2 Aug 9 12:10:57 panther MailScanner[44620]: Uninfected: Delivered 1 messages Aug 9 12:10:57 panther MailScanner[44620]: Virus Processing completed at 319425 bytes per second Aug 9 12:10:57 panther MailScanner[44620]: Batch completed at 630 bytes per second (6453 / 10) Aug 9 12:10:57 panther MailScanner[44620]: Batch (1 message) processed in 10.24 seconds I defined af cf file named 10_w32_zhelatin_gen.cf that is located in %mcp-dir% for catching email with specific subjects. The subjects i want to catch are in the form of: You've received a greeting card from a friend! header MCP_W32_ZHELATIN_GEN Subject =~ /received a greeting card from a/i describe MCP_W32_ZHELATIN_GEN Banned Subject score MCP_W32_ZHELATIN_GEN 10 header MCP_W32_ZHELATIN_GEN Subject =~ /received a greeting ecard from a/i describe MCP_W32_ZHELATIN_GEN Banned Subject score MCP_W32_ZHELATIN_GEN 10 header MCP_W32_ZHELATIN_GEN Subject =~ /received a greeting postcard from a/i describe MCP_W32_ZHELATIN_GEN Banned Subject score MCP_W32_ZHELATIN_GEN 10 header MCP_W32_ZHELATIN_GEN Subject =~ /received a postcard from a/i describe MCP_W32_ZHELATIN_GEN Banned Subject score MCP_W32_ZHELATIN_GEN 10 header MCP_W32_ZHELATIN_GEN Subject =~ /received an ecard from a/i describe MCP_W32_ZHELATIN_GEN Banned Subject score MCP_W32_ZHELATIN_GEN 10 My MCP config in MailScanner.conf is: %mcp-dir% = /usr/local/etc/MailScanner/mcp MCP Checks = yes First Check = mcp MCP Required SpamAssassin Score = 1 MCP High SpamAssassin Score = 10 MCP Error Score = 1 MCP Header = X-%org-name%-MailScanner-MCPCheck: Non MCP Actions = deliver MCP Actions = %rules-dir%/spam.actions.rules High Scoring MCP Actions = %rules-dir%/spam.actions.rules Bounce MCP As Attachment = no MCP Modify Subject = yes MCP Subject Text = {Evil?} High Scoring MCP Modify Subject = yes High Scoring MCP Subject Text = {Evil?} Is Definitely MCP = %rules-dir%/spam.blacklist.rules Is Definitely Not MCP = %rules-dir%/spam.whitelist.rules Definite MCP Is High Scoring = no Always Include MCP Report = yes Detailed MCP Report = yes Include Scores In MCP Report = yes Log MCP = yes MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf MCP SpamAssassin User State Dir = MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin Default Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = %mcp-dir% Recipient MCP Report = %report-dir%/recipient.mcp.report.txt Sender MCP Report = %report-dir%/sender.mcp.report.txt In my email these are the headers: Subject: You've received an ecard from a Class-mate! Message-Id: <20070809093143.DFAD711920@panther> Date: Thu, 9 Aug 2007 11:31:39 +0200 (CEST) From: bla@bla.com To: undisclosed-recipients:; X-Panther-MailScanner-Information: Please contact ISP for more information X-Panther-MailScanner: Found to be clean X-Panther-MailScanner-MCPCheck: MCP-Clean, MCP-Checker (score=0, required 1) X-Panther-MailScanner-SpamCheck: not spam, SpamAssassin (score=0, required 5) X-Panther-MailScanner-From: bla@bla.com X-Spam-Status: No, No X-MailScanner: Found to be clean X-MailScanner-SpamCheck: not spam, SpamAssassin (not cached, score=1.618, required 5, BAYES_40 -0.18, DK_POLICY_SIGNSOME 0.00, NO_REAL_NAME 0.96, UNDISC_RECIPS 0.84) X-MailScanner-SpamScore: 1 -- :wq! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From prandal at herefordshire.gov.uk Thu Aug 9 12:57:43 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Thu Aug 9 12:58:02 2007 Subject: Watermarking quirks still in 4.62.8 In-Reply-To: <46BA67F2.1070005@rheelweb.co.nz> References: <7EF0EE5CB3B263488C8C18823239BEBA013584B1@HC-MBX02.herefordshire.gov.uk> <46ADDBBA.3080701@coders.co.uk><7EF0EE5CB3B263488C8C18823239BEBA013584C5@HC-MBX02.herefordshire.gov.uk> <46BA67F2.1070005@rheelweb.co.nz> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA03CEFC@HC-MBX02.herefordshire.gov.uk> No, but there has been some discussion on the list. IIRC, some MTAs include original headers in receipt messages, but Exchange 2003 isn't one of them. Knowing my dodgy memory, I've probably got that wrong. Cheers. Phil -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Seamus Allan Sent: 09 August 2007 02:04 To: MailScanner discussion Subject: Re: Watermarking quirks still in 4.62.8 Randal, Phil wrote: > Oops, my bad. > > Double-checked and can't reproduce the bounce problem. > > Note to myself: Make sure all MailScanner boxes are configured > identically! > > An internal user sends an email to the ouside world requesting a > read-receipt. > > Recipient's Outlook generates a read-receipt which gets blocked by > MailScanner. > > The orginal email's headers are not included in the receipt message, so > there is no watermark to check. > > Sanitised read receipt below: > > Subject: Read: xxxxx > Date: Mon, 30 Jul 2007 12:54:18 +0100 > MIME-Version: 1.0 > Content-Type: multipart/report; > boundary="----=_NextPart_000_0025_01C7D2A8.BE212390"; > report-type=disposition-notification > X-Mailer: Microsoft Office Outlook, Build 11.0.6353 > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3138 > Thread-Index: AcfKzQ0n7j/g6jVpSo6RfWZRbz2L0gDFrJygACqgSvABBFFGYAAAL41L > In-Reply-To: AAAAALxmnSrmiFpFjRWg8ttEtPck1iMA > Message-Id: <20070730115101.368B748B8A@raq2.kc3.net> > X-Virus-Scanned: by amavisd-new at localhost > X-Greylist: Default is to whitelist mail, not delayed by > milter-greylist-3.0 (mx0.herefordshire.gov.uk [172.29.97.109]); Mon, 30 > Jul 2007 12:54:35 +0100 (BST) > > This is a multi-part message in MIME format. > > ------=_NextPart_000_0025_01C7D2A8.BE212390 > Content-Type: multipart/alternative; > boundary="----=_NextPart_001_0026_01C7D2A8.BE212390" > > > ------=_NextPart_001_0026_01C7D2A8.BE212390 > Content-Type: text/plain; > charset="iso-8859-1" > Content-Transfer-Encoding: 7bit > > Your message > > To: someone@out.there > Subject: FW: xxxxxx > Sent: 30/07/2007 12:50 > > was read on 30/07/2007 12:53. > > ------=_NextPart_001_0026_01C7D2A8.BE212390 > Content-Type: text/html; > charset="iso-8859-1" > Content-Transfer-Encoding: quoted-printable > > > > > charset=3DWindows-1252"> > 6.5.7036.0"> > Read: Heritage Open Days > > > > >

Your message
>
>     To:  someone@out.there
>     Subject:  FW: xxxxxxxx
>     Sent:  30/07/2007 12:50
>
> was read on 30/07/2007 12:53.
>

> > > > ------=_NextPart_001_0026_01C7D2A8.BE212390-- > > ------=_NextPart_000_0025_01C7D2A8.BE212390 > Content-Type: message/disposition-notification > Content-Transfer-Encoding: 7bit > > Reporting-UA: D71QML1J; Microsoft Office Outlook, Build 11.0.6353 > Final-Recipient: rfc822;someone@out.there > Original-Message-ID: AAAAALxmnSrmiFpFjRWg8ttEtPck1iMA > Disposition: manual-action/MDN-sent-automatically; displayed > > ------=_NextPart_000_0025_01C7D2A8.BE212390-- > > > Cheers, > > Phil > -- > Phil Randal > Network Engineer > Herefordshire Council > Hereford, UK > > > I too, am having this issue. In the interim I have disabled watermarks, as we have a couple of clients who require Read Receipts. Have you found a resolution Phil? Cheers Seamus -- *Seamus Allan* Network Engineer Rheel Electronics Ltd -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From prandal at herefordshire.gov.uk Thu Aug 9 13:03:34 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Thu Aug 9 13:03:43 2007 Subject: Spamhaus issues? In-Reply-To: References: Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA03CEFD@HC-MBX02.herefordshire.gov.uk> I'd recommend cbl.abuseat.org at the MTA level. That, combined with GreetPause and milter-greylist gets 85 to 90 percent of incoming spam here. Cheers, Phil -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Res Sent: 08 August 2007 12:26 To: MailScanner discussion Subject: RE: Spamhaus issues? Ahh, nasty, time for a change in RBL's I guess... On Wed, 8 Aug 2007, Jeff Mills wrote: > After looking through their website, I think we may have actually been > firewalled due to excess useage. > I wasn't aware that it was a subscription service for businesses. its a a subscription service if you have X number of requests for hour or some crap like that, there are other very good RBL's around that are not analy retentive like them, we use njabl, sorbs and spamcop. Best of luck Jeff, -- Cheers Res -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From maillists at conactive.com Thu Aug 9 13:05:04 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu Aug 9 13:05:12 2007 Subject: MCP not working In-Reply-To: <2f018d4f4bf70e5feeeddba4bc9383fa@localhost> References: <2f018d4f4bf70e5feeeddba4bc9383fa@localhost> Message-ID: Daniel Eiland wrote on Thu, 9 Aug 2007 12:30:02 +0200: > describe MCP_W32_ZHELATIN_GEN 1. your rules all have the same name, only the first (I think) will get used. You could condense them, anyway, to something like /received a.*card from a/". 2. why would you use MCP for this? You are trying to catch a bit more spam than you normally could with the rules you currently have. So, what you do is add extra rules to the ones coming with the distribution. Either from sites like www.rulesemporium.com or by dropping your own rules in /etc/mail/spammassassin. Not MCP! I suggest looking at the SA documentation and not just going by the MailScanner documentation. The MailScanner documentation will, of course, not cover every aspect of the helper applications like SA or Razor or whatever ... There's also a good mailing list. *Everyone* using MS and SA and being on the MailScanner list should also join the SA list! Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From daniel at bokko.nl Thu Aug 9 13:07:07 2007 From: daniel at bokko.nl (Daniel Eiland) Date: Thu Aug 9 13:19:17 2007 Subject: MCP not working In-Reply-To: References: Message-ID: <8c8323bbac5aa91be960e61c4d76838d@localhost> On Thu, 09 Aug 2007 14:05:04 +0200, Kai Schaetzl wrote: > Daniel Eiland wrote on Thu, 9 Aug 2007 12:30:02 +0200: > >> describe MCP_W32_ZHELATIN_GEN > > 1. your rules all have the same name, only the first (I think) will get > used. You could condense them, anyway, to something like /received a.*card > from a/". Good idea! Thanx. > 2. why would you use MCP for this? You are trying to catch a bit more spam > than you normally could with the rules you currently have. So, what you do > is add extra rules to the ones coming with the distribution. Either from > sites like www.rulesemporium.com or by dropping your own rules in > /etc/mail/spammassassin. Not MCP! Well, the thing is that these emails are in fact virusses. http://vil.nai.com/vil/Content/v_142621.htm But since there's no attachment, it is not scanned by clamav or bitdefender. They are also not picked up by spamassassin rules. I also use rules_du_jour for fetching all kind of rules. Getting this particular email in an outlook client makes (some version of) outlook crash. Clicking the link in this email leads you to a website that will try to use known exploits on your browser. My idea was to block these messages with MCP and delete them when found. When i tag them as spam, users get the email in their spambox. Then i still have the risk they open this mail. When there is a better way of doing this, please let me know. > > I suggest looking at the SA documentation and not just going by the > MailScanner documentation. The MailScanner documentation will, of course, > not cover every aspect of the helper applications like SA or Razor or > whatever ... There's also a good mailing list. *Everyone* using MS and SA > and being on the MailScanner list should also join the SA list! Thanx for the advice. > > Kai > > -- > Kai Sch?tzl, Berlin, Germany > Get your web at Conactive Internet Services: http://www.conactive.com > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! -- :wq! From res at ausics.net Thu Aug 9 13:19:15 2007 From: res at ausics.net (Res) Date: Thu Aug 9 13:19:28 2007 Subject: Spamhaus issues? In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA03CEFD@HC-MBX02.herefordshire.gov.uk> References: <7EF0EE5CB3B263488C8C18823239BEBA03CEFD@HC-MBX02.herefordshire.gov.uk> Message-ID: On Thu, 9 Aug 2007, Randal, Phil wrote: > I'd recommend cbl.abuseat.org at the MTA level. That, combined with They dont have a good hit ratio, I've just just grabed the last 8 blocked IPs by RBL's and cbl only lists 1 of them, where as njabl, spamcop and sorbs all listed all those 8 IP's __ Cheers Res From uxbod at splatnix.net Thu Aug 9 14:00:51 2007 From: uxbod at splatnix.net (UxBoD) Date: Thu Aug 9 13:51:52 2007 Subject: MCP not working In-Reply-To: <8c8323bbac5aa91be960e61c4d76838d@localhost> Message-ID: <21495000.13931186664451603.JavaMail.root@office.splatnix.net> If you are using a recent version of MS then you could create a normal SA rule and do something like this :- SpamAssassin Rule Actions = MYSARULENAME=>delete -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From daniel at bokko.nl Thu Aug 9 13:22:42 2007 From: daniel at bokko.nl (Daniel Eiland) Date: Thu Aug 9 14:08:06 2007 Subject: MCP not working In-Reply-To: <2439085.13841186660702158.JavaMail.root@office.splatnix.net> References: <2439085.13841186660702158.JavaMail.root@office.splatnix.net> Message-ID: <3fa6d34e13819039477fbde8785e5c51@localhost> Thanx! This looks far more intelligent than the rules i came up with. I tested it, but still the MCP score is 0. I is just like mailscanner or spamassassin does not find the cf i created. On Thu, 9 Aug 2007 12:58:22 +0100 (BST), UxBoD wrote: > You are redefining your rule each time. try :- > > header __MCP_W32_ZHELATIN_GEN1 Subject =~ /received a greeting > (card|ecard|postcard) from a/i > header __MCP_W32_ZHELATIN_GEN2 Subject =~ /received a postcard from > a/i > header __MCP_W32_ZHELATIN_GEN3 Subject =~ /received an ecard from a/i > meta MCP_W32_ZHELATIN_GEN __MCP_W32_ZHELATIN_GEN1 || > __MCP_W32_ZHELATIN_GEN2 || __MCP_W32_ZHELATIN_GEN3 > describe MCP_W32_ZHELATIN_GEN Banned Subject > score MCP_W32_ZHELATIN_GEN 10 > > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B > // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B > // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net > > ----- Original Message ----- > From: "Daniel Eiland" > To: mailscanner@lists.mailscanner.info > Sent: Thursday, August 9, 2007 11:30:02 AM (GMT) Europe/London > Subject: MCP not working > > > Hello, > > I hope someone can help me out. > > I have a question regarding MCP. It works, but rules never match. > I am running MailScanner 4.61.7 on FreeBSD. Everything works fine except > for MCP. > In my maillog i can see MCP is enabled and is scanning: > > Aug 9 12:10:55 panther MailScanner[44602]: New Batch: Found 3 messages > waiting > Aug 9 12:10:55 panther MailScanner[44602]: New Batch: Scanning 1 > messages, 9602 bytes > Aug 9 12:10:55 panther MailScanner[44602]: MCP Checks: Starting > Aug 9 12:10:57 panther MailScanner[44602]: MCP Checks completed at 8542 > bytes per second > Aug 9 12:10:57 panther MailScanner[44602]: Spam Checks: Starting > Aug 9 12:10:57 panther MailScanner[44620]: Virus Scanning completed at > 2586 bytes per second > Aug 9 12:10:57 panther MailScanner[44620]: Requeue: F134C11713.526DA to > D4F5A119A2 > Aug 9 12:10:57 panther MailScanner[44620]: Uninfected: Delivered 1 > messages > Aug 9 12:10:57 panther MailScanner[44620]: Virus Processing completed at > 319425 bytes per second > Aug 9 12:10:57 panther MailScanner[44620]: Batch completed at 630 bytes > per second (6453 / 10) > Aug 9 12:10:57 panther MailScanner[44620]: Batch (1 message) processed in > 10.24 seconds > > I defined af cf file named 10_w32_zhelatin_gen.cf that is located in > %mcp-dir% for catching email with specific subjects. > The subjects i want to catch are in the form of: You've received a > greeting card from a friend! > > header MCP_W32_ZHELATIN_GEN Subject =~ /received a greeting card from > a/i > describe MCP_W32_ZHELATIN_GEN Banned Subject > score MCP_W32_ZHELATIN_GEN 10 > header MCP_W32_ZHELATIN_GEN Subject =~ /received a greeting ecard > from a/i > describe MCP_W32_ZHELATIN_GEN Banned Subject > score MCP_W32_ZHELATIN_GEN 10 > header MCP_W32_ZHELATIN_GEN Subject =~ /received a greeting postcard > from a/i > describe MCP_W32_ZHELATIN_GEN Banned Subject > score MCP_W32_ZHELATIN_GEN 10 > header MCP_W32_ZHELATIN_GEN Subject =~ /received a postcard from a/i > describe MCP_W32_ZHELATIN_GEN Banned Subject > score MCP_W32_ZHELATIN_GEN 10 > header MCP_W32_ZHELATIN_GEN Subject =~ /received an ecard from a/i > describe MCP_W32_ZHELATIN_GEN Banned Subject > score MCP_W32_ZHELATIN_GEN 10 > > > My MCP config in MailScanner.conf is: > > > %mcp-dir% = /usr/local/etc/MailScanner/mcp > > MCP Checks = yes > First Check = mcp > > MCP Required SpamAssassin Score = 1 > MCP High SpamAssassin Score = 10 > MCP Error Score = 1 > > MCP Header = X-%org-name%-MailScanner-MCPCheck: > Non MCP Actions = deliver > MCP Actions = %rules-dir%/spam.actions.rules > High Scoring MCP Actions = %rules-dir%/spam.actions.rules > Bounce MCP As Attachment = no > > MCP Modify Subject = yes > MCP Subject Text = {Evil?} > High Scoring MCP Modify Subject = yes > High Scoring MCP Subject Text = {Evil?} > > Is Definitely MCP = %rules-dir%/spam.blacklist.rules > Is Definitely Not MCP = %rules-dir%/spam.whitelist.rules > Definite MCP Is High Scoring = no > Always Include MCP Report = yes > Detailed MCP Report = yes > Include Scores In MCP Report = yes > Log MCP = yes > > MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf > MCP SpamAssassin User State Dir = > MCP SpamAssassin Local Rules Dir = %mcp-dir% > MCP SpamAssassin Default Rules Dir = %mcp-dir% > MCP SpamAssassin Install Prefix = %mcp-dir% > Recipient MCP Report = %report-dir%/recipient.mcp.report.txt > Sender MCP Report = %report-dir%/sender.mcp.report.txt > > > In my email these are the headers: > > > Subject: You've received an ecard from a Class-mate! > Message-Id: <20070809093143.DFAD711920@panther> > Date: Thu, 9 Aug 2007 11:31:39 +0200 (CEST) > From: bla@bla.com > To: undisclosed-recipients:; > > X-Panther-MailScanner-Information: Please contact ISP for more information > X-Panther-MailScanner: Found to be clean > X-Panther-MailScanner-MCPCheck: MCP-Clean, MCP-Checker (score=0, > required 1) > X-Panther-MailScanner-SpamCheck: not spam, SpamAssassin (score=0, > required 5) > X-Panther-MailScanner-From: bla@bla.com > X-Spam-Status: No, No > X-MailScanner: Found to be clean > X-MailScanner-SpamCheck: not spam, SpamAssassin (not cached, > score=1.618, required 5, BAYES_40 -0.18, DK_POLICY_SIGNSOME 0.00, > NO_REAL_NAME 0.96, UNDISC_RECIPS 0.84) > X-MailScanner-SpamScore: 1 > > > > -- > :wq! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! -- :wq! From gmatt at nerc.ac.uk Thu Aug 9 14:28:37 2007 From: gmatt at nerc.ac.uk (Greg Matthews) Date: Thu Aug 9 14:28:49 2007 Subject: ClamAV module logging changed in 4.62 In-Reply-To: <1186581516.5158.41.camel@gblades-suse.linguaphone-intranet.co.uk> References: <46B70923.6040309@nerc.ac.uk><46B72B44.9090105@ecs.soton.ac.uk> <012401c7d859$adeeb620$0301a8c0@SAHOMELT><46B76E09.50401@ecs.soton.ac.uk> <46B837E9.4020309@nerc.ac.uk> <028c01c7d9bb$d8ec8740$0301a8c0@SAHOMELT> <1186581516.5158.41.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <46BB1685.1050809@nerc.ac.uk> One last gasp to this thread... I've hard coded the logging in ProcessClamAVModOutput() so that no matter what the "Include Scanner Name In Reports" is set to, the syslog still gets the scanner name. In other words, ProcessClamAVModOutput() now looks similar to ProcessSophosSAVIOutput() replacing: MailScanner::Log::InfoLog("%s::%s",$Name, $logout); with MailScanner::Log::InfoLog("ClamAVModule::%s", $logout); One to watch next time I upgrade! G -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford -- This message (and any attachments) is for the recipient only. NERC is subject to the Freedom of Information Act 2000 and the contents of this email and any reply you make may be disclosed by NERC unless it is exempt from release under the Act. Any material supplied to NERC may be stored in an electronic records management system. From maillists at conactive.com Thu Aug 9 16:31:16 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu Aug 9 16:31:20 2007 Subject: MCP not working In-Reply-To: <3fa6d34e13819039477fbde8785e5c51@localhost> References: <2439085.13841186660702158.JavaMail.root@office.splatnix.net> <3fa6d34e13819039477fbde8785e5c51@localhost> Message-ID: Daniel Eiland wrote on Thu, 9 Aug 2007 14:22:42 +0200: > I is just like mailscanner or spamassassin does not find the cf i created. Yes .... You did a restart of MS, did you? Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Thu Aug 9 16:31:16 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu Aug 9 16:31:24 2007 Subject: Spamhaus issues? In-Reply-To: References: <7EF0EE5CB3B263488C8C18823239BEBA03CEFD@HC-MBX02.herefordshire.gov.uk> Message-ID: Res wrote on Thu, 9 Aug 2007 22:19:15 +1000 (EST): > They dont have a good hit ratio, I've just just grabed the last 8 blocked > IPs by RBL's and cbl only lists 1 of them, where as njabl, spamcop and > sorbs all listed all those 8 IP's That doesn't mean anything. The three lists you mention are aggregated lists by various criteria. For instance that IP might have been on SORBS because it's dynamic. And it will stay there no matter if the mail coming from there is spam or ham. CBL doesn't include dynamic IP space because it is dynamic IP space. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From ssilva at sgvwater.com Thu Aug 9 16:32:49 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 9 16:33:06 2007 Subject: Watermarking quirks still in 4.62.8 In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA03CEFC@HC-MBX02.herefordshire.gov.uk> References: <7EF0EE5CB3B263488C8C18823239BEBA013584B1@HC-MBX02.herefordshire.gov.uk> <46ADDBBA.3080701@coders.co.uk><7EF0EE5CB3B263488C8C18823239BEBA013584C5@HC-MBX02.herefordshire.gov.uk> <46BA67F2.1070005@rheelweb.co.nz> <7EF0EE5CB3B263488C8C18823239BEBA03CEFC@HC-MBX02.herefordshire.gov.uk> Message-ID: Randal, Phil spake the following on 8/9/2007 4:57 AM: > No, but there has been some discussion on the list. > > IIRC, some MTAs include original headers in receipt messages, but > Exchange 2003 isn't one of them. Knowing my dodgy memory, I've probably > got that wrong. > I am having the problem with Outlook users on my non-exchange system, so it is not just MTA specific. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Thu Aug 9 16:47:04 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 9 16:47:25 2007 Subject: MCP not working In-Reply-To: <8c8323bbac5aa91be960e61c4d76838d@localhost> References: <8c8323bbac5aa91be960e61c4d76838d@localhost> Message-ID: Daniel Eiland spake the following on 8/9/2007 5:07 AM: > On Thu, 09 Aug 2007 14:05:04 +0200, Kai Schaetzl wrote: >> Daniel Eiland wrote on Thu, 9 Aug 2007 12:30:02 +0200: >> >>> describe MCP_W32_ZHELATIN_GEN >> 1. your rules all have the same name, only the first (I think) will get >> used. You could condense them, anyway, to something like /received a.*card >> from a/". > > Good idea! Thanx. > >> 2. why would you use MCP for this? You are trying to catch a bit more spam >> than you normally could with the rules you currently have. So, what you do >> is add extra rules to the ones coming with the distribution. Either from >> sites like www.rulesemporium.com or by dropping your own rules in >> /etc/mail/spammassassin. Not MCP! > > Well, the thing is that these emails are in fact virusses. > http://vil.nai.com/vil/Content/v_142621.htm > But since there's no attachment, it is not scanned by clamav or bitdefender. > They are also not picked up by spamassassin rules. I also use rules_du_jour for fetching all kind of rules. > Getting this particular email in an outlook client makes (some version of) outlook crash. > Clicking the link in this email leads you to a website that will try to use known exploits on your browser. > Have you tried the sanesecurity addons for clam? http://www.sanesecurity.co.uk/clamav/ I think this will catch these AND mark them as viruses. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From daniel at bokko.nl Thu Aug 9 17:01:48 2007 From: daniel at bokko.nl (Daniel Eiland) Date: Thu Aug 9 16:58:20 2007 Subject: MCP not working In-Reply-To: Message-ID: <20070809154558.22D2111CEC@panther.webvanced.nl> Yes. I was wondering, is there some way to --lint the MCP rules? -----Oorspronkelijk bericht----- Van: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Namens Kai Schaetzl Verzonden: donderdag 9 augustus 2007 17:31 Aan: mailscanner@lists.mailscanner.info Onderwerp: Re: MCP not working Daniel Eiland wrote on Thu, 9 Aug 2007 14:22:42 +0200: > I is just like mailscanner or spamassassin does not find the cf i created. Yes .... You did a restart of MS, did you? Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From daniel at bokko.nl Thu Aug 9 17:06:58 2007 From: daniel at bokko.nl (Daniel Eiland) Date: Thu Aug 9 17:03:16 2007 Subject: MCP not working In-Reply-To: Message-ID: <20070809155107.55BC911E21@panther.webvanced.nl> Thanx for the link, i did not know about it. The thing is that this mail does not have an attachment. Mailscanner (i think) only scans attachments with clamav, and not the message body. -----Oorspronkelijk bericht----- Van: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Namens Scott Silva Verzonden: donderdag 9 augustus 2007 17:47 Aan: mailscanner@lists.mailscanner.info Onderwerp: Re: MCP not working Daniel Eiland spake the following on 8/9/2007 5:07 AM: > On Thu, 09 Aug 2007 14:05:04 +0200, Kai Schaetzl wrote: >> Daniel Eiland wrote on Thu, 9 Aug 2007 12:30:02 +0200: >> >>> describe MCP_W32_ZHELATIN_GEN >> 1. your rules all have the same name, only the first (I think) will get >> used. You could condense them, anyway, to something like /received a.*card >> from a/". > > Good idea! Thanx. > >> 2. why would you use MCP for this? You are trying to catch a bit more spam >> than you normally could with the rules you currently have. So, what you do >> is add extra rules to the ones coming with the distribution. Either from >> sites like www.rulesemporium.com or by dropping your own rules in >> /etc/mail/spammassassin. Not MCP! > > Well, the thing is that these emails are in fact virusses. > http://vil.nai.com/vil/Content/v_142621.htm > But since there's no attachment, it is not scanned by clamav or bitdefender. > They are also not picked up by spamassassin rules. I also use rules_du_jour for fetching all kind of rules. > Getting this particular email in an outlook client makes (some version of) outlook crash. > Clicking the link in this email leads you to a website that will try to use known exploits on your browser. > Have you tried the sanesecurity addons for clam? http://www.sanesecurity.co.uk/clamav/ I think this will catch these AND mark them as viruses. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From uxbod at splatnix.net Thu Aug 9 17:19:55 2007 From: uxbod at splatnix.net (UxBoD) Date: Thu Aug 9 17:11:07 2007 Subject: MCP not working In-Reply-To: <20070809154558.22D2111CEC@panther.webvanced.nl> Message-ID: <5466423.13991186676395099.JavaMail.root@office.splatnix.net> spamassassin --config-file=/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf -D --lint Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Daniel Eiland" To: "MailScanner discussion" Sent: Thursday, August 9, 2007 5:01:48 PM (GMT) Europe/London Subject: RE: MCP not working Yes. I was wondering, is there some way to --lint the MCP rules? -----Oorspronkelijk bericht----- Van: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Namens Kai Schaetzl Verzonden: donderdag 9 augustus 2007 17:31 Aan: mailscanner@lists.mailscanner.info Onderwerp: Re: MCP not working Daniel Eiland wrote on Thu, 9 Aug 2007 14:22:42 +0200: > I is just like mailscanner or spamassassin does not find the cf i created. Yes .... You did a restart of MS, did you? Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From v at vladville.com Thu Aug 9 17:23:57 2007 From: v at vladville.com (Vlad Mazek) Date: Thu Aug 9 17:24:01 2007 Subject: Mailscanner RBL checks Message-ID: How does MailScanner tell SpamAssassin which RBL's to check? I have Spam Checks = yes Spam List = # ORDB-RBL SBL+XBL # You can un-comment this to enable them Yet SpamAssassin seems to be making queries to all the lists in the spam.lists.conf How exactly does this work? -- -Vlad -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070809/a9947b55/attachment.html From martinh at solidstatelogic.com Thu Aug 9 17:39:03 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Thu Aug 9 17:39:08 2007 Subject: Mailscanner RBL checks In-Reply-To: Message-ID: Vald Via the standard spamassassin config. These tests here are purely for Mailscanner to run. If you want to tell SpamAssassin NOT to do a particular RBL then you need to give a zero score in the /etc/mail/spamassassin/mailscanner.cf file. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Vlad Mazek > Sent: 09 August 2007 17:24 > To: mailscanner@lists.mailscanner.info > Subject: Mailscanner RBL checks > > How does MailScanner tell SpamAssassin which RBL's to check? I have > Spam Checks = yes > Spam List = # ORDB-RBL SBL+XBL # You can un-comment this to enable them > > Yet SpamAssassin seems to be making queries to all the lists in the > spam.lists.conf > > How exactly does this work? > > -- > -Vlad ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From uxbod at splatnix.net Thu Aug 9 17:51:19 2007 From: uxbod at splatnix.net (UxBoD) Date: Thu Aug 9 17:42:14 2007 Subject: MCP not working In-Reply-To: <20070809155107.55BC911E21@panther.webvanced.nl> Message-ID: <25775270.14021186678279912.JavaMail.root@office.splatnix.net> Latest versions of MS have option to scan whole message when using ClamAV, and not just attachments. Downside is a double scan, so slight performance degregation. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Daniel Eiland" To: "MailScanner discussion" Sent: Thursday, August 9, 2007 5:06:58 PM (GMT) Europe/London Subject: RE: MCP not working Thanx for the link, i did not know about it. The thing is that this mail does not have an attachment. Mailscanner (i think) only scans attachments with clamav, and not the message body. -----Oorspronkelijk bericht----- Van: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Namens Scott Silva Verzonden: donderdag 9 augustus 2007 17:47 Aan: mailscanner@lists.mailscanner.info Onderwerp: Re: MCP not working Daniel Eiland spake the following on 8/9/2007 5:07 AM: > On Thu, 09 Aug 2007 14:05:04 +0200, Kai Schaetzl wrote: >> Daniel Eiland wrote on Thu, 9 Aug 2007 12:30:02 +0200: >> >>> describe MCP_W32_ZHELATIN_GEN >> 1. your rules all have the same name, only the first (I think) will get >> used. You could condense them, anyway, to something like /received a.*card >> from a/". > > Good idea! Thanx. > >> 2. why would you use MCP for this? You are trying to catch a bit more spam >> than you normally could with the rules you currently have. So, what you do >> is add extra rules to the ones coming with the distribution. Either from >> sites like www.rulesemporium.com or by dropping your own rules in >> /etc/mail/spammassassin. Not MCP! > > Well, the thing is that these emails are in fact virusses. > http://vil.nai.com/vil/Content/v_142621.htm > But since there's no attachment, it is not scanned by clamav or bitdefender. > They are also not picked up by spamassassin rules. I also use rules_du_jour for fetching all kind of rules. > Getting this particular email in an outlook client makes (some version of) outlook crash. > Clicking the link in this email leads you to a website that will try to use known exploits on your browser. > Have you tried the sanesecurity addons for clam? http://www.sanesecurity.co.uk/clamav/ I think this will catch these AND mark them as viruses. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From v at vladville.com Thu Aug 9 17:59:57 2007 From: v at vladville.com (Vlad Mazek) Date: Thu Aug 9 18:00:02 2007 Subject: Mailscanner RBL checks In-Reply-To: References: Message-ID: I'm sorry I am just not following; my mailscanner.cf has only one line: dns_available yes Yet, it seems to be querying the external RBL's: SpamAssassin (not cached, score=16.885, required 5, autolearn=disabled, FH_RELAY_NODNS 1.25, HELO_EQ_IP_ADDR 1.12, HTML_MESSAGE 0.00, HTML_OBFUSCATE_05_10 0.57, MIME_HTML_ONLY 1.67, RCVD_IN_BL_SPAMCOP_NET 2.19, RCVD_IN_PBL 0.51, RDNS_NONE 0.10, URIBL_BLACK 1.96, URIBL_JP_SURBL 2.86, URIBL_OB_SURBL 2.13, URIBL_SC_SURBL 2.52 My question is simply where/what is telling SpamAssassin to query all these RBLs because my MailScanner.cf doesn't list any RBLs to be called (line is commented out completely) -Vlad On 8/9/07, Martin.Hepworth wrote: > > Vald > > Via the standard spamassassin config. > > These tests here are purely for Mailscanner to run. > > If you want to tell SpamAssassin NOT to do a particular RBL then you need > to give a zero score in the /etc/mail/spamassassin/mailscanner.cf file. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Vlad Mazek > > Sent: 09 August 2007 17:24 > > To: mailscanner@lists.mailscanner.info > > Subject: Mailscanner RBL checks > > > > How does MailScanner tell SpamAssassin which RBL's to check? I have > > Spam Checks = yes > > Spam List = # ORDB-RBL SBL+XBL # You can un-comment this to enable them > > > > Yet SpamAssassin seems to be making queries to all the lists in the > > spam.lists.conf > > > > How exactly does this work? > > > > -- > > -Vlad > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- -Vlad -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070809/045cf67c/attachment.html From Carl.Andrews at crackerbarrel.com Thu Aug 9 18:05:25 2007 From: Carl.Andrews at crackerbarrel.com (Andrews Carl 455) Date: Thu Aug 9 18:05:28 2007 Subject: Sendmail help ?? Please. In-Reply-To: <25775270.14021186678279912.JavaMail.root@office.splatnix.net> Message-ID: <113A0DFC086C984AB9EFDF6B8614F075017D34C0@exchange03.CBOCS.com> I appologize for posting a non-MS question, but it has been my expierience that if it can be done with email, someone on this list has done it. OS: Linux - UBUNTU 6.06.1 LTS with all patches applied SENDMAIL: 8.13.5 Problem: access.db does work. I have this in my /etc/mail/access: GreetPause: 25000 ClientRate: 100 ClientConn: 100 candrews@crackerbarrel.com REJECT And have recreated access.db with both 'make access' and 'makemap hash /etc/mail/access < /etc/mail/access' and tested both with the command: echo "/map access candrews@crackerbarrel.com" | sendmail -bt And I get 'map_lookup: access (candrews@crackerbarrel.com) returns REJECT (0)' But if I send an email to candrews@crackerbarrel.com through this server it does not get rejected. Also, if I telnet to 'localhost 25' from the computer and send the message that way it is delivered too. What am I missing? I have this working on a CentOS 3.8 server with sendmail 8.12. Thanks for any help or insight you can provide!!! Carl From ssilva at sgvwater.com Thu Aug 9 18:16:37 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 9 18:17:01 2007 Subject: Spamhaus issues? In-Reply-To: References: <7EF0EE5CB3B263488C8C18823239BEBA03CEFD@HC-MBX02.herefordshire.gov.uk> Message-ID: Kai Schaetzl spake the following on 8/9/2007 8:31 AM: > Res wrote on Thu, 9 Aug 2007 22:19:15 +1000 (EST): > >> They dont have a good hit ratio, I've just just grabed the last 8 blocked >> IPs by RBL's and cbl only lists 1 of them, where as njabl, spamcop and >> sorbs all listed all those 8 IP's > > That doesn't mean anything. The three lists you mention are aggregated lists > by various criteria. For instance that IP might have been on SORBS because > it's dynamic. And it will stay there no matter if the mail coming from there > is spam or ham. CBL doesn't include dynamic IP space because it is dynamic > IP space. > > Kai > The blacklists cannot be all things to all people. That is why there are so many. Each admin needs to evaluate a list before he uses it to block mail. I usually try a list in spamassassin with a low score first to see how it hits with my mail. I can use zen or spamhaus at the MTA because it works for me, but other admins might have users or important clients in those spaces. You need to test any list before you use it fully, that is just the nature of the beast. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Thu Aug 9 18:21:52 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 9 18:22:09 2007 Subject: Sendmail help ?? Please. In-Reply-To: <113A0DFC086C984AB9EFDF6B8614F075017D34C0@exchange03.CBOCS.com> References: <25775270.14021186678279912.JavaMail.root@office.splatnix.net> <113A0DFC086C984AB9EFDF6B8614F075017D34C0@exchange03.CBOCS.com> Message-ID: Andrews Carl 455 spake the following on 8/9/2007 10:05 AM: > I appologize for posting a non-MS question, but it has been my > expierience that if it can be done with email, someone on this list has > done it. > > OS: Linux - UBUNTU 6.06.1 LTS with all patches applied > SENDMAIL: 8.13.5 > > Problem: access.db does work. > > I have this in my /etc/mail/access: > GreetPause: 25000 > ClientRate: 100 > ClientConn: 100 > candrews@crackerbarrel.com REJECT > > And have recreated access.db with both 'make access' and 'makemap hash > /etc/mail/access < /etc/mail/access' and tested both with the command: > > echo "/map access candrews@crackerbarrel.com" | sendmail -bt > > And I get 'map_lookup: access (candrews@crackerbarrel.com) returns > REJECT (0)' > > But if I send an email to candrews@crackerbarrel.com through this server > it does not get rejected. Also, if I telnet to 'localhost 25' from the > computer and send the message that way it is delivered too. > > What am I missing? I have this working on a CentOS 3.8 server with > sendmail 8.12. > > > Thanks for any help or insight you can provide!!! > > > Carl Try "To:candrews@crackerbarrel.com REJECT" -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Thu Aug 9 18:27:09 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 9 18:27:37 2007 Subject: Mailscanner RBL checks In-Reply-To: References: Message-ID: Vlad Mazek spake the following on 8/9/2007 9:59 AM: > I'm sorry I am just not following; my mailscanner.cf > has only one line: > > dns_available yes > > Yet, it seems to be querying the external RBL's: > SpamAssassin (not cached, score= 16.885, required 5, autolearn=disabled, > FH_RELAY_NODNS 1.25, HELO_EQ_IP_ADDR 1.12, HTML_MESSAGE 0.00, > HTML_OBFUSCATE_05_10 0.57, MIME_HTML_ONLY 1.67, RCVD_IN_BL_SPAMCOP_NET > 2.19, RCVD_IN_PBL 0.51, RDNS_NONE 0.10, URIBL_BLACK 1.96, URIBL_JP_SURBL > 2.86, URIBL_OB_SURBL 2.13, URIBL_SC_SURBL 2.52 > > My question is simply where/what is telling SpamAssassin to query all > these RBLs because my MailScanner.cf doesn't list any RBLs to be called > (line is commented out completely) Spamassassin has several tests it does all by itself that are indepentent of mailscanner. Spamassassin tests rbl's and gives a score that is added together. When you use rbl's in mailscanner they are just flagged as spam if they hit, independent of how reliable a rbl might be. As you were told in the last mail, if you do not want rbl tests in spamassassin, you have to add a line for each one in mailscanner.cf. As an example, if you didn't want to test for RCVD_IN_BL_SPAMCOP_NET you add the following line; score RCVD_IN_BL_SPAMCOP_NET 0 Does this clear things up a little more? -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From mikael at syska.dk Thu Aug 9 19:43:17 2007 From: mikael at syska.dk (Mikael Syska) Date: Thu Aug 9 19:41:59 2007 Subject: Mailscanner RBL checks In-Reply-To: References: Message-ID: <46BB6045.30809@syska.dk> Scott Silva wrote: > Vlad Mazek spake the following on 8/9/2007 9:59 AM: > >> I'm sorry I am just not following; my mailscanner.cf >> has only one line: >> >> dns_available yes >> >> Yet, it seems to be querying the external RBL's: >> SpamAssassin (not cached, score= 16.885, required 5, autolearn=disabled, >> FH_RELAY_NODNS 1.25, HELO_EQ_IP_ADDR 1.12, HTML_MESSAGE 0.00, >> HTML_OBFUSCATE_05_10 0.57, MIME_HTML_ONLY 1.67, RCVD_IN_BL_SPAMCOP_NET >> 2.19, RCVD_IN_PBL 0.51, RDNS_NONE 0.10, URIBL_BLACK 1.96, URIBL_JP_SURBL >> 2.86, URIBL_OB_SURBL 2.13, URIBL_SC_SURBL 2.52 >> >> My question is simply where/what is telling SpamAssassin to query all >> these RBLs because my MailScanner.cf doesn't list any RBLs to be called >> (line is commented out completely) >> > Spamassassin has several tests it does all by itself that are indepentent of > mailscanner. Spamassassin tests rbl's and gives a score that is added > together. When you use rbl's in mailscanner they are just flagged as spam if > they hit, independent of how reliable a rbl might be. > > As you were told in the last mail, if you do not want rbl tests in > spamassassin, you have to add a line for each one in mailscanner.cf. > As an example, if you didn't want to test for RCVD_IN_BL_SPAMCOP_NET > you add the following line; > score RCVD_IN_BL_SPAMCOP_NET 0 > > Does this clear things up a little more? > Little off-topic: Can't the lookups be completely disabled, so its possible to avoid the the DNS query ? As I understand SA, it will still make the lookup even if the score is 0 ... or am I wrong here ? // ouT From Carl.Andrews at crackerbarrel.com Thu Aug 9 19:46:48 2007 From: Carl.Andrews at crackerbarrel.com (Andrews Carl 455) Date: Thu Aug 9 19:46:58 2007 Subject: Sendmail help ?? Please. In-Reply-To: Message-ID: <113A0DFC086C984AB9EFDF6B8614F075017D34C7@exchange03.CBOCS.com> That did not work either. It does show that it _should_ be rejected : # echo "/map access candrews@crackerbarrel.com" | sendmail -bt ADDRESS TEST MODE (ruleset 3 NOT automatically invoked) Enter
> map_lookup: access (candrews@crackerbarrel.com) no match (0) # echo "/map access to:candrews@crackerbarrel.com" | sendmail -bt ADDRESS TEST MODE (ruleset 3 NOT automatically invoked) Enter
> map_lookup: access (to:candrews@crackerbarrel.com) returns REJECT (0) -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Scott Silva Sent: Thursday, August 09, 2007 12:22 PM To: mailscanner@lists.mailscanner.info Subject: Re: Sendmail help ?? Please. Andrews Carl 455 spake the following on 8/9/2007 10:05 AM: > I appologize for posting a non-MS question, but it has been my > expierience that if it can be done with email, someone on this list > has done it. > > OS: Linux - UBUNTU 6.06.1 LTS with all patches applied > SENDMAIL: 8.13.5 > > Problem: access.db does work. > > I have this in my /etc/mail/access: > GreetPause: 25000 > ClientRate: 100 > ClientConn: 100 > candrews@crackerbarrel.com REJECT > > And have recreated access.db with both 'make access' and 'makemap hash > /etc/mail/access < /etc/mail/access' and tested both with the command: > > echo "/map access candrews@crackerbarrel.com" | sendmail -bt > > And I get 'map_lookup: access (candrews@crackerbarrel.com) returns > REJECT (0)' > > But if I send an email to candrews@crackerbarrel.com through this > server it does not get rejected. Also, if I telnet to 'localhost 25' > from the computer and send the message that way it is delivered too. > > What am I missing? I have this working on a CentOS 3.8 server with > sendmail 8.12. > > > Thanks for any help or insight you can provide!!! > > > Carl Try "To:candrews@crackerbarrel.com REJECT" -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From ssilva at sgvwater.com Thu Aug 9 19:51:10 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 9 19:51:23 2007 Subject: Mailscanner RBL checks In-Reply-To: <46BB6045.30809@syska.dk> References: <46BB6045.30809@syska.dk> Message-ID: Mikael Syska spake the following on 8/9/2007 11:43 AM: > Scott Silva wrote: >> Vlad Mazek spake the following on 8/9/2007 9:59 AM: >> >>> I'm sorry I am just not following; my mailscanner.cf >>> has only one line: >>> >>> dns_available yes >>> >>> Yet, it seems to be querying the external RBL's: >>> SpamAssassin (not cached, score= 16.885, required 5, autolearn=disabled, >>> FH_RELAY_NODNS 1.25, HELO_EQ_IP_ADDR 1.12, HTML_MESSAGE 0.00, >>> HTML_OBFUSCATE_05_10 0.57, MIME_HTML_ONLY 1.67, RCVD_IN_BL_SPAMCOP_NET >>> 2.19, RCVD_IN_PBL 0.51, RDNS_NONE 0.10, URIBL_BLACK 1.96, URIBL_JP_SURBL >>> 2.86, URIBL_OB_SURBL 2.13, URIBL_SC_SURBL 2.52 >>> >>> My question is simply where/what is telling SpamAssassin to query all >>> these RBLs because my MailScanner.cf doesn't list any RBLs to be called >>> (line is commented out completely) >>> >> Spamassassin has several tests it does all by itself that are >> indepentent of >> mailscanner. Spamassassin tests rbl's and gives a score that is added >> together. When you use rbl's in mailscanner they are just flagged as >> spam if >> they hit, independent of how reliable a rbl might be. >> >> As you were told in the last mail, if you do not want rbl tests in >> spamassassin, you have to add a line for each one in mailscanner.cf. >> As an example, if you didn't want to test for RCVD_IN_BL_SPAMCOP_NET >> you add the following line; >> score RCVD_IN_BL_SPAMCOP_NET 0 >> >> Does this clear things up a little more? >> > Little off-topic: > Can't the lookups be completely disabled, so its possible to avoid the > the DNS query ? > > As I understand SA, it will still make the lookup even if the score is 0 > ... or am I wrong here ? > > // ouT AFAIK spamassassin will only do the lookups on rbl's that are enabled. If you don't want to do any lookups, I think you can set dns_available no in mailscanner.cf, but that will disable the most reliable spam checks that spamassassin has. Do you just want to disable certain rbl's or all of them? -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From steve.swaney at fsl.com Thu Aug 9 20:09:44 2007 From: steve.swaney at fsl.com (Stephen Swaney) Date: Thu Aug 9 20:08:39 2007 Subject: Sendmail help ?? Please. In-Reply-To: <113A0DFC086C984AB9EFDF6B8614F075017D34C7@exchange03.CBOCS.com> References: <113A0DFC086C984AB9EFDF6B8614F075017D34C7@exchange03.CBOCS.com> Message-ID: <228701c7dab8$d8fac820$8af05860$@swaney@fsl.com> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Andrews Carl 455 > Sent: Thursday, August 09, 2007 2:47 PM > To: MailScanner discussion > Subject: RE: Sendmail help ?? Please. > > That did not work either. It does show that it _should_ be rejected : > > # echo "/map access candrews@crackerbarrel.com" | sendmail -bt > ADDRESS TEST MODE (ruleset 3 NOT automatically invoked) > Enter
> > map_lookup: access (candrews@crackerbarrel.com) no match (0) > > # echo "/map access to:candrews@crackerbarrel.com" | sendmail -bt > ADDRESS TEST MODE (ruleset 3 NOT automatically invoked) > Enter
> > map_lookup: access (to:candrews@crackerbarrel.com) returns REJECT (0) > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Scott > Silva > Sent: Thursday, August 09, 2007 12:22 PM > To: mailscanner@lists.mailscanner.info > Subject: Re: Sendmail help ?? Please. > > > Andrews Carl 455 spake the following on 8/9/2007 10:05 AM: > > I appologize for posting a non-MS question, but it has been my > > expierience that if it can be done with email, someone on this list > > has done it. > > > > OS: Linux - UBUNTU 6.06.1 LTS with all patches applied > > SENDMAIL: 8.13.5 > > > > Problem: access.db does work. > > > > I have this in my /etc/mail/access: > > GreetPause: 25000 > > ClientRate: 100 > > ClientConn: 100 > > candrews@crackerbarrel.com REJECT > > > > And have recreated access.db with both 'make access' and 'makemap > hash > > > /etc/mail/access < /etc/mail/access' and tested both with the > command: > > > > echo "/map access candrews@crackerbarrel.com" | sendmail -bt > > > > And I get 'map_lookup: access (candrews@crackerbarrel.com) returns > > REJECT (0)' > > > > But if I send an email to candrews@crackerbarrel.com through this > > server it does not get rejected. Also, if I telnet to 'localhost 25' > > from the computer and send the message that way it is delivered too. > > > > What am I missing? I have this working on a CentOS 3.8 server with > > sendmail 8.12. > > > > > > Thanks for any help or insight you can provide!!! > > You should update sendmail to the latest version 8.12 has some problems. Best regards, Steve Steve Swaney steve@fsl.com > > > > Carl > Try "To:candrews@crackerbarrel.com REJECT" > > -- > > MailScanner is like deodorant... > You hope everybody uses it, and > you notice quickly if they don't!!!! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From maillists at conactive.com Thu Aug 9 20:31:20 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu Aug 9 20:31:24 2007 Subject: Mailscanner RBL checks In-Reply-To: References: Message-ID: Vlad Mazek wrote on Thu, 9 Aug 2007 12:59:57 -0400: > Yet, it seems to be querying the external RBL's: No, it does not. You have to make a distinction between MS and SA, both can do RBL lookups. The ones you quote are done solely by SA and it's not MS telling it do that. It's simply configured in the SA configuration files in /etc/mail/spamassassin. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Thu Aug 9 20:31:20 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu Aug 9 20:31:24 2007 Subject: Sendmail help ?? Please. In-Reply-To: <113A0DFC086C984AB9EFDF6B8614F075017D34C0@exchange03.CBOCS.com> References: <113A0DFC086C984AB9EFDF6B8614F075017D34C0@exchange03.CBOCS.com> Message-ID: Andrews Carl 455 wrote on Thu, 9 Aug 2007 12:05:25 -0500: > I appologize for posting a non-MS question, but it has been my > expierience that if it can be done with email, someone on this list has > done it. But then please do not jump in other threads. Post a new mail. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From campbell at cnpapers.com Thu Aug 9 20:34:45 2007 From: campbell at cnpapers.com (Steve Campbell) Date: Thu Aug 9 20:36:37 2007 Subject: Mailscanner RBL checks In-Reply-To: <46BB6045.30809@syska.dk> References: <46BB6045.30809@syska.dk> Message-ID: <46BB6C55.3090607@cnpapers.com> I believe you can do this, but my versions are a little old: In MailScanner.conf, try setting the following: Spam List = Spam Domain List = This turns off RBLs and the like in MS. In either mailscanner.cf, local.cf, or spam.assassin.prefs.conf, set the following: skip_rbl_checks = 1 This turns off RBLs in SA. Make sure they are not commented if they already exist. I may be wrong on this, so anyone can correct me if I am. Steve Campbell Mikael Syska wrote: > Scott Silva wrote: >> Vlad Mazek spake the following on 8/9/2007 9:59 AM: >> >>> I'm sorry I am just not following; my mailscanner.cf >>> has only one line: >>> >>> dns_available yes >>> >>> Yet, it seems to be querying the external RBL's: >>> SpamAssassin (not cached, score= 16.885, required 5, >>> autolearn=disabled, >>> FH_RELAY_NODNS 1.25, HELO_EQ_IP_ADDR 1.12, HTML_MESSAGE 0.00, >>> HTML_OBFUSCATE_05_10 0.57, MIME_HTML_ONLY 1.67, RCVD_IN_BL_SPAMCOP_NET >>> 2.19, RCVD_IN_PBL 0.51, RDNS_NONE 0.10, URIBL_BLACK 1.96, >>> URIBL_JP_SURBL >>> 2.86, URIBL_OB_SURBL 2.13, URIBL_SC_SURBL 2.52 >>> >>> My question is simply where/what is telling SpamAssassin to query all >>> these RBLs because my MailScanner.cf doesn't list any RBLs to be called >>> (line is commented out completely) >>> >> Spamassassin has several tests it does all by itself that are >> indepentent of >> mailscanner. Spamassassin tests rbl's and gives a score that is added >> together. When you use rbl's in mailscanner they are just flagged as >> spam if >> they hit, independent of how reliable a rbl might be. >> >> As you were told in the last mail, if you do not want rbl tests in >> spamassassin, you have to add a line for each one in mailscanner.cf. >> As an example, if you didn't want to test for RCVD_IN_BL_SPAMCOP_NET >> you add the following line; >> score RCVD_IN_BL_SPAMCOP_NET 0 >> >> Does this clear things up a little more? >> > Little off-topic: > Can't the lookups be completely disabled, so its possible to avoid the > the DNS query ? > > As I understand SA, it will still make the lookup even if the score is > 0 ... or am I wrong here ? > > // ouT From ajos1 at onion.demon.co.uk Thu Aug 9 20:43:54 2007 From: ajos1 at onion.demon.co.uk (ajos1@onion.demon.co.uk) Date: Thu Aug 9 20:43:57 2007 Subject: SAVI missing Message-ID: - On my system... it says: MailScanner --version | grep -i missing --------------------------------------- missing SAVI Is SAVI still needed... I only ask as it is amoungst the group of perl RPMs in the MailScanner Tar.gz . == ===================================================================== = = "Where did you learn about ducks?" - Ironside = = Need help dealing with Parking Tickets, Bailiffs, Capita or NTL... = Call... +44 8457 90 90 90 http://www.samaritans.org/ = ===================================================================== From doc at maddoc.net Thu Aug 9 20:53:11 2007 From: doc at maddoc.net (Doc Schneider) Date: Thu Aug 9 20:53:24 2007 Subject: [Fwd: ANNOUNCE: Apache SpamAssassin 3.2.3 available] Message-ID: <46BB70A7.409@maddoc.net> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Apache SpamAssassin 3.2.3 is now available! This is a maintenance release of the 3.2.x branch. - -- - -Doc Lincoln, NE. http://www.genealogyforyou.com/ http://www.cairnproductions.com/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (GNU/Linux) Comment: Using GnuPG with CentOS - http://enigmail.mozdev.org iD8DBQFGu3CmqOEeBwEpgcsRAixmAJ9VbZkjzXCIel0XtealrOVmmffYcwCgjFp3 qhbnhQgTkXCxRoqoENqw8+Q= =vOuK -----END PGP SIGNATURE----- From ssilva at sgvwater.com Thu Aug 9 20:53:33 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 9 20:54:05 2007 Subject: SAVI missing In-Reply-To: References: Message-ID: ajos1@onion.demon.co.uk spake the following on 8/9/2007 1:43 PM: > - > > On my system... it says: > > MailScanner --version | grep -i missing > --------------------------------------- > missing SAVI > > Is SAVI still needed... I only ask as it is amoungst the group of perl RPMs in the MailScanner Tar.gz . > It is only useful if you are running sophos and want the module. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From steve.swaney at fsl.com Thu Aug 9 21:01:14 2007 From: steve.swaney at fsl.com (Stephen Swaney) Date: Thu Aug 9 21:00:08 2007 Subject: SAVI missing In-Reply-To: References: Message-ID: <22d801c7dac0$0a9d3780$1fd7a680$@swaney@fsl.com> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of ajos1@onion.demon.co.uk > Sent: Thursday, August 09, 2007 8:44 PM > To: mailscanner@lists.mailscanner.info > Cc: ajos1@onion.demon.co.uk > Subject: SAVI missing > > - > > On my system... it says: > > MailScanner --version | grep -i missing > --------------------------------------- > missing SAVI > > Is SAVI still needed... I only ask as it is amoungst the group of perl > RPMs in the MailScanner Tar.gz . > SAVI is only necessary if you are using the Sophos virus scanner and want call Sophos with the sophossavi Virus Scanning package. Best regards, Steve Steve Swaney steve@fsl.com From MailScanner at ecs.soton.ac.uk Thu Aug 9 21:00:11 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 9 21:00:45 2007 Subject: SAVI missing In-Reply-To: References: Message-ID: <46BB724B.9080106@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SAVI is used by the "sophossavi" virus scanner. If you're not using Sophos, then you don't need it. You'll probably find it is in the Optional list of perl modules that MailScanner --version outputs. ajos1@onion.demon.co.uk wrote: > - > > On my system... it says: > > MailScanner --version | grep -i missing > --------------------------------------- > missing SAVI > > Is SAVI still needed... I only ask as it is amoungst the group of perl RPMs in the MailScanner Tar.gz . > > == > ===================================================================== > = > = "Where did you learn about ducks?" - Ironside > = > = Need help dealing with Parking Tickets, Bailiffs, Capita or NTL... > = Call... +44 8457 90 90 90 http://www.samaritans.org/ > = > ===================================================================== > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGu3JMEfZZRxQVtlQRAlCRAKD6VV6Gw7tqGPg8YMZ1cNkYgHWwXQCgobTT rprWOns52DWmVcQkkLgCb4g= =KtFg -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Thu Aug 9 21:15:05 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 9 21:15:46 2007 Subject: [Fwd: ANNOUNCE: Apache SpamAssassin 3.2.3 available] In-Reply-To: <46BB70A7.409@maddoc.net> References: <46BB70A7.409@maddoc.net> Message-ID: <46BB75C9.4050601@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Unfortunately I can't download it yet :-( As soon as I can, I'll update my ClamAV+SA package. Doc Schneider wrote: > * PGP Signed by an unknown key > > > Apache SpamAssassin 3.2.3 is now available! This is a maintenance > release of the 3.2.x branch. > > -- > -Doc > Lincoln, NE. > http://www.genealogyforyou.com/ > http://www.cairnproductions.com/ > > * Unknown Key > * 0x012981CB(L) > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGu3XKEfZZRxQVtlQRAq6YAKDhEzSgPMC7iqrclNABN1PLquZiigCgp1iv mElwH5WgKU9ECU15JN5ZwF0= =yONL -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From doc at maddoc.net Thu Aug 9 21:22:36 2007 From: doc at maddoc.net (Doc Schneider) Date: Thu Aug 9 21:22:48 2007 Subject: [Fwd: ANNOUNCE: Apache SpamAssassin 3.2.3 available] In-Reply-To: <46BB75C9.4050601@ecs.soton.ac.uk> References: <46BB70A7.409@maddoc.net> <46BB75C9.4050601@ecs.soton.ac.uk> Message-ID: <46BB778C.7070000@maddoc.net> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 http://spamassassin.apache.org/downloads.cgi Even from there? I have the tarball and can put it at something like fsl's server if you want. Julian Field wrote: > Unfortunately I can't download it yet :-( > As soon as I can, I'll update my ClamAV+SA package. > > Doc Schneider wrote: >> * PGP Signed by an unknown key Gork! Ork! Need to send my key to some keyservers. - -- - -Doc Lincoln, NE. http://www.genealogyforyou.com/ http://www.cairnproductions.com/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (GNU/Linux) Comment: Using GnuPG with CentOS - http://enigmail.mozdev.org iD8DBQFGu3eLqOEeBwEpgcsRAmyRAJ9o8qcITnG9Guw1S8JdTMYb1eHHLwCfdOmO gRQQyFHTVitgQmchmFjX5L4= =SLhD -----END PGP SIGNATURE----- From MailScanner at ecs.soton.ac.uk Thu Aug 9 21:33:20 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 9 21:34:07 2007 Subject: [Fwd: ANNOUNCE: Apache SpamAssassin 3.2.3 available] In-Reply-To: <46BB778C.7070000@maddoc.net> References: <46BB70A7.409@maddoc.net> <46BB75C9.4050601@ecs.soton.ac.uk> <46BB778C.7070000@maddoc.net> Message-ID: <46BB7A10.4060002@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Just got it from here: http://www.apache.org/dist/spamassassin/source/Mail-SpamAssassin-3.2.3.tar.gz Thanks anyway. Doc Schneider wrote: > * PGP Signed by an unknown key > > > http://spamassassin.apache.org/downloads.cgi > > Even from there? I have the tarball and can put it at something like > fsl's server if you want. > > Julian Field wrote: > >> Unfortunately I can't download it yet :-( >> As soon as I can, I'll update my ClamAV+SA package. >> >> Doc Schneider wrote: >> >>>> Old Signed by an unknown key >>>> > > Gork! Ork! Need to send my key to some keyservers. > > -- > -Doc > Lincoln, NE. > http://www.genealogyforyou.com/ > http://www.cairnproductions.com/ > > * Unknown Key > * 0x012981CB(L) > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGu3oTEfZZRxQVtlQRAkqHAKCGf2UxAemltHuI6dDVoBtYd982fACg0fko VWT0T7OvAnvUiB/qznWN1OQ= =4QUr -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Thu Aug 9 21:41:59 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 9 21:42:32 2007 Subject: ANNOUNCE: SpamAssassin 3.2.3 released Message-ID: <46BB7C17.4030306@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 A new version of SpamAssassin has been released and my ClamAV+SpamAssassin package has been updated accordingly. You can download the new version from here: http://www.mailscanner.info/downloads.html Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGu3wYEfZZRxQVtlQRAsMTAKDbhKGWH5hr84n9CBUWY5vyEhGInQCg5cIu kq5T8ppbSxZojmEkg2/pMgY= =97ar -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From dnsadmin at 1bigthink.com Thu Aug 9 22:08:11 2007 From: dnsadmin at 1bigthink.com (dnsadmin 1bigthink.com) Date: Thu Aug 9 22:08:31 2007 Subject: More filetype/filename questions: jsp, js, mno files Message-ID: <200708092108.l79L8YtF000846@mxt.1bigthink.com> Hello All, I have attempted to search for and test allowing the following file types which are frequently passed among my developers in .zip files. I cannot seem to figure out how to allow them. I've figured out how to overload the ruleset for just these users, but still cannot get these filetypes/names through: *.mno *.jsp *.js It's pretty aggravating. Can anyone help? Thanks, Glenn Parsons From Carl.Andrews at crackerbarrel.com Thu Aug 9 22:08:25 2007 From: Carl.Andrews at crackerbarrel.com (Andrews Carl 455) Date: Thu Aug 9 22:08:49 2007 Subject: Sendmail help ?? Please. In-Reply-To: <228701c7dab8$d8fac820$8af05860$@swaney@fsl.com> Message-ID: <113A0DFC086C984AB9EFDF6B8614F075017D34CD@exchange03.CBOCS.com> I am using 8.13. Is that not the latest? -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Stephen Swaney Sent: Thursday, August 09, 2007 2:10 PM To: 'MailScanner discussion' Subject: RE: Sendmail help ?? Please. > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Andrews Carl 455 > Sent: Thursday, August 09, 2007 2:47 PM > To: MailScanner discussion > Subject: RE: Sendmail help ?? Please. > > That did not work either. It does show that it _should_ be rejected : > > # echo "/map access candrews@crackerbarrel.com" | sendmail -bt ADDRESS > TEST MODE (ruleset 3 NOT automatically invoked) Enter >
> > map_lookup: access (candrews@crackerbarrel.com) no match (0) > > # echo "/map access to:candrews@crackerbarrel.com" | sendmail -bt > ADDRESS TEST MODE (ruleset 3 NOT automatically invoked) Enter >
> > map_lookup: access (to:candrews@crackerbarrel.com) returns REJECT > > (0) > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Scott > Silva > Sent: Thursday, August 09, 2007 12:22 PM > To: mailscanner@lists.mailscanner.info > Subject: Re: Sendmail help ?? Please. > > > Andrews Carl 455 spake the following on 8/9/2007 10:05 AM: > > I appologize for posting a non-MS question, but it has been my > > expierience that if it can be done with email, someone on this list > > has done it. > > > > OS: Linux - UBUNTU 6.06.1 LTS with all patches applied > > SENDMAIL: 8.13.5 > > > > Problem: access.db does work. > > > > I have this in my /etc/mail/access: > > GreetPause: 25000 > > ClientRate: 100 > > ClientConn: 100 > > candrews@crackerbarrel.com REJECT > > > > And have recreated access.db with both 'make access' and 'makemap > hash > > > /etc/mail/access < /etc/mail/access' and tested both with the > command: > > > > echo "/map access candrews@crackerbarrel.com" | sendmail -bt > > > > And I get 'map_lookup: access (candrews@crackerbarrel.com) returns > > REJECT (0)' > > > > But if I send an email to candrews@crackerbarrel.com through this > > server it does not get rejected. Also, if I telnet to 'localhost 25' > > from the computer and send the message that way it is delivered too. > > > > What am I missing? I have this working on a CentOS 3.8 server with > > sendmail 8.12. > > > > > > Thanks for any help or insight you can provide!!! > > You should update sendmail to the latest version 8.12 has some problems. Best regards, Steve Steve Swaney steve@fsl.com > > > > Carl > Try "To:candrews@crackerbarrel.com REJECT" > > -- > > MailScanner is like deodorant... > You hope everybody uses it, and > you notice quickly if they don't!!!! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From Carl.Andrews at crackerbarrel.com Thu Aug 9 22:09:09 2007 From: Carl.Andrews at crackerbarrel.com (Andrews Carl 455) Date: Thu Aug 9 22:09:12 2007 Subject: Sendmail help ?? Please. In-Reply-To: Message-ID: <113A0DFC086C984AB9EFDF6B8614F075017D34CE@exchange03.CBOCS.com> I do not understand. What thread did I jump into? This was a new message?? -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Kai Schaetzl Sent: Thursday, August 09, 2007 2:31 PM To: mailscanner@lists.mailscanner.info Subject: Re: Sendmail help ?? Please. Andrews Carl 455 wrote on Thu, 9 Aug 2007 12:05:25 -0500: > I appologize for posting a non-MS question, but it has been my > expierience that if it can be done with email, someone on this list > has done it. But then please do not jump in other threads. Post a new mail. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu Aug 9 22:22:42 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 9 22:23:18 2007 Subject: More filetype/filename questions: jsp, js, mno files In-Reply-To: <200708092108.l79L8YtF000846@mxt.1bigthink.com> References: <200708092108.l79L8YtF000846@mxt.1bigthink.com> Message-ID: <46BB85A2.3050406@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Have you checked they are allowed through both the filename checks and filetype checks? dnsadmin 1bigthink.com wrote: > Hello All, > > I have attempted to search for and test allowing the following file > types which are frequently passed among my developers in .zip files. I > cannot seem to figure out how to allow them. I've figured out how to > overload the ruleset for just these users, but still cannot get these > filetypes/names through: > > *.mno > *.jsp > *.js > > It's pretty aggravating. Can anyone help? > > Thanks, > Glenn Parsons > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGu4WjEfZZRxQVtlQRAhhdAKDPhdzl/WXVmAlSFVrhnLnboZ+7ZQCg84fc rod5m2s/1MDNiO7TvV76xiw= =rwV9 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From dnsadmin at 1bigthink.com Thu Aug 9 22:49:42 2007 From: dnsadmin at 1bigthink.com (dnsadmin 1bigthink.com) Date: Thu Aug 9 22:49:57 2007 Subject: More filetype/filename questions: jsp, js, mno files In-Reply-To: <46BB85A2.3050406@ecs.soton.ac.uk> References: <200708092108.l79L8YtF000846@mxt.1bigthink.com> <46BB85A2.3050406@ecs.soton.ac.uk> Message-ID: <200708092150.l79Lo0EK005144@mxt.1bigthink.com> At 05:22 PM 8/9/2007, you wrote: >-----BEGIN PGP SIGNED MESSAGE----- >Hash: SHA1 > >Have you checked they are allowed through both the filename checks and >filetype checks? > >dnsadmin 1bigthink.com wrote: > > Hello All, > > > > I have attempted to search for and test allowing the following file > > types which are frequently passed among my developers in .zip files. I > > cannot seem to figure out how to allow them. I've figured out how to > > overload the ruleset for just these users, but still cannot get these > > filetypes/names through: > > > > *.mno > > *.jsp > > *.js > > > > It's pretty aggravating. Can anyone help? > > > > Thanks, > > Glenn Parsons > > > >Jules Hello all, Thanks for the response Julian. I have included both in filetypes and filenames and double checked my MailScanner --lint. I suspect I just don't know how to format the filetypes.rules.conf Here are what I tried in filetypes rules.conf: (tab-separated) # Especially for Developers allow \.js$ - - allow \.jsp$ - - allow \.mno$ - - allow JScript - - allow JavaServerPages - - allow mno - - Here is what I have in filename.rules.conf: ### ! Special allowances for Developers ! ### allow \.js$ - - allow \.jsp$ - - allow \.mno$ - - Thanks, Glenn Parsons From ssilva at sgvwater.com Thu Aug 9 22:58:31 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 9 23:00:05 2007 Subject: Sendmail help ?? Please. In-Reply-To: <113A0DFC086C984AB9EFDF6B8614F075017D34CE@exchange03.CBOCS.com> References: <113A0DFC086C984AB9EFDF6B8614F075017D34CE@exchange03.CBOCS.com> Message-ID: Andrews Carl 455 spake the following on 8/9/2007 2:09 PM: > I do not understand. What thread did I jump into? This was a new message?? > In your original message is the evidence. A header with the following; In-Reply-To: <25775270.14021186678279912.JavaMail.root@office.splatnix.net> Which means you opened a message and hit reply. It doesn't matter if you change the subject, that header is still there. Simple e-mail forensics 101 class dismissed! -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From MailScanner at ecs.soton.ac.uk Thu Aug 9 23:04:04 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 9 23:04:37 2007 Subject: More filetype/filename questions: jsp, js, mno files In-Reply-To: <200708092150.l79Lo0EK005144@mxt.1bigthink.com> References: <200708092108.l79L8YtF000846@mxt.1bigthink.com> <46BB85A2.3050406@ecs.soton.ac.uk> <200708092150.l79Lo0EK005144@mxt.1bigthink.com> Message-ID: <46BB8F54.9000402@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 dnsadmin 1bigthink.com wrote: > At 05:22 PM 8/9/2007, you wrote: > >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> Have you checked they are allowed through both the filename checks and >> filetype checks? >> >> dnsadmin 1bigthink.com wrote: >> > Hello All, >> > >> > I have attempted to search for and test allowing the following file >> > types which are frequently passed among my developers in .zip files. I >> > cannot seem to figure out how to allow them. I've figured out how to >> > overload the ruleset for just these users, but still cannot get these >> > filetypes/names through: >> > >> > *.mno >> > *.jsp >> > *.js >> > >> > It's pretty aggravating. Can anyone help? >> > >> > Thanks, >> > Glenn Parsons >> > >> >> Jules > > > Hello all, > > Thanks for the response Julian. I have included both in filetypes and > filenames and double checked my MailScanner --lint. > > I suspect I just don't know how to format the filetypes.rules.conf It's looking for things in the output of the "file" command when run on your files. > > Here are what I tried in filetypes rules.conf: (tab-separated) > > # Especially for Developers > > > allow \.js$ - - > allow \.jsp$ - - > allow \.mno$ - - That's for filenames, not filetypes > > allow JScript - - > allow JavaServerPages - - > allow mno - - That's not what the "file" command outputs. Please read the docs. This is explained in the comments prior to the "Filetype Rules" setting in MailScanner.conf. > > Here is what I have in filename.rules.conf: > > ### ! Special allowances for Developers ! ### > > allow \.js$ - - > allow \.jsp$ - - > allow \.mno$ - - > > Thanks, > Glenn Parsons Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGu49VEfZZRxQVtlQRAhMqAJ0eDOZlaD1rl0g2mI9E83bXH/HmHgCeIEoZ 8Nphl3wCyb/mj1XsH38Gesw= =+3lO -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Thu Aug 9 23:01:05 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 9 23:05:03 2007 Subject: More filetype/filename questions: jsp, js, mno files In-Reply-To: <200708092150.l79Lo0EK005144@mxt.1bigthink.com> References: <200708092108.l79L8YtF000846@mxt.1bigthink.com> <46BB85A2.3050406@ecs.soton.ac.uk> <200708092150.l79Lo0EK005144@mxt.1bigthink.com> Message-ID: dnsadmin 1bigthink.com spake the following on 8/9/2007 2:49 PM: > At 05:22 PM 8/9/2007, you wrote: > >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> Have you checked they are allowed through both the filename checks and >> filetype checks? >> >> dnsadmin 1bigthink.com wrote: >> > Hello All, >> > >> > I have attempted to search for and test allowing the following file >> > types which are frequently passed among my developers in .zip files. I >> > cannot seem to figure out how to allow them. I've figured out how to >> > overload the ruleset for just these users, but still cannot get these >> > filetypes/names through: >> > >> > *.mno >> > *.jsp >> > *.js >> > >> > It's pretty aggravating. Can anyone help? >> > >> > Thanks, >> > Glenn Parsons >> > >> >> Jules > > > Hello all, > > Thanks for the response Julian. I have included both in filetypes and > filenames and double checked my MailScanner --lint. > > I suspect I just don't know how to format the filetypes.rules.conf > > Here are what I tried in filetypes rules.conf: (tab-separated) > > # Especially for Developers > > > allow \.js$ - - > allow \.jsp$ - - > allow \.mno$ - - > > allow JScript - - > allow JavaServerPages - - > allow mno - - > > Here is what I have in filename.rules.conf: > > ### ! Special allowances for Developers ! ### > > allow \.js$ - - > allow \.jsp$ - - > allow \.mno$ - - > > Thanks, > Glenn Parsons If you run the linux file command on those files, what does it say? That is what you have to allow in filetypes.rules.conf. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From dnsadmin at 1bigthink.com Thu Aug 9 23:09:50 2007 From: dnsadmin at 1bigthink.com (dnsadmin 1bigthink.com) Date: Thu Aug 9 23:10:06 2007 Subject: More filetype/filename questions: jsp, js, mno files In-Reply-To: References: <200708092108.l79L8YtF000846@mxt.1bigthink.com> <46BB85A2.3050406@ecs.soton.ac.uk> <200708092150.l79Lo0EK005144@mxt.1bigthink.com> Message-ID: <200708092210.l79MA9vx007497@mxt.1bigthink.com> At 06:01 PM 8/9/2007, you wrote: >dnsadmin 1bigthink.com spake the following on 8/9/2007 2:49 PM: > > At 05:22 PM 8/9/2007, you wrote: > > > >> -----BEGIN PGP SIGNED MESSAGE----- > >> Hash: SHA1 > >> > >> Have you checked they are allowed through both the filename checks and > >> filetype checks? > >> > >> dnsadmin 1bigthink.com wrote: > >> > Hello All, > >> > > >> > I have attempted to search for and test allowing the following file > >> > types which are frequently passed among my developers in .zip files. I > >> > cannot seem to figure out how to allow them. I've figured out how to > >> > overload the ruleset for just these users, but still cannot get these > >> > filetypes/names through: > >> > > >> > *.mno > >> > *.jsp > >> > *.js > >> > > >> > It's pretty aggravating. Can anyone help? > >> > > >> > Thanks, > >> > Glenn Parsons > >> > > >> > >> Jules > > > > > > Hello all, > > > > Thanks for the response Julian. I have included both in filetypes and > > filenames and double checked my MailScanner --lint. > > > > I suspect I just don't know how to format the filetypes.rules.conf > > > > Here are what I tried in filetypes rules.conf: (tab-separated) > > > > # Especially for Developers > > > > > > allow \.js$ - - > > allow \.jsp$ - - > > allow \.mno$ - - > > > > allow JScript - - > > allow JavaServerPages - - > > allow mno - - > > > > Here is what I have in filename.rules.conf: > > > > ### ! Special allowances for Developers ! ### > > > > allow \.js$ - - > > allow \.jsp$ - - > > allow \.mno$ - - > > > > Thanks, > > Glenn Parsons >If you run the linux file command on those files, what does it say? >That is what you have to allow in filetypes.rules.conf. (Rock hits brain).. Ahhhh! Thanks All! Cheers! Glenn From ajos1 at onion.demon.co.uk Thu Aug 9 23:20:41 2007 From: ajos1 at onion.demon.co.uk (ajos1@onion.demon.co.uk) Date: Thu Aug 9 23:20:46 2007 Subject: Correction for - SAVI missing Message-ID: - On my system... when I do: -------------------------- MailScanner --version | grep -i missing It says: -------- missing SAVI My question is... ----------------- Is SAVI still needed... I only ask as it is *NOT* amongst the group of perl RPMs in the MailScanner Tar.gz . == ===================================================================== = = "Where did you learn about ducks?" - Ironside = = Need help dealing with Parking Tickets, Bailiffs, Capita or NTL... = Call... +44 8457 90 90 90 http://www.samaritans.org/ = ===================================================================== From ssilva at sgvwater.com Thu Aug 9 23:23:00 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 9 23:23:19 2007 Subject: More filetype/filename questions: jsp, js, mno files In-Reply-To: <200708092210.l79MA9vx007497@mxt.1bigthink.com> References: <200708092108.l79L8YtF000846@mxt.1bigthink.com> <46BB85A2.3050406@ecs.soton.ac.uk> <200708092150.l79Lo0EK005144@mxt.1bigthink.com> <200708092210.l79MA9vx007497@mxt.1bigthink.com> Message-ID: dnsadmin 1bigthink.com spake the following on 8/9/2007 3:09 PM: > At 06:01 PM 8/9/2007, you wrote: > >> dnsadmin 1bigthink.com spake the following on 8/9/2007 2:49 PM: >> > At 05:22 PM 8/9/2007, you wrote: >> > >> >> -----BEGIN PGP SIGNED MESSAGE----- >> >> Hash: SHA1 >> >> >> >> Have you checked they are allowed through both the filename checks and >> >> filetype checks? >> >> >> >> dnsadmin 1bigthink.com wrote: >> >> > Hello All, >> >> > >> >> > I have attempted to search for and test allowing the following file >> >> > types which are frequently passed among my developers in .zip >> files. I >> >> > cannot seem to figure out how to allow them. I've figured out how to >> >> > overload the ruleset for just these users, but still cannot get >> these >> >> > filetypes/names through: >> >> > >> >> > *.mno >> >> > *.jsp >> >> > *.js >> >> > >> >> > It's pretty aggravating. Can anyone help? >> >> > >> >> > Thanks, >> >> > Glenn Parsons >> >> > >> >> >> >> Jules >> > >> > >> > Hello all, >> > >> > Thanks for the response Julian. I have included both in filetypes and >> > filenames and double checked my MailScanner --lint. >> > >> > I suspect I just don't know how to format the filetypes.rules.conf >> > >> > Here are what I tried in filetypes rules.conf: (tab-separated) >> > >> > # Especially for Developers >> > >> > >> > allow \.js$ - - >> > allow \.jsp$ - - >> > allow \.mno$ - - >> > >> > allow JScript - - >> > allow JavaServerPages - - >> > allow mno - - >> > >> > Here is what I have in filename.rules.conf: >> > >> > ### ! Special allowances for Developers ! ### >> > >> > allow \.js$ - - >> > allow \.jsp$ - - >> > allow \.mno$ - - >> > >> > Thanks, >> > Glenn Parsons >> If you run the linux file command on those files, what does it say? >> That is what you have to allow in filetypes.rules.conf. > > (Rock hits brain).. Ahhhh! > > Thanks All! > > Cheers! > Glenn Here is a stress reduction kit for you! Print this e-mail and tape on the wall. **************************************************************** * * * * * * * * * BANG * * * * HEAD * * * * HERE! * * * * * * * * * **************************************************************** -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From matt at coders.co.uk Thu Aug 9 23:36:31 2007 From: matt at coders.co.uk (Matt Hampton) Date: Thu Aug 9 23:37:01 2007 Subject: Watermarking quirks still in 4.62.8 In-Reply-To: References: <7EF0EE5CB3B263488C8C18823239BEBA013584B1@HC-MBX02.herefordshire.gov.uk> <46ADDBBA.3080701@coders.co.uk><7EF0EE5CB3B263488C8C18823239BEBA013584C5@HC-MBX02.herefordshire.gov.uk> <46BA67F2.1070005@rheelweb.co.nz> <7EF0EE5CB3B263488C8C18823239BEBA03CEFC@HC-MBX02.herefordshire.gov.uk> Message-ID: <46BB96EF.7070009@coders.co.uk> Scott Silva wrote: > Randal, Phil spake the following on 8/9/2007 4:57 AM: >> No, but there has been some discussion on the list. >> >> IIRC, some MTAs include original headers in receipt messages, but >> Exchange 2003 isn't one of them. Knowing my dodgy memory, I've probably >> got that wrong. >> > I am having the problem with Outlook users on my non-exchange system, so it is > not just MTA specific. > My testing shows that it is Outlook when using POP3/IMAP accounts and Exchange 2007. matt From res at ausics.net Thu Aug 9 23:37:04 2007 From: res at ausics.net (Res) Date: Thu Aug 9 23:37:15 2007 Subject: Spamhaus issues? In-Reply-To: References: <7EF0EE5CB3B263488C8C18823239BEBA03CEFD@HC-MBX02.herefordshire.gov.uk> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Thu, 9 Aug 2007, Kai Schaetzl wrote: > Res wrote on Thu, 9 Aug 2007 22:19:15 +1000 (EST): > >> They dont have a good hit ratio, I've just just grabed the last 8 blocked >> IPs by RBL's and cbl only lists 1 of them, where as njabl, spamcop and >> sorbs all listed all those 8 IP's > > That doesn't mean anything. The three lists you mention are aggregated lists > by various criteria. For instance that IP might have been on SORBS because > it's dynamic. And it will stay there no matter if the mail coming from there I am fully aware they use aggregate zones, it has several methods and you can use or exclude what you dont want within sendmails extra enhanced fields. Since 7 they come from .cn .kr .br I can much rest assured they deserve to be in the spam lists. > is spam or ham. CBL doesn't include dynamic IP space because it is dynamic > IP space. Thats there decision, I dont have to use SORBS's dynamic if I dont want to, but I choose to do so, because no dynamic user has any need to be running a mail server AFAIC. - -- Cheers Res -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (GNU/Linux) iD8DBQFGu5cQsWhAmSIQh7MRAvKJAKCTQYbrnzVUBBoAMTS8A81/WTdT/ACgpTU4 +AYnC0UCSlvtOkR1k4CzOWA= =a5ne -----END PGP SIGNATURE----- From ssilva at sgvwater.com Thu Aug 9 23:44:07 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 9 23:44:16 2007 Subject: Correction for - SAVI missing In-Reply-To: References: Message-ID: ajos1@onion.demon.co.uk spake the following on 8/9/2007 4:20 PM: > - > > On my system... when I do: > -------------------------- > MailScanner --version | grep -i missing > > It says: > -------- > missing SAVI > > My question is... > ----------------- > Is SAVI still needed... I only ask as it is *NOT* amongst the group of perl RPMs in the MailScanner Tar.gz . IF you do a MailScanner --version without the grep, you will see that it is in a section titled "Optional module versions are:" So it isn't required, it is optional, and only if you are using the Sophos virus scanner. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Thu Aug 9 23:45:27 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 9 23:50:07 2007 Subject: Watermarking quirks still in 4.62.8 In-Reply-To: <46BB96EF.7070009@coders.co.uk> References: <7EF0EE5CB3B263488C8C18823239BEBA013584B1@HC-MBX02.herefordshire.gov.uk> <46ADDBBA.3080701@coders.co.uk><7EF0EE5CB3B263488C8C18823239BEBA013584C5@HC-MBX02.herefordshire.gov.uk> <46BA67F2.1070005@rheelweb.co.nz> <7EF0EE5CB3B263488C8C18823239BEBA03CEFC@HC-MBX02.herefordshire.gov.uk> <46BB96EF.7070009@coders.co.uk> Message-ID: Matt Hampton spake the following on 8/9/2007 3:36 PM: > Scott Silva wrote: >> Randal, Phil spake the following on 8/9/2007 4:57 AM: >>> No, but there has been some discussion on the list. >>> >>> IIRC, some MTAs include original headers in receipt messages, but >>> Exchange 2003 isn't one of them. Knowing my dodgy memory, I've probably >>> got that wrong. >>> >> I am having the problem with Outlook users on my non-exchange system, so it is >> not just MTA specific. >> > > My testing shows that it is Outlook when using POP3/IMAP accounts and > Exchange 2007. > > matt So again it is Microsoft's fault for not following common practices and re-engineering standards to fit their ideas. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From matt at coders.co.uk Thu Aug 9 23:54:07 2007 From: matt at coders.co.uk (Matt Hampton) Date: Thu Aug 9 23:54:40 2007 Subject: Watermarking quirks still in 4.62.8 In-Reply-To: References: <7EF0EE5CB3B263488C8C18823239BEBA013584B1@HC-MBX02.herefordshire.gov.uk> <46ADDBBA.3080701@coders.co.uk><7EF0EE5CB3B263488C8C18823239BEBA013584C5@HC-MBX02.herefordshire.gov.uk> <46BA67F2.1070005@rheelweb.co.nz> <7EF0EE5CB3B263488C8C18823239BEBA03CEFC@HC-MBX02.herefordshire.gov.uk> <46BB96EF.7070009@coders.co.uk> Message-ID: <46BB9B0F.506@coders.co.uk> Scott Silva wrote: > Matt Hampton spake the following on 8/9/2007 3:36 PM: >> Scott Silva wrote: >>> Randal, Phil spake the following on 8/9/2007 4:57 AM: >>>> No, but there has been some discussion on the list. >>>> >>>> IIRC, some MTAs include original headers in receipt messages, but >>>> Exchange 2003 isn't one of them. Knowing my dodgy memory, I've probably >>>> got that wrong. >>>> >>> I am having the problem with Outlook users on my non-exchange system, so it is >>> not just MTA specific. >>> >> My testing shows that it is Outlook when using POP3/IMAP accounts and >> Exchange 2007. >> >> matt > So again it is Microsoft's fault for not following common practices and > re-engineering standards to fit their ideas. > no comment :-) matt From Jamesp at MusicReports.com Fri Aug 10 00:14:46 2007 From: Jamesp at MusicReports.com (James D. Parra) Date: Fri Aug 10 00:14:55 2007 Subject: Mail Scanner using 99% of CPU Message-ID: <531F1E080638384C9623B00D71AA546D050201D0@exchange.musicreports.com> Hello, Don't know what happened, but all of a sudden Mail Scanner is using 99% of the CPU. Mail is sitting in the queue for a bit of time before it gets processed. Any ideas on where to begin trouble shooting this? Running Mail Scanner on Suse 10.0 with postfix. Thank you, James From ajos1 at onion.demon.co.uk Fri Aug 10 00:15:36 2007 From: ajos1 at onion.demon.co.uk (ajos1@onion.demon.co.uk) Date: Fri Aug 10 00:15:39 2007 Subject: SAVI - Thanks for the replies Message-ID: - Thanks for the 3 replies... much appreciated... From res at ausics.net Fri Aug 10 00:33:50 2007 From: res at ausics.net (Res) Date: Fri Aug 10 00:34:13 2007 Subject: OT (like most things here anyway) BIND8 EOL Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 whereas BIND9 is now 8 years old, and BIND9 is performance-competitive against BIND8, and BIND9 conforms to more of the DNS protocol than BIND8, and BIND9 is more secure and more portable than BIND8, we are declaring BIND8 to be in "end of life" (like BIND4). posted here because I know many of you by your own admission have bad habits of not updating software. - -- Cheers Res -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (GNU/Linux) iD8DBQFGu6ResWhAmSIQh7MRAtgsAJ9c2ZVHzfiRxQuJh/k5rDhZKQeWAACcCPSR 3MHspLegf9MhfjoDMkKVV3U= =K/2c -----END PGP SIGNATURE----- From ssilva at sgvwater.com Fri Aug 10 00:45:28 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Aug 10 00:45:50 2007 Subject: OT (like most things here anyway) BIND8 EOL In-Reply-To: References: Message-ID: Res spake the following on 8/9/2007 4:33 PM: > > whereas BIND9 is now 8 years old, > and BIND9 is performance-competitive against BIND8, > and BIND9 conforms to more of the DNS protocol than BIND8, > and BIND9 is more secure and more portable than BIND8, > we are declaring BIND8 to be in "end of life" (like BIND4). > > > posted here because I know many of you by your own admission have bad > habits of not updating software. > I bet there is still a lot of bind4 installs running around the world! But not here. So bind9 is 8 years old? Bind10 should be just around the end of the decade somewhere. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From donald.dawson at bakerbotts.com Fri Aug 10 01:10:12 2007 From: donald.dawson at bakerbotts.com (donald.dawson@bakerbotts.com) Date: Fri Aug 10 01:10:15 2007 Subject: FW: Performance problem after upgrading from SA 3.2.1 to 3.2.2 Message-ID: > I had posted before, but we couldn't figure out what was adding 3+ > seconds processing time after I upgraded from SA 3.2.1 to 3.2.2. > > It's the following plugin. I have tested loading and commenting out > the plugin - it's the culprit. SA 3.2.2 automatically adds several > plugins automatically. > > # ASN - Look up the Autonomous System Number of the connecting IP > # and create a header containing ASN data for bayes tokenization. > # See plugin's POD docs for usage info. > # > #loadplugin Mail::SpamAssassin::Plugin::ASN > > more info. here: > http://spamassassin.apache.org/full/3.2.x/doc/Mail_SpamAssassin_Plugin > _ASN.html > > Donald > > Donald Dawson > Security Administrator > Baker Botts L.L.P. > 713-229-2183 > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070809/66021d61/attachment.html From lists at gmnet.net Fri Aug 10 02:06:28 2007 From: lists at gmnet.net (mail) Date: Fri Aug 10 02:06:33 2007 Subject: MailScanner and Gentoo Message-ID: <1186707988.17964.77.camel@thor.greenbuzz.net> Hi, I am setting up a new server for may mail services. I am planning to use gentoo. Does anyone use gentoo portage to deal with all this? (Mailscanner, Spammassasin, ClamAV, Mailman, Sendmail, pop, hord, Mailwatch, etc...) Any advice? Thanks! rick From Jeff.Mills at versacold.com.au Fri Aug 10 02:20:38 2007 From: Jeff.Mills at versacold.com.au (Jeff Mills) Date: Fri Aug 10 02:20:43 2007 Subject: MailScanner and Gentoo Message-ID: > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of mail > Sent: Friday, 10 August 2007 11:06 AM > To: mailscanner@lists.mailscanner.info > Subject: MailScanner and Gentoo > > Hi, > > I am setting up a new server for may mail services. I am > planning to use gentoo. > > Does anyone use gentoo portage to deal with all this? > (Mailscanner, Spammassasin, ClamAV, Mailman, Sendmail, pop, > hord, Mailwatch, etc...) I use Gentoo, but I don't use portage. Apparently the ebuild for MailScanner in Gentoo is pretty nasty. I'm doing MailScanner, Spamassassin, ClamAV, bitdefender, Postfix, Mailatch. I can send you a copy of the init.d script I'm using. From v at vladville.com Fri Aug 10 05:32:00 2007 From: v at vladville.com (Vlad Mazek) Date: Fri Aug 10 05:32:05 2007 Subject: Mailscanner RBL checks In-Reply-To: References: Message-ID: Scott, Yes it does as a matter of fact, however, I am unable to find any SA rule that is looking at the RBL, which is what started the entire confusion for me to begin with. Something is causing a lot of RBL lookups and I just can't track down exactly what; my problem is that I don't want to completely turn off the RBL lookups (easy) I just don't want it looking at 16 different lists for every incoming message.. -Vlad On 8/9/07, Scott Silva wrote: > > Vlad Mazek spake the following on 8/9/2007 9:59 AM: > > I'm sorry I am just not following; my mailscanner.cf > > has only one line: > > > > dns_available yes > > > > Yet, it seems to be querying the external RBL's: > > SpamAssassin (not cached, score= 16.885, required 5, autolearn=disabled, > > FH_RELAY_NODNS 1.25, HELO_EQ_IP_ADDR 1.12, HTML_MESSAGE 0.00, > > HTML_OBFUSCATE_05_10 0.57, MIME_HTML_ONLY 1.67, RCVD_IN_BL_SPAMCOP_NET > > 2.19, RCVD_IN_PBL 0.51, RDNS_NONE 0.10, URIBL_BLACK 1.96, URIBL_JP_SURBL > > 2.86, URIBL_OB_SURBL 2.13, URIBL_SC_SURBL 2.52 > > > > My question is simply where/what is telling SpamAssassin to query all > > these RBLs because my MailScanner.cf doesn't list any RBLs to be called > > (line is commented out completely) > Spamassassin has several tests it does all by itself that are indepentent > of > mailscanner. Spamassassin tests rbl's and gives a score that is added > together. When you use rbl's in mailscanner they are just flagged as spam > if > they hit, independent of how reliable a rbl might be. > > As you were told in the last mail, if you do not want rbl tests in > spamassassin, you have to add a line for each one in mailscanner.cf. > As an example, if you didn't want to test for RCVD_IN_BL_SPAMCOP_NET > you add the following line; > score RCVD_IN_BL_SPAMCOP_NET 0 > > Does this clear things up a little more? > > > -- > > MailScanner is like deodorant... > You hope everybody uses it, and > you notice quickly if they don't!!!! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- -Vlad -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070810/2103acde/attachment.html From Carl.Andrews at crackerbarrel.com Fri Aug 10 06:11:14 2007 From: Carl.Andrews at crackerbarrel.com (Andrews Carl 455) Date: Fri Aug 10 06:11:20 2007 Subject: Sendmail help ?? Please. In-Reply-To: Message-ID: <113A0DFC086C984AB9EFDF6B8614F075017D34D4@exchange03.CBOCS.com> Sorry, I did not realize that would make a difference. I opened a message to the newsgroup, clicked reply and deleted the message body and the subject ( I promise not to do this again and appologize to whomever I stepped on it was completely unintentional) . I know I am showing my ignorance, but I do not understand how I offened. I use microsoft outlook as an email client, do other clients behave differently because of information contained within the headers? I am not trying to be dense, in my client this appears as a separate thread. Thanks again, Carl -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Scott Silva Sent: Thursday, August 09, 2007 4:59 PM To: mailscanner@lists.mailscanner.info Subject: Re: Sendmail help ?? Please. Andrews Carl 455 spake the following on 8/9/2007 2:09 PM: > I do not understand. What thread did I jump into? This was a new message?? > In your original message is the evidence. A header with the following; In-Reply-To: <25775270.14021186678279912.JavaMail.root@office.splatnix.net> Which means you opened a message and hit reply. It doesn't matter if you change the subject, that header is still there. Simple e-mail forensics 101 class dismissed! -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From martinh at solidstatelogic.com Fri Aug 10 07:26:07 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Fri Aug 10 07:26:15 2007 Subject: Mail Scanner using 99% of CPU In-Reply-To: <531F1E080638384C9623B00D71AA546D050201D0@exchange.musicreports.com> Message-ID: <33ae840b4147f14eb8690b07648caddc@solidstatelogic.com> James There's some stuff on the wiki about this.. http://wiki.mailscanner.info/doku.php?id=documentation:test_troubleshoot:performance -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of James D. Parra > Sent: 10 August 2007 00:15 > To: mailscanner@lists.mailscanner.info > Subject: Mail Scanner using 99% of CPU > > Hello, > > Don't know what happened, but all of a sudden Mail Scanner is using 99% of > the CPU. Mail is sitting in the queue for a bit of time before it gets > processed. > > Any ideas on where to begin trouble shooting this? Running Mail Scanner on > Suse 10.0 with postfix. > > Thank you, > > James > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From uxbod at splatnix.net Fri Aug 10 08:31:50 2007 From: uxbod at splatnix.net (UxBoD) Date: Fri Aug 10 08:22:20 2007 Subject: MailScanner and Gentoo In-Reply-To: Message-ID: <6214686.14051186731110048.JavaMail.root@office.splatnix.net> Same here. I compile MailScanner outside of Portage as I like to keep up with the betas. Everything else though is done via Portage. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From gmatt at nerc.ac.uk Fri Aug 10 08:56:46 2007 From: gmatt at nerc.ac.uk (Greg Matthews) Date: Fri Aug 10 08:57:01 2007 Subject: FW: Performance problem after upgrading from SA 3.2.1 to 3.2.2 In-Reply-To: References: Message-ID: <46BC1A3E.6090005@nerc.ac.uk> donald.dawson@bakerbotts.com wrote: > I had posted before, but we couldn't figure out what was adding 3+ > seconds processing time after I upgraded from SA 3.2.1 to 3.2.2. > > It's the following plugin. I have tested loading and commenting out the > plugin - it's the culprit. SA 3.2.2 automatically adds several plugins > automatically. are you using a caching name server on your MS box? This should smooth out a lot of the lookups. G -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford -- This message (and any attachments) is for the recipient only. NERC is subject to the Freedom of Information Act 2000 and the contents of this email and any reply you make may be disclosed by NERC unless it is exempt from release under the Act. Any material supplied to NERC may be stored in an electronic records management system. From daniel at bokko.nl Fri Aug 10 09:08:01 2007 From: daniel at bokko.nl (Daniel Eiland) Date: Fri Aug 10 09:08:04 2007 Subject: MCP not working In-Reply-To: <5466423.13991186676395099.JavaMail.root@office.splatnix.net> Message-ID: <20070810075552.6C1AB11A04@panther.webvanced.nl> I get 4 warnings: [26720] warn: config: failed to parse line, skipping, in "/usr/local/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf": use_razor1 0 [26720] warn: config: failed to parse line, skipping, in "/usr/local/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf": decode_attachments 1 [26720] warn: config: failed to parse line, skipping, in "/usr/local/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf": use_razor1 0 [26720] warn: config: failed to parse line, skipping, in "/usr/local/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf": decode_attachments 1 I also see that the cf files are not read from /usr/local/etc/MailScanner/mcp But from [26720] dbg: config: using "/usr/local/etc/mail/spamassassin" for site rules dir -----Oorspronkelijk bericht----- Van: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Namens UxBoD Verzonden: donderdag 9 augustus 2007 18:20 Aan: MailScanner discussion Onderwerp: Re: MCP not working spamassassin --config-file=/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf -D --lint Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Daniel Eiland" To: "MailScanner discussion" Sent: Thursday, August 9, 2007 5:01:48 PM (GMT) Europe/London Subject: RE: MCP not working Yes. I was wondering, is there some way to --lint the MCP rules? -----Oorspronkelijk bericht----- Van: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Namens Kai Schaetzl Verzonden: donderdag 9 augustus 2007 17:31 Aan: mailscanner@lists.mailscanner.info Onderwerp: Re: MCP not working Daniel Eiland wrote on Thu, 9 Aug 2007 14:22:42 +0200: > I is just like mailscanner or spamassassin does not find the cf i created. Yes .... You did a restart of MS, did you? Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From arjan at anymore.nl Fri Aug 10 09:11:00 2007 From: arjan at anymore.nl (Arjan Schrijver) Date: Fri Aug 10 09:12:15 2007 Subject: MailScanner and Gentoo In-Reply-To: <6214686.14051186731110048.JavaMail.root@office.splatnix.net> References: <6214686.14051186731110048.JavaMail.root@office.splatnix.net> Message-ID: <46BC1D94.1060503@anymore.nl> We're using everything from portage. For MailScanner and some others we maintain our own overlay so we can keep up with the versions as they come out. Regards, Arjan UxBoD wrote: > Same here. I compile MailScanner outside of Portage as I like to keep up with the betas. Everything else though is done via Portage. > > Regards, > > --[ UxBoD ]-- > From MailScanner at ecs.soton.ac.uk Fri Aug 10 12:16:05 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 10 12:16:19 2007 Subject: FW: Performance problem after upgrading from SA 3.2.1 to 3.2.2 In-Reply-To: References: Message-ID: <46BC48F5.4080606@ecs.soton.ac.uk> Thank you for posting that! For a bit of help with Bayes I don't think it's worth the extra wait, is it? Cheers, Jules. donald.dawson@bakerbotts.com wrote: > > I had posted before, but we couldn't figure out what was adding 3+ > seconds processing time after I upgraded from SA 3.2.1 to 3.2.2. > > It's the following plugin. I have tested loading and commenting out > the plugin - it's the culprit. SA 3.2.2 automatically adds several > plugins automatically. > > # ASN - Look up the Autonomous System Number of the connecting IP > # and create a header containing ASN data for bayes tokenization. > # See plugin's POD docs for usage info. > # > #loadplugin Mail::SpamAssassin::Plugin::ASN > > more info. here: > _http://spamassassin.apache.org/full/3.2.x/doc/Mail_SpamAssassin_Plugin_ASN.html_ > > > Donald > > Donald Dawson > Security Administrator > Baker Botts L.L.P. > 713-229-2183 > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From maillists at conactive.com Fri Aug 10 12:24:36 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Fri Aug 10 12:24:37 2007 Subject: Sendmail help ?? Please. In-Reply-To: <113A0DFC086C984AB9EFDF6B8614F075017D34CD@exchange03.CBOCS.com> References: <113A0DFC086C984AB9EFDF6B8614F075017D34CD@exchange03.CBOCS.com> Message-ID: Andrews Carl 455 wrote on Thu, 9 Aug 2007 16:08:25 -0500: > I am using 8.13. Is that not the latest? 8.14 is the latest. Anyway, 8.12 works just fine in regard to what you want to achieve. You are doing something wrong, but it's not obvious what it is. I suggest you install Webmin on your machine and use that for administering that portion of sendmail, that is *much* easier than editing access and running makemap each time you want to change something. BTW, I think this is wrong: 'makemap hash /etc/mail/access < /etc/mail/access' correct: 'makemap hash /etc/mail/access.db < /etc/mail/access' notice the missing suffix? You may have actually overwritten your original access file. Don't you get any kind of an error message? I also think that simply doing a "makemap access" in /etc/mail should produce your access.db if I remember right. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Fri Aug 10 12:24:36 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Fri Aug 10 12:24:42 2007 Subject: Sendmail help ?? Please. In-Reply-To: <113A0DFC086C984AB9EFDF6B8614F075017D34D4@exchange03.CBOCS.com> References: <113A0DFC086C984AB9EFDF6B8614F075017D34D4@exchange03.CBOCS.com> Message-ID: Andrews Carl 455 wrote on Fri, 10 Aug 2007 00:11:14 -0500: > clicked reply That's what you should do if you want to "reply". If you don't reply you don't hit "reply", that simple ;-) A thread is not determined by the subject, but by the in-reply-to or references headers. The subject is only used if neither of these headers is available. If you want to post a new question, then simply hit "new message" or what it is called in Outlook and enter the mailing-list email address (some mail client's, like mine, will enter it automatically ..). > I am not trying to be dense, in my client this appears as a separate thread. Because your client is dumb. Actually, I think Outlook *can* thread correctly, but you may need to enable it or maybe it automatically overrides correct threading if the subject doesn't match. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Fri Aug 10 12:31:19 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Fri Aug 10 12:31:21 2007 Subject: Mailscanner RBL checks In-Reply-To: References: Message-ID: Vlad Mazek wrote on Fri, 10 Aug 2007 00:32:00 -0400: > Yes it does as a matter of fact, however, I am unable to find any SA rule that is looking at the RBL and where are you looking for them? Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Fri Aug 10 12:31:19 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Fri Aug 10 12:31:23 2007 Subject: Performance problem after upgrading from SA 3.2.1 to 3.2.2 In-Reply-To: <46BC48F5.4080606@ecs.soton.ac.uk> References: <46BC48F5.4080606@ecs.soton.ac.uk> Message-ID: A sidenote. He also posted this to the sa list. This plugin does *not* get used automatically and it wasn't added with 3.2.2 as he claims. It was added with 3.2.0 and you have to uncomment it for use. So, normally it's off! One should also read the documentation for it, before using it! Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Fri Aug 10 13:08:13 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Fri Aug 10 13:08:15 2007 Subject: Spamhaus issues? In-Reply-To: References: <7EF0EE5CB3B263488C8C18823239BEBA03CEFD@HC-MBX02.herefordshire.gov.uk> Message-ID: Res wrote on Fri, 10 Aug 2007 08:37:04 +1000 (EST): > Thats there decision, I dont have to use SORBS's dynamic if I dont want > to, but I choose to do so, because no dynamic user has any need to be > running a mail server AFAIC. That's not the point. These hosts are *by definition* not on CBL, they do not list by technical criteria but by reported abuse. You claimed "They dont have a good hit ratio". Claiming something like that is simply nonsense as you cannot compare the lists. If you deem CBL not enough for your purposes (and there are good grounds for that, I'm only using it as part of ZEN) that's perfectly understandable. But claiming "they don't have a good hit ratio" is derogatory and wrong. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From glenn.steen at gmail.com Fri Aug 10 13:38:49 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Aug 10 13:38:51 2007 Subject: OT (like most things here anyway) BIND8 EOL In-Reply-To: References: Message-ID: <223f97700708100538n2e5dfbe4x33fb5fd67e52ffee@mail.gmail.com> On 10/08/07, Scott Silva wrote: > Res spake the following on 8/9/2007 4:33 PM: > > > > whereas BIND9 is now 8 years old, > > and BIND9 is performance-competitive against BIND8, > > and BIND9 conforms to more of the DNS protocol than BIND8, > > and BIND9 is more secure and more portable than BIND8, > > we are declaring BIND8 to be in "end of life" (like BIND4). > > > > > > posted here because I know many of you by your own admission have bad > > habits of not updating software. > > > I bet there is still a lot of bind4 installs running around the world! > > But not here. > > So bind9 is 8 years old? Bind10 should be just around the end of the decade > somewhere. Thanks Noel, I imagine though that those who need read that... Might not be reading this list at all:-). And thanks both of you for the laugh. (I need all the positive thinking I can grasp at ATM, finding myself in somewhat of a quagmire... One that more work can't, for once, can't cure... Emotions, who needs them, eh:-) > > MailScanner is like deodorant... > You hope everybody uses it, and > you notice quickly if they don't!!!! > Still my #1 favorite sig:) -- -- Glenn (who would've put this reply off-list, if only Res would've accepted that... He doesn't, so blame him:-):-) email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From donald.dawson at bakerbotts.com Fri Aug 10 13:45:41 2007 From: donald.dawson at bakerbotts.com (donald.dawson@bakerbotts.com) Date: Fri Aug 10 13:45:43 2007 Subject: Performance problem after upgrading from SA 3.2.1 to 3.2.2 In-Reply-To: Message-ID: Kai, When I installed SA 3.2.2 from the package from spamassassin.org, it did not add any plugins or uncomment any plugins - you are correct. On this one MX box I used the tarball from the mailscanner.info site that had clamav and spamassassin 3.2.2 - I'm wondering if that process may have added the plugin. That process may have appended these plugins. loadplugin Mail::SpamAssassin::Plugin::RelayCountry loadplugin Mail::SpamAssassin::Plugin::SPF loadplugin Mail::SpamAssassin::Plugin::URIDNSBL loadplugin Mail::SpamAssassin::Plugin::ASN You are also correct, and each added plugin should be reviewed and tested to see if processing time is affected (logging options in MailScanner that show time per message when processing new batches). It's sometimes difficult to determine if a plugin is necessary and all of the ramifications of adding it. Point taken though. Thanks, Donald -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Kai Schaetzl Sent: Friday, August 10, 2007 6:31 AM To: mailscanner@lists.mailscanner.info Subject: Re: Performance problem after upgrading from SA 3.2.1 to 3.2.2 A sidenote. He also posted this to the sa list. This plugin does *not* get used automatically and it wasn't added with 3.2.2 as he claims. It was added with 3.2.0 and you have to uncomment it for use. So, normally it's off! One should also read the documentation for it, before using it! Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From glenn.steen at gmail.com Fri Aug 10 13:55:46 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Aug 10 13:55:48 2007 Subject: MCP not working In-Reply-To: <20070810075552.6C1AB11A04@panther.webvanced.nl> References: <5466423.13991186676395099.JavaMail.root@office.splatnix.net> <20070810075552.6C1AB11A04@panther.webvanced.nl> Message-ID: <223f97700708100555j60d7be04h181d0e044229763@mail.gmail.com> On 10/08/07, Daniel Eiland wrote: > I get 4 warnings: > > [26720] warn: config: failed to parse line, skipping, in > "/usr/local/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf": use_razor1 0 > [26720] warn: config: failed to parse line, skipping, in > "/usr/local/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf": > decode_attachments 1 > [26720] warn: config: failed to parse line, skipping, in > "/usr/local/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf": use_razor1 0 > [26720] warn: config: failed to parse line, skipping, in > "/usr/local/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf": > decode_attachments 1 These are quite OK, ignore them. The reason is that the newer SA versions don't have these keywords built in, rather loaded from specific plugins... So when you don't load the plugins, you don't have the setting to turn those functions off... But they are still off. Only warnings, so harmless. > I also see that the cf files are not read from > /usr/local/etc/MailScanner/mcp > But from > [26720] dbg: config: using "/usr/local/etc/mail/spamassassin" for site rules > dir You need be more like MCP itself... Something like spamassassin --config-file=/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --siteconfigpath=/etc/MailScanner/mcp -p /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --lint -D 2>&1 | less -e ... should get you there:-). Far better than to lint like this, is to actually use that on a text file wemulating an actual message that it should match... Just do: spamassassin --config-file=/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --siteconfigpath=/etc/MailScanner/mcp -p /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf -t -D < /path/to/file 2>&1 | less -e ... and you should see whether the rule you're testing triggers or not. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Fri Aug 10 14:06:57 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Aug 10 14:07:00 2007 Subject: Sendmail help ?? Please. In-Reply-To: References: <113A0DFC086C984AB9EFDF6B8614F075017D34D4@exchange03.CBOCS.com> Message-ID: <223f97700708100606v411d1be1y33ea72c094558bd9@mail.gmail.com> On 10/08/07, Kai Schaetzl wrote: > Andrews Carl 455 wrote on Fri, 10 Aug 2007 00:11:14 -0500: > > > clicked reply > > That's what you should do if you want to "reply". If you don't reply you don't > hit "reply", that simple ;-) A thread is not determined by the subject, but by > the in-reply-to or references headers. The subject is only used if neither of > these headers is available. If you want to post a new question, then simply > hit "new message" or what it is called in Outlook and enter the mailing-list > email address (some mail client's, like mine, will enter it automatically > ..). > > > I am not trying to be dense, in my client this appears as a separate thread. > > Because your client is dumb. Actually, I think Outlook *can* thread correctly, > but you may need to enable it or maybe it automatically overrides correct > threading if the subject doesn't match. Well, it can and it can't. At least before I quit using it for mailing lists (a few years back) it used to do the most horrendous things to threading. Might be a setup issue, I don't really trust the windoze admins/m-sexchange admins to know their sh*t:-). > Kai > Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From Carl.Andrews at crackerbarrel.com Fri Aug 10 15:19:11 2007 From: Carl.Andrews at crackerbarrel.com (Andrews Carl 455) Date: Fri Aug 10 15:19:15 2007 Subject: Sendmail help ?? Please. In-Reply-To: Message-ID: <113A0DFC086C984AB9EFDF6B8614F075017D34DE@exchange03.CBOCS.com> > Because your client is dumb. I could not agree more! That much I _DID_ know :-> From Carl.Andrews at crackerbarrel.com Fri Aug 10 15:23:04 2007 From: Carl.Andrews at crackerbarrel.com (Andrews Carl 455) Date: Fri Aug 10 15:23:07 2007 Subject: Sendmail help ?? Please. In-Reply-To: Message-ID: <113A0DFC086C984AB9EFDF6B8614F075017D34DF@exchange03.CBOCS.com> > I suggest you install Webmin on your machine and use Thanks I will give that a try. >BTW, I think this is wrong: >'makemap hash /etc/mail/access < /etc/mail/access' >correct: >'makemap hash /etc/mail/access.db < /etc/mail/access' >notice the missing suffix? >You may have actually overwritten your original access file. Don't you get >any kind of an error message? I thought it odd myself, but the command is right off the sendmail.org page and it creates the .db. - http://www.sendmail.org/tips/relaying.php . Thanks again, Carl From gmatt at nerc.ac.uk Fri Aug 10 15:42:40 2007 From: gmatt at nerc.ac.uk (Greg Matthews) Date: Fri Aug 10 15:43:07 2007 Subject: Sendmail help ?? Please. In-Reply-To: <113A0DFC086C984AB9EFDF6B8614F075017D34DF@exchange03.CBOCS.com> References: <113A0DFC086C984AB9EFDF6B8614F075017D34DF@exchange03.CBOCS.com> Message-ID: <46BC7960.5060609@nerc.ac.uk> Andrews Carl 455 wrote: >> I suggest you install Webmin on your machine and use > Thanks I will give that a try. > >> BTW, I think this is wrong: >> 'makemap hash /etc/mail/access < /etc/mail/access' >> correct: >> 'makemap hash /etc/mail/access.db < /etc/mail/access' >> notice the missing suffix? >> You may have actually overwritten your original access file. Don't you > get >> any kind of an error message? > > I thought it odd myself, but the command is right off the sendmail.org > page and it creates the .db. - http://www.sendmail.org/tips/relaying.php > . > the command as shown if fine. makemap just does the right thing. > > Thanks again, > Carl -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford -- This message (and any attachments) is for the recipient only. NERC is subject to the Freedom of Information Act 2000 and the contents of this email and any reply you make may be disclosed by NERC unless it is exempt from release under the Act. Any material supplied to NERC may be stored in an electronic records management system. From ajcartmell at fonant.com Fri Aug 10 15:55:26 2007 From: ajcartmell at fonant.com (Anthony Cartmell) Date: Fri Aug 10 15:55:29 2007 Subject: Performance problem after upgrading from SA 3.2.1 to 3.2.2 In-Reply-To: References: <46BC48F5.4080606@ecs.soton.ac.uk> Message-ID: > A sidenote. He also posted this to the sa list. This plugin does *not* > get > used automatically and it wasn't added with 3.2.2 as he claims. It was > added with 3.2.0 and you have to uncomment it for use. So, normally it's > off! One should also read the documentation for it, before using it! It was added to my system automatically, I didn't turn it on myself and it was added, several times... it's off now :) I suspect a certain MailScanner install from tarball? ;) Anthony -- www.fonant.com - Quality web sites From maillists at conactive.com Fri Aug 10 16:11:50 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Fri Aug 10 16:11:53 2007 Subject: Performance problem after upgrading from SA 3.2.1 to 3.2.2 In-Reply-To: References: Message-ID: wrote on Fri, 10 Aug 2007 07:45:41 -0500: > I'm wondering if that process may have added the plugin. Jules? Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From MailScanner at ecs.soton.ac.uk Fri Aug 10 16:53:57 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 10 16:54:13 2007 Subject: Performance problem after upgrading from SA 3.2.1 to 3.2.2 In-Reply-To: References: <46BC48F5.4080606@ecs.soton.ac.uk> Message-ID: <46BC8A15.3000701@ecs.soton.ac.uk> In which case it's my fault. I enable the ASN plugin by default in my ClamAV+SA package. I have just changed it to not enable it by default, so people's systems will run faster. Sorry about that, Jules. Kai Schaetzl wrote: > A sidenote. He also posted this to the sa list. This plugin does *not* get > used automatically and it wasn't added with 3.2.2 as he claims. It was > added with 3.2.0 and you have to uncomment it for use. So, normally it's > off! One should also read the documentation for it, before using it! > > Kai > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Fri Aug 10 17:02:28 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 10 17:02:51 2007 Subject: Performance problem after upgrading from SA 3.2.1 to 3.2.2 In-Reply-To: References: Message-ID: <46BC8C14.3050808@ecs.soton.ac.uk> Yes, my ClamAV+SA package did it. It doesn't do it any more. I didn't make any other changes for that plugin, I just added the loadplugin line. So just comment out the line in v320.pre. No need to even restart MailScanner, it will pick up the change in a few hours anyway. Jules. donald.dawson@bakerbotts.com wrote: > Kai, > > When I installed SA 3.2.2 from the package from spamassassin.org, it did not add any plugins or uncomment any plugins - you are correct. > > On this one MX box I used the tarball from the mailscanner.info site that had clamav and spamassassin 3.2.2 - I'm wondering if that process may have added the plugin. That process may have appended these plugins. > > loadplugin Mail::SpamAssassin::Plugin::RelayCountry > loadplugin Mail::SpamAssassin::Plugin::SPF > loadplugin Mail::SpamAssassin::Plugin::URIDNSBL > loadplugin Mail::SpamAssassin::Plugin::ASN > > You are also correct, and each added plugin should be reviewed and tested to see if processing time is affected (logging options in MailScanner that show time per message when processing new batches). > > It's sometimes difficult to determine if a plugin is necessary and all of the ramifications of adding it. > > Point taken though. > > Thanks, > Donald > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Kai Schaetzl > Sent: Friday, August 10, 2007 6:31 AM > To: mailscanner@lists.mailscanner.info > Subject: Re: Performance problem after upgrading from SA 3.2.1 to 3.2.2 > > > A sidenote. He also posted this to the sa list. This plugin does *not* get > used automatically and it wasn't added with 3.2.2 as he claims. It was > added with 3.2.0 and you have to uncomment it for use. So, normally it's > off! One should also read the documentation for it, before using it! > > Kai > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Fri Aug 10 17:04:45 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 10 17:04:59 2007 Subject: Performance problem after upgrading from SA 3.2.1 to 3.2.2 In-Reply-To: References: Message-ID: <46BC8C9D.7030105@ecs.soton.ac.uk> Kai Schaetzl wrote: > wrote on Fri, 10 Aug 2007 07:45:41 -0500: > > >> I'm wondering if that process may have added the plugin. >> > > Jules? > I have just released an updated ClamAV+SpamAssassin tarball which doesn't add the ASN plugin. > Kai > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From mkercher at nfsmith.com Fri Aug 10 17:12:34 2007 From: mkercher at nfsmith.com (Mike Kercher) Date: Fri Aug 10 17:12:37 2007 Subject: CRM114 Problem Message-ID: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info> I added CRM114 to a server last week per the docs in the wiki (and like I've done on several other servers), but the score is always -0.00 [root@mail crm114]# cssutil -b -r spam.css Sparse spectra file spam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 15495 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 [root@mail crm114]# cssutil -b -r nonspam.css Sparse spectra file nonspam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 15495 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 The Features learned hasn't changed in many days. Permissions look good, .crm's are +x Any suggestions where to look? Mike From MailScanner at ecs.soton.ac.uk Fri Aug 10 17:21:32 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 10 17:21:48 2007 Subject: Running latest beta? Power outage tomorrow (Saturday) Message-ID: <46BC908C.9000108@ecs.soton.ac.uk> Due to some electrical power maintenance which needs to be done (half a floor lost its neutral the other day, so they want to check the rest of the building), all services at ecs.soton.ac.uk will be out of action tomorrow. Fortunately, the only thing this affects is my mail and the www.mailscanner.eu website, where you get the phishing.bad.sites.conf file from (if you're running the latest beta). The update_bad_phishing_sites cron job that updates the file for you will continue running, leaving your last copy of the file in place. As an extra precaution, I have moved www.mailscanner.eu out of our systems, as a static website. So you should continue to get the file perfectly normally, you just won't get any new hosts added to the list. Everything should revert back to normal by about 7pm GMT tomorrow (Saturday). By then I'm going to be suffering serious withdrawal symptoms! :-( If you need to get in contact with me, I'll be on the IRC channel. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From uxbod at splatnix.net Fri Aug 10 17:53:42 2007 From: uxbod at splatnix.net (UxBoD) Date: Fri Aug 10 17:44:01 2007 Subject: CRM114 Problem In-Reply-To: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info> Message-ID: <24231931.14351186764822763.JavaMail.root@office.splatnix.net> ls -lR /etc/mail/spamassassin plus crm114.cf Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Mike Kercher" To: "MailScanner discussion" Sent: 10 August 2007 17:12:34 o'clock (GMT) Europe/London Subject: CRM114 Problem I added CRM114 to a server last week per the docs in the wiki (and like I've done on several other servers), but the score is always -0.00 [root@mail crm114]# cssutil -b -r spam.css Sparse spectra file spam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 15495 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 [root@mail crm114]# cssutil -b -r nonspam.css Sparse spectra file nonspam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 15495 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 The Features learned hasn't changed in many days. Permissions look good, .crm's are +x Any suggestions where to look? Mike -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From uxbod at splatnix.net Fri Aug 10 17:54:59 2007 From: uxbod at splatnix.net (UxBoD) Date: Fri Aug 10 17:45:18 2007 Subject: Running latest beta? Power outage tomorrow (Saturday) In-Reply-To: <46BC908C.9000108@ecs.soton.ac.uk> Message-ID: <8853313.14381186764899754.JavaMail.root@office.splatnix.net> NO!!!!! :) Its sunny weather this weekend Jules. Get some R&R :D Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From gmane at tippingmar.com Fri Aug 10 17:51:12 2007 From: gmane at tippingmar.com (Mark Nienberg) Date: Fri Aug 10 17:51:22 2007 Subject: Performance problem after upgrading from SA 3.2.1 to 3.2.2 In-Reply-To: <46BC8C14.3050808@ecs.soton.ac.uk> References: <46BC8C14.3050808@ecs.soton.ac.uk> Message-ID: Julian Field wrote: > Yes, my ClamAV+SA package did it. It doesn't do it any more. I didn't > make any other changes for that plugin, I just added the loadplugin > line. So just comment out the line in v320.pre. > > No need to even restart MailScanner, it will pick up the change in a few > hours anyway. > > Jules. It seems to be in the file "init.pre" also. Mark From list-mailscanner at linguaphone.com Fri Aug 10 18:48:39 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Fri Aug 10 18:48:47 2007 Subject: .fdf spam Message-ID: Today I got my first .fdf spam. It looks basically like a pdf file and acrobat opens it as usual but because of the different extension I believe the PDFInfo plugin did not scan it. I have mailed the plugin author to let him know. I doubt this method will last long. I had never heard of a .fdf file before so I suspect it is something a lot of people will add to the file extensions block list. From uxbod at splatnix.net Fri Aug 10 19:06:50 2007 From: uxbod at splatnix.net (UxBoD) Date: Fri Aug 10 18:57:09 2007 Subject: .fdf spam In-Reply-To: Message-ID: <10781898.14441186769210699.JavaMail.root@office.splatnix.net> Why not block the extension ? Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Gareth" To: mailscanner@lists.mailscanner.info Sent: 10 August 2007 18:48:39 o'clock (GMT) Europe/London Subject: .fdf spam Today I got my first .fdf spam. It looks basically like a pdf file and acrobat opens it as usual but because of the different extension I believe the PDFInfo plugin did not scan it. I have mailed the plugin author to let him know. I doubt this method will last long. I had never heard of a .fdf file before so I suspect it is something a lot of people will add to the file extensions block list. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ms-list at alexb.ch Fri Aug 10 19:04:14 2007 From: ms-list at alexb.ch (Alex Broens) Date: Fri Aug 10 19:04:26 2007 Subject: .fdf spam In-Reply-To: References: Message-ID: <46BCA89E.6030705@alexb.ch> On 8/10/2007 7:48 PM, Gareth wrote: > Today I got my first .fdf spam. It looks basically like a pdf file and > acrobat opens it as usual but because of the different extension I believe > the PDFInfo plugin did not scan it. I have mailed the plugin author to let > him know. > > I doubt this method will last long. I had never heard of a .fdf file before > so I suspect it is something a lot of people will add to the file extensions > block list. > There's an updated PDFInfo plugin # PDFInfo Plugin for SpamAssassin # Version: 0.8 # Info: $Id: PDFInfo.pm 902 2007-08-10 17:13:19Z root $ # Current Home: http://www.rulesemporium.com/plugins.htm#pdfinfo # Created: 2007-08-10 # Modified: 2007-08-10 # By: Dallas Engelken # # # Changes: # 0.8 - added .fdf detection (thanks John Lundin) [axb] :-) From iad.scoot at gmail.com Fri Aug 10 19:05:45 2007 From: iad.scoot at gmail.com (Iad Scoot) Date: Fri Aug 10 19:05:48 2007 Subject: .fdf spam In-Reply-To: References: Message-ID: <88bd43930708101105m560165b2td62bedf85b0f5d73@mail.gmail.com> I think that .fdf files are generated from the Adobe SDK - basically a dynamically-created pdf file. On 8/10/07, Gareth wrote: > > Today I got my first .fdf spam. It looks basically like a pdf file and > acrobat opens it as usual but because of the different extension I believe > the PDFInfo plugin did not scan it. I have mailed the plugin author to let > him know. > > I doubt this method will last long. I had never heard of a .fdf file > before > so I suspect it is something a lot of people will add to the file > extensions > block list. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070810/8f67d97d/attachment.html From mkercher at nfsmith.com Fri Aug 10 19:09:39 2007 From: mkercher at nfsmith.com (Mike Kercher) Date: Fri Aug 10 19:09:43 2007 Subject: CRM114 Problem In-Reply-To: <24231931.14351186764822763.JavaMail.root@office.splatnix.net> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info> <24231931.14351186764822763.JavaMail.root@office.splatnix.net> Message-ID: <224FA7E11EA39E45843E11CEBBD3A36F189AAA@HOUPEX01.nfsmith.info> [root@mail spamassassin]# ls -lR .: total 68 drwxr-xr-x 2 root root 4096 Aug 10 13:07 crm114 -rw-r--r-- 1 root root 4737 Aug 10 13:05 crm114.cf -rw-r--r-- 1 root root 16394 Aug 2 07:25 crm114.pm -rw-r--r-- 1 root root 1089 Aug 5 15:02 init.pre -rw-r--r-- 1 root root 274 Jul 25 10:43 local.cf lrwxrwxrwx 1 root root 41 Aug 5 15:02 mailscanner.cf -> /etc/MailScanner/spam.assassin.prefs.conf drwx------ 2 root root 4096 Aug 5 15:25 sa-update-keys -rw-r--r-- 1 root root 64 Jul 25 10:43 spamassassin-default.rc -rw-r--r-- 1 root root 35 Jul 25 10:43 spamassassin-helper.sh -rw-r--r-- 1 root root 55 Jul 25 10:43 spamassassin-spamc.rc -rw-r--r-- 1 root root 2439 Aug 5 18:55 v310.pre -rw-r--r-- 1 root root 922 Jul 25 10:44 v312.pre -rw-r--r-- 1 root root 2346 Aug 5 11:26 v320.pre ./crm114: total 18612 -rw-r--r-- 1 root root 0 Aug 5 18:24 blacklist.mfp -rw-r--r-- 1 root root 17412 Aug 5 18:27 mailfilter.cf -rwxr-xr-x 1 root root 44537 Aug 5 18:23 mailfilter.crm -rwxr-xr-x 1 root root 14511 Aug 5 18:23 maillib.crm -rwxr-xr-x 1 root root 22739 Aug 5 11:08 mailreaver.crm -rwxr-xr-x 1 root root 37621 Aug 5 18:23 mailtrainer.crm -rw------- 1 root root 6291444 Aug 10 13:07 nonspam.css -rw-r--r-- 1 root root 49 Aug 5 18:24 priolist.mfp -rw-r--r-- 1 root root 0 Aug 5 18:24 rewrites.mfp -rw-r--r-- 1 root root 12582924 Aug 10 13:07 spam.css -rw-r--r-- 1 root root 0 Aug 5 18:24 whitelist.mfp -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Friday, August 10, 2007 11:54 AM To: MailScanner discussion Subject: Re: CRM114 Problem ls -lR /etc/mail/spamassassin plus crm114.cf Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Mike Kercher" To: "MailScanner discussion" Sent: 10 August 2007 17:12:34 o'clock (GMT) Europe/London Subject: CRM114 Problem I added CRM114 to a server last week per the docs in the wiki (and like I've done on several other servers), but the score is always -0.00 [root@mail crm114]# cssutil -b -r spam.css Sparse spectra file spam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 15495 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 [root@mail crm114]# cssutil -b -r nonspam.css Sparse spectra file nonspam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 15495 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 The Features learned hasn't changed in many days. Permissions look good, .crm's are +x Any suggestions where to look? Mike -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From mailscanner at home.carlo65.de Fri Aug 10 21:01:15 2007 From: mailscanner at home.carlo65.de (R. Ehle (MailScanner Mailinglist)) Date: Fri Aug 10 21:01:27 2007 Subject: AW: .fdf spam In-Reply-To: <88bd43930708101105m560165b2td62bedf85b0f5d73@mail.gmail.com> References: <88bd43930708101105m560165b2td62bedf85b0f5d73@mail.gmail.com> Message-ID: <4D1CD0994309F84BA83DF998BF0075AF4328E19B@ts-dc2.TS-Webarts.local> Hi, .fdf-Files normally are form data of pdf forms and might be dangerous. If you fill in a form, which has been designed in Acrobat, you can save the data as file (creates a .fdf file). Once you open the .fdf file, it will automatically load the form (a pdf file) too, wherever it is located at (i.e. from the internet) Regards, Roland Von: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Im Auftrag von Iad Scoot Gesendet: Freitag, 10. August 2007 20:06 An: MailScanner discussion Betreff: Re: .fdf spam I think that .fdf files are generated from the Adobe SDK - basically a dynamically-created pdf file. On 8/10/07, Gareth > wrote: Today I got my first .fdf spam. It looks basically like a pdf file and acrobat opens it as usual but because of the different extension I believe the PDFInfo plugin did not scan it. I have mailed the plugin author to let him know. I doubt this method will last long. I had never heard of a .fdf file before so I suspect it is something a lot of people will add to the file extensions block list. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ---------------------------------------------------------- Diese Nachricht wurde von mailMind(R) auf Viren und andere gefaehrliche Inhalte untersucht und ist sauber. --- mailMind(R) - we have your Mailsecurity in mind! http://www.mailmind.de --- -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070810/f6fd0d21/attachment-0001.html From MailScanner at ecs.soton.ac.uk Fri Aug 10 21:10:48 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 10 21:11:32 2007 Subject: AW: .fdf spam In-Reply-To: <4D1CD0994309F84BA83DF998BF0075AF4328E19B@ts-dc2.TS-Webarts.local> References: <88bd43930708101105m560165b2td62bedf85b0f5d73@mail.gmail.com> <4D1CD0994309F84BA83DF998BF0075AF4328E19B@ts-dc2.TS-Webarts.local> Message-ID: <46BCC648.4090709@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Eek! I think this is headed for the dangerous filenames list. R. Ehle (MailScanner Mailinglist) wrote: > > Hi, > > > > .fdf-Files normally are form data of pdf forms and might be dangerous. > If you fill in a form, which has been designed in Acrobat, you can > save the data as file (creates a .fdf file). Once you open the .fdf > file, it will automatically load the form (a pdf file) too, wherever > it is located at (i.e. from the internet) > > > > Regards, > > Roland > > > > *Von:* mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] *Im Auftrag von > *Iad Scoot > *Gesendet:* Freitag, 10. August 2007 20:06 > *An:* MailScanner discussion > *Betreff:* Re: .fdf spam > > > > I think that .fdf files are generated from the Adobe SDK - basically a > dynamically-created pdf file. > > On 8/10/07, *Gareth* > wrote: > > Today I got my first .fdf spam. It looks basically like a pdf file and > acrobat opens it as usual but because of the different extension I > believe > the PDFInfo plugin did not scan it. I have mailed the plugin author to let > him know. > > I doubt this method will last long. I had never heard of a .fdf file > before > so I suspect it is something a lot of people will add to the file > extensions > block list. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > > > ---------------------------------------------- > Diese E-Mail wurde auf Viren und gef?hrliche Anh?nge > durch *mailMind(R)* > untersucht und ist sauber. > --- mailMind(R) - we have your MailSecurity in mind! --- Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGvMZIEfZZRxQVtlQRAtpZAKDqnY/IiLLHmI3NATXV0sAKr3if/gCeLgNV 9uwd79Nu6qlapumP1k/WoOg= =8zoi -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From dstraka at caspercollege.edu Fri Aug 10 21:20:02 2007 From: dstraka at caspercollege.edu (Daniel Straka) Date: Fri Aug 10 21:20:32 2007 Subject: .fdf spam In-Reply-To: <46BCA89E.6030705@alexb.ch> References: <46BCA89E.6030705@alexb.ch> Message-ID: <46BC7413.61A4.0000.0@caspercollege.edu> >>> On 8/10/2007 at 12:04 PM, in message <46BCA89E.6030705@alexb.ch>, Alex Broens wrote: > On 8/10/2007 7:48 PM, Gareth wrote: >> Today I got my first .fdf spam. It looks basically like a pdf file and >> acrobat opens it as usual but because of the different extension I believe >> the PDFInfo plugin did not scan it. I have mailed the plugin author to let >> him know. >> >> I doubt this method will last long. I had never heard of a .fdf file before >> so I suspect it is something a lot of people will add to the file extensions >> block list. >> > > > There's an updated PDFInfo plugin > # PDFInfo Plugin for SpamAssassin > # Version: 0.8 > # Info: $Id: PDFInfo.pm 902 2007-08-10 17:13:19Z root $ > # Current Home: http://www.rulesemporium.com/plugins.htm#pdfinfo > # Created: 2007-08-10 > # Modified: 2007-08-10 > # By: Dallas Engelken > # > # > # Changes: > # 0.8 - added .fdf detection (thanks John Lundin) [axb] OK, I've downloaded the pdfinfo plugin files from SARE. Now what do I do with 'em? I'm running spamassassin version = 3.1.3 MailScanner version = 4.54.6 Followed the directions in the .pm files, but doesn't seem to work for me. Are there some dependencies I don't have? I'm not running Pyzor or DCC, are they required? Thanks in advance.... -- Dan Straka Systems Coordinator Casper College 307.268.2399 From list-mailscanner at linguaphone.com Fri Aug 10 22:00:31 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Fri Aug 10 22:00:43 2007 Subject: .fdf spam In-Reply-To: <46BC7413.61A4.0000.0@caspercollege.edu> Message-ID: PDFInfo does not depend on anything else as the author deliberatly wants to make it that way. Thats unfortunate in my opinion as there are perl modules which detect pdf information better than PDFInfo does. You just put the .pm file into spamassassins perl directory (something like /usr/lib/per/5.8.8/site[or vendor]_perl/Mail/SpamAssassin/Plugin from memory) and the other file in /etc/mail/spamassassin/ Either restart mailscanner or wait 1-4 hours until the child processes reach their max life and restart themselves anyway. > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Daniel > Straka > Sent: 10 August 2007 21:20 > To: MailScanner discussion > Subject: Re: .fdf spam > > > >>> On 8/10/2007 at 12:04 PM, in message > <46BCA89E.6030705@alexb.ch>, Alex Broens > wrote: > > On 8/10/2007 7:48 PM, Gareth wrote: > >> Today I got my first .fdf spam. It looks basically like a pdf file and > >> acrobat opens it as usual but because of the different > extension I believe > >> the PDFInfo plugin did not scan it. I have mailed the plugin > author to let > >> him know. > >> > >> I doubt this method will last long. I had never heard of a > .fdf file before > >> so I suspect it is something a lot of people will add to the > file extensions > >> block list. > >> > > > > > > There's an updated PDFInfo plugin > > # PDFInfo Plugin for SpamAssassin > > # Version: 0.8 > > # Info: $Id: PDFInfo.pm 902 2007-08-10 17:13:19Z root $ > > # Current Home: http://www.rulesemporium.com/plugins.htm#pdfinfo > > # Created: 2007-08-10 > > # Modified: 2007-08-10 > > # By: Dallas Engelken > > # > > # > > # Changes: > > # 0.8 - added .fdf detection (thanks John Lundin) [axb] > > OK, I've downloaded the pdfinfo plugin files from SARE. Now what > do I do with 'em? > I'm running > spamassassin version = 3.1.3 > MailScanner version = 4.54.6 > Followed the directions in the .pm files, but doesn't seem to work for me. > Are there some dependencies I don't have? I'm not running Pyzor > or DCC, are they required? > > Thanks in advance.... > -- > > Dan Straka > Systems Coordinator > Casper College > 307.268.2399 > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > From MailScanner at ecs.soton.ac.uk Fri Aug 10 22:01:03 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 10 22:01:38 2007 Subject: .fdf spam In-Reply-To: <46BC7413.61A4.0000.0@caspercollege.edu> References: <46BCA89E.6030705@alexb.ch> <46BC7413.61A4.0000.0@caspercollege.edu> Message-ID: <46BCD20F.800@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Daniel Straka wrote: >>>> On 8/10/2007 at 12:04 PM, in message <46BCA89E.6030705@alexb.ch>, Alex Broens >>>> > wrote: > >> On 8/10/2007 7:48 PM, Gareth wrote: >> >>> Today I got my first .fdf spam. It looks basically like a pdf file and >>> acrobat opens it as usual but because of the different extension I believe >>> the PDFInfo plugin did not scan it. I have mailed the plugin author to let >>> him know. >>> >>> I doubt this method will last long. I had never heard of a .fdf file before >>> so I suspect it is something a lot of people will add to the file extensions >>> block list. >>> >>> >> There's an updated PDFInfo plugin >> # PDFInfo Plugin for SpamAssassin >> # Version: 0.8 >> # Info: $Id: PDFInfo.pm 902 2007-08-10 17:13:19Z root $ >> # Current Home: http://www.rulesemporium.com/plugins.htm#pdfinfo >> # Created: 2007-08-10 >> # Modified: 2007-08-10 >> # By: Dallas Engelken >> # >> # >> # Changes: >> # 0.8 - added .fdf detection (thanks John Lundin) [axb] >> > > OK, I've downloaded the pdfinfo plugin files from SARE. Now what do I do with 'em? > I'm running > spamassassin version = 3.1.3 > MailScanner version = 4.54.6 > Followed the directions in the .pm files, but doesn't seem to work for me. > Are there some dependencies I don't have? I'm not running Pyzor or DCC, are they required? > > Thanks in advance.... > Put the pdfinfo.cf file in /etc/mail/spamassassin. Put the PDFInfo.pm file in with your other Plugins (my preferred route, yes I know there are alternatives). You'll find the directory with find /usr/lib/perl -type d -name 'Plugin' -print It should be under /usr/lib/perl5/....../Mail/SpamAssassin/Plugin Put the PDFInfo.pm file in there. Now edit your /etc/mail/spamassassin/v310.pre file and add a loadplugin line just like the others in there, but referring PDFInfo instead of whatever plugin line you are copying. Then restart MailScanner. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGvNIQEfZZRxQVtlQRAveUAJ48HLgurTTtQ9GYuDD3hgxHvkMU8ACfW2eU i0nWhRkGslXwKYmVRywpEks= =v1gC -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From dchee at uci.edu Fri Aug 10 22:12:25 2007 From: dchee at uci.edu (Derek Chee) Date: Fri Aug 10 22:12:02 2007 Subject: AW: .fdf spam In-Reply-To: <46BCC648.4090709@ecs.soton.ac.uk> References: <88bd43930708101105m560165b2td62bedf85b0f5d73@mail.gmail.com> <4D1CD0994309F84BA83DF998BF0075AF4328E19B@ts-dc2.TS-Webarts.local> <46BCC648.4090709@ecs.soton.ac.uk> Message-ID: <3580D8B6-B93B-4005-B3B2-22CF01915AA5@uci.edu> I'm not entirely convinced that these .fdf files are really FDF files. Looking inside one, the header says PDF-1.5 while the PDF/FDF specification from Adobe says that the header should be FDF-1.2 if I'm reading it correctly, . I think this might be a case where Acrobat Reader is not looking at the file extension to determine what to do, but instead looking at the file contents. It sees that the file is really a PDF contrary to the extension and loads it as such. -- Derek On Aug 10, 2007, at 1:10 PM, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Eek! I think this is headed for the dangerous filenames list. > > R. Ehle (MailScanner Mailinglist) wrote: >> >> Hi, >> >> >> >> .fdf-Files normally are form data of pdf forms and might be >> dangerous. >> If you fill in a form, which has been designed in Acrobat, you can >> save the data as file (creates a .fdf file). Once you open the .fdf >> file, it will automatically load the form (a pdf file) too, wherever >> it is located at (i.e. from the internet) >> >> >> >> Regards, >> >> Roland >> >> >> >> *Von:* mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] *Im Auftrag von >> *Iad Scoot >> *Gesendet:* Freitag, 10. August 2007 20:06 >> *An:* MailScanner discussion >> *Betreff:* Re: .fdf spam >> >> >> >> I think that .fdf files are generated from the Adobe SDK - >> basically a >> dynamically-created pdf file. >> >> On 8/10/07, *Gareth* > > wrote: >> >> Today I got my first .fdf spam. It looks basically like a pdf file >> and >> acrobat opens it as usual but because of the different extension I >> believe >> the PDFInfo plugin did not scan it. I have mailed the plugin >> author to let >> him know. >> >> I doubt this method will last long. I had never heard of a .fdf file >> before >> so I suspect it is something a lot of people will add to the file >> extensions >> block list. From ssilva at sgvwater.com Fri Aug 10 22:33:54 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Aug 10 22:34:16 2007 Subject: Spamhaus issues? In-Reply-To: References: <7EF0EE5CB3B263488C8C18823239BEBA03CEFD@HC-MBX02.herefordshire.gov.uk> Message-ID: Res spake the following on 8/9/2007 5:19 AM: > On Thu, 9 Aug 2007, Randal, Phil wrote: > >> I'd recommend cbl.abuseat.org at the MTA level. That, combined with > > > They dont have a good hit ratio, I've just just grabed the last 8 > blocked IPs by RBL's and cbl only lists 1 of them, where as njabl, > spamcop and sorbs all listed all those 8 IP's > Just because your last 8 hits didn't come out of that range doesn't make the list invalid. It just makes it less than ideal for YOUR situation. But next week or next month that list could just save you from some some new zero-day virus! :-( -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Fri Aug 10 22:42:32 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Aug 10 22:42:48 2007 Subject: Sendmail help ?? Please. In-Reply-To: <113A0DFC086C984AB9EFDF6B8614F075017D34D4@exchange03.CBOCS.com> References: <113A0DFC086C984AB9EFDF6B8614F075017D34D4@exchange03.CBOCS.com> Message-ID: Andrews Carl 455 spake the following on 8/9/2007 10:11 PM: > Sorry, I did not realize that would make a difference. I opened a message to the newsgroup, clicked reply and deleted the message body and the subject ( I promise not to do this again and appologize to whomever I stepped on it was completely unintentional) . I know I am showing my ignorance, but I do not understand how I offened. I use microsoft outlook as an email client, do other clients behave differently because of information contained within the headers? I am not trying to be dense, in my client this appears as a separate thread. > > Thanks again, > Carl It is not technically an offense, but many of us have busy day jobs, and help here to contribute back to the community and maybe give Julian more time to write those killer new features ;-). Time is usually short, and there is only so much time in the day. With threading, you can watch as threads get added and follow a subject easily, and when a thread turns into a virtual fistfight or an off-topic mess, you can just ignore the rest of the thread and get back to the PHB's tasks. Otherwise, you get too busy wading through the stuff that either doesn't need comment, or you start getting drawn into Postfix VS sendmail discussions. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From res at ausics.net Fri Aug 10 22:54:58 2007 From: res at ausics.net (Res) Date: Fri Aug 10 22:55:07 2007 Subject: Spamhaus issues? In-Reply-To: References: <7EF0EE5CB3B263488C8C18823239BEBA03CEFD@HC-MBX02.herefordshire.gov.uk> Message-ID: On Fri, 10 Aug 2007, Kai Schaetzl wrote: > Res wrote on Fri, 10 Aug 2007 08:37:04 +1000 (EST): > >> Thats there decision, I dont have to use SORBS's dynamic if I dont want >> to, but I choose to do so, because no dynamic user has any need to be >> running a mail server AFAIC. > > That's not the point. These hosts are *by definition* not on CBL, they do > not list by technical criteria but by reported abuse. You claimed "They > dont have a good hit ratio". Claiming something like that is simply *sigh* It *IS* the point, they care not on CBL as you state they dont do dynamics, the IP's are * N O T * dynamic! Who the hell ever said they were I'll never know, probably your presumption, dont try to tell me what I do and do not have in my logs, dont try to teach me how to use RBL's since I was involved with MAPS in its early days, and I will claim it has a useless hit rate if the major RBLs I use list those spamming gits and your favourite CBL does not, as they say "the evidence speaks for itself". -- Cheers Res From dstraka at caspercollege.edu Fri Aug 10 22:55:54 2007 From: dstraka at caspercollege.edu (Daniel Straka) Date: Fri Aug 10 22:56:24 2007 Subject: .fdf spam In-Reply-To: <46BCD20F.800@ecs.soton.ac.uk> References: <46BCA89E.6030705@alexb.ch> <46BC7413.61A4.0000.0@caspercollege.edu><46BC7413.61A4.0000.0@caspercollege.edu> <46BCD20F.800@ecs.soton.ac.uk> Message-ID: <46BC8A8B.61A4.0000.0@caspercollege.edu> >>> On 8/10/2007 at 3:01 PM, in message <46BCD20F.800@ecs.soton.ac.uk>, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Daniel Straka wrote: >>>>> On 8/10/2007 at 12:04 PM, in message <46BCA89E.6030705@alexb.ch>, Alex Broens >>>>> >> wrote: >> >>> On 8/10/2007 7:48 PM, Gareth wrote: >>> >>>> Today I got my first .fdf spam. It looks basically like a pdf file and >>>> acrobat opens it as usual but because of the different extension I believe >>>> the PDFInfo plugin did not scan it. I have mailed the plugin author to let >>>> him know. >>>> >>>> I doubt this method will last long. I had never heard of a .fdf file before >>>> so I suspect it is something a lot of people will add to the file extensions >>>> block list. >>>> >>>> >>> There's an updated PDFInfo plugin >>> # PDFInfo Plugin for SpamAssassin >>> # Version: 0.8 >>> # Info: $Id: PDFInfo.pm 902 2007-08-10 17:13:19Z root $ >>> # Current Home: http://www.rulesemporium.com/plugins.htm#pdfinfo >>> # Created: 2007-08-10 >>> # Modified: 2007-08-10 >>> # By: Dallas Engelken >>> # >>> # >>> # Changes: >>> # 0.8 - added .fdf detection (thanks John Lundin) [axb] >>> >> >> OK, I've downloaded the pdfinfo plugin files from SARE. Now what do I do > with 'em? >> I'm running >> spamassassin version = 3.1.3 >> MailScanner version = 4.54.6 >> Followed the directions in the .pm files, but doesn't seem to work for me. >> Are there some dependencies I don't have? I'm not running Pyzor or DCC, are > they required? >> >> Thanks in advance.... >> > Put the pdfinfo.cf file in /etc/mail/spamassassin. > Put the PDFInfo.pm file in with your other Plugins (my preferred route, > yes I know there are alternatives). You'll find the directory with > > find /usr/lib/perl -type d -name 'Plugin' -print > It should be under /usr/lib/perl5/....../Mail/SpamAssassin/Plugin > Put the PDFInfo.pm file in there. > > Now edit your /etc/mail/spamassassin/v310.pre file and add a loadplugin > line just like the others in there, but referring PDFInfo instead of > whatever plugin line you are copying. > > Then restart MailScanner. > > Jules Thanks Jules...no errors this time so I think its working. Time will tell... From ssilva at sgvwater.com Fri Aug 10 22:58:57 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Aug 10 22:59:14 2007 Subject: Sendmail help ?? Please. In-Reply-To: <46BC7960.5060609@nerc.ac.uk> References: <113A0DFC086C984AB9EFDF6B8614F075017D34DF@exchange03.CBOCS.com> <46BC7960.5060609@nerc.ac.uk> Message-ID: Greg Matthews spake the following on 8/10/2007 7:42 AM: > Andrews Carl 455 wrote: >>> I suggest you install Webmin on your machine and use >> Thanks I will give that a try. >> >>> BTW, I think this is wrong: >>> 'makemap hash /etc/mail/access < /etc/mail/access' >>> correct: >>> 'makemap hash /etc/mail/access.db < /etc/mail/access' >>> notice the missing suffix? >>> You may have actually overwritten your original access file. Don't you >> get >>> any kind of an error message? >> >> I thought it odd myself, but the command is right off the sendmail.org >> page and it creates the .db. - http://www.sendmail.org/tips/relaying.php >> . >> > > the command as shown if fine. makemap just does the right thing. > >> >> Thanks again, >> Carl > > I think you need "feature delay_checks" in the sendmail.mc for to addresses to get checked in the access file. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From res at ausics.net Fri Aug 10 23:01:06 2007 From: res at ausics.net (Res) Date: Fri Aug 10 23:01:15 2007 Subject: OT (like most things here anyway) BIND8 EOL In-Reply-To: <223f97700708100538n2e5dfbe4x33fb5fd67e52ffee@mail.gmail.com> References: <223f97700708100538n2e5dfbe4x33fb5fd67e52ffee@mail.gmail.com> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Fri, 10 Aug 2007, Glenn Steen wrote: > On 10/08/07, Scott Silva wrote: >> Res spake the following on 8/9/2007 4:33 PM: >>> >>> whereas BIND9 is now 8 years old, >>> and BIND9 is performance-competitive against BIND8, >>> and BIND9 conforms to more of the DNS protocol than BIND8, >>> and BIND9 is more secure and more portable than BIND8, >>> we are declaring BIND8 to be in "end of life" (like BIND4). >>> >>> >>> posted here because I know many of you by your own admission have bad >>> habits of not updating software. >>> >> I bet there is still a lot of bind4 installs running around the world! >> >> But not here. >> >> So bind9 is 8 years old? Bind10 should be just around the end of the decade >> somewhere. > > Thanks Noel, I imagine though that those who need read that... Might > not be reading this list at all:-). Its Ok, you and Scott are the only ones who read my posts anyway... suckers for punishment eh? ;P Anyway I posted here since there are many smallies on this list that manage the whole show and may not be aware. > And thanks both of you for the laugh. (I need all the positive > thinking I can grasp at ATM, finding myself in somewhat of a > quagmire... One that more work can't, for once, can't cure... > Emotions, who needs them, eh:-) if (-e "bad emotions") { /bar/copious\ amounts\ of\ alcohol }; - -- Cheers Res -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (GNU/Linux) iD8DBQFGvOAisWhAmSIQh7MRAk1YAKCEq8+kZ23z8h3PVxMFU3AKLtwKnQCePU9v Xh3S6o1Al5WXB52UHiySwO0= =qJze -----END PGP SIGNATURE----- From glenn.steen at gmail.com Sat Aug 11 07:14:16 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Sat Aug 11 07:14:18 2007 Subject: OT (like most things here anyway) BIND8 EOL In-Reply-To: References: <223f97700708100538n2e5dfbe4x33fb5fd67e52ffee@mail.gmail.com> Message-ID: <223f97700708102314u4895a3afj4e24fac8e6105d6f@mail.gmail.com> On 11/08/07, Res wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > On Fri, 10 Aug 2007, Glenn Steen wrote: > > > On 10/08/07, Scott Silva wrote: > >> Res spake the following on 8/9/2007 4:33 PM: > >>> > >>> whereas BIND9 is now 8 years old, > >>> and BIND9 is performance-competitive against BIND8, > >>> and BIND9 conforms to more of the DNS protocol than BIND8, > >>> and BIND9 is more secure and more portable than BIND8, > >>> we are declaring BIND8 to be in "end of life" (like BIND4). > >>> > >>> > >>> posted here because I know many of you by your own admission have bad > >>> habits of not updating software. > >>> > >> I bet there is still a lot of bind4 installs running around the world! > >> > >> But not here. > >> > >> So bind9 is 8 years old? Bind10 should be just around the end of the decade > >> somewhere. > > > > Thanks Noel, I imagine though that those who need read that... Might > > not be reading this list at all:-). > > Its Ok, you and Scott are the only ones who read my posts anyway... > suckers for punishment eh? ;P Obviously:-) > Anyway I posted here since there are many smallies on this list that > manage the whole show and may not be aware. Yeah, good service. > > And thanks both of you for the laugh. (I need all the positive > > thinking I can grasp at ATM, finding myself in somewhat of a > > quagmire... One that more work can't, for once, can't cure... > > Emotions, who needs them, eh:-) > > if (-e "bad emotions") { > /bar/copious\ amounts\ of\ alcohol > }; > Won't help this time, but thanks for the suggestion:-) -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From uxbod at splatnix.net Sat Aug 11 10:05:21 2007 From: uxbod at splatnix.net (UxBoD) Date: Sat Aug 11 09:55:29 2007 Subject: CRM114 Problem In-Reply-To: <224FA7E11EA39E45843E11CEBBD3A36F189AAA@HOUPEX01.nfsmith.info> Message-ID: <8692087.14471186823121824.JavaMail.root@office.splatnix.net> What user is MS running as ? If non-root then the perms on crm114 do not allow write by anybody else. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Mike Kercher" To: "MailScanner discussion" Sent: 10 August 2007 19:09:39 o'clock (GMT) Europe/London Subject: RE: CRM114 Problem [root@mail spamassassin]# ls -lR .: total 68 drwxr-xr-x 2 root root 4096 Aug 10 13:07 crm114 -rw-r--r-- 1 root root 4737 Aug 10 13:05 crm114.cf -rw-r--r-- 1 root root 16394 Aug 2 07:25 crm114.pm -rw-r--r-- 1 root root 1089 Aug 5 15:02 init.pre -rw-r--r-- 1 root root 274 Jul 25 10:43 local.cf lrwxrwxrwx 1 root root 41 Aug 5 15:02 mailscanner.cf -> /etc/MailScanner/spam.assassin.prefs.conf drwx------ 2 root root 4096 Aug 5 15:25 sa-update-keys -rw-r--r-- 1 root root 64 Jul 25 10:43 spamassassin-default.rc -rw-r--r-- 1 root root 35 Jul 25 10:43 spamassassin-helper.sh -rw-r--r-- 1 root root 55 Jul 25 10:43 spamassassin-spamc.rc -rw-r--r-- 1 root root 2439 Aug 5 18:55 v310.pre -rw-r--r-- 1 root root 922 Jul 25 10:44 v312.pre -rw-r--r-- 1 root root 2346 Aug 5 11:26 v320.pre ./crm114: total 18612 -rw-r--r-- 1 root root 0 Aug 5 18:24 blacklist.mfp -rw-r--r-- 1 root root 17412 Aug 5 18:27 mailfilter.cf -rwxr-xr-x 1 root root 44537 Aug 5 18:23 mailfilter.crm -rwxr-xr-x 1 root root 14511 Aug 5 18:23 maillib.crm -rwxr-xr-x 1 root root 22739 Aug 5 11:08 mailreaver.crm -rwxr-xr-x 1 root root 37621 Aug 5 18:23 mailtrainer.crm -rw------- 1 root root 6291444 Aug 10 13:07 nonspam.css -rw-r--r-- 1 root root 49 Aug 5 18:24 priolist.mfp -rw-r--r-- 1 root root 0 Aug 5 18:24 rewrites.mfp -rw-r--r-- 1 root root 12582924 Aug 10 13:07 spam.css -rw-r--r-- 1 root root 0 Aug 5 18:24 whitelist.mfp -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Friday, August 10, 2007 11:54 AM To: MailScanner discussion Subject: Re: CRM114 Problem ls -lR /etc/mail/spamassassin plus crm114.cf Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Mike Kercher" To: "MailScanner discussion" Sent: 10 August 2007 17:12:34 o'clock (GMT) Europe/London Subject: CRM114 Problem I added CRM114 to a server last week per the docs in the wiki (and like I've done on several other servers), but the score is always -0.00 [root@mail crm114]# cssutil -b -r spam.css Sparse spectra file spam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 15495 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 [root@mail crm114]# cssutil -b -r nonspam.css Sparse spectra file nonspam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 15495 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 The Features learned hasn't changed in many days. Permissions look good, .crm's are +x Any suggestions where to look? Mike -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From res at ausics.net Sat Aug 11 10:54:34 2007 From: res at ausics.net (Res) Date: Sat Aug 11 10:54:45 2007 Subject: OT (like most things here anyway) BIND8 EOL In-Reply-To: <223f97700708102314u4895a3afj4e24fac8e6105d6f@mail.gmail.com> References: <223f97700708100538n2e5dfbe4x33fb5fd67e52ffee@mail.gmail.com> <223f97700708102314u4895a3afj4e24fac8e6105d6f@mail.gmail.com> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sat, 11 Aug 2007, Glenn Steen wrote: >>> And thanks both of you for the laugh. (I need all the positive >>> thinking I can grasp at ATM, finding myself in somewhat of a >>> quagmire... One that more work can't, for once, can't cure... >>> Emotions, who needs them, eh:-) >> >> if (-e "bad emotions") { >> /bar/copious\ amounts\ of\ alcohol >> }; >> > Won't help this time, but thanks for the suggestion:-) Hrmm... doesn't sound good :( I hope whatever it is resolves soon, and you can again be your cheerful self life is full of assholish situations... I've lost 2 grandparents and one almost-partner whom I loved very dearly (from car accident) all in last 2 years, and if it wasnt for the alcohol... well... put it this way, whoever said drinking doesn't help is full of shit... it made sleeping much easier (I refuse to take any form of drugs to sleep no matter what, hell I dont even like taking pain killers for headaches), probably not the best method to cope, but I survived, stronger for it i think, as now I take no crap from anyone :P - -- Cheers Res -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (GNU/Linux) iD8DBQFGvYdbsWhAmSIQh7MRAjQ+AJ9xqyiBrnuWhZ8VN5t8FEbMawPm1gCbBvJt Ygq1xJuNmk5zpQH9hW5Yj80= =uLMs -----END PGP SIGNATURE----- From maillists at conactive.com Sat Aug 11 15:11:23 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Sat Aug 11 15:11:26 2007 Subject: Spamhaus issues? In-Reply-To: References: <7EF0EE5CB3B263488C8C18823239BEBA03CEFD@HC-MBX02.herefordshire.gov.uk> Message-ID: Res wrote on Sat, 11 Aug 2007 07:54:58 +1000 (EST): > *sigh* Indeed, you didn't get the point from the beginning and are still not getting it and are not even trying to get it. EOT. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From alex at nkpanama.com Sat Aug 11 16:12:11 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Sat Aug 11 16:13:01 2007 Subject: Running latest beta? Power outage tomorrow (Saturday) In-Reply-To: <8853313.14381186764899754.JavaMail.root@office.splatnix.net> References: <8853313.14381186764899754.JavaMail.root@office.splatnix.net> Message-ID: <46BDD1CB.3090408@nkpanama.com> UxBoD wrote: > NO!!!!! :) Its sunny weather this weekend Jules. Get some R&R :D > > Or some I&I... > Regards, > > --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B > // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B > // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net > > From glenn.steen at gmail.com Sat Aug 11 17:44:31 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Sat Aug 11 17:44:32 2007 Subject: OT (like most things here anyway) BIND8 EOL In-Reply-To: References: <223f97700708100538n2e5dfbe4x33fb5fd67e52ffee@mail.gmail.com> <223f97700708102314u4895a3afj4e24fac8e6105d6f@mail.gmail.com> Message-ID: <223f97700708110944j4d7e3930m11885d575562a3ad@mail.gmail.com> On 11/08/07, Res wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > On Sat, 11 Aug 2007, Glenn Steen wrote: > > >>> And thanks both of you for the laugh. (I need all the positive > >>> thinking I can grasp at ATM, finding myself in somewhat of a > >>> quagmire... One that more work can't, for once, can't cure... > >>> Emotions, who needs them, eh:-) > >> > >> if (-e "bad emotions") { > >> /bar/copious\ amounts\ of\ alcohol > >> }; > >> > > Won't help this time, but thanks for the suggestion:-) > > Hrmm... doesn't sound good :( > I hope whatever it is resolves soon, and you can again be your > cheerful self > > life is full of assholish situations... I've lost 2 grandparents and one > almost-partner whom I loved very dearly (from car accident) all in last 2 > years, and if it wasnt for the alcohol... well... put it this way, whoever > said drinking doesn't help is full of shit... it made sleeping much > easier (I refuse to take any form of drugs to sleep no matter what, hell > I dont even like taking pain killers for headaches), probably not the best > method to cope, but I survived, stronger for it i think, as now I take no > crap from anyone :P > I do agree, most times it helps. . . And the part about taking no crap is relevant. Drop me a line off-list with a usable address and I'll try explain, without boring the others to bits. Thanks in advance buddy. > - -- > > Cheers > Res > > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.7 (GNU/Linux) > > iD8DBQFGvYdbsWhAmSIQh7MRAjQ+AJ9xqyiBrnuWhZ8VN5t8FEbMawPm1gCbBvJt > Ygq1xJuNmk5zpQH9hW5Yj80= > =uLMs > -----END PGP SIGNATURE----- > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From res at ausics.net Sat Aug 11 22:59:41 2007 From: res at ausics.net (Res) Date: Sat Aug 11 22:59:54 2007 Subject: Spamhaus issues? In-Reply-To: References: <7EF0EE5CB3B263488C8C18823239BEBA03CEFD@HC-MBX02.herefordshire.gov.uk> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 *yawn* I got your point Kai, the fact is you introduced something (dynamic ip blocks) into the debate that was completely irrelevant, pay closer attention next time. On Sat, 11 Aug 2007, Kai Schaetzl wrote: > Res wrote on Sat, 11 Aug 2007 07:54:58 +1000 (EST): > >> *sigh* > > Indeed, you didn't get the point from the beginning and are still not > getting it and are not even trying to get it. EOT. > > Kai > > - -- Cheers Res -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (GNU/Linux) iD8DBQFGvjFOsWhAmSIQh7MRAsNaAKCbQU5X0/2IfgjLN3LTo+dYKUskuQCcCHhO 71MzqvSOqREupkzFwCROt6w= =VRK/ -----END PGP SIGNATURE----- From MailScanner at ecs.soton.ac.uk Sat Aug 11 23:27:33 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat Aug 11 23:28:09 2007 Subject: Spamhaus issues? In-Reply-To: References: <7EF0EE5CB3B263488C8C18823239BEBA03CEFD@HC-MBX02.herefordshire.gov.uk> Message-ID: <46BE37D5.6010800@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 C'mon guys, let's call it a day for this thread. The discussion is no longer relevant to others. If you wish to argue/debate/discuss, feel free, just do it off-list. Thanks, Jules. Res wrote: > * PGP Signed by an unknown key > > *yawn* > I got your point Kai, the fact is you introduced something (dynamic ip > blocks) into the debate that was completely irrelevant, pay closer > attention next time. > > > On Sat, 11 Aug 2007, Kai Schaetzl wrote: > >> Res wrote on Sat, 11 Aug 2007 07:54:58 +1000 (EST): >> >>> *sigh* >> >> Indeed, you didn't get the point from the beginning and are still not >> getting it and are not even trying to get it. EOT. >> >> Kai >> >> > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGvjfWEfZZRxQVtlQRAlDgAJsH3lufiPaxniSONz7/DHwu6qLglgCcCxsv Es0cSGsYS9HauFHKRlANzxI= =y/hU -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Sun Aug 12 06:11:28 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Sun Aug 12 06:11:42 2007 Subject: OT (like most things here anyway) BIND8 EOL In-Reply-To: References: <223f97700708100538n2e5dfbe4x33fb5fd67e52ffee@mail.gmail.com> Message-ID: Res spake the following on 8/10/2007 3:01 PM: > On Fri, 10 Aug 2007, Glenn Steen wrote: > >> On 10/08/07, Scott Silva wrote: >>> Res spake the following on 8/9/2007 4:33 PM: >>>> >>>> whereas BIND9 is now 8 years old, >>>> and BIND9 is performance-competitive against BIND8, >>>> and BIND9 conforms to more of the DNS protocol than BIND8, >>>> and BIND9 is more secure and more portable than BIND8, >>>> we are declaring BIND8 to be in "end of life" (like BIND4). >>>> >>>> >>>> posted here because I know many of you by your own admission have bad >>>> habits of not updating software. >>>> >>> I bet there is still a lot of bind4 installs running around the world! >>> >>> But not here. >>> >>> So bind9 is 8 years old? Bind10 should be just around the end of the >>> decade >>> somewhere. > >> Thanks Noel, I imagine though that those who need read that... Might >> not be reading this list at all:-). > > Its Ok, you and Scott are the only ones who read my posts anyway... > suckers for punishment eh? ;P > Always good for a laugh !! > Anyway I posted here since there are many smallies on this list that > manage the whole show and may not be aware. > > >> And thanks both of you for the laugh. (I need all the positive >> thinking I can grasp at ATM, finding myself in somewhat of a >> quagmire... One that more work can't, for once, can't cure... >> Emotions, who needs them, eh:-) > > if (-e "bad emotions") { > /bar/copious\ amounts\ of\ alcohol > }; > I'm taking another week off, so I might just run that code! ;-D -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Sun Aug 12 06:15:22 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Sun Aug 12 06:20:04 2007 Subject: OT (like most things here anyway) BIND8 EOL In-Reply-To: <223f97700708110944j4d7e3930m11885d575562a3ad@mail.gmail.com> References: <223f97700708100538n2e5dfbe4x33fb5fd67e52ffee@mail.gmail.com> <223f97700708102314u4895a3afj4e24fac8e6105d6f@mail.gmail.com> <223f97700708110944j4d7e3930m11885d575562a3ad@mail.gmail.com> Message-ID: Glenn Steen spake the following on 8/11/2007 9:44 AM: > On 11/08/07, Res wrote: > On Sat, 11 Aug 2007, Glenn Steen wrote: > >>>>>> And thanks both of you for the laugh. (I need all the positive >>>>>> thinking I can grasp at ATM, finding myself in somewhat of a >>>>>> quagmire... One that more work can't, for once, can't cure... >>>>>> Emotions, who needs them, eh:-) >>>>> if (-e "bad emotions") { >>>>> /bar/copious\ amounts\ of\ alcohol >>>>> }; >>>>> >>>> Won't help this time, but thanks for the suggestion:-) > Hrmm... doesn't sound good :( > I hope whatever it is resolves soon, and you can again be your > cheerful self > > life is full of assholish situations... I've lost 2 grandparents and one > almost-partner whom I loved very dearly (from car accident) all in last 2 > years, and if it wasnt for the alcohol... well... put it this way, whoever > said drinking doesn't help is full of shit... it made sleeping much > easier (I refuse to take any form of drugs to sleep no matter what, hell > I dont even like taking pain killers for headaches), probably not the best > method to cope, but I survived, stronger for it i think, as now I take no > crap from anyone :P > > >> I do agree, most times it helps. . . And the part about taking no crap >> is relevant. Drop me a line off-list with a usable address and I'll >> try explain, without boring the others to bits. Thanks in advance >> buddy. A fronte praecipitium a tergo lupi - A precipice in front, wolves behind -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From MailScanner at ecs.soton.ac.uk Sun Aug 12 11:58:59 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun Aug 12 11:59:34 2007 Subject: [Fwd: Re: Spamhaus issues? (fwd)] Message-ID: <46BEE7F3.9040405@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 This is the comment I got from Res in reply to my gentle tap on the shoulder. I've had enough of his attitude for a very long time. Sorry, but he asked for it. - -------- Original Message -------- Subject: Re: Spamhaus issues? (fwd) Date: Sun, 12 Aug 2007 08:42:59 +1000 (EST) From: Res To: Julian Field Its about as on topic as the rest of the crud around on list, so is this selective censorship I am seeing... probably, since you dont make a point of shutting down all off topic threads. If you want me off your list just unsub me, you have my blessing, as I doubt I contribute anything to the mailscanner community anyway. Remember to take me off the beta list as well. - ---------- Forwarded message ---------- Date: Sat, 11 Aug 2007 23:27:33 +0100 From: Julian Field Reply-To: MailScanner discussion To: MailScanner discussion Subject: Re: Spamhaus issues? - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 C'mon guys, let's call it a day for this thread. The discussion is no longer relevant to others. If you wish to argue/debate/discuss, feel free, just do it off-list. Thanks, Jules. Res wrote: > * PGP Signed by an unknown key > > *yawn* > I got your point Kai, the fact is you introduced something (dynamic ip > blocks) into the debate that was completely irrelevant, pay closer > attention next time. > > > On Sat, 11 Aug 2007, Kai Schaetzl wrote: > >> Res wrote on Sat, 11 Aug 2007 07:54:58 +1000 (EST): >> >>> *sigh* >> >> Indeed, you didn't get the point from the beginning and are still not >> getting it and are not even trying to get it. EOT. >> >> Kai >> >> > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGvuf0EfZZRxQVtlQRAmkAAKDpnvFWY4ZnG1vBn+K+KqSlL2g7dgCgsInB 7794Ez8nQvi2tpHRyeamCqI= =1tzv -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From smlists at shaw.ca Sun Aug 12 20:35:24 2007 From: smlists at shaw.ca (Steve Mason (lists)) Date: Sun Aug 12 20:36:12 2007 Subject: Dumb Bayes question In-Reply-To: References: Message-ID: <001201c7dd17$ed8aee80$1524010a@SMD800> Hi all. I've been running MailScanner for a while now my home server (4 users) and 2 small non-profit organizations, both around 10 users each. It seems to me I read a while ago, that Bayes isn't too effective on low-volume servers due to it not seeing many messages. Of course I can't seem to find where I read that now. If I use a "starter" database, and occasionally feed it any false positive/negative messages, is Bayes worth using for very small sites? Thanks, Steve -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070812/acd4d066/attachment.html From martinh at solidstatelogic.com Sun Aug 12 20:43:15 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Sun Aug 12 20:43:30 2007 Subject: Dumb Bayes question In-Reply-To: <001201c7dd17$ed8aee80$1524010a@SMD800> Message-ID: <73a34979d76f584cad64980e826bcbf5@solidstatelogic.com> I'd say it is. It'll also auto learn as well.. Another tool of the many that makes up spamassassin. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Steve Mason (lists) > Sent: 12 August 2007 20:35 > To: 'MailScanner discussion' > Subject: Dumb Bayes question > > Hi all. I've been running MailScanner for a while now my home server (4 > users) and 2 small non-profit organizations, both around 10 users each. > It seems to me I read a while ago, that Bayes isn't too effective on low- > volume servers due to it not seeing many messages. Of course I can't seem > to find where I read that now. > > If I use a "starter" database, and occasionally feed it any false > positive/negative messages, is Bayes worth using for very small sites? > > Thanks, > > Steve > ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From list-mailscanner at linguaphone.com Sun Aug 12 21:11:22 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Sun Aug 12 21:11:25 2007 Subject: Dumb Bayes question In-Reply-To: <001201c7dd17$ed8aee80$1524010a@SMD800> Message-ID: I run spamassassin on my home system which is very low usage and bayes is working very well. In fact I would say that bayes works better on small systems for a couple of reasons. 1) Bayes works best when it learns your individual mails. For companies which deal with lots of different topics and areas bayes has to learn a lot of tokens as being ham. For home servers and small organisations they receive a far small variety of ham messages so bayes can work better. 2) The default bayes database size is geared towards the smaller user. In my company if I used the default bayes size (which a lot of people probably do) the oldest token age would be about 2 days which is far too short for it to be very effective. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Steve Mason (lists) Sent: 12 August 2007 20:35 To: 'MailScanner discussion' Subject: Dumb Bayes question Hi all. I've been running MailScanner for a while now my home server (4 users) and 2 small non-profit organizations, both around 10 users each. It seems to me I read a while ago, that Bayes isn't too effective on low-volume servers due to it not seeing many messages. Of course I can't seem to find where I read that now. If I use a "starter" database, and occasionally feed it any false positive/negative messages, is Bayes worth using for very small sites? Thanks, Steve -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070812/0c139f1a/attachment.html From email at ace.net.au Mon Aug 13 03:24:57 2007 From: email at ace.net.au (Peter Nitschke) Date: Mon Aug 13 03:28:06 2007 Subject: [Fwd: Re: Spamhaus issues? (fwd)] In-Reply-To: <46BEE7F3.9040405@ecs.soton.ac.uk> References: <46BEE7F3.9040405@ecs.soton.ac.uk> Message-ID: <200708131154570129.01EE6DF4@dns3.ace.net.au> Julian, You made my day! As a long time MS user (over 5 years), the list became a bit too unfriendly for my liking. I look forward to enjoying and participating more. Cheers, Peter *********** REPLY SEPARATOR *********** On 12/08/2007 at 11:58 AM Julian Field wrote: >-----BEGIN PGP SIGNED MESSAGE----- >Hash: SHA1 > >This is the comment I got from Res in reply to my gentle tap on the >shoulder. >I've had enough of his attitude for a very long time. Sorry, but he >asked for it. > From mike at vesol.com Mon Aug 13 09:35:21 2007 From: mike at vesol.com (Mike Kercher) Date: Mon Aug 13 09:37:38 2007 Subject: [Fwd: Re: Spamhaus issues? (fwd)] In-Reply-To: <46BEE7F3.9040405@ecs.soton.ac.uk> References: <46BEE7F3.9040405@ecs.soton.ac.uk> Message-ID: <6115482898C59848B35DB9D491C9A28E04BB26@srv1.home.middlefinger.net> Good ridance! Well done, Jules. Mike > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Julian Field > Sent: Sunday, August 12, 2007 5:59 AM > To: MailScanner discussion > Subject: [Fwd: Re: Spamhaus issues? (fwd)] > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > This is the comment I got from Res in reply to my gentle tap > on the shoulder. > I've had enough of his attitude for a very long time. Sorry, > but he asked for it. > > - -------- Original Message -------- > Subject: Re: Spamhaus issues? (fwd) > Date: Sun, 12 Aug 2007 08:42:59 +1000 (EST) > From: Res > To: Julian Field > > > > Its about as on topic as the rest of the crud around on list, > so is this selective censorship I am seeing... probably, > since you dont make a point of shutting down all off topic > threads. If you want me off your list just unsub me, you have > my blessing, as I doubt I contribute anything to the > mailscanner community anyway. Remember to take me off the > beta list as well. > > > > > - ---------- Forwarded message ---------- > Date: Sat, 11 Aug 2007 23:27:33 +0100 > From: Julian Field > Reply-To: MailScanner discussion > To: MailScanner discussion > Subject: Re: Spamhaus issues? > > - -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > C'mon guys, let's call it a day for this thread. The > discussion is no longer relevant to others. If you wish to > argue/debate/discuss, feel free, just do it off-list. > > Thanks, > Jules. > > Res wrote: > > * PGP Signed by an unknown key > > > > *yawn* > > I got your point Kai, the fact is you introduced something > (dynamic ip > > blocks) into the debate that was completely irrelevant, pay closer > > attention next time. > > > > > > On Sat, 11 Aug 2007, Kai Schaetzl wrote: > > > >> Res wrote on Sat, 11 Aug 2007 07:54:58 +1000 (EST): > >> > >>> *sigh* > >> > >> Indeed, you didn't get the point from the beginning and > are still not > >> getting it and are not even trying to get it. EOT. > >> > >> Kai > >> > >> > > > > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 > B654 For all your IT requirements visit www.transtec.co.uk > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.2 (Build 2014) > Charset: ISO-8859-1 > > wj8DBQFGvuf0EfZZRxQVtlQRAmkAAKDpnvFWY4ZnG1vBn+K+KqSlL2g7dgCgsInB > 7794Ez8nQvi2tpHRyeamCqI= > =1tzv > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and dangerous > content by MailScanner, and is believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From MailScanner at ecs.soton.ac.uk Mon Aug 13 09:38:11 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 13 09:38:46 2007 Subject: [Fwd: Re: Spamhaus issues? (fwd)] In-Reply-To: <200708131154570129.01EE6DF4@dns3.ace.net.au> References: <46BEE7F3.9040405@ecs.soton.ac.uk> <200708131154570129.01EE6DF4@dns3.ace.net.au> Message-ID: <46C01873.4050805@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Peter Nitschke wrote: > Julian, > > You made my day! > > As a long time MS user (over 5 years), the list became a bit too unfriendly > for my liking. > I'm sorry to hear that. It sounds like I wasn't the only one who had had enough of him. > I look forward to enjoying and participating more. > Glad to hear it! That's what this list is for! :-) Jules. > Cheers, > > Peter > > > *********** REPLY SEPARATOR *********** > > On 12/08/2007 at 11:58 AM Julian Field wrote: > > >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> This is the comment I got from Res in reply to my gentle tap on the >> shoulder. >> I've had enough of his attitude for a very long time. Sorry, but he >> asked for it. >> >> > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGwBh0EfZZRxQVtlQRAhxiAJ9hH19Y6NkgQNndbDAx810Hg0UykgCg046y rfyzovjfNO/poKQGIuXoaY8= =NHYC -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From glenn.steen at gmail.com Mon Aug 13 11:48:12 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Mon Aug 13 11:48:13 2007 Subject: [Fwd: Re: Spamhaus issues? (fwd)] In-Reply-To: <46C01873.4050805@ecs.soton.ac.uk> References: <46BEE7F3.9040405@ecs.soton.ac.uk> <200708131154570129.01EE6DF4@dns3.ace.net.au> <46C01873.4050805@ecs.soton.ac.uk> Message-ID: <223f97700708130348l50c13590t60e4e45c8b1cb163@mail.gmail.com> On 13/08/07, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Peter Nitschke wrote: > > Julian, > > > > You made my day! > > > > As a long time MS user (over 5 years), the list became a bit too unfriendly > > for my liking. > > > I'm sorry to hear that. It sounds like I wasn't the only one who had had > enough of him. > > I look forward to enjoying and participating more. > > > Glad to hear it! That's what this list is for! :-) > > Jules. > Well.... I will speak to Noels defense. Yes, he is opinionated, and yes, he is stubborn... and very very drastic in his expressions. I have not been following this thread in any greater detail, since it stopped being interresting a while back. But he has on several occasions contributed his knowledge in constructive ways... And if you only scratch lightly on the surface, he is a very caring and kind person. My views are doubtless coloured by the helping hand he has reached out to me recently, when I most needed a kind word from a friend, but ... Is it really OK to gang up on him like you do now? To act out on the suggestion to evict him from the list is quite OK by me, and indeed by him as well, Jules. Even talking about it could've been OK. But I think you've come very close to a line here, almost ... gloating ... over the act. I do know (and have been know to agree vocally) that his language can be more than what is acceptable. That is not my point. I'm just saying we seem to have changed one (in my view minor) evil for another (that I, with my background and "old luggage" find very hard to accept... After all, it's bordering on mobbing). I'm not saying that anyone else of the participants of the thread should be "punished". Just that you all should remember that it is people at the other end. Respectfully yours -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From martin.lyberg at gmail.com Mon Aug 13 14:24:50 2007 From: martin.lyberg at gmail.com (Martin) Date: Mon Aug 13 14:25:35 2007 Subject: PATCH SweepViruses.pm - clamavmodule false positives - A PLEA! In-Reply-To: <1186472608.2344.3.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1186407034.31893.47.camel@gblades-suse.linguaphone-intranet.co.uk> <46B72D2E.2000208@ecs.soton.ac.uk> <4165CF7A7F12DE4B96622CCBB90586470B125CA8@largo.campus.ncl.ac.uk> <1186472608.2344.3.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: Gareth wrote: > You only get the false positives problem if you are using clamavmodule > and have "ClamAV Full Message Scan = yes". > Yo can turn off full message scanning but then some of the clamav > signatures are unable to detect some of the phishing attacks. This is > most noticeable if you are using the sanesecurity additional rules. > > It is just a couple of lines which need adding to SweepViruses.pm and I > can send you an updated file if you wish. Hi Gareth, I read about this in the mailscanner list, i've the same problem with falsepositives. Can you send me the updated file please? Is it just to replace the file, or do i have to do anything else? Thank you / Martin > > On Tue, 2007-08-07 at 08:05, Quentin Campbell wrote: >> Julian >> >> If you do release a new version of 4.62.9 to fix this I would be >> grateful if you could also make available a copy of the updated >> SweepViruses.pm file. >> >> I have just finished upgrading 12 mail gateways to 4.62.9-2 and SA 3.2.2 >> and cannot afford to go through the whole process of installing MS again >> so soon. If it is just a single *.pm that needs replacing then that is >> easy enough. >> >> How serious is this 'false positive' problem? Is it correct that I can >> avoid the bug by setting "ClamAV Full Message Scan = no" and do I lose >> much by doing that? >> >> Thanks >> >> Quentin >> >> >>> -----Original Message----- >>> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >>> bounces@lists.mailscanner.info] On Behalf Of Julian Field >>> Sent: 06 August 2007 15:16 >>> To: MailScanner discussion >>> Subject: Re: PATCH SweepViruses.pm - clamavmodule false positives >>> >>> -----BEGIN PGP SIGNED MESSAGE----- >>> Hash: SHA1 >>> >>> You only actually want to apply the first of the 2 patches, as you only >>> want to affect the code that scans the *.message and *.header files. >>> >>> It will be in the next release. >>> >>> Please can some other people test this and confirm it works reliably? >>> >>> Gareth wrote: >>>> Attached is a patch for SweepViruses.pm which fixes the false >>> positives >>>> issue with Phishing.Heuristics.Email.SpoofedDomain when using >>>> Clamavmodule and the full message scan option. >>>> >>>> It passes the CL_SCAN_PHISHING_DOMAINLIST option which according to >>> the >>>> clamavmodule source :- >>>> =item CL_SCAN_PHISHING_DOMAINLIST >>>> Phishing module: restrict URL scanning to domains from .pdf >>>> (RECOMMENDED). >>>> >>>> I believe that as this option was not previously set it is equivalent >>> to >>>> the following clamscan option :- >>>> --no-phishing-restrictedscan >>>> Enable url-based heuristic phishing detection for all domains >>>> (might lead to false positives!). >>>> >>>> Personally I think CL_SCAN_PHISHING_DOMAINLIST should do the same as >>>> --no-phishing-restrictedscan and not be the inverse of it. Maybe a >>> bug. >>>> I will contact the author about it anyway. >>>> >>>> I dont really know what this option does exactly but it is a >>> recommended >>>> setting, its name seems to indicate it is related to the false >>> positives >>>> I was getting, and setting it does seem to have cured the problem. >>>> >>> Jules >>> >>> - -- >>> Julian Field MEng CITP >>> www.MailScanner.info >>> Buy the MailScanner book at www.MailScanner.info/store >>> >>> Need help customising MailScanner? >>> Contact me! >>> Need help fixing or optimising your systems? >>> Contact me! >>> Need help getting you started solving new requirements from your boss? >>> Contact me! >>> >>> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >>> >>> >>> -----BEGIN PGP SIGNATURE----- >>> Version: PGP Desktop 9.6.2 (Build 2014) >>> Comment: (pgp-secured) >>> Charset: ISO-8859-1 >>> >>> wj8DBQFGty0vEfZZRxQVtlQRAgNvAKClvd3nYnkZaaePge//JWDYGr8gVACgv7+H >>> ApgOZBY/pz0cF9ZPiEkxnxs= >>> =Jnzy >>> -----END PGP SIGNATURE----- >>> >>> -- >>> This message has been scanned for viruses and >>> dangerous content by MailScanner, and is >>> believed to be clean. >>> For all your IT requirements visit www.transtec.co.uk >>> >>> -- >>> MailScanner mailing list >>> mailscanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> >>> Before posting, read http://wiki.mailscanner.info/posting >>> >>> Support MailScanner development - buy the book off the website! > From Carl.Andrews at crackerbarrel.com Mon Aug 13 14:58:41 2007 From: Carl.Andrews at crackerbarrel.com (Andrews Carl 455) Date: Mon Aug 13 14:58:46 2007 Subject: Sendmail help ?? Please. Message-ID: <113A0DFC086C984AB9EFDF6B8614F075017D34F1@exchange03.CBOCS.com> Thanks! I had the first FEATURE, but apparently need the 2nd and third also. FEATURE(`delay_checks', `friend', `n')dnl FEATURE(`delay_checks', `hater', `n')dnl FEATURE(`blacklist_recipients')dnl Thanks everyone who offered help and I appologize again for breaking into someone elses thread. Carl -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Scott Silva Sent: Friday, August 10, 2007 4:59 PM To: mailscanner@lists.mailscanner.info Subject: Re: Sendmail help ?? Please. Greg Matthews spake the following on 8/10/2007 7:42 AM: > Andrews Carl 455 wrote: >>> I suggest you install Webmin on your machine and use >> Thanks I will give that a try. >> >>> BTW, I think this is wrong: >>> 'makemap hash /etc/mail/access < /etc/mail/access' >>> correct: >>> 'makemap hash /etc/mail/access.db < /etc/mail/access' notice the >>> missing suffix? You may have actually overwritten your original >>> access file. Don't you >> get >>> any kind of an error message? >> >> I thought it odd myself, but the command is right off the >> sendmail.org page and it creates the .db. - >> http://www.sendmail.org/tips/relaying.php >> . >> > > the command as shown if fine. makemap just does the right thing. > >> >> Thanks again, >> Carl > > I think you need "feature delay_checks" in the sendmail.mc for to addresses to get checked in the access file. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From simon at saq.co.uk Mon Aug 13 15:22:28 2007 From: simon at saq.co.uk (Simon Jones) Date: Mon Aug 13 15:32:00 2007 Subject: help tweaking Message-ID: Hi, anyone know how I can figure out why mailscanner skips seemingly obvious spam messages? It does work quite well but there's a lot of stuff it's missing and I'm not sure why. Another weird thing is that some accounts don't get scanned at all, I setup a user in mailwatch and every message that hits the user is deemed clean even if it is spam, I probably need a little help with the config I guess as mcp doesn't seem to be doing anything either :( If anyone would give me some pointers on checking stuff out and tightening the rules it'd be great. I have installed rules de jour, pyzor razor etc also. Thanks! SMJ From list-mailscanner at linguaphone.com Mon Aug 13 15:43:52 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon Aug 13 15:44:15 2007 Subject: help tweaking In-Reply-To: References: Message-ID: <1187016232.17133.94.camel@gblades-suse.linguaphone-intranet.co.uk> The best thing to do is to upload an example somewhere so we can check it through spamassassin to see the rules which match for us. On Mon, 2007-08-13 at 15:22, Simon Jones wrote: > Hi, anyone know how I can figure out why mailscanner skips seemingly > obvious spam messages? It does work quite well but there's a lot of > stuff it's missing and I'm not sure why. Another weird thing is that > some accounts don't get scanned at all, I setup a user in mailwatch and > every message that hits the user is deemed clean even if it is spam, I > probably need a little help with the config I guess as mcp doesn't seem > to be doing anything either :( > > If anyone would give me some pointers on checking stuff out and > tightening the rules it'd be great. I have installed rules de jour, > pyzor razor etc also. > > Thanks! > > SMJ From simon at saq.co.uk Mon Aug 13 15:42:41 2007 From: simon at saq.co.uk (Simon Jones) Date: Mon Aug 13 15:52:14 2007 Subject: help tweaking References: <1187016232.17133.94.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: Hi Gareth, You mean headers? Like this: Received-SPF: none (nanigirl.net: No applicable sender policy available) receiver=mailgate1.domain.co.uk; identity=mfrom; envelope-from="haluk@nanigirl.net"; helo="[200.209.151.9]"; client-ip=200.209.151.9 Received: from [200.209.151.9] (unknown [200.209.151.9]) by mailgate1.domain.co.uk (Postfix) with ESMTP id 8E6396D85C3 for ; Mon, 13 Aug 2007 14:55:56 +0100 (BST) Received: from [106.102.184.130] (port=8400 helo=[106.102.184.130]) by [200.209.151.9] with esmtp id 1LcxvQ-000LFH-99 for customer@domain.co.uk; Mon, 13 Aug 2007 10:58:45 -0300 Message-ID: <001001c7ddb2$0677cc20$0997d1c8@xpsp2> From: "haluk buchanan" To: customer@domain.co.uk Subject: Date: Mon, 13 Aug 2007 10:58:28 -0300 MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----=_NextPart_000_000C_01C7DD98.E12A9420" X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2900.3138 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3138 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Gareth > Sent: 13 August 2007 15:44 > To: MailScanner discussion > Subject: Re: help tweaking > > The best thing to do is to upload an example somewhere so we can check > it through spamassassin to see the rules which match for us. > > On Mon, 2007-08-13 at 15:22, Simon Jones wrote: > > Hi, anyone know how I can figure out why mailscanner skips seemingly > > obvious spam messages? It does work quite well but there's a lot of > > stuff it's missing and I'm not sure why. Another weird thing is that > > some accounts don't get scanned at all, I setup a user in mailwatch > and > > every message that hits the user is deemed clean even if it is spam, > I > > probably need a little help with the config I guess as mcp doesn't > seem > > to be doing anything either :( > > > > If anyone would give me some pointers on checking stuff out and > > tightening the rules it'd be great. I have installed rules de jour, > > pyzor razor etc also. > > > > Thanks! > > > > SMJ > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From simon at saq.co.uk Mon Aug 13 15:45:56 2007 From: simon at saq.co.uk (Simon Jones) Date: Mon Aug 13 15:55:28 2007 Subject: help tweaking References: Message-ID: Some messages are scanned OK as follows, and other's just don't get scanned at all: SpamAssassin Spam: Y Action(s): store, header, "X-Spam-Status:, Yes" High Scoring Spam: Y Action(s): store, header, "X-Spam-Status:, Yes" SpamAssassin Spam: Y Listed in RBL: N Spam Whitelisted: N Spam Blacklisted: N SpamAssassin Autolearn: N SpamAssassin Score: 16.07 Spam Report: Score Matching Rule Description cached not score=16.076 3 required 1.66 FB_HARD_ERECTION 3.31 URIBL_AB_SURBL Contains an URL listed in the AB SURBL blocklist 3.36 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist 2.62 URIBL_OB_SURBL Contains an URL listed in the OB SURBL blocklist 3.60 URIBL_SC_SURBL Contains an URL listed in the SC SURBL blocklist 1.53 URIBL_WS_SURBL Contains an URL listed in the WS SURBL blocklist > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > Sent: 13 August 2007 15:22 > To: mailscanner@lists.mailscanner.info > Subject: help tweaking > > Hi, anyone know how I can figure out why mailscanner skips seemingly > obvious spam messages? It does work quite well but there's a lot of > stuff it's missing and I'm not sure why. Another weird thing is that > some accounts don't get scanned at all, I setup a user in mailwatch and > every message that hits the user is deemed clean even if it is spam, I > probably need a little help with the config I guess as mcp doesn't seem > to be doing anything either :( > > If anyone would give me some pointers on checking stuff out and > tightening the rules it'd be great. I have installed rules de jour, > pyzor razor etc also. > > Thanks! > > SMJ > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From list-mailscanner at linguaphone.com Mon Aug 13 15:59:16 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon Aug 13 15:59:36 2007 Subject: help tweaking In-Reply-To: References: <1187016232.17133.94.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <1187017156.17133.97.camel@gblades-suse.linguaphone-intranet.co.uk> No a full copy of the email source. I dont know of a way to get it from Outlook. I normally copy the file directly off our IMAP server. On Mon, 2007-08-13 at 15:42, Simon Jones wrote: > Hi Gareth, > > You mean headers? Like this: > > Received-SPF: none (nanigirl.net: No applicable sender policy available) > receiver=mailgate1.domain.co.uk; identity=mfrom; > envelope-from="haluk@nanigirl.net"; helo="[200.209.151.9]"; > client-ip=200.209.151.9 > Received: from [200.209.151.9] (unknown [200.209.151.9]) > by mailgate1.domain.co.uk (Postfix) with ESMTP id 8E6396D85C3 > for ; Mon, 13 Aug 2007 14:55:56 +0100 (BST) > Received: from [106.102.184.130] (port=8400 helo=[106.102.184.130]) > by [200.209.151.9] with esmtp > id 1LcxvQ-000LFH-99 > for customer@domain.co.uk; Mon, 13 Aug 2007 10:58:45 -0300 > Message-ID: <001001c7ddb2$0677cc20$0997d1c8@xpsp2> > From: "haluk buchanan" > To: customer@domain.co.uk > Subject: > Date: Mon, 13 Aug 2007 10:58:28 -0300 > MIME-Version: 1.0 > Content-Type: multipart/mixed; > boundary="----=_NextPart_000_000C_01C7DD98.E12A9420" > X-Priority: 3 > X-MSMail-Priority: Normal > X-Mailer: Microsoft Outlook Express 6.00.2900.3138 > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3138 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Gareth > > Sent: 13 August 2007 15:44 > > To: MailScanner discussion > > Subject: Re: help tweaking > > > > The best thing to do is to upload an example somewhere so we can check > > it through spamassassin to see the rules which match for us. > > > > On Mon, 2007-08-13 at 15:22, Simon Jones wrote: > > > Hi, anyone know how I can figure out why mailscanner skips > seemingly > > > obvious spam messages? It does work quite well but there's a lot of > > > stuff it's missing and I'm not sure why. Another weird thing is > that > > > some accounts don't get scanned at all, I setup a user in mailwatch > > and > > > every message that hits the user is deemed clean even if it is spam, > > I > > > probably need a little help with the config I guess as mcp doesn't > > seem > > > to be doing anything either :( > > > > > > If anyone would give me some pointers on checking stuff out and > > > tightening the rules it'd be great. I have installed rules de jour, > > > pyzor razor etc also. > > > > > > Thanks! > > > > > > SMJ > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! From simon at saq.co.uk Mon Aug 13 15:59:25 2007 From: simon at saq.co.uk (Simon Jones) Date: Mon Aug 13 16:08:58 2007 Subject: help tweaking References: <1187016232.17133.94.camel@gblades-suse.linguaphone-intranet.co.uk> <1187017156.17133.97.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: AAAH! Ok I think I may have figured out a problem in my setup, in MailScanner.conf I had 2 gateways with use spamassassin = &SQLnoScan and one of them with = yes I was trying to get the db working with mailwatch to enable users to enter a spam score which affects their setup but I was obviously distracted at some point and didn't change the setting back, apologies for being dumb :o) Ok that looks more consistent now - although I don't appear to have mcp working, how do I check that mcp is working ok? Simon > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Gareth > Sent: 13 August 2007 15:59 > To: MailScanner discussion > Subject: RE: help tweaking > > No a full copy of the email source. I dont know of a way to get it from > Outlook. I normally copy the file directly off our IMAP server. > > On Mon, 2007-08-13 at 15:42, Simon Jones wrote: > > Hi Gareth, > > > > You mean headers? Like this: > > > > Received-SPF: none (nanigirl.net: No applicable sender policy > available) > > receiver=mailgate1.domain.co.uk; identity=mfrom; > > envelope-from="haluk@nanigirl.net"; helo="[200.209.151.9]"; > > client-ip=200.209.151.9 > > Received: from [200.209.151.9] (unknown [200.209.151.9]) > > by mailgate1.domain.co.uk (Postfix) with ESMTP id 8E6396D85C3 > > for ; Mon, 13 Aug 2007 14:55:56 +0100 > (BST) > > Received: from [106.102.184.130] (port=8400 helo=[106.102.184.130]) > > by [200.209.151.9] with esmtp > > id 1LcxvQ-000LFH-99 > > for customer@domain.co.uk; Mon, 13 Aug 2007 10:58:45 -0300 > > Message-ID: <001001c7ddb2$0677cc20$0997d1c8@xpsp2> > > From: "haluk buchanan" > > To: customer@domain.co.uk > > Subject: > > Date: Mon, 13 Aug 2007 10:58:28 -0300 > > MIME-Version: 1.0 > > Content-Type: multipart/mixed; > > boundary="----=_NextPart_000_000C_01C7DD98.E12A9420" > > X-Priority: 3 > > X-MSMail-Priority: Normal > > X-Mailer: Microsoft Outlook Express 6.00.2900.3138 > > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3138 > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- > > > bounces@lists.mailscanner.info] On Behalf Of Gareth > > > Sent: 13 August 2007 15:44 > > > To: MailScanner discussion > > > Subject: Re: help tweaking > > > > > > The best thing to do is to upload an example somewhere so we can > check > > > it through spamassassin to see the rules which match for us. > > > > > > On Mon, 2007-08-13 at 15:22, Simon Jones wrote: > > > > Hi, anyone know how I can figure out why mailscanner skips > > seemingly > > > > obvious spam messages? It does work quite well but there's a lot > of > > > > stuff it's missing and I'm not sure why. Another weird thing is > > that > > > > some accounts don't get scanned at all, I setup a user in > mailwatch > > > and > > > > every message that hits the user is deemed clean even if it is > spam, > > > I > > > > probably need a little help with the config I guess as mcp > doesn't > > > seem > > > > to be doing anything either :( > > > > > > > > If anyone would give me some pointers on checking stuff out and > > > > tightening the rules it'd be great. I have installed rules de > jour, > > > > pyzor razor etc also. > > > > > > > > Thanks! > > > > > > > > SMJ > > > > > > -- > > > MailScanner mailing list > > > mailscanner@lists.mailscanner.info > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From list-mailscanner at linguaphone.com Mon Aug 13 16:10:30 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon Aug 13 16:10:42 2007 Subject: help tweaking In-Reply-To: References: Message-ID: <1187017830.17131.99.camel@gblades-suse.linguaphone-intranet.co.uk> I take it you are using mailwatch. What does it say for a spam that got through? On Mon, 2007-08-13 at 15:45, Simon Jones wrote: > Some messages are scanned OK as follows, and other's just don't get > scanned at all: > > SpamAssassin > Spam: Y Action(s): store, header, "X-Spam-Status:, Yes" > High Scoring Spam: Y Action(s): store, header, "X-Spam-Status:, Yes" > SpamAssassin Spam: Y > Listed in RBL: N > Spam Whitelisted: N > Spam Blacklisted: N > SpamAssassin Autolearn: N > SpamAssassin Score: 16.07 > Spam Report: Score Matching Rule Description > cached not > score=16.076 > 3 required > 1.66 FB_HARD_ERECTION > 3.31 URIBL_AB_SURBL Contains an URL listed in the AB SURBL blocklist > 3.36 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist > 2.62 URIBL_OB_SURBL Contains an URL listed in the OB SURBL blocklist > 3.60 URIBL_SC_SURBL Contains an URL listed in the SC SURBL blocklist > 1.53 URIBL_WS_SURBL Contains an URL listed in the WS SURBL blocklist > > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > > Sent: 13 August 2007 15:22 > > To: mailscanner@lists.mailscanner.info > > Subject: help tweaking > > > > Hi, anyone know how I can figure out why mailscanner skips seemingly > > obvious spam messages? It does work quite well but there's a lot of > > stuff it's missing and I'm not sure why. Another weird thing is that > > some accounts don't get scanned at all, I setup a user in mailwatch > and > > every message that hits the user is deemed clean even if it is spam, I > > probably need a little help with the config I guess as mcp doesn't > seem > > to be doing anything either :( > > > > If anyone would give me some pointers on checking stuff out and > > tightening the rules it'd be great. I have installed rules de jour, > > pyzor razor etc also. > > > > Thanks! > > > > SMJ > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! From list-mailscanner at linguaphone.com Mon Aug 13 16:12:56 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon Aug 13 16:13:04 2007 Subject: help tweaking In-Reply-To: References: <1187016232.17133.94.camel@gblades-suse.linguaphone-intranet.co.uk> <1187017156.17133.97.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <1187017976.17136.102.camel@gblades-suse.linguaphone-intranet.co.uk> Did you specifically setup mcp? Most people dont use it. I didn't notice any mention of bayes in your earlier post. Perhaps you haven't learnt enough ham and spams for it to work yet. On Mon, 2007-08-13 at 15:59, Simon Jones wrote: > AAAH! Ok I think I may have figured out a problem in my setup, in > MailScanner.conf I had 2 gateways with use spamassassin = &SQLnoScan and > one of them with = yes > > I was trying to get the db working with mailwatch to enable users to > enter a spam score which affects their setup but I was obviously > distracted at some point and didn't change the setting back, apologies > for being dumb :o) > > Ok that looks more consistent now - although I don't appear to have mcp > working, how do I check that mcp is working ok? > > Simon > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Gareth > > Sent: 13 August 2007 15:59 > > To: MailScanner discussion > > Subject: RE: help tweaking > > > > No a full copy of the email source. I dont know of a way to get it > from > > Outlook. I normally copy the file directly off our IMAP server. > > > > On Mon, 2007-08-13 at 15:42, Simon Jones wrote: > > > Hi Gareth, > > > > > > You mean headers? Like this: > > > > > > Received-SPF: none (nanigirl.net: No applicable sender policy > > available) > > > receiver=mailgate1.domain.co.uk; identity=mfrom; > > > envelope-from="haluk@nanigirl.net"; helo="[200.209.151.9]"; > > > client-ip=200.209.151.9 > > > Received: from [200.209.151.9] (unknown [200.209.151.9]) > > > by mailgate1.domain.co.uk (Postfix) with ESMTP id 8E6396D85C3 > > > for ; Mon, 13 Aug 2007 14:55:56 +0100 > > (BST) > > > Received: from [106.102.184.130] (port=8400 helo=[106.102.184.130]) > > > by [200.209.151.9] with esmtp > > > id 1LcxvQ-000LFH-99 > > > for customer@domain.co.uk; Mon, 13 Aug 2007 10:58:45 -0300 > > > Message-ID: <001001c7ddb2$0677cc20$0997d1c8@xpsp2> > > > From: "haluk buchanan" > > > To: customer@domain.co.uk > > > Subject: > > > Date: Mon, 13 Aug 2007 10:58:28 -0300 > > > MIME-Version: 1.0 > > > Content-Type: multipart/mixed; > > > boundary="----=_NextPart_000_000C_01C7DD98.E12A9420" > > > X-Priority: 3 > > > X-MSMail-Priority: Normal > > > X-Mailer: Microsoft Outlook Express 6.00.2900.3138 > > > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3138 > > > > > > > -----Original Message----- > > > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner- > > > > bounces@lists.mailscanner.info] On Behalf Of Gareth > > > > Sent: 13 August 2007 15:44 > > > > To: MailScanner discussion > > > > Subject: Re: help tweaking > > > > > > > > The best thing to do is to upload an example somewhere so we can > > check > > > > it through spamassassin to see the rules which match for us. > > > > > > > > On Mon, 2007-08-13 at 15:22, Simon Jones wrote: > > > > > Hi, anyone know how I can figure out why mailscanner skips > > > seemingly > > > > > obvious spam messages? It does work quite well but there's a > lot > > of > > > > > stuff it's missing and I'm not sure why. Another weird thing is > > > that > > > > > some accounts don't get scanned at all, I setup a user in > > mailwatch > > > > and > > > > > every message that hits the user is deemed clean even if it is > > spam, > > > > I > > > > > probably need a little help with the config I guess as mcp > > doesn't > > > > seem > > > > > to be doing anything either :( > > > > > > > > > > If anyone would give me some pointers on checking stuff out and > > > > > tightening the rules it'd be great. I have installed rules de > > jour, > > > > > pyzor razor etc also. > > > > > > > > > > Thanks! > > > > > > > > > > SMJ > > > > > > > > -- > > > > MailScanner mailing list > > > > mailscanner@lists.mailscanner.info > > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > > > Support MailScanner development - buy the book off the website! > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! From mkercher at nfsmith.com Mon Aug 13 16:33:32 2007 From: mkercher at nfsmith.com (Mike Kercher) Date: Mon Aug 13 16:33:36 2007 Subject: CRM114 Problem In-Reply-To: <8692087.14471186823121824.JavaMail.root@office.splatnix.net> References: <224FA7E11EA39E45843E11CEBBD3A36F189AAA@HOUPEX01.nfsmith.info> <8692087.14471186823121824.JavaMail.root@office.splatnix.net> Message-ID: <224FA7E11EA39E45843E11CEBBD3A36F189B63@HOUPEX01.nfsmith.info> MS/sendmail run as root Mike -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Saturday, August 11, 2007 4:05 AM To: MailScanner discussion Subject: Re: CRM114 Problem What user is MS running as ? If non-root then the perms on crm114 do not allow write by anybody else. Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Mike Kercher" To: "MailScanner discussion" Sent: 10 August 2007 19:09:39 o'clock (GMT) Europe/London Subject: RE: CRM114 Problem [root@mail spamassassin]# ls -lR .: total 68 drwxr-xr-x 2 root root 4096 Aug 10 13:07 crm114 -rw-r--r-- 1 root root 4737 Aug 10 13:05 crm114.cf -rw-r--r-- 1 root root 16394 Aug 2 07:25 crm114.pm -rw-r--r-- 1 root root 1089 Aug 5 15:02 init.pre -rw-r--r-- 1 root root 274 Jul 25 10:43 local.cf lrwxrwxrwx 1 root root 41 Aug 5 15:02 mailscanner.cf -> /etc/MailScanner/spam.assassin.prefs.conf drwx------ 2 root root 4096 Aug 5 15:25 sa-update-keys -rw-r--r-- 1 root root 64 Jul 25 10:43 spamassassin-default.rc -rw-r--r-- 1 root root 35 Jul 25 10:43 spamassassin-helper.sh -rw-r--r-- 1 root root 55 Jul 25 10:43 spamassassin-spamc.rc -rw-r--r-- 1 root root 2439 Aug 5 18:55 v310.pre -rw-r--r-- 1 root root 922 Jul 25 10:44 v312.pre -rw-r--r-- 1 root root 2346 Aug 5 11:26 v320.pre ./crm114: total 18612 -rw-r--r-- 1 root root 0 Aug 5 18:24 blacklist.mfp -rw-r--r-- 1 root root 17412 Aug 5 18:27 mailfilter.cf -rwxr-xr-x 1 root root 44537 Aug 5 18:23 mailfilter.crm -rwxr-xr-x 1 root root 14511 Aug 5 18:23 maillib.crm -rwxr-xr-x 1 root root 22739 Aug 5 11:08 mailreaver.crm -rwxr-xr-x 1 root root 37621 Aug 5 18:23 mailtrainer.crm -rw------- 1 root root 6291444 Aug 10 13:07 nonspam.css -rw-r--r-- 1 root root 49 Aug 5 18:24 priolist.mfp -rw-r--r-- 1 root root 0 Aug 5 18:24 rewrites.mfp -rw-r--r-- 1 root root 12582924 Aug 10 13:07 spam.css -rw-r--r-- 1 root root 0 Aug 5 18:24 whitelist.mfp -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of UxBoD Sent: Friday, August 10, 2007 11:54 AM To: MailScanner discussion Subject: Re: CRM114 Problem ls -lR /etc/mail/spamassassin plus crm114.cf Regards, --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net ----- Original Message ----- From: "Mike Kercher" To: "MailScanner discussion" Sent: 10 August 2007 17:12:34 o'clock (GMT) Europe/London Subject: CRM114 Problem I added CRM114 to a server last week per the docs in the wiki (and like I've done on several other servers), but the score is always -0.00 [root@mail crm114]# cssutil -b -r spam.css Sparse spectra file spam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 15495 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 [root@mail crm114]# cssutil -b -r nonspam.css Sparse spectra file nonspam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 15495 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 The Features learned hasn't changed in many days. Permissions look good, .crm's are +x Any suggestions where to look? Mike -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From email at ace.net.au Mon Aug 13 17:13:42 2007 From: email at ace.net.au (Peter Nitschke) Date: Mon Aug 13 17:16:51 2007 Subject: [Fwd: Re: Spamhaus issues? (fwd)] In-Reply-To: <223f97700708130348l50c13590t60e4e45c8b1cb163@mail.gmail.com> References: <46BEE7F3.9040405@ecs.soton.ac.uk> <200708131154570129.01EE6DF4@dns3.ace.net.au> <46C01873.4050805@ecs.soton.ac.uk> <223f97700708130348l50c13590t60e4e45c8b1cb163@mail.gmail.com> Message-ID: <200708140143420150.04E52C51@dns3.ace.net.au> Did I miss a bunch of posts about this? Glenn, I don't see any mobbing, just cause and effect and 2 emails expressing relief or thanks for the action taken. No doubt all of us are good people beneath the surface, but that doesn't absolve us from having to maintain respect for other members of the community. Anybody that has had the responsibility of moderating a list or forum will have come across an evil-bunny persona clone, and at some point action needs to be taken for the wellbeing and functionality of the list. Yes, it is sad, but Julian was very diplomatic with his polite request, and for his trouble was told that the list is full of crud, and that Julian was at fault for not being a tougher moderator. All that was needed was a polite acknowledgement of the request, or no comment at all. Let's move on. Cheers, Peter *********** REPLY SEPARATOR *********** On 13/08/2007 at 12:48 PM Glenn Steen wrote: >Well.... I will speak to Noels defense. >Yes, he is opinionated, and yes, he is stubborn... and very very >drastic in his expressions. >I have not been following this thread in any greater detail, since it >stopped being interresting a while back. > >But he has on several occasions contributed his knowledge in >constructive ways... And if you only scratch lightly on the surface, >he is a very caring and kind person. >My views are doubtless coloured by the helping hand he has reached out >to me recently, when I most needed a kind word from a friend, but ... >Is it really OK to gang up on him like you do now? >To act out on the suggestion to evict him from the list is quite OK by >me, and indeed by him as well, Jules. Even talking about it could've >been OK. But I think you've come very close to a line here, almost ... >gloating ... over the act. > >I do know (and have been know to agree vocally) that his language can >be more than what is acceptable. That is not my point. >I'm just saying we seem to have changed one (in my view minor) evil >for another (that I, with my background and "old luggage" find very >hard to accept... After all, it's bordering on mobbing). > >I'm not saying that anyone else of the participants of the thread >should be "punished". Just that you all should remember that it is >people at the other end. > >Respectfully yours >-- >-- Glenn From email at ace.net.au Mon Aug 13 17:21:40 2007 From: email at ace.net.au (Peter Nitschke) Date: Mon Aug 13 17:24:49 2007 Subject: Yum/RPM install Message-ID: <200708140151400117.04EC7761@dns3.ace.net.au> There have been a few threads on the issue of making more use of yum and or RPM's to install MailScanner and SA/Clam-av, but none of them seem to have come to any real conclusion. Is there any real disadvantage to doing it all with RPM's rather than having all the modules compiled with each install or upgrade? Peter From sconway at wlnet.com Mon Aug 13 17:29:54 2007 From: sconway at wlnet.com (Stephen Conway) Date: Mon Aug 13 17:29:25 2007 Subject: Size Rejections Message-ID: <038601c7ddc7$2de03fd0$89a0bf70$@com> Hello All: We have the requirement to reject messages back to users that exceed a pre-defined size limit. We have this working well, but in the rejection that goes we have the need to show the sender both the size of his message and possibly the size limit for the message they sent that they exceeded. Are there any variables to pass in the report for these? Is this possible? Regards, Stephen Conway -- ShipMail Now 30% Faster From list-mailscanner at linguaphone.com Mon Aug 13 17:33:52 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon Aug 13 17:34:02 2007 Subject: Yum/RPM install In-Reply-To: <200708140151400117.04EC7761@dns3.ace.net.au> Message-ID: Managing perl modules would be a real pain as you would practically have to install them as separate RPM's aswell. RPM has its own versioning and upgrade system which perl also has. Trying to mix them both at the same time can cause lots of issues. > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Peter > Nitschke > Sent: 13 August 2007 17:22 > To: mailscanner@lists.mailscanner.info > Subject: Yum/RPM install > > > There have been a few threads on the issue of making more use of > yum and or > RPM's to install MailScanner and SA/Clam-av, but none of them seem to have > come to any real conclusion. > > Is there any real disadvantage to doing it all with RPM's rather than > having all the modules compiled with each install or upgrade? > > Peter > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > From prandal at herefordshire.gov.uk Mon Aug 13 17:47:11 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Mon Aug 13 17:47:17 2007 Subject: Yum/RPM install In-Reply-To: References: <200708140151400117.04EC7761@dns3.ace.net.au> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA015118BD@HC-MBX02.herefordshire.gov.uk> Installing perl modules via CPAN can be a pain too. I've taken a pragmatic approach here on our new MailScanner boxes, which is to: 1: Use Julian's installers for ClamAV/SA and MailScanner 2: Install additional perl modules (e.g. perl-Mail-DKIM, etc) from the rpmforge yum repository So far I haven't had to use CPAN to install any required modules. This makes maintenance so much easier, and helps ensure that any security vulnerabilites get dealt with in a timely manner (either via yum or Julian's updated tarballs). Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Gareth > Sent: 13 August 2007 17:34 > To: MailScanner discussion > Subject: RE: Yum/RPM install > > Managing perl modules would be a real pain as you would > practically have to > install them as separate RPM's aswell. RPM has its own versioning and > upgrade system which perl also has. Trying to mix them both > at the same time > can cause lots of issues. > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info]On > Behalf Of Peter > > Nitschke > > Sent: 13 August 2007 17:22 > > To: mailscanner@lists.mailscanner.info > > Subject: Yum/RPM install > > > > > > There have been a few threads on the issue of making more use of > > yum and or > > RPM's to install MailScanner and SA/Clam-av, but none of > them seem to have > > come to any real conclusion. > > > > Is there any real disadvantage to doing it all with RPM's > rather than > > having all the modules compiled with each install or upgrade? > > > > Peter > > > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From email at ace.net.au Mon Aug 13 17:49:51 2007 From: email at ace.net.au (Peter Nitschke) Date: Mon Aug 13 17:52:59 2007 Subject: Yum/RPM install In-Reply-To: References: Message-ID: <200708140219510349.050645C0@dns3.ace.net.au> Which is why I like the concept of doing it all with RPMs. Most are available on the major repo sites, the handful that aren't I have let Julian's script create, then made a local repo for them so I can do repeat installs simply and quickly to other PC's. I realise this is OS specific, but most of us with multiple servers to manage have probably standardised on a particular OS, in my case Centos 5. The MS install script pretty much creates then installs everything as RPM's, and the recent SA/Clam install script recommends using clam RPM's, so I figure that going the last step to all RPM's makes good sense. Julians scripts do a few tweak, eg to SA v3xx.pre files which is easy enough to duplicate, but would I be missing anything else? My thoughts are towards lower manual maintenance by being able to do future upgrades all by RPM, and by being able to create servers with a known predictable setup which doesn't tend to happen if you configure them all individually. Peter *********** REPLY SEPARATOR *********** On 13/08/2007 at 5:33 PM Gareth wrote: >Managing perl modules would be a real pain as you would practically have >to >install them as separate RPM's aswell. RPM has its own versioning and >upgrade system which perl also has. Trying to mix them both at the same >time >can cause lots of issues. > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Peter >> Nitschke >> Sent: 13 August 2007 17:22 >> To: mailscanner@lists.mailscanner.info >> Subject: Yum/RPM install >> >> >> There have been a few threads on the issue of making more use of >> yum and or >> RPM's to install MailScanner and SA/Clam-av, but none of them seem to >have >> come to any real conclusion. >> >> Is there any real disadvantage to doing it all with RPM's rather than >> having all the modules compiled with each install or upgrade? >> >> Peter >> >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >> >> > >-- >MailScanner mailing list >mailscanner@lists.mailscanner.info >http://lists.mailscanner.info/mailman/listinfo/mailscanner > >Before posting, read http://wiki.mailscanner.info/posting > >Support MailScanner development - buy the book off the website! From naolson at gmail.com Mon Aug 13 18:05:44 2007 From: naolson at gmail.com (Nathan Olson) Date: Mon Aug 13 18:06:03 2007 Subject: Yum/RPM install In-Reply-To: <200708140219510349.050645C0@dns3.ace.net.au> References: <200708140219510349.050645C0@dns3.ace.net.au> Message-ID: <8f54b4330708131005n4a23b940hfd9dff9eef46aaf4@mail.gmail.com> We build RPMs for MailScanner and all it's prerequisites. It works fine if you're patient enough to build and maintain them. We only need to build the ones that RedHat doesn't provide already. Nate From list-mailscanner at linguaphone.com Mon Aug 13 18:14:37 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon Aug 13 18:14:47 2007 Subject: Yum/RPM install In-Reply-To: <8f54b4330708131005n4a23b940hfd9dff9eef46aaf4@mail.gmail.com> Message-ID: You also have to build rpms for the packages that redhat wont upgrade aswell. For example I run FC6 but the latest spamassassin available through yum is 3.1.9 since 3.2 is a new major version. For situations like this you want to either maintain your own specific rpm repository or do it via source. Given the variety of playforms and the age of some of the systems there would have to be multiple rpm versions to cater for different library versions that people use for example. With source Julian only needs to worry about one version and since it is compiled it is optimised for the hardware it is running on. > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Nathan > Olson > Sent: 13 August 2007 18:06 > To: MailScanner discussion > Subject: Re: Re[2]: Yum/RPM install > > > We build RPMs for MailScanner and all it's prerequisites. > It works fine if you're patient enough to build and maintain them. > We only need to build the ones that RedHat doesn't provide already. > > Nate > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > From MailScanner at ecs.soton.ac.uk Mon Aug 13 18:17:13 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 13 18:17:49 2007 Subject: Yum/RPM install In-Reply-To: <200708140219510349.050645C0@dns3.ace.net.au> References: <200708140219510349.050645C0@dns3.ace.net.au> Message-ID: <46C09219.3020503@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 How about this? Would you like me to create another ClamAV+SA distribution that used SRPMs in the same way my MailScanner install script does? It will take a bit of work on my part to build all the RPMs, but easy enough to maintain once I've got it there. Does that help you, or not? I'm not going to waste the effort, it's a significant amount of time. Peter Nitschke wrote: > Which is why I like the concept of doing it all with RPMs. > > Most are available on the major repo sites, the handful that aren't I have > let Julian's script create, then made a local repo for them so I can do > repeat installs simply and quickly to other PC's. > > I realise this is OS specific, but most of us with multiple servers to > manage have probably standardised on a particular OS, in my case Centos 5. > > The MS install script pretty much creates then installs everything as > RPM's, and the recent SA/Clam install script recommends using clam RPM's, > so I figure that going the last step to all RPM's makes good sense. > > Julians scripts do a few tweak, eg to SA v3xx.pre files which is easy > enough to duplicate, but would I be missing anything else? > > My thoughts are towards lower manual maintenance by being able to do future > upgrades all by RPM, and by being able to create servers with a known > predictable setup which doesn't tend to happen if you configure them all > individually. > > Peter > > > *********** REPLY SEPARATOR *********** > > On 13/08/2007 at 5:33 PM Gareth wrote: > > >> Managing perl modules would be a real pain as you would practically have >> to >> install them as separate RPM's aswell. RPM has its own versioning and >> upgrade system which perl also has. Trying to mix them both at the same >> time >> can cause lots of issues. >> >> >>> -----Original Message----- >>> From: mailscanner-bounces@lists.mailscanner.info >>> [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Peter >>> Nitschke >>> Sent: 13 August 2007 17:22 >>> To: mailscanner@lists.mailscanner.info >>> Subject: Yum/RPM install >>> >>> >>> There have been a few threads on the issue of making more use of >>> yum and or >>> RPM's to install MailScanner and SA/Clam-av, but none of them seem to >>> >> have >> >>> come to any real conclusion. >>> >>> Is there any real disadvantage to doing it all with RPM's rather than >>> having all the modules compiled with each install or upgrade? >>> >>> Peter >>> >>> >>> -- >>> MailScanner mailing list >>> mailscanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> >>> Before posting, read http://wiki.mailscanner.info/posting >>> >>> Support MailScanner development - buy the book off the website! >>> >>> >>> >>> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> > > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGwJIaEfZZRxQVtlQRAlPCAKDqmUB748A5UHmQ+UAiVGI5NBa9zwCfYcLd 2j+Gr0bpvn2D+Ao1Thhc+9s= =Vh2+ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Mon Aug 13 18:19:42 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 13 18:20:20 2007 Subject: Size Rejections In-Reply-To: <038601c7ddc7$2de03fd0$89a0bf70$@com> References: <038601c7ddc7$2de03fd0$89a0bf70$@com> Message-ID: <46C092AE.7070603@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I don't think you can do it now, but it is possible. Mail me off-list tomorrow and I'll show you how. Stephen Conway wrote: > Hello All: > > We have the requirement to reject messages back to users that exceed a > pre-defined size limit. We have this working well, but in the rejection that > goes we have the need to show the sender both the size of his message and > possibly the size limit for the message they sent that they exceeded. Are > there any variables to pass in the report for these? Is this possible? > > Regards, > > Stephen Conway > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGwJKuEfZZRxQVtlQRAgb0AJ9B954guHi4nnEEVzvgBJrepaB+jwCgq8H0 wgNJm3MA+iAsnCYqbFHaUdI= =lb0F -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From stinkybob at gmail.com Mon Aug 13 18:43:52 2007 From: stinkybob at gmail.com (Eugene MacDougal) Date: Mon Aug 13 18:43:58 2007 Subject: Custom Logging Message-ID: <2579c6b20708131043r6affc8eamd9f48ee608d4db61@mail.gmail.com> I am starting a custom log function so that I can have more details all in a one-liner log. Is there a variable I can grab that will give me how long it took for the mail to process (virus scan, spam scan, etc)? Thanks, Gene -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070813/e558ff91/attachment.html From MailScanner at ecs.soton.ac.uk Mon Aug 13 19:27:01 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 13 19:27:39 2007 Subject: Yum/RPM install In-Reply-To: References: Message-ID: <46C0A275.8050806@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 You say "with source" near the end of your comment. Do you mean "with builds from source (i.e. same as installing via CPAN)" or do you mean "with SRPMs"? Any RPM-based distro of ClamAV+SA I did would involve SRPMs for all the Perl stuff anyway, I refuse to distribute RPMs of Perl modules as they make no sense for exactly the reasons you have described. Gareth wrote: > You also have to build rpms for the packages that redhat wont upgrade > aswell. For example I run FC6 but the latest spamassassin available through > yum is 3.1.9 since 3.2 is a new major version. > For situations like this you want to either maintain your own specific rpm > repository or do it via source. > Given the variety of playforms and the age of some of the systems there > would have to be multiple rpm versions to cater for different library > versions that people use for example. With source Julian only needs to worry > about one version and since it is compiled it is optimised for the hardware > it is running on. > > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Nathan >> Olson >> Sent: 13 August 2007 18:06 >> To: MailScanner discussion >> Subject: Re: Re[2]: Yum/RPM install >> >> >> We build RPMs for MailScanner and all it's prerequisites. >> It works fine if you're patient enough to build and maintain them. >> We only need to build the ones that RedHat doesn't provide already. >> >> Nate >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >> >> >> > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGwKJ1EfZZRxQVtlQRAnz6AJ9RHjZX40dbSk2q5uUF9T/OVzIbIwCcCP69 BX8ubb8ss5hR2Wz68tB4CWc= =gKjK -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Mon Aug 13 19:29:28 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 13 19:30:03 2007 Subject: Custom Logging In-Reply-To: <2579c6b20708131043r6affc8eamd9f48ee608d4db61@mail.gmail.com> References: <2579c6b20708131043r6affc8eamd9f48ee608d4db61@mail.gmail.com> Message-ID: <46C0A308.6010703@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 No there isn't at the moment, sorry. You can't work it out on a per-message basis anyway, as virus scanning (at least) is a per-batch process, not a per-message process. That's one of the reasons MailScanner is as fast (or as slow :-) as it is, compared to other packages such as avamis. Eugene MacDougal wrote: > I am starting a custom log function so that I can have more details > all in a one-liner log. Is there a variable I can grab that will give > me how long it took for the mail to process (virus scan, spam scan, etc)? > > Thanks, > Gene Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGwKMJEfZZRxQVtlQRAsW4AJ9tDiCwRV4PHzaV7W7VSj7GvQdYnQCfWEBF gHvpe3b+tFgIGulUJpHJESw= =H+g4 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From list-mailscanner at linguaphone.com Mon Aug 13 19:42:46 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon Aug 13 19:42:55 2007 Subject: Yum/RPM install In-Reply-To: <46C0A275.8050806@ecs.soton.ac.uk> Message-ID: Yes it full RPMs that I disaprove of as you mentioned. As far as using SRPMs I dont mind either way. Whether it be SRPM or a pure tarball the perl modules get installed and compiled from source so it makes little difference in my mind. > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Julian > Field > Sent: 13 August 2007 19:27 > To: MailScanner discussion > Subject: Re: Yum/RPM install > > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > You say "with source" near the end of your comment. Do you mean "with > builds from source (i.e. same as installing via CPAN)" or do you mean > "with SRPMs"? > > Any RPM-based distro of ClamAV+SA I did would involve SRPMs for all the > Perl stuff anyway, I refuse to distribute RPMs of Perl modules as they > make no sense for exactly the reasons you have described. > > Gareth wrote: > > You also have to build rpms for the packages that redhat wont upgrade > > aswell. For example I run FC6 but the latest spamassassin > available through > > yum is 3.1.9 since 3.2 is a new major version. > > For situations like this you want to either maintain your own > specific rpm > > repository or do it via source. > > Given the variety of playforms and the age of some of the systems there > > would have to be multiple rpm versions to cater for different library > > versions that people use for example. With source Julian only > needs to worry > > about one version and since it is compiled it is optimised for > the hardware > > it is running on. > > > > > >> -----Original Message----- > >> From: mailscanner-bounces@lists.mailscanner.info > >> [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Nathan > >> Olson > >> Sent: 13 August 2007 18:06 > >> To: MailScanner discussion > >> Subject: Re: Re[2]: Yum/RPM install > >> > >> > >> We build RPMs for MailScanner and all it's prerequisites. > >> It works fine if you're patient enough to build and maintain them. > >> We only need to build the ones that RedHat doesn't provide already. > >> > >> Nate > >> -- > >> MailScanner mailing list > >> mailscanner@lists.mailscanner.info > >> http://lists.mailscanner.info/mailman/listinfo/mailscanner > >> > >> Before posting, read http://wiki.mailscanner.info/posting > >> > >> Support MailScanner development - buy the book off the website! > >> > >> > >> > >> > > > > > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.2 (Build 2014) > Charset: ISO-8859-1 > > wj8DBQFGwKJ1EfZZRxQVtlQRAnz6AJ9RHjZX40dbSk2q5uUF9T/OVzIbIwCcCP69 > BX8ubb8ss5hR2Wz68tB4CWc= > =gKjK > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > From sconway at wlnet.com Mon Aug 13 19:50:53 2007 From: sconway at wlnet.com (Stephen Conway) Date: Mon Aug 13 19:50:24 2007 Subject: Test, not receiving MS List message Message-ID: <03ee01c7ddda$e06b5cd0$a1421670$@com> Hello All: Test to the list. I can see my posts are going to the list (via the archives), but I am not getting them. I don't see any messages from the list in my mail system today either. Other mails are generally OK. Regards, Stephen Conway -- ShipMail Now 30% Faster From naolson at gmail.com Mon Aug 13 19:52:34 2007 From: naolson at gmail.com (Nathan Olson) Date: Mon Aug 13 19:52:37 2007 Subject: Yum/RPM install In-Reply-To: References: <8f54b4330708131005n4a23b940hfd9dff9eef46aaf4@mail.gmail.com> Message-ID: <8f54b4330708131152i1d11c455mce57d1b93cf5bc1f@mail.gmail.com> All completely valid points. We build our own spamassassin RPMs as well. It works for us, but mileage will vary like you've mentioned. Nate From mailscanner at slackadelic.com Mon Aug 13 19:54:04 2007 From: mailscanner at slackadelic.com (Matt Hayes) Date: Mon Aug 13 19:54:14 2007 Subject: Test, not receiving MS List message In-Reply-To: <03ee01c7ddda$e06b5cd0$a1421670$@com> References: <03ee01c7ddda$e06b5cd0$a1421670$@com> Message-ID: <46C0A8CC.7010809@slackadelic.com> Stephen Conway wrote: > Hello All: > > Test to the list. I can see my posts are going to the list (via the > archives), but I am not getting them. I don't see any messages from the > list in my mail system today either. Other mails are generally OK. > > Regards, > > Stephen Conway > > Stephen, I got your message. Just let you know in IRC too ;) -Matt From sconway at wlnet.com Mon Aug 13 20:03:14 2007 From: sconway at wlnet.com (Stephen Conway) Date: Mon Aug 13 20:02:44 2007 Subject: Test, not receiving MS List message Message-ID: <041301c7dddc$998321c0$cc896540$@com> Hello All: I had a vacation message attached to my mailbox last week, not sure if because of this, the list moderator maybe put a block on sending me the lists messages. If so, please remove as I have stopped the vacation message. Regards, Stephen Conway -- ShipMail Now 30% Faster From ssilva at sgvwater.com Mon Aug 13 20:20:48 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon Aug 13 20:21:00 2007 Subject: [Fwd: Re: Spamhaus issues? (fwd)] In-Reply-To: <46BEE7F3.9040405@ecs.soton.ac.uk> References: <46BEE7F3.9040405@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 8/12/2007 3:58 AM: > This is the comment I got from Res in reply to my gentle tap on the > shoulder. > I've had enough of his attitude for a very long time. Sorry, but he > asked for it. > > -------- Original Message -------- > Subject: Re: Spamhaus issues? (fwd) > Date: Sun, 12 Aug 2007 08:42:59 +1000 (EST) > From: Res > To: Julian Field > > > > Its about as on topic as the rest of the crud around on list, so is this > selective censorship I am seeing... probably, since you dont make a point > of shutting down all off topic threads. If you want me off your list > just unsub me, you have my blessing, as I doubt I contribute anything to > the mailscanner community anyway. Remember to take me off the beta list > as well. > > > > > ---------- Forwarded message ---------- > Date: Sat, 11 Aug 2007 23:27:33 +0100 > From: Julian Field > Reply-To: MailScanner discussion > To: MailScanner discussion > Subject: Re: Spamhaus issues? > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > C'mon guys, let's call it a day for this thread. The discussion is no > longer relevant to others. If you wish to argue/debate/discuss, feel > free, just do it off-list. > > Thanks, > Jules. > > Res wrote: >> * PGP Signed by an unknown key > >> *yawn* >> I got your point Kai, the fact is you introduced something (dynamic ip >> blocks) into the debate that was completely irrelevant, pay closer >> attention next time. > > >> On Sat, 11 Aug 2007, Kai Schaetzl wrote: > >>> Res wrote on Sat, 11 Aug 2007 07:54:58 +1000 (EST): >>> >>>> *sigh* >>> Indeed, you didn't get the point from the beginning and are still not >>> getting it and are not even trying to get it. EOT. >>> >>> Kai >>> >>> > > > Jules > I have but one question. Did you remove him, or did he remove himself? I hope that he did not just leave in anger, as he has made many worthwhile contributions, and maybe he will regret his hasty in-anger response, and come back. In your defense, you have "tapped" other off topic threads before, and it is usually when they turn into virtual fist fights. You seem to have great tolerance for the occasional off-topic thread, even though they get very far from the original topic. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Mon Aug 13 20:28:12 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon Aug 13 20:28:31 2007 Subject: Yum/RPM install In-Reply-To: <46C09219.3020503@ecs.soton.ac.uk> References: <200708140219510349.050645C0@dns3.ace.net.au> <46C09219.3020503@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 8/13/2007 10:17 AM: > How about this? > > Would you like me to create another ClamAV+SA distribution that used > SRPMs in the same way my MailScanner install script does? > > It will take a bit of work on my part to build all the RPMs, but easy > enough to maintain once I've got it there. > > Does that help you, or not? I'm not going to waste the effort, it's a > significant amount of time. > I think you could get all or most of the .src rpms from either Rpmforge or Atrpms. That might cut some of the initial work. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Mon Aug 13 20:32:33 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon Aug 13 20:35:05 2007 Subject: Test, not receiving MS List message In-Reply-To: <041301c7dddc$998321c0$cc896540$@com> References: <041301c7dddc$998321c0$cc896540$@com> Message-ID: Stephen Conway spake the following on 8/13/2007 12:03 PM: > Hello All: > > I had a vacation message attached to my mailbox last week, not sure if > because of this, the list moderator maybe put a block on sending me the > lists messages. If so, please remove as I have stopped the vacation > message. > > Regards, > > Stephen Conway > > If your vacation message spammed the list, then that is what probably happened. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From MailScanner at ecs.soton.ac.uk Mon Aug 13 20:36:00 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 13 20:36:39 2007 Subject: Yum/RPM install In-Reply-To: References: Message-ID: <46C0B2A0.6070303@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 In which case I don't need to do anything. Gareth wrote: > Yes it full RPMs that I disaprove of as you mentioned. As far as using SRPMs > I dont mind either way. Whether it be SRPM or a pure tarball the perl > modules get installed and compiled from source so it makes little difference > in my mind. > > > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Julian >> Field >> Sent: 13 August 2007 19:27 >> To: MailScanner discussion >> Subject: Re: Yum/RPM install >> >> >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> You say "with source" near the end of your comment. Do you mean "with >> builds from source (i.e. same as installing via CPAN)" or do you mean >> "with SRPMs"? >> >> Any RPM-based distro of ClamAV+SA I did would involve SRPMs for all the >> Perl stuff anyway, I refuse to distribute RPMs of Perl modules as they >> make no sense for exactly the reasons you have described. >> >> Gareth wrote: >> >>> You also have to build rpms for the packages that redhat wont upgrade >>> aswell. For example I run FC6 but the latest spamassassin >>> >> available through >> >>> yum is 3.1.9 since 3.2 is a new major version. >>> For situations like this you want to either maintain your own >>> >> specific rpm >> >>> repository or do it via source. >>> Given the variety of playforms and the age of some of the systems there >>> would have to be multiple rpm versions to cater for different library >>> versions that people use for example. With source Julian only >>> >> needs to worry >> >>> about one version and since it is compiled it is optimised for >>> >> the hardware >> >>> it is running on. >>> >>> >>> >>>> -----Original Message----- >>>> From: mailscanner-bounces@lists.mailscanner.info >>>> [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Nathan >>>> Olson >>>> Sent: 13 August 2007 18:06 >>>> To: MailScanner discussion >>>> Subject: Re: Re[2]: Yum/RPM install >>>> >>>> >>>> We build RPMs for MailScanner and all it's prerequisites. >>>> It works fine if you're patient enough to build and maintain them. >>>> We only need to build the ones that RedHat doesn't provide already. >>>> >>>> Nate >>>> -- >>>> MailScanner mailing list >>>> mailscanner@lists.mailscanner.info >>>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>>> >>>> Before posting, read http://wiki.mailscanner.info/posting >>>> >>>> Support MailScanner development - buy the book off the website! >>>> >>>> >>>> >>>> >>>> >>> >> Jules >> >> - -- >> Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> MailScanner customisation, or any advanced system administration help? >> Contact me at Jules@Jules.FM >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> For all your IT requirements visit www.transtec.co.uk >> >> >> -----BEGIN PGP SIGNATURE----- >> Version: PGP Desktop 9.6.2 (Build 2014) >> Charset: ISO-8859-1 >> >> wj8DBQFGwKJ1EfZZRxQVtlQRAnz6AJ9RHjZX40dbSk2q5uUF9T/OVzIbIwCcCP69 >> BX8ubb8ss5hR2Wz68tB4CWc= >> =gKjK >> -----END PGP SIGNATURE----- >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> For all your IT requirements visit www.transtec.co.uk >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >> >> >> > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGwLKhEfZZRxQVtlQRAvFsAKCO3KQ+pRpJrJohpC80Ciby9xUJAQCfSLa1 9+yP64h0mGiB/SyqUjWFipI= =cU0H -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Mon Aug 13 20:38:02 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 13 20:38:42 2007 Subject: Test, not receiving MS List message In-Reply-To: <041301c7dddc$998321c0$cc896540$@com> References: <041301c7dddc$998321c0$cc896540$@com> Message-ID: <46C0B31A.10203@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Yes, I blocked you as your vacation message was replying to every posting, where it shouldn't reply to list postings at all, or at least only reply to the first one, not all subsequent ones. You're back now, so I've re-enabled your subscription. Please take a look at your vacation responder. Stephen Conway wrote: > Hello All: > > I had a vacation message attached to my mailbox last week, not sure if > because of this, the list moderator maybe put a block on sending me the > lists messages. If so, please remove as I have stopped the vacation > message. > > Regards, > > Stephen Conway > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGwLMbEfZZRxQVtlQRAuQDAKDQnjNKdXK8vE1lZ2QUsLVUg4VhuACdHRIa U7RnNb8OTlcAjhGXC1VgAYs= =tqho -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From glenn.steen at gmail.com Mon Aug 13 20:43:25 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Mon Aug 13 20:43:27 2007 Subject: [Fwd: Re: Spamhaus issues? (fwd)] In-Reply-To: <200708140143420150.04E52C51@dns3.ace.net.au> References: <46BEE7F3.9040405@ecs.soton.ac.uk> <200708131154570129.01EE6DF4@dns3.ace.net.au> <46C01873.4050805@ecs.soton.ac.uk> <223f97700708130348l50c13590t60e4e45c8b1cb163@mail.gmail.com> <200708140143420150.04E52C51@dns3.ace.net.au> Message-ID: <223f97700708131243v6ea868dew4979cb3f19e6720e@mail.gmail.com> On 13/08/07, Peter Nitschke wrote: > Did I miss a bunch of posts about this? > > Glenn, I don't see any mobbing, just cause and effect and 2 emails > expressing relief or thanks for the action taken. > > No doubt all of us are good people beneath the surface, but that doesn't > absolve us from having to maintain respect for other members of the > community. > > Anybody that has had the responsibility of moderating a list or forum will > have come across an evil-bunny persona clone, and at some point action > needs to be taken for the wellbeing and functionality of the list. > > Yes, it is sad, but Julian was very diplomatic with his polite request, and > for his trouble was told that the list is full of crud, and that Julian was > at fault for not being a tougher moderator. > > All that was needed was a polite acknowledgement of the request, or no > comment at all. > > Let's move on. > > Cheers, > > Peter You might well be right, I have a history (way back, but still) of harrassment (whith me at the receiving end), so I might just be a bit over...sensitive, shall we say? Res has, to his credit, aired the view that much of the discussion of this list is off-topic... I actually agree with that, but where he sees it as detrimental, I see it as a pure bonus. And sometimes it is indeed hard to determine if a specific issue is on-topic or not, whatwith all the myriad things that make up a mail filtering system based around MailScanner. So my view is that that decision, on-topic or not, should ultimately (and do so) rest with Julian. I've been in a few ... rows... with Noel in the past, and ... he actually is quite sharp (not only in the mouth), so I've learned to value his views... Not that I always share them;-). And as said, he's been a rock (together with a few others, you know who you are!) lately... Makes me more forgiving, I guess. It goes without saying that I value Jules highly too, so ... I guess I overreacted a bit, and read more malice into the perceived gloating. So yes, lets move on. -- Glenn > > > > *********** REPLY SEPARATOR *********** > > On 13/08/2007 at 12:48 PM Glenn Steen wrote: > > >Well.... I will speak to Noels defense. > >Yes, he is opinionated, and yes, he is stubborn... and very very > >drastic in his expressions. > >I have not been following this thread in any greater detail, since it > >stopped being interresting a while back. > > > >But he has on several occasions contributed his knowledge in > >constructive ways... And if you only scratch lightly on the surface, > >he is a very caring and kind person. > >My views are doubtless coloured by the helping hand he has reached out > >to me recently, when I most needed a kind word from a friend, but ... > >Is it really OK to gang up on him like you do now? > >To act out on the suggestion to evict him from the list is quite OK by > >me, and indeed by him as well, Jules. Even talking about it could've > >been OK. But I think you've come very close to a line here, almost ... > >gloating ... over the act. > > > >I do know (and have been know to agree vocally) that his language can > >be more than what is acceptable. That is not my point. > >I'm just saying we seem to have changed one (in my view minor) evil > >for another (that I, with my background and "old luggage" find very > >hard to accept... After all, it's bordering on mobbing). > > > >I'm not saying that anyone else of the participants of the thread > >should be "punished". Just that you all should remember that it is > >people at the other end. > > > >Respectfully yours > >-- > >-- Glenn > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Mon Aug 13 21:29:02 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Mon Aug 13 21:29:03 2007 Subject: [Fwd: Re: Spamhaus issues? (fwd)] In-Reply-To: References: <46BEE7F3.9040405@ecs.soton.ac.uk> Message-ID: <223f97700708131329l4e599f94ia23d8f50b1febbf@mail.gmail.com> On 13/08/07, Scott Silva wrote: > Julian Field spake the following on 8/12/2007 3:58 AM: > > This is the comment I got from Res in reply to my gentle tap on the > > shoulder. > > I've had enough of his attitude for a very long time. Sorry, but he > > asked for it. > > > > -------- Original Message -------- > > Subject: Re: Spamhaus issues? (fwd) > > Date: Sun, 12 Aug 2007 08:42:59 +1000 (EST) > > From: Res > > To: Julian Field > > > > > > > > Its about as on topic as the rest of the crud around on list, so is this > > selective censorship I am seeing... probably, since you dont make a point > > of shutting down all off topic threads. If you want me off your list > > just unsub me, you have my blessing, as I doubt I contribute anything to > > the mailscanner community anyway. Remember to take me off the beta list > > as well. > > > > > > > > > > ---------- Forwarded message ---------- > > Date: Sat, 11 Aug 2007 23:27:33 +0100 > > From: Julian Field > > Reply-To: MailScanner discussion > > To: MailScanner discussion > > Subject: Re: Spamhaus issues? > > > > -----BEGIN PGP SIGNED MESSAGE----- > > Hash: SHA1 > > > > C'mon guys, let's call it a day for this thread. The discussion is no > > longer relevant to others. If you wish to argue/debate/discuss, feel > > free, just do it off-list. > > > > Thanks, > > Jules. > > > > Res wrote: > >> * PGP Signed by an unknown key > > > >> *yawn* > >> I got your point Kai, the fact is you introduced something (dynamic ip > >> blocks) into the debate that was completely irrelevant, pay closer > >> attention next time. > > > > > >> On Sat, 11 Aug 2007, Kai Schaetzl wrote: > > > >>> Res wrote on Sat, 11 Aug 2007 07:54:58 +1000 (EST): > >>> > >>>> *sigh* > >>> Indeed, you didn't get the point from the beginning and are still not > >>> getting it and are not even trying to get it. EOT. > >>> > >>> Kai > >>> > >>> > > > > > > Jules > > > I have but one question. > Did you remove him, or did he remove himself? > > I hope that he did not just leave in anger, as he has made many worthwhile > contributions, and maybe he will regret his hasty in-anger response, and come > back. > > > In your defense, you have "tapped" other off topic threads before, and it is > usually when they turn into virtual fist fights. You seem to have great > tolerance for the occasional off-topic thread, even though they get very far > from the original topic. I think it is the "community" thing... Even though Jules has never actually said so, I think he keeps it this way because a) he likes the idea of a MailScanner community, and b) because it is polite to answer even the most rudimentary and off-topic questions, and c) because he is to darned nice;-) Hm, how come you and I have featured in quite afew of those off-topic-tapped threads, friend Scott?:-) -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From dnsadmin at 1bigthink.com Mon Aug 13 21:57:13 2007 From: dnsadmin at 1bigthink.com (dnsadmin 1bigthink.com) Date: Mon Aug 13 21:57:31 2007 Subject: More filetype/filename questions: jsp, js, mno files In-Reply-To: References: <200708092108.l79L8YtF000846@mxt.1bigthink.com> <46BB85A2.3050406@ecs.soton.ac.uk> <200708092150.l79Lo0EK005144@mxt.1bigthink.com> <200708092210.l79MA9vx007497@mxt.1bigthink.com> Message-ID: <200708132057.l7DKvVIc008840@mxt.1bigthink.com> At 06:23 PM 8/9/2007, you wrote: >Here is a stress reduction kit for you! > >Print this e-mail and tape on the wall. > >**************************************************************** >* * >* * >* * >* * >* BANG * >* * >* HEAD * >* * >* HERE! * >* * >* * >* * >* * >**************************************************************** Not a good idea at this point, this wouldn't be stress reduction, but slow suicide! My prior questioning was quite naive, putting it politely; ignorant to be more blunt. However, now that I've read the config file and tried numerous ways, I'm still beating my head on this problem: I have developers sending .zip files with .js files enclosed and no matter what I do, I can't get them through MailScanner. Last I tried, I over simplified the solution with: Allow Filetypes = script JScript scripts Deny Filetypes = Filetype Rules = Still not coming through: "MailScanner: JScript Scripts are dangerous in email" I have set: ### ! Special allowances for Developers ! ### allow \.js$ - - allow \.jsp$ - - allow \.mno$ - - in filename.rules.conf as well. Can anyone help? Thanks, Glenn Parsons From MailScanner at ecs.soton.ac.uk Mon Aug 13 22:13:38 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 13 22:14:17 2007 Subject: More filetype/filename questions: jsp, js, mno files In-Reply-To: <200708132057.l7DKvVIc008840@mxt.1bigthink.com> References: <200708092108.l79L8YtF000846@mxt.1bigthink.com> <46BB85A2.3050406@ecs.soton.ac.uk> <200708092150.l79Lo0EK005144@mxt.1bigthink.com> <200708092210.l79MA9vx007497@mxt.1bigthink.com> <200708132057.l7DKvVIc008840@mxt.1bigthink.com> Message-ID: <46C0C982.5080207@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 If you want to disable filename/filetype checking on all files within archives, but still have everything scanned for viruses, simply set Maximum Archive Depth = 0 That will do the trick. dnsadmin 1bigthink.com wrote: > At 06:23 PM 8/9/2007, you wrote: > >> Here is a stress reduction kit for you! >> >> Print this e-mail and tape on the wall. >> >> **************************************************************** >> * * >> * * >> * * >> * * >> * BANG * >> * * >> * HEAD * >> * * >> * HERE! * >> * * >> * * >> * * >> * * >> **************************************************************** > > Not a good idea at this point, this wouldn't be stress reduction, but > slow suicide! > > My prior questioning was quite naive, putting it politely; ignorant > to be more blunt. However, now that I've read the config file and > tried numerous ways, I'm still beating my head on this problem: > > I have developers sending .zip files with .js files enclosed and no > matter what I do, I can't get them through MailScanner. > > Last I tried, I over simplified the solution with: > > Allow Filetypes = script JScript scripts > Deny Filetypes = > Filetype Rules = > > Still not coming through: "MailScanner: JScript Scripts are dangerous > in email" > > I have set: > ### ! Special allowances for Developers ! ### > > allow \.js$ - - > allow \.jsp$ - - > allow \.mno$ - - > > in filename.rules.conf as well. > > Can anyone help? > > Thanks, > Glenn Parsons Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGwMmDEfZZRxQVtlQRAgVFAJ9ql7LNWDuKu1S5u/+ioJIYPgWMkgCg4t1U tUYpsyU5gw+mFvAm+WL/BWo= =0RRU -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From dnsadmin at 1bigthink.com Mon Aug 13 22:28:34 2007 From: dnsadmin at 1bigthink.com (dnsadmin 1bigthink.com) Date: Mon Aug 13 22:28:54 2007 Subject: More filetype/filename questions: jsp, js, mno files In-Reply-To: <46C0C982.5080207@ecs.soton.ac.uk> References: <200708092108.l79L8YtF000846@mxt.1bigthink.com> <46BB85A2.3050406@ecs.soton.ac.uk> <200708092150.l79Lo0EK005144@mxt.1bigthink.com> <200708092210.l79MA9vx007497@mxt.1bigthink.com> <200708132057.l7DKvVIc008840@mxt.1bigthink.com> <46C0C982.5080207@ecs.soton.ac.uk> Message-ID: <200708132128.l7DLSsWP012277@mxt.1bigthink.com> At 05:13 PM 8/13/2007, you wrote: >-----BEGIN PGP SIGNED MESSAGE----- >Hash: SHA1 > >If you want to disable filename/filetype checking on all files within >archives, but still have everything scanned for viruses, simply set >Maximum Archive Depth = 0 > >That will do the trick. > Hmm.. Ahhh! That will do the trick! Thank you Sir! I must visit your wish list again! Cheers! Glenn >dnsadmin 1bigthink.com wrote: > > At 06:23 PM 8/9/2007, you wrote: > > > >> Here is a stress reduction kit for you! > >> > >> Print this e-mail and tape on the wall. > >> > >> **************************************************************** > >> * * > >> * * > >> * * > >> * * > >> * BANG * > >> * * > >> * HEAD * > >> * * > >> * HERE! * > >> * * > >> * * > >> * * > >> * * > >> **************************************************************** > > > > Not a good idea at this point, this wouldn't be stress reduction, but > > slow suicide! > > > > My prior questioning was quite naive, putting it politely; ignorant > > to be more blunt. However, now that I've read the config file and > > tried numerous ways, I'm still beating my head on this problem: > > > > I have developers sending .zip files with .js files enclosed and no > > matter what I do, I can't get them through MailScanner. > > > > Last I tried, I over simplified the solution with: > > > > Allow Filetypes = script JScript scripts > > Deny Filetypes = > > Filetype Rules = > > > > Still not coming through: "MailScanner: JScript Scripts are dangerous > > in email" > > > > I have set: > > ### ! Special allowances for Developers ! ### > > > > allow \.js$ - - > > allow \.jsp$ - - > > allow \.mno$ - - > > > > in filename.rules.conf as well. > > > > Can anyone help? > > > > Thanks, > > Glenn Parsons > >Jules > >- -- >Julian Field MEng CITP >www.MailScanner.info >Buy the MailScanner book at www.MailScanner.info/store > >MailScanner customisation, or any advanced system administration help? >Contact me at Jules@Jules.FM > >PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >For all your IT requirements visit www.transtec.co.uk > > >-----BEGIN PGP SIGNATURE----- >Version: PGP Desktop 9.6.2 (Build 2014) >Charset: ISO-8859-1 > >wj8DBQFGwMmDEfZZRxQVtlQRAgVFAJ9ql7LNWDuKu1S5u/+ioJIYPgWMkgCg4t1U >tUYpsyU5gw+mFvAm+WL/BWo= >=0RRU >-----END PGP SIGNATURE----- > >-- >This message has been scanned for viruses and >dangerous content by MailScanner, and is >believed to be clean. >For all your IT requirements visit www.transtec.co.uk > >-- >MailScanner mailing list >mailscanner@lists.mailscanner.info >http://lists.mailscanner.info/mailman/listinfo/mailscanner > >Before posting, read http://wiki.mailscanner.info/posting > >Support MailScanner development - buy the book off the website! From ssilva at sgvwater.com Tue Aug 14 00:07:08 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue Aug 14 00:10:12 2007 Subject: More filetype/filename questions: jsp, js, mno files In-Reply-To: <200708132128.l7DLSsWP012277@mxt.1bigthink.com> References: <200708092108.l79L8YtF000846@mxt.1bigthink.com> <46BB85A2.3050406@ecs.soton.ac.uk> <200708092150.l79Lo0EK005144@mxt.1bigthink.com> <200708092210.l79MA9vx007497@mxt.1bigthink.com> <200708132057.l7DKvVIc008840@mxt.1bigthink.com> <46C0C982.5080207@ecs.soton.ac.uk> <200708132128.l7DLSsWP012277@mxt.1bigthink.com> Message-ID: dnsadmin 1bigthink.com spake the following on 8/13/2007 2:28 PM: > At 05:13 PM 8/13/2007, you wrote: > > If you want to disable filename/filetype checking on all files within > archives, but still have everything scanned for viruses, simply set > Maximum Archive Depth = 0 > > That will do the trick. > > >> Hmm.. Ahhh! That will do the trick! Thank you Sir! I must visit your >> wish list again! > I went back and read your original post, and I assumed that you wanted to block in zips to everybody but these developers. I'm sorry I didn't ask last week and get more details of what you were trying to accomplish, or you would have gotten this answer then. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Tue Aug 14 02:07:25 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue Aug 14 02:07:36 2007 Subject: [Fwd: Re: Spamhaus issues? (fwd)] In-Reply-To: <223f97700708131329l4e599f94ia23d8f50b1febbf@mail.gmail.com> References: <46BEE7F3.9040405@ecs.soton.ac.uk> <223f97700708131329l4e599f94ia23d8f50b1febbf@mail.gmail.com> Message-ID: Glenn Steen spake the following on 8/13/2007 1:29 PM: > On 13/08/07, Scott Silva wrote: >> Julian Field spake the following on 8/12/2007 3:58 AM: >>> This is the comment I got from Res in reply to my gentle tap on the >>> shoulder. >>> I've had enough of his attitude for a very long time. Sorry, but he >>> asked for it. >>> >>> -------- Original Message -------- >>> Subject: Re: Spamhaus issues? (fwd) >>> Date: Sun, 12 Aug 2007 08:42:59 +1000 (EST) >>> From: Res >>> To: Julian Field >>> >>> >>> >>> Its about as on topic as the rest of the crud around on list, so is this >>> selective censorship I am seeing... probably, since you dont make a point >>> of shutting down all off topic threads. If you want me off your list >>> just unsub me, you have my blessing, as I doubt I contribute anything to >>> the mailscanner community anyway. Remember to take me off the beta list >>> as well. >>> >>> >>> >>> >>> ---------- Forwarded message ---------- >>> Date: Sat, 11 Aug 2007 23:27:33 +0100 >>> From: Julian Field >>> Reply-To: MailScanner discussion >>> To: MailScanner discussion >>> Subject: Re: Spamhaus issues? >>> >>> -----BEGIN PGP SIGNED MESSAGE----- >>> Hash: SHA1 >>> >>> C'mon guys, let's call it a day for this thread. The discussion is no >>> longer relevant to others. If you wish to argue/debate/discuss, feel >>> free, just do it off-list. >>> >>> Thanks, >>> Jules. >>> >>> Res wrote: >>>> * PGP Signed by an unknown key >>>> *yawn* >>>> I got your point Kai, the fact is you introduced something (dynamic ip >>>> blocks) into the debate that was completely irrelevant, pay closer >>>> attention next time. >>> >>>> On Sat, 11 Aug 2007, Kai Schaetzl wrote: >>>>> Res wrote on Sat, 11 Aug 2007 07:54:58 +1000 (EST): >>>>> >>>>>> *sigh* >>>>> Indeed, you didn't get the point from the beginning and are still not >>>>> getting it and are not even trying to get it. EOT. >>>>> >>>>> Kai >>>>> >>>>> >>> >>> Jules >>> >> I have but one question. >> Did you remove him, or did he remove himself? >> >> I hope that he did not just leave in anger, as he has made many worthwhile >> contributions, and maybe he will regret his hasty in-anger response, and come >> back. >> >> >> In your defense, you have "tapped" other off topic threads before, and it is >> usually when they turn into virtual fist fights. You seem to have great >> tolerance for the occasional off-topic thread, even though they get very far >> from the original topic. > > I think it is the "community" thing... Even though Jules has never > actually said so, I think he keeps it this way because a) he likes the > idea of a MailScanner community, and b) because it is polite to answer > even the most rudimentary and off-topic questions, and c) because he > is to darned nice;-) > > Hm, how come you and I have featured in quite afew of those > off-topic-tapped threads, friend Scott?:-) I must confess that sometimes I tread where others fear to go... ;-D I might have climbed Everest in another reality. I guess I'm diverting the topic again.... -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From smlists at shaw.ca Tue Aug 14 02:34:18 2007 From: smlists at shaw.ca (Steve Mason (lists)) Date: Tue Aug 14 02:34:38 2007 Subject: Dumb Bayes question In-Reply-To: References: <001201c7dd17$ed8aee80$1524010a@SMD800> Message-ID: <000001c7de13$3b795220$1524010a@SMD800> Thanks all! >"Please do not make up fake "new" postings by replying to some message and changing the subject, this is awful behavior. THIS IS NOT A NEW MESSAGE. >Please hit the "New message" button if you want to send a question to any list, thanks." > Oops. Guilty as charged... I'll avoid in the future. >Also, please try to avoid HTML, thanks. I must have replied to an HTML message, as I'm set for plain text... Another oops. From email at ace.net.au Tue Aug 14 04:38:06 2007 From: email at ace.net.au (Peter Nitschke) Date: Tue Aug 14 04:41:28 2007 Subject: Yum/RPM install In-Reply-To: <46C09219.3020503@ecs.soton.ac.uk> References: <200708140219510349.050645C0@dns3.ace.net.au> <46C09219.3020503@ecs.soton.ac.uk> Message-ID: <200708141308060598.0757C451@dns3.ace.net.au> Julian, I wasn't thinking of you changing what already works, I was just wanting to clarify whether I would be heading for any problems if I do it myself with RPM's. For me, it's a comfort level thing. I am comfortable with RPM's as I know how to install/upgrade/remove them, see what's there and what version, and it's easy. I can also make my own repo for the servers I manage and upgrade them all faster by adding eg a new MailScanner RPM to my local repo. I will still need to log into the servers to make any conf changes (though that could probably also be scripted), but I won't have to log in, manually download the latest package, untar it, run install.sh and then wait while it re-compiles everything even when some or most of the required modules exist, and then check the conf files. I know this is only workable for me once I have moved all the servers to the same OS, but I am trying to get some of my life back. :) The only thing that would make it easier, would be comments in the changelog about anything outside of the RPM that I need to pay attention to, eg settings that get added to other files such as v320.pre etc. Cheers, Peter *********** REPLY SEPARATOR *********** On 13/08/2007 at 6:17 PM Julian Field wrote: >-----BEGIN PGP SIGNED MESSAGE----- >Hash: SHA1 > >How about this? > >Would you like me to create another ClamAV+SA distribution that used >SRPMs in the same way my MailScanner install script does? > >It will take a bit of work on my part to build all the RPMs, but easy >enough to maintain once I've got it there. > >Does that help you, or not? I'm not going to waste the effort, it's a >significant amount of time. > >Peter Nitschke wrote: >> Which is why I like the concept of doing it all with RPMs. >> >> Most are available on the major repo sites, the handful that aren't I >have >> let Julian's script create, then made a local repo for them so I can do >> repeat installs simply and quickly to other PC's. >> >> I realise this is OS specific, but most of us with multiple servers to >> manage have probably standardised on a particular OS, in my case Centos >5. >> >> The MS install script pretty much creates then installs everything as >> RPM's, and the recent SA/Clam install script recommends using clam RPM's, >> so I figure that going the last step to all RPM's makes good sense. >> >> Julians scripts do a few tweak, eg to SA v3xx.pre files which is easy >> enough to duplicate, but would I be missing anything else? >> >> My thoughts are towards lower manual maintenance by being able to do >future >> upgrades all by RPM, and by being able to create servers with a known >> predictable setup which doesn't tend to happen if you configure them all >> individually. >> >> Peter >> >> >> *********** REPLY SEPARATOR *********** >> >> On 13/08/2007 at 5:33 PM Gareth wrote: >> >> >>> Managing perl modules would be a real pain as you would practically have >>> to >>> install them as separate RPM's aswell. RPM has its own versioning and >>> upgrade system which perl also has. Trying to mix them both at the same >>> time >>> can cause lots of issues. >>> >>> >>>> -----Original Message----- >>>> From: mailscanner-bounces@lists.mailscanner.info >>>> [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Peter >>>> Nitschke >>>> Sent: 13 August 2007 17:22 >>>> To: mailscanner@lists.mailscanner.info >>>> Subject: Yum/RPM install >>>> >>>> >>>> There have been a few threads on the issue of making more use of >>>> yum and or >>>> RPM's to install MailScanner and SA/Clam-av, but none of them seem to >>>> >>> have >>> >>>> come to any real conclusion. >>>> >>>> Is there any real disadvantage to doing it all with RPM's rather than >>>> having all the modules compiled with each install or upgrade? >>>> >>>> Peter >>>> >>>> >>>> -- >>>> MailScanner mailing list >>>> mailscanner@lists.mailscanner.info >>>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>>> >>>> Before posting, read http://wiki.mailscanner.info/posting >>>> >>>> Support MailScanner development - buy the book off the website! >>>> >>>> >>>> >>>> >>> -- >>> MailScanner mailing list >>> mailscanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> >>> Before posting, read http://wiki.mailscanner.info/posting >>> >>> Support MailScanner development - buy the book off the website! >>> >> >> >> >> > >Jules > >- -- >Julian Field MEng CITP >www.MailScanner.info >Buy the MailScanner book at www.MailScanner.info/store > >MailScanner customisation, or any advanced system administration help? >Contact me at Jules@Jules.FM > >PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >For all your IT requirements visit www.transtec.co.uk > > >-----BEGIN PGP SIGNATURE----- >Version: PGP Desktop 9.6.2 (Build 2014) >Charset: ISO-8859-1 > >wj8DBQFGwJIaEfZZRxQVtlQRAlPCAKDqmUB748A5UHmQ+UAiVGI5NBa9zwCfYcLd >2j+Gr0bpvn2D+Ao1Thhc+9s= >=Vh2+ >-----END PGP SIGNATURE----- > >-- >This message has been scanned for viruses and >dangerous content by MailScanner, and is >believed to be clean. >For all your IT requirements visit www.transtec.co.uk > >-- >MailScanner mailing list >mailscanner@lists.mailscanner.info >http://lists.mailscanner.info/mailman/listinfo/mailscanner > >Before posting, read http://wiki.mailscanner.info/posting > >Support MailScanner development - buy the book off the website! From tim.sattler at nordcapital.com Tue Aug 14 08:49:24 2007 From: tim.sattler at nordcapital.com (Sattler, Tim) Date: Tue Aug 14 08:49:41 2007 Subject: Blocked Extensions in password-protected zip archives Message-ID: We need to allow password-protected zip archives that contain files with blocked extensions for certain users. However, if "Maximum Archive Depth" is set to anything bigger than zero, then, even if "Allow Password-Protected Archives" is set to "yes", the archive will be blocked. Thus, I would need something like a ruleset for Maximum Archive Depth that yields 0 for password-protected archives and the default value otherwise. Is it possible? Or is there another way how I can achieve a different handling of blocked extensions for password-protected on one hand and normal zip archives on the other? Regards Tim From simon at saq.co.uk Tue Aug 14 09:26:59 2007 From: simon at saq.co.uk (Simon Jones) Date: Tue Aug 14 09:36:34 2007 Subject: messages on hold Message-ID: Hiya, I'm getting a lot of entries in the maillog with messages on hold. Anyone know why this could be happening? Or where to start looking to see if I do actually have a problem, thanks! Here's an example; Aug 14 09:33:45 gate1 postfix/cleanup[3509]: CD5A26DB42A: hold: header Received: from [81.26.189.95] (unknown [81.26.189.95])??by gate.domain.co.uk (Postfix) with ESMTP id CD5A26DB42A??for ; Tue, 14 Aug 2007 09:33:45 +0100 (BST) from unknown[81.26.189.95]; from= to=< recipient@domain.co.uk > proto=ESMTP helo=<[81.26.189.95] SMJ From martinh at solidstatelogic.com Tue Aug 14 09:50:29 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Tue Aug 14 09:50:31 2007 Subject: messages on hold In-Reply-To: Message-ID: Simon This is how MS works with postfix. Postfix puts the incoming messages into a hold queue, MS reads the hold queue then drops them into the normal queue for delivery. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > Sent: 14 August 2007 09:27 > To: MailScanner discussion > Subject: messages on hold > > Hiya, I'm getting a lot of entries in the maillog with messages on hold. > Anyone know why this could be happening? Or where to start looking to > see if I do actually have a problem, thanks! > > Here's an example; > > Aug 14 09:33:45 gate1 postfix/cleanup[3509]: CD5A26DB42A: hold: header > Received: from [81.26.189.95] (unknown [81.26.189.95])??by > gate.domain.co.uk (Postfix) with ESMTP id CD5A26DB42A??for > ; Tue, 14 Aug 2007 09:33:45 +0100 (BST) from > unknown[81.26.189.95]; from= to=< > recipient@domain.co.uk > proto=ESMTP helo=<[81.26.189.95] > > SMJ > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From simon at saq.co.uk Tue Aug 14 09:44:50 2007 From: simon at saq.co.uk (Simon Jones) Date: Tue Aug 14 09:54:25 2007 Subject: messages on hold References: Message-ID: Ah ok cool, just getting some reports of messages not arriving although MailScanner looks OK so far as I can tell at the moment, is there a log entry for MailScanner putting them in to the normal queue? Some way I can see the messages are going out to the destination OK and not sitting on the gateway server? > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Martin.Hepworth > Sent: 14 August 2007 09:50 > To: MailScanner discussion > Subject: RE: messages on hold > > Simon > > This is how MS works with postfix. Postfix puts the incoming messages > into a hold queue, MS reads the hold queue then drops them into the > normal queue for delivery. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > > Sent: 14 August 2007 09:27 > > To: MailScanner discussion > > Subject: messages on hold > > > > Hiya, I'm getting a lot of entries in the maillog with messages on > hold. > > Anyone know why this could be happening? Or where to start looking > to > > see if I do actually have a problem, thanks! > > > > Here's an example; > > > > Aug 14 09:33:45 gate1 postfix/cleanup[3509]: CD5A26DB42A: hold: > header > > Received: from [81.26.189.95] (unknown [81.26.189.95])??by > > gate.domain.co.uk (Postfix) with ESMTP id CD5A26DB42A??for > > ; Tue, 14 Aug 2007 09:33:45 +0100 (BST) from > > unknown[81.26.189.95]; from= to=< > > recipient@domain.co.uk > proto=ESMTP helo=<[81.26.189.95] > > > > SMJ > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From simon at saq.co.uk Tue Aug 14 09:53:34 2007 From: simon at saq.co.uk (Simon Jones) Date: Tue Aug 14 10:03:07 2007 Subject: messages on hold References: Message-ID: OK I have tones of mail from yesterday and today in /var/spool/postfix/hold anyone know how I can clear it sharpish? Thanks! > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > Sent: 14 August 2007 09:45 > To: MailScanner discussion > Subject: RE: messages on hold > > Ah ok cool, just getting some reports of messages not arriving although > MailScanner looks OK so far as I can tell at the moment, is there a log > entry for MailScanner putting them in to the normal queue? Some way I > can see the messages are going out to the destination OK and not > sitting > on the gateway server? > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Martin.Hepworth > > Sent: 14 August 2007 09:50 > > To: MailScanner discussion > > Subject: RE: messages on hold > > > > Simon > > > > This is how MS works with postfix. Postfix puts the incoming messages > > into a hold queue, MS reads the hold queue then drops them into the > > normal queue for delivery. > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- > > > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > > > Sent: 14 August 2007 09:27 > > > To: MailScanner discussion > > > Subject: messages on hold > > > > > > Hiya, I'm getting a lot of entries in the maillog with messages on > > hold. > > > Anyone know why this could be happening? Or where to start looking > > to > > > see if I do actually have a problem, thanks! > > > > > > Here's an example; > > > > > > Aug 14 09:33:45 gate1 postfix/cleanup[3509]: CD5A26DB42A: hold: > > header > > > Received: from [81.26.189.95] (unknown [81.26.189.95])??by > > > gate.domain.co.uk (Postfix) with ESMTP id CD5A26DB42A??for > > > ; Tue, 14 Aug 2007 09:33:45 +0100 (BST) > from > > > unknown[81.26.189.95]; from= to=< > > > recipient@domain.co.uk > proto=ESMTP helo=<[81.26.189.95] > > > > > > SMJ > > > > > > -- > > > MailScanner mailing list > > > mailscanner@lists.mailscanner.info > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > > ********************************************************************** > > Confidentiality : This e-mail and any attachments are intended for > the > > addressee only and may be confidential. If they come to you in error > > you must take no action based on them, nor must you copy or show them > > to anyone. Please advise the sender by replying to this e-mail > > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > > the author and unless specifically stated to the contrary, are not > > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > > communications medium and can be subject to data corruption. We > advise > > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > > attachments are free from known viruses but in keeping with good > > computing practice, you should ensure that they are virus free. > > > > Red Lion 49 Ltd T/A Solid State Logic > > Registered as a limited company in England and Wales > > (Company No:5362730) > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > > United Kingdom > > > ********************************************************************** > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From martinh at solidstatelogic.com Tue Aug 14 10:11:20 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Tue Aug 14 10:11:26 2007 Subject: messages on hold In-Reply-To: Message-ID: Simon Is mailscanner processing email? You shouldn't have anything left in the hold queue?? -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > Sent: 14 August 2007 09:54 > To: MailScanner discussion > Subject: RE: messages on hold > > OK I have tones of mail from yesterday and today in > /var/spool/postfix/hold anyone know how I can clear it sharpish? > Thanks! > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > > Sent: 14 August 2007 09:45 > > To: MailScanner discussion > > Subject: RE: messages on hold > > > > Ah ok cool, just getting some reports of messages not arriving > although > > MailScanner looks OK so far as I can tell at the moment, is there a > log > > entry for MailScanner putting them in to the normal queue? Some way I > > can see the messages are going out to the destination OK and not > > sitting > > on the gateway server? > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- > > > bounces@lists.mailscanner.info] On Behalf Of Martin.Hepworth > > > Sent: 14 August 2007 09:50 > > > To: MailScanner discussion > > > Subject: RE: messages on hold > > > > > > Simon > > > > > > This is how MS works with postfix. Postfix puts the incoming > messages > > > into a hold queue, MS reads the hold queue then drops them into the > > > normal queue for delivery. > > > > > > -- > > > Martin Hepworth > > > Snr Systems Administrator > > > Solid State Logic > > > Tel: +44 (0)1865 842300 > > > > > > > -----Original Message----- > > > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner- > > > > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > > > > Sent: 14 August 2007 09:27 > > > > To: MailScanner discussion > > > > Subject: messages on hold > > > > > > > > Hiya, I'm getting a lot of entries in the maillog with messages on > > > hold. > > > > Anyone know why this could be happening? Or where to start > looking > > > to > > > > see if I do actually have a problem, thanks! > > > > > > > > Here's an example; > > > > > > > > Aug 14 09:33:45 gate1 postfix/cleanup[3509]: CD5A26DB42A: hold: > > > header > > > > Received: from [81.26.189.95] (unknown [81.26.189.95])??by > > > > gate.domain.co.uk (Postfix) with ESMTP id CD5A26DB42A??for > > > > ; Tue, 14 Aug 2007 09:33:45 +0100 (BST) > > from > > > > unknown[81.26.189.95]; from= to=< > > > > recipient@domain.co.uk > proto=ESMTP helo=<[81.26.189.95] > > > > > > > > SMJ > > > > > > > > -- > > > > MailScanner mailing list > > > > mailscanner@lists.mailscanner.info > > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > > > > > > > > ********************************************************************** > > > Confidentiality : This e-mail and any attachments are intended for > > the > > > addressee only and may be confidential. If they come to you in error > > > you must take no action based on them, nor must you copy or show > them > > > to anyone. Please advise the sender by replying to this e-mail > > > immediately and then delete the original from your computer. > > > Opinion : Any opinions expressed in this e-mail are entirely those > of > > > the author and unless specifically stated to the contrary, are not > > > necessarily those of the author's employer. > > > Security Warning : Internet e-mail is not necessarily a secure > > > communications medium and can be subject to data corruption. We > > advise > > > that you consider this fact when e-mailing us. > > > Viruses : We have taken steps to ensure that this e-mail and any > > > attachments are free from known viruses but in keeping with good > > > computing practice, you should ensure that they are virus free. > > > > > > Red Lion 49 Ltd T/A Solid State Logic > > > Registered as a limited company in England and Wales > > > (Company No:5362730) > > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > > > United Kingdom > > > > > ********************************************************************** > > > > > > -- > > > MailScanner mailing list > > > mailscanner@lists.mailscanner.info > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From simon at saq.co.uk Tue Aug 14 10:17:22 2007 From: simon at saq.co.uk (Simon Jones) Date: Tue Aug 14 10:26:55 2007 Subject: messages on hold References: Message-ID: Hi Martin, I don't think it is working correctly, it is running in some capacity but I have just done a postsuper -H ALL to flush out the hold queue, stopped mailscanner and manually started postfix which has got stuff delivered. i made some changes to spam.assassin.prefs.conf so maybe that's causing the issue, I'm commenting stuff out at the mo. > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Martin.Hepworth > Sent: 14 August 2007 10:11 > To: MailScanner discussion > Subject: RE: messages on hold > > Simon > > Is mailscanner processing email? You shouldn't have anything left in > the hold queue?? > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > > Sent: 14 August 2007 09:54 > > To: MailScanner discussion > > Subject: RE: messages on hold > > > > OK I have tones of mail from yesterday and today in > > /var/spool/postfix/hold anyone know how I can clear it sharpish? > > Thanks! > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- > > > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > > > Sent: 14 August 2007 09:45 > > > To: MailScanner discussion > > > Subject: RE: messages on hold > > > > > > Ah ok cool, just getting some reports of messages not arriving > > although > > > MailScanner looks OK so far as I can tell at the moment, is there a > > log > > > entry for MailScanner putting them in to the normal queue? Some way > I > > > can see the messages are going out to the destination OK and not > > > sitting > > > on the gateway server? > > > > > > > -----Original Message----- > > > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner- > > > > bounces@lists.mailscanner.info] On Behalf Of Martin.Hepworth > > > > Sent: 14 August 2007 09:50 > > > > To: MailScanner discussion > > > > Subject: RE: messages on hold > > > > > > > > Simon > > > > > > > > This is how MS works with postfix. Postfix puts the incoming > > messages > > > > into a hold queue, MS reads the hold queue then drops them into > the > > > > normal queue for delivery. > > > > > > > > -- > > > > Martin Hepworth > > > > Snr Systems Administrator > > > > Solid State Logic > > > > Tel: +44 (0)1865 842300 > > > > > > > > > -----Original Message----- > > > > > From: mailscanner-bounces@lists.mailscanner.info > > > [mailto:mailscanner- > > > > > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > > > > > Sent: 14 August 2007 09:27 > > > > > To: MailScanner discussion > > > > > Subject: messages on hold > > > > > > > > > > Hiya, I'm getting a lot of entries in the maillog with messages > on > > > > hold. > > > > > Anyone know why this could be happening? Or where to start > > looking > > > > to > > > > > see if I do actually have a problem, thanks! > > > > > > > > > > Here's an example; > > > > > > > > > > Aug 14 09:33:45 gate1 postfix/cleanup[3509]: CD5A26DB42A: hold: > > > > header > > > > > Received: from [81.26.189.95] (unknown [81.26.189.95])??by > > > > > gate.domain.co.uk (Postfix) with ESMTP id CD5A26DB42A??for > > > > > ; Tue, 14 Aug 2007 09:33:45 +0100 (BST) > > > from > > > > > unknown[81.26.189.95]; from= to=< > > > > > recipient@domain.co.uk > proto=ESMTP helo=<[81.26.189.95] > > > > > > > > > > SMJ > > > > > > > > > > -- > > > > > MailScanner mailing list > > > > > mailscanner@lists.mailscanner.info > > > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > > > > > > > > > > > > > > > ********************************************************************** > > > > Confidentiality : This e-mail and any attachments are intended > for > > > the > > > > addressee only and may be confidential. If they come to you in > error > > > > you must take no action based on them, nor must you copy or show > > them > > > > to anyone. Please advise the sender by replying to this e-mail > > > > immediately and then delete the original from your computer. > > > > Opinion : Any opinions expressed in this e-mail are entirely > those > > of > > > > the author and unless specifically stated to the contrary, are > not > > > > necessarily those of the author's employer. > > > > Security Warning : Internet e-mail is not necessarily a secure > > > > communications medium and can be subject to data corruption. We > > > advise > > > > that you consider this fact when e-mailing us. > > > > Viruses : We have taken steps to ensure that this e-mail and any > > > > attachments are free from known viruses but in keeping with good > > > > computing practice, you should ensure that they are virus free. > > > > > > > > Red Lion 49 Ltd T/A Solid State Logic > > > > Registered as a limited company in England and Wales > > > > (Company No:5362730) > > > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > > > > United Kingdom > > > > > > > > ********************************************************************** > > > > > > > > -- > > > > MailScanner mailing list > > > > mailscanner@lists.mailscanner.info > > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > > > Support MailScanner development - buy the book off the website! > > > -- > > > MailScanner mailing list > > > mailscanner@lists.mailscanner.info > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From martinh at solidstatelogic.com Tue Aug 14 10:31:21 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Tue Aug 14 10:31:26 2007 Subject: messages on hold In-Reply-To: Message-ID: <0bf9428afe5fc148b3f3abbbc2a8ff2f@solidstatelogic.com> Simon Stop mailscanner then As the postfix user run "MailScanner --debug --debug-sa" and it should give you some clues as to what's wrong. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > Sent: 14 August 2007 10:17 > To: MailScanner discussion > Subject: RE: messages on hold > > Hi Martin, > > I don't think it is working correctly, it is running in some capacity > but I have just done a postsuper -H ALL to flush out the hold queue, > stopped mailscanner and manually started postfix which has got stuff > delivered. i made some changes to spam.assassin.prefs.conf so maybe > that's causing the issue, I'm commenting stuff out at the mo. > > > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Martin.Hepworth > > Sent: 14 August 2007 10:11 > > To: MailScanner discussion > > Subject: RE: messages on hold > > > > Simon > > > > Is mailscanner processing email? You shouldn't have anything left in > > the hold queue?? > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- > > > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > > > Sent: 14 August 2007 09:54 > > > To: MailScanner discussion > > > Subject: RE: messages on hold > > > > > > OK I have tones of mail from yesterday and today in > > > /var/spool/postfix/hold anyone know how I can clear it sharpish? > > > Thanks! > > > > > > > -----Original Message----- > > > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner- > > > > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > > > > Sent: 14 August 2007 09:45 > > > > To: MailScanner discussion > > > > Subject: RE: messages on hold > > > > > > > > Ah ok cool, just getting some reports of messages not arriving > > > although > > > > MailScanner looks OK so far as I can tell at the moment, is there > a > > > log > > > > entry for MailScanner putting them in to the normal queue? Some > way > > I > > > > can see the messages are going out to the destination OK and not > > > > sitting > > > > on the gateway server? > > > > > > > > > -----Original Message----- > > > > > From: mailscanner-bounces@lists.mailscanner.info > > > [mailto:mailscanner- > > > > > bounces@lists.mailscanner.info] On Behalf Of Martin.Hepworth > > > > > Sent: 14 August 2007 09:50 > > > > > To: MailScanner discussion > > > > > Subject: RE: messages on hold > > > > > > > > > > Simon > > > > > > > > > > This is how MS works with postfix. Postfix puts the incoming > > > messages > > > > > into a hold queue, MS reads the hold queue then drops them into > > the > > > > > normal queue for delivery. > > > > > > > > > > -- > > > > > Martin Hepworth > > > > > Snr Systems Administrator > > > > > Solid State Logic > > > > > Tel: +44 (0)1865 842300 > > > > > > > > > > > -----Original Message----- > > > > > > From: mailscanner-bounces@lists.mailscanner.info > > > > [mailto:mailscanner- > > > > > > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > > > > > > Sent: 14 August 2007 09:27 > > > > > > To: MailScanner discussion > > > > > > Subject: messages on hold > > > > > > > > > > > > Hiya, I'm getting a lot of entries in the maillog with > messages > > on > > > > > hold. > > > > > > Anyone know why this could be happening? Or where to start > > > looking > > > > > to > > > > > > see if I do actually have a problem, thanks! > > > > > > > > > > > > Here's an example; > > > > > > > > > > > > Aug 14 09:33:45 gate1 postfix/cleanup[3509]: CD5A26DB42A: > hold: > > > > > header > > > > > > Received: from [81.26.189.95] (unknown [81.26.189.95])??by > > > > > > gate.domain.co.uk (Postfix) with ESMTP id CD5A26DB42A??for > > > > > > ; Tue, 14 Aug 2007 09:33:45 +0100 > (BST) > > > > from > > > > > > unknown[81.26.189.95]; from= to=< > > > > > > recipient@domain.co.uk > proto=ESMTP helo=<[81.26.189.95] > > > > > > > > > > > > SMJ > > > > > > > > > > > > -- > > > > > > MailScanner mailing list > > > > > > mailscanner@lists.mailscanner.info > > > > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > > > > > > > Support MailScanner development - buy the book off the > website! > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > ********************************************************************** > > > > > Confidentiality : This e-mail and any attachments are intended > > for > > > > the > > > > > addressee only and may be confidential. If they come to you in > > error > > > > > you must take no action based on them, nor must you copy or show > > > them > > > > > to anyone. Please advise the sender by replying to this e-mail > > > > > immediately and then delete the original from your computer. > > > > > Opinion : Any opinions expressed in this e-mail are entirely > > those > > > of > > > > > the author and unless specifically stated to the contrary, are > > not > > > > > necessarily those of the author's employer. > > > > > Security Warning : Internet e-mail is not necessarily a secure > > > > > communications medium and can be subject to data corruption. We > > > > advise > > > > > that you consider this fact when e-mailing us. > > > > > Viruses : We have taken steps to ensure that this e-mail and any > > > > > attachments are free from known viruses but in keeping with good > > > > > computing practice, you should ensure that they are virus free. > > > > > > > > > > Red Lion 49 Ltd T/A Solid State Logic > > > > > Registered as a limited company in England and Wales > > > > > (Company No:5362730) > > > > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 > 1RU, > > > > > United Kingdom > > > > > > > > > > > ********************************************************************** > > > > > > > > > > -- > > > > > MailScanner mailing list > > > > > mailscanner@lists.mailscanner.info > > > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > > > > > Support MailScanner development - buy the book off the website! > > > > -- > > > > MailScanner mailing list > > > > mailscanner@lists.mailscanner.info > > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > > > Support MailScanner development - buy the book off the website! > > > -- > > > MailScanner mailing list > > > mailscanner@lists.mailscanner.info > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > ********************************************************************** > > Confidentiality : This e-mail and any attachments are intended for the > > addressee only and may be confidential. If they come to you in error > > you must take no action based on them, nor must you copy or show them > > to anyone. Please advise the sender by replying to this e-mail > > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > > the author and unless specifically stated to the contrary, are not > > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > > communications medium and can be subject to data corruption. We advise > > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > > attachments are free from known viruses but in keeping with good > > computing practice, you should ensure that they are virus free. > > > > Red Lion 49 Ltd T/A Solid State Logic > > Registered as a limited company in England and Wales > > (Company No:5362730) > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > > United Kingdom > > ********************************************************************** > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From simon at saq.co.uk Tue Aug 14 10:41:22 2007 From: simon at saq.co.uk (Simon Jones) Date: Tue Aug 14 10:50:56 2007 Subject: messages on hold References: <0bf9428afe5fc148b3f3abbbc2a8ff2f@solidstatelogic.com> Message-ID: Thanks Martin, really appreciate your help here. The problem was a misconfigured blacklist in /etc/MailScsnner/spam.lists.conf MailScanner must have been trying and erroring constantly and not bothering to time out on the blacklist. I've corrected this now and all looks to be good. Simon > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Martin.Hepworth > Sent: 14 August 2007 10:31 > To: MailScanner discussion > Subject: RE: messages on hold > > Simon > > Stop mailscanner then > > As the postfix user run "MailScanner --debug --debug-sa" and it should > give you some clues as to what's wrong. > > > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > > Sent: 14 August 2007 10:17 > > To: MailScanner discussion > > Subject: RE: messages on hold > > > > Hi Martin, > > > > I don't think it is working correctly, it is running in some capacity > > but I have just done a postsuper -H ALL to flush out the hold queue, > > stopped mailscanner and manually started postfix which has got stuff > > delivered. i made some changes to spam.assassin.prefs.conf so maybe > > that's causing the issue, I'm commenting stuff out at the mo. > > > > > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- > > > bounces@lists.mailscanner.info] On Behalf Of Martin.Hepworth > > > Sent: 14 August 2007 10:11 > > > To: MailScanner discussion > > > Subject: RE: messages on hold > > > > > > Simon > > > > > > Is mailscanner processing email? You shouldn't have anything left > in > > > the hold queue?? > > > > > > -- > > > Martin Hepworth > > > Snr Systems Administrator > > > Solid State Logic > > > Tel: +44 (0)1865 842300 > > > > > > > -----Original Message----- > > > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner- > > > > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > > > > Sent: 14 August 2007 09:54 > > > > To: MailScanner discussion > > > > Subject: RE: messages on hold > > > > > > > > OK I have tones of mail from yesterday and today in > > > > /var/spool/postfix/hold anyone know how I can clear it sharpish? > > > > Thanks! > > > > > > > > > -----Original Message----- > > > > > From: mailscanner-bounces@lists.mailscanner.info > > > [mailto:mailscanner- > > > > > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > > > > > Sent: 14 August 2007 09:45 > > > > > To: MailScanner discussion > > > > > Subject: RE: messages on hold > > > > > > > > > > Ah ok cool, just getting some reports of messages not arriving > > > > although > > > > > MailScanner looks OK so far as I can tell at the moment, is > there > > a > > > > log > > > > > entry for MailScanner putting them in to the normal queue? Some > > way > > > I > > > > > can see the messages are going out to the destination OK and > not > > > > > sitting > > > > > on the gateway server? > > > > > > > > > > > -----Original Message----- > > > > > > From: mailscanner-bounces@lists.mailscanner.info > > > > [mailto:mailscanner- > > > > > > bounces@lists.mailscanner.info] On Behalf Of Martin.Hepworth > > > > > > Sent: 14 August 2007 09:50 > > > > > > To: MailScanner discussion > > > > > > Subject: RE: messages on hold > > > > > > > > > > > > Simon > > > > > > > > > > > > This is how MS works with postfix. Postfix puts the incoming > > > > messages > > > > > > into a hold queue, MS reads the hold queue then drops them > into > > > the > > > > > > normal queue for delivery. > > > > > > > > > > > > -- > > > > > > Martin Hepworth > > > > > > Snr Systems Administrator > > > > > > Solid State Logic > > > > > > Tel: +44 (0)1865 842300 > > > > > > > > > > > > > -----Original Message----- > > > > > > > From: mailscanner-bounces@lists.mailscanner.info > > > > > [mailto:mailscanner- > > > > > > > bounces@lists.mailscanner.info] On Behalf Of Simon Jones > > > > > > > Sent: 14 August 2007 09:27 > > > > > > > To: MailScanner discussion > > > > > > > Subject: messages on hold > > > > > > > > > > > > > > Hiya, I'm getting a lot of entries in the maillog with > > messages > > > on > > > > > > hold. > > > > > > > Anyone know why this could be happening? Or where to start > > > > looking > > > > > > to > > > > > > > see if I do actually have a problem, thanks! > > > > > > > > > > > > > > Here's an example; > > > > > > > > > > > > > > Aug 14 09:33:45 gate1 postfix/cleanup[3509]: CD5A26DB42A: > > hold: > > > > > > header > > > > > > > Received: from [81.26.189.95] (unknown [81.26.189.95])??by > > > > > > > gate.domain.co.uk (Postfix) with ESMTP id CD5A26DB42A??for > > > > > > > ; Tue, 14 Aug 2007 09:33:45 +0100 > > (BST) > > > > > from > > > > > > > unknown[81.26.189.95]; from= to=< > > > > > > > recipient@domain.co.uk > proto=ESMTP helo=<[81.26.189.95] > > > > > > > > > > > > > > SMJ > > > > > > > > > > > > > > -- > > > > > > > MailScanner mailing list > > > > > > > mailscanner@lists.mailscanner.info > > > > > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > > > > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > > > > > > > > > Support MailScanner development - buy the book off the > > website! > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > ********************************************************************** > > > > > > Confidentiality : This e-mail and any attachments are > intended > > > for > > > > > the > > > > > > addressee only and may be confidential. If they come to you > in > > > error > > > > > > you must take no action based on them, nor must you copy or > show > > > > them > > > > > > to anyone. Please advise the sender by replying to this e- > mail > > > > > > immediately and then delete the original from your computer. > > > > > > Opinion : Any opinions expressed in this e-mail are entirely > > > those > > > > of > > > > > > the author and unless specifically stated to the contrary, > are > > > not > > > > > > necessarily those of the author's employer. > > > > > > Security Warning : Internet e-mail is not necessarily a > secure > > > > > > communications medium and can be subject to data corruption. > We > > > > > advise > > > > > > that you consider this fact when e-mailing us. > > > > > > Viruses : We have taken steps to ensure that this e-mail and > any > > > > > > attachments are free from known viruses but in keeping with > good > > > > > > computing practice, you should ensure that they are virus > free. > > > > > > > > > > > > Red Lion 49 Ltd T/A Solid State Logic > > > > > > Registered as a limited company in England and Wales > > > > > > (Company No:5362730) > > > > > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 > > 1RU, > > > > > > United Kingdom > > > > > > > > > > > > > > > ********************************************************************** > > > > > > > > > > > > -- > > > > > > MailScanner mailing list > > > > > > mailscanner@lists.mailscanner.info > > > > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > > > > > > > Support MailScanner development - buy the book off the > website! > > > > > -- > > > > > MailScanner mailing list > > > > > mailscanner@lists.mailscanner.info > > > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > > > > > Support MailScanner development - buy the book off the website! > > > > -- > > > > MailScanner mailing list > > > > mailscanner@lists.mailscanner.info > > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > > > > > > > ********************************************************************** > > > Confidentiality : This e-mail and any attachments are intended for > the > > > addressee only and may be confidential. If they come to you in > error > > > you must take no action based on them, nor must you copy or show > them > > > to anyone. Please advise the sender by replying to this e-mail > > > immediately and then delete the original from your computer. > > > Opinion : Any opinions expressed in this e-mail are entirely those > of > > > the author and unless specifically stated to the contrary, are not > > > necessarily those of the author's employer. > > > Security Warning : Internet e-mail is not necessarily a secure > > > communications medium and can be subject to data corruption. We > advise > > > that you consider this fact when e-mailing us. > > > Viruses : We have taken steps to ensure that this e-mail and any > > > attachments are free from known viruses but in keeping with good > > > computing practice, you should ensure that they are virus free. > > > > > > Red Lion 49 Ltd T/A Solid State Logic > > > Registered as a limited company in England and Wales > > > (Company No:5362730) > > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > > > United Kingdom > > > > ********************************************************************** > > > > > > -- > > > MailScanner mailing list > > > mailscanner@lists.mailscanner.info > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From support-lists at petdoctors.co.uk Tue Aug 14 10:52:43 2007 From: support-lists at petdoctors.co.uk (Nigel Kendrick) Date: Tue Aug 14 10:53:30 2007 Subject: messages on hold In-Reply-To: Message-ID: <000b01c7de58$dc2837a0$3c65a8c0@support01> -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Simon Jones Sent: Tuesday, August 14, 2007 10:17 AM To: MailScanner discussion Subject: RE: messages on hold Hi Martin, I don't think it is working correctly, it is running in some capacity but I have just done a postsuper -H ALL to flush out the hold queue, stopped mailscanner and manually started postfix which has got stuff delivered. i made some changes to spam.assassin.prefs.conf so maybe that's causing the issue, I'm commenting stuff out at the mo. Simon, There's a nifty utility you can install called pfqueue that lists the queue contents in real time - might help with the debugging. For my CentOS setup using the Dag repository all I had to do was type 'yum install pfqueue' Cheers Nigel From simon at saq.co.uk Tue Aug 14 11:00:17 2007 From: simon at saq.co.uk (Simon Jones) Date: Tue Aug 14 11:09:50 2007 Subject: messages on hold References: <000b01c7de58$dc2837a0$3c65a8c0@support01> Message-ID: Thanks Nigel, I'll check it out. > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Nigel Kendrick > Sent: 14 August 2007 10:53 > To: 'MailScanner discussion' > Subject: RE: messages on hold > > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Simon > Jones > Sent: Tuesday, August 14, 2007 10:17 AM > To: MailScanner discussion > Subject: RE: messages on hold > > Hi Martin, > > I don't think it is working correctly, it is running in some capacity > but I have just done a postsuper -H ALL to flush out the hold queue, > stopped mailscanner and manually started postfix which has got stuff > delivered. i made some changes to spam.assassin.prefs.conf so maybe > that's causing the issue, I'm commenting stuff out at the mo. > > > > > > Simon, > > There's a nifty utility you can install called pfqueue that lists the > queue > contents in real time - might help with the debugging. For my CentOS > setup > using the Dag repository all I had to do was type 'yum install pfqueue' > > Cheers > > Nigel > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From maillists at conactive.com Tue Aug 14 11:31:31 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Tue Aug 14 11:31:35 2007 Subject: Blocked Extensions in password-protected zip archives In-Reply-To: References: Message-ID: Tim Sattler wrote on Tue, 14 Aug 2007 09:49:24 +0200: > Is it possible? Or is there another way how I can achieve a different > handling of blocked extensions for password-protected on one hand and > normal zip archives on the other? Are you sure this is a matter of "blocked extensions"? I rather think this is a matter of "password-protected archive". MailScanner treats password-protected archives as viruses. It would need to stop that. This topic has come up regularly in the past, but Julian is reluctant to do this. The effect of handling it as a virus is that it doesn't get saved to the quarantine (if you keep it "clean") and thus can't be released. If you want to have all password-protected archives just pass thru directly in the inboxes then set Allow Password-Protected Archives = yes but this will also allow password-protected archives with malware right in the inbox. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From martin.lyberg at gmail.com Tue Aug 14 12:04:50 2007 From: martin.lyberg at gmail.com (Martin) Date: Tue Aug 14 12:05:04 2007 Subject: Understanding Watermarking Message-ID: Hi, Been away on vacation and had lots to catch up in the newsgroup. :) Read about the new watermarking feature. If i understand this correct, both in- and outbound mail must pass mailscanner for this to work correct, right? Since i'm currently only relaying incoming mail (not outgoing) to an internal exchangeserver, this won't work for me? Is this correct? Is there any documentation to read about this feature? Thanks in advance / Martin From tim.sattler at nordcapital.com Tue Aug 14 12:58:42 2007 From: tim.sattler at nordcapital.com (Sattler, Tim) Date: Tue Aug 14 12:58:54 2007 Subject: Blocked Extensions in password-protected zip archives In-Reply-To: References: Message-ID: I have set "Allow Password-Protected Archives = yes", but encrypted archives are nevertheless blocked if they contain files with blocked extensions. Now I could set "Maximum Archive Depth = 0" to solve this issue, but then files with blocked extensions would also pass in non-protected archives, which is not what I want. Therefore, I would either need an option to disregard blocked extensions within password-protected archives or the possibility to use a ruleset for "Maximum Archive Depth" with a different result for protected and non-protected archives. PS: I know it's an additional risk to let password-protected archives pass through, but it's a business need. Regards Tim -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Kai Schaetzl Sent: Tuesday, August 14, 2007 12:32 PM To: mailscanner@lists.mailscanner.info Subject: Re: Blocked Extensions in password-protected zip archives Tim Sattler wrote on Tue, 14 Aug 2007 09:49:24 +0200: > Is it possible? Or is there another way how I can achieve a different > handling of blocked extensions for password-protected on one hand and > normal zip archives on the other? Are you sure this is a matter of "blocked extensions"? I rather think this is a matter of "password-protected archive". MailScanner treats password-protected archives as viruses. It would need to stop that. This topic has come up regularly in the past, but Julian is reluctant to do this. The effect of handling it as a virus is that it doesn't get saved to the quarantine (if you keep it "clean") and thus can't be released. If you want to have all password-protected archives just pass thru directly in the inboxes then set Allow Password-Protected Archives = yes but this will also allow password-protected archives with malware right in the inbox. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From paul.hutchings at mira.co.uk Tue Aug 14 13:42:34 2007 From: paul.hutchings at mira.co.uk (Paul Hutchings) Date: Tue Aug 14 13:42:44 2007 Subject: Zip Attachments Not Working? Message-ID: I want to test "Zip Attachments" but only on my outgoing email. In Mailscanner.conf I have: # Should the attachments be compressed and put into a single zip file? # This can also be the filename of a ruleset. Zip Attachments = %rules-dir%/zip.rules # If the attachments are to be compressed into a single zip file, # this is the filename of the zip file. # This can also be the filename of a ruleset. Attachments Zip Filename = MIRA_Attachments.zip # If the original total size of all the attachments to be compressed is # less than this number of bytes, they will not be zipped at all. # This can also be the filename of a ruleset. Attachments Min Total Size To Zip = 100k # Attachments whose filenames end in these strings will not be zipped. # This can also be the filename of a ruleset. Attachment Extensions Not To Zip = .zip .rar .gz .tgz .mpg .mpe .mpeg .mp3 .rpm And in %rules-dir%/zip.rules I have: # Only Zip outbound mail From: paul.hutchings@mira.co.uk yes FromOrTo: default no If I sent a 120kb PDF to my external email address it doesn't get zipped. MailScanner is 4.62.9 Any ideas? Paul Hutchings Network Administrator, MIRA Ltd. Tel: 44 (0)24 7635 5378 Fax: 44 (0)24 7635 8378 mailto:paul.hutchings@mira.co.uk -- MIRA Ltd Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. Registered in England and Wales No. 402570 VAT Registration GB 114 5409 96 The contents of this e-mail are confidential and are solely for the use of the intended recipient. If you receive this e-mail in error, please delete it and notify us either by e-mail, telephone or fax. You should not copy, forward or otherwise disclose the content of the e-mail as this is prohibited. From prandal at herefordshire.gov.uk Tue Aug 14 13:43:25 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Tue Aug 14 13:43:30 2007 Subject: Blocked Extensions in password-protected zip archives In-Reply-To: References: Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA0169FBCC@HC-MBX02.herefordshire.gov.uk> This is not intended as a flame, so please don't take it as one. Once again, "business requirements" take precedence over security. That's not your choice, I know. email is NOT a secure and reliable transfer mechanism for sensitive content. Nobody should be sending password-protected zip files to anybody by email. Ever. The best way is to have an https portal site or similar that these files can be uploaded to. How do other MailScanner users handle this issue? Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Sattler, Tim > Sent: 14 August 2007 12:59 > To: MailScanner discussion > Subject: RE: Blocked Extensions in password-protected zip archives > > I have set "Allow Password-Protected Archives = yes", but encrypted > archives are nevertheless blocked if they contain files with blocked > extensions. > > Now I could set "Maximum Archive Depth = 0" to solve this issue, but > then files with blocked extensions would also pass in non-protected > archives, which is not what I want. > > Therefore, I would either need an option to disregard blocked > extensions within password-protected archives or the possibility to > use a ruleset for "Maximum Archive Depth" with a different result for > protected and non-protected archives. > > PS: I know it's an additional risk to let password-protected archives > pass through, but it's a business need. > > Regards > Tim > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Kai Schaetzl > Sent: Tuesday, August 14, 2007 12:32 PM > To: mailscanner@lists.mailscanner.info > Subject: Re: Blocked Extensions in password-protected zip archives > > Tim Sattler wrote on Tue, 14 Aug 2007 09:49:24 +0200: > > > Is it possible? Or is there another way how I can achieve a > different > > handling of blocked extensions for password-protected on > one hand and > > normal zip archives on the other? > > Are you sure this is a matter of "blocked extensions"? I > rather think this > is a matter of "password-protected archive". MailScanner treats > password-protected archives as viruses. It would need to stop > that. This > topic has come up regularly in the past, but Julian is > reluctant to do > this. The effect of handling it as a virus is that it doesn't > get saved to > the quarantine (if you keep it "clean") and thus can't be released. > > If you want to have all password-protected archives just pass thru > directly in the inboxes then set > Allow Password-Protected Archives = yes > but this will also allow password-protected archives with > malware right in > the inbox. > > Kai > > -- > Kai Sch?tzl, Berlin, Germany > Get your web at Conactive Internet Services: http://www.conactive.com > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From maillists at conactive.com Tue Aug 14 13:44:54 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Tue Aug 14 13:44:57 2007 Subject: Understanding Watermarking In-Reply-To: References: Message-ID: Martin wrote on Tue, 14 Aug 2007 13:04:50 +0200: > Read about the new watermarking feature. If i understand this correct, > both in- and outbound mail must pass mailscanner for this to work > correct, right? Yes. And if you read a bit back on the list you'll see that it doesn't work for read receipts, certain DSNs, certain autoreplies and maybe more. There's no guarantee that only fake DSNs are detected by this feature. > > Since i'm currently only relaying incoming mail (not outgoing) to an > internal exchangeserver, this won't work for me? Is this correct? right. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Tue Aug 14 13:44:55 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Tue Aug 14 13:45:01 2007 Subject: Blocked Extensions in password-protected zip archives In-Reply-To: References: Message-ID: Tim Sattler wrote on Tue, 14 Aug 2007 13:58:42 +0200: > I have set "Allow Password-Protected Archives = yes", but encrypted > archives are nevertheless blocked if they contain files with blocked > extensions. I see. I wasn't aware that the file type can still be determined if the archive is password-protected. BTW, there's also a setting for allowing encrypted archives, so there's obviously a difference between "password-protected" and "encrypted". > Therefore, I would either need an option to disregard blocked > extensions within password-protected archives I think this would be a good option as it would allow certain filetypes thru if the sender zips and password-protects them. But I don't see a way to currently achieve this. I think if you want to have an immediate workaround you have to use a rules file and exclude certain senders from the file type check. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From paul at firespam.com Tue Aug 14 13:47:22 2007 From: paul at firespam.com (paul @ firespam) Date: Tue Aug 14 13:47:31 2007 Subject: How to manually test an email? Message-ID: <1187095642.19264.3.camel@paul-laptop.sidlow.office-shadow.com> Hi, I've had quite a few random spams getting through my MailScanner servers recently and I'd like to investigate a bit more... I have saved a spam email that got through as a txt file with the full headers. How can I run this through MailScanner manually and see the output? I know I can do: spamassassin -t < /tmp/email.txt but does this just do spamassassin checks or does it include the MailScanner stuff too? Thanks, Paul -- This message has been scanned for spam, viruses and phishing attempts by firespam.com -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070814/e7ed4d82/attachment.html From list-mailscanner at linguaphone.com Tue Aug 14 13:55:14 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue Aug 14 13:55:26 2007 Subject: How to manually test an email? In-Reply-To: <1187095642.19264.3.camel@paul-laptop.sidlow.office-shadow.com> References: <1187095642.19264.3.camel@paul-laptop.sidlow.office-shadow.com> Message-ID: <1187096114.19272.12.camel@gblades-suse.linguaphone-intranet.co.uk> The command line you suggested will work fine and detect if it is spam. It wont detect if it contains a virus but you can run a virus checker against it for that. Upload the file somewhere and post it here. Its good to see what other peoples installation think of it as it may give you an idea of additional plugins you could be using. On Tue, 2007-08-14 at 13:47, paul @ firespam wrote: > Hi, > > I've had quite a few random spams getting through my MailScanner > servers recently and I'd like to investigate a bit more... > > I have saved a spam email that got through as a txt file with the full > headers. > > How can I run this through MailScanner manually and see the output? > > I know I can do: > spamassassin -t < /tmp/email.txt > > but does this just do spamassassin checks or does it include the > MailScanner stuff too? > > Thanks, > > > Paul From paul at firespam.com Tue Aug 14 14:01:51 2007 From: paul at firespam.com (paul @ firespam) Date: Tue Aug 14 14:01:57 2007 Subject: How to manually test an email? In-Reply-To: <1187096114.19272.12.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1187095642.19264.3.camel@paul-laptop.sidlow.office-shadow.com> <1187096114.19272.12.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <1187096511.19264.7.camel@paul-laptop.sidlow.office-shadow.com> On Tue, 2007-08-14 at 13:55 +0100, Gareth wrote: > Upload the file somewhere and post it here. Its good to see what other > peoples installation think of it as it may give you an idea of > additional plugins you could be using. I have uploaded the file here: http://www.firespam.com/email.txt You can see in the headers the spam score that was applied to it (-1.5!) Thanks, Paul Maddox -- This message has been scanned for spam, viruses and phishing attempts by firespam.com From list-mailscanner at linguaphone.com Tue Aug 14 14:08:14 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue Aug 14 14:08:18 2007 Subject: How to manually test an email? In-Reply-To: <1187096511.19264.7.camel@paul-laptop.sidlow.office-shadow.com> References: <1187095642.19264.3.camel@paul-laptop.sidlow.office-shadow.com> <1187096114.19272.12.camel@gblades-suse.linguaphone-intranet.co.uk> <1187096511.19264.7.camel@paul-laptop.sidlow.office-shadow.com> Message-ID: <1187096894.19272.14.camel@gblades-suse.linguaphone-intranet.co.uk> This is what I got :- Content analysis details: (9.6 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.0 INVALID_TZ_GMT Invalid date in header (wrong GMT/UTC timezone) 0.1 FORGED_RCVD_HELO Received: contains a forged HELO -0.2 BOTNET_SERVERWORDS Hostname contains server-like substrings [botnet_serverwords,ip=217.160.207.111,rdns=mail2.office-shadow.com] 1.7 SARE_MLB_Stock5 BODY: Mentions stock symbol, tickers, or OTC. 1.8 TVD_FUZZY_SYMBOL BODY: TVD_FUZZY_SYMBOL 0.1 HTML_TEXT_AFTER_BODY BODY: HTML contains text after BODY close tag 1.0 BAYES_60 BODY: Bayesian spam probability is 60 to 80% [score: 0.6344] 0.0 HTML_MESSAGE BODY: HTML included in message 4.0 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net [Blocked - see ] On Tue, 2007-08-14 at 14:01, paul @ firespam wrote: > On Tue, 2007-08-14 at 13:55 +0100, Gareth wrote: > > > Upload the file somewhere and post it here. Its good to see what other > > peoples installation think of it as it may give you an idea of > > additional plugins you could be using. > > I have uploaded the file here: > http://www.firespam.com/email.txt > > You can see in the headers the spam score that was applied to it (-1.5!) > > > Thanks, > > Paul Maddox > > > -- > This message has been scanned for spam, viruses and phishing attempts by firespam.com From tim.sattler at nordcapital.com Tue Aug 14 14:13:43 2007 From: tim.sattler at nordcapital.com (Sattler, Tim) Date: Tue Aug 14 14:13:58 2007 Subject: Blocked Extensions in password-protected zip archives In-Reply-To: References: Message-ID: > I see. I wasn't aware that the file type can still be determined if the > archive is password-protected. Password-protected zip archives contain an index of contents which is still readable without knowing the password. I guess that MailScanner analyses this index. Regards Tim From maillists at conactive.com Tue Aug 14 14:17:13 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Tue Aug 14 14:17:13 2007 Subject: How to manually test an email? In-Reply-To: <1187096511.19264.7.camel@paul-laptop.sidlow.office-shadow.com> References: <1187095642.19264.3.camel@paul-laptop.sidlow.office-shadow.com> <1187096114.19272.12.camel@gblades-suse.linguaphone-intranet.co.uk> <1187096511.19264.7.camel@paul-laptop.sidlow.office-shadow.com> Message-ID: Paul @ firespam wrote on Tue, 14 Aug 2007 14:01:51 +0100: > You can see in the headers the spam score that was applied to it (-1.5!) That's because of your untrained Bayes! Don't get this personal, but I would expect a better tweaked anti-spam setup from a "firespam" service ;-) X-Spam-Checker-Version: SpamAssassin 3.2.3 (2007-08-08) X-Spam-Status: Yes, score=19.5 required=5.0 tests=BAYES_95,FRT_PRICE, FRT_SYMBOL,HS_INDEX_PARAM,J_CHICKENPOX_14,J_CHICKENPOX_15,J_CHICKENPOX_23, J_CHICKENPOX_25,J_CHICKENPOX_31,J_CHICKENPOX_32,J_CHICKENPOX_33, J_CHICKENPOX_41,J_CHICKENPOX_42,J_CHICKENPOX_43,J_CHICKENPOX_52,RDNS_NONE, SARE_MLB_Stock5,TVD_FUZZY_SYMBOL autolearn=spam version=3.2.3 X-Spam-Report: * 0.1 RDNS_NONE Delivered to trusted network by a host with no rDNS * 0.6 J_CHICKENPOX_14 BODY: 1alpha-pock-4alpha * 0.6 J_CHICKENPOX_52 BODY: 5alpha-pock-2alpha * 0.6 J_CHICKENPOX_42 BODY: 4alpha-pock-2alpha * 0.6 J_CHICKENPOX_25 BODY: 2alpha-pock-5alpha * 2.9 FRT_SYMBOL BODY: ReplaceTags: Symbol * 0.6 J_CHICKENPOX_31 BODY: 3alpha-pock-1alpha * 3.5 FRT_PRICE BODY: ReplaceTags: Price * 0.6 J_CHICKENPOX_33 BODY: 3alpha-pock-3alpha * 0.6 J_CHICKENPOX_32 BODY: 3alpha-pock-2alpha * 1.7 SARE_MLB_Stock5 BODY: Mentions stock symbol, tickers, or OTC. * 0.6 J_CHICKENPOX_23 BODY: 2alpha-pock-3alpha * 0.6 J_CHICKENPOX_41 BODY: 4alpha-pock-1alpha * 1.7 TVD_FUZZY_SYMBOL BODY: TVD_FUZZY_SYMBOL * 0.6 J_CHICKENPOX_15 BODY: 1alpha-pock-5alpha * 0.6 J_CHICKENPOX_43 BODY: 4alpha-pock-3alpha * 0.0 HS_INDEX_PARAM URI: Link contains a common tracker pattern. * 3.0 BAYES_95 BODY: Bayesian spam probability is 95 to 99% * [score: 0.9782] X-Spam-Flag: YES Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From paul at firespam.com Tue Aug 14 14:17:18 2007 From: paul at firespam.com (paul @ firespam) Date: Tue Aug 14 14:17:25 2007 Subject: How to manually test an email? In-Reply-To: <1187096894.19272.14.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1187095642.19264.3.camel@paul-laptop.sidlow.office-shadow.com> <1187096114.19272.12.camel@gblades-suse.linguaphone-intranet.co.uk> <1187096511.19264.7.camel@paul-laptop.sidlow.office-shadow.com> <1187096894.19272.14.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <1187097438.20369.5.camel@paul-laptop.sidlow.office-shadow.com> On Tue, 2007-08-14 at 14:08 +0100, Gareth wrote: > This is what I got :- > ... I have just upgraded my MailScanner + SpamAssassin to the latest versions and now get this: Content analysis details: (7.6 points, 5.0 required) pts rule name description -------------------------------------------------- 0.1 RDNS_NONE Delivered to trusted network by a host with no rDNS 2.5 FRT_PRICE BODY: ReplaceTags: Price 3.6 FRT_SYMBOL BODY: ReplaceTags: Symbol 1.4 TVD_FUZZY_SYMBOL BODY: TVD_FUZZY_SYMBOL 0.0 HS_INDEX_PARAM URI: Link contains a common tracker pattern. 0.0 HTML_MESSAGE BODY: HTML included in message Which is obviously much better and closer to your results although I still have a few questions... 1) In order for my bayes database to work properly do I need to regularly manually train it? I was under the impression this was an automated process. 2) Why are no RBL checks being reported on? I have setup spamassasin to skip RBL checks, but MailScanner is set to use a few RBLs. Does this mean that the RBLs are not being checked at all? Thanks, Paul -- This message has been scanned for spam, viruses and phishing attempts by firespam.com From martin.lyberg at gmail.com Tue Aug 14 14:22:48 2007 From: martin.lyberg at gmail.com (Martin) Date: Tue Aug 14 14:23:06 2007 Subject: Understanding Watermarking In-Reply-To: References: Message-ID: Kai Schaetzl wrote: > Yes. And if you read a bit back on the list you'll see that it doesn't > work for read receipts, certain DSNs, certain autoreplies and maybe more. > There's no guarantee that only fake DSNs are detected by this feature. Does this mean that read receipts etc will be tagged as spam? / Martin From matt at coders.co.uk Tue Aug 14 14:28:31 2007 From: matt at coders.co.uk (Matt Hampton) Date: Tue Aug 14 14:29:13 2007 Subject: Understanding Watermarking In-Reply-To: References: Message-ID: <46C1ADFF.5040809@coders.co.uk> Martin wrote: > Kai Schaetzl wrote: > >> Yes. And if you read a bit back on the list you'll see that it doesn't >> work for read receipts, certain DSNs, certain autoreplies and maybe >> more. There's no guarantee that only fake DSNs are detected by this >> feature. > > Does this mean that read receipts etc will be tagged as spam? > > / Martin > No - not all - just those that are generated by Outlook 2003 and those by Exchange 2007. matt From maillists at conactive.com Tue Aug 14 14:29:33 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Tue Aug 14 14:29:34 2007 Subject: How to manually test an email? In-Reply-To: <1187097438.20369.5.camel@paul-laptop.sidlow.office-shadow.com> References: <1187095642.19264.3.camel@paul-laptop.sidlow.office-shadow.com> <1187096114.19272.12.camel@gblades-suse.linguaphone-intranet.co.uk> <1187096511.19264.7.camel@paul-laptop.sidlow.office-shadow.com> <1187096894.19272.14.camel@gblades-suse.linguaphone-intranet.co.uk> <1187097438.20369.5.camel@paul-laptop.sidlow.office-shadow.com> Message-ID: Paul @ firespam wrote on Tue, 14 Aug 2007 14:17:18 +0100: > 1) In order for my bayes database to work properly do I need to > regularly manually train it? I was under the impression this was an > automated process. How much tokens do you have in your Bayes db? autolearn is done if the score reaches a certain threshold. With the low score you achieved it won't be learned. Use additional rulesets. You should train Bayes manually when you start a new db. My personal feeling is it should have seen at least 10.000 messages before you can stop that. After that autolearn takes care as long as you achieve high and accurate enough results. 90% or more of the spam we detect is high-scoring. > > 2) Why are no RBL checks being reported on? I have setup spamassasin to > skip RBL checks, but MailScanner is set to use a few RBLs. Does this > mean that the RBLs are not being checked at all? You ran spamassassin on the command line, right? No MS there ;-) Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From list-mailscanner at linguaphone.com Tue Aug 14 14:32:20 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue Aug 14 14:32:27 2007 Subject: How to manually test an email? In-Reply-To: <1187097438.20369.5.camel@paul-laptop.sidlow.office-shadow.com> References: <1187095642.19264.3.camel@paul-laptop.sidlow.office-shadow.com> <1187096114.19272.12.camel@gblades-suse.linguaphone-intranet.co.uk> <1187096511.19264.7.camel@paul-laptop.sidlow.office-shadow.com> <1187096894.19272.14.camel@gblades-suse.linguaphone-intranet.co.uk> <1187097438.20369.5.camel@paul-laptop.sidlow.office-shadow.com> Message-ID: <1187098340.19279.21.camel@gblades-suse.linguaphone-intranet.co.uk> You can download the chickenpox rules from. I forgot I hadn't added them so I have just done so myself. http://www.emtinc.net/includes/chickenpox.cf 1) Bayes does automatically learn but it only learns spam messages if the spamassassin score is over 20. There are types of spam message which may normally be caught as spam but dont get a score over 20 so unless you manually train your bayes will not learn some types of spam message. Personally I get users at work to move all missed spam into a shared mailbox and then learn that regularly. 2) Personally I would let spamassassin do RBL checks aswell. If Mailscanner has already done it then it will be in the cache anyway so no performance hit. If there was a dns timeout then you might have an answer when spamassassin does its check. I have spamcop listed as a rbl on out postfix mta but for a few messages the dns lookup times out and postfix lets it through only for spamassassin to find it when it does rbl checks and give it a nice high score. On Tue, 2007-08-14 at 14:17, paul @ firespam wrote: > On Tue, 2007-08-14 at 14:08 +0100, Gareth wrote: > > This is what I got :- > > ... > > I have just upgraded my MailScanner + SpamAssassin to the latest > versions and now get this: > > Content analysis details: (7.6 points, 5.0 required) > > pts rule name description > -------------------------------------------------- > 0.1 RDNS_NONE Delivered to trusted network by a host with > no rDNS > 2.5 FRT_PRICE BODY: ReplaceTags: Price > 3.6 FRT_SYMBOL BODY: ReplaceTags: Symbol > 1.4 TVD_FUZZY_SYMBOL BODY: TVD_FUZZY_SYMBOL > 0.0 HS_INDEX_PARAM URI: Link contains a common tracker pattern. > 0.0 HTML_MESSAGE BODY: HTML included in message > > Which is obviously much better and closer to your results although I > still have a few questions... > > 1) In order for my bayes database to work properly do I need to > regularly manually train it? I was under the impression this was an > automated process. > > 2) Why are no RBL checks being reported on? I have setup spamassasin to > skip RBL checks, but MailScanner is set to use a few RBLs. Does this > mean that the RBLs are not being checked at all? > > > Thanks, > > > Paul > > > -- > This message has been scanned for spam, viruses and phishing attempts by firespam.com From maillists at conactive.com Tue Aug 14 14:33:38 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Tue Aug 14 14:33:38 2007 Subject: Understanding Watermarking In-Reply-To: References: Message-ID: Martin wrote on Tue, 14 Aug 2007 15:22:48 +0200: > Does this mean that read receipts etc will be tagged as spam? They will be detected by MS as not being a reply to a mail that went thru the system. I don't know if that means they get tagged as spam, I'm not using the feature. Just search the archives for "watermark" (or maybe "water-mark"?) for the various problems. As Matt says, not all read receipts come from a NULL sender. But all that do will be subject to this. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From martin.lyberg at gmail.com Tue Aug 14 14:33:43 2007 From: martin.lyberg at gmail.com (Martin) Date: Tue Aug 14 14:33:56 2007 Subject: Understanding Watermarking In-Reply-To: <46C1ADFF.5040809@coders.co.uk> References: <46C1ADFF.5040809@coders.co.uk> Message-ID: Matt Hampton wrote: > No - not all - just those that are generated by Outlook 2003 and those > by Exchange 2007. Ok. Is there any workaround to not get this tagged as spam? Outlook and exchange is widespread among our clients as far as i know. Thank you / Martin From brose at med.wayne.edu Tue Aug 14 14:36:11 2007 From: brose at med.wayne.edu (Rose, Bobby) Date: Tue Aug 14 14:36:21 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <24231931.14351186764822763.JavaMail.root@office.splatnix.net> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info> <24231931.14351186764822763.JavaMail.root@office.splatnix.net> Message-ID: <8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> Has anyone noticed a performance hit going from SA 3.2.1 to the latest versions. I noticed it last month with 3.2.2 but didn't have time to investigate so I rolled back to 3.2.1. Last week, I applied SA 3.2.3 and I'm seeing the same thing where my inbound queue slowly keeps growing. I've been using MailScanner and SA for years and I'm pretty familiar with how it all works so it's not a newbie issue. If I look at the processing times based on MailScanner logging, with 3.2.3 I see triple digits (between 200 - 400 seconds) for batches of 30 but if roll back to 3.2.1 then it falls to double digits lower than 60 seconds. Has anyone else noticed such a problem? -=Bobby From glenn.steen at gmail.com Tue Aug 14 14:36:19 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue Aug 14 14:36:22 2007 Subject: How to manually test an email? In-Reply-To: <1187097438.20369.5.camel@paul-laptop.sidlow.office-shadow.com> References: <1187095642.19264.3.camel@paul-laptop.sidlow.office-shadow.com> <1187096114.19272.12.camel@gblades-suse.linguaphone-intranet.co.uk> <1187096511.19264.7.camel@paul-laptop.sidlow.office-shadow.com> <1187096894.19272.14.camel@gblades-suse.linguaphone-intranet.co.uk> <1187097438.20369.5.camel@paul-laptop.sidlow.office-shadow.com> Message-ID: <223f97700708140636n2b82e03djaae7abe96583c515@mail.gmail.com> On 14/08/07, paul @ firespam wrote: > > On Tue, 2007-08-14 at 14:08 +0100, Gareth wrote: > > This is what I got :- > > ... > > I have just upgraded my MailScanner + SpamAssassin to the latest > versions and now get this: > > Content analysis details: (7.6 points, 5.0 required) > > pts rule name description > -------------------------------------------------- > 0.1 RDNS_NONE Delivered to trusted network by a host with > no rDNS > 2.5 FRT_PRICE BODY: ReplaceTags: Price > 3.6 FRT_SYMBOL BODY: ReplaceTags: Symbol > 1.4 TVD_FUZZY_SYMBOL BODY: TVD_FUZZY_SYMBOL > 0.0 HS_INDEX_PARAM URI: Link contains a common tracker pattern. > 0.0 HTML_MESSAGE BODY: HTML included in message > > Which is obviously much better and closer to your results although I > still have a few questions... > > 1) In order for my bayes database to work properly do I need to > regularly manually train it? I was under the impression this was an > automated process. It is, but the autolearning is, depending on things like the relationship between header and body rules, number of messages handled etc, sometimes a slow process. You can "jumpstart" your bayes by - keeping a corpus of SPAM and HAM messages that you manually train it with, to exceed the required 200 of each it knows.... After that, the score set chosen will be different and you'll start seeing bayes hits. - Instead jump start it with a "starter db" for bayes. Fortress systems has one on their support site (http://www.fsl.com/support IIRC:). Since these will not really be matching your mailflow, it is frowned upon by some. Still an easy way of getting bayes going. ... or just have more patience:-). To keep your bayes db functioning well, if for example the autolearning doesn't seem to be that effective, you can let a few trusted users train it for you. How to do this will of course depend entirely on your setup. MailWatch can be an invaluable tool for this. > 2) Why are no RBL checks being reported on? I have setup spamassasin to > skip RBL checks, but MailScanner is set to use a few RBLs. Does this > mean that the RBLs are not being checked at all? > When testing spamassassin, like you do now, don't expect it to magically test MailScanner. MailScanner uses serial lookups, so it is a generally bad idea to have more than one or two defined there. And since it is a definitive spam/ham thing there, you could as well "save some resources" and do them in your MTA. Spamassassin is most efficient, since it will do the lookups in parallell... Turn bls back on and you'll start seeing them. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From maillists at conactive.com Tue Aug 14 14:44:40 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Tue Aug 14 14:44:45 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info> <24231931.14351186764822763.JavaMail.root@office.splatnix.net> <8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> Message-ID: Bobby Rose wrote on Tue, 14 Aug 2007 09:36:11 -0400: > Has anyone else noticed such a problem? Yes, read back on the list. Did you install SA from Julian's clamav+sa package? Then disable the ASN plugin. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From glenn.steen at gmail.com Tue Aug 14 14:45:06 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue Aug 14 14:45:15 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info> <24231931.14351186764822763.JavaMail.root@office.splatnix.net> <8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> Message-ID: <223f97700708140645p288f9a7dw33045f3953dc49d8@mail.gmail.com> On 14/08/07, Rose, Bobby wrote: > Has anyone noticed a performance hit going from SA 3.2.1 to the latest > versions. I noticed it last month with 3.2.2 but didn't have time to > investigate so I rolled back to 3.2.1. Last week, I applied SA 3.2.3 > and I'm seeing the same thing where my inbound queue slowly keeps > growing. I've been using MailScanner and SA for years and I'm pretty > familiar with how it all works so it's not a newbie issue. > > If I look at the processing times based on MailScanner logging, with > 3.2.3 I see triple digits (between 200 - 400 seconds) for batches of 30 > but if roll back to 3.2.1 then it falls to double digits lower than 60 > seconds. > > Has anyone else noticed such a problem? > > -=Bobby > There was a recent thread about the ASN plugin... Seems in these versions it is more of a problem than before (Jules Clam+SA package used to enable them, but shouldn't any more). Look through your *pre files (probably in /etc/mail/spamassassin) for that plugin, comment/remove it, restart MS ... and it should be resolved. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From martinh at solidstatelogic.com Tue Aug 14 14:45:43 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Tue Aug 14 14:45:47 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> Message-ID: <3a9c9c3662f0954d97136797613ea17a@solidstatelogic.com> Boddy Which what of installing SA are you using? -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Rose, Bobby > Sent: 14 August 2007 14:36 > To: MailScanner discussion > Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 > > Has anyone noticed a performance hit going from SA 3.2.1 to the latest > versions. I noticed it last month with 3.2.2 but didn't have time to > investigate so I rolled back to 3.2.1. Last week, I applied SA 3.2.3 > and I'm seeing the same thing where my inbound queue slowly keeps > growing. I've been using MailScanner and SA for years and I'm pretty > familiar with how it all works so it's not a newbie issue. > > If I look at the processing times based on MailScanner logging, with > 3.2.3 I see triple digits (between 200 - 400 seconds) for batches of 30 > but if roll back to 3.2.1 then it falls to double digits lower than 60 > seconds. > > Has anyone else noticed such a problem? > > -=Bobby > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From prandal at herefordshire.gov.uk Tue Aug 14 14:45:58 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Tue Aug 14 14:46:15 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info><24231931.14351186764822763.JavaMail.root@office.splatnix.net> <8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA0169FBF8@HC-MBX02.herefordshire.gov.uk> This sounds familiar... Are you running the ASN plugin (check ALL your .pre files)? If so, disable it. http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5589 Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Rose, Bobby > Sent: 14 August 2007 14:36 > To: MailScanner discussion > Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 > > Has anyone noticed a performance hit going from SA 3.2.1 to the latest > versions. I noticed it last month with 3.2.2 but didn't have time to > investigate so I rolled back to 3.2.1. Last week, I applied SA 3.2.3 > and I'm seeing the same thing where my inbound queue slowly keeps > growing. I've been using MailScanner and SA for years and I'm pretty > familiar with how it all works so it's not a newbie issue. > > If I look at the processing times based on MailScanner logging, with > 3.2.3 I see triple digits (between 200 - 400 seconds) for > batches of 30 > but if roll back to 3.2.1 then it falls to double digits lower than 60 > seconds. > > Has anyone else noticed such a problem? > > -=Bobby > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From martinh at solidstatelogic.com Tue Aug 14 14:46:22 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Tue Aug 14 14:46:28 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> Message-ID: <787315892f807e43a726ffe5bc1ad823@solidstatelogic.com> Bobby Sorry - hit the send key too quick.. How are you installing SA? -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Rose, Bobby > Sent: 14 August 2007 14:36 > To: MailScanner discussion > Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 > > Has anyone noticed a performance hit going from SA 3.2.1 to the latest > versions. I noticed it last month with 3.2.2 but didn't have time to > investigate so I rolled back to 3.2.1. Last week, I applied SA 3.2.3 > and I'm seeing the same thing where my inbound queue slowly keeps > growing. I've been using MailScanner and SA for years and I'm pretty > familiar with how it all works so it's not a newbie issue. > > If I look at the processing times based on MailScanner logging, with > 3.2.3 I see triple digits (between 200 - 400 seconds) for batches of 30 > but if roll back to 3.2.1 then it falls to double digits lower than 60 > seconds. > > Has anyone else noticed such a problem? > > -=Bobby > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From brose at med.wayne.edu Tue Aug 14 14:50:09 2007 From: brose at med.wayne.edu (Rose, Bobby) Date: Tue Aug 14 14:50:20 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info><24231931.14351186764822763.JavaMail.root@office.splatnix.net><8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> Message-ID: <8F2A53954C22554EB75D9643FCCE0C6B0472D462@MED-CORE03-MS1.med.wayne.edu> Nope. It's not an ASN plugin issue. This is SA straight from src and ASN isn't in use. My SA init and pre files are the same between the versions. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Kai Schaetzl Sent: Tuesday, August 14, 2007 9:45 AM To: mailscanner@lists.mailscanner.info Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 Bobby Rose wrote on Tue, 14 Aug 2007 09:36:11 -0400: > Has anyone else noticed such a problem? Yes, read back on the list. Did you install SA from Julian's clamav+sa package? Then disable the ASN plugin. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From glenn.steen at gmail.com Tue Aug 14 14:59:47 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue Aug 14 14:59:50 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B0472D462@MED-CORE03-MS1.med.wayne.edu> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info> <24231931.14351186764822763.JavaMail.root@office.splatnix.net> <8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> <8F2A53954C22554EB75D9643FCCE0C6B0472D462@MED-CORE03-MS1.med.wayne.edu> Message-ID: <223f97700708140659r78ee184cjba7e82325c1d3ed4@mail.gmail.com> On 14/08/07, Rose, Bobby wrote: > Nope. It's not an ASN plugin issue. This is SA straight from src and ASN isn't in use. My SA init and pre files are the same between the versions. > Bummer. Always better when it's something easy:-). I guess you need ask over at the SA list then. Personally, I've not noticed anything dramatic. Might perhaps be some other plugin going up ...?:-) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From brose at med.wayne.edu Tue Aug 14 15:07:12 2007 From: brose at med.wayne.edu (Rose, Bobby) Date: Tue Aug 14 15:07:20 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <787315892f807e43a726ffe5bc1ad823@solidstatelogic.com> References: <8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> <787315892f807e43a726ffe5bc1ad823@solidstatelogic.com> Message-ID: <8F2A53954C22554EB75D9643FCCE0C6B0472D463@MED-CORE03-MS1.med.wayne.edu> Compiled from source directly from SA just as I have since the early days. I don't use rpms, not even for MailScanner. I've checked cpan and all my perl modules are current. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Martin.Hepworth Sent: Tuesday, August 14, 2007 9:46 AM To: MailScanner discussion Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 Bobby Sorry - hit the send key too quick.. How are you installing SA? -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Rose, Bobby > Sent: 14 August 2007 14:36 > To: MailScanner discussion > Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 > > Has anyone noticed a performance hit going from SA 3.2.1 to the latest > versions. I noticed it last month with 3.2.2 but didn't have time to > investigate so I rolled back to 3.2.1. Last week, I applied SA 3.2.3 > and I'm seeing the same thing where my inbound queue slowly keeps > growing. I've been using MailScanner and SA for years and I'm pretty > familiar with how it all works so it's not a newbie issue. > > If I look at the processing times based on MailScanner logging, with > 3.2.3 I see triple digits (between 200 - 400 seconds) for batches of > 30 but if roll back to 3.2.1 then it falls to double digits lower than > 60 seconds. > > Has anyone else noticed such a problem? > > -=Bobby > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From martin.lyberg at gmail.com Tue Aug 14 15:08:53 2007 From: martin.lyberg at gmail.com (Martin) Date: Tue Aug 14 15:09:14 2007 Subject: Understanding Watermarking In-Reply-To: References: Message-ID: Kai Schaetzl wrote: > They will be detected by MS as not being a reply to a mail that went thru > the system. I don't know if that means they get tagged as spam, I'm not > using the feature. Just search the archives for "watermark" (or maybe > "water-mark"?) for the various problems. > As Matt says, not all read receipts come from a NULL sender. But all that > do will be subject to this. Alright. Guess i will wait to implement this feature. Gonna read back in the archives about watermarking. Thank you From maillists at conactive.com Tue Aug 14 15:11:51 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Tue Aug 14 15:11:52 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <223f97700708140659r78ee184cjba7e82325c1d3ed4@mail.gmail.com> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info> <24231931.14351186764822763.JavaMail.root@office.splatnix.net> <8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> <8F2A53954C22554EB75D9643FCCE0C6B0472D462@MED-CORE03-MS1.med.wayne.edu> <223f97700708140659r78ee184cjba7e82325c1d3ed4@mail.gmail.com> Message-ID: Glenn Steen wrote on Tue, 14 Aug 2007 15:59:47 +0200: > I guess you need ask over at the SA list then. Personally, I've not > noticed anything dramatic. Same here. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Tue Aug 14 15:11:51 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Tue Aug 14 15:11:53 2007 Subject: Understanding Watermarking In-Reply-To: References: <46C1ADFF.5040809@coders.co.uk> Message-ID: Martin wrote on Tue, 14 Aug 2007 15:33:43 +0200: > Is there any workaround to not get this tagged as spam? Maybe there is, I'm not aware of one. In general, I think you cannot use the watermarking feature for detecting back-scatter. It maybe useful during a back-scatter storm (but then I'd use something at MTA level), but for normal operation I fear it is going to hit too many false postives. That is not specific of the MS implementation, it's a general problem of this method. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Tue Aug 14 15:19:02 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Tue Aug 14 15:19:02 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B0472D463@MED-CORE03-MS1.med.wayne.edu> References: <8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> <787315892f807e43a726ffe5bc1ad823@solidstatelogic.com> <8F2A53954C22554EB75D9643FCCE0C6B0472D463@MED-CORE03-MS1.med.wayne.edu> Message-ID: Well, *did* you check that this plugin didn't get enabled by accident? Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From prandal at herefordshire.gov.uk Tue Aug 14 15:19:42 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Tue Aug 14 15:19:48 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B0472D462@MED-CORE03-MS1.med.wayne.edu> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info><24231931.14351186764822763.JavaMail.root@office.splatnix.net><8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> <8F2A53954C22554EB75D9643FCCE0C6B0472D462@MED-CORE03-MS1.med.wayne.edu> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA0169FC0F@HC-MBX02.herefordshire.gov.uk> I'm getting very slow DNS lookups from combined-HIB.dnsiplists.completewhois.com. That might be a factor. Does using score __RCVD_IN_WHOIS 0 score RCVD_IN_WHOIS_INVALID 0 score URIBL_COMPLETEWHOIS 0 solve the performance problem? Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Rose, Bobby > Sent: 14 August 2007 14:50 > To: MailScanner discussion > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 > and 3.2.3 > > Nope. It's not an ASN plugin issue. This is SA straight from > src and ASN isn't in use. My SA init and pre files are the > same between the versions. > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Kai Schaetzl > Sent: Tuesday, August 14, 2007 9:45 AM > To: mailscanner@lists.mailscanner.info > Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 > and 3.2.3 > > Bobby Rose wrote on Tue, 14 Aug 2007 09:36:11 -0400: > > > Has anyone else noticed such a problem? > > Yes, read back on the list. Did you install SA from Julian's > clamav+sa package? Then disable the ASN plugin. > > Kai > > -- > Kai Sch?tzl, Berlin, Germany > Get your web at Conactive Internet Services: http://www.conactive.com > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From brose at med.wayne.edu Tue Aug 14 15:37:58 2007 From: brose at med.wayne.edu (Rose, Bobby) Date: Tue Aug 14 15:38:18 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: References: <8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu><787315892f807e43a726ffe5bc1ad823@solidstatelogic.com><8F2A53954C22554EB75D9643FCCE0C6B0472D463@MED-CORE03-MS1.med.wayne.edu> Message-ID: <8F2A53954C22554EB75D9643FCCE0C6B0472D464@MED-CORE03-MS1.med.wayne.edu> Yes I did. It's not enabled and does not appear in my debug info when running test messages against SA. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Kai Schaetzl Sent: Tuesday, August 14, 2007 10:19 AM To: mailscanner@lists.mailscanner.info Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 Well, *did* you check that this plugin didn't get enabled by accident? Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From Jim at jameswest.com Tue Aug 14 15:39:57 2007 From: Jim at jameswest.com (Jim West) Date: Tue Aug 14 15:40:25 2007 Subject: How to manually test an email? In-Reply-To: <1187096894.19272.14.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1187095642.19264.3.camel@paul-laptop.sidlow.office-shadow.com> <1187096114.19272.12.camel@gblades-suse.linguaphone-intranet.co.uk> <1187096511.19264.7.camel@paul-laptop.sidlow.office-shadow.com> <1187096894.19272.14.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <42668.192.25.240.225.1187102397.squirrel@mail.jameswest.com> ...and I got this: Content analysis details: (10.2 points, 3.8 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.1 RDNS_NONE Delivered to trusted network by a host with no rDNS 2.0 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net [Blocked - see ] 3.5 FRT_PRICE BODY: ReplaceTags: Price 2.9 FRT_SYMBOL BODY: ReplaceTags: Symbol 1.7 TVD_FUZZY_SYMBOL BODY: TVD_FUZZY_SYMBOL 0.0 HS_INDEX_PARAM URI: Link contains a common tracker pattern. 0.0 HTML_MESSAGE BODY: HTML included in message 0.0 BAYES_50 BODY: Bayesian spam probability is 40 to 60% [score: 0.5413] > This is what I got :- > > > Content analysis details: (9.6 points, 5.0 required) > > pts rule name description > ---- ---------------------- > -------------------------------------------------- > 1.0 INVALID_TZ_GMT Invalid date in header (wrong GMT/UTC > timezone) > 0.1 FORGED_RCVD_HELO Received: contains a forged HELO > -0.2 BOTNET_SERVERWORDS Hostname contains server-like substrings > > [botnet_serverwords,ip=217.160.207.111,rdns=mail2.office-shadow.com] > 1.7 SARE_MLB_Stock5 BODY: Mentions stock symbol, tickers, or > OTC. > 1.8 TVD_FUZZY_SYMBOL BODY: TVD_FUZZY_SYMBOL > 0.1 HTML_TEXT_AFTER_BODY BODY: HTML contains text after BODY close > tag > 1.0 BAYES_60 BODY: Bayesian spam probability is 60 to 80% > [score: 0.6344] > 0.0 HTML_MESSAGE BODY: HTML included in message > 4.0 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net > [Blocked - see > ] > From mailscanner at lists.com.ar Tue Aug 14 16:14:51 2007 From: mailscanner at lists.com.ar (Leonardo Helman) Date: Tue Aug 14 16:14:30 2007 Subject: ZMailer Patch Message-ID: <20070814151450.GA18561@pert.com.ar> Hi Julian, I'm sending you a patch for the ZMDiskStore, it seems the last I sent this wasn't the latest I have or something You have (surely I sent it that way) a xxx == "-UNDEF-" and it should said something like xxx eq "-UNDEF-" Thanks Saludos -- Leonardo Helman Pert Consultores Argentina PERT Consultores Argentina -------------- next part -------------- diff -Naur MailScanner-4.63.1-2.ORIG/lib/MailScanner/ZMDiskStore.pm MailScanner-4.63.1-2/lib/MailScanner/ZMDiskStore.pm --- MailScanner-4.63.1-2.ORIG/lib/MailScanner/ZMDiskStore.pm 2007-05-30 13:30:34.000000000 -0300 +++ MailScanner-4.63.1-2/lib/MailScanner/ZMDiskStore.pm 2007-08-14 11:12:59.000000000 -0300 @@ -504,7 +504,7 @@ sub Start { #my ( $this )=@_; my ($this,$entiremessage )=@_; - if( $$this{_startpos} == "-UNDEF-" ) { + if( $$this{_startpos} eq "-UNDEF-" ) { seek $$this{_handle}, 0, 0; # reset the handle my $InHeader = 0; #print STDERR "Start\n"; @@ -531,7 +531,7 @@ sub Next { my ( $this )=@_; - if( $$this{_startpos} == "-UNDEF-" ) { + if( $$this{_startpos} eq "-UNDEF-" ) { $this->Start(); } return( $$this{_handle}->getline ); From Denis.Beauchemin at USherbrooke.ca Tue Aug 14 16:19:08 2007 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Tue Aug 14 16:19:40 2007 Subject: mailscanner trouble In-Reply-To: <3376.62.150.152.226.1185292117.squirrel@webmail.baladia.gov.kw> References: <3376.62.150.152.226.1185292117.squirrel@webmail.baladia.gov.kw> Message-ID: <46C1C7EC.9020003@USherbrooke.ca> simon a ?crit : > ... > > 2) RBL Check ORDB-RBL timed out and was killed, consecutive failure 2 of 7 > I'm just back from a nice vacation... so my brains may not be up to speed yet... but didn't ORDB-RBL stop working a while ago? Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x62252 F: 819.821.8045 -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3595 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070814/541b9cb2/smime.bin From v at vladville.com Tue Aug 14 16:19:53 2007 From: v at vladville.com (Vlad Mazek) Date: Tue Aug 14 16:19:56 2007 Subject: Mailscanner RBL checks In-Reply-To: <46BB6C55.3090607@cnpapers.com> References: <46BB6045.30809@syska.dk> <46BB6C55.3090607@cnpapers.com> Message-ID: Thing is, skip_rbl_checks =1 would skip them all, I just want to restrict which ones are being queried. Here are the queries that are launched by MailScanner: [2351] dbg: dns: URIBL_RED lookup start [2351] dbg: dns: URIBL_GREY lookup start [2351] dbg: dns: WHOIS_SECUREWHOIS lookup start [2351] dbg: dns: WHOIS_MYPRIVREG lookup start [2351] dbg: dns: WHOIS_NETSOLPR lookup start [2351] dbg: dns: WHOIS_AITPRIV lookup start [2351] dbg: dns: URIBL_SC_SURBL lookup start [2351] dbg: dns: URIBL_AB_SURBL lookup start [2351] dbg: dns: WHOIS_CONTACTPRIV lookup start [2351] dbg: dns: WHOIS_NAMEKING lookup start [2351] dbg: dns: WHOIS_PRIVPROT lookup start [2351] dbg: dns: WHOIS_WHOISGUARD lookup start [2351] dbg: dns: URIBL_PH_SURBL lookup start [2351] dbg: dns: URIBL_BLACK lookup start [2351] dbg: dns: WHOIS_PRIVACYPOST lookup start [2351] dbg: dns: URIBL_RHS_DOB lookup start [2351] dbg: dns: URIBL_JP_SURBL lookup start [2351] dbg: dns: URIBL_WS_SURBL lookup start [2351] dbg: dns: URIBL_OB_SURBL lookup start [2351] dbg: dns: WHOIS_DMNBYPROXY lookup start [2351] dbg: dns: WHOIS_REGISTERFLY lookup start [2351] dbg: dns: WHOIS_UNLISTED lookup start [2351] dbg: dns: WHOIS_MONIKER_PRIV lookup start [2351] dbg: dns: URIBL_SBL lookup start How do I find out which rule/definition is causing all these lookups to launch? -Vlad On 8/9/07, Steve Campbell wrote: > > I believe you can do this, but my versions are a little old: > > In MailScanner.conf, try setting the following: > > Spam List = > Spam Domain List = > > This turns off RBLs and the like in MS. > > In either mailscanner.cf, local.cf, or spam.assassin.prefs.conf, set the > following: > skip_rbl_checks = 1 > > This turns off RBLs in SA. > > Make sure they are not commented if they already exist. > > I may be wrong on this, so anyone can correct me if I am. > > Steve Campbell > > Mikael Syska wrote: > > Scott Silva wrote: > >> Vlad Mazek spake the following on 8/9/2007 9:59 AM: > >> > >>> I'm sorry I am just not following; my mailscanner.cf > >>> has only one line: > >>> > >>> dns_available yes > >>> > >>> Yet, it seems to be querying the external RBL's: > >>> SpamAssassin (not cached, score= 16.885, required 5, > >>> autolearn=disabled, > >>> FH_RELAY_NODNS 1.25, HELO_EQ_IP_ADDR 1.12, HTML_MESSAGE 0.00, > >>> HTML_OBFUSCATE_05_10 0.57, MIME_HTML_ONLY 1.67, RCVD_IN_BL_SPAMCOP_NET > >>> 2.19, RCVD_IN_PBL 0.51, RDNS_NONE 0.10, URIBL_BLACK 1.96, > >>> URIBL_JP_SURBL > >>> 2.86, URIBL_OB_SURBL 2.13, URIBL_SC_SURBL 2.52 > >>> > >>> My question is simply where/what is telling SpamAssassin to query all > >>> these RBLs because my MailScanner.cf doesn't list any RBLs to be > called > >>> (line is commented out completely) > >>> > >> Spamassassin has several tests it does all by itself that are > >> indepentent of > >> mailscanner. Spamassassin tests rbl's and gives a score that is added > >> together. When you use rbl's in mailscanner they are just flagged as > >> spam if > >> they hit, independent of how reliable a rbl might be. > >> > >> As you were told in the last mail, if you do not want rbl tests in > >> spamassassin, you have to add a line for each one in mailscanner.cf. > >> As an example, if you didn't want to test for RCVD_IN_BL_SPAMCOP_NET > >> you add the following line; > >> score RCVD_IN_BL_SPAMCOP_NET 0 > >> > >> Does this clear things up a little more? > >> > > Little off-topic: > > Can't the lookups be completely disabled, so its possible to avoid the > > the DNS query ? > > > > As I understand SA, it will still make the lookup even if the score is > > 0 ... or am I wrong here ? > > > > // ouT > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- -Vlad -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070814/fc28f1a3/attachment.html From martinh at solidstatelogic.com Tue Aug 14 16:28:20 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Tue Aug 14 16:28:29 2007 Subject: mailscanner trouble In-Reply-To: <46C1C7EC.9020003@USherbrooke.ca> Message-ID: <3452520aa33ee2418e480d22ef72c83c@solidstatelogic.com> Dennis You are correct - many moons ago.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Denis Beauchemin > Sent: 14 August 2007 16:19 > To: MailScanner discussion > Subject: Re: mailscanner trouble > > simon a ?crit : > > ... > > > > 2) RBL Check ORDB-RBL timed out and was killed, consecutive failure 2 of > 7 > > > > I'm just back from a nice vacation... so my brains may not be up to > speed yet... but didn't ORDB-RBL stop working a while ago? > > Denis > > -- > _ > ?v? Denis Beauchemin, analyste > /(_)\ Universit? de Sherbrooke, S.T.I. > ^ ^ T: 819.821.8000x62252 F: 819.821.8045 > ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From Richard.Frovarp at sendit.nodak.edu Tue Aug 14 16:56:08 2007 From: Richard.Frovarp at sendit.nodak.edu (Richard Frovarp) Date: Tue Aug 14 16:56:12 2007 Subject: Mailscanner RBL checks In-Reply-To: References: <46BB6045.30809@syska.dk> <46BB6C55.3090607@cnpapers.com> Message-ID: <46C1D098.6080700@sendit.nodak.edu> grep through the rules. URIBLs seem to be in 25_uribl.cf and DNSBLs seem to be in 20_dnsbl_tests.cf Vlad Mazek wrote: > Thing is, skip_rbl_checks =1 would skip them all, I just want to > restrict which ones are being queried. > > Here are the queries that are launched by MailScanner: > [2351] dbg: dns: URIBL_RED lookup start > [2351] dbg: dns: URIBL_GREY lookup start > [2351] dbg: dns: WHOIS_SECUREWHOIS lookup start > [2351] dbg: dns: WHOIS_MYPRIVREG lookup start > [2351] dbg: dns: WHOIS_NETSOLPR lookup start > [2351] dbg: dns: WHOIS_AITPRIV lookup start > [2351] dbg: dns: URIBL_SC_SURBL lookup start > [2351] dbg: dns: URIBL_AB_SURBL lookup start > [2351] dbg: dns: WHOIS_CONTACTPRIV lookup start > [2351] dbg: dns: WHOIS_NAMEKING lookup start > [2351] dbg: dns: WHOIS_PRIVPROT lookup start > [2351] dbg: dns: WHOIS_WHOISGUARD lookup start > [2351] dbg: dns: URIBL_PH_SURBL lookup start > [2351] dbg: dns: URIBL_BLACK lookup start > [2351] dbg: dns: WHOIS_PRIVACYPOST lookup start > [2351] dbg: dns: URIBL_RHS_DOB lookup start > [2351] dbg: dns: URIBL_JP_SURBL lookup start > [2351] dbg: dns: URIBL_WS_SURBL lookup start > [2351] dbg: dns: URIBL_OB_SURBL lookup start > [2351] dbg: dns: WHOIS_DMNBYPROXY lookup start > [2351] dbg: dns: WHOIS_REGISTERFLY lookup start > [2351] dbg: dns: WHOIS_UNLISTED lookup start > [2351] dbg: dns: WHOIS_MONIKER_PRIV lookup start > [2351] dbg: dns: URIBL_SBL lookup start > > How do I find out which rule/definition is causing all these lookups > to launch? > > -Vlad > > On 8/9/07, *Steve Campbell* > wrote: > > I believe you can do this, but my versions are a little old: > > In MailScanner.conf, try setting the following: > > Spam List = > Spam Domain List = > > This turns off RBLs and the like in MS. > > In either mailscanner.cf , local.cf > , or spam.assassin.prefs.conf, set the > following: > skip_rbl_checks = 1 > > This turns off RBLs in SA. > > Make sure they are not commented if they already exist. > > I may be wrong on this, so anyone can correct me if I am. > > Steve Campbell > > Mikael Syska wrote: > > Scott Silva wrote: > >> Vlad Mazek spake the following on 8/9/2007 9:59 AM: > >> > >>> I'm sorry I am just not following; my mailscanner.cf > > >>> has only one line: > >>> > >>> dns_available yes > >>> > >>> Yet, it seems to be querying the external RBL's: > >>> SpamAssassin (not cached, score= 16.885, required 5, > >>> autolearn=disabled, > >>> FH_RELAY_NODNS 1.25, HELO_EQ_IP_ADDR 1.12, HTML_MESSAGE 0.00, > >>> HTML_OBFUSCATE_05_10 0.57, MIME_HTML_ONLY 1.67, > RCVD_IN_BL_SPAMCOP_NET > >>> 2.19, RCVD_IN_PBL 0.51, RDNS_NONE 0.10, URIBL_BLACK 1.96, > >>> URIBL_JP_SURBL > >>> 2.86, URIBL_OB_SURBL 2.13, URIBL_SC_SURBL 2.52 > >>> > >>> My question is simply where/what is telling SpamAssassin to > query all > >>> these RBLs because my MailScanner.cf doesn't list any RBLs to > be called > >>> (line is commented out completely) > >>> > >> Spamassassin has several tests it does all by itself that are > >> indepentent of > >> mailscanner. Spamassassin tests rbl's and gives a score that is > added > >> together. When you use rbl's in mailscanner they are just > flagged as > >> spam if > >> they hit, independent of how reliable a rbl might be. > >> > >> As you were told in the last mail, if you do not want rbl tests in > >> spamassassin, you have to add a line for each one in > mailscanner.cf . > >> As an example, if you didn't want to test for > RCVD_IN_BL_SPAMCOP_NET > >> you add the following line; > >> score RCVD_IN_BL_SPAMCOP_NET 0 > >> > >> Does this clear things up a little more? > >> > > Little off-topic: > > Can't the lookups be completely disabled, so its possible to > avoid the > > the DNS query ? > > > > As I understand SA, it will still make the lookup even if the > score is > > 0 ... or am I wrong here ? > > > > // ouT > From derek at csolve.net Tue Aug 14 16:56:27 2007 From: derek at csolve.net (Derek Buttineau) Date: Tue Aug 14 16:56:35 2007 Subject: TNEF Question Message-ID: <8072BCAE-023A-41D4-8E56-00C3CA14ADFF@csolve.net> Just curious, but is there any reason not to skip the body attachment in the TNEF archive when doing expansion? Looking at TNEF.pm, it looks like all I'd have to do is uncomment line 292: #next if /^msg[\d-]+\.txt$/; Is there any danger in doing this that I might not be accounting for? Thanks -- Regards, Derek Buttineau Internet Systems Developer Compu-SOLVE Internet Services Compu-SOLVE Technologies, Inc Phone: 705-725-1212 x255 E-Mail: derek@csolve.net -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070814/291ecc43/attachment.html From steve.swaney at fsl.com Tue Aug 14 17:13:01 2007 From: steve.swaney at fsl.com (Stephen Swaney) Date: Tue Aug 14 17:12:02 2007 Subject: Off topic - AntiVirus accuracy competition In-Reply-To: <46C1C7EC.9020003@USherbrooke.ca> References: <3376.62.150.152.226.1185292117.squirrel@webmail.baladia.gov.kw> <46C1C7EC.9020003@USherbrooke.ca> Message-ID: <2e7e01c7de8d$fcf7ed10$f6e7c730$@swaney@fsl.com> This is definitely off topic but I know that many of you will be interested in the results since which virus scanners to buy is an often discussed topic here. A quote from the article in the link below will explain. "A rare AntiVirus accuracy competition was conducted at Linuxworld this week, and the results should come as a blow to the paid antivirus industry. Run by delegates from the untangle network gateway, the competition should provide ammunition to critics of the idea that good virus protection cannot be provided for nothing. . . ." http://www.builderau.com.au/blogs/byteclub/viewblogpost.htm?p=339270831 And the results: 1. Kaspersky (97.1%) 2. ClamAV (91.4%) 3. Norton (88.6%) 4. F-Prot (85.7%), and 4. Sophos (85.7%) 6. McAfee (74.3%) 7. SonicWall (54.3%) 8. GlobalHauri (45.7%), and 8. Fortinet (45.7%) 10. Watchguard (2.9%) I hope none of you are using 6. or below. Steve Steve Swaney steve@fsl.com www.fsl.com From v at vladville.com Tue Aug 14 17:14:47 2007 From: v at vladville.com (Vlad Mazek) Date: Tue Aug 14 17:14:51 2007 Subject: Mailscanner RBL checks In-Reply-To: <46C1D098.6080700@sendit.nodak.edu> References: <46BB6045.30809@syska.dk> <46BB6C55.3090607@cnpapers.com> <46C1D098.6080700@sendit.nodak.edu> Message-ID: First thing I did :) There doesn't seem to be anything, not even check_uridnsbl or anything even with the rbl pattern search. I am at a loss as to what is launching these queries but its sure trashing this one site for some reason. -Vlad On 8/14/07, Richard Frovarp wrote: > > grep through the rules. URIBLs seem to be in 25_uribl.cf and DNSBLs seem > to be in 20_dnsbl_tests.cf > > Vlad Mazek wrote: > > Thing is, skip_rbl_checks =1 would skip them all, I just want to > > restrict which ones are being queried. > > > > Here are the queries that are launched by MailScanner: > > [2351] dbg: dns: URIBL_RED lookup start > > [2351] dbg: dns: URIBL_GREY lookup start > > [2351] dbg: dns: WHOIS_SECUREWHOIS lookup start > > [2351] dbg: dns: WHOIS_MYPRIVREG lookup start > > [2351] dbg: dns: WHOIS_NETSOLPR lookup start > > [2351] dbg: dns: WHOIS_AITPRIV lookup start > > [2351] dbg: dns: URIBL_SC_SURBL lookup start > > [2351] dbg: dns: URIBL_AB_SURBL lookup start > > [2351] dbg: dns: WHOIS_CONTACTPRIV lookup start > > [2351] dbg: dns: WHOIS_NAMEKING lookup start > > [2351] dbg: dns: WHOIS_PRIVPROT lookup start > > [2351] dbg: dns: WHOIS_WHOISGUARD lookup start > > [2351] dbg: dns: URIBL_PH_SURBL lookup start > > [2351] dbg: dns: URIBL_BLACK lookup start > > [2351] dbg: dns: WHOIS_PRIVACYPOST lookup start > > [2351] dbg: dns: URIBL_RHS_DOB lookup start > > [2351] dbg: dns: URIBL_JP_SURBL lookup start > > [2351] dbg: dns: URIBL_WS_SURBL lookup start > > [2351] dbg: dns: URIBL_OB_SURBL lookup start > > [2351] dbg: dns: WHOIS_DMNBYPROXY lookup start > > [2351] dbg: dns: WHOIS_REGISTERFLY lookup start > > [2351] dbg: dns: WHOIS_UNLISTED lookup start > > [2351] dbg: dns: WHOIS_MONIKER_PRIV lookup start > > [2351] dbg: dns: URIBL_SBL lookup start > > > > How do I find out which rule/definition is causing all these lookups > > to launch? > > > > -Vlad > > > > On 8/9/07, *Steve Campbell* > > wrote: > > > > I believe you can do this, but my versions are a little old: > > > > In MailScanner.conf, try setting the following: > > > > Spam List = > > Spam Domain List = > > > > This turns off RBLs and the like in MS. > > > > In either mailscanner.cf , local.cf > > , or spam.assassin.prefs.conf, set the > > following: > > skip_rbl_checks = 1 > > > > This turns off RBLs in SA. > > > > Make sure they are not commented if they already exist. > > > > I may be wrong on this, so anyone can correct me if I am. > > > > Steve Campbell > > > > Mikael Syska wrote: > > > Scott Silva wrote: > > >> Vlad Mazek spake the following on 8/9/2007 9:59 AM: > > >> > > >>> I'm sorry I am just not following; my mailscanner.cf > > > > >>> has only one line: > > >>> > > >>> dns_available yes > > >>> > > >>> Yet, it seems to be querying the external RBL's: > > >>> SpamAssassin (not cached, score= 16.885, required 5, > > >>> autolearn=disabled, > > >>> FH_RELAY_NODNS 1.25, HELO_EQ_IP_ADDR 1.12, HTML_MESSAGE 0.00, > > >>> HTML_OBFUSCATE_05_10 0.57, MIME_HTML_ONLY 1.67, > > RCVD_IN_BL_SPAMCOP_NET > > >>> 2.19, RCVD_IN_PBL 0.51, RDNS_NONE 0.10, URIBL_BLACK 1.96, > > >>> URIBL_JP_SURBL > > >>> 2.86, URIBL_OB_SURBL 2.13, URIBL_SC_SURBL 2.52 > > >>> > > >>> My question is simply where/what is telling SpamAssassin to > > query all > > >>> these RBLs because my MailScanner.cf doesn't list any RBLs to > > be called > > >>> (line is commented out completely) > > >>> > > >> Spamassassin has several tests it does all by itself that are > > >> indepentent of > > >> mailscanner. Spamassassin tests rbl's and gives a score that is > > added > > >> together. When you use rbl's in mailscanner they are just > > flagged as > > >> spam if > > >> they hit, independent of how reliable a rbl might be. > > >> > > >> As you were told in the last mail, if you do not want rbl tests > in > > >> spamassassin, you have to add a line for each one in > > mailscanner.cf . > > >> As an example, if you didn't want to test for > > RCVD_IN_BL_SPAMCOP_NET > > >> you add the following line; > > >> score RCVD_IN_BL_SPAMCOP_NET 0 > > >> > > >> Does this clear things up a little more? > > >> > > > Little off-topic: > > > Can't the lookups be completely disabled, so its possible to > > avoid the > > > the DNS query ? > > > > > > As I understand SA, it will still make the lookup even if the > > score is > > > 0 ... or am I wrong here ? > > > > > > // ouT > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- -Vlad -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070814/442bb542/attachment.html From alex at nkpanama.com Tue Aug 14 17:30:34 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Tue Aug 14 17:31:18 2007 Subject: Custom Job Request Message-ID: <46C1D8AA.9010905@nkpanama.com> I'd like to know if anyone here could write a message function that could query a Geo::IP database or similar and write a custom X-Countries header or something similar? Also, maybe by using a ruleset, all "incoming" messages (say, To: domain.com) could have a footer saying: This message traveled through X,Y and Z countries). Please e-mail me off-list with suggestions, questions and/or a quote... Thanks in advance... From Richard.Frovarp at sendit.nodak.edu Tue Aug 14 17:32:56 2007 From: Richard.Frovarp at sendit.nodak.edu (Richard Frovarp) Date: Tue Aug 14 17:32:58 2007 Subject: Mailscanner RBL checks In-Reply-To: References: <46BB6045.30809@syska.dk> <46BB6C55.3090607@cnpapers.com> <46C1D098.6080700@sendit.nodak.edu> Message-ID: <46C1D938.5020301@sendit.nodak.edu> Where did you look? Have you found the two files I referenced? Vlad Mazek wrote: > First thing I did :) There doesn't seem to be anything, not even > check_uridnsbl or anything even with the rbl pattern search. > > I am at a loss as to what is launching these queries but its sure > trashing this one site for some reason. > > -Vlad > > On 8/14/07, *Richard Frovarp* > wrote: > > grep through the rules. URIBLs seem to be in 25_uribl.cf and > DNSBLs seem > to be in 20_dnsbl_tests.cf > > Vlad Mazek wrote: > > Thing is, skip_rbl_checks =1 would skip them all, I just want to > > restrict which ones are being queried. > > > > Here are the queries that are launched by MailScanner: > > [2351] dbg: dns: URIBL_RED lookup start > > [2351] dbg: dns: URIBL_GREY lookup start > > [2351] dbg: dns: WHOIS_SECUREWHOIS lookup start > > [2351] dbg: dns: WHOIS_MYPRIVREG lookup start > > [2351] dbg: dns: WHOIS_NETSOLPR lookup start > > [2351] dbg: dns: WHOIS_AITPRIV lookup start > > [2351] dbg: dns: URIBL_SC_SURBL lookup start > > [2351] dbg: dns: URIBL_AB_SURBL lookup start > > [2351] dbg: dns: WHOIS_CONTACTPRIV lookup start > > [2351] dbg: dns: WHOIS_NAMEKING lookup start > > [2351] dbg: dns: WHOIS_PRIVPROT lookup start > > [2351] dbg: dns: WHOIS_WHOISGUARD lookup start > > [2351] dbg: dns: URIBL_PH_SURBL lookup start > > [2351] dbg: dns: URIBL_BLACK lookup start > > [2351] dbg: dns: WHOIS_PRIVACYPOST lookup start > > [2351] dbg: dns: URIBL_RHS_DOB lookup start > > [2351] dbg: dns: URIBL_JP_SURBL lookup start > > [2351] dbg: dns: URIBL_WS_SURBL lookup start > > [2351] dbg: dns: URIBL_OB_SURBL lookup start > > [2351] dbg: dns: WHOIS_DMNBYPROXY lookup start > > [2351] dbg: dns: WHOIS_REGISTERFLY lookup start > > [2351] dbg: dns: WHOIS_UNLISTED lookup start > > [2351] dbg: dns: WHOIS_MONIKER_PRIV lookup start > > [2351] dbg: dns: URIBL_SBL lookup start > > > > How do I find out which rule/definition is causing all these > lookups > > to launch? > > > > -Vlad > > > From Jamesp at MusicReports.com Tue Aug 14 18:02:05 2007 From: Jamesp at MusicReports.com (James D. Parra) Date: Tue Aug 14 18:02:16 2007 Subject: Spam slam Message-ID: <531F1E080638384C9623B00D71AA546D0502020D@exchange.musicreports.com> Hello, Recently, it seems, we are getting inundated with mail going to bogus addresses for our domain from bogus senders. Running MailScanner with postfix and SpamAssassin. Is there something I can do with Postfix to stop all of the garbage from being processed by MailScanner? I'd love to ban this stuff before it even hits the server. Many thanks in advance. James From mkettler at evi-inc.com Tue Aug 14 18:04:31 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Tue Aug 14 18:06:41 2007 Subject: Custom Job Request In-Reply-To: <46C1D8AA.9010905@nkpanama.com> References: <46C1D8AA.9010905@nkpanama.com> Message-ID: <46C1E09F.6030705@evi-inc.com> Alex Neuman van der Hans wrote: > I'd like to know if anyone here could write a message function that > could query a Geo::IP database or similar and write a custom X-Countries > header or something similar? Also, maybe by using a ruleset, all > "incoming" messages (say, To: domain.com) could have a footer saying: > This message traveled through X,Y and Z countries). > > Please e-mail me off-list with suggestions, questions and/or a quote... > Thanks in advance... Do you use SpamAssassin? Why not use the RelayCountries plugin that comes with SA and uses IP::Country::Fast. By default it doesn't add a real header to the message, but there's tips in the wiki to make it do this: See also: http://wiki.apache.org/spamassassin/RelayCountryPlugin From dgottsc at emory.edu Tue Aug 14 18:11:11 2007 From: dgottsc at emory.edu (Gottschalk, David) Date: Tue Aug 14 18:11:49 2007 Subject: Spam slam In-Reply-To: <531F1E080638384C9623B00D71AA546D0502020D@exchange.musicreports.com> References: <531F1E080638384C9623B00D71AA546D0502020D@exchange.musicreports.com> Message-ID: <8D2EFA3D9FD29C45BCEC3B532F0E23084131E22E8F@RDPEXCH2.Eu.Emory.Edu> Reject mail for unknown users at the MTA level (sendmail, postfix, etc) MailScanner then won't have to process any mail for unknown users. David Gottschalk -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of James D. Parra Sent: Tuesday, August 14, 2007 1:02 PM To: 'mailscanner@lists.mailscanner.info' Subject: Spam slam Hello, Recently, it seems, we are getting inundated with mail going to bogus addresses for our domain from bogus senders. Running MailScanner with postfix and SpamAssassin. Is there something I can do with Postfix to stop all of the garbage from being processed by MailScanner? I'd love to ban this stuff before it even hits the server. Many thanks in advance. James -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From ms-list at alexb.ch Tue Aug 14 18:13:39 2007 From: ms-list at alexb.ch (Alex Broens) Date: Tue Aug 14 18:13:45 2007 Subject: Off topic - AntiVirus accuracy competition In-Reply-To: <2e7e01c7de8d$fcf7ed10$f6e7c730$@swaney@fsl.com> References: <3376.62.150.152.226.1185292117.squirrel@webmail.baladia.gov.kw> <46C1C7EC.9020003@USherbrooke.ca> <2e7e01c7de8d$fcf7ed10$f6e7c730$@swaney@fsl.com> Message-ID: <46C1E2C3.8060403@alexb.ch> On 8/14/2007 6:13 PM, Stephen Swaney wrote: > This is definitely off topic but I know that many of you will be interested > in the results since which virus scanners to buy is an often discussed topic > here. A quote from the article in the link below will explain. > > "A rare AntiVirus accuracy competition was conducted at Linuxworld this > week, and the results should come as a blow to the paid antivirus industry. > Run by delegates from the untangle network gateway, the competition should > provide ammunition to critics of the idea that good virus protection cannot > be provided for nothing. . . ." > > http://www.builderau.com.au/blogs/byteclub/viewblogpost.htm?p=339270831 > > And the results: > > 1. Kaspersky (97.1%) > 2. ClamAV (91.4%) > 3. Norton (88.6%) > 4. F-Prot (85.7%), and > 4. Sophos (85.7%) > 6. McAfee (74.3%) > 7. SonicWall (54.3%) > 8. GlobalHauri (45.7%), and > 8. Fortinet (45.7%) > 10. Watchguard (2.9%) > > I hope none of you are using 6. or below. that list is missing: one above # 1: Nod32 :-) From list-mailscanner at linguaphone.com Tue Aug 14 18:27:13 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue Aug 14 18:27:18 2007 Subject: Spam slam In-Reply-To: <531F1E080638384C9623B00D71AA546D0502020D@exchange.musicreports.com> Message-ID: Yes use postfix's recipient verification. See http://www.postfix.org/ADDRESS_VERIFICATION_README.html Thats what I use and it works very well. > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of James D. > Parra > Sent: 14 August 2007 18:02 > To: 'mailscanner@lists.mailscanner.info' > Subject: Spam slam > > > Hello, > > Recently, it seems, we are getting inundated with mail going to bogus > addresses for our domain from bogus senders. Running MailScanner with > postfix and SpamAssassin. Is there something I can do with Postfix to stop > all of the garbage from being processed by MailScanner? I'd love > to ban this > stuff before it even hits the server. > > Many thanks in advance. > > James > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > From ja at conviator.com Tue Aug 14 19:00:45 2007 From: ja at conviator.com (Jan Agermose) Date: Tue Aug 14 19:01:17 2007 Subject: rule against this? Message-ID: <6B59FCF2EFD0334A8147A1BB463F111E02AE688D@mail-17ps.atlarge.net> Hi We are getting really really many emails that look like this the last 48 hours or so: T+h+i-s Tu_esday i-t-s CYTV!!*! G+e.t on C*Y_T,V Firs t T+hing on TU-ES_DAY, i t'''s goi+ng to e_xpload! Compan *y: C_HINA YOUT*V C'O'R.P ( O,T'C BB:CYTV..O'B) Symb'ol: C,Y+T*V Curr-ent Price.: $_0+.,4-6 Mond ay M_ove: (+U.p Over(12'.2*0%) T*h,e pric'e is at a minim*um it w.i l'l b-o*o_m on Tues'day! Re'com,mendation: "S'TRONG-B+UY" star+tin.g on T+uesday*, AUGU+ST 1+4,, 2 0_0*6'. The above is only a part of the mail and it seams non of the mails are so much alike that they are marked as spam by the bayes system. I've tried to feed a few 100 of them but for every one of them SA Learn says "learned tokens from 1 message" (so I guess its not seen before?) and also it does not seam to have any effect on the ability to block new mails. Anyway - I was thinking that maybe someone had written a rule to block mails like this? Best regards Jan From hvdkooij at vanderkooij.org Tue Aug 14 19:27:19 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Tue Aug 14 19:27:27 2007 Subject: Yum/RPM install In-Reply-To: <46C0A275.8050806@ecs.soton.ac.uk> References: <46C0A275.8050806@ecs.soton.ac.uk> Message-ID: On Mon, 13 Aug 2007, Julian Field wrote: > You say "with source" near the end of your comment. Do you mean "with > builds from source (i.e. same as installing via CPAN)" or do you mean > "with SRPMs"? > > Any RPM-based distro of ClamAV+SA I did would involve SRPMs for all the > Perl stuff anyway, I refuse to distribute RPMs of Perl modules as they > make no sense for exactly the reasons you have described. I think I mentioned this in the past but on both Centos 4 and Centos 5 I was able to install everything I neede through yum except MS itself. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From list-mailscanner at linguaphone.com Tue Aug 14 19:28:45 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue Aug 14 19:28:50 2007 Subject: rule against this? In-Reply-To: <6B59FCF2EFD0334A8147A1BB463F111E02AE688D@mail-17ps.atlarge.net> Message-ID: The chickenpox rules work well against those emails. So do the new rules which come as standard in spamassassin 3.2. > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Jan > Agermose > Sent: 14 August 2007 19:01 > To: MailScanner discussion > Subject: rule against this? > > > Hi > > We are getting really really many emails that look like this the last 48 > hours or so: > > T+h+i-s Tu_esday i-t-s CYTV!!*! > G+e.t on C*Y_T,V Firs t T+hing on TU-ES_DAY, i t'''s goi+ng to e_xpload! > > Compan *y: C_HINA YOUT*V C'O'R.P ( O,T'C BB:CYTV..O'B) > Symb'ol: C,Y+T*V > Curr-ent Price.: $_0+.,4-6 > Mond ay M_ove: (+U.p Over(12'.2*0%) > T*h,e pric'e is at a minim*um it w.i l'l b-o*o_m on Tues'day! > Re'com,mendation: "S'TRONG-B+UY" star+tin.g on T+uesday*, AUGU+ST 1+4,, > 2 0_0*6'. > > The above is only a part of the mail and it seams non of the mails are > so much alike that they are marked as spam by the bayes system. I've > tried to feed a few 100 of them but for every one of them SA Learn says > "learned tokens from 1 message" (so I guess its not seen before?) and > also it does not seam to have any effect on the ability to block new > mails. > > Anyway - I was thinking that maybe someone had written a rule to block > mails like this? > > Best regards > Jan > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > From MailScanner at ecs.soton.ac.uk Tue Aug 14 19:42:33 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 14 19:43:05 2007 Subject: Blocked Extensions in password-protected zip archives In-Reply-To: References: Message-ID: <46C1F799.30304@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 So what you want is this: Check Filenames In Password-Protected Archives = no for some users, yes for most. Correct? This is not too difficult to add. Sattler, Tim wrote: > We need to allow password-protected zip archives that contain files with > > blocked extensions for certain users. However, if "Maximum Archive > Depth" > is set to anything bigger than zero, then, even if "Allow > Password-Protected Archives" is set to "yes", the archive will be > blocked. > > Thus, I would need something like a ruleset for Maximum Archive Depth > that > yields 0 for password-protected archives and the default value > otherwise. > > Is it possible? Or is there another way how I can achieve a different > handling of blocked extensions for password-protected on one hand and > normal zip archives on the other? > > Regards > Tim > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGwfeZEfZZRxQVtlQRAi1mAJ4rxU90yx5HqmBG4OHO6Rn9ZE9XuQCg6YOg 8bW+OA5qlZiWixo3dPpxb5Q= =Qg+Q -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From raymond at prolocation.net Tue Aug 14 19:56:11 2007 From: raymond at prolocation.net (Raymond Dijkxhoorn) Date: Tue Aug 14 19:56:09 2007 Subject: Spam slam In-Reply-To: <531F1E080638384C9623B00D71AA546D0502020D@exchange.musicreports.com> References: <531F1E080638384C9623B00D71AA546D0502020D@exchange.musicreports.com> Message-ID: Hi! > Recently, it seems, we are getting inundated with mail going to bogus > addresses for our domain from bogus senders. Running MailScanner with > postfix and SpamAssassin. Is there something I can do with Postfix to stop > all of the garbage from being processed by MailScanner? I'd love to ban this > stuff before it even hits the server. > > Many thanks in advance. Then configure your mailserver to not accept them in the first place, remove catchall's and so... Bye, Raymond. From ssilva at sgvwater.com Tue Aug 14 19:58:36 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue Aug 14 19:58:59 2007 Subject: Blocked Extensions in password-protected zip archives In-Reply-To: References: Message-ID: Sattler, Tim spake the following on 8/14/2007 4:58 AM: > I have set "Allow Password-Protected Archives = yes", but encrypted > archives are nevertheless blocked if they contain files with blocked > extensions. > > Now I could set "Maximum Archive Depth = 0" to solve this issue, but > then files with blocked extensions would also pass in non-protected > archives, which is not what I want. > > Therefore, I would either need an option to disregard blocked > extensions within password-protected archives or the possibility to > use a ruleset for "Maximum Archive Depth" with a different result for > protected and non-protected archives. > > PS: I know it's an additional risk to let password-protected archives > pass through, but it's a business need. > > Regards > Tim > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Kai Schaetzl > Sent: Tuesday, August 14, 2007 12:32 PM > To: mailscanner@lists.mailscanner.info > Subject: Re: Blocked Extensions in password-protected zip archives > > Tim Sattler wrote on Tue, 14 Aug 2007 09:49:24 +0200: > >> Is it possible? Or is there another way how I can achieve a different >> handling of blocked extensions for password-protected on one hand and >> normal zip archives on the other? > > Are you sure this is a matter of "blocked extensions"? I rather think this > is a matter of "password-protected archive". MailScanner treats > password-protected archives as viruses. It would need to stop that. This > topic has come up regularly in the past, but Julian is reluctant to do > this. The effect of handling it as a virus is that it doesn't get saved to > the quarantine (if you keep it "clean") and thus can't be released. > > If you want to have all password-protected archives just pass thru > directly in the inboxes then set > Allow Password-Protected Archives = yes > but this will also allow password-protected archives with malware right in > the inbox. > > Kai > Why not use a ruleset on both allow password protected archives and maximum archive depth. A PITA to maintain, but more secure. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From MailScanner at ecs.soton.ac.uk Tue Aug 14 20:00:20 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 14 20:00:53 2007 Subject: TNEF Question In-Reply-To: <8072BCAE-023A-41D4-8E56-00C3CA14ADFF@csolve.net> References: <8072BCAE-023A-41D4-8E56-00C3CA14ADFF@csolve.net> Message-ID: <46C1FBC4.8070800@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 What version are you running? I can't find that line of code. Derek Buttineau wrote: > Just curious, but is there any reason not to skip the body attachment > in the TNEF archive when doing expansion? Looking at TNEF.pm, it > looks like all I'd have to do is uncomment line 292: > > #next if /^msg[\d-]+\.txt$/; > > Is there any danger in doing this that I might not be accounting for? > > Thanks > > -- > Regards, > > Derek Buttineau > Internet Systems Developer > Compu-SOLVE Internet Services > Compu-SOLVE Technologies, Inc > > Phone: 705-725-1212 x255 > E-Mail: derek@csolve.net > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGwfvFEfZZRxQVtlQRApiiAKCfbnQ6zLpgK6cVcysiSVsPoWrREgCg1dgh hEHxLLyLGwQ3+1PC5qEhpoE= =aRYR -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From maillists at conactive.com Tue Aug 14 20:31:23 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Tue Aug 14 20:31:26 2007 Subject: Yum/RPM install In-Reply-To: References: <46C0A275.8050806@ecs.soton.ac.uk> Message-ID: Hugo van der Kooij wrote on Tue, 14 Aug 2007 20:27:19 +0200 (CEST): > I think I mentioned this in the past but on both Centos 4 and Centos 5 I > was able to install everything I neede through yum except MS itself. I remember I did the same on Centos 4, but I think there were one or two missing from rpmforge or other trusted sources that I installed from Julian's rpm file. I usually unpack his big package and then use only what I need. I'm going to install on Centos 5 soon, will see how I come along. A single MailScanner-only package, be it rpm download or on a yum repo, would be nice. As much as I understand that Julian packages everything together for beginners I prefer having separate packages in case I have to fix something. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From derek at csolve.net Tue Aug 14 20:33:07 2007 From: derek at csolve.net (Derek Buttineau) Date: Tue Aug 14 20:33:20 2007 Subject: TNEF Question In-Reply-To: <46C1FBC4.8070800@ecs.soton.ac.uk> References: <8072BCAE-023A-41D4-8E56-00C3CA14ADFF@csolve.net> <46C1FBC4.8070800@ecs.soton.ac.uk> Message-ID: <80FB635B-B7EF-4A09-A1D1-3513F3F4E680@csolve.net> On 2007-Aug-14, at 3:00 PM, Julian Field wrote: > What version are you running? I can't find that line of code. Version 4.61.7 Here's what I'm showing as the replacement loop (line 288 -> 303): 288 while (defined($_ = $dirh->read)) { 289 #print STDERR "Directory entry is \"$_\" in \"$dir\"\n"; 290 next unless -f "$dir/$_"; 291 next if $_ eq $tnefname; 292 #next if /^msg[\d-]+\.txt$/; 293 $safename = $message->MakeNameSafe($_, $dir); 294 if (/^msg[\d-]+\.txt$/) { 295 ($type, $encoding) = ("text/plain", "8bit"); 296 } else { 297 ($type, $encoding) = ("application/octet-stream", "base64"); 298 if ($safename ne $_ && -f "$dir/$_") { 299 #print STDERR "Renaming '$dir/$_' to '$dir/$safename'\n"; 300 my $dangerous = quotemeta $_; 301 rename "$dir/$dangerous", "$dir/$safename"; 302 } 303 } From what I've read, it should be safe/sane to ignore the msg text file as it's the body content from the TNEF which will/should already be inline (in plain text) in the message, but just wanted to double check. -- Regards, Derek Buttineau Internet Systems Developer Compu-SOLVE Internet Services Compu-SOLVE Technologies, Inc Phone: 705-725-1212 x255 E-Mail: derek@csolve.net From ja at conviator.com Tue Aug 14 20:37:12 2007 From: ja at conviator.com (Jan Agermose) Date: Tue Aug 14 20:37:41 2007 Subject: SV: rule against this? In-Reply-To: References: <6B59FCF2EFD0334A8147A1BB463F111E02AE688D@mail-17ps.atlarge.net> Message-ID: <6B59FCF2EFD0334A8147A1BB463F111E02AE68F3@mail-17ps.atlarge.net> Aaaahhhh, THANKS! Great, takes all allready. (well, and some code related maillinglists :-) ) http://www.rulesemporium.com/rules/chickenpox.cf Mvh Jan -----Oprindelig meddelelse----- Fra: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] P? vegne af Gareth Sendt: 14. august 2007 20:29 Til: MailScanner discussion Emne: RE: rule against this? The chickenpox rules work well against those emails. So do the new rules which come as standard in spamassassin 3.2. > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Jan > Agermose > Sent: 14 August 2007 19:01 > To: MailScanner discussion > Subject: rule against this? > > > Hi > > We are getting really really many emails that look like this the last 48 > hours or so: > > T+h+i-s Tu_esday i-t-s CYTV!!*! > G+e.t on C*Y_T,V Firs t T+hing on TU-ES_DAY, i t'''s goi+ng to e_xpload! > > Compan *y: C_HINA YOUT*V C'O'R.P ( O,T'C BB:CYTV..O'B) > Symb'ol: C,Y+T*V > Curr-ent Price.: $_0+.,4-6 > Mond ay M_ove: (+U.p Over(12'.2*0%) > T*h,e pric'e is at a minim*um it w.i l'l b-o*o_m on Tues'day! > Re'com,mendation: "S'TRONG-B+UY" star+tin.g on T+uesday*, AUGU+ST 1+4,, > 2 0_0*6'. > > The above is only a part of the mail and it seams non of the mails are > so much alike that they are marked as spam by the bayes system. I've > tried to feed a few 100 of them but for every one of them SA Learn says > "learned tokens from 1 message" (so I guess its not seen before?) and > also it does not seam to have any effect on the ability to block new > mails. > > Anyway - I was thinking that maybe someone had written a rule to block > mails like this? > > Best regards > Jan > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From doc at maddoc.net Tue Aug 14 21:09:08 2007 From: doc at maddoc.net (Doc Schneider) Date: Tue Aug 14 21:09:18 2007 Subject: SV: rule against this? In-Reply-To: <6B59FCF2EFD0334A8147A1BB463F111E02AE68F3@mail-17ps.atlarge.net> References: <6B59FCF2EFD0334A8147A1BB463F111E02AE688D@mail-17ps.atlarge.net> <6B59FCF2EFD0334A8147A1BB463F111E02AE68F3@mail-17ps.atlarge.net> Message-ID: <46C20BE4.8070006@maddoc.net> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Jan Agermose wrote: > Aaaahhhh, THANKS! Great, takes all allready. (well, and some code related maillinglists :-) ) > > http://www.rulesemporium.com/rules/chickenpox.cf > > > Mvh > Jan You can always whitelist_rcvd or whitelist_spf mailing lists that those chickenpox rules hit. This rule set is not something that needs to be gotten more then once, also. There is no active development for it. I've used chickenpox since it was first released and it has always helped to push some spam just over the threshold. HTH, - -- - -Doc SARE Ninja Lincoln, NE. http://www.genealogyforyou.com/ http://www.cairnproductions.com/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (GNU/Linux) Comment: Using GnuPG with CentOS - http://enigmail.mozdev.org iD8DBQFGwgvkqOEeBwEpgcsRAs/wAJ45IGU0maIQf7eNJ9tfybJ7HIZ8RACfVvLJ dICsNoLcXDMCKyDs0TSwRNo= =126U -----END PGP SIGNATURE----- From Denis.Beauchemin at USherbrooke.ca Tue Aug 14 21:09:18 2007 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Tue Aug 14 21:09:36 2007 Subject: Spamassassin Greeting Card Question In-Reply-To: <46A8C642.3010201@fsl.com> References: <113A0DFC086C984AB9EFDF6B8614F075017D327C@exchange03.CBOCS.com> <46A8C0EB.6080006@ecs.soton.ac.uk> <46A8C642.3010201@fsl.com> Message-ID: <46C20BEE.9070208@USherbrooke.ca> Steve Freegard a ?crit : > Julian Field wrote: >> Err... your rules have to have different names. You can't give a >> bunch of rules the same name, or else how does it tell the difference >> between which rule score (and description) applies to which rule? > > And why don't you condense all these rules into a single rule? > > header CBGREET99 Subjet =~ /^You've received (?:a|an) > (?:greeting){0,1}\s{0,1}(?:e|post){0,1}card from a (?:.+)!$/ > score CBGREET99 99 > describe CBGREET99 Greeting card spam and virus > > Would probably work (untested). > > Cheers, > Steve. Hello all, I've noticed that Bitdefender has been catching these for 4-5 days: Generic.Peed.Eml.034E7EA8 I had to add the string "Generic.Peed.Eml" to %rules-dir%/virus.to.quarantine.rules so they would not fill my quarantine. Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x62252 F: 819.821.8045 From ssilva at sgvwater.com Tue Aug 14 21:12:48 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue Aug 14 21:13:09 2007 Subject: Mailscanner RBL checks In-Reply-To: References: <46BB6045.30809@syska.dk> <46BB6C55.3090607@cnpapers.com> <46C1D098.6080700@sendit.nodak.edu> Message-ID: Vlad Mazek spake the following on 8/14/2007 9:14 AM: > First thing I did :) There doesn't seem to be anything, not even > check_uridnsbl or anything even with the rbl pattern search. > > I am at a loss as to what is launching these queries but its sure > trashing this one site for some reason. > > -Vlad Are you running a caching nameserver on this box? It will help a lot -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From v at vladville.com Tue Aug 14 21:15:39 2007 From: v at vladville.com (Vlad Mazek) Date: Tue Aug 14 21:15:43 2007 Subject: Mailscanner RBL checks In-Reply-To: <46C1D938.5020301@sendit.nodak.edu> References: <46BB6045.30809@syska.dk> <46BB6C55.3090607@cnpapers.com> <46C1D098.6080700@sendit.nodak.edu> <46C1D938.5020301@sendit.nodak.edu> Message-ID: I looked in my SpamAssassin directory, /etc/mail/spamassassin I don't have a 20_dnsbl_tests.cf at all. (I've temporarily just set scores for those to 0 to disable them but would still like to get to the bottom of what is looking them up in the first place) -Vlad On 8/14/07, Richard Frovarp wrote: > > Where did you look? Have you found the two files I referenced? > > Vlad Mazek wrote: > > First thing I did :) There doesn't seem to be anything, not even > > check_uridnsbl or anything even with the rbl pattern search. > > > > I am at a loss as to what is launching these queries but its sure > > trashing this one site for some reason. > > > > -Vlad > > > > On 8/14/07, *Richard Frovarp* > > wrote: > > > > grep through the rules. URIBLs seem to be in 25_uribl.cf and > > DNSBLs seem > > to be in 20_dnsbl_tests.cf > > > > Vlad Mazek wrote: > > > Thing is, skip_rbl_checks =1 would skip them all, I just want to > > > restrict which ones are being queried. > > > > > > Here are the queries that are launched by MailScanner: > > > [2351] dbg: dns: URIBL_RED lookup start > > > [2351] dbg: dns: URIBL_GREY lookup start > > > [2351] dbg: dns: WHOIS_SECUREWHOIS lookup start > > > [2351] dbg: dns: WHOIS_MYPRIVREG lookup start > > > [2351] dbg: dns: WHOIS_NETSOLPR lookup start > > > [2351] dbg: dns: WHOIS_AITPRIV lookup start > > > [2351] dbg: dns: URIBL_SC_SURBL lookup start > > > [2351] dbg: dns: URIBL_AB_SURBL lookup start > > > [2351] dbg: dns: WHOIS_CONTACTPRIV lookup start > > > [2351] dbg: dns: WHOIS_NAMEKING lookup start > > > [2351] dbg: dns: WHOIS_PRIVPROT lookup start > > > [2351] dbg: dns: WHOIS_WHOISGUARD lookup start > > > [2351] dbg: dns: URIBL_PH_SURBL lookup start > > > [2351] dbg: dns: URIBL_BLACK lookup start > > > [2351] dbg: dns: WHOIS_PRIVACYPOST lookup start > > > [2351] dbg: dns: URIBL_RHS_DOB lookup start > > > [2351] dbg: dns: URIBL_JP_SURBL lookup start > > > [2351] dbg: dns: URIBL_WS_SURBL lookup start > > > [2351] dbg: dns: URIBL_OB_SURBL lookup start > > > [2351] dbg: dns: WHOIS_DMNBYPROXY lookup start > > > [2351] dbg: dns: WHOIS_REGISTERFLY lookup start > > > [2351] dbg: dns: WHOIS_UNLISTED lookup start > > > [2351] dbg: dns: WHOIS_MONIKER_PRIV lookup start > > > [2351] dbg: dns: URIBL_SBL lookup start > > > > > > How do I find out which rule/definition is causing all these > > lookups > > > to launch? > > > > > > -Vlad > > > > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- -Vlad -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070814/5d3c4f23/attachment.html From steinkel at pa.net Tue Aug 14 21:18:04 2007 From: steinkel at pa.net (Leland J. Steinke) Date: Tue Aug 14 21:18:16 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA0169FC0F@HC-MBX02.herefordshire.gov.uk> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info><24231931.14351186764822763.JavaMail.root@office.splatnix.net><8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> <8F2A53954C22554EB75D9643FCCE0C6B0472D462@MED-CORE03-MS1.med.wayne.edu> <7EF0EE5CB3B263488C8C18823239BEBA0169FC0F@HC-MBX02.herefordshire.gov.uk> Message-ID: <46C20DFC.4050607@pa.net> Randal, Phil wrote: > I'm getting very slow DNS lookups from combined-HIB.dnsiplists.completewhois.com. > > That might be a factor. > > Does using > > score __RCVD_IN_WHOIS 0 > score RCVD_IN_WHOIS_INVALID 0 > score URIBL_COMPLETEWHOIS 0 > > solve the performance problem? Much to my recent regret, I have avoided subscribing to any spamassassin support lists, opting instead to let all of you more adventurous types work out the bugs while I just implement what is recommended on the MS list. Would information such as the above be on the SA users list? Is there a FAQ with known "gotchas" with running SA (3.2.2 in our case), where this is listed? How in Perdition do you track that "combined-HIB.dnsiplists.completewhois.com." is slow? And it's only Tuesday! thanks, Leland From doc at maddoc.net Tue Aug 14 21:20:29 2007 From: doc at maddoc.net (Doc Schneider) Date: Tue Aug 14 21:20:38 2007 Subject: Mailscanner RBL checks In-Reply-To: References: <46BB6045.30809@syska.dk> <46BB6C55.3090607@cnpapers.com> <46C1D098.6080700@sendit.nodak.edu> <46C1D938.5020301@sendit.nodak.edu> Message-ID: <46C20E8D.3010503@maddoc.net> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Vlad Mazek wrote: > I looked in my SpamAssassin directory, /etc/mail/spamassassin > > I don't have a 20_dnsbl_tests.cf at all. > > (I've temporarily just set scores for those to 0 to disable them but > would still like to get to the bottom of what is looking them up in the > first place) > > -Vlad > > /etc/mail/spamassassin is for local rules, depending on what version you're using look in /var/lib/spamassassin/ there are different version directories under there. - -- - -Doc Lincoln, NE. http://www.genealogyforyou.com/ http://www.cairnproductions.com/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (GNU/Linux) Comment: Using GnuPG with CentOS - http://enigmail.mozdev.org iD8DBQFGwg6NqOEeBwEpgcsRAgVvAJ9KZwLFDD5QY+l/lmwLf+OzmfHpqgCgiMCL F2TKszjcBfzymp71RFmXr38= =gCWO -----END PGP SIGNATURE----- From v at vladville.com Tue Aug 14 21:22:32 2007 From: v at vladville.com (Vlad Mazek) Date: Tue Aug 14 21:22:36 2007 Subject: Mailscanner RBL checks In-Reply-To: References: <46BB6045.30809@syska.dk> <46BB6C55.3090607@cnpapers.com> <46C1D098.6080700@sendit.nodak.edu> Message-ID: Yep, but it does not make much difference until the load spikes. My queue processing (for 10 messages) is below 60 seconds. Not sure if thats good or bad but this is what the box averages with clamav and sa-update nightly. -Vlad On 8/14/07, Scott Silva wrote: > > Vlad Mazek spake the following on 8/14/2007 9:14 AM: > > First thing I did :) There doesn't seem to be anything, not even > > check_uridnsbl or anything even with the rbl pattern search. > > > > I am at a loss as to what is launching these queries but its sure > > trashing this one site for some reason. > > > > -Vlad > Are you running a caching nameserver on this box? > It will help a lot > > -- > > MailScanner is like deodorant... > You hope everybody uses it, and > you notice quickly if they don't!!!! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- -Vlad -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070814/735d77fe/attachment.html From v at vladville.com Tue Aug 14 21:24:23 2007 From: v at vladville.com (Vlad Mazek) Date: Tue Aug 14 21:24:28 2007 Subject: Mailscanner RBL checks In-Reply-To: <46C20E8D.3010503@maddoc.net> References: <46BB6045.30809@syska.dk> <46BB6C55.3090607@cnpapers.com> <46C1D098.6080700@sendit.nodak.edu> <46C1D938.5020301@sendit.nodak.edu> <46C20E8D.3010503@maddoc.net> Message-ID: So thaaaaaaaaaths where they hide :) Found it, thank you Doc! -Vlad On 8/14/07, Doc Schneider wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Vlad Mazek wrote: > > I looked in my SpamAssassin directory, /etc/mail/spamassassin > > > > I don't have a 20_dnsbl_tests.cf at all. > > > > (I've temporarily just set scores for those to 0 to disable them but > > would still like to get to the bottom of what is looking them up in the > > first place) > > > > -Vlad > > > > > > /etc/mail/spamassassin is for local rules, depending on what version > you're using look in /var/lib/spamassassin/ there are different version > directories under there. > > > > - -- > - -Doc > Lincoln, NE. > http://www.genealogyforyou.com/ > http://www.cairnproductions.com/ > > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.5 (GNU/Linux) > Comment: Using GnuPG with CentOS - http://enigmail.mozdev.org > > iD8DBQFGwg6NqOEeBwEpgcsRAgVvAJ9KZwLFDD5QY+l/lmwLf+OzmfHpqgCgiMCL > F2TKszjcBfzymp71RFmXr38= > =gCWO > -----END PGP SIGNATURE----- > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- -Vlad -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070814/1601ac40/attachment.html From doc at maddoc.net Tue Aug 14 21:30:33 2007 From: doc at maddoc.net (Doc Schneider) Date: Tue Aug 14 21:30:45 2007 Subject: Mailscanner RBL checks In-Reply-To: References: <46BB6045.30809@syska.dk> <46BB6C55.3090607@cnpapers.com> <46C1D098.6080700@sendit.nodak.edu> <46C1D938.5020301@sendit.nodak.edu> <46C20E8D.3010503@maddoc.net> Message-ID: <46C210E9.5060809@maddoc.net> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Vlad Mazek wrote: > So thaaaaaaaaaths where they hide :) > > Found it, thank you Doc! > > -Vlad Just make sure if you want to do a different score for them to do that in your /etc/mail/spamassassin/local.cf file, since those ones in /var/lib/spamassassin/ will be updated with an sa-update. But nice to be able to see what those dns rules look like eh? Welcome, > On 8/14/07, *Doc Schneider* > wrote: > > Vlad Mazek wrote: >> I looked in my SpamAssassin directory, /etc/mail/spamassassin > >> I don't have a 20_dnsbl_tests.cf at all. > >> (I've temporarily just set scores for those to 0 to disable them but >> would still like to get to the bottom of what is looking them up > in the >> first place) > >> -Vlad > > > > /etc/mail/spamassassin is for local rules, depending on what version > you're using look in /var/lib/spamassassin/ there are different version > directories under there. > > - -- - -Doc Lincoln, NE. http://www.genealogyforyou.com/ http://www.cairnproductions.com/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (GNU/Linux) Comment: Using GnuPG with CentOS - http://enigmail.mozdev.org iD8DBQFGwhDpqOEeBwEpgcsRAsGVAJ9OxHL+CEqIfnNBoxUqgJkW/NRtFACdFBmF B/AMIvfP851wQ9w7mV0MitU= =BPs9 -----END PGP SIGNATURE----- From ms-list at alexb.ch Tue Aug 14 21:30:54 2007 From: ms-list at alexb.ch (Alex Broens) Date: Tue Aug 14 21:31:04 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <46C20DFC.4050607@pa.net> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info><24231931.14351186764822763.JavaMail.root@office.splatnix.net><8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> <8F2A53954C22554EB75D9643FCCE0C6B0472D462@MED-CORE03-MS1.med.wayne.edu> <7EF0EE5CB3B263488C8C18823239BEBA0169FC0F@HC-MBX02.herefordshire.gov.uk> <46C20DFC.4050607@pa.net> Message-ID: <46C210FE.70700@alexb.ch> On 8/14/2007 10:18 PM, Leland J. Steinke wrote: > Randal, Phil wrote: >> I'm getting very slow DNS lookups from >> combined-HIB.dnsiplists.completewhois.com. >> >> That might be a factor. >> >> Does using >> score __RCVD_IN_WHOIS 0 >> score RCVD_IN_WHOIS_INVALID 0 >> score URIBL_COMPLETEWHOIS 0 >> >> solve the performance problem? > > Much to my recent regret, I have avoided subscribing to any spamassassin > support lists, opting instead to let all of you more adventurous types > work out the bugs while I just implement what is recommended on the MS > list. Would information such as the above be on the SA users list? Is > there a FAQ with known "gotchas" with running SA (3.2.2 in our case), > where this is listed? How in Perdition do you track that > "combined-HIB.dnsiplists.completewhois.com." is slow? watch your recursor's query logs? get the feeling after trial and error. The SA users list is an amazing source of interesting noise when you need SA knowledge. If you use SA as part of your job, its a must. Alex From hvdkooij at vanderkooij.org Tue Aug 14 21:49:21 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Tue Aug 14 21:49:29 2007 Subject: Off topic - AntiVirus accuracy competition In-Reply-To: <2e7e01c7de8d$fcf7ed10$f6e7c730$@swaney@fsl.com> References: <3376.62.150.152.226.1185292117.squirrel@webmail.baladia.gov.kw> <46C1C7EC.9020003@USherbrooke.ca> <2e7e01c7de8d$fcf7ed10$f6e7c730$@swaney@fsl.com> Message-ID: On Tue, 14 Aug 2007, Stephen Swaney wrote: > This is definitely off topic but I know that many of you will be interested > in the results since which virus scanners to buy is an often discussed topic > here. A quote from the article in the link below will explain. > > "A rare AntiVirus accuracy competition was conducted at Linuxworld this > week, and the results should come as a blow to the paid antivirus industry. > Run by delegates from the untangle network gateway, the competition should > provide ammunition to critics of the idea that good virus protection cannot > be provided for nothing. . . ." > > http://www.builderau.com.au/blogs/byteclub/viewblogpost.htm?p=339270831 > > And the results: > > 1. Kaspersky (97.1%) > 2. ClamAV (91.4%) > 3. Norton (88.6%) > 4. F-Prot (85.7%), and > 4. Sophos (85.7%) > 6. McAfee (74.3%) > 7. SonicWall (54.3%) > 8. GlobalHauri (45.7%), and > 8. Fortinet (45.7%) > 10. Watchguard (2.9%) > > I hope none of you are using 6. or below. Not quite like the results I get from a sample collection which covers about anything being around for first half of this year. I am rebuilding a malware crossrefernce and the new setup is at http://test.viruspool.net/ I plan to move it over to the main site after I rewrote the virus search page itself from scratch. The backend is good now but the webpage needs a full rewrite now to use the extended database in a much smarter way. The short summary? I find Kaspersky and F-Prot doing rather badly compared to the list you quote. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From MailScanner at ecs.soton.ac.uk Tue Aug 14 22:00:17 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 14 22:00:56 2007 Subject: TNEF Question In-Reply-To: <80FB635B-B7EF-4A09-A1D1-3513F3F4E680@csolve.net> References: <8072BCAE-023A-41D4-8E56-00C3CA14ADFF@csolve.net> <46C1FBC4.8070800@ecs.soton.ac.uk> <80FB635B-B7EF-4A09-A1D1-3513F3F4E680@csolve.net> Message-ID: <46C217E1.8070304@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 That code has changed quite a bit since then. I found a bug in the external TNEF decoder support code which I have fixed. Derek Buttineau wrote: > On 2007-Aug-14, at 3:00 PM, Julian Field wrote: > >> What version are you running? I can't find that line of code. > > Version 4.61.7 > > Here's what I'm showing as the replacement loop (line 288 -> 303): > > 288 while (defined($_ = $dirh->read)) { > 289 #print STDERR "Directory entry is \"$_\" in \"$dir\"\n"; > 290 next unless -f "$dir/$_"; > 291 next if $_ eq $tnefname; > 292 #next if /^msg[\d-]+\.txt$/; > 293 $safename = $message->MakeNameSafe($_, $dir); > 294 if (/^msg[\d-]+\.txt$/) { > 295 ($type, $encoding) = ("text/plain", "8bit"); > 296 } else { > 297 ($type, $encoding) = ("application/octet-stream", "base64"); > 298 if ($safename ne $_ && -f "$dir/$_") { > 299 #print STDERR "Renaming '$dir/$_' to '$dir/$safename'\n"; > 300 my $dangerous = quotemeta $_; > 301 rename "$dir/$dangerous", "$dir/$safename"; > 302 } > 303 } > > From what I've read, it should be safe/sane to ignore the msg text > file as it's the body content from the TNEF which will/should already > be inline (in plain text) in the message, but just wanted to double > check. > > -- > Regards, > > Derek Buttineau > Internet Systems Developer > Compu-SOLVE Internet Services > Compu-SOLVE Technologies, Inc > > Phone: 705-725-1212 x255 > E-Mail: derek@csolve.net > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGwhfiEfZZRxQVtlQRAlwuAJ9zFWEoF1F8Q+zP6TiIWtI09qHo7ACgyvca t1MudHM3EXVmEXXGRZ4CeWg= =gvOR -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From dave.list at pixelhammer.com Tue Aug 14 22:14:35 2007 From: dave.list at pixelhammer.com (DAve) Date: Tue Aug 14 22:15:57 2007 Subject: Off topic - AntiVirus accuracy competition In-Reply-To: References: <3376.62.150.152.226.1185292117.squirrel@webmail.baladia.gov.kw> <46C1C7EC.9020003@USherbrooke.ca> <2e7e01c7de8d$fcf7ed10$f6e7c730$@swaney@fsl.com> Message-ID: <46C21B3B.6010006@pixelhammer.com> Hugo van der Kooij wrote: > On Tue, 14 Aug 2007, Stephen Swaney wrote: > >> This is definitely off topic but I know that many of you will be >> interested >> in the results since which virus scanners to buy is an often discussed >> topic >> here. A quote from the article in the link below will explain. >> >> "A rare AntiVirus accuracy competition was conducted at Linuxworld this >> week, and the results should come as a blow to the paid antivirus >> industry. >> Run by delegates from the untangle network gateway, the competition >> should >> provide ammunition to critics of the idea that good virus protection >> cannot >> be provided for nothing. . . ." >> >> http://www.builderau.com.au/blogs/byteclub/viewblogpost.htm?p=339270831 >> >> And the results: >> >> 1. Kaspersky (97.1%) >> 2. ClamAV (91.4%) >> 3. Norton (88.6%) >> 4. F-Prot (85.7%), and >> 4. Sophos (85.7%) >> 6. McAfee (74.3%) >> 7. SonicWall (54.3%) >> 8. GlobalHauri (45.7%), and >> 8. Fortinet (45.7%) >> 10. Watchguard (2.9%) >> >> I hope none of you are using 6. or below. > > Not quite like the results I get from a sample collection which covers > about anything being around for first half of this year. I am rebuilding > a malware crossrefernce and the new setup is at http://test.viruspool.net/ > > I plan to move it over to the main site after I rewrote the virus search > page itself from scratch. The backend is good now but the webpage needs > a full rewrite now to use the extended database in a much smarter way. > > The short summary? I find Kaspersky and F-Prot doing rather badly > compared to the list you quote. > > Hugo. > Interesting, we tried Kas and BDC behind Clam for about 13 months and neither one caught anything, nothing slipped past Clam to be caught. So we dropped them when we needed the cycles for increased traffic. DAve -- Three years now I've asked Google why they don't have a logo change for Memorial Day. Why do they choose to do logos for other non-international holidays, but nothing for Veterans? Maybe they forgot who made that choice possible. From maillists at conactive.com Tue Aug 14 22:31:16 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Tue Aug 14 22:31:19 2007 Subject: rule against this? In-Reply-To: <46C20BE4.8070006@maddoc.net> References: <6B59FCF2EFD0334A8147A1BB463F111E02AE688D@mail-17ps.atlarge.net> <6B59FCF2EFD0334A8147A1BB463F111E02AE68F3@mail-17ps.atlarge.net> <46C20BE4.8070006@maddoc.net> Message-ID: Doc Schneider wrote on Tue, 14 Aug 2007 15:09:08 -0500: > I've used chickenpox since it was first released and it has always > helped to push some spam just over the threshold. But rarely as good as these new ones. It just looks like it was made specifically for them :-) Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From derek at csolve.net Tue Aug 14 22:39:01 2007 From: derek at csolve.net (Derek Buttineau) Date: Tue Aug 14 22:39:17 2007 Subject: TNEF Question In-Reply-To: <46C217E1.8070304@ecs.soton.ac.uk> References: <8072BCAE-023A-41D4-8E56-00C3CA14ADFF@csolve.net> <46C1FBC4.8070800@ecs.soton.ac.uk> <80FB635B-B7EF-4A09-A1D1-3513F3F4E680@csolve.net> <46C217E1.8070304@ecs.soton.ac.uk> Message-ID: <1283EEC7-B05C-4E99-BDEB-F90B38281576@csolve.net> On 2007-Aug-14, at 5:00 PM, Julian Field wrote: > That code has changed quite a bit since then. I found a bug in the > external TNEF decoder support code which I have fixed. Okay, I'll try an upgrade and go from there, need to investigate not attaching that text message body attachment. :) Thanks Julian -- Regards, Derek Buttineau Internet Systems Developer Compu-SOLVE Internet Services Compu-SOLVE Technologies, Inc Phone: 705-725-1212 x255 E-Mail: derek@csolve.net From Jamesp at MusicReports.com Tue Aug 14 22:40:40 2007 From: Jamesp at MusicReports.com (James D. Parra) Date: Tue Aug 14 22:40:53 2007 Subject: Spam slam Message-ID: <531F1E080638384C9623B00D71AA546D05020213@exchange.musicreports.com> Hi! > Recently, it seems, we are getting inundated with mail going to bogus > addresses for our domain from bogus senders. Running MailScanner with > postfix and SpamAssassin. Is there something I can do with Postfix to stop > all of the garbage from being processed by MailScanner? I'd love to ban this > stuff before it even hits the server. > > Many thanks in advance. Then configure your mailserver to not accept them in the first place, remove catchall's and so... ~~~~ I want to, but I am not sure how. What is the best way do this with Postfix on Suse? Thank you, ~James From seamus at rheelweb.co.nz Tue Aug 14 23:11:15 2007 From: seamus at rheelweb.co.nz (Seamus Allan) Date: Tue Aug 14 23:11:14 2007 Subject: Spam slam In-Reply-To: <531F1E080638384C9623B00D71AA546D05020213@exchange.musicreports.com> References: <531F1E080638384C9623B00D71AA546D05020213@exchange.musicreports.com> Message-ID: <46C22883.4090307@rheelweb.co.nz> An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070815/73692595/attachment.html From maillists at conactive.com Tue Aug 14 23:31:18 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Tue Aug 14 23:31:21 2007 Subject: Off topic - AntiVirus accuracy competition In-Reply-To: References: <3376.62.150.152.226.1185292117.squirrel@webmail.baladia.gov.kw> <46C1C7EC.9020003@USherbrooke.ca> <2e7e01c7de8d$fcf7ed10$f6e7c730$@swaney@fsl.com> Message-ID: Hugo van der Kooij wrote on Tue, 14 Aug 2007 22:49:21 +0200 (CEST): > The short summary? I find Kaspersky and F-Prot doing rather badly compared > to the list you quote. Hm, looking on your list and seeing the *very* bad result for F-Prot I would rather search for the glitch in *your* testing/data-mining procedure. It cannot be *that* bad - unless it's a well outdated product (is it?). A maverick like that usually indicates that something is wrong in the method or data, rather than in the product tested. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From steve.swaney at fsl.com Tue Aug 14 23:47:22 2007 From: steve.swaney at fsl.com (Stephen Swaney) Date: Tue Aug 14 23:46:22 2007 Subject: Off topic - AntiVirus accuracy competition In-Reply-To: References: <3376.62.150.152.226.1185292117.squirrel@webmail.baladia.gov.kw> <46C1C7EC.9020003@USherbrooke.ca> <2e7e01c7de8d$fcf7ed10$f6e7c730$@swaney@fsl.com> Message-ID: <312f01c7dec5$13be9850$3b3bc8f0$@swaney@fsl.com> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Kai Schaetzl > Sent: Tuesday, August 14, 2007 6:31 PM > To: mailscanner@lists.mailscanner.info > Subject: Re: Off topic - AntiVirus accuracy competition > > Hugo van der Kooij wrote on Tue, 14 Aug 2007 22:49:21 +0200 (CEST): > > > The short summary? I find Kaspersky and F-Prot doing rather badly > compared > > to the list you quote. > > Hm, looking on your list and seeing the *very* bad result for F-Prot I > would > rather search for the glitch in *your* testing/data-mining procedure. > It > cannot be *that* bad - unless it's a well outdated product (is it?). A > maverick like that usually indicates that something is wrong in the > method or > data, rather than in the product tested. > > Kai > Hey it's not my test. I just thought the article might be of interest to the list. You're all free to make your own decisions. I don't sell any virus scanners :) I know it was to me since we'll probably replace Sophos when it expires this fall. My personal feeling is that Sophos a bit expensive for the quality. That's been shown in several tests I've seen. All of the responses though have been of interest to me especially the ones that point out the flaws and virus scanners missing from the list. And always remember! the is never such a thing as an totally unbiased test :) Steve Steve Swaney steve@fsl.com www.fsl.com From doc at maddoc.net Tue Aug 14 23:53:06 2007 From: doc at maddoc.net (Doc Schneider) Date: Tue Aug 14 23:53:15 2007 Subject: rule against this? In-Reply-To: References: <6B59FCF2EFD0334A8147A1BB463F111E02AE688D@mail-17ps.atlarge.net> <6B59FCF2EFD0334A8147A1BB463F111E02AE68F3@mail-17ps.atlarge.net> <46C20BE4.8070006@maddoc.net> Message-ID: <46C23252.4030101@maddoc.net> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Kai Schaetzl wrote: > Doc Schneider wrote on Tue, 14 Aug 2007 15:09:08 -0500: > >> I've used chickenpox since it was first released and it has always >> helped to push some spam just over the threshold. > > But rarely as good as these new ones. It just looks like it was made > specifically for them :-) > > Kai > Actually it was written a long time ago for spam that had a similar pattern to it. But as with all things; "what goes around comes around" and Jennifer will be happy to know her rules are still kicking spams butt! 8*) - -- - -Doc Lincoln, NE. http://www.genealogyforyou.com/ http://www.cairnproductions.com/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (GNU/Linux) Comment: Using GnuPG with CentOS - http://enigmail.mozdev.org iD8DBQFGwjJSqOEeBwEpgcsRAqY7AKCAGoXi9j06g9UUbGWmjfbx3TLMbQCeMeCG dHNtBuHQLz97+dWEQBr43pE= =ck4u -----END PGP SIGNATURE----- From suporte at setinet.com.br Wed Aug 15 00:08:01 2007 From: suporte at setinet.com.br (suporte@setinet.com.br) Date: Wed Aug 15 00:08:17 2007 Subject: MailScanner: It could not analyze the message. Message-ID: <004901c7dec7$f6aefdb0$140aa8c0@fabiodepin> Hi friends I?m having problems with a filter in MailScanner. When MailScanner receive somes e-mails with one .txt attachment, it returns the message below: Subject:NoticeOtherInfected MailScanner: It could not analyze the message. Please, i dont know why this happen., and need some help to configure mailscanner.conf properly. Thanks -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070814/8f2f2f8c/attachment.html From itdept at fractalweb.com Wed Aug 15 05:56:02 2007 From: itdept at fractalweb.com (Chris Yuzik) Date: Wed Aug 15 05:56:17 2007 Subject: How to manually test an email? In-Reply-To: <1187095642.19264.3.camel@paul-laptop.sidlow.office-shadow.com> References: <1187095642.19264.3.camel@paul-laptop.sidlow.office-shadow.com> Message-ID: <46C28762.1040804@fractalweb.com> paul @ firespam wrote: > Hi, > > I've had quite a few random spams getting through my MailScanner servers > recently and I'd like to investigate a bit more... > > I have saved a spam email that got through as a txt file with the full > headers. > > How can I run this through MailScanner manually and see the output? > > I know I can do: > spamassassin -t < /tmp/email.txt > > but does this just do spamassassin checks or does it include the > MailScanner stuff too? Paul, I get a whopping 64.8 points: Content analysis details: (64.8 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 15 BAYES_99 BODY: Bayesian spam probability is 99 to 100% [score: 1.0000] 0.1 RDNS_NONE Delivered to trusted network by a host with no rDNS 4.0 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net [Blocked - see ] 3.5 FRT_PRICE BODY: ReplaceTags: Price 1.7 SARE_MLB_Stock5 BODY: Mentions stock symbol, tickers, or OTC. 0.6 J_CHICKENPOX_32 BODY: 3alpha-pock-2alpha 2.9 FRT_SYMBOL BODY: ReplaceTags: Symbol 0.6 J_CHICKENPOX_41 BODY: 4alpha-pock-1alpha 1.7 TVD_FUZZY_SYMBOL BODY: TVD_FUZZY_SYMBOL 0.6 J_CHICKENPOX_15 BODY: 1alpha-pock-5alpha 0.6 J_CHICKENPOX_43 BODY: 4alpha-pock-3alpha 0.6 J_CHICKENPOX_42 BODY: 4alpha-pock-2alpha 0.6 J_CHICKENPOX_33 BODY: 3alpha-pock-3alpha 0.6 J_CHICKENPOX_52 BODY: 5alpha-pock-2alpha 0.6 J_CHICKENPOX_25 BODY: 2alpha-pock-5alpha 0.6 J_CHICKENPOX_23 BODY: 2alpha-pock-3alpha 0.6 J_CHICKENPOX_14 BODY: 1alpha-pock-4alpha 0.6 J_CHICKENPOX_31 BODY: 3alpha-pock-1alpha 0.0 HS_INDEX_PARAM URI: Link contains a common tracker pattern. 0.0 HTML_MESSAGE BODY: HTML included in message 29 CRM114_CHECK CRM114: message is SPAM with crm114-score -146.7300 Hope this helps you. Cheers, Chris From hvdkooij at vanderkooij.org Wed Aug 15 06:48:20 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Wed Aug 15 06:48:28 2007 Subject: Off topic - AntiVirus accuracy competition In-Reply-To: References: <3376.62.150.152.226.1185292117.squirrel@webmail.baladia.gov.kw> <46C1C7EC.9020003@USherbrooke.ca> <2e7e01c7de8d$fcf7ed10$f6e7c730$@swaney@fsl.com> Message-ID: On Wed, 15 Aug 2007, Kai Schaetzl wrote: > Hugo van der Kooij wrote on Tue, 14 Aug 2007 22:49:21 +0200 (CEST): > >> The short summary? I find Kaspersky and F-Prot doing rather badly compared >> to the list you quote. > > Hm, looking on your list and seeing the *very* bad result for F-Prot I would > rather search for the glitch in *your* testing/data-mining procedure. It > cannot be *that* bad - unless it's a well outdated product (is it?). A > maverick like that usually indicates that something is wrong in the method or > data, rather than in the product tested. The main diffeence between the old setup and the new one is the amount of recent samples. One of the Vv partners gave me access to the raw collection of garbage they intercepted world wide. The old testing was against relative few recent samples. The last test batch was started on the 15th and for F-Prot it reported the following: Virus scanning report - 15 August 2007 @ 3:23 F-PROT ANTIVIRUS Program version: 4.6.8 Engine version: 3.16.16 VIRUS SIGNATURE FILES SIGN.DEF created 14 August 2007 SIGN2.DEF created 14 August 2007 MACRO.DEF created 14 August 2007 I find the results at least odd and am still looking into it myself to see if any snag is present. In the past I had to remove files that could kill some scanners.Something similar might be happening here. But 23MB of text makes up for a lot of reading to find deviations. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From hvdkooij at vanderkooij.org Wed Aug 15 07:06:46 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Wed Aug 15 07:06:56 2007 Subject: Off topic - AntiVirus accuracy competition In-Reply-To: <312f01c7dec5$13be9850$3b3bc8f0$@swaney@fsl.com> References: <3376.62.150.152.226.1185292117.squirrel@webmail.baladia.gov.kw> <46C1C7EC.9020003@USherbrooke.ca> <2e7e01c7de8d$fcf7ed10$f6e7c730$@swaney@fsl.com> <312f01c7dec5$13be9850$3b3bc8f0$@swaney@fsl.com> Message-ID: On Tue, 14 Aug 2007, Stephen Swaney wrote: > And always remember! > > the is never such a thing as an totally unbiased test :) Quit true. But the test is not a product I aimed for. Just a result that began to spring up after I wrote the database fillers to create a name comparison database. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From tim.sattler at nordcapital.com Wed Aug 15 08:15:19 2007 From: tim.sattler at nordcapital.com (Sattler, Tim) Date: Wed Aug 15 08:15:28 2007 Subject: Blocked Extensions in password-protected zip archives In-Reply-To: <46C1F799.30304@ecs.soton.ac.uk> References: <46C1F799.30304@ecs.soton.ac.uk> Message-ID: Julian Field wrote: > So what you want is this: > Check Filenames In Password-Protected Archives = no > for some users, yes for most. Exactly. You would do me a great favour if you could implement such an option. Regards Tim From martinh at solidstatelogic.com Wed Aug 15 08:44:12 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed Aug 15 08:44:37 2007 Subject: Off topic - AntiVirus accuracy competition In-Reply-To: <312f01c7dec5$13be9850$3b3bc8f0$@swaney@fsl.com> Message-ID: <63e41c53560b844dafabdfc64f75fdd0@solidstatelogic.com> Steve I was surprised buy Sophos low score on this. They are expensive, but there hit rate has always been very reliable. In fact whenever the desktop AV has missed something, I'll pop on Sophos and every time it's found the issue.... I think I'll treat this with a large pinch of salt.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Stephen Swaney > Sent: 14 August 2007 23:47 > To: 'MailScanner discussion' > Subject: RE: Off topic - AntiVirus accuracy competition > > > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Kai Schaetzl > > Sent: Tuesday, August 14, 2007 6:31 PM > > To: mailscanner@lists.mailscanner.info > > Subject: Re: Off topic - AntiVirus accuracy competition > > > > Hugo van der Kooij wrote on Tue, 14 Aug 2007 22:49:21 +0200 (CEST): > > > > > The short summary? I find Kaspersky and F-Prot doing rather badly > > compared > > > to the list you quote. > > > > Hm, looking on your list and seeing the *very* bad result for F-Prot I > > would > > rather search for the glitch in *your* testing/data-mining procedure. > > It > > cannot be *that* bad - unless it's a well outdated product (is it?). A > > maverick like that usually indicates that something is wrong in the > > method or > > data, rather than in the product tested. > > > > Kai > > > > Hey it's not my test. I just thought the article might be of interest to > the > list. You're all free to make your own decisions. I don't sell any virus > scanners :) > > I know it was to me since we'll probably replace Sophos when it expires > this > fall. My personal feeling is that Sophos a bit expensive for the quality. > That's been shown in several tests I've seen. > > All of the responses though have been of interest to me especially the > ones > that point out the flaws and virus scanners missing from the list. > > And always remember! > > the is never such a thing as an totally unbiased test :) > > Steve > > Steve Swaney > steve@fsl.com > www.fsl.com > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From glenn.steen at gmail.com Wed Aug 15 08:54:24 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 15 08:54:28 2007 Subject: How to manually test an email? In-Reply-To: <46C28762.1040804@fractalweb.com> References: <1187095642.19264.3.camel@paul-laptop.sidlow.office-shadow.com> <46C28762.1040804@fractalweb.com> Message-ID: <223f97700708150054u73beabaak41f9a9d0967969a8@mail.gmail.com> On 15/08/07, Chris Yuzik wrote: > paul @ firespam wrote: > > Hi, > > > > I've had quite a few random spams getting through my MailScanner servers > > recently and I'd like to investigate a bit more... > > > > I have saved a spam email that got through as a txt file with the full > > headers. > > > > How can I run this through MailScanner manually and see the output? > > > > I know I can do: > > spamassassin -t < /tmp/email.txt > > > > but does this just do spamassassin checks or does it include the > > MailScanner stuff too? > > Paul, > > I get a whopping 64.8 points: > (snip) > 29 CRM114_CHECK CRM114: message is SPAM with crm114-score > -146.7300 That is what crm114 does to your scoring... It will be (more or less) the sole decision maker, making all the other SA stuff a vast degree less relevant. That might be fine, provided you trust it (CRM114) implicitly... But uf you don't, use a more ... lenient... multiplication factor, or even fixed scores. > Hope this helps you. > > Cheers, > Chris Cheers to you too Chris -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Wed Aug 15 09:44:30 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 15 09:44:32 2007 Subject: Spam slam In-Reply-To: <531F1E080638384C9623B00D71AA546D05020213@exchange.musicreports.com> References: <531F1E080638384C9623B00D71AA546D05020213@exchange.musicreports.com> Message-ID: <223f97700708150144o6d4749b3je1e0095e4254c10c@mail.gmail.com> On 14/08/07, James D. Parra wrote: > > > Hi! > > > Recently, it seems, we are getting inundated with mail going to bogus > > addresses for our domain from bogus senders. Running MailScanner with > > postfix and SpamAssassin. Is there something I can do with Postfix to stop > > all of the garbage from being processed by MailScanner? I'd love to ban > this > > stuff before it even hits the server. > > > > Many thanks in advance. > > Then configure your mailserver to not accept them in the first place, > remove catchall's and so... > > ~~~~ > > I want to, but I am not sure how. What is the best way do this with Postfix > on Suse? > > Thank you, > > ~James You basically have two options: 1) Do as Gareth suggests and use the recipient address verification as described (very well) in that link... 2) Use your *_recipient_maps (depends on your setup... if you are a GW that relay everything, if you do local delivery ... which map to use. I relay everything from the outside on in, so I use the relay_recipient_maps thing), build a simple file where you list something like "address1@example.net 1" on each line, postmap that ... and you're good to go. There is an administrative overhead here, but ... scripting and cron are (as always:) your firends...;-) For another take on all this, you might want to look at the MS wiki page: http://wiki.mailscanner.info/doku.php?id=documentation:configuration:mta:postfix:how_to:reject_non_existent_users Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Wed Aug 15 09:55:35 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 15 09:55:38 2007 Subject: Off topic - AntiVirus accuracy competition In-Reply-To: <63522809807132897@unknownmsgid> References: <3376.62.150.152.226.1185292117.squirrel@webmail.baladia.gov.kw> <46C1C7EC.9020003@USherbrooke.ca> <63522809807132897@unknownmsgid> Message-ID: <223f97700708150155r450f87bat4e5ff277ea3fafd9@mail.gmail.com> On 14/08/07, Stephen Swaney wrote: (snip) > I hope none of you are using 6. or below. > Not alone, no. As with all tests like these... One has to question methodology, corpus etc etc. The paid "giants" have been playing this kind of game (with the aid of "unbiased" magazines, institutes etc etc) for ages. Although the numbers say something, they are (usually) pretty far from the whole, complete, truth. So, say this instead: Hope none of you are only using one method of defence, but actually spend time or money on getting at least a couple, possibly more, antivirus products. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Wed Aug 15 09:58:59 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 15 09:59:03 2007 Subject: Off topic - AntiVirus accuracy competition In-Reply-To: <8974304841991812977@unknownmsgid> References: <3376.62.150.152.226.1185292117.squirrel@webmail.baladia.gov.kw> <46C1C7EC.9020003@USherbrooke.ca> <8974304841991812977@unknownmsgid> Message-ID: <223f97700708150158k1b325c6dt9dd2cdf0915b2411@mail.gmail.com> On 15/08/07, Stephen Swaney wrote: > (snip) > And always remember! > > the is never such a thing as an totally unbiased test :) Exactly. -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Wed Aug 15 10:04:09 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 15 10:04:10 2007 Subject: Off topic - AntiVirus accuracy competition In-Reply-To: <63e41c53560b844dafabdfc64f75fdd0@solidstatelogic.com> References: <63e41c53560b844dafabdfc64f75fdd0@solidstatelogic.com> Message-ID: <223f97700708150204u17383910uf214bd71c7f78aa6@mail.gmail.com> On 15/08/07, Martin.Hepworth wrote: > Steve > > I was surprised buy Sophos low score on this. They are expensive, but there hit rate has always been very reliable. In fact whenever the desktop AV has missed something, I'll pop on Sophos and every time it's found the issue.... > > I think I'll treat this with a large pinch of salt.. > Yes, quite. I think the only really nice result on that list is the ClamAV one ... Since ClamAV lacks commercial backing, and have no really workable client computer component (meaning windoze IF:-), it is often omitted from ... these kinds of tests. But then, we already knew that it is superior value for money, now didn't we;-). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From maillists at conactive.com Wed Aug 15 10:31:16 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Wed Aug 15 10:31:18 2007 Subject: Off topic - AntiVirus accuracy competition In-Reply-To: <312f01c7dec5$13be9850$3b3bc8f0$@swaney@fsl.com> References: <3376.62.150.152.226.1185292117.squirrel@webmail.baladia.gov.kw> <46C1C7EC.9020003@USherbrooke.ca> <2e7e01c7de8d$fcf7ed10$f6e7c730$@swaney@fsl.com> <312f01c7dec5$13be9850$3b3bc8f0$@swaney@fsl.com> Message-ID: Stephen Swaney wrote on Tue, 14 Aug 2007 18:47:22 -0400: > Hey it's not my test. and I did not reply to you ;-) Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From prandal at herefordshire.gov.uk Wed Aug 15 10:37:48 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Wed Aug 15 10:37:54 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <46C20DFC.4050607@pa.net> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info><24231931.14351186764822763.JavaMail.root@office.splatnix.net><8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> <8F2A53954C22554EB75D9643FCCE0C6B0472D462@MED-CORE03-MS1.med.wayne.edu><7EF0EE5CB3B263488C8C18823239BEBA0169FC0F@HC-MBX02.herefordshire.gov.uk> <46C20DFC.4050607@pa.net> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA0169FCBF@HC-MBX02.herefordshire.gov.uk> Running spamassassin -D -t reveals a lot. I'm running SA with the patch from http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5589 and the debug output made that one pretty obvious. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Leland J. Steinke > Sent: 14 August 2007 21:18 > To: MailScanner discussion > Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 > and 3.2.3 > > Randal, Phil wrote: > > I'm getting very slow DNS lookups from > combined-HIB.dnsiplists.completewhois.com. > > > > That might be a factor. > > > > Does using > > > > score __RCVD_IN_WHOIS 0 > > score RCVD_IN_WHOIS_INVALID 0 > > score URIBL_COMPLETEWHOIS 0 > > > > solve the performance problem? > > Much to my recent regret, I have avoided subscribing to any > spamassassin > support lists, opting instead to let all of you more > adventurous types > work out the bugs while I just implement what is recommended > on the MS > list. Would information such as the above be on the SA users > list? Is > there a FAQ with known "gotchas" with running SA (3.2.2 in our case), > where this is listed? How in Perdition do you track that > "combined-HIB.dnsiplists.completewhois.com." is slow? > > And it's only Tuesday! > > > thanks, > Leland > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From maillists at conactive.com Wed Aug 15 11:51:34 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Wed Aug 15 11:51:37 2007 Subject: rule against this? In-Reply-To: <46C23252.4030101@maddoc.net> References: <6B59FCF2EFD0334A8147A1BB463F111E02AE688D@mail-17ps.atlarge.net> <6B59FCF2EFD0334A8147A1BB463F111E02AE68F3@mail-17ps.atlarge.net> <46C20BE4.8070006@maddoc.net> <46C23252.4030101@maddoc.net> Message-ID: Doc Schneider wrote on Tue, 14 Aug 2007 17:53:06 -0500: > Actually it was written a long time ago I know, I know, am using it since it was available :-) But I almost never saw it hit more than a few times if ever. Already contemplated several times to finally remove it. But this kind of spam usually doesn't make it to my SA, anyway, so it doesn't have a real chance to prove it's usefulness ... Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Wed Aug 15 11:51:34 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Wed Aug 15 11:51:41 2007 Subject: Off topic - AntiVirus accuracy competition In-Reply-To: References: <3376.62.150.152.226.1185292117.squirrel@webmail.baladia.gov.kw> <46C1C7EC.9020003@USherbrooke.ca> <2e7e01c7de8d$fcf7ed10$f6e7c730$@swaney@fsl.com> Message-ID: Hugo van der Kooij wrote on Wed, 15 Aug 2007 07:48:20 +0200 (CEST): > I find the results at least odd and am still looking into it myself to see > if any snag is present. As I suggested it might "just" be an old engine (although it is the newest available). Signature files are not everything, especially not with new viruses. I looked at the F-Prot site and they offer version 6 for Windows. That may not indicate anything, but could also mean that they are way behind on Linux or at least have two very different engines. I see that the free Linux version for Home users and the paid version no.s are the same, so there is no difference. The reason for this bad performance doesn't matter, of course, if it is really on F-Prot's side. > I find the results at least odd That's what I wanted to stress :-) > In the past I had to remove files that could kill > some scanners. Hm, shouldn't happen as this could also happen in real production. If it gulps on some files this is a clear bug. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From MailScanner at ecs.soton.ac.uk Wed Aug 15 12:06:29 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 15 12:07:35 2007 Subject: Blocked Extensions in password-protected zip archives In-Reply-To: References: <46C1F799.30304@ecs.soton.ac.uk> Message-ID: <46C2DE35.4060200@ecs.soton.ac.uk> Sattler, Tim wrote: > Julian Field wrote: > >> So what you want is this: >> Check Filenames In Password-Protected Archives = no >> for some users, yes for most. >> > > Exactly. You would do me a great favour if you could implement such > an option. > Done. It will be in the next release, which should be available soon. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From glenn.steen at gmail.com Wed Aug 15 12:08:00 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 15 12:08:04 2007 Subject: Spamassassin Greeting Card Question In-Reply-To: <46C20BEE.9070208@USherbrooke.ca> References: <113A0DFC086C984AB9EFDF6B8614F075017D327C@exchange03.CBOCS.com> <46A8C0EB.6080006@ecs.soton.ac.uk> <46A8C642.3010201@fsl.com> <46C20BEE.9070208@USherbrooke.ca> Message-ID: <223f97700708150408r2c72c1e0y8d4be906fb2c4528@mail.gmail.com> On 14/08/07, Denis Beauchemin wrote: > Steve Freegard a ?crit : > > Julian Field wrote: > >> Err... your rules have to have different names. You can't give a > >> bunch of rules the same name, or else how does it tell the difference > >> between which rule score (and description) applies to which rule? > > > > And why don't you condense all these rules into a single rule? > > > > header CBGREET99 Subjet =~ /^You've received (?:a|an) > > (?:greeting){0,1}\s{0,1}(?:e|post){0,1}card from a (?:.+)!$/ > > score CBGREET99 99 > > describe CBGREET99 Greeting card spam and virus > > > > Would probably work (untested). > > > > Cheers, > > Steve. > Hello all, > > I've noticed that Bitdefender has been catching these for 4-5 days: > Generic.Peed.Eml.034E7EA8 > > I had to add the string "Generic.Peed.Eml" to > %rules-dir%/virus.to.quarantine.rules so they would not fill my quarantine. > > Denis > Hi Denis, glad to hear your vacation was OK (from the other thread)... These had a short spat of only BDC catching them, here... Then ClamAV kicked in, catching a lot more like: Report: ClamAV Module: message was infected: Email.Ecard-27 Report: Bitdefender: Found virus Generic.Peed.Eml.08371AF0 in file msg-8564-41.txt ... Yes, I use the new-ish "Clamav Full Message Scan = yes" thing. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From brose at med.wayne.edu Wed Aug 15 12:14:08 2007 From: brose at med.wayne.edu (Rose, Bobby) Date: Wed Aug 15 12:14:17 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA0169FCBF@HC-MBX02.herefordshire.gov.uk> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info><24231931.14351186764822763.JavaMail.root@office.splatnix.net><8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu> <8F2A53954C22554EB75D9643FCCE0C6B0472D462@MED-CORE03-MS1.med.wayne.edu><7EF0EE5CB3B263488C8C18823239BEBA0169FC0F@HC-MBX02.herefordshire.gov.uk><46C20DFC.4050607@pa.net> <7EF0EE5CB3B263488C8C18823239BEBA0169FCBF@HC-MBX02.herefordshire.gov.uk> Message-ID: <8F2A53954C22554EB75D9643FCCE0C6B0472D46E@MED-CORE03-MS1.med.wayne.edu> Yeh that might be it. I checked the changelog and saw that the DNS changes were the only real big change between 3.2.1. and 3.2.2 so what I did was installed 3.2.3 and replaced the Dns.pm with the version from 3.2.1. I'll know if that is the problem lies there later on today as traffic load increases. I grepped my logs from between the versions focusing on batches of 30 and I clearly see differences of 100 to 150 secs between 3.2.1 and the later versions. If anyone wants to check their times use this egrep -e"Batch \(30 messages\) processed in" maillog -=B -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Randal, Phil Sent: Wednesday, August 15, 2007 5:38 AM To: MailScanner discussion Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 Running spamassassin -D -t reveals a lot. I'm running SA with the patch from http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5589 and the debug output made that one pretty obvious. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of > Leland J. Steinke > Sent: 14 August 2007 21:18 > To: MailScanner discussion > Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and > 3.2.3 > > Randal, Phil wrote: > > I'm getting very slow DNS lookups from > combined-HIB.dnsiplists.completewhois.com. > > > > That might be a factor. > > > > Does using > > > > score __RCVD_IN_WHOIS 0 > > score RCVD_IN_WHOIS_INVALID 0 > > score URIBL_COMPLETEWHOIS 0 > > > > solve the performance problem? > > Much to my recent regret, I have avoided subscribing to any > spamassassin support lists, opting instead to let all of you more > adventurous types work out the bugs while I just implement what is > recommended on the MS list. Would information such as the above be on > the SA users list? Is there a FAQ with known "gotchas" with running > SA (3.2.2 in our case), where this is listed? How in Perdition do you > track that "combined-HIB.dnsiplists.completewhois.com." is slow? > > And it's only Tuesday! > > > thanks, > Leland > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From prandal at herefordshire.gov.uk Wed Aug 15 12:28:42 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Wed Aug 15 12:28:58 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B0472D46E@MED-CORE03-MS1.med.wayne.edu> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info><24231931.14351186764822763.JavaMail.root@office.splatnix.net><8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu><8F2A53954C22554EB75D9643FCCE0C6B0472D462@MED-CORE03-MS1.med.wayne.edu><7EF0EE5CB3B263488C8C18823239BEBA0169FC0F@HC-MBX02.herefordshire.gov.uk><46C20DFC.4050607@pa.net><7EF0EE5CB3B263488C8C18823239BEBA0169FCBF@HC-MBX02.herefordshire.gov.uk> <8F2A53954C22554EB75D9643FCCE0C6B0472D46E@MED-CORE03-MS1.med.wayne.edu> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA0169FD35@HC-MBX02.herefordshire.gov.uk> Oh, I would have tried 3.2.3 with the aforementioned patch to see if that made a difference too, because that patch will end up in 3.2.4. Is there any chance that you can do that? The patch affects more than DNS.pm, though. If there's still an issue on 3.2.3 with the patch from bug 5589 then you should add a note to that bug and raise the issue on the Spamassassin Users mailing list too. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Rose, Bobby > Sent: 15 August 2007 12:14 > To: MailScanner discussion > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 > and 3.2.3 > > Yeh that might be it. I checked the changelog and saw that the DNS > changes were the only real big change between 3.2.1. and > 3.2.2 so what I > did was installed 3.2.3 and replaced the Dns.pm with the version from > 3.2.1. I'll know if that is the problem lies there later on today as > traffic load increases. > > I grepped my logs from between the versions focusing on batches of 30 > and I clearly see differences of 100 to 150 secs between 3.2.1 and the > later versions. If anyone wants to check their times use this > egrep -e"Batch \(30 messages\) processed in" maillog > > -=B > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Randal, > Phil > Sent: Wednesday, August 15, 2007 5:38 AM > To: MailScanner discussion > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 > and 3.2.3 > > Running spamassassin -D -t reveals a lot. > > I'm running SA with the patch from > > http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5589 > > and the debug output made that one pretty obvious. > > Cheers, > > Phil > > -- > Phil Randal > Network Engineer > Herefordshire Council > Hereford, UK > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of > > Leland J. Steinke > > Sent: 14 August 2007 21:18 > > To: MailScanner discussion > > Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and > > 3.2.3 > > > > Randal, Phil wrote: > > > I'm getting very slow DNS lookups from > > combined-HIB.dnsiplists.completewhois.com. > > > > > > That might be a factor. > > > > > > Does using > > > > > > score __RCVD_IN_WHOIS 0 > > > score RCVD_IN_WHOIS_INVALID 0 > > > score URIBL_COMPLETEWHOIS 0 > > > > > > solve the performance problem? > > > > Much to my recent regret, I have avoided subscribing to any > > spamassassin support lists, opting instead to let all of you more > > adventurous types work out the bugs while I just implement what is > > recommended on the MS list. Would information such as the > above be on > > > the SA users list? Is there a FAQ with known "gotchas" > with running > > SA (3.2.2 in our case), where this is listed? How in > Perdition do you > > > track that "combined-HIB.dnsiplists.completewhois.com." is slow? > > > > And it's only Tuesday! > > > > > > thanks, > > Leland > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From brose at med.wayne.edu Wed Aug 15 12:53:06 2007 From: brose at med.wayne.edu (Rose, Bobby) Date: Wed Aug 15 12:53:14 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA0169FD35@HC-MBX02.herefordshire.gov.uk> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info><24231931.14351186764822763.JavaMail.root@office.splatnix.net><8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu><8F2A53954C22554EB75D9643FCCE0C6B0472D462@MED-CORE03-MS1.med.wayne.edu><7EF0EE5CB3B263488C8C18823239BEBA0169FC0F@HC-MBX02.herefordshire.gov.uk><46C20DFC.4050607@pa.net><7EF0EE5CB3B263488C8C18823239BEBA0169FCBF@HC-MBX02.herefordshire.gov.uk><8F2A53954C22554EB75D9643FCCE0C6B0472D46E@MED-CORE03-MS1.med.wayne.edu> <7EF0EE5CB3B263488C8C18823239BEBA0169FD35@HC-MBX02.herefordshire.gov.uk> Message-ID: <8F2A53954C22554EB75D9643FCCE0C6B0472D46F@MED-CORE03-MS1.med.wayne.edu> My change was done last night before I knew about this dns async issue that was introduced in 3.2.2. I know I saw mention of the async issue with ASN but not DNS in general. I'll try patching 3.2.3 later today after I've confirmed that that is where the delay in SA is coming from. It appears to be resolved after I made my change which I only made based on the changelogs and after diff'ing all the SA pm to confirm that there weren't any changes elsewhere that replacing Dns.pm would effect. I'm just surprised that no one else isn't noticing the performance differences based on MailScanner processing times between versions. Bobby Rose Senior Systems Administrator MSIS Network Operations Wayne State University School of Medicine -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Randal, Phil Sent: Wednesday, August 15, 2007 7:29 AM To: MailScanner discussion Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 Oh, I would have tried 3.2.3 with the aforementioned patch to see if that made a difference too, because that patch will end up in 3.2.4. Is there any chance that you can do that? The patch affects more than DNS.pm, though. If there's still an issue on 3.2.3 with the patch from bug 5589 then you should add a note to that bug and raise the issue on the Spamassassin Users mailing list too. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Rose, > Bobby > Sent: 15 August 2007 12:14 > To: MailScanner discussion > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 and > 3.2.3 > > Yeh that might be it. I checked the changelog and saw that the DNS > changes were the only real big change between 3.2.1. and > 3.2.2 so what I > did was installed 3.2.3 and replaced the Dns.pm with the version from > 3.2.1. I'll know if that is the problem lies there later on today as > traffic load increases. > > I grepped my logs from between the versions focusing on batches of 30 > and I clearly see differences of 100 to 150 secs between 3.2.1 and the > later versions. If anyone wants to check their times use this > egrep -e"Batch \(30 messages\) processed in" maillog > > -=B > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of > Randal, Phil > Sent: Wednesday, August 15, 2007 5:38 AM > To: MailScanner discussion > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 and > 3.2.3 > > Running spamassassin -D -t reveals a lot. > > I'm running SA with the patch from > > http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5589 > > and the debug output made that one pretty obvious. > > Cheers, > > Phil > > -- > Phil Randal > Network Engineer > Herefordshire Council > Hereford, UK > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of > > Leland J. Steinke > > Sent: 14 August 2007 21:18 > > To: MailScanner discussion > > Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and > > 3.2.3 > > > > Randal, Phil wrote: > > > I'm getting very slow DNS lookups from > > combined-HIB.dnsiplists.completewhois.com. > > > > > > That might be a factor. > > > > > > Does using > > > > > > score __RCVD_IN_WHOIS 0 > > > score RCVD_IN_WHOIS_INVALID 0 > > > score URIBL_COMPLETEWHOIS 0 > > > > > > solve the performance problem? > > > > Much to my recent regret, I have avoided subscribing to any > > spamassassin support lists, opting instead to let all of you more > > adventurous types work out the bugs while I just implement what is > > recommended on the MS list. Would information such as the > above be on > > > the SA users list? Is there a FAQ with known "gotchas" > with running > > SA (3.2.2 in our case), where this is listed? How in > Perdition do you > > > track that "combined-HIB.dnsiplists.completewhois.com." is slow? > > > > And it's only Tuesday! > > > > > > thanks, > > Leland > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From prandal at herefordshire.gov.uk Wed Aug 15 14:08:11 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Wed Aug 15 14:08:16 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B0472D46F@MED-CORE03-MS1.med.wayne.edu> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info><24231931.14351186764822763.JavaMail.root@office.splatnix.net><8F2A53954C22554EB75D9643FCCE0C6B0472D461@MED-CORE03-MS1.med.wayne.edu><8F2A53954C22554EB75D9643FCCE0C6B0472D462@MED-CORE03-MS1.med.wayne.edu><7EF0EE5CB3B263488C8C18823239BEBA0169FC0F@HC-MBX02.herefordshire.gov.uk><46C20DFC.4050607@pa.net><7EF0EE5CB3B263488C8C18823239BEBA0169FCBF@HC-MBX02.herefordshire.gov.uk><8F2A53954C22554EB75D9643FCCE0C6B0472D46E@MED-CORE03-MS1.med.wayne.edu><7EF0EE5CB3B263488C8C18823239BEBA0169FD35@HC-MBX02.herefordshire.gov.uk> <8F2A53954C22554EB75D9643FCCE0C6B0472D46F@MED-CORE03-MS1.med.wayne.edu> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA0169FD7E@HC-MBX02.herefordshire.gov.uk> I found a big performance hit with 3.2.x vs 3.1.x on my old MailScanner box, so I reverted to SA 3.1.x. Having built our new boxes with SA 3.2.2, I didn't have any benchmarks to compare with on the new hardware. It would be great to be able to pinpoint the exact cause of your performance issues. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Rose, Bobby > Sent: 15 August 2007 12:53 > To: MailScanner discussion > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 > and 3.2.3 > > My change was done last night before I knew about this dns async issue > that was introduced in 3.2.2. I know I saw mention of the async issue > with ASN but not DNS in general. I'll try patching 3.2.3 later today > after I've confirmed that that is where the delay in SA is > coming from. > It appears to be resolved after I made my change which I only > made based > on the changelogs and after diff'ing all the SA pm to confirm > that there > weren't any changes elsewhere that replacing Dns.pm would effect. > > I'm just surprised that no one else isn't noticing the performance > differences based on MailScanner processing times between versions. > > Bobby Rose > Senior Systems Administrator > MSIS Network Operations > Wayne State University School of Medicine > > > > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Randal, > Phil > Sent: Wednesday, August 15, 2007 7:29 AM > To: MailScanner discussion > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 > and 3.2.3 > > Oh, I would have tried 3.2.3 with the aforementioned patch to see if > that made a difference too, because that patch will end up in 3.2.4. > > Is there any chance that you can do that? The patch affects more than > DNS.pm, though. > > If there's still an issue on 3.2.3 with the patch from bug > 5589 then you > should add a note to that bug and raise the issue on the Spamassassin > Users mailing list too. > > Cheers, > > Phil > > -- > Phil Randal > Network Engineer > Herefordshire Council > Hereford, UK > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On > Behalf Of Rose, > > > Bobby > > Sent: 15 August 2007 12:14 > > To: MailScanner discussion > > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 and > > 3.2.3 > > > > Yeh that might be it. I checked the changelog and saw that the DNS > > changes were the only real big change between 3.2.1. and > > 3.2.2 so what I > > did was installed 3.2.3 and replaced the Dns.pm with the > version from > > 3.2.1. I'll know if that is the problem lies there later > on today as > > traffic load increases. > > > > I grepped my logs from between the versions focusing on > batches of 30 > > and I clearly see differences of 100 to 150 secs between > 3.2.1 and the > > > later versions. If anyone wants to check their times use this > > egrep -e"Batch \(30 messages\) processed in" maillog > > > > -=B > > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of > > Randal, Phil > > Sent: Wednesday, August 15, 2007 5:38 AM > > To: MailScanner discussion > > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 and > > 3.2.3 > > > > Running spamassassin -D -t reveals a lot. > > > > I'm running SA with the patch from > > > > http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5589 > > > > and the debug output made that one pretty obvious. > > > > Cheers, > > > > Phil > > > > -- > > Phil Randal > > Network Engineer > > Herefordshire Council > > Hereford, UK > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of > > > Leland J. Steinke > > > Sent: 14 August 2007 21:18 > > > To: MailScanner discussion > > > Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and > > > 3.2.3 > > > > > > Randal, Phil wrote: > > > > I'm getting very slow DNS lookups from > > > combined-HIB.dnsiplists.completewhois.com. > > > > > > > > That might be a factor. > > > > > > > > Does using > > > > > > > > score __RCVD_IN_WHOIS 0 > > > > score RCVD_IN_WHOIS_INVALID 0 > > > > score URIBL_COMPLETEWHOIS 0 > > > > > > > > solve the performance problem? > > > > > > Much to my recent regret, I have avoided subscribing to any > > > spamassassin support lists, opting instead to let all of you more > > > adventurous types work out the bugs while I just > implement what is > > > recommended on the MS list. Would information such as the > > above be on > > > > > the SA users list? Is there a FAQ with known "gotchas" > > with running > > > SA (3.2.2 in our case), where this is listed? How in > > Perdition do you > > > > > track that "combined-HIB.dnsiplists.completewhois.com." is slow? > > > > > > And it's only Tuesday! > > > > > > > > > thanks, > > > Leland > > > -- > > > MailScanner mailing list > > > mailscanner@lists.mailscanner.info > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From maillists at conactive.com Wed Aug 15 14:14:25 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Wed Aug 15 14:14:29 2007 Subject: Blocked Extensions in password-protected zip archives In-Reply-To: <46C2DE35.4060200@ecs.soton.ac.uk> References: <46C1F799.30304@ecs.soton.ac.uk> <46C2DE35.4060200@ecs.soton.ac.uk> Message-ID: Julian Field wrote on Wed, 15 Aug 2007 12:06:29 +0100: > Done. It will be in the next release, which should be available soon. And what about the ability to release (store) password-protected archives when the quarantine is kept clean? Can you add this, too? Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From paul at firespam.com Wed Aug 15 15:00:49 2007 From: paul at firespam.com (paul @ firespam) Date: Wed Aug 15 15:00:57 2007 Subject: Custom Functions help Message-ID: <1187186449.27602.6.camel@paul-laptop.sidlow.office-shadow.com> Hi, Is it possible to get the email body (either HTML or text) from within a custom function? The release notes for v4.60.8-1 seem to say that: "The Custom Function is now passed not only the message, but also a ref to a list of parameters specified in the MailScanner.conf file." Although I'm not sure if this just means the message ID or other such identifier. Thanks, Paul -- This message has been scanned for spam, viruses and phishing attempts by firespam.com From daniel at bokko.nl Wed Aug 15 15:49:43 2007 From: daniel at bokko.nl (Daniel Eiland) Date: Wed Aug 15 15:49:49 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B0472D46F@MED-CORE03-MS1.med.wayne.edu> Message-ID: <20070815143723.EA5881142B@panther.webvanced.nl> I am also seeing a dramatic performance decrease. My mailserver does around 30k emails a day, no problem with my previous spamassassin install, but after upgrading to 3.2.3 my queue is always around 1000 e-mails and emails are scanned with a delay of around 2 hours. The strange thing is my system is 70-90% idle, so a DNS problem sounds very likely to me. In my maillog I log the speed, I get around 300 bytes per second! That's terribly slow. With a similar server, but with 3.2.1i get 45000 bytes per second. There must be something seriously wrong I think. I tried disabling plugins, but no significant difference. I hope someone has a solution for this. Daniel -----Oorspronkelijk bericht----- Van: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Namens Rose, Bobby Verzonden: woensdag 15 augustus 2007 13:53 Aan: MailScanner discussion Onderwerp: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 My change was done last night before I knew about this dns async issue that was introduced in 3.2.2. I know I saw mention of the async issue with ASN but not DNS in general. I'll try patching 3.2.3 later today after I've confirmed that that is where the delay in SA is coming from. It appears to be resolved after I made my change which I only made based on the changelogs and after diff'ing all the SA pm to confirm that there weren't any changes elsewhere that replacing Dns.pm would effect. I'm just surprised that no one else isn't noticing the performance differences based on MailScanner processing times between versions. Bobby Rose Senior Systems Administrator MSIS Network Operations Wayne State University School of Medicine -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Randal, Phil Sent: Wednesday, August 15, 2007 7:29 AM To: MailScanner discussion Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 Oh, I would have tried 3.2.3 with the aforementioned patch to see if that made a difference too, because that patch will end up in 3.2.4. Is there any chance that you can do that? The patch affects more than DNS.pm, though. If there's still an issue on 3.2.3 with the patch from bug 5589 then you should add a note to that bug and raise the issue on the Spamassassin Users mailing list too. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Rose, > Bobby > Sent: 15 August 2007 12:14 > To: MailScanner discussion > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 and > 3.2.3 > > Yeh that might be it. I checked the changelog and saw that the DNS > changes were the only real big change between 3.2.1. and > 3.2.2 so what I > did was installed 3.2.3 and replaced the Dns.pm with the version from > 3.2.1. I'll know if that is the problem lies there later on today as > traffic load increases. > > I grepped my logs from between the versions focusing on batches of 30 > and I clearly see differences of 100 to 150 secs between 3.2.1 and the > later versions. If anyone wants to check their times use this > egrep -e"Batch \(30 messages\) processed in" maillog > > -=B > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of > Randal, Phil > Sent: Wednesday, August 15, 2007 5:38 AM > To: MailScanner discussion > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 and > 3.2.3 > > Running spamassassin -D -t reveals a lot. > > I'm running SA with the patch from > > http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5589 > > and the debug output made that one pretty obvious. > > Cheers, > > Phil > > -- > Phil Randal > Network Engineer > Herefordshire Council > Hereford, UK > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of > > Leland J. Steinke > > Sent: 14 August 2007 21:18 > > To: MailScanner discussion > > Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and > > 3.2.3 > > > > Randal, Phil wrote: > > > I'm getting very slow DNS lookups from > > combined-HIB.dnsiplists.completewhois.com. > > > > > > That might be a factor. > > > > > > Does using > > > > > > score __RCVD_IN_WHOIS 0 > > > score RCVD_IN_WHOIS_INVALID 0 > > > score URIBL_COMPLETEWHOIS 0 > > > > > > solve the performance problem? > > > > Much to my recent regret, I have avoided subscribing to any > > spamassassin support lists, opting instead to let all of you more > > adventurous types work out the bugs while I just implement what is > > recommended on the MS list. Would information such as the > above be on > > > the SA users list? Is there a FAQ with known "gotchas" > with running > > SA (3.2.2 in our case), where this is listed? How in > Perdition do you > > > track that "combined-HIB.dnsiplists.completewhois.com." is slow? > > > > And it's only Tuesday! > > > > > > thanks, > > Leland > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Wed Aug 15 16:04:30 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 15 16:05:39 2007 Subject: Custom Functions help In-Reply-To: <1187186449.27602.6.camel@paul-laptop.sidlow.office-shadow.com> References: <1187186449.27602.6.camel@paul-laptop.sidlow.office-shadow.com> Message-ID: <46C315FE.5020605@ecs.soton.ac.uk> It means the message object which has a long list of properties which are listed at the top of Message.pm. From those properties you can get at the body in various ways. Rick Cooper may be able to help you if you cross his hand with sufficient silver :-) You'll have to do some digging, I'm afraid. paul @ firespam wrote: > Hi, > > Is it possible to get the email body (either HTML or text) from within a custom function? > > The release notes for v4.60.8-1 seem to say that: > "The Custom Function is now passed not only the message, but also a ref to a list of parameters specified in the MailScanner.conf file." > > Although I'm not sure if this just means the message ID or other such identifier. > > > Thanks, > > Paul > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From gmatt at nerc.ac.uk Wed Aug 15 17:56:09 2007 From: gmatt at nerc.ac.uk (Greg Matthews) Date: Wed Aug 15 17:56:34 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <20070815143723.EA5881142B@panther.webvanced.nl> References: <20070815143723.EA5881142B@panther.webvanced.nl> Message-ID: <46C33029.1000406@nerc.ac.uk> Daniel Eiland wrote: > I am also seeing a dramatic performance decrease. > My mailserver does around 30k emails a day, no problem with my previous > spamassassin install, but after upgrading to 3.2.3 my queue is always around > 1000 e-mails and emails are scanned with a delay of around 2 hours. > > The strange thing is my system is 70-90% idle, so a DNS problem sounds very > likely to me. given the relatively low traffic on this thread and my own inability to spot the performance issue (even tho my upgrade to 3.2.2 happened pretty recently) suggests that most people (myself included) have hidden the problem behind a caching DNS server. Can anyone on this thread confirm whether or not they are using a caching DNS? I've attached a png from one of my relays showing spam check speed. The upgrade happened right at the end of July on this box (more or less where you see the red line). There is no noticeable drop in performance. The dark blue line shows the spam check speed and the average for those weeks is 89.5kB/s the magenta line is the max spam check speed. Note that this is SA only. Virus checks and the like make the overall figures barely register at the bottom of the graph! This is a (~5 years) old dual Xeon currently pushing around 20-25k message per day. > > In my maillog I log the speed, I get around 300 bytes per second! That's > terribly slow. With a similar server, but with 3.2.1i get 45000 bytes per > second. > > There must be something seriously wrong I think. > I tried disabling plugins, but no significant difference. > > I hope someone has a solution for this. have you tried installing a caching DNS? > > Daniel -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford -- This message (and any attachments) is for the recipient only. NERC is subject to the Freedom of Information Act 2000 and the contents of this email and any reply you make may be disclosed by NERC unless it is exempt from release under the Act. Any material supplied to NERC may be stored in an electronic records management system. -------------- next part -------------- A non-text attachment was scrubbed... Name: month Type: image/png Size: 3903 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070815/9aa3ef94/month.png From list-mailscanner at linguaphone.com Wed Aug 15 18:08:06 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 15 18:08:07 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <46C33029.1000406@nerc.ac.uk> Message-ID: > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Greg > Matthews > Sent: 15 August 2007 17:56 > To: MailScanner discussion > Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 > > > given the relatively low traffic on this thread and my own inability to > spot the performance issue (even tho my upgrade to 3.2.2 happened pretty > recently) suggests that most people (myself included) have hidden the > problem behind a caching DNS server. Can anyone on this thread confirm > whether or not they are using a caching DNS? I am using a caching DNS server and upgraded from 3.1.8 to 3.2.3 today and it does seem slower but I cannot really tell since our mail volume is very low and most system maintenance does not even cause the queue to build up to 30 messages. I expect the majority of people are like me and have servers which are capable of processing far more email than they currently receive so each mailscanner run only handles a few messages so it is quick anyway. From brose at med.wayne.edu Wed Aug 15 18:29:48 2007 From: brose at med.wayne.edu (Rose, Bobby) Date: Wed Aug 15 18:30:04 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <20070815143723.EA5881142B@panther.webvanced.nl> References: <8F2A53954C22554EB75D9643FCCE0C6B0472D46F@MED-CORE03-MS1.med.wayne.edu> <20070815143723.EA5881142B@panther.webvanced.nl> Message-ID: <8F2A53954C22554EB75D9643FCCE0C6B0472D476@MED-CORE03-MS1.med.wayne.edu> Ok it's 1EST here and the huge delays that I found on Fri, Mon and Tues when I was running 3.2.3 are not occurring. My mqueue.in has remained swift and steady and the number of Batch 30s is down to only 13 after 24k messsages processed by MS so far today. Today, I'm running with SA 3.2.3 but with the DNS.pm from 3.2.1. Previous days with SA 3.2.3, my batch 30's were in the 200-300 range because of the delays introduced in 3.2.2-.3. Previously at this time with 3.2.2 and 3.2.3, my mqueue.in would be backed up to 700-900 messages which although is normal load for this time of day, it wasn't normal for the queue to be backing up. So I'm betting it is the changes made to the DNS.pm module. I'll try patching 3.2.3 with http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5589 tonight and see what happens tomorrow. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Daniel Eiland Sent: Wednesday, August 15, 2007 10:50 AM To: 'MailScanner discussion' Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 I am also seeing a dramatic performance decrease. My mailserver does around 30k emails a day, no problem with my previous spamassassin install, but after upgrading to 3.2.3 my queue is always around 1000 e-mails and emails are scanned with a delay of around 2 hours. The strange thing is my system is 70-90% idle, so a DNS problem sounds very likely to me. In my maillog I log the speed, I get around 300 bytes per second! That's terribly slow. With a similar server, but with 3.2.1i get 45000 bytes per second. There must be something seriously wrong I think. I tried disabling plugins, but no significant difference. I hope someone has a solution for this. Daniel -----Oorspronkelijk bericht----- Van: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Namens Rose, Bobby Verzonden: woensdag 15 augustus 2007 13:53 Aan: MailScanner discussion Onderwerp: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 My change was done last night before I knew about this dns async issue that was introduced in 3.2.2. I know I saw mention of the async issue with ASN but not DNS in general. I'll try patching 3.2.3 later today after I've confirmed that that is where the delay in SA is coming from. It appears to be resolved after I made my change which I only made based on the changelogs and after diff'ing all the SA pm to confirm that there weren't any changes elsewhere that replacing Dns.pm would effect. I'm just surprised that no one else isn't noticing the performance differences based on MailScanner processing times between versions. Bobby Rose Senior Systems Administrator MSIS Network Operations Wayne State University School of Medicine -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Randal, Phil Sent: Wednesday, August 15, 2007 7:29 AM To: MailScanner discussion Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 Oh, I would have tried 3.2.3 with the aforementioned patch to see if that made a difference too, because that patch will end up in 3.2.4. Is there any chance that you can do that? The patch affects more than DNS.pm, though. If there's still an issue on 3.2.3 with the patch from bug 5589 then you should add a note to that bug and raise the issue on the Spamassassin Users mailing list too. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Rose, > Bobby > Sent: 15 August 2007 12:14 > To: MailScanner discussion > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 and > 3.2.3 > > Yeh that might be it. I checked the changelog and saw that the DNS > changes were the only real big change between 3.2.1. and > 3.2.2 so what I > did was installed 3.2.3 and replaced the Dns.pm with the version from > 3.2.1. I'll know if that is the problem lies there later on today as > traffic load increases. > > I grepped my logs from between the versions focusing on batches of 30 > and I clearly see differences of 100 to 150 secs between 3.2.1 and the > later versions. If anyone wants to check their times use this > egrep -e"Batch \(30 messages\) processed in" maillog > > -=B > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of > Randal, Phil > Sent: Wednesday, August 15, 2007 5:38 AM > To: MailScanner discussion > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 and > 3.2.3 > > Running spamassassin -D -t reveals a lot. > > I'm running SA with the patch from > > http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5589 > > and the debug output made that one pretty obvious. > > Cheers, > > Phil > > -- > Phil Randal > Network Engineer > Herefordshire Council > Hereford, UK > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of > > Leland J. Steinke > > Sent: 14 August 2007 21:18 > > To: MailScanner discussion > > Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and > > 3.2.3 > > > > Randal, Phil wrote: > > > I'm getting very slow DNS lookups from > > combined-HIB.dnsiplists.completewhois.com. > > > > > > That might be a factor. > > > > > > Does using > > > > > > score __RCVD_IN_WHOIS 0 > > > score RCVD_IN_WHOIS_INVALID 0 > > > score URIBL_COMPLETEWHOIS 0 > > > > > > solve the performance problem? > > > > Much to my recent regret, I have avoided subscribing to any > > spamassassin support lists, opting instead to let all of you more > > adventurous types work out the bugs while I just implement what is > > recommended on the MS list. Would information such as the > above be on > > > the SA users list? Is there a FAQ with known "gotchas" > with running > > SA (3.2.2 in our case), where this is listed? How in > Perdition do you > > > track that "combined-HIB.dnsiplists.completewhois.com." is slow? > > > > And it's only Tuesday! > > > > > > thanks, > > Leland From ms-list at alexb.ch Wed Aug 15 18:45:14 2007 From: ms-list at alexb.ch (Alex Broens) Date: Wed Aug 15 18:45:18 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: References: Message-ID: <46C33BAA.8060905@alexb.ch> On 8/15/2007 7:08 PM, Gareth wrote: >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Greg >> Matthews >> Sent: 15 August 2007 17:56 >> To: MailScanner discussion >> Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 >> >> >> given the relatively low traffic on this thread and my own inability to >> spot the performance issue (even tho my upgrade to 3.2.2 happened pretty >> recently) suggests that most people (myself included) have hidden the >> problem behind a caching DNS server. Can anyone on this thread confirm >> whether or not they are using a caching DNS? > > I am using a caching DNS server and upgraded from 3.1.8 to 3.2.3 today and > it does seem slower but I cannot really tell since our mail volume is very > low and most system maintenance does not even cause the queue to build up to > 30 messages. > I expect the majority of people are like me and have servers which are > capable of processing far more email than they currently receive so each > mailscanner run only handles a few messages so it is quick anyway. > Guys look into all the RBL/DNSB tests wich are enabled by default and start disabling the ones you don't really need by setting the score to 0 in a custom.cf file in /etc/mail/spamassassin. I presume some of these lookups are happening on sites with few mirrors and/or low capacity/overlaoded servers and depending on what side of what pond you are, delay may be more or less noticeable. Net lag can be deadly in processing speed, even with a local caching DNS. Check thoroughly what each lookup does and evaluate h2h Alex From Richard.Frovarp at sendit.nodak.edu Wed Aug 15 18:55:08 2007 From: Richard.Frovarp at sendit.nodak.edu (Richard Frovarp) Date: Wed Aug 15 18:55:13 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: References: Message-ID: <46C33DFC.8000101@sendit.nodak.edu> Gareth wrote: >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Greg >> Matthews >> Sent: 15 August 2007 17:56 >> To: MailScanner discussion >> Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 >> >> >> given the relatively low traffic on this thread and my own inability to >> spot the performance issue (even tho my upgrade to 3.2.2 happened pretty >> recently) suggests that most people (myself included) have hidden the >> problem behind a caching DNS server. Can anyone on this thread confirm >> whether or not they are using a caching DNS? >> > > I am using a caching DNS server and upgraded from 3.1.8 to 3.2.3 today and > it does seem slower but I cannot really tell since our mail volume is very > low and most system maintenance does not even cause the queue to build up to > 30 messages. > I expect the majority of people are like me and have servers which are > capable of processing far more email than they currently receive so each > mailscanner run only handles a few messages so it is quick anyway. > > 3.2.x has more rules than 3.1.x. This will naturally result in a slowdown of processing. sa-compile is supposed to make rule checking quicker, so you end up in a wash there if using sa-compile. From hvdkooij at vanderkooij.org Wed Aug 15 19:20:36 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Wed Aug 15 19:20:45 2007 Subject: Off topic - AntiVirus accuracy competition In-Reply-To: References: <3376.62.150.152.226.1185292117.squirrel@webmail.baladia.gov.kw> <46C1C7EC.9020003@USherbrooke.ca> <2e7e01c7de8d$fcf7ed10$f6e7c730$@swaney@fsl.com> Message-ID: On Wed, 15 Aug 2007, Kai Schaetzl wrote: > Hugo van der Kooij wrote on Wed, 15 Aug 2007 07:48:20 +0200 (CEST): > >> In the past I had to remove files that could kill >> some scanners. > > Hm, shouldn't happen as this could also happen in real production. If it > gulps on some files this is a clear bug. I have been debugging some scanners in the past. Most notable was the assistence I got from Alwill (Avast). I had a dozen or two samples that could crash it. I got 3 or 4 test versions before the current version was made publically available. Perhaps similar sessions are required for other products. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From itdept at fractalweb.com Wed Aug 15 19:22:06 2007 From: itdept at fractalweb.com (Chris Yuzik) Date: Wed Aug 15 19:22:23 2007 Subject: How to manually test an email? In-Reply-To: <223f97700708150054u73beabaak41f9a9d0967969a8@mail.gmail.com> References: <1187095642.19264.3.camel@paul-laptop.sidlow.office-shadow.com> <46C28762.1040804@fractalweb.com> <223f97700708150054u73beabaak41f9a9d0967969a8@mail.gmail.com> Message-ID: <46C3444E.1060404@fractalweb.com> Glenn Steen wrote: > That is what crm114 does to your scoring... It will be (more or less) > the sole decision maker, making all the other SA stuff a vast degree > less relevant. > That might be fine, provided you trust it (CRM114) implicitly... But > uf you don't, use a more ... lenient... multiplication factor, or even > fixed scores. You make a very good point. In the past couple of weeks of running CRM114 on our production systems, we've found it to be surprisingly accurate--less at first, far more now. We've been doing daily training, using my modified version of Matt Hampton's perl script available here: http://www.fractalweb.com/scripts/crm_train2.zip "False positives", according to the script are checked (there are only perhaps a dozen each day) and then we manually decide whether they're really spam and train accordingly. Have a good one! Chris From brose at med.wayne.edu Wed Aug 15 20:08:57 2007 From: brose at med.wayne.edu (Rose, Bobby) Date: Wed Aug 15 20:09:08 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <46C33DFC.8000101@sendit.nodak.edu> References: <46C33DFC.8000101@sendit.nodak.edu> Message-ID: <8F2A53954C22554EB75D9643FCCE0C6B0472D477@MED-CORE03-MS1.med.wayne.edu> It's not net lag or bad DNSBLs and it's not an increase I rules, because the DNS queries that I'm using are the same. Today, I am running 3.2.3 but using the DNS.pm from 3.2.1 and everything is running normally. It's not DNS caching because that is also the same here and I've been using re2c sa compiled body rules since the feature was introduced. My observations are that the issue was due to the changes in the DNS code change 5511 which introduced the async issues and DNS completion issues discussed with ASN and DNS code changes in Bug 5589 -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Richard Frovarp Sent: Wednesday, August 15, 2007 1:55 PM To: MailScanner discussion Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 Gareth wrote: >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Greg >> Matthews >> Sent: 15 August 2007 17:56 >> To: MailScanner discussion >> Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and >> 3.2.3 >> >> >> given the relatively low traffic on this thread and my own inability >> to spot the performance issue (even tho my upgrade to 3.2.2 happened >> pretty >> recently) suggests that most people (myself included) have hidden the >> problem behind a caching DNS server. Can anyone on this thread >> confirm whether or not they are using a caching DNS? >> > > I am using a caching DNS server and upgraded from 3.1.8 to 3.2.3 today > and it does seem slower but I cannot really tell since our mail volume > is very low and most system maintenance does not even cause the queue > to build up to 30 messages. > I expect the majority of people are like me and have servers which are > capable of processing far more email than they currently receive so > each mailscanner run only handles a few messages so it is quick anyway. > > 3.2.x has more rules than 3.1.x. This will naturally result in a slowdown of processing. sa-compile is supposed to make rule checking quicker, so you end up in a wash there if using sa-compile. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From theodrake at comcast.net Wed Aug 15 21:02:46 2007 From: theodrake at comcast.net (Ed Bruce) Date: Wed Aug 15 21:03:07 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B0472D476@MED-CORE03-MS1.med.wayne.edu> References: <8F2A53954C22554EB75D9643FCCE0C6B0472D46F@MED-CORE03-MS1.med.wayne.edu> <20070815143723.EA5881142B@panther.webvanced.nl> <8F2A53954C22554EB75D9643FCCE0C6B0472D476@MED-CORE03-MS1.med.wayne.edu> Message-ID: <46C35BE6.1050207@comcast.net> Rose, Bobby wrote: > Ok it's 1EST here and the huge delays that I found on Fri, Mon and Tues > when I was running 3.2.3 are not occurring. My mqueue.in has remained > swift and steady and the number of Batch 30s is down to only 13 after > 24k messsages processed by MS so far today. Today, I'm running with SA > 3.2.3 but with the DNS.pm from 3.2.1. Previous days with SA 3.2.3, my > batch 30's were in the 200-300 range because of the delays introduced in > 3.2.2-.3. Previously at this time with 3.2.2 and 3.2.3, my mqueue.in > would be backed up to 700-900 messages which although is normal load for > this time of day, it wasn't normal for the queue to be backing up. I could find a Dns.pm in the SpamAssassin tar file but not a DNS.pm. I can find a DNS.pm in: /usr/lib/perl5/site_perl/5.8.0/i386-linux-thread-multi/Net/DNS.pm There is also a Dns.pm in: /usr/lib/perl5/site_perl/5.8.0/Mail/SpamAssassin/Dns.pm In my Mail-SpamAssassin-3.2.1 I see this: Mail-SpamAssassin-3.2.1/lib/Mail/SpamAssassin/Dns.pm So which file (DNS.pm or Dns.pm) did you change? -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 249 bytes Desc: OpenPGP digital signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070815/deb38b63/signature-0001.bin From MailScanner at ecs.soton.ac.uk Wed Aug 15 21:07:38 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 15 21:08:10 2007 Subject: Release 4.63.2 beta Message-ID: <46C35D0A.8060108@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I thought it was about time for a new beta. So I've just released 4.63.2. The main new points compared to the last beta are: - -- New setting "Check Filenames In Password-Protected Archives = yes". Useful if you allow password-protected archives to a few of your developers, and they need to exchange executables in them. - -- New setting "Include Binary Attachments In SpamAssassin = no". You can use this option, in conjunction with the small SpamAssassin patch applied for MCP to work, to add to the spam checking the feature that MCP has over it, in that it will process all attachments for spam content, not just the text and HTML. Download as usual from www.mailscanner.info. Please check that the new features all work correctly and that the bug fixes have actually fixed any problems you were having. Thanks! The full Change Log is: * New Features and Improvements * 1 Improved init.d script, so that 'service MailScanner restart' or '/etc/init.d/MailScanner restart' runs faster. It pauses for just long enough for the old MailScanner to die gracefully, and starts up the new one as soon as the old one has died. Previously, it just waited for a fixed length of time which was much longer than needed for most people. 1 Improved tar installer so the directory created for MailScanner includes the build revision number as well as the main version number. 1 Improved phishing net logging to log entire real URL not just hostname. 1 Improvement to update_spamassassin to stop cron-generated mail. 1 New setting "Phishing Bad Sites File" which is a live continuously-updated list of known bad sites that have been reported to various mechanisms around the world. Please don't ask me for more information as I can't give it to you, but every site on the list has been manually tested and the list can be relied upon. Your installation should update this file every hour. NOTE: Run upgrade_languages_conf after installing this upgrade! 2 Reduce default "Restart Every" time to 2 hours so that updates to the known bad phishing sites list are re-read more frequently. 2 Added *.fdf to the list of dangerous filenames. Opening a .fdf file can cause the loading of any file on the internet into Adobe Acrobat. 2 Added 2 new variables to the sender reports: $size = size of message in bytes and $maxmessagesize = maximum allowed size of this message in bytes. 2 Added new setting "Check Filenames In Password-Protected Archives = yes" so that the filename checks can be suppressed on encrypted archives to allow a few people to get exe's and so on through the mail as part of their business needs. Normally leave this setting at "yes". 2 Added new setting "Include Binary Attachments In SpamAssassin = no" which can be used to tell SpamAssassin to look at all attachments, not just the ones containing text (or HTML, etc) which is its normal behaviour. Changing this setting to "yes" will have no effect without a patch to the SpamAssassin code, which you can fetch from http://www.mailscanner.info/mcp.html#patches It will slightly slow down SpamAssassin some of the time, and is therefore disabled by default. This can be very useful if you want to look for rude or derogatory content in messages, and do not want the huge speed impact of using MCP. It can successfully scan the content of Microsoft Word documents, for example. It won't be effective on PDF files however, as these are compressed internally so there is no readable text anywhere in the file. * Fixes * 1 Improvement to phishing net to allow HTML tags with contents split over multiple lines. 1 Changed options to ClamAVmodule so it doesn't hit false positives with the phishing and scam email detection signatures. 1-2 Fixed bug where --lint gives "MailScanner.conf file not found" error. 2 Stopped writing a PID file when "MailScanner --lint" is run. 2 update_spamassassin no longer produces any output, so no crond email. 2 Fixed bug where clamavmodule scanner name wouldn't always be logged correctly. 2 Bugfix in ZMDiskStore.pm ZMailer support from Leonardo Helman. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGw10LEfZZRxQVtlQRAjloAJ4ghpnmoEiLjv4gMay0ZkFo4ByZaACg7T61 g4H315BtDcN2R9NbcbWUGVY= =w7rF -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From brose at med.wayne.edu Wed Aug 15 21:56:43 2007 From: brose at med.wayne.edu (Rose, Bobby) Date: Wed Aug 15 21:56:55 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <46C35BE6.1050207@comcast.net> References: <8F2A53954C22554EB75D9643FCCE0C6B0472D46F@MED-CORE03-MS1.med.wayne.edu> <20070815143723.EA5881142B@panther.webvanced.nl><8F2A53954C22554EB75D9643FCCE0C6B0472D476@MED-CORE03-MS1.med.wayne.edu> <46C35BE6.1050207@comcast.net> Message-ID: <8F2A53954C22554EB75D9643FCCE0C6B0472D47A@MED-CORE03-MS1.med.wayne.edu> ..../perl5/site_perl/5.8.x/SpamAssassin/Dns.pm is the one I replaced. SA does not change other perl modules especially not Net::DNS I have just reinstalled 3.2.3 with the patch mentioned in Bug 5589. I won't know if it resolves my performance observations until later tomorrow (EST) Bobby Rose Senior Systems Administrator MSIS Network Operations Wayne State University School of Medicine -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Ed Bruce Sent: Wednesday, August 15, 2007 4:03 PM To: MailScanner discussion Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 Rose, Bobby wrote: > Ok it's 1EST here and the huge delays that I found on Fri, Mon and > Tues when I was running 3.2.3 are not occurring. My mqueue.in has > remained swift and steady and the number of Batch 30s is down to only > 13 after 24k messsages processed by MS so far today. Today, I'm > running with SA > 3.2.3 but with the DNS.pm from 3.2.1. Previous days with SA 3.2.3, my > batch 30's were in the 200-300 range because of the delays introduced > in 3.2.2-.3. Previously at this time with 3.2.2 and 3.2.3, my > mqueue.in would be backed up to 700-900 messages which although is > normal load for this time of day, it wasn't normal for the queue to be backing up. I could find a Dns.pm in the SpamAssassin tar file but not a DNS.pm. I can find a DNS.pm in: /usr/lib/perl5/site_perl/5.8.0/i386-linux-thread-multi/Net/DNS.pm There is also a Dns.pm in: /usr/lib/perl5/site_perl/5.8.0/Mail/SpamAssassin/Dns.pm In my Mail-SpamAssassin-3.2.1 I see this: Mail-SpamAssassin-3.2.1/lib/Mail/SpamAssassin/Dns.pm So which file (DNS.pm or Dns.pm) did you change? From MailScanner at ecs.soton.ac.uk Wed Aug 15 22:33:58 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 15 22:34:33 2007 Subject: Release 4.63.2 beta In-Reply-To: <46C35D0A.8060108@ecs.soton.ac.uk> References: <46C35D0A.8060108@ecs.soton.ac.uk> Message-ID: <46C37146.2060201@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Julian Field wrote: > -- New setting "Check Filenames In Password-Protected Archives = yes". > Useful if you allow password-protected archives to a few of your > developers, and they need to exchange executables in them. That was easy to add, once I found the right place to put it, so was feasible even if only 1 person wanted it, so far. Hopefully others will find it useful given time to think about it. > -- New setting "Include Binary Attachments In SpamAssassin = no". You > can use this option, in conjunction with the small SpamAssassin patch > applied for MCP to work, to add to the spam checking the feature that > MCP has over it, in that it will process all attachments for spam > content, not just the text and HTML. This is particularly useful if you use MCP to detect certain strings such as rude language (if you have children among your users) or the names of your company's projects or competitors, when these strings might appear in Word documents. Obviously there isn't much point scanning images for strings like this, but who's to say that my_industrial_espionage_notes.jpg is actually an image and not a renamed Word document? So safer to scan everything. You can then use SpamAssassin Rule Actions to detect these rules firing and send the mail to the boss/teacher instead. And all this without the huge speed impact of actually running MCP. Which has to be a good thing, as anyone with MCP running in a large site will probably tell you. > * New Features and Improvements * > 1 Improved init.d script, so that 'service MailScanner restart' or > '/etc/init.d/MailScanner restart' runs faster. It pauses for just long > enough for the old MailScanner to die gracefully, and starts up the > new one > as soon as the old one has died. Previously, it just waited for a fixed > length of time which was much longer than needed for most people. On busy servers you might find it can take quite a while for the children to all die. But they will, eventually. > 1 New setting "Phishing Bad Sites File" which is a live > continuously-updated > list of known bad sites that have been reported to various mechanisms > around > the world. Please don't ask me for more information as I can't give > it to > you, but every site on the list has been manually tested and the list > can be > relied upon. Your installation should update this file every hour. > NOTE: Run upgrade_languages_conf after installing this upgrade! This file is developing nicely and currently lists over 900 sites, all reported within the last week or so. It will continue to grow. Sites are eventually expired out of this file, it won't grow indefinitely. > 2 Added *.fdf to the list of dangerous filenames. Opening a .fdf file can > cause the loading of any file on the internet into Adobe Acrobat. Can someone with one of these fdf files run it through the "file" command and tell me what it says please? > 2 Added new setting "Check Filenames In Password-Protected Archives = > yes" so > that the filename checks can be suppressed on encrypted archives to > allow > a few people to get exe's and so on through the mail as part of their > business needs. Normally leave this setting at "yes". This effectively sets Max Archive Depth = 0 for password-protected archives. > 2 Stopped writing a PID file when "MailScanner --lint" is run. That was a real brain failure on my part! :-) Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGw3FIEfZZRxQVtlQRAm97AJ9VpW3xv26NcFSIu51GXRst3U90rgCfcZ1w GEVnfLduxRF5EmmXfuO3L8M= =ultL -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From gmane at tippingmar.com Wed Aug 15 22:41:15 2007 From: gmane at tippingmar.com (Mark Nienberg) Date: Wed Aug 15 22:41:36 2007 Subject: Release 4.63.2 beta In-Reply-To: <46C35D0A.8060108@ecs.soton.ac.uk> References: <46C35D0A.8060108@ecs.soton.ac.uk> Message-ID: Julian Field wrote: > 2 Added *.fdf to the list of dangerous filenames. Opening a .fdf file can > cause the loading of any file on the internet into Adobe Acrobat. There are perfectly legitimate reasons to send email messages with fdf files attached. If you use the "browser-based review" feature of Acrobat that allows multiple users to review and comment on a pdf file, then the automatically generated email invitations will have an fdf file attached. The user clicks on the fdf file to open the document in Acrobat. The document is usually on a webdav server. Each user's comments are then sent to and saved on the webdav server by the Acrobat program. Blocking fdf files will effectively disable one of the key features of Acrobat. Mark From gmane at tippingmar.com Wed Aug 15 22:46:19 2007 From: gmane at tippingmar.com (Mark Nienberg) Date: Wed Aug 15 22:50:06 2007 Subject: Release 4.63.2 beta In-Reply-To: <46C35D0A.8060108@ecs.soton.ac.uk> References: <46C35D0A.8060108@ecs.soton.ac.uk> Message-ID: [mark@tesla store]$ file test.fdf test.fdf: ISO-8859 text, with very long lines, with CRLF, CR line terminators This is a legitimate fdf file, not one received in a spam message. Mark From maillists at conactive.com Wed Aug 15 23:31:16 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Wed Aug 15 23:31:18 2007 Subject: Release 4.63.2 beta In-Reply-To: <46C35D0A.8060108@ecs.soton.ac.uk> References: <46C35D0A.8060108@ecs.soton.ac.uk> Message-ID: Julian Field wrote on Wed, 15 Aug 2007 21:07:38 +0100: > It > won't be effective on PDF files however, as these are compressed > internally > so there is no readable text anywhere in the file. I'm not using the SA PDFInfo plugin, this comment suggests that this plugin wouldn't work in the past with MailScanner, but might now? Is this correct? Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From ssilva at sgvwater.com Wed Aug 15 23:35:54 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Aug 15 23:36:05 2007 Subject: Release 4.63.2 beta In-Reply-To: References: <46C35D0A.8060108@ecs.soton.ac.uk> Message-ID: Mark Nienberg spake the following on 8/15/2007 2:41 PM: > Julian Field wrote: > >> 2 Added *.fdf to the list of dangerous filenames. Opening a .fdf file can >> cause the loading of any file on the internet into Adobe Acrobat. > > There are perfectly legitimate reasons to send email messages with fdf > files attached. If you use the "browser-based review" feature of > Acrobat that allows multiple users to review and comment on a pdf file, > then the automatically generated email invitations will have an fdf file > attached. The user clicks on the fdf file to open the document in > Acrobat. The document is usually on a webdav server. Each user's > comments are then sent to and saved on the webdav server by the Acrobat > program. > > Blocking fdf files will effectively disable one of the key features of > Acrobat. > > Mark > Since it is an option, you can disable it if you see fit. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From axisml at gmail.com Wed Aug 15 23:37:48 2007 From: axisml at gmail.com (Chris Stone) Date: Wed Aug 15 23:37:52 2007 Subject: Release 4.63.2 beta In-Reply-To: References: <46C35D0A.8060108@ecs.soton.ac.uk> Message-ID: <1187217468.23927.3.camel@csmdv.axint.net> On Thu, 2007-08-16 at 00:31 +0200, Kai Schaetzl wrote: > Julian Field wrote on Wed, 15 Aug 2007 21:07:38 +0100: > > > It > > won't be effective on PDF files however, as these are compressed > > internally > > so there is no readable text anywhere in the file. > > I'm not using the SA PDFInfo plugin, this comment suggests that this > plugin wouldn't work in the past with MailScanner, but might now? Is this > correct? I've been using PDFInfo with MS/SA since it's early closed beta release and have never had a problem with it - working great. Chris From mailscanner at PDSCC.COM Thu Aug 16 00:10:32 2007 From: mailscanner at PDSCC.COM (Harondel J. Sibble) Date: Thu Aug 16 00:10:29 2007 Subject: perl upgrade borks ms Message-ID: <200708152310.l7FNAP0B011614@sinclaire.sibble.net> Okay, Centos 3.x machine running MS 4.57.6-1 Yum upgraded Perl from 5.805 to 5.8.5 this morning and things went sideways. Restarting MS gives the following # /etc/init.d/MailScanner restart Shutting down MailScanner daemons: MailScanner: [FAILED] incoming postfix: [ OK ] outgoing postfix: [ OK ] Starting MailScanner daemons: incoming postfix: [ OK ] outgoing postfix: [ OK ] MailScanner: is only avaliable with the XS version at /usr/lib/perl5/site_perl/5.8.5/Compress/Zlib.pm line 9 BEGIN failed--compilation aborted at /usr/lib/perl5/site_perl/5.8.5/Compress/Zlib.pm line 9. Compilation failed in require at /usr/lib/perl5/vendor_perl/5.8.5/Archive/Zip.pm line 24. BEGIN failed--compilation aborted at /usr/lib/perl5/vendor_perl/5.8.5/Archive/Zip.pm line 24. Compilation failed in require at /usr/lib/MailScanner/MailScanner/Message.pm line 48. BEGIN failed--compilation aborted at /usr/lib/MailScanner/MailScanner/Message.pm line 48. Compilation failed in require at /usr/sbin/MailScanner line 79. BEGIN failed--compilation aborted at /usr/sbin/MailScanner line 79. [ OK ] Googling got me a few things, one involved a perlinstaller script from CPanel which we don't use. Trying to download and install the package anyways as per here http://www.configserver.co.uk/blog/index.php?catid=6&results=1&page=5 I tried reinstalling the modules in question, but both install Compress::Zlib install Bundle::CPAN fail with a lot of the following errors /02_methods............ok t/03_file...............Use of uninitialized value in concatenation (.) or string at /usr/lib/perl5/5.8.5/i386-linux-thread-multi/Scalar/Util.pm line 30. Also tried rerunning the install script for the current version of MS and then installing the newly recreated rpm, no joy. This was one of the suggestions in the list logs, but sadly it didn't help. Any suggestions on how to fix this quickly? Thanks -- Harondel J. Sibble Sibble Computer Consulting Creating solutions for the small business and home computer user. help@pdscc.com (use pgp keyid 0x3AD5C11D) http://www.pdscc.com (604) 739-3709 (voice/fax) (604) 686-2253 (pager) From Jeff.Mills at versacold.com.au Thu Aug 16 00:18:51 2007 From: Jeff.Mills at versacold.com.au (Jeff Mills) Date: Thu Aug 16 00:18:57 2007 Subject: perl upgrade borks ms Message-ID: > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Harondel J. Sibble > Sent: Thursday, 16 August 2007 9:11 AM > To: mailscanner@lists.mailscanner.info > Subject: perl upgrade borks ms > > Okay, Centos 3.x machine running MS 4.57.6-1 > > Yum upgraded Perl from 5.805 to 5.8.5 this morning and things > went sideways. I'm using 5.8.8 in Gentoo with no issues for MailScanner. From richard.siddall at elirion.net Thu Aug 16 01:35:16 2007 From: richard.siddall at elirion.net (Richard Siddall) Date: Thu Aug 16 01:36:44 2007 Subject: perl upgrade borks ms In-Reply-To: <200708152310.l7FNAP0B011614@sinclaire.sibble.net> References: <200708152310.l7FNAP0B011614@sinclaire.sibble.net> Message-ID: <46C39BC4.9010105@elirion.net> Harondel J. Sibble wrote: > Any suggestions on how to fix this quickly? > A quick google indicates cpan> force install Compress:Zlib might work. I seem to recall there's some way of skipping the tests. I suspect the main problem is that the Perl include path has changed, so some of your Perl modules can't be found. Regards, Richard Siddall From micoots at yahoo.com Thu Aug 16 02:39:54 2007 From: micoots at yahoo.com (Michael Mansour) Date: Thu Aug 16 02:39:57 2007 Subject: --lint of filename rules filetype rules Message-ID: <898808.9209.qm@web33309.mail.mud.yahoo.com> Hi, I noticed in my logwatch reports that I had errors like: Cannot open filename-rules file /etc/MailScanner/domain.com.au.filename.rules.conf, skipping#012#000: 7 Time(s) Cannot open filename-rules file /etc/MailScanner/domain.com.au.filetype.rules.conf, skipping#012#000: 7 Time(s) These files are of course referenced through their equivalent /etc/Mailscanner/rules/filename.rules and /etc/Mailscanner/rules/filetype.rules files, but because they are not existent I didn't know until the logwatch report. A "MailScanner --lint" doesn't pickup these errors, yet I think it should. I'm using mailscanner 4.62.9-2. Thanks. Michael. --------------------------------- Get the World's number 1 free email service. Find out more. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070816/fa2bf530/attachment.html From micoots at yahoo.com Thu Aug 16 03:40:09 2007 From: micoots at yahoo.com (Michael Mansour) Date: Thu Aug 16 03:40:13 2007 Subject: --lint with AutoCommit errors Message-ID: <517833.5865.qm@web33311.mail.mud.yahoo.com> Hi, On two of my mail servers, when I do a MailScanner --lint at the very bottom I get: commit ineffective with AutoCommit enabled at /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 96, line 1. Commmit ineffective while AutoCommit is on at /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 96, line 1. I'm using mailscanner-4.62.9-2 and mailwatch 1.0.3. Any ideas how I can trouble-shoot and fix this issue? Thanks. Michael. --------------------------------- Get the World's number 1 free email service. Find out more. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070816/45a88c55/attachment.html From mailscanner at PDSCC.COM Thu Aug 16 05:47:51 2007 From: mailscanner at PDSCC.COM (Harondel J. Sibble) Date: Thu Aug 16 05:47:48 2007 Subject: perl upgrade borks ms In-Reply-To: <46C39BC4.9010105@elirion.net> References: <200708152310.l7FNAP0B011614@sinclaire.sibble.net>, <46C39BC4.9010105@elirion.net> Message-ID: <200708160447.l7G4liKw012331@sinclaire.sibble.net> On 15 Aug 2007 at 20:35, Richard Siddall wrote: > A quick google indicates > cpan> force install Compress:Zlib > might work. I seem to recall there's some way of skipping the tests. Nope. Exact same errors when I try to startup MS. > I suspect the main problem is that the Perl include path has changed, so some > of your Perl modules can't be found. Yeah, maybe it's time to just install a new version of MS -- Harondel J. Sibble Sibble Computer Consulting Creating solutions for the small business and home computer user. help@pdscc.com (use pgp keyid 0x3AD5C11D) http://www.pdscc.com (604) 739-3709 (voice/fax) (604) 686-2253 (pager) From mailscanner at PDSCC.COM Thu Aug 16 08:13:50 2007 From: mailscanner at PDSCC.COM (Harondel J. Sibble) Date: Thu Aug 16 08:13:46 2007 Subject: perl upgrade borks ms In-Reply-To: <200708160447.l7G4liKw012331@sinclaire.sibble.net> References: <200708152310.l7FNAP0B011614@sinclaire.sibble.net>, <46C39BC4.9010105@elirion.net>, <200708160447.l7G4liKw012331@sinclaire.sibble.net> Message-ID: <200708160713.l7G7Dhai012763@sinclaire.sibble.net> On 15 Aug 2007 at 21:47, Harondel J. Sibble wrote: > > I suspect the main problem is that the Perl include path has changed, so > > some of your Perl modules can't be found. > > > Yeah, maybe it's time to just install a new version of MS Tried upgrading to MailScanner-4.62.9-3, got same errors, after going here http://www.mailscanner.info/install/perl.shtml and doing a force install of most of the modules, I notice a common thread on the ones that were failing related to Scalar::Util, once I forced installed that one, all the other modules fell into line. It's back up and running and processing the queue. Wish I'd figured that out like 4 hours ago :-( and I could have spent some time with my SO, rather than glued to a remote session. -- Harondel J. Sibble Sibble Computer Consulting Creating solutions for the small business and home computer user. help@pdscc.com (use pgp keyid 0x3AD5C11D) http://www.pdscc.com (604) 739-3709 (voice/fax) (604) 686-2253 (pager) From martinh at solidstatelogic.com Thu Aug 16 08:40:15 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Thu Aug 16 08:40:51 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: Message-ID: <11a8463a5b71fa40b7327e8688084a26@solidstatelogic.com> If you're using sa.3.2x make sure you've run sa-compile (it'll need re2c installed first), this does make a heck of a difference -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Gareth > Sent: 15 August 2007 18:08 > To: MailScanner discussion > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Greg > > Matthews > > Sent: 15 August 2007 17:56 > > To: MailScanner discussion > > Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 > > > > > > given the relatively low traffic on this thread and my own inability to > > spot the performance issue (even tho my upgrade to 3.2.2 happened pretty > > recently) suggests that most people (myself included) have hidden the > > problem behind a caching DNS server. Can anyone on this thread confirm > > whether or not they are using a caching DNS? > > I am using a caching DNS server and upgraded from 3.1.8 to 3.2.3 today and > it does seem slower but I cannot really tell since our mail volume is very > low and most system maintenance does not even cause the queue to build up > to > 30 messages. > I expect the majority of people are like me and have servers which are > capable of processing far more email than they currently receive so each > mailscanner run only handles a few messages so it is quick anyway. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From glenn.steen at gmail.com Thu Aug 16 10:02:23 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu Aug 16 10:02:26 2007 Subject: Release 4.63.2 beta In-Reply-To: References: <46C35D0A.8060108@ecs.soton.ac.uk> Message-ID: <223f97700708160202qc59fc79t30c6300e3dfa9087@mail.gmail.com> On 15/08/07, Mark Nienberg wrote: > Julian Field wrote: > > > 2 Added *.fdf to the list of dangerous filenames. Opening a .fdf file can > > cause the loading of any file on the internet into Adobe Acrobat. > > There are perfectly legitimate reasons to send email messages with fdf files > attached. If you use the "browser-based review" feature of Acrobat that allows > multiple users to review and comment on a pdf file, then the automatically generated > email invitations will have an fdf file attached. The user clicks on the fdf file to > open the document in Acrobat. The document is usually on a webdav server. Each > user's comments are then sent to and saved on the webdav server by the Acrobat program. > > Blocking fdf files will effectively disable one of the key features of Acrobat. > > Mark > Of course. It would be pointless for the spammers to try exploit it otherwise... This ensures that people will want it flowing through.... So, as with anything, not well thought through features are exploitable. Since you a) Know this b) is capable of turningit off ... this should be no problem at all, provided this is indeed something your userbase/systems/policy "demand". Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Thu Aug 16 10:18:35 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu Aug 16 10:18:37 2007 Subject: --lint with AutoCommit errors In-Reply-To: <517833.5865.qm@web33311.mail.mud.yahoo.com> References: <517833.5865.qm@web33311.mail.mud.yahoo.com> Message-ID: <223f97700708160218s4d745172o4c820a1691c8645c@mail.gmail.com> On 16/08/07, Michael Mansour wrote: > Hi, > > On two of my mail servers, when I do a MailScanner --lint at the very bottom > I get: > > commit ineffective with AutoCommit enabled at > /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm > line 96, line 1. > Commmit ineffective while AutoCommit is on at > /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm > line 96, line 1. > > I'm using mailscanner-4.62.9-2 and mailwatch 1.0.3. > > Any ideas how I can trouble-shoot and fix this issue? > > Thanks. > > Michael. > You have auto-commit turned on for MySQL, which will automatically commit every transaction. To be safe, everyone doesn't have it on, there are appropriate commits after the insert of new log entries in MailWatch.pm ... Which will be reported (more as a warning, if this wasn't "by design") ... It is completely harmless, just ignore it. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From prandal at herefordshire.gov.uk Thu Aug 16 10:25:31 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Thu Aug 16 10:25:37 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B0472D47A@MED-CORE03-MS1.med.wayne.edu> References: <8F2A53954C22554EB75D9643FCCE0C6B0472D46F@MED-CORE03-MS1.med.wayne.edu><20070815143723.EA5881142B@panther.webvanced.nl><8F2A53954C22554EB75D9643FCCE0C6B0472D476@MED-CORE03-MS1.med.wayne.edu><46C35BE6.1050207@comcast.net> <8F2A53954C22554EB75D9643FCCE0C6B0472D47A@MED-CORE03-MS1.med.wayne.edu> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA0169FEB1@HC-MBX02.herefordshire.gov.uk> It might not resolve them, but the improved spamassassin -D output might point you in the right direction. Cherrs, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Rose, Bobby > Sent: 15 August 2007 21:57 > To: MailScanner discussion > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 > and 3.2.3 > > > ..../perl5/site_perl/5.8.x/SpamAssassin/Dns.pm is the one I replaced. > > SA does not change other perl modules especially not Net::DNS > > I have just reinstalled 3.2.3 with the patch mentioned in Bug 5589. I > won't know if it resolves my performance observations until later > tomorrow (EST) > > Bobby Rose > Senior Systems Administrator > MSIS Network Operations > Wayne State University School of Medicine > > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Ed > Bruce > Sent: Wednesday, August 15, 2007 4:03 PM > To: MailScanner discussion > Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 > and 3.2.3 > > Rose, Bobby wrote: > > Ok it's 1EST here and the huge delays that I found on Fri, Mon and > > Tues when I was running 3.2.3 are not occurring. My mqueue.in has > > remained swift and steady and the number of Batch 30s is > down to only > > 13 after 24k messsages processed by MS so far today. Today, I'm > > running with SA > > 3.2.3 but with the DNS.pm from 3.2.1. Previous days with > SA 3.2.3, my > > > batch 30's were in the 200-300 range because of the delays > introduced > > in 3.2.2-.3. Previously at this time with 3.2.2 and 3.2.3, my > > mqueue.in would be backed up to 700-900 messages which although is > > normal load for this time of day, it wasn't normal for the > queue to be > backing up. > > I could find a Dns.pm in the SpamAssassin tar file but not a DNS.pm. I > can find a DNS.pm in: > > /usr/lib/perl5/site_perl/5.8.0/i386-linux-thread-multi/Net/DNS.pm > > There is also a Dns.pm in: > > /usr/lib/perl5/site_perl/5.8.0/Mail/SpamAssassin/Dns.pm > > In my Mail-SpamAssassin-3.2.1 I see this: > > Mail-SpamAssassin-3.2.1/lib/Mail/SpamAssassin/Dns.pm > > > So which file (DNS.pm or Dns.pm) did you change? > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From prandal at herefordshire.gov.uk Thu Aug 16 10:29:33 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Thu Aug 16 10:29:34 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <11a8463a5b71fa40b7327e8688084a26@solidstatelogic.com> References: <11a8463a5b71fa40b7327e8688084a26@solidstatelogic.com> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA0169FEB2@HC-MBX02.herefordshire.gov.uk> Yes, sa-compile causes swapping!!! Sorry, couldn't resist :-) Look at the memory requirements for each MailScanner process when you've enabled sa-compile. It goes through the roof! Also, sa-complie won't make much difference if the slowness is due to DNS timeouts. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Martin.Hepworth > Sent: 16 August 2007 08:40 > To: MailScanner discussion > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 > and 3.2.3 > > If you're using sa.3.2x make sure you've run sa-compile > (it'll need re2c installed first), this does make a heck of a > difference > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Gareth > > Sent: 15 August 2007 18:08 > > To: MailScanner discussion > > Subject: RE: Performance between SpamAssassin 3.2.1 and > 3.2.2 and 3.2.3 > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > > > [mailto:mailscanner-bounces@lists.mailscanner.info]On > Behalf Of Greg > > > Matthews > > > Sent: 15 August 2007 17:56 > > > To: MailScanner discussion > > > Subject: Re: Performance between SpamAssassin 3.2.1 and > 3.2.2 and 3.2.3 > > > > > > > > > given the relatively low traffic on this thread and my > own inability to > > > spot the performance issue (even tho my upgrade to 3.2.2 > happened pretty > > > recently) suggests that most people (myself included) > have hidden the > > > problem behind a caching DNS server. Can anyone on this > thread confirm > > > whether or not they are using a caching DNS? > > > > I am using a caching DNS server and upgraded from 3.1.8 to > 3.2.3 today and > > it does seem slower but I cannot really tell since our mail > volume is very > > low and most system maintenance does not even cause the > queue to build up > > to > > 30 messages. > > I expect the majority of people are like me and have > servers which are > > capable of processing far more email than they currently > receive so each > > mailscanner run only handles a few messages so it is quick anyway. > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are > intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. > We advise > that you consider this fact when e-mailing us. > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From prandal at herefordshire.gov.uk Thu Aug 16 10:51:38 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Thu Aug 16 10:51:48 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B0472D477@MED-CORE03-MS1.med.wayne.edu> References: <46C33DFC.8000101@sendit.nodak.edu> <8F2A53954C22554EB75D9643FCCE0C6B0472D477@MED-CORE03-MS1.med.wayne.edu> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA0169FEB7@HC-MBX02.herefordshire.gov.uk> SA bug 5511 ( http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5511 ) is the likely culprit, but it is a bugfix. That fix makes SA properly use the rbl_timeout value, which the async dns code in 3.2.x didn't before that patch was applied. I'd think that the cause is slow rbl lookups and that the fix in 5511 aggravates the symptoms. See http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5511#c16 Still, 3.2.3 with the patch from bug 5589 is clearly the right thing to do, plus some tweaking of rbl_timeout. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Rose, Bobby > Sent: 15 August 2007 20:09 > To: MailScanner discussion > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 > and 3.2.3 > > It's not net lag or bad DNSBLs and it's not an increase I > rules, because > the DNS queries that I'm using are the same. Today, I am > running 3.2.3 > but using the DNS.pm from 3.2.1 and everything is running normally. > It's not DNS caching because that is also the same here and I've been > using re2c sa compiled body rules since the feature was > introduced. My > observations are that the issue was due to the changes in the DNS code > change 5511 which introduced the async issues and DNS > completion issues > discussed with ASN and DNS code changes in Bug 5589 > > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Richard > Frovarp > Sent: Wednesday, August 15, 2007 1:55 PM > To: MailScanner discussion > Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 > and 3.2.3 > > Gareth wrote: > >> -----Original Message----- > >> From: mailscanner-bounces@lists.mailscanner.info > >> [mailto:mailscanner-bounces@lists.mailscanner.info]On > Behalf Of Greg > >> Matthews > >> Sent: 15 August 2007 17:56 > >> To: MailScanner discussion > >> Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and > >> 3.2.3 > >> > >> > >> given the relatively low traffic on this thread and my own > inability > >> to spot the performance issue (even tho my upgrade to > 3.2.2 happened > >> pretty > >> recently) suggests that most people (myself included) have > hidden the > > >> problem behind a caching DNS server. Can anyone on this thread > >> confirm whether or not they are using a caching DNS? > >> > > > > I am using a caching DNS server and upgraded from 3.1.8 to > 3.2.3 today > > > and it does seem slower but I cannot really tell since our > mail volume > > > is very low and most system maintenance does not even cause > the queue > > to build up to 30 messages. > > I expect the majority of people are like me and have > servers which are > > > capable of processing far more email than they currently receive so > > each mailscanner run only handles a few messages so it is quick > anyway. > > > > > 3.2.x has more rules than 3.1.x. This will naturally result in a > slowdown of processing. sa-compile is supposed to make rule checking > quicker, so you end up in a wash there if using sa-compile. > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From MailScanner at ecs.soton.ac.uk Thu Aug 16 11:15:49 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 16 11:16:22 2007 Subject: Release 4.63.2 beta In-Reply-To: References: <46C35D0A.8060108@ecs.soton.ac.uk> Message-ID: <46C423D5.1000205@ecs.soton.ac.uk> It has nothing to do with the PDFInfo plugin whatsoever. That is separate and gives you metadata about the PDF file, not any text inside it. Kai Schaetzl wrote: > Julian Field wrote on Wed, 15 Aug 2007 21:07:38 +0100: > > >> It >> won't be effective on PDF files however, as these are compressed >> internally >> so there is no readable text anywhere in the file. >> > > I'm not using the SA PDFInfo plugin, this comment suggests that this > plugin wouldn't work in the past with MailScanner, but might now? Is this > correct? > > Kai > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Thu Aug 16 11:16:20 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 16 11:16:34 2007 Subject: Release 4.63.2 beta In-Reply-To: References: <46C35D0A.8060108@ecs.soton.ac.uk> Message-ID: <46C423F4.8040200@ecs.soton.ac.uk> That's why you can edit the files I supply! Don't like something? Then change it. Mark Nienberg wrote: > Julian Field wrote: > >> 2 Added *.fdf to the list of dangerous filenames. Opening a .fdf file >> can >> cause the loading of any file on the internet into Adobe Acrobat. > > There are perfectly legitimate reasons to send email messages with fdf > files attached. If you use the "browser-based review" feature of > Acrobat that allows multiple users to review and comment on a pdf > file, then the automatically generated email invitations will have an > fdf file attached. The user clicks on the fdf file to open the > document in Acrobat. The document is usually on a webdav server. Each > user's comments are then sent to and saved on the webdav server by the > Acrobat program. > > Blocking fdf files will effectively disable one of the key features of > Acrobat. > > Mark > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From maillists at conactive.com Thu Aug 16 11:31:16 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu Aug 16 11:31:18 2007 Subject: Release 4.63.2 beta In-Reply-To: <1187217468.23927.3.camel@csmdv.axint.net> References: <46C35D0A.8060108@ecs.soton.ac.uk> <1187217468.23927.3.camel@csmdv.axint.net> Message-ID: Chris Stone wrote on Wed, 15 Aug 2007 16:37:48 -0600: > working great. Thanks for the clarification. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Thu Aug 16 11:57:32 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu Aug 16 11:57:34 2007 Subject: perl upgrade borks ms In-Reply-To: <200708160713.l7G7Dhai012763@sinclaire.sibble.net> References: <200708152310.l7FNAP0B011614@sinclaire.sibble.net>, <46C39BC4.9010105@elirion.net>, <200708160447.l7G4liKw012331@sinclaire.sibble.net> <200708160713.l7G7Dhai012763@sinclaire.sibble.net> Message-ID: Harondel J. Sibble wrote on Thu, 16 Aug 2007 00:13:50 -0700: > http://www.mailscanner.info/install/perl.shtml Hm, where's that page referenced? I'm trying to get on it from http://www.mailscanner.info/install_guides.html which would be a natural way to find it, but I can't find a path to it. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Thu Aug 16 11:57:32 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu Aug 16 11:57:35 2007 Subject: perl upgrade borks ms In-Reply-To: <200708152310.l7FNAP0B011614@sinclaire.sibble.net> References: <200708152310.l7FNAP0B011614@sinclaire.sibble.net> Message-ID: Harondel J. Sibble wrote on Wed, 15 Aug 2007 16:10:32 -0700: > Yum upgraded Perl from 5.805 to 5.8.5 this morning and things went sideways. This can happen if perl gets updated via rpm and you installed some modules *not* via rpm. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From MailScanner at ecs.soton.ac.uk Thu Aug 16 12:04:00 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 16 12:04:11 2007 Subject: perl upgrade borks ms In-Reply-To: References: <200708152310.l7FNAP0B011614@sinclaire.sibble.net>, <46C39BC4.9010105@elirion.net>, <200708160447.l7G4liKw012331@sinclaire.sibble.net> <200708160713.l7G7Dhai012763@sinclaire.sibble.net> Message-ID: <46C42F20.7070108@ecs.soton.ac.uk> Kai Schaetzl wrote: > Harondel J. Sibble wrote on Thu, 16 Aug 2007 00:13:50 -0700: > > >> http://www.mailscanner.info/install/perl.shtml >> > > Hm, where's that page referenced? I'm trying to get on it from > http://www.mailscanner.info/install_guides.html which would be a natural > way to find it, but I can't find a path to it. > That was an old unlinked document from a previous version of the website, don't know how he found it. It's gone now. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From daniel at bokko.nl Thu Aug 16 12:17:02 2007 From: daniel at bokko.nl (Daniel Eiland) Date: Thu Aug 16 12:17:16 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <46C33029.1000406@nerc.ac.uk> Message-ID: <20070816110440.5099611868@panther.webvanced.nl> I am using a normal non caching BIND nameserver, no DNS forwarder. With 3.2.3 performance decreased from ~50Kb to about 300bytes per second. After disabling Mail::SpamAssassin::Plugin::URIDNSBL it is slightly faster. Spam Checks completed at 4268 bytes per second Still not my 50Kb i was used to. System load is around 0,7 during the day on my freebsd dual 2,4ghz xeon system, 1gb ram and 8 mailscanner childs. System is handling about 30k emails a day. -----Oorspronkelijk bericht----- Van: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Namens Greg Matthews Verzonden: woensdag 15 augustus 2007 18:56 Aan: MailScanner discussion Onderwerp: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 Daniel Eiland wrote: > I am also seeing a dramatic performance decrease. > My mailserver does around 30k emails a day, no problem with my previous > spamassassin install, but after upgrading to 3.2.3 my queue is always around > 1000 e-mails and emails are scanned with a delay of around 2 hours. > > The strange thing is my system is 70-90% idle, so a DNS problem sounds very > likely to me. given the relatively low traffic on this thread and my own inability to spot the performance issue (even tho my upgrade to 3.2.2 happened pretty recently) suggests that most people (myself included) have hidden the problem behind a caching DNS server. Can anyone on this thread confirm whether or not they are using a caching DNS? I've attached a png from one of my relays showing spam check speed. The upgrade happened right at the end of July on this box (more or less where you see the red line). There is no noticeable drop in performance. The dark blue line shows the spam check speed and the average for those weeks is 89.5kB/s the magenta line is the max spam check speed. Note that this is SA only. Virus checks and the like make the overall figures barely register at the bottom of the graph! This is a (~5 years) old dual Xeon currently pushing around 20-25k message per day. > > In my maillog I log the speed, I get around 300 bytes per second! That's > terribly slow. With a similar server, but with 3.2.1i get 45000 bytes per > second. > > There must be something seriously wrong I think. > I tried disabling plugins, but no significant difference. > > I hope someone has a solution for this. have you tried installing a caching DNS? > > Daniel -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford -- This message (and any attachments) is for the recipient only. NERC is subject to the Freedom of Information Act 2000 and the contents of this email and any reply you make may be disclosed by NERC unless it is exempt from release under the Act. Any material supplied to NERC may be stored in an electronic records management system. From goetz.reinicke at filmakademie.de Thu Aug 16 13:52:49 2007 From: goetz.reinicke at filmakademie.de (=?ISO-8859-15?Q?G=F6tz_Reinicke?=) Date: Thu Aug 16 13:53:23 2007 Subject: Problme with some mails - (no null-header or sender address) Message-ID: <46C448A1.2090205@filmakademie.de> Hi, I recently noticed, that all notifications from our trouble ticket serevr to me are marked as spam. I can't remember what I may have changed, but AFAIK I did only the regular updates to mailscanner. The header got this information: X-Mailscanner-SpamCheck: (no null-header or sender address) What may be the problem, or which information are needed to help/troubleshoot? Redhat EL 5 - 2.6.18-8.1.6.el5 mailscanner-4.62.9-1 spamassassin-3.2.0-1.el5.rf perl-5.8.8-10 Thanks and best regards! G?tz Reinicke -- G?tz Reinicke IT Koordinator Tel. +49 7141 969 420 Fax +49 7141 969 55 420 E-Mail goetz.reinicke@filmakademie.de Filmakademie Baden-W?rttemberg GmbH Mathildenstr. 20 71638 Ludwigsburg www.filmakademie.de Eintragung Amtsgericht Stuttgart HRB 205016 Vorsitzender des Aufsichtsrats: Dr. Christoph Palmer, MdL, Minister a.D. Gesch?ftsf?hrer: Prof. Thomas Schadt From MailScanner at ecs.soton.ac.uk Thu Aug 16 13:59:53 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 16 14:00:03 2007 Subject: Problme with some mails - (no null-header or sender address) In-Reply-To: <46C448A1.2090205@filmakademie.de> References: <46C448A1.2090205@filmakademie.de> Message-ID: <46C44A49.2000304@ecs.soton.ac.uk> The simplest solution is to set Use Watermarking = no in MailScanner.conf. G?tz Reinicke wrote: > Hi, > > I recently noticed, that all notifications from our trouble ticket > serevr to me are marked as spam. > > I can't remember what I may have changed, but AFAIK I did only the > regular updates to mailscanner. > > The header got this information: > > X-Mailscanner-SpamCheck: (no null-header or sender address) > > > What may be the problem, or which information are needed to > help/troubleshoot? > > Redhat EL 5 - 2.6.18-8.1.6.el5 > mailscanner-4.62.9-1 > spamassassin-3.2.0-1.el5.rf > perl-5.8.8-10 > > > Thanks and best regards! > > G?tz Reinicke > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From goetz.reinicke at filmakademie.de Thu Aug 16 14:10:38 2007 From: goetz.reinicke at filmakademie.de (=?ISO-8859-15?Q?G=F6tz_Reinicke?=) Date: Thu Aug 16 14:10:54 2007 Subject: Problme with some mails - (no null-header or sender address) In-Reply-To: <46C44A49.2000304@ecs.soton.ac.uk> References: <46C448A1.2090205@filmakademie.de> <46C44A49.2000304@ecs.soton.ac.uk> Message-ID: <46C44CCE.8020000@filmakademie.de> Thanks, works. /G?tz Julian Field schrieb: > The simplest solution is to set > Use Watermarking = no > in MailScanner.conf. > > G?tz Reinicke wrote: >> Hi, >> >> I recently noticed, that all notifications from our trouble ticket >> serevr to me are marked as spam. >> >> I can't remember what I may have changed, but AFAIK I did only the >> regular updates to mailscanner. >> >> The header got this information: >> >> X-Mailscanner-SpamCheck: (no null-header or sender address) -- G?tz Reinicke IT Koordinator Tel. +49 7141 969 420 Fax +49 7141 969 55 420 E-Mail goetz.reinicke@filmakademie.de Filmakademie Baden-W?rttemberg GmbH Mathildenstr. 20 71638 Ludwigsburg www.filmakademie.de Eintragung Amtsgericht Stuttgart HRB 205016 Vorsitzender des Aufsichtsrats: Dr. Christoph Palmer, MdL, Minister a.D. Gesch?ftsf?hrer: Prof. Thomas Schadt From brose at med.wayne.edu Thu Aug 16 14:13:50 2007 From: brose at med.wayne.edu (Rose, Bobby) Date: Thu Aug 16 14:13:56 2007 Subject: Problme with some mails - (no null-header or sender address) In-Reply-To: <46C448A1.2090205@filmakademie.de> References: <46C448A1.2090205@filmakademie.de> Message-ID: <8F2A53954C22554EB75D9643FCCE0C6B0472D47F@MED-CORE03-MS1.med.wayne.edu> If you are going to use "Check Watermarks With No Sender" then you should probably make it a rule and add your trusted exceptions. Your ticket system is using the null address but doesn't have a watermark which means it wasn't processed locally by your MailScanner server. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of G?tz Reinicke Sent: Thursday, August 16, 2007 8:53 AM To: 'MailScanner discussion' Subject: Problme with some mails - (no null-header or sender address) Hi, I recently noticed, that all notifications from our trouble ticket serevr to me are marked as spam. I can't remember what I may have changed, but AFAIK I did only the regular updates to mailscanner. The header got this information: X-Mailscanner-SpamCheck: (no null-header or sender address) What may be the problem, or which information are needed to help/troubleshoot? Redhat EL 5 - 2.6.18-8.1.6.el5 mailscanner-4.62.9-1 spamassassin-3.2.0-1.el5.rf perl-5.8.8-10 Thanks and best regards! G?tz Reinicke -- G?tz Reinicke IT Koordinator Tel. +49 7141 969 420 Fax +49 7141 969 55 420 E-Mail goetz.reinicke@filmakademie.de Filmakademie Baden-W?rttemberg GmbH Mathildenstr. 20 71638 Ludwigsburg www.filmakademie.de Eintragung Amtsgericht Stuttgart HRB 205016 Vorsitzender des Aufsichtsrats: Dr. Christoph Palmer, MdL, Minister a.D. Gesch?ftsf?hrer: Prof. Thomas Schadt -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From prandal at herefordshire.gov.uk Thu Aug 16 15:30:57 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Thu Aug 16 15:31:03 2007 Subject: MailScanner --value broken? Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA0169FF64@HC-MBX02.herefordshire.gov.uk> Using 4.63.2: #MailScanner --value=virusscanning --to=someuser@somewhere.com Can't call method "DFileName" on an undefined value at /usr/lib/MailScanner/MailScanner/SMDiskStore.pm line 90. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK From ssilva at sgvwater.com Thu Aug 16 17:36:53 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 16 17:37:20 2007 Subject: perl upgrade borks ms In-Reply-To: <200708152310.l7FNAP0B011614@sinclaire.sibble.net> References: <200708152310.l7FNAP0B011614@sinclaire.sibble.net> Message-ID: Harondel J. Sibble spake the following on 8/15/2007 4:10 PM: > Okay, Centos 3.x machine running MS 4.57.6-1 > > Yum upgraded Perl from 5.805 to 5.8.5 this morning and things went sideways. > > Restarting MS gives the following > > # /etc/init.d/MailScanner restart > Shutting down MailScanner daemons: > MailScanner: [FAILED] > incoming postfix: [ OK ] > outgoing postfix: [ OK ] > Starting MailScanner daemons: > incoming postfix: [ OK ] > outgoing postfix: [ OK ] > MailScanner: is only avaliable with the XS version at > /usr/lib/perl5/site_perl/5.8.5/Compress/Zlib.pm line 9 > BEGIN failed--compilation aborted at > /usr/lib/perl5/site_perl/5.8.5/Compress/Zlib.pm line 9. > Compilation failed in require at > /usr/lib/perl5/vendor_perl/5.8.5/Archive/Zip.pm line 24. > BEGIN failed--compilation aborted at > /usr/lib/perl5/vendor_perl/5.8.5/Archive/Zip.pm line 24. > Compilation failed in require at /usr/lib/MailScanner/MailScanner/Message.pm > line 48. > BEGIN failed--compilation aborted at > /usr/lib/MailScanner/MailScanner/Message.pm line 48. > Compilation failed in require at /usr/sbin/MailScanner line 79. > BEGIN failed--compilation aborted at /usr/sbin/MailScanner line 79. > [ OK ] > > > Googling got me a few things, one involved a perlinstaller script from CPanel > which we don't use. Trying to download and install the package anyways as per > here > http://www.configserver.co.uk/blog/index.php?catid=6&results=1&page=5 > failed-perl-problem.html> > > I tried reinstalling the modules in question, but both > > install Compress::Zlib > install Bundle::CPAN > > fail with a lot of the following errors > > /02_methods............ok > t/03_file...............Use of uninitialized value in concatenation (.) or > string at /usr/lib/perl5/5.8.5/i386-linux-thread-multi/Scalar/Util.pm > line 30. > > Also tried rerunning the install script for the current version of MS and > then installing the newly recreated rpm, no joy. This was one of the > suggestions in the list logs, but sadly it didn't help. > > Any suggestions on how to fix this quickly? > > Thanks > > > Did the perl upgrade leave you with 2 perls installed? MailScanner really hates that. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From Jim at jameswest.com Thu Aug 16 18:04:34 2007 From: Jim at jameswest.com (Jim West) Date: Thu Aug 16 18:05:04 2007 Subject: perl upgrade borks ms In-Reply-To: References: <200708152310.l7FNAP0B011614@sinclaire.sibble.net> Message-ID: <14616.192.25.240.225.1187283874.squirrel@mail.jameswest.com> I had run into this problem yesterday. This appears to be with ZLib 1.42 don't use it. I had to remove PERL and re-install it. Upgraded everything BUT the Zlib package. Re-installed MailScanner and all was well. I think I narrowed it down to List::Utils having an XS issue. - Jim > Harondel J. Sibble spake the following on 8/15/2007 4:10 PM: >> Okay, Centos 3.x machine running MS 4.57.6-1 >> >> Yum upgraded Perl from 5.805 to 5.8.5 this morning and things went >> sideways. >> >> Restarting MS gives the following >> >> # /etc/init.d/MailScanner restart >> Shutting down MailScanner daemons: >> MailScanner: [FAILED] >> incoming postfix: [ OK ] >> outgoing postfix: [ OK ] >> Starting MailScanner daemons: >> incoming postfix: [ OK ] >> outgoing postfix: [ OK ] >> MailScanner: is only avaliable with the XS version at >> /usr/lib/perl5/site_perl/5.8.5/Compress/Zlib.pm line 9 >> BEGIN failed--compilation aborted at >> /usr/lib/perl5/site_perl/5.8.5/Compress/Zlib.pm line 9. >> Compilation failed in require at >> /usr/lib/perl5/vendor_perl/5.8.5/Archive/Zip.pm line 24. >> BEGIN failed--compilation aborted at >> /usr/lib/perl5/vendor_perl/5.8.5/Archive/Zip.pm line 24. >> Compilation failed in require at >> /usr/lib/MailScanner/MailScanner/Message.pm >> line 48. >> BEGIN failed--compilation aborted at >> /usr/lib/MailScanner/MailScanner/Message.pm line 48. >> Compilation failed in require at /usr/sbin/MailScanner line 79. >> BEGIN failed--compilation aborted at /usr/sbin/MailScanner line 79. >> [ OK ] >> >> >> Googling got me a few things, one involved a perlinstaller script from >> CPanel >> which we don't use. Trying to download and install the package anyways >> as per >> here >> http://www.configserver.co.uk/blog/index.php?catid=6&results=1&page=5 >> > failed-perl-problem.html> >> >> I tried reinstalling the modules in question, but both >> >> install Compress::Zlib >> install Bundle::CPAN >> >> fail with a lot of the following errors >> >> /02_methods............ok >> t/03_file...............Use of uninitialized value in concatenation (.) >> or >> string at /usr/lib/perl5/5.8.5/i386-linux-thread-multi/Scalar/Util.pm >> line 30. >> >> Also tried rerunning the install script for the current version of MS >> and >> then installing the newly recreated rpm, no joy. This was one of the >> suggestions in the list logs, but sadly it didn't help. >> >> Any suggestions on how to fix this quickly? >> >> Thanks >> >> >> > Did the perl upgrade leave you with 2 perls installed? > MailScanner really hates that. > > > -- > > MailScanner is like deodorant... > You hope everybody uses it, and > you notice quickly if they don't!!!! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From mikes at hartwellcorp.com Fri Aug 17 00:07:49 2007 From: mikes at hartwellcorp.com (Michael St. Laurent) Date: Fri Aug 17 00:22:45 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 Message-ID: <3BF93070B3D1B047BA7ABF612958950D018FBC7C@hcex.hartwellcorp.com> I've got the clamav-0.91+spamassassin-3.2.1 package from the MailScanner site. Is there a way to tell it to force the install of the older version of SpamAssassin? I tried just running the install but it did not seem to replace the 3.2.3 version I've already got installed. I'm trying to revert to solve the speed issues. > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Randal, Phil > Sent: Thursday, August 16, 2007 2:30 AM > To: MailScanner discussion > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 > and 3.2.3 > > Yes, sa-compile causes swapping!!! Sorry, couldn't resist :-) > > Look at the memory requirements for each MailScanner process > when you've > enabled sa-compile. It goes through the roof! > > Also, sa-complie won't make much difference if the slowness is due to > DNS timeouts. > > Cheers, > > Phil > > -- > Phil Randal > Network Engineer > Herefordshire Council > Hereford, UK > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > > Of Martin.Hepworth > > Sent: 16 August 2007 08:40 > > To: MailScanner discussion > > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 > > and 3.2.3 > > > > If you're using sa.3.2x make sure you've run sa-compile > > (it'll need re2c installed first), this does make a heck of a > > difference > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner- > > > bounces@lists.mailscanner.info] On Behalf Of Gareth > > > Sent: 15 August 2007 18:08 > > > To: MailScanner discussion > > > Subject: RE: Performance between SpamAssassin 3.2.1 and > > 3.2.2 and 3.2.3 > > > > > > > -----Original Message----- > > > > From: mailscanner-bounces@lists.mailscanner.info > > > > [mailto:mailscanner-bounces@lists.mailscanner.info]On > > Behalf Of Greg > > > > Matthews > > > > Sent: 15 August 2007 17:56 > > > > To: MailScanner discussion > > > > Subject: Re: Performance between SpamAssassin 3.2.1 and > > 3.2.2 and 3.2.3 > > > > > > > > > > > > given the relatively low traffic on this thread and my > > own inability to > > > > spot the performance issue (even tho my upgrade to 3.2.2 > > happened pretty > > > > recently) suggests that most people (myself included) > > have hidden the > > > > problem behind a caching DNS server. Can anyone on this > > thread confirm > > > > whether or not they are using a caching DNS? > > > > > > I am using a caching DNS server and upgraded from 3.1.8 to > > 3.2.3 today and > > > it does seem slower but I cannot really tell since our mail > > volume is very > > > low and most system maintenance does not even cause the > > queue to build up > > > to > > > 30 messages. > > > I expect the majority of people are like me and have > > servers which are > > > capable of processing far more email than they currently > > receive so each > > > mailscanner run only handles a few messages so it is quick anyway. > > > > > > -- > > > MailScanner mailing list > > > mailscanner@lists.mailscanner.info > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > > ********************************************************************** > > Confidentiality : This e-mail and any attachments are > > intended for the > > addressee only and may be confidential. If they come to you > in error > > you must take no action based on them, nor must you copy or > show them > > to anyone. Please advise the sender by replying to this e-mail > > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are > entirely those of > > the author and unless specifically stated to the contrary, are not > > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > > communications medium and can be subject to data corruption. > > We advise > > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > > attachments are free from known viruses but in keeping with good > > computing practice, you should ensure that they are virus free. > > > > Red Lion 49 Ltd T/A Solid State Logic > > Registered as a limited company in England and Wales > > (Company No:5362730) > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > > United Kingdom > > > ********************************************************************** > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From gmane at tippingmar.com Fri Aug 17 02:04:32 2007 From: gmane at tippingmar.com (Mark Nienberg) Date: Fri Aug 17 02:04:37 2007 Subject: Release 4.63.2 beta In-Reply-To: <46C423F4.8040200@ecs.soton.ac.uk> References: <46C35D0A.8060108@ecs.soton.ac.uk> <46C423F4.8040200@ecs.soton.ac.uk> Message-ID: Julian Field wrote: > That's why you can edit the files I supply! Don't like something? Then > change it. > > Mark Nienberg wrote: >> Julian Field wrote: >> >>> 2 Added *.fdf to the list of dangerous filenames. Opening a .fdf file >>> can >>> cause the loading of any file on the internet into Adobe Acrobat. >> >> There are perfectly legitimate reasons to send email messages with fdf >> files attached. If you use the "browser-based review" feature of >> Acrobat that allows multiple users to review and comment on a pdf >> file, then the automatically generated email invitations will have an >> fdf file attached. The user clicks on the fdf file to open the >> document in Acrobat. The document is usually on a webdav server. Each >> user's comments are then sent to and saved on the webdav server by the >> Acrobat program. >> >> Blocking fdf files will effectively disable one of the key features of >> Acrobat. >> >> Mark >> > > Jules Agreed. Just warning others so when their power users of Acrobat start complaining, they will know why. Mark From tobias.axelsson at vxu.se Fri Aug 17 08:10:08 2007 From: tobias.axelsson at vxu.se (Tobias Axelsson) Date: Fri Aug 17 08:10:19 2007 Subject: SLES 10 experience Message-ID: <006801c7e09d$a4f44e30$ad582fc2@taxbrbr> Hi I have now in 3 years running mailscanner/mailwatch on Suse linux enterprise server 9 on three servers almost without problem. Now we need more performance and gonna replace them with three new bladeservers 2x4quadcore/6GB ram and no disk. Becourse of the blade-structure, I gonna need to san-boot them, (the systemdisk is a SAN-disk) and therefor it requires SuSE linux enterprise 10. Do someone have good experience with SLES10? A lot is changed... Thanks, Tobias Sweden -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070817/5b72aba2/attachment.html From list-mailscanner at linguaphone.com Fri Aug 17 09:28:13 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Fri Aug 17 09:28:21 2007 Subject: Just subscribed to the spamhaus data feed Message-ID: <1187339293.6290.4.camel@gblades-suse.linguaphone-intranet.co.uk> I have just subscribed to the spamhaus data feed service and configured the RBL in postfix. In the spamassassin configuration I have added the following scores which I believe is all I need to do to stop spamassassin trying to query the spamhaus public dns servers. Is this correct? score __RCVD_IN_ZEN 0 score RCVD_IN_SBL 0 score RCVD_IN_XBL 0 score RCVD_IN_PBL 0 Would there be any advantage to creating rules to get spamassassin to query the data feed. I assume spamassassin checks all the headers so there might be an advantage in some cases? The data feed is held on the local server so there will be practically no performance hit. From glenn.steen at gmail.com Fri Aug 17 09:49:57 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Aug 17 09:49:59 2007 Subject: SLES 10 experience In-Reply-To: <006801c7e09d$a4f44e30$ad582fc2@taxbrbr> References: <006801c7e09d$a4f44e30$ad582fc2@taxbrbr> Message-ID: <223f97700708170149s15085a11r2e3c01500528412@mail.gmail.com> On 17/08/07, Tobias Axelsson wrote: > > > > > Hi > > I have now in 3 years running mailscanner/mailwatch on Suse linux enterprise > server 9 on three servers almost without problem. > > Now we need more performance and gonna replace them with three new > bladeservers 2x4quadcore/6GB ram and no disk. > > Becourse of the blade-structure, I gonna need to san-boot them, (the > systemdisk is a SAN-disk) and therefor it requires SuSE linux enterprise 10. > Do someone have good experience with SLES10? A lot is changed... Tjena Tobias, I have no real experience, but there have been several indications on the list that the latest and greatest MailScanner works OK on that plattform. > Thanks, Tobias > Sweden How is V?xj?? I hear from my kids (visiting the in-laws) that the weather finally has turned into something resembling summer...:-) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From MailScanner at ecs.soton.ac.uk Fri Aug 17 10:00:05 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 17 10:00:41 2007 Subject: Just subscribed to the spamhaus data feed In-Reply-To: <1187339293.6290.4.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1187339293.6290.4.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <46C56395.5080609@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Gareth wrote: > I have just subscribed to the spamhaus data feed service and configured > the RBL in postfix. > > In the spamassassin configuration I have added the following scores > which I believe is all I need to do to stop spamassassin trying to query > the spamhaus public dns servers. Is this correct? > > score __RCVD_IN_ZEN 0 > score RCVD_IN_SBL 0 > score RCVD_IN_XBL 0 > score RCVD_IN_PBL 0 > > Would there be any advantage to creating rules to get spamassassin to > query the data feed. I assume spamassassin checks all the headers so > there might be an advantage in some cases? > The data feed is held on the local server so there will be practically > no performance hit. > Why not just configure the data feed zones to serve the same zone names as the originals, ie pbl.spamhaus.org and so on? That's what I did, as I didn't want to have to go through all my SpamAssassin setup tweaking all the rules and so on. It's pretty easy to do. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGxWOWEfZZRxQVtlQRAqBbAKD8gOd3fm1vAmf7a/VSxgSdd1HQtQCfb/oO PYdifddkHP4JxOm7frnhU4U= =unz2 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From martinh at solidstatelogic.com Fri Aug 17 10:07:02 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Fri Aug 17 10:07:13 2007 Subject: Just subscribed to the spamhaus data feed In-Reply-To: <1187339293.6290.4.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <8b79e3779859804bbdb740116f36b8a7@solidstatelogic.com> Gareth Correct - giving RBL's a zero score stops them running....you *may* want to think about turning all (or most) of the other RBLS's off as well. I find it can take along time to query all 20 odd of the RBL's otherwise ;-) -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Gareth > Sent: 17 August 2007 09:28 > To: MailScanner discussion > Subject: Just subscribed to the spamhaus data feed > > I have just subscribed to the spamhaus data feed service and configured > the RBL in postfix. > > In the spamassassin configuration I have added the following scores > which I believe is all I need to do to stop spamassassin trying to query > the spamhaus public dns servers. Is this correct? > > score __RCVD_IN_ZEN 0 > score RCVD_IN_SBL 0 > score RCVD_IN_XBL 0 > score RCVD_IN_PBL 0 > > Would there be any advantage to creating rules to get spamassassin to > query the data feed. I assume spamassassin checks all the headers so > there might be an advantage in some cases? > The data feed is held on the local server so there will be practically > no performance hit. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From prandal at herefordshire.gov.uk Fri Aug 17 10:09:05 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Fri Aug 17 10:09:10 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <3BF93070B3D1B047BA7ABF612958950D018FBC7C@hcex.hartwellcorp.com> References: <3BF93070B3D1B047BA7ABF612958950D018FBC7C@hcex.hartwellcorp.com> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA016A0051@HC-MBX02.herefordshire.gov.uk> Oh, there is a way to uninstall SA, look in CPAN's FAQ here for a perl script to do it: http://www.cpan.org/misc/cpan-faq.html#How_delete_Perl_modules But, I suggest that you try instead to install the patch from spamassassin bug 5589 ( http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5589 ), which, by harvesting async DNS results ASAP, should speed things up, and then do a spamassassin -D -t and look at the output to see where the delays are. Choose an email which has a uri in the body so that the uridnsbl code in SA is triggered. And check your rbl_timeout value. It might need reducing to a sensible setting. And please feed back to the SA bugzilla. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Michael St. Laurent > Sent: 17 August 2007 00:08 > To: MailScanner discussion > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 > and 3.2.3 > > I've got the clamav-0.91+spamassassin-3.2.1 package from the > MailScanner > site. Is there a way to tell it to force the install of the older > version of SpamAssassin? I tried just running the install but it did > not seem to replace the 3.2.3 version I've already got installed. > > I'm trying to revert to solve the speed issues. > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > > Of Randal, Phil > > Sent: Thursday, August 16, 2007 2:30 AM > > To: MailScanner discussion > > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 > > and 3.2.3 > > > > Yes, sa-compile causes swapping!!! Sorry, couldn't resist :-) > > > > Look at the memory requirements for each MailScanner process > > when you've > > enabled sa-compile. It goes through the roof! > > > > Also, sa-complie won't make much difference if the slowness > is due to > > DNS timeouts. > > > > Cheers, > > > > Phil > > > > -- > > Phil Randal > > Network Engineer > > Herefordshire Council > > Hereford, UK > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > > > Of Martin.Hepworth > > > Sent: 16 August 2007 08:40 > > > To: MailScanner discussion > > > Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 > > > and 3.2.3 > > > > > > If you're using sa.3.2x make sure you've run sa-compile > > > (it'll need re2c installed first), this does make a heck of a > > > difference > > > > > > -- > > > Martin Hepworth > > > Snr Systems Administrator > > > Solid State Logic > > > Tel: +44 (0)1865 842300 > > > > > > > -----Original Message----- > > > > From: mailscanner-bounces@lists.mailscanner.info > > > [mailto:mailscanner- > > > > bounces@lists.mailscanner.info] On Behalf Of Gareth > > > > Sent: 15 August 2007 18:08 > > > > To: MailScanner discussion > > > > Subject: RE: Performance between SpamAssassin 3.2.1 and > > > 3.2.2 and 3.2.3 > > > > > > > > > -----Original Message----- > > > > > From: mailscanner-bounces@lists.mailscanner.info > > > > > [mailto:mailscanner-bounces@lists.mailscanner.info]On > > > Behalf Of Greg > > > > > Matthews > > > > > Sent: 15 August 2007 17:56 > > > > > To: MailScanner discussion > > > > > Subject: Re: Performance between SpamAssassin 3.2.1 and > > > 3.2.2 and 3.2.3 > > > > > > > > > > > > > > > given the relatively low traffic on this thread and my > > > own inability to > > > > > spot the performance issue (even tho my upgrade to 3.2.2 > > > happened pretty > > > > > recently) suggests that most people (myself included) > > > have hidden the > > > > > problem behind a caching DNS server. Can anyone on this > > > thread confirm > > > > > whether or not they are using a caching DNS? > > > > > > > > I am using a caching DNS server and upgraded from 3.1.8 to > > > 3.2.3 today and > > > > it does seem slower but I cannot really tell since our mail > > > volume is very > > > > low and most system maintenance does not even cause the > > > queue to build up > > > > to > > > > 30 messages. > > > > I expect the majority of people are like me and have > > > servers which are > > > > capable of processing far more email than they currently > > > receive so each > > > > mailscanner run only handles a few messages so it is > quick anyway. > > > > > > > > -- > > > > MailScanner mailing list > > > > mailscanner@lists.mailscanner.info > > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > > > > > > > > > ********************************************************************** > > > Confidentiality : This e-mail and any attachments are > > > intended for the > > > addressee only and may be confidential. If they come to you > > in error > > > you must take no action based on them, nor must you copy or > > show them > > > to anyone. Please advise the sender by replying to this e-mail > > > immediately and then delete the original from your computer. > > > Opinion : Any opinions expressed in this e-mail are > > entirely those of > > > the author and unless specifically stated to the > contrary, are not > > > necessarily those of the author's employer. > > > Security Warning : Internet e-mail is not necessarily a secure > > > communications medium and can be subject to data corruption. > > > We advise > > > that you consider this fact when e-mailing us. > > > Viruses : We have taken steps to ensure that this e-mail and any > > > attachments are free from known viruses but in keeping with good > > > computing practice, you should ensure that they are virus free. > > > > > > Red Lion 49 Ltd T/A Solid State Logic > > > Registered as a limited company in England and Wales > > > (Company No:5362730) > > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > > > United Kingdom > > > > > > ********************************************************************** > > > > > > -- > > > MailScanner mailing list > > > mailscanner@lists.mailscanner.info > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From ms-list at alexb.ch Fri Aug 17 10:17:49 2007 From: ms-list at alexb.ch (Alex Broens) Date: Fri Aug 17 10:17:56 2007 Subject: Just subscribed to the spamhaus data feed In-Reply-To: <1187339293.6290.4.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1187339293.6290.4.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <46C567BD.4000202@alexb.ch> On 8/17/2007 10:28 AM, Gareth wrote: > I have just subscribed to the spamhaus data feed service and configured > the RBL in postfix. > > In the spamassassin configuration I have added the following scores > which I believe is all I need to do to stop spamassassin trying to query > the spamhaus public dns servers. Is this correct? > > score __RCVD_IN_ZEN 0 > score RCVD_IN_SBL 0 > score RCVD_IN_XBL 0 > score RCVD_IN_PBL 0 > > Would there be any advantage to creating rules to get spamassassin to > query the data feed. I assume spamassassin checks all the headers so > there might be an advantage in some cases? > The data feed is held on the local server so there will be practically > no performance hit. > You're missing: score URIBL_SBL 0 h2h Alex From MailScanner at ecs.soton.ac.uk Fri Aug 17 10:50:13 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 17 10:50:28 2007 Subject: Just subscribed to the spamhaus data feed In-Reply-To: <46C567BD.4000202@alexb.ch> References: <1187339293.6290.4.camel@gblades-suse.linguaphone-intranet.co.uk> <46C567BD.4000202@alexb.ch> Message-ID: <46C56F55.6040207@ecs.soton.ac.uk> Alex Broens wrote: > On 8/17/2007 10:28 AM, Gareth wrote: >> I have just subscribed to the spamhaus data feed service and configured >> the RBL in postfix. >> >> In the spamassassin configuration I have added the following scores >> which I believe is all I need to do to stop spamassassin trying to query >> the spamhaus public dns servers. Is this correct? >> >> score __RCVD_IN_ZEN 0 >> score RCVD_IN_SBL 0 >> score RCVD_IN_XBL 0 >> score RCVD_IN_PBL 0 >> >> Would there be any advantage to creating rules to get spamassassin to >> query the data feed. I assume spamassassin checks all the headers so >> there might be an advantage in some cases? If you zero those rules, and you don't set up any instead, nothing is going to use your shiny new data feed! :-) Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From list-mailscanner at linguaphone.com Fri Aug 17 10:56:18 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Fri Aug 17 10:56:30 2007 Subject: Just subscribed to the spamhaus data feed In-Reply-To: <46C56F55.6040207@ecs.soton.ac.uk> References: <1187339293.6290.4.camel@gblades-suse.linguaphone-intranet.co.uk> <46C567BD.4000202@alexb.ch> <46C56F55.6040207@ecs.soton.ac.uk> Message-ID: <1187344578.6295.14.camel@gblades-suse.linguaphone-intranet.co.uk> On Fri, 2007-08-17 at 10:50, Julian Field wrote: > Alex Broens wrote: > > On 8/17/2007 10:28 AM, Gareth wrote: > >> I have just subscribed to the spamhaus data feed service and configured > >> the RBL in postfix. > >> > >> In the spamassassin configuration I have added the following scores > >> which I believe is all I need to do to stop spamassassin trying to query > >> the spamhaus public dns servers. Is this correct? > >> > >> score __RCVD_IN_ZEN 0 > >> score RCVD_IN_SBL 0 > >> score RCVD_IN_XBL 0 > >> score RCVD_IN_PBL 0 > >> > >> Would there be any advantage to creating rules to get spamassassin to > >> query the data feed. I assume spamassassin checks all the headers so > >> there might be an advantage in some cases? > If you zero those rules, and you don't set up any instead, nothing is > going to use your shiny new data feed! > :-) > > Jules But I have them configured as RBL in postfix so they wont even reach Mailscanner :) Anyway I have added an alias so that the standard dns names also go to the data feed instead of the live servers. I have re-enabled the checks in spamassassin as there is no real disadvantage in doing so. From martinh at solidstatelogic.com Fri Aug 17 12:34:22 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Fri Aug 17 12:34:28 2007 Subject: FW: [Clamav-announce] Sourcefire acquires ClamAV Message-ID: <8b2a727cbfa41a48bffc7c6315505772@solidstatelogic.com> -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: clamav-announce-bounces@lists.clamav.net [mailto:clamav-announce- > bounces@lists.clamav.net] On Behalf Of Tomasz Kojm > Sent: 17 August 2007 12:13 > To: clamav-announce@lists.clamav.net > Subject: [Clamav-announce] Sourcefire acquires ClamAV > Importance: High > > Dear ClamAV users, > > On August 17, Sourcefire, the creators of Snort, acquired the ClamAV > project. > The full announcement is available here: > > http://www.sourcefire.com/products/clamav/ > > We'd like to thank everyone in the ClamAV community for their dedication > to > the project. The acquisition by Sourcefire is a testament to the hard work > of > the entire ClamAV community in developing cutting edge technology that > truly > showcases the promise of the open source model. With the additional > resources > Sourcefire will provide we look forward to working with the community to > continue the advancement of ClamAV. > > Sourcefire now owns ClamAV project and related trademarks, as well as the > source code copyrights held by the five principal members of the ClamAV > team. > Sourcefire will also assume control of the ClamAV project including: the > ClamAV.org domain, web site and web site content; and the ClamAV > Sourceforge > project page. > > What's most important is that from the end-user perspective very little > will > change beyond the additional resources Sourcefire will provide in our > continued efforts to advance the ClamAV technology and improve our ability > to > interact with the open source community. The core team will continue to > lead > the advancement of ClamAV and the CVD as employees of Sourcefire. Both the > ClamAV engine and the signature database will remain under GPL. > > For more information please visit our website and the following FAQ page: > > http://www.clamav.net/support/sf-faq > > The ClamAV core team. > > -- > oo ..... Tomasz Kojm > (\/)\......... http://www.ClamAV.net/gpg/tkojm.gpg > \..........._ 0DCA5A08407D5288279DB43454822DC8985A444B > //\ /\ Fri Aug 17 12:58:44 CEST 2007 > _______________________________________________ > http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-announce ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From maillists at conactive.com Fri Aug 17 12:51:25 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Fri Aug 17 12:51:33 2007 Subject: Just subscribed to the spamhaus data feed In-Reply-To: <46C567BD.4000202@alexb.ch> References: <1187339293.6290.4.camel@gblades-suse.linguaphone-intranet.co.uk> <46C567BD.4000202@alexb.ch> Message-ID: Alex Broens wrote on Fri, 17 Aug 2007 11:17:49 +0200: > You're missing: > > score URIBL_SBL 0 URIBL lookups are different, it's not the same as doing an RBL check at MTA level. Actually they are among the best hitting rules in SA. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From ms-list at alexb.ch Fri Aug 17 12:56:42 2007 From: ms-list at alexb.ch (Alex Broens) Date: Fri Aug 17 12:56:46 2007 Subject: Just subscribed to the spamhaus data feed In-Reply-To: References: <1187339293.6290.4.camel@gblades-suse.linguaphone-intranet.co.uk> <46C567BD.4000202@alexb.ch> Message-ID: <46C58CFA.1010703@alexb.ch> On 8/17/2007 1:51 PM, Kai Schaetzl wrote: > Alex Broens wrote on Fri, 17 Aug 2007 11:17:49 +0200: > >> You're missing: >> >> score URIBL_SBL 0 > > URIBL lookups are different, it's not the same as doing an RBL check at > MTA level. Actually they are among the best hitting rules in SA. I know what URIBL lookups do BUT: uridnsbl URIBL_SBL sbl.spamhaus.org. TXT So ff he doesn't want to query Spamhaus public mirrors and only query his rsync'd local data he'd need to disable that rule as well. Alex From root at doctor.nl2k.ab.ca Fri Aug 17 13:13:05 2007 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Fri Aug 17 13:15:42 2007 Subject: [tkojm@clamav.net: [Clamav-announce] Sourcefire acquires ClamAV] Message-ID: <20070817121304.GB16210@doctor.nl2k.ab.ca> Just came across the wire. Hopefully Clamav stays open source and is still free software. ----- Forwarded message from Tomasz Kojm ----- X-NetKnow-InComing-4.63.1-2-MailScanner-Watermark: 1187781257.00551@bTFop2FQc8cowalXEzXMhQ X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org X-Virus-Scanned: Debian amavisd-new at tad.clamav.net X-Original-To: clamav-announce@tad.clamav.net Delivered-To: clamav-announce@tad.clamav.net X-Virus-Scanned: Debian amavisd-new at tad.clamav.net Date: Fri, 17 Aug 2007 13:12:39 +0200 From: Tomasz Kojm To: clamav-announce@lists.clamav.net X-Mailer: Claws Mail 2.10.0 (GTK+ 2.10.13; i686-pc-linux-gnu) Importance: high X-Priority: 1 (Highest) X-Mailman-Approved-At: Fri, 17 Aug 2007 13:12:54 +0200 Subject: [Clamav-announce] Sourcefire acquires ClamAV X-BeenThere: clamav-announce@lists.clamav.net X-Mailman-Version: 2.1.9 Precedence: list Reply-To: noreply@clamav.net List-Id: ClamAV events are announced here List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: clamav-announce-bounces@lists.clamav.net X-NetKnow-InComing-4.63.1-2-MailScanner-Information: Please contact the ISP for more information X-NetKnow-InComing-4.63.1-2-MailScanner: Found to be clean X-NetKnow-InComing-4.63.1-2-MailScanner-From: clamav-announce-bounces@lists.clamav.net X-Spam-Status: No Dear ClamAV users, On August 17, Sourcefire, the creators of Snort, acquired the ClamAV project. The full announcement is available here: http://www.sourcefire.com/products/clamav/ We'd like to thank everyone in the ClamAV community for their dedication to the project. The acquisition by Sourcefire is a testament to the hard work of the entire ClamAV community in developing cutting edge technology that truly showcases the promise of the open source model. With the additional resources Sourcefire will provide we look forward to working with the community to continue the advancement of ClamAV. Sourcefire now owns ClamAV project and related trademarks, as well as the source code copyrights held by the five principal members of the ClamAV team. Sourcefire will also assume control of the ClamAV project including: the ClamAV.org domain, web site and web site content; and the ClamAV Sourceforge project page. What's most important is that from the end-user perspective very little will change beyond the additional resources Sourcefire will provide in our continued efforts to advance the ClamAV technology and improve our ability to interact with the open source community. The core team will continue to lead the advancement of ClamAV and the CVD as employees of Sourcefire. Both the ClamAV engine and the signature database will remain under GPL. For more information please visit our website and the following FAQ page: http://www.clamav.net/support/sf-faq The ClamAV core team. -- oo ..... Tomasz Kojm (\/)\......... http://www.ClamAV.net/gpg/tkojm.gpg \..........._ 0DCA5A08407D5288279DB43454822DC8985A444B //\ /\ Fri Aug 17 12:58:44 CEST 2007 _______________________________________________ http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-announce -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ----- End forwarded message ----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From mikael at syska.dk Fri Aug 17 13:20:27 2007 From: mikael at syska.dk (mikael@syska.dk) Date: Fri Aug 17 13:20:52 2007 Subject: Reports file %var% Message-ID: <65136.80.63.34.182.1187353227.squirrel@mail.syska.dk> Hey Jules and others In the reports dir ... /usr/local/share/MailScanner/reports/dk/ on freebsd most of the reports contains: "For all your IT requirements visit: http://www.transtec.co.uk" Would it not be possible to use %url-base% or %base-signature% like the others from the MailScanner.conf ... it would then be a little more easier to configure instead of removing them from all the files or write new lines ... and then at a other time ... change them again .... // ouT From ka at pacific.net Fri Aug 17 14:03:05 2007 From: ka at pacific.net (Ken A) Date: Fri Aug 17 14:03:13 2007 Subject: Just subscribed to the spamhaus data feed In-Reply-To: References: <1187339293.6290.4.camel@gblades-suse.linguaphone-intranet.co.uk> <46C567BD.4000202@alexb.ch> Message-ID: <46C59C89.3070304@pacific.net> Kai Schaetzl wrote: > Alex Broens wrote on Fri, 17 Aug 2007 11:17:49 +0200: > >> You're missing: >> >> score URIBL_SBL 0 > > URIBL lookups are different, it's not the same as doing an RBL check at > MTA level. Actually they are among the best hitting rules in SA. > > Kai > Yes. Also SA will hit received header lines, which postfix probably won't be checking, so it would be a mistake to turn the SA checks off. Ken -- Ken Anderson Pacific.Net From martinh at solidstatelogic.com Fri Aug 17 14:04:35 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Fri Aug 17 14:04:49 2007 Subject: [tkojm@clamav.net: [Clamav-announce] Sourcefire acquires ClamAV] In-Reply-To: <20070817121304.GB16210@doctor.nl2k.ab.ca> Message-ID: Dave Heads up on your X- headers - a dot is not allowed before the : and may (will) screw up certain MDA's.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Dave Shariff Yadallee - > System Administrator a.k.a. The Root of the Problem > Sent: 17 August 2007 13:13 > To: mailscanner@lists.mailscanner.info > Subject: [tkojm@clamav.net: [Clamav-announce] Sourcefire acquires ClamAV] > > Just came across the wire. Hopefully Clamav stays open source > and is still free software. > > > ----- Forwarded message from Tomasz Kojm ----- > > X-NetKnow-InComing-4.63.1-2-MailScanner-Watermark: > 1187781257.00551@bTFop2FQc8cowalXEzXMhQ > X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org > X-Virus-Scanned: Debian amavisd-new at tad.clamav.net > X-Original-To: clamav-announce@tad.clamav.net > Delivered-To: clamav-announce@tad.clamav.net > X-Virus-Scanned: Debian amavisd-new at tad.clamav.net > Date: Fri, 17 Aug 2007 13:12:39 +0200 > From: Tomasz Kojm > To: clamav-announce@lists.clamav.net > X-Mailer: Claws Mail 2.10.0 (GTK+ 2.10.13; i686-pc-linux-gnu) > Importance: high > X-Priority: 1 (Highest) > X-Mailman-Approved-At: Fri, 17 Aug 2007 13:12:54 +0200 > Subject: [Clamav-announce] Sourcefire acquires ClamAV > X-BeenThere: clamav-announce@lists.clamav.net > X-Mailman-Version: 2.1.9 > Precedence: list > Reply-To: noreply@clamav.net > List-Id: ClamAV events are announced here announce.lists.clamav.net> > List-Unsubscribe: bin/mailman/listinfo/clamav-announce>, > request@lists.clamav.net?subject=unsubscribe> > List-Post: > List-Help: > List-Subscribe: announce>, > > Errors-To: clamav-announce-bounces@lists.clamav.net > X-NetKnow-InComing-4.63.1-2-MailScanner-Information: Please contact the > ISP for more information > X-NetKnow-InComing-4.63.1-2-MailScanner: Found to be clean > X-NetKnow-InComing-4.63.1-2-MailScanner-From: clamav-announce- > bounces@lists.clamav.net > X-Spam-Status: No > > Dear ClamAV users, > > On August 17, Sourcefire, the creators of Snort, acquired the ClamAV > project. > The full announcement is available here: > > http://www.sourcefire.com/products/clamav/ > > We'd like to thank everyone in the ClamAV community for their dedication > to > the project. The acquisition by Sourcefire is a testament to the hard work > of > the entire ClamAV community in developing cutting edge technology that > truly > showcases the promise of the open source model. With the additional > resources > Sourcefire will provide we look forward to working with the community to > continue the advancement of ClamAV. > > Sourcefire now owns ClamAV project and related trademarks, as well as the > source code copyrights held by the five principal members of the ClamAV > team. > Sourcefire will also assume control of the ClamAV project including: the > ClamAV.org domain, web site and web site content; and the ClamAV > Sourceforge > project page. > > What's most important is that from the end-user perspective very little > will > change beyond the additional resources Sourcefire will provide in our > continued efforts to advance the ClamAV technology and improve our ability > to > interact with the open source community. The core team will continue to > lead > the advancement of ClamAV and the CVD as employees of Sourcefire. Both the > ClamAV engine and the signature database will remain under GPL. > > For more information please visit our website and the following FAQ page: > > http://www.clamav.net/support/sf-faq > > The ClamAV core team. > > -- > oo ..... Tomasz Kojm > (\/)\......... http://www.ClamAV.net/gpg/tkojm.gpg > \..........._ 0DCA5A08407D5288279DB43454822DC8985A444B > //\ /\ Fri Aug 17 12:58:44 CEST 2007 > _______________________________________________ > http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-announce > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > > ----- End forwarded message ----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From dgottsc at emory.edu Fri Aug 17 15:02:11 2007 From: dgottsc at emory.edu (Gottschalk, David) Date: Fri Aug 17 15:03:50 2007 Subject: Outbound queue delivery Message-ID: <8D2EFA3D9FD29C45BCEC3B532F0E23084131F2107F@RDPEXCH2.Eu.Emory.Edu> Over the last few days, I've been building a mail relay on Solaris using sendmail. The box is also running the latest version of MailScanner, so mail can get checked before going out. I edited the sendmail startup script, and added MailScanner and a sendmail queue runner. I've ran into something strange though now, and I've got a few questions. Mail was sitting in outbound queue for a long period of time after being processed by MailScanner. I had set the queue runner to process mail every 15 minutes, so that's understandable. I set the queue to run peristantly with the "-qp" option, and mail now gets delivered immediately after scanning. I thought though that MailScanner kicked off a sendmail process to deliver the message immediately after scanning. Is that a incorrect assumption? I have five main production boxes that deliver mail on average 10 seconds or less after MailScanner finishes scanning them, and they have a sendmail queue runner at running every 15 mins. They have a large volume of mail going through them though. So could someone explain this to me? Thanks. David Gottschalk -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070817/4144b1f4/attachment.html From MailScanner at ecs.soton.ac.uk Fri Aug 17 15:13:40 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 17 15:13:50 2007 Subject: Outbound queue delivery In-Reply-To: <8D2EFA3D9FD29C45BCEC3B532F0E23084131F2107F@RDPEXCH2.Eu.Emory.Edu> References: <8D2EFA3D9FD29C45BCEC3B532F0E23084131F2107F@RDPEXCH2.Eu.Emory.Edu> Message-ID: <46C5AD14.9010708@ecs.soton.ac.uk> In MailScanner.conf, what is "Delivery Method" set to? It should always be "batch". Gottschalk, David wrote: > > Over the last few days, I?ve been building a mail relay on Solaris > using sendmail. The box is also running the latest version of > MailScanner, so mail can get checked before going out. > > I edited the sendmail startup script, and added MailScanner and a > sendmail queue runner. I?ve ran into something strange though now, and > I?ve got a few questions. > > Mail was sitting in outbound queue for a long period of time after > being processed by MailScanner. I had set the queue runner to process > mail every 15 minutes, so that?s understandable. > > I set the queue to run peristantly with the ?-qp? option, and mail now > gets delivered immediately after scanning. > > I thought though that MailScanner kicked off a sendmail process to > deliver the message immediately after scanning. Is that a incorrect > assumption? > > I have five main production boxes that deliver mail on average 10 > seconds or less after MailScanner finishes scanning them, and they > have a sendmail queue runner at running every 15 mins. They have a > large volume of mail going through them though. > > So could someone explain this to me? > > Thanks. > > David Gottschalk > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From dgottsc at emory.edu Fri Aug 17 15:17:02 2007 From: dgottsc at emory.edu (Gottschalk, David) Date: Fri Aug 17 15:17:12 2007 Subject: Outbound queue delivery In-Reply-To: <46C5AD14.9010708@ecs.soton.ac.uk> References: <8D2EFA3D9FD29C45BCEC3B532F0E23084131F2107F@RDPEXCH2.Eu.Emory.Edu> <46C5AD14.9010708@ecs.soton.ac.uk> Message-ID: <8D2EFA3D9FD29C45BCEC3B532F0E23084131F21091@RDPEXCH2.Eu.Emory.Edu> It's set to batch. David Gottschalk -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian Field Sent: Friday, August 17, 2007 10:14 AM To: MailScanner discussion Subject: Re: Outbound queue delivery In MailScanner.conf, what is "Delivery Method" set to? It should always be "batch". Gottschalk, David wrote: > > Over the last few days, I've been building a mail relay on Solaris > using sendmail. The box is also running the latest version of > MailScanner, so mail can get checked before going out. > > I edited the sendmail startup script, and added MailScanner and a > sendmail queue runner. I've ran into something strange though now, and > I've got a few questions. > > Mail was sitting in outbound queue for a long period of time after > being processed by MailScanner. I had set the queue runner to process > mail every 15 minutes, so that's understandable. > > I set the queue to run peristantly with the "-qp" option, and mail now > gets delivered immediately after scanning. > > I thought though that MailScanner kicked off a sendmail process to > deliver the message immediately after scanning. Is that a incorrect > assumption? > > I have five main production boxes that deliver mail on average 10 > seconds or less after MailScanner finishes scanning them, and they > have a sendmail queue runner at running every 15 mins. They have a > large volume of mail going through them though. > > So could someone explain this to me? > > Thanks. > > David Gottschalk > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From prandal at herefordshire.gov.uk Fri Aug 17 15:19:43 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Fri Aug 17 15:19:53 2007 Subject: MailScanner --value broken? In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA0169FF64@HC-MBX02.herefordshire.gov.uk> References: <7EF0EE5CB3B263488C8C18823239BEBA0169FF64@HC-MBX02.herefordshire.gov.uk> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA016A0153@HC-MBX02.herefordshire.gov.uk> Nudges Julian... Any ideas on this one? Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Randal, Phil > Sent: 16 August 2007 15:31 > To: mailscanner@lists.mailscanner.info > Subject: MailScanner --value broken? > > Using 4.63.2: > > #MailScanner --value=virusscanning --to=someuser@somewhere.com > Can't call method "DFileName" on an undefined value at > /usr/lib/MailScanner/MailScanner/SMDiskStore.pm line 90. > > Cheers, > > Phil > -- > Phil Randal > Network Engineer > Herefordshire Council > Hereford, UK > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From bbecken at aafp.org Fri Aug 17 15:24:05 2007 From: bbecken at aafp.org (Brad Beckenhauer) Date: Fri Aug 17 15:24:32 2007 Subject: Invalid Queue Files with Postfix Message-ID: <46C56930.D87E.0068.3@aafp.org> I'm running a Postfix system using the Hold method and recently experienced a huge backlog due to "invalid queue files". Eventually the hold directory got enough invalid queue files that MailScanner switch to "accelerated" mode of processing messages. sample from the maillog: Aug 17 08:37:48 mx2 MailScanner[26605]: New Batch: Found invalid queue files: B1FB93EE101 Postcat of this file is below. Finding what's causing these invalid queue files and eliminating them is the first issue. Would a feature in MailScanner that takes action when invalid queue files are found be useful to others? Such a feature could: Detect invalid queue files (which it already does) and a) Move the invalid queue file somewhere safe and notify the admin b) postsuper -d queue_file to get rid of it. Or how about a courtesy email to the email admin when MailScanner switches to "accelerated mode". postcat B1FB93EE101 *** ENVELOPE RECORDS B1FB93EE101 *** message_size: 489 336 1 0 message_arrival_time: Thu Aug 16 09:22:55 2007 sender: Lucien.Hatch8400@hot.ee named_attribute: client_name=62.43.179.119.dyn.user.ono.com named_attribute: client_address=62.43.179.119 named_attribute: message_origin=62.43.179.119.dyn.user.ono.com[62.43.179.119] named_attribute: helo_name=62.43.179.119.dyn.user.ono.com named_attribute: protocol_name=SMTP original_recipient: tnolte@stfm.org recipient: tnolte@stfm.org *** MESSAGE CONTENTS B1FB93EE101 *** Received: from 62.43.179.119.dyn.user.ono.com (62.43.179.119.dyn.user.ono.com [62.43.179.119]) by mx1.aafp.org (Postfix) with SMTP id B1FB93EE101 for ; Thu, 16 Aug 2007 09:22:55 -0500 (CDT) Received: from martinique.hotbox.com (unknown [111.13.212.156]) by galleryplanet.com with SMTP id 5[10 Message-Id: <20070816142255.B1FB93EE101@mx1.aafp.org> Date: Thu, 16 Aug 2007 09:22:55 -0500 (CDT) From: Lucien.Hatch8400@hot.ee To: undisclosed-recipients:; *** HEADER EXTRACTED B1FB93EE101 *** *** MESSAGE FILE END B1FB93EE101 *** From MailScanner at ecs.soton.ac.uk Fri Aug 17 15:29:39 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 17 15:29:53 2007 Subject: Outbound queue delivery In-Reply-To: <8D2EFA3D9FD29C45BCEC3B532F0E23084131F21091@RDPEXCH2.Eu.Emory.Edu> References: <8D2EFA3D9FD29C45BCEC3B532F0E23084131F2107F@RDPEXCH2.Eu.Emory.Edu> <46C5AD14.9010708@ecs.soton.ac.uk> <8D2EFA3D9FD29C45BCEC3B532F0E23084131F21091@RDPEXCH2.Eu.Emory.Edu> Message-ID: <46C5B0D3.3030707@ecs.soton.ac.uk> in which case you need to determine that it is actually successfully doing the call to Sendmail and Sendmail2 (both set in MailScanner.conf). Gottschalk, David wrote: > It's set to batch. > > David Gottschalk > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian Field > Sent: Friday, August 17, 2007 10:14 AM > To: MailScanner discussion > Subject: Re: Outbound queue delivery > > In MailScanner.conf, what is "Delivery Method" set to? It should always > be "batch". > > Gottschalk, David wrote: > >> Over the last few days, I've been building a mail relay on Solaris >> using sendmail. The box is also running the latest version of >> MailScanner, so mail can get checked before going out. >> >> I edited the sendmail startup script, and added MailScanner and a >> sendmail queue runner. I've ran into something strange though now, and >> I've got a few questions. >> >> Mail was sitting in outbound queue for a long period of time after >> being processed by MailScanner. I had set the queue runner to process >> mail every 15 minutes, so that's understandable. >> >> I set the queue to run peristantly with the "-qp" option, and mail now >> gets delivered immediately after scanning. >> >> I thought though that MailScanner kicked off a sendmail process to >> deliver the message immediately after scanning. Is that a incorrect >> assumption? >> >> I have five main production boxes that deliver mail on average 10 >> seconds or less after MailScanner finishes scanning them, and they >> have a sendmail queue runner at running every 15 mins. They have a >> large volume of mail going through them though. >> >> So could someone explain this to me? >> >> Thanks. >> >> David Gottschalk >> >> > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > Need help customising MailScanner? > Contact me! > Need help fixing or optimising your systems? > Contact me! > Need help getting you started solving new requirements from your boss? > Contact me! > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From maillists at conactive.com Fri Aug 17 15:31:27 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Fri Aug 17 15:31:39 2007 Subject: Just subscribed to the spamhaus data feed In-Reply-To: <46C58CFA.1010703@alexb.ch> References: <1187339293.6290.4.camel@gblades-suse.linguaphone-intranet.co.uk> <46C567BD.4000202@alexb.ch> <46C58CFA.1010703@alexb.ch> Message-ID: Alex Broens wrote on Fri, 17 Aug 2007 13:56:42 +0200: > So ff he doesn't want to query Spamhaus public mirrors and only query > his rsync'd local data he'd need to disable that rule as well. You are right. I think Jules' method would be preferrable but then you don't need to disable this rule. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From MailScanner at ecs.soton.ac.uk Fri Aug 17 15:34:43 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 17 15:34:56 2007 Subject: Invalid Queue Files with Postfix In-Reply-To: <46C56930.D87E.0068.3@aafp.org> References: <46C56930.D87E.0068.3@aafp.org> Message-ID: <46C5B203.5020108@ecs.soton.ac.uk> What versions of MailScanner and Postfix are you using? If you are using a very recent Postfix, particularly if you are using milters at all, you need to be running a pretty modern MailScanner. Brad Beckenhauer wrote: > I'm running a Postfix system using the Hold method and recently > experienced a huge backlog due to "invalid queue files". Eventually the > hold directory got enough invalid queue files that MailScanner switch to > "accelerated" mode of processing messages. > > sample from the maillog: > Aug 17 08:37:48 mx2 MailScanner[26605]: New Batch: Found invalid queue > files: B1FB93EE101 > Postcat of this file is below. > > Finding what's causing these invalid queue files and eliminating them > is the first issue. > > Would a feature in MailScanner that takes action when invalid queue > files are found be useful to others? > Such a feature could: > Detect invalid queue files (which it already does) and > a) Move the invalid queue file somewhere safe and notify the admin > b) postsuper -d queue_file to get rid of it. > > Or how about a courtesy email to the email admin when MailScanner > switches to "accelerated mode". > > postcat B1FB93EE101 > > *** ENVELOPE RECORDS B1FB93EE101 *** > message_size: 489 336 1 > 0 > message_arrival_time: Thu Aug 16 09:22:55 2007 > sender: Lucien.Hatch8400@hot.ee > named_attribute: client_name=62.43.179.119.dyn.user.ono.com > named_attribute: client_address=62.43.179.119 > named_attribute: > message_origin=62.43.179.119.dyn.user.ono.com[62.43.179.119] > named_attribute: helo_name=62.43.179.119.dyn.user.ono.com > named_attribute: protocol_name=SMTP > original_recipient: tnolte@stfm.org > recipient: tnolte@stfm.org > *** MESSAGE CONTENTS B1FB93EE101 *** > Received: from 62.43.179.119.dyn.user.ono.com > (62.43.179.119.dyn.user.ono.com [62.43.179.119]) > by mx1.aafp.org (Postfix) with SMTP id B1FB93EE101 > for ; Thu, 16 Aug 2007 09:22:55 -0500 (CDT) > Received: from martinique.hotbox.com (unknown [111.13.212.156]) > by galleryplanet.com with SMTP id 5[10 > Message-Id: <20070816142255.B1FB93EE101@mx1.aafp.org> > Date: Thu, 16 Aug 2007 09:22:55 -0500 (CDT) > From: Lucien.Hatch8400@hot.ee > To: undisclosed-recipients:; > *** HEADER EXTRACTED B1FB93EE101 *** > *** MESSAGE FILE END B1FB93EE101 *** > > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Fri Aug 17 15:48:45 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 17 15:49:16 2007 Subject: Just subscribed to the spamhaus data feed In-Reply-To: References: <1187339293.6290.4.camel@gblades-suse.linguaphone-intranet.co.uk> <46C567BD.4000202@alexb.ch> <46C58CFA.1010703@alexb.ch> Message-ID: <46C5B54D.3030600@ecs.soton.ac.uk> Kai Schaetzl wrote: > Alex Broens wrote on Fri, 17 Aug 2007 13:56:42 +0200: > > >> So ff he doesn't want to query Spamhaus public mirrors and only query >> his rsync'd local data he'd need to disable that rule as well. >> > > You are right. I think Jules' method would be preferrable but then you > don't need to disable this rule. > My setup was dead easy to do, and even easier to test. You just get rbldnsd to spit out 1 line of log info a minute, and watch the number-of-queries counter increase. No mods needed to anything, so less to maintain. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From dgottsc at emory.edu Fri Aug 17 16:11:26 2007 From: dgottsc at emory.edu (Gottschalk, David) Date: Fri Aug 17 16:12:38 2007 Subject: Outbound queue delivery In-Reply-To: <46C5B0D3.3030707@ecs.soton.ac.uk> References: <8D2EFA3D9FD29C45BCEC3B532F0E23084131F2107F@RDPEXCH2.Eu.Emory.Edu> <46C5AD14.9010708@ecs.soton.ac.uk> <8D2EFA3D9FD29C45BCEC3B532F0E23084131F21091@RDPEXCH2.Eu.Emory.Edu> <46C5B0D3.3030707@ecs.soton.ac.uk> Message-ID: <8D2EFA3D9FD29C45BCEC3B532F0E23084131F210FF@RDPEXCH2.Eu.Emory.Edu> Found the problem. I had checked to make sure the "sendmail = /usr/lib/sendmail" was to the correct path before, but I didn't realize MailScanner used "sendmail2 = /usr/sbin/sendmail" to deliver clean messages. That path was incorrect for Solaris (I had copied another MailScanner.conf from another working server), so I changed it to match the first sendmail, and it's working now. Thanks for your help Julian. David Gottschalk AAIT Infrastructure Technology Services david.gottschalk@emory.edu 404.727.9744 -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian Field Sent: Friday, August 17, 2007 10:30 AM To: MailScanner discussion Subject: Re: Outbound queue delivery in which case you need to determine that it is actually successfully doing the call to Sendmail and Sendmail2 (both set in MailScanner.conf). Gottschalk, David wrote: > It's set to batch. > > David Gottschalk > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian Field > Sent: Friday, August 17, 2007 10:14 AM > To: MailScanner discussion > Subject: Re: Outbound queue delivery > > In MailScanner.conf, what is "Delivery Method" set to? It should always > be "batch". > > Gottschalk, David wrote: > >> Over the last few days, I've been building a mail relay on Solaris >> using sendmail. The box is also running the latest version of >> MailScanner, so mail can get checked before going out. >> >> I edited the sendmail startup script, and added MailScanner and a >> sendmail queue runner. I've ran into something strange though now, and >> I've got a few questions. >> >> Mail was sitting in outbound queue for a long period of time after >> being processed by MailScanner. I had set the queue runner to process >> mail every 15 minutes, so that's understandable. >> >> I set the queue to run peristantly with the "-qp" option, and mail now >> gets delivered immediately after scanning. >> >> I thought though that MailScanner kicked off a sendmail process to >> deliver the message immediately after scanning. Is that a incorrect >> assumption? >> >> I have five main production boxes that deliver mail on average 10 >> seconds or less after MailScanner finishes scanning them, and they >> have a sendmail queue runner at running every 15 mins. They have a >> large volume of mail going through them though. >> >> So could someone explain this to me? >> >> Thanks. >> >> David Gottschalk >> >> > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > Need help customising MailScanner? > Contact me! > Need help fixing or optimising your systems? > Contact me! > Need help getting you started solving new requirements from your boss? > Contact me! > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From rthrush at winbeam.com Fri Aug 17 17:21:37 2007 From: rthrush at winbeam.com (Raymond H Thrush II) Date: Fri Aug 17 17:33:48 2007 Subject: SA 3.2.3 bug/ or not bug 5557 Message-ID: <46C5CB11.2040706@winbeam.com> For the past several weeks now I have been having problems with my SA temp files. I have them mounted as tmpfs /raid/spool/MailScanner/incoming they are not being cleaned up properly. the usage grows until it fills memory and causes services to start failing. I found this http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5557 and I was wondering If any of you had anything to input on this issue. I am running centos 4 with all the latest MS/SA/clamd. It is happening on all of my gateway servers, running 6 all tied together for config's via an nfs server. I can cron it to clean up the temp directory, but that is not really a fix more of a temp solution. Raymond H Thrush II Winbeam, Inc. From bbecken at aafp.org Fri Aug 17 17:56:52 2007 From: bbecken at aafp.org (Brad Beckenhauer) Date: Fri Aug 17 17:57:16 2007 Subject: Invalid Queue Files with Postfix In-Reply-To: <46C5B203.5020108@ecs.soton.ac.uk> References: <46C56930.D87E.0068.3@aafp.org> <46C5B203.5020108@ecs.soton.ac.uk> Message-ID: <46C58CFE.D87E.0068.3@aafp.org> >>> On 8/17/2007 at 9:34 AM, in message <46C5B203.5020108@ecs.soton.ac.uk>, Julian Field wrote: > What versions of MailScanner and Postfix are you using? > If you are using a very recent Postfix, particularly if you are using > milters at all, you need to be running a pretty modern MailScanner. Currently running: postfix-2.1.5-5 upgrading to postfix-2.3.x in September 2007 MailScanner 4.60.8 also upgrading in September. Centos 4.5 At some point I'll move to sendmail when my work project load permits. Postfix has been running on 2.1.5 since June 2006, and I normally keep MailScanner up to date. It's pretty normal to find several (2-20) of these invalid queue files daily, so I check daily to make sure the queues keep clean. > > Brad Beckenhauer wrote: >> I'm running a Postfix system using the Hold method and recently >> experienced a huge backlog due to "invalid queue files". Eventually the >> hold directory got enough invalid queue files that MailScanner switch to >> "accelerated" mode of processing messages. >> >> sample from the maillog: >> Aug 17 08:37:48 mx2 MailScanner[26605]: New Batch: Found invalid queue >> files: B1FB93EE101 >> Postcat of this file is below. >> >> Finding what's causing these invalid queue files and eliminating them >> is the first issue. >> >> Would a feature in MailScanner that takes action when invalid queue >> files are found be useful to others? >> Such a feature could: >> Detect invalid queue files (which it already does) and >> a) Move the invalid queue file somewhere safe and notify the admin >> b) postsuper -d queue_file to get rid of it. >> >> Or how about a courtesy email to the email admin when MailScanner >> switches to "accelerated mode". >> >> postcat B1FB93EE101 >> >> *** ENVELOPE RECORDS B1FB93EE101 *** >> message_size: 489 336 1 >> 0 >> message_arrival_time: Thu Aug 16 09:22:55 2007 >> sender: Lucien.Hatch8400@hot.ee >> named_attribute: client_name=62.43.179.119.dyn.user.ono.com >> named_attribute: client_address=62.43.179.119 >> named_attribute: >> message_origin=62.43.179.119.dyn.user.ono.com[62.43.179.119] >> named_attribute: helo_name=62.43.179.119.dyn.user.ono.com >> named_attribute: protocol_name=SMTP >> original_recipient: tnolte@stfm.org >> recipient: tnolte@stfm.org >> *** MESSAGE CONTENTS B1FB93EE101 *** >> Received: from 62.43.179.119.dyn.user.ono.com >> (62.43.179.119.dyn.user.ono.com [62.43.179.119]) >> by mx1.aafp.org (Postfix) with SMTP id B1FB93EE101 >> for ; Thu, 16 Aug 2007 09:22:55 -0500 (CDT) >> Received: from martinique.hotbox.com (unknown [111.13.212.156]) >> by galleryplanet.com with SMTP id 5[10 >> Message-Id: <20070816142255.B1FB93EE101@mx1.aafp.org> >> Date: Thu, 16 Aug 2007 09:22:55 -0500 (CDT) >> From: Lucien.Hatch8400@hot.ee >> To: undisclosed-recipients:; >> *** HEADER EXTRACTED B1FB93EE101 *** >> *** MESSAGE FILE END B1FB93EE101 *** >> >> >> >> > > Jules From brose at med.wayne.edu Fri Aug 17 18:35:42 2007 From: brose at med.wayne.edu (Rose, Bobby) Date: Fri Aug 17 18:35:49 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B0472D477@MED-CORE03-MS1.med.wayne.edu> References: <46C33DFC.8000101@sendit.nodak.edu> <8F2A53954C22554EB75D9643FCCE0C6B0472D477@MED-CORE03-MS1.med.wayne.edu> Message-ID: <8F2A53954C22554EB75D9643FCCE0C6B0472D498@MED-CORE03-MS1.med.wayne.edu> Sorry I couldn't provide feedback yesterday because my research became skewed due to router issues at Michnet which is the backbone provider for all of the univs here in Michigan. It looks like 3.2.3 with the SA bug patch 5589 took care of the issues. After about 24k messages so far, my times and queue is normal. In fact, I've only see 6 Batches of 30s in my logs. Also the debug output of SA for the DNS timings are normal compare to what I was seeing with 3.2.3 without the patch. Bobby Rose Senior Systems Administrator MSIS Network Operations Wayne State University School of Medicine -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Rose, Bobby Sent: Wednesday, August 15, 2007 3:09 PM To: MailScanner discussion Subject: RE: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 It's not net lag or bad DNSBLs and it's not an increase I rules, because the DNS queries that I'm using are the same. Today, I am running 3.2.3 but using the DNS.pm from 3.2.1 and everything is running normally. It's not DNS caching because that is also the same here and I've been using re2c sa compiled body rules since the feature was introduced. My observations are that the issue was due to the changes in the DNS code change 5511 which introduced the async issues and DNS completion issues discussed with ASN and DNS code changes in Bug 5589 -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Richard Frovarp Sent: Wednesday, August 15, 2007 1:55 PM To: MailScanner discussion Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 Gareth wrote: >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Greg >> Matthews >> Sent: 15 August 2007 17:56 >> To: MailScanner discussion >> Subject: Re: Performance between SpamAssassin 3.2.1 and 3.2.2 and >> 3.2.3 >> >> >> given the relatively low traffic on this thread and my own inability >> to spot the performance issue (even tho my upgrade to 3.2.2 happened >> pretty >> recently) suggests that most people (myself included) have hidden the >> problem behind a caching DNS server. Can anyone on this thread >> confirm whether or not they are using a caching DNS? >> > > I am using a caching DNS server and upgraded from 3.1.8 to 3.2.3 today > and it does seem slower but I cannot really tell since our mail volume > is very low and most system maintenance does not even cause the queue > to build up to 30 messages. > I expect the majority of people are like me and have servers which are > capable of processing far more email than they currently receive so > each mailscanner run only handles a few messages so it is quick anyway. > > 3.2.x has more rules than 3.1.x. This will naturally result in a slowdown of processing. sa-compile is supposed to make rule checking quicker, so you end up in a wash there if using sa-compile. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From hvdkooij at vanderkooij.org Fri Aug 17 21:19:24 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Fri Aug 17 21:19:34 2007 Subject: Off topic - AntiVirus accuracy competition In-Reply-To: References: <3376.62.150.152.226.1185292117.squirrel@webmail.baladia.gov.kw> <46C1C7EC.9020003@USherbrooke.ca> <2e7e01c7de8d$fcf7ed10$f6e7c730$@swaney@fsl.com> Message-ID: On Wed, 15 Aug 2007, Hugo van der Kooij wrote: > The main diffeence between the old setup and the new one is the amount of > recent samples. One of the Vv partners gave me access to the raw collection > of garbage they intercepted world wide. The old testing was against relative > few recent samples. It ended up to be a single sample that shot f-prot to pieces. The results are much better now for F-Prot. Now I need to see if something else is bothering Kaspersky. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From glenn.steen at gmail.com Fri Aug 17 21:39:20 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Aug 17 21:39:22 2007 Subject: Invalid Queue Files with Postfix In-Reply-To: <46C58CFE.D87E.0068.3@aafp.org> References: <46C56930.D87E.0068.3@aafp.org> <46C5B203.5020108@ecs.soton.ac.uk> <46C58CFE.D87E.0068.3@aafp.org> Message-ID: <223f97700708171339h2115ce1fu1af220aa23462924@mail.gmail.com> On 17/08/07, Brad Beckenhauer wrote: > >>> On 8/17/2007 at 9:34 AM, in message > <46C5B203.5020108@ecs.soton.ac.uk>, Julian > Field wrote: > > What versions of MailScanner and Postfix are you using? > > If you are using a very recent Postfix, particularly if you are using > > > milters at all, you need to be running a pretty modern MailScanner. > > Currently running: > postfix-2.1.5-5 upgrading to postfix-2.3.x in September 2007 > MailScanner 4.60.8 also upgrading in September. > Centos 4.5 > At some point I'll move to sendmail when my work project load permits. > > Postfix has been running on 2.1.5 since June 2006, and I normally keep > MailScanner up to date. > It's pretty normal to find several (2-20) of these invalid queue files > daily, so I check daily to make sure the queues keep clean. Um, no ... or perhaps, depending in your normal volume that might be normal.... But really, invalid queue files aren't really ... normal:-) Being slightly intoxicated (sorry Hugo), I don't quite remember if there was any changes to my milter changes ..... after 4.60.8, but you might benefit from an upgrade. The key issue is the use of milters, but I do seem to recall there being some changes that affected all (since milters aren't an option for that old a version of postfix).... where I didn't check for the use of p records/milters before doing a spin through. Then again, the spin should only adversely affect performance, not function. So then the question becomes: how large a volume do you have? > > Brad Beckenhauer wrote: > >> I'm running a Postfix system using the Hold method and recently > >> experienced a huge backlog due to "invalid queue files". Eventually > the > >> hold directory got enough invalid queue files that MailScanner > switch to > >> "accelerated" mode of processing messages. > >> > >> sample from the maillog: > >> Aug 17 08:37:48 mx2 MailScanner[26605]: New Batch: Found invalid > queue > >> files: B1FB93EE101 > >> Postcat of this file is below. > >> > >> Finding what's causing these invalid queue files and eliminating > them > >> is the first issue. > >> > >> Would a feature in MailScanner that takes action when invalid queue > >> files are found be useful to others? > >> Such a feature could: > >> Detect invalid queue files (which it already does) and > >> a) Move the invalid queue file somewhere safe and notify the admin > >> b) postsuper -d queue_file to get rid of it. > >> > >> Or how about a courtesy email to the email admin when MailScanner > >> switches to "accelerated mode". > >> > >> postcat B1FB93EE101 > >> > >> *** ENVELOPE RECORDS B1FB93EE101 *** > >> message_size: 489 336 1 > > >> 0 > >> message_arrival_time: Thu Aug 16 09:22:55 2007 > >> sender: Lucien.Hatch8400@hot.ee > >> named_attribute: client_name=62.43.179.119.dyn.user.ono.com > >> named_attribute: client_address=62.43.179.119 > >> named_attribute: > >> message_origin=62.43.179.119.dyn.user.ono.com[62.43.179.119] > >> named_attribute: helo_name=62.43.179.119.dyn.user.ono.com > >> named_attribute: protocol_name=SMTP > >> original_recipient: tnolte@stfm.org > >> recipient: tnolte@stfm.org > >> *** MESSAGE CONTENTS B1FB93EE101 *** > >> Received: from 62.43.179.119.dyn.user.ono.com > >> (62.43.179.119.dyn.user.ono.com [62.43.179.119]) > >> by mx1.aafp.org (Postfix) with SMTP id B1FB93EE101 > >> for ; Thu, 16 Aug 2007 09:22:55 -0500 > (CDT) > >> Received: from martinique.hotbox.com (unknown [111.13.212.156]) > >> by galleryplanet.com with SMTP id 5[10 > >> Message-Id: <20070816142255.B1FB93EE101@mx1.aafp.org> > >> Date: Thu, 16 Aug 2007 09:22:55 -0500 (CDT) > >> From: Lucien.Hatch8400@hot.ee > >> To: undisclosed-recipients:; > >> *** HEADER EXTRACTED B1FB93EE101 *** > >> *** MESSAGE FILE END B1FB93EE101 *** > >> > >> > >> > >> > > > > Jules Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Fri Aug 17 21:51:20 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Aug 17 21:51:22 2007 Subject: Performance between SpamAssassin 3.2.1 and 3.2.2 and 3.2.3 In-Reply-To: <8F2A53954C22554EB75D9643FCCE0C6B0472D498@MED-CORE03-MS1.med.wayne.edu> References: <46C33DFC.8000101@sendit.nodak.edu> <8F2A53954C22554EB75D9643FCCE0C6B0472D477@MED-CORE03-MS1.med.wayne.edu> <8F2A53954C22554EB75D9643FCCE0C6B0472D498@MED-CORE03-MS1.med.wayne.edu> Message-ID: <223f97700708171351p3610ab37kba693ddc31ccb2c3@mail.gmail.com> On 17/08/07, Rose, Bobby wrote: > Sorry I couldn't provide feedback yesterday because my research became > skewed due to router issues at Michnet which is the backbone provider > for all of the univs here in Michigan. > > It looks like 3.2.3 with the SA bug patch 5589 took care of the issues. > After about 24k messages so far, my times and queue is normal. In fact, > I've only see 6 Batches of 30s in my logs. Also the debug output of SA > for the DNS timings are normal compare to what I was seeing with 3.2.3 > without the patch. > > Bobby Rose Thanks Bobby, very good to know. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From maillists at conactive.com Fri Aug 17 22:31:19 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Fri Aug 17 22:31:23 2007 Subject: Off topic - AntiVirus accuracy competition In-Reply-To: References: <3376.62.150.152.226.1185292117.squirrel@webmail.baladia.gov.kw> <46C1C7EC.9020003@USherbrooke.ca> <2e7e01c7de8d$fcf7ed10$f6e7c730$@swaney@fsl.com> Message-ID: Hugo van der Kooij wrote on Fri, 17 Aug 2007 22:19:24 +0200 (CEST): > It ended up to be a single sample that shot f-prot to pieces. The results > are much better now for F-Prot. Now I need to see if something else is > bothering Kaspersky. Thanks for the update ;-) I'm amazed about the good standing of Bitdefender and the (now) low standing of Clam. On the one machine where I have both running in parallel they always score both. I must be missing some of the viruses that cause this. Could it be that quite a few you got in your new sample actually never made it to the wild in bigger quantities? Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From bbecken at aafp.org Fri Aug 17 22:34:33 2007 From: bbecken at aafp.org (Brad Beckenhauer) Date: Fri Aug 17 22:34:50 2007 Subject: Invalid Queue Files with Postfix In-Reply-To: <223f97700708171339h2115ce1fu1af220aa23462924@mail.gmail.com> References: <46C56930.D87E.0068.3@aafp.org> <46C5B203.5020108@ecs.soton.ac.uk> <46C58CFE.D87E.0068.3@aafp.org> <223f97700708171339h2115ce1fu1af220aa23462924@mail.gmail.com> Message-ID: <46C5CE13.D87E.0068.3@aafp.org> >>> On 8/17/2007 at 3:39 PM, in message <223f97700708171339h2115ce1fu1af220aa23462924@mail.gmail.com>, "Glenn Steen" wrote: > On 17/08/07, Brad Beckenhauer wrote: >> >>> On 8/17/2007 at 9:34 AM, in message >> <46C5B203.5020108@ecs.soton.ac.uk>, Julian >> Field wrote: >> > What versions of MailScanner and Postfix are you using? >> > If you are using a very recent Postfix, particularly if you are using >> >> > milters at all, you need to be running a pretty modern MailScanner. >> >> Currently running: >> postfix-2.1.5-5 upgrading to postfix-2.3.x in September 2007 >> MailScanner 4.60.8 also upgrading in September. >> Centos 4.5 >> At some point I'll move to sendmail when my work project load permits. >> >> Postfix has been running on 2.1.5 since June 2006, and I normally keep >> MailScanner up to date. >> It's pretty normal to find several (2-20) of these invalid queue files >> daily, so I check daily to make sure the queues keep clean. > > Um, no ... or perhaps, depending in your normal volume that might be > normal.... But really, invalid queue files aren't really ... normal:-) Normal, as in "I expect to find invalid queue files in the system", not that they are supposed to be there. :-) Perhaps I should have said, on an average day, MailScanner reports finding between 2-20 of these invalid queue files. Which I manually clean out using postsuper -d queue_file. > > Being slightly intoxicated (sorry Hugo), I don't quite remember if > there was any changes to my milter changes ..... after 4.60.8, but you > might benefit from an upgrade. And I'm ready to upgrade, I see many new features in the latest code I want to try. > The key issue is the use of milters, but I do seem to recall there > being some changes that affected all (since milters aren't an option > for that old a version of postfix).... where I didn't check for the > use of p records/milters before doing a spin through. Then again, the > spin should only adversely affect performance, not function. > So then the question becomes: how large a volume do you have? Normal volume total is around 200,000 email/day with recent spikes up to 900,000 email/day as this is the busy time of year for us. Figure about 91% of the total volume is rejected/spam. I have Vispan stats if you want them. That would be a nice feature request for MailScanner, something to provide consistant volume benchmarks across all supported MailScanner platforms. Something like: MailScanner -stats or a configuration setting to enable benchmarking with the understanding that there would be system overhead associated with the additional process. > >> > Brad Beckenhauer wrote: >> >> I'm running a Postfix system using the Hold method and recently >> >> experienced a huge backlog due to "invalid queue files". Eventually >> the >> >> hold directory got enough invalid queue files that MailScanner >> switch to >> >> "accelerated" mode of processing messages. >> >> >> >> sample from the maillog: >> >> Aug 17 08:37:48 mx2 MailScanner[26605]: New Batch: Found invalid >> queue >> >> files: B1FB93EE101 >> >> Postcat of this file is below. >> >> >> >> Finding what's causing these invalid queue files and eliminating >> them >> >> is the first issue. >> >> >> >> Would a feature in MailScanner that takes action when invalid queue >> >> files are found be useful to others? >> >> Such a feature could: >> >> Detect invalid queue files (which it already does) and >> >> a) Move the invalid queue file somewhere safe and notify the admin >> >> b) postsuper -d queue_file to get rid of it. >> >> >> >> Or how about a courtesy email to the email admin when MailScanner >> >> switches to "accelerated mode". >> >> >> >> postcat B1FB93EE101 >> >> >> >> *** ENVELOPE RECORDS B1FB93EE101 *** >> >> message_size: 489 336 1 >> >> >> 0 >> >> message_arrival_time: Thu Aug 16 09:22:55 2007 >> >> sender: Lucien.Hatch8400@hot.ee >> >> named_attribute: client_name=62.43.179.119.dyn.user.ono.com >> >> named_attribute: client_address=62.43.179.119 >> >> named_attribute: >> >> message_origin=62.43.179.119.dyn.user.ono.com[62.43.179.119] >> >> named_attribute: helo_name=62.43.179.119.dyn.user.ono.com >> >> named_attribute: protocol_name=SMTP >> >> original_recipient: tnolte@stfm.org >> >> recipient: tnolte@stfm.org >> >> *** MESSAGE CONTENTS B1FB93EE101 *** >> >> Received: from 62.43.179.119.dyn.user.ono.com >> >> (62.43.179.119.dyn.user.ono.com [62.43.179.119]) >> >> by mx1.aafp.org (Postfix) with SMTP id B1FB93EE101 >> >> for ; Thu, 16 Aug 2007 09:22:55 -0500 >> (CDT) >> >> Received: from martinique.hotbox.com (unknown [111.13.212.156]) >> >> by galleryplanet.com with SMTP id 5[10 >> >> Message-Id: <20070816142255.B1FB93EE101@mx1.aafp.org> >> >> Date: Thu, 16 Aug 2007 09:22:55 -0500 (CDT) >> >> From: Lucien.Hatch8400@hot.ee >> >> To: undisclosed-recipients:; >> >> *** HEADER EXTRACTED B1FB93EE101 *** >> >> *** MESSAGE FILE END B1FB93EE101 *** >> >> >> >> >> >> >> >> >> > >> > Jules > > Cheers From hvdkooij at vanderkooij.org Sat Aug 18 10:52:23 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sat Aug 18 10:52:31 2007 Subject: Off topic - AntiVirus accuracy competition In-Reply-To: References: <3376.62.150.152.226.1185292117.squirrel@webmail.baladia.gov.kw> <46C1C7EC.9020003@USherbrooke.ca> <2e7e01c7de8d$fcf7ed10$f6e7c730$@swaney@fsl.com> Message-ID: On Fri, 17 Aug 2007, Kai Schaetzl wrote: > Hugo van der Kooij wrote on Fri, 17 Aug 2007 22:19:24 +0200 (CEST): > >> It ended up to be a single sample that shot f-prot to pieces. The results >> are much better now for F-Prot. Now I need to see if something else is >> bothering Kaspersky. > > Thanks for the update ;-) I'm amazed about the good standing of Bitdefender > and the (now) low standing of Clam. On the one machine where I have both > running in parallel they always score both. I must be missing some of the > viruses that cause this. Could it be that quite a few you got in your new > sample actually never made it to the wild in bigger quantities? A lot of them do not transfer over SMTP. So you will never see them in MS stats. I am still brooding on why Kaspersky fails so miserably. F-Prot just reported: Results of virus scanning: Files: 105963 MBRs: 0 Boot sectors: 0 Objects scanned: 120985 Infected: 42790 Suspicious: 46122 Disinfected: 0 Deleted: 0 Renamed: 0 Time: 249:21 But Kaspersky ran after that on the same collection and found: Scan summary: Files=55998 Folders=28884 Archives=6051 Packed=25723 Infected=49332 Warnings=4 Suspicios=163 Cured=0 CureFailed=0 Corrupted=121 Protected=604 Error=0 ScanTime=01:05:31 ScanSpeed=1757.622 Kb/s It seems to miss nearly half of all the files. It seems I have some work cut out for me yet. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From MailScanner at ecs.soton.ac.uk Sat Aug 18 15:09:43 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat Aug 18 15:10:22 2007 Subject: Invalid Queue Files with Postfix In-Reply-To: <46C5CE13.D87E.0068.3@aafp.org> References: <46C56930.D87E.0068.3@aafp.org> <46C5B203.5020108@ecs.soton.ac.uk> <46C58CFE.D87E.0068.3@aafp.org> <223f97700708171339h2115ce1fu1af220aa23462924@mail.gmail.com> <46C5CE13.D87E.0068.3@aafp.org> Message-ID: <46C6FDA7.3080605@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Brad Beckenhauer wrote: > > That would be a nice feature request for MailScanner, something to > provide consistant volume benchmarks across all supported MailScanner > platforms. > Something like: > MailScanner -stats > or a configuration setting to enable benchmarking with the > understanding that there would be system overhead associated with the > additional process. > What stats would you like it to log that it doesn't already? There's no communication between the child processes once they are started, but I could add a signal trap so that a kill -USR or something would make them dump some figures to some file or other, then restart the batch they were on. They already catch kill -HUP to force them to die. So exactly what do you want to do when it receives a SIGUSR? > >>>> Brad Beckenhauer wrote: >>>> >>>>> I'm running a Postfix system using the Hold method and recently >>>>> experienced a huge backlog due to "invalid queue files". >>>>> > Eventually > >>> the >>> >>>>> hold directory got enough invalid queue files that MailScanner >>>>> >>> switch to >>> >>>>> "accelerated" mode of processing messages. >>>>> >>>>> sample from the maillog: >>>>> Aug 17 08:37:48 mx2 MailScanner[26605]: New Batch: Found invalid >>>>> >>> queue >>> >>>>> files: B1FB93EE101 >>>>> Postcat of this file is below. >>>>> >>>>> Finding what's causing these invalid queue files and eliminating >>>>> >>> them >>> >>>>> is the first issue. >>>>> >>>>> Would a feature in MailScanner that takes action when invalid >>>>> > queue > >>>>> files are found be useful to others? >>>>> Such a feature could: >>>>> Detect invalid queue files (which it already does) and >>>>> a) Move the invalid queue file somewhere safe and notify the >>>>> > admin > >>>>> b) postsuper -d queue_file to get rid of it. >>>>> >>>>> Or how about a courtesy email to the email admin when >>>>> > MailScanner > >>>>> switches to "accelerated mode". >>>>> >>>>> postcat B1FB93EE101 >>>>> >>>>> *** ENVELOPE RECORDS B1FB93EE101 *** >>>>> message_size: 489 336 1 >>>>> >>>>> 0 >>>>> message_arrival_time: Thu Aug 16 09:22:55 2007 >>>>> sender: Lucien.Hatch8400@hot.ee >>>>> named_attribute: client_name=62.43.179.119.dyn.user.ono.com >>>>> named_attribute: client_address=62.43.179.119 >>>>> named_attribute: >>>>> message_origin=62.43.179.119.dyn.user.ono.com[62.43.179.119] >>>>> named_attribute: helo_name=62.43.179.119.dyn.user.ono.com >>>>> named_attribute: protocol_name=SMTP >>>>> original_recipient: tnolte@stfm.org >>>>> recipient: tnolte@stfm.org >>>>> *** MESSAGE CONTENTS B1FB93EE101 *** >>>>> Received: from 62.43.179.119.dyn.user.ono.com >>>>> (62.43.179.119.dyn.user.ono.com [62.43.179.119]) >>>>> by mx1.aafp.org (Postfix) with SMTP id B1FB93EE101 >>>>> for ; Thu, 16 Aug 2007 09:22:55 -0500 >>>>> >>> (CDT) >>> >>>>> Received: from martinique.hotbox.com (unknown [111.13.212.156]) >>>>> by galleryplanet.com with SMTP id 5[10 >>>>> Message-Id: <20070816142255.B1FB93EE101@mx1.aafp.org> >>>>> Date: Thu, 16 Aug 2007 09:22:55 -0500 (CDT) >>>>> From: Lucien.Hatch8400@hot.ee >>>>> To: undisclosed-recipients:; >>>>> *** HEADER EXTRACTED B1FB93EE101 *** >>>>> *** MESSAGE FILE END B1FB93EE101 *** >>>>> >>>>> >>>>> >>>>> >>>>> >>>> Jules >>>> >> Cheers >> Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.2 (Build 2014) Charset: ISO-8859-1 wj8DBQFGxv2nEfZZRxQVtlQRAhEeAKCRpsWw4N23tFu78xa4/tALr4RriwCfe+DP gEhQvMwKe4Z2QTxVcQ5Qv9U= =9cEv -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From mogens at fumlersoft.dk Sun Aug 19 06:34:17 2007 From: mogens at fumlersoft.dk (Mogens Melander) Date: Sun Aug 19 06:31:22 2007 Subject: CRM114 In-Reply-To: <19019092.6541185811298754.JavaMail.root@office.splatnix.net> References: <19019092.6541185811298754.JavaMail.root@office.splatnix.net> Message-ID: <3682.90.184.17.152.1187501657.squirrel@mail.fumlersoft.dk> On Mon, July 30, 2007 18:01, UxBoD wrote: > I do and I replied :) > > I only changed a couple of things in mailfilter.cf :- > > :spw: // > :log_to_allmail.txt: /no/ > :rewrites_enabled: /no/ > I belive i got the required changes in, but still see errors, that i don't think has to do with config: # spamassassin --lint ERROR: mailreaver.crm broke. Here's the error\: ERROR: /usr/bin/crm: *WARNING* Too many close parenthesis in this math: 0.00 > 10.0) I'll try to keep working. This happened at line 545 of file mailreaver.crm [31154] warn: crm114: Error. Failed to get CRM114-Status. \ at /etc/mail/spamassassin/crm114.pm line 326. Line 545 in mailreaver.crm is: match [:stats_only:] /SET/ I've been searching for unbalanced paranthesis in crm114 dir: # grep ":stats_only:" * mailfilter.crm:isolate (:stats_only:) mailfilter.crm: match [:stats_only:] /SET/ mailfilter.crm: # is this a :stats_only: run (i.e. for CAMRAM) mailfilter.crm: match [:stats_only:] /SET/ mailfilter.crm: # is this a :stats_only: run (i.e. for CAMRAM) mailfilter.crm: match [:stats_only:] /SET/ mailreaver.crm: isolate (:spam: :good: :cache: :dontstore: :stats_only:) mailreaver.crm: isolate (:stats_only:) // mailreaver.crm: alter (:stats_only:) /SET/ mailreaver.crm: match [:stats_only:] /SET/ mailreaver.crm: match [:stats_only:] /SET/ And i still got no clues ??? -- Later Mogens Melander +45 40 85 71 38 +66 870 133 224 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ljosnet at gmail.com Sun Aug 19 13:14:58 2007 From: ljosnet at gmail.com (emm1) Date: Sun Aug 19 13:15:01 2007 Subject: rule against this? In-Reply-To: References: <6B59FCF2EFD0334A8147A1BB463F111E02AE688D@mail-17ps.atlarge.net> <6B59FCF2EFD0334A8147A1BB463F111E02AE68F3@mail-17ps.atlarge.net> <46C20BE4.8070006@maddoc.net> <46C23252.4030101@maddoc.net> Message-ID: <910ee2ac0708190514t5d76c1a3q9e7063b4a0ab9356@mail.gmail.com> Where should I put this file and howto activate it? On 8/15/07, Kai Schaetzl wrote: > Doc Schneider wrote on Tue, 14 Aug 2007 17:53:06 -0500: > > > Actually it was written a long time ago > > I know, I know, am using it since it was available :-) But I almost never > saw it hit more than a few times if ever. Already contemplated several > times to finally remove it. But this kind of spam usually doesn't make it > to my SA, anyway, so it doesn't have a real chance to prove it's > usefulness ... > > Kai > > -- > Kai Sch?tzl, Berlin, Germany > Get your web at Conactive Internet Services: http://www.conactive.com > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From list-mailscanner at linguaphone.com Sun Aug 19 13:25:10 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Sun Aug 19 13:25:18 2007 Subject: rule against this? In-Reply-To: <910ee2ac0708190514t5d76c1a3q9e7063b4a0ab9356@mail.gmail.com> Message-ID: Just save it in /etc/mail/spamassassin/ and it will start working when mailscanner restarts the children which is typically every 3 hours or just restart mailscanner to make it work straight away. > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of emm1 > Sent: 19 August 2007 13:15 > To: MailScanner discussion > Subject: Re: rule against this? > > > Where should I put this file and howto activate it? > > On 8/15/07, Kai Schaetzl wrote: > > Doc Schneider wrote on Tue, 14 Aug 2007 17:53:06 -0500: > > > > > Actually it was written a long time ago > > > > I know, I know, am using it since it was available :-) But I > almost never > > saw it hit more than a few times if ever. Already contemplated several > > times to finally remove it. But this kind of spam usually > doesn't make it > > to my SA, anyway, so it doesn't have a real chance to prove it's > > usefulness ... > > > > Kai > > > > -- > > Kai Sch?tzl, Berlin, Germany > > Get your web at Conactive Internet Services: http://www.conactive.com > > > > > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > From mogens at fumlersoft.dk Sun Aug 19 14:55:13 2007 From: mogens at fumlersoft.dk (Mogens Melander) Date: Sun Aug 19 14:52:19 2007 Subject: mailscanner.cf In-Reply-To: References: <46AA0208.3010003@nerc.ac.uk> <46AA0FAE.8090100@nerc.ac.uk> <46AA10F9.3050604@ecs.soton.ac.uk> <46AA401C.9050707@ecs.soton.ac.uk> <46AA45B7.5070409@alexb.ch> <46AE05E3.3010004@ecs.soton.ac.uk> Message-ID: <1317.90.184.17.152.1187531713.squirrel@mail.fumlersoft.dk> On Mon, July 30, 2007 18:59, Kai Schaetzl wrote: > Julian Field wrote on Mon, 30 Jul 2007 16:38:11 +0100: > >> I'm going to leave it as is. It is suitable for most beginners, and the >> advanced ones among you do all sorts of weird things anyway, so it >> doesn't make any difference to you what I do. > > Well, I asked because you add or offer to add a lot of stuff I personally > wouldn't bother to add. ;-) A simple command-line switch would do ... But > that's probably not feasible with an rpm, only with an unpacked > install.sh. > Personally, i would love to have a ./configure && make install type of setup :^) -- Later Mogens Melander +45 40 85 71 38 +66 870 133 224 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From mogens at fumlersoft.dk Sun Aug 19 15:06:39 2007 From: mogens at fumlersoft.dk (Mogens Melander) Date: Sun Aug 19 15:03:41 2007 Subject: VISPAN mailscanner.info Message-ID: <1531.90.184.17.152.1187532399.squirrel@mail.fumlersoft.dk> Hi guys, Once again i have removed safir.blacknight.ie [83.98.192.7] from vispan's entries in access.db (how did it get in there??) I'm trying to put in a "safir.blacknight.ie OK" in the top, hoping that will do it. -- Later Mogens Melander +45 40 85 71 38 +66 870 133 224 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From rpotter at rpcs.net Sun Aug 19 23:23:57 2007 From: rpotter at rpcs.net (Richard Potter) Date: Sun Aug 19 23:24:03 2007 Subject: Heads up for spamhaus.org problems Message-ID: <20070819222357.GA27826@rpcs.net> Just doing a routine check here, and I have a few mail servers misbehaving. It *appears* sendmail dnsbl to zen.spamhaus.org is timing out, and causing mail delivery delays, or none at all. I'm going to discontinue spamhaus, and see what happens. Richard From raymond at prolocation.net Sun Aug 19 23:34:23 2007 From: raymond at prolocation.net (Raymond Dijkxhoorn) Date: Sun Aug 19 23:34:23 2007 Subject: Heads up for spamhaus.org problems In-Reply-To: <20070819222357.GA27826@rpcs.net> References: <20070819222357.GA27826@rpcs.net> Message-ID: Hi! > Just doing a routine check here, and I have a few mail servers misbehaving. It > *appears* sendmail dnsbl to zen.spamhaus.org is timing out, and causing mail > delivery delays, or none at all. > > I'm going to discontinue spamhaus, and see what happens. Buy rsync from them. Most likely you fire a lot of lookups on their servers and they started to ban high volume mailservers some time ago. We have seen this in a lot of places allready. May i ask how much mail are you processing daily? Bye, Raymond. From Robert.Horton at goodmanmfg.com Mon Aug 20 01:39:19 2007 From: Robert.Horton at goodmanmfg.com (Horton, Robert) Date: Mon Aug 20 01:39:23 2007 Subject: Reporting Score in inline.spam.warning.txt In-Reply-To: <1186399142.31893.6.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1186399142.31893.6.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <50678FBB708A9B4FB6B536F6F657883D028E950F@exch-gman.ad.goodmanmfg.com> Could the $datenumber variable be added to the inline.spam.warning.txt in the future? Thanks, Robert Horton CONFIDENTIALITY NOTE: The information contained in this transmission is privileged and confidential information intended only for the use of the individual or entity named above. If the reader of this message is not the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this transmission in error, do not read it. Please immediately reply to the sender that you have received this communication in error and then delete it. Thank you. From rpotter at rpcs.net Mon Aug 20 03:02:01 2007 From: rpotter at rpcs.net (Richard Potter) Date: Mon Aug 20 03:02:10 2007 Subject: Heads up for spamhaus.org problems In-Reply-To: References: <20070819222357.GA27826@rpcs.net> Message-ID: <20070820020201.GA2841@rpcs.net> On Mon, Aug 20, 2007 at 12:34:23AM +0200, Raymond Dijkxhoorn wrote: > >Just doing a routine check here, and I have a few mail servers > >misbehaving. It > >*appears* sendmail dnsbl to zen.spamhaus.org is timing out, and causing > >mail > >delivery delays, or none at all. > > > >I'm going to discontinue spamhaus, and see what happens. > > Buy rsync from them. Most likely you fire a lot of lookups on their > servers and they started to ban high volume mailservers some time ago. > We have seen this in a lot of places allready. > > May i ask how much mail are you processing daily? Thanks for the reply Raymond.. I wasn't aware they were doing that. These are low volume servers, less than 2,000 messages per day. Does that count as "high volume" to spamhaus? Richard From list-mailscanner at linguaphone.com Mon Aug 20 08:28:32 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon Aug 20 08:28:42 2007 Subject: Heads up for spamhaus.org problems In-Reply-To: <20070820020201.GA2841@rpcs.net> References: <20070819222357.GA27826@rpcs.net> <20070820020201.GA2841@rpcs.net> Message-ID: <1187594912.13419.0.camel@gblades-suse.linguaphone-intranet.co.uk> Yes you will get blocked for 2000 messages per day (we did). I am now using their datafeed service. On Mon, 2007-08-20 at 03:02, Richard Potter wrote: > On Mon, Aug 20, 2007 at 12:34:23AM +0200, Raymond Dijkxhoorn wrote: > > > >Just doing a routine check here, and I have a few mail servers > > >misbehaving. It > > >*appears* sendmail dnsbl to zen.spamhaus.org is timing out, and causing > > >mail > > >delivery delays, or none at all. > > > > > >I'm going to discontinue spamhaus, and see what happens. > > > > Buy rsync from them. Most likely you fire a lot of lookups on their > > servers and they started to ban high volume mailservers some time ago. > > We have seen this in a lot of places allready. > > > > May i ask how much mail are you processing daily? > > Thanks for the reply Raymond.. I wasn't aware they were doing that. These > are low volume servers, less than 2,000 messages per day. Does that count > as "high volume" to spamhaus? > > Richard From paul.hutchings at mira.co.uk Mon Aug 20 09:16:22 2007 From: paul.hutchings at mira.co.uk (Paul Hutchings) Date: Mon Aug 20 09:16:27 2007 Subject: White Listing emails from eBay? Message-ID: I see ClamAV is picking up legitimate emails sent from eBay as things such as "HTML.Phishing.Auction-113 FOUND". What is the most foolproof method to not scan emails from ebay whilst still scanning all the stuff pretending to be from ebay? I assume a rule, probably From: emailebay.com to detect the MTA's? Cheers, Paul Paul Hutchings Network Administrator, MIRA Ltd. Tel: 44 (0)24 7635 5378 Fax: 44 (0)24 7635 8378 mailto:paul.hutchings@mira.co.uk -- MIRA Ltd Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. Registered in England and Wales No. 402570 VAT Registration GB 114 5409 96 The contents of this e-mail are confidential and are solely for the use of the intended recipient. If you receive this e-mail in error, please delete it and notify us either by e-mail, telephone or fax. You should not copy, forward or otherwise disclose the content of the e-mail as this is prohibited. From glenn.steen at gmail.com Mon Aug 20 09:26:07 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Mon Aug 20 09:26:14 2007 Subject: White Listing emails from eBay? In-Reply-To: References: Message-ID: <223f97700708200126w31eeb65r8847a646a7f0dc34@mail.gmail.com> On 20/08/07, Paul Hutchings wrote: > I see ClamAV is picking up legitimate emails sent from eBay as things > such as "HTML.Phishing.Auction-113 FOUND". > > What is the most foolproof method to not scan emails from ebay whilst > still scanning all the stuff pretending to be from ebay? > > I assume a rule, probably From: emailebay.com to detect the MTA's? > > Cheers, > Paul > > Paul Hutchings > Network Administrator, MIRA Ltd. > Tel: 44 (0)24 7635 5378 > Fax: 44 (0)24 7635 8378 > mailto:paul.hutchings@mira.co.uk > > I wouldn't go that route... Who knows when they will suddenly be a virus replicator? I'd instead work on the problem from the other end... If it indeed is a false positive, report it as such to ClamAV. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From martinh at solidstatelogic.com Mon Aug 20 09:28:36 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Mon Aug 20 09:28:38 2007 Subject: White Listing emails from eBay? In-Reply-To: Message-ID: <9d0107efd21aea4289503f588fde0477@solidstatelogic.com> Paul Look at the DKIM plugin you can then DKIM whielist. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Paul Hutchings > Sent: 20 August 2007 09:16 > To: MailScanner discussion > Subject: White Listing emails from eBay? > > I see ClamAV is picking up legitimate emails sent from eBay as things > such as "HTML.Phishing.Auction-113 FOUND". > > What is the most foolproof method to not scan emails from ebay whilst > still scanning all the stuff pretending to be from ebay? > > I assume a rule, probably From: emailebay.com to detect the MTA's? > > Cheers, > Paul > > Paul Hutchings > Network Administrator, MIRA Ltd. > Tel: 44 (0)24 7635 5378 > Fax: 44 (0)24 7635 8378 > mailto:paul.hutchings@mira.co.uk > > > -- > MIRA Ltd > > Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. > > Registered in England and Wales No. 402570 > VAT Registration GB 114 5409 96 > > The contents of this e-mail are confidential and are solely for the use of > the intended recipient. > If you receive this e-mail in error, please delete it and notify us either > by e-mail, telephone or fax. > You should not copy, forward or otherwise disclose the content of the e- > mail as this is prohibited. > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From paul.hutchings at mira.co.uk Mon Aug 20 09:37:18 2007 From: paul.hutchings at mira.co.uk (Paul Hutchings) Date: Mon Aug 20 09:37:26 2007 Subject: White Listing emails from eBay? References: <223f97700708200126w31eeb65r8847a646a7f0dc34@mail.gmail.com> Message-ID: I think the issue is not that it's a false positive - I'd want to know if it came from anywhere other than from eBay. I'll investigate the DKIM suggestion from Martin - as a sticking plaster though is emailebay.com a workable suggestion? TIA Paul Paul Hutchings Network Administrator, MIRA Ltd. Tel: 44 (0)24 7635 5378 Fax: 44 (0)24 7635 8378 mailto:paul.hutchings@mira.co.uk -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Glenn Steen Sent: 20 August 2007 09:26 To: MailScanner discussion Subject: Re: White Listing emails from eBay? On 20/08/07, Paul Hutchings wrote: > I see ClamAV is picking up legitimate emails sent from eBay as things > such as "HTML.Phishing.Auction-113 FOUND". > > What is the most foolproof method to not scan emails from ebay whilst > still scanning all the stuff pretending to be from ebay? > > I assume a rule, probably From: emailebay.com to detect the MTA's? > > Cheers, > Paul > > Paul Hutchings > Network Administrator, MIRA Ltd. > Tel: 44 (0)24 7635 5378 > Fax: 44 (0)24 7635 8378 > mailto:paul.hutchings@mira.co.uk > > I wouldn't go that route... Who knows when they will suddenly be a virus replicator? I'd instead work on the problem from the other end... If it indeed is a false positive, report it as such to ClamAV. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MIRA Ltd Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. Registered in England and Wales No. 402570 VAT Registration GB 114 5409 96 The contents of this e-mail are confidential and are solely for the use of the intended recipient. If you receive this e-mail in error, please delete it and notify us either by e-mail, telephone or fax. You should not copy, forward or otherwise disclose the content of the e-mail as this is prohibited. From carl at theholidayclub.com Mon Aug 20 09:59:43 2007 From: carl at theholidayclub.com (Carl Werner) Date: Mon Aug 20 10:01:35 2007 Subject: Blocking Spam In-Reply-To: References: Message-ID: <46C957FF.8080609@theholidayclub.com> Hi All, My Mailscanner gateway is letting quite a bit of spam emails of the following format through. Any ideas on how to effectively block them? Ex 1 Do you think my bra is too tight. Maybe I should take it off. let me know what you think. http://66.169.144.98/ Ex 2 Subject: My EX-boyfriend took these of me in bed. Do you think he misses me. click http://70.131.100.102/ Ex 3 I cant believe you talked me into taking these pictures, hehe. I hope you like em. http://71.207.192.124/ Thank you. Carl -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From martinh at solidstatelogic.com Mon Aug 20 10:11:03 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Mon Aug 20 10:11:04 2007 Subject: Blocking Spam In-Reply-To: <46C957FF.8080609@theholidayclub.com> Message-ID: Carl If you can put up the entire message (headers and all) on a pastebin or web page and then let us know the location we can run through our system and let you know which rules fired for us.. Also let us know what versions of MailScanner and Spamassassin you're running as well.. ta -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Carl Werner > Sent: 20 August 2007 10:00 > To: MailScanner discussion > Subject: Blocking Spam > > Hi All, > > My Mailscanner gateway is letting quite a bit of spam emails of the > following format through. Any ideas on how to effectively block them? > > Ex 1 > > Do you think my bra is too tight. Maybe I should take it off. let me know > what you think. > http://66.169.144.98/ > > Ex 2 > > Subject: My EX-boyfriend took these of me in bed. Do you think he misses > me. > > click http://70.131.100.102/ > > Ex 3 > > I cant believe you talked me into taking these pictures, hehe. I hope you > like em. > http://71.207.192.124/ > > Thank you. > > Carl > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From ms-list at alexb.ch Mon Aug 20 10:52:52 2007 From: ms-list at alexb.ch (Alex Broens) Date: Mon Aug 20 10:52:56 2007 Subject: Blocking Spam In-Reply-To: <46C957FF.8080609@theholidayclub.com> References: <46C957FF.8080609@theholidayclub.com> Message-ID: <46C96474.6080304@alexb.ch> On 8/20/2007 10:59 AM, Carl Werner wrote: > Hi All, > > My Mailscanner gateway is letting quite a bit of spam emails of the > following format through. Any ideas on how to effectively block them? > > Ex 1 > > Do you think my bra is too tight. Maybe I should take it off. let me know > what you think. > http://66.169.144.98/ > > Ex 2 > > Subject: My EX-boyfriend took these of me in bed. Do you think he misses > me. > > click http://70.131.100.102/ > > Ex 3 > > I cant believe you talked me into taking these pictures, hehe. I hope you > like em. > http://71.207.192.124/ most of these should get tagged using SURBL/URIBL.com do you see any of the IP URLs being tagged at all? Alex From maillists at conactive.com Mon Aug 20 12:31:17 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Mon Aug 20 12:31:21 2007 Subject: mailscanner.cf In-Reply-To: <1317.90.184.17.152.1187531713.squirrel@mail.fumlersoft.dk> References: <46AA0208.3010003@nerc.ac.uk> <46AA0FAE.8090100@nerc.ac.uk> <46AA10F9.3050604@ecs.soton.ac.uk> <46AA401C.9050707@ecs.soton.ac.uk> <46AA45B7.5070409@alexb.ch> <46AE05E3.3010004@ecs.soton.ac.uk> <1317.90.184.17.152.1187531713.squirrel@mail.fumlersoft.dk> Message-ID: Mogens Melander wrote on Sun, 19 Aug 2007 15:55:13 +0200 (CEST): > Personally, i would love to have a ./configure && make install type of > setup you mean "perl Makefile.PL"? :-) Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From hvdkooij at vanderkooij.org Mon Aug 20 12:31:13 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Mon Aug 20 12:31:23 2007 Subject: OT: KAV scanner testing Message-ID: Hi, I have checked everything obvious and even worked my way through logs but can not find any fault in the KAV testing. So I am looking for a few volunteers with other versions of KAV to verify my findings. If you happen to have a KAV version other then KAV4WS 5.5.27/RELEASE build #15 for Linux and are willing to take a swing at it then contact me and I will work out the details to give you a test batch (661 files) for comparison. I will need the generated log in response. Thanks, Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for this quote of George Bernard Shaw.) From hvdkooij at vanderkooij.org Mon Aug 20 12:40:57 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Mon Aug 20 12:41:10 2007 Subject: mailscanner.cf In-Reply-To: References: <46AA0208.3010003@nerc.ac.uk> <46AA0FAE.8090100@nerc.ac.uk> <46AA10F9.3050604@ecs.soton.ac.uk> <46AA401C.9050707@ecs.soton.ac.uk> <46AA45B7.5070409@alexb.ch> <46AE05E3.3010004@ecs.soton.ac.uk> <1317.90.184.17.152.1187531713.squirrel@mail.fumlersoft.dk> Message-ID: On Mon, 20 Aug 2007, Kai Schaetzl wrote: > Mogens Melander wrote on Sun, 19 Aug 2007 15:55:13 +0200 (CEST): > >> Personally, i would love to have a ./configure && make install type of >> setup > > you mean "perl Makefile.PL"? :-) Isn't that usually? perl Makefile.PL make make test make install Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for this quote of George Bernard Shaw.) From maillists at conactive.com Mon Aug 20 14:31:41 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Mon Aug 20 14:31:45 2007 Subject: mailscanner.cf In-Reply-To: References: <46AA0208.3010003@nerc.ac.uk> <46AA0FAE.8090100@nerc.ac.uk> <46AA10F9.3050604@ecs.soton.ac.uk> <46AA401C.9050707@ecs.soton.ac.uk> <46AA45B7.5070409@alexb.ch> <46AE05E3.3010004@ecs.soton.ac.uk> <1317.90.184.17.152.1187531713.squirrel@mail.fumlersoft.dk> 4.0708201338300.12183@faramir.hugo.vanderkooij.org> Reply-To: mailscanner@lists.mailscanner.info X-Rcpt-To: Hugo van der Kooij wrote on Mon, 20 Aug 2007 13:40:57 +0200 (CEST): > Isn't that usually? I was referring to the configure step. As we talk Perl here no configure ;-) Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From donald.dawson at bakerbotts.com Mon Aug 20 14:46:26 2007 From: donald.dawson at bakerbotts.com (donald.dawson@bakerbotts.com) Date: Mon Aug 20 14:46:38 2007 Subject: FW: temp files not being processed - score=0 Message-ID: Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: ms.zxp Type: application/octet-stream Size: 12889 bytes Desc: ms.zxp Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070820/3b7d8f71/ms.obj From bbecken at aafp.org Mon Aug 20 14:59:00 2007 From: bbecken at aafp.org (Brad Beckenhauer) Date: Mon Aug 20 14:59:40 2007 Subject: Invalid Queue Files with Postfix In-Reply-To: <46C6FDA7.3080605@ecs.soton.ac.uk> References: <46C56930.D87E.0068.3@aafp.org> <46C5B203.5020108@ecs.soton.ac.uk> <46C58CFE.D87E.0068.3@aafp.org> <223f97700708171339h2115ce1fu1af220aa23462924@mail.gmail.com> <46C5CE13.D87E.0068.3@aafp.org><46C5CE13.D87E.0068.3@aafp.org> <46C6FDA7.3080605@ecs.soton.ac.uk> Message-ID: <46C957D4.D87E.0068.3@aafp.org> >>> On 8/18/2007 at 9:09 AM, in message <46C6FDA7.3080605@ecs.soton.ac.uk>, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Brad Beckenhauer wrote: >> >> That would be a nice feature request for MailScanner, something to >> provide consistant volume benchmarks across all supported MailScanner >> platforms. >> Something like: >> MailScanner -stats >> or a configuration setting to enable benchmarking with the >> understanding that there would be system overhead associated with the >> additional process. >> > What stats would you like it to log that it doesn't already? > There's no communication between the child processes once they are > started, but I could add a signal trap so that a kill -USR or something > would make them dump some figures to some file or other, then restart > the batch they were on. They already catch kill -HUP to force them to > die. So exactly what do you want to do when it receives a SIGUSR? Several times on the list I've noticed questions like "What's your volume?". Is there already something in MailScanner that can generate an answer to that question? My first thought would be to have MailScanner calculate the daily volume of total daily messages processed. That way when the "What's your volume" question comes up, there is a standardized way to respond to the question. An hourly histogram would be an interesting stat. Date TIME Msgs processed 00:00-01:00 xxxx 01:00-02:00 xxxx 02:00-03:00 xxxx ?---------------------- Mail Volume xxxxx Hourly Avg: xx% Anyway... That was the thought..... Feel free to toss the idea to the bit bucket. I'm not going to be arguing the idea. Thanks for listening. Brad > > >> >>>>> Brad Beckenhauer wrote: >>>>> >>>>>> I'm running a Postfix system using the Hold method and recently >>>>>> experienced a huge backlog due to "invalid queue files". >>>>>> >> Eventually >> >>>> the >>>> >>>>>> hold directory got enough invalid queue files that MailScanner >>>>>> >>>> switch to >>>> >>>>>> "accelerated" mode of processing messages. >>>>>> >>>>>> sample from the maillog: >>>>>> Aug 17 08:37:48 mx2 MailScanner[26605]: New Batch: Found invalid >>>>>> >>>> queue >>>> >>>>>> files: B1FB93EE101 >>>>>> Postcat of this file is below. >>>>>> >>>>>> Finding what's causing these invalid queue files and eliminating >>>>>> >>>> them >>>> >>>>>> is the first issue. >>>>>> >>>>>> Would a feature in MailScanner that takes action when invalid >>>>>> >> queue >> >>>>>> files are found be useful to others? >>>>>> Such a feature could: >>>>>> Detect invalid queue files (which it already does) and >>>>>> a) Move the invalid queue file somewhere safe and notify the >>>>>> >> admin >> >>>>>> b) postsuper -d queue_file to get rid of it. >>>>>> >>>>>> Or how about a courtesy email to the email admin when >>>>>> >> MailScanner >> >>>>>> switches to "accelerated mode". >>>>>> >>>>>> postcat B1FB93EE101 >>>>>> >>>>>> *** ENVELOPE RECORDS B1FB93EE101 *** >>>>>> message_size: 489 336 1 >>>>>> >>>>>> 0 >>>>>> message_arrival_time: Thu Aug 16 09:22:55 2007 >>>>>> sender: Lucien.Hatch8400@hot.ee >>>>>> named_attribute: client_name=62.43.179.119.dyn.user.ono.com >>>>>> named_attribute: client_address=62.43.179.119 >>>>>> named_attribute: >>>>>> message_origin=62.43.179.119.dyn.user.ono.com[62.43.179.119] >>>>>> named_attribute: helo_name=62.43.179.119.dyn.user.ono.com >>>>>> named_attribute: protocol_name=SMTP >>>>>> original_recipient: tnolte@stfm.org >>>>>> recipient: tnolte@stfm.org >>>>>> *** MESSAGE CONTENTS B1FB93EE101 *** >>>>>> Received: from 62.43.179.119.dyn.user.ono.com >>>>>> (62.43.179.119.dyn.user.ono.com [62.43.179.119]) >>>>>> by mx1.aafp.org (Postfix) with SMTP id B1FB93EE101 >>>>>> for ; Thu, 16 Aug 2007 09:22:55 -0500 >>>>>> >>>> (CDT) >>>> >>>>>> Received: from martinique.hotbox.com (unknown [111.13.212.156]) >>>>>> by galleryplanet.com with SMTP id 5[10 >>>>>> Message-Id: <20070816142255.B1FB93EE101@mx1.aafp.org> >>>>>> Date: Thu, 16 Aug 2007 09:22:55 -0500 (CDT) >>>>>> From: Lucien.Hatch8400@hot.ee >>>>>> To: undisclosed-recipients:; >>>>>> *** HEADER EXTRACTED B1FB93EE101 *** >>>>>> *** MESSAGE FILE END B1FB93EE101 *** >>>>>> >>>>>> >>>>>> >>>>>> >>>>>> >>>>> Jules >>>>> >>> Cheers >>> > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.2 (Build 2014) > Charset: ISO-8859-1 > > wj8DBQFGxv2nEfZZRxQVtlQRAhEeAKCRpsWw4N23tFu78xa4/tALr4RriwCfe+DP > gEhQvMwKe4Z2QTxVcQ5Qv9U= > =9cEv > -----END PGP SIGNATURE----- From list-mailscanner at linguaphone.com Mon Aug 20 15:06:43 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon Aug 20 15:06:50 2007 Subject: Invalid Queue Files with Postfix In-Reply-To: <46C957D4.D87E.0068.3@aafp.org> References: <46C56930.D87E.0068.3@aafp.org> <46C5B203.5020108@ecs.soton.ac.uk> <46C58CFE.D87E.0068.3@aafp.org> <223f97700708171339h2115ce1fu1af220aa23462924@mail.gmail.com> <46C5CE13.D87E.0068.3@aafp.org><46C5CE13.D87E.0068.3@aafp.org> <46C6FDA7.3080605@ecs.soton.ac.uk> <46C957D4.D87E.0068.3@aafp.org> Message-ID: <1187618803.13420.54.camel@gblades-suse.linguaphone-intranet.co.uk> On Mon, 2007-08-20 at 14:59, Brad Beckenhauer wrote: > >>> On 8/18/2007 at 9:09 AM, in message <46C6FDA7.3080605@ecs.soton.ac.uk>, Julian > Field wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > > Hash: SHA1 > > > > > > > > Brad Beckenhauer wrote: > >> > >> That would be a nice feature request for MailScanner, something to > >> provide consistant volume benchmarks across all supported MailScanner > >> platforms. > >> Something like: > >> MailScanner -stats > >> or a configuration setting to enable benchmarking with the > >> understanding that there would be system overhead associated with the > >> additional process. > >> > > What stats would you like it to log that it doesn't already? > > There's no communication between the child processes once they are > > started, but I could add a signal trap so that a kill -USR or something > > would make them dump some figures to some file or other, then restart > > the batch they were on. They already catch kill -HUP to force them to > > die. So exactly what do you want to do when it receives a SIGUSR? > > Several times on the list I've noticed questions like "What's your volume?". > Is there already something in MailScanner that can generate an answer to that question? > > My first thought would be to have MailScanner calculate the daily volume of total daily messages processed. That way when the "What's your volume" question comes up, there is a standardized way to respond to the question. An hourly histogram would be an interesting stat. > > Date > TIME Msgs processed > 00:00-01:00 xxxx > 01:00-02:00 xxxx > 02:00-03:00 xxxx > ?---------------------- > Mail Volume xxxxx > Hourly Avg: xx% > > Anyway... That was the thought..... Feel free to toss the idea to the bit bucket. I'm not going to be arguing the idea. > > Thanks for listening. > Brad I just use standard logwatch as it gives a good daily summary. From hmkash at arl.army.mil Mon Aug 20 15:20:41 2007 From: hmkash at arl.army.mil (Kash, Howard (Civ, ARL/CISD)) Date: Mon Aug 20 15:18:31 2007 Subject: CRM114 (UNCLASSIFIED) In-Reply-To: <3682.90.184.17.152.1187501657.squirrel@mail.fumlersoft.dk> References: <19019092.6541185811298754.JavaMail.root@office.splatnix.net> <3682.90.184.17.152.1187501657.squirrel@mail.fumlersoft.dk> Message-ID: <88991ECEE371C644986F0C8837C207B701CC314B@ARLABML01.DS.ARL.ARMY.MIL> Classification: UNCLASSIFIED Caveats: NONE Here's the fix for the "Too many close parenthesis" error in the BlameTheInterns release: http://sourceforge.net/mailarchive/message.php?msg_id=20070722185714.643 0%40gmx.net Howard -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Mogens Melander Sent: Sunday, August 19, 2007 1:34 AM To: MailScanner discussion Subject: Re: CRM114 On Mon, July 30, 2007 18:01, UxBoD wrote: > I do and I replied :) > > I only changed a couple of things in mailfilter.cf :- > > :spw: // > :log_to_allmail.txt: /no/ > :rewrites_enabled: /no/ > I belive i got the required changes in, but still see errors, that i don't think has to do with config: # spamassassin --lint ERROR: mailreaver.crm broke. Here's the error\: ERROR: /usr/bin/crm: *WARNING* Too many close parenthesis in this math: 0.00 > 10.0) I'll try to keep working. This happened at line 545 of file mailreaver.crm [31154] warn: crm114: Error. Failed to get CRM114-Status. \ at /etc/mail/spamassassin/crm114.pm line 326. Line 545 in mailreaver.crm is: match [:stats_only:] /SET/ I've been searching for unbalanced paranthesis in crm114 dir: # grep ":stats_only:" * mailfilter.crm:isolate (:stats_only:) mailfilter.crm: match [:stats_only:] /SET/ mailfilter.crm: # is this a :stats_only: run (i.e. for CAMRAM) mailfilter.crm: match [:stats_only:] /SET/ mailfilter.crm: # is this a :stats_only: run (i.e. for CAMRAM) mailfilter.crm: match [:stats_only:] /SET/ mailreaver.crm: isolate (:spam: :good: :cache: :dontstore: :stats_only:) mailreaver.crm: isolate (:stats_only:) // mailreaver.crm: alter (:stats_only:) /SET/ mailreaver.crm: match [:stats_only:] /SET/ mailreaver.crm: match [:stats_only:] /SET/ And i still got no clues ??? -- Later Mogens Melander +45 40 85 71 38 +66 870 133 224 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! Classification: UNCLASSIFIED Caveats: NONE From brose at med.wayne.edu Mon Aug 20 15:26:56 2007 From: brose at med.wayne.edu (Rose, Bobby) Date: Mon Aug 20 15:27:14 2007 Subject: OT: CRM114 Question In-Reply-To: <88991ECEE371C644986F0C8837C207B701CC314B@ARLABML01.DS.ARL.ARMY.MIL> References: <19019092.6541185811298754.JavaMail.root@office.splatnix.net><3682.90.184.17.152.1187501657.squirrel@mail.fumlersoft.dk> <88991ECEE371C644986F0C8837C207B701CC314B@ARLABML01.DS.ARL.ARMY.MIL> Message-ID: <8F2A53954C22554EB75D9643FCCE0C6B0472D49F@MED-CORE03-MS1.med.wayne.edu> I had to turn this off because after 4 days of use, mailreaver began to eat most of my cpu cycles to the point that the load average max out and sendmail stopped accepting connections. I'm thinking those database files became corrupted but has anyone else seen this happen? Or maybe it was the BlameTheInterns release since I had ran crm114 for 2 days on BlameBaltar release w/o issue. I haven't turned it back on since considering I was working on that SA 3.2.3 dns query slowness issue. Bobby Rose Senior Systems Administrator MSIS Network Operations Wayne State University School of Medicine From hmkash at arl.army.mil Mon Aug 20 15:41:45 2007 From: hmkash at arl.army.mil (Kash, Howard (Civ, ARL/CISD)) Date: Mon Aug 20 15:39:33 2007 Subject: temp files not being processed - score=0 (UNCLASSIFIED) In-Reply-To: References: Message-ID: <88991ECEE371C644986F0C8837C207B701CC314C@ARLABML01.DS.ARL.ARMY.MIL> Classification: UNCLASSIFIED Caveats: NONE I've had the "(not cached, score=0, required 5, autolearn=)" problem several times myself. Typically restarting MailScanner fixed the problem. Last time it happened, simply restarting didn't help so I tried removing SpamAssassin.cache.db and the problem stopped. Can't say for sure removing the cache was the fix, but worth a try. BTW, is there something similar to db_verify that can be run on the SpamAssassin cache to check for consistency? Howard -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of donald.dawson@bakerbotts.com Sent: Monday, August 20, 2007 9:46 AM To: mailscanner@lists.mailscanner.info Subject: FW: temp files not being processed - score=0 <> I have posted this problem before, but I have not found a solution, and I really need the forum's help. One of our MX servers is leaving files in /var/spool/MailScanner/incoming/SpamAssassin-Temp. It appears that each one being left is getting a 0 score. I ran this by Julian recently, and he said he was at least the same issue of files being left in that dir. I added an entry in cron to remove them, but it is just cleaning up the files leftover from a real problem: 1 * * * * /usr/bin/find /var/spool/MailScanner/incoming/SpamAssassin-Temp -type f -mtime +1 -print | /usr/bin/xargs rm -f # delete leftover temp files Here are the number of files in the for today and yesterday: root@houmx05:/var/spool/MailScanner/incoming/SpamAssassin-Temp # ls -la | grep -c ' Aug 19 ' 2409 # ls -la | grep -c ' Aug 18 ' 2135 Although not perfect, here is a count of 'score=0' lines from the maillog for the respective days: # zcat /var/log/maillog.1.gz | grep -c score=0 1221 # zcat /var/log/maillog.2.gz | grep -c score=0 1400 I have already lowered the MX priority of this server to try and receive less email, but it's still delivering emails (not all) with a zero score. I have included MailScanner -v and an output from MailScanner --debug --debug-sa as well (attached ms.zxp - rename to .zip to extract) as the contents of the email. I saw one possible discrepancy in processing the 2nd email via the debug option where it did not end with 'I am generating a hash using the input of'. The output show two emails being processed. The last one was definitely spam, but was scored as 0 and was left in the /var/spool/MailScanner/incoming/SpamAssassin-Temp dir. # MailScanner -v Running on Linux houmx05.bakerbotts.com 2.6.9-1.667smp #1 SMP Tue Nov 2 14:59:52 EST 2004 i686 i686 i386 GNU/Linux This is Fedora Core release 3 (Heidelberg) This is Perl version 5.008005 (5.8.5) This is MailScanner version 4.62.9 Module versions are: 1.00 AnyDBM_File 1.18 Archive::Zip 1.03 Carp 1.119 Convert::BinHex 1.00 DirHandle 1.05 Fcntl 2.73 File::Basename 2.08 File::Copy 2.01 FileHandle 1.06 File::Path 0.18 File::Temp 0.90 Filesys::Df 1.35 HTML::Entities 3.56 HTML::Parser 2.37 HTML::TokeParser 1.21 IO 1.10 IO::File 1.123 IO::Pipe 1.71 Mail::Header 1.86 Math::BigInt 3.05 MIME::Base64 5.420 MIME::Decoder 5.420 MIME::Decoder::UU 5.420 MIME::Head 5.420 MIME::Parser 3.03 MIME::QuotedPrint 5.420 MIME::Tools 0.11 Net::CIDR 1.08 POSIX 1.19 Scalar::Util 1.77 Socket 1.4 Sys::Hostname::Long 0.18 Sys::Syslog 1.9707 Time::HiRes 1.02 Time::localtime Optional module versions are: 1.30 Archive::Tar 0.21 bignum 1.82 Business::ISBN 1.10 Business::ISBN::Data 0.17 Convert::TNEF 1.08 Data::Dump 1.814 DB_File 1.13 DBD::SQLite 1.56 DBI 1.15 Digest 1.01 Digest::HMAC 2.36 Digest::MD5 2.10 Digest::SHA1 1.00 Encode::Detect 0.17008 Error 0.18 ExtUtils::CBuilder 2.18 ExtUtils::ParseXS 0.44 Inline 1.08 IO::String 1.04 IO::Zlib 2.21 IP::Country 0.20 Mail::ClamAV 3.002002 Mail::SpamAssassin v2.004 Mail::SPF 1.999001 Mail::SPF::Query 0.19 Math::BigRat 0.2808 Module::Build 0.20 Net::CIDR::Lite 0.60 Net::DNS 0.002.2 Net::DNS::Resolver::Programmable missing Net::LDAP 4.004 NetAddr::IP 1.94 Parse::RecDescent missing SAVI 2.64 Test::Harness 0.95 Test::Manifest 1.95 Text::Balanced 1.35 URI 0.7203 version 0.62 YAML see attached ms.txt for mailscanner --debug --debug-sa # l /var/spool/MailScanner/incoming/SpamAssassin-Temp/.spamassassin15944T1P9 bFtmp -rw------- 1 root root 2433 Aug 20 03:11 /var/spool/MailScanner/incoming/SpamAssassin-Temp/.spamassassin15944T1P9 bFtmp # fuser /var/spool/MailScanner/incoming/SpamAssassin-Temp/.spamassassin15944T1P9 bFtmp root@houmx05:/var/spool/MailScanner/incoming/SpamAssassin-Temp # grep l7K8B63E015934 /var/log/maillog Aug 20 03:11:14 houmx05 milter-greylist: l7K8B63E015934: skipping greylist because this is the default action, (from=, rcpt=, addr=ARouen-252-1-67-214.w90-23.abo.wanadoo.fr[90.23.62.214]) Aug 20 03:11:14 houmx05 sendmail[15934]: l7K8B63E015934: from=, size=1880, class=0, nrcpts=1, msgid=<000801c7e301$a7518b00$1201a8c0@reginald>, proto=SMTP, daemon=MTA, relay=ARouen-252-1-67-214.w90-23.abo.wanadoo.fr [90.23.62.214] Aug 20 03:11:14 houmx05 sendmail[15934]: l7K8B63E015934: Milter add: header: X-Null-Tag: 6a12c78c6f1e5960796d07939b28851d Aug 20 03:11:14 houmx05 sendmail[15934]: l7K8B63E015934: Milter add: header: X-Greylist: Default is to whitelist mail, not delayed by milter-greylist-3.0rc3 (houmx05.bakerbotts.com [204.194.98.17]); Mon, 20 Aug 2007 03:11:14 -0500 (CDT) Aug 20 03:11:14 houmx05 sendmail[15934]: l7K8B63E015934: to=, delay=00:00:00, mailer=esmtp, pri=31880, stat=queued Aug 20 03:11:29 houmx05 MailScanner[15899]: Message l7K8B63E015934 from 90.23.62.214 (reginald@chmai2.loxinfo.co.th) to bakerbotts.com is not spam, SpamAssassin (not cached, score=0, required 5, autolearn=) Aug 20 03:11:29 houmx05 sendmail[15968]: l7K8B63E015934: to=, delay=00:00:15, xdelay=00:00:00, mailer=esmtp, pri=121880, relay=housweep01.bakerbotts.net. [10.20.254.236], dsn=2.0.0, stat=Sent (Message received OK) Contents of /var/spool/MailScanner/incoming/SpamAssassin-Temp/.spamassassin15944T1P9 bFtmp: X-BakerBotts-MailScanner-From: reginald@chmai2.loxinfo.co.th X-Envelope-From: reginald@chmai2.loxinfo.co.th Return-Path: Received: from abo.wanadoo.fr (ARouen-252-1-67-214.w90-23.abo.wanadoo.fr [90.23.62.214]) by houmx05.bakerbotts.com (8.13.8/8.13.5) with SMTP id l7K8B63E015934 for ; Mon, 20 Aug 2007 03:11:14 -0500 Message-ID: <000801c7e301$a7518b00$1201a8c0@reginald> From: "natal julia" TO: Subject: Hey bro, found this site Date: Mon, 20 Aug 2007 23:02:05 +0300 MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_001_000C_01C7E301.A7518B00" Content-Transfer-Encoding: 7bit X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express Macintosh Edition - 5.01 (1630) X-MimeOLE: Produced By Microsoft MimeOLE V X-Null-Tag: 6a12c78c6f1e5960796d07939b28851d X-Greylist: Default is to whitelist mail, not delayed by milter-greylist-3.0rc3 (houmx05.bakerbotts.com [204.194.98.17]); Mon, 20 Aug 2007 03:11:14 -0500 (CDT) This is a multi-part message in MIME format. ------=_NextPart_001_000C_01C7E301.A7518B00 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit ------=_NextPart_001_000C_01C7E301.A7518B00 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: 7bit Is there any more debug options I can use to figure this one out? Thanks, Donald Donald Dawson Baker Botts L.L.P. Security Administrator 713-229-2183 Classification: UNCLASSIFIED Caveats: NONE From stinkybob at gmail.com Mon Aug 20 15:59:24 2007 From: stinkybob at gmail.com (Eugene MacDougal) Date: Mon Aug 20 15:59:31 2007 Subject: f-prot-autoupdate patch Message-ID: <2579c6b20708200759g210ec2anbedea995c9ddfb20@mail.gmail.com> Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: f-prot-autoupdate.patch Type: application/octet-stream Size: 440 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070820/ec271262/f-prot-autoupdate.obj From MailScanner at ecs.soton.ac.uk Mon Aug 20 18:14:46 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 20 18:15:32 2007 Subject: f-prot-autoupdate patch In-Reply-To: <2579c6b20708200759g210ec2anbedea995c9ddfb20@mail.gmail.com> References: <2579c6b20708200759g210ec2anbedea995c9ddfb20@mail.gmail.com> Message-ID: <46C9CC06.8080107@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 It will be in the next release. Good idea. Eugene MacDougal wrote: > It looks like f-prot-autoupdate does not have any path set. This was > a problem on my system (Solaris 10) because I have wget in > /usr/sfw/bin and root's crontab only receives a limited path on my > system. I set the PATH environment variable in the script and it > seems to help a lot. Please consider including this patch. > > Thanks, > -Gene Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Charset: ISO-8859-1 wj8DBQFGycwGEfZZRxQVtlQRAocLAJ9T1ft+um7HpUqYrwveeBkYw/6XvQCdEImE 8QV6DMccd6Yxsbl75Yf8n4s= =q+ZP -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From gmane at tippingmar.com Mon Aug 20 18:56:12 2007 From: gmane at tippingmar.com (Mark Nienberg) Date: Mon Aug 20 18:56:56 2007 Subject: sophos update installs crontab entry Message-ID: I noticed that the following recently appeared in my root crontab, presumably after MailScanner updated sophos v5: 3-59/5 * * * * /opt/sophos-av/bin/savupdate This runs a sophos update every 5 minutes and doesn't do the locking that MailScanner does, so it is probably best to delete it and allow MailScanner to take care of updates. I wonder if it is possible to modify the sophos-autoupdate script to remove this entry if savupdate creates it? Mark From a.peacock at chime.ucl.ac.uk Mon Aug 20 19:02:07 2007 From: a.peacock at chime.ucl.ac.uk (Anthony Peacock) Date: Mon Aug 20 19:02:17 2007 Subject: sophos update installs crontab entry In-Reply-To: References: Message-ID: <46C9D71F.3010005@chime.ucl.ac.uk> Hi, Mark Nienberg wrote: > I noticed that the following recently appeared in my root crontab, > presumably after MailScanner updated sophos v5: > > 3-59/5 * * * * /opt/sophos-av/bin/savupdate > > This runs a sophos update every 5 minutes and doesn't do the locking > that MailScanner does, so it is probably best to delete it and allow > MailScanner to take care of updates. > > I wonder if it is possible to modify the sophos-autoupdate script to > remove this entry if savupdate creates it? -1 Please don't. I really don't want MailScanner messing with my Sophos install thank you very much. -- Anthony Peacock CHIME, Royal Free & University College Medical School WWW: http://www.chime.ucl.ac.uk/~rmhiajp/ "I'm in shape. - ROUND is a shape" From donald.dawson at bakerbotts.com Mon Aug 20 19:18:12 2007 From: donald.dawson at bakerbotts.com (donald.dawson@bakerbotts.com) Date: Mon Aug 20 19:18:23 2007 Subject: temp files not being processed - score=0 (UNCLASSIFIED) In-Reply-To: <88991ECEE371C644986F0C8837C207B701CC314C@ARLABML01.DS.ARL.ARMY.MIL> Message-ID: That fixed the problem! I ran sa-learn clear also, but that was probably unnecessary to clear Bayes. Thank you so much! Donald -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Kash, Howard (Civ, ARL/CISD) Sent: Monday, August 20, 2007 9:42 AM To: MailScanner discussion Subject: RE: temp files not being processed - score=0 (UNCLASSIFIED) Classification: UNCLASSIFIED Caveats: NONE I've had the "(not cached, score=0, required 5, autolearn=)" problem several times myself. Typically restarting MailScanner fixed the problem. Last time it happened, simply restarting didn't help so I tried removing SpamAssassin.cache.db and the problem stopped. Can't say for sure removing the cache was the fix, but worth a try. BTW, is there something similar to db_verify that can be run on the SpamAssassin cache to check for consistency? Howard -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of donald.dawson@bakerbotts.com Sent: Monday, August 20, 2007 9:46 AM To: mailscanner@lists.mailscanner.info Subject: FW: temp files not being processed - score=0 <> I have posted this problem before, but I have not found a solution, and I really need the forum's help. One of our MX servers is leaving files in /var/spool/MailScanner/incoming/SpamAssassin-Temp. It appears that each one being left is getting a 0 score. I ran this by Julian recently, and he said he was at least the same issue of files being left in that dir. I added an entry in cron to remove them, but it is just cleaning up the files leftover from a real problem: 1 * * * * /usr/bin/find /var/spool/MailScanner/incoming/SpamAssassin-Temp -type f -mtime +1 -print | /usr/bin/xargs rm -f # delete leftover temp files Here are the number of files in the for today and yesterday: root@houmx05:/var/spool/MailScanner/incoming/SpamAssassin-Temp # ls -la | grep -c ' Aug 19 ' 2409 # ls -la | grep -c ' Aug 18 ' 2135 Although not perfect, here is a count of 'score=0' lines from the maillog for the respective days: # zcat /var/log/maillog.1.gz | grep -c score=0 1221 # zcat /var/log/maillog.2.gz | grep -c score=0 1400 I have already lowered the MX priority of this server to try and receive less email, but it's still delivering emails (not all) with a zero score. I have included MailScanner -v and an output from MailScanner --debug --debug-sa as well (attached ms.zxp - rename to .zip to extract) as the contents of the email. I saw one possible discrepancy in processing the 2nd email via the debug option where it did not end with 'I am generating a hash using the input of'. The output show two emails being processed. The last one was definitely spam, but was scored as 0 and was left in the /var/spool/MailScanner/incoming/SpamAssassin-Temp dir. # MailScanner -v Running on Linux houmx05.bakerbotts.com 2.6.9-1.667smp #1 SMP Tue Nov 2 14:59:52 EST 2004 i686 i686 i386 GNU/Linux This is Fedora Core release 3 (Heidelberg) This is Perl version 5.008005 (5.8.5) This is MailScanner version 4.62.9 Module versions are: 1.00 AnyDBM_File 1.18 Archive::Zip 1.03 Carp 1.119 Convert::BinHex 1.00 DirHandle 1.05 Fcntl 2.73 File::Basename 2.08 File::Copy 2.01 FileHandle 1.06 File::Path 0.18 File::Temp 0.90 Filesys::Df 1.35 HTML::Entities 3.56 HTML::Parser 2.37 HTML::TokeParser 1.21 IO 1.10 IO::File 1.123 IO::Pipe 1.71 Mail::Header 1.86 Math::BigInt 3.05 MIME::Base64 5.420 MIME::Decoder 5.420 MIME::Decoder::UU 5.420 MIME::Head 5.420 MIME::Parser 3.03 MIME::QuotedPrint 5.420 MIME::Tools 0.11 Net::CIDR 1.08 POSIX 1.19 Scalar::Util 1.77 Socket 1.4 Sys::Hostname::Long 0.18 Sys::Syslog 1.9707 Time::HiRes 1.02 Time::localtime Optional module versions are: 1.30 Archive::Tar 0.21 bignum 1.82 Business::ISBN 1.10 Business::ISBN::Data 0.17 Convert::TNEF 1.08 Data::Dump 1.814 DB_File 1.13 DBD::SQLite 1.56 DBI 1.15 Digest 1.01 Digest::HMAC 2.36 Digest::MD5 2.10 Digest::SHA1 1.00 Encode::Detect 0.17008 Error 0.18 ExtUtils::CBuilder 2.18 ExtUtils::ParseXS 0.44 Inline 1.08 IO::String 1.04 IO::Zlib 2.21 IP::Country 0.20 Mail::ClamAV 3.002002 Mail::SpamAssassin v2.004 Mail::SPF 1.999001 Mail::SPF::Query 0.19 Math::BigRat 0.2808 Module::Build 0.20 Net::CIDR::Lite 0.60 Net::DNS 0.002.2 Net::DNS::Resolver::Programmable missing Net::LDAP 4.004 NetAddr::IP 1.94 Parse::RecDescent missing SAVI 2.64 Test::Harness 0.95 Test::Manifest 1.95 Text::Balanced 1.35 URI 0.7203 version 0.62 YAML see attached ms.txt for mailscanner --debug --debug-sa # l /var/spool/MailScanner/incoming/SpamAssassin-Temp/.spamassassin15944T1P9 bFtmp -rw------- 1 root root 2433 Aug 20 03:11 /var/spool/MailScanner/incoming/SpamAssassin-Temp/.spamassassin15944T1P9 bFtmp # fuser /var/spool/MailScanner/incoming/SpamAssassin-Temp/.spamassassin15944T1P9 bFtmp root@houmx05:/var/spool/MailScanner/incoming/SpamAssassin-Temp # grep l7K8B63E015934 /var/log/maillog Aug 20 03:11:14 houmx05 milter-greylist: l7K8B63E015934: skipping greylist because this is the default action, (from=, rcpt=, addr=ARouen-252-1-67-214.w90-23.abo.wanadoo.fr[90.23.62.214]) Aug 20 03:11:14 houmx05 sendmail[15934]: l7K8B63E015934: from=, size=1880, class=0, nrcpts=1, msgid=<000801c7e301$a7518b00$1201a8c0@reginald>, proto=SMTP, daemon=MTA, relay=ARouen-252-1-67-214.w90-23.abo.wanadoo.fr [90.23.62.214] Aug 20 03:11:14 houmx05 sendmail[15934]: l7K8B63E015934: Milter add: header: X-Null-Tag: 6a12c78c6f1e5960796d07939b28851d Aug 20 03:11:14 houmx05 sendmail[15934]: l7K8B63E015934: Milter add: header: X-Greylist: Default is to whitelist mail, not delayed by milter-greylist-3.0rc3 (houmx05.bakerbotts.com [204.194.98.17]); Mon, 20 Aug 2007 03:11:14 -0500 (CDT) Aug 20 03:11:14 houmx05 sendmail[15934]: l7K8B63E015934: to=, delay=00:00:00, mailer=esmtp, pri=31880, stat=queued Aug 20 03:11:29 houmx05 MailScanner[15899]: Message l7K8B63E015934 from 90.23.62.214 (reginald@chmai2.loxinfo.co.th) to bakerbotts.com is not spam, SpamAssassin (not cached, score=0, required 5, autolearn=) Aug 20 03:11:29 houmx05 sendmail[15968]: l7K8B63E015934: to=, delay=00:00:15, xdelay=00:00:00, mailer=esmtp, pri=121880, relay=housweep01.bakerbotts.net. [10.20.254.236], dsn=2.0.0, stat=Sent (Message received OK) Contents of /var/spool/MailScanner/incoming/SpamAssassin-Temp/.spamassassin15944T1P9 bFtmp: X-BakerBotts-MailScanner-From: reginald@chmai2.loxinfo.co.th X-Envelope-From: reginald@chmai2.loxinfo.co.th Return-Path: Received: from abo.wanadoo.fr (ARouen-252-1-67-214.w90-23.abo.wanadoo.fr [90.23.62.214]) by houmx05.bakerbotts.com (8.13.8/8.13.5) with SMTP id l7K8B63E015934 for ; Mon, 20 Aug 2007 03:11:14 -0500 Message-ID: <000801c7e301$a7518b00$1201a8c0@reginald> From: "natal julia" TO: Subject: Hey bro, found this site Date: Mon, 20 Aug 2007 23:02:05 +0300 MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_001_000C_01C7E301.A7518B00" Content-Transfer-Encoding: 7bit X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express Macintosh Edition - 5.01 (1630) X-MimeOLE: Produced By Microsoft MimeOLE V X-Null-Tag: 6a12c78c6f1e5960796d07939b28851d X-Greylist: Default is to whitelist mail, not delayed by milter-greylist-3.0rc3 (houmx05.bakerbotts.com [204.194.98.17]); Mon, 20 Aug 2007 03:11:14 -0500 (CDT) This is a multi-part message in MIME format. ------=_NextPart_001_000C_01C7E301.A7518B00 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit ------=_NextPart_001_000C_01C7E301.A7518B00 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: 7bit

Finally the real thing- no more ripoffs!

Enhancement Patches are hot right now, VERY hot!

Unfortunately, most are cheap imitiations and do very little to increase your size and stamina.

Well this is the real thing, not an imitation!

One of the very originals, the absolutely strongest Patch available, anywhere!

Check out the site for more info TODAY, you'll be glad you did ;)

0rder now




Remove you e-mail

Is there any more debug options I can use to figure this one out? Thanks, Donald Donald Dawson Baker Botts L.L.P. Security Administrator 713-229-2183 Classification: UNCLASSIFIED Caveats: NONE -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Mon Aug 20 19:20:24 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 20 19:21:06 2007 Subject: sophos update installs crontab entry In-Reply-To: <46C9D71F.3010005@chime.ucl.ac.uk> References: <46C9D71F.3010005@chime.ucl.ac.uk> Message-ID: <46C9DB68.1090403@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Anthony Peacock wrote: > Hi, > > Mark Nienberg wrote: >> I noticed that the following recently appeared in my root crontab, >> presumably after MailScanner updated sophos v5: >> >> 3-59/5 * * * * /opt/sophos-av/bin/savupdate >> >> This runs a sophos update every 5 minutes and doesn't do the locking >> that MailScanner does, so it is probably best to delete it and allow >> MailScanner to take care of updates. >> >> I wonder if it is possible to modify the sophos-autoupdate script to >> remove this entry if savupdate creates it? > > -1 > > Please don't. > > I really don't want MailScanner messing with my Sophos install thank > you very much. > But hopefully you install Sophos using my Sophos.install script at the moment. It's possible that script could be written to remove that crontab entry. That way it would only get done once, at install-time. Whatever method you use to install it, do *not* install the on-access scanning. You can safely disable all the sav-* init.d scripts too. I might do some work on that. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Charset: ISO-8859-1 wj8DBQFGydtpEfZZRxQVtlQRAqV9AKD4uLESQBBLsOJTzJRc1SE5whoF9wCg52Jx WMM5gxU/G9tDAmrVDrWsZak= =Aq1U -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From list-mailscanner at linguaphone.com Mon Aug 20 19:32:38 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon Aug 20 19:32:43 2007 Subject: antispam server setup website - comments welcome Message-ID: I have created a little webpage listing the software I use and all the plugins etc... Its designed to be a page I can point people to so they can get an idea of what they should be doing and what additional rules they could be using etc... http://www.gbnetwork.co.uk/mailscanner/index.html Comments appreciated. From MailScanner at ecs.soton.ac.uk Mon Aug 20 19:49:39 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 20 19:50:32 2007 Subject: sophos update installs crontab entry In-Reply-To: References: Message-ID: <46C9E243.1060402@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Mark Nienberg wrote: > I noticed that the following recently appeared in my root crontab, > presumably after MailScanner updated sophos v5: > > 3-59/5 * * * * /opt/sophos-av/bin/savupdate > > This runs a sophos update every 5 minutes and doesn't do the locking > that MailScanner does, so it is probably best to delete it and allow > MailScanner to take care of updates. > > I wonder if it is possible to modify the sophos-autoupdate script to > remove this entry if savupdate creates it? Done, but not in sophos-autoupdate. I have also disabled and switched off the Sophos daemons as you don't need any of them running, they just waste resources and generated yet more unwanted syslog output. These changes will be in the Sophos.install in the next release. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Charset: ISO-8859-1 wj8DBQFGyeJEEfZZRxQVtlQRAgF8AKCLZamHW45xXbnLBPTnUZAJ4H38lwCeKboM qfIUJ54QdltETANIqOW5jUA= =uOQN -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Mon Aug 20 20:09:34 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 20 20:10:38 2007 Subject: antispam server setup website - comments welcome In-Reply-To: References: Message-ID: <46C9E6EE.7010109@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Gareth wrote: > http://www.gbnetwork.co.uk/mailscanner/index.html > > Comments appreciated. > I would remove Pyzor. I've never been a fan of it, and get on well without it. It's only 2 servers which is not good for a global service. I would also add DCC. Very useful and very reliable. I have my own DCC server, which I wouldn't advise you try to set up, it was a right pain to get it working, even with help from the author :-( But do use DCC itself as a client, it helps detect a lot of spam and outages and very very rare. There are multiple servers on multiple sites. Other than those, that looks like a pretty comprehensive list. How much help is all the OCR stuff? I've never installed it, and again find that I can live happily without it. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Charset: ISO-8859-1 wj8DBQFGyebvEfZZRxQVtlQRAq11AJ9vEtDO79O0ADHcoeGYgRf2MLHd0gCdGOjF vBl7XjgG+r2arV/Ayi/XEZk= =CNZL -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From list-mailscanner at linguaphone.com Mon Aug 20 20:28:36 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon Aug 20 20:28:41 2007 Subject: antispam server setup website - comments welcome In-Reply-To: <46C9E6EE.7010109@ecs.soton.ac.uk> Message-ID: I get on fairly well with pyzor. It seems able to detect a lot of the image and pdf spam. I do use the alternative server 82.94.255.100:24441 though which is much more reliable. I do intend to try DCC but I believe it matches any email that a lot of people receive so you have to whitelist any mailing lists you are on? The OCR does work reasonably well although there is a lot that it cannot detect. If you use the sanesecurity signatures for clamav then it is probably not really worth installing as they detect the majority of them and you do need a lot of packages for fuzzyocr to work. I also intend to take a look at CRM114 at some point aswell. > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Julian > Field > Sent: 20 August 2007 20:10 > To: MailScanner discussion > Subject: Re: antispam server setup website - comments welcome > > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Gareth wrote: > > http://www.gbnetwork.co.uk/mailscanner/index.html > > > > Comments appreciated. > > > I would remove Pyzor. I've never been a fan of it, and get on well > without it. It's only 2 servers which is not good for a global service. > > I would also add DCC. Very useful and very reliable. I have my own DCC > server, which I wouldn't advise you try to set up, it was a right pain > to get it working, even with help from the author :-( But do use DCC > itself as a client, it helps detect a lot of spam and outages and very > very rare. There are multiple servers on multiple sites. > > Other than those, that looks like a pretty comprehensive list. > > How much help is all the OCR stuff? I've never installed it, and again > find that I can live happily without it. > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.3 (Build 3017) > Charset: ISO-8859-1 > > wj8DBQFGyebvEfZZRxQVtlQRAq11AJ9vEtDO79O0ADHcoeGYgRf2MLHd0gCdGOjF > vBl7XjgG+r2arV/Ayi/XEZk= > =CNZL > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > From MailScanner at ecs.soton.ac.uk Mon Aug 20 20:43:20 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 20 20:44:01 2007 Subject: antispam server setup website - comments welcome In-Reply-To: References: Message-ID: <46C9EED8.1050201@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Gareth wrote: > I get on fairly well with pyzor. It seems able to detect a lot of the image > and pdf spam. I do use the alternative server 82.94.255.100:24441 though > which is much more reliable. > This is a level of tweaking and maintenance that I don't have the time for. > I do intend to try DCC but I believe it matches any email that a lot of > people receive so you have to whitelist any mailing lists you are on? > I never have, and don't have any problems with it. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Charset: ISO-8859-1 wj8DBQFGye7YEfZZRxQVtlQRAr5kAKDQFzly28dIofxsw6VO7vTMzNSatACfYSZA qh4n6f8jDHpRdXnTw9cafyw= =yURk -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From gmane at tippingmar.com Mon Aug 20 20:46:49 2007 From: gmane at tippingmar.com (Mark Nienberg) Date: Mon Aug 20 20:47:23 2007 Subject: sophos update installs crontab entry In-Reply-To: <46C9E243.1060402@ecs.soton.ac.uk> References: <46C9E243.1060402@ecs.soton.ac.uk> Message-ID: Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Mark Nienberg wrote: >> I noticed that the following recently appeared in my root crontab, >> presumably after MailScanner updated sophos v5: >> >> 3-59/5 * * * * /opt/sophos-av/bin/savupdate >> >> This runs a sophos update every 5 minutes and doesn't do the locking >> that MailScanner does, so it is probably best to delete it and allow >> MailScanner to take care of updates. >> >> I wonder if it is possible to modify the sophos-autoupdate script to >> remove this entry if savupdate creates it? > Done, but not in sophos-autoupdate. I have also disabled and switched > off the Sophos daemons as you don't need any of them running, they just > waste resources and generated yet more unwanted syslog output. > > These changes will be in the Sophos.install in the next release. That is a nice improvement to Sophos.install. I guess you are saying that we need to monitor crontab and manually remove the savupdate whenever it reappears? The crontab entry was put there during the initial Sophos installation but I had removed it many months ago. It reappeared recently, though I have made no changes to my Sophos installation. Mark From list-mailscanner at linguaphone.com Mon Aug 20 20:50:04 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon Aug 20 20:50:16 2007 Subject: SpamAssassin Rule Actions enhancement Message-ID: How easy would it be to enhance the 'SpamAssassin Rule Actions' section so that you could write a rule based on the smapassassin score itself? For example :- SpamAssassin Rule Actions = SASCORE>25=>not-deliver store The reason being is that I use the low scoring spam options to mark spam as possible spam and deliver it. High scoring marks mail as spam and delivers it. I would like to be able to just delete anything which is very high scoring. Thanks Gareth From MailScanner at ecs.soton.ac.uk Mon Aug 20 22:10:24 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 20 22:11:41 2007 Subject: SpamAssassin Rule Actions enhancement In-Reply-To: References: Message-ID: <46CA0340.6050701@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 That's a really good idea. I have changed SASCORE to SpamScore but otherwise I have done a full implementation of what you wanted. So instead of a SpamAssassin rule name, you can give any of SpamScore>25 SpamScore>=25 SpamScore==25 SpamScore<=25 SpamScore<25 Note you can only give 1 action per rulename (or spamscore comparison), so to correct your example below, you would have to say SpamAssassin Rule Actions = SpamScore>25=>not-deliver, SpamScore>25=>store This will be in the next release. Note that it can be used to implement as many levels of spam actions as you want. So if normal spam actions and high-scoring spam actions aren't enough for you, you can use this to implement a 3rd or even a 4th level of spam actions as well. Jules. Gareth wrote: > How easy would it be to enhance the 'SpamAssassin Rule Actions' section so > that you could write a rule based on the smapassassin score itself? > For example :- > SpamAssassin Rule Actions = SASCORE>25=>not-deliver store > > The reason being is that I use the low scoring spam options to mark spam as > possible spam and deliver it. High scoring marks mail as spam and delivers > it. I would like to be able to just delete anything which is very high > scoring. > > Thanks > Gareth > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Charset: ISO-8859-1 wj8DBQFGygNNEfZZRxQVtlQRAkN+AJkBqYI0KBh1X+D0BQxw5AGTSOyjvwCgl5Un TGbkU+jBhupmH806ZFeAjcw= =5Uje -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From tim at denmantire.com Mon Aug 20 22:22:00 2007 From: tim at denmantire.com (Tim Boyer) Date: Mon Aug 20 22:22:16 2007 Subject: Heads up for spamhaus.org problems References: <20070819222357.GA27826@rpcs.net> <20070820020201.GA2841@rpcs.net> Message-ID: On Sun, 19 Aug 2007 22:02:01 -0400, Richard Potter wrote: >On Mon, Aug 20, 2007 at 12:34:23AM +0200, Raymond Dijkxhoorn wrote: > >> >Just doing a routine check here, and I have a few mail servers >> >misbehaving. It >> >*appears* sendmail dnsbl to zen.spamhaus.org is timing out, and causing >> >mail >> >delivery delays, or none at all. >> > >> >I'm going to discontinue spamhaus, and see what happens. >> >> Buy rsync from them. Most likely you fire a lot of lookups on their >> servers and they started to ban high volume mailservers some time ago. >> We have seen this in a lot of places allready. >> >> May i ask how much mail are you processing daily? > >Thanks for the reply Raymond.. I wasn't aware they were doing that. These >are low volume servers, less than 2,000 messages per day. Does that count >as "high volume" to spamhaus? > >Richard "Use of the Spamhaus DNSBLs via DNS queries to our public DNSBL mirrors is free for low-traffic mail servers serving less than 100 users. Use of the Spamhaus DNSBLs by commercial or corporate networks, ISPs and ESPs, requires a subscription to Spamhaus's Data Feed service." I'd be shocked if 2,000 messages per day counts as high volume. That's 20 emails per person per day. -- tim boyer tim@denmantire.com From ms-list at alexb.ch Mon Aug 20 22:34:05 2007 From: ms-list at alexb.ch (Alex Broens) Date: Mon Aug 20 22:34:13 2007 Subject: Heads up for spamhaus.org problems In-Reply-To: References: <20070819222357.GA27826@rpcs.net> <20070820020201.GA2841@rpcs.net> Message-ID: <46CA08CD.8070400@alexb.ch> On 8/20/2007 11:22 PM, Tim Boyer wrote: > On Sun, 19 Aug 2007 22:02:01 -0400, Richard Potter wrote: > >> On Mon, Aug 20, 2007 at 12:34:23AM +0200, Raymond Dijkxhoorn wrote: >> >>>> Just doing a routine check here, and I have a few mail servers >>>> misbehaving. It >>>> *appears* sendmail dnsbl to zen.spamhaus.org is timing out, and causing >>>> mail >>>> delivery delays, or none at all. >>>> >>>> I'm going to discontinue spamhaus, and see what happens. >>> Buy rsync from them. Most likely you fire a lot of lookups on their >>> servers and they started to ban high volume mailservers some time ago. >>> We have seen this in a lot of places allready. >>> >>> May i ask how much mail are you processing daily? >> Thanks for the reply Raymond.. I wasn't aware they were doing that. These >> are low volume servers, less than 2,000 messages per day. Does that count >> as "high volume" to spamhaus? >> >> Richard > > "Use of the Spamhaus DNSBLs via DNS queries to our public DNSBL mirrors is free > for low-traffic mail servers serving less than 100 users. Use of the Spamhaus > DNSBLs by commercial or corporate networks, ISPs and ESPs, requires a > subscription to Spamhaus's Data Feed service." > > I'd be shocked if 2,000 messages per day counts as high volume. That's 20 > emails per person per day. no need to be shocked :-) Spamhaus can't block your mail server from doing queries - it blocks your DNS' access to the root zone - so if you use a DNS which is querying Xmillion queries/day and your server is only doing 10000/day then the rest of the X/million+your 10000 makes he count which rates a block. Alex From list-mailscanner at linguaphone.com Mon Aug 20 22:34:02 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon Aug 20 22:34:18 2007 Subject: Heads up for spamhaus.org problems In-Reply-To: Message-ID: > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Tim > Boyer > Sent: 20 August 2007 22:22 > To: mailscanner@lists.mailscanner.info > Subject: Re: Heads up for spamhaus.org problems > > > On Sun, 19 Aug 2007 22:02:01 -0400, Richard Potter > wrote: > > >On Mon, Aug 20, 2007 at 12:34:23AM +0200, Raymond Dijkxhoorn wrote: > > > >> >Just doing a routine check here, and I have a few mail servers > >> >misbehaving. It > >> >*appears* sendmail dnsbl to zen.spamhaus.org is timing out, > and causing > >> >mail > >> >delivery delays, or none at all. > >> > > >> >I'm going to discontinue spamhaus, and see what happens. > >> > >> Buy rsync from them. Most likely you fire a lot of lookups on their > >> servers and they started to ban high volume mailservers some time ago. > >> We have seen this in a lot of places allready. > >> > >> May i ask how much mail are you processing daily? > > > >Thanks for the reply Raymond.. I wasn't aware they were doing that. These > >are low volume servers, less than 2,000 messages per day. Does that count > >as "high volume" to spamhaus? > > > >Richard > > "Use of the Spamhaus DNSBLs via DNS queries to our public DNSBL > mirrors is free > for low-traffic mail servers serving less than 100 users. Use of > the Spamhaus > DNSBLs by commercial or corporate networks, ISPs and ESPs, requires a > subscription to Spamhaus's Data Feed service." > > I'd be shocked if 2,000 messages per day counts as high volume. That's 20 > emails per person per day. > >From my experience when we moved over to MailScanner we did it gradually and on the 3rd day we were processing about 2000-2500 messages per day. On day 4 the Spamhaus DNSBLs stopped matching and never worked from that point onwards. So I would not be surprised if others got blocked for 2000 messages per day. From list-mailscanner at linguaphone.com Mon Aug 20 22:34:34 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon Aug 20 22:34:38 2007 Subject: SpamAssassin Rule Actions enhancement In-Reply-To: <46CA0340.6050701@ecs.soton.ac.uk> Message-ID: Thanks. I'm glad you thought it was a good idea :) > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Julian > Field > Sent: 20 August 2007 22:10 > To: MailScanner discussion > Subject: Re: SpamAssassin Rule Actions enhancement > > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > That's a really good idea. I have changed SASCORE to SpamScore but > otherwise I have done a full implementation of what you wanted. So > instead of a SpamAssassin rule name, you can give any of > SpamScore>25 > SpamScore>=25 > SpamScore==25 > SpamScore<=25 > SpamScore<25 > > Note you can only give 1 action per rulename (or spamscore comparison), > so to correct your example below, you would have to say > > SpamAssassin Rule Actions = SpamScore>25=>not-deliver, SpamScore>25=>store > > This will be in the next release. > > Note that it can be used to implement as many levels of spam actions as > you want. So if normal spam actions and high-scoring spam actions aren't > enough for you, you can use this to implement a 3rd or even a 4th level > of spam actions as well. > > Jules. > > Gareth wrote: > > How easy would it be to enhance the 'SpamAssassin Rule Actions' > section so > > that you could write a rule based on the smapassassin score itself? > > For example :- > > SpamAssassin Rule Actions = SASCORE>25=>not-deliver store > > > > The reason being is that I use the low scoring spam options to > mark spam as > > possible spam and deliver it. High scoring marks mail as spam > and delivers > > it. I would like to be able to just delete anything which is very high > > scoring. > > > > Thanks > > Gareth > > > > > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.3 (Build 3017) > Charset: ISO-8859-1 > > wj8DBQFGygNNEfZZRxQVtlQRAkN+AJkBqYI0KBh1X+D0BQxw5AGTSOyjvwCgl5Un > TGbkU+jBhupmH806ZFeAjcw= > =5Uje > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > From ard at pergamentum.com Mon Aug 20 23:07:33 2007 From: ard at pergamentum.com (Alisdair Davey) Date: Mon Aug 20 23:07:51 2007 Subject: Heads up for spamhaus.org problems In-Reply-To: Message-ID: <200708202207.l7KM7Xda007804@www4.pergamentum.com> > > I'd be shocked if 2,000 messages per day counts as high volume. That's 20 > > emails per person per day. > > >From my experience when we moved over to MailScanner we did it gradually and > on the 3rd day we were processing about 2000-2500 messages per day. On day 4 > the Spamhaus DNSBLs stopped matching and never worked from that point > onwards. So I would not be surprised if others got blocked for 2000 messages > per day. I did a quick count through my log file for today - for 852 delivered messages I rejected 12716 with Spamhaus DNSBLs. That's almost 15:1... Alisdair -- Alisdair Davey ard@pergamentum.com Pergamentum Solutions 2066 Dailey Lane Superior, CO 80027 From ssilva at sgvwater.com Mon Aug 20 23:43:01 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon Aug 20 23:43:14 2007 Subject: White Listing emails from eBay? In-Reply-To: References: <223f97700708200126w31eeb65r8847a646a7f0dc34@mail.gmail.com> Message-ID: Paul Hutchings spake the following on 8/20/2007 1:37 AM: > I think the issue is not that it's a false positive - I'd want to know > if it came from anywhere other than from eBay. > > I'll investigate the DKIM suggestion from Martin - as a sticking plaster > though is emailebay.com a workable suggestion? > Name based whitelisting is too easy to fool. Envelopes are easily forged. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Mon Aug 20 23:57:15 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon Aug 20 23:57:31 2007 Subject: antispam server setup website - comments welcome In-Reply-To: References: <46C9E6EE.7010109@ecs.soton.ac.uk> Message-ID: Gareth spake the following on 8/20/2007 12:28 PM: > I get on fairly well with pyzor. It seems able to detect a lot of the image > and pdf spam. I do use the alternative server 82.94.255.100:24441 though > which is much more reliable. > > I do intend to try DCC but I believe it matches any email that a lot of > people receive so you have to whitelist any mailing lists you are on? > Usually mailing list messages get on there from people who use a "report-as-spam" button on messages they are too lazy to unsubscribe from. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From hmkash at arl.army.mil Tue Aug 21 00:38:31 2007 From: hmkash at arl.army.mil (Kash, Howard (Civ, ARL/CISD)) Date: Tue Aug 21 00:36:20 2007 Subject: SpamAssassin Rule Actions enhancement (UNCLASSIFIED) In-Reply-To: <46CA0340.6050701@ecs.soton.ac.uk> References: <46CA0340.6050701@ecs.soton.ac.uk> Message-ID: <88991ECEE371C644986F0C8837C207B701CC314E@ARLABML01.DS.ARL.ARMY.MIL> Classification: Caveats: *NOTICE: Would anyone else be interested in an option to the 'store' action to specify a directory relative to 'Quarantine Dir'? This way various levels of spamness can be stored in different directories. For example: SpamAssassin Rule Actions = SpamScore>25=>store HIGH, SpamScore>15=>store MED, SpamScore>=5=>store LOW, SpamScore<5=>deliver would store messages with SA scores between 5 and 15 in /var/spool/MailScanner/quarantine/spam/LOW, scores between 15 and 25 in /var/spool/MailScanner/quarantine/spam/MED, and scores over 25 in /var/spool/MailScanner/quarantine/spam/HIGH. How will the 'SpamAssassin Rule Actions', 'Spam Actions', and 'High Scoring Spam Actions' be prioritized? In other words, which one will have presedence if there are conflicting settings (i.e. High Scoring Spam Actions = delete, SpamAssassin Rule Actions = SpamScore>15=>store)? Thanks, Howard Classification: Caveats: From culleym at genevawoods.com Tue Aug 21 01:06:40 2007 From: culleym at genevawoods.com (Culley Morrow) Date: Tue Aug 21 01:07:00 2007 Subject: New Clam, Old, Mailscanner, Ancient Kernel Message-ID: <001a01c7e387$266c2460$0202fea9@genevawoods.com> Howdy folks, I've got a bit of a dilemma here. I've taken over admin for an aging Debian 3.0 server partly morphed to 4.0. By partly I mean it is still using the default 2.4.18-bf2.4 kernel. Way, way, out of date. The upshot is we are planning to replace it in the vaguely near future once we decide what groupware package to put in it's place. I'll list out the software versions below and I need a bit of assistance making them work for now. I know all I need to do is upgrade the kernel to 2.6 and it all works, but I'd like to get them functioning "As-Is" and then do the upgrade so I have something working to fall back on. Clam AV is currently shut off since clamd as a service was so slow. Kernel 2.4.18-bf2.4 Mailscanner 3.27.1-1 Clam AV 0.90.1-3etch3 Spam Assassin 2.64-1 Currently we are inundated with mass spam and I need to get some AV in place, be it Clam or another GNU/GPL/"free as in beer"-ware. I need a hand here if anyone wants to chime in. ~={o}=~ Culley Morrow IT Manager Geneva Woods Pharmacy -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070820/249d59f8/attachment.html From jim.barber at ddihealth.com Tue Aug 21 01:30:54 2007 From: jim.barber at ddihealth.com (Jim Barber) Date: Tue Aug 21 01:31:03 2007 Subject: MailScanner mailing list ended up on a black list. Message-ID: <46CA323E.9020403@ddihealth.com> Hi all. Last night I noticed that most (all?) of my incoming posts from this list were tagged as spam (despite having really low scores). I found the cause was due to an RBL server that I use having listed one of the email servers this list comes from. The MailScanner server that is getting black listed is: 83.98.192.7 which reverse resolves to safir.blacknight.ie The RBL server that I am using is blackholes.five-ten-sg.com This one I've added myself, but I am reluctant to remove it since so far over the months it has served me well. If you go to http://www.five-ten-sg.com/blackhole.php and enter 83.98.192.7 into the form it comes back with the following: ------------------------------------------------------------ IP address 83.98.192.7 is listed here as 83.98.192.165 misc. Although there may be other reasons, most of the listings in this category are due to (1. systems apparently sending bulk mail from ip addresses with bogus or missing reverse dns, or with no web server, or with boilerplate web content, or 2. a suspected multistage relay output, or 3. machines probably running MS SMTPSVC with an open guest account, or 4. running some open proxy), or it is in the same /24 subnet containing multiple machines with that property. ------------------------------------------------------------ The 'misc' (127.0.0.9) return code is defined by the site as: ------------------------------------------------------------ misc - Miscellaneous includes (but is NOT limited to) the following groups. Note that this does NOT include misc.spam which is listed under spam above. 1) /24 blocks of addresses containing systems that are apparently sending bulk email (in volumes apparently comparable with the volume from AOL, Earthlink, Google), with any of the following attributes: missing or bogus reverse dns, reverse dns names in domains with no web server, or domains with boilerplate web content. 2) Systems that are strongly suspected of being multistage open relays (where I have not been able to identify the input stage) or open proxies. 3) Any system that delivers spam here, that appears to be running MS SMTPSVC, and that appears to have relayed the message from China, Korea, Brazil, or any known open proxy. These are generally systems that have enabled the guest account, and spammers are using them as open relays, even though they do require SMTP AUTH. Enabling the guest account allows anyone to relay thru them. ------------------------------------------------------------ Is this the correct place to report it to? It's sort of ironic having an anti-spam list ending up marked as spam. Oh well. Regards, -- ---------- Jim Barber DDI Health From rpotter at rpcs.net Tue Aug 21 01:53:42 2007 From: rpotter at rpcs.net (Richard Potter) Date: Tue Aug 21 01:53:51 2007 Subject: Heads up for spamhaus.org problems In-Reply-To: <46CA08CD.8070400@alexb.ch> References: <20070819222357.GA27826@rpcs.net> <20070820020201.GA2841@rpcs.net> <46CA08CD.8070400@alexb.ch> Message-ID: <20070821005342.GA5580@rpcs.net> On Mon, Aug 20, 2007 at 11:34:05PM +0200, Alex Broens wrote: > On 8/20/2007 11:22 PM, Tim Boyer wrote: > >On Sun, 19 Aug 2007 22:02:01 -0400, Richard Potter > >wrote: > > > >>On Mon, Aug 20, 2007 at 12:34:23AM +0200, Raymond Dijkxhoorn wrote: > >> > >>>>Just doing a routine check here, and I have a few mail servers > >>>>misbehaving. It > >>>>*appears* sendmail dnsbl to zen.spamhaus.org is timing out, and causing > >>>>mail > >>>>delivery delays, or none at all. > >>>> > >>>>I'm going to discontinue spamhaus, and see what happens. > >>>Buy rsync from them. Most likely you fire a lot of lookups on their > >>>servers and they started to ban high volume mailservers some time ago. > >>>We have seen this in a lot of places allready. > >>> > >>>May i ask how much mail are you processing daily? > >>Thanks for the reply Raymond.. I wasn't aware they were doing that. These > >>are low volume servers, less than 2,000 messages per day. Does that count > >>as "high volume" to spamhaus? > >> > >>Richard > > > >"Use of the Spamhaus DNSBLs via DNS queries to our public DNSBL mirrors is > >free > >for low-traffic mail servers serving less than 100 users. Use of the > >Spamhaus > >DNSBLs by commercial or corporate networks, ISPs and ESPs, requires a > >subscription to Spamhaus's Data Feed service." > > > >I'd be shocked if 2,000 messages per day counts as high volume. That's 20 > >emails per person per day. > > no need to be shocked :-) > > Spamhaus can't block your mail server from doing queries - it blocks > your DNS' access to the root zone - so if you use a DNS which is > querying Xmillion queries/day and your server is only doing 10000/day > then the rest of the X/million+your 10000 makes he count which rates a > block. You are exactly right. I was told that off list. I switched the two boxes to an alternative DNS server, and spamhaus worked again. I'm not sure why I didn't figure that out on my own. I actually knew/should have known that. It was Sunday, and I might have had a few beers! :-) Richard From dave.list at pixelhammer.com Tue Aug 21 04:05:55 2007 From: dave.list at pixelhammer.com (DAve) Date: Tue Aug 21 04:07:18 2007 Subject: Heads up for spamhaus.org problems In-Reply-To: <20070821005342.GA5580@rpcs.net> References: <20070819222357.GA27826@rpcs.net> <20070820020201.GA2841@rpcs.net> <46CA08CD.8070400@alexb.ch> <20070821005342.GA5580@rpcs.net> Message-ID: <46CA5693.1090400@pixelhammer.com> Richard Potter wrote: > On Mon, Aug 20, 2007 at 11:34:05PM +0200, Alex Broens wrote: > >> On 8/20/2007 11:22 PM, Tim Boyer wrote: >>> On Sun, 19 Aug 2007 22:02:01 -0400, Richard Potter >>> wrote: >>> >>>> On Mon, Aug 20, 2007 at 12:34:23AM +0200, Raymond Dijkxhoorn wrote: >>>> >>>>>> Just doing a routine check here, and I have a few mail servers >>>>>> misbehaving. It >>>>>> *appears* sendmail dnsbl to zen.spamhaus.org is timing out, and causing >>>>>> mail >>>>>> delivery delays, or none at all. >>>>>> >>>>>> I'm going to discontinue spamhaus, and see what happens. >>>>> Buy rsync from them. Most likely you fire a lot of lookups on their >>>>> servers and they started to ban high volume mailservers some time ago. >>>>> We have seen this in a lot of places allready. >>>>> >>>>> May i ask how much mail are you processing daily? >>>> Thanks for the reply Raymond.. I wasn't aware they were doing that. These >>>> are low volume servers, less than 2,000 messages per day. Does that count >>>> as "high volume" to spamhaus? >>>> >>>> Richard >>> "Use of the Spamhaus DNSBLs via DNS queries to our public DNSBL mirrors is >>> free >>> for low-traffic mail servers serving less than 100 users. Use of the >>> Spamhaus >>> DNSBLs by commercial or corporate networks, ISPs and ESPs, requires a >>> subscription to Spamhaus's Data Feed service." >>> >>> I'd be shocked if 2,000 messages per day counts as high volume. That's 20 >>> emails per person per day. >> no need to be shocked :-) >> >> Spamhaus can't block your mail server from doing queries - it blocks >> your DNS' access to the root zone - so if you use a DNS which is >> querying Xmillion queries/day and your server is only doing 10000/day >> then the rest of the X/million+your 10000 makes he count which rates a >> block. > > > You are exactly right. I was told that off list. I switched the two > boxes to an alternative DNS server, and spamhaus worked again. > > I'm not sure why I didn't figure that out on my own. I actually > knew/should have known that. It was Sunday, and I might have had a > few beers! :-) > > Richard Are you using a caching server? Possibly it's not the 2000 queries a day they block, but the 10,000 needlessly repeated queries from the same DNS server. DAve -- Three years now I've asked Google why they don't have a logo change for Memorial Day. Why do they choose to do logos for other non-international holidays, but nothing for Veterans? Maybe they forgot who made that choice possible. From dave.list at pixelhammer.com Tue Aug 21 04:45:35 2007 From: dave.list at pixelhammer.com (DAve) Date: Tue Aug 21 04:46:57 2007 Subject: Heads up for spamhaus.org problems In-Reply-To: <46CA5693.1090400@pixelhammer.com> References: <20070819222357.GA27826@rpcs.net> <20070820020201.GA2841@rpcs.net> <46CA08CD.8070400@alexb.ch> <20070821005342.GA5580@rpcs.net> <46CA5693.1090400@pixelhammer.com> Message-ID: <46CA5FDF.80609@pixelhammer.com> DAve wrote: > Richard Potter wrote: >> On Mon, Aug 20, 2007 at 11:34:05PM +0200, Alex Broens wrote: >> >>> On 8/20/2007 11:22 PM, Tim Boyer wrote: >>>> On Sun, 19 Aug 2007 22:02:01 -0400, Richard Potter >>>> wrote: >>>> >>>>> On Mon, Aug 20, 2007 at 12:34:23AM +0200, Raymond Dijkxhoorn wrote: >>>>> >>>>>>> Just doing a routine check here, and I have a few mail servers >>>>>>> misbehaving. It >>>>>>> *appears* sendmail dnsbl to zen.spamhaus.org is timing out, and >>>>>>> causing mail >>>>>>> delivery delays, or none at all. >>>>>>> >>>>>>> I'm going to discontinue spamhaus, and see what happens. >>>>>> Buy rsync from them. Most likely you fire a lot of lookups on >>>>>> their servers and they started to ban high volume mailservers some >>>>>> time ago. >>>>>> We have seen this in a lot of places allready. >>>>>> >>>>>> May i ask how much mail are you processing daily? >>>>> Thanks for the reply Raymond.. I wasn't aware they were doing that. >>>>> These >>>>> are low volume servers, less than 2,000 messages per day. Does that >>>>> count >>>>> as "high volume" to spamhaus? >>>>> >>>>> Richard >>>> "Use of the Spamhaus DNSBLs via DNS queries to our public DNSBL >>>> mirrors is free >>>> for low-traffic mail servers serving less than 100 users. Use of the >>>> Spamhaus >>>> DNSBLs by commercial or corporate networks, ISPs and ESPs, requires a >>>> subscription to Spamhaus's Data Feed service." >>>> >>>> I'd be shocked if 2,000 messages per day counts as high volume. >>>> That's 20 >>>> emails per person per day. >>> no need to be shocked :-) >>> >>> Spamhaus can't block your mail server from doing queries - it blocks >>> your DNS' access to the root zone - so if you use a DNS which is >>> querying Xmillion queries/day and your server is only doing 10000/day >>> then the rest of the X/million+your 10000 makes he count which rates >>> a block. >> >> >> You are exactly right. I was told that off list. I switched the two >> boxes to an alternative DNS server, and spamhaus worked again. >> >> I'm not sure why I didn't figure that out on my own. I actually >> knew/should have known that. It was Sunday, and I might have had a few >> beers! :-) >> >> Richard > > Are you using a caching server? Possibly it's not the 2000 queries a day > they block, but the 10,000 needlessly repeated queries from the same DNS > server. > > DAve > I am *not* suggesting spamhaus blocks are your fault. When I re read my response it looked kinda mean the way I said it. I apologize if it appears that way. I do suspect spamhaus gets a large number of queries from non-caching servers. The use of a DNS cache is faster for you, less load for them, everyone wins. DAve -- Three years now I've asked Google why they don't have a logo change for Memorial Day. Why do they choose to do logos for other non-international holidays, but nothing for Veterans? Maybe they forgot who made that choice possible. From wolfgang at sweet-haven.com Tue Aug 21 06:46:59 2007 From: wolfgang at sweet-haven.com (Lew Wolfgang) Date: Tue Aug 21 06:47:11 2007 Subject: MailScanner mailing list ended up on a black list. In-Reply-To: <46CA323E.9020403@ddihealth.com> References: <46CA323E.9020403@ddihealth.com> Message-ID: <46CA7C53.5050000@sweet-haven.com> Hi Jim, Well, it happened to me too. One of my sites hosts email for a small research company. This past Saturday I noticed that a message from the president to his sister on hotmail.com was rejected as being spammy. A quick check showed that we were listed on apews.org with the reason being that another host on our subnet was caught spamming, but is now shut down. Further, it's a /17 subnet! 32,765 other innocent sites (potentially) were judged guilty by association! Microsoft's web site said the thing to do was implement SPF, which I did and after registering with Microsoft, was able to send mail to hotmail/msn addresses. SPF overrides a hit from a DNSBL in Microsoft's world, I guess. Then, this evening, we had another spammy bounce from an att.net address. This time, we're also listed in blackholes.five-ten-sg.com for the same "guilt by association" rationale. I guess they got mailscanner.info with the same broad brush. I see that 83.98.192.7 is in apews.org too. It's not right that innocent mail users and smtp sites have to change IP addresses and/or hosting companies to get away from spam-by-association. I also don't think that customer complaints to the likes of att.net and Microsoft would carry much water. So what are we to do? Lew Wolfgang Jim Barber wrote: > Hi all. > > Last night I noticed that most (all?) of my incoming posts from this > list were tagged as spam (despite having really low scores). > I found the cause was due to an RBL server that I use having listed one > of the email servers this list comes from. > > The MailScanner server that is getting black listed is: 83.98.192.7 > which reverse resolves to safir.blacknight.ie > The RBL server that I am using is blackholes.five-ten-sg.com > This one I've added myself, but I am reluctant to remove it since so far > over the months it has served me well. > > If you go to http://www.five-ten-sg.com/blackhole.php and enter > 83.98.192.7 into the form it comes back with the following: > > ------------------------------------------------------------ > IP address 83.98.192.7 is listed here as 83.98.192.165 misc. > > Although there may be other reasons, most of the listings in this > category are due to > (1. systems apparently sending bulk mail from ip addresses with bogus or > missing reverse dns, or with no web server, or with boilerplate web > content, or > 2. a suspected multistage relay output, or > 3. machines probably running MS SMTPSVC with an open guest account, or > 4. running some open proxy), or it is in the same /24 subnet containing > multiple machines with that property. > ------------------------------------------------------------ > > The 'misc' (127.0.0.9) return code is defined by the site as: > > ------------------------------------------------------------ > misc - Miscellaneous includes (but is NOT limited to) the following groups. > Note that this does NOT include misc.spam which is listed under spam above. > 1) /24 blocks of addresses containing systems that are apparently > sending bulk email (in volumes apparently comparable with the volume > from AOL, Earthlink, Google), with any of the following attributes: > missing or bogus reverse dns, reverse dns names in domains with no web > server, or domains with boilerplate web content. > 2) Systems that are strongly suspected of being multistage open relays > (where I have not been able to identify the input stage) or open proxies. > 3) Any system that delivers spam here, that appears to be running MS > SMTPSVC, and that appears to have relayed the message from China, Korea, > Brazil, or any known open proxy. > These are generally systems that have enabled the guest account, and > spammers are using them as open relays, even though they do require SMTP > AUTH. > Enabling the guest account allows anyone to relay thru them. > ------------------------------------------------------------ > > Is this the correct place to report it to? > It's sort of ironic having an anti-spam list ending up marked as spam. > Oh well. > > Regards, > From jim.barber at ddihealth.com Tue Aug 21 07:07:40 2007 From: jim.barber at ddihealth.com (Jim Barber) Date: Tue Aug 21 07:07:51 2007 Subject: {Spam?} Re: MailScanner mailing list ended up on a black list. In-Reply-To: <46CA7C53.5050000@sweet-haven.com> References: <46CA323E.9020403@ddihealth.com> <46CA7C53.5050000@sweet-haven.com> Message-ID: <46CA812C.9070903@ddihealth.com> An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070821/e2e316c2/attachment.html From Robert.Horton at goodmanmfg.com Tue Aug 21 07:13:34 2007 From: Robert.Horton at goodmanmfg.com (Horton, Robert) Date: Tue Aug 21 07:13:37 2007 Subject: CRM114 Problem In-Reply-To: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info> Message-ID: <50678FBB708A9B4FB6B536F6F657883D028E9528@exch-gman.ad.goodmanmfg.com> Are you still having problems with the score at -0.00? I finally installed this evening and had the same problem. I think there is a bug in the crm114.pm (Version: 0.6.4), but what perplexes me is why some people claim its working...the lines I changed should affect everyone. Maybe this code was changed recently. I changed the following 2 lines in the sub call_crm dbg("crm114: opening pipe: $crm114_command < $tmpf"); $pid = Mail::SpamAssassin::Util::helper_app_pipe_open( *CRM_OUT, $tmpf, 1, $crm114_command); to dbg("crm114: opening pipe: $crm114_cmdline < $tmpf"); $pid = Mail::SpamAssassin::Util::helper_app_pipe_open( *CRM_OUT, $tmpf, 1, $crm114_cmdline); Within minutes crm114 started learning emails and no longer had the -0.00 score. You only get this score when you have an empty spam.css and nonspam.css and it doesn't know what to do with the email yet. Hope this helps, Robert Horton -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Mike Kercher Sent: Friday, August 10, 2007 11:13 AM To: MailScanner discussion Subject: CRM114 Problem I added CRM114 to a server last week per the docs in the wiki (and like I've done on several other servers), but the score is always -0.00 [root@mail crm114]# cssutil -b -r spam.css Sparse spectra file spam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 15495 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 [root@mail crm114]# cssutil -b -r nonspam.css Sparse spectra file nonspam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 15495 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 The Features learned hasn't changed in many days. Permissions look good, .crm's are +x Any suggestions where to look? Mike -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! CONFIDENTIALITY NOTE: The information contained in this transmission is privileged and confidential information intended only for the use of the individual or entity named above. If the reader of this message is not the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this transmission in error, do not read it. Please immediately reply to the sender that you have received this communication in error and then delete it. Thank you. From list-mailscanner at linguaphone.com Tue Aug 21 08:37:16 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue Aug 21 08:37:34 2007 Subject: SpamAssassin Rule Actions enhancement (UNCLASSIFIED) In-Reply-To: <88991ECEE371C644986F0C8837C207B701CC314E@ARLABML01.DS.ARL.ARMY.MIL> References: <46CA0340.6050701@ecs.soton.ac.uk> <88991ECEE371C644986F0C8837C207B701CC314E@ARLABML01.DS.ARL.ARMY.MIL> Message-ID: <1187681835.16331.2.camel@gblades-suse.linguaphone-intranet.co.uk> On Tue, 2007-08-21 at 00:38, Kash, Howard (Civ, ARL/CISD) wrote: > Classification: Caveats: *NOTICE: > > Would anyone else be interested in an option to the 'store' action to > specify a directory relative to 'Quarantine Dir'? This way various > levels of spamness can be stored in different directories. For example: > > SpamAssassin Rule Actions = SpamScore>25=>store HIGH, > SpamScore>15=>store MED, SpamScore>=5=>store LOW, SpamScore<5=>deliver > > would store messages with SA scores between 5 and 15 in > /var/spool/MailScanner/quarantine/spam/LOW, scores between 15 and 25 in > /var/spool/MailScanner/quarantine/spam/MED, and scores over 25 in > /var/spool/MailScanner/quarantine/spam/HIGH. > > > How will the 'SpamAssassin Rule Actions', 'Spam Actions', and 'High > Scoring Spam Actions' be prioritized? In other words, which one will > have presedence if there are conflicting settings (i.e. High Scoring > Spam Actions = delete, SpamAssassin Rule Actions = SpamScore>15=>store)? I assume that the spam actions and high scoring spam action will work as normal. Then the custom rules would apply so if the high scoring option was to deliver you would have to specify the not-deliver action in the custom action if you did not want the email delivered. From martinh at solidstatelogic.com Tue Aug 21 08:39:23 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Tue Aug 21 08:39:49 2007 Subject: antispam server setup website - comments welcome In-Reply-To: <46C9E6EE.7010109@ecs.soton.ac.uk> Message-ID: <7596c7e1d87a2241863c8959a0954aac@solidstatelogic.com> Jules Pyzor is fine, but you have to run a different server other than the broken one 'pyzor update' gives gives you... 82.94.255.100:24441 Is the functioning one. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Julian Field > Sent: 20 August 2007 20:10 > To: MailScanner discussion > Subject: Re: antispam server setup website - comments welcome > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Gareth wrote: > > http://www.gbnetwork.co.uk/mailscanner/index.html > > > > Comments appreciated. > > > I would remove Pyzor. I've never been a fan of it, and get on well > without it. It's only 2 servers which is not good for a global service. > > I would also add DCC. Very useful and very reliable. I have my own DCC > server, which I wouldn't advise you try to set up, it was a right pain > to get it working, even with help from the author :-( But do use DCC > itself as a client, it helps detect a lot of spam and outages and very > very rare. There are multiple servers on multiple sites. > > Other than those, that looks like a pretty comprehensive list. > > How much help is all the OCR stuff? I've never installed it, and again > find that I can live happily without it. > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.3 (Build 3017) > Charset: ISO-8859-1 > > wj8DBQFGyebvEfZZRxQVtlQRAq11AJ9vEtDO79O0ADHcoeGYgRf2MLHd0gCdGOjF > vBl7XjgG+r2arV/Ayi/XEZk= > =CNZL > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From list-mailscanner at linguaphone.com Tue Aug 21 08:41:32 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue Aug 21 08:41:41 2007 Subject: New Clam, Old, Mailscanner, Ancient Kernel In-Reply-To: <001a01c7e387$266c2460$0202fea9@genevawoods.com> References: <001a01c7e387$266c2460$0202fea9@genevawoods.com> Message-ID: <1187682092.16339.6.camel@gblades-suse.linguaphone-intranet.co.uk> My home system is still running redhat 9 with kernel-2.4.20-31.9. I dont have mailscanner or clamav on there but I am running the latest spamassassin with a whole load of plugins. The main thing to do is upgrade perl to 5.8.8 and you should be able to do that through CPAN. Once thats on then you should be able to install spamassassin 3.2.3 and MailScanner without problems as they are all perl based. On Tue, 2007-08-21 at 01:06, Culley Morrow wrote: > Howdy folks, I?ve got a bit of a dilemma here. I?ve taken over admin > for an aging Debian 3.0 server partly morphed to 4.0. By partly I mean > it is still using the default 2.4.18-bf2.4 kernel. Way, way, out of > date. The upshot is we are planning to replace it in the vaguely near > future once we decide what groupware package to put in it?s place. > > > > I?ll list out the software versions below and I need a bit of > assistance making them work for now. I know all I need to do is > upgrade the kernel to 2.6 and it all works, but I?d like to get them > functioning ?As-Is? and then do the upgrade so I have something > working to fall back on. Clam AV is currently shut off since clamd as > a service was so slow. > > > > Kernel 2.4.18-bf2.4 > > Mailscanner 3.27.1-1 > > Clam AV 0.90.1-3etch3 > > Spam Assassin 2.64-1 > > > > Currently we are inundated with mass spam and I need to get some AV in > place, be it Clam or another GNU/GPL/?free as in beer?-ware. I need a > hand here if anyone wants to chime in. > > > > > > ~={o}=~ > > > > > Culley Morrow > IT Manager > Geneva Woods Pharmacy > > > > > > > > > > > > ______________________________________________________________________ > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From martinh at solidstatelogic.com Tue Aug 21 08:44:18 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Tue Aug 21 08:44:23 2007 Subject: New Clam, Old, Mailscanner, Ancient Kernel In-Reply-To: <001a01c7e387$266c2460$0202fea9@genevawoods.com> Message-ID: <49eff3444c609b4383b4c36b540e567b@solidstatelogic.com> Culley Mailscanner v3 had NOT been supported for many years.... I'd start with installing mailscanner v4.latest as fresh install and go from there.. You don't mention how much email (number of and volume), but 1GB per CPU core is recommended due to SA being a real memory hog! Clamd works nice for many people and is supported in the latest MS version. As for spam - more than likely SA 3.2.3 WITH the SARE rules etc will really make a difference.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Culley Morrow > Sent: 21 August 2007 01:07 > To: mailscanner@lists.mailscanner.info > Subject: New Clam, Old, Mailscanner, Ancient Kernel > > Howdy folks, I've got a bit of a dilemma here. I've taken over admin for > an aging Debian 3.0 server partly morphed to 4.0. By partly I mean it is > still using the default 2.4.18-bf2.4 kernel. Way, way, out of date. The > upshot is we are planning to replace it in the vaguely near future once we > decide what groupware package to put in it's place. > > > > I'll list out the software versions below and I need a bit of assistance > making them work for now. I know all I need to do is upgrade the kernel to > 2.6 and it all works, but I'd like to get them functioning "As-Is" and > then do the upgrade so I have something working to fall back on. Clam AV > is currently shut off since clamd as a service was so slow. > > > > Kernel 2.4.18-bf2.4 > > Mailscanner 3.27.1-1 > > Clam AV 0.90.1-3etch3 > > Spam Assassin 2.64-1 > > > > Currently we are inundated with mass spam and I need to get some AV in > place, be it Clam or another GNU/GPL/"free as in beer"-ware. I need a hand > here if anyone wants to chime in. > > > > > > ~={o}=~ > > > > Culley Morrow > IT Manager > Geneva Woods Pharmacy > > > > > > > > ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From list-mailscanner at linguaphone.com Tue Aug 21 08:44:37 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue Aug 21 08:44:42 2007 Subject: Heads up for spamhaus.org problems In-Reply-To: <20070821005342.GA5580@rpcs.net> References: <20070819222357.GA27826@rpcs.net> <20070820020201.GA2841@rpcs.net> <46CA08CD.8070400@alexb.ch> <20070821005342.GA5580@rpcs.net> Message-ID: <1187682277.16339.9.camel@gblades-suse.linguaphone-intranet.co.uk> On Tue, 2007-08-21 at 01:53, Richard Potter wrote: > On Mon, Aug 20, 2007 at 11:34:05PM +0200, Alex Broens wrote: > > > On 8/20/2007 11:22 PM, Tim Boyer wrote: > > >On Sun, 19 Aug 2007 22:02:01 -0400, Richard Potter > > >wrote: > > > > > >>On Mon, Aug 20, 2007 at 12:34:23AM +0200, Raymond Dijkxhoorn wrote: > > >> > > >>>>Just doing a routine check here, and I have a few mail servers > > >>>>misbehaving. It > > >>>>*appears* sendmail dnsbl to zen.spamhaus.org is timing out, and causing > > >>>>mail > > >>>>delivery delays, or none at all. > > >>>> > > >>>>I'm going to discontinue spamhaus, and see what happens. > > >>>Buy rsync from them. Most likely you fire a lot of lookups on their > > >>>servers and they started to ban high volume mailservers some time ago. > > >>>We have seen this in a lot of places allready. > > >>> > > >>>May i ask how much mail are you processing daily? > > >>Thanks for the reply Raymond.. I wasn't aware they were doing that. These > > >>are low volume servers, less than 2,000 messages per day. Does that count > > >>as "high volume" to spamhaus? > > >> > > >>Richard > > > > > >"Use of the Spamhaus DNSBLs via DNS queries to our public DNSBL mirrors is > > >free > > >for low-traffic mail servers serving less than 100 users. Use of the > > >Spamhaus > > >DNSBLs by commercial or corporate networks, ISPs and ESPs, requires a > > >subscription to Spamhaus's Data Feed service." > > > > > >I'd be shocked if 2,000 messages per day counts as high volume. That's 20 > > >emails per person per day. > > > > no need to be shocked :-) > > > > Spamhaus can't block your mail server from doing queries - it blocks > > your DNS' access to the root zone - so if you use a DNS which is > > querying Xmillion queries/day and your server is only doing 10000/day > > then the rest of the X/million+your 10000 makes he count which rates a > > block. > > > You are exactly right. I was told that off list. I switched the two > boxes to an alternative DNS server, and spamhaus worked again. > > I'm not sure why I didn't figure that out on my own. I actually > knew/should have known that. It was Sunday, and I might have had a > few beers! :-) > > Richard When I was blocked for 2000 messages/day I was running a caching nameserver on the local box and no queries were forwarded elsewhere. From glenn.steen at gmail.com Tue Aug 21 08:51:22 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue Aug 21 08:51:24 2007 Subject: Invalid Queue Files with Postfix In-Reply-To: <1187618803.13420.54.camel@gblades-suse.linguaphone-intranet.co.uk> References: <46C56930.D87E.0068.3@aafp.org> <46C5B203.5020108@ecs.soton.ac.uk> <46C58CFE.D87E.0068.3@aafp.org> <223f97700708171339h2115ce1fu1af220aa23462924@mail.gmail.com> <46C5CE13.D87E.0068.3@aafp.org> <46C6FDA7.3080605@ecs.soton.ac.uk> <46C957D4.D87E.0068.3@aafp.org> <1187618803.13420.54.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <223f97700708210051r97ec82ao517b2b5181aeefeb@mail.gmail.com> On 20/08/07, Gareth wrote: > On Mon, 2007-08-20 at 14:59, Brad Beckenhauer wrote: > > >>> On 8/18/2007 at 9:09 AM, in message <46C6FDA7.3080605@ecs.soton.ac.uk>, Julian > > Field wrote: > > > -----BEGIN PGP SIGNED MESSAGE----- > > > Hash: SHA1 > > > > > > > > > > > > Brad Beckenhauer wrote: > > >> > > >> That would be a nice feature request for MailScanner, something to > > >> provide consistant volume benchmarks across all supported MailScanner > > >> platforms. > > >> Something like: > > >> MailScanner -stats > > >> or a configuration setting to enable benchmarking with the > > >> understanding that there would be system overhead associated with the > > >> additional process. > > >> > > > What stats would you like it to log that it doesn't already? > > > There's no communication between the child processes once they are > > > started, but I could add a signal trap so that a kill -USR or something > > > would make them dump some figures to some file or other, then restart > > > the batch they were on. They already catch kill -HUP to force them to > > > die. So exactly what do you want to do when it receives a SIGUSR? > > > > Several times on the list I've noticed questions like "What's your volume?". > > Is there already something in MailScanner that can generate an answer to that question? > > > > My first thought would be to have MailScanner calculate the daily volume of total daily messages processed. That way when the "What's your volume" question comes up, there is a standardized way to respond to the question. An hourly histogram would be an interesting stat. > > > > Date > > TIME Msgs processed > > 00:00-01:00 xxxx > > 01:00-02:00 xxxx > > 02:00-03:00 xxxx > > ?---------------------- > > Mail Volume xxxxx > > Hourly Avg: xx% > > > > Anyway... That was the thought..... Feel free to toss the idea to the bit bucket. I'm not going to be arguing the idea. > > > > Thanks for listening. > > Brad > > I just use standard logwatch as it gives a good daily summary. > pflogsumm and MailWatch do the trick for me:-). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From gmatt at nerc.ac.uk Tue Aug 21 09:55:06 2007 From: gmatt at nerc.ac.uk (Greg Matthews) Date: Tue Aug 21 09:55:24 2007 Subject: New Clam, Old, Mailscanner, Ancient Kernel In-Reply-To: <001a01c7e387$266c2460$0202fea9@genevawoods.com> References: <001a01c7e387$266c2460$0202fea9@genevawoods.com> Message-ID: <46CAA86A.4060206@nerc.ac.uk> Culley Morrow wrote: > I?ll list out the software versions below and I need a bit of assistance > making them work for now. I know all I need to do is upgrade the kernel > to 2.6 and it all works, but I?d like to get them functioning ?As-Is? > and then do the upgrade so I have something working to fall back on. > Clam AV is currently shut off since clamd as a service was so slow. kernel upgrade probably not very important. As others have pointed out, there is little reason not to upgrade MS and SA. Stick as much memory in the box as it can handle. > Kernel 2.4.18-bf2.4 > > Mailscanner 3.27.1-1 > > Clam AV 0.90.1-3etch3 > > Spam Assassin 2.64-1 > > > > Currently we are inundated with mass spam and I need to get some AV in > place, be it Clam or another GNU/GPL/?free as in beer?-ware. I need a > hand here if anyone wants to chime in. if you are "inundated" then the best start you can make is to reject as much as possible at the MTA. As this is Debian, your MTA is probably (but not necessarily) exim. Look at putting in a single well regarded block list at the MTA, something like zen.spamhaus.org but do your research and find one that /you/ like the look of (block list preferences can start flame wars!). Make sure you are rejecting mail at the MTA for all unknown recipients and not accepting then bouncing. Set up your MTA to throttle incoming mail so it doesnt get overwhelmed or let your incoming queue build up uncontrollably. Visit the MS wiki for tips on how to do this - dig deep, it can be a bit tricky to find what you are looking for. Search the archives for good links into the wiki. GREG -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford -- This message (and any attachments) is for the recipient only. NERC is subject to the Freedom of Information Act 2000 and the contents of this email and any reply you make may be disclosed by NERC unless it is exempt from release under the Act. Any material supplied to NERC may be stored in an electronic records management system. From ajcartmell at fonant.com Tue Aug 21 10:23:13 2007 From: ajcartmell at fonant.com (Anthony Cartmell) Date: Tue Aug 21 10:23:09 2007 Subject: antispam server setup website - comments welcome In-Reply-To: <7596c7e1d87a2241863c8959a0954aac@solidstatelogic.com> References: <7596c7e1d87a2241863c8959a0954aac@solidstatelogic.com> Message-ID: > Pyzor is fine, but you have to run a different server other than the > broken one 'pyzor update' gives gives you... > > 82.94.255.100:24441 > > Is the functioning one. With the one from "pyzor discover": [root@clive ~]# pyzor ping 66.250.40.33:24441 (200, 'OK') With the above: [root@clive ~]# pyzor ping 82.94.255.100:24441 (200, 'OK') Or does the ping not indicate the full server status? Anthony -- www.fonant.com - Quality web sites From maillists at conactive.com Tue Aug 21 10:31:22 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Tue Aug 21 10:31:25 2007 Subject: MailScanner mailing list ended up on a black list. In-Reply-To: <46CA7C53.5050000@sweet-haven.com> References: <46CA323E.9020403@ddihealth.com> <46CA7C53.5050000@sweet-haven.com> Message-ID: Lew Wolfgang wrote on Mon, 20 Aug 2007 22:46:59 -0700: > SPF overrides a hit from > a DNSBL in Microsoft's world, I guess. I doubt they use apews. Like spews was it is not suitable for any business. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From martinh at solidstatelogic.com Tue Aug 21 11:10:42 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Tue Aug 21 11:10:56 2007 Subject: antispam server setup website - comments welcome In-Reply-To: Message-ID: <8cb6665400aab84eb7a40767be8a6be7@solidstatelogic.com> No it doesn't, the 'discover' one is not being updated and seems broken. The other 82.250.255.100 actually works.... People have made many attempts to contact the pyzor "maintainer" on this to offer servers/bandwidth but he seems to ignore all offers... -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Anthony Cartmell > Sent: 21 August 2007 10:23 > To: MailScanner discussion > Subject: Re: antispam server setup website - comments welcome > > > Pyzor is fine, but you have to run a different server other than the > > broken one 'pyzor update' gives gives you... > > > > 82.94.255.100:24441 > > > > Is the functioning one. > > With the one from "pyzor discover": > > [root@clive ~]# pyzor ping > 66.250.40.33:24441 (200, 'OK') > > With the above: > > [root@clive ~]# pyzor ping > 82.94.255.100:24441 (200, 'OK') > > Or does the ping not indicate the full server status? > > Anthony > -- > www.fonant.com - Quality web sites > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From alvaro at hostalia.com Tue Aug 21 11:10:56 2007 From: alvaro at hostalia.com (=?ISO-8859-1?Q?Alvaro_Mar=EDn?=) Date: Tue Aug 21 11:10:59 2007 Subject: [Fwd: [Clamav-announce] announcing ClamAV 0.91.2] Message-ID: <46CABA30.9060109@hostalia.com> -------- Original Message -------- Date: Tue, 21 Aug 2007 11:38:52 +0200 From: Luca Gibelli To: ClamAV Announce Subject: [Clamav-announce] announcing ClamAV 0.91.2 Dear ClamAV users, This release fixes various bugs in libclamav, freshclam and clamav-milter, and adds support for PUA (Potentially Unwanted Application) signatures (clamscan: --detect-pua, clamd: DetectPUA). -- The ClamAV team (http://www.clamav.net/team) -- Luca Gibelli (luca _at_ clamav.net) - ClamAV, a GPL anti-virus toolkit [Tel] +1 706 7054022 [Fax] +1 706 5345792 [IM] nervous/jabber.linux.it PGP key id 5EFC5582 @ key server || http://www.clamav.net/gpg/luca.gpg _______________________________________________ http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-announce Regards, -- Alvaro Mar?n Illera Hostalia Internet www.hostalia.com From ajcartmell at fonant.com Tue Aug 21 11:34:58 2007 From: ajcartmell at fonant.com (Anthony Cartmell) Date: Tue Aug 21 11:34:50 2007 Subject: antispam server setup website - comments welcome In-Reply-To: <8cb6665400aab84eb7a40767be8a6be7@solidstatelogic.com> References: <8cb6665400aab84eb7a40767be8a6be7@solidstatelogic.com> Message-ID: > No it doesn't, the 'discover' one is not being updated and seems broken. > > The other 82.250.255.100 actually works.... Ah, OK, I'll stick with that one then. Thanks for the info! > People have made many attempts to contact the pyzor "maintainer" on this > to offer servers/bandwidth but he seems to ignore all offers... It's sad when good software goes un-maintained. Anthony -- www.fonant.com - Quality web sites From MailScanner at ecs.soton.ac.uk Tue Aug 21 12:13:37 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 21 12:13:56 2007 Subject: [Fwd: [Clamav-announce] announcing ClamAV 0.91.2] In-Reply-To: <46CABA30.9060109@hostalia.com> References: <46CABA30.9060109@hostalia.com> Message-ID: <46CAC8E1.8040908@ecs.soton.ac.uk> I have just updated my ClamAV+SpamAssassin package. Alvaro Mar?n wrote: > > > -------- Original Message -------- > Date: Tue, 21 Aug 2007 11:38:52 +0200 > From: Luca Gibelli > To: ClamAV Announce > Subject: [Clamav-announce] announcing ClamAV 0.91.2 > > > Dear ClamAV users, > > This release fixes various bugs in libclamav, freshclam and > clamav-milter, > and adds support for PUA (Potentially Unwanted Application) signatures > (clamscan: --detect-pua, clamd: DetectPUA). > > -- > The ClamAV team (http://www.clamav.net/team) > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From list-mailscanner at linguaphone.com Tue Aug 21 12:47:00 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue Aug 21 12:47:12 2007 Subject: DCC installation Message-ID: <1187696820.16338.16.camel@gblades-suse.linguaphone-intranet.co.uk> Just had a go at installing DCC. Installed the software, checked the DCC perl module was installed, enabled DCC and then restarted mailscanner. I read that the defaults that dcc installs are fine if you want to connect anonymously so in theory it should work. However I have not seen any matches so I think something might be wrong. This is the debug output :- #spamassassin -D -t a #cat a | grep dcc [9628] dbg: dcc: network tests on, registering DCC [9628] dbg: config: fixed relative path: /var/lib/spamassassin/3.002003/updates_spamassassin_org/25_dcc.cf [9628] dbg: config: using "/var/lib/spamassassin/3.002003/updates_spamassassin_org/25_dcc.cf" for included file [9628] dbg: config: read file /var/lib/spamassassin/3.002003/updates_spamassassin_org/25_dcc.cf [9628] dbg: dcc: dccifd is not available: no r/w dccifd socket found [9628] dbg: util: executable for dccproc was found at /usr/local/bin/dccproc [9628] dbg: dcc: dccproc is available: /usr/local/bin/dccproc [9628] dbg: dcc: opening pipe: /usr/local/bin/dccproc -H -x 0 -a 203.25.170.31 < /tmp/.spamassassin9628DjN0rLtmp [9628] dbg: dcc: killed stale helper [9642] [9628] dbg: dcc: [9642] terminated: exit=0xf100 [9628] dbg: dcc: check timed out after 8 seconds X-DCC-CTc-dcc2-Metrics: gecko.npgx.com.au 1031; Body=0 Fuz1=0 Fuz2=0 fMHId05XuL20k3PgNVdccAIexF9wrelX4WoQqkZVRwRKBxIuxyjID3j+fcRaSyFJGGEod8EFk2xW From shuttlebox at gmail.com Tue Aug 21 13:02:08 2007 From: shuttlebox at gmail.com (shuttlebox) Date: Tue Aug 21 13:02:15 2007 Subject: DCC installation In-Reply-To: <1187696820.16338.16.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1187696820.16338.16.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <625385e30708210502o659b48abqabdb7a997bc65dba@mail.gmail.com> On 8/21/07, Gareth wrote: > Just had a go at installing DCC. Installed the software, checked the DCC > perl module was installed, enabled DCC and then restarted mailscanner. > > I read that the defaults that dcc installs are fine if you want to > connect anonymously so in theory it should work. However I have not seen > any matches so I think something might be wrong. Have you opened 6277/udp in your firewall? -- /peter From glenn.steen at gmail.com Tue Aug 21 13:10:09 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue Aug 21 13:10:14 2007 Subject: temp files not being processed - score=0 (UNCLASSIFIED) In-Reply-To: <88991ECEE371C644986F0C8837C207B701CC314C@ARLABML01.DS.ARL.ARMY.MIL> References: <88991ECEE371C644986F0C8837C207B701CC314C@ARLABML01.DS.ARL.ARMY.MIL> Message-ID: <223f97700708210510v7699d8a4p64607cbf7a15f9cb@mail.gmail.com> On 20/08/07, Kash, Howard (Civ, ARL/CISD) wrote: > Classification: UNCLASSIFIED > Caveats: NONE > > > I've had the "(not cached, score=0, required 5, autolearn=)" problem > several times myself. Typically restarting MailScanner fixed the > problem. Last time it happened, simply restarting didn't help so I > tried removing SpamAssassin.cache.db and the problem stopped. Can't say > for sure removing the cache was the fix, but worth a try. > > BTW, is there something similar to db_verify that can be run on the > SpamAssassin cache to check for consistency? > > > Howard > Not really, at least not that I know of... You could always use analyse_SpamAssassin_cache to verify that the user you run MailScanner as can read through it all... -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From R.Sterenborg at netsourcing.nl Tue Aug 21 13:18:16 2007 From: R.Sterenborg at netsourcing.nl (Rob Sterenborg) Date: Tue Aug 21 13:20:10 2007 Subject: FW: [Clamav-users] clamav 0.91.2 is out. Don't use it. Message-ID: <74ACEB3E6A055643A89B8CEC74C7BF2488E134@WISENT.dcyb.net> clamav-users-bounces@lists.clamav.net wrote: > It has a dangerous (lack of) value for CL_SCAN_STDOPT. You're better > off not upgrading until they fix it. > > (filed as bug 631, but it's nothing new: CL_SCAN_STDOPT still doesn't > include CL_SCAN_PHISHING_DOMAINLIST; that omission can cause crashing > and hanging on certain platforms ... the clamav team already > knows about > this problem, and they even enable that option as a default > in clamscan, > just not in the CL_SCAN_STDOPT defined value ... my > suggestion is to not > upgrade until they release a version that fixes this problem) I saw this on the ClamAV list... Grts, Rob From list-mailscanner at linguaphone.com Tue Aug 21 13:40:33 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue Aug 21 13:40:47 2007 Subject: DCC installation In-Reply-To: <625385e30708210502o659b48abqabdb7a997bc65dba@mail.gmail.com> References: <1187696820.16338.16.camel@gblades-suse.linguaphone-intranet.co.uk> <625385e30708210502o659b48abqabdb7a997bc65dba@mail.gmail.com> Message-ID: <1187700033.16339.18.camel@gblades-suse.linguaphone-intranet.co.uk> On Tue, 2007-08-21 at 13:02, shuttlebox wrote: > On 8/21/07, Gareth wrote: > > Just had a go at installing DCC. Installed the software, checked the DCC > > perl module was installed, enabled DCC and then restarted mailscanner. > > > > I read that the defaults that dcc installs are fine if you want to > > connect anonymously so in theory it should work. However I have not seen > > any matches so I think something might be wrong. > > Have you opened 6277/udp in your firewall? Thanks that was it. Everything outbould was permitted but I forgot iptables does not track udp connections. From root at doctor.nl2k.ab.ca Tue Aug 21 15:09:20 2007 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Tue Aug 21 15:11:40 2007 Subject: [luca@clamav.net: [Clamav-announce] announcing ClamAV 0.91.2] Message-ID: <20070821140919.GC6031@doctor.nl2k.ab.ca> Jules and compnay new clamav. Do we have a PUA feture? ----- Forwarded message from Luca Gibelli ----- X-NetKnow-InComing-4.63.2-1-MailScanner-Watermark: 1188121228.68939@z5JrHnKnd5Rlt7or3YFJfA Return-Path: clamav-announce-bounces@lists.clamav.net Received: from tad.clamav.net by doctor.nl2k.ab.ca (8.14.1/8.14.1) with ESMTP id l7L9eDnW003340 for ; Tue, 21 Aug 2007 03:40:27 -0600 (MDT) X-Spam-Filter: check_local@doctor.nl2k.ab.ca by digitalanswers.org X-Virus-Scanned: Debian amavisd-new at tad.clamav.net Received: from tad.clamav.net ([127.0.0.1]) by localhost (tad.clamav.net [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9J+N17Ig9Lm5; Tue, 21 Aug 2007 11:39:57 +0200 (CEST) Received: from tad.clamav.net (localhost.localdomain [127.0.0.1]) by tad.clamav.net (Postfix) with ESMTP id A250A16C050; Tue, 21 Aug 2007 11:39:57 +0200 (CEST) X-Original-To: clamav-announce@tad.clamav.net Delivered-To: clamav-announce@tad.clamav.net X-Virus-Scanned: Debian amavisd-new at tad.clamav.net Received: from tad.clamav.net ([127.0.0.1]) by localhost (tad.clamav.net [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UWwO2le5ZcsN for ; Tue, 21 Aug 2007 11:38:53 +0200 (CEST) Received: from mosquito.nervous.bbs (localhost.localdomain [127.0.0.1]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by tad.clamav.net (Postfix) with ESMTP id A8CF116C050 for ; Tue, 21 Aug 2007 11:38:53 +0200 (CEST) Received: from nervous by mosquito.nervous.bbs with local (Exim 4.63) (envelope-from ) id 1INQCK-0001v9-Jz for clamav-announce@lists.clamav.net; Tue, 21 Aug 2007 11:38:53 +0200 Date: Tue, 21 Aug 2007 11:38:52 +0200 From: Luca Gibelli To: ClamAV Announce Message-ID: <20070821093852.GA7272@adsl.nervous.it> MIME-Version: 1.0 Content-Disposition: inline User-Agent: Mutt/1.5.13 (2006-08-11) X-Mailman-Approved-At: Tue, 21 Aug 2007 11:39:56 +0200 Subject: [Clamav-announce] announcing ClamAV 0.91.2 X-BeenThere: clamav-announce@lists.clamav.net X-Mailman-Version: 2.1.9 Precedence: list Reply-To: noreply@clamav.net List-Id: ClamAV events are announced here List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: clamav-announce-bounces@lists.clamav.net Errors-To: clamav-announce-bounces@lists.clamav.net X-NetKnow-InComing-4.63.2-1-MailScanner-Information: Please contact the ISP for more information X-NetKnow-InComing-4.63.2-1-MailScanner: Found to be clean X-NetKnow-InComing-4.63.2-1-MailScanner-From: clamav-announce-bounces@lists.clamav.net X-Spam-Status: No Dear ClamAV users, This release fixes various bugs in libclamav, freshclam and clamav-milter, and adds support for PUA (Potentially Unwanted Application) signatures (clamscan: --detect-pua, clamd: DetectPUA). -- The ClamAV team (http://www.clamav.net/team) -- Luca Gibelli (luca _at_ clamav.net) - ClamAV, a GPL anti-virus toolkit [Tel] +1 706 7054022 [Fax] +1 706 5345792 [IM] nervous/jabber.linux.it PGP key id 5EFC5582 @ key server || http://www.clamav.net/gpg/luca.gpg _______________________________________________ http://lists.clamav.net/cgi-bin/mailman/listinfo/clamav-announce -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. ----- End forwarded message ----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From rcooper at dwford.com Tue Aug 21 16:23:03 2007 From: rcooper at dwford.com (Rick Cooper) Date: Tue Aug 21 16:23:08 2007 Subject: [luca@clamav.net: [Clamav-announce] announcing ClamAV 0.91.2] In-Reply-To: <20070821140919.GC6031@doctor.nl2k.ab.ca> References: <20070821140919.GC6031@doctor.nl2k.ab.ca> Message-ID: <014901c7e407$2b420740$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On > Behalf Of Dave Shariff Yadallee - System Administrator > a.k.a. The Root of theProblem > Sent: Tuesday, August 21, 2007 10:09 AM > To: mailscanner@lists.mailscanner.info > Subject: [luca@clamav.net: [Clamav-announce] announcing > ClamAV 0.91.2] > > Jules and compnay new clamav. Do we have a PUA feture? > [...] I believe that Mail::ClamAV will have to be updated to include the export CL_DB_PUA and then MailScanner will have to have a new option to tell Sub ClamAVModule if it should use CL_DB_PUA (since I doubt everyone will use it), and of course sub ClamAVModule will have to be updated to include the new flag. If you are using clamd then just enable PUA in the clamd.conf. Personally I have no idea what it does and haven't been able to find any information on it so I plan to ask on the clam list later. Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From root at doctor.nl2k.ab.ca Tue Aug 21 16:36:06 2007 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Tue Aug 21 16:36:39 2007 Subject: [luca@clamav.net: [Clamav-announce] announcing ClamAV 0.91.2] In-Reply-To: <014901c7e407$2b420740$0301a8c0@SAHOMELT> References: <20070821140919.GC6031@doctor.nl2k.ab.ca> <014901c7e407$2b420740$0301a8c0@SAHOMELT> Message-ID: <20070821153605.GB10626@doctor.nl2k.ab.ca> On Tue, Aug 21, 2007 at 11:23:03AM -0400, Rick Cooper wrote: > > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On > > Behalf Of Dave Shariff Yadallee - System Administrator > > a.k.a. The Root of theProblem > > Sent: Tuesday, August 21, 2007 10:09 AM > > To: mailscanner@lists.mailscanner.info > > Subject: [luca@clamav.net: [Clamav-announce] announcing > > ClamAV 0.91.2] > > > > Jules and compnay new clamav. Do we have a PUA feture? > > > [...] > > I believe that Mail::ClamAV will have to be updated to include the export > CL_DB_PUA and then MailScanner will have to have a new option to tell Sub > ClamAVModule if it should use CL_DB_PUA (since I doubt everyone will use > it), and of course sub ClamAVModule will have to be updated to include the > new flag. > > If you are using clamd then just enable PUA in the clamd.conf. Personally I > have no idea what it does and haven't been able to find any information on > it so I plan to ask on the clam list later. > > Rick > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > >From http://download.zicos.com/news.php/n/2647024/Clam-AntiVirus-0.91.2-Default-branch adds support for PUA (Potentially Unwanted Application) signatures (clamscan: --detect-pua, clamd: DetectPUA) And from: http://www.sophos.com/pressoffice/news/articles/2001/11/va_glossary.html#pua Potentially unwanted application (PUA) Description: PUA is a term used to describe an application that is not inherently malicious, but is generally considered unsuitable for the majority of business networks. Potentially unwanted applications include adware, dialers, remote administration tools and hacking tools. Hence you may be correct about definitions. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ssilva at sgvwater.com Tue Aug 21 16:49:01 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue Aug 21 16:49:13 2007 Subject: MailScanner mailing list ended up on a black list. In-Reply-To: <46CA323E.9020403@ddihealth.com> References: <46CA323E.9020403@ddihealth.com> Message-ID: Jim Barber spake the following on 8/20/2007 5:30 PM: > Hi all. > > Last night I noticed that most (all?) of my incoming posts from this > list were tagged as spam (despite having really low scores). > I found the cause was due to an RBL server that I use having listed one > of the email servers this list comes from. > > The MailScanner server that is getting black listed is: 83.98.192.7 > which reverse resolves to safir.blacknight.ie > The RBL server that I am using is blackholes.five-ten-sg.com > This one I've added myself, but I am reluctant to remove it since so far > over the months it has served me well. > > If you go to http://www.five-ten-sg.com/blackhole.php and enter > 83.98.192.7 into the form it comes back with the following: > > ------------------------------------------------------------ > IP address 83.98.192.7 is listed here as 83.98.192.165 misc. > > Although there may be other reasons, most of the listings in this > category are due to > (1. systems apparently sending bulk mail from ip addresses with bogus or > missing reverse dns, or with no web server, or with boilerplate web > content, or > 2. a suspected multistage relay output, or > 3. machines probably running MS SMTPSVC with an open guest account, or > 4. running some open proxy), or it is in the same /24 subnet containing > multiple machines with that property. > ------------------------------------------------------------ > > The 'misc' (127.0.0.9) return code is defined by the site as: > > ------------------------------------------------------------ > misc - Miscellaneous includes (but is NOT limited to) the following groups. > Note that this does NOT include misc.spam which is listed under spam above. > 1) /24 blocks of addresses containing systems that are apparently > sending bulk email (in volumes apparently comparable with the volume > from AOL, Earthlink, Google), with any of the following attributes: > missing or bogus reverse dns, reverse dns names in domains with no web > server, or domains with boilerplate web content. > 2) Systems that are strongly suspected of being multistage open relays > (where I have not been able to identify the input stage) or open proxies. > 3) Any system that delivers spam here, that appears to be running MS > SMTPSVC, and that appears to have relayed the message from China, Korea, > Brazil, or any known open proxy. > These are generally systems that have enabled the guest account, and > spammers are using them as open relays, even though they do require SMTP > AUTH. > Enabling the guest account allows anyone to relay thru them. > ------------------------------------------------------------ > > Is this the correct place to report it to? > It's sort of ironic having an anti-spam list ending up marked as spam. > Oh well. > > Regards, > blackholes.five-ten-sg.com is too aggressive a list for me. One spammer can kill an entire subnet on that list. If you check those spammers on other lists, they are usually there also. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From mailadmin at baladia.gov.kw Tue Aug 21 16:56:58 2007 From: mailadmin at baladia.gov.kw (mailadmin@baladia.gov.kw) Date: Tue Aug 21 16:59:10 2007 Subject: mailscanner lint errors Message-ID: <3384.62.150.152.226.1187711818.squirrel@webmail.baladia.gov.kw> Dear ALL, i am using the latest mailscanner + the jules SA+AV script and have installed as per the docs and when i run the MailScanner --lint it shows me ------------------------------------------------- Version number in MailScanner.conf (4.62.9) is correct. ERROR: The "envelope_sender_header" in your spam.assassin.prefs.conf ERROR: is not correct, it should match X-Baladia-MailScanner-MailScanner-From Checking for SpamAssassin errors (if you use it)... SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp SpamAssassin reported no errors. MailScanner.conf says "Virus Scanners = clamav" Found these virus scanners installed: clamav =========================================================================== Ignore errors about failing to find EOCD signature format error: can't find EOCD signature at /usr/sbin/MailScanner line 451 =========================================================================== Virus Scanner test reports: ClamAV said "eicar.com contains Eicar-Test-Signature" If any of your virus scanners (clamav) are not listed there, you should check that they are installed correctly and that MailScanner is finding them correctly via its virus.scanners.conf. --------------------------------------------------------------------------- r the above errors serious .. how cd i fix it 2) right now i have clamav-0.91.1-1.el5.rf and the latest stable version is 0.91.2 .. how cd i install this since earlier i installed it via Jules script apprecite and thnks regards simon -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From naolson at gmail.com Tue Aug 21 17:17:52 2007 From: naolson at gmail.com (Nathan Olson) Date: Tue Aug 21 17:17:55 2007 Subject: antispam server setup website - comments welcome In-Reply-To: References: <8cb6665400aab84eb7a40767be8a6be7@solidstatelogic.com> Message-ID: <8f54b4330708210917g6117645ay39450f381b2f4832@mail.gmail.com> We've had no problems with Razor. Nate From culleym at genevawoods.com Tue Aug 21 17:36:49 2007 From: culleym at genevawoods.com (Culley Morrow) Date: Tue Aug 21 17:37:04 2007 Subject: MailScanner Digest, Vol 20, Issue 49 In-Reply-To: <200708211100.l7LB09OJ008413@safir.blacknight.ie> References: <200708211100.l7LB09OJ008413@safir.blacknight.ie> Message-ID: <002b01c7e411$7989cf00$d10da8c0@genevawoods.com> Thanks for the replies. This server is quite meager with 256mb RAM and a 30gb hard drive, all running on a 4 year old Dell desktop. Meager is putting it mildly. I've got to make it work while it's in place, a massive replacement is in the works though. Clamscan was what I was meaning actually. I remember reading a while back in the archives that it was a major stumbling point with new versions on older systems. After an update it was running OK, but slowly getting further and further behind in the mail delivery. Anyway, I'll start digging through the wiki for better rules and see what I can start filtering out. ~={o}=~ Culley Morrow IT Manager Geneva Woods Pharmacy -----Original Message----- Message: 11 Date: Tue, 21 Aug 2007 09:55:06 +0100 From: Greg Matthews Subject: Re: New Clam, Old, Mailscanner, Ancient Kernel To: MailScanner discussion Message-ID: <46CAA86A.4060206@nerc.ac.uk> Content-Type: text/plain; charset=windows-1252; format=flowed Culley Morrow wrote: > Ill list out the software versions below and I need a bit of assistance > making them work for now. I know all I need to do is upgrade the kernel > to 2.6 and it all works, but Id like to get them functioning As-Is > and then do the upgrade so I have something working to fall back on. > Clam AV is currently shut off since clamd as a service was so slow. kernel upgrade probably not very important. As others have pointed out, there is little reason not to upgrade MS and SA. Stick as much memory in the box as it can handle. > Kernel 2.4.18-bf2.4 > > Mailscanner 3.27.1-1 > > Clam AV 0.90.1-3etch3 > > Spam Assassin 2.64-1 > > > > Currently we are inundated with mass spam and I need to get some AV in > place, be it Clam or another GNU/GPL/free as in beer-ware. I need a > hand here if anyone wants to chime in. if you are "inundated" then the best start you can make is to reject as much as possible at the MTA. As this is Debian, your MTA is probably (but not necessarily) exim. Look at putting in a single well regarded block list at the MTA, something like zen.spamhaus.org but do your research and find one that /you/ like the look of (block list preferences can start flame wars!). Make sure you are rejecting mail at the MTA for all unknown recipients and not accepting then bouncing. Set up your MTA to throttle incoming mail so it doesnt get overwhelmed or let your incoming queue build up uncontrollably. Visit the MS wiki for tips on how to do this - dig deep, it can be a bit tricky to find what you are looking for. Search the archives for good links into the wiki. GREG -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford From ssilva at sgvwater.com Tue Aug 21 17:49:56 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue Aug 21 17:50:18 2007 Subject: mailscanner lint errors In-Reply-To: <3384.62.150.152.226.1187711818.squirrel@webmail.baladia.gov.kw> References: <3384.62.150.152.226.1187711818.squirrel@webmail.baladia.gov.kw> Message-ID: mailadmin@baladia.gov.kw spake the following on 8/21/2007 8:56 AM: > Dear ALL, > > i am using the latest mailscanner + the jules SA+AV script and have > installed as per the docs and when i run the MailScanner --lint it shows > me > > ------------------------------------------------- > > Version number in MailScanner.conf (4.62.9) is correct. > > ERROR: The "envelope_sender_header" in your spam.assassin.prefs.conf > ERROR: is not correct, it should match X-Baladia-MailScanner-MailScanner-From Edit the spam.assassin.prefs.conf so it matches the above line which it gets from your mailscanner.conf file. > > > Checking for SpamAssassin errors (if you use it)... > SpamAssassin temp dir = /var/spool/MailScanner/incoming/SpamAssassin-Temp > SpamAssassin reported no errors. > MailScanner.conf says "Virus Scanners = clamav" > Found these virus scanners installed: clamav > =========================================================================== > Ignore errors about failing to find EOCD signature > format error: can't find EOCD signature > at /usr/sbin/MailScanner line 451 Like it says you can ignore this error. > =========================================================================== > Virus Scanner test reports: > ClamAV said "eicar.com contains Eicar-Test-Signature" > > If any of your virus scanners (clamav) > are not listed there, you should check that they are installed correctly > and that MailScanner is finding them correctly via its virus.scanners.conf. > > --------------------------------------------------------------------------- > r the above errors serious .. how cd i fix it > > > 2) right now i have clamav-0.91.1-1.el5.rf and the latest stable version > is 0.91.2 .. Since your clamav is an rpm from rpmforge, you didn't install it from Julian's script. > > how cd i install this since earlier i installed it via Jules script There are conflicting views on installing the newest clamav. Seems to be a bug in it. Watch the list for more details. > > > apprecite and thnks > > > regards > > simon > > -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From list-mailscanner at linguaphone.com Tue Aug 21 18:07:51 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue Aug 21 18:07:54 2007 Subject: MailScanner Digest, Vol 20, Issue 49 In-Reply-To: <002b01c7e411$7989cf00$d10da8c0@genevawoods.com> Message-ID: well clamscan is much slower than either the clamavmodule or clamd versions so changing to one of those should help speed it up considerably. Also you are running 0.90 version of clamav which has a bug causing it to take much longer to load its signatures which makes the clamscan method even slower again. Upgrading clamav and switching to clamavmodule will probably double your scanning speed easily. > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Culley > Morrow > Sent: 21 August 2007 17:37 > To: mailscanner@lists.mailscanner.info > Subject: RE: MailScanner Digest, Vol 20, Issue 49 > > > Thanks for the replies. This server is quite meager with 256mb RAM and a > 30gb hard drive, all running on a 4 year old Dell desktop. Meager > is putting > it mildly. I've got to make it work while it's in place, a massive > replacement is in the works though. > > Clamscan was what I was meaning actually. I remember reading a > while back in > the archives that it was a major stumbling point with new > versions on older > systems. After an update it was running OK, but slowly getting further and > further behind in the mail delivery. > > Anyway, I'll start digging through the wiki for better rules and > see what I > can start filtering out. > > ~={o}=~ > > Culley Morrow > IT Manager > Geneva Woods Pharmacy > > > -----Original Message----- > Message: 11 > Date: Tue, 21 Aug 2007 09:55:06 +0100 > From: Greg Matthews > Subject: Re: New Clam, Old, Mailscanner, Ancient Kernel > To: MailScanner discussion > Message-ID: <46CAA86A.4060206@nerc.ac.uk> > Content-Type: text/plain; charset=windows-1252; format=flowed > > Culley Morrow wrote: > > Ill list out the software versions below and I need a bit of > assistance > > making them work for now. I know all I need to do is upgrade the kernel > > to 2.6 and it all works, but Id like to get them functioning As-Is > > and then do the upgrade so I have something working to fall back on. > > Clam AV is currently shut off since clamd as a service was so slow. > > kernel upgrade probably not very important. As others have pointed out, > there is little reason not to upgrade MS and SA. Stick as much memory in > the box as it can handle. > > > Kernel 2.4.18-bf2.4 > > > > Mailscanner 3.27.1-1 > > > > Clam AV 0.90.1-3etch3 > > > > Spam Assassin 2.64-1 > > > > > > > > Currently we are inundated with mass spam and I need to get some AV in > > place, be it Clam or another GNU/GPL/free as in beer-ware. I need a > > hand here if anyone wants to chime in. > > if you are "inundated" then the best start you can make is to reject as > much as possible at the MTA. As this is Debian, your MTA is probably > (but not necessarily) exim. Look at putting in a single well regarded > block list at the MTA, something like zen.spamhaus.org but do your > research and find one that /you/ like the look of (block list > preferences can start flame wars!). Make sure you are rejecting mail at > the MTA for all unknown recipients and not accepting then bouncing. Set > up your MTA to throttle incoming mail so it doesnt get overwhelmed or > let your incoming queue build up uncontrollably. > > Visit the MS wiki for tips on how to do this - dig deep, it can be a bit > tricky to find what you are looking for. Search the archives for good > links into the wiki. > > GREG > -- > Greg Matthews 01491 692445 > Head of UNIX/Linux, iTSS Wallingford > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > From sandrews at andrewscompanies.com Tue Aug 21 18:14:48 2007 From: sandrews at andrewscompanies.com (Steven Andrews) Date: Tue Aug 21 18:14:54 2007 Subject: CRM114 Problem In-Reply-To: <50678FBB708A9B4FB6B536F6F657883D028E9528@exch-gman.ad.goodmanmfg.com> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info> <50678FBB708A9B4FB6B536F6F657883D028E9528@exch-gman.ad.goodmanmfg.com> Message-ID: <1964AAFBC212F742958F9275BF63DBB05B3D63@winchester.andrewscompanies.com> Got the updated files from mschuette.name according to the wiki and it is incremented for your changes; unfortunately, it didn't fix for me. Should I be using a different version than the 20073001 rpm? -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Horton, Robert Sent: Tuesday, August 21, 2007 2:14 AM To: MailScanner discussion Subject: RE: CRM114 Problem Are you still having problems with the score at -0.00? I finally installed this evening and had the same problem. I think there is a bug in the crm114.pm (Version: 0.6.4), but what perplexes me is why some people claim its working...the lines I changed should affect everyone. Maybe this code was changed recently. I changed the following 2 lines in the sub call_crm dbg("crm114: opening pipe: $crm114_command < $tmpf"); $pid = Mail::SpamAssassin::Util::helper_app_pipe_open( *CRM_OUT, $tmpf, 1, $crm114_command); to dbg("crm114: opening pipe: $crm114_cmdline < $tmpf"); $pid = Mail::SpamAssassin::Util::helper_app_pipe_open( *CRM_OUT, $tmpf, 1, $crm114_cmdline); Within minutes crm114 started learning emails and no longer had the -0.00 score. You only get this score when you have an empty spam.css and nonspam.css and it doesn't know what to do with the email yet. Hope this helps, Robert Horton -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Mike Kercher Sent: Friday, August 10, 2007 11:13 AM To: MailScanner discussion Subject: CRM114 Problem I added CRM114 to a server last week per the docs in the wiki (and like I've done on several other servers), but the score is always -0.00 [root@mail crm114]# cssutil -b -r spam.css Sparse spectra file spam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 15495 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 [root@mail crm114]# cssutil -b -r nonspam.css Sparse spectra file nonspam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 15495 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 The Features learned hasn't changed in many days. Permissions look good, .crm's are +x Any suggestions where to look? Mike -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! CONFIDENTIALITY NOTE: The information contained in this transmission is privileged and confidential information intended only for the use of the individual or entity named above. If the reader of this message is not the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this transmission in error, do not read it. Please immediately reply to the sender that you have received this communication in error and then delete it. Thank you. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From mailadmin at baladia.gov.kw Tue Aug 21 19:18:18 2007 From: mailadmin at baladia.gov.kw (mailadmin@baladia.gov.kw) Date: Tue Aug 21 19:20:35 2007 Subject: thnks for ur suggestion In-Reply-To: References: <3384.62.150.152.226.1187711818.squirrel@webmail.baladia.gov.kw> Message-ID: <4177.62.150.152.226.1187720298.squirrel@webmail.baladia.gov.kw> Thanks guy, really apprecite your quick reply btw ur right im sorry i install clamav from rpm forge since i wanted mailscanner to use clamd for virus scanning i will keep in touch with list for more details my clamav update log shows that clamav is outdated thnks once again regards simon > mailadmin@baladia.gov.kw spake the following on 8/21/2007 8:56 AM: >> Dear ALL, >> >> i am using the latest mailscanner + the jules SA+AV script and have >> installed as per the docs and when i run the MailScanner --lint it shows >> me >> >> ------------------------------------------------- >> >> Version number in MailScanner.conf (4.62.9) is correct. >> >> ERROR: The "envelope_sender_header" in your spam.assassin.prefs.conf >> ERROR: is not correct, it should match >> X-Baladia-MailScanner-MailScanner-From > Edit the spam.assassin.prefs.conf so it matches the above line which it > gets > from your mailscanner.conf file. > >> >> >> Checking for SpamAssassin errors (if you use it)... >> SpamAssassin temp dir = >> /var/spool/MailScanner/incoming/SpamAssassin-Temp >> SpamAssassin reported no errors. >> MailScanner.conf says "Virus Scanners = clamav" >> Found these virus scanners installed: clamav >> =========================================================================== >> Ignore errors about failing to find EOCD signature >> format error: can't find EOCD signature >> at /usr/sbin/MailScanner line 451 > Like it says you can ignore this error. >> =========================================================================== >> Virus Scanner test reports: >> ClamAV said "eicar.com contains Eicar-Test-Signature" >> >> If any of your virus scanners (clamav) >> are not listed there, you should check that they are installed correctly >> and that MailScanner is finding them correctly via its >> virus.scanners.conf. >> >> --------------------------------------------------------------------------- >> r the above errors serious .. how cd i fix it >> >> >> 2) right now i have clamav-0.91.1-1.el5.rf and the latest stable version >> is 0.91.2 .. > Since your clamav is an rpm from rpmforge, you didn't install it from > Julian's > script. >> >> how cd i install this since earlier i installed it via Jules script > > There are conflicting views on installing the newest clamav. Seems to be a > bug > in it. Watch the list for more details. >> >> >> apprecite and thnks >> >> >> regards >> >> simon >> >> > > > -- > > MailScanner is like deodorant... > You hope everybody uses it, and > you notice quickly if they don't!!!! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ssilva at sgvwater.com Tue Aug 21 19:46:06 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue Aug 21 19:50:08 2007 Subject: thnks for ur suggestion In-Reply-To: <4177.62.150.152.226.1187720298.squirrel@webmail.baladia.gov.kw> References: <3384.62.150.152.226.1187711818.squirrel@webmail.baladia.gov.kw> <4177.62.150.152.226.1187720298.squirrel@webmail.baladia.gov.kw> Message-ID: mailadmin@baladia.gov.kw spake the following on 8/21/2007 11:18 AM: > Thanks guy, > > really apprecite your quick reply > btw ur right > im sorry > i install clamav from rpm forge since i wanted mailscanner to use clamd > for virus scanning > > i will keep in touch with list for more details > > my clamav update log shows that clamav is outdated > It will always report that as soon as a new version is out. It is usually safe to be back 2 or 3 version for at least a few months as bugs get worked out. I think there are several people on this list running 3.17 with no problems. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From Robert.Horton at goodmanmfg.com Tue Aug 21 20:33:44 2007 From: Robert.Horton at goodmanmfg.com (Horton, Robert) Date: Tue Aug 21 20:33:46 2007 Subject: CRM114 Problem In-Reply-To: <1964AAFBC212F742958F9275BF63DBB05B3D63@winchester.andrewscompanies.com> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info><50678FBB708A9B4FB6B536F6F657883D028E9528@exch-gman.ad.goodmanmfg.com> <1964AAFBC212F742958F9275BF63DBB05B3D63@winchester.andrewscompanies.com> Message-ID: <50678FBB708A9B4FB6B536F6F657883D028E9530@exch-gman.ad.goodmanmfg.com> I didn't use the RPMs and made up my own method. I'm using RHEL 5 to test CRM right now. My install was based off the wiki and the emails in this list. I downloaded http://crm114.sourceforge.net/tarballs/crm114-20070428-BlameSpamConf.src.tar.gz and http://laurikari.net/tre/tre-0.7.5.tar.gz And ran the following commands: tar -zxvf tre-0.7.5.tar.gz cd tre-0.7.5 ./configure --enable-static make make check make install cd .. tar -zxvf crm114-20070428-BlameSpamConf.src.tar.gz cd crm114-20070428-BlameSpamConf.src make make megatest make install cd .. Then I created the /etc/mail/spamassassin/crm114 and grabbed the 2 files from Martin Sch?tte. When creating the crm114 directory I grabbed files from the downloaded crm114-20070428-BlameSpamConf.src directory. The resulting crm114 directory contained the following before startup. -rw-r--r-- 1 root root 0 Aug 20 22:03 blacklist.mfp -rwxr-xr-x 1 root root 17426 Aug 20 22:36 mailfilter.cf -rwxr-xr-x 1 root root 44537 Aug 20 22:02 mailfilter.crm -rwxr-xr-x 1 root root 14511 Aug 20 22:02 maillib.crm -rwxr-xr-x 1 root root 22677 Aug 20 22:02 mailreaver.crm -rwxr-xr-x 1 root root 37621 Aug 20 22:02 mailtrainer.crm -rw-r--r-- 1 root root 12582924 Aug 20 21:59 nonspam.css -rw-r--r-- 1 root root 49 Aug 20 22:03 priolist.mfp -rw-r--r-- 1 root root 0 Aug 20 22:03 rewrites.mfp -rwxr-xr-x 1 root root 6924 Aug 21 14:03 shuffle.crm -rw-r--r-- 1 root root 12582924 Aug 20 21:59 spam.css -rw-r--r-- 1 root root 0 Aug 20 22:03 whitelist.mfp One thing to note is I included shuffle.crm because it was referenced in the cf files. I don't know if it matters or if it's different in the RPM versions. I modified the .cf files as the wiki said. When you first do the lint test you will get the 0.00 score because the nonspam.css and spam.css are new. It stays this way until you start learning which was the original problem for me since the messages were not being learned. -Robert -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Steven Andrews Sent: Tuesday, August 21, 2007 12:15 PM To: MailScanner discussion Subject: RE: CRM114 Problem Got the updated files from mschuette.name according to the wiki and it is incremented for your changes; unfortunately, it didn't fix for me. Should I be using a different version than the 20073001 rpm? -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Horton, Robert Sent: Tuesday, August 21, 2007 2:14 AM To: MailScanner discussion Subject: RE: CRM114 Problem Are you still having problems with the score at -0.00? I finally installed this evening and had the same problem. I think there is a bug in the crm114.pm (Version: 0.6.4), but what perplexes me is why some people claim its working...the lines I changed should affect everyone. Maybe this code was changed recently. I changed the following 2 lines in the sub call_crm dbg("crm114: opening pipe: $crm114_command < $tmpf"); $pid = Mail::SpamAssassin::Util::helper_app_pipe_open( *CRM_OUT, $tmpf, 1, $crm114_command); to dbg("crm114: opening pipe: $crm114_cmdline < $tmpf"); $pid = Mail::SpamAssassin::Util::helper_app_pipe_open( *CRM_OUT, $tmpf, 1, $crm114_cmdline); Within minutes crm114 started learning emails and no longer had the -0.00 score. You only get this score when you have an empty spam.css and nonspam.css and it doesn't know what to do with the email yet. Hope this helps, Robert Horton -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Mike Kercher Sent: Friday, August 10, 2007 11:13 AM To: MailScanner discussion Subject: CRM114 Problem I added CRM114 to a server last week per the docs in the wiki (and like I've done on several other servers), but the score is always -0.00 [root@mail crm114]# cssutil -b -r spam.css Sparse spectra file spam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 15495 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 [root@mail crm114]# cssutil -b -r nonspam.css Sparse spectra file nonspam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 15495 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 The Features learned hasn't changed in many days. Permissions look good, .crm's are +x Any suggestions where to look? Mike -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! CONFIDENTIALITY NOTE: The information contained in this transmission is privileged and confidential information intended only for the use of the individual or entity named above. If the reader of this message is not the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this transmission in error, do not read it. Please immediately reply to the sender that you have received this communication in error and then delete it. Thank you. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! CONFIDENTIALITY NOTE: The information contained in this transmission is privileged and confidential information intended only for the use of the individual or entity named above. If the reader of this message is not the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this transmission in error, do not read it. Please immediately reply to the sender that you have received this communication in error and then delete it. Thank you. From tim at denmantire.com Wed Aug 22 02:26:07 2007 From: tim at denmantire.com (Tim Boyer) Date: Wed Aug 22 02:26:24 2007 Subject: Heads up for spamhaus.org problems References: <20070819222357.GA27826@rpcs.net> <20070820020201.GA2841@rpcs.net> <46CA08CD.8070400@alexb.ch> Message-ID: <844nc31s5e518hupbukd0gqv49sf5g39v0@4ax.com> On Mon, 20 Aug 2007 23:34:05 +0200, Alex Broens wrote: >On 8/20/2007 11:22 PM, Tim Boyer wrote: >> On Sun, 19 Aug 2007 22:02:01 -0400, Richard Potter wrote: >> >>> On Mon, Aug 20, 2007 at 12:34:23AM +0200, Raymond Dijkxhoorn wrote: >>> >>>>> Just doing a routine check here, and I have a few mail servers >>>>> misbehaving. It >>>>> *appears* sendmail dnsbl to zen.spamhaus.org is timing out, and causing >>>>> mail >>>>> delivery delays, or none at all. >>>>> >>>>> I'm going to discontinue spamhaus, and see what happens. >>>> Buy rsync from them. Most likely you fire a lot of lookups on their >>>> servers and they started to ban high volume mailservers some time ago. >>>> We have seen this in a lot of places allready. >>>> >>>> May i ask how much mail are you processing daily? >>> Thanks for the reply Raymond.. I wasn't aware they were doing that. These >>> are low volume servers, less than 2,000 messages per day. Does that count >>> as "high volume" to spamhaus? >>> >>> Richard >> >> "Use of the Spamhaus DNSBLs via DNS queries to our public DNSBL mirrors is free >> for low-traffic mail servers serving less than 100 users. Use of the Spamhaus >> DNSBLs by commercial or corporate networks, ISPs and ESPs, requires a >> subscription to Spamhaus's Data Feed service." >> >> I'd be shocked if 2,000 messages per day counts as high volume. That's 20 >> emails per person per day. > >no need to be shocked :-) > >Spamhaus can't block your mail server from doing queries - it blocks >your DNS' access to the root zone - so if you use a DNS which is >querying Xmillion queries/day and your server is only doing 10000/day >then the rest of the X/million+your 10000 makes he count which rates a >block. > >Alex Hah! Of course. That makes perfect sense. -- tim boyer tim@denmantire.com From Jeramy.Eling at britax-pmg.com Wed Aug 22 08:59:31 2007 From: Jeramy.Eling at britax-pmg.com (Jeramy Eling) Date: Wed Aug 22 08:59:36 2007 Subject: Whitelists and Fuzzy Message-ID: <5CD3BFF77DFFD411BCD100D0B720F94503C4E5E5@probe.britaxpmg.com> Hi All, I have an issue with my MailScanner setup blocking a particular email as the guy has a image as a signature, Fuzzy sees this and cranks the score up. I've whitelisted the email address but still the system see the email as Spam and still blocks it. Does anyone know if it's possible to establish a Whitelist for Fuzzy to ensure that these checks are performed on email from this particular address? Any suggestions would be much appreciated. Thanks In Advance Jez -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070822/0a048a8e/attachment.html From martinh at solidstatelogic.com Wed Aug 22 09:05:54 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed Aug 22 09:05:59 2007 Subject: Whitelists and Fuzzy In-Reply-To: <5CD3BFF77DFFD411BCD100D0B720F94503C4E5E5@probe.britaxpmg.com> Message-ID: Jez Which whitelist did you use - there are several? I wonder why FuzzyOCR is triggering on this guys signature, a graphic signature (however misguided) is quite common. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Jeramy Eling > Sent: 22 August 2007 09:00 > To: mailscanner@lists.mailscanner.info > Subject: Whitelists and Fuzzy > > Hi All, > > I have an issue with my MailScanner setup blocking a particular email as > the guy has a image as a signature, Fuzzy sees this and cranks the score > up. I've whitelisted the email address but still the system see the email > as Spam and still blocks it. > > Does anyone know if it's possible to establish a Whitelist for Fuzzy to > ensure that these checks are performed on email from this particular > address? > > Any suggestions would be much appreciated. > > Thanks In Advance > > Jez ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From Jeramy.Eling at britax-pmg.com Wed Aug 22 09:15:46 2007 From: Jeramy.Eling at britax-pmg.com (Jeramy Eling) Date: Wed Aug 22 09:15:51 2007 Subject: Whitelists and Fuzzy Message-ID: <5CD3BFF77DFFD411BCD100D0B720F94503C4E5E6@probe.britaxpmg.com> Hi Martin A little bit of background, I have MailWatch running and I've got this integrated to do the White and Black listing from within Mailwatch, so as far as the config is concerned it's 'Is Definitely Not Spam' and 'Is Definitely Spam', additionally I have one running to allow certain emails with forms through as well. If I look at the email in the quarantine it shows a score of 5.00 and a matching rule of 'FUZZY_OCR_KNOWN_HASH'. Cheers Jez -----Original Message----- From: Martin.Hepworth [mailto:martinh@solidstatelogic.com] Sent: 22 August 2007 09:06 To: MailScanner discussion Subject: RE: Whitelists and Fuzzy Jez Which whitelist did you use - there are several? I wonder why FuzzyOCR is triggering on this guys signature, a graphic signature (however misguided) is quite common. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Jeramy Eling > Sent: 22 August 2007 09:00 > To: mailscanner@lists.mailscanner.info > Subject: Whitelists and Fuzzy > > Hi All, > > I have an issue with my MailScanner setup blocking a particular email > as the guy has a image as a signature, Fuzzy sees this and cranks the > score up. I've whitelisted the email address but still the system see > the email as Spam and still blocks it. > > Does anyone know if it's possible to establish a Whitelist for Fuzzy > to ensure that these checks are performed on email from this > particular address? > > Any suggestions would be much appreciated. > > Thanks In Advance > > Jez ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From martinh at solidstatelogic.com Wed Aug 22 09:21:46 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed Aug 22 09:21:55 2007 Subject: Whitelists and Fuzzy In-Reply-To: <5CD3BFF77DFFD411BCD100D0B720F94503C4E5E6@probe.britaxpmg.com> Message-ID: Jez Hmm what other rules have hit in SA? Might be worth asking Steve et al on the mailwatch list about a problem with the MW whitelist stuff. There's been several threads on this in the past.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Jeramy Eling > Sent: 22 August 2007 09:16 > To: MailScanner discussion > Subject: RE: Whitelists and Fuzzy > > Hi Martin > > A little bit of background, I have MailWatch running and I've got this > integrated to do the White and Black listing from within Mailwatch, so > as far as the config is concerned it's 'Is Definitely Not Spam' and 'Is > Definitely Spam', additionally I have one running to allow certain > emails with forms through as well. If I look at the email in the > quarantine it shows a score of 5.00 and a matching rule of > 'FUZZY_OCR_KNOWN_HASH'. > > Cheers > > Jez > > > -----Original Message----- > From: Martin.Hepworth [mailto:martinh@solidstatelogic.com] > Sent: 22 August 2007 09:06 > To: MailScanner discussion > Subject: RE: Whitelists and Fuzzy > > Jez > > Which whitelist did you use - there are several? I wonder why FuzzyOCR > is triggering on this guys signature, a graphic signature (however > misguided) is quite common. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Jeramy Eling > > Sent: 22 August 2007 09:00 > > To: mailscanner@lists.mailscanner.info > > Subject: Whitelists and Fuzzy > > > > Hi All, > > > > I have an issue with my MailScanner setup blocking a particular email > > as the guy has a image as a signature, Fuzzy sees this and cranks the > > score up. I've whitelisted the email address but still the system see > > the email as Spam and still blocks it. > > > > Does anyone know if it's possible to establish a Whitelist for Fuzzy > > to ensure that these checks are performed on email from this > > particular address? > > > > Any suggestions would be much appreciated. > > > > Thanks In Advance > > > > Jez > > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error you > must take no action based on them, nor must you copy or show them to > anyone. Please advise the sender by replying to this e-mail immediately > and then delete the original from your computer. > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales (Company > No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 > 1RU, United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From list-mailscanner at linguaphone.com Wed Aug 22 09:22:07 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 22 09:22:15 2007 Subject: Whitelists and Fuzzy In-Reply-To: <5CD3BFF77DFFD411BCD100D0B720F94503C4E5E6@probe.britaxpmg.com> References: <5CD3BFF77DFFD411BCD100D0B720F94503C4E5E6@probe.britaxpmg.com> Message-ID: <1187770927.19242.7.camel@gblades-suse.linguaphone-intranet.co.uk> If you have a whitelist defined in mailwatch then it will be whitelisted regardless of the spamassassin score unless you have not configured the whitelist custom function correctly in mailscanner. Fuzzyocr has oviously detected the picture in the past and has stored a hash of it together with its score in its database to save future processing. If this image got a high score due to misconfiguration of the words file then you can use one of the tools that came with fuzzyocr to remove that image from the database so next time it is found it will recalculate the score. On Wed, 2007-08-22 at 09:15, Jeramy Eling wrote: > Hi Martin > > A little bit of background, I have MailWatch running and I've got this > integrated to do the White and Black listing from within Mailwatch, so > as far as the config is concerned it's 'Is Definitely Not Spam' and 'Is > Definitely Spam', additionally I have one running to allow certain > emails with forms through as well. If I look at the email in the > quarantine it shows a score of 5.00 and a matching rule of > 'FUZZY_OCR_KNOWN_HASH'. > > Cheers > > Jez > > > -----Original Message----- > From: Martin.Hepworth [mailto:martinh@solidstatelogic.com] > Sent: 22 August 2007 09:06 > To: MailScanner discussion > Subject: RE: Whitelists and Fuzzy > > Jez > > Which whitelist did you use - there are several? I wonder why FuzzyOCR > is triggering on this guys signature, a graphic signature (however > misguided) is quite common. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Jeramy Eling > > Sent: 22 August 2007 09:00 > > To: mailscanner@lists.mailscanner.info > > Subject: Whitelists and Fuzzy > > > > Hi All, > > > > I have an issue with my MailScanner setup blocking a particular email > > as the guy has a image as a signature, Fuzzy sees this and cranks the > > score up. I've whitelisted the email address but still the system see > > the email as Spam and still blocks it. > > > > Does anyone know if it's possible to establish a Whitelist for Fuzzy > > to ensure that these checks are performed on email from this > > particular address? > > > > Any suggestions would be much appreciated. > > > > Thanks In Advance > > > > Jez > > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error you > must take no action based on them, nor must you copy or show them to > anyone. Please advise the sender by replying to this e-mail immediately > and then delete the original from your computer. > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales (Company > No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 > 1RU, United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From Jeramy.Eling at britax-pmg.com Wed Aug 22 09:24:26 2007 From: Jeramy.Eling at britax-pmg.com (Jeramy Eling) Date: Wed Aug 22 09:24:31 2007 Subject: Whitelists and Fuzzy Message-ID: <5CD3BFF77DFFD411BCD100D0B720F945047588CE@probe.britaxpmg.com> Martin, I've copied and pasted the full SA rule hits that the email has hit below: - 0.12 AWL From: address is in the auto white-list -2.60 BAYES_00 Bayesian spam probability is 0 to 1% 5.00 FUZZY_OCR_KNOWN_HASH Mail contains an image with known hash 0.37 HTML_30_40 Message is 30% to 40% HTML 0.00 HTML_MESSAGE HTML included in message 0.22 MIME_BASE64_NO_NAME base64 attachment does not have a file name Jez -----Original Message----- From: Martin.Hepworth [mailto:martinh@solidstatelogic.com] Sent: 22 August 2007 09:22 To: MailScanner discussion Subject: RE: Whitelists and Fuzzy Jez Hmm what other rules have hit in SA? Might be worth asking Steve et al on the mailwatch list about a problem with the MW whitelist stuff. There's been several threads on this in the past.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Jeramy Eling > Sent: 22 August 2007 09:16 > To: MailScanner discussion > Subject: RE: Whitelists and Fuzzy > > Hi Martin > > A little bit of background, I have MailWatch running and I've got this > integrated to do the White and Black listing from within Mailwatch, so > as far as the config is concerned it's 'Is Definitely Not Spam' and > 'Is Definitely Spam', additionally I have one running to allow certain > emails with forms through as well. If I look at the email in the > quarantine it shows a score of 5.00 and a matching rule of > 'FUZZY_OCR_KNOWN_HASH'. > > Cheers > > Jez > > > -----Original Message----- > From: Martin.Hepworth [mailto:martinh@solidstatelogic.com] > Sent: 22 August 2007 09:06 > To: MailScanner discussion > Subject: RE: Whitelists and Fuzzy > > Jez > > Which whitelist did you use - there are several? I wonder why FuzzyOCR > is triggering on this guys signature, a graphic signature (however > misguided) is quite common. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner- bounces@lists.mailscanner.info] On Behalf Of > > Jeramy Eling > > Sent: 22 August 2007 09:00 > > To: mailscanner@lists.mailscanner.info > > Subject: Whitelists and Fuzzy > > > > Hi All, > > > > I have an issue with my MailScanner setup blocking a particular > > email as the guy has a image as a signature, Fuzzy sees this and > > cranks the score up. I've whitelisted the email address but still > > the system see the email as Spam and still blocks it. > > > > Does anyone know if it's possible to establish a Whitelist for Fuzzy > > to ensure that these checks are performed on email from this > > particular address? > > > > Any suggestions would be much appreciated. > > > > Thanks In Advance > > > > Jez > > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales (Company > No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford > OX5 1RU, United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From Jeramy.Eling at britax-pmg.com Wed Aug 22 09:29:54 2007 From: Jeramy.Eling at britax-pmg.com (Jeramy Eling) Date: Wed Aug 22 09:30:00 2007 Subject: Whitelists and Fuzzy Message-ID: <5CD3BFF77DFFD411BCD100D0B720F945047588CF@probe.britaxpmg.com> Gareth, Having not used the mentioned tools before do you know where I can find documentation for them. I'm currently looking on the FuzzyOCR site and there doesn't appear to be anything. Jez -----Original Message----- From: Gareth [mailto:list-mailscanner@linguaphone.com] Sent: 22 August 2007 09:22 To: MailScanner discussion Subject: RE: Whitelists and Fuzzy If you have a whitelist defined in mailwatch then it will be whitelisted regardless of the spamassassin score unless you have not configured the whitelist custom function correctly in mailscanner. Fuzzyocr has oviously detected the picture in the past and has stored a hash of it together with its score in its database to save future processing. If this image got a high score due to misconfiguration of the words file then you can use one of the tools that came with fuzzyocr to remove that image from the database so next time it is found it will recalculate the score. On Wed, 2007-08-22 at 09:15, Jeramy Eling wrote: > Hi Martin > > A little bit of background, I have MailWatch running and I've got this > integrated to do the White and Black listing from within Mailwatch, so > as far as the config is concerned it's 'Is Definitely Not Spam' and > 'Is Definitely Spam', additionally I have one running to allow certain > emails with forms through as well. If I look at the email in the > quarantine it shows a score of 5.00 and a matching rule of > 'FUZZY_OCR_KNOWN_HASH'. > > Cheers > > Jez > > > -----Original Message----- > From: Martin.Hepworth [mailto:martinh@solidstatelogic.com] > Sent: 22 August 2007 09:06 > To: MailScanner discussion > Subject: RE: Whitelists and Fuzzy > > Jez > > Which whitelist did you use - there are several? I wonder why FuzzyOCR > is triggering on this guys signature, a graphic signature (however > misguided) is quite common. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner- bounces@lists.mailscanner.info] On Behalf Of > > Jeramy Eling > > Sent: 22 August 2007 09:00 > > To: mailscanner@lists.mailscanner.info > > Subject: Whitelists and Fuzzy > > > > Hi All, > > > > I have an issue with my MailScanner setup blocking a particular > > email as the guy has a image as a signature, Fuzzy sees this and > > cranks the score up. I've whitelisted the email address but still > > the system see the email as Spam and still blocks it. > > > > Does anyone know if it's possible to establish a Whitelist for Fuzzy > > to ensure that these checks are performed on email from this > > particular address? > > > > Any suggestions would be much appreciated. > > > > Thanks In Advance > > > > Jez > > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales (Company > No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford > OX5 1RU, United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From list-mailscanner at linguaphone.com Wed Aug 22 09:37:17 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 22 09:37:33 2007 Subject: Whitelists and Fuzzy In-Reply-To: <5CD3BFF77DFFD411BCD100D0B720F945047588CF@probe.britaxpmg.com> References: <5CD3BFF77DFFD411BCD100D0B720F945047588CF@probe.britaxpmg.com> Message-ID: <1187771836.19248.10.camel@gblades-suse.linguaphone-intranet.co.uk> The program is called fussy-find and is located in the Utils directory in wherever you unpacked the source code to. Documentation is in the readme file in the same directory. On Wed, 2007-08-22 at 09:29, Jeramy Eling wrote: > Gareth, > > Having not used the mentioned tools before do you know where I can find > documentation for them. I'm currently looking on the FuzzyOCR site and > there doesn't appear to be anything. > > Jez > > -----Original Message----- > From: Gareth [mailto:list-mailscanner@linguaphone.com] > Sent: 22 August 2007 09:22 > To: MailScanner discussion > Subject: RE: Whitelists and Fuzzy > > If you have a whitelist defined in mailwatch then it will be whitelisted > regardless of the spamassassin score unless you have not configured the > whitelist custom function correctly in mailscanner. > > Fuzzyocr has oviously detected the picture in the past and has stored a > hash of it together with its score in its database to save future > processing. If this image got a high score due to misconfiguration of > the words file then you can use one of the tools that came with fuzzyocr > to remove that image from the database so next time it is found it will > recalculate the score. > > On Wed, 2007-08-22 at 09:15, Jeramy Eling wrote: > > Hi Martin > > > > A little bit of background, I have MailWatch running and I've got this > > > integrated to do the White and Black listing from within Mailwatch, so > > > as far as the config is concerned it's 'Is Definitely Not Spam' and > > 'Is Definitely Spam', additionally I have one running to allow certain > > > emails with forms through as well. If I look at the email in the > > quarantine it shows a score of 5.00 and a matching rule of > > 'FUZZY_OCR_KNOWN_HASH'. > > > > Cheers > > > > Jez > > > > > > -----Original Message----- > > From: Martin.Hepworth [mailto:martinh@solidstatelogic.com] > > Sent: 22 August 2007 09:06 > > To: MailScanner discussion > > Subject: RE: Whitelists and Fuzzy > > > > Jez > > > > Which whitelist did you use - there are several? I wonder why FuzzyOCR > > > is triggering on this guys signature, a graphic signature (however > > misguided) is quite common. > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > > > [mailto:mailscanner- bounces@lists.mailscanner.info] On Behalf Of > > > Jeramy Eling > > > Sent: 22 August 2007 09:00 > > > To: mailscanner@lists.mailscanner.info > > > Subject: Whitelists and Fuzzy > > > > > > Hi All, > > > > > > I have an issue with my MailScanner setup blocking a particular > > > email as the guy has a image as a signature, Fuzzy sees this and > > > cranks the score up. I've whitelisted the email address but still > > > the system see the email as Spam and still blocks it. > > > > > > Does anyone know if it's possible to establish a Whitelist for Fuzzy > > > > to ensure that these checks are performed on email from this > > > particular address? > > > > > > Any suggestions would be much appreciated. > > > > > > Thanks In Advance > > > > > > Jez > > > > > > > > > > > > ********************************************************************** > > Confidentiality : This e-mail and any attachments are intended for the > > > addressee only and may be confidential. If they come to you in error > > you must take no action based on them, nor must you copy or show them > > to anyone. Please advise the sender by replying to this e-mail > > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > > the author and unless specifically stated to the contrary, are not > > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > > communications medium and can be subject to data corruption. We advise > > > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > > attachments are free from known viruses but in keeping with good > > computing practice, you should ensure that they are virus free. > > > > Red Lion 49 Ltd T/A Solid State Logic > > Registered as a limited company in England and Wales (Company > > No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford > > OX5 1RU, United Kingdom > > ********************************************************************** > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From list-mailscanner at linguaphone.com Wed Aug 22 09:55:46 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 22 09:55:58 2007 Subject: DCC not working Message-ID: <1187772946.19252.14.camel@gblades-suse.linguaphone-intranet.co.uk> I installed DCC and have got to the stage where a debug shows that it is able to query the servers :- | grep dcc [12550] dbg: dcc: network tests on, registering DCC [12550] dbg: config: fixed relative path: /var/lib/spamassassin/3.002003/updates_spamassassin_org/25_dcc.cf [12550] dbg: config: using "/var/lib/spamassassin/3.002003/updates_spamassassin_org/25_dcc.cf" for included file [12550] dbg: config: read file /var/lib/spamassassin/3.002003/updates_spamassassin_org/25_dcc.cf [12550] dbg: dcc: dccifd is not available: no r/w dccifd socket found [12550] dbg: util: executable for dccproc was found at /usr/local/bin/dccproc [12550] dbg: dcc: dccproc is available: /usr/local/bin/dccproc [12550] dbg: dcc: opening pipe: /usr/local/bin/dccproc -H -x 0 -a 203.25.170.31 < /tmp/.spamassassin12550Adpfnktmp [12550] dbg: dcc: got response: X-DCC--Metrics: mailscanner 1114; Body=1 Fuz1=1 Fuz2=1 X-DCC-CTc-dcc2-Metrics: gecko.npgx.com.au 1031; Body=0 Fuz1=0 Fuz2=0 fMHId05XuL20k3PgNVdccAIexF9wrelX4WoQqkZVRwRKBxIuxyjID3j+fcRaSyFJGGEod8EFk2xW However I have left it overnight and in the 1000 or so emails I have received in that time there has not been a single hit. Any ideas what could be wrong? From shuttlebox at gmail.com Wed Aug 22 10:14:07 2007 From: shuttlebox at gmail.com (shuttlebox) Date: Wed Aug 22 10:14:14 2007 Subject: Blastwave edition of MailScanner for Solaris Message-ID: <625385e30708220214v7e97d6b8k75208ce2024c35ef@mail.gmail.com> I have packaged MailScanner 4.62.9-3 for the Blastwave project. For those who don't know about Blastwave it's best described as bringing apt-get to Solaris. We package fresh versions of around 1700 software titles for Solaris 8+ sparc/x86. A complete MailScanner system would be installed by: # pkg-get -i sendmail mailscanner clamav spamassassin That would install those four apps and all their respective dependencies. No more compiling ClamAV, using CPAN for Perl modules and downloading packages from Sunfreeware that just wants another package...and another...and so on. In short - apt-get for Solaris. More info on http://www.blastwave.org. MailScanner is slightly adapted to Solaris/Blastwave to ease configuring somewhat, e.g. paths are changed here and there to fit Blastwave editions of Perl, ClamAV and so on. I only provide start scripts for Sendmail but Blastwave has packages for Exim and Postfix too so maybe someone could help me with that? Please give it a try if you're a Solaris user. There's a general users list for Blastwave where you can get help for Blastwave specific issued, direct questions about the packages themselves there and MailScanner questions here as usual. -- /peter From maillists at conactive.com Wed Aug 22 11:32:08 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Wed Aug 22 11:32:11 2007 Subject: Whitelists and Fuzzy In-Reply-To: <5CD3BFF77DFFD411BCD100D0B720F945047588CF@probe.britaxpmg.com> References: <5CD3BFF77DFFD411BCD100D0B720F945047588CF@probe.britaxpmg.com> Message-ID: You don't seem to have noticed Gareth's comment about the MS whitelist. It seems your whitelist is not correctly set up, so it doesn't work at all. You may want to work on this as well ;-) Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From Jeramy.Eling at britax-pmg.com Wed Aug 22 11:35:24 2007 From: Jeramy.Eling at britax-pmg.com (Jeramy Eling) Date: Wed Aug 22 11:35:29 2007 Subject: Whitelists and Fuzzy Message-ID: <5CD3BFF77DFFD411BCD100D0B720F945047588D2@probe.britaxpmg.com> I have checked the W/L this morning by ading an address to it and bouncing an email in with the suspect signature attached. The email shows in MailWatch as whitelisted but it's still blocked because of the signature. -----Original Message----- From: Kai Schaetzl [mailto:maillists@conactive.com] Sent: 22 August 2007 11:32 To: mailscanner@lists.mailscanner.info Subject: Re: Whitelists and Fuzzy You don't seem to have noticed Gareth's comment about the MS whitelist. It seems your whitelist is not correctly set up, so it doesn't work at all. You may want to work on this as well ;-) Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From list-mailscanner at linguaphone.com Wed Aug 22 11:41:38 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 22 11:41:51 2007 Subject: Whitelists and Fuzzy In-Reply-To: <5CD3BFF77DFFD411BCD100D0B720F945047588D2@probe.britaxpmg.com> References: <5CD3BFF77DFFD411BCD100D0B720F945047588D2@probe.britaxpmg.com> Message-ID: <1187779298.19244.19.camel@gblades-suse.linguaphone-intranet.co.uk> If something is whitelisted then no way can it be classed as spam. Something is wrong with your mailscanner configuration. Check the config file has the following lines :- Then check to make sure SQLBlackWhiteList.pm is in the mailscanner CustomFunctions file and lastely that the SQLBlackWhiteList.pm file has the sql database and account details correctly set. Is Definitely Not Spam = &SQLWhitelist Is Definitely Spam = &SQLBlacklist On Wed, 2007-08-22 at 11:35, Jeramy Eling wrote: > I have checked the W/L this morning by ading an address to it and bouncing an email in with the suspect signature attached. The email shows in MailWatch as whitelisted but it's still blocked because of the signature. > > -----Original Message----- > From: Kai Schaetzl [mailto:maillists@conactive.com] > Sent: 22 August 2007 11:32 > To: mailscanner@lists.mailscanner.info > Subject: Re: Whitelists and Fuzzy > > You don't seem to have noticed Gareth's comment about the MS whitelist. It seems your whitelist is not correctly set up, so it doesn't work at all. > You may want to work on this as well ;-) > > Kai > > -- > Kai Sch?tzl, Berlin, Germany > Get your web at Conactive Internet Services: http://www.conactive.com > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From glenn.steen at gmail.com Wed Aug 22 11:48:11 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 22 11:48:13 2007 Subject: MailScanner Digest, Vol 20, Issue 49 In-Reply-To: References: <002b01c7e411$7989cf00$d10da8c0@genevawoods.com> Message-ID: <223f97700708220348u7618c712g12b813571d14cb8e@mail.gmail.com> On 21/08/07, Gareth wrote: > well clamscan is much slower than either the clamavmodule or clamd versions > so changing to one of those should help speed it up considerably. > > Also you are running 0.90 version of clamav which has a bug causing it to > take much longer to load its signatures which makes the clamscan method even > slower again. > > Upgrading clamav and switching to clamavmodule will probably double your > scanning speed easily. With the meager memory resource (256 MiB), I would think that that would push things into thrashing heavily. Going for clamd (which has a smaller memory footprint) is likely better. Cheers -- Glenn > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Culley > > Morrow > > Sent: 21 August 2007 17:37 > > To: mailscanner@lists.mailscanner.info > > Subject: RE: MailScanner Digest, Vol 20, Issue 49 > > > > > > Thanks for the replies. This server is quite meager with 256mb RAM and a > > 30gb hard drive, all running on a 4 year old Dell desktop. Meager > > is putting > > it mildly. I've got to make it work while it's in place, a massive > > replacement is in the works though. > > > > Clamscan was what I was meaning actually. I remember reading a > > while back in > > the archives that it was a major stumbling point with new > > versions on older > > systems. After an update it was running OK, but slowly getting further and > > further behind in the mail delivery. > > > > Anyway, I'll start digging through the wiki for better rules and > > see what I > > can start filtering out. > > > > ~={o}=~ > > > > Culley Morrow > > IT Manager > > Geneva Woods Pharmacy > > > > > > -----Original Message----- > > Message: 11 > > Date: Tue, 21 Aug 2007 09:55:06 +0100 > > From: Greg Matthews > > Subject: Re: New Clam, Old, Mailscanner, Ancient Kernel > > To: MailScanner discussion > > Message-ID: <46CAA86A.4060206@nerc.ac.uk> > > Content-Type: text/plain; charset=windows-1252; format=flowed > > > > Culley Morrow wrote: > > > I ll list out the software versions below and I need a bit of > > assistance > > > making them work for now. I know all I need to do is upgrade the kernel > > > to 2.6 and it all works, but I d like to get them functioning As-Is > > > and then do the upgrade so I have something working to fall back on. > > > Clam AV is currently shut off since clamd as a service was so slow. > > > > kernel upgrade probably not very important. As others have pointed out, > > there is little reason not to upgrade MS and SA. Stick as much memory in > > the box as it can handle. > > > > > Kernel 2.4.18-bf2.4 > > > > > > Mailscanner 3.27.1-1 > > > > > > Clam AV 0.90.1-3etch3 > > > > > > Spam Assassin 2.64-1 > > > > > > > > > > > > Currently we are inundated with mass spam and I need to get some AV in > > > place, be it Clam or another GNU/GPL/ free as in beer -ware. I need a > > > hand here if anyone wants to chime in. > > > > if you are "inundated" then the best start you can make is to reject as > > much as possible at the MTA. As this is Debian, your MTA is probably > > (but not necessarily) exim. Look at putting in a single well regarded > > block list at the MTA, something like zen.spamhaus.org but do your > > research and find one that /you/ like the look of (block list > > preferences can start flame wars!). Make sure you are rejecting mail at > > the MTA for all unknown recipients and not accepting then bouncing. Set > > up your MTA to throttle incoming mail so it doesnt get overwhelmed or > > let your incoming queue build up uncontrollably. > > > > Visit the MS wiki for tips on how to do this - dig deep, it can be a bit > > tricky to find what you are looking for. Search the archives for good > > links into the wiki. > > > > GREG > > -- > > Greg Matthews 01491 692445 > > Head of UNIX/Linux, iTSS Wallingford > > > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Wed Aug 22 11:52:57 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 22 11:53:01 2007 Subject: DCC not working In-Reply-To: <1187772946.19252.14.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1187772946.19252.14.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <223f97700708220352td47e278k3502befe5fc56e2b@mail.gmail.com> On 22/08/07, Gareth wrote: > I installed DCC and have got to the stage where a debug shows that it is > able to query the servers :- > > | grep dcc > [12550] dbg: dcc: network tests on, registering DCC > [12550] dbg: config: fixed relative path: > /var/lib/spamassassin/3.002003/updates_spamassassin_org/25_dcc.cf > [12550] dbg: config: using > "/var/lib/spamassassin/3.002003/updates_spamassassin_org/25_dcc.cf" for > included file > [12550] dbg: config: read file > /var/lib/spamassassin/3.002003/updates_spamassassin_org/25_dcc.cf > [12550] dbg: dcc: dccifd is not available: no r/w dccifd socket found > [12550] dbg: util: executable for dccproc was found at > /usr/local/bin/dccproc > [12550] dbg: dcc: dccproc is available: /usr/local/bin/dccproc > [12550] dbg: dcc: opening pipe: /usr/local/bin/dccproc -H -x 0 -a > 203.25.170.31 < /tmp/.spamassassin12550Adpfnktmp > [12550] dbg: dcc: got response: X-DCC--Metrics: mailscanner 1114; Body=1 > Fuz1=1 Fuz2=1 > X-DCC-CTc-dcc2-Metrics: gecko.npgx.com.au 1031; Body=0 Fuz1=0 Fuz2=0 > fMHId05XuL20k3PgNVdccAIexF9wrelX4WoQqkZVRwRKBxIuxyjID3j+fcRaSyFJGGEod8EFk2xW > > However I have left it overnight and in the 1000 or so emails I have > received in that time there has not been a single hit. > > Any ideas what could be wrong? > Check that it works for postfix/postfix user. Usual SA test (-t -D < testmessage) should reveal any problems. -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From list-mailscanner at linguaphone.com Wed Aug 22 12:10:42 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 22 12:10:56 2007 Subject: DCC not working In-Reply-To: <223f97700708220352td47e278k3502befe5fc56e2b@mail.gmail.com> References: <1187772946.19252.14.camel@gblades-suse.linguaphone-intranet.co.uk> <223f97700708220352td47e278k3502befe5fc56e2b@mail.gmail.com> Message-ID: <1187781042.19244.24.camel@gblades-suse.linguaphone-intranet.co.uk> On Wed, 2007-08-22 at 11:52, Glenn Steen wrote: > On 22/08/07, Gareth wrote: > > I installed DCC and have got to the stage where a debug shows that it is > > able to query the servers :- > > > > | grep dcc > > [12550] dbg: dcc: network tests on, registering DCC > > [12550] dbg: config: fixed relative path: > > /var/lib/spamassassin/3.002003/updates_spamassassin_org/25_dcc.cf > > [12550] dbg: config: using > > "/var/lib/spamassassin/3.002003/updates_spamassassin_org/25_dcc.cf" for > > included file > > [12550] dbg: config: read file > > /var/lib/spamassassin/3.002003/updates_spamassassin_org/25_dcc.cf > > [12550] dbg: dcc: dccifd is not available: no r/w dccifd socket found > > [12550] dbg: util: executable for dccproc was found at > > /usr/local/bin/dccproc > > [12550] dbg: dcc: dccproc is available: /usr/local/bin/dccproc > > [12550] dbg: dcc: opening pipe: /usr/local/bin/dccproc -H -x 0 -a > > 203.25.170.31 < /tmp/.spamassassin12550Adpfnktmp > > [12550] dbg: dcc: got response: X-DCC--Metrics: mailscanner 1114; Body=1 > > Fuz1=1 Fuz2=1 > > X-DCC-CTc-dcc2-Metrics: gecko.npgx.com.au 1031; Body=0 Fuz1=0 Fuz2=0 > > fMHId05XuL20k3PgNVdccAIexF9wrelX4WoQqkZVRwRKBxIuxyjID3j+fcRaSyFJGGEod8EFk2xW > > > > However I have left it overnight and in the 1000 or so emails I have > > received in that time there has not been a single hit. > > > > Any ideas what could be wrong? > > > Check that it works for postfix/postfix user. Usual SA test (-t -D < > testmessage) should reveal any problems. I did that and it appears to work and sais it gets back a response from the server as in the earlier post. From glenn.steen at gmail.com Wed Aug 22 12:42:24 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed Aug 22 12:42:29 2007 Subject: DCC not working In-Reply-To: <1187781042.19244.24.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1187772946.19252.14.camel@gblades-suse.linguaphone-intranet.co.uk> <223f97700708220352td47e278k3502befe5fc56e2b@mail.gmail.com> <1187781042.19244.24.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <223f97700708220442p56bffcc4teaa7b7d0bd498527@mail.gmail.com> On 22/08/07, Gareth wrote: > On Wed, 2007-08-22 at 11:52, Glenn Steen wrote: > > On 22/08/07, Gareth wrote: > > > I installed DCC and have got to the stage where a debug shows that it is > > > able to query the servers :- > > > > > > | grep dcc > > > [12550] dbg: dcc: network tests on, registering DCC > > > [12550] dbg: config: fixed relative path: > > > /var/lib/spamassassin/3.002003/updates_spamassassin_org/25_dcc.cf > > > [12550] dbg: config: using > > > "/var/lib/spamassassin/3.002003/updates_spamassassin_org/25_dcc.cf" for > > > included file > > > [12550] dbg: config: read file > > > /var/lib/spamassassin/3.002003/updates_spamassassin_org/25_dcc.cf > > > [12550] dbg: dcc: dccifd is not available: no r/w dccifd socket found > > > [12550] dbg: util: executable for dccproc was found at > > > /usr/local/bin/dccproc > > > [12550] dbg: dcc: dccproc is available: /usr/local/bin/dccproc > > > [12550] dbg: dcc: opening pipe: /usr/local/bin/dccproc -H -x 0 -a > > > 203.25.170.31 < /tmp/.spamassassin12550Adpfnktmp > > > [12550] dbg: dcc: got response: X-DCC--Metrics: mailscanner 1114; Body=1 > > > Fuz1=1 Fuz2=1 > > > X-DCC-CTc-dcc2-Metrics: gecko.npgx.com.au 1031; Body=0 Fuz1=0 Fuz2=0 > > > fMHId05XuL20k3PgNVdccAIexF9wrelX4WoQqkZVRwRKBxIuxyjID3j+fcRaSyFJGGEod8EFk2xW > > > > > > However I have left it overnight and in the 1000 or so emails I have > > > received in that time there has not been a single hit. > > > > > > Any ideas what could be wrong? > > > > > Check that it works for postfix/postfix user. Usual SA test (-t -D < > > testmessage) should reveal any problems. > > I did that and it appears to work and sais it gets back a response from > the server as in the earlier post. > If so, did any of the 1000 messages get detected by any other digest check (razor or pyzor)? If you use MailWatch (which I think you do) you should easily be able to check the spamreport field for any mention of DCC... Isuppose this is how you determined that it didn't work? Might just be a question of ... patience;-) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From list-mailscanner at linguaphone.com Wed Aug 22 12:53:07 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 22 12:53:20 2007 Subject: DCC not working In-Reply-To: <223f97700708220442p56bffcc4teaa7b7d0bd498527@mail.gmail.com> References: <1187772946.19252.14.camel@gblades-suse.linguaphone-intranet.co.uk> <223f97700708220352td47e278k3502befe5fc56e2b@mail.gmail.com> <1187781042.19244.24.camel@gblades-suse.linguaphone-intranet.co.uk> <223f97700708220442p56bffcc4teaa7b7d0bd498527@mail.gmail.com> Message-ID: <1187783586.19250.30.camel@gblades-suse.linguaphone-intranet.co.uk> On Wed, 2007-08-22 at 12:42, Glenn Steen wrote: > If so, did any of the 1000 messages get detected by any other digest > check (razor or pyzor)? > If you use MailWatch (which I think you do) you should easily be able > to check the spamreport field for any mention of DCC... Isuppose this > is how you determined that it didn't work? Might just be a question of > ... patience;-) Yes Razor and Pyzor regularly detect spam. The mailwatch spamreport field has no mention of DCC in the 500 spams I have received since DCC appeared to start working. Even Fuzzy OCR had 39 matches in that timeframe and I would expect far better of DCC. From maillists at conactive.com Wed Aug 22 13:31:25 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Wed Aug 22 13:31:30 2007 Subject: Whitelists and Fuzzy In-Reply-To: <5CD3BFF77DFFD411BCD100D0B720F945047588D2@probe.britaxpmg.com> References: <5CD3BFF77DFFD411BCD100D0B720F945047588D2@probe.britaxpmg.com> Message-ID: Jeramy Eling wrote on Wed, 22 Aug 2007 11:35:24 +0100: > I have checked the W/L this morning by ading an address to it to *which* whitelist? Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From Jeramy.Eling at britax-pmg.com Wed Aug 22 13:44:29 2007 From: Jeramy.Eling at britax-pmg.com (Jeramy Eling) Date: Wed Aug 22 13:44:35 2007 Subject: Whitelists and Fuzzy Message-ID: <5CD3BFF77DFFD411BCD100D0B720F94503C4E5E8@probe.britaxpmg.com> The Whitelist which is within the Mailwatch interface 'Is Definitely Not Spam'. -----Original Message----- From: Kai Schaetzl [mailto:maillists@conactive.com] Sent: 22 August 2007 13:31 To: mailscanner@lists.mailscanner.info Subject: Re: Whitelists and Fuzzy Jeramy Eling wrote on Wed, 22 Aug 2007 11:35:24 +0100: > I have checked the W/L this morning by ading an address to it to *which* whitelist? Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From ryanw at falsehope.com Wed Aug 22 13:47:18 2007 From: ryanw at falsehope.com (Ryan Weaver) Date: Wed Aug 22 13:47:29 2007 Subject: ClamAV & Sanesecurity & Spamassassin In-Reply-To: References: <5CD3BFF77DFFD411BCD100D0B720F945047588D2@probe.britaxpmg.com> Message-ID: <000e01c7e4ba$94ad3de0$be07b9a0$@com> Hi, I've looked around but have not been able to find an answer sufficient for me to implement. Is it possible to use the Sanesecurity definitions for ClamAV only via the Spamassassin plugin (i.e. use normal ClamAV Virus definitions for the virus scan, then use only the Sanesecurity definitions with the Spamassassin plugin)? I ask this because I am using the Vispan setup to auto block persistent virus / spam sources, however the Sanesecurity definitions make the initial virus scan return the phishing/spam as a virus hit. This is not completely bad because they are getting caught and blocked, but it would be more sanitary for them to be marked as spam instead of virus. Thanks, Ryan From Denis.Beauchemin at USherbrooke.ca Wed Aug 22 13:47:23 2007 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Wed Aug 22 13:47:55 2007 Subject: Whitelists and Fuzzy In-Reply-To: <5CD3BFF77DFFD411BCD100D0B720F94503C4E5E6@probe.britaxpmg.com> References: <5CD3BFF77DFFD411BCD100D0B720F94503C4E5E6@probe.britaxpmg.com> Message-ID: <46CC305B.2060405@USherbrooke.ca> Jeramy Eling a ?crit : > Hi Martin > > A little bit of background, I have MailWatch running and I've got this > integrated to do the White and Black listing from within Mailwatch, so > as far as the config is concerned it's 'Is Definitely Not Spam' and 'Is > Definitely Spam', additionally I have one running to allow certain > emails with forms through as well. If I look at the email in the > quarantine it shows a score of 5.00 and a matching rule of > 'FUZZY_OCR_KNOWN_HASH'. > > Cheers > > Jez > > > -----Original Message----- > From: Martin.Hepworth [mailto:martinh@solidstatelogic.com] > Sent: 22 August 2007 09:06 > To: MailScanner discussion > Subject: RE: Whitelists and Fuzzy > > Jez > > Which whitelist did you use - there are several? I wonder why FuzzyOCR > is triggering on this guys signature, a graphic signature (however > misguided) is quite common. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Jeramy Eling >> Sent: 22 August 2007 09:00 >> To: mailscanner@lists.mailscanner.info >> Subject: Whitelists and Fuzzy >> >> Hi All, >> >> I have an issue with my MailScanner setup blocking a particular email >> as the guy has a image as a signature, Fuzzy sees this and cranks the >> score up. I have the same problem with someone's sig that triggers on "cialis" even though the pic says "social services". On another occasion I reported a bug on the wiki and never got any feedback. I am thinking about dropping this plugin... Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x62252 F: 819.821.8045 From clacroix at cegep-ste-foy.qc.ca Wed Aug 22 14:15:59 2007 From: clacroix at cegep-ste-foy.qc.ca (Charles Lacroix) Date: Wed Aug 22 14:16:07 2007 Subject: Whitelists and Fuzzy In-Reply-To: <46CC305B.2060405@USherbrooke.ca> References: <5CD3BFF77DFFD411BCD100D0B720F94503C4E5E6@probe.britaxpmg.com> <46CC305B.2060405@USherbrooke.ca> Message-ID: <200708220915.59903.clacroix@cegep-ste-foy.qc.ca> On Wednesday 22 August 2007 08:47, Denis Beauchemin wrote: > Jeramy Eling a ?crit : > > Hi Martin > > > > A little bit of background, I have MailWatch running and I've got this > > integrated to do the White and Black listing from within Mailwatch, so > > as far as the config is concerned it's 'Is Definitely Not Spam' and 'Is > > Definitely Spam', additionally I have one running to allow certain > > emails with forms through as well. If I look at the email in the > > quarantine it shows a score of 5.00 and a matching rule of > > 'FUZZY_OCR_KNOWN_HASH'. > > > > Cheers > > > > Jez > > > > > > -----Original Message----- > > From: Martin.Hepworth [mailto:martinh@solidstatelogic.com] > > Sent: 22 August 2007 09:06 > > To: MailScanner discussion > > Subject: RE: Whitelists and Fuzzy > > > > Jez > > > > Which whitelist did you use - there are several? I wonder why FuzzyOCR > > is triggering on this guys signature, a graphic signature (however > > misguided) is quite common. > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > >> -----Original Message----- > >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > >> bounces@lists.mailscanner.info] On Behalf Of Jeramy Eling > >> Sent: 22 August 2007 09:00 > >> To: mailscanner@lists.mailscanner.info > >> Subject: Whitelists and Fuzzy > >> > >> Hi All, > >> > >> I have an issue with my MailScanner setup blocking a particular email > >> as the guy has a image as a signature, Fuzzy sees this and cranks the > >> score up. > > I have the same problem with someone's sig that triggers on "cialis" > even though the pic says "social services". On another occasion I > reported a bug on the wiki and never got any feedback. I am thinking > about dropping this plugin... > > Denis > > -- > _ > ?v? Denis Beauchemin, analyste > /(_)\ Universit? de Sherbrooke, S.T.I. > ^ ^ T: 819.821.8000x62252 F: 819.821.8045 I tried Fuzzy OCR for a while, and i had the same problem with images signatures. They trigger on pretty much anything in an unpredictable way :) -- Charles Lacroix, Administrateur UNIX. Service des t?l?communications et des technologies C?gep de Sainte-Foy (418) 659-6600 # 4266 From MailScanner at ecs.soton.ac.uk Wed Aug 22 14:18:14 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 22 14:18:38 2007 Subject: ClamAV & Sanesecurity & Spamassassin In-Reply-To: <000e01c7e4ba$94ad3de0$be07b9a0$@com> References: <5CD3BFF77DFFD411BCD100D0B720F945047588D2@probe.britaxpmg.com> <000e01c7e4ba$94ad3de0$be07b9a0$@com> Message-ID: <46CC3796.8090201@ecs.soton.ac.uk> The problem is that SpamAssassin doesn't call ClamAV, for which their signatures are designed. So it can't be done as far as I can see, sorry. Ryan Weaver wrote: > Hi, > > I've looked around but have not been able to find an answer sufficient for > me to implement. > > Is it possible to use the Sanesecurity definitions for ClamAV only via the > Spamassassin plugin (i.e. use normal ClamAV Virus definitions for the virus > scan, then use only the Sanesecurity definitions with the Spamassassin > plugin)? > > I ask this because I am using the Vispan setup to auto block persistent > virus / spam sources, however the Sanesecurity definitions make the initial > virus scan return the phishing/spam as a virus hit. This is not completely > bad because they are getting caught and blocked, but it would be more > sanitary for them to be marked as spam instead of virus. > > Thanks, > Ryan > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From list-mailscanner at linguaphone.com Wed Aug 22 14:36:36 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 22 14:36:47 2007 Subject: ClamAV & Sanesecurity & Spamassassin In-Reply-To: <000e01c7e4ba$94ad3de0$be07b9a0$@com> References: <5CD3BFF77DFFD411BCD100D0B720F945047588D2@probe.britaxpmg.com> <000e01c7e4ba$94ad3de0$be07b9a0$@com> Message-ID: <1187789796.19248.32.camel@gblades-suse.linguaphone-intranet.co.uk> It should be possible. You would need to somehow stop the clamav that mailscanner runs from using the sanesecurity signatures. Then you could configure http://wiki.apache.org/spamassassin/ClamAVPlugin with spamassassin. On Wed, 2007-08-22 at 13:47, Ryan Weaver wrote: > Hi, > > I've looked around but have not been able to find an answer sufficient for > me to implement. > > Is it possible to use the Sanesecurity definitions for ClamAV only via the > Spamassassin plugin (i.e. use normal ClamAV Virus definitions for the virus > scan, then use only the Sanesecurity definitions with the Spamassassin > plugin)? > > I ask this because I am using the Vispan setup to auto block persistent > virus / spam sources, however the Sanesecurity definitions make the initial > virus scan return the phishing/spam as a virus hit. This is not completely > bad because they are getting caught and blocked, but it would be more > sanitary for them to be marked as spam instead of virus. > > Thanks, > Ryan From john at tradoc.fr Wed Aug 22 14:54:36 2007 From: john at tradoc.fr (John Wilcock) Date: Wed Aug 22 14:54:44 2007 Subject: ClamAV & Sanesecurity & Spamassassin In-Reply-To: <46CC3796.8090201@ecs.soton.ac.uk> References: <5CD3BFF77DFFD411BCD100D0B720F945047588D2@probe.britaxpmg.com> <000e01c7e4ba$94ad3de0$be07b9a0$@com> <46CC3796.8090201@ecs.soton.ac.uk> Message-ID: <46CC401C.7000108@tradoc.fr> Julian Field wrote: > The problem is that SpamAssassin doesn't call ClamAV, for which their > signatures are designed. So it can't be done as far as I can see, sorry. I suspect Ryan was thinking of using http://wiki.apache.org/spamassassin/ClamAVPlugin to achieve his suggestion. John. -- -- Over 3000 webcams from ski resorts around the world - www.snoweye.com -- Translate your technical documents and web pages - www.tradoc.fr From MailScanner at ecs.soton.ac.uk Wed Aug 22 14:58:58 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 22 14:59:13 2007 Subject: ClamAV & Sanesecurity & Spamassassin In-Reply-To: <1187789796.19248.32.camel@gblades-suse.linguaphone-intranet.co.uk> References: <5CD3BFF77DFFD411BCD100D0B720F945047588D2@probe.britaxpmg.com> <000e01c7e4ba$94ad3de0$be07b9a0$@com> <1187789796.19248.32.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <46CC4122.2000306@ecs.soton.ac.uk> Didn't realise you could do this. I don't know of any command-line switches for ClamAV that tell it what signature databases to use, but what do I know :-) Gareth wrote: > It should be possible. You would need to somehow stop the clamav that > mailscanner runs from using the sanesecurity signatures. > > Then you could configure > http://wiki.apache.org/spamassassin/ClamAVPlugin with spamassassin. > > On Wed, 2007-08-22 at 13:47, Ryan Weaver wrote: > >> Hi, >> >> I've looked around but have not been able to find an answer sufficient for >> me to implement. >> >> Is it possible to use the Sanesecurity definitions for ClamAV only via the >> Spamassassin plugin (i.e. use normal ClamAV Virus definitions for the virus >> scan, then use only the Sanesecurity definitions with the Spamassassin >> plugin)? >> >> I ask this because I am using the Vispan setup to auto block persistent >> virus / spam sources, however the Sanesecurity definitions make the initial >> virus scan return the phishing/spam as a virus hit. This is not completely >> bad because they are getting caught and blocked, but it would be more >> sanitary for them to be marked as spam instead of virus. >> >> Thanks, >> Ryan >> > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From list-mailscanner at linguaphone.com Wed Aug 22 15:16:11 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 22 15:16:20 2007 Subject: ClamAV & Sanesecurity & Spamassassin In-Reply-To: <46CC4122.2000306@ecs.soton.ac.uk> References: <5CD3BFF77DFFD411BCD100D0B720F945047588D2@probe.britaxpmg.com> <000e01c7e4ba$94ad3de0$be07b9a0$@com> <1187789796.19248.32.camel@gblades-suse.linguaphone-intranet.co.uk> <46CC4122.2000306@ecs.soton.ac.uk> Message-ID: <1187792171.19250.40.camel@gblades-suse.linguaphone-intranet.co.uk> No I was thinking you might have to have two copies of clamav installed with one of them compiled to store its signatures in a different location. You could symlink the main signatures so both installs can see them and mailscanners update works correctly. You could have mailscanner use clamavmodule as it will have most issues with paths etc... You could have clamd started from the 2nd copy which can also see the sanesecurity signatures. The spamassassin plugin looks like it uses a tcpip socket to clamd so it should not be too bad keeping them both separate. On Wed, 2007-08-22 at 14:58, Julian Field wrote: > Didn't realise you could do this. > I don't know of any command-line switches for ClamAV that tell it what > signature databases to use, but what do I know :-) > > Gareth wrote: > > It should be possible. You would need to somehow stop the clamav that > > mailscanner runs from using the sanesecurity signatures. > > > > Then you could configure > > http://wiki.apache.org/spamassassin/ClamAVPlugin with spamassassin. > > > > On Wed, 2007-08-22 at 13:47, Ryan Weaver wrote: > > > >> Hi, > >> > >> I've looked around but have not been able to find an answer sufficient for > >> me to implement. > >> > >> Is it possible to use the Sanesecurity definitions for ClamAV only via the > >> Spamassassin plugin (i.e. use normal ClamAV Virus definitions for the virus > >> scan, then use only the Sanesecurity definitions with the Spamassassin > >> plugin)? > >> > >> I ask this because I am using the Vispan setup to auto block persistent > >> virus / spam sources, however the Sanesecurity definitions make the initial > >> virus scan return the phishing/spam as a virus hit. This is not completely > >> bad because they are getting caught and blocked, but it would be more > >> sanitary for them to be marked as spam instead of virus. > >> > >> Thanks, > >> Ryan > >> > > > > > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > Need help customising MailScanner? > Contact me! > Need help fixing or optimising your systems? > Contact me! > Need help getting you started solving new requirements from your boss? > Contact me! > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk From maillists at conactive.com Wed Aug 22 15:22:15 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Wed Aug 22 15:22:18 2007 Subject: Whitelists and Fuzzy In-Reply-To: <5CD3BFF77DFFD411BCD100D0B720F94503C4E5E8@probe.britaxpmg.com> References: <5CD3BFF77DFFD411BCD100D0B720F94503C4E5E8@probe.britaxpmg.com> Message-ID: Jeramy Eling wrote on Wed, 22 Aug 2007 13:44:29 +0100: > The Whitelist which is within the Mailwatch interface 'Is Definitely Not Spam'. I do not have such an option in my Mailwatch, I know only "Add to Whitelist". There are at least two different ways that this whitelisting is used. If you use the wrong one it's bound to fail, of course, as it won't match. Does your test message (the detected one) gets marked as W/L and green in Mailwatch? Does the same happen for your problem messages? A message that is detected by the MS whitelist will be green, marked as W/L and will not have any SA hits shown. As you see SA hits that means it is not on the MS whitelist, probably because it contains the wrong values for matching (see above). What value does Mailwatch show under Lists in Mailwatch when you whitelist that problem message? And is this a value that could match your problem messages? Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Wed Aug 22 15:22:15 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Wed Aug 22 15:22:22 2007 Subject: ClamAV & Sanesecurity & Spamassassin In-Reply-To: <000e01c7e4ba$94ad3de0$be07b9a0$@com> References: <5CD3BFF77DFFD411BCD100D0B720F945047588D2@probe.britaxpmg.com> <000e01c7e4ba$94ad3de0$be07b9a0$@com> Message-ID: Sigh. *Please*, do not create new messages to a list by hitting reply. If you want to post a question hit "New message" in your mail client. Thanks. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From Jeramy.Eling at britax-pmg.com Wed Aug 22 15:32:52 2007 From: Jeramy.Eling at britax-pmg.com (Jeramy Eling) Date: Wed Aug 22 15:32:54 2007 Subject: Whitelists and Fuzzy Message-ID: <5CD3BFF77DFFD411BCD100D0B720F945047588D5@probe.britaxpmg.com> The address was added to the whitelist via the 'Lists' link at the top of MailWatch, this updates the 'Is Definitly Not Spam' configuration within MailScanner, which in the config is set to an SQL function. The message does indeed come through as W/Listed and highlighted in Green on the display, however it has still been hit by the SA rules. Jez -----Original Message----- From: Kai Schaetzl [mailto:maillists@conactive.com] Sent: 22 August 2007 15:22 To: mailscanner@lists.mailscanner.info Subject: Re: Whitelists and Fuzzy Jeramy Eling wrote on Wed, 22 Aug 2007 13:44:29 +0100: > The Whitelist which is within the Mailwatch interface 'Is Definitely Not Spam'. I do not have such an option in my Mailwatch, I know only "Add to Whitelist". There are at least two different ways that this whitelisting is used. If you use the wrong one it's bound to fail, of course, as it won't match. Does your test message (the detected one) gets marked as W/L and green in Mailwatch? Does the same happen for your problem messages? A message that is detected by the MS whitelist will be green, marked as W/L and will not have any SA hits shown. As you see SA hits that means it is not on the MS whitelist, probably because it contains the wrong values for matching (see above). What value does Mailwatch show under Lists in Mailwatch when you whitelist that problem message? And is this a value that could match your problem messages? Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From list-mailscanner at linguaphone.com Wed Aug 22 15:38:20 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 22 15:38:28 2007 Subject: Whitelists and Fuzzy In-Reply-To: <5CD3BFF77DFFD411BCD100D0B720F945047588D5@probe.britaxpmg.com> References: <5CD3BFF77DFFD411BCD100D0B720F945047588D5@probe.britaxpmg.com> Message-ID: <1187793500.19246.46.camel@gblades-suse.linguaphone-intranet.co.uk> Yes spamassassin is still run against the rules so at least you can see what the score is. However if it is whitelisted then it is never classed as spam by mailscanner. On my mailscanner any whitelisted messages just shows 'whitelisted' where the spamassassin rules are normally listed so although I can see what the score was I cannot tell which specific rules were matched. Is that what you get? On Wed, 2007-08-22 at 15:32, Jeramy Eling wrote: > The address was added to the whitelist via the 'Lists' link at the top of MailWatch, this updates the 'Is Definitly Not Spam' configuration within MailScanner, which in the config is set to an SQL function. > > The message does indeed come through as W/Listed and highlighted in Green on the display, however it has still been hit by the SA rules. > > Jez > > -----Original Message----- > From: Kai Schaetzl [mailto:maillists@conactive.com] > Sent: 22 August 2007 15:22 > To: mailscanner@lists.mailscanner.info > Subject: Re: Whitelists and Fuzzy > > Jeramy Eling wrote on Wed, 22 Aug 2007 13:44:29 +0100: > > > The Whitelist which is within the Mailwatch interface 'Is Definitely Not Spam'. > > I do not have such an option in my Mailwatch, I know only "Add to Whitelist". > There are at least two different ways that this whitelisting is used. If you use the wrong one it's bound to fail, of course, as it won't match. > > Does your test message (the detected one) gets marked as W/L and green in Mailwatch? Does the same happen for your problem messages? A message that is detected by the MS whitelist will be green, marked as W/L and will not have any SA hits shown. As you see SA hits that means it is not on the MS whitelist, probably because it contains the wrong values for matching (see above). What value does Mailwatch show under Lists in Mailwatch when you whitelist that problem message? And is this a value that could match your problem messages? > > Kai > > -- > Kai Sch?tzl, Berlin, Germany > Get your web at Conactive Internet Services: http://www.conactive.com > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From ryanw at falsehope.com Wed Aug 22 15:43:47 2007 From: ryanw at falsehope.com (Ryan Weaver) Date: Wed Aug 22 15:43:55 2007 Subject: ClamAV & Sanesecurity & Spamassassin In-Reply-To: References: <5CD3BFF77DFFD411BCD100D0B720F945047588D2@probe.britaxpmg.com> <000e01c7e4ba$94ad3de0$be07b9a0$@com> Message-ID: <001401c7e4ca$d970bf00$8c523d00$@com> Since you've given no reasons I assume this would be because your personal preference is to view your e-mail in threads and the 'reply' inserts this topic as a take-over into your thread based viewing system. Sorry, I didn't think about that, my bad... Thanks, Ryan -----Original Message----- From: On Behalf Of Kai Schaetzl Sigh. *Please*, do not create new messages to a list by hitting reply. If you want to post a question hit "New message" in your mail client. Thanks. Kai From Jeramy.Eling at britax-pmg.com Wed Aug 22 15:46:24 2007 From: Jeramy.Eling at britax-pmg.com (Jeramy Eling) Date: Wed Aug 22 15:46:26 2007 Subject: Whitelists and Fuzzy Message-ID: <5CD3BFF77DFFD411BCD100D0B720F945047588D6@probe.britaxpmg.com> I've just checked and it would appear to be my inability to read the screen ;) It seems that the test email with image attached is whitelisted, however it's been blocked as it's a BMP and MailScanner stops those to prevent possible buffer overflows. DOH!!! Sorry for going round and round on this one. Thanks all for your help Cheers Jez -----Original Message----- From: Gareth [mailto:list-mailscanner@linguaphone.com] Sent: 22 August 2007 15:38 To: MailScanner discussion Subject: RE: Whitelists and Fuzzy Yes spamassassin is still run against the rules so at least you can see what the score is. However if it is whitelisted then it is never classed as spam by mailscanner. On my mailscanner any whitelisted messages just shows 'whitelisted' where the spamassassin rules are normally listed so although I can see what the score was I cannot tell which specific rules were matched. Is that what you get? On Wed, 2007-08-22 at 15:32, Jeramy Eling wrote: > The address was added to the whitelist via the 'Lists' link at the top of MailWatch, this updates the 'Is Definitly Not Spam' configuration within MailScanner, which in the config is set to an SQL function. > > The message does indeed come through as W/Listed and highlighted in Green on the display, however it has still been hit by the SA rules. > > Jez > > -----Original Message----- > From: Kai Schaetzl [mailto:maillists@conactive.com] > Sent: 22 August 2007 15:22 > To: mailscanner@lists.mailscanner.info > Subject: Re: Whitelists and Fuzzy > > Jeramy Eling wrote on Wed, 22 Aug 2007 13:44:29 +0100: > > > The Whitelist which is within the Mailwatch interface 'Is Definitely Not Spam'. > > I do not have such an option in my Mailwatch, I know only "Add to Whitelist". > There are at least two different ways that this whitelisting is used. If you use the wrong one it's bound to fail, of course, as it won't match. > > Does your test message (the detected one) gets marked as W/L and green in Mailwatch? Does the same happen for your problem messages? A message that is detected by the MS whitelist will be green, marked as W/L and will not have any SA hits shown. As you see SA hits that means it is not on the MS whitelist, probably because it contains the wrong values for matching (see above). What value does Mailwatch show under Lists in Mailwatch when you whitelist that problem message? And is this a value that could match your problem messages? > > Kai > > -- > Kai Sch?tzl, Berlin, Germany > Get your web at Conactive Internet Services: http://www.conactive.com > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From martinh at solidstatelogic.com Wed Aug 22 15:53:56 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed Aug 22 15:54:02 2007 Subject: Whitelists and Fuzzy In-Reply-To: <5CD3BFF77DFFD411BCD100D0B720F945047588D6@probe.britaxpmg.com> Message-ID: <703a19a9f4570747aa0d6f7eb7a9b3cd@solidstatelogic.com> Jez Must have old version of maiLScanner - .bmp hasn't been blocked by default for a while -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Jeramy Eling > Sent: 22 August 2007 15:46 > To: MailScanner discussion > Subject: RE: Whitelists and Fuzzy > > I've just checked and it would appear to be my inability to read the > screen ;) It seems that the test email with image attached is whitelisted, > however it's been blocked as it's a BMP and MailScanner stops those to > prevent possible buffer overflows. DOH!!! > > Sorry for going round and round on this one. > > Thanks all for your help > > Cheers > > Jez > > > > -----Original Message----- > From: Gareth [mailto:list-mailscanner@linguaphone.com] > Sent: 22 August 2007 15:38 > To: MailScanner discussion > Subject: RE: Whitelists and Fuzzy > > Yes spamassassin is still run against the rules so at least you can see > what the score is. However if it is whitelisted then it is never classed > as spam by mailscanner. On my mailscanner any whitelisted messages just > shows 'whitelisted' where the spamassassin rules are normally listed so > although I can see what the score was I cannot tell which specific rules > were matched. > > Is that what you get? > > > On Wed, 2007-08-22 at 15:32, Jeramy Eling wrote: > > The address was added to the whitelist via the 'Lists' link at the top > of MailWatch, this updates the 'Is Definitly Not Spam' configuration > within MailScanner, which in the config is set to an SQL function. > > > > The message does indeed come through as W/Listed and highlighted in > Green on the display, however it has still been hit by the SA rules. > > > > Jez > > > > -----Original Message----- > > From: Kai Schaetzl [mailto:maillists@conactive.com] > > Sent: 22 August 2007 15:22 > > To: mailscanner@lists.mailscanner.info > > Subject: Re: Whitelists and Fuzzy > > > > Jeramy Eling wrote on Wed, 22 Aug 2007 13:44:29 +0100: > > > > > The Whitelist which is within the Mailwatch interface 'Is Definitely > Not Spam'. > > > > I do not have such an option in my Mailwatch, I know only "Add to > Whitelist". > > There are at least two different ways that this whitelisting is used. If > you use the wrong one it's bound to fail, of course, as it won't match. > > > > Does your test message (the detected one) gets marked as W/L and green > in Mailwatch? Does the same happen for your problem messages? A message > that is detected by the MS whitelist will be green, marked as W/L and will > not have any SA hits shown. As you see SA hits that means it is not on the > MS whitelist, probably because it contains the wrong values for matching > (see above). What value does Mailwatch show under Lists in Mailwatch when > you whitelist that problem message? And is this a value that could match > your problem messages? > > > > Kai > > > > -- > > Kai Sch?tzl, Berlin, Germany > > Get your web at Conactive Internet Services: http://www.conactive.com > > > > > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From sandrews at andrewscompanies.com Wed Aug 22 16:09:25 2007 From: sandrews at andrewscompanies.com (Steven Andrews) Date: Wed Aug 22 16:09:31 2007 Subject: CRM114 Problem In-Reply-To: <50678FBB708A9B4FB6B536F6F657883D028E9530@exch-gman.ad.goodmanmfg.com> References: <224FA7E11EA39E45843E11CEBBD3A36F189A80@HOUPEX01.nfsmith.info><50678FBB708A9B4FB6B536F6F657883D028E9528@exch-gman.ad.goodmanmfg.com><1964AAFBC212F742958F9275BF63DBB05B3D63@winchester.andrewscompanies.com> <50678FBB708A9B4FB6B536F6F657883D028E9530@exch-gman.ad.goodmanmfg.com> Message-ID: <1964AAFBC212F742958F9275BF63DBB05B3D80@winchester.andrewscompanies.com> I think I'm going to have to give up and rebuild my box...even this didn't fix mine. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Horton, Robert Sent: Tuesday, August 21, 2007 3:34 PM To: MailScanner discussion Subject: RE: CRM114 Problem I didn't use the RPMs and made up my own method. I'm using RHEL 5 to test CRM right now. My install was based off the wiki and the emails in this list. I downloaded http://crm114.sourceforge.net/tarballs/crm114-20070428-BlameSpamConf.src.tar.gz and http://laurikari.net/tre/tre-0.7.5.tar.gz And ran the following commands: tar -zxvf tre-0.7.5.tar.gz cd tre-0.7.5 ./configure --enable-static make make check make install cd .. tar -zxvf crm114-20070428-BlameSpamConf.src.tar.gz cd crm114-20070428-BlameSpamConf.src make make megatest make install cd .. Then I created the /etc/mail/spamassassin/crm114 and grabbed the 2 files from Martin Sch?tte. When creating the crm114 directory I grabbed files from the downloaded crm114-20070428-BlameSpamConf.src directory. The resulting crm114 directory contained the following before startup. -rw-r--r-- 1 root root 0 Aug 20 22:03 blacklist.mfp -rwxr-xr-x 1 root root 17426 Aug 20 22:36 mailfilter.cf -rwxr-xr-x 1 root root 44537 Aug 20 22:02 mailfilter.crm -rwxr-xr-x 1 root root 14511 Aug 20 22:02 maillib.crm -rwxr-xr-x 1 root root 22677 Aug 20 22:02 mailreaver.crm -rwxr-xr-x 1 root root 37621 Aug 20 22:02 mailtrainer.crm -rw-r--r-- 1 root root 12582924 Aug 20 21:59 nonspam.css -rw-r--r-- 1 root root 49 Aug 20 22:03 priolist.mfp -rw-r--r-- 1 root root 0 Aug 20 22:03 rewrites.mfp -rwxr-xr-x 1 root root 6924 Aug 21 14:03 shuffle.crm -rw-r--r-- 1 root root 12582924 Aug 20 21:59 spam.css -rw-r--r-- 1 root root 0 Aug 20 22:03 whitelist.mfp One thing to note is I included shuffle.crm because it was referenced in the cf files. I don't know if it matters or if it's different in the RPM versions. I modified the .cf files as the wiki said. When you first do the lint test you will get the 0.00 score because the nonspam.css and spam.css are new. It stays this way until you start learning which was the original problem for me since the messages were not being learned. -Robert -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Steven Andrews Sent: Tuesday, August 21, 2007 12:15 PM To: MailScanner discussion Subject: RE: CRM114 Problem Got the updated files from mschuette.name according to the wiki and it is incremented for your changes; unfortunately, it didn't fix for me. Should I be using a different version than the 20073001 rpm? -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Horton, Robert Sent: Tuesday, August 21, 2007 2:14 AM To: MailScanner discussion Subject: RE: CRM114 Problem Are you still having problems with the score at -0.00? I finally installed this evening and had the same problem. I think there is a bug in the crm114.pm (Version: 0.6.4), but what perplexes me is why some people claim its working...the lines I changed should affect everyone. Maybe this code was changed recently. I changed the following 2 lines in the sub call_crm dbg("crm114: opening pipe: $crm114_command < $tmpf"); $pid = Mail::SpamAssassin::Util::helper_app_pipe_open( *CRM_OUT, $tmpf, 1, $crm114_command); to dbg("crm114: opening pipe: $crm114_cmdline < $tmpf"); $pid = Mail::SpamAssassin::Util::helper_app_pipe_open( *CRM_OUT, $tmpf, 1, $crm114_cmdline); Within minutes crm114 started learning emails and no longer had the -0.00 score. You only get this score when you have an empty spam.css and nonspam.css and it doesn't know what to do with the email yet. Hope this helps, Robert Horton -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Mike Kercher Sent: Friday, August 10, 2007 11:13 AM To: MailScanner discussion Subject: CRM114 Problem I added CRM114 to a server last week per the docs in the wiki (and like I've done on several other servers), but the score is always -0.00 [root@mail crm114]# cssutil -b -r spam.css Sparse spectra file spam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 15495 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 [root@mail crm114]# cssutil -b -r nonspam.css Sparse spectra file nonspam.css statistics: Total available buckets : 1048577 Total buckets in use : 0 Total in-use zero-count buckets : 0 Total buckets with value >= max : 0 Total hashed datums in file : 0 Documents learned : 15495 Features learned : 1 Average datums per bucket : 0.00 Maximum length of overflow chain : 0 Average length of overflow chain : 0.00 Average packing density : 0.00 The Features learned hasn't changed in many days. Permissions look good, .crm's are +x Any suggestions where to look? Mike -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! CONFIDENTIALITY NOTE: The information contained in this transmission is privileged and confidential information intended only for the use of the individual or entity named above. If the reader of this message is not the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this transmission in error, do not read it. Please immediately reply to the sender that you have received this communication in error and then delete it. Thank you. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! CONFIDENTIALITY NOTE: The information contained in this transmission is privileged and confidential information intended only for the use of the individual or entity named above. If the reader of this message is not the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this transmission in error, do not read it. Please immediately reply to the sender that you have received this communication in error and then delete it. Thank you. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From Denis.Beauchemin at USherbrooke.ca Wed Aug 22 16:41:00 2007 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Wed Aug 22 16:41:53 2007 Subject: Full message scan oddity Message-ID: <46CC590C.9020403@USherbrooke.ca> Hello, I just upgraded 2 MS servers to the latest stable and enabled the following option: ClamAV Full Message Scan = yes I sent a virus-infected email and noticed the following: Aug 22 11:16:59 smtpe4 MailScanner[21708]: l7MFGi0o022717/01_05_2005.txt:infected: Win32.Bagle.BO@mm Aug 22 11:17:00 smtpe4 MailScanner[21708]: ClamAV Module::INFECTED:: Worm.Bagle.DK:: ./l7MFGi0o022717/ Aug 22 11:17:00 smtpe4 MailScanner[21708]: ClamAV Module::INFECTED:: Worm.Bagle.DK:: ./l7MFGi0o022717/01_05_2005.txt Aug 22 11:17:00 smtpe4 MailScanner[21708]: /l7MFGi0o022717.message/00000350.EML/01_05_2005.txt contient le virus W32/Bagle.dldr.gen !!! Aug 22 11:17:00 smtpe4 MailScanner[21708]: /l7MFGi0o022717/01_05_2005.txt contient le virus W32/Bagle.dldr.gen !!! On a different server without this new feature, I get: Aug 22 11:34:31 132.210.244.93 MailScanner[4049]: /l7MFXTYu031455/01_05_2005.txt contient le virus W32/Bagle.dldr.gen !!! Aug 22 11:34:41 132.210.244.93 MailScanner[4049]: l7MFXTYu031455/01_05_2005.txt:infected: Win32.Bagle.BO@mm Aug 22 11:34:41 132.210.244.93 MailScanner[4049]: ClamAVModule::INFECTED:: Worm.Bagle.DK:: ./l7MFXTYu031455/01_05_2005.txt I now get 2 hits from McAfee and ClamAV, but only 1 from Bitdefender... is there a way to pass only the full message to the AV scanners? That way we would get only 1 warning and the server would also be working less. Thanks! Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x62252 F: 819.821.8045 -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3595 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070822/7baa5548/smime.bin From MailScanner at ecs.soton.ac.uk Wed Aug 22 17:14:45 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 22 17:15:00 2007 Subject: Full message scan oddity In-Reply-To: <46CC590C.9020403@USherbrooke.ca> References: <46CC590C.9020403@USherbrooke.ca> Message-ID: <46CC60F5.9010101@ecs.soton.ac.uk> Denis Beauchemin wrote: > Hello, > > I just upgraded 2 MS servers to the latest stable and enabled the > following option: > ClamAV Full Message Scan = yes > > I sent a virus-infected email and noticed the following: > Aug 22 11:16:59 smtpe4 MailScanner[21708]: > l7MFGi0o022717/01_05_2005.txt:infected: Win32.Bagle.BO@mm > Aug 22 11:17:00 smtpe4 MailScanner[21708]: ClamAV Module::INFECTED:: > Worm.Bagle.DK:: ./l7MFGi0o022717/ > Aug 22 11:17:00 smtpe4 MailScanner[21708]: ClamAV Module::INFECTED:: > Worm.Bagle.DK:: ./l7MFGi0o022717/01_05_2005.txt > Aug 22 11:17:00 smtpe4 MailScanner[21708]: > /l7MFGi0o022717.message/00000350.EML/01_05_2005.txt contient le > virus W32/Bagle.dldr.gen !!! > Aug 22 11:17:00 smtpe4 MailScanner[21708]: > /l7MFGi0o022717/01_05_2005.txt contient le virus > W32/Bagle.dldr.gen !!! > > On a different server without this new feature, I get: > Aug 22 11:34:31 132.210.244.93 MailScanner[4049]: > /l7MFXTYu031455/01_05_2005.txt contient le virus > W32/Bagle.dldr.gen !!! > Aug 22 11:34:41 132.210.244.93 MailScanner[4049]: > l7MFXTYu031455/01_05_2005.txt:infected: Win32.Bagle.BO@mm > Aug 22 11:34:41 132.210.244.93 MailScanner[4049]: > ClamAVModule::INFECTED:: Worm.Bagle.DK:: ./l7MFXTYu031455/01_05_2005.txt > > I now get 2 hits from McAfee and ClamAV, but only 1 from > Bitdefender... is there a way to pass only the full message to the AV > scanners? That way we would get only 1 warning and the server would > also be working less. I could add a feature to do that, but it sounds a very dangerous thing to do. You are relying on your virus scanners' ability to unpack attachments on its own. As a fraction of the whole process for each message, scanning the attachments as well as the full message is only a tiny part of the time involved. I really wouldn't advise setting up MailScanner to _not_ scan the attachments. Only a few virus scanners can do this anyway. I'm really not keen on adding this feature, it's one which hardly anyone would use and it potentially exposes you to viruses with most virus scanners. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From maillists at conactive.com Wed Aug 22 17:31:21 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Wed Aug 22 17:31:26 2007 Subject: Whitelists and Fuzzy In-Reply-To: <1187793500.19246.46.camel@gblades-suse.linguaphone-intranet.co.uk> References: <5CD3BFF77DFFD411BCD100D0B720F945047588D5@probe.britaxpmg.com> <1187793500.19246.46.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: Gareth wrote on Wed, 22 Aug 2007 15:38:20 +0100: > Yes spamassassin is still run against the rules so at least you can see > what the score is. However if it is whitelisted then it is never classed > as spam by mailscanner. On my mailscanner any whitelisted messages just > shows 'whitelisted' where the spamassassin rules are normally listed so > although I can see what the score was I cannot tell which specific rules > were matched. That is not what I see here for whitelisted messages. The spam score shows as 0.0 and no rules are shown. Is that what you describe new to MS or new to MW? Of course, it could be possible that there are really no hits at all, but I doubt that ... Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From list-mailscanner at linguaphone.com Wed Aug 22 17:48:51 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 22 17:48:54 2007 Subject: Whitelists and Fuzzy In-Reply-To: Message-ID: > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Kai > Schaetzl > Sent: 22 August 2007 17:31 > To: mailscanner@lists.mailscanner.info > Subject: Re: Whitelists and Fuzzy > > > Gareth wrote on Wed, 22 Aug 2007 15:38:20 +0100: > > > Yes spamassassin is still run against the rules so at least you can see > > what the score is. However if it is whitelisted then it is never classed > > as spam by mailscanner. On my mailscanner any whitelisted messages just > > shows 'whitelisted' where the spamassassin rules are normally listed so > > although I can see what the score was I cannot tell which specific rules > > were matched. > > That is not what I see here for whitelisted messages. The spam > score shows > as 0.0 and no rules are shown. Is that what you describe new to MS or new > to MW? Of course, it could be possible that there are really no hits at > all, but I doubt that ... > Mine shows 'whitelisted' where the rules are shown and a mostly non zero spam score. From MailScanner at ecs.soton.ac.uk Wed Aug 22 18:01:20 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 22 18:02:02 2007 Subject: Whitelists and Fuzzy In-Reply-To: References: Message-ID: <46CC6BE0.3030208@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 This depends on whether you have Always Include SpamAssassin Report or not. Setting that to yes will cause SpamAssassin to be done regardless of anything else, which is a bit of a waste of time and CPU. I always leave it set to no, as I better uses for the horsepower :-) Gareth wrote: >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Kai >> Schaetzl >> Sent: 22 August 2007 17:31 >> To: mailscanner@lists.mailscanner.info >> Subject: Re: Whitelists and Fuzzy >> >> >> Gareth wrote on Wed, 22 Aug 2007 15:38:20 +0100: >> >> >>> Yes spamassassin is still run against the rules so at least you can see >>> what the score is. However if it is whitelisted then it is never classed >>> as spam by mailscanner. On my mailscanner any whitelisted messages just >>> shows 'whitelisted' where the spamassassin rules are normally listed so >>> although I can see what the score was I cannot tell which specific rules >>> were matched. >>> >> That is not what I see here for whitelisted messages. The spam >> score shows >> as 0.0 and no rules are shown. Is that what you describe new to MS or new >> to MW? Of course, it could be possible that there are really no hits at >> all, but I doubt that ... >> >> > > Mine shows 'whitelisted' where the rules are shown and a mostly non zero > spam score. > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Charset: ISO-8859-1 wj8DBQFGzGvhEfZZRxQVtlQRAoleAKDY4UrmYrdxD8tGDqspoV790RszPQCfUbff O+knzWXjeGnTpF+zVHwlIK4= =xUdT -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From rcooper at dwford.com Wed Aug 22 18:05:21 2007 From: rcooper at dwford.com (Rick Cooper) Date: Wed Aug 22 18:05:27 2007 Subject: ClamAV & Sanesecurity & Spamassassin In-Reply-To: <1187792171.19250.40.camel@gblades-suse.linguaphone-intranet.co.uk> References: <5CD3BFF77DFFD411BCD100D0B720F945047588D2@probe.britaxpmg.com><000e01c7e4ba$94ad3de0$be07b9a0$@com><1187789796.19248.32.camel@gblades-suse.linguaphone-intranet.co.uk><46CC4122.2000306@ecs.soton.ac.uk> <1187792171.19250.40.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <005501c7e4de$a01a0180$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On > Behalf Of Gareth > Sent: Wednesday, August 22, 2007 10:16 AM > To: MailScanner discussion > Subject: Re: ClamAV & Sanesecurity & Spamassassin > > No I was thinking you might have to have two copies of > clamav installed > with one of them compiled to store its signatures in a different > location. > You could symlink the main signatures so both installs can > see them and > mailscanners update works correctly. You could have mailscanner use > clamavmodule as it will have most issues with paths etc... > You could have clamd started from the 2nd copy which can also see the > sanesecurity signatures. The spamassassin plugin looks like it uses a > tcpip socket to clamd so it should not be too bad keeping them both > separate. [...] You only need one clamav installation, you need to setup a special clam database (example: /opt/clamdSane) directory with symlinks to the db files you want to use with in the special clam db dir. MSRBL-Images.hdb -> /usr/local/share/clamav/MSRBL-Images.hdb MSRBL-SPAM.ndb -> /usr/local/share/clamav/MSRBL-SPAM.ndb phish.ndb -> /usr/local/share/clamav/phish.ndb scam.ndb -> /usr/local/share/clamav/scam.ndb Next create a new clamd.conf line clamdSane.conf and change the DatabaseDirectory, TCPSocket (say 3311), and PidFile settings to something other than the default like DatabaseDirectory /opt/SaneDataBase TCPSocket 3311 PidFile /var/run/clamdSane.pid Start your second daemon : clamd --config-file=/path/clamdSane.conf And change this line in clamAV.pm (the plugin) my $clamav = new File::Scan::ClamAV(port => 3310); To my $clamav = new File::Scan::ClamAV(port => 3311); Now clamd should only see the SaneSecurity sigs when processed via the SpamAssassin ClamAV plugin Set your rules as desired Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From maillists at conactive.com Wed Aug 22 18:31:24 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Wed Aug 22 18:31:27 2007 Subject: ClamAV & Sanesecurity & Spamassassin In-Reply-To: <001401c7e4ca$d970bf00$8c523d00$@com> References: <5CD3BFF77DFFD411BCD100D0B720F945047588D2@probe.britaxpmg.com> <000e01c7e4ba$94ad3de0$be07b9a0$@com> <001401c7e4ca$d970bf00$8c523d00$@com> Message-ID: Ryan Weaver wrote on Wed, 22 Aug 2007 09:43:47 -0500: > Since you've given no reasons I assume this would be because your personal > preference is to view your e-mail in threads It doesn't matter if this is my preference or not. The point is that "reply" adds specific threading information, so you keep going in that thread. Thanks. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From Denis.Beauchemin at USherbrooke.ca Wed Aug 22 18:35:54 2007 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Wed Aug 22 18:36:41 2007 Subject: Full message scan oddity In-Reply-To: <46CC60F5.9010101@ecs.soton.ac.uk> References: <46CC590C.9020403@USherbrooke.ca> <46CC60F5.9010101@ecs.soton.ac.uk> Message-ID: <46CC73FA.3030905@USherbrooke.ca> Julian Field a ?crit : > > > Denis Beauchemin wrote: >> Hello, >> >> I just upgraded 2 MS servers to the latest stable and enabled the >> following option: >> ClamAV Full Message Scan = yes >> >> I sent a virus-infected email and noticed the following: >> Aug 22 11:16:59 smtpe4 MailScanner[21708]: >> l7MFGi0o022717/01_05_2005.txt:infected: Win32.Bagle.BO@mm >> Aug 22 11:17:00 smtpe4 MailScanner[21708]: ClamAV Module::INFECTED:: >> Worm.Bagle.DK:: ./l7MFGi0o022717/ >> Aug 22 11:17:00 smtpe4 MailScanner[21708]: ClamAV Module::INFECTED:: >> Worm.Bagle.DK:: ./l7MFGi0o022717/01_05_2005.txt >> Aug 22 11:17:00 smtpe4 MailScanner[21708]: >> /l7MFGi0o022717.message/00000350.EML/01_05_2005.txt contient >> le virus W32/Bagle.dldr.gen !!! >> Aug 22 11:17:00 smtpe4 MailScanner[21708]: >> /l7MFGi0o022717/01_05_2005.txt contient le virus >> W32/Bagle.dldr.gen !!! >> >> On a different server without this new feature, I get: >> Aug 22 11:34:31 132.210.244.93 MailScanner[4049]: >> /l7MFXTYu031455/01_05_2005.txt contient le virus >> W32/Bagle.dldr.gen !!! >> Aug 22 11:34:41 132.210.244.93 MailScanner[4049]: >> l7MFXTYu031455/01_05_2005.txt:infected: Win32.Bagle.BO@mm >> Aug 22 11:34:41 132.210.244.93 MailScanner[4049]: >> ClamAVModule::INFECTED:: Worm.Bagle.DK:: ./l7MFXTYu031455/01_05_2005.txt >> >> I now get 2 hits from McAfee and ClamAV, but only 1 from >> Bitdefender... is there a way to pass only the full message to the >> AV scanners? That way we would get only 1 warning and the server >> would also be working less. > I could add a feature to do that, but it sounds a very dangerous thing > to do. You are relying on your virus scanners' ability to unpack > attachments on its own. As a fraction of the whole process for each > message, scanning the attachments as well as the full message is only > a tiny part of the time involved. I really wouldn't advise setting up > MailScanner to _not_ scan the attachments. Only a few virus scanners > can do this anyway. > > I'm really not keen on adding this feature, it's one which hardly > anyone would use and it potentially exposes you to viruses with most > virus scanners. > > Jules > Julian, It makes perfect sense. I guess I will have to live with not so accurate virus statistics... Thanks again! Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x62252 F: 819.821.8045 From list-mailscanner at linguaphone.com Wed Aug 22 18:50:16 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 22 18:50:24 2007 Subject: Full message scan oddity In-Reply-To: <46CC73FA.3030905@USherbrooke.ca> Message-ID: > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Denis > Beauchemin > Sent: 22 August 2007 18:36 > To: MailScanner discussion > Subject: Re: Full message scan oddity > > > Julian Field a ?crit : > > > > > > Denis Beauchemin wrote: > >> Hello, > >> > >> I just upgraded 2 MS servers to the latest stable and enabled the > >> following option: > >> ClamAV Full Message Scan = yes > >> > >> I sent a virus-infected email and noticed the following: > >> Aug 22 11:16:59 smtpe4 MailScanner[21708]: > >> l7MFGi0o022717/01_05_2005.txt:infected: Win32.Bagle.BO@mm > >> Aug 22 11:17:00 smtpe4 MailScanner[21708]: ClamAV Module::INFECTED:: > >> Worm.Bagle.DK:: ./l7MFGi0o022717/ > >> Aug 22 11:17:00 smtpe4 MailScanner[21708]: ClamAV Module::INFECTED:: > >> Worm.Bagle.DK:: ./l7MFGi0o022717/01_05_2005.txt > >> Aug 22 11:17:00 smtpe4 MailScanner[21708]: > >> /l7MFGi0o022717.message/00000350.EML/01_05_2005.txt contient > >> le virus W32/Bagle.dldr.gen !!! > >> Aug 22 11:17:00 smtpe4 MailScanner[21708]: > >> /l7MFGi0o022717/01_05_2005.txt contient le virus > >> W32/Bagle.dldr.gen !!! > >> > >> On a different server without this new feature, I get: > >> Aug 22 11:34:31 132.210.244.93 MailScanner[4049]: > >> /l7MFXTYu031455/01_05_2005.txt contient le virus > >> W32/Bagle.dldr.gen !!! > >> Aug 22 11:34:41 132.210.244.93 MailScanner[4049]: > >> l7MFXTYu031455/01_05_2005.txt:infected: Win32.Bagle.BO@mm > >> Aug 22 11:34:41 132.210.244.93 MailScanner[4049]: > >> ClamAVModule::INFECTED:: Worm.Bagle.DK:: > ./l7MFXTYu031455/01_05_2005.txt > >> > >> I now get 2 hits from McAfee and ClamAV, but only 1 from > >> Bitdefender... is there a way to pass only the full message to the > >> AV scanners? That way we would get only 1 warning and the server > >> would also be working less. > > I could add a feature to do that, but it sounds a very dangerous thing > > to do. You are relying on your virus scanners' ability to unpack > > attachments on its own. As a fraction of the whole process for each > > message, scanning the attachments as well as the full message is only > > a tiny part of the time involved. I really wouldn't advise setting up > > MailScanner to _not_ scan the attachments. Only a few virus scanners > > can do this anyway. > > > > I'm really not keen on adding this feature, it's one which hardly > > anyone would use and it potentially exposes you to viruses with most > > virus scanners. > > > > Jules > > > Julian, > > It makes perfect sense. I guess I will have to live with not so > accurate virus statistics... > > Thanks again! > > Denis In my opinion you certenly dont want to stop scanning the attachments. The only thing you could do is not report the fact that the virus scanner found a virus in the email if it found something in the attachment. From Denis.Beauchemin at USherbrooke.ca Wed Aug 22 19:03:05 2007 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Wed Aug 22 19:03:22 2007 Subject: Full message scan oddity In-Reply-To: References: Message-ID: <46CC7A59.1080102@USherbrooke.ca> Gareth a ?crit : >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Denis >> Beauchemin >> Sent: 22 August 2007 18:36 >> To: MailScanner discussion >> Subject: Re: Full message scan oddity >> >> >> Julian Field a ?crit : >> >>> Denis Beauchemin wrote: >>> >>>> Hello, >>>> >>>> I just upgraded 2 MS servers to the latest stable and enabled the >>>> following option: >>>> ClamAV Full Message Scan = yes >>>> >>>> I sent a virus-infected email and noticed the following: >>>> Aug 22 11:16:59 smtpe4 MailScanner[21708]: >>>> l7MFGi0o022717/01_05_2005.txt:infected: Win32.Bagle.BO@mm >>>> Aug 22 11:17:00 smtpe4 MailScanner[21708]: ClamAV Module::INFECTED:: >>>> Worm.Bagle.DK:: ./l7MFGi0o022717/ >>>> Aug 22 11:17:00 smtpe4 MailScanner[21708]: ClamAV Module::INFECTED:: >>>> Worm.Bagle.DK:: ./l7MFGi0o022717/01_05_2005.txt >>>> Aug 22 11:17:00 smtpe4 MailScanner[21708]: >>>> /l7MFGi0o022717.message/00000350.EML/01_05_2005.txt contient >>>> le virus W32/Bagle.dldr.gen !!! >>>> Aug 22 11:17:00 smtpe4 MailScanner[21708]: >>>> /l7MFGi0o022717/01_05_2005.txt contient le virus >>>> W32/Bagle.dldr.gen !!! >>>> >>>> On a different server without this new feature, I get: >>>> Aug 22 11:34:31 132.210.244.93 MailScanner[4049]: >>>> /l7MFXTYu031455/01_05_2005.txt contient le virus >>>> W32/Bagle.dldr.gen !!! >>>> Aug 22 11:34:41 132.210.244.93 MailScanner[4049]: >>>> l7MFXTYu031455/01_05_2005.txt:infected: Win32.Bagle.BO@mm >>>> Aug 22 11:34:41 132.210.244.93 MailScanner[4049]: >>>> ClamAVModule::INFECTED:: Worm.Bagle.DK:: >>>> >> ./l7MFXTYu031455/01_05_2005.txt >> >>>> I now get 2 hits from McAfee and ClamAV, but only 1 from >>>> Bitdefender... is there a way to pass only the full message to the >>>> AV scanners? That way we would get only 1 warning and the server >>>> would also be working less. >>>> >>> I could add a feature to do that, but it sounds a very dangerous thing >>> to do. You are relying on your virus scanners' ability to unpack >>> attachments on its own. As a fraction of the whole process for each >>> message, scanning the attachments as well as the full message is only >>> a tiny part of the time involved. I really wouldn't advise setting up >>> MailScanner to _not_ scan the attachments. Only a few virus scanners >>> can do this anyway. >>> >>> I'm really not keen on adding this feature, it's one which hardly >>> anyone would use and it potentially exposes you to viruses with most >>> virus scanners. >>> >>> Jules >>> >>> >> Julian, >> >> It makes perfect sense. I guess I will have to live with not so >> accurate virus statistics... >> >> Thanks again! >> >> Denis >> > > In my opinion you certenly dont want to stop scanning the attachments. The only thing you could do is not report the fact that the virus scanner found a virus in the email if it found something in the attachment. > > Gareth, No, I don't want to stop scanning some content. That's why I will have to live with inaccurate virus statistics (since some virus will be detected twice by ClamAV and McAfee). Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x62252 F: 819.821.8045 -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3595 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070822/8c8ba98e/smime.bin From MailScanner at ecs.soton.ac.uk Wed Aug 22 19:50:03 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 22 19:50:47 2007 Subject: Full message scan oddity In-Reply-To: <46CC7A59.1080102@USherbrooke.ca> References: <46CC7A59.1080102@USherbrooke.ca> Message-ID: <46CC855B.1050702@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Denis Beauchemin wrote: > Gareth a ?crit : >>> -----Original Message----- >>> From: mailscanner-bounces@lists.mailscanner.info >>> [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Denis >>> Beauchemin >>> Sent: 22 August 2007 18:36 >>> To: MailScanner discussion >>> Subject: Re: Full message scan oddity >>> >>> >>> Julian Field a ?crit : >>> >>>> Denis Beauchemin wrote: >>>> >>>>> Hello, >>>>> >>>>> I just upgraded 2 MS servers to the latest stable and enabled the >>>>> following option: >>>>> ClamAV Full Message Scan = yes >>>>> >>>>> I sent a virus-infected email and noticed the following: >>>>> Aug 22 11:16:59 smtpe4 MailScanner[21708]: >>>>> l7MFGi0o022717/01_05_2005.txt:infected: Win32.Bagle.BO@mm >>>>> Aug 22 11:17:00 smtpe4 MailScanner[21708]: ClamAV >>>>> Module::INFECTED:: Worm.Bagle.DK:: ./l7MFGi0o022717/ >>>>> Aug 22 11:17:00 smtpe4 MailScanner[21708]: ClamAV >>>>> Module::INFECTED:: Worm.Bagle.DK:: ./l7MFGi0o022717/01_05_2005.txt >>>>> Aug 22 11:17:00 smtpe4 MailScanner[21708]: >>>>> /l7MFGi0o022717.message/00000350.EML/01_05_2005.txt >>>>> contient le virus W32/Bagle.dldr.gen !!! >>>>> Aug 22 11:17:00 smtpe4 MailScanner[21708]: >>>>> /l7MFGi0o022717/01_05_2005.txt contient le virus >>>>> W32/Bagle.dldr.gen !!! >>>>> >>>>> On a different server without this new feature, I get: >>>>> Aug 22 11:34:31 132.210.244.93 MailScanner[4049]: >>>>> /l7MFXTYu031455/01_05_2005.txt contient le virus >>>>> W32/Bagle.dldr.gen !!! >>>>> Aug 22 11:34:41 132.210.244.93 MailScanner[4049]: >>>>> l7MFXTYu031455/01_05_2005.txt:infected: Win32.Bagle.BO@mm >>>>> Aug 22 11:34:41 132.210.244.93 MailScanner[4049]: >>>>> ClamAVModule::INFECTED:: Worm.Bagle.DK:: >>> ./l7MFXTYu031455/01_05_2005.txt >>> >>>>> I now get 2 hits from McAfee and ClamAV, but only 1 from >>>>> Bitdefender... is there a way to pass only the full message to >>>>> the AV scanners? That way we would get only 1 warning and the >>>>> server would also be working less. >>>>> >>>> I could add a feature to do that, but it sounds a very dangerous >>>> thing to do. You are relying on your virus scanners' ability to >>>> unpack attachments on its own. As a fraction of the whole process >>>> for each message, scanning the attachments as well as the full >>>> message is only a tiny part of the time involved. I really wouldn't >>>> advise setting up MailScanner to _not_ scan the attachments. Only a >>>> few virus scanners can do this anyway. >>>> >>>> I'm really not keen on adding this feature, it's one which hardly >>>> anyone would use and it potentially exposes you to viruses with >>>> most virus scanners. >>>> >>>> Jules >>>> >>>> >>> Julian, >>> >>> It makes perfect sense. I guess I will have to live with not so >>> accurate virus statistics... >>> >>> Thanks again! >>> >>> Denis >>> >> >> In my opinion you certenly dont want to stop scanning the >> attachments. The only thing you could do is not report the fact that >> the virus scanner found a virus in the email if it found something in >> the attachment. >> > Gareth, > > No, I don't want to stop scanning some content. That's why I will > have to live with inaccurate virus statistics (since some virus will > be detected twice by ClamAV and McAfee). The other stats problem is that the sanesecurity ClamAV signatures cause a load of your spam to be reported as a virus. That skews the stats quite a lot :-( Not much I can do about it either. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Charset: UTF-8 wj8DBQFGzIVdEfZZRxQVtlQRAi6yAKDglaGNeEh2e+djpfy48WMD4J86bgCgvUb1 YIi+EJUqn5OBBJUazzWQrqA= =VZUV -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Wed Aug 22 20:01:13 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Aug 22 20:01:34 2007 Subject: ClamAV & Sanesecurity & Spamassassin In-Reply-To: <001401c7e4ca$d970bf00$8c523d00$@com> References: <5CD3BFF77DFFD411BCD100D0B720F945047588D2@probe.britaxpmg.com> <000e01c7e4ba$94ad3de0$be07b9a0$@com> <001401c7e4ca$d970bf00$8c523d00$@com> Message-ID: Ryan Weaver spake the following on 8/22/2007 7:43 AM: > Since you've given no reasons I assume this would be because your personal > preference is to view your e-mail in threads and the 'reply' inserts this > topic as a take-over into your thread based viewing system. > > Sorry, I didn't think about that, my bad... > It is more a matter of politeness than personal preference. Imagine if you are talking to the man next to you about cars, and I walk up and change the subject to something else. The man next to you is still talking about cars. Try to follow both conversations at the same time and you will understand. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Wed Aug 22 20:11:40 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Aug 22 20:12:05 2007 Subject: Full message scan oddity In-Reply-To: <46CC60F5.9010101@ecs.soton.ac.uk> References: <46CC590C.9020403@USherbrooke.ca> <46CC60F5.9010101@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 8/22/2007 9:14 AM: > > > Denis Beauchemin wrote: >> Hello, >> >> I just upgraded 2 MS servers to the latest stable and enabled the >> following option: >> ClamAV Full Message Scan = yes >> >> I sent a virus-infected email and noticed the following: >> Aug 22 11:16:59 smtpe4 MailScanner[21708]: >> l7MFGi0o022717/01_05_2005.txt:infected: Win32.Bagle.BO@mm >> Aug 22 11:17:00 smtpe4 MailScanner[21708]: ClamAV Module::INFECTED:: >> Worm.Bagle.DK:: ./l7MFGi0o022717/ >> Aug 22 11:17:00 smtpe4 MailScanner[21708]: ClamAV Module::INFECTED:: >> Worm.Bagle.DK:: ./l7MFGi0o022717/01_05_2005.txt >> Aug 22 11:17:00 smtpe4 MailScanner[21708]: >> /l7MFGi0o022717.message/00000350.EML/01_05_2005.txt contient le >> virus W32/Bagle.dldr.gen !!! >> Aug 22 11:17:00 smtpe4 MailScanner[21708]: >> /l7MFGi0o022717/01_05_2005.txt contient le virus >> W32/Bagle.dldr.gen !!! >> >> On a different server without this new feature, I get: >> Aug 22 11:34:31 132.210.244.93 MailScanner[4049]: >> /l7MFXTYu031455/01_05_2005.txt contient le virus >> W32/Bagle.dldr.gen !!! >> Aug 22 11:34:41 132.210.244.93 MailScanner[4049]: >> l7MFXTYu031455/01_05_2005.txt:infected: Win32.Bagle.BO@mm >> Aug 22 11:34:41 132.210.244.93 MailScanner[4049]: >> ClamAVModule::INFECTED:: Worm.Bagle.DK:: ./l7MFXTYu031455/01_05_2005.txt >> >> I now get 2 hits from McAfee and ClamAV, but only 1 from >> Bitdefender... is there a way to pass only the full message to the AV >> scanners? That way we would get only 1 warning and the server would >> also be working less. > I could add a feature to do that, but it sounds a very dangerous thing > to do. You are relying on your virus scanners' ability to unpack > attachments on its own. As a fraction of the whole process for each > message, scanning the attachments as well as the full message is only a > tiny part of the time involved. I really wouldn't advise setting up > MailScanner to _not_ scan the attachments. Only a few virus scanners can > do this anyway. > > I'm really not keen on adding this feature, it's one which hardly anyone > would use and it potentially exposes you to viruses with most virus > scanners. > > Jules > What would be nice is the logging module to not report the same infection twice in the same message. IE... If found in unpacked message, suppress output of same virus in raw message. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From Denis.Beauchemin at USherbrooke.ca Wed Aug 22 20:50:26 2007 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Wed Aug 22 20:51:12 2007 Subject: Full message scan oddity In-Reply-To: <46CC855B.1050702@ecs.soton.ac.uk> References: <46CC7A59.1080102@USherbrooke.ca> <46CC855B.1050702@ecs.soton.ac.uk> Message-ID: <46CC9382.2020107@USherbrooke.ca> Julian Field a ?crit : > > The other stats problem is that the sanesecurity ClamAV signatures cause > a load of your spam to be reported as a virus. That skews the stats > quite a lot :-( Not much I can do about it either. > > True, but they are malignant spam, which I could relate to some form of virus ;-) Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x62252 F: 819.821.8045 -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3595 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070822/4948d330/smime.bin From r.berber at computer.org Wed Aug 22 21:00:14 2007 From: r.berber at computer.org (=?ISO-8859-1?Q?Ren=E9_Berber?=) Date: Wed Aug 22 21:00:50 2007 Subject: Whitelists and Fuzzy In-Reply-To: <46CC305B.2060405@USherbrooke.ca> References: <5CD3BFF77DFFD411BCD100D0B720F94503C4E5E6@probe.britaxpmg.com> <46CC305B.2060405@USherbrooke.ca> Message-ID: Denis Beauchemin wrote: > I have the same problem with someone's sig that triggers on "cialis" > even though the pic says "social services". On another occasion I > reported a bug on the wiki and never got any feedback. I am thinking > about dropping this plugin... That's easy to fix, in FuzzyOcr.words change the line to: cialis::0.1 Just to make the answer complete, most people probably already know this, the above tells FuzzyOcr to match with high certainty; the example you name does have 5 of the 6 letters of the word in order, so it is no wonder it matches -- you may even have to lower the 0.1 to 0.01 . In general I use a changed word list with short words and a few other words that are (mis)matched easily using the lower fuzzy factor (higher certainty). A few other words I use with a high fuzzy factor. -- Ren? Berber From jaearick at colby.edu Wed Aug 22 21:13:11 2007 From: jaearick at colby.edu (Jeff A. Earickson) Date: Wed Aug 22 21:13:16 2007 Subject: fell off the wagon, climbing back on Message-ID: Julian et al, I replaced my legacy sendmail box with an fancy new all-in-one email appliance on July 23. Anti-spam, anti-virus, integrated webmail/POP/IMAP/calendaring, shared mail folders, etc, etc. And I bailed off the list, thinking life would be good. Forgive me, Jules, for I have sinned. I've gotten my butt kicked by both the spammers and the user community in the past month. While my new gear is great for integrated webmail etc (and the users like it), its anti-spam setup is clearly inferior to MailScanner. I figured that the [unamed] appliance might be worse than MailScanner in terms of anti-spam, but I was shocked at how much of a difference there is. Due to popular demand/angry mobs, I am putting my legacy system back in front of the appliance to run sendmail/MailScanner in relay mode to get our spam back to where it was. I had left it intact, so this was just a case of updating MailScanner, SA, and clam and redoing my sendmail.cf file. Woe to those who stray from the path of MailScanner. You will be punished. Jeff Earickson Colby College From ryanw at falsehope.com Wed Aug 22 21:29:42 2007 From: ryanw at falsehope.com (Ryan Weaver) Date: Wed Aug 22 21:29:50 2007 Subject: ClamAV & Sanesecurity & Spamassassin In-Reply-To: <005501c7e4de$a01a0180$0301a8c0@SAHOMELT> References: <5CD3BFF77DFFD411BCD100D0B720F945047588D2@probe.britaxpmg.com><000e01c7e4ba$94ad3de0$be07b9a0$@com><1187789796.19248.32.camel@gblades-suse.linguaphone-intranet.co.uk><46CC4122.2000306@ecs.soton.ac.uk> <1187792171.19250.40.camel@gblades-suse.linguaphone-intranet.co.uk> <005501c7e4de$a01a0180$0301a8c0@SAHOMELT> Message-ID: <003601c7e4fb$2ce492d0$86adb870$@com> > -----Original Message----- > From: Rick Cooper > > > -----Original Message----- > > From: Gareth > > Sent: Wednesday, August 22, 2007 10:16 AM > > To: MailScanner discussion > > Subject: Re: ClamAV & Sanesecurity & Spamassassin > > > > No I was thinking you might have to have two copies of > > clamav installed > > with one of them compiled to store its signatures in a different > > location. > > You could symlink the main signatures so both installs can > > see them and > > mailscanners update works correctly. You could have mailscanner use > > clamavmodule as it will have most issues with paths etc... > > You could have clamd started from the 2nd copy which can also see > > the sanesecurity signatures. The spamassassin plugin looks like it > > uses a tcpip socket to clamd so it should not be too bad keeping them > > both separate. > > [...] > > You only need one clamav installation, you need to setup a special clam > database (example: /opt/clamdSane) directory with symlinks to the db > files > you want to use with in the special clam db dir. > > MSRBL-Images.hdb -> /usr/local/share/clamav/MSRBL-Images.hdb > MSRBL-SPAM.ndb -> /usr/local/share/clamav/MSRBL-SPAM.ndb > phish.ndb -> /usr/local/share/clamav/phish.ndb > scam.ndb -> /usr/local/share/clamav/scam.ndb > > Next create a new clamd.conf line clamdSane.conf and change the > DatabaseDirectory, TCPSocket (say 3311), and PidFile settings to > something > other than the default like > > DatabaseDirectory /opt/SaneDataBase > TCPSocket 3311 > PidFile /var/run/clamdSane.pid > > Start your second daemon : clamd --config-file=/path/clamdSane.conf > > And change this line in clamAV.pm (the plugin) > > my $clamav = new File::Scan::ClamAV(port => 3310); > > To > > my $clamav = new File::Scan::ClamAV(port => 3311); > > > Now clamd should only see the SaneSecurity sigs when processed via the > SpamAssassin ClamAV plugin > > Set your rules as desired > > Rick Sounds workable... Kind of convoluted, but workable :) Thanks, Ryan From lists at jfworks.net Wed Aug 22 22:14:23 2007 From: lists at jfworks.net (James) Date: Wed Aug 22 22:14:32 2007 Subject: fell off the wagon, climbing back on In-Reply-To: References: Message-ID: <46CCA72F.2010504@jfworks.net> Jeff A. Earickson wrote: > Julian et al, > > I replaced my legacy sendmail box with an fancy new all-in-one > email appliance on July 23. Anti-spam, anti-virus, integrated > webmail/POP/IMAP/calendaring, shared mail folders, etc, etc. > And I bailed off the list, thinking life would be good. > > Forgive me, Jules, for I have sinned. I've gotten my butt kicked > by both the spammers and the user community in the past month. > While my new gear is great for integrated webmail etc (and the > users like it), its anti-spam setup is clearly inferior to > MailScanner. I figured that the [unamed] appliance might be worse than > MailScanner in > terms of anti-spam, but I was shocked at how much of a difference there > is. > > Due to popular demand/angry mobs, I am putting my legacy system > back in front of the appliance to run sendmail/MailScanner in relay > mode to get our spam back to where it was. I had left it > intact, so this was just a case of updating MailScanner, SA, and clam > and redoing my sendmail.cf file. > > Woe to those who stray from the path of MailScanner. You > will be punished. > > Jeff Earickson > Colby College Tell the name of your sin brother and then you may be absolved. Welcome back ;) From mikes at hartwellcorp.com Wed Aug 22 23:16:09 2007 From: mikes at hartwellcorp.com (Michael St. Laurent) Date: Wed Aug 22 23:17:45 2007 Subject: fell off the wagon, climbing back on Message-ID: <3BF93070B3D1B047BA7ABF612958950D018FBCA4@hcex.hartwellcorp.com> > Tell the name of your sin brother and then you may be > absolved. Welcome > back ;) Hi, my name is Mike and I'm a Sysadmin. Welcome back. ;) From maillists at conactive.com Wed Aug 22 23:31:35 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Wed Aug 22 23:31:38 2007 Subject: Whitelists and Fuzzy In-Reply-To: <46CC6BE0.3030208@ecs.soton.ac.uk> References: <46CC6BE0.3030208@ecs.soton.ac.uk> Message-ID: Julian Field wrote on Wed, 22 Aug 2007 18:01:20 +0100: > This depends on whether you have Always Include SpamAssassin Report or > not. Ah, yes, that's probably off. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From ssilva at sgvwater.com Thu Aug 23 00:20:26 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 23 00:20:38 2007 Subject: fell off the wagon, climbing back on In-Reply-To: References: Message-ID: Jeff A. Earickson spake the following on 8/22/2007 1:13 PM: > Julian et al, > > I replaced my legacy sendmail box with an fancy new all-in-one > email appliance on July 23. Anti-spam, anti-virus, integrated > webmail/POP/IMAP/calendaring, shared mail folders, etc, etc. > And I bailed off the list, thinking life would be good. > > Forgive me, Jules, for I have sinned. I've gotten my butt kicked > by both the spammers and the user community in the past month. > While my new gear is great for integrated webmail etc (and the > users like it), its anti-spam setup is clearly inferior to MailScanner. > I figured that the [unamed] appliance might be worse than MailScanner in > terms of anti-spam, but I was shocked at how much of a difference there > is. > > Due to popular demand/angry mobs, I am putting my legacy system > back in front of the appliance to run sendmail/MailScanner in relay mode > to get our spam back to where it was. I had left it > intact, so this was just a case of updating MailScanner, SA, and clam > and redoing my sendmail.cf file. > > Woe to those who stray from the path of MailScanner. You > will be punished. > > Jeff Earickson > Colby College It is a good thing to have unburned bridges to retreat back over!! ;-P Say 10 hail Julian's and sin no more... -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From hvdkooij at vanderkooij.org Thu Aug 23 06:51:06 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Thu Aug 23 06:51:16 2007 Subject: fell off the wagon, climbing back on In-Reply-To: <3BF93070B3D1B047BA7ABF612958950D018FBCA4@hcex.hartwellcorp.com> References: <3BF93070B3D1B047BA7ABF612958950D018FBCA4@hcex.hartwellcorp.com> Message-ID: On Wed, 22 Aug 2007, Michael St. Laurent wrote: >> Tell the name of your sin brother and then you may be >> absolved. Welcome >> back ;) > > Hi, my name is Mike and I'm a Sysadmin. There are sins beyond .... The sins of the fathers do not aply so it isn't your name ;-) Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for this quote of George Bernard Shaw.) From martinh at solidstatelogic.com Thu Aug 23 08:56:24 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Thu Aug 23 08:56:39 2007 Subject: fell off the wagon, climbing back on In-Reply-To: Message-ID: <8833d120fb64f24e95ea483a4e6b9f34@solidstatelogic.com> Jeff Welcome back - ah the prodigal son returns. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Jeff A. Earickson > Sent: 22 August 2007 21:13 > To: mailscanner mailing list > Subject: fell off the wagon, climbing back on > > Julian et al, > > I replaced my legacy sendmail box with an fancy new all-in-one > email appliance on July 23. Anti-spam, anti-virus, integrated > webmail/POP/IMAP/calendaring, shared mail folders, etc, etc. > And I bailed off the list, thinking life would be good. > > Forgive me, Jules, for I have sinned. I've gotten my butt kicked > by both the spammers and the user community in the past month. > While my new gear is great for integrated webmail etc (and the > users like it), its anti-spam setup is clearly inferior to MailScanner. > I figured that the [unamed] appliance might be worse than MailScanner in > terms of anti-spam, but I was shocked at how much of a difference there > is. > > Due to popular demand/angry mobs, I am putting my legacy system > back in front of the appliance to run sendmail/MailScanner in > relay mode to get our spam back to where it was. I had left it > intact, so this was just a case of updating MailScanner, SA, and clam > and redoing my sendmail.cf file. > > Woe to those who stray from the path of MailScanner. You > will be punished. > > Jeff Earickson > Colby College > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From glenn.steen at gmail.com Thu Aug 23 10:57:55 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu Aug 23 10:57:57 2007 Subject: Whitelists and Fuzzy In-Reply-To: References: <5CD3BFF77DFFD411BCD100D0B720F945047588D5@probe.britaxpmg.com> <1187793500.19246.46.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <223f97700708230257s2e775e08w6bbaf7abf57ad9ff@mail.gmail.com> On 22/08/07, Kai Schaetzl wrote: > Gareth wrote on Wed, 22 Aug 2007 15:38:20 +0100: > > > Yes spamassassin is still run against the rules so at least you can see > > what the score is. However if it is whitelisted then it is never classed > > as spam by mailscanner. On my mailscanner any whitelisted messages just > > shows 'whitelisted' where the spamassassin rules are normally listed so > > although I can see what the score was I cannot tell which specific rules > > were matched. > > That is not what I see here for whitelisted messages. The spam score shows > as 0.0 and no rules are shown. Is that what you describe new to MS or new > to MW? Of course, it could be possible that there are really no hits at > all, but I doubt that ... > > Kai > Quite. The behaviour is dependant on whether you run SA on every message or not (always add sa score, or whatever the setting is named)... As with most things in MailScanner, there is an option to change it;-). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Thu Aug 23 11:06:51 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu Aug 23 11:06:54 2007 Subject: fell off the wagon, climbing back on In-Reply-To: References: Message-ID: <223f97700708230306v4447e378ob01ffbb7b0f4168e@mail.gmail.com> On 22/08/07, Jeff A. Earickson wrote: > Julian et al, > > I replaced my legacy sendmail box with an fancy new all-in-one > email appliance on July 23. Anti-spam, anti-virus, integrated > webmail/POP/IMAP/calendaring, shared mail folders, etc, etc. > And I bailed off the list, thinking life would be good. Shame Jeff, shame! To walk with the unbelievers... > Forgive me, Jules, for I have sinned. I've gotten my butt kicked > by both the spammers and the user community in the past month. > While my new gear is great for integrated webmail etc (and the > users like it), its anti-spam setup is clearly inferior to MailScanner. > I figured that the [unamed] appliance might be worse than MailScanner in Remember that "uname" is a Simple Command, not a Daemon Process. Apply it liberally as "uname -a" in you penitence.... and salvation might just be yours. > terms of anti-spam, but I was shocked at how much of a difference there > is. > > Due to popular demand/angry mobs, I am putting my legacy system > back in front of the appliance to run sendmail/MailScanner in > relay mode to get our spam back to where it was. I had left it > intact, so this was just a case of updating MailScanner, SA, and clam > and redoing my sendmail.cf file. > > Woe to those who stray from the path of MailScanner. You > will be punished. > > Jeff Earickson > Colby College To aid in your repentance, find Scott Silvas head-banging tool, print it, use it. Glad that you've seen the light, returned to the flock, and will henceforth not stray...;) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From MailScanner at ecs.soton.ac.uk Thu Aug 23 11:43:02 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 23 11:44:23 2007 Subject: fell off the wagon, climbing back on In-Reply-To: References: Message-ID: <46CD64B6.9090600@ecs.soton.ac.uk> Jeff A. Earickson wrote: > Julian et al, > > I replaced my legacy sendmail box with an fancy new all-in-one > email appliance on July 23. Anti-spam, anti-virus, integrated > webmail/POP/IMAP/calendaring, shared mail folders, etc, etc. > And I bailed off the list, thinking life would be good. > > Forgive me, Jules, for I have sinned. How long has it been since your last confession? I forgive you your sins, as you have once again joined the way of the light and have repented your heinous sins. Let you walk the one true path into eternity. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From andy.mac at global-domination.org Thu Aug 23 14:03:26 2007 From: andy.mac at global-domination.org (Andrew MacLachlan) Date: Thu Aug 23 14:02:52 2007 Subject: Tiled gif spam Message-ID: I just forwarded this from my Yahoo acct through my MailScanner with FuzzyOcr and it sailed straight through... I'm not sure what my MTA level checks would have made of the original message though. Does anyone have any special tricks or rules to combat these messages? I'm running the latest everything on Centos 4.5 -Andy -- This message was scanned by ESVA and is believed to be clean. -------------- next part -------------- An embedded message was scrubbed... From: "Andrew MacLachlan" Subject: Fw: Funny thing. Date: Thu, 23 Aug 2007 13:39:31 +0100 Size: 12129 Url: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070823/409d5129/attachment.mht From Denis.Beauchemin at USherbrooke.ca Thu Aug 23 14:17:16 2007 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Thu Aug 23 14:17:47 2007 Subject: Whitelists and Fuzzy In-Reply-To: References: <5CD3BFF77DFFD411BCD100D0B720F94503C4E5E6@probe.britaxpmg.com> <46CC305B.2060405@USherbrooke.ca> Message-ID: <46CD88DC.5010102@USherbrooke.ca> Ren? Berber a ?crit : > Denis Beauchemin wrote: > > >> I have the same problem with someone's sig that triggers on "cialis" >> even though the pic says "social services". On another occasion I >> reported a bug on the wiki and never got any feedback. I am thinking >> about dropping this plugin... >> > > That's easy to fix, in FuzzyOcr.words change the line to: > > cialis::0.1 > > Just to make the answer complete, most people probably already know this, the > above tells FuzzyOcr to match with high certainty; the example you name does > have 5 of the 6 letters of the word in order, so it is no wonder it matches -- > you may even have to lower the 0.1 to 0.01 . > > In general I use a changed word list with short words and a few other words that > are (mis)matched easily using the lower fuzzy factor (higher certainty). A few > other words I use with a high fuzzy factor. > Ren?, Could you tell me where you found this information please? I cannot find it anywhere... Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x62252 F: 819.821.8045 -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3595 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070823/80c1a96d/smime.bin From andy.mac at global-domination.org Thu Aug 23 14:21:31 2007 From: andy.mac at global-domination.org (Andrew MacLachlan) Date: Thu Aug 23 14:20:55 2007 Subject: Tiled gif spam Message-ID: Sorry - this is the analysis from Mailwatch: Spam Report: Score Matching Rule score=3.919 4 required 0.00 DKIM_SIGNED -0.00 DKIM_VERIFIED 2.50 HTML_IMAGE_ONLY_16 0.00 HTML_MESSAGE 1.42 SARE_GIF_ATTACH As you can see, it was almost trapped. Of course I could always up the scores for SARE_GIF_ATTACH and HTML_IMAGE_ONLY_16, but I think an additional rule for side-by-side gifs might be a better approach? I'm not sure what the best score might be for such a rule - but something around the 1.0 mark would probably be appropriate. -Andy > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Andrew MacLachlan > Sent: 23 August 2007 14:03 > To: MailScanner discussion > Subject: Tiled gif spam > > I just forwarded this from my Yahoo acct through my MailScanner with > FuzzyOcr and it sailed straight through... I'm not sure what my MTA > level checks would have made of the original message though. > > Does anyone have any special tricks or rules to combat these messages? > > I'm running the latest everything on Centos 4.5 > > -Andy > > > -- > This message was scanned by ESVA and is believed to be clean. > -- This message was scanned by ESVA and is believed to be clean. From list-mailscanner at linguaphone.com Thu Aug 23 14:24:50 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Thu Aug 23 14:25:05 2007 Subject: Tiled gif spam In-Reply-To: References: Message-ID: <1187875490.22243.2.camel@gblades-suse.linguaphone-intranet.co.uk> No Bayes? On Thu, 2007-08-23 at 14:21, Andrew MacLachlan wrote: > Sorry - this is the analysis from Mailwatch: > > Spam Report: > Score Matching Rule > score=3.919 > 4 required > 0.00 DKIM_SIGNED > -0.00 DKIM_VERIFIED > 2.50 HTML_IMAGE_ONLY_16 > 0.00 HTML_MESSAGE > 1.42 SARE_GIF_ATTACH > > As you can see, it was almost trapped. Of course I could always up the > scores for SARE_GIF_ATTACH and HTML_IMAGE_ONLY_16, but I think an > additional rule for side-by-side gifs might be a better approach? I'm > not sure what the best score might be for such a rule - but something > around the 1.0 mark would probably be appropriate. > > -Andy > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Andrew MacLachlan > > Sent: 23 August 2007 14:03 > > To: MailScanner discussion > > Subject: Tiled gif spam > > > > I just forwarded this from my Yahoo acct through my MailScanner with > > FuzzyOcr and it sailed straight through... I'm not sure what my MTA > > level checks would have made of the original message though. > > > > Does anyone have any special tricks or rules to combat these messages? > > > > I'm running the latest everything on Centos 4.5 > > > > -Andy > > > > > > -- > > This message was scanned by ESVA and is believed to be clean. > > > > > > -- > This message was scanned by ESVA and is believed to be clean. From andy.mac at global-domination.org Thu Aug 23 14:43:48 2007 From: andy.mac at global-domination.org (Andrew MacLachlan) Date: Thu Aug 23 14:43:12 2007 Subject: antispam server setup website - comments welcome Message-ID: > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Anthony Cartmell > Sent: 21 August 2007 11:35 > To: MailScanner discussion > Subject: Re: antispam server setup website - comments welcome > > > No it doesn't, the 'discover' one is not being updated and seems broken. > > > > The other 82.250.255.100 actually works.... > > Ah, OK, I'll stick with that one then. Thanks for the info! > > > People have made many attempts to contact the pyzor "maintainer" on this > > to offer servers/bandwidth but he seems to ignore all offers... > > It's sad when good software goes un-maintained. > See the attached install script. If you use this procedure you will use both lists and pyzor will use the highest score returned. - Works well for me. -- This message was scanned by ESVA and is believed to be clean. -------------- next part -------------- cd /tmp wget http://ovh.dl.sourceforge.net/sourceforge/pyzor/pyzor-0.4.0.tar.bz2 tar -xjf pyzor-0.4.0.tar.bz2 cd pyzor-0.4.0 python setup.py build python setup.py install chmod -R a+rX /usr/share/doc/pyzor \ /usr/lib/python2.3/site-packages/pyzor \ /usr/bin/pyzor /usr/bin/pyzord su postfix -s /bin/bash -c 'pyzor discover' echo "82.94.255.100:24441">/var/spool/postfix/.pyzor/servers echo "66.250.40.33:24441">>/var/spool/postfix/.pyzor/servers cd /tmp rm -rf pyzor* From glenn.steen at gmail.com Thu Aug 23 15:02:42 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu Aug 23 15:02:44 2007 Subject: Tiled gif spam In-Reply-To: References: Message-ID: <223f97700708230702v3d75a065m97f13b167b5b0b3d@mail.gmail.com> On 23/08/07, Andrew MacLachlan wrote: > Sorry - this is the analysis from Mailwatch: > > Spam Report: > Score Matching Rule > score=3.919 > 4 required > 0.00 DKIM_SIGNED > -0.00 DKIM_VERIFIED > 2.50 HTML_IMAGE_ONLY_16 > 0.00 HTML_MESSAGE > 1.42 SARE_GIF_ATTACH > > As you can see, it was almost trapped. Of course I could always up the > scores for SARE_GIF_ATTACH and HTML_IMAGE_ONLY_16, but I think an > additional rule for side-by-side gifs might be a better approach? I'm > not sure what the best score might be for such a rule - but something > around the 1.0 mark would probably be appropriate. > > -Andy > Why don't you use ImageInfo? Or do you do that and it didn't trigger even one little rule? If so... Strange... Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From andy.mac at global-domination.org Thu Aug 23 15:13:33 2007 From: andy.mac at global-domination.org (Andrew MacLachlan) Date: Thu Aug 23 15:12:53 2007 Subject: Tiled gif spam Message-ID: New install - Bayes DB not yet populated :-( > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Gareth > Sent: 23 August 2007 14:25 > To: MailScanner discussion > Subject: RE: Tiled gif spam > > No Bayes? > > On Thu, 2007-08-23 at 14:21, Andrew MacLachlan wrote: > > Sorry - this is the analysis from Mailwatch: > > > > Spam Report: > > Score Matching Rule > > score=3.919 > > 4 required > > 0.00 DKIM_SIGNED > > -0.00 DKIM_VERIFIED > > 2.50 HTML_IMAGE_ONLY_16 > > 0.00 HTML_MESSAGE > > 1.42 SARE_GIF_ATTACH > > > > As you can see, it was almost trapped. Of course I could always up the > > scores for SARE_GIF_ATTACH and HTML_IMAGE_ONLY_16, but I think an > > additional rule for side-by-side gifs might be a better approach? I'm > > not sure what the best score might be for such a rule - but something > > around the 1.0 mark would probably be appropriate. > > > > -Andy > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > > bounces@lists.mailscanner.info] On Behalf Of Andrew MacLachlan > > > Sent: 23 August 2007 14:03 > > > To: MailScanner discussion > > > Subject: Tiled gif spam > > > > > > I just forwarded this from my Yahoo acct through my MailScanner with > > > FuzzyOcr and it sailed straight through... I'm not sure what my MTA > > > level checks would have made of the original message though. > > > > > > Does anyone have any special tricks or rules to combat these messages? > > > > > > I'm running the latest everything on Centos 4.5 > > > > > > -Andy > > > > > > > > > -- > > > This message was scanned by ESVA and is believed to be clean. > > > > > > > > > > > -- > > This message was scanned by ESVA and is believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message was scanned by ESVA and is believed to be clean. > Click here to report this message as spam. > http://mail-gw.global-domination.org/cgi-bin/learn- > msg.cgi?id=188D017002.BFCDE > > -- This message was scanned by ESVA and is believed to be clean. From Denis.Beauchemin at USherbrooke.ca Thu Aug 23 15:51:31 2007 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Thu Aug 23 15:51:59 2007 Subject: Tiled gif spam In-Reply-To: <223f97700708230702v3d75a065m97f13b167b5b0b3d@mail.gmail.com> References: <223f97700708230702v3d75a065m97f13b167b5b0b3d@mail.gmail.com> Message-ID: <46CD9EF3.6060904@USherbrooke.ca> Glenn Steen a ?crit : > On 23/08/07, Andrew MacLachlan wrote: > >> Sorry - this is the analysis from Mailwatch: >> >> Spam Report: >> Score Matching Rule >> score=3.919 >> 4 required >> 0.00 DKIM_SIGNED >> -0.00 DKIM_VERIFIED >> 2.50 HTML_IMAGE_ONLY_16 >> 0.00 HTML_MESSAGE >> 1.42 SARE_GIF_ATTACH >> >> As you can see, it was almost trapped. Of course I could always up the >> scores for SARE_GIF_ATTACH and HTML_IMAGE_ONLY_16, but I think an >> additional rule for side-by-side gifs might be a better approach? I'm >> not sure what the best score might be for such a rule - but something >> around the 1.0 mark would probably be appropriate. >> >> -Andy >> >> > Why don't you use ImageInfo? Or do you do that and it didn't trigger > even one little rule? If so... Strange... > > Cheers > Glenn, Just installed it and fed it the email and... nothing... I ran SA in debug and saw it there, but no scoring... How can I tell it to look for n side-by-side gifs? I didn't see anything about side-by-side images, just the total amount of images, which could trigger on many FP... Thanks! Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x62252 F: 819.821.8045 -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3595 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070823/65613fbc/smime.bin From list-mailscanner at linguaphone.com Thu Aug 23 16:25:13 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Thu Aug 23 16:25:20 2007 Subject: Tiled gif spam In-Reply-To: <46CD9EF3.6060904@USherbrooke.ca> References: <223f97700708230702v3d75a065m97f13b167b5b0b3d@mail.gmail.com> <46CD9EF3.6060904@USherbrooke.ca> Message-ID: <1187882713.22245.4.camel@gblades-suse.linguaphone-intranet.co.uk> On Thu, 2007-08-23 at 15:51, Denis Beauchemin wrote: > Glenn Steen a ?crit : > > On 23/08/07, Andrew MacLachlan wrote: > > > >> Sorry - this is the analysis from Mailwatch: > >> > >> Spam Report: > >> Score Matching Rule > >> score=3.919 > >> 4 required > >> 0.00 DKIM_SIGNED > >> -0.00 DKIM_VERIFIED > >> 2.50 HTML_IMAGE_ONLY_16 > >> 0.00 HTML_MESSAGE > >> 1.42 SARE_GIF_ATTACH > >> > >> As you can see, it was almost trapped. Of course I could always up the > >> scores for SARE_GIF_ATTACH and HTML_IMAGE_ONLY_16, but I think an > >> additional rule for side-by-side gifs might be a better approach? I'm > >> not sure what the best score might be for such a rule - but something > >> around the 1.0 mark would probably be appropriate. > >> > >> -Andy > >> > >> > > Why don't you use ImageInfo? Or do you do that and it didn't trigger > > even one little rule? If so... Strange... > > > > Cheers > > > Glenn, > > Just installed it and fed it the email and... nothing... I ran SA in > debug and saw it there, but no scoring... > > How can I tell it to look for n side-by-side gifs? I didn't see > anything about side-by-side images, just the total amount of images, > which could trigger on many FP... > > Thanks! > > Denis Can you post the image up somewhere then we can take a look. From andy.mac at global-domination.org Thu Aug 23 16:28:44 2007 From: andy.mac at global-domination.org (Andrew MacLachlan) Date: Thu Aug 23 16:28:04 2007 Subject: Tiled gif spam Message-ID: > > Why don't you use ImageInfo? Or do you do that and it didn't trigger > > even one little rule? If so... Strange... > > > > Cheers > > > Glenn, > > Just installed it and fed it the email and... nothing... I ran SA in > debug and saw it there, but no scoring... > > How can I tell it to look for n side-by-side gifs? I didn't see > anything about side-by-side images, just the total amount of images, > which could trigger on many FP... > > Thanks! > > Denis Same response here, although DCC got it this time and pushed the score through the spam threshold... I've disabled SqlGrey and the RBLs in PF so MS gets more (some) spam so I can test this new build. Working really well with the new MS/SA/clamd etc. If the RBLs and postgrey were enabled I doubt that the message would have made it through to MS/SA or if it did, it would be delayed so that dcc etc would have time to catch it. -Andy -- This message was scanned by ESVA and is believed to be clean. From Chris at 7of9b.org Thu Aug 23 16:29:10 2007 From: Chris at 7of9b.org (Chris Burton) Date: Thu Aug 23 16:29:58 2007 Subject: Tiled gif spam References: <223f97700708230702v3d75a065m97f13b167b5b0b3d@mail.gmail.com><46CD9EF3.6060904@USherbrooke.ca> <1187882713.22245.4.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <009101c7e59a$5bf81de0$c7fda8c0@murphy3> > Can you post the image up somewhere then we can take a look. I'd guess they've already been posted to the list from the report below... but yes a sample to download would be a lot easier to work with :) Sender: mailscanner-bounces@lists.mailscanner.info Subject: Tiled gif spam Report: ClamAV: ORz5rrgzMj.gif contains MSRBL-Images/0-0-wgr6 Report: ClamAV: BAizt9ewri.gif contains MSRBL-Images/0-0-wgr3 Report: ClamAV: cZpjPKTOG9.gif contains MSRBL-Images/0-0-wgr5 Report: ClamAV: ZGXEPOSRrd.gif contains MSRBL-Images/0-0-wgr4 ChrisB. From martinh at solidstatelogic.com Thu Aug 23 16:31:36 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Thu Aug 23 16:31:41 2007 Subject: Tiled gif spam In-Reply-To: <1187882713.22245.4.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: Better would be to post the entire spam email (headers and all) somewhere then we can run through our systems and see what hits. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Gareth > Sent: 23 August 2007 16:25 > To: MailScanner discussion > Subject: Re: Tiled gif spam > > On Thu, 2007-08-23 at 15:51, Denis Beauchemin wrote: > > Glenn Steen a ?crit : > > > On 23/08/07, Andrew MacLachlan wrote: > > > > > >> Sorry - this is the analysis from Mailwatch: > > >> > > >> Spam Report: > > >> Score Matching Rule > > >> score=3.919 > > >> 4 required > > >> 0.00 DKIM_SIGNED > > >> -0.00 DKIM_VERIFIED > > >> 2.50 HTML_IMAGE_ONLY_16 > > >> 0.00 HTML_MESSAGE > > >> 1.42 SARE_GIF_ATTACH > > >> > > >> As you can see, it was almost trapped. Of course I could always up > the > > >> scores for SARE_GIF_ATTACH and HTML_IMAGE_ONLY_16, but I think an > > >> additional rule for side-by-side gifs might be a better approach? I'm > > >> not sure what the best score might be for such a rule - but something > > >> around the 1.0 mark would probably be appropriate. > > >> > > >> -Andy > > >> > > >> > > > Why don't you use ImageInfo? Or do you do that and it didn't trigger > > > even one little rule? If so... Strange... > > > > > > Cheers > > > > > Glenn, > > > > Just installed it and fed it the email and... nothing... I ran SA in > > debug and saw it there, but no scoring... > > > > How can I tell it to look for n side-by-side gifs? I didn't see > > anything about side-by-side images, just the total amount of images, > > which could trigger on many FP... > > > > Thanks! > > > > Denis > > Can you post the image up somewhere then we can take a look. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From ssilva at sgvwater.com Thu Aug 23 16:40:06 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 23 16:40:31 2007 Subject: Clam and Phishing.Heuristics.Email.SpoofedDomain Message-ID: I am getting hammered by legit newsletters getting hit by this definition. Is there a way to ignore this one rule until the clam maintainers fix it? -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From Denis.Beauchemin at USherbrooke.ca Thu Aug 23 16:43:35 2007 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Thu Aug 23 16:44:11 2007 Subject: Tiled gif spam In-Reply-To: <1187882713.22245.4.camel@gblades-suse.linguaphone-intranet.co.uk> References: <223f97700708230702v3d75a065m97f13b167b5b0b3d@mail.gmail.com> <46CD9EF3.6060904@USherbrooke.ca> <1187882713.22245.4.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <46CDAB27.3040904@USherbrooke.ca> Gareth a ?crit : > On Thu, 2007-08-23 at 15:51, Denis Beauchemin wrote: > >> Glenn Steen a ?crit : >> >>> On 23/08/07, Andrew MacLachlan wrote: >>> >>> >>>> Sorry - this is the analysis from Mailwatch: >>>> >>>> Spam Report: >>>> Score Matching Rule >>>> score=3.919 >>>> 4 required >>>> 0.00 DKIM_SIGNED >>>> -0.00 DKIM_VERIFIED >>>> 2.50 HTML_IMAGE_ONLY_16 >>>> 0.00 HTML_MESSAGE >>>> 1.42 SARE_GIF_ATTACH >>>> >>>> As you can see, it was almost trapped. Of course I could always up the >>>> scores for SARE_GIF_ATTACH and HTML_IMAGE_ONLY_16, but I think an >>>> additional rule for side-by-side gifs might be a better approach? I'm >>>> not sure what the best score might be for such a rule - but something >>>> around the 1.0 mark would probably be appropriate. >>>> >>>> -Andy >>>> >>>> >>>> >>> Why don't you use ImageInfo? Or do you do that and it didn't trigger >>> even one little rule? If so... Strange... >>> >>> Cheers >>> >>> >> Glenn, >> >> Just installed it and fed it the email and... nothing... I ran SA in >> debug and saw it there, but no scoring... >> >> How can I tell it to look for n side-by-side gifs? I didn't see >> anything about side-by-side images, just the total amount of images, >> which could trigger on many FP... >> >> Thanks! >> >> Denis >> > > Can you post the image up somewhere then we can take a look. > > I'm not the one who started this thread. I just saved the original email to disk and ran it through my own SA setup. The original email was from andy.mac@global-domination.org (Andrew MacLachlan). Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x62252 F: 819.821.8045 From support-lists at petdoctors.co.uk Thu Aug 23 17:08:40 2007 From: support-lists at petdoctors.co.uk (Nigel Kendrick) Date: Thu Aug 23 17:09:31 2007 Subject: FP in Phishing Detection Message-ID: <005401c7e59f$df08dfd0$3c65a8c0@support01> Yes, yes, I know it's html in an email, but it's like Canute and the tide trying to convince people that although it's pretty it's also a pain...anyway... Here's a block from an email sent by our Marketing lady - notice that 'www.petdoctors.co.uk' claims to be 'www.petdoctors.co.uk' - what's tripping the phishing alert and is it fixable? (Look away now if easily offended)

Find out more about Pet Doctors at MailScanner has detected a possible fraud attempt from "www.petdoctors.co.uk" claiming to be www.petdoctors.co.uk

Thanks Nigel Kendrick From MailScanner at ecs.soton.ac.uk Thu Aug 23 17:18:48 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 23 17:20:28 2007 Subject: FP in Phishing Detection In-Reply-To: <005401c7e59f$df08dfd0$3c65a8c0@support01> References: <005401c7e59f$df08dfd0$3c65a8c0@support01> Message-ID: <46CDB368.20402@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 What version of MailScanner are you running? I've made a few changes recently. Nigel Kendrick wrote: > Yes, yes, I know it's html in an email, but it's like Canute and the tide > trying to convince people that although it's pretty it's also a > pain...anyway... > > Here's a block from an email sent by our Marketing lady - notice that > 'www.petdoctors.co.uk' claims to be 'www.petdoctors.co.uk' - what's tripping > the phishing alert and is it fixable? > > (Look away now if easily offended) > >

style='font-size: > 10.0pt;font-family:Tahoma'>Find out more about Pet Doctors at href="http://www.petdoctors.co.uk/">MailScanner has > detected a possible fraud attempt from "www.petdoctors.co.uk" claiming to > be www.petdoctors.co.uk pan> size=3 face=Tahoma> style='font-size:12.0pt;mso-bidi-font-size: > 10.0pt;font-family:Tahoma'>

> > Thanks > > Nigel Kendrick > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Charset: ISO-8859-1 wj8DBQFGzbNqEfZZRxQVtlQRAj4vAKC6FICrMNOPMJI5EDPEg0iDZ5uRMgCfY6G7 Sa/XOq83aMw8w5WI8Sej50Q= =qfp9 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From martinh at solidstatelogic.com Thu Aug 23 17:20:53 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Thu Aug 23 17:20:57 2007 Subject: FP in Phishing Detection In-Reply-To: <005401c7e59f$df08dfd0$3c65a8c0@support01> Message-ID: Nigel What vesion of MS (PS you any relation to Graham "shine Jesus Shine" Kendrick?) -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Nigel Kendrick > Sent: 23 August 2007 17:09 > To: MailScanner discussion > Subject: FP in Phishing Detection > > Yes, yes, I know it's html in an email, but it's like Canute and the tide > trying to convince people that although it's pretty it's also a > pain...anyway... > > Here's a block from an email sent by our Marketing lady - notice that > 'www.petdoctors.co.uk' claims to be 'www.petdoctors.co.uk' - what's > tripping > the phishing alert and is it fixable? > > (Look away now if easily offended) > >

style='font-size: > 10.0pt;font-family:Tahoma'>Find out more about Pet Doctors at href="http://www.petdoctors.co.uk/">MailScanner has > detected a possible fraud attempt from "www.petdoctors.co.uk" claiming to > be www.petdoctors.co.uk pan> size=3 face=Tahoma> style='font-size:12.0pt;mso-bidi-font-size: > 10.0pt;font-family:Tahoma'>

> > Thanks > > Nigel Kendrick > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From support-lists at petdoctors.co.uk Thu Aug 23 17:45:16 2007 From: support-lists at petdoctors.co.uk (Nigel Kendrick) Date: Thu Aug 23 17:46:06 2007 Subject: FP in Phishing Detection In-Reply-To: <46CDB368.20402@ecs.soton.ac.uk> Message-ID: <005c01c7e5a4$fbd4e820$3c65a8c0@support01> Hi Jules, Martin, That message would have been through 4.61.7 but I have upgraded to the latest this afternoon. Nigel From steinkel at pa.net Thu Aug 23 18:51:21 2007 From: steinkel at pa.net (Leland J. Steinke) Date: Thu Aug 23 18:51:27 2007 Subject: How can MailScanner "push back"? Message-ID: <46CDC919.3000304@pa.net> Has anybody set up a scheme where MailScanner tells the MTA to stop or slow message acceptance, short of blocking inbound port 25, when message scanning gets too far behind? We use postfix (so I will try not to reply to my own message). I have been playing with the idea of tuning the number of inbound smtpd processes in master.cf to match the capacity of the MailScanner instance running on the underlying hardware. The initial results are not particularly encouraging. Even with in-house RBLs and reduced spam-score thresholds for RBL addition, some of our servers are being overrun with apparent StormWorm emails from IPs all over the map, reducing the RBL's effectiveness. As another way to slow the onslaught in postfix, I added extra client and HELO restrictions, adding reject_unknown_client and reject_unknown_hostname to smtpd_{client,helo}_restrictions, respectively. It looks like the HELO restriction is blocking almost as much legitimate mail as illegitimate. Leland From list-mailscanner at linguaphone.com Thu Aug 23 19:04:02 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Thu Aug 23 19:04:08 2007 Subject: Clam and Phishing.Heuristics.Email.SpoofedDomain In-Reply-To: Message-ID: Are you using clamavmodule by any chance? > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Scott > Silva > Sent: 23 August 2007 16:40 > To: mailscanner@lists.mailscanner.info > Subject: Clam and Phishing.Heuristics.Email.SpoofedDomain > > > I am getting hammered by legit newsletters getting hit by this > definition. Is > there a way to ignore this one rule until the clam maintainers fix it? > > -- > > MailScanner is like deodorant... > You hope everybody uses it, and > you notice quickly if they don't!!!! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > From list-mailscanner at linguaphone.com Thu Aug 23 19:05:36 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Thu Aug 23 19:05:38 2007 Subject: Tiled gif spam In-Reply-To: <46CDAB27.3040904@USherbrooke.ca> Message-ID: > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Denis > Beauchemin > Sent: 23 August 2007 16:44 > To: MailScanner discussion > Subject: Re: Tiled gif spam > > > Gareth a ?crit : > > On Thu, 2007-08-23 at 15:51, Denis Beauchemin wrote: > > > >> Glenn Steen a ?crit : > >> > >>> On 23/08/07, Andrew MacLachlan wrote: > >>> > >>> > >>>> Sorry - this is the analysis from Mailwatch: > >>>> > >>>> Spam Report: > >>>> Score Matching Rule > >>>> score=3.919 > >>>> 4 required > >>>> 0.00 DKIM_SIGNED > >>>> -0.00 DKIM_VERIFIED > >>>> 2.50 HTML_IMAGE_ONLY_16 > >>>> 0.00 HTML_MESSAGE > >>>> 1.42 SARE_GIF_ATTACH > >>>> > >>>> As you can see, it was almost trapped. Of course I could > always up the > >>>> scores for SARE_GIF_ATTACH and HTML_IMAGE_ONLY_16, but I think an > >>>> additional rule for side-by-side gifs might be a better approach? I'm > >>>> not sure what the best score might be for such a rule - but something > >>>> around the 1.0 mark would probably be appropriate. > >>>> > >>>> -Andy > >>>> > >>>> > >>>> > >>> Why don't you use ImageInfo? Or do you do that and it didn't trigger > >>> even one little rule? If so... Strange... > >>> > >>> Cheers > >>> > >>> > >> Glenn, > >> > >> Just installed it and fed it the email and... nothing... I ran SA in > >> debug and saw it there, but no scoring... > >> > >> How can I tell it to look for n side-by-side gifs? I didn't see > >> anything about side-by-side images, just the total amount of images, > >> which could trigger on many FP... > >> > >> Thanks! > >> > >> Denis > >> > > > > Can you post the image up somewhere then we can take a look. > > > > > I'm not the one who started this thread. I just saved the original > email to disk and ran it through my own SA setup. The original email > was from andy.mac@global-domination.org (Andrew MacLachlan). > > Denis I didn't see it. I guess the sanesecurity signatures caught it :) From r.berber at computer.org Thu Aug 23 19:08:57 2007 From: r.berber at computer.org (=?ISO-8859-1?Q?Ren=E9_Berber?=) Date: Thu Aug 23 19:09:15 2007 Subject: Whitelists and Fuzzy In-Reply-To: <46CD88DC.5010102@USherbrooke.ca> References: <5CD3BFF77DFFD411BCD100D0B720F94503C4E5E6@probe.britaxpmg.com> <46CC305B.2060405@USherbrooke.ca> <46CD88DC.5010102@USherbrooke.ca> Message-ID: Denis Beauchemin wrote: > Ren? Berber a ?crit : >> >> That's easy to fix, in FuzzyOcr.words change the line to: >> >> cialis::0.1 >> >> Just to make the answer complete, most people probably already know >> this, the >> above tells FuzzyOcr to match with high certainty; the example you >> name does >> have 5 of the 6 letters of the word in order, so it is no wonder it >> matches -- >> you may even have to lower the 0.1 to 0.01 . >> >> In general I use a changed word list with short words and a few other >> words that >> are (mis)matched easily using the lower fuzzy factor (higher >> certainty). A few >> other words I use with a high fuzzy factor. >> > Ren?, > > Could you tell me where you found this information please? I cannot > find it anywhere... On the configuration file: # Default detection treshold (see manual) # Default value: 0.25 (Can be changed on a per word basis in the wordlist). There's no manual yet, but for more detail on how this "threshold" is used you can read `perldoc String::Approx`. -- Ren? Berber From hvdkooij at vanderkooij.org Thu Aug 23 19:49:48 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Thu Aug 23 19:50:17 2007 Subject: How can MailScanner "push back"? In-Reply-To: <46CDC919.3000304@pa.net> References: <46CDC919.3000304@pa.net> Message-ID: On Thu, 23 Aug 2007, Leland J. Steinke wrote: > Has anybody set up a scheme where MailScanner tells the MTA to stop or slow > message acceptance, short of blocking inbound port 25, when message scanning > gets too far behind? > > We use postfix (so I will try not to reply to my own message). I have been > playing with the idea of tuning the number of inbound smtpd processes in > master.cf to match the capacity of the MailScanner instance running on the > underlying hardware. The initial results are not particularly encouraging. > Even with in-house RBLs and reduced spam-score thresholds for RBL addition, > some of our servers are being overrun with apparent StormWorm emails from IPs > all over the map, reducing the RBL's effectiveness. Considering blocking DSL, cable and other 'user' IP ranges. There are some RBL's focussing on these ranges. It should give you some air. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for this quote of George Bernard Shaw.) From michael at huntley.net Thu Aug 23 19:53:13 2007 From: michael at huntley.net (Michael Huntley) Date: Thu Aug 23 19:53:48 2007 Subject: How can MailScanner "push back"? In-Reply-To: <46CDC919.3000304@pa.net> References: <46CDC919.3000304@pa.net> Message-ID: <46CDD799.9070609@huntley.net> Greylisting stopped a terrible mail storm on our system. http://postgrey.schweikert.ch/ Cheers! Michael vinum vesco valens viscus Leland J. Steinke wrote: > Has anybody set up a scheme where MailScanner tells the MTA to stop or > slow message acceptance, short of blocking inbound port 25, when > message scanning gets too far behind? > > We use postfix (so I will try not to reply to my own message). I have > been playing with the idea of tuning the number of inbound smtpd > processes in master.cf to match the capacity of the MailScanner > instance running on the underlying hardware. The initial results are > not particularly encouraging. Even with in-house RBLs and reduced > spam-score thresholds for RBL addition, some of our servers are being > overrun with apparent StormWorm emails from IPs all over the map, > reducing the RBL's effectiveness. > > As another way to slow the onslaught in postfix, I added extra client > and HELO restrictions, adding reject_unknown_client and > reject_unknown_hostname to smtpd_{client,helo}_restrictions, > respectively. It looks like the HELO restriction is blocking almost > as much legitimate mail as illegitimate. > > > Leland From steinkel at pa.net Thu Aug 23 20:21:12 2007 From: steinkel at pa.net (Leland J. Steinke) Date: Thu Aug 23 20:21:17 2007 Subject: How can MailScanner "push back"? In-Reply-To: <46CDD799.9070609@huntley.net> References: <46CDC919.3000304@pa.net> <46CDD799.9070609@huntley.net> Message-ID: <46CDDE28.9040306@pa.net> Michael Huntley wrote: > Greylisting stopped a terrible mail storm on our system. We've been using sqlgrey for almost 18 months now. The spammers have adapted. Hugo van der Kooij wrote: > Considering blocking DSL, cable and other 'user' IP ranges. There are > some RBL's focussing on these ranges. It should give you some air. We use PSBL and DSBL, in addition to our own RBL. We are an ISP, so I am loath to use RBLs such as PBL to reject connections, instead using them in SA to jack up spam scores. Maybe I need to write a postfix policy daemon to query the hold queue or otherwise check the box's status and 450-reject the connection if the box is overloaded... Leland From maillists at conactive.com Thu Aug 23 20:31:21 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu Aug 23 20:31:24 2007 Subject: How can MailScanner "push back"? In-Reply-To: <46CDC919.3000304@pa.net> References: <46CDC919.3000304@pa.net> Message-ID: Leland J. Steinke wrote on Thu, 23 Aug 2007 13:51:21 -0400: > Has anybody set up a scheme where MailScanner tells the MTA to stop or > slow message acceptance, short of blocking inbound port 25, when message > scanning gets too far behind? I know you have Postfix, but maybe it's got a similar feature. In sendmail you can configure to stop processing and to stop queueing depending on certain system load. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From MailScanner at ecs.soton.ac.uk Thu Aug 23 20:48:27 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 23 20:49:07 2007 Subject: How can MailScanner "push back"? In-Reply-To: <46CDDE28.9040306@pa.net> References: <46CDC919.3000304@pa.net> <46CDD799.9070609@huntley.net> <46CDDE28.9040306@pa.net> Message-ID: <46CDE48B.10908@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Leland J. Steinke wrote: > > Maybe I need to write a postfix policy daemon to query the hold queue > or otherwise check the box's status and 450-reject the connection if > the box is overloaded... That sounds like the best approach to me. Find the length of the hold queue from either direct measurement or watching the logs, and 450-reject connections if the queue is too large. You could alternatively do it without talking to postfix at all by using iptables to block connectivity to port 25 when the queue gets too large. I don't know how hard it is to write a postfix policy daemon :-) Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Charset: ISO-8859-1 wj8DBQFGzeSMEfZZRxQVtlQRAlVLAJ9FzXVh9eu4SAhN3TYuJO9Db/pAjgCfSabm Z/0eutmbLuDQpy7FQPk1vLU= =vyOy -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From davi at jvsinfo.com.br Thu Aug 23 20:58:55 2007 From: davi at jvsinfo.com.br (Davi Baldin) Date: Thu Aug 23 20:58:05 2007 Subject: =?iso-8859-1?q?ATEN=C7=C3O_-_Davi_estar=E1_ausente?= Message-ID: I will be out of the office starting 23/08/2007 and will not return until 01/09/2007. Estarei ausente at? dia 01/09/2007. Assuntos de suporte, favor encaminhar para suporte@jvsinfo.com.br, grato. From steve.freegard at fsl.com Thu Aug 23 21:12:31 2007 From: steve.freegard at fsl.com (Steve Freegard) Date: Thu Aug 23 21:12:31 2007 Subject: How can MailScanner "push back"? In-Reply-To: <46CDDE28.9040306@pa.net> References: <46CDC919.3000304@pa.net> <46CDD799.9070609@huntley.net> <46CDDE28.9040306@pa.net> Message-ID: <46CDEA2F.9030305@fsl.com> Hi Leland, Leland J. Steinke wrote: > Michael Huntley wrote: >> Greylisting stopped a terrible mail storm on our system. > > We've been using sqlgrey for almost 18 months now. The spammers have > adapted. > We've got a modified greylisting implementation in our BarricadeMX product which is very different to SQLgrey and has so far proven 100% effective against the botnet spam that passes traditional greylistng (no extra drawbacks from normal greylisting except for more bandwidth being used). Ping me off-list if you would like to try a demo of it. > Hugo van der Kooij wrote: > > Considering blocking DSL, cable and other 'user' IP ranges. There are > > some RBL's focussing on these ranges. It should give you some air. > > We use PSBL and DSBL, in addition to our own RBL. We are an ISP, so I > am loath to use RBLs such as PBL to reject connections, instead using > them in SA to jack up spam scores. I like the DSBL a lot - but you should probably consider adding cbl.abuseat.org as it will catch a *lot* of extra stuff missed by your existing two. Instead of using the PBL you could use dynablock.njabl.org and bypass any of your own dial-up/DSL ranges. Also consider adding milter-link into Postfix and rejecting stuff listed on multi.surbl.org and black.uribl.com at the MTA level as this will help a lot (on the non-botnet stuff anyway). > Maybe I need to write a postfix policy daemon to query the hold queue or > otherwise check the box's status and 450-reject the connection if the > box is overloaded... I really don't think that this will solve your problem as you'll end up seriously delaying geniune senders with sane retry intervals whilst the bots will continue to hammer away relentlessly whenever you start allowing connections again. It's a problem that will then get exponentially worse the more you shut of the port. It's better to minimise the amount of junk .vs. good message allowed into MailScanner from the MTA which is what we (FSL) are pretty good at now ;-) Kind regards, Steve. From steinkel at pa.net Thu Aug 23 21:14:26 2007 From: steinkel at pa.net (Leland J. Steinke) Date: Thu Aug 23 21:14:32 2007 Subject: How can MailScanner "push back"? In-Reply-To: <46CDE48B.10908@ecs.soton.ac.uk> References: <46CDC919.3000304@pa.net> <46CDD799.9070609@huntley.net> <46CDDE28.9040306@pa.net> <46CDE48B.10908@ecs.soton.ac.uk> Message-ID: <46CDEAA2.9040300@pa.net> Julian Field wrote: > I don't know how hard it is to write a postfix policy daemon :-) > Actually, "he who shall not be named" provides a sample policy daemon with the postfix source. Leland From Richard.Frovarp at sendit.nodak.edu Thu Aug 23 21:21:51 2007 From: Richard.Frovarp at sendit.nodak.edu (Richard Frovarp) Date: Thu Aug 23 21:21:55 2007 Subject: How can MailScanner "push back"? In-Reply-To: <46CDEA2F.9030305@fsl.com> References: <46CDC919.3000304@pa.net> <46CDD799.9070609@huntley.net> <46CDDE28.9040306@pa.net> <46CDEA2F.9030305@fsl.com> Message-ID: <46CDEC5F.1000103@sendit.nodak.edu> Steve Freegard wrote: > > > Instead of using the PBL you could use dynablock.njabl.org and bypass > any of your own dial-up/DSL ranges. dynablock is a mirror of the PBL and will go away at some point. In fact their site is now saying it will be going away soon, as it is long past time to switch to PBL. http://www.njabl.org/dynablock.html From Richard.Frovarp at sendit.nodak.edu Thu Aug 23 21:25:47 2007 From: Richard.Frovarp at sendit.nodak.edu (Richard Frovarp) Date: Thu Aug 23 21:25:50 2007 Subject: How can MailScanner "push back"? In-Reply-To: <46CDC919.3000304@pa.net> References: <46CDC919.3000304@pa.net> Message-ID: <46CDED4B.3020001@sendit.nodak.edu> Leland J. Steinke wrote: > Has anybody set up a scheme where MailScanner tells the MTA to stop or > slow message acceptance, short of blocking inbound port 25, when > message scanning gets too far behind? > > We use postfix (so I will try not to reply to my own message). I have > been playing with the idea of tuning the number of inbound smtpd > processes in master.cf to match the capacity of the MailScanner > instance running on the underlying hardware. The initial results are > not particularly encouraging. Even with in-house RBLs and reduced > spam-score thresholds for RBL addition, some of our servers are being > overrun with apparent StormWorm emails from IPs all over the map, > reducing the RBL's effectiveness. > > As another way to slow the onslaught in postfix, I added extra client > and HELO restrictions, adding reject_unknown_client and > reject_unknown_hostname to smtpd_{client,helo}_restrictions, > respectively. It looks like the HELO restriction is blocking almost > as much legitimate mail as illegitimate. > > > Leland We usually only have issues of one of our boxes getting hammered. If you run multiple machines, and only one is getting hammered, blocking 25 isn't a bad thing. The load will the hopefully go over to your other boxes. If it's spam and you're really lucky it might even stop (never seen this, hence the lucky part). I've shut off our incoming sendmail process on an overloaded box to let it catch up. It actually requires stopping the service MailScanner stop, service MailScanner startout, and check_mailscanner calls. An automated method of controlling postfix of iptables would probably work just as well, so long as all of your servers don't trip at the same time. From steve.freegard at fsl.com Thu Aug 23 22:05:01 2007 From: steve.freegard at fsl.com (Steve Freegard) Date: Thu Aug 23 22:05:01 2007 Subject: How can MailScanner "push back"? In-Reply-To: <46CDEC5F.1000103@sendit.nodak.edu> References: <46CDC919.3000304@pa.net> <46CDD799.9070609@huntley.net> <46CDDE28.9040306@pa.net> <46CDEA2F.9030305@fsl.com> <46CDEC5F.1000103@sendit.nodak.edu> Message-ID: <46CDF67D.4000208@fsl.com> Richard Frovarp wrote: > Steve Freegard wrote: >> >> >> Instead of using the PBL you could use dynablock.njabl.org and bypass >> any of your own dial-up/DSL ranges. > > dynablock is a mirror of the PBL and will go away at some point. In fact > their site is now saying it will be going away soon, as it is long past > time to switch to PBL. > > http://www.njabl.org/dynablock.html Yes - but my rationale behind that statement remains the same; PBL access for an ISP is potentially going to be very expensive (which is why I guess the OP was not using Spamhaus at all), so an rsync of dynablock before it disappears is probably a good idea. Kind regards, Steve. From ssilva at sgvwater.com Thu Aug 23 22:08:36 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 23 22:08:51 2007 Subject: Clam and Phishing.Heuristics.Email.SpoofedDomain In-Reply-To: References: Message-ID: Gareth spake the following on 8/23/2007 11:04 AM: > Are you using clamavmodule by any chance? > Yes I am. I thought about using clamd, but don't have enough volume to be worth the extra work. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From andy.mac at global-domination.org Thu Aug 23 22:50:27 2007 From: andy.mac at global-domination.org (Andrew MacLachlan) Date: Thu Aug 23 22:49:58 2007 Subject: How can MailScanner "push back"? Message-ID: > Actually, "he who shall not be named" provides a sample policy daemon > with the postfix source. > There is a much simpler solution (but I could also be confused...): Main.cf ... # INPUT RATE CONTROL # # The in_flow_delay configuration parameter implements mail input # flow control. This feature is turned on by default, although it # still needs further development (it's disabled on SCO UNIX due # to an SCO bug). # # A Postfix process will pause for $in_flow_delay seconds before # accepting a new message, when the message arrival rate exceeds the # message delivery rate. With the default 100 SMTP server process # limit, this limits the mail inflow to 100 messages a second more # than the number of messages delivered per second. # # Specify 0 to disable the feature. Valid delays are 0..10. # #in_flow_delay = 1s ... -HTH, Andy -- This message was scanned by ESVA and is believed to be clean. From andy.mac at global-domination.org Thu Aug 23 22:52:21 2007 From: andy.mac at global-domination.org (Andrew MacLachlan) Date: Thu Aug 23 22:52:03 2007 Subject: Tiled gif spam Message-ID: > > I didn't see it. I guess the sanesecurity signatures caught it :) > :-) -- This message was scanned by ESVA and is believed to be clean. From andy.mac at global-domination.org Thu Aug 23 22:54:51 2007 From: andy.mac at global-domination.org (Andrew MacLachlan) Date: Thu Aug 23 22:54:09 2007 Subject: =?iso-8859-1?q?RE=3A_ATEN=C7=C3O_-_Davi_estar=E1_ausente?= Message-ID: > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Davi Baldin > Sent: 23 August 2007 20:59 > To: mailscanner@lists.mailscanner.info > Subject: ATEN??O - Davi estar? ausente > > > I will be out of the office starting 23/08/2007 and will not return until > 01/09/2007. Does anyone know Davi's address so we can help ourselves to his things now that we know he's gone on holiday for a week? -- This message was scanned by ESVA and is believed to be clean. From jpenix at binarytribe.com Thu Aug 23 23:14:32 2007 From: jpenix at binarytribe.com (Joshua Penix) Date: Thu Aug 23 23:14:43 2007 Subject: Error in Clam/SA install script Message-ID: <9C05A28F-5A35-42D9-8D98-873F709D8110@binarytribe.com> Nothing major but I thought I'd mention it: Line 439 of install.sh in Julian's install-Clam-SA package attempts to back up SpamAssassin's /etc/mail/spamassassin/*.pre files, but it makes a path assumption and thusly fails as follows: Making backup of pre files to /tmp/backup.pre.9510.tar tar: *pre: Cannot stat: No such file or directory tar: Error exit delayed from previous errors And a blank tarball is created, leaving the user without backups of their SA configs. -- Joshua Penix http://www.binarytribe.com Binary Tribe Linux Integration Services & Network Consulting From miguelk at konsultex.com.br Thu Aug 23 23:33:31 2007 From: miguelk at konsultex.com.br (Miguel Koren O'Brien de Lacy) Date: Thu Aug 23 23:33:50 2007 Subject: =?iso-8859-1?q?ATEN=C7=C3O_-_Davi_estar=E1_ausente?= In-Reply-To: References: Message-ID: <46CE0B3B.5040006@konsultex.com.br> An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070823/64ea640c/attachment.html From ssilva at sgvwater.com Thu Aug 23 23:38:35 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 23 23:38:48 2007 Subject: How can MailScanner "push back"? In-Reply-To: <46CDEA2F.9030305@fsl.com> References: <46CDC919.3000304@pa.net> <46CDD799.9070609@huntley.net> <46CDDE28.9040306@pa.net> <46CDEA2F.9030305@fsl.com> Message-ID: Steve Freegard spake the following on 8/23/2007 1:12 PM: > Hi Leland, > > Leland J. Steinke wrote: >> Michael Huntley wrote: >>> Greylisting stopped a terrible mail storm on our system. >> >> We've been using sqlgrey for almost 18 months now. The spammers have >> adapted. >> > > We've got a modified greylisting implementation in our BarricadeMX > product which is very different to SQLgrey and has so far proven 100% > effective against the botnet spam that passes traditional greylistng (no > extra drawbacks from normal greylisting except for more bandwidth being > used). Ping me off-list if you would like to try a demo of it. > >> Hugo van der Kooij wrote: >> > Considering blocking DSL, cable and other 'user' IP ranges. There are >> > some RBL's focussing on these ranges. It should give you some air. >> >> We use PSBL and DSBL, in addition to our own RBL. We are an ISP, so I >> am loath to use RBLs such as PBL to reject connections, instead using >> them in SA to jack up spam scores. > > I like the DSBL a lot - but you should probably consider adding > cbl.abuseat.org as it will catch a *lot* of extra stuff missed by your > existing two. > > Instead of using the PBL you could use dynablock.njabl.org and bypass > any of your own dial-up/DSL ranges. > Before you use dynablock.njabl.org you should read this; http://njabl.org/dynablock.html. It's been more than 6 months since NJABL maintenance of dynablock was terminated and dynablock became a copy of the Spamhaus PBL. The dynablock zone will be emptied sometime soon and the dynablock.njabl.org zone will be shut down. If you're still using dynablock.njabl.org, it's long past time to switch to pbl.spamhaus.org. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ram at netcore.co.in Fri Aug 24 06:09:30 2007 From: ram at netcore.co.in (ram) Date: Fri Aug 24 06:09:46 2007 Subject: How can MailScanner "push back"? In-Reply-To: <46CDEAA2.9040300@pa.net> References: <46CDC919.3000304@pa.net> <46CDD799.9070609@huntley.net> <46CDDE28.9040306@pa.net> <46CDE48B.10908@ecs.soton.ac.uk> <46CDEAA2.9040300@pa.net> Message-ID: <1187932170.21146.20.camel@localhost.localdomain> On Thu, 2007-08-23 at 16:14 -0400, Leland J. Steinke wrote: > Julian Field wrote: > > I don't know how hard it is to write a postfix policy daemon :-) > > > Actually, "he who shall not be named" provides a sample policy daemon > with the postfix source. I havent done policy daemons before, but it seems to to be trivial. One could use milters too, postfix 2.3 above support milters without hassles , I use a custom milter myself, but not for slowing down mails Slowing down mails I do by adjusting weights on the load balancer with a simple perl script Thanks Ram From hvdkooij at vanderkooij.org Fri Aug 24 07:02:41 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Fri Aug 24 07:02:54 2007 Subject: =?iso-8859-1?q?RE=3A_ATEN=C7=C3O_-_Davi_estar=E1_ausente?= In-Reply-To: References: Message-ID: On Thu, 23 Aug 2007, Andrew MacLachlan wrote: >> I will be out of the office starting 23/08/2007 and will not return until >> 01/09/2007. > > Does anyone know Davi's address so we can help ourselves to his things now that we know he's gone on holiday for a week? Received: from legolas.jvsinfo.com.br (mail.jvsinfo.com.br [189.16.34.130]) Next stop: lacnic Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for this quote of George Bernard Shaw.) From list-mailscanner at linguaphone.com Fri Aug 24 09:21:23 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Fri Aug 24 09:21:35 2007 Subject: Clam and Phishing.Heuristics.Email.SpoofedDomain In-Reply-To: References: Message-ID: <1187943682.24997.9.camel@gblades-suse.linguaphone-intranet.co.uk> On Thu, 2007-08-23 at 22:08, Scott Silva wrote: > Gareth spake the following on 8/23/2007 11:04 AM: > > Are you using clamavmodule by any chance? > > > Yes I am. I thought about using clamd, but don't have enough volume to be > worth the extra work. Ok the problem is causes by a new clamav feature and unfortunetly in the clamavlib the option is enabled by default (equivilent to having --no-phishing-restrictedscan option set on clamscan) whereas everywhere else it is disabled. Attached is a new copy of SweepViruses.pm which turns the option off when calling clamavmodule and rectifies the problem. Jules has already fixed the issue in his development copy. -------------- next part -------------- A non-text attachment was scrubbed... Name: SweepViruses.pm.gz Type: application/x-gzip Size: 30651 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070824/18d0d586/SweepViruses.pm-0001.gz From viralert at fadalto.com Fri Aug 24 10:01:54 2007 From: viralert at fadalto.com (Phil) Date: Fri Aug 24 10:02:13 2007 Subject: MCP problem Message-ID: <20070824085224.M12471@yatta-it.com> Hi all, I'm using MailScanner-4.62.9-3. I have enabled MCP check as for previous version, but I'm not receiving mcp mail catched. My configuration file is: Non MCP Actions = deliver MCP Actions = store attachment forward spammy@yatta-it.com High Scoring MCP Actions = store forward spammy@yatta-it.com Bounce MCP As Attachment = no My mail log file says: Aug 24 10:41:50 tommy sendmail[13040]: l7O8fmQ3013040: from=, size=871, class=0, nrcpts=1, msgid=<200708240841.l7O8fW1r032052@dario.yatta-it.com>, proto=ESMTP, daemon=MTA, relay=217-133-242-204.b2b.tiscali.it [217.133.242.204] Aug 24 10:41:53 tommy MailScanner[12961]: New Batch: Scanning 1 messages, 1457 bytes Aug 24 10:41:53 tommy MailScanner[12961]: MCP Checks: Starting Aug 24 10:41:54 tommy MailScanner[12961]: Message l7O8fmQ3013040 from 217.133.242.204 (root@dario.yatta-it.com) to fdini.com is MCP, MCP-Checker (score=4, required 1, RULE1 4.00) Aug 24 10:41:54 tommy MailScanner[12961]: MCP Checks: Found 1 MCP messages Aug 24 10:41:54 tommy MailScanner[12961]: MCP Actions: message l7O8fmQ3013040 actions are spammy@yatta-it.com,store,forward Aug 24 10:41:54 tommy MailScanner[12961]: MCP Checks completed at 2544 bytes per second Aug 24 10:41:54 tommy MailScanner[12961]: Spam Checks: Starting Aug 24 10:42:11 tommy MailScanner[12961]: Spam Checks completed at 87 bytes per second Aug 24 10:42:11 tommy MailScanner[12961]: Virus and Content Scanning: Starting Aug 24 10:42:11 tommy MailScanner[12961]: Virus Scanning completed at 3874 bytes per second Aug 24 10:42:11 tommy MailScanner[12961]: Virus Processing completed at 1457 bytes per second Aug 24 10:42:11 tommy MailScanner[12961]: Disinfection completed at 1457 bytes per second Aug 24 10:42:11 tommy MailScanner[12961]: Batch completed at 82 bytes per second (1457 / 17) Aug 24 10:42:11 tommy MailScanner[12961]: Batch (1 message) processed in 17.64 seconds Aug 24 10:42:11 tommy MailScanner[12961]: Logging message l7O8fmQ3013040 to SQL Aug 24 10:42:11 tommy MailScanner[12961]: "Always Looked Up Last" took 0.00 seconds Aug 24 10:42:11 tommy MailScanner[12967]: l7O8fmQ3013040: Logged to MailWatch SQL For spam the behaviour of the new version of MailScanner is equal to the old one: Aug 24 10:45:03 tommy sendmail[13416]: l7O8j2So013416: from=, size=766, class=0, nrcpts=1, msgid=<000e01c7e62b$0d4dc050$5a615558@ws05>, proto=ESMTP, daemon=MTA, relay=[88.85.97.90] Aug 24 10:45:04 tommy MailScanner[13332]: New Batch: Scanning 1 messages, 1206 bytes Aug 24 10:45:04 tommy MailScanner[13332]: MCP Checks: Starting Aug 24 10:45:05 tommy MailScanner[13332]: MCP Checks completed at 5063 bytes per second Aug 24 10:45:05 tommy MailScanner[13332]: Spam Checks: Starting Aug 24 10:45:15 tommy MailScanner[13332]: RBL checks: l7O8j2So013416 found in SBL+XBL Aug 24 10:45:24 tommy MailScanner[13332]: Message l7O8j2So013416 from 88.85.97.90 (grissomofncv@timweld.com) to omissis.com is spam, SBL+XBL, SpamAssassin (not cached, score=12.044, required 4, BAYES_60 1.00, DK_POLICY_SIGNSOME 0.00, JM_TORA_XM 2.41, RAZOR2_CF_RANGE_51_100 0.50, RAZOR2_CF_RANGE_E8_51_100 1.50, RAZOR2_CHECK 0.50, RCVD_IN_XBL 3.03, RDNS_NONE 0.10, URIBL_BLACK 3.00) Aug 24 10:45:24 tommy MailScanner[13332]: Spam Checks: Found 1 spam messages Aug 24 10:45:24 tommy MailScanner[13332]: Spam Actions: message l7O8j2So013416 actions are attachment,spammy@yatta-it.com,store,forward Aug 24 10:45:24 tommy MailScanner[13332]: Spam Checks completed at 63 bytes per second Aug 24 10:45:24 tommy MailScanner[13332]: Virus and Content Scanning: Starting Aug 24 10:45:24 tommy MailScanner[13332]: Virus Scanning completed at 3189 bytes per second Aug 24 10:45:24 tommy MailScanner[13332]: Uninfected: Delivered 1 messages Aug 24 10:45:24 tommy MailScanner[13332]: Virus Processing completed at 1206 bytes per second Aug 24 10:45:24 tommy MailScanner[13332]: Batch completed at 62 bytes per second (1206 / 19) Aug 24 10:45:24 tommy MailScanner[13332]: Batch (1 message) processed in 19.44 seconds Aug 24 10:45:24 tommy MailScanner[13332]: Logging message l7O8j2So013416 to SQL Aug 24 10:45:24 tommy MailScanner[13332]: "Always Looked Up Last" took 0.00 seconds Aug 24 10:45:24 tommy MailScanner[13337]: l7O8j2So013416: Logged to MailWatch SQL Aug 24 10:45:24 tommy sendmail[13432]: l7O8j2So013416: to=, delay=00:00:21, xdelay=00:00:00, mailer=local, pri=120766, dsn=2.0.0, stat=Sent Any hint? Thanks to all! Phil From gmane at tippingmar.com Fri Aug 24 18:24:56 2007 From: gmane at tippingmar.com (Mark Nienberg) Date: Fri Aug 24 18:25:08 2007 Subject: Minimum Attachment Size Message-ID: # The minimum size, in bytes, of any attachment in a message. # If this is set less than or equal to zero, then no size checking is done. # It is very useful to set this to 1 as it removes any zero-length # attachments which may be created by broken viruses. # This can also be the filename of a ruleset. Minimum Attachment Size = 1 I tried setting this to 1 recently, (it had been 0) and found that messages with zero-length attachments were not delivered at all. I expected them tho be delivered without the zero-length attachment. Did I misunderstand the comment? Mark From cparker at swatgear.com Fri Aug 24 19:37:51 2007 From: cparker at swatgear.com (Chris W. Parker) Date: Fri Aug 24 19:37:56 2007 Subject: Modify filename rule regex to allow exception Message-ID: <97FD54B5E57A1842AA1A4B232E47611773EC1A@ati-ex-02.ati.local> Hello, I'd like to modify the following rule to allow an exception: \.[a-z][a-z0-9]{2,3}\s*\.[a-z0-9]{3}$ Found possible filename hiding Is it possible for this rule to be modified to allow .doc.rtf? We get contracts in that format and they get stripped because of the filename hiding. Instead of excepting a user (or sender) from all filename checks with a ruleset or removing this rule entirely, I thought it best to just modify the rule. Or is there a better way to handle this? Thanks, Chris. From Denis.Beauchemin at USherbrooke.ca Fri Aug 24 19:49:42 2007 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Fri Aug 24 19:50:22 2007 Subject: Modify filename rule regex to allow exception In-Reply-To: <97FD54B5E57A1842AA1A4B232E47611773EC1A@ati-ex-02.ati.local> References: <97FD54B5E57A1842AA1A4B232E47611773EC1A@ati-ex-02.ati.local> Message-ID: <46CF2846.50605@USherbrooke.ca> Chris W. Parker a ?crit : > Hello, > > I'd like to modify the following rule to allow an exception: > > \.[a-z][a-z0-9]{2,3}\s*\.[a-z0-9]{3}$ Found possible filename hiding > > Is it possible for this rule to be modified to allow .doc.rtf? > > We get contracts in that format and they get stripped because of the > filename hiding. Instead of excepting a user (or sender) from all > filename checks with a ruleset or removing this rule entirely, I thought > it best to just modify the rule. > > > Or is there a better way to handle this? > > > Thanks, > Chris. > Chris, I think the rules are accepted from top to bottom. So you could put the following line BEFORE the oher one in filename.rules.conf : allow \.doc\.rtf$ - - You could also use the following MailScanner.conf option: # Allow any attachment filenames matching any of the patters listed here. # If this setting is empty, it is ignored and no matches are made. # This can also be the filename of a ruleset. Allow Filenames = Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x62252 F: 819.821.8045 From cparker at swatgear.com Fri Aug 24 20:25:41 2007 From: cparker at swatgear.com (Chris W. Parker) Date: Fri Aug 24 20:25:44 2007 Subject: Modify filename rule regex to allow exception References: <97FD54B5E57A1842AA1A4B232E47611773EC1A@ati-ex-02.ati.local> <46CF2846.50605@USherbrooke.ca> Message-ID: <97FD54B5E57A1842AA1A4B232E4761178EEAD8@ati-ex-02.ati.local> On Friday, August 24, 2007 11:50 AM Denis Beauchemin said: > I think the rules are accepted from top to bottom. So you could put > the following line BEFORE the oher one in filename.rules.conf : > allow \.doc\.rtf$ - - This worked. Thanks Denis! Chris. From MailScanner at ecs.soton.ac.uk Fri Aug 24 20:30:29 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 24 20:30:54 2007 Subject: Minimum Attachment Size In-Reply-To: References: Message-ID: <46CF31D5.2020207@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I will have to check this out. Get back to me if you don't hear anything from me this weekend. Mark Nienberg wrote: > # The minimum size, in bytes, of any attachment in a message. > # If this is set less than or equal to zero, then no size checking is > done. > # It is very useful to set this to 1 as it removes any zero-length > # attachments which may be created by broken viruses. > # This can also be the filename of a ruleset. > Minimum Attachment Size = 1 > > I tried setting this to 1 recently, (it had been 0) and found that > messages with zero-length attachments were not delivered at all. I > expected them tho be delivered without the zero-length attachment. > Did I misunderstand the comment? > > Mark > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Charset: ISO-8859-1 wj4DBQFGzzHWEfZZRxQVtlQRAoKdAJjEUQdE7gQzi0aQap5fonJCtGWXAKDkakiK mUF8j9A3iv0oC8Hp2zStqw== =olqg -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Fri Aug 24 22:03:09 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri Aug 24 22:03:25 2007 Subject: Minimum Attachment Size In-Reply-To: <46CF31D5.2020207@ecs.soton.ac.uk> References: <46CF31D5.2020207@ecs.soton.ac.uk> Message-ID: <46CF478D.9050004@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I just checked this on my own setup, and it appears to work fine. I set the min size to 10k and sent through some messages with small attachments. It put the messages in the outgoing queue with the small attachments replaced with reports, as expected. Julian Field wrote: > * PGP Signed: 08/24/07 at 20:30:30 > > I will have to check this out. Get back to me if you don't hear > anything from me this weekend. > > Mark Nienberg wrote: >> # The minimum size, in bytes, of any attachment in a message. >> # If this is set less than or equal to zero, then no size checking is >> done. >> # It is very useful to set this to 1 as it removes any zero-length >> # attachments which may be created by broken viruses. >> # This can also be the filename of a ruleset. >> Minimum Attachment Size = 1 >> >> I tried setting this to 1 recently, (it had been 0) and found that >> messages with zero-length attachments were not delivered at all. I >> expected them tho be delivered without the zero-length attachment. >> Did I misunderstand the comment? >> >> Mark >> > > Jules > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Charset: ISO-8859-1 wj8DBQFGz0ePEfZZRxQVtlQRAhePAJ9Q4IPjtdcnyCP0dZLp8HYxdm0HQACgpxjQ 6vu3YimAjkByENgQF95t/VQ= =S6CZ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Fri Aug 24 23:05:50 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Fri Aug 24 23:06:03 2007 Subject: Clam and Phishing.Heuristics.Email.SpoofedDomain In-Reply-To: <1187943682.24997.9.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1187943682.24997.9.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: Gareth spake the following on 8/24/2007 1:21 AM: > On Thu, 2007-08-23 at 22:08, Scott Silva wrote: >> Gareth spake the following on 8/23/2007 11:04 AM: >>> Are you using clamavmodule by any chance? >>> >> Yes I am. I thought about using clamd, but don't have enough volume to be >> worth the extra work. > > Ok the problem is causes by a new clamav feature and unfortunetly in the > clamavlib the option is enabled by default (equivilent to having > --no-phishing-restrictedscan option set on clamscan) whereas everywhere > else it is disabled. Attached is a new copy of SweepViruses.pm which > turns the option off when calling clamavmodule and rectifies the > problem. Jules has already fixed the issue in his development copy. > I'll give it a try... Thanks! -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From gmane at tippingmar.com Sat Aug 25 01:47:41 2007 From: gmane at tippingmar.com (Mark Nienberg) Date: Sat Aug 25 01:48:01 2007 Subject: Minimum Attachment Size In-Reply-To: <46CF478D.9050004@ecs.soton.ac.uk> References: <46CF31D5.2020207@ecs.soton.ac.uk> <46CF478D.9050004@ecs.soton.ac.uk> Message-ID: Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > I just checked this on my own setup, and it appears to work fine. > I set the min size to 10k and sent through some messages with small > attachments. It put the messages in the outgoing queue with the small > attachments replaced with reports, as expected. Thanks for checking. I don't know what is happening then, so I'll just set it back to 0 for my system. [root@tesla xinetd.d]# MailScanner -v Running on Linux tesla.tippingmar.com 2.6.20-1.2320.fc5 #1 Tue Jun 12 18:50:38 EDT 2007 i686 athlon i386 GNU/Linux This is Fedora Core release 5 (Bordeaux) This is Perl version 5.008008 (5.8.8) This is MailScanner version 4.62.9 Mark From hvdkooij at vanderkooij.org Sat Aug 25 11:13:23 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sat Aug 25 11:13:45 2007 Subject: How can MailScanner "push back"? In-Reply-To: <46CDC919.3000304@pa.net> References: <46CDC919.3000304@pa.net> Message-ID: On Thu, 23 Aug 2007, Leland J. Steinke wrote: > Has anybody set up a scheme where MailScanner tells the MTA to stop or slow > message acceptance, short of blocking inbound port 25, when message scanning > gets too far behind? > > We use postfix (so I will try not to reply to my own message). I have been > playing with the idea of tuning the number of inbound smtpd processes in > master.cf to match the capacity of the MailScanner instance running on the > underlying hardware. The initial results are not particularly encouraging. > Even with in-house RBLs and reduced spam-score thresholds for RBL addition, > some of our servers are being overrun with apparent StormWorm emails from IPs > all over the map, reducing the RBL's effectiveness. > > As another way to slow the onslaught in postfix, I added extra client and > HELO restrictions, adding reject_unknown_client and reject_unknown_hostname > to smtpd_{client,helo}_restrictions, respectively. It looks like the HELO > restriction is blocking almost as much legitimate mail as illegitimate. Here is one I find very usefull. It blocks a significant of user connections from networks I have nothing to do with. Adjust to your own needs. /etc/postfix/dynamic_networks: # # Dynamic Networks # /^adsl.*$/ reject_dynamic /^dhcp.*$/ reject_dynamic /^cable.*$/ reject_dynamic /^dialup.*$/ reject_dynamic /^dsl-.*$/ reject_dynamic /^dslnet.*$/ reject_dynamic /^dyn-.*$/ reject_dynamic /^dynamic-.*$/ reject_dynamic /^host.*$/ reject_dynamic /^ip-.*$/ reject_dynamic /^netblock-.*$/ reject_dynamic /^ppp.*$/ reject_dynamic /^static.*$/ reject_dynamic in /etc/postfix/main.cf: smtpd_restriction_classes = reject_RFC, reject_auto, reject_auto_virus, reject_domain, reject_dynamic, reject_infected, reject_spam, reject_user reject_RFC = check_client_access regexp:/etc/postfix/class/reject_RFC reject_auto = check_client_access regexp:/etc/postfix/class/reject_auto reject_auto_virus = check_client_access regexp:/etc/postfix/class/reject_auto_virus reject_domain = check_client_access regexp:/etc/postfix/class/reject_domain reject_dynamic = check_client_access regexp:/etc/postfix/class/reject_dynamic reject_infected = check_client_access regexp:/etc/postfix/class/reject_infected reject_spam = check_client_access regexp:/etc/postfix/class/reject_spam reject_user = check_client_access regexp:/etc/postfix/class/reject_user mtpd_client_restrictions = ...... regexp:/etc/postfix/dynamic_networks, ...... in /etc/postfix/class/reject_dynamic: /./ REJECT Dynamic (Cable, Dialup or DSL) network access denied; Use a smarthost instead (http://en.wikipedia.org/wiki/Smart_host) Combine it with other entries and it got me a significant decrease of messages I actually have to scan. For example any host ending with abo.wanadoo.fr has nothing to do with SMTP here either. While not a perfect solutions tricks like these may reduce the amount of messages you have to scan from unworkable to managable. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for this quote of George Bernard Shaw.) From v at vladville.com Sun Aug 26 03:58:07 2007 From: v at vladville.com (Vlad Mazek) Date: Sun Aug 26 03:58:15 2007 Subject: Redirecting *.spamhaus.org queries to local feed server Message-ID: Ok, so setup a local rbldnsd server for a spamhaus feed. Stupid question: how do I tell MailScanner/spamassassin to redirect *.spamhaus.com queries to my rbldnsd server? -Vlad -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070825/a8f95be7/attachment.html From doc at maddoc.net Sun Aug 26 06:14:38 2007 From: doc at maddoc.net (Doc Schneider) Date: Sun Aug 26 06:14:51 2007 Subject: Redirecting *.spamhaus.org queries to local feed server In-Reply-To: References: Message-ID: <46D10C3E.9080004@maddoc.net> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Vlad Mazek wrote: > Ok, so setup a local rbldnsd server for a spamhaus feed. > > Stupid question: how do I tell MailScanner/spamassassin to redirect > *.spamhaus.com queries to my rbldnsd server? > > -Vlad > For a caching name server zone "zen.spamhaus.org" { type forward; forward only; forwarders { 1.2.3.4; }; }; Of course change to 1.2.3.4 to the IP of your rbldnsd server. - -- - -Doc Lincoln, NE. http://www.genealogyforyou.com/ http://www.cairnproductions.com/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (GNU/Linux) Comment: Using GnuPG with CentOS - http://enigmail.mozdev.org iD8DBQFG0Qw+qOEeBwEpgcsRAlV1AJ93DMJE+gj2Ll4my38s3q15maYmWACeK2n1 i+3HzfTlJgkgiczcC6CWp5Q= =3qrW -----END PGP SIGNATURE----- From ms-list at alexb.ch Sun Aug 26 08:56:46 2007 From: ms-list at alexb.ch (Alex Broens) Date: Sun Aug 26 08:56:50 2007 Subject: Redirecting *.spamhaus.org queries to local feed server In-Reply-To: <46D10C3E.9080004@maddoc.net> References: <46D10C3E.9080004@maddoc.net> Message-ID: <46D1323E.4050100@alexb.ch> On 8/26/2007 7:14 AM, Doc Schneider wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Vlad Mazek wrote: >> Ok, so setup a local rbldnsd server for a spamhaus feed. >> >> Stupid question: how do I tell MailScanner/spamassassin to redirect >> *.spamhaus.com queries to my rbldnsd server? >> >> -Vlad >> > > For a caching name server > > zone "zen.spamhaus.org" { > type forward; > forward only; > forwarders { 1.2.3.4; }; > }; > > > Of course change to 1.2.3.4 to the IP of your rbldnsd server. that's not enough URIBL_SBL in 25_uribl.cf queries sbl.spamhaus.org so you'll also need zone "sbl.spamhaus.org" IN { type forward; forward first; forwarders { 1.2.3.4; }; }; Alex From v at vladville.com Sun Aug 26 15:48:52 2007 From: v at vladville.com (Vlad Mazek) Date: Sun Aug 26 15:48:57 2007 Subject: Redirecting *.spamhaus.org queries to local feed server In-Reply-To: <46D1323E.4050100@alexb.ch> References: <46D10C3E.9080004@maddoc.net> <46D1323E.4050100@alexb.ch> Message-ID: Should I have equivalent zones for PBL as well or is ZEN enough? -Vlad On 8/26/07, Alex Broens wrote: > > On 8/26/2007 7:14 AM, Doc Schneider wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > > Hash: SHA1 > > > > Vlad Mazek wrote: > >> Ok, so setup a local rbldnsd server for a spamhaus feed. > >> > >> Stupid question: how do I tell MailScanner/spamassassin to redirect > >> *.spamhaus.com queries to my rbldnsd server? > >> > >> -Vlad > >> > > > > For a caching name server > > > > zone "zen.spamhaus.org" { > > type forward; > > forward only; > > forwarders { 1.2.3.4; }; > > }; > > > > > > Of course change to 1.2.3.4 to the IP of your rbldnsd server. > > that's not enough > > URIBL_SBL in 25_uribl.cf queries sbl.spamhaus.org so you'll also need > > zone "sbl.spamhaus.org" IN { > type forward; > forward first; > forwarders { 1.2.3.4; }; > }; > > Alex > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- -Vlad -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070826/2c0f0e29/attachment.html From ms-list at alexb.ch Sun Aug 26 16:54:38 2007 From: ms-list at alexb.ch (Alex Broens) Date: Sun Aug 26 16:54:44 2007 Subject: Redirecting *.spamhaus.org queries to local feed server In-Reply-To: References: <46D10C3E.9080004@maddoc.net> <46D1323E.4050100@alexb.ch> Message-ID: <46D1A23E.8020508@alexb.ch> On 8/26/2007 4:48 PM, Vlad Mazek wrote: > Should I have equivalent zones for PBL as well or is ZEN enough? Nope PBL lookups happen thru Zen See 20_dnsbl_tests.cf Alex > -Vlad > > On 8/26/07, Alex Broens wrote: >> On 8/26/2007 7:14 AM, Doc Schneider wrote: >>> -----BEGIN PGP SIGNED MESSAGE----- >>> Hash: SHA1 >>> >>> Vlad Mazek wrote: >>>> Ok, so setup a local rbldnsd server for a spamhaus feed. >>>> >>>> Stupid question: how do I tell MailScanner/spamassassin to redirect >>>> *.spamhaus.com queries to my rbldnsd server? >>>> >>>> -Vlad >>>> >>> For a caching name server >>> >>> zone "zen.spamhaus.org" { >>> type forward; >>> forward only; >>> forwarders { 1.2.3.4; }; >>> }; >>> >>> >>> Of course change to 1.2.3.4 to the IP of your rbldnsd server. >> that's not enough >> >> URIBL_SBL in 25_uribl.cf queries sbl.spamhaus.org so you'll also need >> >> zone "sbl.spamhaus.org" IN { >> type forward; >> forward first; >> forwarders { 1.2.3.4; }; >> }; >> >> Alex >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> > > > From MailScanner at ecs.soton.ac.uk Sun Aug 26 21:04:43 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun Aug 26 21:05:08 2007 Subject: Redirecting *.spamhaus.org queries to local feed server In-Reply-To: <46D1A23E.8020508@alexb.ch> References: <46D10C3E.9080004@maddoc.net> <46D1323E.4050100@alexb.ch> <46D1A23E.8020508@alexb.ch> Message-ID: <46D1DCDB.1040106@ecs.soton.ac.uk> In my setup, which has all the zones, the only ones that get queried are zen (600k queries) and sbl (1.4m queries). Both xbl and pbl have had 0 queries. Alex Broens wrote: > On 8/26/2007 4:48 PM, Vlad Mazek wrote: >> Should I have equivalent zones for PBL as well or is ZEN enough? > > Nope > > PBL lookups happen thru Zen > See 20_dnsbl_tests.cf > > Alex > >> -Vlad >> >> On 8/26/07, Alex Broens wrote: >>> On 8/26/2007 7:14 AM, Doc Schneider wrote: >>>> -----BEGIN PGP SIGNED MESSAGE----- >>>> Hash: SHA1 >>>> >>>> Vlad Mazek wrote: >>>>> Ok, so setup a local rbldnsd server for a spamhaus feed. >>>>> >>>>> Stupid question: how do I tell MailScanner/spamassassin to redirect >>>>> *.spamhaus.com queries to my rbldnsd server? >>>>> >>>>> -Vlad >>>>> >>>> For a caching name server >>>> >>>> zone "zen.spamhaus.org" { >>>> type forward; >>>> forward only; >>>> forwarders { 1.2.3.4; }; >>>> }; >>>> >>>> >>>> Of course change to 1.2.3.4 to the IP of your rbldnsd server. >>> that's not enough >>> >>> URIBL_SBL in 25_uribl.cf queries sbl.spamhaus.org so you'll also need >>> >>> zone "sbl.spamhaus.org" IN { >>> type forward; >>> forward first; >>> forwarders { 1.2.3.4; }; >>> }; >>> >>> Alex >>> >>> -- >>> MailScanner mailing list >>> mailscanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> >>> Before posting, read http://wiki.mailscanner.info/posting >>> >>> Support MailScanner development - buy the book off the website! >>> >> >> >> > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From wizard at jimhermann.com Sun Aug 26 21:20:44 2007 From: wizard at jimhermann.com (Jim Hermann) Date: Sun Aug 26 21:21:32 2007 Subject: Outgoing Queue Dir Ruleset In-Reply-To: <200708261100.l7QB02E8013272@safir.blacknight.ie> References: <200708261100.l7QB02E8013272@safir.blacknight.ie> Message-ID: <000801c7e81e$953686b0$cc01a8c0@Dual> I have trying to create a ruleset for Outgoing Queue Dir and it does not appear to work. In MailScanner.conf, I changed to: Outgoing Queue Dir = /etc/MailScanner/rules/outgoing.rules My /etc/MailScanner/rules/outgoing.rules is: # Set "Outgoing Queue Dir = /etc/MailScanner/rules/outgoing.rules". To: *@aol.com /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.aol To: *@comcast.net /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.comcast FromOrTo: default /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.scanned I created the new directories in /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/: drwxr-xr-x 6 root root 4.0K Aug 26 14:02 . drwxr-xr-x 4 root root 4.0K Sep 15 2006 .. drwxr-xr-x 2 root root 64K Aug 26 15:14 mqueue drwxr-xr-x 2 root root 4.0K Aug 26 14:01 mqueue.aol drwxr-xr-x 2 root root 4.0K Aug 26 14:01 mqueue.comcast drwxr-xr-x 2 root root 32K Aug 26 15:12 mqueue.scanned I restarted MailScanner and all email stopped moving from the Incoming Queue Dir to anywhere. What did I do wrong? Jim From MailScanner at ecs.soton.ac.uk Sun Aug 26 21:29:25 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun Aug 26 21:29:43 2007 Subject: Outgoing Queue Dir Ruleset In-Reply-To: <000801c7e81e$953686b0$cc01a8c0@Dual> References: <200708261100.l7QB02E8013272@safir.blacknight.ie> <000801c7e81e$953686b0$cc01a8c0@Dual> Message-ID: <46D1E2A5.4090500@ecs.soton.ac.uk> Start by testing them with MailScanner's command-line options. Do a "MailScanner --help" to start with. Is your "Run As User" set to blank (or root)? The last time I tested this functionality it worked just fine, and I think other people use it. If you really can't get it to work with test messages, then mail me back and I'll test it here for you. Make sure your editor hasn't line wrapped the .rules file, the version you posted to the list has been wrapped. Jim Hermann wrote: > I have trying to create a ruleset for Outgoing Queue Dir and it does not > appear to work. > > In MailScanner.conf, I changed to: > > Outgoing Queue Dir = /etc/MailScanner/rules/outgoing.rules > > My /etc/MailScanner/rules/outgoing.rules is: > > # Set "Outgoing Queue Dir = /etc/MailScanner/rules/outgoing.rules". > > To: *@aol.com > /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.aol > To: *@comcast.net > /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.comcast > > FromOrTo: default > /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.scanned > > I created the new directories in > /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/: > > drwxr-xr-x 6 root root 4.0K Aug 26 14:02 . > drwxr-xr-x 4 root root 4.0K Sep 15 2006 .. > drwxr-xr-x 2 root root 64K Aug 26 15:14 mqueue > drwxr-xr-x 2 root root 4.0K Aug 26 14:01 mqueue.aol > drwxr-xr-x 2 root root 4.0K Aug 26 14:01 mqueue.comcast > drwxr-xr-x 2 root root 32K Aug 26 15:12 mqueue.scanned > > I restarted MailScanner and all email stopped moving from the Incoming Queue > Dir to anywhere. > > What did I do wrong? > > Jim > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Sun Aug 26 21:54:18 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun Aug 26 21:55:31 2007 Subject: Outgoing Queue Dir Ruleset In-Reply-To: <46D1E2A5.4090500@ecs.soton.ac.uk> References: <200708261100.l7QB02E8013272@safir.blacknight.ie> <000801c7e81e$953686b0$cc01a8c0@Dual> <46D1E2A5.4090500@ecs.soton.ac.uk> Message-ID: <46D1E87A.9060601@ecs.soton.ac.uk> I have just tested this code, and it works just fine. Are you sure it hadn't put the files in the outgoing queue directories and then delivered them before you had time to look in the directories? Julian Field wrote: > Start by testing them with MailScanner's command-line options. > Do a "MailScanner --help" to start with. > Is your "Run As User" set to blank (or root)? > The last time I tested this functionality it worked just fine, and I > think other people use it. > If you really can't get it to work with test messages, then mail me > back and I'll test it here for you. > > Make sure your editor hasn't line wrapped the .rules file, the version > you posted to the list has been wrapped. > > Jim Hermann wrote: >> I have trying to create a ruleset for Outgoing Queue Dir and it does not >> appear to work. >> >> In MailScanner.conf, I changed to: >> >> Outgoing Queue Dir = /etc/MailScanner/rules/outgoing.rules >> >> My /etc/MailScanner/rules/outgoing.rules is: >> >> # Set "Outgoing Queue Dir = /etc/MailScanner/rules/outgoing.rules". >> >> To: *@aol.com >> /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.aol >> To: *@comcast.net >> /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.comcast >> >> FromOrTo: default >> /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.scanned >> >> I created the new directories in >> /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/: >> >> drwxr-xr-x 6 root root 4.0K Aug 26 14:02 . >> drwxr-xr-x 4 root root 4.0K Sep 15 2006 .. >> drwxr-xr-x 2 root root 64K Aug 26 15:14 mqueue >> drwxr-xr-x 2 root root 4.0K Aug 26 14:01 mqueue.aol >> drwxr-xr-x 2 root root 4.0K Aug 26 14:01 mqueue.comcast >> drwxr-xr-x 2 root root 32K Aug 26 15:12 mqueue.scanned >> >> I restarted MailScanner and all email stopped moving from the >> Incoming Queue >> Dir to anywhere. >> >> What did I do wrong? >> >> Jim >> >> > > Jules > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From eersana at yahoo.com Mon Aug 27 02:53:18 2007 From: eersana at yahoo.com (anas asree) Date: Mon Aug 27 02:53:20 2007 Subject: Block Certain Yahoo Mail List In-Reply-To: Message-ID: <86780.55135.qm@web39802.mail.mud.yahoo.com> I'm using Postfix + Mailscanner Some of my users subscribe to certain yahoo mail list which is not related to their work.. How can I reject/blacklist that particular mail list ? --------------------------------- Got a little couch potato? Check out fun summer activities for kids. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070826/2286c0aa/attachment.html From bahadir.kiziltan at gmail.com Mon Aug 27 06:27:49 2007 From: bahadir.kiziltan at gmail.com (Bahadir Kiziltan) Date: Mon Aug 27 06:27:53 2007 Subject: Block Certain Yahoo Mail List In-Reply-To: <86780.55135.qm@web39802.mail.mud.yahoo.com> References: <86780.55135.qm@web39802.mail.mud.yahoo.com> Message-ID: On 8/27/07, anas asree wrote: > I'm using Postfix + Mailscanner > > Some of my users subscribe to certain yahoo mail list which is not related > to their work.. > > How can I reject/blacklist that particular mail list ? > take a look at the header of a mail coming from the mail list. you should see a line with "List-ID" string. then add the similar entry below to header_cheks file located at /etc/postfix directory by modifying the mail list name accordingly. /^List-Id: $/ REJECT lastly, stop/start postfix daemon. From MailScanner at ecs.soton.ac.uk Mon Aug 27 12:17:24 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 27 12:17:43 2007 Subject: Release 4.63.4 Message-ID: <46D2B2C4.1090504@ecs.soton.ac.uk> Hi folks! I hope all of you in the UK are having a nice day off, it's the last one before Christmas :-( I have just released beta 4.63.4, which will turn into the stable release at the start of September, unless anything important happens before then. The new feature in this release that is not in the previous beta is that in the "SpamAssassin Rule Actions" feature, you can now specify a comma-separated list of actions for each each RULE=>action statement in it, saving you having to specify the RULE once for each action. Please let me know of any bugs in this release, as I want to get them fixed before the stable release on 1st September. Download as usual from www.mailscanner.info. The full Change Log for this release is this: * New Features and Improvements * 1 Improved init.d script, so that 'service MailScanner restart' or '/etc/init.d/MailScanner restart' runs faster. It pauses for just long enough for the old MailScanner to die gracefully, and starts up the new one as soon as the old one has died. Previously, it just waited for a fixed length of time which was much longer than needed for most people. 1 Improved tar installer so the directory created for MailScanner includes the build revision number as well as the main version number. 1 Improved phishing net logging to log entire real URL not just hostname. 1 Improvement to update_spamassassin to stop cron-generated mail. 1 New setting "Phishing Bad Sites File" which is a live continuously-updated list of known bad sites that have been reported to various mechanisms around the world. Please don't ask me for more information as I can't give it to you, but every site on the list has been manually tested and the list can be relied upon. Your installation should update this file every hour. NOTE: Run upgrade_languages_conf after installing this upgrade! 2 Reduce default "Restart Every" time to 2 hours so that updates to the known bad phishing sites list are re-read more frequently. 2 Added *.fdf to the list of dangerous filenames. Opening a .fdf file can cause the loading of any file on the internet into Adobe Acrobat. 2 Added 2 new variables to the sender reports: $size = size of message in bytes and $maxmessagesize = maximum allowed size of this message in bytes. 2 Added new setting "Check Filenames In Password-Protected Archives = yes" so that the filename checks can be suppressed on encrypted archives to allow a few people to get exe's and so on through the mail as part of their business needs. Normally leave this setting at "yes". 2 Added new setting "Include Binary Attachments In SpamAssassin = no" which can be used to tell SpamAssassin to look at all attachments, not just the ones containing text (or HTML, etc) which is its normal behaviour. Changing this setting to "yes" will have no effect without a patch to the SpamAssassin code, which you can fetch from http://www.mailscanner.info/mcp.html#patches It will slightly slow down SpamAssassin some of the time, and is therefore disabled by default. This can be very useful if you want to look for rude or derogatory content in messages, and do not want the huge speed impact of using MCP. It can successfully scan the content of Microsoft Word documents, for example. It won't be effective on PDF files however, as these are compressed internally so there is no readable text anywhere in the file. 3 Added a long $PATH to f-prot-autoupdate so we can find wget on most OS-es including Solaris. 3 Improved Sophos.install to disable the savupdate cron job and switch off the unwanted Sophos services. 3 Added a feature to the "SpamAssassin Rule Actions". You can now specify "SpamScore" and a number comparison, instead of just giving a SpamAssassin rule name. So you can say SpamAssassin Rule Actions = SpamScore>25=>delete and this will cause all messages scoring over 25 to be deleted. You can use this to set different actions at different spam scores, in addition to the normal spam actions and high-scoring spam actions. The numerical tests you can use are ">", ">=", "==", "<=" and "<". 4 The "action" in each "RULE=>action" in "SpamAssassin Rule Actions" can now be a comma-separated list of actions, so you can easily specify multiple actions per rule. * Fixes * 1 Improvement to phishing net to allow HTML tags with contents split over multiple lines. 1 Changed options to ClamAVmodule so it doesn't hit false positives with the phishing and scam email detection signatures. 1-2 Fixed bug where --lint gives "MailScanner.conf file not found" error. 2 Stopped writing a PID file when "MailScanner --lint" is run. 2 update_spamassassin no longer produces any output, so no crond email. 2 Fixed bug where clamavmodule scanner name wouldn't always be logged correctly. 2 Bugfix in ZMDiskStore.pm ZMailer support from Leonardo Helman. 3 Force installation of perl-Getopt-Long to try to solve the problems with command-line options producing 'config file not found' errors. 3 Commented out sample rules in max.message.size.rules file. 3 Fixed MailScanner.conf Sophos-specific settings for Sophos 5. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From jaearick at colby.edu Mon Aug 27 14:56:50 2007 From: jaearick at colby.edu (Jeff A. Earickson) Date: Mon Aug 27 14:57:24 2007 Subject: mailscanner as a front-end, help! Message-ID: Gang, I slid my legacy MailScanner system back in front of my email appliance this morning to block spam. I've got a problem with non-existent/dictionary attack addresses now. They get sent on to the appliance, who doesn't know the address, thence back to the front-end, unroutable -- mail loop, too many hops. I need MailScanner/sendmail to kill non-existent addresses up front. I found milter-ahead (costs euros). Any other ideas? Virtusertables, like http://q.queso.com/archives/002025? My setup: sendmail 8.14.1, MailScanner 4.62.9, SA and the other anti-spam additions. sendmail running as "define(`MAIL_HUB'" setting to pass all (non-spam) email on to the appliance for local delivery. Jeff Earickson Colby College From glenn.steen at gmail.com Mon Aug 27 15:05:25 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Mon Aug 27 15:05:29 2007 Subject: mailscanner as a front-end, help! In-Reply-To: References: Message-ID: <223f97700708270705r71036dcu7a65b3ac5bd9b72b@mail.gmail.com> On 27/08/07, Jeff A. Earickson wrote: > Gang, > > I slid my legacy MailScanner system back in front of my email > appliance this morning to block spam. I've got a problem with > non-existent/dictionary attack addresses now. They get sent > on to the appliance, who doesn't know the address, thence back > to the front-end, unroutable -- mail loop, too many hops. > I need MailScanner/sendmail to kill non-existent addresses up > front. I found milter-ahead (costs euros). Any other ideas? > Virtusertables, like http://q.queso.com/archives/002025? > > My setup: sendmail 8.14.1, MailScanner 4.62.9, SA and the other > anti-spam additions. sendmail running as "define(`MAIL_HUB'" > setting to pass all (non-spam) email on to the appliance for > local delivery. > > Jeff Earickson > Colby College smf-sav can do this, I gather... But depending on how tyhings are set, it might not help (if the appliance doesn't correctly reject the non-existant recipients...). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From mailadmin at baladia.gov.kw Mon Aug 27 16:02:15 2007 From: mailadmin at baladia.gov.kw (mailadmin@baladia.gov.kw) Date: Mon Aug 27 16:04:06 2007 Subject: how to install updated SA+clamAV Message-ID: <2407.62.150.152.226.1188226935.squirrel@webmail.baladia.gov.kw> Dear All, I have a recently installed the following on Centos 5 as per the install docs CentOS5 MailScanner-4.62.9-3 Clam-0.91.1-SA-3.2.3 n its been workin perfectly fine the clamAV 0.91.1 is already outdated and since some bugs were reported in the ClamAV 0.91.2 i jus waited. now i see on mailscanner site the updated Clam-0.91.2-SA-3.2.3 jules script 1) now since its on mailscanner site obviously its perfectly OK to upgrade ClamAV to 0.91.2 2) how cd i update my clamav to 0.91.2 as when i installed it before i installed clamav, clamdb & clamd from dagwiers rpm site as i wanted clamd support for mailscanner and only installed SA running the install.sh script from Clam-0.91.1-SA-3.2.3 easy installtion package apprecite your help regards simon -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ka at pacific.net Mon Aug 27 16:07:14 2007 From: ka at pacific.net (Ken A) Date: Mon Aug 27 16:07:15 2007 Subject: mailscanner as a front-end, help! In-Reply-To: <223f97700708270705r71036dcu7a65b3ac5bd9b72b@mail.gmail.com> References: <223f97700708270705r71036dcu7a65b3ac5bd9b72b@mail.gmail.com> Message-ID: <46D2E8A2.6010908@pacific.net> Glenn Steen wrote: > On 27/08/07, Jeff A. Earickson wrote: >> Gang, >> >> I slid my legacy MailScanner system back in front of my email >> appliance this morning to block spam. I've got a problem with >> non-existent/dictionary attack addresses now. They get sent >> on to the appliance, who doesn't know the address, thence back >> to the front-end, unroutable -- mail loop, too many hops. >> I need MailScanner/sendmail to kill non-existent addresses up >> front. I found milter-ahead (costs euros). Any other ideas? >> Virtusertables, like http://q.queso.com/archives/002025? >> >> My setup: sendmail 8.14.1, MailScanner 4.62.9, SA and the other >> anti-spam additions. sendmail running as "define(`MAIL_HUB'" >> setting to pass all (non-spam) email on to the appliance for >> local delivery. >> >> Jeff Earickson >> Colby College > smf-sav can do this, I gather... But depending on how tyhings are set, > it might not help (if the appliance doesn't correctly reject the > non-existant recipients...). > > Cheers In the past, I used a script to generate a sendmail access list to do this, with To:user@domain RELAY and a default TO:domain Err..'no such user' at the bottom. That was replaced a while ago with smf-sav. Both methods work well. -- Ken Anderson Pacific.Net From Richard.Frovarp at sendit.nodak.edu Mon Aug 27 16:09:13 2007 From: Richard.Frovarp at sendit.nodak.edu (Richard Frovarp) Date: Mon Aug 27 16:09:18 2007 Subject: how to install updated SA+clamAV In-Reply-To: <2407.62.150.152.226.1188226935.squirrel@webmail.baladia.gov.kw> References: <2407.62.150.152.226.1188226935.squirrel@webmail.baladia.gov.kw> Message-ID: <46D2E919.40308@sendit.nodak.edu> mailadmin@baladia.gov.kw wrote: > Dear All, > > I have a recently installed the following on Centos 5 as per the install > docs > > CentOS5 > MailScanner-4.62.9-3 > Clam-0.91.1-SA-3.2.3 > > n its been workin perfectly fine > > the clamAV 0.91.1 is already outdated and since some bugs were reported in > the ClamAV 0.91.2 i jus waited. > > now i see on mailscanner site the updated Clam-0.91.2-SA-3.2.3 jules script > > 1) now since its on mailscanner site obviously its perfectly OK to upgrade > ClamAV to 0.91.2 > > 2) how cd i update my clamav to 0.91.2 > as when i installed it before i installed clamav, clamdb & clamd from > dagwiers rpm site as i wanted clamd support for mailscanner and only > installed SA running the install.sh script from Clam-0.91.1-SA-3.2.3 easy > installtion package > > Then get the RPMs from dagwiers site and upgrade that way. From MailScanner at ecs.soton.ac.uk Mon Aug 27 16:25:40 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 27 16:26:01 2007 Subject: how to install updated SA+clamAV In-Reply-To: <2407.62.150.152.226.1188226935.squirrel@webmail.baladia.gov.kw> References: <2407.62.150.152.226.1188226935.squirrel@webmail.baladia.gov.kw> Message-ID: <46D2ECF4.5070305@ecs.soton.ac.uk> mailadmin@baladia.gov.kw wrote: > Dear All, > > I have a recently installed the following on Centos 5 as per the install > docs > > CentOS5 > MailScanner-4.62.9-3 > Clam-0.91.1-SA-3.2.3 > > n its been workin perfectly fine > > the clamAV 0.91.1 is already outdated and since some bugs were reported in > the ClamAV 0.91.2 i jus waited. > > now i see on mailscanner site the updated Clam-0.91.2-SA-3.2.3 jules script > > 1) now since its on mailscanner site obviously its perfectly OK to upgrade > ClamAV to 0.91.2 > I would personally not install 0.91.2. > 2) how cd i update my clamav to 0.91.2 > as when i installed it before i installed clamav, clamdb & clamd from > dagwiers rpm site as i wanted clamd support for mailscanner and only > installed SA running the install.sh script from Clam-0.91.1-SA-3.2.3 easy > installtion package > Don't install 0.91.2, wait for 0.91.3. 0.91.1 will work perfectly well for you. > > apprecite your help > > > regards > > simon > > > > > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From chen at hhmi.umbc.edu Mon Aug 27 16:38:42 2007 From: chen at hhmi.umbc.edu (Yu Chen) Date: Mon Aug 27 16:38:45 2007 Subject: how to install updated SA+clamAV In-Reply-To: <46D2ECF4.5070305@ecs.soton.ac.uk> References: <2407.62.150.152.226.1188226935.squirrel@webmail.baladia.gov.kw> <46D2ECF4.5070305@ecs.soton.ac.uk> Message-ID: >> installed SA running the install.sh script from Clam-0.91.1-SA-3.2.3 easy >> installtion package >> > Don't install 0.91.2, wait for 0.91.3. > 0.91.1 will work perfectly well for you. Hmmm... I am just about to put MailScanner together with Clam 0.91.2 on the newly installed system, so do you mean I should not install Clam0.91.2 this time? Thanks, CY > >> >> apprecite your help >> >> >> regards >> >> simon >> >> >> >> >> >> >> > > Jules > > =========================================== Yu Chen Howard Hughes Medical Institute Chemistry Building, Rm 182 University of Maryland at Baltimore County 1000 Hilltop Circle Baltimore, MD 21250 phone: (410)455-1728 (primary) (410)455-6347 (secondary) fax: (410)455-1174 email: chen@hhmi.umbc.edu =========================================== From mailadmin at baladia.gov.kw Mon Aug 27 17:24:56 2007 From: mailadmin at baladia.gov.kw (mailadmin@baladia.gov.kw) Date: Mon Aug 27 17:26:37 2007 Subject: how to install updated SA+clamAV Message-ID: <2720.62.150.152.226.1188231896.squirrel@webmail.baladia.gov.kw> Dear All, I have a recently installed the following on Centos 5 as per the install docs CentOS5 MailScanner-4.62.9-3 Clam-0.91.1-SA-3.2.3 n its been workin perfectly fine the clamAV 0.91.1 is already outdated and since some bugs were reported in the ClamAV 0.91.2 i jus waited. now i see on mailscanner site the updated Clam-0.91.2-SA-3.2.3 jules script 1) now since its on mailscanner site obviously its perfectly OK to upgrade ClamAV to 0.91.2 2) how cd i update my clamav to 0.91.2 as when i installed it before i installed clamav, clamdb & clamd from dagwiers rpm site as i wanted clamd support for mailscanner and only installed SA running the install.sh script from Clam-0.91.1-SA-3.2.3 easy installtion package apprecite your help regards simon -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From maillists at conactive.com Mon Aug 27 17:31:30 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Mon Aug 27 17:31:40 2007 Subject: how to install updated SA+clamAV In-Reply-To: <2407.62.150.152.226.1188226935.squirrel@webmail.baladia.gov.kw> References: <2407.62.150.152.226.1188226935.squirrel@webmail.baladia.gov.kw> Message-ID: wrote on Mon, 27 Aug 2007 18:02:15 +0300 (AST): > CentOS5 You want to use yum for upgrading installed packages. Subscribe to the centos mailing list and read a bit of documentation about CentOS. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From tobias.axelsson at vxu.se Mon Aug 27 18:17:33 2007 From: tobias.axelsson at vxu.se (Tobias Axelsson) Date: Mon Aug 27 18:17:41 2007 Subject: SLES 10 experience References: <006801c7e09d$a4f44e30$ad582fc2@taxbrbr> <223f97700708170149s15085a11r2e3c01500528412@mail.gmail.com> Message-ID: <004d01c7e8ce$287cc100$7a01a8c0@taxbrbr> Hi Well, don't got any sun this summer, eccept for my holiday in bulgaria :) Need to go to warm places when you living in this mess of clouds, rain and wind. So who are you, what you working with? Cheers, Tobias ----- Original Message ----- From: "Glenn Steen" To: "MailScanner discussion" Sent: Friday, August 17, 2007 10:49 AM Subject: Re: SLES 10 experience On 17/08/07, Tobias Axelsson wrote: > > > > > Hi > > I have now in 3 years running mailscanner/mailwatch on Suse linux > enterprise > server 9 on three servers almost without problem. > > Now we need more performance and gonna replace them with three new > bladeservers 2x4quadcore/6GB ram and no disk. > > Becourse of the blade-structure, I gonna need to san-boot them, (the > systemdisk is a SAN-disk) and therefor it requires SuSE linux enterprise > 10. > Do someone have good experience with SLES10? A lot is changed... Tjena Tobias, I have no real experience, but there have been several indications on the list that the latest and greatest MailScanner works OK on that plattform. > Thanks, Tobias > Sweden How is V?xj?? I hear from my kids (visiting the in-laws) that the weather finally has turned into something resembling summer...:-) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From wizard at jimhermann.com Mon Aug 27 18:40:58 2007 From: wizard at jimhermann.com (Jim Hermann) Date: Mon Aug 27 18:47:44 2007 Subject: Outgoing Queue Dir Ruleset In-Reply-To: <46D1E87A.9060601@ecs.soton.ac.uk> References: <200708261100.l7QB02E8013272@safir.blacknight.ie> <000801c7e81e$953686b0$cc01a8c0@Dual><46D1E2A5.4090500@ecs.soton.ac.uk> <46D1E87A.9060601@ecs.soton.ac.uk> Message-ID: <00c301c7e8d1$6dc1e120$cc01a8c0@Dual> It's possible. Does MailScanner automatically add the -OQueueDirectory="Outgoing Queue Dir" argument for Sendmail2? It looks like it does. I was not expecting it. I had: Sendmail2 = /usr/sbin/sendmail -L sm-MailScanner -OProcessTitlePrefix=sm-MailScanner -ODeliveryMode=background -OQueueDirectory=/home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.s canned -C /etc/mail/sm-MailScanner.cf So I changed it to: Sendmail2 = /usr/sbin/sendmail -L sm-mailscanner -OProcessTitlePrefix=sm-mailscanner -ODeliveryMode=background -C /etc/mail/sm-MailScanner.cf Jim > -----Original Message----- > From: Julian Field [mailto:MailScanner@ecs.soton.ac.uk] > Sent: Sunday, August 26, 2007 03:54 PM > To: MailScanner discussion > Subject: Re: Outgoing Queue Dir Ruleset > > I have just tested this code, and it works just fine. > Are you sure it hadn't put the files in the outgoing queue > directories > and then delivered them before you had time to look in the > directories? > > Julian Field wrote: > > Start by testing them with MailScanner's command-line options. > > Do a "MailScanner --help" to start with. > > Is your "Run As User" set to blank (or root)? > > The last time I tested this functionality it worked just > fine, and I > > think other people use it. > > If you really can't get it to work with test messages, then mail me > > back and I'll test it here for you. > > > > Make sure your editor hasn't line wrapped the .rules file, > the version > > you posted to the list has been wrapped. > > > > Jim Hermann wrote: > >> I have trying to create a ruleset for Outgoing Queue Dir > and it does not > >> appear to work. > >> > >> In MailScanner.conf, I changed to: > >> > >> Outgoing Queue Dir = /etc/MailScanner/rules/outgoing.rules > >> > >> My /etc/MailScanner/rules/outgoing.rules is: > >> > >> # Set "Outgoing Queue Dir = > /etc/MailScanner/rules/outgoing.rules". > >> > >> To: *@aol.com > >> /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.aol > >> To: *@comcast.net > >> /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.comcast > >> > >> FromOrTo: default > >> /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.scanned > >> > >> I created the new directories in > >> /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/: > >> > >> drwxr-xr-x 6 root root 4.0K Aug 26 14:02 . > >> drwxr-xr-x 4 root root 4.0K Sep 15 2006 .. > >> drwxr-xr-x 2 root root 64K Aug 26 15:14 mqueue > >> drwxr-xr-x 2 root root 4.0K Aug 26 14:01 mqueue.aol > >> drwxr-xr-x 2 root root 4.0K Aug 26 14:01 mqueue.comcast > >> drwxr-xr-x 2 root root 32K Aug 26 15:12 mqueue.scanned > >> > >> I restarted MailScanner and all email stopped moving from the > >> Incoming Queue > >> Dir to anywhere. > >> > >> What did I do wrong? > >> > >> Jim > >> > >> > > > > Jules > > > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > > From jaearick at colby.edu Mon Aug 27 18:52:59 2007 From: jaearick at colby.edu (Jeff A. Earickson) Date: Mon Aug 27 18:54:42 2007 Subject: mailscanner as a front-end, help! In-Reply-To: <46D2E8A2.6010908@pacific.net> References: <223f97700708270705r71036dcu7a65b3ac5bd9b72b@mail.gmail.com> <46D2E8A2.6010908@pacific.net> Message-ID: Thanks to all, smf-sav works great. On Mon, 27 Aug 2007, Ken A wrote: > Date: Mon, 27 Aug 2007 10:07:14 -0500 > From: Ken A > Reply-To: MailScanner discussion > To: MailScanner discussion > Subject: Re: mailscanner as a front-end, help! > > Glenn Steen wrote: >> On 27/08/07, Jeff A. Earickson wrote: >>> Gang, >>> >>> I slid my legacy MailScanner system back in front of my email >>> appliance this morning to block spam. I've got a problem with >>> non-existent/dictionary attack addresses now. They get sent >>> on to the appliance, who doesn't know the address, thence back >>> to the front-end, unroutable -- mail loop, too many hops. >>> I need MailScanner/sendmail to kill non-existent addresses up >>> front. I found milter-ahead (costs euros). Any other ideas? >>> Virtusertables, like http://q.queso.com/archives/002025? >>> >>> My setup: sendmail 8.14.1, MailScanner 4.62.9, SA and the other >>> anti-spam additions. sendmail running as "define(`MAIL_HUB'" >>> setting to pass all (non-spam) email on to the appliance for >>> local delivery. >>> >>> Jeff Earickson >>> Colby College >> smf-sav can do this, I gather... But depending on how tyhings are set, >> it might not help (if the appliance doesn't correctly reject the >> non-existant recipients...). >> >> Cheers > > In the past, I used a script to generate a sendmail access list to do this, > with To:user@domain RELAY and a default TO:domain Err..'no such user' at the > bottom. That was replaced a while ago with smf-sav. Both methods work well. > > -- > Ken Anderson > Pacific.Net > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Mon Aug 27 19:38:00 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 27 19:38:20 2007 Subject: Outgoing Queue Dir Ruleset In-Reply-To: <00c301c7e8d1$6dc1e120$cc01a8c0@Dual> References: <200708261100.l7QB02E8013272@safir.blacknight.ie> <000801c7e81e$953686b0$cc01a8c0@Dual><46D1E2A5.4090500@ecs.soton.ac.uk> <46D1E87A.9060601@ecs.soton.ac.uk> <00c301c7e8d1$6dc1e120$cc01a8c0@Dual> Message-ID: <46D31A08.9080806@ecs.soton.ac.uk> Jim Hermann wrote: > It's possible. Does MailScanner automatically add the > -OQueueDirectory="Outgoing Queue Dir" argument for Sendmail2? It looks like > it does. I was not expecting it. > Of course it does. Otherwise it wouldn't be able to tell sendmail to deliver the message if it wasn't placed in the default queue. You weren't expecting a bug now were you? :-) > I had: > > Sendmail2 = /usr/sbin/sendmail -L sm-MailScanner > -OProcessTitlePrefix=sm-MailScanner -ODeliveryMode=background > -OQueueDirectory=/home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.s > canned -C /etc/mail/sm-MailScanner.cf > > So I changed it to: > > Sendmail2 = /usr/sbin/sendmail -L sm-mailscanner > -OProcessTitlePrefix=sm-mailscanner -ODeliveryMode=background -C > /etc/mail/sm-MailScanner.cf > > Jim > > >> -----Original Message----- >> From: Julian Field [mailto:MailScanner@ecs.soton.ac.uk] >> Sent: Sunday, August 26, 2007 03:54 PM >> To: MailScanner discussion >> Subject: Re: Outgoing Queue Dir Ruleset >> >> I have just tested this code, and it works just fine. >> Are you sure it hadn't put the files in the outgoing queue >> directories >> and then delivered them before you had time to look in the >> directories? >> >> Julian Field wrote: >> >>> Start by testing them with MailScanner's command-line options. >>> Do a "MailScanner --help" to start with. >>> Is your "Run As User" set to blank (or root)? >>> The last time I tested this functionality it worked just >>> >> fine, and I >> >>> think other people use it. >>> If you really can't get it to work with test messages, then mail me >>> back and I'll test it here for you. >>> >>> Make sure your editor hasn't line wrapped the .rules file, >>> >> the version >> >>> you posted to the list has been wrapped. >>> >>> Jim Hermann wrote: >>> >>>> I have trying to create a ruleset for Outgoing Queue Dir >>>> >> and it does not >> >>>> appear to work. >>>> >>>> In MailScanner.conf, I changed to: >>>> >>>> Outgoing Queue Dir = /etc/MailScanner/rules/outgoing.rules >>>> >>>> My /etc/MailScanner/rules/outgoing.rules is: >>>> >>>> # Set "Outgoing Queue Dir = >>>> >> /etc/MailScanner/rules/outgoing.rules". >> >>>> To: *@aol.com >>>> /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.aol >>>> To: *@comcast.net >>>> /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.comcast >>>> >>>> FromOrTo: default >>>> /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.scanned >>>> >>>> I created the new directories in >>>> /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/: >>>> >>>> drwxr-xr-x 6 root root 4.0K Aug 26 14:02 . >>>> drwxr-xr-x 4 root root 4.0K Sep 15 2006 .. >>>> drwxr-xr-x 2 root root 64K Aug 26 15:14 mqueue >>>> drwxr-xr-x 2 root root 4.0K Aug 26 14:01 mqueue.aol >>>> drwxr-xr-x 2 root root 4.0K Aug 26 14:01 mqueue.comcast >>>> drwxr-xr-x 2 root root 32K Aug 26 15:12 mqueue.scanned >>>> >>>> I restarted MailScanner and all email stopped moving from the >>>> Incoming Queue >>>> Dir to anywhere. >>>> >>>> What did I do wrong? >>>> >>>> Jim >>>> >>>> >>>> >>> Jules >>> >>> >> Jules >> >> -- >> Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> MailScanner customisation, or any advanced system administration help? >> Contact me at Jules@Jules.FM >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> For all your IT requirements visit www.transtec.co.uk >> >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> For all your IT requirements visit www.transtec.co.uk >> >> >> >> > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From grupolistas at gmail.com Mon Aug 27 20:03:23 2007 From: grupolistas at gmail.com (infolistas listas) Date: Mon Aug 27 20:03:26 2007 Subject: block attachment per user Message-ID: <44c071aa0708271203lfaeb870p8a3d8aa0c1b3dffd@mail.gmail.com> Hi all is it possible to block some users from attaching files in mailscanner? EX: john, bob and joseph are allow to send attachments but paul, patrick and maria are not allowed. Thanks -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070827/2806a31a/attachment.html From MailScanner at ecs.soton.ac.uk Mon Aug 27 20:14:14 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 27 20:14:34 2007 Subject: block attachment per user In-Reply-To: <44c071aa0708271203lfaeb870p8a3d8aa0c1b3dffd@mail.gmail.com> References: <44c071aa0708271203lfaeb870p8a3d8aa0c1b3dffd@mail.gmail.com> Message-ID: <46D32286.40203@ecs.soton.ac.uk> Just use a ruleset with the Maximum Attachment Size setting in MailScanner.conf. Put this in MailScanner.conf: Maximum Attachment Size = %rules-dir%/max.attach.size.rules and in /etc/MailScanner/rules/max.attach.size.rules put this: from: john@yourdomain.com -1 from: bob@yourdomain.com -1 from: joseph@yourdomain.com -1 from: paul@yourdomain.com 0 from: patrick@yourdomain.com 0 from: maria@yourdomain.com 0 fromorto: default -1 Note the last line sets the default to -1 which is "no limit" for this setting. Then "service MailScanner reload" or (if that command doesn't work) "/etc/init.d/MailScanner reload". MailScanner rulesets are documented at length in the wiki and in the Book. infolistas listas wrote: > Hi all is it possible to block some users from attaching files in > mailscanner? > EX: john, bob and joseph are allow to send attachments but paul, > patrick and maria are not allowed. > Thanks Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From am.lists at gmail.com Mon Aug 27 21:03:15 2007 From: am.lists at gmail.com (am.lists) Date: Mon Aug 27 21:03:18 2007 Subject: Ignoring first hop (backup-mx) Message-ID: <25a66d840708271303r7de8550eq63080a2e778a283c@mail.gmail.com> I'm on the verge of moving hosting providers. Unfortunately, I'm moving the place where my two primary proxies live (MailScanner 4.58 at the moment, upgrade comes soon, Postfix 2.2.2, and ClamAV). I have an agreement with a buddy of mine to provide me with backup-mx services for the next couple of days while I do the move. But... I don't know what his filtering has to offer (if any), and I don't want to inadvertently take in a bunch of junk because I have to w/l his box. Once the move is finished and I'm up and running on the other side, how do I whitelist his IP to receive all of that mail in for my users without killing SPF rules and also being able to check that "2nd" hop instead of the first hop (which will be his server) against my SA rule-based RBLs? Sorry if this is an obvious one, but it's not one I've had to deal with yet. Angelo From ssilva at sgvwater.com Mon Aug 27 21:47:03 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon Aug 27 21:47:34 2007 Subject: Ignoring first hop (backup-mx) In-Reply-To: <25a66d840708271303r7de8550eq63080a2e778a283c@mail.gmail.com> References: <25a66d840708271303r7de8550eq63080a2e778a283c@mail.gmail.com> Message-ID: am.lists spake the following on 8/27/2007 1:03 PM: > I'm on the verge of moving hosting providers. > > Unfortunately, I'm moving the place where my two primary proxies live > (MailScanner 4.58 at the moment, upgrade comes soon, Postfix 2.2.2, > and ClamAV). > > I have an agreement with a buddy of mine to provide me with backup-mx > services for the next couple of days while I do the move. > > But... I don't know what his filtering has to offer (if any), and I > don't want to inadvertently take in a bunch of junk because I have to > w/l his box. > > Once the move is finished and I'm up and running on the other side, > how do I whitelist his IP to receive all of that mail in for my users > without killing SPF rules and also being able to check that "2nd" hop > instead of the first hop (which will be his server) against my SA > rule-based RBLs? > > Sorry if this is an obvious one, but it's not one I've had to deal with yet. > > Angelo You could put his ip in your trusted networks for spamassasssin. That should put the hop before him as the first untrusted network. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From grupolistas at gmail.com Mon Aug 27 21:51:04 2007 From: grupolistas at gmail.com (infolistas listas) Date: Mon Aug 27 21:51:10 2007 Subject: postfix stopped sending mail Message-ID: <44c071aa0708271351v48377f5dg2cd2d28f3763cb98@mail.gmail.com> After instaling mailscanner I cant get postfix to send mail, it stays on the queue forever. I tried stopping mailscanner and still so it didnt work, any ideias? -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070827/577feb1c/attachment.html From MailScanner at ecs.soton.ac.uk Mon Aug 27 22:00:24 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon Aug 27 22:00:40 2007 Subject: postfix stopped sending mail In-Reply-To: <44c071aa0708271351v48377f5dg2cd2d28f3763cb98@mail.gmail.com> References: <44c071aa0708271351v48377f5dg2cd2d28f3763cb98@mail.gmail.com> Message-ID: <46D33B68.5080206@ecs.soton.ac.uk> Start by double checking that you have done *all* the steps listed at http://www.mailscanner.info/postfix.html What directory is the mail sticking in? hold or incoming? infolistas listas wrote: > After instaling mailscanner I cant get postfix to send mail, it stays > on the queue forever. > I tried stopping mailscanner and still so it didnt work, any ideias? Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From hvdkooij at vanderkooij.org Mon Aug 27 22:34:26 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Mon Aug 27 22:34:44 2007 Subject: [SPAM] Re: postfix stopped sending mail In-Reply-To: <46D33B68.5080206@ecs.soton.ac.uk> References: <44c071aa0708271351v48377f5dg2cd2d28f3763cb98@mail.gmail.com> <46D33B68.5080206@ecs.soton.ac.uk> Message-ID: On Mon, 27 Aug 2007, Julian Field wrote: > Start by double checking that you have done *all* the steps listed at > http://www.mailscanner.info/postfix.html > > What directory is the mail sticking in? hold or incoming? And it will not hurt if you can look into the log and pick the section that seems to indicate trouble or a lack of action if checking the steps did not resolve the issue. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for this quote of George Bernard Shaw.) From ssilva at sgvwater.com Mon Aug 27 23:18:38 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon Aug 27 23:19:07 2007 Subject: postfix stopped sending mail In-Reply-To: <44c071aa0708271351v48377f5dg2cd2d28f3763cb98@mail.gmail.com> References: <44c071aa0708271351v48377f5dg2cd2d28f3763cb98@mail.gmail.com> Message-ID: infolistas listas spake the following on 8/27/2007 1:51 PM: > After instaling mailscanner I cant get postfix to send mail, it stays on > the queue forever. > I tried stopping mailscanner and still so it didnt work, any ideias? > Did you install MailScanner properly? Follow this howto; http://wiki.mailscanner.info/doku.php?id=documentation:configuration:mta:postfix:installation -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From am.lists at gmail.com Mon Aug 27 23:39:41 2007 From: am.lists at gmail.com (am.lists) Date: Mon Aug 27 23:39:46 2007 Subject: Ignoring first hop (backup-mx) In-Reply-To: References: <25a66d840708271303r7de8550eq63080a2e778a283c@mail.gmail.com> Message-ID: <25a66d840708271539p79d64461od51f86c5fef75aea@mail.gmail.com> On 8/27/07, Scott Silva wrote: > am.lists spake the following on 8/27/2007 1:03 PM: > > I'm on the verge of moving hosting providers. > > > > Unfortunately, I'm moving the place where my two primary proxies live > > (MailScanner 4.58 at the moment, upgrade comes soon, Postfix 2.2.2, > > and ClamAV). > > > > I have an agreement with a buddy of mine to provide me with backup-mx > > services for the next couple of days while I do the move. > > > > But... I don't know what his filtering has to offer (if any), and I > > don't want to inadvertently take in a bunch of junk because I have to > > w/l his box. > > > > Once the move is finished and I'm up and running on the other side, > > how do I whitelist his IP to receive all of that mail in for my users > > without killing SPF rules and also being able to check that "2nd" hop > > instead of the first hop (which will be his server) against my SA > > rule-based RBLs? > > > > Sorry if this is an obvious one, but it's not one I've had to deal with yet. > > > > Angelo > You could put his ip in your trusted networks for spamassasssin. That should > put the hop before him as the first untrusted network. > Ding ding ding! That's it! I knew it was in there, I just couldn't remember what it was. Thanks Scott. Angelo From drolland at kdinet.com Tue Aug 28 01:58:04 2007 From: drolland at kdinet.com (Diane Rolland) Date: Tue Aug 28 01:58:11 2007 Subject: SARE rules question Message-ID: <000001c7e90e$7e87c730$9700a8c0@kdinet.local> I have tried to install/configure SARE Rules and RulesDeJour from http://www.rulesemporium.com/rules.htm and when I run the below command I get the following failures. /usr/bin/spamassassin -p /etc/MailScanner/spam.assassin.prefs.conf --lint Failed to parse line in SpamAssassin configuration, skipping: lock_method flock Failed to parse line in SpamAssassin configuration, skipping: use_auto_whitelist 0 Failed to parse line in SpamAssassin configuration, skipping: envelope_sender_header X-MailScanner-From By commenting them out of the spam.assassin.prefs.conf file for the above items I get the --lint to run without error, but I'm not sure what that means to my configuration. I have SA 2.55, MailScanner-4.50.15-1 (I know, out of date) Is there any hope for me using the SARE Rules from http://www.rulesemporium.com/rules.htm? Thanks in Advance, Diane -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070827/5cb531d1/attachment.html From am.lists at gmail.com Tue Aug 28 03:30:37 2007 From: am.lists at gmail.com (am.lists) Date: Tue Aug 28 03:30:43 2007 Subject: Simple show of hands... regarding bonded sender, dkim, habeas, etc. Message-ID: <25a66d840708271930h5785beccu7cb7fbab9f62ff17@mail.gmail.com> I think this, although related to mail scanning practices more so than the software, may be a smidge OT, but it's absolutely the correct forum for the question... Does anyone else give "credit" either by way of SA negative scoring, whitelist status, or any other reward (pick a style) for senders coming in as a "bonded sender" or "habeas accredited" or any other pay-to-play sending service? I currently do not, but I was interviewing someone and their answer was "well if they go to the trouble to set that up, then I leave that up to the people at bonded sender, etc. to filter out the applicants for me." Personally, I don't care what accreditation a sender has or spoofs, if it has spammy intention (URI, phraseology, etc.) I'm gonna filter it. Does the community agree? I'd love some other viewpoints on this. Thanks all, Angelo From p.katzmann at thiesen.com Tue Aug 28 07:20:55 2007 From: p.katzmann at thiesen.com (Peter Katzmann) Date: Tue Aug 28 07:21:17 2007 Subject: SARE rules question In-Reply-To: <000001c7e90e$7e87c730$9700a8c0@kdinet.local> References: <000001c7e90e$7e87c730$9700a8c0@kdinet.local> Message-ID: <46D3BEC7.7030209@thiesen.com> Hello Diana, these errors are problems in the spamassasin config anyway. peter Diane Rolland wrote: > I have tried to install/configure SARE Rules and RulesDeJour from > http://www.rulesemporium.com/rules.htm and when I run the below command I > get the following failures. > > /usr/bin/spamassassin -p /etc/MailScanner/spam.assassin.prefs.conf --lint > > Failed to parse line in SpamAssassin configuration, skipping: lock_method > flock > Failed to parse line in SpamAssassin configuration, skipping: > use_auto_whitelist 0 > Failed to parse line in SpamAssassin configuration, skipping: > envelope_sender_header X-MailScanner-From > > By commenting them out of the spam.assassin.prefs.conf file for the above > items I get the --lint to run without error, but I'm not sure what that > means to my configuration. > > I have SA 2.55, MailScanner-4.50.15-1 (I know, out of date) > > Is there any hope for me using the SARE Rules from > http://www.rulesemporium.com/rules.htm? > > Thanks in Advance, > Diane > > > > _______________________________________________________ Registergericht / Court of jurisdiction: Amtsgericht Gie?en HRB 5708 Gesch?ftsf?hrer / Managing Director: Edith Thiesen, J?rgen Thiesen USt.-Id: DE 175 623 789 Ust.-Nr: 018 246 00743 FA Fulda Hauptsitz / Headquarters: Thiesen GmbH / Im Tiegel 9 / 36367 Wartenberg / Germany From mailadmin at baladia.gov.kw Tue Aug 28 07:22:23 2007 From: mailadmin at baladia.gov.kw (mailadmin@baladia.gov.kw) Date: Tue Aug 28 07:24:17 2007 Subject: how to install updated SA+clamAV In-Reply-To: <46D2ECF4.5070305@ecs.soton.ac.uk> References: <2407.62.150.152.226.1188226935.squirrel@webmail.baladia.gov.kw> <46D2ECF4.5070305@ecs.soton.ac.uk> Message-ID: <3504.62.150.152.42.1188282143.squirrel@webmail.baladia.gov.kw> > > > mailadmin@baladia.gov.kw wrote: >> Dear All, >> >> I have a recently installed the following on Centos 5 as per the >> install >> docs >> >> CentOS5 >> MailScanner-4.62.9-3 >> Clam-0.91.1-SA-3.2.3 >> >> n its been workin perfectly fine >> >> the clamAV 0.91.1 is already outdated and since some bugs were reported >> in >> the ClamAV 0.91.2 i jus waited. >> >> now i see on mailscanner site the updated Clam-0.91.2-SA-3.2.3 jules >> script >> >> 1) now since its on mailscanner site obviously its perfectly OK to >> upgrade >> ClamAV to 0.91.2 >> > I would personally not install 0.91.2. >> 2) how cd i update my clamav to 0.91.2 >> as when i installed it before i installed clamav, clamdb & clamd from >> dagwiers rpm site as i wanted clamd support for mailscanner and only >> installed SA running the install.sh script from Clam-0.91.1-SA-3.2.3 >> easy >> installtion package >> > Don't install 0.91.2, wait for 0.91.3. > 0.91.1 will work perfectly well for you. > >> Thanks Julian really apprecite your quick reply regards Benedict >> apprecite your help >> >> >> regards >> >> simon >> >> >> >> >> >> >> > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From list-mailscanner at linguaphone.com Tue Aug 28 08:29:57 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue Aug 28 08:30:02 2007 Subject: Simple show of hands... regarding bonded sender, dkim, habeas, etc. In-Reply-To: <25a66d840708271930h5785beccu7cb7fbab9f62ff17@mail.gmail.com> Message-ID: If they get a negative score in the default spamassassin configuration then I leave it in. I have only ever had one spam come through one of these programs (IADB) and I forwarded the mail to their helpdesk and they agreed it was spam and said they would take it up with the sender. > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of am.lists > Sent: 28 August 2007 03:31 > To: MailScanner discussion > Subject: Simple show of hands... regarding bonded sender, dkim, habeas, > etc. > > > I think this, although related to mail scanning practices more so than > the software, may be a smidge OT, but it's absolutely the correct > forum for the question... > > Does anyone else give "credit" either by way of SA negative scoring, > whitelist status, or any other reward (pick a style) for senders > coming in as a "bonded sender" or "habeas accredited" or any other > pay-to-play sending service? > > I currently do not, but I was interviewing someone and their answer > was "well if they go to the trouble to set that up, then I leave that > up to the people at bonded sender, etc. to filter out the applicants > for me." > > Personally, I don't care what accreditation a sender has or spoofs, if > it has spammy intention (URI, phraseology, etc.) I'm gonna filter it. > > Does the community agree? > > I'd love some other viewpoints on this. > > Thanks all, > > Angelo > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > From viralert at fadalto.com Tue Aug 28 08:47:12 2007 From: viralert at fadalto.com (Phil) Date: Tue Aug 28 08:47:29 2007 Subject: MCP problem In-Reply-To: <20070824085224.M12471@yatta-it.com> References: <20070824085224.M12471@yatta-it.com> Message-ID: <20070828074412.M42671@yatta-it.com> Hi all, I hope you could give me magic hints.. I've a trouble that reduce me to tears :) First of all, on a Fedora Core 6 machine, I'm using MailScanner-4.62.9-3. I have enabled MCP check as for previous version, but I'm not receiving the mcp mail that has been catched. My configuration file is: Non MCP Actions = deliver MCP Actions = store attachment forward spammy@yatta-it.com High Scoring MCP Actions = store forward spammy@yatta-it.com Bounce MCP As Attachment = no My mail log file says: Aug 24 10:41:50 tommy sendmail[13040]: l7O8fmQ3013040: from=, size=871, class=0, nrcpts=1, msgid=<200708240841.l7O8fW1r032052@dario.yatta-it.com>, proto=ESMTP, daemon=MTA, relay=217-133-242-204.b2b.tiscali.it [217.133.242.204] Aug 24 10:41:53 tommy MailScanner[12961]: New Batch: Scanning 1 messages, 1457 bytes Aug 24 10:41:53 tommy MailScanner[12961]: MCP Checks: Starting Aug 24 10:41:54 tommy MailScanner[12961]: Message l7O8fmQ3013040 from 217.133.242.204 (root@dario.yatta-it.com) to fdini.com is MCP, MCP-Checker (score=4, required 1, RULE1 4.00) Aug 24 10:41:54 tommy MailScanner[12961]: MCP Checks: Found 1 MCP messages Aug 24 10:41:54 tommy MailScanner[12961]: MCP Actions: message l7O8fmQ3013040 actions are spammy@yatta-it.com,store,forward Aug 24 10:41:54 tommy MailScanner[12961]: MCP Checks completed at 2544 bytes per second Aug 24 10:41:54 tommy MailScanner[12961]: Spam Checks: Starting Aug 24 10:42:11 tommy MailScanner[12961]: Spam Checks completed at 87 bytes per second Aug 24 10:42:11 tommy MailScanner[12961]: Virus and Content Scanning: Starting Aug 24 10:42:11 tommy MailScanner[12961]: Virus Scanning completed at 3874 bytes per second Aug 24 10:42:11 tommy MailScanner[12961]: Virus Processing completed at 1457 bytes per second Aug 24 10:42:11 tommy MailScanner[12961]: Disinfection completed at 1457 bytes per second Aug 24 10:42:11 tommy MailScanner[12961]: Batch completed at 82 bytes per second (1457 / 17) Aug 24 10:42:11 tommy MailScanner[12961]: Batch (1 message) processed in 17.64 seconds Aug 24 10:42:11 tommy MailScanner[12961]: Logging message l7O8fmQ3013040 to SQL Aug 24 10:42:11 tommy MailScanner[12961]: "Always Looked Up Last" took 0.00 seconds Aug 24 10:42:11 tommy MailScanner[12967]: l7O8fmQ3013040: Logged to MailWatch SQL For spam the behaviour of the new version of MailScanner is equal to the old one: Aug 24 10:45:03 tommy sendmail[13416]: l7O8j2So013416: from=, size=766, class=0, nrcpts=1, msgid=<000e01c7e62b$0d4dc050$5a615558@ws05>, proto=ESMTP, daemon=MTA, relay=[88.85.97.90] Aug 24 10:45:04 tommy MailScanner[13332]: New Batch: Scanning 1 messages, 1206 bytes Aug 24 10:45:04 tommy MailScanner[13332]: MCP Checks: Starting Aug 24 10:45:05 tommy MailScanner[13332]: MCP Checks completed at 5063 bytes per second Aug 24 10:45:05 tommy MailScanner[13332]: Spam Checks: Starting Aug 24 10:45:15 tommy MailScanner[13332]: RBL checks: l7O8j2So013416 found in SBL+XBL Aug 24 10:45:24 tommy MailScanner[13332]: Message l7O8j2So013416 from 88.85.97.90 (grissomofncv@timweld.com) to omissis.com is spam, SBL+XBL, SpamAssassin (not cached, score=12.044, required 4, BAYES_60 1.00, DK_POLICY_SIGNSOME 0.00, JM_TORA_XM 2.41, RAZOR2_CF_RANGE_51_100 0.50, RAZOR2_CF_RANGE_E8_51_100 1.50, RAZOR2_CHECK 0.50, RCVD_IN_XBL 3.03, RDNS_NONE 0.10, URIBL_BLACK 3.00) Aug 24 10:45:24 tommy MailScanner[13332]: Spam Checks: Found 1 spam messages Aug 24 10:45:24 tommy MailScanner[13332]: Spam Actions: message l7O8j2So013416 actions are attachment,spammy@yatta-it.com,store,forward Aug 24 10:45:24 tommy MailScanner[13332]: Spam Checks completed at 63 bytes per second Aug 24 10:45:24 tommy MailScanner[13332]: Virus and Content Scanning: Starting Aug 24 10:45:24 tommy MailScanner[13332]: Virus Scanning completed at 3189 bytes per second Aug 24 10:45:24 tommy MailScanner[13332]: Uninfected: Delivered 1 messages Aug 24 10:45:24 tommy MailScanner[13332]: Virus Processing completed at 1206 bytes per second Aug 24 10:45:24 tommy MailScanner[13332]: Batch completed at 62 bytes per second (1206 / 19) Aug 24 10:45:24 tommy MailScanner[13332]: Batch (1 message) processed in 19.44 seconds Aug 24 10:45:24 tommy MailScanner[13332]: Logging message l7O8j2So013416 to SQL Aug 24 10:45:24 tommy MailScanner[13332]: "Always Looked Up Last" took 0.00 seconds Aug 24 10:45:24 tommy MailScanner[13337]: l7O8j2So013416: Logged to MailWatch SQL Aug 24 10:45:24 tommy sendmail[13432]: l7O8j2So013416: to=, delay=00:00:21, xdelay=00:00:00, mailer=local, pri=120766, dsn=2.0.0, stat=Sent As you can see the first log misses the line Aug 24 10:45:24 tommy sendmail[13432]: l7O8j2So013416: to=, delay=00:00:21, xdelay=00:00:00, mailer=local, pri=120766, dsn=2.0.0, stat=Sent I cannot find the message in the queue folder... it disappears :( Any hint? Thanks to all! Phil From pmb1 at york.ac.uk Tue Aug 28 10:33:57 2007 From: pmb1 at york.ac.uk (Mike Brudenell) Date: Tue Aug 28 10:34:12 2007 Subject: Latest Sophos: possible problem with missing symbol in library Message-ID: <015A2A9D-C1F5-4F84-AFF4-E2C02D58A4A8@york.ac.uk> Greetings - A colleague just sent me a security advisory about Sophos Anti-Virus and how until the very latest release a few days ago it had an issue that could allow a remote DoS attack on your server: http://www.sophos.com/support/knowledgebase/article/28407.html So I decided to use MajorSophos to upgrade our Sophos installation for MailScanner on our Solaris 10 boxes a bit earlier than usual. This seemed to go OK and left us with: Current Sophos version information follows: Product version : 4.21.0 Released : 03 September 2007 However MailScanner is refusing to start its children up. Running in debug mode shows these errors: In Debugging mode, not forking... Can't load '/opt/york/lib/perl5/site_perl/5.8.0/sun4-solaris/auto/ SAVI/SAVI.so' for module SAVI: ld.so.1: /opt/york/bin/perl: fatal: relocation error: file /opt/york/lib/perl5/site_perl/5.8.0/sun4- solaris/auto/SAVI/SAVI.so: symbol SOPHOS_CLSID_SAVI2: referenced symbol not found at /opt/york/lib/perl5/5.8.0/sun4-solaris/ DynaLoader.pm line 229. at /opt/york/MailScanner/lib/MailScanner/SweepViruses.pm line 431 Compilation failed in require at /opt/york/MailScanner/lib/ MailScanner/SweepViruses.pm line 431. I tried upgrading the SAVI.pm Perl module but that wouldn't install either, failing its test suite for the same problem. Googling has revealed that the SOPHOS_CLSID_SAVI2 symbol has gone AWOL from the Sophos libraries before, back in 2002-ish: http://www.vanja.com/listarc/vtools/2002-November/000909.html One of the articles in the above conversation suggested using nm to check the libsavi.so file for the symbol. On a server still running the un-upgraded Sophos I see: % nm -D libsavi.so | fgrep -i CLSID [37] | 2256560| 16|OBJT |GLOB |0 |14 | SOPHOS_CLSID_SAVI2 % but on the system with the upgraded Sophos I instead get: % nm -D /opt/york/Sophos/lib/libsavi.so | fgrep CLSID % So it looks like it may indeed be missing: a problem that may cause the very latest Sophos not to work with the SAVI.pm module. Is anyone else seeing this? (And if you haven't upgraded Sophos yet, be careful if you try it!) Cheers, Mike B-} -- The Computing Service, University of York, Heslington, York Yo10 5DD, UK Tel:+44-1904-433811 FAX:+44-1904-433740 * Unsolicited commercial e-mail is NOT welcome at this e-mail address. * From adrik at salesmanager.nl Tue Aug 28 11:51:23 2007 From: adrik at salesmanager.nl (Adri Koppes) Date: Tue Aug 28 11:51:25 2007 Subject: Mailscanner Clamd scanner module does not detect virus with / Message-ID: I recently switched from ClamAVModule to using Clamd with MailScanner 4.61.7. I also use the extra clamav database MSRBL-Images and MSRBL-SPAM from www.msrbl.com. Some definitions in MSRBL-Images contain virus names with '/' characters. When clamd detects such an images it gives a message like: /usr/local/etc/MailScanner/incoming/69469/l7S87Zuk071123/1.gif: MSRBL-Images/0-0 -wgrZ FOUND However MailScanner does NOT detect the message as being infected. Using the ClamAVModule scanner, the message is correctly identified as being infected. Probably this is due to some special path handling in SweepViruses.pm for the ClamD module. Best regards, A. Koppes SalesManager Software B.V. From MailScanner at ecs.soton.ac.uk Tue Aug 28 12:17:54 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 28 12:18:18 2007 Subject: Mailscanner Clamd scanner module does not detect virus with / In-Reply-To: References: Message-ID: <46D40462.8040008@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Can you send me a sample message so that I can have something to work with please? I obviously need to fix this, preferably before the next stable release later this week. Adri Koppes wrote: > I recently switched from ClamAVModule to using Clamd with MailScanner > 4.61.7. > I also use the extra clamav database MSRBL-Images and MSRBL-SPAM from > www.msrbl.com. > Some definitions in MSRBL-Images contain virus names with '/' > characters. > When clamd detects such an images it gives a message like: > > /usr/local/etc/MailScanner/incoming/69469/l7S87Zuk071123/1.gif: > MSRBL-Images/0-0 > -wgrZ FOUND > > However MailScanner does NOT detect the message as being infected. > Using the ClamAVModule scanner, the message is correctly identified as > being infected. > Probably this is due to some special path handling in SweepViruses.pm > for the ClamD module. > > Best regards, > > A. Koppes > SalesManager Software B.V. > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Comment: (pgp-secured) Charset: ISO-8859-1 wj8DBQFG1ARiEfZZRxQVtlQRAm1SAKCc1w7LLzI2M9lJ44BbpwcYnSfVIACgkdaO Q/T//7IlxLFae7UiV9t9ZCw= =Y1cF -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From paul.hutchings at mira.co.uk Tue Aug 28 13:02:43 2007 From: paul.hutchings at mira.co.uk (Paul Hutchings) Date: Tue Aug 28 13:02:50 2007 Subject: MailScanner via Yum (CentOS) Message-ID: I'm playing with CentOS 5 as a new distribution. It seems I can get most things via the CentOS distribution or by adding rpmforge to the yum repository list. Does anyone know if it is possible to get mailscanner in this manner rather than having to download and build from the RPMs on the site? TIA, Paul Paul Hutchings Network Administrator, MIRA Ltd. Tel: 44 (0)24 7635 5378 Fax: 44 (0)24 7635 8378 mailto:paul.hutchings@mira.co.uk -- MIRA Ltd Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. Registered in England and Wales No. 402570 VAT Registration GB 114 5409 96 The contents of this e-mail are confidential and are solely for the use of the intended recipient. If you receive this e-mail in error, please delete it and notify us either by e-mail, telephone or fax. You should not copy, forward or otherwise disclose the content of the e-mail as this is prohibited. From MailScanner at ecs.soton.ac.uk Tue Aug 28 13:35:01 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 28 13:35:18 2007 Subject: MailScanner via Yum (CentOS) In-Reply-To: References: Message-ID: <46D41675.3000302@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I don't believe you can, no. Sorry. It only takes a few minutes to install with my installation script. Paul Hutchings wrote: > I'm playing with CentOS 5 as a new distribution. > > It seems I can get most things via the CentOS distribution or by adding > rpmforge to the yum repository list. > > Does anyone know if it is possible to get mailscanner in this manner > rather than having to download and build from the RPMs on the site? > > TIA, > Paul > > Paul Hutchings > Network Administrator, MIRA Ltd. > Tel: 44 (0)24 7635 5378 > Fax: 44 (0)24 7635 8378 > mailto:paul.hutchings@mira.co.uk > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Comment: (pgp-secured) Charset: ISO-8859-1 wj8DBQFG1BZ1EfZZRxQVtlQRAoahAJ0Z9qtpC9JrK0ywRm5sEt3q8/GLLQCdFXk9 P8NuVjnpGFmgvKO0sqpDryU= =UUvb -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From wizard at jimhermann.com Tue Aug 28 13:59:57 2007 From: wizard at jimhermann.com (Jim Hermann) Date: Tue Aug 28 13:59:53 2007 Subject: Outgoing Queue Dir Ruleset In-Reply-To: <46D31A08.9080806@ecs.soton.ac.uk> References: <200708261100.l7QB02E8013272@safir.blacknight.ie> <000801c7e81e$953686b0$cc01a8c0@Dual><46D1E2A5.4090500@ecs.soton.ac.uk> <46D1E87A.9060601@ecs.soton.ac.uk><00c301c7e8d1$6dc1e120$cc01a8c0@Dual> <46D31A08.9080806@ecs.soton.ac.uk> Message-ID: <009401c7e973$564e4770$cc01a8c0@Dual> > Jim Hermann wrote: > > It's possible. Does MailScanner automatically add the > > -OQueueDirectory="Outgoing Queue Dir" argument for > Sendmail2? It looks like > > it does. I was not expecting it. > > > Of course it does. Otherwise it wouldn't be able to tell sendmail to > deliver the message if it wasn't placed in the default queue. You > weren't expecting a bug now were you? :-) > > Jules No. I was hoping to use a Ruleset for the Outgoing Queue Dir and use separate instances of sendmail to handle each outgoing queue directory. Is there a way to have MS tell sendmail to use different configuration files for each outgoing queue directory? I want to use these statements: /usr/sbin/sendmail -L sm-mailscanner -OProcessTitlePrefix=sm-mailscanner --DeliveryMode=background -OQueueDirectory=/home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.s canned -C /etc/mail/sm-MailScanner.cf /usr/sbin/sendmail -L sm-aolscanner -OProcessTitlePrefix=sm-aolcanner --DeliveryMode=background -OQueueDirectory=/home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.a ol -C /etc/mail/sm-aolscanner.cf /usr/sbin/sendmail -L sm-comcastcanner -OProcessTitlePrefix=sm-comcastcanner --DeliveryMode=background -OQueueDirectory=/home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.c omcast -C /etc/mail/sm-comcastscanner.cf Jim From MailScanner at ecs.soton.ac.uk Tue Aug 28 14:20:25 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 28 14:21:07 2007 Subject: Outgoing Queue Dir Ruleset In-Reply-To: <009401c7e973$564e4770$cc01a8c0@Dual> References: <200708261100.l7QB02E8013272@safir.blacknight.ie> <000801c7e81e$953686b0$cc01a8c0@Dual><46D1E2A5.4090500@ecs.soton.ac.uk> <46D1E87A.9060601@ecs.soton.ac.uk><00c301c7e8d1$6dc1e120$cc01a8c0@Dual> <46D31A08.9080806@ecs.soton.ac.uk> <009401c7e973$564e4770$cc01a8c0@Dual> Message-ID: <46D42119.1010209@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Jim Hermann wrote: >> Jim Hermann wrote: >> >>> It's possible. Does MailScanner automatically add the >>> -OQueueDirectory="Outgoing Queue Dir" argument for >>> >> Sendmail2? It looks like >> >>> it does. I was not expecting it. >>> >>> >> Of course it does. Otherwise it wouldn't be able to tell sendmail to >> deliver the message if it wasn't placed in the default queue. You >> weren't expecting a bug now were you? :-) >> >> Jules >> > > No. I was hoping to use a Ruleset for the Outgoing Queue Dir and use > separate instances of sendmail to handle each outgoing queue directory. Is > there a way to have MS tell sendmail to use different configuration files > for each outgoing queue directory? > Only by hacking the code, sorry. It's not built-in functionality, sorry. > I want to use these statements: > > /usr/sbin/sendmail -L sm-mailscanner -OProcessTitlePrefix=sm-mailscanner > --DeliveryMode=background > -OQueueDirectory=/home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.s > canned -C /etc/mail/sm-MailScanner.cf > > /usr/sbin/sendmail -L sm-aolscanner -OProcessTitlePrefix=sm-aolcanner > --DeliveryMode=background > -OQueueDirectory=/home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.a > ol -C /etc/mail/sm-aolscanner.cf > > /usr/sbin/sendmail -L sm-comcastcanner -OProcessTitlePrefix=sm-comcastcanner > --DeliveryMode=background > -OQueueDirectory=/home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.c > omcast -C /etc/mail/sm-comcastscanner.cf > > Jim > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Comment: (pgp-secured) Charset: ISO-8859-1 wj8DBQFG1CEaEfZZRxQVtlQRAvvgAJ0eTBycVuZOPCFKvQ4tsWrs+XN7RwCePmOa hF5bS7CQ/4uD7E2YfpS19lk= =PtYA -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Tue Aug 28 14:26:38 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 28 14:27:16 2007 Subject: Outgoing Queue Dir Ruleset In-Reply-To: <46D42119.1010209@ecs.soton.ac.uk> References: <200708261100.l7QB02E8013272@safir.blacknight.ie> <000801c7e81e$953686b0$cc01a8c0@Dual><46D1E2A5.4090500@ecs.soton.ac.uk> <46D1E87A.9060601@ecs.soton.ac.uk><00c301c7e8d1$6dc1e120$cc01a8c0@Dual> <46D31A08.9080806@ecs.soton.ac.uk> <009401c7e973$564e4770$cc01a8c0@Dual> <46D42119.1010209@ecs.soton.ac.uk> Message-ID: <46D4228E.1010802@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 2nd thoughts: can you put a ruleset on sendmail2? The conf file will tell you if you can or not, I can't remember. Julian Field wrote: > * PGP Signed: 08/28/07 at 14:20:26 > > > > Jim Hermann wrote: >>> Jim Hermann wrote: >>> >>>> It's possible. Does MailScanner automatically add the >>>> -OQueueDirectory="Outgoing Queue Dir" argument for >>> Sendmail2? It looks like >>> >>>> it does. I was not expecting it. >>>> >>> Of course it does. Otherwise it wouldn't be able to tell sendmail to >>> deliver the message if it wasn't placed in the default queue. You >>> weren't expecting a bug now were you? :-) >>> >>> Jules >>> >> >> No. I was hoping to use a Ruleset for the Outgoing Queue Dir and use >> separate instances of sendmail to handle each outgoing queue >> directory. Is >> there a way to have MS tell sendmail to use different configuration >> files >> for each outgoing queue directory? >> > Only by hacking the code, sorry. It's not built-in functionality, sorry. >> I want to use these statements: >> >> /usr/sbin/sendmail -L sm-mailscanner -OProcessTitlePrefix=sm-mailscanner >> --DeliveryMode=background >> -OQueueDirectory=/home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.s >> >> canned -C /etc/mail/sm-MailScanner.cf >> >> /usr/sbin/sendmail -L sm-aolscanner -OProcessTitlePrefix=sm-aolcanner >> --DeliveryMode=background >> -OQueueDirectory=/home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.a >> >> ol -C /etc/mail/sm-aolscanner.cf >> >> /usr/sbin/sendmail -L sm-comcastcanner >> -OProcessTitlePrefix=sm-comcastcanner >> --DeliveryMode=background >> -OQueueDirectory=/home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.c >> >> omcast -C /etc/mail/sm-comcastscanner.cf >> >> Jim >> >> > > Jules > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Comment: (pgp-secured) Charset: ISO-8859-1 wj8DBQFG1CKPEfZZRxQVtlQRArJPAKDq7aT/TBUvKefOtyLb4aOLM52W0gCfZFtp 3dMfY8tr25EN8jhrgbtbNfA= =FPKH -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From P.G.M.Peters at utwente.nl Tue Aug 28 16:01:48 2007 From: P.G.M.Peters at utwente.nl (Peter Peters) Date: Tue Aug 28 16:01:55 2007 Subject: MailScanner is far easier to get running on a mail server than Anomy Sanitizer Message-ID: <46D438DC.7050702@utwente.nl> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 "If Linux is hardly affected by viruses, why do system administrators use anti-virus software on their Linux email servers? Because an anti-virus scanner on a mail server can serve as another level of defense for Microsoft Windows desktop users." Read more on http://www.linux.com/feature/118618 - -- Peter Peters, senior beheerder (Security) Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE) Universiteit Twente, Postbus 217, 7500 AE Enschede telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFG1DjbelLo80lrIdIRAr4SAKCjF9tFskApg9ox30RlTTkkifUMqwCeIc+o JLNH8H17qHvpR4wQxlOyrBw= =Q9t4 -----END PGP SIGNATURE----- From lundin at fini.net Tue Aug 28 16:09:32 2007 From: lundin at fini.net (John Lundin) Date: Tue Aug 28 16:10:01 2007 Subject: MailScanner via Yum (CentOS) In-Reply-To: References: Message-ID: <20070828150932.GD21971@fini.net> On Tue, Aug 28, 2007 at 01:02:43PM +0100, Paul Hutchings wrote: > It seems I can get most things via the CentOS distribution or by adding > rpmforge to the yum repository list. > > Does anyone know if it is possible to get mailscanner in this manner > rather than having to download and build from the RPMs on the site? Mostly. I do run MS on a Centos box without installed compile tools. You need to create a MailScanner-perl-MIME-Base64 rpm on another similar system first, copy it over and install it. Install the rpmforge perl packages corresponding to the perl-* srpms in the distribution (the ones that aren't available are in core perl.) I used the tnef from rpmforge. Then install the unpacked mailscanner rpm and configure. Worked for me. In theory (untried) you should just be able to install the MailScanner-perl-MIME-Base64 rpm and then: yum localinstall mailscanner-x.yy.z-k.noarch.rpm Of course, either of these may void your warranty. ;-) To be safe, keep your puppies and kittens away from the installed system. -- lundin@fini.net "I looked at GNU diffutils, and I had to rinse out my eyes with soap and water." -- Linus Torvalds 20050923git From MailScanner at ecs.soton.ac.uk Tue Aug 28 16:22:31 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 28 16:22:51 2007 Subject: MailScanner is far easier to get running on a mail server than Anomy Sanitizer In-Reply-To: <46D438DC.7050702@utwente.nl> References: <46D438DC.7050702@utwente.nl> Message-ID: <46D43DB7.1060705@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Thanks for that. My Google "MailScanner" news-watcher told me about it this morning. I added a comment to it about MailWatch as a GUI for MailScanner. Nice review otherwise. Peter Peters wrote: > * PGP Signed by an unverified key: 08/28/07 at 16:01:47 > > "If Linux is hardly affected by viruses, why do system administrators > use anti-virus software on their Linux email servers? Because an > anti-virus scanner on a mail server can serve as another level of > defense for Microsoft Windows desktop users." > > Read more on http://www.linux.com/feature/118618 > > -- > Peter Peters, senior beheerder (Security) > Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE) > Universiteit Twente, Postbus 217, 7500 AE Enschede > telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe > > * Peter Peters > * 0x496B21D2 - Unverified(L) > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Comment: (pgp-secured) Charset: ISO-8859-1 wj8DBQFG1D24EfZZRxQVtlQRAoo6AKDUxPz4N7jrcEgMFAUfrjAdfN5UzwCgw2G6 V/utTh9VDtQJPn3CXnB6EqQ= =AdGw -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From grupolistas at gmail.com Tue Aug 28 17:55:26 2007 From: grupolistas at gmail.com (infolistas listas) Date: Tue Aug 28 17:55:31 2007 Subject: postfix stopped sending mail In-Reply-To: References: <44c071aa0708271351v48377f5dg2cd2d28f3763cb98@mail.gmail.com> Message-ID: <44c071aa0708280955s333789a4g56629649c07a315@mail.gmail.com> Thanks guys I solved the problem this night, as commented by hugo the problem was with the "hold and incoming" permissions were set unproperly. Thanks again, 2007/8/27, Scott Silva : > > infolistas listas spake the following on 8/27/2007 1:51 PM: > > After instaling mailscanner I cant get postfix to send mail, it stays on > > the queue forever. > > I tried stopping mailscanner and still so it didnt work, any ideias? > > > Did you install MailScanner properly? > > Follow this howto; > > http://wiki.mailscanner.info/doku.php?id=documentation:configuration:mta:postfix:installation > > > -- > > MailScanner is like deodorant... > You hope everybody uses it, and > you notice quickly if they don't!!!! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070828/08754387/attachment.html From ssilva at sgvwater.com Tue Aug 28 18:09:33 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue Aug 28 18:09:52 2007 Subject: Ping Message-ID: Quiet list? Or comm problems? I will soon see.... -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From MailScanner at ecs.soton.ac.uk Tue Aug 28 18:18:20 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 28 18:18:36 2007 Subject: Ping In-Reply-To: References: Message-ID: <46D458DC.8070805@ecs.soton.ac.uk> There's been a dozen or two postings today. Scott Silva wrote: > Quiet list? Or comm problems? > > I will soon see.... Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From waytotheweb at googlemail.com Tue Aug 28 17:12:04 2007 From: waytotheweb at googlemail.com (Sarah Trayser) Date: Tue Aug 28 18:18:45 2007 Subject: DCC not scoring from within MailScanner Message-ID: Hi all, We're using the DCC plugin on all our servers and it used to work, but in the last few weeks it does not seem to be hitting at all. However, when I manually run an email through SpamAssassin (spamassassin -tD < mail.txt), it DOES get a DCC score. For example, I have just tested a spam message that just came into one of the servers, did not get a DCC score through MailScanner/SpamAssassin, but when I did a manual spamassassin test on the same mail just a couple of minutes later it does get a hit on DCC_CHECK. No problems in MailScanner or SpamAssasin lint tests. Running MailScanner v4.62.9, perl 5.8.8, SpamAssassin 3.2.3, DCC 1.3.59, on CentOS 4.5. Any ideas? -- Regards, Sarah Trayser Way to the Web Ltd Server Management Services: http://www.configserver.com Web Hosting: http://www.waytotheweb.com From mkettler at evi-inc.com Tue Aug 28 18:26:26 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Tue Aug 28 18:29:11 2007 Subject: SARE rules question In-Reply-To: <000001c7e90e$7e87c730$9700a8c0@kdinet.local> References: <000001c7e90e$7e87c730$9700a8c0@kdinet.local> Message-ID: <46D45AC2.60501@evi-inc.com> Diane Rolland wrote: > I have tried to install/configure SARE Rules and RulesDeJour from > http://www.rulesemporium.com/rules.htm and when I run the below command > I get the following failures. > > /usr/bin/spamassassin -p /etc/MailScanner/spam.assassin.prefs.conf --lint > > Failed to parse line in SpamAssassin configuration, skipping: > lock_method flock > Failed to parse line in SpamAssassin configuration, skipping: > use_auto_whitelist 0 > Failed to parse line in SpamAssassin configuration, skipping: > envelope_sender_header X-MailScanner-From > > By commenting them out of the spam.assassin.prefs.conf file for the > above items I get the --lint to run without error, but I'm not sure what > that means to my configuration. > > I have SA 2.55, MailScanner-4.50.15-1 (I know, out of date) not just out of date.. ancient. SA 2.55 is from may of 2003. 2.55 is also subject to a remotely exploitable DoS attack by sending it a malformed email. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0796 Before messing with SARE and RDJ, I'd seriously look at upgrading. In any event your version is way too old to support those options. The flock is really just a performance tweak, you won't miss it. This allows SA to use a faster lock method for your bayes database, at the expense of not being NFS compatible. The envelope_sender_header, well, there's no equivalent functionality in your version, but this allows SA to look at nonstandard headers when trying to detect the envelope sender. This really would only affect your whitelist_from* and blacklist_from* efforts. use_auto_whitelist allows you to disable the AWL, but in your version, it defaults to off anyway unless you pass a command-line parameter. (in 2.60 they changed it to default-on and added a config option. In 3.1.0 it became a plugin, so nowdays you can just disable it by not loading it.) From paul.hutchings at mira.co.uk Tue Aug 28 18:30:35 2007 From: paul.hutchings at mira.co.uk (Paul Hutchings) Date: Tue Aug 28 18:30:42 2007 Subject: MailScanner via Yum (CentOS) References: <46D41675.3000302@ecs.soton.ac.uk> Message-ID: Hi Julian, Thanks for the reply. That's how I've been installing it on Suse, just thought I'd ask in case there was a neater/simpler way on CentOS/RHEL. Is there a list somewhere of what the MailScanner script checks for before (if needed) installing itself? It would be nice (I presume, certainly not an expert on this!) to have as much as possible pre-installed? Cheers, Paul Paul Hutchings Network Administrator, MIRA Ltd. Tel: 44 (0)24 7635 5378 Fax: 44 (0)24 7635 8378 mailto:paul.hutchings@mira.co.uk -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian Field Sent: 28 August 2007 13:35 To: MailScanner discussion Subject: Re: MailScanner via Yum (CentOS) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I don't believe you can, no. Sorry. It only takes a few minutes to install with my installation script. Paul Hutchings wrote: > I'm playing with CentOS 5 as a new distribution. > > It seems I can get most things via the CentOS distribution or by adding > rpmforge to the yum repository list. > > Does anyone know if it is possible to get mailscanner in this manner > rather than having to download and build from the RPMs on the site? > > TIA, > Paul > > Paul Hutchings > Network Administrator, MIRA Ltd. > Tel: 44 (0)24 7635 5378 > Fax: 44 (0)24 7635 8378 > mailto:paul.hutchings@mira.co.uk > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Comment: (pgp-secured) Charset: ISO-8859-1 wj8DBQFG1BZ1EfZZRxQVtlQRAoahAJ0Z9qtpC9JrK0ywRm5sEt3q8/GLLQCdFXk9 P8NuVjnpGFmgvKO0sqpDryU= =UUvb -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MIRA Ltd Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. Registered in England and Wales No. 402570 VAT Registration GB 114 5409 96 The contents of this e-mail are confidential and are solely for the use of the intended recipient. If you receive this e-mail in error, please delete it and notify us either by e-mail, telephone or fax. You should not copy, forward or otherwise disclose the content of the e-mail as this is prohibited. From grupolistas at gmail.com Tue Aug 28 18:40:07 2007 From: grupolistas at gmail.com (infolistas listas) Date: Tue Aug 28 18:40:10 2007 Subject: block attachment per user In-Reply-To: <46D32286.40203@ecs.soton.ac.uk> References: <44c071aa0708271203lfaeb870p8a3d8aa0c1b3dffd@mail.gmail.com> <46D32286.40203@ecs.soton.ac.uk> Message-ID: <44c071aa0708281040x27c36f76g17a26ea14cc9aa97@mail.gmail.com> Thanks julian worked perfectly, just following this rules managements is there a way to block these attachments for these specific users from sending mail to another domain that isnt mine, and allow them to attach when sending mail to own domain? EX: john may send mail to mydomain but he may not send to yahoo maria may send mail to mydomain and to yahoo Is it possible? 2007/8/27, Julian Field : > > Just use a ruleset with the Maximum Attachment Size setting in > MailScanner.conf. > > Put this in MailScanner.conf: > Maximum Attachment Size = %rules-dir%/max.attach.size.rules > > and in /etc/MailScanner/rules/max.attach.size.rules put this: > from: john@yourdomain.com -1 > from: bob@yourdomain.com -1 > from: joseph@yourdomain.com -1 > from: paul@yourdomain.com 0 > from: patrick@yourdomain.com 0 > from: maria@yourdomain.com 0 > fromorto: default -1 > > Note the last line sets the default to -1 which is "no limit" for this > setting. > > Then "service MailScanner reload" or (if that command doesn't work) > "/etc/init.d/MailScanner reload". > > MailScanner rulesets are documented at length in the wiki and in the Book. > > > infolistas listas wrote: > > Hi all is it possible to block some users from attaching files in > > mailscanner? > > EX: john, bob and joseph are allow to send attachments but paul, > > patrick and maria are not allowed. > > Thanks > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070828/c4b727d9/attachment.html From MailScanner at ecs.soton.ac.uk Tue Aug 28 18:43:01 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 28 18:43:21 2007 Subject: DCC not scoring from within MailScanner In-Reply-To: References: Message-ID: <46D45EA5.3030306@ecs.soton.ac.uk> Do you have an outgoing firewall? My DCC is running pretty much all the same versions as you, and is working fine. We allow outbound by default except for SMTP. Sarah Trayser wrote: > Hi all, > > We're using the DCC plugin on all our servers and it used to work, but > in the last few weeks it does not seem to be hitting at all. However, > when I manually run an email through SpamAssassin (spamassassin -tD < > mail.txt), it DOES get a DCC score. > > For example, I have just tested a spam message that just came into one > of the servers, did not get a DCC score through > MailScanner/SpamAssassin, but when I did a manual spamassassin test on > the same mail just a couple of minutes later it does get a hit on > DCC_CHECK. > > No problems in MailScanner or SpamAssasin lint tests. > > Running MailScanner v4.62.9, perl 5.8.8, SpamAssassin 3.2.3, DCC > 1.3.59, on CentOS 4.5. > > Any ideas? > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Tue Aug 28 18:50:03 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 28 18:50:22 2007 Subject: MailScanner via Yum (CentOS) In-Reply-To: References: <46D41675.3000302@ecs.soton.ac.uk> Message-ID: <46D4604B.7050007@ecs.soton.ac.uk> Paul Hutchings wrote: > Hi Julian, > > Thanks for the reply. That's how I've been installing it on Suse, just > thought I'd ask in case there was a neater/simpler way on CentOS/RHEL. > > Is there a list somewhere of what the MailScanner script checks for > before (if needed) installing itself? > Read the install.sh script :-) It installs all its required Perl modules as RPMs first. It rebuilds the RPMs from SRPMs to guarantee they are built for the right paths for your system. > It would be nice (I presume, certainly not an expert on this!) to have > as much as possible pre-installed? > It will install everything it needs, or tell you if it's not there. Just make sure you have gcc and make before you start :-) > Cheers, > Paul > > Paul Hutchings > Network Administrator, MIRA Ltd. > Tel: 44 (0)24 7635 5378 > Fax: 44 (0)24 7635 8378 > mailto:paul.hutchings@mira.co.uk > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian > Field > Sent: 28 August 2007 13:35 > To: MailScanner discussion > Subject: Re: MailScanner via Yum (CentOS) > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > I don't believe you can, no. Sorry. It only takes a few minutes to > install with my installation script. > > Paul Hutchings wrote: > >> I'm playing with CentOS 5 as a new distribution. >> >> It seems I can get most things via the CentOS distribution or by >> > adding > >> rpmforge to the yum repository list. >> >> Does anyone know if it is possible to get mailscanner in this manner >> rather than having to download and build from the RPMs on the site? >> >> TIA, >> Paul >> >> Paul Hutchings >> Network Administrator, MIRA Ltd. >> Tel: 44 (0)24 7635 5378 >> Fax: 44 (0)24 7635 8378 >> mailto:paul.hutchings@mira.co.uk >> >> >> >> > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > Need help customising MailScanner? > Contact me! > Need help fixing or optimising your systems? > Contact me! > Need help getting you started solving new requirements from your boss? > Contact me! > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.3 (Build 3017) > Comment: (pgp-secured) > Charset: ISO-8859-1 > > wj8DBQFG1BZ1EfZZRxQVtlQRAoahAJ0Z9qtpC9JrK0ywRm5sEt3q8/GLLQCdFXk9 > P8NuVjnpGFmgvKO0sqpDryU= > =UUvb > -----END PGP SIGNATURE----- > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Tue Aug 28 19:12:57 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 28 19:13:14 2007 Subject: block attachment per user In-Reply-To: <44c071aa0708281040x27c36f76g17a26ea14cc9aa97@mail.gmail.com> References: <44c071aa0708271203lfaeb870p8a3d8aa0c1b3dffd@mail.gmail.com> <46D32286.40203@ecs.soton.ac.uk> <44c071aa0708281040x27c36f76g17a26ea14cc9aa97@mail.gmail.com> Message-ID: <46D465A9.4040105@ecs.soton.ac.uk> infolistas listas wrote: > Thanks julian worked perfectly, just following this rules managements > is there a way to block these attachments for these specific users > from sending mail to another domain that isnt mine, and allow them to > attach when sending mail to own domain? > EX: > > john may send mail to mydomain but he may not send to yahoo From: john@mydomain.com And To: mydomain.com -1 From: john@mydomain.com 0 > > maria may send mail to mydomain and to yahoo > > Is it possible? > > > 2007/8/27, Julian Field < MailScanner@ecs.soton.ac.uk > >: > > Just use a ruleset with the Maximum Attachment Size setting in > MailScanner.conf. > > Put this in MailScanner.conf: > Maximum Attachment Size = %rules-dir%/max.attach.size.rules > > and in /etc/MailScanner/rules/max.attach.size.rules put this: > from: john@yourdomain.com -1 > from: bob@yourdomain.com -1 > from: joseph@yourdomain.com -1 > from: paul@yourdomain.com 0 > from: patrick@yourdomain.com 0 > from: maria@yourdomain.com 0 > fromorto: default -1 > > Note the last line sets the default to -1 which is "no limit" for this > setting. > > Then "service MailScanner reload" or (if that command doesn't work) > "/etc/init.d/MailScanner reload". > > MailScanner rulesets are documented at length in the wiki and in > the Book. > > > infolistas listas wrote: > > Hi all is it possible to block some users from attaching files in > > mailscanner? > > EX: john, bob and joseph are allow to send attachments but paul, > > patrick and maria are not allowed. > > Thanks > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > > Support MailScanner development - buy the book off the website! > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From grupolistas at gmail.com Tue Aug 28 19:13:25 2007 From: grupolistas at gmail.com (infolistas listas) Date: Tue Aug 28 19:13:28 2007 Subject: block attachment per user In-Reply-To: <44c071aa0708281040x27c36f76g17a26ea14cc9aa97@mail.gmail.com> References: <44c071aa0708271203lfaeb870p8a3d8aa0c1b3dffd@mail.gmail.com> <46D32286.40203@ecs.soton.ac.uk> <44c071aa0708281040x27c36f76g17a26ea14cc9aa97@mail.gmail.com> Message-ID: <44c071aa0708281113k70b7d9fg2ded0238543375e7@mail.gmail.com> Ok I lookedup some examples from others rules and found it from: john@domain -1 from: maria@domain -1 to: *gmail.com -1 #allows attach to be send to everything on gmail to: *@domain -1 #allows attach to be send to my domain fromorto: default 0 Thanks. 2007/8/28, infolistas listas : > > Thanks julian worked perfectly, just following this rules managements is > there a way to block these attachments for these specific users from sending > mail to another domain that isnt mine, and allow them to attach when sending > mail to own domain? > EX: > > john may send mail to mydomain but he may not send to yahoo > maria may send mail to mydomain and to yahoo > > Is it possible? > > > 2007/8/27, Julian Field < MailScanner@ecs.soton.ac.uk>: > > > > Just use a ruleset with the Maximum Attachment Size setting in > > MailScanner.conf. > > > > Put this in MailScanner.conf: > > Maximum Attachment Size = %rules-dir%/max.attach.size.rules > > > > and in /etc/MailScanner/rules/max.attach.size.rules put this: > > from: john@yourdomain.com -1 > > from: bob@yourdomain.com -1 > > from: joseph@yourdomain.com -1 > > from: paul@yourdomain.com 0 > > from: patrick@yourdomain.com 0 > > from: maria@yourdomain.com 0 > > fromorto: default -1 > > > > Note the last line sets the default to -1 which is "no limit" for this > > setting. > > > > Then "service MailScanner reload" or (if that command doesn't work) > > "/etc/init.d/MailScanner reload". > > > > MailScanner rulesets are documented at length in the wiki and in the > > Book. > > > > > > infolistas listas wrote: > > > Hi all is it possible to block some users from attaching files in > > > mailscanner? > > > EX: john, bob and joseph are allow to send attachments but paul, > > > patrick and maria are not allowed. > > > Thanks > > > > Jules > > > > -- > > Julian Field MEng CITP > > www.MailScanner.info > > Buy the MailScanner book at www.MailScanner.info/store > > > > MailScanner customisation, or any advanced system administration help? > > Contact me at Jules@Jules.FM > > > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > For all your IT requirements visit www.transtec.co.uk > > > > > > -- > > This message has been scanned for viruses and > > dangerous content by MailScanner, and is > > believed to be clean. > > For all your IT requirements visit www.transtec.co.uk > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070828/2293208b/attachment.html From steve.swaney at fsl.com Tue Aug 28 19:19:39 2007 From: steve.swaney at fsl.com (Stephen Swaney) Date: Tue Aug 28 19:18:56 2007 Subject: MailScanner via Yum (CentOS) In-Reply-To: <46D4604B.7050007@ecs.soton.ac.uk> References: <46D41675.3000302@ecs.soton.ac.uk> <46D4604B.7050007@ecs.soton.ac.uk> Message-ID: <014c01c7e99f$ff4ee1a0$fdeca4e0$@swaney@fsl.com> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Julian Field > Sent: Tuesday, August 28, 2007 1:50 PM > To: MailScanner discussion > Subject: Re: MailScanner via Yum (CentOS) > > > > Paul Hutchings wrote: > > Hi Julian, > > > > Thanks for the reply. That's how I've been installing it on Suse, > just > > thought I'd ask in case there was a neater/simpler way on > CentOS/RHEL. > > > > Is there a list somewhere of what the MailScanner script checks for > > before (if needed) installing itself? > > > Read the install.sh script :-) > It installs all its required Perl modules as RPMs first. It rebuilds > the > RPMs from SRPMs to guarantee they are built for the right paths for > your > system. > > > It would be nice (I presume, certainly not an expert on this!) to > have > > as much as possible pre-installed? > > > It will install everything it needs, or tell you if it's not there. > Just > make sure you have gcc and make before you start :-) and rpm-build :) Steve Steve Swaney steve@fsl.com www.fsl.com > > Cheers, > > Paul > > > > Paul Hutchings > > Network Administrator, MIRA Ltd. > > Tel: 44 (0)24 7635 5378 > > Fax: 44 (0)24 7635 8378 > > mailto:paul.hutchings@mira.co.uk > > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of > Julian > > Field > > Sent: 28 August 2007 13:35 > > To: MailScanner discussion > > Subject: Re: MailScanner via Yum (CentOS) > > > > -----BEGIN PGP SIGNED MESSAGE----- > > Hash: SHA1 > > > > I don't believe you can, no. Sorry. It only takes a few minutes to > > install with my installation script. > > > > Paul Hutchings wrote: > > > >> I'm playing with CentOS 5 as a new distribution. > >> > >> It seems I can get most things via the CentOS distribution or by > >> > > adding > > > >> rpmforge to the yum repository list. > >> > >> Does anyone know if it is possible to get mailscanner in this manner > >> rather than having to download and build from the RPMs on the site? > >> > >> TIA, > >> Paul > >> > >> Paul Hutchings > >> Network Administrator, MIRA Ltd. > >> Tel: 44 (0)24 7635 5378 > >> Fax: 44 (0)24 7635 8378 > >> mailto:paul.hutchings@mira.co.uk > >> > >> > >> > >> > > > > Jules > > > > - -- > > Julian Field MEng CITP > > www.MailScanner.info > > Buy the MailScanner book at www.MailScanner.info/store > > > > Need help customising MailScanner? > > Contact me! > > Need help fixing or optimising your systems? > > Contact me! > > Need help getting you started solving new requirements from your > boss? > > Contact me! > > > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > > > > -----BEGIN PGP SIGNATURE----- > > Version: PGP Desktop 9.6.3 (Build 3017) > > Comment: (pgp-secured) > > Charset: ISO-8859-1 > > > > wj8DBQFG1BZ1EfZZRxQVtlQRAoahAJ0Z9qtpC9JrK0ywRm5sEt3q8/GLLQCdFXk9 > > P8NuVjnpGFmgvKO0sqpDryU= > > =UUvb > > -----END PGP SIGNATURE----- > > > > > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From mkettler at evi-inc.com Tue Aug 28 19:31:26 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Tue Aug 28 19:34:04 2007 Subject: DCC not scoring from within MailScanner In-Reply-To: <46D45EA5.3030306@ecs.soton.ac.uk> References: <46D45EA5.3030306@ecs.soton.ac.uk> Message-ID: <46D469FE.5030207@evi-inc.com> Julian Field wrote: > Do you have an outgoing firewall? Well, that would affect the command-line version too. > My DCC is running pretty much all the > same versions as you, and is working fine. We allow outbound by default > except for SMTP. Mine's working fine on older versions. It seems rather odd that it works on the command-line, but not under MailScanner. Any chance you're using dccifd and the socket is in a place where mailscanner doesn't have access rights? From MailScanner at ecs.soton.ac.uk Tue Aug 28 19:43:59 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 28 19:45:02 2007 Subject: MailScanner via Yum (CentOS) In-Reply-To: <014c01c7e99f$ff4ee1a0$fdeca4e0$@swaney@fsl.com> References: <46D41675.3000302@ecs.soton.ac.uk> <46D4604B.7050007@ecs.soton.ac.uk> <014c01c7e99f$ff4ee1a0$fdeca4e0$@swaney@fsl.com> Message-ID: <46D46CEF.50504@ecs.soton.ac.uk> Stephen Swaney wrote: > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Julian Field >> Sent: Tuesday, August 28, 2007 1:50 PM >> To: MailScanner discussion >> Subject: Re: MailScanner via Yum (CentOS) >> >> >> >> Paul Hutchings wrote: >> >>> Hi Julian, >>> >>> Thanks for the reply. That's how I've been installing it on Suse, >>> >> just >> >>> thought I'd ask in case there was a neater/simpler way on >>> >> CentOS/RHEL. >> >>> Is there a list somewhere of what the MailScanner script checks for >>> before (if needed) installing itself? >>> >>> >> Read the install.sh script :-) >> It installs all its required Perl modules as RPMs first. It rebuilds >> the >> RPMs from SRPMs to guarantee they are built for the right paths for >> your >> system. >> >> >>> It would be nice (I presume, certainly not an expert on this!) to >>> >> have >> >>> as much as possible pre-installed? >>> >>> >> It will install everything it needs, or tell you if it's not there. >> Just >> make sure you have gcc and make before you start :-) >> > > and rpm-build :) > Good point, that's the most common culprit! Thanks Steve :-) > >>> Cheers, >>> Paul >>> >>> Paul Hutchings >>> Network Administrator, MIRA Ltd. >>> Tel: 44 (0)24 7635 5378 >>> Fax: 44 (0)24 7635 8378 >>> mailto:paul.hutchings@mira.co.uk >>> >>> -----Original Message----- >>> From: mailscanner-bounces@lists.mailscanner.info >>> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of >>> >> Julian >> >>> Field >>> Sent: 28 August 2007 13:35 >>> To: MailScanner discussion >>> Subject: Re: MailScanner via Yum (CentOS) >>> >>> -----BEGIN PGP SIGNED MESSAGE----- >>> Hash: SHA1 >>> >>> I don't believe you can, no. Sorry. It only takes a few minutes to >>> install with my installation script. >>> >>> Paul Hutchings wrote: >>> >>> >>>> I'm playing with CentOS 5 as a new distribution. >>>> >>>> It seems I can get most things via the CentOS distribution or by >>>> >>>> >>> adding >>> >>> >>>> rpmforge to the yum repository list. >>>> >>>> Does anyone know if it is possible to get mailscanner in this manner >>>> rather than having to download and build from the RPMs on the site? >>>> >>>> TIA, >>>> Paul >>>> >>>> Paul Hutchings >>>> Network Administrator, MIRA Ltd. >>>> Tel: 44 (0)24 7635 5378 >>>> Fax: 44 (0)24 7635 8378 >>>> mailto:paul.hutchings@mira.co.uk >>>> >>>> >>>> >>>> >>>> >>> Jules >>> >>> - -- >>> Julian Field MEng CITP >>> www.MailScanner.info >>> Buy the MailScanner book at www.MailScanner.info/store >>> >>> Need help customising MailScanner? >>> Contact me! >>> Need help fixing or optimising your systems? >>> Contact me! >>> Need help getting you started solving new requirements from your >>> >> boss? >> >>> Contact me! >>> >>> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >>> >>> >>> -----BEGIN PGP SIGNATURE----- >>> Version: PGP Desktop 9.6.3 (Build 3017) >>> Comment: (pgp-secured) >>> Charset: ISO-8859-1 >>> >>> wj8DBQFG1BZ1EfZZRxQVtlQRAoahAJ0Z9qtpC9JrK0ywRm5sEt3q8/GLLQCdFXk9 >>> P8NuVjnpGFmgvKO0sqpDryU= >>> =UUvb >>> -----END PGP SIGNATURE----- >>> >>> >>> >> Jules >> >> -- >> Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> MailScanner customisation, or any advanced system administration help? >> Contact me at Jules@Jules.FM >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> For all your IT requirements visit www.transtec.co.uk >> >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> For all your IT requirements visit www.transtec.co.uk >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From paul.hutchings at mira.co.uk Tue Aug 28 20:06:18 2007 From: paul.hutchings at mira.co.uk (Paul Hutchings) Date: Tue Aug 28 20:06:20 2007 Subject: MailScanner via Yum (CentOS) References: <46D41675.3000302@ecs.soton.ac.uk> <46D4604B.7050007@ecs.soton.ac.uk> Message-ID: > Read the install.sh script :-) Rather embarrassingly I did once I'd sent the reply to the list :-) I'd appreciate any feedback on how other people handle this - I can see the benefits of using the rpm's supplied with MailScanner as I would assume it sorts out things like minimum versions req'd, but at the same time I'm thinking is there a benefit to using as much as possible of what comes with the OS? -- MIRA Ltd Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. Registered in England and Wales No. 402570 VAT Registration GB 114 5409 96 The contents of this e-mail are confidential and are solely for the use of the intended recipient. If you receive this e-mail in error, please delete it and notify us either by e-mail, telephone or fax. You should not copy, forward or otherwise disclose the content of the e-mail as this is prohibited. From mstandish at gmail.com Tue Aug 28 20:07:55 2007 From: mstandish at gmail.com (Matt Standish) Date: Tue Aug 28 20:07:58 2007 Subject: SLES 10 experience In-Reply-To: <006801c7e09d$a4f44e30$ad582fc2@taxbrbr> References: <006801c7e09d$a4f44e30$ad582fc2@taxbrbr> Message-ID: <39e688060708281207h2d4e1dc4x8f24ad357f1221e5@mail.gmail.com> I have been running Mailscanner on SLES 10 for some time. I did build a custom RPM for postfix for some of the database related stuff.. I haven't had any OS related problems. On 8/17/07, Tobias Axelsson wrote: > > > > > Hi > > I have now in 3 years running mailscanner/mailwatch on Suse linux enterprise > server 9 on three servers almost without problem. > > Now we need more performance and gonna replace them with three new > bladeservers 2x4quadcore/6GB ram and no disk. > > Becourse of the blade-structure, I gonna need to san-boot them, (the > systemdisk is a SAN-disk) and therefor it requires SuSE linux enterprise 10. > Do someone have good experience with SLES10? A lot is changed... > > Thanks, Tobias > Sweden > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- Matt Standish MSN Messenger: mps_@hotmail.com Yahoo Messenger: mattstandish@yahoo.com Google Talk: mstandish From MailScanner at ecs.soton.ac.uk Tue Aug 28 20:28:43 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue Aug 28 20:29:09 2007 Subject: MailScanner via Yum (CentOS) In-Reply-To: References: <46D41675.3000302@ecs.soton.ac.uk> <46D4604B.7050007@ecs.soton.ac.uk> Message-ID: <46D4776B.20902@ecs.soton.ac.uk> Paul Hutchings wrote: >> Read the install.sh script :-) >> > > Rather embarrassingly I did once I'd sent the reply to the list :-) > > I'd appreciate any feedback on how other people handle this - I can see > the benefits of using the rpm's supplied with MailScanner as I would > assume it sorts out things like minimum versions req'd, but at the same > time I'm thinking is there a benefit to using as much as possible of > what comes with the OS? > It doesn't install a new module unless it needs to for some reason. If your current version is okay, then it will leave it as it is and not upgrade it. But many of the requirements are not shipped with the OS. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From dnsadmin at 1bigthink.com Tue Aug 28 20:42:43 2007 From: dnsadmin at 1bigthink.com (dnsadmin 1bigthink.com) Date: Tue Aug 28 20:42:59 2007 Subject: MailScanner via Yum (CentOS) In-Reply-To: References: <46D41675.3000302@ecs.soton.ac.uk> <46D4604B.7050007@ecs.soton.ac.uk> Message-ID: <200708281943.l7SJh2e1008726@mxt.1bigthink.com> At 03:06 PM 8/28/2007, you wrote: > > Read the install.sh script :-) > >Rather embarrassingly I did once I'd sent the reply to the list :-) > >I'd appreciate any feedback on how other people handle this - I can see >the benefits of using the rpm's supplied with MailScanner as I would >assume it sorts out things like minimum versions req'd, but at the same >time I'm thinking is there a benefit to using as much as possible of >what comes with the OS? No. MailScanner and the SpamAssassin/ClamAV installers are updated far more regularly than the similar components of the OS. All the important parts of the OS will still be handled well by RedHat/CentOS. Well, CentOS, anyway. I've been on CentOS since RedHat went the route of support licences. I understand your squeamishness; when I tried SuSe I found some odd things that a lot of familiar programs broke and/or broke familiar programs (only due to my lack of experience with the OS, I'm sure). MailScanner goes very well with RedHat/CentOS. Cheers, Glenn From list-mailscanner at linguaphone.com Tue Aug 28 21:31:34 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue Aug 28 21:31:37 2007 Subject: DCC not scoring from within MailScanner In-Reply-To: <46D469FE.5030207@evi-inc.com> Message-ID: The top 3 problems with getting DCC to work are :- 1) Firewall but this wont allow it to work from the command prompt for any user. 2) Permissions. Test it under the same user which mailscanner runs as. 3) Path issues. Make sure you correctly have the dcc path set in the spamassassin configuration. This is the error I made which resulted in the same issue you are experiencing. > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Matt > Kettler > Sent: 28 August 2007 19:31 > To: MailScanner discussion > Subject: Re: DCC not scoring from within MailScanner > > > Julian Field wrote: > > Do you have an outgoing firewall? > > Well, that would affect the command-line version too. > > > My DCC is running pretty much all the > > same versions as you, and is working fine. We allow outbound by default > > except for SMTP. > > Mine's working fine on older versions. > > It seems rather odd that it works on the command-line, but not > under MailScanner. > > Any chance you're using dccifd and the socket is in a place where > mailscanner > doesn't have access rights? > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > From waytotheweb at googlemail.com Tue Aug 28 22:15:15 2007 From: waytotheweb at googlemail.com (Sarah Trayser) Date: Tue Aug 28 22:15:19 2007 Subject: DCC not scoring from within MailScanner In-Reply-To: References: <46D469FE.5030207@evi-inc.com> Message-ID: Thanks for all the replies. We're using dccproc, not dccifd. On 28/08/07, Gareth wrote: > The top 3 problems with getting DCC to work are :- > > 1) Firewall but this wont allow it to work from the command prompt for any > user. Although we do run a firewall, that can't be the issue since it's working from the command line. > > 2) Permissions. Test it under the same user which mailscanner runs as. In my testing I did this. DCC works when I run a spamassassin test as the mailscanner user, just not when MailScanner calls it, apparently. > 3) Path issues. Make sure you correctly have the dcc path set in the > spamassassin configuration. This is the error I made which resulted in the > same issue you are experiencing. Wouldn't this affect the command line test as well? Where would this be set - mailscanner.cf > spam.assassin.prefs.conf? This is what I see in that file: ifplugin Mail::SpamAssassin::Plugin::DCC #dcc_path /usr/local/bin/dccproc endif As far as I know we have not changed that so I assume it has always been commented out. -- Regards, Sarah Trayser Way to the Web Ltd Server Management Services: http://www.configserver.com Web Hosting: http://www.waytotheweb.com From naolson at gmail.com Tue Aug 28 22:52:28 2007 From: naolson at gmail.com (Nathan Olson) Date: Tue Aug 28 22:52:32 2007 Subject: MailScanner via Yum (CentOS) In-Reply-To: References: <46D41675.3000302@ecs.soton.ac.uk> <46D4604B.7050007@ecs.soton.ac.uk> Message-ID: <8f54b4330708281452g10b0440ej22bfd4e1f4dc721b@mail.gmail.com> We run RHEL5 (64-bit, Server + Virt) and install home-grown RPMs using the latest sources from CPAN for all the components not included or available via RedHat's yum channels. Take Base64.pm, for example. Included in the perl RPM on RHEL5. We just use that. Same with HTML-Tagset and many others. It works fine, but it takes work. Nate From steve.swaney at fsl.com Wed Aug 29 00:46:00 2007 From: steve.swaney at fsl.com (Stephen Swaney) Date: Wed Aug 29 00:45:18 2007 Subject: MailScanner via Yum (CentOS) In-Reply-To: <8f54b4330708281452g10b0440ej22bfd4e1f4dc721b@mail.gmail.com> References: <46D41675.3000302@ecs.soton.ac.uk> <46D4604B.7050007@ecs.soton.ac.uk> <8f54b4330708281452g10b0440ej22bfd4e1f4dc721b@mail.gmail.com> Message-ID: <030a01c7e9cd$968a4500$c39ecf00$@swaney@fsl.com> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Nathan Olson > Sent: Tuesday, August 28, 2007 5:52 PM > To: MailScanner discussion > Subject: Re: MailScanner via Yum (CentOS) > > We run RHEL5 (64-bit, Server + Virt) and install home-grown RPMs using > the > latest sources from CPAN for all the components not included or > available via RedHat's yum channels. > > Take Base64.pm, for example. Included in the perl RPM on RHEL5. We > just use that. > Same with HTML-Tagset and many others. > > It works fine, but it takes work. > > Nate > -- It looks like the sites that know enough to intelligently use the various methods to install rpms can pretty much dissect Julian's install.sh script to use yum (or up2date RH 5.0) to keep their systems updated the way they want to. But it's not simple! After following this thread, I can tell you that based on our experience to update our own applications using yum - and for Julian to try to handle all the Operating Systems he supports - and to continue with incredibly fast implementation of feature requests - and get a little rest now and then - and have some dinners out with his mates - etc - etc -this is not trivial! And this should not be his job! He already makes it so simple for newbes and experienced admins to simply keep their MailScanner apps up to date he shouldn't be asked to do more. What I would suggest is that if you really want to do this is to help Julian. Setup a yum repository that handles all of the dependencies that that MailScanner requires (hint enablerepo=) and if you're really ambitious, add SpamAssassin, Razor, DCC - you get the idea. We're starting doing this for our MailScanner maintenance clients since it will save us time and them costs and we may make this accessible the MailScanner list as we have the time and resources but it won't be soon. We're really too busy with BarricadeMX installs. Who wants' to volunteer :>). We'll be happy to share what we've done so far with you but you'll need a bit of bandwith! Steve Steve Swaney steve@fsl.com www.fsl.com From naolson at gmail.com Wed Aug 29 02:16:47 2007 From: naolson at gmail.com (Nathan Olson) Date: Wed Aug 29 02:16:50 2007 Subject: MailScanner via Yum (CentOS) In-Reply-To: <-5452022688349182458@unknownmsgid> References: <46D41675.3000302@ecs.soton.ac.uk> <46D4604B.7050007@ecs.soton.ac.uk> <8f54b4330708281452g10b0440ej22bfd4e1f4dc721b@mail.gmail.com> <-5452022688349182458@unknownmsgid> Message-ID: <8f54b4330708281816y7572cac2r6ef68f7a94fedce6@mail.gmail.com> Actually, we have SpamAssassin + all requirements (for 64-bit RHEL5 - spec files should work for 32-bit as well) and Razor as RPMs. Is someone actually interested in these? Nate From wizard at jimhermann.com Wed Aug 29 05:25:24 2007 From: wizard at jimhermann.com (Jim Hermann) Date: Wed Aug 29 05:25:12 2007 Subject: Outgoing Queue Dir Ruleset In-Reply-To: <46D42119.1010209@ecs.soton.ac.uk> References: <200708261100.l7QB02E8013272@safir.blacknight.ie> <000801c7e81e$953686b0$cc01a8c0@Dual><46D1E2A5.4090500@ecs.soton.ac.uk> <46D1E87A.9060601@ecs.soton.ac.uk><00c301c7e8d1$6dc1e120$cc01a8c0@Dual> <46D31A08.9080806@ecs.soton.ac.uk><009401c7e973$564e4770$cc01a8c0@Dual> <46D42119.1010209@ecs.soton.ac.uk> Message-ID: <011a01c7e9f4$9ee70220$cc01a8c0@Dual> > Jim Hermann wrote: > > No. I was hoping to use a Ruleset for the Outgoing Queue Dir and use > > separate instances of sendmail to handle each outgoing > queue directory. Is > > there a way to have MS tell sendmail to use different > configuration files > > for each outgoing queue directory? > > > Only by hacking the code, sorry. It's not built-in > functionality, sorry. > >2nd thoughts: can you put a ruleset on sendmail2? The conf file will >tell you if you can or not, I can't remember. I don't feel bad for not noticing. ;) Now my MailScanner.conf contains: Outgoing Queue Dir = /etc/MailScanner/rules/outgoing.rules Sendmail2 = /etc/MailScanner/rules/sendmail2.rules Use Default Rules With Multiple Recipients = yes Delivery Method = batch /etc/MailScanner/rules/outgoing.rules contains: To: *@aol.com /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.scanned1 To: *@cs.com /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.scanned1 To: *@comcast.net /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.scanned2 To: *@yahoo.com /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.scanned2 FromOrTo: default /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.scanned /etc/MailScanner/rules/sendmail2.rules contains: To: *@aol.com /usr/sbin/sendmail -L sm-mailscanner1 -OProcessTitlePrefix=sm-mailscanner1 -ODeliveryMode=background -C /etc/mail/sm-mailscanner1.cf To: *@cs.com /usr/sbin/sendmail -L sm-mailscanner1 -OProcessTitlePrefix=sm-mailscanner1 -ODeliveryMode=background -C /etc/mail/sm-mailscanner1.cf To: *@comcast.net /usr/sbin/sendmail -L sm-mailscanner2 -OProcessTitlePrefix=sm-mailscanner2 -ODeliveryMode=background -C /etc/mail/sm-mailscanner2.cf To: *@yahoo.com /usr/sbin/sendmail -L sm-mailscanner2 -OProcessTitlePrefix=sm-mailscanner2 -ODeliveryMode=background -C /etc/mail/sm-mailscanner2.cf FromOrTo: default /usr/sbin/sendmail -L sm-mailscanner -OProcessTitlePrefix=sm-mailscanner -ODeliveryMode=background -C /etc/mail/sm-mailscanner.cf MailScanner stores the email in the correct directory but does not use the correct version of sendmail2. It does use the default value of sendmail2. The "sm-mailscanner" shows up in the log. How do I get the Ruleset to match the other values for Sendmail2? Thanks. Jim From tgc at statsbiblioteket.dk Wed Aug 29 07:48:32 2007 From: tgc at statsbiblioteket.dk (Tom G. Christensen) Date: Wed Aug 29 07:48:34 2007 Subject: MailScanner via Yum (CentOS) In-Reply-To: References: Message-ID: <46D516C0.4030704@statsbiblioteket.dk> Paul Hutchings wrote: > I'm playing with CentOS 5 as a new distribution. > > It seems I can get most things via the CentOS distribution or by adding > rpmforge to the yum repository list. > > Does anyone know if it is possible to get mailscanner in this manner > rather than having to download and build from the RPMs on the site? > I just did such an install on CentOS 5, but it's not as easy as it should be. The main gotcha is that 3 of the perl modules that MailScanner wants to install conflicts with the main perl package since it already provides the modules. The modules are File-Temp, Getopt-Long and Test-Harness. For my own use I've created a perl package which has these modules as replaceable subpackages. The alternative is to force the install of the offending RPMS. With rpmforge enabled and standing in the MailScanner dir I did: # yum install `ls perl-* | sed -e 's/\(perl-[a-zA-Z-]*\)-[0-9]*.*/\1/'` # yum install tnef perl-HTML-Parser is only 3.55 in CentOS 5 while MailScanner ships 3.56, I built my own version of the RPMforge package with 3.56 instead. mailscanner itself ofcourse it not available via yum but with all the above in place you can just install the rpm package in the MailScanner tarball without running install.sh (yay!). After that it's easy, RPMforge has clamav, SA and Razor ready to install. If you want DCC you can get it from ATrpms.net. -tgc From paul.hutchings at mira.co.uk Wed Aug 29 09:01:11 2007 From: paul.hutchings at mira.co.uk (Paul Hutchings) Date: Wed Aug 29 09:01:19 2007 Subject: MailScanner via Yum (CentOS) References: <46D41675.3000302@ecs.soton.ac.uk> <46D4604B.7050007@ecs.soton.ac.uk> <46D4776B.20902@ecs.soton.ac.uk> Message-ID: Ok what I did was to simply do what I've been doing on Suse i.e. download the rpm installer and run install.sh Afterwards I ran "yum update". Bearing in mind I have rpmforge installed this was the output: ======================================================================== ===== Package Arch Version Repository Size ======================================================================== ===== Updating: perl-Archive-Zip noarch 1.20-1.el5.rf rpmforge 100 k perl-Convert-BinHex noarch 1.119-2.2.el5.rf rpmforge 34 k perl-Convert-TNEF noarch 0.17-3.2.el5.rf rpmforge 18 k perl-DBD-SQLite x86_64 1.13-1.el5.rf rpmforge 52 k perl-Filesys-Df x86_64 0.92-1.el5.rf rpmforge 36 k perl-IO-stringy noarch 2.110-1.2.el5.rf rpmforge 70 k perl-MIME-tools noarch 5.420-1.el5.rf rpmforge 276 k perl-MailTools noarch 1.77-1.el5.rf rpmforge 85 k perl-Net-CIDR noarch 0.11-1.2.el5.rf rpmforge 15 k perl-Sys-Hostname-Long noarch 1.4-1.2.el5.rf rpmforge 12 k tnef x86_64 1.4.3-1.el5.rf rpmforge 46 k Transaction Summary ======================================================================== ===== Install 0 Package(s) Update 11 Package(s) Remove 0 Package(s) So it would appear I'm good to go with the install script and the things yum will update by itself? Cheers, Paul Paul Hutchings Network Administrator, MIRA Ltd. Tel: 44 (0)24 7635 5378 Fax: 44 (0)24 7635 8378 mailto:paul.hutchings@mira.co.uk -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian Field Sent: 28 August 2007 20:29 To: MailScanner discussion Subject: Re: MailScanner via Yum (CentOS) Paul Hutchings wrote: >> Read the install.sh script :-) >> > > Rather embarrassingly I did once I'd sent the reply to the list :-) > > I'd appreciate any feedback on how other people handle this - I can see > the benefits of using the rpm's supplied with MailScanner as I would > assume it sorts out things like minimum versions req'd, but at the same > time I'm thinking is there a benefit to using as much as possible of > what comes with the OS? > It doesn't install a new module unless it needs to for some reason. If your current version is okay, then it will leave it as it is and not upgrade it. But many of the requirements are not shipped with the OS. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MIRA Ltd Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. Registered in England and Wales No. 402570 VAT Registration GB 114 5409 96 The contents of this e-mail are confidential and are solely for the use of the intended recipient. If you receive this e-mail in error, please delete it and notify us either by e-mail, telephone or fax. You should not copy, forward or otherwise disclose the content of the e-mail as this is prohibited. From MailScanner at ecs.soton.ac.uk Wed Aug 29 10:49:39 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 29 10:49:57 2007 Subject: Outgoing Queue Dir Ruleset In-Reply-To: <011a01c7e9f4$9ee70220$cc01a8c0@Dual> References: <200708261100.l7QB02E8013272@safir.blacknight.ie> <000801c7e81e$953686b0$cc01a8c0@Dual><46D1E2A5.4090500@ecs.soton.ac.uk> <46D1E87A.9060601@ecs.soton.ac.uk><00c301c7e8d1$6dc1e120$cc01a8c0@Dual> <46D31A08.9080806@ecs.soton.ac.uk><009401c7e973$564e4770$cc01a8c0@Dual> <46D42119.1010209@ecs.soton.ac.uk> <011a01c7e9f4$9ee70220$cc01a8c0@Dual> Message-ID: <46D54133.8080201@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Jim Hermann wrote: >> Jim Hermann wrote: >> >>> No. I was hoping to use a Ruleset for the Outgoing Queue Dir and use >>> separate instances of sendmail to handle each outgoing >>> >> queue directory. Is >> >>> there a way to have MS tell sendmail to use different >>> >> configuration files >> >>> for each outgoing queue directory? >>> >>> >> Only by hacking the code, sorry. It's not built-in >> functionality, sorry. >> >> 2nd thoughts: can you put a ruleset on sendmail2? The conf file will >> tell you if you can or not, I can't remember. >> > > I don't feel bad for not noticing. ;) > > Now my MailScanner.conf contains: > > Outgoing Queue Dir = /etc/MailScanner/rules/outgoing.rules > Sendmail2 = /etc/MailScanner/rules/sendmail2.rules > Use Default Rules With Multiple Recipients = yes > Delivery Method = batch > > /etc/MailScanner/rules/outgoing.rules contains: > > To: *@aol.com > /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.scanned1 > To: *@cs.com > /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.scanned1 > To: *@comcast.net > /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.scanned2 > To: *@yahoo.com > /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.scanned2 > > FromOrTo: default > /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue.scanned > > /etc/MailScanner/rules/sendmail2.rules contains: > > To: *@aol.com /usr/sbin/sendmail -L sm-mailscanner1 > -OProcessTitlePrefix=sm-mailscanner1 -ODeliveryMode=background -C > /etc/mail/sm-mailscanner1.cf > To: *@cs.com /usr/sbin/sendmail -L sm-mailscanner1 > -OProcessTitlePrefix=sm-mailscanner1 -ODeliveryMode=background -C > /etc/mail/sm-mailscanner1.cf > To: *@comcast.net /usr/sbin/sendmail -L sm-mailscanner2 > -OProcessTitlePrefix=sm-mailscanner2 -ODeliveryMode=background -C > /etc/mail/sm-mailscanner2.cf > To: *@yahoo.com /usr/sbin/sendmail -L sm-mailscanner2 > -OProcessTitlePrefix=sm-mailscanner2 -ODeliveryMode=background -C > /etc/mail/sm-mailscanner2.cf > > FromOrTo: default /usr/sbin/sendmail -L sm-mailscanner > -OProcessTitlePrefix=sm-mailscanner -ODeliveryMode=background -C > /etc/mail/sm-mailscanner.cf > > MailScanner stores the email in the correct directory but does not use the > correct version of sendmail2. It does use the default value of sendmail2. > The "sm-mailscanner" shows up in the log. How do I get the Ruleset to match > the other values for Sendmail2? > You upgrade to my next release :-) I have just found the bug and fixed it. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Comment: (pgp-secured) Charset: ISO-8859-1 wj8DBQFG1UEzEfZZRxQVtlQRAkM0AKCxOtAKfzdRMH4FKPtMi2XEvC5XHACeKP8R 3ObgpFL/qDs1cb37n4Z0mJQ= =umQw -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From christiannygaard at gmail.com Wed Aug 29 12:22:53 2007 From: christiannygaard at gmail.com (Christian Nygaard) Date: Wed Aug 29 12:22:57 2007 Subject: Spam Filter Fusion with MailScanner? Message-ID: <4d4321660708290422j19c1a5fei64802005fa6b4b1e@mail.gmail.com> Hi! Today we are using MailScanner with SpamAssassin but it seems that more Spam is leaking through the last couple of months. I was wondering if anyone have started to use Spam filter fusion, fusing in more filters than SpamAssassin? If you did, how did you do it? On-line Spam Filter Fusion http://plg.uwaterloo.ca/~gvcormac/sigir.pdf http://plg.uwaterloo.ca/~gvcormac/dmcspam.pdf Kind regards, Christian -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070829/553f7341/attachment.html From list-mailscanner at linguaphone.com Wed Aug 29 12:43:46 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 29 12:43:56 2007 Subject: list of variables which can be used in reports Message-ID: <1188387826.3776.3.camel@gblades-suse.linguaphone-intranet.co.uk> Is there a list of variables that can be used in reports anywhere? I have a look in the book and on wiki but could not find anything. In particular I would like to change the inline spam report so that it also reports the total spamassassin score. Thanks Gareth From list-mailscanner at linguaphone.com Wed Aug 29 12:45:41 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 29 12:45:49 2007 Subject: Spam Filter Fusion with MailScanner? In-Reply-To: <4d4321660708290422j19c1a5fei64802005fa6b4b1e@mail.gmail.com> References: <4d4321660708290422j19c1a5fei64802005fa6b4b1e@mail.gmail.com> Message-ID: <1188387941.3781.6.camel@gblades-suse.linguaphone-intranet.co.uk> No I haven't because I find that we catch practically all the spam. Perhaps there are some additional rules or plugins you could be using. Is your mailscanner and spamassassin fully up to date? What plugins, antivirus and additional rules do you use? On Wed, 2007-08-29 at 12:22, Christian Nygaard wrote: > Hi! > > Today we are using MailScanner with SpamAssassin but it seems that > more > Spam is leaking through the last couple of months. > > I was wondering if anyone have started to use Spam filter fusion, > fusing in more > filters than SpamAssassin? If you did, how did you do it? > > On-line Spam Filter Fusion > http://plg.uwaterloo.ca/~gvcormac/sigir.pdf > http://plg.uwaterloo.ca/~gvcormac/dmcspam.pdf > > Kind regards, > Christian > > > > ______________________________________________________________________ > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From wizard at jimhermann.com Wed Aug 29 13:23:04 2007 From: wizard at jimhermann.com (Jim Hermann) Date: Wed Aug 29 13:22:57 2007 Subject: Outgoing Queue Dir Ruleset In-Reply-To: <46D54133.8080201@ecs.soton.ac.uk> References: <200708261100.l7QB02E8013272@safir.blacknight.ie> <000801c7e81e$953686b0$cc01a8c0@Dual><46D1E2A5.4090500@ecs.soton.ac.uk> <46D1E87A.9060601@ecs.soton.ac.uk><00c301c7e8d1$6dc1e120$cc01a8c0@Dual> <46D31A08.9080806@ecs.soton.ac.uk><009401c7e973$564e4770$cc01a8c0@Dual> <46D42119.1010209@ecs.soton.ac.uk><011a01c7e9f4$9ee70220$cc01a8c0@Dual> <46D54133.8080201@ecs.soton.ac.uk> Message-ID: <013c01c7ea37$5aea64c0$cc01a8c0@Dual> > > MailScanner stores the email in the correct directory but > does not use the > > correct version of sendmail2. It does use the default > value of sendmail2. > > The "sm-mailscanner" shows up in the log. How do I get the > Ruleset to match > > the other values for Sendmail2? > > > You upgrade to my next release :-) > I have just found the bug and fixed it. > > Jules Thanks. Can I download the latest beta and get the fix? Jim From MailScanner at ecs.soton.ac.uk Wed Aug 29 13:42:49 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 29 13:43:07 2007 Subject: list of variables which can be used in reports In-Reply-To: <1188387826.3776.3.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1188387826.3776.3.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <46D569C9.7060206@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Each of the sample reports I provide use all the variables available in that report. If you need any adding, just tell me what you want and where you want to use it. Gareth wrote: > Is there a list of variables that can be used in reports anywhere? > I have a look in the book and on wiki but could not find anything. > > In particular I would like to change the inline spam report so that it > also reports the total spamassassin score. > > Thanks > Gareth > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Comment: (pgp-secured) Charset: ISO-8859-1 wj8DBQFG1WnKEfZZRxQVtlQRAjOMAKDv3xvdvg4NnszZQfONbjkx7a/KxACgiMtf ZAqlgmHz/zYbZd8uuP4VlHI= =s2b8 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Wed Aug 29 13:48:14 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 29 13:49:16 2007 Subject: Outgoing Queue Dir Ruleset In-Reply-To: <013c01c7ea37$5aea64c0$cc01a8c0@Dual> References: <200708261100.l7QB02E8013272@safir.blacknight.ie> <000801c7e81e$953686b0$cc01a8c0@Dual><46D1E2A5.4090500@ecs.soton.ac.uk> <46D1E87A.9060601@ecs.soton.ac.uk><00c301c7e8d1$6dc1e120$cc01a8c0@Dual> <46D31A08.9080806@ecs.soton.ac.uk><009401c7e973$564e4770$cc01a8c0@Dual> <46D42119.1010209@ecs.soton.ac.uk><011a01c7e9f4$9ee70220$cc01a8c0@Dual> <46D54133.8080201@ecs.soton.ac.uk> <013c01c7ea37$5aea64c0$cc01a8c0@Dual> Message-ID: <46D56B0E.30507@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Jim Hermann wrote: >>> MailScanner stores the email in the correct directory but >>> >> does not use the >> >>> correct version of sendmail2. It does use the default >>> >> value of sendmail2. >> >>> The "sm-mailscanner" shows up in the log. How do I get the >>> >> Ruleset to match >> >>> the other values for Sendmail2? >>> >>> >> You upgrade to my next release :-) >> I have just found the bug and fixed it. >> >> Jules >> > > Thanks. > > Can I download the latest beta and get the fix? > I have just created 4.63.5 for you. Please test it as soon as you can and let me know how you get on. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Comment: (pgp-secured) Charset: ISO-8859-1 wj8DBQFG1WsOEfZZRxQVtlQRAuO5AJ9eCUCAYr+Bmtrp3ghKH8ozhWJXVQCbBgUF FSQ0YakMCpE6xeDQ1YEVWlc= =p+Qi -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From list-mailscanner at linguaphone.com Wed Aug 29 13:49:46 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 29 13:49:52 2007 Subject: list of variables which can be used in reports In-Reply-To: <46D569C9.7060206@ecs.soton.ac.uk> References: <1188387826.3776.3.camel@gblades-suse.linguaphone-intranet.co.uk> <46D569C9.7060206@ecs.soton.ac.uk> Message-ID: <1188391785.3773.12.camel@gblades-suse.linguaphone-intranet.co.uk> It would be useful to have the total spam score as a variable. The reason being that I get users to drop copies of all false positives into a shared folder and it would save me having to manually add up all the scores to find what the total was. Depending on how much over the threshold it was I decide to do various things such as whitelist them, tell them to fix their mail system or do nothing :) Thanks On Wed, 2007-08-29 at 13:42, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Each of the sample reports I provide use all the variables available in > that report. > If you need any adding, just tell me what you want and where you want to > use it. > > Gareth wrote: > > Is there a list of variables that can be used in reports anywhere? > > I have a look in the book and on wiki but could not find anything. > > > > In particular I would like to change the inline spam report so that it > > also reports the total spamassassin score. > > > > Thanks > > Gareth > > > > > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > Need help customising MailScanner? > Contact me! > Need help fixing or optimising your systems? > Contact me! > Need help getting you started solving new requirements from your boss? > Contact me! > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.3 (Build 3017) > Comment: (pgp-secured) > Charset: ISO-8859-1 > > wj8DBQFG1WnKEfZZRxQVtlQRAjOMAKDv3xvdvg4NnszZQfONbjkx7a/KxACgiMtf > ZAqlgmHz/zYbZd8uuP4VlHI= > =s2b8 > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Wed Aug 29 13:54:07 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 29 13:54:25 2007 Subject: Spam Filter Fusion with MailScanner? In-Reply-To: <1188387941.3781.6.camel@gblades-suse.linguaphone-intranet.co.uk> References: <4d4321660708290422j19c1a5fei64802005fa6b4b1e@mail.gmail.com> <1188387941.3781.6.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <46D56C6F.9080304@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 metoo. I find that I can catch just about every spam that comes in here. I probably miss 2 or 3 per day into my own account, and mailscanner@ecs.soton.ac.uk is in an awful lot of address lists! Over the past couple of months, if anything, I have been more successful than usual. If you want me to give your server a thorough health-check and improve your anti-spam setup, I will happily do so, but I do charge for the service. Contact me off-list if you are interested. Best regards, Jules. Gareth wrote: > No I haven't because I find that we catch practically all the spam. > Perhaps there are some additional rules or plugins you could be using. > Is your mailscanner and spamassassin fully up to date? > What plugins, antivirus and additional rules do you use? > > On Wed, 2007-08-29 at 12:22, Christian Nygaard wrote: > >> Hi! >> >> Today we are using MailScanner with SpamAssassin but it seems that >> more >> Spam is leaking through the last couple of months. >> >> I was wondering if anyone have started to use Spam filter fusion, >> fusing in more >> filters than SpamAssassin? If you did, how did you do it? >> >> On-line Spam Filter Fusion >> http://plg.uwaterloo.ca/~gvcormac/sigir.pdf >> http://plg.uwaterloo.ca/~gvcormac/dmcspam.pdf >> >> Kind regards, >> Christian >> >> >> >> ______________________________________________________________________ >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Comment: (pgp-secured) Charset: ISO-8859-1 wj8DBQFG1WxwEfZZRxQVtlQRAmoAAKDjXnoOxtJBgltNWmhVxn08k23WswCg1FvQ YGOa3VcRm3bJHCNdnNTKhHQ= =fnk4 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Wed Aug 29 13:55:31 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 29 13:55:58 2007 Subject: list of variables which can be used in reports In-Reply-To: <1188391785.3773.12.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1188387826.3776.3.camel@gblades-suse.linguaphone-intranet.co.uk> <46D569C9.7060206@ecs.soton.ac.uk> <1188391785.3773.12.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <46D56CC3.7020200@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 But in which report(s) specifically? And don't say "all of them" :-) Gareth wrote: > It would be useful to have the total spam score as a variable. > > The reason being that I get users to drop copies of all false positives > into a shared folder and it would save me having to manually add up all > the scores to find what the total was. Depending on how much over the > threshold it was I decide to do various things such as whitelist them, > tell them to fix their mail system or do nothing :) > > Thanks > > On Wed, 2007-08-29 at 13:42, Julian Field wrote: > >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> Each of the sample reports I provide use all the variables available in >> that report. >> If you need any adding, just tell me what you want and where you want to >> use it. >> >> Gareth wrote: >> >>> Is there a list of variables that can be used in reports anywhere? >>> I have a look in the book and on wiki but could not find anything. >>> >>> In particular I would like to change the inline spam report so that it >>> also reports the total spamassassin score. >>> >>> Thanks >>> Gareth >>> >>> >>> >> Jules >> >> - -- >> Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> Need help customising MailScanner? >> Contact me! >> Need help fixing or optimising your systems? >> Contact me! >> Need help getting you started solving new requirements from your boss? >> Contact me! >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> >> >> -----BEGIN PGP SIGNATURE----- >> Version: PGP Desktop 9.6.3 (Build 3017) >> Comment: (pgp-secured) >> Charset: ISO-8859-1 >> >> wj8DBQFG1WnKEfZZRxQVtlQRAjOMAKDv3xvdvg4NnszZQfONbjkx7a/KxACgiMtf >> ZAqlgmHz/zYbZd8uuP4VlHI= >> =s2b8 >> -----END PGP SIGNATURE----- >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> For all your IT requirements visit www.transtec.co.uk >> > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Comment: (pgp-secured) Charset: ISO-8859-1 wj8DBQFG1WzEEfZZRxQVtlQRAlCnAKCnSNqx5goX+IwKXK8F+IgWfGc3jwCg+7Gt zJ/GCo6o8GBmLmMx8nzltqk= =bDpY -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From list-mailscanner at linguaphone.com Wed Aug 29 13:59:56 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 29 14:00:09 2007 Subject: list of variables which can be used in reports In-Reply-To: <46D56CC3.7020200@ecs.soton.ac.uk> References: <1188387826.3776.3.camel@gblades-suse.linguaphone-intranet.co.uk> <46D569C9.7060206@ecs.soton.ac.uk> <1188391785.3773.12.camel@gblades-suse.linguaphone-intranet.co.uk> <46D56CC3.7020200@ecs.soton.ac.uk> Message-ID: <1188392396.3779.14.camel@gblades-suse.linguaphone-intranet.co.uk> en/inline.spam.warning.txt please. On Wed, 2007-08-29 at 13:55, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > But in which report(s) specifically? And don't say "all of them" :-) > > Gareth wrote: > > It would be useful to have the total spam score as a variable. > > > > The reason being that I get users to drop copies of all false positives > > into a shared folder and it would save me having to manually add up all > > the scores to find what the total was. Depending on how much over the > > threshold it was I decide to do various things such as whitelist them, > > tell them to fix their mail system or do nothing :) > > > > Thanks > > > > On Wed, 2007-08-29 at 13:42, Julian Field wrote: > > > >> -----BEGIN PGP SIGNED MESSAGE----- > >> Hash: SHA1 > >> > >> Each of the sample reports I provide use all the variables available in > >> that report. > >> If you need any adding, just tell me what you want and where you want to > >> use it. > >> > >> Gareth wrote: > >> > >>> Is there a list of variables that can be used in reports anywhere? > >>> I have a look in the book and on wiki but could not find anything. > >>> > >>> In particular I would like to change the inline spam report so that it > >>> also reports the total spamassassin score. > >>> > >>> Thanks > >>> Gareth > >>> > >>> > >>> > >> Jules > >> > >> - -- > >> Julian Field MEng CITP > >> www.MailScanner.info > >> Buy the MailScanner book at www.MailScanner.info/store > >> > >> Need help customising MailScanner? > >> Contact me! > >> Need help fixing or optimising your systems? > >> Contact me! > >> Need help getting you started solving new requirements from your boss? > >> Contact me! > >> > >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > >> > >> > >> -----BEGIN PGP SIGNATURE----- > >> Version: PGP Desktop 9.6.3 (Build 3017) > >> Comment: (pgp-secured) > >> Charset: ISO-8859-1 > >> > >> wj8DBQFG1WnKEfZZRxQVtlQRAjOMAKDv3xvdvg4NnszZQfONbjkx7a/KxACgiMtf > >> ZAqlgmHz/zYbZd8uuP4VlHI= > >> =s2b8 > >> -----END PGP SIGNATURE----- > >> > >> -- > >> This message has been scanned for viruses and > >> dangerous content by MailScanner, and is > >> believed to be clean. > >> For all your IT requirements visit www.transtec.co.uk > >> > > > > > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > Need help customising MailScanner? > Contact me! > Need help fixing or optimising your systems? > Contact me! > Need help getting you started solving new requirements from your boss? > Contact me! > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.3 (Build 3017) > Comment: (pgp-secured) > Charset: ISO-8859-1 > > wj8DBQFG1WzEEfZZRxQVtlQRAlCnAKCnSNqx5goX+IwKXK8F+IgWfGc3jwCg+7Gt > zJ/GCo6o8GBmLmMx8nzltqk= > =bDpY > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk From Denis.Beauchemin at USherbrooke.ca Wed Aug 29 14:42:27 2007 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Wed Aug 29 14:46:26 2007 Subject: list of variables which can be used in reports In-Reply-To: <1188387826.3776.3.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1188387826.3776.3.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <46D577C3.10705@USherbrooke.ca> Gareth a ?crit : > Is there a list of variables that can be used in reports anywhere? > I have a look in the book and on wiki but could not find anything. > > In particular I would like to change the inline spam report so that it > also reports the total spamassassin score. > > Thanks > Gareth > > Gareth, No need to modify MS if you use "$longspamreport" in your report. I added the following to spam.assassin.prefs.conf and it becomes the new "$longspamreport": clear-report-template report D?tails de l'analyse du message: (_HITS_ points, _REQD_ requis) report pts nom de la r?gle description report ---- ---------------------- -------------------------------------------------- report _SUMMARY_ The _HITS_ prints the total SA score, while _REQD_ prints the required score. Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x62252 F: 819.821.8045 From MailScanner at ecs.soton.ac.uk Wed Aug 29 14:53:28 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 29 14:53:49 2007 Subject: list of variables which can be used in reports In-Reply-To: <1188392396.3779.14.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1188387826.3776.3.camel@gblades-suse.linguaphone-intranet.co.uk> <46D569C9.7060206@ecs.soton.ac.uk> <1188391785.3773.12.camel@gblades-suse.linguaphone-intranet.co.uk> <46D56CC3.7020200@ecs.soton.ac.uk> <1188392396.3779.14.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <46D57A58.50406@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 You should already be able to use "$sascore" in this report. Sorry it's not in the example report, I must have overlooked that. Any others you need? Gareth wrote: > en/inline.spam.warning.txt please. > > On Wed, 2007-08-29 at 13:55, Julian Field wrote: > >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> But in which report(s) specifically? And don't say "all of them" :-) >> >> Gareth wrote: >> >>> It would be useful to have the total spam score as a variable. >>> >>> The reason being that I get users to drop copies of all false positives >>> into a shared folder and it would save me having to manually add up all >>> the scores to find what the total was. Depending on how much over the >>> threshold it was I decide to do various things such as whitelist them, >>> tell them to fix their mail system or do nothing :) >>> >>> Thanks >>> >>> On Wed, 2007-08-29 at 13:42, Julian Field wrote: >>> >>> >>>> -----BEGIN PGP SIGNED MESSAGE----- >>>> Hash: SHA1 >>>> >>>> Each of the sample reports I provide use all the variables available in >>>> that report. >>>> If you need any adding, just tell me what you want and where you want to >>>> use it. >>>> >>>> Gareth wrote: >>>> >>>> >>>>> Is there a list of variables that can be used in reports anywhere? >>>>> I have a look in the book and on wiki but could not find anything. >>>>> >>>>> In particular I would like to change the inline spam report so that it >>>>> also reports the total spamassassin score. >>>>> >>>>> Thanks >>>>> Gareth >>>>> >>>>> >>>>> >>>>> >>>> Jules >>>> >>>> - -- >>>> Julian Field MEng CITP >>>> www.MailScanner.info >>>> Buy the MailScanner book at www.MailScanner.info/store >>>> >>>> Need help customising MailScanner? >>>> Contact me! >>>> Need help fixing or optimising your systems? >>>> Contact me! >>>> Need help getting you started solving new requirements from your boss? >>>> Contact me! >>>> >>>> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >>>> >>>> >>>> -----BEGIN PGP SIGNATURE----- >>>> Version: PGP Desktop 9.6.3 (Build 3017) >>>> Comment: (pgp-secured) >>>> Charset: ISO-8859-1 >>>> >>>> wj8DBQFG1WnKEfZZRxQVtlQRAjOMAKDv3xvdvg4NnszZQfONbjkx7a/KxACgiMtf >>>> ZAqlgmHz/zYbZd8uuP4VlHI= >>>> =s2b8 >>>> -----END PGP SIGNATURE----- >>>> >>>> -- >>>> This message has been scanned for viruses and >>>> dangerous content by MailScanner, and is >>>> believed to be clean. >>>> For all your IT requirements visit www.transtec.co.uk >>>> >>>> >>> >>> >> Jules >> >> - -- >> Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> Need help customising MailScanner? >> Contact me! >> Need help fixing or optimising your systems? >> Contact me! >> Need help getting you started solving new requirements from your boss? >> Contact me! >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> >> >> -----BEGIN PGP SIGNATURE----- >> Version: PGP Desktop 9.6.3 (Build 3017) >> Comment: (pgp-secured) >> Charset: ISO-8859-1 >> >> wj8DBQFG1WzEEfZZRxQVtlQRAlCnAKCnSNqx5goX+IwKXK8F+IgWfGc3jwCg+7Gt >> zJ/GCo6o8GBmLmMx8nzltqk= >> =bDpY >> -----END PGP SIGNATURE----- >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> For all your IT requirements visit www.transtec.co.uk >> > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Comment: (pgp-secured) Charset: ISO-8859-15 wj8DBQFG1XpZEfZZRxQVtlQRAiFpAJ9k5bJIxeq83zR8a4VwiIJHjTMfXACeJC3z G9o7Ewzmqn+55QDHvlYA2Ew= =GBej -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From list-mailscanner at linguaphone.com Wed Aug 29 15:08:45 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed Aug 29 15:08:55 2007 Subject: list of variables which can be used in reports In-Reply-To: <46D57A58.50406@ecs.soton.ac.uk> References: <1188387826.3776.3.camel@gblades-suse.linguaphone-intranet.co.uk> <46D569C9.7060206@ecs.soton.ac.uk> <1188391785.3773.12.camel@gblades-suse.linguaphone-intranet.co.uk> <46D56CC3.7020200@ecs.soton.ac.uk> <1188392396.3779.14.camel@gblades-suse.linguaphone-intranet.co.uk> <46D57A58.50406@ecs.soton.ac.uk> Message-ID: <1188396525.3773.16.camel@gblades-suse.linguaphone-intranet.co.uk> Just modified the report and it is working fine. Thanks On Wed, 2007-08-29 at 14:53, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > You should already be able to use "$sascore" in this report. Sorry it's > not in the example report, I must have overlooked that. Any others you need? > > Gareth wrote: > > en/inline.spam.warning.txt please. > > > > On Wed, 2007-08-29 at 13:55, Julian Field wrote: > > > >> -----BEGIN PGP SIGNED MESSAGE----- > >> Hash: SHA1 > >> > >> But in which report(s) specifically? And don't say "all of them" :-) > >> > >> Gareth wrote: > >> > >>> It would be useful to have the total spam score as a variable. > >>> > >>> The reason being that I get users to drop copies of all false positives > >>> into a shared folder and it would save me having to manually add up all > >>> the scores to find what the total was. Depending on how much over the > >>> threshold it was I decide to do various things such as whitelist them, > >>> tell them to fix their mail system or do nothing :) > >>> > >>> Thanks > >>> > >>> On Wed, 2007-08-29 at 13:42, Julian Field wrote: > >>> > >>> > >>>> -----BEGIN PGP SIGNED MESSAGE----- > >>>> Hash: SHA1 > >>>> > >>>> Each of the sample reports I provide use all the variables available in > >>>> that report. > >>>> If you need any adding, just tell me what you want and where you want to > >>>> use it. > >>>> > >>>> Gareth wrote: > >>>> > >>>> > >>>>> Is there a list of variables that can be used in reports anywhere? > >>>>> I have a look in the book and on wiki but could not find anything. > >>>>> > >>>>> In particular I would like to change the inline spam report so that it > >>>>> also reports the total spamassassin score. > >>>>> > >>>>> Thanks > >>>>> Gareth > >>>>> > >>>>> > >>>>> > >>>>> > >>>> Jules > >>>> > >>>> - -- > >>>> Julian Field MEng CITP > >>>> www.MailScanner.info > >>>> Buy the MailScanner book at www.MailScanner.info/store > >>>> > >>>> Need help customising MailScanner? > >>>> Contact me! > >>>> Need help fixing or optimising your systems? > >>>> Contact me! > >>>> Need help getting you started solving new requirements from your boss? > >>>> Contact me! > >>>> > >>>> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > >>>> > >>>> > >>>> -----BEGIN PGP SIGNATURE----- > >>>> Version: PGP Desktop 9.6.3 (Build 3017) > >>>> Comment: (pgp-secured) > >>>> Charset: ISO-8859-1 > >>>> > >>>> wj8DBQFG1WnKEfZZRxQVtlQRAjOMAKDv3xvdvg4NnszZQfONbjkx7a/KxACgiMtf > >>>> ZAqlgmHz/zYbZd8uuP4VlHI= > >>>> =s2b8 > >>>> -----END PGP SIGNATURE----- > >>>> > >>>> -- > >>>> This message has been scanned for viruses and > >>>> dangerous content by MailScanner, and is > >>>> believed to be clean. > >>>> For all your IT requirements visit www.transtec.co.uk > >>>> > >>>> > >>> > >>> > >> Jules > >> > >> - -- > >> Julian Field MEng CITP > >> www.MailScanner.info > >> Buy the MailScanner book at www.MailScanner.info/store > >> > >> Need help customising MailScanner? > >> Contact me! > >> Need help fixing or optimising your systems? > >> Contact me! > >> Need help getting you started solving new requirements from your boss? > >> Contact me! > >> > >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > >> > >> > >> -----BEGIN PGP SIGNATURE----- > >> Version: PGP Desktop 9.6.3 (Build 3017) > >> Comment: (pgp-secured) > >> Charset: ISO-8859-1 > >> > >> wj8DBQFG1WzEEfZZRxQVtlQRAlCnAKCnSNqx5goX+IwKXK8F+IgWfGc3jwCg+7Gt > >> zJ/GCo6o8GBmLmMx8nzltqk= > >> =bDpY > >> -----END PGP SIGNATURE----- > >> > >> -- > >> This message has been scanned for viruses and > >> dangerous content by MailScanner, and is > >> believed to be clean. > >> For all your IT requirements visit www.transtec.co.uk > >> > > > > > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > Need help customising MailScanner? > Contact me! > Need help fixing or optimising your systems? > Contact me! > Need help getting you started solving new requirements from your boss? > Contact me! > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.3 (Build 3017) > Comment: (pgp-secured) > Charset: ISO-8859-15 > > wj8DBQFG1XpZEfZZRxQVtlQRAiFpAJ9k5bJIxeq83zR8a4VwiIJHjTMfXACeJC3z > G9o7Ewzmqn+55QDHvlYA2Ew= > =GBej > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk From paul.hutchings at mira.co.uk Wed Aug 29 16:23:34 2007 From: paul.hutchings at mira.co.uk (Paul Hutchings) Date: Wed Aug 29 16:23:37 2007 Subject: missing /usr/lib/MailScanner/clamd-wrapper?! Message-ID: When running update_virus_scanners I get "/usr/lib/MailScanner/clamd-wrapper: No such file or directory" Which is understandable as it isn't there. I'm not sure why I'm seeing it though? Scanning is done through clamd and seems to work fine, though of course this makes me wonder how it can be working when it is also specified for clamd in virus.scanners.conf?! Hope that makes sense! Paul Paul Hutchings Network Administrator, MIRA Ltd. Tel: 44 (0)24 7635 5378 Fax: 44 (0)24 7635 8378 mailto:paul.hutchings@mira.co.uk -- MIRA Ltd Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. Registered in England and Wales No. 402570 VAT Registration GB 114 5409 96 The contents of this e-mail are confidential and are solely for the use of the intended recipient. If you receive this e-mail in error, please delete it and notify us either by e-mail, telephone or fax. You should not copy, forward or otherwise disclose the content of the e-mail as this is prohibited. From ssilva at sgvwater.com Wed Aug 29 16:39:52 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed Aug 29 16:40:04 2007 Subject: list of variables which can be used in reports In-Reply-To: <46D577C3.10705@USherbrooke.ca> References: <1188387826.3776.3.camel@gblades-suse.linguaphone-intranet.co.uk> <46D577C3.10705@USherbrooke.ca> Message-ID: Denis Beauchemin spake the following on 8/29/2007 6:42 AM: > Gareth a ?crit : >> Is there a list of variables that can be used in reports anywhere? >> I have a look in the book and on wiki but could not find anything. >> >> In particular I would like to change the inline spam report so that it >> also reports the total spamassassin score. >> >> Thanks >> Gareth >> >> > Gareth, > > No need to modify MS if you use "$longspamreport" in your report. I > added the following to spam.assassin.prefs.conf and it becomes the new > "$longspamreport": > clear-report-template > report D?tails de l'analyse du message: (_HITS_ points, _REQD_ requis) > report pts nom de la r?gle description > report ---- ---------------------- > -------------------------------------------------- > report _SUMMARY_ > > The _HITS_ prints the total SA score, while _REQD_ prints the required > score. > --OT-- French is such a beautiful looking language! I wish I would have studied better in class. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From cparker at swatgear.com Wed Aug 29 17:24:39 2007 From: cparker at swatgear.com (Chris W. Parker) Date: Wed Aug 29 17:24:42 2007 Subject: Releaseing mail from quarantine (wiki instructions didn't work) Message-ID: <97FD54B5E57A1842AA1A4B232E4761178EEAF4@ati-ex-02.ati.local> Hello, First issue is that I've got an email that is being quarantined because it is claimed to be "nested too deeply". To release it from the quarantine I referred to http://wiki.mailscanner.info/doku.php?id=maq:index#quarantine_management . It says to simply copy the qf/df file pair of the offending email into the outgoing queue. But when I do that nothing happens. The email just sits there in the queue whilst other emails (that are received and found to be clean) come and go through the queue. I finally restarted MailScanner and that seemed to get the message on its way. Which brings me to the second issue... After MailScanner restarted it was quarantined again for the same problem. Back to square one. I'd like to suggest that the wiki be updated with more complete instructions since, unless my system is out of the norm, those instructions very lacking. It doesn't mention the need to restart MailScanner and simply copying the qf/df files to the outgoing queue merely results in the email(s) being quarantined again. So now I'm looking for the rule that caused this email to be quarantined in the first place and the best I could find is: ClamAVmodule Maximum Recursion Level = 8 I raised the max up to 25 and redid the release+restart and the user was able to receive the email. When I checked the .zip it only had one folder with two files. So... file.zip: folder fileA.xls fileB.xls This is hardly 25 levels of nesting. What could cause this to be flagged? Another part in this puzzle is that the message was larger than the "Max Spam Check Size = 150000" limit. Could this be related? Thanks, Chris. From Richard.Frovarp at sendit.nodak.edu Wed Aug 29 17:36:16 2007 From: Richard.Frovarp at sendit.nodak.edu (Richard Frovarp) Date: Wed Aug 29 17:36:19 2007 Subject: Releaseing mail from quarantine (wiki instructions didn't work) In-Reply-To: <97FD54B5E57A1842AA1A4B232E4761178EEAF4@ati-ex-02.ati.local> References: <97FD54B5E57A1842AA1A4B232E4761178EEAF4@ati-ex-02.ati.local> Message-ID: <46D5A080.1030908@sendit.nodak.edu> Chris W. Parker wrote: > Hello, > > First issue is that I've got an email that is being quarantined because > it is claimed to be "nested too deeply". > > To release it from the quarantine I referred to > http://wiki.mailscanner.info/doku.php?id=maq:index#quarantine_management > . It says to simply copy the qf/df file pair of the offending email into > the outgoing queue. But when I do that nothing happens. The email just > sits there in the queue whilst other emails (that are received and found > to be clean) come and go through the queue. I finally restarted > MailScanner and that seemed to get the message on its way. Which brings > me to the second issue... After MailScanner restarted it was quarantined > again for the same problem. Back to square one. > > I'd like to suggest that the wiki be updated with more complete > instructions since, unless my system is out of the norm, those > instructions very lacking. It doesn't mention the need to restart > MailScanner and simply copying the qf/df files to the outgoing queue > merely results in the email(s) being quarantined again. > > Are you sure you copied it to the outgoing queue? MailScanner won't read files out of there. It should only be checking the incoming queue. > > Another part in this puzzle is that the message was larger than the "Max > Spam Check Size = 150000" limit. Could this be related? > That should cause the message to be skipped from being checked for spam by SA. Sounds like it probably was as ClamAV is what was triggering on this message. From MailScanner at ecs.soton.ac.uk Wed Aug 29 17:36:55 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 29 17:37:15 2007 Subject: missing /usr/lib/MailScanner/clamd-wrapper?! In-Reply-To: References: Message-ID: <46D5A0A7.40107@ecs.soton.ac.uk> You have an out-of-date virus.scanners.conf file. clamd-wrapper doesn't exist any more. Paul Hutchings wrote: > When running update_virus_scanners I get > "/usr/lib/MailScanner/clamd-wrapper: No such file or directory" > > Which is understandable as it isn't there. I'm not sure why I'm seeing > it though? > > Scanning is done through clamd and seems to work fine, though of course > this makes me wonder how it can be working when it is also specified for > clamd in virus.scanners.conf?! > > Hope that makes sense! > > Paul > > Paul Hutchings > Network Administrator, MIRA Ltd. > Tel: 44 (0)24 7635 5378 > Fax: 44 (0)24 7635 8378 > mailto:paul.hutchings@mira.co.uk > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Wed Aug 29 17:44:41 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 29 17:45:01 2007 Subject: Releaseing mail from quarantine (wiki instructions didn't work) In-Reply-To: <97FD54B5E57A1842AA1A4B232E4761178EEAF4@ati-ex-02.ati.local> References: <97FD54B5E57A1842AA1A4B232E4761178EEAF4@ati-ex-02.ati.local> Message-ID: <46D5A279.8000906@ecs.soton.ac.uk> Once you've copied the message into the *outgoing* queue, it won't get re-read by MailScanner, but you need to tell sendmail to make a delivery attempt on the message, or else it will just get processed the next time the queue runner passes it in the queue. Read the docs for "sendmail -q". If you don't like the instructions on the wiki, please expand them! But you do *not* need to restart MailScanner to flush the outgoing queue, what you are seeing is a side-effect. If you want to try to flush every message in the queue, do "sendmail -q". If you know that the message you are trying to flush contains "01234" in its filename, you can do "sendmail -qI01234" and it will just flush that message. Chris W. Parker wrote: > Hello, > > First issue is that I've got an email that is being quarantined because > it is claimed to be "nested too deeply". > > To release it from the quarantine I referred to > http://wiki.mailscanner.info/doku.php?id=maq:index#quarantine_management > . It says to simply copy the qf/df file pair of the offending email into > the outgoing queue. But when I do that nothing happens. The email just > sits there in the queue whilst other emails (that are received and found > to be clean) come and go through the queue. I finally restarted > MailScanner and that seemed to get the message on its way. Which brings > me to the second issue... After MailScanner restarted it was quarantined > again for the same problem. Back to square one. > > I'd like to suggest that the wiki be updated with more complete > instructions since, unless my system is out of the norm, those > instructions very lacking. It doesn't mention the need to restart > MailScanner and simply copying the qf/df files to the outgoing queue > merely results in the email(s) being quarantined again. > > > So now I'm looking for the rule that caused this email to be quarantined > in the first place and the best I could find is: > > ClamAVmodule Maximum Recursion Level = 8 > > I raised the max up to 25 and redid the release+restart and the user was > able to receive the email. When I checked the .zip it only had one > folder with two files. > > So... > > file.zip: > folder > fileA.xls > fileB.xls > > This is hardly 25 levels of nesting. What could cause this to be > flagged? > > Another part in this puzzle is that the message was larger than the "Max > Spam Check Size = 150000" limit. Could this be related? > > > > Thanks, > Chris. > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From cparker at swatgear.com Wed Aug 29 18:44:32 2007 From: cparker at swatgear.com (Chris W. Parker) Date: Wed Aug 29 18:44:34 2007 Subject: Releaseing mail from quarantine (wiki instructions didn't work) References: <97FD54B5E57A1842AA1A4B232E4761178EEAF4@ati-ex-02.ati.local> <46D5A279.8000906@ecs.soton.ac.uk> Message-ID: <97FD54B5E57A1842AA1A4B232E4761178EEAF6@ati-ex-02.ati.local> On Wednesday, August 29, 2007 9:45 AM Julian Field said: > Once you've copied the message into the *outgoing* queue, it won't get > re-read by MailScanner, but you need to tell sendmail to make a > delivery attempt on the message, or else it will just get processed > the next time the queue runner passes it in the queue. Read the docs > for "sendmail -q". > > If you don't like the instructions on the wiki, please expand them! > But you do *not* need to restart MailScanner to flush the outgoing > queue, what you are seeing is a side-effect. If you want to try to > flush every message in the queue, do "sendmail -q". If you know that > the message you are trying to flush contains "01234" in its filename, > you can do "sendmail -qI01234" and it will just flush that message. Thanks Julian. I didn't realize the wiki was open to everyone so I will note all these things there. Chris. From cparker at swatgear.com Wed Aug 29 18:45:52 2007 From: cparker at swatgear.com (Chris W. Parker) Date: Wed Aug 29 18:45:56 2007 Subject: Releaseing mail from quarantine (wiki instructions didn't work) References: <97FD54B5E57A1842AA1A4B232E4761178EEAF4@ati-ex-02.ati.local> <46D5A279.8000906@ecs.soton.ac.uk> Message-ID: <97FD54B5E57A1842AA1A4B232E4761178EEAF7@ati-ex-02.ati.local> Julian, What about this part? >> ClamAVmodule Maximum Recursion Level = 8 >> >> I raised the max up to 25 and redid the release+restart and the user >> was able to receive the email. When I checked the .zip it only had >> one folder with two files. >> >> So... >> >> file.zip: >> folder >> fileA.xls >> fileB.xls >> >> This is hardly 8 levels of nesting. What could cause this to be >> flagged? Are there any insights you can add to this? Thanks, Chris. From MailScanner at ecs.soton.ac.uk Wed Aug 29 19:14:38 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed Aug 29 19:15:02 2007 Subject: Releaseing mail from quarantine (wiki instructions didn't work) In-Reply-To: <97FD54B5E57A1842AA1A4B232E4761178EEAF7@ati-ex-02.ati.local> References: <97FD54B5E57A1842AA1A4B232E4761178EEAF4@ati-ex-02.ati.local> <46D5A279.8000906@ecs.soton.ac.uk> <97FD54B5E57A1842AA1A4B232E4761178EEAF7@ati-ex-02.ati.local> Message-ID: <46D5B78E.8000208@ecs.soton.ac.uk> Chris W. Parker wrote: > Julian, > > What about this part? > > >>> ClamAVmodule Maximum Recursion Level = 8 >>> >>> I raised the max up to 25 and redid the release+restart and the user >>> was able to receive the email. When I checked the .zip it only had >>> one folder with two files. >>> >>> So... >>> >>> file.zip: >>> folder >>> fileA.xls >>> fileB.xls >>> >>> This is hardly 8 levels of nesting. What could cause this to be >>> flagged? >>> > > Are there any insights you can add to this? > If it's a ClamAVmodule setting, it's just something I pass into the scanner. If there's a bug in ClamAVmodule causing this to be incorrectly interpreted, that ain't my problem :-) Maximum Archive Depth is my problem, so if that is working wrong then do tell me. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From maillists at conactive.com Wed Aug 29 21:31:35 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Wed Aug 29 21:31:38 2007 Subject: MailScanner via Yum (CentOS) In-Reply-To: References: Message-ID: short version: yum install clamav clamav-db --enablerepo=rpmforge for SA: yum install perl-Digest-SHA1 perl-Net-DNS perl-Archive-Tar perl-IO-Zlib yum install --enablerepo=rpmforge perl-Encode-Detect perl-Mail-SPF perl-IP-Country perl-Mail-DKIM perl-Net-Ident for MailScanner: yum install --enablerepo=rpmforge perl-Archive-Zip perl-Convert-BinHex perl-Convert-TNEF perl-DBD-SQLite perl-Filesys-Df perl-IO-stringy perl-MIME-tools perl-Net-CIDR perl-Sys-Hostname-Long install SA (from their latest tarball) unpack the rpm-install tarball for Mailscanner, cd to it and rpm -ivh tnef-*.i386.rpm rpm -ivh mailscanner-*.noarch.rpm configure to your needs Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Wed Aug 29 22:31:28 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Wed Aug 29 22:31:31 2007 Subject: MailScanner via Yum (CentOS) In-Reply-To: <20070828150932.GD21971@fini.net> References: <20070828150932.GD21971@fini.net> Message-ID: John Lundin wrote on Tue, 28 Aug 2007 11:09:32 -0400: > In theory (untried) you should just be able to install the > MailScanner-perl-MIME-Base64 Actually, you don't need it, it's part of Perl. It's just that Julian forces its install if you run the install.sh. So, just run the mailscanner-*.rpm. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From wizard at jimhermann.com Thu Aug 30 03:18:18 2007 From: wizard at jimhermann.com (Jim Hermann) Date: Thu Aug 30 03:18:16 2007 Subject: Outgoing Queue Dir Ruleset In-Reply-To: <46D56B0E.30507@ecs.soton.ac.uk> References: <200708261100.l7QB02E8013272@safir.blacknight.ie> <000801c7e81e$953686b0$cc01a8c0@Dual><46D1E2A5.4090500@ecs.soton.ac.uk> <46D1E87A.9060601@ecs.soton.ac.uk><00c301c7e8d1$6dc1e120$cc01a8c0@Dual> <46D31A08.9080806@ecs.soton.ac.uk><009401c7e973$564e4770$cc01a8c0@Dual> <46D42119.1010209@ecs.soton.ac.uk><011a01c7e9f4$9ee70220$cc01a8c0@Dual> <46D54133.8080201@ecs.soton.ac.uk><013c01c7ea37$5aea64c0$cc01a8c0@Dual> <46D56B0E.30507@ecs.soton.ac.uk> Message-ID: <017c01c7eaac$07ca6e50$cc01a8c0@Dual> > Jim Hermann wrote: > >>> MailScanner stores the email in the correct directory but > >> does not use the > >>> correct version of sendmail2. It does use the default > >> value of sendmail2. > >>> The "sm-mailscanner" shows up in the log. How do I get the > >> Ruleset to match > >>> the other values for Sendmail2? > >>> > >> You upgrade to my next release :-) > >> I have just found the bug and fixed it. > > > > Can I download the latest beta and get the fix? > > > I have just created 4.63.5 for you. Please test it as soon as you can > and let me know how you get on. I just installed it and it appears to be working as specified. Thanks. Jim From tgc at statsbiblioteket.dk Thu Aug 30 07:37:14 2007 From: tgc at statsbiblioteket.dk (Tom G. Christensen) Date: Thu Aug 30 07:37:17 2007 Subject: MailScanner via Yum (CentOS) In-Reply-To: References: Message-ID: <46D6659A.1090903@statsbiblioteket.dk> Kai Schaetzl wrote: > short version: > > yum install clamav clamav-db --enablerepo=rpmforge > > for SA: > yum install perl-Digest-SHA1 perl-Net-DNS perl-Archive-Tar perl-IO-Zlib > yum install --enablerepo=rpmforge perl-Encode-Detect perl-Mail-SPF > perl-IP-Country perl-Mail-DKIM perl-Net-Ident > > for MailScanner: > yum install --enablerepo=rpmforge perl-Archive-Zip perl-Convert-BinHex > perl-Convert-TNEF perl-DBD-SQLite perl-Filesys-Df perl-IO-stringy > perl-MIME-tools perl-Net-CIDR perl-Sys-Hostname-Long > > install SA (from their latest tarball) > Why not install it from rpmforge? It was updated to 3.2.3 within days of the upstream release. > unpack the rpm-install tarball for Mailscanner, cd to it and > > rpm -ivh tnef-*.i386.rpm > rpmfoge also has this one. > rpm -ivh mailscanner-*.noarch.rpm > > configure to your needs > > Kai > -tgc From steve.swaney at fsl.com Thu Aug 30 15:19:14 2007 From: steve.swaney at fsl.com (Stephen Swaney) Date: Thu Aug 30 15:18:35 2007 Subject: BBB trojan Message-ID: <03ed01c7eb10$be41dce0$3ac596a0$@swaney@fsl.com> Heads up. We just started seeing these and they look nasty. Subject: BBB Complaint for Elizabeth MeHaffey [Case id: #48556fc5ba482c6f07ada256696597e1] they purport to be a Better Business Bureau compliant against the company and the recipient of the fraud. Going to a link in the document downloads an executable that is probably not going to be good for your computer. Steve Steve Swaney steve@fsl.com www.fsl.com From R.Sterenborg at netsourcing.nl Thu Aug 30 15:31:29 2007 From: R.Sterenborg at netsourcing.nl (Rob Sterenborg) Date: Thu Aug 30 15:34:30 2007 Subject: BBB trojan In-Reply-To: <03ed01c7eb10$be41dce0$3ac596a0$@swaney@fsl.com> References: <03ed01c7eb10$be41dce0$3ac596a0$@swaney@fsl.com> Message-ID: <74ACEB3E6A055643A89B8CEC74C7BF2488E13E@WISENT.dcyb.net> > Heads up. We just started seeing these and they look nasty. > > Subject: BBB Complaint for Elizabeth MeHaffey [Case id: > #48556fc5ba482c6f07ada256696597e1] > > they purport to be a Better Business Bureau compliant against the > company and the recipient of the fraud. > > Going to a link in the document downloads an executable that is > probably not going to be good for your computer. Could you put the message somewhere on a website and post a link to it? Thanks, Rob From glenn.steen at gmail.com Thu Aug 30 15:43:21 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu Aug 30 15:43:23 2007 Subject: f-prot version 6.0.0 Message-ID: <223f97700708300743w4e6658f3vba82836b9920a4cd@mail.gmail.com> I got this link from our friend Noel (Res...) today, he thought I should alert Jules/the list to the availability of this new version, as well as the changes it introduces. Personally, I don't use f-prot... So someone else will have to touch up the f-prot support to handle the new version. And ... here's the link: http://www.f-prot.com/news/gen_news/070823_release_linux_v6.html (Yeah, this might've been on the list... A quick search of my archive turned up absolutely nothing about it though, so ... :-) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From MailScanner at ecs.soton.ac.uk Thu Aug 30 16:18:51 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 30 16:19:17 2007 Subject: f-prot version 6.0.0 In-Reply-To: <223f97700708300743w4e6658f3vba82836b9920a4cd@mail.gmail.com> References: <223f97700708300743w4e6658f3vba82836b9920a4cd@mail.gmail.com> Message-ID: <46D6DFDB.20607@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I've already written support for it. It will be in the next release. Glenn Steen wrote: > I got this link from our friend Noel (Res...) today, he thought I > should alert Jules/the list to the availability of this new version, > as well as the changes it introduces. > Personally, I don't use f-prot... So someone else will have to touch > up the f-prot support to handle the new version. > > And ... here's the link: > > http://www.f-prot.com/news/gen_news/070823_release_linux_v6.html > > (Yeah, this might've been on the list... A quick search of my archive > turned up absolutely nothing about it though, so ... :-) > Cheers > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Comment: (pgp-secured) Charset: ISO-8859-1 wj8DBQFG1t/bEfZZRxQVtlQRApmdAJ9XSLxzGcq00Ych+fT81lM+m55wGQCg11oC 00BzcFeon1Bm4sOWbns6w18= =lhj9 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Thu Aug 30 16:20:18 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 30 16:20:38 2007 Subject: BBB trojan In-Reply-To: <74ACEB3E6A055643A89B8CEC74C7BF2488E13E@WISENT.dcyb.net> References: <03ed01c7eb10$be41dce0$3ac596a0$@swaney@fsl.com> <74ACEB3E6A055643A89B8CEC74C7BF2488E13E@WISENT.dcyb.net> Message-ID: <46D6E032.20104@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Rob Sterenborg wrote: >> Heads up. We just started seeing these and they look nasty. >> >> Subject: BBB Complaint for Elizabeth MeHaffey [Case id: >> #48556fc5ba482c6f07ada256696597e1] >> >> they purport to be a Better Business Bureau compliant against the >> company and the recipient of the fraud. >> >> Going to a link in the document downloads an executable that is >> probably not going to be good for your computer. >> > > Could you put the message somewhere on a website and post a link to it? > Out of idle curiosity, what is the "Better Business Bureau"? Some company flogging something, I guess... Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Comment: (pgp-secured) Charset: ISO-8859-1 wj8DBQFG1uAzEfZZRxQVtlQRAnKqAJ9osNbjxnJUXlR+PvnN25y6WllsHQCdH+gC BCoJoKuvXiQ3ufWRyAc6KVQ= =qnQa -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From rob at robhq.com Thu Aug 30 16:36:23 2007 From: rob at robhq.com (Rob Freeman) Date: Thu Aug 30 16:36:26 2007 Subject: BBB trojan In-Reply-To: <46D6E032.20104@ecs.soton.ac.uk> References: <74ACEB3E6A055643A89B8CEC74C7BF2488E13E@WISENT.dcyb.net> <46D6E032.20104@ecs.soton.ac.uk> Message-ID: On 8/30/07, Julian Field wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Rob Sterenborg wrote: > >> Heads up. We just started seeing these and they look nasty. > >> > >> Subject: BBB Complaint for Elizabeth MeHaffey [Case id: > >> #48556fc5ba482c6f07ada256696597e1] > >> > >> they purport to be a Better Business Bureau compliant against the > >> company and the recipient of the fraud. > >> > >> Going to a link in the document downloads an executable that is > >> probably not going to be good for your computer. > >> > > > > Could you put the message somewhere on a website and post a link to it? > > > Out of idle curiosity, what is the "Better Business Bureau"? Some > company flogging something, I guess... > > Jules *The Better Business Bureau (BBB)*, founded in 1912, is an organization based in the United Statesand Canada . The BBB states its purpose is to act as a mutually trusted intermediary between consumers and businesses to resolve disputes, to facilitate communication, and to provide information on ethical business practices. Its website lists BBB's core services as: - Business Reliability Reports - Dispute Resolution - Truth-in-Advertising - Consumer and Business Education - Charity Review Rob -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070830/fd9d8795/attachment.html From steve.swaney at fsl.com Thu Aug 30 16:39:16 2007 From: steve.swaney at fsl.com (Stephen Swaney) Date: Thu Aug 30 16:38:37 2007 Subject: BBB trojan In-Reply-To: <46D6E032.20104@ecs.soton.ac.uk> References: <03ed01c7eb10$be41dce0$3ac596a0$@swaney@fsl.com> <74ACEB3E6A055643A89B8CEC74C7BF2488E13E@WISENT.dcyb.net> <46D6E032.20104@ecs.soton.ac.uk> Message-ID: <041401c7eb1b$ed00de90$c7029bb0$@swaney@fsl.com> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Julian Field > Sent: Thursday, August 30, 2007 11:20 AM > To: MailScanner discussion > Subject: Re: BBB trojan > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Rob Sterenborg wrote: > >> Heads up. We just started seeing these and they look nasty. > >> > >> Subject: BBB Complaint for Elizabeth MeHaffey [Case id: > >> #48556fc5ba482c6f07ada256696597e1] > >> > >> they purport to be a Better Business Bureau compliant against the > >> company and the recipient of the fraud. > >> > >> Going to a link in the document downloads an executable that is > >> probably not going to be good for your computer. > >> > > > > Could you put the message somewhere on a website and post a link to > it? > > > Out of idle curiosity, what is the "Better Business Bureau"? Some > company flogging something, I guess... > > Jules > They are legit. A Non-profit that helps sort out consumer complaints here in the US. http://www.bbb.org/ Steve Steve Swaney steve@fsl.com www.fsl.com From sbanderson at impromed.com Thu Aug 30 16:40:11 2007 From: sbanderson at impromed.com (Scott B. Anderson) Date: Thu Aug 30 16:40:26 2007 Subject: BBB trojan In-Reply-To: <46D6E032.20104@ecs.soton.ac.uk> References: <03ed01c7eb10$be41dce0$3ac596a0$@swaney@fsl.com> <74ACEB3E6A055643A89B8CEC74C7BF2488E13E@WISENT.dcyb.net> <46D6E032.20104@ecs.soton.ac.uk> Message-ID: In the US at least, perhaps elsewhere, it is a non profit organization of businesses that promote each other and also track businesses with poor histories, and after confirming bad business practices, distributes the information to anyone in the public that asks for it. I typically check with the BBB website for information on a company before buying something over the internet, for example. Scott Anderson -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian Field Sent: Thursday, August 30, 2007 10:20 AM To: MailScanner discussion Subject: Re: BBB trojan -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Rob Sterenborg wrote: >> Heads up. We just started seeing these and they look nasty. >> >> Subject: BBB Complaint for Elizabeth MeHaffey [Case id: >> #48556fc5ba482c6f07ada256696597e1] >> >> they purport to be a Better Business Bureau compliant against the >> company and the recipient of the fraud. >> >> Going to a link in the document downloads an executable that is >> probably not going to be good for your computer. >> > > Could you put the message somewhere on a website and post a link to it? > Out of idle curiosity, what is the "Better Business Bureau"? Some company flogging something, I guess... Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.3 (Build 3017) Comment: (pgp-secured) Charset: ISO-8859-1 wj8DBQFG1uAzEfZZRxQVtlQRAnKqAJ9osNbjxnJUXlR+PvnN25y6WllsHQCdH+gC BCoJoKuvXiQ3ufWRyAc6KVQ= =qnQa -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From waytotheweb at googlemail.com Thu Aug 30 16:44:13 2007 From: waytotheweb at googlemail.com (Sarah Trayser) Date: Thu Aug 30 16:44:17 2007 Subject: DCC not scoring from within MailScanner In-Reply-To: References: <46D469FE.5030207@evi-inc.com> Message-ID: On 28/08/2007, Sarah Trayser wrote: > Thanks for all the replies. > > We're using dccproc, not dccifd. > > On 28/08/07, Gareth wrote: > > The top 3 problems with getting DCC to work are :- > > > > 1) Firewall but this wont allow it to work from the command prompt for any > > user. > > Although we do run a firewall, that can't be the issue since it's > working from the command line. > > > > > 2) Permissions. Test it under the same user which mailscanner runs as. > > In my testing I did this. DCC works when I run a spamassassin test as > the mailscanner user, just not when MailScanner calls it, apparently. > > > 3) Path issues. Make sure you correctly have the dcc path set in the > > spamassassin configuration. This is the error I made which resulted in the > > same issue you are experiencing. > > Wouldn't this affect the command line test as well? Where would this > be set - mailscanner.cf > spam.assassin.prefs.conf? This is what I see > in that file: > > ifplugin Mail::SpamAssassin::Plugin::DCC > #dcc_path /usr/local/bin/dccproc > endif > > As far as I know we have not changed that so I assume it has always > been commented out. Got it working. All I did was uncomment the dcc_path line in /etc/mail/spamassassin/mailscanner.cf. I'm not sure why it is commented out by default (if it is), or why it is apparently working this way on other peoples' servers but not ours, but at any rate with that line not commented out we are getting scores on the DCC_CHECK from within Mailscanner on all our servers. -- Regards, Sarah Trayser Way to the Web Ltd Server Management Services: http://www.configserver.com Web Hosting: http://www.waytotheweb.com From steve.swaney at fsl.com Thu Aug 30 16:45:42 2007 From: steve.swaney at fsl.com (Stephen Swaney) Date: Thu Aug 30 16:45:01 2007 Subject: BBB trojan In-Reply-To: <74ACEB3E6A055643A89B8CEC74C7BF2488E13E@WISENT.dcyb.net> References: <03ed01c7eb10$be41dce0$3ac596a0$@swaney@fsl.com> <74ACEB3E6A055643A89B8CEC74C7BF2488E13E@WISENT.dcyb.net> Message-ID: <041701c7eb1c$d2682240$773866c0$@swaney@fsl.com> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Rob Sterenborg > Sent: Thursday, August 30, 2007 10:31 AM > To: MailScanner discussion > Subject: RE: BBB trojan > > > Heads up. We just started seeing these and they look nasty. > > > > Subject: BBB Complaint for Elizabeth MeHaffey [Case id: > > #48556fc5ba482c6f07ada256696597e1] > > > > they purport to be a Better Business Bureau compliant against the > > company and the recipient of the fraud. > > > > Going to a link in the document downloads an executable that is > > probably not going to be good for your computer. > > Could you put the message somewhere on a website and post a link to it? > > > Thanks, > Rob Sure. http://www.fsl.com/docs/BBB-fraud.htm Steve Swaney steve@fsl.com www.fsl.com From ka at pacific.net Thu Aug 30 17:00:40 2007 From: ka at pacific.net (Ken A) Date: Thu Aug 30 17:00:46 2007 Subject: BBB trojan In-Reply-To: <041701c7eb1c$d2682240$773866c0$@swaney@fsl.com> References: <03ed01c7eb10$be41dce0$3ac596a0$@swaney@fsl.com> <74ACEB3E6A055643A89B8CEC74C7BF2488E13E@WISENT.dcyb.net> <041701c7eb1c$d2682240$773866c0$@swaney@fsl.com> Message-ID: <46D6E9A8.4090206@pacific.net> Stephen Swaney wrote: >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Rob Sterenborg >> Sent: Thursday, August 30, 2007 10:31 AM >> To: MailScanner discussion >> Subject: RE: BBB trojan >> >>> Heads up. We just started seeing these and they look nasty. >>> >>> Subject: BBB Complaint for Elizabeth MeHaffey [Case id: >>> #48556fc5ba482c6f07ada256696597e1] >>> >>> they purport to be a Better Business Bureau compliant against the >>> company and the recipient of the fraud. >>> >>> Going to a link in the document downloads an executable that is >>> probably not going to be good for your computer. >> Could you put the message somewhere on a website and post a link to it? >> >> >> Thanks, >> Rob > > Sure. > > http://www.fsl.com/docs/BBB-fraud.htm > > I find it funny, when spammers go to great pains to create a 'real' looking email, then can't resist putting some bayes poison at the bottom! What's up with that? It gives me some hope that we may win this battle yet.. at least against the dumb spammers. ;-) Ken > > > Steve Swaney > steve@fsl.com > www.fsl.com > -- Ken Anderson Pacific.Net From jaearick at colby.edu Thu Aug 30 18:38:47 2007 From: jaearick at colby.edu (Jeff A. Earickson) Date: Thu Aug 30 18:40:37 2007 Subject: watermarking and spam mail loops? Message-ID: Gang, I'm trying to understand watermarking from the list archives (I took a month off the list), and I don't get it. It looks like it might be useful for killing spam-caused mail loops between my front-end sendmail/MailScanner mail-relay and my backend local-delivery box. The scene is: 1) spammer with bogus return sends to a nonexistent Colby email address. 2) if MailScanner doesn't kill it as spam, it gets relayed onto the backend system, who doesn't know the recipient. 3) the backend system is configured to send all non-local email to the front-end box, who sees that it is supposed to go to nonexistent Colby address, sent to the back-end, return to step 2 until 26 hops have been hit. Then drop in postmaster's lap. The summary of mail headers is below. I notice that the X-Colby-MailScanner-Watermark is different on every iteration. Can watermarking be used to kill this mail loop early on? My MailScanner.conf settings are: Use Watermarking = yes Add Watermark = yes Check Watermarks With No Sender = yes Treat Invalid Watermarks With No Sender as Spam = spam Check Watermarks To Skip Spam Checks = yes Watermark Secret = [deleted here] Watermark Lifetime = 259200 Watermark Header = X-%org-name%-MailScanner-Watermark: The mail headers look like: ----- Transcript of session follows ----- 554 5.4.6 Too many hops 27 (25 max): from <> via backend.colby.edu, to --l7UHAoe1018830.1188493850/frontend.colby.edu Content-Type: message/rfc822 Return-Path: <> Received: from backend.colby.edu (backend.colby.edu [137.146.28.76]) by frontend.colby.edu (8.14.1/8.14.1) with ESMTP id l7UHAoe0018830 (version=TLSv1/SSLv3 cipher=DES-CBC3-SHA bits=168 verify=OK) for ; Thu, 30 Aug 2007 13:10:50 -0400 (EDT) Received: from frontend.colby.edu (frontend.colby.edu [137.146.28.72]) by backend.colby.edu (MOS 3.8.5-GA) with ESMTP id ACM60239; Thu, 30 Aug 2007 13:10:48 -0400 (EDT) X-Colby-MailScanner-Watermark: 1189098637.87502@sPv+tFbAY318zuq3UUwcPQ Received: from backend.colby.edu (backend.colby.edu [137.146.28.76]) by frontend.colby.edu (8.14.1/8.14.1) with ESMTP id l7UHAb7E018697 for ; Thu, 30 Aug 2007 13:10:37 -0400 (EDT) Received: from frontend.colby.edu (frontend.colby.edu [137.146.28.72]) by backend.colby.edu (MOS 3.8.5-GA) with ESMTP id ACM60230; Thu, 30 Aug 2007 13:10:35 -0400 (EDT) X-Colby-MailScanner-Watermark: 1189098625.26567@Du4LxSJ4zxMUaTBdsi4teA [ SNIP ! a bunch of mail headers in here} Received: from chdsbs.ColbochHD.local (66.83.153.26.nw.nuvox.net [66.83.153.26]) by frontend.colby.edu (8.14.1/8.14.1) with ESMTP id l7UH5v03016243 for ; Thu, 30 Aug 2007 13:06:06 -0400 (EDT) From: postmaster@ColbochHD.com To: bogususer@colby.edu Date: Thu, 30 Aug 2007 11:55:28 -0500 MIME-Version: 1.0 Content-Type: multipart/report; report-type=delivery-status; boundary="9B095B5ADSN=_01C7EB1128F0C4AC0000B3D8chdsbs.ColbochHD" X-DSNContext: 335a7efd - 4457 - 00000001 - 80040546 Message-ID: Subject: {Spam?} Delivery Status Notification (Failure) X-Greylist: Delayed for 00:15:09 by milter-greylist-4.0b1 (frontend.colby.edu [137.146.28.72]); Thu, 30 Aug 2007 13:06:06 -0400 (EDT) X-Colby-MailScanner: ftbc, ftbc, ftbc, ftbc, ftbc, ftbc, ftbc, ftbc, ftbc, ftbc, ftbc, ftbc, ftbc X-Colby-MailScanner-SpamCheck: spam(no null-header or sender address), , , , , , , , , , , , X-Spam-Status: Yes, No, No, No, No, No, No, No, No, No, No, No, No X-Junkmail-IP-Whitelist: YES (by domain ip whitelist at backend.colby.edu) From mailscanner at slackadelic.com Thu Aug 30 16:30:00 2007 From: mailscanner at slackadelic.com (Matt Hayes) Date: Thu Aug 30 19:21:10 2007 Subject: BBB trojan In-Reply-To: <46D6E032.20104@ecs.soton.ac.uk> References: <03ed01c7eb10$be41dce0$3ac596a0$@swaney@fsl.com> <74ACEB3E6A055643A89B8CEC74C7BF2488E13E@WISENT.dcyb.net> <46D6E032.20104@ecs.soton.ac.uk> Message-ID: <46D6E278.9050005@slackadelic.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Julian Field wrote: > > > Rob Sterenborg wrote: >>> Heads up. We just started seeing these and they look nasty. >>> >>> Subject: BBB Complaint for Elizabeth MeHaffey [Case id: >>> #48556fc5ba482c6f07ada256696597e1] >>> >>> they purport to be a Better Business Bureau compliant against the >>> company and the recipient of the fraud. >>> >>> Going to a link in the document downloads an executable that is >>> probably not going to be good for your computer. >>> >> Could you put the message somewhere on a website and post a link to it? > > Out of idle curiosity, what is the "Better Business Bureau"? Some > company flogging something, I guess... > > Jules > The BBB is something here in the states that monitors, for lack of a better term, ethical actions of companies. In a way, if you treat a customer horribly.. the BBB hears about it and your reputation takes a dive.. sort of. THere's more to it.. but that's the gist. - -Matt -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFG1uJ4unv8h7s/76wRAlqbAKC0zoWjwLQU/N7Q6HSaHnJvweXKGwCfX9IF /9wOEm6jyFBW4keWUHT+/eo= =0vDT -----END PGP SIGNATURE----- From ssilva at sgvwater.com Thu Aug 30 20:17:34 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 30 20:17:50 2007 Subject: f-prot version 6.0.0 In-Reply-To: <46D6DFDB.20607@ecs.soton.ac.uk> References: <223f97700708300743w4e6658f3vba82836b9920a4cd@mail.gmail.com> <46D6DFDB.20607@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 8/30/2007 8:18 AM: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > I've already written support for it. It will be in the next release. > Now you are scaring me. Fixing something even before someone asks for it. You must be running Ouija Board 3.0 or have a HighDef crystal ball! ;-P -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Thu Aug 30 20:23:02 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 30 20:23:27 2007 Subject: watermarking and spam mail loops? In-Reply-To: References: Message-ID: Jeff A. Earickson spake the following on 8/30/2007 10:38 AM: > Gang, > > I'm trying to understand watermarking from the list archives > (I took a month off the list), and I don't get it. It looks > like it might be useful for killing spam-caused mail loops > between my front-end sendmail/MailScanner mail-relay and my > backend local-delivery box. The scene is: > > 1) spammer with bogus return sends to a nonexistent Colby > email address. > 2) if MailScanner doesn't kill it as spam, it gets relayed > onto the backend system, who doesn't know the recipient. > 3) the backend system is configured to send all non-local > email to the front-end box, who sees that it is supposed > to go to nonexistent Colby address, sent to the back-end, > return to step 2 until 26 hops have been hit. Then drop > in postmaster's lap. > > The summary of mail headers is below. I notice that the > X-Colby-MailScanner-Watermark is different on every iteration. > Can watermarking be used to kill this mail loop early on? Snip... There is a big minus to using the watermark. If you have users using Outlook or have an exchange server, the read receipts get marked as spam. Shouldn't you have your frontend box do a recipient verify to the internal box and drop the mail to non-existent users? That way you drop the connection and don't have to worry about bounces. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From mkettler at evi-inc.com Thu Aug 30 20:23:06 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Thu Aug 30 20:25:50 2007 Subject: watermarking and spam mail loops? In-Reply-To: References: Message-ID: <46D7191A.4090807@evi-inc.com> Jeff A. Earickson wrote: > Gang, > > I'm trying to understand watermarking from the list archives > (I took a month off the list), and I don't get it. It looks > like it might be useful for killing spam-caused mail loops > between my front-end sendmail/MailScanner mail-relay and my > backend local-delivery box. The scene is: > > 1) spammer with bogus return sends to a nonexistent Colby > email address. > 2) if MailScanner doesn't kill it as spam, it gets relayed > onto the backend system, who doesn't know the recipient. > 3) the backend system is configured to send all non-local > email to the front-end box, who sees that it is supposed > to go to nonexistent Colby address, sent to the back-end, > return to step 2 until 26 hops have been hit. Then drop > in postmaster's lap. > > The summary of mail headers is below. I notice that the > X-Colby-MailScanner-Watermark is different on every iteration. > Can watermarking be used to kill this mail loop early on? Probably not.. the watermark should apply to your own bounce messages. A substantially better solution would be to configure your sendmail to use something like milter-ahead, or a ldap based check to make sure the recipient is valid before you accept the email in the first place. As a bonus, you won't be blacklisted for backscatter-spamming people when the return address used by a spammer is valid, but is forged. From jaearick at colby.edu Thu Aug 30 20:30:04 2007 From: jaearick at colby.edu (Jeff A. Earickson) Date: Thu Aug 30 20:30:25 2007 Subject: watermarking and spam mail loops? In-Reply-To: References: Message-ID: On Thu, 30 Aug 2007, Scott Silva wrote: > Date: Thu, 30 Aug 2007 12:23:02 -0700 > From: Scott Silva > Reply-To: MailScanner discussion > To: mailscanner@lists.mailscanner.info > Subject: Re: watermarking and spam mail loops? > > Jeff A. Earickson spake the following on 8/30/2007 10:38 AM: >> Gang, >> >> I'm trying to understand watermarking from the list archives >> (I took a month off the list), and I don't get it. It looks >> like it might be useful for killing spam-caused mail loops >> between my front-end sendmail/MailScanner mail-relay and my >> backend local-delivery box. The scene is: >> >> 1) spammer with bogus return sends to a nonexistent Colby >> email address. >> 2) if MailScanner doesn't kill it as spam, it gets relayed >> onto the backend system, who doesn't know the recipient. >> 3) the backend system is configured to send all non-local >> email to the front-end box, who sees that it is supposed >> to go to nonexistent Colby address, sent to the back-end, >> return to step 2 until 26 hops have been hit. Then drop >> in postmaster's lap. >> >> The summary of mail headers is below. I notice that the >> X-Colby-MailScanner-Watermark is different on every iteration. >> Can watermarking be used to kill this mail loop early on? > Snip... > There is a big minus to using the watermark. If you have users using Outlook > or have an exchange server, the read receipts get marked as spam. We don't run Exchange on the backend and we don't support Outlook as an email client, so this sounds like a plus to me. :) > > Shouldn't you have your frontend box do a recipient verify to the internal > box and drop the mail to non-existent users? That way you drop the connection > and don't have to worry about bounces. > I've installed smf-sav recently, but I really need milter-ahead or some (free) alternative. What I would really like the sendmail front-end to do is simply see if the user is in /etc/passwd, if not then drop. My front-end has a complete list of my users there. Jeff Earickson Colby College From ssilva at sgvwater.com Thu Aug 30 20:45:41 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 30 20:47:00 2007 Subject: watermarking and spam mail loops? In-Reply-To: References: Message-ID: Jeff A. Earickson spake the following on 8/30/2007 12:30 PM: > On Thu, 30 Aug 2007, Scott Silva wrote: > >> Date: Thu, 30 Aug 2007 12:23:02 -0700 >> From: Scott Silva >> Reply-To: MailScanner discussion >> To: mailscanner@lists.mailscanner.info >> Subject: Re: watermarking and spam mail loops? >> >> Jeff A. Earickson spake the following on 8/30/2007 10:38 AM: >>> Gang, >>> >>> I'm trying to understand watermarking from the list archives >>> (I took a month off the list), and I don't get it. It looks >>> like it might be useful for killing spam-caused mail loops >>> between my front-end sendmail/MailScanner mail-relay and my >>> backend local-delivery box. The scene is: >>> >>> 1) spammer with bogus return sends to a nonexistent Colby >>> email address. >>> 2) if MailScanner doesn't kill it as spam, it gets relayed >>> onto the backend system, who doesn't know the recipient. >>> 3) the backend system is configured to send all non-local >>> email to the front-end box, who sees that it is supposed >>> to go to nonexistent Colby address, sent to the back-end, >>> return to step 2 until 26 hops have been hit. Then drop >>> in postmaster's lap. >>> >>> The summary of mail headers is below. I notice that the >>> X-Colby-MailScanner-Watermark is different on every iteration. >>> Can watermarking be used to kill this mail loop early on? >> Snip... >> There is a big minus to using the watermark. If you have users using >> Outlook or have an exchange server, the read receipts get marked as spam. > > We don't run Exchange on the backend and we don't support Outlook as an > email client, so this sounds like a plus to me. :) > >> >> Shouldn't you have your frontend box do a recipient verify to the >> internal box and drop the mail to non-existent users? That way you >> drop the connection and don't have to worry about bounces. >> > I've installed smf-sav recently, but I really need milter-ahead or > some (free) alternative. What I would really like the sendmail > front-end to do is simply see if the user is in /etc/passwd, if not > then drop. My front-end has a complete list of my users there. > > Jeff Earickson > Colby College Smf-sav is the free alternative to milter-ahead. You can also do it with mimedefang, but it is like hanging a picture with a sledge hammer. That is how I have been doing it, but started it before I knew about smf.sav. I will probably try it on the replacement servers next month. I thought sendmail should check the /etc/passwd file, but the system must know it isn't the final destination. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From MailScanner at ecs.soton.ac.uk Thu Aug 30 21:11:59 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu Aug 30 21:12:15 2007 Subject: DCC not scoring from within MailScanner In-Reply-To: References: <46D469FE.5030207@evi-inc.com> Message-ID: <46D7248F.3080307@ecs.soton.ac.uk> Sarah Trayser wrote: > On 28/08/2007, Sarah Trayser wrote: > >> Thanks for all the replies. >> >> We're using dccproc, not dccifd. >> >> On 28/08/07, Gareth wrote: >> >>> The top 3 problems with getting DCC to work are :- >>> >>> 1) Firewall but this wont allow it to work from the command prompt for any >>> user. >>> >> Although we do run a firewall, that can't be the issue since it's >> working from the command line. >> >> >>> 2) Permissions. Test it under the same user which mailscanner runs as. >>> >> In my testing I did this. DCC works when I run a spamassassin test as >> the mailscanner user, just not when MailScanner calls it, apparently. >> >> >>> 3) Path issues. Make sure you correctly have the dcc path set in the >>> spamassassin configuration. This is the error I made which resulted in the >>> same issue you are experiencing. >>> >> Wouldn't this affect the command line test as well? Where would this >> be set - mailscanner.cf > spam.assassin.prefs.conf? This is what I see >> in that file: >> >> ifplugin Mail::SpamAssassin::Plugin::DCC >> #dcc_path /usr/local/bin/dccproc >> endif >> >> As far as I know we have not changed that so I assume it has always >> been commented out. >> > > > Got it working. All I did was uncomment the dcc_path line in > /etc/mail/spamassassin/mailscanner.cf. I'm not sure why it is > commented out by default (if it is), or why it is apparently working > this way on other peoples' servers but not ours, but at any rate with > that line not commented out we are getting scores on the DCC_CHECK > from within Mailscanner on all our servers. > When you tested it from the command line, you will have a "login" shell running with a $PATH that probably includes /usr/local/bin. When MailScanner is started by init, there is no login shell and you will have a much shorter default $PATH, which doesn't usually include /usr/local/bin. The difference comes down to what is set in which "dot-files" in root's home directory. "init" won't usually have run any of these at all. On Solaris, this path is set in the /etc/default files, but I don't know where Linux sets it. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From hvdkooij at vanderkooij.org Thu Aug 30 21:22:13 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Thu Aug 30 21:22:27 2007 Subject: watermarking and spam mail loops? In-Reply-To: References: Message-ID: On Thu, 30 Aug 2007, Scott Silva wrote: > There is a big minus to using the watermark. If you have users using Outlook > or have an exchange server, the read receipts get marked as spam. Read Receipts are a privacy weakness at best. A privicy violation is more likely. As such it comes pretty close to spam in my view. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for this quote of George Bernard Shaw.) From maillists at conactive.com Thu Aug 30 21:31:30 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu Aug 30 21:31:33 2007 Subject: Heavy increase in spam influx this week? Message-ID: I notice that the "spammy" connects have at least doubled for the last three days or so, on some servers they may even be five or tenfold of the normal traffic. Do you see the same? Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From mailscanner at slackadelic.com Thu Aug 30 21:35:38 2007 From: mailscanner at slackadelic.com (Matt Hayes) Date: Thu Aug 30 21:35:47 2007 Subject: Heavy increase in spam influx this week? In-Reply-To: References: Message-ID: <46D72A1A.5020701@slackadelic.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Kai Schaetzl wrote: > I notice that the "spammy" connects have at least doubled for the last > three days or so, on some servers they may even be five or tenfold of the > normal traffic. Do you see the same? > > Kai > I think a lot of us have seen the same thing. I know here at work and on my own personal hosted box things have gone crazy the past week and a half or so. New virus/spam out I believe. - -Matt -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFG1yoaunv8h7s/76wRAgKxAJwKWOHsAON0ZRFIZCJNXnLmZ9veowCePqCH lh7KL6Oy+yHTKtPb1D+sAkY= =ZJIe -----END PGP SIGNATURE----- From waytotheweb at googlemail.com Thu Aug 30 21:50:33 2007 From: waytotheweb at googlemail.com (Sarah Trayser) Date: Thu Aug 30 21:50:36 2007 Subject: DCC not scoring from within MailScanner In-Reply-To: <46D7248F.3080307@ecs.soton.ac.uk> References: <46D469FE.5030207@evi-inc.com> <46D7248F.3080307@ecs.soton.ac.uk> Message-ID: On 30/08/2007, Julian Field wrote: > > Got it working. All I did was uncomment the dcc_path line in > > /etc/mail/spamassassin/mailscanner.cf. I'm not sure why it is > > commented out by default (if it is), or why it is apparently working > > this way on other peoples' servers but not ours, but at any rate with > > that line not commented out we are getting scores on the DCC_CHECK > > from within Mailscanner on all our servers. > > > When you tested it from the command line, you will have a "login" shell > running with a $PATH that probably includes /usr/local/bin. When > MailScanner is started by init, there is no login shell and you will > have a much shorter default $PATH, which doesn't usually include > /usr/local/bin. The difference comes down to what is set in which > "dot-files" in root's home directory. "init" won't usually have run any > of these at all. On Solaris, this path is set in the /etc/default files, > but I don't know where Linux sets it. > Thank you for the explanation, I think I understand it a bit better now. I also found out why we commented out the dcc_path line. At some point in the past there was no if loadplugin statement in the mailscanner.cf file and if the plugin was not installed, spamassassin would not work if the dcc_path and pyzor_path were set. At that time I guess DCC did work without the dcc_path set. Anyway, it's all good now. Thanks! -- Regards, Sarah Trayser Way to the Web Ltd Server Management Services: http://www.configserver.com Web Hosting: http://www.waytotheweb.com From mkettler at evi-inc.com Thu Aug 30 21:48:46 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Thu Aug 30 21:51:48 2007 Subject: Heavy increase in spam influx this week? In-Reply-To: <46D72A1A.5020701@slackadelic.com> References: <46D72A1A.5020701@slackadelic.com> Message-ID: <46D72D2E.10001@evi-inc.com> Matt Hayes wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Kai Schaetzl wrote: >> I notice that the "spammy" connects have at least doubled for the last >> three days or so, on some servers they may even be five or tenfold of the >> normal traffic. Do you see the same? >> >> Kai >> > > I think a lot of us have seen the same thing. I know here at work and > on my own personal hosted box things have gone crazy the past week and a > half or so. New virus/spam out I believe. My guess is this is the botnet resulting from the storm worm variants going into action. I've been noticing a lot of activity too. For the first time ever my sendmail actually hit my confMAX_DAEMON_CHILDREN limit. A lot of them seem to be "hanging around" in the command read state, so I added a confTO_COMMAND limit of 10 minutes (default is 1 hour). Yes, I know you have to be careful shortening this, but 10 minutes between SMTP commands is still pretty reasonable, and hopefully will help my server shed these dead connections. From ssilva at sgvwater.com Thu Aug 30 22:00:37 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu Aug 30 22:00:58 2007 Subject: watermarking and spam mail loops? In-Reply-To: References: Message-ID: Hugo van der Kooij spake the following on 8/30/2007 1:22 PM: > On Thu, 30 Aug 2007, Scott Silva wrote: > >> There is a big minus to using the watermark. If you have users using >> Outlook or have an exchange server, the read receipts get marked as spam. > > Read Receipts are a privacy weakness at best. A privacy violation is > more likely. As such it comes pretty close to spam in my view. > > Hugo. > The minus came with how many more times my phone rang when they got marked. My PHB's just LOVE Outlook. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ms-list at alexb.ch Thu Aug 30 22:04:52 2007 From: ms-list at alexb.ch (Alex Broens) Date: Thu Aug 30 22:04:58 2007 Subject: Heavy increase in spam influx this week? In-Reply-To: References: Message-ID: <46D730F4.4050306@alexb.ch> On 8/30/2007 10:31 PM, Kai Schaetzl wrote: > I notice that the "spammy" connects have at least doubled for the last > three days or so, on some servers they may even be five or tenfold of the > normal traffic. Do you see the same? > +35% of RBLD'd connections. [axb@msmx1 ~]# grep reject /var/log/maillog | wc -l 1590123 not funny Alex From steve.swaney at fsl.com Thu Aug 30 22:14:51 2007 From: steve.swaney at fsl.com (Stephen Swaney) Date: Thu Aug 30 22:14:14 2007 Subject: Heavy increase in spam influx this week? In-Reply-To: <46D730F4.4050306@alexb.ch> References: <46D730F4.4050306@alexb.ch> Message-ID: <05c701c7eb4a$cdbcacb0$69360610$@swaney@fsl.com> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Alex Broens > Sent: Thursday, August 30, 2007 5:05 PM > To: MailScanner discussion > Subject: Re: Heavy increase in spam influx this week? > > On 8/30/2007 10:31 PM, Kai Schaetzl wrote: > > I notice that the "spammy" connects have at least doubled for the > last > > three days or so, on some servers they may even be five or tenfold of > the > > normal traffic. Do you see the same? > > > > +35% of RBLD'd connections. > > [axb@msmx1 ~]# grep reject /var/log/maillog | wc -l > 1590123 > > not funny > > Alex > You're right about that! I just checked a few of our larger ISP sites and do see that the BarricadeMX sites rejection rate has been creeping up. We're now seeing 96-97% of all mail being rejected at the MTA level for sites that were at 92-94% rejection rates last week. But please note that these sites normally get hammered with spam and these rates normally go up and down. Steve Steve Swaney steve@fsl.com www.fsl.com From maillists at conactive.com Thu Aug 30 22:31:28 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu Aug 30 22:31:29 2007 Subject: MailScanner via Yum (CentOS) In-Reply-To: <46D6659A.1090903@statsbiblioteket.dk> References: <46D6659A.1090903@statsbiblioteket.dk> Message-ID: Tom G. Christensen wrote on Thu, 30 Aug 2007 08:37:14 +0200: > Why not install it from rpmforge? I prefer being able to make test. Also, I've been using SA much earlier than I started using MS, so I'm accustomed to installing it this way. > It was updated to 3.2.3 within days of the upstream release. CentOS 5 won't upgrade to 3.2.3. I didn't take into account that rpmforge may have it as well. > > > unpack the rpm-install tarball for Mailscanner, cd to it and > > > > rpm -ivh tnef-*.i386.rpm > > > rpmfoge also has this one. You are right. I don't know why I didn't get this one from rpmforge. Some old habit ;-) Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From ugob at lubik.ca Thu Aug 30 23:33:03 2007 From: ugob at lubik.ca (Ugo Bellavance) Date: Thu Aug 30 23:33:25 2007 Subject: BBB trojan In-Reply-To: <30014.3723762178$1188483867@news.gmane.org> References: <30014.3723762178$1188483867@news.gmane.org> Message-ID: Stephen Swaney wrote: > Heads up. We just started seeing these and they look nasty. > > Subject: BBB Complaint for Elizabeth MeHaffey [Case id: > #48556fc5ba482c6f07ada256696597e1] > > they purport to be a Better Business Bureau compliant against the company > and the recipient of the fraud. > > Going to a link in the document downloads an executable that is probably not > going to be good for your computer. Did you submit it to clamav? From maillists at conactive.com Fri Aug 31 09:18:13 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Fri Aug 31 09:18:16 2007 Subject: Heavy increase in spam influx this week? In-Reply-To: <46D72D2E.10001@evi-inc.com> References: <46D72A1A.5020701@slackadelic.com> <46D72D2E.10001@evi-inc.com> Message-ID: Matt Kettler wrote on Thu, 30 Aug 2007 16:48:46 -0400: > My guess is this is the botnet resulting from the storm worm variants going into > action. Ah, that's it. I figured as well it might be some new botnet, but I'm not well informed about what's currently du jour in that world. I didn't barely see any of that postcard spam, but now they come back at me from a different angle. > I've been noticing a lot of activity too. For the first time ever my sendmail > actually hit my confMAX_DAEMON_CHILDREN limit. Same here. I get SMS when my servers reach certain thresholds and the night before last night I got one almost every hour before I took measures to up the processes and reduce the backlog of hanging bots. It's the worst onslaught of spam I have seen yet, with the exception of backscatter on some single servers. > A lot of them seem to be "hanging around" in the command read state, so I added > a confTO_COMMAND limit of 10 minutes (default is 1 hour). Yes, I know you have > to be careful shortening this, but 10 minutes between SMTP commands is still > pretty reasonable, and hopefully will help my server shed these dead connections. I think that's still very reasonable. I'm running with 1m on some newer servers, (also for most other TO_ values) and haven't seen any problems with this for months. After all, if commands or data send take that long there's something wrong with the connection, anyway. After I changed those values on the most hit older servers the figures of steadily connected bots plunged. It makes a huge difference. My Postfix machines still suffer from the backlog of bots, as I haven't checked yet if Postfix provides similar time-out options. Anyone knows? These bots send about 5 or ten mails to the same single address, but all with a different sender. And they keep coming back quickly even when they were rejected. It looks as if they want to brute-force the mail delivery by overwhelming the spam protection. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From list-mailscanner at linguaphone.com Fri Aug 31 09:34:24 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Fri Aug 31 09:34:38 2007 Subject: Heavy increase in spam influx this week? In-Reply-To: References: <46D72A1A.5020701@slackadelic.com> <46D72D2E.10001@evi-inc.com> Message-ID: <1188549263.10587.4.camel@gblades-suse.linguaphone-intranet.co.uk> For me the number of spams received has dropped a little this week. Last week zen was rejecting about 7000 per day and this week it is just over 6000. However last night our postfix mta did reach the maximum concurrent connections (50) from one particular IP address and we hit the maximum process count (100) once for a very brief time. It wasn't a DOS attack but seemed to be a spam bot having problems as the connection rate was not that high. I have dropped the maximum concurrent connections significantly which should stop the process count going so high again in future. On Fri, 2007-08-31 at 09:18, Kai Schaetzl wrote: > Matt Kettler wrote on Thu, 30 Aug 2007 16:48:46 -0400: > > > My guess is this is the botnet resulting from the storm worm variants going into > > action. > > Ah, that's it. I figured as well it might be some new botnet, but I'm not well > informed about what's currently du jour in that world. I didn't barely see any of > that postcard spam, but now they come back at me from a different angle. > > > I've been noticing a lot of activity too. For the first time ever my sendmail > > actually hit my confMAX_DAEMON_CHILDREN limit. > > Same here. I get SMS when my servers reach certain thresholds and the night before > last night I got one almost every hour before I took measures to up the processes > and reduce the backlog of hanging bots. It's the worst onslaught of spam I have > seen yet, with the exception of backscatter on some single servers. > > > A lot of them seem to be "hanging around" in the command read state, so I added > > a confTO_COMMAND limit of 10 minutes (default is 1 hour). Yes, I know you have > > to be careful shortening this, but 10 minutes between SMTP commands is still > > pretty reasonable, and hopefully will help my server shed these dead connections. > > I think that's still very reasonable. I'm running with 1m on some newer servers, > (also for most other TO_ values) and haven't seen any problems with this for > months. After all, if commands or data send take that long there's something wrong > with the connection, anyway. After I changed those values on the most hit older > servers the figures of steadily connected bots plunged. It makes a huge difference. > My Postfix machines still suffer from the backlog of bots, as I haven't checked yet > if Postfix provides similar time-out options. Anyone knows? > > These bots send about 5 or ten mails to the same single address, but all with a > different sender. And they keep coming back quickly even when they were rejected. > It looks as if they want to brute-force the mail delivery by overwhelming the spam > protection. > > Kai > > -- > Kai Sch?tzl, Berlin, Germany > Get your web at Conactive Internet Services: http://www.conactive.com From glenn.steen at gmail.com Fri Aug 31 10:51:52 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri Aug 31 10:51:58 2007 Subject: f-prot version 6.0.0 In-Reply-To: <46D6DFDB.20607@ecs.soton.ac.uk> References: <223f97700708300743w4e6658f3vba82836b9920a4cd@mail.gmail.com> <46D6DFDB.20607@ecs.soton.ac.uk> Message-ID: <223f97700708310251j3311ad76jb9b3cbd10a32d6ef@mail.gmail.com> On 30/08/2007, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > I've already written support for it. It will be in the next release. As usual, you outdo yourself. Kind of scary when brilliance becomes everyday:-). Cheers -- Glenn > Glenn Steen wrote: > > I got this link from our friend Noel (Res...) today, he thought I > > should alert Jules/the list to the availability of this new version, > > as well as the changes it introduces. > > Personally, I don't use f-prot... So someone else will have to touch > > up the f-prot support to handle the new version. > > > > And ... here's the link: > > > > http://www.f-prot.com/news/gen_news/070823_release_linux_v6.html > > > > (Yeah, this might've been on the list... A quick search of my archive > > turned up absolutely nothing about it though, so ... :-) > > Cheers > > > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > Need help customising MailScanner? > Contact me! > Need help fixing or optimising your systems? > Contact me! > Need help getting you started solving new requirements from your boss? > Contact me! > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.3 (Build 3017) > Comment: (pgp-secured) > Charset: ISO-8859-1 > > wj8DBQFG1t/bEfZZRxQVtlQRApmdAJ9XSLxzGcq00Ych+fT81lM+m55wGQCg11oC > 00BzcFeon1Bm4sOWbns6w18= > =lhj9 > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From G.Pentland at soton.ac.uk Fri Aug 31 14:32:04 2007 From: G.Pentland at soton.ac.uk (Pentland G.) Date: Fri Aug 31 14:32:18 2007 Subject: Heavy increase in spam influx this week? In-Reply-To: References: <46D72A1A.5020701@slackadelic.com> <46D72D2E.10001@evi-inc.com> Message-ID: <7DB5AD05697FA549A4295DA1D0E5852214B7E0DAFF@UOS-CL-EX7-L1.soton.ac.uk> I've seen this as well on a quite a large scale. It would appear that one of the bots is slightly broken and is hanging around in cmd_read as you have observed. I'm am now running with the following set... define(`confQUEUE_LA',`15')dnl define(`confREFUSE_LA',`10')dnl define(`confMAX_DAEMON_CHILDREN',`500')dnl define(`confDELIVERY_MODE',`background')dnl define(`confMCI_CACHE_SIZE',`8')dnl undefine(`confTO_QUEUEWARN')dnl define(`confTO_QUEUERETURN',`8d')dnl define(`confMIN_FREE_BLOCKS',`40000')dnl define(`confTO_INITIAL',`2m')dnl define(`confTO_CONNECT',`2m')dnl define(`confTO_ICONNECT',`10s')dnl define(`confTO_HELO',`5m')dnl define(`confTO_MAIL',`10m')dnl define(`confTO_RCPT',`10m')dnl define(`confTO_DATAINIT',`5m')dnl define(`confTO_DATABLOCK',`1h')dnl define(`confTO_DATAFINAL',`1h')dnl define(`confTO_RSET',`2m')dnl define(`confTO_QUIT',`2m')dnl define(`confTO_MISC',`2m')dnl define(`confTO_COMMAND',`10m')dnl define(`confTO_IDENT',`0')dnl define(`confTO_FILEOPEN',`60s')dnl define(`confTO_CONTROL',`2m')dnl define(`confTO_AUTH',`10m')dnl define(`confTO_STARTTLS',`10m')dnl And we seem to be dealing with it nicely... 14:26:22 up 2 days, 2:22, 1 user, load average: 3.46, 2.75, 2.33 children of current sendmail listener 178 This is on a dual xeon 3GHz, 4Gb ram. It is almost certainly related to the rapid spread of the virus "Troj/Agent-GBX", that went round the other day. Hope that helps, Gary Kai Schaetzl wrote: > Matt Kettler wrote on Thu, 30 Aug 2007 16:48:46 -0400: > >> My guess is this is the botnet resulting from the storm worm >> variants going into action. > > Ah, that's it. I figured as well it might be some new botnet, but I'm > not well informed about what's currently du jour in that world. I > didn't barely see any of that postcard spam, but now they come back > at me from a different angle. > >> I've been noticing a lot of activity too. For the first time ever my >> sendmail actually hit my confMAX_DAEMON_CHILDREN limit. > > Same here. I get SMS when my servers reach certain thresholds and the > night before last night I got one almost every hour before I took > measures to up the processes and reduce the backlog of hanging bots. > It's the worst onslaught of spam I have seen yet, with the exception > of backscatter on some single servers. > >> A lot of them seem to be "hanging around" in the command read state, >> so I added a confTO_COMMAND limit of 10 minutes (default is 1 hour). >> Yes, I know you have to be careful shortening this, but 10 minutes >> between SMTP commands is still pretty reasonable, and hopefully will >> help my server shed these dead connections. > > I think that's still very reasonable. I'm running with 1m on some > newer servers, (also for most other TO_ values) and haven't seen any > problems with this for months. After all, if commands or data send > take that long there's something wrong with the connection, anyway. > After I changed those values on the most hit older servers the > figures of steadily connected bots plunged. It makes a huge > difference. My Postfix machines still suffer from the backlog of > bots, as I haven't checked yet if Postfix provides similar time-out > options. Anyone knows? > > These bots send about 5 or ten mails to the same single address, but > all with a different sender. And they keep coming back quickly even > when they were rejected. It looks as if they want to brute-force the > mail delivery by overwhelming the spam protection. > > Kai > > -- > Kai Sch?tzl, Berlin, Germany > Get your web at Conactive Internet Services: http://www.conactive.com From wizard at jimhermann.com Fri Aug 31 18:29:19 2007 From: wizard at jimhermann.com (Jim Hermann) Date: Fri Aug 31 18:29:01 2007 Subject: list of variables which can be used in reports In-Reply-To: <46D57A58.50406@ecs.soton.ac.uk> References: <1188387826.3776.3.camel@gblades-suse.linguaphone-intranet.co.uk> <46D569C9.7060206@ecs.soton.ac.uk> <1188391785.3773.12.camel@gblades-suse.linguaphone-intranet.co.uk> <46D56CC3.7020200@ecs.soton.ac.uk><1188392396.3779.14.camel@gblades-suse.linguaphone-intranet.co.uk> <46D57A58.50406@ecs.soton.ac.uk> Message-ID: <027e01c7ebf4$76e73540$cc01a8c0@Dual> > You should already be able to use "$sascore" in this report. > Sorry it's > not in the example report, I must have overlooked that. Any > others you need? Takes what I needed, too. Thanks. Jim ----- Jim Hermann UUism Networks Ministering to the Needs of Online UUs Web Hosting, Email Services, Mailing Lists ----- From steinkel at pa.net Fri Aug 31 18:55:01 2007 From: steinkel at pa.net (Leland J. Steinke) Date: Fri Aug 31 18:55:06 2007 Subject: Heavy increase in spam influx this week? In-Reply-To: References: <46D72A1A.5020701@slackadelic.com> <46D72D2E.10001@evi-inc.com> Message-ID: <46D855F5.70605@pa.net> Kai Schaetzl wrote: > My Postfix machines still suffer from the backlog of bots, as I haven't checked yet > if Postfix provides similar time-out options. Anyone knows? smtpd_timeout? I started reducing this from 300s to 120s several moments ago, after catching up on my email after a particularly long meeting discussing, among other things, requirements for new spam/virus filtering servers... Leland From list-mailscanner at linguaphone.com Fri Aug 31 19:35:57 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Fri Aug 31 19:36:03 2007 Subject: Heavy increase in spam influx this week? In-Reply-To: <46D855F5.70605@pa.net> Message-ID: cat /var/log/maillog | grep -E "(connection count|concurrency)" Looking through my logs there have been the odd one or two IP addresses in the past with about 10 active connections at once but starting from the 27th I started to see connection of over 20 concurrent. I have dropped the concurrent connections per IP from 50 down to 5. We only have a 1Mbps internet connection so if any genuine person tries to send us more than that at the same time I would prefer to limit it to conserve bandwidth anyway. I think I'll do what you did and reduce the smptd_timeout aswell. > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Leland > J. Steinke > Sent: 31 August 2007 18:55 > To: MailScanner discussion > Subject: Re: Heavy increase in spam influx this week? > > > Kai Schaetzl wrote: > > > My Postfix machines still suffer from the backlog of bots, as I > haven't checked yet > > if Postfix provides similar time-out options. Anyone knows? > > smtpd_timeout? > > I started reducing this from 300s to 120s several moments ago, after > catching up on my email after a particularly long meeting discussing, > among other things, requirements for new spam/virus filtering servers... > > > Leland > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > >